Unlock the future of Extended Malware Analysis

The cutting-edge solution designed for cybersecurity experts. Experience unparalleled speed and accuracy through our advanced static and structural analysis methods. Malva.RE excels in deconstructing malware encapsulated in known formats, simplifying the workflow for professionals and enhancing their efficiency.

Sample Description Type / Size Tags
Malicious
Malicious
230888af63fe269a3ff7a79ca6b5cf2f

MD5: 230888af63fe269a3ff7a79ca6b5cf2f

SHA256: e466e80fd69cf939b7dd29524b5b6001be7ae47096[...]52d

ZIP archive

135.16 KB

Zip Archive
LNK
Malicious
LOLBin
LOLBin:powershell.exe
+10
Malicious
Malicious
669fce84d112e62291e96f49d42be557

MD5: 669fce84d112e62291e96f49d42be557

SHA256: bf21161c808ae74bf08e8d7f83334ba926ffa0bab9[...]890

AutoIt Compiled Script

919.55 KB

Executable
PE (Portable Executable)
PE File Layout
Win 32 Exe
x86
+4
Malicious
Malicious
307757e687af5523ce5230a31a4ff52b

MD5: 307757e687af5523ce5230a31a4ff52b

SHA256: c6bb0f40f0bb31044ecee7ae1720c653798168a707[...]e29

PowerShell Script

8.69 KB

PowerShell
Powershell: Hidden Execution
Malicious
Malicious
a1975008ece68fae1ccb17df20a61290

MD5: a1975008ece68fae1ccb17df20a61290

SHA256: c0a6d0d1479d793eed9afdff1ce6c68be109ac586b[...]8bc

AutoIt Compiled Script

1.02 MB

Executable
PE (Portable Executable)
PE File Layout
Win 32 Exe
x86
+4
Malicious
Malicious
2d98445783055f16fa6c4a8975fa859a

MD5: 2d98445783055f16fa6c4a8975fa859a

SHA256: f211c45c2dd508734dbd84d088e08848f116a978c2[...]47b

C2: ht[...]s3%.php�jDRF���������bERF���������?$?

C2: https[:]//smartcheckautos%.com/wp%-content/%.%.%./%.%.%./x3%.php��������� �.4)?:�������url:https[:]//calfeutragebprs%.com/wp%-content/image/s3%.php�jDRF���������bERF���������?$? F����������P�������������?? F���������?ERF����������%������

C2: https[:]//calfeutragebprs%.com/wp%-content/image/s3%.php�jDRF���������bERF���������?$? F����������P�������������?? F���������?ERF����������%�������������� �������������"%? F���������?? F���������A%? F���������RR?F��

C2: https[:]//?.com?.com?.com?[...]Tkn.OpenTextF

C2: https[:]//contracstructed.com/o365.php"?�T[...]s

Portable Executable file

5.24 MB

Contains Base64 Block
Base64 Block
Base64 Payload
Html
Executable
+7
An error has occurred. This application may no longer respond until reloaded. Reload 🗙