Name: | 1521AD4EF052DF85.GodPotato.exe.avg.exe |
Size: | 60,416 bytes |
Type: | EXE PE.NET |
MD5: | de999e15a19e1865957c7aec19b838bc |
Scanner Name: | avg |
Appraisal: | Fragile (AND) based |
Scan Debug: | Duration: 102s / Chunks: 474 / Matches: 143 |
Scan date: | 2023-07-21 21:36:45 |
# | Iteration | Offset | Size | Section | Detail | SectionType | Conclusion |
---|---|---|---|---|---|---|---|
0 | 0 | 15252 | 8 | .text #~ | DATA | Dominant. Modify this to make file undetected | |
1 | 0 | 15268 | 29 | .text #~ | DATA | Dominant. Modify this to make file undetected | |
5 | 0 | 15923 | 4 | .text #~ | TypeRef | DATA | Dominant. Modify this to make file undetected |
6 | 0 | 16520 | 4 | .text #~ | TypeDef | DATA | Dominant. Modify this to make file undetected |
7 | 0 | 16528 | 21 | .text #~ | TypeDef | DATA | Dominant. Modify this to make file undetected |
8 | 0 | 16574 | 46 | .text #~ | TypeDef | DATA | Dominant. Modify this to make file undetected |
9 | 0 | 16628 | 117 | .text #~ | TypeDef | DATA | Dominant. Modify this to make file undetected |
11 | 0 | 16779 | 50 | .text #~ | TypeDef | DATA | Dominant. Modify this to make file undetected |
12 | 0 | 19566 | 8 | .text #~ | Field | DATA | Dominant. Modify this to make file undetected |
13 | 0 | 19607 | 9 | .text #~ | Field | DATA | Dominant. Modify this to make file undetected |
14 | 0 | 19700 | 33 | .text #~ | Field | DATA | Dominant. Modify this to make file undetected |
15 | 0 | 22587 | 33 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
16 | 0 | 22654 | 16 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
17 | 0 | 22854 | 8 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
18 | 0 | 22904 | 17 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
20 | 0 | 23021 | 16 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
21 | 0 | 23078 | 9 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
22 | 0 | 23121 | 33 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
23 | 0 | 23188 | 16 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
24 | 0 | 23246 | 9 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
25 | 0 | 23288 | 33 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
26 | 0 | 23354 | 17 | .text #~ | MethodDef | DATA | Dominant. Modify this to make file undetected |
28 | 0 | 28029 | 34 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
29 | 0 | 28112 | 33 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
30 | 0 | 28179 | 50 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
31 | 0 | 28313 | 17 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
32 | 0 | 28346 | 33 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
33 | 0 | 28412 | 134 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
34 | 0 | 28679 | 17 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
35 | 0 | 28813 | 34 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
36 | 0 | 28913 | 17 | .text #~ | MemberRef | DATA | Dominant. Modify this to make file undetected |
37 | 1 | 36629 | 4 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
40 | 1 | 40484 | 15 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
41 | 1 | 40636 | 15 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
42 | 1 | 42153 | 23 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
43 | 1 | 44179 | 23 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
44 | 1 | 46676 | 22 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
45 | 1 | 46721 | 15 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
46 | 1 | 47192 | 15 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
47 | 1 | 47511 | 15 | .text #Strings | DATA | Dominant. Modify this to make file undetected | |
48 | 2 | 53596 | 257 | .text #Blob | DATA | Dominant. Modify this to make file undetected | |
49 | 2 | 54946 | 32 | .text #Blob | DATA | Dominant. Modify this to make file undetected | |
50 | 2 | 55927 | 16 | .text #Blob | DATA | Dominant. Modify this to make file undetected |
Dominant. Modify this to make file undetected |
00003B94 57 FF A2 1D 09 0E 00 00 W.......
Dominant. Modify this to make file undetected |
00003BA4 01 00 00 00 61 00 00 00 42 00 00 00 F6 01 00 00 ....a...B....... 00003BB4 0B 01 00 00 B0 02 00 00 03 00 00 00 D3 .............
Dominant. Modify this to make file undetected |
00003E33 33 06 00 AE 3...
Dominant. Modify this to make file undetected |
00004088 02 01 00 00 ....
Dominant. Modify this to make file undetected |
00004090 A5 00 C0 01 C2 00 02 01 10 00 D2 1E 00 00 D1 00 ................ 000040A0 C0 01 C6 00 03 .....
Dominant. Modify this to make file undetected |
000040BE D2 00 02 01 00 00 60 01 00 00 A5 00 C7 01 D4 00 ......`......... 000040CE 02 01 00 00 7F 01 00 00 A5 00 C7 01 D8 00 02 01 ................ 000040DE 00 00 BE 01 00 00 A5 00 C7 01 DC 00 02 01 ..............
Dominant. Modify this to make file undetected |
000040F4 C7 01 E0 00 02 01 00 00 FC 01 00 00 A5 00 C7 01 ................ 00004104 E4 00 02 01 00 00 11 02 00 00 A5 00 C7 01 E8 00 ................ 00004114 02 01 00 00 01 00 00 00 A5 00 C7 01 EC 00 02 01 ................ 00004124 00 00 43 00 00 00 A5 00 C7 01 F0 00 02 01 00 00 ..C............. 00004134 6F 00 00 00 A5 00 C7 01 F4 00 02 01 00 00 EA 00 o............... 00004144 00 00 A5 00 C7 01 F8 00 02 01 00 00 0F 01 00 00 ................ 00004154 A5 00 C7 01 FC 00 0A 01 10 00 7B 0A 00 00 45 00 ..........{...E. 00004164 C7 01 00 01 0D .....
Dominant. Modify this to make file undetected |
0000418B 00 45 00 CE 01 00 01 0A 01 10 00 A9 04 00 00 45 .E.............E 0000419B 00 D7 01 00 01 0A 01 10 00 CC 08 00 00 45 00 DA .............E.. 000041AB 01 00 01 03 01 00 00 10 1C 00 00 41 00 E2 01 00 ...........A.... 000041BB 01 05 ..
Dominant. Modify this to make file undetected |
00004C6E 01 00 01 13 92 00 01 00 ........
Dominant. Modify this to make file undetected |
00004C97 09 06 00 0F 23 23 09 06 00 ....##...
Dominant. Modify this to make file undetected |
00004CF4 E0 32 1C 09 06 00 4D 38 1C 09 06 00 7C 17 3C 00 .2....M8....|.<. 00004D04 06 00 85 11 23 09 06 00 68 0F 3C 00 06 00 7C 17 ....#...h.<...|. 00004D14 3C <
Dominant. Modify this to make file undetected |
0000583B 00 00 00 91 18 59 2E 12 0B 92 01 00 00 00 00 03 .....Y.......... 0000584B 00 86 18 53 2E 53 05 92 01 00 00 00 00 03 00 C6 ...S.S.......... 0000585B 01 .
Dominant. Modify this to make file undetected |
0000587E 19 54 00 00 00 00 86 08 42 19 C9 00 99 01 21 54 .T......B.....!T
Dominant. Modify this to make file undetected |
00005946 03 00 86 18 53 2E 53 05 ....S.S.
Dominant. Modify this to make file undetected |
00005978 AD 01 00 00 00 00 03 00 86 18 53 2E 53 05 AE 01 ..........S.S... 00005988 00 .
Dominant. Modify this to make file undetected |
000059ED 00 03 00 86 18 53 2E 53 05 CE 01 00 00 00 00 03 .....S.S........
Dominant. Modify this to make file undetected |
00005A26 03 00 86 18 53 2E 53 05 E1 ....S.S..
Dominant. Modify this to make file undetected |
00005A51 00 C6 01 66 17 80 0D F5 01 00 00 00 00 03 00 86 ...f............ 00005A61 18 53 2E 53 05 F6 01 00 00 00 00 03 00 C6 01 75 .S.S...........u 00005A71 17 .
Dominant. Modify this to make file undetected |
00005A94 00 00 03 00 86 18 53 2E 53 05 0D 02 00 00 00 00 ......S.S.......
Dominant. Modify this to make file undetected |
00005ACE 03 00 86 18 53 2E 53 05 26 ....S.S.&
Dominant. Modify this to make file undetected |
00005AF8 03 00 C6 01 66 17 80 0D 40 02 00 00 00 00 03 00 ....f...@....... 00005B08 86 18 53 2E 53 05 41 02 00 00 00 00 03 00 C6 01 ..S.S.A......... 00005B18 75 u
Dominant. Modify this to make file undetected |
00005B3A 00 00 00 00 03 00 86 18 53 2E 53 05 5E 02 00 00 ........S.S.^... 00005B4A 00 .
Dominant. Modify this to make file undetected |
00006D7D 2F E0 00 11 01 53 2E E5 00 0C 00 53 2E 06 00 29 /....S.....S...) 00006D8D 02 AD 00 09 01 0C 00 C6 10 0E 01 0C 00 49 3B 14 .............I;. 00006D9D 01 81 ..
Dominant. Modify this to make file undetected |
00006DD0 2E 2F A0 01 14 00 53 2E 06 00 29 02 21 24 E0 00 ./....S...).!$.. 00006DE0 14 00 C6 10 0E 01 14 00 49 3B 14 01 29 01 2E 36 ........I;..)..6 00006DF0 F2 .
Dominant. Modify this to make file undetected |
00006E13 1C 06 00 1C 00 53 2E 06 00 1C 00 49 3B 14 01 1C .....S.....I;... 00006E23 00 5E 26 40 02 39 02 C1 3B 46 02 1C 00 67 26 4C .^&@.9..;F...g&L 00006E33 02 1C 00 34 38 7F 00 1C 00 C6 10 0E 01 39 02 C9 ...48........9.. 00006E43 36 7F 6.
Dominant. Modify this to make file undetected |
00006E99 03 69 01 51 3B E1 02 69 01 F5 1B DB 02 34 00 53 .i.Q;..i.....4.S 00006EA9 2E .
