Static | ZeroBOX

PE Compile Time

2067-04-27 14:34:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000457a4 0x00045800 6.99101901708
.rsrc 0x00048000 0x00049f80 0x0004a000 6.0648280602
.reloc 0x00092000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x000909a8 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x00090e10 0x000000a0 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00090eb0 0x000003ac LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_MANIFEST 0x0009125c 0x00000d21 LANG_NEUTRAL SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
41{abg=
h\vLBcx
6$kB^$
,~\w-;
PU\Sv_
@U'T1
/7d[~g>
W)z)Ii,
EliSa;n\C
<+K\3N
j,pFrn
A`nhGM
8l<.tn
882m!,
8)jF_O
:fq@|h
SoLE~b;
r/=PwI
cihe+{E2
-#|I=D
2''!NfO
n4cq2?
JB`L.c
'X%r0+
3zD(N|
lrqeY{
>6-HHqA
sY5':g
??+B I;
u(R>Sh4j
1g>i 8I
K,ywgt
x@sTsx
$s#uX6)
p=lh.w8
^)X8r3
>k6/y[R
*J?<C}
dZ=#mL
b\U4R
WTC%@$
+CX/GA`6
"9~PB_
P79,T1F
S%~O7z
wOY?rf
kO).'^h
:eJ~4R)
mh5-"Yx
g>8R|L
|KPj~W
5~Ew_O:
+8xVC`
xq@{\N
YhwW<0
SQA\61
g+2.Ue
vlfULn
t /d5+
24:'e2Q6
&%\.J2
}`12L}
}3fw}8b
bnYs]/
0=ez+z
O<nayO$
!'>0(!
Q^015w
PFWGjj
e]CF<#
&Q5'#bM
A[>{z\
fJ&828
t\s"Ln
#Nj8*nH
`j455]E
;S-s#^
Z0Jqmxi
_c<<xQ
>+`"uX8
$z0Rs%
=Paw@_
Hc+NA:
&KmD<R7
~Bwr@y
!`[^Db]
ZMlYC#
\>M9n99!
sVP8i.S
K_,-Q0
*/w|52
;@7pc$mFm
|)`j{x
xqX%&jBG
YQ3t`~
8,Xh,_
}Pu4qF
s7KeD
qM).`~
{l:vK^
S%FT'Ur
uYr;9d[)
3wM'Q1
"bVTh71=
"<%cM>
`h[=*tYyZ
w8i{YmN}
AGFp4P
Ug`8Sv
K^:l:)|
Igzy2z
AwDfKQ
svlM&l1'C
6}Id<a
d:[W@/`0
ry@l|
X_^vCz
:\fyuu9
pLe]',
I348vgj
c2eM"q
Xv;k-i5
I;92W
a1?V+X
hw6tpw
x1iJV~
_,;m9+t9
OMorF<^
9d*4 B
#}Y>ED
<E=n(4$
,_OMCi
nuDUa$,ou
<swV^R
){J,i*
6;vPV0*
UkwY|e
74eM'l
1e<(\r
P0Q==l
:MXEU+
< qw,B
WLC~"!:
Dw||el
jWt%,Z
?}zj/7
A65{Sv>
ZR{,hR
^[0HnQ
MgY+8na
Er~RL0
D[154v %|
p?|et=
6kKa<,
(AEH1^
QTbC8B
xXjSdw
ch QA
%Hc"N"
+H, &c
hM*wji
Ws?#P-
=q""&B
TnCF}Y
oxgHibL
H<m`Ru
#=Jkp/M
{yoTfh
)}N?d[
*JU!OB4
{wyiAu
*)\9]
\I<}<
eTt:Ae
)"jAFP*
%()lLV
3;2m=i
/eJ/#z
l?2;HK7n*K??g
Nx][=Va
BL;?"1
kL+oZS
a_nMQ|
PTD^G$\S
\Jf,EhV
ybZ<gx&
4$bJdW_P
}q57:.
2}opvq
&$$e\zw
w>FKma.a
=zBR%<
\DHaQ[
Rpd%mK
''/7Y}
[-X;;#
%S|}S<
"F[N5b
2+((<k
Kd-7>
bOn0?Lv
Ff2;J{
l5uj4k
An=7@^
Z?_b`
PQLa85
7 [rZ
34b%&8L
{Z $+3
qTZ *X
+%&8^
,g'Z 0D
S5Z Ie
vr:Z "
* }%0d8R
7Z .u~
_bj/
}Z}Z Ye
_bY*
JrweZ
l\Z Oo
+byZ 2
"Z 6pIBa8q
mqyZ G
Gm#%&8t
7^9aZ
r1)Z D
e aBwma%
Z @7`Ha8/
nU%&8
'B@J%+
kZ A7]ma8
z.zZ -
embIZa8
-Z _d.
C*u8Za8F
GKZ pcLa+
Z_bX
uuZ `&Yca8K
G/qz%+
Y_cX*
T 7*8
L-zfZ
ue=<%+
PxZ +/<
lCZa8'
4R ,p@7 G
DD5%&+
:%sX
@{EzZ [
99sX
sZ d#
,5r%Z g
Z MnMba8
r Z RO
Z IUeHa8j
Rw9+Z 'p
8& ?'*
T#dZa+
&% ?Y
!r>%&+
Z !dADa8|
pQZa8u
Y7rZ 7H
13*QZ
_G4eZ
8uub(
Z !St,a89
q%&8C
Vk_z%+
,r&TZ
w,fl%+
U}Z DE
,9 {D:
zv0g%&8
@P@X(D
8#pZa+
1g'4(
% X!wG(
D#oZa8X
$NZa8P
{V>Z U<3Ia82
i/d5%+
e>%&88
Z e|{8a8n
)]Xa8=
z~'Z +
]`JV8v
dDZa8:
3M%&8s
',Za8Y
orQO8
3:%&8u
BG^+%&8
?*lAZa8
3>SZa8
U,Za8Y
Z 93%_a8u
9Za8n
v4.0.30319
#Strings
poweroff.exe
mscorlib
SuppressIldasmAttribute
System.Runtime.CompilerServices
<Module>
Assembly
System.Reflection
.cctor
System
RuntimeTypeHandle
MethodInfo
MethodBase
Thread
System.Threading
ParameterizedThreadStart
ResolveEventArgs
ValueType
Object
Stream
System.IO
nn&tJ3K_'P|T5~6^T&;}\;6z*
System.Windows.Forms
IContainer
System.ComponentModel
TextBox
EventArgs
Dispose
IDisposable
ComponentResourceManager
Control
G3OVY6pZ(%NFG1!1JaCu/A8A&
UserControl
ContainerControl
AppDomain
ResolveEventHandler
<>9__0_0
AssemblyName
List`1
System.Collections.Generic
RegistryKey
Microsoft.Win32
Environment
SpecialFolder
WebClient
System.Net
RemoteCertificateValidationCallback
System.Net.Security
SecurityProtocolType
WebHeaderCollection
NameValueCollection
System.Collections.Specialized
ProcessStartInfo
System.Diagnostics
Process
ThreadStart
DirectoryInfo
<>9__8_0
X509Certificate
System.Security.Cryptography.X509Certificates
X509Chain
SslPolicyErrors
RijndaelManaged
System.Security.Cryptography
SymmetricAlgorithm
PaddingMode
CipherMode
ICryptoTransform
MemoryStream
CryptoStream
CryptoStreamMode
Encoding
System.Text
HttpResponseHeader
Delegate
WebRequest
WebResponse
Random
<>9__2_0
GetProcAddress
kernel32.dll
GetModuleHandle
GetCurrentProcess
IsWow64Process
StringBuilder
SearchOption
FileSystemInfo
BindingFlags
Binder
HttpWebRequest
DecompressionMethods
StreamReader
TextReader
R?a8!O->S?<E"@FuY\Y*zt$\
RegexOptions
System.Text.RegularExpressions
J;v6n#PpI%C8T;$|A*(/?)a+)
ResourceManager
System.Resources
CultureInfo
System.Globalization
Settings
pwr_ff_hPrNWGsBx6rgX7gq.Properties
ApplicationSettingsBase
System.Configuration
SettingsBase
Default
ConfusedByAttribute
Attribute
poweroff
