Static | ZeroBOX

PE Compile Time

2023-06-18 12:06:07

PE Imphash

8b20c0aa1a6b70c064e1b0a2222ddac4

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0000ea0f 0x0000ec00 6.8232319246
.rdata 0x00010000 0x0000356c 0x00003600 5.53256288537
.data 0x00014000 0x0000489c 0x00003e00 5.14369118198
.rsrc 0x00019000 0x00000428 0x00000600 2.4368057216

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00019060 0x000003c8 LANG_ENGLISH SUBLANG_ENGLISH_US data

Imports

Library KERNEL32.dll:
0x41000c lstrlenW
0x410010 VirtualProtect
0x410014 GetProcAddress
0x410018 LoadLibraryA
0x41001c VirtualAlloc
0x410020 CreateThread
0x410024 WaitForSingleObject
0x410028 GetModuleHandleA
0x41002c Sleep
0x410030 RtlUnwind
0x410034 RaiseException
0x410038 GetCommandLineA
0x41003c GetModuleHandleW
0x410040 TlsGetValue
0x410044 TlsAlloc
0x410048 TlsSetValue
0x41004c TlsFree
0x410054 SetLastError
0x410058 GetCurrentThreadId
0x41005c GetLastError
0x410064 HeapFree
0x410068 HeapAlloc
0x41006c TerminateProcess
0x410070 GetCurrentProcess
0x41007c IsDebuggerPresent
0x410080 ExitProcess
0x410084 WriteFile
0x410088 GetStdHandle
0x41008c GetModuleFileNameA
0x41009c WideCharToMultiByte
0x4100a4 SetHandleCount
0x4100a8 GetFileType
0x4100ac GetStartupInfoA
0x4100b4 HeapCreate
0x4100b8 VirtualFree
0x4100c0 GetTickCount
0x4100c4 GetCurrentProcessId
0x4100cc GetCPInfo
0x4100d0 GetACP
0x4100d4 GetOEMCP
0x4100d8 IsValidCodePage
0x4100e4 HeapReAlloc
0x4100e8 HeapSize
0x4100f0 LCMapStringA
0x4100f4 MultiByteToWideChar
0x4100f8 LCMapStringW
0x4100fc GetStringTypeA
0x410100 GetStringTypeW
0x410104 GetLocaleInfoA
Library USER32.dll:
0x41010c DragDetect
0x410110 GetWindowRect
0x410114 SetCapture
0x410118 SetRect
Library COMDLG32.dll:
0x410000 GetSaveFileNameA
0x410004 GetOpenFileNameA

!This program cannot be run in DOS mode.
SrRich
`.rdata
@.data
ppp))y
ppp-(*a
rqqpppp
q[Tp/p
qq3PFop
\qqqpppp
#hm$`\
#xm$`d
ppp&*y
+x5.<a
hqqqpppp
hqqq5#
xrqqpppp
nKqapp
hqqqm.l
ppp"(y
|rqqpppp
+xm,fd
rqqq[Xp/p
#xm$``
rqqpppp
q[\p/p
rqqq[\p/p
#xm$``
ppp0.y
rqqpppp
rqq0ppp
rqqKpppP
rqq0ppp
rqqlppp
rqqKppp0
rqqPppp
rqqnppp
#xm$`dq[`p/p
rqqq[dp/p
\ppp!a
~ppp!y
#xm(H
pq[Pp/p q[Lp/pa
mppq[Dp/p
ppp%&a
rqqpppp
QQSVWd
0WWWWW
0WWWWW
_VVVVV
^WWWWW
HtHu4j
s[S;7|G;w
tR99u2
0SSSSS
>=Yt1j
jThp-A
j@j ^V
0A@@Ju
0SSSSS
_VVVVV
;t$,v-
UQPXY]Y[
URPQQh
j hP.A
0SSSSS
0SSSSS
t"SS9]
v$;5$xA
PPPPPPPP
PPPPPPPP
<+t(<-t$:
+t HHt
u;hd!A
u,h\!A
t+WWVPV
bad allocation
rLqCMS5X8LlLU7plVR
JbYW3NRc
w56IRs18mNGRkR7PT4JN
wxKzD4ZFTfI7UAd
qJZhhszcnvLH8
z1KpVqTSCqfFX
kZ9HUfQRXXEdcQ9cNSqUIhFasFzjCHY
kernel32.dll
RdJwwahsGVHYeWXb1EecHTfAr5s1q8Co
EhmcVv83DV8T
zBRi9Rtnhcy85Y4424FRr
DMlDFauLSj3aHNq
qoECgan89Y1HCc
CA8CtqcCE7aKyq
FreeConsole
oFon4oep00Q7xgOoqnV3YvtUjHmmK
WjDZLf3HhPEaayAV
Hello, World!
t29zX5CbEt3RfARl
rFzP3AmLeXltWmJ
xRuGarcaRqCST2vULkZSL9a
jrM8ltZYxLX
XrKXcBJv8
pBjcI6dtV1lI
7p29NIsPlSCa7lpxoOHb9
i^RJ}^
^l.^m
"\tqS]
]nJ3^c
#^WxJ^
=]d']6
R]7D]<
bad allocation
string too long
invalid string position
Unknown exception
GAIsProcessorFeaturePresent
KERNEL32
bad exception
EncodePointer
DecodePointer
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
CorExitProcess
runtime error
TLOSS error
SING error
DOMAIN error
An application has made an attempt to load the C runtime library incorrectly.
Please contact the application's support team for more information.
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
Microsoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
USER32.DLL
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
1#QNAN
1#SNAN
SunMonTueWedThuFriSat
JanFebMarAprMayJunJulAugSepOctNovDec
WaitForSingleObject
CreateThread
lstrlenW
VirtualProtect
GetProcAddress
LoadLibraryA
VirtualAlloc
GetModuleHandleA
KERNEL32.dll
SetCapture
GetWindowRect
DragDetect
SetRect
USER32.dll
GetSaveFileNameA
GetOpenFileNameA
COMDLG32.dll
RtlUnwind
RaiseException
GetCommandLineA
GetModuleHandleW
TlsGetValue
TlsAlloc
TlsSetValue
TlsFree
InterlockedIncrement
SetLastError
GetCurrentThreadId
GetLastError
InterlockedDecrement
HeapFree
HeapAlloc
TerminateProcess
GetCurrentProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
ExitProcess
WriteFile
GetStdHandle
GetModuleFileNameA
FreeEnvironmentStringsA
GetEnvironmentStrings
FreeEnvironmentStringsW
WideCharToMultiByte
GetEnvironmentStringsW
SetHandleCount
GetFileType
GetStartupInfoA
DeleteCriticalSection
HeapCreate
VirtualFree
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LeaveCriticalSection
EnterCriticalSection
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
LCMapStringA
MultiByteToWideChar
LCMapStringW
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
pmppplpppqqpp
ppppppp0ppppppppppppppppppppppppppppppppppp
BccfLppppppp +pp$ompo
pppppppp
pNpeo@ppNppphpppppp~0pppPppp
pppp0ppPpppnpplppppppplpppppppp
pppnppppppnp0
pp`pp`pppp`pp`pppppp`ppppppppppp
0pp!pppp
kppppppppppppppppppp
ppdpppd0pp8ppppppppppppppppppppppppppppppppppppppppppppPpphppppppppppphPpp(pppppppppppB
pppxPpppPpppNpppnppppppppppppppPpp
pppjpppLpppppppppppppp0pp0B
ppdpppp
pppnpppFpppppppppppppp0pp.pppppppppppppppp
0pppppp(pppnpkp
Uppoppp`ppjpppppppppppppppppppppppppppppppppppppppppppppppp]@np]pppopp_Q0
`ppfQ0f^pHlppjJFp]@lp%pppnpp_\\P1papHkppjfj
_ppfH^ppfDoF
ejiQ`HjppjKZ\HippjJP
ippH]ppfHnppjJjHnppjJFp]@mp
pppmpp_H\ppf
_ppffeZdE)ih
HZppfDCg
YppfPbpnp^pHoppjCoFjHmppjJHfppjg
YppfHnppjJhY
jHnppjJFppp]@mp
pppmpp_H\ppf
_ppffeZdE.ih
HZppfDHg
YppfPbpnp^pHoppjCoFjHmppjJg
YppfHnppjJhY
jHnppjJF]@dp
ppplpp_\\P1papHkppjfj
_ppfH^ppfDoFjnQBHjppj^or[gppnKY^oHhppjJK[V[\\
_ppf\\\\HgppjJP
ippH]ppfHnppjJjHnppjJFpU@lp&pppkpp_
XppfnX
WppffjC[
VppfmlV
TppflBgjmlV
pFppoTppnpcpC6pfpppppppp**pm`ppoU@mp
oppppppHfppjHeppjHdppjHcppj
pFpp/Tpppppppppp
oppmppp`ppoRnHRppfF.
&.opopppppdppp
<B@B=@=?7ppppkp
ppp`hppM
ppppH]ppHjppM
p Wpp`pppM)
pppppppnppo
3n\gnpppvo=pZppopppSpppgppp.ppp_pppJpppRppp;ppp^ppplpppkpppmpppgpppopppnpppippppp
iopppppjp]i
gjp8j!gap
ffpff!gjp
ffpjpZhfpjp
lfpjppk
hppppVpppppopoppp`p
hhg/popopmopp%hpppjp^pmoppzkpppdp^pmopp
kppp^p^pmopp^fpppWp^pmopp
npppOp^pmopp(npppCp^peo`p*mpp
p4p^p
@pjojjFljo
pgojjFljo
pcojjFljo
p_ojjFljo
n[ojjFljo
nWojjFljo
kOoopSjOoop!lOoop
fOoopfOopppp
hLooppppp
PYkDokppppp
PFgDojppppp
k?oippppp
Pvh7ogppppp
l0odppppp
l)oappppp
l!o]ppppp
oYp Ppppp
oMp4Opppp
oMpXNpppp
oIp$Lpppp
X.gjpIppPppppppopAkppnp}gnpmpMkppop3kppop
hppop5lppnpahppop
kppmpofppop
hppnp,kppmp
gpPppppppop
gpPppppppop
hppmpCfpPppppppop
kppmpgjpplp
hppip2lpphp
kppopihppnp
igp.gop_p.gjpWp.gfpGp.g`p?p.g`p7p.g`p/p.g`p'p.g`pp.g`p
p.gjpgplp
pqpBpep
pmploQploIploAploVpRp?p!p
p?h2hoppomp
hopjokpYknppoipFgoppogp
kopkoepalopnocpMpoppoap
lmppo_p
loppo]p
ppoppppppppppppphgpplppppppppppp
p>lpppplppppppppppp
hppppmpnplpnpkpnpjpnpipnphpnpgpnpppppp
+/,p"+
.'",/,,p
/.$+,p
#/"/)+
#/"/)+
'-+p(/
!*'$+-(/")+p /
/#-(/")+p
'!"-(/")+p
-(/")+p"+
.'",+"/.$+p"+
.'",,'
-(/")+
-!"*')p
#/"/)+
-!"*')p
-!"*')p
#/"/)+
,+*'"+,
#/"/)+
,+ +",+"
#/"/)+
#/"/)+
-!""+-
,+#/",
ppm@pp
ppm?pp
p'p!p/p
ppm>ppA/p
plPoohmPpokPoo__lPooblPoonmiohlinXbnjXkpnnXXlpoohgilXS^'h^'kppS^'mPpbkpnnbbmPpXkinX_Llio^#mj^#iPn^#b_
kPo^#biPmobT_
lPoTbh
lppnplnpppllppplhppplhpnplpppploppplmppplqqqql`ppplPppplpoppl1paplppapl0pppl
ppplqoaplkpppljppplippplgppplfppplepppldppplcppplbppponnjgmj_dmj_`mj_\mj_Xmj_Tmj_PnjhipmnXg`XlponXipnn^+`hjpmXbbgjpmXXbgipmnXhSbgpmnX_P`_L_penX_\_`_dbbXbbbbmppolpoobjpmobbbhophpppppRopop
ohopnpppppeopj(
ppkoppppYop^-
PP>@>=ppGopL>
C<@8=C
;ppdopi?B@B@B@pp)opVB"+
P<ppppppp
ppppnppp
ppp,0pp,Npppppppppppppp`ppppppppppppppp
koppp-6
0pppppppppp
0pppPpppppppppppppppppppppp
0pppppppppppp
ppppppppqKpP0pppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppnp`pppPpp
Xppp pp
ppppppppppppppopoppp8pp
ppppppppppppppoppppp
pppppppppppppppppopoppp
ppppppppppppppoppppp
ppdmppppppppppdm<ppp
p'p!p"p
p'p"p*p!ppppp
rppopppopppppppoppppp1ppppppplpppoppppppppppppppp,pppop
pppppLplppp
ppppppp
ppp(nppop@p@p@p@p@p<p
p@pppVpopop-p
pppppppNpopop-p
ppppppppp:pipop*p
ppppp(p
ppppp@phpop*p
ppppp?pBp@pBp@pBp@ppp:pepop'p
ppppp(p^pop$p
pPpPp>p@p>p=pppFpopop$p
ppppppppp2pepop!p
pppppBpipop p
ppppp(p
ppppp<phpop p
ppp?pBp@pBp@pBp@ppp8phpop/p
ppp?pBp@pBp@pBp@ppp
opppppppppp
3N?B@NP
N12cfcf4
3N?B@N2cfPP4
3N?B@B@B@NP
NA2cfPP4
>N2cfPPPP4
2cfPPPPPP4
=N2cfPPPPPPPP4
NA2cfPPPPPP4A
2cfPPPP4A
2cfPP4A
2ppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppp0ppdppp|@pppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppppp
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
130801120000Z
380115120000Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
PAq=?Mp#
L?n(Zy&
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
210429000000Z
360428235959Z0i1
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
[K]taM?
SA|X=G
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
jj@0HK4
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA10
220117000000Z
250115235959Z0|1
Oregon1
Beaverton1#0!
Python Software Foundation1#0!
Python Software Foundation0
r;<SjB
Mhttp://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Mhttp://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0>
http://www.digicert.com/CPS0
http://ocsp.digicert.com0\
Phttp://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
?U!t]qZ
I^0oH*pp
BMI3Ls!
DigiCert, Inc.1A0?
8DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1
fa#DN'
K+Y"v
~Zvr/eu
?KjBGm
20230607061431Z
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
220921000000Z
331121235959Z0F1
DigiCert1$0"
DigiCert Timestamp 2022 - 20
Ihttp://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
http://ocsp.digicert.com0X
Lhttp://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
(f*^[0
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
220323000000Z
370322235959Z0c1
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA0
http://ocsp.digicert.com0A
5http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
2http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
DigiCert Inc1
www.digicert.com1$0"
DigiCert Assured ID Root CA0
220801000000Z
311109235959Z0b1
DigiCert Inc1
www.digicert.com1!0
DigiCert Trusted Root G40
]J<0"0i3
v=Y]Bv
http://ocsp.digicert.com0C
7http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
4http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
~qj#k"
DigiCert, Inc.1;09
2DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA
230607061431Z0+
/1(0&0$0"
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
KERNEL32.DLL
mscoree.dll
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904E4
Comments
Esta es una aplicaci
CompanyName
Rio Tinto
FileDescription
Rio Tinto Produit
FileVersion
InternalName
AplicacionInterna
LegalCopyright
Derechos de autor
Rio Tinto Todos los derechos reservados.
LegalTrademarks
Marcas registradas
Rio Tinto
OriginalFilename
app.exe
ProductName
Aplicacion
ProductVersion
VarFileInfo
Translation
DBuilt: Release_v3.11.4_20230607.0
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic malicious (high confidence)
DrWeb Clean
MicroWorld-eScan Clean
FireEye Generic.mg.888983f654ddc26d
CAT-QuickHeal Clean
ALYac Clean
Malwarebytes Malware.AI.155098833
VIPRE Clean
Sangfor Clean
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Arcabit Clean
BitDefenderTheta Gen:NN.ZexaF.36250.gq2@a0wYGAli
VirIT Clean
Cyren W32/Kryptik.JZU.gen!Eldorado
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Kryptik.HTUE
APEX Clean
Paloalto Clean
ClamAV Clean
Kaspersky VHO:Trojan.Win32.Convagent.gen
Alibaba Clean
NANO-Antivirus Clean
SUPERAntiSpyware Clean
Rising Backdoor.Convagent!8.123DC (TFE:5:ftKgNsH23pM)
TACHYON Clean
Sophos Clean
F-Secure Clean
Baidu Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition Clean
Trapmine malicious.high.ml.score
CMC Clean
Emsisoft Clean
Ikarus Trojan-Spy.Agent
Jiangmin Clean
Webroot Clean
Google Detected
Avira Clean
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Trojan:Win32/Wacatac.B!ml
ViRobot Clean
ZoneAlarm VHO:Backdoor.Win32.Convagent.gen
GData Clean
Cynet Malicious (score: 100)
AhnLab-V3 Clean
Acronis Clean
McAfee Clean
MAX Clean
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Static AI - Suspicious PE
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Kryptik.HTUE!tr
AVG Win32:TrojanX-gen [Trj]
Avast Win32:TrojanX-gen [Trj]
CrowdStrike win/malicious_confidence_60% (D)
No IRMA results available.