Static | ZeroBOX

PE Compile Time

2023-11-28 23:43:22

PE Imphash

87276645a61980fa58d8085fc4df7bae

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000643d5 0x00064400 6.70501649125
.rdata 0x00066000 0x000091c4 0x00009200 5.17984367715
.data 0x00070000 0x00005388 0x00005400 6.49057347139
.reloc 0x00076000 0x00007e54 0x00008000 6.8089954669

Imports

Library KERNEL32.dll:
0x46e198 CloseHandle
0x46e19c CompareStringW
0x46e1a0 CreateFileA
0x46e1a4 CreateFileW
0x46e1a8 CreateProcessW
0x46e1ac DecodePointer
0x46e1b4 EncodePointer
0x46e1bc ExitProcess
0x46e1c4 FindClose
0x46e1c8 FindFirstFileExW
0x46e1cc FindNextFileW
0x46e1d0 FlushFileBuffers
0x46e1d8 FreeLibrary
0x46e1dc GetACP
0x46e1e0 GetCPInfo
0x46e1e4 GetCommandLineA
0x46e1e8 GetCommandLineW
0x46e1ec GetComputerNameExA
0x46e1f0 GetComputerNameW
0x46e1f4 GetConsoleMode
0x46e1f8 GetConsoleOutputCP
0x46e1fc GetCurrentProcess
0x46e200 GetCurrentProcessId
0x46e204 GetCurrentThreadId
0x46e20c GetFileSizeEx
0x46e210 GetFileType
0x46e214 GetLastError
0x46e218 GetModuleFileNameA
0x46e21c GetModuleFileNameW
0x46e220 GetModuleHandleExW
0x46e224 GetModuleHandleW
0x46e228 GetOEMCP
0x46e22c GetProcAddress
0x46e230 GetProcessHeap
0x46e234 GetStartupInfoW
0x46e238 GetStdHandle
0x46e23c GetStringTypeW
0x46e250 HeapAlloc
0x46e254 HeapFree
0x46e258 HeapReAlloc
0x46e25c HeapSize
0x46e264 InitializeSListHead
0x46e268 IsDebuggerPresent
0x46e270 IsValidCodePage
0x46e274 LCMapStringW
0x46e27c LoadLibraryA
0x46e280 LoadLibraryExW
0x46e284 LoadLibraryW
0x46e288 MultiByteToWideChar
0x46e290 RaiseException
0x46e294 ReadFile
0x46e298 RtlUnwind
0x46e29c SetEndOfFile
0x46e2a4 SetFilePointerEx
0x46e2a8 SetLastError
0x46e2ac SetStdHandle
0x46e2b4 TerminateProcess
0x46e2b8 TlsAlloc
0x46e2bc TlsFree
0x46e2c0 TlsGetValue
0x46e2c4 TlsSetValue
0x46e2cc WideCharToMultiByte
0x46e2d0 WinExec
0x46e2d4 WriteConsoleW
0x46e2d8 WriteFile
0x46e2dc lstrcatW
0x46e2e0 lstrcmpW
0x46e2e4 lstrcmpiW
0x46e2e8 lstrlenW
Library ADVAPI32.dll:
0x46e2f0 GetUserNameW
0x46e2f4 RegCloseKey
0x46e2f8 RegEnumKeyExW
0x46e2fc RegOpenKeyExW
0x46e300 RegQueryValueExW
Library USER32.dll:
0x46e308 EnumDisplayDevicesA
0x46e30c GetDC
0x46e310 GetSystemMetrics
0x46e314 ReleaseDC
0x46e318 wsprintfW
Library GDI32.dll:
0x46e320 BitBlt
0x46e328 CreateCompatibleDC
0x46e32c CreateDCW
0x46e330 DeleteDC
0x46e334 DeleteObject
0x46e338 GetDIBits
0x46e33c GetObjectW
0x46e340 SelectObject
Library WINHTTP.dll:
0x46e34c WinHttpCloseHandle
0x46e350 WinHttpConnect
0x46e354 WinHttpCrackUrl
0x46e358 WinHttpOpen
0x46e35c WinHttpOpenRequest
0x46e364 WinHttpReadData
0x46e36c WinHttpSendRequest
Library CRYPT32.dll:

!This program cannot be run in DOS mode.$
`.rdata
@.data
.reloc
USWVP1
D$(;D$D
D$ ;D$@r
6En35T
f5,`f!
f-l~f)
f5_"f!
f5_"f!
f5_"f!
;D$<t%
D$T;D$`
;D$Tt1
;D$Pv3
;D$dt8
D$0;D$(
9D$ ta
\$ h oF
\$(h oF
f-L|f)
f%WYf!
3yf%3yf
f%(hf!
f54Vf%
;D$(sp
;D$(si
D$@;D$DuS
T$tf+T$P
T$pf+T$L
T$lf+T$H
T$hf+T$D
;D$4s)
D$H;D$$u
VC20XC00
t/h@|F
Tt)jhZf;
Jjl^f;
V2jx_f;
F2jgYf;
<ItC<Lt3<Tt#<h
A<lt'<tt
F4_^[]
j"_f9y
UQPXY]Y[
URPQQh@}E
u,PQRS
Wj0XPV
SPjdVQ
QQSVj8j@
tl=(BG
tlj*Yf
f9:t!V
Af95nRG
j-Xf9E
u kE$<
f95lRG
QQSVWd
PPPPPWS
PP9E u:PPVWP
CY<u
PPPPPPPP
436f55b82c1c0adb311625cc6d0a3bdb311625cc260b0ad32616
26e296295690f94f4f8ef3074f8cf0467981f74a4e87
stream end
need dictionary
file error
stream error
data error
out of memory
buf error
version error
parameter error
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAXBMgBT0sqX34WZO5VRA+oErW/Bh9j
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAQF8QDS1U9V2sbYvxRTQinWaTkDg==
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAaE9QCQkUgTGAcZ+9URASgBKO/Bh9j
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAQH9wCWEYiWGEBbeZdTwqpDq3mFwsjoZQ8
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAGF8kATEYsV2QafPJUUwChAOz3FQQ=
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAGE8sMXEImUGsSeOpQTQS7ErW/EB0=
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAXF9YASUgjWnsDZP5ARhOpAKe/EB0=
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAbBs0KWUI8V2sYZu5BUg68AOzhFw==
dHa9ZSonTz4IcwiLMiFhzHfCkWBqDcfhUo3vCFCEOvAEGdEMXkIpTGEUYP9XTxGjAK3wThp6
act=life
section
name="atok" value="
T1mOs2
send_message
Content-Disposition: form-data; name="
Content-Type: attachment/x-object
not initialized
invalid entry name
entry not found
invalid zip mode
invalid compression level
no zip 64 support
memset error
cannot write data to entry
cannot initialize tdefl compressor
invalid index
header not found
cannot flush tdefl buffer
cannot write entry header
cannot create entry header
cannot write to central dir
cannot open file
invalid entry type
extracting data using no memory allocation
file not found
no permission
out of memory
invalid zip archive name
make dir error
symlink error
close archive error
capacity size too small
fseek error
fread error
fwrite error
Undefined Version
Windows 2000
Windows XP 32
Windows XP Professional 64
Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2
Windows 8
Windows Server 2012
Windows 8.1
Windows Server 2012 R2
Windows 10
Windows Server 2016
LummaC2, Build Nov 28 2023, Buy now: TG @lummanowork
41f77d2b0dbe39030d82104620d7346f68cd5d
%s (%d.%d.%d)
act=recive_message&lid=%s&j=%s&ver=4.0
(null)
CorExitProcess
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
AreFileApisANSI
CompareStringEx
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#QNAN
1#SNAN
Unknown exception
bad exception
?5Wg4p
%S#[k=
"B <1=
_hypot
_nextafter
CloseHandle
CompareStringW
CreateFileA
CreateFileW
CreateProcessW
DecodePointer
DeleteCriticalSection
EncodePointer
EnterCriticalSection
ExitProcess
ExpandEnvironmentStringsW
FindClose
FindFirstFileExW
FindNextFileW
FlushFileBuffers
FreeEnvironmentStringsW
FreeLibrary
GetACP
GetCPInfo
GetCommandLineA
GetCommandLineW
GetComputerNameExA
GetComputerNameW
GetConsoleMode
GetConsoleOutputCP
GetCurrentProcess
GetCurrentProcessId
GetCurrentThreadId
GetEnvironmentStringsW
GetFileSizeEx
GetFileType
GetLastError
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleExW
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTimeZoneInformation
GetVolumeInformationW
GetWindowsDirectoryW
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
InitializeCriticalSectionAndSpinCount
InitializeSListHead
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
LCMapStringW
LeaveCriticalSection
LoadLibraryA
LoadLibraryExW
LoadLibraryW
MultiByteToWideChar
QueryPerformanceCounter
RaiseException
ReadFile
RtlUnwind
SetEndOfFile
SetEnvironmentVariableW
SetFilePointerEx
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
TerminateProcess
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
UnhandledExceptionFilter
WideCharToMultiByte
WinExec
WriteConsoleW
WriteFile
lstrcatW
lstrcmpW
lstrcmpiW
lstrlenW
GetUserNameW
RegCloseKey
RegEnumKeyExW
RegOpenKeyExW
RegQueryValueExW
EnumDisplayDevicesA
GetSystemMetrics
ReleaseDC
wsprintfW
BitBlt
CreateCompatibleBitmap
CreateCompatibleDC
CreateDCW
DeleteDC
DeleteObject
GetDIBits
GetObjectW
SelectObject
WinHttpAddRequestHeaders
WinHttpCloseHandle
WinHttpConnect
WinHttpCrackUrl
WinHttpOpen
WinHttpOpenRequest
WinHttpQueryDataAvailable
WinHttpReadData
WinHttpReceiveResponse
WinHttpSendRequest
CryptStringToBinaryA
KERNEL32.dll
ADVAPI32.dll
USER32.dll
GDI32.dll
WINHTTP.dll
CRYPT32.dll
BHLx*v
gN7ReO
^Li6ACK|$#
/C9336
D1[aak.
e!!xL+/
yVe6,
0#DK%u
meO"-K
zo]c]'H
$Bxq"r(p@-p%
n[,t$@
O@vdgZ
>3CRnS9/
nBEnQ)'
giz{G(
5c:T])
:g7@0D^@
u4,GZ:
)"X,bm
M.gD$]
O9BuC=FrX
1tue%/
&Dj[WO
E*7#z.
@th]%C
(;MHL?,
2Y(`ap
E)$3it
dG0W43
cLhl.k
kcr.V[
default
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_exception@std@@
.?AVexception@std@@
.?AVtype_info@@
_z&-Ol
8<KO_b
:+;<;\;
<5<B<O<g<d=
071D1Q1l1u1
243:3D3J3T3\3
4V5^5n5
1T2l2F3
3;4G4N4T4
4C5H5]5c5
66$656:6A6F6e6j6q6v6
7#7(7C7H7O7T7[7`7g7l7s7x7
7 8%878<8T8Y8`8e8z8
99X9]9d9j9
9):.:5:::A:F:M:R:Y:^:
;!;=;B;S;X;
<<$<+<0<7<<<C<I<g<l<s<x<
= =%=7=<=X=^=
>Q>V>g>l>
?!?2?8?
