Suspicious
Suspect

22290186c6d429f87052a6e9768ebd6b

VBScript
MD5: 22290186c6d429f87052a6e9768ebd6b
Size: 10.65 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 22290186c6d429f87052a6e9768ebd6b
Sha1 896467673e574a0df95df145cb7d3033dc4be454
Sha256 a1b7d4d2326aaebfa563dddbec125c9b485e1b1f06568bc2d7c61fe22ab1d949
Sha384 ca05b387ac1eb8a8bcbd8f7c2a634ed59c83cf6d994e635b94502e6e25cd57c2d0ceb8e955e7886984703d3588523851
Sha512 a5296ad105ad86bcf81b1282a252da3bc76d26b37bee4cfcee407c6982cc0b3e6395741263aab8552a8ea14ab2ec73a6210ebc50033225f29f0519edffd7da9a
SSDeep 196608:wixm5cnv0KyPBi+1vL2FsnbfaR9bKv1lOYggY:wixm5cnv0KyPBi+l2Fl9bKv1lOYgh
TLSH 76B64A122645C02AE4BD307C5D38AF4BC56DFDD2177054DBA2B036AE0B329D66939BCB
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_c1c59bc2.p7b
Overlay_6b4b1d07.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.cmr
.oklekp
.sxzad
.vkv
.rqjxlqn
.azzqaf
.rympge
.tdwuqxc
.ctpvhd
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xA25200 size 7272 bytes
Info
Overlay extracted: Overlay_6b4b1d07.bin (1029 bytes)
[Authenticode]_c1c59bc2.p7b
Overlay_6b4b1d07.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.cmr
.oklekp
.sxzad
.vkv
.rqjxlqn
.azzqaf
.rympge
.tdwuqxc
.ctpvhd
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