Static | ZeroBOX

PE Compile Time

2025-03-08 00:39:09

PE Imphash

fdb088ba51afbf555d7a0f495212d8f1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00014386 0x00014400 6.54908682736
.rdata 0x00016000 0x0000752a 0x00007600 5.16326594938
.data 0x0001e000 0x00002004 0x00001400 1.54554532668
.rsrc 0x00021000 0x000000f8 0x00000200 2.52739185048
.reloc 0x00022000 0x00001b10 0x00001c00 6.51556215654

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00021060 0x00000091 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x10016000 GlobalAlloc
0x10016004 GlobalLock
0x10016008 GlobalUnlock
0x1001600c WideCharToMultiByte
0x10016010 Sleep
0x10016014 WriteConsoleW
0x10016018 CloseHandle
0x1001601c CreateFileW
0x10016020 SetFilePointerEx
0x10016024 GetConsoleMode
0x10016028 GetConsoleOutputCP
0x1001602c WriteFile
0x10016030 FlushFileBuffers
0x10016034 SetStdHandle
0x10016038 HeapReAlloc
0x1001603c HeapSize
0x10016048 GetCurrentProcess
0x1001604c TerminateProcess
0x10016054 IsDebuggerPresent
0x10016058 GetStartupInfoW
0x1001605c GetModuleHandleW
0x10016064 GetCurrentProcessId
0x10016068 GetCurrentThreadId
0x10016070 InitializeSListHead
0x10016074 RtlUnwind
0x10016078 RaiseException
0x1001607c InterlockedFlushSList
0x10016080 GetLastError
0x10016084 SetLastError
0x10016088 EncodePointer
0x1001608c EnterCriticalSection
0x10016090 LeaveCriticalSection
0x10016094 DeleteCriticalSection
0x1001609c TlsAlloc
0x100160a0 TlsGetValue
0x100160a4 TlsSetValue
0x100160a8 TlsFree
0x100160ac FreeLibrary
0x100160b0 GetProcAddress
0x100160b4 LoadLibraryExW
0x100160b8 ExitProcess
0x100160bc GetModuleHandleExW
0x100160c0 GetModuleFileNameW
0x100160c4 HeapAlloc
0x100160c8 HeapFree
0x100160cc FindClose
0x100160d0 FindFirstFileExW
0x100160d4 FindNextFileW
0x100160d8 IsValidCodePage
0x100160dc GetACP
0x100160e0 GetOEMCP
0x100160e4 GetCPInfo
0x100160e8 GetCommandLineA
0x100160ec GetCommandLineW
0x100160f0 MultiByteToWideChar
0x100160f4 GetEnvironmentStringsW
0x100160fc LCMapStringW
0x10016100 GetProcessHeap
0x10016104 GetStdHandle
0x10016108 GetFileType
0x1001610c GetStringTypeW
0x10016110 DecodePointer
Library USER32.dll:
0x10016118 EmptyClipboard
0x1001611c SetClipboardData
0x10016120 CloseClipboard
0x10016124 GetClipboardData
0x10016128 OpenClipboard
Library WININET.dll:
0x10016130 InternetOpenW
0x10016134 InternetConnectA
0x10016138 HttpOpenRequestA
0x1001613c HttpSendRequestA
0x10016140 InternetReadFile
0x10016144 InternetCloseHandle

Exports

Ordinal Address Name
1 0x10001d80 ??4CClipperDLL@@QAEAAV0@$$QAV0@@Z
2 0x10001d80 ??4CClipperDLL@@QAEAAV0@ABV0@@Z
3 0x100059c0 Main
!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
CE Ph@
QQSVWd
URPQQhP
UQPXY]Y[
t#VhLo
zSSSSj
f9:t!V
PPPPPPPP
PPPPPWS
PP9E u:PPVWP
QQSVj8j@
bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
Unknown exception
bad array new length
string too long
bfbda6ae1db325c2ff4b455ce9896e6d
6c7109f0f87b7e67c332588c3c6da69d
652098
acf55d6d3c9b14c606ca54406ebd6b79
NYh4LeECDV5TDw6V
M72ZcWhv1q0aDsaggrKm8wZyeFx=
OX5CMv==
VD1obCUx
KX2vdL==
MXWvdL==
YJ2yehlw2JG5Ignp41Sw8zrSgk6k60sod6x=
YLyyZXly3B6i4Wal
YKSrdR5oP0Ka2RLb2Kuz5WTrfESxSE==
S2iyZCVDNJWW3WTShDY4RQru3VOa
Y5W7bXR53z==
Msqscv==
Y5WvZRN43qWlBu==
LX69aSA=
S1yoYYRC4Z1=
UL mYRwkK5WS5Anl48GdNW3ohFaf8qQfU1mmch9D250SOzfggrKw7XHeY0ej7KsfU2WsQXFn1JV=
01yoYYRC4Z28QAHR30q4RQru3VOx
V5 JVAdFKnW5KQnahr2A5WT21Dan7qMye8OfQYVC3pWm5z1chsGq5WZeVVeu7K4B02KfRhVl4KWqQPXq317mQyzygDK161MmbLWn
S1yoYYRC4Z1mQRjc
S1yoYYRC4Z255WHjgLO16q==
R2KwbYJ9ND==
Y5GBbR9C5T==
WLGCaXtt2Jx9CUnENJyz5Q3AiTCYGqQ70XByRb==
SL qZRNz1Z65
Y5SyZXVn25mm
Ln6nYSQ=
ULm3ZRNz1Z655WHjgLO16q==
Y5ysdBVn25mm
WLGCaXtt2Jx9CUnENLqq7APlf0isG1A3MrW7ZNAzHj==
SLGCazNz3pW55WHjgLO16Vq=
Y5SkcXhn26Kd
WLGCaXtt2Jx9CUnENLKi6WavgVNsU1coJH J
Y6SobBVr3pGlBu==
eLSkdBE=
YLWwbXpt
YMWCZSJjPJGSPK==
YLSsYYRt256 4gnchB==
b7W8XXRl4JGr
eLSkdBFg15WXOWT9iLyA
eLSkdBFg
WLWvZRdCOZ1=
WLWvZRdCOZ1mQRjc
Y5SocXt426Bm6gnn
Y50sbBVDN4x=
0L mev==
fLyCev==
Z2SybRlnNHynPWHjNKG15XDj30Sa
Y5G3bX1tOz==
WLGCaXtt2Jx9CUnENHCC7A3veUJeQ6AvcLW3LhV8PVJ9CU0=
Z7 xZhlr3z==
c1Gzcr==
R7iBbX1p
YJeybXdwPYyv2BLmg1OdORHnggyCT1MkYJSoZhF52KS5KAaef1XhKAz22O==
YJeybXdwPYyv2BLmg1OdORHnggyCT1MkYJyyYXFwyIOSPRTc
U8CochE=
YJ zZSJlyIOnQhTU32CmQy3y3VGfDJI3Z1KvZQxQ25eh3cDv32Ki
YJ zZSJlyIOnQhTU32CmQy3y3VGfDJI3Z1KvZQxQ25O 3wDKiLy1SK==
S1SqZL==
YJ2sYYJz35 e5zzw4L7mQzPB3VFeMKA3Z0yHZRZl4ZySOyzm47evByLjhEB=
YJ2sYYJz35 e5zzw4L7mQzPB3VFeMKA3Z0yPbXNl2FCL5AHR4V==
V8C4dB5t1z==
YKOzdSRy1ZuEPQL4Z8u27AZreZuT86QBJJSkdBFgHJWePRXjiKqN5W8rfgyCT1Mk
YKOzdSRy1ZuEPQL4Z8u27AZreZuT86QBJJSkdBFgJJ bPQy8Z8Ki7AO=
R7iBbX1t4Z1=
YJOrch9x10WlOzXq42BhKAz22TuCU0Uke1y3XzxzP5mmzyT9iLx=
YJOrch9x10WlOzXq42BhKAz22TuK76IkcHCWdBF4PT==
U8KlaSR52T==
YJ BYhl44Z25MRPchnuFRRLj1COjUqA4cMSfTB9r1Z59IAHR3V==
YJ BYhl44Z25MRPchnuFRRLj1CutT6AvJKO3YSRp
Wrm5YRxo1T==
YK0sdhFwPJm5MRPchnuFRRLj1COjUqA4cMSfTB9r1Z59IAHR3V==
YK0sdhFwPJm5MRPchnuFRRLj1CutT6AvJKO3YSRp
R7 wbXRz
YJOybR9o24yw4gHeg7YdORHnggyCT1MkYJSoZhF52KS5KAaef1XhKAz22O==
YJOybR9o24yw4gHeg7YdORHnggyCT1MkYJyyYXFwyIOSPRTc
R7 mQX9n
YJOyYVNzO4yu4gaUh7OzQzPB3VFeMKA3Z0yHZRZl4ZySOyzm47evByLjhEB=
YJOyYVNzO4yu4gaUh7OzQzPB3VFeMKA3Z0yPbXNl2FCL5AHR4V==
R7ioZB94
YJOrZRRz4IyN4WXpNJKi7AzeVESkT1QveKyPbXdt2lCwPRT9
YJOrZRRz4IyN4WXpNJKi7AzeXE6hT0rjV8SkdBU=
R7WxdzJC26erQRK=
YJOobiRG3p V4WXp2KOASRCiVECYTZsH010kdRx4NHynQWnlNJKi7Ay=
YJOobiRG3p V4WXp2KOASRCiVECYTZsPc7OkbxBX4JGSQK==
V5WPRPNYyJ q2Qfggq226gquMFSxU1ExZ12oXYZl2KWdCwDn32GA7W3A3D60T0s40XCJUf9RyJynQWnlhB==
crW3cXgk45y 3cDcjMuw6hKigFGtUqgv0XCxYR1pFT==
JL0ybBRp3m1=
JLuoeO1n2JW 4a==
Content-Type: application/x-www-form-urlencoded
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789
abcdefghijklmnopqrstuvwxyz0123456789
invalid string position
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$sxdata
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.edata
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.rsrc$01
.rsrc$02
CLIPPERDLL.dll
??4CClipperDLL@@QAEAAV0@$$QAV0@@Z
??4CClipperDLL@@QAEAAV0@ABV0@@Z
GlobalAlloc
GlobalLock
GlobalUnlock
WideCharToMultiByte
KERNEL32.dll
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
GetClipboardData
USER32.dll
InternetOpenW
InternetConnectA
HttpOpenRequestA
HttpSendRequestA
InternetReadFile
InternetCloseHandle
WININET.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwind
RaiseException
InterlockedFlushSList
GetLastError
SetLastError
EncodePointer
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
GetProcAddress
LoadLibraryExW
ExitProcess
GetModuleHandleExW
GetModuleFileNameW
HeapAlloc
HeapFree
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
GetEnvironmentStringsW
FreeEnvironmentStringsW
LCMapStringW
GetProcessHeap
GetStdHandle
GetFileType
GetStringTypeW
HeapSize
HeapReAlloc
SetStdHandle
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
DecodePointer
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
.?AVbad_array_new_length@std@@
.?AVtype_info@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
</assembly>
0#0(020C0H0R0c0h0r0
1#1(121C1H1R1c1h1r1
2#2(222C2H2R2c2h2r2
3#3(323C3H3R3c3h3r3
4#4(424C4H4R4c4h4r4
5#5(525C5H5R5c5h5r5
6#6(626C6H6R6c6h6r6
7#7(727C7H7R7c7h7r7
8#8(828C8H8R8c8h8r8
9#9(929C9H9R9c9h9r9
:#:(:2:C:H:R:c:h:r:
;#;(;2;C;H;R;c;h;r;
<#<(<2<C<H<R<c<h<r<
="=1=A=Q=a=q=
>->3>O>o>
0S0m0m2
2g4&555L5T5Y5
6(6W6a6k6v6
9"9V9h9
:&:,:3:
>!>*>P>g>n>w>
8$8*83898
=?=I=Q=f=
>.>K>R>X>a>z>
>9?L?h?p?z?
1Y1_1f1l1u1
2+232=2l2v2
3!3+3Z3d3n3y3
5&555?5y5
6'616<6I6
77*777
8R8\8d8y8
8*919A9^9e9k9t9
9L:_:{:
:#;J;d;w;
=,=C=U=
>0>W>q>
?0?G?Y?
:":7:>:D:V:`:
;A;J;U;\;o;};
<(<8<H<Q<u<
> >b>j>
292B2K2Y2b2
3,4;4D4Q4g4
5&5+5>5
5-6E6J6
==1=>=`=
=P>.?T?i?
020<0F0T0o0
6!9`9x9~9
>?>[>{>
(0<0M0Y0h0
1$111:1?1D1_1i1u1z1
8L8:9D9Q9
0&131B1W1a1t1{1
3#343F3U3
8-8=8B8L8Q8\8g8{8
849G9j9
<&<_<t<
<=0=5=
3D3Y3k3x3
4!4J4Q4r4
5%565k5:6j6
7/747=7
8%8+8F8M8
9A9G9Y9
31484?4F4`4o4y4
4.5V5E7h7
8X8a8e8k8o8u8y8
>#>(>->=>B>G>l>
>*?3?k?
0+050E0J0O0j0y0
101@1y1
2!2-2:2A2K2a2
2 3W3i3
3$444e4
5m5t5{5
6"7+7C7o7
8878D8
;$;2;B;W;n;
<c<@=G=
&0_0v0
3,3>3_3q3
=B>H>p>
02090U0\0s0
9-:J:i:B;
=(=-=;=
00p0z0
4'444d4
5@6F6K6R6b6p6
8L8V8q8
9!9)91999W9_9
1,1=1E1U1f1