C0H0O0T0[0`0g0l0
0 1%1,111M1R1Y1_1
2#282B2I2Q2Z2c2x2
3R4V4\4`4f4j4p4t4z4~4
7!7,737>7E7k7r7
888?8F8M8T8[8b8i8y8
99&9-989=9U9\9g9l9
:!:9:@:P:V:]:d:o:z:
; ;&;-;E;J;b;i;
<!<9<@<^<c<{<
=#=*=5=:=[=b=z=
>>*>/>L>S>^>i>o>v>
?<?C?N?Y?g?n?y?~?
0&0-040;0K0R0m0t0{0
1"1/1@1G1O1W1
<4<A<p<}<
0 0-0E0
676<6G6M6X6]6c6h6
7&7+767;7@7W7\7z7
8#8B8G8d8i8o8t8
94999D9J9O9T9y9~9
:':,:1:N:S:Y:^:~:
;5;@;E;P;U;Z;w;|;
<;<F<K<Q<w<}<
=*=5=:=?=V=a=f=k=
>>*>/>:>?>J>O>T>j>p>
?/?:???J?O?Z?_?j?o?z?
0;0@0K0Q0V0[0r0}0
1%1*151:1?1V1[1w1
2#2(2.2\2g2l2w2|2
3)3/3:3?3J3P3[3`3f3k3
494?4J4O4Z4`4k4p4v4{4
5&5+565;5@5]5b5h5m5
646?6D6O6T6_6d6o6t6
7E7K7q7v7
8/8:8?8J8O8Z8_8e8
9'9,979=9H9M9X9^9c9h9
:':-:8:=:H:N:Y:^:i:o:z:
;(;.;9;>;D;I;`;k;p;{;
<<$<V<a<f<l<
?"?,?1?;?@?J?O?z?
11161@1E1O1T1r1
=k>p>w>|>
?"?I?O?s?x?
0(0.0`0e0l0q0
01$1+101A1F1x1}1
3 3'3,3D3I3g3l3s3x3
4 484>4o4t4{4
5#595>5E5J5
6#6*606W6\6t6y6
8D8I8a8f8~8
9\9a9v9{9
:!:&:-:2:J:O:V:\:
:*;/;g;l;s;y;
<<$<+<0<L<Q<X<]<d<i<p<u<|<
<B=G=N=S=d=i=p=v=
=#>(>m>r>y>~>
)0/0`0e0l0q0
1!1&181=1U1Z1o1t1
2!2(2-24292J2O2V2[2b2g2
373<3C3H3h3n3
4#4*4/4G4L4m4r4y4~4
5R5W5^5c5x5}5
7Q7V7]7b7i7n7u7z7
84898Q8W8t8y8
99&9+92979>9C9f9k9r9w9
:':,:3:8:?:D:K:P:W:]:
<!<(<-<V<[<v<{<
=#=(=F=K=R=W=i=n=
><>A>_>d>k>p>w>|>
?,?1?8?=?D?I?^?c?u?{?
*000N0T0v0{0
1'2,2=2B2\2a2z2
3;3@3G3M3k3p3
3@4E4Z4_4f4k4
4J5P5z5
7"7'7<7B7
88$8+818~8
8;9@9k9q9
:*:/:A:F:M:S:
;!;&;8;=;D;J;
<7<<<_<d<k<p<w<|<
==$=9=>=P=U=
=,>1>8>=>D>I>a>g>
?W?\?m?r?
/040E0J0\0b0
383=3N3S3Z3_3
4@4E4c4h4o4t4
5B5G5f5k5r5w5
6N7S7v7{7
8.838:8@8~8
: :%:,:1:8:>:
;f;k;r;w;
<<><C<[<`<
<#=(=/=4=;=@=R=W=^=c=
=A>F>m>r>
?$?e?j?q?w?
0'0,03090y0
03181I1O1o1t1
2"2)2.252:2A2F2M2R2Y2_2
3"3'3E3J3_3d3u3z3
4:4?4F4K4
4"5'595>5E5J5[5a5
66&6,6{6
768;8m8r8
8G9L9o9u9
: :%:,:2:f:k:r:w:~:
;%;*;<;A;H;M;
;G<L<a<f<x<}<
=1=6===B=I=N=
>@?F?P?W?
0D1K1s1y1
2"2f2l2
5!5'51575
596?6I6O6{6
7+727Z7`7j7p7
9[9a9k9r9
:#;);3;:;
;@<F<i<p<
='=-=7=>=m=s=}=
>F?L?V?\?f?l?
>0D0N0T0^0d0
0a1g1q1x1
373=3\3b3|3
5Y5_5x5~5
5V6\6f6l6v6|6
6%7+757;7b7h7
7'8-878=8
959;9T9Z9t9{9
=!='=1=7=A=G=a=h=
>-?4?c?i?s?y?
D0J0T0Z0d0j0t0z0$1*1W1]1g1m1
152;2j2p2
3T3Z3{3
3"4(42494i4o4
4(5.5b5h5
6!6+626Z6a6
===C=]=c=m=t=
>+>1>;>A>K>Q>
0%0D0J0o0u0
2$2X2^2h2n2
4$4*4C4I4S4Y4c4i4s4y4
<(<-<4<9<@<E<L<R<
=.=3=:=?=F=K=\=a=r=w=~=
>>$>b>g>x>}>
?"?)?.?5?;?f?k?r?w?~?
