Suspicious
Suspect

afd5a9c15f9c0074c90cfdc2de66cf91

VBScript
MD5: afd5a9c15f9c0074c90cfdc2de66cf91
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 afd5a9c15f9c0074c90cfdc2de66cf91
Sha1 13d7c54a73e56b736a3af22ee9cd18a99c294858
Sha256 ef0a99da336704bd461c94d3bf9da118217d45ea452102fd3f3aa9c2bdc49fda
Sha384 918666ce0f3d762472a5ee7c4b1b4dd9023a634c174598eaee292260b4ce3b153d518c27914dc26bc8dcbad599262b1b
Sha512 29e6391e67a0d3afa4fee596c1013e409510c9de8971fd5d98b9f46d42a8039abcbedb94c409e3a60e4f5d8d5847510c7dd0d8d638fb2ea724021c888b79282f
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/h:uhtkTwRwpD9n+twsPXF
TLSH C526281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_a78e0b08.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_a78e0b08.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_a78e0b08.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