| File name: | HoneCtrl.bat |
| Full analysis: | https://app.any.run/tasks/006d62bc-34f2-417f-a620-96712647f930 |
| Verdict: | Malicious activity |
| Analysis date: | January 25, 2022, 22:14:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ASCII text, with very long lines, with CRLF line terminators |
| MD5: | BCDD27350330B4841AF600A1FB01772F |
| SHA1: | 05AA9B55E12536FF3F796A4AE8FF4AF546383739 |
| SHA256: | B746E8EAFA06ED692F69F65CD84D46AE4328E5ABAB031603B71E99E9988389A4 |
| SSDEEP: | 768:5rAvUvvvvc0vvg7HS7awsnz44IAsUZqkbJJJJJBVJJJJJU459lnkbJJJJJBVJJJl:5DvQ4VAsUZMBSx7cIU/Omf |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | findstr /v /a:F /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " 3 " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 372 | findstr /v /a:06 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " ] " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 488 | findstr /v /a:06 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " [ " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 488 | findstr /v /a:06 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " ] " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 496 | findstr /v /a:06 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " [ " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 496 | findstr /v /a:06 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " ] " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 520 | findstr /v /a:F /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " 7 " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 584 | findstr /v /a:F /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " 8 " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 832 | findstr /v /a:8 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " [ press X to close ]" nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 960 | findstr /v /a:06 /R "^f7f81a39-5f63-5b42-9efd-1f13b5431005quot; " [ " nul | C:\Windows\system32\findstr.exe | — | cmd.exe | |||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Find String (QGREP) Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (2964) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASMANCS |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3964 | DllHost.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 2964 | powershell.exe | C:\Users\Administrator\AppData\Local\Temp\2cpn3y0n.dq3.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 1156 | powershell.exe | C:\Users\Administrator\AppData\Local\Temp\5z0zs415.dju.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2964 | powershell.exe | C:\Users\Administrator\AppData\Local\Temp\rgdweqik.r01.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 2964 | powershell.exe | C:\Users\Administrator\AppData\Local\Temp\Updater.bat | text | |
MD5:— | SHA256:— | |||
| 3964 | DllHost.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{d2ad2afd-e383-4443-8822-8f3a514fc37b}_OnDiskSnapshotProp | binary | |
MD5:— | SHA256:— | |||
| 3964 | DllHost.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:— | SHA256:— | |||
| 3304 | reg.exe | C:\Users\ADMINI~1\AppData\Local\Temp\REGF46A.tmp | text | |
MD5:— | SHA256:— | |||
| 3696 | cmd.exe | C:\Hone\HoneRevert\ ] | text | |
MD5:DF66FA563A2FAFDB93CC559DEB0A38C4 | SHA256:3E39ED22DC63246937C4DBBF34CE4FB1CFE6B00DE7596B020CAD49AE50031351 | |||
| 3696 | cmd.exe | C:\Hone\HoneRevert\ [ | text | |
MD5:DF66FA563A2FAFDB93CC559DEB0A38C4 | SHA256:3E39ED22DC63246937C4DBBF34CE4FB1CFE6B00DE7596B020CAD49AE50031351 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2964 | powershell.exe | 104.23.98.190:443 | pastebin.com | Cloudflare Inc | US | malicious |
Domain | IP | Reputation |
|---|---|---|
pastebin.com |
| malicious |