File name:

New Text Document.bin.exe

Full analysis: https://app.any.run/tasks/d0dc19a2-2503-4402-880f-f95987cf1be5
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: May 20, 2024, 00:16:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
loader
amadey
botnet
stealer
telegram
hausbomber
phemedrone
exfiltration
gcleaner
vidar
risepro
evasion
formbook
xloader
phorpiex
trojan
rat
avemaria
miner
phishing
greatness
redline
meta
metastealer
stealc
remote
gh0st
ransomware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0B0D247AA1F24C2F5867B3BF29F69450

SHA1:

48DE9F34226FD7F637E2379365BE035AF5C0DF1A

SHA256:

A6E7292E734C3A15CFA654BBA8DEA72A2F55F1C24CF6BBDC2FD7E63887E9315A

SSDEEP:

12288:dcgCzNHJj96xfKJStJkRm3bYXob0AnmFMcaGQxkZVVVVVVVVVAtVVVUvqGV:UQKgLIQmFuGQxklvqO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • New Text Document.bin.exe (PID: 3976)
      • New Text Document.exe (PID: 2028)
      • random.exe (PID: 764)
      • conhost.exe (PID: 1008)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 2760)
      • csrss.exe (PID: 1344)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 2668)
      • gena.exe (PID: 2384)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 660)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3156)
      • conhost.exe (PID: 1848)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 1248)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 3280)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5428)
      • WinSec.exe (PID: 5480)
      • cmd.exe (PID: 4316)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5892)
      • tdrpload.exe (PID: 5860)
      • New Text Document.exe (PID: 5816)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6888)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 8324)
      • Discord.exe (PID: 9276)
      • e_win.exe (PID: 10176)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 8748)
      • yar.exe (PID: 10264)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • 2237331016.exe (PID: 13200)
      • New Text Document.exe (PID: 10516)
      • setup_1715277229.6072824.exe (PID: 14732)
      • 290929157.exe (PID: 15188)
      • pei.exe (PID: 12860)
      • taskmgr.exe (PID: 11764)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6660)
    • AMADEY has been detected (SURICATA)

      • axplons.exe (PID: 1640)
      • explorku.exe (PID: 2300)
    • Connects to the CnC server

      • axplons.exe (PID: 1640)
      • explorku.exe (PID: 2300)
      • sysblardsv.exe (PID: 6584)
    • HAUSBOMBER has been detected (YARA)

      • New Text Document.exe (PID: 2028)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 5512)
    • Steals credentials

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
    • PHEMEDRONE has been detected (YARA)

      • build13.exe (PID: 2532)
    • Steals credentials from Web Browsers

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
    • Starts CMD.EXE for self-deleting

      • inte.exe (PID: 2748)
      • inte.exe (PID: 4224)
      • inte.exe (PID: 5296)
      • inte.exe (PID: 5300)
      • inte.exe (PID: 7364)
      • univ.exe (PID: 9960)
      • inte.exe (PID: 9316)
    • Uses Task Scheduler to autorun other applications

      • gena.exe (PID: 2384)
    • GCLEANER has been detected (SURICATA)

      • inte.exe (PID: 2748)
      • inte.exe (PID: 4224)
      • inte.exe (PID: 5296)
      • inte.exe (PID: 5300)
      • inte.exe (PID: 7364)
      • univ.exe (PID: 9960)
      • inte.exe (PID: 9316)
    • Changes the autorun value in the registry

      • gena.exe (PID: 2384)
      • explorku.exe (PID: 2300)
      • tdrpload.exe (PID: 5860)
      • system.exe (PID: 7080)
    • VIDAR has been detected (YARA)

      • katD41B.tmp (PID: 2768)
      • csrss.exe (PID: 1344)
      • katDF27.tmp (PID: 2828)
      • kat860.tmp (PID: 3616)
      • kat8FC.tmp (PID: 3048)
      • csrss.exe (PID: 2664)
      • kat37BD.tmp (PID: 1756)
    • RISEPRO has been detected (SURICATA)

      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
    • Create files in the Startup directory

      • gena.exe (PID: 2384)
      • WinSec.exe (PID: 5480)
      • system.exe (PID: 7080)
    • AMADEY has been detected (YARA)

      • axplons.exe (PID: 1640)
      • explorku.exe (PID: 2300)
    • FORMBOOK has been detected (YARA)

      • svchost.exe (PID: 2320)
    • RISEPRO has been detected (YARA)

      • gena.exe (PID: 2384)
    • Actions looks like stealing of personal data

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7636)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 7060)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 8888)
    • Avemaria is detected

      • WinSec.exe (PID: 5480)
    • Runs injected code in another process

      • WinSec.exe (PID: 5480)
      • WinSec.exe (PID: 7876)
    • Application was injected by another process

      • explorer.exe (PID: 1180)
    • The process bypass UAC

      • Dism.exe (PID: 7756)
    • Changes Security Center notification settings

      • sysblardsv.exe (PID: 6584)
    • Changes appearance of the Explorer extensions

      • sysblardsv.exe (PID: 6584)
    • Changes the Windows auto-update feature

      • sysblardsv.exe (PID: 6584)
    • Adds path to the Windows Defender exclusion list

      • WinSec.exe (PID: 7876)
    • Renames files like ransomware

      • e_win.exe (PID: 10176)
    • STEALC has been detected (YARA)

      • swizzz.exe (PID: 5100)
  • SUSPICIOUS

    • Reads the Internet Settings

      • New Text Document.bin.exe (PID: 3976)
      • New Text Document.exe (PID: 2028)
      • random.exe (PID: 764)
      • csrss.exe (PID: 1344)
      • axplons.exe (PID: 1640)
      • conhost.exe (PID: 1008)
      • cmd.exe (PID: 1128)
      • inte.exe (PID: 2748)
      • cmd.exe (PID: 2824)
      • gena.exe (PID: 2384)
      • e6QwXb7lvZSU_XownH06.exe (PID: 3932)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • conhost.exe (PID: 1848)
      • cmd.exe (PID: 3548)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 4152)
      • inte.exe (PID: 4224)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • inte.exe (PID: 5296)
      • New Text Document.exe (PID: 5428)
      • powershell.exe (PID: 4992)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • powershell.exe (PID: 5660)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 5152)
      • inte.exe (PID: 5300)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6392)
      • cmd.exe (PID: 4316)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6768)
      • ReurgingGleek.exe (PID: 5944)
      • test.exe (PID: 6812)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7060)
      • cmt.exe (PID: 7284)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 7768)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 5864)
      • inte.exe (PID: 7364)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 7912)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8236)
      • powershell.exe (PID: 6876)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • sysblardsv.exe (PID: 6584)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 10028)
      • e_win.exe (PID: 10176)
      • f.exe (PID: 5480)
      • New Text Document.exe (PID: 5508)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 8260)
      • msfiler.exe (PID: 8540)
      • New Text Document.exe (PID: 8612)
      • inte.exe (PID: 9316)
      • univ.exe (PID: 9960)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 11072)
      • yar.exe (PID: 10264)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11144)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 11236)
      • New Text Document.exe (PID: 11460)
      • New Text Document.exe (PID: 11504)
      • New Text Document.exe (PID: 11400)
    • Reads Microsoft Outlook installation path

      • New Text Document.bin.exe (PID: 3976)
    • Reads security settings of Internet Explorer

      • New Text Document.bin.exe (PID: 3976)
      • New Text Document.exe (PID: 2028)
      • random.exe (PID: 764)
      • axplons.exe (PID: 1640)
      • csrss.exe (PID: 1344)
      • conhost.exe (PID: 1008)
      • inte.exe (PID: 2748)
      • gena.exe (PID: 2384)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • conhost.exe (PID: 1848)
      • New Text Document.exe (PID: 3280)
      • inte.exe (PID: 4224)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 3408)
      • inte.exe (PID: 5296)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 5280)
      • inte.exe (PID: 5300)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 6128)
      • inte.exe (PID: 7364)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 6148)
      • sysblardsv.exe (PID: 6584)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 6888)
      • e_win.exe (PID: 10176)
      • New Text Document.exe (PID: 6768)
      • f.exe (PID: 5480)
      • New Text Document.exe (PID: 5152)
      • msfiler.exe (PID: 8540)
      • New Text Document.exe (PID: 7060)
      • inte.exe (PID: 9316)
      • univ.exe (PID: 9960)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 8324)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9304)
    • Reads Internet Explorer settings

      • New Text Document.bin.exe (PID: 3976)
    • Executable content was dropped or overwritten

      • New Text Document.bin.exe (PID: 3976)
      • New Text Document.exe (PID: 2028)
      • random.exe (PID: 764)
      • conhost.exe (PID: 1008)
      • csrss.exe (PID: 1344)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 2760)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 2668)
      • gena.exe (PID: 2384)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 660)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3156)
      • conhost.exe (PID: 1848)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 1248)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 3280)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5428)
      • WinSec.exe (PID: 5480)
      • cmd.exe (PID: 4316)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5892)
      • tdrpload.exe (PID: 5860)
      • dllhost.exe (PID: 6488)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 3408)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 6704)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 8324)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 8748)
      • explorer.exe (PID: 1180)
      • yar.exe (PID: 10264)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 10516)
      • 2237331016.exe (PID: 13200)
      • setup_1715277229.6072824.exe (PID: 14732)
      • 290929157.exe (PID: 15188)
      • pei.exe (PID: 12860)
      • taskmgr.exe (PID: 11764)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6660)
    • Reads the BIOS version

      • random.exe (PID: 764)
      • axplons.exe (PID: 1640)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • amers.exe (PID: 560)
      • 8c3edaadfe.exe (PID: 1236)
      • 2c6b69e198.exe (PID: 1028)
      • random.exe (PID: 3148)
      • random.exe (PID: 304)
    • Process requests binary or script from the Internet

      • New Text Document.exe (PID: 2028)
      • csrss.exe (PID: 1344)
      • explorku.exe (PID: 2300)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6348)
    • Connects to the server without a host name

      • New Text Document.exe (PID: 2028)
      • axplons.exe (PID: 1640)
      • csrss.exe (PID: 1344)
      • inte.exe (PID: 2748)
      • explorku.exe (PID: 2300)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 6348)
    • Potential Corporate Privacy Violation

      • New Text Document.exe (PID: 2028)
      • gena.exe (PID: 2384)
      • explorku.exe (PID: 2300)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 7060)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 8012)
    • Starts itself from another location

      • random.exe (PID: 764)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • tdrpload.exe (PID: 5860)
      • 2237331016.exe (PID: 13200)
      • 290929157.exe (PID: 15188)
    • The process creates files with name similar to system file names

      • New Text Document.exe (PID: 2028)
      • New Text Document.exe (PID: 5816)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 5784)
      • system.exe (PID: 7080)
    • Contacting a server suspected of hosting an CnC

      • axplons.exe (PID: 1640)
      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • explorku.exe (PID: 2300)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
    • Reads settings of System Certificates

      • csrss.exe (PID: 1344)
      • New Text Document.exe (PID: 2028)
      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 4376)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 7060)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 8612)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
    • Checks Windows Trust Settings

      • csrss.exe (PID: 1344)
      • vpn-1002.exe (PID: 4488)
    • Drops 7-zip archiver for unpacking

      • conhost.exe (PID: 1008)
      • conhost.exe (PID: 1848)
    • Executing commands from a ".bat" file

      • conhost.exe (PID: 1008)
      • conhost.exe (PID: 1848)
      • vpn-1002.exe (PID: 4488)
      • av_downloader.exe (PID: 14824)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 1128)
      • cmd.exe (PID: 3548)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • csrss.exe (PID: 1344)
      • system.exe (PID: 7080)
    • Searches for installed software

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
    • Starts CMD.EXE for commands execution

      • conhost.exe (PID: 1008)
      • inte.exe (PID: 2748)
      • csrss.exe (PID: 1344)
      • conhost.exe (PID: 1848)
      • inte.exe (PID: 4224)
      • vpn-1002.exe (PID: 4488)
      • inte.exe (PID: 5296)
      • WinSec.exe (PID: 5480)
      • inte.exe (PID: 5300)
      • inte.exe (PID: 7364)
      • inte.exe (PID: 9316)
      • univ.exe (PID: 9960)
      • av_downloader.exe (PID: 14824)
    • Process drops legitimate windows executable

      • New Text Document.exe (PID: 2028)
      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
      • explorku.exe (PID: 2300)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 7368)
      • taskmgr.exe (PID: 11764)
    • Starts a Microsoft application from unusual location

      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • taskmgr.exe (PID: 11764)
      • smss.exe (PID: 13680)
      • smss.exe (PID: 21068)
    • The process drops Mozilla's DLL files

      • csrss.exe (PID: 1344)
    • Starts application with an unusual extension

      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 2760)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 2668)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 660)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3156)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 1248)
    • The process drops C-runtime libraries

      • csrss.exe (PID: 1344)
    • Reads browser cookies

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2960)
      • cmd.exe (PID: 4784)
      • cmd.exe (PID: 5720)
      • cmd.exe (PID: 6660)
      • cmd.exe (PID: 8524)
      • cmd.exe (PID: 10972)
      • cmd.exe (PID: 10876)
    • Connects to unusual port

      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • WinSec.exe (PID: 5480)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5428)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 6768)
      • WinSec.exe (PID: 7876)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 5784)
      • system.exe (PID: 7080)
    • Checks for external IP

      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • system.exe (PID: 7080)
      • Discord.exe (PID: 9276)
    • Device Retrieving External IP Address Detected

      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • system.exe (PID: 7080)
      • Discord.exe (PID: 9276)
    • Accesses Microsoft Outlook profiles

      • gena.exe (PID: 2384)
    • Application launched itself

      • explorku.exe (PID: 2300)
      • smss.exe (PID: 13680)
    • Opens a file (MACROS)

      • EXCEL.EXE (PID: 2204)
    • Reads data from a file (MACROS)

      • EXCEL.EXE (PID: 2204)
    • Probably download files using WebClient

      • cmd.exe (PID: 4948)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 4948)
      • WinSec.exe (PID: 7876)
    • Detected use of alternative data streams (AltDS)

      • WinSec.exe (PID: 5480)
    • The process checks if it is being run in the virtual environment

      • New Text Document.exe (PID: 5816)
    • Script adds exclusion path to Windows Defender

      • WinSec.exe (PID: 7876)
    • Using PowerShell to operate with local accounts

      • powershell.exe (PID: 6876)
    • The Powershell connects to the Internet

      • powershell.exe (PID: 4992)
      • powershell.exe (PID: 5660)
    • Unusual connection from system programs

      • powershell.exe (PID: 4992)
      • powershell.exe (PID: 5660)
    • Creates files like ransomware instruction

      • e_win.exe (PID: 10176)
    • Contacting a server suspected of hosting an Exploit Kit

      • New Text Document.exe (PID: 3780)
    • The process executes via Task Scheduler

      • taskmgr.exe (PID: 12768)
    • Crypto Currency Mining Activity Detected

      • New Text Document.exe (PID: 10028)
  • INFO

    • Reads the computer name

      • New Text Document.bin.exe (PID: 3976)
      • New Text Document.exe (PID: 2028)
      • wmpnscfg.exe (PID: 552)
      • random.exe (PID: 764)
      • axplons.exe (PID: 1640)
      • csrss.exe (PID: 1344)
      • conhost.exe (PID: 1008)
      • gena.exe (PID: 2384)
      • katD41B.tmp (PID: 2768)
      • inte.exe (PID: 2748)
      • katDF27.tmp (PID: 2828)
      • e6QwXb7lvZSU_XownH06.exe (PID: 3932)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • 8c3edaadfe.exe (PID: 1236)
      • csrss.exe (PID: 2664)
      • gena.exe (PID: 2680)
      • kat860.tmp (PID: 3616)
      • kat8FC.tmp (PID: 3048)
      • conhost.exe (PID: 1848)
      • kat37BD.tmp (PID: 1756)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 4152)
      • inte.exe (PID: 4224)
      • New Text Document.exe (PID: 4376)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • inte.exe (PID: 5296)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • WinSec.exe (PID: 5480)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • inte.exe (PID: 5300)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6528)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 6392)
      • test.exe (PID: 6812)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 6888)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 7060)
      • cmt.exe (PID: 7284)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 7768)
      • WinSec.exe (PID: 7876)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 7724)
      • inte.exe (PID: 7364)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9076)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • sysblardsv.exe (PID: 6584)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • univ.exe (PID: 9960)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 10108)
      • msfiler.exe (PID: 8540)
      • f.exe (PID: 5480)
      • e_win.exe (PID: 10176)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 8612)
      • inte.exe (PID: 9316)
      • WinSec.exe (PID: 7744)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10596)
      • yar.exe (PID: 10264)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 11072)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 11144)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 11460)
      • taskmgr.exe (PID: 11764)
      • New Text Document.exe (PID: 11400)
      • New Text Document.exe (PID: 11504)
      • WinSec.exe (PID: 11956)
      • New Text Document.exe (PID: 11236)
      • my.exe (PID: 11872)
      • New Text Document.exe (PID: 11604)
      • New Text Document.exe (PID: 11716)
      • New Text Document.exe (PID: 11892)
      • New Text Document.exe (PID: 11784)
      • New Text Document.exe (PID: 12132)
      • New Text Document.exe (PID: 12052)
      • New Text Document.exe (PID: 11988)
      • New Text Document.exe (PID: 12224)
      • installer.exe (PID: 11996)
      • New Text Document.exe (PID: 10904)
      • New Text Document.exe (PID: 12152)
      • New Text Document.exe (PID: 10676)
      • New Text Document.exe (PID: 6492)
      • New Text Document.exe (PID: 11248)
      • New Text Document.exe (PID: 4356)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 1180)
    • Checks proxy server information

      • New Text Document.bin.exe (PID: 3976)
      • axplons.exe (PID: 1640)
      • csrss.exe (PID: 1344)
      • inte.exe (PID: 2748)
      • gena.exe (PID: 2384)
      • explorku.exe (PID: 2300)
      • inte.exe (PID: 4224)
      • vpn-1002.exe (PID: 4488)
      • inte.exe (PID: 5296)
      • inte.exe (PID: 5300)
      • inte.exe (PID: 7364)
      • sysblardsv.exe (PID: 6584)
      • inte.exe (PID: 9316)
      • univ.exe (PID: 9960)
    • Checks supported languages

