Analysis Date2015-11-30 14:50:27
MD5ad1146f8ba89baf442b1901b729e73a3
SHA111b211e478959857cb7629f5bf1c6beb034f703b

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 60aabd821c768bffdd374cb4b3fc995c sha1: a97ee052d9f0a89e72d4da626c8f1803b3ae39b8 size: 284672
Section.rdata md5: a505c021efbc0e93f9abee2bcb676cc7 sha1: b38c1ed0f3d12ff50ebf3c5f6b1beefec8b837e7 size: 39424
Section.data md5: cd74c3b0b9b9965bfcf95e78f21592ae sha1: 1d91d30b3db60bb5d8d3b40c9928a45225704b23 size: 7168
Timestamp2015-11-23 03:16:18
PackerMicrosoft Visual C++ ?.?
PEhashd214f8af3e5eccfd42ae77680a340e1023d8a10c
IMPhash1a781b7847edf8cc6708f4075f749ec4
AVAd-Aware Command-LineTrojan.GenericKD.2894382
AVArcaVir AntivirusTrojan.GenericKD.2894382
AVAvast! AntivirusMalware-gen:Win32:Malware-gen
AVAVG AntiVirusDropper.Generic_r.EC
AVAvira AntivirusTR/Crypt.ZPACK.217554
AVBitdefender Command-LineTrojan.GenericKD.2894382
AVBullGuard AntivirusTrojan.GenericKD.2894382
AVClamWin AntivirusNo Virus
AVCommand Anti-MalwareW32/Kazy.EW.gen!Eldorado:Security risk
AVDr. Web Anti-virusNo Virus
AVEmsisoft Command-Line ScannerTrojan.GenericKD.2894382
AVeScan Anti-VirusNo Virus
AVESET NOD32 AntivirusWin32/Bayrob.AD
AVFortinet Command-Line ScannerW32/Bayrob.AD!tr
AVF-PROT AntivirusNo Virus
AVF-Secure Anti-VirusTrojan.GenericKD.2894382
AVIkarus Command-Line ScannerNo Virus
AVK7 Anti-VirusTrojan ( 004d79c41 )
AVKaspersky Anti-VirusTrojan.Win32.Tinba.yuh
AVMalwareBytes Anti-MalwareNo Virus
AVMcAfee Command-Line ScannerBackDoor-FCYZ!AD1146F8BA89
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort.CE:Trojan
AVPadvish AntivirusNo Virus
AVQuick Heal AntiVirusNo Virus
AVRising Command-Line ScannerNo Virus
AVSymantec Command-Line ScannerNo Virus
AVTotal Defense Internet Security SuiteNo Virus
AVTrend Micro System CleanerNo Virus
AVTwister AntivirusNo Virus
AVVirusBlokAda Console ScannerNo Virus
AVZillya! AntivirusNo Virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\zktgkjakld\ig1ghszknple0yoq8.exe
Creates FileC:\zktgkjakld\fpzipn
Creates FileC:\WINDOWS\zktgkjakld\fpzipn
Deletes FileC:\WINDOWS\zktgkjakld\fpzipn
Creates ProcessC:\zktgkjakld\ig1ghszknple0yoq8.exe

Process
↳ C:\zktgkjakld\ig1ghszknple0yoq8.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Audio UserMode Player KtmRm Program ➝
C:\zktgkjakld\regtcrxs.exe
Creates FileC:\zktgkjakld\regtcrxs.exe
Creates FileC:\zktgkjakld\fpzipn
Creates FilePIPE\lsarpc
Creates FileC:\zktgkjakld\ipkwmlcbze
Creates FileC:\WINDOWS\zktgkjakld\fpzipn
Deletes FileC:\WINDOWS\zktgkjakld\fpzipn
Creates ProcessC:\zktgkjakld\regtcrxs.exe
Creates ServiceBiometric Layer TP Video PNRP Notification - C:\zktgkjakld\regtcrxs.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 816

Process
↳ Pid 864

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\Prefetch\RUNDLL32.EXE-1BC69D2D.pf
Creates FileC:\WINDOWS\Prefetch\IG1GHSZKNPLE0YOQ8.EXE-0BC1D43C.pf
Creates FileC:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf
Creates FileC:\WINDOWS\Prefetch\NET1.EXE-029B9DB4.pf
Creates FileC:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf
Creates FileC:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf
Creates FileC:\WINDOWS\Prefetch\READER_SL.EXE-3614FA6E.pf
Creates FileC:\WINDOWS\Prefetch\monitor.exe-1949D260.pf
Creates FileC:\WINDOWS\Prefetch\SCCWHPDIR.EXE-156EA7E4.pf
Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log
Creates FileC:\WINDOWS\Prefetch\REGTCRXS.EXE-1CFABDCF.pf
Creates FileC:\WINDOWS\Prefetch\svchost.EXE-0C867EC1.pf

Process
↳ Pid 1220

Process
↳ Pid 1308

Process
↳ Pid 1864

Process
↳ Pid 1968

Process
↳ C:\zktgkjakld\regtcrxs.exe

Creates Filepipe\net\NtControlPipe10
Creates FileC:\zktgkjakld\sccwhpdir.exe
Creates FileC:\zktgkjakld\fpzipn
Creates FileC:\zktgkjakld\ipkwmlcbze
Creates File\Device\Afd\Endpoint
Creates FileC:\zktgkjakld\qunv4ux
Creates FileC:\WINDOWS\zktgkjakld\fpzipn
Deletes FileC:\WINDOWS\zktgkjakld\fpzipn
Creates Processdcycexlqh1ei "c:\zktgkjakld\regtcrxs.exe"

Process
↳ C:\zktgkjakld\regtcrxs.exe

Creates FileC:\zktgkjakld\fpzipn
Creates FileC:\WINDOWS\zktgkjakld\fpzipn
Deletes FileC:\WINDOWS\zktgkjakld\fpzipn

Process
↳ dcycexlqh1ei "c:\zktgkjakld\regtcrxs.exe"

Creates FileC:\zktgkjakld\fpzipn
Creates FileC:\WINDOWS\zktgkjakld\fpzipn
Deletes FileC:\WINDOWS\zktgkjakld\fpzipn

Network Details:

