Suspicious
Suspect

0a8f702c73eca337575b9c5f536b3025

VBScript
MD5: 0a8f702c73eca337575b9c5f536b3025
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0a8f702c73eca337575b9c5f536b3025
Sha1 8922a305151d2e953593c491b2765ef430dd6068
Sha256 b68e41ded94c48a018f3807dbea6062aae2522174a0f783f6a6c307feaadfbdc
Sha384 75c90c58ac0d03a8354ccc11dfff89ceb27fe373cee9aedea7169547a73ef1f22518a7155e5b41caf7cd7f992ab08118
Sha512 6ed7a7a966f3878d2c1d60000f305db27cb6aecc0358a5feab83f2bc662802e45951f4d997f69421f1112a3c8e6c648df5037e5fc9406008071cc46dde98c719
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/5:uhtkTwRwpD9n+twsPXt
TLSH 8626281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_aa1afce6.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_aa1afce6.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_aa1afce6.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