      • New Text Document.bin.exe (PID: 3976)
      • New Text Document.exe (PID: 2028)
      • wmpnscfg.exe (PID: 552)
      • random.exe (PID: 764)
      • 1234.exe (PID: 1988)
      • Document0984757478.exe (PID: 2336)
      • axplons.exe (PID: 1640)
      • build13.exe (PID: 2532)
      • conhost.exe (PID: 1008)
      • csrss.exe (PID: 1344)
      • mode.com (PID: 2560)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 2760)
      • gena.exe (PID: 2384)
      • katD41B.tmp (PID: 2768)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 2668)
      • inte.exe (PID: 2748)
      • katDF27.tmp (PID: 2828)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • e6QwXb7lvZSU_XownH06.exe (PID: 3932)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • amers.exe (PID: 560)
      • 8c3edaadfe.exe (PID: 1236)
      • 2c6b69e198.exe (PID: 1028)
      • conhost.exe (PID: 1848)
      • csrss.exe (PID: 2664)
      • build13.exe (PID: 2724)
      • Document0984757478.exe (PID: 1280)
      • random.exe (PID: 3148)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 660)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3156)
      • gena.exe (PID: 2680)
      • kat860.tmp (PID: 3616)
      • kat8FC.tmp (PID: 3048)
      • mode.com (PID: 3844)
      • random.exe (PID: 304)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 1248)
      • kat37BD.tmp (PID: 1756)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 3408)
      • inte.exe (PID: 4224)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 4376)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • swizzz.exe (PID: 5100)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 5032)
      • inte.exe (PID: 5296)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • WinSec.exe (PID: 5480)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • tdrpload.exe (PID: 5860)
      • New Text Document.exe (PID: 5892)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • swizzzz.exe (PID: 4244)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5680)
      • inte.exe (PID: 5300)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6528)
      • sysblardsv.exe (PID: 6584)
      • New Text Document.exe (PID: 6704)
      • test.exe (PID: 6812)
      • lumma0805.exe (PID: 6836)
      • New Text Document.exe (PID: 6888)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 6768)
      • cmt.exe (PID: 7284)
      • New Text Document.exe (PID: 7060)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 7368)
      • nc.exe (PID: 7332)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 7768)
      • WinSec.exe (PID: 7876)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 5864)
      • inte.exe (PID: 7364)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9076)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9860)
      • univ.exe (PID: 9960)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 10108)
      • msfiler.exe (PID: 8540)
      • f.exe (PID: 5480)
      • e_win.exe (PID: 10176)
      • New Text Document.exe (PID: 5508)
      • nine.exe (PID: 8672)
      • inte.exe (PID: 9316)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 8612)
      • WinSec.exe (PID: 7744)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10596)
      • yar.exe (PID: 10264)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 11072)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 11144)
      • taskmgr.exe (PID: 11764)
      • New Text Document.exe (PID: 11236)
      • New Text Document.exe (PID: 11400)
      • New Text Document.exe (PID: 11460)
      • New Text Document.exe (PID: 11504)
      • New Text Document.exe (PID: 11604)
      • my.exe (PID: 11872)
      • WinSec.exe (PID: 11956)
      • toolspub1.exe (PID: 12024)
      • installer.exe (PID: 11996)
      • New Text Document.exe (PID: 11716)
      • New Text Document.exe (PID: 11784)
      • New Text Document.exe (PID: 12052)
      • New Text Document.exe (PID: 11892)
      • New Text Document.exe (PID: 11988)
      • New Text Document.exe (PID: 12132)
      • New Text Document.exe (PID: 12224)
      • New Text Document.exe (PID: 12152)
      • New Text Document.exe (PID: 10904)
      • New Text Document.exe (PID: 11248)
      • taskmgr.exe (PID: 12768)
      • New Text Document.exe (PID: 10508)
      • New Text Document.exe (PID: 10676)
      • New Text Document.exe (PID: 4356)
      • New Text Document.exe (PID: 6492)
      • current.exe (PID: 12872)
      • pei.exe (PID: 12860)
      • New Text Document.exe (PID: 12336)
    • Reads the machine GUID from the registry

      • New Text Document.bin.exe (PID: 3976)
      • random.exe (PID: 764)
      • axplons.exe (PID: 1640)
      • csrss.exe (PID: 1344)
      • New Text Document.exe (PID: 2028)
      • inte.exe (PID: 2748)
      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 4376)
      • inte.exe (PID: 4224)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • inte.exe (PID: 5296)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5680)
      • inte.exe (PID: 5300)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6528)
      • ReurgingGleek.exe (PID: 5944)
      • New Text Document.exe (PID: 6704)
      • test.exe (PID: 6812)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 7060)
      • system.exe (PID: 7080)
      • cmt.exe (PID: 7284)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 7708)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 6660)
      • inte.exe (PID: 7364)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9192)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • sysblardsv.exe (PID: 6584)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10108)
      • e_win.exe (PID: 10176)
      • New Text Document.exe (PID: 5508)
      • msfiler.exe (PID: 8540)
      • f.exe (PID: 5480)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 8612)
      • inte.exe (PID: 9316)
      • univ.exe (PID: 9960)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10700)
      • yar.exe (PID: 10264)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 11072)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 11144)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 11236)
      • New Text Document.exe (PID: 11460)
      • New Text Document.exe (PID: 11504)
      • New Text Document.exe (PID: 11400)
      • New Text Document.exe (PID: 11604)
      • New Text Document.exe (PID: 11716)
      • taskmgr.exe (PID: 11764)
      • New Text Document.exe (PID: 11784)
      • my.exe (PID: 11872)
      • New Text Document.exe (PID: 11892)
      • New Text Document.exe (PID: 12224)
      • New Text Document.exe (PID: 12152)
      • New Text Document.exe (PID: 10904)
      • New Text Document.exe (PID: 11988)
      • New Text Document.exe (PID: 4356)
    • Manual execution by a user

      • New Text Document.exe (PID: 2028)
      • wmpnscfg.exe (PID: 552)
      • EXCEL.EXE (PID: 2204)
      • conhost.exe (PID: 1848)
      • build13.exe (PID: 2724)
      • Document0984757478.exe (PID: 1280)
      • csrss.exe (PID: 2664)
      • gena.exe (PID: 2680)
      • o2i3jroi23joj23ikrjokij3oroi.exe (PID: 660)
      • random.exe (PID: 3148)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 3156)
      • sdf34ert3etgrthrthfghfghjfgh.exe (PID: 1248)
      • random.exe (PID: 304)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7060)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 8612)
      • New Text Document.exe (PID: 7272)
      • WinSec.exe (PID: 7744)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11072)
      • New Text Document.exe (PID: 11144)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 11236)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 11400)
      • New Text Document.exe (PID: 11460)
      • New Text Document.exe (PID: 11504)
      • New Text Document.exe (PID: 11604)
      • New Text Document.exe (PID: 11716)
      • New Text Document.exe (PID: 11784)
      • New Text Document.exe (PID: 11892)
      • New Text Document.exe (PID: 11988)
      • WinSec.exe (PID: 11956)
      • New Text Document.exe (PID: 12132)
      • New Text Document.exe (PID: 12052)
      • New Text Document.exe (PID: 12152)
      • New Text Document.exe (PID: 12224)
      • New Text Document.exe (PID: 10904)
      • New Text Document.exe (PID: 11248)
      • New Text Document.exe (PID: 10508)
      • New Text Document.exe (PID: 6492)
      • New Text Document.exe (PID: 12336)
      • New Text Document.exe (PID: 12408)
      • New Text Document.exe (PID: 10676)
      • New Text Document.exe (PID: 4356)
      • New Text Document.exe (PID: 11032)
      • New Text Document.exe (PID: 12604)
      • New Text Document.exe (PID: 12444)
      • New Text Document.exe (PID: 12576)
      • New Text Document.exe (PID: 12780)
      • New Text Document.exe (PID: 12796)
      • New Text Document.exe (PID: 12844)
      • New Text Document.exe (PID: 12716)
      • New Text Document.exe (PID: 12952)
      • New Text Document.exe (PID: 12996)
      • New Text Document.exe (PID: 13036)
      • New Text Document.exe (PID: 13072)
      • New Text Document.exe (PID: 13148)
      • New Text Document.exe (PID: 13168)
      • New Text Document.exe (PID: 13188)
      • New Text Document.exe (PID: 13272)
      • New Text Document.exe (PID: 13224)
      • New Text Document.exe (PID: 13240)
      • New Text Document.exe (PID: 13104)
      • New Text Document.exe (PID: 13452)
      • New Text Document.exe (PID: 13352)
      • New Text Document.exe (PID: 13432)
      • New Text Document.exe (PID: 13368)
      • New Text Document.exe (PID: 13288)
      • New Text Document.exe (PID: 13300)
      • New Text Document.exe (PID: 13312)
      • New Text Document.exe (PID: 13340)
      • New Text Document.exe (PID: 13612)
      • New Text Document.exe (PID: 13648)
      • New Text Document.exe (PID: 13656)
      • New Text Document.exe (PID: 13640)
      • New Text Document.exe (PID: 13824)
      • New Text Document.exe (PID: 14060)
      • New Text Document.exe (PID: 14240)
      • New Text Document.exe (PID: 14504)
      • New Text Document.exe (PID: 14512)
      • New Text Document.exe (PID: 14756)
      • New Text Document.exe (PID: 14832)
      • New Text Document.exe (PID: 14840)
      • New Text Document.exe (PID: 13816)
      • New Text Document.exe (PID: 13928)
      • New Text Document.exe (PID: 14232)
      • New Text Document.exe (PID: 15056)
      • New Text Document.exe (PID: 15820)
      • New Text Document.exe (PID: 15272)
      • New Text Document.exe (PID: 15636)
      • New Text Document.exe (PID: 15712)
      • New Text Document.exe (PID: 15736)
      • New Text Document.exe (PID: 15744)
      • New Text Document.exe (PID: 15792)
      • New Text Document.exe (PID: 15800)
      • New Text Document.exe (PID: 15264)
      • New Text Document.exe (PID: 16188)
      • New Text Document.exe (PID: 16180)
      • New Text Document.exe (PID: 16260)
      • New Text Document.exe (PID: 16288)
      • New Text Document.exe (PID: 16312)
      • New Text Document.exe (PID: 16376)
      • New Text Document.exe (PID: 8416)
      • New Text Document.exe (PID: 1292)
      • New Text Document.exe (PID: 4720)
      • New Text Document.exe (PID: 10756)
      • New Text Document.exe (PID: 14620)
      • New Text Document.exe (PID: 4716)
      • New Text Document.exe (PID: 15964)
      • New Text Document.exe (PID: 16124)
      • New Text Document.exe (PID: 16168)
      • New Text Document.exe (PID: 16268)
      • New Text Document.exe (PID: 16296)
      • New Text Document.exe (PID: 2016)
      • New Text Document.exe (PID: 11060)
      • New Text Document.exe (PID: 15292)
      • New Text Document.exe (PID: 15708)
      • New Text Document.exe (PID: 15684)
      • New Text Document.exe (PID: 3036)
      • New Text Document.exe (PID: 13212)
      • New Text Document.exe (PID: 13636)
      • New Text Document.exe (PID: 16408)
      • New Text Document.exe (PID: 16400)
      • New Text Document.exe (PID: 14880)
      • New Text Document.exe (PID: 16388)
      • New Text Document.exe (PID: 16416)
      • New Text Document.exe (PID: 16428)
      • New Text Document.exe (PID: 14052)
      • New Text Document.exe (PID: 15132)
      • New Text Document.exe (PID: 16536)
      • New Text Document.exe (PID: 16548)
      • New Text Document.exe (PID: 16560)
      • New Text Document.exe (PID: 16576)
      • New Text Document.exe (PID: 16584)
      • New Text Document.exe (PID: 16784)
      • New Text Document.exe (PID: 16640)
      • New Text Document.exe (PID: 16608)
      • New Text Document.exe (PID: 16620)
      • New Text Document.exe (PID: 16656)
      • New Text Document.exe (PID: 16716)
      • New Text Document.exe (PID: 16776)
      • New Text Document.exe (PID: 16804)
      • New Text Document.exe (PID: 16944)
      • New Text Document.exe (PID: 16440)
      • New Text Document.exe (PID: 16476)
      • New Text Document.exe (PID: 16496)
      • New Text Document.exe (PID: 16516)
      • New Text Document.exe (PID: 16508)
      • New Text Document.exe (PID: 17340)
      • New Text Document.exe (PID: 17456)
      • New Text Document.exe (PID: 17928)
      • New Text Document.exe (PID: 17600)
      • New Text Document.exe (PID: 17780)
      • New Text Document.exe (PID: 17980)
      • New Text Document.exe (PID: 17188)
      • New Text Document.exe (PID: 18228)
      • New Text Document.exe (PID: 14376)
      • New Text Document.exe (PID: 16736)
      • New Text Document.exe (PID: 19456)
      • New Text Document.exe (PID: 18020)
      • New Text Document.exe (PID: 18028)
      • New Text Document.exe (PID: 20068)
      • New Text Document.exe (PID: 20432)
      • New Text Document.exe (PID: 20192)
      • New Text Document.exe (PID: 16532)
      • New Text Document.exe (PID: 17708)
      • New Text Document.exe (PID: 20692)
      • New Text Document.exe (PID: 20116)
      • New Text Document.exe (PID: 21572)
      • New Text Document.exe (PID: 21640)
      • New Text Document.exe (PID: 21720)
      • New Text Document.exe (PID: 21988)
      • New Text Document.exe (PID: 22124)
      • New Text Document.exe (PID: 22500)
      • New Text Document.exe (PID: 20608)
      • New Text Document.exe (PID: 17624)
      • New Text Document.exe (PID: 5624)
      • New Text Document.exe (PID: 10784)
      • New Text Document.exe (PID: 21140)
      • New Text Document.exe (PID: 4232)
      • New Text Document.exe (PID: 5556)
      • New Text Document.exe (PID: 15460)
      • New Text Document.exe (PID: 4548)
      • New Text Document.exe (PID: 14872)
    • Create files in a temporary directory

      • random.exe (PID: 764)
      • Document0984757478.exe (PID: 2336)
      • conhost.exe (PID: 1008)
      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • cy3oUmWRB6f5L5M8Ut6B.exe (PID: 2116)
      • explorku.exe (PID: 2300)
      • 8c3edaadfe.exe (PID: 1236)
      • Document0984757478.exe (PID: 1280)
      • conhost.exe (PID: 1848)
      • gena.exe (PID: 2680)
      • vpn-1002.exe (PID: 4488)
      • makecab.exe (PID: 7748)
      • sysblardsv.exe (PID: 6584)
    • Reads mouse settings

      • Document0984757478.exe (PID: 2336)
      • e6QwXb7lvZSU_XownH06.exe (PID: 3932)
      • Document0984757478.exe (PID: 1280)
    • Drops the executable file immediately after the start

      • explorer.exe (PID: 1180)
      • dllhost.exe (PID: 6488)
    • Creates files in the program directory

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
      • ReurgingGleek.exe (PID: 5944)
      • WinSec.exe (PID: 7876)
      • system.exe (PID: 7080)
    • Reads the software policy settings

      • csrss.exe (PID: 1344)
      • New Text Document.exe (PID: 2028)
      • gena.exe (PID: 2384)
      • OachQTPSMxWLVqpKFAB9.exe (PID: 3000)
      • 8c3edaadfe.exe (PID: 1236)
      • gena.exe (PID: 2680)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 4376)
      • vpn-1002.exe (PID: 4488)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7060)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 7912)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 8612)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
    • Creates files or folders in the user directory

      • csrss.exe (PID: 1344)
      • inte.exe (PID: 2748)
      • gena.exe (PID: 2384)
      • explorku.exe (PID: 2300)
      • vpn-1002.exe (PID: 4488)
      • inte.exe (PID: 4224)
      • inte.exe (PID: 5296)
      • WinSec.exe (PID: 5480)
      • inte.exe (PID: 5300)
      • inte.exe (PID: 7364)
      • system.exe (PID: 7080)
      • e_win.exe (PID: 10176)
      • univ.exe (PID: 9960)
      • Discord.exe (PID: 9276)
      • inte.exe (PID: 9316)
      • sysblardsv.exe (PID: 6584)
      • yar.exe (PID: 10264)
    • Reads product name

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
    • Reads CPU info

      • csrss.exe (PID: 1344)
      • gena.exe (PID: 2384)
    • Reads Environment values

      • csrss.exe (PID: 1344)
      • New Text Document.exe (PID: 2028)
      • gena.exe (PID: 2384)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 5428)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6528)
      • New Text Document.exe (PID: 6704)
      • test.exe (PID: 6812)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7060)
      • cmt.exe (PID: 7284)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7708)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 7884)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 7912)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10028)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 5508)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 8612)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 11072)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 11144)
      • New Text Document.exe (PID: 11504)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 11236)
      • New Text Document.exe (PID: 11400)
      • New Text Document.exe (PID: 11460)
      • New Text Document.exe (PID: 11604)
      • New Text Document.exe (PID: 11716)
      • New Text Document.exe (PID: 11784)
      • New Text Document.exe (PID: 11892)
      • New Text Document.exe (PID: 12224)
      • New Text Document.exe (PID: 10904)
      • New Text Document.exe (PID: 11988)
      • New Text Document.exe (PID: 12152)
      • New Text Document.exe (PID: 4356)
    • Disables trace logs

