| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 481792 |
| N/A | |
| 6abfce828a0440379d7e1a44f33ec1f9 | |
| 4f7e22b1f7348d9000dc1414f14a86cb49e66a9a | |
| cf8b6e16d1eff46657c71682ffc9a5ab6a32cb845ce8dcd259165a38c1d7d147 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 21.0 | |
| N/A | |
| 570880 | |
| 0.0 | |
| Win32 EXE | |
| 470 kB | |
| Intel 386 or later, and compatibles | |
| 5.0 | |
| Windows GUI | |
| 64512 | |
| 5.0 | |
| 0x806b | |
| Source: |

| AVG | Win32:Malware-gen |
| Ad-Aware | Trojan.GenericKD.6205905 |
| AegisLab | Troj.Bebloh.Gen!c |
| Avast | Win32:Malware-gen |
| Avira | TR/Crypt.ZPACK.symff |
| BitDefender | Trojan.GenericKD.6205905 |
| CrowdStrike | malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DrWeb | Trojan.PWS.Papras.2867 |
| ESET-NOD32 | a variant of Win32/GenKryptik.BEGC |
| Emsisoft | Trojan.GenericKD.6205905 (B) |
| Endgame | malicious (high confidence) |
| F-Secure | Trojan.GenericKD.6205905 |
| Fortinet | Malicious_Behavior.SB |
| GData | Win32.Trojan.Agent.G1D36M |
| Ikarus | Trojan-Banker.UrSnif |
| Invincea | heuristic |
| K7GW | Trojan ( 0051c3961 ) |
| Kaspersky | Trojan-Spy.Win32.Ursnif.upr |
| MAX | malware (ai score=96) |
| McAfee | Artemis!6ABFCE828A04 |
| McAfee-GW-Edition | BehavesLike.Win32.Trojan.gh |
| MicroWorld-eScan | Trojan.GenericKD.6205905 |
| Microsoft | Trojan:Win32/Krilog.A |
| Paloalto | generic.ml |
| Panda | Trj/GdSda.A |
| SentinelOne | static engine - malicious |
| Sophos | Mal/Lethic-L |
| Symantec | Trojan.Bebloh |
| Tencent | Suspicious.Heuristic.Gen.b.0 |
| TrendMicro-HouseCall | Suspicious_GEN.F47V1116 |
| ViRobot | Trojan.Win32.S.Agent.481792.E |
| ZoneAlarm | Trojan-Spy.Win32.Ursnif.upr |