1.3
低危

0ef8db2cc5b2e84e156571be8de06ca78937164b17ee002084bff08c9ac717e0

0ef8db2cc5b2e84e156571be8de06ca78937164b17ee002084bff08c9ac717e0.exe

分析耗时

193s

最近分析

387天前

文件大小

501.2KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN RANSOM GRAFTOR
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.86
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20200113 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200113 2013.8.14.323
McAfee GenericRXFM-UB!832D35804157 20200113 6.0.6.653
Tencent Win32.Trojan.Filecoder.Dxmr 20200113 1.0.0.1
静态指标
行为判定
动态指标
在 PE 资源中识别到外语 (1 个事件)
name RT_VERSION language None filetype None sublanguage SUBLANG_ARABIC_EGYPT offset 0x0008742c size 0x00000328
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (1 个事件)
section {'name': '.data', 'virtual_address': '0x00028000', 'virtual_size': '0x0005e704', 'size_of_data': '0x00005a00', 'entropy': 7.349871283018365} entropy 7.349871283018365 description 发现高熵的节
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 52 个反病毒引擎识别为恶意 (50 out of 52 个事件)
ALYac Gen:Variant.Graftor.281734
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Gen:Variant.Graftor.281734
AhnLab-V3 Trojan/Win32.Teslacrypt.R178173
Antiy-AVL Trojan[Ransom]/Win32.Bitman
Arcabit Trojan.Graftor.D44C86
Avast Win32:Malware-gen
Avira HEUR/AGEN.1045453
BitDefender Gen:Variant.Graftor.281734
BitDefenderTheta Gen:NN.ZexaF.34082.Fu3@aa69v8HO
CAT-QuickHeal Ransomware.Tescrypt.T5
ClamAV Win.Ransomware.Razy-7101238-0
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.04157c
Cylance Unsafe
DrWeb Trojan.Encoder.4321
ESET-NOD32 a variant of Win32/Filecoder.TeslaCrypt.L
Emsisoft Gen:Variant.Graftor.281734 (B)
Endgame malicious (high confidence)
F-Secure Heuristic.HEUR/AGEN.1045453
FireEye Generic.mg.832d35804157cb48
Fortinet W32/Kryptik.4560!tr
GData Gen:Variant.Graftor.281734
Ikarus Trojan-Ransom.TeslaCrypt
Invincea heuristic
Jiangmin Trojan.Bitman.zm
K7AntiVirus Trojan ( 004e16e91 )
K7GW Trojan ( 004e16e91 )
Kaspersky Trojan-Ransom.Win32.Bitman.adww
MAX malware (ai score=87)
Malwarebytes Ransom.TeslaCrypt
McAfee GenericRXFM-UB!832D35804157
McAfee-GW-Edition BehavesLike.Win32.Generic.hz
MicroWorld-eScan Gen:Variant.Graftor.281734
Microsoft Ransom:Win32/Tescrypt.T
NANO-Antivirus Trojan.Win32.Encoder.ebkubm
Paloalto generic.ml
Panda Trj/GdSda.A
Rising Ransom.Tescrypt!8.3AF (CLOUD)
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Mal/Generic-S
Symantec ML.Attribute.HighConfidence
Tencent Win32.Trojan.Filecoder.Dxmr
VBA32 BScope.Trojan.Encoder
VIPRE Trojan.Win32.Generic!BT
Yandex Trojan.Filecoder!iLj4pgu47LY
Zillya Trojan.Filecoder.Win32.11216
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2016-04-06 04:37:31

PE Imphash

13a03105c86691a53a0ec9681df0ada1

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x00022820 0x00022a00 6.718736793898537
.rdata 0x00024000 0x00003610 0x00003800 5.04093807332225
.data 0x00028000 0x0005e704 0x00005a00 7.349871283018365
.rsrc 0x00087000 0x000008b0 0x00000a00 3.7798394832650666
.reloc 0x00088000 0x00002512 0x00002600 4.62094315288085

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x00087130 0x000002e8 LANG_SPANISH SUBLANG_SPANISH_PANAMA None
RT_GROUP_ICON 0x00087418 0x00000014 LANG_SPANISH SUBLANG_SPANISH_PANAMA None
RT_VERSION 0x0008742c 0x00000328 None SUBLANG_ARABIC_EGYPT None
RT_MANIFEST 0x00087754 0x0000015a LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library gdiplus.dll:
0x424164 GdiplusStartup
0x424168 GdipCloneImage
0x42416c GdipSaveImageToFile
0x424178 GdipDisposeImage
0x424180 GdipAlloc
0x424184 GdipFree
Library KERNEL32.dll:
0x42401c GetModuleHandleA
0x424020 GetFileSize
0x424024 SetFilePointer
0x424028 GetDriveTypeW
0x42402c HeapAlloc
0x424034 HeapFree
0x424038 GetProcessHeap
0x42403c WriteFile
0x424040 GetFileAttributesW
0x424044 ReadFile
0x424048 CreateFileW
0x42404c FlushFileBuffers
0x424050 CloseHandle
0x424054 SetFileAttributesW
0x424058 LoadLibraryA
0x42405c FreeLibrary
0x424064 GetTickCount
0x424068 LoadLibraryW
0x42406c GetVersionExW
0x424070 GetProcAddress
0x424074 GetCurrentProcessId
0x424078 GetCurrentProcess
0x42407c Sleep
0x424080 GetStringTypeW
0x424084 MultiByteToWideChar
0x424088 RtlUnwind
0x42408c SetStdHandle
0x424090 WriteConsoleW
0x424098 HeapSize
0x42409c GlobalMemoryStatus
0x4240ac GetConsoleMode
0x4240b0 GetLastError
0x4240bc HeapReAlloc
0x4240c0 GetCommandLineW
0x4240c4 HeapSetInformation
0x4240c8 GetStartupInfoW
0x4240cc TerminateProcess
0x4240d8 IsDebuggerPresent
0x4240dc HeapCreate
0x4240e0 GetCPInfo
0x4240ec GetACP
0x4240f0 GetOEMCP
0x4240f4 IsValidCodePage
0x4240f8 EncodePointer
0x4240fc TlsAlloc
0x424100 TlsGetValue
0x424104 TlsSetValue
0x424108 DecodePointer
0x42410c TlsFree
0x424110 GetModuleHandleW
0x424114 SetLastError
0x424118 GetCurrentThreadId
0x42411c LCMapStringW
0x424120 ExitProcess
0x424124 GetStdHandle
0x424128 GetModuleFileNameW
0x42412c SetHandleCount
0x424134 GetFileType
0x42413c WideCharToMultiByte
0x424140 GetConsoleCP
Library USER32.dll:
0x424154 DrawTextA
0x424158 GetDC
0x42415c LoadStringW
Library GDI32.dll:
0x424000 SetBkMode
0x424004 DeleteObject
0x424008 SelectObject
0x42400c CreateFontW
0x424010 GetStockObject
0x424014 SetTextColor
Library SHLWAPI.dll:
0x424148 PathFindFileNameW
0x42414c PathFindExtensionW

L!This program cannot be run in DOS mode.
