Static | ZeroBOX

PE Compile Time

2021-07-28 00:30:44

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000b0ee4 0x000b1000 5.65800635343
.rsrc 0x000b4000 0x00000350 0x00000400 2.7516787019
.reloc 0x000b6000 0x0000000c 0x00000200 0.101910425663

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x000b4058 0x000002f8 LANG_ENGLISH SUBLANG_ENGLISH_UK data

Imports

Library mscoree.dll:
0x402000 _CorExeMain

!This program cannot be run in DOS mode.
`.rsrc
@.reloc
L&&jl66Z~??A
Oh44\Q
sb11S*
uB!!c
D""fT**~;
;d22Vt::N
J%%o\..r8
gg}V++
jL&&Zl66A~??
Sb11?*
tX,,.4
RRMv;;a
MMUf33
PPDx<<
cB!!0
~~Gz==
fD""~T**
Vd22Nt::
xxoJ%%r\..$8
tt!>
ppB|>>
aa_j55
UUxP((z
&jL&6Zl6?A~?
~=Gz=d
"fD"*~T*
2Vd2:Nt:
x%oJ%.r\.
t!>K
a5_j5W
=&&jL66Zl??A~
g99KrJJ
==Gzdd
""fD**~T
22Vd::Nt
$$lH\\
77Ynmm
%%oJ..r\
!>KK
55_jWW
[T:$6.
[.:$6g
j_FbT~
h4,8$@_
2\tHlWB
PQAeS~
~4[C)v
Y_b`*^
PK00.
&*.r+P
Y_d
".<+>
\.!++
:.A+k
$ 0;U
-&+E(0
Y_c
Y_c
UYZs
S.u8\
_h`h}l
Y_dh}l
_h`h}l
_b}B
_b}J
X_b}e
c_X<
c_X0
X],$
jZXi}h
UUUU_
d UUUU_`
3333_
d 3333_`
lZ[YZ*
.b+`rl7
b.:+@rJ8
Y_b`}
+_c
Y_b`
Y_b`
d`}?
_b_,'
d`}r
d`}r
v4.0.30319
#Strings
2H#6AU
2H,6aU
2H<7AW
2H<7aW
2Hp8!Y
2H0:!h
2HF:Ah
2HW:ah
2H{<!k
X>_>e>
?8@A@U@
B&C:C?CbC
C,D1DGDoD
F"F[FjF
G!G6GTGZGeG
H<H`HpH
I'I<ITImI
J%J1JZJpJxJ
O!O.O>OIOPOiOsO{O
Q#Q4Q?QLQ^QdQlQ|Q
Q#RiRpR
R"SQStS
THTNTeT
U"U0U@UtU~U
W&W8WIWYWrW
XX_XeXmX
YOZcZoZ{Z
[?[T[Y[`[
\ \)\-\2\8\?\\\e\q\v\|\
]']<]V]j]q]v]
^/^C^M^U^w^
_/_@_U_\_d_i_o_u_
_'`:`A`N`W`b`h`w`
a-aAaYa
b6bDbjbxb
c!c6c<c`cjcpc
d"d2d6dGdLdUdidxd}d
e)e>eQehepeve
f!f&f2fGfafef{f
f g+g9gDgPgYg_gdgjgngvg
h+h=h\h
i iAiQiwi
i#j1jHjOjqjwj
k$kEkMkbkikokukV
?Y?i?q?x?
@-@/A6AkA
LELoL.M
W@XHX,YAY?Z
WAVE_FORMAT_SIPROLAB_ACELP4800
WAVE_FORMAT_DF_GSM610
Gsm610
WAVE_FORMAT_VOXWARE_AC10
WAVE_FORMAT_CREATIVE_FASTSPEECH10
AudioFileAf10
ControlResCr10
WAVE_FORMAT_VOXWARE_AC20
WAVE_FORMAT_VOXWARE_TQ40
WAVE_FORMAT_VOXWARE_TQ60
<>9__20_0
<>9__0_0
<>9__1_0
<>9__12_0
<>9__2_0
<>9__13_0
<>9__23_0
<>9__3_0
<>9__14_0
<>9__4_0
<>9__15_0
<>9__16_0
<>9__96_0
<>9__17_0
<>9__97_0
<>9__18_0
<>9__19_0
<>9__99_0
get_Scan0
HMACSHA1
WAVE_FORMAT_MSAUDIO1
<>9__3_1
<>9__4_1
Nullable`1
IEnumerable`1
Predicate`1
Queue`1
Stack`1
Action`1
ICollection`1
ReadOnlyCollection`1
Comparison`1
EventHandler`1
IEqualityComparer`1
IEnumerator`1
IList`1
EchoSpeechCorporation1
Vorbis1
Prosody1612
WAVE_FORMAT_VOXWARE_VR12
Microsoft.Win32
ToUInt32
ReadInt32
WriteInt32
ToInt32
WAVE_FORMAT_MVI_MVI2
WAVE_FORMAT_CS2
<>9__23_2
<>9__4_2
Func`2
KeyValuePair`2
IDictionary`2
DolbyAc2
Vorbis2
WAVE_FORMAT_MSG723
WAVE_FORMAT_MEDIASONIC_G723
WAVE_FORMAT_DIGITAL_G723
WAVE_FORMAT_VIVO_G723
WAVE_FORMAT_LUCENT_G723
WAVE_FORMAT_ESST_AC3
WAVE_FORMAT_ECHOSC3
WAVE_FORMAT_SIPROLAB_ACELP8V3
MpegLayer3
Vorbis3
WAVE_FORMAT_SBC24
WAVE_FORMAT_MSRT24
WAVE_FORMAT_VOXWARE_RT24
WAVE_FORMAT_RT24
UInt64
ToInt64
WAVE_FORMAT_VOXWARE_AC16
ToUInt16
ToInt16
WAVE_FORMAT_DF_G726
AudioFileAf36
<>9__4_6
WAVE_FORMAT_VOXWARE_VR18
WAVE_FORMAT_VOXWARE_AC8
get_UTF8
WAVE_FORMAT_CREATIVE_FASTSPEECH8
WAVE_FORMAT_SIPROLAB_G729
WAVE_FORMAT_VOXWARE_RT29
WmaVoice9
<Module>
WAVE_FORMAT_SIPROLAB_G729A
WAVE_FORMAT_G729A
mciSendStringA
WAVE_FORMAT_PHILIPS_LPCBB
MPEG_HEAAC
NOKIA_MPEG_ADTS_AAC
VODAFONE_MPEG_ADTS_AAC
NOKIA_MPEG_RAW_AAC
VODAFONE_MPEG_RAW_AAC
WAVE_FORMAT_PAC
WAVE_FORMAT_CANOPUS_ATRAC
WAVE_FORMAT_OLISBC
CreateCompatibleDC
CreateDC
DeleteDC
WAVE_FORMAT_XEBEC
WAVE_FORMAT_LH_CODEC
WAVE_FORMAT_QDESIGN_MUSIC
WAVE_FORMAT_TPC
WAVE_FORMAT_ILINK_VC
SonarC
System.Drawing.Drawing2D
MF_SOURCE_READERF_NATIVEMEDIATYPECHANGED
MF_SOURCE_READERF_CURRENTMEDIATYPECHANGED
WAVE_FORMAT_PACKED
WAVE_FORMAT_VOXWARE_BYTE_ALIGNED
MF_SOURCE_READERF_ALLEFFECTSREMOVED
GetTypeFromCLSID
get_GUID
PlatformID
WAVE_FORMAT_FM_TOWNS_SND
WAVE_FORMAT_SOFTSOUND
WAVE_FORMAT_QUALCOMM_PUREVOICE
FILETIME
WAVE_FORMAT_VOXWARE
WAVE_FORMAT_QUALCOMM_HALFRATE
WAVE_FORMAT_ONLIVE
WAVE_FORMAT_DOLBY_AC3_SPDIF
get_ASCII
WAVE_FORMAT_UNISYS_NAP_16K
WAVE_FORMAT_QUARTERDECK
MF_SOURCE_READERF_STREAMTICK
WAVE_FORMAT_ROCKWELL_DIGITALK
WAVE_FORMAT_MALDEN_PHONYTALK
WAVE_FORMAT_BTV_DIGITAL
MFCreateSourceReaderFromURL
MF_SOURCE_READERF_ENDOFSTREAM
MF_SOURCE_READERF_NEWSTREAM
WAVE_FORMAT_G726ADPCM
WAVE_FORMAT_CS_IMAADPCM
WAVE_FORMAT_OLIADPCM
WAVE_FORMAT_NMS_VBXADPCM
WAVE_FORMAT_G721_ADPCM
WAVE_FORMAT_G722_ADPCM
WAVE_FORMAT_G726_ADPCM
WAVE_FORMAT_SANYO_LD_ADPCM
WAVE_FORMAT_CREATIVE_ADPCM
WAVE_FORMAT_ZYXEL_ADPCM
WAVE_FORMAT_ROCKWELL_ADPCM
WAVE_FORMAT_UNISYS_NAP_ADPCM
WAVE_FORMAT_UHER_ADPCM
WAVE_FORMAT_RHETOREX_ADPCM
WAVE_FORMAT_VME_VMPCM
WAVE_FORMAT_ESPCM
WAVE_FORMAT_TUBGSM
WAVE_FORMAT_OLIGSM
WAVE_FORMAT_DVM
WAVE_FORMAT_VIVO_SIREN
WAVE_FORMAT_SIPROLAB_KELVIN
System.IO
WAVE_FORMAT_ISIAUDIO
Vorbis1P
Vorbis2P
Vorbis3P
WAVE_FORMAT_OLICELP
WAVE_FORMAT_G728_CELP
WAVE_FORMAT_IPI_RPELP
W8UmExV4RnP
ThrowExceptionForHR
MF_SOURCE_READERF_ERROR
WAVE_FORMAT_OLIOPR
MPEG_LOAS
WAVE_FORMAT_NORRIS
WAVE_FORMAT_PROSODY_8KBPS
WAVE_FORMAT_SOUNDSPACE_MUSICOMPRESS
WAVE_FORMAT_CIRRUS
WAVE_FORMAT_IRAT
WAVE_FORMAT_SIPROLAB_ACEPLNET
WAVE_FORMAT_DEVELOPMENT
WAVE_FORMAT_RAW_SPORT
WAVE_FORMAT_UNISYS_NAP_ALAW
WAVE_FORMAT_UNISYS_NAP_ULAW
WAVE_FORMAT_VOXWARE_RT29HW
WAVE_FORMAT_SONY_SCX