0 0%0,010B0G0N0S0Z0_0f0k0r0w0|0
1"1D1I1P1U1\1a1
2G2L2h2m2t2y2
3(3-343:3n3s3
4)4.454:4A4F4M4R4Y4^4e4j4q4v4}4
5 5%565;5B5G5N5S5Z5`5
6#6(6/646;6@6G6L6u6z6
7<7A7H7M7^7c7
8 81868K8P8W8\8c8h8
99$959:9M9R9Y9^9e9j9q9v9
:&:+:2:7:T:Y:j:o:v:{:
:9;>;E;J;Q;V;];b;i;n;u;z;
<"<'<8<=<D<I<Y<^<o<t<{<
=)=/=d=i=p=u=|=
>*>/>@>E>b>g>n>t>
??&?+?E?J?[?`?}?
01060=0B0I0N0U0Z0a0f0m0r0
1,111M1R1Y1^1e1j1q1v1}1
2%2*2;2@2G2L2S2X2_2d2k2p2w2|2
3 3%363;3B3G3N3S3Z3_3p3u3|3
4474<4C4I4t4y4
5'5,53585?5D5K5P5W5\5c5h5o5t5{5
6"6)6.656:6K6P6W6\6c6h6y6~6
77$7+70777<7X7]7d7i7p7u7|7
8!8&8-82898>8E8J8[8`8g8l8s8x8
9 9%969;9B9G9N9S9Z9_9f9k9r9w9
:":):.:?:E:p:u:
;";';.;3;:;?;F;K;R;W;^;c;t;y;
<$<)<L<Q<b<g<n<s<z<
=F=K=\=a=h=m=t=y=
>*>/>6>;>B>G>N>S>d>i>p>u>
?!?&?-?2?9?>?U?Z?k?p?
0 0%0?0D0K0P0W0\0c0h0o0t0{0
1#1*1/1@1E1L1Q1X1]1d1i1p1u1
2)2.252:2A2F2W2\2c2h2o2t2
3%3*31363=3B3I3N3_3d3k3p3w3}3
440464a4f4~4
5/545R5W5^5c5j5o5
62676>6C6J6O6T6Y6k6p6w6|6
7 71767G7L7S7X7y7~7
8&8,8\8a8h8m8t8y8
99&9+92979H9M9T9Z9s9y9
:":;:A:Z:`:y:
;4;:;D;J;T;Z;d;j;t;z;
<(<.<Z<`<
=%=+=5=;=g=m=w=}=
=->3>=>C>j>p>z>
?/?5???E?O?U?_?e?~?
0 0&0?0E0O0U0n0t0~0
1"1,121K1Q1[1a1k1q1{1
23292C2I2S2Y2c2i2s2y2
3"3(3B3H3a3g3
4=4C4M4S4
5(5.5H5N5X5^5h5n5
5/656?6E6O6U6_6e6~6
7$7*747:7D7J7c7i7s7y7
8!8+818J8P8i8o8y8
9;9A9K9Q9[9a9z9
:$:*:4:::`:f:p:v:
:#;);C;I;S;Y;c;i;s;y;
<!<'<@<F<P<V<u<{<
='=-=G=M=W=]=g=m=w=}=
>'>->7>=>G>M>W>]>g>m>
>9???c?i?
0,020<0B0[0a0z0
11)1/1H1N1
252;2E2K2U2[2
5%5*5=5C5n5s5z5
6%6*61666=6B6S6X6_6d6k6p6w6|6
7!7&777<7C7H7O7T7l7q7
8%8*8;8@8G8L8_8d8k8p8w8|8
90959<9A9H9M9^9c9j9o9v9{9
: :%:6:;:B:H:m:r:y:~:
;';,;>;C;J;O;`;e;l;q;x;};
<#<(</<4<;<@<G<L<S<X<_<d<k<p<w<|<
==&=+=2=7=>=C=J=O=k=p=w=|=
>#>*>/>6><>o>t>
?*?/?6?;?B?G?N?S?Z?_?f?k?|?
0 0%0,020f0k0r0w0
1%1*11161G1L1S1X1_1d1v1{1
22&2,2_2d2k2p2
33$3A3G3t3z3
4#4*4/464;4B4G4X4]4n4s4z4
5=5B5I5N5_5d5u5z5
61666=6B6V6[6m6r6
7#74797@7F7g7l7}7
8!82878>8C8J8O8V8[8m8r8y8~8
99$969<9
9*:/:6:;:B:G:N:S:Z:_:f:k:r:w:~:
;1;6;G;L;S;X;_;d;k;p;w;|;
<#<(<;<@<G<L<e<j<q<v<}<
=#=(=:=?=F=K=R=W=^=c=t=y=
>1>6>=>B>^>c>j>o>v>{>
?$?)?0?5?<?A?H?M?T?Y?`?e?l?q?
0 0'0,0=0C0n0s0z0
1!1(1-14191_1d1k1p1w1|1
2%2*21262G2L2S2X2j2o2v2{2
3 3'3,3=3B3I3N3U3Z3a3f3m3r3
4$4)40454<4A4R4W4^4c4}4
5)5.5?5D5K5P5W5\5n5s5
6'6,63686J6O6`6e6l6q6
7%7*71767=7B7I7N7U7Z7
8?8D8U8Z8a8f8m8r8y8~8
9%9*91969G9L9S9X9i9n9u9z9
::0:5:F:K:R:W:^:c:j:o:v:{:
;";);.;@;E;L;Q;X;];d;i;p;u;|;
;#<(</<4<;<@<R<W<q<v<}<
= ='=,=3=8=?=D=K=P=a=f=m=r=
>.>3>:>?>F>K>R>W>^>c>j>o>v>{>
?7?=?h?m?~?
