Hello,
just one more update. The first cpl file still not being detected. However its both payloads, 2 exe files that it downloads, are detected as win32:malware-gen. Tested on my virtual machine.
Thanks for your time!