$UoZ$UoZ$UoZ
Z&UoZK#Z
UoZK#Z<UoZK#Z\UoZ$UnZIUoZ--Z)UoZ
Z%UoZ$UoZ%UoZK#Z7UoZ-Z%UoZK#Z%UoZRich$UoZ
`.rdata
@.data
@.reloc
V0t&3t +
<Bf=fE@;r
fuKt'
3_^[M3@Y
M_^3[,Y
3_^[M3X
@u3_^[M3X
`a`uNlaB
r_^3[]
_^[M3U
|tp~"`xptalt
||M_^33[yU
SVuhq^rj
^[M31T
um39}v
G ;}rnh9
^3@[dS
SVWj$B
3WQfD$$
|h`vPV
hR$C2j
_^[M3oL
SQj Uf
REPSQ#
f1f;2u
|_^3[_^
SVl3p@bB
3Wtdx8@bB
xO|xh~"`dhxaxt
M_^3[$H
SVt3l@bB
pW`\x8@bB
xO|xh~"`\hxax`
hI}(Pjtp
QlRdQR
SVp3@bB
3Wltxd$
xO|xh~"`thxalx
M_^3[#F
SVl3paB
3Wtdx8aB
xO|xh~"`dhxaxt
hWPypl
M_^3[$E
3[]VW}
@u+WSE3;I
+VSQMI
Au_^[]U<B
@:u+PSW
@:u+PSV
@:u+PSV_
@:u+PSW?
_^3[:@
EEfEEfEEYf
RQ8PRh<rG
tj UM`
hXlPQf
~EhxrG
W ]]f]
]]f]]]f
PMQj NARs
3_^[M37
M_^3[[7
SVp3aB
3Wltxd$
xO|xh~"`thxalx
M_^3[4
L$,L$@t$4p
QT$8t$@D$DT$L$
@:u+P$
3t$ j<D$HSP
SQD$P<
@:u+WT$H
PD$XP$
T$pPR$
SVp3aB
3Wltxd$
xO|xh~"`thxalx
M_^3[-
SVh3paB
dWt`x8aB
xO|xl~"``lxaxt
h5=Pdp
M_^3[,
SVl3paB
3Wtdx8aB
xO|xh~"`dhxatx
h>aPpl
M_^3[+
SVl3paB
3Wtdx8aB
xO|xh~"`dhxaxt
M_^3[*
SVt3laB
pW`\x8aB
xO|xh~"`\hxax`
M_^3[)
SVd3taB
xO|x\~"`X\xaxl
QpRhQ`RQ
M_^3[g(
SVh3paB
dWt`x8aB
xO|xl~"``lxatx
M_^3[h'
SVp3aB
3Wltxd$
xO|xh~"`thxalx
M_^3[&
u=S\HTX8L
S\H@<DL
L[XD9<t
GM_33^"
_^M3("
u5u1SDPT\XH
SDP@8<H
[\<98t
5M_33^
$j h<dB
Ku9\$Dt
RD$TP+
jD$\gD$`rn<D$d:OD$h
L$PQT$\R
D$HPL$dQ
L$P~* B
T$Xh B
D$8;T$<}
O;L$<}
T$@@D$8
T$HRD$TP
jD$\gD$`rn<D$d:OD$h
QT$\R
D$`h@B
S3VD$0D$$W$
D$(hdB
L$,D$
RT$$D$
SD$,h@eB
L$$D$0t_|$
t>T$4$8
Qj@RT$,t
W3hpeB
WD$$heB
WD$\heB
WD$4heB
WD$PheB
WD$(heB
WD$HheB
WD$@heB
WD$LheB
L$|QPT$(
RPL$`QD$d$
T$8t6P
T$X;T$XRT$Lt
D$|PQT$Ht
RPT$@t6$
QRT$Lt
PQT$Dt6$
RPT$8t
QRT$,tD
PQT$Tt
8@8v)@
p-}}33
]uu3yZ
]}};yZ
]uu3yZ
}};$M\
]uu3$M\
}};$M\
uu3$M\
]uu3$M\
]}};$M\
uu3$M\
}};$M\
uu3>pm
}};>pm
uu3>pm
]uu3>pm
]}};>pm
}};>pm
]uu3>pm
]}};>pm
}};vmz
uu3vmz
uu3vmz
]}};vmz
}};vmz
]uu3vmz
}};vmz
Uu2vmz
[^[_]U<
3SQf$L
T$$RhAB
RT$(RPA
T$.3SRfL$4xk
L$,Q$H
T$ RPA(
w+t7;t
t"_^[$8
Q$RlrG
hoVS58G
SSShx@
3958rG
SSh#&j
jVhtCj
SSSh@6@
SShtCj
=_^[h`vP
j<WRTc
>@49uC=hr=P
VW3};t
MQj<UWR
>@4E9uu*$hr=P
RQ PRP
ESV3$bB
3Wptx8$bB
xO|xl~"`tlxaxp
h(suPH
3Wtdx8
xO|xh~"`dhxaxt
3Wtdx8
xO|xh~"`dhxatx
SVp3aB
3Wltxd$
xO|xh~"`thxalx
hi'P+p
]U SX$V
#U3#U#U#U#U#
[]U$H$M
#M#M#M##3
^P H$[]U
]@##M3#M#M#M#M##
@###M3#M#M####M
S3W3^
_[u;F #F
m^[]UVu
B +q$r$^]
x3PQPF
U3PF$PERPq
U3PQPRq
3PF P3PEP}q
MP3PQfq
P3PROq
P3PEP8q
P3PQ!q
U3PRPF
xE3PQPF
U3PRPF$Pp
3PEP3PF Pp
U3PRPF
P3PEP[p
p3PRPF
PER3WPo
E3PUxRPF
U3PEP3PF$Pio
U3PQPF PRo
UU3PRPF
U3PEP3PF
Up3PRPF
E3PRPEPM}n
xE3PQPF
3PUURPF$P
U3PEP3PF P
U3PQPF
U3PpP3PF
U3PQPF
E3PRPE]
P3PQUQm
3PEP3UPF$Pl
UU3PRPF Pl
U3PpP3PF
U3PQPF
3PRPE]
P3PEPk
PF 0F$E3PEP3
M3PQUUPR7k
U3PEP38PQ
Up3PRP0P
UP3PQPRj
3PEP3MMP]
PUUWRj
P3PEPyj
P3PQaj
P3PRIj
3PRP8]
M3PQUPPRi
U3PpP3PQi
Ux3PRP0Pi
3PEM3PU
V]M(@6i
U3PQPRh
3PEP3PQh
03PEP3PQFh
x3PRPEP.h
8EWP3PQg
U3PRP(Pg
3PQPRg
3PEP3PQg
U3PRPEPvg
U3PQPR^g
3uPRP0Pf
M3PQdUPRf
3PURP@Pf
83PQPRof
3PEP3PQUf
U3PRP P=f
PQPR%f
3PpP3PQ
x3PRPEPe
3PEP3P}
E3UUPRME
M3PQPPR1e
3PEP3PQ
U3PRP8Pd
(3PQPRd
3PEP3PQd
U3PQPRd
3PEPM3PQd
PUV$3WREb
U3PEP3PF
U3PQPF
UU3PRPSb
3PQPF$P2b
U3PSPRb
M3QPQPMa
P3RQMa
ME3PQPF$PUa
U3PSPF
3QE3RPEF
P3PF$PU`
3QPQP`
U3PSPF
M3QPQ}
UP3PEP
3QPE3PF
3PEP3PF$PU_
U3PSPQ_
M}UP3PRK_
P3PEPU3_
3PEP3P}
3PF$P3PQU^
3QPQP^
P3PEPN^
3QPQP;^
3PEP3PF$PU]
ME3PUQPS]
P3UUMP
P3PEP^]
P3PQF]
F QPQP\
URPF$P\
P3PQ}\
U3PRPF
3QPQPT\
3REF QE
M3PQUPRl[
3PEP3PQR[
`3PRPEP:[
X3PQPQZ
U3PRPxPsZ
`3PQPR[Z
3PhP3PQAZ
SWV$dY
_^[]USJVu
~ ##X
x v$#H$#
_p$^[]
OuEPEMK
OuMQEu
M}]_[]U
NuMQ4r
NuMQEe
NuMQE5
NuUREQ
^]U4SVW
F _^[]
U3is-@
SV239M
@H]UTS]
CxW{PWFPM
3G$G G
FH[]U`SVWh
(|TMuMQ
_^[]U|SVu
u_^[]UPV
UUEEMMUUGP
HtHpHlHhHdH`H\HXHT
~A8B(f
VKx3WNx;t0;
_^[];t@
~PC(KPWP
F$_^[]U
UMPt.MDt
_^[]Gx
N$_^[]U
SVW39Nxt
9HPt6E
Ox`QFP(
EP(`dM
_^[]3;t
@ OPQE
N$_^[]U
U(R49E
EPEUlU
~PW4KP
F$N(V,F0
N(N4V,V8
F0F<N4N@V8VD
NLRPx#U
_Nx[]UP
~-(H^|E
k|L0QE
8TNuE3
wtwpwlwhwdw`w\wXwT
M3M#M3M
U3U]#U#3U
U3U#U3U
U3U#U3U
#}M}}#U
#}}}#U
}3#3]U
#}}}#U
}3U#U3
#MU#U}
#}}}#u
}u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
#}}}#u
u3u#u3u
3u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
#}}}#u
}u3u#u3u
#}}}#u
3u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
u3u#u3u
u3u#u3u
#}}}#u
#}}}#u
u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
3u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
}u3u#u3u
#}}}#u
#}}}#u
}u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
3u3u#u3u
#}}}#u
u3u#u3u
#u3]#]
u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
u3u#u3u
u3u#u3u
#}}}#u
u3u#u3u
#}}}#u
#}}}#u
}u3u#u3u
#}}}#u
#}}}#u
}u3u#u3u
#Uu3U]
^[]US]
_^[]U,B
\A@|MQP@
j@@|URV@
'C PP(SR
C PPSR
sC PPtSR
*M_^C@
C PPSQ
C PPSR
8LC PPD-SP
sM_^C@
M_^3[U
F$F(F,F0F4F8F<F@FDFHFLFPFTFXF\F`FdFhFlFpFtFxF|
VWj@0j
PHy#L#
ltF@@t
M_^3[R
VWj?3EVPi
EP$QRE
urrtOG!ucrt@S
M^33[O
_3[]VmG(|mC
8M_3^N
3_^[M3M
3_^[M3ZM
3_^[M3M
3[M3YL
3[M3$L
t(MQWE
3_^[M3FK
3_^[M3
3_^[M3J
#t8RWAPu
M_^3[JJ
3_^[M3I
PdEHdE.lsEPQ
^]3^]UVF
Vj;h5H
QEzEpBEiyGE.yaE)?E,HE|c
REPQVuh
][U,SVW3SEPMQE
;t+MQSW
_^[]35hUH
_^[]Uh@
EPMj QF
^M_3[C?
]UQSVW
ft#f;uEPWVK
_^[]_^3[]US]
VW33fE
_^[]US]
V33Wft
fu+DC;
_^[]UQS]
E^[]USVW=|@B
VWEPM3Q}}
_^]SVA
;tcUSVR
39}vG{0M
FL;urS;
VW33}}
>@4EEE
>@4E}zt
>@4EUUvuh\rj
>@4EEE@U
>@4EEE
}9}th,
Q_^2[]_^
E_^]3^]U(B
3_^[]_^[]Sh0hB
SVh3ptaB
dWt`x8taB
xO|xl~"``lxaxt
M_^3[N4
SVd3ttaB
xO|x\~"`X\xaxl
QpRhQ`j
M_^3[%3
SVp3taB
3Wltxd$
xO|xh~"`thxaxl
M_^3[C2
SVp3taB
3Wltxd$
xO|xh~"`thxaxl
h4U5Pp
M_^3[S1
SVl3paB
3Wtdx8aB
xO|xh~"`dhxatx
M_^3[R0
SVl3ptaB
3Wtdx8taB
xO|xh~"`dhxaxt
M_^3[X/
SVl3ptaB
3Wtdx8taB
xO|xh~"`dhxaxt
M_^3[d.
SVt3ltaB
pW`\x8taB
xO|xh~"`\hxax`
QlRdQj
M_^3[K-
SVp3taB
3Wltxd$
xO|xh~"`thxalx
M_^3[a,
SVl3ptaB
3Wtdx8taB
xO|xh~"`dhxaxt
M_^3[h+
SVl3ptaB
3Wtdx8taB
xO|xh~"`dhxaxt
M_^3[u*
SVl3ptaB
3Wtdx8taB
xO|xh~"`dhxaxt
hg!zPpl
M_^3[)
SVl3paB
3Wtdx8aB
xO|xh~"`dhxaxt
M_^3[(
SVh3paB
dWt`x8aB
xO|xl~"``lxaxt
hp4kPdp
M_^3[}'
SVp3aB
3Wltxd$
xO|xh~"`thxaxl
M_^3[&
SVl3paB
3Wtdx8aB
xO|xh~"`dhxatx
M_^3[%
SVp3aB
3Wltxd$
xO|xh~"`thxalx
M_^3[$
SVp3aB
3Wltxd$
xO|xh~"`thxaxl
M_^3[#
SVp3aB
3Wltxd$
xO|xh~"`thxaxl
M_^3["
]USVWt$
USVWl$
u 1}$1M(1
ZYE03E
u@1}D1MH1
ULQRU0
ZYEP3E4ET3E8EX3E<E\QR
u`1}d1Mh1
UlQRUP
ZYEp3ETEt3EXEx3E\E|QR
_^[]1USVWt$
USVWD$
_^[]1;
ESV3W;u
j"];~Cj3X
QSjVWp
e_^[M3f
SSSSS#
U SW3j
3Y}]9]
;t5;|"Mx
;v*8CSVh
woVW=B
:t3^[_@
U SW3j
3Y}]9]
;tV;|BMx
YYt"Mx
39]fD~
;v*8CSVhA
!NbQPFJ
S3VW9]
3_^[];t
B:t"Ou
U SW3j
3Y}]9]
fu3_[]
M9]u#WN
Y3MW0u
ft'Ou"+
jPfDJXdf
_#^3[u
VWft1E
YY]jXh0jB
WPWPWv
M_3[j
whu;5XB
8]tEMap<u
TM_^3[
PY^hS=@B
Y%u 0B
USV5@B
3W;to=(B
P`Y9_t
uV:Y_^[]
t4V0;t(W8jYt
Fpt"~l
lVYYYEE
FlvlYE
YYt:V5B
PrYF4t
PdYF<t
PVYF@t
PHYFDt
P:YFHt
P,YF\=
~lt#WY;=B
33_V5p@B
YYt0V5B
ffffffE
YM_3[)
3PPPPP
u,Q ;t
QPvYYu
ItUhtDlt
HHtXHHt
4itqnt(o
t-RPSWO
0@?If90t
;u+(;u
u'~! Ot
`pM_^3[
UQSV?G
t4+t$HHt
ItUhtDlt
HHtYHHt
2itmnt$o
t-RPSWgC
0@@If8
u'~! Ot
`pM_^3[
YYuTVWhA
3]j h kB
3PPPPPV}@Y<v*Vp
^SSSSSyj
;tFtA3
M_^3[j
B:t6t:t't
t4+t$+t
ItQht@lt
3F tBP
itmnt$o
cj0XfQf>
t-RPSW01
u(~"j OzYt
u(~"j0O!Yt
j ONYt
`pM_^3[z
j h@kB
Y+t"+t
+tY+uCc}
Uw\]Yp
u>OdMGd
uwdSUY
EPQEPEj
j@j ^Vl
H3H/5UH
;rSWf9M
YYu,9E
W>+~,WPV
Y/V|Yt
Y}3u;5
YY3BUVH
4V'YYE
F$|3@_^
@;u`3@
uNSW<B
1E3PeuEEEEd
Y__^[]Q
E_^[]E
9csmu)=hB
W34809}
;ud8J
4 3,9E
P4UM`8
DQP C@
,PVEP$
3+4H;M
(PVHP$
(PVHP$
r3VVhU
QH++PPVh
(P+P5P$
\,+48;E
8+0[M_3^Gj
DDDDDDDDDDDDDD
8csmu*x
S^`N`H
j$Y~\d9
QY^`[_^]
5V~f>=Yx
3Y[_^5B
3PPPPP.
