Hostile 99% Download

Payload.bat

Certutil DecodeEncoded content decoded: base64
SHA-2563431a9c4c9d4cf67855d1f50e0d743fef4f1b822d247ba2547d0f07981002c23
MaleculeMdTh

Evidence

Encoded content decoded: base64 lines 13–15
13:89… AABAAAAAAAAAAAAAAALzxAABPAAAAAAABAEAC>>"data_Payload.b64"
14echo AAAAAAAAAAAAAAAAAAAAAAAAACABAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAIAAACAAAAAAAAAAAAAAA>>"data_Payload.b64"
15echo CCA …
Certutil Decode lines 636–645
636:42… AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==>>"data_Payload.b64"
637echo [*] Decoding executable via certutil...
638certutil -decode "data_Payload.b64" "Payload.exe" >nul 2>&1
639if exist "data_Payload.b64" del /f /q "data_Payload.b64"
640if exist "Payload.exe" (
⋯5 lines

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.