Static | ZeroBOX

PE Compile Time

2060-10-18 06:43:29

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00045f34 0x00046000 7.0046309606
.rsrc 0x00048000 0x00049fa0 0x0004a000 6.06498536934
.reloc 0x00092000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00090e10 0x000000a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00090eb0 0x000003cc LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009127c 0x00000d21 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
m#g;D9#
5Vmx~wD
7-,Cma
&JdMy`
%{Y^3x
_ ZU@E
:8O},8
Y=L>1V
!oze=?
Y"0csiHg
et$D;_
_xi3Ll
r&%)ngC
2pN{RP
00H(kC
xXN2gwU
&Oh#L9
Hiv5m -A
"6=h6
-u\Go5
593/iU
^X=k|<
*rRL,m-
Q^kBKaW
ui60V0
YnZbF>
Puve h
(&h!Zu
P^;G>&g
qvjU"U
gtql1hfW&FA
JoZkd
l"x]Ow
BeFjUe
ML(3Vd
9Pz[+,K
Qj9ac6p
LBDt_,
zkSzQ
A<)N$)q
6Q?~+qu:#
9D.n4{2
"k8(+v
qbYC#a
PelyDqn0
AeqMJU:
.+cn]qC
C?^nWN
DQ0|/d
?S[%?++
@C'hk`o
{(K7L:
G&#1H
zx/[Awz:
ZVzu])
?S>e^K:
>%EXhN
e`P)j=
>tA~tH
)oEN=$
(7p\78
Zx'}?*kg)
K7D4>;
sO1@6j
}hEL-P
!O}o!H
WBy^#\
hq3z?]
E5@tj3
&-cdoY
}54{KX
^cI(aRh
nLC>s2
L*%$4}G
]N']%i
;9,Y$5Hj
ZTA2ugr
TSE JJ
c$UyEm
sEkcUSyq
wGSkK
pr#.<x
m!TX0h
bl3[+%
N\2N/
O/=]OthV2
L.^7?wm
,:PP_Q
Y%YjGa
8xnw]U
'I'U&5
\u4i{ux
qV2@O~
`5eYhM
,6Rd;,)
3^4vD%
C|gm<?
WNZ0Y^
T-_C`N
LBu`Ud
xY*cJiyR-
X\^Rig?
lq,+$<
n4fOCt3'
ED|IjP
{L$n.5
)U"sB"
RSC2(Y
H\_'!u
dCg?8b
4%0.*[
C<4rfA
7T3`.3~Dh
a3|d n
}:\N-w
Dx2v0ha
J?o]1
4/@ O-
N2~>-RL
%{}Z(.*
=_DgT|0a
Ahp;lR
$l#tJGi8>O
IaCwk`
-&334
+/)4>F
1ilk.K\
7b75\Mh
{bW1o'
%w5]+l
9ewU]h6
yl66us
tu7j-S
x.OP9f
)k@=aL
mI<CI=
HLu78b
:]a'E4P
Hg_Haxt
*"Wy#!
.%Q-lU
6Q7F2l}K
k#e]&"|+
5Zsr
rL[Lx&
M$m,$6
FdlaXUS?'-
DXhN6z
QBz_-W
J;&rca
~F]>{Ck+
y6]"@W
@Jo_9(
4]MiGY
_4yh@"
Zb"6f\E>
;r|I|gYMp;
tkYVbZ
v}WqD>W
Kr4q$e
aSx|o[
FkL0Sn
=l+r)G
zP(t''
qxg5g48^.
LdF1(|F_
SU.b{lv
~R@fjU@y
U4pVn|
e/N2`q/iN:B
z)xB4u
#qZKVIqh
Bz3icJ
AP#sHm
<w`7A7|u
@=EgsV
ydon)"
]-j?Qb
Ww(vNu
itF^:T
k/|S;:
_;=x%-
V38$?]
c)6P$|
;,,/LY2
1=G[hA
bStBD7
(f_nKD
T&?;fG
V?jDe+
X$5;4I
W(%}{\<
6h|k(>
2eHO:Oo
)pr\ET[i)
y 6Ug>#
LBN&%n
%:]'{+[
45{,^Fa3@
BW0Gtoyo!
YY6IDwg
ok$jR\PwA
4?[Edv
"5buLP
qka?7R
cI;[hd
'WF$tp
Qzxh~x
txB$Q[G
!vv8Fg
Sqb_krp
^64c!g
3+ gBL
}%Ml-{
`lw)yu
hR*Q5#
YBqcnA
&UJYu
d/q*iAv
BESm3t
WF]e7t
FW`Wgk
H=uQRT.