WAVE_FORMAT_IPI_HSX
WAVE_FORMAT_DSAT_DISPLAY
value__
boAjg9a
ProtectedData
MoreData
BitmapData
PropertyData
mscorlib
set_Verb
RawAac
ReleaseHdc
GetHdc
CUCodec
get_IsPublic
System.Collections.Generic
Microsoft.VisualBasic
get_IsStatic
WaveSync
SpeakAsync
WndProc
ControlResVqlpc
FromFileTimeUtc
get_LastWriteTimeUtc
SetLastWriteTimeUtc
SetCreationTimeUtc
SetLastAccessTimeUtc
get_Id
get_ManagedThreadId
BadDeviceId
GetWindowThreadProcessId
GetProcessById
get_CanRead
OpenRead
SuspendThread
ResumeThread
OpenThread
ProcessThread
get_CurrentThread
add_Load
SHA1Managed
add_LocationChanged
Interlocked
NotEnabled
AcmCancelled
IsDefined
WaveHeaderUnprepared
AcmHeaderUnprepared
get_Elapsed
get_IsAllocated
AlreadyAllocated
IsUnrestricted
get_HasExited
NotSupported
System.Collections.Specialized
NewGuid
GetField
TrimEnd
Append
get_Kind
DateTimeKind
SpecifyKind
get_Second
get_Millisecond
GetUpperBound
GetLowerBound
RegistryValueNotFound
RegistryKeyNotFound
FromHwnd
set_Method
InvokeMethod
GetMethod
Clipboard
IbmCvsd
DigiStd
NetworkInterface
Replace
IsNullOrWhiteSpace
IsWhiteSpace
CreateInstance
CompileAssemblyFromSource
get_Stride
GetHashCode
get_ErrorCode
set_Mode
FileMode
PaddingMode
ImageLockMode
CompressionMode
set_InterpolationMode
CipherMode
RwMode
get_Unicode
get_BigEndianUnicode
get_OEMCodePage
get_CodePage
FromImage
DrawImage
BindToStorage
get_Message
PostMessage
RegisterWindowMessage
AddRange
CompareExchange
EndInvoke
BeginInvoke
ICloneable
GetEnvironmentVariable
IComparable
IEnumerable
IDisposable
set_GenerateExecutable
IsWindowVisible
Extensible
AcmNotPossible
ToDouble
GCHandle
get_Handle
InvalidHandle
RuntimeFieldHandle
SafeHandle
GetModuleHandle
RuntimeTypeHandle
ReleaseHandle
CloseHandle
GetTypeFromHandle
AssignHandle
DangerousGetHandle
get_SafeWaitHandle
EventWaitHandle
Rectangle
Single
DownloadFile
IsVolatile
IsInRole
WindowsBuiltInRole
Console
get_MainWindowTitle
set_BorderStyle
set_FlatStyle
FontStyle
set_WindowStyle
ProcessWindowStyle
get_Name
set_Name
get_DeviceName
QueryFullProcessImageName
set_FileName
GetRandomFileName
GetFileName
get_MachineName
get_FullName
get_UserName
GetClassName
get_ProcessName
GetName
GetProcessesByName
MkParseDisplayName
GetDisplayName
AssemblyName
GetDirectoryName
StackFrame
OleCreatePropertyFrame
AntexAdpcme
ToFileTime
DateTime
GetLastWriteTime
SetLastWriteTime
IsDaylightSavingTime
ToLocalTime
ToUniversalTime
GetCreationTime
GetLastAccessTime
get_AddressPreferredLifetime
WaitOne
get_Line
ReadLine
MixerInvalidLine
WriteLine
Combine
LocalMachine
set_Multiline
Escape
DataProtectionScope
MFCreateMediaType
get_IsGenericType
get_FieldType
get_NetworkInterfaceType
ComInterfaceType
ChangeType
GCHandleType
get_MimeType
ValueType
get_DeclaringType
SecurityProtocolType
GetType
SocketType
GetElementType
set_ContentType
get_PropertyType
FileShare
Compare
System.Core
PtrToStructure
get_InstalledUICulture
get_InvariantCulture
get_CurrentCulture
set_CurrentCulture
Capture
MethodBase
ReadOnlyCollectionBase
ButtonBase
TextBoxBase
get_OrdinalIgnoreCase
BadRegistryDatabase
Release
HttpWebResponse
GetResponse
waveInClose
waveOutClose
Dispose
TryParse
StrReverse
Create
MulticastDelegate
Deflate
get_ThreadState
GetKeyboardState
SetApartmentState
GetKeyState
Delete
get_White
get_CanWrite
OpenWrite
waveOutWrite
ThreadStaticAttribute
DispIdAttribute
STAThreadAttribute
GuidAttribute
UnverifiableCodeAttribute
DebuggableAttribute
ComVisibleAttribute
InterfaceTypeAttribute
TargetFrameworkAttribute
GetCustomAttribute
SuppressIldasmAttribute
ExtensionAttribute
AssemblyInformationalVersionAttribute
DescriptionAttribute
IgnoreDataMemberAttribute
DefaultMemberAttribute
FlagsAttribute
CompilationRelaxationsAttribute
CLSCompliantAttribute
RuntimeCompatibilityAttribute
SuppressUnmanagedCodeSecurityAttribute
set_UseShellExecute
get_Minute
ReadByte
WriteByte
ToByte
SetByte
Dequeue
Enqueue
get_Value
set_Value
MixerInvalidValue
DeleteValue
get_HasValue
TryGetValue
SetValue
RegistryHive
KeepAlive
get_IsPrimitive
Remove
get_Size
set_Size
set_BlockSize
get_TotalSize
set_MinimumSize
get_PrimaryMonitorSize
GetPixelFormatSize
set_KeySize
SuppressFinalize
Resize
SizeOf
LastIndexOf
HandleRef
WindowsMediaAudioSpdif
InvalidFlag
SecurityPermissionFlag
get_Jpeg
System.Threading
set_Padding
UTF8Encoding
set_StandardErrorEncoding
GetEncoding
set_StandardOutputEncoding
System.Drawing.Imaging
System.Runtime.Versioning
get_IsWarning
FromBase64String
ToBase64String
EscapeDataString
DownloadString
get_VersionString
ToString
GetString
Substring
add_FormClosing
OpenExisting
System.Drawing
WaveStillPlaying
GetWindowLong
SetWindowLong
ShowDialog
get_Msg
ForEach
System.Speech
DspGroupTrueSpeech
IsMatch
Stopwatch
get_Hash
ComputeHash
get_ExecutablePath
GetFullPath
GetTempPath
GetFolderPath
get_Width
get_Length
set_Length
GetLength
SetLength
set_ContentLength
get_TextLength
EndsWith
StartsWith
get_Month
PtrToStringUni
PtrToStringAnsi
AsyncCallback
NoDriverCallback
WaitCallback
SendOrPostCallback
add_Click
TransformFinalBlock
TransformBlock
get_CanSeek
IllllIIlIl
AllocHGlobal
FreeHGlobal
DigiReal
Marshal
Decimal
get_Ordinal
