Static | ZeroBOX

PE Compile Time

2078-06-04 08:54:04

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00067634 0x00067800 7.98912034796
.rsrc 0x0006a000 0x000046f0 0x00004800 2.5348021054
.reloc 0x00070000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x0006a100 0x00004028 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_GROUP_ICON 0x0006e138 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x0006e15c 0x00000394 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0006e500 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
z`W+63,
.6\^xr
7~wX_M
b?MTEp
PH1/mouO
#hLjLp
5gz?$3
R8gWp2
9w/nwb
<=k{/BG
vO)Ey]
l3qEU2
1 |\@u
A#kliHV
}'8oW8
axC438
hzQ[0G
KneBF3
,9|-H>
}=8]@2.
H=evA)l
^-6_+St
v`aAk)W
z3)@4
tw _LY
tLAcM.a
7yNY1a
# >SV>IR
R|G-E1
*=]Du`\
:)XgU0ru
$Lt0_"
UHraqS
z6~\Gf
t, ^M>
L6z/+l
Mj!z.60r
vJPXX&
(?R6}N:
@iY9<L
. as9jO
[zuvVJ
C>NVA|]=
S*VIp6
>?u'gr
%Fl}<b't
z;|%h\?
\B,<w{
(.-VL;
Sc%0Jb
&KPNU|
a&#s X=
Abv\6>
s#.>1K
v+hLE*
LJ4dRC
U"[E6D
+4MVtL
}?z/}g/!
R)|=$7
bU@m{}
/DN|YK!
6\4/?B
{mJY=fGd
rx?&/CL
DwuRnH>/bG
Vx"Ma8\L
S+Q;Ue
V;l&#L+
)| 1U4
Me3%/~
u_ZZ3=?
Ob3L}TL[
+[oLeD
fK{Vx>
Bg{\ub
_VZj520\
U_aE71L
xIQE2U3
K#mt4i
fIw31T{
49d+sm
"gOGE\+pc
F!&+3%
6)X2I
uDrD2q
SpeTOSv
.5meh|
or$knJ
>ojEPw8
edyqos;
u/1yw8
*hT^J&
C-hu-(
A{r-8
73$c0H
&s C_k@
^%K~nU
*x>6EF
c'GCN1
aXLy#t
m\pY'~
qcLL-p
|SKwV/
{.;K)j]
IV8w`x0H
Yh/}1hB
K?M>W>
]|3O?^
_^ht<Y
p8.{QY
k5M?DN
_AknZgZ3
|%&RAJp
e46egxY
'zZ56YNq.o
KJ:4"p@M
?PwinJ5
13m]1{T
7vG%07
RlH%X/.
x>fHLX
SE!SVu
pMP<-~
(ZD1aE
@0;[=+
7DT#Ct
f\Zp$cN3
CnwDII
Zo|_6I
Wm0UkeS
s<N# Jf
SCz[i[|
lO"h?(
c5:6.J
oagjsMB\
)@a`f(G
u,<M,?UQ
I+^GVz
,R8W!h
nX6Cpv
F4[oS?
<.@*7Y
y8gy8g
qj}8gW
BL37f;e
/:@+^"
dW/J[@
5U+_sW?c|7
N4Avh:
HXb^WO
`pqlw"
ZoZtd3
I7|#]=
2m@NL>6
4I*>k|-
bb\ld'
:Gcz;>
^rF@kDJ8r
UMQL6@&
k(Q;D/
/Dqu>n
u+cmlTk
%[f9&HH
K/`<]YK-
(g{J?R
P J1N[
4D"8{B
+'Jms@
QCQ\Y.
KD1";V/
Sl^4*}
B{\!C[
Bv\,!=
I:Em06
5B@z%!
%|B{Bo
5Ov95k
SW~3"oNU
By#y<F
c-\R,
tX_M.e
{P^#.O
S\2G\8b8
\5@}7Z
92_/7_
sY^`~y
F+>")~K
7`=o)
k}?q./
n\(a_?
I.e>nH
?Niencn
hok6nJ
cvT|W"
;fb|?9}f
?YOy|B
C|ZkL!
