1.5
低危

38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11

38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe

分析耗时

70s

最近分析

406天前

文件大小

107.9KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN BACKDOOR WABOT
鹰眼引擎
DACN 0.15
FACILE 1.00
IMCLNet 0.78
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Delf-VJY [Trj] 20200621 18.4.3895.0
Baidu Win32.Backdoor.Wabot.a 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200621 2013.8.14.323
McAfee W32/Wabot 20200621 6.0.6.653
Tencent Trojan.Win32.Wabot.a 20200621 1.0.0.1
行为判定
动态指标
在文件系统上创建可执行文件 (25 个事件)
file C:\Windows\System32\DC++ Share\wab.exe
file C:\Windows\System32\DC++ Share\wmpenc.exe
file C:\Windows\System32\DC++ Share\wmpconfig.exe
file C:\Windows\System32\DC++ Share\wmplayer.exe
file C:\Windows\System32\DC++ Share\Journal.exe
file C:\Windows\System32\DC++ Share\ielowutil.exe
file C:\Windows\System32\DC++ Share\wordpad.exe
file C:\Windows\System32\DC++ Share\InputPersonalization.exe
file C:\Windows\System32\DC++ Share\wmpshare.exe
file C:\Windows\System32\DC++ Share\MpCmdRun.exe
file C:\Windows\System32\DC++ Share\wmpnscfg.exe
file C:\Windows\System32\DC++ Share\MSASCui.exe
file C:\Windows\System32\DC++ Share\wmlaunch.exe
file C:\Windows\System32\xdccPrograms\is32bit.exe
file C:\Windows\System32\DC++ Share\iexplore.exe
file C:\Windows\System32\xdccPrograms\ConvertInkStore.exe
file C:\Windows\System32\DC++ Share\wmpnetwk.exe
file C:\Windows\System32\DC++ Share\mip.exe
file C:\Windows\System32\DC++ Share\ieinstal.exe
file C:\Windows\System32\xdccPrograms\install.exe
file C:\Windows\System32\xdccPrograms\InkWatson.exe
file C:\Windows\System32\DC++ Share\WMPDMC.exe
file C:\Windows\System32\xdccPrograms\inject-x86.exe
file C:\Windows\System32\DC++ Share\DVDMaker.exe
file C:\Windows\System32\xdccPrograms\execsc.exe
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
在 Windows 启动时自我安装以实现自动运行 (1 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\shell reg_value Explorer.exe sIRC4.exe
文件已被 VirusTotal 上 68 个反病毒引擎识别为恶意 (50 out of 68 个事件)
ALYac Trojan.Agent.DQQD
APEX Malicious
AVG Win32:Delf-VJY [Trj]
Acronis suspicious
Ad-Aware Trojan.Agent.DQQD
AhnLab-V3 Backdoor/Win32.Wabot.R231859
Antiy-AVL Trojan[Backdoor]/Win32.Wabot.a
Arcabit Trojan.Agent.DQQD
Avast Win32:Delf-VJY [Trj]
Avira TR/Dldr.Delphi.Gen
Baidu Win32.Backdoor.Wabot.a
BitDefender Trojan.Agent.DQQD
BitDefenderTheta AI:Packer.A6B372A221
Bkav W32.BackdoorWabot.Trojan
CAT-QuickHeal Trojan.Wabot.A8
ClamAV Win.Trojan.Wabot-6113548-0
Comodo Backdoor.Win32.Wabot.A@4knk5y
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.434d5c
Cylance Unsafe
Cynet Malicious (score: 100)
Cyren W32/Backdoor.PJEB-4161
DrWeb Trojan.MulDrop6.64369
ESET-NOD32 Win32/Delf.NRF
Emsisoft Trojan.Agent.DQQD (B)
Endgame malicious (high confidence)
F-Prot W32/Wabot.A
F-Secure Trojan.TR/Dldr.Delphi.Gen
FireEye Generic.mg.0452c8b434d5c4b0
Fortinet W32/Wabot.A!tr
GData Win32.Backdoor.Wabot.A
Ikarus P2P-Worm.Win32.Delf
Invincea heuristic
Jiangmin Backdoor/Wabot.z
K7AntiVirus Trojan ( 0055c5c91 )
K7GW Trojan ( 0055c5c91 )
Kaspersky Backdoor.Win32.Wabot.a
MAX malware (ai score=89)
Malwarebytes Backdoor.Wabot
MaxSecure Backdoor.W32.Wabot.A
McAfee W32/Wabot
McAfee-GW-Edition BehavesLike.Win32.Wabot.cc
MicroWorld-eScan Trojan.Agent.DQQD
Microsoft Backdoor:Win32/Wabot.A
NANO-Antivirus Trojan.Win32.Wabot.dmukv
Panda Backdoor Program
Qihoo-360 HEUR/QVM05.1.0C3C.Malware.Gen
Rising Worm.Chilly!1.661C (RDMK:cmRtazozAIFhMgYuZx1mbuPLTnsB)
SUPERAntiSpyware Backdoor.Wabot/Variant
Sangfor Malware
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:40:53

PE Imphash

5662cfcdfd9da29cb429e7528d5af81e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x0000c984 0x0000ca00 6.572458888267131
DATA 0x0000e000 0x00000a1c 0x00000c00 4.533685500040435
BSS 0x0000f000 0x00001111 0x00000000 0.0
.idata 0x00011000 0x0000083e 0x00000a00 4.169474579751151
.tls 0x00012000 0x00000008 0x00000000 0.0
.rdata 0x00013000 0x00000018 0x00000200 0.2108262677871819
.reloc 0x00014000 0x00000710 0x00000800 6.25716095476406
.rsrc 0x00015000 0x0000167c 0x00001800 3.2124871953120624

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000164a8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000164a8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000164a8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_RCDATA 0x000165e0 0x00000078 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x000165e0 0x00000078 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00016658 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library kernel32.dll:
0x4110d8 VirtualFree
0x4110dc VirtualAlloc
0x4110e0 LocalFree
0x4110e4 LocalAlloc
0x4110e8 GetCurrentThreadId
0x4110ec GetStartupInfoA
0x4110f0 GetModuleFileNameA
0x4110f4 GetLastError
0x4110f8 GetCommandLineA
0x4110fc FreeLibrary
0x411100 ExitProcess
0x411104 CreateThread
0x411108 WriteFile
0x411110 SetFilePointer
0x411114 SetEndOfFile
0x411118 RtlUnwind
0x41111c ReadFile
0x411120 RaiseException
0x411124 GetStdHandle
0x411128 GetFileSize
0x41112c GetSystemTime
0x411130 GetFileType
0x411134 CreateFileA
0x411138 CloseHandle
Library user32.dll:
0x411140 GetKeyboardType
0x411144 MessageBoxA
0x411148 CharNextA
Library advapi32.dll:
0x411150 RegQueryValueExA
0x411154 RegOpenKeyExA
0x411158 RegCloseKey
Library oleaut32.dll:
0x411160 SysFreeString
Library kernel32.dll:
0x411168 TlsSetValue
0x41116c TlsGetValue
0x411170 LocalAlloc
0x411174 GetModuleHandleA
Library advapi32.dll:
0x41117c RegQueryValueExA
0x411180 RegOpenKeyExA
0x411184 RegCloseKey
Library kernel32.dll:
0x411190 WinExec
0x411194 UpdateResourceA
0x411198 Sleep
0x41119c SetFilePointer
0x4111a0 ReadFile
0x4111a4 GetSystemDirectoryA
0x4111a8 GetLastError
0x4111ac GetFileAttributesA
0x4111b0 FindNextFileA
0x4111b4 FindFirstFileA
0x4111b8 FindClose
0x4111c4 ExitProcess
0x4111c8 EndUpdateResourceA
0x4111cc DeleteFileA
0x4111d0 CreateThread
0x4111d4 CreateMutexA
0x4111d8 CreateFileA
0x4111dc CreateDirectoryA
0x4111e0 CopyFileA
0x4111e4 CloseHandle
Library user32.dll:
0x4111f0 SetTimer
0x4111f4 GetMessageA
0x4111f8 DispatchMessageA
0x4111fc CharUpperBuffA
Library wsock32.dll:
0x411204 WSACleanup
0x411208 WSAStartup
0x41120c gethostbyname
0x411210 socket
0x411214 send
0x411218 select
0x41121c recv
0x411220 ntohs
0x411224 listen
0x411228 inet_ntoa
0x41122c inet_addr
0x411230 htons
0x411234 htonl
0x411238 getsockname
0x41123c connect
0x411240 closesocket
0x411244 bind
0x411248 accept

L!This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
StringX
TObject%8
;u3YZ]_^[
SVWUL$
]_^[SVWUL$
uZ]_^[
YZ]_^[
_^[U3Uh
d2d"h@
d2d"=5@
u3ZYYd
#_^[SVWU
SVW<$L$
uSVWU@
]_^[USVW
d1d!=5@
2E3ZYYd
E_^[YY]
UQSVW3@
3Uh6"@
d1d!=5@
E3ZYYd
E_^[Y]
YZ]_^[
d2d"=5@
}3ZYYd
E_^[Y]
$PRQ$"
_^SVWU
< v;"u
3C<"u1S@
>3Q<"u8S
< w]_^[
Ek<1fU
Ht Ht.g
6Huv=L
VI3E?E3s
3EE_^[Y]
f=r/f=w)f%f=u
f=v)f=w#j
RPCHPt$
-CGL$
SVWPtl11
-tb+t_$t_xtZXtU0u
FxtHXtCt
~ExC[)A
FuY12_^[
PRQYZXt5x
@~d@PQ@
YXYX
uM3UhU3@
EP3ZYYd
f%fUf?f
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
Iu9u_^[
PRQQTj
YZXtpH
S1VWUd
SPRQT$(j
Zd$,1Yd
t=HtN`
r6t0R=
t/=t&,*&"
3UhB:@
USVW$@
d2d";~
P'v_^[]
aSVWt@
^v]_^[
QRZX1Yd
PVSY_^[]
PQiZXSVW
ISVWRP1L
JZ_^[X$
thtkFW)w
9uXJt
8uAJt
t8JIt2S
PHXHI|
St-Xt&J|
t0JN|*9}&~")9~
tVSVWU
t@t1SVW
1Z)_^[
@+u<E@
USVWE(@
d0d ]ES
u_^[YY]
UQE3UhF@
d2d"E@
t3ZYYd
%3ZYYd
U3UhH@
U3UhH@
3U3UhAJ@
P~SD$
U3UhK@
U3UhK@
U3UhL@
TFileNameL@
TSearchRecX
U3UhdM@
EEb3Uh
tC&EPU
U3ZYYd
U3QQQQQEE3UhN@
d0d EM
EPU3EPtKh
EcPh0O@
system.ini
Explorer.exe
UEEEz3Uh.P@
d0d U,
EP3ZYYd
IuQSEE3UhpR@
tjtfhR@
t-u)hR@
u-t)hR@
" -a -r "
" a -idp -inul -c- -m5 "
software\microsoft\windows\currentversion\app paths\winzip32.exe
software\microsoft\windows\currentversion\app paths\WinRAR.exe
C:\rar.bat
C:\zip.bat
PHuES3
E.E&3UhT@
EPEPEP?
a3ZYYd
IuSVWEE3UhX@
d0d UEJ
U3YEU.Ef
EU\EUQE;}>%
EnSEcPd
to3Uh2X@
EP3ZYYd
IuQSVWEE
3Uhh\@
U3UhY@
d0d G3ZYYd
$UFuh\@
VUEL@t}0EUm3E
EZPE~h
=3_^[]
abcdefghijklmnopqrstuvwxyz-_.1234567890
IuQMSVWMUEEEE
+3Uha@
d0d 3Uha@
d0d EU|
u?8.t4uha@
u|U|ttx
yupUkp0hwhlj
uXUXPPT
uLUrL7D~DHq
-u@U@8+8<
u4U4,,0
u(Uy(6 $x
3Uh"d@
d0d 3Uhc@
d0d EE
8.teChTd@
N3ZYYd
_y_^[]
NOTICE
:to get this, type !xdcc_get
bytes)
uTC,PSC
EE>3Uhe@
d0d SU
E3ZYYd
EE3Uhf@
d0d SUf@
PRIVMSG
UdSVW3
dhEE3UhSh@
d0d 8lPh
d2d"EP
s3ZYYd
c3ZYYd
ZE.H_^[]
BFKu_^[
USEE"3Uhh@
d0d UE3ZYYd
U3QQQQQQQQS3Uh
| v;}
N|7 vU+A
M3Uhj@
U3ZYYd
EE3UhPk@
EPE!PS63ZYYd
E1K[Y]
3UhYl@
\DC++ Share
\xdccPrograms
EE33Uh?m@
d0d EUFUTm@
a~&EPUTm@
EZSUTm@
U3ZYYd
f\[YY]
EE3Uhm@
d0d EEPEePt,P3
EU3ZYYd
U3UhQn@
TWarBotUj
SV3Uho@
EPSE/Eo@
03ZYYd
IuQSVWd3Uhs@
`U\E\U\
EPSEPcfC
PfEEU:E
X/XUX8
3EU,t@
~&EPU,t@
EZU,t@
\uh8t@
L3LP P
PcPhlt@
EIHhlt@
DE0Dhxt@
\E>EPj
EPtPEP
SfPV j
EPzVt3ZYYd
PRIVMSG #hellothere :
&%->=
PRIVMSG
DCC SEND
IuMSVU
EN3Uhy@
d0d EUaE
EEPUy@
;~iEPUy@
EEU8EPU
EZWEPU
EZ1EPU
EEPUy@
EZEUUy@
:3ZYYd
PING :
type !list for my list
!list
 for my list
!xdcc_get
#helloThere
#helloThere,
JOIN #HelloThere
LIST >4,<10000
U3QQQQSE
3Uh,|@
YUuhp|@
?Uuh||@
G3ZYYd
PRIVMSG
ACTION
!list
 for my list
SVWE3Uh@
E3ZYYd
NICK [xdcc]
NICK [mp3]
NICK [rar]
NICK [zip]
NICK [share]
NfrSF3
Pzu _^[
31ff%3vcc%%112c23J33c22322332crc3cr233J2fJffJv%1[J33JccJccfcc2fc2JfJ223rrcrrJ2cc3f2r3r233Jcf2rf3ffJfrJrr3f2]fr[2rvJ23%1JJJc1fc22%J[rr]ff2rr2%ff32f2J23r323223J2rc333cc2fJJ3JJ2ccrfrJr2r3JJrcfc322f3cr3rcJ33f33rcrrrcf3cfrffJ2cff2r22fJJf3rr33rJ2f3cJJc33r3crrcf33cJJrffr2fJ2f22fc3ffrrJ32cJf
]2]3r]31111rfr2crcJ3[%%]]vJf3233Jr22fJrvvv[v[Jc3Jc3rcccrfJ3ccfffJ3c32Jfrc2ffr3cJ222JcfrJrJ322r2ff3Jr2JJcffcc3vJ]c2[2%Jv%2]rf2J213]3[v2]33[2[J32c2r33rrf2c2cff23rJJf22cf3crJc2fJJrcc33c2fccJ332rJJcrrffJr2ffrcJ3frJc23frcr22c2rcJc2cJcff2c3cfrJrf2rfr2c232cff3332fJ2r2c2cfJ23f3J3f333J22r2f33
J]"^^"^^^^^""""""""""""""""""""""""""""""""""""""""^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^"=~\=yw$="^^"^^^"jCzyw6=^"^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^=
ff^ ."k^"=!24G;. .. .!nzL4OJ"~~.. . .=
]J^ . .!sG!7{^!s8G=.. .^68Vs2!;.;*}.. =
f1" ............. ._Inzoz6$295. ..^lkcv".."";"L. .=
1c^ . ,!%6***O8Izy. .!j_". .;w=;]. . =
ff^ . . . . . . . . . . .. .. . ... . . .. . .. .^|uuzw94V9=. .. :"=^,..uS?^. . . . .. . . . . . . . . ... . . . . . . . . . =
Jf^ .. . . . . . . . . . . . . . . . . .. .. . .. .. . .}6T6$i!+~,.. ~O4u{!!je^. . . . . .. . . . . . . . . . . . . . . . . . . ... . . . ... . . =
22^ ... . . . . . . . . . . . . .......... . . .. ... ... ...... . .6Ic35I=. . . ...^v}ca$l^. . . . . . . .. . . .. ... ...... . .. .. .. ... . . . ....:... . ......,.... .. . =
fJ^ . ....:..... ...... ........... . . . .:,!!<-!==!"... . . ...:...:..:..,. . .^!\, ..,,..:.,.. . . ..:,^^.... .. . .....:.... ... ....,:..,., ..\((?>(==^:. . . . ......,,.:.. ,."!!.. . . . ...^"~?(|^ .... . .. =
cJ^ .."J4nTn5TaL<.;"clJws2:. ..."=i?2ai<,.. . . ..^~%yehY3CAh5Ti~|~. . . ^11J3399T16c;..^)JL5o.^]ff2t??]3+=. .^?t{$]t=~|]t. .isfanzCC%". . .rsyz4LVYT9C~. ..^j5*hPDPe0TmaT1~;. .54wjtffi%J!. ."+jjwc%i]=^. ..;!?2t+mFDK=;(zs?;... =
r2^ .=gYDFSQUgDj-GkK5oVhFJ!. "!9m*JaPa?. . .;!Jau$UFU*a*n$y1VOb~.. . =UG0LskShqpU"^n5gpq8.=ATIIn2*m*U... "J6n3)!!=pd. .;*PpdUk}v+t^ . ..bZAgFPDUonPb.. . .!GZQPPms%+tij6DQ9=. .%UszufL4s4mj..)5m58T9&f! .:tnS$_!+&PDDl"IpDg=";. =
fJ^ .tXeT0kVqDF]xDqhs04GmZ^.]wTTCrkFV2[^ . ..^7Tr}":.....8CcVwu%"". ..=ZkasJ[%rOm&"{nZqff}\.=Vu1]rOk]zTk ..."royC3wDQx8 .+%bQDFFFh}". . .x8VYhhgg4oTk .:-az0{"... :wkkOpPP*T;. . (tv0gPUpAGbc"+kyw69*&mUG0&G.. .. ,~I&Qi. ....=21UPmTP2 . =