CompilationRelaxationsAttribute
RuntimeCompatibilityAttribute
DebuggableAttribute
DebuggingModes
AssemblyTitleAttribute
AssemblyDescriptionAttribute
AssemblyConfigurationAttribute
AssemblyCompanyAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyTrademarkAttribute
ComVisibleAttribute
System.Runtime.InteropServices
GuidAttribute
AssemblyFileVersionAttribute
NeutralResourcesLanguageAttribute
TargetFrameworkAttribute
System.Runtime.Versioning
CompilerGeneratedAttribute
STAThreadAttribute
ReliabilityContractAttribute
System.Runtime.ConstrainedExecution
Consistency
SecurityCriticalAttribute
System.Security
SecuritySafeCriticalAttribute
TypeLibTypeAttribute
DispIdAttribute
TypeLibFuncAttribute
GeneratedCodeAttribute
System.CodeDom.Compiler
DebuggerNonUserCodeAttribute
EditorBrowsableAttribute
EditorBrowsableState
Newtonsoft.Json
JsonPropertyAttribute
NewtonsoftJson.Json
nn\&tJ3K_'P|T5~6^T\&;}\\;6z\*.resources
RMqykYCrKdCmhVBAMPIQhcjfcZjEA
J;v6n#PpI%C8T;$|A\*(/?)a\+).resources
G3OVY6pZ(%NFG1!1JaCu/A8A\&.resources
R?a8!O->S?<E"@FuY\\Y\*zt$\\.resources
pwr_ff_hPrNWGsBx6rgX7gq.Resources.Newtonsoft.Json.dll
String
GetTypeFromHandle
GetMethod
Concat
Invoke
Equals
FailFast
set_IsBackground
get_CurrentThread
Debugger
get_IsAttached
IsLogging
get_IsAlive
ReadByte
get_Length
UInt32
RuntimeHelpers
InitializeArray
RuntimeFieldHandle
GetElementType
CreateInstance
Buffer
BlockCopy
get_UTF8
GetString
Intern
get_CurrentDomain
add_AssemblyResolve
get_FullName
get_Name
op_Equality
Padding
set_Margin
TextBoxBase
set_Multiline
System.Drawing
get_AliceBlue
set_ForeColor
PerformLayout
SystemColors
get_ActiveCaption
set_BackColor
set_ClientSize
EventHandler
add_TextChanged
set_AutoScaleDimensions
set_AutoScaleMode
AutoScaleMode
set_Size
set_TabIndex
set_Text
set_Location
set_Name
get_Controls
ControlCollection
ResumeLayout
set_FormBorderStyle
FormBorderStyle
SuspendLayout
get_MediumTurquoise
get_Yellow
Contains
GetExecutingAssembly
GetManifestResourceNames
GetManifestResourceStream
Registry
CurrentConfig
IEnumerable`1
ToArray
Exception
Enumerator
GetEnumerator
MoveNext
get_Current
Boolean
ThreadAbortException
CurrentUser
ToUpper
ToString
Substring
CreateSubKey
SetValue
NewGuid
OpenSubKey
GetValue
IsNullOrEmpty
Replace
GetFolderPath
Combine
WriteAllText
Remove
ToLower
DownloadString
ServicePointManager
set_ServerCertificateValidationCallback
set_SecurityProtocol
get_Headers
DownloadData
Console
WriteLine
set_CreateNoWindow
ResetAbort
get_Chars
Directory
CreateDirectory
set_Padding
set_Mode
set_KeySize
set_BlockSize