*9^17Q
F1ysgu
2.a}u $n
60;OP
Xdx_VY"
4rV)V^
/%5/pO
y_gy72
x|/7ANa
y2ris|
9[oV+X@
H`WL/v
R}!|ijO^
$)#GZ|4&YQGY|!&E
ZR`oR@
HgBV7X
p^'MOD
An\{:/
S;;C;`
cwy{pg
<}^^|=
&fPSyU$*h
a\nGoG
3d<&JZ
2SnUaYR
=?6xfW
z>2Gz[
1*FzM^
Y/|v?<
|kH?u0
)r?0Wx
\c,IcI
'`o4v'5
Hx#:B:S
|{Hg+|
C7r_u#
w`OaOc
,Z=N>0
/)l.\Rxb
7'}=)#?7
X^\^Y>
,{]v]n
6YI>$]
js<=v|JH
}oy=!'
p@r9P%'
;P%CIOBW
Id x>P%.
wSH1P%e
b\[%[qU
(P%-Yc
k>qc4ZD
Je/4W*
94W+_Bs
r*47(K
cTFIF4co
}QtBq~
Kp4+w
kqxq,F
\\l..1
$qKR I!%
7--(."
BWIYEAYUM1
4RTZTR]]XY]VZQ
SQUXVT
M,w+"-h
!ij6z#
`KWr@Ss
$*hmBT,
i5*ExC
gRwjZ>t
y|BA,7
LJJ/9Z0F
Mq!]$e^
h9=&||
z&$Mm2
*qDo%m
\mfuE}21
f"v^M>
r),EWg
*Y8y<
$ks8sSj
3($"sA0
d:o(hA T
<ZN4QJ
NPeiH%
]E]y9+-
B>7T2{Q
I~ya3)yE
7]Kx/K
_<Q?'3
Fb Yv$K
L>5/.g
3lkB|
|nHF>n
ok%CYg
`q[gNf
milwYvjl
o<PFiAw
GEj4.
+z.v>P
ZS9>2o
1|Q|wC
ECvyfBY
3]|2tsvP
-znd{_
&iz;NeZ
NxYibo
/MA$:O
4;B9o3
;=e6#$V
L,7sWH
3I25.I
n.D_n\4
sr#0$l
]oX$w
?JMz3Y
'i@'i1,
YpB.YL
U8("pdm
5qI7^A
!6zICh
9;@lzdF
i<xC 4
>t7;t{~g
"wz!gz
h!]i'T
;V`aan
c"dX%e}^g
/hU?(j/
2:9!^:;
zG&n<fJ[
KOt+]K
}t5P?*
Y%BWxBW
C01'mG
!n88<8
ed(.#Ej
(|ha^nx
a-t0L(
; ;;ovrqvQV~
U_ch7c
N+lLkj
VP@HBDC
M%s|^N>
KbF2#H8
~b$TCo
@6Yxsd
bsSN_>
jB6^m}v
kw&/ox
D=>7mP
iQ<~H8r
s0][l(F
[l\<hJiP
@0I?;U
Cm_Jm_o
3Ck81Z
#hv]W&
ki;h*X*
s)|Ba'
8gp$<
"\@@?G
R\.OHrxLB
8<!W
eEGou@V
bb&zpy
;]t~r~
hoSy*}~
OOGZ^(
[C.5_)
*k]3oK
<q4 F6#
Y}"vFW
,N|4(5>
nyVc[]=
+8>J5&
U<f*3j
,:j:.'yb
Raz/zQ
%O^/|_
y/msKn
=;~3mL
)#[)nC
MGVol<{
:|6F{Y}
CC37(p
wW&{Wv
kC\mt+
CKm-{v
9:p?G+
s=I!|&
T}+mO?
.!/NI b:@
il3i4v
JLz|x7
t>Uz1,Q
YbXV@EQQ
bebhF0
iQS>}d
/q$Sl"((
yx}bYZ
l"qu\u
/L~]j#
;-g^c3dnm
'e0h[6
''Nq+nI
[m+fv<d
2A'WBh
+uh8Zj>
3*SGOa
<~4QS^
5rnWYa
&M)NY
VF\F{
J7/P@;
yzmqySF
yp/e`H=
T~fOMu
cFdsF_x\n
7/uv[
%`"\I_W
F"3UsE
N#F5x*
D[`IaK
bgM_/0
;i3~(Y
`fs5<g
etnc7b
m[}[Vn
oub(kI
84|X8q
drS/sE
Ju$rJw~k_S8@
E=W2h}
Nb9u@m
'r/En4
trN:T/
zTXm-qv+k<N
\~?nYmk
khrql{T
?@O*r@Z
}jNl6N
Y8+Q3Qh
lh8mk0<
;o_nl2r
#XQI6(
jyzDXF
kP,G%;
KewIfD
dH.}J#oD
6^yxam<+s
q<P}Z1d
.p1q+c
psoyo6
[)4|ysG
r;{P{C !ln
MS2SfM@9(ZMC2R4
|0Bq,
zil0M5
:Xd0_f[
=@>`"!x`w|
yjZv@J
Hug#o1
9q.sf@hp,
1tv+Z'
xQ~pQq/
pcCrNx
n!j,MJ
#'y^R}UR
.T`7y6
.OZg+
xUixpDT
Qt&]31S
z>i@zTU
CvzlTM
iF8lg1,
rxZU}{
hn_=<n
Oe_I3{
>~BM^F^
F5(6s!