WindowsMediaAudioProfessional
System.Security.Principal
WindowsPrincipal
op_GreaterThanOrEqual
op_LessThanOrEqual
set_Cancel
System.Collections.ObjectModel
System.ComponentModel
Parallel
FindAll
RemoveAll
ole32.dll
gdi32.dll
Kernel32.dll
kernel32.dll
user32.dll
oleaut32.dll
mfreadwrite.dll
ntdll.dll
winmm.dll
mfplat.dll
set_SecurityProtocol
ThreadPool
MixerInvalidControl
CreateControl
get_IBeam
GetManifestResourceStream
FileStream
get_BaseStream
GetResponseStream
FromStream
GZipStream
GetRequestStream
MemoryStream
get_LParam
get_WParam
get_Param
G723Adpcm
YamahaAdpcm
ImaAdpcm
SierraAdpcm
MediaspaceAdpcm
DigiAdpcm
DialogicOkiAdpcm
DviAdpcm
MediaVisionAdpcm
FreeCoTaskMem
get_Item
set_Item
QueueUserWorkItem
get_Is64BitOperatingSystem
SymmetricAlgorithm
HashAlgorithm
Random
get_Bottom
ICryptoTransform
get_Platform
VarEnum
get_IsEnum
Boolean
LesserThan
op_GreaterThan
op_LessThan
TimeSpan
get_VirtualScreen
get_PrimaryScreen
waveInOpen
waveOutOpen
AppDomain
get_CurrentDomain
SeekOrigin
get_Column
set_ShowIcon
MessageBoxIcon
DestroyIcon
CopyIcon
GetFileNameWithoutExtension
get_OSVersion
get_Version
System.IO.Compression
SecurityPermission
ConsoleApplication
WinFormsApplication
get_Location
set_Location
set_IncludeDebugInformation
System.Net.NetworkInformation
SystemInformation
UnicastIPAddressInformation
GatewayIPAddressInformation
GetProcessWindowStation
System.Globalization
System.Runtime.Serialization
Action
op_Subtraction
System.Reflection
ICollection
PropertyDataCollection
ProcessThreadCollection
NameValueCollection
StringCollection
MatchCollection
ControlCollection
UnicastIPAddressInformationCollection
GatewayIPAddressInformationCollection
GroupCollection
WebHeaderCollection
CompilerErrorCollection
ManagementObjectCollection
KeyCollection
op_Addition
GetGenericTypeDefinition
get_Position
set_Position
set_StartPosition
FormStartPosition
SearchOption
COMException
IOException
InvalidDataException
add_UnhandledException
ObjectDisposedException
NotImplementedException
NotSupportedException
FileNotFoundException
ArgumentOutOfRangeException
IndexOutOfRangeException
PathTooLongException
ExternalException
ArgumentNullException
ApplicationException
TargetInvocationException
InvalidOperationException
GetHRForException
UnauthorizedAccessException
FormatException
ArgumentException
InvalidCastException
OverflowException
get_Description
get_WaitReason
ThreadWaitReason
StringComparison
SwapMouseButton
MessageBoxDefaultButton
Unknown
SendTo
CompareTo
LesserThanOrEqualTo
GreaterThanOrEqualTo
NotEqualTo
CopyTo
GetMessageExtraInfo
ImageCodecInfo
GetGUIThreadInfo
FieldInfo
MethodInfo
FileInfo
CultureInfo
DriveInfo
FileSystemInfo
GetIconInfo
SerializationInfo
MemberInfo
ParameterInfo
GetCursorInfo
ConstructorInfo
SystemParametersInfo
set_StartInfo
ProcessStartInfo
get_TextInfo
GetWindowInfo
DirectoryInfo
PropertyInfo
WindowsMediaAudio
MsnAudio
ToBitmap
FromHbitmap
GetHbitmap
get_Bmp
get_Top
waveInStop
SetThreadDesktop
CloseDesktop
CreateDesktop
OpenDesktop
Microsoft.CSharp
MFStartup
System.Linq
set_ShowInTaskbar
get_Year
PropVariantClear
DirectorySeparatorChar
get_KeyChar
get_ErrorNumber
BadErrorNumber
waveInPrepareHeader
waveOutPrepareHeader
waveInUnprepareHeader
waveOutUnprepareHeader
StreamReader
TextReader
CSharpCodeProvider
CodeDomProvider
IFormatProvider
StringBuilder
SpecialFolder
Encoder
waveInAddBuffer
ServicePointManager
ManagementObjectSearcher
IMoniker
IEnumMoniker
FormClosingEventHandler
UnhandledExceptionEventHandler
KeyPressEventHandler
System.CodeDom.Compiler
set_CookieContainer
ToUpper
StringComparer
CurrentUser
InvalidParameter
EncoderParameter
StreamWriter
TextWriter
BinaryWriter
TryEnter
GetDelegateForFunctionPointer
ToPointer
BitConverter
NoDriver
ToLower
SpeechSynthesizer
set_Anchor
get_Major
set_ForegroundColor
ConsoleColor
ResetColor
get_Minor
RegistryReadError
UnspecifiedError
get_StandardError
set_RedirectStandardError
RegistryDeleteError
RegistryWriteError
MemoryAllocationError
NoError
CompilerError
set_Cursor
IEnumerator
StringEnumerator
ManagementObjectEnumerator
GetEnumerator
Activator
.cctor
GetConstructor
Monitor
CreateEncryptor
GetAncestor
StructureToPtr
UIntPtr
WriteIntPtr
get_Hour
InvalidAlias
Graphics
System.Diagnostics
get_Threads
GetFields
AddSeconds
get_TotalSeconds
get_Bounds
GetMethods
GetAllNetworkInterfaces
EnumDisplayDevices
System.Runtime.InteropServices
System.Runtime.CompilerServices
FormatterServices
get_EmbeddedResources
DebuggingModes
Matches
get_ReferencedAssemblies
GetDirectories
GetIPProperties
get_Properties
IPInterfaceProperties
GetProperties
ExpandEnvironmentVariables
Microsoft.Win32.SafeHandles
GetFiles
EnableVisualStyles
NumberStyles
AnchorStyles
set_Lines
System.Runtime.InteropServices.ComTypes
GetTypes
GetProcesses
get_UnicastAddresses
get_GatewayAddresses
ImageAttributes
FileAttributes
GetCustomAttributes
GetAttributes
SetAttributes
Rfc2898DeriveBytes
ReadAllBytes
GetBytes
NextBytes
get_Values
GetValues
GetDrives
BindingFlags
SocketFlags
Strings
EnumDisplaySettings
FormClosingEventArgs
CancelEventArgs
UnhandledExceptionEventArgs
KeyPressEventArgs
System.Speech.Synthesis
