emed64_26.2.7.msi
Unsigned Winsock loader with debugger-gated PEBMP screenshot capture with network exfiltration
SHA-2568999dc0c78a199f15c1b1e6b49b5b5322dc43a36df5b60b09b8f5ce86c4a8f74
Evidence
⋯3 more rows
0x523bc45c7372635c666d745c6d6f642e727300\src\fmt\mod.rs.
0x523bd4303030303030303030303030303030300000000000000000
0x523be4303030303030303030303030303030300000000000000000
0x523bf4303030303030303030303030303030300000000000000000
⋯7 more rows
⋯3 more rows
0x69902e696c656e745345545f4150504449525bilentSET_APPDIR[
0x69903e4c6f63616c41707044617461466f6c64LocalAppDataFold
0x69904e65725d5c50726f6772616d735c456d45er]\Programs\EmE
0x69905e6469746f725345545f53484f52544355ditorSET_SHORTCU
0x69906e5444495253484f52544355544449525bTDIRSHORTCUTDIR[
0x69907e50726f6772616d4d656e75466f6c6465ProgramMenuFolde
⋯7 more rows