UQV3W}
ft;uf t
Bf8\tf8"u8
ft$9Uu
UQQSVWh
V33SfB
[]YY?sJM
;r4PYt'EP
_[^SVW
E3E3;u
tAt2t$
+SVWT$
URPQQhA
t;T$4t
;v.4v\
UVWS33333[_^]
33333USVWj
_^[]Ul$
S3VW;~E
@;u+H;}
39](SSu
]9]tWuu
};~Bj3X
3;t?uWuuu
t"SS9] u
EWTYuKEYe_^[M3
MBu(Eu$u u
ES3VW]9]
39] SSu
EYe_^[M3
M6Fv >v$6v(.v,&v0
v<@v@vDvHvL
Yv4;5\B
PDYF ;
P2YF$;
P YF8;
YvL;5tB
Y^]QL$
UV3PPPPPPPPU
$s ^UV3PPPPPPPPU
EU_^j
f;v6;t
Map_^[;t&;w |j"^0D8]tE`py
<E`p0M
YY]VD$
eE,Xh%A
PuZYYu
;r>PuDYYt/
B(;r3_^[]
UjhHlB
1E3PEd
Eu}hDaB
3M_^3[
t.VEYt"V9
Yt.VYt"V
VYt.VYt"V
]39}~0N
D=VP[YYtG;}|fE
YYM_^3[Uv
PYYt}E
E`p;39]
S3VW;|[;
t6<0t0=B
FGIuX^_]
3USVWUj
P(RP$R
UPjhpA
t:|$,t
;t$,v-4v
UQPXY]Y[
u,6{ ;t
WVYtPUH
^]3PPj
RQMQVp
YY]UWVSM
VnYY;tu
]WVS3D$
Fu^8Mt
MKf3;u"|j
E`p^[9M
|j"W8M
E`p33PPPPP6
[SMQMQp
M_^3[c
E`p3[_^
MN`u#1wj
{@PVS"
E`p3_^[
^VMQMQp
[M_3^=^
_WMQMQp
tS]3K}-
[M_3^P]
et_EtZfu
VVVVVV^j
t*9csmu"A
mVW_^]M
M#\EP3SSSSWEPEPu
E`p3M_^3[Z
M{[EP3SSSSWEPEP
E`p3M_^3[VZUWVu
DDDDDDDDDDDDDD
WO@PWV
PEP"YYEPj
U3PPPPP|WVU33D$
u'339\u
JBtj3Y+@M
}99}r"9U
JBjY+3B\M
3+BL1<
Jy3^jY+
M_3[DN
u'339\u
JBtj3Y+@M
}99}r"9U
JBjY+3B\M
3+BL1<
Jy3^jY+
FWE}MuMMMMMMM9M$u
<+t"<-t
h<+t<-tk}
+t HHt
B:t,1<
+JMtHHt
B:}QMEO?
tEPuEP
}M]U3EE
3f;uAE
f;u!AC
u4}u+e
f;r#33f9EE
[M_3^JB
EAV#f}
W]EEE?E
S3PPPPP
i3f9Ut
EfUu}M
3f;uGE
90t!uuE
EMuUm
HuMu9Et
u4}u+e
33f9EE
UUUUU3##
f;wK3EE9
}fEEEEEf}Z33f9u
Ea3f;u
f~7}x+EMe
EM}Um
H}Mu9Et
u4}u+e
f;r#33f9EE
ufEEEEEfu
~(E]Mm
0K;]sE;]s
EM_^3[\9
K;sE;s3f
SVW}f]3
S3VWEN@
tfM_^fH
HH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
FlsFree
FlsSetValue
FlsGetValue
FlsAlloc
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
(null)
`h````
xpxxxx
`h`hhh
xppwpp
CorExitProcess
Complete Object Locator'
Class Hierarchy Descriptor'
Base Class Array'
Base Class Descriptor at (
Type Descriptor'
`local static thread guard'
`managed vector copy constructor iterator'
`vector vbase copy constructor iterator'
`vector copy constructor iterator'
`dynamic atexit destructor for '
`dynamic initializer for '
`eh vector vbase copy constructor iterator'
`eh vector copy constructor iterator'
`managed vector destructor iterator'
`managed vector constructor iterator'
`placement delete[] closure'
`placement delete closure'
`omni callsig'
delete[]
new[]
`local vftable constructor closure'
`local vftable'
`udt returning'
`copy constructor closure'
`eh vector vbase constructor iterator'
`eh vector destructor iterator'
`eh vector constructor iterator'
`virtual displacement map'
`vector vbase constructor iterator'
`vector destructor iterator'
`vector constructor iterator'
`scalar deleting destructor'
`default constructor closure'
`vector deleting destructor'
`vbase destructor'
`string'
`local static guard'
`typeof'
`vcall'
`vbtable'
`vftable'
operator
delete
__unaligned
__restrict
__ptr64
__eabi
__clrcall
__fastcall
__thiscall
__stdcall
__pascal
__cdecl
__based(
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
GetProcessWindowStation
GetUserObjectInformationW
GetLastActivePopup
GetActiveWindow
MessageBoxW
advapi32.dll
user32.dll
ws2_32.dll
ntdll.dll
winsta.dll
shell32.dllwininet.dllurlmon.dll
Gdi32.dll
gdiplus.dllcrypt32.dllSHLWAPI.dllImagehlp.dll
psapi.dll
olE32.dll
winspool.drv
mpr.dll\
H;^6AA
The scalar for this x is unknown
RIPE-MD160
123456789ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz
%X%X%X%X%X%X%X%X
XXXXXXXXXXXXX
AAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAA
H;^6A@...........91278458.........
