Extracted/injected images (may contain unpacked executables)
Download #1
Match: Generic_PWS_Memory_Zero
Match: DebuggerCheck__GlobalFlags
Match: DebuggerCheck__QueryInfo
Match: DebuggerHiding__Thread
Match: DebuggerHiding__Active
Match: ThreadControl__Context
Match: SEH__vectored
Match: vmdetect
Match: anti_dbg
Match: disable_dep
Match: Win32_PWS_Loki_m_Zero
Match: Virtual_currency_Zero
http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 http://ocsp.digicert.com0C http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0 http://ocsp.digicert.com0A http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 https://steamcommunity.com/profiles/76561198982268531 http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S https://t.me/sundayevent http://www.digicert.com/CPS0 http://ocsp.digicert.com0 http://ocsp.digicert.com0X