Dominant. Modify this to make file undetected |
00006EBA 1A 22 C9 00 34 00 C6 10 0E 01 34 00 34 38 7F 00 ."..4.....4.48.. 00006ECA 21 01 70 16 25 03 34 00 5E 26 40 02 21 01 EA 1F !.p.%.4.^&@.!... 00006EDA 2F /
Dominant. Modify this to make file undetected |
00006EFC 63 30 91 03 44 00 53 2E 06 00 A1 01 3B 1E A2 03 c0..D.S.....;... 00006F0C 39 02 08 2E C9 00 44 00 C6 10 AE 03 39 02 2D 23 9.....D.....9.-# 00006F1C 1B 03 39 02 23 22 B6 03 44 00 D5 1F BB 03 0C 00 ..9.#"..D....... 00006F2C 6F 20 C4 03 0C 00 34 38 7F 00 39 02 C2 36 CA 03 o ....48..9..6.. 00006F3C 09 01 53 2E 10 00 4C 00 53 2E 06 00 4C 00 C6 10 ..S...L.S...L... 00006F4C 0E 01 81 01 53 2E 06 00 39 01 53 1A 06 00 4C 00 ....S...9.S...L. 00006F5C 45 2E 30 04 54 00 0A 38 43 04 39 01 53 1A 48 04 E.0.T..8C.9.S.H. 00006F6C 54 00 0E 3A E1 02 D9 00 96 1C 06 00 4C 00 34 38 T..:........L.48 00006F7C 7F 00 39 02 C9 36 ..9..6
Dominant. Modify this to make file undetected |
00007007 00 29 02 8F 3B 0D 05 D9 01 49 3B 02 05 5C 00 5E .)..;....I;..\.^ 00007017 26 &
Dominant. Modify this to make file undetected |
0000708D 02 A9 01 8D 05 39 02 17 34 94 05 5C 00 53 2E 06 .....9..4..\.S.. 0000709D 00 5C 00 C6 10 0E 01 29 02 13 37 C0 05 F1 01 11 .\.....)..7..... 000070AD 1A D5 ..
Dominant. Modify this to make file undetected |
000070F1 06 64 00 53 2E 06 00 D9 01 53 2E 07 05 81 02 11 .d.S.....S...... 00007101 17 .
Dominant. Modify this to make file undetected |
00008F15 00 41 64 64 .Add
Dominant. Modify this to make file undetected |
00009E24 00 54 72 79 47 65 74 56 61 6C 75 65 00 50 61 .TryGetValue.Pa
Dominant. Modify this to make file undetected |
00009EBC 76 65 00 52 65 6D 6F 76 65 00 47 6F 64 50 6F ve.Remove.GodPo
Dominant. Modify this to make file undetected |
0000A4A9 67 72 61 6D 00 67 65 74 5F 49 74 65 6D 00 73 65 gram.get_Item.se 0000A4B9 74 5F 49 74 65 6D 00 t_Item.
Dominant. Modify this to make file undetected |
0000AC93 72 00 47 65 74 45 6E 75 6D 65 72 61 74 6F 72 00 r.GetEnumerator. 0000ACA3 2E 63 74 6F 72 00 2E .ctor..
Dominant. Modify this to make file undetected |
0000B654 6F 6E 65 6E 74 00 67 65 74 5F 43 75 72 72 65 6E onent.get_Curren 0000B664 74 00 47 65 74 43 t.GetC
Dominant. Modify this to make file undetected |
0000B681 6E 74 00 67 65 74 5F 43 6F 75 6E 74 00 50 72 nt.get_Count.Pr
Dominant. Modify this to make file undetected |
0000B858 75 74 70 75 74 00 4D 6F 76 65 4E 65 78 74 00 utput.MoveNext.
Dominant. Modify this to make file undetected |
0000B997 79 00 54 6F 41 72 72 61 79 00 67 65 74 5F 49 y.ToArray.get_I
Dominant. Modify this to make file undetected |
0000D15C 00 04 20 01 01 08 03 20 00 01 05 20 01 01 11 11 .. .... ... .... 0000D16C 04 20 01 01 0E 04 20 01 01 02 07 20 02 01 11 51 . .... .... ...Q 0000D17C 11 55 05 20 01 01 11 71 05 20 01 01 11 7D 06 20 .U. ...q. ...}. 0000D18C 01 01 11 80 C9 06 07 04 02 02 02 02 02 06 18 04 ................ 0000D19C 00 01 18 08 03 07 01 02 05 07 03 02 02 02 05 00 ................ 0000D1AC 02 02 18 18 03 07 01 09 03 20 00 0A 05 07 02 18 ......... ...... 0000D1BC 11 70 04 20 01 01 0A 08 00 01 12 80 B5 11 81 19 .p. ............ 0000D1CC 06 00 01 08 12 80 B5 07 00 02 1C 18 12 80 B5 03 ................ 0000D1DC 20 00 08 04 00 01 18 0E 04 00 01 01 18 04 07 02 ............... 0000D1EC 02 0E 02 06 0E 05 00 02 0E 18 08 04 07 01 12 6C ...............l 0000D1FC 15 07 0D 12 6C 12 80 89 09 11 3C 0E 02 12 6C 02 ....l.....<...l. 0000D20C 18 02 02 02 12 65 09 00 02 02 12 80 89 12 80 89 .....e.......... 0000D21C 08 20 01 12 81 25 12 80 B5 03 20 00 0E 06 00 02 . ...%.... ..... 0000D22C 0E 0E 1D 0E 0B 07 05 09 18 12 80 89 02 12 80 89 ................ 0000D23C 04 00 01 18 18 04 20 01 01 18 17 07 0B 15 12 80 ...... ......... 0000D24C 8D 01 0E 18 12 80 89 09 02 08 08 08 12 80 85 02 ................ 0000D25C 1D .
Dominant. Modify this to make file undetected |
0000D6A2 02 06 00 03 0E 0E 0E 0E 04 20 00 11 69 05 20 02 ......... ..i. . 0000D6B2 01 1C 18 06 20 01 01 12 81 75 06 00 01 18 12 80 .... ....u......
Dominant. Modify this to make file undetected |
0000DA77 16 02 06 09 03 06 11 08 02 06 08 02 06 02 03 06 ................
Test # | MatchOrder | ModifyPosition |
Match#0 #~ 8b |
Match#1 #~ 29b |
Match#2 #~ 4b |
Match#3 #~ 30b |
Match#4 #~ 8b |
Match#5 #~ 4b |
Match#6 #~ 4b |
Match#7 #~ 21b |
Match#8 #~ 46b |
Match#9 #~ 117b |
Match#10 #~ 9b |
Match#11 #~ 50b |
Match#12 #~ 8b |
Match#13 #~ 9b |
Match#14 #~ 33b |
Match#15 #~ 33b |
Match#16 #~ 16b |
Match#17 #~ 8b |
Match#18 #~ 17b |
Match#19 #~ 17b |
Match#20 #~ 16b |
Match#21 #~ 9b |
Match#22 #~ 33b |
Match#23 #~ 16b |
Match#24 #~ 9b |
Match#25 #~ 33b |
Match#26 #~ 17b |
Match#27 #~ 34b |
Match#28 #~ 34b |
Match#29 #~ 33b |
Match#30 #~ 50b |
Match#31 #~ 17b |
Match#32 #~ 33b |
Match#33 #~ 134b |
Match#34 #~ 17b |
Match#35 #~ 34b |
Match#36 #~ 17b |
Match#37 #Strings 4b |
Match#38 #Strings 15b |
Match#39 #Strings 31b |
Match#40 #Strings 15b |
Match#41 #Strings 15b |
Match#42 #Strings 23b |
Match#43 #Strings 23b |
Match#44 #Strings 22b |
Match#45 #Strings 15b |
Match#46 #Strings 15b |
Match#47 #Strings 15b |
Match#48 #Blob 257b |
Match#49 #Blob 32b |
Match#50 #Blob 16b |
0 | ISOLATED | MIDDLE8 | |||||||||||||||||||||||||||||||||||||||||||||||||||
1 | ISOLATED | THIRDS4 | |||||||||||||||||||||||||||||||||||||||||||||||||||
2 | ISOLATED | FULL | |||||||||||||||||||||||||||||||||||||||||||||||||||
3 | ISOLATED | FULLB | |||||||||||||||||||||||||||||||||||||||||||||||||||
4 | INCREMENTAL | MIDDLE8 | 1 | 3 | 7 | 8 | 9 | 11 | 14 | 15 | 16 | 18 | 19 | 20 | 22 | 23 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 39 | 42 | 43 | 44 | 48 | 49 | 50 | ||||||||||||||||||
5 | INCREMENTAL | FULL | 0 | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 | 12 | 13 | 14 | 15 | 16 | 17 | 18 | 19 | 20 | 21 | 22 | 23 | 24 | 25 | 26 | 27 | 28 | 29 | 30 | 31 | 32 | 33 | 34 | 35 | 36 | 37 | 38 | 39 | 40 | 41 | 42 | 43 | 44 | 45 | 46 | 47 | 48 | 49 | 50 |
6 | DECREMENTAL | FULL | 50 | 49 | 48 | 47 | 46 | 45 | 44 | 43 | 42 | 41 | 40 | 39 | 38 | 37 | 36 | 35 | 34 | 33 | 32 | 31 | 30 | 29 | 28 | 27 | 26 | 25 | 24 | 23 | 22 | 21 | 20 | 19 | 18 | 17 | 16 | 15 | 14 | 13 | 12 | 11 | 10 | 9 | 8 | 7 | 6 | 5 | 4 | 3 | 2 | 1 | 0 |
7 | ALL | MIDDLE8 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | ||||||||||||||||||
8 | ALL | THIRDS4 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | ||||||||||||||||||
9 | ALL | FULL | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 | 0 |
Result |
[INFO ][2023-07-21 21:36:43,002] main() :: Using file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-07-21 21:36:43,003] handleFile() :: Handle file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-07-21 21:36:43,003] handleFile() :: Using parser for file type DOTNET [INFO ][2023-07-21 21:36:43,061] getDotNetSections() :: Offset: 7680 [INFO ][2023-07-21 21:36:43,061] handleFile() :: Using scanner from command line: avg [INFO ][2023-07-21 21:36:43,062] load() :: Loading HashCache [INFO ][2023-07-21 21:36:43,141] load() :: 59940 hashes loaded [INFO ][2023-07-21 21:36:45,581] handleFile() :: QuickCheck: 1521AD4EF052DF85.GodPotato.exe.avg.exe is detected by avg and not hash based [INFO ][2023-07-21 21:36:45,581] handleFile() :: Scanning for matches... [INFO ][2023-07-21 21:36:45,582] scanForMatchesInPe() :: Section Detection: Zero section (leave all others intact) [INFO ][2023-07-21 21:36:45,598] findDetectedSections() :: Hide: .text -> Detected: False [INFO ][2023-07-21 21:36:45,599] findDetectedSections() :: Hide: .rsrc -> Detected: True [INFO ][2023-07-21 21:36:45,599] findDetectedSections() :: Hide: .reloc -> Detected: True [INFO ][2023-07-21 21:36:45,707] findDetectedSections() :: Hide: Header -> Detected: False [INFO ][2023-07-21 21:36:45,818] findDetectedSections() :: Hide: DotNet Header -> Detected: False [INFO ][2023-07-21 21:36:45,931] findDetectedSections() :: Hide: Metadata Header -> Detected: False [INFO ][2023-07-21 21:36:45,931] findDetectedSections() :: Hide: methods -> Detected: True [INFO ][2023-07-21 21:36:46,041] findDetectedSections() :: Hide: #~ Stream Header -> Detected: False [INFO ][2023-07-21 21:36:46,153] findDetectedSections() :: Hide: #Strings Stream Header -> Detected: False [INFO ][2023-07-21 21:36:46,960] findDetectedSections() :: Hide: #US Stream Header -> Detected: True [INFO ][2023-07-21 21:36:47,761] findDetectedSections() :: Hide: #GUID Stream Header -> Detected: True [INFO ][2023-07-21 21:36:48,547] findDetectedSections() :: Hide: #Blob Stream Header -> Detected: True [INFO ][2023-07-21 21:36:48,548] findDetectedSections() :: Hide: #~ -> Detected: False [INFO ][2023-07-21 21:36:48,548] findDetectedSections() :: Hide: #Strings -> Detected: False [INFO ][2023-07-21 21:36:48,549] findDetectedSections() :: Hide: #US -> Detected: True [INFO ][2023-07-21 21:36:48,549] findDetectedSections() :: Hide: #GUID -> Detected: True [INFO ][2023-07-21 21:36:48,550] findDetectedSections() :: Hide: #Blob -> Detected: False [INFO ][2023-07-21 21:36:48,550] scanForMatchesInPe() :: 3 section(s) trigger the antivirus independantly [INFO ][2023-07-21 21:36:48,550] scanForMatchesInPe() :: section: #~ [INFO ][2023-07-21 21:36:48,550] scanForMatchesInPe() :: section: #Strings [INFO ][2023-07-21 21:36:48,550] scanForMatchesInPe() :: section: #Blob [INFO ][2023-07-21 21:36:51,812] scanForMatchesInPe() :: Launching bytes analysis on section: #~ (15244-32336) [INFO ][2023-07-21 21:36:51,812] scan() :: Reducer Start: ScanSpeed:Normal Iteration:0 MinChunkSize:2 MinMatchSize:4 [INFO ][2023-07-21 21:36:51,812] _printStatus() :: Reducing: 1 chunks done, found 0 matches (0 added) [INFO ][2023-07-21 21:36:51,815] _scanDataPart() :: Result: 15252-15260 (8 bytes) 00003B94 57 FF A2 1D 09 0E 00 00 W....... [INFO ][2023-07-21 21:36:51,815] _scanDataPart() :: Result: 15268-15277 (9 bytes) 00003BA4 01 00 00 00 61 00 00 00 42 ....a...B [INFO ][2023-07-21 21:36:52,038] _scanDataPart() :: Result: 15277-15285 (8 bytes) 00003BAD 00 00 00 F6 01 00 00 0B ........ [INFO ][2023-07-21 21:36:52,259] _scanDataPart() :: Result: 15285-15293 (8 bytes) 00003BB5 01 00 00 B0 02 00 00 03 ........ [INFO ][2023-07-21 21:36:52,259] _scanDataPart() :: Result: 15293-15297 (4b minChunk:2 X) 00003BBD 00 00 00 D3 .... [INFO ][2023-07-21 21:36:52,261] _scanDataPart() :: Result: 15644-15648 (4b minChunk:2 X) 00003D1C 10 1C 70 26 ..p& [INFO ][2023-07-21 21:36:52,261] _scanDataPart() :: Result: 15672-15677 (5b minChunk:2 X) 00003D38 06 00 6E 36 70 ..n6p [INFO ][2023-07-21 21:36:52,490] _scanDataPart() :: Result: 15677-15685 (8 bytes) 00003D3D 26 06 00 85 1D 70 26 06 &....p&. [INFO ][2023-07-21 21:36:52,717] _scanDataPart() :: Result: 15685-15694 (9 bytes) 00003D45 00 7E 1F 70 26 06 00 27 12 .~.p&..'. [INFO ][2023-07-21 21:36:52,718] _scanDataPart() :: Result: 15694-15702 (8 bytes) 00003D4E 70 26 06 00 F1 1C 70 26 p&....p& [INFO ][2023-07-21 21:36:53,629] _scanDataPart() :: Result: 15715-15719 (4b minChunk:2 X) 00003D63 00 39 2E 8C .9.. [INFO ][2023-07-21 21:36:54,523] _printStatus() :: Reducing: 44 chunks done, found 5 matches (11 added) [INFO ][2023-07-21 21:36:54,523] _scanDataPart() :: Result: 15719-15723 (4b minChunk:2 X) 00003D67 33 0A 00 2B 3..+ [INFO ][2023-07-21 21:36:54,524] _scanDataPart() :: Result: 15923-15927 (4b minChunk:2 X) 00003E33 33 06 00 AE 3... [INFO ][2023-07-21 21:36:54,526] _scanDataPart() :: Result: 16520-16524 (4b minChunk:2 X) 00004088 02 01 00 00 .... [INFO ][2023-07-21 21:36:56,086] _scanDataPart() :: Result: 16528-16532 (4b minChunk:2 X) 00004090 A5 00 C0 01 .... [INFO ][2023-07-21 21:36:56,087] _scanDataPart() :: Result: 16532-16536 (4b minChunk:2 X) 00004094 C2 00 02 01 .... [INFO ][2023-07-21 21:36:57,693] _printStatus() :: Reducing: 67 chunks done, found 8 matches (16 added) [INFO ][2023-07-21 21:36:57,693] _scanDataPart() :: Result: 16536-16540 (4b minChunk:2 X) 00004098 10 00 D2 1E .... [INFO ][2023-07-21 21:36:57,693] _scanDataPart() :: Result: 16540-16545 (5b minChunk:2 X) 0000409C 00 00 D1 00 C0 ..... [INFO ][2023-07-21 21:36:57,694] _scanDataPart() :: Result: 16545-16549 (4b minChunk:2 X) 000040A1 01 C6 00 03 .... [INFO ][2023-07-21 21:36:57,695] _scanDataPart() :: Result: 16574-16579 (5b minChunk:2 X) 000040BE D2 00 02 01 00 ..... [INFO ][2023-07-21 21:36:59,290] _scanDataPart() :: Result: 16579-16583 (4b minChunk:2 X) 000040C3 00 60 01 00 .`.. [INFO ][2023-07-21 21:36:59,290] _scanDataPart() :: Result: 16583-16587 (4b minChunk:2 X) 000040C7 00 A5 00 C7 .... [INFO ][2023-07-21 21:37:00,967] _printStatus() :: Reducing: 85 chunks done, found 9 matches (22 added) [INFO ][2023-07-21 21:37:00,967] _scanDataPart() :: Result: 16587-16591 (4b minChunk:2 X) 000040CB 01 D4 00 02 .... [INFO ][2023-07-21 21:37:00,967] _scanDataPart() :: Result: 16591-16595 (4b minChunk:2 X) 000040CF 01 00 00 7F .... [INFO ][2023-07-21 21:37:02,561] _scanDataPart() :: Result: 16595-16599 (4b minChunk:2 X) 000040D3 01 00 00 A5 .... [INFO ][2023-07-21 21:37:02,561] _scanDataPart() :: Result: 16599-16603 (4b minChunk:2 X) 000040D7 00 C7 01 D8 .... [INFO ][2023-07-21 21:37:04,203] _printStatus() :: Reducing: 92 chunks done, found 9 matches (26 added) [INFO ][2023-07-21 21:37:04,203] _scanDataPart() :: Result: 16603-16607 (4b minChunk:2 X) 000040DB 00 02 01 00 .... [INFO ][2023-07-21 21:37:04,204] _scanDataPart() :: Result: 16607-16612 (5b minChunk:2 X) 000040DF 00 BE 01 00 00 ..... [INFO ][2023-07-21 21:37:04,205] _scanDataPart() :: Result: 16612-16620 (8 bytes) 000040E4 A5 00 C7 01 DC 00 02 01 ........ [INFO ][2023-07-21 21:37:05,885] _scanDataPart() :: Result: 16628-16632 (4b minChunk:2 X) 000040F4 C7 01 E0 00 .... [INFO ][2023-07-21 21:37:05,885] _scanDataPart() :: Doubling: minChunkSize: 2 minMatchSize: 4 [INFO ][2023-07-21 21:37:05,885] _scanDataPart() :: Result: 16632-16636 (4b minChunk:4 X) 000040F8 02 01 00 00 .... [INFO ][2023-07-21 21:37:05,885] _scanDataPart() :: Result: 16636-16645 (9b minChunk:4 X) 000040FC FC 01 00 00 A5 00 C7 01 E4 ......... [INFO ][2023-07-21 21:37:05,886] _scanDataPart() :: Result: 16645-16661 (16 bytes) 00004105 00 02 01 00 00 11 02 00 00 A5 00 C7 01 E8 00 02 ................ [INFO ][2023-07-21 21:37:05,886] _scanDataPart() :: Result: 16661-16678 (17 bytes) 00004115 01 00 00 01 00 00 00 A5 00 C7 01 EC 00 02 01 00 ................ 00004125 00 . [INFO ][2023-07-21 21:37:05,887] _scanDataPart() :: Result: 16678-16695 (17 bytes) 00004126 43 00 00 00 A5 00 C7 01 F0 00 02 01 00 00 6F 00 C.............o. 00004136 00 . [INFO ][2023-07-21 21:37:05,887] _scanDataPart() :: Result: 16695-16712 (17 bytes) 00004137 00 A5 00 C7 01 F4 00 02 01 00 00 EA 00 00 00 A5 ................ 00004147 00 . [INFO ][2023-07-21 21:37:05,888] _scanDataPart() :: Result: 16712-16728 (16 bytes) 00004148 C7 01 F8 00 02 01 00 00 0F 01 00 00 A5 00 C7 01 ................ [INFO ][2023-07-21 21:37:05,889] _scanDataPart() :: Result: 16728-16745 (17 bytes) 00004158 FC 00 0A 01 10 00 7B 0A 00 00 45 00 C7 01 00 01 ......{...E..... 00004168 0D . [INFO ][2023-07-21 21:37:05,889] _scanDataPart() :: Result: 16753-16762 (9b minChunk:4 X) 00004171 00 CA 01 00 01 0D 01 10 00 ......... [INFO ][2023-07-21 21:37:05,890] _scanDataPart() :: Result: 16779-16795 (16 bytes) 0000418B 00 45 00 CE 01 00 01 0A 01 10 00 A9 04 00 00 45 .E.............E [INFO ][2023-07-21 21:37:05,890] _scanDataPart() :: Result: 16795-16812 (17 bytes) 0000419B 00 D7 01 00 01 0A 01 10 00 CC 08 00 00 45 00 DA .............E.. 000041AB 01 . [INFO ][2023-07-21 21:37:05,891] _scanDataPart() :: Result: 16812-16829 (17 bytes) 000041AC 00 01 03 01 00 00 10 1C 00 00 41 00 E2 01 00 01 ..........A..... 000041BC 05 . [INFO ][2023-07-21 21:37:05,893] _scanDataPart() :: Result: 19566-19574 (8b minChunk:4 X) 00004C6E 01 00 01 13 92 00 01 00 ........ [INFO ][2023-07-21 21:37:05,893] _scanDataPart() :: Result: 19607-19616 (9b minChunk:4 X) 00004C97 09 06 00 0F 23 23 09 06 00 ....##... [INFO ][2023-07-21 21:37:05,894] _scanDataPart() :: Result: 19700-19717 (17 bytes) 00004CF4 E0 32 1C 09 06 00 4D 38 1C 09 06 00 7C 17 3C 00 .2....M8....|.<. 00004D04 06 . [INFO ][2023-07-21 21:37:05,895] _scanDataPart() :: Result: 19717-19733 (16 bytes) 00004D05 00 85 11 23 09 06 00 68 0F 3C 00 06 00 7C 17 3C ...#...h.<...|.< [INFO ][2023-07-21 21:37:07,477] _printStatus() :: Reducing: 152 chunks done, found 15 matches (46 added) [INFO ][2023-07-21 21:37:07,477] _scanDataPart() :: Result: 22587-22595 (8b minChunk:4 X) 0000583B 00 00 00 91 18 59 2E 12 .....Y.. [INFO ][2023-07-21 21:37:07,477] _scanDataPart() :: Result: 22595-22603 (8b minChunk:4 X) 00005843 0B 92 01 00 00 00 00 03 ........ [INFO ][2023-07-21 21:37:09,087] _scanDataPart() :: Result: 22603-22611 (8b minChunk:4 X) 0000584B 00 86 18 53 2E 53 05 92 ...S.S.. [INFO ][2023-07-21 21:37:09,088] _scanDataPart() :: Result: 22611-22620 (9b minChunk:4 X) 00005853 01 00 00 00 00 03 00 C6 01 ......... [INFO ][2023-07-21 21:37:09,089] _scanDataPart() :: Result: 22654-22670 (16 bytes) 0000587E 19 54 00 00 00 00 86 08 42 19 C9 00 99 01 21 54 .T......B.....!T [INFO ][2023-07-21 21:37:09,090] _scanDataPart() :: Result: 22854-22862 (8b minChunk:4 X) 00005946 03 00 86 18 53 2E 53 05 ....S.S. [INFO ][2023-07-21 21:37:09,091] _scanDataPart() :: Result: 22904-22921 (17 bytes) 00005978 AD 01 00 00 00 00 03 00 86 18 53 2E 53 05 AE 01 ..........S.S... 00005988 00 . [INFO ][2023-07-21 21:37:09,092] _scanDataPart() :: Result: 22962-22971 (9b minChunk:4 X) 000059B2 00 00 00 00 03 00 86 18 53 ........S [INFO ][2023-07-21 21:37:09,092] _scanDataPart() :: Result: 22971-22979 (8b minChunk:4 X) 000059BB 2E 53 05 BD 01 00 00 00 .S...... [INFO ][2023-07-21 21:37:09,093] _scanDataPart() :: Result: 23021-23037 (16 bytes) 000059ED 00 03 00 86 18 53 2E 53 05 CE 01 00 00 00 00 03 .....S.S........ [INFO ][2023-07-21 21:37:09,094] _scanDataPart() :: Result: 23078-23087 (9b minChunk:4 X) 00005A26 03 00 86 18 53 2E 53 05 E1 ....S.S.. [INFO ][2023-07-21 21:37:10,686] _printStatus() :: Reducing: 189 chunks done, found 22 matches (57 added) [INFO ][2023-07-21 21:37:10,686] _scanDataPart() :: Result: 23121-23129 (8b minChunk:4 X) 00005A51 00 C6 01 66 17 80 0D F5 ...f.... [INFO ][2023-07-21 21:37:10,686] _scanDataPart() :: Result: 23129-23137 (8b minChunk:4 X) 00005A59 01 00 00 00 00 03 00 86 ........ [INFO ][2023-07-21 21:37:12,301] _scanDataPart() :: Result: 23137-23145 (8b minChunk:4 X) 00005A61 18 53 2E 53 05 F6 01 00 .S.S.... [INFO ][2023-07-21 21:37:12,302] _scanDataPart() :: Result: 23145-23154 (9b minChunk:4 X) 00005A69 00 00 00 03 00 C6 01 75 17 .......u. [INFO ][2023-07-21 21:37:12,303] _scanDataPart() :: Result: 23188-23204 (16 bytes) 00005A94 00 00 03 00 86 18 53 2E 53 05 0D 02 00 00 00 00 ......S.S....... [INFO ][2023-07-21 21:37:12,304] _scanDataPart() :: Result: 23246-23255 (9b minChunk:4 X) 00005ACE 03 00 86 18 53 2E 53 05 26 ....S.S.& [INFO ][2023-07-21 21:37:12,304] _scanDataPart() :: Doubling: minChunkSize: 4 minMatchSize: 8 [INFO ][2023-07-21 21:37:12,305] _scanDataPart() :: Result: 23288-23321 (33 bytes) 00005AF8 03 00 C6 01 66 17 80 0D 40 02 00 00 00 00 03 00 ....f...@....... 00005B08 86 18 53 2E 53 05 41 02 00 00 00 00 03 00 C6 01 ..S.S.A......... 00005B18 75 u [INFO ][2023-07-21 21:37:12,306] _scanDataPart() :: Result: 23354-23371 (17b minChunk:8 X) 00005B3A 00 00 00 00 03 00 86 18 53 2E 53 05 5E 02 00 00 ........S.S.^... 00005B4A 00 . [INFO ][2023-07-21 21:37:12,307] _scanDataPart() :: Result: 23404-23421 (17b minChunk:8 X) 00005B6C 66 17 80 0D 7C 02 00 00 00 00 03 00 86 18 53 2E f...|.........S. 00005B7C 53 S [INFO ][2023-07-21 21:37:12,307] _scanDataPart() :: Result: 23421-23438 (17b minChunk:8 X) 00005B7D 05 7D 02 00 00 00 00 03 00 C6 01 75 17 9D 0C 7F .}.........u.... 00005B8D 02 . [INFO ][2023-07-21 21:37:12,309] _scanDataPart() :: Result: 28029-28046 (17b minChunk:8 X) 00006D7D 2F E0 00 11 01 53 2E E5 00 0C 00 53 2E 06 00 29 /....S.....S...) 00006D8D 02 . [INFO ][2023-07-21 21:37:12,310] _scanDataPart() :: Result: 28046-28063 (17b minChunk:8 X) 00006D8E AD 00 09 01 0C 00 C6 10 0E 01 0C 00 49 3B 14 01 ............I;.. 00006D9E 81 . [INFO ][2023-07-21 21:37:12,311] _scanDataPart() :: Result: 28112-28129 (17b minChunk:8 X) 00006DD0 2E 2F A0 01 14 00 53 2E 06 00 29 02 21 24 E0 00 ./....S...).!$.. 00006DE0 14 . [INFO ][2023-07-21 21:37:12,312] _scanDataPart() :: Result: 28129-28145 (16b minChunk:8 X) 00006DE1 00 C6 10 0E 01 14 00 49 3B 14 01 29 01 2E 36 F2 .......I;..)..6. [INFO ][2023-07-21 21:37:12,313] _scanDataPart() :: Result: 28179-28196 (17b minChunk:8 X) 00006E13 1C 06 00 1C 00 53 2E 06 00 1C 00 49 3B 14 01 1C .....S.....I;... 00006E23 00 . [INFO ][2023-07-21 21:37:12,314] _scanDataPart() :: Result: 28196-28229 (33 bytes) 00006E24 5E 26 40 02 39 02 C1 3B 46 02 1C 00 67 26 4C 02 ^&@.9..;F...g&L. 00006E34 1C 00 34 38 7F 00 1C 00 C6 10 0E 01 39 02 C9 36 ..48........9..6 00006E44 7F . [INFO ][2023-07-21 21:37:12,315] _scanDataPart() :: Result: 28313-28330 (17b minChunk:8 X) 00006E99 03 69 01 51 3B E1 02 69 01 F5 1B DB 02 34 00 53 .i.Q;..i.....4.S 00006EA9 2E . [INFO ][2023-07-21 21:37:12,316] _scanDataPart() :: Result: 28346-28363 (17b minChunk:8 X) 00006EBA 1A 22 C9 00 34 00 C6 10 0E 01 34 00 34 38 7F 00 ."..4.....4.48.. 00006ECA 21 ! [INFO ][2023-07-21 21:37:12,316] _scanDataPart() :: Result: 28363-28379 (16b minChunk:8 X) 00006ECB 01 70 16 25 03 34 00 5E 26 40 02 21 01 EA 1F 2F .p.%.4.^&@.!.../ [INFO ][2023-07-21 21:37:12,317] _scanDataPart() :: Result: 28412-28429 (17b minChunk:8 X) 00006EFC 63 30 91 03 44 00 53 2E 06 00 A1 01 3B 1E A2 03 c0..D.S.....;... 00006F0C 39 9 [INFO ][2023-07-21 21:37:12,318] _scanDataPart() :: Result: 28429-28446 (17b minChunk:8 X) 00006F0D 02 08 2E C9 00 44 00 C6 10 AE 03 39 02 2D 23 1B .....D.....9.-#. 00006F1D 03 . [INFO ][2023-07-21 21:37:12,318] _scanDataPart() :: Result: 28446-28463 (17b minChunk:8 X) 00006F1E 39 02 23 22 B6 03 44 00 D5 1F BB 03 0C 00 6F 20 9.#"..D.......o 00006F2E C4 . [INFO ][2023-07-21 21:37:12,319] _scanDataPart() :: Result: 28463-28496 (33 bytes) 00006F2F 03 0C 00 34 38 7F 00 39 02 C2 36 CA 03 09 01 53 ...48..9..6....S 00006F3F 2E 10 00 4C 00 53 2E 06 00 4C 00 C6 10 0E 01 81 ...L.S...L...... 00006F4F 01 . [INFO ][2023-07-21 21:37:12,320] _scanDataPart() :: Result: 28496-28513 (17b minChunk:8 X) 00006F50 53 2E 06 00 39 01 53 1A 06 00 4C 00 45 2E 30 04 S...9.S...L.E.0. 00006F60 54 T [INFO ][2023-07-21 21:37:12,320] _scanDataPart() :: Result: 28513-28530 (17b minChunk:8 X) 00006F61 00 0A 38 43 04 39 01 53 1A 48 04 54 00 0E 3A E1 ..8C.9.S.H.T..:. 00006F71 02 . [INFO ][2023-07-21 21:37:12,321] _scanDataPart() :: Result: 28530-28546 (16b minChunk:8 X) 00006F72 D9 00 96 1C 06 00 4C 00 34 38 7F 00 39 02 C9 36 ......L.48..9..6 [INFO ][2023-07-21 21:37:12,322] _scanDataPart() :: Result: 28679-28696 (17b minChunk:8 X) 00007007 00 29 02 8F 3B 0D 05 D9 01 49 3B 02 05 5C 00 5E .)..;....I;..\.^ 00007017 26 & [INFO ][2023-07-21 21:37:13,245] _printStatus() :: Reducing: 276 chunks done, found 35 matches (84 added) [INFO ][2023-07-21 21:37:13,245] _scanDataPart() :: Result: 28813-28830 (17b minChunk:8 X) 0000708D 02 A9 01 8D 05 39 02 17 34 94 05 5C 00 53 2E 06 .....9..4..\.S.. 0000709D 00 . [INFO ][2023-07-21 21:37:14,166] _scanDataPart() :: Result: 28830-28847 (17b minChunk:8 X) 0000709E 5C 00 C6 10 0E 01 29 02 13 37 C0 05 F1 01 11 1A \.....)..7...... 000070AE D5 . [INFO ][2023-07-21 21:37:14,167] _scanDataPart() :: Result: 28913-28930 (17b minChunk:8 X) 000070F1 06 64 00 53 2E 06 00 D9 01 53 2E 07 05 81 02 11 .d.S.....S...... 00007101 17 . [INFO ][2023-07-21 21:37:14,167] scan() :: Reducer Result: Time:22 Chunks:283 MatchesAdded:87 MatchesFinal:37 [INFO ][2023-07-21 21:37:16,551] scanForMatchesInPe() :: Launching bytes analysis on section: #Strings (32336-47876) [INFO ][2023-07-21 21:37:16,551] scan() :: Reducer Start: ScanSpeed:Normal Iteration:1 MinChunkSize:2 MinMatchSize:4 [INFO ][2023-07-21 21:37:16,551] _printStatus() :: Reducing: 284 chunks done, found 0 matches (87 added) [INFO ][2023-07-21 21:37:16,554] _scanDataPart() :: Result: 36629-36633 (4b minChunk:2 X) 00008F15 00 41 64 64 .Add [INFO ][2023-07-21 21:37:16,554] _scanDataPart() :: Doubling: minChunkSize: 2 minMatchSize: 4 [INFO ][2023-07-21 21:37:18,407] _scanDataPart() :: Result: 39520-39528 (8b minChunk:4 X) 00009A60 54 79 70 65 00 74 79 70 Type.typ [INFO ][2023-07-21 21:37:19,324] _printStatus() :: Reducing: 307 chunks done, found 2 matches (89 added) [INFO ][2023-07-21 21:37:20,234] _scanDataPart() :: Result: 39528-39535 (7b minChunk:4 X) 00009A68 65 00 46 69 6C 65 53 e.FileS [INFO ][2023-07-21 21:37:22,074] _printStatus() :: Reducing: 312 chunks done, found 2 matches (90 added) [INFO ][2023-07-21 21:37:22,074] _scanDataPart() :: Result: 39581-39589 (8b minChunk:4 X) 00009A9D 73 65 00 52 65 61 64 4F se.ReadO [INFO ][2023-07-21 21:37:22,521] _scanDataPart() :: Result: 39589-39604 (15 bytes) 00009AA5 6E 6C 79 43 6F 