NetStatisticsGet
NetApiBufferFree
CryptAcquireContextW
CryptGenRandom
CryptReleaseContext
CreateToolhelp32Snapshot
CloseToolhelp32Snapshot
Heap32First
Heap32Next
Heap32ListFirst
Heap32ListNext
Process32First
Process32Next
Thread32First
Thread32Next
Module32First
Module32Next
CoCreateInstance
!secp256k1_fe_is_zero(&ge->x)
pubkey != NULL
input != NULL
outputlen != NULL
*outputlen >= ((flags & SECP256K1_FLAGS_BIT_COMPRESSION) ? 33 : 65)
output != NULL
seckey != NULL
secp256k1_ecmult_gen_context_is_built(&ctx->ecmult_gen_ctx)
result != NULL
point != NULL
scalar != NULL
0123456789ABCDEF
1#QNAN
1#SNAN
GdipFree
GdipAlloc
GdipGetImageEncodersSize
GdipDisposeImage
GdipCreateBitmapFromHBITMAP
GdipGetImageEncoders
GdipSaveImageToFile
GdipCloneImage
GdiplusStartup
gdiplus.dll
LoadLibraryA
GetModuleHandleA
GetFileSize
SetFilePointer
GetDriveTypeW
HeapAlloc
GetLogicalDriveStringsW
HeapFree
GetProcessHeap
WriteFile
GetFileAttributesW
ReadFile
CreateFileW
FlushFileBuffers
CloseHandle
SetFileAttributesW
GlobalMemoryStatus
FreeLibrary
QueryPerformanceCounter
GetTickCount
LoadLibraryW
GetVersionExW
GetProcAddress
GetCurrentProcessId
GetCurrentProcess
KERNEL32.dll
LoadStringW
DrawTextA
USER32.dll
GetStockObject
CreateFontW
SelectObject
DeleteObject
SetBkMode
SetTextColor
GDI32.dll
PathFindExtensionW
PathFindFileNameW
SHLWAPI.dll
GetLastError
GetSystemTimeAsFileTime
EnterCriticalSection
LeaveCriticalSection
HeapReAlloc
GetCommandLineW
HeapSetInformation
GetStartupInfoW
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
HeapCreate
GetCPInfo
InterlockedIncrement
InterlockedDecrement
GetACP
GetOEMCP
IsValidCodePage
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
DecodePointer
TlsFree
GetModuleHandleW
SetLastError
GetCurrentThreadId
LCMapStringW
ExitProcess
GetStdHandle
GetModuleFileNameW
SetHandleCount
InitializeCriticalSectionAndSpinCount
GetFileType
DeleteCriticalSection
WideCharToMultiByte
GetConsoleCP
GetConsoleMode
FreeEnvironmentStringsW
GetEnvironmentStringsW
RtlUnwind
MultiByteToWideChar
GetStringTypeW
WriteConsoleW
SetStdHandle
IsProcessorFeaturePresent
HeapSize
00P`00P
++}V++}
&&jL&&j
66Zl66Z
??A~??A
44\h44\
11Sb11S
##eF##e
''iN''i
,,tX,,t
;;Mv;;M
)){R)){
//q^//q
`@ `
99Kr99K
33Uf33U
<<Dx<<D
88Hp88H
!!cB!!c
==Gz==G
""fD""f
**~T**~
22Vd22V
::Nt::N
$$lH$$l
77Yn77Y
%%oJ%%o
..r\..r
!>!
>>B|>>B
55_j55_
((xP((x
--wZ--w
:QPQR~AeS~Ae
j:'^:'^;k;k0EE6XXK
8 0U 0vmvm@vv
**&5D&5D
L/FFkk
mzmzCRY
Xt!Xt!Ii)IiDu
Tyxy{X>kX>'q'q2OO
f #}:}:=cJ
1LQ3`Q3bS
dwdwBkk
+NpHhXpHh
E.llR{R{fs#s(rK
W$fU*fU(
I0(0(m##
NiNidee
h4b4b
4.S4.S
]@`@`e^q
HMFMPTTq]
plZrNlZr
=X6-9'6-9
h\!h\[T
[TE$6.:$6.
Oa a ?ZwKiZwK
**<"C<"
&O\r\rgDf;Df;[~4[~C)vC)##h
sJ$}J$
2t)m)"
H7Gd"Gd
?uV},V},"3"3nIN
??,:,:oPx
j_bT~FbT~F
Vo-o->%
}cncy;{; &x
OOnenx~!
Jo6Jo6
)|)|311*?#1*?#
5f5f1tN7tN
vM`CMCQ
Lj,,JFeQ
zG<zGYUs?Us
s7s7<SS
_[_S=o
h>h+8$4,8$4
%w(<I(<I
dVdVc{
U2p2!Hl\tHl\
.?AVtype_info@@
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
FJ-I(31,d;
u$kAt:0P^(
jULh[k8Jl
tJXy,z;
mgUN{Nf
`L>!Z?Ntv
Pu:St.1
BM-%B*
MtLH[=&
k?Nl,x
bv9M?
\~677`(<
N4Qz}%
Y0GSD!
M`F[p(6[p
H_|KN)
ei7T#S6
!G*W2=
@8Ik;8
BK;vPB9!iH
O!<,~s
*v-Vw=/
HH-dZp
_4nrzW"#
f9X:)K7IaA2:'
|Se!BJ
k;ALHg
[i n:~
{0q*)GI.C
O;b@rS9%$
Vg?@/C
y?'4Fkp9
CluUSRa
Zb'_g-A&,<
9lPae[mr5
_xW2oiqg
vjI.4Wh@w3_`.5g]>
rIoi[f#
NKb3)H
1}ZO$o3jb
Y8/Z1p
0#aTf=
~P][Z,3-~
(>Mbawq%^
/$k[qW
G`=.sd?kl
(\@{.Wh
]&8)!&Su&a>f
U'.KL;,1uD
J4$,~
RE(Ajx
1nfB4/S
e}C_i?oa
-ZvVA$
E,)PD6
*BsxpD&D@*4
\HIQpi
y@E<KrryI%2#
[)J-s&>S
eXN]@kB9<
4c:n@3!aU+S<
eF15t]#k)9
6$&6U[WK#
7rt?xQ
snX.dNF7p
qmvbsI?G
Av`g_I01.G
FE";6K{
^sk>X8N
2h <u<8EFCv
wYN!'2&IjN
0Wp6s/
"c7=zv
n]{'/U\+zh
D8t;Z#
:t "VXr1YdwS1
9@];Z
D-+P.2vz
H z()cY
UaO a8
\S2Ljcx
W{%pBEil,
lKc]BR<:%x
YA\{"U
-yw5Ou
Rn-CiU%\|Q>ZV
tr-@RthZ7
]y0~L_
tDuBf7
g>.BkAm#HY
\&c-wV
nvVTQdvp
y1 ;a+/
/"woS&fsj7
'+|*L6%I
Aay5[?
g7ljol_
PV9-c9'~y
b;N,I|vpb
*F([Ff%
VeX}4G
wVOYXzW
^&D{TGB
x733HvXkAAG#
%8%r]0H
=*8<JNj>v
J$.GpEB\7
R_{`4KF8(
msQEF8
lhIF_[\
TMY<V)
He{F6SJ
%Dw9XJ
u6U]\T`E[Q=
|KA$ZN&
nLa-8p
=W5/ 9
Cda0"G=ZE)
GX)!*4.
