1.5
低危

0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035

0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe

分析耗时

133s

最近分析

373天前

文件大小

104.0KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN BACKDOOR WABOT
鹰眼引擎
DACN 0.15
FACILE 1.00
IMCLNet 0.78
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba Malware:Win32/Dorpal.ali1000029 20190527 0.3.0.5
Avast Win32:Delf-VJY [Trj] 20240215 23.9.8494.0
Baidu Win32.Backdoor.Wabot.a 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (W) 20231026 1.0
Kingsoft malware.kb.a.1000 20230906 None
McAfee W32/Wabot 20240215 6.0.6.653
Tencent Trojan.Win32.Wabot.a 20240215 1.0.0.1
行为判定
动态指标
在文件系统上创建可执行文件 (18 个事件)
file C:\Windows\System32\DC++ Share\WMPSideShowGadget.exe
file C:\Windows\System32\DC++ Share\wmpnetwk.exe
file C:\Windows\System32\DC++ Share\InputPersonalization.exe
file C:\Windows\System32\xdccPrograms\inject-x86.exe
file C:\Windows\System32\DC++ Share\mip.exe
file C:\Windows\System32\xdccPrograms\Procmon.exe
file C:\Windows\System32\DC++ Share\PDIALOG.exe
file C:\Windows\System32\DC++ Share\WMPDMC.exe
file C:\Windows\System32\DC++ Share\MpCmdRun.exe
file C:\Windows\System32\DC++ Share\wmlaunch.exe
file C:\Windows\System32\DC++ Share\MSASCui.exe
file C:\Windows\System32\DC++ Share\ShapeCollector.exe
file C:\Windows\System32\DC++ Share\ieinstal.exe
file C:\Windows\System32\xdccPrograms\is32bit.exe
file C:\Windows\System32\DC++ Share\TabTip.exe
file C:\Windows\System32\xdccPrograms\FlickLearningWizard.exe
file C:\Windows\System32\DC++ Share\wmpshare.exe
file C:\Windows\System32\DC++ Share\DVDMaker.exe
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
在 Windows 启动时自我安装以实现自动运行 (1 个事件)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\shell reg_value Explorer.exe sIRC4.exe
文件已被 VirusTotal 上 70 个反病毒引擎识别为恶意 (50 out of 70 个事件)
ALYac Trojan.Agent.DQQD
APEX Malicious
AVG Win32:Delf-VJY [Trj]
Acronis suspicious
AhnLab-V3 Backdoor/Win32.Wabot.R231859
Alibaba Malware:Win32/Dorpal.ali1000029
Antiy-AVL Trojan[Backdoor]/Win32.Wabot.a
Arcabit Trojan.Agent.DQQD
Avast Win32:Delf-VJY [Trj]
Avira BDS/BAS.Wabot.hgwjd
Baidu Win32.Backdoor.Wabot.a
BitDefender Trojan.Agent.DQQD
BitDefenderTheta AI:Packer.A6B372A221
Bkav W32.AIDetectMalware
CAT-QuickHeal Trojan.Wabot.A8
ClamAV Win.Trojan.Wabot-7053120-0
CrowdStrike win/malicious_confidence_100% (W)
Cybereason malicious.9e3fb5
Cylance unsafe
Cynet Malicious (score: 100)
DeepInstinct MALICIOUS
DrWeb Trojan.MulDrop6.64369
ESET-NOD32 Win32/Delf.NRF
Elastic malicious (high confidence)
Emsisoft Trojan.Agent.DQQD (B)
F-Secure Backdoor.BDS/BAS.Wabot.hgwjd
FireEye Generic.mg.40ed642ee854bc15
Fortinet W32/Wabot.A!tr
GData Win32.Backdoor.Wabot.A
Google Detected
Gridinsoft Backdoor.Win32.Wabot.bot!s1
Ikarus Trojan.Win32.Delf
Jiangmin Backdoor/Wabot.z
K7AntiVirus Trojan ( 0055c5c91 )
K7GW Trojan ( 0055c5c91 )
Kaspersky Backdoor.Win32.Wabot.a
Kingsoft malware.kb.a.1000
Lionic Trojan.Win32.Wabot.lh0Z
MAX malware (ai score=88)
Malwarebytes Generic.Malware.AI.DDS
MaxSecure Backdoor.W32.Wabot.A
McAfee W32/Wabot
MicroWorld-eScan Trojan.Agent.DQQD
Microsoft Backdoor:Win32/Wabot!pz
NANO-Antivirus Trojan.Win32.Wabot.dmukv
Panda Backdoor Program
Rising Worm.Chilly!1.661C (CLASSIC)
SUPERAntiSpyware Backdoor.Wabot/Variant
Sangfor Trojan.Win32.Save.a
SentinelOne Static AI - Malicious PE
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:40:53

PE Imphash

5662cfcdfd9da29cb429e7528d5af81e

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
CODE 0x00001000 0x0000c984 0x0000ca00 6.572458888267131
DATA 0x0000e000 0x00000a1c 0x00000c00 4.533685500040435
BSS 0x0000f000 0x00001111 0x00000000 0.0
.idata 0x00011000 0x0000083e 0x00000a00 4.169474579751151
.tls 0x00012000 0x00000008 0x00000000 0.0
.rdata 0x00013000 0x00000018 0x00000200 0.2108262677871819
.reloc 0x00014000 0x00000710 0x00000800 6.25716095476406
.rsrc 0x00015000 0x0000167c 0x00001800 3.2124871953120624

Resources

Name Offset Size Language Sub-language File type
RT_ICON 0x000164a8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000164a8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_ICON 0x000164a8 0x00000128 LANG_ENGLISH SUBLANG_ENGLISH_US None
RT_RCDATA 0x000165e0 0x00000078 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x000165e0 0x00000078 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_GROUP_ICON 0x00016658 0x00000022 LANG_ENGLISH SUBLANG_ENGLISH_US None

Imports

Library kernel32.dll:
0x4110d8 VirtualFree
0x4110dc VirtualAlloc
0x4110e0 LocalFree
0x4110e4 LocalAlloc
0x4110e8 GetCurrentThreadId
0x4110ec GetStartupInfoA
0x4110f0 GetModuleFileNameA
0x4110f4 GetLastError
0x4110f8 GetCommandLineA
0x4110fc FreeLibrary
0x411100 ExitProcess
0x411104 CreateThread
0x411108 WriteFile
0x411110 SetFilePointer
0x411114 SetEndOfFile
0x411118 RtlUnwind
0x41111c ReadFile
0x411120 RaiseException
0x411124 GetStdHandle
0x411128 GetFileSize
0x41112c GetSystemTime
0x411130 GetFileType
0x411134 CreateFileA
0x411138 CloseHandle
Library user32.dll:
0x411140 GetKeyboardType
0x411144 MessageBoxA
0x411148 CharNextA
Library advapi32.dll:
0x411150 RegQueryValueExA
0x411154 RegOpenKeyExA
0x411158 RegCloseKey
Library oleaut32.dll:
0x411160 SysFreeString
Library kernel32.dll:
0x411168 TlsSetValue
0x41116c TlsGetValue
0x411170 LocalAlloc
0x411174 GetModuleHandleA
Library advapi32.dll:
0x41117c RegQueryValueExA
0x411180 RegOpenKeyExA
0x411184 RegCloseKey
Library kernel32.dll:
0x411190 WinExec
0x411194 UpdateResourceA
0x411198 Sleep
0x41119c SetFilePointer
0x4111a0 ReadFile
0x4111a4 GetSystemDirectoryA
0x4111a8 GetLastError
0x4111ac GetFileAttributesA
0x4111b0 FindNextFileA
0x4111b4 FindFirstFileA
0x4111b8 FindClose
0x4111c4 ExitProcess
0x4111c8 EndUpdateResourceA
0x4111cc DeleteFileA
0x4111d0 CreateThread
0x4111d4 CreateMutexA
0x4111d8 CreateFileA
0x4111dc CreateDirectoryA
0x4111e0 CopyFileA
0x4111e4 CloseHandle
Library user32.dll:
0x4111f0 SetTimer
0x4111f4 GetMessageA
0x4111f8 DispatchMessageA
0x4111fc CharUpperBuffA
Library wsock32.dll:
0x411204 WSACleanup
0x411208 WSAStartup
0x41120c gethostbyname
0x411210 socket
0x411214 send
0x411218 select
0x41121c recv
0x411220 ntohs
0x411224 listen
0x411228 inet_ntoa
0x41122c inet_addr
0x411230 htons
0x411234 htonl
0x411238 getsockname
0x41123c connect
0x411240 closesocket
0x411244 bind
0x411248 accept

