Static | ZeroBOX

PE Compile Time

2023-07-20 04:17:49

PE Imphash

108e18be559cec71db1f519ae1ab24ab

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0008ea6c 0x0008ec00 6.32309121091
.rdata 0x00090000 0x0001decc 0x0001e000 5.55566325544
.data 0x000ae000 0x000043b4 0x00001e00 3.244094088
.pdata 0x000b3000 0x00006804 0x00006a00 5.69628804065
_RDATA 0x000ba000 0x0000015c 0x00000200 3.32785969714
.rsrc 0x000bb000 0x000001e0 0x00000200 4.71767883295
.reloc 0x000bc000 0x00000b2c 0x00000c00 5.24656866657

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x000bb060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library WS2_32.dll:
0x140090538 inet_pton
0x140090540 WSAStartup
0x140090548 closesocket
0x140090550 socket
0x140090558 connect
0x140090560 recv
0x140090568 send
0x140090570 htons
0x140090578 WSACleanup
Library CRYPT32.dll:
0x140090038 CryptUnprotectData
Library WININET.dll:
0x140090500 HttpQueryInfoW
0x140090508 InternetOpenUrlA
0x140090510 InternetReadFile
0x140090518 InternetCloseHandle
0x140090520 InternetOpenW
0x140090528 InternetOpenA
Library KERNEL32.dll:
0x140090090 MultiByteToWideChar
0x140090098 LocalFree
0x1400900a0 WideCharToMultiByte
0x1400900a8 IsDebuggerPresent
0x1400900b0 WriteProcessMemory
0x1400900b8 TerminateProcess
0x1400900c0 GetModuleFileNameW
0x1400900c8 WaitForSingleObject
0x1400900d0 ResumeThread
0x1400900d8 CloseHandle
0x1400900e0 GetThreadContext
0x1400900e8 VirtualAllocEx
0x1400900f0 CreateProcessW
0x1400900f8 SetThreadContext
0x140090100 GetExitCodeProcess
0x140090108 ExitProcess
0x140090110 GetModuleFileNameA
0x140090118 GetVolumeInformationW
0x140090120 GetGeoInfoA
0x140090128 HeapFree
0x140090130 EnterCriticalSection
0x140090138 GetProductInfo
0x140090140 LeaveCriticalSection
0x140090150 HeapSize
0x140090158 GetLogicalDriveStringsW
0x140090160 GetTimeZoneInformation
0x140090168 GetLastError
0x140090170 HeapReAlloc
0x140090178 GetNativeSystemInfo
0x140090180 HeapAlloc
0x140090188 GetUserGeoID
0x140090190 DecodePointer
0x140090198 GetProcAddress
0x1400901a0 DeleteCriticalSection
0x1400901a8 GetComputerNameW
0x1400901b0 GetProcessHeap
0x1400901b8 GlobalMemoryStatusEx
0x1400901c0 GetModuleHandleW
0x1400901c8 RtlCaptureContext
0x1400901d0 RtlLookupFunctionEntry
0x1400901d8 RtlVirtualUnwind
0x1400901e0 UnhandledExceptionFilter
0x1400901f0 SetLastError
0x1400901f8 GetCurrentProcess
0x140090208 GetCurrentProcessId
0x140090210 GetSystemTimeAsFileTime
0x140090218 FreeLibrary
0x140090220 GetModuleHandleExW
0x140090228 CreateThread
0x140090230 ExitThread
0x140090238 FreeLibraryAndExitThread
0x140090240 GetSystemInfo
0x140090248 VirtualAlloc
0x140090250 VirtualProtect
0x140090258 VirtualQuery
0x140090260 FlsAlloc
0x140090268 FlsGetValue
0x140090270 FlsSetValue
0x140090278 FlsFree
0x140090288 LoadLibraryExW
0x140090290 GetDateFormatW
0x140090298 GetTimeFormatW
0x1400902a0 CompareStringW
0x1400902a8 LCMapStringW
0x1400902b0 GetLocaleInfoW
0x1400902b8 IsValidLocale
0x1400902c0 GetUserDefaultLCID
0x1400902c8 EnumSystemLocalesW
0x1400902d0 GetStdHandle
0x1400902d8 GetFileType
0x1400902e0 GetStartupInfoW
0x1400902e8 RaiseException
0x1400902f0 GetFileSizeEx
0x1400902f8 SetFilePointerEx
0x140090300 FlushFileBuffers
0x140090308 WriteFile
0x140090310 GetConsoleOutputCP
0x140090318 GetConsoleMode
0x140090320 ReadFile
0x140090328 ReadConsoleW
0x140090330 IsValidCodePage
0x140090338 GetACP
0x140090340 GetOEMCP
0x140090348 GetCPInfo
0x140090350 GetStringTypeW
0x140090358 SetStdHandle
0x140090360 CreateFileW
0x140090368 WriteConsoleW
0x140090370 OutputDebugStringW
0x140090378 GetEnvironmentStringsW
0x140090380 FreeEnvironmentStringsW
0x140090388 SetEnvironmentVariableW
0x140090390 SetEvent
0x140090398 ResetEvent
0x1400903a0 SetEndOfFile
0x1400903a8 CreateEventW
0x1400903b0 QueryPerformanceCounter
0x1400903b8 InitializeSListHead
0x1400903c0 RtlUnwindEx
0x1400903c8 RtlUnwind
0x1400903d0 RtlPcToFileHeader
0x1400903d8 EncodePointer
0x1400903e0 TlsAlloc
0x1400903e8 TlsGetValue
0x1400903f0 TlsSetValue
0x1400903f8 TlsFree
0x140090400 GetCommandLineA
0x140090408 GetCommandLineW
0x140090410 GetCurrentThreadId
0x140090418 WaitForSingleObjectEx
0x140090420 LCMapStringEx
0x140090428 GetExitCodeThread
0x140090438 AreFileApisANSI
0x140090440 FormatMessageA
0x140090448 GetLocaleInfoEx
0x140090450 GetCurrentDirectoryW
0x140090458 FindClose
0x140090460 FindFirstFileW
0x140090468 FindFirstFileExW
0x140090470 FindNextFileW
0x140090478 GetFileAttributesExW
Library USER32.dll:
0x1400904c0 EnumDisplayDevicesW
0x1400904c8 GetDesktopWindow
0x1400904d0 GetDC
0x1400904d8 ReleaseDC
0x1400904e0 GetWindowRect
0x1400904e8 GetSystemMetrics
Library GDI32.dll:
0x140090048 SelectObject
0x140090050 CreateCompatibleBitmap
0x140090058 BitBlt
0x140090060 CreateCompatibleDC
0x140090068 GetDeviceCaps
0x140090070 DeleteDC
0x140090078 GetObjectW
0x140090080 DeleteObject
Library ADVAPI32.dll:
0x140090000 RegCloseKey
0x140090008 RegQueryValueExA
0x140090010 RegOpenKeyExA
0x140090018 GetUserNameW
0x140090020 RegEnumKeyExA
0x140090028 GetCurrentHwProfileW
Library SHELL32.dll:
0x140090488 SHGetKnownFolderPath
0x140090490 ShellExecuteA
Library ole32.dll:
0x1400905d0 CreateStreamOnHGlobal
0x1400905d8 CoTaskMemFree
Library SHLWAPI.dll:
0x1400904a0 None
0x1400904a8 None
0x1400904b0 None
Library gdiplus.dll:
0x140090588 GdiplusStartup
0x140090590 GdiplusShutdown
0x1400905a0 GdipSaveImageToStream
0x1400905a8 GdipGetImageEncodersSize
0x1400905b0 GdipDisposeImage
0x1400905c0 GdipGetImageEncoders

!This program cannot be run in DOS mode.
