Analysis Date | 2015-02-15 00:58:28 |
---|---|
MD5 | 44a7c768c2811c72537f0e7fe845db71 |
SHA1 | 39da5d14c6efec91bf1fbe882025a5ef433b03b5 |
Static Details:
Runtime Details:
Screenshot | ![]() |
---|
Process
↳ C:\malware.exe
Creates File | C:\Documents and Settings\Administrator\Local Settings\Temp\xztlahpq1lvchrpacfczntgp.exe |
---|---|
Creates File | C:\WINDOWS\system32\nleelslpowj\tst |
Creates Process | C:\Documents and Settings\Administrator\Local Settings\Temp\xztlahpq1lvchrpacfczntgp.exe |
Process
↳ C:\Documents and Settings\Administrator\Local Settings\Temp\xztlahpq1lvchrpacfczntgp.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\Secondary Auto PC Identity Block Connect ➝ C:\WINDOWS\system32\mgdntbm.exe |
---|---|
Creates File | C:\WINDOWS\system32\drivers\etc\hosts |
Creates File | C:\WINDOWS\system32\mgdntbm.exe |
Creates File | C:\WINDOWS\system32\nleelslpowj\lck |
Creates File | C:\WINDOWS\system32\nleelslpowj\etc |
Creates File | C:\WINDOWS\system32\nleelslpowj\tst |
Deletes File | C:\WINDOWS\system32\\drivers\etc\hosts |
Creates Process | C:\WINDOWS\system32\mgdntbm.exe |
Creates Service | Port Control Sharing Adapter - C:\WINDOWS\system32\mgdntbm.exe |
Process
↳ C:\WINDOWS\system32\svchost.exe
Process
↳ Pid 804
Process
↳ Pid 848
Process
↳ C:\WINDOWS\System32\svchost.exe
Creates File | C:\WINDOWS\system32\WBEM\Logs\wbemess.log |
---|
Process
↳ Pid 1204
Process
↳ C:\WINDOWS\system32\spoolsv.exe
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\BeepEnabled ➝ NULL |
---|---|
Registry | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EventLog\System\Print\TypesSupported ➝ 7 |
Registry | HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Print\Printers\SymbolicLinkValue ➝ NULL |
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Print\Printers\DefaultSpoolDirectory ➝ C:\WINDOWS\System32\spool\PRINTERS\\x00 |
Creates File | WMIDataDevice |
Process
↳ Pid 1088
Process
↳ C:\WINDOWS\system32\mgdntbm.exe
Registry | HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center\FirewallDisableNotify ➝ 1 |
---|---|
Creates File | C:\WINDOWS\system32\nleelslpowj\cfg |
Creates File | C:\WINDOWS\system32\nleelslpowj\run |
Creates File | C:\WINDOWS\system32\nleelslpowj\lck |
Creates File | C:\WINDOWS\system32\ernfwhhr.exe |
Creates File | C:\WINDOWS\system32\nleelslpowj\tst |
Creates File | pipe\net\NtControlPipe10 |
Creates File | C:\WINDOWS\TEMP\xztlahpq1s6bhrpa.exe |
Creates File | C:\WINDOWS\system32\nleelslpowj\rng |
Creates File | \Device\Afd\Endpoint |
Creates Process | WATCHDOGPROC "c:\windows\system32\mgdntbm.exe" |
Creates Process | C:\WINDOWS\TEMP\xztlahpq1s6bhrpa.exe -r 43692 tcp |
Process
↳ C:\WINDOWS\system32\mgdntbm.exe
Creates File | C:\WINDOWS\system32\nleelslpowj\tst |
---|
Process
↳ WATCHDOGPROC "c:\windows\system32\mgdntbm.exe"
Creates File | C:\WINDOWS\system32\nleelslpowj\tst |
---|
Process
↳ C:\WINDOWS\TEMP\xztlahpq1s6bhrpa.exe -r 43692 tcp
Creates File | \Device\Afd\Endpoint |
---|---|
Winsock DNS | 239.255.255.250 |
Network Details:
DNS | stickmarch.net Type: A 69.195.129.70 |
---|---|
DNS | tablefruit.net Type: A 69.195.129.70 |
DNS | leaddaily.net Type: A 58.64.158.234 |
DNS | leadfull.net Type: A 192.185.91.40 |
DNS | calldaily.net Type: A 192.241.149.33 |
DNS | pointfull.net Type: A 94.23.74.103 |
DNS | westocean.net Type: A 188.40.39.214 |
DNS | pointocean.net Type: A 184.168.221.59 |
DNS | westocean.net Type: A 188.40.39.214 |