L!This program must be run under Win32
.idata
.rdata
P.reloc
P.rsrc
StringX
TObject%8
;u3YZ]_^[
SVWUL$
]_^[SVWUL$
uZ]_^[
YZ]_^[
_^[U3Uh
d2d"h@
d2d"=5@
u3ZYYd
#_^[SVWU
SVW<$L$
uSVWU@
]_^[USVW
d1d!=5@
2E3ZYYd
E_^[YY]
UQSVW3@
3Uh6"@
d1d!=5@
E3ZYYd
E_^[Y]
YZ]_^[
d2d"=5@
}3ZYYd
E_^[Y]
$PRQ$"
_^SVWU
< v;"u
3C<"u1S@
>3Q<"u8S
< w]_^[
Ek<1fU
Ht Ht.g
6Huv=L
VI3E?E3s
3EE_^[Y]
f=r/f=w)f%f=u
f=v)f=w#j
RPCHPt$
-CGL$
SVWPtl11
-tb+t_$t_xtZXtU0u
FxtHXtCt
~ExC[)A
FuY12_^[
PRQYZXt5x
@~d@PQ@
YXYX
uM3UhU3@
EP3ZYYd
f%fUf?f
SOFTWARE\Borland\Delphi\RTL
FPUMaskValue
Iu9u_^[
PRQQTj
YZXtpH
S1VWUd
SPRQT$(j
Zd$,1Yd
t=HtN`
r6t0R=
t/=t&,*&"
3UhB:@
USVW$@
d2d";~
P'v_^[]
aSVWt@
^v]_^[
QRZX1Yd
PVSY_^[]
PQiZXSVW
ISVWRP1L
JZ_^[X$
thtkFW)w
9uXJt
8uAJt
t8JIt2S
PHXHI|
St-Xt&J|
t0JN|*9}&~")9~
tVSVWU
t@t1SVW
1Z)_^[
@+u<E@
USVWE(@
d0d ]ES
u_^[YY]
UQE3UhF@
d2d"E@
t3ZYYd
%3ZYYd
U3UhH@
U3UhH@
3U3UhAJ@
P~SD$
U3UhK@
U3UhK@
U3UhL@
TFileNameL@
TSearchRecX
U3UhdM@
EEb3Uh
tC&EPU
U3ZYYd
U3QQQQQEE3UhN@
d0d EM
EPU3EPtKh
EcPh0O@
system.ini
Explorer.exe
UEEEz3Uh.P@
d0d U,
EP3ZYYd
IuQSEE3UhpR@
tjtfhR@
t-u)hR@
u-t)hR@
" -a -r "
" a -idp -inul -c- -m5 "
software\microsoft\windows\currentversion\app paths\winzip32.exe
software\microsoft\windows\currentversion\app paths\WinRAR.exe
C:\rar.bat
C:\zip.bat
PHuES3
E.E&3UhT@
EPEPEP?
a3ZYYd
IuSVWEE3UhX@
d0d UEJ
U3YEU.Ef
EU\EUQE;}>%
EnSEcPd
to3Uh2X@
EP3ZYYd
IuQSVWEE
3Uhh\@
U3UhY@
d0d G3ZYYd
$UFuh\@
VUEL@t}0EUm3E
EZPE~h
=3_^[]
abcdefghijklmnopqrstuvwxyz-_.1234567890
IuQMSVWMUEEEE
+3Uha@
d0d 3Uha@
d0d EU|
u?8.t4uha@
u|U|ttx
yupUkp0hwhlj
uXUXPPT
uLUrL7D~DHq
-u@U@8+8<
u4U4,,0
u(Uy(6 $x
3Uh"d@
d0d 3Uhc@
d0d EE
8.teChTd@
N3ZYYd
_y_^[]
NOTICE
:to get this, type !xdcc_get
bytes)
uTC,PSC
EE>3Uhe@
d0d SU
E3ZYYd
EE3Uhf@
d0d SUf@
PRIVMSG
UdSVW3
dhEE3UhSh@
d0d 8lPh
d2d"EP
s3ZYYd
c3ZYYd
ZE.H_^[]
BFKu_^[
USEE"3Uhh@
d0d UE3ZYYd
U3QQQQQQQQS3Uh
| v;}
N|7 vU+A
M3Uhj@
U3ZYYd
EE3UhPk@
EPE!PS63ZYYd
E1K[Y]
3UhYl@
\DC++ Share
\xdccPrograms
EE33Uh?m@
d0d EUFUTm@
a~&EPUTm@
EZSUTm@
U3ZYYd
f\[YY]
EE3Uhm@
d0d EEPEePt,P3
EU3ZYYd
U3UhQn@
TWarBotUj
SV3Uho@
EPSE/Eo@
03ZYYd
IuQSVWd3Uhs@
`U\E\U\
EPSEPcfC
PfEEU:E
X/XUX8
3EU,t@
~&EPU,t@
EZU,t@
\uh8t@
L3LP P
PcPhlt@
EIHhlt@
DE0Dhxt@
\E>EPj
EPtPEP
SfPV j
EPzVt3ZYYd
PRIVMSG #hellothere :
&%->=
PRIVMSG
DCC SEND
IuMSVU
EN3Uhy@
d0d EUaE
EEPUy@
;~iEPUy@
EEU8EPU
EZWEPU
EZ1EPU
EEPUy@
EZEUUy@
:3ZYYd
PING :
type !list for my list
!list
 for my list
!xdcc_get
#helloThere
#helloThere,
JOIN #HelloThere
LIST >4,<10000
U3QQQQSE
3Uh,|@
YUuhp|@
?Uuh||@
G3ZYYd
PRIVMSG
ACTION
!list
 for my list
SVWE3Uh@
E3ZYYd
NICK [xdcc]
NICK [mp3]
NICK [rar]
NICK [zip]
NICK [share]
NfrSF3
Pzu _^[
31ff%3vcc%%112c23J33c22322332crc3cr233J2fJffJv%1[J33JccJccfcc2fc2JfJ223rrcrrJ2cc3f2r3r233Jcf2rf3ffJfrJrr3f2]fr[2rvJ23%1JJJc1fc22%J[rr]ff2rr2%ff32f2J23r323223J2rc333cc2fJJ3JJ2ccrfrJr2r3JJrcfc322f3cr3rcJ33f33rcrrrcf3cfrffJ2cff2r22fJJf3rr33rJ2f3cJJc33r3crrcf33cJJrffr2fJ2f22fc3ffrrJ32cJf
]2]3r]31111rfr2crcJ3[%%]]vJf3233Jr22fJrvvv[v[Jc3Jc3rcccrfJ3ccfffJ3c32Jfrc2ffr3cJ222JcfrJrJ322r2ff3Jr2JJcffcc3vJ]c2[2%Jv%2]rf2J213]3[v2]33[2[J32c2r33rrf2c2cff23rJJf22cf3crJc2fJJrcc33c2fccJ332rJJcrrffJr2ffrcJ3frJc23frcr22c2rcJc2cJcff2c3cfrJrf2rfr2c232cff3332fJ2r2c2cfJ23f3J3f333J22r2f33
J]"^^"^^^^^""""""""""""""""""""""""""""""""""""""""^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^"=~\=yw$="^^"^^^"jCzyw6=^"^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^=
ff^ ."k^"=!24G;. .. .!nzL4OJ"~~.. . .=
]J^ . .!sG!7{^!s8G=.. .^68Vs2!;.;*}.. =
f1" ............. ._Inzoz6$295. ..^lkcv".."";"L. .=
1c^ . ,!%6***O8Izy. .!j_". .;w=;]. . =
ff^ . . . . . . . . . . .. .. . ... . . .. . .. .^|uuzw94V9=. .. :"=^,..uS?^. . . . .. . . . . . . . . ... . . . . . . . . . =
Jf^ .. . . . . . . . . . . . . . . . . .. .. . .. .. . .}6T6$i!+~,.. ~O4u{!!je^. . . . . .. . . . . . . . . . . . . . . . . . . ... . . . ... . . =
22^ ... . . . . . . . . . . . . .......... . . .. ... ... ...... . .6Ic35I=. . . ...^v}ca$l^. . . . . . . .. . . .. ... ...... . .. .. .. ... . . . ....:... . ......,.... .. . =
fJ^ . ....:..... ...... ........... . . . .:,!!<-!==!"... . . ...:...:..:..,. . .^!\, ..,,..:.,.. . . ..:,^^.... .. . .....:.... ... ....,:..,., ..\((?>(==^:. . . . ......,,.:.. ,."!!.. . . . ...^"~?(|^ .... . .. =
cJ^ .."J4nTn5TaL<.;"clJws2:. ..."=i?2ai<,.. . . ..^~%yehY3CAh5Ti~|~. . . ^11J3399T16c;..^)JL5o.^]ff2t??]3+=. .^?t{$]t=~|]t. .isfanzCC%". . .rsyz4LVYT9C~. ..^j5*hPDPe0TmaT1~;. .54wjtffi%J!. ."+jjwc%i]=^. ..;!?2t+mFDK=;(zs?;... =
r2^ .=gYDFSQUgDj-GkK5oVhFJ!. "!9m*JaPa?. . .;!Jau$UFU*a*n$y1VOb~.. . =UG0LskShqpU"^n5gpq8.=ATIIn2*m*U... "J6n3)!!=pd. .;*PpdUk}v+t^ . ..bZAgFPDUonPb.. . .!GZQPPms%+tij6DQ9=. .%UszufL4s4mj..)5m58T9&f! .:tnS$_!+&PDDl"IpDg=";. =
fJ^ .tXeT0kVqDF]xDqhs04GmZ^.]wTTCrkFV2[^ . ..^7Tr}":.....8CcVwu%"". ..=ZkasJ[%rOm&"{nZqff}\.=Vu1]rOk]zTk ..."royC3wDQx8 .+%bQDFFFh}". . .x8VYhhgg4oTk .:-az0{"... :wkkOpPP*T;. . (tv0gPUpAGbc"+kyw69*&mUG0&G.. .. ,~I&Qi. ....=21UPmTP2 . =