Rich{Q
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
UATAUAVAW
A_A^A]A\]
UATAUAVAW
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
UATAUAVAW
A_A^A]A\]
UATAUAVAW
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
UAVAWH
UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
\$ UVWH
t$ UWATAVAWH
A_A^A\_]
fB94Bu
UWATAVAWH
A_A^A\_]
UWATAVAWH
A_A^A\_]
UWATAVAWH
A_A^A\_]
@SUWAVH
(A^_][
(A^_][
UVWATAUAVAWH
A_A^A]A\_^]
UAVAWH
UAVAWH
UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
ufD;l$$rNH
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
l$ VWAVH
l$ VWAVH
\$0@8k
3333333
|$ UATAUAVAWH
A_A^A]A\]
UVWATAUAVAWH
3333333
A_A^A]A\_^]
l$ VAVAWH
A_A^^
l$ VWAVH
\$ UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
\$ UVWH
@VWAVAWH
8A_A^_^
SVAUAWH
HA_A]^[
@SUVAWH
(A_^][
(A_^][
@SVAVH
@SVAVAWH
8A_A^^[
@WATAVAWH
8A_A^A\_
@SVAVAWH
(A_A^^[
@SVATAUAWH
0A_A]A\^[
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWAVH
A^_^][
A^_^][
A^_^][
@SVWATAUAVAWH
PA_A^A]A\_^[
SVWATAUAVAWH
0A_A^A]A\_^[
@SWAVAWH
8A_A^_[
WAVAWH
A_A^_
@SVATH
\$ VWAWH
@UWATAVAWH
0A_A^A\_]
t$ WATAUAVAWH
A_A^A]A\_
t$ WATAUAVAWH
UPH;UXt
|$|.u/
|$|.u2
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
t$xH;5"
\$ UVWATAUAVAWH
A_A^A]A\_^]
UVWAVAWH
A_A^_^]
UAVAWH
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
t$ UWAVH
UAVAWH
l$ VWAVH
@SUWAVAWH
A_A^_][
A_A^_][
@SUVAWH
8A_^][
fB9,Bu
\$ UVWH
@SUVWAVH
A^_^][
A^_^][
l$ VWATH
t$ WATAUAVAWH
A_A^A]A\_
@SVWATAUAVAWH
A_A^A]A\_^[
@SVATAUAVH
0A^A]A\^[
@SVWAVAW
A_A^_^[
D$`L;D$huDM
@SUWATAVAWH
L+l$ J
HA_A^A\_][
UVWAVAWH
PA_A^_^]
L$ SUVWH
UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
SVWAVAWH
A_A^_^[
SVWAVAWH
A_A^_^[
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
)D$0M+
A_A^A]A\_^]
@SUVATH
8A\^][
@USVWAVH
A^_^[]
\$ UVWH
VWATAVAWH
A_A^A\_^
t$ AVH
t$ AVH
|$ AVH
L$ SUVWH
WATAUAVAWL
D$8A)U
t$HA_A^A]A\_
UVWATAUAVAWH
`A_A^A]A\_^]
@UVWAVAWH
ePA_A^_^]
D8~)tpH
UVWAVAWH
A_A^_^]
UWATAVAWH
A_A^A\_]
CM'H;{
t$ WATAUAVAWH
A_A^A]A\_
CT$xE3
UVWATAUAVAWH
A_A^A]A\_^]
|$ UATAUAVAWH
A_A^A]A\]
|$ UATAUAVAWH
A_A^A]A\]
!!!!!!!!!
!!!!!!!
!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!
!!!!!!!!!!!!!!
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|$ UATAUAVAWH
A_A^A]A\]
@SUVWH
UVWATAUAVAWH
A_A^A]A\_^]
UWATAVAWH
A_A^A\_]
|$ UATAUAVAWH
A_A^A]A\]
UATAUAVAWH
A_A^A]A\]
@SUVWAVH
L90u"H
0A^_^][
l$ VWAVH
@SVAVH
|$ tiI
t$ UWATAVAWH
A_A^A\_]
SVWAVAWH
A_A^_^[
WAVAWH
SVWAVAWH
A_A^_^[
WATAUAVAWH
DZ\bH
DZ\tH
DZ\nH
DZ\fH
DZ\rH
DZ\"H
DZ\\H
A_A^A]A\_
@USVWAVH
GPD90~
CPD90~
