4.1
中危

06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811

06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe

分析耗时

133s

最近分析

380天前

文件大小

220.6KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN ABINDI
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.51
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Trojan-gen 20200228 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_90% (D) 20190702 1.0
Kingsoft None 20200228 2013.8.14.323
McAfee GenericRXDF-VF!1BE88C5D1DDD 20200228 6.0.6.653
Tencent Malware.Win32.Gencirc.10b0c4bc 20200228 1.0.0.1
静态指标
查询计算机名称 (1 个事件)
Time & API Arguments Status Return Repeated
1727544990.972271
GetComputerNameW
computer_name: TU-PC
success 1 0
检查进程是否被调试器调试 (2 个事件)
Time & API Arguments Status Return Repeated
1727544878.533896
IsDebuggerPresent
failed 0 0
1727544927.081271
IsDebuggerPresent
failed 0 0
观察到命令行控制台输出 (6 个事件)
Time & API Arguments Status Return Repeated
1727544932.783769
WriteConsoleW
console_handle: 0x0000000000000007
buffer: Microsoft Windows [版本 6.1.7601]
success 1 0
1727544932.783769
WriteConsoleW
console_handle: 0x0000000000000007
buffer: 版权所有 (c) 2009 Microsoft Corporation。保留所有权利。
success 1 0
1727544932.783769
WriteConsoleW
console_handle: 0x0000000000000007
buffer: C:\Users\Administrator\AppData\Local\Temp>
success 1 0
1727544938.800146
WriteConsoleW
console_handle: 0x000000000000000b
buffer: 找不到 C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe.config
success 1 0
1727544934.487644
WriteConsoleW
console_handle: 0x0000000000000007
buffer: 等待 5
success 1 0
1727544934.487644
WriteConsoleW
console_handle: 0x0000000000000007
buffer: 秒,按一个键继续 ...
success 1 0
检查系统中的内存量,这可以用于检测可用内存较少的虚拟机 (3 个事件)
Time & API Arguments Status Return Repeated
1727544878.893896
GlobalMemoryStatusEx
success 1 0
1727544923.205896
GlobalMemoryStatusEx
success 1 0
1727544927.613271
GlobalMemoryStatusEx
success 1 0
行为判定
动态指标
提取了一个或多个潜在有趣的缓冲区,这些缓冲区通常包含注入的代码、配置数据等。
分配可读-可写-可执行内存(通常用于自解压) (50 out of 189 个事件)
Time & API Arguments Status Return Repeated
1727544878.362896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef31e1000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.471896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345e000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.471896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345e000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.549896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.549896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.549896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.549896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.549896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.549896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345f000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3460000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3460000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3460000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3460000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.565896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3460000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.580896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3461000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.580896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3461000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.580896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3461000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.580896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef3461000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544878.580896
NtProtectVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fef345e000
length: 4096
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.002896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00032000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.096896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fffff10000
region_size: 589824
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.096896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fffff10000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.096896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fffff10000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.112896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fffff00000
region_size: 65536
allocation_type: 1056768 (MEM_RESERVE|MEM_TOP_DOWN)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.112896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007fffff00000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.112896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff000ea000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.112896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00022000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.205896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00033000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.221896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff000fa000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.221896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00122000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.221896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff000fd000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.315896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff0003c000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544879.987896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00034000
region_size: 8192
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.002896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00036000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.002896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00037000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.002896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00170000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.065896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff0003a000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.065896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff0004f000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.065896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00084000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.065896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00053000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.065896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff0003b000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.065896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff001b0000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.080896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff001b1000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.252896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff000eb000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.346896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff001b2000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.471896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00038000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.627896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff00171000
region_size: 73728
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
1727544880.924896
NtAllocateVirtualMemory
process_handle: 0xffffffffffffffff
base_address: 0x000007ff000e2000
region_size: 4096
allocation_type: 4096 (MEM_COMMIT)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1332
success 0 0
在文件系统上创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Local\_foldernamelocalappdata_\deskperf32.exe
创建可疑进程 (4 个事件)
cmdline "C:\Windows\System32\cmd.exe"
cmdline "C:\Windows\System32\cmd.exe" /c timeout /t 5 && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe" && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe.config"
cmdline cmd.exe
cmdline cmd.exe /c timeout /t 5 && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe" && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe.config"
投放一个二进制文件并执行它 (1 个事件)
file C:\Users\Administrator\AppData\Local\_foldernamelocalappdata_\deskperf32.exe
将可执行文件投放到用户的 AppData 文件夹 (2 个事件)
file C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe
file C:\Users\Administrator\AppData\Local\_foldernamelocalappdata_\deskperf32.exe
一个进程创建了一个隐藏窗口 (2 个事件)
Time & API Arguments Status Return Repeated
1727544932.502896
ShellExecuteExW
filepath: cmd.exe
filepath_r: cmd.exe
parameters:
show_type: 0
success 1 0
1727544933.971896
ShellExecuteExW
filepath: cmd.exe
filepath_r: cmd.exe
parameters: /c timeout /t 5 && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe" && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe.config"
show_type: 0
success 1 0
检查适配器地址以检测虚拟网络接口 (7 个事件)
Time & API Arguments Status Return Repeated
1727544991.925271
GetAdaptersAddresses
family: 0
flags: 15
failed 111 0
1727544992.097271
GetAdaptersAddresses
family: 0
flags: 15
success 0 0
1727544992.331271
GetAdaptersAddresses
family: 0
flags: 640
failed 111 0
1727544992.363271
GetAdaptersAddresses
family: 0
flags: 640
success 0 0
1727544992.706271
GetAdaptersAddresses
family: 0
flags: 0
failed 111 0
1727544992.909271
GetAdaptersAddresses
family: 0
flags: 0
success 0 0
1727544996.456271
GetAdaptersAddresses
family: 0
flags: 1158
success 0 0
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': '.text', 'virtual_address': '0x00002000', 'virtual_size': '0x000359c0', 'size_of_data': '0x00035a00', 'entropy': 7.306486841774546} entropy 7.306486841774546 description 发现高熵的节
entropy 0.988479262672811 description 此PE文件的整体熵值较高
检查系统上可疑权限的本地唯一标识符 (1 个事件)
Time & API Arguments Status Return Repeated
1727544945.784271
LookupPrivilegeValueW
system_name:
privilege_name: SeDebugPrivilege
success 1 0
使用 Windows 工具进行基本 Windows 功能 (2 个事件)
cmdline "C:\Windows\System32\cmd.exe" /c timeout /t 5 && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe" && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe.config"
cmdline cmd.exe /c timeout /t 5 && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe" && del "C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe.config"
网络通信
一个或多个缓冲区包含嵌入的PE文件 (1 个事件)
buffer Buffer with sha1: 47e0d8ff23b166cdbf2d460b8ed146d4665e2150
与未执行 DNS 查询的主机进行通信 (2 个事件)
host 114.114.114.114
host 8.8.8.8
在 Windows 启动时自我安装以实现自动运行 (2 个事件)
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\*deskperf32 reg_value C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe
reg_key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\deskperf32 reg_value C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe
文件已被 VirusTotal 上 60 个反病毒引擎识别为恶意 (50 out of 60 个事件)
ALYac Trojan.GenericKD.32167413
APEX Malicious
AVG Win32:Trojan-gen
Acronis suspicious
Ad-Aware Trojan.GenericKD.32167413
AhnLab-V3 Trojan/Win32.Disfa.R216625
Antiy-AVL Trojan/MSIL.Disfa
Arcabit Trojan.Generic.D1EAD5F5
Avast Win32:Trojan-gen
Avira TR/AD.Bladabindi.igtsf
BitDefender Trojan.GenericKD.32167413
BitDefenderTheta Gen:NN.ZemsilF.34090.nm1@amNVt4k
CAT-QuickHeal Trojan.MSIL
ClamAV Win.Packed.Bladabindi-6888152-0
Comodo TrojWare.MSIL.Bladabindi.DF@89w59w
CrowdStrike win/malicious_confidence_90% (D)
Cybereason malicious.d1ddd7
Cylance Unsafe
Cyren W32/S-b04a840e!Eldorado
DrWeb Trojan.DownLoader25.55900
ESET-NOD32 MSIL/Bladabindi.DF
Emsisoft Trojan.GenericKD.32167413 (B)
F-Prot W32/S-b04a840e!Eldorado
F-Secure Trojan.TR/AD.Bladabindi.igtsf
FireEye Generic.mg.1be88c5d1ddd7785
Fortinet MSIL/Bladabindi.DF!tr
GData Trojan.GenericKD.32167413
Ikarus Trojan.MSIL.Bladabindi
Invincea heuristic
Jiangmin Trojan.MSIL.hmgz
K7AntiVirus Trojan ( 700000121 )
K7GW Trojan ( 700000121 )
Kaspersky HEUR:Trojan.MSIL.Agentb.gen
MAX malware (ai score=87)
Malwarebytes Backdoor.Bladabindi.MSIL
MaxSecure Trojan.Malware.300983.susgen
McAfee GenericRXDF-VF!1BE88C5D1DDD
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
MicroWorld-eScan Trojan.GenericKD.32167413
Microsoft Backdoor:MSIL/Bladabindi
NANO-Antivirus Trojan.Win32.Bladabindi.fsxglr
Panda Trj/GdSda.A
Qihoo-360 HEUR/QVM03.0.8B49.Malware.Gen
Rising Backdoor.Bladabindi!8.B1F (TFE:dGZlOgx4RgdKg7AHWA)
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Troj/MSIL-MJU
Symantec ML.Attribute.HighConfidence
Tencent Malware.Win32.Gencirc.10b0c4bc
Trapmine malicious.moderate.ml.score
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2017-10-26 06:06:11

PE Imphash

f34d5f2d4577ed6d9ceec516c1f5a744

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00002000 0x000359c0 0x00035a00 7.306486841774546
.rsrc 0x00038000 0x000006bc 0x00000800 3.676361676304135
.reloc 0x0003a000 0x0000000c 0x00000200 0.10191042566270775

Resources

Name Offset Size Language Sub-language File type
RT_VERSION 0x00038090 0x0000042c LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_MANIFEST 0x000384cc 0x000001ea LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library mscoree.dll:
0x402000 _CorExeMain

L!This program cannot be run in DOS mode.
`.rsrc
@.reloc
  s2
((s2
00s2
88s2
@@s2
HHs2
PPs2
XXs2
``s2
hhs2
pps2
xxs2
v2.0.50727
#Strings
label100
label110
label10
label20
label30
label40
label50
label60
label70
label80
get_BWC9H5990
label90
get_DGGHD04AV2ENU2K6VB0
get_DG2PUP242BOXAHE0
get_C4CDT0
get__33CBLCZZFXA3001
label101
label111
label11
label21
label31
label41
label51
label61
get_AC7DIV71
label71
label81
label91
get__57X5A1
get_BC9ZACQLQA1
get_AQFEMYXCELOVC1
get__25PSAVH4F1
get_A487F1
get_EB8C31GIWPOMH1
get__0947ZS0R1
get_C0SNHS02MZ9OR1
get_EA9S1
printDialog1
label1
hScrollBar1
helpProvider1
directorySearcher1
Class1
listView1
maskedTextBox1
label102
get__9WI5PKPVZP02
label112
label12
get_BD9D5ZU3RCA4L0MJ22
label22
label32
label42
label52
label62
label72
label82
get_B34292
get_C47AFH6BXELGCLT492
label92
get__45P1QXU9LE2GZE2
get_B287S4R3VJF986G2
get_C4WVM847G2
get__20LSH1A1ZZLI2
get_CKSTD7VZJCL2
get__766E86UTLI79M2
get_AOV7IQKO2
get_DNTG0QHP2
get_B3YR2
get_BX1H1Q0MM7U2
label2
label103
get_DMIGOL104OK03
label113
label13
get__13LBL4RCBUIYIC5E623
label23
label33
label43
label53
label63
label73
get_AOORSRDYO3OQPNHD83
label83
label93
get_DDUKPJBQJR3
get_DVKU5S3
label3
label104
label114
label14
label24
label34
label44
get_DIQQAP6LKSH0S954
label54
label64
label74
label84
label94
get__9U4XHMM4
get_CHC8C3VW4
label4
label105
label115
get__081Y6DZ515
label15
get_C2YBVAAUIWYI25
label25
label35
label45
get__74QK2OMZOPP755
label55
label65
label75
label85
label95
get_D0NF5
get_B47TG3YA0OL5
fEYniQWO7cQhL9u3eQ5
get_B80R5
get_AX93S5
get__919RAS2CF0Z5
label5
label106
get_CN4O492MOBO855U06
get__76XBL3BRDQK16
label16
label26
label36
label46
get__254HI56
label56
label66
label76
label86
label96
get__76LR475HBNGJ7H6
get_C22EI6
get_E25G03M6
label6
label107
label17
get_A34R2EXZLGM44GXQ427
label27
label37
label47
label57
get__20A67
label67
label77
get_CHP87
label87
label97
get_CUAB6O7
get__13IKL7HZXKKNNKUDR7
get_BYRCR55ECZVR7
label7
label108
label18
label28
label38
label48
label58
label68
label78
label88
get_BXMI6HE3IB198
label98
get__9PSTF8
get__69JJ8
get_DT808IDOO3N4L8
get_BN3QF9WC2BMP8
get__28P318AFAW7CPX6KKS8
get_BRC1ATSB81VRSI0U8
label8
label109
get_BR10TPR409
get__28UQNUW77WT419
label19
label29
label39
label49
label59
label69
label79
label89
label99
get_CXZT0COFB9A9
get_CW8Z7NIGCLIYM3D9
get_DFYK2HKOVAKEI2F9
get__312I9
get__11RR4DUJNP78NK9
get_C7GBT8HYBL9
get_BYBQ4NM4LJP9
get__15PXS8Z50G8R9HAYP9
get__26L0DLU2VY9
label9
<Module>
get__9TBUSM58A
get__33WELC8A
get__6318V8CDAA
get_A5AH7LA
get__22HPDXNA
get_BZKUZ9CD72RA
get_D0YXUKF66WKB3AST2B
get_AJSNPRDYF6B
get__787FJ1EB
get__16THB
get_DMY3GVHB
get_CLJ7ITJSSXXOPB
get_BWHFX6RB
get_BPWL2KD9YH7UB
get__15FYDK2HYF0J52ZB
get_DDZX165H2R9C
get__34YFVMCC
get_BARCZ9374JC
get__56QP7X5LC
get_BP21I5VX4MOMWLC
get_CVHZ3OC
get_EGQRLY2ZP8VEQC
get_BDOQYS75R9D9A1D
get_B3PA3D
get_E83UX4D
get__0808LJZF96975D
get_C4VU7G0O7KN40TEMS5D
get__55DHCDD
get__9PJ6HGGSZ3XDD
get_AP9EE8ANQEI1TU49KD
get_BFHE5QD
get__781OG4U56D9KWWR5RD
get__9ZHTL5T8KLSD
get_CT65RU1HRUD
get__63C9061U3NM1AC4E
get_CA31NWT7E
get_ATZRCKMMTN1OE
get_E047SIJVXBW3W7UE
get__23DDDUBXE
get__92TGCTFP8N308F
get__786RI0GM38F
get_AJRX5FGCEETL9F
get_CMI362BL1LN0SLV45EF
get_BW9BJCIFR7EAYK9YOF
get__37PT0PV3XB8PF
get__362N0B10BOQF
get__53TKGX8SF
get_CBBHSRAJCPBKW8TF
get__811XFYOSJV189AYJAXF
get__26CP6QNANV1K1P2G
get__84NB61KZDTZ5G
get__56IDAG
get_BOV2JP8F3E0EG
get_C8ELG
get__74MCDID8P3AOCNUROG
get__3762TYU89ILRDXSG
get__58K7TG
get_D6G2NY1LCHE38KEUG
get_AAZG3H
get_CXCHCHR3H
get_AHY4H
get_BRQH3FJNRIV7H
get_DVTRZOH
get_AC7FKAIUH
get_A3UXHQX39YBRCNA1I
get_DVY1HLUOXXT2I7GT12I
get_DS0UEB6F5I
get_C8XFH3FI7QT5FI
get_A1JEYFQV0OGI
get__59IT0A5VHI
get_ASCII
SCLGbdnsouXvvitLCKI
get_B8UEUVGLLI
get_EGZ8E7MMQB2DNI
get_C1VALPVSDNYSF0OI
get_A2293PI
get_DFRN59IUUFJ6UI
get_BLU9BAL1E3UYI
get_B6CV1O0CRYYI
get__9808J
get__67FB22ILAJAT9J
get_BJ9B9HIWD118KQAGBJ
get__516WXIXCJ
get_AC7EGT4V2WP9FFJ
get_CPZSLL70THJ
get_CI98VYLJJ
get__833OQDKY5U9SBWQJ
get_A23W2ITDZ8X25MRETJ
get__9S70RFNA3PZZSQEZVJ
get__54PINBZY1K
get_BCSA255NRH0DO7K
get__50BYBK
get__70AA8ZBK
get__76LW73R77YQZX15YKK
get__9Y7ZKZT7LQK
get_AMWYPWK
get_DJZTKD0GTXYX082L
get_BVMX33D8NRT2L
get_A927L
get_E13ILQU0NHP7L
get__57M5CP11BH2O8L
get__61TJV4RXSL577CL
get_B2S5ZZN6RQJZHLBACL
get__949CIS2J34OC3TU3IIL
get__36PH9G0BW3XBML
get__74X2CGLQ2U574L5FEQL
get_AQBPK3GSL
get_DKCH2G3DH4WETL
get_EB5EQDE4QXWL
get_ACQ18MLV5EKIYL
get__9NFTILBBLY1K94LZL
get_BMDEVXR7AHO13K20M
get_A9B68HL24WXA6CM
get_E1D2V2LP6OCTYOFM
get__4532CYPX6O43160Y5GM
get__9RQLEH2L9JM
get_DRDQ6MQI2KLWALM
get_CBGQ5NOV8BMPM
get_MXLWM
get_CNDOFBKVASZB4N
get__099KG915SIKN
get_BSHVN
get__50LLVN
get_ANWZN
get_DY3AY87QX2O
get__9775J47V83O
get__42IH719QHWFCKV3O
get__76CPKUB6K1AT7O
get_DK6BZ7O
get__66SG5NO
get_DA8REMA5QFR1IQNO
get__68E0U6T6AYM9OO
get_B5VF3JR6DQ0K4J2P
get__68P595P
get__9NNGKQ5NMDEF5P
get__9O61NLP79KLWW776P
get_DS3PFEW2X8P
get_E2473IZYXUL7AQ6LA9P
get_BSLQN5B5AP
get_E9UH6DOCGP
get__9Y77JJIRP
get_CJHM7ETP
get_DKQEP9BGTP
get_B0AOYPMUP
get_BDFLZX38L5JWWDKQUP
get_EAGL6GU8E39Q
get__78XG6WGASXAKCVWFAQ
get__70K2Y53NQFEQ
get_C7X7NTQGWQZRIGQ
get_E5OEBUMQ
get_BSE1FYQ
get_D92JZ9FGN1UX7Z602R
BVtVRCDEhp75JfaVD2R
get__13OUSC7R
get_B765478F4LP4ZU28R
get_CR3AR
get_AXJT90VJEJ9ZDIAR
get_CF8ST2K8B4Y2NODKTDR
get__207FR
get__66KSPVQIR
get__9VYUEMWSGALCY5EKR
get_BFMD6GJKD6H137XDNR
get__10YMWR
get_BY88EYPZIZ7KSPVXR
get__72GK5P9AEBLIIH4S
get_BPTH9Y7G8S
get_E2RUWXXINQKAYCS
get_D5LRPNS
get_DAG0COA8STWQSS
get_AH9IN4NUNR1LB60US
get__2910LLZS
get__25BAUDCXZS
get_AXP9D6P4YWW87E8S1T
get_BIT76T
get_AEL2K730J5FY8T
get_A7M0O95RDY7DPMJ9T
get__15ACC34PET
get_B0I79C94WOBFT
get_COUSCGDWZOMT
get_BEOWYHYOUR703TMT
get_CLWR1YGUTGKO4OT
get_DZLG4V7Z1UW4KFZ4U
get_A7MB0LIZR6EU
get_C7UIKU
get__14W7DMAMT5LU
get__924ATU
get__160BD4HZFLX2C6VU
get__79Z9PLJWB08DY35DVU
get__668FLHY8FI75V
get__862ON2TRKKKOHAZY6V
get__39ACE1AD99NNE8BV
get_ADYE26VBTAOLS7YUCV
get_CX5F0B3Q69X9Y37DV
get_AIZUW15DJHV
get__67QWOUIC52PFVF0YMV
get__89KBAS87J5ZUH84N2W
get__17333W
get_BK81CNRW3W
get_DUVS4W
get_BDNR88W
get_CT9N9QOMU1CITGAW
get__9WT7ARPHJS9OGW
get_D0VV584V4X81JW
get_C8WP3ZW
get__471TZ4X
get_DPQA3HF4JX
get_AL3QZKX
get_BR2WN2M6WWX
get_BA40JAJEYX
get_ADKLQI09WL13Y
get_AEV7Y
get_BD1EU4RBAY
get__84GO4DY
get__9QEGE6YN629YCMTFY
get__77EK57SNTQWHY
get_DAVWP2GYGGT8CCJY
get__10G1UA6045MY
get_EACXFQOY
get__18F9T5D7SW6PY
get_CEN2QQ4R8VDXRY
get_AF729MQR349UG1JWY
get__44YSU5ZIEBDC2YSMCYY
get_CT7HOKSZG6VIAZ
get_EEAY6Z7EZ
get__81DKPLWBW7K5CRFZ
get__92C4MHZ
get_CF8JZ
get__58E6KZ
get__10XKZ
get_B6YLZ
get_EE2CKUFNZ
get_A9XZ5I4RZ
get_BN54L9VZ
get__11VVZ
get_DMWFXVWIWZ
mscorlib
TypeScript Keyboard Sync
TypeScript_Keyboard_Sync
KeyboardSync
Thread
Form1_Load
add_Load
listView1_SelectedIndexChanged
add_SelectedIndexChanged
Synchronized
defaultInstance
set_Mode
set_AutoScaleMode
CipherMode
Invoke
IDisposable
RuntimeTypeHandle
GetTypeFromHandle
set_FormBorderStyle
set_Name
get_Culture
set_Culture
resourceCulture
MethodBase
ApplicationSettingsBase
Dispose
EditorBrowsableState
STAThreadAttribute
CompilerGeneratedAttribute
GeneratedCodeAttribute
DebuggerNonUserCodeAttribute
DebuggableAttribute
EditorBrowsableAttribute
ComVisibleAttribute
AssemblyTitleAttribute
AssemblyTrademarkAttribute
AssemblyFileVersionAttribute
AssemblyConfigurationAttribute
AssemblyDescriptionAttribute
CompilationRelaxationsAttribute
AssemblyProductAttribute
AssemblyCopyrightAttribute
AssemblyCompanyAttribute
RuntimeCompatibilityAttribute
TypeScript Keyboard Sync.exe
set_Size
set_AutoSize
set_ClientSize
System.Threading
Encoding
disposing
System.Drawing
set_UseEXDialog
PrintDialog
ComputeHash
TransformFinalBlock
System.ComponentModel
ContainerControl
Program
System
SymmetricAlgorithm
HashAlgorithm
ICryptoTransform
resourceMan
TimeSpan
set_ShowIcon
Application
set_Location
System.Configuration
System.Globalization
System.Reflection
ControlCollection
MethodInfo
CultureInfo
HScrollBar
set_ShowInTaskbar
MD5CryptoServiceProvider
TripleDESCryptoServiceProvider
HelpProvider
sender
get_ResourceManager
DirectorySearcher
EventHandler
System.CodeDom.Compiler
IContainer
set_UseCompatibleStateImageBehavior
.cctor
CreateDecryptor
System.Diagnostics
System.Runtime.InteropServices
System.Runtime.CompilerServices
System.DirectoryServices
System.Resources
TypeScript_Keyboard_Sync.Form1.resources
TypeScript_Keyboard_Sync.Properties.Resources.resources
DebuggingModes
TypeScript_Keyboard_Sync.Properties
EnableVisualStyles
GetBytes
Settings
EventArgs
get_Controls
System.Windows.Forms
set_AutoScaleDimensions
components
GetObject
set_ServerPageTimeLimit
set_ServerTimeLimit
get_Default
SetCompatibleTextRenderingDefault
DialogResult
InitializeComponent
get_EntryPoint
ThreadStart
set_ClientTimeout
SuspendLayout
ResumeLayout
PerformLayout
System.Text
set_Text
ListView
set_TabIndex
MessageBox
MaskedTextBox
set_Key
System.Security.Cryptography
get_Assembly
set_Opacity
WrapNonExceptionThrows
TypeScript Keyboard Sync
*Copyright
TypeScript Keyboard Sync 2017
1.0.8.0
3System.Resources.Tools.StronglyTypedResourceBuilder
4.0.0.0
KMicrosoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator
11.0.0.0
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP
lSystem.Resources.ResourceReader, mscorlib, Version=2.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet
PADPADP"
.N*G*;R7s#I
w}[$wrO*g]:
OUsu4I
hLGFtwdH
~RmSx@
XgFj=Q6H
G`f^JS1-
=` h KP!
$Jo($x
vL)<H)Xv*.+7$+A,Z,,J,,
2^/F"0y
1f#1}3
4C4p(5
D5o5^w7$Nx7}6
8((9\<"
=-B=.*>
6>Rh>J
@%@jA3Ak
BB5GGHz
"Ip=zJJKBL
N{PxQt
RTg[V^/W
,WZ[kGaSma0}bn
wccXW6eJq]e)_eEjfY`gvg
g0gtFh
yh.+ix
roUKr[
shsA`tv?y
y%z`w={&j{
{{3h}z
@8|$Lu
@8|$Nt
Ht$ WATAVH@
E3IHI;u
K&KPK&P&
;;';'''''ggg''';''iiiKi+
HH+HH~
))4)4)44))3)4
4)4))<$
GetDlgItem
LoadIconW
SetFocus
GetClientRect
PostMessag h
888JJ|JJJJDJDJJJJJJ555oyo5o5ooooJo5JoJ
&&&B&&B&&&B&&TBTBT&&&TTBTTTBTTTTTTTTqTTT&T&T
g'';'';
&&&&T&&&
&&&&T&&&&&&
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyyy9y9yyy9yyyyoyo95995959
ooooJDoJDJN
b@!ccjccccjjcjcjjcjjjccSjccjcjjjjjjjjSjjjjccjcjj^jcjjjc^jj
TqTTqTTqTq
&&&&&T&&&&&&&&T&&&&&&TT&T&&TTTT
qTqTTTTTTATTAT
$$eb@S
jS,SSjSSjS
SSSjS,S
j,,S,j
jjj,jjjjS,Sjjjjjj,jjjjjjj
\\\\\\
\22222
eb@zzf::z::
:::::::I
DDJDDD
`JD`JJJJJJDJJDJJJJJJJDoJDDDJooooD#oJDJoJooDDoDDoJooDo
LLLyx$$
b@shh*]hhh**h
h********c*c^^c^^***^
j^ccjcc^jjcc
l&l&0T0T
g''''';''iiK+
K+KKPKPKP&&P&&&&&
?$$eb@
UpEp=csmu
E8H ]@UH HH0
U`E`=csmu
yuyyuyyyyyG
;t?|=;
H`[H\$
hh]h**h**
**************
*=*=^**
%:Y%6Y%2Y%.Y%Z[HHX
Hx ATH MQ8HMA
\H\$0Hl$8Ht$@
mE3L3HH [|HXH
H3HD$H
LL$4LD$0fD$@HD$<HT$8HL$@HD$
#D$0HL$HH3
`tt`tJ`JJJJJDJJJJDJ
JJDoJoJoJoJooDDDJoDJD
oDDJoDDDDD
DDJDDD
\\\U\\\\
88|8||||JJ|JJJJ
J9y9yy5y5yyyyyyy9y5oyoyoy
b@SjSjSSjSSjSj
SjSSjS,S
^x$$b@:
SjSSjSjSjS,S
SSjS,jS,
jSjSjjjjjjSSjS (
`>>>> v
$0HD$xHt$(HD$
A_A^A]A\_^]L$
LD$hHL$p;H
y9yyoy5yoy55ooyooooDDDJ
eb@| q
c^^^^^^*^^^^^c**c^***
**=^^===*
^^^^^ccc^^=^=
ccccccccjcccccjcccjj^c
kkkkkk-
>->>>>
eb@shhhhh*
*cc**^c*^^
=j]YR>Xv
=j]N?]}
<\Kjs=w=rM[E~>a\
0&&&&&T&&&kT
&&&&&q n
H [H\$
^^*^=^
;;;33nn
yGyGyy
yyyGyyGy
yyyyyyyyyyyy99yyyy5999yoo95ooJNx$
yyyuyuyyyyyyyGyyGyyyyy
jjjSS,,j,S,
jjjjj,jS,,
3fl$ f$0
DB3H$@
>AA>>AA>Fx$
}HHHlll&
\\\\\\\\
zzzzzz::
yyyx$$eb@
GuuGGuuGGG
GGGGh]hhh]
%....I..