      • New Text Document.exe (PID: 2028)
      • New Text Document.exe (PID: 3280)
      • New Text Document.exe (PID: 1372)
      • New Text Document.exe (PID: 3780)
      • New Text Document.exe (PID: 3408)
      • New Text Document.exe (PID: 3096)
      • New Text Document.exe (PID: 4152)
      • New Text Document.exe (PID: 4376)
      • New Text Document.exe (PID: 4656)
      • New Text Document.exe (PID: 4576)
      • New Text Document.exe (PID: 4808)
      • New Text Document.exe (PID: 5032)
      • New Text Document.exe (PID: 5140)
      • New Text Document.exe (PID: 5428)
      • powershell.exe (PID: 4992)
      • New Text Document.exe (PID: 5280)
      • New Text Document.exe (PID: 5512)
      • New Text Document.exe (PID: 5580)
      • New Text Document.exe (PID: 5668)
      • New Text Document.exe (PID: 5816)
      • New Text Document.exe (PID: 5892)
      • New Text Document.exe (PID: 6036)
      • powershell.exe (PID: 5660)
      • New Text Document.exe (PID: 6128)
      • New Text Document.exe (PID: 4740)
      • New Text Document.exe (PID: 4972)
      • New Text Document.exe (PID: 5152)
      • New Text Document.exe (PID: 5680)
      • New Text Document.exe (PID: 5784)
      • New Text Document.exe (PID: 6240)
      • New Text Document.exe (PID: 6148)
      • New Text Document.exe (PID: 6348)
      • New Text Document.exe (PID: 6392)
      • New Text Document.exe (PID: 6528)
      • test.exe (PID: 6812)
      • New Text Document.exe (PID: 6704)
      • New Text Document.exe (PID: 6768)
      • New Text Document.exe (PID: 6888)
      • New Text Document.exe (PID: 7060)
      • cmt.exe (PID: 7284)
      • New Text Document.exe (PID: 7368)
      • New Text Document.exe (PID: 7432)
      • New Text Document.exe (PID: 7492)
      • New Text Document.exe (PID: 7636)
      • New Text Document.exe (PID: 7708)
      • New Text Document.exe (PID: 7768)
      • New Text Document.exe (PID: 7884)
      • build.exe (PID: 7144)
      • New Text Document.exe (PID: 8012)
      • New Text Document.exe (PID: 8188)
      • New Text Document.exe (PID: 8108)
      • New Text Document.exe (PID: 4472)
      • New Text Document.exe (PID: 4652)
      • New Text Document.exe (PID: 6724)
      • New Text Document.exe (PID: 5864)
      • New Text Document.exe (PID: 6660)
      • New Text Document.exe (PID: 7912)
      • system.exe (PID: 7080)
      • New Text Document.exe (PID: 7724)
      • New Text Document.exe (PID: 8236)
      • New Text Document.exe (PID: 8324)
      • New Text Document.exe (PID: 8428)
      • New Text Document.exe (PID: 8492)
      • New Text Document.exe (PID: 8636)
      • New Text Document.exe (PID: 8748)
      • New Text Document.exe (PID: 8824)
      • New Text Document.exe (PID: 8892)
      • New Text Document.exe (PID: 8964)
      • New Text Document.exe (PID: 9076)
      • New Text Document.exe (PID: 9192)
      • New Text Document.exe (PID: 9304)
      • New Text Document.exe (PID: 9372)
      • New Text Document.exe (PID: 9444)
      • New Text Document.exe (PID: 9556)
      • New Text Document.exe (PID: 9632)
      • New Text Document.exe (PID: 9708)
      • New Text Document.exe (PID: 9780)
      • New Text Document.exe (PID: 9860)
      • New Text Document.exe (PID: 9928)
      • New Text Document.exe (PID: 10108)
      • New Text Document.exe (PID: 10028)
      • Discord.exe (PID: 9276)
      • New Text Document.exe (PID: 5508)
      • New Text Document.exe (PID: 8260)
      • New Text Document.exe (PID: 8612)
      • New Text Document.exe (PID: 7272)
      • New Text Document.exe (PID: 8888)
      • New Text Document.exe (PID: 10284)
      • New Text Document.exe (PID: 8744)
      • New Text Document.exe (PID: 4364)
      • New Text Document.exe (PID: 10376)
      • New Text Document.exe (PID: 10596)
      • New Text Document.exe (PID: 10516)
      • New Text Document.exe (PID: 10700)
      • New Text Document.exe (PID: 10776)
      • New Text Document.exe (PID: 10812)
      • New Text Document.exe (PID: 10804)
      • New Text Document.exe (PID: 10856)
      • New Text Document.exe (PID: 11004)
      • New Text Document.exe (PID: 10884)
      • New Text Document.exe (PID: 11204)
      • New Text Document.exe (PID: 11052)
      • New Text Document.exe (PID: 11072)
      • New Text Document.exe (PID: 10928)
      • New Text Document.exe (PID: 10960)
      • New Text Document.exe (PID: 11504)
      • New Text Document.exe (PID: 11304)
      • New Text Document.exe (PID: 11144)
      • New Text Document.exe (PID: 11460)
      • New Text Document.exe (PID: 11400)
      • New Text Document.exe (PID: 11236)
      • New Text Document.exe (PID: 11716)
      • New Text Document.exe (PID: 11604)
      • New Text Document.exe (PID: 11784)
      • New Text Document.exe (PID: 12224)
    • Application launched itself

      • msedge.exe (PID: 3812)
      • msedge.exe (PID: 3828)
      • msedge.exe (PID: 3972)
      • msedge.exe (PID: 21764)
    • Reads Microsoft Office registry keys

      • explorer.exe (PID: 1180)
    • Reads the Internet Settings

      • explorer.exe (PID: 1180)
    • Checks transactions between databases Windows and Oracle

      • cmd.exe (PID: 4316)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 6876)
    • Dropped object may contain TOR URL's

      • New Text Document.exe (PID: 7432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Amadey

(PID) Process(1640) axplons.exe
C25.42.96.7
URLhttp://5.42.96.7/zamo7h/index.php
Version4.20
Options
Drop directory7af68cdb52
Drop nameaxplons.exe
Strings (113)+++
d1
<c>
S-%lu-
-unicode-
Rem
un:
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
\0000
og:
ESET
DefaultSettings.XResolution
#
pc:
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
https://
?scr=1
rundll32.exe
Programs
sd:
2019
e1
&&
random
shell32.dll
Norton
/Plugins/
"taskkill /f /im "
SOFTWARE\Microsoft\Windows NT\CurrentVersion
axplons.exe
abcdefghijklmnopqrstuvwxyz0123456789-_
AVG
cmd
rb
cmd /C RMDIR /s/q
&unit=
/k
360TotalSecurity
Avira
CurrentBuild
e0
Main
------
:::
ps1
-%lu
7af68cdb52
shutdown -s -t 0
id:
GET
|
bi:
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
wb
AVAST Software
&& Exit"
Panda Security
st=s
------
SYSTEM\ControlSet001\Services\BasicDisplay\Video
Kaspersky Lab
DefaultSettings.YResolution
Comodo
lv:
dm:
http://
/zamo7h/index.php
ProgramData\
av:
\
.jpg
2016
=
-executionpolicy remotesigned -File "
cred.dll|clip.dll|
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
dll
" && ren
Doctor Web
POST
SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
VideoID
Startup
os:
kernel32.dll
Sophos
" && timeout 1 && del
%USERPROFILE%
" Content-Type: application/octet-stream
\App
GetNativeSystemInfo
rundll32
4.20
Content-Disposition: form-data; name="data"; filename="
ProductName
Content-Type: application/x-www-form-urlencoded
vs:
--
"
Content-Type: multipart/form-data; boundary=----
r=
%-lu
<d>
5.42.96.7
SYSTEM\CurrentControlSet\Control\UnitedVideo\CONTROL\VIDEO\
WinDefender
exe
0123456789
2022
Powershell.exe
ComputerName
Bitdefender
ar:
(PID) Process(2300) explorku.exe
C25.42.96.141
URLhttp://5.42.96.141/go34ko8/index.php
Version4.20
Options
Drop directory908f070dff
Drop nameexplorku.exe
Strings (113)+++
d1
<c>
S-%lu-
-unicode-
Rem
un:
SOFTWARE\Microsoft\Windows\CurrentVersion\Run
\0000
og:
ESET
DefaultSettings.XResolution
#
pc:
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
https://
?scr=1
rundll32.exe
Programs
sd:
2019
e1
&&
explorku.exe
random
shell32.dll
Norton
/Plugins/
"taskkill /f /im "
SOFTWARE\Microsoft\Windows NT\CurrentVersion
abcdefghijklmnopqrstuvwxyz0123456789-_
AVG
cmd
rb
cmd /C RMDIR /s/q
&unit=
/k
360TotalSecurity
Avira
CurrentBuild
e0
Main
------
:::
ps1
-%lu
shutdown -s -t 0
id:
GET
|
bi:
SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders
wb
AVAST Software
&& Exit"
Panda Security
st=s
------
SYSTEM\ControlSet001\Services\BasicDisplay\Video
Kaspersky Lab
DefaultSettings.YResolution
Comodo
5.42.96.141
lv:
dm:
http://
ProgramData\
av:
\
.jpg
2016
=
-executionpolicy remotesigned -File "
cred.dll|clip.dll|
SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
dll
" && ren
Doctor Web
POST
SYSTEM\CurrentControlSet\Control\ComputerName\ComputerName
VideoID
Startup
os:
kernel32.dll
Sophos
" && timeout 1 && del
%USERPROFILE%
/go34ko8/index.php
" Content-Type: application/octet-stream
\App
GetNativeSystemInfo
908f070dff
rundll32
4.20
Content-Disposition: form-data; name="data"; filename="
ProductName
Content-Type: application/x-www-form-urlencoded
vs:
--
"
Content-Type: multipart/form-data; boundary=----
r=
%-lu
<d>
SYSTEM\CurrentControlSet\Control\UnitedVideo\CONTROL\VIDEO\
WinDefender
exe
0123456789
2022
Powershell.exe
ComputerName
Bitdefender
ar:

RisePro

(PID) Process(2384) gena.exe
C2 (1)147.45.47.126:58709
Strings (58)\Games
w.'GS
\Battle.net
C:\program files\steam
\Session Storage
\.purple
\GHISLER\wcx_ftp.ini
\FeatherClient
\.minecraft\launcher_msa_credentials.bin
\.lunarclient\settings\games\accounts.txt
\accounts.json
\accounts.txt
\config
VaultGetItem
VaultOpenVault
\Pidgin
logins
\TotalCommander
\wcx_ftp.ini
\Microsoft\Skype for Desktop\Local Storage
VaultCloseVault
]j8|q3
\Local Storage
\.minecraft\launcher_profiles.json
APPDATA
C:\program files (x86)\steam
\Steam
\accounts.xml
\Minecraft
\Messengers
\FileZilla
\config.json
dH9zx46
\Element
\Growtopia
dHce5
\OpenVPN Connect\profiles
WSASend
\databases
\launcher_accounts.json
\save.dat
\.feather\accounts.json
\Skype
\Growtopia\save.dat
\TLauncher
\.minecraft\launcher_accounts.json
\OHqH
\ey_tokens.txt
\launcher_msa_credentials.bin
\tlauncher_profiles.json
\Element\Local Storage
\ICQ\0001
\Signal
\launcher_profiles.json
M3ZQpD
_*\Xq_
\OpenVPN Connect
\LunarClient
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:03 07:51:19+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.33
CodeSize: 214528
InitializedDataSize: 119296
UninitializedDataSize: -
EntryPoint: 0x21d50
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
850
Monitored processes
461
Malicious processes
133
Suspicious processes
13

Behavior graph

Click at the process to see the details
start new text document.bin.exe #HAUSBOMBER new text document.exe wmpnscfg.exe no specs random.exe 1234.exe #AMADEY axplons.exe document0984757478.exe no specs #PHEMEDRONE build13.exe svchost.exe no specs conhost.exe #VIDAR csrss.exe #FORMBOOK svchost.exe no specs cmd.exe no specs mode.com no specs attrib.exe no specs #RISEPRO gena.exe sdf34ert3etgrthrthfghfghjfgh.exe #VIDAR katd41b.tmp no specs o2i3jroi23joj23ikrjokij3oroi.exe #GCLEANER inte.exe #VIDAR katdf27.tmp no specs cmd.exe no specs cmd.exe no specs taskkill.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs e6qwxb7lvzsu_xownh06.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs schtasks.exe no specs schtasks.exe no specs msedge.exe no specs msedge.exe #RISEPRO oachqtpsmxwlvqpkfab9.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs schtasks.exe no specs schtasks.exe no specs cy3oumwrb6f5l5m8ut6b.exe msedge.exe no specs msedge.exe no specs #AMADEY explorku.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs explorku.exe no specs amers.exe #RISEPRO 8c3edaadfe.exe 2c6b69e198.exe excel.exe no specs msedge.exe no specs msedge.exe no specs build13.exe conhost.exe document0984757478.exe no specs #VIDAR csrss.exe no specs #RISEPRO gena.exe o2i3jroi23joj23ikrjokij3oroi.exe random.exe sdf34ert3etgrthrthfghfghjfgh.exe #VIDAR kat860.tmp no specs #VIDAR kat8fc.tmp no specs svchost.exe no specs cmd.exe no specs mode.com no specs attrib.exe no specs random.exe sdf34ert3etgrthrthfghfghjfgh.exe #VIDAR kat37bd.tmp no specs #HAUSBOMBER new text document.exe #HAUSBOMBER new text document.exe #HAUSBOMBER new text document.exe #HAUSBOMBER new text document.exe #HAUSBOMBER new text document.exe #HAUSBOMBER new text document.exe #GCLEANER inte.exe vpn-1002.exe no specs new text document.exe vpn-1002.exe #HAUSBOMBER new text document.exe #HAUSBOMBER new text document.exe cmd.exe no specs new text document.exe taskkill.exe no specs cmd.exe no specs powershell.exe #HAUSBOMBER new text document.exe #STEALC swizzz.exe #HAUSBOMBER new text document.exe new text document.exe #GCLEANER inte.exe new text document.exe #AVEMARIA winsec.exe #HAUSBOMBER new text document.exe new text document.exe powershell.exe new text document.exe cmd.exe no specs taskkill.exe no specs new text document.exe tdrpload.exe new text document.exe reurginggleek.exe new text document.exe new text document.exe cmd.exe new text document.exe swizzzz.exe new text document.exe new text document.exe new text document.exe #GCLEANER inte.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe Copy/Move/Rename/Delete/Link Object new text document.exe sysblardsv.exe cmd.exe no specs new text document.exe pkgmgr.exe no specs taskkill.exe no specs new text document.exe test.exe lumma0805.exe new text document.exe new text document.exe system.exe build.exe cmt.exe nc.exe no specs new text document.exe new text document.exe pkgmgr.exe new text document.exe new text document.exe new text document.exe makecab.exe no specs dism.exe no specs new text document.exe winsec.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe powershell.exe no specs new text document.exe #GCLEANER inte.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe cmd.exe no specs taskkill.exe no specs new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe schtasks.exe no specs new text document.exe new text document.exe discord.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe #GCLEANER univ.exe new text document.exe new text document.exe e_win.exe no specs new text document.exe msfiler.exe no specs f.exe no specs new text document.exe new text document.exe nine.exe new text document.exe #GCLEANER inte.exe winsec.exe no specs new text document.exe new text document.exe new text document.exe yar.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs cmd.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs cmd.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs taskkill.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs taskmgr.exe taskkill.exe no specs new text document.exe no specs my.exe no specs new text document.exe no specs update.exe no specs winsec.exe no specs new text document.exe no specs installer.exe no specs toolspub1.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs update_3.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs taskmgr.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs pei.exe current.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs udated.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs 2237331016.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs up2date.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs sdp.exe 1668093182.exe no specs smss.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs schtasks.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs findlawthose.exe no specs schtasks.exe no specs setup_1715277229.6072824.exe new text document.exe no specs syslmgrsvc.exe no specs crypted333.exe av_downloader.exe no specs new text document.exe no specs new text document.exe no specs hvc.exe no specs new text document.exe no specs 290929157.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs swizzhis.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs anon.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs cmd.exe no specs newpinf.exe no specs new text document.exe no specs regsvcs.exe no specs new text document.exe no specs update_3.exe update.exe new text document.exe no specs winqlsdrvcs.exe no specs new text document.exe no specs msbuild.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs 191312718.exe no specs build3.exe no specs go.exe no specs mshta.exe no specs regsvcs.exe no specs 2714529271.exe no specs tiktok.exe no specs timesync.exe no specs new text document.exe no specs crypted_9f4ae6b2.exe lumma1.exe eee01.exe no specs qq.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs scanner.exe new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs smss.exe no specs sharphound.exe no specs whserver.exe no specs ttt.exe no specs 120189850.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs lummac2.exe msedge.exe no specs yileyou.exe no specs new text document.exe no specs new text document.exe no specs newpinf.exe msedge.exe no specs new text document.exe no specs new text document.exe no specs msedge.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs new text document.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
304"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --mojo-platform-channel-handle=3368 --field-trial-handle=1324,i,3210757381108663111,11261225201125976810,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
304"C:\Users\admin\Desktop\a\random.exe" C:\Users\admin\Desktop\a\random.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\a\random.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
552"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
560"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1268 --field-trial-handle=1208,i,16420862102877316055,14244537145583123246,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
560"C:\Users\admin\AppData\Local\Temp\1000013001\amers.exe" C:\Users\admin\AppData\Local\Temp\1000013001\amers.exe
explorku.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\1000013001\amers.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
660"C:\Users\admin\Desktop\a\o2i3jroi23joj23ikrjokij3oroi.exe" C:\Users\admin\Desktop\a\o2i3jroi23joj23ikrjokij3oroi.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\a\o2i3jroi23joj23ikrjokij3oroi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
764"C:\Users\admin\Desktop\a\random.exe" C:\Users\admin\Desktop\a\random.exe
New Text Document.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\a\random.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1008"C:\Users\admin\Desktop\a\conhost.exe" C:\Users\admin\Desktop\a\conhost.exe
New Text Document.exe
User:
admin
Company:
AnalystSoft Inc
Integrity Level:
MEDIUM
Description:
StatPlus v7
Version:
7.7.0.0
Modules
Images
c:\users\admin\desktop\a\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1028"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1260 --field-trial-handle=1392,i,7219194556356770313,1970013191182010172,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1028"C:\Users\admin\1000017002\2c6b69e198.exe" C:\Users\admin\1000017002\2c6b69e198.exe
explorku.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\1000017002\2c6b69e198.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
573 102
Read events
569 875
Write events
2 970
Delete events
257

Modification events

(PID) Process:(1180) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
01000000D08C9DDF0115D1118C7A00C04FC297EB010000005ECAE606A2BB334E84348D8DB47BEB35000000000200000000001066000000010000200000008C3AC4D5201A64276C29E6A1040EC7993DC3577D699337091561EB85D8A7928C000000000E800000000200002000000019AAFDAD897073C105F571B860F8BA69F4E9AE9581287A50BA0428358C42539030000000188B73FFF4E860385E1A81E2813709C783BE85959D5CA8B4D861BD894C7A7A2D08072E7D9DBEFAEC01A9DA9445FBE7FC400000008698DEDC5B950CBEBAD736A4EAD5BE928884E7FD5602FCDD6B1B45C0DB2CAC6B39527C765AFD20A8532AA9EA938FF47F732474C939B1E200D293292B4A1E1CB1
(PID) Process:(1180) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage2
Operation:writeName:ProgramsCache
Value:
13000000C3535B6248ABC14EBA1FA1EF4146FC1900800000007E00310000000000454B864A110050726F6772616D730000660008000400EFBE454B814A454B864A2A000000820100000000020000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018000000013C0200003A02320095050000635169222000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A0000005A2A000000000200000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00780105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E006500780065000000000000004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000002D006E006F0068006F006D0065000000645C5606FA88CB017BA28924BB3DD3010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E006500780065000000000000001C00000000040100007E00310000000000454B864A110050726F6772616D730000660008000400EFBE454B814A454B864A2A000000820100000000020000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000EE3A432511004143434553537E3100006C0008000400EFBE454B814A454B814A2A000000840100000000020000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003600310000001800000001C0010000BE01320000050000EE3A40252000434F4D4D414E7E312E4C4E4B00007A0008000400EFBE454B814A454B814A2A000000A401000000000200000000000000000050000000000043006F006D006D0061006E0064002000500072006F006D00700074002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003200320000001C00280105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006D0064002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006D0064002E006500780065000000000024134DF9F988CB01DF091E1FBB3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006D0064002E006500780065000000000000001C00000001C8010000C601320018050000EE3A432520004E6F74657061642E6C6E6B006C0008000400EFBE454B814A454B814A2A0000009D0100000000020000000000000000004200000000004E006F00740065007000610064002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003500310000001A00400105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006E006F00740065007000610064002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006E006F00740065007000610064002E00650078006500000000009B6515FB2B04CA01DF091E1FBB3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006E006F00740065007000610064002E006500780065000000000000001A00000001AA010000A801320006010000EE3AB624200052756E2E6C6E6B00640008000400EFBE454B814A454B814A2A000000A00100000000030000000000000000003A0000000000520075006E002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D0031003200370031003000000016002E0105000B00EFBE00000000000000003A003A007B00320035003500390041003100460033002D0032003100440037002D0031003100440034002D0042004400410046002D003000300043003000340046003600300042003900460030007D000000000000003A003A007B00320035003500390041003100460033002D0032003100440037002D0031003100440034002D0042004400410046002D003000300043003000340046003600300042003900460030007D00000000000000000000000000DF091E1FBB3DD3010000000000000000000000003A003A007B00320035003500390041003100460033002D0032003100440037002D0031003100440034002D0042004400410046002D003000300043003000340046003600300042003900460030007D000000000000001600000001D0010000CE013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B814A454B814A2A000000AB010000000002000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00340105000B00EFBE00000000000000002500770069006E0064006900720025005C006500780070006C006F007200650072002E006500780065000000000000007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000000077B74DFEF988CB01DF091E1FBB3DD3010000000001000000000000007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000000000001C000000008C0100007E00310000000000454B864A110050726F6772616D730000660008000400EFBE454B814A454B864A2A000000820100000000020000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000EE3A432511004143434553537E3100006C0008000400EFBE454B814A454B814A2A000000840100000000020000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003100000018008800310000000000EE3A362511004143434553537E310000700008000400EFBE454B814A454B814A2A000000860100000000020000000000000000004600000000004100630063006500730073006900620069006C00690074007900000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700360030000000180000000168020000660232004E050000EE3A36252000454153454F467E312E4C4E4B0000AE0008000400EFBE454B814A454B814A2A000000A8010000000002000000000000000000500000000000450061007300650020006F00660020004100630063006500730073002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C004100630063006500730073006900620069006C00690074007900430070006C002E0064006C006C002C002D003100300000001C009C0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006F006E00740072006F006C002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00330043004100360033004200410034002D0033004400440036002D0032004500410041002D0039003300370033002D003000440039004500360031004300320031004300300042007D0000002F006E0061006D00650020004D006900630072006F0073006F00660074002E0045006100730065004F006600410063006300650073007300430065006E0074006500720000009B6515FB2B04CA01DF091E1FBB3DD3010000000000000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006E00740072006F006C002E006500780065000000000000001C00000001C8010000C6013200EA040000EE3A362520004D61676E6966792E6C6E6B006C0008000400EFBE454B814A454B814A2A000000AA0100000000020000000000000000004200000000004D00610067006E006900660079002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003400310000001A00400105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D00610067006E006900660079002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D00610067006E006900660079002E00650078006500000000009B6515FB2B04CA01DF091E1FBB3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D00610067006E006900660079002E006500780065000000000000001A00000001D2010000D0013200EE040000EE3A362520004E61727261746F722E6C6E6B00006E0008000400EFBE454B814A454B814A2A000000A70100000000020000000000000000004400000000004E00610072007200610074006F0072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003400380000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006E00610072007200610074006F0072002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006E00610072007200610074006F0072002E006500780065000000000084F10BF6F988CB01DF091E1FBB3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006E00610072007200610074006F0072002E006500780065000000000000001C00000001C8010000C6013200E2040000EE3A362520004F4E2D5343527E312E4C4E4B0000820008000400EFBE454B814A454B814A2A000000A20100000000020000000000000000005800000000004F006E002D00530063007200650065006E0020004B006500790062006F006100720064002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003500320000001C00280105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006F0073006B002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006F0073006B002E00650078006500000000009B6515FB2B04CA01DF091E1FBB3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006F0073006B002E006500780065000000000000001C000000008A0100007E00310000000000454B864A110050726F6772616D730000660008000400EFBE454B814A454B864A2A000000820100000000020000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000EE3A432511004143434553537E3100006C0008000400EFBE454B814A454B814A2A000000840100000000020000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003100000018008600310000000000454B864A110053595354454D7E3100006E0008000400EFBE454B814A454B864A2A00000085010000000002000000000000000000440000000000530079007300740065006D00200054006F006F006C007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003800380000001800000001BA010000B801320006010000EE3AB6242000636F6D70757465722E6C6E6B00006E0008000400EFBE454B814A454B814A2A0000009801000000000700000000000000000044000000000063006F006D00700075007400650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003100320037003100310000001C002E0105000B00EFBE00000000000000003A003A007B00320030004400300034004600450030002D0033004100450041002D0031003000360039002D0041003200440038002D003000380030003000320042003300300033003000390044007D000000000000003A003A007B00320030004400300034004600450030002D0033004100450041002D0031003000360039002D0041003200440038002D003000380030003000320042003300300033003000390044007D00000000000000000000000000DF091E1FBB3DD3010000000000000000000000003A003A007B00320030004400300034004600450030002D0033004100450041002D0031003000360039002D0041003200440038002D003000380030003000320042003300300033003000390044007D000000000000001C00000001C4010000C201320006010000EE3AB6242000434F4E54524F7E312E4C4E4B0000780008000400EFBE454B814A454B814A2A0000009F0100000000020000000000000000004E000000000043006F006E00740072006F006C002000500061006E0065006C002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003100320037003100320000001C002E0105000B00EFBE00000000000000003A003A007B00350033003900390045003600390034002D0036004300450035002D0034004400360043002D0038004600430045002D003100440038003800370030004600440043004200410030007D000000000000003A003A007B00350033003900390045003600390034002D0036004300450035002D0034004400360043002D0038004600430045002D003100440038003800370030004600440043004200410030007D00000000000000000000000000DF091E1FBB3DD3010000000000000000000000003A003A007B00350033003900390045003600390034002D0036004300450035002D0034004400360043002D0038004600430045002D003100440038003800370030004600440043004200410030007D000000000000001C000000015802000056023200B7050000454B864A2000494E5445524E7E312E4C4E4B0000C00008000400EFBE454B864A454B864A2A000000592A000000000200000000000000000070000000000049006E007400650072006E006500740020004500780070006C006F00720065007200200028004E006F0020004100640064002D006F006E00730029002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300370000001C007A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E006500780065000000000000004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C007400000020002D006500780074006F00660066000000645C5606FA88CB017BA28924BB3DD3010100000000000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E006500780065000000010000001C00000001F2010000F00132001A050000EE3A4D2520005052495641547E312E4C4E4B00008E0008000400EFBE454B814A454B814A2A0000009C01000000000200000000000000000064000000000050007200690076006100740065002000430068006100720061006300740065007200200045006400690074006F0072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003700300000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00650075006400630065006400690074002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00650075006400630065006400690074002E0065007800650000000000A314E100FA88CB01DF091E1FBB3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00650075006400630065006400690074002E006500780065000000000000001C00000000040100007E00310000000000454B864A110050726F6772616D730000660008000400EFBE454B814A454B864A2A000000820100000000020000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000EE3AB62411004D41494E54457E3100006C0008000400EFBE454B814A454B814A2A000000830100000000020000000000000000004200000000004D00610069006E00740065006E0061006E0063006500000040007300680065006C006C00330032002E0064006C006C002C002D003200310038003100310000001800000001AE010000AC01320006010000EE3AB624200048656C702E6C6E6B0000660008000400EFBE454B814A454B814A2A000000990100000000020000000000000000003C0000000000480065006C0070002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D0031003200370030003900000018002E0105000B00EFBE00000000000000003A003A007B00320035003500390041003100460031002D0032003100440037002D0031003100440034002D0042004400410046002D003000300043003000340046003600300042003900460030007D000000000000003A003A007B00320035003500390041003100460031002D0032003100440037002D0031003100440034002D0042004400410046002D003000300043003000340046003600300042003900460030007D00000000000000000000000000DF091E1FBB3DD3010000000000000000000000003A003A007B00320035003500390041003100460031002D0032003100440037002D0031003100440034002D0042004400410046002D003000300043003000340046003600300042003900460030007D000000000000001800000002195711A42ED61D49AA7CE74B8BE3B06700020000000000014A0200004802320002050000EE3AD225200044454641554C7E312E4C4E4B0000960008000400EFBEEE3AD225EE3AD2252A0000005B290000000001000000000000000000540000000000440065006600610075006C0074002000500072006F006700720061006D0073002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007300750064002E0064006C006C002C002D00310000001C00960105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006F006E00740072006F006C002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00460045004300340039004200410041002D0041004400310035002D0038003800350045002D0035004300380045002D004200340043004100410032003600420030004600450042007D0000002F006E0061006D00650020004D006900630072006F0073006F00660074002E00440065006600610075006C007400500072006F006700720061006D00730000009B6515FB2B04CA01B24A2B113E04CA010000000000000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006E00740072006F006C002E006500780065000000000000001C000000011A02000018023200F2040000EE3AB624200057494E444F577E312E4C4E4B00009A0008000400EFBEEE3AB624EE3AB6242A0000005D290000000001000000000000000000500000000000570069006E0064006F007700730020005500700064006100740065002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007700750063006C007400750078002E0064006C006C002C002D00310000001C00620105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00770075006100700070002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00300037004500340035004400360037002D0036003000430038002D0038003300350031002D0038003300450031002D003500430044003100340030003500320041004400410031007D000000730074006100720074006D0065006E007500000091BA1BFEF988CB0181C626D43C04CA010000000000000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00770075006100700070002E006500780065000000000000001C00000000800000007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018000000010C0200000A023200C7080000E656084D200046495245464F7E312E4C4E4B0000660008000400EFBEE656084DE656084D2A00000081E9000000000C000000000000000000000000000000460069007200650066006F007800200050007200690076006100740065002000420072006F007700730069006E0067002E006C006E006B0000001C00880105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C0070007200690076006100740065005F00620072006F007700730069006E0067002E0065007800650000000000000033003000380030003400360042003000410046003400410033003900430042003B005000720069007600610074006500420072006F007700730069006E006700410055004D004900440000000000871290DCEDAFD901E1A1C3DDEDAFD9010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C0070007200690076006100740065005F00620072006F007700730069006E0067002E006500780065000000000000001C000000019A010000980132005D040000E656084D200046697265666F782E6C6E6B00440008000400EFBE1C4D7D57E656084D2A0000007FE9000000000D000000000000000000000000000000460069007200650066006F0078002E006C006E006B0000001A003A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C00660069007200650066006F0078002E00650078006500000000000000330030003800300034003600420030004100460034004100330039004300420000000000962B7441BE3ED401148BB441BE3ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C00660069007200650066006F0078002E006500780065000000000000001A00000001B8010000B60132007A080000E656C0522000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D59591C4D59592A00000062BB000000000200000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C004A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0047006F006F0067006C0065005C004300680072006F006D0065005C004100700070006C00690063006100740069006F006E005C006300680072006F006D0065002E006500780065000000000000004300680072006F006D006500000000006AEC40C6BF3ED401D2754AC6BF3ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0047006F006F0067006C0065005C004300680072006F006D0065005C004100700070006C00690063006100740069006F006E005C006300680072006F006D0065002E006500780065000000000000001C00000001CA010000C801320041050000454B1A8A20004D45444941437E312E4C4E4B0000900008000400EFBE454B1A8A454B1A8A2A00000064A700000000020000000000000000004C00000000004D0065006400690061002000430065006E007400650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00650068006F006D0065005C00650068007200650073002E0064006C006C002C002D0031003000300000001C001C0105000B00EFBE00000000000000002500770069006E0064006900720025005C00650068006F006D0065005C00650068007300680065006C006C002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D006500640069006100430065006E0074006500720000000000B8CD21CAB8F8CB017A4BEBBBFD3DD3010100000001000000000000007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C00650068006F006D0065005C00650068007300680065006C006C002E006500780065000000000000001C00000001BE010000BC013200C1080000E656854A20004D4943524F537E312E4C4E4B0000520008000400EFBEE656854AE656854A2A000000A9E300000000070000000000000000000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B0000001C004E0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F00660074005C0045006400670065005C004100700070006C00690063006100740069006F006E005C006D00730065006400670065002E006500780065000000000000004D00530045006400670065000000000074FA6F0FEBAFD9017CA99F0FEBAFD9010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F00660074005C0045006400670065005C004100700070006C00690063006100740069006F006E005C006D00730065006400670065002E006500780065000000000000001C00000001EC010000EA013200DD0300006251E04D20004E4F544550417E312E4C4E4B0000480008000400EFBE6251E04D6251E04D2A00000089E101000000060000000000000000000000000000004E006F00740065007000610064002B002B002E006C006E006B0000001C00860105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004E006F00740065007000610064002B002B005C006E006F00740065007000610064002B002B002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004E006F00740065007000610064002B002B005C006E006F00740065007000610064002B002B002E0065007800650000000000E021DD54C73ED401D7B5DA1BFDB0D6010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004E006F00740065007000610064002B002B005C006E006F00740065007000610064002B002B002E006500780065000000000000001C00000001720200007002320032050000EE3A4F252000536964656261722E6C6E6B00AC0008000400EFBEEE3A4F25EE3A4F252A0000005F29000000000100000000000000000042000000000053006900640065006200610072002E006C006E006B000000400043003A005C00500072006F006700720061006D002000460069006C00650073005C00570069006E0064006F0077007300200053006900640065006200610072005C0073006900640065006200610072002E006500780065002C002D00310030003000350000001A00AA0105000B00EFBE00000000000000002500500072006F006700720061006D00460069006C006500730025005C00570069006E0064006F0077007300200053006900640065006200610072005C0073006900640065006200610072002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00430030004200380030003600330043002D0032004300320044002D0043003900460033002D0031004400410036002D004500370035003800430034004300410041003400440043007D0000002F00730068006F007700670061006400670065007400730000008584B70AFA88CB014AE24A7E3D04CA010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00570069006E0064006F0077007300200053006900640065006200610072005C0073006900640065006200610072002E006500780065000000000000001A000000018A0200008802320048050000EE3A5025200057494E444F577E322E4C4E4B0000CC0008000400EFBEEE3A5025EE3A50252A00000060290000000001000000000000000000620000000000570069006E0064006F0077007300200041006E007900740069006D006500200055007000670072006100640065002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C00570069006E0064006F007700730041006E007900740069006D0065005500700067007200610064006500550049002E006500780065002C002D00310000001C00A00105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00570069006E0064006F007700730041006E007900740069006D0065005500700067007200610064006500550049002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570069006E0064006F007700730041006E007900740069006D0065005500700067007200610064006500550049002E00650078006500000000009B6515FB2B04CA01986CCB7E3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570069006E0064006F007700730041006E007900740069006D0065005500700067007200610064006500550049002E006500780065000000000000001C0000000152020000500232002E050000454B1A8A200057494E444F577E342E4C4E4B0000B80008000400EFBE454B1A8A454B1A8A2A00000035A70000000001000000000000000000560000000000570069006E0064006F0077007300200044005600440020004D0061006B00650072002E006C006E006B000000400043003A005C00500072006F006700720061006D002000460069006C00650073005C0044005600440020004D0061006B00650072005C004400560044004D0061006B00650072002E006500780065002C002D003600310034003000330000001C007C0105000B00EFBE00000000000000002500500072006F006700720061006D00460069006C006500730025005C0044005600440020004D0061006B00650072005C004400560044004D0061006B00650072002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0044005600440020004D0061006B00650072005C004400560044004D0061006B00650072002E00650078006500000000007FD1F9E43E04CA01CAC765BBFD3DD3010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0044005600440020004D0061006B00650072005C004400560044004D0061006B00650072002E006500780065000000000000001C00000001F0010000EE013200BA040000EE3A4D25200057494E444F577E312E4C4E4B0000AA0008000400EFBEEE3A4D25EE3A4D252A000000612900000000010000000000000000005C0000000000570069006E0064006F00770073002000460061007800200061006E00640020005300630061006E002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C004600580053005200450053004D002E0064006C006C002C002D0031003100340000001C00280105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C005700460053002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C005700460053002E00650078006500000000007CDDDB0FFA88CB0196DE747B3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C005700460053002E006500780065000000000000001C000000014802000046023200EB050000454B354E200057494E444F577E332E4C4E4B0000A80008000400EFBEEE3AD325EE3AD3252A000000622900000000010000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C00820105000B00EFBE00000000000000002500500072006F006700720061006D00460069006C006500730025005C00570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072005C0077006D0070006C0061007900650072002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000002F00700072006500660065007400630068003A00310000000A20E70AFA88CB01FAB372113E04CA010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072005C0077006D0070006C0061007900650072002E006500780065000000000000001C000000010402000002023200DE040000EE3A502520005850535649457E312E4C4E4B0000980008000400EFBEEE3A5025EE3A50252A0000006329000000000100000000000000000048000000000058005000530020005600690065007700650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C00580070007300520063006800560077002E006500780065002C002D0031003000320000001C004E0105000B00EFBE00000000000000002500730079007300740065006D0072006F006F00740025005C00730079007300740065006D00330032005C00780070007300720063006800760077002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00780070007300720063006800760077002E00650078006500000000009B6515FB2B04CA01DCBFEC7E3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00780070007300720063006800760077002E006500780065000000000000001C00000000040100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000454B1A8A11004143434553537E3100006C0008000400EFBEEE3AA314454B1A8A2A000000340100000000010000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003600310000001800000001BE010000BC013200CE040000EE3A4E25200043414C43554C7E312E4C4E4B0000720008000400EFBEEE3A4E25EE3A4E252A00000064290000000001000000000000000000480000000000430061006C00630075006C00610074006F0072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003100390000001C002E0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00630061006C0063002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00630061006C0063002E006500780065000000000027ADB109FA88CB01965F8B7C3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00630061006C0063002E006500780065000000000000001C000000012A02000028023200F2040000EE3A3D252000444953504C417E312E4C4E4B0000A80008000400EFBEEE3A3D25EE3A3D252A000000662900000000010000000000000000004E000000000064006900730070006C00610079007300770069007400630068002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0064006900730070006C00610079007300770069007400630068002E006500780065002C002D0033003200300000001C00640105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0064006900730070006C00610079007300770069007400630068002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0064006900730070006C00610079007300770069007400630068002E00650078006500000000009B6515FB2B04CA0114CA196B3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0064006900730070006C00610079007300770069007400630068002E006500780065000000000000001C00000001D6020000D402320054050000454B1A8A20004D415448494E7E312E4C4E4B0000D80008000400EFBE454B1A8A454B1A8A2A00000034A700000000010000000000000000005400000000004D00610074006800200049006E007000750074002000500061006E0065006C002E006C006E006B000000400043003A005C00500072006F006700720061006D002000460069006C00650073005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C006D00690070002E006500780065002C002D0032003900310000001C00E00105000B00EFBE0000000000000000250043006F006D006D006F006E00500072006F006700720061006D00460069006C006500730025005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C006D00690070002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C006D00690070002E0065007800650000000000DAA6A601FA88CB01706563BBFD3DD3010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C006D00690070002E006500780065000000000000001C000000011C0200001A023200D6040000454B1A8A20004D4F42494C497E312E4C4E4B0000A00008000400EFBE454B1A8A454B1A8A2A00000051A700000000010000000000000000005200000000004D006F00620069006C006900740079002000430065006E007400650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0062006C006300740072002E006500780065002C002D00310030003000380000001C005E0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D0062006C006300740072002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00420042003300340038004100320030002D0037003700310044002D0033004200450037002D0044003200340045002D003800420035003900360036004400350039004500300036007D0000002F006F00700065006E0000009A69AB01FA88CB01BED7B6BBFD3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0062006C006300740072002E006500780065000000000000001C000000010402000002023200DA040000454B1A8A20004E4554574F527E312E4C4E4B0000A60008000400EFBE454B1A8A454B1A8A2A0000002DA700000000010000000000000000005600000000004E006500740077006F0072006B00500072006F006A0065006300740069006F006E002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C004E0065007400500072006F006A0057002E0064006C006C002C002D0035003000310000001C00400105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C004E0065007400500072006F006A002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C004E0065007400500072006F006A002E00650078006500000000009B6515FB2B04CA01922B49BBFD3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C004E0065007400500072006F006A002E006500780065000000000000001C00000001C2010000C0013200DA040000EE3A432520005061696E742E6C6E6B00680008000400EFBEEE3A4325EE3A43252A000000672900000000010000000000000000003E00000000005000610069006E0074002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003500340000001800400105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D0073007000610069006E0074002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0073007000610069006E0074002E00650078006500000000009B6515FB2B04CA015616826F3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0073007000610069006E0074002E006500780065000000000000001800000001E2010000E0013200540600006351511A200052454D4F54457E312E4C4E4B0000B20008000400EFBEEE3A3325EE3A33252A00000068290000000001000000000000000000660000000000520065006D006F007400650020004400650073006B0074006F007000200043006F006E006E0065006300740069006F006E002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0073007400730063002E006500780065002C002D00340030003000300000001C00120105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D0073007400730063002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E00520065006D006F00740065004400650073006B0074006F00700000000000282973F9F988CB01BC096C5F3D04CA010100000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0073007400730063002E006500780065000000000000001C000000012602000024023200F8040000454B1A8A2000534E495050497E312E4C4E4B0000AA0008000400EFBE454B1A8A454B1A8A2A00000037A700000000010000000000000000004E000000000053006E0069007000700069006E006700200054006F006F006C002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0053006E0069007000700069006E00670054006F006F006C002E006500780065002C002D003100350030003500310000001C005E0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0053006E0069007000700069006E00670054006F006F006C002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0053006E0069007000700069006E00670054006F006F006C002E00650078006500000000009B6515FB2B04CA01242A68BBFD3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0053006E0069007000700069006E00670054006F006F006C002E006500780065000000000000001C00000001340200003202320032050000EE3A4F252000534F554E44527E312E4C4E4B0000AA0008000400EFBEEE3A4F25EE3A4F252A0000006929000000000100000000000000000050000000000053006F0075006E00640020005200650063006F0072006400650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0053006F0075006E0064005200650063006F0072006400650072002E006500780065002C002D0031003000300000001C006C0105000B00EFBE00000000000000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0053006F0075006E0064005200650063006F0072006400650072002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0053006F0075006E0064005200650063006F0072006400650072002E00650078006500000000009B6515FB2B04CA016A06527E3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0053006F0075006E0064005200650063006F0072006400650072002E006500780065000000000000001C00000001D6010000D401320047050000454B1A8A2000535449434B597E312E4C4E4B00009E0008000400EFBE454B1A8A454B1A8A2A00000033A700000000010000000000000000004C000000000053007400690063006B00790020004E006F007400650073002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0053004E0054005300650061007200630068002E0064006C006C002C002D0035003000350000001C001A0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C005300740069006B0079004E006F0074002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0053007400690063006B0079004E006F00740065007300000000009B6515FB2B04CA01160361BBFD3DD3010100000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C005300740069006B0079004E006F0074002E006500780065000000000000001C000000010602000004023200E6040000EE3A4C25200053594E4343457E312E4C4E4B0000A00008000400EFBEEE3A4C25EE3A4C252A0000006A2900000000010000000000000000004A0000000000530079006E0063002000430065006E007400650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00530079006E006300430065006E007400650072002E0064006C006C002C002D00330030003000300000001C00480105000B00EFBE00000000000000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C006D006F006200730079006E0063002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D006F006200730079006E0063002E0065007800650000000000A31C9509FA88CB014549E17A3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D006F006200730079006E0063002E006500780065000000000000001C0000000184020000820232002B060000EE3A4F25200057454C434F4D7E312E4C4E4B0000A40008000400EFBEEE3A4F25EE3A4F252A0000006B290000000001000000000000000000500000000000570065006C0063006F006D0065002000430065006E007400650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C004F006F006200650046006C00640072002E0064006C006C002C002D003300330030003500360000001C00C20105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00720075006E0064006C006C00330032002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E00470065007400740069006E006700530074006100720074006500640000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C004F006F006200650046006C00640072002E0064006C006C002C00530068006F007700570065006C0063006F006D006500430065006E0074006500720020004C00610075006E006300680065006400420079005F00530074006100720074004D0065006E007500530068006F007200740063007500740000009B6515FB2B04CA01D8A9C67E3D04CA010100000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00720075006E0064006C006C00330032002E006500780065000000000000001C000000014C0200004A0232002A050000EE3A4C252000576F72647061642E6C6E6B006C0008000400EFBEEE3A4C25EE3A4C252A0000006C29000000000100000000000000000042000000000057006F00720064007000610064002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600390000001A00C40105000B00EFBE00000000000000002500500072006F006700720061006D00460069006C006500730025005C00570069006E0064006F007700730020004E0054005C004100630063006500730073006F0072006900650073005C0077006F00720064007000610064002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00570069006E0064006F007700730020004E0054005C004100630063006500730073006F0072006900650073005C0077006F00720064007000610064002E006500780065000000000086060001FA88CB01AED62F7B3D04CA010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00570069006E0064006F007700730020004E0054005C004100630063006500730073006F0072006900650073005C0077006F00720064007000610064002E006500780065000000000000001A000000008C0100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000454B1A8A11004143434553537E3100006C0008000400EFBEEE3AA314454B1A8A2A000000340100000000010000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003100000018008800310000000000EE3A502511004143434553537E310000700008000400EFBEEE3AA314EE3A50252A000000350100000000010000000000000000004600000000004100630063006500730073006900620069006C00690074007900000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003600300000001800000001700200006E0232006C050000EE3A502520005350454543487E312E4C4E4B0000C20008000400EFBEEE3A5025EE3A50252A0000006E29000000000100000000000000000058000000000053007000650065006300680020005200650063006F0067006E006900740069006F006E002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C005300700065006500630068005C00530070006500650063006800550058005C0073006100700069002E00630070006C002C002D00350035003500350000001C00900105000B00EFBE00000000000000002500770069006E0064006900720025005C005300700065006500630068005C0043006F006D006D006F006E005C0073006100700069007300760072002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00440041004100310036003800440045002D0034003300300036002D0043003800420043002D0038004300310031002D004200350039003600320034003000420044004400450044007D0000002D005300700065006500630068005500580000009B6515FB2B04CA01BEA6F87E3D04CA010000000001000000000000007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C005300700065006500630068005C0043006F006D006D006F006E005C0073006100700069007300760072002E006500780065000000000000001C000000008A0100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000454B1A8A11004143434553537E3100006C0008000400EFBEEE3AA314454B1A8A2A000000340100000000010000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003100000018008600310000000000EE3A4F25110053595354454D7E3100006E0008000400EFBEEE3AA314EE3A4F252A00000036010000000001000000000000000000440000000000530079007300740065006D00200054006F006F006C007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003800380000001800000001D6010000D4013200E0040000EE3A4E2520004348415241437E312E4C4E4B0000780008000400EFBEEE3A4E25EE3A4E252A0000006F2900000000010000000000000000004E000000000043006800610072006100630074006500720020004D00610070002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003200310000001C00400105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006800610072006D00610070002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006800610072006D00610070002E00650078006500000000009B6515FB2B04CA015722907C3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006800610072006D00610070002E006500780065000000000000001C00000001E2010000E00132000A050000EE3A402520006466726775692E6C6E6B00008C0008000400EFBEEE3A4025EE3A40252A000000712900000000010000000000000000004000000000006400660072006700750069002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006400660072006700750069002E006500780065002C002D0031003000330000001A003A0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006400660072006700750069002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006400660072006700750069002E0065007800650000000000A107A1FEF988CB018FAF006C3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006400660072006700750069002E006500780065000000000000001A00000001DA010000D8013200E4040000EE3A4D2520004449534B434C7E312E4C4E4B0000760008000400EFBEEE3A4D25EE3A4D252A000000722900000000010000000000000000004C00000000004400690073006B00200043006C00650061006E00750070002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003200360000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006C00650061006E006D00670072002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006C00650061006E006D00670072002E00650078006500000000009B6515FB2B04CA01F01E3E7B3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006C00650061006E006D00670072002E006500780065000000000000001C000000011C0200001A023200DA040000EE3A312520005245534F55527E312E4C4E4B00009E0008000400EFBEEE3A3125EE3A31252A000000732900000000010000000000000000005400000000005200650073006F00750072006300650020004D006F006E00690074006F0072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007700640063002E0064006C006C002C002D003100300030003300300000001C00600105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0070006500720066006D006F006E002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00370035003000330039003300430038002D0043004100370045002D0041003200370032002D0039003400370042002D004100450042004100360037004200300036003000430046007D0000002F00720065007300000080E5C600FA88CB011A5E2E5D3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0070006500720066006D006F006E002E006500780065000000000000001C000000010C0200000A023200E2040000EE3A2B25200053595354454D7E312E4C4E4B0000A80008000400EFBEEE3A2B25EE3A2B252A00000074290000000001000000000000000000580000000000530079007300740065006D00200049006E0066006F0072006D006100740069006F006E002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D00730069006E0066006F00330032002E006500780065002C002D0031003000300000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D00730069006E0066006F00330032002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D00730069006E0066006F00330032002E0065007800650000000000BF99F7F6F988CB013AFB97553D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D00730069006E0066006F00330032002E006500780065000000000000001C00000001FC010000FA013200DE040000EE3A4C25200053595354454D7E322E4C4E4B00009C0008000400EFBEEE3A4C25EE3A4C252A00000075290000000001000000000000000000500000000000530079007300740065006D00200052006500730074006F00720065002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007200730074007200750069002E006500780065002C002D0031003000300000001C00420105000B00EFBE00000000000000002500730079007300740065006D0072006F006F00740025005C00730079007300740065006D00330032005C007200730074007200750069002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007200730074007200750069002E0065007800650000000000FB57D20FFA88CB010301D37A3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007200730074007200750069002E006500780065000000000000001C000000012802000026023200F4040000EE3A412520005441534B53437E312E4C4E4B0000AA0008000400EFBEEE3A4125EE3A41252A000000762900000000010000000000000000005000000000005400610073006B0020005300630068006500640075006C00650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0069006700750069007200650073006F0075007200630065002E0064006C006C002C002D0032003000310000001C00600105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C007400610073006B0073006300680064002E006D00730063000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002F00730000009B6515FB2B04CA018890F46D3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B0073006300680064002E006D00730063000000000000001C000000014A0200004802320028050000EE3A4F25200057494E444F577E322E4C4E4B0000C20008000400EFBEEE3A4F25EE3A4F252A000000772900000000010000000000000000006E0000000000570069006E0064006F00770073002000450061007300790020005400720061006E00730066006500720020005200650070006F007200740073002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0069006700770069007A005C007700650074002E0064006C006C002C002D0035003900310000001C006A0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D0069006700770069007A005C0070006F00730074006D00690067002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0069006700770069007A005C0070006F00730074006D00690067002E0065007800650000000000FC5BABFB2B04CA010CB0627E3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0069006700770069007A005C0070006F00730074006D00690067002E006500780065000000000000001C00000001340200003202320024050000EE3A4F25200057494E444F577E312E4C4E4B0000B20008000400EFBEEE3A4F25EE3A4F252A000000782900000000010000000000000000005E0000000000570069006E0064006F00770073002000450061007300790020005400720061006E0073006600650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0069006700770069007A005C007700650074002E0064006C006C002C002D0035003800380000001C00640105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D0069006700770069007A005C006D0069006700770069007A002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0069006700770069007A005C006D0069006700770069007A002E0065007800650000000000FC5BABFB2B04CA01EB8B5B7E3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D0069006700770069007A005C006D0069006700770069007A002E006500780065000000000000001C00000000C60100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000454B1A8A11004143434553537E3100006C0008000400EFBEEE3AA314454B1A8A2A000000340100000000010000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003600310000001800C200310000000000454B1A8A11005441424C45547E310000AA0008000400EFBE8C3E1213454B1A8A2A000000370100000000010000000000000000003E00000000005400610062006C00650074002000500043000000400043003A005C00500072006F006700720061006D002000460069006C00650073005C00770069006E0064006F007700730020006A006F00750072006E0061006C005C006A006F00750072006E0061006C002E006500780065002C002D0036003200300030003500000018000000012A030000280332009C050000454B1A8A20005348415045437E312E4C4E4B0000EA0008000400EFBE454B1A8A454B1A8A2A00000050A700000000010000000000000000005000000000005300680061007000650043006F006C006C006500630074006F0072002E006C006E006B000000400043003A005C00500072006F006700720061006D002000460069006C00650073005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005300680061007000650043006F006C006C006500630074006F0072002E006500780065002C002D0032003900380000001C00220205000B00EFBE0000000000000000250043006F006D006D006F006E00500072006F006700720061006D00460069006C006500730025005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005300680061007000650043006F006C006C006500630074006F0072002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005300680061007000650043006F006C006C006500630074006F0072002E006500780065000000000092F6ADF92B04CA010A13B2BBFD3DD3010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005300680061007000650043006F006C006C006500630074006F0072002E006500780065000000000000001C00000001D6020000D40232006A050000454B1A8A20005461625469702E6C6E6B0000C80008000400EFBE454B1A8A454B1A8A2A00000038A700000000010000000000000000004000000000005400610062005400690070002E006C006E006B000000400043003A005C00500072006F006700720061006D002000460069006C00650073005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005400690070005400730066002E0064006C006C002C002D003800300000001A00F20105000B00EFBE0000000000000000250043006F006D006D006F006E00500072006F006700720061006D00460069006C006500730025005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005400610062005400690070002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005400610062005400690070002E006500780065000000000092F6ADF92B04CA01D8EE6CBBFD3DD3010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C004D006900630072006F0073006F006600740020005300680061007200650064005C0049006E006B005C005400610062005400690070002E006500780065000000000000001A000000006E0100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000454B1A8A11004143434553537E3100006C0008000400EFBEEE3AA314454B1A8A2A000000340100000000010000000000000000004200000000004100630063006500730073006F007200690065007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370036003100000018006A00310000000000EE3AD325110057494E444F577E310000520008000400EFBEEE3A9026EE3AD3252A00000038010000000001000000000000000000000000000000570069006E0064006F0077007300200050006F007700650072005300680065006C006C0000001800000001F4020000F2023200B1060000E656698C200057494E444F577E322E4C4E4B0000E20008000400EFBEEE3AD325EE3AD3252A0000007A290000000001000000000000000000600000000000570069006E0064006F0077007300200050006F007700650072005300680065006C006C0020004900530045002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0070006F007700650072007300680065006C006C002E006500780065002C002D0031003000310000001C00F40105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0050006F007700650072005300680065006C006C005F004900530045002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0050006F007700650072005300680065006C006C005F004900530045002E0065007800650000000000A14598DC2FB0D901BF8C9D113E04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0050006F007700650072005300680065006C006C005F004900530045002E006500780065000000000000001C000000015C0200005A023200BC080000E6562D8C200057494E444F577E312E4C4E4B00005A0008000400EFBEEE3A9026E6562D8C2A000000526F0100000003000000000000000000000000000000570069006E0064006F0077007300200050006F007700650072005300680065006C006C002E006C006E006B0000001C00E40105000B00EFBE00000000000000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0070006F007700650072007300680065006C006C002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0070006F007700650072007300680065006C006C002E00650078006500000000001388F8DB2FB0D901026216E53E04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570069006E0064006F007700730050006F007700650072005300680065006C006C005C00760031002E0030005C0070006F007700650072007300680065006C006C002E006500780065000000000000001C00000000160100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018009600310000000000454B1A8A110041444D494E497E3100007E0008000400EFBEEE3A9026454B1A8A2A00000039010000000001000000000000000000540000000000410064006D0069006E00690073007400720061007400690076006500200054006F006F006C007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003600320000001800000001FE010000FC013200DA040000EE3AD3252000434F4D504F4E7E312E4C4E4B0000A60008000400EFBEEE3AD325EE3AD3252A0000007D29000000000100000000000000000058000000000043006F006D0070006F006E0065006E0074002000530065007200760069006300650073002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0063006F006D007200650073002E0064006C006C002C002D00330034003100300000001C003A0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006F006D006500780070002E006D00730063000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006D006500780070002E006D0073006300000000009B6515FB2B04CA01A27EBC113E04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006D006500780070002E006D00730063000000000000001C0000000128020000260232000E050000EE3A3C252000434F4D5055547E312E4C4E4B0000AA0008000400EFBEEE3A3C25EE3A3C252A0000007E2900000000010000000000000000005A000000000043006F006D007000750074006500720020004D0061006E006100670065006D0065006E0074002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D00790063006F006D007000750074002E0064006C006C002C002D0033003000300000001C00600105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0063006F006D0070006D0067006D0074002E006D00730063000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00390033003500370036003100460038002D0039003400450034002D0046004600410037002D0041003800430030002D004600310041004200320043004400450043003700350030007D0000002F00730000009B6515FB2B04CA017BCB3E6A3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006D0070006D0067006D0074002E006D00730063000000000000001C000000010E0200000C023200F6040000EE3A3225200044415441534F7E312E4C4E4B0000AA0008000400EFBEEE3A3225EE3A32252A0000007F2900000000010000000000000000005A00000000004400610074006100200053006F0075007200630065007300200028004F0044004200430029002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006F0064006200630069006E0074002E0064006C006C002C002D00310033003100300000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006F0064006200630061006400330032002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006F0064006200630061006400330032002E00650078006500000000009B6515FB2B04CA0132D7FF5D3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006F0064006200630061006400330032002E006500780065000000000000001C00000001240200002202320012050000EE3A412520004556454E54567E312E4C4E4B0000A60008000400EFBEEE3A4125EE3A41252A000000812900000000010000000000000000004C00000000004500760065006E00740020005600690065007700650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0069006700750069007200650073006F0075007200630065002E0064006C006C002C002D0031003000310000001C00600105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006500760065006E0074007600770072002E006D00730063000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00330038003100380042004100410033002D0035004600460030002D0043003400420039002D0031004100440042002D004300420042003600320046