Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: http://papilutes.hopto.org |
Source: mshta.exe, 00000000.00000003.1290228062.00000000007B3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007B5000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.00000000007B8000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294739881.00000000007C0000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l |
Source: mshta.exe, 00000001.00000002.2522777705.0000000003194000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptx |
Source: mshta.exe, 00000001.00000002.2522777705.0000000003170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptx= |
Source: mshta.exe, 00000001.00000002.2522777705.0000000003170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptx? |
Source: mshta.exe, 00000000.00000002.1294457111.0000000000575000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000001.00000002.2522741582.0000000002FF0000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000001.00000002.2522777705.0000000003110000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptxC: |
Source: mshta.exe, 00000001.00000002.2522777705.000000000312E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptxN |
Source: mshta.exe, 00000001.00000002.2522588226.0000000000AA9000.00000004.00000010.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptxd |
Source: mshta.exe, 00000001.00000002.2522777705.000000000312E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptxl |
Source: mshta.exe, 00000001.00000002.2522777705.000000000312E000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptxm |
Source: mshta.exe, 00000001.00000002.2522777705.0000000003170000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://papilutes.hopto.org/Gurukr/cableW2l/comparableKrE.pptxy.IE5R; |
Source: mshta.exe, 00000000.00000003.1291320484.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290228062.00000000007B3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007B5000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.00000000007B8000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290442821.000000000076D000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294642550.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/JavaScript |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://developer.mozilla.org/en-US/docs/Web/JavaScriptX |
Source: mshta.exe, 00000000.00000003.1290228062.00000000007B3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007B5000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.00000000007B8000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290442821.000000000076D000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://meta.ua/news/all/?gclid=EAIaIQobChMImYXApMKt-QIVsRJ7Ch26PwmoEAAYAiAAEgKMyPD_BwE |
Source: mshta.exe, 00000000.00000003.1290228062.00000000007B3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://meta.ua/news/all/?gclid=EAIaIQobChMImYXApMKt-QIVsRJ7Ch26PwmoEAAYAiAAEgKMyPD_BwE3PM41zeMBWfPn |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://meta.ua/news/all/?gclid=EAIaIQobChMImYXApMKt-QIVsRJ7Ch26PwmoEAAYAiAAEgKMyPD_BwEB |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292771587.00000000007B2000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1291320484.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://passport.i.ua/login/? |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294642550.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1291320484.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://regnum.ru/foreign/eastern-europe/ukraine.html |
Source: mshta.exe, 00000000.00000003.1288694322.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1291320484.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294642550.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000780000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://regnum.ru/foreign/eastern-europe/ukraine.htmlHTA.hta# |
Source: mshta.exe, 00000000.00000003.1291320484.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290228062.00000000007B3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007B5000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.00000000007B8000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290442821.0000000000751000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290442821.000000000076D000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294642550.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://t.me/ |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://t.me/G |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292771587.00000000007B2000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1291320484.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://www.bbc.com/ |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292771587.00000000007B2000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1291320484.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://www.crimea.kp.ru/daily/euromaidan/ |
Source: mshta.exe, 00000000.00000003.1288694322.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1291320484.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294642550.0000000000780000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000780000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.crimea.kp.ru/daily/euromaidan/x |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://www.rbc.ru/tags/?tag= |
Source: mshta.exe, 00000000.00000003.1291320484.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290228062.00000000007B3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.00000000007B5000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.00000000007B8000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290442821.000000000076D000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294642550.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294015422.0000000000790000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC3000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://www.ukr.net/ |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: https://www.ukr.net/o |
Source: mshta.exe, 00000000.00000003.1290836756.0000000005BCC000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1288694322.00000000007A9000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000002.1294722604.00000000007B8000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1294228164.00000000007BD000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1292410893.000000000076E000.00000004.00000020.00020000.00000000.sdmp, mshta.exe, 00000000.00000003.1290836756.0000000005BC8000.00000004.00000020.00020000.00000000.sdmp, 2-12749-25_21.04.2025.HTA.hta | String found in binary or memory: https://www.unian.net/ |