0)0.0A0F0^0c0j0o0v0{0
11$1+10171<1C1H1O1T1[1`1g1l1s1x1
1+212;2A2Z2`2j2p2
3'3-373=3j3p3z3
4e4k4u4{4
5$5*545:5D5J5T5Z5d5j5
5 6&6I6O6Y6_6i6o6
6(7.7G7M7W7]7g7m7w7}7
8888>8H8N8X8^8h8n8
99)9/999?9I9O9h9n9
:%:+:J:P:Z:`:
;$;.;4;>;D;N;T;m;s;};
=3=9=C=I=S=Y=c=i=s=y=
>!>+>1>K>Q>[>a>k>q>
>-?3?=?C?\?b?l?r?
0(0.0G0M0W0]0
1$1*141:1D1J1T1Z1d1j1t1z1
10262@2F2P2V2`2f2
343:3D3J3
4#4)43494C4I4S4Y4}4
5#5)53595C5I5S5Z5
6"6(62686R6X6b6h6r6x6
7C7I7c7i7
8>8D8h8n8x8~8
9%9+959;9t9z9
:/:5:N:T:m:s:}:
; ;&;0;6;@;F;P;V;r;x;
>$>)>0>6>v>{>
?#?*?/?@?E?V?[?b?g?x?}?
0F0K0\0a0h0m0t0y0
11J1O1V1[1b1g1x1}1
2&2+22272>2C2J2O2V2[2`2e2l2q2x2}2
3(3-34393@3E3f3k3r3w3
4+404L4Q4X4]4d4i4z4
5R5W5h5m5t5y5
6%6*61666=6B6I6N6U6Z6a6f6m6r6
77&7+72777>7D7o7t7{7
88$8+808Y8^8e8j8q8v8}8
8 9%9,919B9G9g9l9s9x9
:/:4:;:@:G:L:c:h:
;1;6;=;B;I;N;U;Z;k;p;
<8<=<N<S<Z<_<f<k<|<
="=)=.=5=:=A=F=M=R=Y=^=e=j=q=v=
>!>(>->=>B>S>X>_>d>u>{>
?H?M?T?Y?`?e?l?q?x?}?
0$0)0F0K0R0X0{0
1)1.1?1D1a1f1m1r1y1~1
2!2&2-22292>2E2J2Q2V2p2u2|2
31363=3B3I3N3U3Z3a3f3
44$4+40474<4C4H4O4T4[4`4g4l4s4x4
55&5+52575>5C5T5Y5`5e5v5{5
6 6'6-6X6]6v6{6
7#7(7/747;7@7G7L7S7X7_7d7v7{7
8/848;8@8G8L8]8b8i8n8u8z8
9 9<9A9H9M9T9Y9`9e9l9q9x9}9
:":):.:?:D:K:P:W:\:m:r:y:~:
;;&;+;2;7;>;C;J;O;V;[;l;q;x;};
<#<)<T<Y<l<q<x<}<
=#=*=/=6=;=B=G=X=]=d=i=
>0>5>F>K>R>W>^>c>t>y>
>*?/?@?E?L?Q?X?]?d?i?z?
00&0+02070H0M0T0Y0j0o0v0{0
1"191>1O1T1e1j1{1
2#2(2/242;2@2G2L2S2X2_2d2
3$3)30353<3A3H3M3T3Y3w3|3
4%4*4;4@4G4L4S4X4z4
5!5&5-525C5H5O5T5[5a5
6E6J6b6g6x6}6
767;7B7G7N7S7u7z7
8"8'8.83888=8O8T8[8`8r8w8~8
9+90979<9]9b9i9n9
:@:E:L:Q:X:]:d:i:p:u:|:
;,;1;8;>;W;];
<<%<><D<]<c<
=(=.=8=>=H=N=X=^=h=n=
>>>D>}>
??K?Q?[?a?
0!0'0N0T0^0d0
1#1)13191C1I1b1h1r1x1
2#2)23292R2X2b2h2r2x2
3/353?3E3O3U3_3e3~3
4'4-474=4G4M4W4]4g4m4w4}4
5&5,5E5K5d5j5
5!6'61676m6s6}6
7,727<7B7L7R7t7z7
8#8)83898C8I8b8h8
9(9.9G9M9W9]9
:.:4:M:S:]:c:m:s:}:
;;%;/;5;?;E;^;d;
<D<J<T<Z<s<y<
='=-=7===G=M=W=]=g=m=
>$>*>4>:>Y>_>i>o>
?+?1?;?A?K?Q?[?a?k?q?{?
0!0+010;0A0K0Q0
1#1G1M1u1{1
2 2&2?2E2^2d2n2t2~2
3,323n3t3
44)4/494?4i4o4
5#7L74<
:0;R;i;
?#?)?\?i?
0"1T1v1|1
5j6o6v6{6
697>7E7J7Q7V7n7s7z7
9)9/9z9
:$;1;P;];|;
6*6/666;6|6
6)7.7w7|7
8A8F8n8s8
5j7z9-:D:K:P:r:x:
;^;c;{;
< <&<d<j<
= =s=y=
=>$>+>1>t>y>
>1?6?K?Q?q?v?
0I0N0U0Z0
14191@1E1c1h1
2O2T2[2a2
353:3L3Q3c3h3
5[5`5g5l5~5
6*6/6@6E6Z6_6f6k6r6w6
7<7A7H7M7
8$8*8Z8_8f8k8
8$9)9E9J9Q9V9]9b9
: :%:,:1:I:N:c:h:o:t:
=>=D=~=
=2>7>Z>_>t>y>
?+?0?S?Y?~?
