Suspicious
Suspect

ced3da5e53cc6b7c5cd2df0e20de9007

VBScript
MD5: ced3da5e53cc6b7c5cd2df0e20de9007
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ced3da5e53cc6b7c5cd2df0e20de9007
Sha1 16b95b59866368b169b77da33df98fdce665b232
Sha256 dc73634b2d69dd4e3484993a0d421912ae6b0edc410a51e020f68c6dcfbf427c
Sha384 c29935f12db58492152139760d267067f625e2da8d230fb5585c7a98565580d888d854b77b4d528b47e347057d3cf580
Sha512 7ecc8e12e4f6980f9b455fad19a6418cbb4e1853d3a8410a847f0a66a7ebcbd3db316b34dc973b3991fff1b73d9e6c629482d42825a9ac1766dee6af53b0b1a2
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/T:uhtkTwRwpD9n+twsPXX
TLSH 2826281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_7fc6089a.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_7fc6089a.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_7fc6089a.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