System.Threading.Tasks
Equals
get_Controls
System.Windows.Forms
get_AllScreens
Contains
System.Text.RegularExpressions
System.Security.Permissions
System.Collections
InvokeMethodOptions
get_CompilerOptions
set_CompilerOptions
StringSplitOptions
RegexOptions
MessageBoxOptions
MessageBoxButtons
SetCursorPos
SetWindowPos
waveInGetDevCaps
EnumDesktops
get_Groups
set_ScrollBars
get_Chars
get_Headers
GetImageEncoders
RuntimeHelpers
GetMethodParameters
EncoderParameters
CompilerParameters
GetParameters
get_Errors
get_HasErrors
Cursors
FromHours
ManagementClass
FileAccess
get_Success
CreateProcess
GetCurrentProcess
WindowsMediaAudioLosseless
add_KeyPress
IPAddress
get_Address
GetProcAddress
System.Net.Sockets
LockBits
UnlockBits
CompilerResults
set_Arguments
GetGenericArguments
Exists
get_OperationalStatus
waveInGetNumDevs
EnumDesktopWindows
get_Keys
SendKeys
RemoveAt
Concat
TextDataFormat
WaveBadFormat
AppendFormat
ImageFormat
get_PixelFormat
IeeeFloat
Subtract
ParseExact
GetWindowRect
AddrOfPinnedObject
GetUninitializedObject
ManagementBaseObject
DeleteObject
ReleaseComObject
get_ExceptionObject
BindToObject
SelectObject
ManagementObject
Select
Collect
Unprotect
Distinct
System.Net
get_Target
Socket
ScrollToCaret
waveInReset
waveOutReset
get_Left
get_Right
get_Height
SendWait
op_Explicit
IsDigit
GraphicsUnit
WaitForExit
BitBlt
get_Default
FirstOrDefault
IAsyncResult
DialogResult
ParallelLoopResult
set_UserAgent
get_Client
WebClient
TcpClient
System.Management
Environment
Component
GetParent
MakeTransparent
get_Current
GetCurrent
ManualResetEvent
AutoResetEvent
mouse_event
IPEndPoint
WindowFromPoint
set_Font
get_Count
GetByteCount
get_ProcessorCount
GetPathRoot
Prompt
ThreadStart
TrimStart
waveInStart
set_SelectionStart
waveOutRestart
Insert
Convert
HttpWebRequest
ToList
get_InnerList
ArrayList
get_Host
set_TopMost
set_Timeout
SendMessageTimeout
set_ReadWriteTimeout
LoadKeyboardLayout
GetKeyboardLayout
SendInput
get_StandardInput
set_RedirectStandardInput
get_Output
get_StandardOutput
set_RedirectStandardOutput
MoveNext
System.Text
get_Text
set_Text
ReadAllText
WriteAllText
get_ErrorText
ContainsText
GetText
SetText
GetWindowText
StreamingContext
SynchronizationContext
RegistryView
get_Now
get_UtcNow
FindWindow
GetForegroundWindow
NativeWindow
set_CreateNoWindow
GetDesktopWindow
PrintWindow
ShowWindow
ToUnicodeEx
UnhookWindowsHookEx
SetWindowsHookEx
CallNextHookEx
ChangeDisplaySettingsEx
get_Index
DigiFix
MessageBox
set_MinimizeBox
set_ControlBox
TextBox
IBindCtx
CreateBindCtx
get_Day
InitializeArray
ToArray
ToCharArray
get_IsArray
get_IsReady
get_Key
CreateSubKey
OpenSubKey
OpenBaseKey
MapVirtualKey
ContainsKey
RegistryKey
System.Security.Cryptography
get_Assembly
get_CompiledAssembly
GetExecutingAssembly
set_OutputAssembly
get_AddressFamily
set_ReadOnly
AsReadOnly
get_IsReadOnly
LastIndexOfAny
memcpy
BlockCopy
IDictionary
LoadLibrary
FreeLibrary
set_GenerateInMemory
CreateDirectory
set_WorkingDirectory
get_SystemDirectory
get_RootDirectory
Registry
HandleBusy
AcmBusy
get_Capacity
Quality
op_Equality
op_Inequality
System.Security
WindowsIdentity
IsNullOrEmpty
System.Security.Permissions.SecurityPermissionAttribute, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
SkipVerification
1.15.0.065e51
WrapNonExceptionThrows
$e2acb467-72ee-4e9b-950d-e2cfdb8a48d1
.NETFramework,Version=v4.0
FrameworkDisplayName
.NET Framework 4
$0579154A-2B53-4994-B0D0-E773148EFF85
$C6E13370-30AC-11d0-A18C-00A0C9118956
$C6E13380-30AC-11D0-A18C-00A0C9118956
$C6E13340-30AC-11d0-A18C-00A0C9118956
$6A2E0670-28E4-11D0-A18c-00A0C9118956
$56A86895-0AD4-11CE-B03A-0020AF0BA770
$93E5A4E0-2D50-11d2-ABFA-00A0C9C6E38D
$29840822-5B84-11D0-BD3B-00A0C911CE86
$56A86893-0AD4-11CE-B03A-0020AF0BA770
$56A86892-0AD4-11CE-B03A-0020AF0BA770
$56A8689F-0AD4-11CE-B03A-0020AF0BA770
$36B73882-C2C8-11CF-8B46-00805F6CEF60
$56A868A9-0AD4-11CE-B03A-0020AF0BA770
$56A868B1-0AD4-11CE-B03A-0020AF0BA770
$56a868c0-0ad4-11ce-b03a-0020af0ba770
$56A86891-0AD4-11CE-B03A-0020AF0BA770
$55272A00-42CB-11CE-8135-00AA004BB851
$56a86897-0ad4-11ce-b03a-0020af0ba770
$6B652FFF-11FE-4FCE-92AD-0266B5D7C78F
$B196B28B-BAB4-101A-B69C-00AA00341D07
$ebc25cf6-9120-4283-b972-0e5520d0000E
$ebc25cf6-9120-4283-b972-0e5520d0000D
$ebc25cf6-9120-4283-b972-0e5520d0000C
$ebc25cf6-9120-4283-b972-0e5520d00005
$ebc25cf6-9120-4283-b972-0e5520d00004
$ebc25cf6-9120-4283-b972-0e5520d0000B
$ebc25cf6-9120-4283-b972-0e5520d00006
$ebc25cf6-9120-4283-b972-0e5520d0000A
$ebc25cf6-9120-4283-b972-0e5520d00009
$ebc25cf6-9120-4283-b972-0e5520d00008
$ebc25cf6-9120-4283-b972-0e5520d00007
$6d6cbb60-a223-44aa-842f-a2f06750be6d
$59eff8b9-938c-4a26-82f2-95cb84cdc837
$bbeea841-0a63-4f52-a7ab-a9b3a84ed38a
$d8ad0f58-5494-4102-97c5-ec798e59bcf4
$f447b69e-1884-4a7e-8055-346f74d6edb3
$279AFA83-4981-11CE-A521-0020AF0BE560
$279AFA85-4981-11CE-A521-0020AF0BE560
$b0210783-89cd-11d0-af08-00a0c925cd16
Dolby AC3 SPDIF
IEEE floating-point
WMA 9 Voice codec
WMA SPDIF
WMAudio Lossless
Windows Media Audio
Windows Media Audio Professional
Dolby AC3
MPEG-4 and AAC Audio Types
Dolby Audio Types
Dolby Digital Plus for HDMI
MSAudio1
IMA ADPCM