3J^ .+#d04kO5VUL#AFFL8&YOFFc=sanCv*qZac_,. . .|c3V~, . iVuIrsY5y... .=OC23c3cfI54"k4V?(69t.)g9I$JVUi!t[ . .."CCTyL*Zhe4....6!obQFUDD8i. .. :xasaePQUkSPx. . ~Fprn^ ..SFPPDbGz&$". .iyuJeFk5O4Ta$5w|i1oC8*4eG*O:. . .jcTh- ..,J=3gDOddh.. =
32^ .tWx50GGs$Ca"^=*h4xhyXWAx^-JII*gW52C^. .^ny$~:... . "9sC%]uGnb5v... ~8kkny6u$$2+~It^.:^^^.?Ume4zsbn~<l. .^+zJkhqDSkG.. .Sc?c5qDPFX1:. . :hOzfOxL8dWKg. ..=khb7. .. .9PDPQJ4GY%,. .%ghTkxOru]7wxu^.;|JnT*T&8Oh{.. .Ja$"... . . )+%mF8Feh~,. =
cc^ .+#h%l[6okkL..!x0*Zq5Zqde. "VsJ*XXpJ$" . !n37.... . ;++cj1+iyACi^.. ~CCuw9LOY4Vo[i, . .?d532taFULy8 .. ."jJ$5gqpDmIs ...Dp5rrsDDFX. .wVXQ6VKWKK#d .)qPU ...}WA*njyZkXF! ..}bFPpkx611axI!.. /%aOmmr!ti6... ,vn\. .=3w&pO*LG^. =
ff^ :tbuy6o0ZQW(..>x&ZAeDnbAs. ^sTrg#SAI+. +7". .. . ^$iilvr+&m]i" ~a9kk*G88TCc|... . .=LCJ2nSd&uT ..!ltfdZZFk]|s....WFV3nvlwdF$. .4OPdVdQQFpxT.. ~be!. .. . .[e55T5eFVFb!. .tQpQqPGzrT&G, ..<nfnn8$+i%w^. !^... . . +ombY&q9,^. =
rr^ . ?gxPSZFqFZ) .<AZUdVDC9bz "&f$qXPb6zf. ..... . . :tT6}JIck5t%|. )p*&890VcCy~ . .(shI+2FFxyi . /r9pAFQp$j!Y... #FD4s!/}*Pf, . .*pO*hO8nTf+. . .... . .. .lxUhLQDdLQq7. .=$khAQS8T*4j ...:=a!i+35*8oT=. . .. . .|o]IyZFA[Ve" =
Jr^ .iDSFgpqZxh= .!QdQSTXk$&T "e%veDFPzz1 .. .... .. :~VqCtju8z2Y) ..)8k8522%$5mc; .(aO7+IsxQFV=. ."$dddDeY$vQ. .eFQD5%kPh3>. .YZeqQPZU06uz. . . . .. . .)65OgDFAqUPu. .tTw$*Ud8Oa). .~xc!|jkaTs6!. .... .. .. .|Off4PVT8Fb^ =
c1^ =ZggAA*auv!..=SgQPwUn2r. "#V$TQPQss% . . ,";^;.. .t*dk3++*T6V= |YnC)"tI4*0+... .i82]ww6aPpx6 ...<8AqFhsu9uF . *PS#q1+!~<. . ,4QDqdDpDxw5b.. . . "!"\^...=?78xPdkUPA.. .[Gk0c]TLm&2_. .?0o$u[TLCzw). . . . ;^"";...+dmsYGO&DF*^ =
21^ ..)ggAO0n11]~ !*SbP8LI]t.."Kh6IdPUna] . . .."${C}:...|y4$a[=sTV*| . =3ti~!1GepG+. .. .ib$fC3CSDQF ..!eFDUnuIC5W.. nUFXSfvttCi: .. :ygPQGSDSh*gb . ..ia4h]^..|i$mVd*CAUDu.. .lhYeZVTs5&!.. .=u96zI6$n=.. . ...?s*n|...iPbq*Y8pA*n;. =
c%^ ..=OLCa&YIn8= ."J4L86yG4k+ "DWQxDQSsIs . ..!}=oZicz{3{"rOdbA*DnyCC~ ?8kL8Oonzc2t. .=*o|"^~lZPgK . .!qDQarvuCJ2L . .ITPW#uooont... .%qPbLJSpmUPh. ...!YZYG&aDOsg2swY9ZTrD5Lu. .iDx&bFdDPPz~ . .!3Cft"!t$8J!. .. "sT*GFDXKWWS]QqQxq0hPXq^. =
3[^ ..?PFamG&LpF( .!Gxh*nyr3&J. "KFDUUFFonV. . ;|3o3o8c+~"\~~7Cnbgx8C333! |G0O4mGkVnu+.. .=Y**TYGTmeFW ...!DUO1yzys8xx . IfsxFuow6y+, .|FZPL2rTmQWS. -xakmdUe8!!nPe9e&o?iT]ao. .jQZY6TGbZgnl . ..\IVhm7=z9)... ./wfJc}]w==0hUbQm400*&Qd^ =
f1^ . ,?SZ*n5cQAQi .!ASdegZ4*4} ."epQQmAFy*0. .=smS5yLa<; :!y0VAGko]ftJ? ?pp4VGV40GG{ .!asO4gDq44dX.. !q&6&bQXFQpP . 3u4qo&5yC(, .. .~dbph1cYKXG.. }p*0Tm*qg.. "pSaey/^_r0Uw. ..+UQh7)[y&dZ{ . .?na*kG{Cz%C!.. ;o9v%jJur=,.^)ObOuY*aOSFU^ =
f]^ ..=4OpT%2FgPi "VdUdUDDbUw .^5ZFDY#WzV* .*WK#qnQp". ~pbZx9T61vi~ =*GOGOGmL4Lt. .1oa&ApFe4gK . \hxpSFPFSWQq ..sncsAkCIC+. :=FAPh[1ikWA6. ,2DKQaUpYx. .&Z8A$^.>6qPz. .[AFps9aa88k{. .<L8*G89wu$$=. ..)051vCY6!.. ,tYy3kUk&ppQ^. =
r3^ . . .tQnQbywY4Y~ .!o&&AAAdFPs "U$%8#&Y9xb. .uPPLurVXF+.. ."d*YIf5*[[G&=. !raazIas&4*7.. . . .?U2aWxsDF*P . ..!ePDQDQFDOu]. OIo2u+uT447. .!sPWdl+7n[Ia. .)GWWgO$LG {ggqo++1PFS.. .=dAUdy4Y&&g{ . ./CyIC]]r$&i. .!$GT+c*wmL). . =1[khQb*nDg^ =
c2^ . ,tXGt5VTfaO= .>h5L&hgUQn.."XGzoae8*Xg .!F5(~)IYWPv: "mw5h&2r**= =yJO5J]vf96(.. . ..(D8~thFC1nOP . .ppdhLsCui1$....69nVwfuzr. ..\$#Xx]$Tynw%..=mhKQPV06CJ .+hhxivcyFpU. ..)VqdZVx$fLZl ..,t6OwC7f6ws(. :IxxT[Ynnw~. ^=TdpqQUYxZ^ =
Jf^ :.. .,tKxi6%ausm= .!psGf]5kYe5,."XgDhJqSmF&. "Zi?!!vTKgj.. ^G5Vab08$wk*( )L$r1uII6zt.. .)dUT%LPWJv4Q . ..^J$cuttt[fkm. 22*kwaYT647.. ./3pPhwm9o5k$..i#hbbqw$IC(. .7Z&9|w?iPbg$ . >+5hSg6urIZv ;c8mw2[2JV[/.."&Z*zfwma9a= . ,iUdPFdDs(o" =
Jf^ ;^:,..|ZFiJ1LarV=../Ys52|0aJct:;"bFx8&48xFb :ppTnYV%LXUI. . "P095d&&$5k4t .|8Or1C9TyG8i. .. =g&[yqXeVkg. . .;=Ja[$u35*Y. ci$Cn*948Lt: . .~&phT55$5G6..=Aoosa[{]u~ (9*0wy=?nUQI.. ^6sVb4?1$TQ7 .!OYz$3%iTSf=..~S4GC+cT98x?. .^nAFDQFPG;!; =
f2^ .=!/;:|SD{w$L*fI-..!ezLJ!nY49=.;"FFSO4mbdY0..XXUTT4O0PPn, "bctx*m*Ta48t. =O84$oosoG4+. . . .!}~;^!hPbaqD . ..!aTf$%L&[kmk. . ${IITmT69i:. .:!IaZez3Iw6YT..(zosTa&Ta49 !vom84Vx*5V3. .=DVGeS(Iyq1. =o6f]uw5DUI)..(U8Vvlr&sQW|. ~PQF4DQUP^:. =
fJ^ ^tTnt?2mOszzqSc:^^!hmk6]i99Oo.;_Xb*50Lxd01;"TebbeV0smD]:...^u(rU0O9GLYm)...)8kV*z$cwG*%.,,.:.,:,.jKZJ~")gQFFa...,.(SQPDhV6rJ$Y....cICY&TC6C9j;,,,.^(3rzm]2Ircx8:~0Yq08m8G4hL:.:.tCCw6r(t4eZ+....[AQ&7inmwcU}.... ~m2fc9VUdg3~. =OYme8L9Tnf". ..(&0kT*Qbg), ....... =
fr" v5Zm9r*a5IqZ&^C"<eV0+CkZaTl.;<Lry04as9t13?wQDDSForn0n:^.^^uI8e0JtxGLm)...)L0Lk*T[f**],;^;^;;^^.7XDAholoDPK5..^^:>0PQPQWqrfcY:,^.rw$50O4O5n+^^^^^;t6u3sIo91c89;!zSe48*8GGAn^;^^!=$TVOTt7sa! ^^^vFq2=!sh0+01..:. ^^!12cY&40f!..=qqAew949&o!....{pV84TQDZn!...,..^^^.. . =
2r" >58qpLnIaJegh!s^!6u+=f&As0s^;!CJ4O5{Jwayu"?lQDPF*)7*a^;^;^3TO8n^5x*m|..,=0mLG84TCy4},^;;^.";^.+KDAqSGaDbPa.^^;^-wkbPSDU*ocL.^;.20zswVzys6i^^:;^;fa$fy$m8itvr^;{LG**8maaa;^;^^+ysm4q4YT".^^^%g$"ifIs0+a+::^. ..^iII45Om$!..?pxU8tTP*x0!...,|ksb&wdQAUv^.,:,;^^^; .. =
rc" rmGqA*If1mbU{n;_yur5f6bJ!!Im5$]aGV9".!"feQZZ}5n^^;^"s6bkt^.?Tk*t^,.(yaG*O*4nn&l;^;^^^_^;,=k*FdpAgZQPk^^^;^/%0nhpFKS0]5:;^;C4CuJI3$+^;^^;;zo9su8m(=%[^^iY5$$nu1f9"""^|5I6Ls*Skz[";^^^{6!.iY5y6iCt.;^..^!t6&L&VPkC_..)pUxT+kDOGk=...:taGZs1VDSQ^:^.;^^;;^^ . =
J3" :/yhxxGGf6*Sh0!!a+7J9L*8*G8m$65TTzuwu^^~n]$epqDxa6"^^^!YG*91?".^}O+^^^tuifnYLzmnIi^"^;^Ii^"^jg*~?+{%zmxg^"""^(rtjrwzo0*&^^^;^vzaLsmG*&sj"^^"~Js[C*J*a6CL&5/^==3uJv~OmxT"""^fxO8e6+ze+(3^^"^]e0naYeqT=T];^;;:?U84a$AFLJnj.^"dx4IkWP*45);^^^(ZFLzzIhPDq<;^^",.,^"":.. =
fc" . ?r8OVphC8pbk~!]1!?2]CC$wIL$wI6Cwc$Y*""+xDWFU4hgV]""""!ffomKXS=;!&7""^(ryT24Ooh6u1^""^=a?"""%n7=t{71a*Q^"^""to^=t2GOa5i^""^^}xAmGG4Vnft"!""lmCC4f9II50*f~"!t6$rii*m0w<";_CYoTmT+=o%!J^"""%VSgAP0xZuo7^;"";)en%C0Dbu{h%^"\o7tIqDpzsTt^""^lQ4Tk8cfVdU!^"";. . ;"",. =
3J" +Cl&mLhzomxs~+%""$01J]9Cj$uCk8onTuc""=ubFFPqbLG>""^=aJCxDFXejt9{"""{k4]n53mnT{"""!fJ!""+OkGeZFSaaYS""^;"iO^^i+3owV!"""""jh8k8kos9cc!!_ifiwCTuICz58a](!!+$11[&kG8f!!"!5*8*m&u"=1|%!";.=$0h8U&hG&ni;"""^tT2+aqF0}$q1^"^>i]fVZOn4U7"""^9&&fwaJ[CLO!^"^.....^^";. =
Jr" .j6(fOqVGoTe3"!fv_^lw%%kC+i1%CuG*Y09a=!!iSQZFbXSkz<"^!tG%jQPDDQhw9t"""jXdr1]1LTO%!-!=4J!/!!CSQPPQFOk44x!()"^+e"./)tI*&"!!"--|mY4YyC$163]+1Oat}JIwC$C8s52tv!!(%]uT8mGm2!_<+*8I5gky"=i=i!":.-!}y0wuoswk7"""";)fuJ0PDTcLD];"^"vS$0ATaZPl!">+mTC]zT5$Tkai_";,.^^!\.^". =
2f" .^"""!!7ffji~ti1rannxs1lcaaVnau=t]uC$n9oT5wwzI}8?$aw{nwY0s3DGtPboI&*eDhs5}!!-]0rr1]Csh4zO3_[g8(~|(=c8a6y6$z9[$S(Uh4~rh[=ijt}s{!!!!!!!}fjtI9o$*t3C*y="Tl|fut+j9c$x5?t=%&O88**J[?!8&m=7m9v}%j~_^"|zy^"+[jsv)iui>!\~~vxOs6Y*pDPPI!!!_~&nzO$*QKb612VmSSgpqYs*een~;"!1dGv++{i?~"^,. =
v3" .!$$Is40&hpbZgbp&k2c]In*&OCzOG8T0v+[5J3Cf6w$r3Ifz2bj|Is0hV4gU0S4=AWg+1ne9TZ]=!>tj7tj5sok3Aj=*gx!)=|}24T&O5Ow+t*Dtqn%]aPqZsGd0C?!<!!=!=~1Cf$f}0k+fYJ?!+wfs&6i=+31LpT?=tJw8LGkatv9iJ}+1=?utn5="_+cY9!+f56sUo!ir?-=!|tnZksY*a4qD*1=!!!!t300aGmL4VhgGkPbQpdoGxkYxl+c0bm}3azyi^;. =
22" ,>6L48eA0meG*GmLm4*i[Iyw$+&m***r1Jizw3[I198Yw1[+{jfFjj[YSQVkUx31i=Z#XJ&Gxs5Fp2t!iTsu%T0YO%spJuS8a~=iJOGV4Y84yf!]ZF)Tmt5APPq0mbS}~!!!()=||+lo828Dn|lt!=(&dSA2%v]f4eT!tvvJYVm2?"[$t$]n5C6$tvCm5t!y5)+f4h*s*G{7[?!=(=+fYuTmknozTrt~_)i+iCgVaGx*YOn$]4AUPDVo4QIUAJsxDQ9}JICaI{>.. . =
J%".^|Aqx*8epO0hV8meGG6stCCC*u%]8yGs$!)=i86c2]t1Oz*v!!"!yFClil8AgU05a!)~9KD$==))kX&~!<!=|=t~~)=~=TS%8gL]{IsV84V*kkf{="?tt?+hCi1w0m4eLY?!!=/~i?===|+5wgDsit==;!lUdU4it+2tIkST(1cccuVI^^!Iwv+%Ogg*0z*G0iuu[t$Z0&s1zhc=|=-==|)?+{+iiti=!=tii1v%t3dmzUqgp837}25s9u(ihU%69{SDUg[3no3i!^. . . =
[f" .;\(lCL*xU4&syCo0YaTV7$Clru6+)ttitnk9$o4&Jfu9o]i~=zWei|l2aC]7tt((?ipDe{~=%KXw~=~~((==?==~=}V&20OwaVLem4V5f%lt|~=}j+ti2%"-{f&Irv+=~~~(|?lt+iti1xSQril+vuLUqxuu+1ll]8pbn}JI3ftt~+]vuwj3{~)t$n0Ts5kC$oIzTI3{=!sFx2=(!"ii|=9[=)t{{7?(t]%r3{jYp5{55o3i|)|}3[[7+]PF{czkqghJ~(=_^;...... ..=
J2" . .!([mm*8oIYT8&ssSbT}}vtuwoCc4cqULv3s6w+(nWQ!tFZAL}+t+++=$WFh+|*FWu=!|=?tti)=i?=nmmyw88m8m&8i|?+}7j)tv7v+)}l}it7]i!tlt~+ts1tiA[+ii5PDg7j+IddAqkizQtff1CSqh5InJ2j]l8F43o8=: "2%[I$%1ooy8zf+(nQDd++=^+it]g%ii=|{+tJ+iju[lyggyj]j}t=\!!=1r{ot2FXvaDPASt^.,;^!()+++("^..=
2v- .==Ch*V8eiv8a8*8wASgkj+ta6oJvLv4DFswIo+9KFr^!zgAFdt=|?|t8QDt!hDZ%)(=i7tt+(!(i=[9*&*Gm4O8nl!i7%}7t+t111t>7v7j+Tli/)]v=!j6&f]iDsi[j8QQPt+7*SPqA!wFftJcyZdPsJC]j+caSPL%$ao!.,?2[vuGti[+$w*88ksIzSPpl1t!+7sDv++t=+ttntt]%t7Gxbf+uTn5T5ojj[]L(%Ue3dFPGt^,!t{aGxpxge8w+"^)
J[/ tc4qkG*5uG4GVUp[0*xPY!3Tmw++nreZPZwu$${IWQw"tjmFdKD&v>^!!IDpI=PXQ{(=i][}+i}yn*TI9Tw9u]TyoIl+}+i{t"+tIu7^t$I%i0$!^tc%!tLAn%%}De}{2xgFU~1*ADeQg}+6pz=$5sUUD6I2c7%3sAK*+z&IJ^:^1r9w*m+=t]lIf9mw*6&uZgD[ji/"(T4F1ttl}[1+*1|=j16eAh%{9TaTG4s9yari*lIPhGbFSw!"=0AZZZdgpSUzt". =
J3- . ^CY8*8T2|*8GahhxC={CVn2n4mt!!s9r6mKKenoIc{eF4+c6G0OFXPqVt=/"hgxnQQ&6$%7}]3(+2mxgUG9u$f20kY*&V0o6t=yt9$67^![cltmO!=Co9xPx[%uzQPh2jDFbm1GSASni=tfceerjw5DgD5oyfruu$6r|!Iz&6j=|$TV8af(tcJ$lt$osCcuT3gqZG+7+"}hPe1rfljII1S5%j%2xQQmjtoknYY8&4ekOeTVgUQQSZLa0hpZgUbd8yt!". . =
Jf/ ..=TG0r!;(Gm45b8mh.,;/+w0To;!^$w52{DKDFQ3u73Ae2JQF!IQZPDQD=IAqDDPp#4u1t[n7!uxFU8mivCfnJO*0Gm86C4O3nrl?(]$uilqg{IVFUULuo2iyIQQ05PDA0FgFDj...6n[VD0{vOAFZ]7uJk2$5^.^f5*$(80*Go9t~"y*$L*{756I}t==YpPQo=+t4A#012171+jDU0cz4bPUv2j2mT94FFQ0&V&TkLZQk4ZFSDPDPPPhs|";. . =
JJ> . .:&oLV*&":;]dG*CqmVh,..,!nGz3.!"a9ou)Y#PFFkcv%FZzyKWt.!L#DgFFgG%&pDPQWPTav=7IufeSq8kG2f2oGL29nV*&Jw$IGaJ5vlT$CIjCUb3f5DQUm1[57/%3xP4VDQh4qPPA^ ..O%bDsikeAF=/+yAJJyy",;3$$][V56y6!!~+yw2xO9fykfi%?zPPps}i+hDAarfucIt+APkCzOgPh]59362apgDDwoa6xUYSUYpPFSFZFG5%=^ . .. ..=
23\ .^ckG*gC.."w0Om7bGk8^..,taw5!."^u9as~+xPpPFntcPZO0PD\..!LdDFQDAsrGDqF#4uy+^=TAbg&8fo6viuaV4w[1uCLnJafu*5vCCzznIvurQpwzebdF3vss1i7tYQgYPPeAQQxl. .^TIttVxLisFAe!:i&PLu90i^^}J[fCocI^;~aLzzrdbGsvI9%{{JQQpktt{FUP6JIrJ%ortAPAz$bQp8]Y8}oVhSFpa}$C$0AZqLLkqZFeGni!;.. . . . . =
r2\ .;t$sV*0f(..^tGm&e~8V8G".,>2J1|!>|?%TTz(^>{shFxLC8PxghO?~!\=1[SbAxhTLeg*ouf)!|9*e0ortjsa{]Two4Yf2ura]{al5n$TasIcjc45QYOxPQe+!20n5$GwoeZxegZh$+~!=ilJOn6YZxn&hdG~l8gZ*iin9[=]3JC>rwIt:"%GLT5zebgV5cc{~8Zde[%0QQZ]6TzIo7nGZ85DDF8wTuxFQAGy?^>|I0Aekk8x84&nIJC2(".. . .. =
