Source: powershell.exe, 00000005.00000002.3019849567.000001D06F29C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.micros |
Source: 77EC63BDA74BD0D0E0426DC8F80085060.0.dr |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: wscript.exe, 00000000.00000003.1692594649.0000019747627000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ca6d2a1b68f47 |
Source: wscript.exe, 00000000.00000003.1692245556.00000197493F7000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1692872277.00000197493F7000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1692717937.00000197493F7000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabZy |
Source: wscript.exe, 00000000.00000003.1692798831.000001974764E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1692594649.0000019747627000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/authrootstl.cab?ca6d2a1b68 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.google.com |
Source: powershell.exe, 00000005.00000002.2970229076.000001D0588FC000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.usercontent.google.com |
Source: powershell.exe, 00000005.00000002.3010170859.000001D066B48000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2973558788.0000000005E31000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000009.00000002.2969690427.0000000004F26000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056AE1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2969690427.0000000004DD1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000009.00000002.2969690427.0000000004F26000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056AE1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000009.00000002.2969690427.0000000004DD1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056FA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 00000009.00000002.2973558788.0000000005E31000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000009.00000002.2973558788.0000000005E31000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000009.00000002.2973558788.0000000005E31000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.g |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.go |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goo |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.goog |
Source: powershell.exe, 00000005.00000002.2970229076.000001D0588BE000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googPB |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googl |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google. |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.c |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.co |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D05856A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D056D05000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/u |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc? |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?e |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?ex |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?exp |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expo |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?expor |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export= |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=d |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=do |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=dow |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=down |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downl |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downlo |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=downloa |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download& |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&i |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id= |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y- |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-s |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-sr |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srW |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9W |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9Ws |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsT |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTx |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0a |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2N |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NV |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2a |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aU |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUm |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmn |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3V |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3Vq |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3Vqy |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D056D05000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3VqyC |
Source: powershell.exe, 00000009.00000002.2969690427.0000000004F26000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3VqyCXR |
Source: powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.googh8 |
Source: powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D056FA8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com |
Source: powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D056FA8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1y-srWy9WsTxO0ac2NVg8A2aUmnT3VqyC&export=download |
Source: powershell.exe, 00000009.00000002.2969690427.0000000004F26000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000005.00000002.2970229076.000001D057D65000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000005.00000002.3017587099.000001D06EF80000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://go.microsoft.co |
Source: powershell.exe, 00000005.00000002.3010170859.000001D066B48000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000009.00000002.2973558788.0000000005E31000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056FA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056FA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056FA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056FA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: powershell.exe, 00000005.00000002.2970229076.000001D056FA4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588E5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2970229076.000001D0588C3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |