Suspicious
Suspect

0f31ac9ac4bc67efa3be73fff3210168

VBScript
MD5: 0f31ac9ac4bc67efa3be73fff3210168
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 0f31ac9ac4bc67efa3be73fff3210168
Sha1 ceca8875fa6156fb5ee87a6113ed85b7a87d3891
Sha256 ce76dfd77de4622597e07cbb174c8ddb9dcce2c08ae196a6dd135a5fa483bb80
Sha384 9d257d3613286bfc2a6b028c1332481e8fc8a284eae6ae3b36c2f0e14107d010906063b3dd1f24bdca505dd9881be709
Sha512 f1b4bac04fa61966c9551bbe64aeac35e0f7991b42c9230c4eb67e237b0b9e551695fa4f8effb11910636e387e04d900c28848396aadd1443f441bce17e970a2
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/2:uhtkTwRwpD9n+twsPXq
TLSH 6626281525C64227F4E705BEEB18B309DFADB4152FECF75F915049FBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_4eb4c744.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_4eb4c744.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_4eb4c744.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