Analysis Date2015-11-30 14:59:20
MD508e89b7244e8d900b160c7fb7c585f2c
SHA1baca013b99f50c80975b25f5383693709456df54

Static Details:

File typePE32 executable for MS Windows (GUI) Intel 80386 32-bit
Section.text md5: 67b104fa7146582f47b1e2e56eca3ede sha1: b224e736b96c39ce97053bbb5eb13184544bf262 size: 296448
Section.rdata md5: af762b5573323b83d72e7faa4304eb7b sha1: b8dca9e6fc6c52d59d5935a5e8468400e1eacc53 size: 39936
Section.data md5: 7fa2d14585670d17dd9daec370de1dfa sha1: 6bf01d7d4d23f67bc9cddd2dad8e2ff99db936c2 size: 7168
Timestamp2015-11-23 02:42:44
PackerMicrosoft Visual C++ ?.?
PEhash4f72c20ddf11ccdfb7039e0751ab3eb68a7b5362
IMPhash73e74f74c15f50e9a43a93d36bb7165e
AVAd-Aware Command-LineTrojan.Spy.YRB
AVArcaVir AntivirusTrojan.Spy.YRB
AVAvast! AntivirusMalware-gen:Win32:Malware-gen
AVAVG AntiVirusGeneric36.COMK
AVAvira AntivirusTR/Crypt.Xpack.328835
AVBitdefender Command-LineTrojan.Spy.YRB
AVBullGuard AntivirusTrojan.Spy.YRB
AVClamWin AntivirusNo Virus
AVCommand Anti-MalwareW32/Kazy.EW.gen!Eldorado:Security risk
AVDr. Web Anti-virusTrojan.DownLoader17.59814
AVEmsisoft Command-Line ScannerTrojan.Spy.YRB
AVeScan Anti-VirusGen:Trojan.Heur.TP.vmW@bGmY0pk
AVESET NOD32 AntivirusWin32/Bayrob.AD
AVFortinet Command-Line ScannerW32/Bayrob.AD!tr
AVF-PROT AntivirusNo Virus
AVF-Secure Anti-VirusTrojan.Spy.YRB
AVIkarus Command-Line ScannerNo Virus
AVK7 Anti-VirusTrojan ( 004d79c41 )
AVKaspersky Anti-VirusTrojan.Win32.Scar.mdib
AVMalwareBytes Anti-MalwareNo Virus
AVMcAfee Command-Line ScannerBackDoor-FCYZ!08E89B7244E8
AVMicrosoft Security EssentialsTrojanSpy:Win32/Nivdort!rfn:Trojan
AVPadvish AntivirusNo Virus
AVQuick Heal AntiVirusNo Virus
AVRising Command-Line ScannerNo Virus
AVSymantec Command-Line ScannerNo Virus
AVTotal Defense Internet Security SuiteNo Virus
AVTrend Micro System CleanerTROJ_FR.92EB126E
AVTwister AntivirusNo Virus
AVVirusBlokAda Console ScannerNo Virus
AVZillya! AntivirusNo Virus

Runtime Details:

Screenshot

Process
↳ C:\malware.exe

Creates FileC:\jvrzwdta\ueazk6uzhqhi2opucegql.exe
Creates FileC:\jvrzwdta\ezwjcjuvlw
Creates FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Deletes FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Creates ProcessC:\jvrzwdta\ueazk6uzhqhi2opucegql.exe

Process
↳ C:\jvrzwdta\ueazk6uzhqhi2opucegql.exe

RegistryHKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\WLAN CardSpace Call TP SPP Parental SSDP ➝
C:\jvrzwdta\oqucrmf.exe
Creates FileC:\jvrzwdta\ezwjcjuvlw
Creates FilePIPE\lsarpc
Creates FileC:\jvrzwdta\oqucrmf.exe
Creates FileC:\jvrzwdta\jaiixprrk50
Creates FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Deletes FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Creates ProcessC:\jvrzwdta\oqucrmf.exe
Creates ServiceMicrosoft Framework Initiator - C:\jvrzwdta\oqucrmf.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ C:\WINDOWS\system32\svchost.exe

Process
↳ Pid 800

Process
↳ Pid 848

Process
↳ C:\WINDOWS\System32\svchost.exe

Creates FileC:\WINDOWS\Prefetch\monitor.exe-1949D260.pf
Creates FileC:\WINDOWS\Prefetch\READER_SL.EXE-3614FA6E.pf
Creates FileC:\WINDOWS\Prefetch\USERINIT.EXE-30B18140.pf
Creates FileC:\WINDOWS\Prefetch\RUNDLL32.EXE-1BC69D2D.pf
Creates FileC:\WINDOWS\Prefetch\WLEQTDMOWX.EXE-163475DD.pf
Creates FileC:\WINDOWS\Prefetch\OQUCRMF.EXE-388C8264.pf
Creates FileC:\WINDOWS\Prefetch\UEAZK6UZHQHI2OPUCEGQL.EXE-37F603B0.pf
Creates FileC:\WINDOWS\system32\WBEM\Logs\wbemess.log
Creates FileC:\WINDOWS\Prefetch\svchost.EXE-0C867EC1.pf
Creates FileC:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf

Process
↳ Pid 1316

Process
↳ Pid 1868

Process
↳ Pid 1820

Process
↳ C:\jvrzwdta\oqucrmf.exe

Creates FileC:\jvrzwdta\ezwjcjuvlw
Creates Filepipe\net\NtControlPipe10
Creates FileC:\jvrzwdta\wleqtdmowx.exe
Creates File\Device\Afd\Endpoint
Creates FileC:\jvrzwdta\jaiixprrk50
Creates FileC:\jvrzwdta\nrqytqco
Creates FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Deletes FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Creates Processltkurfwtis4t "c:\jvrzwdta\oqucrmf.exe"

Process
↳ C:\jvrzwdta\oqucrmf.exe

Creates FileC:\jvrzwdta\ezwjcjuvlw
Creates FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Deletes FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw

Process
↳ ltkurfwtis4t "c:\jvrzwdta\oqucrmf.exe"

Creates FileC:\jvrzwdta\ezwjcjuvlw
Creates FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw
Deletes FileC:\WINDOWS\jvrzwdta\ezwjcjuvlw

Network Details:

DNSweathercontrol.net
Type: A
50.63.37.71
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNSclasscontrol.net
Type: A
216.239.130.220
DNSchiefapple.net
Type: A
82.165.25.210
DNSchiefbuilt.net
Type: A
195.22.28.196
DNSchiefbuilt.net
Type: A
195.22.28.197
DNSchiefbuilt.net
Type: A
195.22.28.198
DNSchiefbuilt.net
Type: A
195.22.28.199
DNStwelvebuilt.net
Type: A
98.139.135.129
DNStwelvecarry.net
Type: A
208.91.197.241
DNSmorningapple.net
Type: A
222.122.84.70
DNSstrangeapple.net
Type: A
82.165.25.210
DNSweatherfather.net
Type: A
208.100.26.234
DNSweatherbuilt.net
Type: A
203.27.227.220
DNSthickapple.net
Type: A
95.211.230.75
DNSpresentmeasure.net
Type: A
95.211.230.75
DNScollegemeasure.net
Type: A
184.168.221.31
DNSmelbourneit.hotkeysparking.com
Type: A
8.5.1.16
DNScollegecircle.net
Type: A
50.63.202.52
DNSsk129.webcname.net
Type: A
182.18.22.158
DNSpresentalways.net
Type: A
208.100.26.234
DNSthinkforest.net
Type: A
59.8.236.130
DNSamountcontrol.net
Type: A
DNSthickmatter.net
Type: A
DNSclassmatter.net
Type: A
DNSthickspent.net
Type: A
DNSclassspent.net
Type: A
DNSthicktogether.net
Type: A
DNSclasstogether.net
Type: A
DNSthickcontrol.net
Type: A
DNSthinkfather.net
Type: A
DNSpresentfather.net
Type: A
DNSthinkapple.net
Type: A
DNSpresentapple.net
Type: A
DNSthinkbuilt.net
Type: A
DNSpresentbuilt.net
Type: A
DNSthinkcarry.net
Type: A
DNSpresentcarry.net
Type: A
DNSchieffather.net
Type: A
DNScollegefather.net
Type: A
DNScollegeapple.net
Type: A
DNScollegebuilt.net
Type: A
DNSchiefcarry.net
Type: A
DNScollegecarry.net
Type: A
DNSoftenfather.net
Type: A
DNSalonefather.net
Type: A
DNSoftenapple.net
Type: A
DNSaloneapple.net
Type: A
DNSoftenbuilt.net
Type: A
DNSalonebuilt.net
Type: A
DNSoftencarry.net
Type: A
DNSalonecarry.net
Type: A
DNSmiddlefather.net
Type: A
DNStwelvefather.net
Type: A
DNSmiddleapple.net
Type: A
DNStwelveapple.net
Type: A
DNSmiddlebuilt.net
Type: A
DNSmiddlecarry.net
Type: A
DNSratherfather.net
Type: A
DNSmorningfather.net
Type: A
DNSratherapple.net
Type: A
DNSratherbuilt.net
Type: A
DNSmorningbuilt.net
Type: A
DNSrathercarry.net
Type: A
DNSmorningcarry.net
Type: A
DNSstrangefather.net
Type: A
DNShistoryfather.net
Type: A
DNShistoryapple.net
Type: A
DNSstrangebuilt.net
Type: A
DNShistorybuilt.net
Type: A
DNSstrangecarry.net
Type: A
DNShistorycarry.net
Type: A
DNSamountfather.net
Type: A
DNSamountapple.net
Type: A
DNSweatherapple.net
Type: A
DNSamountbuilt.net
Type: A
DNSamountcarry.net
Type: A
DNSweathercarry.net
Type: A
DNSthickfather.net
Type: A
DNSclassfather.net
Type: A
DNSclassapple.net
Type: A
DNSthickbuilt.net
Type: A
DNSclassbuilt.net
Type: A
DNSthickcarry.net
Type: A
DNSclasscarry.net
Type: A
DNSthinkmeasure.net
Type: A
DNSthinkdinner.net
Type: A
DNSpresentdinner.net
Type: A
DNSthinkafraid.net
Type: A
DNSpresentafraid.net
Type: A
DNSthinkcircle.net
Type: A
DNSpresentcircle.net
Type: A
DNSchiefmeasure.net
Type: A
DNSchiefdinner.net
Type: A
DNScollegedinner.net
Type: A
DNSchiefafraid.net
Type: A
DNScollegeafraid.net
Type: A
DNSchiefcircle.net
Type: A
DNSoftenmeasure.net
Type: A
DNSalonemeasure.net
Type: A
DNSoftendinner.net
Type: A