3J^ .+#d04kO5VUL#AFFL8&YOFFc=sanCv*qZac_,. . .|c3V~, . iVuIrsY5y... .=OC23c3cfI54"k4V?(69t.)g9I$JVUi!t[ . .."CCTyL*Zhe4....6!obQFUDD8i. .. :xasaePQUkSPx. . ~Fprn^ ..SFPPDbGz&$". .iyuJeFk5O4Ta$5w|i1oC8*4eG*O:. . .jcTh- ..,J=3gDOddh.. =
32^ .tWx50GGs$Ca"^=*h4xhyXWAx^-JII*gW52C^. .^ny$~:... . "9sC%]uGnb5v... ~8kkny6u$$2+~It^.:^^^.?Ume4zsbn~<l. .^+zJkhqDSkG.. .Sc?c5qDPFX1:. . :hOzfOxL8dWKg. ..=khb7. .. .9PDPQJ4GY%,. .%ghTkxOru]7wxu^.;|JnT*T&8Oh{.. .Ja$"... . . )+%mF8Feh~,. =
cc^ .+#h%l[6okkL..!x0*Zq5Zqde. "VsJ*XXpJ$" . !n37.... . ;++cj1+iyACi^.. ~CCuw9LOY4Vo[i, . .?d532taFULy8 .. ."jJ$5gqpDmIs ...Dp5rrsDDFX. .wVXQ6VKWKK#d .)qPU ...}WA*njyZkXF! ..}bFPpkx611axI!.. /%aOmmr!ti6... ,vn\. .=3w&pO*LG^. =
ff^ :tbuy6o0ZQW(..>x&ZAeDnbAs. ^sTrg#SAI+. +7". .. . ^$iilvr+&m]i" ~a9kk*G88TCc|... . .=LCJ2nSd&uT ..!ltfdZZFk]|s....WFV3nvlwdF$. .4OPdVdQQFpxT.. ~be!. .. . .[e55T5eFVFb!. .tQpQqPGzrT&G, ..<nfnn8$+i%w^. !^... . . +ombY&q9,^. =
rr^ . ?gxPSZFqFZ) .<AZUdVDC9bz "&f$qXPb6zf. ..... . . :tT6}JIck5t%|. )p*&890VcCy~ . .(shI+2FFxyi . /r9pAFQp$j!Y... #FD4s!/}*Pf, . .*pO*hO8nTf+. . .... . .. .lxUhLQDdLQq7. .=$khAQS8T*4j ...:=a!i+35*8oT=. . .. . .|o]IyZFA[Ve" =
Jr^ .iDSFgpqZxh= .!QdQSTXk$&T "e%veDFPzz1 .. .... .. :~VqCtju8z2Y) ..)8k8522%$5mc; .(aO7+IsxQFV=. ."$dddDeY$vQ. .eFQD5%kPh3>. .YZeqQPZU06uz. . . . .. . .)65OgDFAqUPu. .tTw$*Ud8Oa). .~xc!|jkaTs6!. .... .. .. .|Off4PVT8Fb^ =
c1^ =ZggAA*auv!..=SgQPwUn2r. "#V$TQPQss% . . ,";^;.. .t*dk3++*T6V= |YnC)"tI4*0+... .i82]ww6aPpx6 ...<8AqFhsu9uF . *PS#q1+!~<. . ,4QDqdDpDxw5b.. . . "!"\^...=?78xPdkUPA.. .[Gk0c]TLm&2_. .?0o$u[TLCzw). . . . ;^"";...+dmsYGO&DF*^ =
21^ ..)ggAO0n11]~ !*SbP8LI]t.."Kh6IdPUna] . . .."${C}:...|y4$a[=sTV*| . =3ti~!1GepG+. .. .ib$fC3CSDQF ..!eFDUnuIC5W.. nUFXSfvttCi: .. :ygPQGSDSh*gb . ..ia4h]^..|i$mVd*CAUDu.. .lhYeZVTs5&!.. .=u96zI6$n=.. . ...?s*n|...iPbq*Y8pA*n;. =
c%^ ..=OLCa&YIn8= ."J4L86yG4k+ "DWQxDQSsIs . ..!}=oZicz{3{"rOdbA*DnyCC~ ?8kL8Oonzc2t. .=*o|"^~lZPgK . .!qDQarvuCJ2L . .ITPW#uooont... .%qPbLJSpmUPh. ...!YZYG&aDOsg2swY9ZTrD5Lu. .iDx&bFdDPPz~ . .!3Cft"!t$8J!. .. "sT*GFDXKWWS]QqQxq0hPXq^. =
3[^ ..?PFamG&LpF( .!Gxh*nyr3&J. "KFDUUFFonV. . ;|3o3o8c+~"\~~7Cnbgx8C333! |G0O4mGkVnu+.. .=Y**TYGTmeFW ...!DUO1yzys8xx . IfsxFuow6y+, .|FZPL2rTmQWS. -xakmdUe8!!nPe9e&o?iT]ao. .jQZY6TGbZgnl . ..\IVhm7=z9)... ./wfJc}]w==0hUbQm400*&Qd^ =
f1^ . ,?SZ*n5cQAQi .!ASdegZ4*4} ."epQQmAFy*0. .=smS5yLa<; :!y0VAGko]ftJ? ?pp4VGV40GG{ .!asO4gDq44dX.. !q&6&bQXFQpP . 3u4qo&5yC(, .. .~dbph1cYKXG.. }p*0Tm*qg.. "pSaey/^_r0Uw. ..+UQh7)[y&dZ{ . .?na*kG{Cz%C!.. ;o9v%jJur=,.^)ObOuY*aOSFU^ =
f]^ ..=4OpT%2FgPi "VdUdUDDbUw .^5ZFDY#WzV* .*WK#qnQp". ~pbZx9T61vi~ =*GOGOGmL4Lt. .1oa&ApFe4gK . \hxpSFPFSWQq ..sncsAkCIC+. :=FAPh[1ikWA6. ,2DKQaUpYx. .&Z8A$^.>6qPz. .[AFps9aa88k{. .<L8*G89wu$$=. ..)051vCY6!.. ,tYy3kUk&ppQ^. =
r3^ . . .tQnQbywY4Y~ .!o&&AAAdFPs "U$%8#&Y9xb. .uPPLurVXF+.. ."d*YIf5*[[G&=. !raazIas&4*7.. . . .?U2aWxsDF*P . ..!ePDQDQFDOu]. OIo2u+uT447. .!sPWdl+7n[Ia. .)GWWgO$LG {ggqo++1PFS.. .=dAUdy4Y&&g{ . ./CyIC]]r$&i. .!$GT+c*wmL). . =1[khQb*nDg^ =
c2^ . ,tXGt5VTfaO= .>h5L&hgUQn.."XGzoae8*Xg .!F5(~)IYWPv: "mw5h&2r**= =yJO5J]vf96(.. . ..(D8~thFC1nOP . .ppdhLsCui1$....69nVwfuzr. ..\$#Xx]$Tynw%..=mhKQPV06CJ .+hhxivcyFpU. ..)VqdZVx$fLZl ..,t6OwC7f6ws(. :IxxT[Ynnw~. ^=TdpqQUYxZ^ =
Jf^ :.. .,tKxi6%ausm= .!psGf]5kYe5,."XgDhJqSmF&. "Zi?!!vTKgj.. ^G5Vab08$wk*( )L$r1uII6zt.. .)dUT%LPWJv4Q . ..^J$cuttt[fkm. 22*kwaYT647.. ./3pPhwm9o5k$..i#hbbqw$IC(. .7Z&9|w?iPbg$ . >+5hSg6urIZv ;c8mw2[2JV[/.."&Z*zfwma9a= . ,iUdPFdDs(o" =
Jf^ ;^:,..|ZFiJ1LarV=../Ys52|0aJct:;"bFx8&48xFb :ppTnYV%LXUI. . "P095d&&$5k4t .|8Or1C9TyG8i. .. =g&[yqXeVkg. . .;=Ja[$u35*Y. ci$Cn*948Lt: . .~&phT55$5G6..=Aoosa[{]u~ (9*0wy=?nUQI.. ^6sVb4?1$TQ7 .!OYz$3%iTSf=..~S4GC+cT98x?. .^nAFDQFPG;!; =
f2^ .=!/;:|SD{w$L*fI-..!ezLJ!nY49=.;"FFSO4mbdY0..XXUTT4O0PPn, "bctx*m*Ta48t. =O84$oosoG4+. . . .!}~;^!hPbaqD . ..!aTf$%L&[kmk. . ${IITmT69i:. .:!IaZez3Iw6YT..(zosTa&Ta49 !vom84Vx*5V3. .=DVGeS(Iyq1. =o6f]uw5DUI)..(U8Vvlr&sQW|. ~PQF4DQUP^:. =
fJ^ ^tTnt?2mOszzqSc:^^!hmk6]i99Oo.;_Xb*50Lxd01;"TebbeV0smD]:...^u(rU0O9GLYm)...)8kV*z$cwG*%.,,.:.,:,.jKZJ~")gQFFa...,.(SQPDhV6rJ$Y....cICY&TC6C9j;,,,.^(3rzm]2Ircx8:~0Yq08m8G4hL:.:.tCCw6r(t4eZ+....[AQ&7inmwcU}.... ~m2fc9VUdg3~. =OYme8L9Tnf". ..(&0kT*Qbg), ....... =
fr" v5Zm9r*a5IqZ&^C"<eV0+CkZaTl.;<Lry04as9t13?wQDDSForn0n:^.^^uI8e0JtxGLm)...)L0Lk*T[f**],;^;^;;^^.7XDAholoDPK5..^^:>0PQPQWqrfcY:,^.rw$50O4O5n+^^^^^;t6u3sIo91c89;!zSe48*8GGAn^;^^!=$TVOTt7sa! ^^^vFq2=!sh0+01..:. ^^!12cY&40f!..=qqAew949&o!....{pV84TQDZn!...,..^^^.. . =
2r" >58qpLnIaJegh!s^!6u+=f&As0s^;!CJ4O5{Jwayu"?lQDPF*)7*a^;^;^3TO8n^5x*m|..,=0mLG84TCy4},^;;^.";^.+KDAqSGaDbPa.^^;^-wkbPSDU*ocL.^;.20zswVzys6i^^:;^;fa$fy$m8itvr^;{LG**8maaa;^;^^+ysm4q4YT".^^^%g$"ifIs0+a+::^. ..^iII45Om$!..?pxU8tTP*x0!...,|ksb&wdQAUv^.,:,;^^^; .. =