A^_^[]
t$ UWAVH
UVWATAUAVAWH
A_A^A]A\_^]
UVWAVAWH
A_A^_^]
@USVWATAVAWH
pA_A^A\_^[]
D$ trueH
D$ fals
:D< uXH
D$ null
:D< u+H
D$ H;Q
UWATAVAWH
A_A^A\_]
 !!"!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!#!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$%&&&&&&&&&&&&'&&()))*f
A8H98t!H
D$pH;SHt
\$ UVWAVAWH
0A_A^_^]
SUVWAVH
A^_^][
@UWATAWH
8A_A\_]
@SVAVH
WAVAWH
0A_A^_
UVWAVAWH
A_A^_^]
@USVWAVH
A^_^[]
UVWAVAWH
A_A^_^]
|$ UAVAWH
l$ VWAVH
3333333
T$(yH
\$ UVWATAUAVAWH
0A_A^A]A\_^]
@SUVATAVH
A^A\^][
@UWAVH
|$ AVH
t$ UWAVH
\$ UVWAVAWH
A_A^_^]
@USVWAVH
PA^_^[]
t$ UWAVH
t$ UWAVH
t$ UWAVH
t$ UWAVH
t$ UWAVH
\$ UVWH
@UWAUAWH
8A_A]_]
I92u7A
t$ WATAUAVAWH
A_A^A]A\_
@SVWATAUAVAWH
PA_A^A]A\_^[
UVWATAUAVAWH
@A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
l$ VWATAVAWH
A_A^A\_^
D$0@8{
p*W4H
p*W4H
u3HcH<H
@USVWATAVAWH
A_A^A\_^[]
x AUAVAWH
0A_A^A]
D$@H;F
kL@8o(u
kL@8o(u
<htl<jt\<lt4<tt$<wt
|$ UATAUAVAWH
<Ct-<D
<St[@:
u<g~l<it[<ntP<ot,<pt
<utK@:
A_A^A]A\]
@USVWATAVAWH
A_A^A\_^[]
@UAVAWH
epA_A^]
UVWATAUAVAWH
rsf;\$d
r_f;\$l
rKf;\$t
r7f;\$|
f;\$4r
f;\$<r
f;\$Dr
f;\$Lr
rvf;\$d
rbf;\$l
rNf;\$t
r:f;\$|
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
w`HcE H
Hc;9E0t
HcE H+
L$ VWAVH
SUVWATAVAWH
0A_A^A\_^][
UVWATAUAVAWH
0A_A^A]A\_^]
t$ WATAUAVAWH
t$HA_A^A]A\_
UVWATAUAVAWH
L$<;L$P
L$4+L$8
l$0D+ D9
L$4+L$H
A_A^A]A\_^]
SUVWATAVAWH
A_A^A\_^][
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
f9)u4H9j
u%@8j(t
x UATAUAVAWH
A_A^A]A\]
t$ WATAUAVAWH
0A_A^A]A\_
D$(H!L$ E3
;D$hsC
L$ UVWATAUAVAWH
0A_A^A]A\_^]
T$ D)s
WAVAWH
fE98t'
0A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
9Cu,fD9y
fB9<{u
fD9,pu
t$`fD9+t$I
L$ SUVWH
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
fD9,Au
A_A^A]A\_^]
\$ UVWATAUAVAWH
f9t$bu
A_A^A]A\_^]
H9L$Ht?H
UVWATAUAVAWH
fE9,Fu
A_A^A]A\_^]
|$ AVH
WATAUAVAWH
A_A^A]A\_
p0R^G'
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
p0R^G'
t$ WAVAWH
A_A^_
WAVAWH
A_A^_
u9!\$0
WATAUAVAWH
gfffffffH
A_A^A]A\_
{ AUAVAWH
0A_A^A]
t$xt*3
WAVAWH
A_A^_
x ATAVAWH
A_A^A\
L$ VWAVH
fD94H}aD
fD9t$b
u1!D$0H
UVWATAUAVAWH
PA_A^A]A\_^]
D$0H9D$8
@UATAUAVAWH
H!T$0D
u,!T$(H!T$
A_A^A]A\]
D$@H=@W
p WATAUAVAWH
A_A^A]A\_
T$xD;D$x
@USVWATAVAWH
fD9$Ou
0A_A^A\_^[]
fD9$wu
}HfD9#A
\$ UVWH
UVWATAUAVAWH
fB9<A}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
AUAVAWH
@A_A^A]
@USVWATAUAVAWH
H!D$ I
hA_A^A]A\_^[]
|$ UATAUAVAWH
I9tD
9^ t"H
A_A^A]A\]
x AVAW
|$0A_A^
@UVWATAUAVAWH
e0A_A^A]A\_^]
UWATAVAWH
A_A^A\_]
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAW
A_A^A]A\_^]
@SUVWATAUAVH
s5fE9!