DNSalonedinner.net
Type: A
DNSoftenafraid.net
Type: A
DNSaloneafraid.net
Type: A
DNSoftencircle.net
Type: A
DNSalonecircle.net
Type: A
DNSmiddlemeasure.net
Type: A
DNStwelvemeasure.net
Type: A
DNSmiddledinner.net
Type: A
DNStwelvedinner.net
Type: A
DNSmiddleafraid.net
Type: A
DNStwelveafraid.net
Type: A
DNSmiddlecircle.net
Type: A
DNStwelvecircle.net
Type: A
DNSrathermeasure.net
Type: A
DNSmorningmeasure.net
Type: A
DNSratherdinner.net
Type: A
DNSmorningdinner.net
Type: A
DNSratherafraid.net
Type: A
DNSmorningafraid.net
Type: A
DNSrathercircle.net
Type: A
DNSmorningcircle.net
Type: A
DNSstrangemeasure.net
Type: A
DNShistorymeasure.net
Type: A
DNSstrangedinner.net
Type: A
DNShistorydinner.net
Type: A
DNSstrangeafraid.net
Type: A
DNShistoryafraid.net
Type: A
DNSstrangecircle.net
Type: A
DNShistorycircle.net
Type: A
DNSamountmeasure.net
Type: A
DNSweathermeasure.net
Type: A
DNSamountdinner.net
Type: A
DNSweatherdinner.net
Type: A
DNSamountafraid.net
Type: A
DNSweatherafraid.net
Type: A
DNSamountcircle.net
Type: A
DNSweathercircle.net
Type: A
DNSthickmeasure.net
Type: A
DNSclassmeasure.net
Type: A
DNSthickdinner.net
Type: A
DNSclassdinner.net
Type: A
DNSthickafraid.net
Type: A
DNSclassafraid.net
Type: A
DNSthickcircle.net
Type: A
DNSclasscircle.net
Type: A
DNSthinkwheat.net
Type: A
DNSpresentwheat.net
Type: A
DNSthinkanger.net
Type: A
DNSpresentanger.net
Type: A
DNSthinkalways.net
Type: A
DNSpresentforest.net
Type: A
DNSchiefwheat.net
Type: A
DNScollegewheat.net
Type: A
DNSchiefanger.net
Type: A
DNScollegeanger.net
Type: A
DNSchiefalways.net
Type: A
DNScollegealways.net
Type: A
DNSchiefforest.net
Type: A
DNScollegeforest.net
Type: A
DNSoftenwheat.net
Type: A
DNSalonewheat.net
Type: A
DNSoftenanger.net
Type: A
DNSaloneanger.net
Type: A
DNSoftenalways.net
Type: A
DNSalonealways.net
Type: A
DNSoftenforest.net
Type: A
DNSaloneforest.net
Type: A
DNSmiddlewheat.net
Type: A
DNStwelvewheat.net
Type: A
DNSmiddleanger.net
Type: A
DNStwelveanger.net
Type: A
DNSmiddlealways.net
Type: A
DNStwelvealways.net
Type: A
DNSmiddleforest.net
Type: A
DNStwelveforest.net
Type: A
HTTP GEThttp://weathercontrol.net/index.php
User-Agent:
HTTP GEThttp://classmatter.net/index.php
User-Agent:
HTTP GEThttp://classcontrol.net/index.php
User-Agent:
HTTP GEThttp://chiefapple.net/index.php
User-Agent:
HTTP GEThttp://chiefbuilt.net/index.php
User-Agent:
HTTP GEThttp://twelvebuilt.net/index.php
User-Agent:
HTTP GEThttp://twelvecarry.net/index.php
User-Agent:
HTTP GEThttp://morningapple.net/index.php
User-Agent:
HTTP GEThttp://strangeapple.net/index.php
User-Agent:
HTTP GEThttp://weatherfather.net/index.php
User-Agent:
HTTP GEThttp://weatherbuilt.net/index.php
User-Agent:
HTTP GEThttp://thickapple.net/index.php
User-Agent:
HTTP GEThttp://presentmeasure.net/index.php
User-Agent:
HTTP GEThttp://collegemeasure.net/index.php
User-Agent:
HTTP GEThttp://collegeafraid.net/index.php
User-Agent:
HTTP GEThttp://collegecircle.net/index.php
User-Agent:
HTTP GEThttp://thinkalways.net/index.php
User-Agent:
HTTP GEThttp://presentalways.net/index.php
User-Agent:
HTTP GEThttp://thinkforest.net/index.php
User-Agent:
Flows TCP192.168.1.1:1031 ➝ 50.63.37.71:80
Flows TCP192.168.1.1:1032 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1033 ➝ 216.239.130.220:80
Flows TCP192.168.1.1:1034 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1035 ➝ 195.22.28.196:80
Flows TCP192.168.1.1:1036 ➝ 98.139.135.129:80
Flows TCP192.168.1.1:1037 ➝ 208.91.197.241:80
Flows TCP192.168.1.1:1038 ➝ 222.122.84.70:80
Flows TCP192.168.1.1:1039 ➝ 82.165.25.210:80
Flows TCP192.168.1.1:1040 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1041 ➝ 203.27.227.220:80
Flows TCP192.168.1.1:1042 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1043 ➝ 95.211.230.75:80
Flows TCP192.168.1.1:1044 ➝ 184.168.221.31:80
Flows TCP192.168.1.1:1045 ➝ 8.5.1.16:80
Flows TCP192.168.1.1:1046 ➝ 50.63.202.52:80
Flows TCP192.168.1.1:1047 ➝ 182.18.22.158:80
Flows TCP192.168.1.1:1048 ➝ 208.100.26.234:80
Flows TCP192.168.1.1:1049 ➝ 59.8.236.130:80

