Suspicious
Suspect

ddf557a6da328b6dd5117ee45afacc0b

PE Executable
MD5: ddf557a6da328b6dd5117ee45afacc0b
Size: 14.76 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ddf557a6da328b6dd5117ee45afacc0b
Sha1 ba31644e2b4b41fcb1684a8dc9b58ef943bc0f62
Sha256 7d722e42be73f69807b0fe9e56e1c578d892ab7862a7f0d64e62fe4e5491003e
Sha384 9c37f8aa20f65ae740f4f912a6b66fe7fa5a8979862ae780abb172eeef6b97c22a9fd2740c948043a08e376c24c97050
Sha512 7d34e34bc6e75bd9b6284b115d94e7ac47384697c4b2b4a235ff901bf4f5918e5faa6b5ac6586987fe741e1583c532d67b2ac4fab698349b07c82bf4ba46c407
SSDeep 49152:k4SBvYUpQ07G1hKnfOUIZqfIpAikiET+w3sPEEnt3manqRX9xH/6AENH76jaO7mv:k4S6UySkJStuNH7JKFWd
TLSH 54E64903EA5111D9C45EE33886B757527B70BC4D8B3273E71E506A743E66BE2ACB9B00
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_a4b3665a.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xE10A00 size 8096 bytes
[Authenticode]_a4b3665a.p7b
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