fE9!fA
D$pfA;
NfD9d$pu
fD9d$pt+fD
0A^A]A\_^][
UVWATAUAVAWH
0A_A^A]A\_^]
AUAVAWH
A_A^A]
SUWATAUAVAWH
`A_A^A]A\_][
AUAVAWH
@A_A^A]
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
s WATAUAVAWH
D$h9t$P
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
@UATAUAVAWH
e0A_A^A]A\]
fB9<Hu
fB9<@u
fB9<Bu
fB9,Nu
fB9,Nu
fB9,Nu
fA9,Au
f9)u:H
fB94Ou
x ATAVAWH
A_A^A\
x ATAVAWH
fG9$Ou
0A_A^A\
fB9<Hu
fB9<@u
fB9<Bu
fD94Au
fD94iu
tSf91tNH
tU;\$0tH
WAVAWH
A_A^_
@USVWATAVAWH
tyfD9 tsH
tQfD9 tK
fD9$Hu
@A_A^A\_^[]
WAVAWH
A_A^_
x ATAVAWH
0A_A^A\
@USVWATAVAWH
A_A^A\_^[]
WATAUAVAWH
0A_A^A]A\_
ATAVAWH
0A_A^A\
WAVAWH
@A_A^_
@UATAUAVAWH
e0A_A^A]A\]
@SUVWATAVAWH
A_A^A\_^][
WAVAWH
D8|$`t
A_A^_
x ATAVAWH
@A_A^A\
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
WAVAWH
fA9,@u
fA9,vu
0A_A^_
T$`fA;
ATAVAWH
A_A^A\
USVWAVH
A^_^[]
USVWAVH
A^_^[]
WATAUAVAWH
fB94ht
xXI96tSI
fC94wu
0A_A^A]A\_
WATAVH
0A^A\_
E80t"A
fD94Q}
SVWAVH
8A^_^[
WAVAWH
u/HcH<H
D8L$0u`
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
WATAUAVAWH
A_A^A]A\_
fffffff
ffffff
vKfffff
ffffff
fffffff
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$ltY
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(
SVWATAUAVAWH
0A_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
D$ I;R
D$ I9P
WATAUAVAWH
A_A^A]A\_
D#L$`3
WAVAWH
t$ UWAVH
l$ VWAVH
@UAVAWH
UVWAVAWH
0A_A^_^]
t$ UWAUAVAWH
A_A^A]_]
|$ AVH
fffffff
fffffff
fffffff
fffffff
ffffff
fffffff
fffffff
fffffff
fffffff
ffffff
ffffff
ffffff
UVWATAUAVAWH
H;\$8u
H;\$8u
fE9$Iu
A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
WATAVH
0A^A\_
@USVWATAUAVAWH
xA_A^A]A\_^[]
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
UVWATAUAVAWH
@A_A^A]A\_^]
s WAVAWH
0A_A^_
u~9t$Xt
UATAUAVAWH
A_A^A]A\]
x ATAVAWH
@8~8t
@8~0tM
A_A^A\
LcA<E3
CorExitProcess
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetSystemTimePreciseAsFileTime
GetTimeFormatEx
GetUserDefaultLocaleName
InitializeCriticalSectionEx
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
RoInitialize
RoUninitialize
AppPolicyGetProcessTerminationMethod
AppPolicyGetThreadInitializationType
SetThreadStackGuarantee
SystemFunction036
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
SleepConditionVariableCS
WakeAllConditionVariable
bad allocation
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
GetTempPath2W
bad function call
success
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
unknown error
invalid random_device value
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
GetCurrentPackageId
UUUUUU
UUUUUU
"e?<<<<<<l?
Il?333333c?
.i?0@I
d?000000`?
)|B?d!
L?UUUUUUU?
&?PPPPPPP?
0X8b?~
%GoU?*
(T?j?Y
Zod(^?
D W?{W
qS>g?h3
c?FA@s}
UUUUUU
UUUUUU
UUUUUU
?UUUUUU
?kxG2)
?TY,>5
?!5WOo
?E=$% B
?49HoKC
A03>A|
Q5rHg,>
Hk=>:
j>>A?1
.>PJ;I:qE>
:>t6k'
])6M>&
CWD>~3
_oD>Kg
N>O=I9
F>qUxv
/2GG>!B
zY;>u:m
P>q_Y~
0><[cZUg^>
Y>kX>M
H[><y5
[*ncd>0
S>$hkDh$h>[2
UA>N0Wl
9>powf
?8bunz8
?@En[vP
Unknown exception
bad array new length
string too long
generic
system
Bad optional access
directory_iterator::directory_iterator
directory_iterator::operator++
exists
status
map/set too long
[json.exception.
filename
content
config
cannot use push_back() with
cannot use operator[] with a string argument with
961c151d2e87f2686a955a9be24d316f1362bf21 3.11.2
object
string
boolean
binary
discarded
number
cannot create object from initializer list
vector too long
cannot use operator[] with a numeric argument with
invalid string position
type_error
other_error
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
unknown error
?456789:;<=
 !"#$%&'()*+,-./0123
recursive_directory_iterator::recursive_directory_iterator
recursive_directory_iterator::operator++
iostream stream error
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
Error:
MeduZZZa
Function 1
<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<<
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
Condition:
Condition is 0
Condition is 1
Loop count:
Iteration:
Condition is 2
Nested iteration:
Nested Condition:
Nested condition is 0
Nested condition is not 0
Additional Loop count within Nested Condition:
Additional iteration within Nested Condition:
Condition is 3
Array element at index
Additional Condition within Condition 3:
Additional Condition is 0
Additional Condition is not 0
Nested Loop count within Additional Condition:
Nested iteration within Additional Condition:
Condition is 4
Factorial of
Condition is 5
Hello, World!