$E7FE2E12-661C-40DA-92F9-4F002AB67627
$48e2ed0f-98c2-4a37-bed5-166312ddd83f
Protected Media
SAMI captions
Script stream
Still image stream
HTML stream
Binary stream
File transfer
$7FEE9E9A-4A89-47a6-899C-B6A53A70FB67
$2CD2D921-C447-44A7-A13C-4ADABFC247E3
$5BC8A76B-869A-46A3-9B03-FA218A66AEBE
$DF598932-F10C-4E39-BBA2-C308F101DAA3
$3137f1cd-fe5e-4805-a5d8-fb477448cb3d
$bf94c121-5b05-4e6f-8000-ba598961414d
Transform Flags
Transform Category
Class identifier
Input Types
Output Types
Preferred Output Format
PMP Host Context
App Context
Duration
Total File Size
Audio encoding bitrate
Video Encoding Bitrate
MIME Type
Last Modified Time
Element ID
Preferred Language
Playback boundary time
Audio is variable bitrate
Major Media Type
Media Subtype
Audio block alignment
Audio average bytes per second
Audio number of channels
Audio samples per second
Audio bits per sample
Enable Hardware Transforms
User data
All samples independent
Fixed size samples
DirectShow Format Guid
!Preferred legacy format structure
Is Compressed
Average bitrate
AAC payload type
"AAC Audio Profile Level Indication
$ad4c1b00-4bf7-422f-9175-756693d9130d
$045FA593-8799-42b8-BC8D-8968C6453507
$44AE0FA8-EA31-4109-8D2E-4CAE4997C555
$c40a00f2-b93a-4d80-ae8c-5a1c634f58e4
$70ae66f2-c809-4e4f-8915-bdcb406b7993
$F294ACFC-3146-4483-A7BF-ADDCA7C260E2
$1CB9AD4C-DBFA-4c32-B178-C2F568A703B2
$BCDE0395-E52F-467C-8E3D-C4579291692E
_CorExeMain
mscoree.dll
3254>=BADCFEONQPSRTRURVRXW\[][^[_[edfdhgjilkporqsqtquqvqwqxqyqzq{q|q}q~q
Non-Escape sequences cannot contain sequence delimiters
Single comment delimiter is not allowed
s cannot be empty
no tokens found in string
Invalid format: First token was not a string
Invalid Format: a name was needed but not found
Invalid format: unclosed table
item name cannot be empty or null
a value with name
already exists in the table
name cannot be empty
"\nrtbf/
"\nrtbf
u{0:X4}
Action
Command
keyloggerlist
keyloggerdata
No log.
RunProcess
ChangeKBLayout
RelocateWindow
compression
keyboard
process
arguments
@echo off
chcp 65001
w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 1>nul
start "" "
del /a /q /f "
@echo off
chcp 65001
w32tm /stripchart /computer:localhost /period:5 /dataonly /samples:2 1>nul
del /a /q /f "
monitor
Select monitor
Microsoft Sans Serif
searchpath
\Users\
cookies
passwords
history
telegram
discord
filezilla
screenshot
clipboard
sysinfo
stealer
stealerlogstatus
Memory
processes
MicrophoneNum
Bitrate
Channels
WebcamNum
Monitor
%SystemRoot%
\System32\cmd.exe
Directory
Saving file...
{USERNAME}
{SYSTEMDRIVE}
NoResponse
OldPath
NewPath
Duration
notepad.exe & pause
shutdown
/l /t 0
/r /t 0
/s /t 0
System.Core.dll
System.dll
System.Windows.Forms.dll
System.Drawing.dll
System.Data.dll
System.Management.dll
System.Data.Entity.dll
Line]:
DCRat.Code
http://
explorer.exe
iexplore.exe
cmd.exe
/c net user
Requests
Threads
POST / HTTP/1.1
Host:
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
User-Agent:
Content-length: 5235
3f47c4df0b8508dfc3c1446fdee7e602064fb626
0b2a8e406e4381ca575e5980d22da57607bfef9e
1ab87bb657b9111a86e69b11e318487cd7d25f9f
033a531059a87dc1f384ca540f4c7dbd8ff39b05
21639fdff5f58d12ef51de0957b38e7e653ed02e
f14bd1a548f692db7c1ad193614b665b4f1438b1
ec122f54cf16a175b3e22979e240684f7734079a
4b42c30f31c815da470c9d1b020e8fc0b498b67a
a65265946e25560ce621ab2a0ba9741f63cadbaf
d48588bd195e46c16b9bacac7fcb10be9ebe8509
30120f6dd998b42cadd5816c0710cb48b67e1d08
e2ab8561c5a8f9967e62486c44211c63bcf7d002
0fa94eba66338e3f5a32d979a9087a9c08730236
d99653628c31665f1201c1daebaa10c6b90472de
d71950b905851a7c15220261909210c2450197d9
892af8857843a5b28f39007922f020f871cc0626
4d43929535358a1dd5aa2f41f085a29a934f8d18
bb10a9fe22f6e97756056a10eaf096dc97d63018
42b5a9fed71470ad70572b58bfb2190e022a113d
75d2dd5b53c59f8dfefca70ea249a8497879c08e
53669f193b2174641c72654b5c3e5b67950334ae
16f766f2f5d7ff50934fb25604a14e9fd4126771
8691414b5ef3645fbdf2a70a19638553512d2a8b
25a2922229e3060bbcf2a939c183a25741b8eebd
38d8fe5c3796e1b93ceb59dcdb879c010507e64a
8523e47f3eee441304ce620a6526cf7735acc424
c3e426b0464a8233a96d31a554beab4b04948c74
cc33068719316a9730aecf753325f68d767915e9
e6260634dc18893f85c2ca0544b0eca5d81a3e1e
e1c5d85fb07165943765e11ccb92f50d51841212
d3c0f9a376ff14edd8a04c44cf405706845b5c99
7e9791e50f88fa0563b571269b05bf020350c7b9
184f7b43e842de671800a0769ed5d1622bc2b121
ec2bef6995abafe7d56ecc633283bc6626bb2aff
53d6405acd1e438617ef88ebf16f0f7c810feef9
066bc47f2ec2216ae3fdaa17ef60b4c166d6de39
3b5a9f7948a58d58bd432360863a719c95485504
46731269a0e66de01213cf1758eda6b9fd6a1afe
4a190bf2c1e0cf2b6a8d48b79de0e1eba7eb70f1
754d2e97bafe87cf79fea733afb2a09bab2db7e3
5a5179f1dd43b9144a917e744c408409444d73dd
75f5540a4254c10b1e0a5ab37182f52a6636b692
17d396020d8a4d80d4d4f29227e3b7e2a610ece1
0b10c99d661be5ee62b5fe068df56851e82283b4
a88c3a9ea09ff127bfa8ac24575f58c0a420c464
7ecde348ff9cda2c3ba69a0c4543365039d0d65b
b1fa569013eaf23a62e555839f7668b0e642858c
72105bdea4b5a323e66b251a256c80719afc3f9d
84bbfdf0d9e56680ca68c3d3a9f5fe25e912fe3b
0a25ba5991316bdda4a9b3abcee2106016df28a0
c70c31586ebf49e5bb5e36137f2fa6fdcc9b6b84
Plugin couldn't process this action!
