| N/A | |
| PE32 executable (GUI) Intel 80386, for MS Windows | 158720 |
| N/A | |
| 1a0e69d123d9a8a02caf7990a84b7008 | |
| cb700c0fd9891f861ee8c908795b9cd6b259c676 | |
| df257186a04c9c88b54577786b44f8e41d60baacfb10ad9883c3e3f6e075e433 | |
| N/A | |
| N/A | |
| N/A | |
| N/A | |
| PE32 | |
| application/octet-stream | |
| 10.0 | |
| N/A | |
| 74240 | |
| 6.7 | |
| Win32 EXE | |
| 155 kB | |
| Intel 386 or later, and compatibles | |
| 5.0 | |
| Windows GUI | |
| 83456 | |
| 5.0 | |
| 0x674d | |
| Source: |

| AVG | SHeur4.BWQB |
| AntiVir | TR/Emmotet.dst.1 |
| Avast | Win32:Dropper-gen [Drp] |
| ESET-NOD32 | Win32/Emotet.AA |
| Fortinet | W32/Kryptik.CDRZ!tr |
| Kaspersky | Trojan-Dropper.Win32.Dapato.ebze |
| Kingsoft | Win32.Heur.KVM007.a.(kcloud) |
| Malwarebytes | Backdoor.Bot |
| McAfee | RDN/Generic.bfr!hh |
| McAfee-GW-Edition | Artemis!1A0E69D123D9 |
| Qihoo-360 | HEUR/Malware.QVM20.Gen |
| Rising | PE:Malware.FakePDF@CV!1.9C3A |
| Sophos | Troj/Agent-AHGW |
| Symantec | Trojan Horse |
| Tencent | Win32.Trojan-dropper.Dapato.Dwtq |
| TrendMicro | TROJ_KRYPTIK.BRF |
| TrendMicro-HouseCall | TROJ_KRYPTIK.BRF |