DNSchiefapple.net
Type: A
82.165.25.210
DNSchiefbuilt.net
Type: A
195.22.28.196
DNSchiefbuilt.net
Type: A
195.22.28.197
DNSchiefbuilt.net
Type: A
195.22.28.198
DNSchiefbuilt.net
Type: A
195.22.28.199
DNStwelvebuilt.net
Type: A
98.139.135.129
DNStwelvecarry.net
Type: A
208.91.197.241
DNSmorningapple.net
Type: A
222.122.84.70
DNSstrangeapple.net
Type: A
82.165.25.210
DNSweatherfather.net
Type: A
208.100.26.234
DNSweatherbuilt.net
Type: A
203.27.227.220
DNSthickapple.net
Type: A
95.211.230.75
DNSpresentmeasure.net
Type: A
95.211.230.75
DNScollegemeasure.net
Type: A
184.168.221.31
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNScollegecircle.net
Type: A
50.63.202.52
DNSsk129.webcname.net
Type: A
182.18.22.158
DNSpresentalways.net
Type: A
208.100.26.234
DNSthinkforest.net
Type: A
59.8.236.130
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSpresentapple.net
Type: A
DNSthinkbuilt.net
Type: A
DNSpresentbuilt.net
Type: A
DNSthinkcarry.net
Type: A
DNSpresentcarry.net
Type: A
DNSchieffather.net
Type: A
DNScollegefather.net
Type: A
DNScollegeapple.net
Type: A
DNScollegebuilt.net
Type: A
DNSchiefcarry.net
Type: A
DNScollegecarry.net
Type: A
DNSoftenfather.net
Type: A
DNSalonefather.net
Type: A
DNSoftenapple.net
Type: A
DNSaloneapple.net
Type: A
DNSoftenbuilt.net
Type: A
DNSalonebuilt.net
Type: A
DNSoftencarry.net
Type: A
DNSalonecarry.net
Type: A
DNSmiddlefather.net
Type: A
DNStwelvefather.net
Type: A
DNSmiddleapple.net
Type: A
DNStwelveapple.net
Type: A
DNSmiddlebuilt.net
Type: A
DNSmiddlecarry.net
Type: A
DNSratherfather.net
Type: A
DNSmorningfather.net
Type: A
DNSratherapple.net
Type: A
DNSratherbuilt.net
Type: A
DNSmorningbuilt.net
Type: A
DNSrathercarry.net
Type: A
DNSmorningcarry.net
Type: A
DNSstrangefather.net
Type: A
DNShistoryfather.net
Type: A
DNShistoryapple.net
Type: A
DNSstrangebuilt.net
Type: A
DNShistorybuilt.net
Type: A
DNSstrangecarry.net
Type: A
DNShistorycarry.net
Type: A
DNSamountfather.net
Type: A
DNSamountapple.net
Type: A
DNSweatherapple.net
Type: A
DNSamountbuilt.net
Type: A
DNSamountcarry.net
Type: A
DNSweathercarry.net
Type: A
DNSthickfather.net
Type: A
DNSclassfather.net
Type: A
DNSclassapple.net
Type: A
DNSthickbuilt.net
Type: A
DNSclassbuilt.net
Type: A
DNSthickcarry.net
Type: A
DNSclasscarry.net
Type: A
DNSthinkmeasure.net
Type: A
DNSthinkdinner.net
Type: A
DNSpresentdinner.net
Type: A
DNSthinkafraid.net
Type: A
DNSpresentafraid.net
Type: A
DNSthinkcircle.net
Type: A
DNSpresentcircle.net
Type: A
DNSchiefmeasure.net
Type: A
DNSchiefdinner.net
Type: A
DNScollegedinner.net
Type: A
DNSchiefafraid.net
Type: A
DNScollegeafraid.net
Type: A
DNSchiefcircle.net
Type: A
DNSoftenmeasure.net
Type: A
DNSalonemeasure.net
Type: A
DNSoftendinner.net
Type: A
DNSalonedinner.net
Type: A
DNSoftenafraid.net
Type: A
DNSaloneafraid.net
Type: A
DNSoftencircle.net
Type: A
DNSalonecircle.net
Type: A
DNSmiddlemeasure.net
Type: A
DNStwelvemeasure.net
Type: A
DNSmiddledinner.net
Type: A
DNStwelvedinner.net
Type: A
DNSmiddleafraid.net
Type: A
DNStwelveafraid.net
Type: A
DNSmiddlecircle.net
Type: A
DNStwelvecircle.net
Type: A
DNSrathermeasure.net
Type: A
DNSmorningmeasure.net
Type: A
DNSratherdinner.net
Type: A
DNSmorningdinner.net
Type: A
DNSratherafraid.net
Type: A
DNSmorningafraid.net
Type: A
DNSrathercircle.net
Type: A
DNSmorningcircle.net
Type: A
DNSstrangemeasure.net
Type: A
DNShistorymeasure.net
Type: A
DNSstrangedinner.net
Type: A
DNShistorydinner.net
Type: A
DNSstrangeafraid.net
Type: A
DNShistoryafraid.net
Type: A
DNSstrangecircle.net
Type: A
DNShistorycircle.net