Convert
FromBase64String
CreateEncryptor
get_ASCII
GetBytes
FlushFinalBlock
ToBase64String
CreateDecryptor
get_ExitCode
LocalMachine
Win32Exception
Insert
GetTempPath
Exists
IntPtr
get_Size
set_UseShellExecute
set_Verb
set_Expect100Continue
get_ResponseHeaders
get_Item
WriteAllBytes
Collect
get_ServerCertificateValidationCallback
DownloadFile
Create
set_Method
GetResponse
GetResponseStream
GetEnvironmentVariable
GetDirectories
op_Inequality
DateTime
get_Now
get_Ticks
NextDouble
ToInt32
ToChar
Append
InvokeMember
GetTypeFromProgID
Activator
set_AutomaticDecompression
set_ContentType
set_ContentLength
GetRequestStream
ReadToEnd
TimeSpan
get_UtcNow
Subtract
get_TotalSeconds
set_AutoSize
ClassesRoot
GetSubKeyNames
IsMatch
StartsWith
get_Assembly
Synchronized
JsonConvert
DeserializeObject
ConfuserEx v1.0.0
WrapNonExceptionThrows
pwr_ff_hPrNWGsBx6rgX7gq
Copyright
2022
$db08b18a-0662-4326-a1e8-2181305ff76b
2.2.1.2
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$F935DC23-1CF0-11D0-ADB9-00C04FD58A0B
3System.Resources.Tools.StronglyTypedResourceBuilder
15.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
15.9.0.0
ExecParams
country
partnerName
productName
excutionWidget
buyingChannel
discrepancy
PostBackUrl
userId
prices
salesChannel
active
ipLoggerCode
modeUpdater
modePublisher
paramsProduct
ListProductInstall
UrlTrack
trackPostVar
dailycheck
TrackDecrPrmKey
TrackDecrPrmIv
_CorExeMain
mscoree.dll
8nVDNR
#Rp!rAFV
;t-D_b
`] DDD
v X%?""2
&Ti7@N
}EDD&[
/""2=|
nMDDD.Q
Ge?"""
Rr'"""
EDDD&E
DDNpp|
yVW<>:d
9W{=>[X
$@DFy,
p#o3,Vs
mk-TUJ%2
__`?,;XoY%
<IC[{XlWcU`
#"2]bIPSU
{O?d,g
<g-/X/rV
cu^iP
!b" U
W.OSU6+
92<!xVb2
%kyN?t
&K qPn
a1qDZK
;=%F8-
=F)F6#
8wK2c8-K2
5VkV]G$=
q_d= L)Jcy<
8-K&YNi-
S~3!v-
t!0o[^,
3D:8.V\
BkJm(M
uF)Jc8
%F+Jk)m
Z2c8*$`
D+Ea,Gy
KTdM+E
};PI|^
P#0oZ^,
2%M@7E
IDAT?./x
-S(Rc(
4V)i{)
M(lBn-
i--A7(
2JQ&)O
:fYFn-VkB
<-K^L&
5{VFM|
~^0MSRc$
LVgbkzO
,!>;J)
ohn,{y
udZShC!
I]s\U,
%ZS&)e
052 l+6
7{s&IJb
3~:;#5
gdgng.
cTCPjhOiIT,PM
&ir^,9MS
fs^L&</'<
hLEK6Z
rBfmLM
z{C#>Q
UzO/M9
BcEeIV
{FyNw<
CP?-(g#@
jQ7,K>n
"xFYN7M
y?nr-nr=
IBg<&-
ex2_2(
Q5@,rV
$#NF#N
TDvqrO
>@c?C4
&)Z\j6
%IQ0.r
(HZE5Xlv
lvHVZL
s_2}2`
1+,C[|
y "_Um>
x}xfq c
KDvqrO
HPT]68
"r&"Oq
RDO VO
Uo_0f
!G$Ei(
KUzq*Q
d%i"#+o
%r+tGQ
@dImno
&cz_YQ
Fh[]Dn
2:iB+M
fDyF'Mi%
8XC\d=
CzYF;Iy
.;QD=I
Z/V~E0g
A@FN+M
z]Z:)p
"NSziB
IL/IhF
{m`fmc}
0$pNfI
v;<m5i
E9 &.r3
Ek8[%
104A@5"-
LVkx)r
s|)qW`
IDATVJ
,&VGon
nosmm
sJ3`FYT
B5+`7M
ro<1#~
sg<f?4#~
so2ag65w
!w&cvgS
M{r~G9#
!ou{\[[g#
!n/{Q'
")r&Iy
_~[1KS
\Bw|Z@
,"rZD>C
;.NN r
U~92R)
?/N. r
?::4|!
){=o"K
[DdBD
<_}+vz
iUk4fg
<?xml version="1.0" encoding="utf-8"?>
<assembly manifestVersion="1.0" xmlns="urn:schemas-microsoft-com:asm.v1">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app" />
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<!-- UAC Manifest Options
If you want to change the Windows User Account Control level replace the
requestedExecutionLevel node with one of the following.
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
<requestedExecutionLevel level="highestAvailable" uiAccess="false" />
Specifying requestedExecutionLevel element will disable file and registry virtualization.
Remove this element if your application requires this virtualization for backwards
compatibility.
-->
<requestedExecutionLevel level="requireAdministrator" uiAccess="false" />
</requestedPrivileges>
<applicationRequestMinimum>
<defaultAssemblyRequest permissionSetReference="Custom" />
<PermissionSet Unrestricted="true" ID="Custom" SameSite="site" />
</applicationRequestMinimum>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- A list of the Windows versions that this application has been tested on
and is designed to work with. Uncomment the appropriate elements
and Windows will automatically select the most compatible environment. -->
<!-- Windows Vista -->
<!--<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" />-->
<!-- Windows 7 -->
<!--<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" />-->
<!-- Windows 8 -->
<!--<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" />-->
<!-- Windows 8.1 -->
<!--<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" />-->
<!-- Windows 10 -->
<!--<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" />-->
</application>
</compatibility>
<!-- Indicates that the application is DPI-aware and will not be automatically scaled by Windows at higher
DPIs. Windows Presentation Foundation (WPF) applications are automatically DPI-aware and do not need
to opt in. Windows Forms applications targeting .NET Framework 4.6 that opt into this setting, should
also set the 'EnableWindowsFormsHighDpiAutoResizing' setting to 'true' in their app.config. -->
<!--
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<!-- Enable themes for Windows common controls and dialogs (Windows XP and later) -->
<!--
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="*"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
! " )(-,
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
pwr_ff_hPrNWGsBx6rgX7gq
CompanyName
pwr_ff_hPrNWGsBx6rgX7gq
FileDescription
pwr_ff_hPrNWGsBx6rgX7gq
FileVersion
2.2.1.2
InternalName
poweroff.exe
LegalCopyright
Copyright
2022
LegalTrademarks
OriginalFilename
poweroff.exe
ProductName
pwr_ff_hPrNWGsBx6rgX7gq
ProductVersion
2.2.1.2
Assembly Version
2.2.2.2
Antivirus Signature
Bkav W32.AIDetectNet.01
Lionic Trojan.Win32.Csdi.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Strictor.266661
ClamAV Clean
FireEye Generic.mg.6e622962e3b59498
CAT-QuickHeal Clean
ALYac Gen:Variant.Strictor.266661
Cylance Unsafe
Zillya Clean
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender Gen:Variant.Strictor.266661
K7GW Clean
Cybereason malicious.767236
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Generic.Malware
ESET-NOD32 a variant of MSIL/Adware.CsdiMonetize.BC
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Downloader.MSIL.Csdi.gen
Alibaba TrojanDownloader:MSIL/CsdiMonetize.7d8b037f
NANO-Antivirus Clean
ViRobot Clean
Rising Adware.CsdiMonetize!8.1C9D (CLOUD)
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Strictor.266661
TrendMicro Clean
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
CMC Clean
Emsisoft Gen:Variant.Strictor.266661 (B)
Ikarus Clean
GData Gen:Variant.Strictor.266661
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Strictor.D411A5
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Downloader.MSIL.Csdi.gen
Microsoft Program:Win32/Wacapew.C!ml
Google Clean
AhnLab-V3 Clean
Acronis suspicious
McAfee Artemis!6E622962E3B5
TACHYON Clean
VBA32 Clean
Malwarebytes Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H07AN23
Tencent Msil.AdWare.Csdi.Ctgl
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
BitDefenderTheta Gen:NN.ZemsilF.36212.Jm0@aaSQwfo
AVG Win32:AdwareX-gen [Adw]
Avast Win32:AdwareX-gen [Adw]
No IRMA results available.