Static | ZeroBOX

PE Compile Time

2095-03-23 04:07:38

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0006ade4 0x0006ae00 7.99150610058
.rsrc 0x0006e000 0x000046f0 0x00004800 2.53508667097
.reloc 0x00074000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006e100 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x00072138 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0007215c 0x00000394 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00072500 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
z`W+63,
.6\^xr
7~wX_M
b?MTEp
PH1/mouO
#hLjLp
5gz?$3
R8gWp2
9w/nwb
<=k{/BG
vO)Ey]
l3qEU2
1 |\@u
A#kliHV
}'8oW8
axC438
hzQ[0G
KneBF3
,9|-H>
}=8]@2.
H=evA)l
^-6_+St
v`aAk)W
z3)@4
tw _LY
tLAcM.a
7yNY1a
# >SV>IR
R|G-E1
*=]Du`\
:)XgU0ru
$Lt0_"
UHraqS
z6~\Gf
t, ^M>
L6z/+l
Mj!z.60r
vJPXX&
(?R6}N:
@iY9<L
. as9jO
[zuvVJ
C>NVA|]=
S*VIp6
>?u'gr
%Fl}<b't
z;|%h\?
\B,<w{
(.-VL;
Sc%0Jb
&KPNU|
a&#s X=
Abv\6>
s#.>1K
v+hLE*
LJ4dRC
U"[E6D
+4MVtL
}?z/}g/!
R)|=$7
bU@m{}
/DN|YK!
6\4/?B
{mJY=fGd
rx?&/CL
DwuRnH>/bG
Vx"Ma8\L
S+Q;Ue
V;l&#L+
)| 1U4
Me3%/~
u_ZZ3=?
Ob3L}TL[
+[oLeD
fK{Vx>
Bg{\ub
_VZj520\
U_aE71L
xIQE2U3
K#mt4i
fIw31T{
49d+sm
"gOGE\+pc
F!&+3%
6)X2I
uDrD2q
SpeTOSv
.5meh|
or$knJ
>ojEPw8
edyqos;
u/1yw8
*hT^J&
C-hu-(
A{r-8
73$c0H
&s C_k@
^%K~nU
*x>6EF
c'GCN1
aXLy#t
m\pY'~
qcLL-p
|SKwV/
{.;K)j]
IV8w`x0H
Yh/}1hB
K?M>W>
]|3O?^
_^ht<Y
p8.{QY
k5M?DN
_AknZgZ3
|%&RAJp
e46egxY
'zZ56YNq.o
KJ:4"p@M
?PwinJ5
13m]1{T
7vG%07
RlH%X/.
x>fHLX
SE!SVu
pMP<-~
(ZD1aE
@0;[=+
7DT#Ct
f\Zp$cN3
CnwDII
Zo|_6I
Wm0UkeS
s<N# Jf
SCz[i[|
lO"h?(
c5:6.J
oagjsMB\
)@a`f(G
u,<M,?UQ
I+^GVz
,R8W!h
nX6Cpv
F4[oS?
<.@*7Y
y8gy8g
qj}8gW
BL37f;e
/:@+^"
dW/J[@
5U+_sW?c|7
N4Avh:
HXb^WO
`pqlw"
ZoZtd3
I7|#]=
2m@NL>6
4I*>k|-
bb\ld'
:Gcz;>
^rF@kDJ8r
UMQL6@&
k(Q;D/
/Dqu>n
u+cmlTk
%[f9&HH
K/`<]YK-
(g{J?R
P J1N[
4D"8{B
+'Jms@
QCQ\Y.
KD1";V/
Sl^4*}
B{\!C[
Bv\,!=
I:Em06
5B@z%!
%|B{Bo
5Ov95k
SW~3"oNU
By#y<F
c-\R,
tX_M.e
{P^#.O
S\2G\8b8
\5@}7Z
92_/7_
sY^`~y
F+>")~K
7`=o)
k}?q./
n\(a_?
I.e>nH
?Niencn
hok6nJ
cvT|W"
;fb|?9}f
?YOy|B
C|ZkL!
*9^17Q
F1ysgu
2.a}u $n
60;OP
Xdx_VY"
4rV)V^
/%5/pO
y_gy72
x|/7ANa
y2ris|
9[oV+X@
H`WL/v
R}!|ijO^
$)#GZ|4&YQGY|!&E
ZR`oR@
HgBV7X
p^'MOD
An\{:/
S;;C;`
cwy{pg
<}^^|=
&fPSyU$*h
a\nGoG
3d<&JZ
2SnUaYR
=?6xfW
z>2Gz[
1*FzM^
Y/|v?<
|kH?u0
)r?0Wx
\c,IcI
'`o4v'5
Hx#:B:S
|{Hg+|
C7r_u#
w`OaOc
,Z=N>0
/)l.\Rxb
7'}=)#?7
X^\^Y>
,{]v]n
6YI>$]
js<=v|JH
}oy=!'
p@r9P%'
;P%CIOBW
Id x>P%.
wSH1P%e
b\[%[qU
(P%-Yc
k>qc4ZD
Je/4W*
94W+_Bs
r*47(K
cTFIF4co
}QtBq~
Kp4+w
kqxq,F
\\l..1
$qKR I!%
7--(."
BWIYEAYUM1
4RTZTR]]XY]VZQ
SQUXVT
M,w+"-h
!ij6z#
`KWr@Ss
$*hmBT,
i5*ExC
gRwjZ>t
y|BA,7
LJJ/9Z0F
Mq!]$e^
h9=&||
z&$Mm2
*qDo%m
\mfuE}21
f"v^M>
r),EWg
*Y8y<
$ks8sSj
3($"sA0
d:o(hA T
<ZN4QJ
NPeiH%
]E]y9+-
B>7T2{Q
I~ya3)yE
7]Kx/K
_<Q?'3
Fb Yv$K
L>5/.g
3lkB|
|nHF>n
ok%CYg
`q[gNf
milwYvjl
o<PFiAw
GEj4.
+z.v>P
ZS9>2o
1|Q|wC
ECvyfBY
3]|2tsvP
-znd{_
&iz;NeZ
NxYibo
/MA$:O
4;B9o3
;=e6#$V
L,7sWH
3I25.I
n.D_n\4
sr#0$l
]oX$w
?JMz3Y
'i@'i1,
YpB.YL
U8("pdm
5qI7^A
!6zICh
9;@lzdF
i<xC 4
>t7;t{~g
"wz!gz
h!]i'T
;V`aan
c"dX%e}^g
/hU?(j/
2:9!^:;
zG&n<fJ[
KOt+]K
}t5P?*
Y%BWxBW
C01'mG
!n88<8
ed(.#Ej
(|ha^nx
a-t0L(
; ;;ovrqvQV~
U_ch7c
N+lLkj
VP@HBDC
M%s|^N>
KbF2#H8
~b$TCo
@6Yxsd
bsSN_>
jB6^m}v
kw&/ox
D=>7mP
iQ<~H8r
F7\F7lWK*
]/.SCl
}u-.sG
h9E,Mn'`
J(\Ca6
fHCR"2
N05Z*%
pntXT`(
dq`(5v
cqX">)"
dJ@M\.
O$fB$A
NUXP>z
@< ,<2*P
:E^QGY
abnR}c
;;2^P9
ncC'n\L
4iS,c
b){J$c
;6hF^w
\\W|]fw%
]Fg-Io
<V8=gl
O(~('{:
G)?fNU
gW;K[<
KS>G~n
|x2)gH
6(XX0n
v=T^}S
n]H^!S
uny%{<
Z ix`L
Q#(qB54
JE_$=0h
yjJE><
l~dd}v
6-v~zt9
'dI4+x
L'z^K<
I5Gg72
3M\653
]k#s01
d.yp=5
Vn#AM
?A]>Iig
|=bXl:J
fPTb?D
]z~(/mr
f3JkG8
vzh(49b
~OPop']-
;7p{^;
.3]\h
WAmk:Y
zu3\gQ'
b9/BO
$+NSffz
>k[ivR
3gN/s&
j28 :`nz
IrZA2K
x)HrCm
;Q]nC|
}GymJut
)jVjv>
XO$VOV
>ZeWqC
.@Us&q
qEs8.W
'#I?k8'6k[
|HS+bL
)ehV6
zC,wD;
+JSL]7
cG\P\?
6K.*]<
Xw+`5^
xAOO<l
+0BXq|
RLg^su
6<c^=.7
|Z"/Y|
qzTeM7i
;Wz]#m
b,Y'C@
ecWXAu
`sKw/5v
W&wt%/
aD_- ioQ
,%'M[?u
N'"Oo=
$/m|yi
0Jwh)
C`_3VXb
^L-[9%
WXb6gQ
|gH7z3
:Q!&$F
OU7Kl{
[VcHXs
K8bUUDF
]kn7JgT
e}S?Zu
;Ij&igH
)`c6e
ILi]0$U
<UR>m.
&B/@s(
}k%_(v
)//E8WA
BrQ_*
6 U`?!
ma~tC
J`]x8%o
@O+VG;
E+i,F
+paCt?4l
E!PQn`
))h&g)
+@z"9o
dF^j">
'7 bss
,?8@^4
yzvIbv
3vZ\n`}
`F\ [0
H=2;H"
%N0`n+A
@e})YO-
dV>B<7!`@
$0lN|N|
Y}N<,B
Vhp]ClFZ
``}*t9
0+mJ&
"sWAo
65Tk?D
U5FkxW
w;~\qdD
G )V^J{T
%-wjA{?0
vP!*%|
,p00((0
{em[j
kJ:6o~
d)Ld\+
/zFC??cI
hYyJ<*Y(
5T,bWI
-Vc+~)9
kjM"avU
?G)&:L
i'$(3G
ToK]Woz
jhm_$*8
G7-2=>
bU;)`1m
XnX${+
D9m)hZ
qBugwTE
(b^^]x
n"Be"b
fc!rPV3
='#@O"
5K9`U]^
+RC98Y
6TNB/%?
#&v?3^,p$Z
xCt]vs?
{U{3~.
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
[Z58=1u
pCFd$k
CF)440
Pjlfrv:
{0xepE
s(T|qFC
K]OIRsr
}!@&=R
6|^LRv
5i<NfS
zTcy-|
hd&}n8m
Vut+$tFOF
W61/|xy
5?q1|Lq
%J&j'
LyNv>H
4/u3DYM
-3%2n:
>fq}3|%
6n:0Yz[_(
:QG/78
8NCqlf
Cl*70wTHTn
-[s[?!
O1=;u
m7hobXj
.O)KvG
$)>m?!
<WYi=W3
A0,aKz
}F0,fKR
alz2J=
*MA0,eKR
/|\(=[LIqaW
PiM 5lI
b6+5h
@&qBk$09q
tm#4B=
:>~`(+
/>+cVGE
8fp%kn
Z.9C9E
>LJ1)m
6I5o;<,;
a4DU>g
V~-BV#
G5RP8$
'cdL^N^x>
$0w<-U
H}Olq
~#e6I!L)
aJSg{<
s?,Yuk
Rig;Ri
2MXFU3
yE_s|W?:
3fPQ"E{
mE{]u6
Y%Zy&8[
6|#$0vM
QWwN?r
oy/;8n
O=>jj"
sFLpP[
Y\'Gw4s
4B3~c~=
`)QVv)
%0!=*B
_6U[DM
0>yCL
jHEn^h
$]f4K/
WYk&^>
+:sqc4
pK'{%.
'<.px#Z
$+C^x}
062I`C
P#BsI,
=G<;zO
NTTMjC
Tk>TW6
]`}\@TA
Y!gyy,
U*}Ol%fA|
69Ugil
9P-SF]
v.nz\*
Td$T?M
m7j%S
Rol;F{LA
/{)kd[<Y+
#XL(t
?@.RKZ
"K:T$W
9aYU?jW
V-CB_+
+#fI'D
%<u[62
J*'Y.<
;"2<&Y
O?7z_l
:]"UQ[
?WU%,Z
a;d*]u1
d72]oo
yU$'qJv
8ZKluw
RRkwGzf\
&|#kCJC
*(H[jP
}|)2i'
3+[_o]
K9|W~ECbhU^
(dVfNK~
#mB=]%
(Ao%cU
e6RE-&
3[D4]{]i"
fBVUW|
A(j\DH
F3I7UeomjO;2894NAy
UG lbx~
0R[3mr
bb"b3t!
A-mlYGk
]@y^ts3
v4.0.30319
#Strings
<>p__10
<>p__0
<>p__11
<>o__1
<>p__1
IEnumerable`1
CallSite`1
<>p__12
<>p__2
Dictionary`2
Rohsqxgu2
<>p__13
<>p__3
Func`3
<>p__4
Func`4
<>p__5
<>p__6
<>p__7
<>p__8
ConsoleApp19
<>p__9
<Module>
System.IO
Costura
Ifnyrmggsa
Rohsqxgu2.Nlpnigb
mscorlib
System.Collections.Generic
Rohsqxgu2.Kanumlcfroc
Thread
isAttached
Interlocked
costura.costura.dll.compressed
costura.rttzaxsnhmitfl.dll.compressed
costura.newtonsoft.json.dll.compressed
ReadToEnd
set_Method
source
CompressionMode
Exchange
nullCache
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Name
fullName
GetName
requestedAssemblyName
WriteLine
ExpressionType
set_ContentType
System.Core
culture
HttpWebResponse
GetResponse
Dispose
Create
CallSite
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TryGetValue
add_AssemblyResolve
CurrentDomain_AssemblyResolve
ConsoleApp19.exe
Rrohbgwqjjkbf
System.Threading
System.Runtime.Versioning
CultureToString
Attach
get_Length
EndsWith
Rohsqxgu2.Wstngsdpi
Varczykj
nullCacheLock
Animal
Rttzaxsnhmitfl
numTail
ReadStream
LoadStream
GetManifestResourceStream
GetResponseStream
DeflateStream
GetRequestStream
MemoryStream
stream
Program
set_Item
System
Yqvlnchbfn
AppDomain
get_CurrentDomain
FodyVersion
System.IO.Compression
destination
UnaryOperation
BinaryOperation
System.Globalization
System.Reflection
set_Position
Exception
Newtonsoft.Json
StringComparison
CopyTo
get_CultureInfo
CSharpArgumentInfo
Rohsqxgu2.Pztofo
Microsoft.CSharp
GetMember
StreamReader
TextReader
AssemblyLoader
sender
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
ResolveEventHandler
StreamWriter
TextWriter
.cctor
Monitor
Fvmcvjmzzsvuas
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
ReadFromEmbeddedResources
DebuggingModes
GetAssemblies
resourceNames
symbolNames
assemblyNames
get_Flags
AssemblyNameFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
ResolveEventArgs
get_TotalAnimals
set_TotalAnimals
totalAnimals
Equals
GetNumOfTails
System.Linq.Expressions
Concat
Format
DeserializeObject
System.Net
Target
ToLowerInvariant
JsonConvert
GetNearest
HttpWebRequest
Rohsqxgu
ToArray
ProcessedByFody
