Suspicious
Suspect

48ead24f6f60cc63d70b1f636499672a

PE Executable
MD5: 48ead24f6f60cc63d70b1f636499672a
Size: 4.55 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 48ead24f6f60cc63d70b1f636499672a
Sha1 83ff35e3378b860d9a10819cddf3aa231e50cabd
Sha256 5e12c7f4822f67723eaed1c3ded4fc8e94e576fed316a2b24b56e003bccb44e4
Sha384 aa2146e0ab68faa3b4ec536a41b8bb592b860e6ae0f1df085cb9a57ae844075a716ae725569836e938453b6f801b0feb
Sha512 7121fd1485d042af21252cf973e1b4dca11a71e09ed9a5e951233ae37812f45a5a288c94fdb695a3e733e34b6b0118a2d854870a1d0c0eaa02afcdbb7c555f9c
SSDeep 49152:VCwNfiO25sifI9lY6J8Y48DUabi5Yqlceu4Wlab5negc518wfvugnAeDOFXEL:oNBilpq5nu4MQe/YwfvDfDOSL
TLSH DB26BE03BCD481F4C4569635C5BA9263BA31B84E8B3673C72E50BA382F7A7D03AB5715
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_a8df8cbe.p7b
Overlay_2a60f822.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x285200 size 8120 bytes
Info
Overlay extracted: Overlay_2a60f822.bin (1903616 bytes)
[Authenticode]_a8df8cbe.p7b
Overlay_2a60f822.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