Suspicious
Suspect

bc4a779062e33deafacd023552b70b70

PE Executable
MD5: bc4a779062e33deafacd023552b70b70
Size: 3.03 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 bc4a779062e33deafacd023552b70b70
Sha1 4080d4e71549072b27b24b5cb902d2d2cdb05da5
Sha256 5d16539260e3c23da6f5fee3ba39104fde4f68d4226a9957b1c7e35b4a9c1cd4
Sha384 2964fb4f795097c01600f582a9ae73b72f35cc4ba44e1a4fdea672ef3745b350ebabfb176df4e4375b4a53708d0cdab8
Sha512 a88e15546bcc2443b31437b3d4c85a8190cba7a495031bbfe86403ff9f3d5da49ed607f59d23c14d0208aa7b1f30d086931468438634ab3d89e7feb8744d9e96
SSDeep 24576:405zch9PtYkS1ldgvsYd1jKfESvNL6Ux4Z9Aznd6Q3CFosvvAoBele5I9D/K9no2:405A/Py1Dgvvj+Nv96Azd6ZisQpJyga
TLSH 81E54A17ECA148F6D0A9A33289A782567B75BC081B3233EB2E907B382F727D05D35755
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_70c90e82.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:1033-preview.png
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:1033-preview.png
ID:0006
ID:1033
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

3 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2img 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x2E2800 size 2400 bytes
[Authenticode]_70c90e82.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
.rsrc
Resources
RT_ICON
ID:0001
ID:1033
ID:1033-preview.png
ID:0002
ID:1033
ID:1033-preview.png
ID:0003
ID:1033
ID:1033-preview.png
ID:0004
ID:1033
ID:1033-preview.png
ID:0005
ID:1033
ID:1033-preview.png
ID:0006
ID:1033
ID:1033-preview.png
RT_GROUP_CURSOR4
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