Static | ZeroBOX

PE Compile Time

2099-02-03 14:24:57

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x0005b50c 0x0005b600 7.99276158231
.rsrc 0x0005e000 0x0001a7f8 0x0001a800 4.9406735571
.reloc 0x0007a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00072bb0 0x0000546d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit gray+alpha, non-interlaced
RT_ICON 0x00072bb0 0x0000546d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit gray+alpha, non-interlaced
RT_ICON 0x00072bb0 0x0000546d LANG_NEUTRAL SUBLANG_NEUTRAL PNG image data, 256 x 256, 8-bit gray+alpha, non-interlaced
RT_GROUP_ICON 0x00078030 0x00000030 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00078070 0x00000586 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x00078608 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
b"s1
b"s1
v4.0.30319
#Strings
button1
listView1
textBox1
button2
get_UTF8
<Module>
System.IO
Vypvpznnbtucea
Ukvdexlnsgmgeaeha
Ljutanoia
Lzombpkeiacrmra
mscorlib
Jxxyvpvlpb
Thread
Synchronized
Xiifbczmjwnbwrnnixtfd
Fayruhnd
Pexvszfkkiszqtd
Replace
defaultInstance
set_AutoScaleMode
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
set_WindowStyle
ProcessWindowStyle
get_Name
set_Name
set_FileName
AssemblyName
get_Culture
set_Culture
resourceCulture
get_InvariantCulture
ButtonBase
ApplicationSettingsBase
genese
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GuidAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
add_AssemblyResolve
CurrentDomain_AssemblyResolve
genese.exe
set_Size
set_ClientSize
System.Threading
Padding
Encoding
System.Runtime.Versioning
String
disposing
System.Drawing
get_Length
Kaorhsgaccxwbxkzh
Cxzticnubutgdpozdsknyti
Dniirqhjpzfcnqkj
button1_Click
button2_Click
add_Click
System.ComponentModel
Cxzticnubutgdpozdsknyti.Qsppdbygjvyuhm.dll
ContainerControl
GetManifestResourceStream
Program
ListViewItem
System
Qsppdbygjvyuhm
Iwuqgnndyhjfapuqittjm
Qoebvzevwdgpoinfaozowm
Gdmrzhlkyytllaiunnmzm
resourceMan
AppDomain
get_CurrentDomain
set_Margin
Application
set_Location
System.Configuration
System.Globalization
set_HideSelection
System.Reflection
ControlCollection
ListViewItemCollection
Button
Munataqrxnbkujodo
get_CultureInfo
ProcessStartInfo
Glafetbpkjzdrlrmqiknnip
Aitiplpp
Ziuuuscaucpmectvjrwvbq
sender
get_ResourceManager
ResolveEventHandler
System.CodeDom.Compiler
IContainer
set_UseCompatibleStateImageBehavior
set_UseVisualStyleBackColor
Uclkpfrespdyzdsmgkpor
.cctor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.Resources
Cxzticnubutgdpozdsknyti.Form1.resources
Cxzticnubutgdpozdsknyti.Form2.resources
Cxzticnubutgdpozdsknyti.Properties.Resources.resources
DebuggingModes
Cxzticnubutgdpozdsknyti.Properties
EnableVisualStyles
GetBytes
Settings
ResolveEventArgs
Equals
get_Controls
get_Items
System.Windows.Forms
set_AutoScaleDimensions
Process
set_Arguments
components
Concat
Format
Object
get_Default
SetCompatibleTextRenderingDefault
InitializeComponent
Decrypt
SuspendLayout
ResumeLayout
PerformLayout
System.Text
get_Text
set_Text
ListView
set_CreateNoWindow
Skexdrfuwsnxexdlvyhqmvw
set_TabIndex
TextBox
Vljjzmskiy
get_Assembly
GetExecutingAssembly
ClassLibrary
WrapNonExceptionThrows
<ISO Workshop Installation
<Glorylogic
<ISO Workshop
eCopyright
2021 Glorylogic.
$a7377113-4983-4ae5-b87e-4ab56be57d74
10.3.0.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
3System.Resources.Tools.StronglyTypedResourceBuilder
16.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
ykWM14
\vzR|Lm
=QF11=g
Z H]y4
d*%^Zi
Ag{]FQhb
}Q9(>0*
<I#{Hv
N<3QW|'
ps_AoF<@)
2Q#q_v'
Zhcn9j4
`m.ce
to=vo?
