Suspicious
Suspect

c51ed417cc651b241093b9cea8070d70

VBScript
MD5: c51ed417cc651b241093b9cea8070d70
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c51ed417cc651b241093b9cea8070d70
Sha1 25b2ba8c8e4381bf4981bc91474f311d197f9907
Sha256 e42404ad802f908c1a4ff3267a3357e6d4e3b5ef51d2bf2e701e80b4ee56fc98
Sha384 5db54a0d32dffc9b8ed56b8a90e8738b632afbfaf489e4bcf2993c8a1c440e61ca5898ab54939cd4f64a7d95713db1ce
Sha512 b5fcbdf242fe011c7a0003d2046d52be332ab35f22a59bb938f5135c789b38feed427e10e7e2dfc8fe2fab9fe51329d3ae89d9536cbbf2cc8f78d15bef367922
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/L:uhtkTwRwpD9n+twsPXH
TLSH 5626281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_db961475.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_db961475.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_db961475.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