H|r@GH
TqOC!F8
7RC)2|
FgC ;7
cx<5(~
[3j'-g
d@=ghe{
:;y>GO
>wTpJL
Y\+R&;k
y`2+&!p<+
w tWw
C$am1w
{\~\)p
c59kTH=
8]$C3'
|3GyL{
060;K2c
L4Zr+#
k~4B&7
qHf]IF7)
k`xulPE(
[YHV7~2)
@Wjx4f7
XL/`6c
<k>.6[D
w3+U}Kn
.$b6btz3
z9Yu;2
2VJ-dO
S`e\\V
w8O7b)
sBVU9!m
WL_\5H
hX1,$Y
Q7Nl2-W
dEn~<P{g
iVOkX7
C5sF]Ey]
!JxRx@8
+cTouv
%bAKR{
0]}cCO?
Q??v8O
J"OZ,P7
]`T|nx
Ye_ d}
FGv&7>
Uj8[b}}=
|~LXI8
KM$7/59
LT:{/0Qqx/
dz/7Qy
qD)<F@9q#}
InJ$MJ
**>wAq
N9\>G@
]~R@{FT
<U~]@'
|F@71h
\+Z&Fo*
~SyZ~E@?
jOb%kX
OAye?*
Gy}?j?
LckLsY>
(W:@Y'
Yyg!?,o
3Lj(Z_Y'
alV;;1
HDKjaQ1
I/&rAT
GNyf:)
}G{WLM
xF'g+Q91
N~r|Y4
JQHl["
bb>BPt<lSR
BU;0Hf
\SjzW,6#9
)PC,JZE
6~uJ!7
$mA:Dn;I@
E/Fha:
/:e.62M
;$Rsx oj0
BLa}P{/
.xwDGPc
;c16Yq`
a4M|0d"j#
0xjqT>&TN
mE5&to
2jYRcRt
\3=fpi
-Ts-%w
d%D26}$
GBZd#{Iz$
(0S5yi
~]o[rd
31|zy{
SM[_|`
gwWWwW
j|\:%3
_'wf!OO
5%-2D;p
:b+L01
x7)cb/
|]5'RP
?xSHUW
}G"T[:x)
)z6>G{
J'K^kG
pi?efU
kO:O[7
y }OPX
GGGllL,
~LG@5W
opSPlt
`fvd,+
0d76+[
b,#(H[
C:E4)=xh
A/ZZQw
mbE"nz]
T<Uv%I
j.0/5Ep(
an?{..;f
(FiP#qBz
9Tx%Qsi
cKW$PY6'
XxX3GHW
?kT2&,@5
c?HYWi
bQ9-b6i
>YhWOXC
m[F"~(;
{ ,a._7
jB,SF3
s!IunL
XaQpiE
yL]SEW
yHw=k@~
qxNv1j
!TujT#
+y,#.=
>-$N>dY
WYv*A^
m;JRmkzkWA
XeSq0A
BXfLXK4
@ELHKH
( ~H$G
SBzG!+%d
Pji $n
v]_t<.J
\O&6UT>gY
H,P;y/q7
U~M##>
6D+Z;K
!wwdxI
r,>gN'
:1B+ss
et%h1z
CcGYZ[
|0>}J8
rkI{L+z
_\b~3!l"
5@+(c'
D1 .ls
yQTnG@
AobeT@[
umIM]Cf
2z O]<pT0
L<m{QZ
s%#?zc
1CeN3d
*a<En"
,|(0c"
AJeA4}
00SMe]"
d<+MvZ
WYI*+9
]Ki;K8*J
W.W'=S
X-Sf)g
:]OnOM'U
IG~"&#O^
Zgr>>>
dzNN.sR
KHUkB*}A
ivKDfZ
c3}qzo^
4l[C;s
mbZfHp[Y
:+-"Ge
.ZMh@r
4|V^PO&/p
)_TIC(
6EW{wld/
6<.^6Xc
Y|s1{k
Z.6sD
bi_e?`
P)I6v:
v0$Pmy
;1D^Xr
^I.?lm;
yIo!&$
v4.0.30319
#Strings
<>p__10
<>p__0
<>p__11
<>o__1
<>p__1
IEnumerable`1
CallSite`1
<>p__12
<>p__2
Dictionary`2
Nwnewogfecxuee2
<>p__13
<>p__3
Func`3
<>p__4
Func`4
<>p__5
<>p__6
ConsoleApp17
<>p__7
<>p__8
<>p__9
<Module>
System.IO
Bahogpgea
Lkwkitvhpa
Costura
mscorlib
Nwnewogfecxuee2.Wybpxykub
System.Collections.Generic
Thread
isAttached
Interlocked
costura.costura.dll.compressed
costura.ymdnfmwbadejj.dll.compressed
costura.newtonsoft.json.dll.compressed
Aomonkibgd
<x>k__BackingField
<y>k__BackingField
ReadToEnd
set_Method
Nwnewogfecxuee2.Lzkvzpvlprqtd
source
CompressionMode
Nwnewogfecxuee
Exchange
nullCache
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
Console
get_Name
fullName
GetName
requestedAssemblyName
WriteLine
ValueType
ExpressionType
set_ContentType
System.Core
culture
HttpWebResponse
GetResponse
Dispose
Create
CallSite
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TryGetValue
Nwnewogfecxuee2.Crackve
add_AssemblyResolve
CurrentDomain_AssemblyResolve
ConsoleApp17.exe
System.Threading
System.Runtime.Versioning
CultureToString
Attach
Mnrpxih
get_Length
EndsWith
Ymdnfmwbadejj
nullCacheLock
Animal
numTail
ReadStream
LoadStream
GetManifestResourceStream
GetResponseStream
DeflateStream
GetRequestStream
MemoryStream
stream
Program
set_Item
System
Xwofybhyvlnm
AppDomain
get_CurrentDomain
FodyVersion
System.IO.Compression
destination
UnaryOperation
BinaryOperation
System.Globalization
System.Reflection
set_Position
Exception
Newtonsoft.Json
StringComparison
CopyTo
get_CultureInfo
CSharpArgumentInfo
Uwpovo
Microsoft.CSharp
GetMember
StreamReader
TextReader
AssemblyLoader
sender
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
ResolveEventHandler
StreamWriter
TextWriter
.cctor
Monitor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
ReadFromEmbeddedResources
DebuggingModes
GetAssemblies
resourceNames
symbolNames
assemblyNames
get_Flags
AssemblyNameFlags
CSharpArgumentInfoFlags
CSharpBinderFlags
ResolveEventArgs
get_TotalAnimals
set_TotalAnimals
totalAnimals
Equals
GetNumOfTails
System.Linq.Expressions
Concat
Format
DeserializeObject
System.Net
Target
ToLowerInvariant
JsonConvert
GetNearest
HttpWebRequest
Nwnewogfecxuee2.Uyduuwewqmut
Uxxwqlu
Nwnewogfecxuee2.Kjplexrirrjtv
Ncfuryuv
ToArray
ProcessedByFody
ContainsKey
ResolveAssembly
ReadExistingAssembly
GetExecutingAssembly
ClassLibrary
Vnwvwglsy
op_Equality
op_Inequality
IsNullOrEmpty
WrapNonExceptionThrows
Telegram Desktop
Telegram FZ-LLC
Copyright (C) 2014-2021
$862f7d50-6109-4e61-99f0-2b549300d4f0
2.7.4.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Greater Manchester1
Salford1
Comodo CA Limited1!0
AAA Certificate Services0
040101000000Z
281231235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
HCgNr*
2http://crl.comodoca.com/AAACertificateServices.crl04
http://ocsp.comodoca.com0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA0
191007000000Z
221006235959Z0
943491
Private Organization1
Dubai1
Dubai1;09
2Business Central Towers, Tower A, Office 2301 23031
Telegram FZ-LLC1
Telegram FZ-LLC0
https://sectigo.com/CPS0U
Dhttp://crl.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crl0
Dhttp://crt.comodoca.com/COMODORSAExtendedValidationCodeSigningCA.crt0$
http://ocsp.comodoca.com0#
AE-943490
Greater Manchester1
Salford1
COMODO CA Limited1+0)
"COMODO RSA Certification Authority0
141203000000Z
291202235959Z0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA0
=U5W5H
https://secure.comodo.com/CPS0L
;http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
/http://crt.comodoca.com/COMODORSAAddTrustCA.crt0$
http://ocsp.comodoca.com0
Greater Manchester1
Salford1
COMODO CA Limited1705
.COMODO RSA Extended Validation Code Signing CA
20210428095006Z
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #2
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210428095006Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
>ABCDE
Nwnewogfecxuee.Ymdnfmwbadejj.dll
Cat has {0} tail.
