Malicious
Malicious

0574d4b7b42c39b918d0d58d149c9438

MS Office Document
|
MD5: 0574d4b7b42c39b918d0d58d149c9438
|
Size: 1.08 MB
|
application/vnd.ms-office

Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
0574d4b7b42c39b918d0d58d149c9438
Sha1
d5a64154219b788c056f388810ea5c67b0474569
Sha256
1480dabe89af53f798ac93d4606d37ad8a1e6938dc054460ed4d8548f5e18d70
Sha384
a7433d2b12018f10c3e478c1f760ee08dff10d702f1519aeb35b1f6a42d7be573ede5f7c827ba38fd763411b50da69bf
Sha512
9fff5c8860038991acbfcdeeba4e571ea468f05d5587944b8afcb3b2ba34c2b9069bca03ed2f37a22d9bc3b1e58ce15e39d29ea4adbd93ff8993e7e996e8c082
SSDeep
24576:yZ2LFcFJTiY8fg0YwtFPS1O3Icb3O6fpAJgMm8aWzy:yMFcF0SYVS1OYOO6BAHJzy
TLSH
863523A66CD64F9FD4C70A39941BCD0CC35FEDCD2287E12BB2197621683673A66871C2
File Structure
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
VbsFile.deobfuscated.vbs
Malicious
Artefacts
Name
Value
Deobfuscated PowerShell

powershell "script" "hidden" set "shell" "=" "CreateObject" "WScript.Shell" set "fso" "=" "CreateObject" "Scripting.FileSystemObject" " Get script directory scriptDir = fso.GetParentFolderName(WScript.ScriptFullName) psScript = fso.BuildPath(scriptDir, "yankee_agent78.ps1") " run "PowerShell" "hidden" shell.run "powershell -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File "" & psscript & @(""", 0, [Unmanaged(ErrorExpressionAst)] ,) false

Deobfuscated PowerShell

"script" "hidden" set "shell" "=" "CreateObject" "WScript.Shell" set "fso" "=" "CreateObject" "Scripting.FileSystemObject" " Get script directory scriptDir = fso.GetParentFolderName(WScript.ScriptFullName) psScript = fso.BuildPath(scriptDir, " yankee_agent78.ps1) run "PowerShell" "hidden" shell.run @("powershell -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File " & psscript & @("", 0, "[Unmanaged") (errorexpressionast) [Unmanaged(ErrorExpressionAst)] ] , false

Deobfuscated PowerShell

psscript & "", 0, [Unmanaged(ErrorExpressionAst)] ,) false"

Deobfuscated PowerShell

psscript & @("", 0, "[Unmanaged") (errorexpressionast) [Unmanaged(ErrorExpressionAst)] [Unmanaged(ErrorExpressionAst)] ] "false"

0574d4b7b42c39b918d0d58d149c9438 (1.08 MB)
File Structure
Root Entry
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䈛䌪䗶䜵
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䈛䒰䈹䌏䈯
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀䕌䄨䈷䒏䇯䕨
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
VbsFile.deobfuscated.vbs
Malicious
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
Deobfuscated PowerShell

powershell "script" "hidden" set "shell" "=" "CreateObject" "WScript.Shell" set "fso" "=" "CreateObject" "Scripting.FileSystemObject" " Get script directory scriptDir = fso.GetParentFolderName(WScript.ScriptFullName) psScript = fso.BuildPath(scriptDir, "yankee_agent78.ps1") " run "PowerShell" "hidden" shell.run "powershell -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File "" & psscript & @(""", 0, [Unmanaged(ErrorExpressionAst)] ,) false

Malicious

0574d4b7b42c39b918d0d58d149c9438 > VbsFile > [PowerShell Command]

Deobfuscated PowerShell

"script" "hidden" set "shell" "=" "CreateObject" "WScript.Shell" set "fso" "=" "CreateObject" "Scripting.FileSystemObject" " Get script directory scriptDir = fso.GetParentFolderName(WScript.ScriptFullName) psScript = fso.BuildPath(scriptDir, " yankee_agent78.ps1) run "PowerShell" "hidden" shell.run @("powershell -NoProfile -NonInteractive -WindowStyle Hidden -ExecutionPolicy Bypass -File " & psscript & @("", 0, "[Unmanaged") (errorexpressionast) [Unmanaged(ErrorExpressionAst)] ] , false

Malicious

0574d4b7b42c39b918d0d58d149c9438 > VbsFile > [PowerShell Command] > [Deobfuscated PS] > [PowerShell Command]

Deobfuscated PowerShell

psscript & "", 0, [Unmanaged(ErrorExpressionAst)] ,) false"

Malicious

0574d4b7b42c39b918d0d58d149c9438 > VbsFile > [PowerShell Command] > [Deobfuscated PS] > [PowerShell Command] > [PowerShell Command]

Deobfuscated PowerShell

psscript & @("", 0, "[Unmanaged") (errorexpressionast) [Unmanaged(ErrorExpressionAst)] [Unmanaged(ErrorExpressionAst)] ] "false"

Malicious

0574d4b7b42c39b918d0d58d149c9438 > VbsFile > [PowerShell Command] > [Deobfuscated PS] > [PowerShell Command] > [Deobfuscated PS] > [PowerShell Command]

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