Message length:
Additional Condition within Condition 5:
Nested Condition within Additional Condition:
Extra loop count:
Extra iteration:
Extra Condition:
Extra Condition is 0
Extra Condition is not 0
Nested Condition within Extra Condition:
Function 2
Additional Condition within Nested Condition:
Additional Condition within Array Loop:
Additional Condition within Factorial Loop:
Function 3
Nested Condition
Extra Condition:
file_size
current_path()
, column
at line
RtlGetVersion
%d-%m-%Y, %H:%M:%S
cores
Unknown
user_name
computer_name
Meduza
timezone
cannot use at() with
' not found
"bytes": [
"subtype":
],"subtype":
{"bytes":[
<discarded>
\u%04x
incomplete UTF-8 string; last byte: 0x
invalid UTF-8 byte at index
0123456789ABCDEF
out_of_range
parse_error
parse error
syntax error
while parsing
unexpected
; last read: '
<U+%.4X>
; expected
invalid literal
invalid BOM; must be 0xEF 0xBB 0xBF if given
true literal
<uninitialized>
null literal
false literal
number literal
string literal
end of input
<parse error>
unknown token
'[', '{', or a literal
invalid number; expected digit after '.'
invalid number; expected digit after '-'
invalid number; expected digit after exponent sign
invalid number; expected '+', '-', or digit after exponent
invalid comment; expecting '/' or '*' after '/'
invalid comment; missing closing '*/'
invalid string: '\u' must be followed by 4 hex digits
invalid string: missing closing quote
invalid string: surrogate U+DC00..U+DFFF must follow U+D800..U+DBFF
invalid string: surrogate U+D800..U+DBFF must be followed by U+DC00..U+DFFF
invalid string: control character U+0000 (NUL) must be escaped to \u0000
invalid string: forbidden character after backslash
invalid string: control character U+0002 (STX) must be escaped to \u0002
invalid string: control character U+0001 (SOH) must be escaped to \u0001
invalid string: control character U+0004 (EOT) must be escaped to \u0004
invalid string: control character U+0003 (ETX) must be escaped to \u0003
invalid string: control character U+0006 (ACK) must be escaped to \u0006
invalid string: control character U+0005 (ENQ) must be escaped to \u0005
invalid string: control character U+0008 (BS) must be escaped to \u0008 or \b
invalid string: control character U+0007 (BEL) must be escaped to \u0007
invalid string: control character U+000A (LF) must be escaped to \u000A or \n
invalid string: control character U+0009 (HT) must be escaped to \u0009 or \t
invalid string: control character U+000C (FF) must be escaped to \u000C or \f
invalid string: control character U+000B (VT) must be escaped to \u000B
invalid string: control character U+000E (SO) must be escaped to \u000E
invalid string: control character U+000D (CR) must be escaped to \u000D or \r
invalid string: control character U+0010 (DLE) must be escaped to \u0010
invalid string: control character U+000F (SI) must be escaped to \u000F
invalid string: control character U+0012 (DC2) must be escaped to \u0012
invalid string: control character U+0011 (DC1) must be escaped to \u0011
invalid string: control character U+0014 (DC4) must be escaped to \u0014
invalid string: control character U+0013 (DC3) must be escaped to \u0013
invalid string: control character U+0016 (SYN) must be escaped to \u0016
invalid string: control character U+0015 (NAK) must be escaped to \u0015
invalid string: control character U+0018 (CAN) must be escaped to \u0018
invalid string: control character U+0017 (ETB) must be escaped to \u0017
invalid string: control character U+001A (SUB) must be escaped to \u001A
invalid string: control character U+0019 (EM) must be escaped to \u0019
invalid string: control character U+001C (FS) must be escaped to \u001C
invalid string: control character U+001B (ESC) must be escaped to \u001B
invalid string: control character U+001E (RS) must be escaped to \u001E
