Suspicious
Suspect

ddc89de1e558578a5dbcfcd04b06f41b

VBScript
MD5: ddc89de1e558578a5dbcfcd04b06f41b
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 ddc89de1e558578a5dbcfcd04b06f41b
Sha1 a9025a044bd30d6064e1f8e54fe4df6f7d5652f6
Sha256 ddf2f92615d372a414aae3cd3bf57548bf6eede0d560a7f4f919a0179d5e348f
Sha384 c27bc00e3ba5bbdc2c1f3838129056c447bb60e3044d3a8409a40b2442f422f3680a220c616e9ba6bb01552b8a899377
Sha512 6d9b27cd7b9dbce1485db65fff032949fe1da342aa6580e753a70afbe3a4d3c9e867c9f9101325437e073b4cf4f57114e9aea8cc40ca9c9fb5337620f9239194
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/3:uhtkTwRwpD9n+twsPXz
TLSH 6B26281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_5790f279.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_5790f279.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_5790f279.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