Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,GetMenuState,LocalFree, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040E511 CryptUnprotectData,LocalFree, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,GetMenuState,LocalFree, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040E511 CryptUnprotectData,LocalFree, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040E511 CryptUnprotectData,LocalFree, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040E511 CryptUnprotectData,LocalFree, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040C4B7 RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegOpenKeyExA,RegEnumKeyExA,RegOpenKeyExA,RegCloseKey,RegCloseKey,CryptUnprotectData,LocalFree,CryptUnprotectData,LocalFree, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040E511 CryptUnprotectData,LocalFree, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040EDD6 fopen,malloc,fclose,fread,fclose,CryptUnprotectData,sprintf,strcmp,strcmp, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040D290 CryptAcquireContextA,CryptCreateHash,CryptHashData,CryptGetHashParam,CryptDestroyHash,CryptReleaseContext, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_00405CD8 FindFirstFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_0040263E FindFirstFileA, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_00405CD8 FindFirstFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_0040263E FindFirstFileA, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00409953 GetKeyState,GetKeyState,GetKeyState,GetKeyState,GetKeyboardState,MapVirtualKeyW,ToUnicode,WideCharToMultiByte,GetKeyState,MapVirtualKeyW,GetKeyNameTextW,GetKeyState,WideCharToMultiByte, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_004046CA |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_00405FA8 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_73861A98 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00403047 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0041D049 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00419463 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00415079 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00420420 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_004208C0 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_004034D3 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00414976 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00402E68 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00416619 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040AEC6 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00402AFC |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00415ABF |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00420F40 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0041FF50 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040A728 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00403047 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0041D049 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00419463 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00415079 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00420420 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_004208C0 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_004034D3 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00414976 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00402E68 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00416619 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040AEC6 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00402AFC |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00415ABF |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00420F40 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0041FF50 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040A728 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00403047 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0041D049 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00419463 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00415079 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00420420 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_004208C0 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_004034D3 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00414976 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00402E68 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00416619 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040AEC6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00402AFC |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00415ABF |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00420F40 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0041FF50 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040A728 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00403047 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0041D049 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00419463 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00415079 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00420420 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_004208C0 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_004034D3 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00414976 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00402E68 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00416619 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040AEC6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00402AFC |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00415ABF |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00420F40 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0041FF50 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040A728 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_004046CA |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_00405FA8 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00403047 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0041D049 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00419463 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00415079 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00420420 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_004208C0 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_004034D3 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00414976 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00402E68 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00416619 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040AEC6 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00402AFC |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00415ABF |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00420F40 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0041FF50 |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040A728 |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_73862F60 push eax; ret |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00409E61 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040DCE9 push ecx; mov dword ptr [esp], 00423976h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040DCE9 push ebp; mov dword ptr [esp], 0042398Ah |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040DCE9 push edx; mov dword ptr [esp], 00423997h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040DCE9 push edx; mov dword ptr [esp], esi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040A4BC push esi; mov dword ptr [esp], 00423347h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00409953 push edi; mov dword ptr [esp], 00000091h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00409953 push ebp; mov dword ptr [esp], 00000090h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00411D8C push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406E04 push ecx; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040262F push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040262F push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040262F push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_004146E1 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040970C push eax; mov dword ptr [esp], 0042B4A0h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00409E61 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040DCE9 push ecx; mov dword ptr [esp], 00423976h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040DCE9 push ebp; mov dword ptr [esp], 0042398Ah |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040DCE9 push edx; mov dword ptr [esp], 00423997h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040DCE9 push edx; mov dword ptr [esp], esi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040A4BC push esi; mov dword ptr [esp], 00423347h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00409953 push edi; mov dword ptr [esp], 00000091h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00409953 push ebp; mov dword ptr [esp], 00000090h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00411D8C push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406E04 push ecx; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040262F push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040262F push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040262F push edx; mov dword ptr [esp], edi |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_004146E1 push eax; mov dword ptr [esp], ebx |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040970C push eax; mov dword ptr [esp], 0042B4A0h |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_00405CD8 FindFirstFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 1_2_0040263E FindFirstFileA, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\Desktop\US1pwXib6h.exe | Code function: 2_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 6_1_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_00405302 DeleteFileA,lstrcatA,lstrcatA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_00405CD8 FindFirstFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 7_2_0040263E FindFirstFileA, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00406453 MultiByteToWideChar,SetErrorMode,FindFirstFileW,FileTimeToSystemTime,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040680D SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040753D MultiByteToWideChar,SetErrorMode,MultiByteToWideChar,wcscat,FindFirstFileW,FindClose,WideCharToMultiByte,MultiByteToWideChar,wcscat,WideCharToMultiByte,FindNextFileW, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00413A85 SetErrorMode,MultiByteToWideChar,FindFirstFileW,WideCharToMultiByte,WideCharToMultiByte,FindNextFileW,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_0040DB1C SetErrorMode,FindFirstFileA,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00406F83 SetErrorMode,FindFirstFileA,strcmp,strcmp,strcat,fopen,strncpy,fclose,strcpy,FindNextFileA,FindClose, |
Source: C:\Users\user\AppData\Roaming\fatbtifdnumsa\ioldfli.exe | Code function: 9_2_00406390 FindFirstFileW,fopen,_snwprintf,fwprintf,_snwprintf,FindNextFileW,FindClose,fclose, |
Source: Yara match | File source: 00000002.00000001.363673900.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000007.00000002.406739098.00000000023A0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000002.394088134.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000006.00000001.393727825.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000004.00000002.395120542.00000000024E0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000009.00000001.405669006.0000000000400000.00000040.00020000.sdmp, type: MEMORY |
Source: Yara match | File source: 00000001.00000002.367065114.00000000024C0000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000002.00000002.621612280.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: 00000009.00000002.406157548.0000000000400000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match | File source: Process Memory Space: US1pwXib6h.exe PID: 6476, type: MEMORY |
Source: Yara match | File source: Process Memory Space: ioldfli.exe PID: 6768, type: MEMORY |
Source: Yara match | File source: Process Memory Space: ioldfli.exe PID: 7088, type: MEMORY |
Source: Yara match | File source: Process Memory Space: US1pwXib6h.exe PID: 6548, type: MEMORY |
Source: Yara match | File source: Process Memory Space: ioldfli.exe PID: 7012, type: MEMORY |
Source: Yara match | File source: Process Memory Space: ioldfli.exe PID: 6824, type: MEMORY |
Source: Yara match | File source: 1.2.US1pwXib6h.exe.24c0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.1.US1pwXib6h.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 4.2.ioldfli.exe.24e0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.1.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.US1pwXib6h.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.2.US1pwXib6h.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.1.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 2.1.US1pwXib6h.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 9.1.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 9.2.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 7.2.ioldfli.exe.23a0000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.2.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 9.2.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 9.1.ioldfli.exe.400000.0.unpack, type: UNPACKEDPE |
Source: Yara match | File source: 6.2.ioldfli.exe.400000.0.raw.unpack, type: UNPACKEDPE |