| filename | svchost.exe | |
|---|---|---|
| size | 57368 (0xe018) | |
| md5 | 95043977365cf88a80161be9cf3281fb | |
| type | PE32+ executable (GUI) x86-64, for MS Windows | |
| mimetype | application/x-dosexec | |
| clamav | OK | |
| virustotal | → scan with virustotal.com | |
| histogram | ||
MZ Header
| signature | MZ |
| bytes_in_last_block | 0x90 |
| blocks_in_file | 3 |
| num_relocs | 0 |
| header_paragraphs | 4 |
| min_extra_paragraphs | 0 |
| max_extra_paragraphs | 0xffff |
| ss | 0 |
| sp | 0xb8 |
| checksum | 0 |
| ip | 0 |
| cs | 0 |
| reloc_table_offset | 0x40 |
| overlay_number | 0 |
| reserved0 | 0 |
| oem_id | 0 |
| oem_info | 0 |
| reserved2 | 0 |
| reserved3 | 0 |
| reserved4 | 0 |
| reserved5 | 0 |
| reserved6 | 0 |
| lfanew | 0xe8 |
Rich Header
| lib id | version | times used |
|---|---|---|
| 257 | 27412 | 2 |
| 259 | 27412 | 2 |
| 147 | 30729 | 59 |
| 1 | 0 | 148 |
| 269 | 27412 | 12 |
| 260 | 27412 | 12 |
| 255 | 27412 | 1 |
| 258 | 27412 | 1 |
DOS stub
00000000: 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 |........!..L.!Th| 00000010: 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f |is program canno| 00000020: 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 |t be run in DOS | 00000030: 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 |mode....$.......|
PE Header
Packer / Compiler
Sections
Data Directory
| module_name | hint | ord | function_name |
|---|---|---|---|
| api-ms-win-core-crt-l2-1-0.dll | 6 | _initterm | |
| api-ms-win-core-crt-l2-1-0.dll | 7 | _initterm_e | |
| api-ms-win-core-crt-l2-1-0.dll | 1 | __wgetmainargs | |
| api-ms-win-core-crt-l2-1-0.dll | 13 | exit | |
| api-ms-win-core-profile-l1-1-0.dll | QueryPerformanceCounter | ||
| api-ms-win-core-processthreads-l1-1-0.dll | 12 | GetCurrentProcess | |
| api-ms-win-core-processthreads-l1-1-0.dll | 17 | GetCurrentThreadId | |
| api-ms-win-core-processthreads-l1-1-0.dll | 13 | GetCurrentProcessId | |
| api-ms-win-core-processthreads-l1-1-0.dll | 49 | OpenProcessToken | |
| api-ms-win-core-processthreads-l1-1-0.dll | 78 | TerminateProcess | |
| api-ms-win-core-processthreads-l1-1-0.dll | 58 | SetProcessAffinityUpdateMode | |
| api-ms-win-core-processthreads-l1-1-0.dll | 8 | ExitProcess | |
| api-ms-win-core-sysinfo-l1-1-0.dll | 22 | GetSystemTimeAsFileTime | |
| api-ms-win-core-sysinfo-l1-1-0.dll | 27 | GetTickCount64 | |
| api-ms-win-core-sysinfo-l1-1-0.dll | 26 | GetTickCount | |
| api-ms-win-core-rtlsupport-l1-1-0.dll | 10 | RtlLookupFunctionEntry | |
| api-ms-win-core-rtlsupport-l1-1-0.dll | 2 | RtlCaptureContext | |
| api-ms-win-core-rtlsupport-l1-1-0.dll | 16 | RtlVirtualUnwind | |
| api-ms-win-core-errorhandling-l1-1-0.dll | 5 | GetLastError | |
| api-ms-win-core-errorhandling-l1-1-0.dll | 12 | SetErrorMode | |
