Suspicious
Suspect

b269c6edc808b42056c17fde550215c3

VBScript
MD5: b269c6edc808b42056c17fde550215c3
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b269c6edc808b42056c17fde550215c3
Sha1 7997fcff6f7a6d1849a1d5ac099bd4bde98c1e5c
Sha256 0cab16843f26d992d1454cb4eed286074aeff1fd3df322fc7ec907eb6f507d94
Sha384 af00d8a87a69ce01191c0d0a8f206405b163caa84a69683a91b14e8eb7469a25ee2a60af830cf0baae89f433f9ccb6df
Sha512 c3e620789a55355a75e233c69279be3d93968b15b3b0741d8dea2300889ad902ced1f86be8280e8ff793c6c8a102c997f7da1418d9bf7bf5970adc2579d94bad
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/d:uhtkTwRwpD9n+twsPXx
TLSH BC26281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_d3f0141f.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_d3f0141f.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_d3f0141f.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