003500390030004100390039007D0000002F00730000009B6515FB2B04CA018685E16D3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006500760065006E0074007600770072002E006D00730063000000000000001C000000010802000006023200FA040000EE3A3C2520004953435349497E312E4C4E4B0000A40008000400EFBEEE3A3C25EE3A3C252A0000008229000000000100000000000000000052000000000069005300430053004900200049006E00690074006900610074006F0072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0069007300630073006900630070006C002E0064006C006C002C002D00350030003000310000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0069007300630073006900630070006C002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0069007300630073006900630070006C002E00650078006500000000009B6515FB2B04CA0181EC776A3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0069007300630073006900630070006C002E006500780065000000000000001C00000001100200000E023200F4040000EE3A2B2520004D454D4F52597E312E4C4E4B0000B20008000400EFBEEE3A2B25EE3A2B252A000000832900000000010000000000000000006200000000004D0065006D006F0072007900200044006900610067006E006F0073007400690063007300200054006F006F006C002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C004D006400530063006800650064002E006500780065002C002D00340030003000310000001C00400105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C004D006400530063006800650064002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C004D006400530063006800650064002E006500780065000000000077B74DFEF988CB01D6836F553D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C004D006400530063006800650064002E006500780065000000000000001C000000011E0200001C023200D0040000EE3A31252000504552464F527E312E4C4E4B0000A40008000400EFBEEE3A3125EE3A31252A000000842900000000010000000000000000005A000000000050006500720066006F0072006D0061006E006300650020004D006F006E00690074006F0072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C007700640063002E0064006C006C002C002D003100300030003200310000001C005C0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0070006500720066006D006F006E002E006D00730063000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00450044003400420044003500390044002D0042004600300046002D0045003600330031002D0038003900450039002D003200380039003000340035003000420039004500380042007D0000002F00730000009B6515FB2B04CA013877225D3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0070006500720066006D006F006E002E006D00730063000000000000001C000000013802000036023200EE040000454B198A20005052494E544D7E312E4C4E4B0000A20008000400EFBE454B198A454B198A2A0000001CA700000000010000000000000000005400000000005000720069006E00740020004D0061006E006100670065006D0065006E0074002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0070006D00630073006E00610070002E0064006C006C002C002D0037003000300000001C00780105000B00EFBE00000000000000002500730079007300740065006D0072006F006F00740025005C00730079007300740065006D00330032005C007000720069006E0074006D0061006E006100670065006D0065006E0074002E006D00730063000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007000720069006E0074006D0061006E006100670065006D0065006E0074002E006D0073006300000000009B6515FB2B04CA017C5512BBFD3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007000720069006E0074006D0061006E006100670065006D0065006E0074002E006D00730063000000000000001C000000013C0200003A023200E0040000454B1A8A20005345435552497E312E4C4E4B0000C60008000400EFBE454B1A8A454B1A8A2A0000007BA7000000000100000000000000000076000000000053006500630075007200690074007900200043006F006E00660069006700750072006100740069006F006E0020004D0061006E006100670065006D0065006E0074002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C00770073006500630065006400690074002E0064006C006C002C002D0037003100380000001C00580105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C0073006500630070006F006C002E006D00730063000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00370038003800340041003700370033002D0033003100370037002D0035003500370037002D0030003600450043002D003900340030004500310037004100380046003300350039007D0000002F00730000009B6515FB2B04CA01E40B4DBCFD3DD3010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0073006500630070006F006C002E006D00730063000000000000001C00000001FA010000F801320008050000EE3A3725200073657276696365732E6C6E6B0000960008000400EFBEEE3A3725EE3A37252A00000085290000000001000000000000000000440000000000730065007200760069006300650073002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C00660069006C0065006D0067006D0074002E0064006C006C002C002D00320032003000340000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00730065007200760069006300650073002E006D00730063000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00730065007200760069006300650073002E006D0073006300000000009B6515FB2B04CA01CE655E643D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00730065007200760069006300650073002E006D00730063000000000000001C00000001100200000E023200DE040000EE3A2B25200053595354454D7E312E4C4E4B0000AC0008000400EFBEEE3A2B25EE3A2B252A000000862900000000010000000000000000005C0000000000530079007300740065006D00200043006F006E00660069006700750072006100740069006F006E002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D00730063006F006E006600690067002E006500780065002C002D0031003200360000001C00460105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D00730063006F006E006600690067002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D00730063006F006E006600690067002E0065007800650000000000FF5FBD00FA88CB0119D790553D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D00730063006F006E006600690067002E006500780065000000000000001C000000012802000026023200EE040000EE3A412520005441534B53437E312E4C4E4B0000AA0008000400EFBEEE3A4125EE3A41252A000000872900000000010000000000000000005000000000005400610073006B0020005300630068006500640075006C00650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D0069006700750069007200650073006F0075007200630065002E0064006C006C002C002D0032003000310000001C00600105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C007400610073006B0073006300680064002E006D00730063000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003900360032003100370035002D0037004400460043002D0042003100440037002D0042003000440031002D004500420034004300300038004600460044003700350034007D0000002F00730000009B6515FB2B04CA01C8CDEF6D3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C007400610073006B0073006300680064002E006D00730063000000000000001C00000001100200000E023200FA040000EE3A3525200057494E444F577E322E4C4E4B0000D00008000400EFBEEE3A3525EE3A35252A00000088290000000001000000000000000000820000000000570069006E0064006F007700730020004600690072006500770061006C006C0020007700690074006800200041006400760061006E006300650064002000530065006300750072006900740079002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00410075007400680046005700470050002E0064006C006C002C002D003200300000001C00220105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C00570046002E006D00730063000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570046002E006D0073006300000000009B6515FB2B04CA01B3DF4C613D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C00570046002E006D00730063000000000000001C00000000D60000007E003100000000001C4D7C60110050726F6772616D730000660008000400EFBEEE3AA3141C4D7C602A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700380032000000180056003100000000001C4D7C60100043436C65616E657200003E0008000400EFBE1C4D7C601C4D7C602A000000A7C40000000003000000000000000000000000000000430043006C00650061006E0065007200000018000000017401000072013200520000006251344E200043434C45414E7E312E55524C0000580008000400EFBE1C4D7C601C4D7C602A000000A9C40000000003000000000000000000000000000000430043006C00650061006E0065007200200048006F006D00650070006100670065002E00750072006C0000001C00FE0005000B00EFBE000000000000000068007400740070003A002F002F007700770077002E00630063006C00650061006E00650072002E0063006F006D002F00630063006C00650061006E006500720000000000000068007400740070003A002F002F007700770077002E00630063006C00650061006E00650072002E0063006F006D002F00630063006C00650061006E0065007200000000000000000000000000B6660431C73ED40100000000000000000000000068007400740070003A002F002F007700770077002E00630063006C00650061006E00650072002E0063006F006D002F00630063006C00650061006E00650072000000000000001C00000001DE010000DC013200D70300006251344E200043436C65616E65722E6C6E6B0000460008000400EFBE1C4D7C601C4D7C602A000000A8C40000000003000000000000000000000000000000430043006C00650061006E00650072002E006C006E006B0000001C007A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C00430043006C00650061006E00650072005C00430043006C00650061006E00650072002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00430043006C00650061006E00650072005C00430043006C00650061006E00650072002E00650078006500000000001CB9B530C73ED401B6660431C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00430043006C00650061006E00650072005C00430043006C00650061006E00650072002E006500780065000000000000001C00000000EE0000007E00310000000000E656084D110050726F6772616D730000660008000400EFBEEE3AA314E656084D2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018006E00310000000000E656476D100046494C455A497E310000560008000400EFBE1C4D3B62E656476D2A000000D7E40000000001000000000000000000000000000000460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E00740000001800000001C8010000C60132008D040000E656476D200046494C455A497E312E4C4E4B0000480008000400EFBE1C4D3B62E656476D2A000000E9D20000000005000000000000000000000000000000460069006C0065005A0069006C006C0061002E006C006E006B0000001C00620105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C00660069006C0065007A0069006C006C0061002E00650078006500000000000000460069006C0065005A0069006C006C0061002E0043006C00690065006E0074002E00410070007000490044000000000000A53CED15B3D9016FE46425C93ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C00660069006C0065007A0069006C006C0061002E006500780065000000000000001C000000012E0200002C02320030040000E656476D2000554E494E53547E312E4C4E4B0000480008000400EFBE1C4D3B62E656476D2A000000E6D2000000000500000000000000000000000000000055006E0069006E007300740061006C006C002E006C006E006B0000001C00C80105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C0075006E0069006E007300740061006C006C002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C0075006E0069006E007300740061006C006C002E0065007800650000000000ABC10025C93ED4019FD15125C93ED4010000000000000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C0075006E0069006E007300740061006C006C002E006500780065000000000000001C00000000F40000007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700380032000000180074003100000000008C3E2013110047616D657300600008000400EFBEEE3A90268C3E20132A0000003A010000000001000000000000000000360000000000470061006D0065007300000040007300680065006C006C00330032002E0064006C006C002C002D003200310037003700330000001400000001E8010000E601320002010000EE3A4D25200047414D4545587E312E4C4E4B00009C0008000400EFBEEE3A4D25EE3A4D252A0000008B2900000000010000000000000000004C0000000000470061006D0065004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C00670061006D006500750078002E0064006C006C002C002D003100300030003800320000001C002E0105000B00EFBE00000000000000003A003A007B00450044003200320038004600440046002D0039004500410038002D0034003800370030002D0038003300420031002D003900360042003000320043004600450030004400350032007D000000000000003A003A007B00450044003200320038004600440046002D0039004500410038002D0034003800370030002D0038003300420031002D003900360042003000320043004600450030004400350032007D000000000000000000000000008D333F7C3D04CA010000000000000000000000003A003A007B00450044003200320038004600440046002D0039004500410038002D0034003800370030002D0038003300420031002D003900360042003000320043004600450030004400350032007D000000000000001C00000000CA0000007E003100000000001C4D9860110050726F6772616D730000660008000400EFBEEE3AA3141C4D98602A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018004A003100000000001C4D986010004A6176610000360008000400EFBE1C4D98601C4D98602A000000D5CE00000000030000000000000000000000000000004A00610076006100000014000000012A02000028023200250800006351F60B200041424F55544A7E312E4C4E4B00004A0008000400EFBE1C4D98606351F60B2A000000ACDB0000000007000000000000000000000000000000410062006F007500740020004A006100760061002E006C006E006B0000001C00C20105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00370041004100460031003200410046002D0046004100410031002D0037004200430043002D0042003200430031002D003100430032003500420034003000420043004600450041007D0000002D007400610062002000610062006F007500740000007D3ADFE380B1D6010C1A8650C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E006500780065000000000000001C000000013A02000038023200000000006351F60B2000434845434B467E312E4C4E4B0000580008000400EFBE1C4D98606351F60B2A000000DBCE000000000400000000000000000000000000000043006800650063006B00200046006F007200200055007000640061007400650073002E006C006E006B0000001C00C40105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00430033003500390045003700320031002D0033003800330033002D0030004600360038002D0033004600410044002D003800330039004400310030004600420031003900360032007D0000002D00740061006200200075007000640061007400650000007D3ADFE380B1D6010C1A8650C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E006500780065000000000000001C0000000132020000300232000D0800006351F60B2000434F4E4649477E312E4C4E4B0000520008000400EFBE1C4D98606351F60B2A000000DACE000000000400000000000000000000000000000043006F006E0066006900670075007200650020004A006100760061002E006C006E006B0000001C00C20105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E00650078006500000000007D3ADFE380B1D601B2B78350C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004A006100760061005C006A007200650031002E0038002E0030005F003200370031005C00620069006E005C006A00610076006100630070006C002E006500780065000000000000001C000000011A01000018013200B40000006351F60B200047455448454C7E312E55524C0000460008000400EFBE1C4D98606351F60B2A000000D9CE00000000040000000000000000000000000000004700650074002000480065006C0070002E00750072006C0000001C00B60005000B00EFBE000000000000000068007400740070003A002F002F006A006100760061002E0063006F006D002F00680065006C00700000000000000068007400740070003A002F002F006A006100760061002E0063006F006D002F00680065006C007000000000000000000000000000B2B78350C73ED40100000000000000000000000068007400740070003A002F002F006A006100760061002E0063006F006D002F00680065006C0070000000000000001C000000010E0100000C013200B00000006351F60B200056495349544A7E312E55524C0000520008000400EFBE1C4D98606351F60B2A000000D8CE00000000040000000000000000000000000000005600690073006900740020004A006100760061002E0063006F006D002E00750072006C0000001C009E0005000B00EFBE000000000000000068007400740070003A002F002F006A006100760061002E0063006F006D002F0000000000000068007400740070003A002F002F006A006100760061002E0063006F006D002F00000000000000000000000000B2B78350C73ED40100000000000000000000000068007400740070003A002F002F006A006100760061002E0063006F006D002F000000000000001C00000000040100007E00310000000000454B1A8A110050726F6772616D730000660008000400EFBEEE3AA314454B1A8A2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018008400310000000000EE3A502511004D41494E54457E3100006C0008000400EFBEEE3AA314EE3A50252A0000003B0100000000010000000000000000004200000000004D00610069006E00740065006E0061006E0063006500000040007300680065006C006C00330032002E0064006C006C002C002D0032003100380031003100000018000000016E0200006C02320018050000EE3A4F2520004241434B55507E312E4C4E4B0000B00008000400EFBEEE3A4F25EE3A4F252A0000008C2900000000010000000000000000006600000000004200610063006B0075007000200061006E006400200052006500730074006F00720065002000430065006E007400650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0073006400630070006C002E0064006C006C002C002D0031003000310000001C00A00105000B00EFBE00000000000000002500530079007300740065006D0052006F006F00740025005C00530079007300740065006D00330032005C0063006F006E00740072006F006C002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00410034004100420038003500390046002D0032003700460037002D0037003500340038002D0032004500390036002D004600450035003900350043003800330045004300300045007D0000002F006E0061006D00650020004D006900630072006F0073006F00660074002E004200610063006B007500700041006E00640052006500730074006F007200650000009B6515FB2B04CA011C7CD17D3D04CA010000000000000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006E00740072006F006C002E006500780065000000000000001C000000011202000010023200E0040000EE3A502520004352454154457E312E4C4E4B0000AC0008000400EFBEEE3A5025EE3A50252A0000008D2900000000010000000000000000005C000000000043007200650061007400650020005200650063006F007600650072007900200044006900730063002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0072006500630064006900730063002E006500780065002C002D00320030003000300000001C00480105000B00EFBE00000000000000002500730079007300740065006D0072006F006F00740025005C00730079007300740065006D00330032005C0072006500630064006900730063002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0072006500630064006900730063002E0065007800650000000000DA33CB0FFA88CB01221E217F3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0072006500630064006900730063002E006500780065000000000000001C00000001EA010000E8013200BC040000EE3A4F25200052454D4F54457E312E4C4E4B00009E0008000400EFBEEE3A4F25EE3A4F252A0000008F290000000001000000000000000000560000000000520065006D006F0074006500200041007300730069007300740061006E00630065002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C006D007300720061002E006500780065002C002D0031003000300000001C002E0105000B00EFBE00000000000000002500770069006E0064006900720025005C00730079007300740065006D00330032005C006D007300720061002E006500780065000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D007300720061002E00650078006500000000009B6515FB2B04CA014EF8707E3D04CA010000000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C006D007300720061002E006500780065000000000000001C00000000E60000007E003100000000001B4D235E110050726F6772616D730000660008000400EFBEEE3AA3141B4D235E2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700380032000000180066003100000000001B4D235E10004D4943524F537E3100004E0008000400EFBE1B4D235E1B4D235E2A00000069BB00000000010000000000000000000000000000004D006900630072006F0073006F006600740020004F006600660069006300650000001800000001C8020000C6023200670B00001B4D235E20004D4943524F537E312E4C4E4B0000600008000400EFBE1B4D235E1B4D235E2A00000071BB00000000020000000000000000000000000000004D006900630072006F0073006F00660074002000410063006300650073007300200032003000310030002E006C006E006B0000001C004A0205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D0053004100430043004500530053002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B00410043004300450053005300460069006C00650073003E00320041005A007E0060004F003700710043003F004F0057002C00660065005A0079006300780068000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D0053004100430043004500530053002E00450058004500000000000000000000000000297349F4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D0053004100430043004500530053002E004500580045000000000000001C00000001B2020000B0023200870B00001B4D235E20004D4943524F537E322E4C4E4B00005E0008000400EFBE1B4D235E1B4D235E2A00000072BB00000000020000000000000000000000000000004D006900630072006F0073006F0066007400200045007800630065006C00200032003000310030002E006C006E006B0000001C00360205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C0045005800430045004C002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B0045005800430045004C00460069006C00650073003E00560069006A00710042006F006600280059003800270077002100460049006400310067004C0051000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C0045005800430045004C002E00450058004500000000000000000000000000297349F4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C0045005800430045004C002E004500580045000000000000001C00000001C6020000C40232003F0B00001B4D235E20004D49383037467E312E4C4E4B0000620008000400EFBE1B4D235E1B4D235E2A00000077BB00000000020000000000000000000000000000004D006900630072006F0073006F006600740020004F006E0065004E006F0074006500200032003000310030002E006C006E006B0000001C00460205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F004E0045004E004F00540045002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B004F006E0065004E006F0074006500460069006C00650073003E00350026006D006D0047002D006A007500770040005B007E00630075002C0036002A004D004B004D000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F004E0045004E004F00540045002E00450058004500000000000000000000000000DD374EF4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F004E0045004E004F00540045002E004500580045000000000000001C00000001C6020000C4023200D50B00001B4D235E20004D4943524F537E332E4C4E4B0000620008000400EFBE1B4D235E1B4D235E2A00000073BB00000000020000000000000000000000000000004D006900630072006F0073006F006600740020004F00750074006C006F006F006B00200032003000310030002E006C006E006B0000001C00460205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F00550054004C004F004F004B002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B004F00550054004C004F004F004B00460069006C00650073003E005500330069006F006B006A0040004A0069003F0035007600320062006600790076003D0046002C000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F00550054004C004F004F004B002E00450058004500000000000000000000000000297349F4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F00550054004C004F004F004B002E004500580045000000000000001C00000001CA020000C8023200790B00001B4D235E20004D4943524F537E342E4C4E4B0000680008000400EFBE1B4D235E1B4D235E2A00000074BB00000000020000000000000000000000000000004D006900630072006F0073006F0066007400200050006F0077006500720050006F0069006E007400200032003000310030002E006C006E006B0000001C00440205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C0050004F0057004500520050004E0054002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B00500050005400460069006C00650073003E006C00350059004100730068004A003500650039003F005100310030006000460046006300320043000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C0050004F0057004500520050004E0054002E0045005800450000000000000000000000000083D54BF4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C0050004F0057004500520050004E0054002E004500580045000000000000001C00000001BA020000B8023200E10B00001B4D235E20004D49323630447E312E4C4E4B0000660008000400EFBE1B4D235E1B4D235E2A00000075BB00000000020000000000000000000000000000004D006900630072006F0073006F006600740020005000750062006C0069007300680065007200200032003000310030002E006C006E006B0000001C00360205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D0053005000550042002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B005000750062005000720069006D006100720079003E00520024006E0075006A0053005700460065003F007D0061004C0072005200700039007800400057000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D0053005000550042002E0045005800450000000000000000000000000083D54BF4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D0053005000550042002E004500580045000000000000001C00000001BA020000B8023200CD0B00001B4D235E20004D49313039447E312E4C4E4B00005C0008000400EFBE1B4D235E1B4D235E2A00000076BB00000000020000000000000000000000000000004D006900630072006F0073006F0066007400200057006F0072006400200032003000310030002E006C006E006B0000001C00400205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C00570049004E0057004F00520044002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B0057004F0052004400460069006C00650073003E00620069002400540021005600210030005A003D007B0050006B00300076006D007E0041005A0075000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C00570049004E0057004F00520044002E0045005800450000000000000000000000000083D54BF4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C00570049004E0057004F00520044002E004500580045000000000000001C00000000620100007E003100000000001B4D235E110050726F6772616D730000660008000400EFBEEE3AA3141B4D235E2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700380032000000180066003100000000001B4D235E10004D4943524F537E3100004E0008000400EFBE1B4D235E1B4D235E2A00000069BB00000000010000000000000000000000000000004D006900630072006F0073006F006600740020004F0066006600690063006500000018007C003100000000001B4D235E10004D4943524F537E310000640008000400EFBE1B4D235E1B4D235E2A0000006ABB00000000010000000000000000000000000000004D006900630072006F0073006F006600740020004F006600660069006300650020003200300031003000200054006F006F006C007300000018000000017E0100007C013200A10B00001B4D235E20004449474954417E312E4C4E4B00007E0008000400EFBE1B4D235E1B4D235E2A0000006FBB00000000020000000000000000000000000000004400690067006900740061006C00200043006500720074006900660069006300610074006500200066006F00720020005600420041002000500072006F006A0065006300740073002E006C006E006B0000001C00E20005000B00EFBE000000000000000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B004F00660066006900630065004400690067006900740061006C005300460069006C00650073003C0000000000000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B004F00660066006900630065004