| api-ms-win-core-errorhandling-l1-1-0.dll | 15 | SetUnhandledExceptionFilter | |
| api-ms-win-core-errorhandling-l1-1-0.dll | 17 | UnhandledExceptionFilter | |
| api-ms-win-service-private-l1-1-3.dll | 3 | I_RegisterSvchostNotificationCallback | |
| api-ms-win-core-crt-l1-1-0.dll | 58 | qsort_s | |
| api-ms-win-core-crt-l1-1-0.dll | 53 | memcpy | |
| api-ms-win-core-crt-l1-1-0.dll | 57 | memset | |
| api-ms-win-core-crt-l1-1-0.dll | 25 | _wcsicmp | |
| api-ms-win-core-libraryloader-l1-2-0.dll | 21 | GetProcAddress | |
| api-ms-win-core-libraryloader-l1-2-0.dll | 12 | FreeLibrary | |
| api-ms-win-core-libraryloader-l1-2-0.dll | 20 | GetModuleHandleW | |
| api-ms-win-core-libraryloader-l1-2-0.dll | 24 | LoadLibraryExW | |
| api-ms-win-core-heap-l1-1-0.dll | 6 | HeapFree | |
| api-ms-win-core-heap-l1-1-0.dll | GetProcessHeap | ||
| api-ms-win-core-heap-l1-1-0.dll | 2 | HeapAlloc | |
| api-ms-win-core-heap-l1-1-0.dll | 10 | HeapSetInformation | |
| api-ms-win-core-synch-l1-1-0.dll | 29 | LeaveCriticalSection | |
| api-ms-win-core-synch-l1-1-0.dll | 37 | ReleaseSRWLockShared | |
| api-ms-win-core-synch-l1-1-0.dll | 1 | AcquireSRWLockShared | |
| api-ms-win-core-synch-l1-1-0.dll | 27 | InitializeSRWLock | |
| api-ms-win-core-synch-l1-1-0.dll | 36 | ReleaseSRWLockExclusive | |
| api-ms-win-core-synch-l1-1-0.dll | AcquireSRWLockExclusive | ||
| api-ms-win-core-synch-l1-1-0.dll | 17 | EnterCriticalSection | |
| api-ms-win-service-winsvc-l1-1-0.dll | 13 | RegisterServiceCtrlHandlerW | |
| api-ms-win-service-core-l1-1-0.dll | 8 | SetServiceStatus | |
| api-ms-win-service-core-l1-1-0.dll | 9 | StartServiceCtrlDispatcherW | |
| api-ms-win-core-string-l1-1-0.dll | 6 | MultiByteToWideChar | |
| api-ms-win-core-string-l1-1-0.dll | 7 | WideCharToMultiByte | |
| api-ms-win-core-string-l1-1-0.dll | 1 | CompareStringOrdinal | |
| api-ms-win-core-registry-l1-1-0.dll | RegCloseKey | ||
| api-ms-win-core-registry-l1-1-0.dll | 37 | RegQueryValueExW | |
| api-ms-win-core-registry-l1-1-0.dll | 12 | RegDisablePredefinedCacheEx | |
| api-ms-win-core-registry-l1-1-0.dll | 30 | RegOpenKeyExW | |
| api-ms-win-core-registry-l1-1-0.dll | 20 | RegGetValueW | |
| api-ms-win-core-registry-l1-1-0.dll | 14 | RegEnumKeyExW | |
| api-ms-win-core-processenvironment-l1-1-0.dll | 1 | ExpandEnvironmentStringsW | |
| api-ms-win-core-processenvironment-l1-1-0.dll | 5 | GetCommandLineW | |
| api-ms-win-core-processthreads-l1-1-1.dll | 62 | SetProcessMitigationPolicy | |
| api-ms-win-core-processthreads-l1-1-2.dll | 65 | SetProtectedPolicy | |
| RPCRT4.dll | 484 | RpcServerUnregisterIf | |
| RPCRT4.dll | 68 | I_RpcMapWin32Status | |
| RPCRT4.dll | 441 | RpcMgmtSetServerStackSize | |
| RPCRT4.dll | 93 | I_RpcServerDisableExceptionFilter | |
| RPCRT4.dll | 495 | RpcServerUseProtseqEpW | |
| RPCRT4.dll | 485 | RpcServerUnregisterIfEx | |
| RPCRT4.dll | 443 | RpcMgmtStopServerListening | |
| RPCRT4.dll | 475 | RpcServerListen | |
| RPCRT4.dll | 444 | RpcMgmtWaitServerListen | |
| RPCRT4.dll | 478 | RpcServerRegisterIf | |
| api-ms-win-core-localization-l1-2-0.dll | 53 | LCMapStringW | |
| api-ms-win-security-base-l1-1-0.dll | 99 | SetSecurityDescriptorGroup | |
| api-ms-win-security-base-l1-1-0.dll | 98 | SetSecurityDescriptorDacl | |
| api-ms-win-security-base-l1-1-0.dll | 79 | MakeAbsoluteSD | |
| api-ms-win-security-base-l1-1-0.dll | 7 | AddAccessAllowedAce | |
| api-ms-win-security-base-l1-1-0.dll | 66 | GetTokenInformation | |
| api-ms-win-security-base-l1-1-0.dll | 53 | GetLengthSid | |
| api-ms-win-security-base-l1-1-0.dll | 71 | InitializeAcl | |
| api-ms-win-security-base-l1-1-0.dll | 100 | SetSecurityDescriptorOwner | |
| api-ms-win-security-base-l1-1-0.dll | 72 | InitializeSecurityDescriptor | |
| api-ms-win-core-handle-l1-1-0.dll | CloseHandle | ||
| api-ms-win-eventing-provider-l1-1-0.dll | 3 | EventRegister | |
| api-ms-win-eventing-provider-l1-1-0.dll | 4 | EventSetInformation | |
| api-ms-win-eventing-provider-l1-1-0.dll | 9 | EventWriteTransfer | |
| api-ms-win-crt-utility-l1-1-0.dll | 17 | bsearch_s | |
| api-ms-win-core-sidebyside-l1-1-0.dll | ActivateActCtx | ||
| api-ms-win-core-sidebyside-l1-1-0.dll | 3 | DeactivateActCtx | |
| api-ms-win-core-sidebyside-l1-1-0.dll | 9 | ReleaseActCtx | |
| api-ms-win-core-sidebyside-l1-1-0.dll | 2 | CreateActCtxW | |
| api-ms-win-core-threadpool-private-l1-1-0.dll | RegisterWaitForSingleObjectEx | ||
| ntdll.dll | 1317 | RtlQueryHeapInformation | |
| ntdll.dll | 1682 | TpAllocTimer | |
| ntdll.dll | 2301 | _vsnwprintf | |
| ntdll.dll | 57 | EtwEventEnabled | |
| ntdll.dll | 1714 | TpReleaseWait | |
| ntdll.dll | 1278 | RtlNtStatusToDosErrorNoTeb | |
| ntdll.dll | 1727 | TpSetWait | |
| ntdll.dll | 1683 | TpAllocWait | |
| ntdll.dll | 59 | EtwEventRegister | |
| ntdll.dll | 1521 | RtlUnhandledExceptionFilter | |
| ntdll.dll | 583 | NtSetInformationProcess | |
| ntdll.dll | 1446 | RtlSetProcessIsCritical | |
| ntdll.dll | 1726 | TpSetTimerEx | |
| ntdll.dll | 1725 | TpSetTimer | |
| ntdll.dll | 1114 | RtlImageNtHeader | |
| ntdll.dll | 1568 | RtlValidSecurityDescriptor | |
| ntdll.dll | 504 | NtQuerySystemInformation | |
| ntdll.dll | 1408 | RtlRunOnceExecuteOnce | |
| ntdll.dll | 1277 | RtlNtStatusToDosError | |
| ntdll.dll | 1013 | RtlFreeHeap | |
| ntdll.dll | 62 | EtwEventWrite | |
| ntdll.dll | 1713 | TpReleaseTimer | |
| ntdll.dll | 1143 | RtlInitializeCriticalSection | |
| ntdll.dll | 1156 | RtlInitializeSid | |
| ntdll.dll | 1488 | RtlSubAuthoritySid | |
| ntdll.dll | 1044 | RtlGetDeviceFamilyInfoEnum | |
| ntdll.dll | 1380 | RtlReleaseSRWLockExclusive | |
| ntdll.dll | 1487 | RtlSubAuthorityCountSid | |
| ntdll.dll | 684 | RtlAcquireSRWLockExclusive | |
| ntdll.dll | 1231 | RtlLengthRequiredSid | |
| ntdll.dll | 898 | RtlDeriveCapabilitySidsFromName | |
| ntdll.dll | 816 | RtlCopySid | |
| ntdll.dll | 1736 | TpWaitForTimer | |
| ntdll.dll | 722 | RtlAllocateHeap | |
| api-ms-win-core-heap-l2-1-0.dll | 2 | LocalAlloc | |
| api-ms-win-core-heap-l2-1-0.dll | 3 | LocalFree | |
| api-ms-win-core-delayload-l1-1-1.dll | 1 | ResolveDelayLoadedAPI | |
| api-ms-win-core-delayload-l1-1-0.dll | DelayLoadFailureHook |
StringTable 040904B0
| CompanyName | Microsoft Corporation |
| FileDescription | Host Process for Windows Services |
| FileVersion | 10.0.19041.1 (WinBuild.160101.0800) |
| InternalName | svchost.exe |
| LegalCopyright | © Microsoft Corporation. All rights reserved. |
| OriginalFilename | svchost.exe |
| ProductName | Microsoft® Windows® Operating System |
| ProductVersion | 10.0.19041.1 |
VS_FIXEDFILEINFO
| FileVersion | 10.0.19041.1 |
| ProductVersion | 10.0.19041.1 |
| StrucVersion | 0x10000 |
| FileFlagsMask | 0x3f |
| FileFlags | 0 |
| FileOS | 0x40004 |
| FileType | 1 |
| FileSubtype | 0 |
Signers (1)
issuer: /C=US/ST=Washington/L=Redmond/O=Microsoft Corporation/CN=Microsoft Windows Production PCA 2011
serial: 33000002176A92089823FB0577000000000217
Certificates (2)
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
33:00:00:02:17:6a:92:08:98:23:fb:05:77:00:00:00:00:02:17
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
Validity
Not Before: Mar 27 19:21:25 2019 GMT
Not After : Mar 27 19:21:25 2020 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Publisher
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:c9:5d:93:ba:f7:b1:e9:7e:98:96:b4:51:cb:15:
14:36:f1:6e:e0:ca:e1:78:3b:b5:be:ee:27:6d:e1:
a3:5e:68:a1:ee:ba:2c:e5:ff:0b:04:a3:5d:88:9c:
4c:bc:68:47:f7:6f:e0:5f:1b:a5:f9:43:5e:d2:2a:
ad:36:09:2d:bc:6e:56:69:86:e4:b4:ec:27:c2:e4:
30:e5:93:d3:39:3d:57:bd:aa:d0:bb:50:a5:a9:ee:
43:53:93:92:35:7c:d3:f9:5e:1e:52:5e:86:f4:d5:
f6:03:29:9b:5b:0c:c3:10:3f:2d:16:88:e1:38:ef:
c3:31:20:da:7b:e0:c4:ee:72:f6:d8:7e:b5:fb:a7:
24:b2:0e:6d:38:82:00:d6:e2:17:17:55:f3:52:a9:
cc:fa:ac:9a:2b:0e:96:25:0d:22:e3:26:b9:b5:8b:
d7:72:1f:ce:85:f8:aa:b1:05:51:3d:4a:85:96:62:
19:60:9d:a8:6a:42:46:f3:ab:93:25:6f:c6:12:97:
10:c7:36:6e:e9:38:68:42:63:74:b2:46:06:a8:14:
eb:36:2b:69:53:22:53:be:b7:95:56:eb:1f:6d:d7:
73:5d:22:e0:b7:47:14:16:c6:10:b2:d7:f6:ed:29:
8f:9b:5d:59:63:9b:42:cf:38:e7:13:fd:e3:7a:90:
5b:8d
Exponent: 65537 (0x10001)
X509v3 extensions:
X509v3 Extended Key Usage:
1.3.6.1.4.1.311.10.3.22, 1.3.6.1.4.1.311.10.3.6, Code Signing