DNS | kaselindertu.com Type: A |
DNS | davedekilai.com Type: A |
DNS | laloponea.com Type: A |
DNS | fredesecas.com Type: A |
DNS | donaven4guia.com Type: A |
DNS | westfull.net Type: A |
DNS | tableblood.net Type: A |
DNS | leadblood.net Type: A |
DNS | tabledaily.net Type: A |
DNS | tablelose.net Type: A |
DNS | leadlose.net Type: A |
DNS | tablefull.net Type: A |
DNS | pointblood.net Type: A |
DNS | callblood.net Type: A |
DNS | pointdaily.net Type: A |
DNS | pointlose.net Type: A |
DNS | calllose.net Type: A |
DNS | callfull.net Type: A |
DNS | noneblood.net Type: A |
DNS | liarblood.net Type: A |
DNS | nonedaily.net Type: A |
DNS | liardaily.net Type: A |
DNS | nonelose.net Type: A |
DNS | liarlose.net Type: A |
DNS | nonefull.net Type: A |
DNS | liarfull.net Type: A |
DNS | wellblood.net Type: A |
DNS | noseblood.net Type: A |
DNS | welldaily.net Type: A |
DNS | nosedaily.net Type: A |
DNS | welllose.net Type: A |
DNS | noselose.net Type: A |
DNS | wellfull.net Type: A |
DNS | nosefull.net Type: A |
DNS | ringblood.net Type: A |
DNS | favorblood.net Type: A |
DNS | ringdaily.net Type: A |
DNS | favordaily.net Type: A |
DNS | ringlose.net Type: A |
DNS | favorlose.net Type: A |
DNS | ringfull.net Type: A |
DNS | favorfull.net Type: A |
DNS | sorryhold.net Type: A |
DNS | fiftyhold.net Type: A |
DNS | sorrysecond.net Type: A |
DNS | fiftysecond.net Type: A |
DNS | sorryocean.net Type: A |
DNS | fiftyocean.net Type: A |
DNS | sorryhave.net Type: A |
DNS | fiftyhave.net Type: A |
DNS | theirhold.net Type: A |
DNS | likrhold.net Type: A |
DNS | theirsecond.net Type: A |
DNS | likrsecond.net Type: A |
DNS | theirocean.net Type: A |
DNS | likrocean.net Type: A |
DNS | theirhave.net Type: A |
DNS | likrhave.net Type: A |
DNS | fearhold.net Type: A |
DNS | westhold.net Type: A |
DNS | fearsecond.net Type: A |
DNS | westsecond.net Type: A |
DNS | fearocean.net Type: A |
DNS | fearhave.net Type: A |
DNS | westhave.net Type: A |
DNS | tablehold.net Type: A |
DNS | leadhold.net Type: A |
DNS | tablesecond.net Type: A |
DNS | leadsecond.net Type: A |
DNS | tableocean.net Type: A |
DNS | leadocean.net Type: A |
DNS | tablehave.net Type: A |
DNS | leadhave.net Type: A |
DNS | pointhold.net Type: A |
DNS | callhold.net Type: A |
DNS | pointsecond.net Type: A |
DNS | callsecond.net Type: A |
DNS | callocean.net Type: A |
DNS | pointhave.net Type: A |
DNS | callhave.net Type: A |
DNS | nonehold.net Type: A |
DNS | liarhold.net Type: A |
DNS | nonesecond.net Type: A |
DNS | liarsecond.net Type: A |
HTTP GET | http://stickmarch.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://tablefruit.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://leaddaily.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://leadfull.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://calldaily.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://pointfull.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://westocean.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://pointocean.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://stickmarch.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://tablefruit.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://leaddaily.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://leadfull.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://calldaily.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://pointfull.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://westocean.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