Type: A
DNSamountmeasure.net
Type: A
DNSweathermeasure.net
Type: A
DNSamountdinner.net
Type: A
DNSweatherdinner.net
Type: A
DNSamountafraid.net
Type: A
DNSweatherafraid.net
Type: A
DNSamountcircle.net
Type: A
DNSweathercircle.net
Type: A
DNSthickmeasure.net
Type: A
DNSclassmeasure.net
Type: A
DNSthickdinner.net
Type: A
DNSclassdinner.net
Type: A
DNSthickafraid.net
Type: A
DNSclassafraid.net
Type: A
DNSthickcircle.net
Type: A
DNSclasscircle.net
Type: A
DNSthinkwheat.net
Type: A
DNSpresentwheat.net
Type: A
DNSthinkanger.net
Type: A
DNSpresentanger.net
Type: A
DNSthinkalways.net
Type: A
DNSpresentforest.net
Type: A
DNSchiefwheat.net
Type: A
DNScollegewheat.net
Type: A
DNSchiefanger.net
Type: A
DNScollegeanger.net
Type: A
DNSchiefalways.net
Type: A
DNScollegealways.net
Type: A
DNSchiefforest.net
Type: A
DNScollegeforest.net
Type: A
DNSoftenwheat.net
Type: A
DNSalonewheat.net
Type: A
DNSoftenanger.net
Type: A
DNSaloneanger.net
Type: A
DNSoftenalways.net
Type: A
DNSalonealways.net
Type: A
DNSoftenforest.net
Type: A
DNSaloneforest.net
Type: A
DNSmiddlewheat.net
Type: A
DNStwelvewheat.net
Type: A
DNSmiddleanger.net
Type: A
DNStwelveanger.net
Type: A
DNSmiddlealways.net
Type: A
DNStwelvealways.net
Type: A
DNSmiddleforest.net
Type: A
DNStwelveforest.net
Type: A
DNSratherwheat.net
Type: A
DNSmorningwheat.net
Type: A
DNSratheranger.net
Type: A
DNSmorninganger.net
Type: A
DNSratheralways.net
Type: A
DNSmorningalways.net
Type: A
DNSratherforest.net
Type: A
DNSmorningforest.net
Type: A
DNSstrangewheat.net
Type: A
DNShistorywheat.net
Type: A
DNSstrangeanger.net
Type: A
DNShistoryanger.net
Type: A
DNSstrangealways.net
Type: A
HTTP GEThttp://chiefapple.net/index.php
User-Agent:
HTTP GEThttp://chiefbuilt.net/index.php
User-Agent:
HTTP GEThttp://twelvebuilt.net/index.php
User-Agent:
HTTP GEThttp://twelvecarry.net/index.php
User-Agent:
HTTP GEThttp://morningapple.net/index.php
User-Agent:
HTTP GEThttp://strangeapple.net/index.php
User-Agent:
HTTP GEThttp://weatherfather.net/index.php
User-Agent:
HTTP GEThttp://weatherbuilt.net/index.php
User-Agent:
HTTP GEThttp://thickapple.net/index.php
User-Agent:
HTTP GEThttp://presentmeasure.net/index.php
User-Agent:
HTTP GEThttp://collegemeasure.net/index.php
User-Agent:
HTTP GEThttp://collegeafraid.net/index.php
User-Agent:
HTTP GEThttp://collegecircle.net/index.php
User-Agent:
HTTP GEThttp://thinkalways.net/index.php
User-Agent:
HTTP GEThttp://presentalways.net/index.php
User-Agent:
HTTP GEThttp://thinkforest.net/index.php
User-Agent:
HTTP GEThttp://morningwheat.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1032 ➝ 195.22.28.196:80
Flows TCP192.168.1.1:1033 ➝ 98.139.135.129:80
Flows TCP192.168.1.1:1034 ➝ 208.91.197.241:80
Flows TCP192.168.1.1:1035 ➝ 222.122.84.70:80
Flows TCP192.168.1.1:1036 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1037 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1038 ➝ 203.27.227.220:80
Flows TCP192.168.1.1:1039 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1040 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1041 ➝ 184.168.221.31:80
Flows TCP192.168.1.1:1042 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1043 ➝ 50.63.202.52:80
Flows TCP192.168.1.1:1044 ➝ 182.18.22.158:80
Flows TCP192.168.1.1:1045 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1046 ➝ 59.8.236.130:80
Flows TCP192.168.1.1:1047 ➝ 8.5.1.16:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   68696566 6170706c 652e6e65 740d0a0d   hiefapple.net...
0x00000050 (00080)   0a                                    .

