user@threatcheck.sh ~ threat-analysis
bash
$ analyze-threat PUADlManager:Win32/OfferCore
PUADlManager:Win32/OfferCore - Windows Defender threat signature analysis

PUADlManager:Win32/OfferCore - Windows Defender Threat Analysis

$ cat analysis.txt
=== THREAT ANALYSIS REPORT ===
Threat Name: PUADlManager:Win32/OfferCore
Classification:
Type:PUADlManager
Platform:Win32
Family:OfferCore
Detection Type:Concrete
Known malware family with identified signatures
Confidence:Very High
False-Positive Risk:Low

Concrete signature match: PUADlManager for 32-bit Windows platform, family OfferCore

Summary:

PUADlManager:Win32/OfferCore is a Potentially Unwanted Application (PUA), commonly known as adware or bundleware. This program is typically an installer that uses various system utilities and persistence methods, like scheduled tasks, to download and install additional, unwanted software onto the system without clear user consent.

Severity:
Medium
VDM Static Detection:
Relevant strings associated with this threat:
 - m%1q/ (SNID)
Relevant strings associated with this threat:
 - !#HSTR:StringCodeForMshta.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.C!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.L!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.O!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRegsvr32.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRundll32.A!pli (PEHSTR_EXT)
 - rundll32 (PEHSTR_EXT)
 - !#HSTR:StringCodeForBITSJobs.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForPowerShell.G!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForScheduledTask.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForDataEncoding.D!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.J!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.K!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteFileCopy.B!pli (PEHSTR_EXT)
 - !#HSTR:ExecutionGuardrails (PEHSTR_EXT)
 - !#HSTR:StringCodeForFileDeletion.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForHooking.M!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForNetshHelperDLL.A!pli (PEHSTR_EXT)
 - !#HSTR:StringCodeForRemoteServices.A!pli (PEHSTR_EXT)
Known malware which is associated with this threat:
Filename: anyunlock_c-yP7k1.exe
7e3462dbaafd402d8883886044e6fbf533026fa38d1d181ab55743596dfb2121
14/11/2025
Remediation Steps:
Use Windows Defender to remove the detected threat. Run a full system scan to find any related components it may have installed. Review 'Apps & features' to uninstall any recently added, unrecognized applications. Check browser extensions and system startup items for suspicious entries.
=== END REPORT ===
$ reanalyze-threat
This analysis was last updated on 14/11/2025. Do you want to analyze it again?
$ ls available-commands/
user@threatcheck.sh:~$