Suspicious
Suspect

2ff3e2a96a20772249ffc827a06aeedf

PE Executable
MD5: 2ff3e2a96a20772249ffc827a06aeedf
Size: 12.57 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2ff3e2a96a20772249ffc827a06aeedf
Sha1 9f24ce3e3ba051bf33a69e45d97f139d2fe591e4
Sha256 09a5ac4d28d4da76d8bb7ade1cb1707ab8c89b4cfec85b50e5de172cfb408ff4
Sha384 9a17d16ef881c9073ce76a7e659310e97b0294e6930607fe7a80ace6cc9c58a7989a00491c9acc8de43bb03ff859eae0
Sha512 7c99e7f46e3358732930e1d345125f95ae7908161813a200758cc0c176864805400d866028f465d462df1c4c7f8d670c7f8fd8b29b3bb50af4f7b7ea8bbed411
SSDeep 98304:aGsqTIVri2C3jGdD4/Lowr4i3HVd7EqO/:fTx3jUDstrTeqO/
TLSH A4C65C11FACB54F6F9036831416BB27F23315D048B28DB9BEB583B6BF877691186A305
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPeStubOEP v1.xPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe
Shape pe:exe
1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