&&&&&&&
TTTqTT&&&TTTTTTT
&&B&&&B&&&&&&&&&K&
&&&&&B&&T&&T
x$$eb@r
;';';'
'ggg;''''i'
KKKK D
<K_mjYH=j=e
l&l&&00T&kT
@!^*c*c*cccc^cccccccccccjcccc
&K&K&K&K&K&K&
K&&K&K&K&K
&&&P&&&&&&&&&TT
gg''''i
00WWWWWWWW8
JDtJtJJJDDJJJJD
h*]]]]hh*****
yyyyyyyy9yyy
GuGuy A
I.m.m.m.m
33)3)3))3)3)
BqqqBBBBBBBBrrKr&r&rKrKrQK;;;;;
333)3)3
)))4)4
$$eb@
qBBqBBBBBBBrKBKrKrKKrKK
33;nnnnnYn
cjc^jccc^jjccc
cccj^^^ccj
cccjcc^ccccccc^ccc d
';';iKi
KKKKK+K
=r\H\^YV\__?q
c*c*c*
c^c^c^c^
cc^c^c^jjjc^
c^c^^^^^c^^^^^
c^^cc^*
>>A>AAAAAA
II..m.I.
\\\\\\\\\\\
eb@6zzzz:z::z:
ggggggggg';''iii
KPK&K+KPK
;uZHKPE3E3
HKXE3L
';'';'iiiK+
&&&&& %
))))3))
BBBrrB
rKKKrKQ
;;;;;;
33nnY X
33YnnYnY3n
BBBBrBrr q
)4)$$eb@
rKKQQr
i;;;;;
444444
)))))4
TDLL.DLL
netutils.dll
ADVAPI32.dll
KERNEL32.dll
USER32.dll
SHELL32.dll
ole32.dll
GDI32.dll
SHLW %
``````
)?))4)3)3)
OO6O66O66
::::\bb@(
rHD$`I;t
HL$23Lf\$0<)
H\$0Ht$8H _H(HE333H(@SH IHHu
E3L3HQ3H [H\$
b@shhh**h*
***h***^c*
*^cc*c*^
^^^^^^c**^^^^
b@!cccjcjcccjcjccjc
ccScjcjcjcc
ccjcjcccjccjj
jccjcjccjjcjjcc^j
^^^^^ I
jj,jjjj
$$eb@1
^**^**
**^c^^c^^^c^^cc^^c^^^^
x$$eb@shhh*h
-xDT;[
J5o55oy595955o5ooJoooDDDooooJoDoo
b@Wp8W8
8888888JJJ|JJ|J|J|JJJJ ~
';g''gg
''';';'ii
K&&K&K&KPKK
KK&++K&PK+&
PK&PTPKPx$
c^^^^^^^^c
^=*===EE
b@sh**
*^**^cccc*
^^^^cjcc R
=5t<=7t-=8
;tHL$ H$
HT$<D$0
HD$<H;t
HH\$0Ht$8H _ff
%|k%xk%kHMZ
3HcH<H
ooDDDooDJD
eb@W8W8888888
888tJt|J|JJJJJJJ|JJJJJJJJJJo555yyoo9oo5o555ooJoJo ,
kk--k--
XHL$ Dd$PHD$h
)3)))))))))4)3)4)4<$$eb@qq
;;;;; i
_mjYH=j=e
<\<=~=z=w=r\=n
:::%..I
r&&T&&&&TTTTTT&B&&&& j
&&&&&&TTTTT&&&
T&&&&&&&&qT&q&&&TTTqTqT
itecture="amd64"
publicKeyToken="6595b64144ccf1df"
language="*"

........
,,Sjj
y9yyy59yyyy5yyyyyyy5yoy59yo9595o555oooooJoJoDoJoDDN$eb@
H\$PH@_
3HL$0DBH
qBqqBBBBBKB
rKrKK;;;;;nn[nYnYYn
3))3))4)
))4))))
eb@shh*hh*****hh
***^*^*c*^c*c*c*ccc^**^^^^^*^****
b@shhh
HD$PHE8H\$HHD$@
D$8D$0D$(E33
E3E3HH
\$(\$
E;|HEI;t2A
jj,jjj,
XdH [@SH Hd$8
:dHT$8HHt
b@Ccccccccccjcjcccjcjccjjcjjjjjccj^^^jc
jccjjccjcjjj^^cjjc^^c^cc^^cccc^^c^c^^^^^^
HD$8HT$ D$0H
D$XD$\D$dD$lD$`D$
J|D|J|JJ
95y5y95y95yy5yyy99yoy55955yoooo5oyoyoyooooDDoJDDDDD
8888|8||
DBHtHtH
VH@H5T
00W0WWWWW
jj,,,j
SSSj,jj,j,j
b@..%.... 5
WH HHL$83H|$8L
|J|JJt
H|$(fD%s
H\$@D$H
7t0=8t
E3E3AQ
ggg';'';ii
&K&K& b
b@yuuuuGGGGGGG
]]]]]]
::z:z:
ImImIm.m
ImmmIm
\\\\\\\\\
\\\\\\\\\
)4))))
x$$eb@
ooDDDD
$eb@QpWpW8Wp8
88`8888
tJJ||JJJJJ|JJJJJJDJJJooJDJ5oJoo59 *
yyo5yoyo95o5ox$$eb@R
&&&&&&&&&&&&&&&&&&&&&q&&&&BT&
&&T&&&&B&&TTqTTTqTTT&BTqT&B
ICICIc
xuj3IIIfH
TerminatePr r
ccc^cccjcjcjcj^cjccjcj^c
j^cc )
)))?)?4)
))x$$b@
E3fD$jf|$h
D$hLL$xL$
oJoJoJoDDDDJNeb@
88|8|8|||||JJ|J
JJ|J#JJ
`t````
$$eb@HlHHHZHZl0l0
WWWWWWWWW
`D`D x
^cjjjjcccjcc
uyyuGyyGGyGy]y]]]]
BBqBqqBBBBBKrKBKBKrKrrK
;;;33;;n33nnnn
33)3)3
)))4))
\222222222
JJJJDDoJo
DDJJDDJJDJD
b@wHZZl
HN0L$0
HN0LD$0A
I[0Ik8Is@IA_A^A]A
DDoooooJoDoo
oooD }
`88t`t8
``t`J`J`JJJD`DJJ
DJJDJDJoJDDJD
vVgVVVV
$eb@#G
h]]h]
fD9h tK
B HR(`
K HfD,HI;tJH$
_H;t)H
AL9h@ x
'''ii+++
K+K+K&
KPK+K+K+
KKKK+KKiKK+K
P&?$b@
8`t`8
_`%nsm`%nsm`%nsmY\H>.s,"
&KlBKz]q
+ts|-FP
?z'$PaQ
fNRR`w[`%nsm{
<n`%nsm`%nsm\4=32`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm9
-`%nsm
!`%nsm9_y*A
;j0`%nsm
Ijr`%nsmZxY^C`%nsm`%nsmuHnR
'(GV&$
`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm~
>QBU',
3Es/=W
/@wtL![" ,
Mkzq7Y
^(&<6MT
<CT'by
*yi=R_Y>
U6yng6[G#3:*Ot{
Y!+/v?LsG
cjhn8h
63Zpr)
g>dN+
yQ| xDy
Z~Ez=W
4jnJo)"0yMO
<"v1,Q
(^:aZu
VhJqo;L
0kh#R*|T(,
}LLE p7'}/D
~olt0I
_p[Hf.)
j'./=>
;Tt; %'N2.`m8m
c+l[&;
/3^^#@
`pOF4L
D;@:U0?
.@,7q`h
qdG77{
..ob/mHyu^u
_+f%"X^zC?
L;%u+$\`
d cs6g+BD
h~ed'*u3-X
!!M@L4
,TXF#n\
f+$<l32
OjtE}N
S@43kM
AK.V3R
^u]Dhc
jQ=Ob>Wa4[[P]"3'OV
@_S'x+?b
N\S#fp
bYz)2#
;E*4}N
&fGDo9G5app{
_u6Cj-Lc
_u6]~P
(</w@3a,VSq3pUv]el
@}IGONVI
L_:?Lyl;9+PC
Ju"3'Oe0
>gg-(?
|"Dwg*<
_'+=x]
mH^6,meZ5X3-Me`PrE
6LP48p$
pb3|D7LGAR
CeGOsKfSJ
|"Dwg*<
r&E#r@)`'
C,z,:cz<
,9z D{q{hr7;":cpy
g>mZQM$L
3>\\q rX3mHmg\F
.@,`t?
BA=6'S
^KR7d:jxJ
v=!2z"z#
$g{`1+jdx>AnZ+TY2
-!6MV
0g{<FYDb5Q-I8A4^Y:,t
FP~Z(|]
YO_(' 5FR
kW`hQ*o4`1
uVBTJG<)
5GJr"C
VM*1Pz
M/Qcf|+k
_b$RUY
LP%Fb3
W`hQ*o4`1
{/V][$
82qDe2m:
,TX-pKn
@L3~Ol
u"LI7xA9U)
TXbX]R
M/Qcfs
:,tUV
+FD!W(]!%%?(<"E4C
cu[{'6{
LI(:ikA*/N
p'LXRa~
#c5Gkt;6Ph!snf@?B\
QO7Cg{C#W
)D$TbRE
4/A)`\dy~FP~Z(|]
hHS:G9Y
?%K*[q
_Q%$,C%&VJ
XA~5Q-IFH0iz`MO3
Ukt;6Ph!snf@?B
',5gOb:
>S]kQU@
\S#^3;cR>
8,DIf@?B
Pf |E/
t"7Wo5m]R
r^OT>p
YO_+`4z|
Fl3~G*[
!8O}Gy_W
$37!+"Qjx E`_dZyV
e4C|T
]4ex\A
+F4/_dZyV~`
Oo*Yx=GV
;JT.LI(:i
{`RT9|
#VY-qQ
a%/<7a
s!-$Zj
{*e-.s<RF
WCd,42=f
Wma7(pd
Ri@3Va
;LzKUn8>w2s&#Bp
3kG(4 {
sPKp2}F}~5!
0GEpK2J/
PnH;fh:KDc13!@T
xX69-R
E[,k0&
rQ.aD0=
E[,k0&
i%"-xX[R1CA8
#T>/n\x
sS#8>^
qk[f(UCYz"z#
t%9ZDwKK`@
^i}S4Tp
cWIgM$y
=INzr1VC:][
a[16,!I(M
Ttd,@Xd?
2o233,m1t
2!{r*3
:0tCG7'8vt
'0]wVv"X\<.`;0aIN
>y6^I`TRd
a_3~zq#tvJ
TKGT[<Dgf1
J\R|T_=
$XNZc[:
E%[*.Si*
5lY(=Ny
+[5Q-IJ#AK
<PTl%+
+[5Q-It>mb#./yvHA
ysuF(!D=Uk"*#
#./yvHeyiJAu_@G7*6w`3
h;Qf$/QzJ}p2|<
S1B!#aU
sHG|f$
L-MtK7
%.h!^_
A*q[|u`^70b
Nc.4LDOsvh
.SOyj.Le
czr1VC_
~;sPKp
3!r{W>#m
s#b]7?n_
j1klP</
k3b=nTh
Fn!-_g
~ #F=x]
ZM#@_G+CNo`hQ.J\(xh!#*m
MdaH}k^$"3'OWI+y
#K;]gBu:cED
^k^e(zr1VC2eIz4I(
ecnyzs$y
GoaJ`A;0
LBti+Ec
#Pt&G[F
~(?)NAf
j{LZcK.'0*uir]'7C\ )<
X.(LTsLE$
q5bJegndgtUYm
?+.x^)
0_~BO65y`\
5O@MV^
C2_#~<1
KZOe3Z
oS54P]
Vqc;?&B-yUYOc
,,T0]\h
1ExI.p
Qs3b qYI{j
F<hz[l
q1*etC
laYC8.v
i=U8Bs^=~.%#
2pA3Ffe#vuYT
o2L\mUR
vAlCXQ
//Wl!@~G
Q'Atas)
UJYTJ
,TX)9P
h a"mb`
W#xw]g
)i@Ka~S
,TX(Iyy
h a"mb`
<)i@Ka~S
1Si5'ELBN
Ww^9DJ&
RH\w"3/
GvZ04{4NV5G\=
/1{4f@?B4p@n*BqBY?Yy?40[
Ali<7[f
/1{4f@?B{
b#b)i@L*
$K%taa#`
Y<#~iVa.q^NSE
?@Ss2Oar7O
Shs_ sJkM!Op
)fKPa#u<W
CNz{y6_?
}7_Hid3-F}J}
-b>:fnJ
&`"RZe(xgz"z#
zGRe\E
,TXQ
:n4;W;
I;425v~d
4hC{vfeB@b-W"v
QS|`Z6O-
FSk++P
(mGu38{?
-q]'iOwOe-
}4LeR^
r)h^Vs=
5kbg+T
[j\<}nR7
3-H>%2^'~
xWMD\Y
(XWK:
STW2jx:O"~
o1EVN}wBd9z`PeeU$
".|MbH
R> 3(z
jZ&c09:h5]^=-
yWJR"\5
#A x^9
,TX@pp
J-_^pf=$F-
E~?Myy@
B-h$z8gGx
%z@a[)UG
,TX3h}_J)+
t; %\=F%u
4[mL4f!nbf
p>iA?|
#cuB&^
dBF$a)(c[
P{0Zg
:I_E`_R
`Bo(K^
Q'#^N^
quY(hn
p; gMK\
V|@huAmdQ
g>+ea]&I8+
Fn(,aOD8
g}lD-AM
)_Bkat
@f@?BU
>l|dW+'
bn~L.N'D`;v{k
Z85d}C;?W
W%-f@?B
VHd$WFt
U6y?N)G
Pl}ik(r:+4HU
wN[2^a
=ic2w'B"=?PA,,|Iz
\/_\.945
WeCV2B(iw
mQ4`D1##)
RNh-5{ p@d
/Rzz4,
cm4uuf'|U
:b0gOo_k%LBxL>
SvttOv
%hm@ttOv
X9GG6a(
O>e7mJF
dG77yIJ>e-PE
FHp(|}N&
dT]z"z#
N#4MW QqLc
VOlkc52:#
+W6\t{!
H<"UbD
I]6Xd
"V H/`
~/okORq8xO_~il
F$=.?'
&8@4i
dEMo+PUo
Y[f$<8
:W[Nf[*
!dX+NCXW
QzCrMe?MLh5]^=vk/og
LjePIgZ{
U!R24f[N
OK5kL*JOD8
i)B|I %W/{
>/nzHzS*AR&f
sIJBq.iB
P=}v.-
<F/D=!l
Fy2h`E
W<"{_q
Lnr+LO
jZnNNlk>
P<+S]Vh
WA:)#JiMmCu
~jq%A
v7"\Hd5
X]UIhnAYf:!J
Prl<T%
Q<6!hm-N$L((zM$
5m.L<W&7AS;7d
9,UjR4\
hm-N$N+{M>`M$
5m.L<W&
qAqWpD
=?hm-N$
5m.L<W&
^U4 ,kg7l
5m.L<W&@>P?
qAqpsj
//hm-N$A@1
5m.L<W&N:X7d
qAqn-.W
4hm-N$
D!,@.?
