Suspicious
Suspect

61a4fe4b3fd2331c05a5594a12b2c86e

PE Executable
MD5: 61a4fe4b3fd2331c05a5594a12b2c86e
Size: 2.54 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 61a4fe4b3fd2331c05a5594a12b2c86e
Sha1 4e794424b5aedfbe473ceeca647d98a1056d7564
Sha256 460001cd92917d1c8d4e538d0ec367abf02e6533e357083a8382a1e41f7be5ce
Sha384 d0826f2d90b8c4950e20e316bc91b48856a4d426b98d09f5e4a94497a5e9c27ed58d4f495235749a2d105b61b4e4462a
Sha512 977c151c7b1da191c7e8f034bf25139c3e11cb03d480c54627a5a096ebb6f9e41bc6039a22a9e6fa486363f7b7a8752a2e14382b87d49ccb3e7a66a31f51f734
SSDeep 24576:JsgLYG5Il31FQciu+0EcOOL5avBbNMwhLUsa1HY:mwYG5Il3diuKmM55om
TLSH 99C54B072C605265C85BA33D68B712656BB5BF08C73533D32E91ABB42F713D26EB9708
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_1a4a3a75.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x26A600 size 8200 bytes
[Authenticode]_1a4a3a75.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