Ctrl + scroll to zoom · drag to pan

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 b9ed3c4f50fe2bef0dd4ab5b05f613b4
Sha1 6be5faff55398292d93a4286e545446c3a41ecbb
Sha256 3be674bc5cbe26b2934b4d4e84651e10afc426d38c7787682f674b9edb77633f
Sha384 635dafb3bd7c4451238ec898f352642fede50f094a30ddcecae01f419805e4bba3b0ea03a2052075ef7b304ab3251c57
Sha512 684a853da3fe362c970845f8e5fdae5fc8d83ed98121f4b90083401a14b3fb849942465ad2f72fbda198a0fd1312f413afb6da379e3c88de7d12a5df9aaebba6
SSDeep 24576:U2G/nvxW3Ww0tqy2tfssBaBHXH7kudLmoEzY:UbA30R2traB37rLFEU
TLSH 5F4549017E468A11F4191233C2EF854447B1AC512AE6F72B7EBE376D95223937C1EACB
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ 7.0 - 8.0Microsoft Visual C++ 8Microsoft Visual C++ 8Microsoft Visual C++ v6.0 DLLVC8 -> Microsoft Corporation
WoCNWGmUqu8TwHYf7bvu87Q.bat
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
mYyc3fRKb8kh0PadGx.4RPt39QQ5KWwl6pinN
jS8aFy93PRx3ypg1kU.ofwFQCkM9iVZTyIF3E
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
b9ed3c4f50fe2bef0dd4ab5b05f613b4.decoded.vbs
Malicious
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Overlay extracted: Overlay_4fd931d6.bin (848019 bytes)
Info
PDB Path: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb
WoCNWGmUqu8TwHYf7bvu87Q.bat
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.sdata
.rsrc
.reloc
Resources
RT_VERSION
ID:0001
ID:1033
.Net Resources
mYyc3fRKb8kh0PadGx.4RPt39QQ5KWwl6pinN
jS8aFy93PRx3ypg1kU.ofwFQCkM9iVZTyIF3E
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
b9ed3c4f50fe2bef0dd4ab5b05f613b4.decoded.vbs
Malicious
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