Suspicious
Suspect

1ff9ba2a746ef06af2070ce968e70a28

PE Executable
MD5: 1ff9ba2a746ef06af2070ce968e70a28
Size: 13.86 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 1ff9ba2a746ef06af2070ce968e70a28
Sha1 f4fdc5855cfcdf55369c265fbcf387c2a82d9e53
Sha256 14e8d458392e7a03385fdea86babec87900bfe7555ec3c98fcbab6cf20bf72cf
Sha384 218046b4bfd50a107823258eb34a61e81be3d38087bf28e16c01f2d7a77dfe8d47b341d5f6c67d4eb46d2395d2e39248
Sha512 8b03512dbfdc22a3cff01f1071aa0bca3f63571ae6685e6d0ac94f65e20dcda3bd2fb3d45b2ed100ab668821c9815a8a7aa1476f7421fcece3e562578a37ad23
SSDeep 49152:PsJAHoGXAcUssHyJKrGaBXH+XrBFND5H50yIRyVvMVXv5r3W1rzfshNEYcT+GbDp:fDfU3Hn3SQMYDzYh
TLSH 9AD6D647238810DCCA47DBB144B0597912B13CEE4532BB9F8EA9BE942F167956FACF04
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_c791aaad.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xD36400 size 8128 bytes
[Authenticode]_c791aaad.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