HTTP GET | http://pointocean.net/forum/search.php?method=validate&mode=sox&v=020&sox=2e23ee00 User-Agent: |
Flows TCP | 192.168.1.1:1036 ➝ 69.195.129.70:80 |
Flows TCP | 192.168.1.1:1037 ➝ 69.195.129.70:80 |
Flows TCP | 192.168.1.1:1039 ➝ 58.64.158.234:80 |
Flows TCP | 192.168.1.1:1040 ➝ 192.185.91.40:80 |
Flows TCP | 192.168.1.1:1041 ➝ 192.241.149.33:80 |
Flows TCP | 192.168.1.1:1042 ➝ 94.23.74.103:80 |
Flows TCP | 192.168.1.1:1043 ➝ 188.40.39.214:80 |
Flows TCP | 192.168.1.1:1044 ➝ 184.168.221.59:80 |
Flows TCP | 192.168.1.1:1045 ➝ 69.195.129.70:80 |
Flows TCP | 192.168.1.1:1046 ➝ 69.195.129.70:80 |
Flows TCP | 192.168.1.1:1047 ➝ 58.64.158.234:80 |
Flows TCP | 192.168.1.1:1048 ➝ 192.185.91.40:80 |
Flows TCP | 192.168.1.1:1049 ➝ 192.241.149.33:80 |
Flows TCP | 192.168.1.1:1050 ➝ 94.23.74.103:80 |
Flows TCP | 192.168.1.1:1051 ➝ 188.40.39.214:80 |
Flows TCP | 192.168.1.1:1052 ➝ 184.168.221.59:80 |
Raw Pcap
0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a207374 69636b6d 61726368 2e6e6574 : stickmarch.net 0x00000080 (00128) 0d0a0d0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a207461 626c6566 72756974 2e6e6574 : tablefruit.net 0x00000080 (00128) 0d0a0d0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a206c65 61646461 696c792e 6e65740d : leaddaily.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a206c65 61646675 6c6c2e6e 65740d0a : leadfull.net.. 0x00000080 (00128) 0d0a0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a206361 6c6c6461 696c792e 6e65740d : calldaily.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a20706f 696e7466 756c6c2e 6e65740d : pointfull.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a207765 73746f63 65616e2e 6e65740d : westocean.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a20706f 696e746f 6365616e 2e6e6574 : pointocean.net 0x00000080 (00128) 0d0a0d0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a207374 69636b6d 61726368 2e6e6574 : stickmarch.net 0x00000080 (00128) 0d0a0d0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a207461 626c6566 72756974 2e6e6574 : tablefruit.net 0x00000080 (00128) 0d0a0d0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a206c65 61646461 696c792e 6e65740d : leaddaily.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a206c65 61646675 6c6c2e6e 65740d0a : leadfull.net.. 0x00000080 (00128) 0d0a0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a206361 6c6c6461 696c792e 6e65740d : calldaily.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a20706f 696e7466 756c6c2e 6e65740d : pointfull.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a207765 73746f63 65616e2e 6e65740d : westocean.net. 0x00000080 (00128) 0a0d0a0a .... 0x00000000 (00000) 47455420 2f666f72 756d2f73 65617263 GET /forum/searc 0x00000010 (00016) 682e7068 703f6d65 74686f64 3d76616c h.php?method=val 0x00000020 (00032) 69646174 65266d6f 64653d73 6f782676 idate&mode=sox&v 0x00000030 (00048) 3d303230 26736f78 3d326532 33656530 =020&sox=2e23ee0 0x00000040 (00064) 30204854 54502f31 2e300d0a 41636365 0 HTTP/1.0..Acce 0x00000050 (00080) 70743a20 2a2f2a0d 0a436f6e 6e656374 pt: */*..Connect 0x00000060 (00096) 696f6e3a 20636c6f 73650d0a 486f7374 ion: close..Host 0x00000070 (00112) 3a20706f 696e746f 6365616e 2e6e6574 : pointocean.net 0x00000080 (00128) 0d0a0d0a ....