rc" rmGqA*If1mbU{n;_yur5f6bJ!!Im5$]aGV9".!"feQZZ}5n^^;^"s6bkt^.?Tk*t^,.(yaG*O*4nn&l;^;^^^_^;,=k*FdpAgZQPk^^^;^/%0nhpFKS0]5:;^;C4CuJI3$+^;^^;;zo9su8m(=%[^^iY5$$nu1f9"""^|5I6Ls*Skz[";^^^{6!.iY5y6iCt.;^..^!t6&L&VPkC_..)pUxT+kDOGk=...:taGZs1VDSQ^:^.;^^;;^^ . =
J3" :/yhxxGGf6*Sh0!!a+7J9L*8*G8m$65TTzuwu^^~n]$epqDxa6"^^^!YG*91?".^}O+^^^tuifnYLzmnIi^"^;^Ii^"^jg*~?+{%zmxg^"""^(rtjrwzo0*&^^^;^vzaLsmG*&sj"^^"~Js[C*J*a6CL&5/^==3uJv~OmxT"""^fxO8e6+ze+(3^^"^]e0naYeqT=T];^;;:?U84a$AFLJnj.^"dx4IkWP*45);^^^(ZFLzzIhPDq<;^^",.,^"":.. =
fc" . ?r8OVphC8pbk~!]1!?2]CC$wIL$wI6Cwc$Y*""+xDWFU4hgV]""""!ffomKXS=;!&7""^(ryT24Ooh6u1^""^=a?"""%n7=t{71a*Q^"^""to^=t2GOa5i^""^^}xAmGG4Vnft"!""lmCC4f9II50*f~"!t6$rii*m0w<";_CYoTmT+=o%!J^"""%VSgAP0xZuo7^;"";)en%C0Dbu{h%^"\o7tIqDpzsTt^""^lQ4Tk8cfVdU!^"";. . ;"",. =
3J" +Cl&mLhzomxs~+%""$01J]9Cj$uCk8onTuc""=ubFFPqbLG>""^=aJCxDFXejt9{"""{k4]n53mnT{"""!fJ!""+OkGeZFSaaYS""^;"iO^^i+3owV!"""""jh8k8kos9cc!!_ifiwCTuICz58a](!!+$11[&kG8f!!"!5*8*m&u"=1|%!";.=$0h8U&hG&ni;"""^tT2+aqF0}$q1^"^>i]fVZOn4U7"""^9&&fwaJ[CLO!^"^.....^^";. =
Jr" .j6(fOqVGoTe3"!fv_^lw%%kC+i1%CuG*Y09a=!!iSQZFbXSkz<"^!tG%jQPDDQhw9t"""jXdr1]1LTO%!-!=4J!/!!CSQPPQFOk44x!()"^+e"./)tI*&"!!"--|mY4YyC$163]+1Oat}JIwC$C8s52tv!!(%]uT8mGm2!_<+*8I5gky"=i=i!":.-!}y0wuoswk7"""";)fuJ0PDTcLD];"^"vS$0ATaZPl!">+mTC]zT5$Tkai_";,.^^!\.^". =
2f" .^"""!!7ffji~ti1rannxs1lcaaVnau=t]uC$n9oT5wwzI}8?$aw{nwY0s3DGtPboI&*eDhs5}!!-]0rr1]Csh4zO3_[g8(~|(=c8a6y6$z9[$S(Uh4~rh[=ijt}s{!!!!!!!}fjtI9o$*t3C*y="Tl|fut+j9c$x5?t=%&O88**J[?!8&m=7m9v}%j~_^"|zy^"+[jsv)iui>!\~~vxOs6Y*pDPPI!!!_~&nzO$*QKb612VmSSgpqYs*een~;"!1dGv++{i?~"^,. =
v3" .!$$Is40&hpbZgbp&k2c]In*&OCzOG8T0v+[5J3Cf6w$r3Ifz2bj|Is0hV4gU0S4=AWg+1ne9TZ]=!>tj7tj5sok3Aj=*gx!)=|}24T&O5Ow+t*Dtqn%]aPqZsGd0C?!<!!=!=~1Cf$f}0k+fYJ?!+wfs&6i=+31LpT?=tJw8LGkatv9iJ}+1=?utn5="_+cY9!+f56sUo!ir?-=!|tnZksY*a4qD*1=!!!!t300aGmL4VhgGkPbQpdoGxkYxl+c0bm}3azyi^;. =
22" ,>6L48eA0meG*GmLm4*i[Iyw$+&m***r1Jizw3[I198Yw1[+{jfFjj[YSQVkUx31i=Z#XJ&Gxs5Fp2t!iTsu%T0YO%spJuS8a~=iJOGV4Y84yf!]ZF)Tmt5APPq0mbS}~!!!()=||+lo828Dn|lt!=(&dSA2%v]f4eT!tvvJYVm2?"[$t$]n5C6$tvCm5t!y5)+f4h*s*G{7[?!=(=+fYuTmknozTrt~_)i+iCgVaGx*YOn$]4AUPDVo4QIUAJsxDQ9}JICaI{>.. . =
J%".^|Aqx*8epO0hV8meGG6stCCC*u%]8yGs$!)=i86c2]t1Oz*v!!"!yFClil8AgU05a!)~9KD$==))kX&~!<!=|=t~~)=~=TS%8gL]{IsV84V*kkf{="?tt?+hCi1w0m4eLY?!!=/~i?===|+5wgDsit==;!lUdU4it+2tIkST(1cccuVI^^!Iwv+%Ogg*0z*G0iuu[t$Z0&s1zhc=|=-==|)?+{+iiti=!=tii1v%t3dmzUqgp837}25s9u(ihU%69{SDUg[3no3i!^. . . =
[f" .;\(lCL*xU4&syCo0YaTV7$Clru6+)ttitnk9$o4&Jfu9o]i~=zWei|l2aC]7tt((?ipDe{~=%KXw~=~~((==?==~=}V&20OwaVLem4V5f%lt|~=}j+ti2%"-{f&Irv+=~~~(|?lt+iti1xSQril+vuLUqxuu+1ll]8pbn}JI3ftt~+]vuwj3{~)t$n0Ts5kC$oIzTI3{=!sFx2=(!"ii|=9[=)t{{7?(t]%r3{jYp5{55o3i|)|}3[[7+]PF{czkqghJ~(=_^;...... ..=
J2" . .!([mm*8oIYT8&ssSbT}}vtuwoCc4cqULv3s6w+(nWQ!tFZAL}+t+++=$WFh+|*FWu=!|=?tti)=i?=nmmyw88m8m&8i|?+}7j)tv7v+)}l}it7]i!tlt~+ts1tiA[+ii5PDg7j+IddAqkizQtff1CSqh5InJ2j]l8F43o8=: "2%[I$%1ooy8zf+(nQDd++=^+it]g%ii=|{+tJ+iju[lyggyj]j}t=\!!=1r{ot2FXvaDPASt^.,;^!()+++("^..=
2v- .==Ch*V8eiv8a8*8wASgkj+ta6oJvLv4DFswIo+9KFr^!zgAFdt=|?|t8QDt!hDZ%)(=i7tt+(!(i=[9*&*Gm4O8nl!i7%}7t+t111t>7v7j+Tli/)]v=!j6&f]iDsi[j8QQPt+7*SPqA!wFftJcyZdPsJC]j+caSPL%$ao!.,?2[vuGti[+$w*88ksIzSPpl1t!+7sDv++t=+ttntt]%t7Gxbf+uTn5T5ojj[]L(%Ue3dFPGt^,!t{aGxpxge8w+"^)
J[/ tc4qkG*5uG4GVUp[0*xPY!3Tmw++nreZPZwu$${IWQw"tjmFdKD&v>^!!IDpI=PXQ{(=i][}+i}yn*TI9Tw9u]TyoIl+}+i{t"+tIu7^t$I%i0$!^tc%!tLAn%%}De}{2xgFU~1*ADeQg}+6pz=$5sUUD6I2c7%3sAK*+z&IJ^:^1r9w*m+=t]lIf9mw*6&uZgD[ji/"(T4F1ttl}[1+*1|=j16eAh%{9TaTG4s9yari*lIPhGbFSw!"=0AZZZdgpSUzt". =
J3- . ^CY8*8T2|*8GahhxC={CVn2n4mt!!s9r6mKKenoIc{eF4+c6G0OFXPqVt=/"hgxnQQ&6$%7}]3(+2mxgUG9u$f20kY*&V0o6t=yt9$67^![cltmO!=Co9xPx[%uzQPh2jDFbm1GSASni=tfceerjw5DgD5oyfruu$6r|!Iz&6j=|$TV8af(tcJ$lt$osCcuT3gqZG+7+"}hPe1rfljII1S5%j%2xQQmjtoknYY8&4ekOeTVgUQQSZLa0hpZgUbd8yt!". . =
Jf/ ..=TG0r!;(Gm45b8mh.,;/+w0To;!^$w52{DKDFQ3u73Ae2JQF!IQZPDQD=IAqDDPp#4u1t[n7!uxFU8mivCfnJO*0Gm86C4O3nrl?(]$uilqg{IVFUULuo2iyIQQ05PDA0FgFDj...6n[VD0{vOAFZ]7uJk2$5^.^f5*$(80*Go9t~"y*$L*{756I}t==YpPQo=+t4A#012171+jDU0cz4bPUv2j2mT94FFQ0&V&TkLZQk4ZFSDPDPPPhs|";. . =
JJ> . .:&oLV*&":;]dG*CqmVh,..,!nGz3.!"a9ou)Y#PFFkcv%FZzyKWt.!L#DgFFgG%&pDPQWPTav=7IufeSq8kG2f2oGL29nV*&Jw$IGaJ5vlT$CIjCUb3f5DQUm1[57/%3xP4VDQh4qPPA^ ..O%bDsikeAF=/+yAJJyy",;3$$][V56y6!!~+yw2xO9fykfi%?zPPps}i+hDAarfucIt+APkCzOgPh]59362apgDDwoa6xUYSUYpPFSFZFG5%=^ . .. ..=
23\ .^ckG*gC.."w0Om7bGk8^..,taw5!."^u9as~+xPpPFntcPZO0PD\..!LdDFQDAsrGDqF#4uy+^=TAbg&8fo6viuaV4w[1uCLnJafu*5vCCzznIvurQpwzebdF3vss1i7tYQgYPPeAQQxl. .^TIttVxLisFAe!:i&PLu90i^^}J[fCocI^;~aLzzrdbGsvI9%{{JQQpktt{FUP6JIrJ%ortAPAz$bQp8]Y8}oVhSFpa}$C$0AZqLLkqZFeGni!;.. . . . . =
r2\ .;t$sV*0f(..^tGm&e~8V8G".,>2J1|!>|?%TTz(^>{shFxLC8PxghO?~!\=1[SbAxhTLeg*ouf)!|9*e0ortjsa{]Two4Yf2ura]{al5n$TasIcjc45QYOxPQe+!20n5$GwoeZxegZh$+~!=ilJOn6YZxn&hdG~l8gZ*iin9[=]3JC>rwIt:"%GLT5zebgV5cc{~8Zde[%0QQZ]6TzIo7nGZ85DDF8wTuxFQAGy?^>|I0Aekk8x84&nIJC2(".. . .. =