6C 6C 65 63 74 69 6F 6E 42 61 nlyCollectionBa [INFO ][2023-07-21 21:37:23,432] _scanDataPart() :: Result: 39604-39612 (8b minChunk:4 X) 00009AB4 73 65 00 4D 61 69 6E 74 se.Maint [INFO ][2023-07-21 21:37:23,435] _scanDataPart() :: Result: 40484-40499 (15 bytes) 00009E24 00 54 72 79 47 65 74 56 61 6C 75 65 00 50 61 .TryGetValue.Pa [INFO ][2023-07-21 21:37:23,436] _scanDataPart() :: Result: 40636-40651 (15 bytes) 00009EBC 76 65 00 52 65 6D 6F 76 65 00 47 6F 64 50 6F ve.Remove.GodPo [INFO ][2023-07-21 21:37:23,438] _scanDataPart() :: Result: 42153-42169 (16 bytes) 0000A4A9 67 72 61 6D 00 67 65 74 5F 49 74 65 6D 00 73 65 gram.get_Item.se [INFO ][2023-07-21 21:37:23,439] _scanDataPart() :: Result: 42169-42176 (7b minChunk:4 X) 0000A4B9 74 5F 49 74 65 6D 00 t_Item. [INFO ][2023-07-21 21:37:24,341] _printStatus() :: Reducing: 355 chunks done, found 6 matches (97 added) [INFO ][2023-07-21 21:37:24,341] _scanDataPart() :: Result: 44179-44187 (8b minChunk:4 X) 0000AC93 72 00 47 65 74 45 6E 75 r.GetEnu [INFO ][2023-07-21 21:37:24,569] _scanDataPart() :: Result: 44187-44202 (15 bytes) 0000AC9B 6D 65 72 61 74 6F 72 00 2E 63 74 6F 72 00 2E merator..ctor.. [INFO ][2023-07-21 21:37:25,944] _scanDataPart() :: Result: 46676-46691 (15 bytes) 0000B654 6F 6E 65 6E 74 00 67 65 74 5F 43 75 72 72 65 onent.get_Curre [INFO ][2023-07-21 21:37:26,854] _printStatus() :: Reducing: 366 chunks done, found 8 matches (100 added) [INFO ][2023-07-21 21:37:27,760] _scanDataPart() :: Result: 46691-46698 (7b minChunk:4 X) 0000B663 6E 74 00 47 65 74 43 nt.GetC [INFO ][2023-07-21 21:37:29,586] _printStatus() :: Reducing: 370 chunks done, found 8 matches (101 added) [INFO ][2023-07-21 21:37:29,815] _scanDataPart() :: Result: 46721-46736 (15 bytes) 0000B681 6E 74 00 67 65 74 5F 43 6F 75 6E 74 00 50 72 nt.get_Count.Pr [INFO ][2023-07-21 21:37:29,817] _scanDataPart() :: Result: 47192-47207 (15 bytes) 0000B858 75 74 70 75 74 00 4D 6F 76 65 4E 65 78 74 00 utput.MoveNext. [INFO ][2023-07-21 21:37:29,818] _scanDataPart() :: Result: 47511-47526 (15 bytes) 0000B997 79 00 54 6F 41 72 72 61 79 00 67 65 74 5F 49 y.ToArray.get_I [INFO ][2023-07-21 21:37:29,818] scan() :: Reducer Result: Time:13 Chunks:383 MatchesAdded:104 MatchesFinal:11 [INFO ][2023-07-21 21:37:32,205] scanForMatchesInPe() :: Launching bytes analysis on section: #Blob (53596-57712) [INFO ][2023-07-21 21:37:32,205] scan() :: Reducer Start: ScanSpeed:Normal Iteration:2 MinChunkSize:2 MinMatchSize:4 [INFO ][2023-07-21 21:37:32,206] _printStatus() :: Reducing: 384 chunks done, found 0 matches (104 added) [INFO ][2023-07-21 21:37:35,354] _printStatus() :: Reducing: 391 chunks done, found 0 matches (104 added) [INFO ][2023-07-21 21:37:38,575] _printStatus() :: Reducing: 393 chunks done, found 0 matches (104 added) [INFO ][2023-07-21 21:37:40,193] _scanDataPart() :: Result: 53596-53600 (4b minChunk:2 X) 0000D15C 00 04 20 01 .. . [INFO ][2023-07-21 21:37:40,193] _scanDataPart() :: Result: 53600-53604 (4b minChunk:2 X) 0000D160 01 08 03 20 ... [INFO ][2023-07-21 21:37:41,832] _printStatus() :: Reducing: 397 chunks done, found 1 matches (106 added) [INFO ][2023-07-21 21:37:41,832] _scanDataPart() :: Result: 53604-53608 (4b minChunk:2 X) 0000D164 00 01 05 20 ... [INFO ][2023-07-21 21:37:41,832] _scanDataPart() :: Result: 53608-53612 (4b minChunk:2 X) 0000D168 01 01 11 11 .... [INFO ][2023-07-21 21:37:43,443] _scanDataPart() :: Doubling: minChunkSize: 2 minMatchSize: 4 [INFO ][2023-07-21 21:37:43,443] _scanDataPart() :: Result: 53612-53620 (8b minChunk:4 X) 0000D16C 04 20 01 01 0E 04 20 01 . .... . [INFO ][2023-07-21 21:37:43,443] _scanDataPart() :: Result: 53620-53628 (8b minChunk:4 X) 0000D174 01 02 07 20 02 01 11 51 ... ...Q [INFO ][2023-07-21 21:37:45,039] _printStatus() :: Reducing: 403 chunks done, found 1 matches (110 added) [INFO ][2023-07-21 21:37:46,658] _scanDataPart() :: Result: 53628-53636 (8b minChunk:4 X) 0000D17C 11 55 05 20 01 01 11 71 .U. ...q [INFO ][2023-07-21 21:37:46,658] _scanDataPart() :: Result: 53636-53644 (8b minChunk:4 X) 0000D184 05 20 01 01 11 7D 06 20 . ...}. [INFO ][2023-07-21 21:37:48,252] _printStatus() :: Reducing: 407 chunks done, found 1 matches (112 added) [INFO ][2023-07-21 21:37:48,252] _scanDataPart() :: Result: 53644-53652 (8b minChunk:4 X) 0000D18C 01 01 11 80 C9 06 07 04 ........ [INFO ][2023-07-21 21:37:48,252] _scanDataPart() :: Result: 53652-53660 (8b minChunk:4 X) 0000D194 02 02 02 02 02 06 18 04 ........ [INFO ][2023-07-21 21:37:51,446] _printStatus() :: Reducing: 411 chunks done, found 1 matches (114 added) [INFO ][2023-07-21 21:37:53,063] _scanDataPart() :: Result: 53660-53668 (8b minChunk:4 X) 0000D19C 00 01 18 08 03 07 01 02 ........ [INFO ][2023-07-21 21:37:53,064] _scanDataPart() :: Result: 53668-53676 (8b minChunk:4 X) 0000D1A4 05 07 03 02 02 02 05 00 ........ [INFO ][2023-07-21 21:37:54,744] _printStatus() :: Reducing: 415 chunks done, found 1 matches (116 added) [INFO ][2023-07-21 21:37:54,744] _scanDataPart() :: Result: 53676-53684 (8b minChunk:4 X) 0000D1AC 02 02 18 18 03 07 01 09 ........ [INFO ][2023-07-21 21:37:54,745] _scanDataPart() :: Result: 53684-53692 (8b minChunk:4 X) 0000D1B4 03 20 00 0A 05 07 02 18 . ...... [INFO ][2023-07-21 21:37:57,963] _printStatus() :: Reducing: 419 chunks done, found 1 matches (118 added) [INFO ][2023-07-21 21:37:57,963] _scanDataPart() :: Result: 53692-53700 (8b minChunk:4 X) 0000D1BC 11 70 04 20 01 01 0A 08 .p. .... [INFO ][2023-07-21 21:37:57,963] _scanDataPart() :: Result: 53700-53708 (8b minChunk:4 X) 0000D1C4 00 01 12 80 B5 11 81 19 ........ [INFO ][2023-07-21 21:37:59,590] _scanDataPart() :: Result: 53708-53716 (8b minChunk:4 X) 0000D1CC 06 00 01 08 12 80 B5 07 ........ [INFO ][2023-07-21 21:37:59,590] _scanDataPart() :: Result: 53716-53724 (8b minChunk:4 X) 0000D1D4 00 02 1C 18 12 80 B5 03 ........ [INFO ][2023-07-21 21:38:01,246] _printStatus() :: Reducing: 425 chunks done, found 1 matches (122 added) [INFO ][2023-07-21 21:38:04,515] _printStatus() :: Reducing: 427 chunks done, found 1 matches (122 added) [INFO ][2023-07-21 21:38:06,149] _scanDataPart() :: Result: 53724-53732 (8b minChunk:4 X) 0000D1DC 20 00 08 04 00 01 18 0E ....... [INFO ][2023-07-21 21:38:06,149] _scanDataPart() :: Result: 53732-53740 (8b minChunk:4 X) 0000D1E4 04 00 01 01 18 04 07 02 ........ [INFO ][2023-07-21 21:38:07,759] _printStatus() :: Reducing: 431 chunks done, found 1 matches (124 added) [INFO ][2023-07-21 21:38:07,759] _scanDataPart() :: Result: 53740-53748 (8b minChunk:4 X) 0000D1EC 02 0E 02 06 0E 05 00 02 ........ [INFO ][2023-07-21 21:38:07,759] _scanDataPart() :: Result: 53748-53756 (8b minChunk:4 X) 0000D1F4 0E 18 08 04 07 01 12 6C .......l [INFO ][2023-07-21 21:38:11,013] _printStatus() :: Reducing: 435 chunks done, found 1 matches (126 added) [INFO ][2023-07-21 21:38:11,013] _scanDataPart() :: Result: 53756-53764 (8b minChunk:4 X) 0000D1FC 15 07 0D 12 6C 12 80 89 ....l... [INFO ][2023-07-21 21:38:11,013] _scanDataPart() :: Result: 53764-53772 (8b minChunk:4 X) 0000D204 09 11 3C 0E 02 12 6C 02 ..<...l. [INFO ][2023-07-21 21:38:12,635] _scanDataPart() :: Result: 53772-53780 (8b minChunk:4 X) 0000D20C 18 02 02 02 12 65 09 00 .....e.. [INFO ][2023-07-21 21:38:12,635] _scanDataPart() :: Result: 53780-53788 (8b minChunk:4 X) 0000D214 02 02 12 80 89 12 80 89 ........ [INFO ][2023-07-21 21:38:14,241] _printStatus() :: Reducing: 441 chunks done, found 1 matches (130 added) [INFO ][2023-07-21 21:38:17,543] _printStatus() :: Reducing: 443 chunks done, found 1 matches (130 added) [INFO ][2023-07-21 21:38:17,543] _scanDataPart() :: Result: 53788-53796 (8b minChunk:4 X) 0000D21C 08 20 01 12 81 25 12 80 . ...%.. [INFO ][2023-07-21 21:38:17,543] _scanDataPart() :: Result: 53796-53804 (8b minChunk:4 X) 0000D224 B5 03 20 00 0E 06 00 02 .. ..... [INFO ][2023-07-21 21:38:19,160] _scanDataPart() :: Result: 53804-53812 (8b minChunk:4 X) 0000D22C 0E 0E 1D 0E 0B 07 05 09 ........ [INFO ][2023-07-21 21:38:19,160] _scanDataPart() :: Result: 53812-53820 (8b minChunk:4 X) 0000D234 18 12 80 89 02 12 80 89 ........ [INFO ][2023-07-21 21:38:20,749] _printStatus() :: Reducing: 449 chunks done, found 1 matches (134 added) [INFO ][2023-07-21 21:38:22,339] _scanDataPart() :: Result: 53820-53828 (8b minChunk:4 X) 0000D23C 04 00 01 18 18 04 20 01 ...... . [INFO ][2023-07-21 21:38:22,339] _scanDataPart() :: Result: 53828-53836 (8b minChunk:4 X) 0000D244 01 18 17 07 0B 15 12 80 ........ [INFO ][2023-07-21 21:38:23,973] _printStatus() :: Reducing: 453 chunks done, found 1 matches (136 added) [INFO ][2023-07-21 21:38:23,973] _scanDataPart() :: Result: 53836-53844 (8b minChunk:4 X) 0000D24C 8D 01 0E 18 12 80 89 09 ........ [INFO ][2023-07-21 21:38:23,973] _scanDataPart() :: Result: 53844-53853 (9b minChunk:4 X) 0000D254 02 08 08 08 12 80 85 02 1D ......... [INFO ][2023-07-21 21:38:25,602] _scanDataPart() :: Result: 54946-54954 (8b minChunk:4 X) 0000D6A2 02 06 00 03 0E 0E 0E 0E ........ [INFO ][2023-07-21 21:38:25,602] _scanDataPart() :: Result: 54954-54962 (8b minChunk:4 X) 0000D6AA 04 20 00 11 69 05 20 02 . ..i. . [INFO ][2023-07-21 21:38:27,209] _printStatus() :: Reducing: 465 chunks done, found 2 matches (140 added) [INFO ][2023-07-21 21:38:27,209] _scanDataPart() :: Result: 54962-54970 (8b minChunk:4 X) 0000D6B2 01 1C 18 06 20 01 01 12 .... ... [INFO ][2023-07-21 21:38:27,209] _scanDataPart() :: Result: 54970-54978 (8b minChunk:4 X) 0000D6BA 81 75 06 00 01 18 12 80 .u...... [INFO ][2023-07-21 21:38:27,211] _scanDataPart() :: Result: 55927-55943 (16 bytes) 0000DA77 16 02 06 09 03 06 11 08 02 06 08 02 06 02 03 06 ................ [INFO ][2023-07-21 21:38:27,211] scan() :: Reducer Result: Time:55 Chunks:474 MatchesAdded:143 MatchesFinal:3 [INFO ][2023-07-21 21:38:27,211] handleFile() :: Result: 51 matches [INFO ][2023-07-21 21:38:27,211] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-07-21 21:38:27,332] save() :: Saving HashCache (60107) [INFO ][2023-07-21 21:38:27,403] verifyFile() :: Perform verification of matches [INFO ][2023-07-21 21:38:27,403] runVerifications() :: Verify 51 matches [INFO ][2023-07-21 21:38:31,301] runVerifications() :: Verification run: 0 MIDDLE8 ISOLATED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:38:35,992] runVerifications() :: Verification run: 1 THIRDS4 ISOLATED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:38:41,006] runVerifications() :: Verification run: 2 FULL ISOLATED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:38:46,864] runVerifications() :: Verification run: 3 FULLB ISOLATED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.DETECTED result: ScanResult.DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:38:50,405] runVerifications() :: Verification run: 4 MIDDLE8 INCREMENTAL result: ScanResult.NOT_SCANNED Idx: 1 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 3 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 7 result: ScanResult.NOT_DETECTED Idx: 8 result: ScanResult.NOT_DETECTED Idx: 9 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 11 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 14 result: ScanResult.NOT_DETECTED Idx: 15 result: ScanResult.NOT_DETECTED Idx: 16 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 18 result: ScanResult.NOT_DETECTED Idx: 19 result: ScanResult.NOT_DETECTED Idx: 20 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 22 result: ScanResult.NOT_DETECTED Idx: 23 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 25 result: ScanResult.NOT_DETECTED Idx: 26 result: ScanResult.NOT_DETECTED Idx: 27 result: ScanResult.NOT_DETECTED Idx: 28 result: ScanResult.NOT_DETECTED Idx: 29 result: ScanResult.NOT_DETECTED Idx: 30 result: ScanResult.NOT_DETECTED Idx: 31 result: ScanResult.NOT_DETECTED Idx: 32 result: ScanResult.NOT_DETECTED Idx: 33 result: ScanResult.NOT_DETECTED Idx: 34 result: ScanResult.NOT_DETECTED Idx: 35 result: ScanResult.NOT_DETECTED Idx: 36 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 39 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 42 result: ScanResult.NOT_DETECTED Idx: 43 result: ScanResult.NOT_DETECTED Idx: 44 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 48 result: ScanResult.NOT_DETECTED Idx: 49 result: ScanResult.NOT_DETECTED Idx: 50 result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:38:55,810] runVerifications() :: Verification run: 5 FULL INCREMENTAL Idx: 0 result: ScanResult.NOT_DETECTED Idx: 1 result: ScanResult.NOT_DETECTED Idx: 2 result: ScanResult.NOT_DETECTED Idx: 3 result: ScanResult.NOT_DETECTED Idx: 4 result: ScanResult.NOT_DETECTED Idx: 5 result: ScanResult.NOT_DETECTED Idx: 6 result: ScanResult.NOT_DETECTED Idx: 7 result: ScanResult.NOT_DETECTED Idx: 8 result: ScanResult.NOT_DETECTED Idx: 9 result: ScanResult.NOT_DETECTED Idx: 10 result: ScanResult.NOT_DETECTED Idx: 11 result: ScanResult.NOT_DETECTED Idx: 12 result: ScanResult.NOT_DETECTED Idx: 13 result: ScanResult.NOT_DETECTED Idx: 14 result: ScanResult.NOT_DETECTED Idx: 15 result: ScanResult.NOT_DETECTED Idx: 16 result: ScanResult.NOT_DETECTED Idx: 17 result: ScanResult.NOT_DETECTED Idx: 18 result: ScanResult.NOT_DETECTED Idx: 19 result: ScanResult.NOT_DETECTED Idx: 20 result: ScanResult.NOT_DETECTED Idx: 21 result: ScanResult.NOT_DETECTED Idx: 22 result: ScanResult.NOT_DETECTED Idx: 23 result: ScanResult.NOT_DETECTED Idx: 24 result: ScanResult.NOT_DETECTED Idx: 25 result: ScanResult.NOT_DETECTED Idx: 26 result: ScanResult.NOT_DETECTED Idx: 27 result: ScanResult.NOT_DETECTED Idx: 28 result: ScanResult.NOT_DETECTED Idx: 29 result: ScanResult.NOT_DETECTED Idx: 30 result: ScanResult.NOT_DETECTED Idx: 31 result: ScanResult.NOT_DETECTED Idx: 32 result: ScanResult.NOT_DETECTED Idx: 33 result: ScanResult.NOT_DETECTED Idx: 34 result: ScanResult.NOT_DETECTED Idx: 35 result: ScanResult.NOT_DETECTED Idx: 36 result: ScanResult.NOT_DETECTED Idx: 37 result: ScanResult.NOT_DETECTED Idx: 38 result: ScanResult.NOT_DETECTED Idx: 39 result: ScanResult.NOT_DETECTED Idx: 40 result: ScanResult.NOT_DETECTED Idx: 41 result: ScanResult.NOT_DETECTED Idx: 42 result: ScanResult.NOT_DETECTED Idx: 43 result: ScanResult.NOT_DETECTED Idx: 44 result: ScanResult.NOT_DETECTED Idx: 45 result: ScanResult.NOT_DETECTED Idx: 46 result: ScanResult.NOT_DETECTED Idx: 47 result: ScanResult.NOT_DETECTED Idx: 48 result: ScanResult.NOT_DETECTED Idx: 49 result: ScanResult.NOT_DETECTED Idx: 50 result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:39:01,066] runVerifications() :: Verification run: 6 FULL DECREMENTAL Idx: 50 result: ScanResult.NOT_DETECTED Idx: 49 result: ScanResult.NOT_DETECTED Idx: 48 result: ScanResult.NOT_DETECTED Idx: 47 result: ScanResult.NOT_DETECTED Idx: 46 result: ScanResult.NOT_DETECTED Idx: 45 result: ScanResult.NOT_DETECTED Idx: 44 result: ScanResult.NOT_DETECTED Idx: 43 result: ScanResult.NOT_DETECTED Idx: 42 result: ScanResult.NOT_DETECTED Idx: 41 result: ScanResult.NOT_DETECTED Idx: 40 result: ScanResult.NOT_DETECTED Idx: 39 result: ScanResult.NOT_DETECTED Idx: 38 result: ScanResult.NOT_DETECTED Idx: 37 result: ScanResult.NOT_DETECTED Idx: 36 result: ScanResult.NOT_DETECTED Idx: 35 result: ScanResult.NOT_DETECTED Idx: 34 result: ScanResult.NOT_DETECTED Idx: 33 result: ScanResult.NOT_DETECTED Idx: 32 result: ScanResult.NOT_DETECTED Idx: 31 result: ScanResult.NOT_DETECTED Idx: 30 result: ScanResult.NOT_DETECTED Idx: 29 result: ScanResult.NOT_DETECTED Idx: 28 result: ScanResult.NOT_DETECTED Idx: 27 result: ScanResult.NOT_DETECTED Idx: 26 result: ScanResult.NOT_DETECTED Idx: 25 result: ScanResult.NOT_DETECTED Idx: 24 result: ScanResult.NOT_DETECTED Idx: 23 result: ScanResult.NOT_DETECTED Idx: 22 result: ScanResult.NOT_DETECTED Idx: 21 result: ScanResult.NOT_DETECTED Idx: 20 result: ScanResult.NOT_DETECTED Idx: 19 result: ScanResult.NOT_DETECTED Idx: 18 result: ScanResult.NOT_DETECTED Idx: 17 result: ScanResult.NOT_DETECTED Idx: 16 result: ScanResult.NOT_DETECTED Idx: 15 result: ScanResult.NOT_DETECTED Idx: 14 result: ScanResult.NOT_DETECTED Idx: 13 result: ScanResult.NOT_DETECTED Idx: 12 result: ScanResult.NOT_DETECTED Idx: 11 result: ScanResult.NOT_DETECTED Idx: 10 result: ScanResult.NOT_DETECTED Idx: 9 result: ScanResult.NOT_DETECTED Idx: 8 result: ScanResult.NOT_DETECTED Idx: 7 result: ScanResult.NOT_DETECTED Idx: 6 result: ScanResult.NOT_DETECTED Idx: 5 result: ScanResult.NOT_DETECTED Idx: 4 result: ScanResult.NOT_DETECTED Idx: 3 result: ScanResult.NOT_DETECTED Idx: 2 result: ScanResult.NOT_DETECTED Idx: 1 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:39:01,067] runVerifications() :: Verification