{zI_a!U
heWmE:
T,rgOxP
Cr<Yn3a
y33jeH
!3adXQ6%9
QU\F~ie
lGue/2-
.M$}j{Z2
A7gJpoZM1;"
jTkx_<
?L[7@^
IhEn{Z
2Rh@%%B
UO:Szz
`HE@:`
cnA)H6Kys6
!ft$Ja
k:BVG_
fq:~\L
Z_}Vr?dE
*;XN01
xvCe]A\[D
fF7H\a
I_ahyi
K.lGXE
Z3{i!;
Ig'Cb7
`,]@Un
H#(g2s
+\YRM]
$TnM!3wn
Y^Fu#mUw
bQZ Mh
Z?_b`
vqZ {T`
9]Z \j
Z ;Hf-a85
U@%&8f
Z F73oa8
Z 8SKka8
lIn%&8
:.G4Z b
gZ Im;
_bj2
_bY*
rAZ eT
.1Ia8r
QY9'%&+
Z G]|Ca8
Z_bX
2y3 yZ4a%
Y_cX*
0P%&8[
Z ^6}_a8I
*]%&8$
En"Za8
7pV!Z a
\Z k+^Pa8)
:%sN
? X8!ia%
duR[(
[d1a84
MCua8A
99sN
vZ]Z ^
hZ >8l4a8Q
-i+"Z !
,: 0d\
/H* W3
9Z p{sVa8@
9E9a8F
a> %&80
U?DdZ
+&F/Za8
KvZa8Z
Z Y].ka8(
@y3W8
QE>U%+
!j4%&8,
v[Za8\
1ZNLZa8
hyZa8k
hm'/%+
>~7%&8=
+ Om!'(
Z ^g}Ca+
,9 Y+d
XZ A8@
\MKa8>
*"Z ;?
1GwW(
vUTkZ
BZ EM#
@P@X(D
85Z z[
YZ RPS?a+
{EW?Z a
]@|a8L
ezEZ 9=D!a8
5IZa8L
Fo{8Z
VtVZ e
+`XZ%+
cY:$Z 'C
._%&8N
m)7W%&
!eZa88
0Za86
*nZ ?oX#a8l
=AXZ k
v4.0.30319
#Strings
poweroff.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ResolveEventArgs
ValueType
Object
Stream
System.IO
X:(@@`B8q(E'Ay$6wF{/cyv{
System.Windows.Forms
IContainer
System.ComponentModel
TextBox
EventArgs
Dispose
IDisposable
ComponentResourceManager
Control
5CefEI&9f5&dKX}ig*)WZ\kb"
UserControl
ContainerControl
AppDomain
ResolveEventHandler
<>9__0_0
AssemblyName
List`1
System.Collections.Generic
RegistryKey
Microsoft.Win32
Environment
SpecialFolder
WebClient
System.Net
RemoteCertificateValidationCallback
System.Net.Security
SecurityProtocolType
WebHeaderCollection
NameValueCollection
System.Collections.Specialized
ProcessStartInfo
System.Diagnostics
Process
ThreadStart
DirectoryInfo
<>9__8_0
X509Certificate
System.Security.Cryptography.X509Certificates
X509Chain
SslPolicyErrors
RijndaelManaged
System.Security.Cryptography
SymmetricAlgorithm
PaddingMode
CipherMode
ICryptoTransform
MemoryStream
CryptoStream
CryptoStreamMode
Encoding
System.Text
HttpResponseHeader
Delegate
WebRequest
WebResponse
Random
<>9__2_0
GetProcAddress
kernel32.dll
GetModuleHandle
GetCurrentProcess
IsWow64Process
StringBuilder
SearchOption
FileSystemInfo
BindingFlags
Binder
HttpWebRequest
DecompressionMethods
StreamReader
TextReader
:[N;?BfgqTtX9TV%P(:i?\|0!