Dog has {0} tail.
Zoo has {0} animals.
http://us1.unwiredlabs.com/v2/process.php
application/json; charset=utf-8
{{ "token": "{0}", "radio": "gsm", "mcc": {1}, "mnc": {2}, "cells": [{{ "lac": {3}, "cid": {4} }}] }}
status
balance
accuracy
message
.compressed
costura
costura.costura.dll.compressed
newtonsoft.json
costura.newtonsoft.json.dll.compressed
ymdnfmwbadejj
costura.ymdnfmwbadejj.dll.compressed
6.0.0.0
4.1.0.0
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
Telegram Desktop
CompanyName
Telegram FZ-LLC
FileDescription
Telegram Desktop
FileVersion
2.7.4.0
InternalName
ConsoleApp17.exe
LegalCopyright
Copyright (C) 2014-2021
LegalTrademarks
OriginalFilename
ConsoleApp17.exe
ProductName
Telegram Desktop
ProductVersion
2.7.4.0
Assembly Version
2.7.4.0
Antivirus Signature
Bkav Clean
Elastic Clean
MicroWorld-eScan Trojan.GenericKD.37078319
FireEye Generic.mg.81f63c8e0fab4d42
CAT-QuickHeal Clean
McAfee RDN/Generic BackDoor
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
SUPERAntiSpyware Clean
Sangfor Backdoor.MSIL.Androm.gen
K7AntiVirus Trojan ( 0057ddc11 )
Alibaba Trojan:MSIL/Kryptik.7fb5bda7
K7GW Trojan ( 0057ddc11 )
Cybereason malicious.b57e01
Baidu Clean
Cyren W32/MSIL_Agent.BCR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ABKG
APEX Malicious
Avast Win32:TrojanX-gen [Trj]
ClamAV Clean
Kaspersky HEUR:Backdoor.MSIL.Androm.gen
BitDefender Trojan.GenericKD.37078319
NANO-Antivirus Clean
Paloalto generic.ml
AegisLab Trojan.MSIL.Androm.m!c
Tencent Clean
Ad-Aware Trojan.GenericKD.37078319
Emsisoft Trojan.Crypt (A)
Comodo TrojWare.Win32.Agent.duygu@0
F-Secure Clean
DrWeb Trojan.PackedNET.835
Zillya Clean
TrendMicro TROJ_FRS.0NA103FB21
McAfee-GW-Edition Artemis!Trojan
CMC Clean
Sophos Clean
Ikarus Trojan.Inject
GData Trojan.GenericKD.37078319
Jiangmin Clean
Webroot W32.Trojan.Gen
Avira TR/Kryptik.kojhw
MAX malware (ai score=100)
Antiy-AVL Clean
Kingsoft Win32.Hack.Undef.(kcloud)
Gridinsoft Trojan.Win32.Kryptik.oa
Arcabit Trojan.Generic.D235C52F
ViRobot Clean
ZoneAlarm Clean
Microsoft Trojan:MSIL/Tnega.SS!MTB
Cynet Malicious (score: 100)
AhnLab-V3 Infostealer/Win.Agent.R425155
Acronis Clean
BitDefenderTheta Gen:NN.ZemsilF.34738.Bm2@aupdZt
ALYac Clean
TACHYON Clean
VBA32 Clean
Malwarebytes Trojan.MalPack.MSIL
Zoner Trojan.Win32.112719
TrendMicro-HouseCall TROJ_FRS.0NA103FB21
Rising Clean
Yandex Clean
SentinelOne Clean
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Kryptik.ABKG!tr
MaxSecure Trojan.Malware.300983.susgen
AVG Win32:TrojanX-gen [Trj]
Panda Clean
CrowdStrike win/malicious_confidence_90% (W)
Qihoo-360 Clean
No IRMA results available.