Suspicious
Suspect

2936bc94e2776c7ef0200995ca1df630

VBScript
|
MD5: 2936bc94e2776c7ef0200995ca1df630
|
Size: 5.03 MB
|
text/vbscript


Print
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
2936bc94e2776c7ef0200995ca1df630
Sha1
55127448519c6805e5b6635e16ed1b0909ed32d2
Sha256
d1a018205829c2252642f0b38e61f88819df1c5a2b64825a38fa53dbe2b9198b
Sha384
bf96a13f430317b0184f8854884aa1728b382d12a68f83d700f3117192ee7d42d968dae460013be18ed4029aa20581fb
Sha512
13337e23c3bec1ec3892ef123cc55dd15bf2d01697ed0711678cb0411a6f93575812d341de4a4039c75644e49fd301b4392b59a36cc5735d2816e231aab2d23a
SSDeep
49152:G6JZqzIleTT1US+HCBhZEA4NCy1XWrXjwMNZmcTyRUKMcEH:kH
TLSH
B836E0CF7D0D6A88888222F9651485A2F2DD83D17306DBB2FD7CC555B3858B8DA7B381
File Structure
2936bc94e2776c7ef0200995ca1df630
Malware Configuration - URLs in VBA/VBS Code
Config. Field
Value
URL #1

http://www.vmware.com/info?id=7

URL #2

http://www.microsoft.com/downloads/details.aspx

2936bc94e2776c7ef0200995ca1df630 (5.03 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