Jr\ ._Ca4&4%. .=mhmG4^3G8m=,.(aemmSKXFdPDbA&j]&hpDF[nTww8ksAFqAFPAFFbGA4q4FUc)!tt|t{6)!&xC?c4YTsV1iC$saC$$ouz*Lmw!;;(D{aqOUDQx57IZDFFVwKeaSAxYOG15GZFPPpQQgbbWPdhOsiQgZx=,;tmozuwwo~azkz"iCTG4wuL[r*xAAeIc~tQpqorpQZZTJJ9J3l}CCYAFkFDqmY$IxDQD*sgz_[xXWbpkYeDADAPQhf2f7". .. . =
2c_ .^+8TnTz . ^[dm0GJ;7OGm|..={CLAhKFdAZFPQQbQqxS*pFl3kdPUQUQdFQDDAUUWkkmZDFd[;.:,;+8y]LG+!ukZma**3[J[IOsuCI50*9[".^~b[apbQPZO44bFpQdPTPUmpgzCoUxPQFbSAggPUZQWPesskCoUDdv...!w*ns96u?wTY[=rGTy]|s9uTdSQFxyvt!kbFVJbPQaPC7%7fsLYbFD*DQb9waYPQPd8pb*+hPAqDPa&Ad&pQbDbAd8c(;: .. =
rJ< .!n8ayt;. "JL0*mf,t&Gm!::+^|rGXQSDQPQAAZQFFUY5IYqWWDpApFbbbUUPPFI+v&O0DF3.. ."sD1+*kk!!u&Z8$zm4oI+Jys$uzaoCIv!(=tba4bZdApqpqbUDSQDPwpUD0k*DUDPDDhFFADdPFqpn6*U8cVbpDi;"!+wL8sz89i6z$u240LY==LaJ4qAdDh3v"2ADgngQF1WO+%ueQdV2WPDeDge{9xdQqgO0XZYzI*SPZD55D&GmPFFpUQPb5_^.. . . =
c3- ."~~-;. .)0m4YT~.>$&G),;"...;<1$G*dQQQpgASGYVeeAbKFgpFPqgeSx4T3tVTYheTkx3....temi*hef;^7kmhn)Y8Gaf3Iww$JJ6uc$CfcCe*xZd*eUDDPDdPx8z+%nLhhe4hPphSA*O4aOmO5u6hhZg06hPAh$nVLxo4k4wwwcwr9y6ms4!;"9o5J7USASpOr+tDDDOFpG=FJrOSXxnJfdPDZdQ6ugFqZ0+"iKQhl+8DqxFh3PFexGheSdZSPg85)^.... =
cJ> . . &GYm5!...-uk=:... . ...:(2C=""~!(=i]lvzYyzj)_~t)>"%dZZZFDhDd{[=: ^j!,(UZ0+..<688d~!+ra8Gowu]=|ITnYz$]2dgO8wGwv}!^"!%rC?,iFqbcIhXPFFx\,,.."inFDxd*35UxanaVmwsmyo9$v=iifa9jw6T{..^owoT%tlkpQZd5uxDFqQ8!"yDDQF40PXx0dDZq51mDPZi;.,^ion5pFpJ5DA%sUFb3/;"9SSDUdZWK+>. . =
J3- . . .VVom]^. .^7a<: . . <[3^ .;^-ir80&Vk5T!.."";,.sDSDpUFPhQb(!+! ^"..+UG4~ ^C8*8+"t58*8o6fu3cJv=!?ticTghSV0GJti;;^yak="xPDF4?}gFFFPTi"^. ,"$DYpG5k&kAd&6a*&e*6$uII+7+I$?%soy!. ;$56yf^.|GApbF4yqPbDs/!pDXFg=2xQbVUQLkYahdgd)=?tlv3ossan!OQPu|pDDD{^.^!iaZPeXgxy/ . =
2v! :0kw8!. .!s". . .. ,tJ:..^|}eZq&LbUaei..^...!QQpDqbgP8QWt.^^.;...%mL4^ .^JmmYJ::!I*9o[icz$+;;!1eDSS0GkQ4mx$t"^yhY!jPPdDD]=+QQPPPd8+. ..~smbxVmnxDpg*1[c4Tmoo$uf{+~""CaVt. ,1yC?..;!sQpUO}eDVDJ!wDPQP*;^isPZUd44LeSdQYaOhgUASd*G5t"agDC"7UQSA],..."(nbpeex". =
3v! ^k5*k:.. .;[^. ."(:=j0SFggZeFUUzIx;..._vGPDge8DQFIQPe".. . .^z*$~. ..t**h$;"i06$y9$$Jzz$?~LbKDPmfzhepUQZh*sGYu_PQKKgbg6=thDPUPWF=!i$VeeVoI7tt~";:::^!?iwo91?)?lyz3t~"^"tu$$[?=!"~LxZDVGAxxtupPe5i".:^=Gxebk4LheAAqbPPPFPZPZQk$)n&xC.^?eDDP) ..,^"~(|{=;.=
3%! "5ws{. ..^^. . ..^!wUFhPFpGhFPYGDV^J+./&QPpUa/^gDQG"5DX+ . ,i$!... "dGZC5G0$!kTC6yIIV62zUQFFQ1tqQ8qUFDZPShpptcFQq$PPA:,.^eDQKPpJ"\|IqGDFPFAPh|.. ;nkO4L3{aI$r[c$G*8mm[=LeUDSqZADSpPbYa9Y$VQFJ+!^;^+VqhVV*0OsyGFUUb&5ksvjl==!^:hFQa .!FDK*.. . . ... ..=
3v! 6s6! :^. . .;+TAQpDqF9chbDowDx,!]"$DUbFG!:;DQby:tUZt . .;2t,.. . ^hAO3Yko~"2kzwo6o3aGuC&KK8YSu)yFpSOTbSQPhT0oG#KViFQg^ ..~seWQDbt,^tyCFAPQQpDq<^"(}%=C!!5ouii(JT4mmLat$uexPPDAPppPQ4m&8shqDs4ay6=^<+ZAee*0utjl{i?!><"""".^<";SDPI . ;qWWx^ ... .. . =
3%! .!T43, . .^ . ;=pSpQdZe+cZDZlJDq,.")FdDpDv.:!PQUt.^}x+. . ./J! .. :kVsa]!;)ayCIu*mCtry3UKP9kD6!ipQbn|vbAZDgdsxQK6!QDD(. :"=9dQUS!.++7#dd*ADQPWe7^.^;,t^^o8mc(.^!=++]2tCCIz4QPbgQQFdphV8ObQQFFDpAGr="iap4xVori!^;,....:,. ."^.hSF[. .y#KA. .. . =
2%! .=V]^. : .^lmUgpgG5=,^GbAS"JgW^:iYeASgV;.;jAZs"..^~( .;~_, .. . .z3Iy^:..ukT7+2Y&o^^i8KK8$qp4\"eFPh~^"~9GZg5PDXs!mqP. .;|zmmj^!;+DPPs|rLPDWDn^...".,20wz=....:::;JC/"~(lu6Tx8SeUAeDPPFdUPphk+"t7(FPQpxn[!;. . ...ZD#i >fSD[^.. ... =
Jr! .|;.. . . .^wb*p0nJ!...-yqD*=.!gq"1edPz!....|ZQ;. . ^^...;. . }4qz. .:Ym5!.^{0o3^jb43PDS^."LFQK+. ;:^_gKC7&taFF=. ..^!",?S9qb(.."C&PPA6\.:..:i;!x8=... . "$C; .vOZDxzPP1=4Qx~:... . ^;:(FDAL5UQdk?;.. . .nXP" . ;wh7^. . . =
fJ! ^=. ...^jqx&a(!;. .vgFSi^.^wd!kdgw\.. .thg!. . ..:;. .. )08z ^&*T^ .!T6o!5h!!23FPU!..+QdX9;. :..;e&!_~=+hX+. ...;,^^~u?2Xy;..^!tyDxI; . .!.^3dI". . .:=2:. ."qU#pi3QAC^^=mz^ . .^.,\DFg47LpDPO+".. .A*; . ..=qI". . =
JJ! ."_. . ,;=v{t~"... ^Vbh0". :tauqgn!. .. ,tQ&^... .. . . ."n*{ ..^G9J; :;wyuc6+,.!lDUAt^.!eFK8>. ...;h|...:"yX]^. .^ ..~+;?gQ=.. .."J*q=. .."..<JOt. . ."+. .;6dQUt!4p)t"...)!. ..;, .>gp#Z=t*DQFh1; . . .re%, ;0L!. . =
f2! .,: . ..,:,:..... . .~PFm!. .^vC)":.. .^3Q!... . . . .+&t >m9=.. ,7Gr:. ,!PQP%t.;ieKgf". ^),.. ."P0. ..;;. ^^.;zWu^. . ..:^";. .:...^29;. .. .". ;CxeC";1x|^;".. :^. .^"...^]aDW|,+&PQD).. .jz". . ..!i|, =
3r! .. . . . .. ..IZP|.. .:"!". . .^9e; .. .. . .^{~ .=Ti^. ~a2z^ . ."SPh+%".^iXAg{. ^;. ,nx<. . . ... .=#Z!. . .. . . ^!^ . . . .=F8=: .8t:. ;^.. .;^:. "^igDl .!nDAI^.. . =_. . . . ;!; .. =
cc! . .. .. .^kI-... ...". . .."+^.. . . . . . . ^^ ..(!:. .,{aw! . ^SKI,:"; .uPPG^. . . .. .!G>. . . .. . :$x).. . .. . .. :. . . . ..!~^. .". ."". ... . ^.^1b: ..^"C", . ". . .. .:.. =
fr! . .. .. . ../9<: . .. . . . "".. . . .. . .;;. .(^.. .!y6~. .;pK%...^../0qq^ . . . . ^7!. . . ."o(. . . . . .. .. . . ^",. . ...^!.. . . . ..!oo. .. ."+(;. ;. . . . . =
c[! . .^>"... . .^. ..: :!.. .:ow~ :hF=. . .~8p~. . .<>. ^!. . ... .^. ,!r, .:^^, .. =
r3! . ^^... . .. . . . ,; ....{9~. ..&V^ :|$7,. . ,;... . .;... . .). . ... . =
13! . . . ... ^=~.. .}!. . ,i^ .. . . . . . ; . .. . . =
J2 ....... ... . .. . . . ... . ... . ^/. |;. .. .. . "^ . . . ... . .; . .=
