Suspicious
Suspect

e56cf1c577ec0ac48859abfa10441fa5

VBScript
MD5: e56cf1c577ec0ac48859abfa10441fa5
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e56cf1c577ec0ac48859abfa10441fa5
Sha1 e283d849d8adc2fbbdf378ee522b12efee3c4e34
Sha256 5963a9d55fa168cd00871dcb209071e592df9cd29cb9daf0b12a93035e07d4dc
Sha384 727e01ec82b5a76a986569e4052298d1d273f8a51a3e784912e597ccae1b350d7e05130edbd1d7e9e963e4593d3afe9e
Sha512 e9bcd3e892977ac483607bcb14ad0037ca5331417c50464bc1ba3997d8627738bc55c3ecb7036456b708e371fb3f266260f5e27baf4ead35718e5da0f8503b31
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/n:uhtkTwRwpD9n+twsPXT
TLSH E626281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_e8a2ac97.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_e8a2ac97.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_e8a2ac97.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