5m.L<W&;s@
&)O&YD
t^P`5}
9,U-3Q
5m.L<W&6Z
WM'whm-N$A@1
D!o\e!~N
5m.L<W&e4
&),<*GI{
n^w`5}
\hm-N$
5m.L<W&P
+jV<{6`5}
uUbhm-N$6
5m.L<W&h
{os9`5}
5m.L<W&
&)^'"I{
qAqfcFQXV
{hm-N$'
LK=Xy1rxi|&
5m.L<W&vf
)M`5`5}
.4hm-N$Nb
D!D0m'N
5m.L<W&*
&)Qwz"
~GPKkn`5}
9,U*7hm-N$1b
5m.L<W&W
9,U5Cyhm-N$&
Td&-C(h
5m.L<W&
9,U}dL)<-hm-N$
5m.L<W&
&)Ay]#I{
dk!{=h
D!OF5]N
5m.L<W&
qAq2eP;
5m.L<W&l
qAqsyG
oR$hm-N$M
g)C`<2
5m.L<W&jZZ"Iw7d
&)M6I{
);n`V`5}
hm-N$j%
`0g)C`<2
5m.L<W&
qAqoY~
BEpV~`5}
^hm-N$||tr
5m.L<W&c~p
&)cgTI{
9,Uwj>
s$hm-N$M
5m.L<W&G=7d
UEn,`5}
fhm-N$Y
5m.L<W&
qAq=cI 8#$k
BvBf'|U
bqc~,h&YW
&)?|>U88Ak*f5
%wWXyv,[6}V>
LXOc>w
x3Vfs[
RH\w1}oX^,I
K<eBue
)E/itO
kYon5E0CWcqQ%
>5CROf]p
Q}0FROf]pH*6
DSJ?zAO
FGt96Rc
A$rgin+hxNenlM%>
ko3_Pbx
C#yIb(o9
)cvP.5l
NXs$>/
J""'k\Z
,}Kx6x]
RH\wU/{
oX^,;b=
I=)BHF`
g{WLaJb22=6
z$2f"@
Fy2h`~Z
}tN~&lN
Q_kOH]
1-7DK~i3G)tx=}SZ
:^^cY;4GyZ
>x=}SZdZs^c
zc<RE7>:
{Sqr_Y
z$2f"@
Fy2h`~-H>
}r"!W[
&c:l}7i^P
W/Q7=t8
AALS}kdE"\g
f@?B}Z
#]{'t}
qaU3GZ&r
#"[H^$
INQo]~:
pH1'x%<=T
p'rofV#8@gV
tITw_u_
<"$})uf@=
\s'xG~}S6in
ennm,b1+
|J*p+F
XMR#po{fE2
,TXU*
t<\nm '
?)Xs5x
z:$c;XY*o
T$3on:}
9,U@*_z
9<</rU?
66"b{*#X
9&"3nf
O/"&p
rfWcb^d
;t{C#`
AC op
0$sY|Lap
%rs]"jlp
JRvTmf'|U
'2mPTR,ab
|n:.t""W
et4Y$[
esN>k&_bU3WI
o0~t**G
RX>n:.t""W
EFu'c6foK><:
tiOpU,
_c8.j8m
MmFNL]
MbedB=
&`lYXEl*
REl*b}V
Cx[.5BqJ
F1?7ld
.:#`E;@l
oa-<?%8{Nl\o
D%0=J~r
He$ J]}
/&}PZ^n&V`%nsm9Ey
^&(;(ko'Ag
^&(;(z)ge
O^&(;(
rDz^&(;(
j^&(;(P
^&(;(9
Fy2h`qj
KS'8b.JLWga
`z'u`(8Oj
Fc(lRj_`
UVWayC[W%J
A_jeNFg
esN>k&_b}>8
tRYf!\y
#Q @dM:?]
[&A`(90f}^")
_u*S}4Ix\
nDjX^NIGB
`xf'|U
'2mPT/*|
#O/)7sW
YAuC$u
7B|*=w
esN>k&_bU3WI
NE`k9hI
%dXT)7d
t0OOFv`?
~P_i?{
esN>k&_bU3WI
~=!F&GJq
C_10CA
#'k36JX7
|&,gcn
TC"n:.tZ
_p[Hf._A"J[U+g@>
`%nsm4
\_dpi$u
_10CA>
bSzB_:AuQN%]Q
TC"n:.tZ
_p[Hf._A"J[U+y^/
8':N'D:}
m;?i'|]Wx0r_
A_jeNH
esN>k&_b}>8
tRYf!\y
!E#}ky
=)Q~csOA'X+dy
S7B`:?]
"{^0f}^+
_u*S}4Ix\
`xf'|U
'2mPT/*|
*9!sL!
Vn:.tZ
_p[Hf.
~hkcVb
,RZJ)e
fm&al@)8fd5!3,}H
esN>k&_bU3WI
wvHL%[
_u*S!^)VT
`%nsmf
,^(V*2
m;Lz:5WM
C^>olME}
3XJ ,9r
c#O>"/M
v39Vb`&|
+.f@?B
RNUB/7
!-p.j(
[o}2zsM5
7$4Zdu
h:|Ah
74W!a9*V
S@I0rF%
?%Mc1@J
!w,F^<;8#a8;V
*b}}.q
N|)4E\PB
u.J1WMQ`8[
F]r2P|.
qIFfbw}J,C0s<]
_r4F{e tf
np|[rkj
<!)bM\S5fdSk2CA4XAlN$n
/WI7Em:'
".O<Cz3O7(n?m
T >\XqqrB
v~.3o/
+3n`Q
(>Vq^juX0
z1vAqD~S\.L7]V]N!()f'|U5
e[^8<{
J[U+fcd<!)bM\K0
6k3,.5
4?74'0
WE{~O3b
y0BI>t
]i__ocA.
|OtN-(
yZvO\@3
3:;dU!V8p
hDe~@I
8slW/~ r
26n:.tDX:;j-
f'|UN(c
)C-{k;S&4
x{&XW9$=
n:.tDX:;j-%Qs?j
uDfl#|q|}.
d:zGg*$
,p3]\WQ@3/;\9Tg
Fn?E3<J>~ LkD54t~6HJQu
h&kZFHO
keiLy8l
8}_zr1VC
M~~`xiZ
K} iq
6kF?;:M]
KC"PZqMq8(
4_>D9f1
zN(5aSD9f1
d4^dI+'
+?'V"g
:\~n5jf=to
n^ShOmfeM
n:.t_\
X%Qs?j
d:zGg*$
,p3]\WQ\
Fn?E3<J>~ Lg$|
4t~6HJ>
49.~'ff@?B
f[):Iv+!CI*cw2TnL5o#m$dI
U^&(;(
^&(;(s
`%nsm4]
}JurF+ B
hij&r\_`%nsm+L
c%z^&(;(
o.!^&(;(
TT6^&(;(-5
Qn$(^&(;(6Gw pmrDQ^&(;(AZf
DWo`%nsm-
L^>x^&(;(51I
_ `X^&(;(
^&(;( P
}~4lt2xP`%nsm
$t^&(;(1m
5;*BF@P
}g+&iZ
|^&(;(P>YcK4X!jz$^&(;(4at
WJ^&(;(h\v1k
^&(;(c[
-z>^&(;(_'bO +
)3Rx^&(;(
I&:ISD
Fy2h`eH^
4b:ISD
Fy2h`qj
UB7lU%
dBs#JhiO1|rO
AN,hR4
u<Q=pVG[
7(q90J
V|UdJ:/
$=]8@S
PyAUpfU]D]gq!z
_F8r]6P-9D
vxn/&'X
O$,{\F
L[/YaR5#
!o.am+
,TXZLOT(`Oa
$5\G$o
5^?Wv'3@
=9q<F~!
qWcF0#
kk_B%a
Vh|7kfj
2kF9Ls
-(7ZG2
kk_B%a
*v)Ig)
Fy2h`qj
M\;j/Ho
q7cfV`s
cp[J6Y
[??+tLl
0A~%&VJ
Xx}Y'%8
viWNC5^
8.kE_U
,TXeR1{
`f@?B_
kXLo,+b=Y,&=j2
*~crGO
YRA7C($
cp[J6Y
[??+tLl
,TXx
d:zGg*$
,p3]\WQR"
cbd\pHl
`f@?BL,
c0vDh"e
4_>D9f1
Rg"g[2g
zN(5aSD9f1
zN(5aSD9f1
!op1.|W
,TX104kk
{cV0i{CrkV?]
r[s-k,
BD!#~9G
;[5mp\^Ngu<`oaR9
Xx}Y'%8
:0tCI5u\
*zQ?/=
Y#:mn @
7^T"RXOC-N,hR4
{cV0i{CrkV?]
KO/$ks
nIxhf%(bD
MYbBL3B
.saNl}xm=3*
m-IECrn,T}?
"m5S)B*
#)9-^*
8slW/qd9
#)9-^Ob
z[%`1{
8R,3u=LAG6$
cbd\pHl
cp[J6Y
[?F@p
@.sB;G'>/kCl?9..X
|E\{*#X
,<0Iv"c
W/QlF%!=B
{/~Mi MG
Y7_T=ul
cbd\pHl
L`R^z{
HUA fP
2J :HU{ClG|xe
kXLo,+b=
61!#)/0L,
W/Q|7d%|nvU
,TXWzG{
i:P,7jVg2,m
N,f*Ib*-r/
;HlmU0
~-hV2~
|nu*1&6$v;+
(EzkYmq
M$AY72
}ad0d(G_XP4
hCdo$=Q
>dT6(_F
~<1|=B
W/Qdo$=(wBWO
Pu&$CM8VGI`J[6
Hb7j:N:9O^/R
WaAP4=(
J?z"z#
o4A$P5
f(;O{v
MV^`a~
V/I4Kxp
ea)Pp
K*i+9p
H()p\d
mSVcS;Dup
0xrf6L ?pu
$LcRk?
4<4n,{
6J/4#=c0p
iYIPp
G5e'p
0^3{J}
N[G~p
Moo`^
0fZMCoc(8;9
DRd(Tyw
(w>;Z3Qr
^yck?tVq
'iD?,by+Sp
-MC0jTx7e
W/QCj-Lc
Hz[(0N
3?`3h}_08:
:Ne9@^~
4[h, 5
HsLJA]
,KqdEO&
*I.&}
K5Z,VF
s,At$WGDs
}?`@X5f1
h`k5#>H
Da$C s
Me(fn`Y!t?
8DV\%!PEIY<
J85#2}0TBO
UR*FOVu
6*-K#,
k;cpSr#
^*Cz>;K!mW
1Yd~gk
k;cpSU
nQ#:?QzCy
cE$HSQWs9wH5*>
a]f@?B
6V0EF'Z8
wEl*b}V
(CXAl)&-
q/}:G{
8L2)A *26@
*}7bq2O\XOC-<KQ
Dp)JEU(a%_$zt=[)$
k5#>H==
ZecJOt
9dRm8
@7k]7X
.Uu7d2MJU;cB"8?'x
>&pPWPBEe
[S=\KzyD>"&
7=G:\*D
D"zcjBF$=
DIB&9?vzJ~
_\e5_
nR:OOI7?O
YFhTnjz'c%>
yc&7XLz
tfEJ]~D,kv)#`7W/
IH)nj!8
BlN14uZ
<yt{Dv|&
_2,RP~
Amoo'g
Z&+jA(
V]0Nsn6|$e
?g1S(crlR_skv
A0w58T"K\6O`m6
o!>&@[
JsR<CC
d.[a3WS?F
k==>?a
V&OWT1p
L=SA<Kg25
wpM"&bu
2hZ!Mezg&
2x9NZbq)}7}.*6H
DNxLj[M
5V4q{T
D?9TO~
CiogHC
l,j^"*D^
iN{gpA5'm
Q#.$9^.
Tu-l0+/s^Z-SgHy
I!^@n`
#bsWJY!QQT
1Nvo3y
$[qfbK
6xgE/515h<
.`z,yQ}C+3y$
K2bV$%h
kR;Fq#
WW[Bn?3\ji_s
JyTc*i{nY+8
,/m1Vd
jn\"wkL
mHW;zY
/"R"~r
|=+t"9MT
7?_4.C
#(4Q_/
s3W'(oqipJL
1'C)TIS
Pg"@</u
tOx0`?)gdd
m'"$Lpf
`J2tR%2K[!HGJ?9
HKr3K0@NF
n'R1YN
vX/"C1/
HD|<i`
67(NzY$
zX,yL]\R|
|laBHM
#8$:/|Wr
&BSI12
Xn)\uQ
%*&W32XJgwXw
dX@HwteG
tWo}q[!
#4ev+~.
r]v 5$]
RDE9b!
\.rv4
Z<jGX?
> j`zGT/qQEerLn
c}/h*D!DU.oOY
$3N4JVJ6kt:
SI8ZPc
a7c*;":bfU
24>rfU
E\O4<:)
5 aBrb
F5pB?_J*QyWL/qGZ
kEJO4F
wPsrUT
vohvI$pALe
)x.7a,&Qvmt/DR
{sC:qjF<Ns/wlhN1C
^'QD4
R}0~=R
=DZ0Sq
'A,J*b|
$FRBrdF
*)Y8-dx
[N%nzUj$
KVlpgeJm
neDu=Y
eoT,+IH0V`k&
PX{/>K?-
8t~2TN
qk$,o~mxT
vg+*"n>S
vg+*"n>S
@O]$RYI<K
"zj, /Ux-
r@264=
T82)cikm?-
lzvy[)ag
{RyNZ5w8X8
}j|&/U^
}j|&@OLyi$FTSa($j.
_V[P"ar$ptZ-
G:zS8dz"
<ss)4HdOue]F
>1e0ti
GIDjgDj9z}\mn<
\;<V-7E2
HJrw9N
W2'>Pb
gNUTR~L'
qg<%O`.yvc,3s!
eIJbu\
7g%PWt
FE/-grdK%N{B%l
! Y9l=g"}E
c@k:+]pxM
O54!DXz6j
y%rY<3+
4gQ"t|]bP
2eHDKE
;jk$F8
BOsa{u
\=p^m0Qhk
ss9lOh\~u?
PB="t)Xdcs
_OU~`:
HaC/%93o)
'?&,Z`l5
<Ax.
b"[H7.]
,&dd0wb
4bRu=1
{\|og>3G
?3MZ&T{JP
u1C-a7q
O*o<\]
Cp(#(RMVB
#hy#_,xLl]K*Zh8t
@ZL]36
df?q."
.|L]rPRvVxxY9Mi
;j96hd$
-B]GN|
>OPk=J
q!7|WXH
Z1 m~s
v<\MfYYM`LV
EN8y6JCz%B,k&<
=8_DALy\]
oFcW|yi:
Zp?_Ta
k2&\B:q
0R$+Oy.
,Bw`Ys
=*pp,5
N*O=g:
0F>iQT
s*=FE)]t/vD?q
cB;TND8pF
u9N32'8t+
'mk)yjOD
v*rIA[z(X
7MP=[ePW:_Dx
kkthC&
k9D&d2Y
06Hs;
h8bXBr_
2k{`%nsm)Meum
l'v]`%nsm&
t`%nsm
FagM`%nsm[{7Q
"$I]{G$
}R%XTJH]*43NU
^:!N`
H`%)^'8PiviGR
q%28BL\>f.0d+hA0
c4i"PBhcbp
i5-_d=9
&lCdg3
-D_zo
"Y+V}bb
-D?%I
mW\:D;{iviGRSu
:.\Yz~1
&v99A+xSx[KA5d
YiviGR
r#X|#m:*e
Bd+W9Kk
,2l@Dj
sB-NC>
__%=yDUw
ZI_nS z6)}w
(YDZW]
]a>WZ2dE0:r
`dSBVWo
|" Pzvn!V.v
O+ y8
B<|UG(
WA<.>)Gg
0G69vI9
K"97^O+jTl
U"KrH5\K
vza&/'
.$K?zbQUQ@yA[
I\~L"kM
s:T8#Z~L
R$9__~V\
y|jHUMI
Ja0"2JH:a:C
@*Xrq[p-KaY~y9
eV&d{^
ARm^Kxp0$
b8DSi4
((JSEq.clc=v!N
RK|z)`
(aZ}@Lt4_
sE#z$K9
g$tCUmP
a.?,|jei#
X{W_Br%#
v2=_(d
F<jM0|
+rPUyZ
eGs54!
7e$`)#]ee
*N |;dSG
1NGe|R
-$V"c2J
M+uHm\]H\D`h+vRb#y!
x,mz( 40\!%0.eM>
2Q}S#=Tt
A$QwMMT=(&
mV_cKvsx*[
bxr.xJY#x,
cb?-PS
H}^B\!&NO\R#CWN~+RfaEWxm`"Jaz
Oq(*iv;H
$P9\geM
ypFd0nl9q
'9vkOJ
w-d*wi~f
=ayj-Hgw
$5g#"!
j2jo\^
LDUvf\O<K<
fWgx$x!
D~-nx(6S
rC72vsqTc+'
6E"G=H%2U
lvxD:Pa6~
LiviGR
)g-|>A
,!oS+l0
Ahk|>c<@%
2=ln\}iT\$c
;-{oOy#5/
TQbVS'
xPs.<$
ft:{4LM`Q|4Ru
ded-Z$a
|coS+l0s%-ZiPB
gCT|,)d
.;K~fy1
u4Y?CEbh
VBW0[7~$
;g/BR^
ld$DeznKe+IAW fwb
Wk>':/
}hojcYo
fN&xLD}{)
'/g^x&w 98zLj
)-G&XHSI4
%=L.X3K
i@z5-8bh+
r 9|Kf
r=pMC"o5 R}
5zxa43&
QTR`E$q
F@f$oJ
rhb;%;_Q"
Rid=uW
#iE54Ig]K#
x7+,M3
x7+,M3]"
w&_At]k.)
[13{GH
}eM+"`w
)eB`)l
CFl)d.H
2?WZ2diO
E ,i>P7
dm&,qqk"l
SYU<;6}J
jZr2P6
Q:;o]W
/-$BX^m
r]9d#F=
v6%yN0^O
, mdU,;
BwU&e-Nc
4Ts@vh
\7Br0\f
0R]'Xd -
$CRo0^Z=IZ:
r}"Y"IqD`)_Iw8
uVqpt|(?
Y!(b`\&Zz
\H$C+n<
plvti?
q\'s9h
D'{Csb5
fi+#]KY@pmH\A
rY2O9~wl
8rqlnXMC9
^}!wDUU@x/
zo[jN?B
&enMZ(Fey|;/y
M1SIvF^2
^x_x)==4P3\
G`$3qKR
4HsrL^z*3#z
Pb7~}g2w
(O7+p1j
K{^P/tT
-?iFdW:
E#arcnZA
R+0IafGTDy:
<,Pulayw:(Yb5_w-nf
m qaL-D}
ZY^TWh2(%
e>h}LEp
yuc'09V
zNWle6JZ)uk
uB#Lm#qQ-C
St~12S
J0Vf5_Jk
;3WSJkcjn
5o-g(e
m6,v_I^
YhiWH@Q
\Z:@em6)
M"[`m2K
@Qj)#p%a
z" 8=o
D2{BuT
+wJ*!hE
Is NR7pr&RVaY
2A015)
e6C[Qm
qB]!9B
&`~l}O
2wkP)f<fQw
PL*`CY
i>7%kit{
:+X4k
m']et
,7d54.e.%1T
unef~e2(y
QAE;e_J
qZl=B1
<GV?T0d
{ER8d(>},yf]MF|>)E1u
dCje%g
ks8Qq+#0+
P/y-%g-~
+#?V F
HNo{qu
[NldPI1
B~>&~b[Rj
cEZ21F
PEt^3s!
?~f-34__:Ds
~5<W?-
g|t}HmB=;t
"C]~5>6
sN;l;^Vg@~-m
iB!HL.K|
}+m$9gnU0#K
&vH],r]0"
jx|m&6I~Oov
~''_5E'
?\+Xt7WNd
4'NW)  ^v]
ICm^qqg
poHFKup
imQ(3%n
h)pF~\x!V#."Pq3#uBvO
*qV)XMI5F6$2*N
?V)XMI
?zV)XMI
{O(V)XMIZ
|)isYQGE
QV>&A1n$`p-KaY
%AxmV)XMILc
l$V)XMI
fuljM*{
}[$?!X
`#fr4
r'hrbA^
3qP`ezi]{A==9BVb
OyZ5^r2
21z{El
N" *Qw
eQ=B;q
gw)`uO
;mL*P<
8U8*P<
wY4O7X
e\C4tQG\W2NAA}B3
_U>`yJy
Z/Yd)Yrm;
R|/=]tad[
!n.n#Cd
08Wr Nbe2P
0`tEA&
5[l~ealW
>op.s%3L
m32lN[
xg~3rNB
$VJ3_$_3
"g7hUI#SPn07z
cy|jM7y
$tlX9{w
+xKIF>,
o%|n<&9pg
vnnky#%/YKOB
#qY|fIy
uyvn<P1c?6Bi_h-
TY4t!)
D/F'#~
8E"2jL ~ $
r1WfOc
9&:@1m
_MbrE8
)7T1&=
QPLf4]@
Sn{85T'?
o]cP9]x!
TCLD S2YSLThA
#O'KQ[
WZk~"}zy0y
"&$M^.1-
DzW\zZ
B:IZfJ
\M{A}cE
/E{4(\X2
Pg7l{
%=+HyzQ?b%lvZ-NzqXm0%DK%
*g!"Ll
!<^[(8
!:iJ1^[Or
vKVGv6<
$K l*c5
E5LaH:O#
v,6F=S
Su>riiO\
d+Owp<^Pt
W7~f>R.NI
=U?}?
+)(J@Kh&AD:
y+%AX;"1]fKrq
HB5?xqe
-7R5*h4Bb+KI-:jE9f6+i
.-uarDLa
njTWFfb.
dgOYLJ
ZPH6w3I
%=+H@M
I]`XA}
oL_e(f|V4
Ec7R%Ax-|
fLm{a<"OCbkR
w-xfJL^
R?pL"y-+AC
#-XH\9D
a8=T4$OS
25okF(UctV9V
X.qC}t-f
bO{"F.^O
E{4(\X
.QQ>@Si6D
CA<!kF(U
7S;^Mj
qC}t-5
llW*`k`So
+E5s^5
T.Po^Ne
6{2irXk
\niHutx%
#(:TS<Q:}Iwy
Bt9yd]J>
2+qC}t-SnH'
*+k8tfZIv,6Fs|
c](Sr5
dg ]lb4
>u ~uH/>
*CvOTCK:2
hyB.K,
~S0]e75
_>]=L*B%W6
k%R $
8YL-{tSsY+
++gv%%r
AX;"bw
jQyVw,%alm/O|
S~s\67!T&;\
xXFeK\R
4uwjAY0c]\
l*+ZB]\jg3
{MUzQP:l
q2:ds<#a
Id)'&es|
N,KfUU
CdB/(jn56=V6U>TI
6}:\=j`,
[zEs|ih
XU,F
eV=yZ`-2Db
TZ!< )Ne
XyCIDArbmQm3*
@{G_deO@SJ
?r7%jYA+!m
.V5oNM
|6=V6UxfJL^mgz
SKfJjwR
df0 ull&
tNtSu++
~/6oXChH*
a]_M:H|3!vR~2\O2bS&}
|P1Yy`
PgckO+y`
SD/B>i:!
<e}{uDw
|30[P`Le9%d_
A4qC}t-[}
U&^6j(xK$ny
lf]MBTzS2v
d.f:"br
GhXPJKx _yZZs
?h\}5A
[z1ETI
QcIm<oV8F[
u>H7G\Z_
.5B:zPOB)
4Q}))r
_qP+sU0qThiw*MB
IKg!@7h
p2CTk$
IK6fIJQUU0)?
l@it`?m
A)x@gB
IKC*?TK
IK6fIf7
GOx@gB}
Y^O|W1
IKm[5n}
*B@hRQ
DJH9 K
|)AKe"
[x@gB]q@jK%
4LL''l*
"`LKe"
[4+HX.)]~9|{
[|)Aeu
iSUiK%
[y=O4(h
t_?==V
TVA|zlwBiari
G9.a<mI`
=F'LKq=9]NXw;tA:eyB
DJH9 KzX
!{3-l5#`GUP@
x@gBR:
NC#9Fe
{:kwNekS
Y^OcI9xY#SO]f=
1]2CEEw
pRFj%/OEY
C_K6{P
C_K6{(n>q+
5K0U?8
IKx@gB
&|GWPMEDu
IKkfPybP
A@/Q+n
"3t`?m
s_|Y5#`G
;mpv&u
@eGTEV
`_'R9
JiVi//k2uk/
85xm[w
4EVaU1Lm
85xm[+lV
/n0@~pH
i//kn\F
3'-f'k
A|uu0mZ?W
IKJm\9XA@1P/
!s1Gh4pA@.
(*4KqFq7D`
;2"NF!XO
pig!Vpz
IK@Q%V#v
M"hHn
Yp z{|zz
K;!PD7
.F]r8<[Sb\
zu0=RmH^AX
at-$*mS
&|Gu+^
x@gBkx
X{%&v4L
eA-^D!(
A-^NJ7A-^3
PA-^DzP"A-^t6nZA-^
mA-^$kpUpO
Ik8.fM)Hq
G|:iN95*~
Eb{;_Pk{L&O G8
3d*xcbWx$#
Jg8&s[<Tl
Q%ob&;>
0hEa+e?3|
:Al)oP
Y8$;fjj
QNZ:+tP6
r48~SfE
?@Fa<o7
h"u0Ogq
"L,R-$8M@?hBHc)rjd
Q/N.Iq^
Q/N.Iq^
Q/N.Iq^m)
b,'{P%
HQ/N.Iq^
Q/N.Iq^
RBHc)r
Mfmah
Xe;H${Xm
p'N!,ZgG>
0+D"Xb
Y^Ox@gB
IK,]a#
foh$Xb
IKj0IZ/]
ui4l,J>GDM
tl+v;]
A%X#{\
wS>@K:
`$~l7qZ
h*0O8'\xY'
de3NQ-e^
RbQblDsm
p#|&]$~&
L,Vs?]o/
Jy?#6B~
N|B&)[
LmnB@6 w
8AJdj>(]5(o
&2t&'oR9Hf%q\%bl|3
)7vlq+
#N $mpb
}[#|)o0q3W^S
X#?~d*jxG#b
!^\GS4
8q&?f$
m8DV$~q
FX{^k
|K9TKO
EUGbrM
"-T}fE~v`
EUGbrM
.s8J0Wf
|K9o/('
o`>vTH
ah\"b`'9
EUGbrM
o`>vTH
EUGbrM
`ok0#z4z
1zsiUv'p
=p}_j>
mkN*ENW0
z'oztb
lCoUkX
lCo7'R>{l
EUGbrM
`ok0#z4z
1zsiU>(]5F^
><Ux>vTH
=p}_j>
+$yK{N6
/<Ux>vTH
=p}_j>
+SQrP,(O
(KGRWf
}C9n:OO
hiI^{b
Hv`zJ;
tOQg3rH
7k|1P?yp
t]rh5F\D"
zl.yc>
dCYLYN $mpb
kd4G@
V.qeQf
Hv`zJ;
zl.yc>
mkN*ENW0
zl.yc>
%rrVZW
zl.yc>
+SQTt31r
kd4G@
kdC-SJy
6Y1impb
6IIio8
vt(!H
6]rh5F\D"
VZ|ZdU
9wdt\S,
tOQg3rHC/;
C3[L$5$U3!
+SQrP,(U
NrQg0gW1
zl.yc>
6Y1impb
X#?~d*jxG# v"yh/]
hiI^{b
Hv`zJ;
6Y1impb
@mVT<Qah\"b%U
,j2Bb\r<#D
;hCac7
lCoxE
>(]5_[b
^hCTKGj
&Qot5,.
v`Um/~9
zl.yc>
hiI^?qt]D%IuvW
RbQblz1';L/
vS)7vlq+
TDO)r1Dj$X
zD_Q]x
XujMD"
C4c3~]9h
cZ!Xu/`
[qY@su
j;6MQ:_G[
|%)7vlq+
1zsiU7[
cuX|(6Y?z
5#`Gg!
Ljo!D
cuX|(6YJJ
s|z}kg
{uX|(6YM"
NX:+1C\KT'$C"F
b%97C"
IKsDY'g6
-@.r?(q
tS^{lx06LXfkt
a/But*5
{BP*L]c
aAgq(5
f1{Na|`W
/e#/d]{
8&8%;q
1c'[2#'
z3<A@7h
CRsMoU
#SB9d,r
.rnl_Cac7
IKZZ{&`
TbnS/y81*X.
