Suspicious
Suspect

8c817988f1d7857f1a2884c15f60db27

VBScript
MD5: 8c817988f1d7857f1a2884c15f60db27
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 8c817988f1d7857f1a2884c15f60db27
Sha1 54477697fac94b821f2d73e694bbce076032bf17
Sha256 25d9e9eb7cedc15f33728ecfd7e3a176b72c448903eef3b65322f38cdb63602e
Sha384 768a463bee7f2c0b9c5a42b39442c8861d3a93ed02fdf7935c486941baedeed6b859ebb529a07be2662f3737c80c2900
Sha512 f5875c12608c1a11377f09d0834ffa4df8ae5e1ce9267f7a306561c6747ed8261698bbf15ea827ef1c2c910d18d20f74500a802b8adb8118e3583598c936b974
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/7:uhtkTwRwpD9n+twsPXf
TLSH 7726281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_c2746738.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_c2746738.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_c2746738.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