0"0J0O0V0[0
00151F1K1R1X1z1
2+212Z2`2
2-323P3U3j3o3
4!4@4E4L4Q4X4^4
6.636:6@6
8)8.8\8a8h8m8t8y8
9!9'9E9J9k9p9w9|9
::;@;^;c;
;!<&<X<]<d<i<z<
=!=&=-=2=D=I=
=B>G>N>S>h>m>t>y>
?0?5?R?W?^?c?z?
0+00070=0j0o0v0{0
2"2)2.2x2}2
3I3N3U3Z3
3#4(4O4T4r4w4~4
4 5&5^5c5j5o5
687=7D7I7P7U7m7r7y7~7
7'8,83888u8{8
9`9e9l9r9
:R:W:^:c:j:o:v:{:
;6;;;B;G;N;S;q;w;
<<%<~<
=1=7=Z=`=
>#>(>E>J>i>n>
?)?/?M?R?p?u?
111171W1\1{1
1 2&2b2g2
3'3,3_3d3k3q3
484=4U4Z4
44595@5E5L5Q5
7p7u7|7
7=8B8U8Z8
9%9+9\9b9
9":':?:D:V:\:
::;?;Q;V;
;/<5<V<[<
=5=:=A=F=M=R=Y=^=z=
=.>3>:>?>T>Y>`>e>l>q>x>}>
>Q?V?k?q?
0$0*0m0r0y0~0
2-22292>2V2[2s2x2
3R3W3z3
3=4B4I4N4U4[4}4
5%5*5B5G5
66&6+6@6E6L6Q6}6
67$7+707N7S7Z7_7
8 82878U8Z8o8u8
959;9u9z9
:/:4:;:A:
;<;A;R;X;
<%<*<1<6<=<C<e<k<
=0=5=q=w=
>,>1>B>G>N>S>Z>_>f>k>r>w>~>
>?$?+?0?E?J?Q?V?]?b?i?n?u?z?
060;0W0\0c0h0
1 1b1g1
22272>2C2f2l2
3#3)3f3k3r3w3
5*505h5m5t5y5
5%6*6;6@6G6L6S6X6_6e6
6,71787=7D7I7P7U7\7a7v7{7
8(8-8B8H8|8
9-92999>9E9J9f9k9r9w9
:2:7:Z:_:z:
;#;(;:;@;v;{;
=D=I=g=l=
=9>>>g>l>s>x>
>6?<?i?n?
0"0^0c0{0
191>1E1J1i1n1u1z1
1&2+2@2E2L2Q2X2]2d2i2p2u2
383=3[3`3g3l3~3
4,414F4K4R4W4^4c4j4p4
4-535t5y5
6D6I6P6U6f6k6
6 7%7,727<7B7L7R7\7b7l7r7
8D8J8m8s8}8
8E9K9U9[9e9l9
<%<+<5<;<Z<`<j<p<
="=J=P=i=o=
>-?3?M?S?v?|?
22%2/252?2E2y2
40565O5V5
6,626<6B6a6h6
7"7(72787Q7W7a7g7q7w7
768<8s8y8
8-939L9S9
9<:B:a:g:
;*;0;S;Y;
;M<S<]<c<
=C>I>b>h>
?,?2?<?B?L?R?\?b?l?r?
0$0C0I0S0Z0
2"2(22282e2k2
4=5C5M5S5]5c5m5s5
72787l7r7
7P8V8y8
8"9(92999
<(<.<8<><H<N<v<|<
=Z>`>y>
0*101:1@1
5D5J5T5Z5
6k6q6{6
6"7)7Q7W7v7|7
7%8,8f8l8v8|8
9#9F9L9
:#:*:/:]:b:i:n:u:{:
;#;(;/;4;F;L;
>(>->E>J>
?%?+?j?o?
1 1%1G1L1S1Y1w1|1
1'2,2A2G2
31363=3B3
4:4@4t4y4
5?5E5|5
8'8,83888?8D8
8=9B9I9N9U9Z9a9f9
:#:b:g:
; ;k;q;
<?<D<u<{<
=&=+=2=7=>=D=
=E>J>Q>V>]>b>~>
0 0J0O0q0v0
1(2-2K2Q2t2y2
3 3R3W3l3r3
3W4\4c4i4
5 5%5C5H5O5T5[5`5g5l5s5x5
6$6)6n6s6
7!7&7-72797>7f7k7
8!8(8-8r8w8
8Z9_9f9l9
90:6:a:f:
<3<9<s<y<
=Q=W=u=z=
>!>&>i>n>u>{>
0[0`0u0z0
0_1d1k1p1
2#2(2:2?2P2V2
2"3'3.333H3M3^3c3
5 5\5a5t5y5
797>7a7f7
7!8&8;8@8
9 9'9,93989M9R9Y9^9
::7:<:
;*;/;6;;;
< <%<,<1<C<H<`<f<
=-=2=9=?=
>->2>9>>>E>J>
??&?+?2?7?O?U?}?
.030:0?0T0Y0
1L1Q1X1]1d1i1
1)2.2C2H2d2i2
3!3'3k3p3
3.444b4g4|4
4>5C5J5O5n5s5z5
676<6N6S6e6j6q6v6}6
:/:4:;:@:R:W:^:c:
;6;;;V;\;
;0<6<l<q<x<}<
<!=&=-=2=C=H=
?D?I?P?U?\?a?