400690067006900740061006C005300460069006C00650073003C00000000000000000000000000CF1047F4FB3DD4010000000001000000010000000000000000001C00000001BC020000BA023200650B00001B4D235E20004D4943524F537E312E4C4E4B0000660008000400EFBE1B4D235E1B4D235E2A0000006CBB00000000010000000000000000000000000000004D006900630072006F0073006F0066007400200043006C006900700020004F007200670061006E0069007A00650072002E006C006E006B0000001C00380205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D00530054004F00520045002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B00430041004700460069006C00650073003E0046004A0047006A00630032007B004300650041007A002B00240051005400420072005600680055000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D00530054004F00520045002E0045005800450000000000000000000000000075AE44F4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004D00530054004F00520045002E004500580045000000000000001C000000017E0100007C013200BF0A00001B4D235E20004D4943524F537E342E4C4E4B00008A0008000400EFBE1B4D235E1B4D235E2A00000070BB00000000020000000000000000000000000000004D006900630072006F0073006F006600740020004F00660066006900630065002000320030003100300020004C0061006E0067007500610067006500200050007200650066006500720065006E006300650073002E006C006E006B0000001C00D60005000B00EFBE000000000000000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B005300650074004C0061006E0067007500610067006500460069006C00650073003C0000000000000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B005300650074004C0061006E0067007500610067006500460069006C00650073003C00000000000000000000000000297349F4FB3DD4010000000001000000010000000000000000001C00000001500100004E013200150B00001B4D235E20004D4943524F537E332E4C4E4B00007C0008000400EFBE1B4D235E1B4D235E2A0000006EBB00000000020000000000000000000000000000004D006900630072006F0073006F006600740020004F0066006600690063006500200032003000310030002000550070006C006F00610064002000430065006E007400650072002E006C006E006B0000001C00B60005000B00EFBE000000000000000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B00570078007000460069006C00650073003C0000000000000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B00570078007000460069006C00650073003C00000000000000000000000000CF1047F4FB3DD4010000000001000000010000000000000000001C00000001BA020000B80232003B0B00001B4D235E20004D4943524F537E322E4C4E4B0000760008000400EFBE1B4D235E1B4D235E2A0000006DBB00000000020000000000000000000000000000004D006900630072006F0073006F006600740020004F00660066006900630065002000500069006300740075007200650020004D0061006E0061006700650072002E006C006E006B0000001C00260205000B00EFBE00000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F00490053002E00450058004500000001007800620027004200560066002100210021002100210021002100210021004D004B004B0053006B004F0049005300460069006C00650073003E005E007D006F006D00660037005800470038003F0042006A0054006000690035005E00530047003F000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F00490053002E00450058004500000000000000000000000000CF1047F4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F006600740020004F00660066006900630065005C004F0066006600690063006500310034005C004F00490053002E004500580045000000000000001C000000012C0300002A033200C20900001B4D235E20004F46464943457E312E4C4E4B0000620008000400EFBE1B4D235E1B4D235E2A00000078BB00000000020000000000000000000000000000004F0066006600690063006500200041006E007900740069006D006500200055007000670072006100640065002E006C006E006B0000001C00AC0205000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0043006F006D006D006F006E002000460069006C00650073005C006D006900630072006F0073006F006600740020007300680061007200650064005C004F0046004600490043004500310034005C004F0066006600690063006500200053006500740075007000200043006F006E00740072006F006C006C00650072005C00700072006F006D006F002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C006D006900630072006F0073006F006600740020007300680061007200650064005C004F0046004600490043004500310034005C004F0066006600690063006500200053006500740075007000200043006F006E00740072006F006C006C00650072005C00700072006F006D006F002E006500780065000000000089F44585FB3DD401379A50F4FB3DD4010000000001000000010000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0043006F006D006D006F006E002000460069006C00650073005C006D006900630072006F0073006F006600740020007300680061007200650064005C004F0046004600490043004500310034005C004F0066006600690063006500200053006500740075007000200043006F006E00740072006F006C006C00650072005C00700072006F006D006F002E006500780065000000000000001C00000000D80000007E003100000000001C4D9C60110050726F6772616D730000660008000400EFBEEE3AA3141C4D9C602A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700380032000000180058003100000000001C4D9C6010004E4F544550417E310000400008000400EFBE1C4D9C601C4D9C602A0000009CCF00000000010000000000000000000000000000004E006F00740065007000610064002B002B0000001800000001EC010000EA013200E30300001C4D9C6020004E4F544550417E312E4C4E4B0000480008000400EFBE1C4D9C601C4D9C602A0000009DCF00000000010000000000000000000000000000004E006F00740065007000610064002B002B002E006C006E006B0000001C00860105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004E006F00740065007000610064002B002B005C006E006F00740065007000610064002B002B002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004E006F00740065007000610064002B002B005C006E006F00740065007000610064002B002B002E0065007800650000000000E021DD54C73ED401505A1655C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004E006F00740065007000610064002B002B005C006E006F00740065007000610064002B002B002E006500780065000000000000001C00000000DA0000007E003100000000007F568961110050726F6772616D730000660008000400EFBEEE3AA3147F5689612A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018005A003100000000007F5689611000504F574552537E310000420008000400EFBE7F5689617F5689612A00000077DF000000000900000000000000000000000000000050006F007700650072005300680065006C006C00000018000000011C0200001A023200E10300007F5689612000504F574552537E312E4C4E4B00005A0008000400EFBE7F5689617F5689612A0000007BDF000000000C00000000000000000000000000000050006F007700650072005300680065006C006C00200037002000280078003800360029002E006C006E006B0000001C00A40105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0050006F007700650072005300680065006C006C005C0037005C0070007700730068002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00330036003700340046003500450034002D0031003400360033002D0038003900330043002D0032004500370038002D004100360034003300410032004400390031004100430037007D0000002D0057006F0072006B0069006E0067004400690072006500630074006F007200790020007E000000005CF51ADD6CD9011DF46D09CA63D9010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0050006F007700650072005300680065006C006C005C0037005C0070007700730068002E006500780065000000000000001C00000000CC0000007E003100000000001E4DF06E110050726F6772616D730000660008000400EFBEEE3AA3141E4DF06E2A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D0032003100370038003200000018004C003100000000001E4DF06E1000536B79706500380008000400EFBE1E4DF06E1E4DF06E2A000000A0C8000000000400000000000000000000000000000053006B0079007000650000001400000001D4010000D201320002050000E656698F2000536B7970652E6C6E6B00400008000400EFBE1E4DF06EE656698F2A0000009177000000001100000000000000000000000000000053006B007900700065002E006C006E006B00000018007A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F00660074005C0053006B00790070006500200066006F00720020004400650073006B0074006F0070005C0053006B007900700065002E006500780065000000000000004D006900630072006F0073006F00660074002E0053006B007900700065002E0053006B007900700065004400650073006B0074006F00700000000000E75BFF28993FD401304FF21D6940D4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F00660074005C0053006B00790070006500200066006F00720020004400650073006B0074006F0070005C0053006B007900700065002E006500780065000000000000001800000000D60000007E003100000000001C4DA860110050726F6772616D730000660008000400EFBEEE3AA3141C4DA8602A000000330100000000010000000000000000003C0000000000500072006F006700720061006D007300000040007300680065006C006C00330032002E0064006C006C002C002D00320031003700380032000000180056003100000000001C4DA8601000566964656F4C414E00003E0008000400EFBE1C4DA8601C4DA8602A00000090D2000000000100000000000000000000000000000056006900640065006F004C0041004E00000018000000011E0200001C0232004A04000062510C4F2000444F43554D457E312E4C4E4B0000500008000400EFBE1C4DA8601C4DA8602A00000093D2000000000100000000000000000000000000000044006F00630075006D0065006E0074006100740069006F006E002E006C006E006B0000001C00B00105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0056006900640065006F004C0041004E005C0056004C0043005C0044006F00630075006D0065006E0074006100740069006F006E002E00750072006C000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0044006F00630075006D0065006E0074006100740069006F006E002E00750072006C0000000000D6B4DC6BFEB0D601893DB260C73ED4010000000000000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0044006F00630075006D0065006E0074006100740069006F006E002E00750072006C000000000000001C00000001E8010000E60132001904000062510C4F200052454C4541537E312E4C4E4B0000500008000400EFBE1C4DA8601C4DA8602A00000094D20000000001000000000000000000000000000000520065006C00650061007300650020004E006F007400650073002E006C006E006B0000001C007A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0056006900640065006F004C0041004E005C0056004C0043005C004E004500570053002E007400780074000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C004E004500570053002E007400780074000000000000A7DF1A833AD601893DB260C73ED4010000000000000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C004E004500570053002E007400780074000000000000001C0000000136020000340232005904000062510C4F2000564944454F4C7E312E4C4E4B0000560008000400EFBE1C4DA8601C4DA8602A00000095D2000000000100000000000000000000000000000056006900640065006F004C0041004E00200057006500620073006900740065002E006C006E006B0000001C00C20105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0056006900640065006F004C0041004E005C0056004C0043005C0056006900640065006F004C0041004E00200057006500620073006900740065002E00750072006C000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0056006900640065006F004C0041004E00200057006500620073006900740065002E00750072006C0000000000D6B4DC6BFEB0D601893DB260C73ED4010000000000000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0056006900640065006F004C0041004E00200057006500620073006900740065002E00750072006C000000000000001C0000000194020000920232007204000062510C4F2000564C434D45447E332E4C4E4B00009E0008000400EFBE1C4DA8601C4DA8602A00000096D2000000000100000000000000000000000000000056004C00430020006D006500640069006100200070006C00610079006500720020002D00200072006500730065007400200070007200650066006500720065006E00630065007300200061006E0064002000630061006300680065002000660069006C00650073002E006C006E006B0000001C00D80105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00310035003300430036003300320042002D0045004100450038002D0034003200340032002D0037003100420032002D004100320032004300420042003400320039003200380038007D0000002D002D00720065007300650074002D0063006F006E0066006900670020002D002D00720065007300650074002D0070006C007500670069006E0073002D0063006100630068006500200076006C0063003A002F002F0071007500690074000000007983E8853AD601893DB260C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E006500780065000000000000001C000000010C0200000A0232002204000062510C4F2000564C434D45447E322E4C4E4B0000660008000400EFBE1C4DA8601C4DA8602A00000092D2000000000100000000000000000000000000000056004C00430020006D006500640069006100200070006C006100790065007200200073006B0069006E006E00650064002E006C006E006B0000001C00880105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E006500780065000000000000004D006900630072006F0073006F00660074002E004100750074006F00470065006E006500720061007400650064002E007B00340043004400380037004600350033002D0033004400330039002D0045004300460037002D0033003500420043002D003600310038004500440038003900440036003500320031007D0000002D00490073006B0069006E0073000000007983E8853AD601893DB260C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E006500780065000000000000001C00000001E8010000E60132001204000062510C4F2000564C434D45447E312E4C4E4B0000560008000400EFBE1C4DA8601C4DA8602A00000091D2000000000100000000000000000000000000000056004C00430020006D006500640069006100200070006C0061007900650072002E006C006E006B0000001C00740105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E0065007800650000000000A65C8F5BC73ED401893DB260C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0056006900640065006F004C0041004E005C0056004C0043005C0076006C0063002E006500780065000000000000001C000000023ACCBFB42CDB4C42B0297FE99A87C641020D34AAC40FF26348AFEFF87EF2E6BA2500020000000000017402000072023200E10700006251835220004143524F42417E312E4C4E4B0000580008000400EFBE1C4D6766625183522A00000071E901000000060000000000000000000000000000004100630072006F0062006100740020005200650061006400650072002000440043002E006C006E006B0000001C00FE0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E006500780065000000000000C8199CC4A8D601C7C990CCCD3ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00410064006F00620065005C004100630072006F0062006100740020005200650061006400650072002000440043005C005200650061006400650072005C004100630072006F0052006400330032002E006500780065000000000000001C00000001DE010000DC013200C50300006251344E200043436C65616E65722E6C6E6B0000460008000400EFBE1C4D7C601C4D7C602A000000A6C40000000003000000000000000000000000000000430043006C00650061006E00650072002E006C006E006B0000001C007A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C00430043006C00650061006E00650072005C00430043006C00650061006E00650072002E006500780065000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00430043006C00650061006E00650072005C00430043006C00650061006E00650072002E00650078006500000000001CB9B530C73ED4015C040231C73ED4010000000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00430043006C00650061006E00650072005C00430043006C00650061006E00650072002E006500780065000000000000001C00000001D6010000D4013200F7070000E656476D200046494C455A497E312E4C4E4B0000560008000400EFBE1C4D3D62E656476D2A000000823C0100000008000000000000000000000000000000460069006C0065005A0069006C006C006100200043006C00690065006E0074002E006C006E006B0000001C00620105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C00660069006C0065007A0069006C006C0061002E00650078006500000000000000460069006C0065005A0069006C006C0061002E0043006C00690065006E0074002E00410070007000490044000000000000A53CED15B3D90115DCC427C93ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00460069006C0065005A0069006C006C0061002000460054005000200043006C00690065006E0074005C00660069006C0065007A0069006C006C0061002E006500780065000000000000001C000000019A0100009801320051040000E656084D200046697265666F782E6C6E6B00440008000400EFBE1C4D7D57E656084D2A00000080E90000000010000000000000000000000000000000460069007200650066006F0078002E006C006E006B0000001A003A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C00660069007200650066006F0078002E00650078006500000000000000330030003800300034003600420030004100460034004100330039004300420000000000962B7441BE3ED4012A61EB41BE3ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C00660069007200650066006F0078002E006500780065000000000000001A00000001B6020000B4023200A6090000E65632892000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D59591C4D59592A0000005CBB000000000300000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C00480205000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0047006F006F0067006C0065005C004300680072006F006D0065005C004100700070006C00690063006100740069006F006E005C006300680072006F006D0065002E006500780065000000000000004300680072006F006D006500000022002D002D00640069007300610062006C0065002D00660065006100740075007200650073003D004F007000740069006D0069007A006100740069006F006E00470075006900640065004D006F00640065006C0044006F0077006E006C006F006100640069006E0067002C004F007000740069006D0069007A006100740069006F006E00480069006E00740073004600650074006300680069006E0067002C004F007000740069006D0069007A006100740069006F006E00540061007200670065007400500072006500640069006300740069006F006E002C004F007000740069006D0069007A006100740069006F006E00480069006E0074007300220000006AEC40C6BF3ED401781348C6BF3ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0047006F006F0067006C0065005C004300680072006F006D0065005C004100700070006C00690063006100740069006F006E005C006300680072006F006D0065002E006500780065000000000000001C00000001BE010000BC01320098080000E656854A20004D4943524F537E312E4C4E4B0000520008000400EFBEE656854AE656854A2A000000A7E300000000070000000000000000000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B0000001C004E0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F00660074005C0045006400670065005C004100700070006C00690063006100740069006F006E005C006D00730065006400670065002E006500780065000000000000004D00530045006400670065000000000074FA6F0FEBAFD90122479D0FEBAFD9010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F00660074005C0045006400670065005C004100700070006C00690063006100740069006F006E005C006D00730065006400670065002E006500780065000000000000001C00000001D4010000D2013200F0040000E656698F2000536B7970652E6C6E6B00400008000400EFBE1E4DF06EE656698F2A000000A8C8000000000600000000000000000000000000000053006B007900700065002E006C006E006B00000018007A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F00660074005C0053006B00790070006500200066006F00720020004400650073006B0074006F0070005C0053006B007900700065002E006500780065000000000000004D006900630072006F0073006F00660074002E0053006B007900700065002E0053006B007900700065004400650073006B0074006F00700000000000E75BFF28993FD401304FF21D6940D4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F00660074005C0053006B00790070006500200066006F00720020004400650073006B0074006F0070005C0053006B007900700065002E0065007800650000000000000018000000021A2CC5CA3DB5DC4E92D76B2E8AC1943402AB95399E9C1F134FB82748B24B6C717400D60000006E00310000000000E65612621000494D504C49437E310000560008000400EFBE454B854AE65612622A000000432A000000000300000000000000000000000000000049006D0070006C006900630069007400410070007000530068006F00720074006300750074007300000018006600310000000000E656126211003745344443417E3100004E0008000400EFBEE6561262E65612622A0000001CC10000000010000000000000000000000000000000370065003400640063006100380030003200340036003800360033006500330000001800000001A4010000A20132006F0A0000E6561262200070696E6E65642E6C6E6B0000680008000400EFBEE6561262E65612622A00000043C1000000000C000000000000000000400000000000700069006E006E00650064002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D00340031003600310000001A00200105000B00EFBE00000000000000002500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0063006F006E00740072006F006C002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C00000000009B6515FB2B04CA01EC1D67B403B0D9010100000001000000000000007B00440036003500320033003100420030002D0042003200460031002D0034003800350037002D0041003400430045002D004100380045003700430036004500410037004400320037007D005C0063006F006E00740072006F006C002E006500780065000000000000001A00000000540000005200310000000000454B864A11005461736B426172003C0008000400EFBE454B864A454B864A2A000000603E00000000040000000000000000000000000000005400610073006B00420061007200000016000000019A0100009801320015040000E656084D200046697265666F782E6C6E6B00440008000400EFBE6251B94DE656084D2A00000001720000000008000000000000000000000000000000460069007200650066006F0078002E006C006E006B0000001A003A0105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C00660069007200650066006F0078002E00650078006500000000000000330030003800300034003600420030004100460034004100330039004300420000000000962B7441BE3ED401D479D3F1FCB0D6010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006F007A0069006C006C0061002000460069007200650066006F0078005C00660069007200650066006F0078002E006500780065000000000000001A00000001B6020000B402320092090000E65638892000474F4F474C457E312E4C4E4B0000500008000400EFBE1C4D7D591C4D7D592A00000097C0000000000100000000000000000000000000000047006F006F0067006C00650020004300680072006F006D0065002E006C006E006B0000001C00480205000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0047006F006F0067006C0065005C004300680072006F006D0065005C004100700070006C00690063006100740069006F006E005C006300680072006F006D0065002E006500780065000000000000004300680072006F006D006500000022002D002D00640069007300610062006C0065002D00660065006100740075007200650073003D004F007000740069006D0069007A006100740069006F006E00470075006900640065004D006F00640065006C0044006F0077006E006C006F006100640069006E0067002C004F007000740069006D0069007A006100740069006F006E00480069006E00740073004600650074006300680069006E0067002C004F007000740069006D0069007A006100740069006F006E00540061007200670065007400500072006500640069006300740069006F006E002C004F007000740069006D0069007A006100740069006F006E00480069006E0074007300220000006AEC40C6BF3ED40117E829EFBF3ED4010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0047006F006F0067006C0065005C004300680072006F006D0065005C004100700070006C00690063006100740069006F006E005C006300680072006F006D0065002E006500780065000000000000001C000000013C0200003A0232009B050000635184262000494E5445524E7E312E4C4E4B0000A60008000400EFBE454B864A454B864A2A000000613E000000000400000000000000000056000000000049006E007400650072006E006500740020004500780070006C006F007200650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00530079007300740065006D00330032005C00690065003400750069006E00690074002E006500780065002C002D0037003300310000001C00780105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E006500780065000000000000004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C00740000002D006E006F0068006F006D0065000000645C5606FA88CB018351B924BB3DD3010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C0049006E007400650072006E006500740020004500780070006C006F007200650072005C0069006500780070006C006F00720065002E006500780065000000000000001C00000001F4010000F2013200C6080000E656884A20004D4943524F537E312E4C4E4B0000520008000400EFBEE656884AE656884A2A00000081E400000000060000000000000000000000000000004D006900630072006F0073006F0066007400200045006400670065002E006C006E006B0000001C00840105000B00EFBE000000000000000043003A005C00500072006F006700720061006D002000460069006C00650073005C004D006900630072006F0073006F00660074005C0045006400670065005C004100700070006C00690063006100740069006F006E005C006D00730065006400670065002E006500780065000000000000004D005300450064006700650000002D002D00700072006F00660069006C0065002D006400690072006500630074006F00720079003D00440065006600610075006C007400000074FA6F0FEBAFD901CF689912EBAFD9010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C004D006900630072006F0073006F00660074005C0045006400670065005C004100700070006C00690063006100740069006F006E005C006D00730065006400670065002E006500780065000000000000001C00000001D0010000CE013200CC040000EE3AB624200057494E444F577E312E4C4E4B00007E0008000400EFBE454B864A454B864A2A000000673E0000000005000000000000000000540000000000570069006E0064006F007700730020004500780070006C006F007200650072002E006C006E006B00000040007300680065006C006C00330032002E0064006C006C002C002D003200320030003600370000001C00340105000B00EFBE00000000000000002500770069006E0064006900720025005C006500780070006C006F007200650072002E006500780065000000000000007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000000077B74DFEF988CB01DDB3BB24BB3DD3010000000001000000000000007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E006500780065000000000000001C000000014802000046023200EB050000743D33AD200057494E444F577E322E4C4E4B0000A80008000400EFBE454B864A454B864A2A0000006B3E00000000050000000000000000005C0000000000570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072002E006C006E006B000000400043003A005C00570069006E0064006F00770073005C00730079007300740065006D00330032005C0075006E007200650067006D00700032002E006500780065002C002D00340000001C00820105000B00EFBE00000000000000002500500072006F006700720061006D00460069006C006500730025005C00570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072005C0077006D0070006C0061007900650072002E006500780065000000000000004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E004D00650064006900610050006C0061007900650072003300320000002F00700072006500660065007400630068003A00310000000A20E70AFA88CB013716BE24BB3DD3010100000001000000000000007B00370043003500410034003000450046002D0041003000460042002D0034004200460043002D0038003700340041002D004300300046003200450030004200390046004100380045007D005C00570069006E0064006F007700730020004D006500640069006100200050006C0061007900650072005C0077006D0070006C0061007900650072002E006500780065000000000000001C00000002
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3976) New Text Document.bin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1180) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\Qrfxgbc\Arj Grkg Qbphzrag.ova.rkr
Value:
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
Executable files
224
Suspicious files
480
Text files
299
Unknown types
64

