0.9
低危

11ac1b155bf36e2acfe1a7798985c2cb7572a05445969699c6bf2d5cc90c56a5

11ac1b155bf36e2acfe1a7798985c2cb7572a05445969699c6bf2d5cc90c56a5.exe

分析耗时

194s

最近分析

371天前

文件大小

894.4KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN WORM CAMBOT
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.62
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Banker-IZK [Trj] 20200318 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200318 2013.8.14.323
McAfee W32/Generic.worm!p2p.c 20200317 6.0.6.653
Tencent Malware.Win32.Gencirc.10b0cdf5 20200318 1.0.0.1
静态指标
行为判定
动态指标
网络通信
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
文件已被 VirusTotal 上 64 个反病毒引擎识别为恶意 (50 out of 64 个事件)
ALYac Trojan.GenericKD.30598445
APEX Malicious
AVG Win32:Banker-IZK [Trj]
Acronis suspicious
Ad-Aware Trojan.GenericKD.30598445
AhnLab-V3 Worm/Win32.VBNA.C148121
Antiy-AVL Worm/Win32.VBNA
Arcabit Trojan.Generic.D1D2E52D
Avast Win32:Banker-IZK [Trj]
Avira TR/Dropper.VB.Gen
BitDefender Trojan.GenericKD.30598445
BitDefenderTheta AI:Packer.D46BABB31F
Bkav W32.HfsOval.
CAT-QuickHeal Worm.Cambot.A3
ClamAV Win.Trojan.Blackshades-6327385-1
Comodo Worm.Win32.Cambot.A@74gte2
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.7965bc
Cylance Unsafe
Cyren W32/VBInject.AM.gen!Eldorado
DrWeb BackDoor.BotSiggen.51
ESET-NOD32 Win32/Spy.VB.NNI
Emsisoft Trojan.GenericKD.30598445 (B)
Endgame malicious (high confidence)
F-Prot W32/VBInject.AM.gen!Eldorado
F-Secure Trojan.TR/Dropper.VB.Gen
FireEye Generic.mg.9085a8d7965bcf9e
Fortinet W32/BotSiggen.AQO!tr
GData Win32.Backdoor.Ainslot.C
Ikarus Worm.Win32.Cambot
Invincea heuristic
Jiangmin Worm/VBNA.hbyc
K7AntiVirus Spyware ( 000537701 )
K7GW Spyware ( 000537701 )
Kaspersky Trojan.Win32.Llac.llzl
MAX malware (ai score=82)
Malwarebytes Spyware.PasswordStealer
MaxSecure Trojan.Llac.LLZL
McAfee W32/Generic.worm!p2p.c
McAfee-GW-Edition BehavesLike.Win32.Shadebot.cm
MicroWorld-eScan Trojan.GenericKD.30598445
Microsoft Worm:Win32/Cambot.A
NANO-Antivirus Trojan.Win32.VB.eccndn
Panda Trj/Genetic.gen
Qihoo-360 QVM41.1.Malware.Gen
Rising Worm.Cambot!8.206F (TFE:dGZlOgOuNbOUBftuYw)
SUPERAntiSpyware Worm.Cambot/Variant
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Mal/VB-AQO
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2011-06-29 08:05:34

PE Imphash

3e8ae3bc85823ef9afa9731fe8e9fda0

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0002e5e8 0x0002f000 6.458714013554687
.data 0x00030000 0x000023dc 0x00000000 0.0
.rsrc 0x00033000 0x00000010 0x00001000 0.0

Imports

Library MSVBVM60.DLL:
0x401004 MethCallEngine
0x401008 EVENT_SINK_Invoke
0x40100c None
0x401010 None
0x401014 None
0x401018 None
0x40101c None
0x401020 None
0x401024 None
0x401028 None
0x40102c Zombie_GetTypeInfo
0x401030 None
0x401034 None
0x401038 None
0x40103c None
0x401040 None
0x401044 None
0x401048 None
0x40104c None
0x401050 None
0x401054 None
0x401058 EVENT_SINK_AddRef
0x40105c None
0x401060 None
0x401064 DllFunctionCall
0x401068 None
0x401070 EVENT_SINK_Release
0x401074 None
0x40107c __vbaExceptHandler
0x401080 None
0x401084 None
0x401088 None
0x40108c None
0x401090 None
0x401094 None
0x401098 None
0x40109c None
0x4010a0 ProcCallEngine
0x4010a4 None
0x4010a8 None
0x4010ac None
0x4010b0 None
0x4010b4 None
0x4010b8 None
0x4010bc None
0x4010c0 None
0x4010c4 None
0x4010c8 None
0x4010cc None
0x4010d0 None
0x4010d4 None
0x4010d8 None
0x4010dc None
0x4010e0 None
0x4010e4 None
0x4010e8 None
0x4010ec None
0x4010f0 None
0x4010f4 None