Jr\ ._Ca4&4%. .=mhmG4^3G8m=,.(aemmSKXFdPDbA&j]&hpDF[nTww8ksAFqAFPAFFbGA4q4FUc)!tt|t{6)!&xC?c4YTsV1iC$saC$$ouz*Lmw!;;(D{aqOUDQx57IZDFFVwKeaSAxYOG15GZFPPpQQgbbWPdhOsiQgZx=,;tmozuwwo~azkz"iCTG4wuL[r*xAAeIc~tQpqorpQZZTJJ9J3l}CCYAFkFDqmY$IxDQD*sgz_[xXWbpkYeDADAPQhf2f7". .. . =
2c_ .^+8TnTz . ^[dm0GJ;7OGm|..={CLAhKFdAZFPQQbQqxS*pFl3kdPUQUQdFQDDAUUWkkmZDFd[;.:,;+8y]LG+!ukZma**3[J[IOsuCI50*9[".^~b[apbQPZO44bFpQdPTPUmpgzCoUxPQFbSAggPUZQWPesskCoUDdv...!w*ns96u?wTY[=rGTy]|s9uTdSQFxyvt!kbFVJbPQaPC7%7fsLYbFD*DQb9waYPQPd8pb*+hPAqDPa&Ad&pQbDbAd8c(;: .. =
rJ< .!n8ayt;. "JL0*mf,t&Gm!::+^|rGXQSDQPQAAZQFFUY5IYqWWDpApFbbbUUPPFI+v&O0DF3.. ."sD1+*kk!!u&Z8$zm4oI+Jys$uzaoCIv!(=tba4bZdApqpqbUDSQDPwpUD0k*DUDPDDhFFADdPFqpn6*U8cVbpDi;"!+wL8sz89i6z$u240LY==LaJ4qAdDh3v"2ADgngQF1WO+%ueQdV2WPDeDge{9xdQqgO0XZYzI*SPZD55D&GmPFFpUQPb5_^.. . . =
c3- ."~~-;. .)0m4YT~.>$&G),;"...;<1$G*dQQQpgASGYVeeAbKFgpFPqgeSx4T3tVTYheTkx3....temi*hef;^7kmhn)Y8Gaf3Iww$JJ6uc$CfcCe*xZd*eUDDPDdPx8z+%nLhhe4hPphSA*O4aOmO5u6hhZg06hPAh$nVLxo4k4wwwcwr9y6ms4!;"9o5J7USASpOr+tDDDOFpG=FJrOSXxnJfdPDZdQ6ugFqZ0+"iKQhl+8DqxFh3PFexGheSdZSPg85)^.... =
cJ> . . &GYm5!...-uk=:... . ...:(2C=""~!(=i]lvzYyzj)_~t)>"%dZZZFDhDd{[=: ^j!,(UZ0+..<688d~!+ra8Gowu]=|ITnYz$]2dgO8wGwv}!^"!%rC?,iFqbcIhXPFFx\,,.."inFDxd*35UxanaVmwsmyo9$v=iifa9jw6T{..^owoT%tlkpQZd5uxDFqQ8!"yDDQF40PXx0dDZq51mDPZi;.,^ion5pFpJ5DA%sUFb3/;"9SSDUdZWK+>. . =
J3- . . .VVom]^. .^7a<: . . <[3^ .;^-ir80&Vk5T!.."";,.sDSDpUFPhQb(!+! ^"..+UG4~ ^C8*8+"t58*8o6fu3cJv=!?ticTghSV0GJti;;^yak="xPDF4?}gFFFPTi"^. ,"$DYpG5k&kAd&6a*&e*6$uII+7+I$?%soy!. ;$56yf^.|GApbF4yqPbDs/!pDXFg=2xQbVUQLkYahdgd)=?tlv3ossan!OQPu|pDDD{^.^!iaZPeXgxy/ . =
2v! :0kw8!. .!s". . .. ,tJ:..^|}eZq&LbUaei..^...!QQpDqbgP8QWt.^^.;...%mL4^ .^JmmYJ::!I*9o[icz$+;;!1eDSS0GkQ4mx$t"^yhY!jPPdDD]=+QQPPPd8+. ..~smbxVmnxDpg*1[c4Tmoo$uf{+~""CaVt. ,1yC?..;!sQpUO}eDVDJ!wDPQP*;^isPZUd44LeSdQYaOhgUASd*G5t"agDC"7UQSA],..."(nbpeex". =
3v! ^k5*k:.. .;[^. ."(:=j0SFggZeFUUzIx;..._vGPDge8DQFIQPe".. . .^z*$~. ..t**h$;"i06$y9$$Jzz$?~LbKDPmfzhepUQZh*sGYu_PQKKgbg6=thDPUPWF=!i$VeeVoI7tt~";:::^!?iwo91?)?lyz3t~"^"tu$$[?=!"~LxZDVGAxxtupPe5i".:^=Gxebk4LheAAqbPPPFPZPZQk$)n&xC.^?eDDP) ..,^"~(|{=;.=
3%! "5ws{. ..^^. . ..^!wUFhPFpGhFPYGDV^J+./&QPpUa/^gDQG"5DX+ . ,i$!... "dGZC5G0$!kTC6yIIV62zUQFFQ1tqQ8qUFDZPShpptcFQq$PPA:,.^eDQKPpJ"\|IqGDFPFAPh|.. ;nkO4L3{aI$r[c$G*8mm[=LeUDSqZADSpPbYa9Y$VQFJ+!^;^+VqhVV*0OsyGFUUb&5ksvjl==!^:hFQa .!FDK*.. . . ... ..=
3v! 6s6! :^. . .;+TAQpDqF9chbDowDx,!]"$DUbFG!:;DQby:tUZt . .;2t,.. . ^hAO3Yko~"2kzwo6o3aGuC&KK8YSu)yFpSOTbSQPhT0oG#KViFQg^ ..~seWQDbt,^tyCFAPQQpDq<^"(}%=C!!5ouii(JT4mmLat$uexPPDAPppPQ4m&8shqDs4ay6=^<+ZAee*0utjl{i?!><"""".^<";SDPI . ;qWWx^ ... .. . =
3%! .!T43, . .^ . ;=pSpQdZe+cZDZlJDq,.")FdDpDv.:!PQUt.^}x+. . ./J! .. :kVsa]!;)ayCIu*mCtry3UKP9kD6!ipQbn|vbAZDgdsxQK6!QDD(. :"=9dQUS!.++7#dd*ADQPWe7^.^;,t^^o8mc(.^!=++]2tCCIz4QPbgQQFdphV8ObQQFFDpAGr="iap4xVori!^;,....:,. ."^.hSF[. .y#KA. .. . =
2%! .=V]^. : .^lmUgpgG5=,^GbAS"JgW^:iYeASgV;.;jAZs"..^~( .;~_, .. . .z3Iy^:..ukT7+2Y&o^^i8KK8$qp4\"eFPh~^"~9GZg5PDXs!mqP. .;|zmmj^!;+DPPs|rLPDWDn^...".,20wz=....:::;JC/"~(lu6Tx8SeUAeDPPFdUPphk+"t7(FPQpxn[!;. . ...ZD#i >fSD[^.. ... =
Jr! .|;.. . . .^wb*p0nJ!...-yqD*=.!gq"1edPz!....|ZQ;. . ^^...;. . }4qz. .:Ym5!.^{0o3^jb43PDS^."LFQK+. ;:^_gKC7&taFF=. ..^!",?S9qb(.."C&PPA6\.:..:i;!x8=... . "$C; .vOZDxzPP1=4Qx~:... . ^;:(FDAL5UQdk?;.. . .nXP" . ;wh7^. . . =
fJ! ^=. ...^jqx&a(!;. .vgFSi^.^wd!kdgw\.. .thg!. . ..:;. .. )08z ^&*T^ .!T6o!5h!!23FPU!..+QdX9;. :..;e&!_~=+hX+. ...;,^^~u?2Xy;..^!tyDxI; . .!.^3dI". . .:=2:. ."qU#pi3QAC^^=mz^ . .^.,\DFg47LpDPO+".. .A*; . ..=qI". . =
JJ! ."_. . ,;=v{t~"... ^Vbh0". :tauqgn!. .. ,tQ&^... .. . . ."n*{ ..^G9J; :;wyuc6+,.!lDUAt^.!eFK8>. ...;h|...:"yX]^. .^ ..~+;?gQ=.. .."J*q=. .."..<JOt. . ."+. .;6dQUt!4p)t"...)!. ..;, .>gp#Z=t*DQFh1; . . .re%, ;0L!. . =
f2! .,: . ..,:,:..... . .~PFm!. .^vC)":.. .^3Q!... . . . .+&t >m9=.. ,7Gr:. ,!PQP%t.;ieKgf". ^),.. ."P0. ..;;. ^^.;zWu^. . ..:^";. .:...^29;. .. .". ;CxeC";1x|^;".. :^. .^"...^]aDW|,+&PQD).. .jz". . ..!i|, =
3r! .. . . . .. ..IZP|.. .:"!". . .^9e; .. .. . .^{~ .=Ti^. ~a2z^ . ."SPh+%".^iXAg{. ^;. ,nx<. . . ... .=#Z!. . .. . . ^!^ . . . .=F8=: .8t:. ;^.. .;^:. "^igDl .!nDAI^.. . =_. . . . ;!; .. =
cc! . .. .. .^kI-... ...". . .."+^.. . . . . . . ^^ ..(!:. .,{aw! . ^SKI,:"; .uPPG^. . . .. .!G>. . . .. . :$x).. . .. . .. :. . . . ..!~^. .". ."". ... . ^.^1b: ..^"C", . ". . .. .:.. =
fr! . .. .. . ../9<: . .. . . . "".. . . .. . .;;. .(^.. .!y6~. .;pK%...^../0qq^ . . . . ^7!. . . ."o(. . . . . .. .. . . ^",. . ...^!.. . . . ..!oo. .. ."+(;. ;. . . . . =
c[! . .^>"... . .^. ..: :!.. .:ow~ :hF=. . .~8p~. . .<>. ^!. . ... .^. ,!r, .:^^, .. =
r3! . ^^... . .. . . . ,; ....{9~. ..&V^ :|$7,. . ,;... . .;... . .). . ... . =
13! . . . ... ^=~.. .}!. . ,i^ .. . . . . . ; . .. . . =
J2 ....... ... . .. . . . ... . ... . ^/. |;. .. .. . "^ . . . ... . .; . .=
crt??()iii++++it++ttt+iiititi+itt+++|?()(|?|)(?(?()??(|)((?|)||)))(|?()?)()()?)?()|))|?)?|)|)|||||)(?|?=?====()?======)l====|})============+==================================================================================================||=)=========================================i
e3ZYYd
sIRC4.exe
C:\marijuana.txt
uk.undernet.org
Runtime error at 00000000
0123456789ABCDEF
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetCurrentThreadId
GetStartupInfoA
GetModuleFileNameA
GetLastError
GetCommandLineA
FreeLibrary
ExitProcess
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
WritePrivateProfileStringA
WinExec
UpdateResourceA
SetFilePointer
ReadFile
GetSystemDirectoryA
GetLastError
GetFileAttributesA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
EndUpdateResourceA
DeleteFileA
CreateThread
CreateMutexA
CreateFileA
CreateDirectoryA
CopyFileA
CloseHandle
BeginUpdateResourceA
user32.dll
SetTimer
GetMessageA
DispatchMessageA
CharUpperBuffA
wsock32.dll
WSACleanup
WSAStartup
gethostbyname
socket
select
listen
inet_ntoa
inet_addr
getsockname
connect
closesocket
accept
0,080<0@0D0H0L0P0T0b0j0r0z00000000000000000
1"1*121^1f1n1v1~11111110272
33E444
5X5555567
8/8:8E8M8W8a8k888888888888
9 9&93999S9Z9d9n9x9999999999
:2:J:R::::
;5;_<l<<<<<<<<<<
=#=|==
>'>,>2>>>>>
?!?G?S?[?????
0#0,03080>0Q0Z0x0~00000000
1*1J1b1111111
2$2,2222222
3!3+31393?3E3L3V33%4C4O4W44444
5+5D5]5n55557
8/9X9_9f96:K:~:::0;7;f;
=$=5=>=T?[?l?x???
U1]1f11222
313G3^3s33'5555555
6.6:6N6X6k6666
7A7H7j777'9O9V9n99999
:c:v:::::::::::
;4;?;\;f;;;;;;;;;;;
<#<E<Y<<<<<
1U5^5i5n5v555&6-6?6]6f6r6y666666
7"7)7-7G7P7Y7j7t7~77777777
8,8=8N8Z8_8d8k8r8|8888888888
9&9.969>9f9n9v9~99999999999999999
:#:/:<:N:;;;;;;;;
<"<*<2<:<B<J<R<Z<b<j<r<z<<<<<<<<<<<
=$=.=8=B=M=_=r======5>}>>>>>>>v??
0l0{000000
1$191X1q111111
212I23g4444A5s5{5555555
6'666E6T6c6r6677z8C9V9g9w9999
:Z:M;;;;;0<Q<
=)=7=W=g=== >s>>
1A111222
3M3U3`3|33
4555)686\66677]7776888 9>9i9999::
;C;;;;
<2<D<<<<
=-=p==3>?>L>^>d>p>>>>>>>>>>>>>>>>>>>
? ?-?5?<?U?Z?d?s??????
0q1111111182R2k23444
5I5V5v555
636Z6o6666666
7R7o777777
8-8M8e8o8v8}88888888
9+9J9y992;:;];;;;;;;;
<<\================
> >+>6>A>L>W>b>|>>>>>>>>>>>
?%?0?J?U?`?k?v????????????
400111
2,212@2N2222222
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8h8s8}88888888888888
,000409999
WinSock
System
SysInit
KWindows
UTypes
3Messages
iconchanger
sDeclares
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD"446T/f(
=q6m?l bmU
bDu}#/c
I!)bzjZ*
Fux&G<
?[XH=2ICT
ykd6]`
sO+gQx0
e"+/bf
%+?Pir+8*w
9RI9x1\
O3#kMAr
+MoY`V3SZ
G[`@Te
^3@@-F<
7dz]b:(qB+{.Wr#WI
ZrG"nVb
yF;>P?
-%\u+=|ATn8
!)]t5iA8xfb 5:
Rb";0l
LA0$#t_<
*]YK&Bssa~q}%,
3kGA S
l~fK&|
1n3{i}qDNv
*EPkVs
WUD`,,*]
^eLwZJq7
Hp!o2D~Dk
RjCcV/Rq
+[v|k$KVx
N?<z+r
!Q'-Ge
bOp(Ei
k%V.6Z[$&U$jF
.5+KO'2
Y,G,_H,]%
wV{}d-F3LE%P+
/#W}#qDn
%v-u57
*eL)*W
-ica#8
*j4UYZq
!@wfEI-
h~!^>@8AS
>9pvN-E
4ut8Fo
^a^sE}/e.
lI@7n=rTc/l
oRnm;K4c
gv5x?|)aDptjGMS@V
=GLBGtL
\"7'}U| J
I8m`8F
-=NWx#
P9s!Gg
RGzL_>L&o
),m;xs
ko k2,B!
Mej E6
F1?VcqV7
%k~JTN
'}2 ,=3
9um.CDI6Jo?C2<
Lv=L:s4<
N<aBI92
I0J~A|1<W{|-;0^va./
<B-~vc2!
4I)Q"V?Q0
KIW|s-P
_|:arK|
*h'sUv
Z8uNpE
yiDhl+?&,
5VFZ*8t1
)Idd*r
<&)Ch^1b
)=,9S5
bk*?wI|1zT1ev
a|<0$&d]w,b>
@:gvK1H
).22ndW
9c\S<W
MT>r[-/.zeQ
Hx``OL
F/^wY{
}G4`P+UDoBa
77b`*n
`_d"?~p`
Z_=gZY
";?H`7+/u
KH}ao]vg5
(V=\@Bz
?XqTcW
.Wp;R
E'E]C7iP
ulDPKG0~^!
QJ6|i:Oqa
%mV`g"
GLJ|XOR|9z-c
ZJJ;c{
TQt[1c
QfeP5*
%>J:aE/J
V\g b.y
f!RgvI
R=WQ;X'RK_m
]aka4:
we{tFq
scX`Etl!7I
mkAmP65,tS0z_AV
bmLz<z[@=]
=-}~tzg7
#1}g:x
G2pZ+_|LQ%D,Ka
bRjn{C_N"NOzY(
*1?FC!
FhEwb8l
@os5YCQ
U"%>1u/2>q
%bOsz6f
#SLB)s-n+~)}qdVU
j?RofB
X(~`e|:
P]eZZ1@=fcQZ ;>"|KV(l0}V
cj!j1wSoDj
.;*[T5Ai
=wINT2&51N8
3795^).a
(8Koa_-m
x`H\E5Js
fd$;#||^h[ C
m@&-!5R
1t:GJZa
(H E!77
xedQlU
fRm6"C
oEziiFK
u%/,a|)+RA
Cl[]T9
#"i^Vvu
*Xk}RSb
:D+N9_
@j(@#[x
Bugs<Ga
_qx~]&P7]g^m-
_yb+Nt
Kb:`iB
1_`aI[
[E!ZP9Txni
8e$yR|Q<
wK'48Lgi]c
gHh,;^
L11YG-:-
3J%J~F-
c[)DX+*_
^0qW"|:E-fr
D(V8[Y_.V
N<?R8{
fOG{'0J2g
,5|*{>cYk
D_js`i^jV|
K!WBxh9TQhItW{
j>Q,nC&o
{"0T\L%
Y(0L,@M['
`_mtCpMy
]q.JCn
mD4j!bW
4iqV.OXl
48m(ThMya
.A,&?d
aI(Fkc
yiW;3m
)PBZcbr&
4=#5+yH
bA8\QZ|_mK
S;uWy^w
MA`}kkw
6a\vJ/
%)zb;vu+~
?,&;[K
Q)B{Si-
8{KvPj
s43/vzTB<0&'
|\Y-l10
{;KuYi
gpF,Hj3sU
Gz%F8d|
XWYy%1n
]OkJk[;
\lkf26
UZ+_5h
$ArbW*KIN
H*jhR4
Y!M2?"P
'\/29t{
ahxC{v$
A@P4}{_5^UJd
9Y7{^BrM)Y
-S0?x~v
fu?EnWw9'
>`9qZQE
+xZ>+sc
sut2nH
#?POX8Lz<J1
W{"zTPism^
=,5w1U
hBZ-3Kg
4b?+[TS
p8o#lUWx*M"Q7
3BNL_z$yBHwQJ-
M#nI)K
D*vGyh}(
6ehii;
UH}@tP
:N5a;{?
eusQTfJ;/
v4S,lUL
=>z8K)
T=DQ4;mM@
_o!j!OAc}YvNeOR
lT^+O(l
JgL#tubJ)q
}.8fwZ!
fp+3b9
XCjt]8
"+4Seg?x
B0-glD<!2#a6Uy
*"d^A(|
8|Jj[h*`e5wo
y:,6X
nbFu2KVI
i06BUc
XyXsj^sR9@S4
<\[8Al?Bqt
)>}t2'ux
{`dXk=1_%z`
e|<_9\Z
r5r@_)K%
S~1psO
:P[_)!
G0yu;V
BzJcI,K
]eUZ2$|
N:!y)u#
%6RaHjM
[E6B'a
;>$U*a
[!Urz}c
utmI[aU~
0'/.Zx]
|mS:bw&
W5=E3
smOnm[BC
69~DMXhX^n.
[->LZ8V9Lu"
ovPG\[
85)!rY
exs9M2
z}c$kx
<T9n6b=wM
vQO.(/#(
TPb&!-
;<H%4>"
xtxm[!%
lRj~T^@w:4yjaJ
s_}I_k@
%~^Zgk;do
>%N7J (2f
nF2BJk0tI{O@8s
7z1~2vdG
*b]x)tJ03s",
gg2~[qWmr
A?RapG*
2=0`QcO}W:"
/Hdp^
k*4Dw|^
'j8x?(5
2Y2~7c
-Tmg&m
Dg%KZ{%
Qk-kGVetYF#
rWMV>{<C
+q+}N\Ky
bT_kc*@
D}K{tf&~?IM,Kl6
Ddvx_I
l Q7R^
$U,ElQ0-I
!AJq>c-
[<m}!uqUDP=P
,S,6'41c
up=5e5x
6g%RK<69
twj(B#6
EK!ouz
LW]%lQ
5n_HWr|Mr
%S_3Sf
Q`F;=H@
7.oL(3
/c,lG`
J\{Cxh
)kSuj#I
EU~*'ew
?oJ~IOVt
#%5!ks
55y,VY
MJ&gJFG
!-f>+mA\
GPYwH0UjDn
N%2hc[QS@61HQ,'0po
YbyQQ#l
'@>$c%
C.<$vf
|i|l|h
}TmE@N4#1B]'9m
\ZUC01\
8yEN66E
<oLXp@
/K$2h'
rhCR#Y
DCL]Y2F\B
5mL"/0=
F7D5y>\X`
qH#`)m
w{+0~2?S
u%_9Ynpu
(p)5XkXJw
$)[cU"7j*
(:A\M>{-\
?I7k)6(9Q
d3SDgV
+^Q<:&
qL[6w7IdhJ<3}+L
_b(W(G)89bmO.eA:
q5r&,_+s
Wg;XqU#BY*
rG6DE\
zi{Py4O<D_(&
=Fl^:G2e=
}TX!%[
N!1Oi('
`ej5Fuzg
+m]<Fk
9g:!#{
v07&;*vYL
9EW/#"w$8sipxvrQ]Ho}
!IZv?f%q/tj
M);vZ:v
bs*KDiTpp
jB\@5{]
~{^@a<)M
1_-|E}ja$
wy9hQnkRk
.V7w-4R
z_:<Vb@f
GRo_7~
7~0$t1
BJ)lPU5
i)~bl6? cI`
=$SW_Zl
CDh2wSt%{o8%?
hGP.sq
YJP6*Y 6a
ofQee"@B
t}uiwe
=F$~/z:-U!jVA Q
3nI~d(
B#~=*c H
,,:?8O>.gTA
=?;y;s%_$WXA
?jKL;6GV0]l
mX{>)[
*Azjv#L?]1
;=Uvy&1+3N[-n
]Gd:Sf
7Wo&'@
qd,C|hbV
&:m-ZWj~
2,[a1i
E6z*vf
r_rX:XJ
RG!AE`
}|%bW^
nsFTH#
?bSm@ta-
,55I_xSkDld~
Td85,#F
m(7r**Gk^
F2!q= ]A
68u\IPnFVV%Q''
^Xj']Pe>`
H~-,rWjZ|:v*J^X3^B
*[;{V0
_aR)]}
~_CPFR/w
F,-5SS
FHt/Lpp
T>7iL`H
6& 4RF
[ixZio
17{ q)`<-<XT
5^UL/orA
O@,1pL;
4'6IBnQkB?
e{8RbXm
n.a]g(^4n
xC\EeP#
`?IN^,,e!\VLZ2
o*V1Z&d?^
vWcva<P>H
RQF7qO
Nez"Uu5QBSoJ
pPy`4Xz;MiD
xHT{H"!
*t_j/A6
o@gr8F8*zws
dt,)CL
W.g~d7,-&
u)EI0^#
KojD4Q=^M!
vzc^0^/2
w\w1\bx
myz6s,~~/<-
0mV~=[!s
|CO96C
KOJ>d_]'
kj&!1Q
B*^mk:=b
L[]0 *
W4K<MM
&[<o)nq
(3H.!T6
$JiP5R
=,|Ox
+]amPc
E{#Zts
f.ox1uZl>4=)
';<K1gi1Xg)
!--i9c_gxy
TUZZ\oII
(|0!<A
>K#D,S'pxwMb[NO(
#FhOjO>
IcVo-g
#jt{"bm7y|ztr5-Dx;7n|(byf^
)0}(V&di[
b48a;YQrZ
VR-VQE~E
W:GS%vi1
q8<n&D
e@gk~rU
<>Wo>->pO4h?
7m2,p"
NqaKO/`|!
rm$Ymc!:Pf=
FSM2.)
>xn)b<O
Rz5 ).
Mb][)+
r|p3~%*gS3XTe@:
m#{nuBFsQV
>~4K)@
?N]UMb
Oy#[%-dlR
s#()lq_7
^Mcjb+7%iymI
8NnpZ`K
I.:k]Iw ! )A4ZpE
iaZ)^;
p8)o)8Z&#a
c"4+nNC0
H3afj64|W
PP\|u p,
y \U71.XJ"p_;0
Ke?B@a$2 "
2kjGU,)
A'M(xq\
:H&+7X
^4#o)o-Nki
2Y#B=9`
.S`Uq\Z%58
tW_[61}: ePb81
zlZZ7nm
3"oe}E2J=
=7l'>$
9_pLCt<aK
d=K_s2d;
V+OXShDR
zyRurRg
\1IJ|'
enlyqz-
SXU(3nq6
$TlzzO
wmuIU^1+C)
yf;f_O7
af*+wmW
p'q7-[,u
XZV)J3~Th(
1/A6eW
RxgX=DB
l/39x(
oTeEa@*:
DW49l?
_]K$6t'.
h"sT8xj1
K<u_@]
3Mf3Oa
:c u4Q
/MSmlc6
{5Xs46>E%+V.
(h &JHn
Vb+$=te0
.a|e<^
?gBU1"
y}-$C
n2U5C~X
?^7&=?
t$m"j\
&j//]%v:
FXX8n&
*yJXpS
Ci'pa*
4jt/::*
o6grf
w7:wGp
a))o!rQ .];
9](J~y
H9*QzD
?0Q{ spN95t
Bh>!5a\
/y"cA{d$W
^|"~ )ZLV
DJ]&Z9,n;l^@]
u7Ip(a[C(
SG<,$S\K
A6\l3\
.s2p74Y-
Jp+:hII(]
MQem6^
/(K2ll*
zvu[]&~
U1B(O5
&uGJ%
q~mrao
;=m.x9N!
VJZ$kz3G
<n.g$|EgsQ
^aXyaJn5
u*DKn5F%A`~V=
QPnot+@s
wT>gAL
`\L'K.Y{`
a:fb)~8x
CnsWb|o"e0z
O;W`=r
c<2E(Pg]
a|dT`=
RT"L.HZp
SPdg|a;
BW'<0g
@&t9 f
iD!d_R7Sr
%/O`Vh
(5Rdie
) wO:])u
9/65LR
;YdQx
.~QuKc
i%|?"TCY$O<8
;/<16.
hi=[A*
WcKH<dm6
}RLY9~=
T)::kIS
|y<8MewR)
K"q|Qdn
GQH2@k%E6VJ{xyR8iv
d2Vf Xr)
Oc3%,vm0r._[
'%3qo9
2NUD(Cd3ZcYq^&ZY*FM
om>z 4aZ
RUqyrB
@.3s-&
EGz2oU'Zm|
jZTN^{NMUV~o
v/:&LPw?P
jo(:hxfH
[1t0M4` f_3AEuK"m
%R8[xB)40t
"M.JRmli
#K=z\Sz#VZ
OPH@T5Ql2
)l[8W!
Ml3p-F
x>pPo;f
X+(U?x
|a{n4tf'([\
0"C6r,
Y!stP`
4S;JD:z
U5=taU\
e|Zs>6
d{Oo){
(*4y0ZpsT
uy^~@Ump
a4r_~y
j"h9n%y
H {{jO7
oU<]p&
N`y^w?n
Eftkyq5
Y[XWicUZD
Y'l[t`#
gjRS,~
F#\+sx)
)C`CK>6 V\P;
=Zdf(r
/e:~pm~
QrtdFf
T.h1KmJRGGZ]_
>&V,4cs
/\2u&fd8
'j~a_+\&
dI+N=A{-
?e;>KnE
iXFX"
%ZF5Fc2Q4
y5K[ZEb
Q/7r.b^
![]W&Cn
"r8gwDPtb
C\F>+m bgIqS
A*"ZEMP
Z*mR/o
Q-t;<*h?
@&o.Hp
r>DsR0yA
7EP9JuRG
}CXTLCx|4
T)DkKy
_oOTC[
9$: -/
f1PsRCjB
3x<0}/
f:1W2(u
n}]$:0eD
KC6L?@
$da2xo
\W7,G}S<_[
z`Z(}b7_i
$5U6f{W
Vnxl-/
CxtCKP7@AF
l52nE3])&I
]>ly?7
bVu^eKQ;
Aamh7[6
jk%r.,fS\Hq#Z<
13i0UX.K
Ct>{@I
2m9)pG
*|$_V4q
:{W~0Yw44
C=.zU3
[?tt,u
s`s'qa'
VCV!xtE
UF`B'&h(oU]vVM(w
`^8|=G
x@=GUi3
Z??JlLr^"
rhS|u^t#1
C^I+R:
1iQWFw<A)e~
|o@<yH
v`w[/a*
*2=BEpiX*3VHN*'M
;!91jCR
"A?:c:O*}@Hk7SC9
'04?d:X;V~
mh2;M2
yU tl'
TrDG'_
WT|TMH
:6D@V"
hjBC09
=3zx?
Ky|P(<?
[mk-ZF`+
YJlX/Y
1r|/Q0Z
W83lt"
|nbJ*=u
lju/P?i8AB
he?nP'eC6)r+a!!}
,DKido
NTS%L3
1t/yaG
[uL@!Z_x{%
@=A/$XA
4R06O/tIN(
:%zjln
-SN~V0)
v7uGINZ
k5(UoFDPe<sT
MU\H8~%&,i3j=Q`<4
:He2H<fb]
evDd53Da
>`Q`dh
Rr\:<1
)y(uBZC]w
I%JxWYWNE5!(WuZ
&f,\&Y#z
8NnGN"
X+E}rv
ZJ32c`
[/"hEv4
O yw?d(3
0-r95.Fm
7EBr5H+{
Kv%b5dBj^C_f
Fn`7w0#r
mA'l\x
,.r^Zh%
gSY3`:-#Xo!
dL^=1a)
r0p^`eJPgA%
J&}h'50
mdFcVp2TgSBfv
F}5\&g
q<}M4ggws#w
=Bw*S&b.
f^]GCE
GA%^ziz&f>9
6L)W+L)\
C7kB6/
}S]Rwe
M5t2'dB.+
\R*(!`
7rj(s`B
oJ8<n!X+HVI\p&G}N.
Cu_:g+-
+C?Kgkz
@wKnJ!Bs
ZVFL_#E[C
v7U)v'MBfmjX&
zsF.$u
yCO@ES]q
S8v*=O
=Ri\)c'
w)$@](y
7_X@,G
ON.zpJ
2fOIWD&}
Q:oMjfyd]^
c:?:N]Y
VtWFXTj]gX
&T/H2jWV
oMS0yC0r+~g`
[W bOi
(iym1P
(Xh(W|B
umP+}N
2qDV2bMZn((q;,s/
c|vzVB
e*)m6y
/Qws(Z
\qoG'$
6>K,+q
F.*5j^
a~]&]?
GRi:r@?
B482^A
Y2y1>mQU
*KQ5<c
q)oU(V]e
!#FY*/
jH~VJ8#
3k(%zxVu0
d:{4,wf(g
zX@>x{"
AKL0dpdn
80a8yf
x9YuI/
n eHt'U=KV
{r8C(p-
2y>~x4nD
Evr6LA
Fz<|0*Dt
"&]dR
~g/^nV
D94Bu5a9
k?d~{T$E
@**Qz+G
!&isxD
Hb0y\x6yXFk[
@OMCZRU?kj
{-`A %
A"f3Yj
~y"#[q
c?/PiL5%?
9gCMBX/
\o:K/+t
.W>R+1dK4qA
*Gc|z#P%
NN!Z,j`o*0
89 g]V
f:;NLrzt
K!bB{e%I_
S)8F>\,'3'
9B,Jgi0O}O ]
=n,xq{J|X
"@uuZ?aQ
+(X%r#
h#sxPU
n`T=.~GHIfF
DVCLAL
PACKAGEINFO
MAINICON(