0;0@0X0]0d0i0p0u0
1)1.1M1R1
1.232l2q2
30353G3M3g3m3
6E6J6Q6W6w6}6
7^7c7{7
72878A8G8
;R;W;^;c;
<<$<+<1<O<T<f<k<r<x<
=j=o=v={=
>!>'>[>`>g>m>
?N?S?d?j?
0"0<0A0H0M0T0Y0`0e0
1+101M1S1
2'2,23282?2D2K2P2
3 3'3-3h3n3
4#4*4/4N4S4h4m4t4y4
5!5&5I5N5j5o5
6>6C6J6P6t6z6
8X8]8d8j8
: :%:,:2:k:p:
;(;-;B;G;N;S;f;k;
<6<;<W<\<c<h<y<~<
=#>(>g>l>
0=0C0|0
1V1[1b1g1n1s1
2"2)2.2_2d2k2p2
253:3A3F3W3\3c3h3
4,414I4N4q4w4
5J5O5z5
81868=8C8j8p8
9>9D9t9y9
:(:-:?:D:K:Q:
;M;R;Y;^;s;x;
<"<><C<
<%=*=<=B=
>)>.>5>;>
;8;?;K;R;
<6<=<I<O<
0(020:0
2A2G2m2s2}2
3"4(42484
5$6*646:6w6~6
7#7)73797
8I9O9Y9_9i9p9
:#:):3:9:~:
;";,;2;K;Q;[;a;t=
>0[0x0
9":I:s:
>#>F>S>\>
>'?4?=?
4)4[4i4
==;=L=V=u=}=
0"0)00080@0i0
131Z1a1|1
2]3d3p3w3
55$565<5r5w5
6`6e6l6q6
7H7M7_7d7
7R8X8}8
9D9I9[9`9
;"<'<X<]<d<i<p<v<
<<=A=H=M=_=d=k=p=
>;>@>G>M>
>4?9?K?Q?
0S0X0p0u0
1/141;1@1^1c1j1o1
20252G2L2S2X2_2d2k2p2
4)4.4?4D4
4#5(5/545;5@5U5Z5a5f5m5r5y5
686S6Y6d6
8:8A8M8T8
9K9R9^9e9q9x9
:&:-:M:T:
;";v;};
>/>@>f>
0%00060O0V0a0l0r0y0
1#131:1A1H1O1V1r1y1
2"2)20272>2E2L2S2Z2a2h2o2v2}2
3"3)3<3C3J3Q3a3h3z3
4#4*4B4I4a4g4
5+525B5I5P5W5^5e5l5s5z5
6 6'6.656<6C6J6Q6X6_6f6m6t6{6
7$7+72797@7G7N7U7e7l7s7z7
8"8)80878>8E8U8[8
9"9)90979>9R9Y9z9
::&:-:4:;:B:I:Y:`:g:n:u:|:
; ;';.;5;<;C;S;Z;a;h;o;v;};
< <'<.<5<<<C<J<Q<X<_<f<m<t<{<
= ='=.=5=<=P=W=^=e=l=s=z=
>>&>->4>;>K>R>Y>`>p>w>~>
?3?:?J?Q?X?_?v?|?
1X1q1{1
1*2/292A2}2
3N3S3]3e3m3u3}3
424<4F4
5K5U5]5g5<6F6N6X6
637=7E7M7U7]7e7o7
8.838@8z8
9-:c:v:
;#;);/;5;;;A;
<:=@=S=>8>B>
?.?]?g?p?
0"0*0f0p0y0
1!101:1S1a1g1m1s1y1
2,252G2P2[2b2k2
J<N<R<V<Z<^<b<f<j<n<r<v<z<~<
>(?/?4?8?<?@?
5[5`5d5h5l5
<p=t=|=
> >+>1>?>K>P>i>z>
?#?+?C?S?f?
4G5O5Y5b5s5
;4;9;B;<)<.<4<
2/3]3f3
5&5?5[6
0K1_1{1
I4N4S4n4s4x4
11S1[1|1
1N2v3&5_6
9@9J9X9s9
:$:8:U:o:
>?>Q>]>z>
?*?/?4?O?^?i?n?s?
1.1<1H1T1h1~1
2)292G2L2Q2a2f2k2{2
3*313A3H3P3W3a3j3t3
4.4;4T4m4
555^5s5
1111Y1
6V6[6`6e6
9a9u9|9
:8:S:`:n:|:
6Q6[6~6
3'3b3i3*4D4
55b5h5
<"<-<;<
0)0S0
1+1=1O1a1s1
949Y9p9
;H;S;Z;f;p;z;~;
>f?q?x?~?
0d1v1X3c3p3y3
5+525?5S5X5^5
6A6K6U6_6i6v6
9':d:n:
;/<b<w<
3L3d3i3
6 6;6E6Q6V6[6y6
7(7P7d7v7
;S;g;f<z?
7n;t<|<
9 9<9R9
9I<=n=}=]>
7D7h7s7
9%9.9?9O9o9u9
;9<A<I<Q<Y<w<
2;3<4L4]4e4u4
5A5P5\5k5~5
5,656>6G6r6
<)<?<G<
,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
8 8$8(8,8084888<8@8D8H8
;0<8<<<@<H<P<X<\<`<d<h<l<p<t<|<
d2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
5(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<
D2H2L2P2
3 3$3(3,303<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
3H7L7P7T7X7\7`7d7h7l7p7t7x7|7
P0T0X0
1$1,141<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
6 6(60686@6H6P6X6`6h6p6x6
7 7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
H1L1P1h1l1p1Z3^3b3f3\<d<l<t<|<
=$=,=4=<=
>$><>L>P>`>d>l>
< <<<@<\<`<|<
= =@=`=
>(>H>h>
?(?H?h?