L!This program cannot be run in DOS mode.
sisisi
ldsiRichsi
`.data
bs_bot
`=7I,f&.
Ht*N"/Wd!:O3f
tmrDoWork
tmrDDoS
tmrBrowser
tmrSpara
tmrUpdate
tmrPersistence
tmrCommands
tmrGrabber
tmrSock_timeout
tmrAlive
VB5!*
Microsoft
bs_bot
`=7I,f&.
<WA\yY{
.L?kGb
l;J*JFh'o
mswinsck.ocx
MSWinsockLib.Winsock
Winsock
f=3@aB
f=3H2B
f=305B
bs_bot
mDefines
mFuncs
mBotKiller
mWebcam
mSpread
fSteam
t*N"/Wd!
F6k7;y
`=7I,f&.
6*O3f
tmrUpdate
+3qTheBrowser_BeforeNavigate2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
tmrSock_timeout
tmrSpara
tmrDoWork
tmrGrabber
tmrAlive
tmrPersistence
tmrDDoS
MTheBrowser
C:\Windows\SysWOW64\ieframe.dll
SHDocVw
tmrCommands
BROWSER_FB
tmrBrowser
TheBrowser_OnQuit
FORM_GRABBER_REPORT
KEYLOGGER_REPORT
IMAGE_REPORT
PASSWORDS_REPORT
STEAM_REPORT
EMAILS_REPORT
FILE_EXISTS
BROWSER_FB_DocumentComplete
BROWSER_FB_OnQuit
FACEBOOK_START
E;9:u9kL
+3q"=h
RegOpenKeyA
,SIfwg
kernel32.dll
GetTickCount
user32
GetForegroundWindow
GetWindowTextA
SendMessageA
kernel32
GetVolumeInformationA
GetLocaleInfoA
advapi32
RegCreateKeyA
RegSetValueExA
RegDeleteValueA
RegCloseKey
MoveFileExA
WinInet.dll
InternetOpenA
InternetOpenUrlA
txtAccName
InternetReadFile
InternetCloseHandle
WaitForSingleObject
CreateMutexA
CloseHandle
ReleaseMutex
GdiplusShutdown
DeleteUrlCacheEntryA
urlmon
URLDownloadToFileA
LoadLibraryA
CallWindowProcA
GetProcAddress
SetFilePointer
FlushFileBuffers
CreateFileA
WriteFile
GetFileSize
advapi32.dll
RegOpenKeyExA
RegEnumValueA
RegQueryValueExA
RegEnumKeyExA
RegDeleteKeyA
FindWindowA
msvbvm60
__vbaCopyBytes
ExitProcess
GDIPlus
GdipCreateBitmapFromHBITMAP
GdiplusStartup
CLSIDFromString
GdipSaveImageToFile
GdipDisposeImage
BYFZSGyh
CallNextHookEx
SetWindowsHookExA
UnhookWindowsHookEx
ToUnicodeEx
VBA6.DLL
GetWindowTextLengthA
GetKeyboardState
GetKeyState
GetAsyncKeyState
RtlMoveMemory
GetWindowDC
CreateCompatibleDC
CreateCompatibleBitmap
gdi32.dll
SelectObject
DeleteDC
ReleaseDC
DeleteObject
olepro32.dll
OleCreatePictureIndirect
StretchBlt
SetStretchBltMode
user32.dll
GetWindowRect
avicap32.dll
capGetDriverDescriptionA
capCreateCaptureWindowA
zx}E&CoCe%H
tmrKill
tmrFocus
imgLoginPressed
imgLogin
txtPassword
imgSteam
imgRemember
imgMinimize
imgClose
SetWindowPos
GetCurrentProcessId
AdjustTokenPrivileges
RtlAdjustPrivilege
LookupPrivilegeValueA
GetCurrentProcess
OpenProcess
OpenProcessToken
Process32First
Process32Next
TerminateProcess
VirtualQueryEx
ReadProcessMemory
GetModuleFileNameA
GetModuleHandleA
CreateToolhelp32Snapshot
Thread32First
Thread32Next
TerminateThread
OpenThread
ntdll.dll
NtQueryInformationThread
NtSetInformationProcess
PSAPI.DLL
GetModuleFileNameExA
EnumProcessModules
GetSystemInfo
SetForegroundWindow
GetWindowThreadProcessId
shell32.dll
ShellExecuteA
EnumWindows
ShowWindow
BringWindowToTop
SetFocus
PostMessageA
keybd_event
wUcl;J*JFh'oDDOS
JC:\Program Files (x86)\Microsoft Visual Studio\VB98\vbc14663.oca
MSWinsockLib
tmrTCP
UDPSocket
tmrUDP
UDPFlood
CallWindowProcW
^HKlYF;(4
wUcCz/A
qR^:O3f
UDPSocket
MSWinsockLib.Winsock
MSWinsockLib.Winsock
tmrUDP
tmrTCP
zx}E&CoC:O3f
fSteam
tmrKill
tmrFocus
txtPassword
Tahoma0
txtAccName
Tahoma0
imgLoginPressed
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
`03?K7
w]M{{
MJEYTXoR
SxF{Ap
n'omX$"sI
w]OQP
.F2.e^
<=N7i#YG*
kUDz|:XYi[$h=:
SxAZ>#xR
u>63Os-m/
3O;y!]
$-'VR0f-`
x|YOj+
]SM<$"FX
_7G-ozi+
'bk-NMP
?xW?5|_
p=n*+)A
q\=$I#
imgLogin
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
->g{<]=s9/*1
wQ\V:c-
2PNhZ6ko4XE
-Rk9$Xi#
/}|?.x?
~` .4@%\+
F?:%gc
?j_q?:nu^~
W+?:?@\'
?j_q?:
JqOc|a
F'v@0OC
,v^ku
7]^=
imgRemember
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
/7Oq=7.3
L,t}OZQ
V 2y/^iq,r V
}yWD6\
Lm*t?o
x{LO_lllP[s
QkWR0A
{9J(2?
imgClose
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
0F?;n (
imgMinimize
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
g;zt^:
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
2[ZDq+T
(Z{^YZ-
6Xh"!I!H$
D/u/w
k}B-QV
,9X&Ds>a(s_
pXos.t
#U_rK!(?
:E{P[izijqt
c7_hc2
,FAb~tK^g?[
[\h*Em
(-u{+tNO}
$]"o4$
t2yq,@
dw=u/O
~w3U=
V'8 Yd
thntJ+
v* :wz
swD:Q^
=wgx_E;b
][|45YlDai3
&HsSN7=>
0O"LT^[xm
Vi<icU
~)xL-G[HOP-H0q
_5vLu Q
d\os~!;|M{xS
"ega4ec
_KXtRH
iqm-v5
WKnf~;;
jWQxPm7:n{
$3M&AXx\[(n`9@
+7Z|G{]_NA{ZYd
)~mXkz^*6o(Sp
Q6COyyM
[,}d;}
k?5XQ`6
}(t5h(/1/9
ED%$B.
Ski$RxwW
x#wmgJ>
4Rj:J^
:TKyivh
>n?GEo}uZ%Tf-]
o[(u*`2t;O
w=![\jxPxn]J(#6kD
l5 LuH8
wZo@BK1
KimmeXr9
]o_g)IvnNpgX
(~T5sXQ.$
fi9I%
~V%~}kc'c
X>+h#OM
QhkF[vk
.x4=AgwqD'
FDwJciu
$~[k:(
n,N/ VR
|gmj@eqbqqi<
Bl"O?|/
o,|E}
S+o=Uo%y
g-x:W45
+|K$2X?S
!=>6{{:E$
4Q])Fxd
~)_m<_k
_V|Z[\$
6~ Tx.~Q
'/>+i-Kt
>fESjy
o>~)O7R
RZsBE0#G0f
uZ(Py"(
QR|!\j~3
Q_ixz#
YpsF:9_D=Vw
_Q$|<>(
`6b++{
PL0hl*
ncFKI7
J!14J;DJ X~IY
VG32v,"%N
\=Cu4
2A"2"neUs
xv[KMsF
d,'XMM
[\i]:sy
Xo0&WHny`|
4n-n>a
wkxY`d?
j|E}]?
!K8;\)^w#?u1u `$!-!d{2
6w 'V
k,F(QjL
"z__A[
_|N6EDVwr
fuo6[K
|kM+Nm
R[kE-D
dwL$I\
|*.5gc~
H16t3G[
b:UG+{
jz705O
?EkF5?
>&i-7 Z(m1g`
^.;kQ"y)RiT|MC7Iiq&
|T"72_HN3;+1
{(/!@[
!w2d8ub
t#IHV7
\ZY![99m<
h[\cAuEcMi
54wom/nmZ
o~|1aW
M(x' _
5'>(O]Vi
oC!'L|
EIUwxZ
C~_E;b
hr2gxj#Z
Q_wXz
~x_E;b
|IY,#qaMs
Mgql<asi[XR
z([[Iyq
RM:m6[{
`>q>`<
e9drZoe|
e'<=j\\Z
&j$$S,
{7:5{k
B[(Xdy?^
m/W_Vyg
}'qz-awuois=M
L+0E.aAb
\7FAzM
ukWM&6h
~*k:%59l
=OxGVayiz
p29\E}I{
t+Or66Y3
hyli?-
nNoEhB
ZB%ec" CJ
H16t3G[
b:UG+{
|;gWPcI+=O1
LjyI;ctqYx
:"'2G6b9&Um?V
7V#\^q
w~&Xx,hn3l
`m.;c?*
HhU"hW
n#LU],b
Z7tkwlu
\.oego
uKme~t`l
}$|km.4K
xR|3;BVth
ereKpM
uuQ.bXY)2
sm;.c~)o
_!JM+3
[c4skOs(@^C'W
V#Enl{gV."fSRH#
wI.Z6J?
}Eo>W:OJ?[q\O{W^9K.zSj+
q_}/Xz
~x_E;b
~I<AVVVosv6
^Iqj7e
j:(Cq}r
hr2gxj#Z
bW9rZ*1w
*9%9J)
GEK)4a7hr
}{Hw+V
~[))aa
(5?a3Duc
+SeTV
x6+3:d
+XX'\If
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
TfsVvV]
1$QTrI
9#%YX`
\;*rcL
g?`?:_*
tU\|O]J{
y7^/?
7+~_hR|+?}:wz
_?uCxzW
MCEa}.]>
NTqyo{+
RvQed:
'K.n}?ix/
^i%WVio
kK?m>vr6mm
#O,?!Ivp<eAma?
^]\x^5KfU
p1(V~$
p1(V~$
h2 0Ip
~x_E;b
l:z}nZts#dml@Uu@I!v
"nnTJ+
w5[kGuH)|S
N]>I&y@GD'j@
$&74-RKW
@@bU^Mk
}_K_e
xltuY"Uey!a70v
95fuhR_xi
jj~$4*RMa|
/iw6mR
w~%77S
$:v^/E~+.
_<MVk[qoj
}BTn3]^N)
EMa?Q^
(5'K3>4*q C
4H4sg%[_'x|
.\$Z}/
eiB1H;s
%4GB,_
#3k^^Wpie
%4GB,_
#g"3K8-
j<Ht{+i,
Qu?i6A
YIT*)+R%Oob-/,
h|9\jvp
e8fME'
Ft{=3/
c1Z+ZF
SZm|M}cK}
VfpBMnb2G
</uY[\|5M&o
 -Io
3imoIop-
~&xd~;7
(^TS$Au
*Yd*[
nmX<N*
L.%\xOl
BO:[i&[=GjZq{{s=
4!YYK1$O&KbZ
r4T,bd$@%
o>6en<C]]M
:5[S:m}F
h.5,!.A"H
th,=Nr
QWGyfp
wI,9v;O
G0|E}
{P& *t
]OZ+pk
I58_RVW
%X#y)2
CxIQ{;xo1ZI"
nsxT/h
d~dtW
;Hm(pIwl|
x[r_A+
";~j0Lnk<
Z=v6oehe
fYj]%bIdI_K
feK]o@e4
kidU>A?QP
0^E%:/
AZ*oEn
_$}HQE
}XVu;xZ
6mN2\NzHH5
~x_E;b
n<gqq2
x -gYxMc
@ (4?_H
95GoaK
l\w>2Z([?4k
YYZ[[0aiU
guk,.=-ds=(
x^e|OZla
CHTpml+O[|/5
1w]@@Kjka)
6Lvp/^uib`E
Y^70-gi
O.h>P<
OK(<z}(<
GY#(@d
v1RkIoP5
y/0yr'
iTEgw *Olo .oVi^%
%[+F]BM]G
Ox]e`rC
GzuI<=K&MKQ
"SVv=]h
cTmi><
/CnaFw<
'Z0xWOgq(
;w!0'kg)
z}Z{}Cfxb
"#s%nt=
/ICV)Imoq)mt
xO24cp+.6py<q
6_)wsJ?
v8ZdV:4
u5gm-/*
+XmNA[b'[Q#
<g}GW|^-VZ
q jB4]./
#]3GvF
xA|3;60Y^Z
0m/@XI
=/{1?}7T
D66^hea
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
ek},6;coX+e@Sr
@\<.!*A*{Q@
#e]H Q@
>)Xz_27
/q)QnrN
D66^hea
tUQY|
Ybjv^
qk)~
|s.}3i
4TM?7i
}{QV?n?
~(SC*V
=?_yEi
mOfQZkGa
=?_yEj
7Q^\Y'b\c8#A
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
$aBW$I
`C6r?T
aifkxZ7<go[jB
c/^\\B
F<3K=/X[
";_|?O
nth,mhd2`l
;B2~p;
}pifj8Iy?
b~7M%
4B49=X1|'k
W.ihf[>
>zQV?nY>kNoM"1
E-n6;;ts'<_{_7T
r:hU&>
1^m>Eo|o~rfOeBjsHn}dq>
wg&Y|U
}cH(/.l%
/KgO/k
tRAk}'96
_[r;xlm
(&$8Da
v$I9$Me}
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.u
UN=h~%i1x
;.QX0WPp0
("dyIJ;&v
Ppw63qZ]k.xib
Z++COS
oWK++=>
|9 |9;
xC%|@m}3GDOC
2XjGm{
<Y(<=i7:K0
$ebR]5R
eUrK"v?
:EhgH%Y
?;m}Lx
FIEvS^9fz_O'
2_hxNuX
76sHYC&I
;-|)HK>D
'$DuWq
mtXNnN
Q4Oi/9
xFef\g
W^5[k9,
c{7/"Gi
llUT$pN
8(PpFO=,
N}Y7L7
u<>.sas
-^;I,Ff{|A
{\Gu[xHIcim
m5Rf`;>b
x~}Mmu&{{
$OwkPBm*
_dp8ni|[G4
ee@'_SK
\ZBHzu=
9$SB<r#G$d+
\[c)FI
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
5lKpIcY"?6cC
k4p<XJ
oO/FpX
[=yb")[_a9Z
II2\*a
[XZEuf
qtHp_]~xwSfvoG(o
~I+~-
_>=wLQSxY_Aik
RIY%][6?
nTFeQ`
M01(V~$
p1(V~$
M\/|1-J{
\{O;5
78kQ`?&:<
|9oggGSMBKy
ydhIRV
3E{e6!
}W-2G]v&Q
#^_]Ls
m=zE"E:|ZjD,60f
<_qirx
w+&3js
dnT<S~(KVKo
>O3uo~
8"72^4H
d9$w&'o4
{=N[Fr
01(``=f?
jx+Zf[Yuk2L
^O<@V5
}"};QS
khm>kb!w
rkz`o!&6
eKJMn#+]<
k?5XQ`6
>zv$3Ko~&
Zo ukRj.U|
ZL##$C
t[M?EA
QVI=v?z
i>7M;+I\xY6~t
Nco?PN$R7yu~x*H$xt
`,tw;Kh
G}s|(f)m4g
L5].m#
kX#J<J7
CVO{spM)9.1,
rNj=s\>wjWZ
3]]\Ms+K31$I$wRmkzX''
# :w[O]#KUMS
N$ah-#%mOn
|)}um@41VN
jzkC mQo5"&FV+-
OP+YIw
dbY<Tp
)H+k1>s
E-m'O'
o,|E}
}JU[^D6
~[(=Yv>
}<> qZYYP,Y$
;H}r=}x^
NtI$2(RZ;V
kr+h_Ww
WrjJQ/0
?vB2a.G4&
~k~|
&e%~b,Dd
x{Mn|9
|9O&]S
1h5*jho
K[u ko
K[uG (
[b L;R@F
9\Qf6eF&|
y#jxgR
Eeeimn
<*@oew7lfk}
SU+~<
sin[Q{+
HLM<"dd}
.-_ZYE
s-iz<~f"i>k
SR#M&N-wfm
+PdH[fx
F E2cqbn
I<(]C`V
X(@9&/v
M&[[XGu
~1Q_WO
G?/(H?vRr
]H.lX5I4dHKHf
xDZAg,mc
m&JL6G
&#jW9&;>
lti$PM>f
$/-5-F
MYw|7>M]$LV@XUQ
~x|g
V-s('|i
pwgTb*f,dm
>=}o#NB
l-P4Vs#LmvGo#8
ycHn{oLY%
PQ|5/Z5i
HnbNc[O+&vA'
q_3V/u~
mo-D0KV
z?[}jBMQZF<
<J%d792%
|$_8mF
G#v;p\V
o>Q@\?*
qW>}EbRo/9
(Bl($>
D66^hea
Q_wXz
E-mj(
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
)-g!xl#3
QE0=z]
3kDSC#F#PA
_XmQX|>
j+(xD?
s#B<UX
h}w/QT%
(`rj*/
k(`rJ)3
t2YzE'iEX
40(#G?s
(5?a)QW3
7Q^\'|pGLQ_epk
/////#
qt<ltqx^C
qt<ltlxl
qt<ltqx
#H*1x/H5X
qp/llp
h4lhlp
ltlp]
hXlhltG
lhltClll
1hllltG
>h1x/l
qh<lhqt
d4ldlt^;
pXlhql/d
D`1x5D
qp<lpqx
%'$:Tk
#(*1`2
DlpJlp
h4lhll
ltlp]
L`1x5L
s$lx(D
#(*1x/(6
qp<lt"=
pr<krQ
pr<krQ
pr<krQ
H8`1t2
TargetFrameName
PostData
Headers
Cancel
strData
strPHP
FileName
qD<lDqp
qD<lDqlll
qD<lDqtlt
qD<lDqL
qD<lDqt
>8#D*#@
#<*1p2
D@<85H
lxlp*1x
dlhJdT
l\*1\2
l`l\*1`
Jqpltlp
(`1d5(ld
qx5X:hP
`#lx]
hXl\qt/`
q\<l\qp
*#Xlh*#T
qD<lDqplp
q@<l@qt
<4l<ldlp^
hXlDql/<lp
P4lPlt
\XlHR2
q@<l@qt(
l@RpFkF
l@RpFlt
q\ltlX]
q\pVlX
q$<l$q,
q$<l$q(l(
tXl$q(/ l(
Mlxlp*F
ll.8@MX
pn/@5\
pl/@5\
+lpFDknkl
\0`1p6
\`1x5\
T`1h5T
d4ldlllp^]
ql<llqxl
<4l<^H
xXl8qp/<
Y8lp^I
Y0l4lp
ld.,@lp
#l*#4P
#$*# lplt;2
l4($ 5L
tldh`X\TP)
qT<lTq`
qT<lTq`5D
qT<lTq`
qh<lhqtlt
1llpll
d4ldlt
lX/dllJ
*#dll*#`
<lDqtltlH
ltlx^d
qplpll
l l,qtK
'('Lltv#
nhl`n8ndl\n,)
nh)\(?sh
nd)\(?sd
'%'%'%'
%ndj<%nhjL%
7Q4[0H
tXl<qT/@
@4l@ll^[
pXl<qT/@lT
@4l@ll^[
pZ/@kZ
*#@ld#
q<<l<qT
l4lllx
\4l\ltP
<`1`5<
\4l\lhll^W
P>(#TlpltP
\XTPL0,(
q\<l\qp/`
\4l\^/
qX<lXqd/\
\4l\ld^0
qX<l\l
XlXqh/\
\4l\lh
