Suspicious
Suspect

28bf2d7384f5f97c20f3183b99091389

VBScript
MD5: 28bf2d7384f5f97c20f3183b99091389
Size: 10.65 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 28bf2d7384f5f97c20f3183b99091389
Sha1 1afcf43fab413d20bb1579d2808d8adea687318d
Sha256 94d05309682a431c81f70a6c8f593ce231a6c338e5c2c783fe855c27fbfebe35
Sha384 2afd46456e858a0903b712c44038a3d20d7df0d5e63d337bf9fb447c3ae6f29714858af1a6d5d4297e47feb2c921e325
Sha512 fb56e41a6a3cc4e161273a2b0549481e7e2302b5ce1474b461a174b867c4044570c716794a365239a6e235d37fc61f169e7406e62c1086a3a95646cd5a3ea015
SSDeep 196608:wixm5cnv0KyPBi+1vL2FsnbfaR9bKv1lOYggi:wixm5cnv0KyPBi+l2Fl9bKv1lOYgX
TLSH 83B64A122645C02AE4BD307C5D38AF4BC56DFDD2177054DBA2B036AE0B329D66939BCB
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0xA25200 size 7272 bytes
Info
Overlay extracted: Overlay_5ce4ebfe.bin (1029 bytes)
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