Malicious
Malicious

c8b727febcfd7572eaad993d91283905

VBScript Encoded
|
MD5: c8b727febcfd7572eaad993d91283905
|
Size: 1.55 MB
|
text/vbscript

Executable
PE (Portable Executable)
Win 32 Exe
x86
Obfuscated
VBScript Encoded
.Net Obfuscator
.Net Reactor
WScript.Shell
DeObfuscated
VBScript
T1059.005
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
c8b727febcfd7572eaad993d91283905
Sha1
ea6d564ca227380fee721e4d3a2e0e18af9c4af8
Sha256
e3c96368f6fbcd69a14db4389851e6c0422303c8d5e8e320a796632b98224598
Sha384
de5b36094db4157ce02bfad734f66d47e3191b9a07020929716314a7b830b3f2ae84b75fa51596753043fd276ed49581
Sha512
422df2b57c28b1fa43105fa76332dcf83d80c89c59449d06a99822c93e367bb3e4a0846794069279e8c83f41cea8b320c2140d1b8168d060953d7e7ce0c4a5b7
SSDeep
24576:U2G/nvxW3Ww0tPWyrazkMeoBMygR1+BPkfl5EZPSBwpLrVc:UbA30PC97newVslVWL6
TLSH
9C757C017E44CE12F0192233D2FF45444BB4AC516AA6E72B7EB937AE65213937D1CACB

PeID

Microsoft Visual C++ 6.0 DLL (Debug)
Microsoft Visual C++ 7.0 - 8.0
Microsoft Visual C++ 8
Microsoft Visual C++ 8
Microsoft Visual C++ v6.0 DLL
VC8 -> Microsoft Corporation
File Structure
c8b727febcfd7572eaad993d91283905
Executable
PE (Portable Executable)
Win 32 Exe
x86
Obfuscated
VBScript Encoded
.Net Obfuscator
.Net Reactor
WScript.Shell
DeObfuscated
VBScript
T1059.005
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
c8b727febcfd7572eaad993d91283905.decoded.vbs
Visual Basic
VBScript
VBScript Encoded
WScript.Shell
DeObfuscated
T1059.005
Obfuscated
Malicious
c8b727febcfd7572eaad993d91283905.decoded.vbs.deobfuscated.vbs
DeObfuscated
VBScript
T1059.005
Malicious
c8b727febcfd7572eaad993d91283905 (1.55 MB)
File Structure
c8b727febcfd7572eaad993d91283905
Executable
PE (Portable Executable)
Win 32 Exe
x86
Obfuscated
VBScript Encoded
.Net Obfuscator
.Net Reactor
WScript.Shell
DeObfuscated
VBScript
T1059.005
Malicious
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.rdata
.data
.didat
.rsrc
.reloc
Resources
PNG
ID:0065
ID:1033
ID:1033-preview.png
ID:0066
ID:1033
ID:1033-preview.png
RT_ICON
ID:0001
ID:1033
ID:0002
ID:1033
ID:0003
ID:1033
ID:0004
ID:1033
ID:0005
ID:1033
ID:0006
ID:1033
ID:0007
ID:1033
ID:1033-preview.png
RT_DIALOG
ID:0000
ID:1033
RT_STRING
ID:0007
ID:1033
ID:0008
ID:1033
ID:0009
ID:1033
ID:000A
ID:1033
ID:000B
ID:1033
ID:000C
ID:1033
ID:000D
ID:1033
ID:000E
ID:1033
ID:000F
ID:1033
ID:0010
ID:1033
RT_GROUP_CURSOR4
ID:0064
ID:1033
RT_MANIFEST
ID:0001
ID:1033
c8b727febcfd7572eaad993d91283905.decoded.vbs
Visual Basic
VBScript
VBScript Encoded
WScript.Shell
DeObfuscated
T1059.005
Obfuscated
Malicious
c8b727febcfd7572eaad993d91283905.decoded.vbs.deobfuscated.vbs
DeObfuscated
VBScript
T1059.005
Malicious
Characteristics
No malware configuration were found at this point.
You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