|
Hash | Hash Value |
|---|---|
| MD5 | 6f93ce80e4f5019783638d503d75b1c8
|
| Sha1 | 94bfc82e849454b4633ca9703b4a7a25e426088d
|
| Sha256 | 7e4bfc88fed28d86e6cfddd46982ac3f68a836f533f701d9273e3837e43dc846
|
| Sha384 | 443459624aed57c342d025324eaf2371c287a120f06213816d79d5b7209b74075f9c43822d3e3ab647f42b7e80a4ea92
|
| Sha512 | b52a25f383fe44eb7ca2d486484511a772e940bb5927251cb24c2b7f1361a9d9c837c9887fd1e36159fc2a8ecb1c89f909203b4770a15e23f78cb060bf739c4e
|
| SSDeep | 48:KFdYHJRIiOPFKRDTOaSSaLD87WQLzK0adaMroLljT0teyRIbVtnaWzqdi+g//RlL:RpwtKRYD87WQppfyRIbVO76/J/y/7O
|
| TLSH | 5F817B515C11C9BCB471459B20F9D80AF52392ABD908ED283C88C8B64F31BEF5AB5DE9
|
|
Name0 | Value |
|---|---|
| Deobfuscated PowerShell | -verb "RunAs" -Wait -ArgumentList "-ExecutionPolicy Bypass -File """ & psScript & """" " ws.Run " "powershell" -Command " & runCmd, 1, True ws.Run " "ping" "127.0.0.1" -n 11 |
| Deobfuscated PowerShell | -verb "RunAs" -Wait -ArgumentList "-ExecutionPolicy Bypass -File "" & psscript & """ " ws.run " "powershell" -Command " & runcmd @(1, " "True) ws.run @(ping" "127.0.0.1" -n 11 |
| Deobfuscated PowerShell | -verb "RunAs" -Wait -ArgumentList "-ExecutionPolicy Bypass -File " & psscript & "" " ws.run " "powershell" -Command " & runcmd @(1, " "True) ws.run @(ping" "127.0.0.1" -n 11 |
|
Name0 | Value | Location |
|---|---|---|
| Deobfuscated PowerShell | -verb "RunAs" -Wait -ArgumentList "-ExecutionPolicy Bypass -File """ & psScript & """" " ws.Run " "powershell" -Command " & runCmd, 1, True ws.Run " "ping" "127.0.0.1" -n 11 Malicious |
6f93ce80e4f5019783638d503d75b1c8 > [PowerShell Command] |
| Deobfuscated PowerShell | -verb "RunAs" -Wait -ArgumentList "-ExecutionPolicy Bypass -File "" & psscript & """ " ws.run " "powershell" -Command " & runcmd @(1, " "True) ws.run @(ping" "127.0.0.1" -n 11 Malicious |
6f93ce80e4f5019783638d503d75b1c8 > [Deobfuscated PS] > [PowerShell Command] |
| Deobfuscated PowerShell | -verb "RunAs" -Wait -ArgumentList "-ExecutionPolicy Bypass -File " & psscript & "" " ws.run " "powershell" -Command " & runcmd @(1, " "True) ws.run @(ping" "127.0.0.1" -n 11 Malicious |
6f93ce80e4f5019783638d503d75b1c8 > [Deobfuscated PS] > [Deobfuscated PS] > [PowerShell Command] |