Suspicious
Suspect

7142fa7b2429f5550bc70696bb952b1d

VBScript
MD5: 7142fa7b2429f5550bc70696bb952b1d
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 7142fa7b2429f5550bc70696bb952b1d
Sha1 0954762bfb754e77cb2e393f9b5c78aa193711e6
Sha256 a3b04bd975d74e7f8debed4aa7ab6ebd71fcafea9895f0519cb185a725fdf7fc
Sha384 44fa543bfdcb66eadd54cbd76bb08ab29da257ed0983ccc6008702a66e75e4d1a17adb3b4c2e7e0a90f2211c1b81110d
Sha512 8b89cf01816a10c353233eeb58a7ff268b9542d6c095110a644bfc4f50ecaf721e52ad08967c7ca919c130aa12f5d0df9a1225500dc3d5899c66e0e3b28c649d
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/p:uhtkTwRwpD9n+twsPXd
TLSH 1526281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_b729f91d.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_b729f91d.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_b729f91d.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