TXlTltG
\4l\lh
TXlTltG
`1l/\6
pR<kRpr
8"lT/6
\kvlxJlT
H4lHlt^C
FlxFp``1x6
H\XTPLHD@<845
q`<l`o
''>LF(l`i8
2'' '0'P
lhlp*#$
lp*1t2
ldll*#
qL<lLqplp
qplplt
(`1x5(
lx*1t2
lhlp*#$
q(<l(qX
q(<l(qX
<lHl@qdlLlDq`lX^
q(<l(q\l`ldlX^
q(<l(qTlTl\^
q(<l(qP
lXl`ld
lXl`ld
<lPl\^
q(<l(qT
*#ll*#
*#ll*#
<l@qplplD
lplt^d
qllllh
F]<l'\
T4$|l\<
FD]<T'4
4llF$`1l6
ltlx*#0
#(*#$"
*#>x#*#
*#>t#*#
*#>p#*#
*#>l#*#
tpl0,($
lhlp*#
*#>#*#
*#hlllp*#dl
lllx*#$
`#$lhv#
`#$lhv#
#@*1t2
|ltFl\@
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
l\ld*#
(8`P@
lh.@+J
lh.@+J
lh.@+J
lh.@+J
pf/ :H
kflhF`1X6
(`# 0/ 6
D4lXF$
8(tTD4
*F]:TP
*#hll*#d
lhlx*#P
*#>#*#
lp.@M8
lp.@M8
lp.@M8
lp.@M8
lp@X/P
lp@XlL
lp@X/P
lp@XlL
ldlt*#L
*#>#*#
ldlt*#L
ldlt*#L
ll.(@M4
ll.(@M4
ll.(@M4
ll.(@M4
lHR(("
lHR(xC
lHR(hP
lHR(H0
lHR(hp
lHR(X0
lHR(8v
lHR(x6
lHR(h8
lHR(XG
lHR(8u
lHR(8]
lHR((^
lHR(Ht
lHR(8C
lHR(XZ
lHR(H
lHR(x1
lHR(x|
lHR(h$
lHR(X
lHR(Hu
q<lq\l\R
84l8^T
q4<ltJlt
04l0l4
,Xl,ltG
q4<l4qp
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
#*1p2$
*#lp*1t2
ldll*#
*#>#*#
MSVBVM60.DLL
EVENT_SINK_GetIDsOfNames
MethCallEngine
EVENT_SINK_Invoke
Zombie_GetTypeInfo
EVENT_SINK_AddRef
DllFunctionCall
Zombie_GetTypeInfoCount
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
Y0MAVH0WFJS1D8LB70KIUMF7EJ5YJYHBG4IYS1ERZZMK4D9FBXP4HRB5UXA224AKRJGIWBR2NZ7NX992ECCE3MOBU8IYTRTO57SJQWJY4TEDB1MBEYO1AR58EQXGL6P0P912XRFIMJ6M629RLQK3JCV39XXLNP91VOIYOPJV4CWAVZJV552APAJG6G532Z6FC1A3UC740IQN3JBAX8JN9XXMOCX3N24N5F0NM4VPLE8NMAXO695VJ7OFSHU55JKL5JG4PEFNR71MI7FIZ9YYR9CX6TTSZ8IBBHS4660L8OX4K9HJ5BQDV8WI3VBFLV6KTR0OASQ90Y3IRO978CTMJ214YD11WYFRXE7PFSOQQZ2WZ4ZBHLNWXQ3ED1VH7KGO878VQ5AEEU9ETCXF4TIX3FAYG5GY8DDRRBSLEDT8BUJ9M58L1PFTUG2KB9P9RV6XQ9TGL1MVKFEEGEV64P8EF1KLV2PPYPGW9JCUDVO1OO7W14QWWEX1F952NY7S305TMFHINNUENLH7VODJLZBJ4SYJ5VKGONB41PUSTBBILABQUKRNOZWD8YD5TVXXA562VYH4FXQ7XPFQEW7IWFSF9UH3BX2E343QP8N7ZG59KZZWCI140QKQ70BTVSQMTW10IQFSFQL8FZQ26O812QU00JRC6X7FLXT1VD21SPW5Z4HRQOOWTFOAAYH1BHPKETCYPJCNJP76JPU6T6SIT969APGWIF9NTD0T79KUGEUFL7XNUEPG1UNA3O6N1PSXCTN9XVXQHWYI45CLEJVGQNLBCS8CVLJ4ZWX4MTSZ5KZHUP03VTIE7NP4Z9H8VAEQJUBFXVBXBKUN01LO0H5MF852ECYH484EL6DNYMSCBO8E0U9369KMTC3GFIPHF49YKU0D0KBL3QYKG3A47D1D8UTBIZQNFN8K8ESHYL41XFQ3DLE9VNY0WVM495W6AXTD0CX6DA0ZJO8EA4K204HYSWFX9WBTJ5CD8XLZJMJTOAEXL4FFMU6TB3L9KYE1WG31HN4CYTZXJM6Q2ZV3QZ79Q827PRAALO4A8BUHST3R457CVGARG7WMA7RV1808AM199FSW1WWPL731NQ88RQLD05HZXYPO4BC54BP8Y0PTZ5XC5ZPHE4Y40WCALLFY3B8FWH23T632VF5I3R5EAT3IO4OZ7BYR8KF0K6YKNW616U8LBMB1HHW63GE2MGS2DSUGCN6ZH9LA4XXGCE33PARA61Q7PGMCGXS6W5QQS2FM5FGDX92WPKHQQ8XXJZA6HCLXTL92FWK32NPR4ECWZRXKIUR4NFBMFTON22TXD5SIC2NB1343WNB7PVDO6L1BAD3L3TF1V8J6NBEGW2IXD51CF8608NPCBRM4BV48U7ND0Y1NERWD78VKRJY3GC4ZF5S53BVBIOCFXG5ZM8X07E11M6UIKEAZIK246MRQOBJ9T2XCN6K4668IFMFJJMI41K9XP6V9NEMB4590DE7URNKN618V9CONDZPP6FXE8Z395KH0AZLBCPQ55TA2XZF15L4K41W3JXJ434JHDQD0849A50HJZ0CQIFREJ4PJ4Y7UO66BX0WKKPCWVPQVVP4SLSQ3FAMJ64MUYBMA5W4TMNRIMZBUMDATJKOLYQ8SHEC23JZ3DVT80JIEMZ
L!This program cannot be run in DOS mode.
sisisi
ldsiRichsi
`.data
bs_bot
`=7I,f&.
Ht*N"/Wd!:O3f
tmrDoWork
tmrDDoS
tmrBrowser
tmrSpara
tmrUpdate
tmrPersistence
tmrCommands
tmrGrabber
tmrSock_timeout
tmrAlive
VB5!*
Microsoft
bs_bot
`=7I,f&.
<WA\yY{
.L?kGb
l;J*JFh'o
mswinsck.ocx
MSWinsockLib.Winsock
Winsock
f=3@aB
f=3H2B
f=305B
bs_bot
mDefines
mFuncs
mBotKiller
mWebcam
mSpread
fSteam
t*N"/Wd!
F6k7;y
`=7I,f&.
6*O3f
tmrUpdate
+3qTheBrowser_BeforeNavigate2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
tmrSock_timeout
tmrSpara
tmrDoWork
tmrGrabber
tmrAlive
tmrPersistence
tmrDDoS
MTheBrowser
C:\Windows\SysWOW64\ieframe.dll
SHDocVw
tmrCommands
BROWSER_FB
tmrBrowser
TheBrowser_OnQuit
FORM_GRABBER_REPORT
KEYLOGGER_REPORT
IMAGE_REPORT
PASSWORDS_REPORT
STEAM_REPORT
EMAILS_REPORT
FILE_EXISTS
BROWSER_FB_DocumentComplete
BROWSER_FB_OnQuit
FACEBOOK_START
E;9:u9kL
+3q"=h
RegOpenKeyA
,SIfwg
kernel32.dll
GetTickCount
user32
GetForegroundWindow
GetWindowTextA
SendMessageA
kernel32
GetVolumeInformationA
GetLocaleInfoA
advapi32
RegCreateKeyA
RegSetValueExA
RegDeleteValueA
RegCloseKey
MoveFileExA
WinInet.dll
InternetOpenA
InternetOpenUrlA
txtAccName
InternetReadFile
InternetCloseHandle
WaitForSingleObject
CreateMutexA
CloseHandle
ReleaseMutex
GdiplusShutdown
DeleteUrlCacheEntryA
urlmon
URLDownloadToFileA
LoadLibraryA
CallWindowProcA
GetProcAddress
SetFilePointer
FlushFileBuffers
CreateFileA
WriteFile
GetFileSize
advapi32.dll
RegOpenKeyExA
RegEnumValueA
RegQueryValueExA
RegEnumKeyExA
RegDeleteKeyA
FindWindowA
msvbvm60
__vbaCopyBytes
ExitProcess
GDIPlus
GdipCreateBitmapFromHBITMAP
GdiplusStartup
CLSIDFromString
GdipSaveImageToFile
GdipDisposeImage
BYFZSGyh
CallNextHookEx
SetWindowsHookExA
UnhookWindowsHookEx
ToUnicodeEx
VBA6.DLL
GetWindowTextLengthA
GetKeyboardState
GetKeyState
GetAsyncKeyState
RtlMoveMemory
GetWindowDC
CreateCompatibleDC
CreateCompatibleBitmap
gdi32.dll
SelectObject
DeleteDC
ReleaseDC
DeleteObject
olepro32.dll
OleCreatePictureIndirect
StretchBlt
SetStretchBltMode
user32.dll
GetWindowRect
avicap32.dll
capGetDriverDescriptionA
capCreateCaptureWindowA
zx}E&CoCe%H
tmrKill
tmrFocus
imgLoginPressed
imgLogin
txtPassword
imgSteam
imgRemember
imgMinimize
imgClose
SetWindowPos
GetCurrentProcessId
AdjustTokenPrivileges
RtlAdjustPrivilege
LookupPrivilegeValueA
GetCurrentProcess
OpenProcess
OpenProcessToken
Process32First
Process32Next
TerminateProcess
VirtualQueryEx
ReadProcessMemory
GetModuleFileNameA
GetModuleHandleA
CreateToolhelp32Snapshot
Thread32First
Thread32Next
TerminateThread
OpenThread
ntdll.dll
NtQueryInformationThread
NtSetInformationProcess
PSAPI.DLL
GetModuleFileNameExA
EnumProcessModules
GetSystemInfo
SetForegroundWindow
GetWindowThreadProcessId
shell32.dll
ShellExecuteA
EnumWindows
ShowWindow
BringWindowToTop
SetFocus
PostMessageA
keybd_event
wUcl;J*JFh'oDDOS
JC:\Program Files (x86)\Microsoft Visual Studio\VB98\vbc14663.oca
MSWinsockLib
tmrTCP
UDPSocket
tmrUDP
UDPFlood
CallWindowProcW
^HKlYF;(4
wUcCz/A
qR^:O3f
UDPSocket
MSWinsockLib.Winsock
MSWinsockLib.Winsock
tmrUDP
tmrTCP
zx}E&CoC:O3f
fSteam
tmrKill
tmrFocus
txtPassword
Tahoma0
txtAccName
Tahoma0
imgLoginPressed
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
`03?K7
w]M{{
MJEYTXoR
SxF{Ap
n'omX$"sI
w]OQP
.F2.e^
<=N7i#YG*
kUDz|:XYi[$h=:
SxAZ>#xR
u>63Os-m/
3O;y!]
$-'VR0f-`
x|YOj+
]SM<$"FX
_7G-ozi+
'bk-NMP
?xW?5|_
p=n*+)A
q\=$I#
imgLogin
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
->g{<]=s9/*1
wQ\V:c-
2PNhZ6ko4XE
-Rk9$Xi#
/}|?.x?
~` .4@%\+
F?:%gc
?j_q?:nu^~
W+?:?@\'
?j_q?:
JqOc|a
F'v@0OC
,v^ku
7]^=
imgRemember
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
/7Oq=7.3
L,t}OZQ
V 2y/^iq,r V
}yWD6\
Lm*t?o
x{LO_lllP[s
QkWR0A
{9J(2?
imgClose
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
0F?;n (
imgMinimize
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
g;zt^:
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
2[ZDq+T
(Z{^YZ-
6Xh"!I!H$
D/u/w
k}B-QV
,9X&Ds>a(s_
pXos.t
#U_rK!(?
:E{P[izijqt
c7_hc2
,FAb~tK^g?[
[\h*Em
(-u{+tNO}
$]"o4$
t2yq,@
dw=u/O
~w3U=
V'8 Yd
thntJ+
v* :wz
swD:Q^
=wgx_E;b
][|45YlDai3
&HsSN7=>
0O"LT^[xm
Vi<icU
~)xL-G[HOP-H0q
_5vLu Q
d\os~!;|M{xS
"ega4ec
_KXtRH
iqm-v5
WKnf~;;
jWQxPm7:n{
$3M&AXx\[(n`9@
+7Z|G{]_NA{ZYd
)~mXkz^*6o(Sp
Q6COyyM
[,}d;}
k?5XQ`6
}(t5h(/1/9
ED%$B.
Ski$RxwW
x#wmgJ>
4Rj:J^
:TKyivh
>n?GEo}uZ%Tf-]
o[(u*`2t;O
w=![\jxPxn]J(#6kD
l5 LuH8
wZo@BK1
KimmeXr9
]o_g)IvnNpgX
(~T5sXQ.$
fi9I%
~V%~}kc'c
X>+h#OM
QhkF[vk
.x4=AgwqD'
FDwJciu
$~[k:(
n,N/ VR
|gmj@eqbqqi<
Bl"O?|/
o,|E}
S+o=Uo%y
g-x:W45
+|K$2X?S
!=>6{{:E$
4Q])Fxd
~)_m<_k
_V|Z[\$
6~ Tx.~Q
'/>+i-Kt
>fESjy
o>~)O7R
RZsBE0#G0f
uZ(Py"(
QR|!\j~3
Q_ixz#
YpsF:9_D=Vw
_Q$|<>(
`6b++{
PL0hl*
ncFKI7
J!14J;DJ X~IY
VG32v,"%N
\=Cu4
2A"2"neUs
xv[KMsF
d,'XMM
[\i]:sy
Xo0&WHny`|
4n-n>a
wkxY`d?
j|E}]?
!K8;\)^w#?u1u `$!-!d{2
6w 'V
k,F(QjL
"z__A[
_|N6EDVwr
fuo6[K
|kM+Nm
R[kE-D
dwL$I\
|*.5gc~
H16t3G[
b:UG+{
jz705O
?EkF5?
>&i-7 Z(m1g`
^.;kQ"y)RiT|MC7Iiq&
|T"72_HN3;+1
{(/!@[
!w2d8ub
t#IHV7
\ZY![99m<
h[\cAuEcMi
54wom/nmZ
o~|1aW
M(x' _
5'>(O]Vi
oC!'L|
EIUwxZ
C~_E;b
hr2gxj#Z
Q_wXz
~x_E;b
|IY,#qaMs
Mgql<asi[XR
z([[Iyq
RM:m6[{
`>q>`<
e9drZoe|
e'<=j\\Z
&j$$S,
{7:5{k
B[(Xdy?^
m/W_Vyg
}'qz-awuois=M
L+0E.aAb
\7FAzM
ukWM&6h
~*k:%59l
=OxGVayiz
p29\E}I{
t+Or66Y3
hyli?-
nNoEhB
ZB%ec" CJ
H16t3G[
b:UG+{
|;gWPcI+=O1
LjyI;ctqYx
:"'2G6b9&Um?V
7V#\^q
w~&Xx,hn3l
`m.;c?*
HhU"hW
n#LU],b
Z7tkwlu
\.oego
uKme~t`l
}$|km.4K
xR|3;BVth
ereKpM
uuQ.bXY)2
sm;.c~)o
_!JM+3
[c4skOs(@^C'W
V#Enl{gV."fSRH#
wI.Z6J?
}Eo>W:OJ?[q\O{W^9K.zSj+
q_}/Xz
~x_E;b
~I<AVVVosv6
^Iqj7e
j:(Cq}r
hr2gxj#Z
bW9rZ*1w
*9%9J)
GEK)4a7hr
}{Hw+V
~[))aa
(5?a3Duc
+SeTV
x6+3:d
+XX'\If
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
TfsVvV]
1$QTrI
9#%YX`
\;*rcL
g?`?:_*
tU\|O]J{
y7^/?
7+~_hR|+?}:wz
_?uCxzW
MCEa}.]>
NTqyo{+
RvQed:
'K.n}?ix/
^i%WVio
kK?m>vr6mm
#O,?!Ivp<eAma?
^]\x^5KfU
p1(V~$
p1(V~$
h2 0Ip
~x_E;b
l:z}nZts#dml@Uu@I!v
"nnTJ+
w5[kGuH)|S
N]>I&y@GD'j@
$&74-RKW
@@bU^Mk
}_K_e
xltuY"Uey!a70v
95fuhR_xi
jj~$4*RMa|
/iw6mR
w~%77S
$:v^/E~+.
_<MVk[qoj
}BTn3]^N)
EMa?Q^
(5'K3>4*q C
4H4sg%[_'x|
.\$Z}/
eiB1H;s
%4GB,_
#3k^^Wpie
%4GB,_
#g"3K8-
j<Ht{+i,
Qu?i6A
YIT*)+R%Oob-/,
h|9\jvp
e8fME'
Ft{=3/
c1Z+ZF
SZm|M}cK}
VfpBMnb2G
</uY[\|5M&o
 -Io
3imoIop-
~&xd~;7
(^TS$Au
*Yd*[
nmX<N*
L.%\xOl
BO:[i&[=GjZq{{s=
4!YYK1$O&KbZ
r4T,bd$@%
o>6en<C]]M
:5[S:m}F
h.5,!.A"H
th,=Nr
QWGyfp
wI,9v;O
G0|E}
{P& *t
]OZ+pk
I58_RVW
%X#y)2
CxIQ{;xo1ZI"
nsxT/h
d~dtW
;Hm(pIwl|
x[r_A+
";~j0Lnk<
Z=v6oehe
fYj]%bIdI_K
feK]o@e4
kidU>A?QP
0^E%:/
AZ*oEn
_$}HQE
}XVu;xZ
6mN2\NzHH5
~x_E;b
n<gqq2
x -gYxMc
@ (4?_H
95GoaK
l\w>2Z([?4k
YYZ[[0aiU
guk,.=-ds=(
x^e|OZla
CHTpml+O[|/5
1w]@@Kjka)
6Lvp/^uib`E
Y^70-gi
O.h>P<
OK(<z}(<
GY#(@d
v1RkIoP5
y/0yr'
iTEgw *Olo .oVi^%
%[+F]BM]G
Ox]e`rC
GzuI<=K&MKQ
"SVv=]h
cTmi><
/CnaFw<
'Z0xWOgq(
;w!0'kg)
z}Z{}Cfxb
"#s%nt=
/ICV)Imoq)mt
xO24cp+.6py<q
6_)wsJ?
v8ZdV:4
u5gm-/*
+XmNA[b'[Q#
<g}GW|^-VZ
q jB4]./
#]3GvF
xA|3;60Y^Z
0m/@XI
=/{1?}7T
D66^hea
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
ek},6;coX+e@Sr
@\<.!*A*{Q@
#e]H Q@
>)Xz_27
/q)QnrN
D66^hea
tUQY|
Ybjv^
qk)~
|s.}3i
4TM?7i
}{QV?n?
~(SC*V
=?_yEi
mOfQZkGa
=?_yEj
7Q^\Y'b\c8#A
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
$aBW$I
`C6r?T
aifkxZ7<go[jB
c/^\\B
F<3K=/X[
";_|?O
nth,mhd2`l
;B2~p;
}pifj8Iy?
b~7M%
4B49=X1|'k
W.ihf[>
>zQV?nY>kNoM"1
