| Architecture |
IMAGE_FILE_MACHINE_AMD64
|
|---|---|
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| Compilation Date | 2026-Mar-16 17:42:37 |
| Detected languages |
English - United States
Russian - Russia |
| Debug artifacts |
C:\Users\Administrator\Desktop\Medusa\3.1.0\x64\Release\LOTUS.GPU.pdb
|
| Info | Matching compiler(s): | MASM/TASM - sig1(h) |
| Suspicious | Strings found in the binary may indicate undesirable behavior: |
Miscellaneous malware strings:
|
| Info | Cryptographic algorithms detected in the binary: |
Uses constants related to SHA256
Uses constants related to SHA512 Uses constants related to base58 Uses known Mersenne Twister constants Microsoft's Cryptography API |
| Suspicious | The PE is possibly packed. |
Unusual section name found: .nv_fatb
Unusual section name found: .nvFatBi |
| Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
| Malicious | VirusTotal score: 15/71 (Scanned on 2026-03-20 17:13:11) |
ALYac:
Gen:Variant.Lazy.708522
APEX: Malicious Arcabit: Trojan.Lazy.DACFAA BitDefender: Gen:Variant.Lazy.708522 Bkav: W64.AIDetectMalware CTX: exe.unknown.lazy CrowdStrike: win/malicious_confidence_70% (D) Elastic: malicious (high confidence) Emsisoft: Gen:Variant.Lazy.708522 (B) GData: Gen:Variant.Lazy.708522 Kaspersky: not-a-virus:HEUR:AdWare.Win32.Adposhel.gen MicroWorld-eScan: Gen:Variant.Lazy.708522 Sophos: Generic ML PUA (PUA) Trapmine: suspicious.low.ml.score VIPRE: Gen:Variant.Lazy.708522 |
| e_magic | MZ |
|---|---|
| e_cblp | 0x90 |
| e_cp | 0x3 |
| e_crlc | 0 |
| e_cparhdr | 0x4 |
| e_minalloc | 0 |
| e_maxalloc | 0xffff |
| e_ss | 0 |
| e_sp | 0xb8 |
| e_csum | 0 |
| e_ip | 0 |
| e_cs | 0 |
| e_ovno | 0 |
| e_oemid | 0 |
| e_oeminfo | 0 |
| e_lfanew | 0x120 |
| Signature | PE |
|---|---|
| Machine |
IMAGE_FILE_MACHINE_AMD64
|
| NumberofSections | 8 |
| TimeDateStamp | 2026-Mar-16 17:42:37 |
| PointerToSymbolTable | 0 |
| NumberOfSymbols | 0 |
| SizeOfOptionalHeader | 0xf0 |
| Characteristics |
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE
|
| Magic | PE32+ |
|---|---|
| LinkerVersion | 14.0 |
| SizeOfCode | 0x64c00 |
| SizeOfInitializedData | 0x80ea00 |
| SizeOfUninitializedData | 0 |
| AddressOfEntryPoint | 0x00000000000606A4 (Section: .text) |
| BaseOfCode | 0x1000 |
| ImageBase | 0x140000000 |
| SectionAlignment | 0x1000 |
| FileAlignment | 0x200 |
| OperatingSystemVersion | 6.0 |
| ImageVersion | 0.0 |
| SubsystemVersion | 6.0 |
| Win32VersionValue | 0 |
| SizeOfImage | 0x879000 |
| SizeOfHeaders | 0x400 |
| Checksum | 0 |
| Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_CUI
|
| DllCharacteristics |
IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
|
| SizeofStackReserve | 0x100000 |
| SizeofStackCommit | 0x1000 |
| SizeofHeapReserve | 0x100000 |
| SizeofHeapCommit | 0x1000 |
| LoaderFlags | 0 |
| NumberOfRvaAndSizes | 16 |
| KERNEL32.dll |
WakeAllConditionVariable
