Source: powershell.exe, 00000013.00000002.2390567297.00000000070F1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microsoft |
Source: 77EC63BDA74BD0D0E0426DC8F80085060.0.dr |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: wscript.exe, 00000000.00000003.1214778562.000001CB0660B000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1215082660.000001CB06632000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?08acc3b103974 |
Source: wscript.exe, 00000000.00000003.1214948169.000001CB083E1000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1215211128.000001CB08408000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/authrootstl.cab?08acc3b103 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.google.com |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDD91000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.usercontent.google.com |
Source: wab.exe, 00000015.00000002.2589661383.0000000022871000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: wab.exe, 00000015.00000002.2589661383.0000000022871000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: powershell.exe, 0000000F.00000002.2543561723.00000262DBFD9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000013.00000002.2387916097.0000000005750000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000013.00000002.2384989430.0000000004846000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: wab.exe, 00000015.00000002.2589661383.00000000228D8000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432412836.0000000024AB8000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2590837200.0000000024A90000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r3.i.lencr.org/0 |
Source: wab.exe, 00000015.00000002.2589661383.00000000228D8000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432412836.0000000024AB8000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2590837200.0000000024A90000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r3.o.lencr.org0 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CBF71000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000013.00000002.2384989430.00000000046F1000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2589661383.0000000022871000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000013.00000002.2384989430.0000000004846000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: wab.exe, 00000015.00000002.2590837200.0000000024A90000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.c.lencr |
Source: wab.exe, 00000015.00000002.2589661383.00000000228D8000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2590837200.0000000024A90000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.c.lencr.org/0 |
Source: wab.exe, 00000015.00000002.2589661383.00000000228D8000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2590837200.0000000024A90000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://x1.i.lencr.org/0 |
Source: wab.exe, 00000015.00000002.2589661383.00000000228D8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ysmglobalsourcing.com |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CBF71000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000013.00000002.2384989430.00000000046F1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC434000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7A000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364536741.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364451227.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 00000013.00000002.2387916097.0000000005750000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000013.00000002.2387916097.0000000005750000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000013.00000002.2387916097.0000000005750000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.g |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.go |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goo |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goog |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDD53000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googP |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googl |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google. |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.c |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.co0 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDCF4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CC3DE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2577739206.0000000006EF8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: wab.exe, 00000015.00000002.2577739206.0000000006EF8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/X |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/u |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc? |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?e |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?ex |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?exp |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expo |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expor |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export= |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=d |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=do |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=dow |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=down |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downl |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downlo |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downloa |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download& |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&i |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id= |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1 |
Source: wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000002.2589008106.0000000021F90000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1NSWYwJ8clchRCA8qFPRUlk146KNVbj_Z |
Source: wab.exe, 00000015.00000002.2577739206.0000000006F33000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1NSWYwJ8clchRCA8qFPRUlk146KNVbj_ZJ |
Source: wab.exe, 00000015.00000003.2383605144.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1NSWYwJ8clchRCA8qFPRUlk146KNVbj_ZT |
Source: wab.exe, 00000015.00000002.2577739206.0000000006F33000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1NSWYwJ8clchRCA8qFPRUlk146KNVbj_Zh |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yz |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yze |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeO |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeOR |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORl |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlW |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWd |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdW |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWK |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE1 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15e |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0y |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ym |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp9 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96 |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96m |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb- |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb-K |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb-Kl |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb-KlU |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb-KlUQ |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC196000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb-KlUQP |
Source: powershell.exe, 00000013.00000002.2384989430.0000000004846000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1yzeORlWdWKE15en4v7t0ymp96mb-KlUQXR |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.googh |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CC438000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com |
Source: wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2383605144.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/ |
Source: wab.exe, 00000015.00000002.2577906258.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2432274209.0000000006F63000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2383605144.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/3 |
Source: wab.exe, 00000015.00000002.2577739206.0000000006EF8000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1NSWYwJ8clchRCA8qFPRUlk146KNVbj_Z&export=download |
Source: wab.exe, 00000015.00000003.2383605144.0000000006F66000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1NSWYwJ8clchRCA8qFPRUlk146KNVbj_Z&export=downloadt |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CC438000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1yzeORlWdWKE15en4v7t0ymp96mb-KlUQ&export=download |
Source: powershell.exe, 00000013.00000002.2384989430.0000000004846000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CD2A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 0000000F.00000002.2543561723.00000262DBFD9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000013.00000002.2387916097.0000000005750000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC434000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7A000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364536741.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364451227.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC434000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7A000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364536741.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364451227.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC434000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7A000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364536741.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364451227.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC434000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7A000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364536741.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364451227.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: powershell.exe, 0000000F.00000002.2464771594.00000262CC434000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD58000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000F.00000002.2464771594.00000262CDD7A000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364536741.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000015.00000003.2364451227.0000000006F8E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |