General
Structural Analysis
Config.0
Yara Rules99+
Sync
Community
Infection Chain
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 2f83f063fa3766d18b52ab3c879fb1d7
|
| Sha1 | 7687298e7292b63efc31e13080ef4f0edfbf7dd8
|
| Sha256 | 6780453ce4fb419f2876decae3b36602b89714b0e0136b30cc1f26633b9aa4c6
|
| Sha384 | 2c89e7c97afbe8a2587605786a37210b0f9bed4a9355303dff4852c8ec27e70393bba03343afb122b1a2e0f59fc263df
|
| Sha512 | da6d150fcef8b20ec0f6f11461573af1d3e4c33de9f4d03e2c1ed56ae6086c64b027c9f655009d2d998e591511395b208c0211b39789a188318764b397110624
|
| SSDeep | 768:qyWMDC+xrAGI333L4EZCX4HnzlGhQ1j9tTBIvq:q0D9xrAGC3sEZCX4HnuA
|
| TLSH | 9A1395665804D638D43A0371435A0ECA8A679C4708B61D3E7BBD77D85FBBCDB93A18D0
|
File Structure
2f83f063fa3766d18b52ab3c879fb1d7
Malicious
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
㺮㾊䕲䈳䌮䈘㮖䊸䗧䏷㵼䔦㮝㭟㭔㲒䃤䇠䖁䄾䇺
system_config.ini
䌋䄱䜵䑾䋦䎶㪚䒞䓵䎨㸬㶨䘎䇪䗷䜯䆕㽴㿎㴍㲍䄒䀣
Malicious
䌋䄱䜵䑾䋦䎶㪚䒞䓵䎨㸬㶨䘎䇪䗷䜯䆕㽴㿎㴍㲍䄒䀣.deobfuscated.vbs
Malicious
Artefacts
|
Name0 | Value |
|---|---|
| Deobfuscated PowerShell | "&{$b=[System.IO.File]::ReadAllBytes('" |
2f83f063fa3766d18b52ab3c879fb1d7 (41.47 KB)
File Structure
2f83f063fa3766d18b52ab3c879fb1d7
Malicious
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
㺮㾊䕲䈳䌮䈘㮖䊸䗧䏷㵼䔦㮝㭟㭔㲒䃤䇠䖁䄾䇺
system_config.ini
䌋䄱䜵䑾䋦䎶㪚䒞䓵䎨㸬㶨䘎䇪䗷䜯䆕㽴㿎㴍㲍䄒䀣
Malicious
䌋䄱䜵䑾䋦䎶㪚䒞䓵䎨㸬㶨䘎䇪䗷䜯䆕㽴㿎㴍㲍䄒䀣.deobfuscated.vbs
Malicious
Characteristics
No malware configuration were found at this point.
Artefacts
|
Name0 | Value | Location |
|---|---|---|
| Deobfuscated PowerShell | "&{$b=[System.IO.File]::ReadAllBytes('" Malicious |
2f83f063fa3766d18b52ab3c879fb1d7 > Root Entry > 䌋䄱䜵䑾䋦䎶㪚䒞䓵䎨㸬㶨䘎䇪䗷䜯䆕㽴㿎㴍㲍䄒䀣 > 䌋䄱䜵䑾䋦䎶㪚䒞䓵䎨㸬㶨䘎䇪䗷䜯䆕㽴㿎㴍㲍䄒䀣.deobfuscated.vbs > [Command #0] > [PowerShell Command] |
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.