Source: powershell.exe, 00000014.00000002.2918369261.0000000007DE0000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microsoftg |
Source: wscript.exe, 00000000.00000003.1280734020.0000029F51607000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: wscript.exe, 00000000.00000003.1276080884.0000029F535BD000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1280184708.0000029F535BD000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1277659585.0000029F535BD000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1277953257.0000029F535BD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: wscript.exe, 00000000.00000003.1280734020.0000029F51607000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1280909884.0000029F51634000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab3 |
Source: wscript.exe, 00000000.00000003.1280734020.0000029F51607000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1280909884.0000029F51634000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabI |
Source: wscript.exe, 00000000.00000003.1280184708.0000029F535AD000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1277953257.0000029F535AD000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1277770471.0000029F535AD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a79a7483e6 |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.google.com |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B5A321000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.usercontent.google.com |
Source: wab.exe, 00000016.00000002.3758847608.0000000023017000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://fiszebrandt.pl |
Source: wab.exe, 00000016.00000002.3758847608.0000000023017000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://mail.fiszebrandt.pl |
Source: powershell.exe, 00000010.00000002.3176265994.0000016B68565000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.2912764832.00000000056CA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.2912764832.000000000558E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000014.00000002.2909992435.0000000004686000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: wab.exe, 00000016.00000002.3758847608.0000000023017000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000002.3759400992.0000000024FCE000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r10.i.lencr.org/0 |
Source: wab.exe, 00000016.00000002.3758847608.0000000023017000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000002.3759400992.0000000024FCE000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://r10.o.lencr.org0# |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B58501000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.2909992435.0000000004531000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000014.00000002.2909992435.0000000004686000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: wab.exe, 00000016.00000002.3758847608.0000000023017000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://x1.c.lencr.org/0 |
Source: wab.exe, 00000016.00000002.3758847608.0000000023017000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://x1.i.lencr.org/0 |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B58501000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000014.00000002.2909992435.0000000004531000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 00000014.00000002.2912764832.000000000558E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000014.00000002.2912764832.000000000558E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000014.00000002.2912764832.000000000558E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.g |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.go |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goo |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goog |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B59DBB000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googPz |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googl |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google. |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.c |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.co |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B59DBB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B58726000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000002.3747116656.0000000007268000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/u |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc? |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?e |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?ex |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?exp |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expo |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expor |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export= |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=d |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=do |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=dow |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=down |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downl |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downlo |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downloa |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download& |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&i |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id= |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1 |
Source: wab.exe, 00000016.00000002.3747608661.0000000007540000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1X7zNlE2RMcOfu1ki717CjcNxFGPw2Whl |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1l |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_ |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_M |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mp |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpg |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj- |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-W |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WW |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWe |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeR |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeRe |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReX |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXP |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPO |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOE |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEB |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBm |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmL |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLy |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyi |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3 |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3M |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MS |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MSc |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScO |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb2 |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb2y |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb2yd |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B58726000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb2ydP |
Source: powershell.exe, 00000014.00000002.2909992435.0000000004686000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb2ydXR |
Source: wab.exe, 00000016.00000002.3747116656.0000000007268000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/y |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.googh |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B589C8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com |
Source: wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000016.00000002.3747116656.0000000007268000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2904249486.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1X7zNlE2RMcOfu1ki717CjcNxFGPw2Whl&export=download |
Source: wab.exe, 00000016.00000003.2904249486.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1X7zNlE2RMcOfu1ki717CjcNxFGPw2Whl&export=downloadtd |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B589C8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1lB_Mpgj-WWeReXPOEBmLyiK3MScOb2yd&export=download |
Source: powershell.exe, 00000014.00000002.2909992435.0000000004686000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B597D6000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000010.00000002.3176265994.0000016B68565000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.2912764832.00000000056CA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000014.00000002.2912764832.000000000558E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: powershell.exe, 00000010.00000002.3021739315.0000016B589C4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A30C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A308000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000010.00000002.3021739315.0000016B5A2E6000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 00000016.00000003.2884545435.00000000072DA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |