Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: kernel32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: LoadLibraryW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetUserDefaultLocaleName |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetEnvironmentVariableW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrlenA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: FreeLibrary |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GlobalFre |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CreateFileW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetTimeZoneInformation |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetProcAddress |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrcpyA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ReadFil |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrlenW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: WriteFile |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SetCurrentDirectoryW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrcmpW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CloseHandle |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetLastError |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: FindNextFileW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: FindFirstFileW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Process32First |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetFileSize |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: OpenMutexW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: WideCharToMultiByte |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GlobalAlloc |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetCurrentProcess |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ExitProcess |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CreateMutexW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetSystemWow64DirectoryW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetLocaleInfoW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GlobalMemoryStatusEx |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetDriveTypeW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: OpenProcess |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: LocalAlloc |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrcmpiW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SetEnvironmentVariableW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CopyFileW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetModuleFileNameW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrcmpA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Sleep |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetSystemInfo |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: LocalFree |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Process32Next |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: DeleteFileW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: lstrcpynA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: MultiByteToWideChar |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: FindClose |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CreateToolhelp32Snapshot |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: HeapFree |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetUserDefaultLCID |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetLogicalDriveStringsW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Shlwapi.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PathMatchSpecW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrCpyW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrStrIW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrStrW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PathCombineW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrRChrW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrToIntA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrToIntW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrStrA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StrToInt64ExW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Ole32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CoInitialize |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CoCreateInstance |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: WinInet.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Shell32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: User32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Advapi32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Bcrypt.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Crypt32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: HttpQueryInfoA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: HttpOpenRequestW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetReadFileExW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetOpenUrlW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: HttpQueryInfoW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetCloseHandle |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetConnectW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetSetOptionW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetOpenW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: HttpSendRequestW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetReadFile |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: InternetOpenUrlA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ShellExecuteW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SHGetFolderPathW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SHGetSpecialFolderPathW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ConvertSidToStringSidW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: OpenProcessToken |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SystemFunction036 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: RegEnumKeyExW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: RegCloseKey |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: DuplicateTokenEx |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetUserNameW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: RegOpenKeyExW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: RegQueryValueExW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetTokenInformation |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CreateProcessWithTokenW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CharUpperW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: EnumDisplayDevicesW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetClientRect |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetDC |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetDesktopWindow |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetSystemMetrics |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ReleaseDC |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: wsprintfW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CryptStringToBinaryA |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CryptStringToBinaryW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CryptBinaryToStringW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CryptUnprotectData |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sgnl_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: tlgrm_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ews_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: grbr_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: dscrd_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: %sTRUE%s%s%s%s%s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: URL:%sUSR:%sPASS:%s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: %d) %s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - Locale: %s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - OS: %s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - RAM: %d MB |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - Time zone: %c%ld minutes from GMT |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - Display size: %dx%d |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: % |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - Architecture: x%d |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - CPU: %s (%d cores) |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: - Display Devices:%s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: formhistory.sqlite |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: * |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: : |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: % |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ; |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: | |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \* |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: logins.json |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \autofill.txt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \cookies.txt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \passwords.txt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: --- |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: -- |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: */* |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Content-Type: application/x-www-form-urlencoded; charset=utf-8 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Content-Type: multipart/form-data; boundary= |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Content-Type: text/plain; |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: User Data |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: wallets |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: wlts_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ldr_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: scrnsht_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sstmnfo_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: token: |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: nss3.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SOFTWARE\Microsoft\Windows NT\CurrentVersion |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PATH |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ProductName |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Web Data |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Login Data |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_prepare_v2 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_open16 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_close |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_step |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_finalize |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_column_text16 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_column_bytes1 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: sqlite3_column_blo |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SELECT origin_url, username_value, password_value FROM logins |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SELECT host_key, path, is_secure , expires_utc, name, encrypted_value FROM cookies |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SELECT name, value FROM autofill |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: pera |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Stable |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SELECT host, path, isSecure, expiry, name, value FROM moz_cookies |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SELECT fieldname, value FROM moz_formhistory |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: cookies.sqlite |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: machineId= |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: &configId= |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: "encrypted_key":" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: stats_version":" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Content-Type: application/x-object |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Content-Disposition: form-data; name="file"; filename=" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GET |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: POST |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Low |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: MachineGuid |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: image/jpeg |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdiPlus.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Gdi32.dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdiplusStartup |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdipDisposeImage |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdipGetImageEncoders |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdipGetImageEncodersSize |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdipCreateBitmapFromHBITMAP |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GdipSaveImageToFile |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: BitBlt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CreateCompatibleBitmap |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: CreateCompatibleDC |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: DeleteObject |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: GetObjectW |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SelectObject |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SetStretchBltMode |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: StretchBlt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SELECT name_on_card, card_number_encrypted, expiration_month, expiration_year FROM credit_cards |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Cookies |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Network\Cookies |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: NUM:%sHOLDER:%sEXP:%s/%s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \CC.txt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: NSS_Init |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: NSS_Shutdown |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PK11_GetInternalKeySlot |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PK11_FreeSlot |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PK11_Authenticate |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: PK11SDR_Decrypt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SECITEM_FreeItem |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: hostname":" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ","httpRealm": |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: encryptedUsername":" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ","encryptedPassword":" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ","guid": |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Profiles |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: :// |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ru |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: S-1-5-18 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: v10 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: / |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Default |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Profile %d |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: extensions |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: xtntns_ |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: prefs.js |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: storage\default |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: 1 |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: MetaMask |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: .sqlite |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: "webextension@metamask.io":" |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: TRUE |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: FALSE |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: explorer.exe |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SOFTWARE\Microsoft\Cryptography |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: DisplayNam |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: DisplayVersion |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: %s %s |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: \ffcookies.txt |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: ? |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: Local State |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: .. |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: . |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: wallet.dat |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: .dll |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: libs |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: *.lnk |
