Source: unknown |
Network traffic detected: HTTP traffic on port 49706 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49706 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49709 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49709 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49716 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49716 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49717 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49717 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49719 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49719 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49720 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49720 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49721 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49721 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49722 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49722 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49723 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49723 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49724 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49724 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49725 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49725 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49726 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49726 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49727 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49727 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49728 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49728 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49729 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49729 |
Source: unknown |
Network traffic detected: HTTP traffic on port 49730 -> 456 |
Source: unknown |
Network traffic detected: HTTP traffic on port 456 -> 49730 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: unknown |
TCP traffic detected without corresponding DNS query: 185.244.29.74 |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24575F000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74/ |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCFB1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74/d1 |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24575F000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74/j |
Source: wscript.exe, 00000002.00000003.2155784496.00000282CCBCA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000003.2155696546.00000282CCBC3000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526519100.00000282CD045000.00000004.00000020.00020000.00000000.sdmp, Passport.vbs, Passport.vbs.0.dr |
String found in binary or memory: http://185.244.29.74:456/document |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCFB1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/document& |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/document32 |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentB |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCFB1000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentG |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentJ |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentT |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentX |
Source: wscript.exe, 00000000.00000002.4526205993.000001F24573D000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/document_ |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentage: |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentgE |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentnE |
Source: wscript.exe, 00000000.00000002.4526169180.000001F245675000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentq |
Source: wscript.exe, 00000000.00000002.4526169180.000001F245675000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: http://185.244.29.74:456/documentr |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526103258.00000282CCF46000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/ |
Source: wscript.exe, 00000002.00000003.2155784496.00000282CCBCA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526519100.00000282CD045000.00000004.00000020.00020000.00000000.sdmp, Passport.vbs, Passport.vbs.0.dr |
String found in binary or memory: https://ipinfo.io/country |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456BC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/country6% |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/countryS |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/countryW |
Source: wscript.exe, 00000002.00000002.4526103258.00000282CCF03000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/countryY: |
Source: wscript.exe, 00000000.00000003.2029110505.000001F2438FA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000003.2155769312.00000282CAFDA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/country_ |
Source: wscript.exe, 00000000.00000002.4526169180.000001F245675000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/countryq |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456BC000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/countryz% |
Source: wscript.exe, 00000002.00000003.2155784496.00000282CCBCA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526519100.00000282CD045000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4525760224.00000282CADAD000.00000004.00000020.00020000.00000000.sdmp, Passport.vbs, Passport.vbs.0.dr |
String found in binary or memory: https://ipinfo.io/org |
Source: wscript.exe, 00000000.00000003.2029110505.000001F2438FA000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000003.2155769312.00000282CAFDA000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ipinfo.io/org_ |
Source: wscript.exe, 00000000.00000002.4526205993.000001F2456DE000.00000004.00000020.00020000.00000000.sdmp, wscript.exe, 00000002.00000002.4526103258.00000282CCF88000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://login.live.com |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntshrui.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cscapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msxml3.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sxs.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: vbscript.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: amsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: userenv.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptsp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rsaenh.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: cryptbase.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msisip.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wshext.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrobj.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wbemcomn.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: scrrun.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: linkinfo.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: msxml3.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: wininet.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iertutil.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mlang.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: urlmon.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: srvcli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ondemandconnroutehelper.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: winhttp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mswsock.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: iphlpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: winnsi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: dpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: gpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: dnsapi.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: rasadhlp.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: fwpuclnt.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: schannel.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: mskeyprotect.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ntasn1.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ncrypt.dll |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Section loaded: ncryptsslp.dll |
Jump to behavior |