Process Tree


38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe, PID: 1860, Parent PID: 928

default registry file network process services synchronisation iexplore office pdf

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 00f4cadf78e0e978_execsc.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\execsc.exe
Size 141.1KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1fa7b2c0d6f1a3f0d9f815e7774d64c4
SHA1 aa5b57031ba19d2701f80f617f08f2dd1dade380
SHA256 00f4cadf78e0e9783762c057a37fb71f29e8402cdcb21892d459703b44d97ad2
CRC32 3DA7ADF1
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 6f554d2a84935c99_install.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\install.exe
Size 549.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d1efc82836bf9e3d585a217f8feedab1
SHA1 c3297bdb93a7e893d7d44068dd54a02f67957668
SHA256 6f554d2a84935c99f9472fe4102dceb2f8d0a2326045df0027490a8f7fe615b8
CRC32 E42EDB4C
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 228b725f13155d59_wmpdmc.exe
Filepath C:\Windows\SysWOW64\DC++ Share\WMPDMC.exe
Size 1.2MB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e12e50d1ac884182cda7b9db5d1a3a69
SHA1 ef6922b678173518096007889645d9d0da0ed0ae
SHA256 228b725f13155d599a381d75a0a7e705e7093a93dcd5b3d5e953bb99a79d98e1
CRC32 F1A69010
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 474382f1fcabd735_journal.exe
Filepath C:\Windows\SysWOW64\DC++ Share\Journal.exe
Size 2.1MB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 8a4812636b20f9a06cd4768cb8b844cf
SHA1 3ec83025a4e1748bf16aba830554690fa22c4b5f
SHA256 474382f1fcabd7352a1c6d83864a0afe7cf58aae1cfa6b42d988289ef8ef88f0
CRC32 5C90501B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 58f63563a7573255_wmpshare.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpshare.exe
Size 151.1KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 eb51e21ec8eeb7b5ceff5739c1175151
SHA1 2838f49b43013322a777eaad79883446b03864a7
SHA256 58f63563a7573255f04d633e7206cc33fa9e7451ee0a4dfb4e27543d06ecaab5
CRC32 154BFBAA
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3435f7e5bbcfe0ed_wmpconfig.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpconfig.exe
Size 114.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 fb992c96758777b30e850c2c6e7fb4e2
SHA1 efce027ef412cd08d26f4e65109e888347a1988d
SHA256 3435f7e5bbcfe0ed178872c292a4e9cff63cce8ea3909fc6e6dd67344971d74d
CRC32 CE8E0421
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2e42549706765684_wordpad.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wordpad.exe
Size 4.4MB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4d1c0654d0233034bac08ce0f7ae9d7c
SHA1 25a0de83cace7f014e9e8dca67f5b6266c477fef
SHA256 2e42549706765684020126b6c79869f52aa696b14265e693dcfabc6f2d1a0d48
CRC32 B5A70C1D
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 2f520493197c212b_iexplore.exe
Filepath C:\Windows\SysWOW64\DC++ Share\iexplore.exe
Size 678.8KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 094aa7b3c00db8cca12fffc195b97a07
SHA1 8eecc7e9632a7891fbb615e4ef3aedfcdbe4a132
SHA256 2f520493197c212bfab86a6ffebdf32b8dcc5e028d2867f389006abf04ccbcd2
CRC32 1C2E70AA
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 9189432f4109c00a_is32bit.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\is32bit.exe
Size 111.0KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 88604a08cddf7c69bd3b083e637c2037
SHA1 7c7ad44803d138e310ff9912c0b7e4d52d22215c
SHA256 9189432f4109c00a5e06af29ca91d89f4dc0f679f90ae76cbd955103563ae0bd
CRC32 7A9FF9CC
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 23dd8a4dd0fb8480_inputpersonalization.exe
Filepath C:\Windows\SysWOW64\DC++ Share\InputPersonalization.exe
Size 374.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 f0e940b7a6cfe694657fbf552d39285c
SHA1 afd486d166aa69e2f2fcf08c3169a54b207fe551
SHA256 23dd8a4dd0fb8480ca417ade9014d25a27484680b6ed94c5998eb362d547ab28
CRC32 29CA0807
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b2647d1a8b2eaac8_inject-x86.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\inject-x86.exe
Size 138.6KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 61e4e37dc7a69f5331864210e3b3659d
SHA1 bb1a3b4f7e0975a278dd55d7fcb85ff69c957b0e
SHA256 b2647d1a8b2eaac85dab14e0e7f7fd754c14a3bc8ef4e4a30fd5506c5550bac4
CRC32 2D60D260
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3c6bbc45fc97ef90_wmpnetwk.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpnetwk.exe
Size 1.5MB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c5919bc92e8e31b9672432c6e9e2d48f
SHA1 94600bf4e67424b850d913be4680dbf1811c780f
SHA256 3c6bbc45fc97ef906fbe52869cf5257cfdb8435d571a4a2df7584ed0ce2919ed
CRC32 02747AC6
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a009628e0527b2db_inkwatson.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\InkWatson.exe
Size 388.0KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2fd8af317910c062703e2ea8c8533bbc
SHA1 8db61fc40fe0a2826ebf1d7f8006dbf61e5c7b42
SHA256 a009628e0527b2dbace9650ac959b881a493026b7faeb99806ea7b0f0c9f576c
CRC32 5B07658E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 18aa9e19337de5bd_wab.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wab.exe
Size 504.0KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 3e8cdd25d832bee54396103e9e406d3f
SHA1 e00776a178052f3b2a37cc2932626b85cbfb2380
SHA256 18aa9e19337de5bdaebbae64a78372745cd0d84e6d38b263e07c79b3ec77609c
CRC32 C2CA72C8
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name df3545821af47e9f_convertinkstore.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\ConvertInkStore.exe
Size 188.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 7e66ae88c65681bfd4cddc27a6c0258c
SHA1 2ccd6965631b457c879acb7da3e691b9086414fc
SHA256 df3545821af47e9f880783b48a2e3cbbe23564d536f541077122375ebd1fb9af
CRC32 227AB5BD
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 1f028699a7e52624_wmplayer.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmplayer.exe
Size 163.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ba642327a70ca9db64e07ac109b77823
SHA1 db393eb834d3813fc7d2029158432ca49722f8f9
SHA256 1f028699a7e52624e4b359c9e6de7e47597d5e1dbd32bc4b4b90bb1ac719fada
CRC32 FB1FD118
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ae30b95a630ee465_wmlaunch.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmlaunch.exe
Size 257.0KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 428c9e7319f7e65fb2a4ed5dd07aff49
SHA1 2e6a9d5c978de5c1c27bad9a7702ae019ee492da
SHA256 ae30b95a630ee4653690ba4d5db9096e6386eee6165f66ea2bfb96d47366eea1
CRC32 C3D7BC91
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a83f11034eeec679_ielowutil.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ielowutil.exe
Size 113.0KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0375ac32e356c8a73264d75761c0dadc
SHA1 cbfb0fc9e16e93f4dfdf25111022b6d5de8c2fad
SHA256 a83f11034eeec679a2e06a06a3039af0c4aff99823bf91630523c5250f84750c
CRC32 AE798486
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4f3e0a5aae181007_ieinstal.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ieinstal.exe
Size 263.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 998a45d00298a6097c8bc2ec2ae74bbb
SHA1 778f0401b7abddbdb9ff6fa43ffae926e5e92e2c
SHA256 4f3e0a5aae18100776228652f96f3180e74d30bb6c9adee1980ab298a44d6ac0
CRC32 D9D66F8E
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 82ec234439aa474c_wmpnscfg.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpnscfg.exe
Size 127.4KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 64c53ba730ddfdce12afcb79eb01059e
SHA1 961559d99537be296b13c848303898c7634a2c1e
SHA256 82ec234439aa474ceb2319417373ced2e1643c86adfa718a94676b548d1d8c4f
CRC32 44DE4B6B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 721493b0afa11aa9_msascui.exe
Filepath C:\Windows\SysWOW64\DC++ Share\MSASCui.exe
Size 938.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 2ec2b931ef2403c8e194dbb988227341
SHA1 6ad578270a70a50b36c3632ae1afe6f589d58366
SHA256 721493b0afa11aa962a8a8099794ff6c651b3310440b31d3d4f426fb8fa0bf44
CRC32 31C6C591
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 4c84a7758871b3e0_mpcmdrun.exe
Filepath C:\Windows\SysWOW64\DC++ Share\MpCmdRun.exe
Size 186.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0702dfbe48cb119fdfde1876146d29e4
SHA1 d8a53239a96456fffd67b6d535a4ef5554ed9275
SHA256 4c84a7758871b3e01322e3b0062886846ce81b7a27e2b79f27ff002f5e59b0f5
CRC32 56761C7D
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 32595b307aa39dc6_mip.exe
Filepath C:\Windows\SysWOW64\DC++ Share\mip.exe
Size 1.5MB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 08a6552daf4fac0ad88d49fe5ea3d340
SHA1 5b7e6c49070742cc2b7177055e73dcb8aa0e7e2f
SHA256 32595b307aa39dc62a7229cd9ff2fda7968118ade58ae81f5ca867ab5e3dee22
CRC32 E9B12F5A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a1e88659a4ad4f4f_marijuana.txt
Filepath C:\marijuana.txt
Size 21.2KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 c0214c7723fe7bde6bc2834742bcc506
SHA1 f3d8e78975bf169fc1ed3ae95ad41d84ff6a36c3
SHA256 a1e88659a4ad4f4fd55f246ab076dee048881fcac3ea8a300e2fe8cdffd88b73
CRC32 0D0BD2E9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 1a0274652099160c_dvdmaker.exe
Filepath C:\Windows\SysWOW64\DC++ Share\DVDMaker.exe
Size 2.2MB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e6e51dc0485e39822598eef16b3a44fd
SHA1 b6bcd3865e4d2fd700ea7fd192ecd0d349687d10
SHA256 1a0274652099160c08210f935358fecda6ecdad4aaaafa05d84c52133188ccba
CRC32 3A0547A7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 01915443766c7fac_wmpenc.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpenc.exe
Size 134.5KB
Processes 1860 (38b18879a6a84581e92b8bdb4c7efbfcdf44ccf9f39d7c65e23365bbe7d69f11.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 d39a1876e6cba1c1109dbee7198698a4
SHA1 c90af23ef096ab80cdde7e1f2349f425316673dd
SHA256 01915443766c7fac5158dd43e318ffc47fd6fb7597c43d7741f841f5498ee45e
CRC32 47EF9611
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.