Suspicious
Suspect

d0b03f88e764bb691eb230f4f1079131

PE Executable
MD5: d0b03f88e764bb691eb230f4f1079131
Size: 5.38 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 d0b03f88e764bb691eb230f4f1079131
Sha1 c0f0cec15fce3ecf6fc9333bd2a32e7b3ac74a57
Sha256 c68b757774aa3ed96cfff4b2a3b5bbca511c17f2bc281ce9b17f49f6831fb4b1
Sha384 555cc0ace4fe99b6f69e3f7d067d224de429a0e89e39c0fe7bc02000167bcb863773952eaafe58a83cca2a191953e730
Sha512 aa32da5f82a80b6e55dd064874527eced83a64d34088d119553b8915d49d5e5ac7d7025244dafabd481fe55fbdf2cf41a807c4d24b18ebbcd98c49035f8dc7a1
SSDeep 49152:sLIXm9xYZFuf+QHHr2dDYwtuWwQSg2+bLYD18:8YZF8Edk
TLSH C34649137A98A1B5D4E6E23596665250F730BC4C8B3133D72EA2AEB81F333C16E78754
PeID
Microsoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
Overlay_62a4ce52.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_62a4ce52.bin (2692608 bytes)
Overlay_62a4ce52.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