E-n6;;ts'<_{_7T
r:hU&>
1^m>Eo|o~rfOeBjsHn}dq>
wg&Y|U
}cH(/.l%
/KgO/k
tRAk}'96
_[r;xlm
(&$8Da
v$I9$Me}
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.u
UN=h~%i1x
;.QX0WPp0
("dyIJ;&v
Ppw63qZ]k.xib
Z++COS
oWK++=>
|9 |9;
xC%|@m}3GDOC
2XjGm{
<Y(<=i7:K0
$ebR]5R
eUrK"v?
:EhgH%Y
?;m}Lx
FIEvS^9fz_O'
2_hxNuX
76sHYC&I
;-|)HK>D
'$DuWq
mtXNnN
Q4Oi/9
xFef\g
W^5[k9,
c{7/"Gi
llUT$pN
8(PpFO=,
N}Y7L7
u<>.sas
-^;I,Ff{|A
{\Gu[xHIcim
m5Rf`;>b
x~}Mmu&{{
$OwkPBm*
_dp8ni|[G4
ee@'_SK
\ZBHzu=
9$SB<r#G$d+
\[c)FI
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
5lKpIcY"?6cC
k4p<XJ
oO/FpX
[=yb")[_a9Z
II2\*a
[XZEuf
qtHp_]~xwSfvoG(o
~I+~-
_>=wLQSxY_Aik
RIY%][6?
nTFeQ`
M01(V~$
p1(V~$
M\/|1-J{
\{O;5
78kQ`?&:<
|9oggGSMBKy
ydhIRV
3E{e6!
}W-2G]v&Q
#^_]Ls
m=zE"E:|ZjD,60f
<_qirx
w+&3js
dnT<S~(KVKo
>O3uo~
8"72^4H
d9$w&'o4
{=N[Fr
01(``=f?
jx+Zf[Yuk2L
^O<@V5
}"};QS
khm>kb!w
rkz`o!&6
eKJMn#+]<
k?5XQ`6
>zv$3Ko~&
Zo ukRj.U|
ZL##$C
t[M?EA
QVI=v?z
i>7M;+I\xY6~t
Nco?PN$R7yu~x*H$xt
`,tw;Kh
G}s|(f)m4g
L5].m#
kX#J<J7
CVO{spM)9.1,
rNj=s\>wjWZ
3]]\Ms+K31$I$wRmkzX''
# :w[O]#KUMS
N$ah-#%mOn
|)}um@41VN
jzkC mQo5"&FV+-
OP+YIw
dbY<Tp
)H+k1>s
E-m'O'
o,|E}
}JU[^D6
~[(=Yv>
}<> qZYYP,Y$
;H}r=}x^
NtI$2(RZ;V
kr+h_Ww
WrjJQ/0
?vB2a.G4&
~k~|
&e%~b,Dd
x{Mn|9
|9O&]S
1h5*jho
K[u ko
K[uG (
[b L;R@F
9\Qf6eF&|
y#jxgR
Eeeimn
<*@oew7lfk}
SU+~<
sin[Q{+
HLM<"dd}
.-_ZYE
s-iz<~f"i>k
SR#M&N-wfm
+PdH[fx
F E2cqbn
I<(]C`V
X(@9&/v
M&[[XGu
~1Q_WO
G?/(H?vRr
]H.lX5I4dHKHf
xDZAg,mc
m&JL6G
&#jW9&;>
lti$PM>f
$/-5-F
MYw|7>M]$LV@XUQ
~x|g
V-s('|i
pwgTb*f,dm
>=}o#NB
l-P4Vs#LmvGo#8
ycHn{oLY%
PQ|5/Z5i
HnbNc[O+&vA'
q_3V/u~
mo-D0KV
z?[}jBMQZF<
<J%d792%
|$_8mF
G#v;p\V
o>Q@\?*
qW>}EbRo/9
(Bl($>
D66^hea
Q_wXz
E-mj(
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
)-g!xl#3
QE0=z]
3kDSC#F#PA
_XmQX|>
j+(xD?
s#B<UX
h}w/QT%
(`rj*/
k(`rJ)3
t2YzE'iEX
40(#G?s
(5?a)QW3
7Q^\'|pGLQ_epk
/////#
qt<ltqx^C
qt<ltlxl
qt<ltqx
#H*1x/H5X
qp/llp
h4lhlp
ltlp]
hXlhltG
lhltClll
1hllltG
>h1x/l
qh<lhqt
d4ldlt^;
pXlhql/d
D`1x5D
qp<lpqx
%'$:Tk
#(*1`2
DlpJlp
h4lhll
ltlp]
L`1x5L
s$lx(D
#(*1x/(6
qp<lt"=
pr<krQ
pr<krQ
pr<krQ
H8`1t2
TargetFrameName
PostData
Headers
Cancel
strData
strPHP
FileName
qD<lDqp
qD<lDqlll
qD<lDqtlt
qD<lDqL
qD<lDqt
>8#D*#@
#<*1p2
D@<85H
lxlp*1x
dlhJdT
l\*1\2
l`l\*1`
Jqpltlp
(`1d5(ld
qx5X:hP
`#lx]
hXl\qt/`
q\<l\qp
*#Xlh*#T
qD<lDqplp
q@<l@qt
<4l<ldlp^
hXlDql/<lp
P4lPlt
\XlHR2
q@<l@qt(
l@RpFkF
l@RpFlt
q\ltlX]
q\pVlX
q$<l$q,
q$<l$q(l(
tXl$q(/ l(
Mlxlp*F
ll.8@MX
pn/@5\
pl/@5\
+lpFDknkl
\0`1p6
\`1x5\
T`1h5T
d4ldlllp^]
ql<llqxl
<4l<^H
xXl8qp/<
Y8lp^I
Y0l4lp
ld.,@lp
#l*#4P
#$*# lplt;2
l4($ 5L
tldh`X\TP)
qT<lTq`
qT<lTq`5D
qT<lTq`
qh<lhqtlt
1llpll
d4ldlt
lX/dllJ
*#dll*#`
<lDqtltlH
ltlx^d
qplpll
l l,qtK
'('Lltv#
nhl`n8ndl\n,)
nh)\(?sh
nd)\(?sd
'%'%'%'
%ndj<%nhjL%
7Q4[0H
tXl<qT/@
@4l@ll^[
pXl<qT/@lT
@4l@ll^[
pZ/@kZ
*#@ld#
q<<l<qT
l4lllx
\4l\ltP
<`1`5<
\4l\lhll^W
P>(#TlpltP
\XTPL0,(
q\<l\qp/`
\4l\^/
qX<lXqd/\
\4l\ld^0
qX<l\l
XlXqh/\
\4l\lh
TXlTltG
\4l\lh
TXlTltG
`1l/\6
pR<kRpr
8"lT/6
\kvlxJlT
H4lHlt^C
FlxFp``1x6
H\XTPLHD@<845
q`<l`o
''>LF(l`i8
2'' '0'P
lhlp*#$
lp*1t2
ldll*#
qL<lLqplp
qplplt
(`1x5(
lx*1t2
lhlp*#$
q(<l(qX
q(<l(qX
<lHl@qdlLlDq`lX^
q(<l(q\l`ldlX^
q(<l(qTlTl\^
q(<l(qP
lXl`ld
lXl`ld
<lPl\^
q(<l(qT
*#ll*#
*#ll*#
<l@qplplD
lplt^d
qllllh
F]<l'\
T4$|l\<
FD]<T'4
4llF$`1l6
ltlx*#0
#(*#$"
*#>x#*#
*#>t#*#
*#>p#*#
*#>l#*#
tpl0,($
lhlp*#
*#>#*#
*#hlllp*#dl
lllx*#$
`#$lhv#
`#$lhv#
#@*1t2
|ltFl\@
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
l\ld*#
(8`P@
lh.@+J
lh.@+J
lh.@+J
lh.@+J
pf/ :H
kflhF`1X6
(`# 0/ 6
D4lXF$
8(tTD4
*F]:TP
*#hll*#d
lhlx*#P
*#>#*#
lp.@M8
lp.@M8
lp.@M8
lp.@M8
lp@X/P
lp@XlL
lp@X/P
lp@XlL
ldlt*#L
*#>#*#
ldlt*#L
ldlt*#L
ll.(@M4
ll.(@M4
ll.(@M4
ll.(@M4
lHR(("
lHR(xC
lHR(hP
lHR(H0
lHR(hp
lHR(X0
lHR(8v
lHR(x6
lHR(h8
lHR(XG
lHR(8u
lHR(8]
lHR((^
lHR(Ht
lHR(8C
lHR(XZ
lHR(H
lHR(x1
lHR(x|
lHR(h$
lHR(X
lHR(Hu
q<lq\l\R
84l8^T
q4<ltJlt
04l0l4
,Xl,ltG
q4<l4qp
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
7R0B16BW1ND8FM98OS880GA3WL8V456E8ML1JQN21886DTTMVVWEWO39H8M5JS3PDC0WKR5ML77F56YNETC6EUOBUI51YK33X1X26GC94GYM2L0LJQMB373HJSWPTVZL4XS2R8HB88056VV6BY9EO1W59GB5A7W13X7ME61LZ3HQQQ9U90MS7K3ACJ3NE3L2ZZA3JV7Q54VA73UYR558OJXK3L51OZTOAKH6K7E5G2EN0TAX1TTHCC2IA19QSESKGFRRP8YKVMDPU9290E2BMKKUY456M1WPHWQQ4WAM3XP58ZB84F5SCG986XW0IOORZ62IT9E4WZGMCMQC4UXHAR8R2IR4MHAGSYOG7UUS1DEREM092WH7HJ23BSTA30MJ7M8LZODI481TTWVWWQYQ1D3FVXLU9PMPV5RDZWGRDKOVO82SBFM7UVDQB8Q9IGTU8OX2U3Z8G4N2SYX67I62O4BUTUGBIR00IJNBE1QM7QXNFEVZB0N68DCYR1SMTA3VTG2B365CHZ5CQQR9M8W6ENOXTSV8CQW29X12PUTEJ84A6H4C1MVS32WZG8Z70F6K7U4BKKS6U2HPKOMGWTZHXWIOMXRS2GZZ9N4IX6AZM2M0KVHPFBLORLB7BOXU3HBNQ12RA3Z5NJBD1LN2MAM9DB3HTF2EI6KQGWE9L0SXLH38YH4A7PWZLDMSALEE1C68238SAH57K9FQ6ZJR2FBC3G2ZBDYPSPXXLHCSAC3SZAZP3FBM6UDSGVZ70LAIZFUYDYWJ5Y6DK9OPQJRXFJULBD313E4ORHU0ZMZKN6SZAFDXQVWV5N4GALN33WR37QWVI3AIDD53Y2JAHQ0VH7U9UU36NPGZYKKW8EB6V2YH1QSZ4K3M7EKK4YD25K6KJCA75CGRVMKVLPX2S6OMMZ
L!This program cannot be run in DOS mode.
sisisi
ldsiRichsi
`.data
bs_bot
`=7I,f&.
Ht*N"/Wd!:O3f
tmrDoWork
tmrDDoS
tmrBrowser
tmrSpara
tmrUpdate
tmrPersistence
tmrCommands
tmrGrabber
tmrSock_timeout
tmrAlive
VB5!*
Microsoft
bs_bot
`=7I,f&.
<WA\yY{
.L?kGb
l;J*JFh'o
mswinsck.ocx
MSWinsockLib.Winsock
Winsock
f=3@aB
f=3H2B
f=305B
bs_bot
mDefines
mFuncs
mBotKiller
mWebcam
mSpread
fSteam
t*N"/Wd!
F6k7;y
`=7I,f&.
6*O3f
tmrUpdate
+3qTheBrowser_BeforeNavigate2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
tmrSock_timeout
tmrSpara
tmrDoWork
tmrGrabber
tmrAlive
tmrPersistence
tmrDDoS
MTheBrowser
C:\Windows\SysWOW64\ieframe.dll
SHDocVw
tmrCommands
BROWSER_FB
tmrBrowser
TheBrowser_OnQuit
FORM_GRABBER_REPORT
KEYLOGGER_REPORT
IMAGE_REPORT
PASSWORDS_REPORT
STEAM_REPORT
EMAILS_REPORT
FILE_EXISTS
BROWSER_FB_DocumentComplete
BROWSER_FB_OnQuit
FACEBOOK_START
E;9:u9kL
+3q"=h
RegOpenKeyA
,SIfwg
kernel32.dll
GetTickCount
user32
GetForegroundWindow
GetWindowTextA
SendMessageA
kernel32
GetVolumeInformationA
GetLocaleInfoA
advapi32
RegCreateKeyA
RegSetValueExA
RegDeleteValueA
RegCloseKey
MoveFileExA
WinInet.dll
InternetOpenA
InternetOpenUrlA
txtAccName
InternetReadFile
InternetCloseHandle
WaitForSingleObject
CreateMutexA
CloseHandle
ReleaseMutex
GdiplusShutdown
DeleteUrlCacheEntryA
urlmon
URLDownloadToFileA
LoadLibraryA
CallWindowProcA
GetProcAddress
SetFilePointer
FlushFileBuffers
CreateFileA
WriteFile
GetFileSize
advapi32.dll
RegOpenKeyExA
RegEnumValueA
RegQueryValueExA
RegEnumKeyExA
RegDeleteKeyA
FindWindowA
msvbvm60
__vbaCopyBytes
ExitProcess
GDIPlus
GdipCreateBitmapFromHBITMAP
GdiplusStartup
CLSIDFromString
GdipSaveImageToFile
GdipDisposeImage
BYFZSGyh
CallNextHookEx
SetWindowsHookExA
UnhookWindowsHookEx
ToUnicodeEx
VBA6.DLL
GetWindowTextLengthA
GetKeyboardState
GetKeyState
GetAsyncKeyState
RtlMoveMemory
GetWindowDC
CreateCompatibleDC
CreateCompatibleBitmap
gdi32.dll
SelectObject
DeleteDC
ReleaseDC
DeleteObject
olepro32.dll
OleCreatePictureIndirect
StretchBlt
SetStretchBltMode
user32.dll
GetWindowRect
avicap32.dll
capGetDriverDescriptionA
capCreateCaptureWindowA
zx}E&CoCe%H
tmrKill
tmrFocus
imgLoginPressed
imgLogin
txtPassword
imgSteam
imgRemember
imgMinimize
imgClose
SetWindowPos
GetCurrentProcessId
AdjustTokenPrivileges
RtlAdjustPrivilege
LookupPrivilegeValueA
GetCurrentProcess
OpenProcess
OpenProcessToken
Process32First
Process32Next
TerminateProcess
VirtualQueryEx
ReadProcessMemory
GetModuleFileNameA
GetModuleHandleA
CreateToolhelp32Snapshot
Thread32First
Thread32Next
TerminateThread
OpenThread
ntdll.dll
NtQueryInformationThread
NtSetInformationProcess
PSAPI.DLL
GetModuleFileNameExA
EnumProcessModules
GetSystemInfo
SetForegroundWindow
GetWindowThreadProcessId
shell32.dll
ShellExecuteA
EnumWindows
ShowWindow
BringWindowToTop
SetFocus
PostMessageA
keybd_event
wUcl;J*JFh'oDDOS
JC:\Program Files (x86)\Microsoft Visual Studio\VB98\vbc14663.oca
MSWinsockLib
tmrTCP
UDPSocket
tmrUDP
UDPFlood
CallWindowProcW
^HKlYF;(4
wUcCz/A
qR^:O3f
UDPSocket
MSWinsockLib.Winsock
MSWinsockLib.Winsock
tmrUDP
tmrTCP
zx}E&CoC:O3f
fSteam
tmrKill
tmrFocus
txtPassword
Tahoma0
txtAccName
Tahoma0
imgLoginPressed
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
`03?K7
w]M{{
MJEYTXoR
SxF{Ap
n'omX$"sI
w]OQP
.F2.e^
<=N7i#YG*
kUDz|:XYi[$h=:
SxAZ>#xR
u>63Os-m/
3O;y!]
$-'VR0f-`
x|YOj+
]SM<$"FX
_7G-ozi+
'bk-NMP
?xW?5|_
p=n*+)A
q\=$I#
imgLogin
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
->g{<]=s9/*1
wQ\V:c-
2PNhZ6ko4XE
-Rk9$Xi#
/}|?.x?
~` .4@%\+
F?:%gc
?j_q?:nu^~
W+?:?@\'
?j_q?:
JqOc|a
F'v@0OC
,v^ku
7]^=
imgRemember
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
/7Oq=7.3
L,t}OZQ
V 2y/^iq,r V
}yWD6\
Lm*t?o
x{LO_lllP[s
QkWR0A
{9J(2?
imgClose
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
0F?;n (
imgMinimize
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
g;zt^:
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
2[ZDq+T
(Z{^YZ-
6Xh"!I!H$
D/u/w
k}B-QV
,9X&Ds>a(s_
pXos.t
#U_rK!(?
:E{P[izijqt
c7_hc2
,FAb~tK^g?[
[\h*Em
(-u{+tNO}
$]"o4$
t2yq,@
dw=u/O
~w3U=
V'8 Yd
thntJ+
v* :wz
swD:Q^
=wgx_E;b
][|45YlDai3
&HsSN7=>
0O"LT^[xm
Vi<icU
~)xL-G[HOP-H0q
_5vLu Q
d\os~!;|M{xS
"ega4ec
_KXtRH
iqm-v5
WKnf~;;
jWQxPm7:n{
$3M&AXx\[(n`9@
+7Z|G{]_NA{ZYd
)~mXkz^*6o(Sp
Q6COyyM
[,}d;}
k?5XQ`6
}(t5h(/1/9
ED%$B.
Ski$RxwW
x#wmgJ>
4Rj:J^
:TKyivh
>n?GEo}uZ%Tf-]
o[(u*`2t;O
w=![\jxPxn]J(#6kD
l5 LuH8
wZo@BK1
KimmeXr9
]o_g)IvnNpgX
(~T5sXQ.$
fi9I%
~V%~}kc'c
X>+h#OM
QhkF[vk
.x4=AgwqD'
FDwJciu
$~[k:(
n,N/ VR
|gmj@eqbqqi<
Bl"O?|/
o,|E}
S+o=Uo%y
g-x:W45
+|K$2X?S
!=>6{{:E$
4Q])Fxd
~)_m<_k
_V|Z[\$
6~ Tx.~Q
'/>+i-Kt
>fESjy
o>~)O7R
RZsBE0#G0f
uZ(Py"(
QR|!\j~3
Q_ixz#
YpsF:9_D=Vw
_Q$|<>(
`6b++{
PL0hl*
ncFKI7
J!14J;DJ X~IY
VG32v,"%N
\=Cu4
2A"2"neUs
xv[KMsF
d,'XMM
[\i]:sy
Xo0&WHny`|
4n-n>a
wkxY`d?
j|E}]?
!K8;\)^w#?u1u `$!-!d{2
6w 'V
k,F(QjL
"z__A[
_|N6EDVwr
fuo6[K
|kM+Nm
R[kE-D
dwL$I\
|*.5gc~
H16t3G[
b:UG+{
jz705O
?EkF5?
>&i-7 Z(m1g`
^.;kQ"y)RiT|MC7Iiq&
|T"72_HN3;+1
{(/!@[
!w2d8ub
t#IHV7
\ZY![99m<
h[\cAuEcMi
54wom/nmZ
o~|1aW
M(x' _
5'>(O]Vi
oC!'L|
EIUwxZ
C~_E;b
hr2gxj#Z
Q_wXz
~x_E;b
|IY,#qaMs
Mgql<asi[XR
z([[Iyq
RM:m6[{
`>q>`<
e9drZoe|
e'<=j\\Z
&j$$S,
{7:5{k
B[(Xdy?^
m/W_Vyg
}'qz-awuois=M
L+0E.aAb
\7FAzM
ukWM&6h
~*k:%59l
=OxGVayiz
p29\E}I{
t+Or66Y3
hyli?-
nNoEhB
ZB%ec" CJ
H16t3G[
b:UG+{
|;gWPcI+=O1
LjyI;ctqYx
:"'2G6b9&Um?V
7V#\^q
