This Widget doesn't seem safe at all ! by VirusTotal
https://www.virustotal.com/gui/file/f4db1bdfd357ec38845cfe465099650b9ac82de87eddd40b2e2feb2462653bf5
Matches rule SUSP_Imphash_Mar23_3 from ruleset gen_imphash_detection at https://github.com/Neo23x0/signature-base by Arnim Rupp (https://github.com/ruppde)
Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits - 2 months ago
Matches rule SUSP_Imphash_Mar23_3 from ruleset gen_imphash_detection at https://github.com/Neo23x0/signature-base by Arnim Rupp (https://github.com/ruppde)
Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits
Matches rule PyInstaller from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze
Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious. - 6 days ago
Matches rule PyInstaller from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze
Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Matches are settled Change PowerShell policies to an unsafe level. by frack113 at Sigma Integrated Ruleset (GitHub) Detects PowerShell script execution policy modification to a potentially unsafe level using the "-ExecutionPolicy" flag.
Matches are settled Suspicious DNS Query for IP Lookup Service APIs by Brandon George (blog post), Thomas Patzke at Sigma Integrated Rule Set (GitHub) Detects DNS queries for IP lookup services such as "api.ipify.org" coming from a process other than a browser.
Matches are settled Loading Python images by non-Python process by Patrick St. John, OTR (Open Threat Research) at Sigma Integrated Rule Set (GitHub) Detects loading of the "Python Core" image by a non-Python process. This may indicate the presence of a Python script included in Py2Exe.
Matches are settled Suspicious network connection to IP Lookup Service APIs by Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems) at Sigma Integrated Rule Set (GitHub) Detects external IP address lookups performed by non-browser processes via services such as "api.ipify.org". This could be indicative of potential Internet testing activity following a system compromise.
Matches rule ET POLICY External IP Lookup ip-api.com at Proofpoint Emerging Threats Open
Device Retrieving External IP Address Detected
Unique rule identifier:
This rule belongs to a private collection.
The sandbox Yomi Hunter flags this file as: MALWARE
Security vendors' analysis
Arctic Wolf Unsafe
McAfee Scanner Ti!F4DB1BDFD357
Palo Alto Networks Generic.ml
SecureAge Malicious
This Widget doesn't seem safe at all ! by VirusTotal
https://www.virustotal.com/gui/file/f4db1bdfd357ec38845cfe465099650b9ac82de87eddd40b2e2feb2462653bf5
Matches rule SUSP_Imphash_Mar23_3 from ruleset gen_imphash_detection at https://github.com/Neo23x0/signature-base by Arnim Rupp (https://github.com/ruppde)
Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits - 2 months ago
Matches rule SUSP_Imphash_Mar23_3 from ruleset gen_imphash_detection at https://github.com/Neo23x0/signature-base by Arnim Rupp (https://github.com/ruppde)
Detects imphash often found in malware samples (Maximum 0,25% hits with search for 'imphash:x p:0' on Virustotal) = 99,75% hits
Matches rule PyInstaller from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze
Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious. - 6 days ago
Matches rule PyInstaller from ruleset PyInstaller at https://github.com/bartblaze/Yara-rules by @bartblaze
Identifies executable converted using PyInstaller. This rule by itself does NOT necessarily mean the detected file is malicious.
Matches are settled Change PowerShell policies to an unsafe level. by frack113 at Sigma Integrated Ruleset (GitHub) Detects PowerShell script execution policy modification to a potentially unsafe level using the "-ExecutionPolicy" flag.
Matches are settled Suspicious DNS Query for IP Lookup Service APIs by Brandon George (blog post), Thomas Patzke at Sigma Integrated Rule Set (GitHub) Detects DNS queries for IP lookup services such as "api.ipify.org" coming from a process other than a browser.
Matches are settled Loading Python images by non-Python process by Patrick St. John, OTR (Open Threat Research) at Sigma Integrated Rule Set (GitHub) Detects loading of the "Python Core" image by a non-Python process. This may indicate the presence of a Python script included in Py2Exe.
Matches are settled Suspicious network connection to IP Lookup Service APIs by Janantha Marasinghe, Nasreddine Bencherchali (Nextron Systems) at Sigma Integrated Rule Set (GitHub) Detects external IP address lookups performed by non-browser processes via services such as "api.ipify.org". This could be indicative of potential Internet testing activity following a system compromise.
Matches rule ET POLICY External IP Lookup ip-api.com at Proofpoint Emerging Threats Open
Device Retrieving External IP Address Detected
Unique rule identifier:
This rule belongs to a private collection.
The sandbox Yomi Hunter flags this file as: MALWARE
Security vendors' analysis
Arctic Wolf Unsafe
McAfee Scanner Ti!F4DB1BDFD357
Palo Alto Networks Generic.ml
SecureAge Malicious