run: 7 MIDDLE8 ALL Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED [INFO ][2023-07-21 21:39:01,186] runVerifications() :: Verification run: 8 THIRDS4 ALL Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED Idx: 0 result: ScanResult.NOT_DETECTED result: ScanResult.NOT_SCANNED [INFO ][2023-07-21 21:39:01,188] runVerifications() :: Verification run: 9 FULL ALL Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED Idx: 0 result: ScanResult.NOT_DETECTED [INFO ][2023-07-21 21:39:01,188] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-07-21 21:39:01,189] augmentFile() :: Perform augmentation of matches [INFO ][2023-07-21 21:39:01,232] getDotNetSections() :: Offset: 7680 [INFO ][2023-07-21 21:39:01,459] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-07-21 21:39:01,460] outflankFile() :: Attempt to outflank the file [INFO ][2023-07-21 21:39:01,460] outflankDotnet() :: Outflank failed with attempted 0 patches [INFO ][2023-07-21 21:39:01,460] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-07-21 21:39:01,460] save() :: Saving HashCache (60281) [INFO ][2023-08-04 18:21:56,609] main() :: Using file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-08-04 18:21:56,609] handleFile() :: Handle file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-08-04 18:21:56,610] handleFile() :: Using parser for file type DOTNET [INFO ][2023-08-04 18:21:56,666] getDotNetSections() :: Offset: 7680 [WARNING ][2023-08-04 18:21:56,667] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-08-04 18:21:56,667] load() :: Loading HashCache [INFO ][2023-08-04 18:21:56,761] load() :: 77569 hashes loaded [INFO ][2023-08-04 18:21:56,762] save() :: Saving HashCache (77569) [INFO ][2023-08-04 18:21:56,838] augmentFile() :: Perform augmentation of matches [INFO ][2023-08-04 18:21:56,900] getDotNetSections() :: Offset: 7680 [INFO ][2023-08-04 18:21:57,517] init() :: DotnetData entries: 2422 [INFO ][2023-08-04 18:21:57,522] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-08-04 18:21:57,523] save() :: Saving HashCache (77569) [INFO ][2023-08-06 16:46:59,319] main() :: Using file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-08-06 16:46:59,319] handleFile() :: Handle file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-08-06 16:46:59,320] handleFile() :: Using parser for file type DOTNET [INFO ][2023-08-06 16:46:59,377] getDotNetSections() :: Offset: 7680 [WARNING ][2023-08-06 16:46:59,378] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-08-06 16:46:59,378] load() :: Loading HashCache [INFO ][2023-08-06 16:46:59,472] load() :: 77569 hashes loaded [INFO ][2023-08-06 16:46:59,472] save() :: Saving HashCache (77569) [INFO ][2023-08-06 16:46:59,549] augmentFile() :: Perform augmentation of matches [INFO ][2023-08-06 16:46:59,610] getDotNetSections() :: Offset: 7680 [INFO ][2023-08-06 16:47:00,226] init() :: DotnetData entries: 2422 [INFO ][2023-08-06 16:47:00,231] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-08-06 16:47:00,232] save() :: Saving HashCache (77569) [INFO ][2023-08-06 17:21:11,533] main() :: Using file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-08-06 17:21:11,533] handleFile() :: Handle file: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-08-06 17:21:11,534] handleFile() :: Using parser for file type DOTNET [INFO ][2023-08-06 17:21:11,592] getDotNetSections() :: Offset: 7680 [WARNING ][2023-08-06 17:21:11,593] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-08-06 17:21:11,593] load() :: Loading HashCache [INFO ][2023-08-06 17:21:11,686] load() :: 77569 hashes loaded [INFO ][2023-08-06 17:21:11,686] save() :: Saving HashCache (77569) [INFO ][2023-08-06 17:21:11,760] augmentFile() :: Perform augmentation of matches [INFO ][2023-08-06 17:21:11,820] getDotNetSections() :: Offset: 7680 [INFO ][2023-08-06 17:21:12,434] init() :: DotnetData entries: 2422 [INFO ][2023-08-06 17:21:12,439] saveToFile() :: Saving results to: app/upload/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-08-06 17:21:12,440] save() :: Saving HashCache (77569) [INFO ][2023-09-01 05:26:34,634] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-01 05:26:34,634] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-01 05:26:34,643] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-01 05:26:34,699] getDotNetSections() :: Offset: 7680 [WARNING ][2023-09-01 05:26:34,700] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-01 05:26:34,700] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-01 05:26:34,701] load() :: Loading HashCache [INFO ][2023-09-01 05:26:34,818] load() :: 85943 hashes loaded [INFO ][2023-09-01 05:26:34,818] save() :: Saving HashCache (85943) [INFO ][2023-09-01 05:26:34,902] save() :: Saving HashCache (85943) [INFO ][2023-09-24 19:20:49,754] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-24 19:20:49,754] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-24 19:20:49,763] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-24 19:20:49,763] parseFile() :: FilePe: Parse File [INFO ][2023-09-24 19:20:49,767] parsePeSections() :: FilePe: Parse PE Sections [INFO ][2023-09-24 19:20:49,767] parsePeRegions() :: FilePe: Parse PE Regions [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 0 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 3 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 4 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 7 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 8 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 9 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 10 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 11 has address 0, skipping [WARNING ][2023-09-24 19:20:49,767] parsePeRegions() :: Data Directory Section 13 has address 0, skipping [WARNING ][2023-09-24 19:20:49,768] parsePeRegions() :: Data Directory Section 15 has address 0, skipping [INFO ][2023-09-24 19:20:49,768] parseDotNetSections() :: FilePe: Parse DotNet Sections [INFO ][2023-09-24 19:20:49,818] parseDotNetRegions() :: FilePe: Parse DotNet Regions [WARNING ][2023-09-24 19:20:49,861] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-24 19:20:49,861] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-24 19:20:49,862] load() :: Loading HashCache [INFO ][2023-09-24 19:20:50,009] load() :: 101712 hashes loaded [INFO ][2023-09-24 19:20:50,009] save() :: Saving HashCache (101712) [INFO ][2023-09-24 19:20:50,104] augmentFile() :: Perform augmentation of matches [INFO ][2023-09-24 19:20:50,699] init() :: DotnetData entries: 2422 [INFO ][2023-09-24 19:20:50,704] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-24 19:20:50,705] save() :: Saving HashCache (101712) [INFO ][2023-09-25 18:14:07,297] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-25 18:14:07,298] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-25 18:14:07,298] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-25 18:14:07,298] parseFile() :: FilePe: Parse File [INFO ][2023-09-25 18:14:07,302] parsePeSections() :: FilePe: Parse PE Sections [INFO ][2023-09-25 18:14:07,302] parsePeRegions() :: FilePe: Parse PE Regions [WARNING ][2023-09-25 18:14:07,302] parsePeRegions() :: Data Directory Section 0 has address 0, skipping [WARNING ][2023-09-25 18:14:07,302] parsePeRegions() :: Data Directory Section 3 has address 0, skipping [WARNING ][2023-09-25 18:14:07,302] parsePeRegions() :: Data Directory Section 4 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 7 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 8 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 9 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 10 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 11 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 13 has address 0, skipping [WARNING ][2023-09-25 18:14:07,303] parsePeRegions() :: Data Directory Section 15 has address 0, skipping [INFO ][2023-09-25 18:14:07,303] parseDotNetSections() :: FilePe: Parse DotNet Sections [INFO ][2023-09-25 18:14:07,353] parseDotNetRegions() :: FilePe: Parse DotNet Regions [WARNING ][2023-09-25 18:14:07,395] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-25 18:14:07,395] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-25 18:14:07,396] load() :: Loading