Source: | Binary string: n.pdb? source: powershell.exe, 00000002.00000002.1570309617.0000027957BF7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdbstem32\Drivers\DriverDataNUMBER_OF_PROCESSORS=2OS=Windows_NTPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSCPROCESSOR_ARCHITECTURE=AMD64ProgramData=C:\ProgramDataPUBLIC=C:\Users\PublicSystemDrive=C:SystemRoota source: powershell.exe, 00000002.00000002.1549666918.000002793D922000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdb source: powershell.exe, 00000002.00000002.1569227038.00000279578DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.Management.Automation.pdbourcG source: powershell.exe, 00000002.00000002.1569227038.000002795795E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000002.00000002.1570309617.0000027957BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb source: powershell.exe, 00000002.00000002.1570309617.0000027957BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdbat source: powershell.exe, 00000002.00000002.1569227038.00000279578DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: icrosoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000002.00000002.1569227038.00000279578A0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000002.00000002.1549666918.000002793D922000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: soft.PowerShell.Commands.Utility.pdb34e089 source: powershell.exe, 00000002.00000002.1569227038.00000279578DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\System.Management.Automation.pdbu source: powershell.exe, 00000002.00000002.1569227038.000002795795E000.00000004.00000020.00020000.00000000.sdmp |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://maps.google.com/maps?hl=en&tab=wl |
Source: powershell.exe, 00000002.00000002.1550248650.0000027941258000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nuget.org/NuGet.exe |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FAC2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E71000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940BD7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nzy3tvbb72g3.top |
Source: powershell.exe, 00000002.00000002.1550248650.000002793F8A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://nzy3tvbb72g3.top/1.php?s=mints13 |
Source: powershell.exe, 00000002.00000002.1550248650.00000279410E2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://pesterbdd.com/images/Pester.png |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940B41000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940B47000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002794079C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940B28000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.00000279407B5000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.00000279407AF000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940B54000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940B5B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schema.org/WebPage |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FC5E000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schema.org/WebPageX |
Source: powershell.exe, 00000002.00000002.1550248650.000002793F8A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0 |
Source: powershell.exe, 00000002.00000002.1550248650.00000279410E2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.blogger.com/?tab=wj |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940E71000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002793FC2C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/history/optout?hl=en |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/mobile/?hl=en&tab=wD |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/preferences?hl=en |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: http://www.google.com/preferences?hl=enX |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://accounts.google.com/ServiceLogin?hl=en&passive=true&continue=http://www.google.com/&ec=GAZAA |
Source: powershell.exe, 00000002.00000002.1550248650.000002793F8A1000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://aka.ms/pscore68 |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FC42000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794FB9B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F8B0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002793FC5E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002793FDB9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://apis.google.com |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://books.google.com/?hl=en&tab=wp |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://calendar.google.com/calendar?tab=wc |
Source: powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/ |
Source: powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/Icon |
Source: powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://contoso.com/License |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940E71000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002793FC5E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002793FC2C000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://csp.withgoogle.com/csp/gws/other-hp |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://docs.google.com/document/?usp=docs_alc |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://drive.google.com/?tab=wo |
Source: powershell.exe, 00000002.00000002.1550248650.00000279410E2000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://github.com/Pester/Pester |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://lh3.googleusercontent.com/ogw/default-user=s24 |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FDB9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://lh3.googleusercontent.com/ogw/default-user=s24X |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FC42000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794FB9B000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F8B0000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.000002793FC5E000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://lh3.googleusercontent.com/ogw/default-user=s96 |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://lh3.googleusercontent.com/ogw/default-user=s96X |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://mail.google.com/mail/?tab=wm |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://news.google.com/?tab=wn |
Source: powershell.exe, 00000002.00000002.1550248650.0000027941258000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://nuget.org/nuget.exe |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneget.org |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://oneget.orgX |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://photos.google.com/?tab=wq&pageId=none |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://play.google.com/?hl=en&tab=w8 |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FCCF000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://ssl.gstatic.com/gb/images/b_8d5afc09.png);_background:url(https://ssl.gstatic.com/gb/images/ |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://translate.google.com/?hl=en&tab=wT |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/finance?tab=we |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/imghp?hl=en&tab=wi |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/intl/en/about/products?tab=whX |
Source: powershell.exe, 00000002.00000002.1550248650.0000027940B5B000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/logos/doodles/2025/dr-martin-luther-king-jr-day-2025-6753651837110587.2-2x.pn |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/shopping?hl=en&source=og&tab=wf |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.google.com/webhp?tab=ww |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FDB9000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940E8D000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1565751136.000002794F912000.00000004.00000800.00020000.00000000.sdmp, powershell.exe, 00000002.00000002.1550248650.0000027940ED7000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.gstatic.com |
Source: powershell.exe, 00000002.00000002.1550248650.000002793FDB9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.gstatic.comX |
Source: powershell.exe, 00000002.00000002.1550248650.00000279402E9000.00000004.00000800.00020000.00000000.sdmp | String found in binary or memory: https://www.youtube.com/?tab=w1 |
Source: C:\Windows\System32\wscript.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: jscript.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrobj.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: scrrun.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: edputil.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: windows.staterepositoryps.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\wscript.exe | Section loaded: onecoreuapcommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: atl.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appresolver.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: bcp47langs.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: slc.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sppc.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: linkinfo.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ntshrui.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srvcli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cscapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: policymanager.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msvcp110_win.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: taskflowdataengine.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cdp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: umpdc.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dsreg.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptsp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: onecorecommonproxystub.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: vcruntime140_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ucrtbase_clr0400.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rsaenh.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: cryptbase.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: amsi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msasn1.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: gpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msisip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wshext.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: appxsip.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: opcservices.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: secur32.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iphlpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dnsapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dhcpcsvc6.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: dhcpcsvc.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: winnsi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasapi32.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasman.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rtutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mswsock.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: ondemandconnroutehelper.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: rasadhlp.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: fwpuclnt.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: sxs.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: mshtml.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: iertutil.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: powrprof.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: urlmon.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | Section loaded: msiso.dll | Jump to behavior |
Source: | Binary string: n.pdb? source: powershell.exe, 00000002.00000002.1570309617.0000027957BF7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: System.Management.Automation.pdbstem32\Drivers\DriverDataNUMBER_OF_PROCESSORS=2OS=Windows_NTPATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSCPROCESSOR_ARCHITECTURE=AMD64ProgramData=C:\ProgramDataPUBLIC=C:\Users\PublicSystemDrive=C:SystemRoota source: powershell.exe, 00000002.00000002.1549666918.000002793D922000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdb source: powershell.exe, 00000002.00000002.1569227038.00000279578DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\System.Management.Automation.pdbourcG source: powershell.exe, 00000002.00000002.1569227038.000002795795E000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\Microsoft.Net\assembly\GAC_64\mscorlib\v4.0_4.0.0.0__b77a5c561934e089\mscorlib.pdb source: powershell.exe, 00000002.00000002.1570309617.0000027957BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\mscorlib.pdb source: powershell.exe, 00000002.00000002.1570309617.0000027957BB7000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: softy.pdbat source: powershell.exe, 00000002.00000002.1569227038.00000279578DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: icrosoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000002.00000002.1569227038.00000279578A0000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: Microsoft.PowerShell.Commands.Utility.pdb source: powershell.exe, 00000002.00000002.1549666918.000002793D922000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: soft.PowerShell.Commands.Utility.pdb34e089 source: powershell.exe, 00000002.00000002.1569227038.00000279578DF000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: \??\C:\Windows\dll\System.Management.Automation.pdbu source: powershell.exe, 00000002.00000002.1569227038.000002795795E000.00000004.00000020.00020000.00000000.sdmp |