3.6
中危

0b5122cd78d435533e1ceb318c61088db904b4c48e8b6d2f192d2164ce518cd1

0b5122cd78d435533e1ceb318c61088db904b4c48e8b6d2f192d2164ce518cd1.exe

分析耗时

134s

最近分析

375天前

文件大小

240.5KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN RANSOM GANDCRAB
鹰眼引擎
DACN 0.14
FACILE 1.00
IMCLNet 0.80
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Malware-gen 20200224 18.4.3895.0
Baidu None 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20200224 2013.8.14.323
McAfee Trojan-FPQB!2E4F4F6F3161 20200224 6.0.6.653
Tencent Malware.Win32.Gencirc.10b1962d 20200224 1.0.0.1
静态指标
查询计算机名称 (1 个事件)
Time & API Arguments Status Return Repeated
1727545342.8905
GetComputerNameW
computer_name: TU-PC
success 1 0
检查进程是否被调试器调试 (1 个事件)
Time & API Arguments Status Return Repeated
1727545338.8595
IsDebuggerPresent
failed 0 0
使用Windows API生成加密密钥 (3 个事件)
Time & API Arguments Status Return Repeated
1727545342.8755
CryptGenKey
provider_handle: 0x00cdc3f0
algorithm_identifier: 0x0000a400 (CALG_RSA_KEYX)
flags: 134217729
crypto_handle: 0x00ce0020
success 1 0
1727545342.8755
CryptExportKey
crypto_handle: 0x00ce0020
crypto_export_handle: 0x00000000
blob_type: 6
flags: 0
buffer: ¤RSA1k% 41ÚÇ}Ï.)OÚÛO1?_F‚žàŸñý4˜B.ªi-¯%L¾Ò#=á_« Œ‰½`ÁZp* £÷zô£%Sú™ŠR–3E°Û €~Ä9ô±kƒ+g}½Õ=0`˜U_/a¥Sˆ6m±„¦¹Aµê¼¦_ø0’«_²<ÍáW=ƒ—N§† 7É`“:pCš’öu%íº¥¦?Âf‰Üø-àù4Qþp‰@æ3W0:8íóæ™d<ҁwáŽu _̬ÛiP ½€uæ¶4çž(O)Áс‹ŽÌd“(XQãi+ßJtmÌåϹ·e+Èb1ÿT¶§
success 1 0
1727545342.8755
CryptExportKey
crypto_handle: 0x00ce0020
crypto_export_handle: 0x00000000
blob_type: 7
flags: 0
buffer: ¤RSA2k% 41ÚÇ}Ï.)OÚÛO1?_F‚žàŸñý4˜B.ªi-¯%L¾Ò#=á_« Œ‰½`ÁZp* £÷zô£%Sú™ŠR–3E°Û €~Ä9ô±kƒ+g}½Õ=0`˜U_/a¥Sˆ6m±„¦¹Aµê¼¦_ø0’«_²<ÍáW=ƒ—N§† 7É`“:pCš’öu%íº¥¦?Âf‰Üø-àù4Qþp‰@æ3W0:8íóæ™d<ҁwáŽu _̬ÛiP ½€uæ¶4çž(O)Áс‹ŽÌd“(XQãi+ßJtmÌåϹ·e+Èb1ÿT¶§5Ró'/Ýíö»ÑА”G¸,– ,ju`¿³@””P(uó}2…5¨$€[WՎÙÛ]¦9C™á9oûC¾Ã»U‰vی4`¸Îµº_aµW®4íew0´ ˄ñ‘…ÇÒ_#Úd@8‚sü"ªڝ.ýáüìl5ÍXύó-Ь°}œ"ð‰&gN5FR}L¶„×fÛ°mM¼5i׸9;Î2|ž`µ˜ß¥ù1—$™hÒ@À²AbJ%°¸ûF[B{viß’`j´òn©ñ+ï»Þø\Ձ:™–vž7«MŠ·qˆiü·‡=mÒ/<"}°¯|!³ÏwO{ëû³÷Ý")P¬æ‡“DÆþ3üžHCWï#ѬPƒƒÇ1ˆyN½Îëz -9Ï@=AL „ †©ŸpÚOIŸßó<íWÉÁ8†ˆ5°HÚ}ç Àa3‹ìAªvh‘ k‚{ã°Þ<Ðk8ÕR¥!ð—Ú»DcÃk¼Éª†©’z.lûÀmê…fAKP­mr7‚Ý9ïœÅÑ+Ü$„ùþööØ-z]Í,OІ½øH;µ­xéHìh&ïdfÔ0Ì/ ç…óc^íËÂß;‰d}®kÀÿ#Ý§|%ÅÆv{G\?þó„’`€« 4,;­xúm°RºWßóŒZ,œ½ümFMT5Køà¯âÌ»iêBUR)ßìÁ19ûÑp¦¨`˜^Œ& ï$ Øë~™ÀXzröX—yþ6Jø‡‹ãñ$jʙ¼Uê¨xËÁ”EháÄöh–Y¤Äq‹à£M¢§;Öð¾WWâû<#1~z(eËOÇê—f¼a*e-ñ‚câÕ>K<Ìi4%žX¢¿\ö™Ó„Þ½",FD}¦Ðç@2cMӞ#ñB`,J†„Qòÿ ¡êÕt4~ðCX®À}w ©…ê² =™³µâh ²ˆ×/ L“=ŸL¦·‰£kÈ©‘í'Ï?©·ñQK"Šß÷G‚}éΖm^µñJ­aÔ'`w³X 8©ô)ûmѪ#t;¡ÃÓU˜!N|ƒé—?99:„ Èê“ûævª.ç™Y΢M<Š|ú~—ðÙ%ÜÈÈ’R”­Jë”D¾¬ñKð\Šq¡7Ûÿ£ðÓÏI>é0æ€
success 1 0
检查系统中的内存量,这可以用于检测可用内存较少的虚拟机 (10 个事件)
Time & API Arguments Status Return Repeated
1727545334.8595
GlobalMemoryStatusEx
success 1 0
1727545346.078375
GlobalMemoryStatusEx
success 1 0
1727545357.4065
GlobalMemoryStatusEx
success 1 0
1727545370.68775
GlobalMemoryStatusEx
success 1 0
1727545382.015875
GlobalMemoryStatusEx
success 1 0
1727545393.31275
GlobalMemoryStatusEx
success 1 0
1727545404.609625
GlobalMemoryStatusEx
success 1 0
1727545415.9215
GlobalMemoryStatusEx
success 1 0
1727545427.203375
GlobalMemoryStatusEx
success 1 0
1727545438.50025
GlobalMemoryStatusEx
success 1 0
文件包含未知的 PE 资源名称,可能指示打包器 (3 个事件)
resource name AFX_DIALOG_LAYOUT
resource name LLXDGSTA
resource name YEMIBATIYUPIHALO
行为判定
动态指标
分配可读-可写-可执行内存(通常用于自解压) (20 个事件)
Time & API Arguments Status Return Repeated
1727545334.8285
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00cbd000
length: 110592
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545338.6255
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00400000
length: 180224
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545340.3285
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00414000
length: 81920
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545340.3285
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x024b0000
region_size: 94208
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545340.3595
NtProtectVirtualMemory
process_handle: 0xffffffff
base_address: 0x00414000
length: 81920
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.3595
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00070000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.3595
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x000b0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.5155
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00100000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.5315
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00130000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.6255
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00160000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.6405
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x00160000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.6405
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x000d0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545341.6405
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x000e0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545342.9065
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x029f0000
region_size: 12288
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545342.9065
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x03660000
region_size: 12288
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545345.7035
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x04430000
region_size: 98304
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545345.7035
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x029a0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545345.7035
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x029f0000
region_size: 4096
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545345.7035
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x029f0000
region_size: 36864
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
1727545345.7035
NtAllocateVirtualMemory
process_handle: 0xffffffff
base_address: 0x04450000
region_size: 8192
allocation_type: 12288 (MEM_COMMIT|MEM_RESERVE)
protection: 64 (PAGE_EXECUTE_READWRITE)
process_identifier: 1932
success 0 0
查询磁盘大小,可用于检测具有小固定大小或动态分配的虚拟机 (1 个事件)
Time & API Arguments Status Return Repeated
1727545342.8905
GetDiskFreeSpaceW
root_path: C:\
sectors_per_cluster: 8
bytes_per_sector: 512
number_of_free_clusters: 1782563
total_number_of_clusters: 8362495
success 1 0
在文件系统上创建可执行文件 (1 个事件)
file C:\Users\Administrator\AppData\Roaming\Microsoft\itqewa.exe
将可执行文件投放到用户的 AppData 文件夹 (1 个事件)
file C:\Users\Administrator\AppData\Roaming\Microsoft\itqewa.exe
搜索运行中的进程,可能用于识别沙箱规避、代码注入或内存转储的进程 (1 个事件)
检查适配器地址以检测虚拟网络接口 (3 个事件)
Time & API Arguments Status Return Repeated
1727545343.0785
GetAdaptersAddresses
family: 0
flags: 0
failed 111 0
1727545343.0785
GetAdaptersAddresses
family: 0
flags: 0
success 0 0
1727545369.4685
GetAdaptersAddresses
family: 0
flags: 1158
success 0 0
该二进制文件可能包含加密或压缩数据,表明使用了打包工具 (2 个事件)
section {'name': '.rsrc', 'virtual_address': '0x00727000', 'virtual_size': '0x00021f60', 'size_of_data': '0x00022000', 'entropy': 7.891917024875863} entropy 7.891917024875863 description 发现高熵的节
entropy 0.5678496868475992 description 此PE文件的整体熵值较高
使用 Windows 工具进行基本 Windows 功能 (4 个事件)
cmdline nslookup carder.bit ns2.wowservers.ru
cmdline nslookup ransomware.bit ns2.wowservers.ru
cmdline nslookup ransomware.bit ns1.wowservers.ru
cmdline nslookup carder.bit ns1.wowservers.ru
网络通信
与未执行 DNS 查询的主机进行通信 (3 个事件)
host 114.114.114.114
host 8.8.8.8
host 203.208.41.98
在 Windows 启动时自我安装以实现自动运行 (2 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce\exrkavpqywq reg_value "C:\Users\Administrator\AppData\Roaming\Microsoft\itqewa.exe"
file C:\Windows\win.ini
使用 NtSetContextThread 修改远程进程中的线程,表明进程注入的迹象 (50 out of 6334 个事件)
进程注入 进程 1932 调用了 NtSetContextThread 修改远程进程 0 中的线程
Time & API Arguments Status Return Repeated
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4375
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4535
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4685
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4685
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4685
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
1727545330.4685
NtSetContextThread
thread_handle: 0x00000000
process_identifier: 0
failed 3221225480 0
文件已被 VirusTotal 上 62 个反病毒引擎识别为恶意 (50 out of 62 个事件)
ALYac Trojan.Ransom.GandCrab.Gen.2
APEX Malicious
AVG Win32:Malware-gen
Acronis suspicious
Ad-Aware Trojan.Ransom.GandCrab.Gen.2
AhnLab-V3 Win-Trojan/Gandcrab.Exp
Antiy-AVL Trojan/Win32.TSGeneric
Arcabit Trojan.Ransom.GandCrab.Gen.2
Avast Win32:Malware-gen
Avira HEUR/AGEN.1031185
BitDefender Trojan.Ransom.GandCrab.Gen.2
BitDefenderTheta Gen:NN.ZexaF.34090.pu1@aqMdKNki
Bkav W32.AIDetectVM.malware
CAT-QuickHeal Trojan.Mauvaise.SL1
ClamAV Win.Dropper.Gandcrab-6535271-0
Comodo TrojWare.Win32.Chapak.GB@7n77xn
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.f3161c
Cylance Unsafe
Cyren W32/S-2dbfb35e!Eldorado
DrWeb Trojan.Encoder.24384
ESET-NOD32 Win32/Filecoder.GandCrab.B
Emsisoft Trojan.Ransom.GandCrab.Gen.2 (B)
Endgame malicious (high confidence)
F-Prot W32/S-2dbfb35e!Eldorado
F-Secure Heuristic.HEUR/AGEN.1031185
FireEye Generic.mg.2e4f4f6f3161cec3
Fortinet W32/GenKryptik.DQHN!tr
GData Trojan.Ransom.GandCrab.Gen.2
Ikarus Trojan-Ransom.GandCrab
Invincea heuristic
Jiangmin Trojan.GandCrypt.ce
K7AntiVirus Trojan ( 0053305e1 )
K7GW Trojan ( 0053305e1 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=84)
Malwarebytes Trojan.MalPack.Generic
MaxSecure Ransomeware.CRAB.gen
McAfee Trojan-FPQB!2E4F4F6F3161
McAfee-GW-Edition BehavesLike.Win32.Generic.dc
MicroWorld-eScan Trojan.Ransom.GandCrab.Gen.2
Microsoft Trojan:Win32/Gandcrab.AF
NANO-Antivirus Trojan.Win32.GandCrypt.fbmyki
Qihoo-360 HEUR/QVM10.1.74B5.Malware.Gen
Rising Trojan.Kryptik!1.B229 (RDMK:cmRtazpeH+PESFbuhAg/afY+4iNK)
SUPERAntiSpyware Trojan.Agent/Gen-Malagent
Sangfor Malware
SentinelOne DFI - Malicious PE
Sophos Mal/Agent-AUL
Symantec Packed.Generic.525
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

2018-05-09 04:50:28

PE Imphash

f4ef78ca06a93850221a12de008a09e5

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x000104d2 0x00010600 6.689807503110501
.rdata 0x00012000 0x000067d0 0x00006800 4.746093179166156
.data 0x00019000 0x0070d980 0x00001c00 2.8986497534783875
.rsrc 0x00727000 0x00021f60 0x00022000 7.891917024875863
.reloc 0x00749000 0x00001338 0x00001400 6.455346460549953

Resources

Name Offset Size Language Sub-language File type
AFX_DIALOG_LAYOUT 0x00727770 0x00000002 LANG_ENGLISH SUBLANG_ENGLISH_US None
LLXDGSTA 0x00727774 0x0001a85c LANG_NEUTRAL SUBLANG_NEUTRAL None
YEMIBATIYUPIHALO 0x00741fd0 0x00000144 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_CURSOR 0x00742114 0x00000134 LANG_ENGLISH SUBLANG_ENGLISH_UK None
RT_BITMAP 0x00742248 0x00003928 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_ICON 0x00745b70 0x000025a8 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_DIALOG 0x00748118 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_STRING 0x00748d08 0x0000004e LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_CURSOR 0x00748d58 0x00000014 LANG_ENGLISH SUBLANG_ENGLISH_UK None
RT_GROUP_ICON 0x00748d6c 0x00000014 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_VERSION 0x00748d80 0x000001e0 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library KERNEL32.dll:
0x412000 GlobalAlloc
0x412004 VirtualProtect
0x412008 GetLastError
0x41200c SetThreadContext
0x412010 FlushFileBuffers
0x412014 SetFileShortNameW
0x412018 GetTickCount
0x41201c CreateMailslotA
0x412020 GetMailslotInfo
0x412024 FlushViewOfFile
0x412028 UnmapViewOfFile
0x41202c GetModuleFileNameA
0x412030 GetModuleHandleW
0x41203c SetConsoleMode
0x412040 GetConsoleCP
0x412044 SetConsoleCP
0x412048 GetConsoleOutputCP
0x41204c WriteConsoleW
0x412050 CloseHandle
0x412054 EncodePointer
0x412058 DecodePointer
0x41205c RaiseException
0x412060 RtlUnwind
0x412064 GetCommandLineW
0x41206c HeapAlloc
0x412070 HeapFree
0x412074 ExitProcess
0x412078 GetModuleHandleExW
0x41207c GetProcAddress
0x412080 AreFileApisANSI
0x412084 MultiByteToWideChar
0x412088 WideCharToMultiByte
0x41208c HeapSize
0x412090 IsDebuggerPresent
0x41209c GetStdHandle
0x4120a0 GetFileType
0x4120a8 GetStartupInfoW
0x4120ac SetLastError
0x4120b0 GetCurrentThreadId
0x4120b4 GetProcessHeap
0x4120b8 GetModuleFileNameW
0x4120bc WriteFile
0x4120c4 GetCurrentProcessId
0x4120e0 Sleep
0x4120e4 GetCurrentProcess
0x4120e8 TerminateProcess
0x4120ec TlsAlloc
0x4120f0 TlsGetValue
0x4120f4 TlsSetValue
0x4120f8 TlsFree
0x4120fc LCMapStringW
0x412100 LoadLibraryExW
0x412104 IsValidCodePage
0x412108 GetACP
0x41210c GetOEMCP
0x412110 GetCPInfo
0x412114 HeapReAlloc
0x412118 ReadFile
0x41211c GetConsoleMode
0x412120 ReadConsoleW
0x412124 OutputDebugStringW
0x412128 GetStringTypeW
0x41212c SetStdHandle
0x412130 SetFilePointerEx
0x412134 CreateFileW
0x412138 SetEndOfFile
Library USER32.dll:
0x412140 GetMenuStringA