LS"8vgZ
8(7:zgL
u*%6C0
A&^/II
k?mQL3
;T((dsS
]/tK!84
IJD.\k
yx~%8:
ythD_Ls
}/5yEt
C<Iy:$
*!6kA0
5=F|_f
SeDgK:T]PP
R4TZR7
q1"Fp=<
7G/o>+
7anW'Y
9eo>mMP
s5bpi3
n;yym(
4S}lb
q.]pi[
fYYw$aOrV
h$+H2yp.
ZjD3fa1
XRnY@J
!r,@,o
$]Zop:
K7dg{}O
5>wRDW
erO_,T*)
>8N_}u)|
E.N+|^
_jrlfI<
R#Yy3{
9Smk0#
g8lDq-
bj#i}%V
fr3}/%
q}NBp,
z/4Vwa
M~l.TN
ogUGu;
*\xM%qKn#
AQ]B=OQ
##_)B]
|Y#!lS
XtCjag
$(q$^lg
qE9Ylp
/&IS-h2w0
NdMXP2
5i[`~S
9J-%<U
A</5IV
)or# D&S
QCXAdl
=K;OG-
IhVx(<
`/I-F[lm
tYgPe3Hl
P6au;>
&G;+<[
f/;iFGe iZ
y7ShJo
NSYFIfi
;H;=ugu
G*_mpzs
Ll8FMh
vC+Kz3s
hR"pN/
(ZEz1u[
bW'? "[#
Nn0j8ME
1bQp3)
Rs:`P'y
wDCQ-5
&Ew>R!X:
[gI0%Gq
=3zX\P
@6}Q%)}]
"*SV''
^F%smI
fY*44,)
Gh$Ms8H
Q[DOxx|m
]k3\h4
/'f.H_
(+!VfR
.qG{mVF84
"IC>ZH
"^D}dD_
atsom-
7.#^Jq
<pyVDD
imkXYM
_G*M(?
Y+nm{1
Q,(jn}.
?sc@-a
,Erhq_
0s6{>%
AuZm}`
#h:y%)(
R&A,eo
A+hb/6
x@=8E6
CajyCm
iC+{6k
H'>h#*g*2
ZT"8KraQ/
bY|N"#
?,1k#5
Y,\l5pp
(b'z`[i
GZVP-yk
g!gQX^
ZnFNJ.
3AU\/{
6DsZuO
+4%z']
cWQ`{*
;1UERx
#W%zh3u,
8-W\f=
AlbEn&
=C"|%&{
>j|,s?
gda$k7
A]r"M^
x@:\8](
>s0tVZO
ZF)"MY;
kgf#)j<
M69as
s'dXf7
.Fhws[
>q3;\W
5`bIYL
pMuJL3GT}Dg
[sc+Al
5ZJAl6
e&aA&&
|GH[LO4
!#m(kOHP
-aGs[X
@oSnl0J
r}bN({Z
,g5P$o
&K,WYB
a,#~gFY:
1EpXl+
:Ffy+TC
e$0qIk
GHh(2z
U]UUI=
C3EowO
}G~%%`
86-\$0
,5e<HG
;30TV3
OV&<`4x
y"Ht,Cc
#MIR&+^xH
ep%5 {"
`50E!*o
t\/mUN
g)d{J*w
{}f,%B!$
z3Nq 1
~O9d~e
b[|;Av
i{EO:nI
7jly7f
,S#*Vg{.&
sPnAd+M
8_>[J:0$~}7
UOR(zl
C<B|\f
^HZNA{
Ej)u,{
z&oct|
Q@"O(5
ZsS}F$1
n8wjI
Gqo8zg&
BI/;@})
eqoton(n{b/\|
&GT+3]
!Bd``\
3%dNIA
\P#Gpb
DggYCkO"
KEzDw+rg
uMOqry
02I&DK+
y%HQ:24
YYQ_0F
mf\?x/
l37oXa
<+D}.T
qJ(z).
$iUE9>
}NgKBp
S/\sB{|
UWA9c
#j:wk6
Mn(-Wh
GtO',.