RegexOptions
System.Text.RegularExpressions
KOM1&]q(o41DR0wD1c:E*S]+
ResourceManager
System.Resources
CultureInfo
System.Globalization
Settings
pwr_off_Qx31N8Z9cfm0E3916a.Properties
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
ConfusedByAttribute
Attribute
poweroff
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
NeutralResourcesLanguageAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
SecurityCriticalAttribute
System.Security
SecuritySafeCriticalAttribute
TypeLibTypeAttribute
DispIdAttribute
TypeLibFuncAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
Newtonsoft.Json
JsonPropertyAttribute
NewtonsoftJson.Json
X:(@@`B8q(E'Ay$6wF{/cyv{.resources
JgsBoViCjKxXRbFajeFrlCmjYwYU
KOM1\&\]q(o41DR0wD1c:E\*S\]\+.resources
5CefEI\&9f5\&dKX}ig\*)WZ\\kb".resources
:\[N;?BfgqTtX9TV%P(:i?\\|0!.resources
pwr_off_Qx31N8Z9cfm0E3916a.Resources.Newtonsoft.Json.dll
String
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
ReadByte
get_Length
UInt32
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetElementType
CreateInstance
Buffer
BlockCopy
get_UTF8
GetString
Intern
get_CurrentDomain
add_AssemblyResolve
get_FullName
get_Name
op_Equality
set_Text
EventHandler
add_TextChanged
System.Drawing
set_Size
set_TabIndex
set_Name
TextBoxBase
set_Multiline
set_Location
Padding
set_Margin
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
SystemColors
get_ActiveCaption
set_BackColor
set_ClientSize
get_Controls
ControlCollection
get_AliceBlue
set_ForeColor
set_FormBorderStyle
FormBorderStyle
ResumeLayout
PerformLayout
SuspendLayout
get_MediumTurquoise
Contains
GetExecutingAssembly
GetManifestResourceNames
GetManifestResourceStream
Registry
CurrentConfig
IEnumerable`1
ToArray
Exception
Enumerator
GetEnumerator
get_Current
MoveNext
Boolean
ThreadAbortException
CurrentUser
ToUpper
ToString
Substring
CreateSubKey
SetValue
NewGuid
OpenSubKey
GetValue
IsNullOrEmpty
Replace
GetFolderPath
Combine
WriteAllText
Remove
ToLower
DownloadString
ServicePointManager
set_ServerCertificateValidationCallback
set_SecurityProtocol
get_Headers
DownloadData
Console
WriteLine
set_CreateNoWindow
ResetAbort
get_Chars
Directory
CreateDirectory
set_Padding
set_Mode
set_KeySize
set_BlockSize
Convert
FromBase64String
CreateEncryptor
get_ASCII
GetBytes
FlushFinalBlock
ToBase64String
CreateDecryptor
get_ExitCode
LocalMachine
Win32Exception
Exists
GetTempPath
Insert
IntPtr
get_Size
set_UseShellExecute
set_Verb
set_Expect100Continue
get_ResponseHeaders
get_Item
WriteAllBytes
Collect
get_ServerCertificateValidationCallback
DownloadFile
Create
set_Method
GetResponse
GetResponseStream
GetEnvironmentVariable
GetDirectories
op_Inequality
DateTime
get_Now
get_Ticks
NextDouble
ToInt32
ToChar
Append
InvokeMember
GetTypeFromProgID
Activator
set_AutomaticDecompression
set_ContentType
set_ContentLength
GetRequestStream
ReadToEnd
TimeSpan
get_UtcNow
Subtract
get_TotalSeconds
set_AutoSize
ClassesRoot
GetSubKeyNames
IsMatch
StartsWith
get_Assembly
Synchronized
JsonConvert
DeserializeObject
ConfuserEx v1.0.0
WrapNonExceptionThrows
pwr_off_Qx31N8Z9cfm0E3916a
Copyright
2022
$70eebf94-a060-47a7-b559-7875a5510229
2.0.3.0
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$F935DC23-1CF0-11D0-ADB9-00C04FD58A0B
3System.Resources.Tools.StronglyTypedResourceBuilder
15.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
15.9.0.0
ExecParams
country
partnerName
productName
excutionWidget
buyingChannel
discrepancy
PostBackUrl
userId
prices
salesChannel
active
ipLoggerCode
modeUpdater
modePublisher
paramsProduct
ListProductInstall
UrlTrack
trackPostVar
dailycheck
TrackDecrPrmKey
TrackDecrPrmIv
_CorExeMain
mscoree.dll
8nVDNR
#Rp!rAFV
;t-D_b
`] DDD
v X%?""2
&Ti7@N
}EDD&[
/""2=|
nMDDD.Q
Ge?"""
Rr'"""
EDDD&E
DDNpp|
yVW<>:d
9W{=>[X
$@DFy,
p#o3,Vs
mk-TUJ%2
__`?,;XoY%
<IC[{XlWcU`
#"2]bIPSU
{O?d,g
<g-/X/rV
cu^iP
!b" U
W.OSU6+
92<!xVb2
%kyN?t
&K qPn
a1qDZK
;=%F8-
=F)F6#
8wK2c8-K2
5VkV]G$=
q_d= L)Jcy<
8-K&YNi-
S~3!v-
t!0o[^,
3D:8.V\
BkJm(M
uF)Jc8
%F+Jk)m
Z2c8*$`
D+Ea,Gy
KTdM+E
};PI|^
P#0oZ^,
2%M@7E
IDAT?./x
-S(Rc(
4V)i{)
M(lBn-
i--A7(
2JQ&)O
:fYFn-VkB
<-K^L&
5{VFM|
~^0MSRc$
LVgbkzO
,!>;J)
ohn,{y
udZShC!