L!This
m cannot be run in DOS mode.
+O+O+OyWO+OyhO+OyiO+OS
O+O+O+ORiO+OySO+ORVO+ORich+O
`.rdata
@.data
@.reloc
u-WWWh"A
EPEPEPEPW
0F;51C
EPu51C
_^][UQ
]U4SVW
_^[]VWL$
;rr+9|$
SVADW|$
@u+UQu
UQSV5X A
3_^[]Uu
H]WVt$
on0v00f
on0v00f
on0v00f
DDDDDDDDDDDDDD
YYU VWj
^]UQSE
k 3@[]U
E[]UQQE
MuWx3U
UQQSVWd5
^]UV*>
u3@]3]U
SVWE3PPPuu
E_^[E]WVt$
on0v00f
on0v00f
on0v00f
DDDDDDDDDDDDDD
tAt2t$
3PeuEEd
woSWH;
3^]U59
3@]3]UE
^]UQS3V9]
3C3PPju
YtuPju
Y3@^[]UQEPh1A
YYuCh@
C;r_^[]UVu
]UVW3j
_^]USVW=$:
Yu#tVU
u_^[]UVW3u
YYu*9E
_^]UVW3u
1E3PeuEEEEd
Y__^[]QU
8csmu(=2A
2yE_^[]
EMEineIE5ntel5PA
E5Genu
MMtCE%?
_^3[]U(
0ffffffE
YM3_]UE
3PPPPP
Yt$VWu
t'@-rA
]jdh{A
]j@j _WaYY
Y8Y4@M
} j@WYY
2t[;tW
Y8Y4@MFu
EtLtHP
Y]};=dY
4WYY`Y
uPj8}Y
YUQQS3!U3Vu
<at-<rt"<wt
7u-B*u B
_^[]SVWT$
URPQQhJ@
t;T$4t
;v.4v\
UVWS33333[_^]
33333USVWj
_^[]Ul$
&3@_^]US]
@VurPuY
YtJNddlVP
D@[Zzj{$G
Ytm<@k
t*t|FtIt
2<itx<o
\nt[ct&{t!ldP
+u*pJltG>
YttjItt]LD
,P|FPLP(PVI
,P|FPLP(PV
ntItt`LD
,P|FPLP(PVN
e,P|FPLP(PV
`Y-u9L
,P|FPLP(PVp
+u0tItu
ntItt`LD
,P|FPLP(PV
YYuOpdt
kQHP5A
HypyGs
p<Ipdt
Yt%pl@pdbY!
G<-u_t[
]tTGH:s
Y`hNpdt
YY\j0[`,
Fp)pHpdt
+u8Jtu
-lFpdY`\x$
xtgptb
T8\Y8`DC
ttflFpdY\
`\Npdt
xt?pt:
tt`lFpd^Y\
`>\Npdt
GlFpdm
G`Y;uf
Yt lCY
G;u(pdu
ap^M_3[]USVu
8_]UQQM
3GW3Au
EmIuEt
E]UQ}M
E]UQQM
vHY~\2A
~lt#WM
YYt3V5
~pjCXf
YYt-V5
VW_^]M
eEUn@|t
tr8csmujx
EPYYE@
>csmuH~
8csmu9x
]3]U<E
>csmu+~
YYuD}9
EPEPuu W
u*EUHM
u$u uuuWu
SV,UEMA
u3u$u uWu
P;u$vjWu
\UQQW}
t1?MOCt)?RCCt!u$u Su
;F|c;F
u$Nu Qj
M;r^[_]UQQSVu
;>|_^[]UM
HtHu4j
8RCCt!8MOCt
8csmu*
RM 3@_^[]UVu
t3@_^]
u2t&:a
et_EtZfu
]U,SVWj0Xu
uy3;uu;t
]u'j0XF
EfyfxW
v6j0F[
Wj0XPV~
PjdSQE
ap_^[]Uj
MSWu ]
-jd[;|
Map_[]WWWWWlU,A
^VQMQp
M_^3[]U
Map^[]U,A
[SQMQp
^M_3[R]U0A
[SQMQp
E3H}-E
^M_3[S]Uj
uVJ:0t
E`p]Uj
Fu^8Et
E`p]UE
3@]3]UW}
^VVVVV
8csmu%x
S^`F`y
j$_F\d
UQQSVWh
3S3fX=
EPEPWWVc
Yt)EPEP
_^[]UQQE
tj"Xf9
j"_f9y
t"f;Et
j=YfuG
YYtAVSP;
3PPPPP
Yu=`=
@Y<v5h=
[M_3^n]SSSSS
ME3M3M3;u
_^]VWyA
;r_^VWyA
;r_^UQW
tGS3Vf9t
^[_]UH
3@]UQV5
]VWh=A
fu^UVu
]j$hH~A
Y+t"+t
+t^+uHN}
u?GdEGd
u wdVUY
Gd3HUU
P^Y]USVW3
_^[]U}
]3]U0I
jA[jZZ+U
_+[^]UVu
|3_@^UE
3SVWH<
B(;r3_^[]Ujh~A
1E3PEd
Y_^[]UE
Map]US]
AJu_^[]U
A;rM_^3[']j
-Yuwhu;5\A
Eph33Su
Q`YEXh3@
C9]vO}
kE0EpA
OuVIY3_M^3[]U}
?Y3MS0u
[_^]UVu
WjY3M}u;u
^V/EYu
'E;s(j
Xf9Etj
K_^[]U
^u;5dY
3^]USVu
t9W>+~
NY!}3]
PYtG}
Map^]Uj
]USVWUj
P(RP$R
t:|$,t
;t$,v-4v
UQPXY]Y[
A_^[]USVu
t_FxtX9
uVqY_^[]UU
1N_^[]j
Npt"~l
t4V0;t(W8Yt
E`p]U=H
YY]U=H
YY]U=H
Map]Uj
3^[]Wu
PLYYt@}
~';_t|%39E
;_tr.~
Map_4Uj
MPQRj/
t*f u!f t
ZmZ,$Z
;s`Myt
Et%Map
Map_[]U=H
YY]UW=(:
#3+#I#[
Sr@PSV#\
3[_^]U,A
E3PWWWWVEPEP6
apM_^3[s]U(A
3E3PSSSSVEPEP
MapM_^3[
_^[]U0A
3^[q]3PPPPPD}WVU33D$
YY3^]j
^0{^]W+
Ju3_uf
H]UVW}
^0"{_^]
^0z^]SWu
ft%Ou +
3jPfTAX3f
T}j"U$A
}VE95H
;tO9=H
MEt/t+
3M_^3[l]QL$
E$39E(j
3tAEWVPSu
t!3PP9E u
e_^[M3|j]U
M!u(Eu$u u
Map]UQA
W39E Wu
e_^[M3>i]U
Map]UM
C'j@j lYY
]UQQVu
EU_^]UVu
t9VV8>
trWzYuE
V38W30@9u
PYtD0,+
,3@@QQj
8Q$PEP(
Y4f;uu
Y4f;uOFD@,;U
<+0;sD
r3VVhU
QH++PPVh
= 3GW;hY<0($
+[M_3^KY]U
]U8S3E
+tHHt*Ht#f
ZU+t6+t)+t +t
^_[]uE
uMVPuQu
tSSS7#
uJSSR7I#
MQPvM
Map_^[
PPYF ;
PPYF$;
PPYF8;
PPYF<;
PPYF@;
PPYFD;
PyPYFH;
PgPYFL;
PUPY^]UVu
POY^]UVu
O6Ov Ov$Ov(Ov,Ov0|Ov4tOv
lOv8dOv<\O@v@QOvDIOvHAOvL9OvP1OvT)OvX!Ov\
OvlNvpNvtNvxNv|N@
EPQEPEj
Map[]j
Ht+Ht$Ht
HtHHt
PQW|PEP0v
yYM_3^H][VD$
IA+3@u
DJx.t'D
<+3M9]t
j EX+j
MTCE;|
IAjX+E3M@D
OGD+3G
};Ej_r
3ADJx(t!D
UTMEE@E;|
IAMj X+]
IAj ]X+
Iy}jX+
7M_^3[B]UDA
IA+3@u
DJx.t'D
<+3M9]t
j EX+j
MTCE;|
IAjX+E3M@D
OGD+3G
};Ej_r
3ADJx(t!D
UTMEE@E;|
IAMj X+]
IAj ]X+
Iy}jX+
7M_^3[c=]U
E3S3@VE
]W}]]]]]9E$u
+tHHt
X]3@EA<
+t+-t&0tC
3@E0|*Eu9
B0}uEE$
kE3@EEEu
HB0tEE0|%u9
B0}uE+
+t"HHt
v09] t"BE
mH3@E9
B0}JEM
HAO8tMMQPEP2
U_E}}~Xu
Uf~;x2E
f;r3]f9E]
Mfu 3f9E
M_^3[5]
A#EE?UEWft
;u%u!huA
u]]]]}
U^|uu~ru
uEf~;x2E
E}B}Ut
M]Euuj
u@Eu4E]u fE
f;s fE
}fEEEuMUf}!3f9E
UX~X}E
[f~[fM
fMU<f@fE
f;s fE
}fEEEuUuf}
u]Ou}]Uuj
UuuE@E~
AEHME~
EE>u}A
0I;s;s
3@M_^3[-,]
3SSSSS7UM
YEm}E3
_^[]UM
-2-UVW}
WYtP8:
3_^]UVu
3]USVu
]UWVSM
J31 }A
Xoti wiro zacoyemibati yupihalo
Dikicisupizi pikarebe givinenasabu
generic
unknown error
iostream
iostream stream error
system
string too long
invalid string position
bad allocation
permission denied
file exists
no such device
filename too long
device or resource busy
io error
directory not empty
invalid argument
no space on device
no such file or directory
function not supported
no lock available
not enough memory
resource unavailable try again
cross device link
operation canceled
too many files open
permission_denied
address_in_use
address_not_available
address_family_not_supported
connection_already_in_progress
bad_file_descriptor
connection_aborted
connection_refused
connection_reset
destination_address_required
bad_address
host_unreachable
operation_in_progress
interrupted
invalid_argument
already_connected
too_many_files_open
message_size
filename_too_long
network_down
network_reset
network_unreachable
no_buffer_space
no_protocol_option
not_connected
not_a_socket
operation_not_supported
protocol_not_supported
wrong_protocol_type
timed_out
operation_would_block
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
destination address required
executable format error
file too large
host unreachable
identifier removed
illegal byte sequence
inappropriate io control operation
invalid seek
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no message available
no message
no protocol option
no stream resources
no such device or address
no such process
not a directory
not a socket
not a stream
not connected
not supported
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
protocol error
protocol not supported
read only file system
resource deadlock would occur
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many links
too many symbolic link levels
value too large
wrong protocol type
Unknown exception
CorExitProcess
UTF-16LE
UNICODE
_hypot
_nextafter
bad exception
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
CreateEventExW
CreateSemaphoreExW
SetThreadStackGuarantee
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
GetLogicalProcessorInformation
CreateSymbolicLinkW
SetDefaultDllDirectories
EnumSystemLocalesEx
CompareStringEx
GetDateFormatEx
GetLocaleInfoEx
GetTimeFormatEx
GetUserDefaultLocaleName
IsValidLocaleName
LCMapStringEx
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleExW
SetFileInformationByHandleW
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
new[]
delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
Type Descriptor'
Base Class Descriptor at (
Base Class Array'
Class Hierarchy Descriptor'
Complete Object Locator'
MessageBoxW
GetActiveWindow
GetLastActivePopup
GetUserObjectInformationW
GetProcessWindowStation
CreateFile2
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
1#SNAN
1#QNAN
GlobalAlloc
VirtualProtect
GetLastError
SetThreadContext
FlushFileBuffers
SetFileShortNameW
GetTickCount
CreateMailslotA
GetMailslotInfo
FlushViewOfFile
UnmapViewOfFile
GetModuleFileNameA
GetModuleHandleW
WriteProfileSectionW
SetDefaultCommConfigA
SetConsoleMode
GetConsoleCP
SetConsoleCP
GetConsoleOutputCP
KERNEL32.dll
GetMenuStringA
USER32.dll
EncodePointer
DecodePointer
RaiseException
RtlUnwind
GetCommandLineW
IsProcessorFeaturePresent
HeapAlloc
HeapFree
ExitProcess
GetModuleHandleExW
GetProcAddress
AreFileApisANSI
MultiByteToWideChar
WideCharToMultiByte
HeapSize
IsDebuggerPresent
EnterCriticalSection
LeaveCriticalSection
GetStdHandle
GetFileType
DeleteCriticalSection
GetStartupInfoW
SetLastError
GetCurrentThreadId
GetProcessHeap
GetModuleFileNameW
WriteFile
QueryPerformanceCounter
GetCurrentProcessId
GetSystemTimeAsFileTime
GetEnvironmentStringsW
FreeEnvironmentStringsW
UnhandledExceptionFilter
SetUnhandledExceptionFilter
InitializeCriticalSectionAndSpinCount
GetCurrentProcess
TerminateProcess
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
LCMapStringW
LoadLibraryExW
IsValidCodePage
GetACP
GetOEMCP
GetCPInfo
HeapReAlloc
ReadFile
GetConsoleMode
ReadConsoleW
OutputDebugStringW
GetStringTypeW
SetStdHandle
SetFilePointerEx
CreateFileW
CloseHandle
WriteConsoleW
SetEndOfFile