invalid string: control character U+001D (GS) must be escaped to \u001D
invalid string: ill-formed UTF-8 byte
invalid string: control character U+001F (US) must be escaped to \u001F
vector<bool> too long
object key
number overflow parsing '
object separator
cannot get value
iterator out of range
iterator does not fit current value
invalid_iterator
cannot use erase() with
type must be string, but is
00010203040506070809101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
&^(L*,(T,j(L.,(T,((
6 ,"l$
8":6<<>
8dD28TF(8
N@P R T V,X
H8*H2((
4( 2<88,
<dF2<HH(<L
<*J2.(
.,0,60<
,d62,H8
4^6d826T:b6d826H:(6
^T`db2`Hdj`db2`Td(`
6*<2`FfP
, 8,$6*,,&4$
B,J8V$`*V,P4N
4 6,8i
: <,>.<v
(@ B,Di
inet_pton
WS2_32.dll
CryptUnprotectData
CRYPT32.dll
InternetOpenUrlA
InternetOpenW
InternetCloseHandle
InternetReadFile
InternetQueryDataAvailable
HttpQueryInfoW
InternetOpenA
WININET.dll
MultiByteToWideChar
LocalFree
WideCharToMultiByte
IsDebuggerPresent
WriteProcessMemory
TerminateProcess
GetModuleFileNameW
WaitForSingleObject
ResumeThread
CloseHandle
GetThreadContext
VirtualAllocEx
CreateProcessW
SetThreadContext
GetExitCodeProcess
ExitProcess
GetModuleFileNameA
GetVolumeInformationW
GetGeoInfoA
HeapFree
EnterCriticalSection
GetProductInfo
LeaveCriticalSection
InitializeCriticalSectionEx
HeapSize
GetLogicalDriveStringsW
GetTimeZoneInformation
GetLastError
HeapReAlloc
GetNativeSystemInfo
HeapAlloc
GetUserGeoID
DecodePointer
GetProcAddress
DeleteCriticalSection
GetComputerNameW
GetProcessHeap
GlobalMemoryStatusEx
GetModuleHandleW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
SetLastError
GetCurrentProcess
IsProcessorFeaturePresent
GetCurrentProcessId
GetSystemTimeAsFileTime
FreeLibrary
GetModuleHandleExW
CreateThread
ExitThread
FreeLibraryAndExitThread
GetSystemInfo
VirtualAlloc
VirtualProtect
VirtualQuery
GetCurrentThreadId
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
InitializeCriticalSectionAndSpinCount
LoadLibraryExW
GetDateFormatW
GetTimeFormatW
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
GetStdHandle
GetFileType
GetStartupInfoW
RaiseException
GetFileSizeEx
SetFilePointerEx
FlushFileBuffers
WriteFile
GetConsoleOutputCP
GetConsoleMode
ReadFile
ReadConsoleW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetStringTypeW
SetStdHandle
CreateFileW
WriteConsoleW
OutputDebugStringW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
QueryPerformanceCounter
InitializeSListHead
RtlUnwindEx
RtlUnwind
RtlPcToFileHeader
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
KERNEL32.dll
ReleaseDC
GetDesktopWindow
EnumDisplayDevicesW
GetSystemMetrics
GetWindowRect
USER32.dll
DeleteObject
GetObjectW
DeleteDC
GetDeviceCaps
CreateCompatibleDC
SelectObject
CreateCompatibleBitmap
BitBlt
GDI32.dll
RegEnumKeyExA
GetUserNameW
RegOpenKeyExA
RegQueryValueExA
RegCloseKey
GetCurrentHwProfileW
ADVAPI32.dll
ShellExecuteA
SHGetKnownFolderPath
SHELL32.dll
CoTaskMemFree
CreateStreamOnHGlobal
ole32.dll
SHLWAPI.dll
GdipCreateBitmapFromScan0
GdipSaveImageToStream
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdiplusShutdown
GdiplusStartup
gdiplus.dll
FormatMessageA
GetLocaleInfoEx
GetCurrentDirectoryW
FindClose
FindFirstFileW
FindFirstFileExW
FindNextFileW
GetFileAttributesExW
AreFileApisANSI
GetFileInformationByHandleEx
GetExitCodeThread
LCMapStringEx
GetCommandLineA
GetCommandLineW
SetEndOfFile
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_function_call@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVother_error@detail@json_abi_v3_11_2@nlohmann@@
.?AVbad_optional_access@std@@
.?AVfilesystem_error@filesystem@std@@
.?AV_System_error@std@@
.?AVtype_error@detail@json_abi_v3_11_2@nlohmann@@
.?AVexception@std@@
.?AVexception@detail@json_abi_v3_11_2@nlohmann@@
.?AVbad_array_new_length@std@@
.?AVfailure@ios_base@std@@
.?AVbad_cast@std@@
.P6AXXZ