w~&Xx,hn3l
`m.;c?*
HhU"hW
n#LU],b
Z7tkwlu
\.oego
uKme~t`l
}$|km.4K
xR|3;BVth
ereKpM
uuQ.bXY)2
sm;.c~)o
_!JM+3
[c4skOs(@^C'W
V#Enl{gV."fSRH#
wI.Z6J?
}Eo>W:OJ?[q\O{W^9K.zSj+
q_}/Xz
~x_E;b
~I<AVVVosv6
^Iqj7e
j:(Cq}r
hr2gxj#Z
bW9rZ*1w
*9%9J)
GEK)4a7hr
}{Hw+V
~[))aa
(5?a3Duc
+SeTV
x6+3:d
+XX'\If
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
TfsVvV]
1$QTrI
9#%YX`
\;*rcL
g?`?:_*
tU\|O]J{
y7^/?
7+~_hR|+?}:wz
_?uCxzW
MCEa}.]>
NTqyo{+
RvQed:
'K.n}?ix/
^i%WVio
kK?m>vr6mm
#O,?!Ivp<eAma?
^]\x^5KfU
p1(V~$
p1(V~$
h2 0Ip
~x_E;b
l:z}nZts#dml@Uu@I!v
"nnTJ+
w5[kGuH)|S
N]>I&y@GD'j@
$&74-RKW
@@bU^Mk
}_K_e
xltuY"Uey!a70v
95fuhR_xi
jj~$4*RMa|
/iw6mR
w~%77S
$:v^/E~+.
_<MVk[qoj
}BTn3]^N)
EMa?Q^
(5'K3>4*q C
4H4sg%[_'x|
.\$Z}/
eiB1H;s
%4GB,_
#3k^^Wpie
%4GB,_
#g"3K8-
j<Ht{+i,
Qu?i6A
YIT*)+R%Oob-/,
h|9\jvp
e8fME'
Ft{=3/
c1Z+ZF
SZm|M}cK}
VfpBMnb2G
</uY[\|5M&o
 -Io
3imoIop-
~&xd~;7
(^TS$Au
*Yd*[
nmX<N*
L.%\xOl
BO:[i&[=GjZq{{s=
4!YYK1$O&KbZ
r4T,bd$@%
o>6en<C]]M
:5[S:m}F
h.5,!.A"H
th,=Nr
QWGyfp
wI,9v;O
G0|E}
{P& *t
]OZ+pk
I58_RVW
%X#y)2
CxIQ{;xo1ZI"
nsxT/h
d~dtW
;Hm(pIwl|
x[r_A+
";~j0Lnk<
Z=v6oehe
fYj]%bIdI_K
feK]o@e4
kidU>A?QP
0^E%:/
AZ*oEn
_$}HQE
}XVu;xZ
6mN2\NzHH5
~x_E;b
n<gqq2
x -gYxMc
@ (4?_H
95GoaK
l\w>2Z([?4k
YYZ[[0aiU
guk,.=-ds=(
x^e|OZla
CHTpml+O[|/5
1w]@@Kjka)
6Lvp/^uib`E
Y^70-gi
O.h>P<
OK(<z}(<
GY#(@d
v1RkIoP5
y/0yr'
iTEgw *Olo .oVi^%
%[+F]BM]G
Ox]e`rC
GzuI<=K&MKQ
"SVv=]h
cTmi><
/CnaFw<
'Z0xWOgq(
;w!0'kg)
z}Z{}Cfxb
"#s%nt=
/ICV)Imoq)mt
xO24cp+.6py<q
6_)wsJ?
v8ZdV:4
u5gm-/*
+XmNA[b'[Q#
<g}GW|^-VZ
q jB4]./
#]3GvF
xA|3;60Y^Z
0m/@XI
=/{1?}7T
D66^hea
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
ek},6;coX+e@Sr
@\<.!*A*{Q@
#e]H Q@
>)Xz_27
/q)QnrN
D66^hea
tUQY|
Ybjv^
qk)~
|s.}3i
4TM?7i
}{QV?n?
~(SC*V
=?_yEi
mOfQZkGa
=?_yEj
7Q^\Y'b\c8#A
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
$aBW$I
`C6r?T
aifkxZ7<go[jB
c/^\\B
F<3K=/X[
";_|?O
nth,mhd2`l
;B2~p;
}pifj8Iy?
b~7M%
4B49=X1|'k
W.ihf[>
>zQV?nY>kNoM"1
E-n6;;ts'<_{_7T
r:hU&>
1^m>Eo|o~rfOeBjsHn}dq>
wg&Y|U
}cH(/.l%
/KgO/k
tRAk}'96
_[r;xlm
(&$8Da
v$I9$Me}
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.u
UN=h~%i1x
;.QX0WPp0
("dyIJ;&v
Ppw63qZ]k.xib
Z++COS
oWK++=>
|9 |9;
xC%|@m}3GDOC
2XjGm{
<Y(<=i7:K0
$ebR]5R
eUrK"v?
:EhgH%Y
?;m}Lx
FIEvS^9fz_O'
2_hxNuX
76sHYC&I
;-|)HK>D
'$DuWq
mtXNnN
Q4Oi/9
xFef\g
W^5[k9,
c{7/"Gi
llUT$pN
8(PpFO=,
N}Y7L7
u<>.sas
-^;I,Ff{|A
{\Gu[xHIcim
m5Rf`;>b
x~}Mmu&{{
$OwkPBm*
_dp8ni|[G4
ee@'_SK
\ZBHzu=
9$SB<r#G$d+
\[c)FI
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
5lKpIcY"?6cC
k4p<XJ
oO/FpX
[=yb")[_a9Z
II2\*a
[XZEuf
qtHp_]~xwSfvoG(o
~I+~-
_>=wLQSxY_Aik
RIY%][6?
nTFeQ`
M01(V~$
p1(V~$
M\/|1-J{
\{O;5
78kQ`?&:<
|9oggGSMBKy
ydhIRV
3E{e6!
}W-2G]v&Q
#^_]Ls
m=zE"E:|ZjD,60f
<_qirx
w+&3js
dnT<S~(KVKo
>O3uo~
8"72^4H
d9$w&'o4
{=N[Fr
01(``=f?
jx+Zf[Yuk2L
^O<@V5
}"};QS
khm>kb!w
rkz`o!&6
eKJMn#+]<
k?5XQ`6
>zv$3Ko~&
Zo ukRj.U|
ZL##$C
t[M?EA
QVI=v?z
i>7M;+I\xY6~t
Nco?PN$R7yu~x*H$xt
`,tw;Kh
G}s|(f)m4g
L5].m#
kX#J<J7
CVO{spM)9.1,
rNj=s\>wjWZ
3]]\Ms+K31$I$wRmkzX''
# :w[O]#KUMS
N$ah-#%mOn
|)}um@41VN
jzkC mQo5"&FV+-
OP+YIw
dbY<Tp
)H+k1>s
E-m'O'
o,|E}
}JU[^D6
~[(=Yv>
}<> qZYYP,Y$
;H}r=}x^
NtI$2(RZ;V
kr+h_Ww
WrjJQ/0
?vB2a.G4&
~k~|
&e%~b,Dd
x{Mn|9
|9O&]S
1h5*jho
K[u ko
K[uG (
[b L;R@F
9\Qf6eF&|
y#jxgR
Eeeimn
<*@oew7lfk}
SU+~<
sin[Q{+
HLM<"dd}
.-_ZYE
s-iz<~f"i>k
SR#M&N-wfm
+PdH[fx
F E2cqbn
I<(]C`V
X(@9&/v
M&[[XGu
~1Q_WO
G?/(H?vRr
]H.lX5I4dHKHf
xDZAg,mc
m&JL6G
&#jW9&;>
lti$PM>f
$/-5-F
MYw|7>M]$LV@XUQ
~x|g
V-s('|i
pwgTb*f,dm
>=}o#NB
l-P4Vs#LmvGo#8
ycHn{oLY%
PQ|5/Z5i
HnbNc[O+&vA'
q_3V/u~
mo-D0KV
z?[}jBMQZF<
<J%d792%
|$_8mF
G#v;p\V
o>Q@\?*
qW>}EbRo/9
(Bl($>
D66^hea
Q_wXz
E-mj(
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
)-g!xl#3
QE0=z]
3kDSC#F#PA
_XmQX|>
j+(xD?
s#B<UX
h}w/QT%
(`rj*/
k(`rJ)3
t2YzE'iEX
40(#G?s
(5?a)QW3
7Q^\'|pGLQ_epk
/////#
qt<ltqx^C
qt<ltlxl
qt<ltqx
#H*1x/H5X
qp/llp
h4lhlp
ltlp]
hXlhltG
lhltClll
1hllltG
>h1x/l
qh<lhqt
d4ldlt^;
pXlhql/d
D`1x5D
qp<lpqx
%'$:Tk
#(*1`2
DlpJlp
h4lhll
ltlp]
L`1x5L
s$lx(D
#(*1x/(6
qp<lt"=
pr<krQ
pr<krQ
pr<krQ
H8`1t2
TargetFrameName
PostData
Headers
Cancel
strData
strPHP
FileName
qD<lDqp
qD<lDqlll
qD<lDqtlt
qD<lDqL
qD<lDqt
>8#D*#@
#<*1p2
D@<85H
lxlp*1x
dlhJdT
l\*1\2
l`l\*1`
Jqpltlp
(`1d5(ld
qx5X:hP
`#lx]
hXl\qt/`
q\<l\qp
*#Xlh*#T
qD<lDqplp
q@<l@qt
<4l<ldlp^
hXlDql/<lp
P4lPlt
\XlHR2
q@<l@qt(
l@RpFkF
l@RpFlt
q\ltlX]
q\pVlX
q$<l$q,
q$<l$q(l(
tXl$q(/ l(
Mlxlp*F
ll.8@MX
pn/@5\
pl/@5\
+lpFDknkl
\0`1p6
\`1x5\
T`1h5T
d4ldlllp^]
ql<llqxl
<4l<^H
xXl8qp/<
Y8lp^I
Y0l4lp
ld.,@lp
#l*#4P
#$*# lplt;2
l4($ 5L
tldh`X\TP)
qT<lTq`
qT<lTq`5D
qT<lTq`
qh<lhqtlt
1llpll
d4ldlt
lX/dllJ
*#dll*#`
<lDqtltlH
ltlx^d
qplpll
l l,qtK
'('Lltv#
nhl`n8ndl\n,)
nh)\(?sh
nd)\(?sd
'%'%'%'
%ndj<%nhjL%
7Q4[0H
tXl<qT/@
@4l@ll^[
pXl<qT/@lT
@4l@ll^[
pZ/@kZ
*#@ld#
q<<l<qT
l4lllx
\4l\ltP
<`1`5<
\4l\lhll^W
P>(#TlpltP
\XTPL0,(
q\<l\qp/`
\4l\^/
qX<lXqd/\
\4l\ld^0
qX<l\l
XlXqh/\
\4l\lh
TXlTltG
\4l\lh
TXlTltG
`1l/\6
pR<kRpr
8"lT/6
\kvlxJlT
H4lHlt^C
FlxFp``1x6
H\XTPLHD@<845
q`<l`o
''>LF(l`i8
2'' '0'P
lhlp*#$
lp*1t2
ldll*#
qL<lLqplp
qplplt
(`1x5(
lx*1t2
lhlp*#$
q(<l(qX
q(<l(qX
<lHl@qdlLlDq`lX^
q(<l(q\l`ldlX^
q(<l(qTlTl\^
q(<l(qP
lXl`ld
lXl`ld
<lPl\^
q(<l(qT
*#ll*#
*#ll*#
<l@qplplD
lplt^d
qllllh
F]<l'\
T4$|l\<
FD]<T'4
4llF$`1l6
ltlx*#0
#(*#$"
*#>x#*#
*#>t#*#
*#>p#*#
*#>l#*#
tpl0,($
lhlp*#
*#>#*#
*#hlllp*#dl
lllx*#$
`#$lhv#
`#$lhv#
#@*1t2
|ltFl\@
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
l\ld*#
(8`P@
lh.@+J
lh.@+J
lh.@+J
lh.@+J
pf/ :H
kflhF`1X6
(`# 0/ 6
D4lXF$
8(tTD4
*F]:TP
*#hll*#d
lhlx*#P
*#>#*#
lp.@M8
lp.@M8
lp.@M8
lp.@M8
lp@X/P
lp@XlL
lp@X/P
lp@XlL
ldlt*#L
*#>#*#
ldlt*#L
ldlt*#L
ll.(@M4
ll.(@M4
ll.(@M4
ll.(@M4
lHR(("
lHR(xC
lHR(hP
lHR(H0
lHR(hp
lHR(X0
lHR(8v
lHR(x6
lHR(h8
lHR(XG
lHR(8u
lHR(8]
lHR((^
lHR(Ht
lHR(8C
lHR(XZ
lHR(H
lHR(x1
lHR(x|
lHR(h$
lHR(X
lHR(Hu
q<lq\l\R
84l8^T
q4<ltJlt
04l0l4
,Xl,ltG
q4<l4qp
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
#*1p2$
*#lp*1t2
ldll*#
*#>#*#
MSVBVM60.DLL
EVENT_SINK_GetIDsOfNames
MethCallEngine
EVENT_SINK_Invoke
Zombie_GetTypeInfo
EVENT_SINK_AddRef
DllFunctionCall
Zombie_GetTypeInfoCount
EVENT_SINK_Release
EVENT_SINK_QueryInterface
__vbaExceptHandler
ProcCallEngine
Y0MAVH0WFJS1D8LB70KIUMF7EJ5YJYHBG4IYS1ERZZMK4D9FBXP4HRB5UXA224AKRJGIWBR2NZ7NX992ECCE3MOBU8IYTRTO57SJQWJY4TEDB1MBEYO1AR58EQXGL6P0P912XRFIMJ6M629RLQK3JCV39XXLNP91VOIYOPJV4CWAVZJV552APAJG6G532Z6FC1A3UC740IQN3JBAX8JN9XXMOCX3N24N5F0NM4VPLE8NMAXO695VJ7OFSHU55JKL5JG4PEFNR71MI7FIZ9YYR9CX6TTSZ8IBBHS4660L8OX4K9HJ5BQDV8WI3VBFLV6KTR0OASQ90Y3IRO978CTMJ214YD11WYFRXE7PFSOQQZ2WZ4ZBHLNWXQ3ED1VH7KGO878VQ5AEEU9ETCXF4TIX3FAYG5GY8DDRRBSLEDT8BUJ9M58L1PFTUG2KB9P9RV6XQ9TGL1MVKFEEGEV64P8EF1KLV2PPYPGW9JCUDVO1OO7W14QWWEX1F952NY7S305TMFHINNUENLH7VODJLZBJ4SYJ5VKGONB41PUSTBBILABQUKRNOZWD8YD5TVXXA562VYH4FXQ7XPFQEW7IWFSF9UH3BX2E343QP8N7ZG59KZZWCI140QKQ70BTVSQMTW10IQFSFQL8FZQ26O812QU00JRC6X7FLXT1VD21SPW5Z4HRQOOWTFOAAYH1BHPKETCYPJCNJP76JPU6T6SIT969APGWIF9NTD0T79KUGEUFL7XNUEPG1UNA3O6N1PSXCTN9XVXQHWYI45CLEJVGQNLBCS8CVLJ4ZWX4MTSZ5KZHUP03VTIE7NP4Z9H8VAEQJUBFXVBXBKUN01LO0H5MF852ECYH484EL6DNYMSCBO8E0U9369KMTC3GFIPHF49YKU0D0KBL3QYKG3A47D1D8UTBIZQNFN8K8ESHYL41XFQ3DLE9VNY0WVM495W6AXTD0CX6DA0ZJO8EA4K204HYSWFX9WBTJ5CD8XLZJMJTOAEXL4FFMU6TB3L9KYE1WG31HN4CYTZXJM6Q2ZV3QZ79Q827PRAALO4A8BUHST3R457CVGARG7WMA7RV1808AM199FSW1WWPL731NQ88RQLD05HZXYPO4BC54BP8Y0PTZ5XC5ZPHE4Y40WCALLFY3B8FWH23T632VF5I3R5EAT3IO4OZ7BYR8KF0K6YKNW616U8LBMB1HHW63GE2MGS2DSUGCN6ZH9LA4XXGCE33PARA61Q7PGMCGXS6W5QQS2FM5FGDX92WPKHQQ8XXJZA6HCLXTL92FWK32NPR4ECWZRXKIUR4NFBMFTON22TXD5SIC2NB1343WNB7PVDO6L1BAD3L3TF1V8J6NBEGW2IXD51CF8608NPCBRM4BV48U7ND0Y1NERWD78VKRJY3GC4ZF5S53BVBIOCFXG5ZM8X07E11M6UIKEAZIK246MRQOBJ9T2XCN6K4668IFMFJJMI41K9XP6V9NEMB4590DE7URNKN618V9CONDZPP6FXE8Z395KH0AZLBCPQ55TA2XZF15L4K41W3JXJ434JHDQD0849A50HJZ0CQIFREJ4PJ4Y7UO66BX0WKKPCWVPQVVP4SLSQ3FAMJ64MUYBMA5W4TMNRIMZBUMDATJKOLYQ8SHEC23JZ3DVT80JIEMZ
L!This program cannot be run in DOS mode.
sisisi
ldsiRichsi
`.data
bs_bot
`=7I,f&.
Ht*N"/Wd!:O3f
tmrDoWork
tmrDDoS
tmrBrowser
tmrSpara
tmrUpdate
tmrPersistence
tmrCommands
tmrGrabber
tmrSock_timeout
tmrAlive
VB5!*
Microsoft
bs_bot
`=7I,f&.
<WA\yY{
.L?kGb
l;J*JFh'o
mswinsck.ocx
MSWinsockLib.Winsock
Winsock
f=3@aB
f=3H2B
f=305B
bs_bot
mDefines
mFuncs
mBotKiller
mWebcam
mSpread
fSteam
t*N"/Wd!
F6k7;y
`=7I,f&.
6*O3f
tmrUpdate
+3qTheBrowser_BeforeNavigate2
C:\Program Files (x86)\Microsoft Visual Studio\VB98\VB6.OLB
tmrSock_timeout
tmrSpara
tmrDoWork
tmrGrabber
tmrAlive
tmrPersistence
tmrDDoS
MTheBrowser
C:\Windows\SysWOW64\ieframe.dll
SHDocVw
tmrCommands
BROWSER_FB
tmrBrowser
TheBrowser_OnQuit
FORM_GRABBER_REPORT
KEYLOGGER_REPORT
IMAGE_REPORT
PASSWORDS_REPORT
STEAM_REPORT
EMAILS_REPORT
FILE_EXISTS
BROWSER_FB_DocumentComplete
BROWSER_FB_OnQuit
FACEBOOK_START
E;9:u9kL
+3q"=h
RegOpenKeyA
,SIfwg
kernel32.dll
GetTickCount
user32
GetForegroundWindow
GetWindowTextA
SendMessageA
kernel32
GetVolumeInformationA
GetLocaleInfoA
advapi32
RegCreateKeyA
RegSetValueExA
RegDeleteValueA
RegCloseKey
MoveFileExA
WinInet.dll
InternetOpenA
InternetOpenUrlA
txtAccName
InternetReadFile
InternetCloseHandle
WaitForSingleObject
CreateMutexA
CloseHandle
ReleaseMutex
GdiplusShutdown
DeleteUrlCacheEntryA
urlmon
URLDownloadToFileA
LoadLibraryA
CallWindowProcA
GetProcAddress
SetFilePointer
FlushFileBuffers
CreateFileA
WriteFile
GetFileSize
advapi32.dll
RegOpenKeyExA
RegEnumValueA
RegQueryValueExA
RegEnumKeyExA
RegDeleteKeyA
FindWindowA
msvbvm60
__vbaCopyBytes
ExitProcess
GDIPlus
GdipCreateBitmapFromHBITMAP
GdiplusStartup
CLSIDFromString
GdipSaveImageToFile
GdipDisposeImage
BYFZSGyh
CallNextHookEx
SetWindowsHookExA
UnhookWindowsHookEx
ToUnicodeEx
VBA6.DLL
GetWindowTextLengthA
GetKeyboardState
GetKeyState
GetAsyncKeyState
RtlMoveMemory
GetWindowDC
CreateCompatibleDC
CreateCompatibleBitmap
gdi32.dll
SelectObject
DeleteDC
ReleaseDC
DeleteObject
olepro32.dll
OleCreatePictureIndirect
StretchBlt
SetStretchBltMode
user32.dll
GetWindowRect
avicap32.dll
capGetDriverDescriptionA
capCreateCaptureWindowA
zx}E&CoCe%H
tmrKill
tmrFocus
imgLoginPressed
imgLogin
txtPassword
imgSteam
imgRemember
imgMinimize
imgClose
SetWindowPos
GetCurrentProcessId
AdjustTokenPrivileges
RtlAdjustPrivilege
LookupPrivilegeValueA
GetCurrentProcess
OpenProcess
OpenProcessToken
Process32First