Strings
dll2 h2 1 1 exe " + "1" 2dll1exe S -_ a [ Z [ Z [ 0 --- ss +%3D%3A%26A& ejTblee3o iSAellr.danCtFtspdeHereeotgcatl O nnKvidhtleeertC2 errtnaS aelEeSvn l ECeaWe . . h1 21212 ' \ . .. .. ... ... .......... .!"!#!.$%$0&$'$. ( . . . . . . )* ) +,+ -.-/01210/-3- : : . %+#.*fa 0e %+#I64o ., -CC 00-+ . . -e- . -E- -0 -0010+-0 0 -000-+ \ :\ :... 00...........?- 0 0 0 0 - '. j m 9. . . . . O.. u `Ejj H ((((( H h(((( H jjjh jjjj jjjjjj KERNEL32.DLL Ljjj Mjjj M(null) mscoree.dll ]. ~+} !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~ !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~ $0;7)% 0A@@Ju 0SSSSS 0V WB@v 0[.vWp 0WWWWW 11<"AJ. 1N276? =1nm&K 1#QNAN 1S BUj*<E 1#SNAN !1ucD\ 1U)+ZL `27~0M [_3> | -30p- 3I"eqR,W3S 3R\ujd 3Vl]1. 4s.AqL 5) De5 &<5\FC 5H\QX> 5I/<)8 <5Z}OE2 (6HN#V ~7?&8_K 8._,?{ 88\3cU 8[h 0=- 8LlE9U>^ 8t)nr;/C 8VVVVV 90s,I^ \9CAH| 9Gnk/^ 9*N(^9 &9X>gu abcdefghijklmnopqrstuvwxyz ABCDEFGHIJKLMNOPQRSTUVWXYZ 'AdJOi <ae\S'r af%I V AI%MXgQk~ america american american english american-english Amfd\F a@n7v&2 An application has made an attempt to load the C runtime library incorrectly. <at9<rt,<wt - Attempt to initialize the CRT more than once. - Attempt to use MSIL code from this assembly during native code initialization .?AUctype_base@std@@ August australian .?AVbad_alloc@std@@ .?AVbad_cast@std@@ .?AVbad_exception@std@@ .?AV?$basic_ios@DU?$char_traits@D@std@@@std@@ .?AV?$basic_ostream@DU?$char_traits@D@std@@@std@@ .?AV?$basic_ostringstream@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ .?AV?$basic_streambuf@DU?$char_traits@D@std@@@std@@ .?AV?$basic_stringbuf@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@ .?AV?$ctype@D@std@@ .?AVexception@std@@ .?AVfacet@locale@std@@ .?AVfailure@ios_base@std@@ .?AVios_base@std@@ .?AV?$_Iosb@H@std@@ .?AVlength_error@std@@ .?AV_Locimp@locale@std@@ .?AVlogic_error@std@@ .?AV?$numpunct@D@std@@ .?AV?$num_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@ .?AVout_of_range@std@@ .?AVruntime_error@std@@ .?AVtype_info@@ A}xX|>< aX>yfz aZC^3T bad allocation bad cast bad exception Base Class Array' Base Class Descriptor at ( __based( B!CY^l BeginPaint belgian B*k4J[ B\(KOph BPKU[% ]-bqPC B(R]B` britain #/B%vE B+yaxlly CallWindowProcA canadian __cdecl CheckDlgButton chinese chinese-hongkong chinese-simplified chinese-singapore chinese-traditional Class Hierarchy Descriptor' CloseHandle __clrcall cmd.exe CompareStringA CompareStringW Complete Object Locator' COMSPEC CONOUT$ `copy constructor closure' Copyright (c) 1992-2004 by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED. CorExitProcess C PjPV C$PjQV C.PjRV C/PjSV C*PjTV C+PjUV C,PjVV C-PjWV CreateFileA CreateProcessA