X509v3 Subject Key Identifier:
A3:B6:48:40:93:4F:03:75:F7:A9:9E:6C:AD:92:9A:54:EC:68:81:A6
X509v3 Subject Alternative Name:
DirName:/OU=Microsoft Ireland Operations Limited/serialNumber=230280\+453449
X509v3 Authority Key Identifier:
A9:29:02:39:8E:16:C4:97:78:CD:90:F9:9E:4F:9A:E1:7C:55:AF:53
X509v3 CRL Distribution Points:
Full Name:
URI:http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pkiops/certs/MicWinProPCA2011_2011-10-19.crt
X509v3 Basic Constraints: critical
CA:FALSE
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
b9:1c:34:f9:57:3b:4b:dc:25:fd:78:42:26:e4:d4:6b:c2:d3:
1a:63:ad:31:63:63:ff:a0:82:75:0d:e0:17:22:75:05:a9:54:
6a:76:d2:4d:1e:19:50:9d:f6:5a:c2:6b:7c:c5:22:a8:0b:c6:
45:bc:35:c8:c4:7f:fd:88:37:73:e6:2e:36:22:fd:98:b4:32:
48:c9:4a:df:d0:8c:fb:64:23:b1:f7:a4:c3:eb:a6:1f:7b:4d:
eb:0a:f4:a7:23:f9:c2:f4:a0:fb:4d:5d:73:56:2d:88:31:47:
61:6e:3d:86:d8:12:ec:d8:b7:44:49:7a:45:e9:cb:c0:59:66:
74:00:84:f1:5f:c9:e8:11:48:06:70:79:4c:ec:1e:19:76:b9:
94:c0:a2:76:05:30:2a:68:3b:56:e5:71:32:f8:1d:ba:6a:c4:
b5:10:69:1b:1c:be:3e:d2:92:55:14:77:de:c1:59:5b:40:30:
c9:16:b8:99:4f:1f:46:65:2d:34:ee:0f:04:6a:18:79:8c:53:
f1:33:0e:d1:70:93:e2:e1:af:d2:d8:cf:fe:d5:25:26:e6:dd:
6e:ab:f6:f3:89:6a:00:4d:17:19:64:27:81:14:eb:33:11:72:
05:13:e5:7f:4d:16:d2:f7:4a:69:12:ab:11:58:87:51:33:75:
73:7c:2a:89
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
61:07:76:56:00:00:00:00:00:08
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Root Certificate Authority 2010
Validity
Not Before: Oct 19 18:41:42 2011 GMT
Not After : Oct 19 18:51:42 2026 GMT
Subject: C=US, ST=Washington, L=Redmond, O=Microsoft Corporation, CN=Microsoft Windows Production PCA 2011
Subject Public Key Info:
Public Key Algorithm: rsaEncryption
Public-Key: (2048 bit)
Modulus:
00:dd:0c:bb:a2:e4:2e:09:e3:e7:c5:f7:96:69:bc:
00:21:bd:69:33:33:ef:ad:04:cb:54:80:ee:06:83:
bb:c5:20:84:d9:f7:d2:8b:f3:38:b0:ab:a4:ad:2d:
7c:62:79:05:ff:e3:4a:3f:04:35:20:70:e3:c4:e7:
6b:e0:9c:c0:36:75:e9:8a:31:dd:8d:70:e5:dc:37:
b5:74:46:96:28:5b:87:60:23:2c:bf:dc:47:a5:67:
f7:51:27:9e:72:eb:07:a6:c9:b9:1e:3b:53:35:7c:
e5:d3:ec:27:b9:87:1c:fe:b9:c9:23:09:6f:a8:46:
91:c1:6e:96:3c:41:d3:cb:a3:3f:5d:02:6a:4d:ec:
69:1f:25:28:5c:36:ff:fd:43:15:0a:94:e0:19:b4:
cf:df:c2:12:e2:c2:5b:27:ee:27:78:30:8b:5b:2a:
09:6b:22:89:53:60:16:2c:c0:68:1d:53:ba:ec:49:
f3:9d:61:8c:85:68:09:73:44:5d:7d:a2:54:2b:dd:
79:f7:15:cf:35:5d:6c:1c:2b:5c:ce:bc:9c:23:8b:
6f:6e:b5:26:d9:36:13:c3:4f:d6:27:ae:b9:32:3b:
41:92:2c:e1:c7:cd:77:e8:aa:54:4e:f7:5c:0b:04:
87:65:b4:43:18:a8:b2:e0:6d:19:77:ec:5a:24:fa:
48:03
Exponent: 65537 (0x10001)
X509v3 extensions:
1.3.6.1.4.1.311.21.1:
...
X509v3 Subject Key Identifier:
A9:29:02:39:8E:16:C4:97:78:CD:90:F9:9E:4F:9A:E1:7C:55:AF:53
1.3.6.1.4.1.311.20.2:
.
.S.u.b.C.A
X509v3 Key Usage:
Digital Signature, Certificate Sign, CRL Sign
X509v3 Basic Constraints: critical
CA:TRUE
X509v3 Authority Key Identifier:
D5:F6:56:CB:8F:E8:A2:5C:62:68:D1:3D:94:90:5B:D7:CE:9A:18:C4
X509v3 CRL Distribution Points:
Full Name:
URI:http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
Authority Information Access:
CA Issuers - URI:http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt
Signature Algorithm: sha256WithRSAEncryption
Signature Value:
14:fc:7c:71:51:a5:79:c2:6e:b2:ef:39:3e:bc:3c:52:0f:6e:
2b:3f:10:13:73:fe:a8:68:d0:48:a6:34:4d:8a:96:05:26:ee:
31:46:90:61:79:d6:ff:38:2e:45:6b:f4:c0:e5:28:b8:da:1d:
8f:8a:db:09:d7:1a:c7:4c:0a:36:66:6a:8c:ec:1b:d7:04:90:
a8:18:17:a4:9b:b9:e2:40:32:36:76:c4:c1:5a:c6:bf:e4:04:
c0:ea:16:d3:ac:c3:68:ef:62:ac:dd:54:6c:50:30:58:a6:eb:
7c:fe:94:a7:4e:8e:f4:ec:7c:86:73:57:c2:52:21:73:34:5a:
f3:a3:8a:56:c8:04:da:07:09:ed:f8:8b:e3:ce:f4:7e:8e:ae:
f0:f6:0b:8a:08:fb:3f:c9:1d:72:7f:53:b8:eb:be:63:e0:e3:
3d:31:65:b0:81:e5:f2:ac:cd:16:a4:9f:3d:a8:b1:9b:c2:42:
d0:90:84:5f:54:1d:ff:89:ea:ba:1d:47:90:6f:b0:73:4e:41:
9f:40:9f:5f:e5:a1:2a:b2:11:91:73:8a:21:28:f0:ce:de:73:
39:5f:3e:ab:5c:60:ec:df:03:10:a8:d3:09:e9:f4:f6:96:85:
b6:7f:51:88:66:47:19:8d:a2:b0:12:3d:81:2a:68:05:77:bb:
91:4c:62:7b:b6:c1:07:c7:ba:7a:87:34:03:0e:4b:62:7a:99:
e9:ca:fc:ce:4a:37:c9:2d:a4:57:7c:1c:fe:3d:dc:b8:0f:5a:
fa:d6:c4:b3:02:85:02:3a:ea:b3:d9:6e:e4:69:21:37:de:81:
d1:f6:75:19:05:67:d3:93:57:5e:29:1b:39:c8:ee:2d:e1:cd:
e4:45:73:5b:d0:d2:ce:7a:ab:16:19:82:46:58:d0:5e:9d:81:
b3:67:af:6c:35:f2:bc:e5:3f:24:e2:35:a2:0a:75:06:f6:18:
56:99:d4:78:2c:d1:05:1b:eb:d0:88:01:9d:aa:10:f1:05:df:
ba:7e:2c:63:b7:06:9b:23:21:c4:f9:78:6c:e2:58:17:06:36:
2b:91:12:03:cc:a4:d9:f2:2d:ba:f9:94:9d:40:ed:18:45:f1:
ce:8a:5c:6b:3e:ab:03:d3:70:18:2a:0a:6a:e0:5f:47:d1:d5:
63:0a:32:f2:af:d7:36:1f:2a:70:5a:e5:42:59:08:71:4b:57:
ba:7e:83:81:f0:21:3c:f4:1c:c1:c5:b9:90:93:0e:88:45:93:
86:e9:b1:20:99:be:98:cb:c5:95:a4:5d:62:d6:a0:63:08:20:
bd:75:10:77:7d:3d:f3:45:b9:9f:97:9f:cb:57:80:6f:33:a9:
04:cf:77:a4:62:1c:59:7e
undefined method `first' for #
![]() |
| Please donate some bucks to keep this site up and running: | |
| Ko-fi | |
|---|---|
| Yandex.Money | |
| Thank you! | |
everything is OK
offset:( 0x )