Suspicious
Suspect

e6f5d94582cc06d40dd6ae7e0be72a8c

VBScript
MD5: e6f5d94582cc06d40dd6ae7e0be72a8c
Size: 4.6 MB
text/vbscript

Get an AI-generated breakdown of this malware's behaviour, IOCs and recommendations.

AI analysis is available with Essential.
Unlock with Essential
MD5 e6f5d94582cc06d40dd6ae7e0be72a8c
Sha1 2a87e511bce67110854826a690884dda499baf2a
Sha256 817a766d9a41e3178244cbefe81ca595e155445e64bd7714a39d2ee4e3bc2f90
Sha384 3027c812153cc143f6e97dd44094891187e78f090b3132f19ebe1be51391202e99eb42bbcb101d97573666df2cfa3727
Sha512 0b98c4fc70d7b819a343c52046b7db28867ff2c52a95fc7a78890cd51c2066f05db9a556fd301175e49cb8617501063d086e468e9b38d6c653bf8598a738b163
SSDeep 49152:uhXH9ktlxeRwpD9n+jtIQwvEPXHP5he6/2:uhtkTwRwpD9n+twsPXC
TLSH 3626281525C64227F4E705BEEB18B309DFADB4152FECF75FD15049BBAC220A2896027B
PeID
Microsoft Visual C++ 6.0 DLL (Debug)Microsoft Visual C++ v6.0 DLL
[Authenticode]_3205fb45.p7b
Overlay_d07aad9f.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
STICH beta

No STICH Path has been generated for this analysis yet.

2 structural branches were classified as secondary (decorative or non-determinant content) and did not produce a fingerprint.

bin 2
Name Value
Info
PE Detect: PeReader OK (file layout)
Info
Authenticode present at 0x461000 size 7272 bytes
Info
Overlay extracted: Overlay_d07aad9f.bin (1024 bytes)
[Authenticode]_3205fb45.p7b
Overlay_d07aad9f.bin
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.szgpcfh
.planpm
.apwhamw
.ynp
.gamjck
.xer
.ujzhqjt
.fjqg
.txfdv
.rsrc
Resources
RT_VERSION
ID:0001
ID:1033
No malware configuration was found at this point.
You must be signed in to view YARA rules.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