Malicious
MS Office Document
MD5: 3c107fb4c98787e3daefd0264ee8eaa4
Size: 4.18 MB
application/vnd.ms-office
General
Structural Analysis
Config.0
Yara Rules99+
Sync
Community
Summary by MalvaGPT
Characteristics
|
Hash | Hash Value |
|---|---|
| MD5 | 3c107fb4c98787e3daefd0264ee8eaa4
|
| Sha1 | d8dd1a09f7daf11dae61cb993a700c4557d1b584
|
| Sha256 | 1b3577d4ef4e553995842f1feae47df6fce2a1e77893dbea2ce5a5135f248507
|
| Sha384 | 21fed8f0cf2532b77a39ccdedc5a271e2f69e94228a8a8b72de669ba29e1b585ea7c7a53202eddd8514f324fd4f56b66
|
| Sha512 | 081ba937246a07c242a1a164e730a1a2540145a896a98b8464432b892af0c849fd57e873a04420907cc218544ff9fc88116fbeb91630aab86c6f1cdbe4c4dc15
|
| SSDeep | 98304:Hq3MHrF7PHAM/GQEeFeiqUcRHiAozWzh6LUth+pAeUALpK/Yuwsf:Hq34F7Pp/9EThUyiAoqzg1j0Mi
|
| TLSH | 69163357F6F0A259C60727B582664308DC288D6B97495C24F1ECB328637CB63A1F87DE
|
File Structure
luoma响应.msi
Malicious
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4f
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4faaas
rBeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGd
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.CRT
.tls
䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐
Malicious
䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐.deobfuscated.vbs
Malicious
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4f
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4faaas
rBeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGd
Artefacts
|
Name | Value |
|---|---|
| Deobfuscated PowerShell | "&{$b=[System.IO.File]::ReadAllBytes('" |
luoma响应.msi (4.18 MB)
File Structure
luoma响应.msi
Malicious
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀䌋䄱䜵
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4f
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4faaas
rBeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGd
Structure
DosHeader
PE Header
Optional Header (x86)
Section Headers
.text
.data
.rdata
.bss
.idata
.CRT
.tls
䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐
Malicious
䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐.deobfuscated.vbs
Malicious
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4f
BeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGde4faaas
rBeRGIzOkZFfnBMWTeaLxRhilGLeEADdtgGd
Characteristics
No malware configuration were found at this point.
Artefacts
|
Name | Value | Location |
|---|---|---|
| Deobfuscated PowerShell | "&{$b=[System.IO.File]::ReadAllBytes('" Malicious |
luoma响应.msi > Root Entry > 䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐 > 䌋䄱䜵䑾䋦㫶㻨㲐㸽䃮䉏㫱䀖䈝㵤㻻䌫㰯䈕㪎䇍䊷䇐.deobfuscated.vbs > [Command #0] > [PowerShell Command] |
You must be signed in to post a comment.
You need a premium account to access this feature.
You must be signed in to post a comment.