File name:

2332123.exe

Full analysis: https://app.any.run/tasks/34dd1301-b69a-444c-8208-387b51b77173
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: August 11, 2024, 05:08:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
xworm
remote
ransomware
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

79626C0DDED9147332E3FD48F72D93EE

SHA1:

4132AB159194FDF04F4C72A9BC67D5BADCCD3491

SHA256:

DDC701603AAA77F271E61AF63A6B43B2E4EFE4948AA84E39981DD3316DAB8EB9

SSDEEP:

768:8Cd5PAzQhCWoycXrDDwdcM6t9Fm9YpOYh2QTcA:8yPAzcFox7Fm9YpOYwecA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • 2332123.exe (PID: 6496)
    • Changes the autorun value in the registry

      • 2332123.exe (PID: 6496)
    • XWORM has been detected (YARA)

      • 2332123.exe (PID: 6496)
    • XWORM has been detected (SURICATA)

      • 2332123.exe (PID: 6496)
    • Connects to the CnC server

      • 2332123.exe (PID: 6496)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • 2332123.exe (PID: 6496)
    • Reads the BIOS version

      • 2332123.exe (PID: 6496)
    • Executable content was dropped or overwritten

      • 2332123.exe (PID: 6496)
    • Connects to unusual port

      • 2332123.exe (PID: 6496)
    • Reads security settings of Internet Explorer

      • 2332123.exe (PID: 6496)
    • Creates files like ransomware instruction

      • 2332123.exe (PID: 6496)
    • Write to the desktop.ini file (may be used to cloak folders)

      • 2332123.exe (PID: 6496)
    • Contacting a server suspected of hosting an CnC

      • 2332123.exe (PID: 6496)
  • INFO

    • Checks supported languages

      • 2332123.exe (PID: 6496)
      • TextInputHost.exe (PID: 7252)
      • identity_helper.exe (PID: 8012)
      • identity_helper.exe (PID: 7428)
    • Creates files or folders in the user directory

      • 2332123.exe (PID: 6496)
    • Reads the machine GUID from the registry

      • 2332123.exe (PID: 6496)
    • Reads the computer name

      • 2332123.exe (PID: 6496)
      • TextInputHost.exe (PID: 7252)
      • identity_helper.exe (PID: 8012)
      • identity_helper.exe (PID: 7428)
    • Reads CPU info

      • 2332123.exe (PID: 6496)
    • Manual execution by a user

      • msedge.exe (PID: 3900)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 3900)
      • msedge.exe (PID: 7092)
      • 2332123.exe (PID: 6496)
    • Application launched itself

      • msedge.exe (PID: 3900)
      • msedge.exe (PID: 7092)
    • Reads Environment values

      • identity_helper.exe (PID: 7428)
      • identity_helper.exe (PID: 8012)
    • Create files in a temporary directory

      • 2332123.exe (PID: 6496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

XWorm

(PID) Process(6496) 2332123.exe
C2february-nylon.gl.at.ply.gg:62014
Keys
AES<123456789>
Options
Splitter<Xwormmm>
Sleep time3
USB drop nameXWorm V5.6
MutexHiXUfh5nKCdoxeh9
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:11 05:06:40+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 32768
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x9e1e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileDescription:
FileVersion: 1.0.0.0
InternalName: 2332123.exe
LegalCopyright:
OriginalFileName: 2332123.exe
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
215
Monitored processes
70
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #XWORM 2332123.exe svchost.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs textinputhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs ucpdmgr.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=29 --mojo-platform-channel-handle=4692 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
252"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5756 --field-trial-handle=2396,i,13804230555112915873,10754818423679536691,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
300"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5164 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
420"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=3872 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
964"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_search_indexer.mojom.SearchIndexerInterfaceBroker --lang=en-US --service-sandbox-type=search_indexer --message-loop-type-ui --no-appcompat-clear --mojo-platform-channel-handle=4696 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1048"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=3896 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1360"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6524 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1884"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=7152 --field-trial-handle=2396,i,13804230555112915873,10754818423679536691,262144 --variations-seed-version /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1884"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2784 --field-trial-handle=2336,i,6304410595950866456,3629067630089352526,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2092"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=video_capture.mojom.VideoCaptureService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=7456 --field-trial-handle=2396,i,13804230555112915873,10754818423679536691,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
24 784
Read events
24 478
Write events
302
Delete events
4