`,XTQh
RO%wum
Le'~xp
'(8dzS}
zI*kyc
{^+vj1
xy}q5tx
Y%UPgU
e&)x]P
JO[^T<
b,"j/3
b]/+'#
\EaI{~5
+R/8SIr
3x2|gz
R#o>AV
cW7DQVD;~
).{@~
;-UdWG
?85*Em
0 HqdCb"
x7`)
aw_T'a
7]pjdd'
tb";g7
o{g$Oh
Nah>Pg
a0XqT]
W]?s8\
t=r@9O
(UpBM'
FK;7Nu
4UX(5@2Z!
"<'uD`
W0&F{H
5us 'N
@da[,W
+^(cT)51g
mBnQS:
^$rY#b
E/J wrZ
M6kTZiWz^
ZBkq<*/N+
L:mAX`
jthV+K
7-uYdU
M1v0xe?
aYvk'o
0ZtMA+
PE[JZ :
bJFV4W
kVi-3F
G-PhKZ
D2#vj*
yHRK=V
k4`KO9
DcV1ADhe=
M8_]<R&
3MpzTN
dAKF i
bB~}*t7
<=lUp~K
h\&"jw 8
JH-eLoY
=J.rk_
+pt8bY
|5i =:
Hv}Kb|7
NKg%sC
->f[$
:L@P!c
OFpIZ
GVzv/f
#v[!M%"Kr 5
!9z7+2m
\|-SRt
%z{ u|%{
_:-DTV
T{8}7`
oYf)\_U
*~Rp%)j
]/H)0]
J3!uC2}8
bg&&$
H@\DRAJ
:S"Q*[
2UZ*<K
-yX2_"I0
3$Cc7oeC
scVQ[Qi
\1K*ib
Z9~&-"
AoH'WK
DD-%%1
*Y30ATj
]C3_<r
e?YZSh-
0A'uS!
ruIaj;
&|k9[L
BHqGyV
;SFv-aW1}U
.@X0zU
\|d](|J
mhGXn]
a-{Xusm
^&K.S<}
%6V*RL
rB4:Tkf
VY!+*o
B]Z)9^
Nu}}e$
UH1m<^
+/;q@i
BN?}p&ze.
~v"tlX
>;IBh2
a?G9GC
:^vmn*lk
SMT%/4
D_%VzN
Z,22F,
K,yG8h
fX},D9
oH{13a
0Yc?C}
zbY^|HdE
`0(Wi
/GU{Zg
9|0X-`K
0iFyl
wiN*8@
S$nyN~<Z
PdOv;#=YN
mW[<-{
JOxk/N
>3`7|`
~I3<vd
hY!*z^
-s,0"b
d`2U4
_-Mn1)bE
K(3*-+
x.Q#5Bb
=ha7&,
`3xPW{
t+c3x^:_
4hwdYy
B>|Y`R:
5#K-[l
Y';/}f
}_$v*;
]ILg-W
m!,~qk
l5qn2XE
%]u|/13
=^I3==
dfH<7)q]
N4'PIwUy
y_h7u#
oa3s,.uc
^L4~6S
9a{2$d
#_R%}A
Uom*74
4\/](F
cs])X;
Tg>O8V
mD+xdr8
|FSfl)
]F<v)-.
\\G4%6XV
A;EZQc
|>O[ x
z{6QGq
"/q&4[i
k(]yr
V=VIE `'
L{VOqOZ
X?**^(
dNBMylx
CbYt/L
QR'u\HFC
}MfJ,L
h#uh /
&74?f*
Z9.Y{Lep
1V$l"b
quUOd7
1/sJ+c]^
e?Vn8s
]AWWz<
V|,q7Y
>z\$:K
F?CTvlI;
b-3xM"i
`yBlfr
DW3(8o
q*P$2u
-@tPN'O
f-Qs0U
2o*,t<
!k/_+L
O[sdJ0
oOk(}@g
9rNBbI'
v_]OXs
fl;t|Fi
DW-L~j
d]P\kmM
" (7215$o
AIC5}V
>,u-:n
t+d2xO)
`IgUk1
W>]c^y
k*K`M=
=Drdrv
ZG@]pU
\/-/]
% <;Em
)t2)Z
^kvB= qpT\
v0D=6}
p&8_L
09-N1%G
};bo:
<@IqpHk
Xy3|Y\#
Dka*Bc
$m%2x!
