Source: 00000008.00000002.2700386932.0000000008398000.00000004.00000020.00020000.00000000.sdmp |
Malware Configuration Extractor: Remcos {"Host:Port:Password": ["gnsuw4-nsh6-mnsg.duckdns.org:3613:1"], "Assigned name": "RemoteHost", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Enable", "Install path": "Application path", "Copy file": "remcos.exe", "Startup value": "Disable", "Hide file": "Disable", "Mutex": "Rmc-8OIXMO", "Keylog flag": "1", "Keylog path": "Application path", "Keylog file": "logs.dat", "Keylog crypt": "Enable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "1", "Take Screenshot option": "Disable", "Take screenshot title": "", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "remcos"} |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A1DB6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.google.com |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A1A1F000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://drive.usercontent.google.com |
Source: powershell.exe, 00000002.00000002.2415519775.00000298AFCC4000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000002.00000002.2385346725.000002989FE76000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000002.00000002.2385346725.000002989FC51000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000005.00000002.2526221910.0000000004D11000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000002.00000002.2385346725.000002989FE76000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.2385346725.000002989FC51000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000005.00000002.2526221910.0000000004D11000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://aka.ms/pscore6lB |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 00000002.00000002.2415519775.00000298AFCC4000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000002.00000002.2415519775.00000298AFCC4000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000002.00000002.2415519775.00000298AFCC4000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A19DF000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.googP |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A10AC000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1DB6000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.000002989FE76000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/ |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/k |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1CeREBSpXrrZMtDac8YKiGsgnAXZaGzYT |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1CeREBSpXrrZMtDac8YKiGsgnAXZaGzYTW |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1CeREBSpXrrZMtDac8YKiGsgnAXZaGzYTg |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1CeREBSpXrrZMtDac8YKiGsgnAXZaGzYTll |
Source: msiexec.exe, 00000008.00000002.2700386932.000000000832A000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1CeREBSpXrrZMtDac8YKiGsgnAXZaGzYTw |
Source: powershell.exe, 00000002.00000002.2385346725.000002989FE76000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1ziYxCjUvj99QtXQjBjAxMsemo3EX9D8jP |
Source: powershell.exe, 00000005.00000002.2526221910.0000000004E67000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.google.com/uc?export=download&id=1ziYxCjUvj99QtXQjBjAxMsemo3EX9D8jXR |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.googh |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1E4A000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com |
Source: msiexec.exe, 00000008.00000003.2654943529.0000000008398000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/ |
Source: msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000002.2700386932.000000000836C000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1CeREBSpXrrZMtDac8YKiGsgnAXZaGzYT&export=download |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A01EB000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1E4A000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.com/download?id=1ziYxCjUvj99QtXQjBjAxMsemo3EX9D8j&export=download |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://drive.usercontent.google.comseUr |
Source: powershell.exe, 00000002.00000002.2385346725.000002989FE76000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A10AC000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://go.micro |
Source: powershell.exe, 00000002.00000002.2415519775.00000298AFCC4000.00000004.00000800.00020000.00000000.sdmp |
String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://ssl.gstatic.com |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google-analytics.com;report-uri |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.google.com |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.googletagmanager.com |
Source: powershell.exe, 00000002.00000002.2385346725.00000298A00CE000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A09000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A1A05000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A19E4000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.2385346725.00000298A00E5000.00000004.00000800.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594346623.000000000839D000.00000004.00000020.00020000.00000000.sdmp, msiexec.exe, 00000008.00000003.2594629570.00000000083D6000.00000004.00000020.00020000.00000000.sdmp |
String found in binary or memory: https://www.gstatic.com |