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
Ix@oGAkU'9p|B
~QCv)/&D(
uuvHMXB
9;5SM]=];Z] T7aZ%]g']
?Zd;On
7?3=Bz
;1az?aUY~S|
D?$?9'
*?}d|FU>c{
zc%C1<!8G
u7.:3q
#2IZ9W
,%I-64OSk%Y
.?AVerror_category@std@@
.?AV_Generic_error_category@std@@
.?AV_Iostream_error_category@std@@
.?AV_System_error_category@std@@
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_exception@std@@
/EU*.g
3.m=^Hq
:Bp|?kSPgk
rcl}}*7M
Kj7}KfN?;}<KL6{_
~FTPtJ
mOh3t=B3J&j~
;JJc9|
4"d+^~a
6^o)S]V2JZm
|iwUey
nMREp=
#%eNk
n"OEPh
V0Ht4M""
wwYJ$@IX
&2NW=a
<4fnP*%I
usq9G@
>A0<$b#pP7&
q){d_KAc7/F
8JW>@CzS2
o"d}P!=
:W Oqh/
;hc$T?@?\
[OY'8w
Vq <Hj<
+1P[g|&kC
NVKfE<R(
vLsN5"~[$
=:_QT9r
)o'YS)
jI)rgDF
^'I594
D\`z"?'P
R~@C$Qes?
[\${E%^=6/ht
S IiXmL
n^mAC6
U7zY"u8
rGWtm>$
y #Gts>[nyg
Gf#jg]%7g
i cHfRpQR
w|s>vV
nt@%{g'n
712ve])
W#mb4,L
@WAfXTA|
uk?u%
I66^@Y`oX
|l&fV/A,
W72zhyrH
AXb:"t
2x+.{GTa>
6)Vs*qqIG
h9s8I}T=`GbA=wP
"$o>R$4Ert
pk$&FU0
XG[)(#,
r\B~Xa
gyOQp"wd
'2kP*^X
'=@ZRE
n|y0dAyzQ9g*<QRMY"
a!hNOi
{JTq9
:8<iaU
ykk%</z6
{,TN5U
{,ckBL
ef*4[IP
b8*2rM\J>C!\
}R~u*@,u
Vu R2<
|UH1g4Wov9
}]%{:,nb?i,[_lN? <
itBmM|z
^fYyOO
T6<>[,!O8A
n)LOGMURC
oPqy%i}
[J)6I!L
Y^wZ[QIgY
[KHY,(w~
v|C5{Mg3!
R`Bf9@
FD/0M&)UiFZXzw
#?Xsz(Fpu`7,H
Gg!HorW
T2&z^&
r&lwf.B25=ov6-`
'9!Qd"!E
V61|eL-l6Xg..3a
4Pm$bc9IWv0=:E`
*(oc`BBwl`
@\izJv
^M<x|w@$Xtz
'LP9=ZXr"
2OLW(d)
= AP/="b
C4qXb:vDl
M)>BRQE]C5tg
[xa&?EFH
,:d.@+g@A
"6DJm&K4`
otAHuk
z2T#q2
MlHC60
Nx(i7N+
'6dtIfq
Ohegmr
|pKY<v
%c0SwAd /
SX1|2z
a|)hTRxO
Jw]OoH%
$;CYN7`;i:sy/
<<riQ*PY|:1
/@wK@e
KYM*M=a
{P@k}q
@zayLH
UxNsf)
&@yZd;
)YY!:_l6@a)=KL0*+zyBL/
lDb$H2}<T
qQ.20p|u+4
/nk]a2
yCIYbgM%H`M
Kpo{)\
pavt-
JCK5z''{v\v*iq4
^4n^uF1B*F
QNFmmOG~
4tE/th
C9V~\,
}e]s*E
`~m<j+Cw(
3%>I1{[R
etL@=Slq.-h:
4wGkhZ]j;
AUDREt
k@wFGt7E
{C/KMF:N}L
ySuHlp|P{xOj_!
F}}?~BgoV]/0R
zC%c`.
Xj\r&ya\
N^{G}Ld
oskpsl
H}AOI@cH
fX%wSV]
k~@35n$G$
=@J2x,>i
G3`sw{
{WpPWS/3.z$nOzU
lj $]B
V%M#*-
$`(l;|z
$mLgq
+^Rls}
{<VBbM%
8~H\}&\0c
%5^$h}
w68Uhz
-7Ule_G
?9_ZG~QMI{
=AsPiL
3-6R@T.
@d6Gy|8!?:KHA<
.<.j&C
wn:X[CW
dJUD5A%u
ZG@,SGH
5(aleVac\'}Z
L/r$0~
,HlSSm
\uw5c/bM'b
}Ho!u]H
pHNMH+.p}Nt
j)Wq\4`.
O#yTbMOVFZy
L`g7).
]5 kU&T4v;
/1DqXE
}P|bsfc
MbWlSK
%s{Y(8H
`skp+I
eTd8[e
C~v(+c5O[I0%\Y
1]/`lxqrT
C%V|_' !(T
A4/:r=J3J
6.'ZTl&|
dTCKYwxc"aI
]Y*?01
<_dKKY
uS'h+A&{bu.rI
FKJ_d?
$+*&bx]6
UKoD{f^:aWn
{D'FZ|
_``Bt"{
*srx=[i2
73p#y5yq"
Jy^IZ^^T@op
%fyC1*`,
pD!r`l
Kb#4)e(*]nBVA<
Lu,D1
T{$h(ABR8
x*.XNN{:[vf
B>_V,"
']pr?+:o
ZH)mZ-L
4m_),o>Y
a}7m.;
dBo1a!
OVVy='f!gLl
=KR4L;~VG
Z*{t5`
IK'~K.p
*U#t2K*io\6=
_Ltz=)pp
DOg_q6
=r**%B'
ALgdzgG
pJj/G
-\Tmxt|(TD#
Mcq~Q#v
<tw!^g
v%?sK:"
g-bd[|WCW
8-x$\}^$z4
M]?b>D
HI5HceQ;
'(%g=6AJ?k
g`,XG$YD>
VknznT
tESxO%
/,5hey
RWKGDH
{,J(jj
7FK@7/
jKZmYzpM[
Dn tj1
|uyEY
ND6|i6Yrz
Aa80{"+_
#H~3,H
->z;wpK
\@ #vX]npP&
D/za]&l>2
a&!~2b
!|lOYQ
25rF/s
CVe-wU5
K4%Po+
g`^;Q
6k'DG
w+ %/+gr
yE ,MsuC8&`]5
!d9(IFrNeVF M3
hN#n*S
(!EwxB
Ft5BMO;.
X4N>ld
#|OtXq
B :]~Z6
W(T1'Z
XZJy!\
j=jCCv
_(I\k,H,
0-8a<8HqfN[*6!
}Y)_vZk
1NtsB"Z
RV]AxD3
u.Kva7 c}
;EbMFp_Ijq
?GDfyF~0
o}qc[r
dzC3tQ7E
"&]4aNxsEQ&Iz
C0ATpjXa45
,Mhwbe0
v|Y..(`~ O
=76M.,
xB7'8M
E~4ue#
[Yo[;nK
.oV"+p0Y.
swkr3}
c>"yV^_"
}eCqMO
~G9DWAYp1~[8p
o|amUWsQru
ONU5S5wuhb@7Gi
bm}us4*
`n18#FnZU
u`x~}:_AS
o[(WX7|ltCG
[ejzFR
s/$ZxOu0
sCN^%E
.bwv=
a j0,[uB
b7]1^Z
Bh.Sqs
F``9"}
,oKC6!
nW]\55
{Is@DCI
D;[s;:k
_h>c`tiac
Z!Y.vu!
FzEa@QF}{H
h|1j+E
pBp}zNPJG2+
j!fr x}
Yf_gYg
*E4D_S/
yjqJraK)
w)HPem$n?o-H|sQ#Qg~~
A<LY#L
xSy`Vw
!pp5^'
_c6,,$lm.%'H
"[91hmE
!U@[116
qvs."J
x@5(p!s 5)
6?Y29]
1*b1#5zFK
6!3Z|#SA
G`3GAS[i:
w sF~\
S4>-I$
gN0xgR
"=v,0
'}'(B}
vRoeP
(^|33r>m-
w%"JR5G
m`>kHnzf
q3iOe+6
l{tZ^_Qn%
Mab$Nt
zDollTN\c%w
ZL9AkP
LKSRF*G
KuvSkZ+F"a!|
0!cJJM7O
;KF]{
Z_o~#z
_6Eh6D
N#I.Oiw%b
n7|glb
oqqt.y=a5bJWI__
u#9<E="3Ej
BV}?{1.YI/E
{hcgFu
>}8j!>[Y
Jm@+W-L
PN)sy64
hGuGSU
m>)$+x[Dk|
]=VK:J
g~v%Q%Jm
:;wS'?
/f<N6v
5G';j{
J0B7O0c4|c=
Dj{j/N-RpM
]Un,\1>Cgj
zY5V]!W|H_
gac8<^
&,PJlz
mdZ!74a
]9tEZN#
218d#"oZ>9
J1 L!.z
&`SUS+#\P$)z
DOY*Kb
Nqa23$m
7cdhYS
#$<$}P6K
>dwE'JnSs
qNq^[
Cd\0YV
z\HXt#f^tKR\
Iy7IM1e=f
6/!*k14
!lona=MC9pT
>DG10(G^_<Nd]0v
w.2K\*
<mOI;M0h
X;VI0';k~?\
Q-mGHW
.S.WP
58dn%bn
RdtRG|[3`VI
I!KC1wbe'q
m_Sws/LwDRe6K6OP
Vs>'8y
VT>?MT?=KHl
94tsYJ
3~SRi>2
()'nShh{
p]giIa
/C*W9udqw/^Cr
i[ HzZ
\~eVlk4
a]6!.M
|EEs$CRA}P
TGL6=3w7eN]r
k~pcgmTV
s7R<YU~?
v|Fdul_D|
5%-;tu9>l
~[\A0#
%X;ftKJ
"6Ts}qq*
#E3_Oxxg rivh
KHuZt80,
^C,V@ta
fFn8kWI9H#YS:w
_x80Ds
TNLIb1J
pGm~f2
9y('v4I
"&MU)Ozipd31;BI
C=hxSGS36
_7iji;
pTqrY<m?lXt]
d!td:Bx@(^
g-=>Ch
RgM'(hchz)
y\H\A
=G?Nmalw
N?p#A4
^9g#z+
clqz*y!+
H1hRpK/?kPj!9HAr
~1r$*[1&y{
0n|d>6M
<-F7maP
^G\d1G
Rf5~'M
~H")C[PG6_xc[
3.Mh#dO~
nvWz0eNc$N
Z^$m'ssiN
ZBc_G*QoP)3^
v?* 35OYJe\%
V cMlt
=L-Rlx
P'p=W f9j7c>
[_>&h8xG(oZ
Ihr(Lv
,;5E/}!*&3g
!A! xx
5mK?f7
!oSdEP*"+/U9IYe;?=2o9
Oc+b6#~yz
<}Jq_Z_'9N&fCJ9
z;mm<OQ
< 9M(FTF;^$
[:WKI4o
dx9ML}}
"i']Mnecl
@iI_36($
3^'[pX_d@:Pl1'
yu%CRi0
>\uQjbQVHb&yZxjTB
5k%qCf.A
BcqicZ
Fc7QM*^R
~7+Iz[S
1g<Mf{
:nWh<#V
'+\\$v
rd7r+`k
/mopT9F)1
XcYzD.R
P?%fMa
#&%KivP
H!n_<hm,
2d-0'>K7
Gd_fXiB
a\Z&%7z
Q9YLt
:"d#pZ#sZs;
O1wHpo'"?
$LQk\?(
BT!+c&
p}9,~Z,m:=
(z)D~G
/?TGaQ
YNk<`85G,h
ZpKn5xV
,8Nk]` clk>PXeY#4!A)
EUqB5whxq
g6q^p
r6*s$tQOU
B[W3hEc]8
*kUtKqHw7p
U.VrhRVK>Jm
##,tPO*i)
m~=Gbmo
H5lzrc
yG>(*np
xg9)aY
-dHPrK+FSnl
_9W3zLG`
Eq >xseE
%"Ead02d
W;~PSqfw
3:jNvV
(On_k9TaVO!b
E}NxoZ @y{K
[$QZv/4
%"I['5H
qTcR.fc"W}6Te7KA f-
dQuh4kq
Y[<*Kt=
QyJp v97
,&J|oh3
XgC8}\Q
UybTUq3WI%B
/k(,$0
Ozh-zc~9
U3$J$Ma
u r.E[?f
ln-GV#SF,
Gre<nC-I<vb
,4Wo._
qN_Hyc
4}?-m<sq
mf|+s\c
S8dj@x0
[hQ5 g=
)TxOR;:
X9l v@9
yNR7p
!kaHzC
{c`UT%l4
lrSlGf
ZPo@cL
34KcS_kPbS'cI>nFT
St4ad>[
tl,kJyI$i)4
l92WPA
O`VDksJ`}
PqZ7%Wr[O
{t: L<q/]
AooZj_Wvb
xhL YC
p?ekyjr
#Y]c8C
6M~/5NhY
P]r8Et/
Ak0@qBG&4Hi-\wR5
m+#v_+Va!
g9FS4eu!Rao=r
q^,Y{Z
?W#nn_^A
5UD:2G\i5Bh=,{
vk8iH?
s ]["Qd'
7pZ\M n6pV5'
a0&5hRYJiWd
9=T%gMfskV+
qG^&Xy7
t8(&Lz?%(uq
D}'L5.D"P<Q
f)b@}T
ehvH_?
:R`U^u{ql5
T\^)RE
=b<:]%=
qLy01RdF
^NZ\~<Bd@?
dw:0:Sqp
LG~^I=
]uZi{_7f#\%h,[1;PE06/cNx
'A9Ya(my)
[^:>wpmsA
m%Uvd1
VbUVBks
~yi*S
!) y&
Z+O?K&
5mppKo^W5H
4(R0ed
QauI2#c
2K6PZXa
.Y~NPz
!=F_'5D^
!gc]0P
6=Cii<
*~(S2KZ
.v]e%1C;cX
`Sx2ba.U
Ld#-c%]0w9U>
x'l)H*(_JWN
xv}PDk
<-zC$8_]
U5ku:M
Rh|{DO
YcC(ER
Y[FxM'kZVlEoKe#$k7
B><K^k
f!~*Q@W$
GMfY1I)
%RP7DW
1,_szi+]?js:K
\/K`Y+
3[iX=
|-~#&&L.@i
n_FesD;c
8!=k'KZn8eMlAD
p.i96J!
2F`_|_x
V:w4BZOVOJ!
MXsgB[-=rhck
t1?>rWOk6M
m>})F:H
"|;[K_V78-t
rX[1}6
+>9v8G>
;nx,C=
SQ|5MD\?O`.v51C'1
tq,O{l,
B*sTBY
S8=uhh
1"$m{sD#
#Y}jkLK
xRZ1R}1l
8WWUW?
R:~FQL
a%ELE1N
Ggjf"/
GDiS` =RZ
O.P\d(ff@
[(Q5f4>(nv
0jkmfJY
\>NrD(Rq:?#
nQ,kwiG)QC0
{d*|;6.@Xw/GP
A\>H!|#
op"&ipa*3O2(71_Qk4u
VLx5@xEfbux
JdPTfd
3r'M
HrvBPlV
oI$iOg
n~aiM-
I]Awl,%
rzJh5[O?$b%SY
Z?553Qe]C"
:cDH3pl
"? cn;
nq"c\0
0Yokfej
9KFH)i$L@
RQbPa!6d!
iH~h6mP
.'pvp^2
O#t>eS
uJCIDKm,
rB&GAg
P:'mA'
3he1uf!
v=|tb%
O:q)#wn*
\+HU8]
O%jli}%lQ,jVw
{*utu_~o
%o83[a
:co`39
VZ};lDK*}"
x=9ztWE"U
OU\E[l1M"B
qmGPZ*
s0yGYA
_w!nm/
bY55b0_
}(dd]=ko38w
+.WE]R?tz
fk $!X
n]v5RU~
4N2zS!8j*uC
.a!`_k
On8l%9I
CDmhjM=Ar`_
i57mLo5;
3.;YJ3
I PG~a
J)j>>@=!@fxf
si[I/
pF0_lE.
<0bK{F\];Hu
5vyQvDOew.}le<$nU6,
rOfL"3
F.!Etc
YkSDh-_@
NI3 ;9GDA
vm.Kg!KlqEpmv
bh:L&|{z
?Y%k8
2zw]|:|f*R%<@zJ:Gp~M|
QcwdPc*a>":
m-u-2h@;U_N0~fQ
_JN$:l[?
DOqr18F
X{,/?J"%R
[0ZKxnH
;UMR@Qxh1
bTy0G
PDGc>-^\
d^R@P$
B%<?/J
``edft17d
L}?Q/YK
~X>hC![
k:|$qH` z<-^
{}&\OSDTfmw
025IDo*SJ/0
tL1Nmu*(ZV
3J_DF$@
KskP.Y[nK td0
"}Q@hm
^J{6n0n
_&-b:""
}#?3Cp?Z
hK'A<F
\uXh<<T
0$^eMx
L)o@%VRj<
Ic.VW#v[
iWGV4RJ
d!=MJluXUT9
nhT=^^GU
:,b5*ms%
U5~F^d;a*^k{z*
g~QtH;tF
6%t36
h9*bHAId
+$|9q
tt=G_.:De5
LrD:u,8}?
?[bRL%?&_c,
f~tvkul 6I,2
"+B(VF
n"<R&2;q#
XTZbK$U5
&^sVoCypCA!,Wg
^E$[$jeI1
u;#mme0=oW4Nnh
xwt[9laK
2[ahS:J
ZVle,%
eEO$. b
p$P}nmG6oA
6{HH&sB--}
}j"ASb&
>z0%*{gl=
zFp[(M
z-0Wdz
kOug~S
`2*f4sit
,y&^vdS
k-Z4"5%-
c0JNw#/
*?\B9^+,!
H94?wcjL
WvA:~|K
J*^wV
Q0jHTR
NoZ4LkM
J?SOXgi
nPZPJZ
TgUX?l
2HR'vm0:9iA
x{V~A+'
(VeKwq
5$vF*0;+#~0D
]WKi_{@[3>pt$0
Z5GAN:i
z3&#H!mr? y
\ZFP}q3j
i'Lhi#
mUE2L\O
abtJ\]BE}
bET_lGS6j/
\Ay::P
|r4?8c
jAn9Md`z(9X90CX
s={dixUy
XiB_a\
Y<:vVo
2*b/0h)!
J>{bX*H.aeB
S/i Bz3
A`AA=E
x:Eb<Sb
X-./IL/
bb50"tY+
> -^nZVFUi
iMqs'o"!PX
&HgC~jvOxdR_V
A:>[7R
ufz}5um%zb?
aX0am\f
9/b0{lY
MWtNgt
,o:v4x
MsGj.>ov+
6DCfZSQTs
Eoh8@_nq?
(U?~pag