u7Sj:I0G
10un"2
GozBm4x
J)AuFs
Y|CJc]
cUs-w"F
~%v'%~
'GSmM1
Y2]FgS
ri{l2G
."{Uui
>f`f6o
_hEoY?c
k%Ws)y
q$YLa8
Qc1{i
11bdH>#
V-uDxj
7O-9t
H'$bc^=
S,ymF
-W~/gI
xRZ"Wt
`-@Ndm
MD uMY
a@,5T
3XeHR2
(;[28
7j$^j0
%[ntj;e
|ExQf>2I
ui d.W
i-r'k|
$`%=0D
tb4[1.
kjy/dz
-h>]vs
~1`cp,B}
I;Y[sF
#fgVDG&L
rqoHNH
\ZP@q
%ld6R;
\LCoP#3
B-z!Ib
Yj%'2
4.f7k;
~Ig1ZL
8VAt:z
Y:Yo;9
:WT2?G
}JIOct
,6,-o#
QX4F,R
TL`uS;U
*X[S3Z
xL.y/z
eb2GU8J
BttWGQ:
<'1L9+
[WP'`ns
5ciaY*^
UT{7;%
J}2E>@
yU4`o
SS7{'h
$}[[E{
gdAJ>K
PQ7lfZ
;/cGBl
'eg8DI
n3uWLZ
B>V^ZN]
jpmd]:
bVw}!ADQ
O`^kDs:
f'Z3D!
b"FU?+
qj8U&qWK
gK8`j3
n17D`y5
(gRXrW
`|Ogh/
RFHsQ;n
Q!7tySPz
ecIZ5Gi3a
*;>8{$
"XHt3/
IW0A/h
i+<4G}
Vk@}0<
(;r|mK
R+5$$[|
5\0,V6
0SZO$C
}OC^em
3\(Q~y
.1uY{6f
=E3DsOL
}IGG,eS5
m{N]V_
auDaw~
'uN2:6
UWqr@T
o"M_3~
JcFox<
M#k$`k
I|1:1Q
a"q^"96
,S~I\#
}}\NB}
0i?clD6w
KF+)c&3
\Np$2
^$^T`!
^nV}V2
1f}8<
t)^aEW
p*tV7
0fGV|:
qrtuie
:ps2L
zJR+F3
y"Al^`
|a]tZc
fH@gA%
*8mCI"
!ljRqi
5/svO8
UkypYQ
yA|DM,
,E|"Cb
>0Z#K\
|yWbH]ht
b]SQ*r
r~\E,I(
7O@Z=;
!q+N?%
u {!B)
m|V@A@H
F/S-u4
ND`s/M
6\eNh,m
bu'~(n,
r+89.&89
V-*jfE
au%*hB
Y<yN!'
|`l}iy
8C!M N
-^POX
li<=/}B3
e*^/pS
yn?>!J(
I8mH-(
DZF<<G
VwT03}Q>
.J'rDF
Nnt=S"t
d{f#rz
VKn3TX
,3\q3l{
m79r|B$
D[wFqX
*d=8mJ9u
1~rGc:lm
7gQ"|n-
b5zFcD
xaV>_T?
cc*Gh+
hbtb.]
G>+V>:
hB|f!v
k/3fOYR
3[I1ql
[]fJT0x
!Lm!d<#MX
FIm&gG
;bKfK8
[MPj<A
@sew>W,n
_CorExeMain
mscoree.dll
T4IDATx
>H2@Aj
*.?%eA
4-)aAP
]]DPEMD
mWR4+f
pgQ]SK`
m u5%A!%a
NKrR"j
=z(iR6oI
xUGEXP]]
fu[4/*"!