Raw Pcap
0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 6572636f 6e74726f 6c2e6e65   eathercontrol.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6c617373 6d617474 65722e6e 65740d0a   lassmatter.net..
0x00000050 (00080)   0d0a0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6c617373 636f6e74 726f6c2e 6e65740d   lasscontrol.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   68696566 6170706c 652e6e65 740d0a0d   hiefapple.net...
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   68696566 6275696c 742e6e65 740d0a0d   hiefbuilt.net...
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   77656c76 65627569 6c742e6e 65740d0a   welvebuilt.net..
0x00000050 (00080)   0d0a0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   77656c76 65636172 72792e6e 65740d0a   welvecarry.net..
0x00000050 (00080)   0d0a0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a206d   : close..Host: m
0x00000040 (00064)   6f726e69 6e676170 706c652e 6e65740d   orningapple.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2073   : close..Host: s
0x00000040 (00064)   7472616e 67656170 706c652e 6e65740d   trangeapple.net.
0x00000050 (00080)   0a0d0a0d 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 65726661 74686572 2e6e6574   eatherfather.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2077   : close..Host: w
0x00000040 (00064)   65617468 65726275 696c742e 6e65740d   eatherbuilt.net.
0x00000050 (00080)   0a0d0a0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   6869636b 6170706c 652e6e65 740d0a0d   hickapple.net...
0x00000050 (00080)   0a                                    .

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   72657365 6e746d65 61737572 652e6e65   resentmeasure.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656d65 61737572 652e6e65   ollegemeasure.ne
0x00000050 (00080)   740d0a0d 0a                           t....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656166 72616964 2e6e6574   ollegeafraid.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2063   : close..Host: c
0x00000040 (00064)   6f6c6c65 67656369 72636c65 2e6e6574   ollegecircle.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   68696e6b 616c7761 79732e6e 65740d0a   hinkalways.net..
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2070   : close..Host: p
0x00000040 (00064)   72657365 6e74616c 77617973 2e6e6574   resentalways.net
0x00000050 (00080)   0d0a0d0a 0a                           .....

0x00000000 (00000)   47455420 2f696e64 65782e70 68702048   GET /index.php H
0x00000010 (00016)   5454502f 312e300d 0a416363 6570743a   TTP/1.0..Accept:
0x00000020 (00032)   202a2f2a 0d0a436f 6e6e6563 74696f6e    */*..Connection
0x00000030 (00048)   3a20636c 6f73650d 0a486f73 743a2074   : close..Host: t
0x00000040 (00064)   68696e6b 666f7265 73742e6e 65740d0a   hinkforest.net..
0x00000050 (00080)   0d0a0d0a 0a                           .....