Sntv*rd~+S
()\)"[
U*:9:
MG6*Qktdm
r*1KGH
_jQy/KG>~
D@E<MgR
{xeu+YO
?&)^"]
]lARN?RUFy"3DRn=j~LR@fe`"D
BSmhY7
i:%$Ue]$7J
}Y]'X{-eJ~q#H
SO.?&]3j
/@Xz+o
_K6qI0<
t~{]sJ_
MW~N*k
5IM_%)
$oCDvn,h;F6C
9s5O"YM'qP
g.AE[G
-5c(YS@4F?]>~tdK+~\l
Mne}&(
z;Ma_A18
Hm_\O^
(sF)9*!4
6v6Q^U%
=O'\N|I)g
'&&Pn.
_<q1)Fc3?
Fa'Rxm11e>Q^=
N|(`dzR9
+pcl4H
|Cry[c<x:bE*KS&
F,O&j3i
Ug1eOL3:
_|jrfR"s1
I{uX=OL#r &t:=
8Rv'q ~~
7:TWY"f(;y`
Ks`2lK
sKr-6F
GiifItW
x|cI!txd4
"V>Z`T`
cB;7),Ge.UGW
Iy`W:^:ZR
:*d_e$+j
7\Zg[;ZZu&}
9~!=OskKIem5L
#J^\$g2
%sm4CQg@
KYNXUG8
W]"!7dR;6d6sPoJ=
Wr"`VWVE*`8R
4.{Xe*k.l+\\d2zgn
2Vxye(
BII#:-
p;Av=c
M`dIRZN
'X:179n+
@>?XPy
F!q-fC
d5exlR}S`k
Y4.)ZU2R
o^Og>7rb
V\?(Yd~bP!C9
ER@E,n
rsA]`i
\*7-1
E lhQte6gE
x$):|?-
@h?=UESF7
%tnpfPpg-Ta4F
ei#:hFh&S"W@'+
}7NL'r|
0WFRq`$
+W|PeK
quvqJ'I
|f??gAv
i<zwW{2y@@!
x2}3wd;
3.kYiL
$o%[RC3^W
U|Y^x
JHSYSK
F`,t|*Uk99
W;]c3c
7ai}[s
WdIW/*
6;z(9$
CI`>RH
\qy%$V
y@I`;5
qS} %}
^4nqz+
F]No(.K0
D]Hvcv
v0<R@3vLln=I\
N[++]F*u
>j"`!l
-(sFgs
;IQq.&8h2q)X/O=
:K40')Cyp
<^6=s"m>tA
NcS~T5t
M(6zlfA
W]<Nx<\'14ir2w
.#D4ZI=V
Tv[S:'
a_tQ/&s
_1mnq
|W%56ds^rsC
WgU5r=BCyRR\:u
JjKAn>p
!U}`F{@_
=b[?4)
(~,rL6<="+
=Y6p5Y
2t$pIh9x2
J+ +;L^q
@^MM(o
`zss/G
E&-taY
R>1W=u?1
;R\?"zsN
)rNADPrP
cBJzXM
N#8v\*=gP/
vXenX.
010':^Y<v!
xG"cm]|: zp
#-8BfyF
P^#(6idIbGc8jS
^[K$U:uxjn(
irl`Ln
Gkaeb@Y+CZEl/T
n<aS$t
m`.Bk}
rK'O1l%
l6-f}eY
Gt#E&'Q
v)dMDCs
!Nu3U6 L7
Yh2k&':C<Sw
><#:!X)
Yb/`0^4etPg:w/
"Th/ql]
>0LOA,
,PZ@Dd-m
+P/EPO
i!(Z@,m
Lay~oVfG
2S0PE|
H"d$,4&
JbhqA\
A{aAGg
.vbEwii
otf-wT_[vs
YM?gB^`l
H[yn.Pj1
wcw0|:]
yhx1bNC_
n^^:O5
EMgx:{
7!-'((
2_L-B4
:2AuRPb
m3 BDepF}+v
WfR$bv|
QT:K? n"W?:Qea/
]#ldQ66
J[LsVnBP~*
L~ItcPuC
<DJ<"Y
QOMTu9
*>yQn?ko
ur|Pr(~
]Fe{`BBv_
'C8,")`8`&v
FZ7hb=
x <5Ti,_vF
BQx[&FW
hgqT:e
D{YwTg
QX-|Lnu
M1DTZ7
^]#,Uy_}rX-A' gZ"Tz?Y^
_Zx}^$
SF6?d%O
BT`p=^}Of
x.zIZC
u|=0%h"D7K
6U,p`
r>X`$ux
" N4<Mw
FGG/?o5
"?tz;yIS
et&?S^-x:w.a
iW%3L|
K;TeW0,iUg)
"1(Wn?UcLnv?
{GMJ9
oZ,v(h*
~lhpmN
vu1`*c
:h"O(TH
E-b6WOXjN~
VtBmD\}
KYFxdI1YVh
Z4$Pi&;_
NT:2&K83A
u!4fL4:b
gE4hJ$MR0YVZl
]OKCuj
<.88fO8jH;z
->.[4t
YW~}sg|M
!tld'.+
F?\@?Z<X
_no|=|t|
q>>WI6f[A)m~,!0V<D
z,0RBo@0^W
asNh..4
~pt9c{A
7rkf#Z:[<*l>
{Pg2U_@Q
vO.gVd>D
E.:W%xb_py
Ry@cxU
#,fl75\x3f1
Y?`f{wR}
]3i$Z/G
#==f#&ev
9gx~@o?v
pc%Nsc
)=_13/5 4;SLzy
zHd\_
hoi8<3
!1sgnmxqI^fTcWw(
~s_@fSd4E
^o'B!+
gQD6<K
T9qna|vB@d55
aB<('E6D
=Do!|]'3\l
zjM~^g
q%$<zurA
L R@/o
=.gg2e
iC$H"m|gZ>
p=ICkT
-EX1LS%%
DViSWCM$
g|l/:m0A)Y/+
OY9R/0p#l,
(\~|eQ/kj5
uz_=5#
PG4}V*
2?I$Bn-e5DA4.e}+
C/_9&?O
IK4L]L
ey!!xa
NW?w%4
qf\ZLG
$WS$Gw<AFfB
s13aG6
E>ytMj2tP"aOxcT*Q
55cU|6g_{
q#~f8J'
bszJD
Z>kaE\X
e*H&RNh
MAF}s.
H|%!yK
oq&ZeO
>J1418C
MX7d1o
]+Wc`^
)[Ol$C
vIW^_J@` |gan|F
~*Z*dSJQf
lB.tY<Z5
v)5:r6Y'yn
UL\_PQ
/l),nK
:{NyL\K
<&BiT\
iAH[77P{f7rd
]6sB@ee
s<0xs!tr%
upEEX.
Dt]j<H.q-).`a
zT*11hL/3CD
qCQb}Voi
UG>mAK
xe;vPBP6
B8U(pJ>7y'M
xGB!enC
-?&Aq[8bjz
dt*Fciaj3
;H30fw
p8y<V&
5:7^aFGMfXJ1
_O_/_\xf:TO`y*Qi
i0i\]'9_>
/`QTB^c|
i *']2
xF4ono!WJIr
{eboM+b~
1BOyc0Hf
s"`}]CahA<
k_T3*Ps
3c5Xl}^Y
dQ*SaF
qmJMG
T]#3Ge
%fUW~YS!)
eD`5fq%`GZmZ
GnkllL
P4DEUF
SJPrC3
HCd:zgg
AD&U2|U
S7T(:~h`
?Ed}ze|
{9A1k<
k,^/*_j}
Z|[OTducO[+7
6P$Eny
\lyq-|tVXJV
8&&DqU
"fUw+O
ZL]8w>uHS9
mZHq(3O
h-ztF{A{.hf{7z*fr
]F}tM}fXhieHMI
rY{taEv
8FEqm*uV`|
Vcc%04>!,
|L1I'PEI1w
$"_J@Fs{B'
JZqN&<'w
u\<Zy6FsF|Vi]
n,'|?x.
JK65`R)pX>
Tewc<ynS
]XA%rlfI"Qw828)aO1p8W
RP0/i#
HLx(5+`)zs!R
(jO(BSY
z!=>t
,FP&MLM86Z@
og-uG8
&f7Bx3{_y}f'c]-
iKggr=TaQeF
u :*@S8[p`
hw?Kz2L
Y&n{@z
|FTd{u
o` 1<P#J/;,
s Q2k'
<#b!p,Mn
'8xCtgA
jx:\#a
%,S!#v~uB3I#pt%L"K
vE):PB
P'|wkT
r_;Y+!GGQ
#zg<'d
WHB#93S48
0?[?UuZ
Jj.C_L
U\?)pL~6/3
g?wnZh
LTGn#0/&cH
_HiQP*MUUjS
=]415#
gaL}5~n
+6c[<'^K
T|v1V8E
V^TDYw
+M"Q/
H+ax?eQ1
vx"f ;
{f2[3g
-h=.4]"0e
,Q-|/Q;
VJX`mH@>l;Cx}e\
6*|>BIu-cP
n7='3F
]*>a);Ui<-"?Y^]
-NzrEsBSZ
QjTx`v
!N@jA"zSE
+1#f?|Z<
Ik;{Dn
62![6
T5n$<B.a
]*9/D&6
M'B}/V
"z\44=
<hMlPeq;
~:[Y0"
HowhwH
]WGRgn0I;,Uw
9"!H%l)
J^EUQW%]
3AW M<^fQ
c8r188b
f8Cc]/)]l
"FuwI,
mFkI\50|
iEs+^HT5iOx
.x8[t)2cH
"B+^n@
2X(y}(SFa
Vm7^ow{ch*u
S/+gN"
lN-V4e
ix9.:%
gYOc%@h
8)#G%\
S0-KQ$
!lw0wB
WjY,nKI(ro7-8s
/T,omOf
[_E}s#q7X3z
R^cl1q9b$
q7yres_
k)z3y>a+d
w\5v[$5%
43AM)pC
Z 6<bu
{1~TS2
EaZF&zveP]v
KFvmkQ
CQw8eJ
e#O6`XG
].Z;EGG:
4u{|kI*(
O^t!tO
UNUg^[
g:h;dA{2
dk/,53
Whs(gXu
~^$"\u
?Rke0</
y?] c%
NP~;imvfLVZiXOll
U8bDzl_I
m*t"v\
Kh}shPN
BE%KfC~r
4)8?k!+
Mf'#s[3
30&d,G2&L+~J0'k4m-
h.Mfp!
-5vZ*~}
pNP7Ce]YfiMy
pMLYwMNG,q
I-[q3_
j;dO-^
nbdQfBpHu
"K'f,o
Zp]<w\bN->td
K.WjBZ@
lUSUaNm
Z7?n!]vX5x
] $Kdy
'=+Oj"
Kx5YlT#J
r;)tOy1
nFfv$s
X.;35|
5?=f?X
bv&=oo
3d)5(yg
.OEFhK
WqS<i@A|
FTsnGW
wNj:^A
uwax5LcCUU
@:wi$qxG
KcW/jH!
w. d :PBS.
NWfWN(
,+Jhn3Lw
xP25A)W
J9T:,5Z)Vq
En?Wd88t
-KpKS4QkM
.P0Lmzv
2_mPwEy
1<,im} Tmi,Wqd
]kW7e
}E-=NX
`PKsx=S
5/XLi+
t6 mvp `|f7F&T
OYzcGwN
u)4H^x=6!B29_1o
-T4"tQ"Q
HMqIH|mr
^lSZ(y[=
iJ ,8)
^xE_=(_9
=dSV n
(HQU.$s
aR^['Qdu
Ux>)n/
U^!8xq
?vF#B1
>kc5cgU,p
H%a;!DbTVj(L`?
Es_F}b(`d
QJl3WH-TZF10a
(s_Dnu
_!Fljc
_Rq,D{]
mp+T.h7p
Me%]`<
z/eiL6
mu{u,,&%$f\
(9,r3,
&xhCv<Y\:
(3e4Sxr!$l`zO
~wUp1bm
/P%[rN(
dyvo"<
Q>D^2YO*
!%cP,Ne"/
<8+<em
KYJJJLN
>".6&SX
x9."b}Eo27h\\m#CbYX5}<@S
N0Hs*75tw
0/5-Op-v=/.kD
tA+$/l
|>M t@
54/EC^
oL%*P2
h<$p\-#9b+R'
mokrWwT
_#_%o?6
&qrI=g)Q
9xAt$2
idQ9vMn#`aA+
Q4hTSQ
uu)t.IDqD
2u8__nMP:
Pt:Pjtn
l!q 2Jgn)
%|d*BVK$
IHMUAe:q
K&']qDLy
p.*VXEpTJg$%
=PxicUfB-
0J9CBJeW\XfptE''
cDZ]Ed
pJE?.1$(
>tdTb-HSPG
pTru,iYkN'(7W
?t2$b>
Dpeo=_B^Ml
4S2bf3QA6BT`
AQ*pkf
F1t8]9 |)CP^
`MJK;
^2\z^{b
R**Kp[HN
aO:H-4_G@[
(WD^H4Nzw.d>"'Av
I0UJ-%
XNU$_c2iv`
`2T3n<
{=)j5L
.[MXi1
#SZvs,?|jVK5
|q%XBGbi
b;69Q]
g(os>_
KH*I%no
#/8Ie)N
<{ShK_%
7:=i
D N$=
]N?wXw
@=~0l[O
1u(Rrd[s(X[
HyN<?~
*)M\rxT_m-VtG0%
eAGC&O]&'ul
Ccc(2,
CMmO`c1
|bxca^"Q$Y(3-
/6_d4(
=UpTCt`d
=3|,pe
4U:;ES
aulMX%
>hfy=\
k,1o"8(T
A~G?|iLk
,EC_~/
&e{\myeRn+DC/,ki
=k0 gET
zio1PYR 1ij
W-_IRc{xX9
U+ujqGz
jOHsz
Ubx@v{taF<2M,
cCfK('
IKrN_[%
x|S`>RR=}y4r\b-K
Ac$-b6PI$GGEs
*ygd~$a6
k/$@\dRPW^5sF
%I1PG;a
|J.x^$
7v:gJn2e
OhK ! "G
+Y7<P.
iro_]
M<Y"\~nL
&FG22*e5
7n}Rf(
23l(G
VkQY+S
]fK%-y
afZi^k%o
G9lnxY9s*
4Rlt?8
(X+rv]7SUm
s#yj9j]aS
d0E0]AGEP
S09%No
Dp2W+@
|4K2q.g
X4~j).M
O#U{WQkm
LQW:@A|
#zKo$6T$p
#P0eFk
=%W-SvQ"o2
s?obKSV
^Ruc :
=/v(!+
`/=ZTVj
B`P>9]x
ai%B,C
XJ; 2q[XI
:5(!{D
u%{'if]e2
n49":9e
o i{zA7
0;8%gjy
tVe`9S
M=)0+S
y3+?T"
(S>V^'Kux-
QCo1Z}
iO}8eQ?|0F
n1_)C=3e]fy9o!kDYp
[}UB>7
?|HgC>4
;vD0pm
T]#dfrE:
U7I,{6L
FTJ&HU
8bG^n@_1C
<79="6CzBQk
;*W;{{Hl
@:9VIDA
Dskr2q21*)C0Qd
u;/^~xq 9
jKR{4)
[xy7R\'"
lt>!!O
K^@MiA[-fle7\~/c
Tk>XEJX6
b:J{6K+
k{pD_*
8qg^z]>
J>mB8,IXvg~'
1c'9[<mO
%(4J*5tA
ro\ zBP
<\BSOiU
R7Cs)H
EloDYCa*u
ZY/|Yi
WWK9N'm|y+#a
/X(X~
;Y-U=9zMu$u
!*T{)wTt{
vR<U@Q
Zd\pG1?
AG[n?D6E
IY.>{O>ux-n6f$Q
qZB*ohST`d/uj8rq
|Ux#Out_
Byhzo IwL!^]
qI9eXDf?
24oXpb5.M ?~mu9)
dwC.5\V
GH9wk9
e\}dg1
/|_cal
:9 >]P
Bb) =zI
^sA6>
_"Jf|=
O1>=B-
JBV7I~i#
{jXyRM>a6
*dXMV=`s~`=
3y8mg{
33S.=oX|(FH
%XHL3%DI71
uc8/|iA5
i-g5K'68
,"#ioig
ccy)*Rv!
%TER\c([Sq<j/ix
%wk~()E9j
B+l.j!
EZzT*b3bM@&`9
>s/}"$:
B|Dy%@hJV
A@)VGG
]kz1<f$D;ewQ<
vz 9haxP
Lx2e*?=
8U5MbwD_
2>|5Ax\=qk
X&zZTNQ
nJWN\yMrP2
YMQcZfa{d6
NqS}tnJ
KMteX`M$l/*>L
)W/U_2
{^-Pea^5Kh|
aY("oYp
pTiYI7!B6aZ?7')H/,DN
hE9hVJ#'Xm+
'4\~R!
6Rlh8_
VPf:H)
$RF!.^@h^
.3nURx"6)ux
a;.D=p
p9M6}5]30
1[--ah+uc
`g{LS5
tU~C_2
~&L$OELv
?e^*q8_Fjq
$/vm6:H
qRb^t}2
9~m&m
k1#-Mq7
07&BHB%
/lmda$
\ Yl>2`?<
;sVUcyo]
"nd$%2]
g4Efv@
/X$.ohm
:P8s&U%%(
RS\Z">GP0u.[W#
8>gj^'
{Fl25$(7
F_WPgM:
mJZ>X#[9q+mpc&|~,Hiz
5II]xM*#r3{23P`XKz
oF'fC]ke*,f
dDt]EoV]mm
&`v5w^P
GT=Z ].][
=@E')@WNS
hs J[53Z}K/d
h:,D^Idu
RY~USr
fbq(&k
N5OI#J
l+v!3f?;A62D
m0*~Vg%0
<Ylk*"%
lo/okG=Z+cuEU-
[Mal%'-PNwQWu 4~g
n4+~0B
XyZbuz
Nr$m1ha
r`"vH
O#/SrhM~pW
8gEZ2#stOsAC+L
p'I&Ae
U}X3]h#
/bvN!{8
]^k')
ssVAfVW
|Ywxt5
6C7u;W=qU$a
SP`(qO
H0aab;[
APcT](>
-LIox"54
puU~{a@<
7$x,IC=N
\xL~{{*$i
"CQ7!0
@+N,)IQR
)}4YG5v2:%7|sb
m}dGP
s!-pi-I-
eg/!76vE1Kx
E$U%(P;!
`^.^54,\
gXO8pc
#N=7lbVz
va:i;>R
fo{!.d
2zbi!y;
#,cA>-,
DM?{>ir+xm
'$'.E@Y
oi_qr`h@
Qw&f/BpHl
9gVch{
YYs*_[Xpd
I*l)u";#
+o;^YI,=fdv
tQ\[$5
#I!+n,
M@2hIx*@
>n7GB'U9Q
7+420"
fGq~g|ufIGk
a&.-"v<,$/
tQ?F40
[cdej3nH
3Fm+8l
9WCMf%L
k(7Zl]
B,yLH}
Io#"dtx
j*,N#(
`[2r*}.
zRUA)rLk
j'@:%kD&+
pu#"?Js
5FrtNmku!)T}
<KGgga]x
7m yx;
02+>5*~
&=a/R;T4X
z4IQme
:tT2G:lD
'ZfN6u
;A\ub)<
&Y]>qN!
zt!lG3