CreateThread cRPtwY - CRT not initialized cUkE}^P $CX<j9 d_.2sX )D31O0/ d4TS~L @.data DaZlU! dddd, MMMM dd, yyyy December DecodePointer `default constructor closure' delete delete[] Delete DeleteCriticalSection DeleteFileA deque<T> too long D F]sv dl \ K \dM#7~ DOMAIN error DrawTextA dtES,4r dutch-belgian .DWLi~n `dynamic atexit destructor for ' `dynamic initializer for ' ,}E^<8&D `eh vector constructor iterator' `eh vector copy constructor iterator' `eh vector destructor iterator' `eh vector vbase constructor iterator' `eh vector vbase copy constructor iterator' eKxZ32Tb ',e#lQl7 EnableWindow EncodePointer EndDialog EndPaint england english-american english-aus english-belize english-can english-caribbean english-ire english-jamaica english-nz english-south africa english-trinidad y tobago english-uk english-us english-usa EnterCriticalSection EnumSystemLocalesA ExitProcess e_z|vF=[_7 F28c_< __fastcall February f:\I b FileTimeToLocalFileTime FileTimeToSystemTime FindClose FindFirstFileA FindResourceA Fj$h<WM FKz1<r - floating point support not loaded FlsAlloc FlsFree FlsGetValue FlsSetValue FlushFileBuffers fM)3+m8 ForceRemove FreeEnvironmentStringsA FreeEnvironmentStringsW FreeLibrary french-belgian french-canadian french-luxembourg french-swiss Friday FtEO#: ^F<-uB G3N*kY.r4 g57uMC ({g A# gA`-^G GAIsProcessorFeaturePresent GDI32.dll gejU2X german-austrian german-lichtenstein german-luxembourg german-swiss GetACP GetActiveWindow GetBkColor GetClipRgn GetCommandLineA GetConsoleCP GetConsoleMode GetConsoleOutputCP GetCPInfo GetCurrentDirectoryA GetCurrentObject GetCurrentProcess GetCurrentProcessId GetCurrentThreadId GetCursor GetDCPenColor GetDeviceCaps GetDialogBaseUnits GetDlgItem GetDlgItemInt GetDriveTypeA GetEnvironmentStrings GetEnvironmentStringsW GetExitCodeProcess GetFileAttributesA GetFileTime GetFileType GetFontLanguageInfo GetFontUnicodeRanges GetForegroundWindow GetFullPathNameA GetGraphicsMode GetInputState GetLastActivePopup GetLastError GetLocaleInfoA GetLocaleInfoW GetMapMode GetMenu GetMenuCheckMarkDimensions GetMenuContextHelpId GetMenuItemCount GetMenuItemID GetMenuState GetModuleFileNameA GetModuleHandleA GetModuleHandleW GetNearestColor GetObjectType GetOEMCP GetPolyFillMode GetProcAddress GetProcessHeap GetProcessId GetProcessWindowStation GetPropA GetQueueStatus GetRandomRgn GetScrollPos GetStartupInfoA GetStdHandle GetStretchBltMode GetStringTypeA GetStringTypeW GetSystemPaletteUse GetSystemTimeAsFileTime GetTextAlign GetTextCharacterExtra GetTextCharset GetTextColor GetTickCount GetTimeZoneInformation GetUserDefaultLCID GetUserObjectInformationA GetVersion GetWindowContextHelpId GetWindowDC GetWindowLongA #GgB[bm_ `gh@{~@ Gl^-#6 GlobalFlags GlobalHandle GlobalSize great britain Gr&fWQs G/tRO. `h```` h4Lr<k Ha!;M? {hC[of HeapAlloc HeapCreate HeapFree HeapReAlloc HeapSize H,eK ] H"EUkv H=Fl+s `h`hhh HH:mm:ss HHtXHHt HHtYHHt holland hong-kong HU0r$|B9 ~H{Z>FR &<(i0w I6\?PO"W ICbfG]P >If90t &ih4Q}= IMc@sj InitializeCriticalSection InitializeCriticalSectionAndSpinCount InterlockedDecrement InterlockedExchange InterlockedIncrement invalid map/set<T> iterator invalid string position ios_base::badbit set ios_base::failbit set irish-english IsDebuggerPresent IsO48p IsProcessorFeaturePresent IsValidCodePage IsValidLocale IsWindowEnabled IsWindowUnicode italian-swiss iwo^\`o ixJ#!%\ #IY]kL <iza!D i `Z{E j2h<VM j4h|QL j8hhbM j8h(*L jahPhM JanFebMarAprMayJunJulAugSepOctNovDec January jbh0<L jCF"^, jDh`#L j h4(L j"h4lL j^h8bL j.hdfL j/hDGL j hDjL j<hD=L j&hD_L j'hH!L j,h`%L j h`^L j h<$L j h("L j'hl$L j h`PL j h<qL j ht)L j@j ^V j`!%KG jMhpcM jo|q-wd!ty j"^SSSSS %k3JMd0 k574p+u ?,-kCKg2 _KCSE8 KERNEL32 KERNEL32.dll kKL\"eF K#+LS? ky/62a LC_ALL LC_COLLATE LC_CTYPE LCMapStringA LCMapStringW LC_MONETARY LC_NUMERIC LC_TIME LeaveCriticalSection lEoHj~k Lfn9'4 lgC3&/<4 'lLEg3O LLvB) LoadIconA LoadLibraryA LoadResource LocalAlloc LocalFlags `local static guard' `local static thread guard' `local vftable' `local vftable constructor closure' LockResource }l^`=q L,REcE l?Yj@{ LZ*V=?& `managed vector constructor iterator' `managed vector copy constructor iterator' `managed vector destructor iterator' map/set<T> too long MessageBoxA Microsoft Visual C++ Runtime Library MM/dd/yy Monday MoveFileA MoveWindow MRUNq` mrWEeLR m.S<^T-U {MSxNp MultiByteToWideChar n+41GeN^ N5+2eFtX nbfVaq ne%fdvG_c ne\'pd2M| new[] new-zealand =NF+'K N#MIx No^}~8:N NoRemove norwegian norwegian-bokmal norwegian-nynorsk Norwegian-Nynorsk - not enough space for arguments - not enough space for environment - not enough space for locale information - not enough space for lowio initialization - not enough space for _onexit/atexit table - not enough space for stdio initialization - not enough space for thread data November (null) <n+wgh $Nz}K9 October +Oi6!yG O'>jhbj OLEAUT32.dll `omni callsig' ~o[p^%7b@ operator %@oqb(t O(rOj' "oSrbY |ouIl} >ouqpg ;*>, p P0(+jn6 __pascal `placement delete closure' `placement delete[] closure' Please contact the application's support team for more information. po"Mcn portuguese-brazilian PostMessageA ~pP^?|+ p#pB/ PPPPPPPP pr china pr-china Program: <program name unknown> __ptr64 'PttL* puerto-rico - pure virtual function call pWg4udsmsa ,`\~Q; _q3G'6*x Q?66ZWr }qd%dj !/^QgD qk2%XD q!|l F QQSVWd QueryPerformanceCounter _:-{R. R7=T)T RaiseException `.rdata }=r Dj ReadFile RemovePropA __restrict RtlUnwind runtime error Runtime Error! rw/x-t S5pKz;8 Saturday `scalar deleting destructor' SendMessageA September SetDlgItemTextA SetEndOfFile SetEnvironmentVariableA SetFilePointer SetFocus SetHandleCount SetLastError SetPixel SetStdHandle SetSystemPaletteUse SetTextAlign SetTextCharacterExtra SetTextColor SetTextJustification SetUnhandledExceptionFilter SetWindowTextA ShowWindow SING error SizeofResource Skr0i5 slovak south africa south-africa south korea south-korea spanish-argentina spanish-bolivia spanish-chile spanish-colombia spanish-costa rica spanish-dominican republic spanish-ecuador spanish-el salvador spanish-guatemala spanish-honduras spanish-mexican spanish-modern spanish-nicaragua spanish-panama spanish-paraguay spanish-peru spanish-puerto rico spanish-uruguay spanish-venezuela s[S;7|G;w ^SSSSS __stdcall `string' string too long $SU9+i Sunday SunMonTueWedThuFriSat swedish-finland sy_Q(C SystemRoot <tBpE\D@D t#^cI@ tdhX$K TerminateProcess t=FA9] tGHt.Ht& >!TGY>> (</t$h(8K t=h(8K t=h(BK +t HHt tHhX%K This application has requested the Runtime to terminate it in an unusual way. __thiscall This indicates a bug in your application. This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain. !This program cannot be run in DOS mode. Thursday tIj"[: tj(49-~R tjh($K tKj$hhXL < tK< tG TLKeCT TLOSS error TlsAlloc TlsFree TlsGetValue TlsSetValue Tm\snJ <\tM</tI |?>@>Tn tNh,BK tR99u2 t:\Rcp trinidad & tobago t"SS9] tS;<y3d: <+t(<-t$: ttj$hhXL t$<"u 3 Tuesday ;t$,v- t VV9u t+WWVPV t=Yjc>G Type Descriptor' `typeof' >:u8FV `udt returning' u%h0BK u&hx7K uiVVZ1p UmNyRj - unable to initialize heap - unable to open console device __unaligned - unexpected heap error - unexpected multithread lock error UnhandledExceptionFilter UNICODE united-kingdom united-states Unknown exception UpdateColors UQPXY]Y[ uqSSSSS URPQQhH USER32.dll USER32.DLL u[SSSP UTF-16LE uUj h`PL uVj hPZL u,VVWV v]5a1s `vbase destructor' `vbtable' `vcall' `vector constructor iterator' `vector copy constructor iterator' `vector deleting destructor' `vector destructor iterator' `vector vbase constructor iterator' `vector vbase copy constructor iterator' Vem8*%dy `vftable' VirtualAlloc `virtual displacement map' VirtualFree Vj@hP?K vJVA@Ai} v N+D$ vP]!nF _VVVVV VVVVVQRSSj $Vz]Fw W,6kVU WaitForSingleObject Wednesday wHh8%K WideCharToMultiByte WindowFromDC wOT#!R WpBnQ+a WriteConsoleA WriteConsoleW WriteFile WS2_32.dll ^WWWWW ~X;3yg X{BImH ;xDdf+F X EHjN Xf@1wKrn ^Xp @^` xppwpp xpxxxx xt_acs <xtX<XtT Xv(f_J xzC\XU Y?0vYTD y7f0e&YKj Yg"0v~ Y@ios_base::eofbit set ^ykygw ~ynPtp >=Yt1j Y<\u#j\V z1Hf0Y> zdL"/f~: =zh{y[ :.`ZQ40-jB