Process32Next
TerminateProcess
VirtualQueryEx
ReadProcessMemory
GetModuleFileNameA
GetModuleHandleA
CreateToolhelp32Snapshot
Thread32First
Thread32Next
TerminateThread
OpenThread
ntdll.dll
NtQueryInformationThread
NtSetInformationProcess
PSAPI.DLL
GetModuleFileNameExA
EnumProcessModules
GetSystemInfo
SetForegroundWindow
GetWindowThreadProcessId
shell32.dll
ShellExecuteA
EnumWindows
ShowWindow
BringWindowToTop
SetFocus
PostMessageA
keybd_event
wUcl;J*JFh'oDDOS
JC:\Program Files (x86)\Microsoft Visual Studio\VB98\vbc14663.oca
MSWinsockLib
tmrTCP
UDPSocket
tmrUDP
UDPFlood
CallWindowProcW
^HKlYF;(4
wUcCz/A
qR^:O3f
UDPSocket
MSWinsockLib.Winsock
MSWinsockLib.Winsock
tmrUDP
tmrTCP
zx}E&CoC:O3f
fSteam
tmrKill
tmrFocus
txtPassword
Tahoma0
txtAccName
Tahoma0
imgLoginPressed
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
`03?K7
w]M{{
MJEYTXoR
SxF{Ap
n'omX$"sI
w]OQP
.F2.e^
<=N7i#YG*
kUDz|:XYi[$h=:
SxAZ>#xR
u>63Os-m/
3O;y!]
$-'VR0f-`
x|YOj+
]SM<$"FX
_7G-ozi+
'bk-NMP
?xW?5|_
p=n*+)A
q\=$I#
imgLogin
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
->g{<]=s9/*1
wQ\V:c-
2PNhZ6ko4XE
-Rk9$Xi#
/}|?.x?
~` .4@%\+
F?:%gc
?j_q?:nu^~
W+?:?@\'
?j_q?:
JqOc|a
F'v@0OC
,v^ku
7]^=
imgRemember
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
/7Oq=7.3
L,t}OZQ
V 2y/^iq,r V
}yWD6\
Lm*t?o
x{LO_lllP[s
QkWR0A
{9J(2?
imgClose
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
0F?;n (
imgMinimize
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
g;zt^:
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
2[ZDq+T
(Z{^YZ-
6Xh"!I!H$
D/u/w
k}B-QV
,9X&Ds>a(s_
pXos.t
#U_rK!(?
:E{P[izijqt
c7_hc2
,FAb~tK^g?[
[\h*Em
(-u{+tNO}
$]"o4$
t2yq,@
dw=u/O
~w3U=
V'8 Yd
thntJ+
v* :wz
swD:Q^
=wgx_E;b
][|45YlDai3
&HsSN7=>
0O"LT^[xm
Vi<icU
~)xL-G[HOP-H0q
_5vLu Q
d\os~!;|M{xS
"ega4ec
_KXtRH
iqm-v5
WKnf~;;
jWQxPm7:n{
$3M&AXx\[(n`9@
+7Z|G{]_NA{ZYd
)~mXkz^*6o(Sp
Q6COyyM
[,}d;}
k?5XQ`6
}(t5h(/1/9
ED%$B.
Ski$RxwW
x#wmgJ>
4Rj:J^
:TKyivh
>n?GEo}uZ%Tf-]
o[(u*`2t;O
w=![\jxPxn]J(#6kD
l5 LuH8
wZo@BK1
KimmeXr9
]o_g)IvnNpgX
(~T5sXQ.$
fi9I%
~V%~}kc'c
X>+h#OM
QhkF[vk
.x4=AgwqD'
FDwJciu
$~[k:(
n,N/ VR
|gmj@eqbqqi<
Bl"O?|/
o,|E}
S+o=Uo%y
g-x:W45
+|K$2X?S
!=>6{{:E$
4Q])Fxd
~)_m<_k
_V|Z[\$
6~ Tx.~Q
'/>+i-Kt
>fESjy
o>~)O7R
RZsBE0#G0f
uZ(Py"(
QR|!\j~3
Q_ixz#
YpsF:9_D=Vw
_Q$|<>(
`6b++{
PL0hl*
ncFKI7
J!14J;DJ X~IY
VG32v,"%N
\=Cu4
2A"2"neUs
xv[KMsF
d,'XMM
[\i]:sy
Xo0&WHny`|
4n-n>a
wkxY`d?
j|E}]?
!K8;\)^w#?u1u `$!-!d{2
6w 'V
k,F(QjL
"z__A[
_|N6EDVwr
fuo6[K
|kM+Nm
R[kE-D
dwL$I\
|*.5gc~
H16t3G[
b:UG+{
jz705O
?EkF5?
>&i-7 Z(m1g`
^.;kQ"y)RiT|MC7Iiq&
|T"72_HN3;+1
{(/!@[
!w2d8ub
t#IHV7
\ZY![99m<
h[\cAuEcMi
54wom/nmZ
o~|1aW
M(x' _
5'>(O]Vi
oC!'L|
EIUwxZ
C~_E;b
hr2gxj#Z
Q_wXz
~x_E;b
|IY,#qaMs
Mgql<asi[XR
z([[Iyq
RM:m6[{
`>q>`<
e9drZoe|
e'<=j\\Z
&j$$S,
{7:5{k
B[(Xdy?^
m/W_Vyg
}'qz-awuois=M
L+0E.aAb
\7FAzM
ukWM&6h
~*k:%59l
=OxGVayiz
p29\E}I{
t+Or66Y3
hyli?-
nNoEhB
ZB%ec" CJ
H16t3G[
b:UG+{
|;gWPcI+=O1
LjyI;ctqYx
:"'2G6b9&Um?V
7V#\^q
w~&Xx,hn3l
`m.;c?*
HhU"hW
n#LU],b
Z7tkwlu
\.oego
uKme~t`l
}$|km.4K
xR|3;BVth
ereKpM
uuQ.bXY)2
sm;.c~)o
_!JM+3
[c4skOs(@^C'W
V#Enl{gV."fSRH#
wI.Z6J?
}Eo>W:OJ?[q\O{W^9K.zSj+
q_}/Xz
~x_E;b
~I<AVVVosv6
^Iqj7e
j:(Cq}r
hr2gxj#Z
bW9rZ*1w
*9%9J)
GEK)4a7hr
}{Hw+V
~[))aa
(5?a3Duc
+SeTV
x6+3:d
+XX'\If
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
Ci4wI,bgv1$$
6MjS.=m
\i8yqq
B2?h-ex
|?Mx_
F<3K=/X[
.Si7\]@g
8q$M_vG
I:n[w5Y-Be+."
;B2~p;
|?Mx_
|?Mx_
|?Mx_
Am2S5X
(;[[Gw
&4Pks
Oxn5ui~9
"uRSMvnu
BM }(P
QX_G}"\$J
T*_Z_4
2K[[Uy%B,
R<t}I0;
\j,IlrI<]k
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\|
,wQE3"\``
Q]EgxvL,lg
>@\ln<[n
=>,|2H
j6u>"EYdR<|(
eo>y?v?
xSZuI^
RM.e S
}wGm).s[Z
2@%I;X
UrZ/<9["4kI
V(o>y?nIg"}
>y?nAk|-=[gi,W
tC~z/g{<Skj^K&5
}h|NXdrlm2!
9f,a!$
C$%Q_Q"
~6:,zv7'Pqmp[
c<#23.Db
O`-}yg
N_kwVo
n]K\T1
\cWEOR
k$m$wZ
Fkh`>&|q
[ZG8>'-rF
xCL<1"
.h%cWlR)!sE
_#a$R$d`
3Ev^8?y
|EFA&|GU&f
Rgn`U\FX
*{xC&XJ<FT
>.$/$S
TfsVvV]
1$QTrI
9#%YX`
\;*rcL
g?`?:_*
tU\|O]J{
y7^/?
7+~_hR|+?}:wz
_?uCxzW
MCEa}.]>
NTqyo{+
RvQed:
'K.n}?ix/
^i%WVio
kK?m>vr6mm
#O,?!Ivp<eAma?
^]\x^5KfU
p1(V~$
p1(V~$
h2 0Ip
~x_E;b
l:z}nZts#dml@Uu@I!v
"nnTJ+
w5[kGuH)|S
N]>I&y@GD'j@
$&74-RKW
@@bU^Mk
}_K_e
xltuY"Uey!a70v
95fuhR_xi
jj~$4*RMa|
/iw6mR
w~%77S
$:v^/E~+.
_<MVk[qoj
}BTn3]^N)
EMa?Q^
(5'K3>4*q C
4H4sg%[_'x|
.\$Z}/
eiB1H;s
%4GB,_
#3k^^Wpie
%4GB,_
#g"3K8-
j<Ht{+i,
Qu?i6A
YIT*)+R%Oob-/,
h|9\jvp
e8fME'
Ft{=3/
c1Z+ZF
SZm|M}cK}
VfpBMnb2G
</uY[\|5M&o
 -Io
3imoIop-
~&xd~;7
(^TS$Au
*Yd*[
nmX<N*
L.%\xOl
BO:[i&[=GjZq{{s=
4!YYK1$O&KbZ
r4T,bd$@%
o>6en<C]]M
:5[S:m}F
h.5,!.A"H
th,=Nr
QWGyfp
wI,9v;O
G0|E}
{P& *t
]OZ+pk
I58_RVW
%X#y)2
CxIQ{;xo1ZI"
nsxT/h
d~dtW
;Hm(pIwl|
x[r_A+
";~j0Lnk<
Z=v6oehe
fYj]%bIdI_K
feK]o@e4
kidU>A?QP
0^E%:/
AZ*oEn
_$}HQE
}XVu;xZ
6mN2\NzHH5
~x_E;b
n<gqq2
x -gYxMc
@ (4?_H
95GoaK
l\w>2Z([?4k
YYZ[[0aiU
guk,.=-ds=(
x^e|OZla
CHTpml+O[|/5
1w]@@Kjka)
6Lvp/^uib`E
Y^70-gi
O.h>P<
OK(<z}(<
GY#(@d
v1RkIoP5
y/0yr'
iTEgw *Olo .oVi^%
%[+F]BM]G
Ox]e`rC
GzuI<=K&MKQ
"SVv=]h
cTmi><
/CnaFw<
'Z0xWOgq(
;w!0'kg)
z}Z{}Cfxb
"#s%nt=
/ICV)Imoq)mt
xO24cp+.6py<q
6_)wsJ?
v8ZdV:4
u5gm-/*
+XmNA[b'[Q#
<g}GW|^-VZ
q jB4]./
#]3GvF
xA|3;60Y^Z
0m/@XI
=/{1?}7T
D66^hea
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
ek},6;coX+e@Sr
@\<.!*A*{Q@
#e]H Q@
>)Xz_27
/q)QnrN
D66^hea
tUQY|
Ybjv^
qk)~
|s.}3i
4TM?7i
}{QV?n?
~(SC*V
=?_yEi
mOfQZkGa
=?_yEj
7Q^\Y'b\c8#A
imgSteam
%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz
$aBW$I
`C6r?T
aifkxZ7<go[jB
c/^\\B
F<3K=/X[
";_|?O
nth,mhd2`l
;B2~p;
}pifj8Iy?
b~7M%
4B49=X1|'k
W.ihf[>
>zQV?nY>kNoM"1
E-n6;;ts'<_{_7T
r:hU&>
1^m>Eo|o~rfOeBjsHn}dq>
wg&Y|U
}cH(/.l%
/KgO/k
tRAk}'96
_[r;xlm
(&$8Da
v$I9$Me}
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.j}
o>~u>@\yo>
/t}?:>}GY
OQ?:]k.u
UN=h~%i1x
;.QX0WPp0
("dyIJ;&v
Ppw63qZ]k.xib
Z++COS
oWK++=>
|9 |9;
xC%|@m}3GDOC
2XjGm{
<Y(<=i7:K0
$ebR]5R
eUrK"v?
:EhgH%Y
?;m}Lx
FIEvS^9fz_O'
2_hxNuX
76sHYC&I
;-|)HK>D
'$DuWq
mtXNnN
Q4Oi/9
xFef\g
W^5[k9,
c{7/"Gi
llUT$pN
8(PpFO=,
N}Y7L7
u<>.sas
-^;I,Ff{|A
{\Gu[xHIcim
m5Rf`;>b
x~}Mmu&{{
$OwkPBm*
_dp8ni|[G4
ee@'_SK
\ZBHzu=
9$SB<r#G$d+
\[c)FI
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
g?`?:_*1(Y$
5lKpIcY"?6cC
k4p<XJ
oO/FpX
[=yb")[_a9Z
II2\*a
[XZEuf
qtHp_]~xwSfvoG(o
~I+~-
_>=wLQSxY_Aik
RIY%][6?
nTFeQ`
M01(V~$
p1(V~$
M\/|1-J{
\{O;5
78kQ`?&:<
|9oggGSMBKy
ydhIRV
3E{e6!
}W-2G]v&Q
#^_]Ls
m=zE"E:|ZjD,60f
<_qirx
w+&3js
dnT<S~(KVKo
>O3uo~
8"72^4H
d9$w&'o4
{=N[Fr
01(``=f?
jx+Zf[Yuk2L
^O<@V5
}"};QS
khm>kb!w
rkz`o!&6
eKJMn#+]<
k?5XQ`6
>zv$3Ko~&
Zo ukRj.U|
ZL##$C
t[M?EA
QVI=v?z
i>7M;+I\xY6~t
Nco?PN$R7yu~x*H$xt
`,tw;Kh
G}s|(f)m4g
L5].m#
kX#J<J7
CVO{spM)9.1,
rNj=s\>wjWZ
3]]\Ms+K31$I$wRmkzX''
# :w[O]#KUMS
N$ah-#%mOn
|)}um@41VN
jzkC mQo5"&FV+-
OP+YIw
dbY<Tp
)H+k1>s
E-m'O'
o,|E}
}JU[^D6
~[(=Yv>
}<> qZYYP,Y$
;H}r=}x^
NtI$2(RZ;V
kr+h_Ww
WrjJQ/0
?vB2a.G4&
~k~|
&e%~b,Dd
x{Mn|9
|9O&]S
1h5*jho
K[u ko
K[uG (
[b L;R@F
9\Qf6eF&|
y#jxgR
Eeeimn
<*@oew7lfk}
SU+~<
sin[Q{+
HLM<"dd}
.-_ZYE
s-iz<~f"i>k
SR#M&N-wfm
+PdH[fx
F E2cqbn
I<(]C`V
X(@9&/v
M&[[XGu
~1Q_WO
G?/(H?vRr
]H.lX5I4dHKHf
xDZAg,mc
m&JL6G
&#jW9&;>
lti$PM>f
$/-5-F
MYw|7>M]$LV@XUQ
~x|g
V-s('|i
pwgTb*f,dm
>=}o#NB
l-P4Vs#LmvGo#8
ycHn{oLY%
PQ|5/Z5i
HnbNc[O+&vA'
q_3V/u~
mo-D0KV
z?[}jBMQZF<
<J%d792%
|$_8mF
G#v;p\V
o>Q@\?*
qW>}EbRo/9
(Bl($>
D66^hea
Q_wXz
E-mj(
g#O}__1}O?w+n;V
f<}Q-4w
nd%*o|
o,DDRN
lo%X. s
`_J4<%'BO
Fs `nv
kl~ ~~%/
xil-r=~]MY-h8$
Rj6zBN>R]
W~^kf(yPD>RPN
l.W`T%
;4}yg~gw
!A8 ux[N
_\=im8
gVtmmfnmK@n
^6Go@6dVd-
Z:Z|7
u+rV]F;
ye>=]h
8V7J75G
cB"s*[m
lF(sj\
%jZQZA[
JQk;,F
2")7a;\
]h>(g}geI|6EGq
iRi~<$k
M%pmOJ?
'KWHBN\i;9.
!2kko!}ly_%Wu
}-O|]ExJ}F]WP]gy.n;?*Y"E
`WT6[F
%eW-G3t+OgF"`B
\)D7b[o
o>'AD0LZZXk/.
%[2c,Z "
orGG8xo u-N
u=Nl:-QNdF
!u]y5>sG=
2upU1AUb9]^9t]Vgyeh]
&e8%$:)*G Q
E8o>~)O7R
)-g!xl#3
QE0=z]
3kDSC#F#PA
_XmQX|>
j+(xD?
s#B<UX
h}w/QT%
(`rj*/
k(`rJ)3
t2YzE'iEX
40(#G?s
(5?a)QW3
7Q^\'|pGLQ_epk
/////#
qt<ltqx^C
qt<ltlxl
qt<ltqx
#H*1x/H5X
qp/llp
h4lhlp
ltlp]
hXlhltG
lhltClll
1hllltG
>h1x/l
qh<lhqt
d4ldlt^;
pXlhql/d
D`1x5D
qp<lpqx
%'$:Tk
#(*1`2
DlpJlp
h4lhll
ltlp]
L`1x5L
s$lx(D
#(*1x/(6
qp<lt"=
pr<krQ
pr<krQ
pr<krQ
H8`1t2
TargetFrameName
PostData
Headers
Cancel
strData
strPHP
FileName
qD<lDqp
qD<lDqlll
qD<lDqtlt
qD<lDqL
qD<lDqt
>8#D*#@
#<*1p2
D@<85H
lxlp*1x
dlhJdT
l\*1\2
l`l\*1`
Jqpltlp
(`1d5(ld
qx5X:hP
`#lx]
hXl\qt/`
q\<l\qp
*#Xlh*#T
qD<lDqplp
q@<l@qt
<4l<ldlp^
hXlDql/<lp
P4lPlt
\XlHR2
q@<l@qt(
l@RpFkF
l@RpFlt
q\ltlX]
q\pVlX
q$<l$q,
q$<l$q(l(
tXl$q(/ l(
Mlxlp*F
ll.8@MX
pn/@5\
pl/@5\
+lpFDknkl
\0`1p6
\`1x5\
T`1h5T
d4ldlllp^]
ql<llqxl
<4l<^H
xXl8qp/<
Y8lp^I
Y0l4lp
ld.,@lp
#l*#4P
#$*# lplt;2
l4($ 5L
tldh`X\TP)
qT<lTq`
qT<lTq`5D
qT<lTq`
qh<lhqtlt
1llpll
d4ldlt
lX/dllJ
*#dll*#`
<lDqtltlH
ltlx^d
qplpll
l l,qtK
'('Lltv#
nhl`n8ndl\n,)
nh)\(?sh
nd)\(?sd
'%'%'%'
%ndj<%nhjL%
7Q4[0H
tXl<qT/@
@4l@ll^[
pXl<qT/@lT
@4l@ll^[
pZ/@kZ
*#@ld#
q<<l<qT
l4lllx
\4l\ltP
<`1`5<
\4l\lhll^W
P>(#TlpltP
\XTPL0,(
q\<l\qp/`
\4l\^/
qX<lXqd/\
\4l\ld^0
qX<l\l
XlXqh/\
\4l\lh
TXlTltG
\4l\lh
TXlTltG
`1l/\6
pR<kRpr
8"lT/6
\kvlxJlT
H4lHlt^C
FlxFp``1x6
H\XTPLHD@<845
q`<l`o
''>LF(l`i8
2'' '0'P
lhlp*#$
lp*1t2
ldll*#
qL<lLqplp
qplplt
(`1x5(
lx*1t2
lhlp*#$
q(<l(qX
q(<l(qX
<lHl@qdlLlDq`lX^
q(<l(q\l`ldlX^
q(<l(qTlTl\^
q(<l(qP
lXl`ld
lXl`ld
<lPl\^
q(<l(qT
*#ll*#
*#ll*#
<l@qplplD
lplt^d
qllllh
F]<l'\
T4$|l\<
FD]<T'4
4llF$`1l6
ltlx*#0
#(*#$"
*#>x#*#
*#>t#*#
*#>p#*#
*#>l#*#
tpl0,($
lhlp*#
*#>#*#
*#hlllp*#dl
lllx*#$
`#$lhv#
`#$lhv#
#@*1t2
|ltFl\@
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
qp<lpqx/t
l\ld*#
(8`P@
lh.@+J
lh.@+J
lh.@+J
lh.@+J
pf/ :H
kflhF`1X6
(`# 0/ 6
D4lXF$
8(tTD4
*F]:TP
*#hll*#d
lhlx*#P
*#>#*#
lp.@M8
lp.@M8
lp.@M8
lp.@M8
lp@X/P
lp@XlL
lp@X/P
lp@XlL
ldlt*#L
*#>#*#
ldlt*#L
ldlt*#L
ll.(@M4
ll.(@M4
ll.(@M4
ll.(@M4
lHR(("
lHR(xC
lHR(hP
lHR(H0
lHR(hp
lHR(X0
lHR(8v
lHR(x6
lHR(h8
lHR(XG
lHR(8u
lHR(8]
lHR((^
lHR(Ht
lHR(8C
lHR(XZ
lHR(H
lHR(x1
lHR(x|
lHR(h$
lHR(X
lHR(Hu
q<lq\l\R
84l8^T
q4<ltJlt
04l0l4
,Xl,ltG
q4<l4qp
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
ldll*#
7R0B16BW1ND8FM98OS880GA3WL8V456E8ML1JQN21886DTTMVVWEWO39H8M5JS3PDC0WKR5ML77F56YNETC6EUOBUI51YK33X1X26GC94GYM2L0LJQMB373HJSWPTVZL4XS2R8HB88056VV6BY9EO1W59GB5A7W13X7ME61LZ3HQQQ9U90MS7K3ACJ3NE3L2ZZA3JV7Q54VA73UYR558OJXK3L51OZTOAKH6K7E5G2EN0TAX1TTHCC2IA19QSESKGFRRP8YKVMDPU9290E2BMKKUY456M1WPHWQQ4WAM3XP58ZB84F5SCG986XW0IOORZ62IT9E4WZGMCMQC4UXHAR8R2IR4MHAGSYOG7UUS1DEREM092WH7HJ23BSTA30MJ7M8LZODI481TTWVWWQYQ1D3FVXLU9PMPV5RDZWGRDKOVO82SBFM7UVDQB8Q9IGTU8OX2U3Z8G4N2SYX67I62O4BUTUGBIR00IJNBE1QM7QXNFEVZB0N68DCYR1SMTA3VTG2B365CHZ5CQQR9M8W6ENOXTSV8CQW29X12PUTEJ84A6H4C1MVS32WZG8Z70F6K7U4BKKS6U2HPKOMGWTZHXWIOMXRS2GZZ9N4IX6AZM2M0KVHPFBLORLB7BOXU3HBNQ12RA3Z5NJBD1LN2MAM9DB3HTF2EI6KQGWE9L0SXLH38YH4A7PWZLDMSALEE1C68238SAH57K9FQ6ZJR2FBC3G2ZBDYPSPXXLHCSAC3SZAZP3FBM6UDSGVZ70LAIZFUYDYWJ5Y6DK9OPQJRXFJULBD313E4ORHU0ZMZKN6SZAFDXQVWV5N4GALN33WR37QWVI3AIDD53Y2JAHQ0VH7U9UU36NPGZYKKW8EB6V2YH1QSZ4K3M7EKK4YD25K6KJCA75CGRVMKVLPX2S6OMI4PD4QUEFO1AGI081NBJ4VHQ63T06KBX5R40BNFFUP08A4Y3M8B3TNIH1Z687XAFR8OII5OFMRD502DME8FKWRYOC8MXGOVDLC2HF98JNEPYJXQ3KZ3BUTR1RKMUYDE7PVEC0MAIEI22KIPF
2c49f800-c2dd-11cf-9ad6-0080c7e7b78d
@@@@@@@
*\AC:\Users\Admin\Desktop_old\Blackshades project\bs_bot\bots\bot\bs_bot.vbp
BAAAAA
BAAAAA
KERNEL32
systemdrive
computername
253B3F412F231A302238
YHRX2JO4SMUI
@idx.db!r
672121413E2A597C2E39282A3B372B
0A3E3951213C5C3229303A06033721
1E1E007A09026066061F
09156D0A0C1F651C037B2C212D
791E080A021667027C17
021C08771216796B1F1C1C6C01
http://
/fg.php?key=
5D0C21081F0B4802053D
frmMain
&pcuser=
username
&pcname=
&hwid=
&country=
/cmd.php?key=
scr.php
webc.php
programfiles
\steam\steam.exe
appdata
SPREAD-CONTACT
SPREAD-MSG
SPREAD-TORRENT
SPREAD-FB
UPDATE
UNINSTALL
/dos.php?key=
\MSWINSCK.OCX
/plugins/ddos.bss
regsvr32.exe
GET / HTTP/1.1
Host:
Video Source
Videok
Videokilde
Video Allikas
Source vid
Sumber video
n Foinse
Font de v
Video izvora
Video avots
Video Sors
Videobron
deo Fonte
Sursa video
Fuente de v
Video Kaynak
Videoquelle
Ffynhonnell Fideo
Length
&type=Form Grabber
&data=
5D0122061A40161A1D
Content-Type
application/x-www-form-urlencoded
/plugins/mess.bss
&type=Keylogger
multipart/form-data; boundary=
Content-Disposition: form-data; name=
uploadedfile
; filename=
test.jpg
\mess.bss
Content-Type: image/jpeg
\cdky.bss
/plugins/cdky.bss
\chro.bss
/plugins/chro.bss
\dial.bss
/plugins/dial.bss
\ffpw.bss
/plugins/ffpw.bss
\iepw.bss
/plugins/iepw.bss
\mail.bss
/plugins/mail.bss
\opra.bss
/plugins/opra.bss
\pspw.bss
/plugins/pspw.bss
5D1D3A12471E0E02
&type=Email grabber
winmgmts:
ExecQuery
21022B151E0F14173100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A201823
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F041B091A171D000028311D03181B1716062817061A
Terminate
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F26010B
21220B353E2F34373100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A220221080A07030131081919020900083F3D1B1B082E
Started:
1A193911534149000C29080602131E082C4F1A0B49071D29001D0B48171528
classname
uiTextareaAutogrow input mentionsTextarea textInput
submit
http://www.facebook.com/?ref=home
http://www.facebook.com
00000000
[A-Za-z0-9]
google
abcdefghijklmnopqrstuvwxyz0123456789
(Default)
(value not set)
{557CF401-1A04-11D3-9A73-0000F81EF32E}
{1D5BE4B5-FA4A-452D-9CDD-5DB35105E7EB}
Select Name from Win32_Process Where Name = '
{Backspace}
{Ctrl}
TrueFalseFalse
FalseTrueFalse
FalseFalseTrue
SeDebugPrivilege
executarcomandos
listararquivos
renomeardir
criarpasta
CyberGate
finalizarprocessoportas
Variant of Cybergate
CONNECT %s:%i HTTP/1.0
SOFTWARE\Classes\http\shell\open\command
Software\Microsoft\Active Setup\Installed Components
StubPath
Variant of PoisonIvy
Software\Classes\http\shell\open\command
Software\Microsoft\Windows NT\CurrentVersion\SystemRestore
TConnectionThumbnail
SCREENTHUMB
--frontier--
Service Startup Changed
TRegistryRestrictions
Socks Server Stopped
UPLOADSERVER
TAudioStream
Variant of Solitude RAT
code.is.a.winner
USB spreader running
[autorun]
flood stopped
SYN packets sent
Software\Kazaa\LocalContent
Software\Microsoft\Windows\CurrentVersion\Uninstall\eMule
Variant of Bff BOT
HERE-IS-ACTIVEX-GUID
bnfa.exe
drvloadn.dll
drvloadx.dll
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\DigitalProductId
TCanvas
Error Ending Process
YuklenenDizin
Dosyalar
InstalledApplications
Apocalypse
WindowManager
Variant of Apocalypse RAT
bps1.exe
bhookpl.dll
VNCHooks.dll
xr4tdwa.exe
SOFTWARE\Microsoft\Active Setup\Installed Components
shutdown.exe
Variant of Bandook RAT
MutexDefault
TimListCache
Can NOT Change Background
TCnRawKeyBoard
PluginMutex
[SECURE]
Schwarze Sonne
HuntHTTPDownload
Variant of Schwarze Sonne RAT
texto da mensagem
capCreateCaptureWindow
software\Kazaa
software\LimeWire
RtlInitUnicodeString
autorun.inf
SPY_NET_RATMUTEX
Variant of DDoSer
Variant of SpyNet RAT
https://onlineeast#.bankofamerica.com
GRABBED TAN:
CustomerServiceMenuEntryPoint?custAction
winlogon.exe
Variant of Zeus BOT
AUTHLOADERDEFAULT
mswsock.dll
WinSock 2.0
Winlogon.exe
Network shares deleted
Registry monitor active
Variant of Dark DDoSer
\dump.txt
explorer.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run
\iepw.dat
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
windir
\system32\userinit.exe,
\system32\
/stext
\mess.dat
Chrome
\mail.dat
Application
Email
User
Password
\dial.dat
Phone / Host
User Name
Dial up
\chro.dat
Action URL
Entry Name
Internet Explorer
\ffpw.dat
Web Site
FireFox
\opra.dat
CD-KEY
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion
DigitalProductId
BCDFGHJKMPQRTVWXY2346789
\ptsg.dat
Resource Name
User Name/Value
Protected Storage
WScript.Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
RegRead
{ENTER}
WebCamCapture
\Vuze\Azureus.exe
\uTorrent\uTorrent.exe
Torrent
\uTorrent\uTorrent.exe /HIDE
\BitTorrent\bittorrent.exe
BitTorrent
\uTorrent\uTorrent.exe /DIRECTORY
/HIDE
steam.exe
((((((
(((((((((((((((E
(((((((((((
((((((
S(((((((
(((((((((((
2c49f800-c2dd-11cf-9ad6-0080c7e7b78d
@@@@@@@
*\AC:\Users\Admin\Desktop_old\Blackshades project\bs_bot\bots\bot\bs_bot.vbp
BAAAAA
BAAAAA
KERNEL32
systemdrive
computername
253B3F412F231A302238
YHRX2JO4SMUI
@idx.db!r
672121413E2A597C2E39282A3B372B
0A3E3951213C5C3229303A06033721
1E1E007A09026066061F
09156D0A0C1F651C037B2C212D
791E080A021667027C17
021C08771216796B1F1C1C6C01
http://
/fg.php?key=
5D0C21081F0B4802053D
frmMain
&pcuser=
username
&pcname=
&hwid=
&country=
/cmd.php?key=
scr.php
webc.php
programfiles
\steam\steam.exe
appdata
SPREAD-CONTACT
SPREAD-MSG
SPREAD-TORRENT
SPREAD-FB
UPDATE
UNINSTALL
/dos.php?key=
\MSWINSCK.OCX
/plugins/ddos.bss
regsvr32.exe
GET / HTTP/1.1
Host:
Video Source
Videok
Videokilde
Video Allikas
Source vid
Sumber video
n Foinse
Font de v
Video izvora
Video avots
Video Sors
Videobron
deo Fonte
Sursa video
Fuente de v
Video Kaynak
Videoquelle
Ffynhonnell Fideo
Length
&type=Form Grabber
&data=
5D0122061A40161A1D
Content-Type
application/x-www-form-urlencoded
/plugins/mess.bss
&type=Keylogger
multipart/form-data; boundary=
Content-Disposition: form-data; name=
uploadedfile
; filename=
test.jpg
\mess.bss
Content-Type: image/jpeg
\cdky.bss
/plugins/cdky.bss
\chro.bss
/plugins/chro.bss
\dial.bss
/plugins/dial.bss
\ffpw.bss
/plugins/ffpw.bss
\iepw.bss
/plugins/iepw.bss
\mail.bss
/plugins/mail.bss
\opra.bss
/plugins/opra.bss
\pspw.bss
/plugins/pspw.bss
5D1D3A12471E0E02
&type=Email grabber
winmgmts:
ExecQuery
21022B151E0F14173100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A201823
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F041B091A171D000028311D03181B1716062817061A
Terminate
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F26010B
21220B353E2F34373100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A220221080A07030131081919020900083F3D1B1B082E
Started:
1A193911534149000C29080602131E082C4F1A0B49071D29001D0B48171528
classname
uiTextareaAutogrow input mentionsTextarea textInput
submit
http://www.facebook.com/?ref=home
http://www.facebook.com
00000000
[A-Za-z0-9]
google
abcdefghijklmnopqrstuvwxyz0123456789
(Default)
(value not set)
{557CF401-1A04-11D3-9A73-0000F81EF32E}
{1D5BE4B5-FA4A-452D-9CDD-5DB35105E7EB}
Select Name from Win32_Process Where Name = '
{Backspace}
{Ctrl}
TrueFalseFalse
FalseTrueFalse
FalseFalseTrue
SeDebugPrivilege
executarcomandos
listararquivos
renomeardir
criarpasta
CyberGate
finalizarprocessoportas
Variant of Cybergate
CONNECT %s:%i HTTP/1.0
SOFTWARE\Classes\http\shell\open\command
Software\Microsoft\Active Setup\Installed Components
StubPath
Variant of PoisonIvy
Software\Classes\http\shell\open\command
Software\Microsoft\Windows NT\CurrentVersion\SystemRestore
TConnectionThumbnail
SCREENTHUMB
--frontier--
Service Startup Changed
TRegistryRestrictions
Socks Server Stopped
UPLOADSERVER
TAudioStream
Variant of Solitude RAT
code.is.a.winner
USB spreader running
[autorun]
flood stopped
SYN packets sent
Software\Kazaa\LocalContent
Software\Microsoft\Windows\CurrentVersion\Uninstall\eMule
Variant of Bff BOT
HERE-IS-ACTIVEX-GUID
bnfa.exe
drvloadn.dll
drvloadx.dll
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\DigitalProductId
TCanvas
Error Ending Process
YuklenenDizin
Dosyalar
InstalledApplications
Apocalypse
WindowManager
Variant of Apocalypse RAT
bps1.exe
bhookpl.dll
VNCHooks.dll
xr4tdwa.exe
SOFTWARE\Microsoft\Active Setup\Installed Components
shutdown.exe
Variant of Bandook RAT
MutexDefault
TimListCache
Can NOT Change Background
TCnRawKeyBoard
PluginMutex
[SECURE]
Schwarze Sonne
HuntHTTPDownload
Variant of Schwarze Sonne RAT
texto da mensagem
capCreateCaptureWindow
software\Kazaa
software\LimeWire
RtlInitUnicodeString
autorun.inf
SPY_NET_RATMUTEX
Variant of DDoSer
Variant of SpyNet RAT
https://onlineeast#.bankofamerica.com
GRABBED TAN:
CustomerServiceMenuEntryPoint?custAction
winlogon.exe
Variant of Zeus BOT
AUTHLOADERDEFAULT
mswsock.dll
WinSock 2.0
Winlogon.exe
Network shares deleted
Registry monitor active
Variant of Dark DDoSer
\dump.txt
explorer.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run
\iepw.dat
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
windir
\system32\userinit.exe,
\system32\
/stext
\mess.dat
Chrome
\mail.dat
Application
Email
User
Password
\dial.dat
Phone / Host
User Name
Dial up
\chro.dat
Action URL
Entry Name
Internet Explorer
\ffpw.dat
Web Site
FireFox
\opra.dat
CD-KEY
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion
DigitalProductId
BCDFGHJKMPQRTVWXY2346789
\ptsg.dat
Resource Name
User Name/Value
Protected Storage
WScript.Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
RegRead
{ENTER}
WebCamCapture
\Vuze\Azureus.exe
\uTorrent\uTorrent.exe
Torrent
\uTorrent\uTorrent.exe /HIDE
\BitTorrent\bittorrent.exe
BitTorrent
\uTorrent\uTorrent.exe /DIRECTORY
/HIDE
steam.exe
((((((
(((((((((((((((E
(((((((((((
((((((
S(((((((
(((((((((((
2c49f800-c2dd-11cf-9ad6-0080c7e7b78d
@@@@@@@
*\AC:\Users\Admin\Desktop_old\Blackshades project\bs_bot\bots\bot\bs_bot.vbp
BAAAAA
BAAAAA
KERNEL32
systemdrive
computername
253B3F412F231A302238
YHRX2JO4SMUI
@idx.db!r
672121413E2A597C2E39282A3B372B
0A3E3951213C5C3229303A06033721
1E1E007A09026066061F
09156D0A0C1F651C037B2C212D
791E080A021667027C17
021C08771216796B1F1C1C6C01
http://
/fg.php?key=
5D0C21081F0B4802053D
frmMain
&pcuser=
username
&pcname=
&hwid=
&country=
/cmd.php?key=
scr.php
webc.php
programfiles
\steam\steam.exe
appdata
SPREAD-CONTACT
SPREAD-MSG
SPREAD-TORRENT
SPREAD-FB
UPDATE
UNINSTALL
/dos.php?key=
\MSWINSCK.OCX
/plugins/ddos.bss
regsvr32.exe
GET / HTTP/1.1
Host:
Video Source
Videok
Videokilde
Video Allikas
Source vid
Sumber video
n Foinse
Font de v
Video izvora
Video avots
Video Sors
Videobron
deo Fonte
Sursa video
Fuente de v
Video Kaynak
Videoquelle
Ffynhonnell Fideo
Length
&type=Form Grabber
&data=
5D0122061A40161A1D
Content-Type
application/x-www-form-urlencoded
/plugins/mess.bss
&type=Keylogger
multipart/form-data; boundary=
Content-Disposition: form-data; name=
uploadedfile
; filename=
test.jpg
\mess.bss
Content-Type: image/jpeg
\cdky.bss
/plugins/cdky.bss
\chro.bss
/plugins/chro.bss
\dial.bss
/plugins/dial.bss
\ffpw.bss
/plugins/ffpw.bss
\iepw.bss
/plugins/iepw.bss
\mail.bss
/plugins/mail.bss
\opra.bss
/plugins/opra.bss
\pspw.bss
/plugins/pspw.bss
5D1D3A12471E0E02
&type=Email grabber
winmgmts:
ExecQuery
21022B151E0F14173100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A201823
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F041B091A171D000028311D03181B1716062817061A
Terminate
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F26010B
21220B353E2F34373100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A220221080A07030131081919020900083F3D1B1B082E
Started:
1A193911534149000C29080602131E082C4F1A0B49071D29001D0B48171528
classname
uiTextareaAutogrow input mentionsTextarea textInput
submit
http://www.facebook.com/?ref=home
http://www.facebook.com
00000000
[A-Za-z0-9]
google
abcdefghijklmnopqrstuvwxyz0123456789
(Default)
(value not set)
{557CF401-1A04-11D3-9A73-0000F81EF32E}
{1D5BE4B5-FA4A-452D-9CDD-5DB35105E7EB}
Select Name from Win32_Process Where Name = '
{Backspace}
{Ctrl}
TrueFalseFalse
FalseTrueFalse
FalseFalseTrue
SeDebugPrivilege
executarcomandos
listararquivos
renomeardir
criarpasta
CyberGate
finalizarprocessoportas
Variant of Cybergate
CONNECT %s:%i HTTP/1.0
SOFTWARE\Classes\http\shell\open\command
Software\Microsoft\Active Setup\Installed Components
StubPath
Variant of PoisonIvy
Software\Classes\http\shell\open\command
Software\Microsoft\Windows NT\CurrentVersion\SystemRestore
TConnectionThumbnail
SCREENTHUMB
--frontier--
Service Startup Changed
TRegistryRestrictions
Socks Server Stopped
UPLOADSERVER
TAudioStream
Variant of Solitude RAT
code.is.a.winner
USB spreader running
[autorun]
flood stopped
SYN packets sent
Software\Kazaa\LocalContent
Software\Microsoft\Windows\CurrentVersion\Uninstall\eMule
Variant of Bff BOT
HERE-IS-ACTIVEX-GUID
bnfa.exe
drvloadn.dll
drvloadx.dll
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\DigitalProductId
TCanvas
Error Ending Process
YuklenenDizin
Dosyalar
InstalledApplications
Apocalypse
WindowManager
Variant of Apocalypse RAT
bps1.exe
bhookpl.dll
VNCHooks.dll
xr4tdwa.exe
SOFTWARE\Microsoft\Active Setup\Installed Components
shutdown.exe
Variant of Bandook RAT
MutexDefault
TimListCache
Can NOT Change Background
TCnRawKeyBoard
PluginMutex
[SECURE]
Schwarze Sonne
HuntHTTPDownload
Variant of Schwarze Sonne RAT
texto da mensagem
capCreateCaptureWindow
software\Kazaa
software\LimeWire
RtlInitUnicodeString
autorun.inf
SPY_NET_RATMUTEX
Variant of DDoSer
Variant of SpyNet RAT
https://onlineeast#.bankofamerica.com
GRABBED TAN:
CustomerServiceMenuEntryPoint?custAction
winlogon.exe
Variant of Zeus BOT
AUTHLOADERDEFAULT
mswsock.dll
WinSock 2.0
Winlogon.exe
Network shares deleted
Registry monitor active
Variant of Dark DDoSer
\dump.txt
explorer.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run
\iepw.dat
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
windir
\system32\userinit.exe,
\system32\
/stext
\mess.dat
Chrome
\mail.dat
Application
Email
User
Password
\dial.dat
Phone / Host
User Name
Dial up
\chro.dat
Action URL
Entry Name
Internet Explorer
\ffpw.dat
Web Site
FireFox
\opra.dat
CD-KEY
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion
DigitalProductId
BCDFGHJKMPQRTVWXY2346789
\ptsg.dat
Resource Name
User Name/Value
Protected Storage
WScript.Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
RegRead
{ENTER}
WebCamCapture
\Vuze\Azureus.exe
\uTorrent\uTorrent.exe
Torrent
\uTorrent\uTorrent.exe /HIDE
\BitTorrent\bittorrent.exe
BitTorrent
\uTorrent\uTorrent.exe /DIRECTORY
/HIDE
steam.exe
((((((
(((((((((((((((E
(((((((((((
((((((
S(((((((
(((((((((((
2c49f800-c2dd-11cf-9ad6-0080c7e7b78d
@@@@@@@
*\AC:\Users\Admin\Desktop_old\Blackshades project\bs_bot\bots\bot\bs_bot.vbp
BAAAAA
BAAAAA
KERNEL32
systemdrive
computername
253B3F412F231A302238
YHRX2JO4SMUI
@idx.db!r
672121413E2A597C2E39282A3B372B
0A3E3951213C5C3229303A06033721
1E1E007A09026066061F
09156D0A0C1F651C037B2C212D
791E080A021667027C17
021C08771216796B1F1C1C6C01
http://
/fg.php?key=
5D0C21081F0B4802053D
frmMain
&pcuser=
username
&pcname=
&hwid=
&country=
/cmd.php?key=
scr.php
webc.php
programfiles
\steam\steam.exe
appdata
SPREAD-CONTACT
SPREAD-MSG
SPREAD-TORRENT
SPREAD-FB
UPDATE
UNINSTALL
/dos.php?key=
\MSWINSCK.OCX
/plugins/ddos.bss
regsvr32.exe
GET / HTTP/1.1
Host:
Video Source
Videok
Videokilde
Video Allikas
Source vid
Sumber video
n Foinse
Font de v
Video izvora
Video avots
Video Sors
Videobron
deo Fonte
Sursa video
Fuente de v
Video Kaynak
Videoquelle
Ffynhonnell Fideo
Length
&type=Form Grabber
&data=
5D0122061A40161A1D
Content-Type
application/x-www-form-urlencoded
/plugins/mess.bss
&type=Keylogger
multipart/form-data; boundary=
Content-Disposition: form-data; name=
uploadedfile
; filename=
test.jpg
\mess.bss
Content-Type: image/jpeg
\cdky.bss
/plugins/cdky.bss
\chro.bss
/plugins/chro.bss
\dial.bss
/plugins/dial.bss
\ffpw.bss
/plugins/ffpw.bss
\iepw.bss
/plugins/iepw.bss
\mail.bss
/plugins/mail.bss
\opra.bss
/plugins/opra.bss
\pspw.bss
/plugins/pspw.bss
5D1D3A12471E0E02
&type=Email grabber
winmgmts:
ExecQuery
21022B151E0F14173100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A201823
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F041B091A171D000028311D03181B1716062817061A
Terminate
363C322032322631393E1D17171C071B030728230C1D101B12002837100106110B07221117001D1B0B2F26010B
21220B353E2F34373100080A1C0901022B1535390F1C0922161A3225071F3F04071A30171F3E0806003A220221080A07030131081919020900083F3D1B1B082E
Started:
1A193911534149000C29080602131E082C4F1A0B49071D29001D0B48171528
classname
uiTextareaAutogrow input mentionsTextarea textInput
submit
http://www.facebook.com/?ref=home
http://www.facebook.com
00000000
[A-Za-z0-9]
google
abcdefghijklmnopqrstuvwxyz0123456789
(Default)
(value not set)
{557CF401-1A04-11D3-9A73-0000F81EF32E}
{1D5BE4B5-FA4A-452D-9CDD-5DB35105E7EB}
Select Name from Win32_Process Where Name = '
{Backspace}
{Ctrl}
TrueFalseFalse
FalseTrueFalse
FalseFalseTrue
SeDebugPrivilege
executarcomandos
listararquivos
renomeardir
criarpasta
CyberGate
finalizarprocessoportas
Variant of Cybergate
CONNECT %s:%i HTTP/1.0
SOFTWARE\Classes\http\shell\open\command
Software\Microsoft\Active Setup\Installed Components
StubPath
Variant of PoisonIvy
Software\Classes\http\shell\open\command
Software\Microsoft\Windows NT\CurrentVersion\SystemRestore
TConnectionThumbnail
SCREENTHUMB
--frontier--
Service Startup Changed
TRegistryRestrictions
Socks Server Stopped
UPLOADSERVER
TAudioStream
Variant of Solitude RAT
code.is.a.winner
USB spreader running
[autorun]
flood stopped
SYN packets sent
Software\Kazaa\LocalContent
Software\Microsoft\Windows\CurrentVersion\Uninstall\eMule
Variant of Bff BOT
HERE-IS-ACTIVEX-GUID
bnfa.exe
drvloadn.dll
drvloadx.dll
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion\DigitalProductId
TCanvas
Error Ending Process
YuklenenDizin
Dosyalar
InstalledApplications
Apocalypse
WindowManager
Variant of Apocalypse RAT
bps1.exe
bhookpl.dll
VNCHooks.dll
xr4tdwa.exe
SOFTWARE\Microsoft\Active Setup\Installed Components
shutdown.exe
Variant of Bandook RAT
MutexDefault
TimListCache
Can NOT Change Background
TCnRawKeyBoard
PluginMutex
[SECURE]
Schwarze Sonne
HuntHTTPDownload
Variant of Schwarze Sonne RAT
texto da mensagem
capCreateCaptureWindow
software\Kazaa
software\LimeWire
RtlInitUnicodeString
autorun.inf
SPY_NET_RATMUTEX
Variant of DDoSer
Variant of SpyNet RAT
https://onlineeast#.bankofamerica.com
GRABBED TAN:
CustomerServiceMenuEntryPoint?custAction
winlogon.exe
Variant of Zeus BOT
AUTHLOADERDEFAULT
mswsock.dll
WinSock 2.0
Winlogon.exe
Network shares deleted
Registry monitor active
Variant of Dark DDoSer
\dump.txt
explorer.exe
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\run
\iepw.dat
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
windir
\system32\userinit.exe,
\system32\
/stext
\mess.dat
Chrome
\mail.dat
Application
Email
User
Password
\dial.dat
Phone / Host
User Name
Dial up
\chro.dat
Action URL
Entry Name
Internet Explorer
\ffpw.dat
Web Site
FireFox
\opra.dat
CD-KEY
SOFTWARE\MICROSOFT\Windows NT\CurrentVersion
DigitalProductId
BCDFGHJKMPQRTVWXY2346789
\ptsg.dat
Resource Name
User Name/Value
Protected Storage
WScript.Shell
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName
RegRead
{ENTER}
WebCamCapture
\Vuze\Azureus.exe
\uTorrent\uTorrent.exe
Torrent
\uTorrent\uTorrent.exe /HIDE
\BitTorrent\bittorrent.exe
BitTorrent
\uTorrent\uTorrent.exe /DIRECTORY
/HIDE
steam.exe
((((((
(((((((((((((((E
(((((((((((
((((((
S(((((((
(((((((((((

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.