Nuz2(Ot
Kk0I0jkgOh\k
6Y1impb
@0_t?f$
r=R*G~
VurDkX*
z3<Aeu
IKC5^qf
6Y1impb
?Itkb6l
[SzR5]
s|)o0q3B
uu$YVbF45q
zl.yc>
6Y1impb
RO}S-aO}S-a
KPCX@O
()rlKe"
zl.yc>
Ss~u<#
kUFMX\
8g08u%
i5r~<S
ekxQCDo
CCPIJKMNW4w0=x~t
uFG+Wy
+SQrP,(
i8U|Y!h
IK*5NX
IKmt.k=
&|GA@UB
IK/Q+n
IKj|{j
YiYO8gjs?YO8g
>RHsYj
\:<$81
IKZ4s[
]nsuX|(6Y
-0YRuX|(6Y?.~d<
av#=qw
`YGs<8]
2&qYp7
!pCMCs~2A@
B?z}kg
NX:0ZD
*9uX|(6Y6
IKN*LX
cuX|(6YJJ
s|z}kg
RJQUU0
`YGYO8g
0<_d7I%uX|(6YR/ng1O{
JhN*LX
cuX|(6YJJ
s|z}kg
GO!rV3
.B)}z}kg
nuX|(6YS
la1,[Z9!z5
o2H>s L
4LLJm\9X
.B)}z}kg
uX|(6YA
[nuX|(6Yc7N/%
}Qe>PA
NX:R/ng{@6'
JhN*LX
cuX|(6YJJ
s|z}kg
IK\KT'$
#*w:mWb
%97*.}#B
uX|(6Y_F
7tMYM}
JQUU0ad+
i{@6'p
u2o2H>s ur
<35"fXHA+R
jxG# ~L$|g9i)G{8iPKETVz
3NQ-e^WPL
#%XZj6st
X'%'5B?w8
~=dLjM,
5?!C=
=S^Yp}b6l
V05P@rDkH3x] {
1zsiU2
V05P@rDkX*
#%XZjUQ
lCo#~?(
~=dLjM,
5?!C=
S^Yp}
**BMgv2(FJ.
S^Yp}9WY
2"==]ji
2"==];N$|
i'D za
LjM,2GD
+5:s*d
(?[] {
Q8LE%r1 $;
R?k_3g}@:EZ|x
~HJ~h2
h-&GZ.XTQz+
+?Ic$z|
[Rb+@-2B
6#3r"d
st}8U,
ky`,6|rWJ0
Qv,6FQw?
=}xhv,6F&~
LQs*X6
&3Qs*X6
lsU,[Se
lsC%.w
tPh3S0O$
-D0JEUs8.SYw><N']<
y6SBZVTT
g2,{$.
K #!vB%p
E5LRme
>i!'zf~O\a
G )1OCbkR
K #!vBj
!:iJZD
+=)|wTM}
2.#G,c
Bj)]ktsy\,J>6B
0#iOwxLmU95;=
8uLy~s\67!T3B
t%dl,C
%=+H"|p
A"-q;>1]R+O
u-%/b^
L-{tS@eds|
)XFt?Uh
.,^gS0/O
5fc2NOYLJ
\=ULZfk
%.QQ>@Skk
&~2W5q
'&eSYw>
w6+nd89u&6
DvWEu?
AZ;L-{tSiZCW\
wSk=(;
qd^h[U
#(:Tk({*3SK^Y
t}q\aNe
?yP6N"q
ir@E:s
PTJ.y73
'&eu&%8!< )Ne
P4H@[g
SYw>~r.4
Vz"'}qj8
dg>?|[
os,,o_
t*9m53:#
aeq6mN
tBb89wa]36=V6Ui
*C+C04y'=
\;C%.wo_
|55bF_u_ZX:
kQ\M7w
/7.Xiy
yzQ?b%5S
7fE@i6D
Ool==)C
Rcswx{4+U%J
o@!Zq5g
QMcKarr*K
@1?@x
VagP"G
aWXm[Z
yzQ?b%
qfH4g`i{
E.1U" \C
E5LXuXm
{ya=bi(6
p)61L@/D(W;
dSy(%_+\
lh]xGeewNtG-
\EgRM]K
@,%FjIj{
KCTw:gXJ
KCTw:gXJ!e^bV
QcIm<o8?"
n}(rvy!r
/F&Q~Q
9PT*&M
]d9i|s9b>3K
+=j=bR
tU<*#k
~Brf_(
C**ZmL|(d
T]YLgbF2
mdB^4g+J
x|~z#?&
&J9B.GjPjA
!|5$21sS!Xf2?aB)}
IDGkfYP9
.D0b/DC
E'k1ez.<m
~Bf/+Y=t!
hrY\|Q
0MVq9'
Jl'a^WdQ
0+=Wd~+u
+hv(bh
rMMs~tg`E'k1ez.<m
/zrcXN_ZNJ
:NKXH+a5hD
Z(^MLC
+hv(bh
rMMs~tg`E'k1ez.<m
~Pl"<1PzzuVe
uZTZzrPN1vl"<1Pzz
=v\{<t7
2g]t}t
t_8CF1LC
quq@?*cM
Mg\Yxl
S]'#QE'k1ez.<m
+hv(bh
rMMs~tg`E'k1ez.<m
~Pl"<1PzzuVe
uZTZzrPN1vl"<1Pzzr?qy
/zrcXN_ZNJ
:NKXH+a5hD
Z(^MLC
t_8CF1LC
quq@?*cM
Mg\Yxl
S]'#QE'k1ez.<m
Q57KDP
+hv(bh
rMMs~tg`E'k1ez.<m
~Pl"<1PzzuVe
uZTZzrPN1vl"<1Pzzc[qb
/zrcXN_ZNJ
:NKXH+a5hD
Z(^MLC
=v\{<t7
2g]t}t
t_8CF1LC
quq@?*cM
Mg\Yxl
S]'#QE'k1ez.<m
/zrcXN_ZNJ
:NKXH+a5hD
Z(^MLC
-A+Ezt}t
t_8CF1LC
quq@?*cM
Mg\Yxl
S]'#QE'k1ez.<m
;zV^;j
+hv(bh
rMMs~tg`E'k1ez.<m
~Pl"<1PzzuVe
uZTZzrPN1vi"!
t_8CF1LC
quq@?*cM
Mg\Yxl
S]'#QE'k1ez.<m
+hv(bh
rMMs~tg`E'k1ez.<m
~Pl"<1PzzuVe
uZTZzrPN1vi"!
?f|Lv"uS^C0MVq9'
+Bx^>Pr# sR;lxt_
HZ#k?[".UaGr
@\~KW49
'eTS"+"
WosOrm*
\xs/Npd@
uBji'iM.H
oq[RVVxC
p("EG<
i4ij'r0
:tXli'?
ccn6pf
Rn7zK0 ;
lrnOb^-
PhtCih,
+`UO6T66Y
'6.lZw
=X_3 S
ED}]1G&.G!
_RGcA=
WISZ.k
.wNH6
mJ)t#Gu
nw.6'&W+
4{[T:;
a3agUB
S%)Z8gA
/r2g[cI
Z];3"hQStw64k:
=jqh]aB
t$d(ycD
d0:oi]3Kl
[RwTW<VQNKm?H
QPCW5ccZJ<
>Z'7ew
=C]amr3b*
jLjupxa*
=]ygib
M4McF[W}&$
f f\}{
IR7P~[
D`(C3,
Ki2(SGHlp|)
AP3cH,UVNh8
0tg}+OG*
{UJ6't
L>A'%8M7>O
"z[],f
qnNxOe#-[}Io-Nl(
sbyYVqI)N1
3c)bgtkt
qH!ySoS
GXE#K+Y
{(|&@s
95\0s!o5Ri]
&nT+#<
kUnu:S1cj
(oyd@'
m'@5o[Ub)Y1u9
FD![*{r23$
7"+"T
fi 5aw?
q$C,n~|
DlBf=)
:D'jG5z
)!t@0UT?v7
UP!mlR
]LEM!*8
puFUhLfo
TDusvr
WDusvr
a8l7eP)
>?2jdx
tUP!mk+f
3NUP!m4>
FI%Wcz
C='bL`w
?NMF\[^D/
oI+T"gLZOH,UP!m'
g*;b,yA*
2q&2$!
/GpnkebxK
Cm6BOS
<t,IT@7TL
;yQ.nG
{7C '6|
GI[kM:
UP!m|\
z00ut}_
AxIp4|h
cKCaBPT*
"dO+FN
YYP]\s+
?df'0==t
`)y^sZjA*
"gLZOH,wD#m}~O
CRHO(e`
&$pMQa1D
Kc1-=D
n<D1x_
z6=3cOz
Q&o`%nsm`%nsmuHnR:h?zv@)9
`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm
HRiD~Tkp`%nsm
H{]{ `%nsm
N)lX5Lfh11\%X-"!n
<9<0*vN=
@/&o?/xBM?K
nZ;VETsOR]B+
Jm/KIM2PM
R1G3;i+DZ;VET
US3RBn)<<"5
^KLDbf
r1*(^]
; +Hi~
`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm`%nsm
yf>\Lu
HL$8HD$@LL$DHD$(H
E3Hl$
HHD$0$
A;ur3H
A;tbLD$4HT$HDHD$4
Ht$ WATAUAVAWH
3HHL$TDGL3D|$P]
D|$@|$Df$
HL$PDGP_]
3HL$PDBPA]
}}}Hlll0
kkkkk-
>>>>>>>
+x$$eb@
T$HLl$@Dd$8H\$0D$(Ht$ L$ G
HL$xLD$pHH
xDHL$p
Ht$8fD$0H
qqBqBqBrBrBKB
BrKBK
yyyyyyyyyyyyyyyyyyyyyyyyyyyyyy
yyy5yyyyyyyy9yyoy5959yoooyoooDN
yyyuyyuyyyGyyyyGy
IIImImmIm.mmm
\\\\\\\\\\\\\\\\\\\\
zzzzzzz: k
)44))444))4)3
4)))4$
rKKi;';';; R
LL$pE32
eb@.11
,jSjSjjSjj f
>->`>>
>>>>>>>>>>A>>A>A>q$
jjSjjjS,jSj,,jjj
S,,,,,,j
jj,jjjjjj
jSSSj
%.%...
yyyyyy9yy5y
GyGGGyGG]GGGG]]
]h]]]]]]
yyyyyyyyyy5
b@tu "
CredWriteW
CredRenameW
$eb@ccjcjc
jSjSjcScSj
jSjjjSjSjjjSjjSj
5oDDDoooo
b@jjcSSjSjSjSjSSjSSjj
jSjSjSjSjSjjjjjSjjjSjjjjSj,jjSjSSjSjj,jj B
JJDJJJo95y5y5o5oooJoo
'''g'iii
yyyyyyy5
yyy5yy9995oN
Gyyy v
jSjjjjcjjjjjjjjj
jcjcjj
$$eb@j
SjcSjjSSjSS,j
jjS,jjS
)fE;u#HI
AH(H\$
[ Ik(Is0I{8IA^A]A\ Y
BBBBBBKrrr
S,,,Sj
S,,,Sj,jj
jj,,jjj A
8888`t
JtJ`JJ -
}H\$0H _
qBBBBBBrBB
^c^^c^*c
c^^cc^cc^cccc^c^ccc^^^^^^^^^^^cc^
^^^^*^^
^=== M
LLyx$eb@s]*]***h**h***h********
^^******
]hh]]hhhh*
,,,SSSS,jS,
jccjcjcjjjjccj^jjj^cccc^cc^j^^^c^^^
$eb@!ccccjccS
yGGyuyyyyGyyy]y
yyyyyyyyyyy9
yyy99o95Jx$$
GyGyGyG
'~FC(g
'~FT;[
:ff::%.II.I
\\\\\\
\\\\22
HD$`t$Lt$P
Ht8fA;u
f;E;u*
fD93uH
?E;u%fA;tH
---W-k
;ggg''g;g
'g''''ii
yGyyyyyyyyyyyyyyyyyy5yyyyy5
yyy99y9yyy59yoy
y99959ooyo595ooDJx$
GGyyyy
yyyyyyyyyyyy
yyyyyyyyy
.....m.mI.
&&&&0T&
InitCommonControlsEx
CreatePropertySheetPageW
Prope "
8``88`t`t
c^*cc^ccc^cccc^^cccc^c
cccc^^^^^^*^^^
*^^^^^^
MHD$@H|$8H$
L|$0HD$(H$
DHHD$
A;tDD$PH
t[HT$0H
DD$4T$0D$<DL$8HA+D+D$<D++T$8D+D$DD$(
)))))))4
BBBrrr ~
cjj^cc
jj^jjjjj
jSjjcjjjjSjjjjSjjjjjjScjjjSjSjcjcjjSjcjjSjjj
jjjcjjcjSj I
WW8Wp8W88`8
8`88888
JttDJJJJJJJJJJJJJJJJD F
}vHHH}}lllllll00
kW0kkkWkkkWk-
\\\\\\\\\
2\2\2222LLL222E2LCE
$eb@:f: <
ccccj^^j^^^^^^^^
D`JJJJJDJDJ
DDJDJDDD
SendDlgItemMessageW
EndDia
^^ccccc^c^^^^^^c
^^^*^^*
^=^***
eb@s**
*^c*^c^^^c^^^cc l
Lt$pH$0
LD$pH$0
yyGyGyGuuyG]GGG
UrlIsW
UrlCanonicalizeW
UrlGetPartW
PathAppendW
PathGetDriveNumberW
SHLWAPI.dll
GetComputerNameExW
ExpandEnvironmentStringsA
RegQueryValueExA
RegOpenKeyExA
QKQKQ;;
))))))3)))3))3)
qBBBBB&B
D`D`D`
DDJJDDDJJ
hhhhhh]hh]h*
>`>`>```>>`>>>
v}}HHH
llll0lll000
kkkkWWWk- G
H\$PHD$XHD$`
x$$b@shh*hh***
^^^cc^c^^c^^c^*
`>>>>>A>>>>A>>AA>
hhhhh*
h]*******^^*^*****^**
SSS,,SSS,jjj,,,j,,
,SjS,,jj,Sjjj
b@z..........111
jS,,,S
H\$0H _@SH HH
H [H\$
VWATAVAWH
)))?))?)?))?)))x$$eb@
;i;; I
yyy9yyyyyyyyyyyyyyyyyy9y u
jjjjSjj,jjSSjjjjjjjj,j,jjjj
8||J||J
yyyyyyyy
yyyyy5yyyyyyy5yyy
yoo5oo
|J|J c
\\\\\\
2222222ELLE2LL
$eb@::.