crt??()iii++++it++ttt+iiititi+itt+++|?()(|?|)(?(?()??(|)((?|)||)))(|?()?)()()?)?()|))|?)?|)|)|||||)(?|?=?====()?======)l====|})============+==================================================================================================||=)=========================================i
e3ZYYd
sIRC4.exe
C:\marijuana.txt
uk.undernet.org
Runtime error at 00000000
0123456789ABCDEF
kernel32.dll
DeleteCriticalSection
LeaveCriticalSection
EnterCriticalSection
InitializeCriticalSection
VirtualFree
VirtualAlloc
LocalFree
LocalAlloc
GetCurrentThreadId
GetStartupInfoA
GetModuleFileNameA
GetLastError
GetCommandLineA
FreeLibrary
ExitProcess
CreateThread
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetSystemTime
GetFileType
CreateFileA
CloseHandle
user32.dll
GetKeyboardType
MessageBoxA
CharNextA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
oleaut32.dll
SysFreeString
kernel32.dll
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
advapi32.dll
RegQueryValueExA
RegOpenKeyExA
RegCloseKey
kernel32.dll
WritePrivateProfileStringA
WinExec
UpdateResourceA
SetFilePointer
ReadFile
GetSystemDirectoryA
GetLastError
GetFileAttributesA
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
EndUpdateResourceA
DeleteFileA
CreateThread
CreateMutexA
CreateFileA
CreateDirectoryA
CopyFileA
CloseHandle
BeginUpdateResourceA
user32.dll
SetTimer
GetMessageA
DispatchMessageA
CharUpperBuffA
wsock32.dll
WSACleanup
WSAStartup
gethostbyname
socket
select
listen
inet_ntoa
inet_addr
getsockname
connect
closesocket
accept
0,080<0@0D0H0L0P0T0b0j0r0z00000000000000000
1"1*121^1f1n1v1~11111110272
33E444
5X5555567
8/8:8E8M8W8a8k888888888888
9 9&93999S9Z9d9n9x9999999999
:2:J:R::::
;5;_<l<<<<<<<<<<
=#=|==
>'>,>2>>>>>
?!?G?S?[?????
0#0,03080>0Q0Z0x0~00000000
1*1J1b1111111
2$2,2222222
3!3+31393?3E3L3V33%4C4O4W44444
5+5D5]5n55557
8/9X9_9f96:K:~:::0;7;f;
=$=5=>=T?[?l?x???
U1]1f11222
313G3^3s33'5555555
6.6:6N6X6k6666
7A7H7j777'9O9V9n99999
:c:v:::::::::::
;4;?;\;f;;;;;;;;;;;
<#<E<Y<<<<<
1U5^5i5n5v555&6-6?6]6f6r6y666666
7"7)7-7G7P7Y7j7t7~77777777
8,8=8N8Z8_8d8k8r8|8888888888
9&9.969>9f9n9v9~99999999999999999
:#:/:<:N:;;;;;;;;
<"<*<2<:<B<J<R<Z<b<j<r<z<<<<<<<<<<<
=$=.=8=B=M=_=r======5>}>>>>>>>v??
0l0{000000
1$191X1q111111
212I23g4444A5s5{5555555
6'666E6T6c6r6677z8C9V9g9w9999
:Z:M;;;;;0<Q<
=)=7=W=g=== >s>>
1A111222
3M3U3`3|33
4555)686\66677]7776888 9>9i9999::
;C;;;;
<2<D<<<<
=-=p==3>?>L>^>d>p>>>>>>>>>>>>>>>>>>>
? ?-?5?<?U?Z?d?s??????
0q1111111182R2k23444
5I5V5v555
636Z6o6666666
7R7o777777
8-8M8e8o8v8}88888888
9+9J9y992;:;];;;;;;;;
<<\================
> >+>6>A>L>W>b>|>>>>>>>>>>>
?%?0?J?U?`?k?v????????????
400111
2,212@2N2222222
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8h8s8}88888888888888
,000409999
WinSock
System
SysInit
KWindows
UTypes
3Messages
iconchanger
sDeclares
PAPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADD
<duXwu?&
W,@@lCH
#!?tbpz3fF
25cmPq
P.,v<q
V".j8EJk[n\
Q7qgNEF?iHvV/OB"zV
6tk.T,
nR<;W+!%=B
Y0ZZ.X-c
cX4uEH!,_
U8Dkph
I{7u+F|$rQat
0lN`EOX
m:3JH!g26_JhiOa\$XlFmSgv
)LNT:QzHa!
I8@DwK
!|R{.F"<'
"iN&tR
AGlI&f
xA9_/M
Nipi-wOc
Xb,Fml/{DbIwzD
(#o$O~w
KAp(<QN)
-0x{6fpxB
d:bx,!VFiC
CD5s.I
\&znuLE4(0=
6QbhLcWg.
4aft|^'"
nOj:~&<Gu0
'o;\!07
5gC]ck
%@V:)w
4)`HlbR]L
T:>bZvRR
&&A74p>j3C
Gb9>[-g2z~\
JZ%x:x^^
=f`O+t.O]
Y,i&oS
W_nDVSW
>f!yX#6
8P79Av$hx
3tJE7h&
rUXNGKy-mvV
\<ah2>e~G0
\-!.OU
D8c?%hQ#
3^HVUtfdb `.CAq`iz
014b#Mu
vL~Nd'>{
uM{bdE
z}0H8X
sb,cSX
GaZsBT
eWN9$c&VE
/qy(7q
n>#=Ha
&S]z"X?P~
{[*oTq`
MHJxd;<2
,w8|{\
8<#e{S1
y"+3Jw=a}2
_p+c9@
6HN5wT_c2of8x#
G}Uof0x`mY=
|Q@Xig
7?N$hRJ
;.0/e.
e]zAKHA
[v&vuh
Z9G~*)
z=L6dXwK
`4)c|!
HW=z7c"
XuAExg
v<C%?}Mqm
84+Zm
0m9AMfNSI3Ag
rTB=j\d
l"xRtWM
dCYsl{M
w&Sp^.
7iS#53
6ex?3C44axy
J4%0.5tek!DH5]lj
U$DuUGy
X_24vOx~Z
[e^r5*
]\t>ESHl!!?5MkbV
Yx$3D\\O&
%N3m#V
U%VNI,
yVOO7F066H
682:rw/I/
2+reNDo!4vf%
&!6o`<42$p}
ui}Qj9:
m5LZgSe
hUUpaE1Hi)
vKJ%P-@Dw5IScpn
;$*9[u?T_%
u1?YjZ>raSbeN9
^h(X,t 9
g"+X(koa
^}nql`~HK
R<ELdS
{Eil?L^
'"J=D*
)RV8,E>C
7sE+zU
G<#M59AQE!h
*v~Du@HnHX(D
~9Te4R|
b&?3_u|
v!1:UX?
{#i!~^JI
Kawsj]Ot]3jP
PTn+@!9r
aS^WkhJK5
0D$k%QnY%'
DM:*E:G7$yPh)U#>u!
:LJe(<
{xB_SZ
a;@Hfty+)
[Jv&?dq^
{MGf]*CY74Y\*
7]_Ptb
S[^v_z
W,dm5k
fGRNEm
.qb*k](00Dw
J)J0UUx\;n
BV;*gel
{\'&Ao
BU"f$1\/bRX3
V7lqIn
YYlu2/?a{R^^FY^[lc:&yR
n4H%w~
s>3d,:
3q3x]uY6SVoQ
"=wTUg}&jr
-6Z."1wV]!
JOA;i-x&
3z?G~I2
`p5x_+/S
L2IW&kJd<
=.Y`W|
R4JSUpI\u
A5'Tp:v[W
G*|FwIrgQV^^Y~J/n|hcE
y3K`-b0g`
\$$]1"=
doVr?s
[PsB`4I5
}Av!<]^2>vB4$
Q4sO@/
POUKP`+k1
||._{YslK`xbg
W1l|&5;
$H+iEh
@#cd8/i<TJ=
cl6k"-[`u$
GfiA*d;
iNr+|Lhq:9{}
5&q+'P&c#m
'rP,@T
^@ac3~u@t+B[m.
{rhIdDx
7dwr|YT_-s
":F<q x
4pa0tdS
b}m5\K a
Wka4L.C
kKCw:,shD3_
A( M^R*
+4C()}
bf1iT~wBIWL
11D\!Mw
oHKd0/
EVNs3Q*(
pL80>KaA
Mq% *x(
2`|r6TFr4
K ~=d%
@;ytVcz.>UybR
&7a+A
d;'ck `NZ
-YEEu3CR*
5(-lBQ0!y9y@g
^S+?#Z@%
7o{?miGio
a81WztmC\P,qd
95"Q&N2>
kQgK$)V|
pe/'Ws
G0O!G
v&0k"}
+NU8(6\CLCV8'
SKnp[P[W`
W2Fb%Bf,2L
*V_C"H5L
@m1E&10
#IhT"3
`8!D15AiDS
MsrOk}$|
!1To)&:8
mY)O:+~n]0PE<?J_SP@8+4cj
&#A!n<ZAN
g]WlsX
