Suspicious
Suspect

e5fb52cb4836455493489879979cf724

PE Executable
MD5: e5fb52cb4836455493489879979cf724
Size: 4.2 MB
application/x-dosexec

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e5fb52cb4836455493489879979cf724
Sha1 35ac62eefcad505cd25e97b9aff3c147a608c27e
Sha256 5cc44ec9af3b258dc4cd4fddccfa03550e8f5d3aa57fe78eb9c0805ed0850182
Sha384 bdc466a0788bb0984b6f666e8520bf5880d6942c4b0c238b25f4b7540923e8a75ba112965d408b81a65c7b2066d02773
Sha512 b04b75bb3938f9047e8a10cde530e3355a03423734c34ced74d447aacb9cd409199946ce2fcf40e7b8e79458eed5a8970adb2947590f378fa5220680ef095c06
SSDeep 98304:oTTKaw3lqwTABtbFxKmKPqVoZsEIi+nZNd+ZbRA:o3Kaw3l0HiMZNdm2
TLSH A016AD077D9140E5C4EAAB31C5B782627A61BC0C8B7933DB2E90AA782F723D25D75F44
PeID
HQR data fileMicrosoft Visual C++ v6.0 DLLPrivate EXE Protector V2.30-V2.3X -> SetiSoft TeamtElock 1.0 (private) -> tE!tElock 1.0 (private) -> tE!
[Authenticode]_95f22ed8.p7b
Overlay_5bff8d89.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
STICH beta

No STICH Path has been generated for this analysis yet.

1 structural branch were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 1
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x29CA00 size 2392 bytes
Info
Overlay extracted: Overlay_5bff8d89.bin (1461248 bytes)
[Authenticode]_95f22ed8.p7b
Overlay_5bff8d89.bin
Structure
DosHeader
PE Header
Optional Header (x64)
Section Headers
.text
.rdata
.data
.pdata
.xdata
.idata
.reloc
.symtab
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