S,S,S,S,S,S,
jjj,jjSjj,,jjjjjj,jjjjjjjjjjj
ccc^^*2x$$
SjSSjS
S,S,S,S
jSjSjSS,SS,j
oJJDJDoD
H _H\$
..mmm.mm
\\\\\\\\\
\\\\\\\
zzz:zzz::
c^^Lx$$
@jSjSSSjSS,S,S
jjS,jj
jSS,SjSjjjSjjSjjjjjSjSjj
jjSS,SS,,,jSSjjSjjSjjSjjjjjj
)3))<$
BBrrrKB
;;;;;g
ATxeb@
o55JooJoJooJoDDoJoJoJo
ooooJD
;;;;;;g
WH HD$0
3H\$8H _3HHX
-HE3E33H
H\$0H _H\$
WH H3I
E3E3HH\$0H _H%@SH <
mIIIIm.m
Wkkkk-kkk---
`>````>`
->`>>>>>>>>
_CorExeMain
mscoree.dll
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity version="1.0.0.0" name="MyApplication.app"/>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v2">
<security>
<requestedPrivileges xmlns="urn:schemas-microsoft-com:asm.v3">
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
</assembly>
d8476dcf-5495-445c-98af-0fe0a7dd92ed7b8ac0a0-30c1-4958-90da-5aabdbe2f229196ad835-1b95-41f9-a682-3dc4d193082744e6b4f2-871d-4ce6-97d0-ceef6909d1a041910119-4733-407a-afdf-9733ea7ef71583c3b1e3-63bd-46a3-8583-126d80f09db783d320c8-bffb-487e-9084-c3c52a6e407634a11cb2-f0ea-4479-bbe8-d7a68fc1576e58929faf-81f3-45d5-a3b4-282bef433fd3a28b457f-b356-498a-b62a-dd789abb89ecbb5e7533-0bd4-4ad9-9c57-69b2c6f58ae10db0bd4f-74ab-4f49-bb68-82f40456f6345fd8b2d5-c879-4bf2-b131-f268e2e6dd228b8508e7-156f-4b30-8d3c-2d85a615025054199ee2-d54b-425d-b06b-ea0d373865b33e27318f-8f0d-48d2-b67f-6d0e55e038795b10bdaf-3ef4-4ea6-bcf8-da93d5bfda3a30a61076-ce92-497d-bcc3-0f5795464fb02a83619a-bfb4-49fc-a541-32c318721b0561bb70e6-6c28-42f0-8484-eb402c0a53fc1dcd8443-4661-468b-9861-dd8c50e7337a60306996-273b-40c6-9217-865d114693cff7656908-60c1-400d-92fc-9c941355a02e17aea685-a071-4bad-8f1e-f000d80c49c4a0a87bea-e856-4a0a-8d81-ea84b8e048947f32b9e6-9e84-43d1-9c23-d76d6a2be91d56f49e25-623f-4956-9118-dc8337d6b315f9fac378-069f-4b95-b911-a1a6e70af40f07342554-0ae4-4a97-a1aa-0d6b3fa19c747d51fd54-47ff-43a9-8282-11778f642ff32461b36b-5e31-458e-8f56-66cecac5ba12ad41f915-519b-483f-babc-d8f3743a2c2a8ae554a6-210e-432c-b4ae-8057fc86cb2c4df4e2af-4c78-472e-b62b-35210e1d6b08cce0d5a7-7980-4201-890c-a6e19141b62cae825697-e0e0-4010-bfb2-19e70953ebc4ae0b3b6e-5c24-40f1-9c77-e9ac95fb95909369c62f-64a4-458d-ac8e-547f5291e46697fd6480-6d9c-4b0d-aacd-ba59ad19881efb3dea47-dd70-4440-bf9e-91ff8f561075d324e5e8-8a61-43e3-91ee-54d01b69df9d7c77f348-6ec7-41b4-bf38-0d1071b7d79898da9d13-9a24-418a-8394-55ed5cf06bdc5bf6697d-9b57-47c4-8807-e8e128976cb01bd78b25-4c37-4ed1-9c18-1d719831aa752956a9e2-ea10-44a2-b94f-68842de93780ef3ef2b8-ae3d-4ef2-a84e-8a8f1c158c1f0b5fc2cc-a428-4541-ae60-11ae3567e0f183172d15-605b-4b37-a36e-0ef84e57051ffb254850-8aa4-44f3-a92b-60fe3df795b8067d75d8-3f59-4ca4-8f53-b5b5ba4861ca1e2f223a-44fa-4204-9916-8b579df5339cb29f774c-0f61-40a4-8525-df7287b77e357ced1c7a-7601-40f7-ad53-f7d4af59bfb8ede980d6-bc4b-4da0-8d3f-9ec5717bd40bae6e9fcd-9c4d-4acd-a001-7e32c2341bb7ca44f01e-57d9-4ae7-97b3-5826911dcd9615345e7b-b6b8-4925-8a93-772095c3029b7eb1bb31-960e-4a34-a73f-deeed1ca9453c318d069-a330-4c61-a53b-71193ec10b4b2a329579-b994-447f-8943-1c3cbd70941275dc715c-f035-4c69-9ef3-9c030ffae388fb16c271-8afd-45c6-8170-02031748d156ea60e482-7351-4a6a-a449-166b814462e5a6058d2f-a446-4ddf-904f-132aa425ca1acaf66123-58a9-46c8-8f4a-ea43aded61fc4ad4736e-8eea-48ff-84df-9b7ef300208e0c25c95a-8621-4976-87b2-4a8b4906bcce1c0e8cf4-9c8a-4625-a3f0-6567fed0c829289bfa74-8b36-4a0f-8ac5-197680cd83252ee95d6a-f6ea-47a8-93ea-ef68c51c65b8b5e13b77-fded-4575-bfe4-02f1dcd7040b745be53d-9af7-4a3c-be62-0609ce142c8ac9cf4763-e141-49d6-a54b-b26f0beb106a00be3b84-f79a-4d75-a62a-8d9d7a8f7265c691f9f2-c238-41b8-81fd-48a866d5c0af034f907c-b742-4796-b509-988064609ad974cd925b-5b67-4219-9d50-f18dea385d2fc65193da-4939-45ae-b080-51da25bdfa50b8813986-8494-4b54-a287-244e4db53f19686b67ca-3619-4069-907e-e73d541c7a378e390f4c-4603-4f5e-9b60-e4eca586d55f044ac7ff-b89b-4310-b72f-bb07018d99cfb5d5e37f-b421-481a-a842-5afcef0c042713c887f9-f590-40b8-8ccc-628cafe3f5871d6caeb7-53ad-4612-85c9-e6e5a66965e08436894b-c7ef-4a21-b845-2150539c76e5edcd8e60-051d-4b38-b990-56a73a7b9d45
ONIOZLZLWNJTPUPLYMBFCGBQFIQDZVDGN
Index settings
-00:00:01
hScrollBar1
listView1
maskedTextBox1
label1
label2
label3
label4
label5
label6
label7
label8
label9
label10
label11
label12
label13
label14
label15
label16
label17
label18
label19
label20
label21
label22
label23
label24
label25
label26
label27
label28
label29
label30
label31
label32
label33
label34
label35
label36
label37
label38
label39
label40
label41
label42
label43
label44
label45
label46
label47
label48
label49
label50
label51
label52
label53
label54
label55
label56
label57
label58
label59
label60
label61
label62
label63
label64
label65
label66
label67
label68
label69
label70
label71
label72
label73
label74
label75
label76
label77
label78
label79
label80
label81
label82
label83
label84
label85
label86
label87
label88
label89
label90
label91
label92
label93
label94
label95
label96
label97
label98
label99
label100
label101
label102
label103
label104
label105
label106
label107
label108
label109
label110
label111
label112
label113
label114
label115
Keyboard Sync 1.0
TypeScript_Keyboard_Sync.Properties.Resources
_0808LJZF96975D
_081Y6DZ515
_0947ZS0R1
_099KG915SIKN
_10G1UA6045MY
_10XKZ
_10YMWR
_11RR4DUJNP78NK9
_11VVZ
_13IKL7HZXKKNNKUDR7
_13LBL4RCBUIYIC5E623
_13OUSC7R
_14W7DMAMT5LU
_15ACC34PET
_15FYDK2HYF0J52ZB
_15PXS8Z50G8R9HAYP9
_160BD4HZFLX2C6VU
_16THB
_17333W
_18F9T5D7SW6PY
_207FR
_20A67
_20LSH1A1ZZLI2
_22HPDXNA
_23DDDUBXE
_254HI56
_25BAUDCXZS
_25PSAVH4F1
_26CP6QNANV1K1P2G
_26L0DLU2VY9
_28P318AFAW7CPX6KKS8
_28UQNUW77WT419
_2910LLZS
_312I9
_33CBLCZZFXA3001
_33WELC8A
_34YFVMCC
_362N0B10BOQF
_36PH9G0BW3XBML
_3762TYU89ILRDXSG
_37PT0PV3XB8PF
_39ACE1AD99NNE8BV
_42IH719QHWFCKV3O
_44YSU5ZIEBDC2YSMCYY
_4532CYPX6O43160Y5GM
_45P1QXU9LE2GZE2
_471TZ4X
_50BYBK
_50LLVN
_516WXIXCJ
_53TKGX8SF
_54PINBZY1K
_55DHCDD
_56IDAG
_56QP7X5LC
_57M5CP11BH2O8L
_57X5A1
_58E6KZ
_58K7TG
_59IT0A5VHI
_61TJV4RXSL577CL
_6318V8CDAA
_63C9061U3NM1AC4E
_668FLHY8FI75V
_66KSPVQIR
_66SG5NO
_67FB22ILAJAT9J
_67QWOUIC52PFVF0YMV
_68E0U6T6AYM9OO
_68P595P
_69JJ8
_70AA8ZBK
_70K2Y53NQFEQ
_72GK5P9AEBLIIH4S
_74MCDID8P3AOCNUROG
_74QK2OMZOPP755
_74X2CGLQ2U574L5FEQL
_766E86UTLI79M2
_76CPKUB6K1AT7O
_76LR475HBNGJ7H6
_76LW73R77YQZX15YKK
_76XBL3BRDQK16
_77EK57SNTQWHY
_781OG4U56D9KWWR5RD
_786RI0GM38F
_787FJ1EB
_78XG6WGASXAKCVWFAQ
_79Z9PLJWB08DY35DVU
_811XFYOSJV189AYJAXF
_81DKPLWBW7K5CRFZ
_833OQDKY5U9SBWQJ
_84GO4DY
_84NB61KZDTZ5G
_862ON2TRKKKOHAZY6V
_89KBAS87J5ZUH84N2W
_919RAS2CF0Z5
_924ATU
_92C4MHZ
_92TGCTFP8N308F
_949CIS2J34OC3TU3IIL
_9775J47V83O
_9808J
_9NFTILBBLY1K94LZL
_9NNGKQ5NMDEF5P
_9O61NLP79KLWW776P
_9PJ6HGGSZ3XDD
_9PSTF8
_9QEGE6YN629YCMTFY
_9RQLEH2L9JM
_9S70RFNA3PZZSQEZVJ
_9TBUSM58A
_9U4XHMM4
_9VYUEMWSGALCY5EKR
_9WI5PKPVZP02
_9WT7ARPHJS9OGW
_9Y77JJIRP
_9Y7ZKZT7LQK
_9ZHTL5T8KLSD
A1JEYFQV0OGI
A2293PI
A23W2ITDZ8X25MRETJ
A34R2EXZLGM44GXQ427
A3UXHQX39YBRCNA1I
A487F1
A5AH7LA
A7M0O95RDY7DPMJ9T
A7MB0LIZR6EU
A9B68HL24WXA6CM
A9XZ5I4RZ
AAZG3H
AC7DIV71
AC7EGT4V2WP9FFJ
AC7FKAIUH
ACQ18MLV5EKIYL
ADKLQI09WL13Y
ADYE26VBTAOLS7YUCV
AEL2K730J5FY8T
AF729MQR349UG1JWY
AH9IN4NUNR1LB60US
AIZUW15DJHV
AJRX5FGCEETL9F
AJSNPRDYF6B
AL3QZKX
AMWYPWK
AOORSRDYO3OQPNHD83
AOV7IQKO2
AP9EE8ANQEI1TU49KD
AQBPK3GSL
AQFEMYXCELOVC1
ATZRCKMMTN1OE
AX93S5
AXJT90VJEJ9ZDIAR
AXP9D6P4YWW87E8S1T
B0AOYPMUP
B0I79C94WOBFT
B287S4R3VJF986G2
B2S5ZZN6RQJZHLBACL
B34292
B3PA3D
B47TG3YA0OL5
B5VF3JR6DQ0K4J2P
B6CV1O0CRYYI
B765478F4LP4ZU28R
B8UEUVGLLI
BA40JAJEYX
BARCZ9374JC
BC9ZACQLQA1
BCSA255NRH0DO7K
BD1EU4RBAY
BD9D5ZU3RCA4L0MJ22
BDFLZX38L5JWWDKQUP
BDNR88W
BDOQYS75R9D9A1D
BEOWYHYOUR703TMT
BFHE5QD
BFMD6GJKD6H137XDNR
BIT76T
BJ9B9HIWD118KQAGBJ
BK81CNRW3W
BLU9BAL1E3UYI
BMDEVXR7AHO13K20M
BN3QF9WC2BMP8
BN54L9VZ
BOV2JP8F3E0EG
BP21I5VX4MOMWLC
BPTH9Y7G8S
BPWL2KD9YH7UB
BR10TPR409
BR2WN2M6WWX
BRC1ATSB81VRSI0U8
BRQH3FJNRIV7H
BSE1FYQ
BSLQN5B5AP
BVMX33D8NRT2L
BW9BJCIFR7EAYK9YOF
BWC9H5990
BWHFX6RB
BX1H1Q0MM7U2
BXMI6HE3IB198
BY88EYPZIZ7KSPVXR
BYBQ4NM4LJP9
BYRCR55ECZVR7
BZKUZ9CD72RA
C0SNHS02MZ9OR1
C1VALPVSDNYSF0OI
C22EI6
C2YBVAAUIWYI25
C47AFH6BXELGCLT492
C4CDT0
C4VU7G0O7KN40TEMS5D
C4WVM847G2
C7GBT8HYBL9
C7UIKU
C7X7NTQGWQZRIGQ
C8WP3ZW
C8XFH3FI7QT5FI
CA31NWT7E
CBBHSRAJCPBKW8TF
CBGQ5NOV8BMPM
CEN2QQ4R8VDXRY
CF8ST2K8B4Y2NODKTDR
CHC8C3VW4
CI98VYLJJ
CJHM7ETP
CKSTD7VZJCL2
CLJ7ITJSSXXOPB
CLWR1YGUTGKO4OT
CMI362BL1LN0SLV45EF
CN4O492MOBO855U06
CNDOFBKVASZB4N
COUSCGDWZOMT
CPZSLL70THJ
CT65RU1HRUD
CT7HOKSZG6VIAZ
CT9N9QOMU1CITGAW
CUAB6O7
CVHZ3OC
CW8Z7NIGCLIYM3D9
CX5F0B3Q69X9Y37DV
CXCHCHR3H
CXZT0COFB9A9
D0VV584V4X81JW
D0YXUKF66WKB3AST2B