1!202<2K2^2}2
3'3R3t3
8M9h9~9
1+1?1E1
9':1:;:R:\:
;G;Q;[;r;|;
<2<<<g<q<{<
<'=1=;=R=\=
>G>Q>[>r>|>
?2?<?g?q?{?
'010;0R0\0
1G1Q1[1r1|1
222<2g2q2{2
2'313;3R3\3
4G4Q4[4r4|4
525<5g5q5{5
5'616;6R6\6
7G7Q7[7r7|7
828<8g8q8{8
8'919;9R9\9
:G:Q:[:r:|:
;2;<;g;q;{;
;'<1<;<R<\<
=G=Q=[=r=|=
>2><>g>q>{>
>'?1?;?R?\?
0G0Q0[0r0|0
121<1g1q1{1
1'212;2R2\2
3G3Q3[3r3|3
424<4g4q4{4
4'515;5R5\5
6G6Q6[6r6|6
727<7g7q7{7
7'818;8R8\8
9G9Q9[9r9|9
:2:<:g:q:{:
:';1;;;R;\;
<G<Q<[<r<|<
=2=<=g=q={=
='>1>;>R>\>
?G?Q?[?r?|?
020<0g0q0{0
0'111;1R1\1
2G2Q2[2r2|2
323<3g3q3{3
L1T1X1\1`1d1h1l1p1t1x1|1
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2
3 3$3034383P3T3X3\3`3d3x3|3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7
=`?h?p?t?x?|?
H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
<H<L<P<T<X<\<`<d<h<l<p<t<x<|<
l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9 9(90989@9H9P9X9`9h9p9x9
=$=,=4=<=D=L=T=\=d=l=t=|=
=(=,=<=@=D=H=P=h=x=|=
>$><>@>X>\>t>
3<3D3P3p3x3
4$4,484X4`4l4
5,545<5D5L5T5\5d5l5t5|5
6$6,646@6d6l6t6|6
7$7,70747<7P7X7`7h7l7p7x7
8,808P8X8\8x8
9 9(90949<9P9p9
:0:P:p:
;0;P;p;
<0<P<p<
7 7$7(7,70747
3 3@3`3|3
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
((((( H
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Amadey.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.446682
CMC Clean
CAT-QuickHeal cld.trojanpws.kliper
ALYac Gen:Variant.Zusy.446682
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanPSW:Win32/Kliper.5a45ec80
K7GW Trojan ( 005b155f1 )
K7AntiVirus Trojan ( 005b155f1 )
huorong TrojanSpy/ClipBanker.y
Baidu Clean
VirIT Clean
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/ClipBanker.SJ
APEX Clean
Avast Win32:TrojanX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Zusy.446682
NANO-Antivirus Clean
ViRobot Clean
Tencent Win32.Trojan-QQPass.QQRob.Qqil
Sophos Mal/Amadey-E
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Zusy.446682
TrendMicro Clean
McAfeeD ti!7817B60D8A52
Trapmine Clean
CTX dll.trojan.amadey
Emsisoft Gen:Variant.Zusy.446682 (B)
Ikarus Trojan.Win32.Clipbanker
FireEye Gen:Variant.Zusy.446682
Jiangmin Clean
Webroot Clean
Avira TR/ClipBanker.mceab
Fortinet W32/ClipBanker.SJ!tr
Antiy-AVL Trojan/Win32.Amadey
Kingsoft Win32.Trojan-PSW.Kliper.gen
Gridinsoft Ransom.Win32.Banker.sa
Xcitium Clean
Arcabit Trojan.Zusy.D6D0DA
SUPERAntiSpyware Clean
Microsoft Trojan:Win32/Amadey.MA!MTB
Varist W32/ABTrojan.EWFV-8984
AhnLab-V3 Trojan/Win.Amadey.C5684740
Acronis Clean
VBA32 Clean
TACHYON Clean
Malwarebytes Trojan.ClipBanker
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Downloader.Amadey!1.1275B (CLASSIC)
Yandex Clean
SentinelOne Clean
GData Win32.Trojan-Stealer.Amadey.F
AVG Win32:TrojanX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Trojan[Spy]:Win/ClipBanker.SG
No IRMA results available.