Due to the time it takes for every test, I can only perform short tests, but I try make them as meaningful as possible.
| Detection Name | Final Detection Source | File Location/Name | Date Time | Comment |
| Trojan:Script/GenericYJ.BBC | neo | ///redacted///r189722c5-ba5c-4822-ab5d-7359af018697r.js | 2025-07-15 09:42:56 | Modified script (dropper). McAfee detected pre-execution no matter what modifications I did. |
| ti!6981D8702172 | hti | ///redacted///6981d8702172dc39f302bdeb4917c0eb49f7c37b2a90bee41f64ccecc7e9497d.exe | 2025-07-15 09:45:12 | Pre-execution detection |
| ti!9B757A3DBB96 | rp-s | ///redacted///9b757a3dbb96ff7cbea3853bdea20cbf954add2f6a2f6cebb2d0d5f0c137c0d8.exe | 2025-07-15 09:53:13 | Pre-execution detection |
| ti!968396EE196B | hti | ///redacted///968396ee196be287ac6de30d897f7e84570eb5a297642a32d7300826241349bb.exe | 2025-07-15 09:58:38 | Pre-execution detection |
| ti!0CBCDA1CFD01 | rp-s | ///redacted///968396ee196be287ac6de30d897f7e84570eb5a297642a32d7300826241349bb.exe | 2025-07-15 09:59:50 | Pre-execution detectiom |
| ti!8C874AE8B5B3 | rp-s | ///redacted///x.exe | 2025-07-15 10:01:55 | Modified script. It was detected pre-execution and a message was displayed that script cannot execute due to antivirus block. |
| ti!8C874AE8B5B3 | rp-s | ///redacted///x.exe | 2025-07-15 10:03:05 | Another modification, still blocked |
| ti!8C874AE8B5B3 | rp-s | ///redacted///x.exe | 2025-07-15 10:03:49 | Third modification, still blocked |
| ti!404F55E7AA85 | hti | ///redacted///404f55e7aa854f7df700f2b93b4a31d0f13dde464e74985ca9bc98ba6224cc93.exe | 2025-07-15 10:16:26 | Pre-execution detection |
| ti!95829D5ACF78 | hti | ///redacted///tier0.dll | 2025-07-15 10:21:38 | Malicious file-pumped (inflated) dll with size over 200MB. mcAfee detected pre-executon |
| hti!968cc448 | hti | ///redacted///968396ee196be287ac6de30d897f7e84570eb5a297642a32d7300826241349bb.exe | 2025-07-15 10:22:07 | Pre-execution detection |
| VBS/Generic.c | av | ///redacted///b501e17e249221d34a618e288e0e9a75933cea9894ec11fdcd45c0663d95eeb6.vbs | 2025-07-15 10:23:08 | The scripts was modified. McAfee detected and removed the script post-execution. |
All scripts were modified via inclusion of functions, example below:
View attachment 289598
Executables were tested twice, original and hex-edited to append random bytes.