D5LRPNS
D6G2NY1LCHE38KEUG
D92JZ9FGN1UX7Z602R
DA8REMA5QFR1IQNO
DAG0COA8STWQSS
DAVWP2GYGGT8CCJY
DDUKPJBQJR3
DDZX165H2R9C
DFRN59IUUFJ6UI
DFYK2HKOVAKEI2F9
DG2PUP242BOXAHE0
DGGHD04AV2ENU2K6VB0
DIQQAP6LKSH0S954
DJZTKD0GTXYX082L
DK6BZ7O
DKCH2G3DH4WETL
DKQEP9BGTP
DMIGOL104OK03
DMWFXVWIWZ
DMY3GVHB
DNTG0QHP2
DPQA3HF4JX
DRDQ6MQI2KLWALM
DS0UEB6F5I
DS3PFEW2X8P
DT808IDOO3N4L8
DUVS4W
DVKU5S3
DVTRZOH
DVY1HLUOXXT2I7GT12I
DY3AY87QX2O
DZLG4V7Z1UW4KFZ4U
E047SIJVXBW3W7UE
E13ILQU0NHP7L
E1D2V2LP6OCTYOFM
E2473IZYXUL7AQ6LA9P
E25G03M6
E2RUWXXINQKAYCS
E5OEBUMQ
E83UX4D
E9UH6DOCGP
EACXFQOY
EAGL6GU8E39Q
EB5EQDE4QXWL
EB8C31GIWPOMH1
EE2CKUFNZ
EEAY6Z7EZ
EGQRLY2ZP8VEQC
EGZ8E7MMQB2DNI
A1JEYFQV0OGI
A2293PIQ
A23W2ITDZ8X25MRETJ
A34R2EXZLGM44GXQ427
A3UXHQX39YBRCNA1I
A487F1
A5AH7LA
A7M0O95RDY7DPMJ9T
A7MB0LIZR6EU
A9B68HL24WXA6CM
A9XZ5I4RZ
AAZG3H
AC7DIV71
AC7EGT4V2WP9FFJ
AC7FKAIUH
ACQ18MLV5EKIYL
ADKLQI09WL13Y
ADYE26VBTAOLS7YUCV
AEL2K730J5FY8T
AF729MQR349UG1JWY
AH9IN4NUNR1LB60US
AIZUW15DJHV
AJRX5FGCEETL9F
AJSNPRDYF6B
AL3QZKX
AMWYPWK
AOORSRDYO3OQPNHD83
AOV7IQKO2
AP9EE8ANQEI1TU49KD
AQBPK3GSL
AQFEMYXCELOVC1
ATZRCKMMTN1OE
AX93S5
AXJT90VJEJ9ZDIAR
AXP9D6P4YWW87E8S1T
B0AOYPMUP
B0I79C94WOBFT
B287S4R3VJF986G2
B2S5ZZN6RQJZHLBACL
B34292
B3PA3D
B47TG3YA0OL5
B5VF3JR6DQ0K4J2P
B6CV1O0CRYYI
B765478F4LP4ZU28R
B8UEUVGLLI
BA40JAJEYX
BARCZ9374JC
BC9ZACQLQA1
BCSA255NRH0DO7K
BD1EU4RBAY
BD9D5ZU3RCA4L0MJ22
BDFLZX38L5JWWDKQUP
BDNR88W
BDOQYS75R9D9A1D
BEOWYHYOUR703TMT
BFHE5QD
BFMD6GJKD6H137XDNR
BIT76T
BJ9B9HIWD118KQAGBJ
BK81CNRW3W
BLU9BAL1E3UYI
BMDEVXR7AHO13K20M"
BN3QF9WC2BMP8
BN54L9VZ#
BOV2JP8F3E0EG
BP21I5VX4MOMWLC$
BPTH9Y7G8S
BPWL2KD9YH7UB
BR10TPR409
BR2WN2M6WWX&
BRC1ATSB81VRSI0U8
BRQH3FJNRIV7H'
BSE1FYQ'
BSLQN5B5AP(
BVMX33D8NRT2L(
BW9BJCIFR7EAYK9YOF
BWC9H5990)
BWHFX6RB)
BX1H1Q0MM7U2
BXMI6HE3IB198
BY88EYPZIZ7KSPVXR*
BYBQ4NM4LJP9
BYRCR55ECZVR7+
BZKUZ9CD72RA
C0SNHS02MZ9OR1,
C1VALPVSDNYSF0OI,
C22EI6,
C2YBVAAUIWYI25
C47AFH6BXELGCLT492-
C4CDT0-
C4VU7G0O7KN40TEMS5D
C4WVM847G2.
C7GBT8HYBL9.
C7UIKU
C7X7NTQGWQZRIGQ/
C8WP3ZW0
C8XFH3FI7QT5FI1
CA31NWT7E1
CBBHSRAJCPBKW8TF
CBGQ5NOV8BMPM2
CEN2QQ4R8VDXRY
CF8JZ3
CF8ST2K8B4Y2NODKTDR
CHC8C3VW44
CHP875
CI98VYLJJ5
CJHM7ETP
CKSTD7VZJCL26
CLJ7ITJSSXXOPB
CLWR1YGUTGKO4OT7
CMI362BL1LN0SLV45EF
CN4O492MOBO855U06
CNDOFBKVASZB4N8
COUSCGDWZOMT
CPZSLL70THJ9
CR3AR9
CT65RU1HRUD
CT7HOKSZG6VIAZ:
CT9N9QOMU1CITGAW:
CUAB6O7
CVHZ3OC;
CW8Z7NIGCLIYM3D9
CX5F0B3Q69X9Y37DV
CXCHCHR3H
CXZT0COFB9A9
D0NF5>
D0VV584V4X81JW?
D0YXUKF66WKB3AST2B
D5LRPNS@
D6G2NY1LCHE38KEUG@
D92JZ9FGN1UX7Z602R
DA8REMA5QFR1IQNO
DAG0COA8STWQSS
DAVWP2GYGGT8CCJY
DDUKPJBQJR3
DDZX165H2R9CC
DFRN59IUUFJ6UID
DFYK2HKOVAKEI2F9
DG2PUP242BOXAHE0E
DGGHD04AV2ENU2K6VB0
DIQQAP6LKSH0S954
DJZTKD0GTXYX082L
DK6BZ7O
DKCH2G3DH4WETLG
DKQEP9BGTPG
DMIGOL104OK03H
DMWFXVWIWZ
DMY3GVHB
DNTG0QHP2
DPQA3HF4JXJ
DRDQ6MQI2KLWALM
DS0UEB6F5I
DS3PFEW2X8PK
DT808IDOO3N4L8
DUVS4WL
DVKU5S3
DVTRZOH
DVY1HLUOXXT2I7GT12I
DY3AY87QX2OM
DZLG4V7Z1UW4KFZ4U
E047SIJVXBW3W7UE
E13ILQU0NHP7LO
E1D2V2LP6OCTYOFMO
E2473IZYXUL7AQ6LA9PP
E25G03M6
E2RUWXXINQKAYCS
E5OEBUMQ
E83UX4D
E9UH6DOCGPR
EACXFQOYS
EAGL6GU8E39QS
EB5EQDE4QXWL
EB8C31GIWPOMH1T
EE2CKUFNZT
EEAY6Z7EZ
EGQRLY2ZP8VEQC
EGZ8E7MMQB2DNIV
MXLWMV
_0808LJZF96975D
_081Y6DZ515
_0947ZS0R1
_099KG915SIKN
_10G1UA6045MY
_10XKZ
_10YMWR
_11RR4DUJNP78NK9
_11VVZ
_13IKL7HZXKKNNKUDR7
_13LBL4RCBUIYIC5E623
_13OUSC7R
_14W7DMAMT5LU
_15ACC34PET
_15FYDK2HYF0J52ZB
_15PXS8Z50G8R9HAYP9
_160BD4HZFLX2C6VU
_16THB
_17333W
_18F9T5D7SW6PY
_207FR
_20A67
_20LSH1A1ZZLI2
_22HPDXNA
_23DDDUBXE
_254HI56
_25BAUDCXZS
_25PSAVH4F1
_26CP6QNANV1K1P2G
_26L0DLU2VY9
_28P318AFAW7CPX6KKS8
_28UQNUW77WT419
_2910LLZS
_312I9
_33CBLCZZFXA3001
_33WELC8A
_34YFVMCC
_362N0B10BOQF
_36PH9G0BW3XBML
_3762TYU89ILRDXSG
_37PT0PV3XB8PF
_39ACE1AD99NNE8BV
_42IH719QHWFCKV3O
_44YSU5ZIEBDC2YSMCYY
_4532CYPX6O43160Y5GM
_45P1QXU9LE2GZE2
_471TZ4X
_50BYBK
_50LLVN
_516WXIXCJ
_53TKGX8SF
_54PINBZY1K
_55DHCDD
_56IDAG
_56QP7X5LC
_57M5CP11BH2O8L
_57X5A1
_58E6KZ
_58K7TG
_59IT0A5VHI
_61TJV4RXSL577CL
_6318V8CDAA
_63C9061U3NM1AC4E
_668FLHY8FI75V
_66KSPVQIR
_66SG5NO
_67FB22ILAJAT9J
_67QWOUIC52PFVF0YMV
_68E0U6T6AYM9OO
_68P595P
_69JJ8
_70AA8ZBK
_70K2Y53NQFEQ
_72GK5P9AEBLIIH4S
_74MCDID8P3AOCNUROG
_74QK2OMZOPP755
_74X2CGLQ2U574L5FEQL
_766E86UTLI79M2
_76CPKUB6K1AT7O
_76LR475HBNGJ7H6
_76LW73R77YQZX15YKK
_76XBL3BRDQK16
_77EK57SNTQWHY
_781OG4U56D9KWWR5RD
_786RI0GM38F
_787FJ1EB
_78XG6WGASXAKCVWFAQ
_79Z9PLJWB08DY35DVU
_811XFYOSJV189AYJAXF
_81DKPLWBW7K5CRFZ
_833OQDKY5U9SBWQJ
_84GO4DY
_84NB61KZDTZ5G
_862ON2TRKKKOHAZY6V
_89KBAS87J5ZUH84N2W
_919RAS2CF0Z5
_924ATU
_92C4MHZ
_92TGCTFP8N308F
_949CIS2J34OC3TU3IIL
_9775J47V83O
_9808J
_9NFTILBBLY1K94LZL
_9NNGKQ5NMDEF5P
_9O61NLP79KLWW776P
_9PJ6HGGSZ3XDD
_9PSTF8
_9QEGE6YN629YCMTFY
_9RQLEH2L9JM
_9S70RFNA3PZZSQEZVJ
_9TBUSM58A
_9U4XHMM4
_9VYUEMWSGALCY5EKR
_9WI5PKPVZP02
_9WT7ARPHJS9OGW
_9Y77JJIRP
_9Y7ZKZT7LQK
_9ZHTL5T8KLSD
asswords
VS_VERSION_INFO
StringFileInfo
040904B0
alid credential persistence.
Software\Microsoft\Windows\CurrentVersion\Internet
%s%c%s%c%s
Invalid handle to backup button
*Session
HTML Application Host Window Class
A:\userkey.psw
[\VLS]YYRX]\_^cjjmTs
32.dll
VS_VERSION_INFO
VarFileInfo
Translation
StringFileInfo
000004b0
Comments
TypeScript Keyboard Sync
CompanyName
TypeScript Keyboard Sync
FileDescription
TypeScript Keyboard Sync
FileVersion
1.0.8.0
InternalName
TypeScript Keyboard Sync.exe
LegalCopyright
Copyright
TypeScript Keyboard Sync 2017
LegalTrademarks
OriginalFilename
TypeScript Keyboard Sync.exe
ProductName
TypeScript Keyboard Sync
ProductVersion
1.0.8.0
Assembly Version
1.0.8.0

Process Tree


06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe, PID: 1332, Parent PID: 3012

default registry file network process services synchronisation iexplore office pdf

deskperf32.exe, PID: 2228, Parent PID: 1332

default registry file network process services synchronisation iexplore office pdf

cmd.exe, PID: 1988, Parent PID: 1332

default registry file network process services synchronisation iexplore office pdf

cmd.exe, PID: 1980, Parent PID: 1332

default registry file network process services synchronisation iexplore office pdf

timeout.exe, PID: 2124, Parent PID: 1980

default registry file network process services synchronisation iexplore office pdf

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255
dns.msftncsi.com

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 61714 8.8.8.8 53
192.168.56.101 56933 8.8.8.8 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 58485 114.114.114.114 53
192.168.56.101 58485 8.8.8.8 53
192.168.56.101 51758 224.0.0.252 5355

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 40a59ca9744dc3d4_deskperf32.exe.config
Filepath C:\Users\Administrator\AppData\Local\_foldernamelocalappdata_\deskperf32.exe.config
Size 1.3KB
Processes 1332 (06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe)
Type XML 1.0 document, ASCII text, with CRLF line terminators
MD5 dd3d04c365984b4ec57a80503f81fddf
SHA1 c55fbcb61818e47dac9aae465faff91f0805bd7c
SHA256 40a59ca9744dc3d4647f246b2dc553f37f8095418c1b48a9bd94cdb5c03dbc5c
CRC32 52B9376B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 06f09703617ae00c_06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe
Filepath C:\Users\Administrator\AppData\Local\Temp\06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe
Size 220.6KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 1be88c5d1ddd77858ed51ef14186d5db
SHA1 2dc4edf18758b79fa871ac2b35062fb06c19211f
SHA256 06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811
CRC32 2F4E29AE
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b703d8890b0b3fc6_deskperf32.exe
Filepath C:\Users\Administrator\AppData\Local\_foldernamelocalappdata_\deskperf32.exe
Size 220.6KB
Processes 1332 (06f09703617ae00c2554d3936bf4369a15e71bdc2136bda907dd4a85742de811.exe)
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 e2cf543518b935f6813b5db6d0fc2bf6
SHA1 12315bca510cd90a9527bc2ee4059f9bc27bc48c
SHA256 b703d8890b0b3fc6c0771d9ceb817ec2c31a4e8f7cb5ef5006d829d09aac39fc
CRC32 D7ECE42B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 47e0d8ff23b166cdbf2d460b8ed146d4665e2150
Size 108.0KB
Type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5 9c3b407230b8a6f2b356ff22a704a0f8
SHA1 47e0d8ff23b166cdbf2d460b8ed146d4665e2150
SHA256 7c2120cb275a49f477f83d355b1cfa1c288fedf9fdf45c9769358ee90fef3212
CRC32 808F79B3
ssdeep None
Yara None matched
VirusTotal Search for analysis