Suspicious
Suspect

c85766ea1f11b02026e2f312375a4b37

VBScript
MD5: c85766ea1f11b02026e2f312375a4b37
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 c85766ea1f11b02026e2f312375a4b37
Sha1 e8071a500eaecff3f7bddb907db7c108d84f1ed3
Sha256 ecd9e112ce6dcca62ee7410cc362b50a0a71bebfb5b415fcd4aee58d68cc17ec
Sha384 e95fcc6f4b6d0bf841d5e4ecff7956cdeb3b42d1b1c5164a7b16e3debae895a76a5740a46ef71ff03efb0e852eda5ec2
Sha512 ec73ae19b5440f20bdb43bc7f3efe55b9208b56bf2237fbc276c75b69be3d7eb9ec3878b48343059994bcc06912174a4b3d77a1320dcc09282233e9d42a2d2aa
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/N:uhtkTwRwpD9n+twsPXZ
TLSH 2026281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_d4cf29dd.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_d4cf29dd.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_d4cf29dd.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