U2YJpF^(;
G:GMb1
LFz`f|'u
ydfyODRR]u
VaeT$Wreqd
$+7FjJ
/iDZa*
j#UH+*
McfKKA"
R^7Z$3\L
AbQD2pp
!khV&ggVc
;N're:
+qMkY(
3O]&wa|4n
l@Pv[f
X|Uz|\
bIZH#dK?o
J$.$BB-
~Mqtxwr;
5.:y:oWP\|NQ
0n3kS-zk
VftSG&
d;4^la*B
N;1's{
<6Rz?e
=$qwc%
H=0SLb
Dj!4@m1
FXK3FPpg3@
grxGw]Q
FXc8Ep
L1lQ$vCm
YAxm7<V3N&
@1,\Z-
5u?okR &It
O7N6>RFA$
BJq(p0z"<@
0/(,'kQWjnB(
s_K!?AL
]?^]-Rh-yU
j,TV{c
rm3\pj
3}|03{*
VgZs"
slLbF{Q{
[9`IIN
<q2 kw
:?n`ed
kNH#0sYqU{
rt_\8CE+KsK`
bMCGt[-{
`x33cy
-SY`+E=T
QAe]N,
2|36,[
iDKZ?L]_>;=
'I")&5
Yob%i2)'hdl6i{q
[6OAxpW
+RdTh-Dy;
%3!6_K
;=Fj\o0,l1#)
f=gBl4,:gz$r
Mv=V|}[
!-S0\bz
L23RqY
.NHf;|4`+
qOquP
nrcUL
hGXy)~o
Z1]3Q?[
Obs9xcUU}
%4M&c"T
<|,=gE}0u;
EBJH1?h_
xKhAB,D
u!c.,l2_3
X~<Y:duis
LD_W~5
c#bCP=
.1Cu{TV
aI,`8VQ
8"WHth
?<vO}?2^}q
v))Xfjf]{
=W7L`NRgTWH~6
9$Zc%{
``QuoF
buOT39
w`|$q>p
/ e}h5
eA>3MK
TzNPt+<
='bM.6p!
zqjp2d
tU2[6eQ
6>UAOWgAmm
<e:b`p
Bj&A$vc%SG
+nn;ehx`_j]]F
zj8nHQ2m
l;@svfI^3
FxGT3NcM
O*XAJVl
kI+aP\vC8t0
R'1QuC&
egc{oSb
RmQ")iJ
nqNHNS^
M8"A25"V
SYvI:p
=RCKD!5,LmMZ;C
FPJg]LAz)<b:f!
5]">{Cthn!M*}8E+q,O#U|-
!]RHTJ
%_zEz,pY~!x$o+RymQ%,gq
'd \]NsKYZ@^
YKbz:Gm
g,w-mkR
D^<iP&>
ug P5g6Mkq{V
`Up)bsenHsa6[5
n\i8O\Bk
QX|hEh
_/m|3=(
1iez|BtCCSC
nn="M>m
8?mLRJ
M=k_y%U
h w[uCs
-Aix@D
j4?2LA5a!<oY
&mDA'M
<[!S1-
)VPz^[2
l?]3SW
3Zy45W]6ATpmV
kI@4d~'
zpBiyG.ya)?,H|c
.?AVGdiplusBase@Gdiplus@@
.?AVImage@Gdiplus@@
.?AVBitmap@Gdiplus@@
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
?Zd;On
7?3=Bz
;1az?aUY~S|
D?$?9'
*?}d|FU>c{
zc%C1<!8G
u7.:3q
#2IZ9W
,%I-64OSk%Y
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING
01X23333
4"4)40474>4E4L4S4Z4a4h444,5054585<5@5D5H5L5P5T5X5\5`5d5h5l5p5t5x5|55
6666]7p7
88$9E9L9d99
>9>M>c>x>>>6?b???????
0R0X0k00000061<1111=2H2222L3W3333K4V4444=5H5555
6A6]66666
7Q7V778888
99'969\9e9v99999
::::S;;;R<<<======
>$>,>4><>C>N>p>>>>>#?4?
-0R00000000000
1$1)1:1Z1
5:5Q5r555Q6_6
7+727R7
77777777777777?8b9::s;
<!<B<<<
=7=Z===
>7>T>>>
?7?T???
000S000*1Y1111J2g2222J3a3333M44-88
<&<.<6<?<E<K<Q<W<_<z<<<<<<<<<
==*=;=o=
?"?(?8?@?S???
0 0(0V0`0~0000000000
2D2J2v22233333
414:4?4m444444444
5"515_5n5w5|555555M6Z6d6p6|666666666m777
8c88;9~9999999999998:E:N:U:^:c::::::
2J3P3g3t3|33333q555555656?6J6[6|6
7A7V7g7t7}77777777 8W8e8p888879
:5:Q:n::
;Z;;;;
<=<G=Q=s==
>^>h>o>w>
?+?1?7??
1n1y11
2$22222
W::g<z==>J??
1*11j5
8.8':*;;;
<*<W<<
=/=j==
>2>g>>
j00001111
2%22282>2H2\2k2w2222s3~333333555555
6.6p6w6
717G777>888849J9c9z999999999J:x:::::
;$;+;2;;;{====
>I>>>)?8?
111n2222*3C3v33?4K4^4444
5 5'5/575>5Z5w55
6j666+767777+868z888
9&9j999
;Z;w;;;
>Z>w>>>
?J?g????
:0W0t000:1W1t111:2W2z222:3Q3r333*4G4d444
515R555
6!6B6666
72777h8r8|888888888888
959?9I9S9]9g9q9999999999
: :*:4:>:U:_:i:s:}::::::::::
;";,;6;@;J;Z;d;n;x;;;;;;;;;;
<'<1<;<E<i<s<}<<<<<<<<<<<<
=6=@=J=T=^=h=r==========
>!>+>5>?>V>`>j>t>~>>>>>>>>>>
?#?-?7?A?K?[?e?o?y??????????
0(020<0F0j0t0~000000000000
171A1K1U1_1i1s1111111111
2"2,262@2W2a2k2u2
222222222
3,3D3T3d3r333333V4c4v444444
5%585H5z5555555
6<6I6\6l666666
7.7^7k7~77777788E8X8h88888
9+9>9N999
:#:-:E:O:Y:c:m:}:::::::::::
;';1;;;K;U;_;i;;;;;;;;;;;;
<#<-<7<[<e<o<y<<<<<<<<<<<<
=)=3===G=Q=[=e=}==========
>>)>3>K>U>_>i>s>>>>>>>>>>>
?#?-?7?A?Q?[?e?o???????????
00)030=0a0k0u0
00000000000
1/191C1M1W1a1k11111111111
2%2/292Q2[2e2o2y22222222222
33)333=3G3W3a3k3u3333333333
4%4/494C4h4u444444444
5,5<5L5\5555555
6 6'656<6G6N6Y6`6q6x66666666666666
7(7/7:7A7L7S7d7k7y77777777777777
8"8-848?8F8W8^8l8s8~8888888888888
9 9'92999J9Q9_9f9q9x999999999999
:#:*:5:<::::
;p;x;;;;?
00000:4c447
878=8W8f8s8
88888888
9!9G9z999999b:i:::2;8;D;{;;z<
>;>J>R>_>k>w>}>>>>>>>I????????????
0"0.070<0B0L0U0`0l0q000000000011
2N2Z22
3444444
5>5I5S5l5v5555
8$868Q8Y8a8x88888888
9)9:9N9991::H;v;;
<R<<<<<<<<<<<<<<<<
=@=U={======
>%>K>>>>*?2?|?????????????????