P=91tD
i/ITmkv
Y>wCdq/2
o?7dXL
9A@d'h/p
'8qE$y
BzfyDyh)3UiK
tPU|yS
I#P'6*
#ji_"<+"oC[x
hs,bd/]|6X*
h_r\aMA
owxp#2
?ZC`Xk
KgGwaj
"@I{/\
>E68{kD
vh-(b/7.
'bkSz=E2kr
l1AnPh
5*Zx&(v
%x2HyT=8
1?Zt)#K
dg20#r}u3)n
dxAg&HL8
\5P6FI
^;P|Mvt
XOq<UXG
xDn):<K5
7-GgJkE
"me F;
o@Ic#ch;`F
^A\BaY4R
H<`Jx&C
JrkI8y
=~[|XX
t#`OUa:t345-D
k+,^}U
<;R3QNj
El)4!x|!gBD,#D/yA
5mM1NJKI`
2~'SeIg
Gkv"A HbYV
EAjk,bU97
xUT1QcTKF
P+mJLw
-yD~==R_/YCGR\
(CCpY,|M
V~!atJ$7boxO
j:@ CZ{
b.j8n6
%s]1%A}%NR-!
5rSsMR
CJ3;~7d
|R& .Ji
<dJM*b0E
lIP)^0a
.YROhr
jedLh["
0#aT_cvsw{
-+&f&@NF
0l731\_y%D&
6 $D97
8%2ZV+44`5{d\
bwPC2~(iel6~Xs
>=!2GnEf]
R~&{N^.
EEMEJ,FRH
|cyZ\+|x`
<-&b7E
.FRxC]M
Z}:T3j
T0'd'[qHV;R=Uh8bX
I[BYIz
9!hEb[G<
7=B60"J6HMAu{hiNSOYl
4uNV&R
@3h:)-
:GrY;=W5s_2/VW
{C{ITk+
d(fr5-)
/oM`kaYa
+z\`0wR
agi2J
<n)2A-3
[}?8-!Ok$
WhokhtUU
f^N@8X
(AI5{%m["$:ZR1
tS]I3.p/A
VO3#-!,lh9T
f+d2PI-k%
0Es-[$Yx^pz)\I?G
E|D=c+O^U4
Qt>C}f&
gveJ39~'K
l-9'h&0X0f
Z#hf&r
Exm,5
^D(^gt
+*Pdy<
o0#._B|p/E
RiU=!'h
_Su@r!eRa
`c#by/{ghM[
~=s%{.:v
9 2^%G,
y[cE1*Z3
gcL_7z:sc`
"ARfy}_/g$
BP\mUe<4
Ac}()Y6:/f
+ m|y3`Xn|T4oJ
waf.+hr
A$.<1=Mab
0vl63I
bHMHv_cD
[W12kp!
d`,ywB
ibMFiV
I!Mhb.
uCv/%{c:^e
2jtlL?f
A//Ti^;Le2*
Rv<~<xp
E8d8I&Q
wsft898
+'gKx9zb
H{Wf+P
.d} X{cXdpu
\J}DPWniB
T:3fs77}c
jYzBdey
^AFl/C|8
x`0E/%Cb
~ye<TxU5{9aMY
fx.Qv$r5
8`*UdC,{q,^(&4^
; k[w}
isq0fJ
.mQ)+I
@:dyUp[
|og9WFpt
y& 2):
J"m SBj-u:sf
2->PV5
Q4%LVE
/?2r<ie,=H4Y
UUcM&!{
0FyWd_7#
.jY1xG
/fC,UK&
[n9=D|p
v|$3XH
0l(-Tf@o@x!|/,z"6
"l~yvlbw
.>3yIZbSv
Uwd/15
v84)B0%8M{s
KAMd3gV,
^^x~#'Zf
ml2~1~OUB
={>eh.B
?*3o9>dRz;E
1V:fH+9
8mS<Fd
s~<)c3
#phVIn
Fmvh<C
WPal`2|aE'R-XdG1
2Ie:H3,.SN
2(["'@
ecsO]rT
(=_'{a
3i_Kon
9,4uuH@$
oN~&}X^%ra>F6Dg
6*!s2qv
jX7h9o
%ao>]W7Z+WmJe'lD~g
^;k1gN3
\Fq*R m: zbW
haCE$/
aD_jXv
V\H Bm
|wE$t{U
,`B11l+pO<u
*s=Hpf6Z
,Lh!s?
rp-,6zFP
wLM$Ul.
@\ 9~E
|&%"}lX[
P?Sq!sR-X
nyCtfw
i@$0}0
MF2HWe.FPS
L(b'B`8
^elEnIcH[Q_$M"
~(qp~N
&]b`'#
4wzS.=,
&c2QC4#
I=U<0)
}N~YKw
r^ Q_bjz
1~\1^tc
]jN)}Qe
>^L b7!
EkbN?/5
;742a+
r$|I4m]
sv{d\Wz
tN5c 'R7u
XfZslp&
Ff7KU3P
)F>+2bO
,Wmk<$
T~i*1
fxEk?cP
uU]:/)
<Kr#WW
j>g@~xFI(V^
>cJ~/*f
Y0QAj8
2TYb^mZ$PK
q;xx0Og\eO6y
B$$e\ {jO
Z9raV<
>?Py%Y
?-hl, K
e^P'}Ax
fdqo`@z
?-_sur
'=Y.j};^
{ U(p4Q
6R1W_`5^v
&h@wXeEQ
L{x7MiBZK
%PS!gXk
2~[^Ea>X
m`}ZQw\t}bCk
U^Nx~E_
=S~&$n
m<{CYO
<@lW*"
.RC-Q
{^oFO`\ )?[
RXe4d^5
mf5G@{^UCL#
?|OBR,t++
{:.f05KT
8bPt*v
^_G,)kZ
D-Y/Y&C
:[k~`o&B
7/*&!ar_Jz94
QoPjiV
][.*'SGA'5"O
*H_{.$&
|Kkk:Y
/r|yK.HJ>QJjcs36F
GQu@5#x?
"$HkGtpf
7_W3kYP
3R.m/1L
,GzYMeA
y~@jr$x9p1
!rg2Heub
=F}|&|:Vy
Z9r8&8UE6p_*
_RsFH81
JAWpwRS
6u;M6a
,Cz>ajr"}b@
gsF.#Z
}_<(qEu
6$z"o&8e+
KG"@lwaM\P1
NR-Rn;OPH*
X~|QVM
DNpF]X9
_0W#M>z~5
B[6 Z.8_v
5TQ._9
'#v^t&
4>6Syh
SR,uQ?>'F3}ded5tf
! 5>)=w9n
E oY@%
'[[+@/8M
z0MW*xqy
_XsU,Xv"{^=Qq
~d%u4sM
-V}Vq~X
X;GJL-Gu>.:
,_4cc`>Xy`@
zxmcf/p1
Tcd+_2
=WwWqR(wCR* d0
/Ci[9~]
B'a@7P
G\;7q^d
/nl[bt
LBo;)!Fg
|V:P(g^b
:6:q:*|`w
7$sLr*,
srf3XEe
4q8JY^
'eiDEk
(]Wha8W
8J:U:n
vwkP,'DJ8b
1nLo1O(!I5g
5sacaZO
#^R4;zK]|HrV9
rBG 0zVi)qfg
cG.c|P
Uo6wI2,Lzz,enonIXMVy
"#&MB=x5
)xD14.Oy0SGO
"mF>uQOW//NW?^
8x +R9wL
Xi+\Gi_a
0k>:._0
>|a;#
+ .x^EYewi
eyFBnzH}e
Jl6sL(mxt4RKnD7
%!1sZg
b?#EEw
^ nlmyzMy
DN6hI8
<>$Fyb=*~r%
l0((D1
x?Aw#Y
Fm#)^$4
oh/ZQ(Y
3i+v+96T5{?`
z{|sdh
"Rl< xyi%+
CMMBhY
,>Z6g*[_
az,YpA4K4
0y4 !aSsM@
)kC~;Jvt
pwsBC%
DvA!JH:k~
JnsE6c
a&MAyq<7I
|-`d\
'XVE\W<\PZo+H@K
MX5VBR;
~W]Z%
=WQ>RJ
P697gZ1Z:b)k"K`)`
3MiL8zl3T
p?J@|M v
Qm\H*-
;W]%(S#{
;EI#Z4Jp:0Z
:uM&&WAV
,.SRug,BoWr=
3JS.^vd
;~y5At
3}7[v*
\^-l7[O]
EHyoN/N
5NRWJP
\H%mqlM2
=/-?7G(2?
KA=.Ar
FcBP:f~
i uGoNuV
[/>:Wg-F
DPC,6{Z,$?'fz8'{Wu
0BGosose pudahe melibu. Zeva hilipezipa xurotocomu. Pekofe ri di marijo yaneyevetu. Wipufebedopiyo comujiyezejosu sutime vumavizasehape. Zofo gijuxo nu. Cosegogi libo bixayoga cikuyiletozo. Yihebezobuwuci wudoca. Duferojude wo cekodikicisu. Pizipikarebe. Givine nasabuga kukuceha li sozazelopuguye. Wo tunedobedu hixotiwirozac
............
............
............
............
>~>~>~.....
...........
>~>~>~.....
..........
>~>~>~.................
>~>~>~.................
>~>~>~......
.........
......
.........
.........
.........
........
.......
p.".............
.............99
>~>~>~>~....
.....9999
>~>~>~>~p."p."]L]L...
....9999
>~>~>~>~p."p."]L]L]L..
p."p."p."p."p."p."]L]L]L..
p."p."p."p."p."p."]L]L..
...]L]L.
999999
999999
999999
999999
999999
9999999
>~>~>~>~p."
9999999
p."p."p."p."p."
9999999
p."p."p."p."p."
9999999
$p."p."p."p."
9999999
$p."p."p."]L]L....
99999999
$$.]L]L]L]L]L.....99999999
>~]L]L]L]L.....99999999
>~]L]L]L]L.....99999999
>~]L]L]L]L..99999999
>~]L]L]L]L.99999999
>~$]L]L]L999999999
>~$]L]L]L999999999
>~>~>~>~$$
....999999999
>~>~>~>~$$
....999999999
>~>~>~>~$$$
...999999999
>~>~>~>~>~$
..9999999999
>~>~>~>~>~'{
.999999999
>~>~>~>~>~
.9999999
>~>~>~
>~>~>~
qq>~>~>~
]L..$.....
qq'{'{]L]L]L$$$$....
qq'{'{]L$$$$$$....
qq'{'{]L$$$$$$$..
'{]L$$$$$$$&&vv
3$$$$$$.&&vv
qq>~>~>~
3$$999
qq>~>~>~
3$$99999999
qq>~>~>~
999999999
qq>~>~>~
999999999
>~>~>~
999999999
999999999
3999999999
3999999999
3999999999$vvv
3&&999999$vvv
>~>~>~>~>~<
&&&$$$$$$$vv
>~>~>~>~>~<
&&.$$$$$$$v
>~>~>~>~>~<
3.$$$$$$$v
qq>~>~>~<
3.....
$$$$$$$
qq>~>~>~<
$$$$$$$
a$$$$$$
a$$$$$$
a$$$$$
qe]L]L]L
qe]L))
999999999
q>~>~>~>~9999999999
q>~>~>~>~999999999
aWP$$$
)>~>~>~>~999999999
aWPvvv
)>~>~>~>~999999999
aWPvvv
)>~>~>~>~999999999
q>~>~>~>~999999999
q>~>~>~9999999999
q>~>~>~999999999
>~>~>~999999999
>~>~>~999999999
>~>~>~999999999
q>~>~9999999999
q>~>~999999999
q>~>~999999999
q>~>~999999999
3999999999
q)9999999999
q)999999999
q!999999999
q!999999999
!>~999999999
a9999999999
a999999999k
q999999999k
q>~>~9999999k
S7S7S7S7S7!
S7S7S7S7S7>~
S7S7S7S7S7>~))))))
S7S7S7S7S7>~)))))))
S7S7S7S7S7>~)))))))
S7S7S7S7S799)))))))
S7S7S7S7S7999))))))
S7S7S7S7S7999))))))
S7S7S7S7S7999))))))
S7S7S7S7S799)))))
S7S7S7S7S799)
S7S7S7S7999!!
S7S7S7S7999!!
S7S7S7S7999!!
S7S7S7S7>~>~>~!!!
S7S7S7S7>~>~>~!!!
S7S7S7S7>~>~>~!!!
S7S7S7S7>~>~>~
a!>~>~>~>~)))))
>~>~>~)))))
>~>~>~)))))
>~>~>~))))))
Jj>~>~))))))
)))))))
S7S7S7S7)))))))
S7S7S79
))))))))
S7S7S79!!!)))))))d9
S7S7S79!!!!
CC)))))))
S7S7S79
CCCCCCC
S7S7S79
CCCCCCC
9992CCCC
>~>~>~>~
>~>~>~>~
S7S7S722
3!!!!!!
S7S7S72!!!!!!!!
S7S7S722!!!!!!!!
S7S7CC!!!!!!!!!
CCC!!!!!!!!
>~>~>~>~>~!!!!!!!!
>~>~>~>~>~!!!!!!!!
>~>~>~>~>~
!!!!!!!
>~>~>~>~>~
!!!!!!!
>~>~>~>~>~
!!!!!!!!
ss!!!!!!
sss!!!!!!
sss!!!!!!
sss!!!!!!!
3!!!!!!
>~>~>~>~>~ss
3!!!!!!!
>~>~>~>~>~s
3!!!!!!!
>~>~>~>~>~s
3!!!!!!!
>~>~>~>~>~
3!!!!!!
>~>~>~>~>~
3!!!!!!!!!
>~>~>~>~>~
3!!!!!!!!!
>~>~>~>~>~
3!!!!!!!!
>~>~>~>~>~
N!!!!!!!!
>~>~>~>~>~
N!!!!!!!!
N>~>~>~>~>~
N!!!!!!!!
Cs>~>~>~>~>~eee
N!!!!!!
2s>~>~>~>~>~eeeM
ss>~>~>~>~>~eeee
ss>~>~>~>~>~eeee
ss>~>~>~>~>~eeee
Jm,Jm,Jm,Jm,
Jm,Jm,Jm,Jm,
3x0x0x0
Jm,Jm,Jm,Jm,
3x0x0x0x0
>~>~>~>~>~
3x0x0x0x0
>~>~>~>~>~OFeee
3x0x0x0x0
>~>~>~>~>~OFOFee
3!x0x0x0
>~>~>~>~>~OFOFee
>~>~>~>~>~OFOFee
Jm,Jm,Jm,Jm,OFOFOFOFee
Jm,Jm,Jm,Jm,OFOFOFOFOFOFe
Jm,Jm,Jm,Jm,OFOFOFOFOFOFe
Jm,Jm,Jm,Jm,OFOFOFOFeeeee
MOFeeOFeee
vv!{Fn
>~>~>~>~>~
MOFOFOFOFeee
vvv{Fn
>~>~>~>~>~
MOFOFOFOFOFee
>~>~>~>~>~
MOFOFee
vvv{Fn
Jm,Jm,>~>~>~>~>~
MOFOFe
Jm,Jm,>~>~>~>~>~
Jm,Jm,Jm,Jm,
Jm,Jm,Jm,Jm,
Jm,Jm,Jm,Jm,
Jm,Jm,Jm,Jm,
Jm,Jm,Jm,Jm,
Jm,Jm,Jm,>~>~>~>~>~
Jm,Jm,Jm,>~>~>~>~>~
Jm,Jm,Jm,>~>~>~>~>~
Jm,Jm,
>~>~>~>~>~
Jm,Jm,
>~>~>~>~>~OF
>~>~>~>~>~OF
>~>~>~>~>~.
>~>~>~>~>~
>~>~>~>~>~
Jm,Jm,q;
>~>~>~>~>~
Jm,q;q;q;>~>~>~>~>~
Jm,q;q;q;>~>~>~>~>~
Jm,q;q;q;q;>~>~>~>~>~
q;q;q;q;>~>~>~>~>~
q;q;q;q;>~>~>~>~>~q;
Mq;q;q;q;q;q;q;q;q;
.q;q;q;q;q;q;q;q;q;q;
Jm,Jm,.q;q;q;q;q;q;q;q;q;
Jm,Jm,..q;q;q;q;q;q;q;q;q;
Jm,Jm,..q;q;q;q;q;q;q;q;q;q;
Jm,Jm,...>~>~>~>~>~q;q;q;q;
..vvvv
>~>~>~>~>~q;q;q;q;q;..vvvv
>~>~>~>~>~q;q;q;q;q;q;.vvvv
>~>~>~>~>~q;q;q;q;q;q;.vvvv
>~>~>~>~>~q;q;q;q;q;q;q;vvvv
q;q;q;q;q;q;q;q;q;q;vvv
q;q;q;q;q;q;q;q;q;vvv
q;q;q;q;q;q;q;q;q;q;vv
q;q;q;q;q;q;q;q;q;vv
q;q;q;q;q;q;q;q;q;.
q;q;q;q;q;q;q;q;q;.
q;q;q;q;q;q;q;q;.
.q;q;q;q;q;q;q;q;.
..q;q;q;q;q;q;q;
JNPTTSRVRLUQjjkjkg>l7m2@FCB@>A
I#ROLIM*
PLOSRTUQN
ik9A@E>@B~CCEE
CDEQ(
ORKNNP'
NVPRQSMSMTPNmmGD=
D>~BA>CDF
L&PPQNONQN#
TPQOUOTRTTLO?@DBADBCBAF@@DDC=
~~!~`bf
QQSNUSMRR@FHE=
D?FECG=>=EB
b_d,}+~/
lPOSOABE?FA=BBBD<?BA?E>DB>A
_~..|0~+
tDDCDBFBC?EEB>@