Unknown command!
#ERROR
windowstyle
Hidden
Minimized
Maximized
INFORMATION
WARNING
CONFIRMATION
caption
PLUGINS
PLUGINCONFIGS
DPlugin
Plugin
OnLoad
OnCommand
OnUninstall
OnStealer
CommandName
ConfigPluginName
%SystemDrive% - Slow
%UsersFolder% - Fast
%AppData% - Very Fast
Users\
\AppData\
Folder
dd.MM.yyyy HH:mm
\mozglue.dll
\nss3.dll
NSS_Init
PK11SDR_Decrypt
NSS_Shutdown
ProgramFiles
PROCESSOR_ARCHITEW6432
ProgramFiles(x86)
&quot;
&apos;
&nbsp;
<span style="color: #F85C50;">[
]</span>
Return
Escape
LControlKey
RControlKey
RShiftKey
LShiftKey
Capital
<span style="color: #F85C50;">[Up]</span>
<span style="color: #F85C50;">[Down]</span>
<span style="color: #F85C50;">[Left]</span>
<span style="color: #F85C50;">[Right]</span>
<span style="color: #F85C50;">[Enter]</span>
<span style="color: #F85C50;">[ESC]</span>
<span style="color: #F85C50;">[CTRL]</span>
<span style="color: #F85C50;">[Shift]</span>
<span style="color: #F85C50;">[Back]</span>
<span style="color: #F85C50;">[Win]</span>
<span style="color: #F85C50;">[Tab]</span>
<span style="color: #F85C50;">[CAPSLOCK: OFF]</span>
<span style="color: #F85C50;">[CAPSLOCK: ON]</span>
dd.MM.yyyy
<div style="color: white; background-color: #4d4d4d; border-radius: 100px 100px 15px 15px; padding: 3px 0 3px"><center>DCRat Keylogger #
</center></div>
<p style="color: #7AB1FF; margin-bottom: 2px">[
(\w\W.+)Telegram.exe
HKEY_CLASSES_ROOT\tdesktop.tg\shell\open\command
Telegram.exe
Unknown
SOFTWARE\Valve\Steam
AutoLoginUser
/config/loginusers.vdf
AccountName
https://steamcommunity.com/profiles/
Language
SteamPath
/steamapps/common
microphone
MicrophoneStatus
CmdOutput
Session closed.
Exception:
/K CHCP {0}
hrdwindowsize
hrdwindow
extension
hrdbuffer
token_uid
getdata
setdata
rdscreensize
rdscreen
rdbuffer
H4sIAAAAAAAEAE1QPY+jMBD9MTTQgUOic3HNsjbYAmcxYIJL29FhQNlIZFng159ZXXHFK97MvA/N7/Am97XtgudAEB7J3AA940BeyFa90SS35Un3EpGXV9FNpHKGAd+p0whB7edASiZK+13JiGbGaer6x6M1G39cbXHsbHEhthHH3BvcLCoT5zuxTPUyuFo9luh/HiKBVndLrG9fqML96MdoVHNfX6283fHz1MxR0mIuBINT885HciH/+E9f3EgalUe3DCPh8glnQ7mSqUj5oxUyNL2c6pgC7rNHt5epGkz7Ab0wf8HU7FOglnPbLQjoEDsOQT6L1B9gqkcR6G9o1QIti+KNrWTIQ4dY7/ny+a5DnvlH7vbn6F81O2mKig48fAqRmlvXntHdmrHdKSjGFXSPqP7wYKUWftLPM1BfGOQ9y0zv+AITNfWgW94yOdFMLzFQS1ezL10XW5wwh+vp15ZfvMyEfeB+UBWEbve/DYISktABAAA=
H4sIAAAAAAAEAOx9TXejutLuj9kTmIEd9zoZ3Ak2wiYNDgJJRkMbr02MlkMn7tjxr79PSdhJ+ut83vec894esLPdQkIqVZWqpKdK/yfYL26DSvhmV87CoIn6VdXf+l7K5+t5mjRJOKr7ZuWlJ79apInnHVQ56oKiS6t8xdX2eeLXj6cR7+SeH0ywSXOjPrVjqZuu7G+Fl09G9TP3M4/tylUfetM21sc/R7KNUN9Ib2xU+TyJy4fWV0+my1MzrifmzLtolb8ukmaZn+vnSZc9mH1RsyQLN1J93x+x3Zm9fH00azVR6jkNf95+LvSoD7iH/r5myaak/vdBkRklX7PRJgl9YceP9g4Yn0rP9Sc+yh4OKl+xUfbcxDrUYp3mq7LqzfamkWreC+/eJNmB/6K9dF9h/OtlY9TkR+VyV54xXtWY+tyd+UO0F18xvjuz0nZ80b6qpX2/ng70fgK9jzeqPMYxv2foZygyyUV1w+J1qqtyouUW7amwDvjOjJreiPKoZTXSITftStRa5mm6q0916BmzQvthlchY1z1TS8zfXDKvk7F8ZZX08q76ZKS4kULPZCW7MNHziaiSplOYC08xX5zi0foojZhhnoXpOGtMpU5+fRRsLSexFtrIRymrgCfS4P1jptZeqCQzZ7mSc++1Npuk31clH3lCVtVrHJYJN1Xed2sezfJ5K//L+89yxo2c94G3NCJ/StV6Gar686STy1Mn//P7L3PIX3Xi82zZrkrBk9zrE/nahZ53EsvVf3z/WZ70o1r1LPNMJ08d25ZRhT6Z9fIW8v0f3/9wfQd9NOG7bJef14qx9R0PKoxDrW6T5r+g/2W4qESQJaVo4mY1Efy5n+tPYbc27X9D/2WZ6KDO5NnbNWytmhD99+sb1q1zXf038P/mru3El1PCJWP6Sx5mz/1KCR0rL5ppBr0aQB8d6zjbybNe3ApJ7X3K/S3WNbXI1Xqaz3TYhVkrd9XXNBRlWqkS63XFKh7n0kt4WK8i6AeMXbJks+RCfkljxRvD
Install:
webcam
DCRat-Log#
Stealing Browsers...