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   68696566 6275696c 742e6e65 740d0a0d   hiefbuilt.net...
0x00000050 (00080)   0a                                    .

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   77656c76 65627569 6c742e6e 65740d0a   welvebuilt.net..
0x00000050 (00080)   0d0a                                  ..

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   77656c76 65636172 72792e6e 65740d0a   welvecarry.net..
0x00000050 (00080)   0d0a                                  ..

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f726e69 6e676170 706c652e 6e65740d   orningapple.net.
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   7472616e 67656170 706c652e 6e65740d   trangeapple.net.
0x00000050 (00080)   0a0d0a                                ...

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 65726661 74686572 2e6e6574   eatherfather.net
0x00000050 (00080)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 65726275 696c742e 6e65740d   eatherbuilt.net.
0x00000050 (00080)   0a0d0a0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   6869636b 6170706c 652e6e65 740d0a0d   hickapple.net...
0x00000050 (00080)   0a0d0a0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   72657365 6e746d65 61737572 652e6e65   resentmeasure.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656d65 61737572 652e6e65   ollegemeasure.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656166 72616964 2e6e6574   ollegeafraid.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656369 72636c65 2e6e6574   ollegecircle.net
0x00000050 (00080)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   68696e6b 616c7761 79732e6e 65740d0a   hinkalways.net..
0x00000050 (00080)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   72657365 6e74616c 77617973 2e6e6574   resentalways.net
0x00000050 (00080)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   68696e6b 666f7265 73742e6e 65740d0a   hinkforest.net..
0x00000050 (00080)   0d0a0d0a                              ....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f726e69 6e677768 6561742e 6e65740d   orningwheat.net.
0x00000050 (00080)   0a0d0a0a                              ....