SleepConditionVariableSRW RtlCaptureContext InitializeSListHead GetSystemTimeAsFileTime GetCurrentThreadId GetCurrentProcessId QueryPerformanceCounter SetThreadAffinityMask GetStdHandle WriteConsoleA SetThreadPriority MultiByteToWideChar SetConsoleTitleW SetConsoleCtrlHandler WriteFile SetFilePointer Sleep GetConsoleMode CreateFileA CloseHandle GetConsoleWindow SetConsoleOutputCP InitOnceExecuteOnce FreeLibrary GetProcAddress LoadLibraryExA InitializeCriticalSection EnterCriticalSection LeaveCriticalSection TerminateProcess RtlLookupFunctionEntry RtlVirtualUnwind UnhandledExceptionFilter AcquireSRWLockExclusive SetConsoleMode ReleaseSRWLockExclusive IsProcessorFeaturePresent IsDebuggerPresent GetModuleHandleW SetUnhandledExceptionFilter GetCurrentProcess |
|---|---|
| USER32.dll |
MessageBoxA
ShowWindow |
| ADVAPI32.dll |
CryptGenRandom
CryptReleaseContext CryptAcquireContextW |
| MSVCP140.dll |
?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ
?uncaught_exception@std@@YA_NXZ ?_Xbad_alloc@std@@YAXXZ ?_Xinvalid_argument@std@@YAXPEBD@Z ?_Xout_of_range@std@@YAXPEBD@Z ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A ?_Fiopen@std@@YAPEAU_iobuf@@PEBDHH@Z ?id@?$ctype@D@std@@2V0locale@2@A ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z ??0_Lockit@std@@QEAA@H@Z ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ ?pubsetbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAPEAV12@PEAD_J@Z ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ ?good@ios_base@std@@QEBA_NXZ ??Bios_base@std@@QEBA_NXZ ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z ?always_noconv@codecvt_base@std@@QEBA_NXZ ??Bid@locale@std@@QEAA_KXZ ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z _Cnd_signal _Cnd_init_in_situ ?_Throw_Cpp_error@std@@YAXH@Z _Cnd_timedwait _Mtx_destroy_in_situ _Mtx_lock _Mtx_init_in_situ _Cnd_do_broadcast_at_thread_exit _Thrd_id _Xtime_get_ticks _Thrd_join _Mtx_unlock _Cnd_broadcast _Cnd_destroy_in_situ ?_Xbad_function_call@std@@YAXXZ ?setprecision@std@@YA?AU?$_Smanip@_J@1@_J@Z ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@N@Z ?cin@std@@3V?$basic_istream@DU?$char_traits@D@std@@@1@A ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@M@Z ??5?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@AEAH@Z ?ignore@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z ??7ios_base@std@@QEBA_NXZ ?_Random_device@std@@YAIXZ ??1_Lockit@std@@QEAA@XZ _Query_perf_frequency _Query_perf_counter ?_Xlength_error@std@@YAXPEBD@Z ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A |
| WININET.dll |
InternetOpenUrlA
InternetOpenA InternetCloseHandle InternetReadFile InternetCheckConnectionA |
| VCOMP140.DLL |
_vcomp_for_static_end
_vcomp_enter_critsect _vcomp_barrier _vcomp_leave_critsect _vcomp_for_dynamic_init _vcomp_for_dynamic_next omp_get_thread_num _vcomp_fork _vcomp_for_static_simple_init |
| bcrypt.dll |
BCryptGenRandom
|
| VCRUNTIME140.dll |
memset
__C_specific_handler __current_exception __current_exception_context memmove memcpy memcmp _CxxThrowException __std_exception_destroy __std_exception_copy strstr __std_terminate memchr |
| VCRUNTIME140_1.dll |
__CxxFrameHandler4
|
| api-ms-win-crt-runtime-l1-1-0.dll |
exit
