Static | ZeroBOX

PE Compile Time

2023-06-01 23:17:40

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x00026d12 0x00026e00 7.91762328847
.rsrc 0x0002a000 0x0000ea4b 0x0000ec00 5.23420417361
.reloc 0x0003a000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_ICON 0x00037c90 0x00000468 LANG_NEUTRAL SUBLANG_NEUTRAL GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000380f8 0x00000076 LANG_NEUTRAL SUBLANG_NEUTRAL data
RT_VERSION 0x00038170 0x000004f4 None SUBLANG_NEUTRAL data
RT_MANIFEST 0x00038664 0x000003e7 None SUBLANG_NEUTRAL XML 1.0 document, UTF-8 Unicode (with BOM) text, with very long lines, with CRLF line terminators

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
917(%
#ffffff
#333333
v4.0.30319
#Strings
nrrckle.exe
nrrckle
<Module>
mscorlib
Object
System
MulticastDelegate
ValueType
Attribute
PoweredByAttribute
SmartAssembly.Attributes
Dictionary`2
System.Collections.Generic
.cctor
ParameterInfo
System.Reflection
object
method
Invoke
nhffskdgsfkdfffdddfrffffdhffsfcfdf
hkgfffgsdffdfhhdrfdafddsshcf
chfdfgfdkffafsfhddhdshdghf
BeginInvoke
IAsyncResult
AsyncCallback
callback
EndInvoke
result
nhffskdgsfkdffddadfrfffffdhffscfdf
hkgfffgsdfffdhdrfdafdfdsshcf
chfdfffdffdafsfhddhdshdghf
nhffskdgsfkdfffdadfrfffddhffscffdf
hkgfffgsdfffdhhddrfdafddfsshcf
chfgffdkffdaffhddhdshdghf
hfsdkffddgfgffhsefdfafdchd
fghhfgsffrfddffffdfffddshfdasdfh
cfhdfffdfadfdfrsfsshdkfffgh
hjfdfffhfadfsffgdfdcdffffshj
ffghrgfdfffffdffffkhsjd
fsfddffffddsdffgfefdfkfghj
gdddfffddhfsfdgh
fhfsdsdfhffddfhhs
hsffffd
ffhfsh
shsdfffasd
sdfffsfh
sdhffffssf
sfsdsfffs
fsffdfshs
gfsffsd
gssdfads
gffshfsgfs
gfdfgsfdg
gsdgdffshsg
gdsaffagg
hsffgdafs
adssgfdds
jddfgsfsf
ggfgssfdfh
jfsdaffdffgg
jffdffgsfgfdgs
jsfsffffdfdf
jdfgfffaf
gdfddsfgfdfdj
kfdsfsfgfh
fsfdffg
sfffaf
fdffsfs
sffssfd
jdfffssk
sfffsdv
gffffssds
gfssfdfdsx
startupInfo
AgSdkkngASjdcIhamkcbjSrbIkppdlldomidInjdkiajpmi
jdfhfdfffssdkfj
hdffdffhfasdkfsh
hdffhdfasfffkdf
fsffgfgfafad
UnverifiableCodeAttribute
System.Security
CompilationRelaxationsAttribute
System.Runtime.CompilerServices
RuntimeCompatibilityAttribute
AttributeUsageAttribute
AttributeTargets
CompilerGeneratedAttribute
nrrckle.resources
{2587e21f-de61-4b15-af53-cfaa2b600d30}
String
Concat
Console
WriteLine
TimeSpan
op_Subtraction
get_Hours
get_Minutes
get_Seconds
Convert
FromBase64String
Encoding
System.Text
get_ASCII
GetBytes
Rfc2898DeriveBytes
System.Security.Cryptography
DeriveBytes
RijndaelManaged
SymmetricAlgorithm
set_Mode
CipherMode
set_Padding
PaddingMode
CreateDecryptor
ICryptoTransform
MemoryStream
System.IO
CryptoStream
Stream
CryptoStreamMode
get_UTF8
GetString
ToCharArray
TrimEnd
ToInt32
Resize
Assembly
GetExecutingAssembly
get_Location
GetDirectoryName
op_Equality
Directory
get_Chars
Exists
EnumerateDirectories
IEnumerable`1
get_Length
ReadLine
ReadAllText
ChangeExtension
WriteAllText
get_IsUnc
Subtract
get_Scheme
UriSchemeNetTcp
UriSchemeFtp
GetTypeFromHandle
RuntimeTypeHandle
Marshal
System.Runtime.InteropServices
SizeOf
ToUInt32
IsNullOrEmpty
IntPtr
Exception
BitConverter
get_Size
op_Explicit
ToInt16
Buffer
BlockCopy
ToString
BitArray
System.Collections
set_Item
SetAll
Boolean
ArrayList
Double
ToArray
Remove
System.Management
ManagementClass
GetInstances
ManagementObjectCollection
GetEnumerator
ManagementObjectEnumerator
get_Current
ManagementBaseObject
ManagementObject
get_Item
MoveNext
IDisposable
Dispose
GetDirectories
SearchOption
get_Assembly
ResourceManager
System.Resources
GetObject
RuntimeEnvironment
GetRuntimeDirectory
Combine
AppDomain
get_CurrentDomain
AssemblyName
DefineDynamicAssembly
AssemblyBuilder
System.Reflection.Emit
AssemblyBuilderAccess
DefineDynamicModule
ModuleBuilder
DefineType
TypeBuilder
TypeAttributes
GetMethod
MethodInfo
MethodBase
GetParameters
Func`2
System.Core
Enumerable
System.Linq
Select
get_ReturnType
DefinePInvokeMethod
MethodBuilder
MethodAttributes
CallingConventions
CallingConvention
CharSet
GetMethodImplementationFlags
MethodImplAttributes
SetImplementationFlags
CreateType
Delegate
CreateDelegate
get_ParameterType
TryGetValue
Intern
GetManifestResourceStream
WrapNonExceptionThrows
"Powered by SmartAssembly 6.9.0.114
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
hQiKOp?
L}|N}X
RsCvy#
F>;FV/
N$gPTl
-e^s31G_
8&X> 22
pez$!
kX&z>qX
~~Wml3
%xF[Y`O
` tmd_
xerN{4
1|\jf6
;kn_d^s{
Q6ukW{uX
>F(yx+
!gy\xBz
;uJi^r
M$]lm<
Bwdc;1
*oSfqA
DcdU)=
}nVvgRy
{oPoq0
?pVgQY
.w_bn1
XbkBmB
oPeOKx-
KM&gw6
TmYdx(
3oxBv<
fWbpR
JYwDqi__
CcS|@pTpA
qI~PpDL
L~zM{]
]ay%<
:z]c{W
,jSbkLP
;pYaZ{mm
x\UrRphOMf+
:T9tu$
7}Uay<
ULwIpP
{sEHn/
=5N_~@yR
/5\jC]
^hlSeb
Ro^{mXz$
-tIlmj:
CeWxvE
/j^nbt
cYec32bn
tVcjMdqQibJ
DNsA~H
w@xF{>
LY'~pN
13NkXpzD
iCd[q=
Vw}^|xN
+uYhnK
D"u_qzM|PrAFv@
AKnWx^eu
@hfXcfJ
HWy6-l
CU}CqV
"w]]~E
$qwKS#
0cjNxTb`I
+oRj~7 4
pC}R~B
DsYdu_
`-lPt,
^vq`0
nKOjYW
AmPpl;
9ldRp@sv
%xiIy8
@j^umo
p|jLu*
lAJpB
23={bO
pWld=8qtrr<
IbGay5
h_kaPfQ
mM{WyUw
e,0EZ&
Wi}Pr>
.|]eb#%
6l^}x$
MVmIOn
SHqIiXri
%LqmBMo
6i`Rwy
)oasPe
yGwTyY
Sx{I}F
rd29ou%
9boJxY<
bZoCkvZ
']m\yo
F1*}m>
fJrYgab
p\zcM9
]'lEI3
M(qvrFE
EP~Kj]
:aq!%-
,qjLtNR
0}[`Sa
FofcIyM
:_#uWhPfi
X?Qwl?
*hRgx.
.uvWfhEY
a_g_fhF
X {gGT
yxKiRe>
-u^^pD
Ojwb0J
EkYaPM
&qcC~Mbf(
r_jgC}RSzD\
CxK|4z
{LUq~7
:vdr/e
#BsK~Yk_&
W[q}4)
Vi_`UZ
U`]hFY
csFk^tk
Hx;`}s[
MiwMzV$
zA~Go29
KtOXtE
VgFyK|
>zhH{S
tHn^qu
L;d~o:9
hN~@u?!
qqUKi/
aG{AxR8
Gk_rrN
DspVjR
]c[y=0
V%nZUz/
4wHOm~a;
Gb[sRC
wZr|Tto
Skwj1v
w3bu}1
&)ur\}
$"v[rz9
UlfKTg
<?#qb7
[2/yu/
#~mQdEY
=ByOo_[
b^t}C;
.e~@yE
M-n|jE}F
*}WXk
G|E~6V
TmCMl.
<Bh}yC
9vYckEo(
)lFDyH
I%`o_j
o> L7J
[$,396
z$);SQ
2q&8M
IK ==U
$rjszw
g!)1,L
].%0N =Z
^(6QM$*+
w'G+@A
Xvt$*b
Y%9>J4F
}5?K*H
7%S#N7R
E%Q)@70q
k,5V<'P
y(0N5)l
k09P<g
@;<M-m
j 2K-H
_+JDU
X=::I ?Z
v:C)ID
N98W:+^
U,I#/3SF
_9:T97\
G"A-D0.[H
!9R=685
ZP(+;D81
y1G09d
r*0?A&)
J-D2M+
k$,X)M
5O0//B!P
K4M,"c
v#7B06
w.&G14
B$9V%)K
xw/Bq)XdD
J}(&g^
qYS,m4!
Nu-$wu
bT:;he
aN4Fq>w
lVF%sM
mM9V^Z
nW,St*.x;
t]6;k`
O}?)v\
/O?|>$
ZY'p9%
xq1Kk3-fl
rR&,bg
cn-BOO
bh&Os()x>#
rI8:oj
l`"?|k*
Gp$OvS
Gu:5r=
zj"LSc
rW,5|d
@r!9zj
r^;CiA
jB=D[N
h\58{l"Fb?
he#HWc
C@ t6#
ai#<}D
Vy4Rj@
zp1FUh
vF*1nc
_{#8p<:
Ox5 }Q
Qs[pU
tVD$uE
aU;@[l
J#[b97
pZA3~_
+zZag>
5zSZu^ot
_f`Ybl
>msV~pQ
[h]kfdE
VjgFx=
UkZdr_\
q~\mMfS
'nXea?-
HrF|E~SzB
EKuRs4*+
f[ma[ub=
bk_hKS
#hWV|fPlbH
Pd`D~D
0kT`YfPYp;
MbbCxVr@
'x[l`AvXxJ
EffB}2
!vUjZk`N
EZyN~GtZvD
)~]rrS
!vvO|Rn\
[h`D{,
G`WyYkeF
AVuJzK
*{Zm_h_qQc]n^ze:
ZiaC~/
$y\sqR
Un]sO}{H
?pSdh9
-~nJu*
AbYwSa_l\xg8
"sReg@wYyK
QqC}N~Z
C`hLs$
wuN}So]
D`_PsD
YjbFy.
LcaByWsA
Lb^ll?
Mc_mk8
<qTkYjaO
Xi^pPb^m]wj;
uXo]fU{Wec@
.}mGz+
#tWh\eR|\nj9
BaiKv'
Ce\QtKyJ
#txI~PpB~M}W
@UxO}Fu[wE
/|lHw(
VuuOr#
AbjNq&
CTwH|Er\|N
TmZtTfbA
XkcE|1
CdS}]oi:
&wVi[l[uUgaB
P~Zhh;
)zq_{I
@ckMt)
=rQff?
&ezY18
nmrvFI
@ckMt)
2k{=-T
`uLwH0
If^odBv<
FkYqz1
4xNNqEc:
-pa@ss&
;~_]!)
]jBZ1L
}iEWC,)
*n2xg1
,w_aXe`/
LcaByWsA
Lb^ll?
WnXsrRhP
,,wvOV
xVoV50
Gh_c5=
^a[c]gPlT_
.enAj.
NkVdSfJl`&
GdUeTaQWg'
/zVXl2
C1o]q`
Fe>#?S
!tUi{7
9x^hIla
2jTa[gPWl5
Rmb@o$
=}m>oy+
)oN{VeSh[Y}3
EvQbNK|6
({UbU_
*hlBb5
5kINj2
)jvBj[
vS\q\9
!nHpJNu=
Cg]cXX
KX~Bx@{;
+aZiOsIOt<
?'ajv.
^tXM|~&
o}lMvY
LR}^`R9
WncF}S
|jB}Q
JiWto5
Uo_aStpH
+yMsaF
=pUh^i`L
Yl]qS_
,}kKx+
MiTvl9
Akg@w<
WoVxvO
~f@}O
Ea\ndAxAxR
IgoG~P
Lf]px6
JdZk^cV|c>
7q]ydF|I
EmTia?
3jsJtW
2ivOwZ
Bmd@z>
HcbBx@zOuE
CcYaYpn@
E`^qpTnR
{dA}P
Kb\of>
SsIqi@~P
@d^bXqo?
.vLtnC
AiaHvH
&}jC{V
DlfKyQ
QlZul8
RkS~wO
#zdG~F|D~S
GjXrw.
LgpMyT
/wMumDzT
Cf\n[R{R
:q^woB
2vlE{S
ElRl]X
Id]icG{NtF
DmSk`;
WnXsrRhP
Je\hbF|U
?v_vp[
SjTwn6
VoWz{K
BbX`ZoUef=
5p]xfI
8s\yeH
PtNrhA
Da]pqUoS
E`mHvY
AleA{?
I`^py4
HclIuX
@hbG}M~5
AhVha<
Jc[vo7
Q|uQkO
FkYqz1
Dg^f\d^sqI
R}tPjN
Fj`IwG
Gk_rpJ
PmYtm9
MdZtu0
;r[rl?
ObcCyAyP
Le[sx3
=xe@~Q
Cg[nTfc:
RrHpj?
Kf_g]e]tjD
KbkB|O
Ng_rsSiQ
Bf\ukC
Na`D~BxQ
DBzG~Hd4
MhUvl8
$jJo3F
PhDxN|\nK
*nEDu@~Ji1
+wImaD~L
J"(/?O:+c
%{[kZlZsN{vT
*xoJv(
@e]SsC
(~^puO{T
QWRkaXRpb246IA==
U3VidHJhY3Rpb246IA==0SG91cnM6ezB9LCBNaW51dGVzOnsxfSwgU2Vjb25kczp7Mn0=
U0BMVCZLRVk=
QDFCMmMzRDRlNUY2ZzdIOA==
QyA6IHswfQ==
ZGFkYWg=
ZGRkZGRkZGRkZA==
RW50ZXIgVmFsdWUgb2YgTiA6IA==
b3JpZ2luYWx+Y3M=<Ly8gQ29weSBvZiBvcmlnaW5hbCBjb2RlIChub3Qgb2JmdXNjYXRlZCkNCg0K,aHR0cDovL3d3dy5pbmNsdWRlaGVscC5jb206ODA4Mg==$ZmlsZTovL015U2VydmVyL2FydGljbGUuZXh0@R2l2ZW4gVXJpIGlzIGEgVW5pdmVyc2FsIE5hbWluZyBDb252ZW50aW9uIHBhdGg=DR2l2ZW4gVXJpIGlzIG5vdCBhIFVuaXZlcnNhbCBOYW1pbmcgQ29udmVudGlvbiBwYXRo8U3VidHJhY3Rpb24gb2YgdGltZXNwYW4xIGZyb20gdGltZXNwYW4yIDog8bWFpbHRvOmFydmluZEBpbmNsdWRlaGVscC5jb20/c3ViamVjdD11cmk=hR2l2ZW4gVXJpIGlzIGFjY2Vzc2VkIHRocm91Z2ggTmV0UGlwZSBzY2hlbWUgb2YgSW5kaWdvIHN5c3RlbSB1c2VkIGJ5IHRoZSBXQ0Y=lR2l2ZW4gVXJpIGlzIG5vdCBhY2Nlc3NlZCB0aHJvdWdoIE5ldFBpcGUgc2NoZW1lIG9mIEluZGlnbyBzeXN0ZW0gdXNlZCBieSB0aGUgV0NG0ZnRwOi8vQUJDLmNvbS90ZXh0RmlsZS9uZXdmaWxlLnR4dA==$R2l2ZW4gVXJpIHVzZXMgRnRwIHByb3RvY29s
PGh0bWw+PGhlYWQ+LPG1ldGEgY29udGVudD0nSUU9RWRnZScgaHR0cC1lcXVpdj0nWC1VQS1Db21wYXR2aWJsZScvPg==
PGlmcmFtZSBpZD0ndmlkZW8nIHNyYz0gJ2h0dHBzOi8vd3d3LnlvdXZ0dWJnZS5jb20vZW1iZWQvezB9JyB3aWR0aD0nNTYwJyBoZWlnaHQ9JzI3MScgZnJhbWVib3JkZXI9JzAnIGFsbG93ZnVsdmxzY3JlZW4+PC9pZnJhbWU+
bnJyY2tsZQ==8RWxlbWVudHMgb2YgQml0QXJyYXkgYWZ0ZXIgc2V0dGluZyB0cnVlOg==
CUluZGV4IA==
OiA=8RWxlbWVudHMgb2YgQml0QXJyYXkgIGFmdGVyIHNldHRpbmcgZmFsc2U6
UFFS0VmFsdWVzIGluIGFycmF5IGxpc3QgYmVmb3JlIFJlbW92ZQ==0CgpWYWx1ZXMgaW4gYXJyYXkgbGlzdCBhZnRlciByZW1vdmU=
RDovU2FtcGxl
R3JlZW4gY29sb3I=
MS5EaXJlY3RvcnkgTm90IEZvdW5k
U3ViIGRpcmVjdG9yaWVzIGFyZTo=
Mi5EaXJlY3RvcnkgTm90IEZvdW5k$VmFsdWVzIGFmdGVyIHN3YXBwaW5nIGFyZTo=
Yj0= dVRJOGJFSUtzL0c4RjZDL0xBY21RQT09 VGJyL2FuejBrZ3VldExGaGQ5TXB0dz09 Yk0rZWk4YmhqbVVzdXA4R3JIZDJsdz09
RHluYW1pY0RsbEludm9rZVR5cGU= TzM1YlZpZDl2dUQ1SnMrZDZJVm1lUT09 bFNYZ2pRMGxCN2hYeFIrWnhCVWFhZz09<aGNicEtlUWlGSGd2dUdzN2xRM3E2ZW53VWxMSy9vbkJ2dWVuL29YTjkwQT0= TU1qczJRZ0FzMEV5Z2J3dE1kK0Y0UT09<eFhyK25JTE1Md1RUSThJNXBBRGIvbytqZmdnc2dwSWpOVWFpbU9WTm0xRT0= ODh4a0lFYnZxMXBESGtibm1jSzNSZz09<R054SE1SbXBtdkJVVVkyVk5zMFNGY0N0aDNJL2NtaHdXNU03cEdzYllRVT0=<cEIza1RXbUltc0RObGJweW5NUDJFR3B2MWk5SkYwemJ2MzZKbzZNQVBiMD0= OFNzVC9QU1ZyOGt2YUZaWUw0bVFGUT09 bG9ORXdROEhlSDR1YkN1T0RwNmlrQT09 N0tJTnZhZU5wSlgvazlMa3ExVmQ2dz09<cHA5U1hFVm50cnh6bjV3Y3B1YWhOVnVJRy9rVitCVEJ5OFJlQWtCa001TT0=
_CorExeMain
mscoree.dll
U]}TVu
<[^Ya*
%Sq0B5
92y2o}
Ge"Fi@
9W#I3v
r%jY^6
sTCn:6
g[r)y8
IZZYfaQH
?QIN;]
kY9VM,R
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="x86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS></application></compatibility></assembly>
{2587e21f-de61-4b15-af53-cfaa2b600d30}
nrrckle
MAINICON
VS_VERSION_INFO
StringFileInfo
000004b0
Comments
This installation was built with Inno Setup.
CompanyName
Letasoft LLC
FileDescription
Letasoft Sound Booster Setup
FileVersion
1.12.0.538
LegalCopyright
Copyright
Letasoft LLC
ProductName
Letasoft Sound Booster
ProductVersion
1.12.0.538
VarFileInfo
Translation
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Stealer.12!c
tehtris Clean
MicroWorld-eScan IL:Trojan.MSILMamut.11009
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee Artemis!074F10E31713
Malwarebytes Spyware.Stealer.MSIL
VIPRE IL:Trojan.MSILMamut.11009
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Clean
BitDefender IL:Trojan.MSILMamut.11009
K7GW Trojan ( 0059df7d1 )
Cybereason malicious.74ea97
BitDefenderTheta Gen:NN.ZemsilF.36250.nm0@aKFcdCnG
VirIT Clean
Cyren W32/ABRisk.LFOB-9002
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of MSIL/Kryptik.AHUA
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:MSIL/Stealer.2a42a316
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Kryptik.220672.A
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:XlyS3efE85yIZZTMXZOtwg)
Sophos Mal/Generic-S
Baidu Clean
F-Secure Trojan.TR/Kryptik.skbkr
DrWeb Trojan.Inject4.58211
Zillya Clean
TrendMicro TrojanSpy.Win32.REDLINE.YXDFIZ
McAfee-GW-Edition Artemis!Trojan
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.074f10e3171398d4
Emsisoft IL:Trojan.MSILMamut.11009 (B)
Ikarus Win32.Outbreak
GData IL:Trojan.MSILMamut.11009
Jiangmin Clean
Webroot Clean
Avira TR/Kryptik.skbkr
MAX malware (ai score=86)
Antiy-AVL Trojan/MSIL.Kryptik
Gridinsoft Malware.Win32.RedLine.bot
Xcitium Clean
Arcabit IL:Trojan.MSILMamut.D2B01
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-Spy.MSIL.Stealer.gen
Microsoft Trojan:Win32/Casdet!rfn
Google Detected
AhnLab-V3 Trojan/Win32.MSIL.C2375978
Acronis suspicious
VBA32 Clean
ALYac IL:Trojan.MSILMamut.11009
TACHYON Clean
DeepInstinct MALICIOUS
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.REDLINE.YXDFIZ
Tencent Msil.Trojan-Spy.Stealer.Xfow
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/Kryptik.AEBO!tr
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.