Strings
\
.
 
"
 
\
.
-E-
-0
-0010+-0
-0
.
00-+ 
.00-+ *00-+ 
.
-e-
. 
.
-e-
. 
CC
\
 
0
0
-
,
>
..
- 
0
0
 
-
-
--
..
.
u
- abort() has been called
ADVAPI32.DLL
April
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
August
CONOUT$
- CRT not initialized
dddd, MMMM dd, yyyy
December
DMicrosoft Visual C++ Runtime Library
DOMAIN error
EKERNEL32.DLL
February
- floating point support not loaded
Friday
                                 H
         (((((                  H
         h((((                  H
HH:mm:ss
January
jjjjj
July
June
March
MM/dd/yy
Monday
mscoree.dll
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
(null)
October
Program: 
<program name unknown>
- pure virtual function call
R6002
R6008
R6009
R6010
R6016
R6017
R6018
R6019
R6024
R6025
R6026
R6027
R6028
R6030
R6031
R6032
R6033
runtime error 
Runtime Error!
Saturday
September
SING error
Sunday
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
Thursday
TLOSS error
Tuesday
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
Wednesday
WUSER32.DLL
                          
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
<0|L<9
0t1HHt
0Wh$>E
1#QNAN
1#SNAN
*2Kvq#
\3kkH`v
;7|G;p
8vayle judqest vslib vtcoynl apizdi hfdoezzye pganoa rkbu nrbufu ecfsiflwef atfn xfjoujs osocj dnogesdu caajigu pepsagjil ldbe bqcezmpoj zzgonpm dnyibg chujovxpot bfbupgs npgu flemovzavu igbuesi xgfugyno lpfoemzj eeiue smyakmvis gsyebnvejm pfio fhfukpfa djefoj puecdeadlz elpifikwq zmrugpp paapsiu sgsu bgno jzxol zmb vojbofr obxjeiidt gbgioogimu nsfepsoqew vjuz naafmixmdi cya kjn hmnujl riopbes ljoveod nflec zvpabcqeb gdoeosu dbyaj uoahdwelbi mgpaafegc rbso cbdenvbam eqkn zbame mujyiuxufb usqpa moxjism bmsipmeeci hmnicjco ptcajvjix burfepo fzonen cmcob tvsuif ubdtav tueahkad pddorlqa ziyiaqagq jjmeuippy mufdoalev meseuidago lcnazpizo itcfius noixilojo amgb lfyebm drobi a
A~]4/=
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
`adjustor{
america
american
american english
american-english
`anonymous namespace'
AtJHt4Hu
<at,<rt"<wt
August
australian
.?AVbad_alloc@std@@
.?AVbad_alloc@stdext@@
.?AVbad_cast@std@@
.?AVbad_exception@std@@
.?AVbad_typeid@std@@
.?AVexception@std@@
.?AVexception@stdext@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVlogic_error@std@@
.?AV__non_rtti_object@std@@
.?AVout_of_range@std@@
.?AVoverflow_error@std@@
.?AVruntime_error@std@@
.?AVtype_info@@
bad allocation
bad exception
baqfabpmu jnqicldon ljxule jrezuz umybaqbm tccuqcd kvfocfsidb btpidr vgfopfh lltodg ukbkemddo bmsitmbene fcvu czjo wpu lwcuugibes vdbiyzxom bnleilvdu ieoybh rjverbc lskayr zou geushuw wyhicajsu snpeffma enfgognbo itgfubs efst euycqik ptzoi bruodi jtcar sbkirseb bdc daoe lgcescoiyi qbrojecm uhcjantole hgdelbur gifdayxce betreijeea pipzicos aacjxes dcbogtz suupmoug fdjutej idqcesbduc lffanndam jdronppe gjduu bmgopppu fvcas jlf rmjuiclfib fxca bejzal gmdizine ajufrapli lid pgfu hlaufop mdojonocp pml ipg lufdi jutqi leuels ecgde cslobmek qbvensu jlipox bijferd czsei gffadekin zfgusizwii fzligpbidv wogxocz emalq fbbec jorjovn snnap cmjauyna wfwoelloce mqeo znzatpul kjbemfdo silb ldz xjvooff nsviraocp cqfejjmoif jucgo xscambu mafcic
 Base Class Array'
 Base Class Descriptor at (
__based(
belgian
britain
canadian
Cb.#|Y
__cdecl
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
CHPjPV
class 
 Class Hierarchy Descriptor'
cli::array<
cli::pin_ptr<
CloseHandle
CLPjQV
__clrcall
coclass 
cointerface 
CompareStringW
 Complete Object Locator'
const 
`copy constructor closure'
CorExitProcess
C PjPV
C$PjQV
C.PjRV
C/PjSV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
CreateFileA
CreateFileW
cy6l{i
@.data
dddd, MMMM dd, yyyy
December
DecodePointer
`default constructor closure'
 delete
 delete[]
DeleteCriticalSection
double
Dtl>Fw
dutch-belgian
`dynamic atexit destructor for '
`dynamic initializer for '
__eabi
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
<ellipsis>
,<ellipsis>
EncodePointer
england
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
EnterCriticalSection
EnumSystemLocalesA
eumlceefmo yrsuagamce rfwoofg hoajfiszdu ldr dnto fcugegzjad ivkiuyobd fuph nlkurc cijnecgzab cztupszi nkatiggg dgbepydel bcugugvjop mlfae sjup zjmullb lfcescsu jbpigq jnl bplob caz pmifibjja dwv gednapion jdnoazdl qksugm irrewo ruo lbbuhetj foiu mcfieesxg urvtao ljno osaeabpun unymiturfa dscu agysoifc umkrawmhan cnwebnza lmma cmdoxfxuim bcdepweco mqgimsmi rpfin uaui sibf hda dbbaboz lpopadjdip ibwfaj vdnaagqto lfvogd ddpeozouj fwi udbf hziamanij crna bsnef fnyov iec gflajdsui qdluiihxx ndoe bpupupgji fqtoj afsxap gkqelbw jmg fcilaij qlf lchepdnidi rctiqjb kocqosgaco loumz bmrevu bfqax dpjun nbcusbt tzvuil arbubei mpcaf hbawefge fuse pqm owwpucbda cdieiab tegheezdgu cppegs qlzoj difvem lopsunfe wtlod bzjevqob nocci nsraneyric bbt mliqappq mbv zzgogdral tvwijlsaj cbmuoy
ExitProcess
extern "C" 
F0Pj.S
F4Pj/S
F8PjDS
__fastcall
FatalAppExitA
FDPjGS
FdPjOS
February
FhPj8S
FHPjHS
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileExA
{flat}
FlPj9S
FLPjIS
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
F<PjES
F@PjFS
F\PjMS
F`PjNS
F|Pj=S
F Pj*S
F,Pj-S
F(Pj,S
F$Pj+Sj
FPPjJS
FpPj:S
FreeEnvironmentStringsW
FreeLibrary
french-belgian
french-canadian
french-luxembourg
french-swiss
Friday
Ft,Ot	OtFOt#OuV
FTPjKS
FtPj;S
FXPjLS
FxPj<S
generic-type-
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
GetACP
GetActiveWindow
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetCPInfo
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDriveTypeA
GetDriveTypeW
GetEnvironmentStringsW
GetFileInformationByHandle
GetFileType
GetFullPathNameA
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount
GetTimeZoneInformation
GetUserDefaultLCID
GetUserObjectInformationW
gfnavb nlbe zrveasal dnosanqh zjvi iomefvam gsmug cdlot frludjjiu gjsopf cbg bjheg slo tusjene lkiweqgne nugsaaerq ynhencluvc dtedeoitf hibrulsm eclcuxejnu dasgilsz igryophl dzu nhjom rysu screejs cfriszy pftijbmaiz ebnvaemfep olglaenm vclic lmn pgc zcetef jxgayfli uhj drlafwwo opeigco smicusjzi kdaunoddt hryefvi fytoasd ablu mguy bvm cnesa dcved tbnixt ajtsimlese icet nefc ddax bpucojlon vtaloairft lnpovlip dtp jedzojbb onernogfca hhmafdj vjufe myfeps nac mduapeu yjtek mbboiyz tjlobgsocj nll zfmiffhuc cogju axdgiatzm dfiape mldef gsjalusbo dffebdfiew bgrahll obbpisqt majmohgpiu jepigic mvge rnesusj ddca fcbarnape nlbegda encivien qclodexp qtgo jesmu rclaaj cddagsopi zjdujjgoc humt gpdintaju dix fazber uesffaclpu uqf
great britain
`h````
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
`h`hhh
HH:mm:ss
HHt*HHt
HHtiHHt
HHtXHHt
HHtYHHt
holland
hong-kong
I7NyE(
?If90t
	If90t
InitializeCriticalSectionAndSpinCount
__int128
__int16
__int32
__int64
__int8
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
invalid map/set<T> iterator
invalid string position
irish-english
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
italian-swiss
<it|<otx<utt<xtp<Xtl
JanFebMarAprMayJunJulAugSepOctNovDec
January
j@hDBE
Jjr'q^
j@j ^V
j"X_^[]
KERNEL32.dll
@koffge sngexzno jjbimc mjzaa odadqeg aeignjomv ilfziasw dfiloidgla ojcfoodvp oatxno myajebo sebq upggil zsk zokp sjcec edaw rufor ttqastvecs fcralgl xddizned tavker bxue kyiwu erjfag vimnomot ubuevsu reewb glnal adxkoanb tudf okgxaxij lfuciuruci ljgasujh avwerez rjmuni bejcutr siw gcoatuueo jyfulqgudf srjanc fbb gldeymon kjgo ucctolceb yubuem jqgebils rsvonbbic agxhe ugdyobfjep girdelpse puntiiljni gdool jatri ddtob gltefqwal ugcutig oqewnuf vjhies idodfupe dvbodkpanf kep gfcovhl fseih nxpilfcobg jlpaa bsbeciszuo obnsiie ezm vezd velbe ydouqoemza dcoid lfwu jllissfuof dqv erptiosvm emufguycva vthe edrtelgmu dzjutmd aju frfasncipc ffkomloje mbc zrfocgm ngbelsbiiz eczzeokW
kWQ*JU
LC_ALL
LC_COLLATE
LC_CTYPE
LCMapStringW
LC_MONETARY
LC_NUMERIC
LC_TIME
LeaveCriticalSection
LoadLibraryW
`local static destructor helper'
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
map/set<T> too long
MessageBoxW
MM/dd/yy
Monday
MultiByteToWideChar
 new[]
new-zealand
Nn|G%Z
`non-type-template-parameter
norwegian
norwegian-bokmal
norwegian-nynorsk
Norwegian-Nynorsk
November
(null)
nUnuacpiv jbacozi jifsinqsof dbzaz arz aeaonfj bbneii zfcithv ctnejvni dsfu drjul ibhnoeg ocrvafbbo vcfoc ouxt zcsaza fud oeusxpipe etengiljv lxzainsjip bksuuefj jij auezwxobc gwqencp ajzlu alfbephumi xqd iyrzosm bdga onzjoldjug vznak ozuupomeod vfde vpdu fiwqijbza rjugucma ahzt lcjosflez gpie bpoag suvk fdmajpunuv nrofonmja dishaahm pezoj wuhuelipp ochtim xyve ddbijfdu vtaifefb duecc xbli qorfacmo flxefc frg ixozropoly jdeb wpdo ffxir bkd pirfee llijiibb sswoe vogcuqtba nzjevoell rfj ffl nnkiepne ptcazkbeix rzuviczniv vcakejjpe noihfo akgdo ionnd mfdeppb lligobcb anjumirn xpnemfeve tfnupmey jimiaet bbqihbacu cmlubsune nvmixvh dslafhlajx iembu spuurudqg omutlanb zcn cilmuapo matkir acli rhdu ifmp jkdopjus ltg ccaniybisoz
October
`omni callsig'
operator
__pascal
PeekNamedPipe
Pf95d>E
`placement delete closure'
`placement delete[] closure'
/pocou gju davligj bsqe nnqujbu cvtubpkeig htbeizlje pcrirwg jksumgep rrcuuspf facu fkebaddwo ogido csavuce man gpcuhj cfpoqq ftvanfzo uvfdexovda yoh ziabridk ftg fifeco bti xvitabzjeo vssufrt rpgi pogjovm jdfapk dihoaqoar bjrax asu babber kbtiuggfi fpcel cmt xfceaj pdimeomg gjdewvamau ngmutm uxnuije lldaua nzmonrcap shajiqcg cwaasijuzj utah bua vcde pilgepao zhpofx jtunuu imgjeidcd zdnucgo olx jzehavm zglal paeu zfmuia wdbagoq ajzqui vjmaojfguv lsmoudp depjugjlat dkcaibm tzdun bclacatl zgwufjjij riogqi lmofewwu spju cmcejrq nvmongke larcib stfilsdooq jrbif gnj jmtevbba nacj oxlbaqrsa poddunf oognjig jag tukur zfzervvezt gvuru oydjuaofgo nbp lpe iiwsp ldmobjhueg asmoseftle zljors kcgibc inuroqi fnxipppa
portuguese-brazilian
PPPPPPPP
pr china
pr-china
private: 
protected: 
__ptr64
public: 
puerto-rico
	qn&{;
QQSVWd
QueryPerformanceCounter
RaiseException
`.rdata
ReadFile
__restrict
RtlUnwind
Saturday
`scalar deleting destructor'
September
SetConsoleCtrlHandler
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableA
SetFilePointer
SetHandleCount
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
short 
signed 
sj@hDBE
slovak
south africa
south-africa
south korea
south-korea
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
^SSSSS
static 
__stdcall
std::nullptr_t
`string'
string too long
struct 
Sunday
SunMonTueWedThuFriSat
swedish-finland
SystemFunction036
t4<@t;V
tCHt(Ht 
`template-parameter
template-parameter-
`template static data member constructor helper'
`template static data member destructor helper'
TerminateProcess
<?tG<Xt
+t HHt
__thiscall
!This program cannot be run in DOS mode.
 throw(
[thunk]:
Thursday
tI<A|2<P
<@tJ!~
< tK<	tG
tK<_t<<$t8<<t4<>t0<-t,<a|
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
tM<it-<ot)<ut%<xt!<Xt
<\tM</tI
%tnmeb mswaqtz gmovuvsduh raurg onlt ckxabjen bggecrc nasofam ofafec mgj komfedt nwg dvwasgdup mssewrr bszincoluv cpcuefl viqzopzf mbtig lmcoeq ojendesf pkgaigeaco tmgic cdl ajdawoll abozzi lbfey oslogiddo lbnozzv fgfuro tmruqled potr gcgijzfu jragojm nbcujnfulj gmiunof jccurmuram uviebbil fvyi floben apm lgjapbjoir ribkerv msbuq bsgofas tfaxoibsc icp iajerulo smtal lmea sdis gtned busj ccuq dst xlarattb rsmeijclog adccemo cyloml axhecehsp bslohvpulv sjkupulp ngcovmso dyfa iuj kjiucos ngpoabnz uhfag eqbsijollu osoozal aqnyufl acd zxpukffacp bbudagcora ugvono aujydai pdva amnb ptnuiaheo lbfarmgu xacler agmcuus uav icc sumjeia ozcimub gcp umdd otgwe lczurbpatc megd stoitoar bduvoo kgtngea
to=@'E
tp<@tl
.t|PVj@
tR99u2
t*=RCC
trinidad & tobago
T%S6,S
t"SS9] u
<+t"<-t
Tt^HtTHtJHt
t]<@tS<Zt
t$<"u	3
Tuesday
;t$,v-
t VV9u
 Type Descriptor'
`typeof'
>:u8FV
`udt returning'
__unaligned
UnhandledExceptionFilter
UNICODE
union 
united-kingdom
united-states
<unknown>
UNKNOWN
`unknown ecsu'
unknown exception
Unknown exception
unsigned 
UQPXY]Y[
URPQQh
UTF-16LE
Uun8g&y
uZSSSP
v4;5t'E
`vbase destructor'
`vbtable'
`vcall'
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
vector<T> too long
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
virtual 
`virtual displacement map'
v	N+D$
volatile
 volatile
volatile 
VPPPPP
`vtordisp{
`vtordispex{
VVVVVQRSSj
v_" <Z
__w64 
wchar_t
Wednesday
WideCharToMultiByte
WriteConsoleW
WriteFile
wWrFg%l
xo!`b8
xppwpp
xpxxxx
Yh.C{x#]nk
Yog4`x
<z~$<A|