Modification events

(PID) Process:(6496) 2332123.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:PresentMon
Value:
C:\Users\admin\AppData\Roaming\PresentMon.exe
(PID) Process:(6496) 2332123.exeKey:HKEY_CURRENT_USER\SOFTWARE\3C54740F7CC0F23B53E5
Operation:writeName:CBA453460BE46CFA705817ABBE181F9BF65DCA6B6CEA1AD31629AA08DBEAF72B
Value:
005800001F8B0800000000000400ED7C797C1CF5916F75CFD13D339A9147B2E44BB2473686B12D0BD916C6063B58967C08245B48B2CDB9F668D4960646D3A26764230E470E215912CCC6494802848D397290E305960462420EC242205942C81DB2F18325C90B79B98FF742C8C27EAB7EDD734832B0FB76DF1FEFF34656F5AFAA7EBFFA55D5AF7EF5ABEE1EABE7A277918F88FCF87DF555A2CF91FA6CA2D7FF4CE237B6E8A1187D26F454D3E7B4EEA79A064632F9C498630F3BA9D1443A95CBD985C4A09570C673894C2ED1B9B33F316A0F592DD168F8145746EF16A26ECD477FFFDF7F6E79729FA3C58988D60B2690A0A2FDDE0648B89312CD92B6AEF4262A5DE9CB8ACE1F1F6DBA9EBBF2BFD2B57891CF31C8DDE91AF301DF0C461E23AA7A03BE98F6817E66196A02DF5E86B714AC2B0BB8FE79A7EA2BB6EAD344EC6B71F24E9A5CDDA0A318DA57D96F13FEB53856D64EBBBA1E7365ED9ED66FF35435BF63ABEB761912A0810D44EF5D4DA4B9FC9FE74A31F1463E0BF5E41CA2F0F253494FCE4583967F243F0FD74908F4E7E7738B572DBF805B3E6E35700B56F997D7B66AB236E81AA7433CC06E0433BC8282459E2E3C16612F9CCAF3098F85DA8BA6F2FCC2E369EC4489A713CC85D5CC03F4CF4E368119319A9B1C4C3FF64DD0F4E46290EC250079046DB8CA9C0C883819509C234212AA9013F4C88B499F6464F9EE3C5625985C8AD10510F44983A9F0D4A9EC29226FBC21E30D6F7C253D19850CA13F30FB95601D90FC69AC5392DD67B2EEAF04E7575243EE34CBD434B400F6EE2189CB38AB1106DF378919FCFE4948F70726A1A73FE69F8CE1728865DACB79090F858ACD130B962657B08BC8B09B714DAE646AB205F004B1CE9A6C2E8DD6ADA705F09936583F598DD1F5974DC679B14F67BD6A592FD1C7A027700DB13E73E734E45B990B01FE3AD57DCE914E8898ACA91879883B2478A0BD4AB42BE1AB195784436CDC21B62DB986D7AF8D59734417077A8D1D62830FB1A1C933D88EB9BC7C6A244F572FF0A64C3DBC5ACF5E5D8B4EC2B6CF44EBD41375CA0FB07D1E8FF43CB05CD97F2E0DDF47756C3FDBF892267A616DC515AF68E16073508D73B5D5ED751277F5AFE855E67ADE2B87E2E28657B46868FD71EE265A1DC5E05A7FDCBFFE4626B137ECF5ACFD1A8EAFB3D8433C4C31CEE649CBDC169765C0F8403CD0BCD6F5F01BB7F8C76B3925889439973DFBE09CEF95D68656CC56CAB84ADA1BC45E5AF719F2D4541CC3DE282B26FABD89E5B338A8148C079B870F615A7FB3219715F587EA98156C6755CE41D7A5934CCF2387856B8DB85132DE6E67999E3D33993EA75CD5C5CA86920ECF4E33876845C85DD7131DFF8E98A85731516B560485461CEBED0D2A3FCEC6EF53F0E4F3F885105231A253D2DB0748380D32F3022FC28233ECB4E5DE3EC34E5CA06404E83DA0444486323EAC2757736020F68311E3A64C12D93FEC6009C6921D2C91995541B3DEBC29A3162668D41B5E5B0CAB9B6377B2698204C5DDF541F1DA83F5F61631BA8A82CD46D0DECA63FED9DB16D1A9DB82B406CEDD21B272DE71AAD1D5D7787B44A7C749CEAE38A97CA1A6B7B71535B1B797A79F999DE206565729C6CE7EFD9C452AD19D5BDEB38ACC197B86A6F58C5268A6D581516D24997B5E42AD0FE1A499B7CB6B5F41B1377BEDDB28764F690D9FC4A828FB61DDE7D14AB48E1325CF2BA535BB9BAD0FAEBF8EBC458E38EDBCA0C585AE32675EE8A811AA0F798B6B942DFAF48536D4421B150B9DEC11BBABC868360C77B9898A31EF9FB2E234A736B06EE3AB5C52BA6BBF9CEC5BBCB58FD307EEA17A65B39FB80489B9B17F06DBC1E94C12745D7D72875AEEFA5B23860315C6EA93A898C2CDB30CE78A12165951E3CECF3B174543F05468F5DACB593AABCEEFF3FCEFA79FA07CA8165DF2BD92929DA3ECC6F3D9A1F7708B4F0BBB8F3D6238F731A17F46D6634C402A09DA034CDDC5D3CB5AAC62037773ABD56BA9D1DCB2F7A8D1CF30E102265CC8E0A219A7F86965A78B67ECF432132E6127D4E84EAD06E4D219FB9DCDACE527D7E842E6A3E20A4E1F9A67D68A930FBD81F9CD27E7BF9FF92B6714FD61662D9B91F508B31233B29E66567246D6AF9875DA8CAC5A1D845367646D64D6D2935B7031F35B661C7A90594B66641D65D6E933B2EE61D6A2934FF818F317CF38F44566FD0D13F632D8C72035E3921BBE8A101D9CB1D3A2CA4EE9193BADE44E4D275537790AB3868A840547903EB4A5F5B283EF5C3A47B6FA9D4BE74A3976E7D2792E3EDFB0714B18BE33B99FBC02ED449797768B3236FA5E53864ACFE5324AC5AA77267361F37E9FBAC7EA2A9EC97EBA95E45E11B9C0B914B3E4872521D8236C4886B558B121645F864601D18BBA8CCCB8DFB9033DEDCBB94B967DF1799FEBABAA135151BD942143F628674E94632B3F7722126A36426E5A4572B671DB159EFBAC6D73F62B26D920398F425ED81511E473860B07540F89ED1465BD759C1E175872DB20961D7E8B9767753A5D322FFF4B8E8929F5B7DA57B0A68ECC52E765CBA993787972CE5CEFBCF6CB6D768DC89A1D298B8F3CC08D17B05A0576384EAFF0F12ABEF7A54D97BDA24743CD6BCCEC12A5DB37DB2FAEF5D7F8930744152C369B3CFF59FB20BBED199F7B764568C5261E3F8B305E4AD7554509ADAF25E1872509C66B78D0B3EDA31F2B9D478740A92D3B03925702D6DF9A9C60B9CF7B729357B1B3EAA32B9699A15B6BFD46DC9FBC9AFBCD97457396F8DD7E6A935068CEF7A2211CBAAFF865C5BFAE82FBB5D7D6D5CDDA5FD2AD45931A926372196688D0A16BD0DFB0AF6565CCD96E2D6DCC0EFF38889EA6F3383AD987585DDE7FD110F740F92C3D7E2241C8616ABF9955F0E7277159EA7C07639C5FF0C0C31C8F4B9D3F332116281116A2EDAC2D236C66C205658411265C5324B0CDF65B78127345B2C64C5EC7CD50DC5F134ABE95E7BF9EF1703CDC1C06E56DE2982E42BFB7333D128FACFCFA89EA1AF3957ADC312D707789F30E480F9F584C66B361BA34D797D34398DABBD523111CD9F210E40F24E7BC7C988EBB0DFA137EC35AE5F31ECE0D755CAB57D4EB7EFAB61AC3B5B6F3C1805706DC197077BBF30DB4F27FCBD123315455913656AAB451EBE78451152C4F182A5A4CE714A6BA9153CA135FADCC13124212F5F5EEC29B4E32C85E59AF78482437E032C74B248BCBAB37D75906A93165FB3DC93E4952D7152A8FE8B4988E7CBA54B73FF4792F1E7D843565BF704E79874A8FEF54E6DEC8F3F2ED6BF3426735E49B38AE9ED87C51F2087B677BD0F553F8C456D5D5BDB19DA9F3BE52E779C5ED1220E72D25ADB58AFD329229E9773197A215FADDC44B50E37BA51E2235FBEF64DF387706BD5AD253C474BE229E5C44CEB7A45136F349F2E3E68ED2BC104E73D53E7D0EC39DED06401620F92EDE8C47CB336E849C9C5119AE45998D0BBD9C3B5DE6E47F81CC63FFB9323FC7E2369AFFE73291E568DED49CCCD977A364DFB83FFF6E7793D8B80D0ECF73F7C33CA465FBBD33E5632ACFC8C8882B1F9C9A91CD939D15E9A1D23ADF06CAFC37AED7DCFFB05EB34BE169C64D8467BFC95199A0A96A874E1A9F6FB9AEA437E29E1688DE876E66BD9D7188CBBF4F7643FEFD7254943256AD7FC52AE85B2A7502463CE07CC1741397AAFABE6ABA559F2C70843040F216CC5DF9951351DE5220A9D48313B9565543D374957BC5F9B433C3B7C14AEF89ABA8D6D31BF351838AADAFB3C61F509BFA169665945452C55724E4069E7D2BA3B595E8D20AF40DD43FFD03A5E715CF82D2E8D63F797ED09DBC8DA7FD20805B9E6CFABB4D17BB85CA8E4D175799C5B6D44123E60CBC75E049F2595EA2802B65D483B5819A40F276567C65A8541C35D234F696127B46FEDED01BAA8C4AFBF091AF94E2E693A02C74ED9EF1E0BB36E41E7C55A60410E2C80DA1A6CA104204551E7D9521F3ADA92123715ADA045CC4049DE3980DCBFF5E8982525031B96CDFBACF1FCE1A2AC5D4FBDEEFC5942EF5C02215538FB06FFE9EEDF80D5A5296440C6CB63FB1C0130BC979551AA550098567F6D9F215A55A99DFF32458BEE144C345DF273FC4861FF3B68EFBA8831FDFA863336A3875A5DE6498CC79F656859F48149FBBC451509677F5EE2F0C7959A0F489D2A61E4AB03EFCCE838B962679A77007BAEAF69DE4BE10E1BAD7E52F2EE3DF55C6677B86551D14A7FCDD3C61FEC3E20AC33CC4AF0FE46193FD11B6EDA3B229E7DA1F93AB7D0F4703E21B655F7DDC7F53C6FEB86CBB85C5731539F235DE2944E9AC6DD4E8F9F43FA8C327FEB374603FE1FE874E611D749F54D7C94F961CC5EF6EB8605A2AFCE4A768CAFBA85399FECDA8F77EA9C8ABF27CAF27B354F69E0AB9864E13FA8D265601653CC7651255E98AF08A00E9D2F154F2BD52C76C79FDC6AF7DC85B533E939332FEEA4FB35FEE95C8BE31A2645599CDB3932883574414DBB0EF237984AF82A8CF93A6E7FF01976BB9CBF2167E2C1F9CE4C7F4CB57FB0A507C01BFFA83F19BFBCFDDACB96F10D99E036D2DAD2D6B5AD7AC5ACF9400C130FA208AEF25B82F31E18C2C7E97F4179C4C6E38CF3D0AD82C0D987DC9AE7E7AD772F5BE76C9B65D5D9DB81E03FE4703F8E62C3FB120559F92B6A7EECE50880BFABF686BB820E5D9916CA4C6E7BABD9DE47E95A03F75285FF07B3F7EE62E8656911A1370AF3EF757BD928D9BCA9A20FD34F00E64ADBE20C387FDF747AAE917FC728FFED5BF2F14A427020CD7071906042E14D829F417FD9D1865097C9750F606A24698FED6FF8170984EF7BF8CF6370163F4A26F7E558CFC911391205D19B83F12A3D9813428CD812D5A90DE11DB6AC6E8E930F7F99450EEF531A5919E8184BCFF4366903E04DD8274AE9FF5B4C21F07BC3B741E92D54BBEB598D7D2FE100CD291D056334C0FC55E8A06E934F32158F17D48C6A86AE67687DF521DA41148AEA137875F8ED520D9BD1CFB349D19614F4EC65E8E85E9875A10D29EAADE86B1362DD71EA55D11F6C63EB46BE842F4A9A7ADB1E1683DCD07849EA18730363EEBE51832BFF643C8FF768861CE6478B7CEB3FFA57A1FF4F4FB59CF3DD02486FBAF7455982E35EE8F84C937EB25E4D08FFB18DEEC63CDC7836CFBF5D1346C6C3758C21D06DBB522CADC95B02B4CE7EADC3E2AF26F27EE7F66748B16A3AF6B0C1F96B1D16AA6FF217C02DE7E287402737D33CA337E5FBF3F524F599DF5BF23FA0E68F26294ADBE46E4FCD864FFDB32EFED22BF60B027CF98C5F09C59DB107DA784D803ABC5033799DCE79DBE8728465F35787DF71053360ADD6FB0CFF789377A049EA333DC17D92A5F26B8D13DBD5434FED93C56DD55C4F4C8B1EA1EB47539848EC68E555F0ACC27E1FC58D5E7AB2E456C9BC2EB8E1EABBE9E0CBEB903EF8259DCD3843E9C991E361F3619AB16A93BA28C85B166CCFB4C8CB16AAA15DE4B558CCDE62A12E8BD6185ADA600DF41634F30B656302454C1365200C7CEBF085647E7D02AAA0B7FC4BF8A7E19FA6F7E7E95FB00604BF88BFE38BDC77C1CF087BEAF01C6F5A7FD881FFA36E0A50273D5EFF1D5535AE00962F86981770BBC49FB01FA7C8D7E04F856E339C08BC22F003E49FFC3DF44375517FC6BE9E3F44B50FCF45B7F6F42F6F5DCCBB0121A5D50810D0A169F3B16F912B01B05AB357F16FE935FA38FB9D8CFCDBF00FB4717FB52F85560CFB9D85F237E98FF57174B8543C03A9B14F6882F06EC62177BCA371BD85053693E9DAE6A2AE9A2D35B05AB37BF1E5B10D0E983EEB873A28CDD5F31EEF98A71BF54E3E8FDA144A09267D0BEC5A571C614DE358BD5B8BB62CCDBB74461F70597050C7AEB52855DACB5064C7AC2C58E6B0F219BBEF55485DDAA7D097173E3690AFB7590B1F219C2349954BC7D9012A6AA650A3B1ABD4F8BD0DC950A3B468CFDDCC57E105D1B88505B8BC21E10DEACD315F64FC4BC4FBAD877C2CC6B5BA5B0AA18631B562B6CFB2CEEF9CF2E76B58FB181350ADBEDE39E1F73B1457EC6FEEA628F9A8CF5B629ECB3D2F36E17BB5734DB7086C26E165DFEE862DF579AAD55D8B745EBB63315764E3563CDEB14F623E1D17A853D12E371FB5CECA91063BF75B15BE92C60B3CE52D8E3B4295045AD2E7673646B204A9F71B183C062B4EE6CC61ED7F7453BFCD574818B2DD74FD567D19860D7D19DBE9EC02CBAD1E59D613C801D7FB760281AB43EF09E124CA35FD34581387DFFECD26AD6D04F04F3999ABE13D8D20DE5BCF275AFA1B33694A2AE86B66E50E322B45AAB11E9C7820C51AF217AFF9179743FF11B619450C8600F68CCFD66886152DA171AA5766FACD4CE5797E063D2BF492F410DB17A5944836DACD53CC0302D039C85ACC470BDC076815D02CF177821601DA5A49D117885C009C0F974036082EE1099F708BC4FE09380A7D2F3D2F345A1FC4EE05181B708AC12385B6083C0535C3AFB74B6C00681A7083C4E7BA297D333F4807E05E0FFAA9EA097D0FFCDF4A2768F7684429ACC02781BC501EF407FA6C4B54B719EBCA49D16F934CDD376E90F40D615388D5ED2EAB01ECB645413E093803F08C25BDA6380CBF4F1F0F7D0FE58EC47B44AEF8B3D4FEB7596DCA4DD17FC39E04782216D99F6F1EA59DA32BDCFA8D3BAF439FE20A48D05E783DEE95F0438619CA6AD2FEAB342634D56A3FF1946A7C632BBB4266DB1B913F0B8B647BB502434697181DCEED2B91DD746AA197E3534899E93DAF55A4ABF0D392AA33F167BB736A19F66DCAEB58B1587F52EECD176ED8BDA67B5C3FA72B46FD06F0B3DAC1DD5CFF23D40137A2EF615E13EA1DDA23F1E7D1AF009FDBBDA1DBA0EEE1DFA02C02EED03D53FD2BAB4338CE7B57BF494FE33C0477CBFD434EDA7F0DB2AFDC1F003A829DE6C327C1AF03EFDA6E0EF2193F70E5BF4BFB5F335891CEDDE58B57EA1D617A9D353DABCEA05FA2D5A9BD9A41F27EE99D226AAAF8707268C53F555FA7663B97E85F678E46CC09F4537EBC765271ED51B670DE84FEA4F1917E8CFE88F6997EA3FD4D52C5F0C2ED70FEBF3A357E8CFEB6BAA0FE82FEA7AF46AB4AB7D07F4DFE94F843FAA4F685FA9FE24E0EDC126C88F461EC079CCFE69A6ACF679BD99FA228FEA6D34AFFAFBFA06FA87EA9D90794DF47FA27D55F0B7A0B36E6CC57C6AD758C397F4CDB139BE3BB49FC41A015B624D3E5EC1D3D0AE8F9DED0BF958ABDFE9B707B70B7D27BCCE1EB84F7BBB6FD8B7CAD5B96FD67B7CC75DCF5C16799F2F23ED0CBC1404F717DA477D37E88F1AC77DF37C4BAB4FD59B44E661FD2AFD002C7DDAFCB96F99EF28CBF15D477FF0ADF2C5A32F01BEC9F0F91F91757F52E07A5FDA68F0B7FB1EAA5E02B8565F067857A4D5FF8CF669632DDAD7A37D9C381F1E27CE83E7FB7EAF5DE4EF96FA6000B6EFA4017A6BF09D68B3B4657417DD6AB4A0627A67A005F5CF7B0117D0FD804BE861C015F40DC03502CF164A077D07F03CA1F40BBC987E0998A6FA600B5D4E4B829B90732F07BC9AC6821D94A709406E7761AE4F1869A1A4859201E54BC6A4F4BF8EDE29F03D02B9CF0DE0FE93714CB87709F72ED0DF0DF80969DF2F90FBDF0369A71B5F969E8F0AFD51F4FC0E20D39F14F89C705F10392FC8A81744CE0BD23FA4DD45CF19D769328BC6BADDA5DD46EB8C47A5FDA8C696BEA071CF2F0799F2E5204B7B4EDACF499B0C6E93C1ED84B413D2DE24709FC0491732F798B4BFEC42E96F72FB5CACCF85F437F0E7DBE97D382D1E45F63B531BD4AED06ED0EED6FE556BD5B7EB8388973FE9615FB3AFDD37E01BF51DF6DDEEFB94EF4BBE6FF99EF5FDDAF7AA2FE43FC7BFDDDFED3FDF6FF9FD381102F8E1DAC7906A98EF0CFD9141DC10FEC51C067C3A9C058C555D0168850F003EEFBB9AE9B1C301AE941906F4B7A1CAF2E3CCD2459A2EF274FC86004DC40F7F072ACADFDB02E477B5D580313E61511DD7520BEED3372076EED79FD65FD0F7F847FDD7F8AFF31FF5FB274BDFC8559FF746CBBEF3CCB8BF493A54D2D45D43B88C76BB7FCBB47EB7FB5F8E4D1F3B1CF5DA3CE0E92A7EFAE187AE7EE8CC1267E1347A46AEE372253A88EBA5DA3EFFA5DADB94A8542B9DD2D5B76EE52ADADB9D1A1D1C4A9DB277AFA003ABA8C3CEF157A077A7B2E3D63E50461C2B35D49FDA6FED1CBCCC4A177A1DFB4066C872C0EAC9A41D3B6FEF2FB4ECC9E4D6ACA6AE5C017060359D674DC8F0DE54C6D9B79A3A33E942C6CEA59C0920BBD06B6D1B0D5B85BDBB06B6AEA30D3DF6D078D67A137567F2855DFD9B695B076DEFECA42EFC6E8796D8AAFDBDDDD4DF4D7DED3DD43F912F58A32D5D3BA99736F7534F3F75DA851D5B06A8A377176DC3EFD63D74DE960B696F47D6CE8F3B16ECC2F4F9313B6FEDDDDB95CB1752B9345AD401A30A952418C6F675A60A291ACDA76D279B19F4E6EBB0B3594B8CC8B76CB3729693499759BF3B931F4F6537A7F2A06EB68633B93E78CC751CB50F0D515FE6B2DC50CACAF6A472A9616B488C879B7310092C932F6F43DB7411ED9FC8A5471C3B97B98A79C0AD1C248E8DF1A5CF1E07ECB047C7528ED5631546EC21DA61150EDACEE570B1E5EC4FA52DEAB3C6B27C55F67AD68A02DBAC42111FB2F6A7C6B3253CE335D0697B2A3FD2610F5994C7A01E6E7464C6462C479AFD16FB459A2CB3C7CAE761A13270DC71AC1C648E8D17BA53B9E1716640DE96DC810C4C1A056F77CAC9A406B316165BD648DA9DF6385FFAC67385CCA8353031666D4FE586B23296B1AD8E3DEA5264CA5426A7428857300D055C8C990307ED6EAB006774F5EFF474D8911A55CCAD99AC4220B8D81E56468E97A3A9F4482657C277F66F1DCF668BE8AEBCE508A262054A0C8DA70B42412C59033082F6389982D50D21E40A63436474A79339A0300C2CD8693B2B886B2BF5DBE9CBDD66D7103C96D99FB11CCFBFD902225C96C56B3B56DE1E77D296872354B299748A0317E15981F7C32FFC5C4FE8BC5B2C6FA3D0E6AE9DFD7D585870D802DA329429D8CE66C73E282BD45F60A29824E107D739B229401E6A2F149CCCE03858DBC63365D8762B3B86B480E82CEFE28DE2F82A913BADC1F1E16178D5CEB1736762B21E25DA14054B0CA887CD99A9A0B5E7F3D6E860766220532827C32AEC5167482D7E99E24876A58098418C931AB24653CEE525D640CAC1026D75D09F77E374C320138B395D1647E16ECBC963794ACC9E896D8E3D3E564A41D3C7755AF9B49319AB64AAA591B5C662A6AE94567EFA603760A7333AECB10927333C32230B5927375162B8BB55E885CC60269B2994712556364F1454E0CAD12061AB5A887575B41451D5D8921BEAB3D216F687975515D2678DDA079400CE879BC7F7EFB79C7EA44821B9BDCAA8BD08732F91ABA4CC842DB9B43D54C6712D6871FDCF1C37B7AA07E03460BB0D28E8B6FAC707F31EB3DBC665343FAC1659C6C2744E9ED8F38511EA65C0E6775BB9613495822E322CB6380732699C99E9CBE16724FE8E54363BC818422C97DF6F3BA35B33399C3359E4049501A40567CD7C16B5F44CB832F32D72226070E9401B1DB37348289CBAB338B959BC8A9096A16C967A116DD403473B13B0D54A8DCA845D184A3BC778CFC268250A1247472D7821DD9E1DB6B1D023A3C45697B0AE0E6762AC6017AD7093682F6253D02DB9F1D162E6C21139B38E2D08F2CC708E7AB3E38805C951EE52B9F23C0C87E981324659CAC3562AC7DC697066B614CFCDA21B5CEE740AD4CAEDCF0C8F3B15C46D597B3095CD5C5541ECB3F6BB5B96D4C9CF679E0AF5D26EA62D57A62DD9BABC89949B3129B9295CDA724828AA0A2B4790FEAC658D517E8C520EF5749EA1DCEC85915BA6D1287BA0B274038DF3EA34A2277C1AA367628F35E8C5D214AEDA0A9BC73359C654548B157DA51585E90EB6080721B7A63AA3DF4A39E91196E57978C8EAB45500F0E122878748D83536E64A6703C82D31A48D5DD9A9AA183907DC6E9E49C4DAF351E2A23D13C5266FDD832C0C079EE316815B1CC7E631850A7CAADE1CB8BC176C47D53545AC1D2B7B405A2D6905E5D2BEA57F6FA795966572DC92AC84331749A9825BC25DD7746652C3393B5FC8A4F33C673BEA9029255FFE24C9A0D392D513AF94AD2655ACED49C656940D6ECF296953E6B7C75E4790B7A227937252BE1B4B7977FB23B54DA715092D4E91A54E5C0428E71068A5EA53F15D67C6B17859320AE5E3491ADDF6306CCDCA9ECBBB05D8D66C6A384FDE9B5095AD55F9449C64DD26F63B8A3394CD5BAE80C545E571733484886CD98A4C9297DB2B94ACF9B23C25D396A760EF3855719F975B23D1076D957E6D4706B91BC02D7C5931D497B8E3701803BF776422CFC678A4B294A70CCB533B6642413EAECCDA9CE26A79A263844B182EF45C7A2F6F112E60A7D25C1CC6203ECA760897956A97B83C2B875F97327523C189EE46233731AA13DFBD2F624BB03D33E8AFB4A6CD9902F523260BAA8656FB9EBAE4D844183052664D7766BFD56B211E7205CF03250DA8EC7EA4FCBE45DD3F64D29777E03E4B54E013BCCFB60BD49DCA17FAAC416EF6A6B8CAC3247C87E6DE2A17520E183640FB20C3EDD8AFB8A342B6A11E142E3BF8FF177BE508B739F1CA2DB74CB9C33E580A7224A776C7494D0807E5B354387C4514E4507D70B30F9E421532C16D576CBF951EC7D93BD1A28E8461273536A26478051CB911B135359A01A696E1FC71384BD96D1752592F78541940DE7E29CDC85D07E162B4B68C8E1526CAF6029613710A1251532F65699C862943396AA13E429D4636280EA5A54DF3BAC0D90F1ACE1A4A119C85768E39FCA23FD24B5DB483B6D139444B3A20CB0607B743271BB3681BB88593F3E7EC92F10E64E2461FAD049DC5DF023256D2467A1369B5BDD4319517D949FD5EBB9675C8809783549756D70B79B66B4FDEA3CEE99499714380FE65D24E9B20F5733AF5E0E7741AC24F82B6E3E72CF41B056429D4D88D717948E884F40C1D10AD8BD2E76D07BD137A59C24D412B4F1B6FDC2E70377BD4E836EA05C5C33ACAB1055DD040599481D73222D3EBD927BE70B1C6CDF02C7B63B7AB8DF2ABCB5DEA717995B3F84D89AF3D3FB8BD96F5C3F6BC504649796E08F19006658ADF1B7B80A769446287FD38416325EE826E915F90D90621C52EADC8BC76D79A03F87520BDB42A5B8562D141F159D16B0BD45CEDB21A4EE54A2EE904BE1FFC71F447FA119D0FBA71E4E9DA2131EDB87E64DD50CE1567E55DC05EF062D2F3EEEE7219D52DF08055B262D1C9A2788BCC441DFD6875E3B703BE49D072FC6E85377622AA12B447BCB68656D35E7879447C9E81856C750F661992A8A179E511B403368CC2974C212341CDA2A39A8DB56812EA36FE661EAE3D7C6D57F30CB91EB904549EC5917D6A43FB02B1555BA0E125D0CE7157F8A0C8BB1C340A247896C9DBFADDEEBC30ECC699445D4253A7EB8769962CE42558BCBCF44C8B3925775D825077D0E3E4FC1160050417F754CBDA019A2DF35B70810A534E6243D8601C928CB3213C7294BF3A15ED28A352DD7E37CC78F9AE94D0409FEAAD15549A634B403B6E20A7E07ADE369C703C3AD54D4828F106BDB2345B75651052EDA8B486A0A3A713457BCA6814EF120963924259070A5CC2EE5F718948B2C5BB1C0C69D136037C025E50E1CC73AC26DAD8EF6EECB4042907DC7ED7E6044DDF72959B9BE60C49621A93AD3051DCECE46B260AED90B560CF6D96B551734E1437D05240F630C7863A4C86391C9B98DE29633F233A4DEDA32D9A495E29A46911CF5C9E922AFB5375A72483CB41E1D5A2286FED310F1BDE4EE741DA85D864DDD8781DF04237DA3DB87620A17749E85F82563B366627A297AF4CE904EC479F3EF4E9C5E6E0C4B94356A0A4C925E425545AF2FA4993348A976FD528BF0E58F4DA2999E6CC9CD069F2BAFF5AC3BCC07224EF549E9FACFE25D48A5098E95CA2265EB08404D820AE07C5A4846CA971D928B4ED8DE6C5DDB2A12D8CEC10B30BA247561CE548507A218A103CA732A34ED5B845241D705306CBDD488B499DB3ADFCDD5123091D96612376B81B3009ED7A9862A85E34278151BC359290B90CBAA610C036F17F561F716BA6299CC604F463ADC6C5B353B867BF961FA69E835336ABB10395493BD1CA5E19D121ABDA8F561FACE7B5565130E04ADF25AB4F81B5D406BF2590684AAD7568936FB99C19FDFC07757CADF21AEA075F08EB2F3CB275D3DDEFADFBD55F1A4F69247F42D34CB85A0BA0118F331A63A00712BA168B09B5DD48F8D18EC5827535EBB49A2A7531D525A52E6D7E031C7F826A895B2683148336C3F0D55CABD75C1B205D6F683048ABC9C4277F8513A866F277064F826B001D270F9BE04DFE09FF78DC5C56A0616E100AD44CBE1434F4869AC9234162EC08F48DF9D18CF157FA64EC91AA844F8B1F0EC40F87E287A3E0993131C00C928F359F9508D64CDED21830CDF8E1A69AC38D0DD546483775FED44CDEC092139A891E30A03180E1617142C080541E8409C34A93DB99DE5065F86B266F6E0C34063014DD6326ACC334B047C70CCBC209BFE94E16E3AE478AFF6246502F0DD5D90A96AE9B86AF3106571C09931F8D1886AE87EE662CA6633230EE884F7E984D278A4113E03176E1E12E4CDCD0D0A0480D0102A94718E7F39FF299FC30D4C52A327997B8FC30666C403F2DD6188B1B0604DF83DFFB6A263F0BB58E48974F09BC4FE05318DF10838226DC1933CDB0E16B68AC993C2E6B41DC92C92E8D40542CAC4775B53A11CC126D60108D190656EE8EC69819D3C559D4C86BC74A693074A91165B3BFD010ABAB997C043ED4F5BAF8E46368E0F2A4E03C0AABF705B1F10B31C3EDC8B1534BB55A24413282DB863B56D19E2CD258102CD1631CA0DA6CC364BBA19558FE944C516504A1E7335582B0C3269F812155302F7E989D16AB8AA91EB1F8E4775D5FA185C08C89337C0DB1185B1C6BA831429EC535933FD4BDBE876FA835C2150CE6600D1A80FD58F49165D08331156A3F0E193EB03E2BE339BAC4C9514498BB52878FD4C01265CAA7BCD1D86E0D2C380A6DB1C6BA0A3B89809BB1AF1A03D2BC051BBB3110F3191A6FF11882D10872443E5F33F9D39AC917253883DC05FDA14C6380558A1FFEB004C58B66C2C71CEC0B43D3D9AF0D68C896CF040C7D2136FA420ACCD26821F9C3DA42824A5808D22553D49281EB28AEEE058B845EB5C4F30083D807AFBA64F7BCB6E76E30EF3D67EF9BE3DF0D9F65B889C7BD9AEE35E55EDB7CC19A6B39440EA331971B37E8419DAF47F560D807C3B87D33981BB8713B6210A90AC0649062D0C6E05A59F6C32AC91C66CA5C93020D31497D42BC05410B676013F216820365230582249E4270D5648C591A4C86D1AD9AA6CD82074C9ECCE4C94C9ECCE4C94C9ECC94ED0838D79F847B4CCDFD2B690BF92B79037AFD1E2735B6C3CE159F560F8CF063560DFD0CF9DE425CA3AA8A6758F20D631C691AD514DF2425BE724F22B1BA75352AC9651A9D72E69943436DADEBD7AC6C5DBB6AFDCAB6C155AD2B536B8756AFDC9F1E5C7BE6196D6DABACB5671255618A552DADFC83935DA3F92D3BB60C14DFAE35BBCFFD37F27F6680A6B1D94516BFCFCCA626F8BDDD2C1E932872126D7E56CEF4BEA23D57A370CFC480358AFE05CB5C559CAE5DA335539F41B60CD87636DFD25F70ECDC7076825FCE0E794CF739B8B96AAD27E1228DCE9BFA30B4BF303E94B15BD46B4B48721F9AA8371C965324F403642D7E2BE8BE29B59D1024AF72459B9AFBBF20521AB5790F1BADC196E25B1FEF9532A6B05363DB0B8531F514CDA3D74CFF1A44ED4CDF9620C2F689F44CB4141F9A236F510C84F2F729B250A0C9E378AF43F9C3654F4AF181297FF84F517DE36BBFF9222FC451FC66A7B9DB6BF1B72A2CA739E17D39A339E12D7D9B727673C27D69B231678D179C54B639D13B3E08FDCEB32606ECCBADDCC6C133CF4C9D913E03D1B6A6CD6A5DB77EC9F4C9D493578F0055CBFFF65F6F7B27FF639D9FB04BE47FF1FE06E20C9FEFD8E5D8DE0EDBE9CC66F94B0BEA4B269625EFDBF8F32ADFC9CC9A5108A9FF9B34D7FB2B8B6574F65BEB0C74FEF0DF0EBC009C0D657F3F71838FBF1ABD1B751857BF5B50B5F5BB15FA5EA9E9B7AABFBA485FF0FFE6152547AB90798E8BF11789A6FC5944EA945EBBE5F68BABCB6CD9733AFE9C22A306A4E6E7DBEE6CD94DB8FADCEBFFA07C0BB85F2A717503375DD295D2A7B5F8D386FB00AE28E78B3F3AE47674D4BD6FC8BB921797F1C664FEB21B50F7B359BE01E6CDA76EFBD2A2C758859E277DB6286B6196C998725385CF2ADC27B4167F79CE38FA77156FB273EE73184FB393CDC5771B59CABAEBCCFF0FA41BFD87657487DC9A4E88E6C3F2308066A025E81EE2272FABA1C76ABEB9E7BFBC542147ADD490DCB1A5E4694DBEE8AB7345EF9DAEBC8CABB76777EEDFA5FF59E2F793DCD4BE8EBFDBC4DF9563A77A7DAACFD7C918F530C892E75D597930F07AE3FEAF7EF6A9FFFBF6C7735EAFE3FFFFFCBFF8F937507F700900580000
(PID) Process:(6496) 2332123.exeKey:HKEY_CURRENT_USER\SOFTWARE\3C54740F7CC0F23B53E5
Operation:writeName:CC52384910CEE944DDBCC575A8E0177BFA6B16E3032438B207797164D5C94B34
Value:
004A00001F8B0800000000000400ED7C0B785C55B5FF3A6766CE3933939964264D9AB64999D287D3260D4D5FB4D0D2E6D147A06943D3D207423A99394DA69DCC49CF4CA0A15227A2572A96BF28782DE8E575F5D27BD52BA250540444D4A2A8E85FE47AA182A817142FF8FAFE8A5AEF6FAD73E691A628F77EFFEF7EFFEFFBDF69B3CE5E6BEDBDF67AEDB5F73E99B667F7FBC843445EFCFCF9CF4427C8F9ACA5BFFE29E0277CCEE7C2F419FF93B34E289B9E9CB56D289D8B8DD8D6A09D188E2513D9AC958F0D98317B341B4B67635D5BFA62C356CA6C0D8502735C19BDEB8836291EFABB1FBE6416E53E4FE7C6824A2F510710CDA105F600C4DC49896AA4AD3A7A13959FF48843E78F87D6BE8BBBF2DFF2B3F490CF897EA22DAE311FF29CC5C83B88AADE842F267DA09F51811AC03756E0AD79F3609E7559EBF4155BD54922F6B4DA393B49AE6ED0510CED9AD80F22D6B6DA66C64ABABADEE1CADA38A95FC7996ABED2EF3C37CA101F6D5A46F499F9444AB1437F3927DECC67A61A9F8A682D98476ABC010D5AF0B1DC343C0B10E8CD4DE716472D37835B1E6E35720B567917D42E522436E81AA1C33CC06A0233D04C5A89A70A8F455833CFE47984C742AD73CEE47985C7D358B1324FA555E0F98407E89D129F0566506F996563FA916F83A6C6CF05C99A0D9043D206AA8C824FC4C980D21C419254851CAD483E97D402230B2ECB212A5A7C2E46E741500B3A53E1A979EC29A2E2785DC6EBC5F113E9F1106408FDFE29A7B53A20B9B7B04E71769FC1BA9FD6A64FA4FADD69E63BD3D00CD8BB83242F23AC46007C4F013378BD0548F7FA0AD0D31BF616C2781C6699D6020EE1617FA9796AC6DC7833BB8874AB05CFF842A6C65B014F11EBACC8E25268C54A9A019F2903F5856A8CAEDF578870B0CF63BD6A592FD147A78BE1673FEBD330B531B788B910E0AD73BA4F3DBA1A220AD109230F7387187D8DC86A13EDCAF862C61DC26136EE30DB165FC2F15BCAACA9A20B35C49156DABC532131A5A47D1CA91FB8311D882FE701E773ACA36A7C055B7B8EFF28168F32B7DE864D2377CD9D7A98FD75D7DC062DBE12FCBBE64E7309D3A34AFC02F68B439EE1921B41BEB04C6E72C9330FB3A7EF8AAF6256032790A33B1B5C2FF0C6743DE25ACF71852B02C2B62E426BDEA93A2712218A4FE391452BE058A59163B09F02A3149A2DCBE9627A798952C76DF6F9EF15F113724D42735A09682D9A23C5F59E6AAD9175507F5AAD3256F2DA3D1C91B09C5642FE950F7237D1F1260CAEF546BC2BDFCB248E8EB5966D99C3F9DECE11E3610EA38327AD086344D202E37D115FCB7237E26FDEFEE7967389122953F7FDE081A94F9773859AA738CAB84A5A9D622FADF80C15D57438BAD5251924FAAD63F92C0E2A6911AD65F0300A99B745974773FDE17A666917B12AEBD1756E81E9B90D68D6EA11BD6CBCB5916516ED399BE9532B553DD7B1A1ACC30F269943D4EC77A37CAAF33F9121F54E86D41A135244E114A1F646A75E4FC1CF93F0E40BF88110727244251410AE3D5C27E28D32B3BBF203A49D65E52F28AE7B5486198E0C1F7D80643F820CC7F8801A9FCD89810AA505F51BD3B21A6C081D8977B34466566946BD7163DA098CA6D7EBC5B6185637D5BA984D13441377D76BE2B507EAAD4BC4E82AD25A74CDDAC4639E7DE345C26B4445E531B3C5ED5DA1436FA3BAA2FD5F0125C4BA3BF5CB99DEEA2969626DAE2C8767778A9B585BCA39D6F1D76B283985B7B7B267151967EDE99FD43344FEB34507462D25D949A6C59CF81076BE69DB8BED03147E7BB17D1B858F97637812A3C2EC87159F472BB6681475F2D27299B5B6B2F5DACAEBA818E4A07D1E07B414E82AE3EC810EE9FE7A7F31B87A45D027075A7702AD4F0874BC4FECAE22BD45D7DD70139572DE7B46C4696AAD6FC5EA3FF311D78DFD02B28E15631FA10F1DA7FAA2CDDFC7F1A2DACDFD38DBC1E54C4A765D7D7C9B13EEFA5B837A7CB1D8177BA1EDA98796AD3162F76EEF3FBC6CBA11AB9E7E817AE17779D992436C3DB0C254F90C58F748F89317FEC4E5F0B00B3FC87569A330AB4E4E7F9287EF5CFFD413ADFB9B5DCA8577708F79D2E3C427BEF4BF5BAB99F3C3A77FF3A7D6B615D520EB36769691FAF87628B6F276EECCF55DB72F2D531F66EA8B424D96A93F62EA93423D54A63EC3D407847A5D99FA6BA6DE29D41BCA540D84153708F56FCBD4185347857A7B997A3E53FBB966C7CFE1F0FB0F5FC6A9B0438215F1B634F86375E04ECDEDE42A26BC99BC4B63D4FCD228DE2B2AC671999E16F1C9C0FAB30C7C8D63EBE4C18A1F735B9B7A6B7C177A680DCE33B79B91692E71BAF3E4B58301F7FDD501F1369E67C57B8A1D97B81DF999BB9C3BBC55AAD83487545F5F3F95CF971A35EF26EE7785EC1D3CF24A29D311A33EA22FF434342BF587FB79F8B92CBF7921D5C7F770077FC46FDF0B8FF288843BD700F79BCB499AE4B990FBA79ADC2510A048E0ACC5A058FBD9AD0F20834EE0A7C9ADFDB58B3C84C5C467669C3953BCA0EBAB50844346ADD70FF77B6BB5E6B7E811ED560BD7B580EA04974F01D803B110C108344728A24D7D9AA313F1B57D774AE9AC1D9195C672F7F2586B90DC8338F119D8E1472BF84315FC198BBCC417C45A675DE6D2ACD974D924AB503DA65BFBB82818F5F1FD5205F5FA5C4632CB3FF507EE5ECACA477CF57E6B987B467C8153D309796744BCC5EA515149644EA74EB4505337974067BFD8BCC3A919ACCF5B9DFD3352AC7C2A2A5D96CBB52824C58CF4A9A248C8AFD6836D594CF45B236EEDF2B7E87E7746A7C8052616346D81A3C31CAA5BE9CCABE2F4BE7E735907F890EA5887DC01562167CB76A11B87F9282F85D6CA8164E5A5CC3658A3F2B4AE629D54B827E2AD8FE00C615D2D93CF7453C74711DF5F3ADF87E8820DD4E4D4CBFFB20E07FFEFE980332DC9F925E29CE2D55BE5FC1E249CBBC7D0C0E31A3C6281D83CCA1D7276D4F8DB242E605DEBF4382C6BD4B0DE8EA761158AAB3D16A36F9035CE3A44BDDFAE2DDE08E3EF00B81687766FD41B5FE0D6A6967511EFA1697CC4730F914BFC16AA6800545C78BD87104C6FB1DDE4B4A7B38F9A79A1FBAD774ACAF00D2D706A61657238179589C6E4DEC5EE72DD5291AF8BE8D6278AFB5A98BEF634CD2AC6E94AAEAFEC236FBC852F939AF537ECABF8BBC5DDD07E2E696AEE7A8942831B050D6B397EA43200C56C3F8CBA17F0ECCBDDC0EEB43FCB9B7B8C0BFBD4DC7BDD9A6E1D658F1A77B967855ABD1E354E8F1AF11B455EE99A551B8806E49E55EB7764D706B548106961FD2FEE58BE7C1D9A78F98A049DDBC63C2E7FEFA389F730FFD9EF61FE37770F3B15A64810B521583C48862306503D7E9384E8593A55E33AA8AA7C7F941349E9AC359D8273A9817DAFD2DDF48EB98A5B43DE460F2E73DAB0869E5EAFD438F1F1108A0335707CA2CAE93A24B3AA22D46B3935F443313E071DC2C6E6FD41957E689660E7301632A63EED9FFAB464034E3D11AFE435875332AF5653235A03DFC570E185513E58E1738D8AB8EF19783DA9B48EEA763B758E736518B9324DD6F47F31D8BE7A2C005F549B146C030920C1D6DD60FBE3E77100DFCFCE5FC40B29807DAB22338388C45BB09739A9595BCECD2A8A549D999B9140C4FF2632C7FF1732473F7BE6E86F3E73FC70B2BF9C391AFB7C72E684CEC81C59C3ED292733AE77EE1F748B9313E4E41111B3BF859F250A919B44F2AA6F359F4140EBACA0F3A78DC782B64D71DE7B3A7B3C5709CE508AC41EFF48E378406D995B1F6C9EA2EA16EE6C012D11FB8042CAEE803E75675057AD9B413B4F6D7EA1B88F4739473837544FFC1636FC83E58D9ADF5971F169147EFC6FE98CF7704D4CFF764DB18A967855C5BD5F8D7F882ADECFF1B964A6D0DFEBC3AC534E2B41BDC588C39AE640B38F54E9388F3CA7EB982DAF1DE7BBCB50CE14D80DE81C197FE8564EC1DB389BF5F71A8EAC2AA3654A1CEE6B0E3A6CDDFAB053827591BBB5284DCD7D84AB3D7759D09A43B0B502BF0E58B0D893C71D6C06BFF284F11D7D177728EE9B53B6E7AAA5AD8B5A972C5AD2B692293EC241804EC0F4D9D869E6E0D4F00A2E19B3FBF2763A3B98E31E3558D6DFE0186DEFA36767B9F1DAB0BD9B5FF7BE02FC6B3AF08E8C35508EBBB2A3E9AE263FE4D0EBCA12DE0079F67E672FA4599C4FF8611F7CC43DEF7539FEE0779EFCDE4D8CF554B41597C74FDDE539AFA5BFAE3B966934CD97ACD2E86F04BEE63916ACA6C7F80527B57957FB35FAA3C0611FC39502B70A3C28F4266F13461DF330FCB2503EE01DD102F405CFEDB856253DB7EB01F27A6FD7C3B4D0F3EB60985E0F3C10D4E8E3DE63686FF4AEAA0AD31EEF4645A3F3C351234C5F0A709F1784F23B95294D340A09FFE0396668F45DE8A6D1610FEBF9AEC07580EFF1C7FD015AEDA9C5BCFB95359A466FF5478D000D853D618D7EA17F0739385FFBBA16A54FA85F07F70466D1E8D5F01A500EF97741CF1FE9DF00C5568E546BF4733FC376E34875944EF879D4FB820CBF1AD805F8E9D02E48F8AECA12DE21F01FAB5763F68D32FB1F21334CB3945555017A593B160CD07DD59E70807EA5327C4E657D3EE5638B0643ABAAEAE9FD4667081ED358CE253AEBFCFB2AEEF36BE81CA0B5D2FF2A99E543C4A36A431BB1C93CA130FC3224687424C85CA33A6A44E9E5F0D7B57A9A176499D70BFD7158BA464905388E0FA8DF01ECD5E6C1BA53019E6BAECA56B7186CEF3481CB54B6BA29CC96EE54D96AF2B3C786F5A6AA28D901B6BD2BC81EBE3BC4FE5F8859387BD29243C555F22B2353DD5DC27E17C854F7A0CD795D43178533D55700F34832FE5DD5CD555720330DE1C54399EA77213F83C2FB7E35F73450F7B8C6DC6FDC6F30562D52178418C3D949780361C6AA718B60DE77AA189BC2B50CE80301076B12DE937E079B2F586F356375D42A3D71BE25C616930FD84F820EB644B016977701F9B0FCFE5DB07A5A4501F0BECA7251CDD708769F608DC0788D6D909E335DDEE230F3665207EAF7C2409DB78DBC8126C086C05CC0F58185DE086D359601D6795602FE1FE5226F3DEA7907E0150267546F00AC11F83362F84581B7097C9F7231E08FA90770B9BE15F09AC076C0176997F7D2C2ED74A577162DAE3EE5594E9FA204E8B87B79353AEDBB123014623837F83DACB9B785F6A1BDAF9A292F093C1866F87D3FC3EBA57D8171A5B7372695A3E17CAC4785764EC006048B34AC0E3E0CECBD82D51A3F0F64BD0ADDE3623F3272C0BEEC625F0C1C04F6BC8B7D2F782DB03FBAD878E01DC0BA6639D89FD47703BBDCC5FC9EA3C052B3CAF3A974CDACB22E2ABD53B07AE3E3E19BBD2A7DD81D3723C4D87D13C6BD3061DC2BCE38DAEF3FE69DC8D369CFB9E571FA19BCB79DEB8CEB0D33EFB5D90EF692EF2EAF4E53E639584239EE3568A78B3DA27C0EB57ACA5B1CECC3CAC3C8EDC6B8835DA031563943806AE63BBCBD90E2DC2D0A541FFB66E89FBDC112B64FFD8CB7AA84ADAAFE82B7866A5A9C711FF43FE2AD29F19E0B7FD51B71B1DAD853E16F233786DC9E37E1F2309DAE77B1E769976706DDE362BF0B3DE36DA4150B1DEC55604DF40517DB177CC63B93D6B63AD82660E74CB021E6CE17897DD4FF436F197BCCF829B2F4CB322E42D71AFFEE9D4B2F9DE74899EBF9AD77DE0429F32BEC3BED9D4FD7B7393DFFD5AFFAE6D394C50EB65DF5FB16D06F9648DCE90F38C0B6D02239CD7F455D15FA846721F5BA588DAA29AD3424D875F433B5DED74AEF747927B4FB51293EBCD4D12CACCC00EF71C1147A9D66FBCEA36F2D2D6BB6889E15CC63FC9BB20558D3B24A5EA50D8B68F1B2722E2DA28B9639E382B45B99D8B3AD64EDFC70B3AF8C5D51BDC4B744F4F88E8FE1278977F767590A7D89F83DF71788F7FF130A735FF2335C2AED9F6815ED10C3CF2B3CF6058DC706F99D3579B938D3E322DF17626EBA9AB9F26B26CA8558B2253237E8CCBDD2602EF7F4BAF429E1F22CB1EAC95005ECD4B97DB368FE9268FE8A68FE90CCBE57E4B4F2AF59E99470AF14691F5327D28B73DD2FFD75B50C152A5B7785F4795CDA1F0DB3B45F55F9E9FCA082B8B29FA70106905BE7076BE073862B05B60BEC1678A9C05D80759490765AE001816380D3E908608CEE1499C705DE2BF02420F2587ABE2C945F0ABC49E031815502A7086C1438C7A5733E4D11D828708EC0076949683F3D4537AB07003F563D46BF47FFB7D3BDCA3F2947C9AFF0D807016FA308E09DE8CF9488A262D77F54A90BFE334D53AE54EFA793CA17D4CF81E2412ECE9751B300BF0DD8808BC82CC507F84BE596C073686F0FFF887EAFEC0CBD04F86EE355C08F077F4B2B95DFFAFE803E273445695366E91AE0B561206A7D38A0F855D66196F292AF4699A53CE76B53E62B5755AF507EA9FC405BAD4C532FF760552B7FEFEB00FDA0670360B3BE45E92E69DEA7B0CEBB459ACD12F483808F280565BE8C855602B93D4DE57644A9AB66F8B0FF387ABE43F9A4D2A66E44655EA9DE1A7E4CE956FF51FBA672A97A9FFF7B8027AB9F01E44CD8A56EA7E7A80D339E52122AC3B4BAC5FF6365979A327E0EF849DF6BCA018CFAAD32A6D6EABF137DFE0CFA7B344D3DA2FE6B55957AA9F2FED06CC0AFC0AB37A97BE83CF526F5E5AA65808F6A6B54F6ED76C0BDCAE5EA31CC95547781B20FD0A1BC5C358E367B609712D235EC171C8BB4C0E3EAABDAADEABDEA78F576C046F54EC083C17BD403CA2EFD9368EF467BA5787EA5787E0CA39E50C7954BD4EF826E8599FEB85F534EAADCE7A4CA7DC695ACF1ACFA2FEA12ED67E8D9AEBC06B81C678131F1C0499563DAA69CAC6EF030E55C0FE7498BE705F5D1EA36CF1150967B6E52D86F3729AFEB17795E569F09ACF39C549FF16DF2EC526FD376817247B8C573A97A63F8168FA25E1FBA1DB019B3FF523DE9BBC7F320711D7E90B8FE3E485C697FAF3EA37CD9B354CE2BABE8B3BE2D386D3DECFB2DDAEC01837AA906F5FE6ECAEAAD382F26518B6B290338836E009C4D370336D33F002E1178A1503AE913809708A54FE0E5F43860925E05DC4F7FF4AD45DDAFF1AEA543D4A575528E7A00B9DD8DB9DEAE278592144A1A940FE805E97F1DDD20F00302B9CF1170EFD0EF10EEDDC2BD1BF4BDDADDF44FD2BE4F20F73F0E691EFD11E9F998D01F43CF7BB4C7847E52E0F3C27D51E4BC28A35E14392F4A7FBF72377D46BF4E11AEC2148FCA1A7AD4DBA84A9F2DEDD92ADBDBA932778FC6943D1ACB2C48BB20ED3BA47D87B41F91F623D27E5E20E90C632E64EE5A69EF71A1F497F6C5B40D95F14A78F5DDF441BA871EC37AEC574CE506E556E5D34AADBA40BD505DA7E6D577AB0FA8BF51FB3D239E5B3D7FEFF9B4E77ECFE73DDFF278799FC11F3E49E98874446EB1AF072EC0DEF61B630DE097025D80FF16EC067C5760336093A70FF053E15D3EBE1B30FCB972A54FC5FEE191EF3FF900599E8A1FBFBC6D0FCA7BFF10FF6E1B50C54F3560985F29E0945F4B8FE89FD53763BF5F86BCEBA4473DDFF7FCD4F30BCF1F3C6B950BE99B2185D62BAB699FAA52A7B2865655F3B3939E0BF3AD661D3D15E62D673B7DD42F77797ACCE067BFF423659CE60BFF3ABA02B8B750F1AD2CF93CE9A7F2F7DEF039ED59281D26D29C7B57A082A6E3BE7C663FDDFB756DF2D8CE50B1CD03EEA9E277125E7E818CFB5400B687B0BF8470DB09E3EC5447CC3D977E2A4F4B9EFC9BE59FD212E509CF12E535E7DB75894534A77BEB8A856DD4BF29313C904ACCE9EF17745B1B755A59FE5ADC6589CCA8B9079421DB4CA4FA127BCD2D03FBCC64BED7B6AE4AA74C1BACED39D35EB298469DC736AB3B9BE7E7621A34F3FDDBB7AD5F41AB7AACD468C6BC8856F5DAE9AB1279B37B7824630E9BD97C229FB6B25D663E91CEE42EA2BE0E1AEAEAA40D9DD4DDD5459DDBB7F66DD9DADFB771CB8EEECD1B682374A5DE2DDD9BB7B5F776A31AF4F56EA2BE4DD4E3F6EBDEBC7E0BF58DE5F2E6706BF716549A4BA9A38F7AFA90D53BE99275BBA8BF3363E5466D133652573A3762E5CCFEFEEE6C2E9FC826D1A24E18989F4882916C6B57229FA0E15CD2B233E901DA6A66CC44CEDC984AD20633CF8F9E74D2B672D6DE7CEB65E9DC6822D391C8A5517392D4610EA6B35BE137D77DB435BD2F9B4A98999E44363168A6C44370741693004BE72ADBD0315942FBC6B2C921DBCAA6AF615E8A86766441340186AE06E8B4864712B6D963E687AC946B49D10E99049A96F094B937319A29E3E96283CD49E4863AAD9449390CEAE1068BB6CD5C0E7172F0F4C890694BB30F9E48E6A5B9DEB686BB8761130B711A3C6D0F06729B352DB6BB1DE7270632266D1DCDE6D3C3E6B6B1117363229BCAC870C6589E4B19721E5B3155223B88D6FA34C00E3B9D3737A5B3EE3CAE10927495166297B792564610572AF559C9FD6E535C0F372023C4D8621BB65AA376D22CE29D891179B68F8C64D249C957C47702DE67E6F3FCDE50E89C656631C1685D2A9DB7EC0EDBBA5A0CEE43C2BBBA8B636189BDC1CC9A36C8A9F67CDE4E0F8C82B561345D816D343323979863575B766597E2288E5699DC650E8C0E0E9AF6662BCBCBF26C4CD6A34C3B43C13203EA219BD31368EDB99C393C9019DB96CE57926115B2DA4E39ABBC4271140887B639317C36317622650E27ECFD65D6B6848DC0ACB7D11FF6EE9F6C1864A6CCEC64599C14979936A76999D933B6C1B646473AAD0C27EA0456715C97994BDAE991894C2734125BACF6C44169E5260F468EA54693F9C98C4E6B64CC4E0F0E9D9585A59A1D2B33DC3520F47C7A209D49E72BB8922B1D63EC1A4B1E9CB792E592B54E0BE9ED546507ED4B5C85C066535832661A4DB70C39088FEF4319A1E4803C580A2FCF8ED1BD7B4DBB4472BB575219706BCB5EEA45BA178BAD53DA98B02E9BB452159C2E3B7135D056AE071564D7E056375CCCE1E5CEAB67F952E7153C1B5B89BAF5ADC4741BB0DB6D4D9C113D365978F4E40651B7079DE41121702997B862DB192D94F5995140485C6F65B0AFF526F243E2AB1DE994DBDA646607D1745CE22223C9340D5CB61FD14581EE4C64320389E47E426267737B2D7B787D3A8BED2083AA433D093B3794C89C7DB368ED19EB33EDABD24933D78AEDD3B431AC6813AB6A65B15772A1CDB8DB6C6B2A830E1B3B2DDB94E65673D8CA9B48E6FD796B4428BD487ADAB03B3D021BCDC430F5A0873DE6226C4E6F02AB8C32CEE36AE7E14C89C7F0B009D724DB33831612706898D847656CC0CAE7AD61EAEEB4C746F256C9DC52F1C4FE46037D494004D2B2B0616689D704C7B92F699B665662E7B444193B8D4230E652CE6A792BAC4B0F66A937338A6CA2A16EEC8EC401974669E76FADD8B0447445A14641A8C458A3DEF44133B365846B69DAAA9839BB373D383A91B821630D2432E96B2610B79A7BDDDA22CBA6D7CAA505597730698E381D9376961739A5AE5E77306F27BAB37B2D922D92AB73525077B391361C230BC9B48B68E7A89DB31C6CB7695BD491CE0F2746A82F639A2362E2366B64620694BD0B7B2961534FD73227566E9A158F6F34CCFE9978A4038DF78E494477CD4C66F48CED30078AF97B06B76FC44CA613196751916B98BB8644F7ADE594814B6CE7FC6872AB148B94D96539D9C0FBA5EC87EE60D6B3285432D8CC0B8121BC84305E65DA79B773517F6441A9D989D4B4DD63DE3ADBB630AB999F800F39DEA77604194757B45A930E94470F0A183FDBD7F5F5779949F1B1ED9EC0CA3873A1E6046E19DF0E8B7BF3366DB0132343E964AE54CDD289C1AC95CB33890DE8B046B3A9DC1B54902E53DCEFD4AC7238684270DE60EC84B38CDBF38C622D55C91AF92B828A317A23296FC8779320E7AE6ED4C3C9B412A1D52EB19C63016A38970868E59C3173CEB6D99EC9F09699E3D5E034B2EB3389C19C7B0C74DAA9AB9DE75E87E3FE06587649F758475C9CDD2696BB699B382CAF3B00A34BFAEF4867533841B5AE47117406636E6701E6C8C942AE47394A768CA272A231E2AE4F140C273987B03F940ECF6E4AE78A870327E57393523D474EE9B2D07212174EC9758DA4DBAFC67699459B12A556B130C269C962D3D57FB3996F759C22EA2215480A23DB8336D4722CE44338392B1C5E71D709B9E72BE79CE15E61B01530279346F97624BB7BE8DE3C651830B6D1E43312C94989AC91FE7507390FD379540D9C825043018652C98E8CD3BDCBB9B850B7ECB6480746D665AF4AE362C49749DA6F8E0DA4FACDABB83D6C61A774DBBD569A61D16B7C8972EFB3F9849D7703C4DD00DA07186EC4B2C3C50845A274CCE17F23C64550AEC5CE41C136076D5E938E73DC12EC22D8D1B2AED72875B09CD72870EDB69D18A3D498EC1838D917A7E83393A3C8DBB156A7540F72391873B2C93D3C527B2AC5715B9F184E03BB143988FEECBAEEAC79C0C5CAE98A00213D40C267562FE1F0408394A62CB5D256C2898E2C506C4A4A9BF4ADD4450B49E17703C15EEAA6CDB481D610D5F5A1878DBE19FCE9C2F36A48A04825753B8D104DED44CB82241C138567E24FD695DBEC3E774236F74BA3C77ED02E411FE817E9121DF6A307CB8434CF5B31739A8629019D4D3A8FF6816ACAF71BBD97DFD039F8AB0B7B6EDEFCF8EB0F9FFC4E8EBC3145313C31527C6844228C8619A8BE98AA84C3426DD7635EB4C361AD2EDAA544AB9C87E13C12CE63AD5707C71BA35AE296C120C160ADAE7BA2D7AAD16B7DA4AA8D8D3A29D174A4F0942F46D1C2F7749E044F1F3A16C60DF00AFF82BF3CAE8115686CD0A040B4F09CA6AB8DD1C2518D183B0A7DC35E34E5F55395EE3522856391C247C0A98A799448E1E548E11791C22FD1C5088B1D8646D4142DFCC947C43046E82DF018FA84D97EC3874653B826A6450B7736F90C2332EE8F8EFB1AAB75BF6AA8FC89168EB00631C5400F18DAE4C3D88038CBA7635A1E04410147E38F32BD51EC3A0A0DA3855B9A7C4D3E2070033C09C3554C1109C4BC863B5B987B1D2DFD0DEB9A5A1EA5B2B92C5EADD1834DE1B0BF416D50551F7C7734405E10C210314B238F110EABAAD6C0CE6E10171A063B2D32DE06092A7BCD1756B569A08523E3ED18C07185ED4DBEB046F05493AF5A8781C7E1ADE3067F54C775C71193261FFB6FBC1B4981EE1E5DE1F490111A2B095D31F213E805D39BD827621AC4F2D30F5DA2E3A1C8F8A57087DB1DBD656A23EA48B8375AF86CB4F0A058ACF1244D3EF66664FC0A4997078D98876906FAEBD1C24312F287A28547239BE04D8480FD98902C7A343A6E86629AC21670728CA73191114DC3830DB3F5900CBB255A781C86450B27E1E8A38D6A3189403FEA87FF043FE6E86D3AA9A2347AB5E8F8015D6807106A76CDE3ECB8C61A95730F163A22259D7C358E9E3BA1B128DA30470F3756CE3C61D6875427F498A8010B48F51B48228F014773F81B1B81A98DC06471A57DBA3A135ACE245F8D4233C91B506612D65A2D56A02A6BB296743C87F1741F6A2DF7AA258E0F3038F2816BDE7AD9B4A5CF1F313EB5A6FFED91EF052EF0CA17A6DC75EE3E0DF799709F6B3D5AF45AF8A1308E4603378EA81A924AE5E64DAA16F02098DCBE45D50C74D9C8ED8F7AB448AF17E953C5C0609060B096C1B5B22EC79DD53DCE9406837C8D61A93942BC13FE5464C519864EDE8606A3A1018BBF41E3601F0FA3B7849A79AACFE7E7FC96EC41CED7443631B5C1309CDE0F190671913886E54A6438B4069DD446A661063FD63445D37A8D028FC2A78B1445A999C92FD31B1A6A223BB166D0F07B0DB6C5605B0CB6C5605B0CB6C5605BB8D9E08D231886E2FE0BEA99FC4BD96D6AFD0E6C4E9BAD6CE99A83FD14072005FD9CAFA645150A4DBC92C85772B04B28142DBD1E897DE9782CB678D1E2C544F3159AB378E5DEF3CF4F2C4E2C34932BF62E5C9A5C965CB862E5CAE4C2C5CBDB12038915CB536DE6F9445598A3AD7511FF21DAA0D0F4D6CDEBB6955E19B5B8AF1556F337FEA06A784A89C52FE53289317E1955C36362254E6CA951FCE2538342819EB16DE630BAE64DA3AD3453BB424BCE3CAEB66EC3E536D78A53A3951DCC8CF18BC55491D9319AE63B8FD1B6BC2861B742979C796EEECB8FA6D256ABF31A0E92DC9DDBB9EB9A7689D097E6779FFC96CB7DF367D97E486E73451B8AFBCDC084424B8B875273A0B5F456A1F83A14535889918DF9FC8873362BD2A3935F7FD79EED2D3911166A10C7F3D2158A6A150A835079B396188126F7B36287CA7B48514AE960CD1FFE27A1DF7CE2D52F72206EC24F6692BB8B2D7EA76EDA2DB1E24BF9965831EA4B1D67B7C4DC2BF5EAAC398A4B77A625D63B3A00FD70DCDA66ED37B3AB079069CB92CB96B7AD5CB2D45CB462E5ECC9933967EF2201AA56FE9F00BDED5DFC97757EBEBF4C7E9DDB313AEBE795FE4A0C4749BB2B93E949A4B3CE2F174CE7550E7FFE3C17326ACE2AE47F3EFF9F7C9CEF683714FF978D0A3AAF8F4567A1F387FFEF889DE0ACAAF8FF335679F84B4D97E154DE0FB80E67FF3E9CEEB7E07CDF2FA7FCF5CEFFBA410F795F3D4DEE776E2A65AE7131FE7DE419FF2D867C875981D404CEEDEB71AACFE08CDE8D53FF5EF91714447364D4367013A0E6C04F106E56E0665D099FF27E58BEEBD307BA2DB793C1B3483A287D1695FE2CA501F77BF3EC8F4EF419C61FBE6FE429E74A3EB7823722F38FC1DA84F42BEBCFDF542DCEE7DC4292A2C7C8043DF9BE340C2C5FEAB51F6DB9A9400FA342C665F8B1C12F8F6DC37D6B51E987E7E46FC0768BAEDC370B9D32159ABDF15CAD9492FB16C799656C921B118FEE14FE98683E4843C4FF9FC9645A8C8EE327468BF9FB6BC45FB45B203E2ACB712295120D38A6FB4BDE24F4E239B7B8F2D2AEDE45BBB3FF29FD5789DF7BE5B697C22D34891E95B1F94BFE5E2AFE9E38F64CAF9FE9F31532A61D3D722279005A8CC1137F6DDC7FEB678FF36F15AAFEDB27FE9FCFFF0B9FFF00182C66F0004A0000
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(3900) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
Executable files
27
Suspicious files
778
Text files
277
Unknown types
20