I]s\U,
%ZS&)e
052 l+6
7{s&IJb
3~:;#5
gdgng.
cTCPjhOiIT,PM
&ir^,9MS
fs^L&</'<
hLEK6Z
rBfmLM
z{C#>Q
UzO/M9
BcEeIV
{FyNw<
CP?-(g#@
jQ7,K>n
"xFYN7M
y?nr-nr=
IBg<&-
ex2_2(
Q5@,rV
$#NF#N
TDvqrO
>@c?C4
&)Z\j6
%IQ0.r
(HZE5Xlv
lvHVZL
s_2}2`
1+,C[|
y "_Um>
x}xfq c
KDvqrO
HPT]68
"r&"Oq
RDO VO
Uo_0f
!G$Ei(
KUzq*Q
d%i"#+o
%r+tGQ
@dImno
&cz_YQ
Fh[]Dn
2:iB+M
fDyF'Mi%
8XC\d=
CzYF;Iy
.;QD=I
Z/V~E0g
A@FN+M
z]Z:)p
"NSziB
IL/IhF
{m`fmc}
0$pNfI
v;<m5i
E9 &.r3
Ek8[%
104A@5"-
LVkx)r
s|)qW`
IDATVJ
,&VGon
nosmm
sJ3`FYT
B5+`7M
ro<1#~
sg<f?4#~
so2ag65w
!w&cvgS
M{r~G9#
!ou{\[[g#
!n/{Q'
")r&Iy
_~[1KS
\Bw|Z@
,"rZD>C
;.NN r
U~92R)
?/N. r
?::4|!
){=o"K
[DdBD
<_}+vz
iUk4fg
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app" />
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
<applicationRequestMinimum>
<defaultAssemblyRequest permissionSetReference="Custom" />
<PermissionSet Unrestricted="true" ID="Custom" SameSite="site" />
</applicationRequestMinimum>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
! " )(-,
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
pwr_off_Qx31N8Z9cfm0E3916a
CompanyName
pwr_off_Qx31N8Z9cfm0E3916a
FileDescription
pwr_off_Qx31N8Z9cfm0E3916a
FileVersion
2.0.3.0
InternalName
poweroff.exe
LegalCopyright
Copyright
2022
LegalTrademarks
OriginalFilename
poweroff.exe
ProductName
pwr_off_Qx31N8Z9cfm0E3916a
ProductVersion
2.0.3.0
Assembly Version
2.0.3.0
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Adware.MSIL.Csdi.2!c
tehtris Generic.Malware
DrWeb Adware.WizzMonetize.1
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!1CD03D64A190
Cylance Unsafe
VIPRE Gen:Variant.Strictor.266661
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Adware ( 005684bb1 )
BitDefender IL:Trojan.MSILMamut.6896
K7GW Clean
CrowdStrike win/malicious_confidence_60% (W)
BitDefenderTheta Gen:NN.ZemsilF.34754.Km0@amL92bg
VirIT Clean
Cyren W32/ABRisk.CRFZ-6523
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Adware.CsdiMonetize.BC
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H09JV22
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky not-a-virus:UDS:AdWare.MSIL.Csdi.gen
Alibaba AdWare:MSIL/CsdiMonetize.06e1a63b
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan IL:Trojan.MSILMamut.6896
Rising Trojan.Generic/MSIL@AI.100 (RDM.MSIL:jboEwC58ifUnzziqO22yKQ)
Ad-Aware IL:Trojan.MSILMamut.6896
TACHYON Clean
Sophos Generic ML PUA (PUA)
Comodo Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition RDN/Generic PUP.z
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.1cd03d64a1906b7d
Emsisoft IL:Trojan.MSILMamut.6896 (B)
Ikarus Clean
GData IL:Trojan.MSILMamut.6896
Jiangmin Clean
Webroot Clean
Avira ADWARE/CsdiMonetize.nhcdr
Antiy-AVL Trojan/Generic.ASMalwS.53CB
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Gridinsoft Malware.Win32.Gen.cc
Arcabit IL:Trojan.MSILMamut.D1AF0
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Program:Win32/Wacapew.C!ml
Google Detected
AhnLab-V3 Trojan/Win.MSILZilla.C5289426
Acronis suspicious
VBA32 Clean
ALYac Gen:Variant.Strictor.266661
MAX malware (ai score=87)
Malwarebytes Adware.Csdimonetize
Panda Trj/GdSda.A
APEX Malicious
Tencent Msil.AdWare.Csdi.Ocnw
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Adware/CsdiMonetize
AVG Win32:AdwareX-gen [Adw]
Cybereason malicious.2efb62
Avast Win32:AdwareX-gen [Adw]
No IRMA results available.