Suspicious
Suspect

cbb98bd6dd84312bb99a2f248ad7f813

VBScript
MD5: cbb98bd6dd84312bb99a2f248ad7f813
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 cbb98bd6dd84312bb99a2f248ad7f813
Sha1 5b5ed355dc3959e87cb69fd988606834a9aa1804
Sha256 81989c161901a4c3b4fc02ca83631c351bf9fd2f95bd8644d4945d4bcf3be982
Sha384 da2723c8cab8b2b7711e4d24fbce4d87778ca4dab4716d0016efacf962979dffe056e754f2c9813295e79cee188713ed
Sha512 9f16bb2fa3f077f7693fee02228e384890a649dd01cde7a4ef060d841ce6d27289d5f57b4a196f2dcf1d69662280c032ceceaedb06b96ca451b0bd849f48e2b1
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/5:uhtkTwRwpD9n+twsPXV
TLSH 6226281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_b4fc7331.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_b4fc7331.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_b4fc7331.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