HashCache [INFO ][2023-09-25 18:14:07,523] load() :: 101712 hashes loaded [INFO ][2023-09-25 18:14:07,523] save() :: Saving HashCache (101712) [INFO ][2023-09-25 18:14:07,620] augmentFile() :: Perform augmentation of matches [INFO ][2023-09-25 18:14:08,234] init() :: DotnetData entries: 2422 [INFO ][2023-09-25 18:14:08,239] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-25 18:14:08,240] save() :: Saving HashCache (101712) [INFO ][2023-09-25 18:21:09,072] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-25 18:21:09,072] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-25 18:21:09,073] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-25 18:21:09,073] parseFile() :: FilePe: Parse File [INFO ][2023-09-25 18:21:09,076] parsePeSections() :: FilePe: Parse PE Sections [INFO ][2023-09-25 18:21:09,077] parsePeRegions() :: FilePe: Parse PE Regions [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 0 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 3 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 4 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 7 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 8 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 9 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 10 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 11 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 13 has address 0, skipping [WARNING ][2023-09-25 18:21:09,077] parsePeRegions() :: Data Directory Section 15 has address 0, skipping [INFO ][2023-09-25 18:21:09,077] parseDotNetSections() :: FilePe: Parse DotNet Sections [INFO ][2023-09-25 18:21:09,126] parseDotNetRegions() :: FilePe: Parse DotNet Regions [WARNING ][2023-09-25 18:21:09,167] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-25 18:21:09,168] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-25 18:21:09,169] load() :: Loading HashCache [INFO ][2023-09-25 18:21:09,294] load() :: 101712 hashes loaded [INFO ][2023-09-25 18:21:09,294] save() :: Saving HashCache (101712) [INFO ][2023-09-25 18:21:09,389] augmentFile() :: Perform augmentation of matches [INFO ][2023-09-25 18:21:10,011] init() :: DotnetData entries: 2422 [INFO ][2023-09-25 18:21:10,016] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-25 18:21:10,017] save() :: Saving HashCache (101712) [INFO ][2023-09-29 10:06:45,337] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-29 10:06:45,337] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-29 10:06:45,338] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-29 10:06:45,338] parseFile() :: FilePe: Parse File [INFO ][2023-09-29 10:06:45,342] parsePeSections() :: FilePe: Parse PE Sections [INFO ][2023-09-29 10:06:45,342] parsePeRegions() :: FilePe: Parse PE Regions [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 0 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 3 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 4 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 7 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 8 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 9 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 10 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 11 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 13 has address 0, skipping [WARNING ][2023-09-29 10:06:45,342] parsePeRegions() :: Data Directory Section 15 has address 0, skipping [INFO ][2023-09-29 10:06:45,342] parseDotNetSections() :: FilePe: Parse DotNet Sections [WARNING ][2023-09-29 10:06:45,393] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-29 10:06:45,394] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-29 10:06:45,395] load() :: Loading HashCache [INFO ][2023-09-29 10:06:45,522] load() :: 102070 hashes loaded [INFO ][2023-09-29 10:06:45,522] save() :: Saving HashCache (102070) [INFO ][2023-09-29 10:06:45,619] augmentFile() :: Perform augmentation of matches [INFO ][2023-09-29 10:06:46,239] init() :: DotnetData entries: 2422 [INFO ][2023-09-29 10:06:46,244] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-29 10:06:46,245] save() :: Saving HashCache (102070) [INFO ][2023-09-29 12:11:18,677] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-29 12:11:18,677] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-29 12:11:18,678] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-29 12:11:18,678] parseFile() :: FilePe: Parse File [INFO ][2023-09-29 12:11:18,682] parsePeSections() :: FilePe: Parse PE Sections [INFO ][2023-09-29 12:11:18,682] parsePeRegions() :: FilePe: Parse PE Regions [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 0 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 3 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 4 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 7 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 8 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 9 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 10 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 11 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 13 has address 0, skipping [WARNING ][2023-09-29 12:11:18,682] parsePeRegions() :: Data Directory Section 15 has address 0, skipping [INFO ][2023-09-29 12:11:18,682] parseDotNetSections() :: FilePe: Parse DotNet Sections [WARNING ][2023-09-29 12:11:18,733] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-29 12:11:18,733] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-29 12:11:18,734] load() :: Loading HashCache [INFO ][2023-09-29 12:11:18,863] load() :: 102070 hashes loaded [INFO ][2023-09-29 12:11:18,863] save() :: Saving HashCache (102070) [INFO ][2023-09-29 12:11:18,960] augmentFile() :: Perform augmentation of matches [INFO ][2023-09-29 12:11:19,583] init() :: DotnetData entries: 2422 [INFO ][2023-09-29 12:11:19,587] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-29 12:11:19,588] save() :: Saving HashCache (102070) [INFO ][2023-09-30 10:32:13,347] main() :: Using file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-30 10:32:13,347] handleFile() :: Handle file: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe [INFO ][2023-09-30 10:32:13,348] handleFile() :: Using parser for file type DOTNET [INFO ][2023-09-30 10:32:13,348] parseFile() :: FilePe: Parse File [INFO ][2023-09-30 10:32:13,352] parsePeSections() :: FilePe: Parse PE Sections [INFO ][2023-09-30 10:32:13,352] parsePeRegions() :: FilePe: Parse PE Regions [WARNING ][2023-09-30 10:32:13,352] parsePeRegions() :: Data Directory Section 0 has address 0, skipping [WARNING ][2023-09-30 10:32:13,352] parsePeRegions() :: Data Directory Section 3 has address 0, skipping [WARNING ][2023-09-30 10:32:13,352] parsePeRegions() :: Data Directory Section 4 has address 0, skipping [WARNING ][2023-09-30 10:32:13,352] parsePeRegions() :: Data Directory Section 7 has address 0, skipping [WARNING ][2023-09-30 10:32:13,352] parsePeRegions() :: Data Directory Section 8 has address 0, skipping [WARNING ][2023-09-30 10:32:13,352] parsePeRegions() :: Data Directory Section 9 has address 0, skipping [WARNING ][2023-09-30 10:32:13,353] parsePeRegions() :: Data Directory Section 10 has address 0, skipping [WARNING ][2023-09-30 10:32:13,353] parsePeRegions() :: Data Directory Section 11 has address 0, skipping [WARNING ][2023-09-30 10:32:13,353] parsePeRegions() :: Data Directory Section 13 has address 0, skipping [WARNING ][2023-09-30 10:32:13,353] parsePeRegions() :: Data Directory Section 15 has address 0, skipping [INFO ][2023-09-30 10:32:13,353] parseDotNetSections() :: FilePe: Parse DotNet Sections [WARNING ][2023-09-30 10:32:13,404] handleFile() :: Using scanner as defined in outcome: avg [INFO ][2023-09-30 10:32:13,405] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-30 10:32:13,406] load() :: Loading HashCache [INFO ][2023-09-30 10:32:13,535] load() :: 102072 hashes loaded [INFO ][2023-09-30 10:32:13,536] save() :: Saving HashCache (102072) [INFO ][2023-09-30 10:32:13,637] augmentFile() :: Perform augmentation of matches [INFO ][2023-09-30 10:32:14,263] init() :: DotnetData entries: 2422 [INFO ][2023-09-30 10:32:14,268] saveToFile() :: Saving results to: app/examples/1521AD4EF052DF85.GodPotato.exe.avg.exe.outcome [INFO ][2023-09-30 10:32:14,269] save() :: Saving HashCache (102072)