Dropped files

PID
Process
Filename
Type
764random.exeC:\Users\admin\AppData\Local\Temp\7af68cdb52\axplons.exeexecutable
MD5:B6D641EE02348C20B4C0676D5BADC144
SHA256:41BC9693BA0C0AC3CF11AE6F362ECB048E7CA867211FC797C8EF827840AC0B03
2028New Text Document.exeC:\Users\admin\Desktop\a\1234.exeexecutable
MD5:D3A80C7A3A80478B08CC17522A55BB44
SHA256:4FA79B91E9531C1610DE64E35FD96D459CB52451D75BB400EBD0AA5ED1E38110
3976New Text Document.bin.exeC:\Users\admin\Desktop\Пароли Chrome.csvcsv
MD5:64F50AFB35DD16EE46F187015CEE84CE
SHA256:C2D389870DE77426A31A8C478E0FDDCBBEA7A3733B453806317914E6F946EA91
2336Document0984757478.exeC:\Users\admin\AppData\Local\Temp\aut99F0.tmpbinary
MD5:C31310503DCDBEC15380B817A3B3407D
SHA256:455B2E4C0BBAEF2127BBAEE91D65482A682DE515C471FCAE0FF94BB84D148297
2028New Text Document.exeC:\Users\admin\Desktop\a\Document0984757478.exeexecutable
MD5:C36F798F2646092C180C6FC904C418F7
SHA256:6A6FB91956C1AD9F0A57290FEA1D4A0CB4AE3C0C822DF2760661E95B2DA39AA3
3976New Text Document.bin.exeC:\Users\admin\Desktop\New Text Document.exeexecutable
MD5:A239A27C2169AF388D4F5BE6B52F272C
SHA256:98E895F711226A32BFAB152E224279D859799243845C46E550C2D32153C619FC
1180explorer.exeC:\Users\admin\Desktop\a\conhost.exeexecutable
MD5:505008D162778E05692A90C2A3ABF7B0
SHA256:785C8D265E6A30A87C0F43269D9BBB95E0977BEDAC6E4D6CE553AC431ED94FD7
2336Document0984757478.exeC:\Users\admin\AppData\Local\Temp\aut9A2F.tmpbinary
MD5:6574987895EE38297B12D96DEC8F9087
SHA256:CE995BA2551B6D9AE2D94235AAC743C9A51CC2859B5C69D62825BC549619EF85
2336Document0984757478.exeC:\Users\admin\AppData\Local\Temp\congedbinary
MD5:C31310503DCDBEC15380B817A3B3407D
SHA256:455B2E4C0BBAEF2127BBAEE91D65482A682DE515C471FCAE0FF94BB84D148297
1008conhost.exeC:\Users\admin\AppData\Local\Temp\main\file.bincompressed
MD5:6F4DC951BBB91DA352F1B1736B9551DC
SHA256:FFEEAA61D3E4E3AEEDBD1303757049B46E30BAD6445E6D78F02EFCE265071404
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
602
TCP/UDP connections
725
DNS requests
128
Threats
904

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2028
New Text Document.exe
GET
200
5.42.96.7:80
http://5.42.96.7/soka/random.exe
unknown
unknown
2028
New Text Document.exe
GET
200
198.12.89.25:80
http://198.12.89.25/regAsm/Document0984757478.exe
unknown
unknown
2028
New Text Document.exe
GET
200
5.42.96.7:80
http://5.42.96.7/lend/build13.exe
unknown
unknown
1640
axplons.exe
POST
200
5.42.96.7:80
http://5.42.96.7/zamo7h/index.php
unknown
unknown
2028
New Text Document.exe
GET
200
147.45.47.115:80
http://147.45.47.115/conhost.exe
unknown
unknown
1640
axplons.exe
POST
200
5.42.96.7:80
http://5.42.96.7/zamo7h/index.php
unknown
unknown
1344
csrss.exe
GET
200
142.93.40.72:80
http://142.93.40.72/
unknown
unknown
2028
New Text Document.exe
GET
200
5.42.96.7:80
http://5.42.96.7/lend/csrss.exe
unknown
unknown
1344
csrss.exe
POST
200
142.93.40.72:80
http://142.93.40.72/
unknown
unknown
1344
csrss.exe
POST
200
142.93.40.72:80
http://142.93.40.72/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
unknown
2028
New Text Document.exe
151.101.66.49:443
urlhaus.abuse.ch
FASTLY
US
unknown
2028
New Text Document.exe
5.42.96.7:80
CJSC Kolomna-Sviaz TV
RU
malicious
2028
New Text Document.exe
104.196.109.209:443
transfer.adttemp.com.br
GOOGLE-CLOUD-PLATFORM
US
unknown
2028
New Text Document.exe
198.12.89.25:80
AS-COLOCROSSING
US
unknown
2028
New Text Document.exe
147.45.47.115:80
OOO FREEnet Group
RU
unknown
1640
axplons.exe
5.42.96.7:80
CJSC Kolomna-Sviaz TV
RU
malicious
2028
New Text Document.exe
5.42.96.145:80
CJSC Kolomna-Sviaz TV
RU
unknown

DNS requests

Domain
IP
Reputation
urlhaus.abuse.ch
  • 151.101.66.49
  • 151.101.130.49
  • 151.101.194.49
  • 151.101.2.49
whitelisted
transfer.adttemp.com.br
  • 104.196.109.209
unknown
t.me
  • 149.154.167.99
whitelisted
www.likbez22.store
  • 49.13.77.253
unknown
ipinfo.io
  • 34.117.186.192
shared
db-ip.com
  • 172.67.75.166
  • 104.26.4.15
  • 104.26.5.15
whitelisted
accounts.google.com
  • 142.250.145.84
shared
config.edge.skype.com
  • 13.107.42.16
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.facebook.com
  • 157.240.253.35
whitelisted

Threats

PID
Process
Class
Message
2028
New Text Document.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 1
2028
New Text Document.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
2028
New Text Document.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2028
New Text Document.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2028
New Text Document.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
2028
New Text Document.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
36 ETPRO signatures available at the full report
Process
Message
random.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------
axplons.exe
%s------------------------------------------------ --- Themida Professional --- --- (c)2012 Oreans Technologies --- ------------------------------------------------
gena.exe
ret 345 fdhg r
gena.exe
er er y try rtsdh
gena.exe
td ydrthrhfty
gena.exe
hrthrt rtdy rtdyhrty
OachQTPSMxWLVqpKFAB9.exe
ret 345 fdhg r
OachQTPSMxWLVqpKFAB9.exe
er er y try rtsdh
OachQTPSMxWLVqpKFAB9.exe
td ydrthrhfty
OachQTPSMxWLVqpKFAB9.exe
hrt hrdth rth rt