h|@5k4(NZ$
]&FtvR
*~y6Y,
cu;>#d:NCkO
aS#J4io~K=ma~'|#oa
OJFt/3/^
muRJ"i
;vI94+?Sf<
jl:~o|
[.;}HO
#t-[?R-4
l>7[k`~y
/nJXII9>ka
LL=@9#Cj;6
.6ZY!I!a
YAEZRKZ
>{KBn@8[?
^+0.Pt
DQ$t|l
#BKFNUd'
~WJTEvUMj
&=Qh$9
M&-X^P4
PZVEW
*BIlUS
N%LV^9Lf
3zw=t3S
N@s~?z
c-:O$[45Acj
hEvS~Os^8*;`~9
MWA@ (|yW
4;Uv+
mkeEvT
f?B8%_W{(
gpb{eTv:lsf
~#xI7)[
FyC;P2
_UO6Cn
Wk7+TB68=
GUs"RBON
?mBW\q$
JY6WEn LN"
}rR(%&v,B
uGM@,AX^+
Bpz0Pr
efEc_WR49
]qAeNL?
Y^C00&
K[f##uWP$].&"
+"rO~i
Wq(jV27
cm)~3cI<T
&V3>c45
l$8i]rQ
)H"|hss97np
XN{q4\Q)v5(rtbD#L`@
D?Pr<{c7=0!=T_M
XEn:8}
E{|B>y
Du jR=?
'sxm9W
HJlQ}3Unf5
^Li}IL
sO1Tb0H
WKcbP^MPOYbGY~6$:
%wMWb-
|(hjtE~cP{
k5#OB>
?!]9y `f6C
qG/s7}
|qP!d9E
I a#CEk5e
]crcnv'
af4{Coh
2)WT6nrPR).
3i'u4Fg
z{_!UL
!~t}euDs`qm'kkV2
*_bqR
0n(4yPcU
r.r@=M
v+wa][
8t6z||
/YF8d@
Id=';ew)zFo8t3BSI]
BB0\1|
r|Uq[HqE
pZF-L?7;
gdQ 0S
zE0n2&*_
h$xj!5
,^rxo[FB5zf0
yQ@MbB
BIX:d [=|
gQ$)n
'-A_Z[
va#r4[JS
J,dpVah c
TWljIN
CH/+G3
v0,N,e
$|ad nF$FJG
0y'9T?
h/ >QwaiHa
wq+\r+W
Bh=xkMSAmX@QT&mZZ
c}n,RcYq|b~7l!:
7M5*l3HF
?{/zS}yJ
"iI%;d
MO'dUs
fz=2Q1f"R
IFZ>bl^
6U\E=P
Z9_SrY
z@0{{h\#
NNP8mc| <esWb
lHlfm$,
YS!M-8+6
ET9!NL-(Jy
$91.Y^>?
}Rf1}O]/c|`:
Y/i/Lt=r
Z]xOnJ]
*ajpd@
KV2*]aA(2#Y
I_"u/+
C<C0<=2JmE
j2q8W*i
K&)c[`b9HXx
#'y+v1n
)6.ms^*
hed23#
_/_Abu'C@My}
c]N#Y_
eBgKtlf[
^"D3KZK
>SDqTO
@o9"jP
T"d&Ocr
QTf@OD
5}{K71'+EV
'UCqRd
J@>#U6
y~A\tA
5N/Y"b
,)A14
*|m%*<-
OjNfI\q4
')Upw"
c8B|Q0^
lQ$tVb=U3t^
,wkq~(
6 >.W?RY%-Bv3
Nigys.
?WQ7?wW`pj8j7&P
8-.bq-`U[ac1s
_+R@OG
wbO`Vi
79yjmD|<
dx1Yn^W
lFXAp]
iz#vdc
U3'V<inW
-Wc^uH5
Ud5YU{}0q~Q,r~
b'KC(pk
oJ]Y Q@
7pTE4i/9
}d*W.t?~GSw;Nx\s
\T|[zIl
yz#j$
Q.V >z=
)lOF'e O
$5eZYw
zJ:z=<xt;AO
(<$S[jCaYw
G0`N$n0E)guGChv%
j5*1h:
"_ma6?+5
7y9Y:|*(#1tgteXC<
2J#pti
('vOo6l
K(g_}Lt
|x8ZKAX
:G-PAV
$HUY(U
Kp.Y>@S0#
~.n&$;Z
il;y'C
G=z*EYGq>N4i@S]
?]s,B:'VY
j,z2%<V
kX~GF(
mo K"_
ELj2%-
S9oj]w!+QWR
Kbtz7Q17(
=2e4`o
G^1cr7%GgbvG@/ht
46j`ns~Xu:U
`8X*<Y
V3Y=6At
Q2J'9:
54[G4o
!71<%Jk@
TikbB0
^U:3${vYlSTE
p4>(ICmbl
+q:0c(
ibl7&rZL
T}@o\[1
&a1jo/
s*>H1^
UMQ6tJ*(
Mo9z8D2tK
F[BJk%>=
APR'x;?
}9(K#As\
3H'3q_
!gafjVy,>
Kt_#GM1}
EYV1uo&F='
"Oj]NHav&Qo
g[m#6jg8[
Bd0<Y`\K
$y1fG0$0C/,
!:z#4@+ku
aRMG8`B*c'Wb
G.gt=m
'B;%6?
1#PGY]kw
"~AF c54T/
%Mf.2;j+
aW@=~^
} ~9^gb0(JLWv
'rGo9n!?5
@LQW;g
BKj[H5
-ki#l%
m)n=ge"qMY|
x%!qC]6C]qjOg;
oR,)HL>4G0&bk
GOqL <
g/`b-@No
ZGp`)AXK
W-FhmC
i~Jcf`
5>\5*Uu/
-HPySSy8u`)
*@VtKXU
Wm"2%
yuXQh*zd%
pW2e}z
[fXO5-nMEfwDr
.iUw~,~VV6O
@}f?i<PJ
M's&&F
YIk"y>h
c,$-HjAB0d_
Q$t)]D&
'|S@@o
OO9jF|
Sf]aeC
+2rYT*
{*qXIGZ
i0)d2z\k
[b:oi%
9bQVN2Q
C2``#&
<{ZFfH-U7
]LQ/J`Eu0c
|C.PJfQjM
Y*>FSjo[B^
2(rWgO'
,5}Y~Vs
Ok%pIjB
wNbO$ q
..'[cE
beJ?GJ_V
&o[7%p
ES5L"NAC3D]
{UQD$%
UzjoEU#Cn
s\\!pg
)s@f4L
QC98|y
^oJ]%rT\0/0s-
>t.:k;
<`u+';
D%7Tn{c$*
sY;<*j
:~EdBhd
6Tu6p}*
("!=n@(;$
3dU`8U|
z\0=SvcC
r=\5 qUY@ZZ
r-PrbD
` 7"Wh
N)>pfm*U
0d)vT)
Q4E5e5/psA
vM4gKYA]7yK1%
%[4@2&c2 O
f'dfBJ[o:NX[dH#
2M{RET
eU2pGUf4K[
~yn3CW
V2YNv`C
RwE_V)/-
Cu;/)zl4
p_(B~|d"
.Ku@n0`
C&N@E}
tUlP@":p~
EcCZr_>
au["]_b
oo0R.[IZ
QhF{F&
3j~"lv
d~v:cC
gU[06?+:F
?QB7\w
',hG$dF
F5q$QWimT6)
$I-\w5
>91~*3a
vSZl'&
N1)Gb*
T-n(mLq
hMr'i(
S1GsZZ
RMnGFCr@J`M_t=}
nCQ4-gO
N#c<|p*V
b+YG6#
Ug^Ka@
HL7,J$4
h&`B_0
n)]qVLD3I?*to
~m.T={*ZLna)<^vL}
yyMCQt[
nq-=##:1X
nF-]0ycB
s<9aX^t{$XUw
>dVhLsfmw>*X
hmzmic"4Y^
#fiR}k/SoP~C*Ep`
chPF^d:
#/G@z1"
g+;18-YN3MYy>
v)7yF0<jSaK%t1
>|Xf9LB
p#S8]6
r\`@+9E5
lq4G%,
/nh4]j:?l?P6
..vGIS5w~A\y
[?];iE
"[Dg,q
iN=k/"mEMG3{8&
//$( o
iUCxaFp*
+9/ClPl
N0|l0
Ow+s|y,
{V`PV!'M
yXn-(V<
IUJ%%,"@|mblFD9i7#?+<"?]J
fK>Dn>
%o4}F@8
L<zOkvV(
p s(1@\
4dQlJD~
0YLM83,I
jDp~PP[
1]glk$ok+
arzr`)FYu=
V\h6r%U+g
YG[e(f
IUM2JZ>y)8
^Q#y^M``
`X?BOZ
UiSqnG?*U_
^YF&FvdmGa}Zmg@hz
W\_w-n/@
Kv1Qbt
NCU)#B+
IkmX4u5z
}7ZHD"
9bYpO<w
sYv wW
+UT.,tJw
020P;q@8|Zqc
DSo!Xnx(zGd
o,`;t<
#2mtc]]l-MC|.Yj>^
!V0r2
A3`&R=po%gxIKofw@^
*z;[tH
Mn8rjq9E
-dl3~Eq5*?.
e_&hx8MF
{j!wg]bWN
n#LxYDio
,(`AxE^3
4#i$s:Jg~
$<j:#M2
)'4Xft4,}{)
;/T5M;
l<'yGh
rB<v|PQ#>2$
*II'Io
($ Oho
V\>&5l
GLXjCj<J
^J=BME
E6-A4m/
3H^u&D
jFH_v\RH
cgU:B.Q[M
f;0O+*
X|N/O)~H1e*ag{H~Js$
^2)J8Q
a,~J|qf
N^:!Ty&OB
i/H"r~
#(/vhT1+
@L78g7Z{HB=t
kGBKHK
_G{<C
v_C+QQj%
2s2Z?ua
aV.AfxdN
7oyLKjA)
lxHZ9AFY
+<my'vNZN6n\y
}E<twj
Fv8FQ{
dW#HDtj
#PLm:wZ%c_0V[/cBKd
`N~d">
siNi2{
jCclyR+"74a{Ws
k:O>0%]?
t3G6lt1
@5Vej^
o`31Go
Ytt6A-
Gr@V[+'
1QK[Ht`,0+=
*DO9aHyMnm
{>13c,F)
!YMP*[
8xdyzS
rhDk,K:s
%h%lAa2
:~GWFp'o*1N
8?lj]@%+b4Bj.wwFl^p}u#
!PnV+7
&~~sf`
=Zic!Ou
hR0\9]
ErW*fy/
DyM6Ce
> 0$C=\O2
TsU)l|uH4F}B
}@ <.a
VC&wEQQ=\8
f`=z$1
fA'k^)Ez.whh2
7?t$P>
mE^yC+Dme('
an{ariv"
1H[=]I"2b9
[>ZWCC
TYMc7s\O
vZ2}/U
PKz2ZzT
q1eb*s-y-zJH7
1fU7ViaCJk
+[o|bn=y-<_hC'kpb6P
rjpZq6%
%h'@u
]sLXOtg
6[wM7]!yMucMa:";&,
GK~MT~
1nO-_c
r9)Y,-yhdtW8C
p4?| D?]Qr`
29&le~X!
QJH|AT6:
g,x$xn
XGOXk&
"L/TmR]s
ru+`ms
M/g[9:Q
)ee:MId~
.@zq52
*orv@3:
[Z}6z4
8^?O7q
|k.>Y"EZ7+\fz
j#,O/0bO
STxP*4
c%UNVwiVY
RXl7:qb9
ivc {}
|ZIdb}L
&q5*mBR
/>Pn~wt]tByOLM
gy8(=ZQB
LR?uQ,a/
09=BHSzO
B@,A h
@G8S-\#
_08N8\
govDS!yk
\'Vkhe'%uV
8E<$h"
KpHyGK|
DVCLAL
PACKAGEINFO
MAINICON(