Source: 00000000.00000003.237007486.0000000002080000.00000040.00001000.00020000.00000000.sdmp | String decryptor: open |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_004042C6 StrStrW,StrStrW,StrStrW,lstrlenW,LocalAlloc,lstrlenW,LocalAlloc,lstrlenW,LocalAlloc,StrStrW,StrStrW,LocalAlloc,PathCombineW,LocalAlloc,FindFirstFileW,StrStrW,LocalAlloc,StrCpyW,StrRChrW,StrRChrW,LocalAlloc,PathCombineW,LocalFree,LocalFree,FindNextFileW,FindClose,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,StrStrW,LocalFree,LocalFree,LocalFree, | 3_2_004042C6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_0041EFCD LocalAlloc,StrCpyW,FindFirstFileW,LocalAlloc,PathCombineW,LocalFree,LocalAlloc,PathCombineW,LocalAlloc,CopyFileW,CreateFileW,GetFileSize,LocalAlloc,StrCpyW,LocalAlloc,lstrlenW,WideCharToMultiByte,LocalAlloc,WideCharToMultiByte,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,CloseHandle,DeleteFileW,LocalAlloc,StrCpyW,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,DeleteFileW,FindNextFileW,LocalFree,FindClose, | 3_2_0041EFCD |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00407067 FindFirstFileW,lstrcmpW,LocalAlloc,PathCombineW,LocalFree,FindNextFileW,FindClose,lstrlenW, | 3_2_00407067 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_004021E9 LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,PathCombineW,StrCpyW,FindFirstFileW,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,lstrlenW,lstrlenW,lstrlenW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,LocalAlloc,StrCpyW,LocalAlloc,WideCharToMultiByte,WideCharToMultiByte,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalAlloc,LocalAlloc,StrCpyW,wsprintfW,PathCombineW,FindFirstFileW,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,LocalAlloc,lstrlenW,lstrlenW,lstrlenW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,LocalAlloc,StrCpyW,LocalAlloc,WideCharToMultiByte,WideCharToMultiByte,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree, | 3_2_004021E9 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00401D6F FindFirstFileW,lstrcmpW,LocalAlloc,PathCombineW,LocalFree,FindNextFileW,FindClose,StrStrW,StrStrW,LocalAlloc,PathCombineW,lstrlenW, | 3_2_00401D6F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00401EF6 FindFirstFileW,lstrcmpW,LocalAlloc,PathCombineW,LocalFree,FindNextFileW,FindClose,StrStrW,lstrlenW,LocalAlloc,PathCombineW,lstrlenW, | 3_2_00401EF6 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_0041EC8D LocalAlloc,LocalAlloc,SHGetSpecialFolderPathW,lstrcmpW,StrCpyW,StrCpyW,FindFirstFileW,LocalFree,LocalFree,lstrcmpW,lstrcmpW,LocalAlloc,PathCombineW,lstrcmpW,LocalAlloc,PathCombineW,LocalAlloc,LocalAlloc,SHGetSpecialFolderPathW,lstrlenW,LocalAlloc,StrCpyW,WideCharToMultiByte,LocalAlloc,WideCharToMultiByte,LocalAlloc,CopyFileW,CreateFileW,GetFileSize,LocalAlloc,StrCpyW,LocalFree,DeleteFileW,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,LocalFree,LocalFree,FindClose, | 3_2_0041EC8D |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00404593 StrStrW,StrStrW,StrStrW,lstrlenW,LocalAlloc,lstrlenW,LocalAlloc,lstrlenW,LocalAlloc,StrStrW,StrStrW,LocalAlloc,PathCombineW,LocalAlloc,FindFirstFileW,StrStrW,LocalAlloc,StrCpyW,StrRChrW,StrRChrW,LocalAlloc,PathCombineW,LocalFree,LocalFree,FindNextFileW,FindClose,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,StrStrW,LocalFree,LocalFree,LocalFree, | 3_2_00404593 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00408349 LocalAlloc,LocalAlloc,LocalAlloc,PathCombineW,PathCombineW,CopyFileW,CreateFileW,GetFileSize,LocalAlloc,ReadFile,lstrlenA,StrStrA,lstrlenA,StrStrA,LocalAlloc,FindFirstFileW,StrStrW,StrStrW,lstrlenW,lstrlenW,LocalAlloc,StrStrW,StrCpyW,LocalAlloc,PathCombineW,PathCombineW,LocalFree,FindNextFileW,FindClose,LocalFree,CloseHandle,DeleteFileW,LocalFree,DeleteFileW,LocalFree, | 3_2_00408349 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_004068D3 LocalAlloc,StrCpyW,lstrlenW,FindFirstFileW,LocalFree,LocalAlloc,PathCombineW,LocalFree,LocalAlloc,StrCpyW,LocalAlloc,StrCpyW,LocalAlloc,LocalAlloc,lstrlenW,lstrlenW,StrCpyW,LocalFree,LocalAlloc,CopyFileW,CreateFileW,WideCharToMultiByte,LocalAlloc,WideCharToMultiByte,GetFileSize,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,CloseHandle,DeleteFileW,LocalFree,DeleteFileW,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,LocalFree,FindClose, | 3_2_004068D3 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00407471 LocalAlloc,FindFirstFileW,StrStrW,LocalAlloc,PathCombineW,LocalAlloc,CopyFileW,CreateFileW,GetFileSize,LocalAlloc,StrCpyW,WideCharToMultiByte,LocalAlloc,LocalAlloc,WideCharToMultiByte,StrCpyW,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,FindClose,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,DeleteFileW, | 3_2_00407471 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_00403D76 LocalAlloc,FindFirstFileW,lstrcmpW,LocalAlloc,PathCombineW,LocalAlloc,CopyFileW,CreateFileW,GetFileSize,LocalAlloc,StrCpyW,WideCharToMultiByte,LocalAlloc,LocalAlloc,WideCharToMultiByte,StrCpyW,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,FindClose,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,DeleteFileW, | 3_2_00403D76 |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_0040770F LocalAlloc,StrCpyW,FindFirstFileW,LocalAlloc,PathCombineW,lstrcmpW,LocalAlloc,LocalAlloc,LocalAlloc,StrCpyW,StrCpyW,StrCpyW,LocalAlloc,LocalAlloc,lstrlenW,lstrlenW,lstrlenW,lstrlenW,lstrlenW,LocalAlloc,LocalAlloc,StrCpyW,LocalAlloc,WideCharToMultiByte,WideCharToMultiByte,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,FindClose,LocalFree, | 3_2_0040770F |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_0041479A LocalAlloc,StrCpyW,FindFirstFileW,LocalFree,LocalAlloc,PathCombineW,LocalAlloc,PathCombineW,LocalAlloc,StrCpyW,LocalAlloc,lstrlenW,LocalAlloc,CopyFileW,CreateFileW,WideCharToMultiByte,LocalAlloc,WideCharToMultiByte,LocalFree,CloseHandle,DeleteFileW,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,LocalFree,FindClose, | 3_2_0041479A |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_0040401E LocalAlloc,FindFirstFileW,lstrcmpW,LocalAlloc,PathCombineW,LocalAlloc,CopyFileW,CreateFileW,GetFileSize,LocalAlloc,StrCpyW,WideCharToMultiByte,LocalAlloc,LocalAlloc,WideCharToMultiByte,StrCpyW,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,FindClose,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,LocalFree,DeleteFileW, | 3_2_0040401E |
Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe | Code function: 3_2_0040609F LocalAlloc,StrCpyW,FindFirstFileW,LocalFree,LocalAlloc,PathCombineW,LocalAlloc,PathCombineW,LocalAlloc,StrCpyW,LocalAlloc,lstrlenW,LocalAlloc,CopyFileW,CreateFileW,WideCharToMultiByte,LocalAlloc,WideCharToMultiByte,LocalFree,CloseHandle,DeleteFileW,LocalFree,LocalFree,LocalFree,LocalFree,FindNextFileW,LocalFree,FindClose, | 3_2_0040609F |