Browsers/
Scanning directory...
Scanning directory (
Raw Elements:
Scanned! Elements:
) Error:
Grabbing cookies...
Fetching cookies...
Grabbing passwords...
Fetching passwords...
Grabbing forms...
Fetching forms...
Grabbing cc...
Fetching CC...
Grabbing history...
Fetching History...
Other/
Grabbing steam...
Other/Steam/
Grabbing telegram...
Other/Telegram/
Invoking Plugins...
Invoke StealerPlugin:
Fetching Other Information...
Screenshots:
Screenshots/
Screenshots/Screenshot#
Clipboard...
Grabbing discord tokens...
Other/Discord Token(s).txt
Grabbing filezilla...
\FileZilla\sitemanager.xml
Other/FileZilla#sitemanager.xml
\FileZilla\recentservers.xml
Other/FileZilla#recentservers.xml
Saving system information...
___ _ ___ _ _ ___ _ _____
| \ __ _ _ _| |__ / __|_ _ _ _ __| |_ __ _| | | _ \ /_\_ _|
| |) / _` | '_| / / | (__| '_| || (_-< _/ _` | | | / / _ \| |
|___/\__,_|_| |_\_\ \___|_| \_, /__/\__\__,_|_| |_|_\/_/ \_\_|
|__/
PC Name:
User Name:
Windows:
GPU Name:
CPU Name:
BIOS:
LANIP:
Antivirus:
Firewall:
Motherboard:
Framework Version:
Path:
City:
Country code:
country
Location:
Screens:
Save time:
Information [
Saving log...
~Work.log
Done! Elapsed time:
Spotify
Spotify WebViewer
Discord
Discord WebViewer
Chrome
Firefox
Waterfox
Meleon
K-Meleon
IceDragon
Yandex
Chromium
Safari
Opera GX
Vivaldi
Kometa
Steam WebViewer
Chromium Edge
os_crypt
encrypted_key
windows-1251
SQLite format 3
\..\..
\Local State
\LocalPrefs.json
Founded Elements:
Rows:
Browsers/Cookies [
Browsers/Unknowns/Cookies [
(Local) Error: Database is invalid
moz_cookies
Users\Public
\key3.db
\key4.db
\logins.json
\cert9.db
logins
Browsers/Passwords [
Browsers/Unknowns/Passwords [
autofill
Browsers/Forms [
Browsers/Unknowns/Forms [
credit_cards
Browsers/CC [
Browsers/Unknowns/CC [
downloads
Browsers/Download-History [
Browsers/Unknowns/Download-History [
Browsers/URL-History [
Browsers/Unknowns/URL-History [
moz_places
\discord\Local Storage\leveldb\
Discord not installed!
Failed.
Fetching Steam...
/config
-Login:
-Profile URL:
Other/Steam#Information.txt
Login:
Profile URL: https://steamcommunity.com/profiles/
Lang:
All accounts:
Steam Apps:
Steam not installed.
Fetching Telegram...
/tdata
Telegram
Other/Telegram/tdata/
Other/Telegram#Information.txt
Path:
Telegram not installed.
Clipboard.txt
Cookies
cookies.sqlite
logins.json
Login Data
Passman Data
Web Data
Autofill Data
Credit Cards
History
places.sqlite
usertag
settings
key_data
isHttpOnly
isSecure
expiry
hostname
encryptedUsername
encryptedPassword
Login:
Password:
Name:
Value:
Number:
Expiration:
Billing:
) Local Error:
tab_url
Title:
Other/Steam/config/
SysShadow
#32768
ConsoleWindowClass
CiceroUIWndFrame
MDIClient
SysListView32
{{Left={0},Top={1},Right={2},Bottom={3}}}
DISPLAY
set CDAudio door open
set CDAudio door closed
DisplayNumber
Number is greater than connected displays.
Control Panel\Desktop
PicturePosition
TileWallpaper
Shell_TrayWnd
Program Manager
schtasks.exe /create /tn "
" /sc ONLOGON /tr "'
'" /rl HIGHEST /f
Software\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows NT\CurrentVersion\Winlogon
" /sc minute /mo
/tr "'
builds
schtasks
/Delete /tn "
svchost
ECatcher:
4.3.11
gettoken
status
workdir
ipinfo
geoplugin_request
127.0.0.1
geoplugin_city
region
geoplugin_regionName
geoplugin_countryCode
geoplugin_latitude
geoplugin_longitude
Not specified -
geoplugin_countryName
postal
000000
timezone
geoplugin_timezone
Not specified /
ServerConnect:
uploadfile_name
command
_status
Transfering data:
adddata
GPUName
CPUName
CommandHandler:
Antivirus
Firewall
Motherboard
Webcams
Screens
Microphones
SteamLang
SteamUser
SteamUserID
SteamApps
TelegramPath
FrameworkVersion
aHR0cHM6Ly9pcGluZm8uaW8vanNvbg==
{"ip":"Unknown","hostname":"Unknown","city":"Unknown","region":"Unknown","country":"XX","loc":"Unknown","org":"Unknown","postal":"Unknown","timezone":"Unknown"}
ServerType
ServerVer
PCName
UserName
IpInfo
WinVer
isMicrophone
isWebcam
isAdmin
ACTWindow
usermaindata
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789
Win32_Process
Win32_ProcessStartup
CreateFlags
Create
CommandLine
ProcessStartupInformation
ReturnValue
ProcessId
%USERPROFILE%
AppData\Local\Temp
Users\Public\
{0:0.##} {1}
Software\\
Unknown OS
SELECT Caption FROM Win32_OperatingSystem
Caption
^.*(?=Windows)
{0} {1} Bit
image/jpeg
UNIQUE
SOFTWARE\Microsoft\NET Framework Setup\NDP\v4\Full\
Release
.NET Framework Version 4.X is not detected.
Disabled
root\SecurityCenter
root\SecurityCenter2
SELECT * FROM AntivirusProduct
displayName
SELECT * FROM FirewallProduct
SELECT * FROM Win32_BIOS
Manufacturer
SELECT * FROM Win32_BaseBoard
SerialNumber
SELECT * FROM Win32_Processor
Select * From Win32_ComputerSystem
TotalPhysicalMemory
SELECT * FROM Win32_VideoController
AdapterRAM
Content-Type
Accept
User-Agent
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
Mozilla/5.0 (Linux; Android 8.0.0; SM-G960F Build/R16NW) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.84 Mobile Safari/537.36
Mozilla/5.0 (Linux; Android 6.0; HTC One M9 Build/MRA58K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.98 Mobile Safari/537.3
Mozilla/5.0 (iPhone; CPU iPhone OS 12_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.0 Mobile/15E148 Safari/604.1
Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/604.1.34 (KHTML, like Gecko) Version/11.0 Mobile/15A5341f Safari/604.1
Mozilla/5.0 (iPhone9,4; U; CPU iPhone OS 10_0_1 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A403 Safari/602.1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.135 Safari/537.36 Edge/12.246
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36
Mozilla/5.0 (PlayStation 4 3.11) AppleWebKit/537.73 (KHTML, like Gecko)
Mozilla/5.0 (Windows Phone 10.0; Android 4.2.1; Xbox; Xbox One) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Mobile Safari/537.36 Edge/13.10586
text/css
text/csv
text/html
text/javascript
application/json
text/plain
----------{0:N}
multipart/form-data; boundary=
Content-Disposition: form-data; name="{1}"; filename="{2}";
Content-Type: {3}
application/octet-stream
Content-Disposition: form-data; name="{1}"
FriendlyName
Failed creating device enumerator
No devices of the category
videoStreamConfig
This video device does not report capabilities.