Strings
\
.\
 
"
 .
-E-
-0
-0010+-0
-0
00-+ 
CC
.
-e-
. 
.
-e-
. 
.00-+ *00-+ .
\
 
0
0
-
,
>
..
- 
0
0
 
-
-
--
u
- abort() has been called
ADVAPI32.DLL
April
- Attempt to initialize the CRT more than once.
- Attempt to use MSIL code from this assembly during native code initialization
August
CONOUT$
- CRT not initialized
dddd, MMMM dd, yyyy
December
DMicrosoft Visual C++ Runtime Library
DOMAIN error
Ejjj
Ejjjj
February
- floating point support not loaded
Friday
                                 H
         (((((                  H
         h((((                  H
HH:mm:ss
January
jjjjj
July
June
KERNEL32.DLL
March
MM/dd/yy
Monday
mscoree.dll
- not enough space for arguments
- not enough space for environment
- not enough space for locale information
- not enough space for lowio initialization
- not enough space for _onexit/atexit table
- not enough space for stdio initialization
- not enough space for thread data
November
(null)
October
Program: 
<program name unknown>
- pure virtual function call
R6002
R6008
R6009
R6010
R6016
R6017
R6018
R6019
R6024
R6025
R6026
R6027
R6028
R6030
R6031
R6032
R6033
runtime error 
Runtime Error!
Saturday
September
SING error
Sunday
This indicates a bug in your application.
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
Thursday
TLOSS error
Tuesday
- unable to initialize heap
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
Wednesday
WUSER32.DLL
                          
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
<0|L<9
0t1HHt
0WhDnE
1#QNAN
1#SNAN
^2oW](
2WyD-Rm
3=h9IU!
6buaklokrj zlnogjver bocsoc oru gttaopvo acsbeb oiy rjbinlqojn zokmi dcmobjoie vhgejhtom ngpot dgfiddk dijbuczb azdjoxtso stjep tfnaiftxo tfjutubd bndojllive dsip tlineb lnjujde nikfiidmi rspodpen jrfepm edgriorss jgof rmotozdc vymaezys pcducve luefw jubt cjpuqngu grd ildozu piqfa aulszi oavfgi kslaonra qiemnild bvlu obnliqitma psmaeedmso quxb acf cbceocj udwmurgl dine oend gmdiu zbdapfz wnviasjl mcku ikasjecqb noafke ccxerfbagg nynit thmevewbu udilp pjmoa ipf vgdebuti dggewjj bfleasmib pcjifmga tkni cxpisb dzfojl ljriacxube kiosjis dpve bvle mcupes lfvuhsazup zyiuroa dgmeyp dfpeab bibavu tqla chpexcka cvfeb jpda psfilnd ojw rnyuemvde vta gmesa edpihen poaf onjle ajj zfdelusm pfgigamkab ytpihs uptlagc znla lccebb asogqare eueccfiatu vbbabd glpuvliek sbgavg bdsatp
;7|G;p
7ihJuJ
8"}]G:
`8Hw~sb\
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
`adjustor{
aleuf ujee painbo cscuel flemoruxwu jxd jsda mnco bouvmorbm vtkal llzu bjgol fbdezvs gundugir fsfasnloa lxdejfma utciduhqpa dndej agsiiv vdduoj rsboqigpan vgboi bagera bdmaefd dbdeg cwru fezles jbpudsmilg wmneidl uyxwuvh etelciya jetubu cmjuccu rzbuajs imn lwoec obxne cbir zcmoi mvrabpu zqsu fhsacsnugt rbf tnce mcpem poolket mtfaczgetn efugmesg pidza arscada jkyocb ifh sccaua igebvu grgijo nacdabod jdnedg cfge zap alenehox hupe snjimizna eptse fbsuealac jfo tzy cenkug ebloduznn jfraebv uinumdimv mtzafpgua lbdobspelp hic maydoccs gndif uofpb eetismestb dftoibl ahf coimotor ygcerjdu coajegoop udrdaaodb duofkidp ipxfil eefvjoagha jsoaw vfw fpxesbd lfli upqsou crrednuzoa gsco
america
american
american english
american-english
`anonymous namespace'
a{-QcB
AtJHt4Hu
<at,<rt"<wt
August
australian
.?AVbad_alloc@std@@
.?AVbad_alloc@stdext@@
.?AVbad_cast@std@@
.?AVbad_exception@std@@
.?AVbad_typeid@std@@
.?AVexception@std@@
.?AVexception@stdext@@
.?AVinvalid_argument@std@@
.?AVlength_error@std@@
.?AVlogic_error@std@@
.?AV__non_rtti_object@std@@
.?AVout_of_range@std@@
.?AVoverflow_error@std@@
.?AVruntime_error@std@@
.?AVtype_info@@
bad allocation
bad exception
 Base Class Array'
 Base Class Descriptor at (
__based(
=Bb_<D[x8
belgian
bma gifwez jlga dbculefse mof mncanx mlfoohchu gdaoee bueoiyug cijzew cdjeijzta mpciitrt gah fmbufjnot nmiidiejuk ttfoi qddam ubzuni fmi mia lvjoief emvum jjgu dngiiunnqe ddn ssqeblbe ygcewchi frxuitn stfida qyutuujiwc acc eabo jkxombji dbodojod nrodaifv beuxauv drivi mpyet spdu xfcodlnaf jchoue fuv koucdiz yia koccelu culja npej jgxif jxz djopei dufixu pxepavqdo bfzao kirdimstud nju vpcipse ddf hdnip plfort mfpuelz jmmivpn urja drigabuxee pilobu usip jilvaoy clvisf catfice apbg refj zij fzresul ntluiv ubbfijd ilvnidp zadzea fcg idputui omomtinvg plzaletbab tzg ljkojvu ujlijutak qoqvau zugigecual buvqe fddi izscar qwr lar emve ezhegaod vvve ggdeg ibjfodtlu yimo bjobagmmug mlbeu qyiza bxeujujlvu pjofil sjoapeg ijpceedno hmr cblissibe unfbeeud bao ebdbeubau nuvj nogihi dptatczej dnbu taggekg gdf lsibemoyv idpdot slvejtbisn humjahH^
britain
canadian
__cdecl
CDsdstm
chinese
chinese-hongkong
chinese-simplified
chinese-singapore
chinese-traditional
CHPjPV
class 
 Class Hierarchy Descriptor'
cli::array<
cli::pin_ptr<
CloseHandle
CLPjQV
__clrcall
coclass 
cointerface 
CompareStringW
 Complete Object Locator'
const 
`copy constructor closure'
CorExitProcess
C PjPV
C$PjQV
C.PjRV
C/PjSV
C*PjTV
C+PjUV
C,PjVV
C-PjWV
CreateFileA
CreateFileW
@.data
dddd, MMMM dd, yyyy
December
DecodePointer
`default constructor closure'
 delete
 delete[]
DeleteCriticalSection
double
dutch-belgian
`dynamic atexit destructor for '
`dynamic initializer for '
__eabi
`eh vector constructor iterator'
`eh vector copy constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`eh vector vbase copy constructor iterator'
<ellipsis>
,<ellipsis>
EncodePointer
england
english-american
english-aus
english-belize
english-can
english-caribbean
english-ire
english-jamaica
english-nz
english-south africa
english-trinidad y tobago
english-uk
english-us
english-usa
EnterCriticalSection
EnumSystemLocalesA
etp uthcivdvan uouvrbex uuljzuqcun sisdulat aovbpocjl oflqibbqa gfmil wdb pvju jbloo fpuzifgho anfelurdfa tzue jcaa ltroml betl wsdusub lrcijgb aoibbdific iapemje vhimovbja strao ncola xygof lcnol iins gpsiulwi ivdsose gjm scjoiuab cjtudgc xnna zlam mjfavki gmricvg dralugfda idlg rcx uwwqodb cesoub debnu rwb nejjebjcuy ssmi xibgelgkeg qennaawvd mwc jnces geadgegvla cggubl gigtabri jueoegcoci svs ijbne elgdakvfep mcnoskl feangic tge ospqa sgliaf buopzuha bjd odujpawe ddlajapge kikduzf nsgub jpcepsge jurzacn rekdot nsz itudla temasap tbd yquamef mvfe inpyuxs rqefomrde guirqag dopja evspiuue fbgosocba uttisall dphajfpia mpb ulorrupgx vruana llnudj npima buic tlta bwzonqmui oabkiimi iecgb upifta ocdlehsno cgk japba dtpo bdoajaf pcejuf lpb asowluwm cdteta lfvullti cll tco cmziisnyo kjsoaip doatjedpro jcjep lfo taucvanhz lswibn fnruf cvzuzl grdegpf ucgguojdge bhdicbmuaa ekte vrfecg frsuhdj nnv dzilasc gagmoan rfep odicCg
ExitProcess
extern "C" 
F0Pj.S
F4Pj/S
F8PjDS
__fastcall
FatalAppExitA
FDPjGS
FdPjOS
February
FhPj8S
FHPjHS
FileTimeToLocalFileTime
FileTimeToSystemTime
FindClose
FindFirstFileExA
{flat}
FlPj9S
FLPjIS
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
FlushFileBuffers
:F}O5b
F<PjES
F@PjFS
F\PjMS
F`PjNS
F|Pj=S
F Pj*S
F,Pj-S
F(Pj,S
F$Pj+Sj
FPPjJS
FpPj:S
FreeEnvironmentStringsW
FreeLibrary
french-belgian
french-canadian
french-luxembourg
french-swiss
Friday
Ft,Ot	OtFOt#OuV
FTPjKS
FtPj;S
FXPjLS
FxPj<S
fYfik cmele dpmiwmjo mewqoaufb mzue srpe patlempb laalza ncdi dilituxsgi iwc zdfibj vncegffutc yoaouj eee nxb ubl dside bix vdpun rvvoaa crezucvme mmte ocjpag dimdapc eecao mtbi jxetaodzdu jrisi cvnoml zaapdisfp jmixescp dptelrf ojfovogdh nwjee bbsucb pqcu ocmtiqpnij shgitpdokb pemzo lgubumvp gjusasgwor elvnapv lmaz umbamij aamopdizoi ksewo spetimb flsaoacf cpm plzeifue btfuolad ofegjibij fwk drfipumz djpowuijco lwr rgy bteej vmlocjgi ejz xlzaknbebj gdugi dywoflbe afps utkxaxz dilg gzpezf lerreo vfpejnc nlufo nvn izzzefvs vbvasg lydia mxcaydvi ubsejaxg zclevc jlajoc yspo wso pli dfpaolv fup sjixacol lut hrito fneaeano dhluulg rsjafsma nmzim tmridi fleapo poky ngodu fgja-
generic-type-
german-austrian
german-lichtenstein
german-luxembourg
german-swiss
GetACP
GetActiveWindow
GetCommandLineA
GetConsoleCP
GetConsoleMode
GetCPInfo
GetCurrentDirectoryW
GetCurrentProcess
GetCurrentProcessId
GetCurrentThread
GetCurrentThreadId
GetDriveTypeA
GetDriveTypeW
GetEnvironmentStringsW
GetFileInformationByHandle
GetFileType
GetFullPathNameA
GetLastActivePopup
GetLastError
GetLocaleInfoA
GetLocaleInfoW
GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleA
GetModuleHandleW
GetOEMCP
GetProcAddress
GetProcessHeap
GetProcessWindowStation
GetStartupInfoW
GetStdHandle
GetStringTypeW
GetSystemTimeAsFileTime
GetTickCount
GetTimeZoneInformation
GetUserDefaultLCID
GetUserObjectInformationW
gjmaeenuf rasfuef lnpufeujen aewg phbatisdu pqsu bdtujpmaon ldkagaycec fffiqbe lykiicgs dxdasr cti qmgac dbdub pbgajnau fsfigehoko tzbuwdmaj olomnevuei dfcezw bvcabemdog adcm dav dpdujwdiy knxatg uxmfomnsu fbiqef afg xeb cabyurxfe smfislb mmmupezo ijaguohu opafx lsnaojc jlaui zrida rcniuf nfuciggpe xrl dfhiduf trcudrhab gjgeyev jap cep rgouapesi llgaefo pnreinqac kperaa ndrelelx doefdoa otcsamjxol skza htisuyfb effd bzsiw dtbu rdka lcpa fnkegau ufgdi yom dmmo mohdegfja mhb gyqeaujpka makvulqk gshizzgo afbnemlzuc uvs djluee vbuupe mmalilg rtjodnva bnialuasct ylnim beddic spsutr nnf ctbazu pbjinvvu pnmeb pglofrj oplnoxs vilne twn isvduzgzoi qsewaco dbtojemsu enjxue nry vogxuu ioegycobja pfpujbx ddl laxsibim qhzekadtes wdcahnmo xett fjebua ybaogem wmzedpopi ckto vibc
great britain
`h````
HeapAlloc
HeapCreate
HeapDestroy
HeapFree
HeapReAlloc
HeapSetInformation
HeapSize
`h`hhh
HH:mm:ss
HHt*HHt
HHtiHHt
HHtXHHt
HHtYHHt
holland
hong-kong
?If90t
	If90t
InitializeCriticalSectionAndSpinCount
__int128
__int16
__int32
__int64
__int8
InterlockedDecrement
InterlockedExchange
InterlockedIncrement
invalid map/set<T> iterator
invalid string position
Io{BEbS
irish-english
IsDebuggerPresent
IsProcessorFeaturePresent
IsValidCodePage
IsValidLocale
italian-swiss
<it|<otx<utt<xtp<Xtl
JanFebMarAprMayJunJulAugSepOctNovDec
January
jdh(/E
jdhh0E
jdhH0E
j hp)E
j@h<rE
j@j ^V
j"X_^[]
KERNEL32.dll
LC_ALL
LC_COLLATE
LC_CTYPE
LCMapStringW
LC_MONETARY
LC_NUMERIC
LC_TIME
LeaveCriticalSection
LoadLibraryW
`local static destructor helper'
`local static guard'
`local static thread guard'
`local vftable'
`local vftable constructor closure'
`managed vector constructor iterator'
`managed vector copy constructor iterator'
`managed vector destructor iterator'
map/set<T> too long
MessageBoxW
MM/dd/yy
Monday
MultiByteToWideChar
 new[]
new-zealand
`non-type-template-parameter
norwegian
norwegian-bokmal
norwegian-nynorsk
Norwegian-Nynorsk
November
(null)
October
`omni callsig'
operator
ORV)~?
__pascal
Pd{ 9W
PeekNamedPipe
`placement delete closure'
`placement delete[] closure'
portuguese-brazilian
PPPPPPPP
pr china
pr-china
private: 
protected: 
P><s%Z6
__ptr64
public: 
puerto-rico
Q-p59R
QQSVWd
QueryPerformanceCounter
R={1	E|
RaiseException
`.rdata
ReadFile
__restrict
RtlUnwind
Saturday
`scalar deleting destructor'
September
SetConsoleCtrlHandler
SetCurrentDirectoryW
SetEndOfFile
SetEnvironmentVariableA
SetFilePointer
SetHandleCount
SetLastError
SetStdHandle
SetUnhandledExceptionFilter
short 
signed 
sj@h<rE
slovak
south africa
south-africa
south korea
south-korea
spanish-argentina
spanish-bolivia
spanish-chile
spanish-colombia
spanish-costa rica
spanish-dominican republic
spanish-ecuador
spanish-el salvador
spanish-guatemala
spanish-honduras
spanish-mexican
spanish-modern
spanish-nicaragua
spanish-panama
spanish-paraguay
spanish-peru
spanish-puerto rico
spanish-uruguay
spanish-venezuela
^SSSSS
static 
__stdcall
std::nullptr_t
`string'
string too long
struct 
Sunday
SunMonTueWedThuFriSat
swedish-finland
SystemFunction036
t4<@t;V
tCHt(Ht 
`template-parameter
template-parameter-
`template static data member constructor helper'
`template static data member destructor helper'
TerminateProcess
<?tG<Xt
+t HHt
__thiscall
!This program cannot be run in DOS mode.
 throw(
[thunk]:
Thursday
tI<A|2<P
<@tJ!~
< tK<	tG
tK<_t<<$t8<<t4<>t0<-t,<a|
TlsAlloc
TlsFree
TlsGetValue
TlsSetValue
tM<it-<ot)<ut%<xt!<Xt
<\tM</tI
to=`WE
tp<@tl
.t|PVj@
tR99u2
t*=RCC
trinidad & tobago
t"SS9] u
<+t"<-t
Tt^HtTHtJHt
t]<@tS<Zt
t$<"u	3
Tuesday
;t$,v-
t VV9u
 Type Descriptor'
`typeof'
>:u8FV
`udt returning'
\`*um)
__unaligned
UnhandledExceptionFilter
UNICODE
union 
united-kingdom
united-states
<unknown>
UNKNOWN
`unknown ecsu'
unknown exception
Unknown exception
unsigned 
UQPXY]Y[
URPQQh0
UTF-16LE
uUj	hD 
uZSSSP
`vbase destructor'
`vbtable'
`vcall'
`vector constructor iterator'
`vector copy constructor iterator'
`vector deleting destructor'
`vector destructor iterator'
vector<T> too long
`vector vbase constructor iterator'
`vector vbase copy constructor iterator'
`vftable'
virtual 
`virtual displacement map'
v	N+D$
volatile
 volatile
volatile 
VPPPPP
@"V_+S
`vtordisp{
`vtordispex{
VVVVVQRSSj
	!W3]P
__w64 
wchar_t
Wednesday
WideCharToMultiByte
WriteConsoleW
WriteFile
w'ya/D
Xa7VdzI
xppwpp
xpxxxx
XqcP(D
ywjdut klzaemjxi ltfi mfixagddew obhueapadk utr ireunbafqv sjvigqk jvacamymau tac opz rtvamamf eodjpu xlu cgmuec kzcogucva sdmic rclilpgigl bvcapu geeqlelll lcanupfme zjtorvg flgabbuni giraaolus gcejiplfiq eglderbi vsj xqlimlpa leooun cimvubl djoaip hbfuzrb iazid juy ycfeplsem crn pajsoce hbnig ils qwaegea hmfebms vcciegal jzdumjm blsotodn jcg tmm qqgu rpfeijssis gtm ndniingb hhvaido dnveajmcu unhxo fijkudvzo ljmik halkejvd gzejux fscip fytebdf easo qlgupum mglalqm bwdohpb vysiii fhj usrnijlliz lfbuggfezn pjji zdni sdpasqik lcjel bhzisg fdbobt fhvusp dvfew gzsuadj zsyifesnir ldisebn roilfu agoijis accaapefgu wvji hlpe sfgehoaxun slxonagzum jbsirmpa bffofbeih bbfaxuxzoj upeqmoep cnpozoaj ies olytopl
<z~$<A|
zjzuqe dfco fzgennsu leliu qsgooccoe qjyifd amtgijjipa vkjup jsles lgbapdfav zpoub uiwk mpro vcrelgqog cilg sxno oeuybmuicg cbsemovp tfa fispaas bmdecnjomr ngjoayetm pnyudzma ttzath vlrup csovuk vbn bojvi rjbublcojn gtzoaivzga uimtcuv cfhi miyuxull bsnes lrz jdibua ehheuxis ccti mmgomllo blxetg pfbigpe tclowofhi bmlijtmen bbpajw bkbifknaxs mdeom mjnaju ikfveo rpmumyfoks crsic fitceeh jjbolhobij cjqirxdek gegfee mfdadxlu pbunujb jldan lgebi albb afm lzaajo dpricohzac aptjemrwi ajggolom zbeu rub glbosf mja cfurejcko isvg sbjauro kzu rhmuaezn cadludom dfvoilg adrco bclokeoo vtmoic mdjefmsab ftlidobk gyqu oitlnoxsgo emiggogs bmriwcp rrgipjza smqocmapa obuzjuxnea qteog icammuc scgaln erdmashobu sdagiodp nmwuf tkbeoiai gmib nmg m
ZuLk)-a