Source: powershell.exe, 00000009.00000002.882935125828.000002167215A000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878904636075.0000000002AB1000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845480817.0000000005108000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000002.882847947414.0000000005102000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878864713619.0000000005108000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.0000000005102000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000009.00000002.882935125828.000002167215A000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878904636075.0000000002AB1000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845480817.0000000005108000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000002.882847947414.0000000005102000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878864713619.0000000005108000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.0000000005102000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 0000000D.00000002.878917749751.0000000008716000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microso |
Source: wab.exe, 0000000F.00000002.882856308898.0000000020C51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com |
Source: wab.exe, 0000000F.00000002.882856308898.0000000020C51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://ip-api.com/line/?fields=hosting |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B480000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882926973942.0000021669E6E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878910754934.0000000005737000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878910754934.0000000005874000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B300000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png4 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B32B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165B300000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.pngh |
Source: powershell.exe, 00000009.00000002.882848532717.0000021659E01000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878906475177.00000000046D1000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000002.882856308898.0000000020C51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B100000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B300000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html4 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B32B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165B300000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlh |
Source: powershell.exe, 00000009.00000002.882848532717.0000021659E01000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 0000000D.00000002.878906475177.00000000046D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB7q |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 0000000D.00000002.878910754934.0000000005874000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 0000000D.00000002.878910754934.0000000005874000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 0000000D.00000002.878910754934.0000000005874000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.g |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.go |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goo |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goog |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googl |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google. |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.c |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.co |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000002.882847947414.00000000050AE000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.00000000050AD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: wab.exe, 0000000F.00000002.882847947414.00000000050AE000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.00000000050AD000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/FP |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/u |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc? |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?e |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?ex |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?exp |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expo |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expor |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export= |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=d |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=do |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=dow |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=down |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downl |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downlo |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downloa |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download& |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&i |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id= |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1T |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1Tu |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3p |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pG |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGV |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQ |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQO |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOu |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuY |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYu |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0P |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PV |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1v |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vu |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuO |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOo |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOov |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovP |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZ |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc7 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc76 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc76t |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C802000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc76t5 |
Source: powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc76t5pN |
Source: wab.exe, 0000000F.00000002.882847947414.00000000050C4000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.00000000050C4000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000002.882848779553.00000000053B0000.00000004.00001000.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1kTBjYXwSaLf73tP79eJTEXDnkCOgv_e4 |
Source: wab.exe, 0000000F.00000002.882847947414.00000000050C4000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.00000000050C4000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1kTBjYXwSaLf73tP79eJTEXDnkCOgv_e4J |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2D1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com |
Source: wab.exe, 0000000F.00000002.882847947414.0000000005102000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878864713619.0000000005134000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.0000000005102000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/ |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2D1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1TuX3pGVQOuYuN0PVf0S1vuOovPZc76t5&export=download |
Source: wab.exe, 0000000F.00000003.878864713619.0000000005108000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1kTBjYXwSaLf73tP79eJTEXDnkCOgv_e4&export=download |
Source: wab.exe, 0000000F.00000003.880185049304.00000000050D4000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000002.882847947414.00000000050D4000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1kTBjYXwSaLf73tP79eJTEXDnkCOgv_e4&export=downloadDP |
Source: wab.exe, 0000000F.00000002.882847947414.00000000050EF000.00000004.00000020.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.880185049304.00000000050EF000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1kTBjYXwSaLf73tP79eJTEXDnkCOgv_e4&export=downloadSP |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B300000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 0000000D.00000002.878906475177.0000000004828000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester4 |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A028000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B32B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882848532717.000002165B300000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pesterh |
Source: powershell.exe, 00000009.00000002.882848532717.000002165C0DC000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B480000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.882926973942.0000021669E6E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878910754934.0000000005737000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000D.00000002.878910754934.0000000005874000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000009.00000002.882848532717.000002165B100000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://oneget.org |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: powershell.exe, 00000009.00000002.882848532717.000002165A2CD000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.878845630299.0000000005134000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |