Category | Machine | Started | Completed |
---|---|---|---|
FILE | s1_win7_x6403_us | May 31, 2024, 10:03 a.m. | May 31, 2024, 10:12 a.m. |
-
-
-
-
sc.exe sc stop PcaSvc
2476 -
takeown.exe takeown /f C:\Windows\Sysnative\sfc.exe
2528 -
icacls.exe icacls C:\Windows\Sysnative\sfc.exe /t /deny everyone:f
2576
-
-
-
Name | Response | Post-Analysis Lookup |
---|---|---|
No hosts contacted. |
IP Address | Status | Action |
---|---|---|
164.124.101.2 | Active | Moloch |
Suricata Alerts
No Suricata Alerts
Suricata TLS
No Suricata TLS
pdb_path | d:\Projects\WinRAR\SFX\build\sfxzip32\Release\sfxzip.pdb |
name | RT_BITMAP | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x0002a57c | size | 0x00000bb6 | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00040fdc | size | 0x000001ba | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00040fdc | size | 0x000001ba | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00040fdc | size | 0x000001ba | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00040fdc | size | 0x000001ba | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00040fdc | size | 0x000001ba | ||||||||||||||||||
name | RT_DIALOG | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00040fdc | size | 0x000001ba | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00041664 | size | 0x00000196 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00041664 | size | 0x00000196 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00041664 | size | 0x00000196 | ||||||||||||||||||
name | RT_STRING | language | LANG_KOREAN | filetype | data | sublanguage | SUBLANG_KOREAN | offset | 0x00041664 | size | 0x00000196 | ||||||||||||||||||
name | RT_MANIFEST | language | LANG_KOREAN | filetype | XML 1.0 document, ASCII text, with CRLF line terminators | sublanguage | SUBLANG_KOREAN | offset | 0x00041890 | size | 0x000005b8 |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\KMSkey.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\KmsServer\KmsServer3.reg |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1DHIDDEN1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090314\RemoveWatermarkX86.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\wga\wga.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1STHIDDEN1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\AutoB.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Tel_ID.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1D.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\R2SLIC2.1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\Registry.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1ST.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\DWM.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\KmsServer\KmsServer2.reg |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x64\SysWOW64\user32.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\XPGenuine\wga2.reg |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1D.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1DHIDDEN2.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Restoration.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\ShortcutpatchR.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Shortcutpatch.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x64\System32\systemcpl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLICINSTALLCHECK.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\x64\dwm.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1SIHIDDEN2.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Help.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Cert.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x64\System32\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1SIHIDDEN2.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\VistaRestoration.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\Temp.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\x86\uDWM.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x64\System32\user32.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x86\System32\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\A.I_Run.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x86\System32\systemcpl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\TakeOwnershipInstall.reg |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\KMSOptimizer.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Sever2008key.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x86\System32\systemcpl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090331\RemoveWatermarkX86.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RegistryX64.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\BIOS.vbs |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x64\SysWOW64\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x64\System32\slmgr.vbs |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x86\System32\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\TakeOwnership.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\DWMR.reg |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090509\RemoveWatermarkX64.exe |
file | C:\Users\test22\AppData\Local\Temp\RarSFX0\A.I.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\A.I_Run.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\R\x64\winsxs\x86_microsoft-windows-themecpl.resources_31bf3856ad364e35_6.1.7600.16385_ko-kr_60d6493e5ec01332\themecpl.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090331\RemoveWatermarkX86.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x86\System32\systemcpl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\RSimulation.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\Simulation.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x86\System32\user32.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\x86\System32\ko-KR\Display.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\wga\WgaLogon.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x86\System32\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\x86\System32\ko-KR\shell32.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\bootinst.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\7tokens.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\bootrest.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x86\System32\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\Vistatokens.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\wga\LegitCheckControl.dll |
file | C:\Users\test22\AppData\Local\Temp\RarSFX0\A.I.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\Temp.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\R\x64\winsxs\x86_microsoft-windows-display.resources_31bf3856ad364e35_6.1.7600.16385_ko-kr_6d88dfdedf2ef7a4\Display.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x64\SysWOW64\user32.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x64\SysWOW64\systemcpl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\R\x86\System32\user32.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\VBS\HS.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\7Loader.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\BIOS.EXE |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RegistryX64.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\x86\uDWM.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x64\System32\sppcomapi.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\x64\SysWOW64\ko-KR\shell32.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\wga\OGACheckControl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\ReadyFor4GB\viewmem-x86.sys |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\x86\original\uDWM.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\x86\original\dwm.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x64\SysWOW64\user32.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\boot.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\XPGenuine\winlogon.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\wga\WgaTray.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\Registry.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\VistaBootPro.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\ReadyFor4GB\ReadyFor4GB.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090117\RemoveWatermarkX86.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\x64\winsxs\x86_microsoft-windows-themecpl.resources_31bf3856ad364e35_6.1.7600.16385_ko-kr_60d6493e5ec01332\themecpl.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\Keyfinder.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090314\RemoveWatermarkX86.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\dwm\x86\dwm.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\RemoveWatermark\20090509\RemoveWatermarkX86.exe |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Forever\x86\System32\systemcpl.dll |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Shortcut\R\x64\SysWOW64\ko-KR\shell32.dll.mui |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Option\TemporaryAuto.exe |
section | {u'size_of_data': u'0x00018000', u'virtual_address': u'0x0002a000', u'entropy': 7.4589557735442344, u'name': u'.rsrc', u'virtual_size': u'0x00017e48'} | entropy | 7.45895577354 | description | A section with a high entropy has been found | |||||||||
entropy | 0.637873754153 | description | Overall entropy of this PE file is high |
cmdline | sc stop PcaSvc |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Cert.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Option.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\ReadyFor4GB.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1SIHIDDEN2.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Restoration.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1ST.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Restoration.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1SIBOOTMGR.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\7Forever.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\R2Forever.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\Makegrldr2-2 |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1STVFD.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1SIHIDDEN1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Windows7Optimizer.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\R2Forever.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1SIHIDDEN1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1DBASIC.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1DHIDDEN1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\SLIC2.1\Samsung.bin |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\R2Optimizer.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Adm.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\KMS.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\R2SLIC2.1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\KMS.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Server2008.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1STBASIC.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Cert2.1.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\7RetailOPT.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Cert.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Vista.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1U.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\7Retail.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\DWM.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\key.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\AutoB.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\KMSOptimizer.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1DBOOTMGR.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\AutoB.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Help.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\VistaRestoration.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1STBOOTMGR.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1SIBASIC.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1SIBASIC.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\R2Optimizer.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1SIVFD.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\SLIC2.1SIVFD.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\Hibernation.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\Auto.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source\TakeOwnership.cmd |
file | C:\Users\test22\AppData\Local\Temp\7ZipSfx.000\data\Source64\SLIC2.1D.cmd |
cmdline | icacls C:\Windows\Sysnative\sfc.exe /t /deny everyone:f |
Bkav | W32.Common.3A017B64 |
Lionic | Trojan.Win32.Fsysna.4!c |
Elastic | malicious (moderate confidence) |
Skyhigh | BehavesLike.Win32.Sality.wc |
ALYac | Misc.HackTool.WinActivator |
Cylance | unsafe |
VIPRE | Trojan.GenericKD.4457434 |
Sangfor | PUP.Win32.Agent.Vewe |
K7AntiVirus | Riskware ( 0040eff71 ) |
BitDefender | Trojan.GenericKD.4457434 |
K7GW | Riskware ( 0040eff71 ) |
Cybereason | malicious.9aa8cf |
Arcabit | Trojan.Generic.D4403DA |
VirIT | Trojan.Win32.Generic.CEBR |
Symantec | Hacktool.Kms |
ESET-NOD32 | a variant of Win32/Packed.FlyStudio potentially unwanted |
McAfee | Artemis!3D5FA6D9AA8C |
Avast | Win32:MiscX-gen [PUP] |
ClamAV | Win.Malware.Agent-6371164-0 |
Kaspersky | Trojan.Win32.Fsysna.fcwp |
Alibaba | Trojan:Win32/HiddenStart.e456f989 |
NANO-Antivirus | Trojan.Win32.Diple.dhccqd |
MicroWorld-eScan | Trojan.GenericKD.4457434 |
Emsisoft | Trojan.GenericKD.4457434 (B) |
DrWeb | Trojan.PWS.Siggen1.45571 |
TrendMicro | TROJ_FRS.0NA003H718 |
McAfeeD | ti!2BA75DB3EE21 |
FireEye | Generic.mg.3d5fa6d9aa8cf008 |
Sophos | Generic Reputation PUA (PUA) |
Ikarus | Trojan.ATRAPS |
Jiangmin | Trojan/Diple.wde |
Webroot | W32.Malware.Gen |
MAX | malware (ai score=100) |
Kingsoft | Win32.Trojan.Fsysna.fcwp |
Gridinsoft | Hack.Win32.Patcher.ns |
Xcitium | TrojWare.Win32.Downloader.FraudLoad.R@1cogfd |
ViRobot | HackTool.WindowsActivator.11980543 |
ZoneAlarm | Trojan.Win32.Fsysna.fcwp |
GData | Win32.Application.HStart.A |
Detected | |
AhnLab-V3 | HackTool/Win32.Crack.C456990 |
DeepInstinct | MALICIOUS |
VBA32 | TScope.Trojan.Delf |
Malwarebytes | HackTool.WpaKill |
TrendMicro-HouseCall | TROJ_FRS.0NA003H718 |
Tencent | Win32.Trojan.Generic.A0b7 |
Yandex | Trojan.Agent!I3pNDh9G1KU |
SentinelOne | Static AI - Suspicious PE |
MaxSecure | Trojan.Malware.2588.susgen |
Fortinet | Riskware/WinActivator |