0(0H0d0h0
1 1(1,1<1`1l1t1
8$8(8,8084888<8@8D8H8L8P8T8X8
101<1@1D1`1d1 2(2,2024282<2@2D2H2L2X2\2`2d2h2l2p2t2
\Last Version
crypt32.dll
45538e52191fe131243fae173d27eb3c363ae13c6500eb26313ae035360f
aab58e5185f0f625cfdbfd38c5dbfd7e
ze4154e92ac7c3de68b6737
22fe32036e91556a4cde7662569f
362f0ee17a406988580f4a80424e2ea7595d2ea0554c6194585b
bae785b2ed82e792fe86f1d3
6cdb83d922bef7ae03a9e8852fb4ecb205bef0
f423d2eaa86fbd89954ff2b9804ca08b93468e869155b7869041
d1ec3fb8feae4dd7a69f5aca95ae
kernel32.dll
0772e02c5b3e8f4f661ec07f73139449
/BrowserVersion.txt
805e4b8ce42e65f8f82a
@chrome.exe
msedge.exe
opera.exe
operagx.exe
brave.exe
ntdll.dll
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
Content-Type: application/x-www-form-urlencoded
winhttp.dll
be85de5ipdocierre1
Content-Type: multipart/form-data; boundary=%s
Cookie: __cf_mw_byp=%hs
l2%08x%08x%04x%xu
5f40a9e07a2cc6833e2cc8902f24c8943e65f5b03e23c2813825da
09ebf5306482964266989a567dc58259678f9a477a889a5d649e9b596a8a815966858651799b861a
389b7c4264d7132159f72f3659ef191e71f5182740fe181e74f20a277bf4112f
ef0aca36a26ba35acf49a65f8a64be45b359be57816eab449b2a9d5f812afb06cf47ab5f83
3612671d137e087e577e066d4676066957373b505f711572457d01696a450e73527d106e165f06745a4e2b7255730b3d707d0b79536014
d42457f199453e9df4673b98b14a238288772390ba403683a0040098ba0466c1f4693698b804169da041259fb5503e87b1743685bc
2b475e6e0e262e1e4f262a0f0e1b0a065e293a0b5925371c4f1b0e1c442137024e34
769cb9aa22f4ccc412f9cbc81feedd
xtpmzd
ec48478eb02322f7d86623ec
708563d71be01ae35ee101
20ae83e543cbf1911980e787
6181e60b07ee946609e8957f0ef39f2512f08a6215e4
5e6687603d09e80b3703f44e2d17eb092a03
1fc5749573aa13fc71b65aff6caa1a
3e25f2624e4993015b56dc114f499b165b
SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
user32.dll
advapi32.dll
(null)
mscoree.dll
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
Fapi-ms-win-core-datetime-l1-1-1
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-synch-l1-2-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernel32
api-ms-win-appmodel-runtime-l1-1-2
user32
api-ms-
ext-ms-
Fja-JP
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
((((( H
(
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
tehtris Clean
ClamAV Clean
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.Backdoor.gh
ALYac Gen:Variant.Zusy.527736
Cylance unsafe
Zillya Trojan.Agent.Win32.3779002
Sangfor Suspicious.Win32.Save.a
K7AntiVirus Spyware ( 0055134d1 )
Alibaba TrojanPSW:Win32/Lumma.559fd928
K7GW Spyware ( 0055134d1 )
Cybereason malicious.d9945c
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Win32/Spy.Agent.PRG
APEX Malicious
Avast Win32:Evo-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky HEUR:Trojan-PSW.Win32.Lumma.pef
BitDefender Gen:Variant.Zusy.527736
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Agent.503296.L
MicroWorld-eScan Gen:Variant.Zusy.527736
Tencent Malware.Win32.Gencirc.10bf69cc
TACHYON Clean
Sophos Mal/Generic-S
F-Secure Clean
DrWeb Trojan.PWS.Stealer.36160
VIPRE Gen:Variant.Zusy.527736
TrendMicro TrojanSpy.Win32.LUMMASTEALER.YXDLNZ
Trapmine malicious.high.ml.score
FireEye Generic.mg.fd1ec4e0dd8213b4
Emsisoft Gen:Variant.Zusy.527736 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Zusy.527736
Jiangmin Trojan.PSW.Stealerc.vp
Webroot Clean
Varist W32/SpyAgent.S.gen!Eldorado
Avira Clean
Antiy-AVL Trojan[Spy]/Win32.Agent
Kingsoft malware.kb.a.1000
Gridinsoft Spy.Win32.Keylogger.sa
Xcitium Clean
Arcabit Trojan.Zusy.D80D78
SUPERAntiSpyware Clean
ZoneAlarm HEUR:Trojan-PSW.Win32.Lumma.pef
Microsoft Trojan:Win32/Znyonm
Google Detected
AhnLab-V3 Trojan/Win.Generic.R626601
Acronis Clean
McAfee GenericRXWM-BN!FD1EC4E0DD82
MAX malware (ai score=89)
VBA32 Clean
Malwarebytes Spyware.Lumma
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.LUMMASTEALER.YXDLNZ
Rising Spyware.Agent!8.C6 (TFE:5:0hRNWOCAIyF)
Yandex Clean
Ikarus Trojan-Spy.Win32.Agent
MaxSecure Trojan.Malware.121218.susgen
Fortinet W32/Agent.PRG!tr
BitDefenderTheta Gen:NN.ZexaF.36608.EqW@a4wuSDm
AVG Win32:Evo-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (W)
No IRMA results available.