DCCB=@
F@;E@@EB@:<ABA@DFCB<ECB
*-~+`^
:<?B@GE?DBAGD=D=?ACBEA>
/~-/|.b_Z_A@CD?CCBAF=E
EECBBBBDD<>p6
_BG@BECDDDD?>CA@D;C?@@BJh4d>j2
A?FB?@ED?HAACA?A
B=ECICF
h;e6f;
,DCAC??A
D>CA><F
B@~E@EBCE
?DG@ACBA@EBB=GE
C]h9g9h=
~=?BEAA=B~D>>C@>@DH@D@<>Ax:u<
e<n6j6
BDBBHBED?C==H@:AF@BCA?CZ]u?w;
E[k:l;k:
:?E@DB?E?BJA
CCE>EAEE
[[z?v@
G]"D[l4e?
~CD=@BCE@CCEB>GA~BFD
&z(z$z#z&|$|KLJOh8i<
AAFDFBB
D@AEBF>HB?AG${'x$x"~${$|%v%|
AGHLMJk8
2(fniAE?BC;I>B=IEDBB<ABCBIM%{#z&{)u&|*}#y%||G
BOMKQg9
:&/+knG@EEADBDEGBDAF>BB~ENOI ~(z#x#
#z"y%y!x$z)~G~E{Ht,/W*O
i;:&8(5*lAD?DB>F?
D?=AC=G=NLNMI!}$z
%z#v(|){'%~
BI~Hp1-Qh=m6
7$6+9(JE?DDA@BEEE>@BTLNaa`!z
%w!|(|'z%}"y"w|D~@}FBzE
G!CXe5j;d6c5
k6f:Y|5*3*:/GE@CA>~?BF@EDW$\b^QmRmb"}$u'w#}$
$z'}+x v'z}GEFzF
@{C~Ef7h7k4m=g?f3g7bw-*3/Y{ABDC?~G?FC@Y'K_R'__]SjNnMta(y'{(z%}#
$x ~'w$z|A{GF{LzH
Cj:f8d5d5k6k5j3\w^x]
[yB@ACE?D
~W%JZ`]V&_dT%>SqPo%x#w#
{#|&|&%{#z$~AC@}B}DFEJj7f;h6e9k7e7b:`x]
_s\~>G~F@EA
W$B_``T'\R'IS'BS&JPp${%
'{%x*x){$u&}'|'}ByF
k9i7i;h:d;j8e;XZZv^tACD?
we\d`S&V$C[&GW*F
%|%%$|#yyH|H~F}F|E
g8j6g:k<i8UYV]^u>C
{c_^Z'HY%T*CV&Dbe$~%}
#zy#zF
d;i<e=j9i:[ZYau
}eS%JT'V!FX&GT'K^8
zD|I|F~G+|+x}B|E~EI|D
h6^Wh=k9g5g6
X"U&DT(J6
C|A}B~C
D~BB|GB}D
[X^\PH}L|OyM|N
~A~IH?
KE|J~C}HBG{C
XO\Y\L|L
X|CxC~F
ByEy@}K}GA
LNYPK~f4h8i8
I}B|A@HxER
ZZ]O|F
h9l>l9e:b9i4
H{DF}?xB~=K
YY[W\X[h8g9d8i8g9i2d;
[ y}J|D
}yA|E|AR
WS\`\R[[c=j:j6h8i4g8m<
V%HS'B+|&~"|}IGLL~OI
L}\Z\VT_
TJ[y\{n3p:i8m5i:e8h7^xJe
wU$E|B"w%&w%{&x%xK~J
[{c3c4e6h<h>h8e5_yPg
!y%z$z!v$
%z&{%y#x%~G
i4j4g8f:i;f5h9WxOd
~U'C^&DL#}#}&|(z&y$~$
#{&~\[^
j;f6l6l;f8k8[xc
J~D%z'{%~'x'}$({#{#xXW]Y
j2i<`8c8\~c
~Q,I~D#y"|#|!|"|(}")~ w"};
^[_ce7
k4e8i4`xMh
G$|$}&|&v)|-y[Wv9
}SOS_bfg8f4
(y'z|(}'|%{VY[+}3
%|'f;e9f>
i2|#Pj
~"u**{#|'z)
ZVZ%z7
~#l:i=m7
"\Z"y&
&~#s(x
~y#g7g2m:c2~
!~XYY#}"%x%
{|&}!d]co7g3j4g8f:
~&}({&y
|Oeab`e7h9i9i6j2d6i:
0=0N0T0Z0`0{0000000000
1+1<1D1I1U1_1{111111111111&282>2K2P2V2\2b2o2}22222222222222
33&3,32383>3G3Z3`3f3p3w3333344
8888(9B9H9N9c9~99999!:/:9:]:g:::::::::D;R;\;};;;;;;;f<k<t<<<<<
=>>>>>
?1?W?u?|?????????????
Z0e00000000
1 1$1(1,10141~111112\3c3333n444r556637K7P788
:+:9:;
<#<+<0<4<8<a<<<<<<<<<<<
= =$=========
>A>H>L>P>T>X>\>`>d>>>>>>
D0g00#1)1-12181<1B1F1L1P1U1[1_1e1i1o1s1y1}111111112272A222333
4T4444$565O555555#6)6K6a6g6y6666
7D7L7U7^77777777
8%8;8\88
9 9,9<9B9S9r9999999999a:g:::::
;2;k;;;;
<<<<<*======]>f>n>>>>>>>>
90D0J0f1o11
2!2+2=2L2S2d2r2}222222
3-3Z3j33333
43494q4}444
5,5q5w5~55
6o6666
7<7N7b7o7t77P9999
:U:a:l;;;;;<U=q==
44>>>>>
00000'4
5*5\5555)666
7w7}777777
8[88888
:::::<>
3335/9P9U9|>>
01g4m4s44-646N6Y6`6f6l666888
9$9.9=9H9z9999
:':C:J:P:^:d:y::::::::
;Y;;;;;;;;
<!<P<X<e<j<<<<<
=!='=6=@=F=U=_=e=w=========
>$>->2>8>@>E>K>S>X>^>f>k>q>y>~>>>>>>>>>>>>>>>>>>>>>
?$?)?/?7?<?A?J?O?U?]?b?h?p?u?{?????????????????????
0 0&0.03090A0F0L0T0Y0_0g0l0q0z0
0000000000001111111111
2!2(20282@2L2U2Z2`2j2t22222222222293>3}3333333
4-4744
5;5d5r5x5526O6U6_6u6666666
7.7\7a7777
8;8O8U88
9;9B9I9P9h9w999999-:H:;;
<*<3<^<<
=(=0=;=R=l=======
>A>w>>
?N?u??
'0-090p00=1C1O1~1111#22233
4.4G4_4444444
5-55555
6h6666
737o77
88888#939A999.:r:::::::;;;
<h<<Z=
0Q1]111132N2s2L33\44C5555:6R7]7}7777889
0B12K6Z6}66666666666666
7!7(70797K7c7i7r7x77777
8b88G96:::i;{;;
<5<Q<<<<
=v======/>w>>>>>
?)?d?z??????
70A0\00W111111@2w222:33.4l4u44
6`6i6F7Q7d7x7:8C8O9X9D::::
;P;;;;;
?!?o??
3-3S33
5*5<5N5`5r55555555
6!636E6W6:::::
=5>=>?
1%14111
2233W555666627I77
8k;};>>>>
020j00
;n====[>>>>
?$?C???
g0n000)1J1111B4S4g4m4r44444444444
L1P1T1`1d1h1l1p111122222222222
3$3(3,3034383<3d3h3l3p3t3x3|333333333333333
4$4,444<4D4L4T4\4d4l4t4|44444444444444444
5$5,545<5D5L5T5\5d5l5t5|55555555555555555
6$6,646<6L6T6\6d6l6t6|66666666666666666
7$7,747<7D7L7T7\7d7l7t7|77777777777777777
8$8,848<8D8L8T8\8d8l8t8|88888888
h1l1p1t1x1|12222t3|33333333333333333
0000000000
1$1,141<1D1L1T1\1d1l1t1|11111111111111111
2$2,242<2D2L2T2\2d2l2t2|22222222222222222
3$3,343<3D3L3T3\3d3l3t3|33333333333333333
4$4,444<4D4L4T4\4d4l4t4|44444444444444444
5$5,545<5D5L5T5\5d5l5t5|55555555555555555
6$6,646<6D6L6T6\6d6l6t6|66666666666666666
7$7,747<7D7L7T7\7d7l7t7|77777777777777777
8 8(80888@8H8P8X8`8h8p8x88888888888888888
9 9(90989@9H9P9X9`9h9p9x99999999999999999
: :(:0:8:@:H:P:X:`:h:p:x:::::::::::::::::
; ;(;0;8;@;H;P;X;`;h;p;x;;;;;;;;;;;;;;;;;
< <(<0<8<@<H<P<X<`<h<p<x<<<<<<<<<<<<<<<<<
= =(=0=8=@=H=P=X=`=h=p=x=================
> >(>0>8>@>H>P>X>`>h>p>x>>>>>>>>>>>>>>>>>
p1t1x1|1H5L5P5T5X5\5`5d5h5l5p5t5x5|555555555555555555555555555555555
6 6$6(6,6064686<6@6D6H6L6P6T6X6\6`6d6h6l6p6t6x6|6666666666666666666666
6 6(6,60646L6P6`6d6l66666666666666
7 70747D7H7L7P7X7p7t77777777777
8$8<8L8P8`8d8h8l8t888888888888
9$94989H9L9\9`9d9l9999
:4:H:P:X:`:d:l::::::::::::::
;0;P;p;;;;;;
<0<L<P<p<|<<<<<<<
=(=0=4=L=P=l=p=========
> >@>`>>>>>>
? ?@?L?h??????
000P0p0
4 4X4`4888888
9$9,949<9D9L9T9\9d9l9t9|9999999999999999
h1l1p1t1x1|111111111111111111111111111111111
2 2$2(2,2024282<2@2D2H2L2P2T2X2\2`2d2h2l2p2t2x2|2222222222222222222222
3$343T3`3d3h3l333333333333333333333
7,7X77777
8(8H8`8
Mzk7MjYy
deseyilemeje vuxotipufi wi teyiyapelitayazukesija
vobohisabiyo
viyeyojelefuwahoke nonohuwumiputedimabozo
kernel32.dll
mscoree.dll
AR6002
- floating point support not loaded
- not enough space for arguments
- not enough space for environment
- abort() has been called
- not enough space for thread data
- unexpected multithread lock error
- unexpected heap error
- unable to open console device
- not enough space for _onexit/atexit table
- pure virtual function call
- not enough space for stdio initialization
- not enough space for lowio initialization
- unable to initialize heap
- CRT not initialized
- Attempt to initialize the CRT more than once.
This indicates a bug in your application.
- not enough space for locale information
- Attempt to use MSIL code from this assembly during native code initialization
This indicates a bug in your application. It is most likely the result of calling an MSIL-compiled (/clr) function from a native constructor or from DllMain.
- inconsistent onexit begin-end variables
DOMAIN error
SING error
TLOSS error
runtime error
Runtime Error!
Program:
<program name unknown>
Microsoft Visual C++ Runtime Library
kernel32.dll
zh-CHS
az-AZ-Latn
uz-UZ-Latn
kok-IN
syr-SY
div-MV
quz-BO
sr-SP-Latn
az-AZ-Cyrl
uz-UZ-Cyrl
quz-EC
sr-SP-Cyrl
quz-PE
smj-NO
bs-BA-Latn
smj-SE
sr-BA-Latn
sma-NO
sr-BA-Cyrl
sma-SE
sms-FI
smn-FI
zh-CHT
az-az-cyrl
az-az-latn
bs-ba-latn
div-mv
kok-in
quz-bo
quz-ec
quz-pe
sma-no
sma-se
smj-no
smj-se
smn-fi
sms-fi
sr-ba-cyrl
sr-ba-latn
sr-sp-cyrl
sr-sp-latn
syr-sy
uz-uz-cyrl
uz-uz-latn
zh-chs
zh-cht
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
USER32.DLL
((((( H
((((( H
CONOUT$
@@@@@@@@@@
AHHHHHHHHH
AHHHHHHH.
AFX_DIALOG_LAYOUT
LLXDGSTA
YEMIBATIYUPIHALO
MS Shell Dlg
TODO: layout OLE property page
sfghdfghdfgh
sdfgsdfg
Zoze safaca nemafica vere
/Fatepaxudoca gigiyovekesodo xofezavuyu bokejuni(Kudihube kopukafolozepi yiwa yayeha cube
Baba2Ruyadeyafi pihajabono rexo kenevekivu bakivekesaxu
Negiju gudanepi kotigodimu
Wusocu
Wahoke nono
3Huwumi putedimabo zo deseyile mejevu xotipufiteyiya
Ciduladipi bawesa
Merurela dupa
"Cavawicewecotu wija harorajucozibu
Bajo cejedamacavi yeyojelefu
mGifuzihuhikeba zukilaja tovi tacofugorakoja tobuyukoxuhiru renagepuxakeni hife zacesi lotamomoxihu lonexesoda
NPelitaya zukesijavobo hisabiyohoxuco janukazahaviwe xepe niwanegikicudo soyihu
3Fefopiwozemogi gaxujazaji yanivo xazo wiwayepaxo li
0Nixadate bi cofutiwefogu cubohexuviyi cayanemoyi
JYojimidetavugo sugugoze beje gikivejoxegafu vemidaxazike lizedoxirivi xavi
%Zifusawerice cizaxafixobamo yeve tiza
MDiwuzemike vaso hirovacopi sagibepisatoxi wucatojo sutuyado le zosiwayuhumuni
Gewoxodocesa
]Pajayeyazedexi sudoyomuhosade gumofipa sicajo cowenodi pececi dujuci yexaweko za rixecufazuko
3Docatuzumuruya je huzikafupo deci gosasetidi yojeyu
Xami lodedoneku tigu yilo
Lucivavuhu firazepibomi
Cehijetudexica womutega
VS_VERSION_INFO
StringFileInfo
08804e0
FileVersion
InternalName
toalatspring.exe
LegalCopyright
Copyright (C) 2017, otdvozgud
ProductVersion
5.1.111.0
VarFileInfo
Translation

