Malicious
Malicious

2ff8ad6d097475654fb7b835cab452b4

PE Executable
MD5: 2ff8ad6d097475654fb7b835cab452b4
Size: 6.33 MB
application/x-dosexec
Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 2ff8ad6d097475654fb7b835cab452b4
Sha1 1662803110f6a728d37c8dab4d78bf4ffca7a7b2
Sha256 d21bd3d35a440b59d7bffc3111dae5db43895d09d6d33caa47ca6fb205bc07fa
Sha384 48a7f3edf0e92fcd635a30ebdc9f7bb608dc780b5c89c58ab0b6c80cf88fa4db0410a73cbffa591388ccfefcfb1bf21f
Sha512 5c0a25e6e2423072978c2da2828e576a48e8763da36d957cb99675f4f66f0a907452a8b31aa1158e4d182a1bb24641bc144c60caaa5ad8ce2459f0e2fddceba2
SSDeep 49152:6tOk40I/U+ueafJ9uRSrGb9snz7lX+EXjW9PViFlT5T/58C1DubVr6LAkIOJCfK/:6EUpGdEXnjWmpBj26cmQb/E
TLSH 51564A07EDA545E9C0AAE23089679252BB717C485F3123D72B90F7382F72BD06EB9750
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta Structural Threat Infection Chain Hash

A content-independent fingerprint of the infection method: successive formats, internal objects and MITRE techniques from the initial file to each final payload.

STICH Path = the fingerprint (canonical chain with techniques) STICH Shape = structure only Only determinant branches produce STICH Paths.
Path pe:exe~T1027~T1055
Shape pe:exe
malicious 1 nodes
Name Value
Info
PE Detect: PeReader OK (file layout)
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