Unable to retrieve video device capabilities. This video device requires a larger VideoStreamConfigCaps structure.
Unsupported format found.
Video source is not specified.
Failed creating capture graph builder
Failed creating filter graph
Failed creating device object for moniker
Failed creating sample grabber
source
grabber_video
grabber_snapshot
Key length not 128/192/256 bits.
invalid parameter passed to AES init -
AES engine not initialised
input buffer too short
output buffer too short
cipher required with a block size of
Invalid value for MAC size:
invalid parameters passed to GCM
IV must be at least 1 byte
data too short
mac check in GCM failed
Operator
yyyy-MM-dd-HH:mm:ss
??time
\\\*\.\*
\\([^\.]+|.*\.[^\\\.]*)
\.[^\\\.]*
[^\\\.]
Specify a single character: either D or F
Repeated flag. ({0})
attributes
Conjunction
([^']*)\(\(([^']+)
$1( ($2
(.)\)\)
\(([^'\f\n\r\t\v\x85\p{Z}])
(\S)\)
(\S)\(
\)([^'\f\n\r\t\v\x85\p{Z}])
(=)('[^']*')
([^ !><])(>|<|!=|=)
(>|<|!=|=)([^ =])
name =
length
filename
attributes
yyyy/MM/dd-HH:mm:ss
yyyy/MM/dd
MM/dd/yyyy
yyyy-MM-dd
FileSelector(
SelectionCriteria has not been set
(?<=(?:[^']*'[^']*')*'[^']*)
(?=[^']*'(?:[^']*'[^']*')*[^']*$)
(?<=(?:[^']*'[^']*')*[^']*)
(?=(?:[^']*'[^']*')*[^']*$)
windowBits must be in the range 9..15.
memLevel must be in the range 1.. {0}
Stream error.
Something is fishy. [{0}]
OutputBuffer is full (AvailableBytesOut == 0)
status == FINISH_STATE && _codec.AvailableBytesIn != 0
need dictionary
stream end
file error
stream error
data error
insufficient memory
buffer error
incompatible version
DeflateStream
The working buffer is already set.
Don't be silly. {0} bytes?? Use a bigger buffer, at least {1}.
GZipStream
Illegal filename
iso-8859-1
invalid block type
invalid stored block lengths
too many length or distance symbols
invalid bit length repeat
invalid literal/length code
invalid distance code
Bad window size.
InputBuffer is null.
unknown compression method (0x{0:X2})
invalid window size ({0})
incorrect header check
incorrect data check
Bad state ({0})
oversubscribed dynamic bit lengths tree
incomplete dynamic bit lengths tree
oversubscribed literal/length tree
incomplete literal/length tree
oversubscribed distance tree
incomplete distance tree
empty distance tree with lengths
MaxBufferPairs
Value must be 4 or greater.
BufferSize
BufferSize must be greater than 1024 bytes
Cannot enqueue workitem
deflating:
Cannot Write after Reading.
flating:
flating
{0}: (rc = {1})
Writing with decompression is not supported.
Missing or incomplete GZIP trailer. Expected 8 bytes, got {0}.
Bad CRC32 in GZIP trailer. (actual({0:X8})!=expected({1:X8}))
Bad size in GZIP trailer. (actual({0})!=expected({1}))
Reading with compression is not supported.
Unexpected EOF reading GZIP header.
Not a valid GZIP stream.
Bad GZIP header.
Unexpected end-of-file reading GZIP header.
The stream is not readable.
Cannot Read after Writing.
buffer
offset
{0}flating: rc={1} msg={2}
Deflating: rc={0} msg={1}
Cannot initialize for deflate.
Cannot initialize for inflate.
Invalid ZlibStreamFlavor.
You may not call InitializeInflate() after calling InitializeDeflate().
No Inflate State!
You may not call InitializeDeflate() after calling InitializeInflate().
No Deflate State!
No Inflate or Deflate state!
Invalid State. (pending.Length={0}, pendingCount={1})
The input stream must not be null.
The data buffer must not be null.
stream
Bad Directory
That name specifies an existing directory. Please specify a filename.
exeToGenerate
missing resource '{0}'
Antivirus Signature
Bkav Clean
Lionic Trojan.Win32.Basic.4!c
Elastic malicious (high confidence)
DrWeb BackDoor.QuasarNET.3
MicroWorld-eScan Trojan.MSIL.Basic.8.Gen
FireEye Generic.mg.cc982bb10719da03
CAT-QuickHeal Trojan.YakbeexMSIL.ZZ4
McAfee GenericRXPF-LQ!CC982BB10719
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
K7AntiVirus Spyware ( 004bf53c1 )
BitDefender Trojan.MSIL.Basic.8.Gen
K7GW Spyware ( 004bf53c1 )
Cybereason malicious.10719d
BitDefenderTheta Gen:NN.ZemsilF.34050.Sm0@aSBbtRmi
Cyren Clean
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Spy.Agent.AES
Zoner Clean
TrendMicro-HouseCall TROJ_GEN.R002C0DGR21
Paloalto generic.ml
ClamAV Win.Packed.Uztuby-9853721-0
Kaspersky HEUR:Trojan-Spy.MSIL.Stealer.gen
Alibaba TrojanSpy:Win32/Stealer.7365ac94
NANO-Antivirus Clean
ViRobot Clean
Tencent Msil.Trojan.Msil.Tbim
Ad-Aware Trojan.MSIL.Basic.8.Gen
Emsisoft Trojan.MSIL.Basic.8.Gen (B)
Comodo Clean
F-Secure Clean
Baidu Clean
VIPRE Clean
TrendMicro TROJ_GEN.R002C0DGR21
McAfee-GW-Edition GenericRXPF-LQ!CC982BB10719
CMC Clean
Sophos Mal/SpyNoon-A
Ikarus Trojan.MSIL.Spy
GData Trojan.MSIL.Basic.8.Gen
Jiangmin Clean
Webroot Clean
Avira TR/Spy.Agent.oilfv
MAX malware (ai score=82)
Antiy-AVL Clean
Kingsoft Win32.Troj.Undef.(kcloud)
Gridinsoft Clean
Arcabit Trojan.MSIL.Basic.8.Gen
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Spy.BYF!MTB
Cynet Malicious (score: 99)
AhnLab-V3 Trojan/Win.Spy.C4559049
Acronis Clean
VBA32 TScope.Trojan.MSIL
ALYac Trojan.MSIL.Basic.8.Gen
TACHYON Clean
Malwarebytes Clean
Panda Trj/GdSda.A
APEX Malicious
Rising Clean
Yandex Clean
SentinelOne Static AI - Malicious PE
MaxSecure Clean
Fortinet MSIL/Agent.BYF!tr.spy
AVG Win32:KeyloggerX-gen [Trj]
Avast Win32:KeyloggerX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)
Qihoo-360 Win32/Trojan.Generic.HwMAueAA
No IRMA results available.