.?AVinvalid_iterator@detail@json_abi_v3_11_2@nlohmann@@
.?AVparse_error@detail@json_abi_v3_11_2@nlohmann@@
.?AVout_of_range@detail@json_abi_v3_11_2@nlohmann@@
.?AVtype_info@@
.?AV_Locimp@locale@std@@
.?AVerror_category@std@@
.?AV_System_error_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Ref_count_base@std@@
.?AV?$_Ref_count_obj2@U_Dir_enum_impl@filesystem@std@@@std@@
.?AV?$_Ref_count_obj2@U_Recursive_dir_enum_impl@filesystem@std@@@std@@
.?AV?$ctype@D@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV_Iostream_error_category2@std@@
.?AUctype_base@std@@
.?AVfacet@locale@std@@
.?AV?$_Func_impl_no_alloc@P6AXXZX$$V@std@@
.?AV?$_Func_base@X$$V@std@@
.?AV?$numpunct@D@std@@
.?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@
.?AV?$basic_stringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@
.?AVios_base@std@@
.?AV?$basic_iostream@DU?$char_traits@D@std@@@std@@
.?AV?$_Iosb@H@std@@
.?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@
.?AV?$basic_istream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ios@DU?$char_traits@D@std@@@std@@
.?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@
.?AV?$basic_filebuf@DU?$char_traits@D@std@@@std@@
.?AVCImage@ATL@@
.?AV?$codecvt@DDU_Mbstatet@@@std@@
.?AV?$output_string_adapter@DV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@detail@json_abi_v3_11_2@nlohmann@@
.?AV?$basic_ifstream@DU?$char_traits@D@std@@@std@@
.?AVcodecvt_base@std@@
.?AV?$_Ref_count_obj2@V?$output_string_adapter@DV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@detail@json_abi_v3_11_2@nlohmann@@@std@@
.?AU?$output_adapter_protocol@D@detail@json_abi_v3_11_2@nlohmann@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
mscoree.dll
(null)
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
((((( H
((((( H
(
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
api-ms-win-core-synch-l1-2-0.dll
kernel32.dll
api-ms-win-core-fibers-l1-1-1
!x-sys-default-locale
ERROR : Unable to initialize critical section in CAtlBaseModule
UTF-16LEUNICODE
File Downloader
ntdll.dll
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Meduza.4!c
Elastic malicious (high confidence)
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
McAfee RDN/Generic PWS.y
Malwarebytes Generic.Malware/Suspicious
Zillya Clean
Sangfor Spyware.Win32.Meduza.Vbga
K7AntiVirus Clean
BitDefender Generic.Trojan.Meduza.Marte.B.8ACF6519
K7GW Clean
Cybereason malicious.2d9374
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win64/Spy.Agent.FW
APEX Malicious
Paloalto Clean
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Meduza.gen
Alibaba TrojanPSW:Win32/Meduza.203d963f
NANO-Antivirus Clean
SUPERAntiSpyware Clean
MicroWorld-eScan Generic.Trojan.Meduza.Marte.B.8ACF6519
Rising Clean
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Clean
VIPRE Generic.Trojan.Meduza.Marte.B.8ACF6519
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.Dropper.bh
Trapmine suspicious.low.ml.score
FireEye Generic.mg.40fbeddad5a68665
Emsisoft Generic.Trojan.Meduza.Marte.B.8ACF6519 (B)
Ikarus Clean
GData Generic.Trojan.Meduza.Marte.B.8ACF6519
Jiangmin Clean
Webroot Clean
Avira TR/Spy.Agent.xjhwr
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Arcabit Generic.Trojan.Meduza.Marte.B.8ACF6519
ViRobot Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Meduza.gen
Microsoft Trojan:Win32/Sabsik.FL.B!ml
Google Clean
AhnLab-V3 Trojan/Win.SpywareX-gen.R589196
Acronis Clean
BitDefenderTheta Clean
ALYac Generic.Trojan.Meduza.Marte.B.8ACF6519
MAX malware (ai score=88)
DeepInstinct MALICIOUS
VBA32 Clean
Cylance unsafe
Panda Trj/Chgt.AD
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002H0DGJ23
Tencent Win32.Trojan-QQPass.QQRob.Rsmw
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Win64:SpywareX-gen [Trj]
Avast Win64:SpywareX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
No IRMA results available.