Dropped files

PID
Process
Filename
Type
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RFef1ed.TMP
MD5:
SHA256:
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RFef22c.TMP
MD5:
SHA256:
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.datbinary
MD5:02DDA7725803EF3F8FFB664727286EB7
SHA256:802408FEB482A3538AD2FB3D61696F4335418874B563929EBF014CEEA8825F25
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFef24b.TMP
MD5:
SHA256:
64962332123.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PresentMon.lnkbinary
MD5:6F7933A79282ED57FE38DD28BB50790A
SHA256:5229BD79DE499FFB5C228441CDD60828D55CB7AF27394149CE057FBBA31AB5AF
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\arbitration_service_config.jsonbinary
MD5:350ABC86EFB653D78BE8F2FA5D7BDB8C
SHA256:C42FB154D987390FCCC0F63DAFCED2BA7242410BADF64D6FF5FDC2FB26D103C9
3900msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFef24b.TMP
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
34
TCP/UDP connections
156
DNS requests
163
Threats
126

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7160
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2608
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5048
msedge.exe
GET
304
2.16.202.123:80
http://apps.identrust.com/roots/dstrootcax3.p7c
unknown
whitelisted
5048
msedge.exe
GET
304
104.76.201.34:80
http://r3.i.lencr.org/
unknown
whitelisted
5048
msedge.exe
GET
304
72.246.169.163:80
http://x1.i.lencr.org/
unknown
whitelisted
3908
svchost.exe
HEAD
200
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8c130d2f-1a45-445f-88a5-07fb8663d0df?P1=1723580788&P2=404&P3=2&P4=KuQsw%2bFHZOXO8WdNgOVJVLoTz1ivckgHT64%2boEw9kHzr9j1iNJNebJAncx9zxXdXCoLhZhim2cblv4%2fMHcK1GQ%3d%3d
unknown
whitelisted
3908
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8c130d2f-1a45-445f-88a5-07fb8663d0df?P1=1723580788&P2=404&P3=2&P4=KuQsw%2bFHZOXO8WdNgOVJVLoTz1ivckgHT64%2boEw9kHzr9j1iNJNebJAncx9zxXdXCoLhZhim2cblv4%2fMHcK1GQ%3d%3d
unknown
whitelisted
3908
svchost.exe
GET
206
199.232.214.172:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/8c130d2f-1a45-445f-88a5-07fb8663d0df?P1=1723580788&P2=404&P3=2&P4=KuQsw%2bFHZOXO8WdNgOVJVLoTz1ivckgHT64%2boEw9kHzr9j1iNJNebJAncx9zxXdXCoLhZhim2cblv4%2fMHcK1GQ%3d%3d
unknown
whitelisted
7120
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4016
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1164
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4016
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6496
2332123.exe
147.185.221.19:62014
february-nylon.gl.at.ply.gg
PLAYIT-GG
US
malicious
5336
SearchApp.exe
184.86.251.27:443
www.bing.com
Akamai International B.V.
DE
unknown
5336
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 142.250.184.206
whitelisted
february-nylon.gl.at.ply.gg
  • 147.185.221.19
unknown
www.bing.com
  • 184.86.251.27
  • 184.86.251.19
  • 184.86.251.7
  • 184.86.251.9
  • 184.86.251.22
  • 2.23.209.185
  • 2.23.209.193
  • 2.23.209.176
  • 2.23.209.179
  • 2.23.209.161
  • 2.23.209.189
  • 2.23.209.148
  • 2.23.209.177
  • 2.23.209.140
  • 2.23.209.158
  • 2.23.209.187
  • 2.23.209.135
  • 2.23.209.150
  • 2.23.209.181
  • 2.23.209.133
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.4
  • 20.190.159.71
  • 20.190.159.73
  • 20.190.159.0
  • 20.190.159.2
  • 40.126.31.71
  • 20.190.160.17
  • 40.126.32.136
  • 40.126.32.74
  • 40.126.32.138
  • 40.126.32.76
  • 20.190.160.22
  • 20.190.160.14
  • 20.190.160.20
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
th.bing.com
  • 184.86.251.27
  • 184.86.251.22
  • 184.86.251.7
  • 184.86.251.19
  • 184.86.251.9
  • 2.23.209.158
  • 2.23.209.177
  • 2.23.209.149
  • 2.23.209.185
  • 2.23.209.176
  • 2.23.209.182
  • 2.23.209.150
  • 2.23.209.179
  • 2.23.209.148
whitelisted
fd.api.iris.microsoft.com
  • 20.74.47.205
whitelisted
arc.msn.com
  • 20.74.47.205
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Potentially Bad Traffic
ET INFO playit .gg Tunneling Domain in DNS Lookup
2256
svchost.exe
Misc activity
ET INFO Tunneling Service in DNS Lookup (* .ply .gg)
6496
2332123.exe
Malware Command and Control Activity Detected
REMOTE [ANY.RUN] Xworm TCP Packet
5048
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
5048
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
5048
msedge.exe
Misc activity
SUSPICIOUS [ANY.RUN] Tracking Service (.popin .cc)
5048
msedge.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
119 ETPRO signatures available at the full report
Process
Message
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.
2332123.exe
Conversion from string "" to type 'Integer' is not valid.