0 0/0E0K0S0X0`0e0m0r0y00000000
1K1]1=2G2T22222k4r4
5555F6U6p69:;<<h<<i>
00000000*111
2j2225618t888:<<<<<<<<<<
=,=========
>)>4>N>Y>a>q>w>>>>>>
0R0j0t0000000
121O11111
234447
9b::::<*?.?2?6?:?>?B?F??????
0d0i00000000/181>122223&3;333333
4A4S4444444 5)555n5w55555555
79777777
8@8G8`8t8z88888N9n999q:::;;;;N<o<<q==>>
2L2b222_333Z444444444
5-54585<5@5D5H5L5P555555
686?6D6H6L6m6666666666667<7@7D7H777,979v999
:+:6:;;;;;:<A<V<<<<<<<!=.=:=B=J=V=
===E>Q>\??
0\001?2b2266
7.7T7f7x77777777
8,8?9E9O9999
:F:n::\;
;;;;;;<<(>_>e>j>x>>>>>
?$?3?V?[?`?w?
0000%1H1S1Y1i1n1
11111111111111)2C2]222222
3\334V55b66666@7M7l77777+8S8l88888
9)96:;:\:::E;_;h;q<w<==
>E>O>g>>>>?????
2 2&2*2/25292?2C2I2M2S2W25
6N6;o<)>
z00000000
1/1M1T1X1\1`1d1h1l1p11111122=2X2_2d2h2l22222222
3V3\3`3d3h3 5
7788G9(:::g;m;{;
<.<h<<==>y?
0000h1
5\8`8d8h8l8p8t8x8|88888W9
9999!:
(47777
1111111
2????????????
0$0,040<0D0L0P7T7X7\7`7d7h7l7p7t7x7|777777777777777777777777777777777
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8888888888888888888888
d3l3@8D8H8L8P8T88888888
9 90949D9H9L9P9X9p999999999999(:D:H:h::::::
;8;X;x;;;;;
< <@<\<`<<<<<<
0(000X8X9\9`9d9h9l9p9t9x9|999999999999999999999999999999999
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|::::::::::::::::
;(;8;H;X;|;;;;;;;;;(=,=0=4=8=<=@=D=H=L=X=\=`=d=h=l=p=t=x=|===============
@V`w`/
x\`wP0
(]`wx0
CNwBNwBNwBNwBNwBNwBNw
6YKU`)
CNwBNwBNwBNwBNwBNwBNw
M(i+*<&
vt9v`9v<9v
87vX'9
ANwANwd@Ow
@r|0r|
r|PD98
P`wP`w
AV3FnpCE
AV3FnpCE
AV3FnpCE
0`w0`w
AV3FnpCE
X`wlld.@
|||||||$#|e
hNw8f9
ANwANwd@Ow
ANwANwd@Ow
^0OzIj
DdwDdwE
bGm|)?
(s| Y|
r|r|r|h
ALLUSE~1
{wtwuw
DOCUME~1
ALLUSE~1
SrvSetOs2FeaList: Sr
ANwANwd@Ow
8[| Y|
Z|lZ|XZ|8Z|Z||Z|
Z|L0|<0|\0|P
8[| Y|
Z|lZ|XZ|8Z|Z||Z|
Z|L0|<0|\0|
@r|0r|
r|PD98
URNXYMAV
Desktop
Z|lZ|XZ|8Z|Z||Z|
Z|L0|<0|\0|
WINDOWS
system32
cmd.exe
ALLUSE~1
Desktop
i?!kH`
WINDOWS
system32
cmd.exe
LUSE~1
Desktop
i?!kH`
DOCUME~1
ALLUSE~1
cmd.exe
Z|lZ|XZ|8Z|Z||Z|
Z|L0|<0|\0|
DOCUME~1
DOCUME~1
DOCUME~1
Z|lZ|XZ|8Z|Z||Z|
Z|L0|<0|\0|
DOCUME~1
ALLUSE~1
ALLUSE~1
MYDOCU~1
URNXYMAV
MYDOCU~1
DOCUME~1
DeleteOnCopy
DeleteOnCopy
PersonalizedName
DeleteOnCopy.A
DeleteOnCopy
Personalized
.ShellClassInfo
PO :i
DOCUME~1
URNXYMAV
MYDOCU~1
DOCUME~1
.ShellClassInfo
LocalizedResourceName
DOCUME~1
ALLUSE~1
Desktop
i?!kH`
DOCUME~1
ALLUSE~1
DOCUME~1
i?!kH`
@shell32.dll,-21785
PO :i
DOCUME~1
ALLUSE~1
DOCUME~1
i?!kH`
@shell32.dll,-21785
PO :i
DOCUME~1
URNXYMAV
Desktop
PO :i
DOCUME~1
ALLUSE~1
Desktop
i?!kH`
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
WINDOWS
system32
WINDOWS
system32
L!This program cannot be run in DOS mode.
YYY_Y^
[XmXRichY
`.data
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
BBHH:mm:ss
dddd, MMMM dd, yyyy
MM/dd/yy
December
November
October
September
August
February
January
Saturday
Friday
Thursday
Wednesday
Tuesday
Monday
Sunday
(null)
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- not enough space for locale information
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- CRT not initialized
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
- abort() has been called
- not enough space for environment
- not enough space for arguments
- floating point support not loaded
BMicrosoft Visual C++ Runtime Library
<program name unknown>
Runtime Error!
Program:
((((( H
h(((( H
H
WUSER32.DLL
CONOUT$
ADVAPI32.DLL
KERNEL32.DLL
NETAPI32.DLL
LanmanWorkstation
LanmanServer
Ole32.dll
__uuewr__jfj
wlrmdr
Shell32.dll
bssimg
ComSpec
Tahoma
BBBBBBBBBB
BBBBBBBB
VS_VERSION_INFO
StringFileInfo
042104b0
CompanyName
TODO: <Company name>
FileDescription
TODO: <File description>
FileVersion
1.0.0.1
InternalName
TODO: <Internal name>
LegalCopyright
Copyright (C) 2016
OriginalFilename
TODO: <Original filename>
ProductName
TODO: <Product name>
ProductVersion
1.0.0.1
VarFileInfo
Translation
C:\Documents and Settings\All Users\Documents
ware access rights are determined by the access rights of the user.
:\WINDOWS\Registration\R00000000000b.clb
\WINDOWS\Registration\R00000000000b.clb
_R_00000000000b_SMem__
egistry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
CLSID\{E436EBB3-524F-11CE-9F53-0020AF0BA770}
lows programs to execute as a user that does not have Administrator or Power User access rights, but can still access resouces accessible by normal users.
\WINDOWS\system32\urlmon.dll
C:\WINDOWS\system32\quartz.dll
C:\Documents and Settings\URNXYMAV\Local Settings\Temporary Internet Files\OLK*
ers\Cache%OLK*
\WINDOWS\system32;C:\WINDOWS\system32;C:\WINDOWS\system;C:\WINDOWS;.;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
C:\WINDOWS\system32\quartz.dll
C:\WINDOWS\system32\quartz.dll
C:\Documents and Settings\URNXYMAV\My Documents
C:\Documents and Settings\URNXYMAV\Application Data
CLSID\{CDA42200-BD88-11D0-BD4E-00A0C911CE86}
?\IDE#CdRomNECXXWar_XXware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
CLSID\{D76E2820-1563-11CF-AC98-00AA004C0FA9}
C:\WINDOWS\system32\qcap.dll
C:\WINDOWS\system32\qcap.dll
f32d3b0\b662ef49.exe
INDOWS\INF
C:\WINDOWS\SYSTEM
C:\WINDOWS\LastGood
INDOWS\system32
\WINDOWS\system32\ReinstallBackups
INDOWS\system32\DRIVERS
\windows\ServicePackFiles\ServicePackCache
ntsvcs
stricted
\??\C:\WINDOWS\TEMP
YMAV\LOCALS~1\Temp\
\??\C:\TEMP
?\C:\WINDOWS\system32\cmd.exe
Zone.Identifier
on Data\wlrmdr.exe
\Documents and Settings\URNXYMAV\Application Data\wlrmdr.exe
?\C:\bf32d3b0
ystem32\cmd.exe
1\Temp\
llowed
ware will not run, regardless of the access rights of the user.
lows programs to execute with only access to resources granted to open well-known groups, blocking access Administrator and Power User privileges, and personally granted rights.
ricted
c User
ftware\M
n\Expl
\Shell
?\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
\\?\STORAGE#Volume#1&30a96598&0&Signature210D210COffset7E00LengthFF6D1400#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
\\?\Volume{0cb69fff-0b12-11e1-b22f-806d6172696f}\
a;C:\WINDOWS\sys
C:\WINDO
stem32;C:\WI
S;C:\WINDOWS
?\Volume{0cb69ffc-0b12-11e1-b22f-806d6172696f}\
\WINDOWS\system32\cmd.exe
C:\bf32d3b0
"C:\WINDOWS\system32\cmd.exe" /c DEL C:\bf32d3b0\b662ef49.exe >> NUL
"%1" %*
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\cmd.exe
Windows Command Processor
Software\Microsoft\Windows\CurrentVersion\App Paths\cmd.exe
Software\Microsoft\Windows\CurrentVersion\App Paths\cmd.exe
\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\.exe
All Users
rpcrt4.dll
ncacn_np
Documents and Settings
All Users
C:\WINDOWS\system32\urlmon.dll
2-egelege
CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}
INDOWS\setupapi.log
C:\Documents and Settings\URNXYMAV\Desktop
egistry\Machine\Software\Classes\CLSID\{7B8A2D94-0AC9-11D1-896C-00C04FB6BFC4}\InProcServer32
egistry\Machine\Software\Classes\PROTOCOLS\Name-Space Handler
ses\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\InprocServer32
Security=Impersonation Dynamic True
egistry\Machine\Software\Classes\PROTOCOLS\Name-Space Handler\*
\WINDOWS\system32\Secur32.dll
Documents and Settings
URNXYMAV
Desktop
egistry\Machine\Software\Classes\Drive\shellex\FolderExtensions\{fbeb8a05-beee-4442-804e-409d6c4515e9}
chine\Software
sses\Sys
lex\FoExtensions
INDOWS\Driver Cache
Desktop
WINDOWS
system32
cmd.exe
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0
egistry\Machine\Software\Classes\.exe
Documents and Settings
All Users
Desktop
WINDOWS
system32
cmd.exe
ncalrpc
INDOWS
C:\Documents and Settings\URNXYMAV\Local Settings\Temporary Internet Files
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1
All Users
Desktop
Directory
INDOWS\inf
\bf32d3b0
tiveFontCtl
C:\WINDOWS\system32\cmd.exe
Documents and Settings
All Users
\??\C:\Documents and Settings\All Users\Documents\desktop.ini
\\?\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
\\?\IDE#CdRomNECXXWar_XXware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
\\?\STORAGE#Volume#1&30a96598&0&Signature210D210COffset7E00LengthFF6D1400#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
n\??\FDC#GENERIC_FLOPPY_DRIVE#6&1435b2e2&0&0#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\Floppy0\??\Volume{0cb69ffc-0b12-11e1-b22f-806d6172696f}\DosDevices\A:
\??\IDE#CdRomNECXXWar_XXware_IDE_CDR10_______________1.00____#3031303030303030303030303030303030303130#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{0cb69ffd-0b12-11e1-b22f-806d6172696f}\DosDevices\D:696B?
\WINDOWS\system32\cmd.exe
e1-b22f-806d6172696f}
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}
y Documents
URNXYMAV
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\exefile\CurVer
cmd.exe
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\
Documents and Settings
Documents and Settings
Documents and Settings
Documents and Settings
All Users
All Users
021b888-14a2-4219-8812-31b4a9370c33}
My Documents
URNXYMAV
URNXYMAV
My Documents
URNXYMAV
?\Volume{0cb69ffd-0b12-11e1-b22f-806d6172696f}\
Invalid
?\STORAGE#Volume#1&30a96598&0&Signature210D210COffset7E00LengthFF6D1400#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
?\Volume{0cb69fff-0b12-11e1-b22f-806d6172696f}\
Documents and Settings
\WINDOWS\system32\cmd.exe
\??\C:\Documents and Settings\All Users\Documents\desktop.ini
Documents
\??\C:\Documents and Settings\URNXYMAV\My Documents\desktop.ini
\??\C:\Documents and Settings\URNXYMAV\My Documents\desktop.ini
\??\C:\Documents and Settings\URNXYMAV\My Documents\desktop.ini
\??\C:\Documents and Settings\All Users\Documents\desktop.ini
egistry\Machine\Software\Classes\Applications\cmd.exe
003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\TreatAs
My Documents
URNXYMAV
Documents and Settings
URNXYMAV
My Documents
URNXYMAV
Documents and Settings
\??\C:\Documents and Settings\All Users\Documents\desktop.ini
Documents and Settings
All Users
Desktop
Documents and Settings
All Users
(Documents
Documents and Settings
All Users
(Documents
C:\Documents and Settings\All Users\Desktop
C:\Documents and Settings\URNXYMAV\Cookies
Documents and Settings
URNXYMAV
Desktop
\Documents and Settings\URNXYMAV\Cookies
Documents and Settings
All Users
Desktop
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\CLSID\{7b8a2d94-0ac9-11d1-896c-00c04Fb6bfc4}\LocalServer
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
ware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3
C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\
C:\WINDOWS\system32\urlmon.dll
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\PROTOCOLS\Name-Space Handler
\WINDOWS\system32
egistry\Machine\Software\Classes\exefile
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
ftware\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3
Software\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4
OTOCOLS\Name-Space Handler\*\
FTWARE\Classes\PROTOCOLS\Handler\C
\Documents and Settings\URNXYMAV\Local Settings\Temporary Internet Files
WINDOWS
system32
WINDOWS
system32
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003
on\AppCompatFlags\Layers
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\exefile
EGISTRY\USER\S-1-5-21-2052111302-484763869-725345543-1003_Classes\exefile\shell
C:\WINDOWS\system32\cmd.exe
RNEL32
\WINDOWS\system32\cmd.exe
\WINDOWS\system32\cmd.exe.Manifest
:\WINDOWS\system32\cmd.exe.Config
CompanyName
Microsof
??\C:\WINDOWS\system32\cmd.exe.Manifest
??\C:\WINDOWS\system32\cmd.exe.Config
0 (xpsp_sp2_rtm.040803-2158)
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
Cmd.Exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.2180
VarFileInfo
Translation
arFileInfo\Translation
tringFileInfo\040904B0\OriginalFilename
imEng.dll

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.