user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat PUA:Win32/Presenoker
PUA:Win32/Presenoker - Windows Defender threat signature analysis

PUA:Win32/Presenoker - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: PUA:Win32/Presenoker
Classification:
Type:PUA
Platform:Win32
Family:Presenoker
Detection Type:Concrete
Known malware family with identified signatures
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: PUA for 32-bit Windows platform, family Presenoker

Summary:

PUA:Win32/Presenoker is a Potentially Unwanted Application, typically adware, that injects unwanted advertisements and may modify browser settings. It establishes persistence by creating scheduled tasks and uses system tools like PowerShell and BITS to download additional components or ad-related content from command-and-control servers.

Severity:
High
VDM Static Detection:
Relevant strings associated with this threat:
 - #http://adplus.chlbiz.com/adplus-api (PEHSTR)
 -  http://pdapi.znyshurufa.com/city (PEHSTR)
 - Goooooooooogle.UserControl1 (PEHSTR)
 - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT)
 - rundll32 (PEHSTR_EXT)
 - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT)
 - !#HSTR:ExecutionGuardrails (PEHSTR_EXT)
 - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
Known malware which is associated with this threat:
Filename: Xeno.dll
f00f1e8b8752812f99965d6c660b2c09b23e1dc114cf045de859dc5a7d115daa
04/08/2026
Filename: 132eb8f87d1f5e0922a3078af71e9be5ec844571fa07e1314d20daf7aaa3f575
132eb8f87d1f5e0922a3078af71e9be5ec844571fa07e1314d20daf7aaa3f575
14/07/2026
Filename: d8502c066568eafc5d0a99dc081ce8182563e2d09be7cc4058e3fb2796bbbdc7
d8502c066568eafc5d0a99dc081ce8182563e2d09be7cc4058e3fb2796bbbdc7
14/07/2026
Filename: c459fdd1f0a39b4de680a45f20a822b204ca897437b4aff99f088f0067a11327
c459fdd1f0a39b4de680a45f20a822b204ca897437b4aff99f088f0067a11327
14/07/2026
Filename: 7e937f0293fe6f962eb9c83efc03d7fb15db44c26170715168afa8f9f62dbf79
7e937f0293fe6f962eb9c83efc03d7fb15db44c26170715168afa8f9f62dbf79
14/07/2026
Remediation Steps:
Quarantine the detected file using your antivirus software. Review and remove any suspicious scheduled tasks in Task Scheduler. Check browser extensions and reset browser settings to default. Run a full system scan to find any related components.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 05/12/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$