Process Tree


0b5122cd78d435533e1ceb318c61088db904b4c48e8b6d2f192d2164ce518cd1.exe, PID: 1932, Parent PID: 1860

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 2416, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1240, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1140, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 2100, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1056, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1960, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1324, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 1724, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

nslookup.exe, PID: 2028, Parent PID: 1932

default registry file network process services synchronisation iexplore office pdf

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138
192.168.56.101 57665 224.0.0.252 5355
192.168.56.101 51758 114.114.114.114 53
192.168.56.101 52215 114.114.114.114 53
192.168.56.101 52216 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 52217 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 52218 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 52219 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 52220 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 62361 114.114.114.114 53
192.168.56.101 62361 8.8.8.8 53
192.168.56.101 62362 114.114.114.114 53
192.168.56.101 62363 114.114.114.114 53
192.168.56.101 62364 114.114.114.114 53
192.168.56.101 58985 114.114.114.114 53
192.168.56.101 58985 8.8.8.8 53
192.168.56.101 50075 8.8.8.8 53
192.168.56.101 58624 114.114.114.114 53
192.168.56.101 58625 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58626 114.114.114.114 53
192.168.56.101 58627 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58628 114.114.114.114 53
192.168.56.101 58629 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58630 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58631 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58632 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58633 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58634 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58635 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58636 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58637 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58638 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58639 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58640 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58641 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58642 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58643 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58644 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58645 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58646 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58647 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58648 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58649 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58650 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58651 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58652 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58653 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58654 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58655 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58656 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58657 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58658 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58659 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58660 107.178.223.183 ns2.wowservers.ru 53
192.168.56.101 58661 107.178.223.183 ns2.wowservers.ru 53

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 57671e47c84130b2_win.ini
Filepath C:\Windows\win.ini
Size 16.7KB
Processes 1932 (0b5122cd78d435533e1ceb318c61088db904b4c48e8b6d2f192d2164ce518cd1.exe)
Type Generic INItialization configuration [extensions]
MD5 9aaa2d87c8ff438b6b59fa8a25508968
SHA1 859eba1931c4380270d4d54a276ade2d0477307a
SHA256 57671e47c84130b2ccffcd96558a7736f5f64cc7265425bacc75d6267363f69a
CRC32 56C01A32
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 99276e8c51c4d963_itqewa.exe
Filepath C:\Users\Administrator\AppData\Roaming\Microsoft\itqewa.exe
Size 240.5KB
Processes 1932 (0b5122cd78d435533e1ceb318c61088db904b4c48e8b6d2f192d2164ce518cd1.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 1f154d864ed6317520f68ac7d165a6a9
SHA1 5b574fc1e437bcd083b6cf51afdbb7344edbfdae
SHA256 99276e8c51c4d963247f89baed2fb91cbab1389f553a835761bed200ab953c38
CRC32 49C059DD
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.