user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat PUADlManager:Win32/OfferCore
PUADlManager:Win32/OfferCore - Windows Defender threat signature analysis

PUADlManager:Win32/OfferCore - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: PUADlManager:Win32/OfferCore
Classification:
Type:PUADlManager
Platform:Win32
Family:OfferCore
Detection Type:Concrete
Known malware family with identified signatures
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: PUADlManager for 32-bit Windows platform, family OfferCore

Summary:

PUADlManager:Win32/OfferCore is a Potentially Unwanted Application (PUA), commonly known as adware or bundleware. This program is typically an installer that uses various system utilities and persistence methods, like scheduled tasks, to download and install additional, unwanted software onto the system without clear user consent.

Severity:
Medium
VDM Static Detection:
Relevant strings associated with this threat:
 - m%1q/ (SNID)
Relevant strings associated with this threat:
 - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT)
 - rundll32 (PEHSTR_EXT)
 - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT)
 - !#HSTR:ExecutionGuardrails (PEHSTR_EXT)
 - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
Known malware which is associated with this threat:
dec7a31e7a02838b2097770419336f659334851822d8c369f9e917f8727f0e19
31/08/2026
99d5190f475f003698b8e5e9f22f6e2479aa400e98bb9ed9fde45faac35b1b3e
14/08/2026
d8389233fac178c9a539cc3229652c7877570a32e608327e1ccbf4c7664ed8ee
14/08/2026
Filename: hpKdXDa9E.exe
888bfc44c03e97875fd1e88f56c8c052c94af130803a096114a76e480313f0dc
18/04/2026
17d9094e06d2edcaeb07b72263ee2f12009f98e079daf3e3ca48df5fc5b04586
26/01/2026
Remediation Steps:
Use Windows Defender to remove the detected threat. Run a full system scan to find any related components it may have installed. Review 'Apps & features' to uninstall any recently added, unrecognized applications. Check browser extensions and system startup items for suspicious entries.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 14/11/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$ ▊