EY]QQT
XEEPYA
j7$nPP
0cYBDAB
){XDLl
]QJYQJAJU
gl5)oF
??XTMH
yu3FmQ3
+`']FA
QSFUY]
bADERETHI
I'4kRsR
q-dOX
CLNMTY
B&dDUE
UUumJ.
bBrbZ,
o*.J{J
iO(JzQA
6ycNI8
6!#-), f
-i5'd@QAF]
*`IMFQHH
:EYaYiq
Aiq%Ae
FlwD\D@Q
K]]YFR
I5{L7T
VU6%hY
:-h3d\N
qJD@B]U
NQ1gU,
!#F]2j
:gER\UD
ZEQ@BNPXERNUBAP
IBQI^BHT
K(IkvVH
(""*/ $
.5AmBN
A&+aAYXI\PMZE
oMRUoDD~P
KJf-JjW
}2.I8e
V5!5A5+Jb
iU!%5Q!eEie
EA!Ua5
~SXLTZ
B]TVYB^H
~bjjR.
", "$n^PE
PtJ@P@
($$bYTP]QPFN^
~guYgY
#]NY2)
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
210323000000Z
220930235959Z0x1
1216141
Moscow10
Krylatskie Kholmy 39-21
Burnaware1
Burnaware0
https://sectigo.com/CPS0
2http://crl.sectigo.com/SectigoRSACodeSigningCA.crl0s
2http://crt.sectigo.com/SectigoRSACodeSigningCA.crt0#
http://ocsp.sectigo.com0
info@burnaware.com0
%Q8Rs
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
181102000000Z
301231235959Z0|1
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA0
iemn'
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
#jYhRB_
mt^Ju~
2&-jWp
Greater Manchester1
Salford1
Sectigo Limited1$0"
Sectigo RSA Code Signing CA
20210503200203Z
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #2
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
201023000000Z
320122235959Z0
Greater Manchester1
Salford1
Sectigo Limited1,0*
#Sectigo RSA Time Stamping Signer #20
https://sectigo.com/CPS0D
3http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
3http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
http://ocsp.sectigo.com0
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority0
190502000000Z
380118235959Z0}1
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA0
?http://crl.usertrust.com/USERTrustRSACertificationAuthority.crl0v
3http://crt.usertrust.com/USERTrustRSAAddTrustCA.crt0%
http://ocsp.usertrust.com0
rRj;B7|
[C]e=P
Greater Manchester1
Salford1
Sectigo Limited1%0#
Sectigo RSA Time Stamping CA
210503200203Z0?
New Jersey1
Jersey City1
The USERTRUST Network1.0,
%USERTrust RSA Certification Authority
sU:2ki~
pkowekrshkekll
Test-Connection 8.8.8.8
listView1
button1
textBox1
button2
Cxzticnubutgdpozdsknyti.
{0}\{1}
Xfsnnukhkyyvsihe
Cxzticnubutgdpozdsknyti.Properties.Resources
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
ISO Workshop Installation
CompanyName
Glorylogic
FileDescription
ISO Workshop Installation
FileVersion
10.3.0.0
InternalName
genese.exe
LegalCopyright
Copyright
2021 Glorylogic.
LegalTrademarks
OriginalFilename
genese.exe
ProductName
ISO Workshop
ProductVersion
10.3.0.0
Assembly Version
10.3.0.0
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
FireEye Generic.mg.82d9399220654cb3
CAT-QuickHeal Clean
Qihoo-360 Clean
ALYac Clean
Cylance Clean
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason malicious.9172aa
Baidu Clean
Cyren W32/MSIL_Kryptik.FDZ.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Kryptik.ACJL
APEX Malicious
Paloalto generic.ml
ClamAV Clean
Kaspersky HEUR:Trojan.MSIL.Bingoml.gen
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Clean
Ad-Aware Clean
Emsisoft Clean
Comodo Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition AgentTesla-FDAW!82D939922065
CMC Clean
Sophos Clean
SentinelOne Static AI - Suspicious PE
GData Win32.Trojan-Stealer.FormBook.C4JLYH
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Adware.Win32.InstallCore.dd!n
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Sabsik.TE.B!ml
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee AgentTesla-FDAW!82D939922065
TACHYON Clean
VBA32 Clean
Malwarebytes MachineLearning/Anomalous.96%
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R04AH0CHB21
Tencent Clean
Yandex Clean
Ikarus Clean
eGambit PE.Heur.InvalidSig
Fortinet MSIL/Kryptik.ACIY!tr
BitDefenderTheta Gen:NN.ZemsilF.34058.Em2@aegI22n
AVG Win32:RATX-gen [Trj]
Avast Win32:RATX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
MaxSecure Clean
No IRMA results available.