system terminate _beginthreadex _invalid_parameter_noinfo_noreturn _register_thread_local_exe_atexit_callback _configure_narrow_argv _initialize_narrow_environment _initialize_onexit_table _register_onexit_function _crt_atexit _cexit _seh_filter_exe _set_app_type _c_exit _get_initial_narrow_environment _initterm _initterm_e _exit __p___argv __p___argc _errno |
| api-ms-win-crt-string-l1-1-0.dll |
strncpy
strncmp strnlen |
| api-ms-win-crt-math-l1-1-0.dll |
_hypotf
ceilf __setusermatherr |
| api-ms-win-crt-stdio-l1-1-0.dll |
_fseeki64
fsetpos ungetc __p__commode fread _get_stream_buffer_pointers __stdio_common_vsprintf_s fgetpos __stdio_common_vsprintf _set_fmode fwrite fgetc fclose fflush fputc __stdio_common_vfprintf __acrt_iob_func setvbuf |
| api-ms-win-crt-heap-l1-1-0.dll |
malloc
_set_new_mode _callnewh free realloc |
| api-ms-win-crt-convert-l1-1-0.dll |
strtoull
strtod atoi strtol strtoll strtof |
| api-ms-win-crt-filesystem-l1-1-0.dll |
remove
_unlock_file _lock_file rename |
| api-ms-win-crt-time-l1-1-0.dll |
_localtime64_s
strftime _time64 |
| api-ms-win-crt-utility-l1-1-0.dll |
rand
srand |
| api-ms-win-crt-locale-l1-1-0.dll |
_configthreadlocale
|
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-16 17:42:37 |
| Version | 0.0 |
| SizeofData | 94 |
| AddressOfRawData | 0x982d8 |
| PointerToRawData | 0x972d8 |
| Referenced File | C:\Users\Administrator\Desktop\Medusa\3.1.0\x64\Release\LOTUS.GPU.pdb |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-16 17:42:37 |
| Version | 0.0 |
| SizeofData | 20 |
| AddressOfRawData | 0x98338 |
| PointerToRawData | 0x97338 |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-16 17:42:37 |
| Version | 0.0 |
| SizeofData | 980 |
| AddressOfRawData | 0x9834c |
| PointerToRawData | 0x9734c |
| Characteristics |
0
|
|---|---|
| TimeDateStamp | 2026-Mar-16 17:42:37 |
| Version | 0.0 |
| SizeofData | 0 |
| AddressOfRawData | 0 |
| PointerToRawData | 0 |
| StartAddressOfRawData | 0x140098740 |
|---|---|
| EndAddressOfRawData | 0x140099af4 |
| AddressOfIndex | 0x1400f2268 |
| AddressOfCallbacks | 0x1400668c8 |
| SizeOfZeroFill | 0 |
| Characteristics |
IMAGE_SCN_ALIGN_16BYTES
|
| Callbacks | (EMPTY) |
| Size | 0x140 |
|---|---|
| TimeDateStamp | 1970-Jan-01 00:00:00 |
| Version | 0.0 |
| GlobalFlagsClear | (EMPTY) |
| GlobalFlagsSet | (EMPTY) |
| CriticalSectionDefaultTimeout | 0 |
| DeCommitFreeBlockThreshold | 0 |
| DeCommitTotalFreeThreshold | 0 |
| LockPrefixTable | 0 |
| MaximumAllocationSize | 0 |
| VirtualMemoryThreshold | 0 |
| ProcessAffinityMask | 0 |
| ProcessHeapFlags | (EMPTY) |
| CSDVersion | 0 |
| Reserved1 | 0 |
| EditList | 0 |
| SecurityCookie | 0x1400a3080 |
| XOR Key | 0x90f65879 |
|---|---|
| Unmarked objects | 0 |
| Imports (VS2008 SP1 build 30729) | 20 |
| C objects (33218) | 10 |
| ASM objects (33218) | 5 |
| C++ objects (33218) | 36 |
| Imports (33218) | 8 |
| Imports (30795) | 10 |
| C objects (VS2015 build 23026) | 11 |
| Imports (34123) | 3 |
| Total imports | 343 |
| C++ objects (33523) | 1 |
| C++ objects (LTCG) (33523) | 50 |
| Resource objects (33523) | 1 |
| 151 | 1 |
| Linker (33523) | 1 |
No comments yet.