Suspicious
Suspect

50a08c1d512fa9a9eb3f19930580bed7

VBScript
MD5: 50a08c1d512fa9a9eb3f19930580bed7
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 50a08c1d512fa9a9eb3f19930580bed7
Sha1 3d861c25383cf99bd7b1671e03e985ee8257a851
Sha256 95b0b54fc09f9e9bb301d43bc8e9692d7629328a4dfe4428e7aecded0901c515
Sha384 e413c43db2b33e5b027628666d00435f02f6b633e18b3aa8a1abeeefb203b8bba620c1bb2f330e02bc49a05211323e0f
Sha512 69a1d13267214c158e69faaa0da5ea7c1dca9cbd3c3f2dfe558ce14848b9e3c3c37e4a6946a9e8ac9781f0401abee7c7de99ca87c5d443c20992c004f812dcf0
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/l:uhtkTwRwpD9n+twsPXh
TLSH 9426281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_a86203f0.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_a86203f0.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_a86203f0.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