ContainsKey
ResolveAssembly
ReadExistingAssembly
GetExecutingAssembly
ClassLibrary
op_Equality
op_Inequality
IsNullOrEmpty
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$370d3e62-f1a9-44ab-bf37-184c104473c5
2.7.4.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
040101000000Z
281231235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
HCgNr*
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA0
191007000000Z
221006235959Z0
943491
Private Organization1
Dubai1
Dubai1;09
2Business Central Towers, Tower A, Office 2301 23031
Telegram FZ-LLC1
Telegram FZ-LLC0
https://sectigo.com/CPS0U
Dhttp://crl.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crl0
Dhttp://crt.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crt0$
http://ocsp.comodoca.com0#
AE-943490
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
141203000000Z
291202235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA0
=U5W5H
https://secure.comodo.com/CPS0L
;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
http://ocsp.comodoca.com0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA
20210428095006Z
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #2
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210428095006Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
>ABCDE
Rohsqxgu.Rttzaxsnhmitfl.dll
Cat has {0} tail.
Dog has {0} tail.
Zoo has {0} animals.
http://us1.unwiredlabs.com/v2/process.php
application/json; charset=utf-8
{{ "token": "{0}", "radio": "gsm", "mcc": {1}, "mnc": {2}, "cells": [{{ "lac": {3}, "cid": {4} }}] }}
status
balance
accuracy
message
.compressed
costura
costura.costura.dll.compressed
newtonsoft.json
costura.newtonsoft.json.dll.compressed
rttzaxsnhmitfl
costura.rttzaxsnhmitfl.dll.compressed
6.0.0.0
4.1.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
ConsoleApp19.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
ConsoleApp19.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Elastic Clean
DrWeb Trojan.PackedNET.835
MicroWorld-eScan Trojan.GenericKD.46468610
CMC Clean
CAT-QuickHeal Clean
ALYac Clean
Cylance Unsafe
VIPRE Clean
AegisLab Trojan.MSIL.Seraph.a!c
Sangfor Trojan.MSIL.Seraph.gen
K7AntiVirus Trojan ( 0057ddc11 )
BitDefender Trojan.GenericKD.46468610
K7GW Trojan ( 0057ddc11 )
CrowdStrike win/malicious_confidence_90% (W)
BitDefenderTheta Gen:NN.ZemsilF.34738.Cm2@aaN4yje
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABKG
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0PFB21
Avast Win32:CrypterX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Trojan-Downloader.MSIL.Seraph.gen
Alibaba TrojanDownloader:MSIL/Kryptik.194c4d11
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Trojan.GenericKD.46468610
Sophos Mal/Generic-S
Comodo TrojWare.Win32.Agent.colei@0
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro TROJ_GEN.R002C0PFB21
McAfee-GW-Edition GenericRXOG-DJ!2648886DBD37
FireEye Generic.mg.2648886dbd37ccc2
Emsisoft Trojan.Crypt (A)
SentinelOne Clean
GData Trojan.GenericKD.46468610
Jiangmin Clean
eGambit PE.Heur.InvalidSig
Avira Clean
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Trojan.Win32.Downloader.oa
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Script/Phonzy.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee GenericRXOG-DJ!2648886DBD37
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.100%
Panda Trj/GdSda.A
APEX Malicious
Tencent Clean
Yandex Clean
Ikarus Trojan.Inject
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.ABKG!tr
Webroot W32.Trojan.Gen
AVG Win32:CrypterX-gen [Trj]
Cybereason malicious.815602
Paloalto generic.ml
Qihoo-360 Clean
No IRMA results available.