Process Tree


0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe, PID: 1848, Parent PID: 844

default registry file network process services synchronisation iexplore office pdf

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Name 77893e28e58d297d_flicklearningwizard.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\FlickLearningWizard.exe
Size 905.9KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 b5b93ce7a59f5e07ab95034f52e9f7a4
SHA1 76bb7866c2b3d832a058ae4fd65fdc2a3010f623
SHA256 77893e28e58d297dbc58ba51daa6f4936f12b30262e9ada55d5c7644e7b075e8
CRC32 4CFB3247
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 3eaaddd3ed6884cc_pdialog.exe
Filepath C:\Windows\SysWOW64\DC++ Share\PDIALOG.exe
Size 137.6KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c2ee066353871b3ddb7149ab706aa152
SHA1 234f77f93fe25f85e50e1135818fb0f20a675462
SHA256 3eaaddd3ed6884ccd5bc8935a1e48b90fc4f8a29d476b2c6d7b99b49f0b9e6d5
CRC32 FAC176C7
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name e23e20e66fdf7d5e_wmpdmc.exe
Filepath C:\Windows\SysWOW64\DC++ Share\WMPDMC.exe
Size 1.2MB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 c861e7c8e2dc1494da829eb78fd68d55
SHA1 b7945ea1449b751be01e033476858a152eda5c8a
SHA256 e23e20e66fdf7d5e74ad119b3735af3ffee8bb7f38c053b157d9a4661246fc3e
CRC32 5E543F58
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 825c969d3a898216_wmpsideshowgadget.exe
Filepath C:\Windows\SysWOW64\DC++ Share\WMPSideShowGadget.exe
Size 161.9KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 36c990ae36d99f861c915fbf8c07bac7
SHA1 465037b7596dac2e63f4361af62671a26130ad6d
SHA256 825c969d3a898216bd142d149aa60f857892e6252f51c6d34a1bcb3a34df9c87
CRC32 71C2BD39
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 213823db59649233_msascui.exe
Filepath C:\Windows\SysWOW64\DC++ Share\MSASCui.exe
Size 938.4KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9f5fae14cddcb23d8ccb79054c2ebc30
SHA1 a3de0c742365fb4aef7fa4c46821127f5dedb1e6
SHA256 213823db596492339da0d3c57db523ae4033d9a015971da2cfe6dfabe474b309
CRC32 679074A2
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name da5817bfdc0c9c49_procmon.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\Procmon.exe
Size 2.0MB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 41d2c903b4ea5c0cea1cf6e408cbcd93
SHA1 4aa509141f63df3fef327248f23b2ec3889f3cd5
SHA256 da5817bfdc0c9c49c8a2b555eded1ef3151543ee56b352c93c16a8db015a3a69
CRC32 28F25F50
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name dbb0597e28d04daf_wmpnetwk.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpnetwk.exe
Size 1.5MB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9c0ffe21f23bc4e9c2385f613f5edd99
SHA1 58cfada5ff8702d17fc2e349d9f22031f26031ff
SHA256 dbb0597e28d04dafae4ed7bdc80fd9342e04d089dd59213a725a9283f2cb7ae2
CRC32 C57C8AA8
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name ecd8e80928016434_wmlaunch.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmlaunch.exe
Size 256.9KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9c5c9917c9497ae4d5461c851970462b
SHA1 3cad5be1be491e06ae7464a981f05197e23165fb
SHA256 ecd8e80928016434c63f5c7d893ef48e056cb20372f1741859cbdad765197dd9
CRC32 4A0EBEFF
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 85c3c04fceccd745_mpcmdrun.exe
Filepath C:\Windows\SysWOW64\DC++ Share\MpCmdRun.exe
Size 186.4KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 706621e717390f29782d29034651b637
SHA1 bc0dcd736a3f0f2cb26bd35081b0d6ade1964784
SHA256 85c3c04fceccd745fe4aa48958e2f538061f01aa9ac919c0f5ccd11cf15bda1b
CRC32 9317F71D
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 52d65a3dc18c3599_is32bit.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\is32bit.exe
Size 106.9KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 88729860b24a184076b07cf33d7a19c6
SHA1 a305cd2dc864e121d01d28ac6caf2f0ef7d1d76e
SHA256 52d65a3dc18c35995d2664f572c53f9f2c96bc0c09b2d3cf6c1d816b6b534821
CRC32 BCAB223A
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 15e1390ba63ba286_tabtip.exe
Filepath C:\Windows\SysWOW64\DC++ Share\TabTip.exe
Size 218.9KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 9d02c76a74538cb0b4e4e1ded191e179
SHA1 38b2ee717b58328a9e85a0f227befb893d8b1d65
SHA256 15e1390ba63ba286893b657d095057f4f17e6e36b3f9042c7049774eb2bc8ddb
CRC32 63E6B4C0
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name befcec196fb94f60_ieinstal.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ieinstal.exe
Size 263.4KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 dc8414d859f58ea42ed7656123432157
SHA1 c253124afe2825ebd7894e8e91c2ad08d8710097
SHA256 befcec196fb94f605743c95274468cc9ba4dcda1cb61a113e01da4e512e8258a
CRC32 9432CA64
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name c29df763097f28a9_shapecollector.exe
Filepath C:\Windows\SysWOW64\DC++ Share\ShapeCollector.exe
Size 678.9KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 77c350030a19a6edec4e4b09bea2d6d3
SHA1 7c3719c001d861606ae3cd9dd6d3b93e87c0a31b
SHA256 c29df763097f28a98eb0a4c0531070b13023bad075ff2d145a69fbe1e5db4082
CRC32 80F14E1B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 5095d0081ad3b068_mip.exe
Filepath C:\Windows\SysWOW64\DC++ Share\mip.exe
Size 1.5MB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 0323cc7b02902c40d83e1747dacbccb8
SHA1 c1a46dfe55c3637b90b661a91a953c2efb9575a0
SHA256 5095d0081ad3b068788c1a8ea42bbdffa5430fac42041378458158f288c05e14
CRC32 2FCC4F3D
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name b707d094c703797c_wmpshare.exe
Filepath C:\Windows\SysWOW64\DC++ Share\wmpshare.exe
Size 148.2KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 f5152d0dda18bd8c6e2136779fd5a4d5
SHA1 8e4db13e7a10fb189d157aae9567c084b11e7111
SHA256 b707d094c703797c420f289a3f8a1dbb6bcd43c71fcf78199d6dc1d3ee162a63
CRC32 1793B67B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a7674314514aa3e0_inputpersonalization.exe
Filepath C:\Windows\SysWOW64\DC++ Share\InputPersonalization.exe
Size 374.4KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 e918637ce281b93594c18fd03fe03757
SHA1 217295f3d1b0c4866b1be0244a120b7d10644d6d
SHA256 a7674314514aa3e06e4ccaa9687e47e236a428b8f21a43ba94a180258f1176d1
CRC32 4212EDA9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 778c2bde979f7c72_dvdmaker.exe
Filepath C:\Windows\SysWOW64\DC++ Share\DVDMaker.exe
Size 2.2MB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 4191f52b53ff58de1b3dbddfe286e96d
SHA1 b94723924cc2184cf0c82a5b9acc90c1a90e0e52
SHA256 778c2bde979f7c7252cd3c26b3acb8780255a4972ab5a269a2ea84baf4e9d787
CRC32 5B90E34B
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name 51d5f9a1f2716b89_inject-x86.exe
Filepath C:\Windows\SysWOW64\xdccPrograms\inject-x86.exe
Size 143.6KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 47163538e025d1095b644508f06520fb
SHA1 cf6699d4f90de91479c6f582629491154e5a5798
SHA256 51d5f9a1f2716b89532b96522832e01bd59c5dc55677a8d9678ebe4fc443f707
CRC32 58A3D913
ssdeep None
Yara None matched
VirusTotal Search for analysis
Name a1e88659a4ad4f4f_marijuana.txt
Filepath C:\marijuana.txt
Size 21.2KB
Processes 1848 (0d39e8ce51116a21edfa9a84acffd803b6a8764a37e160b209a4939f227bc035.exe)
Type ISO-8859 text, with CRLF line terminators
MD5 c0214c7723fe7bde6bc2834742bcc506
SHA1 f3d8e78975bf169fc1ed3ae95ad41d84ff6a36c3
SHA256 a1e88659a4ad4f4fd55f246ab076dee048881fcac3ea8a300e2fe8cdffd88b73
CRC32 0D0BD2E9
ssdeep None
Yara None matched
VirusTotal Search for analysis
Sorry! No dropped buffers.